KEV Intelligence is becoming Previdian.

Exploitation intelligence

Observed Exploitation Signals

Sensor-backed exploitation attempts against internet-facing services, mapped to vulnerabilities and reviewed for confidence. See where attacker activity is concentrating before severity scores alone tell the story.

KEVs Observed
39
Known exploited vulnerabilities seen in the selected window
Exploitation Events
5,544
Attempts mapped to tracked vulnerabilities across the sensor network
Attacker IPs
254
Unique source addresses observed in the selected window

Exploitation Attempts

24-hour activity, grouped by observation date · 01 Sep–02 Sep 2026 UTC

Exploitation Attempts

24-hour activity, grouped by observation date

2,029
3,515
1 Sep 2 Sep

Click a day to filter stats and tables to that date.

Where Exploitation Activity Concentrated

The highest-volume vulnerabilities in this snapshot, ranked by mapped exploitation attempts—not theoretical severity.

Inspect full KEV record

PHPUnit

PHPUnit

Attempts
3,628
Attackers
77
Sensors
33

PHP

PHP Group

Attempts
505
Attackers
68
Sensors
31

WordPress

WordPress

Attempts
372
Attackers
24
Sensors
4

NoneCms

NoneCms

Attempts
307
Attackers
73
Sensors
32

ThinkPHP Framework

ThinkPHP

Attempts
250
Attackers
69
Sensors
31

Apache HTTP Server

Apache

Attempts
127
Attackers
81
Sensors
32

Observed Exploitation Attempts

Search the highest-volume records in the selected window. Each row shows activity breadth and recency alongside raw volume.

How to Read the Signal

Attempts indicate volume. Unique IPs and sensors indicate breadth. First and last seen show persistence. Use the linked CVE record for evidence and remediation context.

CVE-2017-9841

PHPUnit

PHPUnit

Attempts
3,628
Attacker IPs
77
Sensors
33
CVE-2024-4577

PHP

PHP Group

Attempts
505
Attacker IPs
68
Sensors
31
CVE-2026-63030

WordPress

WordPress

Attempts
372
Attacker IPs
24
Sensors
4
CVE-2018-20062

NoneCms

NoneCms

Attempts
307
Attacker IPs
73
Sensors
32
CVE-2022-47945

ThinkPHP Framework

ThinkPHP

Attempts
250
Attacker IPs
69
Sensors
31
CVE-2021-41773

Apache HTTP Server

Apache

Attempts
127
Attacker IPs
81
Sensors
32
CVE-2026-0770

Langflow

Langflow

Attempts
101
Attacker IPs
35
Sensors
2
CVE-2025-55182

react-server-dom-webpack, react-server-dom-turbopack, react-server-dom-parcel

Meta

Attempts
71
Attacker IPs
10
Sensors
12
CVE-2022-41040

Microsoft Exchange Server 2013 Cumulative Update 23, Microsoft Exchange Server 2016 Cumulative Update 22, Microsoft Exchange Server 2019 Cumulative Update 11, Microsoft Exchange Server 2019 Cumulative Update 12, Microsoft Exchange Server 2016 Cumulative Update 23

Microsoft

Attempts
27
Attacker IPs
27
Sensors
27
CVE-2026-9198

Langflow OSS

IBM

Attempts
25
Attacker IPs
19
Sensors
2
CVE-2026-4020

Gravity SMTP

RocketGenius

Attempts
11
Attacker IPs
9
Sensors
11
CVE-2024-12847

DGN1000

NETGEAR

Attempts
10
Attacker IPs
10
Sensors
8
CVE-2025-64095

Dnn.Platform

Dnnsoftware

Attempts
10
Attacker IPs
1
Sensors
3
CVE-2017-10271

WebLogic Server

Oracle

Attempts
10
Attacker IPs
1
Sensors
1
CVE-2021-24212

WooCommerce Help Scout

WooCommerce

Attempts
8
Attacker IPs
1
Sensors
2
CVE-2023-2825

GitLab

GitLab

Attempts
6
Attacker IPs
2
Sensors
1
CVE-2020-14882

WebLogic Server

Oracle

Attempts
6
Attacker IPs
1
Sensors
1
CVE-2026-8037

LoadMaster, ECS Connections Manager, Object Scale Connection Manager, MOVEit WAF

Progress Software

Attempts
5
Attacker IPs
5
Sensors
1
CVE-2018-10562

GPON home routers

Dasan

Attempts
5
Attacker IPs
5
Sensors
5
CVE-2023-1389

TP-Link Archer AX21 (AX1800)

TP-Link

Attempts
5
Attacker IPs
2
Sensors
5
CVE-2026-56291

balbooa.com Balbooa Forms extension for Joomla

Balbooa.com

Attempts
4
Attacker IPs
1
Sensors
3
CVE-2018-2894

WebLogic Server

Oracle

Attempts
4
Attacker IPs
3
Sensors
1
CVE-2025-34046

E-Office

Shanghai Fanwei Network Technology

Attempts
4
Attacker IPs
1
Sensors
2
CVE-2020-14883

WebLogic Server

Oracle

Attempts
4
Attacker IPs
1
Sensors
1
CVE-2026-33017

langflow

Langflow-ai

Attempts
3
Attacker IPs
1
Sensors
1
CVE-2026-55450

langflow

Langflow-ai

Attempts
3
Attacker IPs
3
Sensors
2
CVE-2026-55040

Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition

Microsoft

Attempts
3
Attacker IPs
2
Sensors
1
CVE-2018-13379

Fortinet FortiOS, FortiProxy

Fortinet

Attempts
3
Attacker IPs
1
Sensors
3
CVE-2025-20281

Cisco Identity Services Engine Software

Cisco

Attempts
3
Attacker IPs
3
Sensors
1
CVE-2025-20282

Cisco Identity Services Engine Software

Cisco

Attempts
2
Attacker IPs
1
Sensors
1
CVE-2025-5777

ADC, Gateway

NetScaler

Attempts
2
Attacker IPs
2
Sensors
1
CVE-2025-8943

Flowise

Flowise

Attempts
2
Attacker IPs
2
Sensors
1
CVE-2026-8452

ADC, Gateway

NetScaler

Attempts
2
Attacker IPs
1
Sensors
1
CVE-2023-26801

BL-AC1900_2.0, BL-WR9000, BL-X26, BL-LTE300

LB-LINK

Attempts
1
Attacker IPs
1
Sensors
1
CVE-2016-5312

Messaging Gateway

Symantec

Attempts
1
Attacker IPs
1
Sensors
1
CVE-2026-46442

Flowise

FlowiseAI

Attempts
1
Attacker IPs
1
Sensors
1

Showing 39 of 39 highest-volume records · 01 Sep–02 Sep 2026 UTC