{"ok":true,"source":"CISA KEV","updated":"2026-09-24T19:00:55.0481Z","items":[{"n":"1,700+","t":"software flaws are confirmed to be under active attack right now — meaning criminals are already using them to break into real organizations","s":"CISA Known Exploited Vulnerabilities catalog"},{"n":"47","t":"of those were flagged as actively-exploited in just the last 30 days, so the list of live threats grows almost every week","s":"U.S. government's official exploited-flaw watchlist"},{"n":"1 in 5","t":"of these actively-exploited flaws is known to be used in ransomware attacks — the kind that lock up a business until it pays","s":"CISA Known Exploited Vulnerabilities catalog"},{"n":"Live","t":"attackers are actively exploiting a security hole in WSO2 Multiple Products — if your business uses it, applying the vendor's update is urgent","s":"CVE-2026-5430 · WSO2 Multiple Products Path Traversal Vulnerability"},{"n":"Live","t":"attackers are actively exploiting a security hole in Adobe Commerce and Magento — if your business uses it, applying the vendor's update is urgent","s":"CVE-2026-71362 · Adobe Commerce and Magento Incorrect Authorization Vulnerability"},{"n":"Live","t":"attackers are actively exploiting a security hole in Arista VeloCloud Orchestrator — if your business uses it, applying the vendor's update is urgent","s":"CVE-2026-93952 · Arista VeloCloud Orchestrator Improper Input Validation Vulnerability"}]}