Exploited vulnerabilities
The CISA Known Exploited Vulnerabilities catalogue, with severity and affected-product data from the National Vulnerability Database. Everything on this list has been observed in real attacks — it is not a forecast.
- 1695
- On the catalogue
- 8
- Added in 7 days
- 7
- Due within 7 days
- 354
- Used in ransomware
| CVE | Affected | CVSS | Added | Due | |
|---|---|---|---|---|---|
| CVE-2026-34686 | Adobe Commerce | 8.7high | — | — | |
| CVE-2026-34653 | Adobe Commerce | 8.7high | — | — | |
| CVE-2026-34622 | Adobe Acrobat | 8.6high | — | — | |
| CVE-2026-34617 | Adobe Connect | 8.7high | — | — | |
| CVE-2026-33216 | Linuxfoundation Nats-Server | 8.6high | — | — | |
| CVE-2026-27305 | Adobe Coldfusion | 8.6high | — | — | |
| CVE-2026-27290 | Adobe Framemaker | 8.6high | — | — | |
| CVE-2026-27140 | Golang Go | 8.8high | — | — | |
| CVE-2026-23950 | Isaacs Tar | 8.8high | — | — | |
| CVE-2026-21333 | Adobe Illustrator | 8.6high | — | — | |
| CVE-2026-21290 | Adobe Commerce B2b | 8.7high | — | — | |
| CVE-2026-21280 | Adobe Illustrator | 8.6high | — | — | |
| CVE-2026-21272 | Adobe Dreamweaver | 8.6high | — | — | |
| CVE-2026-21271 | Adobe Dreamweaver | 8.6high | — | — | |
| CVE-2026-21268 | Adobe Dreamweaver | 8.6high | — | — | |
| CVE-2026-21267 | Adobe Dreamweaver | 8.6high | — | — | |
| CVE-2026-20094 | Cisco Unified Computing System | 8.8high | — | — | |
| CVE-2025-67030 | Codehaus-Plexus Plexus-Utils | 8.8high | — | — | |
| CVE-2025-61732 | Golang Go | 8.6high | — | — | |
| CVE-2025-34025 | Versa-Networks Concerto | 8.8high | — | — | |
| CVE-2025-15467 | Openssl Openssl | 8.8high | — | — | |
| CVE-2024-33775 | Nagios Nagios Xi | 8.8high | — | — | |
| CVE-2024-21626 | Linuxfoundation Runc | 8.6high | — | — | |
| CVE-2022-25762 | Apache Tomcat | 8.6high | — | — | |
| CVE-2022-20767 | Cisco Secure Firewall Threat Defense | 8.6high | — | — |