All patch & vulnerability trackers

Vulnerabilities exploited this week

The full exploited catalog is the exploited-CVE tracker; ranked next to the patches it is What's Hot; the whole picture is Senserva Live.

Every CVE that crossed from theoretical to confirmed exploited in the wild in the last 7 days: the newest CISA KEV catalog additions for July 2026, all vendors, enriched with CVSS and EPSS and flagged for ransomware use. Updated today and every day, multiple times daily, free, no sign-in.

Treat it as your today-view of the vendor security advisories that actually matter: if a CVE is on this page, someone is exploiting it right now, whether it lives in Cisco IOS XE, PAN-OS, Fortinet, Windows, or a package deep in your stack.

All 1,250+ exploited CVEs By vendor Microsoft patches CVE reference Patch Tuesday All trackers

Added to CISA KEV in the last 7 days

Every column sorts and searches. Click any row for the full description and links.

The last few weeks in exploitation

CISA confirmed 9 newly exploited vulnerabilities in the last 7 days, after 4 the week before and 9 across the two weeks before that: 23 new KEV entries in 30 days. Most-affected vendors this month: Microsoft, Ubiquiti, SonicWall, Cisco. Every entry below links to a Senserva page with the risk facts, the fix, and a validated AI read; our AI output follows the Senserva Trustworthy AI rules, every claim tied to a published feed fact.

This week's additions, at a glance

CVE-2023-4346 (KNX Association)CVE-2026-46817 (Oracle)CVE-2026-15409 (SonicWall)CVE-2026-15410 (SonicWall)CVE-2026-56155 (Microsoft)CVE-2026-56164 (Microsoft)CVE-2008-4128 (Cisco)CVE-2026-48939 (iCagenda)CVE-2026-56291 (Balbooa)

The 25 hottest CVEs right now

Ranked by confirmed exploitation (CISA KEV), ransomware use, EPSS, CVSS severity, and recency. The full list, CVEs and patches side by side: Hot Patches and CVEs, also a free JSON feed.

CVE-2026-48282CVE-2026-55255CVE-2008-4250CVE-2007-3010CVE-2012-0151CVE-2026-56290CVE-2014-1761CVE-2015-5122CVE-2026-34910CVE-2026-42897CVE-2026-45504CVE-2013-0631CVE-2016-0151CVE-2019-0808CVE-2013-3346CVE-2026-10520CVE-2019-1579CVE-2026-35273CVE-2012-0507CVE-2026-20253CVE-2019-2725CVE-2013-2465CVE-2021-30551CVE-2012-4681CVE-2026-12569

Sources and more info: CISA KEV catalog, FIRST.org EPSS, NIST NVD. On Senserva: the full exploited-CVE tracker, the Microsoft patch tracker, and free feeds and the JSON API (attribution: Patch Data Provided by Senserva).

One Free Unlimited Audit
All users All settings All patches All tenants

Everything Siemserva by Senserva does, in one free run: your complete patch state ranked by real exploitation, all 650+ security checks across Microsoft 365, Intune, Defender, and Entra ID, and full reports you keep. Every user, every setting, every tenant you manage. Results land in an open database that stays yours, so you can write your own reports from it for as long as you like.

Start my free audit

Free registration is all it takes. No card, no time limit on reading your results. Building something? The same patch and CVE data is a free feed and JSON API, no login.

Take this week to your AI

Generated from this week's actual KEV additions, refreshed three times a day (5 AM, 12:30 PM, and 7 PM US Central). Copy it into Claude, ChatGPT, or Copilot. Free, no sign-in.

The rest of the last 30 days

Every column sorts and searches. Click any row for the full description and links.

Full catalog, searchable with EPSS ranking and CISA due dates: the exploited-CVE tracker. Microsoft entries link to their CVE pages with the fixing KB.

Authoritative references

The primary sources this page is built from, and the ones worth bookmarking alongside it.

Frequently asked questions

Which vulnerabilities are being exploited this week?

The list above shows every CVE added to the CISA Known Exploited Vulnerabilities (KEV) catalog in the last 7 days, across all vendors. KEV means exploitation in the wild has been confirmed by CISA, not just predicted. The page refreshes three times a day: 5 AM, 12:30 PM, and 7 PM US Central.

What does it mean when a vulnerability is added to CISA KEV?

CISA has confirmed active exploitation and, for U.S. federal agencies, sets a remediation due date. For everyone else it is the strongest fix-first signal available: attackers are using it right now.

How is exploited this week different from a new CVE?

Thousands of CVEs are published every month, but only a small fraction are ever exploited. This page tracks the moment a CVE crosses from theoretical to actively exploited, which is usually when it should jump the patch queue.

How often is this page updated?

Multiple times daily from the CISA KEV catalog, enriched with CVSS and EPSS. When CISA adds new entries, they appear here the same day.

What was added to the CISA KEV catalog today?

The cards at the top of this page are the newest CISA KEV catalog additions, each with its date added. The page refreshes three times a day: 5 AM, 12:30 PM, and 7 PM US Central, so entries CISA adds today appear here the same day, with CVSS, EPSS, and ransomware context attached.

Which vendors show up most in the KEV catalog?

Cisco (including IOS XE and Identity Services Engine), Microsoft, Apple, Adobe, Google, Palo Alto Networks (PAN-OS), Fortinet, and Ivanti (including Pulse Connect Secure) are recurring names. Live per-vendor counts and a searchable list are on the exploited-CVE tracker.

Is there a CISA KEV JSON feed I can use?

CISA publishes the official KEV catalog as JSON and CSV on cisa.gov. Senserva also provides free JSON and RSS feeds of the enriched data, EPSS-ranked with no login, on the feeds page.

Is this the same as CISA's Top Routinely Exploited Vulnerabilities advisory?

No. That is an annual joint advisory listing the CVEs most exploited during a past year (the 2023 edition is the best known). This page tracks the live CISA KEV catalog: the moment a CVE is confirmed exploited, it is added and appears here. Both are CISA exploitation signals; this one moves daily.

Can I use this data with my own AI?

Yes. A free copy-paste AI prompt below the list is generated from this week's actual additions and carries the CVE names, vendors, CVSS, EPSS, and ransomware use into Claude, ChatGPT, or Copilot for triage in your own words.

Sponsored by Senserva

Siemserva by Senserva reports patch status for your own devices: which ones are missing the updates on this page, ranked by what attackers actually exploit.

  • Patch status in one scan: which devices are affected, which are not
  • Missing updates ranked by CISA KEV and EPSS, so you fix the right things first
  • Data from Intune, Microsoft Defender, Windows Autopatch, and Azure Update Manager, with more sources on the way
  • Third-party app patching too: updates published to Intune by PatchMyPC, Scappman, Robopack, or any vendor, read vendor-neutrally
  • Optional AI Enhanced Reporting: plain-language summaries and recommended next steps written into your reports
  • Then go further: 650+ security checks find the drift management gaps across Microsoft 365, Intune, Defender, and Entra ID, with compliance evidence and Senserva Trustworthy AI remediation
Senserva patching for Microsoft 365
Two minutes, click to play

Patching in action in two minutes. Watch page · All videos.

3 actively exploited CVEs are unmitigated on devices in this tenant, per CISA KEV.View fix-first list ↓
312
Devices scanned
Intune + Autopatch + Defender
3
Exploited updates missing
CISA KEV, unmitigated
905
Microsoft updates tracked
Refreshed daily, MSRC + NVD
650+
Security checks in scan
Patch, config, identity, logs

Triage order for this list

Same order in the dashboard, the report, and every AI answer
1st · overrides everything
Actively exploited (KEV)
e.g. KB5040219, CVE-2026-31210
2nd · tiebreaker
Severity (Critical → Low)
MSRC + EPSS probability
3rd · tiebreaker
Days waiting
Oldest unresolved first

Ranked missing updates, fix-first order

27 findings · showing top 2
#UpdateCVESeveritySourceDevicesWaiting
1KB5040219
Windows 11 23H2 cumulative
CVE-2026-31210
KEV EPSS 0.94
CriticalDefender4119 daysAdd to fix-first
2KB5040088
.NET Framework security update
CVE-2026-29981
KEV
CriticalIntune1712 daysAdd to fix-first
Estimated dashboard, sample data for illustration

Ask Senserva

via Claude + MCP
Which devices are still missing the fix for CVE-2026-31210?
41 devices are missing KB5040219, which resolves CVE-2026-31210. This CVE is on CISA KEV, so CISA BOD 22-01 calls for remediation within 14 days. You are at 19 days and counting.
source: scan_db · defender_posture · kev_join, not model memory
Senserva is a Microsoft Intelligent Security Association member. Get Going with Senserva Senserva patching Built for IT admins and security teams, with audit-ready data for compliance.

Reference: the Microsoft patching guide, how Intune, Windows Autopatch, Defender, and Azure Update Manager fit together.

Data notice: this page is provided as is, for informational purposes only, without warranty of any kind. Senserva, LLC does not guarantee the accuracy, completeness, or timeliness of third-party data (CISA KEV, NVD, EPSS) and accepts no liability for actions taken based on it; verify against the authoritative vendor advisory before acting. All use of this data is subject to the Senserva EULA.