About
whattopatch keeps a dated, ranked reading of every vulnerability CISA lists as exploited, so people who patch systems can see what to look at first. Updated .
What the site is
Every entry on CISA's Known Exploited Vulnerabilities list has a page here, and so does every vendor and product with three or more entries. Each page answers first, with its date: is it exploited, since when, how urgent is it by our open method, what does CISA say to do, and where is the fix.
The site also keeps what CISA's list does not: the changes CISA makes to its entries over time, such as a ransomware flag turning from Unknown to Known, a moved deadline or a removal.
Who runs it
The operator of https://whattopatch.com runs the site and answers for it. Write to hello@whattopatch.com.
Independence
whattopatch is not affiliated with or endorsed by CISA, the US Department of Homeland Security, FIRST or MITRE, and it shows none of their logos or seals. We take their public data, credit it on every page and link the original.
The site carries no advertising and no tracking, and no vendor pays for a place in it. The rank comes from published rules, the same for every vendor.
How the pages are made
Programs read the sources on a schedule, keep every file they read, and rebuild a page when its data changes. The words on each page are written by those programs from the data; no page carries a summary written by an AI model.
- Methodologyhow the rank works
- Sourcesevery source and its licence