Threat Landscape
Real-time data from CISA and NIST demonstrates why continuous information security is not optional — it is a necessity.
Global threat activity
Real-time data from multiple open threat databases shows where cyber attacks originate and how they target European countries.
Threat source summary
Aggregated statistics from the six threat databases visualised on the map.
Threat sources – geographic spread
Top 5 source countries
Total indicator count aggregated across all sources.
1,734
Actively exploited vulnerabilities
39
New in the last 30 days
2,766
New CVEs in the last 7 days
16
Critical (CVSS 9.0+)
50
High (CVSS 7.0–8.9)
Vendors with active remediation deadlines
Ransomware share
361 / 1,734
Critical CVEs in the last 7 days
The five most severe new vulnerabilities with a CVSS score of 9.0 or higher.
1 Oct 2026
A missing authentication vulnerability in the Kernel Memory Access Driver (PSKMAD) used by WatchGuard endpoint security products allows a local, authenticated attacker to bypass the driver's access...
1 Oct 2026
Use After Free vulnerability in Apache HTTP Server's mod_rewrite when using lookahead (%{LA-U:HTTP:...}) This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
1 Oct 2026
Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
1 Oct 2026
Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
1 Oct 2026
A flaw was found in Foreman. An authenticated attacker with low-level permissions can achieve remote code execution (RCE) by bypassing the safemode sandbox within the templating engine. Due to impr...
Latest exploited vulnerabilities
| CVE ID | Vendor | Product | Date added | Ransomware |
|---|---|---|---|---|
| CVE-2026-88779 | Citrix | NetScaler | 4 Oct 2026 | Unknown |
| CVE-2026-102490 | Zammad GmbH | Zammad | 2 Oct 2026 | Unknown |
| CVE-2026-102489 | Zammad GmbH | Zammad | 2 Oct 2026 | Unknown |
| CVE-2026-104286 | Fortinet | FortiMail | 1 Oct 2026 | Unknown |
| CVE-2026-76504 | Cisco | Catalyst SD-WAN Manager | 30 Sept 2026 | Unknown |
| CVE-2026-86950 | Apple | Multiple Products | 29 Sept 2026 | Unknown |
| CVE-2026-88772 | Citrix | NetScaler | 27 Sept 2026 | Unknown |
| CVE-2026-88771 | Citrix | NetScaler | 27 Sept 2026 | Unknown |
| CVE-2026-67279 | MikroTik | RouterOS | 25 Sept 2026 | Unknown |
| CVE-2026-65660 | Microsoft | SharePoint | 25 Sept 2026 | Unknown |
Citrix
NetScaler
4 Oct 2026
Zammad GmbH
Zammad
2 Oct 2026
Zammad GmbH
Zammad
2 Oct 2026
Fortinet
FortiMail
1 Oct 2026
Cisco
Catalyst SD-WAN Manager
30 Sept 2026
Apple
Multiple Products
29 Sept 2026
Citrix
NetScaler
27 Sept 2026
Citrix
NetScaler
27 Sept 2026
MikroTik
RouterOS
25 Sept 2026
Microsoft
SharePoint
25 Sept 2026
Why it matters
The threat landscape changes daily
The data above comes directly from the US agencies CISA and NIST. It clearly shows that new threats and vulnerabilities are discovered continuously — and that attackers are actively exploiting them.
New vulnerabilities every day
Hundreds of new CVEs are published every week. Without systematic monitoring, you risk missing critical updates.
Ransomware-linked threats are growing
A significant share of actively exploited vulnerabilities have known links to ransomware campaigns.
Regulatory requirements are tightening
NIS2 and the Cybersecurity Act require organisations to work continuously on risk management and incident preparedness.
Ready to strengthen your cybersecurity?
Book a free meeting and we will discuss how we can help your organisation meet the new requirements.
Book a meeting