CISA Known Exploited Vulnerabilities

Every entry here is confirmed to be exploited in the wild — this is the patch-first list, not a theoretical risk register. Newest first, free to read, no account needed.

KEV entries tracked
1721
Linked to ransomware
12
Showing
120

CVE-2026-93952

CriticalArista · VeloCloud OrchestratorAdded 2d ago

This vulnerability is confirmed exploited in the wild and could let a remote attacker reach privileged internal functions, potentially taking control of the orchestrator and the data it manages. Treat internet-exposed VCO systems as urgent because confidentiality, integrity, and availability may all be affected.

Federal remediation due 9/25/2026

CVE-2026-85102

CriticalCheck Point · Multiple ProductsAdded 2d ago

This vulnerability is confirmed exploited in the wild and could let an unauthenticated attacker remotely run code on affected VPN-enabled gateways or firewalls. A compromised gateway can expose or disrupt traffic across your network.

Federal remediation due 9/25/2026

CVE-2026-94127

CriticalF5 · BIG-IP APMAdded 2d ago

This is an actively exploited remote code execution flaw in BIG-IP APM. An unauthenticated attacker could take control of affected systems when an access policy and OAuth profile are configured on a virtual server.

Federal remediation due 9/25/2026

CVE-2026-93616

CriticalCheck Point · Multiple ProductsAdded 2d ago

This is being actively exploited and can let an unauthenticated attacker upload and run arbitrary scripts on affected management and logging systems. Treat any internet-exposed affected system as urgent because compromise could give an attacker control over critical security infrastructure.

Federal remediation due 9/25/2026

CVE-2026-7273

CriticalZyxel · GS1900 Series SwitchesAdded 3d ago

Someone on your network could send a crafted web request to an affected switch and potentially run operating-system commands without logging in. It is listed in CISA's Known Exploited Vulnerabilities catalog, so treat exposed or reachable switches as urgent.

Federal remediation due 9/24/2026

CVE-2025-39964

CriticalLinux · KernelAdded 6d ago

This flaw can let someone on a system cause unpredictable data handling and internal socket-state problems when applications use AF_ALG sockets. It is listed as actively exploited, so affected Linux systems should be treated as urgent even though the reported 30-day exploitation probability is low.

Federal remediation due 9/21/2026

CVE-2025-39682

CriticalLinux · KernelAdded 6d ago

This Linux kernel TLS receive-path flaw is listed in CISA’s Known Exploited Vulnerabilities catalog, so it may be actively used against vulnerable systems. It could cause TLS records to be handled incorrectly, with risk depending on how your systems use kernel TLS.

Federal remediation due 9/21/2026

CVE-2026-53266

CriticalLinux · KernelAdded 6d ago

This Linux kernel flaw can allow a crafted network packet to corrupt kernel memory, which may lead to a system crash or potentially higher-level compromise. It is listed by CISA as actively exploited, so affected systems should be treated as urgent even though the reported EPSS score is low.

Federal remediation due 9/21/2026

CVE-2026-87886

CriticalAcronis · BackupAdded 8d ago

This flaw could let someone gain higher permissions on servers using the Acronis Backup plugin for cPanel & WHM or extension for Plesk. It is listed in CISA's Known Exploited Vulnerabilities catalog, so treat affected internet-exposed systems as urgent.

Federal remediation due 9/19/2026

CVE-2026-76460

CriticalCisco · Identity Services EngineAdded 8d ago

This vulnerability is being exploited in the wild and could let an unauthenticated remote attacker bypass the web-based management interface and gain unauthorized access to affected Cisco ISE or ISE-PIC devices.

Federal remediation due 9/19/2026

CVE-2026-58704

CriticalGoogle · PixelAdded 8d ago

This is known to be exploited in the wild and could let an attacker bypass permission checks and gain higher privileges through the cellular modem. Prioritize affected Pixel devices even though the EPSS estimate is low.

Federal remediation due 9/19/2026

CVE-2026-76461

CriticalCisco · Secure Email GatewayAdded 10d ago

This vulnerability can let an unauthenticated remote attacker run commands as root on a Cisco Secure Email Gateway. It is known to be exploited in the wild, so exposed systems should be treated as urgent.

Federal remediation due 9/17/2026

CVE-2026-84869

CriticalConnectWise · ScreenConnectAdded 13d ago

A person connected through an active remote session may be able to transfer and run files without approval from the device user. This can lead to malware installation or takeover of affected endpoint devices; ScreenConnect servers are not affected.

Federal remediation due 9/14/2026

CVE-2026-85706

CriticalGitLab · Community Edition and Enterprise EditionAdded 13d ago

This vulnerability is confirmed to be exploited in the wild. An unauthenticated attacker may be able to read arbitrary files from affected GitLab instances, potentially exposing secrets, configuration, or other sensitive data.

Federal remediation due 9/14/2026

CVE-2026-42018

CriticalJFrog · ArtifactoryAdded 13d ago

This vulnerability is confirmed exploited in the wild and may let an unauthenticated person obtain an internal anonymous-user token, potentially exposing sensitive Artifactory resources even when anonymous access is disabled.

Federal remediation due 9/25/2026

CVE-2026-42016

CriticalJFrog · ArtifactoryAdded 13d ago

This vulnerability can let an attacker with a token gain more access than that token should allow. It is listed in CISA KEV as actively exploited, so affected systems should be treated as urgent even though the EPSS estimate is low.

Federal remediation due 9/25/2026

CVE-2026-86060

CriticalMikroTik · RouterOSAdded 14d ago

Someone who can reach the RouterOS SSH login service may be able to gain higher privileges without authenticating. This is a critical risk for exposed routers and management networks.

Federal remediation due 9/13/2026

CVE-2026-67277

CriticalMikroTik · RouterOSAdded 14d ago

This is known to be exploited in the wild and can let someone access kernel memory or crash the affected RouterOS btest service. A successful attack could expose sensitive device information or disrupt network connectivity.

Federal remediation due 9/13/2026

CVE-2026-19490

CriticalCitrix · NetScalerAdded 15d ago

This can let an unauthenticated remote attacker bypass login controls on exposed NetScaler ADC or Gateway services configured for AAA, SSL VPN, ICA Proxy, CVPN, or RDP Proxy. It is listed in CISA's Known Exploited Vulnerabilities catalog, so treat affected internet-facing appliances as urgent.

Federal remediation due 9/12/2026

CVE-2026-20079

CriticalCisco · Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementAdded 15d ago

This flaw is being actively exploited and can let a remote attacker bypass login controls, run scripts, and gain root-level control of affected management systems. Compromise of firewall management can put the firewall environment and connected networks at risk.

Federal remediation due 9/12/2026

CVE-2025-25249

CriticalFortinet · Multiple ProductsAdded 15d ago

This vulnerability can let an attacker run code or commands by sending specially crafted network packets. It is listed in CISA's Known Exploited Vulnerabilities catalog, so treat exposed and reachable systems as urgent.

Federal remediation due 9/12/2026

CVE-2026-87491

CriticalGoogle · Chromium V8Added 15d ago

This is confirmed exploited in the wild and can let a malicious web page run code inside a browser’s sandbox. Browsers built on Chromium may be affected, including Chrome, Edge, and Opera.

Federal remediation due 9/23/2026

CVE-2026-85880

CriticalMicrosoft · WindowsAdded 16d ago

This flaw is being actively exploited and can let someone who already has access to a Windows system gain higher privileges. That can turn a limited compromise into full control of the device.

Federal remediation due 9/22/2026

CVE-2026-86218

CriticalN-able · N-centralAdded 16d ago

This is a critical remote code execution flaw that can let an unauthenticated attacker take control of an affected N-central server over the network. Systems running versions earlier than 2026.3.1.14 are at risk.

Federal remediation due 9/11/2026

CVE-2026-75650

CriticalAdobe · Commerce and MagentoAdded 16d ago

This can let an attacker run code as the affected Adobe Commerce user without user interaction. Treat internet-facing or otherwise reachable Commerce systems as urgent because the CVSS score is 10 and the scope can extend beyond the vulnerable component.

Federal remediation due 9/11/2026

CVE-2026-81963

CriticalMicrosoft · WindowsAdded 16d ago

This vulnerability can let a person who already has local access to a Windows device gain SYSTEM-level control. It is listed in CISA's Known Exploited Vulnerabilities catalog, so treat affected systems as an active risk.

Federal remediation due 9/22/2026

CVE-2026-85046

CriticalGoogle · Chromium V8Added 20d ago

This is being actively exploited and can let a malicious web page run code inside a Chromium-based browser sandbox. Systems using browsers built on Chromium may be affected, including Chrome, Edge, and Opera.

Federal remediation due 9/18/2026

CVE-2026-83549

CriticalSonicWall · SMA1000 AppliancesAdded 22d ago

An attacker who already has administrator access can run commands on the appliance, potentially taking full control of it. This vulnerability is confirmed to be exploited in the wild, so exposed SMA1000 appliances should be treated as urgent.

Federal remediation due 9/5/2026

CVE-2026-82329

CriticalJFrog · ArtifactoryAdded 22d ago

Someone who can reach Artifactory over the network may be able to gain administrator access without signing in. This could let them access, change, or delete repositories, artifacts, and configuration.

Federal remediation due 9/5/2026

CVE-2026-49869

CriticalKestra · Kestra OSSAdded 22d ago

This is confirmed exploited in the wild and can let an unauthenticated remote attacker run arbitrary workflows and OS commands. Internet-exposed Kestra OSS instances should be treated as urgent because an attacker may not need credentials.

Federal remediation due 9/5/2026

CVE-2026-9586

CriticalSangoma · SwitchvoxAdded 22d ago

An internet-reachable Switchvox system could be compromised without a login, allowing an attacker to access or change backend database data and potentially run code. This is confirmed exploited in the wild, so treat exposed systems as urgent.

Federal remediation due 9/5/2026

CVE-2026-59822

CriticalBerriAI · LiteLLMAdded 22d ago

An attacker may be able to access LiteLLM's MCP Streamable HTTP service without valid credentials by using a made-up Bearer token. This issue is listed in CISA KEV, so treat exposed instances as an active priority despite the low EPSS estimate.

Federal remediation due 9/16/2026

CVE-2026-48710

CriticalKludex · StarletteAdded 22d ago

This is a confirmed exploited vulnerability that can let an attacker manipulate how a request path is interpreted, potentially bypassing path-based authentication controls. Prioritize any internet-facing applications using Starlette, especially where access decisions depend on URL paths.

Federal remediation due 9/16/2026

CVE-2026-83548

CriticalSonicWall · SMA1000 AppliancesAdded 22d ago

This flaw is confirmed to be exploited in the wild and can let an unauthenticated remote attacker access sensitive functions and perform unauthorized actions. Internet-exposed SMA1000 appliances should be treated as urgent because no login is required for exploitation.

Federal remediation due 9/5/2026

CVE-2026-82078

CriticalPaperCut · NG/MFAdded 24d ago

This could let someone who can change PaperCut system configuration run arbitrary code as the PaperCut server process. The impact is severe, but exploitation depends on already having access to modify configuration.

Federal remediation due 9/14/2026

CVE-2026-81578

CriticalPaperCut · NG/MFAdded 24d ago

This is confirmed exploited in the wild and can let an unauthenticated remote attacker change certain PaperCut NG/MF system settings. It can also be chained with CVE-2026-82078, increasing the potential impact.

Federal remediation due 9/14/2026

CVE-2026-53362

CriticalLinux · KernelAdded 28d ago

This flaw can let an attacker gain higher privileges on affected Linux systems through IPv6 networking. It is listed in CISA KEV, so treat affected systems as actively at risk despite the low EPSS estimate.

Federal remediation due 8/30/2026

CVE-2026-66384

CriticalJFrog · ArtifactoryAdded 28d ago

This vulnerability is confirmed exploited in the wild and could let an authenticated Artifactory user write files outside the intended Docker cache location under certain remote-repository conditions. Treat internet-exposed or broadly accessible Artifactory instances as urgent, despite the low EPSS estimate.

Federal remediation due 9/10/2026

CVE-2023-49105

CriticalownCloud · ownCloudAdded 28d ago

This flaw can let an unauthenticated attacker read, change, or delete files for users whose usernames are known and who do not have a signing key configured. It is confirmed exploited in the wild, so exposed ownCloud systems should be treated as urgent.

Federal remediation due 8/30/2026

CVE-2015-5287

CriticalRed Hat · Automatic Bug Reporting ToolAdded 29d ago

A local user who already has certain permissions could gain higher privileges by exploiting predictable temporary-file handling. This CVE is listed in CISA's Known Exploited Vulnerabilities catalog, so treat affected systems as a priority even though exploitation requires local access.

Federal remediation due 9/9/2026

CVE-2021-23758

CriticalAjax.NET Professional · Ajax.NET ProfessionalAdded 29d ago

This flaw can let a remote attacker run code on servers using Ajax.NET Professional. It is listed in CISA's Known Exploited Vulnerabilities catalog and has a high reported exploitation likelihood.

Federal remediation due 9/9/2026

CVE-2019-1068

CriticalMicrosoft · SQL ServerAdded 29d ago

This vulnerability can let an attacker run code as the SQL Server Database Engine service account, potentially taking control of the database server and its data. It is listed in CISA KEV and has a 44.7% estimated likelihood of exploitation within 30 days.

Federal remediation due 8/29/2026

CVE-2015-3246

CriticalRed Hat · LibuserAdded 29d ago

This vulnerability is known to be exploited in the wild. A logged-in local user could corrupt the system password file, causing an outage or potentially gaining higher privileges.

Federal remediation due 9/9/2026

CVE-2026-8452

CriticalCitrix · NetScaler ADC and NetScaler GatewayAdded 29d ago

This vulnerability can let an attacker cause a denial of service, potentially taking affected NetScaler ADC or Gateway services offline. It is listed in CISA’s Known Exploited Vulnerabilities catalog, so treat exposed systems as an urgent risk despite the low EPSS estimate.

Federal remediation due 8/29/2026

CVE-2022-0995

CriticalLinux · KernelAdded 29d ago

This flaw is confirmed exploited in the wild and could let a local user gain higher privileges or crash an affected Linux system. Prioritize systems where untrusted users, workloads, or containers can obtain local access.

Federal remediation due 9/9/2026

CVE-2026-60004

CriticalGitea · GiteaAdded 1mo ago

This is actively exploited and lets someone with repository write access run shell commands as the Gitea service account. That could lead to server compromise, source-code theft, or changes to hosted repositories.

Federal remediation due 8/28/2026

CVE-2026-21962

CriticalOracle · HTTP Server and Oracle Weblogic Server Proxy Plug-inAdded 1mo ago

This vulnerability is confirmed exploited in the wild and could let an attacker read, change, create, or delete data accessible through these Oracle components. The reported exploitation likelihood is high, so exposed or internet-facing deployments should be treated as urgent.

Federal remediation due 8/27/2026

CVE-2026-73570

CriticalSynacor · Zimbra Collaboration Suite (ZCS)Added 1mo ago

An internet-facing Zimbra server could let an unauthenticated attacker run operating system commands as the Zimbra user through specially crafted email delivery requests. This is confirmed exploited in the wild, so exposed systems should be treated as urgent.

Federal remediation due 8/24/2026

CVE-2026-72529

CriticalTrueConf · ServerAdded 1mo ago

This vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog, meaning attackers are actively using it. Someone with network access to TCP port 4307 could run arbitrary scripts on an affected TrueConf Server without authentication.

Federal remediation due 8/23/2026

CVE-2026-72530

CriticalTrueConf · ServerAdded 1mo ago

Someone with network access to TCP port 4307 could run code on the TrueConf Server host, potentially taking control of the system. This vulnerability is confirmed exploited in the wild, so treat exposed or reachable servers as urgent.

Federal remediation due 9/3/2026

CVE-2026-64849

CriticalMLflow · MLflowAdded 1mo ago

This vulnerability can let an attacker use MLflow to access internal systems or cloud metadata services and retrieve their responses. It is confirmed exploited in the wild, so prioritize any internet-exposed MLflow deployments today.

Federal remediation due 9/2/2026

CVE-2026-59310

CriticalUsed in ransomwareBroadcom · VMware vCenterAdded 1mo ago

This is known to be exploited in the wild and could let someone with network access to vCenter run code on the server. A compromised vCenter can give an attacker broad control over virtual infrastructure.

Federal remediation due 8/21/2026

CVE-2026-55040

CriticalMicrosoft · SharePointAdded 1mo ago

This vulnerability is confirmed exploited in the wild and could let someone bypass a SharePoint security control over the network. Treat internet-facing and business-critical SharePoint systems as urgent.

Federal remediation due 8/21/2026

CVE-2026-65400

CriticalApple · macOSAdded 1mo ago

Someone on your network could access Screen Sharing on affected macOS systems without valid credentials. This is confirmed exploited in the wild, so exposed or reachable systems need urgent attention.

Federal remediation due 8/21/2026

CVE-2026-33824

CriticalMicrosoft · Internet Key Exchange (IKE) Service ExtensionsAdded 1mo ago

This flaw can let an attacker run code remotely on affected systems, and it is confirmed to be exploited in the wild. Prioritize any internet-exposed or externally reachable systems that use this service.

Federal remediation due 8/21/2026

CVE-2025-62593

CriticalRay-Project · RayAdded 1mo ago

This vulnerability can let an attacker run code on systems where developers use Ray, potentially through Firefox or Safari. It is listed in CISA's Known Exploited Vulnerabilities catalog, so treat affected internet-exposed or developer systems as urgent despite the low EPSS score.

Federal remediation due 8/20/2026

CVE-2026-68820

CriticalMicrosoft · Windows Ancillary Function Driver for WinSock Added 1mo ago

This flaw lets an authorized user on a Windows system gain higher privileges. It is listed in CISA’s Known Exploited Vulnerabilities catalog, so treat affected systems as a priority for remediation and review.

Federal remediation due 8/25/2026

CVE-2026-20349

CriticalCisco · Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Added 1mo ago

This vulnerability is actively exploited and can let a remote, unauthenticated attacker repeatedly force an affected firewall to reload, disrupting network access. Because these devices are security gateways, outages can affect many systems at once.

Federal remediation due 8/14/2026

CVE-2026-72898

CriticalMetabase · MetabaseAdded 1mo ago

An internet-reachable, unauthenticated attacker may be able to take administrator control of Metabase, steal database credentials, and export data. This vulnerability is confirmed exploited in the wild and should be treated as urgent.

Federal remediation due 8/14/2026

CVE-2026-8037

CriticalProgress · LoadMasterAdded 1mo ago

An unauthenticated attacker can run arbitrary commands on a vulnerable LoadMaster appliance, which can lead to full device compromise. This CVE is confirmed exploited in the wild and has a high predicted likelihood of exploitation.

Federal remediation due 8/10/2026

CVE-2026-63077

CriticalUsed in ransomwareJetBrains · TeamCityAdded 1mo ago

Attackers are already exploiting this flaw, and it can let someone remotely run code on an exposed TeamCity server without signing in. Treat affected systems as urgent, especially if they are internet-accessible.

Federal remediation due 8/8/2026

CVE-2026-9198

CriticalIBM · LangflowAdded 1mo ago

Unauthenticated attackers can take full control of default Langflow deployments remotely. CISA confirms this vulnerability is being exploited in the wild, so exposed systems require action today.

Federal remediation due 8/7/2026

CVE-2026-34486

CriticalApache · TomcatAdded 1mo ago

Attackers are already exploiting this flaw, and it can bypass Tomcat’s EncryptInterceptor, exposing sensitive data that should be encrypted. With a 42.6% 30-day exploitation probability and CISA KEV listing, prioritize affected systems today, especially internet-facing assets.

Federal remediation due 8/7/2026

CVE-2026-18556

CriticalN-able · N-centralAdded 1mo ago

Attackers are already exploiting this authentication bypass, which may let them access N-central without valid credentials. Prioritize internet-exposed systems despite the low EPSS score.

Federal remediation due 8/7/2026

CVE-2026-18577

CriticalN-able · N-centralAdded 1mo ago

Attackers are already exploiting this authentication bypass to take over N-central accounts. Prioritize internet-exposed systems despite the 2.5% EPSS score.

Federal remediation due 8/6/2026

CVE-2026-20316

CriticalUsed in ransomwareCisco · Secure Firewall Management Center (FMC)Added 1mo ago

Attackers are already exploiting this flaw and can remotely log in without authentication using a built-in low-privilege account, exposing sensitive data. Treat affected systems as a priority, especially if they are internet-accessible.

Federal remediation due 8/1/2026

CVE-2026-16812

CriticalArista · VeloCloud OrchestratorAdded 1mo ago

This vulnerability is confirmed exploited in the wild and could let a remote attacker compromise the orchestrator host and the confidentiality, integrity, and availability of managed data. Treat internet-exposed systems as urgent despite the low EPSS score.

Federal remediation due 7/30/2026

CVE-2025-68686

CriticalFortinet · FortiOSAdded 1mo ago

Attackers are already exploiting this flaw, but they must first compromise FortiOS through another vulnerability and gain filesystem-level access. It can then help them bypass a prior fix intended to prevent post-compromise persistence.

Federal remediation due 8/10/2026

CVE-2026-50522

CriticalMicrosoft · SharePointAdded 2mo ago

Attackers can remotely run code without authorization, which could lead to full compromise of affected SharePoint systems. Exploitation is confirmed in the wild, and the 30-day exploitation probability is 75.8%, so act today.

Federal remediation due 7/25/2026

CVE-2026-16232

CriticalCheck Point · SmartConsoleAdded 2mo ago

Attackers are already exploiting this flaw and may gain full administrative access without credentials. With a 71.4% EPSS score, exposed systems require action today.

Federal remediation due 7/25/2026

CVE-2026-63030

CriticalWordPress · CoreAdded 2mo ago

Attackers are already exploiting this flaw, and exploitation could let them alter the WordPress database and run code on the server. With a 98.4% 30-day exploitation probability, exposed systems need action today.

Federal remediation due 7/24/2026

CVE-2026-60137

CriticalWordPress · CoreAdded 2mo ago

Attackers are already exploiting this flaw, and it has a high near-term exploitation probability. When chained with CVE-2026-63030, an unauthenticated attacker could take control of a default WordPress installation and run code remotely.

Federal remediation due 8/4/2026

CVE-2026-0770

CriticalLangflow · LangflowAdded 2mo ago

Remote attackers can execute arbitrary code on affected Langflow installations. Exploitation is confirmed in the wild, so exposed systems require action today.

Federal remediation due 7/24/2026

CVE-2021-27137

CriticalDD-WRT · DD-WRTAdded 2mo ago

This flaw can let an unauthenticated attacker run code through DD-WRT’s UPnP service. CISA confirms active exploitation, so exposed devices should be treated as an urgent priority.

Federal remediation due 7/24/2026

CVE-2026-39808

CriticalFortinet · FortiSandboxAdded 2mo ago

Attackers are already exploiting this flaw and can run unauthorized commands without signing in by sending crafted HTTP requests. With a 89.7% exploitation probability, exposed systems require action today.

Federal remediation due 7/19/2026

CVE-2026-25089

CriticalFortinet · FortiSandboxAdded 2mo ago

An unauthenticated attacker can send crafted HTTP requests to run commands on affected systems. Exploitation is confirmed in the wild, and the high EPSS score makes this an urgent issue for internet-exposed assets.

Federal remediation due 7/19/2026

CVE-2026-58644

CriticalMicrosoft · SharePointAdded 2mo ago

Attackers can execute code remotely without authorization, and CISA confirms this vulnerability is being exploited in the wild. Internet-exposed SharePoint systems should be treated as urgent.

Federal remediation due 7/19/2026

CVE-2023-4346

CriticalKNX Association · KNX Protocol Connection Authorization Option 1Added 2mo ago

This vulnerability is confirmed as exploited in the wild and could let an attacker purge affected devices and lock them with a BCU key. Prioritize exposed devices and installations without additional security options.

Federal remediation due 7/29/2026

CVE-2026-46817

CriticalOracle · E-Business SuiteAdded 2mo ago

Attackers are already exploiting this flaw, and an attacker who can reach the application over HTTP may take over Oracle Payments without signing in. Prioritize internet-exposed systems today.

Federal remediation due 7/18/2026

CVE-2026-15409

CriticalUsed in ransomwareSonicWall · SMA1000 AppliancesAdded 2mo ago

Remote attackers can abuse an exposed appliance without signing in, and exploitation has been confirmed in ransomware campaigns. With a 78.4% EPSS score and CISA KEV listing, treat this as an urgent priority.

Federal remediation due 7/17/2026

CVE-2026-56164

CriticalMicrosoft · SharePoint ServerAdded 2mo ago

Attackers are already exploiting this flaw to gain elevated privileges remotely without authorization. Prioritize internet-exposed SharePoint Server systems today.

Federal remediation due 7/17/2026

CVE-2026-56155

CriticalMicrosoft · Active Directory Federation ServicesAdded 2mo ago

This vulnerability can let an authorized local attacker gain higher privileges on an affected federation server. It is confirmed as exploited in the wild, so prioritize exposed assets under CISA BOD 26-04 timelines despite the relatively low EPSS score.

Federal remediation due 7/28/2026

CVE-2026-15410

CriticalUsed in ransomwareSonicWall · SMA1000 AppliancesAdded 2mo ago

An administrator account could be used remotely to run operating-system commands on the appliance. This vulnerability is confirmed as exploited in ransomware campaigns and has a 76.3% estimated chance of exploitation within 30 days, so exposed systems require action today.

Federal remediation due 7/17/2026

CVE-2008-4128

CriticalCisco · IOSAdded 2mo ago

This flaw can let an attacker trick an authenticated administrator into running arbitrary commands on a Cisco IOS device. It is confirmed exploited in the wild and has a 33% estimated chance of exploitation within 30 days, so exposed devices should be addressed today.

Federal remediation due 7/16/2026

CVE-2026-56291

CriticalBalbooa · FormsAdded 2mo ago

Attackers are already exploiting this flaw, and affected internet-facing systems are at high risk. An attacker can upload executable files without signing in and potentially take full control of the server.

Federal remediation due 7/13/2026

CVE-2026-48939

CriticaliCagenda · iCagendaAdded 2mo ago

Attackers can upload and run PHP code through the attachment feature, potentially taking control of the affected system. CISA confirms active exploitation, so exposed installations should be addressed today.

Federal remediation due 7/13/2026

CVE-2026-48282

CriticalAdobe · ColdFusionAdded 2mo ago

Attackers are already exploiting this flaw, and successful attacks can run arbitrary code with the ColdFusion user’s permissions. With a 99.2% exploitation probability, exposed systems need action today.

Federal remediation due 7/10/2026

CVE-2026-56290

CriticalJoomlack · Page BuilderAdded 2mo ago

Attackers can upload files without signing in and potentially run code on affected systems. Exploitation is confirmed in the wild, and the 83.3% EPSS score indicates urgent risk.

Federal remediation due 7/10/2026

CVE-2026-55255

CriticalLangflow · LangflowAdded 2mo ago

An authenticated attacker can run another user’s flows by supplying the victim’s flow ID, potentially exposing data or triggering unauthorized actions. CISA confirms this vulnerability is being exploited, and its 29.1% EPSS indicates high near-term risk.

Federal remediation due 7/10/2026

CVE-2026-48908

CriticalJoomShaper · SP Page BuilderAdded 2mo ago

Unauthenticated attackers can upload and run PHP code, potentially taking full control of affected websites. Exploitation is confirmed in the wild, and the 30-day exploitation probability is 88.1%, so exposed systems require action today.

Federal remediation due 7/10/2026

CVE-2026-45659

CriticalUsed in ransomwareMicrosoft · SharePoint ServerAdded 2mo ago

This vulnerability is being exploited in the wild and lets an authorized attacker execute code remotely on SharePoint Server. Prioritize internet-exposed systems today.

Federal remediation due 7/4/2026

CVE-2026-48558

CriticalSimpleHelp · SimpleHelpAdded 2mo ago

This is being actively exploited and can let a remote attacker forge a login token to gain a fully authenticated technician session, potentially bypassing multi-factor authentication. Prioritize internet-exposed systems with OIDC authentication configured.

Federal remediation due 7/2/2026

CVE-2026-12569

CriticalUsed in ransomwarePTC · Windchill and FlexPLMAdded 3mo ago

An attacker can remotely run arbitrary code without signing in. This critical vulnerability is already being exploited, including in ransomware campaigns, so exposed systems require action today.

Federal remediation due 6/28/2026

CVE-2026-20230

CriticalCisco · Unified Communications ManagerAdded 3mo ago

Attackers are already exploiting this vulnerability, and exploitation may let them write files that can later be used to gain root control. With an 83.2% EPSS and CISA KEV listing, exposed systems require action today.

Federal remediation due 6/28/2026

CVE-2026-34908

CriticalUbiquiti · UniFi OSAdded 3mo ago

This vulnerability is confirmed to be exploited in the wild and has a high predicted exploitation probability. Someone with network access could make unauthorized changes to UniFi OS systems.

Federal remediation due 6/26/2026

CVE-2026-34910

CriticalUbiquiti · UniFi OSAdded 3mo ago

This command-injection flaw could let someone with network access run commands on affected UniFi OS systems. It is confirmed as exploited in the wild and has an 87% estimated chance of exploitation within 30 days, so prioritize it today.

Federal remediation due 6/26/2026

CVE-2026-34909

CriticalUbiquiti · UniFi OSAdded 3mo ago

This vulnerability is confirmed exploited and has a high near-term exploitation probability. Someone with network access could read system files and potentially gain access to an underlying account.

Federal remediation due 6/26/2026

CVE-2025-67038

CriticalLantronix · EDS5000Added 3mo ago

This vulnerability is confirmed exploited in the wild and can let an attacker run operating-system commands with root privileges. Prioritize exposed EDS5000 devices for action today.

Federal remediation due 6/26/2026

CVE-2026-20253

CriticalSplunk · EnterpriseAdded 3mo ago

This is being actively exploited and has a 96.2% estimated chance of exploitation within 30 days. An unauthenticated attacker could create or erase arbitrary files through the PostgreSQL sidecar endpoint, risking disruption or further compromise.

Federal remediation due 6/21/2026

CVE-2026-48907

CriticalWidget Factory · Joomla Content Editor Added 3mo ago

Attackers are already exploiting this flaw, and an unauthenticated user could upload and run PHP code on affected systems. Internet-exposed installations should be treated as urgent.

Federal remediation due 6/19/2026

CVE-2026-54420

CriticalLiteSpeed · cPanel PluginAdded 3mo ago

This vulnerability is confirmed as exploited in the wild and could let a hosting user with FTP or web-shell access follow symbolic links on shared CloudLinux/CageFS servers. Treat affected internet-exposed systems as a priority despite the low EPSS score.

Federal remediation due 6/18/2026

CVE-2026-20262

CriticalCisco · Catalyst SD-WAN ManagerAdded 3mo ago

This vulnerability is confirmed to be exploited and could let an authenticated remote attacker create or overwrite any file on the affected system. Prioritize internet-exposed systems for action today.

Federal remediation due 6/29/2026

CVE-2026-35273

CriticalUsed in ransomwareOracle · PeopleSoft Enterprise PeopleToolsAdded 3mo ago

An unauthenticated attacker could take over affected PeopleSoft Enterprise PeopleTools systems. Exploitation is confirmed, including in ransomware campaigns, and the 30-day exploitation probability is 95.5%, so exposed systems require action today.

Federal remediation due 6/15/2026

CVE-2026-10520

CriticalIvanti · SentryAdded 3mo ago

Attackers are actively exploiting this flaw, and an unauthenticated attacker can gain root-level control when an unmanaged Sentry appliance has externally reachable endpoints. With a 99.9% EPSS and CISA KEV listing, exposed appliances require action today.

Federal remediation due 6/14/2026

CVE-2026-7473

CriticalArista · Extensible Operating SystemAdded 3mo ago

This flaw can cause an Arista EOS switch to wrongly decapsulate and forward unexpected tunneled traffic, potentially bypassing intended network controls. It is listed in CISA's Known Exploited Vulnerabilities catalog, so treat affected systems as a priority despite the 1.1% EPSS score.

Federal remediation due 6/23/2026

CVE-2026-20245

CriticalCisco · Catalyst SD-WAN ManagerAdded 3mo ago

This vulnerability is confirmed exploited in the wild and can let an authenticated local attacker gain root control by supplying a crafted file. Prioritize action today, especially because the estimated 30-day exploitation probability is 25.3%.

Federal remediation due 6/23/2026

CVE-2026-11645

CriticalGoogle · Chromium V8Added 3mo ago

Attackers are already exploiting this flaw, and a crafted web page could run malicious code within the browser sandbox. Chromium-based browsers such as Chrome, Edge, and Opera may be affected.

Federal remediation due 6/23/2026

CVE-2026-42271

CriticalBerriAI · LiteLLMAdded 3mo ago

Any authenticated user, including one with a low-privilege internal key, could run arbitrary commands on the LiteLLM host. Exploitation is confirmed in the wild and the 30-day exploitation probability is high, so act today.

Federal remediation due 6/22/2026

CVE-2026-50751

CriticalUsed in ransomwareCheck Point · Security GatewayAdded 3mo ago

Attackers can connect to the remote access VPN without a valid user password. Exploitation is confirmed in the wild, including in ransomware campaigns, and the 30-day exploitation probability is 82.6%.

Federal remediation due 6/11/2026

CVE-2026-28318

CriticalSolarWinds · Serv-UAdded 3mo ago

Attackers can remotely crash the Serv-U service without authentication, causing an outage. Exploitation has been confirmed in the wild, so prioritize action today.

Federal remediation due 6/19/2026

CVE-2026-45247

CriticalMirasvit · Mirasvit Full Page Cache WarmerAdded 3mo ago

Attackers can exploit this without signing in to run code on affected systems. It is confirmed as exploited in the wild and has a 27.5% estimated chance of exploitation within 30 days, so act today.

Federal remediation due 6/6/2026

CVE-2022-0492

CriticalLinux · KernelAdded 3mo ago

This flaw can let an attacker gain higher privileges through the cgroups v1 release_agent feature. It is confirmed exploited in the wild, so prioritize affected systems today.

Federal remediation due 6/5/2026

CVE-2025-48595

CriticalAndroid · FrameworkAdded 3mo ago

This vulnerability can let a local attacker run code with higher privileges on affected Android devices. It is confirmed as exploited in the wild, so treat remediation as urgent despite the low EPSS score.

Federal remediation due 6/5/2026

CVE-2024-21182

CriticalOracle · WebLogic ServerAdded 3mo ago

This vulnerability is confirmed exploited in the wild and could let anyone who can reach WebLogic over T3 or IIOP access critical data or all data available to the server. Prioritize action today.

Federal remediation due 6/4/2026

CVE-2026-0257

CriticalUsed in ransomwarePalo Alto Networks · PAN-OSAdded 3mo ago

Attackers can bypass authentication and establish an unauthorized VPN connection into your network. Exploitation is confirmed, including in ransomware campaigns, and the 93.9% EPSS indicates a high near-term risk.

Federal remediation due 6/1/2026

CVE-2026-45321

CriticalUsed in ransomwareTanStack · TanStackAdded 4mo ago

Malicious TanStack packages published under a trusted identity can steal credentials from systems that install them. This is confirmed exploited in the wild and observed in ransomware campaigns, so act today.

Federal remediation due 6/10/2026

CVE-2026-8398

CriticalDaemon · Daemon Tools LiteAdded 4mo ago

This vulnerability can compromise data, alter systems, or disrupt service, and it is confirmed to be exploited in the wild. Prioritize action today despite the relatively low EPSS estimate.

Federal remediation due 5/30/2026

CVE-2026-48027

CriticalUsed in ransomwareNx · Nx ConsoleAdded 4mo ago

A malicious Nx Console release can steal credentials from disk and memory. It is confirmed exploited in the wild and observed in ransomware campaigns, so act today.

Federal remediation due 6/10/2026

CVE-2026-48172

CriticalLiteSpeed · cPanel PluginAdded 4mo ago

Any cPanel user account can run arbitrary scripts with root privileges, potentially taking full control of the server. CISA confirms active exploitation, so exposed systems need action today.

Federal remediation due 5/29/2026

CVE-2026-9082

CriticalDrupal · CoreAdded 4mo ago

Attackers are already exploiting this flaw, and successful attacks could grant higher privileges or remote control of affected Drupal sites. With an 88.3% exploitation probability, treat exposed systems as an urgent priority today.

Federal remediation due 5/27/2026

Only see the ones that touch what you run

ThreatLoops matches KEV entries against your actual stack and pushes the handful that matter to Slack, Teams or a webhook — instead of another list to read every morning.

Source: CISA Known Exploited Vulnerabilities catalog. Plain-English notes are generated from the published advisory text.