Exploited vulnerabilities
The CISA Known Exploited Vulnerabilities catalogue, with severity and affected-product data from the National Vulnerability Database. Everything on this list has been observed in real attacks — it is not a forecast.
- 1699
- On the catalogue
- 5
- Added in 7 days
- 6
- Due within 7 days
- 358
- Used in ransomware
| CVE | Affected | CVSS | Added | Due | |
|---|---|---|---|---|---|
| CVE-2026-50736 | Enterprisedb Pglogical | 7.5high | — | — | |
| CVE-2026-50151 | Linuxfoundation Oras | 7.5high | — | — | |
| CVE-2026-49851 | Not specified | 7.5high | — | — | |
| CVE-2026-4926 | Pillarjs Path-To-Regexp | 7.5high | — | — | |
| CVE-2026-49007 | Not specified | 7.5high | — | — | |
| CVE-2026-4890 | Not specified | 7.5high | — | — | |
| CVE-2026-48399 | Adobe Campaign | 7.5high | — | — | |
| CVE-2026-48352 | Adobe C2pa | 7.5high | — | — | |
| CVE-2026-48351 | Adobe C2pa | 7.5high | — | — | |
| CVE-2026-48348 | Adobe Animate | 7.7high | — | — | |
| CVE-2026-48347 | Adobe Animate | 7.7high | — | — | |
| CVE-2026-48332 | Adobe Coldfusion | 7.7high | — | — | |
| CVE-2026-48328 | Adobe Coldfusion | 7.7high | — | — | |
| CVE-2026-48295 | Adobe C2pa | 7.5high | — | — | |
| CVE-2026-47937 | Adobe Acrobat Dc | 7.7high | — | — | |
| CVE-2026-46385 | Not specified | 7.5high | — | — | |
| CVE-2026-46384 | Not specified | 7.5high | — | — | |
| CVE-2026-44902 | Opentelemetry Opentelemetry\/Auto-Instrumentations-Node | 7.5high | — | — | |
| CVE-2026-44488 | Axios Axios | 7.5high | — | — | |
| CVE-2026-44487 | Axios Axios | 7.5high | — | — | |
| CVE-2026-44486 | Axios Axios | 7.5high | — | — | |
| CVE-2026-44432 | Python Urllib3 | 7.5high | — | — | |
| CVE-2026-44289 | Protobufjs Project Protobufjs | 7.5high | — | — | |
| CVE-2026-44020 | Docling Docling | 7.5high | — | — | |
| CVE-2026-44017 | Docling Docling | 7.5high | — | — |