Exploited CVEs / By vendor

Actively exploited vulnerabilities by vendor

Every vendor with 5 or more CVEs on the CISA Known Exploited Vulnerabilities catalog. Refreshed daily; vendors join the list automatically as CISA catalogs their CVEs.

VendorExploited CVEsRansomware-linkedNewest addition
Microsoft383105CVE-2026-68820 (2026-08-11)
Cisco966CVE-2026-20349 (2026-08-11)
Apple93-CVE-2025-31277 (2026-03-20)
Adobe8010CVE-2026-48282 (2026-07-07)
Google72-CVE-2026-11645 (2026-06-09)
Oracle4513CVE-2026-46817 (2026-07-15)
Apache408CVE-2026-34486 (2026-08-04)
Ivanti3512CVE-2026-10520 (2026-06-11)
Fortinet2913CVE-2025-68686 (2026-07-27)
Linux262CVE-2022-0492 (2026-06-02)
D-Link262CVE-2025-29635 (2026-04-24)
VMware269CVE-2025-22224 (2025-03-04)
Citrix227CVE-2026-3055 (2026-03-30)
Synacor185CVE-2025-48700 (2026-04-20)
SonicWall1712CVE-2026-15409 (2026-07-14)
Android17-CVE-2025-48595 (2026-06-02)
Palo Alto Networks156CVE-2026-0257 (2026-05-29)
Samsung15-CVE-2024-7399 (2026-04-24)
SAP143CVE-2025-42999 (2025-05-15)
Mozilla131CVE-2010-3765 (2025-10-06)
Atlassian138CVE-2021-26086 (2024-11-12)
Trend Micro12-CVE-2026-34926 (2026-05-21)
Qualcomm12-CVE-2026-21385 (2026-03-03)
Zyxel122CVE-2024-40890 (2025-02-11)
SolarWinds112CVE-2026-28318 (2026-06-05)
Roundcube11-CVE-2025-49113 (2026-02-20)
QNAP119CVE-2023-47565 (2023-12-21)
Progress94CVE-2026-8037 (2026-08-07)
Arm9-CVE-2024-4610 (2024-06-12)
Zoho92CVE-2022-28810 (2023-03-07)
IBM82CVE-2026-9198 (2026-08-04)
Juniper8-CVE-2015-7755 (2025-10-02)
NETGEAR8-CVE-2017-5521 (2022-09-08)
F574CVE-2025-53521 (2026-03-27)
Mitel75CVE-2024-41710 (2025-02-12)
Sophos71CVE-2020-15069 (2025-02-06)
Red Hat73CVE-2018-14667 (2023-09-28)
Jenkins61CVE-2017-1000353 (2025-10-02)
TP-Link6-CVE-2023-50224 (2025-09-03)
Langflow51CVE-2026-0770 (2026-07-21)
WordPress5-CVE-2026-60137 (2026-07-21)
Drupal52CVE-2026-9082 (2026-05-22)
GNU5-CVE-2026-24061 (2026-01-26)
RARLAB54CVE-2025-6218 (2025-12-09)
DrayTek5-CVE-2024-12987 (2025-05-15)
Exim51CVE-2010-4344 (2022-03-25)

Vendors below the 5-CVE threshold are in the full exploited-CVE tracker. The newest additions across all vendors: exploited this week.

New to a term on this page? CVE, KB, KEV, CVSS, and EPSS are each explained once, on the Senserva security lexicon. Reference: Microsoft CVE and vulnerability management and the Microsoft patching guide.
Provided as is, without warranty; verify against the vendor advisory before acting. Data notice and terms.