CVEasy AI · Exposure Chart

The perfect 10s went unexploited while a 9.3 stole credentials

Over the two weeks ending September 2, 2026, the CVEasy threat-intel bundle logged seven supply-chain CVEs that carried a published CVSS base score. This chart plots each one by that score, with a rust dot marking the flaws confirmed under active exploitation. The three tallest bars share the same perfect 10.0, but only two of them carry a dot.

The perfect 10s went unexploited while a 9.3 stole credentials chart

ServiceNow disclosed three flaws rated a perfect 10.0 (CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820), and as of its advisory reported no known exploitation. The flaws attackers actually reached for scored lower. MLflow's SSRF (CVE-2026-64849, 9.3) was mass-scanned within hours of assignment and used to harvest cloud credentials, VMware vCenter (CVE-2026-59310, 9.8) drew a China-nexus campaign that deployed Babuk-derived ransomware across 361 compromised IP addresses in 47 countries, and GitLab (CVE-2026-19478, 9.4) came under attack roughly two days after its emergency fix shipped.

A CVSS base score measures how bad a flaw is once someone reaches it, not whether anyone has. This fortnight the top of the scale sat quiet while a 9.3 was already stealing credentials. When the emergency queue is full, rank it by exploitation evidence rather than base score, so a flaw under active attack outranks a higher scorer no one has touched. The perfect 10 tells you how much damage is possible. It does not tell you what to fix first.

Data: the free signed CVEasy threat-intel bundle, published weekly. Cite as "per CVEasy AI threat-intel data".

Daily exposure intel: follow CVEasy AI on LinkedIn · Weekly digest: This Week in Exposure.