Actively exploited vulnerabilities
Sourced from CISA's Known Exploited Vulnerabilities catalog. Each entry explains what the flaw affects and the defensive action to take.
- CVE-2026-86060 — MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command VulnerabilityMikroTikAdded 2026-09-10
- CVE-2026-67277 — MikroTik RouterOS Missing Authentication for Critical Function VulnerabilityMikroTikAdded 2026-09-10
- CVE-2026-19490 — Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel VulnerabilityCitrixAdded 2026-09-09
- CVE-2025-25249 — Fortinet Multiple Products Heap-based Buffer Overflow VulnerabilityFortinetAdded 2026-09-09
- CVE-2026-87491 — Google Chromium V8 Out of Bounds Write VulnerabilityGoogleAdded 2026-09-09
- CVE-2026-20079 — Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel VulnerabilityCiscoAdded 2026-09-09
- CVE-2026-75650 — Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine VulnerabilityAdobeAdded 2026-09-08
- CVE-2026-81963 — Microsoft Windows Link Following VulnerabilityMicrosoftAdded 2026-09-08
- CVE-2026-86218 — N-able N-central Static Code Injection VulnerabilityN-ableAdded 2026-09-08
- CVE-2026-85880 — Microsoft Windows Heap-Based Buffer Overflow VulnerabilityMicrosoftAdded 2026-09-08
- CVE-2026-85046 — Google Chromium V8 Type Confusion VulnerabilityGoogleAdded 2026-09-04
- CVE-2026-59822 — BerriAI LiteLLM Improper Authentication VulnerabilityBerriAIAdded 2026-09-02
- CVE-2026-48710 — Kludex Starlette HTTP Request/Response Smuggling VulnerabilityKludexAdded 2026-09-02
- CVE-2026-49869 — Kestra OSS OS Command Injection VulnerabilityKestraAdded 2026-09-02
- CVE-2026-82329 — JFrog Artifactory Improper Authentication VulnerabilityJFrogAdded 2026-09-02
- CVE-2026-9586 — Sangoma Switchvox SQL Injection VulnerabilitySangomaAdded 2026-09-02
- CVE-2026-83548 — SonicWall SMA1000 Appliances Server-Side Request Forgery VulnerabilitySonicWallAdded 2026-09-02
- CVE-2026-83549 — SonicWall SMA1000 Appliances OS Command Injection VulnerabilitySonicWallAdded 2026-09-02
- CVE-2026-82078 — PaperCut NG/MF Unsafe Reflection VulnerabilityPaperCutAdded 2026-08-31
- CVE-2026-81578 — PaperCut NG/MF Missing Authentication for Critical Function VulnerabilityPaperCutAdded 2026-08-31
- CVE-2023-49105 — ownCloud Improper Authentication VulnerabilityownCloudAdded 2026-08-27
- CVE-2026-53362 — Linux Kernel Unspecified VulnerabilityLinuxAdded 2026-08-27
- CVE-2026-66384 — JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory VulnerabilityJFrogAdded 2026-08-27
- CVE-2021-23758 — Ajax.NET Professional Deserialization of Untrusted Data VulnerabilityAjax.NET ProfessionalAdded 2026-08-26
- CVE-2015-3246 — Red Hat Libuser Race Condition VulnerabilityRed HatAdded 2026-08-26
- CVE-2015-5287 — Red Hat Automatic Bug Reporting Tool Privilege Escalation VulnerabilityRed HatAdded 2026-08-26
- CVE-2022-0995 — Linux Kernel Out-of-Bounds Write VulnerabilityLinuxAdded 2026-08-26
- CVE-2026-8452 — Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer VulnerabilityCitrixAdded 2026-08-26
- CVE-2019-1068 — Microsoft SQL Server Remote Code Execution VulnerabilityMicrosoftAdded 2026-08-26
- CVE-2026-60004 — Gitea Code Injection VulnerabilityGiteaAdded 2026-08-25
- CVE-2026-21962 — Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control VulnerabilityOracleAdded 2026-08-24
- CVE-2026-73570 — Zimbra Collaboration Suite (ZCS) OS Command Injection VulnerabilitySynacorAdded 2026-08-21
- CVE-2026-72530 — TrueConf Server Code Injection VulnerabilityTrueConfAdded 2026-08-20
- CVE-2026-72529 — TrueConf Server Missing Authentication for Critical Function VulnerabilityTrueConfAdded 2026-08-20
- CVE-2026-64849 — MLflow Server-Side Request Forgery VulnerabilityMLflowAdded 2026-08-19
- CVE-2026-33824 — Microsoft Internet Key Exchange (IKE) Service Extensions Double Free VulnerabilityMicrosoftAdded 2026-08-18
- CVE-2026-59310 — Broadcom VMware vCenter Path Traversal VulnerabilityBroadcomAdded 2026-08-18
- CVE-2026-55040 — Microsoft SharePoint Weak Authentication VulnerabilityMicrosoftAdded 2026-08-18
- CVE-2026-65400 — Apple macOS Improper Authentication VulnerabilityAppleAdded 2026-08-18
- CVE-2025-62593 — Ray-Project Ray Code Injection VulnerabilityRay-ProjectAdded 2026-08-17
- CVE-2026-20349 — Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection VulnerabilityCiscoAdded 2026-08-11
- CVE-2026-68820 — Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free VulnerabilityMicrosoftAdded 2026-08-11
- CVE-2026-72898 — Metabase SQL Injection VulnerabilityMetabaseAdded 2026-08-11
- CVE-2026-8037 — Progress LoadMaster Command Injection VulnerabilityProgressAdded 2026-08-07
- CVE-2026-63077 — JetBrains TeamCity Deserialization of Untrusted Data VulnerabilityJetBrainsAdded 2026-08-05
- CVE-2026-18556 — N-able N-central Authentication Bypass Using an Alternate Path or Channel VulnerabilityN-ableAdded 2026-08-04
- CVE-2026-34486 — Apache Tomcat Missing Encryption of Sensitive Data VulnerabilityApacheAdded 2026-08-04
- CVE-2026-9198 — IBM Langflow Code Injection VulnerabilityIBMAdded 2026-08-04
- CVE-2026-18577 — N-able N-central Authentication Bypass Using an Alternate Path or Channel VulnerabilityN-ableAdded 2026-08-03
- CVE-2026-20316 — Cisco Secure Firewall Management Center Use of Hard-coded Password VulnerabilityCiscoAdded 2026-07-29ransomware use
- CVE-2025-68686 — Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor VulnerabilityFortinetAdded 2026-07-27
- CVE-2026-16812 — Arista VeloCloud Orchestrator On-Prem OS Command Injection VulnerabilityAristaAdded 2026-07-27
- CVE-2026-16232 — Check Point SmartConsole Improper Authentication VulnerabilityCheck PointAdded 2026-07-22
- CVE-2026-50522 — Microsoft SharePoint Deserialization of Untrusted Data Vulnerability MicrosoftAdded 2026-07-22
- CVE-2026-60137 — WordPress Core SQL Injection VulnerabilityWordPressAdded 2026-07-21
- CVE-2026-63030 — WordPress Core Interpretation Conflict VulnerabilityWordPressAdded 2026-07-21
- CVE-2026-0770 — Langflow Inclusion of Functionality from Untrusted Control Sphere VulnerabilityLangflowAdded 2026-07-21
- CVE-2021-27137 — DD-WRT Stack-Based Buffer Overflow VulnerabilityDD-WRTAdded 2026-07-21
- CVE-2026-58644 — Microsoft SharePoint Deserialization of Untrusted Data VulnerabilityMicrosoftAdded 2026-07-16
- CVE-2026-25089 — Fortinet FortiSandbox OS Command Injection VulnerabilityFortinetAdded 2026-07-16