Live intelligenceLast source refresh: 29 Sept, 10:58 UTCCVE.org primary · CNA / CISA / NIST provenance · CISA KEV
BlackTree Vulnerability Intelligence
Catalogue scope2026

Know what matters. Patch with purpose.

Every CVE published in 2026, translated into clear operational guidance: what it is, why it matters, how it is used, and how quickly you should act.

Evidence-linkedPatch-focusedHuman-readable
Priority brief202629 Sept, 10:58 UTC
172 vulnerabilities require immediate review

Confirmed exploitation remains separate from public exploit references.

Open priority listView CVEs ↗
2026 CVE intelligence
Material changesCosmetic edits and duplicate refreshes excluded1,63224h ↗9,7267d ↗
Sources current:CVE.org · EPSS · CISA KEV · NIST NVD

Current aggregate snapshot. Missing status is not evidence of low risk. CVSS authority split: CNA 56,619 · CISA 10,077 · NIST 2,581 · Other 67 · Unscored 2,895.

CVE.orgCurrentPrimary published CVE records

398,937 records · refreshed 29 Sept, 10:58 UTC

FIRST EPSSCurrentExploitation probability forecasts

380,224 records · refreshed 28 Sept, 14:07 UTC

CISA KEVCurrentConfirmed exploitation in the wild

1,728 records · refreshed 29 Sept, 10:58 UTC

NIST NVDCurrentNIST enrichment and scheduling state

399,658 records · refreshed 29 Sept, 10:58 UTC

72,240published
17,262exploit references
172Confirmed exploited
26,042Patch references
Coverage Missing data is not low risk
  • 96.0%CVSS
  • 98.8%EPSS
  • 99.1%EUVD
  • 12.7%VEX
  • 96.0%product
  • 97.1%versions
  • 91.8%CWE
  • 36.5%NVD not scheduled
… matching recordsRefreshing
Loading live vulnerabilities…

The current catalogue is being retrieved.

Transparent by design

From a new CVE to a decision you can defend.

Vulnerability feeds create a daily triage problem: thousands of records, changing evidence and scores that answer different questions. BlackTree brings those signals together without hiding their source, so you can see what needs attention now, what can wait and why.

  1. 01
    Evidence arrives

    We monitor CVE.org, FIRST, CISA and NIST for new records and meaningful updates.

  2. 02
    Signals stay separate

    CVSS impact, EPSS probability and CISA-confirmed exploitation are never collapsed into a misleading single score.

  3. 03
    Context becomes action

    Affected versions, access requirements, exploitation evidence and available fixes become a practical urgency recommendation.

  4. 04
    The decision stays current

    Material changes are surfaced so you can revisit a decision when the evidence, exposure or remediation changes.

What this solvesLess feed-chasing. A shorter review queue. Decisions with evidence behind them.

Every recommendation remains traceable to its source, and missing data is treated as uncertainty rather than low risk.