All patch & vulnerability trackers
The 1,299 vulnerabilities attackers are exploiting right now, ranked by risk
The exploited-right-now list the Microsoft Update Guide leaves out, ranked so the worst is first. Senserva tracks 1,299 actively exploited non-Microsoft CVEs across 280 vendors, 238 of them tied to ransomware campaigns, and 10 added in the last 7 days. Every entry carries CVSS, the FIRST.org EPSS probability, the CISA required action and due date, and the vendor advisory that fixes it, cross-referenced with VulnCheck KEV and the ENISA EUVD. Updated August 29, 2026 and refreshed twice a day, free and with no sign-in.
Senserva is a Microsoft Intelligent Security Association member · JSON and RSS feeds included, no login required: feeds and API.
Exploited this week By vendor Microsoft patches CVE reference Patch Tuesday End of life products Senserva patching All trackers
The hottest exploited CVEs right now
The ten non-Microsoft CVEs under the most real-world pressure right now, ranked by the Senserva CVE Ranking: CISA KEV confirmed exploitation, ransomware, EPSS, severity, and recency. See the hottest CVEs and KBs together on the What's Hot page.
Show the full top 100 hottest CVEs
Sourced from CISA KEV, NVD, and FIRST.org EPSS, cross-referenced with VulnCheck KEV and the ENISA EUVD (EU). The Fix column links each vendor's PSIRT advisory. The page loads its data from api/kev-nonms.json, a free JSON endpoint; usage rules on the feeds page. Last updated 2026-08-29 20:58 GMT.
Our read:
Do this today:
Spotlight:
Click any row to expand it: full description, EPSS and CVSS, the verbatim CISA required action and due date, and the fix advisory.
Generated from the live data above, refreshed twice a day (5 AM and 3 PM US Central). Copy it into Claude, ChatGPT, or Copilot. Free, no sign-in.
Data sources
Every row is built from authoritative, public security feeds, refreshed automatically.
| Source | What it provides |
|---|---|
| CISA KEV catalog | The list itself: which CVEs are actively exploited, vendor, product, ransomware use, and the required action. |
| NVD (NIST) | CVSS base score and severity for each CVE. |
| CIRCL CVE Search | CVSS fallback when NVD has no score yet, so newly added CVEs still get a severity. |
| EPSS (FIRST.org) | Exploit Prediction Scoring System: probability a CVE is exploited within 30 days, used to rank the list. |
| VulnCheck KEV | A broader Known Exploited Vulnerabilities list than CISA KEV. Shown as a "VulnCheck KEV" signal. Data courtesy of VulnCheck, used with attribution. |
| ENISA EUVD | The European Union Vulnerability Database (ENISA, under NIS2). Shown as an "EU EUVD" signal for the CVEs the EU tracks as exploited. Courtesy of ENISA, used with attribution. |
| Vendor PSIRTs | The Fix / advisory column links to each vendor's own security advisory (Cisco, Fortinet, Ivanti, Citrix, Adobe, Apple, VMware/Broadcom, and more), where the patched version lives. |