Would you know if a tool in your stack is under active attack?
patchletter watches CISA's catalog of actively exploited vulnerabilities (KEV) and emails you the moment a tool you track is affected. Free, no account.
Actively exploited — right now in the catalog
| Tool | CVE | Vulnerability | In KEV since | |
|---|---|---|---|---|
| JFrog Artifactory | CVE-2026-66384 | JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability5.3 medium · over the network, with a basic account · CISA deadline: 12 days left | 27 Aug | → |
| JFrog Artifactory | CVE-2026-66384 | JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability5.3 medium · over the network, with a basic account · CISA deadline: 12 days left | 27 Aug | → |
| Microsoft SQL Server | CVE-2019-1068 | Microsoft SQL Server Remote Code Execution Vulnerability8.8 high · over the network, with a basic account · CISA deadline was 29 Aug | 26 Aug | → |
| Gitea | CVE-2026-60004 | Gitea Code Injection VulnerabilityCISA deadline was 28 Aug | 25 Aug | → |
| Zimbra Collaboration | CVE-2026-73570 | Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability8.9 high · over the network, without login · CISA deadline was 24 Aug | 21 Aug | → |
| macOS | CVE-2026-65400 | Apple macOS Improper Authentication Vulnerability9.8 critical · over the network, without login · CISA deadline was 21 Aug | 18 Aug | → |
| VMware vCenter | CVE-2026-59310 | Broadcom VMware vCenter Path Traversal Vulnerability9.8 critical · over the network, without login · CISA deadline was 21 Aug | 18 Aug | → |
| Metabase | CVE-2026-72898 | Metabase SQL Injection Vulnerability10.0 critical · over the network, without login · CISA deadline was 14 Aug | 11 Aug | → |
| Cisco ASA / Firepower | CVE-2026-20349 | Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability8.6 high · over the network, without login · CISA deadline was 14 Aug | 11 Aug | → |
| Apache Tomcat | CVE-2026-34486 | Apache Tomcat Missing Encryption of Sensitive Data Vulnerability7.5 high · over the network, without login · CISA deadline was 7 Aug | 4 Aug | → |
| FortiOS (FortiGate) | CVE-2025-68686 | Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability5.9 medium · over the network, without login · CISA deadline was 10 Aug | 27 Jul | → |
| Langflow | CVE-2026-0770 | Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability9.8 critical · over the network, without login · CISA deadline was 24 Jul | 21 Jul | → |
Source: CISA KEV · checked daily · 313 matches across 74 of 1239 tracked tools, 96 of them ransomware-linked (as of 29/08/2026)
Counted per pair of vulnerability and tool: a flaw affecting three tools counts three times. Included is only what is currently listed in the KEV catalog and unambiguously matched to a tool in this catalog. The public feed /api/v1/cves is deliberately broader — it also contains fuzzy matches and flaws CISA has since removed from the KEV catalog, which is why its numbers are higher.
Newest entry:
Also: BSI security advisories
The KEV catalog above lists only vulnerabilities proven to be under active exploitation. Germany's BSI (CERT-Bund) warns more broadly — here are the latest advisories for tools in this catalog.
- WID-SEC-W-2026-2245
- WID-SEC-W-2026-2868
Red Hat Enterprise Linux (pcp): Mehrere Schwachstellen
Amazon Linux, Oracle Linux, Rocky Linux, Red Hat Enterprise Linux +1
- WID-SEC-W-2026-0861
- WID-SEC-W-2026-2187
GIMP: Schwachstelle ermöglicht Denial of Service und potenziell Codeausführung
- WID-SEC-W-2026-1064
CPython: Mehrere Schwachstellen
Amazon Linux, Fedora, Python, Oracle Linux +4
- WID-SEC-W-2026-2204
GIMP: Schwachstelle ermöglicht Codeausführung und Denial of Service
- WID-SEC-W-2026-3059
Red Hat Undertow: Schwachstelle ermöglicht Denial of Service
- WID-SEC-W-2026-2309
Perl, Red Hat Enterprise Linux, openSUSE Leap, Ubuntu Server
An advisory does not tell you whether your version is affected. It names the product — the details are in the original advisory at the BSI.
BSI advisories do not trigger emails; emails are sent for KEV entries only. All BSI advisories
How CVE tracking works
CISA KEV, watched daily
We match the KEV catalog — only vulnerabilities proven to be actively exploited — against the tools in the catalog every day.
Email alert when affected
When a new KEV vulnerability affects a tool you subscribe to, you get an email right away — one-click unsubscribe.
Context per tool
On each tool page you see the actively exploited vulnerabilities, a ransomware flag, and the link to the NVD entry.
Why KEV, not the CVE flood
There are tens of thousands of CVEs — very few are ever exploited. CISA's KEV catalog lists only those proven to be under active attack. Those are the ones you want to see first. patchletter doesn't scan your systems — it tells you which of the tools you track are affected, so you can check your installed version.
Frequently asked questions
What is the CISA KEV catalog?
The US agency CISA's Known Exploited Vulnerabilities catalog: a curated list of vulnerabilities proven to be actively exploited in the wild. Far less noise than the full set of CVEs.
Do I get an email when a tool is affected?
Yes. If you subscribe to a tool, you get an email as soon as a new actively exploited vulnerability (KEV) affects it — one click to unsubscribe.
Do you scan my systems?
No. We match the KEV catalog against the tools you track, at the product level. Use the linked CVE entry to check whether your installed version is affected.
Why only KEV and not every CVE?
KEV is low-noise and shows real, present danger. Full CVE coverage with CVSS scores is planned, but not live yet.
What does it cost?
Nothing. All you need is an email address to subscribe to tools.
Know the moment it hits your tools
Pick your software in the catalogue — you'll get an email when a new actively exploited vulnerability affects it.
Subscribe to a tool