Threat and Exploit Intelligence Analytics

Deep insights into vulnerability landscape, exploitation trends and risk metrics.

Vulnerability Funnel

From NVD publication to confirmed exploitation

Year in progress — partial data
NVD Published
Monitored
EPSS > 10%
Exploited in Wild
TTE ≤ 5 days
Zero-Day
69,585 183 80 183 109 92
0.3%
43.7%
228.8%
59.6%
84.4%

Daily Monitoring Flow

CVEs added vs removed from monitoring (last 90 days)

CVE Distribution by Year

Severity breakdown across tracked years
947
Monitored CVEs
-25.0% vs last 30d
8.8
Avg CVSS Score
Across all active CVEs
926
Exploited in Wild
97.8% of monitored CVEs confirmed exploited
1d
Mean Time to Weaponize
Avg days from publish to first PoC/exploit (outliers removed)
75d
Mean Time to Exploit
Avg days from publish to confirmed exploitation (outliers removed)

Exploitation Timing by Severity

Fastest and average time-to-exploit/weaponize per severity level (outliers removed via IQR)
CRITICAL (340 CVEs)
-49.7d Fastest
-0.6d Median
65d Avg Exploit
0d Avg PoC
205 Zero-Day
HIGH (183 CVEs)
-117.0d Fastest
0.3d Median
84d Avg Exploit
6d Avg PoC
87 Zero-Day
Global Timing
-117.0d Fastest
-0.5d Median
75d Avg Exploit
1d Avg PoC
Zero-Day (56.2% of 555 with TTE)
312 Total
205 Critical
87 High
5-Day Window
321 Exploited (36.6%)
384 With PoC (69.2%)

Threat Overlap

Intersection of KEV, Exploits and High EPSS
236 19 0 182 98 1 399 KEV (915) Exploit (601) EPSS >50% (498)

CVE Timeline (90d)

EPSS Distribution

Top CWE Categories

Most Dangerous CVEs

Ranked by composite score (CVSS x EPSS x KEV x Exploit)
CVE-ID Severity CVSS EPSS Score
CVE-2024-3400 KEV EXP CRITICAL 10 100.0% 60.0
CVE-2021-44228 KEV EXP CRITICAL 10 100.0% 60.0
CVE-2024-1709 KEV EXP CRITICAL 10 100.0% 59.99
CVE-2025-55182 KEV EXP CRITICAL 10 99.8% 59.94
CVE-2025-32432 KEV EXP CRITICAL 10 99.8% 59.94
CVE-2020-0796 KEV EXP CRITICAL 10 99.8% 59.94
CVE-2021-22205 KEV EXP CRITICAL 10 99.7% 59.92
CVE-2023-20198 KEV EXP CRITICAL 10 99.6% 59.87
CVE-2024-4040 KEV EXP CRITICAL 10 99.5% 59.86
CVE-2022-0543 KEV EXP CRITICAL 10 99.4% 59.81

Vendor Exposure

Vendor CVEs Avg CVSS Exposure
Microsoft 100 8.0
10.6%
Google 65 8.8
6.9%
Apple 45 8.5
4.8%
Cisco 42 8.6
4.4%
Ivanti 33 8.5
3.5%
Apache 26 9.3
2.7%
Fortinet 23 9.3
2.4%
Vmware 22 8.9
2.3%
Oracle 22 9.1
2.3%
Adobe 16 9.1
1.7%

EPSS Movers

Biggest EPSS increases in the last 7 days
CVE-ID Previous Current Change
CVE-2026-85706 1.1% 93.00% +91.81%
CVE-2026-81578 1.6% 85.60% +83.96%
CVE-2026-48908 14.8% 88.50% +73.69%
CVE-2026-71362 24.5% 87.50% +62.99%
CVE-2026-82078 1.7% 63.50% +61.84%
CVE-2024-57728 7.0% 64.70% +57.68%
CVE-2026-20079 35.9% 88.20% +52.23%
CVE-2026-85046 1.4% 48.90% +47.45%
CVE-2025-62593 16.9% 62.50% +45.57%
CVE-2026-87902 0.4% 40.00% +39.56%

Recent KEV Additions

Latest CVEs added to CISA KEV catalog
CVE-ID Severity Product Date Added
CVE-2023-22894 MEDIUM N/A 2026-10-08
CVE-2021-3199 CRITICAL N/A 2026-10-08
CVE-2026-88779 HIGH NetScaler ADC 2026-10-04
CVE-2026-102490 CRITICAL Zammad GmbH Zammad 2026-10-02
CVE-2026-102489 CRITICAL Zammad GmbH Zammad 2026-10-02
CVE-2026-104286 CRITICAL Fortinet FortiMail 2026-10-01
CVE-2026-76504 CRITICAL Cisco Catalyst SD-WAN Manager 2026-09-30
CVE-2026-86950 HIGH Apple iOS and iPadOS 2026-09-29
CVE-2026-88772 CRITICAL Citrix NetScaler ADC 2026-09-27
CVE-2026-88771 CRITICAL Citrix NetScaler ADC 2026-09-27

EPSS Monthly Snapshots

Top CVEs by EPSS, frozen at the end of each month
Oct 2026 — 5 CVEs
1. CVE-2020-5902
100.0%
2. CVE-2021-1498
100.0%
3. CVE-2021-21985
100.0%
4. CVE-2021-22005
100.0%
5. CVE-2021-26084
100.0%
Sep 2026 — 5 CVEs
1. CVE-2020-5902
100.0%
2. CVE-2021-1498
100.0%
3. CVE-2021-21985
100.0%
4. CVE-2021-22005
100.0%
5. CVE-2021-26084
100.0%
Aug 2026 — 5 CVEs
1. CVE-2020-5902
100.0%
2. CVE-2021-1498
100.0%
3. CVE-2021-21985
100.0%
4. CVE-2021-22005
100.0%
5. CVE-2021-26084
100.0%
Jul 2026 — 5 CVEs
1. CVE-2020-5902
100.0%
2. CVE-2021-1498
100.0%
3. CVE-2021-21985
100.0%
4. CVE-2021-22005
100.0%
5. CVE-2021-26084
100.0%
Jun 2026 — 5 CVEs
1. CVE-2020-5902
100.0%
2. CVE-2021-1498
100.0%
3. CVE-2021-21985
100.0%
4. CVE-2021-22005
100.0%
5. CVE-2021-26084
100.0%

Monthly EPSS Growth Leaders

CVEs that gained the most EPSS during each month
Oct 2026 — 5 CVEs
1. CVE-2026-50751
6.3% 85.3%
+79.04%
2. CVE-2026-73570
11.7% 71.7%
+59.93%
3. CVE-2026-55040
17.5% 69.5%
+52.0%
4. CVE-2026-32201
1.0% 43.4%
+42.39%
5. CVE-2026-87902
19.8% 40.0%
+20.22%
Sep 2026 — 5 CVEs
1. CVE-2026-85706
1.1% 91.4%
+90.28%
2. CVE-2026-48908
14.8% 88.5%
+73.69%
3. CVE-2026-71362
24.5% 87.5%
+62.99%
4. CVE-2024-57728
7.0% 64.7%
+57.68%
5. CVE-2026-20079
35.9% 88.2%
+52.23%
Aug 2026 — 5 CVEs
1. CVE-2026-63077
0.6% 87.7%
+87.06%
2. CVE-2026-72898
0.7% 79.2%
+78.53%
3. CVE-2026-45659
9.1% 76.1%
+66.95%
4. CVE-2026-42897
5.6% 71.2%
+65.56%
5. CVE-2024-57726
8.6% 66.6%
+57.97%
Jul 2026 — 5 CVEs
1. CVE-2026-48282
1.0% 99.2%
+98.18%
2. CVE-2026-63030
8.9% 98.4%
+89.47%
3. CVE-2026-48908
0.7% 88.1%
+87.4%
4. CVE-2026-56290
0.3% 83.3%
+82.98%
5. CVE-2026-15409
1.4% 78.4%
+77.04%
Jun 2026 — 5 CVEs
1. CVE-2026-10520
0.2% 98.9%
+98.72%
2. CVE-2026-35273
0.0% 92.3%
+92.31%
3. CVE-2026-20253
0.1% 88.2%
+88.1%
4. CVE-2026-24858
3.9% 85.8%
+81.9%
5. CVE-2026-48907
0.1% 80.4%
+80.31%

SSVC Decision Distribution

CISA Stakeholder-Specific Vulnerability Categorization

EPSS vs KEV Prediction — Complementary Coverage

Where EPSS underestimates and our ML model catches what EPSS misses — complementary divergence between metrics.
Backtest 2024+ — 82 CVEs entered KEV:
EPSS alone would catch
23 / 82 (28%)
We alone catch
35 / 82 (43%)
Both combined
44 / 82 (54%)
Unpredictable (both miss)
38 / 82 (46%)

SSVC Decision vs Severity

Why severity alone is insufficient for prioritization

Threat Velocity

Weekly inflow of new threats (last 12 weeks)

EPSS Prediction Accuracy

EPSS score before vs after KEV listing — did EPSS predict it?

Patch Priority Queue

Top CVEs by composite risk — SSVC + KEV Prediction + EPSS
CVE-ID SSVC KEV-ML EPSS CVSS Signals
CVE-2024-3400
Palo Alto Networks PAN-OS
ACT 81% 100.0% 10.0 KEV EXP RW
CVE-2021-44228
Apache Software Foundation Apa
ACT 80% 100.0% 10.0 KEV EXP RW
CVE-2021-35464
ForgeRock Access Management (A
ACT 81% 100.0% 9.8 KEV EXP RW
CVE-2021-22005
VMware vCenter Server
ACT 84% 100.0% 9.8 KEV EXP RW
CVE-2022-26134
Atlassian Confluence Data Cent
ACT 83% 100.0% 9.8 KEV EXP RW
CVE-2023-27350
PaperCut NG
ACT 72% 100.0% 9.8 KEV EXP RW
CVE-2024-23897
Jenkins Project Jenkins
ACT 73% 100.0% 9.8 KEV EXP RW
CVE-2022-29464
WSO2 Multiple Products
ACT 78% 100.0% 9.8 KEV EXP RW
CVE-2020-5902
F5 BIG-IP
ACT 8% 100.0% 9.8 KEV EXP RW
CVE-2021-1498
Cisco HyperFlex HX Data Platfo
ACT 81% 100.0% 9.8 KEV EXP RW
CVE-2021-26084
Atlassian Confluence Server
ACT 93% 100.0% 9.8 KEV EXP RW
CVE-2024-7593
Ivanti vTM
ACT 83% 100.0% 9.8 KEV EXP RW
CVE-2023-1671
Sophos Web Appliance
ACT 71% 100.0% 9.8 KEV
CVE-2023-35082
Ivanti EPMM
ACT 83% 100.0% 9.8 KEV RW
CVE-2021-21985
VMware vCenter Server
ACT 80% 100.0% 9.8 KEV EXP RW

Detection Gap

SSVC Act/Attend CVEs with NO detection rules
CVE-ID SSVC EPSS Severity Signals
CVE-2023-44487
IETF HTTP/2
ACT 100.0% HIGH KEV
CVE-2025-22457
Ivanti Connect Secure
ACT 100.0% CRITICAL KEV RW
CVE-2023-38035
Ivanti MobileIron Sentry
ACT 100.0% CRITICAL KEV RW
CVE-2020-0796
Microsoft Windows 10 Version 1
ACT 99.8% CRITICAL KEV RW
CVE-2023-29298
Adobe ColdFusion
ACT 99.8% HIGH KEV
CVE-2023-34048
VMware vCenter Server
ACT 99.4% CRITICAL KEV RW
CVE-2020-14750
Oracle Corporation WebLogic Se
ACT 99.3% CRITICAL KEV RW
CVE-2022-24086
Adobe Magento Commerce
ACT 99.2% CRITICAL KEV RW
CVE-2022-26138
Atlassian Questions For Conflu
ACT 98.2% CRITICAL KEV
CVE-2020-6207
SAP SE SAP Solution Manager (U
ACT 98.1% CRITICAL KEV
CVE-2024-3272
D-Link DNS-320L
ACT 98.0% CRITICAL KEV
CVE-2020-25078
D-Link DCS-2530L and DCS-2670L
ACT 97.5% HIGH KEV
CVE-2024-4358
Progress Software Corporation
ACT 97.5% CRITICAL KEV
CVE-2023-27524
Apache Software Foundation Apa
ACT 97.4% CRITICAL KEV RW
CVE-2020-25213
WordPress File Manager Plugin
ACT 97.3% CRITICAL KEV
CVE-2020-5847
Unraid Unraid
ACT 95.8% CRITICAL KEV
CVE-2022-36537
ZK Framework AuUploader
ACT 95.4% HIGH KEV RW
CVE-2022-23134
Zabbix Frontend
ACT 95.3% MEDIUM KEV
CVE-2020-2883
Oracle Corporation WebLogic Se
ACT 94.9% CRITICAL KEV RW
CVE-2024-21413
Microsoft Office 2019
ACT 94.7% CRITICAL KEV RW