What is being attacked right now is public
Below runs a real situation room: vulnerabilities with confirmed active exploitation from the US agency CISA, and recently documented data breaches. No estimates, no extrapolation.
Attackers work through the same list you see here. The difference is who checks it against their own estate every day.
The situation room, running on this page
The figures are pulled directly from the Known Exploited Vulnerabilities Catalog published by CISA and from the public breach catalog of Have I Been Pwned.
Vulnerabilities with confirmed active exploitation
of those used in ransomware campaigns
added in the last 90 days
with a remediation deadline in the next 30 days
Most recently added entries
| Vulnerability | Vendor | Added |
|---|---|---|
| CVE-2026-64849MLflow Server-Side Request Forgery Vulnerability | MLflowMLflow | 19/08/2026 |
| CVE-2026-65400Apple macOS Improper Authentication Vulnerability | ApplemacOS | 18/08/2026 |
| CVE-2026-55040Microsoft SharePoint Weak Authentication Vulnerability | MicrosoftSharePoint | 18/08/2026 |
| CVE-2026-59310Broadcom VMware vCenter Path Traversal Vulnerability | BroadcomVMware vCenter | 18/08/2026 |
| CVE-2026-33824Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability | MicrosoftInternet Key Exchange (IKE) Service Extensions | 18/08/2026 |
| CVE-2025-62593Ray-Project Ray Code Injection Vulnerability | Ray-ProjectRay | 17/08/2026 |
| CVE-2026-72898Metabase SQL Injection Vulnerability | MetabaseMetabase | 11/08/2026 |
| CVE-2026-68820Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability | MicrosoftWindows Ancillary Function Driver for WinSock | 11/08/2026 |
Sources: the Known Exploited Vulnerabilities Catalog of the US Cybersecurity and Infrastructure Security Agency (CISA) and Have I Been Pwned (CC BY 4.0). (2026.08.19)
To be blunt: a dashboard protects nothing, it only shows. The value starts when someone matches this list against your actual estate and closes the affected systems.
The most recently disclosed breaches
This overview updates automatically from the public Have I Been Pwned corpus. It shows how routinely credentials leak from services your people use privately.
accounts recorded across all known breaches combined.
documented breaches in the public corpus.
of them were added in the last twelve months alone.
of the breaches also exposed passwords.
Oz Hair and Beauty
ozhairandbeauty.com
- Accounts affected
- 2 M
- Date of breach
- 15 August 2026
Data exposed
Fanlore
fanlore.org
- Accounts affected
- 144,520
- Date of breach
- 6 August 2026
Data exposed
RingCentral
ringcentral.com
- Accounts affected
- 1.6 M
- Date of breach
- 27 July 2026
Data exposed
Data source: Have I Been Pwned, licensed under CC BY 4.0. Presentation and assessment by CAVRIX.
Three facts that shape your week
The attack list is open to everyone
The CISA catalog names vulnerabilities with proven active exploitation, including CVE number, vendor and product. Everyone reads that list, including the other side. If you run Fortinet, Ivanti, Exchange or VMware, chances are your stack is on it.
Days pass between disclosure and exploitation, not months
Every entry carries an added date and a remediation due date. Many flaws are already exploited before the patch reaches your maintenance window. A quarterly patch rhythm does not match that pace.
Mid-sized companies hear about it last
Not because the information is missing, but because nobody checks it against their own estate daily. Without a current inventory, every advisory is just news. With one, it becomes a task with an owner, a system and a deadline.
From situation room to closed gap
We do not run the display for its own sake. We work the list against your environment, every business day.
Matching
- Daily comparison of new catalog entries against your inventory of servers, clients, firewalls and VPN gateways
- A maintained inventory as the basis, including version levels and external exposure
- You hear from us only when you are actually affected, instead of getting every headline forwarded
Prioritisation and delivery
- Order set by real exposure, internet reachability and the ransomware flag
- Patching inside the agreed maintenance window, with a rollback plan for critical systems
- Interim measures where no patch exists yet, such as restricting access or disabling the service
Evidence
- Documentation per vulnerability: detected, assessed, treated, with date and system
- Usable as evidence for risk management and vulnerability handling under Section 30(2) BSIG for entities in scope of NIS2
- Aligned with ISO 27001:2022 A.5.7 Threat intelligence and A.8.8 Management of technical vulnerabilities
New entries matched against your estate instead of occasional reviews
Priority set by your environment, not by a severity score on paper
Every treatment recorded with date, system and outcome
Questions
Does a German company have to follow the CISA catalog?
No. The catalog is a binding list for US federal agencies and creates no legal obligation for you. It is, however, the best freely available indicator of what is genuinely being exploited right now. We use it as working input, not as a regulation.
Are we required to maintain a situation picture?
There is no duty to maintain this specific picture. If your entity falls in scope of NIS2, Section 30(2) BSIG requires risk management including the handling of vulnerabilities. A maintained situation picture is a practical way to meet and evidence that.
How does this differ from a vulnerability scanner?
A scanner finds what is exposed in your network. The catalog tells you what attackers are exploiting today. Only the combination gives a defensible order: an affected system plus proven exploitation beats any theoretical severity rating.
Can we not just watch the dashboard ourselves?
You can watch it here at any time, free of charge. Watching does not protect. You need a maintained inventory, someone who compares it daily, and a maintenance window where patching actually happens.
Where does the breach data come from?
From the public catalog of documented breaches maintained by Have I Been Pwned, available under CC BY 4.0. We name the source visibly on this page and do not alter the records.
Hold the list against your own estate
Send us a short outline of your environment. We will tell you which entries in the current catalog affect you and in what order to close them. Contact: info@cavrix.de