Live intelligenceLast source refresh: 4 Sept, 19:01 UTCCVE.org primary · CNA / CISA / NIST provenance · CISA KEV
BlackTree Vulnerability Intelligence
Catalogue scope2026

Know what matters. Patch with purpose.

Every CVE published in 2026, translated into clear operational guidance: what it is, why it matters, how it is used, and how quickly you should act.

Evidence-linkedPatch-focusedHuman-readable
Priority brief20264 Sept, 19:01 UTC
141 vulnerabilities require immediate review

Confirmed exploitation remains separate from public exploit references.

Open priority listView CVEs ↗
59,517CVEs published in 2026CVE record publication date
15,264public exploit referencesnot automatically lab-validated
141confirmed exploitedCISA KEV evidence
18,187patch referencesstructured source evidence
Structured data coverage2026

Field sources are tracked separately. Missing data is never treated as low risk.

CVSS records grouped by contributing authority: CNA 47,347 · CISA 8,484 · NIST 2,495 · Other 40 · Unscored 1,151

98.1%CVSS scored58,366 of 59,517
99.3%EPSS forecast59,113 of 59,517 · FIRST current
99.4%ENISA EUVD mapped59,161 of 59,517 · official European mapping
9.0%vendor VEX stated5,347 of 59,517 · direct CSAF product state
100.0%product identified59,517 of 59,517 · CNA, CISA ADP or NIST
97.4%versions mapped57,949 of 59,517 · structured affected range
94.1%CWE classified56,035 of 59,517
33.7%NVD not scheduled20,056 of 59,517 · separate NIST workflow status
Source healthOperational data provenance

Current aggregate snapshot. Missing status is not evidence of low risk.

CVE.orgPrimary published CVE records
Current

318,971 records · refreshed 4 Sept, 19:01 UTC

FIRST EPSSExploitation probability forecasts
Current

300,990 records · refreshed 4 Sept, 14:42 UTC

CISA KEVConfirmed exploitation in the wild
Current

1,695 records · refreshed 4 Sept, 19:01 UTC

NIST NVDNIST enrichment and scheduling state
Current

318,974 records · refreshed 4 Sept, 19:02 UTC

Change intelligenceSee what changed, not just what was published.

Material updates to severity, exploitation, remediation, affected versions, guidance and BlackTree coverage. Cosmetic edits and duplicate refreshes are excluded.

Last 24 hours1,148 CVEsCounted 4 Sept, 19:36 UTC · Open updates →Last seven days4,780 CVEsCounted 4 Sept, 19:36 UTC · Open updates →
Inventory applicabilityMatch a CycloneDX or SPDX SBOM and optional VEX statementsOpen private matching workspace
SBOM and VEX matching

Check which catalogue records apply to your inventory

Privacy model: files are parsed in this browser. BlackTree receives only normalized component identifiers and optional VEX statements for this request. Files, identifiers and results are not written to the database or retained by default.

matching recordsRefreshing
Loading live vulnerabilities…

The current catalogue is being retrieved.

Transparent by design

From a new CVE to a decision you can defend.

Vulnerability feeds create a daily triage problem: thousands of records, changing evidence and scores that answer different questions. BlackTree brings those signals together without hiding their source, so you can see what needs attention now, what can wait and why.

  1. 01
    Evidence arrives

    We monitor CVE.org, FIRST, CISA and NIST for new records and meaningful updates.

  2. 02
    Signals stay separate

    CVSS impact, EPSS probability and CISA-confirmed exploitation are never collapsed into a misleading single score.

  3. 03
    Context becomes action

    Affected versions, access requirements, exploitation evidence and available fixes become a practical urgency recommendation.

  4. 04
    The decision stays current

    Material changes are surfaced so you can revisit a decision when the evidence, exposure or remediation changes.

What this solvesLess feed-chasing. A shorter review queue. Decisions with evidence behind them.

Every recommendation remains traceable to its source, and missing data is treated as uncertainty rather than low risk.