Exploited vulnerabilities
The CISA Known Exploited Vulnerabilities catalogue, with severity and affected-product data from the National Vulnerability Database. Everything on this list has been observed in real attacks — it is not a forecast.
- 1703
- On the catalogue
- 8
- Added in 7 days
- 8
- Due within 7 days
- 359
- Used in ransomware
| CVE | Affected | CVSS | Added | Due | |
|---|---|---|---|---|---|
| CVE-2026-66016 | Not specified | 6.7medium | — | — | |
| CVE-2026-6374 | Not specified | 7.3high | — | — | |
| CVE-2026-61313 | Oracle Hyperion Calculation Manager | 6.7medium | — | — | |
| CVE-2026-61173 | Oracle Agile Product Lifecycle Management | 7.4high | — | — | |
| CVE-2026-60317 | Oracle Mysql Connector\/Net | 7.4high | — | — | |
| CVE-2026-58440 | Not specified | 6.8medium | — | — | |
| CVE-2026-58380 | Gimp Gimp | 7.3high | — | — | |
| CVE-2026-57263 | Not specified | 6.8medium | — | — | |
| CVE-2026-57262 | Not specified | 6.8medium | — | — | |
| CVE-2026-5172 | Not specified | 7.3high | — | — | |
| CVE-2026-5006 | Not specified | 6.8medium | — | — | |
| CVE-2026-48526 | Pyjwt Project Pyjwt | 7.4high | — | — | |
| CVE-2026-48287 | Adobe C2pa | 7.4high | — | — | |
| CVE-2026-47960 | Adobe Coldfusion | 7.4high | — | — | |
| CVE-2026-44393 | Not specified | 7.4high | — | — | |
| CVE-2026-43869 | Apache Thrift | 7.3high | — | — | |
| CVE-2026-42246 | Ruby-Lang Net\ | 7.4high | — | — | |
| CVE-2026-42011 | Not specified | 7.4high | — | — | |
| CVE-2026-41605 | Apache Thrift | 7.3high | — | — | |
| CVE-2026-4134 | Lenovo Software Fix | 7.3high | — | — | |
| CVE-2026-41035 | Samba Rsync | 7.4high | — | — | |
| CVE-2026-40542 | Apache Httpclient | 7.3high | — | — | |
| CVE-2026-3593 | Isc Bind | 7.4high | — | — | |
| CVE-2026-35535 | Sudo Project Sudo | 7.4high | — | — | |
| CVE-2026-34647 | Adobe Commerce | 7.4high | — | — |