CVEasy AI · Exposure Chart
Over the two weeks ending July 22, 2026, the CVEasy threat-intel bundle logged a run of critical vulnerabilities that shared one uncomfortable trait: attackers reached them first. This chart plots the seven flaws that carried a published CVSS score, ranked by that score, with a rust dot marking the ones confirmed under active exploitation.
Six of the seven were already being exploited in the wild. Adobe ColdFusion (CVE-2026-48282) and SonicWall SMA1000 (CVE-2026-15409) both sat at a perfect CVSS 10.0, and both were hit within days: ColdFusion within minutes of a public proof-of-concept, SonicWall as a zero-day before any patch existed. Citrix NetScaler (CVE-2026-8451) drew exploitation attempts less than 24 hours after disclosure, and two SharePoint deserialization flaws (CVE-2026-45659 and CVE-2026-58644) landed on the CISA KEV catalog, one of them tied to the DHS HSIN breach. The lone exception on the chart is Zoom (CVE-2026-53412), a CVSS 9.8 account-takeover flaw with no in-the-wild activity reported as of July 17.
The practitioner takeaway is about timing, not severity. A CVSS number tells you how bad a flaw is if reached; it says nothing about whether someone is reaching it today. On this chart the highest scores and the fastest exploitation lined up, but the pattern holding the story together is the gap between patch and attack shrinking to days or hours. Prioritize by what is being exploited now, and treat KEV additions and public proof-of-concept releases as the clock starting, not a future risk.
Data: the free signed CVEasy threat-intel bundle, published weekly. Cite as "per CVEasy AI threat-intel data".
Daily exposure intel: follow CVEasy AI on LinkedIn · Weekly digest: This Week in Exposure.