Exploited vulnerabilities
The CISA Known Exploited Vulnerabilities catalogue, with severity and affected-product data from the National Vulnerability Database. Everything on this list has been observed in real attacks — it is not a forecast.
- 1703
- On the catalogue
- 8
- Added in 7 days
- 8
- Due within 7 days
- 359
- Used in ransomware
| CVE | Affected | CVSS | Added | Due | |
|---|---|---|---|---|---|
| CVE-2026-34649 | Adobe Commerce | 7.5high | — | — | |
| CVE-2026-34648 | Adobe Commerce | 7.5high | — | — | |
| CVE-2026-34646 | Adobe Commerce | 7.5high | — | — | |
| CVE-2026-34645 | Adobe Commerce | 7.5high | — | — | |
| CVE-2026-34619 | Adobe Coldfusion | 7.7high | — | — | |
| CVE-2026-34070 | Langchain Langchain Core | 7.5high | — | — | |
| CVE-2026-33939 | Handlebarsjs Handlebars | 7.5high | — | — | |
| CVE-2026-33895 | Digitalbazaar Forge | 7.5high | — | — | |
| CVE-2026-33891 | Digitalbazaar Forge | 7.5high | — | — | |
| CVE-2026-33846 | Not specified | 7.5high | — | — | |
| CVE-2026-33845 | Gnu Gnutls | 7.5high | — | — | |
| CVE-2026-33487 | Goxmldsig Project Goxmldsig | 7.5high | — | — | |
| CVE-2026-33218 | Linuxfoundation Nats-Server | 7.5high | — | — | |
| CVE-2026-33079 | Not specified | 7.5high | — | — | |
| CVE-2026-32981 | Anyscale Ray | 7.5high | — | — | |
| CVE-2026-32829 | Pseitz Lz4 Flex | 7.5high | — | — | |
| CVE-2026-3238 | Not specified | 7.5high | — | — | |
| CVE-2026-32286 | Jackc Pgproto3 | 7.5high | — | — | |
| CVE-2026-32141 | Webreflection Flatted | 7.5high | — | — | |
| CVE-2026-3104 | Isc Bind | 7.5high | — | — | |
| CVE-2026-29785 | Linuxfoundation Nats-Server | 7.5high | — | — | |
| CVE-2026-28356 | Not specified | 7.5high | — | — | |
| CVE-2026-27889 | Linuxfoundation Nats-Server | 7.5high | — | — | |
| CVE-2026-27282 | Adobe Coldfusion | 7.5high | — | — | |
| CVE-2026-26278 | Naturalintelligence Fast-Xml-Parser | 7.5high | — | — |