What's exploited and loud this week
Of the 150 CVEs on the radar, 28 are in CISA KEV and 15 are both exploited and loud in the news.
- In CISA KEV28
- Reported exploited3the news's claim
- EPSS only119a probability, left half
Cell size is the week's stories · past 7 days · snapshot 12:30 UTC, Sep 27 · How it is read
Point at a cell, or focus the chart and use the arrow keys, to read a CVE.
Exploited and loudLoud, not exploitedNone this weekExploited, still quietQuiet, not exploitedNo coverage this week
Exploited and loudLoud, not exploitedNone this weekExploited, still quietQuiet, not exploitedNo coverage
| CVE | Region | Exploitation | Coverage | EPSS |
|---|---|---|---|---|
| CVE-2026-85102 | Exploited and loud | In CISA KEV | 8 stories | <1% |
| CVE-2026-93616 | Exploited and loud | In CISA KEV | 7 stories | 2% |
| CVE-2026-87902 | Exploited and loud | In CISA KEV | 10 stories | 3% |
| CVE-2026-7273 | Exploited and loud | In CISA KEV | 6 stories | 1% |
| CVE-2026-94127 | Exploited and loud | In CISA KEV | 6 stories | 1% |
| CVE-2026-93952 | Exploited and loud | In CISA KEV | 5 stories | <1% |
| CVE-2026-76460 | Exploited and loud | In CISA KEV | 3 stories | 14% |
| CVE-2026-71362 | Exploited, still quiet | In CISA KEV | 2 stories | 2% |
| CVE-2026-60137 | Exploited, still quiet | In CISA KEV | 2 stories | 6% |
| CVE-2026-91843 | Exploited and loud | Reported exploited | 4 stories | <1% |
| CVE-2025-49113 | Exploited and loud | In CISA KEV | 3 stories | 99% |
| CVE-2025-68461 | Exploited and loud | In CISA KEV | 3 stories | 27% |
| CVE-2026-48842 | Exploited and loud | Reported exploited | 3 stories | <1% |
| CVE-2026-60004 | Exploited, still quiet | In CISA KEV | 2 stories | 24% |
| CVE-2026-35273 | Exploited, still quiet | In CISA KEV | 4 stories | 9% |
| CVE-2019-0221 | Quiet, not exploited | EPSS only | no coverage | 59% |
| CVE-2026-63030 | Exploited, still quiet | In CISA KEV | 2 stories | 10% |
| CVE-2026-65400 | Exploited, still quiet | In CISA KEV | 1 story | 1% |
| CVE-2026-5430 | Exploited, still quiet | In CISA KEV | 2 stories | <1% |
| CVE-2026-85103 | Exploited and loud | Reported exploited | 3 stories | 4% |
| CVE-2026-67279 | Exploited, still quiet | In CISA KEV | 3 stories | <1% |
| CVE-2026-85046 | Exploited, still quiet | In CISA KEV | 2 stories | 49% |
| CVE-2026-65660 | Exploited, still quiet | In CISA KEV | no coverage | 1% |
| CVE-2025-39682 | Exploited and loud | In CISA KEV | 3 stories | 3% |
| CVE-2025-39964 | Exploited and loud | In CISA KEV | 3 stories | <1% |
| CVE-2026-53266 | Exploited and loud | In CISA KEV | 3 stories | <1% |
| CVE-2015-7571 | Quiet, not exploited | EPSS only | no coverage | 8% |
| CVE-2016-1839 | Quiet, not exploited | EPSS only | no coverage | 7% |
| CVE-2018-11219 | Quiet, not exploited | EPSS only | no coverage | 7% |
| CVE-2018-18955 | Quiet, not exploited | EPSS only | no coverage | 8% |
| CVE-2018-4241 | Quiet, not exploited | EPSS only | no coverage | 8% |
| CVE-2019-13574 | Quiet, not exploited | EPSS only | no coverage | 8% |
| CVE-2019-5526 | Quiet, not exploited | EPSS only | no coverage | 9% |
| CVE-2016-9813 | Quiet, not exploited | EPSS only | no coverage | 8% |
| CVE-2017-9640 | Quiet, not exploited | EPSS only | no coverage | 8% |
| CVE-2015-7241 | Quiet, not exploited | EPSS only | no coverage | 13% |
| CVE-2015-8556 | Quiet, not exploited | EPSS only | no coverage | 13% |
| CVE-2016-10277 | Quiet, not exploited | EPSS only | no coverage | 10% |
| CVE-2016-10718 | Quiet, not exploited | EPSS only | no coverage | 12% |
| CVE-2016-2335 | Quiet, not exploited | EPSS only | no coverage | 10% |
| CVE-2016-8020 | Quiet, not exploited | EPSS only | no coverage | 11% |
| CVE-2017-0785 | Quiet, not exploited | EPSS only | no coverage | 12% |
| CVE-2017-17759 | Quiet, not exploited | EPSS only | no coverage | 11% |
| CVE-2017-9675 | Quiet, not exploited | EPSS only | no coverage | 12% |
| CVE-2017-9811 | Quiet, not exploited | EPSS only | no coverage | 10% |
| CVE-2017-9812 | Quiet, not exploited | EPSS only | no coverage | 11% |
| CVE-2017-9872 | Quiet, not exploited | EPSS only | no coverage | 10% |
| CVE-2018-1002202 | Quiet, not exploited | EPSS only | no coverage | 11% |
| CVE-2018-15685 | Quiet, not exploited | EPSS only | no coverage | 10% |
| CVE-2018-17961 | Quiet, not exploited | EPSS only | no coverage | 10% |
| CVE-2018-19475 | Quiet, not exploited | EPSS only | no coverage | 10% |
| CVE-2018-19788 | Quiet, not exploited | EPSS only | no coverage | 11% |
| CVE-2018-5724 | Quiet, not exploited | EPSS only | no coverage | 12% |
| CVE-2018-6911 | Quiet, not exploited | EPSS only | no coverage | 13% |
| CVE-2019-0612 | Quiet, not exploited | EPSS only | no coverage | 11% |
| CVE-2019-7298 | Quiet, not exploited | EPSS only | no coverage | 10% |
| CVE-2014-7279 | Quiet, not exploited | EPSS only | no coverage | 12% |
| CVE-2018-6092 | Quiet, not exploited | EPSS only | no coverage | 9% |
| CVE-2018-6229 | Quiet, not exploited | EPSS only | no coverage | 10% |
| CVE-2019-7297 | Quiet, not exploited | EPSS only | no coverage | 12% |
| CVE-2026-16812 | Exploited, still quiet | In CISA KEV | 2 stories | 1% |
| CVE-2016-3132 | Quiet, not exploited | EPSS only | no coverage | 12% |
| CVE-2017-14084 | Quiet, not exploited | EPSS only | no coverage | 10% |
| CVE-2017-15806 | Quiet, not exploited | EPSS only | no coverage | 11% |
| CVE-2017-3546 | Quiet, not exploited | EPSS only | no coverage | 10% |
| CVE-2018-19862 | Quiet, not exploited | EPSS only | no coverage | 13% |
| CVE-2018-6223 | Quiet, not exploited | EPSS only | no coverage | 10% |
| CVE-2018-7254 | Quiet, not exploited | EPSS only | no coverage | 10% |
| CVE-2015-8865 | Quiet, not exploited | EPSS only | no coverage | 5% |
| CVE-2016-0199 | Quiet, not exploited | EPSS only | no coverage | 51% |
| CVE-2016-3288 | Quiet, not exploited | EPSS only | no coverage | 52% |
| CVE-2016-3303 | Quiet, not exploited | EPSS only | no coverage | 51% |
| CVE-2016-3304 | Quiet, not exploited | EPSS only | no coverage | 51% |
| CVE-2016-3357 | Quiet, not exploited | EPSS only | no coverage | 55% |
| CVE-2016-4264 | Quiet, not exploited | EPSS only | no coverage | 69% |
| CVE-2016-4543 | Quiet, not exploited | EPSS only | no coverage | 12% |
| CVE-2016-6515 | Quiet, not exploited | EPSS only | no coverage | 59% |
| CVE-2016-6603 | Quiet, not exploited | EPSS only | no coverage | 87% |
| CVE-2016-7547 | Quiet, not exploited | EPSS only | no coverage | 93% |
| CVE-2017-11153 | Quiet, not exploited | EPSS only | no coverage | 12% |
| CVE-2017-11810 | Quiet, not exploited | EPSS only | no coverage | 55% |
| CVE-2017-11839 | Quiet, not exploited | EPSS only | no coverage | 62% |
| CVE-2017-11840 | Quiet, not exploited | EPSS only | no coverage | 60% |
| CVE-2017-11841 | Quiet, not exploited | EPSS only | no coverage | 60% |
| CVE-2017-11861 | Quiet, not exploited | EPSS only | no coverage | 64% |
| CVE-2017-11890 | Quiet, not exploited | EPSS only | no coverage | 50% |
| CVE-2017-17932 | Quiet, not exploited | EPSS only | no coverage | 54% |
| CVE-2017-3730 | Quiet, not exploited | EPSS only | no coverage | 55% |
| CVE-2017-6361 | Quiet, not exploited | EPSS only | no coverage | 57% |
| CVE-2017-6526 | Quiet, not exploited | EPSS only | no coverage | 57% |
| CVE-2017-8487 | Quiet, not exploited | EPSS only | no coverage | 54% |
| CVE-2017-8496 | Quiet, not exploited | EPSS only | no coverage | 51% |
| CVE-2017-8594 | Quiet, not exploited | EPSS only | no coverage | 50% |
| CVE-2017-8618 | Quiet, not exploited | EPSS only | no coverage | 58% |
| CVE-2017-8734 | Quiet, not exploited | EPSS only | no coverage | 53% |
| CVE-2017-8751 | Quiet, not exploited | EPSS only | no coverage | 50% |
| CVE-2018-0946 | Quiet, not exploited | EPSS only | no coverage | 52% |
| CVE-2018-19300 | Quiet, not exploited | EPSS only | no coverage | 74% |
| CVE-2018-7297 | Quiet, not exploited | EPSS only | no coverage | 64% |
| CVE-2018-7756 | Quiet, not exploited | EPSS only | no coverage | 61% |
| CVE-2018-8133 | Quiet, not exploited | EPSS only | no coverage | 51% |
| CVE-2018-8474 | Quiet, not exploited | EPSS only | no coverage | 38% |
| CVE-2018-8495 | Quiet, not exploited | EPSS only | no coverage | 51% |
| CVE-2019-9020 | Quiet, not exploited | EPSS only | no coverage | 10% |
| CVE-2014-1889 | Quiet, not exploited | EPSS only | no coverage | 10% |
| CVE-2022-0847 | Exploited, still quiet | In CISA KEV | 1 story | 93% |
| CVE-2016-9796 | Quiet, not exploited | EPSS only | no coverage | 13% |
| CVE-2017-7461 | Quiet, not exploited | EPSS only | no coverage | 11% |
| CVE-2018-1002203 | Quiet, not exploited | EPSS only | no coverage | 11% |
| CVE-2018-11492 | Quiet, not exploited | EPSS only | no coverage | 11% |
| CVE-2018-19042 | Quiet, not exploited | EPSS only | no coverage | 10% |
| CVE-2016-4340 | Quiet, not exploited | EPSS only | no coverage | 10% |
| CVE-2016-6599 | Quiet, not exploited | EPSS only | no coverage | 12% |
| CVE-2018-20555 | Quiet, not exploited | EPSS only | no coverage | 10% |
| CVE-2018-5319 | Quiet, not exploited | EPSS only | no coverage | 12% |
| CVE-2018-6397 | Quiet, not exploited | EPSS only | no coverage | 12% |
| CVE-2017-5674 | Quiet, not exploited | EPSS only | no coverage | 22% |
| CVE-2017-11914 | Quiet, not exploited | EPSS only | no coverage | 63% |
| CVE-2018-3924 | Quiet, not exploited | EPSS only | no coverage | 44% |
| CVE-2018-8552 | Quiet, not exploited | EPSS only | no coverage | 51% |
| CVE-2014-8675 | Quiet, not exploited | EPSS only | no coverage | 13% |
| CVE-2026-58644 | Exploited, still quiet | In CISA KEV | no coverage | 16% |
| CVE-2017-6558 | Quiet, not exploited | EPSS only | no coverage | 15% |
| CVE-2018-2879 | Quiet, not exploited | EPSS only | no coverage | 22% |
| CVE-2015-8279 | Quiet, not exploited | EPSS only | no coverage | 51% |
| CVE-2017-16720 | Quiet, not exploited | EPSS only | no coverage | 50% |
| CVE-2018-8831 | Quiet, not exploited | EPSS only | no coverage | 53% |
| CVE-2019-3964 | Quiet, not exploited | EPSS only | no coverage | 53% |
| CVE-2021-44026 | Exploited, still quiet | In CISA KEV | 1 story | 70% |
| CVE-2026-63077 | Exploited, still quiet | In CISA KEV | 1 story | 10% |
| CVE-2025-32794 | Quiet, not exploited | EPSS only | no coverage | 10% |
| CVE-2026-31431 | Exploited, still quiet | In CISA KEV | 1 story | 3% |
| CVE-2015-7246 | Quiet, not exploited | EPSS only | no coverage | 14% |
| CVE-2017-3241 | Quiet, not exploited | EPSS only | no coverage | 33% |
| CVE-2018-11714 | Quiet, not exploited | EPSS only | no coverage | 68% |
| CVE-2018-14665 | Quiet, not exploited | EPSS only | no coverage | 27% |
| CVE-2018-18284 | Quiet, not exploited | EPSS only | no coverage | 16% |
| CVE-2018-20251 | Quiet, not exploited | EPSS only | no coverage | 32% |
| CVE-2019-0768 | Quiet, not exploited | EPSS only | no coverage | 49% |
| CVE-2016-2226 | Quiet, not exploited | EPSS only | no coverage | 7% |
| CVE-2017-0569 | Quiet, not exploited | EPSS only | no coverage | 8% |
| CVE-2017-10952 | Quiet, not exploited | EPSS only | no coverage | 7% |
| CVE-2017-6193 | Quiet, not exploited | EPSS only | no coverage | 8% |
| CVE-2017-8311 | Quiet, not exploited | EPSS only | no coverage | 9% |
| CVE-2017-9742 | Quiet, not exploited | EPSS only | no coverage | 8% |
| CVE-2017-9746 | Quiet, not exploited | EPSS only | no coverage | 9% |
| CVE-2017-9747 | Quiet, not exploited | EPSS only | no coverage | 8% |
| CVE-2017-9750 | Quiet, not exploited | EPSS only | no coverage | 8% |
| CVE-2018-4087 | Quiet, not exploited | EPSS only | no coverage | 7% |
| CVE-2018-4200 | Quiet, not exploited | EPSS only | no coverage | 9% |
Act now ranked by threat score
- 1CVE-2026-85102Improper Certificate Validation in Quantum Security GatewayIn CISA KEV · in the news for exploitation8 storiesEPSS <1%
- 2CVE-2026-93616Directory Traversal and File upload allows execution of arbitrary script on the Management ServerIn CISA KEV · in the news for exploitation · new this week7 storiesEPSS 2%
- 3CVE-2026-87902An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for ...In CISA KEV · in the news for exploitation · new this week10 storiesEPSS 3%
- 4CVE-2026-7273A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw...In CISA KEV · in the news for incident · Red Heron6 storiesEPSS 1%
- 5CVE-2026-94127BIG-IP APM OAuth vulnerabilityIn CISA KEV · in the news for research · new this week6 storiesEPSS 1%
- 6CVE-2026-93952Security Advisory 0183In CISA KEV · in the news for patch · new this week5 storiesEPSS <1%
- 7CVE-2026-76460Cisco Identity Services Engine Authentication Bypass VulnerabilityIn CISA KEV · in the news for exploitation · WaterPlum3 storiesEPSS 14%
- 8CVE-2026-71362Adobe Commerce | Incorrect Authorization (CWE-863)In CISA KEV · in the news for exploitation2 storiesEPSS 2%
- 9CVE-2026-60137WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_QueryIn CISA KEV · in the news for incident · Red Heron2 storiesEPSS 6%
- 10CVE-2026-91843Stack overflow in login process to the Security Management and Log ServersReported exploited · in the news for exploitation · WaterPlum4 storiesEPSS <1%
Exploited, still quiet
16 CVEs this week stand on the exploited side with little or no coverage. These are in CISA KEV or reported exploited, and the press has not caught up with them; patch queues often haven't either.
- 1CVE-2022-0847A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thu...In CISA KEV · in the news for incident · Red Heron1 storyEPSS 93%
- 2CVE-2021-44026Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.In CISA KEV · in the news for exploitation · Winter Vivern1 storyEPSS 70%
- 3CVE-2026-85046Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)In CISA KEV · in the news for exploitation · UTA05652 storiesEPSS 49%
- 4CVE-2026-60004Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.In CISA KEV · in the news for incident · Red Heron2 storiesEPSS 24%
- 5CVE-2026-58644Microsoft SharePoint Remote Code Execution VulnerabilityIn CISA KEVno coverageEPSS 16%
- 6CVE-2026-63030WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code ExecutionIn CISA KEV · in the news for incident · Red Heron2 storiesEPSS 10%
- 7CVE-2026-63077In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocolIn CISA KEV · in the news for exploitation1 storyEPSS 10%
- 8CVE-2026-35273Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily explo...In CISA KEV · in the news for incident · ShinyHunters4 storiesEPSS 9%
How the radar is read
- Coverage, up
- How loud the security press is about the CVE. Every story counts, secondary outlets count less than primary sources, and every mention fades with a 7-day half-life. Plotted as a percentile among the CVEs on the radar that have any coverage: halfway up means louder than half of them. CVEs no one wrote about sit in the hatched strip at the base; they are here for their exploitation alone.
- Exploitation, across
- How real the exploitation is, not only how likely. From the right: in CISA KEV (confirmed exploited, the one fact in magenta), exploitation reported by the news, a public PoC reported by the news, and otherwise the EPSS probability. The key and the axis show only the steps present this week. Within a step, cells spread across a band so they don't stack: higher EPSS leans right, the rest is only spacing. A CVE with EPSS alone is never counted as exploited, however likely: it sits on the left half, on a square-root scale so the many low values stay apart. A cell's colour is its level: magenta for KEV, the ramp for EPSS, which never reaches magenta.
- Held back for now
- The exploit flag in CVE records counts vendor statements such as "not aware of any public exploit" as exploits, so it places no cell until that data is fixed. A PoC counts only when the news reports one.
- What makes the radar
- About 70% of the cells are CVEs in the news; the rest are the most exploited of everything else, including ones nobody is writing about yet. Replaying July and August, news coverage and reported exploitation were the strongest early signals: this selection caught about 7 in 10 of the CVEs CISA added to KEV the following month.
- Act-now order
- The fused threat score: a weighted sum of signals, each fading over time. Exploitation weighs most and fades slowly (a KEV listing and reported exploitation ×3, a first exploit or Metasploit module ×2, a PoC, scanner template or EPSS jump ×1; 90-day half-life). News attention (7 days) and interest on cve.tools, meaning views, searches and explainer requests (14 days) and watches (30 days), add on top.
Only what you run
The same radar, filtered by sector, vendor or the products in your stack.
Sign in to filter by your stack