Live situation room

What is being attacked right now is public

Below runs a real situation room: vulnerabilities with confirmed active exploitation from the US agency CISA, and recently documented data breaches. No estimates, no extrapolation.

Attackers work through the same list you see here. The difference is who checks it against their own estate every day.

Live data

The situation room, running on this page

The figures are pulled directly from the Known Exploited Vulnerabilities Catalog published by CISA and from the public breach catalog of Have I Been Pwned.

1,671

Vulnerabilities with confirmed active exploitation

349

of those used in ransomware campaigns

69

added in the last 90 days

6

with a remediation deadline in the next 30 days

Most recently added entries

VulnerabilityVendorAdded
CVE-2026-64849MLflow Server-Side Request Forgery VulnerabilityMLflowMLflow19/08/2026
CVE-2026-65400Apple macOS Improper Authentication VulnerabilityApplemacOS18/08/2026
CVE-2026-55040Microsoft SharePoint Weak Authentication VulnerabilityMicrosoftSharePoint18/08/2026
CVE-2026-59310Broadcom VMware vCenter Path Traversal VulnerabilityBroadcomVMware vCenter18/08/2026
CVE-2026-33824Microsoft Internet Key Exchange (IKE) Service Extensions Double Free VulnerabilityMicrosoftInternet Key Exchange (IKE) Service Extensions18/08/2026
CVE-2025-62593Ray-Project Ray Code Injection VulnerabilityRay-ProjectRay17/08/2026
CVE-2026-72898Metabase SQL Injection VulnerabilityMetabaseMetabase11/08/2026
CVE-2026-68820Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free VulnerabilityMicrosoftWindows Ancillary Function Driver for WinSock 11/08/2026

Sources: the Known Exploited Vulnerabilities Catalog of the US Cybersecurity and Infrastructure Security Agency (CISA) and Have I Been Pwned (CC BY 4.0). (2026.08.19)

To be blunt: a dashboard protects nothing, it only shows. The value starts when someone matches this list against your actual estate and closes the affected systems.

Live

The most recently disclosed breaches

This overview updates automatically from the public Have I Been Pwned corpus. It shows how routinely credentials leak from services your people use privately.

12.7 B

accounts recorded across all known breaches combined.

884

documented breaches in the public corpus.

119

of them were added in the last twelve months alone.

66 %

of the breaches also exposed passwords.

Oz Hair and Beauty

Oz Hair and Beauty

ozhairandbeauty.com

Accounts affected
2 M
Date of breach
15 August 2026

Data exposed

Email addressesGeographic locationsNamesPhone numbersPurchases
Fanlore

Fanlore

fanlore.org

Accounts affected
144,520
Date of breach
6 August 2026

Data exposed

Email addressesNamesPasswordsUsernames
RingCentral

RingCentral

ringcentral.com

Accounts affected
1.6 M
Date of breach
27 July 2026

Data exposed

Email addressesNamesPhone numbersPhysical addresses

Data source: Have I Been Pwned, licensed under CC BY 4.0. Presentation and assessment by CAVRIX.

The situation

Three facts that shape your week

Public01

The attack list is open to everyone

The CISA catalog names vulnerabilities with proven active exploitation, including CVE number, vendor and product. Everyone reads that list, including the other side. If you run Fortinet, Ivanti, Exchange or VMware, chances are your stack is on it.

Time window02

Days pass between disclosure and exploitation, not months

Every entry carries an added date and a remediation due date. Many flaws are already exploited before the patch reaches your maintenance window. A quarterly patch rhythm does not match that pace.

Blind spot03

Mid-sized companies hear about it last

Not because the information is missing, but because nobody checks it against their own estate daily. Without a current inventory, every advisory is just news. With one, it becomes a task with an owner, a system and a deadline.

What we do

From situation room to closed gap

We do not run the display for its own sake. We work the list against your environment, every business day.

Matching

  • Daily comparison of new catalog entries against your inventory of servers, clients, firewalls and VPN gateways
  • A maintained inventory as the basis, including version levels and external exposure
  • You hear from us only when you are actually affected, instead of getting every headline forwarded

Prioritisation and delivery

  • Order set by real exposure, internet reachability and the ransomware flag
  • Patching inside the agreed maintenance window, with a rollback plan for critical systems
  • Interim measures where no patch exists yet, such as restricting access or disabling the service

Evidence

  • Documentation per vulnerability: detected, assessed, treated, with date and system
  • Usable as evidence for risk management and vulnerability handling under Section 30(2) BSIG for entities in scope of NIS2
  • Aligned with ISO 27001:2022 A.5.7 Threat intelligence and A.8.8 Management of technical vulnerabilities
What changes
Daily

New entries matched against your estate instead of occasional reviews

By exposure

Priority set by your environment, not by a severity score on paper

Evidenced

Every treatment recorded with date, system and outcome

FAQ

Questions

  • Does a German company have to follow the CISA catalog?

    No. The catalog is a binding list for US federal agencies and creates no legal obligation for you. It is, however, the best freely available indicator of what is genuinely being exploited right now. We use it as working input, not as a regulation.

  • Are we required to maintain a situation picture?

    There is no duty to maintain this specific picture. If your entity falls in scope of NIS2, Section 30(2) BSIG requires risk management including the handling of vulnerabilities. A maintained situation picture is a practical way to meet and evidence that.

  • How does this differ from a vulnerability scanner?

    A scanner finds what is exposed in your network. The catalog tells you what attackers are exploiting today. Only the combination gives a defensible order: an affected system plus proven exploitation beats any theoretical severity rating.

  • Can we not just watch the dashboard ourselves?

    You can watch it here at any time, free of charge. Watching does not protect. You need a maintained inventory, someone who compares it daily, and a maintenance window where patching actually happens.

  • Where does the breach data come from?

    From the public catalog of documented breaches maintained by Have I Been Pwned, available under CC BY 4.0. We name the source visibly on this page and do not alter the records.

Hold the list against your own estate

Send us a short outline of your environment. We will tell you which entries in the current catalog affect you and in what order to close them. Contact: info@cavrix.de