ctipilot.ch

CVEs

776 CVEs referenced across all briefs. Click an ID for the full appearance trail.

Total CVEs
776
2008 – 2026
Recent (30 d)
303
entities with new coverage in window
Distinct sources
217
hosts cited at least once
Total appearances
770
brief-section attributions
Co-occurrence links
1892
entity ↔ entity in same item

Recent coverage

Aggregate mentions per ISO week, last 14 weeks.

By year

  • 2026677
  • 202548
  • 202413
  • 202313
  • 20225
  • 20215
  • 20205
  • 20191
  • 20182
  • 20172
  • 20161
  • 20151
  • 20132
  • 20081
All years 2026 6772025 482024 132023 132022 52021 52020 52019 12018 22017 22016 12015 12013 22008 1
CVETitleFirst seenLast seenLatest coverage
CVE-2026-58047cPanel & WHM — HTTP request smuggling in cpsrvd allowing an unauthenticated attacker to manipulate responses delivered to other users on the same server (CVSS v4.0 5.6); interim mitigation disables cpsrvd backend connection reuse2026-08-062026-08-06
CVE-2026-58048cPanel & WHM — SQL mode not preserved when renaming a database, so an authenticated account holder with the MySQL/MariaDB feature executes SQL in root context (CVSS v4.0 9.4, HackerOne CNA); fixed across the 11.110–11.136 build lines and WP Squared 138.1.62026-08-062026-08-06
CVE-2026-58067Veeam Service Provider Console — unauthenticated host-memory exhaustion denial of service (CVSS v4.0 8.7); fixed in 9.3.0.350572026-08-062026-08-06
CVE-2026-58071Veeam Service Provider Console — unauthenticated access to the proxied appliance API as Portal Administrator during a window after an admin session begins (CVSS v4.0 8.2); fixed in 9.3.0.350572026-08-062026-08-06
CVE-2026-58072Veeam Service Provider Console — arbitrary file write on the management server leading to remote code execution (CVSS v4.0 9.0); fixed in 9.3.0.350572026-08-062026-08-06
CVE-2026-58073Veeam Service Provider Console — unauthenticated attacker impersonates a managed agent and obtains its credentials (CVSS v4.0 9.5, high attack complexity); fixed in SPC 9.3.0.350572026-08-062026-08-06
CVE-2026-58074Veeam ONE — arbitrary code execution on the server by a high-privileged user (CVSS v4.0 8.6); fixed in 13.1.0.70342026-08-062026-08-06
CVE-2026-58075Veeam ONE — unauthenticated arbitrary file read from the host, leveragable to local privilege escalation (CVSS v4.0 8.7); fixed in 13.1.0.70342026-08-062026-08-06
CVE-2026-63077JetBrains TeamCity On-Premises — unauthenticated deserialization RCE via the agent-polling protocol (CVSS 9.8); added to the CISA KEV catalog 2026-08-05 on evidence of active exploitation, reversing the vendor's no-known-exploitation position at disclosure2026-07-292026-08-062026-07-29
CVE-2026-63455HPE Aruba Networking SD-WAN Orchestrator — REST API authentication bypass via spoofed HTTP headers (CVSS v3.1 9.8), 9.6.x branch only; fixed in 9.6.2.40210 / 9.6.3.40140 / 9.7.0.432642026-08-062026-08-06
CVE-2026-63456HPE Aruba Networking SD-WAN Orchestrator — second REST API authentication bypass via spoofed HTTP headers (CVSS v3.1 9.8), 9.6.x branch only; fixed in 9.6.2.40210 / 9.6.3.40140 / 9.7.0.432642026-08-062026-08-06
CVE-2026-64630Veeam ONE — low-privileged retrieval of report data outside a shared link's scope (CVSS v4.0 5.3); fixed in 13.1.0.70342026-08-062026-08-06
CVE-2026-64631Veeam ONE — SQL injection by a low-privileged user extracting database contents (CVSS v4.0 8.6); fixed in 13.1.0.70342026-08-062026-08-06
CVE-2026-64633Veeam ONE — unauthenticated remote code execution on the agent host (CVSS v4.0 10.0); fixed in Veeam ONE 13.1.0.70342026-08-062026-08-06
CVE-2026-64634Veeam ONE — local privilege escalation into the Reporter service context (CVSS v4.0 8.4); fixed in 13.1.0.70342026-08-062026-08-06
CVE-2026-66747Zbtlink routers/CPE — ENDLESSDOORS, a factory-installed unauthenticated root-command backdoor started by the vendor's own init script across 20+ models; no fix, VulnCheck advises device replacement2026-08-062026-08-06
CVE-2026-17583Thermo Fisher Applied Biosystems genetic analyzers — missing integrity checking on .fsa/.hid output files allows post-run tampering with DNA results (CVSS 3.1 8.4, local); no vendor fix stated in ICSMA-26-216-012026-08-052026-08-052026-08-05
CVE-2026-18556N-able N-central — authentication bypass using an alternate path or channel (CWE-288), affects through 2026.1, fixed in 2026.2 (CVSS 8.2) | CISA KEV 2026-08-04.2026-08-032026-08-052026-08-05 +1 more
CVE-2026-18574Check Point Security Management / Multi-Domain Security Management — unauthenticated bypass of management authentication to arbitrary command execution; fixed in Jumbo HFA R81.20 Take 161 / R82 Take 122 / R82.10 Take 40, no fix for the R80.x / R81 / R81.10 end-of-support trains2026-08-052026-08-052026-08-05
CVE-2026-18577N-able N-central — incomplete patch for CVE-2026-18556; unauthenticated admin auth bypass exploited in the wild, fixed in build 2026.3.1.7 (CVSS 8.2)2026-08-032026-08-052026-08-03
CVE-2026-29146Apache Tomcat — EncryptInterceptor defaulted to CBC and was exploitable as a padding oracle; its fix introduced the fail-open regression tracked as CVE-2026-344862026-08-052026-08-05
CVE-2026-34486Apache Tomcat Tribes/EncryptInterceptor fail-open — the fix for CVE-2026-29146 let messages that fail decryption reach the Java deserialization path; CISA KEV 2026-08-04 (previously recorded only as reverse-shell attempts observed by Unit 42); fixed in 9.0.117 / 10.1.54 / 11.0.212026-08-022026-08-052026-08-05
CVE-2026-9198IBM Langflow — unauthenticated auto_login endpoint mints a superuser token, chained with the code-validation endpoint for pre-auth code execution (CVSS 9.8); CISA KEV 2026-08-04; affects Langflow OSS 1.0.0-1.10.02026-08-052026-08-052026-08-05
CVE-2026-15409SonicWall SMA1000 Work Place unauthenticated SSRF (CVSS 10.0, actively exploited)2026-07-142026-08-042026-08-04 +2 more
CVE-2026-15410SonicWall SMA1000 AMC post-auth code injection (actively exploited)2026-07-142026-08-042026-08-04 +2 more
CVE-2026-20079CVE-2026-20079 — Cisco Secure Firewall Management Center web interface: unauthenticated authentication bypass to root via a boot-time csm_processes session (CVSS 10.0, CWE-288); disclosed 2026-03-04 with no fix, per-train hot fixes added to the advisory 2026-07-31; Cisco reports no known malicious use, VulnCheck built a working exploit2026-08-042026-08-042026-08-04
CVE-2026-51294FABRICATED / NOT A REAL VULNERABILITY — a use-after-free claim against SQLite 3.41 from the LLM-generated advisory batch published via the programmervuln/cveadvisory- GitHub repository. NOT among the six ids JFrog Security Research reproduction-tested; JFrog assessed 54 of the 55 advisories from that account as completely fabricated, and SQLite's maintainer reported the wave independently on 2026-07-29. Still live as an unreviewed record in the GitHub Advisory Database (GHSA-4r76-5xh9-qj36) on 2026-08-04, after BSI CERT-Bund and NCSC-NL had withdrawn their SQLite advisories. Recorded here so a scanner or triage lookup resolves to the retraction — do NOT open remediation work from this id.2026-08-042026-08-04
CVE-2026-51296FABRICATED / NOT A REAL VULNERABILITY — one of the LLM-generated SQLite advisories published via the programmervuln/cveadvisory- GitHub repository. JFrog Security Research reproduction-tested it under AddressSanitizer against the claimed SQLite release and it did not reproduce; it cited lines 3555 and 3575 of src/json.c in a file that is 2706 lines long in the claimed version 3.41.0. NCSC-NL withdrew NCSC-2026-0268 on 2026-08-03 stating the CVE was hallucinated by an LLM, and BSI CERT-Bund withdrew WID-SEC-2026-2581 and WID-SEC-2026-2604 the same day. Recorded here so a scanner or triage lookup resolves to the retraction — do NOT open remediation work from this id.2026-08-042026-08-04
CVE-2026-51297FABRICATED / NOT A REAL VULNERABILITY — one of the LLM-generated SQLite advisories published via the programmervuln/cveadvisory- GitHub repository. JFrog Security Research reproduction-tested it under AddressSanitizer against the claimed SQLite release and it did not reproduce; it referenced jsonBlobEdit(), a function absent from the claimed version 3.41.0. NCSC-NL withdrew NCSC-2026-0268 on 2026-08-03 stating the CVE was hallucinated by an LLM, and BSI CERT-Bund withdrew WID-SEC-2026-2581 and WID-SEC-2026-2604 the same day. Recorded here so a scanner or triage lookup resolves to the retraction — do NOT open remediation work from this id.2026-08-042026-08-04
CVE-2026-51300FABRICATED / NOT A REAL VULNERABILITY — one of the LLM-generated SQLite advisories published via the programmervuln/cveadvisory- GitHub repository. JFrog Security Research reproduction-tested it under AddressSanitizer against the claimed SQLite release and it did not reproduce; the cited line numbers are a comment and a memory allocation, unrelated to the deletion logic it describes. NCSC-NL withdrew NCSC-2026-0268 on 2026-08-03 stating the CVE was hallucinated by an LLM, and BSI CERT-Bund withdrew WID-SEC-2026-2581 and WID-SEC-2026-2604 the same day. Recorded here so a scanner or triage lookup resolves to the retraction — do NOT open remediation work from this id.2026-08-042026-08-04
CVE-2026-51302FABRICATED / NOT A REAL VULNERABILITY — one of the LLM-generated SQLite advisories published via the programmervuln/cveadvisory- GitHub repository. JFrog Security Research reproduction-tested it under AddressSanitizer against the claimed SQLite release and it did not reproduce; the named function exprComputeOperands() did not exist in SQLite 3.41 and sqlite3ReleaseTempReg() performs no heap deallocation, making the claimed bug class impossible; Red Hat initially scored it 10.0 before downgrading to 7.6. NCSC-NL withdrew NCSC-2026-0268 on 2026-08-03 stating the CVE was hallucinated by an LLM, and BSI CERT-Bund withdrew WID-SEC-2026-2581 and WID-SEC-2026-2604 the same day. Recorded here so a scanner or triage lookup resolves to the retraction — do NOT open remediation work from this id.2026-08-042026-08-04
CVE-2026-51303FABRICATED / NOT A REAL VULNERABILITY — one of the LLM-generated SQLite advisories published via the programmervuln/cveadvisory- GitHub repository. JFrog Security Research reproduction-tested it under AddressSanitizer against the claimed SQLite release and it did not reproduce; it claimed a fix in 3.51.3 although a 3.51.2-to-3.51.3 diff shows no changes to src/expr.c at all. NCSC-NL withdrew NCSC-2026-0268 on 2026-08-03 stating the CVE was hallucinated by an LLM, and BSI CERT-Bund withdrew WID-SEC-2026-2581 and WID-SEC-2026-2604 the same day. Recorded here so a scanner or triage lookup resolves to the retraction — do NOT open remediation work from this id.2026-08-042026-08-04
CVE-2026-51304FABRICATED / NOT A REAL VULNERABILITY — one of the LLM-generated SQLite advisories published via the programmervuln/cveadvisory- GitHub repository. JFrog Security Research reproduction-tested it under AddressSanitizer against the claimed SQLite release and it did not reproduce; it gave a single-argument signature for a function that requires a database-handle argument. NCSC-NL withdrew NCSC-2026-0268 on 2026-08-03 stating the CVE was hallucinated by an LLM, and BSI CERT-Bund withdrew WID-SEC-2026-2581 and WID-SEC-2026-2604 the same day. Recorded here so a scanner or triage lookup resolves to the retraction — do NOT open remediation work from this id.2026-08-042026-08-04
CVE-2025-11371Gladinet CentreStack and Triofox — files or directories accessible to external parties; added to the CISA Known Exploited Vulnerabilities catalog 2025-11-04. Referenced as historical exploitation context by the 2026-08-03 CentreStack entry.2025-11-042026-08-03
CVE-2025-14611Gladinet CentreStack and Triofox — hard-coded cryptographic key vulnerability; added to the CISA Known Exploited Vulnerabilities catalog 2025-12-15. Referenced as historical exploitation context by the 2026-08-03 CentreStack entry.2025-12-152026-08-03
CVE-2025-30406Gladinet CentreStack — use of a hard-coded cryptographic key; added to the CISA Known Exploited Vulnerabilities catalog 2025-04-08. Referenced as historical exploitation context by the 2026-08-03 CentreStack entry.2025-04-082026-08-03
CVE-2026-12185Bouncy Castle for Java (< 1.85) — BKS/UBER keystore allocates from untrusted lengths before integrity check (CVSS 7.1)2026-08-032026-08-032026-08-03
CVE-2026-12802Bouncy Castle for Java (< 1.85) — CMS AuthEnvelopedData fails to enforce tag-length on decryption (CVSS 8.7)2026-08-032026-08-032026-08-03
CVE-2026-12803Bouncy Castle for Java (< 1.85) — KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery) (CVSS 8.7)2026-08-032026-08-032026-08-03
CVE-2026-12816Bouncy Castle for Java (< 1.85) — IESEngine stream-mode MAC forgery via length-dependent KDF split (CVSS 8.7)2026-08-032026-08-032026-08-03
CVE-2026-12817Bouncy Castle for Java (< 1.85) — OpenPGP AEAD decryption skips final tag on chunk-aligned data (CVSS 8.7)2026-08-032026-08-032026-08-03
CVE-2026-12852Bouncy Castle for Java (< 1.85) — MLS wire decoder allocates attacker-declared opaque length before bounds check (CVSS 8.7)2026-08-032026-08-032026-08-03
CVE-2026-12860Bouncy Castle for Java (< 1.85) — RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path (CVSS 8.7)2026-08-032026-08-032026-08-03
CVE-2026-13506Bouncy Castle for Java (< 1.85) — Lazy ASN.1 sequence forcing resets nesting-depth guard (CVSS 8.7)2026-08-032026-08-032026-08-03
CVE-2026-13586Bouncy Castle for Java (< 1.85) — PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS) (CVSS 5.3)2026-08-032026-08-032026-08-03
CVE-2026-14682Bouncy Castle for Java (< 1.85) — Possible OOM from unbounded up-front allocation on a definite-length read (CVSS 8.7)2026-08-032026-08-032026-08-03
CVE-2026-15055Bouncy Castle for Java (< 1.85) — PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input (CVSS 5.3)2026-08-032026-08-032026-08-03
CVE-2026-54363Gladinet CentreStack < 17.5 — hardcoded cryptographic key (static SysNumber) forges AccessTickets and x-glad-auth headers, reaching a domain-administrator IdentityTicket and unauthenticated RCE (CVSS 9.3)2026-08-032026-08-032026-08-03
CVE-2026-54364Gladinet CentreStack < 17.4 — session-variable injection at SelectProvider.aspx bypasses the IsValidRSession check (CVSS 6.9)2026-08-032026-08-032026-08-03
CVE-2026-54365Gladinet CentreStack < 17.3 — unauthenticated deserialization in GSNamespace.dll reaches NetUserAdd, creating arbitrary local OS accounts (CVSS 8.7)2026-08-032026-08-032026-08-03
CVE-2026-54366Gladinet CentreStack < 17.4 — XXE at the unauthenticated SharePoint StorageConfig endpoint exfiltrates files including Web.config (CVSS 8.7)2026-08-032026-08-032026-08-03
CVE-2026-54367Gladinet CentreStack < 17.2 — unauthenticated authorization bypass via forged EntAcctId values reaches any account's settings (CVSS 8.8)2026-08-032026-08-032026-08-03
CVE-2026-54368Gladinet CentreStack < 17.4 — authenticated SQL injection via the x-glad-filter header writes files through PostgreSQL large-object functions (CVSS 8.7)2026-08-032026-08-032026-08-03
CVE-2026-58059Bouncy Castle for Java (< 1.85) — Quadratic-time escaping when stringifying X.500 distinguished names (CVSS 8.7)2026-08-032026-08-032026-08-03
CVE-2026-58060Bouncy Castle for Java (< 1.85) — HSS public-key level count unbounded, enabling huge allocation on verify (CVSS 8.7)2026-08-032026-08-032026-08-03
CVE-2026-58061Bouncy Castle for Java (< 1.85) — CCM-family modes write plaintext to caller buffer before tag check (CVSS 8.7)2026-08-032026-08-032026-08-03
CVE-2026-58062Bouncy Castle for Java (< 1.85) — Stapled OCSP response accepted without binding to the checked certificate (CVSS 9.3)2026-08-032026-08-032026-08-03
CVE-2026-58063Bouncy Castle for Java (< 1.85) — BCFKS keystore load honours unbounded KDF cost from untrusted file (CVSS 5.3)2026-08-032026-08-032026-08-03
CVE-2026-59638Bouncy Castle for Java (< 1.85) — JSSE hostname verifier CN-fallback enabled by default despite documented opt-in (CVSS 9.3)2026-08-032026-08-032026-08-03
CVE-2026-59639Bouncy Castle for Java (< 1.85) — CMS verifySignatures returns true for SignedData with zero signers (CVSS 8.7)2026-08-032026-08-032026-08-03
CVE-2026-59640Bouncy Castle for Java (< 1.85) — OpenPGP CFB quick-check oracle active on symmetric/session-key paths (CVSS 8.7)2026-08-032026-08-032026-08-03
CVE-2026-59641Bouncy Castle for Java (< 1.85) — S/MIME validator trusts signer-asserted signingTime for path validation (CVSS 8.7)2026-08-032026-08-032026-08-03
CVE-2026-59642Bouncy Castle for Java (< 1.85) — CMS AuthenticatedData content not bound to MAC when authAttrs present (CVSS 8.7)2026-08-032026-08-032026-08-03
CVE-2026-59643Bouncy Castle for Java (< 1.85) — OpenPGP inline-signature policy failures silently ignored (CVSS 8.7)2026-08-032026-08-032026-08-03
CVE-2026-59644Bouncy Castle for Java (< 1.85) — MLS hash-ratchet honours arbitrary 32-bit generation counter from sender (CVSS 8.7)2026-08-032026-08-032026-08-03
CVE-2026-59645Bouncy Castle for Java (< 1.85) — OER parser recurses without depth limit on self-referential IEEE 1609.2 schema (CVSS 8.7)2026-08-032026-08-032026-08-03
CVE-2026-59646Bouncy Castle for Java (< 1.85) — DTLS handshake reassembler allocates buffer from unchecked 24-bit length (CVSS 8.7)2026-08-032026-08-032026-08-03
CVE-2026-59647Bouncy Castle for Java (< 1.85) — CRMF/CMP password-MAC honours unbounded iteration count (CVSS 6.9)2026-08-032026-08-032026-08-03
CVE-2026-59648Bouncy Castle for Java (< 1.85) — OpenPGP Argon2 S2K honours attacker-chosen memory and passes (CVSS 6.9)2026-08-032026-08-032026-08-03
CVE-2026-59649Bouncy Castle for Java (< 1.85) — OpenPGP user-attribute subpacket length bounded only by JVM max memory (CVSS 8.7)2026-08-032026-08-032026-08-03
CVE-2026-59650Bouncy Castle for Java (< 1.85) — MTI/A0 DH agreement exponentiates unvalidated peer value (CVSS 9.3)2026-08-032026-08-032026-08-03
CVE-2026-59651Bouncy Castle for Java (< 1.85) — BKS keystore accepts legacy version with 16-bit integrity MAC key (CVSS 7.1)2026-08-032026-08-032026-08-03
CVE-2026-59652Bouncy Castle for Java (< 1.85) — LDAP filter injection in legacy jdk1.4 LDAPStoreHelper (CVSS 6.9)2026-08-032026-08-032026-08-03
CVE-2026-8763Bouncy Castle for Java (< 1.85) — Name Constraints bypass via trailing dot in rfc822Name and URI (CVSS 9.3)2026-08-032026-08-032026-08-03
CVE-2013-4786CVE-2013-4786 — 24,650 internet-exposed BMCs hand a crackable password hash to any unauthenticated caller, and Lava found ransom notes on live management interfaces2026-07-302026-08-022026-07-30
CVE-2025-15467OpenSSL CMS AuthEnvelopedData parsing stack buffer overflow (CVSS 9.8 per Siemens ProductCERT; OpenSSL rates it High) — pre-auth, fires before AEAD tag verification; vendored in Siemens Desigo CC, where family V7 has no fix available, V8 is fixed by patch V8.0 QU2.0021 and V9 by 9.0.1; public command-execution PoC2026-07-292026-08-022026-07-29
CVE-2025-68686FortiOS SSL-VPN symlink-persistence patch bypass (exploited, KEV)2026-07-282026-08-022026-07-28
CVE-2026-0769Langflow eval_custom_component_code eval injection (CVSS 9.8, CWE-95) — unauthenticated RCE, published by ZDI as a 0-day advisory with no fixed version documented anywhere and "restrict interaction with the product" as the only stated mitigation; VulnCheck reports observed exploitation for credential harvesting, cryptomining and lateral movement; NOT in CISA KEV (distinct from the KEV-listed CVE-2026-0770)2026-07-292026-08-022026-07-29
CVE-2026-12569PTC Windchill / FlexPLM — pre-auth deserialization RCE, CISA KEV-listed, now driving a Cl0p-attributed mass data-theft extortion campaign2026-06-202026-08-022026-07-27 +4 more
CVE-2026-14446IBM WebSphere Application Server traditional — missing authentication for critical function in the administrative console (CWE-306), CVSS 9.8; interim fix APAR DT496500, Fix Pack targeted 3Q20262026-08-012026-08-022026-08-01
CVE-2026-14512IBM WebSphere Application Server traditional — pre-authentication unsafe deserialization (CWE-502), CVSS 9.8; interim fix APAR PH72166, Fix Pack targeted 3Q20262026-08-012026-08-022026-08-01
CVE-2026-16232Check Point SmartConsole authentication bypass to full admin (exploited)2026-07-232026-08-022026-07-29 +1 more
CVE-2026-16723Alibaba fastjson 1.2.68–1.2.83 — remote code execution under stock defaults in Spring Boot fat-JAR deployments; no patched 1.x release, exploited in the wild2026-07-272026-08-022026-07-27
CVE-2026-16812Arista VeloCloud Orchestrator on-prem unauthenticated OS command injection (exploited, KEV)2026-07-282026-08-022026-07-28
CVE-2026-20316CVE-2026-20316 — Cisco Secure Firewall Management Center ships a static low-privilege account in its web interface, and Cisco confirms exploitation has been ongoing2026-07-302026-08-022026-07-30
CVE-2026-28323SolarWinds Web Help Desk — unauthenticated SAML 2.0 authentication bypass, CVSS 9.8; fixed in 2026.2.12026-08-012026-08-022026-08-01
CVE-2026-3055Citrix NetScaler ADC/Gateway out-of-bounds memory read when configured as a SAML Identity Provider (CWE-125, CVSS 9.8) — CISA KEV-listed and exploited by multiple unrelated clusters, including manual exfiltration of appliance memory searched for session cookies (Unit 42, 2026-07-30); fixed in 13.1-62.24 / 14.1-66.60 / 13.1-FIPS-NDcPP 13.1-37.2632026-07-012026-08-022026-07-31
CVE-2026-33824Windows IKE Extensions (IKE VPN) — Unit 42 records reverse-shell callbacks from three endpoints in the autonomous-AI intrusion campaign2026-08-022026-08-02
CVE-2026-39987marimo notebook — pre-auth RCE via the unauthenticated /terminal/ws endpoint (CWE-306), CVSS 4.0 9.3, fixed in 0.23.0, CISA KEV-listed; Unit 42 records command execution confirmed on 11 endpoints during the 2026-07 autonomous-agent campaign2026-05-302026-08-022026-08-02
CVE-2026-42897Microsoft Exchange Server Outlook Web Access stored XSS (CWE-79, CVSS 3.1 8.1, Microsoft CNA) — exploited in the wild by TA488/LAUNDRY BEAR to deliver the OWAReaper browser implant; CISA KEV 2026-05-15; permanent fix is the July 2026 Exchange SU (SE RTM; 2019 CU14/CU15 and 2016 CU23 via ESU Period 2), which does not remove earlier mitigations2026-05-112026-08-022026-07-31 +4 more
CVE-2026-44090Phoenix Contact CHARX SEC-3xxx — MQTT broker reachable without authentication, protected from external access only by the device firewall (CWE-306); CVSS 3.1 9.82026-08-022026-08-022026-08-02
CVE-2026-44101Phoenix Contact CHARX SEC-3xxx — missing authentication on the CHARX OCPP Agent lets a remote attacker reconfigure the backend connection (CWE-306); CVSS 3.1 9.82026-08-022026-08-022026-08-02
CVE-2026-44104Phoenix Contact CHARX SEC-3xxx — basemodule firmware update validates only a CRC32 checksum with no cryptographic signature verification (CWE-347), allowing unauthenticated installation of modified firmware; CVSS 3.1 9.82026-08-022026-08-022026-08-02
CVE-2026-44108Phoenix Contact CHARX SEC-3xxx — firewall terminates prematurely during shutdown because of script execution order (CWE-696), exposing internal services in the window; CVSS 3.1 9.82026-08-022026-08-022026-08-02
CVE-2026-48448Adobe Campaign Classic — unauthenticated SQL injection giving arbitrary file-system read; CVSS 3.1 8.6, fixed in ACC v7 7.4.3 build 9398 (APSB26-114)2026-08-022026-08-022026-08-02
CVE-2026-48449Adobe Campaign Classic — Incorrect Authorization (CWE-863) giving unauthenticated arbitrary code execution; CVSS 3.1 10.0, on-premise and hybrid on-premise components only, fixed in ACC v7 7.4.3 build 9398 (APSB26-114)2026-08-022026-08-022026-08-02
CVE-2026-59243Apache Airflow FAB provider — Azure AD OAuth login decoded ID tokens with verify_signature defaulted to False, allowing login as any user incl. Admin; no CVSS published by any party; fixed in apache-airflow-providers-fab 3.7.32026-07-292026-08-022026-07-29
CVE-2026-59726CVE-2026-59726 (RufRoot) — Ruflo's MCP bridge took unauthenticated tool calls on all interfaces, and the memory it poisons is not cleaned up by the patch (CVSS 10.0)2026-07-302026-08-022026-07-30
CVE-2026-61511vBulletin {vb:math} runMaths eval injection, unauthenticated RCE (public exploit)2026-07-282026-08-022026-07-28
CVE-2026-65766JoomShaper SP Page Builder for Joomla — pre-authentication SQL injection in the Dynamic Content endpoint's ORDER BY clause, guarded only by a CSRF token Joomla issues to anonymous visitors; Joomla CNA CVSS 4.0 9.2 (discloser self-scored 8.7), fixed in 6.7.12026-08-022026-08-022026-08-02
CVE-2026-65876JoomShaper SP Page Builder for Joomla — unauthenticated SQL injection through the catid parameter of the loadMoreArticles endpoint; Joomla CNA CVSS 4.0 9.2, fixed in 6.7.1. Not among the four flaws mySites.guru reported and not tested by it2026-08-022026-08-022026-08-02
CVE-2026-65877JoomShaper SP Page Builder for Joomla — authenticated SQL injection in the media manager's search and date filters, reachable by a low-privilege author; Joomla CNA CVSS 4.0 8.2, fixed in 6.7.12026-08-022026-08-022026-08-02
CVE-2026-65878JoomShaper SP Page Builder for Joomla — authenticated arbitrary file delete via an unguarded request-supplied path in the media-delete action; Joomla CNA CVSS 4.0 8.3, fixed in 6.7.12026-08-022026-08-022026-08-02
CVE-2026-65879JoomShaper SP Page Builder for Joomla — unauthenticated mail relay via a shared secret hardcoded identically into every shipped copy (CWE-798); the Joomla CNA assigned no metrics, so the 9.8 is a CISA-ADP CVSS 3.1 score and is not on the CVSS 4.0 scale its siblings use. Fixed in 6.7.12026-08-022026-08-022026-08-02
CVE-2026-65883Aimy Captcha-Less Form Guard (Joomla plugin) — unauthenticated PHP object injection to RCE, CVSS 9.8; fixed in 20.12026-08-012026-08-022026-08-01
CVE-2026-65884Balbooa Gridbox for Joomla — registration handler adds caller-supplied usergroup IDs, letting an unauthenticated visitor register an account directly into an administrator group; CVSS 4.0 10.0 (CWE-284, Joomla CNA), exploit maturity Attacked; affected 1.0.0-2.20.1, fixed 2.20.22026-07-312026-08-022026-07-31
CVE-2026-65885Balbooa Gridbox for Joomla — authenticated arbitrary file upload; becomes unauthenticated RCE chained with CVE-2026-65884 because the attacker can create the required account; CVSS 4.0 9.4 (CWE-434, Joomla CNA), exploit maturity Attacked; affected 1.0.0-2.20.1, fixed 2.20.22026-07-312026-08-022026-07-31
CVE-2026-66066Ruby on Rails Active Storage variant processing on libvips — unauthenticated arbitrary file read (and possible RCE via exposed application secrets) from an untrusted image upload; CVSS 4.0 9.5 assigned by GitHub Security Advisories as the Rails CNA; fixed in activestorage 7.2.3.2 / 8.0.5.1 / 8.1.3.1 and requires libvips >= 8.13 to be effective2026-07-312026-08-022026-08-02 +1 more
CVE-2026-7849Phoenix Contact CHARX SEC-3xxx EV charging controllers — unauthenticated command injection into the system configuration executed as root (CWE-77); CVSS 3.1 9.8, firmware below 1.9.1, fix unreleased at disclosure (CERT@VDE VDE-2026-008)2026-08-022026-08-022026-08-02
CVE-2026-14528IBM WebSphere Application Server traditional — sensitive information written to log files (CWE-532), CVSS 7.42026-08-012026-08-012026-08-01
CVE-2026-28299SolarWinds Web Help Desk — denial of service, server crash due to insufficient memory; 8.2 High per the vendor's 2026.2.1 release-notes CVE table; fixed in 2026.2.12026-08-012026-08-012026-08-01
CVE-2026-14869HCSEC-2026-23 — HashiCorp Terraform MCP Server leaks its own bearer token to an attacker-supplied address, and its credential cache crosses sessions and tenants (CVE-2026-14869, CVE-2026-16496, CVE-2026-16498)2026-07-302026-07-302026-07-30
CVE-2026-16496HCSEC-2026-23 — HashiCorp Terraform MCP Server leaks its own bearer token to an attacker-supplied address, and its credential cache crosses sessions and tenants (CVE-2026-14869, CVE-2026-16496, CVE-2026-16498)2026-07-302026-07-302026-07-30
CVE-2026-16498HCSEC-2026-23 — HashiCorp Terraform MCP Server leaks its own bearer token to an attacker-supplied address, and its credential cache crosses sessions and tenants (CVE-2026-14869, CVE-2026-16496, CVE-2026-16498)2026-07-302026-07-302026-07-30
CVE-2026-41703VMSA-2026-0006 — VMware vCenter: unauthenticated Directory Service auth bypass and Syslog traversal RCE (both CVSS 9.8), plus a VMXNET3 guest-to-host escape2026-07-302026-07-302026-07-30
CVE-2026-41709VMSA-2026-0006 — VMware vCenter: unauthenticated Directory Service auth bypass and Syslog traversal RCE (both CVSS 9.8), plus a VMXNET3 guest-to-host escape2026-07-302026-07-302026-07-30
CVE-2026-47876VMSA-2026-0006 — VMware vCenter: unauthenticated Directory Service auth bypass and Syslog traversal RCE (both CVSS 9.8), plus a VMXNET3 guest-to-host escape2026-07-302026-07-302026-07-30
CVE-2026-59309VMSA-2026-0006 — VMware vCenter: unauthenticated Directory Service auth bypass and Syslog traversal RCE (both CVSS 9.8), plus a VMXNET3 guest-to-host escape2026-07-302026-07-302026-07-30
CVE-2026-59310VMSA-2026-0006 — VMware vCenter: unauthenticated Directory Service auth bypass and Syslog traversal RCE (both CVSS 9.8), plus a VMXNET3 guest-to-host escape2026-07-302026-07-302026-07-30
CVE-2026-65617Hugging Face intrusion update — the sandbox escape was a chain of previously unknown JFrog Artifactory flaws, now patched, and the models also used publicly exposed credentials on four third-party services2026-07-302026-07-302026-07-30
CVE-2026-65921Hugging Face intrusion update — the sandbox escape was a chain of previously unknown JFrog Artifactory flaws, now patched, and the models also used publicly exposed credentials on four third-party services2026-07-302026-07-302026-07-30
CVE-2026-65922Hugging Face intrusion update — the sandbox escape was a chain of previously unknown JFrog Artifactory flaws, now patched, and the models also used publicly exposed credentials on four third-party services2026-07-302026-07-302026-07-30
CVE-2026-65923Hugging Face intrusion update — the sandbox escape was a chain of previously unknown JFrog Artifactory flaws, now patched, and the models also used publicly exposed credentials on four third-party services2026-07-302026-07-302026-07-30
CVE-2026-65924Hugging Face intrusion update — the sandbox escape was a chain of previously unknown JFrog Artifactory flaws, now patched, and the models also used publicly exposed credentials on four third-party services2026-07-302026-07-302026-07-30
CVE-2026-65925Hugging Face intrusion update — the sandbox escape was a chain of previously unknown JFrog Artifactory flaws, now patched, and the models also used publicly exposed credentials on four third-party services2026-07-302026-07-302026-07-30
CVE-2026-66014Hugging Face intrusion update — the sandbox escape was a chain of previously unknown JFrog Artifactory flaws, now patched, and the models also used publicly exposed credentials on four third-party services2026-07-302026-07-302026-07-30
CVE-2026-66015Hugging Face intrusion update — the sandbox escape was a chain of previously unknown JFrog Artifactory flaws, now patched, and the models also used publicly exposed credentials on four third-party services2026-07-302026-07-302026-07-30
CVE-2026-66018Hugging Face intrusion update — the sandbox escape was a chain of previously unknown JFrog Artifactory flaws, now patched, and the models also used publicly exposed credentials on four third-party services2026-07-302026-07-302026-07-30
CVE-2026-7891Siemens Mendix Runtime (all versions, CVSS 9.1) — platform-enforced access rules on the System.User entity cannot be overridden by access rules on a specialization, so the anonymous role commonly reaches all stored user records; no code fix, mitigation is App Security role-management reconfiguration2026-07-292026-07-292026-07-29
CVE-2025-33053Windows shortcut working-directory resolution flaw abused for remote WebDAV execution2026-07-262026-07-262026-07-26
CVE-2026-0770CVE-2026-0770 — Langflow: unauthenticated exec_globals RCE (actively exploited, CISA KEV 2026-07-21)2026-07-222026-07-262026-07-22
CVE-2026-14499IBM Langflow OSS Python Interpreter authenticated command injection (CVSS 8.8) — fixed in 1.10.2, not 1.10.12026-07-262026-07-262026-07-26
CVE-2026-47056Oracle Data Integrator REST Service — unauthenticated takeover (CVSS 10.0, July 2026 CPU)2026-07-262026-07-262026-07-26
CVE-2026-60137WordPress core WP_Query author__not_in SQL injection (WP2Shell chain component)2026-07-182026-07-262026-07-26 +1 more
CVE-2026-60217Oracle Coherence Core — unauthenticated takeover over TCP (CVSS 10.0, July 2026 CPU)2026-07-262026-07-262026-07-26
CVE-2026-60365Oracle Fusion Middleware CVSS 10.0 unauthenticated flaw — listed twice in Oracle's July 2026 risk matrix (Oracle HTTP Server and WebLogic Server Proxy Plug-in), which is why the ten-row / nine-CVE counts diverge2026-07-262026-07-26
CVE-2026-61211Oracle Database Server — DBMS_CLOUD privilege abuse to full server control (CVSS 9.9)2026-07-262026-07-262026-07-26
CVE-2026-61425Balbooa Gridbox for Joomla — unauthenticated cookie-forgery authentication bypass to Super User2026-07-262026-07-262026-07-26
CVE-2026-62415Membership Pro for Joomla — unauthenticated file upload (CVSS 9.1, Joomla CNA); fixed in 4.6.22026-07-262026-07-262026-07-26
CVE-2026-63030WP2Shell: WordPress core REST batch route confusion to pre-auth RCE chain2026-07-182026-07-262026-07-26 +1 more
CVE-2026-63047Events Booking for Joomla — unauthenticated invoice IDOR exposing personal and financial data2026-07-262026-07-262026-07-26
CVE-2026-65759JoomShaper EasyStore for Joomla — unauthenticated order/payment forgery on the repayment endpoint (CVSS 4.0 8.7, Joomla CNA)2026-07-262026-07-262026-07-26
CVE-2026-65760JoomShaper EasyStore for Joomla — cross-customer order/invoice IDOR reachable by any logged-in customer (CVSS 4.0 9.2, Joomla CNA)2026-07-262026-07-262026-07-26
CVE-2026-65761JoomShaper EasyStore for Joomla — unauthenticated SQL injection, full site-database read (CVSS 4.0 9.3, Joomla CNA)2026-07-262026-07-262026-07-26
CVE-2023-43770Roundcube webmail persistent XSS (n-day exploited by TA458/Operation RoundPress)2026-07-252026-07-25
CVE-2025-27915Zimbra Collaboration half-click webmail flaw (TA458/Operation RoundPress)2026-07-252026-07-25
CVE-2025-3929mDaemon webmail half-click flaw (TA458/Operation RoundPress)2026-07-252026-07-25
CVE-2026-54121Certighost — Windows Server AD CS elevation of privilege (DC impersonation to DCSync)2026-07-252026-07-252026-07-25
CVE-2026-62144Check Point Security Management / MDS unauthenticated command execution2026-07-252026-07-252026-07-25
CVE-2026-62145Check Point Gaia Portal read-only to root command execution2026-07-252026-07-252026-07-25
CVE-2026-8496SOGo webmail half-click XSS zero-day (Operation RoundPress / TA458)2026-07-252026-07-252026-07-25
CVE-2025-66376Zimbra Collaboration Suite Classic Web Client stored XSS (view-based/zero-click) exploited by Russian actor LAUNDRY BEAR; CVSS 7.2 (MITRE)/6.1 (NVD); CISA KEV; patched ZCS 10.0.18/10.1.132026-07-242026-07-242026-07-24
CVE-2026-16002MZ Automation lib60870 out-of-bounds read parser-crash DoS (IEC 60870-5-104); lib60870 <= 2.4.0 (CVSS 3.1 8.2 / 4.0 8.8)2026-07-242026-07-242026-07-24
CVE-2026-49035MZ Automation libIEC61850 unauthenticated heap-overflow RCE via crafted MMS Initiate request (CVSS 3.1 8.1 / 4.0 9.2); libIEC61850 1.0.0-1.6.12026-07-242026-07-242026-07-24
CVE-2026-50032MZ Automation libIEC61850 NULL-pointer dereference DoS in MMS Write Named Variable List handler (CVSS 3.1 7.5 / 4.0 8.7)2026-07-242026-07-242026-07-24
CVE-2026-50039MZ Automation libIEC61850 stack-based buffer overflow via crafted ReadRequest (CVSS 3.1 7.5 / 4.0 8.7)2026-07-242026-07-242026-07-24
CVE-2026-50103MZ Automation libIEC61850 NULL-pointer dereference DoS in L2 GOOSE/R-GOOSE parser via malformed TLV (CVSS 3.1 6.5 / 4.0 7.1)2026-07-242026-07-242026-07-24
CVE-2026-28302SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE)2026-07-232026-07-232026-07-23
CVE-2026-28304SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE)2026-07-232026-07-232026-07-23
CVE-2026-28305SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE)2026-07-232026-07-232026-07-23
CVE-2026-28306SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE)2026-07-232026-07-232026-07-23
CVE-2026-28307SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE)2026-07-232026-07-232026-07-23
CVE-2026-28308SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE)2026-07-232026-07-232026-07-23
CVE-2026-28309SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE)2026-07-232026-07-232026-07-23
CVE-2026-28310SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE)2026-07-232026-07-232026-07-23
CVE-2026-28311SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE)2026-07-232026-07-232026-07-23
CVE-2026-28312SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE)2026-07-232026-07-232026-07-23
CVE-2026-28313SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE)2026-07-232026-07-232026-07-23
CVE-2026-28314SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE)2026-07-232026-07-232026-07-23
CVE-2026-28315SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE)2026-07-232026-07-232026-07-23
CVE-2026-28316SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE)2026-07-232026-07-232026-07-23
CVE-2026-28317SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE)2026-07-232026-07-232026-07-23
CVE-2026-28321SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE)2026-07-232026-07-232026-07-23
CVE-2026-47678GLPI 11.0.8/10.0.26 security release (critical RCE via form import; MFA bypass)2026-07-232026-07-232026-07-23
CVE-2026-47679GLPI 11.0.8/10.0.26 security release (critical RCE via form import; MFA bypass)2026-07-232026-07-232026-07-23
CVE-2026-48482GLPI 11.0.8/10.0.26 security release (critical RCE via form import; MFA bypass)2026-07-232026-07-232026-07-23
CVE-2026-49470GLPI 11.0.8/10.0.26 security release (critical RCE via form import; MFA bypass)2026-07-232026-07-232026-07-23
CVE-2026-52848GLPI 11.0.8/10.0.26 security release (critical RCE via form import; MFA bypass)2026-07-232026-07-232026-07-23
CVE-2026-53610GLPI 11.0.8/10.0.26 security release (critical RCE via form import; MFA bypass)2026-07-232026-07-232026-07-23
CVE-2026-53625GLPI 11.0.8/10.0.26 security release (critical RCE via form import; MFA bypass)2026-07-232026-07-232026-07-23
CVE-2026-53626GLPI 11.0.8/10.0.26 security release (critical RCE via form import; MFA bypass)2026-07-232026-07-232026-07-23
CVE-2026-53629GLPI 11.0.8/10.0.26 security release (critical RCE via form import; MFA bypass)2026-07-232026-07-232026-07-23
CVE-2026-55214GLPI 11.0.8/10.0.26 security release (critical RCE via form import; MFA bypass)2026-07-232026-07-232026-07-23
CVE-2026-10631CVE-2026-10631 — Zimbra: EWS extension access-control issue (fixed 10.1.20; RESERVED on NVD)2026-07-222026-07-222026-07-22
CVE-2026-50054CVE-2026-50054 — Zimbra: mailbox delegation authorization flaw (fixed 10.1.20; RESERVED on NVD)2026-07-222026-07-222026-07-22
CVE-2026-50055CVE-2026-50055 — Zimbra: mail-forwarding restriction bypass (fixed 10.1.20; RESERVED on NVD)2026-07-222026-07-222026-07-22
CVE-2026-50522CVE-2026-50522 — Microsoft SharePoint Server: Site-Owner deserialization RCE (CVSS 9.8)2026-07-152026-07-222026-07-22 +1 more
CVE-2026-7754CVE-2026-7754 — Langflow OSS: SSRF from insecure default configuration (fixed 1.10.1)2026-07-222026-07-22
CVE-2026-7755CVE-2026-7755 — Langflow OSS: RCE via insufficient validation of MCP server config files (fixed 1.10.1)2026-07-222026-07-22
CVE-2026-8476CVE-2026-8476 — Langflow OSS: unsafe deserialization in AsyncDiskCache via apply_tweaks() (fixed 1.10.1)2026-07-222026-07-22
CVE-2026-8859CVE-2026-8859 — Langflow OSS: path-traversal arbitrary file write (fixed 1.10.1)2026-07-222026-07-222026-07-22
CVE-2026-9135CVE-2026-9135 — Langflow OSS: code injection in Policies/ToolGuard component (fixed 1.10.1)2026-07-222026-07-222026-07-22
CVE-2026-9202CVE-2026-9202 — Langflow OSS: unauthenticated account creation reaching RCE (fixed 1.10.1)2026-07-222026-07-222026-07-22
CVE-2026-2291dnsmasq really_insert() DNS-cache heap buffer overflow (RCE per Exodus; NVD frames as DoS/cache-poisoning)2026-07-212026-07-212026-07-21
CVE-2026-6875ServiceNow AI Platform sandbox escape — unauthenticated code execution within the platform (CVSS 9.5); hosted fixed server-side, self-hosted/partner patch listed family releases2026-07-132026-07-212026-07-21 +1 more
CVE-2026-42533nginx / NGINX Plus PCRE capture-clobber pre-auth heap overflow (CVSS 9.2); F5 out-of-band patch 2026-07-15/16, credited researcher demonstrates RCE beyond F5's DoS-only framing (no public PoC, no ITW as of 2026-07-20); fixed nginx 1.30.4/1.31.3, NGINX Plus R36 P7/37.0.3.12026-07-202026-07-202026-07-20
CVE-2025-40947Siemens RUGGEDCOM ROX II feature-key gpgv command injection to root (CVSS 7.5); Unit 42 chain2026-07-182026-07-182026-07-18
CVE-2025-40948Siemens RUGGEDCOM ROX II arbitrary file disclosure via root-privileged xz misuse (CVSS 6.8); Unit 42 chain2026-07-182026-07-182026-07-18
CVE-2025-40949Siemens RUGGEDCOM ROX II task-scheduler command injection, persistent root (CVSS 9.1); Siemens SSA-0811422026-07-182026-07-182026-07-18
CVE-2026-47865VMware Avi Load Balancer control-plane unauthenticated authentication bypass (CVSS 9.8), VMSA-2026-00052026-07-182026-07-182026-07-18
CVE-2026-47866VMware Avi Load Balancer authorization bypass (CVSS 8.3), VMSA-2026-00052026-07-182026-07-182026-07-18
CVE-2026-47867VMware Avi Load Balancer high-privilege RCE (CVSS 8.7), VMSA-2026-00052026-07-182026-07-182026-07-18
CVE-2026-47868VMware Avi Load Balancer local privilege escalation to root (CVSS 7.8), VMSA-2026-00052026-07-182026-07-182026-07-18
CVE-2026-47869VMware Avi Load Balancer authenticated RCE (CVSS 8.7), VMSA-2026-00052026-07-182026-07-182026-07-18
CVE-2026-47870VMware Avi Load Balancer privilege escalation (CVSS 7.1), VMSA-2026-00052026-07-182026-07-182026-07-18
CVE-2026-47871VMware Avi Load Balancer authenticated directory traversal (CVSS 8.8), VMSA-2026-00052026-07-182026-07-182026-07-18
CVE-2026-54733Moodle local_o365 plugin JWT-signature-not-verified SSO auth bypass2026-07-182026-07-182026-07-18
CVE-2026-15718Mozilla Firefox WebAssembly engine invalid-pointer memory-safety flaw (public exploit code, no confirmed ITW); fixed 152.0.62026-07-172026-07-172026-07-17
CVE-2026-15719Mozilla Firefox DOM Navigation site-isolation bypass (public exploit code, no confirmed ITW); fixed 152.0.62026-07-172026-07-172026-07-17
CVE-2026-32201Microsoft SharePoint Server on-prem RCE — part of the actively-exploited SharePoint cluster (CISA KEV 2026-04-14), referenced as context in the CVE-2026-58644 exploitation update2026-07-172026-07-17
CVE-2026-58644CVE-2026-58644 — Microsoft SharePoint Server deserialization RCE (CVSS 9.8); confirmed exploited + CISA KEV 2026-07-162026-07-152026-07-172026-07-17 +1 more
CVE-2023-4346KNX Connection Authorization Option 1 overly-restrictive account-lockout DoS (CVSS 7.5, CWE-645); CISA KEV 2026-07-15, no software patch (procedural mitigation)2026-07-162026-07-162026-07-16
CVE-2026-46817Oracle E-Business Suite / Oracle Payments File Transmission unauthenticated RCE/takeover (CVSS 9.8); CISA KEV 2026-07-15, exploited ITW since 2026-06-27; fixed Oracle May 2026 CPU (12.2.3-12.2.15)2026-06-012026-07-162026-07-16 +1 more
CVE-2025-13162CVE-2025-13162 — ABB 800xA for Advant Master / Control Builder A: DLL search-path element (CVSS 4.4)2026-07-152026-07-15
CVE-2025-14771CVE-2025-14771 — ABB T-MAC Plus: authenticated file disclosure (CVSS 9.9)2026-07-152026-07-152026-07-15
CVE-2025-14772CVE-2025-14772 — ABB T-MAC Plus: broken access control / authz bypass (CVSS 8.8)2026-07-152026-07-152026-07-15
CVE-2025-14773CVE-2025-14773 — ABB T-MAC Plus: stored XSS (CVSS 8.0)2026-07-152026-07-152026-07-15
CVE-2025-14774CVE-2025-14774 — ABB T-MAC Plus: Card Reader service DoS (CVSS 7.4)2026-07-152026-07-152026-07-15
CVE-2026-10577CVE-2026-10577 — Rockwell 1715-AENTR EtherNet/IP Adapter: unauthenticated debug-port takeover (CVSS 10.0)2026-07-152026-07-152026-07-15
CVE-2026-55040CVE-2026-55040 — Microsoft SharePoint Server: JWT authentication bypass, Pwn2Own chain (CVSS 9.1)2026-07-152026-07-152026-07-15
CVE-2026-55944CVE-2026-55944 — Microsoft Dynamics NAV / Dynamics 365 Business Central (On-Prem): pre-auth deserialization RCE (CVSS 9.8)2026-07-152026-07-152026-07-15
CVE-2015-5281GRUB 2 Secure Boot bypass (historical) — cited by ESET/CERT/CC as an old bug reopened by pre-15.3 UEFI shims lacking SBAT (context in CVE-2026-8863/10797 entry)2026-07-142026-07-14
CVE-2026-10797Forgotten pre-0.9 UEFI shim signature-length validation mismatch (revocation-check vs signature-verification size divergence) — Secure Boot bypass; revoked via Microsoft dbx 2026-06-09 (ESET Research)2026-07-142026-07-142026-07-14
CVE-2026-2699Progress ShareFile Storage Zone Controller pre-auth authentication bypass (CVSS 9.8) — Shadowserver confirmed active in-the-wild exploitation 2026-07-10; fixed 5.12.42026-07-132026-07-142026-07-14 +1 more
CVE-2026-27690SAP Approuter unauthenticated HTTP request smuggling (CVSS 9.1)2026-07-142026-07-142026-07-14
CVE-2026-44747SAP NetWeaver AS ABAP kernel memory corruption (CVSS 9.9)2026-07-142026-07-142026-07-14
CVE-2026-44761SAP Commerce Cloud hardcoded sample OAuth2 credential (CVSS 9.1)2026-07-142026-07-142026-07-14
CVE-2026-56155Microsoft AD FS local elevation of privilege (exploited zero-day)2026-07-142026-07-142026-07-14
CVE-2026-56164Microsoft SharePoint Server unauthenticated elevation of privilege (exploited zero-day)2026-07-142026-07-142026-07-14
CVE-2026-8863Forgotten pre-0.9 UEFI shim trust-validation weakness (Secure Boot bypass on machines trusting the Microsoft third-party UEFI CA); revoked via Microsoft dbx 2026-06-09 (ESET Research)2026-07-142026-07-142026-07-14
CVE-2008-4128Cisco IOS (end-of-life devices) — named by the 2026-07-13 FSB Centre 16 joint advisory as an exploited legacy CVE; no patch (EOL)2026-07-132026-07-13
CVE-2018-0171Cisco IOS/IOS XE Smart Install pre-auth RCE — actively exploited by FSB Centre 16 / Static Tundra2026-07-132026-07-132026-07-13
CVE-2026-2701Progress ShareFile Storage Zone Controller — storage-repository web-shell RCE chained from CVE-2026-26992026-07-132026-07-132026-07-13
CVE-2026-4769WAGO I/O System Field — undocumented early-boot diagnostic interface, unauthenticated full compromise (CWE-912)2026-07-132026-07-132026-07-13
CVE-2026-61500Rejetto HFS < 3.2.1 predictable session-signing PRNG (Math.random) enables pre-auth admin session forgery to RCE via server_code (CVSS 9.3); fixed 3.2.12026-07-132026-07-132026-07-13
CVE-2026-61501Rejetto HFS 3.0.0–3.2.0 stored XSS in admin log via crafted failed-login username; fixed 3.2.12026-07-132026-07-132026-07-13
CVE-2026-61502Rejetto HFS 3.0.0–3.2.0 state-changing admin actions accepted over GET with no anti-CSRF check; fixed 3.2.12026-07-132026-07-132026-07-13
CVE-2026-61503Rejetto HFS 3.0.0–3.2.0 unauthenticated username enumeration (incl. default admin) via login-endpoint response differences; fixed 3.2.12026-07-132026-07-132026-07-13
CVE-2026-61504Rejetto HFS 3.0.0–3.2.0 stored XSS via unescaped filenames in fallback 'basic' listing; fixed 3.2.12026-07-132026-07-132026-07-13
CVE-2026-61505Rejetto HFS 3.0.0–3.2.0 path traversal via lang query parameter (limited JSON file read); fixed 3.2.12026-07-132026-07-132026-07-13
CVE-2026-10698Progress MOVEit Transfer Custom Reports table-scope bypass, admin-privileged (CVSS 7.2; CERT-FR AVI-0856)2026-07-112026-07-112026-07-11
CVE-2026-10699Progress MOVEit Transfer SFTP-service memory-leak pre-auth denial of service (CVSS 7.5; CERT-FR AVI-0856)2026-07-112026-07-112026-07-11
CVE-2026-11903Progress MOVEit Transfer Ad Hoc module stored XSS, low-priv authenticated (CVSS 8.0; CERT-FR AVI-0856)2026-07-112026-07-112026-07-11
CVE-2026-47291Windows HTTP.sys pre-auth kernel RCE (CVSS 9.8); ZDI published full exploitation mechanics + detection signature 2026-07-102026-06-102026-07-112026-07-11 +1 more
CVE-2026-57827Joomla RSFiles! (com_rsfiles) unauthenticated file-upload RCE (CVSS 4.0 10.0); part of the mySites.guru Joomla-extension CWE-434 wave2026-07-112026-07-112026-07-11
CVE-2026-57828Joomla Phoca Download (com_phocadownload) authenticated file-upload RCE via member-upload allow-list bypass (CVSS 4.0 9.0)2026-07-112026-07-112026-07-11
CVE-2026-60090PraisonAI PGVector/Cassandra knowledge store — SQL/CQL injection via unvalidated vector dimension (CVSS 9.3)2026-07-112026-07-112026-07-11
CVE-2026-61445PraisonAI AICoder — arbitrary file write / command execution via LLM tool calls (CVSS 9.4)2026-07-112026-07-112026-07-11
CVE-2026-61447PraisonAI CodeAgent — unsandboxed LLM-generated Python execution with full env-secret leak (CVSS 10.0)2026-07-112026-07-112026-07-11
CVE-2021-29441Apache Nacos authentication bypass (Nacos-Server User-Agent header) abused by WP-SHELLSTORM for Java-stack credential theft2026-07-102026-07-10
CVE-2025-5777CitrixBleed 2 (NetScaler ADC/Gateway pre-auth memory over-read) — weaponised in the STAC3725 IAB-to-DragonForce kill chain (Huntress)2026-07-012026-07-102026-07-10
CVE-2025-63681Open WebUI /api/tasks/stop/ IDOR — unauthorized task cancellation (unpatched)2026-07-102026-07-102026-07-10
CVE-2025-64496Open WebUI Direct Connections XSS chained to unsandboxed Python exec() → RCE2026-07-102026-07-102026-07-10
CVE-2026-1969WordPress ThemeREX Addons plugin vulnerability weaponized by the WP-SHELLSTORM crew2026-07-102026-07-10
CVE-2026-20896Gitea Docker reverse-proxy trust-all auth bypass (X-WEBAUTH-USER impersonation) — NCSC-CH escalated status to actively-exploited 2026-07-102026-06-232026-07-102026-07-10 +1 more
CVE-2026-3844WordPress Breeze Cache Cleaner plugin flaw — highest-yield exploit in the WP-SHELLSTORM webshell-brokerage campaign2026-07-102026-07-10
CVE-2026-44556Open WebUI /api/openai/responses proxy reaches any model without per-model authz2026-07-102026-07-102026-07-10
CVE-2026-44557Open WebUI incomplete collection allowlist exposes knowledge-base metadata to any user2026-07-102026-07-102026-07-10
CVE-2026-44564Open WebUI Socket.IO ydoc:document:update checks room membership not write permission2026-07-102026-07-102026-07-10
CVE-2026-48939iCagenda for Joomla — unauthenticated file-upload-to-RCE, exploited zero-day, CISA KEV2026-07-102026-07-102026-07-10
CVE-2026-54015Open WebUI prompt version-history IDOR (caller-supplied history-ID unauthorized)2026-07-102026-07-102026-07-10
CVE-2026-54798Siemens SICAM 8 HTTP-reachable debug interface → authenticated DoS2026-07-102026-07-102026-07-10
CVE-2026-54799Siemens SICAM 8 firmware-update signature-validation bypass → persistent malicious firmware2026-07-102026-07-102026-07-10
CVE-2026-54800Siemens SICAM 8 ships with OPC UA security disabled by default2026-07-102026-07-102026-07-10
CVE-2026-54801Siemens SICAM 8 web-API admin-account credential-validation bypass → privilege escalation2026-07-102026-07-102026-07-10
CVE-2024-42009Roundcube XSS — exploited by FrostyNeighbor / Ghostwriter (UNC1151) for Polish-targeting credential harvesting2026-05-172026-07-092026-07-09
CVE-2025-49113Roundcube Crypt_GPG_Engine PHP deserialization RCE - chained by UNK_MassTraction after CVE-2024-42009 XSS (Proofpoint)2026-07-092026-07-092026-07-09
CVE-2026-12486GeoVision GV-I/O Box 4E unauthenticated OS command injection (Talos, CVSS 9.1)2026-07-092026-07-092026-07-09
CVE-2026-12958AWS Language Servers / Amazon Q Developer symlink trust-boundary write outside workspace (GhostApproval, CWE-61); fixed language-servers 1.69.0 / @aws/lsp-codewhisperer 0.0.1172026-07-092026-07-092026-07-09
CVE-2026-13125GeoVision GeoWebPlayer unauthenticated localhost WebSocket screen-capture (Talos, CVSS 8.8)2026-07-092026-07-092026-07-09
CVE-2026-14480OpenPLC v3 Runtime authenticated arbitrary file-write to native RCE (CVSS 9.9; CISA ICSA-26-190-01, no fix)2026-07-092026-07-092026-07-09
CVE-2026-22879VTK-DICOM heap overflow on crafted DICOM file (Talos, CVSS 8.1)2026-07-092026-07-092026-07-09
CVE-2026-48614Plesk XML API code injection (CWE-94) — authenticated low-priv to arbitrary root file write / LPE (CVSS 9.9); CCB Belgium; affected <18.0.30, fixed 18.0.30-18.0.78.4 (18.0.79+ unaffected)2026-07-092026-07-092026-07-09
CVE-2026-50549Cursor IDE sandbox escape via symlink + failed path canonicalization (GhostApproval); fixed Cursor 3.02026-07-092026-07-092026-07-09
CVE-2026-50656Microsoft Defender Malware Protection Engine 'RoguePlanet' link-following LPE to SYSTEM - now fixed (engine >=1.1.26060.3008); NCSC-CH Nightmare Eclipse tracker2026-06-192026-07-092026-07-09 +2 more
CVE-2026-5263wolfSSL registeredID SAN name-constraint bypass (Talos, CVSS 7.4)2026-07-092026-07-092026-07-09
CVE-2026-53359Linux KVM/x86 'Januscape' shadow-MMU use-after-free — guest-to-host VM escape on Intel and AMD (public PoC host-DoS; RCE withheld); fixed 6.1.177/6.6.144/6.12.95/6.18.38/7.1.32026-07-092026-07-092026-07-09
CVE-2026-56291Balbooa Forms for Joomla (com_baforms) unauthenticated file-upload RCE (CWE-434, CVSS 4.0 10.0) — zero-day exploited pre-patch; 3rd Joomla-extension file-upload RCE in the 2026-06/07 wave2026-07-092026-07-092026-07-09
CVE-2026-6678wolfSSL PKCS#7 OtherRecipientInfo integer underflow -> heap overflow (Talos, CVSS 7.5)2026-07-092026-07-092026-07-09
CVE-2026-7532wolfSSL iPAddress SAN name-constraint bypass (Talos coordinated disclosure, CVSS 9.1)2026-07-092026-07-092026-07-09
CVE-2020-22653Ruckus wireless router flaw exploited by UAT-7810 for ORB initial access (context; Cisco Talos)2026-07-082026-07-08
CVE-2020-22658Ruckus wireless router flaw exploited by UAT-7810 for ORB initial access (context; Cisco Talos)2026-07-082026-07-08
CVE-2023-25717Ruckus wireless router flaw exploited by UAT-7810 for ORB initial access (context; Cisco Talos)2026-07-082026-07-08
CVE-2025-2492ASUS AiCloud router flaw exploited by UAT-7810 for ORB initial access (context; Cisco Talos)2026-07-082026-07-08
CVE-2026-20744Hydro-Quebec EV-charging OCPP WebSocket unauthenticated access -> privilege escalation (CVSS 9.8), CISA ICSA-26-188-012026-07-082026-07-082026-07-08
CVE-2026-33017Langflow unauthenticated RCE (build_public_tmp), CISA KEV, exploited in the Langflow IDOR chain2026-07-082026-07-082026-07-08
CVE-2026-40138BeyondTrust RS/PRA pre-auth authentication bypass (CVSS4 9.2), NCSC-CH BT26-032026-07-082026-07-082026-07-08
CVE-2026-40139BeyondTrust RS/PRA pre-auth authentication bypass (CVSS4 9.2), NCSC-CH BT26-032026-07-082026-07-082026-07-08
CVE-2026-40140BeyondTrust RS/PRA unauthenticated DoS (network-communication subsystem), BT26-032026-07-082026-07-082026-07-08
CVE-2026-40141BeyondTrust RS/PRA authenticated broken-access-control (resource access beyond scope), BT26-032026-07-082026-07-082026-07-08
CVE-2026-42952Hydro-Quebec EV-charging: no auth-attempt throttling -> DoS (CVSS 7.5), ICSA-26-188-012026-07-082026-07-082026-07-08
CVE-2026-43499GhostLock — Linux kernel rtmutex use-after-free LPE + container escape, public exploit2026-07-082026-07-082026-07-08
CVE-2026-44383Hydro-Quebec EV-charging: duplicate concurrent sessions per charge-point ID -> DoS (CVSS 7.5), ICSA-26-188-012026-07-082026-07-082026-07-08
CVE-2026-48282Adobe ColdFusion CWE-22 path-traversal RCE (CVSS 10.0), APSB26-68 — actively exploited, CISA KEV 2026-07-072026-07-022026-07-082026-07-08 +1 more
CVE-2026-48908JoomShaper SP Page Builder unauth file-upload RCE (CVSS 10.0), CISA KEV zero-day2026-07-082026-07-082026-07-08
CVE-2026-50746Ubiquiti UniFi Connect unauthenticated command-injection RCE (CVSS 10.0), SAB-0662026-07-082026-07-082026-07-08
CVE-2026-50747Ubiquiti UniFi Talk authenticated SQL injection (CVSS 9.9), SAB-0662026-07-082026-07-082026-07-08
CVE-2026-50748Ubiquiti UniFi Access command injection (CVSS 9.9), SAB-0662026-07-082026-07-082026-07-08
CVE-2026-54402Ubiquiti UniFi OS command injection (CVSS 9.9), SAB-0662026-07-082026-07-082026-07-08
CVE-2026-54403Ubiquiti UniFi OS path-traversal auth-bypass (CVSS 8.6), chainable, SAB-0662026-07-082026-07-082026-07-08
CVE-2026-55115Ubiquiti UniFi Protect SSRF privilege escalation (CVSS 9.9), SAB-0662026-07-082026-07-082026-07-08
CVE-2026-55255Langflow cross-tenant IDOR (CWE-639), actively exploited, CISA KEV — chained with RCE CVE-2026-330172026-07-082026-07-082026-07-08
CVE-2026-56290Joomlack Page Builder CK unauth file-upload RCE (CVSS 10.0), CISA KEV zero-day2026-07-082026-07-082026-07-08
CVE-2026-59509cve-search unauthenticated /fetch_cve_data parameter manipulation exposes admin credential hashes2026-07-052026-07-052026-07-05
CVE-2025-3248Langflow /api/v1/validate/code missing-auth RCE — initial access for the JADEPUFFER agentic ransomware operation2026-07-042026-07-042026-07-04
CVE-2026-13368WatchGuard Fireware OS iked pre-auth use-after-free RCE (IKEv2/LDAP path, CVSS 9.2)2026-07-032026-07-032026-07-03
CVE-2026-20191Cisco Catalyst Center unauthenticated path-traversal arbitrary file read (CVSS 7.5; dropped from §2, awareness only)2026-07-032026-07-03
CVE-2026-34038Coolify authenticated OS command injection to RCE + secrets exfil (CVSS 9.9)2026-07-032026-07-032026-07-03
CVE-2026-57517Control Web Panel pre-auth blind SQLi to web-shell RCE via INTO DUMPFILE (CVSS 9.8)2026-07-032026-07-032026-07-03
CVE-2026-14439Altium Enterprise Server / Altium 365 Git Service CWE-22 path-traversal to RCE (CVSS 9.4)2026-07-022026-07-022026-07-02
CVE-2026-45659Microsoft SharePoint Server CWE-502 deserialization RCE — authenticated Site Member (PR:L) can execute code over network; CVSS 8.8; NCSC.ch flagged 2026-05-26; § 7 drop (did not clear § 2 gates)2026-05-272026-07-022026-07-02
CVE-2026-48276Adobe ColdFusion CWE-434 unrestricted file-upload RCE (CVSS 10.0), APSB26-682026-07-022026-07-022026-07-02
CVE-2026-48277Adobe ColdFusion CWE-20 improper-input-validation RCE (CVSS 10.0), APSB26-682026-07-022026-07-022026-07-02
CVE-2026-48281Adobe ColdFusion CWE-20 improper-input-validation RCE (CVSS 10.0), APSB26-682026-07-022026-07-022026-07-02
CVE-2026-48283Adobe ColdFusion CWE-434 unrestricted file-upload RCE (CVSS 10.0), APSB26-682026-07-022026-07-022026-07-02
CVE-2026-48286Adobe Campaign Classic CWE-863 incorrect-authorization code execution (CVSS 10.0), APSB26-692026-07-022026-07-02
CVE-2026-48316Adobe ColdFusion CWE-20 improper-input-validation RCE (CVSS 10.0), APSB26-682026-07-022026-07-022026-07-02
CVE-2026-8037Progress Kemp LoadMaster pre-auth RCE — uninitialized malloc heap corruption in escape_quotes()/ /accessv2 to root (CVSS 9.8); fixed 7.2.63.22026-06-092026-07-022026-07-02 +1 more
CVE-2023-4966Citrix NetScaler ADC/Gateway 'CitrixBleed' session-token memory overread — cited as CVE-2026-8451 lineage context2026-07-012026-07-01
CVE-2025-12101Citrix NetScaler ADC/Gateway memory-leak (CitrixBleed variant) — cited as CVE-2026-8451 lineage context2026-07-012026-07-01
CVE-2026-10816Citrix NetScaler ADC/Gateway — Management Interface unauthenticated arbitrary file read (CTX696604)2026-07-012026-07-01
CVE-2026-10817Citrix NetScaler ADC/Gateway — memory overread when TCP TimeStamp enabled on LB/CS/VPN vserver (CTX696604)2026-07-012026-07-01
CVE-2026-13474Citrix NetScaler ADC/Gateway — CTX696604 companion CVE2026-07-012026-07-01
CVE-2026-35273Oracle PeopleSoft PeopleTools PSEMHUB pre-auth RCE (CVSS 9.8), zero-day exploited by UNC6240/ShinyHunters2026-06-122026-07-012026-07-01 +3 more
CVE-2026-8451Citrix NetScaler ADC/Gateway — pre-auth SAML AuthnRequest XML-parser memory overread (CitrixBleed lineage, CVSS 8.8), public PoC2026-07-012026-07-012026-07-01
CVE-2026-8452Citrix NetScaler ADC/Gateway — memory-management flaw (Gateway/DNS-proxy/AAA vserver), DoS/undefined control flow (CTX696604)2026-07-012026-07-01
CVE-2026-8655Citrix NetScaler ADC/Gateway — memory-management flaw (Gateway/DNS-proxy/AAA vserver), DoS/undefined control flow (CTX696604)2026-07-012026-07-01
CVE-2026-13165SzafirHost (KIR e-signature client) JAR parser confusion (JarFile vs JarInputStream, CWE-434) → native-library RCE past signature check; fixed v1.2.22026-06-302026-06-302026-06-30
CVE-2026-33691Progress Kemp LoadMaster — OWASP CRS whitespace-padding file-upload extension-check bypass (high); same bulletin as CVE-2026-80372026-06-092026-06-30
CVE-2026-43503Linux kernel 'DirtyClone' LPE — SKBFL_SHARED_FRAG drop in __pskb_copy_fclone() + IPsec in-place decrypt; JFrog working exploit on Debian/Ubuntu/Fedora (CVSS 8.8)2026-06-272026-06-302026-06-30 +2 more
CVE-2026-48558SimpleHelp RMM OIDC SSO auth bypass — forged-token full Technician session + MFA bypass; now actively exploited (CISA KEV 2026-06-29), Djinn infostealer via TaskWeaver loader (CVSS 10.0)2026-06-132026-06-302026-06-30 +1 more
CVE-2026-54305n8n Dynamic Credentials EE — missing ownership/scope checks enable cross-tenant OAuth credential hijack/revoke (CVSS 8.9, GHSA-2j5h-858j-5mpf); NCSC-2026-02122026-06-302026-06-30
CVE-2026-54307n8n public API — editor-level users read other users' credentials in shared instances (CVSS 8.5); NCSC-2026-02122026-06-302026-06-30
CVE-2026-55200libssh2 pre-auth heap OOB write in ssh2_transport_read() (CVSS 9.2) — public PoC released 2026-06-29; no fixed release tagged yet2026-06-282026-06-302026-06-30 +2 more
CVE-2025-67038Lantronix EDS5000 OS command injection to root (BRIDGE:BREAK; CISA KEV 2026-06-23)2026-06-242026-06-292026-06-29 +1 more
CVE-2026-10735ShapedPlugin WordPress Pro supply-chain backdoor (build/EDD pipeline compromise)2026-06-232026-06-292026-06-29 +1 more
CVE-2026-11800Keycloak JWT algorithm confusion -> federated-user impersonation (CVSS 8.1)2026-06-282026-06-292026-06-29 +1 more
CVE-2026-20230Cisco Unified Communications Manager WebDialer unauthenticated SSRF → OS-root file write (SIR Critical); fix 14SU6 / Release 15 COP2026-06-042026-06-292026-06-29 +2 more
CVE-2026-20245Cisco Catalyst SD-WAN Manager command-injection to root — Mandiant confirms pre-disclosure zero-day exploitation; patched (chains CVE-2026-20127/-20182)2026-06-012026-06-292026-06-29 +4 more
CVE-2026-34908Ubiquiti UniFi OS improper access control (chain step 1 to unauth root; CISA KEV 2026-06-23)2026-06-242026-06-292026-06-29 +1 more
CVE-2026-34909Ubiquiti UniFi OS path traversal (chain step 2 to unauth root; CISA KEV 2026-06-23)2026-06-242026-06-292026-06-29 +1 more
CVE-2026-34910Ubiquiti UniFi OS improper input validation/command injection to root (CISA KEV 2026-06-23, actively exploited)2026-06-242026-06-292026-06-29 +1 more
CVE-2026-46331Linux kernel 'pedit COW' LPE — tc act_pedit out-of-bounds write poisons setuid-binary page cache; public weaponised PoC2026-06-272026-06-292026-06-29 +1 more
CVE-2026-52806Gogs argument-injection RCE (CVE-2026-52806); now actively exploited in K8s cryptojacking campaign (Wiz)2026-06-142026-06-292026-06-29 +1 more
CVE-2026-55199libssh2 infinite-loop pre-auth DoS via crafted SSH_MSG_EXT_INFO (CVSS 8.2)2026-06-282026-06-292026-06-29 +1 more
CVE-2026-58053Gitea act_runner Docker container-hardening bypass to host escape (CVSS 9.4, public PoC)2026-06-282026-06-292026-06-29 +1 more
CVE-2026-9800Keycloak policy-enforcer authorization bypass via access-denied-page path (CVSS 8.1)2026-06-282026-06-292026-06-29 +1 more
CVE-2025-8088WinRAR path-traversal (referenced as initial-access exploit in Gamaredon GammaPhish/GammaWorm campaign, Sekoia 2026-06-01)2026-06-022026-06-282026-06-27 +3 more
CVE-2026-12789ILIAS 11.0 SQL injection in ilTrQuery learning-progress subsystem (no patch, PoC public)2026-06-232026-06-282026-06-23
CVE-2026-20262Cisco Catalyst SD-WAN Manager web UI authenticated path traversal — arbitrary file write to root RCE; CISA KEV 2026-06-152026-06-162026-06-282026-06-22 +1 more
CVE-2026-9099Keycloak group-admin to realm-admin privilege escalation2026-06-282026-06-28
CVE-2021-26855Microsoft Exchange Server SSRF (ProxyLogon) — cited in 2026-05-16 § 5 deep dive Background as precedent for on-prem Exchange exploitation pattern2026-05-162026-06-27
CVE-2023-32315Openfire admin-console path-traversal auth bypass — StrikeShark/SharkLoader initial-access vector2026-06-272026-06-27
CVE-2023-46747F5 BIG-IP TMUI unauthenticated RCE — StrikeShark/SharkLoader initial-access vector2026-06-272026-06-27
CVE-2024-21762Fortinet FortiOS SSL-VPN out-of-bounds write RCE — StrikeShark/SharkLoader initial-access vector2026-06-272026-06-27
CVE-2024-36401OSGeo GeoServer OGC-filter RCE — StrikeShark/SharkLoader initial-access vector2026-06-272026-06-27
CVE-2026-10712GitLab Web IDE workbench stored XSS (CVSS 8.0) — patched 19.1.1/19.0.3/18.11.6; assessed, did not clear §2 gate2026-06-262026-06-27
CVE-2026-12957Amazon Q Developer (VS Code) auto-loads workspace .amazonq/mcp.json without consent — repo-planted code execution + AWS credential theft2026-06-272026-06-272026-06-27
CVE-2026-20127Cisco Catalyst SD-WAN Manager pre-auth RCE (UAT-8616 prior exploitation, Feb 2026)2026-05-152026-06-272026-06-27 +1 more
CVE-2026-20182Cisco Catalyst SD-WAN Controller/Manager pre-auth authentication bypass (CVSS 10.0, actively exploited by UAT-8616)2026-05-112026-06-272026-06-27 +3 more
CVE-2026-43284Dirty Frag — Linux kernel xfrm-ESP page-cache write primitive, LPE (ITW, PoC public)2026-05-042026-06-272026-05-11 +1 more
CVE-2026-43500Dirty Frag — Linux kernel RxRPC page-cache write primitive, LPE chain (ITW, patch pending)2026-05-042026-06-272026-05-11 +1 more
CVE-2026-46300Fragnesia — Linux kernel xfrm ESP-in-TCP LPE (PoC public)2026-05-112026-06-272026-05-15 +1 more
CVE-2026-50751Check Point Security Gateway IKEv1 Remote Access/Mobile Access certificate-validation authentication bypass (CVSS 9.3) — actively exploited by Qilin affiliate since 2026-05-07, CISA KEV2026-06-092026-06-272026-06-22 +2 more
CVE-2026-10086GitLab EE Analytics Dashboard stored XSS (CVSS 8.7) — patched 19.1.1/19.0.3/18.11.6; assessed, did not clear §2 gate2026-06-262026-06-26
CVE-2026-12635GitLab repository-mirroring SSRF (CVSS 3.1) — patched 19.1.1/19.0.3/18.11.6; low severity, did not clear §2 gate2026-06-262026-06-26
CVE-2026-8461FFmpeg MagicYUV decoder heap OOB write (PixelSmash, CVSS 8.8) — fixed FFmpeg 8.1.2; out-of-window this run2026-06-262026-06-26
CVE-2026-39893Cacti <1.2.31 — pre-auth SQLi in graph_view.php (rfilter); evaluated, dropped to § 7 (out-of-window, single GHSA)2026-06-252026-06-25
CVE-2026-56422MISP <2.5.42 — broken access control2026-06-252026-06-252026-06-25
CVE-2026-56423MISP <2.5.42 — cross-org IDOR overwrite2026-06-252026-06-252026-06-25
CVE-2026-56424MISP <2.5.42 — broken access control, cross-org hard-delete2026-06-252026-06-252026-06-25
CVE-2026-56425MISP <2.5.42 — Azure-AD OAuth state-reuse session hijack2026-06-252026-06-252026-06-25
CVE-2026-56446MISP <2.5.42 — NDJSON log-injection PHP RCE (site-admin)2026-06-252026-06-252026-06-25
CVE-2026-56447MISP <2.5.42 — rdkafka plugin-load RCE (site-admin)2026-06-252026-06-252026-06-25
CVE-2026-7473Arista EOS tunnel-decapsulation logic flaw (CWE-1023) bypasses VXLAN segmentation; CISA KEV, exploited2026-06-102026-06-252026-06-10
CVE-2024-40766SonicWall SonicOS improper access control (mgmt + SSLVPN, Gen 5/6/7) — Akira/Fog ransomware on-ramp2026-06-232026-06-232026-06-23
CVE-2025-59718FortiGate credential-reuse vector referenced in FortiBleed campaign2026-06-232026-06-23
CVE-2025-59719FortiGate credential-reuse vector referenced in FortiBleed campaign2026-06-232026-06-23
CVE-2026-20779Gitea TOTP 2FA bypass (web TOCTOU + X-Gitea-OTP replay)2026-06-232026-06-23
CVE-2026-22874Gitea SSRF in webhook / repo-migration subsystems2026-06-232026-06-23
CVE-2026-24858FortiGate credential-reuse vector referenced in FortiBleed campaign2026-06-232026-06-23
CVE-2026-27775Gitea protected-branch enforcement race (single-push batch)2026-06-232026-06-23
CVE-2026-41947DifyTap — Dify AI platform cross-tenant authorization bypass (evaluated, dropped § 7: authenticated, no ITW, aggregator-only primary)2026-06-232026-06-23
CVE-2026-47645Microsoft 365 Copilot Business Chat open redirect (BSI WID-SEC-2026-2020; server-side mitigated, dropped § 7)2026-06-232026-06-23
CVE-2026-47729Squidbleed — 29-year-old heap over-read in Squid FTP gateway leaks cross-user HTTP credentials2026-06-232026-06-232026-06-23
CVE-2026-49777ShapedPlugin supply-chain backdoor — duplicate CVE submission for CVE-2026-10735 (noted § 7)2026-06-232026-06-23
CVE-2026-54130Microsoft 365 Copilot missing-authentication info disclosure (BSI WID-SEC-2026-2020; server-side mitigated, dropped § 7)2026-06-232026-06-23
CVE-2013-3307Linksys/D-Link RTL819X command-injection RCE — initial-access vector for the AryStinger botnet2026-06-222026-06-222026-06-22
CVE-2016-5681D-Link DIR-850L HTTP-service stack buffer overflow RCE — AryStinger botnet access vector2026-06-222026-06-222026-06-22
CVE-2025-11837QNAP Malware Remover code injection (fixed 6.6.8.20251023) — AryStinger NAS access vector2026-06-222026-06-222026-06-22
CVE-2025-13036Rockwell FactoryTalk Historian Site Edition — authentication bypass (CVSS 7.7)2026-06-182026-06-222026-06-22 +1 more
CVE-2026-0257PAN-OS GlobalProtect pre-auth authentication bypass2026-05-252026-06-222026-06-22 +4 more
CVE-2026-0646Rockwell 1794-AENTR/AENTRXT FLEX I/O — CIP-handling denial-of-service (CVSS 7.5)2026-06-182026-06-222026-06-22 +1 more
CVE-2026-0647Rockwell 1794-AENTR/AENTRXT FLEX I/O — unauthenticated web-interface password reset (CVSS 9.4)2026-06-182026-06-222026-06-22 +1 more
CVE-2026-11317Rockwell CompactLogix/ControlLogix 5370/5570 — CIP message major non-recoverable fault DoS (CVSS 7.5)2026-06-182026-06-222026-06-22 +1 more
CVE-2026-20181Cisco ISE / ISE-PIC — authenticated path-traversal OS command execution to root (CVSS 9.1)2026-06-192026-06-222026-06-22 +1 more
CVE-2026-20190Cisco ISE / ISE-PIC — unauthenticated read of sensitive data incl. hashed admin credentials (CVSS 7.5)2026-06-192026-06-222026-06-22 +1 more
CVE-2026-20253Splunk Enterprise pre-auth RCE via unauthenticated PostgreSQL sidecar REST API proxied by web tier, CVSS 9.82026-06-142026-06-222026-06-22 +2 more
CVE-2026-25089FortiSandbox unauthenticated OS command injection in VNC handler (CVSS 9.8); dropped from brief - no inclusion gate cleared2026-06-112026-06-222026-06-22 +2 more
CVE-2026-35278Oracle PeopleSoft PeopleTools 8.61/8.62 Performance Monitor — missing-auth RCE (CVSS 9.8)2026-06-182026-06-222026-06-22 +1 more
CVE-2026-39808Fortinet FortiSandbox — JRPC API OS command injection (CVSS 9.8); actively exploited2026-06-172026-06-222026-06-22 +1 more
CVE-2026-39813Fortinet FortiSandbox — JRPC API path traversal / auth bypass (CVSS 9.1); actively exploited2026-06-172026-06-222026-06-22 +1 more
CVE-2026-4020Gravity SMTP WordPress plugin unauthenticated info-disclosure (email-connector credential dump), mass-exploited2026-06-212026-06-222026-06-22 +1 more
CVE-2026-46978Oracle Solaris 11.4 Remote Administration Daemon — unauthenticated flaw (CVSS 10.0), Oracle June 2026 CSPU2026-06-182026-06-222026-06-22 +1 more
CVE-2026-48907Widget Factory Joomla Content Editor (JCE) <2.9.99.5 — unauthenticated profile-import to PHP RCE (CVSS v4 10.0); CISA KEV2026-06-172026-06-222026-06-22 +1 more
CVE-2026-54420LiteSpeed cPanel/WHM plugin symlink-following on CloudLinux/CageFS shared hosting; exploited ITW May 2026; CISA KEV2026-06-162026-06-222026-06-22 +1 more
CVE-2026-55803Drupal core — JSON:API PHP object injection (SA-CORE-2026-005, critical)2026-06-192026-06-222026-06-22 +1 more
CVE-2026-55804Drupal core — deserialization gadget chain (SA-CORE-2026-006)2026-06-192026-06-222026-06-22 +1 more
CVE-2023-24932Windows Boot Manager Secure Boot bypass (BlackLotus-class) — possible FishMonger SprySOCKS UEFI component (unconfirmed)2026-06-172026-06-21
CVE-2026-10795UpdraftPlus WordPress plugin unauthenticated auth-bypass to RCE (all-zero AES key on failed RSA decrypt), CVSS 8.1; actively exploited2026-06-142026-06-212026-06-14
CVE-2026-12046pgAdmin 4 — unauthenticated pickle.loads RCE primitive in SQL Editor (server mode, CVSS v4 9.5)2026-06-192026-06-212026-06-19
CVE-2026-2473Google Cloud Vertex AI SDK — predictable staging-bucket cross-tenant pickle RCE ('Pickle in the Middle'); patched 1.148.02026-06-172026-06-21
CVE-2026-40624AVer PTC500S/PTC115/PTC500+/PTC115+ cameras — unauthenticated RCE via management web interface (CVSS 9.8), CISA ICSA-26-169-012026-06-202026-06-212026-06-20
CVE-2026-42055NGINX — heap overflow in ngx_http_proxy_v2_module/ngx_http_grpc_module (CVSS v4 9.2)2026-06-192026-06-212026-06-19
CVE-2026-42530NGINX — HTTP/3 QUIC use-after-free in ngx_http_v3_module (CVSS v4 9.2)2026-06-192026-06-212026-06-19
CVE-2026-42824Microsoft 365 Copilot Enterprise Search 'SearchLeak' command-injection/info-disclosure; one-click exfil; patched server-side2026-06-162026-06-212026-06-16
CVE-2026-48611phpBB OAuth improper-authentication account hijack (admin) even when OAuth disabled; CVSS 9.8; fixed 3.3.172026-06-162026-06-212026-06-16
CVE-2026-12045pgAdmin 4 — AI Assistant read-only-transaction bypass to RCE via COPY TO PROGRAM (CVSS v4 9.4)2026-06-192026-06-192026-06-19
CVE-2026-12048pgAdmin 4 — stored XSS via unsanitised PostgreSQL error/EXPLAIN content (CVSS v4 9.3)2026-06-192026-06-192026-06-19
CVE-2026-55806Drupal core — rebuild.php trusted-host bypass (SA-CORE-2026-007)2026-06-192026-06-19
CVE-2026-55807Drupal core — Media module oEmbed SSRF (SA-CORE-2026-008)2026-06-192026-06-19
CVE-2026-55808Drupal core — JSON:API/REST image-upload MIME-validation gap (SA-CORE-2026-009)2026-06-192026-06-19
CVE-2020-25213WP File Manager pre-auth RCE — used as fallback vector in the ErrTraffic ClickFix framework2026-06-172026-06-17
CVE-2023-52271Topaz Antifraud wsftprm.sys vulnerable kernel driver — DragonForce BYOVD chain2026-06-172026-06-17
CVE-2025-1055K7 Security K7RKScan.sys vulnerable kernel driver — DragonForce BYOVD chain2026-06-172026-06-17
CVE-2025-55182React/Next.js Server Actions deserialisation ("React2Shell") — weaponised by PCPJack worm2026-05-102026-06-17
CVE-2025-61155Tower of Fantasy GameDriverx64.sys vulnerable kernel driver — DragonForce BYOVD chain2026-06-172026-06-17
CVE-2026-20251Splunk Secure Gateway jsonpickle deserialization RCE (CVSS 8.8) — assessed, no §2 gate (no ITW, post-auth); NCSC-NL advisory2026-06-162026-06-16
CVE-2026-40217LiteLLM Custom Code Guardrails sandbox escape to RCE via exec()/bytecode; CVSS 8.8; fixed v1.83.142026-06-162026-06-162026-06-16
CVE-2026-47101LiteLLM authorization bypass via unvalidated allowed_routes in key-generation; CVSS 8.8; fixed v1.83.142026-06-162026-06-162026-06-16
CVE-2026-47102LiteLLM privilege escalation — self-promote to proxy_admin via /user/update; CVSS 8.8; fixed v1.83.142026-06-162026-06-162026-06-16
CVE-2026-48612phpBB OAuth improper state verification + CSRF session hijack; CVSS 8.0; fixed 3.3.172026-06-162026-06-162026-06-16
CVE-2026-10087GitLab EE Analytics Dashboard stored XSS (CVSS 8.7) — assessed, no §2 gate2026-06-152026-06-15
CVE-2026-34182OpenSSL CMS AuthEnvelopedData integrity bypass (moderate) — assessed, out-of-window, not promoted2026-06-152026-06-15
CVE-2026-47124Traefik v3.x security-policy bypass (GHSA-3g6v-2r68-prfc) — assessed, no §2 gate, out-of-window2026-06-152026-06-15
CVE-2026-47928Adobe ColdFusion unauthenticated no-interaction RCE (CVSS 9.6, APSB26-64; scope change S:C; fixed 2023 Update 20 / 2025 Update 9)2026-06-152026-06-15
CVE-2026-47932Adobe ColdFusion path-traversal security-feature bypass (CVSS 8.8, APSB26-64) — co-disclosed; assessed, not promoted2026-06-152026-06-15
CVE-2026-7250GitLab CE/EE Grape API unauthenticated DoS (CVSS 7.5) — assessed, no §2 gate2026-06-152026-06-15
CVE-2026-9204GitLab CE/EE Gitaly repository-import SSRF (CVSS 5.3) — assessed, no §2 gate2026-06-152026-06-15
CVE-2020-17103Windows Cloud Filter driver cldflt.sys privilege escalation (MiniPlasma PoC)2026-05-182026-06-142026-05-25 +2 more
CVE-2022-38028Windows Print Spooler privilege escalation weaponised by APT28 GooseEgg (cited as historical context in Sekoia APT28 retrospective)2026-06-142026-06-14
CVE-2025-67644LangGraph SQLite checkpointer SQL injection in get_state_history() (CVSS 7.3; fixed langgraph-checkpoint-sqlite 3.0.1)2026-06-132026-06-142026-06-13
CVE-2026-10520Ivanti Sentry pre-auth OS command injection to root (MICS handleMessage), CVSS 10.0; public PoC by watchTowr2026-06-102026-06-142026-06-14 +1 more
CVE-2026-10523Ivanti Sentry authentication bypass (CWE-288), companion to CVE-2026-105202026-06-102026-06-142026-06-10
CVE-2026-11645Google Chrome V8 out-of-bounds read/write, exploited ITW, CISA KEV; fixed 149.0.7827.1032026-06-102026-06-142026-06-10
CVE-2026-12183BUK TS-G gas-station automation unauthenticated admin bypass, CVSS 9.8 (dropped from brief — aggregator-only sourcing)2026-06-142026-06-14
CVE-2026-23111Linux kernel nf_tables use-after-free in nft_map_catchall_activate() (single-character genmask inversion) — local-root + container escape, working public exploit (Exodus Intelligence), patched upstream 2026-02-05, CVSS 7.82026-06-092026-06-142026-06-09
CVE-2026-28277LangGraph unsafe msgpack deserialization on checkpoint load, chains with SQLi to RCE (CVSS 6.8; fixed langgraph 1.0.10)2026-06-132026-06-142026-06-13
CVE-2026-3300Everest Forms Pro (WordPress) Calculation Addon unauthenticated eval() PHP code injection (CVSS 9.8); mass exploitation since 2026-04-13 creating rogue admin accounts; patched v1.9.13 (2026-03-18)2026-06-082026-06-142026-06-08
CVE-2026-41089Windows Netlogon stack buffer overflow — unauthenticated remote RCE to SYSTEM on domain controllers (CVSS 9.8, May 2026 Patch Tuesday); active ITW exploitation confirmed by CCB Belgium 2026-06-012026-05-132026-06-142026-06-11 +3 more
CVE-2026-42271BerriAI LiteLLM MCP test endpoints command injection to host RCE (CVSS 8.8) — CISA KEV, actively exploited; unauthenticated when chained with CVE-2026-487102026-06-092026-06-142026-06-09
CVE-2026-44748SAP NetWeaver AS ABAP SAML XML Signature Wrapping (CVSS 9.9), SAP_BASIS 702-9192026-06-102026-06-142026-06-14 +1 more
CVE-2026-44963Veeam Backup & Replication 12.x authenticated domain-user deserialization RCE (CVSS 9.4); fixed 12.3.2.48542026-06-102026-06-142026-06-10
CVE-2026-45585Windows YellowKey BitLocker bypass via WinRE2026-05-182026-06-142026-05-30 +2 more
CVE-2026-45586Windows CTFMON elevation of privilege (June 2026 Patch Tuesday); referenced in § 7 GreenPlasma cross-source discrepancy note2026-06-112026-06-14
CVE-2026-45657Windows kernel TCP/IP use-after-free network RCE to SYSTEM (CVSS 9.8)2026-06-122026-06-142026-06-12
CVE-2026-47210vm2 Node.js sandbox escape via WebAssembly JSPI Promise-species bypass, CVSS 9.8 (dropped from brief — out-of-window, no ITW)2026-06-142026-06-14
CVE-2026-47344TYPO3 Core June 2026 (TYPO3-CORE-SA-2026-006) — XSS bypassing the HTML Sanitizer; lead CVE of the 13-advisory batch2026-06-102026-06-142026-06-10
CVE-2026-47895strongSwan libstrongswan identity-clone double-free, unauth RCE over EAP; fixed 6.0.72026-06-102026-06-142026-06-10
CVE-2026-49200Acer Wave-7 mesh router broken access control — unauthenticated cleartext credential log acer_cgi.log exposure (CVSS 10.0, no patch until ~end-June 2026)2026-06-082026-06-142026-06-08
CVE-2026-49201Acer Wave-7 mesh router hardcoded AES key in upload.cgi backup handler — persistent backdoor injection (CVSS 10.0, no patch until ~end-June 2026)2026-06-082026-06-142026-06-08
CVE-2026-49261MariaDB Server Galera wsrep_notify_cmd OS command injection (CVSS 10.0)2026-06-122026-06-142026-06-14 +1 more
CVE-2026-5027Langflow path traversal (POST /api/v2/files) -> arbitrary file write, pre-auth via default auto-login, exploited ITW2026-06-112026-06-142026-06-11
CVE-2026-27022LangGraph Redis checkpointer RediSearch query injection (CVSS 6.5; fixed @langchain/langgraph-checkpoint-redis 1.0.1)2026-06-132026-06-132026-06-13
CVE-2026-45447OpenSSL PKCS7_verify heap use-after-free on empty SignedData.digestAlgorithms (High; fixed 4.0.1/3.6.3/3.5.7/3.4.6/3.0.21) — out-of-window drop this run2026-06-132026-06-13
CVE-2026-6552GitLab EE Group SAML identity API improper authorization, Group Owner account takeover (CVSS 8.7; fixed 19.0.2/18.11.5/18.10.8) — did not clear daily section-2 gate2026-06-132026-06-13
CVE-2026-26142Nuance PowerScribe unauthenticated deserialization RCE (CVSS 9.8)2026-06-122026-06-122026-06-12
CVE-2026-47643Azure Stack Edge external file path control RCE (CVSS 9.8)2026-06-122026-06-122026-06-12
CVE-2026-48163MariaDB Galera wsrep parameter-injection (companion fix to CVE-2026-49261)2026-06-122026-06-122026-06-12
CVE-2026-48165MariaDB Galera wsrep parameter-injection (companion fix to CVE-2026-49261)2026-06-122026-06-122026-06-12
CVE-2026-48579Exchange Online improper-authorisation information disclosure (CVSS 9.1, service-side fix)2026-06-122026-06-122026-06-12
CVE-2026-35616Fortinet FortiClient EMS 7.4.5/7.4.6 — improper-access-control on X-SSL-CLIENT-VERIFY header lets unauth attacker spoof mTLS state and reach management API; ITW exploited to push EKZ Infostealer per Arctic Wolf 2026-05-272026-05-252026-06-112026-05-29 +1 more
CVE-2026-50507Windows BitLocker physical-access bypass, publicly disclosed, June 2026 Patch Tuesday2026-06-102026-06-112026-06-10
CVE-2026-22732SAP Commerce Cloud / Data Hub missing HTTP security headers via Spring Security (CVSS 9.1)2026-06-102026-06-102026-06-10
CVE-2026-27671SAP NetWeaver/ABAP RFC kernel memory corruption, unauthenticated (CVSS 9.8)2026-06-102026-06-102026-06-10
CVE-2026-40128SAP NetWeaver AS Java Web Container path traversal (CVSS 9.0)2026-06-102026-06-102026-06-10
CVE-2026-44815Windows DHCP Client Service RCE (CVSS 9.8), June 2026 Patch Tuesday2026-06-102026-06-102026-06-10
CVE-2026-47281Visual Studio Code EoP to SYSTEM via malicious .code-workspace (CVSS 9.6)2026-06-102026-06-102026-06-10
CVE-2026-49160Windows HTTP.sys HTTP/2 compression-bomb DoS (IIS analogue of CVE-2026-49975); MaxHeadersCount mitigation2026-06-102026-06-102026-06-10
CVE-2026-49975HTTP/2 Bomb — HPACK dynamic-table amplification + Slowloris stream-hold memory-exhaustion DoS vs nginx/Apache/IIS/Envoy/Pingora; nginx 1.29.8 & Apache mod_http2 2.0.41 patched, IIS/Envoy/Pingora unpatched at disclosure2026-06-012026-06-102026-06-04 +1 more
CVE-2026-48710Starlette/FastAPI host-header auth bypass (BadHost)2026-05-252026-06-092026-06-09 +2 more
CVE-2026-50752Check Point IKEv1 site-to-site VPN MitM via certificate validation weakness (CVSS 7.4) — no observed exploitation2026-06-092026-06-092026-06-09
CVE-2021-27137DD-WRT UPnP/SSDP parser stack buffer overflow — FortiGuard-attributed propagation vector for C0XMO/Gafgyt botnet; DOES NOT RESOLVE ON NVD/MITRE (flagged 2026-06-08, vendor-attributed/unverified)2026-06-082026-06-08
CVE-2026-10881Google Chrome ANGLE graphics engine out-of-bounds read/write → sandbox escape (CVSS 9.6); Chrome 149 record 429-patch release2026-06-072026-06-072026-06-07
CVE-2026-37977Keycloak CORS ACAO reflected from unverified JWT azp claim on UMA endpoint (fixed 26.6.3)2026-06-072026-06-072026-06-07
CVE-2026-39210FFmpeg parser/demuxer heap or stack overflow (depthfirst AI-agent discovery; PoC public, fixed upstream)2026-06-072026-06-072026-06-07
CVE-2026-39211FFmpeg parser/demuxer heap or stack overflow (depthfirst AI-agent discovery; PoC public, fixed upstream)2026-06-072026-06-072026-06-07
CVE-2026-39212FFmpeg parser/demuxer heap or stack overflow (depthfirst AI-agent discovery; PoC public, fixed upstream)2026-06-072026-06-072026-06-07
CVE-2026-39213FFmpeg parser/demuxer heap or stack overflow (depthfirst AI-agent discovery; PoC public, fixed upstream)2026-06-072026-06-072026-06-07
CVE-2026-39214FFmpeg parser/demuxer heap or stack overflow (depthfirst AI-agent discovery; PoC public, fixed upstream)2026-06-072026-06-072026-06-07
CVE-2026-39215FFmpeg parser/demuxer heap or stack overflow (depthfirst AI-agent discovery; PoC public, fixed upstream)2026-06-072026-06-072026-06-07
CVE-2026-39216FFmpeg parser/demuxer heap or stack overflow (depthfirst AI-agent discovery; PoC public, fixed upstream)2026-06-072026-06-072026-06-07
CVE-2026-39217FFmpeg parser/demuxer heap or stack overflow (depthfirst AI-agent discovery; PoC public, fixed upstream)2026-06-072026-06-072026-06-07
CVE-2026-39218FFmpeg parser/demuxer heap or stack overflow (depthfirst AI-agent discovery; PoC public, fixed upstream)2026-06-072026-06-072026-06-07
CVE-2026-4874Keycloak SSRF via OIDC token endpoint manipulation (fixed 26.6.3)2026-06-012026-06-072026-06-07 +1 more
CVE-2026-8830Keycloak missing server-side WebAuthn credential-registration validation (fixed 26.6.3)2026-06-072026-06-072026-06-07
CVE-2026-9704Keycloak token-exchange privilege escalation via silent subject_token removal (fixed 26.6.3)2026-06-012026-06-072026-06-07 +1 more
CVE-2026-9792Keycloak ROPC grant bypass of client-policy enforcement (fixed 26.6.3)2026-06-072026-06-072026-06-07
CVE-2026-9802Keycloak refresh-token replay window after server restart resets startupTime (fixed 26.6.3)2026-06-072026-06-072026-06-07
CVE-2026-10854MISP access-control bypass exposing private galaxy metadata to non-admin org users (CVSS 5.3)2026-06-062026-06-06
CVE-2026-10868MISP mass-assignment account-takeover in UsersController::edit() (CVSS 9.0, patched 2026-06-04)2026-06-012026-06-062026-06-06 +1 more
CVE-2026-28318SolarWinds Serv-U uncontrolled resource consumption — unauthenticated DoS via Content-Encoding: deflate (CISA KEV 2026-06-05)2026-06-062026-06-062026-06-06
CVE-2026-23479Redis use-after-free in unblockClientOnKey() → GOT-overwrite RCE (post-auth; default-passwordless)2026-06-052026-06-052026-06-05
CVE-2026-34906Simple SA Wirtualna Uczelnia unauthenticated SSTI → RCE (redirectToUrl)2026-06-052026-06-052026-06-05
CVE-2026-34907Simple SA Wirtualna Uczelnia reflected XSS (locale parameter)2026-06-052026-06-052026-06-05
CVE-2026-41283OpenStack Mistral policy-enforcement bypass → authenticated arbitrary code execution (OSSA-2026-020; evaluated and dropped — see brief §7)2026-06-052026-06-05
CVE-2026-10611MISP OTP bypass — session established in beforeFilter before OTP when LdapAuth.mixedAuth+require_otp both on; fix commit 39b3cb15 / >=2.5.372026-06-042026-06-042026-06-04
CVE-2026-33829Windows Snipping Tool ms-screensketch: URI handler NTLM hash leak — patched April 2026; cited as structural predecessor of unpatched search: URI variant2026-06-042026-06-04
CVE-2026-41100Microsoft 365 Copilot for Android OAuth-token theft via production debug flag (CVSS 4.4); patched 2026-05-122026-06-042026-06-042026-06-04
CVE-2026-41101Microsoft Word for Android OAuth-token theft via production debug flag (CVSS 7.1); patched 2026-05-122026-06-042026-06-042026-06-04
CVE-2026-41102Microsoft PowerPoint for Android OAuth-token theft via production debug flag (CVSS 7.1); patched 2026-05-122026-06-042026-06-042026-06-04
CVE-2026-42832Microsoft Excel for Android OAuth-token theft via setIsDebugMode(true) debug flag left in production (CVSS 7.7); patched 2026-05-122026-06-042026-06-042026-06-04
CVE-2026-45247Mirasvit Full Page Cache Warmer (Magento 2) unauthenticated PHP object-injection RCE via CacheWarmer cookie; CISA KEV 2026-06-03, ITW from 2026-04-24; fix v1.11.122026-06-042026-06-042026-06-04
CVE-2026-7195Progress Sitefinity CMS web-services improper input validation (CWE-20); BSI WID-SEC-2026-17832026-06-042026-06-04
CVE-2026-7198Progress Sitefinity CMS OData improper input validation (CVSS 9.8, CWE-20), affects 15.4.8623-15.4.8629; BSI WID-SEC-2026-17832026-06-042026-06-04
CVE-2026-7201Progress Sitefinity CMS ServiceStack web-services credential exposure (CVSS 8.8, CWE-522); BSI WID-SEC-2026-17832026-06-042026-06-04
CVE-2026-7312Progress Sitefinity CMS — CWE-522 Insufficiently Protected Credentials (Sitefinity Insight credential disclosure, gated on Insight integration/non-default config); CVSS 10.0 per NVD; BSI WID-SEC-2026-1783; evaluated 2026-06-04, dropped to §7 (no fetchable vendor primary, no ITW)2026-06-042026-06-04
CVE-2026-7313Progress Sitefinity CMS legacy-branch flaw (CVSS 8.7), affects v8.0-13.3; BSI WID-SEC-2026-17832026-06-042026-06-04
CVE-2026-7325Devolutions Server LDAP coercion exposing PAM credentials (DEVO-2026-0013, CVSS 7.1); evaluated 2026-06-04, dropped to §7 (no ITW, below §2 gate)2026-06-042026-06-04
CVE-2026-8181Burst Statistics WordPress 3.4.0-3.4.1.1 unauthenticated REST auth-bypass (is_mainwp_authenticated) → admin impersonation/rogue admin; actively exploited; fix v3.4.22026-06-042026-06-042026-06-04
CVE-2026-8206Kirki WordPress Freeform Page Builder 6.0.0-6.0.6 unauthenticated password-reset hijack → admin account takeover; actively exploited; fix v6.0.72026-06-042026-06-042026-06-04
CVE-2026-9047Devolutions Server MFA bypass via improper factor-key state handling (DEVO-2026-0013, CVSS 7.5); evaluated 2026-06-04, dropped to §7 (no ITW, below §2 gate)2026-06-042026-06-04
CVE-2020-1472ZeroLogon — Netlogon privilege escalation; chained by Cl0p in South Staffordshire Water 2020-2022 intrusion (cited in ICO 2026-05-11 enforcement)2026-05-122026-06-03
CVE-2022-0492Linux kernel cgroup v1 release_agent container escape (missing CAP_SYS_ADMIN check); CISA KEV 2026-06-022026-06-032026-06-032026-06-03
CVE-2024-21182Oracle WebLogic Server unauth T3/IIOP data access (CVSS 7.5); CISA KEV 2026-06-01 on active exploitation2026-06-022026-06-032026-06-03
CVE-2025-48595Android Framework integer-overflow LPE (no-interaction), limited targeted exploitation; June 2026 bulletin2026-06-032026-06-032026-06-03
CVE-2026-34926Trend Micro Apex One On-Premise relative path traversal fleet-wide code injection2026-05-222026-06-032026-05-22
CVE-2026-40402Windows Hyper-V UAF guest-to-host escape (May 2026 Patch Tuesday); evaluated 2026-06-03, not covered (out-of-window)2026-06-032026-06-03
CVE-2026-41096Windows DNS Client (dnsapi.dll) heap buffer overflow — RCE via malicious DNS response (CVSS 9.8, May 2026 Patch Tuesday)2026-05-132026-06-032026-05-13
CVE-2026-5426Digital Knowledge KnowledgeDeliver LMS — pre-shared ASP.NET machineKey ViewState deserialization RCE; exploited as zero-day pre-2026-02-242026-05-252026-06-032026-05-26 +1 more
CVE-2026-42251KAMSOFT KS-SOMED healthcare software — hardcoded FTP credentials in update client allow malicious-update injection / supply-chain (CVSS 4.0 8.7, CERT-PL)2026-06-022026-06-02
CVE-2026-44825Apache Solr 9.4.0-9.10.1/10.0.0 — hardcoded BasicAuth template credentials allow unauthenticated remote admin (CVSS 8.1, BSI WID-SEC-2026-1740); no patch yet, manual workaround2026-06-022026-06-022026-06-02
CVE-2026-46243CIFSwitch — Linux kernel CIFS/SMB-client LPE to root via forged cifs.spnego key requests (19-year-old bug; RHEL9/SLES15/Mint/Kali); dropped from 2026-06-02 brief as out-of-window + no Section 2 gate2026-06-022026-06-02
CVE-2026-8732WP Maps Pro WordPress plugin <=6.1.0 — unauthenticated admin-account creation via disclosed nonce + wp_ajax_nopriv_ handler; actively exploited (CVSS 9.8); fixed 6.1.12026-06-022026-06-022026-06-02
CVE-2026-8931Disig Web Signer 2.0.3-2.5.3 — unauthenticated RCE in Slovak eIDAS qualified-signature client (CVSS 4.0 9.4, SK-CERT); fixed 2.5.52026-06-022026-06-022026-06-02
CVE-2026-46818Oracle E-Business Suite — May 2026 CPU critical (referenced in §7, dropped)2026-06-012026-06-01
CVE-2026-46819Oracle E-Business Suite — May 2026 CPU critical (referenced in §7, dropped)2026-06-012026-06-01
CVE-2026-46820Oracle E-Business Suite — May 2026 CPU critical (referenced in §7, dropped)2026-06-012026-06-01
CVE-2026-46821Oracle E-Business Suite — May 2026 CPU critical (referenced in §7, dropped)2026-06-012026-06-01
CVE-2025-62582Delta Electronics DIAView SCADA — unauthenticated remote database access (predecessor to CVE-2026-9642 mitigation bypass)2026-05-272026-05-31
CVE-2026-26980Ghost CMS Content API unauthenticated SQLi (CVSS 9.4); ITW-exploited in ClickFix campaign; fixed 6.19.12026-05-252026-05-312026-05-25
CVE-2026-32996Veeam Agent for Microsoft Windows — local privilege escalation enabling arbitrary command execution / lateral movement (CVSS 7.3)2026-05-292026-05-312026-05-29
CVE-2026-32997Veeam Software Appliance (Linux) — authenticated Backup Administrator can write arbitrary files (CVSS 8.6)2026-05-292026-05-312026-05-29
CVE-2026-33384QuickCMS (OpenSolution) session fixation — CERT-PL; dropped (niche, CVSS 4.8)2026-05-312026-05-31
CVE-2026-33386QuickCMS (OpenSolution) MITM-XSS via HTTP plugin fetch — CERT-PL; dropped (niche, CVSS 2.3)2026-05-312026-05-31
CVE-2026-35087Slican PBX administrative protocol authentication bypass — attacker bypasses login by executing a specific command; CVSS 4.0: 9.3; CERT Polska disclosure 2026-05-272026-05-282026-05-312026-05-28
CVE-2026-35089Slican PBX deterministic secure-key generation from publicly-obtainable system properties — admin credentials recoverable without auth; CVSS 4.0: 8.7; CERT Polska2026-05-282026-05-312026-05-28
CVE-2026-35090Slican PBX remote management modem interface — hardcoded caller-ID bypasses admin auth and temporarily re-enables remote access when configured off; CVSS 4.0: 9.3; CERT Polska2026-05-282026-05-312026-05-28
CVE-2026-41052SUSE Rancher — project-owner role can flip namespace PSA labels to privileged, enabling container-to-host escape (CVSS 8.4)2026-05-292026-05-312026-05-29
CVE-2026-41053SUSE Rancher GitHub App auth — group principals granted for every team in GitHub org to any team-belonging user (CVSS 8.8)2026-05-292026-05-312026-05-29
CVE-2026-4408Samba SAMR RPC server — unauthenticated shell injection via %u substitution in check password script (CVSS 10.0)2026-05-252026-05-312026-05-29 +1 more
CVE-2026-4480Samba print-command subsystem — unauthenticated shell injection via %J substitution; raw/classic printing only (CVSS 10.0)2026-05-252026-05-312026-05-29 +1 more
CVE-2026-44848Portainer CE — Docker plugin endpoints not registered in proxy authorization handler; non-admin can install/enable plugins → root host execution (CVSS 9.4)2026-05-292026-05-312026-05-29
CVE-2026-44849Portainer CE Docker Swarm service API — EndpointSecuritySettings restrictions not enforced; non-admin escapes to host via privileged containers (CVSS 9.4)2026-05-292026-05-312026-05-29
CVE-2026-44939SUSE Rancher cluster-import endpoint — command injection via URL-encoded newline in authImage YAML field; control-plane node RCE (CVSS 9.6)2026-05-292026-05-312026-05-29
CVE-2026-4776Mautic API contact-filtering SQL injection (post-auth)2026-05-312026-05-312026-05-31
CVE-2026-48172LiteSpeed User-End cPanel plugin lsws.redisAble priv-esc to root (CVSS 10.0, ITW)2026-05-182026-05-312026-05-24 +1 more
CVE-2026-4868GitLab CE/EE Duo AI integration — improper user identity resolution allows authenticated user to impersonate another user when triggering Duo AI workflows (CVSS 8.2)2026-05-292026-05-312026-05-29
CVE-2026-48842Roundcube Webmail pre-auth SQL injection in virtuser_query plugin via preg_replace backslash escape bypass; CVSS 8.1; patched in 1.6.16 LTS / 1.7.12026-05-252026-05-312026-05-28 +1 more
CVE-2026-8992Ivanti Secure Access Client local privilege escalation2026-05-302026-05-312026-05-30
CVE-2026-9058Szafir SDK (KIR) improper certificate verification / auth bypass — Polish qualified e-signature SDK; fixed v4632026-05-262026-05-312026-05-26
CVE-2026-9170IBM HTTP Server / WebSphere Application Server — pre-auth RCE via improper input validation in HTTP request parser (CVSS 9.8); NCSC.ch flagged 2026-05-282026-05-252026-05-312026-05-29 +1 more
CVE-2026-9312GitHub Enterprise Server < 3.22 — unauthenticated SSRF via upload-endpoint path traversal exposes internal services and credentials (CVSS 4.0 = 9.2; GHSA-fwfp-h68w-2hcr)2026-05-272026-05-312026-05-27
CVE-2026-9557Mautic Focus component SSRF (post-auth; reaches internal/cloud-metadata)2026-05-312026-05-312026-05-31
CVE-2026-9558Mautic stored XSS (post-auth)2026-05-312026-05-312026-05-31
CVE-2026-9559Mautic stored XSS / JS injection (post-auth)2026-05-312026-05-312026-05-31
CVE-2026-9642Delta Electronics DIAView SCADA — incomplete fix / mitigation bypass of CVE-2025-62582 unauthenticated remote database access (CVSS 3.1 = 9.8; Tenable TRA-2026-44)2026-05-272026-05-312026-05-27
CVE-2026-9808Mautic file inclusion / path traversal (post-auth)2026-05-312026-05-312026-05-31
CVE-2026-9809Mautic path traversal / file manipulation (post-auth)2026-05-312026-05-312026-05-31
CVE-2026-9811Mautic JavaScript code injection (post-auth)2026-05-312026-05-312026-05-31
CVE-2024-39930Gogs prior argument-injection variant (referenced in Rapid7 2026-05-29 disclosure as same-class predecessor)2026-05-292026-05-29
CVE-2026-1402GitLab CE/EE — Wiki DoS via insufficient validation of malformed markup (CVSS 6.5)2026-05-292026-05-292026-05-29
CVE-2026-2601GitLab EE — Developer-role users can access deployment data (pipeline environment variables, deployment keys) via missing authorization checks (CVSS 4.3)2026-05-292026-05-292026-05-29
CVE-2026-26194Gogs argument-injection RCE (CVE id claimed by S3 sub-agent — unverified against authoritative NVD entry; Rapid7 publication states no CVE assigned at disclosure; deferred to next-run verification)2026-05-292026-05-29
CVE-2026-2710GitLab CE/EE — seventh CVE in 19.0.1 / 18.11.4 / 18.10.7 patch release (defender-relevance not enumerated; left to vendor page)2026-05-292026-05-29
CVE-2026-5296GitLab EE — Developer-role users can bypass group-level flow restrictions when foundational flows enabled (CVSS 4.3)2026-05-292026-05-292026-05-29
CVE-2026-6713GitLab CE/EE — unauthenticated enumeration of private project paths via API (CVSS 5.3)2026-05-292026-05-292026-05-29
CVE-2026-8716GitLab CE/EE — Authenticated users can access CI data from unintended reference types via incorrect reference resolution (CVSS 4.3)2026-05-292026-05-292026-05-29
CVE-2026-8834IBM HTTP Server Administration Server — heap-based buffer overflow (CVSS 8.0)2026-05-292026-05-29
CVE-2026-8850IBM HTTP Server mod_ibm_upload — DoS via NULL pointer dereference (CVSS 7.5)2026-05-292026-05-29
CVE-2026-8854IBM HTTP Server mod_mem_cache — DoS via expired pointer dereference (CVSS 7.5)2026-05-292026-05-29
CVE-2026-8855IBM HTTP Server — RCE in TLS mutual-authentication configurations (CVSS 8.1)2026-05-292026-05-29
CVE-2026-8856IBM HTTP Server — DoS via uncontrolled resource consumption (CVSS 7.7)2026-05-292026-05-29
CVE-2026-27771Gitea container registry access-control failure — private repo container images unauthenticatedly pullable across all versions < 1.26.2 (4-year exposure window); Forgejo confirmed affected; § 7 drop 2026-05-282026-05-282026-05-28
CVE-2026-42945NGINX ngx_http_rewrite_module heap buffer overflow (earlier of two May 2026 disclosures); exploitation attempts per NCSC-NL; § 7 drop (primary 2026-05-18 out-of-window)2026-05-152026-05-282026-05-18 +1 more
CVE-2026-45321TanStack Router npm credential-stealing payload — exfiltrated Nx contributor GitHub CLI OAuth token (precursor to CVE-2026-48027 Nx Console compromise); CISA KEV 2026-05-272026-05-222026-05-282026-05-28
CVE-2026-48027Nx Console v18.95.0 VS Code extension supply-chain compromise — credential-stealing payload harvested 1Password, Claude Code config, npm, GitHub, AWS creds; CISA KEV 2026-05-272026-05-282026-05-282026-05-28
CVE-2026-48843Roundcube Webmail CSS sanitisation failure via SVG animate attributeName=style — info disclosure / SSRF in HTML email rendering; patched in 1.6.16 LTS / 1.7.12026-05-282026-05-282026-05-28
CVE-2026-48844Roundcube Webmail code injection via LDAP autovalues option — arbitrary PHP code evaluation when option is configured; patched in 1.6.16 LTS / 1.7.12026-05-282026-05-282026-05-28
CVE-2026-48848Roundcube Webmail HTML sanitisation bypass via SVG document permitting CSS injection; patched in 1.6.16 LTS / 1.7.12026-05-282026-05-282026-05-28
CVE-2026-8398DAEMON Tools Lite signed-build trojanisation (12.5.0.2421–12.5.0.2434) via Disc Soft Limited build infrastructure; CISA KEV 2026-05-272026-05-282026-05-282026-05-28
CVE-2026-9256NGINX ngx_http_rewrite_module heap buffer overflow — out-of-bounds write in worker process memory pool via overlapping regex capture groups; CVSS v3.1 8.1 / v4.0 9.2; exploitation attempts per NCSC-NL; § 7 drop (primary 2026-05-22 out-of-window)2026-05-242026-05-28
CVE-2026-44895yoda-digital mcp-gitlab-server < 0.6.0 — no-auth SSE RPC endpoint bound to 0.0.0.0 with wildcard CORS exposes operator GitLab PAT (CVSS 4.0 = 9.2; GHSA-8jr5-6gvj-rfpf); noted in § 7 (niche package)2026-05-272026-05-27
CVE-2024-12802SonicWall Gen6 SSL-VPN MFA bypass via UPN vs SAM account-name split; Akira-linked actors exploited Feb-Mar 2026; firmware update insufficient without 6-step LDAP reconfiguration2026-05-182026-05-252026-05-21 +1 more
CVE-2024-55591FortiOS / FortiProxy authentication bypass — weaponised by 'The Gentlemen' RaaS initial access2026-05-102026-05-25
CVE-2025-32433Erlang SSH RCE (Cisco context) — confirmed by Check Point Research as initial-access CVE for The Gentlemen RaaS2026-05-172026-05-25
CVE-2025-34291Langflow CORS misconfiguration + SameSite=None refresh token theft2026-05-222026-05-252026-05-22
CVE-2026-0300Palo Alto PAN-OS Captive Portal unauthenticated root RCE (CVSS 9.3, ITW, KEV deadline 2026-05-09)2026-05-042026-05-252026-05-18 +4 more
CVE-2026-20223Cisco Secure Workload internal REST API zero-auth Site Admin CVSS 10.02026-05-182026-05-252026-05-22 +1 more
CVE-2026-2743SEPPmail Secure E-Mail Gateway — pre-auth path traversal in LFT /v1/file.app → arbitrary file write as nobody → RCE via /etc/syslog.conf overwrite2026-05-202026-05-252026-05-20
CVE-2026-31635Linux kernel RxGK rxgk_decrypt_skb() page-cache write (missing COW guard) — DirtyDecrypt LPE; affects Fedora / Arch / openSUSE Tumbleweed (CONFIG_RXGK=y)2026-05-202026-05-252026-05-20
CVE-2026-41091Microsoft Defender Malware Protection Engine — link-following EoP to SYSTEM (CWE-59); Engine ≤ 1.1.26030.3008; actively exploited2026-05-182026-05-252026-05-22 +2 more
CVE-2026-42096Sparx Pro Cloud Server — authenticated SQL injection via database API endpoint; PCS ≤ 6.12026-05-182026-05-252026-05-20 +1 more
CVE-2026-42097Sparx Pro Cloud Server — pre-auth bypass via model-parameter omission in POST binary blob → unauthenticated SQL query execution; CVSS4 9.32026-05-182026-05-252026-05-20 +1 more
CVE-2026-42098Sparx Enterprise Architect ≤ 17.1 — client-side RBAC bypass via EA client binary patch (CWE-603); CVSS4 8.72026-05-182026-05-252026-05-20 +1 more
CVE-2026-42099Sparx Pro Cloud Server WebEA — race condition in /data_api/dl_internal_artifact.php → RCE in web-server context (CWE-362); CVSS4 7.72026-05-182026-05-252026-05-20 +1 more
CVE-2026-42100Sparx Pro Cloud Server — malformed SQL crash (DoS); CWE-8352026-05-182026-05-252026-05-20 +1 more
CVE-2026-42231n8n self-hosted automation — xml2js prototype pollution (CWE-1321), root of authenticated-to-RCE chain via Git node SSH2026-05-192026-05-252026-05-19
CVE-2026-42822Microsoft Azure Local Disconnected Operations (ALDO) — CVSS 10.0 unauthenticated network elevation-of-privilege; MSRC Exploitation More Likely2026-05-182026-05-252026-05-21 +1 more
CVE-2026-43997vm2 Node.js sandbox — host-object access via BaseHandler.getPrototypeOf trap; sandbox escape to host context; CVSS 10.0; patched 3.11.02026-05-202026-05-252026-05-20
CVE-2026-45498Microsoft Defender Antivirus local DoS — exploited alongside CVE-2026-41091 in combined out-of-band engine update 4.18.26040.72026-05-182026-05-252026-05-22 +1 more
CVE-2026-45584Microsoft Defender Malware Protection Engine — heap-based buffer overflow over network → unauthenticated RCE in Defender process context; CVSS 8.12026-05-202026-05-252026-05-20
CVE-2026-45829ChromaDB Python FastAPI server pre-auth RCE via embedding-function model loading before auth check (CVSS 4.0 = 10.0; v1.5.9 unpatched at disclosure)2026-05-182026-05-252026-05-21 +1 more
CVE-2026-7507Keycloak OIDC login flow session fixation enabling account takeover (Keycloak 26.6.2; BSI WID-SEC-2026-1612 HIGH)2026-05-182026-05-252026-05-21 +1 more
CVE-2026-9082Drupal core highly-critical pre-auth SQL injection in database abstraction API on PostgreSQL backends; CISA KEV-listed 2026-05-22 (SA-CORE-2026-004)2026-05-182026-05-252026-05-23 +2 more
CVE-2025-9086Stormshield SNS remote DoS (CERTFR-2026-AVI-0631); dropped from §2, mentioned in §72026-05-242026-05-24
CVE-2026-33278NLnet Labs Unbound DNSSEC validator UAF (CVSS 9.8), fixed 1.25.12026-05-242026-05-242026-05-24
CVE-2026-3593ISC BIND 9 DoH use-after-free (CVSS 7.4), fixed 9.20.232026-05-242026-05-242026-05-24
CVE-2026-37979Keycloak OIDC token introspection endpoint does not enforce audience restriction; lightweight access tokens leak claims cross-client (Keycloak 26.6.2)2026-05-182026-05-242026-05-21 +1 more
CVE-2026-37982Keycloak execute-actions token replay enabling unauthorised WebAuthn / FIDO2 credential enrollment on victim account (Keycloak 26.6.2)2026-05-182026-05-242026-05-21 +1 more
CVE-2026-42944NLnet Labs Unbound heap overflow, default-config (CVSS 8.6), fixed 1.25.12026-05-242026-05-242026-05-24
CVE-2026-4630Keycloak Authorization Services Protection API cross-realm IDOR allowing realm-A authenticated attacker to access realm-B resources (Keycloak 26.6.2)2026-05-182026-05-242026-05-21 +1 more
CVE-2026-46333ssh-keysign-pwn — 9-year ptrace race in Linux kernel __ptrace_may_access() reaches root + SSH host-key exfiltration; four public Qualys exploits on default major distros2026-05-232026-05-242026-05-23
CVE-2026-5946ISC BIND 9 non-Internet CLASS DoS (CVSS 7.5), fixed 9.18.49/9.20.232026-05-242026-05-242026-05-24
CVE-2019-13272Linux kernel ptrace credential-window LPE (Jann Horn, 2019) — historical predecessor cited as background in 2026-05-23 CVE-2026-46333 deep dive2026-05-232026-05-23
CVE-2021-4034PwnKit — polkit pkexec local root (Qualys, 2022) — historical reference cited in 2026-05-23 CVE-2026-46333 deep dive as functional-equivalent outcome2026-05-232026-05-23
CVE-2023-4911Looney Tunables — glibc ld.so local privilege escalation (Qualys, 2023) — historical reference cited in 2026-05-23 CVE-2026-46333 deep dive as disclosure-pattern precedent2026-05-232026-05-23
CVE-2026-23652Microsoft Azure CVSS 10.0 cluster — server-side mitigated, no customer action required (MSRC May 2026)2026-05-222026-05-22
CVE-2026-40411Microsoft Azure CVSS 10.0 cluster — server-side mitigated, no customer action required (MSRC May 2026)2026-05-222026-05-22
CVE-2026-42823Microsoft Azure CVSS 10.0 cluster — server-side mitigated, no customer action required (MSRC May 2026)2026-05-222026-05-22
CVE-2026-42901Microsoft Entra ID / Azure CVSS 10.0 cluster — server-side mitigated, no customer action required (MSRC May 2026)2026-05-222026-05-22
CVE-2026-47280Microsoft Entra ID / Azure CVSS 10.0 cluster — server-side mitigated, no customer action required (MSRC May 2026)2026-05-222026-05-22
CVE-2017-7692SquirrelMail post-auth RCE — used by Webworm against Serbian government targets per ESET 2026-05-20 (initial-access probe after credential theft)2026-05-212026-05-21
CVE-2026-37978Keycloak admin evaluate-scopes endpoint cross-role PII leakage bypassing user-view permissions (Keycloak 26.6.2)2026-05-212026-05-212026-05-21
CVE-2026-6856Keycloak WebAuthn packed self-attestation acceptable-AAGUID policy bypass enabling enrolment of hardware tokens outside policy (Keycloak 26.6.2)2026-05-212026-05-212026-05-21
CVE-2026-26083Fortinet FortiSandbox unauthenticated RCE in Web UI (CWE-862, CVSS 9.1 vendor / 9.8 NVD) — pre-auth, patch in 4.4.9 / 5.0.2 / Cloud 5.0.6; Cloud 23/24 require migration2026-05-112026-05-202026-05-13 +1 more
CVE-2026-26956vm2 Node.js sandbox — symbol-to-string coercion TypeError sandbox bypass; patched 3.10.52026-05-202026-05-202026-05-20
CVE-2026-31431Copy Fail — Linux kernel algif_aead local privilege escalation (ITW, KEV)2026-05-042026-05-20
CVE-2026-43999vm2 NodeVM allow-list bypass — Module._load() reachable when child_process is explicitly permitted → OS command execution; CVSS 9.92026-05-202026-05-202026-05-20
CVE-2026-44005vm2 prototype pollution via attacker-controlled JS; CVSS 10.0; affects 3.9.6 – 3.10.5; patched 3.11.02026-05-202026-05-202026-05-20
CVE-2026-44006vm2 code injection via BaseHandler.getPrototypeOf; CVSS 10.0; patched 3.11.02026-05-202026-05-202026-05-20
CVE-2026-44008vm2 null-proto exception exploitation; CVSS 9.8; affects ≤ 3.11.1; patched 3.11.22026-05-202026-05-202026-05-20
CVE-2026-44009vm2 neutralizeArraySpeciesBatch() bypass via null-proto exception; CVSS 9.8; affects ≤ 3.11.1; patched 3.11.22026-05-202026-05-202026-05-20
CVE-2026-44128SEPPmail Secure Email Gateway — unauthenticated RCE via exposed GINAv2 test endpoints (CVSS 9.3)2026-05-042026-05-202026-05-11 +1 more
CVE-2026-44277Fortinet FortiAuthenticator unauthenticated RCE in management interface (CWE-284, CVSS 9.8) — pre-auth, patch in 6.5.7 / 6.6.9 / 8.0.32026-05-112026-05-202026-05-13 +1 more
CVE-2026-45185Exim 4.97–4.99.2 GnuTLS builds — BDAT/CHUNKING use-after-free (Dead.Letter), pre-auth RCE (CVSS 9.8, ENISA EUVD critical); fixed in Exim 4.99.32026-05-132026-05-202026-05-13
CVE-2026-41702VMware Fusion 25H2 (macOS) — TOCTOU SETUID race condition LPE (CVSS 7.8); dropped from § 2 in 2026-05-19 brief (did not clear inclusion gates)2026-05-192026-05-19
CVE-2026-42232n8n HTTP Request Node injection — companion amplifier to CVE-2026-42231 prototype-pollution chain2026-05-192026-05-192026-05-19
CVE-2026-44789n8n XML Node injection — companion amplifier to CVE-2026-42231 prototype-pollution chain2026-05-192026-05-192026-05-19
CVE-2026-44790n8n Git node SSH chain — terminal sink of CVE-2026-42231 prototype-pollution to RCE2026-05-192026-05-192026-05-19
CVE-2026-44791n8n XML Node injection — companion amplifier to CVE-2026-42231 prototype-pollution chain2026-05-192026-05-192026-05-19
CVE-2026-46351BigBlueButton bbb-web < 3.0.21 — insecure sessionToken generation (CWE-330) enables session hijack2026-05-192026-05-192026-05-19
CVE-2026-46353BigBlueButton bbb-web < 3.0.21 — presentationUploadExternalUrl API checksum bypass (CWE-284)2026-05-192026-05-192026-05-19
CVE-2026-46404BigBlueButton bbb-web < 3.0.23 — SSRF in presentation URL validation (CWE-918)2026-05-192026-05-192026-05-19
CVE-2023-33241Fireblocks GG18/GG20 Paillier missing-ZK-proof flaw (TSSHOCK class; cited as background-class for THORChain 2026-05-15 GG20 TSS exploit)2026-05-182026-05-18
CVE-2025-54518AMD-SB-7052 — Zen 2 µop-cache corruption / SoC isolation LPE (CVSS 7.3 CVSS 4.0)2026-05-162026-05-182026-05-16
CVE-2026-34260SAP S/4HANA Enterprise Search ABAP — authenticated SQL injection in SAP_BASIS 751–758 / 816 (CVSS 9.6)2026-05-112026-05-182026-05-13 +1 more
CVE-2026-34263SAP Commerce Cloud — unauthenticated arbitrary code execution via Spring Security misordering on cloud-config endpoint (CVSS 9.6, SAP Note 3733064)2026-05-112026-05-182026-05-13 +1 more
CVE-2026-41103Microsoft SSO Plugin for Jira/Confluence — unauthenticated Entra ID credential forgery (CVSS 9.1, More Likely exploitation)2026-05-132026-05-182026-05-13
CVE-2026-41225F5 BIG-IP iControl REST Manager-role authenticated RCE (May 2026 Quarterly Notification, CVSS 9.1)2026-05-172026-05-182026-05-17
CVE-2026-41553DHTMLX PDF Export Module — unauthenticated server-side JavaScript injection RCE (CVSS 4.0 score 10.0)2026-05-172026-05-182026-05-17
CVE-2026-44088KIR SzafirHost — JAR zip-polyglot signature-verification bypass enabling RCE in Polish qualified e-signature browser helper (CVSS 8.6)2026-05-112026-05-182026-05-17 +1 more
CVE-2026-44112OpenClaw / Clawdbot — OpenShell sandbox TOCTOU write escape (CVSS 9.6, Claw Chain)2026-05-162026-05-182026-05-16
CVE-2026-45691Nextcloud Server/Enterprise Server 2FA bypass via WebDAV pre-authenticated session token reuse2026-05-152026-05-18
CVE-2026-45793PHP Composer GitHub Actions token disclosure in error messages (fixed in 2.9.8 / 2.2.28)2026-05-152026-05-18
CVE-2026-7182DHTMLX Diagram export module — path traversal (CVSS 4.0 score 9.2)2026-05-172026-05-182026-05-17
CVE-2026-8043Ivanti Xtraction < 2026.2 external control of file name/path (CWE-73, CVSS 9.6) — arbitrary file read + HTML write to web tree; auth required2026-05-142026-05-182026-05-14
CVE-2023-38831WinRAR file-extension spoofing arbitrary code execution (cited as veteran exploit by Kaspersky Q1 2026 report)2026-05-102026-05-17
CVE-2025-33073RelayKing NTLM relay — post-access primitive used by The Gentlemen RaaS2026-05-172026-05-17
CVE-2025-69690Netgate pfSense Community Edition authenticated root RCE — vendor refuses to fix2026-05-112026-05-172026-05-11
CVE-2025-69691Netgate pfSense Community Edition authenticated root RCE companion to CVE-2025-69690 — vendor refuses to fix2026-05-112026-05-172026-05-11
CVE-2026-20122Cisco Catalyst SD-WAN companion CVE (exploited since March 2026)2026-05-152026-05-17
CVE-2026-20128Cisco Catalyst SD-WAN companion CVE (exploited since March 2026)2026-05-152026-05-17
CVE-2026-20133Cisco Catalyst SD-WAN companion CVE (exploited since March 2026)2026-05-152026-05-17
CVE-2026-33634Checkmarx Jenkins AST plugin backdoor (TeamPCP/UNC6780 supply-chain compromise, SANDCLOCK credential stealer, CVSS 9.4)2026-05-122026-05-172026-05-12
CVE-2026-34176F5 BIG-IP privilege escalation via misconfigured permissions (May 2026 Quarterly, CVSS 8.7)2026-05-172026-05-17
CVE-2026-40061F5 BIG-IP privilege escalation via misconfigured permissions (May 2026 Quarterly, CVSS 8.7)2026-05-172026-05-17
CVE-2026-40631F5 BIG-IP privilege escalation via misconfigured permissions (May 2026 Quarterly, CVSS 8.7)2026-05-172026-05-17
CVE-2026-40698F5 BIG-IP SSH password exposure in iControl REST audit logs (May 2026 Quarterly, CVSS 8.7)2026-05-172026-05-17
CVE-2026-41552DHTMLX PDF Export Module — path traversal via src attribute (CVSS 4.0 score 9.2)2026-05-172026-05-172026-05-17
CVE-2026-41953F5 BIG-IP iControl REST command injection (May 2026 Quarterly, CVSS 8.7)2026-05-172026-05-17
CVE-2026-42406F5 BIG-IP iControl REST command injection (May 2026 Quarterly, CVSS 8.7)2026-05-172026-05-17
CVE-2026-42898Microsoft Dynamics 365 On-Premises — authenticated code injection with scope change (CVSS 9.9, May 2026 Patch Tuesday)2026-05-132026-05-172026-05-13
CVE-2026-42924F5 BIG-IP iControl REST command injection (May 2026 Quarterly, CVSS 8.7)2026-05-172026-05-17
CVE-2026-42930F5 BIG-IP iControl REST command injection (May 2026 Quarterly, CVSS 8.7)2026-05-172026-05-17
CVE-2026-44113OpenClaw / Clawdbot — TOCTOU read escape / file disclosure (CVSS 7.7, Claw Chain)2026-05-162026-05-172026-05-16
CVE-2026-44115OpenClaw / Clawdbot — command-parser allowlist bypass (CVSS 8.8, Claw Chain)2026-05-162026-05-172026-05-16
CVE-2026-44118OpenClaw / Clawdbot — MCP loopback senderIsOwner privilege escalation (CVSS 7.8, Claw Chain)2026-05-162026-05-172026-05-16
CVE-2026-4670Progress MOVEit Automation unauthenticated authentication bypass (CVSS 9.8)2026-05-062026-05-17
CVE-2026-6073GitLab CE/EE — stored XSS in analytics dashboards (CVSS 8.7); cited as dropped from § 22026-05-172026-05-17
CVE-2026-6722PHP SOAP extension UAF in SOAP_GLOBAL(ref_map) (with companions CVE-2026-7261, CVE-2026-7262); patched in PHP 8.4.8 / 8.3.22 / 8.2.302026-05-112026-05-172026-05-11
CVE-2026-7261PHP SOAP companion to CVE-2026-6722; patched 2026-05-082026-05-112026-05-172026-05-11
CVE-2026-7262PHP SOAP companion to CVE-2026-6722; patched 2026-05-082026-05-112026-05-172026-05-11
CVE-2026-7377GitLab CE/EE — stored XSS in container registry virtual registry upstreams (CVSS 8.7); cited as dropped from § 22026-05-172026-05-17
CVE-2026-7481GitLab CE/EE — stored XSS in Jira integration (CVSS 8.7); cited as dropped from § 22026-05-172026-05-17
CVE-2021-34473Microsoft Exchange Server pre-auth RCE (ProxyShell) — cited in 2026-05-16 § 5 deep dive Background2026-05-162026-05-16
CVE-2023-42793JetBrains TeamCity authentication bypass — cited in 2026-05-16 § 3 SentinelOne CI/CD subversion case study2026-05-162026-05-16
CVE-2022-20775Cisco SD-WAN local privilege escalation (UAT-8616 version-downgrade re-exploitation technique)2026-05-152026-05-15
CVE-2026-33825BlueHammer — Windows zero-day by Nightmare Eclipse (confirmed ITW by Huntress, April 2026)2026-05-152026-05-15
CVE-2026-45690Nextcloud Server SQL injection in column-type parameter (Moderate)2026-05-152026-05-15
CVE-2026-8511Google Chrome CVE (mentioned in recency-dropped items, 2026-05-12)2026-05-152026-05-15
CVE-2026-8580Google Chrome CVE (mentioned in recency-dropped items, 2026-05-12)2026-05-152026-05-15
CVE-2022-41040Microsoft Exchange Server SSRF (ProxyNotShell) — cited as initial-access vector in 2026-05-14 FamousSparrow deep dive; chained with CVE-2022-410822026-05-142026-05-14
CVE-2022-41082Microsoft Exchange Server PowerShell remoting deserialization RCE (ProxyNotShell) — cited as initial-access vector in 2026-05-14 FamousSparrow deep dive; chained with CVE-2022-410402026-05-142026-05-14
CVE-2026-23819HPE ArubaOS AOS-10 stored XSS in web management interface (CVSS 8.8) — referenced in 2026-05-14 § 7 drop note (gate not cleared)2026-05-142026-05-14
CVE-2026-44211Cline kanban npm package cross-origin WebSocket hijack (CVSS 9.6) — referenced in 2026-05-14 § 7 drop note (out-of-window)2026-05-142026-05-14
CVE-2026-34259SAP Forecasting & Replenishment — authenticated OS-command injection (CVSS 8.2, SAP May 2026 patch day)2026-05-132026-05-13
CVE-2026-40361Microsoft Word Preview Pane RCE (CVSS 8.4, More Likely exploitation, May 2026 Patch Tuesday)2026-05-132026-05-13
CVE-2026-40364Microsoft Word Preview Pane RCE (CVSS 8.4, More Likely exploitation, May 2026 Patch Tuesday)2026-05-132026-05-13
CVE-2026-40366Microsoft Word Preview Pane RCE (CVSS 8.4, May 2026 Patch Tuesday)2026-05-132026-05-13
CVE-2026-40367Microsoft Word Preview Pane RCE (CVSS 8.4, May 2026 Patch Tuesday)2026-05-132026-05-13
CVE-2026-40478Earlier Thymeleaf CVE referenced in § 7 disambiguating the dropped Thymeleaf item; CSO Online article 2026-04-17 covered this CVE rather than CVE-2026-419012026-05-132026-05-13
CVE-2026-41901Thymeleaf SSTI sandbox bypass — referenced in § 7 explaining out-of-window drop (GHSA published 2026-04-29)2026-05-132026-05-13
CVE-2024-1708ConnectWise ScreenConnect path traversal — chained with CVE-2024-1709 by Kimsuky/Storm-1175; KEV deadline 2026-05-12 (out-of-window per § 7 of 2026-05-12 brief)2026-05-122026-05-12
CVE-2024-1709ConnectWise ScreenConnect authentication bypass (CVSS 10.0) — chained with CVE-2024-1708; cited as 2026-05-12 drop2026-05-122026-05-12
CVE-2026-0073Android adbd wireless ADB authentication bypass (CVSS 8.8, adjacent-network, public PoC 2026-05-11) — § 2 gate not cleared2026-05-122026-05-12
CVE-2026-5786Ivanti EPMM remote authenticated → administrative-access via improper access control (CVSS 8.8, May 2026 update)2026-05-042026-05-122026-05-10
CVE-2026-5787Ivanti EPMM on-prem improper certificate validation → pre-auth Sentry impersonation (CVSS 9.1, ITW, KEV chain)2026-05-042026-05-122026-05-10 +1 more
CVE-2026-5788Ivanti EPMM unauthenticated arbitrary method invocation (CVSS 7.0, May 2026 update)2026-05-042026-05-122026-05-10
CVE-2026-6973Ivanti EPMM on-prem admin API improper input validation → RCE (CVSS 7.2, ITW, KEV deadline 2026-05-10)2026-05-042026-05-122026-05-10 +1 more
CVE-2026-7821Ivanti EPMM — fourth companion CVE in May 2026 EPMM update (high-severity per BleepingComputer / SecurityWeek)2026-05-042026-05-122026-05-10
CVE-2017-11882Microsoft Office Equation Editor RCE (cited as veteran exploit by Kaspersky Q1 2026 exploit report)2026-05-102026-05-10
CVE-2018-0802Microsoft Office Equation Editor RCE (cited as largest-share detected exploit by Kaspersky Q1 2026 report)2026-05-102026-05-10
CVE-2023-35078Ivanti EPMM pre-auth API access (2023, exploited by APT29; cited as historical precedent in 2026-05-08 deep dive)2026-05-082026-05-10
CVE-2024-57726SimpleHelp RMM unauthenticated privilege escalation (ITW)2026-05-072026-05-10
CVE-2024-57728SimpleHelp RMM path traversal — unauthenticated file download (ITW)2026-05-072026-05-10
CVE-2024-7399Samsung MagicINFO 9 Server unauthenticated arbitrary file write → RCE (CVSS 8.8, ITW)2026-05-072026-05-10
CVE-2025-0283Ivanti EPMM critical (January 2025, state-actor exploitation; cited as historical precedent in 2026-05-08 deep dive)2026-05-082026-05-10
CVE-2025-29927Next.js middleware authorisation bypass via crafted header — weaponised by PCPJack worm2026-05-102026-05-10
CVE-2025-48703CentOS Web Panel FileManager shell injection — weaponised by PCPJack worm2026-05-102026-05-10
CVE-2025-68670xrdp pre-authentication stack buffer overflow → RCE2026-05-092026-05-102026-05-09
CVE-2025-9501W3 Total Cache PHP injection via mfunc comment processor — weaponised by PCPJack worm2026-05-102026-05-10
CVE-2026-1281Ivanti EPMM January 2026 critical — historical precedent cited in 2026-05-09 Ivanti UPDATE2026-05-092026-05-10
CVE-2026-1340Ivanti EPMM January 2026 critical companion — historical precedent cited in 2026-05-09 Ivanti UPDATE2026-05-092026-05-10
CVE-2026-1357WPVivid Backup unauthenticated file upload — weaponised by PCPJack worm2026-05-102026-05-10
CVE-2026-20034Cisco Unity Connection authenticated RCE in management API (CVSS 8.8, NATO NCSC discovery; logged § 7 — dropped from § 2, gate not cleared)2026-05-102026-05-10
CVE-2026-20035Cisco Unity Connection unauthenticated SSRF in default-enabled Web Inbox (CVSS 7.2; logged § 7 — dropped from § 2, gate not cleared)2026-05-102026-05-10
CVE-2026-21510Windows Shell LNK exploit predecessor — APT28 weaponised against Ukraine and EU; February 2026 patch left CVE-2026-32202 residual2026-05-042026-05-10
CVE-2026-23918Apache HTTP Server 2.4.66 HTTP/2 double-free — DoS and potential RCE (CVSS 8.8)2026-05-062026-05-10
CVE-2026-23926Zabbix frontend stored XSS in map element labels (CVSS 6.1)2026-05-072026-05-10
CVE-2026-23927Zabbix API confidentiality — unprivileged user can read admin host data (CVSS 5.3)2026-05-072026-05-10
CVE-2026-23928Zabbix frontend reflected XSS in host-group filter (CVSS 6.1)2026-05-072026-05-10
CVE-2026-25592Microsoft Semantic Kernel .NET SDK — unintended [KernelFunction] on SessionsPythonPlugin Download/UploadFileAsync → arbitrary file write → sandbox escape (CVSS 9.9)2026-05-042026-05-102026-05-10
CVE-2026-26030Microsoft Semantic Kernel Python SDK — prompt-injection-to-RCE via InMemoryVectorStore filter (CVSS 9.9, PoC public)2026-05-042026-05-102026-05-10
CVE-2026-28780Apache httpd mod_proxy_ajp heap overflow → remote crash / potential RCE (CVSS 7.5)2026-05-072026-05-10
CVE-2026-29201cPanel/WHM CVE cluster — dropped from § 3 (embargoed, gate not cleared)2026-05-042026-05-102026-05-10
CVE-2026-29202cPanel/WHM CVE cluster — dropped from § 3 (embargoed, gate not cleared)2026-05-042026-05-102026-05-10
CVE-2026-29203cPanel/WHM unsafe symlink handling — chmod abuse on arbitrary files (CVSS 8.8, second emergency TSR)2026-05-042026-05-102026-05-10
CVE-2026-32202Windows Shell protection mechanism failure → NTLM coercion / spoofing (CVSS 4.3, APT28 ITW, KEV deadline 2026-05-12)2026-05-042026-05-102026-05-08
CVE-2026-32305Traefik proxy mTLS bypass via fragmented TLS ClientHello2026-05-062026-05-10
CVE-2026-32312GLPI < 10.0.25 / 11.0.7 SSRF (CERTFR-2026-AVI-0551)2026-05-082026-05-102026-05-08
CVE-2026-33725Metabase Enterprise Java serialization → authenticated RCE (CVSS 8.8)2026-05-072026-05-10
CVE-2026-40108GLPI < 10.0.25 / 11.0.7 data integrity compromise (CERTFR-2026-AVI-0551)2026-05-082026-05-102026-05-08
CVE-2026-40981Spring Cloud Config Server Google Secrets Manager backend flaw (HIGH)2026-05-092026-05-10
CVE-2026-40982Spring Cloud Config Server pre-auth directory traversal (CVSS 9.8)2026-05-092026-05-102026-05-09
CVE-2026-41002Spring Cloud Config Server companion CVE (HIGH)2026-05-092026-05-10
CVE-2026-41004Spring Cloud Config Server companion CVE (MEDIUM)2026-05-092026-05-10
CVE-2026-41940cPanel/WHM authentication bypass via CRLF injection (mass exploitation ongoing, KEV)2026-05-062026-05-10
CVE-2026-42208LiteLLM Proxy pre-auth SQL injection — all upstream LLM API keys at risk (CVSS 9.3, KEV deadline 2026-05-11)2026-05-042026-05-102026-05-09
CVE-2026-42317GLPI < 10.0.25 / 11.0.7 XSS (CERTFR-2026-AVI-0551)2026-05-082026-05-102026-05-08
CVE-2026-42318GLPI < 10.0.25 / 11.0.7 XSS (CERTFR-2026-AVI-0551)2026-05-082026-05-102026-05-08
CVE-2026-42320GLPI < 10.0.25 / 11.0.7 XSS (CERTFR-2026-AVI-0551)2026-05-082026-05-102026-05-08
CVE-2026-42321GLPI < 10.0.25 / 11.0.7 XSS (CERTFR-2026-AVI-0551)2026-05-082026-05-102026-05-08
CVE-2026-44125SEPPmail GINAv2 — missing authentication in admin REST API (CVSS 9.3)2026-05-042026-05-102026-05-09
CVE-2026-44126SEPPmail GINAv2 — insecure deserialisation via session cookie → RCE (CVSS 9.2)2026-05-042026-05-102026-05-09
CVE-2026-44127SEPPmail appliance management — LFI and arbitrary file deletion (CVSS 8.8)2026-05-042026-05-102026-05-09
CVE-2026-44129SEPPmail GINAv2 — server-side template injection via Freemarker (CVSS 8.3)2026-05-042026-05-102026-05-09
CVE-2026-5174Progress MOVEit Automation authenticated privilege escalation (CVSS 8.8)2026-05-062026-05-10
CVE-2026-5385GLPI < 10.0.25 / 11.0.7 security policy bypass / auth bypass (CERTFR-2026-AVI-0551)2026-05-082026-05-102026-05-08
CVE-2026-6022Progress Telerik RadAsyncUpload DoS via path traversal (CVSS 7.5)2026-05-072026-05-10
CVE-2026-6023Progress Telerik RadFilter deserialization → unauthenticated RCE (CVSS 9.8)2026-05-072026-05-10
CVE-2026-7864SEPPmail appliance management — information disclosure (CVSS 6.9)2026-05-042026-05-102026-05-09
CVE-2026-25077Apache CloudStack post-auth authentication token flaw — dropped from § 3 (gate not cleared)2026-05-092026-05-09
CVE-2026-21509Microsoft Office Protected View bypass — security feature bypass (CVSS 7.8, KEV deadline 2026-02-16 already passed; deferred from §4)2026-05-082026-05-08
CVE-2026-21513Microsoft Office Protected View chain CVE (deferred from §4; see CVE-2026-21509 series)2026-05-082026-05-08
CVE-2026-21514Microsoft Office Protected View chain CVE (deferred from §4; see CVE-2026-21509 series)2026-05-082026-05-08