Vulnerabilities with confirmed active exploitation in the wild - not just a high severity score - sourced from CISA's Known Exploited Vulnerabilities catalog and scored by real-world exploitation likelihood.
Refreshed daily from CISA's Known Exploited Vulnerabilities catalog, VulnCheck's KEV, and ENISA's EU Vulnerability Database, scored with EPSS (Exploit Prediction Scoring System) from FIRST.org - a model estimating the probability a vulnerability will actually be exploited, not just how severe it could theoretically be. Ranked by priority and capped at the 60 highest-priority entries, not just newest-first, so the list stays current without growing unbounded.
Apache Struts Jakarta Multipart parser allows for malicious file upload using the Content-Type value, leading to remote code execution. This is the exact vulnerability behind Equifax's 2017 breach - a financial services credit-reporting agency - which exposed roughly 147 million people's financial and personal data, one of the largest breaches ever tied to a single named CVE.
CVE-2017-5638 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw successful exploitation lets an attacker run their own code on the affected system - effectively taking full remote control of it. CISA has also tied this vulnerability to known ransomware campaigns, which raises the stakes of leaving it unpatched. It affects Apache Struts, most relevant to organizations in Financial Services.
Staying safe: Apply the vendor's security update as soon as possible. Treat this as the highest-urgency patch class: remote code execution hands an attacker full control with no further steps needed, so isolate internet-facing instances immediately if patching can't happen right away.
Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise PeopleTools.
CVE-2026-35273 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw gives an attacker a way to compromise the system beyond its intended security boundaries. CISA has also tied this vulnerability to known ransomware campaigns, which raises the stakes of leaving it unpatched. It affects Oracle PeopleSoft Enterprise PeopleTools, which is broadly deployed across essentially every industry.
Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… More generally: confirm whether Oracle PeopleSoft Enterprise PeopleTools is exposed to the internet or reachable by untrusted users, prioritize patching internet-facing instances first, and check available logs for indicators of prior exploitation before assuming a patch alone closes the incident.
Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection.
CVE-2026-0257 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw lets an attacker access the system without valid credentials, bypassing the login process entirely. CISA has also tied this vulnerability to known ransomware campaigns, which raises the stakes of leaving it unpatched. It affects Palo Alto Networks PAN-OS, which is broadly deployed across essentially every industry.
Staying safe: Apply mitigations per vendor instructions, follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Rotate credentials and review authentication logs for signs of prior unauthorized access - this flaw may have already let someone in without ever needing a valid password.
SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.
CVE-2026-15409 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw lets an attacker trick the server into making requests on their behalf, often reaching internal systems that aren't meant to be exposed. CISA has also tied this vulnerability to known ransomware campaigns, which raises the stakes of leaving it unpatched. It affects SonicWall SMA1000 Appliances, which is broadly deployed across essentially every industry.
Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… Restrict the affected service's own outbound network access to only what it legitimately needs - this flaw is exploited specifically to reach internal systems the service was never meant to contact.
Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.
CVE-2026-50751 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw lets an attacker access the system without valid credentials, bypassing the login process entirely. CISA has also tied this vulnerability to known ransomware campaigns, which raises the stakes of leaving it unpatched. It affects Check Point Security Gateway, which is broadly deployed across essentially every industry.
Staying safe: Apply mitigations per vendor instructions, follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Rotate credentials and review authentication logs for signs of prior unauthorized access - this flaw may have already let someone in without ever needing a valid password.
Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.
CVE-2026-45659 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw lets an attacker execute code by feeding the application specially-crafted data it wasn't built to safely handle. CISA has also tied this vulnerability to known ransomware campaigns, which raises the stakes of leaving it unpatched. It affects Microsoft SharePoint Server, which is broadly deployed across essentially every industry.
Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… Treat any data this service has ever accepted from an untrusted source as potentially having triggered this, and review for signs of unexpected code execution, not just requests to the deserialization endpoint itself.
Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code.
CVE-2026-59310 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw lets an attacker read or write files outside the folders the application is supposed to be restricted to. CISA has also tied this vulnerability to known ransomware campaigns, which raises the stakes of leaving it unpatched. It affects Broadcom VMware vCenter, which is broadly deployed across essentially every industry.
Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… Check whether any files outside the application's intended directories were read or modified, and review web server logs for unusual "../"-style path patterns in requests.
PTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attacker to execute arbitrary code by sending a malicious request to the network.
CVE-2026-12569 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw gives an attacker a way to compromise the system beyond its intended security boundaries. CISA has also tied this vulnerability to known ransomware campaigns, which raises the stakes of leaving it unpatched. It affects PTC Windchill and FlexPLM, which is broadly deployed across essentially every industry.
Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… More generally: confirm whether PTC Windchill and FlexPLM is exposed to the internet or reachable by untrusted users, prioritize patching internet-facing instances first, and check available logs for indicators of prior exploitation before assuming a patch alone closes the incident.
SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.
CVE-2026-15410 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw gives an attacker a way to compromise the system beyond its intended security boundaries. CISA has also tied this vulnerability to known ransomware campaigns, which raises the stakes of leaving it unpatched. It affects SonicWall SMA1000 Appliances, which is broadly deployed across essentially every industry.
Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… More generally: confirm whether SonicWall SMA1000 Appliances is exposed to the internet or reachable by untrusted users, prioritize patching internet-facing instances first, and check available logs for indicators of prior exploitation before assuming a patch alone closes the incident.
Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.
CVE-2026-20316 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw gives an attacker a way to compromise the system beyond its intended security boundaries. CISA has also tied this vulnerability to known ransomware campaigns, which raises the stakes of leaving it unpatched. It affects Cisco Secure Firewall Management Center (FMC), which is broadly deployed across essentially every industry.
Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… More generally: confirm whether Cisco Secure Firewall Management Center (FMC) is exposed to the internet or reachable by untrusted users, prioritize patching internet-facing instances first, and check available logs for indicators of prior exploitation before assuming a patch alone closes the incident.
Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload that could harvested credentials from multiple sources on disk and in memory.
CVE-2026-48027 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw gives an attacker a way to compromise the system beyond its intended security boundaries. CISA has also tied this vulnerability to known ransomware campaigns, which raises the stakes of leaving it unpatched. It affects Nx Nx Console, which is broadly deployed across essentially every industry.
Staying safe: Apply mitigations per vendor instructions, follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. More generally: confirm whether Nx Nx Console is exposed to the internet or reachable by untrusted users, prioritize patching internet-facing instances first, and check available logs for indicators of prior exploitation before assuming a patch alone closes the incident.
Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication Bypass using an alternate path or channel vulnerability that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.
CVE-2026-20079 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw lets an attacker access the system without valid credentials, bypassing the login process entirely. It affects Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management, which is broadly deployed across essentially every industry.
Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… Rotate credentials and review authentication logs for signs of prior unauthorized access - this flaw may have already let someone in without ever needing a valid password.
Ivanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve root-level remote code execution. This vulnerability can be successfully exploited in cases where the Sentry appliance is in an unmanaged state with its endpoints externally reachable. The use of mTLS with EPMM or restricted HTTPS access through Neurons for MDM makes interfaces inaccessible to external actors.
CVE-2026-10520 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw successful exploitation lets an attacker run their own code on the affected system - effectively taking full remote control of it. It affects Ivanti Sentry, which is broadly deployed across essentially every industry.
Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… Treat this as the highest-urgency patch class: remote code execution hands an attacker full control with no further steps needed, so isolate internet-facing instances immediately if patching can't happen right away.
Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints.
CVE-2026-8037 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw lets an attacker run arbitrary operating-system commands on the server. It affects Progress LoadMaster, which is broadly deployed across essentially every industry.
Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… Review shell/process execution logs on the affected system for unexpected commands, and treat any output the application has generated since as suspect until confirmed clean.
Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813.
CVE-2026-34486 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw gives an attacker a way to compromise the system beyond its intended security boundaries. It affects Apache Tomcat, which is broadly deployed across essentially every industry.
Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… More generally: confirm whether Apache Tomcat is exposed to the internet or reachable by untrusted users, prioritize patching internet-facing instances first, and check available logs for indicators of prior exploitation before assuming a patch alone closes the incident.
WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.
CVE-2026-63030 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw successful exploitation lets an attacker run their own code on the affected system - effectively taking full remote control of it. It affects WordPress Core, which is broadly deployed across essentially every industry.
Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… Treat this as the highest-urgency patch class: remote code execution hands an attacker full control with no further steps needed, so isolate internet-facing instances immediately if patching can't happen right away.
Splunk Enterprise contains a missing authentication for critical function vulnerability which could allow an unauthenticated user to create or truncate arbitrary files through a PostgreSQL sidecar service endpoint.
CVE-2026-20253 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw gives an attacker a way to compromise the system beyond its intended security boundaries. It affects Splunk Enterprise, which is broadly deployed across essentially every industry.
Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… More generally: confirm whether Splunk Enterprise is exposed to the internet or reachable by untrusted users, prioritize patching internet-facing instances first, and check available logs for indicators of prior exploitation before assuming a patch alone closes the incident.
Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data.
CVE-2026-72898 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw lets an attacker manipulate the underlying database directly, potentially reading, modifying, or deleting data they should never be able to touch. It affects Metabase Metabase, which is broadly deployed across essentially every industry.
Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… Review database access logs for unusual queries, and restrict the application's own database account to the minimum privileges it actually needs, so a successful injection can't reach further than necessary.
Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.
CVE-2026-39808 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw lets an attacker run arbitrary operating-system commands on the server. It affects Fortinet FortiSandbox, which is broadly deployed across essentially every industry.
Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… Review shell/process execution logs on the affected system for unexpected commands, and treat any output the application has generated since as suspect until confirmed clean.
SolarWinds Orion API contains an authentication bypass vulnerability that could allow a remote attacker to execute API commands. Orion is widely deployed for network monitoring across U.S. federal government agencies - CISA issued Emergency Directive 21-01 in December 2020 specifically instructing federal civilian agencies to disconnect or patch affected Orion instances after a separate supply-chain compromise of the same product was discovered.
CVE-2020-10148 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw lets an attacker access the system without valid credentials, bypassing the login process entirely. It affects SolarWinds Orion, most relevant to organizations in Government & Public Sector.
Staying safe: Apply the vendor's security update as soon as possible. Rotate credentials and review authentication logs for signs of prior unauthorized access - this flaw may have already let someone in without ever needing a valid password.
Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) contain a server-side request forgery (SSRF) Vulnerability that could allow an unauthenticated, remote attacker to write files to the underlying operating system that could be used later to elevate to root.
CVE-2026-20230 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw lets an attacker trick the server into making requests on their behalf, often reaching internal systems that aren't meant to be exposed. It affects Cisco Unified Communications Manager, which is broadly deployed across essentially every industry.
Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… Restrict the affected service's own outbound network access to only what it legitimately needs - this flaw is exploited specifically to reach internal systems the service was never meant to contact.
Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account.
CVE-2026-60004 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw gives an attacker a way to compromise the system beyond its intended security boundaries. It affects Gitea Gitea, which is broadly deployed across essentially every industry.
Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… More generally: confirm whether Gitea Gitea is exposed to the internet or reachable by untrusted users, prioritize patching internet-facing instances first, and check available logs for indicators of prior exploitation before assuming a patch alone closes the incident.
Ubiquiti UniFi OS contains an improper input validation vulnerability which could allow a malicious actor with access to the network to conduct command injection.
CVE-2026-34910 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw lets an attacker run arbitrary operating-system commands on the server. It affects Ubiquiti UniFi OS, which is broadly deployed across essentially every industry.
Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… Review shell/process execution logs on the affected system for unexpected commands, and treat any output the application has generated since as suspect until confirmed clean.
Ajax.NET Professional (AjaxPro) contains a deserialization of untrusted data vulnerability that could allow for remote code execution via arbitrary .NET classes. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.
CVE-2021-23758 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw successful exploitation lets an attacker run their own code on the affected system - effectively taking full remote control of it. It affects Ajax.NET Professional Ajax.NET Professional, which is broadly deployed across essentially every industry.
Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… Treat this as the highest-urgency patch class: remote code execution hands an attacker full control with no further steps needed, so isolate internet-facing instances immediately if patching can't happen right away.
JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol.
CVE-2026-63077 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw successful exploitation lets an attacker run their own code on the affected system - effectively taking full remote control of it. It affects JetBrains TeamCity, which is broadly deployed across essentially every industry.
Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… Treat this as the highest-urgency patch class: remote code execution hands an attacker full control with no further steps needed, so isolate internet-facing instances immediately if patching can't happen right away.
Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.
CVE-2026-50522 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw lets an attacker execute code by feeding the application specially-crafted data it wasn't built to safely handle. It affects Microsoft SharePoint, which is broadly deployed across essentially every industry.
Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… Treat any data this service has ever accepted from an untrusted source as potentially having triggered this, and review for signs of unexpected code execution, not just requests to the deserialization endpoint itself.
Ubiquiti UniFi OS contains an improper access control vulnerability which could allow a malicious actor with access to the network to make unauthorized changes to the system.
CVE-2026-34908 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw gives an attacker a way to compromise the system beyond its intended security boundaries. It affects Ubiquiti UniFi OS, which is broadly deployed across essentially every industry.
Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… More generally: confirm whether Ubiquiti UniFi OS is exposed to the internet or reachable by untrusted users, prioritize patching internet-facing instances first, and check available logs for indicators of prior exploitation before assuming a patch alone closes the incident.
BerriAI LiteLLM contains a command injection vulnerability that could allow any authenticated user, including holders of low-privilege internal-user keys, to run arbitrary commands on the host.
CVE-2026-42271 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw lets an attacker run arbitrary operating-system commands on the server. It affects BerriAI LiteLLM, which is broadly deployed across essentially every industry.
Staying safe: Apply mitigations per vendor instructions, follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Review shell/process execution logs on the affected system for unexpected commands, and treat any output the application has generated since as suspect until confirmed clean.
WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations.
CVE-2026-60137 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw successful exploitation lets an attacker run their own code on the affected system - effectively taking full remote control of it. It affects WordPress Core, which is broadly deployed across essentially every industry.
Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… Treat this as the highest-urgency patch class: remote code execution hands an attacker full control with no further steps needed, so isolate internet-facing instances immediately if patching can't happen right away.
Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.
CVE-2026-25089 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw lets an attacker run arbitrary operating-system commands on the server. It affects Fortinet FortiSandbox, which is broadly deployed across essentially every industry.
Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… Review shell/process execution logs on the affected system for unexpected commands, and treat any output the application has generated since as suspect until confirmed clean.
vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code by supplying crafted input through the pagenav[pagenumber] parameter. Attackers can exploit the insufficiently restrictive regex filter by using phpfuck-style encoding with permitted characters to inject and execute arbitrary PHP code via the unauthenticated ajax/render template route without any authentication.
CVE-2026-61511 is in VulnCheck's Known Exploited Vulnerabilities catalog (Community), meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw gives an attacker a way to compromise the system beyond its intended security boundaries. It affects vBulletin vBulletin, which is broadly deployed across essentially every industry.
Staying safe: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable. More generally: confirm whether vBulletin vBulletin is exposed to the internet or reachable by untrusted users, prioritize patching internet-facing instances first, and check available logs for indicators of prior exploitation before assuming a patch alone closes the incident.
Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.
CVE-2026-33824 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw successful exploitation lets an attacker run their own code on the affected system - effectively taking full remote control of it. It affects Microsoft Internet Key Exchange (IKE) Service Extensions, which is broadly deployed across essentially every industry.
Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… Treat this as the highest-urgency patch class: remote code execution hands an attacker full control with no further steps needed, so isolate internet-facing instances immediately if patching can't happen right away.
Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.
CVE-2026-16232 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw lets an attacker access the system without valid credentials, bypassing the login process entirely. It affects Check Point SmartConsole, which is broadly deployed across essentially every industry.
Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… Rotate credentials and review authentication logs for signs of prior unauthorized access - this flaw may have already let someone in without ever needing a valid password.
Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.17.4, the fix for unauthenticated OS command injection in the nuclio dashboard on the local/Docker platform is incomplete. The fix added validateFunctionName for function names and common.Quote() for the named-resource shell command path, but the list-all resource path (triggered when no specific resource name is provided) still interpolates the resourceNamespace parameter unquoted into a /bin/sh -c command string. An unauthenticated attacker can inject shell metacharacters via the X-Nuclio-Functio…
CVE-2026-79756 is in VulnCheck's Known Exploited Vulnerabilities catalog (Community), meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw lets an attacker run arbitrary operating-system commands on the server. It affects iguazio nuclio, which is broadly deployed across essentially every industry.
Staying safe: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable. Review shell/process execution logs on the affected system for unexpected commands, and treat any output the application has generated since as suspect until confirmed clean.
Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticated users.
CVE-2026-48907 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw gives an attacker a way to compromise the system beyond its intended security boundaries. It affects Widget Factory Joomla Content Editor, which is broadly deployed across essentially every industry.
Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… More generally: confirm whether Widget Factory Joomla Content Editor is exposed to the internet or reachable by untrusted users, prioritize patching internet-facing instances first, and check available logs for indicators of prior exploitation before assuming a patch alone closes the incident.
Ubiquiti UniFi OS contains a path traversal vulnerability which could allow a malicious actor with access to the network to access files on the underlying system that could be manipulated to access an underlying account.
CVE-2026-34909 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw lets an attacker read or write files outside the folders the application is supposed to be restricted to. It affects Ubiquiti UniFi OS, which is broadly deployed across essentially every industry.
Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… Check whether any files outside the application's intended directories were read or modified, and review web server logs for unusual "../"-style path patterns in requests.
Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, in a default dozzle deploy (the documented quickstart, no DOZZLE_AUTH_PROVIDER set), POST /api/notifications/test-webhook is reachable without authentication and forwards an attacker-controlled URL into a WebhookDispatcher that sends an HTTP POST to the supplied URL with attacker-controlled request headers, and returns the response status code AND up to 1MB of the response body to the caller, when the target replies non-2xx. This vulnerability is fixed in 10.5.2.
CVE-2026-45298 is in VulnCheck's Known Exploited Vulnerabilities catalog (Community), meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw lets an attacker trick the server into making requests on their behalf, often reaching internal systems that aren't meant to be exposed. It affects amirraminfar dozzle, which is broadly deployed across essentially every industry.
Staying safe: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable. Restrict the affected service's own outbound network access to only what it legitimately needs - this flaw is exploited specifically to reach internal systems the service was never meant to contact.
Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.
CVE-2026-93952 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw gives an attacker a way to compromise the system beyond its intended security boundaries. It affects Arista VeloCloud Orchestrator, which is broadly deployed across essentially every industry.
Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… More generally: confirm whether Arista VeloCloud Orchestrator is exposed to the internet or reachable by untrusted users, prioritize patching internet-facing instances first, and check available logs for indicators of prior exploitation before assuming a patch alone closes the incident.
Check Point Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN contain an improper certificate validation vulnerability which could allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.
CVE-2026-85102 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw gives an attacker a way to compromise the system beyond its intended security boundaries. It affects Check Point Multiple Products, which is broadly deployed across essentially every industry.
Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… More generally: confirm whether Check Point Multiple Products is exposed to the internet or reachable by untrusted users, prioritize patching internet-facing instances first, and check available logs for indicators of prior exploitation before assuming a patch alone closes the incident.
Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 - Upload/remove accepted a client-controlled root (_path_type could point at the component site/admin trees), did not enforce path containment, and used a weak extension check. CSRF token was also missing on upload/remove.
CVE-2026-75949 is in VulnCheck's Known Exploited Vulnerabilities catalog (Community), meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw lets an attacker read or write files outside the folders the application is supposed to be restricted to. It affects cmsjunkie.com J-BusinessDirectory extension for Joomla, which is broadly deployed across essentially every industry.
Staying safe: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable. Check whether any files outside the application's intended directories were read or modified, and review web server logs for unusual "../"-style path patterns in requests.
Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations.
CVE-2026-0770 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw gives an attacker a way to compromise the system beyond its intended security boundaries. It affects Langflow Langflow, which is broadly deployed across essentially every industry.
Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… More generally: confirm whether Langflow Langflow is exposed to the internet or reachable by untrusted users, prioritize patching internet-facing instances first, and check available logs for indicators of prior exploitation before assuming a patch alone closes the incident.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pixelite Events Manager events-manager allows Reflected XSS.This issue affects Events Manager: from n/a through 7.4.2.
CVE-2026-66457 is in VulnCheck's Known Exploited Vulnerabilities catalog (Community), meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw lets an attacker inject malicious script into pages viewed by other users, often to steal their session or credentials. It affects pixelite events manager, which is broadly deployed across essentially every industry.
Staying safe: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable. Force a session/credential reset for privileged users of the affected application - this flaw is commonly used to hijack an active session rather than compromise the server directly.
F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unauthenticated attacker to perform remote code execution.
CVE-2026-94127 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw successful exploitation lets an attacker run their own code on the affected system - effectively taking full remote control of it. It affects F5 BIG-IP APM, which is broadly deployed across essentially every industry.
Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… Treat this as the highest-urgency patch class: remote code execution hands an attacker full control with no further steps needed, so isolate internet-facing instances immediately if patching can't happen right away.
Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent contain a path traversal vulnerability that allows an unauthenticated attacker to upload and execute arbitrary scripts.
CVE-2026-93616 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw lets an attacker read or write files outside the folders the application is supposed to be restricted to. It affects Check Point Multiple Products, which is broadly deployed across essentially every industry.
Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… Check whether any files outside the application's intended directories were read or modified, and review web server logs for unusual "../"-style path patterns in requests.
An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.
CVE-2026-87902 is in VulnCheck's Known Exploited Vulnerabilities catalog (Community), meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw successful exploitation lets an attacker run their own code on the affected system - effectively taking full remote control of it. It affects WordPress wordpress, which is broadly deployed across essentially every industry.
Staying safe: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable. Treat this as the highest-urgency patch class: remote code execution hands an attacker full control with no further steps needed, so isolate internet-facing instances immediately if patching can't happen right away.
## Unauthenticated Command Execution via HTTP MCP `execute_module` ### Summary The HTTP MCP endpoint (`POST /mcp`) in flyto-core accepts unauthenticated JSON-RPC `tools/call` requests and dispatches them to arbitrary registered modules, including `sandbox.execute_shell`, which passes attacker-controlled input directly to `asyncio.create_subprocess_shell`. An unauthenticated attacker can execute arbitrary OS commands as the flyto-core server process. By default the server binds to `127.0.0.1`, making this a High-severity local vulnerability (CVSS 8.4); if started with `--host 0.0.0.0`, it be…
CVE-2026-55786 is in VulnCheck's Known Exploited Vulnerabilities catalog (Community), meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw successful exploitation lets an attacker run their own code on the affected system - effectively taking full remote control of it. It affects FlytoHub Flyto2 Core, which is broadly deployed across essentially every industry.
Staying safe: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable. Treat this as the highest-urgency patch class: remote code execution hands an attacker full control with no further steps needed, so isolate internet-facing instances immediately if patching can't happen right away.
Zyxel GS1900 series switches contain a stack-based buffer overflow vulnerability in the CGI program which could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.
CVE-2026-7273 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw lets an attacker corrupt the program's memory, which can crash the system or, in the worst case, run arbitrary code. It affects Zyxel GS1900 Series Switches, which is broadly deployed across essentially every industry.
Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… The patch itself is the primary defense here - memory-safety flaws are hard to confirm after the fact from logs alone, so prevention matters more than detection for this class.
OmniRoute is an open-source AI gateway providing a single endpoint for multiple model providers. In 3.8.49 and earlier, the OmniRoute POST /api/acp/agents custom ACP agent endpoint accepted attacker-controlled binary and versionCommand values and used only a self-consistency check before execFileSync executed the selected interpreter and arguments. The same request called refreshAgentCache, and resolveVersionProbe accepted the matched command before the execFileSync sink ran it. The tokenizeVersionCommand function and DISALLOWED_VERSION_COMMAND_CHARS filter rejected a limited set of shell met…
CVE-2026-88062 is in VulnCheck's Known Exploited Vulnerabilities catalog (Community), meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw gives an attacker a way to compromise the system beyond its intended security boundaries. It affects diegosouzapw OmniRoute, which is broadly deployed across essentially every industry.
Staying safe: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable. More generally: confirm whether diegosouzapw OmniRoute is exposed to the internet or reachable by untrusted users, prioritize patching internet-facing instances first, and check available logs for indicators of prior exploitation before assuming a patch alone closes the incident.
The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.57.2. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
CVE-2026-92229 is in VulnCheck's Known Exploited Vulnerabilities catalog (Community), meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw gives an attacker a way to compromise the system beyond its intended security boundaries. It affects wpmudev Forminator Forms – Contact Form, Payment Form & Custom Form Builder, which is broadly deployed across essentially every industry.
Staying safe: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable. More generally: confirm whether wpmudev Forminator Forms – Contact Form, Payment Form & Custom Form Builder is exposed to the internet or reachable by untrusted users, prioritize patching internet-facing instances first, and check available logs for indicators of prior exploitation before assuming a patch alone closes the incident.
Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.
CVE-2026-9198 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw successful exploitation lets an attacker run their own code on the affected system - effectively taking full remote control of it. It affects IBM Langflow, which is broadly deployed across essentially every industry.
Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… Treat this as the highest-urgency patch class: remote code execution hands an attacker full control with no further steps needed, so isolate internet-facing instances immediately if patching can't happen right away.
The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.0.4 via the upload_file function. This is due to a mismatch between the field validation pipeline and the file persistence pipeline, where hidden file upload fields bypass extension validation and a rejected file's intact upload state is later passed to upload_file() without re-validation. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible. Exploitation requires the targeted form to contain…
CVE-2026-84434 is in VulnCheck's Known Exploited Vulnerabilities catalog (Community), meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw successful exploitation lets an attacker run their own code on the affected system - effectively taking full remote control of it. It affects Gravity Forms Gravity Forms, which is broadly deployed across essentially every industry.
Staying safe: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable. Treat this as the highest-urgency patch class: remote code execution hands an attacker full control with no further steps needed, so isolate internet-facing instances immediately if patching can't happen right away.
Linux Kernel contains an improper check for unusual or exceptional conditions vulnerability in the TLS receive path which allows a zero-length record retrieved from the rx_list to bypass the intended recvmsg() record-type handling, potentially causing subsequent TLS records to be processed using incorrect zero-copy and queuing assumptions. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.
CVE-2025-39682 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw gives an attacker a way to compromise the system beyond its intended security boundaries. It affects Linux Kernel, which is broadly deployed across essentially every industry.
Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… More generally: confirm whether Linux Kernel is exposed to the internet or reachable by untrusted users, prioritize patching internet-facing instances first, and check available logs for indicators of prior exploitation before assuming a patch alone closes the incident.
Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine service account.
CVE-2019-1068 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw successful exploitation lets an attacker run their own code on the affected system - effectively taking full remote control of it. It affects Microsoft SQL Server, which is broadly deployed across essentially every industry.
Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… Treat this as the highest-urgency patch class: remote code execution hands an attacker full control with no further steps needed, so isolate internet-facing instances immediately if patching can't happen right away.
Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state.
CVE-2025-39964 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw gives an attacker a way to compromise the system beyond its intended security boundaries. It affects Linux Kernel, which is broadly deployed across essentially every industry.
Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… More generally: confirm whether Linux Kernel is exposed to the internet or reachable by untrusted users, prioritize patching internet-facing instances first, and check available logs for indicators of prior exploitation before assuming a patch alone closes the incident.
Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentication bypass when the authentication depends on the reconstructed URL’s path. This vulnerability could be chaned with CVE-2026-42271.
CVE-2026-48710 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw lets an attacker access the system without valid credentials, bypassing the login process entirely. It affects Kludex Starlette, which is broadly deployed across essentially every industry.
Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… Rotate credentials and review authentication logs for signs of prior unauthorized access - this flaw may have already let someone in without ever needing a valid password.
AutoAgent contains an unauthenticated remote code execution vulnerability in the TCP server that binds to all interfaces and executes attacker-supplied commands as root. Attackers can connect to the exposed communication port and execute arbitrary bash commands within the container, gaining access to bind-mounted host workspace directories.
CVE-2026-86124 is in VulnCheck's Known Exploited Vulnerabilities catalog (Community), meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw successful exploitation lets an attacker run their own code on the affected system - effectively taking full remote control of it. It affects HKUDS AutoAgent, which is broadly deployed across essentially every industry.
Staying safe: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable. Treat this as the highest-urgency patch class: remote code execution hands an attacker full control with no further steps needed, so isolate internet-facing instances immediately if patching can't happen right away.
Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.
CVE-2026-53266 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw lets an attacker corrupt the program's memory, which can crash the system or, in the worst case, run arbitrary code. It affects Linux Kernel, which is broadly deployed across essentially every industry.
Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… The patch itself is the primary defense here - memory-safety flaws are hard to confirm after the fact from logs alone, so prevention matters more than detection for this class.
N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for CVE-2026-18556.
CVE-2026-18577 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw lets an attacker access the system without valid credentials, bypassing the login process entirely. It affects N-able N-central, which is broadly deployed across essentially every industry.
Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… Rotate credentials and review authentication logs for signs of prior unauthorized access - this flaw may have already let someone in without ever needing a valid password.
knowns versions before 0.30.0 contain a path traversal vulnerability in the POST /api/templates/preview endpoint that allows unauthenticated attackers to read arbitrary files. Attackers can supply directory traversal sequences in the templateFile parameter to bypass path restrictions and read sensitive files like credentials and configuration through the JSON response.
CVE-2026-86538 is in VulnCheck's Known Exploited Vulnerabilities catalog (Community), meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw lets an attacker read or write files outside the folders the application is supposed to be restricted to. It affects knowns-dev knowns, which is broadly deployed across essentially every industry.
Staying safe: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable. Check whether any files outside the application's intended directories were read or modified, and review web server logs for unusual "../"-style path patterns in requests.
Dolibarr 23.0.4 before 24.0.1 contains an authorization bypass vulnerability that allows unauthenticated attackers to read arbitrary files through the document storage endpoints by supplying a crafted hashp parameter value. Attackers can send a request with hashp=shared to skip token validation while satisfying the authorization condition in htdocs/document.php and htdocs/viewimage.php, gaining access to application logs, uploaded business documents, database backups containing password hashes, and files belonging to other multicompany entities.
CVE-2026-89013 is in VulnCheck's Known Exploited Vulnerabilities catalog (Community), meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw gives an attacker a way to compromise the system beyond its intended security boundaries. It affects dolibarr dolibarr erp\/crm, which is broadly deployed across essentially every industry.
Staying safe: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable. More generally: confirm whether dolibarr dolibarr erp\/crm is exposed to the internet or reachable by untrusted users, prioritize patching internet-facing instances first, and check available logs for indicators of prior exploitation before assuming a patch alone closes the incident.
Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-55040 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw gives an attacker a way to compromise the system beyond its intended security boundaries. It affects Microsoft SharePoint, which is broadly deployed across essentially every industry.
Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… More generally: confirm whether Microsoft SharePoint is exposed to the internet or reachable by untrusted users, prioritize patching internet-facing instances first, and check available logs for indicators of prior exploitation before assuming a patch alone closes the incident.
Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.
CVE-2026-76460 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw gives an attacker a way to compromise the system beyond its intended security boundaries. It affects Cisco Identity Services Engine, which is broadly deployed across essentially every industry.
Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… More generally: confirm whether Cisco Identity Services Engine is exposed to the internet or reachable by untrusted users, prioritize patching internet-facing instances first, and check available logs for indicators of prior exploitation before assuming a patch alone closes the incident.