See which vulnerabilities are under attack, and exactly what fixes them

CVEs tracked.

A free, no registration required, daily-refreshed dashboard of patch and vulnerability data across Microsoft and open-source software, ranked by real-world exploitation (CISA KEV) and exploit probability (EPSS). Built for IT, Audit and security teams. Pick a tracker to drill in, or pull the feeds and JSON API.

Senserva is a Microsoft Intelligent Security Association member

Sourced from Microsoft MSRC, NVD, CISA KEV, FIRST.org EPSS, OSV.dev, VulnCheck KEV, and the ENISA EUVD (EU), with vendor PSIRT advisories for the fix. Refreshed daily.

Take the whole landscape to your AI

Generated from the live data above, refreshed three times a day (5 AM, 12:30 PM, and 7 PM US Central). Copy it into Claude, ChatGPT, or Copilot. Free, no sign-in.

The hottest Microsoft updates right now

Ranked by the Senserva CVE Ranking. Full list on the Microsoft patch tracker.

Loading the hottest updates...

The hottest non-Microsoft CVEs right now

Same ranking, across every vendor in CISA KEV. Full list on the CISA KEV tracker.

Loading the hottest CVEs...

The trackers

Each is a free, searchable, daily-refreshed view, ranked the same way: actively exploited (CISA KEV) first, then EPSS and CVSS.

Microsoft Patch Tuesday
The latest Patch Tuesday at a glance, updates, CVEs, and how many are actively exploited, plus a month-by-month history going back years. Ranked by what attackers are really using.
MSRC + CISA KEV + EPSS
See Patch Tuesday and its history
Microsoft patch tracker
Every Patch Tuesday and out-of-band update (KB) and the CVEs it fixes, ranked by risk. Per-KB and per-CVE pages, a product-family heatmap, a searchable table, and download links to the Microsoft Update Catalog.
MSRC + NVD + CISA KEV + EPSS
Open the patch tracker
Microsoft CVE list and lookup
Search and rank Microsoft CVEs by severity, type, and real-world exploitation, each cross-referenced to the patch (KB) that fixes it. Filter to actively exploited or ransomware-linked in one click.
NVD + MSRC + CISA KEV + EPSS
Open the CVE lookup
Non-Microsoft exploited CVEs
Every non-Microsoft CVE in the CISA Known Exploited Vulnerabilities catalog, EPSS-ranked. The Cisco, Fortinet, Ivanti, Citrix, VMware, Apache, and Adobe flaws under active attack right now, in one view.
CISA KEV + NVD + EPSS
Open the exploited-CVE tracker
Open source patch tracker
Actively-exploited open-source CVEs mapped to the affected package and the version that fixes each one, via OSV.dev. The exact upgrade across Maven, npm, PyPI, NuGet, Go, RubyGems, Packagist, and more.
CISA KEV + OSV.dev + EPSS
Open the open-source tracker
End of life tracker
Product end-of-life and end-of-support dates across hundreds of products, Microsoft pinned to the top. Out-of-support software gets no security patches, so this flags what you must upgrade, not just patch.
endoflife.date
Open the EOL tracker
Most-exploited vendors
Vendors with the most CVEs added to CISA KEV in the time frame, across Microsoft and the rest of the ecosystem. The red portion of each bar is the ransomware-linked share. Open the full non-Microsoft tracker.
All time

Data sources

Every tracker is built from authoritative, public feeds, refreshed automatically. No login, no telemetry, no scan data.

Microsoft MSRCPatch Tuesday data: KB-to-CVE mappings, Microsoft severity, affected products, and exploitation status.
NVD (NIST)The U.S. National Vulnerability Database: CVE metadata, CVSS v3 scores and vectors, and CWE weakness types.
CISA KEVThe Known Exploited Vulnerabilities catalog: CVEs confirmed exploited in the wild, with ransomware association.
EPSS (FIRST.org)Exploit Prediction Scoring System: the probability a CVE is exploited within 30 days, used to rank every list.
OSV.devOpen-source package and fixed version for each CVE, aggregating GitHub Security Advisories, PyPA, RustSec, and other OSV-schema sources. Used under the Apache-2.0 license; advisory records are CC BY 4.0.
CIRCL CVE SearchCVSS fallback when NVD has no score yet, so newly disclosed CVEs still get a severity.
VulnCheck KEVA broader Known Exploited Vulnerabilities list than CISA KEV, surfaced as a "VulnCheck KEV" signal. Data courtesy of VulnCheck, used with attribution.
ENISA EUVDThe European Union Vulnerability Database (ENISA, under NIS2), surfaced as an "EU EUVD" signal. Courtesy of ENISA, used with attribution.
Vendor PSIRTsEach vendor's own security advisory (Cisco, Fortinet, Ivanti, Citrix, Adobe, Apple, VMware/Broadcom, and more), linked as the authoritative fix for non-Microsoft, non-open-source products.
Attribution. Exploitation data labeled VulnCheck KEV is provided by VulnCheck and is used with attribution per VulnCheck's terms. EU cross-references are from the ENISA EU Vulnerability Database (EUVD). Open-source package fixes are from OSV.dev. Vendor PSIRT advisories are linked, not redistributed. Senserva is not affiliated with or endorsed by these providers.

For EU teams: vulnerabilities are cross-referenced to the ENISA EU Vulnerability Database (EUVD), the EU's official database under the NIS2 directive.

JSON and RSS feeds included, no login required. All feeds, the API, and quick-start examples.

How it is built

The feeds are pulled and rebuilt daily, then ranked: actively exploited (CISA KEV) first, then EPSS exploit probability and CVSS severity. Every KB and CVE gets its own linkable, cross-referenced page. Static and fast, with no account required.

From your own estate

These trackers cover the public picture. Senserva ranks the same data against the patches and CVEs actually present across your Microsoft 365, Intune, Defender, and Entra ID estate.

Patch and vulnerability tracker FAQ

Common questions about the free patch and vulnerability trackers and how the rankings work.

What is the Siemserva by Senserva patch and vulnerability tracker?

The patch and vulnerability tracker is a free, daily-refreshed hub that ranks Microsoft and open-source patches and CVEs by real-world risk: actively exploited (CISA KEV) first, then EPSS exploit probability and CVSS severity. It links the Microsoft patch tracker, Microsoft CVE and vulnerability management, the non-Microsoft exploited-CVE tracker, the open-source patch tracker, and the end-of-life tracker.

Is the patch and vulnerability tracker free?

Yes. Every tracker is free to use, with no sign-in and no telemetry. Running Senserva adds the part a public tracker cannot: which of these patches and CVEs are actually present on your own devices, ranked, so you fix the right things first.

How often is the patch and vulnerability data updated?

Daily. The trackers auto-refresh from Microsoft MSRC, NVD, CISA KEV, FIRST.org EPSS, OSV.dev, and other public feeds, so the counts, charts, and tables reflect the latest Patch Tuesday and the current exploitation signals.

What data sources does the tracker use?

Microsoft MSRC for Patch Tuesday KB-to-CVE data, NVD and CIRCL for CVSS, CISA KEV for actively-exploited status, FIRST.org EPSS for exploit probability, OSV.dev and the GitHub Advisory Database for open-source package fixes, plus VulnCheck KEV and the ENISA EUVD for broader exploitation signals.

How are patches and vulnerabilities ranked?

By what is actually exploited, not just severity. Actively-exploited CVEs (CISA KEV) rank first, then FIRST.org EPSS exploit probability, then CVSS severity. This surfaces the handful attackers are really using, a better fix-first order than CVSS alone.

How is this different from a CVE list or the MSRC Update Guide?

A CVE list tells you what is broken. These trackers rank every patch and CVE by real-world exploitation and tie each one to the fix, the KB for Microsoft or the package version for open source, so you know what to patch first and exactly how.

Which trackers are included?

The Microsoft patch tracker (Patch Tuesday KBs), Microsoft CVE and vulnerability management, the non-Microsoft exploited-CVE tracker (CISA KEV), the open-source patch tracker (package fixes), and the end-of-life tracker (out-of-support products).

Can I take this data to my own AI?

Yes. Every tracker includes a free copy-paste AI prompt generated from its live data each day, and this page has a cross-tracker prompt covering the whole landscape: Microsoft KBs, exploited CVEs, open-source fixes, and end-of-life dates, ready for Claude, ChatGPT, or Copilot.

Fixing what this tracker finds

These trackers show the public picture. The short walkthrough below shows the same ranking applied to your own tenant: which updates and CVEs are actually missing on your devices, fixed with approval.

Senserva patching for Microsoft 365

Open the watch page for this video, or read about Senserva patching.

Senserva
Three Free Unlimited Audits
1 scan to find, 2 to review your fixes.
Setup and running in minutes. Your data stays local, in a results database only you hold.
Everything Siemserva by Senserva does: every missing patch ranked by real attacks, all 650+ security checks, and full reports.
All users · All settings · All patches · All tenants
Includes our advanced Claude MCP: everything you need to run full audits.
Start my free audit Watch a guided first scan

Free registration is all it takes, no card. Want it always on? Summer Special: unlimited use, up to 50 tenants, $600/mo or $6,500/yr.

Reference: the Microsoft patching guide, how Intune, Windows Autopatch, Defender, and Azure Update Manager fit together, and where third-party patch vendors fit in.

Data notice: the trackers, feeds, and API are provided as is, for informational purposes only, without warranty of any kind. Senserva, LLC does not guarantee the accuracy, completeness, or timeliness of third-party data and accepts no liability for actions taken based on it; verify against the primary source before acting. All use of this data is subject to the Senserva EULA.