See which vulnerabilities are under attack, and exactly what fixes them

CVEs tracked.

A free, no registration required, daily-refreshed dashboard of patch and vulnerability data across Microsoft and open-source software, ranked by real-world exploitation (CISA KEV) and exploit probability (EPSS). Built for IT, Audit and security teams. Pick a tracker to drill in, or pull the feeds and JSON API.

Senserva is a Microsoft Intelligent Security Association member

Sourced from Microsoft MSRC, NVD, CISA KEV, FIRST.org EPSS, OSV.dev, VulnCheck KEV, and the ENISA EUVD (EU), with vendor PSIRT advisories for the fix. Refreshed daily.

Take the whole landscape to your AI

Generated from the live data above, refreshed three times a day (5 AM, 12:30 PM, and 7 PM US Central). Copy it into Claude, ChatGPT, or Copilot. Free, no sign-in.

The hottest Microsoft updates right now

Ranked by the Senserva CVE Ranking. Full list on the Microsoft patch tracker.

Loading the hottest updates...

The hottest non-Microsoft CVEs right now

Same ranking, across every vendor in CISA KEV. Full list on the CISA KEV tracker.

Loading the hottest CVEs...

The trackers

Each is a free, searchable, daily-refreshed view, ranked the same way: actively exploited (CISA KEV) first, then EPSS and CVSS.

Microsoft Patch Tuesday
The latest Patch Tuesday at a glance, updates, CVEs, and how many are actively exploited, plus a month-by-month history going back years. Ranked by what attackers are really using.
MSRC + CISA KEV + EPSS
See Patch Tuesday and its history
Microsoft patch tracker
Every Patch Tuesday and out-of-band update (KB) and the CVEs it fixes, ranked by risk. Per-KB and per-CVE pages, a product-family heatmap, a searchable table, and download links to the Microsoft Update Catalog.
MSRC + NVD + CISA KEV + EPSS
Open the patch tracker
Microsoft CVE list and lookup
Search and rank Microsoft CVEs by severity, type, and real-world exploitation, each cross-referenced to the patch (KB) that fixes it. Filter to actively exploited or ransomware-linked in one click.
NVD + MSRC + CISA KEV + EPSS
Open the CVE lookup
Non-Microsoft exploited CVEs
Every non-Microsoft CVE in the CISA Known Exploited Vulnerabilities catalog, EPSS-ranked. The Cisco, Fortinet, Ivanti, Citrix, VMware, Apache, and Adobe flaws under active attack right now, in one view.
CISA KEV + NVD + EPSS
Open the exploited-CVE tracker
Open source patch tracker
Actively-exploited open-source CVEs mapped to the affected package and the version that fixes each one, via OSV.dev. The exact upgrade across Maven, npm, PyPI, NuGet, Go, RubyGems, Packagist, and more.
CISA KEV + OSV.dev + EPSS
Open the open-source tracker
End of life tracker
Product end-of-life and end-of-support dates across hundreds of products, Microsoft pinned to the top. Out-of-support software gets no security patches, so this flags what you must upgrade, not just patch.
endoflife.date
Open the EOL tracker
Most-exploited vendors
Vendors with the most CVEs added to CISA KEV in the time frame, across Microsoft and the rest of the ecosystem. The red portion of each bar is the ransomware-linked share. Open the full non-Microsoft tracker.
All time

Data sources

Every tracker is built from authoritative, public feeds, refreshed automatically. No login, no telemetry, no scan data.

Microsoft MSRCPatch Tuesday data: KB-to-CVE mappings, Microsoft severity, affected products, and exploitation status.
NVD (NIST)The U.S. National Vulnerability Database: CVE metadata, CVSS v3 scores and vectors, and CWE weakness types.
CISA KEVThe Known Exploited Vulnerabilities catalog: CVEs confirmed exploited in the wild, with ransomware association.
EPSS (FIRST.org)Exploit Prediction Scoring System: the probability a CVE is exploited within 30 days, used to rank every list.
OSV.devOpen-source package and fixed version for each CVE, aggregating GitHub Security Advisories, PyPA, RustSec, and other OSV-schema sources. Used under the Apache-2.0 license; advisory records are CC BY 4.0.
CIRCL CVE SearchCVSS fallback when NVD has no score yet, so newly disclosed CVEs still get a severity.
VulnCheck KEVA broader Known Exploited Vulnerabilities list than CISA KEV, surfaced as a "VulnCheck KEV" signal. Data courtesy of VulnCheck, used with attribution.
ENISA EUVDThe European Union Vulnerability Database (ENISA, under NIS2), surfaced as an "EU EUVD" signal. Courtesy of ENISA, used with attribution.
Vendor PSIRTsEach vendor's own security advisory (Cisco, Fortinet, Ivanti, Citrix, Adobe, Apple, VMware/Broadcom, and more), linked as the authoritative fix for non-Microsoft, non-open-source products.
Attribution. Exploitation data labeled VulnCheck KEV is provided by VulnCheck and is used with attribution per VulnCheck's terms. EU cross-references are from the ENISA EU Vulnerability Database (EUVD). Open-source package fixes are from OSV.dev. Vendor PSIRT advisories are linked, not redistributed. Senserva is not affiliated with or endorsed by these providers.

For EU teams: vulnerabilities are cross-referenced to the ENISA EU Vulnerability Database (EUVD), the EU's official database under the NIS2 directive.

JSON and RSS feeds included, no login required. All feeds, the API, and quick-start examples.

How it is built

The feeds are pulled and rebuilt daily, then ranked: actively exploited (CISA KEV) first, then EPSS exploit probability and CVSS severity. Every KB and CVE gets its own linkable, cross-referenced page. Static and fast, with no account required.

From your own estate

These trackers cover the public picture. Senserva ranks the same data against the patches and CVEs actually present across your Microsoft 365, Intune, Defender, and Entra ID estate.

Patch and vulnerability tracker FAQ

Common questions about the free patch and vulnerability trackers and how the rankings work.

What is the Siemserva by Senserva patch and vulnerability tracker?

The patch and vulnerability tracker is a free, daily-refreshed hub that ranks Microsoft and open-source patches and CVEs by real-world risk: actively exploited (CISA KEV) first, then EPSS exploit probability and CVSS severity. It links the Microsoft patch tracker, Microsoft CVE and vulnerability management, the non-Microsoft exploited-CVE tracker, the open-source patch tracker, and the end-of-life tracker.

Is the patch and vulnerability tracker free?

Yes. Every tracker is free to use, with no sign-in and no telemetry. Running Senserva adds the part a public tracker cannot: which of these patches and CVEs are actually present on your own devices, ranked, so you fix the right things first.

How often is the patch and vulnerability data updated?

Daily. The trackers auto-refresh from Microsoft MSRC, NVD, CISA KEV, FIRST.org EPSS, OSV.dev, and other public feeds, so the counts, charts, and tables reflect the latest Patch Tuesday and the current exploitation signals.

What data sources does the tracker use?

Microsoft MSRC for Patch Tuesday KB-to-CVE data, NVD and CIRCL for CVSS, CISA KEV for actively-exploited status, FIRST.org EPSS for exploit probability, OSV.dev and the GitHub Advisory Database for open-source package fixes, plus VulnCheck KEV and the ENISA EUVD for broader exploitation signals.

How are patches and vulnerabilities ranked?

By what is actually exploited, not just severity. Actively-exploited CVEs (CISA KEV) rank first, then FIRST.org EPSS exploit probability, then CVSS severity. This surfaces the handful attackers are really using, a better fix-first order than CVSS alone.

How is this different from a CVE list or the MSRC Update Guide?

A CVE list tells you what is broken. These trackers rank every patch and CVE by real-world exploitation and tie each one to the fix, the KB for Microsoft or the package version for open source, so you know what to patch first and exactly how.

Which trackers are included?

The Microsoft patch tracker (Patch Tuesday KBs), Microsoft CVE and vulnerability management, the non-Microsoft exploited-CVE tracker (CISA KEV), the open-source patch tracker (package fixes), and the end-of-life tracker (out-of-support products).

Can I take this data to my own AI?

Yes. Every tracker includes a free copy-paste AI prompt generated from its live data each day, and this page has a cross-tracker prompt covering the whole landscape: Microsoft KBs, exploited CVEs, open-source fixes, and end-of-life dates, ready for Claude, ChatGPT, or Copilot.

Fixing what this tracker finds

These trackers show the public picture. The short walkthrough below shows the same ranking applied to your own tenant: which updates and CVEs are actually missing on your devices, fixed with approval.

Senserva patching for Microsoft 365

Open the watch page for this video, or read about Senserva patching.

Sponsored by Senserva

Siemserva by Senserva reports patch status for your own devices: which ones are missing the updates on this page, ranked by what attackers actually exploit.

  • Patch status in one scan: which devices are affected, which are not
  • Missing updates ranked by CISA KEV and EPSS, so you fix the right things first
  • Data from Intune, Microsoft Defender, Windows Autopatch, and Azure Update Manager, with more sources on the way
  • Third-party app patching too: updates published to Intune by PatchMyPC, Scappman, Robopack, or any vendor, read vendor-neutrally
  • Optional AI Enhanced Reporting: plain-language summaries and recommended next steps written into your reports
  • Then go further: 650+ security checks find the drift management gaps across Microsoft 365, Intune, Defender, and Entra ID, with compliance evidence and Senserva Trustworthy AI remediation
Senserva patching for Microsoft 365
Two minutes, click to play

Patching in action in two minutes. Watch page · All videos.

3 actively exploited CVEs are unmitigated on devices in this tenant, per CISA KEV.View fix-first list ↓
312
Devices scanned
Intune + Autopatch + Defender
3
Exploited updates missing
CISA KEV, unmitigated
905
Microsoft updates tracked
Refreshed daily, MSRC + NVD
650+
Security checks in scan
Patch, config, identity, logs

Triage order for this list

Same order in the dashboard, the report, and every AI answer
1st · overrides everything
Actively exploited (KEV)
e.g. KB5040219, CVE-2026-31210
2nd · tiebreaker
Severity (Critical → Low)
MSRC + EPSS probability
3rd · tiebreaker
Days waiting
Oldest unresolved first

Ranked missing updates, fix-first order

27 findings · showing top 2
#UpdateCVESeveritySourceDevicesWaiting
1KB5040219
Windows 11 23H2 cumulative
CVE-2026-31210
KEV EPSS 0.94
CriticalDefender4119 daysAdd to fix-first
2KB5040088
.NET Framework security update
CVE-2026-29981
KEV
CriticalIntune1712 daysAdd to fix-first
Estimated dashboard, sample data for illustration

Ask Senserva

via Claude + MCP
Which devices are still missing the fix for CVE-2026-31210?
41 devices are missing KB5040219, which resolves CVE-2026-31210. This CVE is on CISA KEV, so CISA BOD 22-01 calls for remediation within 14 days. You are at 19 days and counting.
source: scan_db · defender_posture · kev_join, not model memory
Get Devices Found Get Devices Missing
Senserva is a Microsoft Intelligent Security Association member. Get Going with Senserva Senserva patching Built for IT admins and security teams, with audit-ready data for compliance.

Reference: the Microsoft patching guide, how Intune, Windows Autopatch, Defender, and Azure Update Manager fit together, and where third-party patch vendors fit in.

Data notice: the trackers, feeds, and API are provided as is, for informational purposes only, without warranty of any kind. Senserva, LLC does not guarantee the accuracy, completeness, or timeliness of third-party data and accepts no liability for actions taken based on it; verify against the primary source before acting. All use of this data is subject to the Senserva EULA.