cbcvebase.

Weekly · free · for blue teams

Exploited This Week

Every Monday: the CVEs that actually got weaponized or added to CISA KEV in the last seven days — each one cross-linked to its public PoC, Nuclei template, detection rule, and threat-intel writeup. So you know what to patch, hunt, and build a rule for this week — without paying $600/mo for an enterprise feed.

No spam. One email a week. Unsubscribe in one click.

Read the latest issue first — Exploited This Week — Jul 20–Jul 27, 2026

What's in every issue

Patch now — added to CISA KEV

Federally-mandated, actively-exploited additions, ranked by EPSS — with the due date and the threat-intel context. e.g. Palo Alto PAN-OS GlobalProtect auth bypass; the Nx Console & TanStack npm supply-chain compromises.

Newly weaponized — exploit code appeared

CVEs that gained a public ExploitDB PoC, Metasploit module, or Nuclei template this week — curated to the high-signal ones, each marked with its detection coverage (or a flagged detection gap where nobody has a rule yet).

EPSS surges — exploitation risk jumped

The biggest week-over-week jumps in predicted exploitation, so you catch the ones trending toward mass-exploitation before they hit KEV. e.g. the “Dirty Frag” Linux-kernel LPE chain that surged from 0.01 → 0.40.

Why this exists

KEV is a list. EPSS is a score. ExploitDB, Nuclei, Sigma, and the vendor advisories all live in different places. Stitching them together every week to answer one question — “what do I actually need to act on?” — is busywork.

cvebase already cross-links 90+ sources into one index. This digest is that index, distilled to the week's signal — built for detection engineers, threat hunters, and small security teams who can't justify an enterprise threat-intel subscription.

Recent issues

Get the next issue

Know what got weaponized before your Monday standup — and which of it nobody has a detection rule for yet.