<\/head>

Threat and Exploit Intelligence Analytics

Deep insights into vulnerability landscape, exploitation trends and risk metrics.

Vulnerability Funnel

From NVD publication to confirmed exploitation

Year in progress — partial data
NVD Published
Monitored
EPSS > 10%
Exploited in Wild
TTE ≤ 5 days
Zero-Day
50,987 151 91 151 91 74
0.3%
60.3%
165.9%
60.3%
81.3%

Daily Monitoring Flow

CVEs added vs removed from monitoring (last 90 days)

CVE Distribution by Year

Severity breakdown across tracked years
913
Monitored CVEs
+20.0% vs last 30d
8.7
Avg CVSS Score
Across all active CVEs
871
Exploited in Wild
95.4% of monitored CVEs confirmed exploited
1d
Mean Time to Weaponize
Avg days from publish to first PoC/exploit (outliers removed)
78d
Mean Time to Exploit
Avg days from publish to confirmed exploitation (outliers removed)

Exploitation Timing by Severity

Fastest and average time-to-exploit/weaponize per severity level (outliers removed via IQR)
CRITICAL (318 CVEs)
-49.7d Fastest
-0.6d Median
73d Avg Exploit
0d Avg PoC
190 Zero-Day
HIGH (181 CVEs)
-117.0d Fastest
0.3d Median
84d Avg Exploit
5d Avg PoC
84 Zero-Day
Global Timing
-117.0d Fastest
-0.5d Median
78d Avg Exploit
1d Avg PoC
Zero-Day (55.3% of 532 with TTE)
294 Total
190 Critical
84 High
5-Day Window
300 Exploited (35.6%)
366 With PoC (68.8%)

Threat Overlap

Intersection of KEV, Exploits and High EPSS
229 21 0 133 99 1 410 KEV (871) Exploit (565) EPSS >50% (510)

CVE Timeline (90d)

EPSS Distribution

Top CWE Categories

Most Dangerous CVEs

Ranked by composite score (CVSS x EPSS x KEV x Exploit)
CVE-ID Severity CVSS EPSS Score
CVE-2024-3400 KEV EXP CRITICAL 10 100.0% 60.0
CVE-2021-44228 KEV EXP CRITICAL 10 100.0% 60.0
CVE-2024-1709 KEV EXP CRITICAL 10 100.0% 59.99
CVE-2025-32432 KEV EXP CRITICAL 10 99.8% 59.95
CVE-2025-55182 KEV EXP CRITICAL 10 99.8% 59.94
CVE-2020-0796 KEV EXP CRITICAL 10 99.8% 59.94
CVE-2021-22205 KEV EXP CRITICAL 10 99.7% 59.92
CVE-2023-20198 KEV EXP CRITICAL 10 99.6% 59.87
CVE-2024-4040 KEV EXP CRITICAL 10 99.5% 59.86
CVE-2022-0543 KEV EXP CRITICAL 10 99.4% 59.81

Vendor Exposure

Vendor CVEs Avg CVSS Exposure
Microsoft 100 8.0
11.0%
Google 62 8.8
6.8%
Apple 44 8.5
4.8%
Cisco 38 8.3
4.2%
Ivanti 33 8.6
3.6%
Apache 26 9.3
2.8%
Vmware 22 8.9
2.4%
Oracle 22 9.1
2.4%
Fortinet 21 9.4
2.3%
Sonicwall 15 8.4
1.6%

EPSS Movers

Biggest EPSS increases in the last 7 days
CVE-ID Previous Current Change
CVE-2026-63077 0.6% 87.70% +87.06%
CVE-2026-72898 0.7% 79.20% +78.53%
CVE-2026-45659 9.1% 76.10% +66.95%
CVE-2026-42897 5.6% 71.20% +65.56%
CVE-2024-57726 8.6% 66.60% +57.97%
CVE-2026-34486 42.6% 98.60% +55.99%
CVE-2026-18577 1.5% 54.10% +52.59%
CVE-2026-6875 26.7% 77.60% +50.85%
CVE-2026-59310 1.1% 45.90% +44.74%
CVE-2020-10221 36.8% 80.20% +43.47%

Recent KEV Additions

Latest CVEs added to CISA KEV catalog
CVE-ID Severity Product Date Added
CVE-2026-66384 MEDIUM jfrog artifactory 2026-08-27
CVE-2023-49105 CRITICAL Owncloud Owncloud Server 2026-08-27
CVE-2026-8452 CRITICAL NetScaler ADC 2026-08-26
CVE-2021-23758 HIGH Ajaxpro.2 Project Ajaxpro.2 2026-08-26
CVE-2026-60004 CRITICAL Gitea 2026-08-25
CVE-2026-21962 CRITICAL Oracle Corporation Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in 2026-08-24
CVE-2026-73570 HIGH Zimbra Collaboration 2026-08-21
CVE-2026-72530 CRITICAL TrueConf Server 2026-08-20
CVE-2026-72529 CRITICAL TrueConf Server 2026-08-20
CVE-2026-64849 CRITICAL mlflow 2026-08-19

EPSS Monthly Snapshots

Top CVEs by EPSS, frozen at the end of each month
Aug 2026 — 5 CVEs
1. CVE-2020-5902
100.0%
2. CVE-2021-1498
100.0%
3. CVE-2021-21985
100.0%
4. CVE-2021-22005
100.0%
5. CVE-2021-26084
100.0%
Jul 2026 — 5 CVEs
1. CVE-2020-5902
100.0%
2. CVE-2021-1498
100.0%
3. CVE-2021-21985
100.0%
4. CVE-2021-22005
100.0%
5. CVE-2021-26084
100.0%
Jun 2026 — 5 CVEs
1. CVE-2020-5902
100.0%
2. CVE-2021-1498
100.0%
3. CVE-2021-21985
100.0%
4. CVE-2021-22005
100.0%
5. CVE-2021-26084
100.0%

Monthly EPSS Growth Leaders

CVEs that gained the most EPSS during each month
Aug 2026 — 5 CVEs
1. CVE-2026-63077
0.6% 87.7%
+87.06%
2. CVE-2026-72898
0.7% 79.2%
+78.53%
3. CVE-2026-45659
9.1% 76.1%
+66.95%
4. CVE-2026-42897
5.6% 71.2%
+65.56%
5. CVE-2024-57726
8.6% 66.6%
+57.97%
Jul 2026 — 5 CVEs
1. CVE-2026-48282
1.0% 99.2%
+98.18%
2. CVE-2026-63030
8.9% 98.4%
+89.47%
3. CVE-2026-48908
0.7% 88.1%
+87.4%
4. CVE-2026-56290
0.3% 83.3%
+82.98%
5. CVE-2026-15409
1.4% 78.4%
+77.04%
Jun 2026 — 5 CVEs
1. CVE-2026-10520
0.2% 98.9%
+98.72%
2. CVE-2026-35273
0.0% 92.3%
+92.31%
3. CVE-2026-20253
0.1% 88.2%
+88.1%
4. CVE-2026-24858
3.9% 85.8%
+81.9%
5. CVE-2026-48907
0.1% 80.4%
+80.31%

SSVC Decision Distribution

CISA Stakeholder-Specific Vulnerability Categorization

EPSS vs KEV Prediction — Complementary Coverage

Where EPSS underestimates and our ML model catches what EPSS misses — complementary divergence between metrics.
Backtest 2024+ — 82 CVEs entered KEV:
EPSS alone would catch
23 / 82 (28%)
We alone catch
35 / 82 (43%)
Both combined
44 / 82 (54%)
Unpredictable (both miss)
38 / 82 (46%)

SSVC Decision vs Severity

Why severity alone is insufficient for prioritization

Threat Velocity

Weekly inflow of new threats (last 12 weeks)

EPSS Prediction Accuracy

EPSS score before vs after KEV listing — did EPSS predict it?

Patch Priority Queue

Top CVEs by composite risk — SSVC + KEV Prediction + EPSS
CVE-ID SSVC KEV-ML EPSS CVSS Signals
CVE-2024-3400
Palo Alto Networks PAN-OS
ACT 76% 100.0% 10.0 KEV EXP RW
CVE-2021-44228
Apache Software Foundation Apa
ACT 56% 100.0% 10.0 KEV EXP RW
CVE-2023-35078
Ivanti Endpoint Manager Mobile
ACT 68% 100.0% 10.0 KEV RW
CVE-2023-22518
Atlassian Confluence Data Cent
ACT 65% 100.0% 9.8 KEV EXP RW
CVE-2020-5902
F5 BIG-IP
ACT 39% 100.0% 9.8 KEV EXP RW
CVE-2022-29464
WSO2 Multiple Products
ACT 77% 100.0% 9.8 KEV EXP RW
CVE-2021-1498
Cisco HyperFlex HX Data Platfo
ACT 76% 100.0% 9.8 KEV EXP RW
CVE-2023-1671
Sophos Web Appliance
ACT 59% 100.0% 9.8 KEV
CVE-2021-35464
ForgeRock Access Management (A
ACT 82% 100.0% 9.8 KEV EXP RW
CVE-2022-26134
Atlassian Confluence Data Cent
ACT 68% 100.0% 9.8 KEV EXP RW
CVE-2023-27350
PaperCut NG
ACT 64% 100.0% 9.8 KEV EXP RW
CVE-2021-22005
VMware vCenter Server
ACT 79% 100.0% 9.8 KEV EXP RW
CVE-2021-26084
Atlassian Confluence Server
ACT 79% 100.0% 9.8 KEV EXP RW
CVE-2023-35082
Ivanti EPMM
ACT 71% 100.0% 9.8 KEV RW
CVE-2021-21985
VMware vCenter Server
ACT 79% 100.0% 9.8 KEV EXP RW

Detection Gap

SSVC Act/Attend CVEs with NO detection rules
CVE-ID SSVC EPSS Severity Signals
CVE-2023-44487
IETF HTTP/2
ACT 100.0% HIGH KEV
CVE-2025-22457
Ivanti Connect Secure
ACT 100.0% CRITICAL KEV RW
CVE-2023-38035
Ivanti MobileIron Sentry
ACT 100.0% CRITICAL KEV RW
CVE-2020-0796
Microsoft Windows 10 Version 1
ACT 99.8% CRITICAL KEV RW
CVE-2023-29298
Adobe ColdFusion
ACT 99.8% HIGH KEV
CVE-2023-34048
VMware vCenter Server
ACT 99.4% CRITICAL KEV RW
CVE-2020-14750
Oracle Corporation WebLogic Se
ACT 99.3% CRITICAL KEV RW
CVE-2022-24086
Adobe Magento Commerce
ACT 99.2% CRITICAL KEV RW
CVE-2020-6207
SAP SE SAP Solution Manager (U
ACT 98.3% CRITICAL KEV
CVE-2022-26138
Atlassian Questions For Conflu
ACT 98.2% CRITICAL KEV
CVE-2024-3272
D-Link DNS-320L
ACT 98.0% CRITICAL KEV
CVE-2020-25078
D-Link DCS-2530L and DCS-2670L
ACT 97.9% HIGH KEV
CVE-2024-4358
Progress Software Corporation
ACT 97.5% CRITICAL KEV
CVE-2023-27524
Apache Software Foundation Apa
ACT 97.4% CRITICAL KEV RW
CVE-2020-25213
WordPress File Manager Plugin
ACT 97.3% CRITICAL KEV
CVE-2020-5847
Unraid Unraid
ACT 95.8% CRITICAL KEV
CVE-2022-36537
ZK Framework AuUploader
ACT 95.3% HIGH KEV RW
CVE-2020-2883
Oracle Corporation WebLogic Se
ACT 94.9% CRITICAL KEV RW
CVE-2024-21413
Microsoft Office 2019
ACT 94.7% CRITICAL KEV RW
CVE-2020-5849
Unraid Unraid
ACT 93.2% HIGH KEV