M37

Every vulnerability the U.S. government listed as exploited in August 2026

This is the material behind the video. Each row is one vulnerability with every layer of the public record beside it: what CISA’s catalogue says, what the CVE record says, and what the model that estimates exploitation said the day before the listing and again afterwards. Every value is what one of those records states, and where a record states nothing the cell says so instead of showing a zero.

Harvested 2026-09-01 from catalogue version 2026.09.01, which held 1,687 entries in total.

The numbers in the video

7 of 31
had no EPSS score at all on the day before CISA listed them.
n = 31
What it does not mean. The seven were not overlooked. A CVE gets its first score once its record is published, and for every one of them the NVD record was published on or after the day we asked, so there was no score to have.
9 of 24
of the scored entries sat in the top tenth of that day's ranking, and 10 sat below the halfway mark.
n = 24
What it does not mean. It does not grade the model. Nothing here compares these entries against the thousands of CVEs that were scored the same day and never listed, and one month of 31 events cannot settle how a forecaster is doing.
18 days
was the middle gap between a CVE record being published and CISA listing it.
n = 31
What it does not mean. It does not describe a typical entry. One record had existed for 4,033 days when it was listed, and another was listed the day before its record was published at all.
29 of 31
carry a CVSS rating of critical or high.
n = 31
What it does not mean. It does not order them. A rating that nearly every entry shares says the same thing about almost all of them, and the two rated medium are on the list beside the rest.

How this was put together

Every entry CISA added to its Known Exploited Vulnerabilities catalogue with a date in August 2026 was taken from the catalogue's own JSON feed. For each one we asked FIRST's EPSS API twice, once for the score published on the day before CISA listed it and once for the score on 1 September 2026, and we asked the NVD for the CVE record's severity rating, weakness type, publication date and references. Nothing below was retyped from a screen. The table is generated from the stored responses, and the numbers in the video come out of the same file. Each row also links the vendor advisories the catalogue lists in its own notes field, with CISA's directive links filtered out because they sit on nearly every entry. All 78 distinct advisory links were fetched on the day this was put together and every one of them answered.

The catalogue itself is at cisa.gov/known-exploited-vulnerabilities-catalog, and it is updated on CISA’s own schedule, so a row below can look different there later.

What these numbers cannot tell you

What we could not get

The month, row by row

31 vulnerabilities, one row each. You can sort by any column heading, and the box below narrows the table to rows containing a word you type. Opening a row shows the catalogue’s own name for it, the weakness type, when the CVE record was published, the deadline it carries, and every advisory the catalogue points at.

Both EPSS columns hold the probability the model published, between 0 and 1. The left one is the last score computed before the listing was public and the right one was read on 2026-09-01, after every entry here was already known to be exploited.

Showing 25 of 31 rows. In the order the catalogue listed them.

Row detailRatingRecord
CVE-2026-18577N-able / N-central8.2high2026-08-031 d3 dno scoreno rankno score0.54068NVD
CVE-2026-18556N-able / N-central8.2high2026-08-043 d3 d0.0027019.1 pct19.10.40158NVD
CVE-2026-34486Apache / Tomcat7.5high2026-08-04117 d3 d0.4262798.6 pct98.60.98616NVD
CVE-2026-9198IBM / Langflow9.8critical2026-08-0418 d3 d0.0188677.5 pct77.50.34734NVD
CVE-2026-63077JetBrains / TeamCity9.8critical2026-08-059 d3 d0.0064947.6 pct47.60.87709NVD
CVE-2026-8037Progress / LoadMaster9.8critical2026-08-0764 d3 d0.8479399.7 pct99.70.99571NVD
CVE-2026-20349Cisco / Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) 8.6high2026-08-110 d3 dno scoreno rankno score0.02213NVD
CVE-2026-68820Microsoft / Windows Ancillary Function Driver for WinSock 7.0high2026-08-110 d14 dno scoreno rankno score0.06184NVD
CVE-2026-72898Metabase / Metabase10.0critical2026-08-111 d3 dno scoreno rankno score0.82323NVD
CVE-2025-62593Ray-Project / Ray9.4critical2026-08-17264 d3 d0.0036930 pct300.16888NVD
CVE-2026-33824Microsoft / Internet Key Exchange (IKE) Service Extensions9.8critical2026-08-18126 d3 d0.5585099 pct990.72695NVD
CVE-2026-55040Microsoft / SharePoint9.1critical2026-08-1835 d3 d0.0397189.6 pct89.60.39652NVD
CVE-2026-59310Broadcom / VMware vCenter9.8critical2026-08-1819 d3 d0.0114063.9 pct63.90.45878NVD
CVE-2026-65400Apple / macOS9.8critical2026-08-1812 d3 d0.0049640.3 pct40.30.09905NVD
CVE-2026-64849MLflow / MLflow9.3critical2026-08-192 d14 d0.0034927.9 pct27.90.16410NVD
CVE-2026-72529TrueConf / Server9.3critical2026-08-201 d3 dno scoreno rankno score0.01554NVD
CVE-2026-72530TrueConf / Server9.5critical2026-08-201 d14 dno scoreno rankno score0.01827NVD
CVE-2026-73570Synacor / Zimbra Collaboration Suite (ZCS)8.9high2026-08-218 d3 d0.0053943.1 pct43.10.20528NVD
CVE-2026-21962Oracle / HTTP Server and Oracle Weblogic Server Proxy Plug-in10.0critical2026-08-24216 d3 d0.4323098.7 pct98.70.42020NVD
CVE-2026-60004Gitea / Gitea9.8critical2026-08-25-1 d3 dno scoreno rankno score0.86777NVD
CVE-2015-3246Red Hat / Libuser5.1medium2026-08-264033 d14 d0.0709293.7 pct93.70.08799NVD
CVE-2015-5287Red Hat / Automatic Bug Reporting Tool7.8high2026-08-263915 d14 d0.0341288 pct880.04962NVD
CVE-2019-1068Microsoft / SQL Server8.8high2026-08-262599 d3 d0.4466598.7 pct98.70.52845NVD
CVE-2021-23758Ajax.NET Professional / Ajax.NET Professional9.8critical2026-08-261727 d14 d0.8909699.8 pct99.80.83633NVD
CVE-2022-0995Linux / Kernel7.8high2026-08-261615 d14 d0.0634493.1 pct93.10.09518NVD
25 of 31 shown

Ask us to make one of these

Most of the work behind this video was reading a public record carefully and checking what it does and does not support. If your organisation keeps a record like that, a catalogue, a register, a filing history, a dataset you publish, we can build the same kind of explainer out of it, with the working shown on a page like this one.

Tell us which record and what you would want somebody to understand at the end of it. We read everything and we answer, including when the answer is no. If we take something on, the method is written down before the work starts and published with the result, whichever way the result goes.

9592 Solutions UG (haftungsbeschränkt), Fährstr. 217, 40221 Düsseldorf, Germany is the controller for what you send here. Your address and your message are used to answer you and to work out whether we take the request on, under Art. 6(1)(b) and Art. 6(1)(f) GDPR. They go to nobody else and they are not used for advertising. Write to christo@9592.tech for a copy or a deletion at any time. The longer version is on the privacy page.

9592 Solutions UG (haftungsbeschränkt), Düsseldorf · Privacy · youtube.com/@m37channel