M37
Every vulnerability the U.S. government listed as exploited in August 2026
This is the material behind the video. Each row is one vulnerability with every layer of the public record beside it: what CISA’s catalogue says, what the CVE record says, and what the model that estimates exploitation said the day before the listing and again afterwards. Every value is what one of those records states, and where a record states nothing the cell says so instead of showing a zero.
The numbers in the video
How this was put together
Every entry CISA added to its Known Exploited Vulnerabilities catalogue with a date in August 2026 was taken from the catalogue's own JSON feed. For each one we asked FIRST's EPSS API twice, once for the score published on the day before CISA listed it and once for the score on 1 September 2026, and we asked the NVD for the CVE record's severity rating, weakness type, publication date and references. Nothing below was retyped from a screen. The table is generated from the stored responses, and the numbers in the video come out of the same file. Each row also links the vendor advisories the catalogue lists in its own notes field, with CISA's directive links filtered out because they sit on nearly every entry. All 78 distinct advisory links were fetched on the day this was put together and every one of them answered.
The catalogue itself is at cisa.gov/known-exploited-vulnerabilities-catalog, and it is updated on CISA’s own schedule, so a row below can look different there later.
What these numbers cannot tell you
- A CVSS base score is a severity rating, not a prediction and not a risk score.
- 22 of these rows carry a CVSS 3.1 base score and 9 carry a CVSS 4.0 base score. They are not necessarily on one scale.
- EPSS estimates the probability of observed exploitation activity over a forward window. A low score followed by a KEV listing is not by itself an error, because exploitation is rare and a calibrated model has to give low probabilities to almost everything.
- The 'day before' column is the last EPSS score computed before the listing was public. Where it is absent, the CVE record had not been published yet, so no score existed.
- The 'now' column was read after every one of these was public, so it is not a forecast of anything. It is what the model says today about a vulnerability already known to be exploited.
- CISA lists a vulnerability on evidence of exploitation. The catalogue does not say whose evidence, or who was affected.
- The ransomware column reads Unknown for all 31 entries. That is a published field left empty, not a finding.
- Nothing on this page is computed. Every value is what a record stated, and an absence is shown as absent rather than as a zero.
What we could not get
- Who was affected. CISA lists a vulnerability on evidence that it is being exploited and does not publish the evidence, the target, or the reporter. No column here can tell you who was hit or how many.
- Company disclosures. We searched the SEC's EDGAR full-text index for 8-K filings citing Item 1.05, the cybersecurity incident item, across the whole of August 2026. Three documents came back and one of them was actually filed under that item; the other two carry the phrase inside an attached exhibit. Most organisations running this software never file with the SEC, and a company that does file can disclose under a different item, so that count describes the filing record and says nothing about how many incidents there were.
The month, row by row
31 vulnerabilities, one row each. You can sort by any column heading, and the box below narrows the table to rows containing a word you type. Opening a row shows the catalogue’s own name for it, the weakness type, when the CVE record was published, the deadline it carries, and every advisory the catalogue points at.
Showing 25 of 31 rows. In the order the catalogue listed them.
| Row detail | Rating | Record | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| CVE-2026-18577 | N-able / N-central | 8.2 | high | 2026-08-03 | 1 d | 3 d | no scoreno rank | no score | 0.54068 | NVD | |
| CVE-2026-18556 | N-able / N-central | 8.2 | high | 2026-08-04 | 3 d | 3 d | 0.0027019.1 pct | 19.1 | 0.40158 | NVD | |
| CVE-2026-34486 | Apache / Tomcat | 7.5 | high | 2026-08-04 | 117 d | 3 d | 0.4262798.6 pct | 98.6 | 0.98616 | NVD | |
| CVE-2026-9198 | IBM / Langflow | 9.8 | critical | 2026-08-04 | 18 d | 3 d | 0.0188677.5 pct | 77.5 | 0.34734 | NVD | |
| CVE-2026-63077 | JetBrains / TeamCity | 9.8 | critical | 2026-08-05 | 9 d | 3 d | 0.0064947.6 pct | 47.6 | 0.87709 | NVD | |
| CVE-2026-8037 | Progress / LoadMaster | 9.8 | critical | 2026-08-07 | 64 d | 3 d | 0.8479399.7 pct | 99.7 | 0.99571 | NVD | |
| CVE-2026-20349 | Cisco / Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) | 8.6 | high | 2026-08-11 | 0 d | 3 d | no scoreno rank | no score | 0.02213 | NVD | |
| CVE-2026-68820 | Microsoft / Windows Ancillary Function Driver for WinSock | 7.0 | high | 2026-08-11 | 0 d | 14 d | no scoreno rank | no score | 0.06184 | NVD | |
| CVE-2026-72898 | Metabase / Metabase | 10.0 | critical | 2026-08-11 | 1 d | 3 d | no scoreno rank | no score | 0.82323 | NVD | |
| CVE-2025-62593 | Ray-Project / Ray | 9.4 | critical | 2026-08-17 | 264 d | 3 d | 0.0036930 pct | 30 | 0.16888 | NVD | |
| CVE-2026-33824 | Microsoft / Internet Key Exchange (IKE) Service Extensions | 9.8 | critical | 2026-08-18 | 126 d | 3 d | 0.5585099 pct | 99 | 0.72695 | NVD | |
| CVE-2026-55040 | Microsoft / SharePoint | 9.1 | critical | 2026-08-18 | 35 d | 3 d | 0.0397189.6 pct | 89.6 | 0.39652 | NVD | |
| CVE-2026-59310 | Broadcom / VMware vCenter | 9.8 | critical | 2026-08-18 | 19 d | 3 d | 0.0114063.9 pct | 63.9 | 0.45878 | NVD | |
| CVE-2026-65400 | Apple / macOS | 9.8 | critical | 2026-08-18 | 12 d | 3 d | 0.0049640.3 pct | 40.3 | 0.09905 | NVD | |
| CVE-2026-64849 | MLflow / MLflow | 9.3 | critical | 2026-08-19 | 2 d | 14 d | 0.0034927.9 pct | 27.9 | 0.16410 | NVD | |
| CVE-2026-72529 | TrueConf / Server | 9.3 | critical | 2026-08-20 | 1 d | 3 d | no scoreno rank | no score | 0.01554 | NVD | |
| CVE-2026-72530 | TrueConf / Server | 9.5 | critical | 2026-08-20 | 1 d | 14 d | no scoreno rank | no score | 0.01827 | NVD | |
| CVE-2026-73570 | Synacor / Zimbra Collaboration Suite (ZCS) | 8.9 | high | 2026-08-21 | 8 d | 3 d | 0.0053943.1 pct | 43.1 | 0.20528 | NVD | |
| CVE-2026-21962 | Oracle / HTTP Server and Oracle Weblogic Server Proxy Plug-in | 10.0 | critical | 2026-08-24 | 216 d | 3 d | 0.4323098.7 pct | 98.7 | 0.42020 | NVD | |
| CVE-2026-60004 | Gitea / Gitea | 9.8 | critical | 2026-08-25 | -1 d | 3 d | no scoreno rank | no score | 0.86777 | NVD | |
| CVE-2015-3246 | Red Hat / Libuser | 5.1 | medium | 2026-08-26 | 4033 d | 14 d | 0.0709293.7 pct | 93.7 | 0.08799 | NVD | |
| CVE-2015-5287 | Red Hat / Automatic Bug Reporting Tool | 7.8 | high | 2026-08-26 | 3915 d | 14 d | 0.0341288 pct | 88 | 0.04962 | NVD | |
| CVE-2019-1068 | Microsoft / SQL Server | 8.8 | high | 2026-08-26 | 2599 d | 3 d | 0.4466598.7 pct | 98.7 | 0.52845 | NVD | |
| CVE-2021-23758 | Ajax.NET Professional / Ajax.NET Professional | 9.8 | critical | 2026-08-26 | 1727 d | 14 d | 0.8909699.8 pct | 99.8 | 0.83633 | NVD | |
| CVE-2022-0995 | Linux / Kernel | 7.8 | high | 2026-08-26 | 1615 d | 14 d | 0.0634493.1 pct | 93.1 | 0.09518 | NVD |
Ask us to make one of these
Most of the work behind this video was reading a public record carefully and checking what it does and does not support. If your organisation keeps a record like that, a catalogue, a register, a filing history, a dataset you publish, we can build the same kind of explainer out of it, with the working shown on a page like this one.
Tell us which record and what you would want somebody to understand at the end of it. We read everything and we answer, including when the answer is no. If we take something on, the method is written down before the work starts and published with the result, whichever way the result goes.
9592 Solutions UG (haftungsbeschränkt), Fährstr. 217, 40221 Düsseldorf, Germany is the controller for what you send here. Your address and your message are used to answer you and to work out whether we take the request on, under Art. 6(1)(b) and Art. 6(1)(f) GDPR. They go to nobody else and they are not used for advertising. Write to christo@9592.tech for a copy or a deletion at any time. The longer version is on the privacy page.