$_SecureScope악용 확인 · 악용 확률 · 한국어 권고
악용 확인1,695최근 7일 신규10한국어 권고 연결46CVE악용 확인 전체 →

오늘의 위협 상황

점수 순으로 줄 세우지 않습니다. 실제 악용이 확인된 것을 먼저 보여주고, 한국어 공식 권고가 나왔는지 함께 알려줍니다.

EPSS 기준일2026-09-05
악용 확인 (CISA KEV)1,695미국 정부가 실제 악용을 확인한 취약점
최근 7일 신규 등재10이번 주에 악용이 새로 확인된 것
랜섬웨어 캠페인 사용354CISA 가 랜섬웨어 사용을 확인한 것
한국어 권고가 있는 CVE46KISA 보호나라 권고문에 등장
CVE 원장3,036NVD 에서 수집한 취약점

최근 30일 · 악용이 새로 확인된 취약점

전체
CVE등재일공급사 · 제품취약점심각도
CVE-2026-850462026-09-04Google Chromium V8Google Chromium V8 Type Confusion Vulnerability높음8.8
CVE-2026-95862026-09-02Sangoma SwitchvoxSangoma Switchvox SQL Injection Vulnerability심각9.3
CVE-2026-835492026-09-02SonicWall SMA1000 AppliancesSonicWall SMA1000 Appliances OS Command Injection Vulnerabil…높음7.8
CVE-2026-835482026-09-02SonicWall SMA1000 AppliancesSonicWall SMA1000 Appliances Server-Side Request Forgery Vul…심각10.0
CVE-2026-823292026-09-02JFrog ArtifactoryJFrog Artifactory Improper Authentication Vulnerability심각9.8
CVE-2026-598222026-09-02BerriAI LiteLLMBerriAI LiteLLM Improper Authentication Vulnerability높음8.8
CVE-2026-498692026-09-02Kestra Kestra OSSKestra OSS OS Command Injection Vulnerability심각10.0
CVE-2026-487102026-09-02Kludex StarletteKludex Starlette HTTP Request/Response Smuggling Vulnerabili…보통6.5
출처: CISA Known Exploited Vulnerabilities Catalog. 등재는 미국 정부가 악용 정황을 확인했다는 뜻이며, 우리가 판단한 것이 아닙니다.

우선순위 — 악용 확인 → 악용 확률 순

CVE 원장
CVE-2024-3400랜섬웨어 악용A command injection as a result of arbitrary file creation vulnerability in the GlobalProt…100.0%심각10.0
CVE-2021-44228랜섬웨어 악용Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.…100.0%심각10.0
CVE-2020-5902랜섬웨어 악용In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and…100.0%심각9.8
CVE-2024-21893랜섬웨어 악용A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure…100.0%높음8.2
CVE-2024-21887랜섬웨어 악용A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) a…100.0%심각9.1
CVE-2023-44487악용 확인The HTTP/2 protocol allows a denial of service (server resource consumption) because reque…100.0%높음7.5
CVE-2019-0708랜섬웨어 악용A remote code execution vulnerability exists in Remote Desktop Services formerly known as …100.0%심각9.8
CVE-2023-4966랜섬웨어 악용Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as…100.0%높음7.5
CVE-2021-22005랜섬웨어 악용The vCenter Server contains an arbitrary file upload vulnerability in the Analytics servic…100.0%심각9.8
CVE-2019-19781랜섬웨어 악용An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, …100.0%심각9.8
정렬: ① CISA KEV 등재 ② EPSS 백분위 ③ 공개일. CVSS 점수 순이 아닙니다 — 점수가 높아도 악용되지 않는 취약점이 훨씬 많습니다.

악용 확률이 오르는 중

자세히
아직 비교할 이력이 없습니다EPSS 스냅샷은 하루 한 번 쌓입니다. 최소 이틀이 지나야 변화가 보입니다.
EPSS(FIRST.org)의 일일 백분위를 우리가 매일 저장해 비교합니다. 원본 API 는 오늘 값만 주므로, 이 표는 스냅샷이 쌓인 만큼만 답할 수 있습니다.

바로 가기

이 사이트가 하지 않는 것. 심각도를 우리가 판단하지 않고, 점수를 계산하지 않으며, 영문 원문을 번역하지 않습니다. "즉시 패치하라" 같은 문장은 발행처 원문을 인용할 때만 나타나며 항상 출처를 함께 답니다. 판단은 시스템을 아는 사람이 해야 합니다.