All patch & vulnerability trackers

The 1,299 vulnerabilities attackers are exploiting right now, ranked by risk

The exploited-right-now list the Microsoft Update Guide leaves out, ranked so the worst is first. Senserva tracks 1,299 actively exploited non-Microsoft CVEs across 280 vendors, 238 of them tied to ransomware campaigns, and 10 added in the last 7 days. Every entry carries CVSS, the FIRST.org EPSS probability, the CISA required action and due date, and the vendor advisory that fixes it, cross-referenced with VulnCheck KEV and the ENISA EUVD. Updated August 29, 2026 and refreshed twice a day, free and with no sign-in.

Senserva is a Microsoft Intelligent Security Association member · JSON and RSS feeds included, no login required: feeds and API.

Exploited this week By vendor Microsoft patches CVE reference Patch Tuesday End of life products Senserva patching All trackers

The hottest exploited CVEs right now

The ten non-Microsoft CVEs under the most real-world pressure right now, ranked by the Senserva CVE Ranking: CISA KEV confirmed exploitation, ransomware, EPSS, severity, and recency. See the hottest CVEs and KBs together on the What's Hot page.

Loading the hottest CVEs...
Show the full top 100 hottest CVEs
Loading the full list...

Sourced from CISA KEV, NVD, and FIRST.org EPSS, cross-referenced with VulnCheck KEV and the ENISA EUVD (EU). The Fix column links each vendor's PSIRT advisory. The page loads its data from api/kev-nonms.json, a free JSON endpoint; usage rules on the feeds page. Last updated 2026-08-29 20:58 GMT.

Export:RSS

Click any row to expand it: full description, EPSS and CVSS, the verbatim CISA required action and due date, and the fix advisory.

Take this data to your AI

Generated from the live data above, refreshed twice a day (5 AM and 3 PM US Central). Copy it into Claude, ChatGPT, or Copilot. Free, no sign-in.

Most-exploited vendors, drawn by Senserva Vivid
Vendors with the most CVEs added to CISA KEV in the trailing twelve months; the red segment of each bar is the ransomware-linked share. Microsoft is shown for comparison; the rest of this page covers non-Microsoft software. To see one vendor's rows, type its name into the table search below.
The vendors with the most CVEs added to CISA KEV in the trailing twelve months, each bar's inner segment the ransomware-linked share, Microsoft included for comparison
Exploitation trend, drawn by Senserva Vivid
Non-Microsoft CVEs added to CISA KEV each month, with the ransomware-linked share inside each bar and the trailing severity-weighted risk as a line. Move the time frame to ask a different question, and click any month to filter the table below to it.
Tracking Microsoft instead?
See the Microsoft Patch Tracker for every Patch Tuesday KB and the CVEs it fixes, EPSS-ranked.
Microsoft Patch Tracker

Data sources

Every row is built from authoritative, public security feeds, refreshed automatically.

Source What it provides
CISA KEV catalogThe list itself: which CVEs are actively exploited, vendor, product, ransomware use, and the required action.
NVD (NIST)CVSS base score and severity for each CVE.
CIRCL CVE SearchCVSS fallback when NVD has no score yet, so newly added CVEs still get a severity.
EPSS (FIRST.org)Exploit Prediction Scoring System: probability a CVE is exploited within 30 days, used to rank the list.
VulnCheck KEVA broader Known Exploited Vulnerabilities list than CISA KEV. Shown as a "VulnCheck KEV" signal. Data courtesy of VulnCheck, used with attribution.
ENISA EUVDThe European Union Vulnerability Database (ENISA, under NIS2). Shown as an "EU EUVD" signal for the CVEs the EU tracks as exploited. Courtesy of ENISA, used with attribution.
Vendor PSIRTsThe Fix / advisory column links to each vendor's own security advisory (Cisco, Fortinet, Ivanti, Citrix, Adobe, Apple, VMware/Broadcom, and more), where the patched version lives.
Attribution. Exploitation data labeled VulnCheck KEV is provided by VulnCheck and is used with attribution per VulnCheck's terms. EU cross-references are from the ENISA EUVD. Vendor PSIRT advisories are linked, not redistributed. Senserva is not affiliated with or endorsed by these providers.

CISA Top Routinely Exploited Vulnerabilities

CISA and its international partners publish a yearly joint advisory naming the CVEs attackers exploited most. For 2023, advisory AA24-317A lists 15 vulnerabilities, led by Citrix NetScaler, Cisco IOS XE, Fortinet FortiOS, and Progress MOVEit Transfer. Every one is in the live CISA KEV table above with current EPSS and ransomware flags; each row here links to its detail page.

CVE Vendor and product Vulnerability type
CVE-2023-3519Citrix NetScaler ADC and GatewayCode injection (remote code execution)
CVE-2023-4966Citrix NetScaler ADC and Gateway (Citrix Bleed)Sensitive information disclosure
CVE-2023-20198Cisco IOS XE Web UIPrivilege escalation
CVE-2023-20273Cisco IOS XE Web UICommand injection
CVE-2023-27997Fortinet FortiOS and FortiProxy SSL-VPNHeap buffer overflow (remote code execution)
CVE-2023-34362Progress MOVEit TransferSQL injection
CVE-2023-22515Atlassian Confluence Data Center and ServerBroken access control
CVE-2021-44228Apache Log4j2 (Log4Shell)Remote code execution
CVE-2023-2868Barracuda Email Security GatewayImproper input validation (command injection)
CVE-2022-47966Zoho ManageEngine (multiple products)Remote code execution
CVE-2023-27350PaperCut MF and NGImproper access control (remote code execution)
CVE-2020-1472Microsoft Netlogon (Zerologon)Privilege escalation
CVE-2023-42793JetBrains TeamCityAuthentication bypass (remote code execution)
CVE-2023-23397Microsoft OutlookPrivilege escalation
CVE-2023-49103ownCloud graphapiInformation disclosure

Two entries are Microsoft products, Zerologon and the Outlook flaw; for those see the Microsoft patch tracker. Browse the full exploited history for a vendor: Citrix, Cisco, Fortinet, Apache, Ivanti, Palo Alto Networks, VMware, or the full vendor index.

From CISA KEV to your actual exposure

This is the whole actively-exploited non-Microsoft catalog. Senserva matches it against the third-party software, devices, and apps it finds in your Microsoft 365, Intune, Defender, and Entra ID tenant, then ranks what is exposed by CISA KEV and EPSS, so you patch the few that matter first.

Matched to your tenant

Senserva cross-references this catalog with the software and devices it inventories, so you see which exploited CVEs you are actually exposed to.

CVE and patch management

One connected model

Third-party exposure sits with configuration, logs, and Conditional Access in one model, so real risk rises to the top.

The unified security model

AI remediation you approve

Bring your own AI. It reads the connected model and produces validated fixes you review before anything changes.

AI remediation

Compliance evidence

Exposed, exploited CVEs map straight to the frameworks an auditor asks about, from the same model.

Compliance evidence

See it on your own tenant

Frequently asked questions

What is the CISA KEV catalog?

CISA's Known Exploited Vulnerabilities (KEV) catalog is the U.S. government's authoritative list of CVEs confirmed to be exploited in the wild. Because exploitation is proven, KEV entries are the vulnerabilities to patch first, ahead of anything scored only by severity.

What is an EPSS score?

EPSS (Exploit Prediction Scoring System) from FIRST.org estimates the probability that a CVE will be exploited in the next 30 days. This tracker ranks the exploited vulnerabilities by EPSS so the most likely-to-be-attacked rise to the top.

Which vulnerabilities does this tracker cover?

Every actively exploited, third-party (non-Microsoft) vulnerability in CISA KEV: Apache, Cisco, Citrix, Fortinet, Ivanti, VMware, and the rest, with vendor, product, CVSS, ransomware use, and the vendor advisory that fixes each one. Microsoft vulnerabilities are on the separate Microsoft patch tracker.

How often is the exploited vulnerability list updated?

Daily. The data refreshes from CISA KEV, NVD, and FIRST.org EPSS, cross-referenced with VulnCheck KEV and the ENISA EUVD, so newly exploited CVEs appear within a day of being cataloged.

Is this exploited vulnerability tracker free?

Yes, free with no sign-in. You can search, sort, and export to CSV or JSON. Running Senserva adds the part a public list cannot: which of these exploited CVEs your own environment is actually exposed to, ranked, so you fix the right things first.

Can I use this exploited-CVE data with my own AI?

Yes. A free copy-paste AI prompt near the table is generated from the live data each day and carries the top exploited CVEs, with vendor, CVSS, EPSS, ransomware use, and CISA due dates, into Claude, ChatGPT, or Copilot for triage in your own words.

What are the top routinely exploited vulnerabilities?

CISA and its international partners publish a yearly joint advisory naming the CVEs attackers exploited most. For 2023, advisory AA24-317A lists 15, led by Citrix NetScaler (CVE-2023-3519 and Citrix Bleed CVE-2023-4966), Cisco IOS XE (CVE-2023-20198), Fortinet FortiOS (CVE-2023-27997), and Progress MOVEit Transfer (CVE-2023-34362). All 15 are listed above and appear in the live table with current EPSS and ransomware flags.

How often does CISA add new known exploited vulnerabilities?

CISA adds CVEs to the KEV catalog on a rolling basis, often several times a week, whenever exploitation is confirmed. This tracker refreshes daily, so new additions appear within a day of being cataloged. The most recent ones are on the exploited this week page.

Will a CISA KEV-listed vulnerability see ransomware exploitation soon?

Many do. CISA flags the KEV entries known to be used in ransomware campaigns, and those are marked in the Ransomware column here. A KEV listing already means exploitation is confirmed, so treat every entry, ransomware-flagged or not, as urgent and patch by the CISA due date shown in the table.

The alerts Senserva Watch has sent

Every mass alert we email Watch members, logged as it goes out: the date, the CVEs and KBs it covered, and the text. What was sent, never to whom. No login needed; the log is also a free JSON feed at api/watch-alerts.json.

Reference: the Microsoft patching guide, how Intune, Windows Autopatch, Defender, and Azure Update Manager fit together, and where third-party patch vendors fit in.

Data notice: the trackers, feeds, and API are provided as is, for informational purposes only, without warranty of any kind. Senserva, LLC does not guarantee the accuracy, completeness, or timeliness of third-party data and accepts no liability for actions taken based on it; verify against the primary source before acting. All use of this data is subject to the Senserva EULA.

Now see the same thing in your own tenant.

Siemserva by Senserva reads your Microsoft 365, Intune, Defender, and Entra ID environment and returns every missing update ranked by what is actually being exploited, alongside all 650+ configuration checks.

1Find it2Fix it3Prove it
Start my free auditAll you do is register.