All patch & vulnerability trackers

CISA KEV additions this week: 3 new exploited CVEs

3 vulnerabilities crossed from theoretical to confirmed exploited in the wild in the last 7 days, across 3 vendors (Cisco, Microsoft, Metabase). The likeliest to be attacked next is CVE-2026-72898 (Metabase), which FIRST.org rates at 10% probability of exploitation in the next 30 days. Every entry is enriched with CVSS and EPSS and flagged for ransomware use, updated August 15, 2026 and every day, multiple times daily, free and with no sign-in.

Treat it as your today-view of the vendor security advisories that actually matter: if a CVE is on this page, someone is exploiting it right now, whether it lives in Cisco IOS XE, PAN-OS, Fortinet, Windows, or a package deep in your stack.

All 1,250+ exploited CVEs By vendor Microsoft patches CVE reference Patch Tuesday All trackers

Added to CISA KEV in the last 7 days

Every column sorts and searches. Click any row for the full description and links.

The last few weeks in exploitation

CISA confirmed 5 newly exploited vulnerabilities in the last 7 days, after 5 the week before and 13 across the two weeks before that: 28 new KEV entries in 30 days, 2 of them tied to ransomware campaigns. Most-affected vendors this month: Microsoft, Cisco, Fortinet, N-able. Every entry below links to a Senserva page with the risk facts, the fix, and a validated AI read; our AI output follows the Senserva Trustworthy AI rules, every claim tied to a published feed fact.

This week's additions, at a glance

CVE-2026-20349 (Cisco)CVE-2026-68820 (Microsoft)CVE-2026-72898 (Metabase)CVE-2026-8037 (Progress)CVE-2026-63077 (JetBrains)

What the security community is talking about

The most-discussed CVEs on Hacker News over the trailing year. Community attention, not a CISA exploitation verdict; the page behind each link has the confirmed risk facts.

CVE-2026-20841 (832 Hacker News points): "Windows Notepad App Remote Code Execution Vulnerability"

CVE-2026-2441 (379 Hacker News points): "Zero-day CSS: CVE-2026-2441 exists in the wild"

CVE-2025-55315 (289 Hacker News points): "Understanding the Worst .NET Vulnerability"

CVE-2026-31431 (249 Hacker News points): "CVE-2026-31431: Copy Fail vs. rootless containers"

CVE-2025-43300 (245 Hacker News points): "iOS 18.6.1 0-click RCE POC"

CVE-2025-55182 (181 Hacker News points): "Critical RCE Vulnerabilities in React and Next.js"

The 25 hottest CVEs right now

Ranked by confirmed exploitation (CISA KEV), ransomware use, EPSS, CVSS severity, and recency. Every row opens that CVE's full Senserva page: the risk facts, the fix, the change history we recorded, and a validated AI read. The full list, CVEs and patches side by side: Hot Patches and CVEs, also a free JSON feed.

#1CVE-2026-15409CriticalSonicWall SMA1000 Appliances Server-Side Request Forgeryexploited in the wild · ransomware · EPSS 74% · CVSS 10.0 #2CVE-2026-35273CriticalOracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vuln...exploited in the wild · ransomware · EPSS 95% · CVSS 9.8 #3CVE-2026-0257CriticalPalo Alto Networks PAN-OS Authentication Bypassexploited in the wild · ransomware · EPSS 94% · CVSS 9.1 #4CVE-2026-41940CriticalWebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Funct...exploited in the wild · ransomware · EPSS 98% · CVSS 9.8 #5CVE-2026-8037CriticalProgress LoadMaster Command Injectionexploited in the wild · EPSS 99% · CVSS 9.8 #6CVE-2026-72898CriticalMetabase SQL Injectionexploited in the wild · EPSS 10% · CVSS 10.0 #7CVE-2026-50751CriticalCheck Point Security Gateway Improper Authenticationexploited in the wild · ransomware · EPSS 83% · CVSS 9.3 #8CVE-2025-55182CriticalMeta React Server Components Remote Code Executionexploited in the wild · ransomware · EPSS 100% · CVSS 10.0 #9CVE-2026-15410HighSonicWall SMA1000 Appliances Code Injectionexploited in the wild · ransomware · EPSS 76% · CVSS 7.2 #10CVE-2024-27199HighJetBrains TeamCity Relative Path Traversalexploited in the wild · ransomware · EPSS 100% · CVSS 7.3 #11CVE-2025-61882CriticalOracle E-Business Suite Unspecifiedexploited in the wild · ransomware · EPSS 100% · CVSS 9.8 #12CVE-2025-26399CriticalSolarWinds Web Help Desk Deserialization of Untrusted Dataexploited in the wild · ransomware · EPSS 88% · CVSS 9.8 #13CVE-2025-10035CriticalFortra GoAnywhere MFT Deserialization of Untrusted Dataexploited in the wild · ransomware · EPSS 100% · CVSS 9.8 #14CVE-2026-23760CriticalSmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel Vulnerab...exploited in the wild · ransomware · EPSS 96% · CVSS 9.8 #15CVE-2026-20349HighCisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense...exploited in the wild · CVSS 8.6 #16CVE-2024-1708HighConnectWise ScreenConnect Path Traversalexploited in the wild · ransomware · EPSS 88% · CVSS 8.4 #17CVE-2026-24423CriticalSmarterTools SmarterMail Missing Authentication for Critical Functionexploited in the wild · ransomware · EPSS 88% · CVSS 9.8 #18CVE-2025-61884HighOracle E-Business Suite Server-Side Request Forgery (SSRF)exploited in the wild · ransomware · EPSS 98% · CVSS 7.5 #19CVE-2026-1731CriticalBeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vu...exploited in the wild · ransomware · EPSS 88% · CVSS 9.8 #20CVE-2026-68820HighWindows Ancillary Function Driver for WinSock Elevation of Privilegeexploited in the wild · CVSS 7.0 #21CVE-2025-52691CriticalSmarterTools SmarterMail Unrestricted Upload of File with Dangerous Typeexploited in the wild · ransomware · EPSS 85% · CVSS 10.0 #22CVE-2026-34486HighApache Tomcat Missing Encryption of Sensitive Dataexploited in the wild · EPSS 83% · CVSS 7.5 #23CVE-2023-27351HighPaperCut NG/MF Improper Authenticationexploited in the wild · ransomware · EPSS 77% · CVSS 7.5 #24CVE-2026-12569CriticalPTC Windchill and FlexPLM Improper Input Validationexploited in the wild · ransomware · EPSS 30% · CVSS 9.8 #25CVE-2021-44228CriticalApache Log4j2 Remote Code Executionexploited in the wild · ransomware · EPSS 100% · CVSS 10.0

Sources and more info: CISA KEV catalog, FIRST.org EPSS, NIST NVD. On Senserva: the full exploited-CVE tracker, the Microsoft patch tracker, and free feeds and the JSON API (attribution: Patch Data Provided by Senserva).

Take this week to your AI

Generated from this week's actual KEV additions, refreshed twice a day (5 AM and 3 PM US Central). Copy it into Claude, ChatGPT, or Copilot. Free, no sign-in.

The rest of the last 30 days

Every column sorts and searches. Click any row for the full description and links.

Full catalog, searchable with EPSS ranking and CISA due dates: the exploited-CVE tracker. Microsoft entries link to their CVE pages with the fixing KB.

Authoritative references

The primary sources this page is built from, and the ones worth bookmarking alongside it.

Frequently asked questions

Which vulnerabilities are being exploited this week?

The list above shows every CVE added to the CISA Known Exploited Vulnerabilities (KEV) catalog in the last 7 days, across all vendors. KEV means exploitation in the wild has been confirmed by CISA, not just predicted. The page refreshes twice a day: 5 AM and 3 PM US Central.

What does it mean when a vulnerability is added to CISA KEV?

CISA has confirmed active exploitation and, for U.S. federal agencies, sets a remediation due date. For everyone else it is the strongest fix-first signal available: attackers are using it right now.

How is exploited this week different from a new CVE?

Thousands of CVEs are published every month, but only a small fraction are ever exploited. This page tracks the moment a CVE crosses from theoretical to actively exploited, which is usually when it should jump the patch queue.

How often is this page updated?

Multiple times daily from the CISA KEV catalog, enriched with CVSS and EPSS. When CISA adds new entries, they appear here the same day.

What was added to the CISA KEV catalog today?

The cards at the top of this page are the newest CISA KEV catalog additions, each with its date added. The page refreshes twice a day: 5 AM and 3 PM US Central, so entries CISA adds today appear here the same day, with CVSS, EPSS, and ransomware context attached.

Which vendors show up most in the KEV catalog?

Cisco (including IOS XE and Identity Services Engine), Microsoft, Apple, Adobe, Google, Palo Alto Networks (PAN-OS), Fortinet, and Ivanti (including Pulse Connect Secure) are recurring names. Live per-vendor counts and a searchable list are on the exploited-CVE tracker.

Is there a CISA KEV JSON feed I can use?

CISA publishes the official KEV catalog as JSON and CSV on cisa.gov. Senserva also provides free JSON and RSS feeds of the enriched data, EPSS-ranked with no login, on the feeds page.

Is this the same as CISA's Top Routinely Exploited Vulnerabilities advisory?

No. That is an annual joint advisory listing the CVEs most exploited during a past year (the 2023 edition is the best known). This page tracks the live CISA KEV catalog: the moment a CVE is confirmed exploited, it is added and appears here. Both are CISA exploitation signals; this one moves daily.

Can I use this data with my own AI?

Yes. A free copy-paste AI prompt below the list is generated from this week's actual additions and carries the CVE names, vendors, CVSS, EPSS, and ransomware use into Claude, ChatGPT, or Copilot for triage in your own words.

Reference: the Microsoft patching guide, how Intune, Windows Autopatch, Defender, and Azure Update Manager fit together.

Data notice: this page is provided as is, for informational purposes only, without warranty of any kind. Senserva, LLC does not guarantee the accuracy, completeness, or timeliness of third-party data (CISA KEV, NVD, EPSS) and accepts no liability for actions taken based on it; verify against the authoritative vendor advisory before acting. All use of this data is subject to the Senserva EULA.