Observed arrival · 2026-09-12
KEV Watch: the vulnerabilities CISA has not listed yet
A nightly cybersecurity watchlist tracks CVEs reported as exploited before they appear in CISA’s Known Exploited Vulnerabilities catalog.
Field notes
The watchlist separates entries into four evidence tiers: recent exploitation reports occupy the top tiers, while a lower tier can include CVEs with no report but a rising EPSS score. The homepage records 1,709 CVEs already in the CISA catalog alongside the pre-catalog candidates, allowing its historical comparison to remain visible rather than presenting only a forward-looking alert stream. Individual rows expose tracker names, report dates, severity, EPSS, and a points total.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
One card from the complete issue