CVE Exploitation Report
Beta The CVEs HoneyDB's honeypot network saw being exploited last month, ranked by activity.
CVE-2021-43798 led August 2026; 79% of observations targeted CVEs four years or older
- 33,532 IP-day observations came from 5,869 distinct source IPs against 330 distinct CVEs in August 2026.
- CVE-2021-43798 took rank 1 with 2,838 observations from 1,208 IPs across all 31 days of the month.
- CVE-1999-0517 entered on 2026-08-18 and drew the month's largest source population at 1,854 IPs.
- KEV-listed CVEs made up 51% of distinct CVEs but only 38% of observations.
- 33 CVEs were observed before their KEV listing, topped by CVE-2018-14933 at 2,619 days.
- CVE-2024-47175 rose 56 places to rank 63, while CVE-2024-7029 fell 112 places to rank 232.
AI-generated summary.
August 2026 CVE exploitation
methodology 1.0 · window 2026-08-01 → 2026-08-31 (31/31 days of sensor data)
Seen before KEV
HoneyDB sensors recorded exploitation attempts against these CVEs before CISA added them to its Known Exploited Vulnerabilities catalog.
- CVE-2018-14933 · first seen 2017-10-17 · KEV 2024-12-18 2,619 days before KEV
- CVE-2016-20017 · first seen 2018-06-24 · KEV 2024-01-08 2,024 days before KEV
- CVE-2014-6271 · first seen 2016-12-01 · KEV 2022-01-28 1,884 days before KEV (at least)
Movers
rank change vs last month · positions climbed (+) or dropped (−)
Climbing
- CVE-2024-47175 #63 +56
- CVE-2018-1000861 #35 +41
- CVE-2019-1003000 #36 +41
- CVE-2023-27898 #37 +41
- CVE-2018-7600 #38 +41
- CVE-2018-7602 #39 +41
- CVE-2019-6340 #40 +41
- CVE-2022-25277 #41 +41
- CVE-2016-9299 #33 +39
- CVE-2020-7373 #110 +23
Falling
- CVE-2024-7029 #232 -112
- CVE-2024-10914 #208 -102
- CVE-2022-25075 #183 -76
- CVE-2022-22947 #179 -62
- CVE-2016-0792 #121 -32
- CVE-2016-6563 #66 -24
- CVE-2024-47177 #74 -22
- CVE-2020-2021 #81 -22
- CVE-2021-3064 #82 -22
- CVE-2019-11581 #83 -22
What the report tells you
Every month HoneyDB counts the exploitation attempts its honeypot network recorded against known CVEs — one observation per source IP, per CVE, per day — and ranks the CVEs by that activity. Each CVE is cross-checked against the CISA Known Exploited Vulnerabilities catalog, so you can see which ones attackers are working on before they are officially listed, and how much of the traffic still targets vulnerabilities that are years old.
Coverage caveat. HoneyDB can only observe exploitation of vulnerabilities its sensors and analyzers detect. These figures describe activity against HoneyDB's honeypot network, not internet-wide prevalence.
Signed-in users get the full ranking of every observed CVE with KEV detail and lead times, the source networks and countries behind each one, new, returning and dropped CVEs, the CVE age distribution — plus the whole dataset through the API.
See the full CVE exploitation report
Sign in to rank every observed CVE, see who is exploiting it, and pull the dataset from the API.
Sign in to view the report → See the API