Monitoring
Control Room/Cyber
Situation category · live

Cyber

Live tracking of critical software vulnerabilities. The engine watches new CVE publications from the NIST National Vulnerability Database and opens a situation whenever a CVSS 9.0+ critical lands.

Active now

Recent

Critical vulnerability — CVE-2026-63732

resolved · 3d ago · NIST NVD

9.9

Critical vulnerability — CVE-2026-54052

resolved · 11d ago · NIST NVD

9.9

Critical vulnerability — CVE-2026-56699

resolved · 11d ago · NIST NVD

10.0

Critical vulnerability — CVE-2026-48318

resolved · 12d ago · NIST NVD

9.9

Critical vulnerability — CVE-2026-47767

resolved · 12d ago · NIST NVD

9.8

Critical vulnerability — CVE-2026-62390

resolved · 12d ago · NIST NVD

9.8

Critical vulnerability — CVE-2026-56451

resolved · 12d ago · NIST NVD

10.0

Critical vulnerability — CVE-2026-61500

resolved · 13d ago · NIST NVD

9.8

Critical vulnerability — CVE-2026-61447

resolved · 15d ago · NIST NVD

10.0

Critical vulnerability — CVE-2026-61445

resolved · 15d ago · NIST NVD

9.9

Critical vulnerability — CVE-2026-58480

resolved · 18d ago · NIST NVD

9.8

Critical vulnerability — CVE-2026-14345

resolved · 19d ago · NIST NVD

9.8

Critical vulnerability — CVE-2026-54763

resolved · 20d ago · NIST NVD

10.0

Critical vulnerability — CVE-2026-9181

resolved · 20d ago · NIST NVD

9.8

Critical vulnerability — CVE-2026-48316

resolved · 20d ago · NIST NVD

10.0

Critical vulnerability — CVE-2026-40141

resolved · 20d ago · NIST NVD

9.9

Critical vulnerability — CVE-2026-14807

resolved · 20d ago · NIST NVD

9.8

Critical vulnerability — CVE-2026-4321

resolved · 23d ago · NIST NVD

9.8

Critical vulnerability — CVE-2026-14544

resolved · 23d ago · NIST NVD

9.8

Background

What a “critical” CVE means

Every vulnerability the engine surfaces here scores 9.0 or higher on CVSS — the Common Vulnerability Scoring System published by FIRST.org, which rates severity from 0.0 to 10.0. A 9.0–10.0 “critical” typically means an attacker can compromise a system remotely with little or no effort: no authentication, no user interaction, and full impact on confidentiality, integrity, or availability. The National Vulnerability Database (NVD), run by NIST, is the authoritative record for each CVE's official description and CVSS metrics (source: FIRST.org CVSS v3.1 specification; NIST NVD).

Score is not the same as urgency

A high CVSS score signals theoretical severity, not active risk. CISA's Known Exploited Vulnerabilities (KEV) catalog tracks which flaws are actually being exploited in the wild — and a CVSS 7.5 that is KEV-listed is more urgent to patch than a CVSS 9.8 with no known exploitation. Sound prioritisation combines the CVSS score with real-world exploitation data (source: CISA Known Exploited Vulnerabilities Catalog).

Featured advisory — CVE-2026-48276 (Adobe ColdFusion)

CVE-2026-48276 is a critical remote-code-execution flaw in Adobe ColdFusion (affecting ColdFusion 2025.9, 2023.20 and earlier) caused by unrestricted upload of a file with a dangerous type. A remote, unauthenticated attacker can upload a server-executable file and run arbitrary code in the context of the ColdFusion service account, with no user interaction required. Adobe published fixed builds in security bulletin APSB26-68; recommended mitigations include applying the update, restricting ColdFusion Administrator and file-upload endpoints to trusted management networks, and auditing web-accessible directories for unauthorised .cfm/.cfc/.jsp files (source: NIST NVD, CVE-2026-48276; Adobe security bulletin APSB26-68). This is factual security-advisory information, not a scan of your systems — confirm your own exposure against the vendor advisory.

Common questions

What does a CVSS score of 9.0 or higher mean?

On the CVSS v3.1 scale (0.0–10.0, published by FIRST.org), 9.0–10.0 is rated “critical” — usually a vulnerability an attacker can exploit remotely with no authentication and no user interaction, resulting in full compromise. Monitoring opens a cyber situation whenever a new CVSS 9.0+ critical is published to the NIST NVD.

What is CVE-2026-48276?

CVE-2026-48276 is a critical remote-code-execution vulnerability in Adobe ColdFusion (2025.9, 2023.20 and earlier) arising from unrestricted upload of a file with a dangerous type: a remote, unauthenticated attacker can upload a server-executable file and run arbitrary code. Adobe released fixed builds in bulletin APSB26-68. (Source: NIST NVD; Adobe APSB26-68.)

Does a high CVSS score mean I should patch it first?

Not necessarily. CVSS measures theoretical severity, while CISA's Known Exploited Vulnerabilities (KEV) catalog tracks what is actually being exploited. A lower-scored but actively-exploited flaw can be more urgent than a higher-scored one with no known exploitation. Prioritise using both signals together.

Is this monitoring, or advice?

This surface is information only. Monitoring mirrors public vulnerability data from the NIST NVD and cites security advisories — it does not scan your systems and it is not security or compliance advice. Always confirm your own exposure against the vendor advisory and CISA guidance.

References

Other categories

Data: NIST NVD · severity levels and detection by Monitoring · refreshes every 5 minutes