All patch & vulnerability trackers
CISA KEV additions this week: 6 new exploited CVEs
Every CVE that crossed from theoretical to confirmed exploited in the wild in the last 7 days: the newest CISA KEV catalog additions for July 2026, all vendors, enriched with CVSS and EPSS and flagged for ransomware use. Updated today and every day, multiple times daily, free, no sign-in.
Treat it as your today-view of the vendor security advisories that actually matter: if a CVE is on this page, someone is exploiting it right now, whether it lives in Cisco IOS XE, PAN-OS, Fortinet, Windows, or a package deep in your stack.
All 1,250+ exploited CVEs By vendor Microsoft patches CVE reference Patch Tuesday All trackers
Added to CISA KEV in the last 7 days
Every column sorts and searches. Click any row for the full description and links.
The last few weeks in exploitation
CISA confirmed 9 newly exploited vulnerabilities in the last 7 days, after 9 the week before and 8 across the two weeks before that: 30 new KEV entries in 30 days, 1 of them tied to ransomware campaigns. Most-affected vendors this month: Microsoft, Ubiquiti, Langflow, WordPress. Every entry below links to a Senserva page with the risk facts, the fix, and a validated AI read; our AI output follows the Senserva Trustworthy AI rules, every claim tied to a published feed fact.
This week's additions, at a glance
CVE-2026-16232 (Check Point)CVE-2026-50522 (Microsoft)CVE-2021-27137 (DD-WRT)CVE-2026-0770 (Langflow)CVE-2026-60137 (WordPress)CVE-2026-63030 (WordPress)CVE-2026-25089 (Fortinet)CVE-2026-39808 (Fortinet)CVE-2026-58644 (Microsoft)
What the security community is talking about
The most-discussed CVEs on Hacker News over the trailing year. Community attention, not a CISA exploitation verdict; the page behind each link has the confirmed risk facts.
CVE-2026-20841 (832 Hacker News points): "Windows Notepad App Remote Code Execution Vulnerability"
CVE-2026-2441 (379 Hacker News points): "Zero-day CSS: CVE-2026-2441 exists in the wild"
CVE-2025-55315 (289 Hacker News points): "Understanding the Worst .NET Vulnerability"
CVE-2026-31431 (249 Hacker News points): "CVE-2026-31431: Copy Fail vs. rootless containers"
CVE-2025-43300 (245 Hacker News points): "iOS 18.6.1 0-click RCE POC"
CVE-2025-55182 (181 Hacker News points): "Critical RCE Vulnerabilities in React and Next.js"
The 25 hottest CVEs right now
Ranked by confirmed exploitation (CISA KEV), ransomware use, EPSS, CVSS severity, and recency. The full list, CVEs and patches side by side: Hot Patches and CVEs, also a free JSON feed.
CVE-2026-50522CVE-2026-48282CVE-2026-55255CVE-2008-4250CVE-2007-3010CVE-2026-42897CVE-2026-45504CVE-2026-55040CVE-2026-12569CVE-2026-56290CVE-2012-0151CVE-2026-34910CVE-2026-45503CVE-2014-1761CVE-2015-5122CVE-2026-35273CVE-2013-0631CVE-2016-0151CVE-2019-0808CVE-2013-3346CVE-2026-10520CVE-2026-45659CVE-2026-46817CVE-2019-1579CVE-2026-63030
Sources and more info: CISA KEV catalog, FIRST.org EPSS, NIST NVD. On Senserva: the full exploited-CVE tracker, the Microsoft patch tracker, and free feeds and the JSON API (attribution: Patch Data Provided by Senserva).
Generated from this week's actual KEV additions, refreshed twice a day (5 AM and 3 PM US Central). Copy it into Claude, ChatGPT, or Copilot. Free, no sign-in.
The rest of the last 30 days
Every column sorts and searches. Click any row for the full description and links.
Full catalog, searchable with EPSS ranking and CISA due dates: the exploited-CVE tracker. Microsoft entries link to their CVE pages with the fixing KB.
Authoritative references
The primary sources this page is built from, and the ones worth bookmarking alongside it.
- CISA Known Exploited Vulnerabilities Catalog: the official catalog this page tracks, with federal remediation due dates.
- CISA KEV JSON feed: the official machine-readable catalog (CSV is on the catalog page).
- CISA Cybersecurity Advisories: the alerts that often accompany new KEV entries.
- CISA joint advisory: 2023 Top Routinely Exploited Vulnerabilities: the annual look-back companion to this live view.
- FIRST.org EPSS: the daily exploit-probability scores shown on each entry.
- NIST National Vulnerability Database: CVSS scoring and per-CVE detail for every entry.
- Microsoft Security Update Guide (MSRC): the authoritative fix record for the Microsoft entries.
- CVE Program (MITRE): the CVE identifiers themselves.
Frequently asked questions
Which vulnerabilities are being exploited this week?
The list above shows every CVE added to the CISA Known Exploited Vulnerabilities (KEV) catalog in the last 7 days, across all vendors. KEV means exploitation in the wild has been confirmed by CISA, not just predicted. The page refreshes twice a day: 5 AM and 3 PM US Central.
What does it mean when a vulnerability is added to CISA KEV?
CISA has confirmed active exploitation and, for U.S. federal agencies, sets a remediation due date. For everyone else it is the strongest fix-first signal available: attackers are using it right now.
How is exploited this week different from a new CVE?
Thousands of CVEs are published every month, but only a small fraction are ever exploited. This page tracks the moment a CVE crosses from theoretical to actively exploited, which is usually when it should jump the patch queue.
How often is this page updated?
Multiple times daily from the CISA KEV catalog, enriched with CVSS and EPSS. When CISA adds new entries, they appear here the same day.
What was added to the CISA KEV catalog today?
The cards at the top of this page are the newest CISA KEV catalog additions, each with its date added. The page refreshes twice a day: 5 AM and 3 PM US Central, so entries CISA adds today appear here the same day, with CVSS, EPSS, and ransomware context attached.
Which vendors show up most in the KEV catalog?
Cisco (including IOS XE and Identity Services Engine), Microsoft, Apple, Adobe, Google, Palo Alto Networks (PAN-OS), Fortinet, and Ivanti (including Pulse Connect Secure) are recurring names. Live per-vendor counts and a searchable list are on the exploited-CVE tracker.
Is there a CISA KEV JSON feed I can use?
CISA publishes the official KEV catalog as JSON and CSV on cisa.gov. Senserva also provides free JSON and RSS feeds of the enriched data, EPSS-ranked with no login, on the feeds page.
Is this the same as CISA's Top Routinely Exploited Vulnerabilities advisory?
No. That is an annual joint advisory listing the CVEs most exploited during a past year (the 2023 edition is the best known). This page tracks the live CISA KEV catalog: the moment a CVE is confirmed exploited, it is added and appears here. Both are CISA exploitation signals; this one moves daily.
Can I use this data with my own AI?
Yes. A free copy-paste AI prompt below the list is generated from this week's actual additions and carries the CVE names, vendors, CVSS, EPSS, and ransomware use into Claude, ChatGPT, or Copilot for triage in your own words.
Free registration is all it takes, no card. Want it always on? Summer Special: unlimited use, up to 50 tenants, $600/mo or $6,500/yr.
Reference: the Microsoft patching guide, how Intune, Windows Autopatch, Defender, and Azure Update Manager fit together.
Data notice: this page is provided as is, for informational purposes only, without warranty of any kind. Senserva, LLC does not guarantee the accuracy, completeness, or timeliness of third-party data (CISA KEV, NVD, EPSS) and accepts no liability for actions taken based on it; verify against the authoritative vendor advisory before acting. All use of this data is subject to the Senserva EULA.