Vulnerability intelligence
Zero-Day Vulnerabilities
A zero-day vulnerability is a vulnerability known to have been exploited in real-world attacks before a vendor patch or other official remediation became available. The archive covers known zero-day vulnerabilities dating back to 2006.
Historical activity
Zero-Day Vulnerabilities by Year
Select a year to open the filtered archive.
Affected vendors
Top Vendors
| Vendor | Zero-days | Share |
|---|---|---|
| Microsoft | 337 | 33.7% |
| 87 | 8.7% | |
| Adobe | 78 | 7.8% |
| Apple Inc. | 73 | 7.3% |
| Cisco Systems, Inc | 28 | 2.8% |
| Oracle | 17 | 1.7% |
| JustSystems Corporation | 16 | 1.6% |
| Fortinet, Inc | 15 | 1.5% |
| Ivanti | 15 | 1.5% |
| Mozilla | 11 | 1.1% |
Weakness types
Top CWE Categories
| CWE | Weakness | Zero-days | Share |
|---|---|---|---|
| CWE-119 | Memory corruption | 222 | 22.2% |
| CWE-20 | Improper input validation | 91 | 9.1% |
| CWE-416 | Use After Free | 81 | 8.1% |
| CWE-264 | Permissions, Privileges, and Access Controls | 38 | 3.8% |
| CWE-843 | Type confusion | 34 | 3.4% |
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | 26 | 2.6% |
| CWE-287 | Improper Authentication | 25 | 2.5% |
| CWE-787 | Out-of-bounds write | 25 | 2.5% |
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | 25 | 2.5% |
| CWE-122 | Heap-based Buffer Overflow | 23 | 2.3% |
Known exploited catalogs
Zero-Days in Known Exploited Vulnerability Catalogs
Coverage of the zero-day dataset by two independent catalogs. A record can appear in one catalog, both, or neither.
Catalog overlap
Recently discovered
Latest Zero-Day Vulnerabilities
| CVE | Vendor / Product | Vulnerability | Discovered | KEV |
|---|---|---|---|---|
| CVE-2026-58704 | GooglePixel | Improper input validation in Pixel | CISA KEV | |
| CVE-2026-76460 | Cisco Systems, IncCisco Identity Services Engine (ISE) | Incorrect use of privileged APIs in Cisco Identity Services Engine (ISE) | CISA KEV | |
| CVE-2026-87886 | AcronisAcronis Backup plugin for cPanel & WHM for Linux | Incorrect default permissions in Acronis Backup extension for Plesk for Linux and Acronis Backup plugin for cPanel & WHM for Linux | CISA KEV | |
| CVE-2026-76461 | Cisco Systems, IncSecure Email Gateway | SQL injection in Secure Email Gateway | CISA KEV | |
| CVE-2026-87491 | GoogleGoogle Chrome | Out-of-bounds write in Google Chromium | CISA KEV | |
| CVE-2026-85880 | MicrosoftMicrosoft Windows | Heap-based buffer overflow in Microsoft Windows and Windows Server | CISA KEV | |
| CVE-2026-81963 | MicrosoftMicrosoft Windows | Insecure link following in Microsoft Windows and Windows Server | CISA KEV | |
| CVE-2026-75650 | AdobeAdobe Commerce (formerly Magento Commerce) | Template injection in Adobe products | CISA KEV | |
| CVE-2026-85046 | GoogleGoogle Chrome | Type Confusion in Google Chromium | CISA KEV | |
| CVE-2026-67276 | MikroTikMikroTik RouterOS | Improper Verification of Cryptographic Signature in MikroTik RouterOS | — |