Exploited CVEs / By vendor / Qualcomm

Qualcomm vulnerabilities actively exploited

12 Qualcomm CVEs on the CISA Known Exploited Vulnerabilities catalog, newest first. Refreshed daily.

Every CVE below is confirmed exploited in the wild, not just theoretically severe. The newest addition is CVE-2026-21385 (Multiple Chipsets, added 2026-03-03). New CISA KEV entries appear here the day they are cataloged; the freshest across all vendors are on exploited this week.

12 exploited CVEs
Senserva AI Opinion and rich prompt for Qualcomm exploited CVEs

Copy this prompt into Claude, ChatGPT, or Copilot. The facts are included, sourced from this page.

Multiple Chipsets: 11 exploited CVEs

CVEProductAdded to KEVSignals
CVE-2026-21385Multiple Chipsets2026-03-03CVSS 7.8, EPSS 1%
CVE-2025-21479Multiple Chipsets2025-06-03CVSS 8.6, EPSS 1%
CVE-2025-21480Multiple Chipsets2025-06-03CVSS 8.6, EPSS 0%
CVE-2025-27038Multiple Chipsets2025-06-03CVSS 7.5, EPSS 1%
CVE-2024-43047Multiple Chipsets2024-10-08CVSS 7.8, EPSS 1%
CVE-2022-22071Multiple Chipsets2023-12-05CVSS 7.8, EPSS 0%
CVE-2023-33063Multiple Chipsets2023-12-05CVSS 7.8, EPSS 1%
CVE-2023-33106Multiple Chipsets2023-12-05CVSS 7.8, EPSS 1%
CVE-2023-33107Multiple Chipsets2023-12-05CVSS 7.8, EPSS 1%
CVE-2021-1905Multiple Chipsets2021-11-03CVSS 7.8, EPSS 1%
CVE-2021-1906Multiple Chipsets2021-11-03CVSS 5.5, EPSS 1%

Other Qualcomm products

CVEProductAdded to KEVSignals
CVE-2020-11261Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables2021-12-01CVSS 7.8, EPSS 2%

Common questions about exploited Qualcomm CVEs

Which Qualcomm vulnerabilities are actively exploited?

As of August 2026, 12 Qualcomm CVEs are on the CISA Known Exploited Vulnerabilities catalog, meaning exploitation in the wild is confirmed. The most-listed products are Multiple Chipsets (11).

What is the newest exploited Qualcomm CVE?

CVE-2026-21385, affecting Multiple Chipsets, added to the CISA KEV catalog on 2026-03-03. This page refreshes daily, so the newest entry is always first in the table.

How urgent are these Qualcomm CVEs?

KEV listing is the strongest fix-first signal there is: it means confirmed exploitation, not a prediction. Patch these ahead of higher-CVSS issues that nobody is exploiting. Check the vendor advisory (linked below) for fixed versions and workarounds.

Can I ask my own AI about exploited Qualcomm CVEs?

Yes. This page includes a free copy-paste AI prompt carrying the newest Qualcomm KEV entries, with CVSS, EPSS, and ransomware context, into Claude, ChatGPT, or Copilot. The data is refreshed twice a day (5 AM and 3 PM US Central).

All vendors, searchable with due dates and CSV export: the exploited-CVE tracker. Every vendor with a page: exploited by vendor.

Most searched on Senserva right now

New to a term on this page? CVE, KB, KEV, CVSS, and EPSS are each explained once, on the Senserva security lexicon. Reference: Microsoft CVE and vulnerability management and the Microsoft patching guide.
Provided as is, without warranty; verify against the vendor advisory before acting. Data notice and terms.