Threat landscape
Software flaws hackers are using right now
The US government’s list of security flaws that attackers are actively using, with how serious each one is and which products it affects. Everything on this list has been seen in a real attack. None of it is a prediction.
- 1710
- Flaws on the list
- 11
- Added in 7 days
- 6
- Fix deadline within 7 days
- 360
- Used by ransomware gangs
| CVE | Affected | CVSS | Exploit odds | Added | Due | |
|---|---|---|---|---|---|---|
| CVE-2026-48386 | Adobe Coldfusion | 7.5high | Not scored | — | — | |
| CVE-2026-48385 | Adobe Coldfusion | 7.7high | 1.2% · top 34% | — | — | |
| CVE-2026-48364 | Adobe Coldfusion | 8.2high | under 1% · top 81% | — | — | |
| CVE-2026-48363 | Adobe Coldfusion | 8.2high | under 1% · top 81% | — | — | |
| CVE-2026-48345 | Adobe Animate | 8.2high | under 1% · top 43% | — | — | |
| CVE-2026-48290 | Adobe C2pa | 8.2high | under 1% · top 78% | — | — | |
| CVE-2026-47984 | Adobe Commerce | 8.2high | under 1% · top 51% | — | — | |
| CVE-2026-47895 | Not specified | 7.5high | under 1% · top 50% | — | — | |
| CVE-2026-47893 | Vmware Spring Framework | 7.5high | under 1% · top 84% | — | — | |
| CVE-2026-47889 | Vmware Spring Framework | 7.5high | under 1% · top 83% | — | — | |
| CVE-2026-47888 | Vmware Spring Framework | 7.5high | under 1% · top 75% | — | — | |
| CVE-2026-47886 | Vmware Spring Framework | 7.5high | under 1% · top 75% | — | — | |
| CVE-2026-47885 | Vmware Spring Framework | 7.5high | Not scored | — | — | |
| CVE-2026-47879 | Vmware Spring Cloud Gateway | 7.7high | under 1% · top 84% | — | — | |
| CVE-2026-47852 | Vmware Spring Ai | 7.5high | under 1% · top 90% | — | — | |
| CVE-2026-47851 | Vmware Spring Ai | 7.5high | under 1% · top 82% | — | — | |
| CVE-2026-47827 | Not specified | 7.5high | 1.2% · top 35% | — | — | |
| CVE-2026-47666 | Not specified | 7.6high | under 1% · top 90% | — | — | |
| CVE-2026-47629 | Nvidia Triton Inference Server | 7.5high | under 1% · top 64% | — | — | |
| CVE-2026-47628 | Nvidia Triton Inference Server | 7.5high | under 1% · top 64% | — | — | |
| CVE-2026-4740 | Redhat Advanced Cluster Management For Kubernetes | 8.2high | under 1% · top 96% | — | — | |
| CVE-2026-46728 | Denx U-Boot | 8.2high | under 1% · top 88% | — | — | |
| CVE-2026-4671 | Not specified | 7.5high | under 1% · top 69% | — | — | |
| CVE-2026-46603 | Not specified | 7.5high | under 1% · top 65% | — | — | |
| CVE-2026-46369 | Not specified | 7.5high | under 1% · top 67% | — | — |