Active exploitation
Vulnerabilities under attack right now: CISA KEV additions, in-the-wild exploitation, and what to patch first.
Linux kernel IPv6 flaw (CVE-2026-53362) lets a container break out to host root, now exploited
CVE-2026-53362 is an actively exploited Linux kernel IPv6 flaw that lets a low-privilege user escape a container to host root.
CISA says a 2022 Linux kernel flaw lets a local user become root, and it's now being exploited (CVE-2022-0995)
CISA added Linux kernel flaw CVE-2022-0995 to its actively-exploited list. A local user can escalate to root.
An old ownCloud flaw is now stealing files from unpatched servers, including a nuclear agency
CVE-2023-49105, an ownCloud auth bypass patched in 2023, is now in CISA's KEV list after a suspected Chinese operator stole nuclear-agency files.
PaperCut print servers are under active attack through a login-free code-execution flaw
Attackers are exploiting an unauthenticated flaw in PaperCut NG and MF print servers to run code as the host account. Restrict access and patch now.
Gitea flaw CVE-2026-60004 lets any user run code on your server, now exploited. Patch 1.27.1.
CISA added Gitea's CVE-2026-60004 to its exploited list on Aug 25. A public exploit lets any user run code via the diffpatch API. Patch to 1.27.1 and hunt.
Zimbra RCE (CVE-2026-73570) lets an unauthenticated attacker run commands over SMTP. Patch to 10.1.20.
CVE-2026-73570 is an unauthenticated command injection in Zimbra Collaboration Suite, now in CISA KEV and exploited in the wild.
A single web request can hijack SPIP websites with no login, and the first patch missed it (CVE-2026-77806)
SPIP before 4.4.21 has a critical unauthenticated code-execution flaw (CVE-2026-77806, CVSS 9.8) exploited in the wild. The 4.4.20 patch fell short; update now.
Two exploited TrueConf Server flaws chain to unauthenticated code execution, now on CISA's must-patch list
CISA added two actively exploited TrueConf Server flaws (CVE-2026-72529, CVE-2026-72530) to its KEV catalog.
MLflow's unauthenticated SSRF flaw (CVE-2026-64849) can leak cloud credentials. Patch to 3.15.0 now.
CVE-2026-64849 is an unauthenticated, full-read SSRF in MLflow's webhook delivery. It reaches cloud metadata and leaks instance credentials. Fixed in 3.15.0.
Windows Task Host flaw CVE-2025-60710 gives a local user SYSTEM, and ransomware gangs now exploit it
CISA confirms ransomware crews are exploiting CVE-2025-60710, a Windows Task Host flaw that elevates a local user to SYSTEM on Windows 11 and Server 2025.
A malicious web page can run code on developers' Ray AI servers, and CISA confirms active exploitation
CISA flagged CVE-2025-62593 in Ray as actively exploited. A malicious web page can reach a developer's local Ray dashboard and run code. Patch to Ray 2.52.0.
Cisco ASA and FTD firewalls can be crashed by an unauthenticated attacker (CVE-2026-20349). Patch by Aug 14.
CVE-2026-20349 lets an unauthenticated attacker reload Cisco ASA and FTD firewalls for a denial of service. Exploited now, no workaround. Patch by Aug 14.
Langflow's auto-login default gives any stranger admin, then RCE
CVE-2026-9198 lets an unauthenticated attacker mint a Langflow superuser token via auto-login, then run code as admin. KEV-listed, patch past 1.10.0 now.
N-able N-central auth bypass grants admin; first fix failed
N-able N-central RMM has an actively exploited authentication bypass (CVE-2026-18577). The first patch failed; upgrade to 2026.3.1.7 and hunt your endpoints.
Cisco's firewall management software has a hardcoded password, and attackers are already using it
Cisco Secure Firewall Management Center ships a static password (CVE-2026-20316) that lets unauthenticated attackers log in. Now in CISA KEV. Patch and hunt.
For this week's most-exploited bugs, the patch was the easy part
This week's most-exploited bugs each shipped with a fix, yet patching FortiOS, SharePoint, Check Point, and Langflow did not end the incident.
On-prem VeloCloud Orchestrator flaw (CVE-2026-16812) lets attackers run commands, and it is exploited now
CVE-2026-16812 is a CVSS 10.0 OS command injection in on-prem VeloCloud Orchestrator, actively exploited. See the affected and fixed builds to patch now.
Check Point's SmartConsole flaw lets an unauthenticated attacker become full admin, and it is being exploited
Check Point SmartConsole flaw CVE-2026-16232 is exploited and in CISA KEV, letting an unauthenticated attacker log in as full admin.
You patched SharePoint three times this month. The key attackers want is still in the lock.
CVE-2026-50522, a CVSS 9.8 SharePoint RCE, went from public PoC to active exploitation in hours.
Langflow's code-validation endpoint just produced its second unauthenticated RCE
CVE-2026-0770 (CVSS 9.8) is an unauthenticated root RCE in Langflow's validate endpoint, actively exploited and added to CISA's KEV catalog.
ServiceNow is under active attack through a route the public exploit does not show. Patch, don't block.
ServiceNow's pre-auth sandbox-escape flaw CVE-2026-6875 (CVSS 9.5) is under active exploitation.
SharePoint's new RCE is live, and patching alone won't clean it
CVE-2026-58644, a SharePoint deserialization RCE, is in CISA's KEV catalog and exploited as a zero-day. Patching alone won't evict an attacker who stole keys.
Two Microsoft zero-days were exploited before the fix shipped
Microsoft's July 2026 Patch Tuesday fixes two zero-days already exploited in the wild: an ADFS and a SharePoint Server privilege bug.
Two more Joomla extensions hit the exploited list. It is the same bug, five times now.
CISA added Balbooa Forms (CVE-2026-56291) and iCagenda (CVE-2026-48939) to its exploited list on July 10, the fourth and fifth Joomla extension with the same
Two Joomla page builders are exploited for site takeover. The patch won't evict the intruder.
CISA flagged two CVSS-10 Joomla page-builder flaws, SP Page Builder (CVE-2026-48908) and Page Builder CK (CVE-2026-56290), as exploited.
Adobe ColdFusion is under active attack, but the max-severity rating overstates who is exposed
Adobe ColdFusion flaw CVE-2026-48282 (CVSS 10.0) is now exploited in the wild and in CISA KEV. Who is actually exposed, how to detect it, and what to patch.
Kemp LoadMaster's quote sanitizer became a pre-auth root RCE, exploited hours after the writeup dropped
Kemp LoadMaster's CVE-2026-8037 gives unauthenticated root through its API and is under active exploitation. Affected versions, the fix, and how to detect it.
Microsoft said this SharePoint bug was unlikely to be exploited. CISA just proved it wrong.
Microsoft rated SharePoint's CVE-2026-45659 unlikely to be exploited. CISA added it to the KEV catalog on July 1 after active exploitation. Patch and hunt now.
Adobe's six max-severity ColdFusion flaws have no exploit yet, and that is the countdown
Adobe patched six unauthenticated CVSS 10.0 code-execution flaws in ColdFusion (bulletin APSB26-68).
Oracle E-Business Suite is under attack again, and the patch has been out since May
CVE-2026-46817, a CVSS 9.8 flaw in Oracle E-Business Suite Payments, is exploited weeks after Oracle's May patch. What to check and how to fix it now.
Windchill holds your product blueprints. A web shell on its login page hands them over.
CISA added PTC Windchill RCE CVE-2026-12569 to its KEV catalog after web shells hit exposed PLM servers. Patch to 11.0 M030 before the June 28 deadline.
Cisco Unified CM's flaw is being exploited. Whether it touches you depends on one default setting.
CVE-2026-20230 in Cisco Unified CM can reach root, but only where WebDialer is enabled, and it ships off. Check that before you panic-patch.
Mistype the password and this Lantronix box runs attacker commands as root. CISA says it is happening now.
CISA flagged CVE-2025-67038 as exploited on June 23. A failed login on a Lantronix EDS5000 serial server runs attacker commands as root.
Attackers can take over your self-hosted UniFi controller with no password. CISA says it is happening now.
Three chained UniFi OS Server flaws give unauthenticated root. CISA added all three to its exploited list on June 23. Patch to 5.0.8 and check who can reach it.
Your Splunk box runs a database sidecar you never configured. Attackers use it for root.
CVE-2026-20253 is an unauthenticated RCE in Splunk Enterprise 10.x via a bundled PostgreSQL sidecar. On CISA KEV, exploited now. Patch to 10.0.7 or 10.2.4.
Cisco called this SD-WAN flaw medium. Attackers used it to take root on your WAN.
CVE-2026-20262 is an actively exploited Cisco SD-WAN Manager flaw that escalates a low-privilege login to root.
FortiSandbox Under Attack: The Box That Catches Malware Is Now the Way In
Three critical FortiSandbox flaws are under active exploitation, two unauthenticated and one patched a week ago.
Three requests, no password, a webshell: the JCE flaw hitting Joomla hosts now
Unauthenticated RCE (CVSS 10, CVE-2026-48907) in JCE, the most-installed Joomla editor. KEV-listed and exploited. Patch to 2.9.99.6 and hunt for webshells.
LiteSpeed's cPanel plugin gave shared-hosting tenants root twice in 2026. CageFS didn't help.
CVE-2026-54420 and CVE-2026-48172 let shared-hosting tenants reach root through the LiteSpeed cPanel plugin. Why CageFS isolation failed and what to patch now.
Ivanti Sentry's CVE-2026-10520: patch the gateway, then hunt for the breach
Ivanti Sentry CVE-2026-10520 is an unauthenticated root RCE under active attack. CISA's new 3-day patch rule applies; patched gateways were already breached.
Ready to meet the Guardians?
Deploys fast - agentless for monitoring and cloud, a lightweight agent for deep endpoint security. Just Suriq, standing watch.