Newly exploited and freshly published critical vulnerabilities, updated several times a day from the CISA KEV catalog and the NVD feed. KEV entries are being exploited in the wild — patch those first.
CVE Watch — exploited & fresh critical vulnerabilities
| CVE | Src | CVSS | Date | Affected | Summary |
|---|---|---|---|---|---|
| CVE-2026-76461 | NVD | 9.8 | 2026-09-14 | CVE-2026-76461 | A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an … |
| CVE-2026-76443 | NVD | 9.8 | 2026-09-14 | CVE-2026-76443 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gatew… |
| CVE-2026-76441 | NVD | 9.8 | 2026-09-14 | CVE-2026-76441 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gatew… |
| CVE-2026-76440 | NVD | 9.8 | 2026-09-14 | CVE-2026-76440 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gatew… |
| CVE-2026-61701 | NVD | 8.8 | 2026-09-14 | CVE-2026-61701 | Laravel MagicLink creates links for authentication without a password or for accessing private content. From … |
| CVE-2026-55416 | NVD | 8.8 | 2026-09-14 | CVE-2026-55416 | Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, an … |
| CVE-2026-55072 | NVD | 8.5 | 2026-09-14 | CVE-2026-55072 | Pimcore is an Open Source Data & Experience Management Platform. Prior to 2026.1.5, an authenticated user wit… |
| CVE-2026-54155 | NVD | 7.7 | 2026-09-14 | CVE-2026-54155 | node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to 2.166.0, the UserNameIdentityToke… |
| CVE-2026-20353 | NVD | 9.8 | 2026-09-14 | CVE-2026-20353 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gatew… |
| CVE-2026-47701 | NVD | 7.7 | 2026-09-14 | CVE-2026-47701 | The OpenTelemetry Operator is a Kubernetes Operator for the OpenTelemetry Collector. Prior to 0.152.0, cmd/ot… |
| CVE-2026-82438 | NVD | 8.1 | 2026-09-14 | CVE-2026-82438 | DescriptionThree separate mechanisms allowed a web page on an unrelated origin to read responses that Storm… |
| CVE-2026-82432 | NVD | 8.1 | 2026-09-14 | CVE-2026-82432 | DescriptionNimbus validated `topology.blobstore.map` against the calling subject at submission time only. T… |
| CVE-2026-82435 | NVD | 9.8 | 2026-09-14 | CVE-2026-82435 | DescriptionThe worker's Netty message decoder is installed ahead of the SASL authentication handlers in the… |
| CVE-2026-82431 | NVD | 9.8 | 2026-09-14 | CVE-2026-82431 | Description`SimpleACLAuthorizer` evaluated the user-level command set by returning early when `nimbus.users… |
| CVE-2026-82430 | NVD | 7.8 | 2026-09-14 | CVE-2026-82430 | DescriptionWhen launching a Docker or OCI worker, the setuid-root `worker-launcher` first changes ownership… |
| CVE-2026-82429 | NVD | 7.8 | 2026-09-14 | CVE-2026-82429 | DescriptionThe setuid-root `worker-launcher` binary adjusts ownership and permissions of worker directories… |
| CVE-2026-82427 | NVD | 7.8 | 2026-09-14 | CVE-2026-82427 | DescriptionA topology's `topology.blobstore.map` lets the submitter choose a local name for each blob that … |
| CVE-2026-82428 | NVD | 8.8 | 2026-09-14 | CVE-2026-82428 | DescriptionDependency artifacts uploaded with `storm jar --artifacts` were stored under a blob key derived … |
| CVE-2026-59569 | NVD | 8.1 | 2026-09-14 | CVE-2026-59569 | An improper input validation vulnerability in Zscaler Client Connector on Android and ChromeOS allows an atta… |
| CVE-2026-82441 | NVD | 9.1 | 2026-09-14 | CVE-2026-82441 | DescriptionA submitted topology carries two lists of blobstore keys, `dependency_jars` and `dependency_arti… |
| CVE-2026-82439 | NVD | 9.8 | 2026-09-14 | CVE-2026-82439 | DescriptionThe DRPC server kept a map from function name to request queue and created an entry the first ti… |
| CVE-2026-73370 | NVD | 9.8 | 2026-09-14 | CVE-2026-73370 | Incorrect Authorization vulnerability in Apache Syncope.Delegated administration security checks performe… |
| CVE-2026-73236 | NVD | 7.5 | 2026-09-14 | CVE-2026-73236 | Incorrect Authorization vulnerability in Apache Syncope.Delegated administration security checks are base… |
| CVE-2026-90938 | NVD | 8.6 | 2026-09-14 | CVE-2026-90938 | LangBot's plugin runtime (pip package langbot_plugin) through 0.4.17 starts a debug WebSocket server on 0.0.0… |
| CVE-2026-90937 | NVD | 9.9 | 2026-09-14 | CVE-2026-90937 | froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowing authen… |
| CVE-2026-78336 | NVD | 7.5 | 2026-09-14 | CVE-2026-78336 | Insertion of sensitive information into sent data vulnerability in Apache Syncope.Any authenticated user … |
| CVE-2026-78330 | NVD | 9.8 | 2026-09-14 | CVE-2026-78330 | Incorrect privilege assignment vulnerability in Apache Syncope.When the configured JWKS settings for intern… |
| CVE-2026-77181 | NVD | 9.8 | 2026-09-14 | CVE-2026-77181 | Incorrect Authorization vulnerability in Apache Syncope.An administrator with ClientApp's update entitlem… |
| CVE-2026-77051 | NVD | 9.8 | 2026-09-14 | CVE-2026-77051 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache … |
| CVE-2026-73178 | NVD | 7.5 | 2026-09-14 | CVE-2026-73178 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Syncope.An administrator… |
| CVE-2026-75030 | NVD | 9.8 | 2026-09-14 | CVE-2026-75030 | Missing Authorization vulnerability in Apache Syncope.An administrator with task execution entitlements m… |
| CVE-2026-73668 | NVD | 9.8 | 2026-09-14 | CVE-2026-73668 | Incorrect Authorization vulnerability in Apache Syncope.An administrator with adequate entitlements in … |
| CVE-2026-73579 | NVD | 9.8 | 2026-09-14 | CVE-2026-73579 | Incorrect Authorization vulnerability in Apache Syncope.Any search requests are transformed into SQL, Neo… |
| CVE-2026-73470 | NVD | 9.8 | 2026-09-14 | CVE-2026-73470 | Improper Privilege Management vulnerability in Apache Syncope.Delegations can be created or updated wit… |
| CVE-2026-87779 | NVD | 7.5 | 2026-09-14 | CVE-2026-87779 | Insertion of sensitive information into log file vulnerability in Apache Syncope.When AES key of non-stan… |
| CVE-2026-87802 | NVD | 9.1 | 2026-09-14 | CVE-2026-87802 | Improper verification of cryptographic signature vulnerability in Apache Syncope.When SRA is configured f… |
| CVE-2026-87785 | NVD | 9.1 | 2026-09-14 | CVE-2026-87785 | Authentication bypass by spoofing vulnerability in Apache Syncope.When the configured JWKS settings for i… |
| CVE-2026-86460 | NVD | 9.8 | 2026-09-14 | CVE-2026-86460 | Cypher injection vulnerability in the Neo4j persistence layer when processing some FIQL search conditions.… |
| CVE-2026-82232 | NVD | 9.8 | 2026-09-14 | CVE-2026-82232 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Apache … |
| CVE-2026-72524 | NVD | 8.8 | 2026-09-14 | CVE-2026-72524 | Incorrect Authorization vulnerability in Apache Doris allows an authenticated user to bypass privilege checks… |
| CVE-2026-68955 | NVD | 7.8 | 2026-09-14 | CVE-2026-68955 | The installer for Rakuten Kobo Desktop Application (Windows version) insecurely loads Dynamic Link Libraries.… |
| CVE-2023-50462 | NVD | 5.3 | 2026-09-14 | CVE-2023-50462 | An issue was discovered in the content_consent (aka Content Consent) extension through 2.0.1 for TYPO3. It fa… |
| CVE-2023-46035 | NVD | 5.9 | 2026-09-14 | CVE-2023-46035 | The svg_optimizer gem before 0.3.0 for Ruby performs entity expansion on untrusted documents. |
| CVE-2023-32803 | NVD | 7.5 | 2026-09-14 | CVE-2023-32803 | The ca-certificates package before ca-certificates-2021.2.50-72 for Amazon Linux 2 (AL2) does not properly re… |
| CVE-2026-33964 | NVD | 6.4 | 2026-09-14 | CVE-2026-33964 | An issue was discovered in camera in Samsung Mobile Processor Exynos 1580 and 2500. An untrusted pointer dere… |
| CVE-2026-33963 | NVD | 7.5 | 2026-09-14 | CVE-2026-33963 | An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600… |
| CVE-2026-31278 | NVD | 7.7 | 2026-09-14 | CVE-2026-31278 | An issue in the /api/v2/setting/adserversetting endpoint of Suprema BioStar 2 before 2.9.12 and and BioStar X… |
| CVE-2026-23789 | NVD | 7.8 | 2026-09-14 | CVE-2026-23789 | An issue was discovered in MFC in Samsung Mobile Processor and Wearable Processor Exynos 850, 1080, 2100, 128… |
| CVE-2025-63842 | NVD | 5.4 | 2026-09-14 | CVE-2025-63842 | A Cross-Site Scripting (XSS) vulnerability in the web backend for the Repetico app 1.9.7.31 for Android allow… |
| CVE-2024-53922 | NVD | 5.7 | 2026-09-14 | CVE-2024-53922 | An issue was discovered in the buffer queue driver in Samsung Automotive Processor Exynos Auto 8890, V7, V9, … |
| CVE-2026-76461 | KEV | — | 2026-09-14 | Cisco Secure Email Gateway | Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could… |
| CVE-2026-90600 | NVD | 6.3 | 2026-09-13 | CVE-2026-90600 | A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. This impacts an unknown functi… |
| CVE-2026-90597 | NVD | 6.3 | 2026-09-13 | CVE-2026-90597 | A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. The affected eleme… |
| CVE-2026-89050 | NVD | 4.3 | 2026-09-13 | CVE-2026-89050 | The Quads Ads Manager for Google AdSense WordPress plugin before 3.0.5 does not verify payment completion wit… |
| CVE-2026-88802 | NVD | 7.5 | 2026-09-13 | CVE-2026-88802 | The MDJM Event Management WordPress plugin before 1.7.8.5 and the Mobile Events Manager WordPress plugin thro… |
| CVE-2026-88793 | NVD | 8.8 | 2026-09-13 | CVE-2026-88793 | The YouTube Embed WordPress plugin from 10.0 to 10.3 does not perform any authorisation check on one of its A… |
| CVE-2026-85129 | NVD | 8.8 | 2026-09-13 | CVE-2026-85129 | The Hoo Companion WordPress plugin 1.0.2 does not have any authorisation or validation checks in one of its i… |
| CVE-2026-36989 | NVD | 5.8 | 2026-09-13 | CVE-2026-36989 | A SQL Injection vulnerability exists in LuxSoft LuxCal through 5.3.4L via rssfeed.php and common/retrieve.php. |
| CVE-2026-37008 | NVD | 8.1 | 2026-09-13 | CVE-2026-37008 | CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a d… |
| CVE-2026-74933 | NVD | 8.8 | 2026-09-13 | CVE-2026-74933 | The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not have authorisation checks on some of its REST … |
| CVE-2026-81648 | NVD | 10.0 | 2026-09-13 | CVE-2026-81648 | The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one o… |
| CVE-2026-90583 | NVD | 4.3 | 2026-09-13 | CVE-2026-90583 | A security flaw has been discovered in kagisearch smallweb up to 0ecb9c48edbf98dc7e934b54fbac43869e64b4cf. Th… |
| CVE-2026-90581 | NVD | 6.3 | 2026-09-13 | CVE-2026-90581 | A vulnerability was determined in cym1102 nginxWebUI up to 4.4.2. This issue affects the function MainControl… |
| CVE-2026-90580 | NVD | 6.3 | 2026-09-13 | CVE-2026-90580 | A vulnerability was found in FlowiseAI Flowise up to 3.0.2. This vulnerability affects the function axios.pos… |
| CVE-2026-29811 | NVD | 7.7 | 2026-09-13 | CVE-2026-29811 | CyberPanel before 2.4.4 attempts to detect an "alais" domain (i.e., a second domain that serves the same cont… |
| CVE-2020-15875 | NVD | 5.0 | 2026-09-13 | CVE-2020-15875 | An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract … |
| CVE-2026-90574 | NVD | 6.3 | 2026-09-13 | CVE-2026-90574 | A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. This affects an unknown f… |
| CVE-2026-90565 | NVD | 5.3 | 2026-09-13 | CVE-2026-90565 | A security flaw has been discovered in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9e… |
| CVE-2026-90566 | NVD | 7.3 | 2026-09-13 | CVE-2026-90566 | A weakness has been identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c7… |
| CVE-2026-90525 | NVD | 6.3 | 2026-09-13 | CVE-2026-90525 | A weakness has been identified in itsourcecode Sales and Inventory System 1.0. This affects an unknown functi… |
| CVE-2026-90526 | NVD | 7.3 | 2026-09-13 | CVE-2026-90526 | A security vulnerability has been detected in SourceCodester School Registration and Fee System 1.0. This imp… |
| CVE-2026-90783 | NVD | 7.8 | 2026-09-13 | CVE-2026-90783 | MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib library's ODML superindex pars… |
| CVE-2026-90519 | NVD | 6.3 | 2026-09-13 | CVE-2026-90519 | A weakness has been identified in PHPGurukul Bank Locker Management System 1.0. Affected is an unknown functi… |
| CVE-2026-90517 | NVD | 5.3 | 2026-09-13 | CVE-2026-90517 | A vulnerability was identified in PHPGurukul Bank Locker Management System 1.0. This affects an unknown funct… |
| CVE-2026-90518 | NVD | 6.3 | 2026-09-13 | CVE-2026-90518 | A security flaw has been discovered in PHPGurukul Bank Locker Management System 1.0. This impacts an unknown … |
| CVE-2026-90775 | NVD | 6.5 | 2026-09-13 | CVE-2026-90775 | PostGIS address_standardizer through 3.7.0 fails to validate the Weight parameter from caller-supplied rules … |
| CVE-2026-90776 | NVD | 7.5 | 2026-09-13 | CVE-2026-90776 | Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time complexity vulnerability in the addresspars… |
| CVE-2026-90516 | NVD | 7.3 | 2026-09-13 | CVE-2026-90516 | A vulnerability was found in SourceCodester School Registration and Fee System 1.0. The affected element is a… |
| CVE-2026-90515 | NVD | 7.3 | 2026-09-13 | CVE-2026-90515 | A vulnerability was determined in SourceCodester School Registration and Fee System 1.0. The impacted element… |
| CVE-2026-90774 | NVD | 7.5 | 2026-09-13 | CVE-2026-90774 | rustypaste before 0.18.1 validates the destination path before applying the optional custom filename HTTP hea… |
| CVE-2026-90514 | NVD | 7.3 | 2026-09-13 | CVE-2026-90514 | A vulnerability has been found in SourceCodester School Registration and Fee System 1.0. Impacted is an unkno… |
| CVE-2026-85706 | KEV | — | 2026-09-11 | GitLab Community Edition and Enterprise Edition | GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability that allows an unauth… |
| CVE-2026-42018 | KEV | — | 2026-09-11 | JFrog Artifactory | JFrog Artifactory contains an improper authentication vulnerability that could return an internal anonymous-u… |
| CVE-2026-42016 | KEV | — | 2026-09-11 | JFrog Artifactory | JFrog Artifactory contains an incorrect authorization vulnerability that allows leads to privilege escalation… |
| CVE-2026-84869 | KEV | — | 2026-09-11 | ConnectWise ScreenConnect | ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerabil… |
| CVE-2026-67277 | KEV | — | 2026-09-10 | MikroTik RouterOS | MikroTik RouterOS contains a missing authenticaion for critical function vulnerability which allows kernel me… |
| CVE-2026-86060 | KEV | — | 2026-09-10 | MikroTik RouterOS | MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which… |
| CVE-2026-20079 | KEV | — | 2026-09-09 | Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management | Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Manage… |
| CVE-2026-87491 | KEV | — | 2026-09-09 | Google Chromium V8 | Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arb… |
| CVE-2025-25249 | KEV | — | 2026-09-09 | Fortinet Multiple Products | Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that a… |
| CVE-2026-19490 | KEV | — | 2026-09-09 | Citrix NetScaler | Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an altern… |
| CVE-2026-85880 | KEV | — | 2026-09-08 | Microsoft Windows | Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allo… |
| CVE-2026-86218 | KEV | — | 2026-09-08 | N-able N-central | N-able N-central contains a static code injection vulnerability that could allow for pre-authentication remot… |
| CVE-2026-81963 | KEV | — | 2026-09-08 | Microsoft Windows | Microsoft Windows Update Stack contains a link following vulnerability that allows a local attacker to escala… |
| CVE-2026-75650 | KEV | — | 2026-09-08 | Adobe Commerce and Magento | Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a templ… |
| CVE-2026-85046 | KEV | — | 2026-09-04 | Google Chromium V8 | Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary… |
| CVE-2026-83549 | KEV | — | 2026-09-02 | SonicWall SMA1000 Appliances | SonicWall SMA1000 Appliances contains an OS command injection vulnerability that could enable a remote authen… |
| CVE-2026-83548 | KEV | — | 2026-09-02 | SonicWall SMA1000 Appliances | SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote u… |
| CVE-2026-9586 | KEV | — | 2026-09-02 | Sangoma Switchvox | Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to e… |
| CVE-2026-82329 | KEV | — | 2026-09-02 | JFrog Artifactory | JFrog Artifactory contains an improper authentication vulnerability that under default configuration can allo… |
| CVE-2026-49869 | KEV | — | 2026-09-02 | Kestra Kestra OSS | Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker… |
| CVE-2026-48710 | KEV | — | 2026-09-02 | Kludex Starlette | Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to injec… |
| CVE-2026-59822 | KEV | — | 2026-09-02 | BerriAI LiteLLM | BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that co… |
| CVE-2026-81578 | KEV | — | 2026-08-31 | PaperCut NG/MF | PaperCut NG/MF contains a missing authentication for critical function vulnerability which allows an unauthen… |
| CVE-2026-82078 | KEV | — | 2026-08-31 | PaperCut NG/MF | PaperCut NG/MF contains an unsafe reflection vulnerability that allows an attacker to manipulate system confi… |
| CVE-2026-66384 | KEV | — | 2026-08-27 | JFrog Artifactory | JFrog Artifactory contains an improper limitation of a pathname to a restricted directory vulnerability. This… |
| CVE-2026-53362 | KEV | — | 2026-08-27 | Linux Kernel | Linux Kernel contains an unspecified vulnerability that can allow for privilege escalation via IPv6 networkin… |
| CVE-2023-49105 | KEV | — | 2026-08-27 | ownCloud ownCloud | ownCloud contains an improper authentication vulnerability that allows an attacker to access, modify, or dele… |
| CVE-2019-1068 | KEV | — | 2026-08-26 | Microsoft SQL Server | Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute c… |
| CVE-2026-8452 | KEV | — | 2026-08-26 | Citrix NetScaler ADC and NetScaler Gateway | Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of… |
| CVE-2022-0995 | KEV | — | 2026-08-26 | Linux Kernel | Linux Kernel contains an out-of-bounds memory write vulnerability which could allow a local user to gain priv… |
| CVE-2015-5287 | KEV | — | 2026-08-26 | Red Hat Automatic Bug Reporting Tool | Red Hat Automatic Bug Reporting Tool (ABRT) contains a privilege escalation vulnerability that could allow lo… |
| CVE-2015-3246 | KEV | — | 2026-08-26 | Red Hat Libuser | Red Hat libuser contains a race condition vulnerability that allows authenticated local users to corrupt the … |
| CVE-2021-23758 | KEV | — | 2026-08-26 | Ajax.NET Professional Ajax.NET Professional | Ajax.NET Professional (AjaxPro) contains a deserialization of untrusted data vulnerability that could allow f… |
| CVE-2026-60004 | KEV | — | 2026-08-25 | Gitea Gitea | Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a … |
| CVE-2026-21962 | KEV | — | 2026-08-24 | Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in | Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in contain an improper access control vulnerability … |
| CVE-2026-73570 | KEV | — | 2026-08-21 | Synacor Zimbra Collaboration Suite (ZCS) | Zimbra Collaboration Suite (ZCS) contains an OS command injection vulnerability which could allow an unauthen… |
| CVE-2026-72529 | KEV | — | 2026-08-20 | TrueConf Server | TrueConf Server contains a missing authentication for critical function vulnerability which could allow a rem… |
| CVE-2026-72530 | KEV | — | 2026-08-20 | TrueConf Server | TrueConf Server contains a code injection vulnerability that could allow an unauthorized remote attacker with… |
| CVE-2026-64849 | KEV | — | 2026-08-19 | MLflow MLflow | MLflow contains a server-side request forgery vulnerability that can allow attackers to reach internal or clo… |
| CVE-2026-65400 | KEV | — | 2026-08-18 | Apple macOS | Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to … |
| CVE-2026-55040 | KEV | — | 2026-08-18 | Microsoft SharePoint | Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to by… |
| CVE-2026-59310 | KEV | — | 2026-08-18 | Broadcom VMware vCenter | Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network… |
| CVE-2026-33824 | KEV | — | 2026-08-18 | Microsoft Internet Key Exchange (IKE) Service Extensions | Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enab… |
| CVE-2025-62593 | KEV | — | 2026-08-17 | Ray-Project Ray | Ray-Project Ray contains a code injection vulnerability that could allow remote code execution. Developers us… |
| CVE-2026-72898 | KEV | — | 2026-08-11 | Metabase Metabase | Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbi… |
| CVE-2026-68820 | KEV | — | 2026-08-11 | Microsoft Windows Ancillary Function Driver for WinSock | Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows a… |
| CVE-2026-20349 | KEV | — | 2026-08-11 | Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) | Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a he… |
| CVE-2026-8037 | KEV | — | 2026-08-07 | Progress LoadMaster | Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to ex… |
| CVE-2026-63077 | KEV | — | 2026-08-05 | JetBrains TeamCity | JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticate… |
| CVE-2026-9198 | KEV | — | 2026-08-04 | IBM Langflow | Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote… |
| CVE-2026-34486 | KEV | — | 2026-08-04 | Apache Tomcat | Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the Enc… |
| CVE-2026-18556 | KEV | — | 2026-08-04 | N-able N-central | N-able N-central contains an authentication bypass using an alternate path or channel that allows for authent… |
| CVE-2026-18577 | KEV | — | 2026-08-03 | N-able N-central | N-able N-central contains an authentication bypass using an alternate path or channel allows for authenticati… |
| CVE-2026-20316 | KEV | — | 2026-07-29 | Cisco Secure Firewall Management Center (FMC) | Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of… |
| CVE-2026-16812 | KEV | — | 2026-07-27 | Arista VeloCloud Orchestrator | Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote … |
| CVE-2025-68686 | KEV | — | 2026-07-27 | Fortinet FortiOS | Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This m… |
| CVE-2026-50522 | KEV | — | 2026-07-22 | Microsoft SharePoint | Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthor… |
| CVE-2026-16232 | KEV | — | 2026-07-22 | Check Point SmartConsole | Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticat… |
| CVE-2026-60137 | KEV | — | 2026-07-21 | WordPress Core | WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the pa… |
1 / 1
KEV = CISA Known Exploited Vulnerabilities (actively exploited in the wild — patch first). NVD = newly published CVEs relevant to common server/dev stacks, sorted by CVSS. Data updates several times a day from public feeds.
Sources: CISA Known Exploited Vulnerabilities catalog + NVD CVE feed, filtered to software stacks worth watching. Click a column header to sort; use the filter buttons to isolate KEV entries.