CVE & CISA KEV INTELLIGENCE
Vulnerability Intelligence: From Advisory to Active Exploit.
Not all vulnerabilities carry equal risk. AttackSurface tracks real-world weaponization timelines, correlating CVE advisories with CISA KEV (Known Exploited Vulnerabilities) and EPSS probability spikes against your tracked bug bounty targets.
CISA KEV Catalog1,695 CVEsActively Weaponized in Wild
Critical Severity2CVSS ≥ 9.0 Rating
Real-Time Security Events4Validated Ingestion Baseline
EPSS Prediction FeedSynchronizedDaily Delta Scoring
Vulnerability Lifecycle Inspector
Select a critical CVE below to view its chronological weaponization milestones and telemetry audit trail.
CVE-2024-38077CISA KEV ACTIVECVSS 9.8EPSS: 94.2%
Windows Remote Desktop Licensing Service RCE (MadLicense)
Weakness: CWE-122 (Heap-based Buffer Overflow)
AFFECTED SYSTEMSWindows Server 2000 through 2025 (RDL Service enabled)
Weaponization & Observation Progression
Patch Tuesday AdvisoryJul 09, 2026
Microsoft releases security bulletin for RDL service overflow.
Public PoC PublishedJul 15, 2026
Exploit chain reverse-engineered from patch differential.
In-the-Wild ExploitationAug 02, 2026
CISA adds to KEV catalog due to ransomware group usage.
Perimeter Delta AlertAug 10, 2026
AttackSurface detects exposed port 135/3389 with unpatched RDL.
Continuously correlated with real bug bounty target scopes on AttackSurface.
Open Live Intelligence Workspace →