CVE Tools

What's exploited and loud this week

Of the 150 CVEs on the radar, 28 are in CISA KEV and 15 are both exploited and loud in the news.

  • In CISA KEV28
  • Reported exploited3the news's claim
  • EPSS only119a probability, left half

Cell size is the week's stories · past 7 days · snapshot 12:30 UTC, Sep 27 · How it is read

Point at a cell, or focus the chart and use the arrow keys, to read a CVE.

Exploited and loudLoud, not exploitedNone this weekExploited, still quietQuiet, not exploitedNo coverage this week
Exploited and loudLoud, not exploitedNone this weekExploited, still quietQuiet, not exploitedNo coverage
CVEs on the radar this week, in act-now order
CVERegionExploitationCoverageEPSS
CVE-2026-85102Exploited and loudIn CISA KEV8 stories<1%
CVE-2026-93616Exploited and loudIn CISA KEV7 stories2%
CVE-2026-87902Exploited and loudIn CISA KEV10 stories3%
CVE-2026-7273Exploited and loudIn CISA KEV6 stories1%
CVE-2026-94127Exploited and loudIn CISA KEV6 stories1%
CVE-2026-93952Exploited and loudIn CISA KEV5 stories<1%
CVE-2026-76460Exploited and loudIn CISA KEV3 stories14%
CVE-2026-71362Exploited, still quietIn CISA KEV2 stories2%
CVE-2026-60137Exploited, still quietIn CISA KEV2 stories6%
CVE-2026-91843Exploited and loudReported exploited4 stories<1%
CVE-2025-49113Exploited and loudIn CISA KEV3 stories99%
CVE-2025-68461Exploited and loudIn CISA KEV3 stories27%
CVE-2026-48842Exploited and loudReported exploited3 stories<1%
CVE-2026-60004Exploited, still quietIn CISA KEV2 stories24%
CVE-2026-35273Exploited, still quietIn CISA KEV4 stories9%
CVE-2019-0221Quiet, not exploitedEPSS onlyno coverage59%
CVE-2026-63030Exploited, still quietIn CISA KEV2 stories10%
CVE-2026-65400Exploited, still quietIn CISA KEV1 story1%
CVE-2026-5430Exploited, still quietIn CISA KEV2 stories<1%
CVE-2026-85103Exploited and loudReported exploited3 stories4%
CVE-2026-67279Exploited, still quietIn CISA KEV3 stories<1%
CVE-2026-85046Exploited, still quietIn CISA KEV2 stories49%
CVE-2026-65660Exploited, still quietIn CISA KEVno coverage1%
CVE-2025-39682Exploited and loudIn CISA KEV3 stories3%
CVE-2025-39964Exploited and loudIn CISA KEV3 stories<1%
CVE-2026-53266Exploited and loudIn CISA KEV3 stories<1%
CVE-2015-7571Quiet, not exploitedEPSS onlyno coverage8%
CVE-2016-1839Quiet, not exploitedEPSS onlyno coverage7%
CVE-2018-11219Quiet, not exploitedEPSS onlyno coverage7%
CVE-2018-18955Quiet, not exploitedEPSS onlyno coverage8%
CVE-2018-4241Quiet, not exploitedEPSS onlyno coverage8%
CVE-2019-13574Quiet, not exploitedEPSS onlyno coverage8%
CVE-2019-5526Quiet, not exploitedEPSS onlyno coverage9%
CVE-2016-9813Quiet, not exploitedEPSS onlyno coverage8%
CVE-2017-9640Quiet, not exploitedEPSS onlyno coverage8%
CVE-2015-7241Quiet, not exploitedEPSS onlyno coverage13%
CVE-2015-8556Quiet, not exploitedEPSS onlyno coverage13%
CVE-2016-10277Quiet, not exploitedEPSS onlyno coverage10%
CVE-2016-10718Quiet, not exploitedEPSS onlyno coverage12%
CVE-2016-2335Quiet, not exploitedEPSS onlyno coverage10%
CVE-2016-8020Quiet, not exploitedEPSS onlyno coverage11%
CVE-2017-0785Quiet, not exploitedEPSS onlyno coverage12%
CVE-2017-17759Quiet, not exploitedEPSS onlyno coverage11%
CVE-2017-9675Quiet, not exploitedEPSS onlyno coverage12%
CVE-2017-9811Quiet, not exploitedEPSS onlyno coverage10%
CVE-2017-9812Quiet, not exploitedEPSS onlyno coverage11%
CVE-2017-9872Quiet, not exploitedEPSS onlyno coverage10%
CVE-2018-1002202Quiet, not exploitedEPSS onlyno coverage11%
CVE-2018-15685Quiet, not exploitedEPSS onlyno coverage10%
CVE-2018-17961Quiet, not exploitedEPSS onlyno coverage10%
CVE-2018-19475Quiet, not exploitedEPSS onlyno coverage10%
CVE-2018-19788Quiet, not exploitedEPSS onlyno coverage11%
CVE-2018-5724Quiet, not exploitedEPSS onlyno coverage12%
CVE-2018-6911Quiet, not exploitedEPSS onlyno coverage13%
CVE-2019-0612Quiet, not exploitedEPSS onlyno coverage11%
CVE-2019-7298Quiet, not exploitedEPSS onlyno coverage10%
CVE-2014-7279Quiet, not exploitedEPSS onlyno coverage12%
CVE-2018-6092Quiet, not exploitedEPSS onlyno coverage9%
CVE-2018-6229Quiet, not exploitedEPSS onlyno coverage10%
CVE-2019-7297Quiet, not exploitedEPSS onlyno coverage12%
CVE-2026-16812Exploited, still quietIn CISA KEV2 stories1%
CVE-2016-3132Quiet, not exploitedEPSS onlyno coverage12%
CVE-2017-14084Quiet, not exploitedEPSS onlyno coverage10%
CVE-2017-15806Quiet, not exploitedEPSS onlyno coverage11%
CVE-2017-3546Quiet, not exploitedEPSS onlyno coverage10%
CVE-2018-19862Quiet, not exploitedEPSS onlyno coverage13%
CVE-2018-6223Quiet, not exploitedEPSS onlyno coverage10%
CVE-2018-7254Quiet, not exploitedEPSS onlyno coverage10%
CVE-2015-8865Quiet, not exploitedEPSS onlyno coverage5%
CVE-2016-0199Quiet, not exploitedEPSS onlyno coverage51%
CVE-2016-3288Quiet, not exploitedEPSS onlyno coverage52%
CVE-2016-3303Quiet, not exploitedEPSS onlyno coverage51%
CVE-2016-3304Quiet, not exploitedEPSS onlyno coverage51%
CVE-2016-3357Quiet, not exploitedEPSS onlyno coverage55%
CVE-2016-4264Quiet, not exploitedEPSS onlyno coverage69%
CVE-2016-4543Quiet, not exploitedEPSS onlyno coverage12%
CVE-2016-6515Quiet, not exploitedEPSS onlyno coverage59%
CVE-2016-6603Quiet, not exploitedEPSS onlyno coverage87%
CVE-2016-7547Quiet, not exploitedEPSS onlyno coverage93%
CVE-2017-11153Quiet, not exploitedEPSS onlyno coverage12%
CVE-2017-11810Quiet, not exploitedEPSS onlyno coverage55%
CVE-2017-11839Quiet, not exploitedEPSS onlyno coverage62%
CVE-2017-11840Quiet, not exploitedEPSS onlyno coverage60%
CVE-2017-11841Quiet, not exploitedEPSS onlyno coverage60%
CVE-2017-11861Quiet, not exploitedEPSS onlyno coverage64%
CVE-2017-11890Quiet, not exploitedEPSS onlyno coverage50%
CVE-2017-17932Quiet, not exploitedEPSS onlyno coverage54%
CVE-2017-3730Quiet, not exploitedEPSS onlyno coverage55%
CVE-2017-6361Quiet, not exploitedEPSS onlyno coverage57%
CVE-2017-6526Quiet, not exploitedEPSS onlyno coverage57%
CVE-2017-8487Quiet, not exploitedEPSS onlyno coverage54%
CVE-2017-8496Quiet, not exploitedEPSS onlyno coverage51%
CVE-2017-8594Quiet, not exploitedEPSS onlyno coverage50%
CVE-2017-8618Quiet, not exploitedEPSS onlyno coverage58%
CVE-2017-8734Quiet, not exploitedEPSS onlyno coverage53%
CVE-2017-8751Quiet, not exploitedEPSS onlyno coverage50%
CVE-2018-0946Quiet, not exploitedEPSS onlyno coverage52%
CVE-2018-19300Quiet, not exploitedEPSS onlyno coverage74%
CVE-2018-7297Quiet, not exploitedEPSS onlyno coverage64%
CVE-2018-7756Quiet, not exploitedEPSS onlyno coverage61%
CVE-2018-8133Quiet, not exploitedEPSS onlyno coverage51%
CVE-2018-8474Quiet, not exploitedEPSS onlyno coverage38%
CVE-2018-8495Quiet, not exploitedEPSS onlyno coverage51%
CVE-2019-9020Quiet, not exploitedEPSS onlyno coverage10%
CVE-2014-1889Quiet, not exploitedEPSS onlyno coverage10%
CVE-2022-0847Exploited, still quietIn CISA KEV1 story93%
CVE-2016-9796Quiet, not exploitedEPSS onlyno coverage13%
CVE-2017-7461Quiet, not exploitedEPSS onlyno coverage11%
CVE-2018-1002203Quiet, not exploitedEPSS onlyno coverage11%
CVE-2018-11492Quiet, not exploitedEPSS onlyno coverage11%
CVE-2018-19042Quiet, not exploitedEPSS onlyno coverage10%
CVE-2016-4340Quiet, not exploitedEPSS onlyno coverage10%
CVE-2016-6599Quiet, not exploitedEPSS onlyno coverage12%
CVE-2018-20555Quiet, not exploitedEPSS onlyno coverage10%
CVE-2018-5319Quiet, not exploitedEPSS onlyno coverage12%
CVE-2018-6397Quiet, not exploitedEPSS onlyno coverage12%
CVE-2017-5674Quiet, not exploitedEPSS onlyno coverage22%
CVE-2017-11914Quiet, not exploitedEPSS onlyno coverage63%
CVE-2018-3924Quiet, not exploitedEPSS onlyno coverage44%
CVE-2018-8552Quiet, not exploitedEPSS onlyno coverage51%
CVE-2014-8675Quiet, not exploitedEPSS onlyno coverage13%
CVE-2026-58644Exploited, still quietIn CISA KEVno coverage16%
CVE-2017-6558Quiet, not exploitedEPSS onlyno coverage15%
CVE-2018-2879Quiet, not exploitedEPSS onlyno coverage22%
CVE-2015-8279Quiet, not exploitedEPSS onlyno coverage51%
CVE-2017-16720Quiet, not exploitedEPSS onlyno coverage50%
CVE-2018-8831Quiet, not exploitedEPSS onlyno coverage53%
CVE-2019-3964Quiet, not exploitedEPSS onlyno coverage53%
CVE-2021-44026Exploited, still quietIn CISA KEV1 story70%
CVE-2026-63077Exploited, still quietIn CISA KEV1 story10%
CVE-2025-32794Quiet, not exploitedEPSS onlyno coverage10%
CVE-2026-31431Exploited, still quietIn CISA KEV1 story3%
CVE-2015-7246Quiet, not exploitedEPSS onlyno coverage14%
CVE-2017-3241Quiet, not exploitedEPSS onlyno coverage33%
CVE-2018-11714Quiet, not exploitedEPSS onlyno coverage68%
CVE-2018-14665Quiet, not exploitedEPSS onlyno coverage27%
CVE-2018-18284Quiet, not exploitedEPSS onlyno coverage16%
CVE-2018-20251Quiet, not exploitedEPSS onlyno coverage32%
CVE-2019-0768Quiet, not exploitedEPSS onlyno coverage49%
CVE-2016-2226Quiet, not exploitedEPSS onlyno coverage7%
CVE-2017-0569Quiet, not exploitedEPSS onlyno coverage8%
CVE-2017-10952Quiet, not exploitedEPSS onlyno coverage7%
CVE-2017-6193Quiet, not exploitedEPSS onlyno coverage8%
CVE-2017-8311Quiet, not exploitedEPSS onlyno coverage9%
CVE-2017-9742Quiet, not exploitedEPSS onlyno coverage8%
CVE-2017-9746Quiet, not exploitedEPSS onlyno coverage9%
CVE-2017-9747Quiet, not exploitedEPSS onlyno coverage8%
CVE-2017-9750Quiet, not exploitedEPSS onlyno coverage8%
CVE-2018-4087Quiet, not exploitedEPSS onlyno coverage7%
CVE-2018-4200Quiet, not exploitedEPSS onlyno coverage9%

Act now ranked by threat score

  1. 1CVE-2026-85102Improper Certificate Validation in Quantum Security GatewayIn CISA KEV · in the news for exploitation8 storiesEPSS <1%
  2. 2CVE-2026-93616Directory Traversal and File upload allows execution of arbitrary script on the Management ServerIn CISA KEV · in the news for exploitation · new this week7 storiesEPSS 2%
  3. 3CVE-2026-87902An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for ...In CISA KEV · in the news for exploitation · new this week10 storiesEPSS 3%
  4. 4CVE-2026-7273A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw...In CISA KEV · in the news for incident · Red Heron6 storiesEPSS 1%
  5. 5CVE-2026-94127BIG-IP APM OAuth vulnerabilityIn CISA KEV · in the news for research · new this week6 storiesEPSS 1%
  6. 6CVE-2026-93952Security Advisory 0183In CISA KEV · in the news for patch · new this week5 storiesEPSS <1%
  7. 7CVE-2026-76460Cisco Identity Services Engine Authentication Bypass VulnerabilityIn CISA KEV · in the news for exploitation · WaterPlum3 storiesEPSS 14%
  8. 8CVE-2026-71362Adobe Commerce | Incorrect Authorization (CWE-863)In CISA KEV · in the news for exploitation2 storiesEPSS 2%
  9. 9CVE-2026-60137WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_QueryIn CISA KEV · in the news for incident · Red Heron2 storiesEPSS 6%
  10. 10CVE-2026-91843Stack overflow in login process to the Security Management and Log ServersReported exploited · in the news for exploitation · WaterPlum4 storiesEPSS <1%

Exploited, still quiet

16 CVEs this week stand on the exploited side with little or no coverage. These are in CISA KEV or reported exploited, and the press has not caught up with them; patch queues often haven't either.

  1. 1CVE-2022-0847A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thu...In CISA KEV · in the news for incident · Red Heron1 storyEPSS 93%
  2. 2CVE-2021-44026Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.In CISA KEV · in the news for exploitation · Winter Vivern1 storyEPSS 70%
  3. 3CVE-2026-85046Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)In CISA KEV · in the news for exploitation · UTA05652 storiesEPSS 49%
  4. 4CVE-2026-60004Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.In CISA KEV · in the news for incident · Red Heron2 storiesEPSS 24%
  5. 5CVE-2026-58644Microsoft SharePoint Remote Code Execution VulnerabilityIn CISA KEVno coverageEPSS 16%
  6. 6CVE-2026-63030WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code ExecutionIn CISA KEV · in the news for incident · Red Heron2 storiesEPSS 10%
  7. 7CVE-2026-63077In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocolIn CISA KEV · in the news for exploitation1 storyEPSS 10%
  8. 8CVE-2026-35273Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily explo...In CISA KEV · in the news for incident · ShinyHunters4 storiesEPSS 9%

How the radar is read

Coverage, up
How loud the security press is about the CVE. Every story counts, secondary outlets count less than primary sources, and every mention fades with a 7-day half-life. Plotted as a percentile among the CVEs on the radar that have any coverage: halfway up means louder than half of them. CVEs no one wrote about sit in the hatched strip at the base; they are here for their exploitation alone.
Exploitation, across
How real the exploitation is, not only how likely. From the right: in CISA KEV (confirmed exploited, the one fact in magenta), exploitation reported by the news, a public PoC reported by the news, and otherwise the EPSS probability. The key and the axis show only the steps present this week. Within a step, cells spread across a band so they don't stack: higher EPSS leans right, the rest is only spacing. A CVE with EPSS alone is never counted as exploited, however likely: it sits on the left half, on a square-root scale so the many low values stay apart. A cell's colour is its level: magenta for KEV, the ramp for EPSS, which never reaches magenta.
Held back for now
The exploit flag in CVE records counts vendor statements such as "not aware of any public exploit" as exploits, so it places no cell until that data is fixed. A PoC counts only when the news reports one.
What makes the radar
About 70% of the cells are CVEs in the news; the rest are the most exploited of everything else, including ones nobody is writing about yet. Replaying July and August, news coverage and reported exploitation were the strongest early signals: this selection caught about 7 in 10 of the CVEs CISA added to KEV the following month.
Act-now order
The fused threat score: a weighted sum of signals, each fading over time. Exploitation weighs most and fades slowly (a KEV listing and reported exploitation ×3, a first exploit or Metasploit module ×2, a PoC, scanner template or EPSS jump ×1; 90-day half-life). News attention (7 days) and interest on cve.tools, meaning views, searches and explainer requests (14 days) and watches (30 days), add on top.

Only what you run

The same radar, filtered by sector, vendor or the products in your stack.

Sign in to filter by your stack

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store