A vulnerability identified as CVE-2023-54405 was reportedly exploited on the same day it was publicly disclosed, October 2, 2026. This rapid exploitation window was measured from the CVE's publication date to its earliest listing in an exploited vulnerabilities catalog.
The vulnerability's lifecycle began with its reservation on October 2, 2026, followed by its publication on the same day. The first listing of CVE-2023-54405 as exploited also occurred on October 2, 2026.
While the US federal CISA KEV and the European Union's ENISA (EUVD) do not list this vulnerability as exploited, it was listed by VulnCheck KEV, a commercial research catalog, on October 2, 2026. CIRCL, an aggregator, also mirrored this listing on the same date, though aggregator listings are not independently counted for corroboration.
The claim of exploitation rests on this single catalog entry from VulnCheck KEV. There is no corroborating second catalog to confirm the active exploitation of CVE-2023-54405. Public exploitation evidence, comprising one report collected from VulnCheck and CIRCL, first appeared on October 2, 2026. These sources link to original reports, which have not been independently verified.
The CVE record for CVE-2023-54405 currently shows no CVSS severity score and an EPSS (Exploit Prediction Scoring System) percentile of 0.59%, placing it in the 46.2th percentile.






