CVE · KEV · CSA

24h · CSA · KEV · as of 2026.09.18

Open threat center

Cyber Dash

First page of an open threat center. Not a wall of alerts — a count. CVEs, KEV, and Singapore notices.

One-page exec memo, PDF

disclosed

73,384CVEs

2026 through 5 Oct

daily count

264/ day

rejected IDs excluded

a note

count ≠ exploit

exploitation is still rare

24hPast 24 hours

major events

12 items in the last 24 hours. Critical vulnerabilities 5, breaches 3, APT 1, AI security 5. No Singapore item in this window. Headlines stay in the source language.

local snapshot · 6 Oct, 10:08 SGT

01Monthly counts

monthly counts

In 2026 (through 5 Oct), WordPress ecology 7,777, Windows / Microsoft 3,566 — about 2.2×. Density of public IDs, not a risk ranking.

Fig. 1 · 2026 · MixTap a bar

severity strata

  • Crit 7,356 · 10%
  • High 29,047 · 40%
  • Med 31,189 · 43%
  • Low 5,792 · 8%

02Stacks

the main stacks

Tap a card to hide that stack from the monthly chart. WordPress counts plugins and themes; Windows counts the Microsoft line.

Fig · large leftovers in 2026 (circa early Sep)

The named leftovers in 2026’s rest. IBM is there: 623, just past Apple. Cisco’s public volume is two-fifths of IBM’s — and it still leads IBM on KEV.

  • IBMWebSphere / AIX / QRadar623KEV added 1

    Yes. Just past Apple by volume. Enterprise long tail. Almost never on KEV.

  • MozillaFirefox413KEV added 0

    Browser disclosures. Higher average score, little in-the-wild use.

  • AdobeAEM / Acrobat289KEV added 5

    Seasonal AEM and Reader patches. Hits KEV more often than IBM.

  • Cisconetwork gear244KEV added 17

    Small public volume. Second in 2026 KEV additions.

  • D-LinkSOHO routers227KEV added 0

    Home routers. Tenda and Totolink add still more, all in the rest.

  • SamsungAndroid OEM174KEV added 0

    Phones and appliance firmware, paced with Android patches.

  • GitLabDevOps158KEV added 1

    Self-hosted DevOps. Mid volume, occasional catalog entries.

  • SAPERP143KEV added 0

    Enterprise ERP. Long patch windows, never the monthly headline.

Vendor public-ID ranks, not a row-by-row split of this center’s rest. Homework sites (SourceCodester, code-projects) and Tenda-class routers pad the rest further, and almost never enter KEV.

03Volume vs exploited

volume is not exploitation

In 2026 the WordPress ecology discloses far more than Windows. CISA KEV reverses it: Microsoft added 39, WordPress core 4. A large count is not the first to be exploited.

Fig. 3 · 2026 public volume
  • WordPress

    plugins & themes, not core

    7,777

  • Windows

    Microsoft product line

    3,566

WordPress is about 2.2× Windows.

Fig. 4 · KEV added in 2026
  • Microsoft39
  • Cisco18
  • Linux8
  • Google8
  • Apple9
  • Oracle4
  • WordPress4

Counts follow the CISA KEV catalog, not third-party “exploited” tallies. Full register below.

04Known exploited

CISA KEV

Public IDs are a disclosure census. CISA KEV is confirmed exploitation. Catalog 1,734; 250 added in 2026. Microsoft 39, WordPress core 4. The largest stacks barely appear here.

catalog

1,734

v2026.10.04

added 2026

250

local snapshot

known ransomware use

361

Known ransomware

forensic triage

75

BOD 26-04 forensic

Fig. 5 · monthly additions
  • Microsoft
  • Cisco
  • Apple
  • Linux
  • Google
  • Fortinet
  • Rest
Fig. 6 · mix
  • Rest160
  • Microsoft39
  • Cisco18
  • Apple9
  • Linux8
  • Google8
  • Fortinet8

250 rows · catalog 2026-10-04 · local snapshot

Showing the first 12. Narrow vendor or search to see the rest.

Source: CISA KEV catalog JSON (2026.10.04). Listing is not compromise — it is reliable evidence of in-the-wild use. BOD 22-01 / 26-04 due dates bind US federal civilian agencies; for everyone else this is a priority queue. WordPress plugins almost never enter. What does: the core chain (wp2shell) and a few historic plugins.

05Lion City notices

SingCERT

Public notices from Singapore’s cyber emergency team. 128 alerts in 2026, 24 of them naming active exploitation. A local priority queue, not the global census.

2026 alerts
128

2026-10-03

Active exploitation
24

2026

2025–26
377

local snapshot

Advisories
13

2026

Fig. 7 · 2026 alerts by month
  • 11
    01
  • 9
    02
  • 8
    03
  • 17
    04
  • 19
    05
  • 16
    06
  • 14
    07
  • 16
    08
  • 17
    09
  • 1
    10

128 rows · through 2026-10-03

Source: CSA Singapore’s public SingCERT index. A notice is guidance for Singapore, not proof your estate is hit. Weekly bulletins are PDF digests and stay folded by default.

06Monthly ledger

the monthly ledger

Tap a row to highlight the same month in Fig. 1. The Jul–Aug 2026 jump is half Oracle’s quarterly spike, half the rest of the catalog rising.

MoWPWinLinuxGoogleOracleAppleRestTotal
Jan62018048028040602,1903,850
Feb7809056034055803,1775,082
Mar82014062039070954,1116,246
Apr79022058036080703,7205,820
May860160720420901104,5926,952
Jun9102407804501101304,8347,454
Jul8806208904801,1501405,6159,775
Aug9408109805209801557,90612,291
Sep9831,1062,1476252742469,56114,942
Oct*19400000778972
Total7,7773,5667,7573,8652,8491,08646,48473,384

07Weakness mix

common classes

These are classes, not vendors. XSS is still the largest share, mostly on CMS extensions. Memory-safety bugs are fewer — and they hit harder.

  • XSSCWE-7922%

    Mostly WordPress plugins

  • SQL injectionCWE-8911%

    Still common in extensions

  • Out-of-bounds writeCWE-7879%

    Kernels and local software

  • Path traversalCWE-228%

    File and backup plugins

  • Missing authenticationCWE-2878%

    Unauthenticated admin interfaces

  • CSRFCWE-3527%

    CMS and admin panels

  • Use after freeCWE-4166%

    Browsers and kernels

  • Missing authorizationCWE-8626%

    Logged in, still out of bounds

  • The restCWE-other23%

    Long tail, scattered