Sensor-led exploitation intelligence

Your early warning for vulnerabilities moving into active exploitation.

KEV Intelligence uses proprietary sensors and private honeypots to surface active exploitation, corroborated by vendor advisories and public evidence. Inspect the evidence, prioritize with confidence, and act sooner.

Start with the free live feed, RSS, and JSON. Pro adds deeper evidence, telemetry, and integration-ready context.

Live sensor activity

Exploitation activity observed across KEV Intelligence sensors during the last 7 days.

Live telemetry

74

KEVs observed

4,698

Exploitation events

840

Attacker IPs

View exploitation signals

Earlier visibility, backed by evidence

2,726
High-confidence records

Exploitation records supported by strong, inspectable evidence

1,061
Beyond CISA KEV

Exploited vulnerabilities missing from CISA’s catalog

74
Observed in sensors

Tracked KEVs seen across proprietary sensors in the last 7 days

1,864+
Actionable artifacts

PoCs, Nuclei, Metasploit, and virtual-patch context

Early warning alerts

Get alerts on high-impact exploitation

Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.

Evidence depth

Early warning your team can verify

Every warning connects the exploitation verdict to inspectable evidence, confidence, available sensor telemetry, affected versions, and practical security artifacts.

Browse exploited CVEs

Verified vulnerability record

CVE-2026-33497

langflow · affected before 1.7.1

Confirmed confidence

Version 1.7.1 contains a patch

Sensor telemetry

1 attempt · 1 sensor

First-party observations recorded across 1 attacker IP.

Evidence

Active exploitation observed

Independent exploitation attestation added to the KEV Intelligence record.

Actionable artifact

Nuclei template available

Public scanner coverage helps validate exposed systems.

Evidence, telemetry, and action stay attached to the CVE.

Browse exploited CVEs →

Intelligence system

How exploitation signals become trusted warnings

KEV Intelligence observes exploitation through proprietary sensors and private honeypots, corroborates signals against vendor advisories and public evidence, and keeps the evidence chain attached as warnings move into operational workflows.

  1. 01

    Observe

    Proprietary sensors and private honeypots surface exploitation activity, supported by vendor advisories and relevant public evidence.

  2. 02

    Attest

    Evaluate source credibility, specificity, corroboration, and available first-party telemetry.

  3. 03

    Enrich

    Add EPSS, CVSS, CWE, affected-version context, PoCs, Nuclei, Metasploit, and virtual-patch context.

  4. 04

    Deliver

    Send trusted warnings through the live feed, email alerts, RSS, JSON, and Pro API.

  5. 74 KEVs observed in sensors (7d)

    Evidence remains inspectable at every stage

Built to act

Turn earlier visibility into faster security action

Explore use cases

Act on exploitation sooner

See active exploitation earlier. Prioritize it with evidence.

Start with the free live feed, then add deeper telemetry, confidence, and automation through the Pro API.