Exploitation intelligence

Observed Exploitation Signals

Sensor-backed exploitation attempts against internet-facing services, mapped to CVEs and reviewed for confidence. See where attacker activity is concentrating before severity scores alone tell the story.

KEVs Observed
144
Known exploited vulnerabilities seen in the selected window
Exploitation Events
58,662
Attempts mapped to tracked CVEs across the sensor network
Attacker IPs
2,434
Unique source addresses observed in the selected window

Exploitation Attempts

30-day activity, grouped by observation date · 20 Jul–19 Aug 2026 UTC

Exploitation Attempts

30-day activity, grouped by observation date

880
2,623
2,513
1,805
1,628
2,069
2,191
2,697
1,622
1,261
2,492
2,548
2,369
2,733
2,635
2,349
2,957
2,383
6,040
2,714
2,101
405
829
702
740
966
436
354
1,352
1,387
881
20 Jul 27 Jul 3 Aug 10 Aug 19 Aug

Click a day to filter stats and tables to that date.

Where Exploitation Activity Concentrated

The highest-volume CVEs in this snapshot, ranked by mapped exploitation attempts—not theoretical severity.

Inspect full KEV record

PHPUnit

PHPUnit

Attempts
37,064
Attackers
382
Sensors
31

Apache HTTP Server

Apache Software Foundation

Attempts
3,178
Attackers
565
Sensors
30

WordPress

WordPress

Attempts
2,884
Attackers
142
Sensors
14

NoneCms

NoneCms

Attempts
2,622
Attackers
353
Sensors
31

ThinkPHP Framework

ThinkPHP

Attempts
2,611
Attackers
330
Sensors
30

Langflow

Langflow

Attempts
1,914
Attackers
172
Sensors
12

Observed Exploitation Attempts

Search the highest-volume records in the selected window. Each row shows activity breadth and recency alongside raw volume.

How to Read the Signal

Attempts indicate volume. Unique IPs and sensors indicate breadth. First and last seen show persistence. Use the linked CVE record for evidence and remediation context.

CVE-2017-9841

PHPUnit

PHPUnit

Attempts
37,064
Attacker IPs
382
Sensors
31
CVE-2021-41773

Apache HTTP Server

Apache Software Foundation

Attempts
3,178
Attacker IPs
565
Sensors
30
CVE-2026-63030

WordPress

WordPress

Attempts
2,884
Attacker IPs
142
Sensors
14
CVE-2018-20062

NoneCms

NoneCms

Attempts
2,622
Attacker IPs
353
Sensors
31
CVE-2022-47945

ThinkPHP Framework

ThinkPHP

Attempts
2,611
Attacker IPs
330
Sensors
30
CVE-2026-0770

Langflow

Langflow

Attempts
1,914
Attacker IPs
172
Sensors
12
CVE-2025-55182

react-server-dom-webpack, react-server-dom-turbopack, react-server-dom-parcel

Meta

Attempts
1,183
Attacker IPs
79
Sensors
26
CVE-2026-9198

Langflow OSS

IBM

Attempts
812
Attacker IPs
334
Sensors
20
CVE-2026-8037

LoadMaster, ECS Connections Manager, Object Scale Connection Manager, MOVEit WAF

Progress Software

Attempts
741
Attacker IPs
57
Sensors
5
CVE-2026-15409

SMA1000

SonicWall

Attempts
441
Attacker IPs
46
Sensors
15
CVE-2026-55040

Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition

Microsoft

Attempts
392
Attacker IPs
28
Sensors
3
CVE-2022-41040

Microsoft Exchange Server 2013 Cumulative Update 23, Microsoft Exchange Server 2016 Cumulative Update 22, Microsoft Exchange Server 2019 Cumulative Update 11, Microsoft Exchange Server 2019 Cumulative Update 12, Microsoft Exchange Server 2016 Cumulative Update 23

Microsoft

Attempts
324
Attacker IPs
277
Sensors
30
CVE-2024-37014

Langflow

langflow-ai

Attempts
296
Attacker IPs
12
Sensors
3
CVE-2024-12847

DGN1000

NETGEAR

Attempts
228
Attacker IPs
176
Sensors
30
CVE-2026-16723

Fastjson

Alibaba

Attempts
192
Attacker IPs
1
Sensors
2
CVE-2018-10562

GPON home routers

Dasan

Attempts
191
Attacker IPs
175
Sensors
28
CVE-2018-13379

Fortinet FortiOS, FortiProxy

Fortinet

Attempts
164
Attacker IPs
104
Sensors
31
CVE-2017-18368

P660HN-T1A v1 TCLinux Fw

ZyXEL

Attempts
132
Attacker IPs
19
Sensors
1
CVE-2026-4020

Gravity SMTP

RocketGenius

Attempts
121
Attacker IPs
61
Sensors
23
CVE-2020-3452

Cisco Adaptive Security Appliance (ASA) Software

Cisco

Attempts
120
Attacker IPs
111
Sensors
30
CVE-2026-48282

ColdFusion

Adobe

Attempts
115
Attacker IPs
16
Sensors
6
CVE-2021-41277

metabase

metabase

Attempts
88
Attacker IPs
9
Sensors
28
CVE-2026-20253

Splunk Enterprise

Splunk

Attempts
79
Attacker IPs
7
Sensors
1
CVE-2023-26801

BL-AC1900_2.0, BL-WR9000, BL-X26, BL-LTE300

LB-LINK

Attempts
79
Attacker IPs
2
Sensors
3
CVE-2013-3821

PeopleSoft Products

Oracle

Attempts
77
Attacker IPs
6
Sensors
1
CVE-2024-20767

ColdFusion

Adobe

Attempts
68
Attacker IPs
30
Sensors
18
CVE-2013-2251

Struts

Apache

Attempts
68
Attacker IPs
13
Sensors
8
CVE-2017-10271

WebLogic Server

Oracle Corporation

Attempts
55
Attacker IPs
17
Sensors
6
CVE-2014-2383

dompdf

dompdf

Attempts
55
Attacker IPs
14
Sensors
5
CVE-2025-8943

Flowise

Flowise

Attempts
53
Attacker IPs
26
Sensors
5
CVE-2026-39808

FortiSandbox, FortiSandbox PaaS

Fortinet

Attempts
51
Attacker IPs
14
Sensors
2
CVE-2026-48313

ColdFusion

Adobe

Attempts
45
Attacker IPs
11
Sensors
3
CVE-2026-35273

PeopleSoft Enterprise PeopleTools

Oracle Corporation

Attempts
39
Attacker IPs
16
Sensors
5
CVE-2025-29635

DIR-823X

D-Link

Attempts
37
Attacker IPs
4
Sensors
18
CVE-2025-1302

jsonpath-plus

JSONPath-Plus

Attempts
35
Attacker IPs
3
Sensors
4
CVE-2024-3721

DVR-4104, DVR-4216

TBK

Attempts
32
Attacker IPs
11
Sensors
17
CVE-2020-14882

WebLogic Server

Oracle Corporation

Attempts
30
Attacker IPs
10
Sensors
4
CVE-2026-46442

Flowise

FlowiseAI

Attempts
30
Attacker IPs
14
Sensors
1
CVE-2023-1389

TP-Link Archer AX21 (AX1800)

TP-Link

Attempts
30
Attacker IPs
4
Sensors
13
CVE-2026-33017

langflow

langflow-ai

Attempts
29
Attacker IPs
11
Sensors
1
CVE-2014-8361

SDK

Realtek

Attempts
25
Attacker IPs
20
Sensors
1
CVE-2025-20282

Cisco Identity Services Engine Software

Cisco

Attempts
21
Attacker IPs
17
Sensors
1
CVE-2020-14883

WebLogic Server

Oracle Corporation

Attempts
19
Attacker IPs
8
Sensors
3
CVE-2026-8452

ADC, Gateway

NetScaler

Attempts
19
Attacker IPs
11
Sensors
1
CVE-2024-4879

Now Platform

ServiceNow

Attempts
18
Attacker IPs
9
Sensors
4

Showing 50 of 50 highest-volume records · 20 Jul–19 Aug 2026 UTC

Early warning alerts

Get alerts on high-impact exploitation

Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.