Exploitation intelligence

Observed Exploitation Signals

Sensor-backed exploitation attempts against internet-facing services, mapped to CVEs and reviewed for confidence. See where attacker activity is concentrating before severity scores alone tell the story.

KEVs Observed
23
Known exploited vulnerabilities seen in the selected window
Exploitation Events
1,646
Attempts mapped to tracked CVEs across the sensor network
Attacker IPs
114
Unique source addresses observed in the selected window

Exploitation Attempts

24-hour activity, grouped by observation date · 18 Aug–19 Aug 2026 UTC

Exploitation Attempts

24-hour activity, grouped by observation date

765
881
18 Aug 19 Aug

Click a day to filter stats and tables to that date.

Where Exploitation Activity Concentrated

The highest-volume CVEs in this snapshot, ranked by mapped exploitation attempts—not theoretical severity.

Inspect full KEV record

PHPUnit

PHPUnit

Attempts
1,137
Attackers
31
Sensors
24

WordPress

WordPress

Attempts
215
Attackers
6
Sensors
2

Apache HTTP Server

Apache Software Foundation

Attempts
109
Attackers
65
Sensors
27

NoneCms

NoneCms

Attempts
58
Attackers
22
Sensors
19

ThinkPHP Framework

ThinkPHP

Attempts
56
Attackers
22
Sensors
18

Langflow OSS

IBM

Attempts
13
Attackers
11
Sensors
2

Observed Exploitation Attempts

Search the highest-volume records in the selected window. Each row shows activity breadth and recency alongside raw volume.

How to Read the Signal

Attempts indicate volume. Unique IPs and sensors indicate breadth. First and last seen show persistence. Use the linked CVE record for evidence and remediation context.

CVE-2017-9841

PHPUnit

PHPUnit

Attempts
1,137
Attacker IPs
31
Sensors
24
CVE-2026-63030

WordPress

WordPress

Attempts
215
Attacker IPs
6
Sensors
2
CVE-2021-41773

Apache HTTP Server

Apache Software Foundation

Attempts
109
Attacker IPs
65
Sensors
27
CVE-2018-20062

NoneCms

NoneCms

Attempts
58
Attacker IPs
22
Sensors
19
CVE-2022-47945

ThinkPHP Framework

ThinkPHP

Attempts
56
Attacker IPs
22
Sensors
18
CVE-2026-9198

Langflow OSS

IBM

Attempts
13
Attacker IPs
11
Sensors
2
CVE-2025-55182

react-server-dom-webpack, react-server-dom-turbopack, react-server-dom-parcel

Meta

Attempts
12
Attacker IPs
1
Sensors
1
CVE-2026-33017

langflow

langflow-ai

Attempts
8
Attacker IPs
1
Sensors
1
CVE-2024-4879

Now Platform

ServiceNow

Attempts
6
Attacker IPs
4
Sensors
1
CVE-2026-8452

ADC, Gateway

NetScaler

Attempts
4
Attacker IPs
3
Sensors
1
CVE-2026-4020

Gravity SMTP

RocketGenius

Attempts
4
Attacker IPs
4
Sensors
3
CVE-2020-3452

Cisco Adaptive Security Appliance (ASA) Software

Cisco

Attempts
3
Attacker IPs
3
Sensors
3
CVE-2018-13379

Fortinet FortiOS, FortiProxy

Fortinet

Attempts
3
Attacker IPs
3
Sensors
3
CVE-2026-0770

Langflow

Langflow

Attempts
3
Attacker IPs
2
Sensors
2
CVE-2018-10562

GPON home routers

Dasan

Attempts
3
Attacker IPs
3
Sensors
3
CVE-2023-1389

TP-Link Archer AX21 (AX1800)

TP-Link

Attempts
2
Attacker IPs
1
Sensors
2
CVE-2025-20282

Cisco Identity Services Engine Software

Cisco

Attempts
1
Attacker IPs
1
Sensors
1
CVE-2025-5777

ADC, Gateway

NetScaler

Attempts
1
Attacker IPs
1
Sensors
1

Showing 23 of 23 highest-volume records · 18 Aug–19 Aug 2026 UTC

Early warning alerts

Get alerts on high-impact exploitation

Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.