Edition of September 29, 2026 · updated daily
The vulnerabilities attackers actually exploit, in the products you use.
Every day, the vulnerabilities attackers are really using, from the official catalog of the US cybersecurity agency (CISA). Tell us which devices and software you run, and see what affects you and what to patch first.
Free · no account · no cookies · every figure sourced
Or start with:
Network edge devices: Firewalls and VPNs, ADCs, Switches and routers, Home routers and IoT.
Today’s figures
-
1729 exploited vulnerabilities in CISA’s catalog
-
43 added in the last 30 days, from 25 brands
-
3 active CERT-FR alerts on these vulnerabilities
Source: CISA KEV catalog, version 2026.09.29, collected September 29, 2026 at 14:57 UTC; alerts: CERT-FR.
The last 90 days
98 exploited vulnerabilities added, from 47 brands. 26 of 98 affect a network edge device.
Network edge devices: Firewalls and VPNs, ADCs, Switches and routers, Home routers and IoT.
- 1. Operating systems 12
- 1. Firewalls and VPNs 12
- 3. CMS and websites 9
- 3. Collaboration and video 9
- 5. Development and CI/CD 7
- 5. AI and automation 7
- 5. Switches and routers 7
- 8. ADCs 6
- Other categories 29
Additions per product category, for categories with at least 5 additions; the others are grouped. Same number: tied. Categories: indicative classification by this site. Source: CISA KEV catalog.
Active CERT-FR alerts
- CERTFR-2026-ALE-011 — Multiples vulnérabilités dans Citrix NetScaler ADC et Gateway (updated September 28, 2026) · Citrix
- CERTFR-2026-ALE-010 — Vulnérabilité dans Metabase (updated September 10, 2026) · Metabase
- CERTFR-2026-ALE-009 — Multiples vulnérabilités dans SonicWall Secure Mobile Access (updated September 2, 2026) · SonicWall
Information reused under the Open Licence 2.0 (Etalab); the date of last update is shown for each advisory. This site is neither affiliated with nor endorsed by ANSSI.
Priority
Latest exploited vulnerabilities
The top of the patch list: the most recent catalog additions come first.
Rank 1Citrix NetScaler ADC / Gateway
CVE-2026-88771Recently addedActive CERT-FR alertHunt for compromise (CISA)
Citrix NetScaler Improper Input Validation Vulnerability
Added to the catalog less than 30 days ago: ranked by date added.
- Added
- Sep 27, 2026
- CISA deadline
- 3 days
- CVSS severity
- 9.8 (critical)
Rank 2Citrix NetScaler ADC / Gateway
CVE-2026-88772Recently addedActive CERT-FR alertHunt for compromise (CISA)
Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
Added to the catalog less than 30 days ago: ranked by date added.
- Added
- Sep 27, 2026
- CISA deadline
- 3 days
- CVSS severity
- 8.1 (high)
Rank 3Microsoft SharePoint Server
CVE-2026-65660Recently addedHunt for compromise (CISA)
Microsoft SharePoint Code Injection Vulnerability
Added to the catalog less than 30 days ago: ranked by date added.
- Added
- Sep 25, 2026
- CISA deadline
- 3 days
- CVSS severity
- 8.8 (high)
Rank 4WordPress Core
CVE-2026-87902Recently addedHunt for compromise (CISA)
WordPress Core Remote File Inclusion Vulnerability
Added to the catalog less than 30 days ago: ranked by date added.
- Added
- Sep 25, 2026
- CISA deadline
- 3 days
- CVSS severity
- 8.1 (high)
Rank 5MikroTik RouterOS
CVE-2026-67279Recently added
Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability
Added to the catalog less than 30 days ago: ranked by date added.
- Added
- Sep 25, 2026
- CISA deadline
- 3 days
- CVSS severity
- 6.5 (medium)
Network edge devices
Where to start
Firewalls, VPNs, gateways, routers: exposed to the Internet, they are the first targets of attackers.
- Firewalls, VPNs and remote access
Devices that filter traffic and provide remote access to the network: attackers’ first target, because they are exposed to the internet.
12 in the last 90 days · 111 in total
- Load balancers and access gateways (ADC)
Appliances placed in front of applications to balance load, filter web traffic or publish remote access.
6 in the last 90 days · 31 in total
- Switches, routers and SD-WAN
The core of the corporate network: switches, routers, SD-WAN and Wi-Fi controllers.
7 in the last 90 days · 89 in total
- Home and small-office routers, cameras and IoT
Small-office routers, home gateways, IP cameras, video recorders and connected devices: often forgotten and rarely updated.
1 in the last 90 days · 90 in total
- All products
By product type (25 categories) or by brand (275), Microsoft included.
How it works
How to read this site
-
“Exploited”, for real
A vulnerability appears here only if real-world attacks have been observed and it is listed in CISA’s official catalog.
-
What should I do?
Most of the time, apply the vendor’s patch. Each vulnerability page restates CISA’s required action and links to the vendor’s security advisories.
-
Everything is sourced
Every value shows its source and when it was collected. See the sources.