Find. Rank. Fix. Prove.

Know What To Patch First

Microsoft's latest Patch Tuesday release and every non-Microsoft CISA-confirmed actively-exploited advisory, ranked together by real-world exploitation rather than severity alone — so a CVSS 9.8 with no known exploitation signal does not outrank the 7.5 confirmed in active ransomware campaigns.

At a glance

Data as of 07 Sep 03:54 UTC — last checked against CISA KEV (07 Sep 03:54 UTC, re-checked every 6 h), Microsoft (07 Sep 03:54 UTC, re-checked every 6 h) and FIRST EPSS (07 Sep 03:54 UTC, re-checked every 12 h). Source publication dates are under the feed.

How to read these four numbers

Four cuts that move independently of one another. "Actively exploited" and "Critical/High risk" are not among them on purpose: every KEV item is actively exploited by construction and the exploited floor puts every one of them in the High band or above, so both would have reported the same number as each other, twice.

Exigent is a floor, not a census: CISA publishes no CVSS, so an entry whose score has not been resolved cannot qualify however severe it turns out to be. Resolution runs in the background and its results are kept between restarts, so this figure reflects coverage as much as exposure — a rise can mean more entries have been scored, not that more are exploited.

Priority feed

Ranked by risk, not by date. Entries from previous years appear at the top when they are still being exploited — that is the point, not an oversight. For what changed recently, use the New to CISA KEV cut above. The highest EVULNABLE Risk items across both sources, ranked on one scale. Ties are broken by FIRST EPSS and then CVE ID, so the order is stable between visits rather than reshuffling under you. A CISA KEV listing is the confirmation of active exploitation, so KEV cards say it once as their source rather than repeating it as a second pill.

Showing the top 10 of 1,757 tracked items, ranked by EVULNABLE Risk.

1 Highest risk right now
EVULNABLE Risk · priority 97/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data
CVE-2025-55182
ExigentOverdue by 9 monthsRansomwareCISA KEV

Meta — Meta React Server Components Remote Code Execution Vulnerability

CVSS 10.0 (NVD)EPSS 0.998 (99.96th pctl)KEV since 2025-12-05

Why it matters: Listed in the CISA KEV catalog, and an EPSS probability of 0.998.

Out-of-Band / Urgent Remediation
  1. 2 97 Immediate CVE-2026-35273 ExigentOverdue by 3 monthsRansomwareCISA KEV Oracle — Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability Out-of-Band / Urgent Remediation
    CVSS 9.8 (NVD)EPSS 0.955 (99.86th pctl)KEV since 2026-06-12

    Why it matters: Listed in the CISA KEV catalog, and an EPSS probability of 0.955.

    Intelligence coverage 75/90 — no pre-patch disclosure data
  2. 3 96 Immediate CVE-2025-10035 ExigentOverdue by 11 monthsRansomwareCISA KEV Fortra — Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability Out-of-Band / Urgent Remediation
    CVSS 9.8 (NVD)EPSS 0.998 (99.96th pctl)KEV since 2025-09-29

    Why it matters: Listed in the CISA KEV catalog, and an EPSS probability of 0.998.

    Intelligence coverage 75/90 — no pre-patch disclosure data
  3. 4 96 Immediate CVE-2025-61882 ExigentOverdue by 10 monthsRansomwareCISA KEV Oracle — Oracle E-Business Suite Unspecified Vulnerability Out-of-Band / Urgent Remediation
    CVSS 9.8 (NVD)EPSS 0.997 (99.95th pctl)KEV since 2025-10-06

    Why it matters: Listed in the CISA KEV catalog, and an EPSS probability of 0.997.

    Intelligence coverage 75/90 — no pre-patch disclosure data
  4. 5 95 Immediate CVE-2025-3248 ExigentOverdue by 15 monthsRansomwareCISA KEV Langflow — Langflow Missing Authentication Vulnerability Out-of-Band / Urgent Remediation
    CVSS 9.8 (NVD)EPSS 0.999 (99.98th pctl)KEV since 2025-05-05

    Why it matters: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.

    Intelligence coverage 75/90 — no pre-patch disclosure data
  5. 6 95 Immediate CVE-2025-22457 ExigentOverdue by 17 monthsRansomwareCISA KEV Ivanti — Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability Out-of-Band / Urgent Remediation
    CVSS 9.8 (NVD)EPSS 0.999 (99.98th pctl)KEV since 2025-04-04

    Why it matters: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.

    Intelligence coverage 75/90 — no pre-patch disclosure data
  6. 7 95 Immediate CVE-2025-31161 ExigentOverdue by 16 monthsRansomwareCISA KEV CrushFTP — CrushFTP Authentication Bypass Vulnerability Out-of-Band / Urgent Remediation
    CVSS 9.8 (NVD)EPSS 0.999 (99.98th pctl)KEV since 2025-04-07

    Why it matters: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.

    Intelligence coverage 75/90 — no pre-patch disclosure data
  7. 8 95 Immediate CVE-2025-31324 ExigentOverdue by 16 monthsRansomwareCISA KEV SAP — SAP NetWeaver Unrestricted File Upload Vulnerability Out-of-Band / Urgent Remediation
    CVSS 9.8 (NVD)EPSS 0.995 (99.94th pctl)KEV since 2025-04-29

    Why it matters: Listed in the CISA KEV catalog, and an EPSS probability of 0.995.

    Intelligence coverage 75/90 — no pre-patch disclosure data
  8. 9 95 Immediate CVE-2026-41940 ExigentOverdue by 4 monthsRansomwareCISA KEV WebPros — WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability Out-of-Band / Urgent Remediation
    CVSS 9.3 (NVD)EPSS 0.985 (99.92nd pctl)KEV since 2026-04-30

    Why it matters: Listed in the CISA KEV catalog, and an EPSS probability of 0.985.

    Intelligence coverage 75/90 — no pre-patch disclosure data
  9. 10 95 Immediate CVE-2026-23760 ExigentOverdue by 7 monthsRansomwareCISA KEV SmarterTools — SmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel Vulnerability Out-of-Band / Urgent Remediation
    CVSS 9.3 (NVD)EPSS 0.963 (99.88th pctl)KEV since 2026-01-26

    Why it matters: Listed in the CISA KEV catalog, and an EPSS probability of 0.963.

    Intelligence coverage 75/90 — no pre-patch disclosure data

For the full browsers — this month's Microsoft release, the CISA KEV catalog, Linux distribution advisories and vendor security bulletins — open Patch Advisories. The Linux and bulletin feeds are not folded into this ranked list: they carry CVSS and FIRST EPSS too inconsistently to score fairly on one scale, and a fabricated score is worse than a separate section.

The shape of the backlog

By EVULNABLE Risk band

Immediate 458 26% · 85-100 Urgent 852 48% · 65-84 Elevated 387 22% · 10-64 Routine 59 3% · 4-9 Informational 1 <1% · 0-3 Exigent flag 358 counted within Immediate

Exigent is a flag layered on Immediate, not a sixth band — it is counted beside the bar rather than as a slice, which would both double-count those items and imply a band above Immediate.

Against CISA’s remediation deadline

Due within 7 days 7 <1% Due in 8–30 days 3 <1% Due later 0 0% Past CISA deadline 1,299 73% No CISA deadline 448 25%

CISA publishes a federal remediation due date with each KEV entry. Those dates are binding remediation targets for U.S. Federal Civilian Executive Branch agencies under applicable CISA directives; other organizations commonly use them as prioritization guidance. The catalog reaches back to 2021, so “past deadline” is its normal condition rather than an alarm, and it is shown here rather than as a headline number that would have repeated the tracked-items count. The band worth acting on this week is the small one due within 7 days. Patch Tuesday CVEs carry no CISA deadline at all.

Built from dates as published by each source
Microsoft Security Updates
August 2026 Security Updates
CISA KEV
released 4 Sep 2026 · catalog 2026.09.04
FIRST EPSS
scored 6 Sep 2026 · model v2026.06.15

What you can do here

  1. PrioritizeWhat to fix first, ranked across every source by real-world exploitation rather than severity alone
  2. AnalyzeUpload a Nessus, Qualys, OpenVAS or Wazuh export and get it consolidated, enriched and prioritized
  3. InvestigateLook up a CVE with its EPSS probability, KEV status and remediation context in one place
  4. PatchThis month's Microsoft release and every vendor advisory, in one ranked, filterable, exportable list
  5. Compare VM platformsQualys, Tenable, Rapid7 and seven more, on capability, pricing basis and time to value

Reference and utilities