Exploitation intelligence

Observed Exploitation Signals

Sensor-backed exploitation attempts against internet-facing services, mapped to CVEs and reviewed for confidence. See where attacker activity is concentrating before severity scores alone tell the story.

KEVs Observed
90
Known exploited vulnerabilities seen in the selected window
Exploitation Events
4,733
Attempts mapped to tracked CVEs across the sensor network
Attacker IPs
759
Unique source addresses observed in the selected window

Exploitation Attempts

Seven-day activity, grouped by observation date · 08 Aug–15 Aug 2026 UTC

Exploitation Attempts

Seven-day activity, grouped by observation date

604
475
401
829
700
740
965
19
8 Aug 9 Aug 10 Aug 11 Aug 12 Aug 13 Aug 14 Aug 15 Aug

Click a day to filter stats and tables to that date.

Where Exploitation Activity Concentrated

The highest-volume CVEs in this snapshot, ranked by mapped exploitation attempts—not theoretical severity.

Inspect full KEV record

WordPress

WordPress

Attempts
911
Attackers
43
Sensors
2

NoneCms

NoneCms

Attempts
730
Attackers
159
Sensors
30

ThinkPHP Framework

ThinkPHP

Attempts
695
Attackers
150
Sensors
29

Apache HTTP Server

Apache Software Foundation

Attempts
634
Attackers
211
Sensors
30

Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition

Microsoft

Attempts
366
Attackers
22
Sensors
1

react-server-dom-webpack, react-server-dom-turbopack, react-server-dom-parcel

Meta

Attempts
294
Attackers
21
Sensors
10

Observed Exploitation Attempts

Search the highest-volume records in the selected window. Each row shows activity breadth and recency alongside raw volume.

How to Read the Signal

Attempts indicate volume. Unique IPs and sensors indicate breadth. First and last seen show persistence. Use the linked CVE record for evidence and remediation context.

CVE-2026-63030

WordPress

WordPress

Attempts
911
Attacker IPs
43
Sensors
2
CVE-2018-20062

NoneCms

NoneCms

Attempts
730
Attacker IPs
159
Sensors
30
CVE-2022-47945

ThinkPHP Framework

ThinkPHP

Attempts
695
Attacker IPs
150
Sensors
29
CVE-2021-41773

Apache HTTP Server

Apache Software Foundation

Attempts
634
Attacker IPs
211
Sensors
30
CVE-2026-55040

Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition

Microsoft

Attempts
366
Attacker IPs
22
Sensors
1
CVE-2025-55182

react-server-dom-webpack, react-server-dom-turbopack, react-server-dom-parcel

Meta

Attempts
294
Attacker IPs
21
Sensors
10
CVE-2026-9198

Langflow OSS

IBM

Attempts
160
Attacker IPs
99
Sensors
18
CVE-2026-8037

LoadMaster, ECS Connections Manager, Object Scale Connection Manager, MOVEit WAF

Progress Software

Attempts
131
Attacker IPs
14
Sensors
3
CVE-2026-0770

Langflow

Langflow

Attempts
110
Attacker IPs
43
Sensors
9
CVE-2022-41040

Microsoft Exchange Server 2013 Cumulative Update 23, Microsoft Exchange Server 2016 Cumulative Update 22, Microsoft Exchange Server 2019 Cumulative Update 11, Microsoft Exchange Server 2019 Cumulative Update 12, Microsoft Exchange Server 2016 Cumulative Update 23

Microsoft

Attempts
87
Attacker IPs
85
Sensors
30
CVE-2018-10562

GPON home routers

Dasan

Attempts
38
Attacker IPs
38
Sensors
20
CVE-2024-12847

DGN1000

NETGEAR

Attempts
38
Attacker IPs
38
Sensors
21
CVE-2024-20767

ColdFusion

Adobe

Attempts
36
Attacker IPs
15
Sensors
12
CVE-2026-4020

Gravity SMTP

RocketGenius

Attempts
36
Attacker IPs
21
Sensors
14
CVE-2018-13379

Fortinet FortiOS, FortiProxy

Fortinet

Attempts
31
Attacker IPs
28
Sensors
25
CVE-2017-18368

P660HN-T1A v1 TCLinux Fw

ZyXEL

Attempts
30
Attacker IPs
13
Sensors
1
CVE-2020-3452

Cisco Adaptive Security Appliance (ASA) Software

Cisco

Attempts
28
Attacker IPs
28
Sensors
25
CVE-2026-20253

Splunk Enterprise

Splunk

Attempts
19
Attacker IPs
3
Sensors
1
CVE-2025-8943

Flowise

Flowise

Attempts
18
Attacker IPs
10
Sensors
2
CVE-2025-1302

jsonpath-plus

JSONPath-Plus

Attempts
14
Attacker IPs
1
Sensors
1
CVE-2014-2383

dompdf

dompdf

Attempts
14
Attacker IPs
11
Sensors
1
CVE-2013-2251

Struts

Apache

Attempts
13
Attacker IPs
8
Sensors
1
CVE-2026-49049

Helix3 extension for Joomla

joomshaper.com

Attempts
10
Attacker IPs
1
Sensors
1
CVE-2017-10271

WebLogic Server

Oracle Corporation

Attempts
8
Attacker IPs
4
Sensors
2
CVE-2025-20282

Cisco Identity Services Engine Software

Cisco

Attempts
6
Attacker IPs
5
Sensors
1
CVE-2026-34910

UniFi OS Server, UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, UDM-Beast, EFG, UDW, UDR, UDR7, UDR-5G, Express 7, UNVR, UNVR-Pro, UNVR-Instant, UNVR-G2, UNVR-G2-Pro, ENVR, ENVR-Core, UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4, UNAS-Pro-8, UCKP, UCK, UCK-Enterprise, UCG-Ultra, UCG-Max, UCG-Fiber, UCG-Industrial

Ubiquiti Inc

Attempts
5
Attacker IPs
2
Sensors
2
CVE-2013-3821

PeopleSoft Products

Oracle

Attempts
5
Attacker IPs
1
Sensors
1
CVE-2025-31324

SAP NetWeaver (Visual Composer development server)

SAP_SE

Attempts
5
Attacker IPs
2
Sensors
2
CVE-2025-5777

ADC, Gateway

NetScaler

Attempts
4
Attacker IPs
3
Sensors
1
CVE-2024-24919

Check Point Quantum Gateway, Spark Gateway and CloudGuard Network

checkpoint

Attempts
4
Attacker IPs
4
Sensors
1
CVE-2022-21587

Web Applications Desktop Integrator

Oracle Corporation

Attempts
4
Attacker IPs
1
Sensors
1
CVE-2026-46442

Flowise

FlowiseAI

Attempts
4
Attacker IPs
2
Sensors
1
CVE-2020-14882

WebLogic Server

Oracle Corporation

Attempts
4
Attacker IPs
1
Sensors
1
CVE-2026-29059

windmill

windmill-labs

Attempts
4
Attacker IPs
1
Sensors
1
CVE-2026-55450

langflow

langflow-ai

Attempts
4
Attacker IPs
3
Sensors
2
CVE-2024-37014

Langflow

langflow-ai

Attempts
4
Attacker IPs
3
Sensors
1
CVE-2026-5027

langflow

langflow-ai

Attempts
4
Attacker IPs
3
Sensors
1
CVE-2023-4966

NetScaler ADC, NetScaler Gateway

Citrix

Attempts
3
Attacker IPs
2
Sensors
1
CVE-2025-2505

Age Gate

philsbury

Attempts
3
Attacker IPs
2
Sensors
2
CVE-2025-20281

Cisco Identity Services Engine Software

Cisco

Attempts
3
Attacker IPs
3
Sensors
2
CVE-2020-14883

WebLogic Server

Oracle Corporation

Attempts
3
Attacker IPs
1
Sensors
1
CVE-2026-35273

PeopleSoft Enterprise PeopleTools

Oracle Corporation

Attempts
2
Attacker IPs
2
Sensors
2
CVE-2026-15409

SMA1000

SonicWall

Attempts
2
Attacker IPs
2
Sensors
2

Showing 50 of 50 highest-volume records · 08 Aug–15 Aug 2026 UTC

Early warning alerts

Get alerts on high-impact exploitation

Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.