Exploitation timeline
Threadlinqs has recorded 9 open-webui CVEs published between and . The busiest month was 2026-09 (8 new CVEs). None of them is listed in CISA KEV yet.
Most exploited vulnerabilities
Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 9 of 9 tracked open-webui CVEs.
- CVE-2026-56399medium 5EPSS 0.3%
- CVE-2026-88000medium 6.5EPSS 0.3%
- CVE-2026-88002medium 6.5EPSS 0.3%
- CVE-2026-88001medium 5EPSS 0.3%
- CVE-2026-87998high 7.1EPSS 0.3%
- CVE-2026-87999high 7.1EPSS 0.2%
- CVE-2026-87994medium 4.3EPSS 0.2%
- CVE-2026-87997medium 4.3EPSS 0.2%
- CVE-2026-87017medium 4.3EPSS 0.2%
Products affected
Threadlinqs normalises CPE and CNA product records across all 9 CVEs; 1 distinct open-webui product is affected. The most frequently affected:
- open-webui 9 CVEs
Threat activity
1 tracked threat campaign reference open-webui products or exploit open-webui CVEs:
How to prioritise open-webui patching
This order follows the data Threadlinqs holds for open-webui, not a generic severity checklist:
- No open-webui CVE is in CISA KEV yet, so rank by exploit probability instead.
- Outside KEV, the highest EPSS scores are CVE-2026-56399 (0.3%), CVE-2026-88000 (0.3%), CVE-2026-88002 (0.3%).
- 0 CVEs score Critical and 2 High on CVSS v3 (maximum 7.1, average 5.6); sequence these after KEV and high-EPSS items.
About this data
Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.