NEW: Group Profiler — instant APT intel lookup. Try it →

Cross-source corroborated CVEs

ThreatFilter ingests 52 public threat-intelligence feeds. A CVE gets a page here only once at least 3 distinct sources have reported it, which is a fraction of a percent of everything seen. Each page is the raw record of who published first and how long every other source took to follow, which is a confidence signal no single advisory can give you.

  • 2 corroborated
  • 2 in CISA KEV
  • 2 reported as exploited
  1. CVE-2026-68820

    4 sources MEDIUM CISA KEV EXPLOITED microsoft

    First reported 2026-08-11 by cisa-kev , then microsoft-msrc, tenable-advisories, qualys-blog

  2. CVE-2026-63077

    3 sources CRITICAL 9.8 CISA KEV EXPLOITED jetbrains

    First reported 2026-07-29 by rapid7-blog , then cisa-kev, thehackernews

Where this comes from

Nothing on these pages is hand-written. The corroboration set is recomputed from the live feed on every build, so a CVE appears here the moment a third independent source reports it and the timeline extends itself as more do.

Live advisory feed · Every source we track · Analyst tools · API