patchletter

What is actually being exploited — and why CVSS gives you the wrong order

Sixteen of the vulnerabilities attackers are actively using right now are rated “medium”. If your patch order follows the CVSS score and you draw the line at “high”, those sixteen never make the list. Not because anyone decided they were harmless — because a number decided it for you.

Where these numbers come from

patchletter tracks 722 products and mirrors the CISA catalogue of known exploited vulnerabilities (KEV). That catalogue has one entry requirement that no other list applies: exploitation must be observed, not theorised. As of 26 July 2026, 163 of those entries touch a product we follow, published between November 2021 and June 2026. Severity comes from the NVD.

So this is not “all CVEs”. It is the far smaller, far more useful set: the flaws somebody actually walked through.

Severity is not urgency

RatingActively exploited
Critical59
High88
Medium16

Read the last row again. Those sixteen are not edge cases waiting for someone to build a proof of concept. They are being used. CVSS scores how bad a flaw could be in the abstract; it says nothing about whether anyone has bothered. A medium-rated authentication bypass in an appliance facing the internet outranks a critical-rated flaw in a library nobody has worked out how to reach.

The practical rule is short: exploited beats unexploited, regardless of score. Use CVSS to sort within a group, never to decide which group something belongs to.

Ransomware concentrates on very few doors

Forty of the 163 entries carry CISA’s ransomware marker. They are not spread thin:

ProductWith ransomware link
Exchange Server13
FortiOS (FortiGate)11
PAN-OS6
Confluence Data Center5

Thirty-five of forty sit in four products. Mail server, two firewalls, one wiki — all of them reachable from outside, all of them holding credentials or acting as the way in. If you run any of these, their patch notes deserve a different level of attention than the rest of your estate.

The perimeter is the target

FortiOS accounts for 14 entries, PAN-OS for 12, Cisco IOS XE for 4. Thirty exploited vulnerabilities in three products whose entire job is to stand between the internet and everything else. The device you bought to keep attackers out is the device they attack.

That inverts a habit many estates still have: firewall firmware gets patched on a slow, careful cycle because an outage is disruptive, while workstations get patched weekly. The data suggests the opposite priority — a workstation flaw needs a user to do something, an appliance flaw needs only an open port.

What this means on Monday morning

  • Sort by exploited, then by severity — never severity alone.
  • Treat internet-facing appliances as their own class with their own, shorter deadline.
  • Know which of these four products you run before the next entry appears, not after.

The last one is the only part that needs no judgement, just a list. patchletter keeps that list for you: pick your products in the catalogue and you get an email when one of them shows up in the KEV catalogue — the current state is always on the CVE page. Free, no tracking, hosted in Germany.

All figures from our own dataset as of 26 July 2026: 163 KEV entries across 722 tracked products. Severity from the NVD, ransomware marker and exploitation evidence from CISA.