KEV Intelligence is becoming Previdian.

Monthly exploitation report · August 2026

Known Exploited Vulnerabilities Report — August 2026

Executive analysis of KEV additions, sensor-observed exploitation activity, CISA visibility gaps, and the vulnerabilities that drove August 2026.

92
KEVs added

77 were outside CISA KEV when added

160,586
Exploitation events

Up 204.9% from July

86.3%
Top-five concentration

Share of events tied to five vulnerabilities

4.1 days
Median CISA lead

Across 16 vulnerabilities added by Previdian first

Executive brief

The month in three decisions

01

Validate exposure against the top five

Five vulnerabilities produced 86.3% of August events. Prioritize asset discovery and remediation around ADC, Gateway, PHPUnit, react-server-dom-webpack, react-server-dom-turbopack, react-server-dom-parcel, PHP, and WordPress.

02

Do not rely on CISA KEV alone

Previdian added 77 exploited vulnerabilities outside CISA KEV during August; 62 were still absent at month-end.

03

Treat telemetry as directional evidence

Event volume and source breadth help identify pressure, but observations do not prove that a real-world target was compromised or represent all exploitation activity worldwide.

Exploitation activity

Activity rose sharply—and remained concentrated

Previdian sensors recorded 160,586 exploitation events in August, up from 52,674 in July. A small set of vulnerabilities drove most of the observed volume.

+204.9% month over month

Observed exploitation events

July versus August 2026

July
52,674
August
160,586

158

Vulnerabilities observed

2,738

Source IPs

21

First observed

Concentration of observed events

Top vulnerability 33.0%
Top five 86.3%
Top ten 94.7%

For CISOs, this concentration supports a focused exposure-validation and remediation sprint rather than treating every observed CVE as equally urgent.

Most targeted

The vulnerabilities driving August activity

Ranked by sensor-observed exploitation events. Event volume shows intensity; unique source IPs help indicate breadth.

1
CVE-2026-8451

NetScaler · ADC, Gateway

Outside CISA KEV at month-end

33.0% of monthly events

Events
52,986
Source IPs
9
2
CVE-2017-9841

PHPUnit · PHPUnit

In CISA KEV

32.8% of monthly events

Events
52,705
Source IPs
546
3
CVE-2025-55182

Meta · react-server-dom-webpack, react-server-dom-turbopack, react-server-dom-parcel

In CISA KEV

11.6% of monthly events

Events
18,629
Source IPs
95
7
CVE-2021-41773

Apache · Apache HTTP Server

In CISA KEV

2.0% of monthly events

Events
3,266
Source IPs
721
8
CVE-2022-47945

ThinkPHP · ThinkPHP Framework

Outside CISA KEV at month-end

2.0% of monthly events

Events
3,137
Source IPs
447
9
CVE-2026-8037

Progress Software · LoadMaster, ECS Connections Manager, Object Scale Connection Manager, MOVEit WAF

In CISA KEV

1.3% of monthly events

Events
2,094
Source IPs
35
10
CVE-2026-55040

Microsoft · Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition

In CISA KEV

0.8% of monthly events

Events
1,350
Source IPs
70

Vendor exposure

Newly added KEVs by vendor

Microsoft

3 outside CISA KEV when added

5

Flowise

3 outside CISA KEV when added

3

langflow-ai

3 outside CISA KEV when added

3

mlflow

3 outside CISA KEV when added

3

Weaver Network Co., Ltd.

3 outside CISA KEV when added

3

Weakness patterns

Most common CWE classes

CWE-94 · Improper Control of Generation of Code ('Code Injection')

Most common newly added weakness

11

CWE-22 · Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

9 newly added KEVs

9

CWE-89 · Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

9 newly added KEVs

9

CWE-306 · Missing Authentication for Critical Function

6 newly added KEVs

6

CWE-78 · Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

6 newly added KEVs

6

57.6%

Critical severity

168

Public PoC references

140

Nuclei references

157

Observed request paths

Methodology and limitations

How to interpret and cite this report

These notes define the reporting window, what sensor observations mean, and where the dataset should not be generalized.

Full Previdian methodology
Reporting period

1 August 2026 00:00 UTC through 31 August 2026 23:59 UTC.

Sensor scope

Previdian telemetry represents activity observed by the Previdian sensor network; it does not represent all exploitation activity globally.

Interpretation

An observed exploitation attempt does not by itself demonstrate that a real-world target was successfully compromised.

CISA status

Month-end status is reconstructed from stored CISA addition dates. Removals are not tracked.

Source-IP coverage

Unique source-IP counts require raw sensor rows. When only daily rollups exist, the metric is unavailable.

Historical records

Historical or backfilled KEV records cannot be identified reliably from existing fields and are not listed as a separate category.

Sensor network size

Public reports do not disclose Previdian sensor network size or per-CVE sensor counts.

Early-warning lead time

Early-warning lead time is the gap from first autonomous-watchlist listing to first Previdian KEV. Only positive gaps are counted. Listings after a KEV already existed are excluded.

Prefer deep links to individual CVE reports and this methodology when citing sensor-observed vulnerabilities.