Active Threats

Exploits

Vulnerabilities with confirmed active exploitation in the wild - not just a high severity score - sourced from CISA's Known Exploited Vulnerabilities catalog and scored by real-world exploitation likelihood.

Refreshed daily from CISA's Known Exploited Vulnerabilities catalog, VulnCheck's KEV, and ENISA's EU Vulnerability Database, scored with EPSS (Exploit Prediction Scoring System) from FIRST.org - a model estimating the probability a vulnerability will actually be exploited, not just how severe it could theoretically be. Ranked by priority and capped at the 60 highest-priority entries, not just newest-first, so the list stays current without growing unbounded.

CVE-2017-5638 Ransomware-Linked

Apache Struts Remote Code Execution Vulnerability

Apache · Struts
100.0% EPSS score - probability of exploitation in the next 30 days
100.0% EPSS percentile - riskier than this share of all scored CVEs
Financial Services

Apache Struts Jakarta Multipart parser allows for malicious file upload using the Content-Type value, leading to remote code execution. This is the exact vulnerability behind Equifax's 2017 breach - a financial services credit-reporting agency - which exposed roughly 147 million people's financial and personal data, one of the largest breaches ever tied to a single named CVE.

CVE-2017-5638 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw successful exploitation lets an attacker run their own code on the affected system - effectively taking full remote control of it. CISA has also tied this vulnerability to known ransomware campaigns, which raises the stakes of leaving it unpatched. It affects Apache Struts, most relevant to organizations in Financial Services.

Staying safe: Apply the vendor's security update as soon as possible. Treat this as the highest-urgency patch class: remote code execution hands an attacker full control with no further steps needed, so isolate internet-facing instances immediately if patching can't happen right away.

CVE-2026-35273 Ransomware-Linked

Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability

Oracle · PeopleSoft Enterprise PeopleTools
95.5% EPSS score - probability of exploitation in the next 30 days
99.9% EPSS percentile - riskier than this share of all scored CVEs
General / Any Organization

Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise PeopleTools.

CVE-2026-35273 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw gives an attacker a way to compromise the system beyond its intended security boundaries. CISA has also tied this vulnerability to known ransomware campaigns, which raises the stakes of leaving it unpatched. It affects Oracle PeopleSoft Enterprise PeopleTools, which is broadly deployed across essentially every industry.

Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… More generally: confirm whether Oracle PeopleSoft Enterprise PeopleTools is exposed to the internet or reachable by untrusted users, prioritize patching internet-facing instances first, and check available logs for indicators of prior exploitation before assuming a patch alone closes the incident.

CVE-2026-0257 Ransomware-Linked

Palo Alto Networks PAN-OS Authentication Bypass Vulnerability

Palo Alto Networks · PAN-OS
93.9% EPSS score - probability of exploitation in the next 30 days
99.8% EPSS percentile - riskier than this share of all scored CVEs
General / Any Organization

Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection.

CVE-2026-0257 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw lets an attacker access the system without valid credentials, bypassing the login process entirely. CISA has also tied this vulnerability to known ransomware campaigns, which raises the stakes of leaving it unpatched. It affects Palo Alto Networks PAN-OS, which is broadly deployed across essentially every industry.

Staying safe: Apply mitigations per vendor instructions, follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Rotate credentials and review authentication logs for signs of prior unauthorized access - this flaw may have already let someone in without ever needing a valid password.

CVE-2026-15409 Ransomware-Linked

SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability

SonicWall · SMA1000 Appliances
83.7% EPSS score - probability of exploitation in the next 30 days
99.7% EPSS percentile - riskier than this share of all scored CVEs
General / Any Organization

SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.

CVE-2026-15409 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw lets an attacker trick the server into making requests on their behalf, often reaching internal systems that aren't meant to be exposed. CISA has also tied this vulnerability to known ransomware campaigns, which raises the stakes of leaving it unpatched. It affects SonicWall SMA1000 Appliances, which is broadly deployed across essentially every industry.

Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… Restrict the affected service's own outbound network access to only what it legitimately needs - this flaw is exploited specifically to reach internal systems the service was never meant to contact.

CVE-2026-50751 Ransomware-Linked

Check Point Security Gateway Improper Authentication Vulnerability

Check Point · Security Gateway
82.6% EPSS score - probability of exploitation in the next 30 days
99.6% EPSS percentile - riskier than this share of all scored CVEs
General / Any Organization

Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.

CVE-2026-50751 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw lets an attacker access the system without valid credentials, bypassing the login process entirely. CISA has also tied this vulnerability to known ransomware campaigns, which raises the stakes of leaving it unpatched. It affects Check Point Security Gateway, which is broadly deployed across essentially every industry.

Staying safe: Apply mitigations per vendor instructions, follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Rotate credentials and review authentication logs for signs of prior unauthorized access - this flaw may have already let someone in without ever needing a valid password.

CVE-2026-45659 Ransomware-Linked

Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability

Microsoft · SharePoint Server
76.1% EPSS score - probability of exploitation in the next 30 days
99.5% EPSS percentile - riskier than this share of all scored CVEs
General / Any Organization

Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.

CVE-2026-45659 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw lets an attacker execute code by feeding the application specially-crafted data it wasn't built to safely handle. CISA has also tied this vulnerability to known ransomware campaigns, which raises the stakes of leaving it unpatched. It affects Microsoft SharePoint Server, which is broadly deployed across essentially every industry.

Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… Treat any data this service has ever accepted from an untrusted source as potentially having triggered this, and review for signs of unexpected code execution, not just requests to the deserialization endpoint itself.

CVE-2026-59310 Ransomware-Linked

Broadcom VMware vCenter Path Traversal Vulnerability

Broadcom · VMware vCenter
50.4% EPSS score - probability of exploitation in the next 30 days
98.9% EPSS percentile - riskier than this share of all scored CVEs
General / Any Organization

Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code.

CVE-2026-59310 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw lets an attacker read or write files outside the folders the application is supposed to be restricted to. CISA has also tied this vulnerability to known ransomware campaigns, which raises the stakes of leaving it unpatched. It affects Broadcom VMware vCenter, which is broadly deployed across essentially every industry.

Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… Check whether any files outside the application's intended directories were read or modified, and review web server logs for unusual "../"-style path patterns in requests.

CVE-2026-12569 Ransomware-Linked

PTC Windchill and FlexPLM Improper Input Validation Vulnerability

PTC · Windchill and FlexPLM
40.6% EPSS score - probability of exploitation in the next 30 days
98.5% EPSS percentile - riskier than this share of all scored CVEs
General / Any Organization

PTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attacker to execute arbitrary code by sending a malicious request to the network.

CVE-2026-12569 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw gives an attacker a way to compromise the system beyond its intended security boundaries. CISA has also tied this vulnerability to known ransomware campaigns, which raises the stakes of leaving it unpatched. It affects PTC Windchill and FlexPLM, which is broadly deployed across essentially every industry.

Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… More generally: confirm whether PTC Windchill and FlexPLM is exposed to the internet or reachable by untrusted users, prioritize patching internet-facing instances first, and check available logs for indicators of prior exploitation before assuming a patch alone closes the incident.

CVE-2026-15410 Ransomware-Linked

SonicWall SMA1000 Appliances Code Injection Vulnerability

SonicWall · SMA1000 Appliances
11.8% EPSS score - probability of exploitation in the next 30 days
95.8% EPSS percentile - riskier than this share of all scored CVEs
General / Any Organization

SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.

CVE-2026-15410 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw gives an attacker a way to compromise the system beyond its intended security boundaries. CISA has also tied this vulnerability to known ransomware campaigns, which raises the stakes of leaving it unpatched. It affects SonicWall SMA1000 Appliances, which is broadly deployed across essentially every industry.

Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… More generally: confirm whether SonicWall SMA1000 Appliances is exposed to the internet or reachable by untrusted users, prioritize patching internet-facing instances first, and check available logs for indicators of prior exploitation before assuming a patch alone closes the incident.

CVE-2026-20316 Ransomware-Linked

Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability

Cisco · Secure Firewall Management Center (FMC)
11.2% EPSS score - probability of exploitation in the next 30 days
95.7% EPSS percentile - riskier than this share of all scored CVEs
General / Any Organization

Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.

CVE-2026-20316 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw gives an attacker a way to compromise the system beyond its intended security boundaries. CISA has also tied this vulnerability to known ransomware campaigns, which raises the stakes of leaving it unpatched. It affects Cisco Secure Firewall Management Center (FMC), which is broadly deployed across essentially every industry.

Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… More generally: confirm whether Cisco Secure Firewall Management Center (FMC) is exposed to the internet or reachable by untrusted users, prioritize patching internet-facing instances first, and check available logs for indicators of prior exploitation before assuming a patch alone closes the incident.

CVE-2026-48027 Ransomware-Linked

Nx Console Embedded Malicious Code Vulnerability

Nx · Nx Console
1.8% EPSS score - probability of exploitation in the next 30 days
77.3% EPSS percentile - riskier than this share of all scored CVEs
General / Any Organization

Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload that could harvested credentials from multiple sources on disk and in memory.

CVE-2026-48027 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw gives an attacker a way to compromise the system beyond its intended security boundaries. CISA has also tied this vulnerability to known ransomware campaigns, which raises the stakes of leaving it unpatched. It affects Nx Nx Console, which is broadly deployed across essentially every industry.

Staying safe: Apply mitigations per vendor instructions, follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. More generally: confirm whether Nx Nx Console is exposed to the internet or reachable by untrusted users, prioritize patching internet-facing instances first, and check available logs for indicators of prior exploitation before assuming a patch alone closes the incident.

CVE-2026-20079

Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability

Cisco · Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management
75.8% EPSS score - probability of exploitation in the next 30 days
99.5% EPSS percentile - riskier than this share of all scored CVEs
General / Any Organization

Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication Bypass using an alternate path or channel vulnerability that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.

CVE-2026-20079 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw lets an attacker access the system without valid credentials, bypassing the login process entirely. It affects Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management, which is broadly deployed across essentially every industry.

Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… Rotate credentials and review authentication logs for signs of prior unauthorized access - this flaw may have already let someone in without ever needing a valid password.

CVE-2026-10520

Ivanti Sentry OS Command Injection Vulnerability

Ivanti · Sentry
99.9% EPSS score - probability of exploitation in the next 30 days
100.0% EPSS percentile - riskier than this share of all scored CVEs
General / Any Organization

Ivanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve root-level remote code execution. This vulnerability can be successfully exploited in cases where the Sentry appliance is in an unmanaged state with its endpoints externally reachable. The use of mTLS with EPMM or restricted HTTPS access through Neurons for MDM makes interfaces inaccessible to external actors.

CVE-2026-10520 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw successful exploitation lets an attacker run their own code on the affected system - effectively taking full remote control of it. It affects Ivanti Sentry, which is broadly deployed across essentially every industry.

Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… Treat this as the highest-urgency patch class: remote code execution hands an attacker full control with no further steps needed, so isolate internet-facing instances immediately if patching can't happen right away.

CVE-2026-8037

Progress LoadMaster Command Injection Vulnerability

Progress · LoadMaster
99.6% EPSS score - probability of exploitation in the next 30 days
99.9% EPSS percentile - riskier than this share of all scored CVEs
General / Any Organization

Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints.

CVE-2026-8037 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw lets an attacker run arbitrary operating-system commands on the server. It affects Progress LoadMaster, which is broadly deployed across essentially every industry.

Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… Review shell/process execution logs on the affected system for unexpected commands, and treat any output the application has generated since as suspect until confirmed clean.

CVE-2026-34486

Apache Tomcat Missing Encryption of Sensitive Data Vulnerability

Apache · Tomcat
98.6% EPSS score - probability of exploitation in the next 30 days
99.9% EPSS percentile - riskier than this share of all scored CVEs
General / Any Organization

Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813.

CVE-2026-34486 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw gives an attacker a way to compromise the system beyond its intended security boundaries. It affects Apache Tomcat, which is broadly deployed across essentially every industry.

Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… More generally: confirm whether Apache Tomcat is exposed to the internet or reachable by untrusted users, prioritize patching internet-facing instances first, and check available logs for indicators of prior exploitation before assuming a patch alone closes the incident.

CVE-2026-63030

WordPress Core Interpretation Conflict Vulnerability

WordPress · Core
97.3% EPSS score - probability of exploitation in the next 30 days
99.9% EPSS percentile - riskier than this share of all scored CVEs
General / Any Organization

WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.

CVE-2026-63030 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw successful exploitation lets an attacker run their own code on the affected system - effectively taking full remote control of it. It affects WordPress Core, which is broadly deployed across essentially every industry.

Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… Treat this as the highest-urgency patch class: remote code execution hands an attacker full control with no further steps needed, so isolate internet-facing instances immediately if patching can't happen right away.

CVE-2026-20253

Splunk Enterprise Missing Authentication for Critical Function Vulnerability

Splunk · Enterprise
96.9% EPSS score - probability of exploitation in the next 30 days
99.9% EPSS percentile - riskier than this share of all scored CVEs
General / Any Organization

Splunk Enterprise contains a missing authentication for critical function vulnerability which could allow an unauthenticated user to create or truncate arbitrary files through a PostgreSQL sidecar service endpoint.

CVE-2026-20253 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw gives an attacker a way to compromise the system beyond its intended security boundaries. It affects Splunk Enterprise, which is broadly deployed across essentially every industry.

Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… More generally: confirm whether Splunk Enterprise is exposed to the internet or reachable by untrusted users, prioritize patching internet-facing instances first, and check available logs for indicators of prior exploitation before assuming a patch alone closes the incident.

CVE-2026-72898

Metabase SQL Injection Vulnerability

Metabase · Metabase
94.2% EPSS score - probability of exploitation in the next 30 days
99.8% EPSS percentile - riskier than this share of all scored CVEs
General / Any Organization

Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data.

CVE-2026-72898 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw lets an attacker manipulate the underlying database directly, potentially reading, modifying, or deleting data they should never be able to touch. It affects Metabase Metabase, which is broadly deployed across essentially every industry.

Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… Review database access logs for unusual queries, and restrict the application's own database account to the minimum privileges it actually needs, so a successful injection can't reach further than necessary.

CVE-2026-39808

Fortinet FortiSandbox OS Command Injection Vulnerability

Fortinet · FortiSandbox
92.8% EPSS score - probability of exploitation in the next 30 days
99.8% EPSS percentile - riskier than this share of all scored CVEs
General / Any Organization

Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.

CVE-2026-39808 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw lets an attacker run arbitrary operating-system commands on the server. It affects Fortinet FortiSandbox, which is broadly deployed across essentially every industry.

Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… Review shell/process execution logs on the affected system for unexpected commands, and treat any output the application has generated since as suspect until confirmed clean.

CVE-2020-10148

SolarWinds Orion Authentication Bypass Vulnerability

SolarWinds · Orion
92.0% EPSS score - probability of exploitation in the next 30 days
99.8% EPSS percentile - riskier than this share of all scored CVEs
Government & Public Sector

SolarWinds Orion API contains an authentication bypass vulnerability that could allow a remote attacker to execute API commands. Orion is widely deployed for network monitoring across U.S. federal government agencies - CISA issued Emergency Directive 21-01 in December 2020 specifically instructing federal civilian agencies to disconnect or patch affected Orion instances after a separate supply-chain compromise of the same product was discovered.

CVE-2020-10148 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw lets an attacker access the system without valid credentials, bypassing the login process entirely. It affects SolarWinds Orion, most relevant to organizations in Government & Public Sector.

Staying safe: Apply the vendor's security update as soon as possible. Rotate credentials and review authentication logs for signs of prior unauthorized access - this flaw may have already let someone in without ever needing a valid password.

CVE-2026-20230

Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability

Cisco · Unified Communications Manager
88.2% EPSS score - probability of exploitation in the next 30 days
99.8% EPSS percentile - riskier than this share of all scored CVEs
General / Any Organization

Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) contain a server-side request forgery (SSRF) Vulnerability that could allow an unauthenticated, remote attacker to write files to the underlying operating system that could be used later to elevate to root.

CVE-2026-20230 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw lets an attacker trick the server into making requests on their behalf, often reaching internal systems that aren't meant to be exposed. It affects Cisco Unified Communications Manager, which is broadly deployed across essentially every industry.

Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… Restrict the affected service's own outbound network access to only what it legitimately needs - this flaw is exploited specifically to reach internal systems the service was never meant to contact.

CVE-2026-60004

Gitea Code Injection Vulnerability

Gitea · Gitea
86.8% EPSS score - probability of exploitation in the next 30 days
99.7% EPSS percentile - riskier than this share of all scored CVEs
General / Any Organization

Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account.

CVE-2026-60004 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw gives an attacker a way to compromise the system beyond its intended security boundaries. It affects Gitea Gitea, which is broadly deployed across essentially every industry.

Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… More generally: confirm whether Gitea Gitea is exposed to the internet or reachable by untrusted users, prioritize patching internet-facing instances first, and check available logs for indicators of prior exploitation before assuming a patch alone closes the incident.

CVE-2026-34910

Ubiquiti UniFi OS Improper Input Validation Vulnerability

Ubiquiti · UniFi OS
87.0% EPSS score - probability of exploitation in the next 30 days
99.7% EPSS percentile - riskier than this share of all scored CVEs
General / Any Organization

Ubiquiti UniFi OS contains an improper input validation vulnerability which could allow a malicious actor with access to the network to conduct command injection.

CVE-2026-34910 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw lets an attacker run arbitrary operating-system commands on the server. It affects Ubiquiti UniFi OS, which is broadly deployed across essentially every industry.

Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… Review shell/process execution logs on the affected system for unexpected commands, and treat any output the application has generated since as suspect until confirmed clean.

CVE-2021-23758

Ajax.NET Professional Deserialization of Untrusted Data Vulnerability

Ajax.NET Professional · Ajax.NET Professional
83.6% EPSS score - probability of exploitation in the next 30 days
99.7% EPSS percentile - riskier than this share of all scored CVEs
General / Any Organization

Ajax.NET Professional (AjaxPro) contains a deserialization of untrusted data vulnerability that could allow for remote code execution via arbitrary .NET classes. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.

CVE-2021-23758 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw successful exploitation lets an attacker run their own code on the affected system - effectively taking full remote control of it. It affects Ajax.NET Professional Ajax.NET Professional, which is broadly deployed across essentially every industry.

Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… Treat this as the highest-urgency patch class: remote code execution hands an attacker full control with no further steps needed, so isolate internet-facing instances immediately if patching can't happen right away.

CVE-2026-63077

JetBrains TeamCity Deserialization of Untrusted Data Vulnerability

JetBrains · TeamCity
86.5% EPSS score - probability of exploitation in the next 30 days
99.7% EPSS percentile - riskier than this share of all scored CVEs
General / Any Organization

JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol.

CVE-2026-63077 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw successful exploitation lets an attacker run their own code on the affected system - effectively taking full remote control of it. It affects JetBrains TeamCity, which is broadly deployed across essentially every industry.

Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… Treat this as the highest-urgency patch class: remote code execution hands an attacker full control with no further steps needed, so isolate internet-facing instances immediately if patching can't happen right away.

CVE-2026-50522

Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

Microsoft · SharePoint
85.4% EPSS score - probability of exploitation in the next 30 days
99.7% EPSS percentile - riskier than this share of all scored CVEs
General / Any Organization

Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.

CVE-2026-50522 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw lets an attacker execute code by feeding the application specially-crafted data it wasn't built to safely handle. It affects Microsoft SharePoint, which is broadly deployed across essentially every industry.

Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… Treat any data this service has ever accepted from an untrusted source as potentially having triggered this, and review for signs of unexpected code execution, not just requests to the deserialization endpoint itself.

CVE-2026-34908

Ubiquiti UniFi OS Improper Access Control Vulnerability

Ubiquiti · UniFi OS
85.2% EPSS score - probability of exploitation in the next 30 days
99.7% EPSS percentile - riskier than this share of all scored CVEs
General / Any Organization

Ubiquiti UniFi OS contains an improper access control vulnerability which could allow a malicious actor with access to the network to make unauthorized changes to the system.

CVE-2026-34908 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw gives an attacker a way to compromise the system beyond its intended security boundaries. It affects Ubiquiti UniFi OS, which is broadly deployed across essentially every industry.

Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… More generally: confirm whether Ubiquiti UniFi OS is exposed to the internet or reachable by untrusted users, prioritize patching internet-facing instances first, and check available logs for indicators of prior exploitation before assuming a patch alone closes the incident.

CVE-2026-42271

BerriAI LiteLLM Command Injection Vulnerability

BerriAI · LiteLLM
83.0% EPSS score - probability of exploitation in the next 30 days
99.6% EPSS percentile - riskier than this share of all scored CVEs
General / Any Organization

BerriAI LiteLLM contains a command injection vulnerability that could allow any authenticated user, including holders of low-privilege internal-user keys, to run arbitrary commands on the host.

CVE-2026-42271 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw lets an attacker run arbitrary operating-system commands on the server. It affects BerriAI LiteLLM, which is broadly deployed across essentially every industry.

Staying safe: Apply mitigations per vendor instructions, follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Review shell/process execution logs on the affected system for unexpected commands, and treat any output the application has generated since as suspect until confirmed clean.

CVE-2026-60137

WordPress Core SQL Injection Vulnerability

WordPress · Core
78.3% EPSS score - probability of exploitation in the next 30 days
99.6% EPSS percentile - riskier than this share of all scored CVEs
General / Any Organization

WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations.

CVE-2026-60137 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw successful exploitation lets an attacker run their own code on the affected system - effectively taking full remote control of it. It affects WordPress Core, which is broadly deployed across essentially every industry.

Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… Treat this as the highest-urgency patch class: remote code execution hands an attacker full control with no further steps needed, so isolate internet-facing instances immediately if patching can't happen right away.

CVE-2026-25089

Fortinet FortiSandbox OS Command Injection Vulnerability

Fortinet · FortiSandbox
76.1% EPSS score - probability of exploitation in the next 30 days
99.5% EPSS percentile - riskier than this share of all scored CVEs
General / Any Organization

Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.

CVE-2026-25089 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw lets an attacker run arbitrary operating-system commands on the server. It affects Fortinet FortiSandbox, which is broadly deployed across essentially every industry.

Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… Review shell/process execution logs on the affected system for unexpected commands, and treat any output the application has generated since as suspect until confirmed clean.

CVE-2026-61511

vBulletin vBulletin Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')

vBulletin · vBulletin
70.8% EPSS score - probability of exploitation in the next 30 days
99.4% EPSS percentile - riskier than this share of all scored CVEs
General / Any Organization

vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code by supplying crafted input through the pagenav[pagenumber] parameter. Attackers can exploit the insufficiently restrictive regex filter by using phpfuck-style encoding with permitted characters to inject and execute arbitrary PHP code via the unauthenticated ajax/render template route without any authentication.

CVE-2026-61511 is in VulnCheck's Known Exploited Vulnerabilities catalog (Community), meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw gives an attacker a way to compromise the system beyond its intended security boundaries. It affects vBulletin vBulletin, which is broadly deployed across essentially every industry.

Staying safe: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable. More generally: confirm whether vBulletin vBulletin is exposed to the internet or reachable by untrusted users, prioritize patching internet-facing instances first, and check available logs for indicators of prior exploitation before assuming a patch alone closes the incident.

CVE-2026-33824

Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability

Microsoft · Internet Key Exchange (IKE) Service Extensions
72.7% EPSS score - probability of exploitation in the next 30 days
99.4% EPSS percentile - riskier than this share of all scored CVEs
General / Any Organization

Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.

CVE-2026-33824 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw successful exploitation lets an attacker run their own code on the affected system - effectively taking full remote control of it. It affects Microsoft Internet Key Exchange (IKE) Service Extensions, which is broadly deployed across essentially every industry.

Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… Treat this as the highest-urgency patch class: remote code execution hands an attacker full control with no further steps needed, so isolate internet-facing instances immediately if patching can't happen right away.

CVE-2026-16232

Check Point SmartConsole Improper Authentication Vulnerability

Check Point · SmartConsole
72.1% EPSS score - probability of exploitation in the next 30 days
99.4% EPSS percentile - riskier than this share of all scored CVEs
General / Any Organization

Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.

CVE-2026-16232 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw lets an attacker access the system without valid credentials, bypassing the login process entirely. It affects Check Point SmartConsole, which is broadly deployed across essentially every industry.

Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… Rotate credentials and review authentication logs for signs of prior unauthorized access - this flaw may have already let someone in without ever needing a valid password.

CVE-2026-79756

iguazio nuclio Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

iguazio · nuclio
5.1% EPSS score - probability of exploitation in the next 30 days
92.0% EPSS percentile - riskier than this share of all scored CVEs
General / Any Organization

Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.17.4, the fix for unauthenticated OS command injection in the nuclio dashboard on the local/Docker platform is incomplete. The fix added validateFunctionName for function names and common.Quote() for the named-resource shell command path, but the list-all resource path (triggered when no specific resource name is provided) still interpolates the resourceNamespace parameter unquoted into a /bin/sh -c command string. An unauthenticated attacker can inject shell metacharacters via the X-Nuclio-Functio…

CVE-2026-79756 is in VulnCheck's Known Exploited Vulnerabilities catalog (Community), meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw lets an attacker run arbitrary operating-system commands on the server. It affects iguazio nuclio, which is broadly deployed across essentially every industry.

Staying safe: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable. Review shell/process execution logs on the affected system for unexpected commands, and treat any output the application has generated since as suspect until confirmed clean.

CVE-2026-48907

Widget Factory Joomla Content Editor Improper Access Control Vulnerability

Widget Factory · Joomla Content Editor
66.0% EPSS score - probability of exploitation in the next 30 days
99.2% EPSS percentile - riskier than this share of all scored CVEs
General / Any Organization

Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticated users.

CVE-2026-48907 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw gives an attacker a way to compromise the system beyond its intended security boundaries. It affects Widget Factory Joomla Content Editor, which is broadly deployed across essentially every industry.

Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… More generally: confirm whether Widget Factory Joomla Content Editor is exposed to the internet or reachable by untrusted users, prioritize patching internet-facing instances first, and check available logs for indicators of prior exploitation before assuming a patch alone closes the incident.

CVE-2026-34909

Ubiquiti UniFi OS Path Traversal Vulnerability

Ubiquiti · UniFi OS
63.9% EPSS score - probability of exploitation in the next 30 days
99.2% EPSS percentile - riskier than this share of all scored CVEs
General / Any Organization

Ubiquiti UniFi OS contains a path traversal vulnerability which could allow a malicious actor with access to the network to access files on the underlying system that could be manipulated to access an underlying account.

CVE-2026-34909 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw lets an attacker read or write files outside the folders the application is supposed to be restricted to. It affects Ubiquiti UniFi OS, which is broadly deployed across essentially every industry.

Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… Check whether any files outside the application's intended directories were read or modified, and review web server logs for unusual "../"-style path patterns in requests.

CVE-2026-45298

amirraminfar dozzle Server-Side Request Forgery (SSRF)

amirraminfar · dozzle
1.5% EPSS score - probability of exploitation in the next 30 days
71.9% EPSS percentile - riskier than this share of all scored CVEs
General / Any Organization

Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, in a default dozzle deploy (the documented quickstart, no DOZZLE_AUTH_PROVIDER set), POST /api/notifications/test-webhook is reachable without authentication and forwards an attacker-controlled URL into a WebhookDispatcher that sends an HTTP POST to the supplied URL with attacker-controlled request headers, and returns the response status code AND up to 1MB of the response body to the caller, when the target replies non-2xx. This vulnerability is fixed in 10.5.2.

CVE-2026-45298 is in VulnCheck's Known Exploited Vulnerabilities catalog (Community), meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw lets an attacker trick the server into making requests on their behalf, often reaching internal systems that aren't meant to be exposed. It affects amirraminfar dozzle, which is broadly deployed across essentially every industry.

Staying safe: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable. Restrict the affected service's own outbound network access to only what it legitimately needs - this flaw is exploited specifically to reach internal systems the service was never meant to contact.

CVE-2026-93952

Arista VeloCloud Orchestrator Improper Input Validation Vulnerability

Arista · VeloCloud Orchestrator
0.4% EPSS score - probability of exploitation in the next 30 days
36.3% EPSS percentile - riskier than this share of all scored CVEs
General / Any Organization

Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.

CVE-2026-93952 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw gives an attacker a way to compromise the system beyond its intended security boundaries. It affects Arista VeloCloud Orchestrator, which is broadly deployed across essentially every industry.

Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… More generally: confirm whether Arista VeloCloud Orchestrator is exposed to the internet or reachable by untrusted users, prioritize patching internet-facing instances first, and check available logs for indicators of prior exploitation before assuming a patch alone closes the incident.

CVE-2026-85102

Check Point Multiple Products Improper Certificate Validation Vulnerability

Check Point · Multiple Products
0.3% EPSS score - probability of exploitation in the next 30 days
26.3% EPSS percentile - riskier than this share of all scored CVEs
General / Any Organization

Check Point Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN contain an improper certificate validation vulnerability which could allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.

CVE-2026-85102 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw gives an attacker a way to compromise the system beyond its intended security boundaries. It affects Check Point Multiple Products, which is broadly deployed across essentially every industry.

Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… More generally: confirm whether Check Point Multiple Products is exposed to the internet or reachable by untrusted users, prioritize patching internet-facing instances first, and check available logs for indicators of prior exploitation before assuming a patch alone closes the incident.

CVE-2026-75949

Unrestricted Upload of File with Dangerous Type

cmsjunkie.com · J-BusinessDirectory extension for Joomla
0.3% EPSS score - probability of exploitation in the next 30 days
24.3% EPSS percentile - riskier than this share of all scored CVEs
General / Any Organization

Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 - Upload/remove accepted a client-controlled root (_path_type could point at the component site/admin trees), did not enforce path containment, and used a weak extension check. CSRF token was also missing on upload/remove.

CVE-2026-75949 is in VulnCheck's Known Exploited Vulnerabilities catalog (Community), meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw lets an attacker read or write files outside the folders the application is supposed to be restricted to. It affects cmsjunkie.com J-BusinessDirectory extension for Joomla, which is broadly deployed across essentially every industry.

Staying safe: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable. Check whether any files outside the application's intended directories were read or modified, and review web server logs for unusual "../"-style path patterns in requests.

CVE-2026-0770

Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability

Langflow · Langflow
63.4% EPSS score - probability of exploitation in the next 30 days
99.2% EPSS percentile - riskier than this share of all scored CVEs
General / Any Organization

Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations.

CVE-2026-0770 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw gives an attacker a way to compromise the system beyond its intended security boundaries. It affects Langflow Langflow, which is broadly deployed across essentially every industry.

Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… More generally: confirm whether Langflow Langflow is exposed to the internet or reachable by untrusted users, prioritize patching internet-facing instances first, and check available logs for indicators of prior exploitation before assuming a patch alone closes the incident.

CVE-2026-66457

pixelite events_manager Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

pixelite · events manager
0.2% EPSS score - probability of exploitation in the next 30 days
8.4% EPSS percentile - riskier than this share of all scored CVEs
General / Any Organization

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pixelite Events Manager events-manager allows Reflected XSS.This issue affects Events Manager: from n/a through 7.4.2.

CVE-2026-66457 is in VulnCheck's Known Exploited Vulnerabilities catalog (Community), meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw lets an attacker inject malicious script into pages viewed by other users, often to steal their session or credentials. It affects pixelite events manager, which is broadly deployed across essentially every industry.

Staying safe: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable. Force a session/credential reset for privileged users of the affected application - this flaw is commonly used to hijack an active session rather than compromise the server directly.

CVE-2026-94127

F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability

F5 · BIG-IP APM
General / Any Organization

F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unauthenticated attacker to perform remote code execution.

CVE-2026-94127 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw successful exploitation lets an attacker run their own code on the affected system - effectively taking full remote control of it. It affects F5 BIG-IP APM, which is broadly deployed across essentially every industry.

Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… Treat this as the highest-urgency patch class: remote code execution hands an attacker full control with no further steps needed, so isolate internet-facing instances immediately if patching can't happen right away.

CVE-2026-93616

Check Point Multiple Products Path Traversal Vulnerability

Check Point · Multiple Products
General / Any Organization

Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent contain a path traversal vulnerability that allows an unauthenticated attacker to upload and execute arbitrary scripts.

CVE-2026-93616 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw lets an attacker read or write files outside the folders the application is supposed to be restricted to. It affects Check Point Multiple Products, which is broadly deployed across essentially every industry.

Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… Check whether any files outside the application's intended directories were read or modified, and review web server logs for unusual "../"-style path patterns in requests.

CVE-2026-87902

WordPress wordpress Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

WordPress · wordpress
General / Any Organization

An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.

CVE-2026-87902 is in VulnCheck's Known Exploited Vulnerabilities catalog (Community), meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw successful exploitation lets an attacker run their own code on the affected system - effectively taking full remote control of it. It affects WordPress wordpress, which is broadly deployed across essentially every industry.

Staying safe: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable. Treat this as the highest-urgency patch class: remote code execution hands an attacker full control with no further steps needed, so isolate internet-facing instances immediately if patching can't happen right away.

CVE-2026-55786

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

FlytoHub · Flyto2 Core
General / Any Organization

## Unauthenticated Command Execution via HTTP MCP `execute_module` ### Summary The HTTP MCP endpoint (`POST /mcp`) in flyto-core accepts unauthenticated JSON-RPC `tools/call` requests and dispatches them to arbitrary registered modules, including `sandbox.execute_shell`, which passes attacker-controlled input directly to `asyncio.create_subprocess_shell`. An unauthenticated attacker can execute arbitrary OS commands as the flyto-core server process. By default the server binds to `127.0.0.1`, making this a High-severity local vulnerability (CVSS 8.4); if started with `--host 0.0.0.0`, it be…

CVE-2026-55786 is in VulnCheck's Known Exploited Vulnerabilities catalog (Community), meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw successful exploitation lets an attacker run their own code on the affected system - effectively taking full remote control of it. It affects FlytoHub Flyto2 Core, which is broadly deployed across essentially every industry.

Staying safe: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable. Treat this as the highest-urgency patch class: remote code execution hands an attacker full control with no further steps needed, so isolate internet-facing instances immediately if patching can't happen right away.

CVE-2026-7273

Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability

Zyxel · GS1900 Series Switches
2.0% EPSS score - probability of exploitation in the next 30 days
79.7% EPSS percentile - riskier than this share of all scored CVEs
General / Any Organization

Zyxel GS1900 series switches contain a stack-based buffer overflow vulnerability in the CGI program which could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.

CVE-2026-7273 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw lets an attacker corrupt the program's memory, which can crash the system or, in the worst case, run arbitrary code. It affects Zyxel GS1900 Series Switches, which is broadly deployed across essentially every industry.

Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… The patch itself is the primary defense here - memory-safety flaws are hard to confirm after the fact from logs alone, so prevention matters more than detection for this class.

CVE-2026-88062

Improper Control of Generation of Code ('Code Injection')

diegosouzapw · OmniRoute
0.9% EPSS score - probability of exploitation in the next 30 days
59.5% EPSS percentile - riskier than this share of all scored CVEs
General / Any Organization

OmniRoute is an open-source AI gateway providing a single endpoint for multiple model providers. In 3.8.49 and earlier, the OmniRoute POST /api/acp/agents custom ACP agent endpoint accepted attacker-controlled binary and versionCommand values and used only a self-consistency check before execFileSync executed the selected interpreter and arguments. The same request called refreshAgentCache, and resolveVersionProbe accepted the matched command before the execFileSync sink ran it. The tokenizeVersionCommand function and DISALLOWED_VERSION_COMMAND_CHARS filter rejected a limited set of shell met…

CVE-2026-88062 is in VulnCheck's Known Exploited Vulnerabilities catalog (Community), meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw gives an attacker a way to compromise the system beyond its intended security boundaries. It affects diegosouzapw OmniRoute, which is broadly deployed across essentially every industry.

Staying safe: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable. More generally: confirm whether diegosouzapw OmniRoute is exposed to the internet or reachable by untrusted users, prioritize patching internet-facing instances first, and check available logs for indicators of prior exploitation before assuming a patch alone closes the incident.

CVE-2026-92229

incsub forminator Improper Control of Generation of Code ('Code Injection')

wpmudev · Forminator Forms – Contact Form, Payment Form & Custom Form Builder
0.4% EPSS score - probability of exploitation in the next 30 days
34.2% EPSS percentile - riskier than this share of all scored CVEs
General / Any Organization

The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.57.2. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

CVE-2026-92229 is in VulnCheck's Known Exploited Vulnerabilities catalog (Community), meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw gives an attacker a way to compromise the system beyond its intended security boundaries. It affects wpmudev Forminator Forms – Contact Form, Payment Form & Custom Form Builder, which is broadly deployed across essentially every industry.

Staying safe: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable. More generally: confirm whether wpmudev Forminator Forms – Contact Form, Payment Form & Custom Form Builder is exposed to the internet or reachable by untrusted users, prioritize patching internet-facing instances first, and check available logs for indicators of prior exploitation before assuming a patch alone closes the incident.

CVE-2026-9198

IBM Langflow Code Injection Vulnerability

IBM · Langflow
60.6% EPSS score - probability of exploitation in the next 30 days
99.1% EPSS percentile - riskier than this share of all scored CVEs
General / Any Organization

Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.

CVE-2026-9198 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw successful exploitation lets an attacker run their own code on the affected system - effectively taking full remote control of it. It affects IBM Langflow, which is broadly deployed across essentially every industry.

Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… Treat this as the highest-urgency patch class: remote code execution hands an attacker full control with no further steps needed, so isolate internet-facing instances immediately if patching can't happen right away.

CVE-2026-84434

Unrestricted Upload of File with Dangerous Type

Gravity Forms · Gravity Forms
2.8% EPSS score - probability of exploitation in the next 30 days
85.6% EPSS percentile - riskier than this share of all scored CVEs
General / Any Organization

The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.0.4 via the upload_file function. This is due to a mismatch between the field validation pipeline and the file persistence pipeline, where hidden file upload fields bypass extension validation and a rejected file's intact upload state is later passed to upload_file() without re-validation. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible. Exploitation requires the targeted form to contain…

CVE-2026-84434 is in VulnCheck's Known Exploited Vulnerabilities catalog (Community), meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw successful exploitation lets an attacker run their own code on the affected system - effectively taking full remote control of it. It affects Gravity Forms Gravity Forms, which is broadly deployed across essentially every industry.

Staying safe: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable. Treat this as the highest-urgency patch class: remote code execution hands an attacker full control with no further steps needed, so isolate internet-facing instances immediately if patching can't happen right away.

CVE-2025-39682

Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability

Linux · Kernel
2.0% EPSS score - probability of exploitation in the next 30 days
80.2% EPSS percentile - riskier than this share of all scored CVEs
General / Any Organization

Linux Kernel contains an improper check for unusual or exceptional conditions vulnerability in the TLS receive path which allows a zero-length record retrieved from the rx_list to bypass the intended recvmsg() record-type handling, potentially causing subsequent TLS records to be processed using incorrect zero-copy and queuing assumptions. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.

CVE-2025-39682 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw gives an attacker a way to compromise the system beyond its intended security boundaries. It affects Linux Kernel, which is broadly deployed across essentially every industry.

Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… More generally: confirm whether Linux Kernel is exposed to the internet or reachable by untrusted users, prioritize patching internet-facing instances first, and check available logs for indicators of prior exploitation before assuming a patch alone closes the incident.

CVE-2019-1068

Microsoft SQL Server Remote Code Execution Vulnerability

Microsoft · SQL Server
52.8% EPSS score - probability of exploitation in the next 30 days
98.9% EPSS percentile - riskier than this share of all scored CVEs
General / Any Organization

Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine service account.

CVE-2019-1068 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw successful exploitation lets an attacker run their own code on the affected system - effectively taking full remote control of it. It affects Microsoft SQL Server, which is broadly deployed across essentially every industry.

Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… Treat this as the highest-urgency patch class: remote code execution hands an attacker full control with no further steps needed, so isolate internet-facing instances immediately if patching can't happen right away.

CVE-2025-39964

Linux Kernel Race Condition Vulnerability

Linux · Kernel
0.8% EPSS score - probability of exploitation in the next 30 days
54.7% EPSS percentile - riskier than this share of all scored CVEs
General / Any Organization

Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state.

CVE-2025-39964 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw gives an attacker a way to compromise the system beyond its intended security boundaries. It affects Linux Kernel, which is broadly deployed across essentially every industry.

Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… More generally: confirm whether Linux Kernel is exposed to the internet or reachable by untrusted users, prioritize patching internet-facing instances first, and check available logs for indicators of prior exploitation before assuming a patch alone closes the incident.

CVE-2026-48710

Kludex Starlette HTTP Request/Response Smuggling Vulnerability

Kludex · Starlette
36.3% EPSS score - probability of exploitation in the next 30 days
98.4% EPSS percentile - riskier than this share of all scored CVEs
General / Any Organization

Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentication bypass when the authentication depends on the reconstructed URL’s path. This vulnerability could be chaned with CVE-2026-42271.

CVE-2026-48710 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw lets an attacker access the system without valid credentials, bypassing the login process entirely. It affects Kludex Starlette, which is broadly deployed across essentially every industry.

Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… Rotate credentials and review authentication logs for signs of prior unauthorized access - this flaw may have already let someone in without ever needing a valid password.

CVE-2026-86124

Missing Authentication for Critical Function

HKUDS · AutoAgent
0.5% EPSS score - probability of exploitation in the next 30 days
44.6% EPSS percentile - riskier than this share of all scored CVEs
General / Any Organization

AutoAgent contains an unauthenticated remote code execution vulnerability in the TCP server that binds to all interfaces and executes attacker-supplied commands as root. Attackers can connect to the exposed communication port and execute arbitrary bash commands within the container, gaining access to bind-mounted host workspace directories.

CVE-2026-86124 is in VulnCheck's Known Exploited Vulnerabilities catalog (Community), meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw successful exploitation lets an attacker run their own code on the affected system - effectively taking full remote control of it. It affects HKUDS AutoAgent, which is broadly deployed across essentially every industry.

Staying safe: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable. Treat this as the highest-urgency patch class: remote code execution hands an attacker full control with no further steps needed, so isolate internet-facing instances immediately if patching can't happen right away.

CVE-2026-53266

Linux Kernel Out-of-Bounds Write Vulnerability

Linux · Kernel
0.3% EPSS score - probability of exploitation in the next 30 days
20.2% EPSS percentile - riskier than this share of all scored CVEs
General / Any Organization

Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.

CVE-2026-53266 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw lets an attacker corrupt the program's memory, which can crash the system or, in the worst case, run arbitrary code. It affects Linux Kernel, which is broadly deployed across essentially every industry.

Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… The patch itself is the primary defense here - memory-safety flaws are hard to confirm after the fact from logs alone, so prevention matters more than detection for this class.

CVE-2026-18577

N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

N-able · N-central
54.1% EPSS score - probability of exploitation in the next 30 days
99.0% EPSS percentile - riskier than this share of all scored CVEs
General / Any Organization

N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for CVE-2026-18556.

CVE-2026-18577 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw lets an attacker access the system without valid credentials, bypassing the login process entirely. It affects N-able N-central, which is broadly deployed across essentially every industry.

Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… Rotate credentials and review authentication logs for signs of prior unauthorized access - this flaw may have already let someone in without ever needing a valid password.

CVE-2026-86538

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

knowns-dev · knowns
0.7% EPSS score - probability of exploitation in the next 30 days
53.0% EPSS percentile - riskier than this share of all scored CVEs
General / Any Organization

knowns versions before 0.30.0 contain a path traversal vulnerability in the POST /api/templates/preview endpoint that allows unauthenticated attackers to read arbitrary files. Attackers can supply directory traversal sequences in the templateFile parameter to bypass path restrictions and read sensitive files like credentials and configuration through the JSON response.

CVE-2026-86538 is in VulnCheck's Known Exploited Vulnerabilities catalog (Community), meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw lets an attacker read or write files outside the folders the application is supposed to be restricted to. It affects knowns-dev knowns, which is broadly deployed across essentially every industry.

Staying safe: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable. Check whether any files outside the application's intended directories were read or modified, and review web server logs for unusual "../"-style path patterns in requests.

CVE-2026-89013

dolibarr dolibarr_erp\/crm Incorrect Authorization

dolibarr · dolibarr erp\/crm
0.4% EPSS score - probability of exploitation in the next 30 days
31.2% EPSS percentile - riskier than this share of all scored CVEs
General / Any Organization

Dolibarr 23.0.4 before 24.0.1 contains an authorization bypass vulnerability that allows unauthenticated attackers to read arbitrary files through the document storage endpoints by supplying a crafted hashp parameter value. Attackers can send a request with hashp=shared to skip token validation while satisfying the authorization condition in htdocs/document.php and htdocs/viewimage.php, gaining access to application logs, uploaded business documents, database backups containing password hashes, and files belonging to other multicompany entities.

CVE-2026-89013 is in VulnCheck's Known Exploited Vulnerabilities catalog (Community), meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw gives an attacker a way to compromise the system beyond its intended security boundaries. It affects dolibarr dolibarr erp\/crm, which is broadly deployed across essentially every industry.

Staying safe: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable. More generally: confirm whether dolibarr dolibarr erp\/crm is exposed to the internet or reachable by untrusted users, prioritize patching internet-facing instances first, and check available logs for indicators of prior exploitation before assuming a patch alone closes the incident.

CVE-2026-55040

Microsoft SharePoint Weak Authentication Vulnerability

Microsoft · SharePoint
50.6% EPSS score - probability of exploitation in the next 30 days
98.9% EPSS percentile - riskier than this share of all scored CVEs
General / Any Organization

Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network.

CVE-2026-55040 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw gives an attacker a way to compromise the system beyond its intended security boundaries. It affects Microsoft SharePoint, which is broadly deployed across essentially every industry.

Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… More generally: confirm whether Microsoft SharePoint is exposed to the internet or reachable by untrusted users, prioritize patching internet-facing instances first, and check available logs for indicators of prior exploitation before assuming a patch alone closes the incident.

CVE-2026-76460

Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability

Cisco · Identity Services Engine
0.8% EPSS score - probability of exploitation in the next 30 days
54.6% EPSS percentile - riskier than this share of all scored CVEs
General / Any Organization

Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.

CVE-2026-76460 is in CISA's Known Exploited Vulnerabilities catalog, meaning it isn't a theoretical risk - it has confirmed active exploitation in the wild, not just a high severity score. This specific flaw gives an attacker a way to compromise the system beyond its intended security boundaries. It affects Cisco Identity Services Engine, which is broadly deployed across essentially every industry.

Staying safe: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see guidance) guidance and CISA’s “Forensics Triage Requirements” (see guidance). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's inter… More generally: confirm whether Cisco Identity Services Engine is exposed to the internet or reachable by untrusted users, prioritize patching internet-facing instances first, and check available logs for indicators of prior exploitation before assuming a patch alone closes the incident.