Cyber
Live tracking of critical software vulnerabilities. The engine watches new CVE publications from the NIST National Vulnerability Database and opens a situation whenever a CVSS 9.0+ critical lands.
Active now
Recent
Critical vulnerability — CVE-2026-63732
● resolved · 3d ago · NIST NVD
Critical vulnerability — CVE-2026-54052
● resolved · 11d ago · NIST NVD
Critical vulnerability — CVE-2026-56699
● resolved · 11d ago · NIST NVD
Critical vulnerability — CVE-2026-48318
● resolved · 12d ago · NIST NVD
Critical vulnerability — CVE-2026-47767
● resolved · 12d ago · NIST NVD
Critical vulnerability — CVE-2026-62390
● resolved · 12d ago · NIST NVD
Critical vulnerability — CVE-2026-56451
● resolved · 12d ago · NIST NVD
Critical vulnerability — CVE-2026-61500
● resolved · 13d ago · NIST NVD
Critical vulnerability — CVE-2026-61447
● resolved · 15d ago · NIST NVD
Critical vulnerability — CVE-2026-61445
● resolved · 15d ago · NIST NVD
Critical vulnerability — CVE-2026-58480
● resolved · 18d ago · NIST NVD
Critical vulnerability — CVE-2026-14345
● resolved · 19d ago · NIST NVD
Critical vulnerability — CVE-2026-54763
● resolved · 20d ago · NIST NVD
Critical vulnerability — CVE-2026-9181
● resolved · 20d ago · NIST NVD
Critical vulnerability — CVE-2026-48316
● resolved · 20d ago · NIST NVD
Critical vulnerability — CVE-2026-40141
● resolved · 20d ago · NIST NVD
Critical vulnerability — CVE-2026-14807
● resolved · 20d ago · NIST NVD
Critical vulnerability — CVE-2026-4321
● resolved · 23d ago · NIST NVD
Critical vulnerability — CVE-2026-14544
● resolved · 23d ago · NIST NVD
Background
What a “critical” CVE means
Every vulnerability the engine surfaces here scores 9.0 or higher on CVSS — the Common Vulnerability Scoring System published by FIRST.org, which rates severity from 0.0 to 10.0. A 9.0–10.0 “critical” typically means an attacker can compromise a system remotely with little or no effort: no authentication, no user interaction, and full impact on confidentiality, integrity, or availability. The National Vulnerability Database (NVD), run by NIST, is the authoritative record for each CVE's official description and CVSS metrics (source: FIRST.org CVSS v3.1 specification; NIST NVD).
Score is not the same as urgency
A high CVSS score signals theoretical severity, not active risk. CISA's Known Exploited Vulnerabilities (KEV) catalog tracks which flaws are actually being exploited in the wild — and a CVSS 7.5 that is KEV-listed is more urgent to patch than a CVSS 9.8 with no known exploitation. Sound prioritisation combines the CVSS score with real-world exploitation data (source: CISA Known Exploited Vulnerabilities Catalog).
Featured advisory — CVE-2026-48276 (Adobe ColdFusion)
CVE-2026-48276 is a critical remote-code-execution flaw in Adobe ColdFusion (affecting ColdFusion 2025.9, 2023.20 and earlier) caused by unrestricted upload of a file with a dangerous type. A remote, unauthenticated attacker can upload a server-executable file and run arbitrary code in the context of the ColdFusion service account, with no user interaction required. Adobe published fixed builds in security bulletin APSB26-68; recommended mitigations include applying the update, restricting ColdFusion Administrator and file-upload endpoints to trusted management networks, and auditing web-accessible directories for unauthorised .cfm/.cfc/.jsp files (source: NIST NVD, CVE-2026-48276; Adobe security bulletin APSB26-68). This is factual security-advisory information, not a scan of your systems — confirm your own exposure against the vendor advisory.
Common questions
What does a CVSS score of 9.0 or higher mean?
On the CVSS v3.1 scale (0.0–10.0, published by FIRST.org), 9.0–10.0 is rated “critical” — usually a vulnerability an attacker can exploit remotely with no authentication and no user interaction, resulting in full compromise. Monitoring opens a cyber situation whenever a new CVSS 9.0+ critical is published to the NIST NVD.
What is CVE-2026-48276?
CVE-2026-48276 is a critical remote-code-execution vulnerability in Adobe ColdFusion (2025.9, 2023.20 and earlier) arising from unrestricted upload of a file with a dangerous type: a remote, unauthenticated attacker can upload a server-executable file and run arbitrary code. Adobe released fixed builds in bulletin APSB26-68. (Source: NIST NVD; Adobe APSB26-68.)
Does a high CVSS score mean I should patch it first?
Not necessarily. CVSS measures theoretical severity, while CISA's Known Exploited Vulnerabilities (KEV) catalog tracks what is actually being exploited. A lower-scored but actively-exploited flaw can be more urgent than a higher-scored one with no known exploitation. Prioritise using both signals together.
Is this monitoring, or advice?
This surface is information only. Monitoring mirrors public vulnerability data from the NIST NVD and cites security advisories — it does not scan your systems and it is not security or compliance advice. Always confirm your own exposure against the vendor advisory and CISA guidance.
References
Other categories
Data: NIST NVD · severity levels and detection by Monitoring · refreshes every 5 minutes