Live situation room

What is being attacked right now is public

Below runs a real situation room: vulnerabilities with confirmed active exploitation from the US agency CISA, and recently documented data breaches. No estimates, no extrapolation.

Attackers work through the same list you see here. The difference is who checks it against their own estate every day.

Live data

The situation room, running on this page

The figures are pulled directly from the Known Exploited Vulnerabilities Catalog published by CISA and from the public breach catalog of Have I Been Pwned.

1,734

Vulnerabilities with confirmed active exploitation

361

of those used in ransomware campaigns

99

added in the last 90 days

1

with a remediation deadline in the next 30 days

Most recently added entries

VulnerabilityVendorAdded
CVE-2026-88779Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer VulnerabilityCitrixNetScaler04/10/2026
CVE-2026-102489Zammad GmbH Zammad Session Fixation VulnerabilityZammad GmbHZammad02/10/2026
CVE-2026-102490Zammad GmbH Zammad Improper Privilege Management VulnerabilityZammad GmbHZammad02/10/2026
CVE-2026-104286Fortinet FortiMail Path Traversal VulnerabilityFortinetFortiMail01/10/2026
CVE-2026-76504Cisco Catalyst SD-WAN Manager Hex Encoding VulnerabilityCiscoCatalyst SD-WAN Manager30/09/2026
CVE-2026-86950Apple Multiple Products Out-of-Bounds Write VulnerabilityAppleMultiple Products29/09/2026
CVE-2026-88771Citrix NetScaler Improper Input Validation VulnerabilityCitrixNetScaler27/09/2026
CVE-2026-88772Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer VulnerabilityCitrixNetScaler27/09/2026

Sources: the Known Exploited Vulnerabilities Catalog of the US Cybersecurity and Infrastructure Security Agency (CISA) and Have I Been Pwned (CC BY 4.0). (2026.10.04)

To be blunt: a dashboard protects nothing, it only shows. The value starts when someone matches this list against your actual estate and closes the affected systems.

Live

The most recently disclosed breaches

This overview updates automatically from the public Have I Been Pwned corpus. It shows how routinely credentials leak from services your people use privately.

12.8 B

accounts recorded across all known breaches combined.

891

documented breaches in the public corpus.

117

of them were added in the last twelve months alone.

66 %

of the breaches also exposed passwords.

LimeLeads

LimeLeads

limeleads.com

Accounts affected
17.8 M
Date of breach
1 August 2019

Data exposed

Email addressesEmployersGeographic locationsJob titlesPhone numbers
Burger King Russia

Burger King Russia

burgerkingrus.ru

Accounts affected
3.2 M
Date of breach
25 August 2024

Data exposed

Dates of birthEmail addressesGendersGeographic locationsNamesPhone numbers
Chess.com (2026)

Chess.com (2026)

chess.com

Accounts affected
4.7 M
Date of breach
3 August 2026

Data exposed

Email addressesGeographic locationsNamesUsernames

Data source: Have I Been Pwned, licensed under CC BY 4.0. Presentation and assessment by CAVRIX.

The situation

Three facts that shape your week

Public01

The attack list is open to everyone

The CISA catalog names vulnerabilities with proven active exploitation, including CVE number, vendor and product. Everyone reads that list, including the other side. If you run Fortinet, Ivanti, Exchange or VMware, chances are your stack is on it.

Time window02

Days pass between disclosure and exploitation, not months

Every entry carries an added date and a remediation due date. Many flaws are already exploited before the patch reaches your maintenance window. A quarterly patch rhythm does not match that pace.

Blind spot03

Mid-sized companies hear about it last

Not because the information is missing, but because nobody checks it against their own estate daily. Without a current inventory, every advisory is just news. With one, it becomes a task with an owner, a system and a deadline.

What we do

From situation room to closed gap

We do not run the display for its own sake. We work the list against your environment, every business day.

Matching

  • Daily comparison of new catalog entries against your inventory of servers, clients, firewalls and VPN gateways
  • A maintained inventory as the basis, including version levels and external exposure
  • You hear from us only when you are actually affected, instead of getting every headline forwarded

Prioritisation and delivery

  • Order set by real exposure, internet reachability and the ransomware flag
  • Patching inside the agreed maintenance window, with a rollback plan for critical systems
  • Interim measures where no patch exists yet, such as restricting access or disabling the service

Evidence

  • Documentation per vulnerability: detected, assessed, treated, with date and system
  • Usable as evidence for risk management and vulnerability handling under Section 30(2) BSIG for entities in scope of NIS2
  • Aligned with ISO 27001:2022 A.5.7 Threat intelligence and A.8.8 Management of technical vulnerabilities
What changes
Daily

New entries matched against your estate instead of occasional reviews

By exposure

Priority set by your environment, not by a severity score on paper

Evidenced

Every treatment recorded with date, system and outcome

FAQ

Questions

  • Does a German company have to follow the CISA catalog?

    No. The catalog is a binding list for US federal agencies and creates no legal obligation for you. It is, however, the best freely available indicator of what is genuinely being exploited right now. We use it as working input, not as a regulation.

  • Are we required to maintain a situation picture?

    There is no duty to maintain this specific picture. If your entity falls in scope of NIS2, Section 30(2) BSIG requires risk management including the handling of vulnerabilities. A maintained situation picture is a practical way to meet and evidence that.

  • How does this differ from a vulnerability scanner?

    A scanner finds what is exposed in your network. The catalog tells you what attackers are exploiting today. Only the combination gives a defensible order: an affected system plus proven exploitation beats any theoretical severity rating.

  • Can we not just watch the dashboard ourselves?

    You can watch it here at any time, free of charge. Watching does not protect. You need a maintained inventory, someone who compares it daily, and a maintenance window where patching actually happens.

  • Where does the breach data come from?

    From the public catalog of documented breaches maintained by Have I Been Pwned, available under CC BY 4.0. We name the source visibly on this page and do not alter the records.

Hold the list against your own estate

Send us a short outline of your environment. We will tell you which entries in the current catalog affect you and in what order to close them. Contact: info@cavrix.de