Synced 17 Sept 2026 15:07 UTC Account

Is your software actually safe to run?

Paste any version — in one second see if it's vulnerable, being exploited right now, or past end-of-life, plus the exact version to upgrade to.

Name, name + version, the output of nginx -v, or a CVE ID like CVE-2021-44228

Free, no account No lookup tracking 649 products
Powered by authoritative data NVD National Vulnerability Database CISA KEV Known Exploited FIRST EPSS Exploit prediction endoflife.date Lifecycle
649
Products tracked iThe software products IsItPatched monitors — 649 today, expanding over time.
139
Products being exploited iTracked products with at least one vulnerability in CISA's Known Exploited Vulnerabilities (KEV) catalog — being exploited in the wild right now.
1
Newly exploited today iNew CVEs added to CISA's exploited list today (UTC) affecting tracked products. Resets at midnight UTC.
564
CVEs actively exploited iTotal vulnerabilities across tracked products currently on CISA's KEV list. Tap to see them all.

Recently patched iTracked products that have just shipped a new supported release — the safe version to move to. The positive counterpart to the exploitation radar.

Freshly released safe versions across tracked software — newest first.

View all 155 recently patched releases →

Needs attention iScore 0–100. Starts at 100, minus points per open Critical / High / Medium CVE. Capped at 20 if actively exploited (in CISA KEV), and 40 if the version is end-of-life. Higher = safer.

The most at-risk tracked products, worst first.

Healthy / Good: 207Attention: 48High risk / Critical: 206Unknown: 188 442 of 649 need attention
Cisco ASACisco · all versions
0/100
Critical · exploited
Fortinet FortiOSFortinet · all versions
0/100
Critical · exploited
Palo Alto PAN-OSPalo Alto Networks · all versions
0/100
Critical · exploited
Oracle WebLogicOracle · all versions
0/100
Critical · exploited
Red Hat Enterprise LinuxRed Hat
10.20/100
Critical · exploited
Windows Server 2016Microsoft
10.0.261000/100
Critical · exploited
View & search all 649 products →

CVE disclosure trend iNew CVEs published across tracked products, by month — last 12 months. A volume signal, not a verdict.

11,237 CVEs disclosed across tracked products in the last 12 months.

Oct 2025: 229 CVEs disclosedNov 2025: 54 CVEs disclosedDec 2025: 118 CVEs disclosedJan 2026: 302 CVEs disclosedFeb 2026: 232 CVEs disclosedMar 2026: 380 CVEs disclosedApr 2026: 695 CVEs disclosedMay 2026: 1054 CVEs disclosedJun 2026: 2581 CVEs disclosedJul 2026: 2818 CVEs disclosedAug 2026: 1575 CVEs disclosedSept 2026: 1199 CVEs disclosed
OctNovDecJanFebMarAprMayJunJulAugSept

Security overview

IsItPatched tracks 649 widely-used software products — web servers, databases, CMS platforms, frameworks and infrastructure — and checks every version against known vulnerabilities (NVD), active exploitation (CISA KEV), exploitation probability (EPSS) and end-of-life dates. Right now 139 tracked products are affected by vulnerabilities under active exploitation, and the average health score across the catalogue is 55/100. The products needing attention most urgently include Cisco ASA, Fortinet FortiOS, Palo Alto PAN-OS. The next release to reach end-of-life is Qt (cycle 6.11) on 2026-09-22. On the positive side of the ledger, 155 tracked products have shipped a new supported release in the last 180 days — the safe versions to move to. For any product, IsItPatched shows the minimum safe version you should upgrade to.

What the statuses mean

Healthy / GoodOn the latest supported version — no, or only minor, known issues.
AttentionHas open vulnerabilities worth patching soon.
High risk / CriticalSerious open vulnerabilities (high CVSS severity). A fix almost always exists — upgrade to the recommended version.
Critical · exploitedSerious vulnerabilities being actively exploited right now (in CISA's KEV list). Patch urgently.
End of lifeNo longer receives security patches — this is the true "no-fix" case. Move to a supported version.

Missing a product or a feature?

Tell us what you'd like IsItPatched to track or build next — we read every message.

Send feedback →