CTIPilot

CVEs

1147 CVEs referenced across all briefs. Click an ID for the full appearance trail.

Total CVEs
1147
2008 – 2026
Recent (30 d)
237
entities with new coverage in window
Distinct sources
290
hosts cited at least once
Total appearances
946
brief-section attributions
Co-occurrence links
4309
entity ↔ entity in same item

Recent coverage

Aggregate mentions per ISO week, last 21 weeks.

By year

  • 20261006
  • 202565
  • 202416
  • 202317
  • 20229
  • 202113
  • 20207
  • 20194
  • 20182
  • 20173
  • 20161
  • 20151
  • 20132
  • 20081
All years 2026 10062025 652024 162023 172022 92021 132020 72019 42018 22017 32016 12015 12013 22008 1
CVETitleFirst seenLast seenLatest coverage
CVE-2026-28324SolarWinds Observability Self-Hosted: unauthenticated RCE via insufficient integrity checks (CVSS 9.8), no confirmed exploitation2026-09-242026-09-24·
CVE-2026-28325SolarWinds Observability Self-Hosted: unauthenticated RCE via deserialization of untrusted data (CVSS 8.8), no confirmed exploitation2026-09-242026-09-24·
CVE-2026-87902WordPress Core: unauthenticated page-template path traversal to conditional RCE, actively exploited within 24h of patch with a named public Nuclei template2026-09-242026-09-24·
CVE-2026-43641Softaculous Virtualizor: unauthenticated OS command injection to root via billing-module hook2026-09-232026-09-232026-09-23
CVE-2026-43642Softaculous Virtualizor: unauthenticated PHP object injection in billing-module hook2026-09-232026-09-232026-09-23
CVE-2026-43643Softaculous Virtualizor: unauthenticated cross-tenant balance write via billing-module hook2026-09-232026-09-232026-09-23
CVE-2026-67276MikroTik RouterOS SSH signature-verification bypass (MikroTrick component); CERT Polska confirms active exploitation2026-09-062026-09-232026-09-06
CVE-2026-67279MikroTik RouterOS SSH pre-auth rekey exec request, unauthenticated managed-file-namespace write2026-09-062026-09-232026-09-06
CVE-2026-85102Check Point Quantum Security Gateway/Spark Firewall, improper certificate validation, unauthenticated RCE in VPN negotiation (CVSS 9.8)2026-09-102026-09-232026-09-10
CVE-2026-93616Check Point Security Management: pre-auth path traversal to arbitrary script execution, exploited as a zero-day since July2026-09-232026-09-232026-09-23
CVE-2026-93952Arista VeloCloud Orchestrator: actively exploited, two release trains still have no fix2026-09-232026-09-232026-09-23
CVE-2026-94127F5 BIG-IP APM: unauthenticated heap overflow in OAuth-profile processing reaches RCE2026-09-232026-09-232026-09-23
CVE-2026-13639Synology DSM, unauthenticated insufficient login-logic entropy, arbitrary file read/write and DoS2026-09-222026-09-222026-09-22
CVE-2026-13673Synology DSM, authenticated LDAP API permission flaw, arbitrary file read/write and DoS2026-09-222026-09-222026-09-22
CVE-2026-13684Synology DSM, unauthenticated SCGI output-encoding bug, arbitrary file read/write and DoS2026-09-222026-09-222026-09-22
CVE-2026-50343Windows Install Service "Dark Elevator" privesc, incomplete fix later closed by CVE-2026-668042026-09-222026-09-222026-09-22
CVE-2026-6205Synology DSM, authenticated Upload API path-control flaw, arbitrary file write and DoS2026-09-222026-09-222026-09-22
CVE-2026-66804Windows Cross Device Service, dangling COM registration reaches SYSTEM privesc (Google Project Zero)2026-09-222026-09-222026-09-22
CVE-2026-7273Zyxel GS1900 Series Switches stack-based buffer overflow, exploited at scale by an actor GreyNoise assesses overlaps Red Heron, CISA KEV2026-09-222026-09-222026-09-22
CVE-2019-0708BlueKeep, Windows RDP pre-auth RCE (2019), exploited by NightEagle/APT-Q-95 for local-account creation and by BlueMoon-adjacent chains historically2026-09-212026-09-212026-09-21
CVE-2020-0688Microsoft Exchange Server post-auth RCE via ViewState (2020), exploit component bundled into NightEagle/APT-Q-95's GhostContainer Exchange backdoor2026-09-212026-09-212026-09-21
CVE-2020-1472ZeroLogon, Netlogon privilege escalation; chained by Cl0p in South Staffordshire Water 2020-2022 intrusion (cited in ICO 2026-05-11 enforcement)2026-05-122026-09-21·
CVE-2025-24799GLPI unauthenticated SQL injection via the inventory endpoint, exploited by an operator associated with The Gentlemen RaaS for initial access2026-09-212026-09-212026-09-21
CVE-2026-71133Oracle Access Manager (Authentication Engine), unauthenticated flaw over HTTP, CVSS 10.0, September 2026 CSPU2026-09-202026-09-202026-09-20
CVE-2026-83020Oracle Platform Security for Java (centralized third-party jars), unauthenticated flaw over HTTP, CVSS 10.0, September 2026 CSPU2026-09-202026-09-202026-09-20
CVE-2026-83021Oracle WebLogic Server (Web Container), unauthenticated flaw over HTTP, CVSS 10.0, September 2026 CSPU2026-09-202026-09-202026-09-20
CVE-2026-83059Oracle Internet Directory (OID LDAP Server), unauthenticated flaw over LDAP, CVSS 10.0, September 2026 CSPU2026-09-202026-09-202026-09-20
CVE-2026-83099Oracle Forms (Forms Services), unauthenticated flaw over HTTP, CVSS 10.0, September 2026 CSPU2026-09-202026-09-202026-09-20
CVE-2026-87230Oracle Hyperion Financial Management (Security), unauthenticated flaw over HTTP, CVSS 10.0, September 2026 CSPU2026-09-202026-09-202026-09-20
CVE-2025-39682Linux Kernel kTLS receive-path zero-length record logic error, CISA KEV 2026-09-18, network-reachable with kernel TLS receive offload2026-09-192026-09-192026-09-19
CVE-2025-39964Linux Kernel AF_ALG crypto-socket concurrent-write race condition, CISA KEV 2026-09-18, local2026-09-192026-09-192026-09-19
CVE-2026-53266Linux Kernel netfilter bridge ebtables SNAT ARP-rewrite out-of-bounds write, CISA KEV 2026-09-18, local2026-09-192026-09-192026-09-19
CVE-2026-81642NLnet Labs Unbound DNSSEC-validator self-referencing compression-pointer heap overflow, RCE possible (CVSS4.0 9.1)2026-09-192026-09-192026-09-19
CVE-2026-82717NLnet Labs Unbound CNAME-synthesis heap corruption during upstream response processing, RCE possible under specific builds (CVSS4.0 8.4)2026-09-192026-09-192026-09-19
CVE-2026-20130Cisco Identity Services Engine CWE-class-grouped bundle CVE from the Sept 2026 hardening release (CVSS 10.0), not reported exploited2026-09-172026-09-182026-09-17
CVE-2026-20192Cisco Identity Services Engine CWE-class-grouped bundle CVE from the Sept 2026 hardening release (CVSS 10.0), not reported exploited2026-09-172026-09-182026-09-17
CVE-2026-20242Cisco Secure Firewall Management Center Java deserialization RCE via External Database Access allowlist (CVSS 9.8), not reported exploited2026-08-042026-09-182026-08-04
CVE-2026-20324Cisco Secure Firewall Management Center sftunnel arbitrary file write to root (CVSS 9.9), requires existing low-privilege device credentials, not reported exploited2026-08-042026-09-182026-08-04
CVE-2026-76423Cisco Identity Services Engine sibling unauthenticated API authentication bypass (CVSS 10.0), not yet confirmed exploited2026-09-172026-09-182026-09-17
CVE-2026-76460Cisco Identity Services Engine unauthenticated API authentication bypass to root (CVSS 10.0), confirmed exploited, found via a TAC support case2026-09-172026-09-182026-09-17
CVE-2026-87886Acronis Backup plugin for cPanel & WHM/Plesk local privilege escalation via insecure default permissions (CVSS 7.8), CISA KEV-listed 2026-09-16, exploitation basis is a single customer report2026-09-182026-09-182026-09-18
CVE-2026-91843Check Point Security Management/Multi-Domain Security Management/Log Server unauthenticated stack overflow in login process to root RCE (CVSS 9.8), no confirmed exploitation, LivePatch fix2026-09-182026-09-182026-09-18
CVE-2026-58704Google Pixel cellular-modem zero-click privilege escalation, exploited in limited targeted attacks, CISA KEV 2026-09-162026-09-172026-09-172026-09-17
CVE-2026-85706GitLab CE/EE unauthenticated path traversal in repository commits API, arbitrary file read, CVSS 10.02026-09-122026-09-162026-09-12
CVE-2026-87719GitLab EE insecure GraphQL-subscription deserialization, Advanced Search config/credential exposure via Duo Chat (CVSS 9.9), same 19.3.2 release as CVE-2026-857062026-09-122026-09-162026-09-12
CVE-2026-20353Cisco Secure Email Gateway / Secure Email and Web Manager, uncontrolled resource consumption grouping, September 2026 hardening release, not reported exploited2026-09-152026-09-152026-09-15
CVE-2026-76440Cisco Secure Email Gateway / Secure Email and Web Manager, path-traversal grouping, September 2026 hardening release, not reported exploited2026-09-152026-09-152026-09-15
CVE-2026-76441Cisco Secure Email Gateway / Secure Email and Web Manager, improper access control grouping, September 2026 hardening release, not reported exploited2026-09-152026-09-152026-09-15
CVE-2026-76442Cisco Secure Email Gateway / Secure Email and Web Manager, input-validation grouping, September 2026 hardening release, not reported exploited2026-09-152026-09-152026-09-15
CVE-2026-76443Cisco Secure Email Gateway / Secure Email and Web Manager, second injection-class grouping, September 2026 hardening release, distinct from the exploited CVE-2026-764612026-09-152026-09-152026-09-15
CVE-2026-76461Cisco Secure Email Gateway, unauthenticated SQL injection in email parsing reaches root command execution, exploited, CISA KEV (3-day deadline)2026-09-152026-09-152026-09-15
CVE-2026-82329JFrog Artifactory auth-bypass, CVSS 9.8, now confirmed under active exploitation (watchTowr, NCSC-CH); attackers minting admin tokens via a default 'phantom' join key2026-09-012026-09-152026-09-01
CVE-2026-20079CVE-2026-20079, Cisco Secure Firewall Management Center web interface: unauthenticated authentication bypass to root via a boot-time csm_processes session (CVSS 10.0, CWE-288); disclosed 2026-03-04 with no fix, per-train hot fixes added to the advisory 2026-07-31; Cisco reports no known malicious use, VulnCheck built a working exploit2026-08-042026-09-132026-08-04
CVE-2026-20316CVE-2026-20316; Cisco Secure Firewall Management Center ships a static low-privilege account in its web interface, and Cisco confirms exploitation has been ongoing2026-07-302026-09-132026-07-30
CVE-2026-85046Google Chrome V8 type confusion, actively exploited via a crafted HTML page2026-09-042026-09-132026-09-10 +1 more
CVE-2026-85880Windows ALPC heap-based buffer overflow EoP / AppContainer sandbox escape to SYSTEM (CVSS 7.8), actively exploited zero-day, CISA KEV 2026-09-08, legacy line (Windows 10, Server 2012-2022)2026-09-092026-09-132026-09-10 +1 more
CVE-2026-87491Google Chrome V8 out-of-bounds write, exploited in the wild, patched in Chrome 153 (seventh exploited Chrome zero-day of 2026)2026-09-102026-09-132026-09-10
CVE-2026-88765GitLab EE, buffer overflow in Advanced Search Unicode-conversion wrapper reachable via crafted Git project import (CVSS 8.5)2026-09-122026-09-132026-09-12
CVE-2026-15409SonicWall SMA1000 Work Place unauthenticated SSRF (CVSS 10.0, actively exploited)2026-07-142026-09-122026-07-14
CVE-2026-42016JFrog Artifactory token scope-validation flaw chained with CVE-2026-42018 into admin takeover, confirmed exploited2026-09-122026-09-122026-09-12
CVE-2026-42018JFrog Artifactory anonymous-user token exposure chained with CVE-2026-42016 into admin takeover, confirmed exploited2026-09-122026-09-122026-09-12
CVE-2026-84869ConnectWise ScreenConnect client file-transfer authorization flaw, worm-like exploitation from 20 August 2026, patched 26.6.52026-09-122026-09-122026-09-12
CVE-2026-12645Ivanti Neurons for ITSM, authenticated missing-authorization escalation to RCE (CVSS 9.9)2026-09-112026-09-112026-09-11
CVE-2026-12646Ivanti Neurons for ITSM, authenticated missing-authorization escalation to RCE (CVSS 9.9)2026-09-112026-09-112026-09-11
CVE-2026-12647Ivanti Neurons for ITSM, authenticated missing-authorization escalation to RCE (CVSS 9.9)2026-09-112026-09-112026-09-11
CVE-2026-12648Ivanti Neurons for ITSM, authenticated deserialization RCE (CVSS 8.8)2026-09-112026-09-112026-09-11
CVE-2026-12650Ivanti Neurons for ITSM, authenticated deserialization RCE (CVSS 9.9)2026-09-112026-09-112026-09-11
CVE-2026-12651Ivanti Neurons for ITSM, authenticated deserialization RCE (CVSS 8.8)2026-09-112026-09-112026-09-11
CVE-2026-12744Ivanti Neurons for ITSM, unauthenticated deserialization RCE (CVSS 9.8), September 2026 security update2026-09-112026-09-112026-09-11
CVE-2026-12745Ivanti Neurons for ITSM, unauthenticated deserialization RCE (CVSS 9.8), September 2026 security update2026-09-112026-09-112026-09-11
CVE-2026-18851Ivanti Endpoint Manager Mobile (EPMM), authenticated missing-authorization escalation to admin (CVSS 8.8)2026-09-112026-09-112026-09-11
CVE-2026-67277MikroTik RouterOS bandwidth-test unauthenticated memory disclosure / DoS2026-09-062026-09-112026-09-06
CVE-2026-83527Ivanti Sentry, unauthenticated authentication bypass to admin access (CVSS 8.1)2026-09-112026-09-112026-09-11
CVE-2020-6287RECON, SAP NetWeaver AS Java LM Configuration Wizard unauthenticated admin-account creation (2020); cited by Onapsis as historical precedent for 72-hour SAP patch reverse-engineering2026-09-102026-09-10·
CVE-2021-42278noPac, Active Directory sAMAccountName spoofing (2021); cited by GreyNoise as one of three domain-admin escalation paths in the PaperCut AI-orchestrated campaign2026-09-102026-09-10·
CVE-2021-42287noPac, Active Directory KDC ticket forging companion flaw (2021); cited by GreyNoise as one of three domain-admin escalation paths in the PaperCut AI-orchestrated campaign2026-09-102026-09-10·
CVE-2025-25249Fortinet FortiOS/FortiSwitchManager CAPWAP heap overflow, CISA KEV 2026-09-09, actively exploited since July 2026 via the PivotC2 RAT2026-09-102026-09-102026-09-10
CVE-2025-31324SAP NetWeaver Visual Composer unauthenticated file upload (2025), Mandiant's named most-exploited CVE of 2025; cited by Onapsis as historical precedent for OVERPASS/S4GET's severity2026-09-102026-09-10·
CVE-2026-19489Citrix NetScaler ADC/Gateway, memory overflow leading to unpredictable behaviour or denial of service; requires SIP ALG enabled on a Large Scale NAT group. CVSS 8.8.2026-08-202026-09-102026-08-20
CVE-2026-19490Citrix NetScaler ADC/Gateway, authentication bypass using an alternate path on Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual servers; CVSS v4.0 9.3, no exploitation observed as of 2026-08-19.2026-08-202026-09-102026-08-20
CVE-2026-44756SAP OVERPASS, unauthenticated memory-corruption RCE in shared SAP kernel Extended Passport processing (CVSS 10.0), September 2026 Patch Day2026-09-102026-09-102026-09-10
CVE-2026-58240SAP S4GET, unauthenticated Message Server trust-bypass RCE (CVSS 9.8), September 2026 Patch Day2026-09-102026-09-102026-09-10
CVE-2026-81578PaperCut NG/MF, authentication bypass in the web management interface (Tapestry request-routing confusion), chained to CVE-2026-82078 for pre-auth RCE, exploited before a patch existed2026-08-292026-09-102026-08-29
CVE-2026-82078PaperCut NG/MF, unsafe dynamic class loading in the database connector, reached via CVE-2026-81578's config rewrite to achieve arbitrary Java bytecode execution2026-08-292026-09-102026-08-29
CVE-2026-85103Check Point Quantum Security Gateway/Management Server, unauthenticated heap overflow in VPN certificate ASN.1 decoding (CVSS 9.8)2026-09-102026-09-102026-09-10
CVE-2026-81963Windows Update Stack link-following EoP to SYSTEM (CVSS 7.8), actively exploited zero-day, CISA KEV 2026-09-08, newest builds (Server 2025, Windows 11)2026-09-092026-09-092026-09-09
CVE-2026-75650StyleSmuggler, unauthenticated CVSS 10.0 RCE in Magento/Adobe Commerce via template-engine injection, exploited before Adobe's hotfix existed2026-09-082026-09-082026-09-08
CVE-2026-86206N-able N-central, internal API access-control gap (part of the September 2026 auth-bypass chain)2026-09-072026-09-072026-09-07
CVE-2026-86207N-able N-central, authentication bypass by primary weakness reaching internal APIs2026-09-072026-09-072026-09-07
CVE-2026-86218N-able N-central, pre-authentication RCE zero-day, confirmed exploited in the wild2026-09-072026-09-072026-09-07
CVE-2026-61408Dell Secure Connect Gateway 5.0, flaw reported alongside CVE-2026-61410 and CVE-2026-61409 (DSA-2026-382)2026-09-062026-09-06·
CVE-2026-61409Dell Secure Connect Gateway 5.0, OS command injection reported alongside CVE-2026-61410 (DSA-2026-382)2026-09-062026-09-062026-09-06
CVE-2026-61410Dell Secure Connect Gateway 5.0, missing authorization allowing unauthenticated remote command execution via a single crafted request (DSA-2026-382)2026-09-062026-09-062026-09-06
CVE-2026-63077JetBrains TeamCity On-Premises, unauthenticated deserialization RCE via the agent-polling protocol (CVSS 9.8); added to the CISA KEV catalog 2026-08-05 on evidence of active exploitation, reversing the vendor's no-known-exploitation position at disclosure2026-07-292026-09-062026-09-06 +1 more
CVE-2026-67278MikroTik RouterOS X.509 malformed-signature acceptance enabling TLS impersonation2026-09-062026-09-062026-09-06
CVE-2026-67281MikroTik RouterOS WebFig /jsproxy unauthenticated file read via stale session pointer2026-09-062026-09-062026-09-06
CVE-2026-80172Dell Secure Connect Gateway 5.0, insufficient verification of data authenticity; an unauthenticated attacker replays a captured request indefinitely to mint ADMIN access and refresh tokens (DSA-2026-382)2026-09-062026-09-062026-09-06
CVE-2026-80238Dell Secure Connect Gateway 5.0, execution with unnecessary privileges; exposed Docker socket yields host root from a low-privileged SSH operator and an orchestrator-container escape (DSA-2026-382)2026-09-062026-09-062026-09-06
CVE-2026-86060MikroTik RouterOS SSH crafted-username privilege escalation (MikroTrick component); CERT Polska confirms active exploitation2026-09-062026-09-062026-09-06
CVE-2026-43284Dirty Frag, Linux kernel xfrm-ESP page-cache write primitive, LPE (ITW, PoC public)2026-05-092026-09-052026-05-09
CVE-2026-43500Dirty Frag, Linux kernel RxRPC page-cache write primitive, LPE chain (ITW, patch pending)2026-05-092026-09-052026-05-09
CVE-2026-46300Fragnesia, Linux kernel xfrm ESP-in-TCP LPE (PoC public)2026-05-152026-09-052026-05-15
CVE-2026-58400GeoNetwork opensource: Saxon XSLT processor configured without secure processing, reachable via formatter upload chain to unauthenticated RCE2026-09-052026-09-052026-09-05
CVE-2026-63219GeoNetwork opensource: unauthenticated formatter-upload endpoint chained to unauthenticated RCE via unsafe Saxon XSLT processing2026-09-052026-09-052026-09-05
CVE-2026-19766HPE Networking Fabric Composer adjacent-network auth bypass (CVSS 9.6)2026-09-042026-09-042026-09-04
CVE-2026-20212Cisco Nexus 9000 Series Silicon One S1HAL unauthenticated root RCE (CVSS 9.8)2026-09-042026-09-042026-09-04
CVE-2026-73700HPE Networking Fabric Composer authenticated stored XSS (CVSS 9.0)2026-09-042026-09-042026-09-04
CVE-2026-73701HPE Networking Fabric Composer unauthenticated privileged RCE (CVSS 9.0)2026-09-042026-09-042026-09-04
CVE-2026-73749HPE ArubaOS-CX unauthenticated buffer-overflow RCE (CVSS 9.8)2026-09-042026-09-042026-09-04
CVE-2026-73752HPE ArubaOS-CX unauthenticated adjacent-network arbitrary file write (CVSS 8.8)2026-09-042026-09-042026-09-04
CVE-2026-73778HPE ArubaOS-CX predictable factory-default admin password (CVSS 8.1)2026-09-042026-09-042026-09-04
CVE-2026-73781HPE ArubaOS-CX authenticated stored XSS, named in BleepingComputer's account of HPE's bulletin but absent from NCSC-NL's structured mirror of the same bulletin; referenced only as an example of the source-count discrepancy, not independently confirmed2026-09-042026-09-04·
CVE-2026-73782HPE ArubaOS-CX unauthenticated format-string CLI flaw (CVSS 8.1)2026-09-042026-09-042026-09-04
CVE-2026-76657HPE Networking Fabric Composer API auth-bypass to admin (CVSS 10.0)2026-09-042026-09-042026-09-04
CVE-2026-76658HPE Networking Fabric Composer SSH daemon unauthenticated RCE (CVSS 10.0)2026-09-042026-09-042026-09-04
CVE-2026-85042Google Chrome DevTools use-after-free, High severity, no reported exploitation2026-09-042026-09-042026-09-04
CVE-2026-85043Google Chrome Network incomplete cleanup, High severity, no reported exploitation2026-09-042026-09-042026-09-04
CVE-2026-85044Google Chrome Mobile use-of-released-resource, Medium severity, no reported exploitation2026-09-042026-09-042026-09-04
CVE-2026-85045Google Chrome V8 race condition, High severity, no reported exploitation2026-09-042026-09-042026-09-04
CVE-2026-85047Google Chrome Transactions Platform improper input validation, Medium severity, no reported exploitation2026-09-042026-09-042026-09-04
CVE-2026-85048Google Chrome Compositing use-after-free, High severity, no reported exploitation2026-09-042026-09-042026-09-04
CVE-2026-85049Google Chrome Skia use-after-free, High severity, no reported exploitation2026-09-042026-09-042026-09-04
CVE-2026-85050Google Chrome WebGL out-of-bounds write, High severity, no reported exploitation2026-09-042026-09-042026-09-04
CVE-2026-85051Google Chrome Compositing type confusion, High severity, no reported exploitation2026-09-042026-09-042026-09-04
CVE-2026-85052Google Chrome CrashReporting out-of-bounds read, High severity, no reported exploitation2026-09-042026-09-042026-09-04
CVE-2026-85053Google Chrome CacheStorage improper resource exposure, High severity, no reported exploitation2026-09-042026-09-042026-09-04
CVE-2026-0768Langflow, code-parameter code injection RCE in the validate endpoint, renewed mass exploitation since August 20262026-09-032026-09-032026-09-03
CVE-2026-19592OpenAI Codex CLI, GitSpawn class, core.fsmonitor-adjacent helper mechanism running outside the command sandbox without user approval2026-09-032026-09-032026-09-03
CVE-2026-59822BerriAI LiteLLM, MCP OAuth2-passthrough fallback auth bypass, CISA KEV 2026-09-022026-09-032026-09-032026-09-03
CVE-2026-71963Hermes Agent (Nous Research), GitSpawn class, git-config-triggered command execution; VulnCheck-assigned, unpublished in NVD/MITRE/CIRCL as of 2026-09-032026-09-032026-09-03·
CVE-2026-72718Goose (AI coding agent), GitSpawn class, core.fsmonitor git-config command execution via `goose review`2026-09-032026-09-032026-09-03
CVE-2026-83548SonicWall SMA1000; pre-auth SSRF in Work Place interface, actively exploited2026-09-032026-09-032026-09-03
CVE-2026-83549SonicWall SMA1000, post-auth OS command injection in Appliance Management Console, actively exploited2026-09-032026-09-032026-09-03
CVE-2026-9586Sangoma Switchvox, unauthenticated SQL injection to RCE via PostgreSQL COPY TO PROGRAM, CISA KEV 2026-09-022026-09-032026-09-032026-09-03
CVE-2026-19318WatchGuard Fireware OS, third pre-auth stack overflow in iked (IKE_AUTH/EAP-MSCHAPv2); requires IKE payload diagnostic logging enabled; CVSS 9.3, no exploitation reported2026-08-312026-09-022026-08-31
CVE-2026-78174WatchGuard Dimension, session hijack via unredacted session tokens in web UI diagnostic log; low-privileged Administrator can extract a Super Administrator's session; CVSS 9.3, no exploitation reported2026-08-312026-09-022026-08-31
CVE-2026-42271BerriAI LiteLLM MCP test endpoints command injection to host RCE (CVSS 8.7), CISA KEV, actively exploited; unauthenticated when chained with CVE-2026-487102026-06-092026-09-012026-08-31 +1 more
CVE-2026-62911Microsoft Exchange Server MRSProxy, missing channel-binding check, authentication bypass by capture-replay; public exploit code published 27 August 20262026-08-292026-09-012026-08-29
CVE-2026-13086WatchGuard Fireware OS Mobile Security epm service - pre-auth stack overflow yielding root RCE2026-08-312026-08-312026-08-31
CVE-2026-19313WatchGuard Fireware OS iked - pre-auth heap buffer overflow yielding RCE, patched 2026-08-272026-08-312026-08-312026-08-31
CVE-2026-19315WatchGuard Fireware OS iked - pre-auth type confusion via duplicated EAP payload in IKE_AUTH, yielding RCE2026-08-312026-08-312026-08-31
CVE-2026-48710Starlette/FastAPI host-header auth bypass (BadHost)2026-05-302026-08-312026-08-31 +2 more
CVE-2026-49869Kestra workflow orchestrator - critical pre-auth login-bypass vulnerability, exploited to reach worker-side shell execution2026-08-312026-08-312026-08-31
CVE-2026-81851WatchGuard Fireware OS iked - heap-based buffer overflow yielding denial of service (BSI CERT-Bund WID-SEC-2026-3068, same advisory family as CVE-2026-19313/19315/13086, not itemised in WatchGuard's own blog roundup)2026-08-312026-08-31·
CVE-2026-21962Oracle HTTP Server / WebLogic Server Proxy Plug-in - unauthenticated access-control bypass, CVSS 10.0; CISA KEV 2026-08-24, exploited since January 20262026-08-302026-08-302026-08-30
CVE-2026-60004Gitea diffpatch endpoint - Git-hook code injection, command execution as the service account, CVSS 9.8; CISA KEV 2026-08-25, fixed in 1.27.12026-08-302026-08-302026-08-30
CVE-2023-27350PaperCut NG/MF, 2023 authentication-bypass RCE mass-exploited by ransomware operators; cited as historical background by Rapid7's 2026-08-28 analysis of the unrelated CVE-2026-81578/82078 chain2026-08-292026-08-29·
CVE-2026-18885ServiceNow AI Platform, unauthenticated GraphQL Composite Data API code injection (CVSS4.0 10.0)2026-08-292026-08-292026-08-29
CVE-2026-18886ServiceNow Now Platform, unauthenticated access-control bypass in the system-configuration image-upload processor (CVSS4.0 10.0)2026-08-292026-08-292026-08-29
CVE-2026-6876ServiceNow Now Platform, sandbox escape, same vulnerability class as CVE-2026-6875 (CVSS4.0 8.7)2026-08-292026-08-292026-08-29
CVE-2026-74820ServiceNow AI Platform, unauthenticated dynamic-schema SQL injection (CVSS4.0 10.0)2026-08-292026-08-292026-08-29
CVE-2023-49105A 2023 ownCloud auth-bypass CVE re-enters CISA KEV because Hunt.io caught a suspected Chinese-speaking operator's open staging server using it to steal nuclear-research and naval-contractor data from two Philippine organisations2026-08-282026-08-282026-08-28
CVE-2024-28000A 2023 ownCloud auth-bypass CVE re-enters CISA KEV because Hunt.io caught a suspected Chinese-speaking operator's open staging server using it to steal nuclear-research and naval-contractor data from two Philippine organisations2026-08-282026-08-282026-08-28
CVE-2025-41450Claroty Team82: Danfoss AK-SM 800A refrigeration system managers, undocumented 'code-of-the-day' authentication bypass and post-authentication command-injection RCE across roughly 2,765 internet-exposed devices2026-08-282026-08-282026-08-28
CVE-2025-41451Claroty Team82: Danfoss AK-SM 800A refrigeration system managers, undocumented 'code-of-the-day' authentication bypass and post-authentication command-injection RCE across roughly 2,765 internet-exposed devices2026-08-282026-08-282026-08-28
CVE-2025-41452Claroty Team82: Danfoss AK-SM 800A refrigeration system managers, undocumented 'code-of-the-day' authentication bypass and post-authentication command-injection RCE across roughly 2,765 internet-exposed devices2026-08-282026-08-282026-08-28
CVE-2025-49113Roundcube Crypt_GPG_Engine PHP deserialization RCE - chained by UNK_MassTraction after CVE-2024-42009 XSS (Proofpoint)2026-07-092026-08-282026-08-12 +1 more
CVE-2026-12537Google Gemini CLI GitHub Actions harness, trust-boundary bypass; fixed gemini-cli 0.39.1 / run-gemini-cli 0.1.22, published 2026-04-242026-08-102026-08-282026-08-10
CVE-2026-15981miniOrange's SAML2Core library ships the same openssl_verify() tri-state authentication bypass across both its WordPress and Joomla SAML SSO products, one vendor code defect, two ecosystems, exploitation already attempted against the WordPress line2026-08-282026-08-282026-08-28
CVE-2026-19912Kaltura mwEmbed/html5lib video player: unauthenticated RCE and arbitrary file read via an undocumented ServiceUrl parameter, no vendor response, no patch, 630+ exposed instances found by the discoverer2026-08-282026-08-282026-08-28
CVE-2026-19913Kaltura mwEmbed/html5lib video player: unauthenticated RCE and arbitrary file read via an undocumented ServiceUrl parameter, no vendor response, no patch, 630+ exposed instances found by the discoverer2026-08-282026-08-282026-08-28
CVE-2026-20742Copeland XWEB Pro refrigeration controller, OS command injection (Claroty Team82 disclosure)2026-08-282026-08-282026-08-28
CVE-2026-20764Copeland XWEB Pro refrigeration controller, OS command injection (Claroty Team82 disclosure)2026-08-282026-08-282026-08-28
CVE-2026-20902Copeland XWEB Pro refrigeration controller, OS command injection (Claroty Team82 disclosure)2026-08-282026-08-282026-08-28
CVE-2026-20910Copeland XWEB Pro refrigeration controller, OS command injection (Claroty Team82 disclosure)2026-08-282026-08-282026-08-28
CVE-2026-21273Adobe ColdFusion 2025/2023, privilege escalation via input validation (APSB26-90)2026-08-282026-08-28·
CVE-2026-21389Copeland XWEB Pro refrigeration controller, OS command injection (Claroty Team82 disclosure)2026-08-282026-08-282026-08-28
CVE-2026-21653Johnson Controls C-CURE 9000 / victor: unauthenticated adjacent-network deserialization RCE on physical access-control application servers reaches connected security-workstation clients too (CVE-2026-21655, CVSS 9.6)2026-08-282026-08-282026-08-28
CVE-2026-21655Johnson Controls C-CURE 9000 / victor: unauthenticated adjacent-network deserialization RCE on physical access-control application servers reaches connected security-workstation clients too (CVE-2026-21655, CVSS 9.6)2026-08-282026-08-282026-08-28
CVE-2026-21718Claroty Team82: 23 vulnerabilities in Copeland XWEB Pro supervisory refrigeration controllers chain to unauthenticated root RCE; a deterministic admin password derived from the device's own MAC address is one of two independent pre-auth paths2026-08-282026-08-282026-08-28
CVE-2026-23702Copeland XWEB Pro refrigeration controller, OS command injection (Claroty Team82 disclosure)2026-08-282026-08-282026-08-28
CVE-2026-24452Copeland XWEB Pro refrigeration controller, OS command injection (Claroty Team82 disclosure)2026-08-282026-08-282026-08-28
CVE-2026-24517Copeland XWEB Pro refrigeration controller, OS command injection (Claroty Team82 disclosure)2026-08-282026-08-282026-08-28
CVE-2026-24663Copeland XWEB Pro refrigeration controller, OS command injection (Claroty Team82 disclosure)2026-08-282026-08-282026-08-28
CVE-2026-24689Copeland XWEB Pro refrigeration controller, OS command injection (Claroty Team82 disclosure)2026-08-282026-08-282026-08-28
CVE-2026-24695Copeland XWEB Pro refrigeration controller, OS command injection (Claroty Team82 disclosure)2026-08-282026-08-282026-08-28
CVE-2026-25037Copeland XWEB Pro refrigeration controller, OS command injection (Claroty Team82 disclosure)2026-08-282026-08-282026-08-28
CVE-2026-25085Claroty Team82: 23 vulnerabilities in Copeland XWEB Pro supervisory refrigeration controllers chain to unauthenticated root RCE; a deterministic admin password derived from the device's own MAC address is one of two independent pre-auth paths2026-08-282026-08-282026-08-28
CVE-2026-25105Copeland XWEB Pro refrigeration controller, OS command injection (Claroty Team82 disclosure)2026-08-282026-08-282026-08-28
CVE-2026-25109Copeland XWEB Pro refrigeration controller, OS command injection (Claroty Team82 disclosure)2026-08-282026-08-282026-08-28
CVE-2026-25111Copeland XWEB Pro refrigeration controller, OS command injection (Claroty Team82 disclosure)2026-08-282026-08-282026-08-28
CVE-2026-25195Copeland XWEB Pro refrigeration controller, OS command injection (Claroty Team82 disclosure)2026-08-282026-08-282026-08-28
CVE-2026-25196Copeland XWEB Pro refrigeration controller, OS command injection (Claroty Team82 disclosure)2026-08-282026-08-282026-08-28
CVE-2026-25721Copeland XWEB Pro refrigeration controller, OS command injection (Claroty Team82 disclosure)2026-08-282026-08-282026-08-28
CVE-2026-27302Adobe August 2026 Patch Day: ColdFusion ships a CVSS 10.0 unauthenticated OS command injection, and Campaign Classic ships two more unauthenticated CVSS 10.0 flaws in the same release2026-08-282026-08-282026-08-28
CVE-2026-32475Elementor Pro (WordPress, ~6M installs): unauthenticated arbitrary file upload to RCE via a validator/mover desynchronization in the Forms File Upload field (CVE-2026-32475, CVSS 9.0)2026-08-282026-08-282026-08-28
CVE-2026-34265SAP NetWeaver Application Server ABAP / ABAP Platform kernel, logical errors in DIAG protocol parsing allow an unauthenticated attacker to generate memory corruptions, CVSS 9.8, SAP Security Note 3714806.2026-08-122026-08-282026-08-12
CVE-2026-34496Johnson Controls C-CURE 9000 / victor: unauthenticated adjacent-network deserialization RCE on physical access-control application servers reaches connected security-workstation clients too (CVE-2026-21655, CVSS 9.6)2026-08-282026-08-282026-08-28
CVE-2026-42945NGINX ngx_http_rewrite_module heap buffer overflow (earlier of two May 2026 disclosures); exploitation attempts per NCSC-NL; § 7 drop (primary 2026-05-18 out-of-window)2026-05-152026-08-282026-08-12 +2 more
CVE-2026-44758SAP Manufacturing Integration and Intelligence code injection reaching arbitrary OS command execution with a higher privilege requirement, CVSS 9.1, SAP Security Note 3758900.2026-08-122026-08-282026-08-12
CVE-2026-44772SAP Manufacturing Integration and Intelligence code injection reaching arbitrary OS command execution, CVSS 9.9, SAP Security Note 3765948; the patch removes the vulnerable servlet component.2026-08-122026-08-282026-08-12
CVE-2026-48273Adobe August 2026 Patch Day: ColdFusion ships a CVSS 10.0 unauthenticated OS command injection, and Campaign Classic ships two more unauthenticated CVSS 10.0 flaws in the same release2026-08-282026-08-282026-08-28
CVE-2026-48362Adobe August 2026 Patch Day: ColdFusion ships a CVSS 10.0 unauthenticated OS command injection, and Campaign Classic ships two more unauthenticated CVSS 10.0 flaws in the same release2026-08-282026-08-282026-08-28
CVE-2026-48381Adobe August 2026 Patch Day: ColdFusion ships a CVSS 10.0 unauthenticated OS command injection, and Campaign Classic ships two more unauthenticated CVSS 10.0 flaws in the same release2026-08-282026-08-282026-08-28
CVE-2026-48440Adobe ColdFusion 2025/2023, heap-based buffer overflow (APSB26-90)2026-08-282026-08-28·
CVE-2026-53362Linux kernel IPv6 UDP fraggap accounting bug (CVE-2026-53362) added to CISA KEV, an unprivileged local heap overflow via MSG_SPLICE_PAGES, no exploitation narrative published2026-08-282026-08-282026-08-28
CVE-2026-54316Anthropic Claude Code Action, CI command-validation bypass (quote-stripping before inspection; read-only allowlist exempt from path checks); fixed claude-code 2.1.163, published 2026-06-132026-08-102026-08-282026-08-10
CVE-2026-58231SAP Commerce Cloud Data Hub Adapter, unauthenticated improper-authorization flaw reaching arbitrary code execution (CVSS 10.0), fixed in SAP Security Note 3771065 and requiring a rebuild and redeploy. Exploitation attempts against honeypot sensors recorded by Defused on 2026-08-14, three days after patch day, with no public proof-of-concept; NCSC-NL advisory NCSC-2026-0302 (2026-08-15) records active scanning for vulnerable systems.2026-08-122026-08-282026-08-12
CVE-2026-58243SAP ABAP Development Tools SQL Console; host expressions in SQL statements let a low-privileged authenticated user run unauthorized database operations, CVSS 8.8, SAP Security Note 3772411.2026-08-122026-08-282026-08-12
CVE-2026-59109Zalktis (Latvian accounting software): unauthenticated SQL injection reachable by any PEPPOL/UBL e-invoice sender, no account, no network position, just a routine bookkeeping import (CVE-2026-59109)2026-08-282026-08-282026-08-28
CVE-2026-59310VMSA-2026-0006, VMware vCenter Syslog directory traversal to remote code execution; confirmed actively exploited from 2026-08-03, 361 victim IP addresses across 47 countries2026-07-302026-08-282026-07-30
CVE-2026-61979miniOrange's SAML2Core library ships the same openssl_verify() tri-state authentication bypass across both its WordPress and Joomla SAML SSO products, one vendor code defect, two ecosystems, exploitation already attempted against the WordPress line2026-08-282026-08-282026-08-28
CVE-2026-64796Sourcerer for Joomla: unauthenticated RCE exploited in the wild since before a working fix existed; the vendor's first two patches did not close it, and the CVE was re-scoped in place to widen the affected range2026-08-282026-08-282026-08-28
CVE-2026-65617Hugging Face intrusion update; the sandbox escape was a chain of previously unknown JFrog Artifactory flaws, now patched, and the models also used publicly exposed credentials on four third-party services2026-07-212026-08-282026-07-21
CVE-2026-65921Hugging Face intrusion update; the sandbox escape was a chain of previously unknown JFrog Artifactory flaws, now patched, and the models also used publicly exposed credentials on four third-party services2026-07-212026-08-282026-07-21
CVE-2026-65922Hugging Face intrusion update; the sandbox escape was a chain of previously unknown JFrog Artifactory flaws, now patched, and the models also used publicly exposed credentials on four third-party services2026-07-212026-08-282026-07-21
CVE-2026-65923Hugging Face intrusion update; the sandbox escape was a chain of previously unknown JFrog Artifactory flaws, now patched, and the models also used publicly exposed credentials on four third-party services2026-07-212026-08-282026-07-21
CVE-2026-65924Hugging Face intrusion update; the sandbox escape was a chain of previously unknown JFrog Artifactory flaws, now patched, and the models also used publicly exposed credentials on four third-party services2026-07-212026-08-282026-07-21
CVE-2026-65925Hugging Face intrusion update; the sandbox escape was a chain of previously unknown JFrog Artifactory flaws, now patched, and the models also used publicly exposed credentials on four third-party services2026-07-212026-08-282026-07-21
CVE-2026-66014Hugging Face intrusion update; the sandbox escape was a chain of previously unknown JFrog Artifactory flaws, now patched, and the models also used publicly exposed credentials on four third-party services2026-07-212026-08-282026-07-21
CVE-2026-66015Hugging Face intrusion update; the sandbox escape was a chain of previously unknown JFrog Artifactory flaws, now patched, and the models also used publicly exposed credentials on four third-party services2026-07-212026-08-282026-07-21
CVE-2026-66018Hugging Face intrusion update; the sandbox escape was a chain of previously unknown JFrog Artifactory flaws, now patched, and the models also used publicly exposed credentials on four third-party services2026-07-212026-08-282026-07-21
CVE-2026-66384JFrog Artifactory: authenticated Docker-cache path traversal (CVE-2026-66384) added to CISA KEV, a CI/CD artifact-store write primitive with no published exploitation narrative2026-08-282026-08-282026-08-28
CVE-2026-67365iCagenda Calendar module for Joomla: unauthenticated SQL injection via com_ajax needs no session, token or account (CVE-2026-67365, CVSS 9.2), and the vulnerable module's own version number does not track the package version2026-08-282026-08-282026-08-28
CVE-2026-68820Microsoft Windows Ancillary Function Driver for WinSock (afd.sys) use-after-free race condition, exploited as a zero-day by the Lazarus-affiliated Operation Dream Job campaign to reach SYSTEM and load the FudModule v3.1 kernel rootkit; patched 2026-08-11, CISA KEV the same day.2026-08-122026-08-282026-08-12
CVE-2026-71384Adobe August 2026 Patch Day: ColdFusion ships a CVSS 10.0 unauthenticated OS command injection, and Campaign Classic ships two more unauthenticated CVSS 10.0 flaws in the same release2026-08-282026-08-282026-08-28
CVE-2026-71386Adobe ColdFusion 2025/2023, cross-site scripting escalating to code execution (APSB26-90)2026-08-282026-08-28·
CVE-2026-71398Adobe August 2026 Patch Day: ColdFusion ships a CVSS 10.0 unauthenticated OS command injection, and Campaign Classic ships two more unauthenticated CVSS 10.0 flaws in the same release2026-08-282026-08-282026-08-28
CVE-2026-74253Sourcerer for Joomla: unauthenticated RCE exploited in the wild since before a working fix existed; the vendor's first two patches did not close it, and the CVE was re-scoped in place to widen the affected range2026-08-282026-08-282026-08-28
CVE-2026-74803YOOtheme ZOO for Joomla: unauthenticated file-upload RCE (CVSS 10.0) plus a precondition-free SQL injection reachable with no submission form at all, three releases in three days, and the 3.x line has no fix2026-08-282026-08-282026-08-28
CVE-2026-74804YOOtheme ZOO for Joomla: unauthenticated file-upload RCE (CVSS 10.0) plus a precondition-free SQL injection reachable with no submission form at all, three releases in three days, and the 3.x line has no fix2026-08-282026-08-282026-08-28
CVE-2026-75114YOOtheme ZOO (Joomla), open redirect in Twitter comment callback2026-08-282026-08-282026-08-28
CVE-2026-76253Splunk Enterprise, privilege escalation via scheduled-search alert-action configuration, reaches the full credential store (SVD-2026-0801)2026-08-282026-08-282026-08-28
CVE-2026-76310Splunk Enterprise August 2026 hardening release (SVD-2026-0801): three unauthenticated CVSS 9.4 flaws let anyone holding an embedded-report token hijack the report owner's session, admins included2026-08-282026-08-282026-08-28
CVE-2026-76311Splunk Enterprise August 2026 hardening release (SVD-2026-0801): three unauthenticated CVSS 9.4 flaws let anyone holding an embedded-report token hijack the report owner's session, admins included2026-08-282026-08-282026-08-28
CVE-2026-76312Splunk Enterprise August 2026 hardening release (SVD-2026-0801): three unauthenticated CVSS 9.4 flaws let anyone holding an embedded-report token hijack the report owner's session, admins included2026-08-282026-08-282026-08-28
CVE-2026-76350Splunk Enterprise August 2026 hardening release (SVD-2026-0801): three unauthenticated CVSS 9.4 flaws let anyone holding an embedded-report token hijack the report owner's session, admins included2026-08-282026-08-282026-08-28
CVE-2026-76351Splunk Enterprise August 2026 hardening release (SVD-2026-0801): three unauthenticated CVSS 9.4 flaws let anyone holding an embedded-report token hijack the report owner's session, admins included2026-08-282026-08-282026-08-28
CVE-2026-76612YOOtheme ZOO for Joomla: unauthenticated file-upload RCE (CVSS 10.0) plus a precondition-free SQL injection reachable with no submission form at all, three releases in three days, and the 3.x line has no fix2026-08-282026-08-282026-08-28
CVE-2026-76613YOOtheme ZOO for Joomla: unauthenticated file-upload RCE (CVSS 10.0) plus a precondition-free SQL injection reachable with no submission form at all, three releases in three days, and the 3.x line has no fix2026-08-282026-08-282026-08-28
CVE-2026-77537Ubiquiti UniFi ecosystem: 22 CVEs in one bulletin, three at CVSS 10.0, unauthenticated CRLF-injection auth bypass, and unauthenticated command injection in UniFi Protect and UniFi Talk2026-08-282026-08-282026-08-28
CVE-2026-77550Ubiquiti UniFi ecosystem: 22 CVEs in one bulletin, three at CVSS 10.0, unauthenticated CRLF-injection auth bypass, and unauthenticated command injection in UniFi Protect and UniFi Talk2026-08-282026-08-282026-08-28
CVE-2026-77554Ubiquiti UniFi ecosystem: 22 CVEs in one bulletin, three at CVSS 10.0, unauthenticated CRLF-injection auth bypass, and unauthenticated command injection in UniFi Protect and UniFi Talk2026-08-282026-08-282026-08-28
CVE-2026-77995miniOrange's SAML2Core library ships the same openssl_verify() tri-state authentication bypass across both its WordPress and Joomla SAML SSO products, one vendor code defect, two ecosystems, exploitation already attempted against the WordPress line2026-08-282026-08-282026-08-28
CVE-2026-77998miniOrange's SAML2Core library ships the same openssl_verify() tri-state authentication bypass across both its WordPress and Joomla SAML SSO products, one vendor code defect, two ecosystems, exploitation already attempted against the WordPress line2026-08-282026-08-282026-08-28
CVE-2026-8451Citrix NetScaler ADC/Gateway, pre-auth SAML IdP memory overread leaking process memory in the NSC_TASS cookie; carried by NCSC-CH as actively exploited with a public PoC since 2026-07-03. Fixed in 14.1-72.61 / 13.1-63.182026-07-012026-08-282026-07-01
CVE-2026-8452Citrix NetScaler ADC/Gateway, heap overflow during SAML SignedInfo canonicalization; CVE record describes only Denial of Service, but watchTowr published a pre-authentication chain to root (identifier is watchTowr's inference). Fixed in 14.1-72.61 / 13.1-63.182026-07-012026-08-282026-07-01
CVE-2026-18963Red Hat build of Keycloak (keycloak-services), reset-credentials flow bypass letting an unauthenticated attacker complete a password reset without the email-verification click and set new credentials, reaching full account takeover including administrators (CVSS 9.1, Red Hat as CNA; root cause improper state validation). Fixed 2026-08-18 in RHBK 26.4.15 (RHSA-2026:56520) and 26.6.6 (RHSA-2026:56523) plus the matching image and operator errata. Product-state correction (2026-08-24 audit): Red Hat records only two products under package_state, both "Not affected", the JBoss EAP Expansion Pack and Red Hat Single Sign-On 7; no Red Hat product is affected and unfixed.2026-08-192026-08-242026-08-19
CVE-2026-19478GitLab CE/EE, code injection via a GraphQL directive allowing an unauthenticated user to remotely modify or delete public projects and user data (CVSS 9.4, vendor-assigned). Fixed out of band on 2026-08-17 in 18.11.11 / 19.0.8 / 19.1.6 / 19.2.4. Actively exploited: WatchTowr honeypots caught in-the-wild attempts ~2 days after the patch (SecurityWeek 2026-08-20); NCSC-CH amended its advisory 2026-08-21; covered by entries/2026-08-22/cve-2026-19478-gitlab-honeypot-exploitation-confirmed. Not on CISA KEV as of 2026-08-24.2026-08-192026-08-242026-08-19
CVE-2026-56179Windows NAT (Hyper-V, upstream-spoofing configuration), NatJack primitive; the August 2026 update adds ISN randomisation, shipped disabled by default and enabled only via a registry key2026-08-102026-08-242026-08-10
CVE-2026-76904GeoServer / GeoTools jsonArrayContains unauthenticated SQL injection, exploited; fixed 2026-08-14 in GeoServer 3.0.1 / 2.28.5 / 2.27.6 (GeoTools 35.1 / 34.5 / 33.6); identifier assigned 2026-08-212026-08-242026-08-24·
CVE-2026-77647SPIP before 4.4.20, unconditional pre-authentication RCE reported anonymously via ANSSI; the vendor's bulletin states exploitation attempts were already observed in the wild (August 2026). A second, distinct unconditional pre-auth RCE affects 4.4.20 itself and is fixed only in 4.4.21, that one is CVE-2026-77806. No mechanism is described by any citable vendor or CERT source.2026-08-222026-08-242026-08-22
CVE-2026-77806SPIP before 4.4.21, second unconditional pre-auth RCE, affecting 4.4.20 itself; exploited in the wild August 2026; identifier added to CERT-FR's advisory 2026-08-242026-08-222026-08-242026-08-22
CVE-2019-16098MSI Afterburner RTCore64.sys driver flaw, long patched, recorded only as one of the two vulnerable drivers Cisco Talos observed the SPECTRE implant loading to obtain a kernel read/write primitive for unlinking EDR notification callbacks. Not a new or in-window disclosure.2026-08-232026-08-232026-08-23
CVE-2019-18935Historical, long-patched CVE referenced only as background by a 2026-08-23 entry; not an in-window disclosure and not this run's finding. Telerik UI for ASP.NET AJAX deserialization flaw named by Cisco Talos among UAT-10147's mass-exploitation set.2026-08-232026-08-23·
CVE-2021-21551Dell DBUtil_2_3.sys driver flaw, long patched, recorded only as the second vulnerable driver Cisco Talos observed the SPECTRE implant loading as its kernel read/write primitive. Not a new or in-window disclosure.2026-08-232026-08-232026-08-23
CVE-2021-23758Historical, long-patched CVE referenced only as background by a 2026-08-23 entry; not an in-window disclosure and not this run's finding. AjaxPro deserialization flaw named by Cisco Talos among UAT-10147's mass-exploitation set.2026-08-232026-08-23·
CVE-2021-24092Historical, long-patched CVE referenced only as background by a 2026-08-23 entry; not an in-window disclosure and not this run's finding. Local privilege-escalation flaw in the same Windows Defender BTR.sys driver file, disclosed by SentinelLabs and patched by Microsoft in February 2021; referenced as historical background by the BTR Reforged deep dive and unrelated to that technique.2026-08-232026-08-23·
CVE-2021-29442Historical, long-patched CVE referenced only as background by a 2026-08-23 entry; not an in-window disclosure and not this run's finding. Nacos missing-authentication flaw on the Derby management endpoint, named by Cisco Talos among UAT-10147's mass-exploitation set and chained toward script-engine code execution.2026-08-232026-08-23·
CVE-2022-27925Historical, long-patched CVE referenced only as background by a 2026-08-23 entry; not an in-window disclosure and not this run's finding. Zimbra Collaboration Suite flaw Cisco Talos names among the long-public vulnerabilities UAT-10147 mass-exploits for initial access; historically reached unauthenticated code execution when chained with CVE-2022-37042.2026-08-232026-08-23·
CVE-2022-37042Historical, long-patched CVE referenced only as background by a 2026-08-23 entry; not an in-window disclosure and not this run's finding. Zimbra authentication-bypass flaw that historically completed the unauthenticated path alongside CVE-2022-27925; recorded for the chaining nuance the Talos shorthand omits.2026-08-232026-08-23·
CVE-2026-20030Cisco Crosswork applications, SQL injection, CVSS 3.1 10.0; patched, exploitation status unknown (relayed by NCSC-CH 2026-08-21)2026-08-232026-08-23·
CVE-2026-20231Cisco Secure Workload, command/OS injection, CVSS 3.1 9.9; patched, exploitation status unknown (relayed by NCSC-CH 2026-08-21)2026-08-232026-08-23·
CVE-2026-20315Cisco Secure Workload, improper access control, CVSS 3.1 10.0; patched, exploitation status unknown (relayed by NCSC-CH 2026-08-21)2026-08-232026-08-23·
CVE-2026-20317Cisco Secure Workload, improper authentication, CVSS 3.1 10.0; patched, exploitation status unknown (relayed by NCSC-CH 2026-08-21)2026-08-232026-08-23·
CVE-2026-20318Cisco Secure Workload, path traversal, CVSS 3.1 9.6; patched, exploitation status unknown (relayed by NCSC-CH 2026-08-21)2026-08-232026-08-23·
CVE-2026-20357Cisco Crosswork, missing authentication for a critical function, CVSS 3.1 10.0; patched, exploitation status unknown (relayed by NCSC-CH 2026-08-21)2026-08-232026-08-23·
CVE-2026-20358Cisco Crosswork, external control of the file system, CVSS 3.1 10.0; patched, exploitation status unknown (relayed by NCSC-CH 2026-08-21)2026-08-232026-08-23·
CVE-2026-20359Cisco Crosswork, insufficiently protected credentials, CVSS 3.1 9.9; patched, exploitation status unknown (relayed by NCSC-CH 2026-08-21)2026-08-232026-08-23·
CVE-2026-69836Microsoft Entra ID deserialization of untrusted data (CWE-502), CVSS 3.1 base 10.0, a cloud-service CVE already mitigated by Microsoft with no tenant action available. Recorded here for the exploitation-status contradiction: MSRC revision 1.1 of 2026-08-21 corrected the record to not-exploited, while ENISA's EU Vulnerability Database still carried it on the exploited feed when checked on 2026-08-22.2026-08-232026-08-232026-08-23
CVE-2026-72529TrueConf Server missing authentication for a critical function on port 4307/TCP; an unauthenticated caller invokes an undocumented function to run a script inside the server's isolated environment. CISA KEV and ENISA EUVD both record exploitation since 2026-08-20; chained with CVE-2026-72530 by Head Mare to reach SYSTEM. Fixed 2026-06-18 in 5.3.9/5.4.9/5.5.5.2026-08-232026-08-232026-08-23
CVE-2026-72530TrueConf Server sandbox escape, a flaw in the isolated environment's code-generation logic lets an attacker who already has script execution there run arbitrary OS commands as NT AUTHORITY\SYSTEM. CISA KEV and ENISA EUVD both record exploitation since 2026-08-20. Fixed 2026-06-18 in 5.3.9/5.4.9/5.5.5.2026-08-232026-08-232026-08-23
CVE-2026-77710misp-stix STIX-import trust-boundary flaw (CVSS 4.0 6.9); the importer decided whether a document was a trusted internal MISP export from markers the producer controls, then copied a whole attribute dictionary onto imported attributes, letting a crafted bundle set distribution, sharing_group_id and tags. Last affected 2026.7.8; fixed by commits only, no tagged release.2026-08-232026-08-232026-08-23
CVE-2026-77755misp-stix denial of service (CVSS 4.0 8.7), parse failures called sys.exit(), raising SystemExit past callers' exception handlers, so one malformed STIX document terminates a long-running importer; no size limit was applied before parsing. Last affected 2026.7.8; fixed by commits only.2026-08-232026-08-232026-08-23
CVE-2026-77761misp-stix cross-document parser state contamination (CVSS 4.0 6.3), reused parser instances retained galaxy data, references, titles and timestamps across conversions, so one document's content can appear in the event generated from the next. Last affected 2026.7.8; fixed by commits only.2026-08-232026-08-232026-08-23
CVE-2026-19586TP-Link Omada gateways, pre-authentication OS command injection in the OpenVPN server; fixed per hardware revision in the vendor firmware table2026-08-222026-08-222026-08-22
CVE-2026-19683TP-Link Omada gateways, second flaw in the August 2026 Omada advisory2026-08-222026-08-222026-08-22
CVE-2026-20319Cisco Crosswork / Secure Workload, the ninth CVE of the August 2026 hardening set, absent from the W34 weekly rollup enumeration2026-08-222026-08-22·
CVE-2026-53413Zoom, one of three August 2026 client flaws; lower patch floor than CVE-2026-534152026-08-222026-08-222026-08-22
CVE-2026-53414Zoom, one of three August 2026 client flaws; lower patch floor than CVE-2026-534152026-08-222026-08-222026-08-22
CVE-2026-53415Zoom, requires a HIGHER fixed version than its two siblings; patching to the obvious floor leaves it open2026-08-222026-08-222026-08-22
CVE-2026-77644PTC Windchill, one of three new August 2026 CVEs, all PR:N, no obtainable fixed version for two of them2026-08-222026-08-222026-08-22
CVE-2026-77645PTC Windchill, one of three new August 2026 CVEs, all PR:N2026-08-222026-08-222026-08-22
CVE-2026-77646PTC Windchill PDMLink, one of three new August 2026 CVEs, all PR:N2026-08-222026-08-222026-08-22
CVE-2026-9033TP-Link Omada gateways, third flaw in the August 2026 Omada advisory2026-08-222026-08-222026-08-22
CVE-2026-64960Thirteen CVEs in ATutor, none of which will ever be fixed, including an unauthenticated auto-login token forgery that authenticates as any account, a2026-08-212026-08-212026-08-21
CVE-2026-64961Thirteen CVEs in ATutor, none of which will ever be fixed, including an unauthenticated auto-login token forgery that authenticates as any account, a2026-08-212026-08-212026-08-21
CVE-2026-64962Thirteen CVEs in ATutor, none of which will ever be fixed, including an unauthenticated auto-login token forgery that authenticates as any account, a2026-08-212026-08-212026-08-21
CVE-2026-64963Thirteen CVEs in ATutor, none of which will ever be fixed, including an unauthenticated auto-login token forgery that authenticates as any account, a2026-08-212026-08-212026-08-21
CVE-2026-64964Thirteen CVEs in ATutor, none of which will ever be fixed, including an unauthenticated auto-login token forgery that authenticates as any account, a2026-08-212026-08-212026-08-21
CVE-2026-64965Thirteen CVEs in ATutor, none of which will ever be fixed, including an unauthenticated auto-login token forgery that authenticates as any account, a2026-08-212026-08-212026-08-21
CVE-2026-64966Thirteen CVEs in ATutor, none of which will ever be fixed, including an unauthenticated auto-login token forgery that authenticates as any account, a2026-08-212026-08-212026-08-21
CVE-2026-64967Thirteen CVEs in ATutor, none of which will ever be fixed, including an unauthenticated auto-login token forgery that authenticates as any account, a2026-08-212026-08-212026-08-21
CVE-2026-64968Thirteen CVEs in ATutor, none of which will ever be fixed, including an unauthenticated auto-login token forgery that authenticates as any account, a2026-08-212026-08-212026-08-21
CVE-2026-64969Thirteen CVEs in ATutor, none of which will ever be fixed, including an unauthenticated auto-login token forgery that authenticates as any account, a2026-08-212026-08-212026-08-21
CVE-2026-64970Thirteen CVEs in ATutor, none of which will ever be fixed, including an unauthenticated auto-login token forgery that authenticates as any account, a2026-08-212026-08-212026-08-21
CVE-2026-64971Thirteen CVEs in ATutor, none of which will ever be fixed, including an unauthenticated auto-login token forgery that authenticates as any account, a2026-08-212026-08-212026-08-21
CVE-2026-64972Thirteen CVEs in ATutor, none of which will ever be fixed, including an unauthenticated auto-login token forgery that authenticates as any account, a2026-08-212026-08-212026-08-21
CVE-2026-69414Microsoft Defender / Malware Protection Engine elevation of privilege, publicly referred to as ShieldBreak, Microsoft's identifier for the proof-of-concept claiming a bypass of the July fix for CVE-2026-50656. Important, CVSS 3.1 base 7.8, publicly disclosed, exploitation not detected, assessed 'Exploitation More Likely'; no update available at publication.2026-08-122026-08-212026-08-12
CVE-2026-60672Oracle WebLogic Server (Core), unauthenticated flaw over T3 and IIOP, CVSS 9.8; August 2026 Critical Security Patch Update.2026-08-202026-08-202026-08-20
CVE-2026-60782Oracle E-Business Suite, Oracle Payments (File Transmission), unauthenticated flaw over HTTP, CVSS 9.8, EBS 12.2.3-12.2.15; August 2026 Critical Security Patch Update.2026-08-202026-08-202026-08-20
CVE-2026-61241Oracle Internet Directory (OID LDAP Server), unauthenticated flaw over LDAP, CVSS 3.1 base 10.0, scope changed; August 2026 Critical Security Patch Update.2026-08-202026-08-202026-08-20
CVE-2026-64849MLflow, unauthenticated full-read SSRF in webhook delivery; the URL guard validates the resolved address but never pins it, and delivery follows redirects unvalidated. CISA KEV 2026-08-19; fixed in 3.15.0.2026-08-202026-08-202026-08-20
CVE-2026-70880Oracle Hyperion Data Relationship Management (Access and security), unauthenticated flaw over TCP, CVSS 3.1 base 10.0; August 2026 Critical Security Patch Update.2026-08-202026-08-202026-08-20
CVE-2026-70921Oracle Hyperion Financial Management (Security), unauthenticated flaw over TLS, CVSS 3.1 base 10.0; August 2026 Critical Security Patch Update.2026-08-202026-08-202026-08-20
CVE-2026-70926Oracle E-Business Suite, Oracle Workflow (Workflow Notification Mailer), unauthenticated flaw over SMTP, CVSS 9.8, EBS 12.2.3-12.2.15; August 2026 Critical Security Patch Update.2026-08-202026-08-202026-08-20
CVE-2026-73570Zimbra Collaboration, pre-authentication command injection in SNMP notification processing reaching OS command execution as the Zimbra user; fixed in 10.1.20 (21 July 2026), CVE published 13 August, ENISA records exploitation from 2026-08-18.2026-08-202026-08-202026-08-20
CVE-2021-27101Accellion FTA SQL injection, referenced by the 2026-08-19 Cl0p Windchill implant entry solely as campaign lineage: the flaw Cl0p exploited before deploying its DEWMODE web shell. Long patched; recorded for provenance of that historical reference, not as in-window coverage.2026-08-192026-08-19·
CVE-2023-34362Progress MOVEit Transfer SQL injection, referenced by the 2026-08-19 Cl0p Windchill implant entry solely as campaign lineage: the flaw Cl0p exploited before deploying its LEMURLOOT web shell. Long patched; recorded for provenance of that historical reference, not as in-window coverage.2026-08-192026-08-19·
CVE-2026-12569PTC Windchill / FlexPLM, pre-auth deserialization RCE, CISA KEV-listed, now driving a Cl0p-attributed mass data-theft extortion campaign2026-06-202026-08-192026-06-20
CVE-2026-14613Keycloak, FGAP v2 role groups endpoint discloses hidden group metadata without group view permission. Named here only as one of the five flaws closed by RHSA-2026:56523 (Red Hat build of Keycloak 26.6.6, 2026-08-18) alongside CVE-2026-18963; recorded so the 26.4 and 26.6 upgrade decisions are comparable, and not otherwise assessed by this store.2026-08-192026-08-19·
CVE-2026-15571Keycloak, predictable account-linking hash enables account takeover via a malicious OIDC client. Closed by RHSA-2026:56523 (Red Hat build of Keycloak 26.6.6, 2026-08-18); Red Hat records a public date of 2026-08-18. A second account-takeover path on the same identity surface as CVE-2026-18963 and one reason the 26.6.6 upgrade is not equivalent to 26.4.15.2026-08-192026-08-19·
CVE-2026-15748WPMU DEV Forminator Forms (WordPress, 600,000+ installs), unauthenticated arbitrary file upload to remote code execution in handle_file_upload: the dangerous-extension blocklist matches MIME-type keys exactly and is bypassed by a pipe-alternative key, while a forged Select-field value overrides the upload field's own type configuration. CVSS 9.8, Wordfence as CNA. Exploitable only on forms carrying both a File Upload and a Select field. Fixed in 1.56.2 (2026-07-31); root-cause write-up published 2026-08-17, relayed by NCSC-CH 2026-08-18. No exploitation reported.2026-08-192026-08-192026-08-19
CVE-2026-15826Cozmoslabs User Profile Builder (WordPress, 40,000+ installs), unauthenticated authentication bypass via type confusion: wppb_log_in_user() calls absint() on the return value of wp_insert_user() before the is_wp_error() check, so a 61-70 character username makes core return a WP_Error that coerces to the integer 1 and the plugin issues an autologin bound to user ID 1. CVSS 9.8, Wordfence as CNA. Exploitable only where the plugin's Automatically Log In setting is enabled. Fixed in 3.16.5 (2026-07-16); write-up 2026-08-14, relayed by NCSC-CH 2026-08-18. No exploitation reported.2026-08-192026-08-192026-08-19
CVE-2026-17048Keycloak, vault-resolved rotated client secrets leaked via the Admin REST API. Closed by RHSA-2026:56523 (Red Hat build of Keycloak 26.6.6, 2026-08-18); a credential-disclosure flaw on the component that fronts single sign-on, recorded alongside CVE-2026-18963 for upgrade comparability.2026-08-192026-08-19·
CVE-2026-19650GitLab CE/EE, cross-site request forgery in the GraphQL multiplex query handler allowing mutations to be executed via GET requests through improper request validation (CVSS 7.1, vendor-assigned). Fixed in the same 2026-08-17 out-of-band release as CVE-2026-19478.2026-08-192026-08-192026-08-19
CVE-2026-33824Windows IKE Extensions (IKE VPN), Unit 42 records reverse-shell callbacks from three endpoints in the autonomous-AI intrusion campaign2026-07-312026-08-192026-07-31
CVE-2026-55040Microsoft SharePoint Server security-feature bypass (CWE-1390 weak authentication), CVSS 9.1, four-weakness JWT forgery chain published with proof-of-concept; exploitation attempts observed against honeypots 2026-08-122026-07-142026-08-192026-07-14
CVE-2026-72898Metabase unauthenticated SQL injection via the /api/session/reset_password endpoint reaching administrator access, CVSS 10.0; the identifier assigned in GHSA-vwf4-m7j8-wcjf for the zero-day Metabase confirmed was already being exploited, CISA KEV 2026-08-11.2026-08-092026-08-192026-08-09
CVE-2026-9796Keycloak, privilege escalation via a time-of-check-to-time-of-use race. Closed by RHSA-2026:56523 (Red Hat build of Keycloak 26.6.6, 2026-08-18); recorded as one of the five flaws in that erratum, not otherwise assessed by this store.2026-08-192026-08-19·
CVE-2023-25158GeoTools/GeoServer OGC filter SQL injection fixed in 2023. Referenced by the 2026-08-18 GeoServer entry as the flaw the jsonArrayContains injection regresses: GeoTools states the mitigation published for this CVE (enabling prepared statements and disabling encode functions) is not effective against the 2026 variant, so operators who applied it are not protected.2026-08-182026-08-18·
CVE-2025-62593Ray dashboard code injection, unauthenticated job-submission endpoints guarded only by a User-Agent string check, bypassable from Firefox and Safari via fetch() combined with DNS rebinding, reaching code execution on the host running Ray. Fixed in Ray 2.52.0; CISA KEV-listed 2026-08-17.2026-08-182026-08-182026-08-18
CVE-2021-22681UPDATE, water-sector PLC lockout status: an OT vendor's decade retrospective attributes the Minnesota controller intrusions to a CVE whose own record2026-08-162026-08-16·
CVE-2022-26134Atlassian Confluence Server and Data Center OGNL injection reaching unauthenticated remote code execution, fixed by Atlassian in June 2022. Referenced by the 2026-08-16 Evooo1Bot entry as one of three enterprise-class exploit modules carried by that Mirai-derived botnet; the flaw itself is long patched; the delta is that it is now in commodity automated scanning.2026-08-162026-08-16·
CVE-2022-29464WSO2 API Manager, Identity Server and Enterprise Integrator unrestricted file upload reaching remote code execution via the /fileupload endpoint, fixed by WSO2 in April 2022. Referenced by the 2026-08-16 Evooo1Bot entry as an enterprise exploit module in that botnet's arsenal.2026-08-162026-08-16·
CVE-2024-4577PHP-CGI argument injection on Windows deployments. Referenced by the 2026-08-16 Evooo1Bot entry as an exploit module carried by that botnet.2026-08-162026-08-16·
CVE-2025-1974Kubernetes ingress-nginx admission-controller remote code execution, disclosed March 2025 and fixed in ingress-nginx 1.12.1 and 1.11.5. Referenced by the 2026-08-16 Evooo1Bot entry as the most recent of three enterprise-class exploit modules in that botnet's arsenal.2026-08-162026-08-16·
CVE-2026-19188Haiwell IoT Cloud HMI Gateway, unauthenticated OS command injection as root via the Net Check cmdPing diagnostic (CVSS 10.0); fixed in Scada-v3.50.1.192026-08-152026-08-162026-08-15
CVE-2026-20349Cisco Secure Firewall ASA/FTD Remote Access SSL VPN, insufficient error checking on HTTP request processing lets an unauthenticated attacker reload the device (denial of service), CVSS 8.6, no workaround; Cisco PSIRT confirmed active exploitation and CISA KEV-listed it 2026-08-11 with a 14 August due date.2026-08-122026-08-162026-08-12
CVE-2026-34348UPDATE; the fourth passkey attack thread this pipeline could not source last week is now documented, and it closed: Windows cached YubiKey assertions2026-08-162026-08-16·
CVE-2026-45659Microsoft SharePoint Server CWE-502 deserialization RCE, authenticated Site Member (PR:L); CISA KEV since 2026-07-01 and flagged for known ransomware campaign use as of catalog version 2026.08.112026-05-272026-08-162026-07-02
CVE-2026-50656Microsoft Defender Malware Protection Engine 'RoguePlanet' link-following LPE to SYSTEM - now fixed (engine >=1.1.26060.3008); NCSC-CH Nightmare Eclipse tracker2026-06-192026-08-162026-08-12 +2 more
CVE-2026-58115Siemens SIMATIC IoT2050 Advanced, unauthenticated Node-RED HTTP interface allows remote code execution with maximum privileges (CVSS 10.0), fixed in V4.3.4.12026-08-132026-08-162026-08-13
CVE-2026-65400Apple macOS Screen Sharing (screensharingd) pre-authentication improper authentication, CVSS 7.1, fixed in macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9. NCSC-NL advisory NCSC-2026-0280 revision 1.0.1 (2026-08-12) records active abuse observed on multiple systems with port 5900 reachable from the internet, root access obtained in all of them and a Monero cryptocurrency miner planted.2026-08-082026-08-162026-08-08
CVE-2026-71362Adobe Commerce / Adobe Commerce B2B / Magento Open Source, incorrect authorization (CWE-863), CVSS 3.1 9.1, unauthenticated customer account takeover by switching a customer session to another customer's account; no authentication, no admin privileges and no user interaction required. Fixed in the -2026-aug isolated patch files of APSB26-92 (2026-08-11). Adobe states it is not aware of exploits in the wild; Sansec reports its Shield WAF already blocking exploitation attempts.2026-08-162026-08-162026-08-16
CVE-2026-26035Fortinet FortiWeb, improper authentication lets an unauthenticated attacker log into the GUI/CLI with any username and password when the non-default RADIUS admin Wildcard option is enabled2026-08-152026-08-152026-08-15
CVE-2026-70465Fortinet FortiClient for Windows, buffer copy without size check lets an unauthenticated attacker able to alter or craft DNS responses execute arbitrary code (CVSS 8.1); fixed in 7.4.4 / 7.2.122026-08-152026-08-152026-08-15
CVE-2026-70466Fortinet FortiWeb, incomplete list of disallowed inputs allows an unauthenticated attacker to bypass WAF policies; fixed in 8.0.3 / 7.6.6, with no fixed build for the 7.4 and 7.2 branches2026-08-152026-08-152026-08-15
CVE-2026-70468Fortinet FortiManager / FortiManager Cloud, FGFM authentication bypass letting a holder of a valid certificate impersonate any managed FortiGate when fgfm-peercert-withoutsn is set2026-08-152026-08-152026-08-15
CVE-2026-73487Flowise before 3.1.3, regex-based Python code-validator bypass in CSV and Airtable Agent nodes reachable by prompt injection through the unauthenticated prediction API2026-08-082026-08-152026-08-08
CVE-2024-38193Windows Ancillary Function Driver for WinSock use-after-free, patched August 2024 and reported at the time as exploited by FudModule. Referenced as prior-art context by the 2026-08-12 Lazarus entry: the same driver family has now yielded a second FudModule privilege-escalation zero-day.2026-08-122026-08-12·
CVE-2025-60719Use-after-free in the Windows AFD.sys driver fixed in November 2025 and not linked to any particular threat actor. Referenced by the 2026-08-12 Lazarus entry: Check Point states the 2026 exploit initially resembled it but testing on a fully patched system confirmed a distinct, previously undocumented vulnerability.2026-08-122026-08-12·
CVE-2026-18556N-able N-central, authentication bypass using an alternate path or channel (CWE-288), affects through 2026.1, fixed in 2026.2 (CVSS 8.2) | CISA KEV 2026-08-04.2026-08-032026-08-122026-08-03
CVE-2026-18577N-able N-central, incomplete patch for CVE-2026-18556; unauthenticated admin auth bypass exploited in the wild, superseded by Hotfix 2 build 2026.3.1.10 of 2026-08-06, which the vendor requires even where 2026.3.1.7 was applied (CVSS 8.2)2026-08-032026-08-122026-08-03
CVE-2026-62832Windows User Profile Service improper link resolution before file access, local elevation of privilege, CVSS 7.8, publicly disclosed before the fix and rated Exploitation More Likely; patched 2026-08-11. Rapid7 assesses the advisory is a solid match for the LegacyHive proof-of-concept.2026-07-292026-08-122026-07-29
CVE-2026-63520Microsoft SharePoint Server remote code execution (CWE-20 improper input validation), CVSS 8.1, patched 2026-08-11. Rapid7, which discovered it, states it is the second of a pair that chain into a critical unauthenticated RCE against a vulnerable SharePoint server.2026-07-142026-08-122026-07-14
CVE-2024-55591Fortinet FortiOS / FortiProxy authentication bypass (CWE-288), named by joint advisory AA26-222A as a primary Gunra ransomware initial-access vector, abused to create a persistent super-user account on the appliance2026-05-102026-08-112026-08-11
CVE-2025-24472Fortinet FortiOS / FortiProxy authentication bypass (CWE-288), named by joint advisory AA26-222A as a primary Gunra ransomware initial-access vector, abused to create a persistent super-user account on the appliance2026-08-112026-08-112026-08-11
CVE-2017-16740Rockwell Automation Allen-Bradley MicroLogix 1400 Series B/C firmware 21.002 and earlier; stack-based buffer overflow that may allow remote code execution. Referenced as a firmware-currency signal on internet-exposed controllers in already-attacked water-utility cities; Forescout states exploitation would require Modbus TCP enabled, which was not confirmed, and that no CVE is confirmed as exploited in that campaign.2026-08-102026-08-10·
CVE-2026-25770Wazuh cluster protocol privilege escalation to root via file write, fixed in 4.14.3 by the _ALLOWED_PREFIXES hardening. Referenced as the earlier fix that CVE-2026-49441 and CVE-2026-48024 both bypass through sibling code paths.2026-08-102026-08-10·
CVE-2026-31431Copy Fail, Linux kernel algif_aead local privilege escalation (ITW, KEV)2026-05-062026-08-102026-07-18
CVE-2026-44901Wazuh distributed API, deserialization RCE as root via unallowlisted builtin resolution when a request fans out across two or more nodes (CVSS 8.4); fixed 4.14.62026-08-102026-08-102026-08-10
CVE-2026-45798Wazuh wazuh-authd, pre-authentication stack buffer overflow reachable on TCP/1515 under the shipped anonymous-SSL default (CVSS 7.5); fixed 4.14.62026-08-102026-08-102026-08-10
CVE-2026-48024Wazuh cluster protocol, sibling arbitrary-file-write-to-root path via peer-controlled merged-file header traversal (CVSS 9.1); fixed 4.14.62026-08-102026-08-102026-08-10
CVE-2026-49441Wazuh cluster protocol, arbitrary file write to root RCE on the master file-receive path, bypassing the CVE-2026-25770 fix (CVSS 9.1); fixed 4.14.62026-08-102026-08-102026-08-10
CVE-2026-56181NatJack, Windows NAT origin-validation error allowing downstream-spoofing TCP session hijack, affecting Hyper-V; fixed in the July 2026 security update2026-08-102026-08-102026-08-10
CVE-2026-63913NatJack; Linux netfilter TCP conntrack state machine forced to CLOSE by an RST with an invalid sequence number, enabling downstream-spoofing TCP session hijack; fixed in 7.1 and stable/LTS backports2026-08-102026-08-102026-08-10
CVE-2026-64638WordPress Core XSS2Shell, pre-auth login-screen reflected XSS chaining via DOM clobbering and a JSONP callback to Application-Password minting and plugin upload (CVSS 4.0 8.9); fixed 7.0.3 with backports to 4.7.342026-08-102026-08-102026-08-10
CVE-2026-66066Ruby on Rails Active Storage variant processing on libvips, unauthenticated arbitrary file read (and possible RCE via exposed application secrets) from an untrusted image upload; CVSS 4.0 9.5 assigned by GitHub Security Advisories as the Rails CNA; fixed in activestorage 7.2.3.2 / 8.0.5.1 / 8.1.3.1 and requires libvips >= 8.13 to be effective2026-07-312026-08-102026-07-31
CVE-2026-12070Tobit TeamDavid Webbox, authenticated arbitrary file deletion via @@COMMENTFILE2026-08-092026-08-092026-08-09
CVE-2026-12071Tobit TeamDavid Webbox, open redirect via URL-encoded manipulation of the 302 redirect domain2026-08-092026-08-092026-08-09
CVE-2026-17583Thermo Fisher Applied Biosystems genetic analyzers, result files written without integrity checking; CORRECTED 2026-08-09: patched software exists for five product lines (4.0.3 / 5.0.3 / 1.2.6 / 1.2.1 / 1.7.4), three EoL lines unfixed2026-08-052026-08-092026-08-05
CVE-2026-25177KerberLoss, Active Directory Domain Services SPN uniqueness bypass via unfilterable Unicode, enabling Kerberos ticket mis-encryption and NTLM downgrade2026-08-092026-08-09·
CVE-2026-2699Progress ShareFile Storage Zone Controller, pre-auth authentication bypass, exploited in the wild from 2026-07-10 (Shadowserver); NEVER CISA KEV-listed (verified against catalogVersion 2026.08.07)2026-07-132026-08-092026-07-13
CVE-2026-2701Progress ShareFile Storage Zone Controller, chained storage-repointing RCE, exploited alongside CVE-2026-2699; NEVER CISA KEV-listed (verified against catalogVersion 2026.08.07)2026-07-132026-08-092026-07-13
CVE-2026-27912ResetNightmare, Windows Kerberos password-change flow accepts a UPN-borrowed identity, taking a low-privileged user to Domain Admin2026-08-092026-08-09·
CVE-2026-54199Tobit TeamDavid Webbox, HTTP header injection in the link-storing function via request body2026-08-092026-08-092026-08-09
CVE-2026-54200Tobit TeamDavid Webbox, authenticated local file inclusion via @@attach with NTFS ADS filter bypass2026-08-092026-08-092026-08-09
CVE-2026-54201Tobit TeamDavid Webbox, error log files served without authentication or authorisation2026-08-092026-08-092026-08-09
CVE-2026-54202Tobit TeamDavid Webbox, authenticated path traversal in archive creation2026-08-092026-08-092026-08-09
CVE-2026-54203Tobit TeamDavid Webbox, unauthenticated uninitialised-heap disclosure via /.well-known/mta-sts. leaking stored credentials2026-08-092026-08-092026-08-09
CVE-2026-54204Tobit TeamDavid Webbox, unauthenticated SSRF via UNC path in the search pathnameroot parameter2026-08-092026-08-092026-08-09
CVE-2026-54205Tobit TeamDavid Webbox, authenticated SSRF via UNC path in the link-storing pathname parameter2026-08-092026-08-092026-08-09
CVE-2026-54206Tobit TeamDavid Webbox, authenticated SSRF via UNC path in the @@INCLUDE messaging command2026-08-092026-08-092026-08-09
CVE-2026-54207Tobit TeamDavid Webbox, authenticated SSRF via UNC path in the !ArcEntryMove archive-move function2026-08-092026-08-092026-08-09
CVE-2026-54208Tobit TeamDavid Webbox, unauthenticated arbitrary file write reaching stored XSS2026-08-092026-08-092026-08-09
CVE-2026-54209Tobit TeamDavid Webbox, unauthenticated buffer overflow via (editini) arbitrary-path read into a fixed stack buffer2026-08-092026-08-092026-08-09
CVE-2026-54210Tobit TeamDavid Webbox, unauthenticated buffer overflow via overlong upload filename2026-08-092026-08-092026-08-09
CVE-2026-54211Tobit TeamDavid Webbox, authenticated buffer overflow in serverClient_close.html form parameters2026-08-092026-08-092026-08-09
CVE-2026-54212Tobit TeamDavid Webbox, unauthenticated buffer overflow via crafted API request body2026-08-092026-08-092026-08-09
CVE-2026-54213Tobit TeamDavid Webbox, unauthenticated single-request denial of service via /internalRestart2026-08-092026-08-092026-08-09
CVE-2026-54214Tobit TeamDavid Webbox, HTTP header injection via the cType parameter (Content-Type control)2026-08-092026-08-092026-08-09
CVE-2026-54215Tobit TeamDavid Webbox, open redirect via the replyUrl parameter2026-08-092026-08-092026-08-09
CVE-2026-54216Tobit TeamDavid Webbox, reflected cross-site scripting via !templateName/EntryInfo2026-08-092026-08-092026-08-09
CVE-2026-54217Tobit TeamDavid Webbox, stored cross-site scripting via email content2026-08-092026-08-092026-08-09
CVE-2026-54218Tobit TeamDavid Webbox, reversible (XOR-obfuscated) storage of user passwords in access.ini2026-08-092026-08-092026-08-09
CVE-2026-71851crypto-js < 4.0.0, CryptoJS.lib.WordArray.random() is not a CSPRNG; ~2^39/2^47 effective entropy, actively exploited to drain wallets (Coinspect 'Ill Bloom')2026-08-092026-08-092026-08-09
CVE-2025-71409CPDLC over ATN-B1, missing authentication for VHF Data Link messages allows rogue ground stations to inject clearances (CVSS 7.1); no mitigation available2026-08-082026-08-082026-08-08
CVE-2025-71410CPDLC over ATN-B1, Unnumbered Disconnect and malformed link-control frames terminate CPDLC sessions (CVSS 5.3); no mitigation available2026-08-082026-08-082026-08-08
CVE-2025-71411CPDLC over ATN-B1, broadcast control frames disconnect multiple aircraft simultaneously (CVSS 5.3); no mitigation available2026-08-082026-08-082026-08-08
CVE-2025-71412CPDLC over ATN-B1, injection of false emergency or status messages (CVSS 7.1); no mitigation available2026-08-082026-08-082026-08-08
CVE-2025-71413CPDLC over ATN-B1, malformed or out-of-sequence X.25-layer frames cause repeated resets (CVSS 5.3); no mitigation available2026-08-082026-08-082026-08-08
CVE-2026-20267Cisco IOS XE August 2026 hardening release, improper access control CWE grouping (CVSS 9.0); fixed 17.9.10/17.12.8/17.15.6/17.18.4/26.1.22026-08-082026-08-082026-08-08
CVE-2026-20268Cisco IOS XE August 2026 hardening release, memory-buffer bounds CWE grouping (CVSS 8.6)2026-08-082026-08-082026-08-08
CVE-2026-20269Cisco IOS XE August 2026 hardening release, resource lifetime CWE grouping (CVSS 8.6)2026-08-082026-08-082026-08-08
CVE-2026-20270Cisco IOS XE August 2026 hardening release, incorrect calculation CWE grouping (CVSS 8.6)2026-08-082026-08-082026-08-08
CVE-2026-20271Cisco IOS XE August 2026 hardening release, control-flow management CWE grouping (CVSS 8.6)2026-08-082026-08-082026-08-08
CVE-2026-20272Cisco IOS XE August 2026 hardening release, command/OS/argument injection CWE grouping (CVSS 9.8), highest of the batch; no workaround2026-08-082026-08-082026-08-08
CVE-2026-20273Cisco IOS XE August 2026 hardening release, input validation / path traversal CWE grouping (CVSS 8.6)2026-08-082026-08-082026-08-08
CVE-2026-41273Flowise, earlier authentication bypass on the OAuth2 credential-refresh route; the fix was incomplete and is bypassed by CVE-2026-706362026-08-082026-08-08·
CVE-2026-53359Linux KVM/x86 'Januscape' shadow-MMU use-after-free, guest-to-host VM escape on Intel and AMD (public PoC host-DoS; RCE withheld); fixed 6.1.177/6.6.144/6.12.95/6.18.38/7.1.32026-07-092026-08-082026-07-09
CVE-2026-60137WordPress core WP_Query author__not_in SQL injection (WP2Shell chain component)2026-07-182026-08-082026-07-18
CVE-2026-63030WP2Shell: WordPress core REST batch route confusion to pre-auth RCE chain2026-07-182026-08-082026-07-18
CVE-2026-64561Linux KVM/x86 'Zapscape'; use-after-free in the recursive shadow-MMU zap path gives guest-root-to-host escape (CVSS 8.8); needs nested virtualization, and on Intel EPT page-walk lengths 4 and 5 exposed to L1; fixed upstream 2abd5287f0832026-07-092026-08-082026-07-09
CVE-2026-67621Flowise ≤3.1.4, missing authorization on document-store mutation endpoints lets a view-only member drive ingestion (CVSS 4.0 7.2, CWE-862); no fix, vendor sunsetting2026-08-082026-08-082026-08-08
CVE-2026-67622Flowise ≤3.1.4; IDOR in the OpenAI Assistants integration gives cross-workspace credential access (CVSS 4.0 8.5, CWE-639); no fix, vendor sunsetting2026-08-082026-08-082026-08-08
CVE-2026-70636Flowise ≤3.1.4, unauthenticated OAuth2 credential-refresh endpoint reachable via prefix-whitelist bypass (CVSS 4.0 8.7, CWE-862); bypass of CVE-2026-41273; no fix, vendor sunsetting2026-08-082026-08-082026-08-08
CVE-2026-8037Progress Kemp LoadMaster pre-auth command injection, added to CISA KEV 2026-08-07 on evidence of active exploitation; fixed GA 7.2.63.2 / LTSF 7.2.54.182026-06-092026-08-082026-06-30
CVE-2026-15572Keycloak; Dynamic Client Registration 'Allowed Protocol Mapper Types' policy does not re-validate mapper type on update, allowing a type-swap to an admin-role-hardcoding mapper and full realm admin; CVSS 8.8, fixed in 26.4.14 / 26.6.5 / 26.7.12026-08-072026-08-072026-08-07
CVE-2026-15573Keycloak; Authorization Services PathMatcher does not normalize URIs, so a trailing slash or matrix parameter selects a less restrictive policy and an authenticated user reaches restricted paths; CVSS 8.1, fixed in 26.4.14 / 26.6.5 / 26.7.12026-08-072026-08-072026-08-07
CVE-2026-16071Keycloak, LDAP entry-DN user search escapes the configured users-DN boundary, disclosing and importing directory entries from outside the intended scope; CVSS 5.4, fixed in 26.4.14 / 26.6.5 / 26.7.12026-08-072026-08-072026-08-07
CVE-2026-16100Keycloak, user-event metrics record request-controlled error text as Prometheus labels, giving an authenticated user an unbounded-cardinality memory-exhaustion DoS; CVSS 6.5, fixed in 26.4.14 / 26.6.5 / 26.7.12026-08-072026-08-072026-08-07
CVE-2026-16102Keycloak, default Dynamic Client Registration policy mis-validates the claim path for User Property mappers, letting a standard account with a limited Initial Access Token forge administrative roles and reach full realm control; CVSS 8.1, fixed in 26.4.14 / 26.6.5 / 26.7.12026-08-072026-08-072026-08-07
CVE-2026-16442Keycloak; SAML IdP-initiated SSO endpoint does not check the link-only restriction, so an attacker controlling a linked upstream identity gains full access to the local account; CVSS 7.4, fixed in 26.4.14 / 26.6.5 / 26.7.12026-08-072026-08-072026-08-07
CVE-2026-16443Keycloak / Red Hat Build of Keycloak, SAML broker metadata import without key-usage attributes disables response signature validation, letting an unauthenticated attacker forge a SAML response and log in as any user whose external identifier is known; CVSS 7.4, fixed in 26.4.14 / 26.6.5 / 26.7.12026-08-072026-08-072026-08-07
CVE-2026-48317Adobe Campaign Classic (on-premise), authenticated eval injection (CWE-95) reaching arbitrary code execution, CVSS 9.6; APSB26-120, fixed in ACC v7 7.4.3 build 93992026-08-072026-08-072026-08-07
CVE-2026-48323Adobe Campaign Classic (on-premise), unauthenticated template-engine injection (CWE-1336) reaching arbitrary code execution, CVSS 10.0, scope changed; APSB26-120, fixed in ACC v7 7.4.3 build 93992026-08-072026-08-072026-08-07
CVE-2026-48326Adobe Campaign Classic (on-premise), authenticated SQL injection (CWE-89) reaching arbitrary code execution, CVSS 9.9; APSB26-120, fixed in ACC v7 7.4.3 build 93992026-08-072026-08-072026-08-07
CVE-2026-48330Adobe Campaign Classic (on-premise), unauthenticated SQL injection (CWE-89) reaching arbitrary code execution, CVSS 10.0, scope changed; APSB26-120, fixed in ACC v7 7.4.3 build 93992026-08-072026-08-072026-08-07
CVE-2026-48331Adobe Campaign Classic (on-premise), unauthenticated SSRF (CWE-918) reaching arbitrary code execution, CVSS 10.0, scope changed; APSB26-120, fixed in ACC v7 7.4.3 build 93992026-08-072026-08-072026-08-07
CVE-2026-48333Adobe Campaign Classic (on-premise), unauthenticated incorrect authorization (CWE-863) giving privilege escalation, CVSS 9.8; APSB26-120, fixed in ACC v7 7.4.3 build 93992026-08-072026-08-072026-08-07
CVE-2026-48399Adobe Campaign Classic (on-premise), violation of secure design principles (CWE-657) giving a security-feature bypass, CVSS 7.5; APSB26-120, fixed in ACC v7 7.4.3 build 93992026-08-072026-08-072026-08-07
CVE-2026-58047cPanel & WHM, HTTP request smuggling in cpsrvd allowing an unauthenticated attacker to manipulate responses delivered to other users on the same server (CVSS v4.0 5.6); interim mitigation disables cpsrvd backend connection reuse2026-08-062026-08-062026-08-06
CVE-2026-58048cPanel & WHM, SQL mode not preserved when renaming a database, so an authenticated account holder with the MySQL/MariaDB feature executes SQL in root context (CVSS v4.0 9.4, HackerOne CNA); fixed across the 11.110–11.136 build lines and WP Squared 138.1.62026-08-062026-08-062026-08-06
CVE-2026-58067Veeam Service Provider Console, unauthenticated host-memory exhaustion denial of service (CVSS v4.0 8.7); fixed in 9.3.0.350572026-08-062026-08-062026-08-06
CVE-2026-58071Veeam Service Provider Console, unauthenticated access to the proxied appliance API as Portal Administrator during a window after an admin session begins (CVSS v4.0 8.2); fixed in 9.3.0.350572026-08-062026-08-062026-08-06
CVE-2026-58072Veeam Service Provider Console, arbitrary file write on the management server leading to remote code execution (CVSS v4.0 9.0); fixed in 9.3.0.350572026-08-062026-08-062026-08-06
CVE-2026-58073Veeam Service Provider Console, unauthenticated attacker impersonates a managed agent and obtains its credentials (CVSS v4.0 9.5, high attack complexity); fixed in SPC 9.3.0.350572026-08-062026-08-062026-08-06
CVE-2026-58074Veeam ONE, arbitrary code execution on the server by a high-privileged user (CVSS v4.0 8.6); fixed in 13.1.0.70342026-08-062026-08-062026-08-06
CVE-2026-58075Veeam ONE, unauthenticated arbitrary file read from the host, leveragable to local privilege escalation (CVSS v4.0 8.7); fixed in 13.1.0.70342026-08-062026-08-062026-08-06
CVE-2026-63455HPE Aruba Networking SD-WAN Orchestrator, REST API authentication bypass via spoofed HTTP headers (CVSS v3.1 9.8), 9.6.x branch only; fixed in 9.6.2.40210 / 9.6.3.40140 / 9.7.0.432642026-08-062026-08-062026-08-06
CVE-2026-63456HPE Aruba Networking SD-WAN Orchestrator, second REST API authentication bypass via spoofed HTTP headers (CVSS v3.1 9.8), 9.6.x branch only; fixed in 9.6.2.40210 / 9.6.3.40140 / 9.7.0.432642026-08-062026-08-062026-08-06
CVE-2026-64630Veeam ONE; low-privileged retrieval of report data outside a shared link's scope (CVSS v4.0 5.3); fixed in 13.1.0.70342026-08-062026-08-062026-08-06
CVE-2026-64631Veeam ONE, SQL injection by a low-privileged user extracting database contents (CVSS v4.0 8.6); fixed in 13.1.0.70342026-08-062026-08-062026-08-06
CVE-2026-64633Veeam ONE, unauthenticated remote code execution on the agent host (CVSS v4.0 10.0); fixed in Veeam ONE 13.1.0.70342026-08-062026-08-062026-08-06
CVE-2026-64634Veeam ONE, local privilege escalation into the Reporter service context (CVSS v4.0 8.4); fixed in 13.1.0.70342026-08-062026-08-062026-08-06
CVE-2026-66747Zbtlink routers/CPE, ENDLESSDOORS, a factory-installed unauthenticated root-command backdoor started by the vendor's own init script across 20+ models; no fix, VulnCheck advises device replacement2026-08-062026-08-062026-08-06
CVE-2026-18574Check Point Security Management / Multi-Domain Security Management, unauthenticated bypass of management authentication to arbitrary command execution; fixed in Jumbo HFA R81.20 Take 161 / R82 Take 122 / R82.10 Take 40, no fix for the R80.x / R81 / R81.10 end-of-support trains2026-08-052026-08-052026-08-05
CVE-2026-29146Apache Tomcat; EncryptInterceptor defaulted to CBC and was exploitable as a padding oracle; its fix introduced the fail-open regression tracked as CVE-2026-344862026-08-052026-08-05·
CVE-2026-34486Apache Tomcat Tribes/EncryptInterceptor fail-open; the fix for CVE-2026-29146 let messages that fail decryption reach the Java deserialization path; CISA KEV 2026-08-04 (previously recorded only as reverse-shell attempts observed by Unit 42); fixed in 9.0.117 / 10.1.54 / 11.0.212026-08-022026-08-052026-08-05
CVE-2026-9198IBM Langflow, unauthenticated auto_login endpoint mints a superuser token, chained with the code-validation endpoint for pre-auth code execution (CVSS 9.8); CISA KEV 2026-08-04; affects Langflow OSS 1.0.0-1.10.02026-07-222026-08-052026-07-22
CVE-2026-15410SonicWall SMA1000 AMC post-auth code injection (actively exploited)2026-07-142026-08-042026-07-14
CVE-2026-51294FABRICATED / NOT A REAL VULNERABILITY, a use-after-free claim against SQLite 3.41 from the LLM-generated advisory batch published via the programmervuln/cveadvisory- GitHub repository. NOT among the six ids JFrog Security Research reproduction-tested; JFrog assessed 54 of the 55 advisories from that account as completely fabricated, and SQLite's maintainer reported the wave independently on 2026-07-29. Still live as an unreviewed record in the GitHub Advisory Database (GHSA-4r76-5xh9-qj36) on 2026-08-04, after BSI CERT-Bund and NCSC-NL had withdrawn their SQLite advisories. Recorded here so a scanner or triage lookup resolves to the retraction; do NOT open remediation work from this id.2026-08-042026-08-04·
CVE-2026-51296FABRICATED / NOT A REAL VULNERABILITY, one of the LLM-generated SQLite advisories published via the programmervuln/cveadvisory- GitHub repository. JFrog Security Research reproduction-tested it under AddressSanitizer against the claimed SQLite release and it did not reproduce; it cited lines 3555 and 3575 of src/json.c in a file that is 2706 lines long in the claimed version 3.41.0. NCSC-NL withdrew NCSC-2026-0268 on 2026-08-03 stating the CVE was hallucinated by an LLM, and BSI CERT-Bund withdrew WID-SEC-2026-2581 and WID-SEC-2026-2604 the same day. Recorded here so a scanner or triage lookup resolves to the retraction; do NOT open remediation work from this id.2026-08-042026-08-04·
CVE-2026-51297FABRICATED / NOT A REAL VULNERABILITY, one of the LLM-generated SQLite advisories published via the programmervuln/cveadvisory- GitHub repository. JFrog Security Research reproduction-tested it under AddressSanitizer against the claimed SQLite release and it did not reproduce; it referenced jsonBlobEdit(), a function absent from the claimed version 3.41.0. NCSC-NL withdrew NCSC-2026-0268 on 2026-08-03 stating the CVE was hallucinated by an LLM, and BSI CERT-Bund withdrew WID-SEC-2026-2581 and WID-SEC-2026-2604 the same day. Recorded here so a scanner or triage lookup resolves to the retraction; do NOT open remediation work from this id.2026-08-042026-08-04·
CVE-2026-51300FABRICATED / NOT A REAL VULNERABILITY, one of the LLM-generated SQLite advisories published via the programmervuln/cveadvisory- GitHub repository. JFrog Security Research reproduction-tested it under AddressSanitizer against the claimed SQLite release and it did not reproduce; the cited line numbers are a comment and a memory allocation, unrelated to the deletion logic it describes. NCSC-NL withdrew NCSC-2026-0268 on 2026-08-03 stating the CVE was hallucinated by an LLM, and BSI CERT-Bund withdrew WID-SEC-2026-2581 and WID-SEC-2026-2604 the same day. Recorded here so a scanner or triage lookup resolves to the retraction; do NOT open remediation work from this id.2026-08-042026-08-04·
CVE-2026-51302FABRICATED / NOT A REAL VULNERABILITY, one of the LLM-generated SQLite advisories published via the programmervuln/cveadvisory- GitHub repository. JFrog Security Research reproduction-tested it under AddressSanitizer against the claimed SQLite release and it did not reproduce; the named function exprComputeOperands() did not exist in SQLite 3.41 and sqlite3ReleaseTempReg() performs no heap deallocation, making the claimed bug class impossible; Red Hat initially scored it 10.0 before downgrading to 7.6. NCSC-NL withdrew NCSC-2026-0268 on 2026-08-03 stating the CVE was hallucinated by an LLM, and BSI CERT-Bund withdrew WID-SEC-2026-2581 and WID-SEC-2026-2604 the same day. Recorded here so a scanner or triage lookup resolves to the retraction; do NOT open remediation work from this id.2026-08-042026-08-04·
CVE-2026-51303FABRICATED / NOT A REAL VULNERABILITY, one of the LLM-generated SQLite advisories published via the programmervuln/cveadvisory- GitHub repository. JFrog Security Research reproduction-tested it under AddressSanitizer against the claimed SQLite release and it did not reproduce; it claimed a fix in 3.51.3 although a 3.51.2-to-3.51.3 diff shows no changes to src/expr.c at all. NCSC-NL withdrew NCSC-2026-0268 on 2026-08-03 stating the CVE was hallucinated by an LLM, and BSI CERT-Bund withdrew WID-SEC-2026-2581 and WID-SEC-2026-2604 the same day. Recorded here so a scanner or triage lookup resolves to the retraction; do NOT open remediation work from this id.2026-08-042026-08-04·
CVE-2026-51304FABRICATED / NOT A REAL VULNERABILITY, one of the LLM-generated SQLite advisories published via the programmervuln/cveadvisory- GitHub repository. JFrog Security Research reproduction-tested it under AddressSanitizer against the claimed SQLite release and it did not reproduce; it gave a single-argument signature for a function that requires a database-handle argument. NCSC-NL withdrew NCSC-2026-0268 on 2026-08-03 stating the CVE was hallucinated by an LLM, and BSI CERT-Bund withdrew WID-SEC-2026-2581 and WID-SEC-2026-2604 the same day. Recorded here so a scanner or triage lookup resolves to the retraction; do NOT open remediation work from this id.2026-08-042026-08-04·
CVE-2025-11371Gladinet CentreStack and Triofox, files or directories accessible to external parties; added to the CISA Known Exploited Vulnerabilities catalog 2025-11-04. Referenced as historical exploitation context by the 2026-08-03 CentreStack entry.2025-11-042026-08-03·
CVE-2025-14611Gladinet CentreStack and Triofox, hard-coded cryptographic key vulnerability; added to the CISA Known Exploited Vulnerabilities catalog 2025-12-15. Referenced as historical exploitation context by the 2026-08-03 CentreStack entry.2025-12-152026-08-03·
CVE-2025-30406Gladinet CentreStack, use of a hard-coded cryptographic key; added to the CISA Known Exploited Vulnerabilities catalog 2025-04-08. Referenced as historical exploitation context by the 2026-08-03 CentreStack entry.2025-04-082026-08-03·
CVE-2026-12185Bouncy Castle for Java (< 1.85), BKS/UBER keystore allocates from untrusted lengths before integrity check (CVSS 7.1)2026-08-032026-08-032026-08-03
CVE-2026-12802Bouncy Castle for Java (< 1.85); CMS AuthEnvelopedData fails to enforce tag-length on decryption (CVSS 8.7)2026-08-032026-08-032026-08-03
CVE-2026-12803Bouncy Castle for Java (< 1.85); KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery) (CVSS 8.7)2026-08-032026-08-032026-08-03
CVE-2026-12816Bouncy Castle for Java (< 1.85), IESEngine stream-mode MAC forgery via length-dependent KDF split (CVSS 8.7)2026-08-032026-08-032026-08-03
CVE-2026-12817Bouncy Castle for Java (< 1.85), OpenPGP AEAD decryption skips final tag on chunk-aligned data (CVSS 8.7)2026-08-032026-08-032026-08-03
CVE-2026-12852Bouncy Castle for Java (< 1.85), MLS wire decoder allocates attacker-declared opaque length before bounds check (CVSS 8.7)2026-08-032026-08-032026-08-03
CVE-2026-12860Bouncy Castle for Java (< 1.85), RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path (CVSS 8.7)2026-08-032026-08-032026-08-03
CVE-2026-13506Bouncy Castle for Java (< 1.85), Lazy ASN.1 sequence forcing resets nesting-depth guard (CVSS 8.7)2026-08-032026-08-032026-08-03
CVE-2026-13586Bouncy Castle for Java (< 1.85), PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS) (CVSS 5.3)2026-08-032026-08-032026-08-03
CVE-2026-14682Bouncy Castle for Java (< 1.85), Possible OOM from unbounded up-front allocation on a definite-length read (CVSS 8.7)2026-08-032026-08-032026-08-03
CVE-2026-15055Bouncy Castle for Java (< 1.85), PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input (CVSS 5.3)2026-08-032026-08-032026-08-03
CVE-2026-54363Gladinet CentreStack < 17.5, hardcoded cryptographic key (static SysNumber) forges AccessTickets and x-glad-auth headers, reaching a domain-administrator IdentityTicket and unauthenticated RCE (CVSS 9.3)2026-08-032026-08-032026-08-03
CVE-2026-54364Gladinet CentreStack < 17.4, session-variable injection at SelectProvider.aspx bypasses the IsValidRSession check (CVSS 6.9)2026-08-032026-08-032026-08-03
CVE-2026-54365Gladinet CentreStack < 17.3, unauthenticated deserialization in GSNamespace.dll reaches NetUserAdd, creating arbitrary local OS accounts (CVSS 8.7)2026-08-032026-08-032026-08-03
CVE-2026-54366Gladinet CentreStack < 17.4, XXE at the unauthenticated SharePoint StorageConfig endpoint exfiltrates files including Web.config (CVSS 8.7)2026-08-032026-08-032026-08-03
CVE-2026-54367Gladinet CentreStack < 17.2, unauthenticated authorization bypass via forged EntAcctId values reaches any account's settings (CVSS 8.8)2026-08-032026-08-032026-08-03
CVE-2026-54368Gladinet CentreStack < 17.4, authenticated SQL injection via the x-glad-filter header writes files through PostgreSQL large-object functions (CVSS 8.7)2026-08-032026-08-032026-08-03
CVE-2026-58059Bouncy Castle for Java (< 1.85), Quadratic-time escaping when stringifying X.500 distinguished names (CVSS 8.7)2026-08-032026-08-032026-08-03
CVE-2026-58060Bouncy Castle for Java (< 1.85), HSS public-key level count unbounded, enabling huge allocation on verify (CVSS 8.7)2026-08-032026-08-032026-08-03
CVE-2026-58061Bouncy Castle for Java (< 1.85), CCM-family modes write plaintext to caller buffer before tag check (CVSS 8.7)2026-08-032026-08-032026-08-03
CVE-2026-58062Bouncy Castle for Java (< 1.85), Stapled OCSP response accepted without binding to the checked certificate (CVSS 9.3)2026-08-032026-08-032026-08-03
CVE-2026-58063Bouncy Castle for Java (< 1.85), BCFKS keystore load honours unbounded KDF cost from untrusted file (CVSS 5.3)2026-08-032026-08-032026-08-03
CVE-2026-59638Bouncy Castle for Java (< 1.85), JSSE hostname verifier CN-fallback enabled by default despite documented opt-in (CVSS 9.3)2026-08-032026-08-032026-08-03
CVE-2026-59639Bouncy Castle for Java (< 1.85), CMS verifySignatures returns true for SignedData with zero signers (CVSS 8.7)2026-08-032026-08-032026-08-03
CVE-2026-59640Bouncy Castle for Java (< 1.85), OpenPGP CFB quick-check oracle active on symmetric/session-key paths (CVSS 8.7)2026-08-032026-08-032026-08-03
CVE-2026-59641Bouncy Castle for Java (< 1.85), S/MIME validator trusts signer-asserted signingTime for path validation (CVSS 8.7)2026-08-032026-08-032026-08-03
CVE-2026-59642Bouncy Castle for Java (< 1.85), CMS AuthenticatedData content not bound to MAC when authAttrs present (CVSS 8.7)2026-08-032026-08-032026-08-03
CVE-2026-59643Bouncy Castle for Java (< 1.85), OpenPGP inline-signature policy failures silently ignored (CVSS 8.7)2026-08-032026-08-032026-08-03
CVE-2026-59644Bouncy Castle for Java (< 1.85), MLS hash-ratchet honours arbitrary 32-bit generation counter from sender (CVSS 8.7)2026-08-032026-08-032026-08-03
CVE-2026-59645Bouncy Castle for Java (< 1.85), OER parser recurses without depth limit on self-referential IEEE 1609.2 schema (CVSS 8.7)2026-08-032026-08-032026-08-03
CVE-2026-59646Bouncy Castle for Java (< 1.85), DTLS handshake reassembler allocates buffer from unchecked 24-bit length (CVSS 8.7)2026-08-032026-08-032026-08-03
CVE-2026-59647Bouncy Castle for Java (< 1.85), CRMF/CMP password-MAC honours unbounded iteration count (CVSS 6.9)2026-08-032026-08-032026-08-03
CVE-2026-59648Bouncy Castle for Java (< 1.85), OpenPGP Argon2 S2K honours attacker-chosen memory and passes (CVSS 6.9)2026-08-032026-08-032026-08-03
CVE-2026-59649Bouncy Castle for Java (< 1.85), OpenPGP user-attribute subpacket length bounded only by JVM max memory (CVSS 8.7)2026-08-032026-08-032026-08-03
CVE-2026-59650Bouncy Castle for Java (< 1.85), MTI/A0 DH agreement exponentiates unvalidated peer value (CVSS 9.3)2026-08-032026-08-032026-08-03
CVE-2026-59651Bouncy Castle for Java (< 1.85), BKS keystore accepts legacy version with 16-bit integrity MAC key (CVSS 7.1)2026-08-032026-08-032026-08-03
CVE-2026-59652Bouncy Castle for Java (< 1.85), LDAP filter injection in legacy jdk1.4 LDAPStoreHelper (CVSS 6.9)2026-08-032026-08-032026-08-03
CVE-2026-8763Bouncy Castle for Java (< 1.85), Name Constraints bypass via trailing dot in rfc822Name and URI (CVSS 9.3)2026-08-032026-08-032026-08-03
CVE-2013-4786CVE-2013-4786, 24,650 internet-exposed BMCs hand a crackable password hash to any unauthenticated caller, and Lava found ransom notes on live management interfaces2026-07-302026-08-022026-07-30
CVE-2025-15467OpenSSL CMS AuthEnvelopedData parsing stack buffer overflow (CVSS 9.8 per Siemens ProductCERT; OpenSSL rates it High), pre-auth, fires before AEAD tag verification; vendored in Siemens Desigo CC, where family V7 has no fix available, V8 is fixed by patch V8.0 QU2.0021 and V9 by 9.0.1; public command-execution PoC2026-07-292026-08-022026-07-29
CVE-2025-68686FortiOS SSL-VPN symlink-persistence patch bypass (exploited, KEV)2026-07-282026-08-022026-07-28
CVE-2026-0769Langflow eval_custom_component_code eval injection (CVSS 9.8, CWE-95), unauthenticated RCE, published by ZDI as a 0-day advisory with no fixed version documented anywhere and "restrict interaction with the product" as the only stated mitigation; VulnCheck reports observed exploitation for credential harvesting, cryptomining and lateral movement; NOT in CISA KEV (distinct from the KEV-listed CVE-2026-0770)2026-07-292026-08-022026-07-29
CVE-2026-14446IBM WebSphere Application Server traditional, missing authentication for critical function in the administrative console (CWE-306), CVSS 9.8; interim fix APAR DT496500, Fix Pack targeted 3Q20262026-08-012026-08-022026-08-01
CVE-2026-14512IBM WebSphere Application Server traditional, pre-authentication unsafe deserialization (CWE-502), CVSS 9.8; interim fix APAR PH72166, Fix Pack targeted 3Q20262026-08-012026-08-022026-08-01
CVE-2026-16232Check Point SmartConsole authentication bypass to full admin (exploited)2026-07-232026-08-022026-07-23
CVE-2026-16723Alibaba fastjson 1.2.68–1.2.83, remote code execution under stock defaults in Spring Boot fat-JAR deployments; no patched 1.x release, exploited in the wild2026-07-272026-08-022026-07-27
CVE-2026-16812Arista VeloCloud Orchestrator on-prem unauthenticated OS command injection (exploited, KEV)2026-07-282026-08-022026-07-28
CVE-2026-28323SolarWinds Web Help Desk, unauthenticated SAML 2.0 authentication bypass, CVSS 9.8; fixed in 2026.2.12026-08-012026-08-022026-08-01
CVE-2026-3055Citrix NetScaler ADC/Gateway out-of-bounds memory read when configured as a SAML Identity Provider (CWE-125, CVSS 9.8), CISA KEV-listed and exploited by multiple unrelated clusters, including manual exfiltration of appliance memory searched for session cookies (Unit 42, 2026-07-30); fixed in 13.1-62.24 / 14.1-66.60 / 13.1-FIPS-NDcPP 13.1-37.2632026-07-012026-08-022026-07-31
CVE-2026-39987marimo notebook, pre-auth RCE via the unauthenticated /terminal/ws endpoint (CWE-306), CVSS 4.0 9.3, fixed in 0.23.0, CISA KEV-listed; Unit 42 records command execution confirmed on 11 endpoints during the 2026-07 autonomous-agent campaign2026-05-302026-08-022026-07-31
CVE-2026-42897Microsoft Exchange Server Outlook Web Access stored XSS (CWE-79, CVSS 3.1 8.1, Microsoft CNA), exploited in the wild by TA488/LAUNDRY BEAR to deliver the OWAReaper browser implant; CISA KEV 2026-05-15; permanent fix is the July 2026 Exchange SU (SE RTM; 2019 CU14/CU15 and 2016 CU23 via ESU Period 2), which does not remove earlier mitigations2026-05-162026-08-022026-05-18 +2 more
CVE-2026-44090Phoenix Contact CHARX SEC-3xxx, MQTT broker reachable without authentication, protected from external access only by the device firewall (CWE-306); CVSS 3.1 9.82026-08-022026-08-022026-08-02
CVE-2026-44101Phoenix Contact CHARX SEC-3xxx, missing authentication on the CHARX OCPP Agent lets a remote attacker reconfigure the backend connection (CWE-306); CVSS 3.1 9.82026-08-022026-08-022026-08-02
CVE-2026-44104Phoenix Contact CHARX SEC-3xxx, basemodule firmware update validates only a CRC32 checksum with no cryptographic signature verification (CWE-347), allowing unauthenticated installation of modified firmware; CVSS 3.1 9.82026-08-022026-08-022026-08-02
CVE-2026-44108Phoenix Contact CHARX SEC-3xxx, firewall terminates prematurely during shutdown because of script execution order (CWE-696), exposing internal services in the window; CVSS 3.1 9.82026-08-022026-08-022026-08-02
CVE-2026-48448Adobe Campaign Classic, unauthenticated SQL injection giving arbitrary file-system read; CVSS 3.1 8.6, fixed in ACC v7 7.4.3 build 9398 (APSB26-114)2026-08-022026-08-022026-08-02
CVE-2026-48449Adobe Campaign Classic, Incorrect Authorization (CWE-863) giving unauthenticated arbitrary code execution; CVSS 3.1 10.0, on-premise and hybrid on-premise components only, fixed in ACC v7 7.4.3 build 9398 (APSB26-114)2026-08-022026-08-022026-08-02
CVE-2026-59243Apache Airflow FAB provider, Azure AD OAuth login decoded ID tokens with verify_signature defaulted to False, allowing login as any user incl. Admin; no CVSS published by any party; fixed in apache-airflow-providers-fab 3.7.32026-07-292026-08-022026-07-29
CVE-2026-59726CVE-2026-59726 (RufRoot), Ruflo's MCP bridge took unauthenticated tool calls on all interfaces, and the memory it poisons is not cleaned up by the patch (CVSS 10.0)2026-07-302026-08-022026-07-30
CVE-2026-61511vBulletin {vb:math} runMaths eval injection, unauthenticated RCE (public exploit)2026-07-282026-08-022026-07-28
CVE-2026-65766JoomShaper SP Page Builder for Joomla, pre-authentication SQL injection in the Dynamic Content endpoint's ORDER BY clause, guarded only by a CSRF token Joomla issues to anonymous visitors; Joomla CNA CVSS 4.0 9.2 (discloser self-scored 8.7), fixed in 6.7.12026-08-022026-08-022026-08-02
CVE-2026-65876JoomShaper SP Page Builder for Joomla, unauthenticated SQL injection through the catid parameter of the loadMoreArticles endpoint; Joomla CNA CVSS 4.0 9.2, fixed in 6.7.1. Not among the four flaws mySites.guru reported and not tested by it2026-08-022026-08-022026-08-02
CVE-2026-65877JoomShaper SP Page Builder for Joomla, authenticated SQL injection in the media manager's search and date filters, reachable by a low-privilege author; Joomla CNA CVSS 4.0 8.2, fixed in 6.7.12026-08-022026-08-022026-08-02
CVE-2026-65878JoomShaper SP Page Builder for Joomla, authenticated arbitrary file delete via an unguarded request-supplied path in the media-delete action; Joomla CNA CVSS 4.0 8.3, fixed in 6.7.12026-08-022026-08-022026-08-02
CVE-2026-65879JoomShaper SP Page Builder for Joomla, unauthenticated mail relay via a shared secret hardcoded identically into every shipped copy (CWE-798); the Joomla CNA assigned no metrics, so the 9.8 is a CISA-ADP CVSS 3.1 score and is not on the CVSS 4.0 scale its siblings use. Fixed in 6.7.12026-08-022026-08-022026-08-02
CVE-2026-65883Aimy Captcha-Less Form Guard (Joomla plugin), unauthenticated PHP object injection to RCE, CVSS 9.8; fixed in 20.12026-08-012026-08-022026-08-01
CVE-2026-65884Balbooa Gridbox for Joomla; registration handler adds caller-supplied usergroup IDs, letting an unauthenticated visitor register an account directly into an administrator group; CVSS 4.0 10.0 (CWE-284, Joomla CNA), exploit maturity Attacked; affected 1.0.0-2.20.1, fixed 2.20.22026-07-262026-08-022026-07-26
CVE-2026-65885Balbooa Gridbox for Joomla, authenticated arbitrary file upload; becomes unauthenticated RCE chained with CVE-2026-65884 because the attacker can create the required account; CVSS 4.0 9.4 (CWE-434, Joomla CNA), exploit maturity Attacked; affected 1.0.0-2.20.1, fixed 2.20.22026-07-262026-08-022026-07-26
CVE-2026-7849Phoenix Contact CHARX SEC-3xxx EV charging controllers, unauthenticated command injection into the system configuration executed as root (CWE-77); CVSS 3.1 9.8, firmware below 1.9.1, fix unreleased at disclosure (CERT@VDE VDE-2026-008)2026-08-022026-08-022026-08-02
CVE-2026-14528IBM WebSphere Application Server traditional, sensitive information written to log files (CWE-532), CVSS 7.42026-08-012026-08-012026-08-01
CVE-2026-28299SolarWinds Web Help Desk, denial of service, server crash due to insufficient memory; 8.2 High per the vendor's 2026.2.1 release-notes CVE table; fixed in 2026.2.12026-08-012026-08-012026-08-01
CVE-2026-14869HCSEC-2026-23, HashiCorp Terraform MCP Server leaks its own bearer token to an attacker-supplied address, and its credential cache crosses sessions and tenants (CVE-2026-14869, CVE-2026-16496, CVE-2026-16498)2026-07-302026-07-302026-07-30
CVE-2026-16496HCSEC-2026-23, HashiCorp Terraform MCP Server leaks its own bearer token to an attacker-supplied address, and its credential cache crosses sessions and tenants (CVE-2026-14869, CVE-2026-16496, CVE-2026-16498)2026-07-302026-07-302026-07-30
CVE-2026-16498HCSEC-2026-23, HashiCorp Terraform MCP Server leaks its own bearer token to an attacker-supplied address, and its credential cache crosses sessions and tenants (CVE-2026-14869, CVE-2026-16496, CVE-2026-16498)2026-07-302026-07-302026-07-30
CVE-2026-41703VMSA-2026-0006, VMware vCenter: unauthenticated Directory Service auth bypass and Syslog traversal RCE (both CVSS 9.8), plus a VMXNET3 guest-to-host escape2026-07-302026-07-302026-07-30
CVE-2026-41709VMSA-2026-0006, VMware vCenter: unauthenticated Directory Service auth bypass and Syslog traversal RCE (both CVSS 9.8), plus a VMXNET3 guest-to-host escape2026-07-302026-07-302026-07-30
CVE-2026-47876VMSA-2026-0006, VMware vCenter: unauthenticated Directory Service auth bypass and Syslog traversal RCE (both CVSS 9.8), plus a VMXNET3 guest-to-host escape2026-07-302026-07-302026-07-30
CVE-2026-59309VMSA-2026-0006, VMware vCenter: unauthenticated Directory Service auth bypass and Syslog traversal RCE (both CVSS 9.8), plus a VMXNET3 guest-to-host escape2026-07-302026-07-302026-07-30
CVE-2026-7891Siemens Mendix Runtime (all versions, CVSS 9.1), platform-enforced access rules on the System.User entity cannot be overridden by access rules on a specialization, so the anonymous role commonly reaches all stored user records; no code fix, mitigation is App Security role-management reconfiguration2026-07-292026-07-292026-07-29
CVE-2025-33053Windows shortcut working-directory resolution flaw abused for remote WebDAV execution2026-07-262026-07-262026-07-26
CVE-2026-0770CVE-2026-0770, Langflow: unauthenticated exec_globals RCE (actively exploited, CISA KEV 2026-07-21)2026-07-222026-07-262026-07-22
CVE-2026-14499IBM Langflow OSS Python Interpreter authenticated command injection (CVSS 8.8), fixed in 1.10.2, not 1.10.12026-07-222026-07-262026-07-22
CVE-2026-47056Oracle Data Integrator REST Service, unauthenticated takeover (CVSS 10.0, July 2026 CPU)2026-07-262026-07-262026-07-26
CVE-2026-60217Oracle Coherence Core, unauthenticated takeover over TCP (CVSS 10.0, July 2026 CPU)2026-07-262026-07-262026-07-26
CVE-2026-60365Oracle Fusion Middleware CVSS 10.0 unauthenticated flaw, listed twice in Oracle's July 2026 risk matrix (Oracle HTTP Server and WebLogic Server Proxy Plug-in), which is why the ten-row / nine-CVE counts diverge2026-07-262026-07-26·
CVE-2026-61211Oracle Database Server, DBMS_CLOUD privilege abuse to full server control (CVSS 9.9)2026-07-262026-07-262026-07-26
CVE-2026-61425Balbooa Gridbox for Joomla, unauthenticated cookie-forgery authentication bypass to Super User2026-07-262026-07-262026-07-26
CVE-2026-62415Membership Pro for Joomla, unauthenticated file upload (CVSS 9.1, Joomla CNA); fixed in 4.6.22026-07-262026-07-262026-07-26
CVE-2026-63047Events Booking for Joomla, unauthenticated invoice IDOR exposing personal and financial data2026-07-262026-07-262026-07-26
CVE-2026-65759JoomShaper EasyStore for Joomla, unauthenticated order/payment forgery on the repayment endpoint (CVSS 4.0 8.7, Joomla CNA)2026-07-262026-07-262026-07-26
CVE-2026-65760JoomShaper EasyStore for Joomla, cross-customer order/invoice IDOR reachable by any logged-in customer (CVSS 4.0 9.2, Joomla CNA)2026-07-262026-07-262026-07-26
CVE-2026-65761JoomShaper EasyStore for Joomla, unauthenticated SQL injection, full site-database read (CVSS 4.0 9.3, Joomla CNA)2026-07-262026-07-262026-07-26
CVE-2023-43770Roundcube webmail persistent XSS (n-day exploited by TA458/Operation RoundPress)2026-07-252026-07-25·
CVE-2025-27915Zimbra Collaboration half-click webmail flaw (TA458/Operation RoundPress)2026-07-252026-07-25·
CVE-2025-3929mDaemon webmail half-click flaw (TA458/Operation RoundPress)2026-07-252026-07-25·
CVE-2026-54121Certighost, Windows Server AD CS elevation of privilege (DC impersonation to DCSync)2026-07-252026-07-252026-07-25
CVE-2026-62144Check Point Security Management / MDS unauthenticated command execution2026-07-232026-07-252026-07-23
CVE-2026-62145Check Point Gaia Portal read-only to root command execution2026-07-232026-07-252026-07-23
CVE-2026-8496SOGo webmail half-click XSS zero-day (Operation RoundPress / TA458)2026-07-252026-07-252026-07-25
CVE-2025-66376Zimbra Collaboration Suite Classic Web Client stored XSS (view-based/zero-click) exploited by Russian actor LAUNDRY BEAR; CVSS 7.2 (MITRE)/6.1 (NVD); CISA KEV; patched ZCS 10.0.18/10.1.132026-07-242026-07-242026-07-24
CVE-2026-16002MZ Automation lib60870 out-of-bounds read parser-crash DoS (IEC 60870-5-104); lib60870 <= 2.4.0 (CVSS 3.1 8.2 / 4.0 8.8)2026-07-242026-07-242026-07-24
CVE-2026-49035MZ Automation libIEC61850 unauthenticated heap-overflow RCE via crafted MMS Initiate request (CVSS 3.1 8.1 / 4.0 9.2); libIEC61850 1.0.0-1.6.12026-07-242026-07-242026-07-24
CVE-2026-50032MZ Automation libIEC61850 NULL-pointer dereference DoS in MMS Write Named Variable List handler (CVSS 3.1 7.5 / 4.0 8.7)2026-07-242026-07-242026-07-24
CVE-2026-50039MZ Automation libIEC61850 stack-based buffer overflow via crafted ReadRequest (CVSS 3.1 7.5 / 4.0 8.7)2026-07-242026-07-242026-07-24
CVE-2026-50103MZ Automation libIEC61850 NULL-pointer dereference DoS in L2 GOOSE/R-GOOSE parser via malformed TLV (CVSS 3.1 6.5 / 4.0 7.1)2026-07-242026-07-242026-07-24
CVE-2026-28302SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE)2026-07-232026-07-232026-07-23
CVE-2026-28304SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE)2026-07-232026-07-232026-07-23
CVE-2026-28305SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE)2026-07-232026-07-232026-07-23
CVE-2026-28306SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE)2026-07-232026-07-232026-07-23
CVE-2026-28307SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE)2026-07-232026-07-232026-07-23
CVE-2026-28308SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE)2026-07-232026-07-232026-07-23
CVE-2026-28309SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE)2026-07-232026-07-232026-07-23
CVE-2026-28310SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE)2026-07-232026-07-232026-07-23
CVE-2026-28311SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE)2026-07-232026-07-232026-07-23
CVE-2026-28312SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE)2026-07-232026-07-232026-07-23
CVE-2026-28313SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE)2026-07-232026-07-232026-07-23
CVE-2026-28314SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE)2026-07-232026-07-232026-07-23
CVE-2026-28315SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE)2026-07-232026-07-232026-07-23
CVE-2026-28316SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE)2026-07-232026-07-232026-07-23
CVE-2026-28317SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE)2026-07-232026-07-232026-07-23
CVE-2026-28321SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE)2026-07-232026-07-232026-07-23
CVE-2026-47678GLPI 11.0.8/10.0.26 security release (critical RCE via form import; MFA bypass)2026-07-232026-07-232026-07-23
CVE-2026-47679GLPI 11.0.8/10.0.26 security release (critical RCE via form import; MFA bypass)2026-07-232026-07-232026-07-23
CVE-2026-48482GLPI 11.0.8/10.0.26 security release (critical RCE via form import; MFA bypass)2026-07-232026-07-232026-07-23
CVE-2026-49470GLPI 11.0.8/10.0.26 security release (critical RCE via form import; MFA bypass)2026-07-232026-07-232026-07-23
CVE-2026-52848GLPI 11.0.8/10.0.26 security release (critical RCE via form import; MFA bypass)2026-07-232026-07-232026-07-23
CVE-2026-53610GLPI 11.0.8/10.0.26 security release (critical RCE via form import; MFA bypass)2026-07-232026-07-232026-07-23
CVE-2026-53625GLPI 11.0.8/10.0.26 security release (critical RCE via form import; MFA bypass)2026-07-232026-07-232026-07-23
CVE-2026-53626GLPI 11.0.8/10.0.26 security release (critical RCE via form import; MFA bypass)2026-07-232026-07-232026-07-23
CVE-2026-53629GLPI 11.0.8/10.0.26 security release (critical RCE via form import; MFA bypass)2026-07-232026-07-232026-07-23
CVE-2026-55214GLPI 11.0.8/10.0.26 security release (critical RCE via form import; MFA bypass)2026-07-232026-07-232026-07-23
CVE-2026-10631CVE-2026-10631, Zimbra: EWS extension access-control issue (fixed 10.1.20; RESERVED on NVD)2026-07-222026-07-222026-07-22
CVE-2026-50054CVE-2026-50054, Zimbra: mailbox delegation authorization flaw (fixed 10.1.20; RESERVED on NVD)2026-07-222026-07-222026-07-22
CVE-2026-50055CVE-2026-50055, Zimbra: mail-forwarding restriction bypass (fixed 10.1.20; RESERVED on NVD)2026-07-222026-07-222026-07-22
CVE-2026-50522CVE-2026-50522, Microsoft SharePoint Server: Site-Owner deserialization RCE (CVSS 9.8)2026-07-142026-07-222026-07-14
CVE-2026-7754CVE-2026-7754, Langflow OSS: SSRF from insecure default configuration (fixed 1.10.1)2026-07-222026-07-22·
CVE-2026-7755CVE-2026-7755, Langflow OSS: RCE via insufficient validation of MCP server config files (fixed 1.10.1)2026-07-222026-07-22·
CVE-2026-8476CVE-2026-8476, Langflow OSS: unsafe deserialization in AsyncDiskCache via apply_tweaks() (fixed 1.10.1)2026-07-222026-07-22·
CVE-2026-8859CVE-2026-8859, Langflow OSS: path-traversal arbitrary file write (fixed 1.10.1)2026-07-222026-07-222026-07-22
CVE-2026-9135CVE-2026-9135, Langflow OSS: code injection in Policies/ToolGuard component (fixed 1.10.1)2026-07-222026-07-222026-07-22
CVE-2026-9202CVE-2026-9202, Langflow OSS: unauthenticated account creation reaching RCE (fixed 1.10.1)2026-07-222026-07-222026-07-22
CVE-2026-2291dnsmasq really_insert() DNS-cache heap buffer overflow (RCE per Exodus; NVD frames as DoS/cache-poisoning)2026-07-212026-07-212026-07-21
CVE-2026-6875ServiceNow AI Platform sandbox escape, unauthenticated code execution within the platform (CVSS 9.5); hosted fixed server-side, self-hosted/partner patch listed family releases2026-07-132026-07-212026-07-13
CVE-2026-42533nginx / NGINX Plus PCRE capture-clobber pre-auth heap overflow (CVSS 9.2); F5 out-of-band patch 2026-07-15/16, credited researcher demonstrates RCE beyond F5's DoS-only framing (no public PoC, no ITW as of 2026-07-20); fixed nginx 1.30.4/1.31.3, NGINX Plus R36 P7/37.0.3.12026-07-202026-07-202026-07-20
CVE-2025-40947Siemens RUGGEDCOM ROX II feature-key gpgv command injection to root (CVSS 7.5); Unit 42 chain2026-07-182026-07-182026-07-18
CVE-2025-40948Siemens RUGGEDCOM ROX II arbitrary file disclosure via root-privileged xz misuse (CVSS 6.8); Unit 42 chain2026-07-182026-07-182026-07-18
CVE-2025-40949Siemens RUGGEDCOM ROX II task-scheduler command injection, persistent root (CVSS 9.1); Siemens SSA-0811422026-07-182026-07-182026-07-18
CVE-2026-47865VMware Avi Load Balancer control-plane unauthenticated authentication bypass (CVSS 9.8), VMSA-2026-00052026-07-182026-07-182026-07-18
CVE-2026-47866VMware Avi Load Balancer authorization bypass (CVSS 8.3), VMSA-2026-00052026-07-182026-07-182026-07-18
CVE-2026-47867VMware Avi Load Balancer high-privilege RCE (CVSS 8.7), VMSA-2026-00052026-07-182026-07-182026-07-18
CVE-2026-47868VMware Avi Load Balancer local privilege escalation to root (CVSS 7.8), VMSA-2026-00052026-07-182026-07-182026-07-18
CVE-2026-47869VMware Avi Load Balancer authenticated RCE (CVSS 8.7), VMSA-2026-00052026-07-182026-07-182026-07-18
CVE-2026-47870VMware Avi Load Balancer privilege escalation (CVSS 7.1), VMSA-2026-00052026-07-182026-07-182026-07-18
CVE-2026-47871VMware Avi Load Balancer authenticated directory traversal (CVSS 8.8), VMSA-2026-00052026-07-182026-07-182026-07-18
CVE-2026-54733Moodle local_o365 plugin JWT-signature-not-verified SSO auth bypass2026-07-182026-07-182026-07-18
CVE-2026-15718Mozilla Firefox WebAssembly engine invalid-pointer memory-safety flaw (public exploit code, no confirmed ITW); fixed 152.0.62026-07-172026-07-172026-07-17
CVE-2026-15719Mozilla Firefox DOM Navigation site-isolation bypass (public exploit code, no confirmed ITW); fixed 152.0.62026-07-172026-07-172026-07-17
CVE-2026-32201Microsoft SharePoint Server on-prem RCE, part of the actively-exploited SharePoint cluster (CISA KEV 2026-04-14), referenced as context in the CVE-2026-58644 exploitation update2026-07-172026-07-17·
CVE-2026-58644CVE-2026-58644, Microsoft SharePoint Server deserialization RCE (CVSS 9.8); confirmed exploited + CISA KEV 2026-07-162026-07-142026-07-172026-07-14
CVE-2023-4346KNX Connection Authorization Option 1 overly-restrictive account-lockout DoS (CVSS 7.5, CWE-645); CISA KEV 2026-07-15, no software patch (procedural mitigation)2026-07-162026-07-162026-07-16
CVE-2026-46817Oracle E-Business Suite / Oracle Payments File Transmission unauthenticated RCE/takeover (CVSS 9.8); CISA KEV 2026-07-15, exploited ITW since 2026-06-27; fixed Oracle May 2026 CPU (12.2.3-12.2.15)2026-06-012026-07-162026-07-16 +1 more
CVE-2025-13162CVE-2025-13162, ABB 800xA for Advant Master / Control Builder A: DLL search-path element (CVSS 4.4)2026-07-152026-07-15·
CVE-2025-14771CVE-2025-14771, ABB T-MAC Plus: authenticated file disclosure (CVSS 9.9)2026-07-152026-07-152026-07-15
CVE-2025-14772CVE-2025-14772, ABB T-MAC Plus: broken access control / authz bypass (CVSS 8.8)2026-07-152026-07-152026-07-15
CVE-2025-14773CVE-2025-14773, ABB T-MAC Plus: stored XSS (CVSS 8.0)2026-07-152026-07-152026-07-15
CVE-2025-14774CVE-2025-14774, ABB T-MAC Plus: Card Reader service DoS (CVSS 7.4)2026-07-152026-07-152026-07-15
CVE-2026-10577CVE-2026-10577, Rockwell 1715-AENTR EtherNet/IP Adapter: unauthenticated debug-port takeover (CVSS 10.0)2026-07-152026-07-152026-07-15
CVE-2026-55944CVE-2026-55944, Microsoft Dynamics NAV / Dynamics 365 Business Central (On-Prem): pre-auth deserialization RCE (CVSS 9.8)2026-07-142026-07-152026-07-14
CVE-2015-5281GRUB 2 Secure Boot bypass (historical), cited by ESET/CERT/CC as an old bug reopened by pre-15.3 UEFI shims lacking SBAT (context in CVE-2026-8863/10797 entry)2026-07-142026-07-14·
CVE-2026-10797Forgotten pre-0.9 UEFI shim signature-length validation mismatch (revocation-check vs signature-verification size divergence), Secure Boot bypass; revoked via Microsoft dbx 2026-06-09 (ESET Research)2026-07-142026-07-142026-07-14
CVE-2026-27690SAP Approuter unauthenticated HTTP request smuggling (CVSS 9.1)2026-07-142026-07-142026-07-14
CVE-2026-44747SAP NetWeaver AS ABAP kernel memory corruption (CVSS 9.9)2026-07-142026-07-142026-07-14
CVE-2026-44761SAP Commerce Cloud hardcoded sample OAuth2 credential (CVSS 9.1)2026-07-142026-07-142026-07-14
CVE-2026-56155Microsoft AD FS local elevation of privilege (exploited zero-day)2026-07-142026-07-142026-07-14
CVE-2026-56164Microsoft SharePoint Server unauthenticated elevation of privilege (exploited zero-day)2026-07-142026-07-142026-07-14
CVE-2026-8863Forgotten pre-0.9 UEFI shim trust-validation weakness (Secure Boot bypass on machines trusting the Microsoft third-party UEFI CA); revoked via Microsoft dbx 2026-06-09 (ESET Research)2026-07-142026-07-142026-07-14
CVE-2008-4128Cisco IOS (end-of-life devices), named by the 2026-07-13 FSB Centre 16 joint advisory as an exploited legacy CVE; no patch (EOL)2026-07-132026-07-13·
CVE-2018-0171Cisco IOS/IOS XE Smart Install pre-auth RCE, actively exploited by FSB Centre 16 / Static Tundra2026-07-132026-07-132026-07-13
CVE-2026-4769WAGO I/O System Field, undocumented early-boot diagnostic interface, unauthenticated full compromise (CWE-912)2026-07-132026-07-132026-07-13
CVE-2026-61500Rejetto HFS < 3.2.1 predictable session-signing PRNG (Math.random) enables pre-auth admin session forgery to RCE via server_code (CVSS 9.3); fixed 3.2.12026-07-132026-07-132026-07-13
CVE-2026-61501Rejetto HFS 3.0.0–3.2.0 stored XSS in admin log via crafted failed-login username; fixed 3.2.12026-07-132026-07-132026-07-13
CVE-2026-61502Rejetto HFS 3.0.0–3.2.0 state-changing admin actions accepted over GET with no anti-CSRF check; fixed 3.2.12026-07-132026-07-132026-07-13
CVE-2026-61503Rejetto HFS 3.0.0–3.2.0 unauthenticated username enumeration (incl. default admin) via login-endpoint response differences; fixed 3.2.12026-07-132026-07-132026-07-13
CVE-2026-61504Rejetto HFS 3.0.0–3.2.0 stored XSS via unescaped filenames in fallback 'basic' listing; fixed 3.2.12026-07-132026-07-132026-07-13
CVE-2026-61505Rejetto HFS 3.0.0–3.2.0 path traversal via lang query parameter (limited JSON file read); fixed 3.2.12026-07-132026-07-132026-07-13
CVE-2026-10698Progress MOVEit Transfer Custom Reports table-scope bypass, admin-privileged (CVSS 7.2; CERT-FR AVI-0856)2026-07-112026-07-112026-07-11
CVE-2026-10699Progress MOVEit Transfer SFTP-service memory-leak pre-auth denial of service (CVSS 7.5; CERT-FR AVI-0856)2026-07-112026-07-112026-07-11
CVE-2026-11903Progress MOVEit Transfer Ad Hoc module stored XSS, low-priv authenticated (CVSS 8.0; CERT-FR AVI-0856)2026-07-112026-07-112026-07-11
CVE-2026-47291Windows HTTP.sys pre-auth kernel RCE (CVSS 9.8); ZDI published full exploitation mechanics + detection signature 2026-07-102026-06-102026-07-112026-06-10
CVE-2026-57827Joomla RSFiles! (com_rsfiles) unauthenticated file-upload RCE (CVSS 4.0 10.0); part of the mySites.guru Joomla-extension CWE-434 wave2026-07-112026-07-112026-07-11
CVE-2026-57828Joomla Phoca Download (com_phocadownload) authenticated file-upload RCE via member-upload allow-list bypass (CVSS 4.0 9.0)2026-07-112026-07-112026-07-11
CVE-2026-60090PraisonAI PGVector/Cassandra knowledge store, SQL/CQL injection via unvalidated vector dimension (CVSS 9.3)2026-07-112026-07-112026-07-11
CVE-2026-61445PraisonAI AICoder, arbitrary file write / command execution via LLM tool calls (CVSS 9.4)2026-07-112026-07-112026-07-11
CVE-2026-61447PraisonAI CodeAgent, unsandboxed LLM-generated Python execution with full env-secret leak (CVSS 10.0)2026-07-112026-07-112026-07-11
CVE-2021-29441Apache Nacos authentication bypass (Nacos-Server User-Agent header) abused by WP-SHELLSTORM for Java-stack credential theft2026-07-102026-07-10·
CVE-2025-5777CitrixBleed 2 (NetScaler ADC/Gateway pre-auth memory over-read), weaponised in the STAC3725 IAB-to-DragonForce kill chain (Huntress)2026-07-012026-07-102026-07-10
CVE-2025-63681Open WebUI /api/tasks/stop/ IDOR, unauthorized task cancellation (unpatched)2026-07-102026-07-102026-07-10
CVE-2025-64496Open WebUI Direct Connections XSS chained to unsandboxed Python exec() → RCE2026-07-102026-07-102026-07-10
CVE-2026-1969WordPress ThemeREX Addons plugin vulnerability weaponized by the WP-SHELLSTORM crew2026-07-102026-07-10·
CVE-2026-20896Gitea Docker reverse-proxy trust-all auth bypass (X-WEBAUTH-USER impersonation), NCSC-CH escalated status to actively-exploited 2026-07-102026-06-232026-07-102026-06-23
CVE-2026-3844WordPress Breeze Cache Cleaner plugin flaw, highest-yield exploit in the WP-SHELLSTORM webshell-brokerage campaign2026-07-102026-07-10·
CVE-2026-44556Open WebUI /api/openai/responses proxy reaches any model without per-model authz2026-07-102026-07-102026-07-10
CVE-2026-44557Open WebUI incomplete collection allowlist exposes knowledge-base metadata to any user2026-07-102026-07-102026-07-10
CVE-2026-44564Open WebUI Socket.IO ydoc:document:update checks room membership not write permission2026-07-102026-07-102026-07-10
CVE-2026-48939iCagenda for Joomla, unauthenticated file-upload-to-RCE, exploited zero-day, CISA KEV2026-07-102026-07-102026-07-10
CVE-2026-54015Open WebUI prompt version-history IDOR (caller-supplied history-ID unauthorized)2026-07-102026-07-102026-07-10
CVE-2026-54798Siemens SICAM 8 HTTP-reachable debug interface → authenticated DoS2026-07-102026-07-102026-07-10
CVE-2026-54799Siemens SICAM 8 firmware-update signature-validation bypass → persistent malicious firmware2026-07-102026-07-102026-07-10
CVE-2026-54800Siemens SICAM 8 ships with OPC UA security disabled by default2026-07-102026-07-102026-07-10
CVE-2026-54801Siemens SICAM 8 web-API admin-account credential-validation bypass → privilege escalation2026-07-102026-07-102026-07-10
CVE-2024-42009Roundcube XSS, exploited by FrostyNeighbor / Ghostwriter (UNC1151) for Polish-targeting credential harvesting2026-05-172026-07-092026-07-09
CVE-2026-12486GeoVision GV-I/O Box 4E unauthenticated OS command injection (Talos, CVSS 9.1)2026-07-092026-07-092026-07-09
CVE-2026-12958AWS Language Servers / Amazon Q Developer symlink trust-boundary write outside workspace (GhostApproval, CWE-61); fixed language-servers 1.69.0 / @aws/lsp-codewhisperer 0.0.1172026-07-092026-07-092026-07-09
CVE-2026-13125GeoVision GeoWebPlayer unauthenticated localhost WebSocket screen-capture (Talos, CVSS 8.8)2026-07-092026-07-092026-07-09
CVE-2026-14480OpenPLC v3 Runtime authenticated arbitrary file-write to native RCE (CVSS 9.9; CISA ICSA-26-190-01, no fix)2026-07-092026-07-092026-07-09
CVE-2026-22879VTK-DICOM heap overflow on crafted DICOM file (Talos, CVSS 8.1)2026-07-092026-07-092026-07-09
CVE-2026-48614Plesk XML API code injection (CWE-94), authenticated low-priv to arbitrary root file write / LPE (CVSS 9.9); CCB Belgium; affected <18.0.30, fixed 18.0.30-18.0.78.4 (18.0.79+ unaffected)2026-07-092026-07-092026-07-09
CVE-2026-50549Cursor IDE sandbox escape via symlink + failed path canonicalization (GhostApproval); fixed Cursor 3.02026-07-092026-07-092026-07-09
CVE-2026-5263wolfSSL registeredID SAN name-constraint bypass (Talos, CVSS 7.4)2026-07-092026-07-092026-07-09
CVE-2026-56291Balbooa Forms for Joomla (com_baforms) unauthenticated file-upload RCE (CWE-434, CVSS 4.0 10.0), zero-day exploited pre-patch; 3rd Joomla-extension file-upload RCE in the 2026-06/07 wave2026-07-092026-07-092026-07-09
CVE-2026-6678wolfSSL PKCS#7 OtherRecipientInfo integer underflow -> heap overflow (Talos, CVSS 7.5)2026-07-092026-07-092026-07-09
CVE-2026-7532wolfSSL iPAddress SAN name-constraint bypass (Talos coordinated disclosure, CVSS 9.1)2026-07-092026-07-092026-07-09
CVE-2020-22653Ruckus wireless router flaw exploited by UAT-7810 for ORB initial access (context; Cisco Talos)2026-07-082026-07-08·
CVE-2020-22658Ruckus wireless router flaw exploited by UAT-7810 for ORB initial access (context; Cisco Talos)2026-07-082026-07-08·
CVE-2023-25717Ruckus wireless router flaw exploited by UAT-7810 for ORB initial access (context; Cisco Talos)2026-07-082026-07-08·
CVE-2025-2492ASUS AiCloud router flaw exploited by UAT-7810 for ORB initial access (context; Cisco Talos)2026-07-082026-07-08·
CVE-2026-20744Hydro-Quebec EV-charging OCPP WebSocket unauthenticated access -> privilege escalation (CVSS 9.8), CISA ICSA-26-188-012026-07-082026-07-082026-07-08
CVE-2026-33017Langflow unauthenticated RCE (build_public_tmp), CISA KEV, exploited in the Langflow IDOR chain2026-07-082026-07-082026-07-08
CVE-2026-40138BeyondTrust RS/PRA pre-auth authentication bypass (CVSS4 9.2), NCSC-CH BT26-032026-07-082026-07-082026-07-08
CVE-2026-40139BeyondTrust RS/PRA pre-auth authentication bypass (CVSS4 9.2), NCSC-CH BT26-032026-07-082026-07-082026-07-08
CVE-2026-40140BeyondTrust RS/PRA unauthenticated DoS (network-communication subsystem), BT26-032026-07-082026-07-082026-07-08
CVE-2026-40141BeyondTrust RS/PRA authenticated broken-access-control (resource access beyond scope), BT26-032026-07-082026-07-082026-07-08
CVE-2026-42952Hydro-Quebec EV-charging: no auth-attempt throttling -> DoS (CVSS 7.5), ICSA-26-188-012026-07-082026-07-082026-07-08
CVE-2026-43499GhostLock, Linux kernel rtmutex use-after-free LPE + container escape, public exploit2026-07-082026-07-082026-07-08
CVE-2026-44383Hydro-Quebec EV-charging: duplicate concurrent sessions per charge-point ID -> DoS (CVSS 7.5), ICSA-26-188-012026-07-082026-07-082026-07-08
CVE-2026-48282Adobe ColdFusion CWE-22 path-traversal RCE (CVSS 10.0), APSB26-68, actively exploited, CISA KEV 2026-07-072026-07-022026-07-082026-07-02
CVE-2026-48908JoomShaper SP Page Builder unauth file-upload RCE (CVSS 10.0), CISA KEV zero-day2026-07-082026-07-082026-07-08
CVE-2026-50746Ubiquiti UniFi Connect unauthenticated command-injection RCE (CVSS 10.0), SAB-0662026-07-082026-07-082026-07-08
CVE-2026-50747Ubiquiti UniFi Talk authenticated SQL injection (CVSS 9.9), SAB-0662026-07-082026-07-082026-07-08
CVE-2026-50748Ubiquiti UniFi Access command injection (CVSS 9.9), SAB-0662026-07-082026-07-082026-07-08
CVE-2026-54402Ubiquiti UniFi OS command injection (CVSS 9.9), SAB-0662026-07-082026-07-082026-07-08
CVE-2026-54403Ubiquiti UniFi OS path-traversal auth-bypass (CVSS 8.6), chainable, SAB-0662026-07-082026-07-082026-07-08
CVE-2026-55115Ubiquiti UniFi Protect SSRF privilege escalation (CVSS 9.9), SAB-0662026-07-082026-07-082026-07-08
CVE-2026-55255Langflow cross-tenant IDOR (CWE-639), actively exploited, CISA KEV, chained with RCE CVE-2026-330172026-07-082026-07-082026-07-08
CVE-2026-56290Joomlack Page Builder CK unauth file-upload RCE (CVSS 10.0), CISA KEV zero-day2026-07-082026-07-082026-07-08
CVE-2026-59509cve-search unauthenticated /fetch_cve_data parameter manipulation exposes admin credential hashes2026-07-052026-07-052026-07-05
CVE-2025-3248Langflow /api/v1/validate/code missing-auth RCE, initial access for the JADEPUFFER agentic ransomware operation2026-07-042026-07-042026-07-04
CVE-2026-13368WatchGuard Fireware OS iked pre-auth use-after-free RCE (IKEv2/LDAP path, CVSS 9.2)2026-07-032026-07-032026-07-03
CVE-2026-20191Cisco Catalyst Center unauthenticated path-traversal arbitrary file read (CVSS 7.5; dropped from §2, awareness only)2026-07-032026-07-03·
CVE-2026-34038Coolify authenticated OS command injection to RCE + secrets exfil (CVSS 9.9)2026-07-032026-07-032026-07-03
CVE-2026-57517Control Web Panel pre-auth blind SQLi to web-shell RCE via INTO DUMPFILE (CVSS 9.8)2026-07-032026-07-032026-07-03
CVE-2026-14439Altium Enterprise Server / Altium 365 Git Service CWE-22 path-traversal to RCE (CVSS 9.4)2026-07-022026-07-022026-07-02
CVE-2026-48276Adobe ColdFusion CWE-434 unrestricted file-upload RCE (CVSS 10.0), APSB26-682026-07-022026-07-022026-07-02
CVE-2026-48277Adobe ColdFusion CWE-20 improper-input-validation RCE (CVSS 10.0), APSB26-682026-07-022026-07-022026-07-02
CVE-2026-48281Adobe ColdFusion CWE-20 improper-input-validation RCE (CVSS 10.0), APSB26-682026-07-022026-07-022026-07-02
CVE-2026-48283Adobe ColdFusion CWE-434 unrestricted file-upload RCE (CVSS 10.0), APSB26-682026-07-022026-07-022026-07-02
CVE-2026-48286Adobe Campaign Classic CWE-863 incorrect-authorization code execution (CVSS 10.0), APSB26-692026-07-022026-07-02·
CVE-2026-48316Adobe ColdFusion CWE-20 improper-input-validation RCE (CVSS 10.0), APSB26-682026-07-022026-07-022026-07-02
CVE-2023-4966Citrix NetScaler ADC/Gateway 'CitrixBleed' session-token memory overread, cited as CVE-2026-8451 lineage context2026-07-012026-07-01·
CVE-2025-12101Citrix NetScaler ADC/Gateway memory-leak (CitrixBleed variant), cited as CVE-2026-8451 lineage context2026-07-012026-07-01·
CVE-2026-10816Citrix NetScaler ADC/Gateway, Management Interface unauthenticated arbitrary file read (CTX696604)2026-07-012026-07-01·
CVE-2026-10817Citrix NetScaler ADC/Gateway, memory overread when TCP TimeStamp enabled on LB/CS/VPN vserver (CTX696604)2026-07-012026-07-01·
CVE-2026-13474Citrix NetScaler ADC/Gateway, CTX696604 companion CVE2026-07-012026-07-01·
CVE-2026-35273Oracle PeopleSoft PeopleTools PSEMHUB pre-auth RCE (CVSS 9.8), zero-day exploited by UNC6240/ShinyHunters2026-06-112026-07-012026-06-28 +1 more
CVE-2026-8655Citrix NetScaler ADC/Gateway, memory-management flaw (Gateway/DNS-proxy/AAA vserver), DoS/undefined control flow (CTX696604)2026-07-012026-07-01·
CVE-2026-13165SzafirHost (KIR e-signature client) JAR parser confusion (JarFile vs JarInputStream, CWE-434) → native-library RCE past signature check; fixed v1.2.22026-06-302026-06-302026-06-30
CVE-2026-33691Progress Kemp LoadMaster, OWASP CRS whitespace-padding file-upload extension-check bypass (high); same bulletin as CVE-2026-80372026-06-092026-06-30·
CVE-2026-43503Linux kernel 'DirtyClone' LPE, SKBFL_SHARED_FRAG drop in __pskb_copy_fclone() + IPsec in-place decrypt; JFrog working exploit on Debian/Ubuntu/Fedora (CVSS 8.8)2026-06-272026-06-302026-06-27
CVE-2026-48558SimpleHelp RMM OIDC SSO auth bypass, forged-token full Technician session + MFA bypass; now actively exploited (CISA KEV 2026-06-29), Djinn infostealer via TaskWeaver loader (CVSS 10.0)2026-06-132026-06-302026-06-30 +1 more
CVE-2026-54305n8n Dynamic Credentials EE, missing ownership/scope checks enable cross-tenant OAuth credential hijack/revoke (CVSS 8.9, GHSA-2j5h-858j-5mpf); NCSC-2026-02122026-06-302026-06-30·
CVE-2026-54307n8n public API, editor-level users read other users' credentials in shared instances (CVSS 8.5); NCSC-2026-02122026-06-302026-06-30·
CVE-2026-55200libssh2 pre-auth heap OOB write in ssh2_transport_read() (CVSS 9.2), public PoC released 2026-06-29; no fixed release tagged yet2026-06-282026-06-302026-06-28
CVE-2026-52806Gogs argument-injection RCE (CVE-2026-52806); now actively exploited in K8s cryptojacking campaign (Wiz)2026-06-142026-06-292026-06-20
CVE-2025-67038Lantronix EDS5000 OS command injection to root (BRIDGE:BREAK; CISA KEV 2026-06-23)2026-06-242026-06-282026-06-24
CVE-2025-8088WinRAR path-traversal (referenced as initial-access exploit in Gamaredon GammaPhish/GammaWorm campaign, Sekoia 2026-06-01)2026-06-022026-06-282026-06-27 +2 more
CVE-2026-10735ShapedPlugin WordPress Pro supply-chain backdoor (build/EDD pipeline compromise)2026-06-232026-06-282026-06-23
CVE-2026-11800Keycloak JWT algorithm confusion -> federated-user impersonation (CVSS 8.1)2026-06-282026-06-282026-06-28
CVE-2026-12789ILIAS 11.0 SQL injection in ilTrQuery learning-progress subsystem (no patch, PoC public)2026-06-232026-06-282026-06-23
CVE-2026-20230Cisco Unified Communications Manager WebDialer unauthenticated SSRF → OS-root file write (SIR Critical); fix 14SU6 / Release 15 COP2026-06-042026-06-282026-06-24 +1 more
CVE-2026-20245Cisco Catalyst SD-WAN Manager command-injection to root; Mandiant confirms pre-disclosure zero-day exploitation; patched (chains CVE-2026-20127/-20182)2026-06-062026-06-282026-06-26 +1 more
CVE-2026-20262Cisco Catalyst SD-WAN Manager web UI authenticated path traversal, arbitrary file write to root RCE; CISA KEV 2026-06-152026-06-162026-06-282026-06-16
CVE-2026-34908Ubiquiti UniFi OS improper access control (chain step 1 to unauth root; CISA KEV 2026-06-23)2026-06-242026-06-282026-06-24
CVE-2026-34909Ubiquiti UniFi OS path traversal (chain step 2 to unauth root; CISA KEV 2026-06-23)2026-06-242026-06-282026-06-24
CVE-2026-34910Ubiquiti UniFi OS improper input validation/command injection to root (CISA KEV 2026-06-23, actively exploited)2026-06-242026-06-282026-06-24
CVE-2026-46331Linux kernel 'pedit COW' LPE, tc act_pedit out-of-bounds write poisons setuid-binary page cache; public weaponised PoC2026-06-272026-06-282026-06-27
CVE-2026-55199libssh2 infinite-loop pre-auth DoS via crafted SSH_MSG_EXT_INFO (CVSS 8.2)2026-06-282026-06-282026-06-28
CVE-2026-58053Gitea act_runner Docker container-hardening bypass to host escape (CVSS 9.4, public PoC)2026-06-282026-06-282026-06-28
CVE-2026-9099Keycloak group-admin to realm-admin privilege escalation2026-06-282026-06-28·
CVE-2026-9800Keycloak policy-enforcer authorization bypass via access-denied-page path (CVSS 8.1)2026-06-282026-06-282026-06-28
CVE-2021-26855Microsoft Exchange Server SSRF (ProxyLogon), cited in 2026-05-16 § 5 deep dive Background as precedent for on-prem Exchange exploitation pattern2026-05-162026-06-27·
CVE-2023-32315Openfire admin-console path-traversal auth bypass, StrikeShark/SharkLoader initial-access vector2026-06-272026-06-27·
CVE-2023-46747F5 BIG-IP TMUI unauthenticated RCE, StrikeShark/SharkLoader initial-access vector2026-06-272026-06-27·
CVE-2024-21762Fortinet FortiOS SSL-VPN out-of-bounds write RCE, StrikeShark/SharkLoader initial-access vector2026-06-272026-06-27·
CVE-2024-36401OSGeo GeoServer OGC-filter RCE, StrikeShark/SharkLoader initial-access vector2026-06-272026-06-27·
CVE-2026-10712GitLab Web IDE workbench stored XSS (CVSS 8.0), patched 19.1.1/19.0.3/18.11.6; assessed, did not clear §2 gate2026-06-262026-06-27·
CVE-2026-12957Amazon Q Developer (VS Code) auto-loads workspace .amazonq/mcp.json without consent, repo-planted code execution + AWS credential theft2026-06-272026-06-272026-06-27
CVE-2026-20127Cisco Catalyst SD-WAN Manager pre-auth RCE (UAT-8616 prior exploitation, Feb 2026)2026-05-152026-06-272026-06-06
CVE-2026-20182Cisco Catalyst SD-WAN Controller/Manager pre-auth authentication bypass (CVSS 10.0, actively exploited by UAT-8616)2026-05-152026-06-272026-06-06 +1 more
CVE-2026-50751Check Point Security Gateway IKEv1 Remote Access/Mobile Access certificate-validation authentication bypass (CVSS 9.3), actively exploited by Qilin affiliate since 2026-05-07, CISA KEV2026-06-092026-06-272026-06-09
CVE-2026-10086GitLab EE Analytics Dashboard stored XSS (CVSS 8.7), patched 19.1.1/19.0.3/18.11.6; assessed, did not clear §2 gate2026-06-262026-06-26·
CVE-2026-12635GitLab repository-mirroring SSRF (CVSS 3.1), patched 19.1.1/19.0.3/18.11.6; low severity, did not clear §2 gate2026-06-262026-06-26·
CVE-2026-8461FFmpeg MagicYUV decoder heap OOB write (PixelSmash, CVSS 8.8), fixed FFmpeg 8.1.2; out-of-window this run2026-06-262026-06-26·
CVE-2026-39893Cacti <1.2.31, pre-auth SQLi in graph_view.php (rfilter); evaluated, dropped to § 7 (out-of-window, single GHSA)2026-06-252026-06-25·
CVE-2026-56422MISP <2.5.42, broken access control2026-06-252026-06-252026-06-25
CVE-2026-56423MISP <2.5.42, cross-org IDOR overwrite2026-06-252026-06-252026-06-25
CVE-2026-56424MISP <2.5.42, broken access control, cross-org hard-delete2026-06-252026-06-252026-06-25
CVE-2026-56425MISP <2.5.42, Azure-AD OAuth state-reuse session hijack2026-06-252026-06-252026-06-25
CVE-2026-56446MISP <2.5.42, NDJSON log-injection PHP RCE (site-admin)2026-06-252026-06-252026-06-25
CVE-2026-56447MISP <2.5.42, rdkafka plugin-load RCE (site-admin)2026-06-252026-06-252026-06-25
CVE-2026-7473Arista EOS tunnel-decapsulation logic flaw (CWE-1023) bypasses VXLAN segmentation; CISA KEV, exploited2026-06-102026-06-252026-06-10
CVE-2024-40766SonicWall SonicOS improper access control (mgmt + SSLVPN, Gen 5/6/7), Akira/Fog ransomware on-ramp2026-06-232026-06-232026-06-23
CVE-2025-59718FortiGate credential-reuse vector referenced in FortiBleed campaign2026-06-232026-06-23·
CVE-2025-59719FortiGate credential-reuse vector referenced in FortiBleed campaign2026-06-232026-06-23·
CVE-2026-20779Gitea TOTP 2FA bypass (web TOCTOU + X-Gitea-OTP replay)2026-06-232026-06-23·
CVE-2026-22874Gitea SSRF in webhook / repo-migration subsystems2026-06-232026-06-23·
CVE-2026-24858FortiGate credential-reuse vector referenced in FortiBleed campaign2026-06-232026-06-23·
CVE-2026-27775Gitea protected-branch enforcement race (single-push batch)2026-06-232026-06-23·
CVE-2026-41947DifyTap, Dify AI platform cross-tenant authorization bypass (evaluated, dropped § 7: authenticated, no ITW, aggregator-only primary)2026-06-232026-06-23·
CVE-2026-47645Microsoft 365 Copilot Business Chat open redirect (BSI WID-SEC-2026-2020; server-side mitigated, dropped § 7)2026-06-232026-06-23·
CVE-2026-47729Squidbleed, 29-year-old heap over-read in Squid FTP gateway leaks cross-user HTTP credentials2026-06-232026-06-232026-06-23
CVE-2026-49777ShapedPlugin supply-chain backdoor, duplicate CVE submission for CVE-2026-10735 (noted § 7)2026-06-232026-06-23·
CVE-2026-54130Microsoft 365 Copilot missing-authentication info disclosure (BSI WID-SEC-2026-2020; server-side mitigated, dropped § 7)2026-06-232026-06-23·
CVE-2013-3307Linksys/D-Link RTL819X command-injection RCE, initial-access vector for the AryStinger botnet2026-06-222026-06-222026-06-22
CVE-2016-5681D-Link DIR-850L HTTP-service stack buffer overflow RCE, AryStinger botnet access vector2026-06-222026-06-222026-06-22
CVE-2025-11837QNAP Malware Remover code injection (fixed 6.6.8.20251023), AryStinger NAS access vector2026-06-222026-06-222026-06-22
CVE-2023-24932Windows Boot Manager Secure Boot bypass (BlackLotus-class), possible FishMonger SprySOCKS UEFI component (unconfirmed)2026-06-172026-06-21·
CVE-2025-13036Rockwell FactoryTalk Historian Site Edition, authentication bypass (CVSS 7.7)2026-06-182026-06-212026-06-18
CVE-2026-0257PAN-OS GlobalProtect pre-auth authentication bypass2026-05-302026-06-212026-05-30
CVE-2026-0646Rockwell 1794-AENTR/AENTRXT FLEX I/O, CIP-handling denial-of-service (CVSS 7.5)2026-06-182026-06-212026-06-18
CVE-2026-0647Rockwell 1794-AENTR/AENTRXT FLEX I/O, unauthenticated web-interface password reset (CVSS 9.4)2026-06-182026-06-212026-06-18
CVE-2026-10795UpdraftPlus WordPress plugin unauthenticated auth-bypass to RCE (all-zero AES key on failed RSA decrypt), CVSS 8.1; actively exploited2026-06-142026-06-212026-06-14
CVE-2026-11317Rockwell CompactLogix/ControlLogix 5370/5570, CIP message major non-recoverable fault DoS (CVSS 7.5)2026-06-182026-06-212026-06-18
CVE-2026-12046pgAdmin 4, unauthenticated pickle.loads RCE primitive in SQL Editor (server mode, CVSS v4 9.5)2026-06-192026-06-212026-06-19
CVE-2026-20181Cisco ISE / ISE-PIC, authenticated path-traversal OS command execution to root (CVSS 9.1)2026-06-192026-06-212026-06-19
CVE-2026-20190Cisco ISE / ISE-PIC, unauthenticated read of sensitive data incl. hashed admin credentials (CVSS 7.5)2026-06-192026-06-212026-06-19
CVE-2026-20253Splunk Enterprise pre-auth RCE via unauthenticated PostgreSQL sidecar REST API proxied by web tier, CVSS 9.82026-06-142026-06-212026-06-14
CVE-2026-2473Google Cloud Vertex AI SDK, predictable staging-bucket cross-tenant pickle RCE ('Pickle in the Middle'); patched 1.148.02026-06-172026-06-21·
CVE-2026-25089FortiSandbox unauthenticated OS command injection in VNC handler (CVSS 9.8); dropped from brief - no inclusion gate cleared2026-06-112026-06-212026-06-12
CVE-2026-35278Oracle PeopleSoft PeopleTools 8.61/8.62 Performance Monitor, missing-auth RCE (CVSS 9.8)2026-06-182026-06-212026-06-18
CVE-2026-39808Fortinet FortiSandbox, JRPC API OS command injection (CVSS 9.8); actively exploited2026-06-122026-06-212026-06-12
CVE-2026-39813Fortinet FortiSandbox, JRPC API path traversal / auth bypass (CVSS 9.1); actively exploited2026-06-122026-06-212026-06-12
CVE-2026-4020Gravity SMTP WordPress plugin unauthenticated info-disclosure (email-connector credential dump), mass-exploited2026-06-212026-06-212026-06-21
CVE-2026-40624AVer PTC500S/PTC115/PTC500+/PTC115+ cameras, unauthenticated RCE via management web interface (CVSS 9.8), CISA ICSA-26-169-012026-06-202026-06-212026-06-20
CVE-2026-42055NGINX, heap overflow in ngx_http_proxy_v2_module/ngx_http_grpc_module (CVSS v4 9.2)2026-06-192026-06-212026-06-19
CVE-2026-42530NGINX, HTTP/3 QUIC use-after-free in ngx_http_v3_module (CVSS v4 9.2)2026-06-192026-06-212026-06-19
CVE-2026-42824Microsoft 365 Copilot Enterprise Search 'SearchLeak' command-injection/info-disclosure; one-click exfil; patched server-side2026-06-162026-06-212026-06-16
CVE-2026-46978Oracle Solaris 11.4 Remote Administration Daemon, unauthenticated flaw (CVSS 10.0), Oracle June 2026 CSPU2026-06-182026-06-212026-06-18
CVE-2026-48611phpBB OAuth improper-authentication account hijack (admin) even when OAuth disabled; CVSS 9.8; fixed 3.3.172026-06-162026-06-212026-06-16
CVE-2026-48907Widget Factory Joomla Content Editor (JCE) <2.9.99.5, unauthenticated profile-import to PHP RCE (CVSS v4 10.0); CISA KEV2026-06-172026-06-212026-06-17
CVE-2026-54420LiteSpeed cPanel/WHM plugin symlink-following on CloudLinux/CageFS shared hosting; exploited ITW May 2026; CISA KEV2026-06-162026-06-212026-06-16
CVE-2026-55803Drupal core, JSON:API PHP object injection (SA-CORE-2026-005, critical)2026-06-192026-06-212026-06-19
CVE-2026-55804Drupal core, deserialization gadget chain (SA-CORE-2026-006)2026-06-192026-06-212026-06-19
CVE-2026-12045pgAdmin 4, AI Assistant read-only-transaction bypass to RCE via COPY TO PROGRAM (CVSS v4 9.4)2026-06-192026-06-192026-06-19
CVE-2026-12048pgAdmin 4, stored XSS via unsanitised PostgreSQL error/EXPLAIN content (CVSS v4 9.3)2026-06-192026-06-192026-06-19
CVE-2026-55806Drupal core, rebuild.php trusted-host bypass (SA-CORE-2026-007)2026-06-192026-06-19·
CVE-2026-55807Drupal core, Media module oEmbed SSRF (SA-CORE-2026-008)2026-06-192026-06-19·
CVE-2026-55808Drupal core, JSON:API/REST image-upload MIME-validation gap (SA-CORE-2026-009)2026-06-192026-06-19·
CVE-2020-25213WP File Manager pre-auth RCE, used as fallback vector in the ErrTraffic ClickFix framework2026-06-172026-06-17·
CVE-2023-52271Topaz Antifraud wsftprm.sys vulnerable kernel driver, DragonForce BYOVD chain2026-06-172026-06-17·
CVE-2025-1055K7 Security K7RKScan.sys vulnerable kernel driver, DragonForce BYOVD chain2026-06-172026-06-17·
CVE-2025-55182React/Next.js Server Actions deserialisation ("React2Shell"), weaponised by PCPJack worm2026-05-102026-06-17·
CVE-2025-61155Tower of Fantasy GameDriverx64.sys vulnerable kernel driver, DragonForce BYOVD chain2026-06-172026-06-17·
CVE-2026-20251Splunk Secure Gateway jsonpickle deserialization RCE (CVSS 8.8), assessed, no §2 gate (no ITW, post-auth); NCSC-NL advisory2026-06-162026-06-16·
CVE-2026-40217LiteLLM Custom Code Guardrails sandbox escape to RCE via exec()/bytecode; CVSS 8.8; fixed v1.83.142026-06-162026-06-162026-06-16
CVE-2026-47101LiteLLM authorization bypass via unvalidated allowed_routes in key-generation; CVSS 8.8; fixed v1.83.142026-06-162026-06-162026-06-16
CVE-2026-47102LiteLLM privilege escalation, self-promote to proxy_admin via /user/update; CVSS 8.8; fixed v1.83.142026-06-162026-06-162026-06-16
CVE-2026-48612phpBB OAuth improper state verification + CSRF session hijack; CVSS 8.0; fixed 3.3.172026-06-162026-06-162026-06-16
CVE-2026-10087GitLab EE Analytics Dashboard stored XSS (CVSS 8.7), assessed, no §2 gate2026-06-152026-06-15·
CVE-2026-34182OpenSSL CMS AuthEnvelopedData integrity bypass (moderate), assessed, out-of-window, not promoted2026-06-152026-06-15·
CVE-2026-47124Traefik v3.x security-policy bypass (GHSA-3g6v-2r68-prfc), assessed, no §2 gate, out-of-window2026-06-152026-06-15·
CVE-2026-47928Adobe ColdFusion unauthenticated no-interaction RCE (CVSS 9.6, APSB26-64; scope change S:C; fixed 2023 Update 20 / 2025 Update 9)2026-06-152026-06-15·
CVE-2026-47932Adobe ColdFusion path-traversal security-feature bypass (CVSS 8.8, APSB26-64), co-disclosed; assessed, not promoted2026-06-152026-06-15·
CVE-2026-7250GitLab CE/EE Grape API unauthenticated DoS (CVSS 7.5), assessed, no §2 gate2026-06-152026-06-15·
CVE-2026-9204GitLab CE/EE Gitaly repository-import SSRF (CVSS 5.3), assessed, no §2 gate2026-06-152026-06-15·
CVE-2020-17103Windows Cloud Filter driver cldflt.sys privilege escalation (MiniPlasma PoC)2026-05-182026-06-142026-05-19
CVE-2022-38028Windows Print Spooler privilege escalation weaponised by APT28 GooseEgg (cited as historical context in Sekoia APT28 retrospective)2026-06-142026-06-14·
CVE-2025-67644LangGraph SQLite checkpointer SQL injection in get_state_history() (CVSS 7.3; fixed langgraph-checkpoint-sqlite 3.0.1)2026-06-132026-06-142026-06-13
CVE-2026-10520Ivanti Sentry pre-auth OS command injection to root (MICS handleMessage), CVSS 10.0; public PoC by watchTowr2026-06-102026-06-142026-06-10
CVE-2026-10523Ivanti Sentry authentication bypass (CWE-288), companion to CVE-2026-105202026-06-102026-06-142026-06-10
CVE-2026-11645Google Chrome V8 out-of-bounds read/write, exploited ITW, CISA KEV; fixed 149.0.7827.1032026-06-102026-06-142026-06-10
CVE-2026-12183BUK TS-G gas-station automation unauthenticated admin bypass, CVSS 9.8 (dropped from brief, aggregator-only sourcing)2026-06-142026-06-14·
CVE-2026-23111Linux kernel nf_tables use-after-free in nft_map_catchall_activate() (single-character genmask inversion), local-root + container escape, working public exploit (Exodus Intelligence), patched upstream 2026-02-05, CVSS 7.82026-06-092026-06-142026-06-09
CVE-2026-28277LangGraph unsafe msgpack deserialization on checkpoint load, chains with SQLi to RCE (CVSS 6.8; fixed langgraph 1.0.10)2026-06-132026-06-142026-06-13
CVE-2026-3300Everest Forms Pro (WordPress) Calculation Addon unauthenticated eval() PHP code injection (CVSS 9.8); mass exploitation since 2026-04-13 creating rogue admin accounts; patched v1.9.13 (2026-03-18)2026-06-082026-06-142026-06-08
CVE-2026-41089Windows Netlogon stack buffer overflow, unauthenticated remote RCE to SYSTEM on domain controllers (CVSS 9.8, May 2026 Patch Tuesday); active ITW exploitation confirmed by CCB Belgium 2026-06-012026-05-132026-06-142026-06-11 +1 more
CVE-2026-44748SAP NetWeaver AS ABAP SAML XML Signature Wrapping (CVSS 9.9), SAP_BASIS 702-9192026-06-102026-06-142026-06-10
CVE-2026-44963Veeam Backup & Replication 12.x authenticated domain-user deserialization RCE (CVSS 9.4); fixed 12.3.2.48542026-06-102026-06-142026-06-10
CVE-2026-45585Windows YellowKey BitLocker bypass via WinRE2026-05-152026-06-142026-05-30 +1 more
CVE-2026-45586Windows CTFMON elevation of privilege (June 2026 Patch Tuesday); referenced in § 7 GreenPlasma cross-source discrepancy note2026-06-112026-06-14·
CVE-2026-45657Windows kernel TCP/IP use-after-free network RCE to SYSTEM (CVSS 9.8)2026-06-122026-06-142026-06-12
CVE-2026-47210vm2 Node.js sandbox escape via WebAssembly JSPI Promise-species bypass, CVSS 9.8 (dropped from brief, out-of-window, no ITW)2026-06-142026-06-14·
CVE-2026-47344TYPO3 Core June 2026 (TYPO3-CORE-SA-2026-006), XSS bypassing the HTML Sanitizer; lead CVE of the 13-advisory batch2026-06-102026-06-142026-06-10
CVE-2026-47895strongSwan libstrongswan identity-clone double-free, unauth RCE over EAP; fixed 6.0.72026-06-102026-06-142026-06-10
CVE-2026-49200Acer Wave-7 mesh router broken access control, unauthenticated cleartext credential log acer_cgi.log exposure (CVSS 10.0, no patch until ~end-June 2026)2026-06-082026-06-142026-06-08
CVE-2026-49201Acer Wave-7 mesh router hardcoded AES key in upload.cgi backup handler, persistent backdoor injection (CVSS 10.0, no patch until ~end-June 2026)2026-06-082026-06-142026-06-08
CVE-2026-49261MariaDB Server Galera wsrep_notify_cmd OS command injection (CVSS 10.0)2026-06-122026-06-142026-06-12
CVE-2026-5027Langflow path traversal (POST /api/v2/files) -> arbitrary file write, pre-auth via default auto-login, exploited ITW2026-06-112026-06-142026-06-11
CVE-2026-27022LangGraph Redis checkpointer RediSearch query injection (CVSS 6.5; fixed @langchain/langgraph-checkpoint-redis 1.0.1)2026-06-132026-06-132026-06-13
CVE-2026-45447OpenSSL PKCS7_verify heap use-after-free on empty SignedData.digestAlgorithms (High; fixed 4.0.1/3.6.3/3.5.7/3.4.6/3.0.21); out-of-window drop this run2026-06-132026-06-13·
CVE-2026-6552GitLab EE Group SAML identity API improper authorization, Group Owner account takeover (CVSS 8.7; fixed 19.0.2/18.11.5/18.10.8), did not clear daily section-2 gate2026-06-132026-06-13·
CVE-2026-26142Nuance PowerScribe unauthenticated deserialization RCE (CVSS 9.8)2026-06-122026-06-122026-06-12
CVE-2026-47643Azure Stack Edge external file path control RCE (CVSS 9.8)2026-06-122026-06-122026-06-12
CVE-2026-48163MariaDB Galera wsrep parameter-injection (companion fix to CVE-2026-49261)2026-06-122026-06-122026-06-12
CVE-2026-48165MariaDB Galera wsrep parameter-injection (companion fix to CVE-2026-49261)2026-06-122026-06-122026-06-12
CVE-2026-48579Exchange Online improper-authorisation information disclosure (CVSS 9.1, service-side fix)2026-06-122026-06-122026-06-12
CVE-2026-35616Fortinet FortiClient EMS 7.4.5/7.4.6; improper-access-control on X-SSL-CLIENT-VERIFY header lets unauth attacker spoof mTLS state and reach management API; ITW exploited to push EKZ Infostealer per Arctic Wolf 2026-05-272026-05-292026-06-112026-05-29
CVE-2026-50507Windows BitLocker physical-access bypass, publicly disclosed, June 2026 Patch Tuesday2026-06-102026-06-112026-06-10
CVE-2026-22732SAP Commerce Cloud / Data Hub missing HTTP security headers via Spring Security (CVSS 9.1)2026-06-102026-06-102026-06-10
CVE-2026-27671SAP NetWeaver/ABAP RFC kernel memory corruption, unauthenticated (CVSS 9.8)2026-06-102026-06-102026-06-10
CVE-2026-40128SAP NetWeaver AS Java Web Container path traversal (CVSS 9.0)2026-06-102026-06-102026-06-10
CVE-2026-44815Windows DHCP Client Service RCE (CVSS 9.8), June 2026 Patch Tuesday2026-06-102026-06-102026-06-10
CVE-2026-47281Visual Studio Code EoP to SYSTEM via malicious .code-workspace (CVSS 9.6)2026-06-102026-06-102026-06-10
CVE-2026-49160Windows HTTP.sys HTTP/2 compression-bomb DoS (IIS analogue of CVE-2026-49975); MaxHeadersCount mitigation2026-06-102026-06-102026-06-10
CVE-2026-49975HTTP/2 Bomb, HPACK dynamic-table amplification + Slowloris stream-hold memory-exhaustion DoS vs nginx/Apache/IIS/Envoy/Pingora; nginx 1.29.8 & Apache mod_http2 2.0.41 patched, IIS/Envoy/Pingora unpatched at disclosure2026-06-042026-06-102026-06-04
CVE-2026-50752Check Point IKEv1 site-to-site VPN MitM via certificate validation weakness (CVSS 7.4), no observed exploitation2026-06-092026-06-092026-06-09
CVE-2021-27137DD-WRT UPnP/SSDP parser stack buffer overflow, FortiGuard-attributed propagation vector for C0XMO/Gafgyt botnet; DOES NOT RESOLVE ON NVD/MITRE (flagged 2026-06-08, vendor-attributed/unverified)2026-06-082026-06-08·
CVE-2026-10881Google Chrome ANGLE graphics engine out-of-bounds read/write → sandbox escape (CVSS 9.6); Chrome 149 record 429-patch release2026-06-072026-06-072026-06-07
CVE-2026-37977Keycloak CORS ACAO reflected from unverified JWT azp claim on UMA endpoint (fixed 26.6.3)2026-06-072026-06-072026-06-07
CVE-2026-39210FFmpeg parser/demuxer heap or stack overflow (depthfirst AI-agent discovery; PoC public, fixed upstream)2026-06-072026-06-072026-06-07
CVE-2026-39211FFmpeg parser/demuxer heap or stack overflow (depthfirst AI-agent discovery; PoC public, fixed upstream)2026-06-072026-06-072026-06-07
CVE-2026-39212FFmpeg parser/demuxer heap or stack overflow (depthfirst AI-agent discovery; PoC public, fixed upstream)2026-06-072026-06-072026-06-07
CVE-2026-39213FFmpeg parser/demuxer heap or stack overflow (depthfirst AI-agent discovery; PoC public, fixed upstream)2026-06-072026-06-072026-06-07
CVE-2026-39214FFmpeg parser/demuxer heap or stack overflow (depthfirst AI-agent discovery; PoC public, fixed upstream)2026-06-072026-06-072026-06-07
CVE-2026-39215FFmpeg parser/demuxer heap or stack overflow (depthfirst AI-agent discovery; PoC public, fixed upstream)2026-06-072026-06-072026-06-07
CVE-2026-39216FFmpeg parser/demuxer heap or stack overflow (depthfirst AI-agent discovery; PoC public, fixed upstream)2026-06-072026-06-072026-06-07
CVE-2026-39217FFmpeg parser/demuxer heap or stack overflow (depthfirst AI-agent discovery; PoC public, fixed upstream)2026-06-072026-06-072026-06-07
CVE-2026-39218FFmpeg parser/demuxer heap or stack overflow (depthfirst AI-agent discovery; PoC public, fixed upstream)2026-06-072026-06-072026-06-07
CVE-2026-4874Keycloak SSRF via OIDC token endpoint manipulation (fixed 26.6.3)2026-06-072026-06-072026-06-07
CVE-2026-8830Keycloak missing server-side WebAuthn credential-registration validation (fixed 26.6.3)2026-06-072026-06-072026-06-07
CVE-2026-9704Keycloak token-exchange privilege escalation via silent subject_token removal (fixed 26.6.3)2026-06-072026-06-072026-06-07
CVE-2026-9792Keycloak ROPC grant bypass of client-policy enforcement (fixed 26.6.3)2026-06-072026-06-072026-06-07
CVE-2026-9802Keycloak refresh-token replay window after server restart resets startupTime (fixed 26.6.3)2026-06-072026-06-072026-06-07
CVE-2026-10854MISP access-control bypass exposing private galaxy metadata to non-admin org users (CVSS 5.3)2026-06-062026-06-06·
CVE-2026-10868MISP mass-assignment account-takeover in UsersController::edit() (CVSS 9.0, patched 2026-06-04)2026-06-062026-06-062026-06-06
CVE-2026-28318SolarWinds Serv-U uncontrolled resource consumption, unauthenticated DoS via Content-Encoding: deflate (CISA KEV 2026-06-05)2026-06-062026-06-062026-06-06
CVE-2026-23479Redis use-after-free in unblockClientOnKey() → GOT-overwrite RCE (post-auth; default-passwordless)2026-06-052026-06-052026-06-05
CVE-2026-34906Simple SA Wirtualna Uczelnia unauthenticated SSTI → RCE (redirectToUrl)2026-06-052026-06-052026-06-05
CVE-2026-34907Simple SA Wirtualna Uczelnia reflected XSS (locale parameter)2026-06-052026-06-052026-06-05
CVE-2026-41283OpenStack Mistral policy-enforcement bypass → authenticated arbitrary code execution (OSSA-2026-020; evaluated and dropped, see brief §7)2026-06-052026-06-05·
CVE-2026-10611MISP OTP bypass, session established in beforeFilter before OTP when LdapAuth.mixedAuth+require_otp both on; fix commit 39b3cb15 / >=2.5.372026-06-042026-06-042026-06-04
CVE-2026-33829Windows Snipping Tool ms-screensketch: URI handler NTLM hash leak, patched April 2026; cited as structural predecessor of unpatched search: URI variant2026-06-042026-06-04·
CVE-2026-41100Microsoft 365 Copilot for Android OAuth-token theft via production debug flag (CVSS 4.4); patched 2026-05-122026-06-042026-06-042026-06-04
CVE-2026-41101Microsoft Word for Android OAuth-token theft via production debug flag (CVSS 7.1); patched 2026-05-122026-06-042026-06-042026-06-04
CVE-2026-41102Microsoft PowerPoint for Android OAuth-token theft via production debug flag (CVSS 7.1); patched 2026-05-122026-06-042026-06-042026-06-04
CVE-2026-42832Microsoft Excel for Android OAuth-token theft via setIsDebugMode(true) debug flag left in production (CVSS 7.7); patched 2026-05-122026-06-042026-06-042026-06-04
CVE-2026-45247Mirasvit Full Page Cache Warmer (Magento 2) unauthenticated PHP object-injection RCE via CacheWarmer cookie; CISA KEV 2026-06-03, ITW from 2026-04-24; fix v1.11.122026-06-042026-06-042026-06-04
CVE-2026-7195Progress Sitefinity CMS web-services improper input validation (CWE-20); BSI WID-SEC-2026-17832026-06-042026-06-04·
CVE-2026-7198Progress Sitefinity CMS OData improper input validation (CVSS 9.8, CWE-20), affects 15.4.8623-15.4.8629; BSI WID-SEC-2026-17832026-06-042026-06-04·
CVE-2026-7201Progress Sitefinity CMS ServiceStack web-services credential exposure (CVSS 8.8, CWE-522); BSI WID-SEC-2026-17832026-06-042026-06-04·
CVE-2026-7312Progress Sitefinity CMS, CWE-522 Insufficiently Protected Credentials (Sitefinity Insight credential disclosure, gated on Insight integration/non-default config); CVSS 10.0 per NVD; BSI WID-SEC-2026-1783; evaluated 2026-06-04, dropped to §7 (no fetchable vendor primary, no ITW)2026-06-042026-06-04·
CVE-2026-7313Progress Sitefinity CMS legacy-branch flaw (CVSS 8.7), affects v8.0-13.3; BSI WID-SEC-2026-17832026-06-042026-06-04·
CVE-2026-7325Devolutions Server LDAP coercion exposing PAM credentials (DEVO-2026-0013, CVSS 7.1); evaluated 2026-06-04, dropped to §7 (no ITW, below §2 gate)2026-06-042026-06-04·
CVE-2026-8181Burst Statistics WordPress 3.4.0-3.4.1.1 unauthenticated REST auth-bypass (is_mainwp_authenticated) → admin impersonation/rogue admin; actively exploited; fix v3.4.22026-06-042026-06-042026-06-04
CVE-2026-8206Kirki WordPress Freeform Page Builder 6.0.0-6.0.6 unauthenticated password-reset hijack → admin account takeover; actively exploited; fix v6.0.72026-06-042026-06-042026-06-04
CVE-2026-9047Devolutions Server MFA bypass via improper factor-key state handling (DEVO-2026-0013, CVSS 7.5); evaluated 2026-06-04, dropped to §7 (no ITW, below §2 gate)2026-06-042026-06-04·
CVE-2022-0492Linux kernel cgroup v1 release_agent container escape (missing CAP_SYS_ADMIN check); CISA KEV 2026-06-022026-06-032026-06-032026-06-03
CVE-2024-21182Oracle WebLogic Server unauth T3/IIOP data access (CVSS 7.5); CISA KEV 2026-06-01 on active exploitation2026-06-022026-06-032026-06-03
CVE-2025-48595Android Framework integer-overflow LPE (no-interaction), limited targeted exploitation; June 2026 bulletin2026-06-032026-06-032026-06-03
CVE-2026-34926Trend Micro Apex One On-Premise relative path traversal fleet-wide code injection2026-05-222026-06-032026-05-22
CVE-2026-40402Windows Hyper-V UAF guest-to-host escape (May 2026 Patch Tuesday); evaluated 2026-06-03, not covered (out-of-window)2026-06-032026-06-03·
CVE-2026-41096Windows DNS Client (dnsapi.dll) heap buffer overflow, RCE via malicious DNS response (CVSS 9.8, May 2026 Patch Tuesday)2026-05-132026-06-032026-05-13
CVE-2026-5426Digital Knowledge KnowledgeDeliver LMS, pre-shared ASP.NET machineKey ViewState deserialization RCE; exploited as zero-day pre-2026-02-242026-05-262026-06-032026-05-26
CVE-2026-42251KAMSOFT KS-SOMED healthcare software, hardcoded FTP credentials in update client allow malicious-update injection / supply-chain (CVSS 4.0 8.7, CERT-PL)2026-06-022026-06-02·
CVE-2026-44825Apache Solr 9.4.0-9.10.1/10.0.0, hardcoded BasicAuth template credentials allow unauthenticated remote admin (CVSS 8.1, BSI WID-SEC-2026-1740); no patch yet, manual workaround2026-06-022026-06-022026-06-02
CVE-2026-46243CIFSwitch, Linux kernel CIFS/SMB-client LPE to root via forged cifs.spnego key requests (19-year-old bug; RHEL9/SLES15/Mint/Kali); dropped from 2026-06-02 brief as out-of-window + no Section 2 gate2026-06-022026-06-02·
CVE-2026-8732WP Maps Pro WordPress plugin <=6.1.0, unauthenticated admin-account creation via disclosed nonce + wp_ajax_nopriv_ handler; actively exploited (CVSS 9.8); fixed 6.1.12026-06-022026-06-022026-06-02
CVE-2026-8931Disig Web Signer 2.0.3-2.5.3, unauthenticated RCE in Slovak eIDAS qualified-signature client (CVSS 4.0 9.4, SK-CERT); fixed 2.5.52026-06-022026-06-022026-06-02
CVE-2026-46818Oracle E-Business Suite, May 2026 CPU critical (referenced in §7, dropped)2026-06-012026-06-01·
CVE-2026-46819Oracle E-Business Suite, May 2026 CPU critical (referenced in §7, dropped)2026-06-012026-06-01·
CVE-2026-46820Oracle E-Business Suite, May 2026 CPU critical (referenced in §7, dropped)2026-06-012026-06-01·
CVE-2026-46821Oracle E-Business Suite, May 2026 CPU critical (referenced in §7, dropped)2026-06-012026-06-01·
CVE-2025-62582Delta Electronics DIAView SCADA, unauthenticated remote database access (predecessor to CVE-2026-9642 mitigation bypass)2026-05-272026-05-31·
CVE-2026-26980Ghost CMS Content API unauthenticated SQLi (CVSS 9.4); ITW-exploited in ClickFix campaign; fixed 6.19.12026-05-252026-05-312026-05-25
CVE-2026-32996Veeam Agent for Microsoft Windows, local privilege escalation enabling arbitrary command execution / lateral movement (CVSS 7.3)2026-05-292026-05-312026-05-29
CVE-2026-32997Veeam Software Appliance (Linux); authenticated Backup Administrator can write arbitrary files (CVSS 8.6)2026-05-292026-05-312026-05-29
CVE-2026-33384QuickCMS (OpenSolution) session fixation, CERT-PL; dropped (niche, CVSS 4.8)2026-05-312026-05-31·
CVE-2026-33386QuickCMS (OpenSolution) MITM-XSS via HTTP plugin fetch, CERT-PL; dropped (niche, CVSS 2.3)2026-05-312026-05-31·
CVE-2026-35087Slican PBX administrative protocol authentication bypass, attacker bypasses login by executing a specific command; CVSS 4.0: 9.3; CERT Polska disclosure 2026-05-272026-05-282026-05-312026-05-28
CVE-2026-35089Slican PBX deterministic secure-key generation from publicly-obtainable system properties, admin credentials recoverable without auth; CVSS 4.0: 8.7; CERT Polska2026-05-282026-05-312026-05-28
CVE-2026-35090Slican PBX remote management modem interface, hardcoded caller-ID bypasses admin auth and temporarily re-enables remote access when configured off; CVSS 4.0: 9.3; CERT Polska2026-05-282026-05-312026-05-28
CVE-2026-41052SUSE Rancher; project-owner role can flip namespace PSA labels to privileged, enabling container-to-host escape (CVSS 8.4)2026-05-292026-05-312026-05-29
CVE-2026-41053SUSE Rancher GitHub App auth, group principals granted for every team in GitHub org to any team-belonging user (CVSS 8.8)2026-05-292026-05-312026-05-29
CVE-2026-4408Samba SAMR RPC server, unauthenticated shell injection via %u substitution in check password script (CVSS 10.0)2026-05-292026-05-312026-05-29
CVE-2026-4480Samba print-command subsystem, unauthenticated shell injection via %J substitution; raw/classic printing only (CVSS 10.0)2026-05-292026-05-312026-05-29
CVE-2026-44848Portainer CE, Docker plugin endpoints not registered in proxy authorization handler; non-admin can install/enable plugins → root host execution (CVSS 9.4)2026-05-292026-05-312026-05-29
CVE-2026-44849Portainer CE Docker Swarm service API, EndpointSecuritySettings restrictions not enforced; non-admin escapes to host via privileged containers (CVSS 9.4)2026-05-292026-05-312026-05-29
CVE-2026-44939SUSE Rancher cluster-import endpoint, command injection via URL-encoded newline in authImage YAML field; control-plane node RCE (CVSS 9.6)2026-05-292026-05-312026-05-29
CVE-2026-4776Mautic API contact-filtering SQL injection (post-auth)2026-05-312026-05-312026-05-31
CVE-2026-48172LiteSpeed User-End cPanel plugin lsws.redisAble priv-esc to root (CVSS 10.0, ITW)2026-05-242026-05-312026-05-24
CVE-2026-4868GitLab CE/EE Duo AI integration, improper user identity resolution allows authenticated user to impersonate another user when triggering Duo AI workflows (CVSS 8.2)2026-05-292026-05-312026-05-29
CVE-2026-48842Roundcube Webmail pre-auth SQL injection in virtuser_query plugin via preg_replace backslash escape bypass; CVSS 8.1; patched in 1.6.16 LTS / 1.7.12026-05-282026-05-312026-05-28
CVE-2026-8992Ivanti Secure Access Client local privilege escalation2026-05-082026-05-312026-05-08
CVE-2026-9058Szafir SDK (KIR) improper certificate verification / auth bypass, Polish qualified e-signature SDK; fixed v4632026-05-262026-05-312026-05-26
CVE-2026-9170IBM HTTP Server / WebSphere Application Server, pre-auth RCE via improper input validation in HTTP request parser (CVSS 9.8); NCSC.ch flagged 2026-05-282026-05-292026-05-312026-05-29
CVE-2026-9312GitHub Enterprise Server < 3.22, unauthenticated SSRF via upload-endpoint path traversal exposes internal services and credentials (CVSS 4.0 = 9.2; GHSA-fwfp-h68w-2hcr)2026-05-272026-05-312026-05-27
CVE-2026-9557Mautic Focus component SSRF (post-auth; reaches internal/cloud-metadata)2026-05-312026-05-312026-05-31
CVE-2026-9558Mautic stored XSS (post-auth)2026-05-312026-05-312026-05-31
CVE-2026-9559Mautic stored XSS / JS injection (post-auth)2026-05-312026-05-312026-05-31
CVE-2026-9642Delta Electronics DIAView SCADA, incomplete fix / mitigation bypass of CVE-2025-62582 unauthenticated remote database access (CVSS 3.1 = 9.8; Tenable TRA-2026-44)2026-05-272026-05-312026-05-27
CVE-2026-9808Mautic file inclusion / path traversal (post-auth)2026-05-312026-05-312026-05-31
CVE-2026-9809Mautic path traversal / file manipulation (post-auth)2026-05-312026-05-312026-05-31
CVE-2026-9811Mautic JavaScript code injection (post-auth)2026-05-312026-05-312026-05-31
CVE-2024-39930Gogs prior argument-injection variant (referenced in Rapid7 2026-05-29 disclosure as same-class predecessor)2026-05-292026-05-29·
CVE-2026-1402GitLab CE/EE, Wiki DoS via insufficient validation of malformed markup (CVSS 6.5)2026-05-292026-05-292026-05-29
CVE-2026-2601GitLab EE; Developer-role users can access deployment data (pipeline environment variables, deployment keys) via missing authorization checks (CVSS 4.3)2026-05-292026-05-292026-05-29
CVE-2026-26194Gogs argument-injection RCE (CVE id claimed by S3 sub-agent, unverified against authoritative NVD entry; Rapid7 publication states no CVE assigned at disclosure; deferred to next-run verification)2026-05-292026-05-29·
CVE-2026-2710GitLab CE/EE, seventh CVE in 19.0.1 / 18.11.4 / 18.10.7 patch release (defender-relevance not enumerated; left to vendor page)2026-05-292026-05-29·
CVE-2026-5296GitLab EE; Developer-role users can bypass group-level flow restrictions when foundational flows enabled (CVSS 4.3)2026-05-292026-05-292026-05-29
CVE-2026-6713GitLab CE/EE, unauthenticated enumeration of private project paths via API (CVSS 5.3)2026-05-292026-05-292026-05-29
CVE-2026-8716GitLab CE/EE; Authenticated users can access CI data from unintended reference types via incorrect reference resolution (CVSS 4.3)2026-05-292026-05-292026-05-29
CVE-2026-8834IBM HTTP Server Administration Server, heap-based buffer overflow (CVSS 8.0)2026-05-292026-05-29·
CVE-2026-8850IBM HTTP Server mod_ibm_upload, DoS via NULL pointer dereference (CVSS 7.5)2026-05-292026-05-29·
CVE-2026-8854IBM HTTP Server mod_mem_cache, DoS via expired pointer dereference (CVSS 7.5)2026-05-292026-05-29·
CVE-2026-8855IBM HTTP Server, RCE in TLS mutual-authentication configurations (CVSS 8.1)2026-05-292026-05-29·
CVE-2026-8856IBM HTTP Server, DoS via uncontrolled resource consumption (CVSS 7.7)2026-05-292026-05-29·
CVE-2026-27771Gitea container registry access-control failure, private repo container images unauthenticatedly pullable across all versions < 1.26.2 (4-year exposure window); Forgejo confirmed affected; § 7 drop 2026-05-282026-05-282026-05-28·
CVE-2026-45321TanStack Router npm credential-stealing payload, exfiltrated Nx contributor GitHub CLI OAuth token (precursor to CVE-2026-48027 Nx Console compromise); CISA KEV 2026-05-272026-05-222026-05-282026-05-28
CVE-2026-48027Nx Console v18.95.0 VS Code extension supply-chain compromise, credential-stealing payload harvested 1Password, Claude Code config, npm, GitHub, AWS creds; CISA KEV 2026-05-272026-05-282026-05-282026-05-28
CVE-2026-48843Roundcube Webmail CSS sanitisation failure via SVG animate attributeName=style, info disclosure / SSRF in HTML email rendering; patched in 1.6.16 LTS / 1.7.12026-05-282026-05-282026-05-28
CVE-2026-48844Roundcube Webmail code injection via LDAP autovalues option; arbitrary PHP code evaluation when option is configured; patched in 1.6.16 LTS / 1.7.12026-05-282026-05-282026-05-28
CVE-2026-48848Roundcube Webmail HTML sanitisation bypass via SVG document permitting CSS injection; patched in 1.6.16 LTS / 1.7.12026-05-282026-05-282026-05-28
CVE-2026-8398DAEMON Tools Lite signed-build trojanisation (12.5.0.2421–12.5.0.2434) via Disc Soft Limited build infrastructure; CISA KEV 2026-05-272026-05-282026-05-282026-05-28
CVE-2026-9256NGINX ngx_http_rewrite_module heap buffer overflow, out-of-bounds write in worker process memory pool via overlapping regex capture groups; CVSS v3.1 8.1 / v4.0 9.2; exploitation attempts per NCSC-NL; § 7 drop (primary 2026-05-22 out-of-window)2026-05-242026-05-28·
CVE-2026-44895yoda-digital mcp-gitlab-server < 0.6.0, no-auth SSE RPC endpoint bound to 0.0.0.0 with wildcard CORS exposes operator GitLab PAT (CVSS 4.0 = 9.2; GHSA-8jr5-6gvj-rfpf); noted in § 7 (niche package)2026-05-272026-05-27·
CVE-2024-12802SonicWall Gen6 SSL-VPN MFA bypass via UPN vs SAM account-name split; Akira-linked actors exploited Feb-Mar 2026; firmware update insufficient without 6-step LDAP reconfiguration2026-05-212026-05-252026-05-21
CVE-2025-32433Erlang SSH RCE (Cisco context), confirmed by Check Point Research as initial-access CVE for The Gentlemen RaaS2026-05-172026-05-25·
CVE-2025-34291Langflow CORS misconfiguration + SameSite=None refresh token theft2026-05-222026-05-252026-05-22
CVE-2026-0300Palo Alto PAN-OS Captive Portal unauthenticated root RCE (CVSS 9.3, ITW, KEV deadline 2026-05-09)2026-05-072026-05-252026-05-18 +2 more
CVE-2026-20223Cisco Secure Workload internal REST API zero-auth Site Admin CVSS 10.02026-05-222026-05-252026-05-22
CVE-2026-2743SEPPmail Secure E-Mail Gateway, pre-auth path traversal in LFT /v1/file.app → arbitrary file write as nobody → RCE via /etc/syslog.conf overwrite2026-05-092026-05-252026-05-09
CVE-2026-31635Linux kernel RxGK rxgk_decrypt_skb() page-cache write (missing COW guard), DirtyDecrypt LPE; affects Fedora / Arch / openSUSE Tumbleweed (CONFIG_RXGK=y)2026-05-202026-05-252026-05-20
CVE-2026-41091Microsoft Defender Malware Protection Engine, link-following EoP to SYSTEM (CWE-59); Engine ≤ 1.1.26030.3008; actively exploited2026-05-202026-05-252026-05-20
CVE-2026-42096Sparx Pro Cloud Server, authenticated SQL injection via database API endpoint; PCS ≤ 6.12026-05-202026-05-252026-05-20
CVE-2026-42097Sparx Pro Cloud Server, pre-auth bypass via model-parameter omission in POST binary blob → unauthenticated SQL query execution; CVSS4 9.32026-05-202026-05-252026-05-20
CVE-2026-42098Sparx Enterprise Architect ≤ 17.1, client-side RBAC bypass via EA client binary patch (CWE-603); CVSS4 8.72026-05-202026-05-252026-05-20
CVE-2026-42099Sparx Pro Cloud Server WebEA, race condition in /data_api/dl_internal_artifact.php → RCE in web-server context (CWE-362); CVSS4 7.72026-05-202026-05-252026-05-20
CVE-2026-42100Sparx Pro Cloud Server, malformed SQL crash (DoS); CWE-8352026-05-202026-05-252026-05-20
CVE-2026-42231n8n self-hosted automation, xml2js prototype pollution (CWE-1321), root of authenticated-to-RCE chain via Git node SSH2026-05-192026-05-252026-05-19
CVE-2026-42822Microsoft Azure Local Disconnected Operations (ALDO), CVSS 10.0 unauthenticated network elevation-of-privilege; MSRC Exploitation More Likely2026-05-212026-05-252026-05-21
CVE-2026-43997vm2 Node.js sandbox, host-object access via BaseHandler.getPrototypeOf trap; sandbox escape to host context; CVSS 10.0; patched 3.11.02026-05-202026-05-252026-05-20
CVE-2026-45498Microsoft Defender Antivirus local DoS, exploited alongside CVE-2026-41091 in combined out-of-band engine update 4.18.26040.72026-05-202026-05-252026-05-20
CVE-2026-45584Microsoft Defender Malware Protection Engine, heap-based buffer overflow over network → unauthenticated RCE in Defender process context; CVSS 8.12026-05-202026-05-252026-05-20
CVE-2026-45829ChromaDB Python FastAPI server pre-auth RCE via embedding-function model loading before auth check (CVSS 4.0 = 10.0; v1.5.9 unpatched at disclosure)2026-05-212026-05-252026-05-21
CVE-2026-7507Keycloak OIDC login flow session fixation enabling account takeover (Keycloak 26.6.2; BSI WID-SEC-2026-1612 HIGH)2026-05-212026-05-252026-05-21
CVE-2026-9082Drupal core highly-critical pre-auth SQL injection in database abstraction API on PostgreSQL backends; CISA KEV-listed 2026-05-22 (SA-CORE-2026-004)2026-05-202026-05-252026-05-20
CVE-2025-9086Stormshield SNS remote DoS (CERTFR-2026-AVI-0631); dropped from §2, mentioned in §72026-05-242026-05-24·
CVE-2026-33278NLnet Labs Unbound DNSSEC validator UAF (CVSS 9.8), fixed 1.25.12026-05-242026-05-242026-05-24
CVE-2026-3593ISC BIND 9 DoH use-after-free (CVSS 7.4), fixed 9.20.232026-05-242026-05-242026-05-24
CVE-2026-37979Keycloak OIDC token introspection endpoint does not enforce audience restriction; lightweight access tokens leak claims cross-client (Keycloak 26.6.2)2026-05-212026-05-242026-05-21
CVE-2026-37982Keycloak execute-actions token replay enabling unauthorised WebAuthn / FIDO2 credential enrollment on victim account (Keycloak 26.6.2)2026-05-212026-05-242026-05-21
CVE-2026-42944NLnet Labs Unbound heap overflow, default-config (CVSS 8.6), fixed 1.25.12026-05-242026-05-242026-05-24
CVE-2026-4630Keycloak Authorization Services Protection API cross-realm IDOR allowing realm-A authenticated attacker to access realm-B resources (Keycloak 26.6.2)2026-05-212026-05-242026-05-21
CVE-2026-46333ssh-keysign-pwn; 9-year ptrace race in Linux kernel __ptrace_may_access() reaches root + SSH host-key exfiltration; four public Qualys exploits on default major distros2026-05-232026-05-242026-05-23
CVE-2026-5946ISC BIND 9 non-Internet CLASS DoS (CVSS 7.5), fixed 9.18.49/9.20.232026-05-242026-05-242026-05-24
CVE-2019-13272Linux kernel ptrace credential-window LPE (Jann Horn, 2019), historical predecessor cited as background in 2026-05-23 CVE-2026-46333 deep dive2026-05-232026-05-23·
CVE-2021-4034PwnKit, polkit pkexec local root (Qualys, 2022), historical reference cited in 2026-05-23 CVE-2026-46333 deep dive as functional-equivalent outcome2026-05-232026-05-23·
CVE-2023-4911Looney Tunables, glibc ld.so local privilege escalation (Qualys, 2023), historical reference cited in 2026-05-23 CVE-2026-46333 deep dive as disclosure-pattern precedent2026-05-232026-05-23·
CVE-2026-23652Microsoft Azure CVSS 10.0 cluster, server-side mitigated, no customer action required (MSRC May 2026)2026-05-222026-05-22·
CVE-2026-40411Microsoft Azure CVSS 10.0 cluster, server-side mitigated, no customer action required (MSRC May 2026)2026-05-222026-05-22·
CVE-2026-42823Microsoft Azure CVSS 10.0 cluster, server-side mitigated, no customer action required (MSRC May 2026)2026-05-222026-05-22·
CVE-2026-42901Microsoft Entra ID / Azure CVSS 10.0 cluster, server-side mitigated, no customer action required (MSRC May 2026)2026-05-222026-05-22·
CVE-2026-47280Microsoft Entra ID / Azure CVSS 10.0 cluster, server-side mitigated, no customer action required (MSRC May 2026)2026-05-222026-05-22·
CVE-2017-7692SquirrelMail post-auth RCE, used by Webworm against Serbian government targets per ESET 2026-05-20 (initial-access probe after credential theft)2026-05-212026-05-21·
CVE-2026-37978Keycloak admin evaluate-scopes endpoint cross-role PII leakage bypassing user-view permissions (Keycloak 26.6.2)2026-05-212026-05-212026-05-21
CVE-2026-6856Keycloak WebAuthn packed self-attestation acceptable-AAGUID policy bypass enabling enrolment of hardware tokens outside policy (Keycloak 26.6.2)2026-05-212026-05-212026-05-21
CVE-2026-26083Fortinet FortiSandbox unauthenticated RCE in Web UI (CWE-862, CVSS 9.1 vendor / 9.8 NVD), pre-auth, patch in 4.4.9 / 5.0.2 / Cloud 5.0.6; Cloud 23/24 require migration2026-05-132026-05-202026-05-13
CVE-2026-26956vm2 Node.js sandbox, symbol-to-string coercion TypeError sandbox bypass; patched 3.10.52026-05-202026-05-202026-05-20
CVE-2026-43999vm2 NodeVM allow-list bypass, Module._load() reachable when child_process is explicitly permitted → OS command execution; CVSS 9.92026-05-202026-05-202026-05-20
CVE-2026-44005vm2 prototype pollution via attacker-controlled JS; CVSS 10.0; affects 3.9.6 – 3.10.5; patched 3.11.02026-05-202026-05-202026-05-20
CVE-2026-44006vm2 code injection via BaseHandler.getPrototypeOf; CVSS 10.0; patched 3.11.02026-05-202026-05-202026-05-20
CVE-2026-44008vm2 null-proto exception exploitation; CVSS 9.8; affects ≤ 3.11.1; patched 3.11.22026-05-202026-05-202026-05-20
CVE-2026-44009vm2 neutralizeArraySpeciesBatch() bypass via null-proto exception; CVSS 9.8; affects ≤ 3.11.1; patched 3.11.22026-05-202026-05-202026-05-20
CVE-2026-44128SEPPmail Secure Email Gateway, unauthenticated RCE via exposed GINAv2 test endpoints (CVSS 9.3)2026-05-092026-05-202026-05-09
CVE-2026-44277Fortinet FortiAuthenticator unauthenticated RCE in management interface (CWE-284, CVSS 9.8), pre-auth, patch in 6.5.7 / 6.6.9 / 8.0.32026-05-132026-05-202026-05-13
CVE-2026-45185Exim 4.97–4.99.2 GnuTLS builds, BDAT/CHUNKING use-after-free (Dead.Letter), pre-auth RCE (CVSS 9.8, ENISA EUVD critical); fixed in Exim 4.99.32026-05-132026-05-202026-05-13
CVE-2026-41702VMware Fusion 25H2 (macOS), TOCTOU SETUID race condition LPE (CVSS 7.8); dropped from § 2 in 2026-05-19 brief (did not clear inclusion gates)2026-05-192026-05-19·
CVE-2026-42232n8n HTTP Request Node injection, companion amplifier to CVE-2026-42231 prototype-pollution chain2026-05-192026-05-192026-05-19
CVE-2026-44789n8n XML Node injection, companion amplifier to CVE-2026-42231 prototype-pollution chain2026-05-192026-05-192026-05-19
CVE-2026-44790n8n Git node SSH chain, terminal sink of CVE-2026-42231 prototype-pollution to RCE2026-05-192026-05-192026-05-19
CVE-2026-44791n8n XML Node injection, companion amplifier to CVE-2026-42231 prototype-pollution chain2026-05-192026-05-192026-05-19
CVE-2026-46351BigBlueButton bbb-web < 3.0.21, insecure sessionToken generation (CWE-330) enables session hijack2026-05-192026-05-192026-05-19
CVE-2026-46353BigBlueButton bbb-web < 3.0.21, presentationUploadExternalUrl API checksum bypass (CWE-284)2026-05-192026-05-192026-05-19
CVE-2026-46404BigBlueButton bbb-web < 3.0.23, SSRF in presentation URL validation (CWE-918)2026-05-192026-05-192026-05-19
CVE-2023-33241Fireblocks GG18/GG20 Paillier missing-ZK-proof flaw (TSSHOCK class; cited as background-class for THORChain 2026-05-15 GG20 TSS exploit)2026-05-182026-05-18·
CVE-2025-54518AMD-SB-7052, Zen 2 µop-cache corruption / SoC isolation LPE (CVSS 7.3 CVSS 4.0)2026-05-162026-05-182026-05-16
CVE-2026-34260SAP S/4HANA Enterprise Search ABAP, authenticated SQL injection in SAP_BASIS 751–758 / 816 (CVSS 9.6)2026-05-132026-05-182026-05-13
CVE-2026-34263SAP Commerce Cloud, unauthenticated arbitrary code execution via Spring Security misordering on cloud-config endpoint (CVSS 9.6, SAP Note 3733064)2026-05-132026-05-182026-05-13
CVE-2026-41103Microsoft SSO Plugin for Jira/Confluence, unauthenticated Entra ID credential forgery (CVSS 9.1, More Likely exploitation)2026-05-132026-05-182026-05-13
CVE-2026-41225F5 BIG-IP iControl REST Manager-role authenticated RCE (May 2026 Quarterly Notification, CVSS 9.1)2026-05-172026-05-182026-05-17
CVE-2026-41553DHTMLX PDF Export Module, unauthenticated server-side JavaScript injection RCE (CVSS 4.0 score 10.0)2026-05-172026-05-182026-05-17
CVE-2026-44088KIR SzafirHost, JAR zip-polyglot signature-verification bypass enabling RCE in Polish qualified e-signature browser helper (CVSS 8.6)2026-05-172026-05-182026-05-17
CVE-2026-44112OpenClaw / Clawdbot, OpenShell sandbox TOCTOU write escape (CVSS 9.6, Claw Chain)2026-05-162026-05-182026-05-16
CVE-2026-45691Nextcloud Server/Enterprise Server 2FA bypass via WebDAV pre-authenticated session token reuse2026-05-152026-05-18·
CVE-2026-45793PHP Composer GitHub Actions token disclosure in error messages (fixed in 2.9.8 / 2.2.28)2026-05-152026-05-18·
CVE-2026-7182DHTMLX Diagram export module, path traversal (CVSS 4.0 score 9.2)2026-05-172026-05-182026-05-17
CVE-2026-8043Ivanti Xtraction < 2026.2 external control of file name/path (CWE-73, CVSS 9.6), arbitrary file read + HTML write to web tree; auth required2026-05-142026-05-182026-05-14
CVE-2023-38831WinRAR file-extension spoofing arbitrary code execution (cited as veteran exploit by Kaspersky Q1 2026 report)2026-05-102026-05-17·
CVE-2025-33073RelayKing NTLM relay, post-access primitive used by The Gentlemen RaaS2026-05-172026-05-17·
CVE-2025-69690Netgate pfSense Community Edition authenticated root RCE, vendor refuses to fix2026-05-112026-05-172026-05-11
CVE-2025-69691Netgate pfSense Community Edition authenticated root RCE companion to CVE-2025-69690, vendor refuses to fix2026-05-112026-05-172026-05-11
CVE-2026-20122Cisco Catalyst SD-WAN companion CVE (exploited since March 2026)2026-05-152026-05-17·
CVE-2026-20128Cisco Catalyst SD-WAN companion CVE (exploited since March 2026)2026-05-152026-05-17·
CVE-2026-20133Cisco Catalyst SD-WAN companion CVE (exploited since March 2026)2026-05-152026-05-17·
CVE-2026-33634Checkmarx Jenkins AST plugin backdoor (TeamPCP/UNC6780 supply-chain compromise, SANDCLOCK credential stealer, CVSS 9.4)2026-05-122026-05-172026-05-12
CVE-2026-34176F5 BIG-IP privilege escalation via misconfigured permissions (May 2026 Quarterly, CVSS 8.7)2026-05-172026-05-17·
CVE-2026-40061F5 BIG-IP privilege escalation via misconfigured permissions (May 2026 Quarterly, CVSS 8.7)2026-05-172026-05-17·
CVE-2026-40631F5 BIG-IP privilege escalation via misconfigured permissions (May 2026 Quarterly, CVSS 8.7)2026-05-172026-05-17·
CVE-2026-40698F5 BIG-IP SSH password exposure in iControl REST audit logs (May 2026 Quarterly, CVSS 8.7)2026-05-172026-05-17·
CVE-2026-41552DHTMLX PDF Export Module, path traversal via src attribute (CVSS 4.0 score 9.2)2026-05-172026-05-172026-05-17
CVE-2026-41953F5 BIG-IP iControl REST command injection (May 2026 Quarterly, CVSS 8.7)2026-05-172026-05-17·
CVE-2026-42406F5 BIG-IP iControl REST command injection (May 2026 Quarterly, CVSS 8.7)2026-05-172026-05-17·
CVE-2026-42898Microsoft Dynamics 365 On-Premises, authenticated code injection with scope change (CVSS 9.9, May 2026 Patch Tuesday)2026-05-132026-05-172026-05-13
CVE-2026-42924F5 BIG-IP iControl REST command injection (May 2026 Quarterly, CVSS 8.7)2026-05-172026-05-17·
CVE-2026-42930F5 BIG-IP iControl REST command injection (May 2026 Quarterly, CVSS 8.7)2026-05-172026-05-17·
CVE-2026-44113OpenClaw / Clawdbot, TOCTOU read escape / file disclosure (CVSS 7.7, Claw Chain)2026-05-162026-05-172026-05-16
CVE-2026-44115OpenClaw / Clawdbot, command-parser allowlist bypass (CVSS 8.8, Claw Chain)2026-05-162026-05-172026-05-16
CVE-2026-44118OpenClaw / Clawdbot, MCP loopback senderIsOwner privilege escalation (CVSS 7.8, Claw Chain)2026-05-162026-05-172026-05-16
CVE-2026-4670Progress MOVEit Automation unauthenticated authentication bypass (CVSS 9.8)2026-05-062026-05-17·
CVE-2026-6073GitLab CE/EE, stored XSS in analytics dashboards (CVSS 8.7); cited as dropped from § 22026-05-172026-05-17·
CVE-2026-6722PHP SOAP extension UAF in SOAP_GLOBAL(ref_map) (with companions CVE-2026-7261, CVE-2026-7262); patched in PHP 8.4.8 / 8.3.22 / 8.2.302026-05-112026-05-172026-05-11
CVE-2026-7261PHP SOAP companion to CVE-2026-6722; patched 2026-05-082026-05-112026-05-172026-05-11
CVE-2026-7262PHP SOAP companion to CVE-2026-6722; patched 2026-05-082026-05-112026-05-172026-05-11
CVE-2026-7377GitLab CE/EE, stored XSS in container registry virtual registry upstreams (CVSS 8.7); cited as dropped from § 22026-05-172026-05-17·
CVE-2026-7481GitLab CE/EE, stored XSS in Jira integration (CVSS 8.7); cited as dropped from § 22026-05-172026-05-17·
CVE-2021-34473Microsoft Exchange Server pre-auth RCE (ProxyShell), cited in 2026-05-16 § 5 deep dive Background2026-05-162026-05-16·
CVE-2023-42793JetBrains TeamCity authentication bypass, cited in 2026-05-16 § 3 SentinelOne CI/CD subversion case study2026-05-162026-05-16·
CVE-2022-20775Cisco SD-WAN local privilege escalation (UAT-8616 version-downgrade re-exploitation technique)2026-05-152026-05-15·
CVE-2026-33825BlueHammer, Windows zero-day by Nightmare Eclipse (confirmed ITW by Huntress, April 2026)2026-05-152026-05-15·
CVE-2026-45690Nextcloud Server SQL injection in column-type parameter (Moderate)2026-05-152026-05-15·
CVE-2026-8511Google Chrome CVE (mentioned in recency-dropped items, 2026-05-12)2026-05-152026-05-15·
CVE-2026-8580Google Chrome CVE (mentioned in recency-dropped items, 2026-05-12)2026-05-152026-05-15·
CVE-2022-41040Microsoft Exchange Server SSRF (ProxyNotShell), cited as initial-access vector in 2026-05-14 FamousSparrow deep dive; chained with CVE-2022-410822026-05-142026-05-14·
CVE-2022-41082Microsoft Exchange Server PowerShell remoting deserialization RCE (ProxyNotShell), cited as initial-access vector in 2026-05-14 FamousSparrow deep dive; chained with CVE-2022-410402026-05-142026-05-14·
CVE-2026-23819HPE ArubaOS AOS-10 stored XSS in web management interface (CVSS 8.8); referenced in 2026-05-14 § 7 drop note (gate not cleared)2026-05-142026-05-14·
CVE-2026-44211Cline kanban npm package cross-origin WebSocket hijack (CVSS 9.6); referenced in 2026-05-14 § 7 drop note (out-of-window)2026-05-142026-05-14·
CVE-2026-34259SAP Forecasting & Replenishment, authenticated OS-command injection (CVSS 8.2, SAP May 2026 patch day)2026-05-132026-05-13·
CVE-2026-40361Microsoft Word Preview Pane RCE (CVSS 8.4, More Likely exploitation, May 2026 Patch Tuesday)2026-05-132026-05-13·
CVE-2026-40364Microsoft Word Preview Pane RCE (CVSS 8.4, More Likely exploitation, May 2026 Patch Tuesday)2026-05-132026-05-13·
CVE-2026-40366Microsoft Word Preview Pane RCE (CVSS 8.4, May 2026 Patch Tuesday)2026-05-132026-05-13·
CVE-2026-40367Microsoft Word Preview Pane RCE (CVSS 8.4, May 2026 Patch Tuesday)2026-05-132026-05-13·
CVE-2026-40478Earlier Thymeleaf CVE referenced in § 7 disambiguating the dropped Thymeleaf item; CSO Online article 2026-04-17 covered this CVE rather than CVE-2026-419012026-05-132026-05-13·
CVE-2026-41901Thymeleaf SSTI sandbox bypass, referenced in § 7 explaining out-of-window drop (GHSA published 2026-04-29)2026-05-132026-05-13·
CVE-2024-1708ConnectWise ScreenConnect path traversal, chained with CVE-2024-1709 by Kimsuky/Storm-1175; KEV deadline 2026-05-12 (out-of-window per § 7 of 2026-05-12 brief)2026-05-122026-05-12·
CVE-2024-1709ConnectWise ScreenConnect authentication bypass (CVSS 10.0), chained with CVE-2024-1708; cited as 2026-05-12 drop2026-05-122026-05-12·
CVE-2026-0073Android adbd wireless ADB authentication bypass (CVSS 8.8, adjacent-network, public PoC 2026-05-11), § 2 gate not cleared2026-05-122026-05-12·
CVE-2026-5786Ivanti EPMM remote authenticated → administrative-access via improper access control (CVSS 8.8, May 2026 update)2026-05-082026-05-122026-05-08
CVE-2026-5787Ivanti EPMM on-prem improper certificate validation → pre-auth Sentry impersonation (CVSS 9.1, ITW, KEV chain)2026-05-082026-05-122026-05-08
CVE-2026-5788Ivanti EPMM unauthenticated arbitrary method invocation (CVSS 7.0, May 2026 update)2026-05-082026-05-122026-05-08
CVE-2026-6973Ivanti EPMM on-prem admin API improper input validation → RCE (CVSS 7.2, ITW, KEV deadline 2026-05-10)2026-05-082026-05-122026-05-08
CVE-2026-7821Ivanti EPMM; fourth companion CVE in May 2026 EPMM update (high-severity per BleepingComputer / SecurityWeek)2026-05-082026-05-122026-05-08
CVE-2017-11882Microsoft Office Equation Editor RCE (cited as veteran exploit by Kaspersky Q1 2026 exploit report)2026-05-102026-05-10·
CVE-2018-0802Microsoft Office Equation Editor RCE (cited as largest-share detected exploit by Kaspersky Q1 2026 report)2026-05-102026-05-10·
CVE-2023-35078Ivanti EPMM pre-auth API access (2023, exploited by APT29; cited as historical precedent in 2026-05-08 deep dive)2026-05-082026-05-10·
CVE-2024-57726SimpleHelp RMM unauthenticated privilege escalation (ITW)2026-05-072026-05-10·
CVE-2024-57728SimpleHelp RMM path traversal, unauthenticated file download (ITW)2026-05-072026-05-10·
CVE-2024-7399Samsung MagicINFO 9 Server unauthenticated arbitrary file write → RCE (CVSS 8.8, ITW)2026-05-072026-05-10·
CVE-2025-0283Ivanti EPMM critical (January 2025, state-actor exploitation; cited as historical precedent in 2026-05-08 deep dive)2026-05-082026-05-10·
CVE-2025-29927Next.js middleware authorisation bypass via crafted header, weaponised by PCPJack worm2026-05-102026-05-10·
CVE-2025-48703CentOS Web Panel FileManager shell injection, weaponised by PCPJack worm2026-05-102026-05-10·
CVE-2025-68670xrdp pre-authentication stack buffer overflow → RCE2026-05-092026-05-102026-05-09
CVE-2025-9501W3 Total Cache PHP injection via mfunc comment processor, weaponised by PCPJack worm2026-05-102026-05-10·
CVE-2026-1281Ivanti EPMM January 2026 critical, historical precedent cited in 2026-05-09 Ivanti UPDATE2026-05-092026-05-10·
CVE-2026-1340Ivanti EPMM January 2026 critical companion, historical precedent cited in 2026-05-09 Ivanti UPDATE2026-05-092026-05-10·
CVE-2026-1357WPVivid Backup unauthenticated file upload, weaponised by PCPJack worm2026-05-102026-05-10·
CVE-2026-20034Cisco Unity Connection authenticated RCE in management API (CVSS 8.8, NATO NCSC discovery; logged § 7, dropped from § 2, gate not cleared)2026-05-102026-05-10·
CVE-2026-20035Cisco Unity Connection unauthenticated SSRF in default-enabled Web Inbox (CVSS 7.2; logged § 7, dropped from § 2, gate not cleared)2026-05-102026-05-10·
CVE-2026-21510Windows Shell LNK exploit predecessor, APT28 weaponised against Ukraine and EU; February 2026 patch left CVE-2026-32202 residual2026-05-102026-05-10·
CVE-2026-23918Apache HTTP Server 2.4.66 HTTP/2 double-free, DoS and potential RCE (CVSS 8.8)2026-05-062026-05-10·
CVE-2026-23926Zabbix frontend stored XSS in map element labels (CVSS 6.1)2026-05-072026-05-10·
CVE-2026-23927Zabbix API confidentiality; unprivileged user can read admin host data (CVSS 5.3)2026-05-072026-05-10·
CVE-2026-23928Zabbix frontend reflected XSS in host-group filter (CVSS 6.1)2026-05-072026-05-10·
CVE-2026-25592Microsoft Semantic Kernel .NET SDK, unintended [KernelFunction] on SessionsPythonPlugin Download/UploadFileAsync → arbitrary file write → sandbox escape (CVSS 9.9)2026-05-102026-05-102026-05-10
CVE-2026-26030Microsoft Semantic Kernel Python SDK, prompt-injection-to-RCE via InMemoryVectorStore filter (CVSS 9.9, PoC public)2026-05-102026-05-102026-05-10
CVE-2026-28780Apache httpd mod_proxy_ajp heap overflow → remote crash / potential RCE (CVSS 7.5)2026-05-072026-05-10·
CVE-2026-29201cPanel/WHM CVE cluster, dropped from § 3 (embargoed, gate not cleared)2026-05-092026-05-102026-05-10
CVE-2026-29202cPanel/WHM CVE cluster, dropped from § 3 (embargoed, gate not cleared)2026-05-092026-05-102026-05-10
CVE-2026-29203cPanel/WHM unsafe symlink handling, chmod abuse on arbitrary files (CVSS 8.8, second emergency TSR)2026-05-092026-05-102026-05-10
CVE-2026-32202Windows Shell protection mechanism failure → NTLM coercion / spoofing (CVSS 4.3, APT28 ITW, KEV deadline 2026-05-12)2026-05-082026-05-102026-05-08
CVE-2026-32305Traefik proxy mTLS bypass via fragmented TLS ClientHello2026-05-062026-05-10·
CVE-2026-32312GLPI < 10.0.25 / 11.0.7 SSRF (CERTFR-2026-AVI-0551)2026-05-082026-05-102026-05-08
CVE-2026-33725Metabase Enterprise Java serialization → authenticated RCE (CVSS 8.8)2026-05-072026-05-10·
CVE-2026-40108GLPI < 10.0.25 / 11.0.7 data integrity compromise (CERTFR-2026-AVI-0551)2026-05-082026-05-102026-05-08
CVE-2026-40981Spring Cloud Config Server Google Secrets Manager backend flaw (HIGH)2026-05-092026-05-10·
CVE-2026-40982Spring Cloud Config Server pre-auth directory traversal (CVSS 9.8)2026-05-092026-05-102026-05-09
CVE-2026-41002Spring Cloud Config Server companion CVE (HIGH)2026-05-092026-05-10·
CVE-2026-41004Spring Cloud Config Server companion CVE (MEDIUM)2026-05-092026-05-10·
CVE-2026-41940cPanel/WHM authentication bypass via CRLF injection (mass exploitation ongoing, KEV)2026-05-062026-05-10·
CVE-2026-42208LiteLLM Proxy pre-auth SQL injection, all upstream LLM API keys at risk (CVSS 9.3, KEV deadline 2026-05-11)2026-05-092026-05-102026-05-09
CVE-2026-42317GLPI < 10.0.25 / 11.0.7 XSS (CERTFR-2026-AVI-0551)2026-05-082026-05-102026-05-08
CVE-2026-42318GLPI < 10.0.25 / 11.0.7 XSS (CERTFR-2026-AVI-0551)2026-05-082026-05-102026-05-08
CVE-2026-42320GLPI < 10.0.25 / 11.0.7 XSS (CERTFR-2026-AVI-0551)2026-05-082026-05-102026-05-08
CVE-2026-42321GLPI < 10.0.25 / 11.0.7 XSS (CERTFR-2026-AVI-0551)2026-05-082026-05-102026-05-08
CVE-2026-44125SEPPmail GINAv2, missing authentication in admin REST API (CVSS 9.3)2026-05-092026-05-102026-05-09
CVE-2026-44126SEPPmail GINAv2, insecure deserialisation via session cookie → RCE (CVSS 9.2)2026-05-092026-05-102026-05-09
CVE-2026-44127SEPPmail appliance management, LFI and arbitrary file deletion (CVSS 8.8)2026-05-092026-05-102026-05-09
CVE-2026-44129SEPPmail GINAv2, server-side template injection via Freemarker (CVSS 8.3)2026-05-092026-05-102026-05-09
CVE-2026-5174Progress MOVEit Automation authenticated privilege escalation (CVSS 8.8)2026-05-062026-05-10·
CVE-2026-5385GLPI < 10.0.25 / 11.0.7 security policy bypass / auth bypass (CERTFR-2026-AVI-0551)2026-05-082026-05-102026-05-08
CVE-2026-6022Progress Telerik RadAsyncUpload DoS via path traversal (CVSS 7.5)2026-05-072026-05-10·
CVE-2026-6023Progress Telerik RadFilter deserialization → unauthenticated RCE (CVSS 9.8)2026-05-072026-05-10·
CVE-2026-7864SEPPmail appliance management, information disclosure (CVSS 6.9)2026-05-092026-05-102026-05-09
CVE-2026-25077Apache CloudStack post-auth authentication token flaw, dropped from § 3 (gate not cleared)2026-05-092026-05-09·
CVE-2026-21509Microsoft Office Protected View bypass, security feature bypass (CVSS 7.8, KEV deadline 2026-02-16 already passed; deferred from §4)2026-05-082026-05-08·
CVE-2026-21513Microsoft Office Protected View chain CVE (deferred from §4; see CVE-2026-21509 series)2026-05-082026-05-08·
CVE-2026-21514Microsoft Office Protected View chain CVE (deferred from §4; see CVE-2026-21509 series)2026-05-082026-05-08·