All patch & vulnerability trackers

The 1,266 vulnerabilities attackers are exploiting right now, ranked by risk

The exploited-right-now list Microsoft's Update Guide leaves out, ranked so the worst is first. Every CVE in CISA's Known Exploited Vulnerabilities catalog, ranked by the Senserva CVE Ranking: the Apache, Cisco, Citrix, Fortinet, Ivanti, and VMware flaws in active use right now. Jump to the hottest right now, or search below.

Senserva is a Microsoft Intelligent Security Association member · JSON and RSS feeds included, no login required: feeds and API.

Exploited this week By vendor Microsoft patches CVE reference Patch Tuesday End of life products Senserva patching All trackers

The hottest exploited CVEs right now

The ten non-Microsoft CVEs under the most real-world pressure right now, ranked by the Senserva CVE Ranking: CISA KEV confirmed exploitation, ransomware, EPSS, severity, and recency. See the hottest CVEs and KBs together on the What's Hot page.

Loading the hottest CVEs...
Show the full top 100 hottest CVEs
Loading the full list...

Sourced from CISA KEV, NVD, and FIRST.org EPSS, cross-referenced with VulnCheck KEV and the ENISA EUVD (EU). The Fix column links each vendor's PSIRT advisory. Last updated 2026-07-20 20:32 GMT.

SenservaSenserva provides Three Free Unlimited Audits, including all tenants and full Claude MCP.Start my Audit
Export:RSS

Click any row to expand it: full description, EPSS and CVSS, the verbatim CISA required action and due date, and the fix advisory.

Take this data to your AI

Generated from the live data above, refreshed three times a day (5 AM, 12:30 PM, and 7 PM US Central). Copy it into Claude, ChatGPT, or Copilot. Free, no sign-in.

Most-exploited vendors
Vendors with the most CVEs added to CISA KEV in the time frame. Microsoft is shown for comparison; the rest of this page covers non-Microsoft software. The red portion of each bar is the ransomware-linked share.
All time
Exploitation trend
Non-Microsoft CVEs added to CISA KEV per month, ransomware-linked highlighted.
12 months
This is the list. Senserva tells you which ones are in your tenant.
This page is the whole actively-exploited non-Microsoft catalog. Senserva matches it against the software, devices, and apps it finds in your Microsoft 365, Intune, Defender, and Entra ID estate, then ranks what is actually exposed by CISA KEV and EPSS, so you patch the few that matter first.
Scan my tenant free See the Security Center
Tracking Microsoft instead?
See the Microsoft Patch Tracker for every Patch Tuesday KB and the CVEs it fixes, EPSS-ranked.
Microsoft Patch Tracker

Data sources

Every row is built from authoritative, public security feeds, refreshed automatically.

Source What it provides
CISA KEV catalogThe list itself: which CVEs are actively exploited, vendor, product, ransomware use, and the required action.
NVD (NIST)CVSS base score and severity for each CVE.
CIRCL CVE SearchCVSS fallback when NVD has no score yet, so newly added CVEs still get a severity.
EPSS (FIRST.org)Exploit Prediction Scoring System: probability a CVE is exploited within 30 days, used to rank the list.
VulnCheck KEVA broader Known Exploited Vulnerabilities list than CISA KEV. Shown as a "VulnCheck KEV" signal. Data courtesy of VulnCheck, used with attribution.
ENISA EUVDThe European Union Vulnerability Database (ENISA, under NIS2). Shown as an "EU EUVD" signal for the CVEs the EU tracks as exploited. Courtesy of ENISA, used with attribution.
Vendor PSIRTsThe Fix / advisory column links to each vendor's own security advisory (Cisco, Fortinet, Ivanti, Citrix, Adobe, Apple, VMware/Broadcom, and more), where the patched version lives.
Attribution. Exploitation data labeled VulnCheck KEV is provided by VulnCheck and is used with attribution per VulnCheck's terms. EU cross-references are from the ENISA EUVD. Vendor PSIRT advisories are linked, not redistributed. Senserva is not affiliated with or endorsed by these providers.

CISA Top Routinely Exploited Vulnerabilities

CISA and its international partners publish a yearly joint advisory naming the CVEs attackers exploited most. For 2023, advisory AA24-317A lists 15 vulnerabilities, led by Citrix NetScaler, Cisco IOS XE, Fortinet FortiOS, and Progress MOVEit Transfer. Every one is in the live CISA KEV table above with current EPSS and ransomware flags; each row here links to its detail page.

CVE Vendor and product Vulnerability type
CVE-2023-3519Citrix NetScaler ADC and GatewayCode injection (remote code execution)
CVE-2023-4966Citrix NetScaler ADC and Gateway (Citrix Bleed)Sensitive information disclosure
CVE-2023-20198Cisco IOS XE Web UIPrivilege escalation
CVE-2023-20273Cisco IOS XE Web UICommand injection
CVE-2023-27997Fortinet FortiOS and FortiProxy SSL-VPNHeap buffer overflow (remote code execution)
CVE-2023-34362Progress MOVEit TransferSQL injection
CVE-2023-22515Atlassian Confluence Data Center and ServerBroken access control
CVE-2021-44228Apache Log4j2 (Log4Shell)Remote code execution
CVE-2023-2868Barracuda Email Security GatewayImproper input validation (command injection)
CVE-2022-47966Zoho ManageEngine (multiple products)Remote code execution
CVE-2023-27350PaperCut MF and NGImproper access control (remote code execution)
CVE-2020-1472Microsoft Netlogon (Zerologon)Privilege escalation
CVE-2023-42793JetBrains TeamCityAuthentication bypass (remote code execution)
CVE-2023-23397Microsoft OutlookPrivilege escalation
CVE-2023-49103ownCloud graphapiInformation disclosure

Two entries are Microsoft products, Zerologon and the Outlook flaw; for those see the Microsoft patch tracker. Browse the full exploited history for a vendor: Citrix, Cisco, Fortinet, Apache, Ivanti, Palo Alto Networks, VMware, or the full vendor index.

From CISA KEV to your actual exposure

This is the whole actively-exploited non-Microsoft catalog. Senserva matches it against the third-party software, devices, and apps it finds in your Microsoft 365, Intune, Defender, and Entra ID estate, then ranks what is exposed by CISA KEV and EPSS, so you patch the few that matter first.

Matched to your tenant

Senserva cross-references this catalog with the software and devices it inventories, so you see which exploited CVEs you are actually exposed to.

CVE and patch management

One connected model

Third-party exposure sits with configuration, logs, and Conditional Access in one model, so real risk rises to the top.

The unified security model

AI remediation you approve

Bring your own AI. It reads the connected model and produces validated fixes you review before anything changes.

AI remediation

Compliance evidence

Exposed, exploited CVEs map straight to the frameworks an auditor asks about, from the same model.

Compliance evidence

See it on your own tenant

Frequently asked questions

What is the CISA KEV catalog?

CISA's Known Exploited Vulnerabilities (KEV) catalog is the U.S. government's authoritative list of CVEs confirmed to be exploited in the wild. Because exploitation is proven, KEV entries are the vulnerabilities to patch first, ahead of anything scored only by severity.

What is an EPSS score?

EPSS (Exploit Prediction Scoring System) from FIRST.org estimates the probability that a CVE will be exploited in the next 30 days. This tracker ranks the exploited vulnerabilities by EPSS so the most likely-to-be-attacked rise to the top.

Which vulnerabilities does this tracker cover?

Every actively exploited, third-party (non-Microsoft) vulnerability in CISA KEV: Apache, Cisco, Citrix, Fortinet, Ivanti, VMware, and the rest, with vendor, product, CVSS, ransomware use, and the vendor advisory that fixes each one. Microsoft vulnerabilities are on the separate Microsoft patch tracker.

How often is the exploited vulnerability list updated?

Daily. The data refreshes from CISA KEV, NVD, and FIRST.org EPSS, cross-referenced with VulnCheck KEV and the ENISA EUVD, so newly exploited CVEs appear within a day of being cataloged.

Is this exploited vulnerability tracker free?

Yes, free with no sign-in. You can search, sort, and export to CSV or JSON. Running Senserva adds the part a public list cannot: which of these exploited CVEs your own estate is actually exposed to, ranked, so you fix the right things first.

Can I use this exploited-CVE data with my own AI?

Yes. A free copy-paste AI prompt near the table is generated from the live data each day and carries the top exploited CVEs, with vendor, CVSS, EPSS, ransomware use, and CISA due dates, into Claude, ChatGPT, or Copilot for triage in your own words.

What are the top routinely exploited vulnerabilities?

CISA and its international partners publish a yearly joint advisory naming the CVEs attackers exploited most. For 2023, advisory AA24-317A lists 15, led by Citrix NetScaler (CVE-2023-3519 and Citrix Bleed CVE-2023-4966), Cisco IOS XE (CVE-2023-20198), Fortinet FortiOS (CVE-2023-27997), and Progress MOVEit Transfer (CVE-2023-34362). All 15 are listed above and appear in the live table with current EPSS and ransomware flags.

How often does CISA add new known exploited vulnerabilities?

CISA adds CVEs to the KEV catalog on a rolling basis, often several times a week, whenever exploitation is confirmed. This tracker refreshes daily, so new additions appear within a day of being cataloged. The most recent ones are on the exploited this week page.

Will a CISA KEV-listed vulnerability see ransomware exploitation soon?

Many do. CISA flags the KEV entries known to be used in ransomware campaigns, and those are marked in the Ransomware column here. A KEV listing already means exploitation is confirmed, so treat every entry, ransomware-flagged or not, as urgent and patch by the CISA due date shown in the table.

Senserva
Three Free Unlimited Audits
1 scan to find, 2 to review your fixes.
Setup and running in minutes. Your data stays local, in a results database only you hold.
Everything Siemserva by Senserva does: every missing patch ranked by real attacks, all 650+ security checks, and full reports.
All users · All settings · All patches · All tenants
Includes our advanced Claude MCP: everything you need to run full audits.
Start my free audit Watch a guided first scan

Free registration is all it takes, no card. Want it always on? Summer Special: unlimited use, up to 50 tenants, $600/mo or $6,500/yr.

Reference: the Microsoft patching guide, how Intune, Windows Autopatch, Defender, and Azure Update Manager fit together, and where third-party patch vendors fit in.

Data notice: the trackers, feeds, and API are provided as is, for informational purposes only, without warranty of any kind. Senserva, LLC does not guarantee the accuracy, completeness, or timeliness of third-party data and accepts no liability for actions taken based on it; verify against the primary source before acting. All use of this data is subject to the Senserva EULA.

See where your own tenant stands

This tracker follows exploited vulnerabilities beyond Microsoft's own products. To see where your own Microsoft 365 stands against today's threats, run a free, unlimited audit.

Three free audits, across every tenant you manage: 1 scan to find, 2 to review your fixes. It finds:

  • Every missing patch, ranked by real attacks (CISA KEV, EPSS), so you fix the right things first.
  • The machines your consoles cannot see: unenrolled devices, silent patch failures, and servers with no patch path.
  • All 650+ security checks and audit-ready evidence, in an open results database that stays yours.

Includes our advanced Claude MCP: everything you need to run full audits.

Start my free audit