Reports & Trends

Last updated: July 27, 2026 · Data from the last 30 days ·
Updated daily at 21:00 UTC

Exploitation Activity — Last 30 Days

Daily count of new CVEs added to the CISA Known Exploited Vulnerabilities catalog
and ransomware victims tracked by Ransomware.live. Taller bars mean busier days —
use this to spot clusters and decide whether your team is in a high-tempo period.
161 new KEVs and 5,482 ransomware victims recorded in this window.

New KEVs per Day

2 4 5 7 6 7 3 4 2 2 2 2 1 5 4 4 6 6 6 7 7 7 7 7 7 7 7 7 7 6 6 6 6 7 Jun 28 Jul 5 Jul 12 Jul 19 Jul 26

Ransomware Victims per Day

67 134 201 268 114 117 131 145 202 199 202 188 192 209 133 127 197 222 219 221 205 212 231 171 160 169 170 160 164 178 169 175 232 268 Jun 28 Jul 5 Jul 12 Jul 19 Jul 26

EPSS Movement Tracker

CVEs whose exploitation probability (EPSS) has increased the most since they were
first published on ThreatPodium. EPSS is a daily probability score from FIRST.org
estimating the likelihood of exploitation within 30 days. A large jump means
attacker tooling or active scanning has increased — these are the CVEs trending
toward confirmed exploitation before the KEV catalog catches up.
Showing 15 CVEs with a movement of
5 percentage points or more.

CVE Vendor / Product First EPSS Current EPSS Change
CVE-2026-20253 Splunk Enterprise 1.7% 92.1% +90.4pp
CVE-2026-63030 WordPress Core 8.9% 98.1% +89.2pp
CVE-2026-60137 WordPress Core 20.4% 78.0% +57.6pp
CVE-2026-42271 BerriAI LiteLLM 4.1% 60.8% +56.7pp
CVE-2026-10520 Ivanti Sentry 3.3% 59.5% +56.2pp
CVE-2026-0257 Palo Alto Networks PAN-OS 0.1% 46.5% +46.4pp
CVE-2026-34910 Ubiquiti UniFi OS 33.6% 78.6% +45.0pp
CVE-2026-0770 Langflow Langflow 10.4% 53.5% +43.1pp
CVE-2026-50522 Microsoft SharePoint 20.3% 57.1% +36.8pp
CVE-2026-39808 Fortinet FortiSandbox 48.7% 84.2% +35.5pp
CVE-2022-0492 Linux Kernel 5.2% 33.7% +28.5pp
CVE-2026-48282 Adobe ColdFusion 1.0% 28.6% +27.6pp
CVE-2026-45321 TanStack TanStack 0.0% 17.1% +17.1pp
CVE-2026-9082 Drupal Core 17.3% 34.2% +16.9pp
CVE-2026-8398 Daemon Daemon Tools Lite 0.0% 15.5% +15.5pp

Vendor Risk Leaderboard — Last 30 Days

Vendors ranked by cumulative KEV exposure over the last 30 days.
A vendor at the top of this list has had actively exploited vulnerabilities confirmed
by CISA repeatedly — not just in a single busy week. The “Days with KEV Activity”
column shows consistency: a vendor appearing on 8 of 30 days is a structural
concern worth continuous monitoring, not just a one-off patch event.

Microsoft 27 Fortinet 15 Langflow 12 WordPress 11 Sonicwall 9 Simplehelp 7 Icagenda 7 Oracle 7 Ubiquiti 6 Cisco 6

# Vendor Total KEVs (30d) Days with KEV Activity
1 Microsoft 27 21
2 Fortinet 15 8
3 Langflow 12 12
4 WordPress 11 7
5 Sonicwall 9 7
6 Simplehelp 7 7
7 Icagenda 7 7
8 Oracle 7 7
9 Ubiquiti 6 2
10 Cisco 6 6