KEV Intelligence is becoming Previdian.

Exploitation intelligence

Observed Exploitation Signals

Sensor-backed exploitation attempts against internet-facing services, mapped to vulnerabilities and reviewed for confidence. See where attacker activity is concentrating before severity scores alone tell the story.

KEVs Observed
157
Known exploited vulnerabilities seen in the selected window
Exploitation Events
135,324
Attempts mapped to tracked vulnerabilities across the sensor network
Attacker IPs
Unique source addresses observed in the selected window

Exploitation Attempts

90-day activity, grouped by observation date · 27 May–25 Aug 2026 UTC

Exploitation Attempts

90-day activity, grouped by observation date

0
0
0
0
0
0
0
0
0
0
0
0
23
25
49
365
134
87
536
232
370
341
176
168
366
312
682
95
130
171
183
287
92
741
526
939
361
10,886
581
439
437
443
584
693
661
805
572
759
779
1,163
796
598
917
2,790
2,414
2,651
2,667
1,915
1,725
2,171
2,354
2,928
1,727
1,341
2,636
2,765
2,536
2,983
2,825
2,545
3,221
2,605
6,529
2,953
2,372
584
1,082
1,037
980
1,286
672
621
1,605
1,642
1,388
2,365
6,912
7,186
4,852
13,082
2,873
27 May 15 Jun 4 Jul 23 Jul 25 Aug

Click a day to filter stats and tables to that date.

Where Exploitation Activity Concentrated

The highest-volume vulnerabilities in this snapshot, ranked by mapped exploitation attempts—not theoretical severity.

Inspect full KEV record

PHPUnit

PHPUnit

Attempts
53,747
Attackers
Sensors

react-server-dom-webpack, react-server-dom-turbopack, react-server-dom-parcel

Meta

Attempts
12,907
Attackers
Sensors

PHP

PHP Group

Attempts
8,514
Attackers
Sensors

Sentry

ivanti

Attempts
8,271
Attackers
Sensors

Apache HTTP Server

Apache Software Foundation

Attempts
7,430
Attackers
Sensors

ThinkPHP Framework

ThinkPHP

Attempts
7,139
Attackers
Sensors

Observed Exploitation Attempts

Search the highest-volume records in the selected window. Each row shows activity breadth and recency alongside raw volume.

How to Read the Signal

Attempts indicate volume. Unique IPs and sensors indicate breadth. First and last seen show persistence. Use the linked CVE record for evidence and remediation context.

CVE-2025-55182

react-server-dom-webpack, react-server-dom-turbopack, react-server-dom-parcel

Meta

Attempts
12,907
Attacker IPs
CVE-2021-41773

Apache HTTP Server

Apache Software Foundation

Attempts
7,430
Attacker IPs
CVE-2022-47945

ThinkPHP Framework

ThinkPHP

Attempts
7,139
Attacker IPs
CVE-2026-8451

ADC, Gateway

NetScaler

Attempts
6,677
Attacker IPs
CVE-2026-0770

Langflow

Langflow

Attempts
2,082
Attacker IPs
CVE-2026-8037

LoadMaster, ECS Connections Manager, Object Scale Connection Manager, MOVEit WAF

Progress Software

Attempts
1,670
Attacker IPs
CVE-2026-20230

Cisco Unified Communications Manager

Cisco

Attempts
1,321
Attacker IPs
CVE-2026-20253

Splunk Enterprise

Splunk

Attempts
1,260
Attacker IPs
CVE-2026-35273

PeopleSoft Enterprise PeopleTools

Oracle Corporation

Attempts
1,091
Attacker IPs
CVE-2026-46817

Oracle Payments

Oracle Corporation

Attempts
1,014
Attacker IPs
CVE-2026-57739

AcyMailing SMTP Newsletter

AcyMailing Newsletter Team

Attempts
878
Attacker IPs
CVE-2022-41040

Microsoft Exchange Server 2013 Cumulative Update 23, Microsoft Exchange Server 2016 Cumulative Update 22, Microsoft Exchange Server 2019 Cumulative Update 11, Microsoft Exchange Server 2019 Cumulative Update 12, Microsoft Exchange Server 2016 Cumulative Update 23

Microsoft

Attempts
601
Attacker IPs
CVE-2026-39808

FortiSandbox, FortiSandbox PaaS

Fortinet

Attempts
574
Attacker IPs
CVE-2026-4020

Gravity SMTP

RocketGenius

Attempts
563
Attacker IPs
CVE-2026-55040

Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition

Microsoft

Attempts
405
Attacker IPs
CVE-2018-10562

GPON home routers

Dasan

Attempts
389
Attacker IPs
CVE-2017-18368

P660HN-T1A v1 TCLinux Fw

ZyXEL

Attempts
377
Attacker IPs
CVE-2020-14882

WebLogic Server

Oracle Corporation

Attempts
363
Attacker IPs
CVE-2025-61882

Oracle Concurrent Processing

Oracle Corporation

Attempts
276
Attacker IPs
CVE-2026-48282

ColdFusion 2025, ColdFusion 2023

Adobe

Attempts
258
Attacker IPs
CVE-2018-13379

Fortinet FortiOS, FortiProxy

Fortinet

Attempts
246
Attacker IPs
CVE-2023-1389

TP-Link Archer AX21 (AX1800)

TP-Link

Attempts
234
Attacker IPs
CVE-2020-3452

Cisco Adaptive Security Appliance (ASA) Software

Cisco

Attempts
202
Attacker IPs
CVE-2017-10271

WebLogic Server

Oracle Corporation

Attempts
188
Attacker IPs
CVE-2023-26801

BL-AC1900_2.0, BL-WR9000, BL-X26, BL-LTE300

LB-LINK

Attempts
173
Attacker IPs
CVE-2017-9822

DotNetNuke CMS Fixed in 9.1.1

DotNetNuke

Attempts
164
Attacker IPs
CVE-2025-1302

jsonpath-plus

JSONPath-Plus

Attempts
136
Attacker IPs
CVE-2020-17518

Apache Flink

Apache Software Foundation

Attempts
116
Attacker IPs
CVE-2023-20198

Cisco IOS XE Software

Cisco

Attempts
116
Attacker IPs
CVE-2025-34037

E4200, E3200, E3000, E2500 v1/v2, E2100L v1, E2000, E1550, E1500 v1, E1200 v1, E1000 v1, E900 v1

Linksys

Attempts
116
Attacker IPs
CVE-2020-14883

WebLogic Server

Oracle Corporation

Attempts
99
Attacker IPs

Showing 50 of 50 highest-volume records · 27 May–25 Aug 2026 UTC

Early warning alerts

Get alerts on high-impact exploitation

Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.