CVEs
1147 CVEs referenced across all briefs. Click an ID for the full appearance trail.
Total CVEs
1147
2008 – 2026
Recent (30 d)
237
entities with new coverage in window
Distinct sources
290
hosts cited at least once
Total appearances
946
brief-section attributions
Co-occurrence links
4309
entity ↔ entity in same item
Recent coverage
Aggregate mentions per ISO week, last 21 weeks.
By year
| CVE | Title | First seen | Last seen | Latest coverage |
|---|---|---|---|---|
| CVE-2026-28324 | SolarWinds Observability Self-Hosted: unauthenticated RCE via insufficient integrity checks (CVSS 9.8), no confirmed exploitation | 2026-09-24 | 2026-09-24 | · |
| CVE-2026-28325 | SolarWinds Observability Self-Hosted: unauthenticated RCE via deserialization of untrusted data (CVSS 8.8), no confirmed exploitation | 2026-09-24 | 2026-09-24 | · |
| CVE-2026-87902 | WordPress Core: unauthenticated page-template path traversal to conditional RCE, actively exploited within 24h of patch with a named public Nuclei template | 2026-09-24 | 2026-09-24 | · |
| CVE-2026-43641 | Softaculous Virtualizor: unauthenticated OS command injection to root via billing-module hook | 2026-09-23 | 2026-09-23 | 2026-09-23 |
| CVE-2026-43642 | Softaculous Virtualizor: unauthenticated PHP object injection in billing-module hook | 2026-09-23 | 2026-09-23 | 2026-09-23 |
| CVE-2026-43643 | Softaculous Virtualizor: unauthenticated cross-tenant balance write via billing-module hook | 2026-09-23 | 2026-09-23 | 2026-09-23 |
| CVE-2026-67276 | MikroTik RouterOS SSH signature-verification bypass (MikroTrick component); CERT Polska confirms active exploitation | 2026-09-06 | 2026-09-23 | 2026-09-06 |
| CVE-2026-67279 | MikroTik RouterOS SSH pre-auth rekey exec request, unauthenticated managed-file-namespace write | 2026-09-06 | 2026-09-23 | 2026-09-06 |
| CVE-2026-85102 | Check Point Quantum Security Gateway/Spark Firewall, improper certificate validation, unauthenticated RCE in VPN negotiation (CVSS 9.8) | 2026-09-10 | 2026-09-23 | 2026-09-10 |
| CVE-2026-93616 | Check Point Security Management: pre-auth path traversal to arbitrary script execution, exploited as a zero-day since July | 2026-09-23 | 2026-09-23 | 2026-09-23 |
| CVE-2026-93952 | Arista VeloCloud Orchestrator: actively exploited, two release trains still have no fix | 2026-09-23 | 2026-09-23 | 2026-09-23 |
| CVE-2026-94127 | F5 BIG-IP APM: unauthenticated heap overflow in OAuth-profile processing reaches RCE | 2026-09-23 | 2026-09-23 | 2026-09-23 |
| CVE-2026-13639 | Synology DSM, unauthenticated insufficient login-logic entropy, arbitrary file read/write and DoS | 2026-09-22 | 2026-09-22 | 2026-09-22 |
| CVE-2026-13673 | Synology DSM, authenticated LDAP API permission flaw, arbitrary file read/write and DoS | 2026-09-22 | 2026-09-22 | 2026-09-22 |
| CVE-2026-13684 | Synology DSM, unauthenticated SCGI output-encoding bug, arbitrary file read/write and DoS | 2026-09-22 | 2026-09-22 | 2026-09-22 |
| CVE-2026-50343 | Windows Install Service "Dark Elevator" privesc, incomplete fix later closed by CVE-2026-66804 | 2026-09-22 | 2026-09-22 | 2026-09-22 |
| CVE-2026-6205 | Synology DSM, authenticated Upload API path-control flaw, arbitrary file write and DoS | 2026-09-22 | 2026-09-22 | 2026-09-22 |
| CVE-2026-66804 | Windows Cross Device Service, dangling COM registration reaches SYSTEM privesc (Google Project Zero) | 2026-09-22 | 2026-09-22 | 2026-09-22 |
| CVE-2026-7273 | Zyxel GS1900 Series Switches stack-based buffer overflow, exploited at scale by an actor GreyNoise assesses overlaps Red Heron, CISA KEV | 2026-09-22 | 2026-09-22 | 2026-09-22 |
| CVE-2019-0708 | BlueKeep, Windows RDP pre-auth RCE (2019), exploited by NightEagle/APT-Q-95 for local-account creation and by BlueMoon-adjacent chains historically | 2026-09-21 | 2026-09-21 | 2026-09-21 |
| CVE-2020-0688 | Microsoft Exchange Server post-auth RCE via ViewState (2020), exploit component bundled into NightEagle/APT-Q-95's GhostContainer Exchange backdoor | 2026-09-21 | 2026-09-21 | 2026-09-21 |
| CVE-2020-1472 | ZeroLogon, Netlogon privilege escalation; chained by Cl0p in South Staffordshire Water 2020-2022 intrusion (cited in ICO 2026-05-11 enforcement) | 2026-05-12 | 2026-09-21 | · |
| CVE-2025-24799 | GLPI unauthenticated SQL injection via the inventory endpoint, exploited by an operator associated with The Gentlemen RaaS for initial access | 2026-09-21 | 2026-09-21 | 2026-09-21 |
| CVE-2026-71133 | Oracle Access Manager (Authentication Engine), unauthenticated flaw over HTTP, CVSS 10.0, September 2026 CSPU | 2026-09-20 | 2026-09-20 | 2026-09-20 |
| CVE-2026-83020 | Oracle Platform Security for Java (centralized third-party jars), unauthenticated flaw over HTTP, CVSS 10.0, September 2026 CSPU | 2026-09-20 | 2026-09-20 | 2026-09-20 |
| CVE-2026-83021 | Oracle WebLogic Server (Web Container), unauthenticated flaw over HTTP, CVSS 10.0, September 2026 CSPU | 2026-09-20 | 2026-09-20 | 2026-09-20 |
| CVE-2026-83059 | Oracle Internet Directory (OID LDAP Server), unauthenticated flaw over LDAP, CVSS 10.0, September 2026 CSPU | 2026-09-20 | 2026-09-20 | 2026-09-20 |
| CVE-2026-83099 | Oracle Forms (Forms Services), unauthenticated flaw over HTTP, CVSS 10.0, September 2026 CSPU | 2026-09-20 | 2026-09-20 | 2026-09-20 |
| CVE-2026-87230 | Oracle Hyperion Financial Management (Security), unauthenticated flaw over HTTP, CVSS 10.0, September 2026 CSPU | 2026-09-20 | 2026-09-20 | 2026-09-20 |
| CVE-2025-39682 | Linux Kernel kTLS receive-path zero-length record logic error, CISA KEV 2026-09-18, network-reachable with kernel TLS receive offload | 2026-09-19 | 2026-09-19 | 2026-09-19 |
| CVE-2025-39964 | Linux Kernel AF_ALG crypto-socket concurrent-write race condition, CISA KEV 2026-09-18, local | 2026-09-19 | 2026-09-19 | 2026-09-19 |
| CVE-2026-53266 | Linux Kernel netfilter bridge ebtables SNAT ARP-rewrite out-of-bounds write, CISA KEV 2026-09-18, local | 2026-09-19 | 2026-09-19 | 2026-09-19 |
| CVE-2026-81642 | NLnet Labs Unbound DNSSEC-validator self-referencing compression-pointer heap overflow, RCE possible (CVSS4.0 9.1) | 2026-09-19 | 2026-09-19 | 2026-09-19 |
| CVE-2026-82717 | NLnet Labs Unbound CNAME-synthesis heap corruption during upstream response processing, RCE possible under specific builds (CVSS4.0 8.4) | 2026-09-19 | 2026-09-19 | 2026-09-19 |
| CVE-2026-20130 | Cisco Identity Services Engine CWE-class-grouped bundle CVE from the Sept 2026 hardening release (CVSS 10.0), not reported exploited | 2026-09-17 | 2026-09-18 | 2026-09-17 |
| CVE-2026-20192 | Cisco Identity Services Engine CWE-class-grouped bundle CVE from the Sept 2026 hardening release (CVSS 10.0), not reported exploited | 2026-09-17 | 2026-09-18 | 2026-09-17 |
| CVE-2026-20242 | Cisco Secure Firewall Management Center Java deserialization RCE via External Database Access allowlist (CVSS 9.8), not reported exploited | 2026-08-04 | 2026-09-18 | 2026-08-04 |
| CVE-2026-20324 | Cisco Secure Firewall Management Center sftunnel arbitrary file write to root (CVSS 9.9), requires existing low-privilege device credentials, not reported exploited | 2026-08-04 | 2026-09-18 | 2026-08-04 |
| CVE-2026-76423 | Cisco Identity Services Engine sibling unauthenticated API authentication bypass (CVSS 10.0), not yet confirmed exploited | 2026-09-17 | 2026-09-18 | 2026-09-17 |
| CVE-2026-76460 | Cisco Identity Services Engine unauthenticated API authentication bypass to root (CVSS 10.0), confirmed exploited, found via a TAC support case | 2026-09-17 | 2026-09-18 | 2026-09-17 |
| CVE-2026-87886 | Acronis Backup plugin for cPanel & WHM/Plesk local privilege escalation via insecure default permissions (CVSS 7.8), CISA KEV-listed 2026-09-16, exploitation basis is a single customer report | 2026-09-18 | 2026-09-18 | 2026-09-18 |
| CVE-2026-91843 | Check Point Security Management/Multi-Domain Security Management/Log Server unauthenticated stack overflow in login process to root RCE (CVSS 9.8), no confirmed exploitation, LivePatch fix | 2026-09-18 | 2026-09-18 | 2026-09-18 |
| CVE-2026-58704 | Google Pixel cellular-modem zero-click privilege escalation, exploited in limited targeted attacks, CISA KEV 2026-09-16 | 2026-09-17 | 2026-09-17 | 2026-09-17 |
| CVE-2026-85706 | GitLab CE/EE unauthenticated path traversal in repository commits API, arbitrary file read, CVSS 10.0 | 2026-09-12 | 2026-09-16 | 2026-09-12 |
| CVE-2026-87719 | GitLab EE insecure GraphQL-subscription deserialization, Advanced Search config/credential exposure via Duo Chat (CVSS 9.9), same 19.3.2 release as CVE-2026-85706 | 2026-09-12 | 2026-09-16 | 2026-09-12 |
| CVE-2026-20353 | Cisco Secure Email Gateway / Secure Email and Web Manager, uncontrolled resource consumption grouping, September 2026 hardening release, not reported exploited | 2026-09-15 | 2026-09-15 | 2026-09-15 |
| CVE-2026-76440 | Cisco Secure Email Gateway / Secure Email and Web Manager, path-traversal grouping, September 2026 hardening release, not reported exploited | 2026-09-15 | 2026-09-15 | 2026-09-15 |
| CVE-2026-76441 | Cisco Secure Email Gateway / Secure Email and Web Manager, improper access control grouping, September 2026 hardening release, not reported exploited | 2026-09-15 | 2026-09-15 | 2026-09-15 |
| CVE-2026-76442 | Cisco Secure Email Gateway / Secure Email and Web Manager, input-validation grouping, September 2026 hardening release, not reported exploited | 2026-09-15 | 2026-09-15 | 2026-09-15 |
| CVE-2026-76443 | Cisco Secure Email Gateway / Secure Email and Web Manager, second injection-class grouping, September 2026 hardening release, distinct from the exploited CVE-2026-76461 | 2026-09-15 | 2026-09-15 | 2026-09-15 |
| CVE-2026-76461 | Cisco Secure Email Gateway, unauthenticated SQL injection in email parsing reaches root command execution, exploited, CISA KEV (3-day deadline) | 2026-09-15 | 2026-09-15 | 2026-09-15 |
| CVE-2026-82329 | JFrog Artifactory auth-bypass, CVSS 9.8, now confirmed under active exploitation (watchTowr, NCSC-CH); attackers minting admin tokens via a default 'phantom' join key | 2026-09-01 | 2026-09-15 | 2026-09-01 |
| CVE-2026-20079 | CVE-2026-20079, Cisco Secure Firewall Management Center web interface: unauthenticated authentication bypass to root via a boot-time csm_processes session (CVSS 10.0, CWE-288); disclosed 2026-03-04 with no fix, per-train hot fixes added to the advisory 2026-07-31; Cisco reports no known malicious use, VulnCheck built a working exploit | 2026-08-04 | 2026-09-13 | 2026-08-04 |
| CVE-2026-20316 | CVE-2026-20316; Cisco Secure Firewall Management Center ships a static low-privilege account in its web interface, and Cisco confirms exploitation has been ongoing | 2026-07-30 | 2026-09-13 | 2026-07-30 |
| CVE-2026-85046 | Google Chrome V8 type confusion, actively exploited via a crafted HTML page | 2026-09-04 | 2026-09-13 | 2026-09-10 +1 more |
| CVE-2026-85880 | Windows ALPC heap-based buffer overflow EoP / AppContainer sandbox escape to SYSTEM (CVSS 7.8), actively exploited zero-day, CISA KEV 2026-09-08, legacy line (Windows 10, Server 2012-2022) | 2026-09-09 | 2026-09-13 | 2026-09-10 +1 more |
| CVE-2026-87491 | Google Chrome V8 out-of-bounds write, exploited in the wild, patched in Chrome 153 (seventh exploited Chrome zero-day of 2026) | 2026-09-10 | 2026-09-13 | 2026-09-10 |
| CVE-2026-88765 | GitLab EE, buffer overflow in Advanced Search Unicode-conversion wrapper reachable via crafted Git project import (CVSS 8.5) | 2026-09-12 | 2026-09-13 | 2026-09-12 |
| CVE-2026-15409 | SonicWall SMA1000 Work Place unauthenticated SSRF (CVSS 10.0, actively exploited) | 2026-07-14 | 2026-09-12 | 2026-07-14 |
| CVE-2026-42016 | JFrog Artifactory token scope-validation flaw chained with CVE-2026-42018 into admin takeover, confirmed exploited | 2026-09-12 | 2026-09-12 | 2026-09-12 |
| CVE-2026-42018 | JFrog Artifactory anonymous-user token exposure chained with CVE-2026-42016 into admin takeover, confirmed exploited | 2026-09-12 | 2026-09-12 | 2026-09-12 |
| CVE-2026-84869 | ConnectWise ScreenConnect client file-transfer authorization flaw, worm-like exploitation from 20 August 2026, patched 26.6.5 | 2026-09-12 | 2026-09-12 | 2026-09-12 |
| CVE-2026-12645 | Ivanti Neurons for ITSM, authenticated missing-authorization escalation to RCE (CVSS 9.9) | 2026-09-11 | 2026-09-11 | 2026-09-11 |
| CVE-2026-12646 | Ivanti Neurons for ITSM, authenticated missing-authorization escalation to RCE (CVSS 9.9) | 2026-09-11 | 2026-09-11 | 2026-09-11 |
| CVE-2026-12647 | Ivanti Neurons for ITSM, authenticated missing-authorization escalation to RCE (CVSS 9.9) | 2026-09-11 | 2026-09-11 | 2026-09-11 |
| CVE-2026-12648 | Ivanti Neurons for ITSM, authenticated deserialization RCE (CVSS 8.8) | 2026-09-11 | 2026-09-11 | 2026-09-11 |
| CVE-2026-12650 | Ivanti Neurons for ITSM, authenticated deserialization RCE (CVSS 9.9) | 2026-09-11 | 2026-09-11 | 2026-09-11 |
| CVE-2026-12651 | Ivanti Neurons for ITSM, authenticated deserialization RCE (CVSS 8.8) | 2026-09-11 | 2026-09-11 | 2026-09-11 |
| CVE-2026-12744 | Ivanti Neurons for ITSM, unauthenticated deserialization RCE (CVSS 9.8), September 2026 security update | 2026-09-11 | 2026-09-11 | 2026-09-11 |
| CVE-2026-12745 | Ivanti Neurons for ITSM, unauthenticated deserialization RCE (CVSS 9.8), September 2026 security update | 2026-09-11 | 2026-09-11 | 2026-09-11 |
| CVE-2026-18851 | Ivanti Endpoint Manager Mobile (EPMM), authenticated missing-authorization escalation to admin (CVSS 8.8) | 2026-09-11 | 2026-09-11 | 2026-09-11 |
| CVE-2026-67277 | MikroTik RouterOS bandwidth-test unauthenticated memory disclosure / DoS | 2026-09-06 | 2026-09-11 | 2026-09-06 |
| CVE-2026-83527 | Ivanti Sentry, unauthenticated authentication bypass to admin access (CVSS 8.1) | 2026-09-11 | 2026-09-11 | 2026-09-11 |
| CVE-2020-6287 | RECON, SAP NetWeaver AS Java LM Configuration Wizard unauthenticated admin-account creation (2020); cited by Onapsis as historical precedent for 72-hour SAP patch reverse-engineering | 2026-09-10 | 2026-09-10 | · |
| CVE-2021-42278 | noPac, Active Directory sAMAccountName spoofing (2021); cited by GreyNoise as one of three domain-admin escalation paths in the PaperCut AI-orchestrated campaign | 2026-09-10 | 2026-09-10 | · |
| CVE-2021-42287 | noPac, Active Directory KDC ticket forging companion flaw (2021); cited by GreyNoise as one of three domain-admin escalation paths in the PaperCut AI-orchestrated campaign | 2026-09-10 | 2026-09-10 | · |
| CVE-2025-25249 | Fortinet FortiOS/FortiSwitchManager CAPWAP heap overflow, CISA KEV 2026-09-09, actively exploited since July 2026 via the PivotC2 RAT | 2026-09-10 | 2026-09-10 | 2026-09-10 |
| CVE-2025-31324 | SAP NetWeaver Visual Composer unauthenticated file upload (2025), Mandiant's named most-exploited CVE of 2025; cited by Onapsis as historical precedent for OVERPASS/S4GET's severity | 2026-09-10 | 2026-09-10 | · |
| CVE-2026-19489 | Citrix NetScaler ADC/Gateway, memory overflow leading to unpredictable behaviour or denial of service; requires SIP ALG enabled on a Large Scale NAT group. CVSS 8.8. | 2026-08-20 | 2026-09-10 | 2026-08-20 |
| CVE-2026-19490 | Citrix NetScaler ADC/Gateway, authentication bypass using an alternate path on Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual servers; CVSS v4.0 9.3, no exploitation observed as of 2026-08-19. | 2026-08-20 | 2026-09-10 | 2026-08-20 |
| CVE-2026-44756 | SAP OVERPASS, unauthenticated memory-corruption RCE in shared SAP kernel Extended Passport processing (CVSS 10.0), September 2026 Patch Day | 2026-09-10 | 2026-09-10 | 2026-09-10 |
| CVE-2026-58240 | SAP S4GET, unauthenticated Message Server trust-bypass RCE (CVSS 9.8), September 2026 Patch Day | 2026-09-10 | 2026-09-10 | 2026-09-10 |
| CVE-2026-81578 | PaperCut NG/MF, authentication bypass in the web management interface (Tapestry request-routing confusion), chained to CVE-2026-82078 for pre-auth RCE, exploited before a patch existed | 2026-08-29 | 2026-09-10 | 2026-08-29 |
| CVE-2026-82078 | PaperCut NG/MF, unsafe dynamic class loading in the database connector, reached via CVE-2026-81578's config rewrite to achieve arbitrary Java bytecode execution | 2026-08-29 | 2026-09-10 | 2026-08-29 |
| CVE-2026-85103 | Check Point Quantum Security Gateway/Management Server, unauthenticated heap overflow in VPN certificate ASN.1 decoding (CVSS 9.8) | 2026-09-10 | 2026-09-10 | 2026-09-10 |
| CVE-2026-81963 | Windows Update Stack link-following EoP to SYSTEM (CVSS 7.8), actively exploited zero-day, CISA KEV 2026-09-08, newest builds (Server 2025, Windows 11) | 2026-09-09 | 2026-09-09 | 2026-09-09 |
| CVE-2026-75650 | StyleSmuggler, unauthenticated CVSS 10.0 RCE in Magento/Adobe Commerce via template-engine injection, exploited before Adobe's hotfix existed | 2026-09-08 | 2026-09-08 | 2026-09-08 |
| CVE-2026-86206 | N-able N-central, internal API access-control gap (part of the September 2026 auth-bypass chain) | 2026-09-07 | 2026-09-07 | 2026-09-07 |
| CVE-2026-86207 | N-able N-central, authentication bypass by primary weakness reaching internal APIs | 2026-09-07 | 2026-09-07 | 2026-09-07 |
| CVE-2026-86218 | N-able N-central, pre-authentication RCE zero-day, confirmed exploited in the wild | 2026-09-07 | 2026-09-07 | 2026-09-07 |
| CVE-2026-61408 | Dell Secure Connect Gateway 5.0, flaw reported alongside CVE-2026-61410 and CVE-2026-61409 (DSA-2026-382) | 2026-09-06 | 2026-09-06 | · |
| CVE-2026-61409 | Dell Secure Connect Gateway 5.0, OS command injection reported alongside CVE-2026-61410 (DSA-2026-382) | 2026-09-06 | 2026-09-06 | 2026-09-06 |
| CVE-2026-61410 | Dell Secure Connect Gateway 5.0, missing authorization allowing unauthenticated remote command execution via a single crafted request (DSA-2026-382) | 2026-09-06 | 2026-09-06 | 2026-09-06 |
| CVE-2026-63077 | JetBrains TeamCity On-Premises, unauthenticated deserialization RCE via the agent-polling protocol (CVSS 9.8); added to the CISA KEV catalog 2026-08-05 on evidence of active exploitation, reversing the vendor's no-known-exploitation position at disclosure | 2026-07-29 | 2026-09-06 | 2026-09-06 +1 more |
| CVE-2026-67278 | MikroTik RouterOS X.509 malformed-signature acceptance enabling TLS impersonation | 2026-09-06 | 2026-09-06 | 2026-09-06 |
| CVE-2026-67281 | MikroTik RouterOS WebFig /jsproxy unauthenticated file read via stale session pointer | 2026-09-06 | 2026-09-06 | 2026-09-06 |
| CVE-2026-80172 | Dell Secure Connect Gateway 5.0, insufficient verification of data authenticity; an unauthenticated attacker replays a captured request indefinitely to mint ADMIN access and refresh tokens (DSA-2026-382) | 2026-09-06 | 2026-09-06 | 2026-09-06 |
| CVE-2026-80238 | Dell Secure Connect Gateway 5.0, execution with unnecessary privileges; exposed Docker socket yields host root from a low-privileged SSH operator and an orchestrator-container escape (DSA-2026-382) | 2026-09-06 | 2026-09-06 | 2026-09-06 |
| CVE-2026-86060 | MikroTik RouterOS SSH crafted-username privilege escalation (MikroTrick component); CERT Polska confirms active exploitation | 2026-09-06 | 2026-09-06 | 2026-09-06 |
| CVE-2026-43284 | Dirty Frag, Linux kernel xfrm-ESP page-cache write primitive, LPE (ITW, PoC public) | 2026-05-09 | 2026-09-05 | 2026-05-09 |
| CVE-2026-43500 | Dirty Frag, Linux kernel RxRPC page-cache write primitive, LPE chain (ITW, patch pending) | 2026-05-09 | 2026-09-05 | 2026-05-09 |
| CVE-2026-46300 | Fragnesia, Linux kernel xfrm ESP-in-TCP LPE (PoC public) | 2026-05-15 | 2026-09-05 | 2026-05-15 |
| CVE-2026-58400 | GeoNetwork opensource: Saxon XSLT processor configured without secure processing, reachable via formatter upload chain to unauthenticated RCE | 2026-09-05 | 2026-09-05 | 2026-09-05 |
| CVE-2026-63219 | GeoNetwork opensource: unauthenticated formatter-upload endpoint chained to unauthenticated RCE via unsafe Saxon XSLT processing | 2026-09-05 | 2026-09-05 | 2026-09-05 |
| CVE-2026-19766 | HPE Networking Fabric Composer adjacent-network auth bypass (CVSS 9.6) | 2026-09-04 | 2026-09-04 | 2026-09-04 |
| CVE-2026-20212 | Cisco Nexus 9000 Series Silicon One S1HAL unauthenticated root RCE (CVSS 9.8) | 2026-09-04 | 2026-09-04 | 2026-09-04 |
| CVE-2026-73700 | HPE Networking Fabric Composer authenticated stored XSS (CVSS 9.0) | 2026-09-04 | 2026-09-04 | 2026-09-04 |
| CVE-2026-73701 | HPE Networking Fabric Composer unauthenticated privileged RCE (CVSS 9.0) | 2026-09-04 | 2026-09-04 | 2026-09-04 |
| CVE-2026-73749 | HPE ArubaOS-CX unauthenticated buffer-overflow RCE (CVSS 9.8) | 2026-09-04 | 2026-09-04 | 2026-09-04 |
| CVE-2026-73752 | HPE ArubaOS-CX unauthenticated adjacent-network arbitrary file write (CVSS 8.8) | 2026-09-04 | 2026-09-04 | 2026-09-04 |
| CVE-2026-73778 | HPE ArubaOS-CX predictable factory-default admin password (CVSS 8.1) | 2026-09-04 | 2026-09-04 | 2026-09-04 |
| CVE-2026-73781 | HPE ArubaOS-CX authenticated stored XSS, named in BleepingComputer's account of HPE's bulletin but absent from NCSC-NL's structured mirror of the same bulletin; referenced only as an example of the source-count discrepancy, not independently confirmed | 2026-09-04 | 2026-09-04 | · |
| CVE-2026-73782 | HPE ArubaOS-CX unauthenticated format-string CLI flaw (CVSS 8.1) | 2026-09-04 | 2026-09-04 | 2026-09-04 |
| CVE-2026-76657 | HPE Networking Fabric Composer API auth-bypass to admin (CVSS 10.0) | 2026-09-04 | 2026-09-04 | 2026-09-04 |
| CVE-2026-76658 | HPE Networking Fabric Composer SSH daemon unauthenticated RCE (CVSS 10.0) | 2026-09-04 | 2026-09-04 | 2026-09-04 |
| CVE-2026-85042 | Google Chrome DevTools use-after-free, High severity, no reported exploitation | 2026-09-04 | 2026-09-04 | 2026-09-04 |
| CVE-2026-85043 | Google Chrome Network incomplete cleanup, High severity, no reported exploitation | 2026-09-04 | 2026-09-04 | 2026-09-04 |
| CVE-2026-85044 | Google Chrome Mobile use-of-released-resource, Medium severity, no reported exploitation | 2026-09-04 | 2026-09-04 | 2026-09-04 |
| CVE-2026-85045 | Google Chrome V8 race condition, High severity, no reported exploitation | 2026-09-04 | 2026-09-04 | 2026-09-04 |
| CVE-2026-85047 | Google Chrome Transactions Platform improper input validation, Medium severity, no reported exploitation | 2026-09-04 | 2026-09-04 | 2026-09-04 |
| CVE-2026-85048 | Google Chrome Compositing use-after-free, High severity, no reported exploitation | 2026-09-04 | 2026-09-04 | 2026-09-04 |
| CVE-2026-85049 | Google Chrome Skia use-after-free, High severity, no reported exploitation | 2026-09-04 | 2026-09-04 | 2026-09-04 |
| CVE-2026-85050 | Google Chrome WebGL out-of-bounds write, High severity, no reported exploitation | 2026-09-04 | 2026-09-04 | 2026-09-04 |
| CVE-2026-85051 | Google Chrome Compositing type confusion, High severity, no reported exploitation | 2026-09-04 | 2026-09-04 | 2026-09-04 |
| CVE-2026-85052 | Google Chrome CrashReporting out-of-bounds read, High severity, no reported exploitation | 2026-09-04 | 2026-09-04 | 2026-09-04 |
| CVE-2026-85053 | Google Chrome CacheStorage improper resource exposure, High severity, no reported exploitation | 2026-09-04 | 2026-09-04 | 2026-09-04 |
| CVE-2026-0768 | Langflow, code-parameter code injection RCE in the validate endpoint, renewed mass exploitation since August 2026 | 2026-09-03 | 2026-09-03 | 2026-09-03 |
| CVE-2026-19592 | OpenAI Codex CLI, GitSpawn class, core.fsmonitor-adjacent helper mechanism running outside the command sandbox without user approval | 2026-09-03 | 2026-09-03 | 2026-09-03 |
| CVE-2026-59822 | BerriAI LiteLLM, MCP OAuth2-passthrough fallback auth bypass, CISA KEV 2026-09-02 | 2026-09-03 | 2026-09-03 | 2026-09-03 |
| CVE-2026-71963 | Hermes Agent (Nous Research), GitSpawn class, git-config-triggered command execution; VulnCheck-assigned, unpublished in NVD/MITRE/CIRCL as of 2026-09-03 | 2026-09-03 | 2026-09-03 | · |
| CVE-2026-72718 | Goose (AI coding agent), GitSpawn class, core.fsmonitor git-config command execution via `goose review` | 2026-09-03 | 2026-09-03 | 2026-09-03 |
| CVE-2026-83548 | SonicWall SMA1000; pre-auth SSRF in Work Place interface, actively exploited | 2026-09-03 | 2026-09-03 | 2026-09-03 |
| CVE-2026-83549 | SonicWall SMA1000, post-auth OS command injection in Appliance Management Console, actively exploited | 2026-09-03 | 2026-09-03 | 2026-09-03 |
| CVE-2026-9586 | Sangoma Switchvox, unauthenticated SQL injection to RCE via PostgreSQL COPY TO PROGRAM, CISA KEV 2026-09-02 | 2026-09-03 | 2026-09-03 | 2026-09-03 |
| CVE-2026-19318 | WatchGuard Fireware OS, third pre-auth stack overflow in iked (IKE_AUTH/EAP-MSCHAPv2); requires IKE payload diagnostic logging enabled; CVSS 9.3, no exploitation reported | 2026-08-31 | 2026-09-02 | 2026-08-31 |
| CVE-2026-78174 | WatchGuard Dimension, session hijack via unredacted session tokens in web UI diagnostic log; low-privileged Administrator can extract a Super Administrator's session; CVSS 9.3, no exploitation reported | 2026-08-31 | 2026-09-02 | 2026-08-31 |
| CVE-2026-42271 | BerriAI LiteLLM MCP test endpoints command injection to host RCE (CVSS 8.7), CISA KEV, actively exploited; unauthenticated when chained with CVE-2026-48710 | 2026-06-09 | 2026-09-01 | 2026-08-31 +1 more |
| CVE-2026-62911 | Microsoft Exchange Server MRSProxy, missing channel-binding check, authentication bypass by capture-replay; public exploit code published 27 August 2026 | 2026-08-29 | 2026-09-01 | 2026-08-29 |
| CVE-2026-13086 | WatchGuard Fireware OS Mobile Security epm service - pre-auth stack overflow yielding root RCE | 2026-08-31 | 2026-08-31 | 2026-08-31 |
| CVE-2026-19313 | WatchGuard Fireware OS iked - pre-auth heap buffer overflow yielding RCE, patched 2026-08-27 | 2026-08-31 | 2026-08-31 | 2026-08-31 |
| CVE-2026-19315 | WatchGuard Fireware OS iked - pre-auth type confusion via duplicated EAP payload in IKE_AUTH, yielding RCE | 2026-08-31 | 2026-08-31 | 2026-08-31 |
| CVE-2026-48710 | Starlette/FastAPI host-header auth bypass (BadHost) | 2026-05-30 | 2026-08-31 | 2026-08-31 +2 more |
| CVE-2026-49869 | Kestra workflow orchestrator - critical pre-auth login-bypass vulnerability, exploited to reach worker-side shell execution | 2026-08-31 | 2026-08-31 | 2026-08-31 |
| CVE-2026-81851 | WatchGuard Fireware OS iked - heap-based buffer overflow yielding denial of service (BSI CERT-Bund WID-SEC-2026-3068, same advisory family as CVE-2026-19313/19315/13086, not itemised in WatchGuard's own blog roundup) | 2026-08-31 | 2026-08-31 | · |
| CVE-2026-21962 | Oracle HTTP Server / WebLogic Server Proxy Plug-in - unauthenticated access-control bypass, CVSS 10.0; CISA KEV 2026-08-24, exploited since January 2026 | 2026-08-30 | 2026-08-30 | 2026-08-30 |
| CVE-2026-60004 | Gitea diffpatch endpoint - Git-hook code injection, command execution as the service account, CVSS 9.8; CISA KEV 2026-08-25, fixed in 1.27.1 | 2026-08-30 | 2026-08-30 | 2026-08-30 |
| CVE-2023-27350 | PaperCut NG/MF, 2023 authentication-bypass RCE mass-exploited by ransomware operators; cited as historical background by Rapid7's 2026-08-28 analysis of the unrelated CVE-2026-81578/82078 chain | 2026-08-29 | 2026-08-29 | · |
| CVE-2026-18885 | ServiceNow AI Platform, unauthenticated GraphQL Composite Data API code injection (CVSS4.0 10.0) | 2026-08-29 | 2026-08-29 | 2026-08-29 |
| CVE-2026-18886 | ServiceNow Now Platform, unauthenticated access-control bypass in the system-configuration image-upload processor (CVSS4.0 10.0) | 2026-08-29 | 2026-08-29 | 2026-08-29 |
| CVE-2026-6876 | ServiceNow Now Platform, sandbox escape, same vulnerability class as CVE-2026-6875 (CVSS4.0 8.7) | 2026-08-29 | 2026-08-29 | 2026-08-29 |
| CVE-2026-74820 | ServiceNow AI Platform, unauthenticated dynamic-schema SQL injection (CVSS4.0 10.0) | 2026-08-29 | 2026-08-29 | 2026-08-29 |
| CVE-2023-49105 | A 2023 ownCloud auth-bypass CVE re-enters CISA KEV because Hunt.io caught a suspected Chinese-speaking operator's open staging server using it to steal nuclear-research and naval-contractor data from two Philippine organisations | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2024-28000 | A 2023 ownCloud auth-bypass CVE re-enters CISA KEV because Hunt.io caught a suspected Chinese-speaking operator's open staging server using it to steal nuclear-research and naval-contractor data from two Philippine organisations | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2025-41450 | Claroty Team82: Danfoss AK-SM 800A refrigeration system managers, undocumented 'code-of-the-day' authentication bypass and post-authentication command-injection RCE across roughly 2,765 internet-exposed devices | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2025-41451 | Claroty Team82: Danfoss AK-SM 800A refrigeration system managers, undocumented 'code-of-the-day' authentication bypass and post-authentication command-injection RCE across roughly 2,765 internet-exposed devices | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2025-41452 | Claroty Team82: Danfoss AK-SM 800A refrigeration system managers, undocumented 'code-of-the-day' authentication bypass and post-authentication command-injection RCE across roughly 2,765 internet-exposed devices | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2025-49113 | Roundcube Crypt_GPG_Engine PHP deserialization RCE - chained by UNK_MassTraction after CVE-2024-42009 XSS (Proofpoint) | 2026-07-09 | 2026-08-28 | 2026-08-12 +1 more |
| CVE-2026-12537 | Google Gemini CLI GitHub Actions harness, trust-boundary bypass; fixed gemini-cli 0.39.1 / run-gemini-cli 0.1.22, published 2026-04-24 | 2026-08-10 | 2026-08-28 | 2026-08-10 |
| CVE-2026-15981 | miniOrange's SAML2Core library ships the same openssl_verify() tri-state authentication bypass across both its WordPress and Joomla SAML SSO products, one vendor code defect, two ecosystems, exploitation already attempted against the WordPress line | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2026-19912 | Kaltura mwEmbed/html5lib video player: unauthenticated RCE and arbitrary file read via an undocumented ServiceUrl parameter, no vendor response, no patch, 630+ exposed instances found by the discoverer | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2026-19913 | Kaltura mwEmbed/html5lib video player: unauthenticated RCE and arbitrary file read via an undocumented ServiceUrl parameter, no vendor response, no patch, 630+ exposed instances found by the discoverer | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2026-20742 | Copeland XWEB Pro refrigeration controller, OS command injection (Claroty Team82 disclosure) | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2026-20764 | Copeland XWEB Pro refrigeration controller, OS command injection (Claroty Team82 disclosure) | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2026-20902 | Copeland XWEB Pro refrigeration controller, OS command injection (Claroty Team82 disclosure) | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2026-20910 | Copeland XWEB Pro refrigeration controller, OS command injection (Claroty Team82 disclosure) | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2026-21273 | Adobe ColdFusion 2025/2023, privilege escalation via input validation (APSB26-90) | 2026-08-28 | 2026-08-28 | · |
| CVE-2026-21389 | Copeland XWEB Pro refrigeration controller, OS command injection (Claroty Team82 disclosure) | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2026-21653 | Johnson Controls C-CURE 9000 / victor: unauthenticated adjacent-network deserialization RCE on physical access-control application servers reaches connected security-workstation clients too (CVE-2026-21655, CVSS 9.6) | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2026-21655 | Johnson Controls C-CURE 9000 / victor: unauthenticated adjacent-network deserialization RCE on physical access-control application servers reaches connected security-workstation clients too (CVE-2026-21655, CVSS 9.6) | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2026-21718 | Claroty Team82: 23 vulnerabilities in Copeland XWEB Pro supervisory refrigeration controllers chain to unauthenticated root RCE; a deterministic admin password derived from the device's own MAC address is one of two independent pre-auth paths | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2026-23702 | Copeland XWEB Pro refrigeration controller, OS command injection (Claroty Team82 disclosure) | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2026-24452 | Copeland XWEB Pro refrigeration controller, OS command injection (Claroty Team82 disclosure) | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2026-24517 | Copeland XWEB Pro refrigeration controller, OS command injection (Claroty Team82 disclosure) | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2026-24663 | Copeland XWEB Pro refrigeration controller, OS command injection (Claroty Team82 disclosure) | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2026-24689 | Copeland XWEB Pro refrigeration controller, OS command injection (Claroty Team82 disclosure) | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2026-24695 | Copeland XWEB Pro refrigeration controller, OS command injection (Claroty Team82 disclosure) | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2026-25037 | Copeland XWEB Pro refrigeration controller, OS command injection (Claroty Team82 disclosure) | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2026-25085 | Claroty Team82: 23 vulnerabilities in Copeland XWEB Pro supervisory refrigeration controllers chain to unauthenticated root RCE; a deterministic admin password derived from the device's own MAC address is one of two independent pre-auth paths | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2026-25105 | Copeland XWEB Pro refrigeration controller, OS command injection (Claroty Team82 disclosure) | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2026-25109 | Copeland XWEB Pro refrigeration controller, OS command injection (Claroty Team82 disclosure) | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2026-25111 | Copeland XWEB Pro refrigeration controller, OS command injection (Claroty Team82 disclosure) | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2026-25195 | Copeland XWEB Pro refrigeration controller, OS command injection (Claroty Team82 disclosure) | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2026-25196 | Copeland XWEB Pro refrigeration controller, OS command injection (Claroty Team82 disclosure) | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2026-25721 | Copeland XWEB Pro refrigeration controller, OS command injection (Claroty Team82 disclosure) | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2026-27302 | Adobe August 2026 Patch Day: ColdFusion ships a CVSS 10.0 unauthenticated OS command injection, and Campaign Classic ships two more unauthenticated CVSS 10.0 flaws in the same release | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2026-32475 | Elementor Pro (WordPress, ~6M installs): unauthenticated arbitrary file upload to RCE via a validator/mover desynchronization in the Forms File Upload field (CVE-2026-32475, CVSS 9.0) | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2026-34265 | SAP NetWeaver Application Server ABAP / ABAP Platform kernel, logical errors in DIAG protocol parsing allow an unauthenticated attacker to generate memory corruptions, CVSS 9.8, SAP Security Note 3714806. | 2026-08-12 | 2026-08-28 | 2026-08-12 |
| CVE-2026-34496 | Johnson Controls C-CURE 9000 / victor: unauthenticated adjacent-network deserialization RCE on physical access-control application servers reaches connected security-workstation clients too (CVE-2026-21655, CVSS 9.6) | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2026-42945 | NGINX ngx_http_rewrite_module heap buffer overflow (earlier of two May 2026 disclosures); exploitation attempts per NCSC-NL; § 7 drop (primary 2026-05-18 out-of-window) | 2026-05-15 | 2026-08-28 | 2026-08-12 +2 more |
| CVE-2026-44758 | SAP Manufacturing Integration and Intelligence code injection reaching arbitrary OS command execution with a higher privilege requirement, CVSS 9.1, SAP Security Note 3758900. | 2026-08-12 | 2026-08-28 | 2026-08-12 |
| CVE-2026-44772 | SAP Manufacturing Integration and Intelligence code injection reaching arbitrary OS command execution, CVSS 9.9, SAP Security Note 3765948; the patch removes the vulnerable servlet component. | 2026-08-12 | 2026-08-28 | 2026-08-12 |
| CVE-2026-48273 | Adobe August 2026 Patch Day: ColdFusion ships a CVSS 10.0 unauthenticated OS command injection, and Campaign Classic ships two more unauthenticated CVSS 10.0 flaws in the same release | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2026-48362 | Adobe August 2026 Patch Day: ColdFusion ships a CVSS 10.0 unauthenticated OS command injection, and Campaign Classic ships two more unauthenticated CVSS 10.0 flaws in the same release | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2026-48381 | Adobe August 2026 Patch Day: ColdFusion ships a CVSS 10.0 unauthenticated OS command injection, and Campaign Classic ships two more unauthenticated CVSS 10.0 flaws in the same release | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2026-48440 | Adobe ColdFusion 2025/2023, heap-based buffer overflow (APSB26-90) | 2026-08-28 | 2026-08-28 | · |
| CVE-2026-53362 | Linux kernel IPv6 UDP fraggap accounting bug (CVE-2026-53362) added to CISA KEV, an unprivileged local heap overflow via MSG_SPLICE_PAGES, no exploitation narrative published | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2026-54316 | Anthropic Claude Code Action, CI command-validation bypass (quote-stripping before inspection; read-only allowlist exempt from path checks); fixed claude-code 2.1.163, published 2026-06-13 | 2026-08-10 | 2026-08-28 | 2026-08-10 |
| CVE-2026-58231 | SAP Commerce Cloud Data Hub Adapter, unauthenticated improper-authorization flaw reaching arbitrary code execution (CVSS 10.0), fixed in SAP Security Note 3771065 and requiring a rebuild and redeploy. Exploitation attempts against honeypot sensors recorded by Defused on 2026-08-14, three days after patch day, with no public proof-of-concept; NCSC-NL advisory NCSC-2026-0302 (2026-08-15) records active scanning for vulnerable systems. | 2026-08-12 | 2026-08-28 | 2026-08-12 |
| CVE-2026-58243 | SAP ABAP Development Tools SQL Console; host expressions in SQL statements let a low-privileged authenticated user run unauthorized database operations, CVSS 8.8, SAP Security Note 3772411. | 2026-08-12 | 2026-08-28 | 2026-08-12 |
| CVE-2026-59109 | Zalktis (Latvian accounting software): unauthenticated SQL injection reachable by any PEPPOL/UBL e-invoice sender, no account, no network position, just a routine bookkeeping import (CVE-2026-59109) | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2026-59310 | VMSA-2026-0006, VMware vCenter Syslog directory traversal to remote code execution; confirmed actively exploited from 2026-08-03, 361 victim IP addresses across 47 countries | 2026-07-30 | 2026-08-28 | 2026-07-30 |
| CVE-2026-61979 | miniOrange's SAML2Core library ships the same openssl_verify() tri-state authentication bypass across both its WordPress and Joomla SAML SSO products, one vendor code defect, two ecosystems, exploitation already attempted against the WordPress line | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2026-64796 | Sourcerer for Joomla: unauthenticated RCE exploited in the wild since before a working fix existed; the vendor's first two patches did not close it, and the CVE was re-scoped in place to widen the affected range | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2026-65617 | Hugging Face intrusion update; the sandbox escape was a chain of previously unknown JFrog Artifactory flaws, now patched, and the models also used publicly exposed credentials on four third-party services | 2026-07-21 | 2026-08-28 | 2026-07-21 |
| CVE-2026-65921 | Hugging Face intrusion update; the sandbox escape was a chain of previously unknown JFrog Artifactory flaws, now patched, and the models also used publicly exposed credentials on four third-party services | 2026-07-21 | 2026-08-28 | 2026-07-21 |
| CVE-2026-65922 | Hugging Face intrusion update; the sandbox escape was a chain of previously unknown JFrog Artifactory flaws, now patched, and the models also used publicly exposed credentials on four third-party services | 2026-07-21 | 2026-08-28 | 2026-07-21 |
| CVE-2026-65923 | Hugging Face intrusion update; the sandbox escape was a chain of previously unknown JFrog Artifactory flaws, now patched, and the models also used publicly exposed credentials on four third-party services | 2026-07-21 | 2026-08-28 | 2026-07-21 |
| CVE-2026-65924 | Hugging Face intrusion update; the sandbox escape was a chain of previously unknown JFrog Artifactory flaws, now patched, and the models also used publicly exposed credentials on four third-party services | 2026-07-21 | 2026-08-28 | 2026-07-21 |
| CVE-2026-65925 | Hugging Face intrusion update; the sandbox escape was a chain of previously unknown JFrog Artifactory flaws, now patched, and the models also used publicly exposed credentials on four third-party services | 2026-07-21 | 2026-08-28 | 2026-07-21 |
| CVE-2026-66014 | Hugging Face intrusion update; the sandbox escape was a chain of previously unknown JFrog Artifactory flaws, now patched, and the models also used publicly exposed credentials on four third-party services | 2026-07-21 | 2026-08-28 | 2026-07-21 |
| CVE-2026-66015 | Hugging Face intrusion update; the sandbox escape was a chain of previously unknown JFrog Artifactory flaws, now patched, and the models also used publicly exposed credentials on four third-party services | 2026-07-21 | 2026-08-28 | 2026-07-21 |
| CVE-2026-66018 | Hugging Face intrusion update; the sandbox escape was a chain of previously unknown JFrog Artifactory flaws, now patched, and the models also used publicly exposed credentials on four third-party services | 2026-07-21 | 2026-08-28 | 2026-07-21 |
| CVE-2026-66384 | JFrog Artifactory: authenticated Docker-cache path traversal (CVE-2026-66384) added to CISA KEV, a CI/CD artifact-store write primitive with no published exploitation narrative | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2026-67365 | iCagenda Calendar module for Joomla: unauthenticated SQL injection via com_ajax needs no session, token or account (CVE-2026-67365, CVSS 9.2), and the vulnerable module's own version number does not track the package version | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2026-68820 | Microsoft Windows Ancillary Function Driver for WinSock (afd.sys) use-after-free race condition, exploited as a zero-day by the Lazarus-affiliated Operation Dream Job campaign to reach SYSTEM and load the FudModule v3.1 kernel rootkit; patched 2026-08-11, CISA KEV the same day. | 2026-08-12 | 2026-08-28 | 2026-08-12 |
| CVE-2026-71384 | Adobe August 2026 Patch Day: ColdFusion ships a CVSS 10.0 unauthenticated OS command injection, and Campaign Classic ships two more unauthenticated CVSS 10.0 flaws in the same release | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2026-71386 | Adobe ColdFusion 2025/2023, cross-site scripting escalating to code execution (APSB26-90) | 2026-08-28 | 2026-08-28 | · |
| CVE-2026-71398 | Adobe August 2026 Patch Day: ColdFusion ships a CVSS 10.0 unauthenticated OS command injection, and Campaign Classic ships two more unauthenticated CVSS 10.0 flaws in the same release | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2026-74253 | Sourcerer for Joomla: unauthenticated RCE exploited in the wild since before a working fix existed; the vendor's first two patches did not close it, and the CVE was re-scoped in place to widen the affected range | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2026-74803 | YOOtheme ZOO for Joomla: unauthenticated file-upload RCE (CVSS 10.0) plus a precondition-free SQL injection reachable with no submission form at all, three releases in three days, and the 3.x line has no fix | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2026-74804 | YOOtheme ZOO for Joomla: unauthenticated file-upload RCE (CVSS 10.0) plus a precondition-free SQL injection reachable with no submission form at all, three releases in three days, and the 3.x line has no fix | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2026-75114 | YOOtheme ZOO (Joomla), open redirect in Twitter comment callback | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2026-76253 | Splunk Enterprise, privilege escalation via scheduled-search alert-action configuration, reaches the full credential store (SVD-2026-0801) | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2026-76310 | Splunk Enterprise August 2026 hardening release (SVD-2026-0801): three unauthenticated CVSS 9.4 flaws let anyone holding an embedded-report token hijack the report owner's session, admins included | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2026-76311 | Splunk Enterprise August 2026 hardening release (SVD-2026-0801): three unauthenticated CVSS 9.4 flaws let anyone holding an embedded-report token hijack the report owner's session, admins included | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2026-76312 | Splunk Enterprise August 2026 hardening release (SVD-2026-0801): three unauthenticated CVSS 9.4 flaws let anyone holding an embedded-report token hijack the report owner's session, admins included | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2026-76350 | Splunk Enterprise August 2026 hardening release (SVD-2026-0801): three unauthenticated CVSS 9.4 flaws let anyone holding an embedded-report token hijack the report owner's session, admins included | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2026-76351 | Splunk Enterprise August 2026 hardening release (SVD-2026-0801): three unauthenticated CVSS 9.4 flaws let anyone holding an embedded-report token hijack the report owner's session, admins included | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2026-76612 | YOOtheme ZOO for Joomla: unauthenticated file-upload RCE (CVSS 10.0) plus a precondition-free SQL injection reachable with no submission form at all, three releases in three days, and the 3.x line has no fix | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2026-76613 | YOOtheme ZOO for Joomla: unauthenticated file-upload RCE (CVSS 10.0) plus a precondition-free SQL injection reachable with no submission form at all, three releases in three days, and the 3.x line has no fix | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2026-77537 | Ubiquiti UniFi ecosystem: 22 CVEs in one bulletin, three at CVSS 10.0, unauthenticated CRLF-injection auth bypass, and unauthenticated command injection in UniFi Protect and UniFi Talk | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2026-77550 | Ubiquiti UniFi ecosystem: 22 CVEs in one bulletin, three at CVSS 10.0, unauthenticated CRLF-injection auth bypass, and unauthenticated command injection in UniFi Protect and UniFi Talk | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2026-77554 | Ubiquiti UniFi ecosystem: 22 CVEs in one bulletin, three at CVSS 10.0, unauthenticated CRLF-injection auth bypass, and unauthenticated command injection in UniFi Protect and UniFi Talk | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2026-77995 | miniOrange's SAML2Core library ships the same openssl_verify() tri-state authentication bypass across both its WordPress and Joomla SAML SSO products, one vendor code defect, two ecosystems, exploitation already attempted against the WordPress line | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2026-77998 | miniOrange's SAML2Core library ships the same openssl_verify() tri-state authentication bypass across both its WordPress and Joomla SAML SSO products, one vendor code defect, two ecosystems, exploitation already attempted against the WordPress line | 2026-08-28 | 2026-08-28 | 2026-08-28 |
| CVE-2026-8451 | Citrix NetScaler ADC/Gateway, pre-auth SAML IdP memory overread leaking process memory in the NSC_TASS cookie; carried by NCSC-CH as actively exploited with a public PoC since 2026-07-03. Fixed in 14.1-72.61 / 13.1-63.18 | 2026-07-01 | 2026-08-28 | 2026-07-01 |
| CVE-2026-8452 | Citrix NetScaler ADC/Gateway, heap overflow during SAML SignedInfo canonicalization; CVE record describes only Denial of Service, but watchTowr published a pre-authentication chain to root (identifier is watchTowr's inference). Fixed in 14.1-72.61 / 13.1-63.18 | 2026-07-01 | 2026-08-28 | 2026-07-01 |
| CVE-2026-18963 | Red Hat build of Keycloak (keycloak-services), reset-credentials flow bypass letting an unauthenticated attacker complete a password reset without the email-verification click and set new credentials, reaching full account takeover including administrators (CVSS 9.1, Red Hat as CNA; root cause improper state validation). Fixed 2026-08-18 in RHBK 26.4.15 (RHSA-2026:56520) and 26.6.6 (RHSA-2026:56523) plus the matching image and operator errata. Product-state correction (2026-08-24 audit): Red Hat records only two products under package_state, both "Not affected", the JBoss EAP Expansion Pack and Red Hat Single Sign-On 7; no Red Hat product is affected and unfixed. | 2026-08-19 | 2026-08-24 | 2026-08-19 |
| CVE-2026-19478 | GitLab CE/EE, code injection via a GraphQL directive allowing an unauthenticated user to remotely modify or delete public projects and user data (CVSS 9.4, vendor-assigned). Fixed out of band on 2026-08-17 in 18.11.11 / 19.0.8 / 19.1.6 / 19.2.4. Actively exploited: WatchTowr honeypots caught in-the-wild attempts ~2 days after the patch (SecurityWeek 2026-08-20); NCSC-CH amended its advisory 2026-08-21; covered by entries/2026-08-22/cve-2026-19478-gitlab-honeypot-exploitation-confirmed. Not on CISA KEV as of 2026-08-24. | 2026-08-19 | 2026-08-24 | 2026-08-19 |
| CVE-2026-56179 | Windows NAT (Hyper-V, upstream-spoofing configuration), NatJack primitive; the August 2026 update adds ISN randomisation, shipped disabled by default and enabled only via a registry key | 2026-08-10 | 2026-08-24 | 2026-08-10 |
| CVE-2026-76904 | GeoServer / GeoTools jsonArrayContains unauthenticated SQL injection, exploited; fixed 2026-08-14 in GeoServer 3.0.1 / 2.28.5 / 2.27.6 (GeoTools 35.1 / 34.5 / 33.6); identifier assigned 2026-08-21 | 2026-08-24 | 2026-08-24 | · |
| CVE-2026-77647 | SPIP before 4.4.20, unconditional pre-authentication RCE reported anonymously via ANSSI; the vendor's bulletin states exploitation attempts were already observed in the wild (August 2026). A second, distinct unconditional pre-auth RCE affects 4.4.20 itself and is fixed only in 4.4.21, that one is CVE-2026-77806. No mechanism is described by any citable vendor or CERT source. | 2026-08-22 | 2026-08-24 | 2026-08-22 |
| CVE-2026-77806 | SPIP before 4.4.21, second unconditional pre-auth RCE, affecting 4.4.20 itself; exploited in the wild August 2026; identifier added to CERT-FR's advisory 2026-08-24 | 2026-08-22 | 2026-08-24 | 2026-08-22 |
| CVE-2019-16098 | MSI Afterburner RTCore64.sys driver flaw, long patched, recorded only as one of the two vulnerable drivers Cisco Talos observed the SPECTRE implant loading to obtain a kernel read/write primitive for unlinking EDR notification callbacks. Not a new or in-window disclosure. | 2026-08-23 | 2026-08-23 | 2026-08-23 |
| CVE-2019-18935 | Historical, long-patched CVE referenced only as background by a 2026-08-23 entry; not an in-window disclosure and not this run's finding. Telerik UI for ASP.NET AJAX deserialization flaw named by Cisco Talos among UAT-10147's mass-exploitation set. | 2026-08-23 | 2026-08-23 | · |
| CVE-2021-21551 | Dell DBUtil_2_3.sys driver flaw, long patched, recorded only as the second vulnerable driver Cisco Talos observed the SPECTRE implant loading as its kernel read/write primitive. Not a new or in-window disclosure. | 2026-08-23 | 2026-08-23 | 2026-08-23 |
| CVE-2021-23758 | Historical, long-patched CVE referenced only as background by a 2026-08-23 entry; not an in-window disclosure and not this run's finding. AjaxPro deserialization flaw named by Cisco Talos among UAT-10147's mass-exploitation set. | 2026-08-23 | 2026-08-23 | · |
| CVE-2021-24092 | Historical, long-patched CVE referenced only as background by a 2026-08-23 entry; not an in-window disclosure and not this run's finding. Local privilege-escalation flaw in the same Windows Defender BTR.sys driver file, disclosed by SentinelLabs and patched by Microsoft in February 2021; referenced as historical background by the BTR Reforged deep dive and unrelated to that technique. | 2026-08-23 | 2026-08-23 | · |
| CVE-2021-29442 | Historical, long-patched CVE referenced only as background by a 2026-08-23 entry; not an in-window disclosure and not this run's finding. Nacos missing-authentication flaw on the Derby management endpoint, named by Cisco Talos among UAT-10147's mass-exploitation set and chained toward script-engine code execution. | 2026-08-23 | 2026-08-23 | · |
| CVE-2022-27925 | Historical, long-patched CVE referenced only as background by a 2026-08-23 entry; not an in-window disclosure and not this run's finding. Zimbra Collaboration Suite flaw Cisco Talos names among the long-public vulnerabilities UAT-10147 mass-exploits for initial access; historically reached unauthenticated code execution when chained with CVE-2022-37042. | 2026-08-23 | 2026-08-23 | · |
| CVE-2022-37042 | Historical, long-patched CVE referenced only as background by a 2026-08-23 entry; not an in-window disclosure and not this run's finding. Zimbra authentication-bypass flaw that historically completed the unauthenticated path alongside CVE-2022-27925; recorded for the chaining nuance the Talos shorthand omits. | 2026-08-23 | 2026-08-23 | · |
| CVE-2026-20030 | Cisco Crosswork applications, SQL injection, CVSS 3.1 10.0; patched, exploitation status unknown (relayed by NCSC-CH 2026-08-21) | 2026-08-23 | 2026-08-23 | · |
| CVE-2026-20231 | Cisco Secure Workload, command/OS injection, CVSS 3.1 9.9; patched, exploitation status unknown (relayed by NCSC-CH 2026-08-21) | 2026-08-23 | 2026-08-23 | · |
| CVE-2026-20315 | Cisco Secure Workload, improper access control, CVSS 3.1 10.0; patched, exploitation status unknown (relayed by NCSC-CH 2026-08-21) | 2026-08-23 | 2026-08-23 | · |
| CVE-2026-20317 | Cisco Secure Workload, improper authentication, CVSS 3.1 10.0; patched, exploitation status unknown (relayed by NCSC-CH 2026-08-21) | 2026-08-23 | 2026-08-23 | · |
| CVE-2026-20318 | Cisco Secure Workload, path traversal, CVSS 3.1 9.6; patched, exploitation status unknown (relayed by NCSC-CH 2026-08-21) | 2026-08-23 | 2026-08-23 | · |
| CVE-2026-20357 | Cisco Crosswork, missing authentication for a critical function, CVSS 3.1 10.0; patched, exploitation status unknown (relayed by NCSC-CH 2026-08-21) | 2026-08-23 | 2026-08-23 | · |
| CVE-2026-20358 | Cisco Crosswork, external control of the file system, CVSS 3.1 10.0; patched, exploitation status unknown (relayed by NCSC-CH 2026-08-21) | 2026-08-23 | 2026-08-23 | · |
| CVE-2026-20359 | Cisco Crosswork, insufficiently protected credentials, CVSS 3.1 9.9; patched, exploitation status unknown (relayed by NCSC-CH 2026-08-21) | 2026-08-23 | 2026-08-23 | · |
| CVE-2026-69836 | Microsoft Entra ID deserialization of untrusted data (CWE-502), CVSS 3.1 base 10.0, a cloud-service CVE already mitigated by Microsoft with no tenant action available. Recorded here for the exploitation-status contradiction: MSRC revision 1.1 of 2026-08-21 corrected the record to not-exploited, while ENISA's EU Vulnerability Database still carried it on the exploited feed when checked on 2026-08-22. | 2026-08-23 | 2026-08-23 | 2026-08-23 |
| CVE-2026-72529 | TrueConf Server missing authentication for a critical function on port 4307/TCP; an unauthenticated caller invokes an undocumented function to run a script inside the server's isolated environment. CISA KEV and ENISA EUVD both record exploitation since 2026-08-20; chained with CVE-2026-72530 by Head Mare to reach SYSTEM. Fixed 2026-06-18 in 5.3.9/5.4.9/5.5.5. | 2026-08-23 | 2026-08-23 | 2026-08-23 |
| CVE-2026-72530 | TrueConf Server sandbox escape, a flaw in the isolated environment's code-generation logic lets an attacker who already has script execution there run arbitrary OS commands as NT AUTHORITY\SYSTEM. CISA KEV and ENISA EUVD both record exploitation since 2026-08-20. Fixed 2026-06-18 in 5.3.9/5.4.9/5.5.5. | 2026-08-23 | 2026-08-23 | 2026-08-23 |
| CVE-2026-77710 | misp-stix STIX-import trust-boundary flaw (CVSS 4.0 6.9); the importer decided whether a document was a trusted internal MISP export from markers the producer controls, then copied a whole attribute dictionary onto imported attributes, letting a crafted bundle set distribution, sharing_group_id and tags. Last affected 2026.7.8; fixed by commits only, no tagged release. | 2026-08-23 | 2026-08-23 | 2026-08-23 |
| CVE-2026-77755 | misp-stix denial of service (CVSS 4.0 8.7), parse failures called sys.exit(), raising SystemExit past callers' exception handlers, so one malformed STIX document terminates a long-running importer; no size limit was applied before parsing. Last affected 2026.7.8; fixed by commits only. | 2026-08-23 | 2026-08-23 | 2026-08-23 |
| CVE-2026-77761 | misp-stix cross-document parser state contamination (CVSS 4.0 6.3), reused parser instances retained galaxy data, references, titles and timestamps across conversions, so one document's content can appear in the event generated from the next. Last affected 2026.7.8; fixed by commits only. | 2026-08-23 | 2026-08-23 | 2026-08-23 |
| CVE-2026-19586 | TP-Link Omada gateways, pre-authentication OS command injection in the OpenVPN server; fixed per hardware revision in the vendor firmware table | 2026-08-22 | 2026-08-22 | 2026-08-22 |
| CVE-2026-19683 | TP-Link Omada gateways, second flaw in the August 2026 Omada advisory | 2026-08-22 | 2026-08-22 | 2026-08-22 |
| CVE-2026-20319 | Cisco Crosswork / Secure Workload, the ninth CVE of the August 2026 hardening set, absent from the W34 weekly rollup enumeration | 2026-08-22 | 2026-08-22 | · |
| CVE-2026-53413 | Zoom, one of three August 2026 client flaws; lower patch floor than CVE-2026-53415 | 2026-08-22 | 2026-08-22 | 2026-08-22 |
| CVE-2026-53414 | Zoom, one of three August 2026 client flaws; lower patch floor than CVE-2026-53415 | 2026-08-22 | 2026-08-22 | 2026-08-22 |
| CVE-2026-53415 | Zoom, requires a HIGHER fixed version than its two siblings; patching to the obvious floor leaves it open | 2026-08-22 | 2026-08-22 | 2026-08-22 |
| CVE-2026-77644 | PTC Windchill, one of three new August 2026 CVEs, all PR:N, no obtainable fixed version for two of them | 2026-08-22 | 2026-08-22 | 2026-08-22 |
| CVE-2026-77645 | PTC Windchill, one of three new August 2026 CVEs, all PR:N | 2026-08-22 | 2026-08-22 | 2026-08-22 |
| CVE-2026-77646 | PTC Windchill PDMLink, one of three new August 2026 CVEs, all PR:N | 2026-08-22 | 2026-08-22 | 2026-08-22 |
| CVE-2026-9033 | TP-Link Omada gateways, third flaw in the August 2026 Omada advisory | 2026-08-22 | 2026-08-22 | 2026-08-22 |
| CVE-2026-64960 | Thirteen CVEs in ATutor, none of which will ever be fixed, including an unauthenticated auto-login token forgery that authenticates as any account, a | 2026-08-21 | 2026-08-21 | 2026-08-21 |
| CVE-2026-64961 | Thirteen CVEs in ATutor, none of which will ever be fixed, including an unauthenticated auto-login token forgery that authenticates as any account, a | 2026-08-21 | 2026-08-21 | 2026-08-21 |
| CVE-2026-64962 | Thirteen CVEs in ATutor, none of which will ever be fixed, including an unauthenticated auto-login token forgery that authenticates as any account, a | 2026-08-21 | 2026-08-21 | 2026-08-21 |
| CVE-2026-64963 | Thirteen CVEs in ATutor, none of which will ever be fixed, including an unauthenticated auto-login token forgery that authenticates as any account, a | 2026-08-21 | 2026-08-21 | 2026-08-21 |
| CVE-2026-64964 | Thirteen CVEs in ATutor, none of which will ever be fixed, including an unauthenticated auto-login token forgery that authenticates as any account, a | 2026-08-21 | 2026-08-21 | 2026-08-21 |
| CVE-2026-64965 | Thirteen CVEs in ATutor, none of which will ever be fixed, including an unauthenticated auto-login token forgery that authenticates as any account, a | 2026-08-21 | 2026-08-21 | 2026-08-21 |
| CVE-2026-64966 | Thirteen CVEs in ATutor, none of which will ever be fixed, including an unauthenticated auto-login token forgery that authenticates as any account, a | 2026-08-21 | 2026-08-21 | 2026-08-21 |
| CVE-2026-64967 | Thirteen CVEs in ATutor, none of which will ever be fixed, including an unauthenticated auto-login token forgery that authenticates as any account, a | 2026-08-21 | 2026-08-21 | 2026-08-21 |
| CVE-2026-64968 | Thirteen CVEs in ATutor, none of which will ever be fixed, including an unauthenticated auto-login token forgery that authenticates as any account, a | 2026-08-21 | 2026-08-21 | 2026-08-21 |
| CVE-2026-64969 | Thirteen CVEs in ATutor, none of which will ever be fixed, including an unauthenticated auto-login token forgery that authenticates as any account, a | 2026-08-21 | 2026-08-21 | 2026-08-21 |
| CVE-2026-64970 | Thirteen CVEs in ATutor, none of which will ever be fixed, including an unauthenticated auto-login token forgery that authenticates as any account, a | 2026-08-21 | 2026-08-21 | 2026-08-21 |
| CVE-2026-64971 | Thirteen CVEs in ATutor, none of which will ever be fixed, including an unauthenticated auto-login token forgery that authenticates as any account, a | 2026-08-21 | 2026-08-21 | 2026-08-21 |
| CVE-2026-64972 | Thirteen CVEs in ATutor, none of which will ever be fixed, including an unauthenticated auto-login token forgery that authenticates as any account, a | 2026-08-21 | 2026-08-21 | 2026-08-21 |
| CVE-2026-69414 | Microsoft Defender / Malware Protection Engine elevation of privilege, publicly referred to as ShieldBreak, Microsoft's identifier for the proof-of-concept claiming a bypass of the July fix for CVE-2026-50656. Important, CVSS 3.1 base 7.8, publicly disclosed, exploitation not detected, assessed 'Exploitation More Likely'; no update available at publication. | 2026-08-12 | 2026-08-21 | 2026-08-12 |
| CVE-2026-60672 | Oracle WebLogic Server (Core), unauthenticated flaw over T3 and IIOP, CVSS 9.8; August 2026 Critical Security Patch Update. | 2026-08-20 | 2026-08-20 | 2026-08-20 |
| CVE-2026-60782 | Oracle E-Business Suite, Oracle Payments (File Transmission), unauthenticated flaw over HTTP, CVSS 9.8, EBS 12.2.3-12.2.15; August 2026 Critical Security Patch Update. | 2026-08-20 | 2026-08-20 | 2026-08-20 |
| CVE-2026-61241 | Oracle Internet Directory (OID LDAP Server), unauthenticated flaw over LDAP, CVSS 3.1 base 10.0, scope changed; August 2026 Critical Security Patch Update. | 2026-08-20 | 2026-08-20 | 2026-08-20 |
| CVE-2026-64849 | MLflow, unauthenticated full-read SSRF in webhook delivery; the URL guard validates the resolved address but never pins it, and delivery follows redirects unvalidated. CISA KEV 2026-08-19; fixed in 3.15.0. | 2026-08-20 | 2026-08-20 | 2026-08-20 |
| CVE-2026-70880 | Oracle Hyperion Data Relationship Management (Access and security), unauthenticated flaw over TCP, CVSS 3.1 base 10.0; August 2026 Critical Security Patch Update. | 2026-08-20 | 2026-08-20 | 2026-08-20 |
| CVE-2026-70921 | Oracle Hyperion Financial Management (Security), unauthenticated flaw over TLS, CVSS 3.1 base 10.0; August 2026 Critical Security Patch Update. | 2026-08-20 | 2026-08-20 | 2026-08-20 |
| CVE-2026-70926 | Oracle E-Business Suite, Oracle Workflow (Workflow Notification Mailer), unauthenticated flaw over SMTP, CVSS 9.8, EBS 12.2.3-12.2.15; August 2026 Critical Security Patch Update. | 2026-08-20 | 2026-08-20 | 2026-08-20 |
| CVE-2026-73570 | Zimbra Collaboration, pre-authentication command injection in SNMP notification processing reaching OS command execution as the Zimbra user; fixed in 10.1.20 (21 July 2026), CVE published 13 August, ENISA records exploitation from 2026-08-18. | 2026-08-20 | 2026-08-20 | 2026-08-20 |
| CVE-2021-27101 | Accellion FTA SQL injection, referenced by the 2026-08-19 Cl0p Windchill implant entry solely as campaign lineage: the flaw Cl0p exploited before deploying its DEWMODE web shell. Long patched; recorded for provenance of that historical reference, not as in-window coverage. | 2026-08-19 | 2026-08-19 | · |
| CVE-2023-34362 | Progress MOVEit Transfer SQL injection, referenced by the 2026-08-19 Cl0p Windchill implant entry solely as campaign lineage: the flaw Cl0p exploited before deploying its LEMURLOOT web shell. Long patched; recorded for provenance of that historical reference, not as in-window coverage. | 2026-08-19 | 2026-08-19 | · |
| CVE-2026-12569 | PTC Windchill / FlexPLM, pre-auth deserialization RCE, CISA KEV-listed, now driving a Cl0p-attributed mass data-theft extortion campaign | 2026-06-20 | 2026-08-19 | 2026-06-20 |
| CVE-2026-14613 | Keycloak, FGAP v2 role groups endpoint discloses hidden group metadata without group view permission. Named here only as one of the five flaws closed by RHSA-2026:56523 (Red Hat build of Keycloak 26.6.6, 2026-08-18) alongside CVE-2026-18963; recorded so the 26.4 and 26.6 upgrade decisions are comparable, and not otherwise assessed by this store. | 2026-08-19 | 2026-08-19 | · |
| CVE-2026-15571 | Keycloak, predictable account-linking hash enables account takeover via a malicious OIDC client. Closed by RHSA-2026:56523 (Red Hat build of Keycloak 26.6.6, 2026-08-18); Red Hat records a public date of 2026-08-18. A second account-takeover path on the same identity surface as CVE-2026-18963 and one reason the 26.6.6 upgrade is not equivalent to 26.4.15. | 2026-08-19 | 2026-08-19 | · |
| CVE-2026-15748 | WPMU DEV Forminator Forms (WordPress, 600,000+ installs), unauthenticated arbitrary file upload to remote code execution in handle_file_upload: the dangerous-extension blocklist matches MIME-type keys exactly and is bypassed by a pipe-alternative key, while a forged Select-field value overrides the upload field's own type configuration. CVSS 9.8, Wordfence as CNA. Exploitable only on forms carrying both a File Upload and a Select field. Fixed in 1.56.2 (2026-07-31); root-cause write-up published 2026-08-17, relayed by NCSC-CH 2026-08-18. No exploitation reported. | 2026-08-19 | 2026-08-19 | 2026-08-19 |
| CVE-2026-15826 | Cozmoslabs User Profile Builder (WordPress, 40,000+ installs), unauthenticated authentication bypass via type confusion: wppb_log_in_user() calls absint() on the return value of wp_insert_user() before the is_wp_error() check, so a 61-70 character username makes core return a WP_Error that coerces to the integer 1 and the plugin issues an autologin bound to user ID 1. CVSS 9.8, Wordfence as CNA. Exploitable only where the plugin's Automatically Log In setting is enabled. Fixed in 3.16.5 (2026-07-16); write-up 2026-08-14, relayed by NCSC-CH 2026-08-18. No exploitation reported. | 2026-08-19 | 2026-08-19 | 2026-08-19 |
| CVE-2026-17048 | Keycloak, vault-resolved rotated client secrets leaked via the Admin REST API. Closed by RHSA-2026:56523 (Red Hat build of Keycloak 26.6.6, 2026-08-18); a credential-disclosure flaw on the component that fronts single sign-on, recorded alongside CVE-2026-18963 for upgrade comparability. | 2026-08-19 | 2026-08-19 | · |
| CVE-2026-19650 | GitLab CE/EE, cross-site request forgery in the GraphQL multiplex query handler allowing mutations to be executed via GET requests through improper request validation (CVSS 7.1, vendor-assigned). Fixed in the same 2026-08-17 out-of-band release as CVE-2026-19478. | 2026-08-19 | 2026-08-19 | 2026-08-19 |
| CVE-2026-33824 | Windows IKE Extensions (IKE VPN), Unit 42 records reverse-shell callbacks from three endpoints in the autonomous-AI intrusion campaign | 2026-07-31 | 2026-08-19 | 2026-07-31 |
| CVE-2026-55040 | Microsoft SharePoint Server security-feature bypass (CWE-1390 weak authentication), CVSS 9.1, four-weakness JWT forgery chain published with proof-of-concept; exploitation attempts observed against honeypots 2026-08-12 | 2026-07-14 | 2026-08-19 | 2026-07-14 |
| CVE-2026-72898 | Metabase unauthenticated SQL injection via the /api/session/reset_password endpoint reaching administrator access, CVSS 10.0; the identifier assigned in GHSA-vwf4-m7j8-wcjf for the zero-day Metabase confirmed was already being exploited, CISA KEV 2026-08-11. | 2026-08-09 | 2026-08-19 | 2026-08-09 |
| CVE-2026-9796 | Keycloak, privilege escalation via a time-of-check-to-time-of-use race. Closed by RHSA-2026:56523 (Red Hat build of Keycloak 26.6.6, 2026-08-18); recorded as one of the five flaws in that erratum, not otherwise assessed by this store. | 2026-08-19 | 2026-08-19 | · |
| CVE-2023-25158 | GeoTools/GeoServer OGC filter SQL injection fixed in 2023. Referenced by the 2026-08-18 GeoServer entry as the flaw the jsonArrayContains injection regresses: GeoTools states the mitigation published for this CVE (enabling prepared statements and disabling encode functions) is not effective against the 2026 variant, so operators who applied it are not protected. | 2026-08-18 | 2026-08-18 | · |
| CVE-2025-62593 | Ray dashboard code injection, unauthenticated job-submission endpoints guarded only by a User-Agent string check, bypassable from Firefox and Safari via fetch() combined with DNS rebinding, reaching code execution on the host running Ray. Fixed in Ray 2.52.0; CISA KEV-listed 2026-08-17. | 2026-08-18 | 2026-08-18 | 2026-08-18 |
| CVE-2021-22681 | UPDATE, water-sector PLC lockout status: an OT vendor's decade retrospective attributes the Minnesota controller intrusions to a CVE whose own record | 2026-08-16 | 2026-08-16 | · |
| CVE-2022-26134 | Atlassian Confluence Server and Data Center OGNL injection reaching unauthenticated remote code execution, fixed by Atlassian in June 2022. Referenced by the 2026-08-16 Evooo1Bot entry as one of three enterprise-class exploit modules carried by that Mirai-derived botnet; the flaw itself is long patched; the delta is that it is now in commodity automated scanning. | 2026-08-16 | 2026-08-16 | · |
| CVE-2022-29464 | WSO2 API Manager, Identity Server and Enterprise Integrator unrestricted file upload reaching remote code execution via the /fileupload endpoint, fixed by WSO2 in April 2022. Referenced by the 2026-08-16 Evooo1Bot entry as an enterprise exploit module in that botnet's arsenal. | 2026-08-16 | 2026-08-16 | · |
| CVE-2024-4577 | PHP-CGI argument injection on Windows deployments. Referenced by the 2026-08-16 Evooo1Bot entry as an exploit module carried by that botnet. | 2026-08-16 | 2026-08-16 | · |
| CVE-2025-1974 | Kubernetes ingress-nginx admission-controller remote code execution, disclosed March 2025 and fixed in ingress-nginx 1.12.1 and 1.11.5. Referenced by the 2026-08-16 Evooo1Bot entry as the most recent of three enterprise-class exploit modules in that botnet's arsenal. | 2026-08-16 | 2026-08-16 | · |
| CVE-2026-19188 | Haiwell IoT Cloud HMI Gateway, unauthenticated OS command injection as root via the Net Check cmdPing diagnostic (CVSS 10.0); fixed in Scada-v3.50.1.19 | 2026-08-15 | 2026-08-16 | 2026-08-15 |
| CVE-2026-20349 | Cisco Secure Firewall ASA/FTD Remote Access SSL VPN, insufficient error checking on HTTP request processing lets an unauthenticated attacker reload the device (denial of service), CVSS 8.6, no workaround; Cisco PSIRT confirmed active exploitation and CISA KEV-listed it 2026-08-11 with a 14 August due date. | 2026-08-12 | 2026-08-16 | 2026-08-12 |
| CVE-2026-34348 | UPDATE; the fourth passkey attack thread this pipeline could not source last week is now documented, and it closed: Windows cached YubiKey assertions | 2026-08-16 | 2026-08-16 | · |
| CVE-2026-45659 | Microsoft SharePoint Server CWE-502 deserialization RCE, authenticated Site Member (PR:L); CISA KEV since 2026-07-01 and flagged for known ransomware campaign use as of catalog version 2026.08.11 | 2026-05-27 | 2026-08-16 | 2026-07-02 |
| CVE-2026-50656 | Microsoft Defender Malware Protection Engine 'RoguePlanet' link-following LPE to SYSTEM - now fixed (engine >=1.1.26060.3008); NCSC-CH Nightmare Eclipse tracker | 2026-06-19 | 2026-08-16 | 2026-08-12 +2 more |
| CVE-2026-58115 | Siemens SIMATIC IoT2050 Advanced, unauthenticated Node-RED HTTP interface allows remote code execution with maximum privileges (CVSS 10.0), fixed in V4.3.4.1 | 2026-08-13 | 2026-08-16 | 2026-08-13 |
| CVE-2026-65400 | Apple macOS Screen Sharing (screensharingd) pre-authentication improper authentication, CVSS 7.1, fixed in macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9. NCSC-NL advisory NCSC-2026-0280 revision 1.0.1 (2026-08-12) records active abuse observed on multiple systems with port 5900 reachable from the internet, root access obtained in all of them and a Monero cryptocurrency miner planted. | 2026-08-08 | 2026-08-16 | 2026-08-08 |
| CVE-2026-71362 | Adobe Commerce / Adobe Commerce B2B / Magento Open Source, incorrect authorization (CWE-863), CVSS 3.1 9.1, unauthenticated customer account takeover by switching a customer session to another customer's account; no authentication, no admin privileges and no user interaction required. Fixed in the -2026-aug isolated patch files of APSB26-92 (2026-08-11). Adobe states it is not aware of exploits in the wild; Sansec reports its Shield WAF already blocking exploitation attempts. | 2026-08-16 | 2026-08-16 | 2026-08-16 |
| CVE-2026-26035 | Fortinet FortiWeb, improper authentication lets an unauthenticated attacker log into the GUI/CLI with any username and password when the non-default RADIUS admin Wildcard option is enabled | 2026-08-15 | 2026-08-15 | 2026-08-15 |
| CVE-2026-70465 | Fortinet FortiClient for Windows, buffer copy without size check lets an unauthenticated attacker able to alter or craft DNS responses execute arbitrary code (CVSS 8.1); fixed in 7.4.4 / 7.2.12 | 2026-08-15 | 2026-08-15 | 2026-08-15 |
| CVE-2026-70466 | Fortinet FortiWeb, incomplete list of disallowed inputs allows an unauthenticated attacker to bypass WAF policies; fixed in 8.0.3 / 7.6.6, with no fixed build for the 7.4 and 7.2 branches | 2026-08-15 | 2026-08-15 | 2026-08-15 |
| CVE-2026-70468 | Fortinet FortiManager / FortiManager Cloud, FGFM authentication bypass letting a holder of a valid certificate impersonate any managed FortiGate when fgfm-peercert-withoutsn is set | 2026-08-15 | 2026-08-15 | 2026-08-15 |
| CVE-2026-73487 | Flowise before 3.1.3, regex-based Python code-validator bypass in CSV and Airtable Agent nodes reachable by prompt injection through the unauthenticated prediction API | 2026-08-08 | 2026-08-15 | 2026-08-08 |
| CVE-2024-38193 | Windows Ancillary Function Driver for WinSock use-after-free, patched August 2024 and reported at the time as exploited by FudModule. Referenced as prior-art context by the 2026-08-12 Lazarus entry: the same driver family has now yielded a second FudModule privilege-escalation zero-day. | 2026-08-12 | 2026-08-12 | · |
| CVE-2025-60719 | Use-after-free in the Windows AFD.sys driver fixed in November 2025 and not linked to any particular threat actor. Referenced by the 2026-08-12 Lazarus entry: Check Point states the 2026 exploit initially resembled it but testing on a fully patched system confirmed a distinct, previously undocumented vulnerability. | 2026-08-12 | 2026-08-12 | · |
| CVE-2026-18556 | N-able N-central, authentication bypass using an alternate path or channel (CWE-288), affects through 2026.1, fixed in 2026.2 (CVSS 8.2) | CISA KEV 2026-08-04. | 2026-08-03 | 2026-08-12 | 2026-08-03 |
| CVE-2026-18577 | N-able N-central, incomplete patch for CVE-2026-18556; unauthenticated admin auth bypass exploited in the wild, superseded by Hotfix 2 build 2026.3.1.10 of 2026-08-06, which the vendor requires even where 2026.3.1.7 was applied (CVSS 8.2) | 2026-08-03 | 2026-08-12 | 2026-08-03 |
| CVE-2026-62832 | Windows User Profile Service improper link resolution before file access, local elevation of privilege, CVSS 7.8, publicly disclosed before the fix and rated Exploitation More Likely; patched 2026-08-11. Rapid7 assesses the advisory is a solid match for the LegacyHive proof-of-concept. | 2026-07-29 | 2026-08-12 | 2026-07-29 |
| CVE-2026-63520 | Microsoft SharePoint Server remote code execution (CWE-20 improper input validation), CVSS 8.1, patched 2026-08-11. Rapid7, which discovered it, states it is the second of a pair that chain into a critical unauthenticated RCE against a vulnerable SharePoint server. | 2026-07-14 | 2026-08-12 | 2026-07-14 |
| CVE-2024-55591 | Fortinet FortiOS / FortiProxy authentication bypass (CWE-288), named by joint advisory AA26-222A as a primary Gunra ransomware initial-access vector, abused to create a persistent super-user account on the appliance | 2026-05-10 | 2026-08-11 | 2026-08-11 |
| CVE-2025-24472 | Fortinet FortiOS / FortiProxy authentication bypass (CWE-288), named by joint advisory AA26-222A as a primary Gunra ransomware initial-access vector, abused to create a persistent super-user account on the appliance | 2026-08-11 | 2026-08-11 | 2026-08-11 |
| CVE-2017-16740 | Rockwell Automation Allen-Bradley MicroLogix 1400 Series B/C firmware 21.002 and earlier; stack-based buffer overflow that may allow remote code execution. Referenced as a firmware-currency signal on internet-exposed controllers in already-attacked water-utility cities; Forescout states exploitation would require Modbus TCP enabled, which was not confirmed, and that no CVE is confirmed as exploited in that campaign. | 2026-08-10 | 2026-08-10 | · |
| CVE-2026-25770 | Wazuh cluster protocol privilege escalation to root via file write, fixed in 4.14.3 by the _ALLOWED_PREFIXES hardening. Referenced as the earlier fix that CVE-2026-49441 and CVE-2026-48024 both bypass through sibling code paths. | 2026-08-10 | 2026-08-10 | · |
| CVE-2026-31431 | Copy Fail, Linux kernel algif_aead local privilege escalation (ITW, KEV) | 2026-05-06 | 2026-08-10 | 2026-07-18 |
| CVE-2026-44901 | Wazuh distributed API, deserialization RCE as root via unallowlisted builtin resolution when a request fans out across two or more nodes (CVSS 8.4); fixed 4.14.6 | 2026-08-10 | 2026-08-10 | 2026-08-10 |
| CVE-2026-45798 | Wazuh wazuh-authd, pre-authentication stack buffer overflow reachable on TCP/1515 under the shipped anonymous-SSL default (CVSS 7.5); fixed 4.14.6 | 2026-08-10 | 2026-08-10 | 2026-08-10 |
| CVE-2026-48024 | Wazuh cluster protocol, sibling arbitrary-file-write-to-root path via peer-controlled merged-file header traversal (CVSS 9.1); fixed 4.14.6 | 2026-08-10 | 2026-08-10 | 2026-08-10 |
| CVE-2026-49441 | Wazuh cluster protocol, arbitrary file write to root RCE on the master file-receive path, bypassing the CVE-2026-25770 fix (CVSS 9.1); fixed 4.14.6 | 2026-08-10 | 2026-08-10 | 2026-08-10 |
| CVE-2026-56181 | NatJack, Windows NAT origin-validation error allowing downstream-spoofing TCP session hijack, affecting Hyper-V; fixed in the July 2026 security update | 2026-08-10 | 2026-08-10 | 2026-08-10 |
| CVE-2026-63913 | NatJack; Linux netfilter TCP conntrack state machine forced to CLOSE by an RST with an invalid sequence number, enabling downstream-spoofing TCP session hijack; fixed in 7.1 and stable/LTS backports | 2026-08-10 | 2026-08-10 | 2026-08-10 |
| CVE-2026-64638 | WordPress Core XSS2Shell, pre-auth login-screen reflected XSS chaining via DOM clobbering and a JSONP callback to Application-Password minting and plugin upload (CVSS 4.0 8.9); fixed 7.0.3 with backports to 4.7.34 | 2026-08-10 | 2026-08-10 | 2026-08-10 |
| CVE-2026-66066 | Ruby on Rails Active Storage variant processing on libvips, unauthenticated arbitrary file read (and possible RCE via exposed application secrets) from an untrusted image upload; CVSS 4.0 9.5 assigned by GitHub Security Advisories as the Rails CNA; fixed in activestorage 7.2.3.2 / 8.0.5.1 / 8.1.3.1 and requires libvips >= 8.13 to be effective | 2026-07-31 | 2026-08-10 | 2026-07-31 |
| CVE-2026-12070 | Tobit TeamDavid Webbox, authenticated arbitrary file deletion via @@COMMENTFILE | 2026-08-09 | 2026-08-09 | 2026-08-09 |
| CVE-2026-12071 | Tobit TeamDavid Webbox, open redirect via URL-encoded manipulation of the 302 redirect domain | 2026-08-09 | 2026-08-09 | 2026-08-09 |
| CVE-2026-17583 | Thermo Fisher Applied Biosystems genetic analyzers, result files written without integrity checking; CORRECTED 2026-08-09: patched software exists for five product lines (4.0.3 / 5.0.3 / 1.2.6 / 1.2.1 / 1.7.4), three EoL lines unfixed | 2026-08-05 | 2026-08-09 | 2026-08-05 |
| CVE-2026-25177 | KerberLoss, Active Directory Domain Services SPN uniqueness bypass via unfilterable Unicode, enabling Kerberos ticket mis-encryption and NTLM downgrade | 2026-08-09 | 2026-08-09 | · |
| CVE-2026-2699 | Progress ShareFile Storage Zone Controller, pre-auth authentication bypass, exploited in the wild from 2026-07-10 (Shadowserver); NEVER CISA KEV-listed (verified against catalogVersion 2026.08.07) | 2026-07-13 | 2026-08-09 | 2026-07-13 |
| CVE-2026-2701 | Progress ShareFile Storage Zone Controller, chained storage-repointing RCE, exploited alongside CVE-2026-2699; NEVER CISA KEV-listed (verified against catalogVersion 2026.08.07) | 2026-07-13 | 2026-08-09 | 2026-07-13 |
| CVE-2026-27912 | ResetNightmare, Windows Kerberos password-change flow accepts a UPN-borrowed identity, taking a low-privileged user to Domain Admin | 2026-08-09 | 2026-08-09 | · |
| CVE-2026-54199 | Tobit TeamDavid Webbox, HTTP header injection in the link-storing function via request body | 2026-08-09 | 2026-08-09 | 2026-08-09 |
| CVE-2026-54200 | Tobit TeamDavid Webbox, authenticated local file inclusion via @@attach with NTFS ADS filter bypass | 2026-08-09 | 2026-08-09 | 2026-08-09 |
| CVE-2026-54201 | Tobit TeamDavid Webbox, error log files served without authentication or authorisation | 2026-08-09 | 2026-08-09 | 2026-08-09 |
| CVE-2026-54202 | Tobit TeamDavid Webbox, authenticated path traversal in archive creation | 2026-08-09 | 2026-08-09 | 2026-08-09 |
| CVE-2026-54203 | Tobit TeamDavid Webbox, unauthenticated uninitialised-heap disclosure via /.well-known/mta-sts. leaking stored credentials | 2026-08-09 | 2026-08-09 | 2026-08-09 |
| CVE-2026-54204 | Tobit TeamDavid Webbox, unauthenticated SSRF via UNC path in the search pathnameroot parameter | 2026-08-09 | 2026-08-09 | 2026-08-09 |
| CVE-2026-54205 | Tobit TeamDavid Webbox, authenticated SSRF via UNC path in the link-storing pathname parameter | 2026-08-09 | 2026-08-09 | 2026-08-09 |
| CVE-2026-54206 | Tobit TeamDavid Webbox, authenticated SSRF via UNC path in the @@INCLUDE messaging command | 2026-08-09 | 2026-08-09 | 2026-08-09 |
| CVE-2026-54207 | Tobit TeamDavid Webbox, authenticated SSRF via UNC path in the !ArcEntryMove archive-move function | 2026-08-09 | 2026-08-09 | 2026-08-09 |
| CVE-2026-54208 | Tobit TeamDavid Webbox, unauthenticated arbitrary file write reaching stored XSS | 2026-08-09 | 2026-08-09 | 2026-08-09 |
| CVE-2026-54209 | Tobit TeamDavid Webbox, unauthenticated buffer overflow via (editini) arbitrary-path read into a fixed stack buffer | 2026-08-09 | 2026-08-09 | 2026-08-09 |
| CVE-2026-54210 | Tobit TeamDavid Webbox, unauthenticated buffer overflow via overlong upload filename | 2026-08-09 | 2026-08-09 | 2026-08-09 |
| CVE-2026-54211 | Tobit TeamDavid Webbox, authenticated buffer overflow in serverClient_close.html form parameters | 2026-08-09 | 2026-08-09 | 2026-08-09 |
| CVE-2026-54212 | Tobit TeamDavid Webbox, unauthenticated buffer overflow via crafted API request body | 2026-08-09 | 2026-08-09 | 2026-08-09 |
| CVE-2026-54213 | Tobit TeamDavid Webbox, unauthenticated single-request denial of service via /internalRestart | 2026-08-09 | 2026-08-09 | 2026-08-09 |
| CVE-2026-54214 | Tobit TeamDavid Webbox, HTTP header injection via the cType parameter (Content-Type control) | 2026-08-09 | 2026-08-09 | 2026-08-09 |
| CVE-2026-54215 | Tobit TeamDavid Webbox, open redirect via the replyUrl parameter | 2026-08-09 | 2026-08-09 | 2026-08-09 |
| CVE-2026-54216 | Tobit TeamDavid Webbox, reflected cross-site scripting via !templateName/EntryInfo | 2026-08-09 | 2026-08-09 | 2026-08-09 |
| CVE-2026-54217 | Tobit TeamDavid Webbox, stored cross-site scripting via email content | 2026-08-09 | 2026-08-09 | 2026-08-09 |
| CVE-2026-54218 | Tobit TeamDavid Webbox, reversible (XOR-obfuscated) storage of user passwords in access.ini | 2026-08-09 | 2026-08-09 | 2026-08-09 |
| CVE-2026-71851 | crypto-js < 4.0.0, CryptoJS.lib.WordArray.random() is not a CSPRNG; ~2^39/2^47 effective entropy, actively exploited to drain wallets (Coinspect 'Ill Bloom') | 2026-08-09 | 2026-08-09 | 2026-08-09 |
| CVE-2025-71409 | CPDLC over ATN-B1, missing authentication for VHF Data Link messages allows rogue ground stations to inject clearances (CVSS 7.1); no mitigation available | 2026-08-08 | 2026-08-08 | 2026-08-08 |
| CVE-2025-71410 | CPDLC over ATN-B1, Unnumbered Disconnect and malformed link-control frames terminate CPDLC sessions (CVSS 5.3); no mitigation available | 2026-08-08 | 2026-08-08 | 2026-08-08 |
| CVE-2025-71411 | CPDLC over ATN-B1, broadcast control frames disconnect multiple aircraft simultaneously (CVSS 5.3); no mitigation available | 2026-08-08 | 2026-08-08 | 2026-08-08 |
| CVE-2025-71412 | CPDLC over ATN-B1, injection of false emergency or status messages (CVSS 7.1); no mitigation available | 2026-08-08 | 2026-08-08 | 2026-08-08 |
| CVE-2025-71413 | CPDLC over ATN-B1, malformed or out-of-sequence X.25-layer frames cause repeated resets (CVSS 5.3); no mitigation available | 2026-08-08 | 2026-08-08 | 2026-08-08 |
| CVE-2026-20267 | Cisco IOS XE August 2026 hardening release, improper access control CWE grouping (CVSS 9.0); fixed 17.9.10/17.12.8/17.15.6/17.18.4/26.1.2 | 2026-08-08 | 2026-08-08 | 2026-08-08 |
| CVE-2026-20268 | Cisco IOS XE August 2026 hardening release, memory-buffer bounds CWE grouping (CVSS 8.6) | 2026-08-08 | 2026-08-08 | 2026-08-08 |
| CVE-2026-20269 | Cisco IOS XE August 2026 hardening release, resource lifetime CWE grouping (CVSS 8.6) | 2026-08-08 | 2026-08-08 | 2026-08-08 |
| CVE-2026-20270 | Cisco IOS XE August 2026 hardening release, incorrect calculation CWE grouping (CVSS 8.6) | 2026-08-08 | 2026-08-08 | 2026-08-08 |
| CVE-2026-20271 | Cisco IOS XE August 2026 hardening release, control-flow management CWE grouping (CVSS 8.6) | 2026-08-08 | 2026-08-08 | 2026-08-08 |
| CVE-2026-20272 | Cisco IOS XE August 2026 hardening release, command/OS/argument injection CWE grouping (CVSS 9.8), highest of the batch; no workaround | 2026-08-08 | 2026-08-08 | 2026-08-08 |
| CVE-2026-20273 | Cisco IOS XE August 2026 hardening release, input validation / path traversal CWE grouping (CVSS 8.6) | 2026-08-08 | 2026-08-08 | 2026-08-08 |
| CVE-2026-41273 | Flowise, earlier authentication bypass on the OAuth2 credential-refresh route; the fix was incomplete and is bypassed by CVE-2026-70636 | 2026-08-08 | 2026-08-08 | · |
| CVE-2026-53359 | Linux KVM/x86 'Januscape' shadow-MMU use-after-free, guest-to-host VM escape on Intel and AMD (public PoC host-DoS; RCE withheld); fixed 6.1.177/6.6.144/6.12.95/6.18.38/7.1.3 | 2026-07-09 | 2026-08-08 | 2026-07-09 |
| CVE-2026-60137 | WordPress core WP_Query author__not_in SQL injection (WP2Shell chain component) | 2026-07-18 | 2026-08-08 | 2026-07-18 |
| CVE-2026-63030 | WP2Shell: WordPress core REST batch route confusion to pre-auth RCE chain | 2026-07-18 | 2026-08-08 | 2026-07-18 |
| CVE-2026-64561 | Linux KVM/x86 'Zapscape'; use-after-free in the recursive shadow-MMU zap path gives guest-root-to-host escape (CVSS 8.8); needs nested virtualization, and on Intel EPT page-walk lengths 4 and 5 exposed to L1; fixed upstream 2abd5287f083 | 2026-07-09 | 2026-08-08 | 2026-07-09 |
| CVE-2026-67621 | Flowise ≤3.1.4, missing authorization on document-store mutation endpoints lets a view-only member drive ingestion (CVSS 4.0 7.2, CWE-862); no fix, vendor sunsetting | 2026-08-08 | 2026-08-08 | 2026-08-08 |
| CVE-2026-67622 | Flowise ≤3.1.4; IDOR in the OpenAI Assistants integration gives cross-workspace credential access (CVSS 4.0 8.5, CWE-639); no fix, vendor sunsetting | 2026-08-08 | 2026-08-08 | 2026-08-08 |
| CVE-2026-70636 | Flowise ≤3.1.4, unauthenticated OAuth2 credential-refresh endpoint reachable via prefix-whitelist bypass (CVSS 4.0 8.7, CWE-862); bypass of CVE-2026-41273; no fix, vendor sunsetting | 2026-08-08 | 2026-08-08 | 2026-08-08 |
| CVE-2026-8037 | Progress Kemp LoadMaster pre-auth command injection, added to CISA KEV 2026-08-07 on evidence of active exploitation; fixed GA 7.2.63.2 / LTSF 7.2.54.18 | 2026-06-09 | 2026-08-08 | 2026-06-30 |
| CVE-2026-15572 | Keycloak; Dynamic Client Registration 'Allowed Protocol Mapper Types' policy does not re-validate mapper type on update, allowing a type-swap to an admin-role-hardcoding mapper and full realm admin; CVSS 8.8, fixed in 26.4.14 / 26.6.5 / 26.7.1 | 2026-08-07 | 2026-08-07 | 2026-08-07 |
| CVE-2026-15573 | Keycloak; Authorization Services PathMatcher does not normalize URIs, so a trailing slash or matrix parameter selects a less restrictive policy and an authenticated user reaches restricted paths; CVSS 8.1, fixed in 26.4.14 / 26.6.5 / 26.7.1 | 2026-08-07 | 2026-08-07 | 2026-08-07 |
| CVE-2026-16071 | Keycloak, LDAP entry-DN user search escapes the configured users-DN boundary, disclosing and importing directory entries from outside the intended scope; CVSS 5.4, fixed in 26.4.14 / 26.6.5 / 26.7.1 | 2026-08-07 | 2026-08-07 | 2026-08-07 |
| CVE-2026-16100 | Keycloak, user-event metrics record request-controlled error text as Prometheus labels, giving an authenticated user an unbounded-cardinality memory-exhaustion DoS; CVSS 6.5, fixed in 26.4.14 / 26.6.5 / 26.7.1 | 2026-08-07 | 2026-08-07 | 2026-08-07 |
| CVE-2026-16102 | Keycloak, default Dynamic Client Registration policy mis-validates the claim path for User Property mappers, letting a standard account with a limited Initial Access Token forge administrative roles and reach full realm control; CVSS 8.1, fixed in 26.4.14 / 26.6.5 / 26.7.1 | 2026-08-07 | 2026-08-07 | 2026-08-07 |
| CVE-2026-16442 | Keycloak; SAML IdP-initiated SSO endpoint does not check the link-only restriction, so an attacker controlling a linked upstream identity gains full access to the local account; CVSS 7.4, fixed in 26.4.14 / 26.6.5 / 26.7.1 | 2026-08-07 | 2026-08-07 | 2026-08-07 |
| CVE-2026-16443 | Keycloak / Red Hat Build of Keycloak, SAML broker metadata import without key-usage attributes disables response signature validation, letting an unauthenticated attacker forge a SAML response and log in as any user whose external identifier is known; CVSS 7.4, fixed in 26.4.14 / 26.6.5 / 26.7.1 | 2026-08-07 | 2026-08-07 | 2026-08-07 |
| CVE-2026-48317 | Adobe Campaign Classic (on-premise), authenticated eval injection (CWE-95) reaching arbitrary code execution, CVSS 9.6; APSB26-120, fixed in ACC v7 7.4.3 build 9399 | 2026-08-07 | 2026-08-07 | 2026-08-07 |
| CVE-2026-48323 | Adobe Campaign Classic (on-premise), unauthenticated template-engine injection (CWE-1336) reaching arbitrary code execution, CVSS 10.0, scope changed; APSB26-120, fixed in ACC v7 7.4.3 build 9399 | 2026-08-07 | 2026-08-07 | 2026-08-07 |
| CVE-2026-48326 | Adobe Campaign Classic (on-premise), authenticated SQL injection (CWE-89) reaching arbitrary code execution, CVSS 9.9; APSB26-120, fixed in ACC v7 7.4.3 build 9399 | 2026-08-07 | 2026-08-07 | 2026-08-07 |
| CVE-2026-48330 | Adobe Campaign Classic (on-premise), unauthenticated SQL injection (CWE-89) reaching arbitrary code execution, CVSS 10.0, scope changed; APSB26-120, fixed in ACC v7 7.4.3 build 9399 | 2026-08-07 | 2026-08-07 | 2026-08-07 |
| CVE-2026-48331 | Adobe Campaign Classic (on-premise), unauthenticated SSRF (CWE-918) reaching arbitrary code execution, CVSS 10.0, scope changed; APSB26-120, fixed in ACC v7 7.4.3 build 9399 | 2026-08-07 | 2026-08-07 | 2026-08-07 |
| CVE-2026-48333 | Adobe Campaign Classic (on-premise), unauthenticated incorrect authorization (CWE-863) giving privilege escalation, CVSS 9.8; APSB26-120, fixed in ACC v7 7.4.3 build 9399 | 2026-08-07 | 2026-08-07 | 2026-08-07 |
| CVE-2026-48399 | Adobe Campaign Classic (on-premise), violation of secure design principles (CWE-657) giving a security-feature bypass, CVSS 7.5; APSB26-120, fixed in ACC v7 7.4.3 build 9399 | 2026-08-07 | 2026-08-07 | 2026-08-07 |
| CVE-2026-58047 | cPanel & WHM, HTTP request smuggling in cpsrvd allowing an unauthenticated attacker to manipulate responses delivered to other users on the same server (CVSS v4.0 5.6); interim mitigation disables cpsrvd backend connection reuse | 2026-08-06 | 2026-08-06 | 2026-08-06 |
| CVE-2026-58048 | cPanel & WHM, SQL mode not preserved when renaming a database, so an authenticated account holder with the MySQL/MariaDB feature executes SQL in root context (CVSS v4.0 9.4, HackerOne CNA); fixed across the 11.110–11.136 build lines and WP Squared 138.1.6 | 2026-08-06 | 2026-08-06 | 2026-08-06 |
| CVE-2026-58067 | Veeam Service Provider Console, unauthenticated host-memory exhaustion denial of service (CVSS v4.0 8.7); fixed in 9.3.0.35057 | 2026-08-06 | 2026-08-06 | 2026-08-06 |
| CVE-2026-58071 | Veeam Service Provider Console, unauthenticated access to the proxied appliance API as Portal Administrator during a window after an admin session begins (CVSS v4.0 8.2); fixed in 9.3.0.35057 | 2026-08-06 | 2026-08-06 | 2026-08-06 |
| CVE-2026-58072 | Veeam Service Provider Console, arbitrary file write on the management server leading to remote code execution (CVSS v4.0 9.0); fixed in 9.3.0.35057 | 2026-08-06 | 2026-08-06 | 2026-08-06 |
| CVE-2026-58073 | Veeam Service Provider Console, unauthenticated attacker impersonates a managed agent and obtains its credentials (CVSS v4.0 9.5, high attack complexity); fixed in SPC 9.3.0.35057 | 2026-08-06 | 2026-08-06 | 2026-08-06 |
| CVE-2026-58074 | Veeam ONE, arbitrary code execution on the server by a high-privileged user (CVSS v4.0 8.6); fixed in 13.1.0.7034 | 2026-08-06 | 2026-08-06 | 2026-08-06 |
| CVE-2026-58075 | Veeam ONE, unauthenticated arbitrary file read from the host, leveragable to local privilege escalation (CVSS v4.0 8.7); fixed in 13.1.0.7034 | 2026-08-06 | 2026-08-06 | 2026-08-06 |
| CVE-2026-63455 | HPE Aruba Networking SD-WAN Orchestrator, REST API authentication bypass via spoofed HTTP headers (CVSS v3.1 9.8), 9.6.x branch only; fixed in 9.6.2.40210 / 9.6.3.40140 / 9.7.0.43264 | 2026-08-06 | 2026-08-06 | 2026-08-06 |
| CVE-2026-63456 | HPE Aruba Networking SD-WAN Orchestrator, second REST API authentication bypass via spoofed HTTP headers (CVSS v3.1 9.8), 9.6.x branch only; fixed in 9.6.2.40210 / 9.6.3.40140 / 9.7.0.43264 | 2026-08-06 | 2026-08-06 | 2026-08-06 |
| CVE-2026-64630 | Veeam ONE; low-privileged retrieval of report data outside a shared link's scope (CVSS v4.0 5.3); fixed in 13.1.0.7034 | 2026-08-06 | 2026-08-06 | 2026-08-06 |
| CVE-2026-64631 | Veeam ONE, SQL injection by a low-privileged user extracting database contents (CVSS v4.0 8.6); fixed in 13.1.0.7034 | 2026-08-06 | 2026-08-06 | 2026-08-06 |
| CVE-2026-64633 | Veeam ONE, unauthenticated remote code execution on the agent host (CVSS v4.0 10.0); fixed in Veeam ONE 13.1.0.7034 | 2026-08-06 | 2026-08-06 | 2026-08-06 |
| CVE-2026-64634 | Veeam ONE, local privilege escalation into the Reporter service context (CVSS v4.0 8.4); fixed in 13.1.0.7034 | 2026-08-06 | 2026-08-06 | 2026-08-06 |
| CVE-2026-66747 | Zbtlink routers/CPE, ENDLESSDOORS, a factory-installed unauthenticated root-command backdoor started by the vendor's own init script across 20+ models; no fix, VulnCheck advises device replacement | 2026-08-06 | 2026-08-06 | 2026-08-06 |
| CVE-2026-18574 | Check Point Security Management / Multi-Domain Security Management, unauthenticated bypass of management authentication to arbitrary command execution; fixed in Jumbo HFA R81.20 Take 161 / R82 Take 122 / R82.10 Take 40, no fix for the R80.x / R81 / R81.10 end-of-support trains | 2026-08-05 | 2026-08-05 | 2026-08-05 |
| CVE-2026-29146 | Apache Tomcat; EncryptInterceptor defaulted to CBC and was exploitable as a padding oracle; its fix introduced the fail-open regression tracked as CVE-2026-34486 | 2026-08-05 | 2026-08-05 | · |
| CVE-2026-34486 | Apache Tomcat Tribes/EncryptInterceptor fail-open; the fix for CVE-2026-29146 let messages that fail decryption reach the Java deserialization path; CISA KEV 2026-08-04 (previously recorded only as reverse-shell attempts observed by Unit 42); fixed in 9.0.117 / 10.1.54 / 11.0.21 | 2026-08-02 | 2026-08-05 | 2026-08-05 |
| CVE-2026-9198 | IBM Langflow, unauthenticated auto_login endpoint mints a superuser token, chained with the code-validation endpoint for pre-auth code execution (CVSS 9.8); CISA KEV 2026-08-04; affects Langflow OSS 1.0.0-1.10.0 | 2026-07-22 | 2026-08-05 | 2026-07-22 |
| CVE-2026-15410 | SonicWall SMA1000 AMC post-auth code injection (actively exploited) | 2026-07-14 | 2026-08-04 | 2026-07-14 |
| CVE-2026-51294 | FABRICATED / NOT A REAL VULNERABILITY, a use-after-free claim against SQLite 3.41 from the LLM-generated advisory batch published via the programmervuln/cveadvisory- GitHub repository. NOT among the six ids JFrog Security Research reproduction-tested; JFrog assessed 54 of the 55 advisories from that account as completely fabricated, and SQLite's maintainer reported the wave independently on 2026-07-29. Still live as an unreviewed record in the GitHub Advisory Database (GHSA-4r76-5xh9-qj36) on 2026-08-04, after BSI CERT-Bund and NCSC-NL had withdrawn their SQLite advisories. Recorded here so a scanner or triage lookup resolves to the retraction; do NOT open remediation work from this id. | 2026-08-04 | 2026-08-04 | · |
| CVE-2026-51296 | FABRICATED / NOT A REAL VULNERABILITY, one of the LLM-generated SQLite advisories published via the programmervuln/cveadvisory- GitHub repository. JFrog Security Research reproduction-tested it under AddressSanitizer against the claimed SQLite release and it did not reproduce; it cited lines 3555 and 3575 of src/json.c in a file that is 2706 lines long in the claimed version 3.41.0. NCSC-NL withdrew NCSC-2026-0268 on 2026-08-03 stating the CVE was hallucinated by an LLM, and BSI CERT-Bund withdrew WID-SEC-2026-2581 and WID-SEC-2026-2604 the same day. Recorded here so a scanner or triage lookup resolves to the retraction; do NOT open remediation work from this id. | 2026-08-04 | 2026-08-04 | · |
| CVE-2026-51297 | FABRICATED / NOT A REAL VULNERABILITY, one of the LLM-generated SQLite advisories published via the programmervuln/cveadvisory- GitHub repository. JFrog Security Research reproduction-tested it under AddressSanitizer against the claimed SQLite release and it did not reproduce; it referenced jsonBlobEdit(), a function absent from the claimed version 3.41.0. NCSC-NL withdrew NCSC-2026-0268 on 2026-08-03 stating the CVE was hallucinated by an LLM, and BSI CERT-Bund withdrew WID-SEC-2026-2581 and WID-SEC-2026-2604 the same day. Recorded here so a scanner or triage lookup resolves to the retraction; do NOT open remediation work from this id. | 2026-08-04 | 2026-08-04 | · |
| CVE-2026-51300 | FABRICATED / NOT A REAL VULNERABILITY, one of the LLM-generated SQLite advisories published via the programmervuln/cveadvisory- GitHub repository. JFrog Security Research reproduction-tested it under AddressSanitizer against the claimed SQLite release and it did not reproduce; the cited line numbers are a comment and a memory allocation, unrelated to the deletion logic it describes. NCSC-NL withdrew NCSC-2026-0268 on 2026-08-03 stating the CVE was hallucinated by an LLM, and BSI CERT-Bund withdrew WID-SEC-2026-2581 and WID-SEC-2026-2604 the same day. Recorded here so a scanner or triage lookup resolves to the retraction; do NOT open remediation work from this id. | 2026-08-04 | 2026-08-04 | · |
| CVE-2026-51302 | FABRICATED / NOT A REAL VULNERABILITY, one of the LLM-generated SQLite advisories published via the programmervuln/cveadvisory- GitHub repository. JFrog Security Research reproduction-tested it under AddressSanitizer against the claimed SQLite release and it did not reproduce; the named function exprComputeOperands() did not exist in SQLite 3.41 and sqlite3ReleaseTempReg() performs no heap deallocation, making the claimed bug class impossible; Red Hat initially scored it 10.0 before downgrading to 7.6. NCSC-NL withdrew NCSC-2026-0268 on 2026-08-03 stating the CVE was hallucinated by an LLM, and BSI CERT-Bund withdrew WID-SEC-2026-2581 and WID-SEC-2026-2604 the same day. Recorded here so a scanner or triage lookup resolves to the retraction; do NOT open remediation work from this id. | 2026-08-04 | 2026-08-04 | · |
| CVE-2026-51303 | FABRICATED / NOT A REAL VULNERABILITY, one of the LLM-generated SQLite advisories published via the programmervuln/cveadvisory- GitHub repository. JFrog Security Research reproduction-tested it under AddressSanitizer against the claimed SQLite release and it did not reproduce; it claimed a fix in 3.51.3 although a 3.51.2-to-3.51.3 diff shows no changes to src/expr.c at all. NCSC-NL withdrew NCSC-2026-0268 on 2026-08-03 stating the CVE was hallucinated by an LLM, and BSI CERT-Bund withdrew WID-SEC-2026-2581 and WID-SEC-2026-2604 the same day. Recorded here so a scanner or triage lookup resolves to the retraction; do NOT open remediation work from this id. | 2026-08-04 | 2026-08-04 | · |
| CVE-2026-51304 | FABRICATED / NOT A REAL VULNERABILITY, one of the LLM-generated SQLite advisories published via the programmervuln/cveadvisory- GitHub repository. JFrog Security Research reproduction-tested it under AddressSanitizer against the claimed SQLite release and it did not reproduce; it gave a single-argument signature for a function that requires a database-handle argument. NCSC-NL withdrew NCSC-2026-0268 on 2026-08-03 stating the CVE was hallucinated by an LLM, and BSI CERT-Bund withdrew WID-SEC-2026-2581 and WID-SEC-2026-2604 the same day. Recorded here so a scanner or triage lookup resolves to the retraction; do NOT open remediation work from this id. | 2026-08-04 | 2026-08-04 | · |
| CVE-2025-11371 | Gladinet CentreStack and Triofox, files or directories accessible to external parties; added to the CISA Known Exploited Vulnerabilities catalog 2025-11-04. Referenced as historical exploitation context by the 2026-08-03 CentreStack entry. | 2025-11-04 | 2026-08-03 | · |
| CVE-2025-14611 | Gladinet CentreStack and Triofox, hard-coded cryptographic key vulnerability; added to the CISA Known Exploited Vulnerabilities catalog 2025-12-15. Referenced as historical exploitation context by the 2026-08-03 CentreStack entry. | 2025-12-15 | 2026-08-03 | · |
| CVE-2025-30406 | Gladinet CentreStack, use of a hard-coded cryptographic key; added to the CISA Known Exploited Vulnerabilities catalog 2025-04-08. Referenced as historical exploitation context by the 2026-08-03 CentreStack entry. | 2025-04-08 | 2026-08-03 | · |
| CVE-2026-12185 | Bouncy Castle for Java (< 1.85), BKS/UBER keystore allocates from untrusted lengths before integrity check (CVSS 7.1) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-12802 | Bouncy Castle for Java (< 1.85); CMS AuthEnvelopedData fails to enforce tag-length on decryption (CVSS 8.7) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-12803 | Bouncy Castle for Java (< 1.85); KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery) (CVSS 8.7) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-12816 | Bouncy Castle for Java (< 1.85), IESEngine stream-mode MAC forgery via length-dependent KDF split (CVSS 8.7) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-12817 | Bouncy Castle for Java (< 1.85), OpenPGP AEAD decryption skips final tag on chunk-aligned data (CVSS 8.7) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-12852 | Bouncy Castle for Java (< 1.85), MLS wire decoder allocates attacker-declared opaque length before bounds check (CVSS 8.7) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-12860 | Bouncy Castle for Java (< 1.85), RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path (CVSS 8.7) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-13506 | Bouncy Castle for Java (< 1.85), Lazy ASN.1 sequence forcing resets nesting-depth guard (CVSS 8.7) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-13586 | Bouncy Castle for Java (< 1.85), PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS) (CVSS 5.3) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-14682 | Bouncy Castle for Java (< 1.85), Possible OOM from unbounded up-front allocation on a definite-length read (CVSS 8.7) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-15055 | Bouncy Castle for Java (< 1.85), PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input (CVSS 5.3) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-54363 | Gladinet CentreStack < 17.5, hardcoded cryptographic key (static SysNumber) forges AccessTickets and x-glad-auth headers, reaching a domain-administrator IdentityTicket and unauthenticated RCE (CVSS 9.3) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-54364 | Gladinet CentreStack < 17.4, session-variable injection at SelectProvider.aspx bypasses the IsValidRSession check (CVSS 6.9) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-54365 | Gladinet CentreStack < 17.3, unauthenticated deserialization in GSNamespace.dll reaches NetUserAdd, creating arbitrary local OS accounts (CVSS 8.7) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-54366 | Gladinet CentreStack < 17.4, XXE at the unauthenticated SharePoint StorageConfig endpoint exfiltrates files including Web.config (CVSS 8.7) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-54367 | Gladinet CentreStack < 17.2, unauthenticated authorization bypass via forged EntAcctId values reaches any account's settings (CVSS 8.8) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-54368 | Gladinet CentreStack < 17.4, authenticated SQL injection via the x-glad-filter header writes files through PostgreSQL large-object functions (CVSS 8.7) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-58059 | Bouncy Castle for Java (< 1.85), Quadratic-time escaping when stringifying X.500 distinguished names (CVSS 8.7) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-58060 | Bouncy Castle for Java (< 1.85), HSS public-key level count unbounded, enabling huge allocation on verify (CVSS 8.7) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-58061 | Bouncy Castle for Java (< 1.85), CCM-family modes write plaintext to caller buffer before tag check (CVSS 8.7) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-58062 | Bouncy Castle for Java (< 1.85), Stapled OCSP response accepted without binding to the checked certificate (CVSS 9.3) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-58063 | Bouncy Castle for Java (< 1.85), BCFKS keystore load honours unbounded KDF cost from untrusted file (CVSS 5.3) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-59638 | Bouncy Castle for Java (< 1.85), JSSE hostname verifier CN-fallback enabled by default despite documented opt-in (CVSS 9.3) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-59639 | Bouncy Castle for Java (< 1.85), CMS verifySignatures returns true for SignedData with zero signers (CVSS 8.7) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-59640 | Bouncy Castle for Java (< 1.85), OpenPGP CFB quick-check oracle active on symmetric/session-key paths (CVSS 8.7) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-59641 | Bouncy Castle for Java (< 1.85), S/MIME validator trusts signer-asserted signingTime for path validation (CVSS 8.7) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-59642 | Bouncy Castle for Java (< 1.85), CMS AuthenticatedData content not bound to MAC when authAttrs present (CVSS 8.7) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-59643 | Bouncy Castle for Java (< 1.85), OpenPGP inline-signature policy failures silently ignored (CVSS 8.7) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-59644 | Bouncy Castle for Java (< 1.85), MLS hash-ratchet honours arbitrary 32-bit generation counter from sender (CVSS 8.7) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-59645 | Bouncy Castle for Java (< 1.85), OER parser recurses without depth limit on self-referential IEEE 1609.2 schema (CVSS 8.7) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-59646 | Bouncy Castle for Java (< 1.85), DTLS handshake reassembler allocates buffer from unchecked 24-bit length (CVSS 8.7) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-59647 | Bouncy Castle for Java (< 1.85), CRMF/CMP password-MAC honours unbounded iteration count (CVSS 6.9) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-59648 | Bouncy Castle for Java (< 1.85), OpenPGP Argon2 S2K honours attacker-chosen memory and passes (CVSS 6.9) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-59649 | Bouncy Castle for Java (< 1.85), OpenPGP user-attribute subpacket length bounded only by JVM max memory (CVSS 8.7) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-59650 | Bouncy Castle for Java (< 1.85), MTI/A0 DH agreement exponentiates unvalidated peer value (CVSS 9.3) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-59651 | Bouncy Castle for Java (< 1.85), BKS keystore accepts legacy version with 16-bit integrity MAC key (CVSS 7.1) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-59652 | Bouncy Castle for Java (< 1.85), LDAP filter injection in legacy jdk1.4 LDAPStoreHelper (CVSS 6.9) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-8763 | Bouncy Castle for Java (< 1.85), Name Constraints bypass via trailing dot in rfc822Name and URI (CVSS 9.3) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2013-4786 | CVE-2013-4786, 24,650 internet-exposed BMCs hand a crackable password hash to any unauthenticated caller, and Lava found ransom notes on live management interfaces | 2026-07-30 | 2026-08-02 | 2026-07-30 |
| CVE-2025-15467 | OpenSSL CMS AuthEnvelopedData parsing stack buffer overflow (CVSS 9.8 per Siemens ProductCERT; OpenSSL rates it High), pre-auth, fires before AEAD tag verification; vendored in Siemens Desigo CC, where family V7 has no fix available, V8 is fixed by patch V8.0 QU2.0021 and V9 by 9.0.1; public command-execution PoC | 2026-07-29 | 2026-08-02 | 2026-07-29 |
| CVE-2025-68686 | FortiOS SSL-VPN symlink-persistence patch bypass (exploited, KEV) | 2026-07-28 | 2026-08-02 | 2026-07-28 |
| CVE-2026-0769 | Langflow eval_custom_component_code eval injection (CVSS 9.8, CWE-95), unauthenticated RCE, published by ZDI as a 0-day advisory with no fixed version documented anywhere and "restrict interaction with the product" as the only stated mitigation; VulnCheck reports observed exploitation for credential harvesting, cryptomining and lateral movement; NOT in CISA KEV (distinct from the KEV-listed CVE-2026-0770) | 2026-07-29 | 2026-08-02 | 2026-07-29 |
| CVE-2026-14446 | IBM WebSphere Application Server traditional, missing authentication for critical function in the administrative console (CWE-306), CVSS 9.8; interim fix APAR DT496500, Fix Pack targeted 3Q2026 | 2026-08-01 | 2026-08-02 | 2026-08-01 |
| CVE-2026-14512 | IBM WebSphere Application Server traditional, pre-authentication unsafe deserialization (CWE-502), CVSS 9.8; interim fix APAR PH72166, Fix Pack targeted 3Q2026 | 2026-08-01 | 2026-08-02 | 2026-08-01 |
| CVE-2026-16232 | Check Point SmartConsole authentication bypass to full admin (exploited) | 2026-07-23 | 2026-08-02 | 2026-07-23 |
| CVE-2026-16723 | Alibaba fastjson 1.2.68–1.2.83, remote code execution under stock defaults in Spring Boot fat-JAR deployments; no patched 1.x release, exploited in the wild | 2026-07-27 | 2026-08-02 | 2026-07-27 |
| CVE-2026-16812 | Arista VeloCloud Orchestrator on-prem unauthenticated OS command injection (exploited, KEV) | 2026-07-28 | 2026-08-02 | 2026-07-28 |
| CVE-2026-28323 | SolarWinds Web Help Desk, unauthenticated SAML 2.0 authentication bypass, CVSS 9.8; fixed in 2026.2.1 | 2026-08-01 | 2026-08-02 | 2026-08-01 |
| CVE-2026-3055 | Citrix NetScaler ADC/Gateway out-of-bounds memory read when configured as a SAML Identity Provider (CWE-125, CVSS 9.8), CISA KEV-listed and exploited by multiple unrelated clusters, including manual exfiltration of appliance memory searched for session cookies (Unit 42, 2026-07-30); fixed in 13.1-62.24 / 14.1-66.60 / 13.1-FIPS-NDcPP 13.1-37.263 | 2026-07-01 | 2026-08-02 | 2026-07-31 |
| CVE-2026-39987 | marimo notebook, pre-auth RCE via the unauthenticated /terminal/ws endpoint (CWE-306), CVSS 4.0 9.3, fixed in 0.23.0, CISA KEV-listed; Unit 42 records command execution confirmed on 11 endpoints during the 2026-07 autonomous-agent campaign | 2026-05-30 | 2026-08-02 | 2026-07-31 |
| CVE-2026-42897 | Microsoft Exchange Server Outlook Web Access stored XSS (CWE-79, CVSS 3.1 8.1, Microsoft CNA), exploited in the wild by TA488/LAUNDRY BEAR to deliver the OWAReaper browser implant; CISA KEV 2026-05-15; permanent fix is the July 2026 Exchange SU (SE RTM; 2019 CU14/CU15 and 2016 CU23 via ESU Period 2), which does not remove earlier mitigations | 2026-05-16 | 2026-08-02 | 2026-05-18 +2 more |
| CVE-2026-44090 | Phoenix Contact CHARX SEC-3xxx, MQTT broker reachable without authentication, protected from external access only by the device firewall (CWE-306); CVSS 3.1 9.8 | 2026-08-02 | 2026-08-02 | 2026-08-02 |
| CVE-2026-44101 | Phoenix Contact CHARX SEC-3xxx, missing authentication on the CHARX OCPP Agent lets a remote attacker reconfigure the backend connection (CWE-306); CVSS 3.1 9.8 | 2026-08-02 | 2026-08-02 | 2026-08-02 |
| CVE-2026-44104 | Phoenix Contact CHARX SEC-3xxx, basemodule firmware update validates only a CRC32 checksum with no cryptographic signature verification (CWE-347), allowing unauthenticated installation of modified firmware; CVSS 3.1 9.8 | 2026-08-02 | 2026-08-02 | 2026-08-02 |
| CVE-2026-44108 | Phoenix Contact CHARX SEC-3xxx, firewall terminates prematurely during shutdown because of script execution order (CWE-696), exposing internal services in the window; CVSS 3.1 9.8 | 2026-08-02 | 2026-08-02 | 2026-08-02 |
| CVE-2026-48448 | Adobe Campaign Classic, unauthenticated SQL injection giving arbitrary file-system read; CVSS 3.1 8.6, fixed in ACC v7 7.4.3 build 9398 (APSB26-114) | 2026-08-02 | 2026-08-02 | 2026-08-02 |
| CVE-2026-48449 | Adobe Campaign Classic, Incorrect Authorization (CWE-863) giving unauthenticated arbitrary code execution; CVSS 3.1 10.0, on-premise and hybrid on-premise components only, fixed in ACC v7 7.4.3 build 9398 (APSB26-114) | 2026-08-02 | 2026-08-02 | 2026-08-02 |
| CVE-2026-59243 | Apache Airflow FAB provider, Azure AD OAuth login decoded ID tokens with verify_signature defaulted to False, allowing login as any user incl. Admin; no CVSS published by any party; fixed in apache-airflow-providers-fab 3.7.3 | 2026-07-29 | 2026-08-02 | 2026-07-29 |
| CVE-2026-59726 | CVE-2026-59726 (RufRoot), Ruflo's MCP bridge took unauthenticated tool calls on all interfaces, and the memory it poisons is not cleaned up by the patch (CVSS 10.0) | 2026-07-30 | 2026-08-02 | 2026-07-30 |
| CVE-2026-61511 | vBulletin {vb:math} runMaths eval injection, unauthenticated RCE (public exploit) | 2026-07-28 | 2026-08-02 | 2026-07-28 |
| CVE-2026-65766 | JoomShaper SP Page Builder for Joomla, pre-authentication SQL injection in the Dynamic Content endpoint's ORDER BY clause, guarded only by a CSRF token Joomla issues to anonymous visitors; Joomla CNA CVSS 4.0 9.2 (discloser self-scored 8.7), fixed in 6.7.1 | 2026-08-02 | 2026-08-02 | 2026-08-02 |
| CVE-2026-65876 | JoomShaper SP Page Builder for Joomla, unauthenticated SQL injection through the catid parameter of the loadMoreArticles endpoint; Joomla CNA CVSS 4.0 9.2, fixed in 6.7.1. Not among the four flaws mySites.guru reported and not tested by it | 2026-08-02 | 2026-08-02 | 2026-08-02 |
| CVE-2026-65877 | JoomShaper SP Page Builder for Joomla, authenticated SQL injection in the media manager's search and date filters, reachable by a low-privilege author; Joomla CNA CVSS 4.0 8.2, fixed in 6.7.1 | 2026-08-02 | 2026-08-02 | 2026-08-02 |
| CVE-2026-65878 | JoomShaper SP Page Builder for Joomla, authenticated arbitrary file delete via an unguarded request-supplied path in the media-delete action; Joomla CNA CVSS 4.0 8.3, fixed in 6.7.1 | 2026-08-02 | 2026-08-02 | 2026-08-02 |
| CVE-2026-65879 | JoomShaper SP Page Builder for Joomla, unauthenticated mail relay via a shared secret hardcoded identically into every shipped copy (CWE-798); the Joomla CNA assigned no metrics, so the 9.8 is a CISA-ADP CVSS 3.1 score and is not on the CVSS 4.0 scale its siblings use. Fixed in 6.7.1 | 2026-08-02 | 2026-08-02 | 2026-08-02 |
| CVE-2026-65883 | Aimy Captcha-Less Form Guard (Joomla plugin), unauthenticated PHP object injection to RCE, CVSS 9.8; fixed in 20.1 | 2026-08-01 | 2026-08-02 | 2026-08-01 |
| CVE-2026-65884 | Balbooa Gridbox for Joomla; registration handler adds caller-supplied usergroup IDs, letting an unauthenticated visitor register an account directly into an administrator group; CVSS 4.0 10.0 (CWE-284, Joomla CNA), exploit maturity Attacked; affected 1.0.0-2.20.1, fixed 2.20.2 | 2026-07-26 | 2026-08-02 | 2026-07-26 |
| CVE-2026-65885 | Balbooa Gridbox for Joomla, authenticated arbitrary file upload; becomes unauthenticated RCE chained with CVE-2026-65884 because the attacker can create the required account; CVSS 4.0 9.4 (CWE-434, Joomla CNA), exploit maturity Attacked; affected 1.0.0-2.20.1, fixed 2.20.2 | 2026-07-26 | 2026-08-02 | 2026-07-26 |
| CVE-2026-7849 | Phoenix Contact CHARX SEC-3xxx EV charging controllers, unauthenticated command injection into the system configuration executed as root (CWE-77); CVSS 3.1 9.8, firmware below 1.9.1, fix unreleased at disclosure (CERT@VDE VDE-2026-008) | 2026-08-02 | 2026-08-02 | 2026-08-02 |
| CVE-2026-14528 | IBM WebSphere Application Server traditional, sensitive information written to log files (CWE-532), CVSS 7.4 | 2026-08-01 | 2026-08-01 | 2026-08-01 |
| CVE-2026-28299 | SolarWinds Web Help Desk, denial of service, server crash due to insufficient memory; 8.2 High per the vendor's 2026.2.1 release-notes CVE table; fixed in 2026.2.1 | 2026-08-01 | 2026-08-01 | 2026-08-01 |
| CVE-2026-14869 | HCSEC-2026-23, HashiCorp Terraform MCP Server leaks its own bearer token to an attacker-supplied address, and its credential cache crosses sessions and tenants (CVE-2026-14869, CVE-2026-16496, CVE-2026-16498) | 2026-07-30 | 2026-07-30 | 2026-07-30 |
| CVE-2026-16496 | HCSEC-2026-23, HashiCorp Terraform MCP Server leaks its own bearer token to an attacker-supplied address, and its credential cache crosses sessions and tenants (CVE-2026-14869, CVE-2026-16496, CVE-2026-16498) | 2026-07-30 | 2026-07-30 | 2026-07-30 |
| CVE-2026-16498 | HCSEC-2026-23, HashiCorp Terraform MCP Server leaks its own bearer token to an attacker-supplied address, and its credential cache crosses sessions and tenants (CVE-2026-14869, CVE-2026-16496, CVE-2026-16498) | 2026-07-30 | 2026-07-30 | 2026-07-30 |
| CVE-2026-41703 | VMSA-2026-0006, VMware vCenter: unauthenticated Directory Service auth bypass and Syslog traversal RCE (both CVSS 9.8), plus a VMXNET3 guest-to-host escape | 2026-07-30 | 2026-07-30 | 2026-07-30 |
| CVE-2026-41709 | VMSA-2026-0006, VMware vCenter: unauthenticated Directory Service auth bypass and Syslog traversal RCE (both CVSS 9.8), plus a VMXNET3 guest-to-host escape | 2026-07-30 | 2026-07-30 | 2026-07-30 |
| CVE-2026-47876 | VMSA-2026-0006, VMware vCenter: unauthenticated Directory Service auth bypass and Syslog traversal RCE (both CVSS 9.8), plus a VMXNET3 guest-to-host escape | 2026-07-30 | 2026-07-30 | 2026-07-30 |
| CVE-2026-59309 | VMSA-2026-0006, VMware vCenter: unauthenticated Directory Service auth bypass and Syslog traversal RCE (both CVSS 9.8), plus a VMXNET3 guest-to-host escape | 2026-07-30 | 2026-07-30 | 2026-07-30 |
| CVE-2026-7891 | Siemens Mendix Runtime (all versions, CVSS 9.1), platform-enforced access rules on the System.User entity cannot be overridden by access rules on a specialization, so the anonymous role commonly reaches all stored user records; no code fix, mitigation is App Security role-management reconfiguration | 2026-07-29 | 2026-07-29 | 2026-07-29 |
| CVE-2025-33053 | Windows shortcut working-directory resolution flaw abused for remote WebDAV execution | 2026-07-26 | 2026-07-26 | 2026-07-26 |
| CVE-2026-0770 | CVE-2026-0770, Langflow: unauthenticated exec_globals RCE (actively exploited, CISA KEV 2026-07-21) | 2026-07-22 | 2026-07-26 | 2026-07-22 |
| CVE-2026-14499 | IBM Langflow OSS Python Interpreter authenticated command injection (CVSS 8.8), fixed in 1.10.2, not 1.10.1 | 2026-07-22 | 2026-07-26 | 2026-07-22 |
| CVE-2026-47056 | Oracle Data Integrator REST Service, unauthenticated takeover (CVSS 10.0, July 2026 CPU) | 2026-07-26 | 2026-07-26 | 2026-07-26 |
| CVE-2026-60217 | Oracle Coherence Core, unauthenticated takeover over TCP (CVSS 10.0, July 2026 CPU) | 2026-07-26 | 2026-07-26 | 2026-07-26 |
| CVE-2026-60365 | Oracle Fusion Middleware CVSS 10.0 unauthenticated flaw, listed twice in Oracle's July 2026 risk matrix (Oracle HTTP Server and WebLogic Server Proxy Plug-in), which is why the ten-row / nine-CVE counts diverge | 2026-07-26 | 2026-07-26 | · |
| CVE-2026-61211 | Oracle Database Server, DBMS_CLOUD privilege abuse to full server control (CVSS 9.9) | 2026-07-26 | 2026-07-26 | 2026-07-26 |
| CVE-2026-61425 | Balbooa Gridbox for Joomla, unauthenticated cookie-forgery authentication bypass to Super User | 2026-07-26 | 2026-07-26 | 2026-07-26 |
| CVE-2026-62415 | Membership Pro for Joomla, unauthenticated file upload (CVSS 9.1, Joomla CNA); fixed in 4.6.2 | 2026-07-26 | 2026-07-26 | 2026-07-26 |
| CVE-2026-63047 | Events Booking for Joomla, unauthenticated invoice IDOR exposing personal and financial data | 2026-07-26 | 2026-07-26 | 2026-07-26 |
| CVE-2026-65759 | JoomShaper EasyStore for Joomla, unauthenticated order/payment forgery on the repayment endpoint (CVSS 4.0 8.7, Joomla CNA) | 2026-07-26 | 2026-07-26 | 2026-07-26 |
| CVE-2026-65760 | JoomShaper EasyStore for Joomla, cross-customer order/invoice IDOR reachable by any logged-in customer (CVSS 4.0 9.2, Joomla CNA) | 2026-07-26 | 2026-07-26 | 2026-07-26 |
| CVE-2026-65761 | JoomShaper EasyStore for Joomla, unauthenticated SQL injection, full site-database read (CVSS 4.0 9.3, Joomla CNA) | 2026-07-26 | 2026-07-26 | 2026-07-26 |
| CVE-2023-43770 | Roundcube webmail persistent XSS (n-day exploited by TA458/Operation RoundPress) | 2026-07-25 | 2026-07-25 | · |
| CVE-2025-27915 | Zimbra Collaboration half-click webmail flaw (TA458/Operation RoundPress) | 2026-07-25 | 2026-07-25 | · |
| CVE-2025-3929 | mDaemon webmail half-click flaw (TA458/Operation RoundPress) | 2026-07-25 | 2026-07-25 | · |
| CVE-2026-54121 | Certighost, Windows Server AD CS elevation of privilege (DC impersonation to DCSync) | 2026-07-25 | 2026-07-25 | 2026-07-25 |
| CVE-2026-62144 | Check Point Security Management / MDS unauthenticated command execution | 2026-07-23 | 2026-07-25 | 2026-07-23 |
| CVE-2026-62145 | Check Point Gaia Portal read-only to root command execution | 2026-07-23 | 2026-07-25 | 2026-07-23 |
| CVE-2026-8496 | SOGo webmail half-click XSS zero-day (Operation RoundPress / TA458) | 2026-07-25 | 2026-07-25 | 2026-07-25 |
| CVE-2025-66376 | Zimbra Collaboration Suite Classic Web Client stored XSS (view-based/zero-click) exploited by Russian actor LAUNDRY BEAR; CVSS 7.2 (MITRE)/6.1 (NVD); CISA KEV; patched ZCS 10.0.18/10.1.13 | 2026-07-24 | 2026-07-24 | 2026-07-24 |
| CVE-2026-16002 | MZ Automation lib60870 out-of-bounds read parser-crash DoS (IEC 60870-5-104); lib60870 <= 2.4.0 (CVSS 3.1 8.2 / 4.0 8.8) | 2026-07-24 | 2026-07-24 | 2026-07-24 |
| CVE-2026-49035 | MZ Automation libIEC61850 unauthenticated heap-overflow RCE via crafted MMS Initiate request (CVSS 3.1 8.1 / 4.0 9.2); libIEC61850 1.0.0-1.6.1 | 2026-07-24 | 2026-07-24 | 2026-07-24 |
| CVE-2026-50032 | MZ Automation libIEC61850 NULL-pointer dereference DoS in MMS Write Named Variable List handler (CVSS 3.1 7.5 / 4.0 8.7) | 2026-07-24 | 2026-07-24 | 2026-07-24 |
| CVE-2026-50039 | MZ Automation libIEC61850 stack-based buffer overflow via crafted ReadRequest (CVSS 3.1 7.5 / 4.0 8.7) | 2026-07-24 | 2026-07-24 | 2026-07-24 |
| CVE-2026-50103 | MZ Automation libIEC61850 NULL-pointer dereference DoS in L2 GOOSE/R-GOOSE parser via malformed TLV (CVSS 3.1 6.5 / 4.0 7.1) | 2026-07-24 | 2026-07-24 | 2026-07-24 |
| CVE-2026-28302 | SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE) | 2026-07-23 | 2026-07-23 | 2026-07-23 |
| CVE-2026-28304 | SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE) | 2026-07-23 | 2026-07-23 | 2026-07-23 |
| CVE-2026-28305 | SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE) | 2026-07-23 | 2026-07-23 | 2026-07-23 |
| CVE-2026-28306 | SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE) | 2026-07-23 | 2026-07-23 | 2026-07-23 |
| CVE-2026-28307 | SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE) | 2026-07-23 | 2026-07-23 | 2026-07-23 |
| CVE-2026-28308 | SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE) | 2026-07-23 | 2026-07-23 | 2026-07-23 |
| CVE-2026-28309 | SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE) | 2026-07-23 | 2026-07-23 | 2026-07-23 |
| CVE-2026-28310 | SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE) | 2026-07-23 | 2026-07-23 | 2026-07-23 |
| CVE-2026-28311 | SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE) | 2026-07-23 | 2026-07-23 | 2026-07-23 |
| CVE-2026-28312 | SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE) | 2026-07-23 | 2026-07-23 | 2026-07-23 |
| CVE-2026-28313 | SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE) | 2026-07-23 | 2026-07-23 | 2026-07-23 |
| CVE-2026-28314 | SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE) | 2026-07-23 | 2026-07-23 | 2026-07-23 |
| CVE-2026-28315 | SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE) | 2026-07-23 | 2026-07-23 | 2026-07-23 |
| CVE-2026-28316 | SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE) | 2026-07-23 | 2026-07-23 | 2026-07-23 |
| CVE-2026-28317 | SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE) | 2026-07-23 | 2026-07-23 | 2026-07-23 |
| CVE-2026-28321 | SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE) | 2026-07-23 | 2026-07-23 | 2026-07-23 |
| CVE-2026-47678 | GLPI 11.0.8/10.0.26 security release (critical RCE via form import; MFA bypass) | 2026-07-23 | 2026-07-23 | 2026-07-23 |
| CVE-2026-47679 | GLPI 11.0.8/10.0.26 security release (critical RCE via form import; MFA bypass) | 2026-07-23 | 2026-07-23 | 2026-07-23 |
| CVE-2026-48482 | GLPI 11.0.8/10.0.26 security release (critical RCE via form import; MFA bypass) | 2026-07-23 | 2026-07-23 | 2026-07-23 |
| CVE-2026-49470 | GLPI 11.0.8/10.0.26 security release (critical RCE via form import; MFA bypass) | 2026-07-23 | 2026-07-23 | 2026-07-23 |
| CVE-2026-52848 | GLPI 11.0.8/10.0.26 security release (critical RCE via form import; MFA bypass) | 2026-07-23 | 2026-07-23 | 2026-07-23 |
| CVE-2026-53610 | GLPI 11.0.8/10.0.26 security release (critical RCE via form import; MFA bypass) | 2026-07-23 | 2026-07-23 | 2026-07-23 |
| CVE-2026-53625 | GLPI 11.0.8/10.0.26 security release (critical RCE via form import; MFA bypass) | 2026-07-23 | 2026-07-23 | 2026-07-23 |
| CVE-2026-53626 | GLPI 11.0.8/10.0.26 security release (critical RCE via form import; MFA bypass) | 2026-07-23 | 2026-07-23 | 2026-07-23 |
| CVE-2026-53629 | GLPI 11.0.8/10.0.26 security release (critical RCE via form import; MFA bypass) | 2026-07-23 | 2026-07-23 | 2026-07-23 |
| CVE-2026-55214 | GLPI 11.0.8/10.0.26 security release (critical RCE via form import; MFA bypass) | 2026-07-23 | 2026-07-23 | 2026-07-23 |
| CVE-2026-10631 | CVE-2026-10631, Zimbra: EWS extension access-control issue (fixed 10.1.20; RESERVED on NVD) | 2026-07-22 | 2026-07-22 | 2026-07-22 |
| CVE-2026-50054 | CVE-2026-50054, Zimbra: mailbox delegation authorization flaw (fixed 10.1.20; RESERVED on NVD) | 2026-07-22 | 2026-07-22 | 2026-07-22 |
| CVE-2026-50055 | CVE-2026-50055, Zimbra: mail-forwarding restriction bypass (fixed 10.1.20; RESERVED on NVD) | 2026-07-22 | 2026-07-22 | 2026-07-22 |
| CVE-2026-50522 | CVE-2026-50522, Microsoft SharePoint Server: Site-Owner deserialization RCE (CVSS 9.8) | 2026-07-14 | 2026-07-22 | 2026-07-14 |
| CVE-2026-7754 | CVE-2026-7754, Langflow OSS: SSRF from insecure default configuration (fixed 1.10.1) | 2026-07-22 | 2026-07-22 | · |
| CVE-2026-7755 | CVE-2026-7755, Langflow OSS: RCE via insufficient validation of MCP server config files (fixed 1.10.1) | 2026-07-22 | 2026-07-22 | · |
| CVE-2026-8476 | CVE-2026-8476, Langflow OSS: unsafe deserialization in AsyncDiskCache via apply_tweaks() (fixed 1.10.1) | 2026-07-22 | 2026-07-22 | · |
| CVE-2026-8859 | CVE-2026-8859, Langflow OSS: path-traversal arbitrary file write (fixed 1.10.1) | 2026-07-22 | 2026-07-22 | 2026-07-22 |
| CVE-2026-9135 | CVE-2026-9135, Langflow OSS: code injection in Policies/ToolGuard component (fixed 1.10.1) | 2026-07-22 | 2026-07-22 | 2026-07-22 |
| CVE-2026-9202 | CVE-2026-9202, Langflow OSS: unauthenticated account creation reaching RCE (fixed 1.10.1) | 2026-07-22 | 2026-07-22 | 2026-07-22 |
| CVE-2026-2291 | dnsmasq really_insert() DNS-cache heap buffer overflow (RCE per Exodus; NVD frames as DoS/cache-poisoning) | 2026-07-21 | 2026-07-21 | 2026-07-21 |
| CVE-2026-6875 | ServiceNow AI Platform sandbox escape, unauthenticated code execution within the platform (CVSS 9.5); hosted fixed server-side, self-hosted/partner patch listed family releases | 2026-07-13 | 2026-07-21 | 2026-07-13 |
| CVE-2026-42533 | nginx / NGINX Plus PCRE capture-clobber pre-auth heap overflow (CVSS 9.2); F5 out-of-band patch 2026-07-15/16, credited researcher demonstrates RCE beyond F5's DoS-only framing (no public PoC, no ITW as of 2026-07-20); fixed nginx 1.30.4/1.31.3, NGINX Plus R36 P7/37.0.3.1 | 2026-07-20 | 2026-07-20 | 2026-07-20 |
| CVE-2025-40947 | Siemens RUGGEDCOM ROX II feature-key gpgv command injection to root (CVSS 7.5); Unit 42 chain | 2026-07-18 | 2026-07-18 | 2026-07-18 |
| CVE-2025-40948 | Siemens RUGGEDCOM ROX II arbitrary file disclosure via root-privileged xz misuse (CVSS 6.8); Unit 42 chain | 2026-07-18 | 2026-07-18 | 2026-07-18 |
| CVE-2025-40949 | Siemens RUGGEDCOM ROX II task-scheduler command injection, persistent root (CVSS 9.1); Siemens SSA-081142 | 2026-07-18 | 2026-07-18 | 2026-07-18 |
| CVE-2026-47865 | VMware Avi Load Balancer control-plane unauthenticated authentication bypass (CVSS 9.8), VMSA-2026-0005 | 2026-07-18 | 2026-07-18 | 2026-07-18 |
| CVE-2026-47866 | VMware Avi Load Balancer authorization bypass (CVSS 8.3), VMSA-2026-0005 | 2026-07-18 | 2026-07-18 | 2026-07-18 |
| CVE-2026-47867 | VMware Avi Load Balancer high-privilege RCE (CVSS 8.7), VMSA-2026-0005 | 2026-07-18 | 2026-07-18 | 2026-07-18 |
| CVE-2026-47868 | VMware Avi Load Balancer local privilege escalation to root (CVSS 7.8), VMSA-2026-0005 | 2026-07-18 | 2026-07-18 | 2026-07-18 |
| CVE-2026-47869 | VMware Avi Load Balancer authenticated RCE (CVSS 8.7), VMSA-2026-0005 | 2026-07-18 | 2026-07-18 | 2026-07-18 |
| CVE-2026-47870 | VMware Avi Load Balancer privilege escalation (CVSS 7.1), VMSA-2026-0005 | 2026-07-18 | 2026-07-18 | 2026-07-18 |
| CVE-2026-47871 | VMware Avi Load Balancer authenticated directory traversal (CVSS 8.8), VMSA-2026-0005 | 2026-07-18 | 2026-07-18 | 2026-07-18 |
| CVE-2026-54733 | Moodle local_o365 plugin JWT-signature-not-verified SSO auth bypass | 2026-07-18 | 2026-07-18 | 2026-07-18 |
| CVE-2026-15718 | Mozilla Firefox WebAssembly engine invalid-pointer memory-safety flaw (public exploit code, no confirmed ITW); fixed 152.0.6 | 2026-07-17 | 2026-07-17 | 2026-07-17 |
| CVE-2026-15719 | Mozilla Firefox DOM Navigation site-isolation bypass (public exploit code, no confirmed ITW); fixed 152.0.6 | 2026-07-17 | 2026-07-17 | 2026-07-17 |
| CVE-2026-32201 | Microsoft SharePoint Server on-prem RCE, part of the actively-exploited SharePoint cluster (CISA KEV 2026-04-14), referenced as context in the CVE-2026-58644 exploitation update | 2026-07-17 | 2026-07-17 | · |
| CVE-2026-58644 | CVE-2026-58644, Microsoft SharePoint Server deserialization RCE (CVSS 9.8); confirmed exploited + CISA KEV 2026-07-16 | 2026-07-14 | 2026-07-17 | 2026-07-14 |
| CVE-2023-4346 | KNX Connection Authorization Option 1 overly-restrictive account-lockout DoS (CVSS 7.5, CWE-645); CISA KEV 2026-07-15, no software patch (procedural mitigation) | 2026-07-16 | 2026-07-16 | 2026-07-16 |
| CVE-2026-46817 | Oracle E-Business Suite / Oracle Payments File Transmission unauthenticated RCE/takeover (CVSS 9.8); CISA KEV 2026-07-15, exploited ITW since 2026-06-27; fixed Oracle May 2026 CPU (12.2.3-12.2.15) | 2026-06-01 | 2026-07-16 | 2026-07-16 +1 more |
| CVE-2025-13162 | CVE-2025-13162, ABB 800xA for Advant Master / Control Builder A: DLL search-path element (CVSS 4.4) | 2026-07-15 | 2026-07-15 | · |
| CVE-2025-14771 | CVE-2025-14771, ABB T-MAC Plus: authenticated file disclosure (CVSS 9.9) | 2026-07-15 | 2026-07-15 | 2026-07-15 |
| CVE-2025-14772 | CVE-2025-14772, ABB T-MAC Plus: broken access control / authz bypass (CVSS 8.8) | 2026-07-15 | 2026-07-15 | 2026-07-15 |
| CVE-2025-14773 | CVE-2025-14773, ABB T-MAC Plus: stored XSS (CVSS 8.0) | 2026-07-15 | 2026-07-15 | 2026-07-15 |
| CVE-2025-14774 | CVE-2025-14774, ABB T-MAC Plus: Card Reader service DoS (CVSS 7.4) | 2026-07-15 | 2026-07-15 | 2026-07-15 |
| CVE-2026-10577 | CVE-2026-10577, Rockwell 1715-AENTR EtherNet/IP Adapter: unauthenticated debug-port takeover (CVSS 10.0) | 2026-07-15 | 2026-07-15 | 2026-07-15 |
| CVE-2026-55944 | CVE-2026-55944, Microsoft Dynamics NAV / Dynamics 365 Business Central (On-Prem): pre-auth deserialization RCE (CVSS 9.8) | 2026-07-14 | 2026-07-15 | 2026-07-14 |
| CVE-2015-5281 | GRUB 2 Secure Boot bypass (historical), cited by ESET/CERT/CC as an old bug reopened by pre-15.3 UEFI shims lacking SBAT (context in CVE-2026-8863/10797 entry) | 2026-07-14 | 2026-07-14 | · |
| CVE-2026-10797 | Forgotten pre-0.9 UEFI shim signature-length validation mismatch (revocation-check vs signature-verification size divergence), Secure Boot bypass; revoked via Microsoft dbx 2026-06-09 (ESET Research) | 2026-07-14 | 2026-07-14 | 2026-07-14 |
| CVE-2026-27690 | SAP Approuter unauthenticated HTTP request smuggling (CVSS 9.1) | 2026-07-14 | 2026-07-14 | 2026-07-14 |
| CVE-2026-44747 | SAP NetWeaver AS ABAP kernel memory corruption (CVSS 9.9) | 2026-07-14 | 2026-07-14 | 2026-07-14 |
| CVE-2026-44761 | SAP Commerce Cloud hardcoded sample OAuth2 credential (CVSS 9.1) | 2026-07-14 | 2026-07-14 | 2026-07-14 |
| CVE-2026-56155 | Microsoft AD FS local elevation of privilege (exploited zero-day) | 2026-07-14 | 2026-07-14 | 2026-07-14 |
| CVE-2026-56164 | Microsoft SharePoint Server unauthenticated elevation of privilege (exploited zero-day) | 2026-07-14 | 2026-07-14 | 2026-07-14 |
| CVE-2026-8863 | Forgotten pre-0.9 UEFI shim trust-validation weakness (Secure Boot bypass on machines trusting the Microsoft third-party UEFI CA); revoked via Microsoft dbx 2026-06-09 (ESET Research) | 2026-07-14 | 2026-07-14 | 2026-07-14 |
| CVE-2008-4128 | Cisco IOS (end-of-life devices), named by the 2026-07-13 FSB Centre 16 joint advisory as an exploited legacy CVE; no patch (EOL) | 2026-07-13 | 2026-07-13 | · |
| CVE-2018-0171 | Cisco IOS/IOS XE Smart Install pre-auth RCE, actively exploited by FSB Centre 16 / Static Tundra | 2026-07-13 | 2026-07-13 | 2026-07-13 |
| CVE-2026-4769 | WAGO I/O System Field, undocumented early-boot diagnostic interface, unauthenticated full compromise (CWE-912) | 2026-07-13 | 2026-07-13 | 2026-07-13 |
| CVE-2026-61500 | Rejetto HFS < 3.2.1 predictable session-signing PRNG (Math.random) enables pre-auth admin session forgery to RCE via server_code (CVSS 9.3); fixed 3.2.1 | 2026-07-13 | 2026-07-13 | 2026-07-13 |
| CVE-2026-61501 | Rejetto HFS 3.0.0–3.2.0 stored XSS in admin log via crafted failed-login username; fixed 3.2.1 | 2026-07-13 | 2026-07-13 | 2026-07-13 |
| CVE-2026-61502 | Rejetto HFS 3.0.0–3.2.0 state-changing admin actions accepted over GET with no anti-CSRF check; fixed 3.2.1 | 2026-07-13 | 2026-07-13 | 2026-07-13 |
| CVE-2026-61503 | Rejetto HFS 3.0.0–3.2.0 unauthenticated username enumeration (incl. default admin) via login-endpoint response differences; fixed 3.2.1 | 2026-07-13 | 2026-07-13 | 2026-07-13 |
| CVE-2026-61504 | Rejetto HFS 3.0.0–3.2.0 stored XSS via unescaped filenames in fallback 'basic' listing; fixed 3.2.1 | 2026-07-13 | 2026-07-13 | 2026-07-13 |
| CVE-2026-61505 | Rejetto HFS 3.0.0–3.2.0 path traversal via lang query parameter (limited JSON file read); fixed 3.2.1 | 2026-07-13 | 2026-07-13 | 2026-07-13 |
| CVE-2026-10698 | Progress MOVEit Transfer Custom Reports table-scope bypass, admin-privileged (CVSS 7.2; CERT-FR AVI-0856) | 2026-07-11 | 2026-07-11 | 2026-07-11 |
| CVE-2026-10699 | Progress MOVEit Transfer SFTP-service memory-leak pre-auth denial of service (CVSS 7.5; CERT-FR AVI-0856) | 2026-07-11 | 2026-07-11 | 2026-07-11 |
| CVE-2026-11903 | Progress MOVEit Transfer Ad Hoc module stored XSS, low-priv authenticated (CVSS 8.0; CERT-FR AVI-0856) | 2026-07-11 | 2026-07-11 | 2026-07-11 |
| CVE-2026-47291 | Windows HTTP.sys pre-auth kernel RCE (CVSS 9.8); ZDI published full exploitation mechanics + detection signature 2026-07-10 | 2026-06-10 | 2026-07-11 | 2026-06-10 |
| CVE-2026-57827 | Joomla RSFiles! (com_rsfiles) unauthenticated file-upload RCE (CVSS 4.0 10.0); part of the mySites.guru Joomla-extension CWE-434 wave | 2026-07-11 | 2026-07-11 | 2026-07-11 |
| CVE-2026-57828 | Joomla Phoca Download (com_phocadownload) authenticated file-upload RCE via member-upload allow-list bypass (CVSS 4.0 9.0) | 2026-07-11 | 2026-07-11 | 2026-07-11 |
| CVE-2026-60090 | PraisonAI PGVector/Cassandra knowledge store, SQL/CQL injection via unvalidated vector dimension (CVSS 9.3) | 2026-07-11 | 2026-07-11 | 2026-07-11 |
| CVE-2026-61445 | PraisonAI AICoder, arbitrary file write / command execution via LLM tool calls (CVSS 9.4) | 2026-07-11 | 2026-07-11 | 2026-07-11 |
| CVE-2026-61447 | PraisonAI CodeAgent, unsandboxed LLM-generated Python execution with full env-secret leak (CVSS 10.0) | 2026-07-11 | 2026-07-11 | 2026-07-11 |
| CVE-2021-29441 | Apache Nacos authentication bypass (Nacos-Server User-Agent header) abused by WP-SHELLSTORM for Java-stack credential theft | 2026-07-10 | 2026-07-10 | · |
| CVE-2025-5777 | CitrixBleed 2 (NetScaler ADC/Gateway pre-auth memory over-read), weaponised in the STAC3725 IAB-to-DragonForce kill chain (Huntress) | 2026-07-01 | 2026-07-10 | 2026-07-10 |
| CVE-2025-63681 | Open WebUI /api/tasks/stop/ IDOR, unauthorized task cancellation (unpatched) | 2026-07-10 | 2026-07-10 | 2026-07-10 |
| CVE-2025-64496 | Open WebUI Direct Connections XSS chained to unsandboxed Python exec() → RCE | 2026-07-10 | 2026-07-10 | 2026-07-10 |
| CVE-2026-1969 | WordPress ThemeREX Addons plugin vulnerability weaponized by the WP-SHELLSTORM crew | 2026-07-10 | 2026-07-10 | · |
| CVE-2026-20896 | Gitea Docker reverse-proxy trust-all auth bypass (X-WEBAUTH-USER impersonation), NCSC-CH escalated status to actively-exploited 2026-07-10 | 2026-06-23 | 2026-07-10 | 2026-06-23 |
| CVE-2026-3844 | WordPress Breeze Cache Cleaner plugin flaw, highest-yield exploit in the WP-SHELLSTORM webshell-brokerage campaign | 2026-07-10 | 2026-07-10 | · |
| CVE-2026-44556 | Open WebUI /api/openai/responses proxy reaches any model without per-model authz | 2026-07-10 | 2026-07-10 | 2026-07-10 |
| CVE-2026-44557 | Open WebUI incomplete collection allowlist exposes knowledge-base metadata to any user | 2026-07-10 | 2026-07-10 | 2026-07-10 |
| CVE-2026-44564 | Open WebUI Socket.IO ydoc:document:update checks room membership not write permission | 2026-07-10 | 2026-07-10 | 2026-07-10 |
| CVE-2026-48939 | iCagenda for Joomla, unauthenticated file-upload-to-RCE, exploited zero-day, CISA KEV | 2026-07-10 | 2026-07-10 | 2026-07-10 |
| CVE-2026-54015 | Open WebUI prompt version-history IDOR (caller-supplied history-ID unauthorized) | 2026-07-10 | 2026-07-10 | 2026-07-10 |
| CVE-2026-54798 | Siemens SICAM 8 HTTP-reachable debug interface → authenticated DoS | 2026-07-10 | 2026-07-10 | 2026-07-10 |
| CVE-2026-54799 | Siemens SICAM 8 firmware-update signature-validation bypass → persistent malicious firmware | 2026-07-10 | 2026-07-10 | 2026-07-10 |
| CVE-2026-54800 | Siemens SICAM 8 ships with OPC UA security disabled by default | 2026-07-10 | 2026-07-10 | 2026-07-10 |
| CVE-2026-54801 | Siemens SICAM 8 web-API admin-account credential-validation bypass → privilege escalation | 2026-07-10 | 2026-07-10 | 2026-07-10 |
| CVE-2024-42009 | Roundcube XSS, exploited by FrostyNeighbor / Ghostwriter (UNC1151) for Polish-targeting credential harvesting | 2026-05-17 | 2026-07-09 | 2026-07-09 |
| CVE-2026-12486 | GeoVision GV-I/O Box 4E unauthenticated OS command injection (Talos, CVSS 9.1) | 2026-07-09 | 2026-07-09 | 2026-07-09 |
| CVE-2026-12958 | AWS Language Servers / Amazon Q Developer symlink trust-boundary write outside workspace (GhostApproval, CWE-61); fixed language-servers 1.69.0 / @aws/lsp-codewhisperer 0.0.117 | 2026-07-09 | 2026-07-09 | 2026-07-09 |
| CVE-2026-13125 | GeoVision GeoWebPlayer unauthenticated localhost WebSocket screen-capture (Talos, CVSS 8.8) | 2026-07-09 | 2026-07-09 | 2026-07-09 |
| CVE-2026-14480 | OpenPLC v3 Runtime authenticated arbitrary file-write to native RCE (CVSS 9.9; CISA ICSA-26-190-01, no fix) | 2026-07-09 | 2026-07-09 | 2026-07-09 |
| CVE-2026-22879 | VTK-DICOM heap overflow on crafted DICOM file (Talos, CVSS 8.1) | 2026-07-09 | 2026-07-09 | 2026-07-09 |
| CVE-2026-48614 | Plesk XML API code injection (CWE-94), authenticated low-priv to arbitrary root file write / LPE (CVSS 9.9); CCB Belgium; affected <18.0.30, fixed 18.0.30-18.0.78.4 (18.0.79+ unaffected) | 2026-07-09 | 2026-07-09 | 2026-07-09 |
| CVE-2026-50549 | Cursor IDE sandbox escape via symlink + failed path canonicalization (GhostApproval); fixed Cursor 3.0 | 2026-07-09 | 2026-07-09 | 2026-07-09 |
| CVE-2026-5263 | wolfSSL registeredID SAN name-constraint bypass (Talos, CVSS 7.4) | 2026-07-09 | 2026-07-09 | 2026-07-09 |
| CVE-2026-56291 | Balbooa Forms for Joomla (com_baforms) unauthenticated file-upload RCE (CWE-434, CVSS 4.0 10.0), zero-day exploited pre-patch; 3rd Joomla-extension file-upload RCE in the 2026-06/07 wave | 2026-07-09 | 2026-07-09 | 2026-07-09 |
| CVE-2026-6678 | wolfSSL PKCS#7 OtherRecipientInfo integer underflow -> heap overflow (Talos, CVSS 7.5) | 2026-07-09 | 2026-07-09 | 2026-07-09 |
| CVE-2026-7532 | wolfSSL iPAddress SAN name-constraint bypass (Talos coordinated disclosure, CVSS 9.1) | 2026-07-09 | 2026-07-09 | 2026-07-09 |
| CVE-2020-22653 | Ruckus wireless router flaw exploited by UAT-7810 for ORB initial access (context; Cisco Talos) | 2026-07-08 | 2026-07-08 | · |
| CVE-2020-22658 | Ruckus wireless router flaw exploited by UAT-7810 for ORB initial access (context; Cisco Talos) | 2026-07-08 | 2026-07-08 | · |
| CVE-2023-25717 | Ruckus wireless router flaw exploited by UAT-7810 for ORB initial access (context; Cisco Talos) | 2026-07-08 | 2026-07-08 | · |
| CVE-2025-2492 | ASUS AiCloud router flaw exploited by UAT-7810 for ORB initial access (context; Cisco Talos) | 2026-07-08 | 2026-07-08 | · |
| CVE-2026-20744 | Hydro-Quebec EV-charging OCPP WebSocket unauthenticated access -> privilege escalation (CVSS 9.8), CISA ICSA-26-188-01 | 2026-07-08 | 2026-07-08 | 2026-07-08 |
| CVE-2026-33017 | Langflow unauthenticated RCE (build_public_tmp), CISA KEV, exploited in the Langflow IDOR chain | 2026-07-08 | 2026-07-08 | 2026-07-08 |
| CVE-2026-40138 | BeyondTrust RS/PRA pre-auth authentication bypass (CVSS4 9.2), NCSC-CH BT26-03 | 2026-07-08 | 2026-07-08 | 2026-07-08 |
| CVE-2026-40139 | BeyondTrust RS/PRA pre-auth authentication bypass (CVSS4 9.2), NCSC-CH BT26-03 | 2026-07-08 | 2026-07-08 | 2026-07-08 |
| CVE-2026-40140 | BeyondTrust RS/PRA unauthenticated DoS (network-communication subsystem), BT26-03 | 2026-07-08 | 2026-07-08 | 2026-07-08 |
| CVE-2026-40141 | BeyondTrust RS/PRA authenticated broken-access-control (resource access beyond scope), BT26-03 | 2026-07-08 | 2026-07-08 | 2026-07-08 |
| CVE-2026-42952 | Hydro-Quebec EV-charging: no auth-attempt throttling -> DoS (CVSS 7.5), ICSA-26-188-01 | 2026-07-08 | 2026-07-08 | 2026-07-08 |
| CVE-2026-43499 | GhostLock, Linux kernel rtmutex use-after-free LPE + container escape, public exploit | 2026-07-08 | 2026-07-08 | 2026-07-08 |
| CVE-2026-44383 | Hydro-Quebec EV-charging: duplicate concurrent sessions per charge-point ID -> DoS (CVSS 7.5), ICSA-26-188-01 | 2026-07-08 | 2026-07-08 | 2026-07-08 |
| CVE-2026-48282 | Adobe ColdFusion CWE-22 path-traversal RCE (CVSS 10.0), APSB26-68, actively exploited, CISA KEV 2026-07-07 | 2026-07-02 | 2026-07-08 | 2026-07-02 |
| CVE-2026-48908 | JoomShaper SP Page Builder unauth file-upload RCE (CVSS 10.0), CISA KEV zero-day | 2026-07-08 | 2026-07-08 | 2026-07-08 |
| CVE-2026-50746 | Ubiquiti UniFi Connect unauthenticated command-injection RCE (CVSS 10.0), SAB-066 | 2026-07-08 | 2026-07-08 | 2026-07-08 |
| CVE-2026-50747 | Ubiquiti UniFi Talk authenticated SQL injection (CVSS 9.9), SAB-066 | 2026-07-08 | 2026-07-08 | 2026-07-08 |
| CVE-2026-50748 | Ubiquiti UniFi Access command injection (CVSS 9.9), SAB-066 | 2026-07-08 | 2026-07-08 | 2026-07-08 |
| CVE-2026-54402 | Ubiquiti UniFi OS command injection (CVSS 9.9), SAB-066 | 2026-07-08 | 2026-07-08 | 2026-07-08 |
| CVE-2026-54403 | Ubiquiti UniFi OS path-traversal auth-bypass (CVSS 8.6), chainable, SAB-066 | 2026-07-08 | 2026-07-08 | 2026-07-08 |
| CVE-2026-55115 | Ubiquiti UniFi Protect SSRF privilege escalation (CVSS 9.9), SAB-066 | 2026-07-08 | 2026-07-08 | 2026-07-08 |
| CVE-2026-55255 | Langflow cross-tenant IDOR (CWE-639), actively exploited, CISA KEV, chained with RCE CVE-2026-33017 | 2026-07-08 | 2026-07-08 | 2026-07-08 |
| CVE-2026-56290 | Joomlack Page Builder CK unauth file-upload RCE (CVSS 10.0), CISA KEV zero-day | 2026-07-08 | 2026-07-08 | 2026-07-08 |
| CVE-2026-59509 | cve-search unauthenticated /fetch_cve_data parameter manipulation exposes admin credential hashes | 2026-07-05 | 2026-07-05 | 2026-07-05 |
| CVE-2025-3248 | Langflow /api/v1/validate/code missing-auth RCE, initial access for the JADEPUFFER agentic ransomware operation | 2026-07-04 | 2026-07-04 | 2026-07-04 |
| CVE-2026-13368 | WatchGuard Fireware OS iked pre-auth use-after-free RCE (IKEv2/LDAP path, CVSS 9.2) | 2026-07-03 | 2026-07-03 | 2026-07-03 |
| CVE-2026-20191 | Cisco Catalyst Center unauthenticated path-traversal arbitrary file read (CVSS 7.5; dropped from §2, awareness only) | 2026-07-03 | 2026-07-03 | · |
| CVE-2026-34038 | Coolify authenticated OS command injection to RCE + secrets exfil (CVSS 9.9) | 2026-07-03 | 2026-07-03 | 2026-07-03 |
| CVE-2026-57517 | Control Web Panel pre-auth blind SQLi to web-shell RCE via INTO DUMPFILE (CVSS 9.8) | 2026-07-03 | 2026-07-03 | 2026-07-03 |
| CVE-2026-14439 | Altium Enterprise Server / Altium 365 Git Service CWE-22 path-traversal to RCE (CVSS 9.4) | 2026-07-02 | 2026-07-02 | 2026-07-02 |
| CVE-2026-48276 | Adobe ColdFusion CWE-434 unrestricted file-upload RCE (CVSS 10.0), APSB26-68 | 2026-07-02 | 2026-07-02 | 2026-07-02 |
| CVE-2026-48277 | Adobe ColdFusion CWE-20 improper-input-validation RCE (CVSS 10.0), APSB26-68 | 2026-07-02 | 2026-07-02 | 2026-07-02 |
| CVE-2026-48281 | Adobe ColdFusion CWE-20 improper-input-validation RCE (CVSS 10.0), APSB26-68 | 2026-07-02 | 2026-07-02 | 2026-07-02 |
| CVE-2026-48283 | Adobe ColdFusion CWE-434 unrestricted file-upload RCE (CVSS 10.0), APSB26-68 | 2026-07-02 | 2026-07-02 | 2026-07-02 |
| CVE-2026-48286 | Adobe Campaign Classic CWE-863 incorrect-authorization code execution (CVSS 10.0), APSB26-69 | 2026-07-02 | 2026-07-02 | · |
| CVE-2026-48316 | Adobe ColdFusion CWE-20 improper-input-validation RCE (CVSS 10.0), APSB26-68 | 2026-07-02 | 2026-07-02 | 2026-07-02 |
| CVE-2023-4966 | Citrix NetScaler ADC/Gateway 'CitrixBleed' session-token memory overread, cited as CVE-2026-8451 lineage context | 2026-07-01 | 2026-07-01 | · |
| CVE-2025-12101 | Citrix NetScaler ADC/Gateway memory-leak (CitrixBleed variant), cited as CVE-2026-8451 lineage context | 2026-07-01 | 2026-07-01 | · |
| CVE-2026-10816 | Citrix NetScaler ADC/Gateway, Management Interface unauthenticated arbitrary file read (CTX696604) | 2026-07-01 | 2026-07-01 | · |
| CVE-2026-10817 | Citrix NetScaler ADC/Gateway, memory overread when TCP TimeStamp enabled on LB/CS/VPN vserver (CTX696604) | 2026-07-01 | 2026-07-01 | · |
| CVE-2026-13474 | Citrix NetScaler ADC/Gateway, CTX696604 companion CVE | 2026-07-01 | 2026-07-01 | · |
| CVE-2026-35273 | Oracle PeopleSoft PeopleTools PSEMHUB pre-auth RCE (CVSS 9.8), zero-day exploited by UNC6240/ShinyHunters | 2026-06-11 | 2026-07-01 | 2026-06-28 +1 more |
| CVE-2026-8655 | Citrix NetScaler ADC/Gateway, memory-management flaw (Gateway/DNS-proxy/AAA vserver), DoS/undefined control flow (CTX696604) | 2026-07-01 | 2026-07-01 | · |
| CVE-2026-13165 | SzafirHost (KIR e-signature client) JAR parser confusion (JarFile vs JarInputStream, CWE-434) → native-library RCE past signature check; fixed v1.2.2 | 2026-06-30 | 2026-06-30 | 2026-06-30 |
| CVE-2026-33691 | Progress Kemp LoadMaster, OWASP CRS whitespace-padding file-upload extension-check bypass (high); same bulletin as CVE-2026-8037 | 2026-06-09 | 2026-06-30 | · |
| CVE-2026-43503 | Linux kernel 'DirtyClone' LPE, SKBFL_SHARED_FRAG drop in __pskb_copy_fclone() + IPsec in-place decrypt; JFrog working exploit on Debian/Ubuntu/Fedora (CVSS 8.8) | 2026-06-27 | 2026-06-30 | 2026-06-27 |
| CVE-2026-48558 | SimpleHelp RMM OIDC SSO auth bypass, forged-token full Technician session + MFA bypass; now actively exploited (CISA KEV 2026-06-29), Djinn infostealer via TaskWeaver loader (CVSS 10.0) | 2026-06-13 | 2026-06-30 | 2026-06-30 +1 more |
| CVE-2026-54305 | n8n Dynamic Credentials EE, missing ownership/scope checks enable cross-tenant OAuth credential hijack/revoke (CVSS 8.9, GHSA-2j5h-858j-5mpf); NCSC-2026-0212 | 2026-06-30 | 2026-06-30 | · |
| CVE-2026-54307 | n8n public API, editor-level users read other users' credentials in shared instances (CVSS 8.5); NCSC-2026-0212 | 2026-06-30 | 2026-06-30 | · |
| CVE-2026-55200 | libssh2 pre-auth heap OOB write in ssh2_transport_read() (CVSS 9.2), public PoC released 2026-06-29; no fixed release tagged yet | 2026-06-28 | 2026-06-30 | 2026-06-28 |
| CVE-2026-52806 | Gogs argument-injection RCE (CVE-2026-52806); now actively exploited in K8s cryptojacking campaign (Wiz) | 2026-06-14 | 2026-06-29 | 2026-06-20 |
| CVE-2025-67038 | Lantronix EDS5000 OS command injection to root (BRIDGE:BREAK; CISA KEV 2026-06-23) | 2026-06-24 | 2026-06-28 | 2026-06-24 |
| CVE-2025-8088 | WinRAR path-traversal (referenced as initial-access exploit in Gamaredon GammaPhish/GammaWorm campaign, Sekoia 2026-06-01) | 2026-06-02 | 2026-06-28 | 2026-06-27 +2 more |
| CVE-2026-10735 | ShapedPlugin WordPress Pro supply-chain backdoor (build/EDD pipeline compromise) | 2026-06-23 | 2026-06-28 | 2026-06-23 |
| CVE-2026-11800 | Keycloak JWT algorithm confusion -> federated-user impersonation (CVSS 8.1) | 2026-06-28 | 2026-06-28 | 2026-06-28 |
| CVE-2026-12789 | ILIAS 11.0 SQL injection in ilTrQuery learning-progress subsystem (no patch, PoC public) | 2026-06-23 | 2026-06-28 | 2026-06-23 |
| CVE-2026-20230 | Cisco Unified Communications Manager WebDialer unauthenticated SSRF → OS-root file write (SIR Critical); fix 14SU6 / Release 15 COP | 2026-06-04 | 2026-06-28 | 2026-06-24 +1 more |
| CVE-2026-20245 | Cisco Catalyst SD-WAN Manager command-injection to root; Mandiant confirms pre-disclosure zero-day exploitation; patched (chains CVE-2026-20127/-20182) | 2026-06-06 | 2026-06-28 | 2026-06-26 +1 more |
| CVE-2026-20262 | Cisco Catalyst SD-WAN Manager web UI authenticated path traversal, arbitrary file write to root RCE; CISA KEV 2026-06-15 | 2026-06-16 | 2026-06-28 | 2026-06-16 |
| CVE-2026-34908 | Ubiquiti UniFi OS improper access control (chain step 1 to unauth root; CISA KEV 2026-06-23) | 2026-06-24 | 2026-06-28 | 2026-06-24 |
| CVE-2026-34909 | Ubiquiti UniFi OS path traversal (chain step 2 to unauth root; CISA KEV 2026-06-23) | 2026-06-24 | 2026-06-28 | 2026-06-24 |
| CVE-2026-34910 | Ubiquiti UniFi OS improper input validation/command injection to root (CISA KEV 2026-06-23, actively exploited) | 2026-06-24 | 2026-06-28 | 2026-06-24 |
| CVE-2026-46331 | Linux kernel 'pedit COW' LPE, tc act_pedit out-of-bounds write poisons setuid-binary page cache; public weaponised PoC | 2026-06-27 | 2026-06-28 | 2026-06-27 |
| CVE-2026-55199 | libssh2 infinite-loop pre-auth DoS via crafted SSH_MSG_EXT_INFO (CVSS 8.2) | 2026-06-28 | 2026-06-28 | 2026-06-28 |
| CVE-2026-58053 | Gitea act_runner Docker container-hardening bypass to host escape (CVSS 9.4, public PoC) | 2026-06-28 | 2026-06-28 | 2026-06-28 |
| CVE-2026-9099 | Keycloak group-admin to realm-admin privilege escalation | 2026-06-28 | 2026-06-28 | · |
| CVE-2026-9800 | Keycloak policy-enforcer authorization bypass via access-denied-page path (CVSS 8.1) | 2026-06-28 | 2026-06-28 | 2026-06-28 |
| CVE-2021-26855 | Microsoft Exchange Server SSRF (ProxyLogon), cited in 2026-05-16 § 5 deep dive Background as precedent for on-prem Exchange exploitation pattern | 2026-05-16 | 2026-06-27 | · |
| CVE-2023-32315 | Openfire admin-console path-traversal auth bypass, StrikeShark/SharkLoader initial-access vector | 2026-06-27 | 2026-06-27 | · |
| CVE-2023-46747 | F5 BIG-IP TMUI unauthenticated RCE, StrikeShark/SharkLoader initial-access vector | 2026-06-27 | 2026-06-27 | · |
| CVE-2024-21762 | Fortinet FortiOS SSL-VPN out-of-bounds write RCE, StrikeShark/SharkLoader initial-access vector | 2026-06-27 | 2026-06-27 | · |
| CVE-2024-36401 | OSGeo GeoServer OGC-filter RCE, StrikeShark/SharkLoader initial-access vector | 2026-06-27 | 2026-06-27 | · |
| CVE-2026-10712 | GitLab Web IDE workbench stored XSS (CVSS 8.0), patched 19.1.1/19.0.3/18.11.6; assessed, did not clear §2 gate | 2026-06-26 | 2026-06-27 | · |
| CVE-2026-12957 | Amazon Q Developer (VS Code) auto-loads workspace .amazonq/mcp.json without consent, repo-planted code execution + AWS credential theft | 2026-06-27 | 2026-06-27 | 2026-06-27 |
| CVE-2026-20127 | Cisco Catalyst SD-WAN Manager pre-auth RCE (UAT-8616 prior exploitation, Feb 2026) | 2026-05-15 | 2026-06-27 | 2026-06-06 |
| CVE-2026-20182 | Cisco Catalyst SD-WAN Controller/Manager pre-auth authentication bypass (CVSS 10.0, actively exploited by UAT-8616) | 2026-05-15 | 2026-06-27 | 2026-06-06 +1 more |
| CVE-2026-50751 | Check Point Security Gateway IKEv1 Remote Access/Mobile Access certificate-validation authentication bypass (CVSS 9.3), actively exploited by Qilin affiliate since 2026-05-07, CISA KEV | 2026-06-09 | 2026-06-27 | 2026-06-09 |
| CVE-2026-10086 | GitLab EE Analytics Dashboard stored XSS (CVSS 8.7), patched 19.1.1/19.0.3/18.11.6; assessed, did not clear §2 gate | 2026-06-26 | 2026-06-26 | · |
| CVE-2026-12635 | GitLab repository-mirroring SSRF (CVSS 3.1), patched 19.1.1/19.0.3/18.11.6; low severity, did not clear §2 gate | 2026-06-26 | 2026-06-26 | · |
| CVE-2026-8461 | FFmpeg MagicYUV decoder heap OOB write (PixelSmash, CVSS 8.8), fixed FFmpeg 8.1.2; out-of-window this run | 2026-06-26 | 2026-06-26 | · |
| CVE-2026-39893 | Cacti <1.2.31, pre-auth SQLi in graph_view.php (rfilter); evaluated, dropped to § 7 (out-of-window, single GHSA) | 2026-06-25 | 2026-06-25 | · |
| CVE-2026-56422 | MISP <2.5.42, broken access control | 2026-06-25 | 2026-06-25 | 2026-06-25 |
| CVE-2026-56423 | MISP <2.5.42, cross-org IDOR overwrite | 2026-06-25 | 2026-06-25 | 2026-06-25 |
| CVE-2026-56424 | MISP <2.5.42, broken access control, cross-org hard-delete | 2026-06-25 | 2026-06-25 | 2026-06-25 |
| CVE-2026-56425 | MISP <2.5.42, Azure-AD OAuth state-reuse session hijack | 2026-06-25 | 2026-06-25 | 2026-06-25 |
| CVE-2026-56446 | MISP <2.5.42, NDJSON log-injection PHP RCE (site-admin) | 2026-06-25 | 2026-06-25 | 2026-06-25 |
| CVE-2026-56447 | MISP <2.5.42, rdkafka plugin-load RCE (site-admin) | 2026-06-25 | 2026-06-25 | 2026-06-25 |
| CVE-2026-7473 | Arista EOS tunnel-decapsulation logic flaw (CWE-1023) bypasses VXLAN segmentation; CISA KEV, exploited | 2026-06-10 | 2026-06-25 | 2026-06-10 |
| CVE-2024-40766 | SonicWall SonicOS improper access control (mgmt + SSLVPN, Gen 5/6/7), Akira/Fog ransomware on-ramp | 2026-06-23 | 2026-06-23 | 2026-06-23 |
| CVE-2025-59718 | FortiGate credential-reuse vector referenced in FortiBleed campaign | 2026-06-23 | 2026-06-23 | · |
| CVE-2025-59719 | FortiGate credential-reuse vector referenced in FortiBleed campaign | 2026-06-23 | 2026-06-23 | · |
| CVE-2026-20779 | Gitea TOTP 2FA bypass (web TOCTOU + X-Gitea-OTP replay) | 2026-06-23 | 2026-06-23 | · |
| CVE-2026-22874 | Gitea SSRF in webhook / repo-migration subsystems | 2026-06-23 | 2026-06-23 | · |
| CVE-2026-24858 | FortiGate credential-reuse vector referenced in FortiBleed campaign | 2026-06-23 | 2026-06-23 | · |
| CVE-2026-27775 | Gitea protected-branch enforcement race (single-push batch) | 2026-06-23 | 2026-06-23 | · |
| CVE-2026-41947 | DifyTap, Dify AI platform cross-tenant authorization bypass (evaluated, dropped § 7: authenticated, no ITW, aggregator-only primary) | 2026-06-23 | 2026-06-23 | · |
| CVE-2026-47645 | Microsoft 365 Copilot Business Chat open redirect (BSI WID-SEC-2026-2020; server-side mitigated, dropped § 7) | 2026-06-23 | 2026-06-23 | · |
| CVE-2026-47729 | Squidbleed, 29-year-old heap over-read in Squid FTP gateway leaks cross-user HTTP credentials | 2026-06-23 | 2026-06-23 | 2026-06-23 |
| CVE-2026-49777 | ShapedPlugin supply-chain backdoor, duplicate CVE submission for CVE-2026-10735 (noted § 7) | 2026-06-23 | 2026-06-23 | · |
| CVE-2026-54130 | Microsoft 365 Copilot missing-authentication info disclosure (BSI WID-SEC-2026-2020; server-side mitigated, dropped § 7) | 2026-06-23 | 2026-06-23 | · |
| CVE-2013-3307 | Linksys/D-Link RTL819X command-injection RCE, initial-access vector for the AryStinger botnet | 2026-06-22 | 2026-06-22 | 2026-06-22 |
| CVE-2016-5681 | D-Link DIR-850L HTTP-service stack buffer overflow RCE, AryStinger botnet access vector | 2026-06-22 | 2026-06-22 | 2026-06-22 |
| CVE-2025-11837 | QNAP Malware Remover code injection (fixed 6.6.8.20251023), AryStinger NAS access vector | 2026-06-22 | 2026-06-22 | 2026-06-22 |
| CVE-2023-24932 | Windows Boot Manager Secure Boot bypass (BlackLotus-class), possible FishMonger SprySOCKS UEFI component (unconfirmed) | 2026-06-17 | 2026-06-21 | · |
| CVE-2025-13036 | Rockwell FactoryTalk Historian Site Edition, authentication bypass (CVSS 7.7) | 2026-06-18 | 2026-06-21 | 2026-06-18 |
| CVE-2026-0257 | PAN-OS GlobalProtect pre-auth authentication bypass | 2026-05-30 | 2026-06-21 | 2026-05-30 |
| CVE-2026-0646 | Rockwell 1794-AENTR/AENTRXT FLEX I/O, CIP-handling denial-of-service (CVSS 7.5) | 2026-06-18 | 2026-06-21 | 2026-06-18 |
| CVE-2026-0647 | Rockwell 1794-AENTR/AENTRXT FLEX I/O, unauthenticated web-interface password reset (CVSS 9.4) | 2026-06-18 | 2026-06-21 | 2026-06-18 |
| CVE-2026-10795 | UpdraftPlus WordPress plugin unauthenticated auth-bypass to RCE (all-zero AES key on failed RSA decrypt), CVSS 8.1; actively exploited | 2026-06-14 | 2026-06-21 | 2026-06-14 |
| CVE-2026-11317 | Rockwell CompactLogix/ControlLogix 5370/5570, CIP message major non-recoverable fault DoS (CVSS 7.5) | 2026-06-18 | 2026-06-21 | 2026-06-18 |
| CVE-2026-12046 | pgAdmin 4, unauthenticated pickle.loads RCE primitive in SQL Editor (server mode, CVSS v4 9.5) | 2026-06-19 | 2026-06-21 | 2026-06-19 |
| CVE-2026-20181 | Cisco ISE / ISE-PIC, authenticated path-traversal OS command execution to root (CVSS 9.1) | 2026-06-19 | 2026-06-21 | 2026-06-19 |
| CVE-2026-20190 | Cisco ISE / ISE-PIC, unauthenticated read of sensitive data incl. hashed admin credentials (CVSS 7.5) | 2026-06-19 | 2026-06-21 | 2026-06-19 |
| CVE-2026-20253 | Splunk Enterprise pre-auth RCE via unauthenticated PostgreSQL sidecar REST API proxied by web tier, CVSS 9.8 | 2026-06-14 | 2026-06-21 | 2026-06-14 |
| CVE-2026-2473 | Google Cloud Vertex AI SDK, predictable staging-bucket cross-tenant pickle RCE ('Pickle in the Middle'); patched 1.148.0 | 2026-06-17 | 2026-06-21 | · |
| CVE-2026-25089 | FortiSandbox unauthenticated OS command injection in VNC handler (CVSS 9.8); dropped from brief - no inclusion gate cleared | 2026-06-11 | 2026-06-21 | 2026-06-12 |
| CVE-2026-35278 | Oracle PeopleSoft PeopleTools 8.61/8.62 Performance Monitor, missing-auth RCE (CVSS 9.8) | 2026-06-18 | 2026-06-21 | 2026-06-18 |
| CVE-2026-39808 | Fortinet FortiSandbox, JRPC API OS command injection (CVSS 9.8); actively exploited | 2026-06-12 | 2026-06-21 | 2026-06-12 |
| CVE-2026-39813 | Fortinet FortiSandbox, JRPC API path traversal / auth bypass (CVSS 9.1); actively exploited | 2026-06-12 | 2026-06-21 | 2026-06-12 |
| CVE-2026-4020 | Gravity SMTP WordPress plugin unauthenticated info-disclosure (email-connector credential dump), mass-exploited | 2026-06-21 | 2026-06-21 | 2026-06-21 |
| CVE-2026-40624 | AVer PTC500S/PTC115/PTC500+/PTC115+ cameras, unauthenticated RCE via management web interface (CVSS 9.8), CISA ICSA-26-169-01 | 2026-06-20 | 2026-06-21 | 2026-06-20 |
| CVE-2026-42055 | NGINX, heap overflow in ngx_http_proxy_v2_module/ngx_http_grpc_module (CVSS v4 9.2) | 2026-06-19 | 2026-06-21 | 2026-06-19 |
| CVE-2026-42530 | NGINX, HTTP/3 QUIC use-after-free in ngx_http_v3_module (CVSS v4 9.2) | 2026-06-19 | 2026-06-21 | 2026-06-19 |
| CVE-2026-42824 | Microsoft 365 Copilot Enterprise Search 'SearchLeak' command-injection/info-disclosure; one-click exfil; patched server-side | 2026-06-16 | 2026-06-21 | 2026-06-16 |
| CVE-2026-46978 | Oracle Solaris 11.4 Remote Administration Daemon, unauthenticated flaw (CVSS 10.0), Oracle June 2026 CSPU | 2026-06-18 | 2026-06-21 | 2026-06-18 |
| CVE-2026-48611 | phpBB OAuth improper-authentication account hijack (admin) even when OAuth disabled; CVSS 9.8; fixed 3.3.17 | 2026-06-16 | 2026-06-21 | 2026-06-16 |
| CVE-2026-48907 | Widget Factory Joomla Content Editor (JCE) <2.9.99.5, unauthenticated profile-import to PHP RCE (CVSS v4 10.0); CISA KEV | 2026-06-17 | 2026-06-21 | 2026-06-17 |
| CVE-2026-54420 | LiteSpeed cPanel/WHM plugin symlink-following on CloudLinux/CageFS shared hosting; exploited ITW May 2026; CISA KEV | 2026-06-16 | 2026-06-21 | 2026-06-16 |
| CVE-2026-55803 | Drupal core, JSON:API PHP object injection (SA-CORE-2026-005, critical) | 2026-06-19 | 2026-06-21 | 2026-06-19 |
| CVE-2026-55804 | Drupal core, deserialization gadget chain (SA-CORE-2026-006) | 2026-06-19 | 2026-06-21 | 2026-06-19 |
| CVE-2026-12045 | pgAdmin 4, AI Assistant read-only-transaction bypass to RCE via COPY TO PROGRAM (CVSS v4 9.4) | 2026-06-19 | 2026-06-19 | 2026-06-19 |
| CVE-2026-12048 | pgAdmin 4, stored XSS via unsanitised PostgreSQL error/EXPLAIN content (CVSS v4 9.3) | 2026-06-19 | 2026-06-19 | 2026-06-19 |
| CVE-2026-55806 | Drupal core, rebuild.php trusted-host bypass (SA-CORE-2026-007) | 2026-06-19 | 2026-06-19 | · |
| CVE-2026-55807 | Drupal core, Media module oEmbed SSRF (SA-CORE-2026-008) | 2026-06-19 | 2026-06-19 | · |
| CVE-2026-55808 | Drupal core, JSON:API/REST image-upload MIME-validation gap (SA-CORE-2026-009) | 2026-06-19 | 2026-06-19 | · |
| CVE-2020-25213 | WP File Manager pre-auth RCE, used as fallback vector in the ErrTraffic ClickFix framework | 2026-06-17 | 2026-06-17 | · |
| CVE-2023-52271 | Topaz Antifraud wsftprm.sys vulnerable kernel driver, DragonForce BYOVD chain | 2026-06-17 | 2026-06-17 | · |
| CVE-2025-1055 | K7 Security K7RKScan.sys vulnerable kernel driver, DragonForce BYOVD chain | 2026-06-17 | 2026-06-17 | · |
| CVE-2025-55182 | React/Next.js Server Actions deserialisation ("React2Shell"), weaponised by PCPJack worm | 2026-05-10 | 2026-06-17 | · |
| CVE-2025-61155 | Tower of Fantasy GameDriverx64.sys vulnerable kernel driver, DragonForce BYOVD chain | 2026-06-17 | 2026-06-17 | · |
| CVE-2026-20251 | Splunk Secure Gateway jsonpickle deserialization RCE (CVSS 8.8), assessed, no §2 gate (no ITW, post-auth); NCSC-NL advisory | 2026-06-16 | 2026-06-16 | · |
| CVE-2026-40217 | LiteLLM Custom Code Guardrails sandbox escape to RCE via exec()/bytecode; CVSS 8.8; fixed v1.83.14 | 2026-06-16 | 2026-06-16 | 2026-06-16 |
| CVE-2026-47101 | LiteLLM authorization bypass via unvalidated allowed_routes in key-generation; CVSS 8.8; fixed v1.83.14 | 2026-06-16 | 2026-06-16 | 2026-06-16 |
| CVE-2026-47102 | LiteLLM privilege escalation, self-promote to proxy_admin via /user/update; CVSS 8.8; fixed v1.83.14 | 2026-06-16 | 2026-06-16 | 2026-06-16 |
| CVE-2026-48612 | phpBB OAuth improper state verification + CSRF session hijack; CVSS 8.0; fixed 3.3.17 | 2026-06-16 | 2026-06-16 | 2026-06-16 |
| CVE-2026-10087 | GitLab EE Analytics Dashboard stored XSS (CVSS 8.7), assessed, no §2 gate | 2026-06-15 | 2026-06-15 | · |
| CVE-2026-34182 | OpenSSL CMS AuthEnvelopedData integrity bypass (moderate), assessed, out-of-window, not promoted | 2026-06-15 | 2026-06-15 | · |
| CVE-2026-47124 | Traefik v3.x security-policy bypass (GHSA-3g6v-2r68-prfc), assessed, no §2 gate, out-of-window | 2026-06-15 | 2026-06-15 | · |
| CVE-2026-47928 | Adobe ColdFusion unauthenticated no-interaction RCE (CVSS 9.6, APSB26-64; scope change S:C; fixed 2023 Update 20 / 2025 Update 9) | 2026-06-15 | 2026-06-15 | · |
| CVE-2026-47932 | Adobe ColdFusion path-traversal security-feature bypass (CVSS 8.8, APSB26-64), co-disclosed; assessed, not promoted | 2026-06-15 | 2026-06-15 | · |
| CVE-2026-7250 | GitLab CE/EE Grape API unauthenticated DoS (CVSS 7.5), assessed, no §2 gate | 2026-06-15 | 2026-06-15 | · |
| CVE-2026-9204 | GitLab CE/EE Gitaly repository-import SSRF (CVSS 5.3), assessed, no §2 gate | 2026-06-15 | 2026-06-15 | · |
| CVE-2020-17103 | Windows Cloud Filter driver cldflt.sys privilege escalation (MiniPlasma PoC) | 2026-05-18 | 2026-06-14 | 2026-05-19 |
| CVE-2022-38028 | Windows Print Spooler privilege escalation weaponised by APT28 GooseEgg (cited as historical context in Sekoia APT28 retrospective) | 2026-06-14 | 2026-06-14 | · |
| CVE-2025-67644 | LangGraph SQLite checkpointer SQL injection in get_state_history() (CVSS 7.3; fixed langgraph-checkpoint-sqlite 3.0.1) | 2026-06-13 | 2026-06-14 | 2026-06-13 |
| CVE-2026-10520 | Ivanti Sentry pre-auth OS command injection to root (MICS handleMessage), CVSS 10.0; public PoC by watchTowr | 2026-06-10 | 2026-06-14 | 2026-06-10 |
| CVE-2026-10523 | Ivanti Sentry authentication bypass (CWE-288), companion to CVE-2026-10520 | 2026-06-10 | 2026-06-14 | 2026-06-10 |
| CVE-2026-11645 | Google Chrome V8 out-of-bounds read/write, exploited ITW, CISA KEV; fixed 149.0.7827.103 | 2026-06-10 | 2026-06-14 | 2026-06-10 |
| CVE-2026-12183 | BUK TS-G gas-station automation unauthenticated admin bypass, CVSS 9.8 (dropped from brief, aggregator-only sourcing) | 2026-06-14 | 2026-06-14 | · |
| CVE-2026-23111 | Linux kernel nf_tables use-after-free in nft_map_catchall_activate() (single-character genmask inversion), local-root + container escape, working public exploit (Exodus Intelligence), patched upstream 2026-02-05, CVSS 7.8 | 2026-06-09 | 2026-06-14 | 2026-06-09 |
| CVE-2026-28277 | LangGraph unsafe msgpack deserialization on checkpoint load, chains with SQLi to RCE (CVSS 6.8; fixed langgraph 1.0.10) | 2026-06-13 | 2026-06-14 | 2026-06-13 |
| CVE-2026-3300 | Everest Forms Pro (WordPress) Calculation Addon unauthenticated eval() PHP code injection (CVSS 9.8); mass exploitation since 2026-04-13 creating rogue admin accounts; patched v1.9.13 (2026-03-18) | 2026-06-08 | 2026-06-14 | 2026-06-08 |
| CVE-2026-41089 | Windows Netlogon stack buffer overflow, unauthenticated remote RCE to SYSTEM on domain controllers (CVSS 9.8, May 2026 Patch Tuesday); active ITW exploitation confirmed by CCB Belgium 2026-06-01 | 2026-05-13 | 2026-06-14 | 2026-06-11 +1 more |
| CVE-2026-44748 | SAP NetWeaver AS ABAP SAML XML Signature Wrapping (CVSS 9.9), SAP_BASIS 702-919 | 2026-06-10 | 2026-06-14 | 2026-06-10 |
| CVE-2026-44963 | Veeam Backup & Replication 12.x authenticated domain-user deserialization RCE (CVSS 9.4); fixed 12.3.2.4854 | 2026-06-10 | 2026-06-14 | 2026-06-10 |
| CVE-2026-45585 | Windows YellowKey BitLocker bypass via WinRE | 2026-05-15 | 2026-06-14 | 2026-05-30 +1 more |
| CVE-2026-45586 | Windows CTFMON elevation of privilege (June 2026 Patch Tuesday); referenced in § 7 GreenPlasma cross-source discrepancy note | 2026-06-11 | 2026-06-14 | · |
| CVE-2026-45657 | Windows kernel TCP/IP use-after-free network RCE to SYSTEM (CVSS 9.8) | 2026-06-12 | 2026-06-14 | 2026-06-12 |
| CVE-2026-47210 | vm2 Node.js sandbox escape via WebAssembly JSPI Promise-species bypass, CVSS 9.8 (dropped from brief, out-of-window, no ITW) | 2026-06-14 | 2026-06-14 | · |
| CVE-2026-47344 | TYPO3 Core June 2026 (TYPO3-CORE-SA-2026-006), XSS bypassing the HTML Sanitizer; lead CVE of the 13-advisory batch | 2026-06-10 | 2026-06-14 | 2026-06-10 |
| CVE-2026-47895 | strongSwan libstrongswan identity-clone double-free, unauth RCE over EAP; fixed 6.0.7 | 2026-06-10 | 2026-06-14 | 2026-06-10 |
| CVE-2026-49200 | Acer Wave-7 mesh router broken access control, unauthenticated cleartext credential log acer_cgi.log exposure (CVSS 10.0, no patch until ~end-June 2026) | 2026-06-08 | 2026-06-14 | 2026-06-08 |
| CVE-2026-49201 | Acer Wave-7 mesh router hardcoded AES key in upload.cgi backup handler, persistent backdoor injection (CVSS 10.0, no patch until ~end-June 2026) | 2026-06-08 | 2026-06-14 | 2026-06-08 |
| CVE-2026-49261 | MariaDB Server Galera wsrep_notify_cmd OS command injection (CVSS 10.0) | 2026-06-12 | 2026-06-14 | 2026-06-12 |
| CVE-2026-5027 | Langflow path traversal (POST /api/v2/files) -> arbitrary file write, pre-auth via default auto-login, exploited ITW | 2026-06-11 | 2026-06-14 | 2026-06-11 |
| CVE-2026-27022 | LangGraph Redis checkpointer RediSearch query injection (CVSS 6.5; fixed @langchain/langgraph-checkpoint-redis 1.0.1) | 2026-06-13 | 2026-06-13 | 2026-06-13 |
| CVE-2026-45447 | OpenSSL PKCS7_verify heap use-after-free on empty SignedData.digestAlgorithms (High; fixed 4.0.1/3.6.3/3.5.7/3.4.6/3.0.21); out-of-window drop this run | 2026-06-13 | 2026-06-13 | · |
| CVE-2026-6552 | GitLab EE Group SAML identity API improper authorization, Group Owner account takeover (CVSS 8.7; fixed 19.0.2/18.11.5/18.10.8), did not clear daily section-2 gate | 2026-06-13 | 2026-06-13 | · |
| CVE-2026-26142 | Nuance PowerScribe unauthenticated deserialization RCE (CVSS 9.8) | 2026-06-12 | 2026-06-12 | 2026-06-12 |
| CVE-2026-47643 | Azure Stack Edge external file path control RCE (CVSS 9.8) | 2026-06-12 | 2026-06-12 | 2026-06-12 |
| CVE-2026-48163 | MariaDB Galera wsrep parameter-injection (companion fix to CVE-2026-49261) | 2026-06-12 | 2026-06-12 | 2026-06-12 |
| CVE-2026-48165 | MariaDB Galera wsrep parameter-injection (companion fix to CVE-2026-49261) | 2026-06-12 | 2026-06-12 | 2026-06-12 |
| CVE-2026-48579 | Exchange Online improper-authorisation information disclosure (CVSS 9.1, service-side fix) | 2026-06-12 | 2026-06-12 | 2026-06-12 |
| CVE-2026-35616 | Fortinet FortiClient EMS 7.4.5/7.4.6; improper-access-control on X-SSL-CLIENT-VERIFY header lets unauth attacker spoof mTLS state and reach management API; ITW exploited to push EKZ Infostealer per Arctic Wolf 2026-05-27 | 2026-05-29 | 2026-06-11 | 2026-05-29 |
| CVE-2026-50507 | Windows BitLocker physical-access bypass, publicly disclosed, June 2026 Patch Tuesday | 2026-06-10 | 2026-06-11 | 2026-06-10 |
| CVE-2026-22732 | SAP Commerce Cloud / Data Hub missing HTTP security headers via Spring Security (CVSS 9.1) | 2026-06-10 | 2026-06-10 | 2026-06-10 |
| CVE-2026-27671 | SAP NetWeaver/ABAP RFC kernel memory corruption, unauthenticated (CVSS 9.8) | 2026-06-10 | 2026-06-10 | 2026-06-10 |
| CVE-2026-40128 | SAP NetWeaver AS Java Web Container path traversal (CVSS 9.0) | 2026-06-10 | 2026-06-10 | 2026-06-10 |
| CVE-2026-44815 | Windows DHCP Client Service RCE (CVSS 9.8), June 2026 Patch Tuesday | 2026-06-10 | 2026-06-10 | 2026-06-10 |
| CVE-2026-47281 | Visual Studio Code EoP to SYSTEM via malicious .code-workspace (CVSS 9.6) | 2026-06-10 | 2026-06-10 | 2026-06-10 |
| CVE-2026-49160 | Windows HTTP.sys HTTP/2 compression-bomb DoS (IIS analogue of CVE-2026-49975); MaxHeadersCount mitigation | 2026-06-10 | 2026-06-10 | 2026-06-10 |
| CVE-2026-49975 | HTTP/2 Bomb, HPACK dynamic-table amplification + Slowloris stream-hold memory-exhaustion DoS vs nginx/Apache/IIS/Envoy/Pingora; nginx 1.29.8 & Apache mod_http2 2.0.41 patched, IIS/Envoy/Pingora unpatched at disclosure | 2026-06-04 | 2026-06-10 | 2026-06-04 |
| CVE-2026-50752 | Check Point IKEv1 site-to-site VPN MitM via certificate validation weakness (CVSS 7.4), no observed exploitation | 2026-06-09 | 2026-06-09 | 2026-06-09 |
| CVE-2021-27137 | DD-WRT UPnP/SSDP parser stack buffer overflow, FortiGuard-attributed propagation vector for C0XMO/Gafgyt botnet; DOES NOT RESOLVE ON NVD/MITRE (flagged 2026-06-08, vendor-attributed/unverified) | 2026-06-08 | 2026-06-08 | · |
| CVE-2026-10881 | Google Chrome ANGLE graphics engine out-of-bounds read/write → sandbox escape (CVSS 9.6); Chrome 149 record 429-patch release | 2026-06-07 | 2026-06-07 | 2026-06-07 |
| CVE-2026-37977 | Keycloak CORS ACAO reflected from unverified JWT azp claim on UMA endpoint (fixed 26.6.3) | 2026-06-07 | 2026-06-07 | 2026-06-07 |
| CVE-2026-39210 | FFmpeg parser/demuxer heap or stack overflow (depthfirst AI-agent discovery; PoC public, fixed upstream) | 2026-06-07 | 2026-06-07 | 2026-06-07 |
| CVE-2026-39211 | FFmpeg parser/demuxer heap or stack overflow (depthfirst AI-agent discovery; PoC public, fixed upstream) | 2026-06-07 | 2026-06-07 | 2026-06-07 |
| CVE-2026-39212 | FFmpeg parser/demuxer heap or stack overflow (depthfirst AI-agent discovery; PoC public, fixed upstream) | 2026-06-07 | 2026-06-07 | 2026-06-07 |
| CVE-2026-39213 | FFmpeg parser/demuxer heap or stack overflow (depthfirst AI-agent discovery; PoC public, fixed upstream) | 2026-06-07 | 2026-06-07 | 2026-06-07 |
| CVE-2026-39214 | FFmpeg parser/demuxer heap or stack overflow (depthfirst AI-agent discovery; PoC public, fixed upstream) | 2026-06-07 | 2026-06-07 | 2026-06-07 |
| CVE-2026-39215 | FFmpeg parser/demuxer heap or stack overflow (depthfirst AI-agent discovery; PoC public, fixed upstream) | 2026-06-07 | 2026-06-07 | 2026-06-07 |
| CVE-2026-39216 | FFmpeg parser/demuxer heap or stack overflow (depthfirst AI-agent discovery; PoC public, fixed upstream) | 2026-06-07 | 2026-06-07 | 2026-06-07 |
| CVE-2026-39217 | FFmpeg parser/demuxer heap or stack overflow (depthfirst AI-agent discovery; PoC public, fixed upstream) | 2026-06-07 | 2026-06-07 | 2026-06-07 |
| CVE-2026-39218 | FFmpeg parser/demuxer heap or stack overflow (depthfirst AI-agent discovery; PoC public, fixed upstream) | 2026-06-07 | 2026-06-07 | 2026-06-07 |
| CVE-2026-4874 | Keycloak SSRF via OIDC token endpoint manipulation (fixed 26.6.3) | 2026-06-07 | 2026-06-07 | 2026-06-07 |
| CVE-2026-8830 | Keycloak missing server-side WebAuthn credential-registration validation (fixed 26.6.3) | 2026-06-07 | 2026-06-07 | 2026-06-07 |
| CVE-2026-9704 | Keycloak token-exchange privilege escalation via silent subject_token removal (fixed 26.6.3) | 2026-06-07 | 2026-06-07 | 2026-06-07 |
| CVE-2026-9792 | Keycloak ROPC grant bypass of client-policy enforcement (fixed 26.6.3) | 2026-06-07 | 2026-06-07 | 2026-06-07 |
| CVE-2026-9802 | Keycloak refresh-token replay window after server restart resets startupTime (fixed 26.6.3) | 2026-06-07 | 2026-06-07 | 2026-06-07 |
| CVE-2026-10854 | MISP access-control bypass exposing private galaxy metadata to non-admin org users (CVSS 5.3) | 2026-06-06 | 2026-06-06 | · |
| CVE-2026-10868 | MISP mass-assignment account-takeover in UsersController::edit() (CVSS 9.0, patched 2026-06-04) | 2026-06-06 | 2026-06-06 | 2026-06-06 |
| CVE-2026-28318 | SolarWinds Serv-U uncontrolled resource consumption, unauthenticated DoS via Content-Encoding: deflate (CISA KEV 2026-06-05) | 2026-06-06 | 2026-06-06 | 2026-06-06 |
| CVE-2026-23479 | Redis use-after-free in unblockClientOnKey() → GOT-overwrite RCE (post-auth; default-passwordless) | 2026-06-05 | 2026-06-05 | 2026-06-05 |
| CVE-2026-34906 | Simple SA Wirtualna Uczelnia unauthenticated SSTI → RCE (redirectToUrl) | 2026-06-05 | 2026-06-05 | 2026-06-05 |
| CVE-2026-34907 | Simple SA Wirtualna Uczelnia reflected XSS (locale parameter) | 2026-06-05 | 2026-06-05 | 2026-06-05 |
| CVE-2026-41283 | OpenStack Mistral policy-enforcement bypass → authenticated arbitrary code execution (OSSA-2026-020; evaluated and dropped, see brief §7) | 2026-06-05 | 2026-06-05 | · |
| CVE-2026-10611 | MISP OTP bypass, session established in beforeFilter before OTP when LdapAuth.mixedAuth+require_otp both on; fix commit 39b3cb15 / >=2.5.37 | 2026-06-04 | 2026-06-04 | 2026-06-04 |
| CVE-2026-33829 | Windows Snipping Tool ms-screensketch: URI handler NTLM hash leak, patched April 2026; cited as structural predecessor of unpatched search: URI variant | 2026-06-04 | 2026-06-04 | · |
| CVE-2026-41100 | Microsoft 365 Copilot for Android OAuth-token theft via production debug flag (CVSS 4.4); patched 2026-05-12 | 2026-06-04 | 2026-06-04 | 2026-06-04 |
| CVE-2026-41101 | Microsoft Word for Android OAuth-token theft via production debug flag (CVSS 7.1); patched 2026-05-12 | 2026-06-04 | 2026-06-04 | 2026-06-04 |
| CVE-2026-41102 | Microsoft PowerPoint for Android OAuth-token theft via production debug flag (CVSS 7.1); patched 2026-05-12 | 2026-06-04 | 2026-06-04 | 2026-06-04 |
| CVE-2026-42832 | Microsoft Excel for Android OAuth-token theft via setIsDebugMode(true) debug flag left in production (CVSS 7.7); patched 2026-05-12 | 2026-06-04 | 2026-06-04 | 2026-06-04 |
| CVE-2026-45247 | Mirasvit Full Page Cache Warmer (Magento 2) unauthenticated PHP object-injection RCE via CacheWarmer cookie; CISA KEV 2026-06-03, ITW from 2026-04-24; fix v1.11.12 | 2026-06-04 | 2026-06-04 | 2026-06-04 |
| CVE-2026-7195 | Progress Sitefinity CMS web-services improper input validation (CWE-20); BSI WID-SEC-2026-1783 | 2026-06-04 | 2026-06-04 | · |
| CVE-2026-7198 | Progress Sitefinity CMS OData improper input validation (CVSS 9.8, CWE-20), affects 15.4.8623-15.4.8629; BSI WID-SEC-2026-1783 | 2026-06-04 | 2026-06-04 | · |
| CVE-2026-7201 | Progress Sitefinity CMS ServiceStack web-services credential exposure (CVSS 8.8, CWE-522); BSI WID-SEC-2026-1783 | 2026-06-04 | 2026-06-04 | · |
| CVE-2026-7312 | Progress Sitefinity CMS, CWE-522 Insufficiently Protected Credentials (Sitefinity Insight credential disclosure, gated on Insight integration/non-default config); CVSS 10.0 per NVD; BSI WID-SEC-2026-1783; evaluated 2026-06-04, dropped to §7 (no fetchable vendor primary, no ITW) | 2026-06-04 | 2026-06-04 | · |
| CVE-2026-7313 | Progress Sitefinity CMS legacy-branch flaw (CVSS 8.7), affects v8.0-13.3; BSI WID-SEC-2026-1783 | 2026-06-04 | 2026-06-04 | · |
| CVE-2026-7325 | Devolutions Server LDAP coercion exposing PAM credentials (DEVO-2026-0013, CVSS 7.1); evaluated 2026-06-04, dropped to §7 (no ITW, below §2 gate) | 2026-06-04 | 2026-06-04 | · |
| CVE-2026-8181 | Burst Statistics WordPress 3.4.0-3.4.1.1 unauthenticated REST auth-bypass (is_mainwp_authenticated) → admin impersonation/rogue admin; actively exploited; fix v3.4.2 | 2026-06-04 | 2026-06-04 | 2026-06-04 |
| CVE-2026-8206 | Kirki WordPress Freeform Page Builder 6.0.0-6.0.6 unauthenticated password-reset hijack → admin account takeover; actively exploited; fix v6.0.7 | 2026-06-04 | 2026-06-04 | 2026-06-04 |
| CVE-2026-9047 | Devolutions Server MFA bypass via improper factor-key state handling (DEVO-2026-0013, CVSS 7.5); evaluated 2026-06-04, dropped to §7 (no ITW, below §2 gate) | 2026-06-04 | 2026-06-04 | · |
| CVE-2022-0492 | Linux kernel cgroup v1 release_agent container escape (missing CAP_SYS_ADMIN check); CISA KEV 2026-06-02 | 2026-06-03 | 2026-06-03 | 2026-06-03 |
| CVE-2024-21182 | Oracle WebLogic Server unauth T3/IIOP data access (CVSS 7.5); CISA KEV 2026-06-01 on active exploitation | 2026-06-02 | 2026-06-03 | 2026-06-03 |
| CVE-2025-48595 | Android Framework integer-overflow LPE (no-interaction), limited targeted exploitation; June 2026 bulletin | 2026-06-03 | 2026-06-03 | 2026-06-03 |
| CVE-2026-34926 | Trend Micro Apex One On-Premise relative path traversal fleet-wide code injection | 2026-05-22 | 2026-06-03 | 2026-05-22 |
| CVE-2026-40402 | Windows Hyper-V UAF guest-to-host escape (May 2026 Patch Tuesday); evaluated 2026-06-03, not covered (out-of-window) | 2026-06-03 | 2026-06-03 | · |
| CVE-2026-41096 | Windows DNS Client (dnsapi.dll) heap buffer overflow, RCE via malicious DNS response (CVSS 9.8, May 2026 Patch Tuesday) | 2026-05-13 | 2026-06-03 | 2026-05-13 |
| CVE-2026-5426 | Digital Knowledge KnowledgeDeliver LMS, pre-shared ASP.NET machineKey ViewState deserialization RCE; exploited as zero-day pre-2026-02-24 | 2026-05-26 | 2026-06-03 | 2026-05-26 |
| CVE-2026-42251 | KAMSOFT KS-SOMED healthcare software, hardcoded FTP credentials in update client allow malicious-update injection / supply-chain (CVSS 4.0 8.7, CERT-PL) | 2026-06-02 | 2026-06-02 | · |
| CVE-2026-44825 | Apache Solr 9.4.0-9.10.1/10.0.0, hardcoded BasicAuth template credentials allow unauthenticated remote admin (CVSS 8.1, BSI WID-SEC-2026-1740); no patch yet, manual workaround | 2026-06-02 | 2026-06-02 | 2026-06-02 |
| CVE-2026-46243 | CIFSwitch, Linux kernel CIFS/SMB-client LPE to root via forged cifs.spnego key requests (19-year-old bug; RHEL9/SLES15/Mint/Kali); dropped from 2026-06-02 brief as out-of-window + no Section 2 gate | 2026-06-02 | 2026-06-02 | · |
| CVE-2026-8732 | WP Maps Pro WordPress plugin <=6.1.0, unauthenticated admin-account creation via disclosed nonce + wp_ajax_nopriv_ handler; actively exploited (CVSS 9.8); fixed 6.1.1 | 2026-06-02 | 2026-06-02 | 2026-06-02 |
| CVE-2026-8931 | Disig Web Signer 2.0.3-2.5.3, unauthenticated RCE in Slovak eIDAS qualified-signature client (CVSS 4.0 9.4, SK-CERT); fixed 2.5.5 | 2026-06-02 | 2026-06-02 | 2026-06-02 |
| CVE-2026-46818 | Oracle E-Business Suite, May 2026 CPU critical (referenced in §7, dropped) | 2026-06-01 | 2026-06-01 | · |
| CVE-2026-46819 | Oracle E-Business Suite, May 2026 CPU critical (referenced in §7, dropped) | 2026-06-01 | 2026-06-01 | · |
| CVE-2026-46820 | Oracle E-Business Suite, May 2026 CPU critical (referenced in §7, dropped) | 2026-06-01 | 2026-06-01 | · |
| CVE-2026-46821 | Oracle E-Business Suite, May 2026 CPU critical (referenced in §7, dropped) | 2026-06-01 | 2026-06-01 | · |
| CVE-2025-62582 | Delta Electronics DIAView SCADA, unauthenticated remote database access (predecessor to CVE-2026-9642 mitigation bypass) | 2026-05-27 | 2026-05-31 | · |
| CVE-2026-26980 | Ghost CMS Content API unauthenticated SQLi (CVSS 9.4); ITW-exploited in ClickFix campaign; fixed 6.19.1 | 2026-05-25 | 2026-05-31 | 2026-05-25 |
| CVE-2026-32996 | Veeam Agent for Microsoft Windows, local privilege escalation enabling arbitrary command execution / lateral movement (CVSS 7.3) | 2026-05-29 | 2026-05-31 | 2026-05-29 |
| CVE-2026-32997 | Veeam Software Appliance (Linux); authenticated Backup Administrator can write arbitrary files (CVSS 8.6) | 2026-05-29 | 2026-05-31 | 2026-05-29 |
| CVE-2026-33384 | QuickCMS (OpenSolution) session fixation, CERT-PL; dropped (niche, CVSS 4.8) | 2026-05-31 | 2026-05-31 | · |
| CVE-2026-33386 | QuickCMS (OpenSolution) MITM-XSS via HTTP plugin fetch, CERT-PL; dropped (niche, CVSS 2.3) | 2026-05-31 | 2026-05-31 | · |
| CVE-2026-35087 | Slican PBX administrative protocol authentication bypass, attacker bypasses login by executing a specific command; CVSS 4.0: 9.3; CERT Polska disclosure 2026-05-27 | 2026-05-28 | 2026-05-31 | 2026-05-28 |
| CVE-2026-35089 | Slican PBX deterministic secure-key generation from publicly-obtainable system properties, admin credentials recoverable without auth; CVSS 4.0: 8.7; CERT Polska | 2026-05-28 | 2026-05-31 | 2026-05-28 |
| CVE-2026-35090 | Slican PBX remote management modem interface, hardcoded caller-ID bypasses admin auth and temporarily re-enables remote access when configured off; CVSS 4.0: 9.3; CERT Polska | 2026-05-28 | 2026-05-31 | 2026-05-28 |
| CVE-2026-41052 | SUSE Rancher; project-owner role can flip namespace PSA labels to privileged, enabling container-to-host escape (CVSS 8.4) | 2026-05-29 | 2026-05-31 | 2026-05-29 |
| CVE-2026-41053 | SUSE Rancher GitHub App auth, group principals granted for every team in GitHub org to any team-belonging user (CVSS 8.8) | 2026-05-29 | 2026-05-31 | 2026-05-29 |
| CVE-2026-4408 | Samba SAMR RPC server, unauthenticated shell injection via %u substitution in check password script (CVSS 10.0) | 2026-05-29 | 2026-05-31 | 2026-05-29 |
| CVE-2026-4480 | Samba print-command subsystem, unauthenticated shell injection via %J substitution; raw/classic printing only (CVSS 10.0) | 2026-05-29 | 2026-05-31 | 2026-05-29 |
| CVE-2026-44848 | Portainer CE, Docker plugin endpoints not registered in proxy authorization handler; non-admin can install/enable plugins → root host execution (CVSS 9.4) | 2026-05-29 | 2026-05-31 | 2026-05-29 |
| CVE-2026-44849 | Portainer CE Docker Swarm service API, EndpointSecuritySettings restrictions not enforced; non-admin escapes to host via privileged containers (CVSS 9.4) | 2026-05-29 | 2026-05-31 | 2026-05-29 |
| CVE-2026-44939 | SUSE Rancher cluster-import endpoint, command injection via URL-encoded newline in authImage YAML field; control-plane node RCE (CVSS 9.6) | 2026-05-29 | 2026-05-31 | 2026-05-29 |
| CVE-2026-4776 | Mautic API contact-filtering SQL injection (post-auth) | 2026-05-31 | 2026-05-31 | 2026-05-31 |
| CVE-2026-48172 | LiteSpeed User-End cPanel plugin lsws.redisAble priv-esc to root (CVSS 10.0, ITW) | 2026-05-24 | 2026-05-31 | 2026-05-24 |
| CVE-2026-4868 | GitLab CE/EE Duo AI integration, improper user identity resolution allows authenticated user to impersonate another user when triggering Duo AI workflows (CVSS 8.2) | 2026-05-29 | 2026-05-31 | 2026-05-29 |
| CVE-2026-48842 | Roundcube Webmail pre-auth SQL injection in virtuser_query plugin via preg_replace backslash escape bypass; CVSS 8.1; patched in 1.6.16 LTS / 1.7.1 | 2026-05-28 | 2026-05-31 | 2026-05-28 |
| CVE-2026-8992 | Ivanti Secure Access Client local privilege escalation | 2026-05-08 | 2026-05-31 | 2026-05-08 |
| CVE-2026-9058 | Szafir SDK (KIR) improper certificate verification / auth bypass, Polish qualified e-signature SDK; fixed v463 | 2026-05-26 | 2026-05-31 | 2026-05-26 |
| CVE-2026-9170 | IBM HTTP Server / WebSphere Application Server, pre-auth RCE via improper input validation in HTTP request parser (CVSS 9.8); NCSC.ch flagged 2026-05-28 | 2026-05-29 | 2026-05-31 | 2026-05-29 |
| CVE-2026-9312 | GitHub Enterprise Server < 3.22, unauthenticated SSRF via upload-endpoint path traversal exposes internal services and credentials (CVSS 4.0 = 9.2; GHSA-fwfp-h68w-2hcr) | 2026-05-27 | 2026-05-31 | 2026-05-27 |
| CVE-2026-9557 | Mautic Focus component SSRF (post-auth; reaches internal/cloud-metadata) | 2026-05-31 | 2026-05-31 | 2026-05-31 |
| CVE-2026-9558 | Mautic stored XSS (post-auth) | 2026-05-31 | 2026-05-31 | 2026-05-31 |
| CVE-2026-9559 | Mautic stored XSS / JS injection (post-auth) | 2026-05-31 | 2026-05-31 | 2026-05-31 |
| CVE-2026-9642 | Delta Electronics DIAView SCADA, incomplete fix / mitigation bypass of CVE-2025-62582 unauthenticated remote database access (CVSS 3.1 = 9.8; Tenable TRA-2026-44) | 2026-05-27 | 2026-05-31 | 2026-05-27 |
| CVE-2026-9808 | Mautic file inclusion / path traversal (post-auth) | 2026-05-31 | 2026-05-31 | 2026-05-31 |
| CVE-2026-9809 | Mautic path traversal / file manipulation (post-auth) | 2026-05-31 | 2026-05-31 | 2026-05-31 |
| CVE-2026-9811 | Mautic JavaScript code injection (post-auth) | 2026-05-31 | 2026-05-31 | 2026-05-31 |
| CVE-2024-39930 | Gogs prior argument-injection variant (referenced in Rapid7 2026-05-29 disclosure as same-class predecessor) | 2026-05-29 | 2026-05-29 | · |
| CVE-2026-1402 | GitLab CE/EE, Wiki DoS via insufficient validation of malformed markup (CVSS 6.5) | 2026-05-29 | 2026-05-29 | 2026-05-29 |
| CVE-2026-2601 | GitLab EE; Developer-role users can access deployment data (pipeline environment variables, deployment keys) via missing authorization checks (CVSS 4.3) | 2026-05-29 | 2026-05-29 | 2026-05-29 |
| CVE-2026-26194 | Gogs argument-injection RCE (CVE id claimed by S3 sub-agent, unverified against authoritative NVD entry; Rapid7 publication states no CVE assigned at disclosure; deferred to next-run verification) | 2026-05-29 | 2026-05-29 | · |
| CVE-2026-2710 | GitLab CE/EE, seventh CVE in 19.0.1 / 18.11.4 / 18.10.7 patch release (defender-relevance not enumerated; left to vendor page) | 2026-05-29 | 2026-05-29 | · |
| CVE-2026-5296 | GitLab EE; Developer-role users can bypass group-level flow restrictions when foundational flows enabled (CVSS 4.3) | 2026-05-29 | 2026-05-29 | 2026-05-29 |
| CVE-2026-6713 | GitLab CE/EE, unauthenticated enumeration of private project paths via API (CVSS 5.3) | 2026-05-29 | 2026-05-29 | 2026-05-29 |
| CVE-2026-8716 | GitLab CE/EE; Authenticated users can access CI data from unintended reference types via incorrect reference resolution (CVSS 4.3) | 2026-05-29 | 2026-05-29 | 2026-05-29 |
| CVE-2026-8834 | IBM HTTP Server Administration Server, heap-based buffer overflow (CVSS 8.0) | 2026-05-29 | 2026-05-29 | · |
| CVE-2026-8850 | IBM HTTP Server mod_ibm_upload, DoS via NULL pointer dereference (CVSS 7.5) | 2026-05-29 | 2026-05-29 | · |
| CVE-2026-8854 | IBM HTTP Server mod_mem_cache, DoS via expired pointer dereference (CVSS 7.5) | 2026-05-29 | 2026-05-29 | · |
| CVE-2026-8855 | IBM HTTP Server, RCE in TLS mutual-authentication configurations (CVSS 8.1) | 2026-05-29 | 2026-05-29 | · |
| CVE-2026-8856 | IBM HTTP Server, DoS via uncontrolled resource consumption (CVSS 7.7) | 2026-05-29 | 2026-05-29 | · |
| CVE-2026-27771 | Gitea container registry access-control failure, private repo container images unauthenticatedly pullable across all versions < 1.26.2 (4-year exposure window); Forgejo confirmed affected; § 7 drop 2026-05-28 | 2026-05-28 | 2026-05-28 | · |
| CVE-2026-45321 | TanStack Router npm credential-stealing payload, exfiltrated Nx contributor GitHub CLI OAuth token (precursor to CVE-2026-48027 Nx Console compromise); CISA KEV 2026-05-27 | 2026-05-22 | 2026-05-28 | 2026-05-28 |
| CVE-2026-48027 | Nx Console v18.95.0 VS Code extension supply-chain compromise, credential-stealing payload harvested 1Password, Claude Code config, npm, GitHub, AWS creds; CISA KEV 2026-05-27 | 2026-05-28 | 2026-05-28 | 2026-05-28 |
| CVE-2026-48843 | Roundcube Webmail CSS sanitisation failure via SVG animate attributeName=style, info disclosure / SSRF in HTML email rendering; patched in 1.6.16 LTS / 1.7.1 | 2026-05-28 | 2026-05-28 | 2026-05-28 |
| CVE-2026-48844 | Roundcube Webmail code injection via LDAP autovalues option; arbitrary PHP code evaluation when option is configured; patched in 1.6.16 LTS / 1.7.1 | 2026-05-28 | 2026-05-28 | 2026-05-28 |
| CVE-2026-48848 | Roundcube Webmail HTML sanitisation bypass via SVG document permitting CSS injection; patched in 1.6.16 LTS / 1.7.1 | 2026-05-28 | 2026-05-28 | 2026-05-28 |
| CVE-2026-8398 | DAEMON Tools Lite signed-build trojanisation (12.5.0.2421–12.5.0.2434) via Disc Soft Limited build infrastructure; CISA KEV 2026-05-27 | 2026-05-28 | 2026-05-28 | 2026-05-28 |
| CVE-2026-9256 | NGINX ngx_http_rewrite_module heap buffer overflow, out-of-bounds write in worker process memory pool via overlapping regex capture groups; CVSS v3.1 8.1 / v4.0 9.2; exploitation attempts per NCSC-NL; § 7 drop (primary 2026-05-22 out-of-window) | 2026-05-24 | 2026-05-28 | · |
| CVE-2026-44895 | yoda-digital mcp-gitlab-server < 0.6.0, no-auth SSE RPC endpoint bound to 0.0.0.0 with wildcard CORS exposes operator GitLab PAT (CVSS 4.0 = 9.2; GHSA-8jr5-6gvj-rfpf); noted in § 7 (niche package) | 2026-05-27 | 2026-05-27 | · |
| CVE-2024-12802 | SonicWall Gen6 SSL-VPN MFA bypass via UPN vs SAM account-name split; Akira-linked actors exploited Feb-Mar 2026; firmware update insufficient without 6-step LDAP reconfiguration | 2026-05-21 | 2026-05-25 | 2026-05-21 |
| CVE-2025-32433 | Erlang SSH RCE (Cisco context), confirmed by Check Point Research as initial-access CVE for The Gentlemen RaaS | 2026-05-17 | 2026-05-25 | · |
| CVE-2025-34291 | Langflow CORS misconfiguration + SameSite=None refresh token theft | 2026-05-22 | 2026-05-25 | 2026-05-22 |
| CVE-2026-0300 | Palo Alto PAN-OS Captive Portal unauthenticated root RCE (CVSS 9.3, ITW, KEV deadline 2026-05-09) | 2026-05-07 | 2026-05-25 | 2026-05-18 +2 more |
| CVE-2026-20223 | Cisco Secure Workload internal REST API zero-auth Site Admin CVSS 10.0 | 2026-05-22 | 2026-05-25 | 2026-05-22 |
| CVE-2026-2743 | SEPPmail Secure E-Mail Gateway, pre-auth path traversal in LFT /v1/file.app → arbitrary file write as nobody → RCE via /etc/syslog.conf overwrite | 2026-05-09 | 2026-05-25 | 2026-05-09 |
| CVE-2026-31635 | Linux kernel RxGK rxgk_decrypt_skb() page-cache write (missing COW guard), DirtyDecrypt LPE; affects Fedora / Arch / openSUSE Tumbleweed (CONFIG_RXGK=y) | 2026-05-20 | 2026-05-25 | 2026-05-20 |
| CVE-2026-41091 | Microsoft Defender Malware Protection Engine, link-following EoP to SYSTEM (CWE-59); Engine ≤ 1.1.26030.3008; actively exploited | 2026-05-20 | 2026-05-25 | 2026-05-20 |
| CVE-2026-42096 | Sparx Pro Cloud Server, authenticated SQL injection via database API endpoint; PCS ≤ 6.1 | 2026-05-20 | 2026-05-25 | 2026-05-20 |
| CVE-2026-42097 | Sparx Pro Cloud Server, pre-auth bypass via model-parameter omission in POST binary blob → unauthenticated SQL query execution; CVSS4 9.3 | 2026-05-20 | 2026-05-25 | 2026-05-20 |
| CVE-2026-42098 | Sparx Enterprise Architect ≤ 17.1, client-side RBAC bypass via EA client binary patch (CWE-603); CVSS4 8.7 | 2026-05-20 | 2026-05-25 | 2026-05-20 |
| CVE-2026-42099 | Sparx Pro Cloud Server WebEA, race condition in /data_api/dl_internal_artifact.php → RCE in web-server context (CWE-362); CVSS4 7.7 | 2026-05-20 | 2026-05-25 | 2026-05-20 |
| CVE-2026-42100 | Sparx Pro Cloud Server, malformed SQL crash (DoS); CWE-835 | 2026-05-20 | 2026-05-25 | 2026-05-20 |
| CVE-2026-42231 | n8n self-hosted automation, xml2js prototype pollution (CWE-1321), root of authenticated-to-RCE chain via Git node SSH | 2026-05-19 | 2026-05-25 | 2026-05-19 |
| CVE-2026-42822 | Microsoft Azure Local Disconnected Operations (ALDO), CVSS 10.0 unauthenticated network elevation-of-privilege; MSRC Exploitation More Likely | 2026-05-21 | 2026-05-25 | 2026-05-21 |
| CVE-2026-43997 | vm2 Node.js sandbox, host-object access via BaseHandler.getPrototypeOf trap; sandbox escape to host context; CVSS 10.0; patched 3.11.0 | 2026-05-20 | 2026-05-25 | 2026-05-20 |
| CVE-2026-45498 | Microsoft Defender Antivirus local DoS, exploited alongside CVE-2026-41091 in combined out-of-band engine update 4.18.26040.7 | 2026-05-20 | 2026-05-25 | 2026-05-20 |
| CVE-2026-45584 | Microsoft Defender Malware Protection Engine, heap-based buffer overflow over network → unauthenticated RCE in Defender process context; CVSS 8.1 | 2026-05-20 | 2026-05-25 | 2026-05-20 |
| CVE-2026-45829 | ChromaDB Python FastAPI server pre-auth RCE via embedding-function model loading before auth check (CVSS 4.0 = 10.0; v1.5.9 unpatched at disclosure) | 2026-05-21 | 2026-05-25 | 2026-05-21 |
| CVE-2026-7507 | Keycloak OIDC login flow session fixation enabling account takeover (Keycloak 26.6.2; BSI WID-SEC-2026-1612 HIGH) | 2026-05-21 | 2026-05-25 | 2026-05-21 |
| CVE-2026-9082 | Drupal core highly-critical pre-auth SQL injection in database abstraction API on PostgreSQL backends; CISA KEV-listed 2026-05-22 (SA-CORE-2026-004) | 2026-05-20 | 2026-05-25 | 2026-05-20 |
| CVE-2025-9086 | Stormshield SNS remote DoS (CERTFR-2026-AVI-0631); dropped from §2, mentioned in §7 | 2026-05-24 | 2026-05-24 | · |
| CVE-2026-33278 | NLnet Labs Unbound DNSSEC validator UAF (CVSS 9.8), fixed 1.25.1 | 2026-05-24 | 2026-05-24 | 2026-05-24 |
| CVE-2026-3593 | ISC BIND 9 DoH use-after-free (CVSS 7.4), fixed 9.20.23 | 2026-05-24 | 2026-05-24 | 2026-05-24 |
| CVE-2026-37979 | Keycloak OIDC token introspection endpoint does not enforce audience restriction; lightweight access tokens leak claims cross-client (Keycloak 26.6.2) | 2026-05-21 | 2026-05-24 | 2026-05-21 |
| CVE-2026-37982 | Keycloak execute-actions token replay enabling unauthorised WebAuthn / FIDO2 credential enrollment on victim account (Keycloak 26.6.2) | 2026-05-21 | 2026-05-24 | 2026-05-21 |
| CVE-2026-42944 | NLnet Labs Unbound heap overflow, default-config (CVSS 8.6), fixed 1.25.1 | 2026-05-24 | 2026-05-24 | 2026-05-24 |
| CVE-2026-4630 | Keycloak Authorization Services Protection API cross-realm IDOR allowing realm-A authenticated attacker to access realm-B resources (Keycloak 26.6.2) | 2026-05-21 | 2026-05-24 | 2026-05-21 |
| CVE-2026-46333 | ssh-keysign-pwn; 9-year ptrace race in Linux kernel __ptrace_may_access() reaches root + SSH host-key exfiltration; four public Qualys exploits on default major distros | 2026-05-23 | 2026-05-24 | 2026-05-23 |
| CVE-2026-5946 | ISC BIND 9 non-Internet CLASS DoS (CVSS 7.5), fixed 9.18.49/9.20.23 | 2026-05-24 | 2026-05-24 | 2026-05-24 |
| CVE-2019-13272 | Linux kernel ptrace credential-window LPE (Jann Horn, 2019), historical predecessor cited as background in 2026-05-23 CVE-2026-46333 deep dive | 2026-05-23 | 2026-05-23 | · |
| CVE-2021-4034 | PwnKit, polkit pkexec local root (Qualys, 2022), historical reference cited in 2026-05-23 CVE-2026-46333 deep dive as functional-equivalent outcome | 2026-05-23 | 2026-05-23 | · |
| CVE-2023-4911 | Looney Tunables, glibc ld.so local privilege escalation (Qualys, 2023), historical reference cited in 2026-05-23 CVE-2026-46333 deep dive as disclosure-pattern precedent | 2026-05-23 | 2026-05-23 | · |
| CVE-2026-23652 | Microsoft Azure CVSS 10.0 cluster, server-side mitigated, no customer action required (MSRC May 2026) | 2026-05-22 | 2026-05-22 | · |
| CVE-2026-40411 | Microsoft Azure CVSS 10.0 cluster, server-side mitigated, no customer action required (MSRC May 2026) | 2026-05-22 | 2026-05-22 | · |
| CVE-2026-42823 | Microsoft Azure CVSS 10.0 cluster, server-side mitigated, no customer action required (MSRC May 2026) | 2026-05-22 | 2026-05-22 | · |
| CVE-2026-42901 | Microsoft Entra ID / Azure CVSS 10.0 cluster, server-side mitigated, no customer action required (MSRC May 2026) | 2026-05-22 | 2026-05-22 | · |
| CVE-2026-47280 | Microsoft Entra ID / Azure CVSS 10.0 cluster, server-side mitigated, no customer action required (MSRC May 2026) | 2026-05-22 | 2026-05-22 | · |
| CVE-2017-7692 | SquirrelMail post-auth RCE, used by Webworm against Serbian government targets per ESET 2026-05-20 (initial-access probe after credential theft) | 2026-05-21 | 2026-05-21 | · |
| CVE-2026-37978 | Keycloak admin evaluate-scopes endpoint cross-role PII leakage bypassing user-view permissions (Keycloak 26.6.2) | 2026-05-21 | 2026-05-21 | 2026-05-21 |
| CVE-2026-6856 | Keycloak WebAuthn packed self-attestation acceptable-AAGUID policy bypass enabling enrolment of hardware tokens outside policy (Keycloak 26.6.2) | 2026-05-21 | 2026-05-21 | 2026-05-21 |
| CVE-2026-26083 | Fortinet FortiSandbox unauthenticated RCE in Web UI (CWE-862, CVSS 9.1 vendor / 9.8 NVD), pre-auth, patch in 4.4.9 / 5.0.2 / Cloud 5.0.6; Cloud 23/24 require migration | 2026-05-13 | 2026-05-20 | 2026-05-13 |
| CVE-2026-26956 | vm2 Node.js sandbox, symbol-to-string coercion TypeError sandbox bypass; patched 3.10.5 | 2026-05-20 | 2026-05-20 | 2026-05-20 |
| CVE-2026-43999 | vm2 NodeVM allow-list bypass, Module._load() reachable when child_process is explicitly permitted → OS command execution; CVSS 9.9 | 2026-05-20 | 2026-05-20 | 2026-05-20 |
| CVE-2026-44005 | vm2 prototype pollution via attacker-controlled JS; CVSS 10.0; affects 3.9.6 – 3.10.5; patched 3.11.0 | 2026-05-20 | 2026-05-20 | 2026-05-20 |
| CVE-2026-44006 | vm2 code injection via BaseHandler.getPrototypeOf; CVSS 10.0; patched 3.11.0 | 2026-05-20 | 2026-05-20 | 2026-05-20 |
| CVE-2026-44008 | vm2 null-proto exception exploitation; CVSS 9.8; affects ≤ 3.11.1; patched 3.11.2 | 2026-05-20 | 2026-05-20 | 2026-05-20 |
| CVE-2026-44009 | vm2 neutralizeArraySpeciesBatch() bypass via null-proto exception; CVSS 9.8; affects ≤ 3.11.1; patched 3.11.2 | 2026-05-20 | 2026-05-20 | 2026-05-20 |
| CVE-2026-44128 | SEPPmail Secure Email Gateway, unauthenticated RCE via exposed GINAv2 test endpoints (CVSS 9.3) | 2026-05-09 | 2026-05-20 | 2026-05-09 |
| CVE-2026-44277 | Fortinet FortiAuthenticator unauthenticated RCE in management interface (CWE-284, CVSS 9.8), pre-auth, patch in 6.5.7 / 6.6.9 / 8.0.3 | 2026-05-13 | 2026-05-20 | 2026-05-13 |
| CVE-2026-45185 | Exim 4.97–4.99.2 GnuTLS builds, BDAT/CHUNKING use-after-free (Dead.Letter), pre-auth RCE (CVSS 9.8, ENISA EUVD critical); fixed in Exim 4.99.3 | 2026-05-13 | 2026-05-20 | 2026-05-13 |
| CVE-2026-41702 | VMware Fusion 25H2 (macOS), TOCTOU SETUID race condition LPE (CVSS 7.8); dropped from § 2 in 2026-05-19 brief (did not clear inclusion gates) | 2026-05-19 | 2026-05-19 | · |
| CVE-2026-42232 | n8n HTTP Request Node injection, companion amplifier to CVE-2026-42231 prototype-pollution chain | 2026-05-19 | 2026-05-19 | 2026-05-19 |
| CVE-2026-44789 | n8n XML Node injection, companion amplifier to CVE-2026-42231 prototype-pollution chain | 2026-05-19 | 2026-05-19 | 2026-05-19 |
| CVE-2026-44790 | n8n Git node SSH chain, terminal sink of CVE-2026-42231 prototype-pollution to RCE | 2026-05-19 | 2026-05-19 | 2026-05-19 |
| CVE-2026-44791 | n8n XML Node injection, companion amplifier to CVE-2026-42231 prototype-pollution chain | 2026-05-19 | 2026-05-19 | 2026-05-19 |
| CVE-2026-46351 | BigBlueButton bbb-web < 3.0.21, insecure sessionToken generation (CWE-330) enables session hijack | 2026-05-19 | 2026-05-19 | 2026-05-19 |
| CVE-2026-46353 | BigBlueButton bbb-web < 3.0.21, presentationUploadExternalUrl API checksum bypass (CWE-284) | 2026-05-19 | 2026-05-19 | 2026-05-19 |
| CVE-2026-46404 | BigBlueButton bbb-web < 3.0.23, SSRF in presentation URL validation (CWE-918) | 2026-05-19 | 2026-05-19 | 2026-05-19 |
| CVE-2023-33241 | Fireblocks GG18/GG20 Paillier missing-ZK-proof flaw (TSSHOCK class; cited as background-class for THORChain 2026-05-15 GG20 TSS exploit) | 2026-05-18 | 2026-05-18 | · |
| CVE-2025-54518 | AMD-SB-7052, Zen 2 µop-cache corruption / SoC isolation LPE (CVSS 7.3 CVSS 4.0) | 2026-05-16 | 2026-05-18 | 2026-05-16 |
| CVE-2026-34260 | SAP S/4HANA Enterprise Search ABAP, authenticated SQL injection in SAP_BASIS 751–758 / 816 (CVSS 9.6) | 2026-05-13 | 2026-05-18 | 2026-05-13 |
| CVE-2026-34263 | SAP Commerce Cloud, unauthenticated arbitrary code execution via Spring Security misordering on cloud-config endpoint (CVSS 9.6, SAP Note 3733064) | 2026-05-13 | 2026-05-18 | 2026-05-13 |
| CVE-2026-41103 | Microsoft SSO Plugin for Jira/Confluence, unauthenticated Entra ID credential forgery (CVSS 9.1, More Likely exploitation) | 2026-05-13 | 2026-05-18 | 2026-05-13 |
| CVE-2026-41225 | F5 BIG-IP iControl REST Manager-role authenticated RCE (May 2026 Quarterly Notification, CVSS 9.1) | 2026-05-17 | 2026-05-18 | 2026-05-17 |
| CVE-2026-41553 | DHTMLX PDF Export Module, unauthenticated server-side JavaScript injection RCE (CVSS 4.0 score 10.0) | 2026-05-17 | 2026-05-18 | 2026-05-17 |
| CVE-2026-44088 | KIR SzafirHost, JAR zip-polyglot signature-verification bypass enabling RCE in Polish qualified e-signature browser helper (CVSS 8.6) | 2026-05-17 | 2026-05-18 | 2026-05-17 |
| CVE-2026-44112 | OpenClaw / Clawdbot, OpenShell sandbox TOCTOU write escape (CVSS 9.6, Claw Chain) | 2026-05-16 | 2026-05-18 | 2026-05-16 |
| CVE-2026-45691 | Nextcloud Server/Enterprise Server 2FA bypass via WebDAV pre-authenticated session token reuse | 2026-05-15 | 2026-05-18 | · |
| CVE-2026-45793 | PHP Composer GitHub Actions token disclosure in error messages (fixed in 2.9.8 / 2.2.28) | 2026-05-15 | 2026-05-18 | · |
| CVE-2026-7182 | DHTMLX Diagram export module, path traversal (CVSS 4.0 score 9.2) | 2026-05-17 | 2026-05-18 | 2026-05-17 |
| CVE-2026-8043 | Ivanti Xtraction < 2026.2 external control of file name/path (CWE-73, CVSS 9.6), arbitrary file read + HTML write to web tree; auth required | 2026-05-14 | 2026-05-18 | 2026-05-14 |
| CVE-2023-38831 | WinRAR file-extension spoofing arbitrary code execution (cited as veteran exploit by Kaspersky Q1 2026 report) | 2026-05-10 | 2026-05-17 | · |
| CVE-2025-33073 | RelayKing NTLM relay, post-access primitive used by The Gentlemen RaaS | 2026-05-17 | 2026-05-17 | · |
| CVE-2025-69690 | Netgate pfSense Community Edition authenticated root RCE, vendor refuses to fix | 2026-05-11 | 2026-05-17 | 2026-05-11 |
| CVE-2025-69691 | Netgate pfSense Community Edition authenticated root RCE companion to CVE-2025-69690, vendor refuses to fix | 2026-05-11 | 2026-05-17 | 2026-05-11 |
| CVE-2026-20122 | Cisco Catalyst SD-WAN companion CVE (exploited since March 2026) | 2026-05-15 | 2026-05-17 | · |
| CVE-2026-20128 | Cisco Catalyst SD-WAN companion CVE (exploited since March 2026) | 2026-05-15 | 2026-05-17 | · |
| CVE-2026-20133 | Cisco Catalyst SD-WAN companion CVE (exploited since March 2026) | 2026-05-15 | 2026-05-17 | · |
| CVE-2026-33634 | Checkmarx Jenkins AST plugin backdoor (TeamPCP/UNC6780 supply-chain compromise, SANDCLOCK credential stealer, CVSS 9.4) | 2026-05-12 | 2026-05-17 | 2026-05-12 |
| CVE-2026-34176 | F5 BIG-IP privilege escalation via misconfigured permissions (May 2026 Quarterly, CVSS 8.7) | 2026-05-17 | 2026-05-17 | · |
| CVE-2026-40061 | F5 BIG-IP privilege escalation via misconfigured permissions (May 2026 Quarterly, CVSS 8.7) | 2026-05-17 | 2026-05-17 | · |
| CVE-2026-40631 | F5 BIG-IP privilege escalation via misconfigured permissions (May 2026 Quarterly, CVSS 8.7) | 2026-05-17 | 2026-05-17 | · |
| CVE-2026-40698 | F5 BIG-IP SSH password exposure in iControl REST audit logs (May 2026 Quarterly, CVSS 8.7) | 2026-05-17 | 2026-05-17 | · |
| CVE-2026-41552 | DHTMLX PDF Export Module, path traversal via src attribute (CVSS 4.0 score 9.2) | 2026-05-17 | 2026-05-17 | 2026-05-17 |
| CVE-2026-41953 | F5 BIG-IP iControl REST command injection (May 2026 Quarterly, CVSS 8.7) | 2026-05-17 | 2026-05-17 | · |
| CVE-2026-42406 | F5 BIG-IP iControl REST command injection (May 2026 Quarterly, CVSS 8.7) | 2026-05-17 | 2026-05-17 | · |
| CVE-2026-42898 | Microsoft Dynamics 365 On-Premises, authenticated code injection with scope change (CVSS 9.9, May 2026 Patch Tuesday) | 2026-05-13 | 2026-05-17 | 2026-05-13 |
| CVE-2026-42924 | F5 BIG-IP iControl REST command injection (May 2026 Quarterly, CVSS 8.7) | 2026-05-17 | 2026-05-17 | · |
| CVE-2026-42930 | F5 BIG-IP iControl REST command injection (May 2026 Quarterly, CVSS 8.7) | 2026-05-17 | 2026-05-17 | · |
| CVE-2026-44113 | OpenClaw / Clawdbot, TOCTOU read escape / file disclosure (CVSS 7.7, Claw Chain) | 2026-05-16 | 2026-05-17 | 2026-05-16 |
| CVE-2026-44115 | OpenClaw / Clawdbot, command-parser allowlist bypass (CVSS 8.8, Claw Chain) | 2026-05-16 | 2026-05-17 | 2026-05-16 |
| CVE-2026-44118 | OpenClaw / Clawdbot, MCP loopback senderIsOwner privilege escalation (CVSS 7.8, Claw Chain) | 2026-05-16 | 2026-05-17 | 2026-05-16 |
| CVE-2026-4670 | Progress MOVEit Automation unauthenticated authentication bypass (CVSS 9.8) | 2026-05-06 | 2026-05-17 | · |
| CVE-2026-6073 | GitLab CE/EE, stored XSS in analytics dashboards (CVSS 8.7); cited as dropped from § 2 | 2026-05-17 | 2026-05-17 | · |
| CVE-2026-6722 | PHP SOAP extension UAF in SOAP_GLOBAL(ref_map) (with companions CVE-2026-7261, CVE-2026-7262); patched in PHP 8.4.8 / 8.3.22 / 8.2.30 | 2026-05-11 | 2026-05-17 | 2026-05-11 |
| CVE-2026-7261 | PHP SOAP companion to CVE-2026-6722; patched 2026-05-08 | 2026-05-11 | 2026-05-17 | 2026-05-11 |
| CVE-2026-7262 | PHP SOAP companion to CVE-2026-6722; patched 2026-05-08 | 2026-05-11 | 2026-05-17 | 2026-05-11 |
| CVE-2026-7377 | GitLab CE/EE, stored XSS in container registry virtual registry upstreams (CVSS 8.7); cited as dropped from § 2 | 2026-05-17 | 2026-05-17 | · |
| CVE-2026-7481 | GitLab CE/EE, stored XSS in Jira integration (CVSS 8.7); cited as dropped from § 2 | 2026-05-17 | 2026-05-17 | · |
| CVE-2021-34473 | Microsoft Exchange Server pre-auth RCE (ProxyShell), cited in 2026-05-16 § 5 deep dive Background | 2026-05-16 | 2026-05-16 | · |
| CVE-2023-42793 | JetBrains TeamCity authentication bypass, cited in 2026-05-16 § 3 SentinelOne CI/CD subversion case study | 2026-05-16 | 2026-05-16 | · |
| CVE-2022-20775 | Cisco SD-WAN local privilege escalation (UAT-8616 version-downgrade re-exploitation technique) | 2026-05-15 | 2026-05-15 | · |
| CVE-2026-33825 | BlueHammer, Windows zero-day by Nightmare Eclipse (confirmed ITW by Huntress, April 2026) | 2026-05-15 | 2026-05-15 | · |
| CVE-2026-45690 | Nextcloud Server SQL injection in column-type parameter (Moderate) | 2026-05-15 | 2026-05-15 | · |
| CVE-2026-8511 | Google Chrome CVE (mentioned in recency-dropped items, 2026-05-12) | 2026-05-15 | 2026-05-15 | · |
| CVE-2026-8580 | Google Chrome CVE (mentioned in recency-dropped items, 2026-05-12) | 2026-05-15 | 2026-05-15 | · |
| CVE-2022-41040 | Microsoft Exchange Server SSRF (ProxyNotShell), cited as initial-access vector in 2026-05-14 FamousSparrow deep dive; chained with CVE-2022-41082 | 2026-05-14 | 2026-05-14 | · |
| CVE-2022-41082 | Microsoft Exchange Server PowerShell remoting deserialization RCE (ProxyNotShell), cited as initial-access vector in 2026-05-14 FamousSparrow deep dive; chained with CVE-2022-41040 | 2026-05-14 | 2026-05-14 | · |
| CVE-2026-23819 | HPE ArubaOS AOS-10 stored XSS in web management interface (CVSS 8.8); referenced in 2026-05-14 § 7 drop note (gate not cleared) | 2026-05-14 | 2026-05-14 | · |
| CVE-2026-44211 | Cline kanban npm package cross-origin WebSocket hijack (CVSS 9.6); referenced in 2026-05-14 § 7 drop note (out-of-window) | 2026-05-14 | 2026-05-14 | · |
| CVE-2026-34259 | SAP Forecasting & Replenishment, authenticated OS-command injection (CVSS 8.2, SAP May 2026 patch day) | 2026-05-13 | 2026-05-13 | · |
| CVE-2026-40361 | Microsoft Word Preview Pane RCE (CVSS 8.4, More Likely exploitation, May 2026 Patch Tuesday) | 2026-05-13 | 2026-05-13 | · |
| CVE-2026-40364 | Microsoft Word Preview Pane RCE (CVSS 8.4, More Likely exploitation, May 2026 Patch Tuesday) | 2026-05-13 | 2026-05-13 | · |
| CVE-2026-40366 | Microsoft Word Preview Pane RCE (CVSS 8.4, May 2026 Patch Tuesday) | 2026-05-13 | 2026-05-13 | · |
| CVE-2026-40367 | Microsoft Word Preview Pane RCE (CVSS 8.4, May 2026 Patch Tuesday) | 2026-05-13 | 2026-05-13 | · |
| CVE-2026-40478 | Earlier Thymeleaf CVE referenced in § 7 disambiguating the dropped Thymeleaf item; CSO Online article 2026-04-17 covered this CVE rather than CVE-2026-41901 | 2026-05-13 | 2026-05-13 | · |
| CVE-2026-41901 | Thymeleaf SSTI sandbox bypass, referenced in § 7 explaining out-of-window drop (GHSA published 2026-04-29) | 2026-05-13 | 2026-05-13 | · |
| CVE-2024-1708 | ConnectWise ScreenConnect path traversal, chained with CVE-2024-1709 by Kimsuky/Storm-1175; KEV deadline 2026-05-12 (out-of-window per § 7 of 2026-05-12 brief) | 2026-05-12 | 2026-05-12 | · |
| CVE-2024-1709 | ConnectWise ScreenConnect authentication bypass (CVSS 10.0), chained with CVE-2024-1708; cited as 2026-05-12 drop | 2026-05-12 | 2026-05-12 | · |
| CVE-2026-0073 | Android adbd wireless ADB authentication bypass (CVSS 8.8, adjacent-network, public PoC 2026-05-11), § 2 gate not cleared | 2026-05-12 | 2026-05-12 | · |
| CVE-2026-5786 | Ivanti EPMM remote authenticated → administrative-access via improper access control (CVSS 8.8, May 2026 update) | 2026-05-08 | 2026-05-12 | 2026-05-08 |
| CVE-2026-5787 | Ivanti EPMM on-prem improper certificate validation → pre-auth Sentry impersonation (CVSS 9.1, ITW, KEV chain) | 2026-05-08 | 2026-05-12 | 2026-05-08 |
| CVE-2026-5788 | Ivanti EPMM unauthenticated arbitrary method invocation (CVSS 7.0, May 2026 update) | 2026-05-08 | 2026-05-12 | 2026-05-08 |
| CVE-2026-6973 | Ivanti EPMM on-prem admin API improper input validation → RCE (CVSS 7.2, ITW, KEV deadline 2026-05-10) | 2026-05-08 | 2026-05-12 | 2026-05-08 |
| CVE-2026-7821 | Ivanti EPMM; fourth companion CVE in May 2026 EPMM update (high-severity per BleepingComputer / SecurityWeek) | 2026-05-08 | 2026-05-12 | 2026-05-08 |
| CVE-2017-11882 | Microsoft Office Equation Editor RCE (cited as veteran exploit by Kaspersky Q1 2026 exploit report) | 2026-05-10 | 2026-05-10 | · |
| CVE-2018-0802 | Microsoft Office Equation Editor RCE (cited as largest-share detected exploit by Kaspersky Q1 2026 report) | 2026-05-10 | 2026-05-10 | · |
| CVE-2023-35078 | Ivanti EPMM pre-auth API access (2023, exploited by APT29; cited as historical precedent in 2026-05-08 deep dive) | 2026-05-08 | 2026-05-10 | · |
| CVE-2024-57726 | SimpleHelp RMM unauthenticated privilege escalation (ITW) | 2026-05-07 | 2026-05-10 | · |
| CVE-2024-57728 | SimpleHelp RMM path traversal, unauthenticated file download (ITW) | 2026-05-07 | 2026-05-10 | · |
| CVE-2024-7399 | Samsung MagicINFO 9 Server unauthenticated arbitrary file write → RCE (CVSS 8.8, ITW) | 2026-05-07 | 2026-05-10 | · |
| CVE-2025-0283 | Ivanti EPMM critical (January 2025, state-actor exploitation; cited as historical precedent in 2026-05-08 deep dive) | 2026-05-08 | 2026-05-10 | · |
| CVE-2025-29927 | Next.js middleware authorisation bypass via crafted header, weaponised by PCPJack worm | 2026-05-10 | 2026-05-10 | · |
| CVE-2025-48703 | CentOS Web Panel FileManager shell injection, weaponised by PCPJack worm | 2026-05-10 | 2026-05-10 | · |
| CVE-2025-68670 | xrdp pre-authentication stack buffer overflow → RCE | 2026-05-09 | 2026-05-10 | 2026-05-09 |
| CVE-2025-9501 | W3 Total Cache PHP injection via mfunc comment processor, weaponised by PCPJack worm | 2026-05-10 | 2026-05-10 | · |
| CVE-2026-1281 | Ivanti EPMM January 2026 critical, historical precedent cited in 2026-05-09 Ivanti UPDATE | 2026-05-09 | 2026-05-10 | · |
| CVE-2026-1340 | Ivanti EPMM January 2026 critical companion, historical precedent cited in 2026-05-09 Ivanti UPDATE | 2026-05-09 | 2026-05-10 | · |
| CVE-2026-1357 | WPVivid Backup unauthenticated file upload, weaponised by PCPJack worm | 2026-05-10 | 2026-05-10 | · |
| CVE-2026-20034 | Cisco Unity Connection authenticated RCE in management API (CVSS 8.8, NATO NCSC discovery; logged § 7, dropped from § 2, gate not cleared) | 2026-05-10 | 2026-05-10 | · |
| CVE-2026-20035 | Cisco Unity Connection unauthenticated SSRF in default-enabled Web Inbox (CVSS 7.2; logged § 7, dropped from § 2, gate not cleared) | 2026-05-10 | 2026-05-10 | · |
| CVE-2026-21510 | Windows Shell LNK exploit predecessor, APT28 weaponised against Ukraine and EU; February 2026 patch left CVE-2026-32202 residual | 2026-05-10 | 2026-05-10 | · |
| CVE-2026-23918 | Apache HTTP Server 2.4.66 HTTP/2 double-free, DoS and potential RCE (CVSS 8.8) | 2026-05-06 | 2026-05-10 | · |
| CVE-2026-23926 | Zabbix frontend stored XSS in map element labels (CVSS 6.1) | 2026-05-07 | 2026-05-10 | · |
| CVE-2026-23927 | Zabbix API confidentiality; unprivileged user can read admin host data (CVSS 5.3) | 2026-05-07 | 2026-05-10 | · |
| CVE-2026-23928 | Zabbix frontend reflected XSS in host-group filter (CVSS 6.1) | 2026-05-07 | 2026-05-10 | · |
| CVE-2026-25592 | Microsoft Semantic Kernel .NET SDK, unintended [KernelFunction] on SessionsPythonPlugin Download/UploadFileAsync → arbitrary file write → sandbox escape (CVSS 9.9) | 2026-05-10 | 2026-05-10 | 2026-05-10 |
| CVE-2026-26030 | Microsoft Semantic Kernel Python SDK, prompt-injection-to-RCE via InMemoryVectorStore filter (CVSS 9.9, PoC public) | 2026-05-10 | 2026-05-10 | 2026-05-10 |
| CVE-2026-28780 | Apache httpd mod_proxy_ajp heap overflow → remote crash / potential RCE (CVSS 7.5) | 2026-05-07 | 2026-05-10 | · |
| CVE-2026-29201 | cPanel/WHM CVE cluster, dropped from § 3 (embargoed, gate not cleared) | 2026-05-09 | 2026-05-10 | 2026-05-10 |
| CVE-2026-29202 | cPanel/WHM CVE cluster, dropped from § 3 (embargoed, gate not cleared) | 2026-05-09 | 2026-05-10 | 2026-05-10 |
| CVE-2026-29203 | cPanel/WHM unsafe symlink handling, chmod abuse on arbitrary files (CVSS 8.8, second emergency TSR) | 2026-05-09 | 2026-05-10 | 2026-05-10 |
| CVE-2026-32202 | Windows Shell protection mechanism failure → NTLM coercion / spoofing (CVSS 4.3, APT28 ITW, KEV deadline 2026-05-12) | 2026-05-08 | 2026-05-10 | 2026-05-08 |
| CVE-2026-32305 | Traefik proxy mTLS bypass via fragmented TLS ClientHello | 2026-05-06 | 2026-05-10 | · |
| CVE-2026-32312 | GLPI < 10.0.25 / 11.0.7 SSRF (CERTFR-2026-AVI-0551) | 2026-05-08 | 2026-05-10 | 2026-05-08 |
| CVE-2026-33725 | Metabase Enterprise Java serialization → authenticated RCE (CVSS 8.8) | 2026-05-07 | 2026-05-10 | · |
| CVE-2026-40108 | GLPI < 10.0.25 / 11.0.7 data integrity compromise (CERTFR-2026-AVI-0551) | 2026-05-08 | 2026-05-10 | 2026-05-08 |
| CVE-2026-40981 | Spring Cloud Config Server Google Secrets Manager backend flaw (HIGH) | 2026-05-09 | 2026-05-10 | · |
| CVE-2026-40982 | Spring Cloud Config Server pre-auth directory traversal (CVSS 9.8) | 2026-05-09 | 2026-05-10 | 2026-05-09 |
| CVE-2026-41002 | Spring Cloud Config Server companion CVE (HIGH) | 2026-05-09 | 2026-05-10 | · |
| CVE-2026-41004 | Spring Cloud Config Server companion CVE (MEDIUM) | 2026-05-09 | 2026-05-10 | · |
| CVE-2026-41940 | cPanel/WHM authentication bypass via CRLF injection (mass exploitation ongoing, KEV) | 2026-05-06 | 2026-05-10 | · |
| CVE-2026-42208 | LiteLLM Proxy pre-auth SQL injection, all upstream LLM API keys at risk (CVSS 9.3, KEV deadline 2026-05-11) | 2026-05-09 | 2026-05-10 | 2026-05-09 |
| CVE-2026-42317 | GLPI < 10.0.25 / 11.0.7 XSS (CERTFR-2026-AVI-0551) | 2026-05-08 | 2026-05-10 | 2026-05-08 |
| CVE-2026-42318 | GLPI < 10.0.25 / 11.0.7 XSS (CERTFR-2026-AVI-0551) | 2026-05-08 | 2026-05-10 | 2026-05-08 |
| CVE-2026-42320 | GLPI < 10.0.25 / 11.0.7 XSS (CERTFR-2026-AVI-0551) | 2026-05-08 | 2026-05-10 | 2026-05-08 |
| CVE-2026-42321 | GLPI < 10.0.25 / 11.0.7 XSS (CERTFR-2026-AVI-0551) | 2026-05-08 | 2026-05-10 | 2026-05-08 |
| CVE-2026-44125 | SEPPmail GINAv2, missing authentication in admin REST API (CVSS 9.3) | 2026-05-09 | 2026-05-10 | 2026-05-09 |
| CVE-2026-44126 | SEPPmail GINAv2, insecure deserialisation via session cookie → RCE (CVSS 9.2) | 2026-05-09 | 2026-05-10 | 2026-05-09 |
| CVE-2026-44127 | SEPPmail appliance management, LFI and arbitrary file deletion (CVSS 8.8) | 2026-05-09 | 2026-05-10 | 2026-05-09 |
| CVE-2026-44129 | SEPPmail GINAv2, server-side template injection via Freemarker (CVSS 8.3) | 2026-05-09 | 2026-05-10 | 2026-05-09 |
| CVE-2026-5174 | Progress MOVEit Automation authenticated privilege escalation (CVSS 8.8) | 2026-05-06 | 2026-05-10 | · |
| CVE-2026-5385 | GLPI < 10.0.25 / 11.0.7 security policy bypass / auth bypass (CERTFR-2026-AVI-0551) | 2026-05-08 | 2026-05-10 | 2026-05-08 |
| CVE-2026-6022 | Progress Telerik RadAsyncUpload DoS via path traversal (CVSS 7.5) | 2026-05-07 | 2026-05-10 | · |
| CVE-2026-6023 | Progress Telerik RadFilter deserialization → unauthenticated RCE (CVSS 9.8) | 2026-05-07 | 2026-05-10 | · |
| CVE-2026-7864 | SEPPmail appliance management, information disclosure (CVSS 6.9) | 2026-05-09 | 2026-05-10 | 2026-05-09 |
| CVE-2026-25077 | Apache CloudStack post-auth authentication token flaw, dropped from § 3 (gate not cleared) | 2026-05-09 | 2026-05-09 | · |
| CVE-2026-21509 | Microsoft Office Protected View bypass, security feature bypass (CVSS 7.8, KEV deadline 2026-02-16 already passed; deferred from §4) | 2026-05-08 | 2026-05-08 | · |
| CVE-2026-21513 | Microsoft Office Protected View chain CVE (deferred from §4; see CVE-2026-21509 series) | 2026-05-08 | 2026-05-08 | · |
| CVE-2026-21514 | Microsoft Office Protected View chain CVE (deferred from §4; see CVE-2026-21509 series) | 2026-05-08 | 2026-05-08 | · |