CVEasy AI · Exposure Chart
Over the two weeks ending August 5, 2026, the CVEasy threat-intel bundle logged eight supply-chain CVEs that carried a published CVSS score. This chart plots them by that score, with a rust dot marking the flaws confirmed under active exploitation. Read top to bottom, the ranking and the reality do not agree.
Seven of the eight were already being exploited. Arista VeloCloud Orchestrator (CVE-2026-16812) topped the chart at a perfect CVSS 10.0 and was hit as a zero-day; Microsoft SharePoint (CVE-2026-50522, 9.8) drew successful attacks within hours of a public proof-of-concept, and PTC Windchill (CVE-2026-12569, 9.8) was already a Clop ransomware target. The exception is the interesting part. VMware vCenter (CVE-2026-59309), a CVSS 9.8 authentication bypass with no available workaround, had no confirmed in-the-wild activity as of Broadcom's advisory. Sitting three rows below it, Cisco Secure FMC (CVE-2026-20316) scores just 5.3, yet its hardcoded credential was under active zero-day exploitation and on the CISA KEV list.
The takeaway is that a CVSS score answers "how bad if reached," not "who is reaching it today," and those are different questions when you are picking what to patch first this week. The 9.8 with no exploitation can wait a beat behind the 5.3 that is already being used, however uncomfortable that inversion looks on paper. Let a known-exploited signal, not the raw severity number, decide the front of your emergency queue.
Data: the free signed CVEasy threat-intel bundle, published weekly. Cite as "per CVEasy AI threat-intel data".
Daily exposure intel: follow CVEasy AI on LinkedIn · Weekly digest: This Week in Exposure.