Threat and Exploit Intelligence Analytics

Deep insights into vulnerability landscape, exploitation trends and risk metrics.

Vulnerability Funnel

From NVD publication to confirmed exploitation

Year in progress — partial data
NVD Published
Monitored
EPSS > 10%
Exploited in Wild
TTE ≤ 5 days
Zero-Day
48,607 140 82 140 87 72
0.3%
58.6%
170.7%
62.1%
82.8%

Daily Monitoring Flow

CVEs added vs removed from monitoring (last 90 days)

CVE Distribution by Year

Severity breakdown across tracked years
900
Monitored CVEs
+25.0% vs last 30d
8.7
Avg CVSS Score
Across all active CVEs
865
Exploited in Wild
96.1% of monitored CVEs confirmed exploited
1d
Mean Time to Weaponize
Avg days from publish to first PoC/exploit (outliers removed)
82d
Mean Time to Exploit
Avg days from publish to confirmed exploitation (outliers removed)

Exploitation Timing by Severity

Fastest and average time-to-exploit/weaponize per severity level (outliers removed via IQR)
CRITICAL (311 CVEs)
-49.7d Fastest
-0.6d Median
76d Avg Exploit
-1d Avg PoC
187 Zero-Day
HIGH (179 CVEs)
-117.0d Fastest
0.3d Median
84d Avg Exploit
5d Avg PoC
84 Zero-Day
Global Timing
-117.0d Fastest
-0.5d Median
82d Avg Exploit
1d Avg PoC
Zero-Day (55.7% of 522 with TTE)
291 Total
187 Critical
84 High
5-Day Window
297 Exploited (35.6%)
361 With PoC (69.2%)

Threat Overlap

Intersection of KEV, Exploits and High EPSS
233 17 0 127 101 0 404 KEV (865) Exploit (548) EPSS >50% (505)

CVE Timeline (90d)

EPSS Distribution

Top CWE Categories

Most Dangerous CVEs

Ranked by composite score (CVSS x EPSS x KEV x Exploit)
CVE-ID Severity CVSS EPSS Score
CVE-2024-3400 KEV EXP CRITICAL 10 100.0% 60.0
CVE-2021-44228 KEV EXP CRITICAL 10 100.0% 60.0
CVE-2024-1709 KEV EXP CRITICAL 10 100.0% 59.99
CVE-2025-32432 KEV EXP CRITICAL 10 99.8% 59.95
CVE-2020-0796 KEV EXP CRITICAL 10 99.8% 59.94
CVE-2021-22205 KEV EXP CRITICAL 10 99.7% 59.92
CVE-2025-55182 KEV EXP CRITICAL 10 99.6% 59.88
CVE-2023-20198 KEV EXP CRITICAL 10 99.6% 59.87
CVE-2024-4040 KEV EXP CRITICAL 10 99.5% 59.86
CVE-2022-0543 KEV EXP CRITICAL 10 99.3% 59.78

Vendor Exposure

Vendor CVEs Avg CVSS Exposure
Microsoft 99 8.0
11.0%
Google 62 8.8
6.9%
Apple 44 8.5
4.9%
Cisco 38 8.3
4.2%
Ivanti 33 8.5
3.7%
Apache 26 9.3
2.9%
Vmware 22 8.9
2.4%
Oracle 21 9.1
2.3%
Fortinet 21 9.4
2.3%
Sonicwall 15 8.4
1.7%

EPSS Movers

Biggest EPSS increases in the last 7 days
CVE-ID Previous Current Change
CVE-2026-42897 5.6% 70.30% +64.67%
CVE-2026-16232 12.7% 73.30% +60.61%
CVE-2026-48939 24.3% 82.50% +58.15%
CVE-2024-57726 8.6% 66.60% +57.97%
CVE-2026-58644 5.1% 45.50% +40.42%
CVE-2026-34486 42.6% 82.90% +40.31%
CVE-2025-11953 62.4% 94.00% +31.6%
CVE-2026-12569 2.3% 30.20% +27.93%
CVE-2026-34908 58.4% 85.20% +26.76%
CVE-2026-33824 55.9% 77.90% +22.05%

Recent KEV Additions

Latest CVEs added to CISA KEV catalog
CVE-ID Severity Product Date Added
CVE-2026-73570 HIGH Zimbra Collaboration 2026-08-21
CVE-2026-72530 CRITICAL TrueConf Server 2026-08-20
CVE-2026-72529 CRITICAL TrueConf Server 2026-08-20
CVE-2026-64849 CRITICAL mlflow 2026-08-19
CVE-2026-65400 CRITICAL Apple macOS 2026-08-18
CVE-2026-59310 CRITICAL VMware Cloud Foundation 2026-08-18
CVE-2026-55040 CRITICAL Microsoft SharePoint Enterprise Server 2016 2026-08-18
CVE-2026-33824 CRITICAL Microsoft Windows 10 Version 1607 2026-08-18
CVE-2025-62593 HIGH ray-project ray 2026-08-17
CVE-2026-20349 HIGH Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 2026-08-11

EPSS Monthly Snapshots

Top CVEs by EPSS, frozen at the end of each month
Aug 2026 — 5 CVEs
1. CVE-2020-5902
100.0%
2. CVE-2021-1498
100.0%
3. CVE-2021-21985
100.0%
4. CVE-2021-22005
100.0%
5. CVE-2021-26084
100.0%
Jul 2026 — 5 CVEs
1. CVE-2020-5902
100.0%
2. CVE-2021-1498
100.0%
3. CVE-2021-21985
100.0%
4. CVE-2021-22005
100.0%
5. CVE-2021-26084
100.0%
Jun 2026 — 5 CVEs
1. CVE-2020-5902
100.0%
2. CVE-2021-1498
100.0%
3. CVE-2021-21985
100.0%
4. CVE-2021-22005
100.0%
5. CVE-2021-26084
100.0%

Monthly EPSS Growth Leaders

CVEs that gained the most EPSS during each month
Aug 2026 — 5 CVEs
1. CVE-2026-42897
5.6% 70.3%
+64.67%
2. CVE-2026-48939
24.3% 82.5%
+58.15%
3. CVE-2024-57726
8.6% 66.6%
+57.97%
4. CVE-2026-34486
42.6% 82.9%
+40.31%
5. CVE-2026-58644
6.0% 45.5%
+39.49%
Jul 2026 — 5 CVEs
1. CVE-2026-48282
1.0% 99.2%
+98.18%
2. CVE-2026-63030
8.9% 98.4%
+89.47%
3. CVE-2026-48908
0.7% 88.1%
+87.4%
4. CVE-2026-56290
0.3% 83.3%
+82.98%
5. CVE-2026-15409
1.4% 78.4%
+77.04%
Jun 2026 — 5 CVEs
1. CVE-2026-10520
0.2% 98.9%
+98.72%
2. CVE-2026-35273
0.0% 92.3%
+92.31%
3. CVE-2026-20253
0.1% 88.2%
+88.1%
4. CVE-2026-24858
3.9% 85.8%
+81.9%
5. CVE-2026-48907
0.1% 80.4%
+80.31%

SSVC Decision Distribution

CISA Stakeholder-Specific Vulnerability Categorization

EPSS vs KEV Prediction — Complementary Coverage

Where EPSS underestimates and our ML model catches what EPSS misses — complementary divergence between metrics.
Backtest 2024+ — 82 CVEs entered KEV:
EPSS alone would catch
23 / 82 (28%)
We alone catch
35 / 82 (43%)
Both combined
44 / 82 (54%)
Unpredictable (both miss)
38 / 82 (46%)

SSVC Decision vs Severity

Why severity alone is insufficient for prioritization

Threat Velocity

Weekly inflow of new threats (last 12 weeks)

EPSS Prediction Accuracy

EPSS score before vs after KEV listing — did EPSS predict it?

Patch Priority Queue

Top CVEs by composite risk — SSVC + KEV Prediction + EPSS
CVE-ID SSVC KEV-ML EPSS CVSS Signals
CVE-2024-3400
Palo Alto Networks PAN-OS
ACT 76% 100.0% 10.0 KEV EXP RW
CVE-2023-35078
Ivanti Endpoint Manager Mobile
ACT 68% 100.0% 10.0 KEV RW
CVE-2021-44228
Apache Software Foundation Apa
ACT 56% 100.0% 10.0 KEV EXP RW
CVE-2021-1498
Cisco HyperFlex HX Data Platfo
ACT 76% 100.0% 9.8 KEV EXP RW
CVE-2021-21985
VMware vCenter Server
ACT 79% 100.0% 9.8 KEV EXP RW
CVE-2021-26084
Atlassian Confluence Server
ACT 79% 100.0% 9.8 KEV EXP RW
CVE-2022-29464
WSO2 Multiple Products
ACT 77% 100.0% 9.8 KEV EXP RW
CVE-2023-22518
Atlassian Confluence Data Cent
ACT 65% 100.0% 9.8 KEV EXP RW
CVE-2021-22005
VMware vCenter Server
ACT 80% 100.0% 9.8 KEV EXP RW
CVE-2023-35082
Ivanti EPMM
ACT 71% 100.0% 9.8 KEV RW
CVE-2022-26134
Atlassian Confluence Data Cent
ACT 68% 100.0% 9.8 KEV EXP RW
CVE-2020-5902
F5 BIG-IP
ACT 39% 100.0% 9.8 KEV EXP RW
CVE-2021-35464
ForgeRock Access Management (A
ACT 82% 100.0% 9.8 KEV EXP RW
CVE-2023-1671
Sophos Web Appliance
ACT 59% 100.0% 9.8 KEV
CVE-2023-27350
PaperCut NG
ACT 68% 100.0% 9.8 KEV EXP RW

Detection Gap

SSVC Act/Attend CVEs with NO detection rules
CVE-ID SSVC EPSS Severity Signals
CVE-2023-44487
IETF HTTP/2
ACT 100.0% HIGH KEV
CVE-2025-22457
Ivanti Connect Secure
ACT 100.0% CRITICAL KEV RW
CVE-2023-38035
Ivanti MobileIron Sentry
ACT 100.0% CRITICAL KEV RW
CVE-2020-0796
Microsoft Windows 10 Version 1
ACT 99.8% CRITICAL KEV RW
CVE-2023-29298
Adobe ColdFusion
ACT 99.8% HIGH KEV
CVE-2023-34048
VMware vCenter Server
ACT 99.4% CRITICAL KEV RW
CVE-2020-14750
Oracle Corporation WebLogic Se
ACT 99.3% CRITICAL KEV RW
CVE-2022-24086
Adobe Magento Commerce
ACT 99.1% CRITICAL KEV RW
CVE-2020-6207
SAP SE SAP Solution Manager (U
ACT 98.3% CRITICAL KEV
CVE-2022-26138
Atlassian Questions For Conflu
ACT 98.2% CRITICAL KEV
CVE-2024-3272
D-Link DNS-320L
ACT 98.0% CRITICAL KEV
CVE-2020-25078
D-Link DCS-2530L and DCS-2670L
ACT 97.7% HIGH KEV
CVE-2024-4358
Progress Software Corporation
ACT 97.5% CRITICAL KEV
CVE-2023-27524
Apache Software Foundation Apa
ACT 97.4% CRITICAL KEV RW
CVE-2020-25213
WordPress File Manager Plugin
ACT 97.3% CRITICAL KEV
CVE-2020-5847
Unraid Unraid
ACT 95.8% CRITICAL KEV
CVE-2022-36537
ZK Framework AuUploader
ACT 95.3% HIGH KEV RW
CVE-2020-2883
Oracle Corporation WebLogic Se
ACT 94.9% CRITICAL KEV RW
CVE-2024-21413
Microsoft Office 2019
ACT 94.7% CRITICAL KEV RW
CVE-2020-5849
Unraid Unraid
ACT 93.2% HIGH KEV