Threat landscape
Software flaws hackers are using right now
The US government’s list of security flaws that attackers are actively using, with how serious each one is and which products it affects. Everything on this list has been seen in a real attack. None of it is a prediction.
- 1710
- Flaws on the list
- 7
- Added in 7 days
- 5
- Fix deadline within 7 days
- 360
- Used by ransomware gangs
| CVE | Affected | CVSS | Exploit odds | Added | Due | |
|---|---|---|---|---|---|---|
| CVE-2026-49223 | Not specified | 7.6high | under 1% · top 69% | — | — | |
| CVE-2026-49222 | Not specified | 7.6high | under 1% · top 69% | — | — | |
| CVE-2026-49217 | Not specified | 7.5high | under 1% · top 83% | — | — | |
| CVE-2026-48771 | Not specified | 8.2high | under 1% · top 89% | — | — | |
| CVE-2026-48763 | Not specified | 8.2high | under 1% · top 68% | — | — | |
| CVE-2026-48486 | Not specified | 7.5high | under 1% · top 90% | — | — | |
| CVE-2026-48447 | Adobe Lightroom | 7.7high | under 1% · top 96% | — | — | |
| CVE-2026-48439 | Adobe C2pa | 7.5high | Not scored | — | — | |
| CVE-2026-48438 | Adobe C2pa | 7.5high | Not scored | — | — | |
| CVE-2026-48416 | Not specified | 7.5high | Not scored | — | — | |
| CVE-2026-48415 | Not specified | 7.6high | under 1% · top 72% | — | — | |
| CVE-2026-48414 | Not specified | 7.7high | under 1% · top 57% | — | — | |
| CVE-2026-48386 | Adobe Coldfusion | 7.5high | Not scored | — | — | |
| CVE-2026-48385 | Adobe Coldfusion | 7.7high | 1.2% · top 34% | — | — | |
| CVE-2026-48364 | Adobe Coldfusion | 8.2high | under 1% · top 81% | — | — | |
| CVE-2026-48363 | Adobe Coldfusion | 8.2high | under 1% · top 81% | — | — | |
| CVE-2026-48345 | Adobe Animate | 8.2high | under 1% · top 43% | — | — | |
| CVE-2026-48290 | Adobe C2pa | 8.2high | under 1% · top 78% | — | — | |
| CVE-2026-47984 | Adobe Commerce | 8.2high | under 1% · top 51% | — | — | |
| CVE-2026-47895 | Not specified | 7.5high | under 1% · top 50% | — | — | |
| CVE-2026-47893 | Vmware Spring Framework | 7.5high | under 1% · top 84% | — | — | |
| CVE-2026-47889 | Vmware Spring Framework | 7.5high | under 1% · top 83% | — | — | |
| CVE-2026-47888 | Vmware Spring Framework | 7.5high | under 1% · top 75% | — | — | |
| CVE-2026-47886 | Vmware Spring Framework | 7.5high | under 1% · top 75% | — | — | |
| CVE-2026-47885 | Vmware Spring Framework | 7.5high | Not scored | — | — |