Exploitation intelligence

Observed Exploitation Signals

Sensor-backed exploitation attempts against internet-facing services, mapped to CVEs and reviewed for confidence. See where attacker activity is concentrating before severity scores alone tell the story.

KEVs Observed
28
Known exploited vulnerabilities seen in the selected window
Exploitation Events
960
Attempts mapped to tracked CVEs across the sensor network
Attacker IPs
167
Unique source addresses observed in the selected window

Exploitation Attempts

24-hour activity, grouped by observation date · 14 Aug–15 Aug 2026 UTC

Exploitation Attempts

24-hour activity, grouped by observation date

952
8
14 Aug 15 Aug

Click a day to filter stats and tables to that date.

Where Exploitation Activity Concentrated

The highest-volume CVEs in this snapshot, ranked by mapped exploitation attempts—not theoretical severity.

Inspect full KEV record

WordPress

WordPress

Attempts
270
Attackers
9
Sensors
1

Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition

Microsoft

Attempts
210
Attackers
14
Sensors
1

NoneCms

NoneCms

Attempts
126
Attackers
41
Sensors
27

ThinkPHP Framework

ThinkPHP

Attempts
122
Attackers
40
Sensors
26

Apache HTTP Server

Apache Software Foundation

Attempts
109
Attackers
67
Sensors
27

Microsoft Exchange Server 2013 Cumulative Update 23, Microsoft Exchange Server 2016 Cumulative Update 22, Microsoft Exchange Server 2019 Cumulative Update 11, Microsoft Exchange Server 2019 Cumulative Update 12, Microsoft Exchange Server 2016 Cumulative Update 23

Microsoft

Attempts
25
Attackers
25
Sensors
25

Observed Exploitation Attempts

Search the highest-volume records in the selected window. Each row shows activity breadth and recency alongside raw volume.

How to Read the Signal

Attempts indicate volume. Unique IPs and sensors indicate breadth. First and last seen show persistence. Use the linked CVE record for evidence and remediation context.

CVE-2026-63030

WordPress

WordPress

Attempts
270
Attacker IPs
9
Sensors
1
CVE-2026-55040

Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition

Microsoft

Attempts
210
Attacker IPs
14
Sensors
1
CVE-2018-20062

NoneCms

NoneCms

Attempts
126
Attacker IPs
41
Sensors
27
CVE-2022-47945

ThinkPHP Framework

ThinkPHP

Attempts
122
Attacker IPs
40
Sensors
26
CVE-2021-41773

Apache HTTP Server

Apache Software Foundation

Attempts
109
Attacker IPs
67
Sensors
27
CVE-2022-41040

Microsoft Exchange Server 2013 Cumulative Update 23, Microsoft Exchange Server 2016 Cumulative Update 22, Microsoft Exchange Server 2019 Cumulative Update 11, Microsoft Exchange Server 2019 Cumulative Update 12, Microsoft Exchange Server 2016 Cumulative Update 23

Microsoft

Attempts
25
Attacker IPs
25
Sensors
25
CVE-2025-55182

react-server-dom-webpack, react-server-dom-turbopack, react-server-dom-parcel

Meta

Attempts
23
Attacker IPs
5
Sensors
3
CVE-2026-9198

Langflow OSS

IBM

Attempts
10
Attacker IPs
10
Sensors
1
CVE-2018-10562

GPON home routers

Dasan

Attempts
8
Attacker IPs
8
Sensors
8
CVE-2025-8943

Flowise

Flowise

Attempts
6
Attacker IPs
3
Sensors
1
CVE-2020-3452

Cisco Adaptive Security Appliance (ASA) Software

Cisco

Attempts
6
Attacker IPs
6
Sensors
5
CVE-2017-10271

WebLogic Server

Oracle Corporation

Attempts
5
Attacker IPs
1
Sensors
1
CVE-2018-13379

Fortinet FortiOS, FortiProxy

Fortinet

Attempts
5
Attacker IPs
5
Sensors
5
CVE-2020-14882

WebLogic Server

Oracle Corporation

Attempts
4
Attacker IPs
1
Sensors
1
CVE-2026-0770

Langflow

Langflow

Attempts
4
Attacker IPs
3
Sensors
1
CVE-2026-4020

Gravity SMTP

RocketGenius

Attempts
3
Attacker IPs
3
Sensors
2
CVE-2020-14883

WebLogic Server

Oracle Corporation

Attempts
3
Attacker IPs
1
Sensors
1
CVE-2026-58231

SAP Commerce Cloud (Data Hub Adapter)

SAP_SE

Attempts
2
Attacker IPs
1
Sensors
1
CVE-2017-18368

P660HN-T1A v1 TCLinux Fw

ZyXEL

Attempts
1
Attacker IPs
1
Sensors
1
CVE-2023-4966

NetScaler ADC, NetScaler Gateway

Citrix

Attempts
1
Attacker IPs
1
Sensors
1
CVE-2026-55255

langflow

langflow-ai

Attempts
1
Attacker IPs
1
Sensors
1
CVE-2026-8451

ADC, Gateway

NetScaler

Attempts
1
Attacker IPs
1
Sensors
1
CVE-2026-8037

LoadMaster, ECS Connections Manager, Object Scale Connection Manager, MOVEit WAF

Progress Software

Attempts
1
Attacker IPs
1
Sensors
1

Showing 28 of 28 highest-volume records · 14 Aug–15 Aug 2026 UTC

Early warning alerts

Get alerts on high-impact exploitation

Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.