🛡 CISA Known Exploited Vulnerabilities
The live CISA KEV catalog — vulnerabilities confirmed to be actively exploited in the wild, with remediation deadlines. Source: cisa.gov/known-exploited-vulnerabilities-catalog
| CVE | Vendor | Product | Name | Date Added | Due date | Due in | Ransomware | CWEs | Links |
|---|---|---|---|---|---|---|---|---|---|
| CVE-2026-20316 | Cisco | Secure Firewall Management Center (FMC) | Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability | 2026-07-29 | 2026-08-01 | -1d | — | CWE-259 | NVD ↗ CISA ↗ |
| CVE-2025-68686 | Fortinet | FortiOS | Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability | 2026-07-27 | 2026-08-10 | +8d | — | CWE-200 | NVD ↗ CISA ↗ |
| CVE-2026-16812 | Arista | VeloCloud Orchestrator | Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability | 2026-07-27 | 2026-07-30 | -3d | — | CWE-78 | NVD ↗ CISA ↗ |
| CVE-2026-16232 | Check Point | SmartConsole | Check Point SmartConsole Improper Authentication Vulnerability | 2026-07-22 | 2026-07-25 | -8d | — | CWE-287 | NVD ↗ CISA ↗ |
| CVE-2026-50522 | Microsoft | SharePoint | Microsoft SharePoint Deserialization of Untrusted Data Vulnerability | 2026-07-22 | 2026-07-25 | -8d | — | CWE-502 | NVD ↗ CISA ↗ |
| CVE-2026-60137 | WordPress | Core | WordPress Core SQL Injection Vulnerability | 2026-07-21 | 2026-08-04 | +2d | — | CWE-89 | NVD ↗ CISA ↗ |
| CVE-2026-63030 | WordPress | Core | WordPress Core Interpretation Conflict Vulnerability | 2026-07-21 | 2026-07-24 | -9d | — | CWE-436 | NVD ↗ CISA ↗ |
| CVE-2026-0770 | Langflow | Langflow | Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability | 2026-07-21 | 2026-07-24 | -9d | — | CWE-829 | NVD ↗ CISA ↗ |
| CVE-2021-27137 | DD-WRT | DD-WRT | DD-WRT Stack-Based Buffer Overflow Vulnerability | 2026-07-21 | 2026-07-24 | -9d | — | CWE-121 | NVD ↗ CISA ↗ |
| CVE-2026-58644 | Microsoft | SharePoint | Microsoft SharePoint Deserialization of Untrusted Data Vulnerability | 2026-07-16 | 2026-07-19 | -14d | — | CWE-502 | NVD ↗ CISA ↗ |
| CVE-2026-25089 | Fortinet | FortiSandbox | Fortinet FortiSandbox OS Command Injection Vulnerability | 2026-07-16 | 2026-07-19 | -14d | — | CWE-78 | NVD ↗ CISA ↗ |
| CVE-2026-39808 | Fortinet | FortiSandbox | Fortinet FortiSandbox OS Command Injection Vulnerability | 2026-07-16 | 2026-07-19 | -14d | — | CWE-78 | NVD ↗ CISA ↗ |
| CVE-2026-46817 | Oracle | E-Business Suite | Oracle E-Business Suite Improper Privilege Management Vulnerability | 2026-07-15 | 2026-07-18 | -15d | — | CWE-269, CWE-287, CWE-306 | NVD ↗ CISA ↗ |
| CVE-2023-4346 | KNX Association | KNX Protocol Connection Authorization Option 1 | KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability | 2026-07-15 | 2026-07-29 | -4d | — | CWE-645 | NVD ↗ CISA ↗ |
| CVE-2026-56155 | Microsoft | Active Directory Federation Services | Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability | 2026-07-14 | 2026-07-28 | -5d | — | CWE-1220 | NVD ↗ CISA ↗ |
| CVE-2026-56164 | Microsoft | SharePoint Server | Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability | 2026-07-14 | 2026-07-17 | -16d | — | CWE-306 | NVD ↗ CISA ↗ |
| CVE-2026-15409 | SonicWall | SMA1000 Appliances | SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability | 2026-07-14 | 2026-07-17 | -16d | — | CWE-918 | NVD ↗ CISA ↗ |
| CVE-2026-15410 | SonicWall | SMA1000 Appliances | SonicWall SMA1000 Appliances Code Injection Vulnerability | 2026-07-14 | 2026-07-17 | -16d | — | CWE-94 | NVD ↗ CISA ↗ |
| CVE-2008-4128 | Cisco | IOS | Cisco IOS Cross-Site Request Forgery Vulnerability | 2026-07-13 | 2026-07-16 | -17d | — | CWE-352 | NVD ↗ CISA ↗ |
| CVE-2026-56291 | Balbooa | Forms | Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability | 2026-07-10 | 2026-07-13 | -20d | — | CWE-434 | NVD ↗ CISA ↗ |
| CVE-2026-48939 | iCagenda | iCagenda | iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability | 2026-07-10 | 2026-07-13 | -20d | — | CWE-434 | NVD ↗ CISA ↗ |
| CVE-2026-48908 | JoomShaper | SP Page Builder | JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability | 2026-07-07 | 2026-07-10 | -23d | — | CWE-434 | NVD ↗ CISA ↗ |
| CVE-2026-55255 | Langflow | Langflow | Langflow Authorization Bypass Through User-Controlled Key Vulnerability | 2026-07-07 | 2026-07-10 | -23d | — | CWE-639 | NVD ↗ CISA ↗ |
| CVE-2026-56290 | Joomlack | Page Builder | Joomlack Page Builder Improper Access Control Vulnerability | 2026-07-07 | 2026-07-10 | -23d | — | CWE-284 | NVD ↗ CISA ↗ |
| CVE-2026-48282 | Adobe | ColdFusion | Adobe ColdFusion Path Traversal Vulnerability | 2026-07-07 | 2026-07-10 | -23d | — | CWE-22 | NVD ↗ CISA ↗ |
There is no 100% safe environment
Every entry above was, at some point, a patch an organisation hadn't yet applied. No system connected to a network is ever perfectly safe — new flaws are found constantly, and attackers actively hunt for the gap between a vulnerability's disclosure and its remediation. The goal isn't an unreachable "zero risk"; it's shrinking that gap and limiting what a single successful exploit can reach.
What actually reduces the risk
- Patch by exploitability, not just severity — a CVE on this list is being used right now, so it jumps the queue ahead of a higher CVSS score that isn't.
- Keep an accurate, current inventory of internet-facing software and versions — you can't patch what you don't know you're running.
- Segment networks and apply least-privilege access, so one compromised system doesn't hand over the whole environment.
- Keep offline, tested backups — the single biggest factor in surviving a ransomware incident without paying.
- Monitor continuously (SIEM/EDR with real analysts) so exploitation is caught in minutes, not discovered months later.
- Rehearse your incident response plan before you need it — the first time responders read the runbook shouldn't be during a live breach.
Want to know where your own organisation stands against exposures like these?
Distribution by CVSS score
Every published CVE, grouped by its CVSS score band. Most sit in the High/Medium range — a reminder that "not critical" rarely means "not exploitable".
| Severity | Score | Nb CVE |
|---|---|---|
| Critical | 10 | 7,853 |
| Critical | 9.5–9.9 | 1,521 |
| Critical | 9–9.4 | 4,778 |
| High | 8.5–8.9 | 7,293 |
| High | 8–8.4 | 8,773 |
| High | 7.5–7.9 | 43,524 |
| High | 7–7.4 | 20,687 |
| Medium | 6.5–6.9 | 27,534 |
| Medium | 6–6.4 | 19,978 |
| Medium | 5.5–5.9 | 33,155 |
| Medium | 5–5.4 | 17,389 |
| Medium | 4.5–4.9 | 5,958 |
| Medium | 4–4.4 | 2,501 |
| Low | 3.5–3.9 | 2,621 |
| Low | 3–3.4 | 622 |
| Low | 2.5–2.9 | 1,812 |
| Low | 2–2.4 | 2,705 |
| Low | 1.5–1.9 | 116 |
| Low | 1–1.4 | 235 |
| Low | 0.5–0.9 | 14 |
CVEs created per quarter
The volume of newly published CVEs, quarter by quarter, since CVE numbering began — the steady climb reflects both more software and far better disclosure practice, not just "things getting worse".
| Period | Nb CVE |
|---|---|
| July 01, 2026 → September 30, 2026 | 2,584 |
| April 01, 2026 → June 30, 2026 | 20,629 |
| January 01, 2026 → March 31, 2026 | 16,256 |
| October 01, 2025 → December 31, 2025 | 13,148 |
| July 01, 2025 → September 30, 2025 | 12,206 |
| April 01, 2025 → June 30, 2025 | 12,206 |
| January 01, 2025 → March 31, 2025 | 12,410 |
| October 01, 2024 → December 31, 2024 | 11,131 |
| July 01, 2024 → September 30, 2024 | 8,659 |
| April 01, 2024 → June 30, 2024 | 12,007 |
| January 01, 2024 → March 31, 2024 | 8,909 |
| October 01, 2023 → December 31, 2023 | 7,914 |
| July 01, 2023 → September 30, 2023 | 7,699 |
| April 01, 2023 → June 30, 2023 | 7,514 |
| January 01, 2023 → March 31, 2023 | 7,822 |
| October 01, 2022 → December 31, 2022 | 6,797 |
| July 01, 2022 → September 30, 2022 | 6,885 |
| April 01, 2022 → June 30, 2022 | 6,431 |
| January 01, 2022 → March 31, 2022 | 6,301 |
| October 01, 2021 → December 31, 2021 | 5,783 |
| July 01, 2021 → September 30, 2021 | 5,779 |
| April 01, 2021 → June 30, 2021 | 5,375 |
| January 01, 2021 → March 31, 2021 | 5,027 |
| October 01, 2020 → December 31, 2020 | 4,633 |
| July 01, 2020 → September 30, 2020 | 4,329 |