Threat radar

What attackers are exploiting—and what may be next

Vulnerabilities confirmed as exploited in the wild, and those with the highest predicted likelihood of exploitation.

Updated 09 Oct 2026 16:20 UTC

Public threat intelligence only. No customer environment data is shown.

Confirmed exploitationPredicted nextHow scoring works

EPSS probability of a sample of these vulnerabilitiesRadar plot of 36 of the vulnerabilities listed below. Distance from the centre is the EPSS probability on a compressed scale: closer to the centre means a higher modelled probability of exploitation in the next 30 days. Red points are confirmed exploited by CISA KEV; blue points are EPSS forecast entries. Position around the circle carries no meaning, and nothing here shows location or attack volume.

Confirmed (CISA KEV)Predicted (EPSS)Closer to the centre = higher EPSS probability. Position shows no location and no attack volume.

What this page is drawn from

  • 1,739Confirmed catalogEntries on CISA’s Known Exploited Vulnerabilities catalog
  • 40Recently confirmedThe most recently published of those, listed below
  • 0Awaiting CVSSOf those, how many have no severity score yet
  • 403,874Advisory recordsEvery advisory ingested, 1988 to date
  • CISA KEV
  • CVE Program
  • FIRST EPSS
  • ExploitDB
  • NVD
  • OSV

Confirmed

CISA KEV

Published evidence of exploitation in the wild

Predicted

FIRST EPSS

Estimated probability of exploitation in the next 30 days

Confirmed is evidence. Predicted is probability. Neither tells you whether your environment is exposed.

Confirmed · CISA KEV

Confirmed exploited in the wild

Every entry is on CISA’s Known Exploited Vulnerabilities catalog: an authority has published evidence of exploitation. Most recent first. 1,739 entries in the catalog in total.

CVSS severity of the 40 entries listed
  • Critical23
  • High15
  • Medium2
  • Low0
  • Not scored0

Critical: 23; High: 15; Medium: 2; Low: 0; Not scored: 0 out of 40 entries.

Vulnerabilities confirmed exploited in the wild, most recently published first
CVEWhat it isCVSSEPSSPublished
CVE-2026-88779 (opens the NVD record in a new tab)Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41…7.5High0.6%04 Oct 2026
CVE-2026-104286 (opens the NVD record in a new tab)An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in…9.8Critical2.2%01 Oct 2026
CVE-2026-102490 (opens the NVD record in a new tab)Zammad packages built with packager.io (DEB and RPM) could have allowed a local attacker who…9.8Critical0.5%30 Sep 2026
CVE-2026-102489 (opens the NVD record in a new tab)Undisclosed RCE in Zammad v6.3 and higher8.7High1.3%30 Sep 2026
CVE-2026-76504 (opens the NVD record in a new tab)A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN…9.8Critical1.8%30 Sep 2026
CVE-2026-86950 (opens the NVD record in a new tab)An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in…8.8High1.2%28 Sep 2026
CVE-2026-88772 (opens the NVD record in a new tab)Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC…8.1High1.3%27 Sep 2026
CVE-2026-88771 (opens the NVD record in a new tab)Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. …9.8Critical1.1%27 Sep 2026
CVE-2026-87902 (opens the NVD record in a new tab)An unauthenticated attacker can make `get_page_template()` page-template resolution include a…8.1High40.0%22 Sep 2026
CVE-2026-94127 (opens the NVD record in a new tab)When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific…9.8Critical2.2%22 Sep 2026
CVE-2026-93616 (opens the NVD record in a new tab)A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload…9.8Critical19.7%22 Sep 2026
CVE-2026-93952 (opens the NVD record in a new tab)VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote…10.0Critical1.1%22 Sep 2026
CVE-2026-76460 (opens the NVD record in a new tab)A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated…10.0Critical14.0%16 Sep 2026
CVE-2026-87886 (opens the NVD record in a new tab)Local privilege escalation due to insecure file permissions. The following products are affected…7.8High0.2%16 Sep 2026
CVE-2026-58704 (opens the NVD record in a new tab)In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This…8.8High0.6%15 Sep 2026
CVE-2026-76461 (opens the NVD record in a new tab)A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway…9.8Critical28.3%14 Sep 2026
CVE-2026-85706 (opens the NVD record in a new tab)GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.11.12…10.0Critical93.0%11 Sep 2026
CVE-2026-85102 (opens the NVD record in a new tab)Improper certificate trust validation during VPN negotiation in Check Point Quantum Security…9.8Critical7.5%09 Sep 2026
CVE-2026-87491 (opens the NVD record in a new tab)Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to…8.8High3.1%09 Sep 2026
CVE-2026-84869 (opens the NVD record in a new tab)A condition in the ScreenConnect client may allow files to be transferred and executed through an…9.9Critical0.9%08 Sep 2026
CVE-2026-85880 (opens the NVD record in a new tab)Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability7.8High3.6%08 Sep 2026
CVE-2026-75650 (opens the NVD record in a new tab)Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template…10.0Critical3.9%08 Sep 2026
CVE-2026-86218 (opens the NVD record in a new tab)N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before…9.8Critical14.5%08 Sep 2026
CVE-2026-81963 (opens the NVD record in a new tab)Windows Update Stack Elevation of Privilege Vulnerability7.8High0.4%08 Sep 2026
CVE-2026-86060 (opens the NVD record in a new tab)RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin…9.8Critical6.4%05 Sep 2026
CVE-2026-67279 (opens the NVD record in a new tab)RouterOS SSH enters the connection protocol after a client-requested rekey even though user…6.5Medium1.0%05 Sep 2026
CVE-2026-67277 (opens the NVD record in a new tab)RouterOS accepts a "related" btest connection before the corresponding primary session has…8.2High1.6%05 Sep 2026
CVE-2026-85046 (opens the NVD record in a new tab)Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute…8.8High48.9%04 Sep 2026
CVE-2026-83548 (opens the NVD record in a new tab)A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due…10.0Critical8.8%02 Sep 2026
CVE-2026-82329 (opens the NVD record in a new tab)JFrog Artifactory contains an authentication weakness that, under default configuration, may allow…9.8Critical14.1%02 Sep 2026
CVE-2026-49869 (opens the NVD record in a new tab)Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21…10.0Critical2.1%02 Sep 2026
CVE-2026-83549 (opens the NVD record in a new tab)Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command…7.8High10.8%02 Sep 2026
CVE-2026-9586 (opens the NVD record in a new tab)An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3…9.8Critical19.0%02 Sep 2026
CVE-2026-81578 (opens the NVD record in a new tab)An improper access control vulnerability exists in the web management interface of PaperCut MF and…9.8Critical85.6%31 Aug 2026
CVE-2026-82078 (opens the NVD record in a new tab)An unsafe dynamic class loading vulnerability exists in the database connection utilities of…9.1Critical63.5%31 Aug 2026
CVE-2026-53362 (opens the NVD record in a new tab)In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on…7.8High0.7%27 Aug 2026
CVE-2026-66384 (opens the NVD record in a new tab)An authenticated user may write data outside the intended Docker cache path under specific…5.3Medium0.7%27 Aug 2026
CVE-2026-8452 (opens the NVD record in a new tab)Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or…9.8Critical1.0%26 Aug 2026
CVE-2026-60004 (opens the NVD record in a new tab)Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook…9.8Critical24.0%25 Aug 2026
CVE-2026-73570 (opens the NVD record in a new tab)A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the…8.9High71.7%21 Aug 2026

Being on this list does not mean you are affected — it means the software is under attack somewhere. Whether you run it, whether it is reachable, and whether anything of yours is behind it are separate questions.

Predicted · EPSS

Highest exploitation probability, not yet in the catalog

Ranked by EPSS, FIRST’s model of the probability of exploitation in the next 30 days. This is a forecast, not observed exploitation. Catalog entries are excluded, and the publication year is shown: a high score on an older CVE usually means continuous opportunistic attack rather than something new.

CVSS severity of the 40 entries listed
  • Critical14
  • High9
  • Medium15
  • Low2
  • Not scored0

Critical: 14; High: 9; Medium: 15; Low: 2; Not scored: 0 out of 40 entries.

Vulnerabilities with the highest predicted exploitation probability, highest first
CVEWhat it isCVSSEPSSPublished
CVE-2021-45105 (opens the NVD record in a new tab)Apache Log4j2 does not always protect from infinite recursion in lookup evaluation5.9Medium100.0%18 Dec 20212021
CVE-2014-3566 (opens the NVD record in a new tab)The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a…3.4Low100.0%15 Oct 20142014
CVE-2023-50387 (opens the NVD record in a new tab)Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses…7.5High100.0%14 Feb 20242024
CVE-2014-0195 (opens the NVD record in a new tab)The dtls1_reassemble_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly validate fragment lengths in DTLS ClientHello messages…6.8Medium100.0%05 Jun 20142014
CVE-2014-3704 (opens the NVD record in a new tab)The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection…7.5High100.0%16 Oct 20142014
CVE-2015-7297 (opens the NVD record in a new tab)SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than…7.5High100.0%29 Oct 20152015
CVE-2012-1456 (opens the NVD record in a new tab)The TAR file parser in AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, Fortinet…4.3Medium99.9%21 Mar 20122012
CVE-2019-0232 (opens the NVD record in a new tab)When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 is vulnerable to Remote Code Execution due to a…8.1High99.9%15 Apr 20192019
CVE-2024-29826 (opens the NVD record in a new tab)An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary…9.6Critical99.9%31 May 20242024
CVE-2024-29825 (opens the NVD record in a new tab)An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary…9.6Critical99.9%31 May 20242024
CVE-2024-29823 (opens the NVD record in a new tab)An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary…9.6Critical99.9%31 May 20242024
CVE-2015-4000 (opens the NVD record in a new tab)The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to…3.7Low99.9%21 May 20152015
CVE-2020-13379 (opens the NVD record in a new tab)The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL…8.2High99.9%03 Jun 20202020
CVE-2017-12635 (opens the NVD record in a new tab)Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB before 1.7.0 and 2.x before 2.1.1 to submit _users documents with duplicate keys…9.8Critical99.8%14 Nov 20172017
CVE-2017-8917 (opens the NVD record in a new tab)SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspecified…9.8Critical99.8%17 May 20172017
CVE-2012-1459 (opens the NVD record in a new tab)The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190…4.3Medium99.8%21 Mar 20122012
CVE-2025-53771 (opens the NVD record in a new tab)Microsoft SharePoint Server Spoofing Vulnerability6.5Medium99.8%20 Jul 20252025
CVE-2022-39952 (opens the NVD record in a new tab)A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through…9.8Critical99.8%16 Feb 20232023
CVE-2012-1446 (opens the NVD record in a new tab)The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400.0.1158, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Norman Antivirus 6.06.12…4.3Medium99.7%21 Mar 20122012
CVE-2008-2938 (opens the NVD record in a new tab)Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when allowLinking and UTF-8 are enabled, allows remote attackers to read…4.3Medium99.7%13 Aug 20082008
CVE-2020-10220 (opens the NVD record in a new tab)An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php searchColumn…9.8Critical99.7%07 Mar 20202020
CVE-2023-27372 (opens the NVD record in a new tab)SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18, 4.0.10, 4.1.8, and…9.8Critical99.7%28 Feb 20232023
CVE-2012-1443 (opens the NVD record in a new tab)The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Command…4.3Medium99.6%21 Mar 20122012
CVE-2020-14181 (opens the NVD record in a new tab)Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerability in the /ViewUserHover.jspa endpoint. The…5.3Medium99.6%17 Sep 20202020
CVE-2020-16040 (opens the NVD record in a new tab)Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML…6.5Medium99.6%08 Jan 20212021
CVE-2022-1471 (opens the NVD record in a new tab)Remote Code execution in SnakeYAML8.3High99.6%01 Dec 20222022
CVE-2014-0094 (opens the NVD record in a new tab)The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via the class parameter, which is passed to the getClass…5.0Medium99.6%11 Mar 20142014
CVE-2017-1000028 (opens the NVD record in a new tab)Oracle, GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated Directory Traversal vulnerability, that can be exploited by issuing a specially crafted HTTP…7.5High99.5%17 Jul 20172017
CVE-2013-0156 (opens the NVD record in a new tab)active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly restrict casts of string values, which…7.5High99.4%13 Jan 20132013
CVE-2023-37679 (opens the NVD record in a new tab)A remote command execution (RCE) vulnerability in NextGen Mirth Connect v4.3.0 allows attackers to execute arbitrary commands on the hosting…9.8Critical99.4%03 Aug 20232023
CVE-2023-32560 (opens the NVD record in a new tab)An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disruption or arbitrary code execution. Thanks to a Researcher at Tenable for…8.8High99.4%10 Aug 20232023
CVE-2023-34960 (opens the NVD record in a new tab)A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to execute arbitrary commands via a SOAP API call with a crafted PowerPoint…9.8Critical99.3%01 Aug 20232023
CVE-2021-34429 (opens the NVD record in a new tab)For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF directory and/or bypass some security…5.3Medium99.3%15 Jul 20212021
CVE-2017-12542 (opens the NVD record in a new tab)A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53 was…10.0Critical99.3%15 Feb 20182018
CVE-2018-12998 (opens the NVD record in a new tab)A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration Manager before build 123128, OpManager before build 123148…6.1Medium99.3%29 Jun 20182018
CVE-2023-23333 (opens the NVD record in a new tab)There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restrictions through…9.8Critical99.3%06 Feb 20232023
CVE-2020-11022 (opens the NVD record in a new tab)jQuery has a potential XSS vulnerability6.9Medium99.2%29 Apr 20202020
CVE-2020-36289 (opens the NVD record in a new tab)Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerability in the…5.3Medium99.2%12 May 20212021
CVE-2022-40300 (opens the NVD record in a new tab)Zoho ManageEngine Password Manager Pro through 12120 before 12121, PAM360 through 5550 before 5600, and Access Manager Plus through 4304 before 4305 have multiple SQL injection…9.8Critical99.1%16 Sep 20222022
CVE-2015-1538 (opens the NVD record in a new tab)Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android before 5.1.1 LMY48I allows remote attackers to execute arbitrary code via crafted…10.0Critical99.1%01 Oct 20152015

How to read this radar

CVSS — impact

How severe exploitation would be. It says nothing about whether anyone is exploiting it.

EPSS — probability

A published model’s forecast for the next 30 days. A probability, not an observation.

CISA KEV — evidence

An authority has published evidence that this is being exploited somewhere.

Neither list is ordered by CVSS. Ordering by severity alone sends a team to a 9.8 nobody has ever attacked ahead of a 7.5 being used today. Confirmed exploitation on a reachable asset is what deserves attention first — which needs your estate, not a catalog. See how Exploit Hound ranks it →

  1. Threat intelligence
  2. Your assets
  3. Reachability
  4. Prioritized remediation

These are the threats. Which ones can actually reach you?

Public threat intelligence shows what is being attacked. Exploit Hound shows which vulnerable assets are present, exposed, reachable, and worth fixing first.

Start Finding ExposureSee the product tour

v2.80.1 Exploit Hound 2.80.1 · Continuous Threat Exposure Management