Exploited CVEs / By vendor

Actively exploited vulnerabilities by vendor

Every vendor with 5 or more CVEs on the CISA Known Exploited Vulnerabilities catalog. Refreshed daily; vendors join the list automatically as CISA catalogs their CVEs.

VendorExploited CVEsRansomware-linkedNewest addition
Microsoft386114CVE-2019-1068 (2026-08-26)
Cisco966CVE-2026-20349 (2026-08-11)
Apple94-CVE-2026-65400 (2026-08-18)
Adobe8010CVE-2026-48282 (2026-07-07)
Google72-CVE-2026-11645 (2026-06-09)
Oracle4613CVE-2026-21962 (2026-08-24)
Apache408CVE-2026-34486 (2026-08-04)
Ivanti3512CVE-2026-10520 (2026-06-11)
Fortinet2914CVE-2025-68686 (2026-07-27)
Linux282CVE-2026-53362 (2026-08-27)
D-Link262CVE-2025-29635 (2026-04-24)
VMware269CVE-2025-22224 (2025-03-04)
Citrix237CVE-2026-8452 (2026-08-26)
SonicWall1913CVE-2026-83548 (2026-09-02)
Synacor195CVE-2026-73570 (2026-08-21)
Android17-CVE-2025-48595 (2026-06-02)
Palo Alto Networks156CVE-2026-0257 (2026-05-29)
Samsung15-CVE-2024-7399 (2026-04-24)
SAP143CVE-2025-42999 (2025-05-15)
Mozilla131CVE-2010-3765 (2025-10-06)
Atlassian138CVE-2021-26086 (2024-11-12)
Trend Micro12-CVE-2026-34926 (2026-05-21)
Qualcomm12-CVE-2026-21385 (2026-03-03)
Zyxel122CVE-2024-40890 (2025-02-11)
SolarWinds112CVE-2026-28318 (2026-06-05)
Roundcube11-CVE-2025-49113 (2026-02-20)
QNAP119CVE-2023-47565 (2023-12-21)
Red Hat94CVE-2015-3246 (2026-08-26)
Progress94CVE-2026-8037 (2026-08-07)
Arm9-CVE-2024-4610 (2024-06-12)
Zoho92CVE-2022-28810 (2023-03-07)
IBM82CVE-2026-9198 (2026-08-04)
Juniper8-CVE-2015-7755 (2025-10-02)
NETGEAR8-CVE-2017-5521 (2022-09-08)
F574CVE-2025-53521 (2026-03-27)
Mitel75CVE-2024-41710 (2025-02-12)
Sophos72CVE-2020-15069 (2025-02-06)
Jenkins61CVE-2017-1000353 (2025-10-02)
TP-Link6-CVE-2023-50224 (2025-09-03)
PaperCut52CVE-2026-81578 (2026-08-31)
Broadcom5-CVE-2026-59310 (2026-08-18)
Langflow51CVE-2026-0770 (2026-07-21)
WordPress5-CVE-2026-60137 (2026-07-21)
Drupal52CVE-2026-9082 (2026-05-22)
GNU5-CVE-2026-24061 (2026-01-26)
RARLAB54CVE-2025-6218 (2025-12-09)
DrayTek5-CVE-2024-12987 (2025-05-15)
Exim51CVE-2010-4344 (2022-03-25)

Vendors below the 5-CVE threshold are in the full exploited-CVE tracker. The newest additions across all vendors: exploited this week.

New to a term on this page? CVE, KB, KEV, CVSS, and EPSS are each explained once, on the Senserva security lexicon. Reference: Microsoft CVE and vulnerability management and the Microsoft patching guide.
Provided as is, without warranty; verify against the vendor advisory before acting. Data notice and terms.