Threat radar

Exploited in the wild, and what is most likely next

Two lists from public vulnerability sources: what an authority has confirmed is being exploited, and what a published model rates as most likely to be exploited soon. They are different claims and the page keeps them apart.

Built from data synchronised 25 Aug 2026 14:20 UTC. Drawn from 357,648 advisory records this platform ingests from NVD, CISA KEV, FIRST EPSS, GitHub Security Advisories and OSV. Nothing on this page describes any customer environment.

Confirmed exploited in the wild

Every entry below is on CISA’s Known Exploited Vulnerabilities catalog, which means a government authority has published evidence of exploitation. This is the only list here that reports a fact rather than a forecast. Most recent first.

Vulnerabilities confirmed exploited in the wild
CVEWhat it isCVSSEPSSPublished
CVE-2026-73570Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerabilitynot scored0.5%21 Aug 2026
CVE-2026-69836Microsoft Entra ID Deserialization of Untrusted Data Vulnerabilitynot scored1.4%21 Aug 2026
CVE-2026-72529TrueConf Server Missing Authentication for Critical Function Vulnerabilitynot scored0.3%20 Aug 2026
CVE-2026-72530TrueConf Server Code Injection Vulnerabilitynot scored0.3%20 Aug 2026
CVE-2026-59310Broadcom VMware vCenter Path Traversal Vulnerabilitynot scored1.1%18 Aug 2026
CVE-2026-55040Microsoft SharePoint Weak Authentication Vulnerabilitynot scored4.0%18 Aug 2026
CVE-2026-65400Apple macOS Improper Authentication Vulnerabilitynot scored0.5%18 Aug 2026
CVE-2026-64849MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTT9.30.3%17 Aug 2026
CVE-2026-63505Exploit Available: Probo 0.222.2 - IDORnot scoredno score17 Aug 2026
CVE-2026-58058Exploit Available: Nmap 7.99 - Extension Header Integer Underflownot scored0.3%17 Aug 2026
CVE-2026-55584Exploit Available: phpSysInfo 3.4.5 - IP Allowlist Bypassnot scoredno score17 Aug 2026
CVE-2026-55780Exploit Available: NanaZip 6.5 - DoSnot scored0.1%17 Aug 2026
CVE-2026-72898Metabase SQL Injection Vulnerabilitynot scored1.1%11 Aug 2026
CVE-2026-61459Exploit Available: mcp-server-kubernetes 3.8.x - Argument Injectionnot scored0.5%11 Aug 2026
CVE-2026-68820Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerabilitynot scored0.4%11 Aug 2026

2,092 entries in the catalog in total. 14 of the 15 entries above have no CVSS score yet. A vulnerability enters this catalog when someone is seen exploiting it, which is routinely before it has been scored — so at any given moment the things actually under attack are disproportionately the ones a CVSS-ordered list ranks last, or not at all.

Being on this list does not mean you are affected — it means the software is under attack somewhere. Whether you run it, whether it is reachable, and whether anything of yours is behind it are separate questions, and they are the ones exposure management exists to answer.

Highest exploitation probability, not yet in the catalog

Ranked by EPSS, FIRST’s published model of the probability that a vulnerability will be exploited in the next 30 days. Entries already on the CISA catalog are excluded, so this list is what the model is pointing at rather than what is already confirmed.

Vulnerabilities with the highest predicted exploitation probability
CVEWhat it isCVSSEPSSPublished
CVE-2021-45105Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from u5.9100.0%18 Dec 2021
CVE-2014-3566The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CB3.4100.0%15 Oct 2014
CVE-2023-50387Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow r7.5100.0%14 Feb 2024
CVE-2014-0195The dtls1_reassemble_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m,6.8100.0%05 Jun 2014
CVE-2014-3704The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not7.5100.0%16 Oct 2014
CVE-2015-7297SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary7.5100.0%29 Oct 2015
CVE-2012-1456The TAR file parser in AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Comodo Anti4.399.9%21 Mar 2012
CVE-2025-53771Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform sp6.599.9%20 Jul 2025
CVE-2024-29826An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an8.899.9%31 May 2024
CVE-2024-29825An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an8.899.9%31 May 2024
CVE-2024-29823An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an8.899.9%31 May 2024
CVE-2015-4000The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a3.799.9%21 May 2015
CVE-2020-13379The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This v8.299.9%03 Jun 2020
CVE-2017-12635Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible9.899.8%14 Nov 2017
CVE-2017-8917SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL9.899.8%17 May 2017

EPSS is a forecast, not an observation. A high score on an older CVE usually means it is under continuous opportunistic attack across the internet rather than that it is new. A low score is not a statement that a vulnerability is safe to leave, and neither number knows anything about your environment.

Why neither list is ordered by CVSS

CVSS scores how bad a vulnerability would be if exploited. It does not estimate whether anyone is exploiting it. Ordering work by CVSS alone is what sends a team to a 9.8 nobody has ever attacked ahead of a 7.5 being used today — and it is why both tables above show CVSS as a column rather than as the sort order.

Exploit Hound ranks remediation the same way, over an estate rather than over a corpus: what an action removes, weighted by whether the thing is exposed, reachable and actually being exploited. See how that is ranked →

These are the vulnerabilities. The question is which ones reach you.

A catalog cannot tell you that. Point Exploit Hound at the assets you are authorized to assess and it will tell you which of these are present, which are reachable, and what removes the most exposure first.

Start Finding Exposure See the walkthrough

v2.58.6 Exploit Hound 2.58.6 · Continuous Threat Exposure Management