logo

April 2026 CVE Landscape

ID: b31afed9-67fa-5696-b131-65e5b5eef15f

STIX ID: report--b31afed9-67fa-5696-b131-65e5b5eef15f

Feed Name: Recorded Future Blog

Threat Score
80/100

Date Published: 2026-05-15

Date Updated: 2026-05-15

...
...

Recorded Future’s Insikt Group identified 37 high‑impact vulnerabilities actively exploited in April 2026 (35 with Very Critical risk scores), including 16 RCEs and 31 listed in CISA’s KEV. The report analyzes specific exploitation activity — notably a TBK DVR campaign delivering the Nexcorium botnet and a missing‑authentication Nginx UI flaw — provides PoC and detection (Nuclei) resources, and flags several vulnerabilities tied to ransomware operations (Medusa, Sorry).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.