Meta — Meta React Server Components Remote Code Execution Vulnerability
Why it matters: Listed in the CISA KEV catalog, and an EPSS probability of 0.998.
Find. Rank. Fix. Prove.
Microsoft's latest Patch Tuesday release and every non-Microsoft CISA-confirmed actively-exploited advisory, ranked together by real-world exploitation rather than severity alone — so a CVSS 9.8 with no known exploitation signal does not outrank the 7.5 confirmed in active ransomware campaigns.
Data as of 07 Sep 03:54 UTC — last checked against CISA KEV (07 Sep 03:54 UTC, re-checked every 6 h), Microsoft (07 Sep 03:54 UTC, re-checked every 6 h) and FIRST EPSS (07 Sep 03:54 UTC, re-checked every 12 h). Source publication dates are under the feed.
Four cuts that move independently of one another. "Actively exploited" and "Critical/High risk" are not among them on purpose: every KEV item is actively exploited by construction and the exploited floor puts every one of them in the High band or above, so both would have reported the same number as each other, twice.
Exigent is a floor, not a census: CISA publishes no CVSS, so an entry whose score has not been resolved cannot qualify however severe it turns out to be. Resolution runs in the background and its results are kept between restarts, so this figure reflects coverage as much as exposure — a rise can mean more entries have been scored, not that more are exploited.
Ranked by risk, not by date. Entries from previous years appear at the top when they are still being exploited — that is the point, not an oversight. For what changed recently, use the New to CISA KEV cut above. The highest EVULNABLE Risk items across both sources, ranked on one scale. Ties are broken by FIRST EPSS and then CVE ID, so the order is stable between visits rather than reshuffling under you. A CISA KEV listing is the confirmation of active exploitation, so KEV cards say it once as their source rather than repeating it as a second pill.
Showing the top 10 of 1,757 tracked items, ranked by EVULNABLE Risk.
Why it matters: Listed in the CISA KEV catalog, and an EPSS probability of 0.998.
Why it matters: Listed in the CISA KEV catalog, and an EPSS probability of 0.955.
Intelligence coverage 75/90 — no pre-patch disclosure dataWhy it matters: Listed in the CISA KEV catalog, and an EPSS probability of 0.998.
Intelligence coverage 75/90 — no pre-patch disclosure dataWhy it matters: Listed in the CISA KEV catalog, and an EPSS probability of 0.997.
Intelligence coverage 75/90 — no pre-patch disclosure dataWhy it matters: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.
Intelligence coverage 75/90 — no pre-patch disclosure dataWhy it matters: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.
Intelligence coverage 75/90 — no pre-patch disclosure dataWhy it matters: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.
Intelligence coverage 75/90 — no pre-patch disclosure dataWhy it matters: Listed in the CISA KEV catalog, and an EPSS probability of 0.995.
Intelligence coverage 75/90 — no pre-patch disclosure dataWhy it matters: Listed in the CISA KEV catalog, and an EPSS probability of 0.985.
Intelligence coverage 75/90 — no pre-patch disclosure dataWhy it matters: Listed in the CISA KEV catalog, and an EPSS probability of 0.963.
Intelligence coverage 75/90 — no pre-patch disclosure dataFor the full browsers — this month's Microsoft release, the CISA KEV catalog, Linux distribution advisories and vendor security bulletins — open Patch Advisories. The Linux and bulletin feeds are not folded into this ranked list: they carry CVSS and FIRST EPSS too inconsistently to score fairly on one scale, and a fabricated score is worse than a separate section.
Exigent is a flag layered on Immediate, not a sixth band — it is counted beside the bar rather than as a slice, which would both double-count those items and imply a band above Immediate.
CISA publishes a federal remediation due date with each KEV entry. Those dates are binding remediation targets for U.S. Federal Civilian Executive Branch agencies under applicable CISA directives; other organizations commonly use them as prioritization guidance. The catalog reaches back to 2021, so “past deadline” is its normal condition rather than an alarm, and it is shown here rather than as a headline number that would have repeated the tracked-items count. The band worth acting on this week is the small one due within 7 days. Patch Tuesday CVEs carry no CISA deadline at all.