CVEasy AI · Exposure Chart

Every flaw on this chart was already being exploited

Across the last two weeks, every supply-chain flaw serious enough to chart was already under attack. Seven CVEs, each rated 7.8 or higher on CVSS, each carrying confirmed active exploitation. For five of the seven, the attacks landed before a patch was available.

Every flaw on this chart was already being exploited chart

The chart ranks seven exploited CVEs by CVSS base score, and every bar carries the rust dot that marks reported exploitation. Three sit at a flat 10.0: SonicWall's SMA1000 SSRF (CVE-2026-83548), the Cisco Secure FMC authentication bypass (CVE-2026-20079), and the Adobe Commerce code injection Sansec named StyleSmuggler (CVE-2026-75650). SonicWall and Adobe both confirmed exploitation before a fix existed, Adobe by three days. Cisco's Secure Email Gateway SQL injection (CVE-2026-76461, 9.8) and PaperCut's pre-auth RCE (CVE-2026-82078, 9.4) were hit as zero-days as well, and the JFrog Artifactory auth bypass (CVE-2026-82329, 9.8) drew a working exploit three days after disclosure once a public proof of concept dropped.

The takeaway is about timing, not severity. A patch cadence measured in weeks does nothing against a flaw that is exploited the day it is disclosed, or before it. Five of these seven gave defenders no patched state to reach in time, which moves the useful work upstream: shrink what is reachable from the internet, and reorder the emergency queue by exploitation evidence from CISA KEV and EPSS rather than by base score alone. The CVSS number still ranks blast radius. It says nothing about how fast the clock is already running.

Data: the free signed CVEasy threat-intel bundle, published weekly. Cite as "per CVEasy AI threat-intel data".

Daily exposure intel: follow CVEasy AI on LinkedIn · Weekly digest: This Week in Exposure.