Reports & Trends

Last updated: September 10, 2026 · Data from the last 30 days ·
Updated daily at 21:00 UTC

Exploitation Activity — Last 30 Days

Daily count of new CVEs added to the CISA Known Exploited Vulnerabilities catalog
and ransomware victims tracked by Ransomware.live. Taller bars mean busier days —
use this to spot clusters and decide whether your team is in a high-tempo period.
171 new KEVs and 6,100 ransomware victims recorded in this window.

New KEVs per Day

2 4 5 7 4 4 3 3 3 4 5 6 7 7 7 7 7 6 7 7 7 7 7 7 7 7 7 7 7 7 7 7 Aug 12 Aug 19 Aug 26 Sep 2 Sep 9

Ransomware Victims per Day

64 129 194 258 256 231 228 229 247 225 236 205 236 233 244 254 258 252 252 248 242 238 251 233 230 223 193 170 158 161 167 Aug 12 Aug 19 Aug 26 Sep 2 Sep 9

EPSS Movement Tracker

CVEs whose exploitation probability (EPSS) has increased the most since they were
first published on ThreatPodium. EPSS is a daily probability score from FIRST.org
estimating the likelihood of exploitation within 30 days. A large jump means
attacker tooling or active scanning has increased — these are the CVEs trending
toward confirmed exploitation before the KEV catalog catches up.
Showing 15 CVEs with a movement of
5 percentage points or more.

CVE Vendor / Product First EPSS Current EPSS Change
CVE-2026-20253 Splunk Enterprise 1.7% 92.1% +90.4pp
CVE-2026-63030 WordPress Core 8.9% 98.1% +89.2pp
CVE-2026-60137 WordPress Core 20.4% 78.0% +57.6pp
CVE-2026-42271 BerriAI LiteLLM 4.1% 60.8% +56.7pp
CVE-2026-10520 Ivanti Sentry 3.3% 59.5% +56.2pp
CVE-2026-34910 Ubiquiti UniFi OS 33.6% 78.6% +45.0pp
CVE-2026-59310 Broadcom VMware vCenter 1.1% 45.9% +44.8pp
CVE-2026-0770 Langflow Langflow 10.4% 53.5% +43.1pp
CVE-2026-20079 Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management 35.9% 74.7% +38.8pp
CVE-2026-34486 Apache Tomcat 42.6% 81.2% +38.6pp
CVE-2026-50522 Microsoft SharePoint 20.3% 57.1% +36.8pp
CVE-2026-39808 Fortinet FortiSandbox 48.7% 84.2% +35.5pp
CVE-2023-49105 ownCloud ownCloud 11.1% 43.2% +32.1pp
CVE-2026-48282 Adobe ColdFusion 1.0% 28.6% +27.6pp
CVE-2026-33824 Microsoft Internet Key Exchange (IKE) Service Extensions 55.9% 72.7% +16.9pp

Vendor Risk Leaderboard — Last 30 Days

Vendors ranked by cumulative KEV exposure over the last 30 days.
A vendor at the top of this list has had actively exploited vulnerabilities confirmed
by CISA repeatedly — not just in a single busy week. The “Days with KEV Activity”
column shows consistency: a vendor appearing on 8 of 30 days is a structural
concern worth continuous monitoring, not just a one-off patch event.

Microsoft 20 Trueconf 12 Cisco 8 Papercut 7 Sangoma 7 Sonicwall 7 Metabase 6 Apple 6 Broadcom 6 Mlflow 6

# Vendor Total KEVs (30d) Days with KEV Activity
1 Microsoft 20 18
2 Trueconf 12 6
3 Cisco 8 8
4 Papercut 7 5
5 Sangoma 7 7
6 Sonicwall 7 6
7 Metabase 6 6
8 Apple 6 6
9 Broadcom 6 6
10 Mlflow 6 6