// Cyber Threat

🛡 CISA Known Exploited Vulnerabilities

The live CISA KEV catalog — vulnerabilities confirmed to be actively exploited in the wild, with remediation deadlines. Source: cisa.gov/known-exploited-vulnerabilities-catalog

Total1,656
Catalog date2026-07-29
Released2026-07-29 18:45 UTC
Last Fetched2026-08-02 19:59 UTC
Refresh in32m 56s
1,656Results
276Vendors
332Known ransomware
1,654Overdue
CVEVendorProductNameDate AddedDue dateDue inRansomwareCWEsLinks
CVE-2026-20316CiscoSecure Firewall Management Center (FMC)Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability2026-07-292026-08-01-1dCWE-259NVD ↗ CISA ↗
CVE-2025-68686FortinetFortiOSFortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability2026-07-272026-08-10+8dCWE-200NVD ↗ CISA ↗
CVE-2026-16812AristaVeloCloud OrchestratorArista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability2026-07-272026-07-30-3dCWE-78NVD ↗ CISA ↗
CVE-2026-16232Check PointSmartConsoleCheck Point SmartConsole Improper Authentication Vulnerability2026-07-222026-07-25-8dCWE-287NVD ↗ CISA ↗
CVE-2026-50522MicrosoftSharePointMicrosoft SharePoint Deserialization of Untrusted Data Vulnerability 2026-07-222026-07-25-8dCWE-502NVD ↗ CISA ↗
CVE-2026-60137WordPressCoreWordPress Core SQL Injection Vulnerability2026-07-212026-08-04+2dCWE-89NVD ↗ CISA ↗
CVE-2026-63030WordPressCoreWordPress Core Interpretation Conflict Vulnerability2026-07-212026-07-24-9dCWE-436NVD ↗ CISA ↗
CVE-2026-0770LangflowLangflowLangflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability2026-07-212026-07-24-9dCWE-829NVD ↗ CISA ↗
CVE-2021-27137DD-WRTDD-WRTDD-WRT Stack-Based Buffer Overflow Vulnerability2026-07-212026-07-24-9dCWE-121NVD ↗ CISA ↗
CVE-2026-58644MicrosoftSharePointMicrosoft SharePoint Deserialization of Untrusted Data Vulnerability2026-07-162026-07-19-14dCWE-502NVD ↗ CISA ↗
CVE-2026-25089FortinetFortiSandboxFortinet FortiSandbox OS Command Injection Vulnerability2026-07-162026-07-19-14dCWE-78NVD ↗ CISA ↗
CVE-2026-39808FortinetFortiSandboxFortinet FortiSandbox OS Command Injection Vulnerability2026-07-162026-07-19-14dCWE-78NVD ↗ CISA ↗
CVE-2026-46817OracleE-Business SuiteOracle E-Business Suite Improper Privilege Management Vulnerability2026-07-152026-07-18-15dCWE-269, CWE-287, CWE-306NVD ↗ CISA ↗
CVE-2023-4346KNX AssociationKNX Protocol Connection Authorization Option 1KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability2026-07-152026-07-29-4dCWE-645NVD ↗ CISA ↗
CVE-2026-56155MicrosoftActive Directory Federation ServicesMicrosoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability 2026-07-142026-07-28-5dCWE-1220NVD ↗ CISA ↗
CVE-2026-56164MicrosoftSharePoint ServerMicrosoft SharePoint Server Missing Authentication for Critical Function Vulnerability2026-07-142026-07-17-16dCWE-306NVD ↗ CISA ↗
CVE-2026-15409SonicWallSMA1000 AppliancesSonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability2026-07-142026-07-17-16dCWE-918NVD ↗ CISA ↗
CVE-2026-15410SonicWallSMA1000 AppliancesSonicWall SMA1000 Appliances Code Injection Vulnerability2026-07-142026-07-17-16dCWE-94NVD ↗ CISA ↗
CVE-2008-4128CiscoIOSCisco IOS Cross-Site Request Forgery Vulnerability2026-07-132026-07-16-17dCWE-352NVD ↗ CISA ↗
CVE-2026-56291BalbooaFormsBalbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability2026-07-102026-07-13-20dCWE-434NVD ↗ CISA ↗
CVE-2026-48939iCagendaiCagendaiCagenda Unrestricted Upload of File with Dangerous Type Vulnerability2026-07-102026-07-13-20dCWE-434NVD ↗ CISA ↗
CVE-2026-48908JoomShaperSP Page BuilderJoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability2026-07-072026-07-10-23dCWE-434NVD ↗ CISA ↗
CVE-2026-55255LangflowLangflowLangflow Authorization Bypass Through User-Controlled Key Vulnerability2026-07-072026-07-10-23dCWE-639NVD ↗ CISA ↗
CVE-2026-56290JoomlackPage BuilderJoomlack Page Builder Improper Access Control Vulnerability2026-07-072026-07-10-23dCWE-284NVD ↗ CISA ↗
CVE-2026-48282AdobeColdFusionAdobe ColdFusion Path Traversal Vulnerability2026-07-072026-07-10-23dCWE-22NVD ↗ CISA ↗
Page 1 of 67 — 1,656 entries

There is no 100% safe environment

Every entry above was, at some point, a patch an organisation hadn't yet applied. No system connected to a network is ever perfectly safe — new flaws are found constantly, and attackers actively hunt for the gap between a vulnerability's disclosure and its remediation. The goal isn't an unreachable "zero risk"; it's shrinking that gap and limiting what a single successful exploit can reach.

What actually reduces the risk

  • Patch by exploitability, not just severity — a CVE on this list is being used right now, so it jumps the queue ahead of a higher CVSS score that isn't.
  • Keep an accurate, current inventory of internet-facing software and versions — you can't patch what you don't know you're running.
  • Segment networks and apply least-privilege access, so one compromised system doesn't hand over the whole environment.
  • Keep offline, tested backups — the single biggest factor in surviving a ransomware incident without paying.
  • Monitor continuously (SIEM/EDR with real analysts) so exploitation is caught in minutes, not discovered months later.
  • Rehearse your incident response plan before you need it — the first time responders read the runbook shouldn't be during a live breach.

Want to know where your own organisation stands against exposures like these?

// the wider CVE landscape

Distribution by CVSS score

Every published CVE, grouped by its CVSS score band. Most sit in the High/Medium range — a reminder that "not critical" rarely means "not exploitable".

109.5–9.99–9.48.5–8.98–8.47.5–7.97–7.46.5–6.96–6.45.5–5.95–5.44.5–4.94–4.43.5–3.93–3.42.5–2.92–2.41.5–1.91–1.40.5–0.9010,00020,00030,00040,000
CriticalHighMediumLow
SeverityScoreNb CVE
Critical107,853
Critical9.5–9.91,521
Critical9–9.44,778
High8.5–8.97,293
High8–8.48,773
High7.5–7.943,524
High7–7.420,687
Medium6.5–6.927,534
Medium6–6.419,978
Medium5.5–5.933,155
Medium5–5.417,389
Medium4.5–4.95,958
Medium4–4.42,501
Low3.5–3.92,621
Low3–3.4622
Low2.5–2.91,812
Low2–2.42,705
Low1.5–1.9116
Low1–1.4235
Low0.5–0.914
// since 1988

CVEs created per quarter

The volume of newly published CVEs, quarter by quarter, since CVE numbering began — the steady climb reflects both more software and far better disclosure practice, not just "things getting worse".

1990199520002005201020152020202505,00010,00015,00020,000
PeriodNb CVE
July 01, 2026 → September 30, 20262,584
April 01, 2026 → June 30, 202620,629
January 01, 2026 → March 31, 202616,256
October 01, 2025 → December 31, 202513,148
July 01, 2025 → September 30, 202512,206
April 01, 2025 → June 30, 202512,206
January 01, 2025 → March 31, 202512,410
October 01, 2024 → December 31, 202411,131
July 01, 2024 → September 30, 20248,659
April 01, 2024 → June 30, 202412,007
January 01, 2024 → March 31, 20248,909
October 01, 2023 → December 31, 20237,914
July 01, 2023 → September 30, 20237,699
April 01, 2023 → June 30, 20237,514
January 01, 2023 → March 31, 20237,822
October 01, 2022 → December 31, 20226,797
July 01, 2022 → September 30, 20226,885
April 01, 2022 → June 30, 20226,431
January 01, 2022 → March 31, 20226,301
October 01, 2021 → December 31, 20215,783
July 01, 2021 → September 30, 20215,779
April 01, 2021 → June 30, 20215,375
January 01, 2021 → March 31, 20215,027
October 01, 2020 → December 31, 20204,633
July 01, 2020 → September 30, 20204,329
Page 1 of 7 — 151 entries

← Zurück zur Cyber-Welt