Dispatched Daily, 06:00 ET · Free, No Catch
Every day, the world publishes hundreds of vulnerability reports, breach disclosures, and exploit writeups. Almost none of it demands action today. We tell you the ones that do.
The Exploit Bulletin digests CISA KEV, the NVD, and the security research community every morning, and publishes only what meets a strict bar: confirmed active exploitation, weaponized critical vulnerabilities, and confirmed breaches of infrastructure you likely depend on. A severity score alone never qualifies an item — evidence of exploitation does. No unproven speculation.
The 6 AM Dispatch
Get the Bulletin by email
One email every morning at 6:00 ET — only what demands action today, with concrete detection and patch guidance. Free. Unsubscribe anytime.
No spam, no reselling your address.
Latest Dispatch
Tuesday, September 1, 2026
5 items require action today.
- Unauthenticated deserialization enables remote code execution in SolarWinds Web Help Desk (CVE-2025-40553)
- Default-configuration authentication bypass grants administrative access in JFrog Artifactory (CVE-2026-82329)
- Unauthenticated arbitrary file upload in WP Cookie Notice GDPR consent plugin (CVE-2026-82970)
- Unauthenticated role escalation via checkout parameter in Custom User Registration Fields for WooCommerce (CVE-2026-15369)
- Unauthenticated SQL injection in /pa endpoint leads to remote code execution in Sangoma Switchvox (CVE-2026-9586)
By the Numbers · all-time since Tuesday, August 18, 2026
- 5,747
- vulnerabilities evaluated.
- 46
- escalated by The Exploit Bulletin.
- 5,701
- rejected as not requiring immediate action.
For Security Engineers
Five minutes over coffee tells you what to check in your own environment today — with concrete detection and patch guidance for every item.
For CISOs
A defensible answer to “did we know?” — every item is graded on corroborated exploitation evidence and cites its sources, so what reaches your team is the short list you can stand behind.
Free, By Design
Condensed threat intelligence shouldn’t be locked behind an enterprise contract. Every edition is free to read, on the web and in your inbox.
The 6 AM Dispatch
Get the Bulletin by email
One email every morning at 6:00 ET — only what demands action today, with concrete detection and patch guidance. Free. Unsubscribe anytime.
No spam, no reselling your address.