Skip to content
English

Edition of September 29, 2026 · updated daily

The vulnerabilities attackers actually exploit, in the products you use.

Every day, the vulnerabilities attackers are really using, from the official catalog of the US cybersecurity agency (CISA). Tell us which devices and software you run, and see what affects you and what to patch first.

Free · no account · no cookies · every figure sourced

Or start with:

Network edge devices: Firewalls and VPNs, ADCs, Switches and routers, Home routers and IoT.

Today’s figures

Source: CISA KEV catalog, version 2026.09.29, collected September 29, 2026 at 14:57 UTC; alerts: CERT-FR.

My radar

Patch first on your radar

Loading your radar…

    All my vulnerabilities Edit my radar

    The last 90 days

    98 exploited vulnerabilities added, from 47 brands. 26 of 98 affect a network edge device.

    Network edge devices: Firewalls and VPNs, ADCs, Switches and routers, Home routers and IoT.

    Additions per product category, for categories with at least 5 additions; the others are grouped. Same number: tied. Categories: indicative classification by this site. Source: CISA KEV catalog.

    Active CERT-FR alerts

    Information reused under the Open Licence 2.0 (Etalab); the date of last update is shown for each advisory. This site is neither affiliated with nor endorsed by ANSSI.

    Priority

    Latest exploited vulnerabilities

    Full list (1,729)

    The top of the patch list: the most recent catalog additions come first.

    1. Rank 1Citrix NetScaler ADC / Gateway

      CVE-2026-88771

      Recently addedActive CERT-FR alertHunt for compromise (CISA)

      Citrix NetScaler Improper Input Validation Vulnerability

      Added to the catalog less than 30 days ago: ranked by date added.

      Added
      Sep 27, 2026
      CISA deadline
      3 days
      CVSS severity
      9.8 (critical)
    2. Rank 2Citrix NetScaler ADC / Gateway

      CVE-2026-88772

      Recently addedActive CERT-FR alertHunt for compromise (CISA)

      Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

      Added to the catalog less than 30 days ago: ranked by date added.

      Added
      Sep 27, 2026
      CISA deadline
      3 days
      CVSS severity
      8.1 (high)
    3. Rank 3Microsoft SharePoint Server

      CVE-2026-65660

      Recently addedHunt for compromise (CISA)

      Microsoft SharePoint Code Injection Vulnerability

      Added to the catalog less than 30 days ago: ranked by date added.

      Added
      Sep 25, 2026
      CISA deadline
      3 days
      CVSS severity
      8.8 (high)
    4. Rank 4WordPress Core

      CVE-2026-87902

      Recently addedHunt for compromise (CISA)

      WordPress Core Remote File Inclusion Vulnerability

      Added to the catalog less than 30 days ago: ranked by date added.

      Added
      Sep 25, 2026
      CISA deadline
      3 days
      CVSS severity
      8.1 (high)
    5. Rank 5MikroTik RouterOS

      CVE-2026-67279

      Recently added

      Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability

      Added to the catalog less than 30 days ago: ranked by date added.

      Added
      Sep 25, 2026
      CISA deadline
      3 days
      CVSS severity
      6.5 (medium)

    Network edge devices

    Where to start

    Firewalls, VPNs, gateways, routers: exposed to the Internet, they are the first targets of attackers.

    How it works

    How to read this site