SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-10-02 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

400,783 CVEs1,731 in CISA KEV17,275 with EPSS ≥ 10%25,052 with a public exploitUpdated 2 October 2026

Known exploited — most recently added

All KEV entries →
CVESummaryPriorityPublished
CVE-2026-104286Fortinet FortiMail Path Traversal VulnerabilityKEVCRITICAL 9.8EPSS —1 October 2026
CVE-2026-76504Cisco Catalyst SD-WAN Manager Hex Encoding VulnerabilityKEVCRITICAL 9.8EPSS 1.10%30 September 2026
CVE-2026-86950Apple Multiple Products Out-of-Bounds Write VulnerabilityKEVHIGH 8.8EPSS 1.24%28 September 2026
CVE-2026-88771Citrix NetScaler Improper Input Validation VulnerabilityKEVCRITICAL 9.5EPSS 1.06%27 September 2026
CVE-2026-88772Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer VulnerabilityKEVCRITICAL 9.5EPSS 1.30%27 September 2026
CVE-2026-65660Microsoft SharePoint Code Injection VulnerabilityKEVHIGH 8.8EPSS 2.10%11 August 2026
CVE-2026-87902WordPress Core Remote File Inclusion VulnerabilityKEVEXPLOITHIGH 8.1EPSS 19.8%22 September 2026
CVE-2026-67279Mikrotik RouterOS Improper Enforcement of Behavioral Workflow VulnerabilityKEVMEDIUM 6.9EPSS 1.03%5 September 2026

Newest public exploits

All with a public exploit →
CVESummaryPriorityPublished
CVE-2026-100885A vulnerability was found in Krayin laravel-crm up to 2.2.4.EXPLOITMEDIUM 5.5EPSS 0.40%27 September 2026
CVE-2026-87902WordPress Core Remote File Inclusion VulnerabilityKEVEXPLOITHIGH 8.1EPSS 19.8%22 September 2026
CVE-2026-86060MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command VulnerabilityKEVEXPLOITCRITICAL 9.2EPSS 1.85%5 September 2026
CVE-2026-80428ILIAS before versions 9.22, 10.10, and 11.3 contains an unauthenticated PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting serialized objects through the LTI authentication endpoint and…EXPLOITCRITICAL 9.3EPSS 4.67%26 August 2026
CVE-2025-57819Sangoma FreePBX Authentication Bypass VulnerabilityKEVEXPLOITCRITICAL 10.0EPSS 85.5%28 August 2025
CVE-2026-59827Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4, Metabase instances with an H2 database connection, including the default sample database, deserialize arbitrary Java objects returned in H2 native query result columns of type OTHER without validation,…EXPLOITHIGH 8.8EPSS 3.79%9 July 2026
CVE-2026-39987Marimo Remote Code Execution VulnerabilityKEVEXPLOITCRITICAL 9.3EPSS 37.9%9 April 2026
CVE-2025-70336A Stored cross-site scripting (XSS) vulnerability in 'Create New Live Item' in PodcastGenerator 3.2.9 allows remote attackers to inject arbitrary script or HTML via the 'TITLE', 'SHORT DESCRIPTION' and 'LONG DESCRIPTION' parameters.EXPLOITMEDIUM 4.8EPSS 0.55%28 January 2026

Most likely to be exploited this month

All with EPSS ≥ 10% →
CVESummaryPriorityPublished
CVE-2024-7593Ivanti Virtual Traffic Manager Authentication Bypass VulnerabilityKEVCRITICAL 9.8EPSS 100.0%13 August 2024
CVE-2024-3400Palo Alto Networks PAN-OS Command Injection VulnerabilityKEVEXPLOITCRITICAL 10.0EPSS 100.0%12 April 2024
CVE-2024-23897Jenkins Command Line Interface (CLI) Path Traversal VulnerabilityKEVEXPLOITCRITICAL 9.8EPSS 100.0%24 January 2024
CVE-2024-21893Ivanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) VulnerabilityKEVHIGH 8.2EPSS 100.0%31 January 2024
CVE-2024-21887Ivanti Connect Secure and Policy Secure Command Injection VulnerabilityKEVCRITICAL 9.1EPSS 100.0%12 January 2024
CVE-2023-4966Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow VulnerabilityKEVHIGH 7.5EPSS 100.0%10 October 2023
CVE-2023-44487HTTP/2 Rapid Reset Attack VulnerabilityKEVEXPLOITHIGH 7.5EPSS 100.0%10 October 2023
CVE-2023-35082Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass VulnerabilityKEVCRITICAL 9.8EPSS 100.0%15 August 2023
CVESummaryPriorityPublished
CVE-2026-96289Uncontrolled Recursion vulnerability in Apache Thrift PHP bindings.HIGH 8.2EPSS —2 October 2026
CVE-2026-96287Inefficient Algorithmic Complexity vulnerability in Apache Thrift Perl bindings.HIGH 8.2EPSS —2 October 2026
CVE-2026-96286Uncaught exception vulnerability in Apache Thrift Perl bindings.HIGH 8.2EPSS —2 October 2026
CVE-2026-96277Uncaught exception, Improper Handling of Exceptional Conditions vulnerability in Apache Thrift Ruby bindings.HIGH 8.7EPSS —2 October 2026
CVE-2026-94658Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings.HIGH 8.7EPSS —2 October 2026
CVE-2026-94657Allocation of resources without limits or throttling vulnerability in Apache Thrift JavaME bindings.HIGH 8.2EPSS —2 October 2026
CVE-2026-94656Allocation of resources without limits or throttling vulnerability in Apache Thrift ruby bindings.HIGH 8.2EPSS —2 October 2026
CVE-2026-94655Allocation of resources without limits or throttling, Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings.HIGH 8.2EPSS —2 October 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.