KEV Intelligence is becoming Previdian.

Exploitation intelligence

Observed Exploitation Signals

Sensor-backed exploitation attempts against internet-facing services, mapped to vulnerabilities and reviewed for confidence. See where attacker activity is concentrating before severity scores alone tell the story.

KEVs Observed
128
Known exploited vulnerabilities seen in the selected window
Exploitation Events
39,408
Attempts mapped to tracked vulnerabilities across the sensor network
Attacker IPs
707
Unique source addresses observed in the selected window

Exploitation Attempts

Seven-day activity, grouped by observation date · 18 Aug–25 Aug 2026 UTC

Exploitation Attempts

Seven-day activity, grouped by observation date

1,510
1,388
2,365
6,912
7,186
4,852
13,082
2,113
18 Aug 19 Aug 20 Aug 21 Aug 22 Aug 23 Aug 24 Aug 25 Aug

Click a day to filter stats and tables to that date.

Where Exploitation Activity Concentrated

The highest-volume vulnerabilities in this snapshot, ranked by mapped exploitation attempts—not theoretical severity.

Inspect full KEV record

PHPUnit

PHPUnit

Attempts
14,757
Attackers
235
Sensors
31

react-server-dom-webpack, react-server-dom-turbopack, react-server-dom-parcel

Meta

Attempts
10,622
Attackers
51
Sensors
27

ADC, Gateway

NetScaler

Attempts
6,022
Attackers
2
Sensors
1

PHP

PHP Group

Attempts
2,693
Attackers
250
Sensors
31

WordPress

WordPress

Attempts
1,207
Attackers
62
Sensors
21

AcyMailing SMTP Newsletter

AcyMailing Newsletter Team

Attempts
878
Attackers
14
Sensors
15

Observed Exploitation Attempts

Search the highest-volume records in the selected window. Each row shows activity breadth and recency alongside raw volume.

How to Read the Signal

Attempts indicate volume. Unique IPs and sensors indicate breadth. First and last seen show persistence. Use the linked CVE record for evidence and remediation context.

CVE-2017-9841

PHPUnit

PHPUnit

Attempts
14,757
Attacker IPs
235
Sensors
31
CVE-2025-55182

react-server-dom-webpack, react-server-dom-turbopack, react-server-dom-parcel

Meta

Attempts
10,622
Attacker IPs
51
Sensors
27
CVE-2026-8451

ADC, Gateway

NetScaler

Attempts
6,022
Attacker IPs
2
Sensors
1
CVE-2024-4577

PHP

PHP Group

Attempts
2,693
Attacker IPs
250
Sensors
31
CVE-2026-63030

WordPress

WordPress

Attempts
1,207
Attacker IPs
62
Sensors
21
CVE-2026-57739

AcyMailing SMTP Newsletter

AcyMailing Newsletter Team

Attempts
878
Attacker IPs
14
Sensors
15
CVE-2021-41773

Apache HTTP Server

Apache Software Foundation

Attempts
839
Attacker IPs
312
Sensors
30
CVE-2018-20062

NoneCms

NoneCms

Attempts
661
Attacker IPs
142
Sensors
31
CVE-2022-47945

ThinkPHP Framework

ThinkPHP

Attempts
616
Attacker IPs
137
Sensors
30
CVE-2026-9198

Langflow OSS

IBM

Attempts
82
Attacker IPs
61
Sensors
12
CVE-2024-20767

ColdFusion

Adobe

Attempts
73
Attacker IPs
29
Sensors
28
CVE-2026-4020

Gravity SMTP

RocketGenius

Attempts
70
Attacker IPs
41
Sensors
24
CVE-2026-0770

Langflow

Langflow

Attempts
47
Attacker IPs
24
Sensors
11
CVE-2022-41040

Microsoft Exchange Server 2013 Cumulative Update 23, Microsoft Exchange Server 2016 Cumulative Update 22, Microsoft Exchange Server 2019 Cumulative Update 11, Microsoft Exchange Server 2019 Cumulative Update 12, Microsoft Exchange Server 2016 Cumulative Update 23

Microsoft

Attempts
45
Attacker IPs
45
Sensors
26
CVE-2024-12847

DGN1000

NETGEAR

Attempts
43
Attacker IPs
30
Sensors
17
CVE-2026-73570

Collaboration

Zimbra

Attempts
39
Attacker IPs
2
Sensors
1
CVE-2018-10562

GPON home routers

Dasan

Attempts
39
Attacker IPs
35
Sensors
20
CVE-2013-2251

Struts

Apache

Attempts
36
Attacker IPs
3
Sensors
3
CVE-2026-8037

LoadMaster, ECS Connections Manager, Object Scale Connection Manager, MOVEit WAF

Progress Software

Attempts
32
Attacker IPs
5
Sensors
2
CVE-2026-55040

Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition

Microsoft

Attempts
31
Attacker IPs
10
Sensors
2
CVE-2023-1389

TP-Link Archer AX21 (AX1800)

TP-Link

Attempts
29
Attacker IPs
3
Sensors
14
CVE-2020-3452

Cisco Adaptive Security Appliance (ASA) Software

Cisco

Attempts
26
Attacker IPs
16
Sensors
10
CVE-2026-35273

PeopleSoft Enterprise PeopleTools

Oracle Corporation

Attempts
25
Attacker IPs
7
Sensors
2
CVE-2025-29635

DIR-823X

D-Link

Attempts
24
Attacker IPs
2
Sensors
12
CVE-2026-8452

ADC, Gateway

NetScaler

Attempts
18
Attacker IPs
5
Sensors
1
CVE-2019-12725

Zeroshell

Zeroshell

Attempts
17
Attacker IPs
2
Sensors
4
CVE-2018-13379

Fortinet FortiOS, FortiProxy

Fortinet

Attempts
15
Attacker IPs
10
Sensors
6
CVE-2025-8943

Flowise

Flowise

Attempts
12
Attacker IPs
8
Sensors
3
CVE-2014-2383

dompdf

dompdf

Attempts
11
Attacker IPs
1
Sensors
1
CVE-2024-4879

Now Platform

ServiceNow

Attempts
11
Attacker IPs
7
Sensors
3
CVE-2025-1302

jsonpath-plus

JSONPath-Plus

Attempts
10
Attacker IPs
2
Sensors
2
CVE-2026-33017

langflow

langflow-ai

Attempts
10
Attacker IPs
2
Sensors
1
CVE-2017-10271

WebLogic Server

Oracle Corporation

Attempts
10
Attacker IPs
3
Sensors
3
CVE-2026-46442

Flowise

FlowiseAI

Attempts
10
Attacker IPs
3
Sensors
1
CVE-2024-3721

DVR-4104, DVR-4216

TBK

Attempts
9
Attacker IPs
2
Sensors
9
CVE-2024-8181

Flowise

FlowiseAI

Attempts
8
Attacker IPs
5
Sensors
3
CVE-2023-2825

GitLab

GitLab

Attempts
8
Attacker IPs
2
Sensors
1
CVE-2021-41277

metabase

metabase

Attempts
7
Attacker IPs
5
Sensors
4
CVE-2023-4966

NetScaler ADC, NetScaler Gateway

Citrix

Attempts
6
Attacker IPs
6
Sensors
2
CVE-2026-39808

FortiSandbox, FortiSandbox PaaS

Fortinet

Attempts
6
Attacker IPs
3
Sensors
1
CVE-2026-46817

Oracle Payments

Oracle Corporation

Attempts
6
Attacker IPs
2
Sensors
1
CVE-2022-21587

Web Applications Desktop Integrator

Oracle Corporation

Attempts
5
Attacker IPs
2
Sensors
2
CVE-2025-5777

ADC, Gateway

NetScaler

Attempts
5
Attacker IPs
4
Sensors
1
CVE-2023-20198

Cisco IOS XE Software

Cisco

Attempts
5
Attacker IPs
2
Sensors
2
CVE-2026-29059

windmill

windmill-labs

Attempts
4
Attacker IPs
1
Sensors
1

Showing 50 of 50 highest-volume records · 18 Aug–25 Aug 2026 UTC

Early warning alerts

Get alerts on high-impact exploitation

Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.