Exploited vulnerabilities
The CISA Known Exploited Vulnerabilities catalogue, with severity and affected-product data from the National Vulnerability Database. Everything on this list has been observed in real attacks — it is not a forecast.
- 1703
- On the catalogue
- 9
- Added in 7 days
- 9
- Due within 7 days
- 359
- Used in ransomware
| CVE | Affected | CVSS | Added | Due | |
|---|---|---|---|---|---|
| CVE-2026-43829 | Not specified | 7.5high | — | — | |
| CVE-2026-42944 | Nlnetlabs Unbound | 7.5high | — | — | |
| CVE-2026-42570 | Svelte Devalue | 7.5high | — | — | |
| CVE-2026-41992 | Gnu Gzip | 7.5high | — | — | |
| CVE-2026-41675 | Not specified | 7.5high | — | — | |
| CVE-2026-41674 | Not specified | 7.5high | — | — | |
| CVE-2026-41673 | Not specified | 7.5high | — | — | |
| CVE-2026-41672 | Not specified | 7.5high | — | — | |
| CVE-2026-41602 | Apache Thrift | 7.5high | — | — | |
| CVE-2026-41292 | Nlnetlabs Unbound | 7.5high | — | — | |
| CVE-2026-40938 | Linuxfoundation Tekton Pipelines | 7.5high | — | — | |
| CVE-2026-39458 | F5 Big-Ip Access Policy Manager | 7.5high | — | — | |
| CVE-2026-39363 | Vitejs Vite | 7.5high | — | — | |
| CVE-2026-34713 | Adobe C2pa | 7.5high | — | — | |
| CVE-2026-34712 | Adobe C2pa | 7.5high | — | — | |
| CVE-2026-34711 | Adobe C2pa | 7.5high | — | — | |
| CVE-2026-34665 | Adobe C2pa | 7.5high | — | — | |
| CVE-2026-34652 | Adobe Commerce | 7.5high | — | — | |
| CVE-2026-34651 | Adobe Commerce | 7.5high | — | — | |
| CVE-2026-34650 | Adobe Commerce | 7.5high | — | — | |
| CVE-2026-34649 | Adobe Commerce | 7.5high | — | — | |
| CVE-2026-34648 | Adobe Commerce | 7.5high | — | — | |
| CVE-2026-34646 | Adobe Commerce | 7.5high | — | — | |
| CVE-2026-34645 | Adobe Commerce | 7.5high | — | — | |
| CVE-2026-34619 | Adobe Coldfusion | 7.7high | — | — |