This Week in Cyber RiskWeekly
This week in cyber risk: 5 newly confirmed-exploited CVEs
Updated 12 August 2026 · Timeframe: New KEV this week (7 days); 52-week trend chart
5 CVEs entered CISA's KEV catalog in the last 7 days, and 6 more had their EPSS exploit-probability spike.
Why it matters
KEV entries are the vulnerabilities attackers are provably using right now; the EPSS movers are where exploitation is heading next.
What to do
- Security leaders. Confirm every KEV entry is on your mandatory-patch track and report coverage to the board.
- Lean IT orgs. Patch anything on the KEV list first — those are confirmed exploited, not theoretical.
- MSPs. Sweep client fleets for the week's KEV CVEs; prioritize internet-facing systems.
Our take
Resilience starts from assuming exploitation, not just possibility. The KEV list is the shortest path to cutting real attacker leverage.
Earlier issues
Past states of this signal, most recent first.
10 August 2026 This week in cyber risk: 6 newly confirmed-exploited CVEs
Timeframe: New KEV this week (7 days); 52-week trend chart
6 CVEs entered CISA's KEV catalog in the last 7 days, and 6 more had their EPSS exploit-probability spike.
03 August 2026 This week in cyber risk: 4 newly confirmed-exploited CVEs
Timeframe: New KEV this week (7 days); 52-week trend chart
4 CVEs entered CISA's KEV catalog in the last 7 days, and 6 more had their EPSS exploit-probability spike. That is below the recent average of about 7.
29 July 2026 This week in cyber risk: 5 newly confirmed-exploited CVEs
Timeframe: New KEV this week (7 days); 52-week trend chart
5 CVEs entered CISA's KEV catalog in the last 7 days, and 6 more had their EPSS exploit-probability spike. That is the fewest in any week we have tracked.
24 July 2026 This week in cyber risk: 6 newly confirmed-exploited CVEs
Timeframe: New KEV this week (7 days); 52-week trend chart
6 CVEs entered CISA's KEV catalog in the last 7 days, and 6 more had their EPSS exploit-probability spike.