Hazard · updated today
Two questions, answered with evidence.
Which vulnerabilities are attackers actually using — and what it has cost UK organisations when the answer was ignored. Both halves are built from public data, updated daily, and free to use.
Running Fortinet, Ivanti or Exchange? Build a watchlist and see only what is being exploited in your stack — no account, nothing stored.
1,661
vulnerabilities confirmed exploited
335
used in ransomware campaigns
219
UK enforcement actions on record
£53.48m
in penalties issued
Newly confirmed exploited
All 1,661 →- CVE-2026-63077 JetBrains TeamCity Deserialization of Untrusted Data Vulnerability JetBrains · TeamCity
- CVE-2026-18556 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability N-able · N-central
- CVE-2026-34486 Apache Tomcat Missing Encryption of Sensitive Data Vulnerability Apache · Tomcat
- CVE-2026-9198 IBM Langflow Code Injection Vulnerability IBM · Langflow
- CVE-2026-18577 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability N-able · N-central
- CVE-2026-20316 Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability Cisco · Secure Firewall Management Center (FMC)
- CVE-2025-68686 Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability Fortinet · FortiOS
- CVE-2026-16812 Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability Arista · VeloCloud Orchestrator
Latest UK enforcement
All 219 →- Chief Constable Commissioner for the Metropolis/ Metropolitan Police Service (MPS) Incident 1 (ICO Ref: INV/0034/2025), concerning the service of unredacted documents in support of a Stalking Protection Order appl…
- Chief Constable Commissioner for the Metropolis/ Metropolitan Police Service (MPS) Incident 1 (ICO Ref: INV/0034/2025), concerning the service of unredacted documents in support of a Stalking Protection Order appl…
- Geoffrey Smith A council worker who unlawfully accessed hundreds of personal records has been handed a suspended sentence.
- Debbie Okparavero and Maliha Islam Confiscation orders totalling over £118,000 have been secured against two former RAC employees who unlawfully copied and sold pers…
- Thermotech Wall and Loft Surveys Ltd In April 2025, the ICO carried out a search warrant to obtain evidence in relation to TWLS and its compliance with PECR. Following…
- Thermotech Wall and Loft Surveys Ltd In April 2025, the ICO carried out a search warrant to obtain evidence in relation to TWLS and its compliance with PECR. Following…
Cause and consequence
Most sites cover one side or the other. The point of putting them together is that the link is real: the failure modes regulators fine organisations for are the same failure modes attackers rely on.
335 vulnerabilities · 2 UK cases
Ransomware, both ends
The vulnerabilities ransomware crews exploit, next to what ransomware has cost UK organisations in enforcement.
3 UK cases
Unpatched software
The most preventable cause on the register — and the exploited CVEs that are already past their fix deadline.
19 sectors
Who pays, and for what
Every UK sector the ICO has acted against, ranked by total penalties and dominant failure mode.
Sister publication
The breaches as they break
The Perimeter covers cyber-attacks and data breaches daily — the real-world incidents these exploited vulnerabilities cause.