Critical Threat Feed

Showing vulnerabilities with a CRITICAL rating or those confirmed to be actively exploited by CISA.

CVSS 9.6

CVE-2026-39399

Target: NuGet Gallery - Backend Job

CVSS 9.8

CVE-2026-33824

Target: Windows - IKE Extension

CVSS 9

CVE-2026-26149

Target: Microsoft Power Apps

CVSS 9.8

CVE-2026-39813

Target: FortiSandbox - File Directory Service

CVSS 9.8

CVE-2026-39808

Target: FortiSandbox - OS Command Handler

CVSS 8.8

CVE-2009-0238

Actively Exploited

Target: Microsoft Office - Excel

CVSS 7.8

CVE-2023-36424

Actively Exploited

Target: Windows - Common Log File System Driver

CVSS 8.8

CVE-2023-21529

Actively Exploited

Target: Microsoft Exchange Server - Microsoft Exchange Server

CVSS 7.8

CVE-2012-1854

Actively Exploited

Target: Microsoft Office - VBE6.dll

CVSS 8.6

CVE-2026-34621

Actively Exploited

Target: Acrobat & Reader DC (Continuous/Classic)

CVSS 9.8

CVE-2026-34387

Target: Fleet - Software Installer Pipeline

CVSS 9.8

CVE-2026-32186

Target: Microsoft Bing - Search Service

CVSS 9.1

CVE-2026-21671

Target: Veeam Backup & Replication - Backup Administrator

CVSS 9

CVE-2026-27825

Target: MCP Atlassian - MCP Server

CVSS 9.8

CVE-2026-21622

Target: hexpm - Elixir.Hexpm.Accounts.PasswordReset

CVSS 9.6

CVE-2026-25130

Target: Cybersecurity AI (CAI) - Framework

CVSS 9.8

CVE-2025-14237

Target: Canon Laser Printers and Small Office Multifunctional Printers - XPS Font Parse Processing

CVSS 9.8

CVE-2025-14236

Target: Canon - Address Book attribute tag processing

CVSS 9.8

CVE-2025-14235

Target: Canon Laser Printers and Small Office Multifunction Printers - XPS Font FPGM Data Processing

CVSS 9.8

CVE-2025-14234

Target: Canon Printers - CPCA list processing

CVSS 9.8

CVE-2025-14233

Target: Canon Printers - CPCA file deletion processing

CVSS 9.8

CVE-2025-14232

Target: Canon Laser Printers and Small Office Multifunction Printers - XML Processing

CVSS 9.8

CVE-2025-14231

Target: Canon - Print Job Processing by WSD

CVSS 9.1

CVE-2025-11250

Target: ManageEngine ADSelfService Plus - Authentication Module

CVSS 9.8

CVE-2025-40604

Target: SonicWall Email Security - Appliance Root Filesystem

CVSS 9.8

CVE-2025-8324

Target: ManageEngine Analytics Plus - Analytics Plus Service

CVSS 9.9

CVE-2025-48983

Target: Veeam Backup & Replication - Mount service

CVSS 9.8

CVE-2025-58447

Target: rAthena - Login Server

CVSS 9.8

CVE-2025-50901

Target: JEEWMS - Web Application

CVSS 9.8

CVE-2025-54950

Target: PyTorch - ExecuTorch

CVSS 9.1

CVE-2025-45006

Target: Rocket Chip - RISC-V Processor

CVSS 9.6

CVE-2025-3835

Target: ManageEngine Exchange Reporter Plus - Content Search module

CVSS 9.8

CVE-2025-2146

Target: Canon Printers - WebService Authentication

CVSS 9.1

CVE-2025-47928

Target: Spotipy - Python Library for Spotify Web API

CVSS 9

CVE-2025-47154

Target: Ladybird - LibJS

CVSS 9.8

CVE-2024-24421

Target: Magma - nas_message_decode function

CVSS 9.8

CVE-2024-53915

Target: Veritas Enterprise Vault - Server

CVSS 9.8

CVE-2024-53914

Target: Veritas Enterprise Vault - Server

CVSS 9.8

CVE-2024-53913

Target: Veritas Enterprise Vault - Server

CVSS 9.8

CVE-2024-53912

Target: Veritas Enterprise Vault - Server

CVSS 9.8

CVE-2024-53911

Target: Veritas Enterprise Vault - Server

CVSS 9.8

CVE-2024-53910

Target: Veritas Enterprise Vault - Server

CVSS 9.8

CVE-2024-53909

Target: Veritas Enterprise Vault - Server

CVSS 9.8

CVE-2024-45971

Target: MZ Automation LibIEC61850 - MMS Client

CVSS 9.8

CVE-2024-49400

Target: Tacquito - Authorization Service

CVSS 9.8

CVE-2024-32608

Target: HDF5 library

CVSS 9.8

CVE-2024-46946

Target: LangChain Experimental - LLMSymbolicMathChain

CVSS 9.8

CVE-2024-40568

Target: BTstack - Mesh Component

CVSS 9.8

CVE-2024-40766

Actively Exploited

Target: SonicWall SonicOS - Management Access

CVSS 10

CVE-2024-38366

Target: CocoaPods - Trunk Server

CVSS 9

CVE-2024-37899

Target: XWiki Platform - User Profile Service

CVSS 9.9

CVE-2024-35344

Target: Anpviz IP Camera - Firmware

CVSS 9.8

CVE-2024-35343

Target: Anpviz IP Cameras - Web Server

CVSS 9.8

CVE-2024-33874

Target: HDF5 Library - H5Omtime.c

CVSS 9.1

CVE-2024-32622

Target: HDF5 Library - H5FL

CVSS 9.8

CVE-2024-32621

Target: HDF5 Library - H5HG

CVSS 9.8

CVE-2024-32615

Target: HDF5 Library - H5Znbit.c

CVSS 9.8

CVE-2024-32611

Target: HDF5 Library - H5Aint.c

CVSS 9.8

CVE-2024-29164

Target: HDF5 - H5R__decode_heap

CVSS 9.8

CVE-2024-29159

Target: HDF5 - H5Z__filter_scaleoffset

CVSS 9.8

CVE-2024-29157

Target: HDF5 - H5HG_read

CVSS 9.8

CVE-2024-33434

Target: CHAOS - Core Service

CVSS 9.8

CVE-2024-28222

Target: NetBackup - BPCD process

CVSS 9.8

CVE-2024-22394

Target: SonicOS - SSL-VPN

CVSS 9.8

CVE-2026-35616

Target: FortiClientEMS - FortiClient

CVSS 9.6

CVE-2026-28373

Target: Stackfield Desktop App

CVSS 10

CVE-2026-33105

Target: Microsoft Azure Kubernetes Service - Azure Kubernetes

CVSS 9.8

CVE-2026-20160

Target: Cisco Smart Software Manager On-Prem - SSM On-Prem

CVSS 9.8

CVE-2026-20093

Target: Cisco Integrated Management Controller - IMC

CVSS 10

CVE-2026-30302

Target: CodeRider-Kilo - Command Auto-Approval Module

CVSS 9.8

CVE-2026-30303

Target: Axon Code - Command Auto-Approval Module

CVSS 9.8

CVE-2026-30793

Target: RustDesk Client

CVSS 9.8

CVE-2026-30790

Target: RustDesk Server Pro - RustDesk Server

CVSS 9.8

CVE-2026-30789

Target: RustDesk Client

CVSS 9.8

CVE-2026-30783

Target: RustDesk Client

CVSS 10

CVE-2026-20131

Actively Exploited

Target: Cisco Secure Firewall Management Center (FMC) Software

CVSS 9.8

CVE-2026-32194

Target: Microsoft Bing Images - Search Engine

CVSS 9.8

CVE-2026-32191

Target: Microsoft Bing Images - Search Engine

CVSS 9.8

CVE-2023-54330

Target: Inbit Messenger - Network Handler

CVSS 9.8

CVE-2023-38036

Target: Ivanti Avalanche - Manager

CVSS 9.9

CVE-2023-40714

Target: FortiSIEM - GUI

CVSS 9.8

CVE-2023-25610

Target: FortiOS - Administrative Interface

CVSS 9.8

CVE-2023-37936

Target: FortiSwitch - Firmware

CVSS 9.8

CVE-2023-34990

Target: FortiWLM - Web Interface

CVSS 9.9

CVE-2023-20036

Target: Cisco IND - Web UI

CVSS 9.1

CVE-2023-20154

Target: Cisco Modeling Labs - Web Interface

CVSS 9.6

CVE-2023-45590

Target: FortiClient - Linux

CVSS 9.9

CVE-2023-46808

Target: Ivanti Neurons for ITSM - File Upload Component

CVSS 9.8

CVE-2023-48788

Actively Exploited

Target: FortiClientEMS - FortiClientEMS

CVSS 9.6

CVE-2023-47534

Target: FortiClientEMS - CSV Parser

CVSS 9.8

CVE-2023-42789

Target: FortiOS - Firewall

CVSS 9

CVE-2023-46241

Target: Discourse - Microsoft Auth Plugin

CVSS 9.8

CVE-2023-31488

Target: Cisco Secure Email Gateway - Hyland Perceptive Filters

CVSS 10

CVE-2023-51438

Target: SIMATIC IPC - maxView Storage Manager

CVSS 9.8

CVE-2023-52174

Target: XnView Classic - xnview.exe

CVSS 9.8

CVE-2023-52173

Target: XnView Classic - xnview.exe

CVSS 9.8

CVE-2023-48654

Target: One Identity Password Manager - Kiosk Mode

CVSS 9.1

CVE-2023-29487

Target: Heimdal Thor - Threat To Process Correlation

CVSS 9.8

CVE-2023-29486

Target: Heimdal Thor - Next-Gen Antivirus

CVSS 9.8

CVE-2023-29485

Target: Heimdal Thor - DarkLayer Guard