CyberMax
Home › Reports

A patch list every Monday: what attackers exploited this week

For: Vulnerability-management teams, MSPs patching for clients, and security leads who brief the team on Monday morning.

Free security newsletters tell you the stories. Kevscope Weekly gives your patch team the list: every vulnerability CISA added to its Known Exploited Vulnerabilities catalogue in the last 30 days with its due date, CVSS and EPSS score, a watchlist of new critical CVEs that are not in KEV yet, and the CSV files and build script behind every figure. Rebuilt every week from CISA KEV, FIRST EPSS and NVD.

Pages from the Kevscope Weekly exploited vulnerabilities brief
A real weekly edition

Newest KEV additions in the 26 Sep 2026 edition (KEV catalogue 2026.09.25, EPSS of 25 Sep)

CVEVendorProductCVSSEPSSKEV due
CVE-2026-87902WordPressCore8.1 HIGH2.88%2026-09-28
CVE-2026-65660MicrosoftSharePoint8.8 HIGH1.22%2026-09-28
CVE-2026-67279MikroTikRouterOS6.9 MEDIUM0.71%2026-09-28
CVE-2026-71362AdobeCommerce and Magento9.1 CRITICAL89.62%2026-09-27
CVE-2026-5430WSO2Multiple Products10.0 CRITICAL0.58%2026-09-27
CVE-2026-93616Check PointMultiple Products9.8 CRITICAL19.65%2026-09-25

Source: kev-added-last-30-days.csv from the 26 Sep 2026 edition (revenue/packs/polar/kev-weekly/release/kev-brief-weekly-latest.zip), built from CISA KEV 2026.09.25, FIRST EPSS of 2026-09-25 and NVD.

Kevscope Weekly vs the alternatives

Published prices, each checked on the date shown; prices change, so confirm on each site.

ProductPriceFreeChecked
Kevscope Weekly$9/month or $79/yearLive KEV data previewlive
SANS @RISKFree (with free SANS membership), weekly emailyes2026-10-10
Vulnerable U Premium$49/month or $499/yearfree newsletter2026-10-10
PageCrawl.io (monitor the KEV page yourself)Standard $160/year ($13.33/month); Enterprise $300/year6 pages, 220 checks a month2026-10-10

Why teams pick Kevscope Weekly

How it works

  1. Subscribe and download this week's PDF and ZIP (HTML report, CSVs, build script).
  2. Sort kev-added-last-30-days.csv by KEV due date and hand it to the patch team.
  3. Check the critical watchlist for new CVEs with high EPSS that are not in KEV yet.
  4. Next Monday, the new edition replaces it.

FAQ

Why not SANS @RISK or another free newsletter?

Read them for the stories; they are good and free. Kevscope Weekly is structured data: KEV additions with due dates, EPSS and CVSS in CSV form, ready to load into a ticket queue or spreadsheet.

Why not just watch the CISA KEV page?

You can, for free. The brief adds EPSS and CVSS to each entry, a watchlist of critical CVEs not yet in KEV, trends, and the files, every week.

What sources are used?

CISA's Known Exploited Vulnerabilities catalogue (CC0), FIRST EPSS scores and NVD CVE records. Not affiliated with CISA, NIST, MITRE or FIRST.

Is it advice for my environment?

No. It is general information built from public data; your own asset inventory decides what to patch first.

Can I cancel?

Yes, any time; you keep the editions you downloaded.

Works well with

Kevscope APIthe data by APIKevscope Patch Playbook + Prioritizerpatch playbookDepmoordependency vulnerability check

Related

Kevscope Weekly in the CyberMax StorePlans, checkout, FAQCVE prioritization API (KEV + EPSS)KevscopeDaily CISA KEV and EPSS data feed with diffsDeltawrenWhich vulnerable dependency to fix firstDepmoorAll CyberMax briefs and bundlesBuyer guides with pricesAPI alternativesPublished prices side by side
Product names of other companies are trademarks of their owners and are used only to compare published prices; no affiliation is implied.