Advertisement
CVE-2026-83548: SonicWall SMA1000 SSRF Under Active Exploitation
A critical server-side request forgery (SSRF) vulnerability, CVE-2026-83548, in SonicWall SMA1000 Appliances is under active exploitation.
CVE-2026-9586: Sangoma Switchvox RCE via SQL Injection
Sangoma Switchvox is affected by CVE-2026-9586, an unauthenticated remote SQL injection vulnerability enabling RCE, with active exploitation confirmed.
CVE-2026-49869: Kestra OSS OS Command Injection Exploited
CISA has added CVE-2026-49869, an OS command injection in Kestra OSS, to its KEV catalog, confirming active exploitation by unauthenticated attackers.
CVE-2026-59822: BerriAI LiteLLM Authentication Bypass
BerriAI LiteLLM is vulnerable to an improper authentication flaw (CVE-2026-59822) actively exploited to bypass authentication.
CVE-2021-23758: Ajax.NET RCE via Deserialization of Untrusted Data
CVE-2021-23758 in Ajax.NET Professional allows remote code execution via untrusted data deserialization, with CISA confirming active exploitation.
CVE-2026-66384: JFrog Artifactory Path Traversal Exploit
CISA warns of active exploitation of CVE-2026-66384 in JFrog Artifactory, allowing authenticated users to write data outside intended paths. Patch immediately.
Advertisement
CVE-2026-53362: Linux Kernel IPv6 Privilege Escalation
CISA adds CVE-2026-53362 to KEV, confirming active exploitation of a Linux Kernel privilege escalation vulnerability via IPv6. Patch now.
CVE-2026-60004: Gitea Code Injection Under Active Exploitation
CISA confirms active exploitation of CVE-2026-60004, a Gitea code injection vulnerability allowing shell command execution with repository write access.
CVE-2026-72529: Critical RCE in TrueConf Server via Missing Auth
CISA warns of active exploitation of CVE-2026-72529 in TrueConf Server, allowing remote attackers to execute arbitrary scripts via port 4307/TCP.
CVE-2026-72530: TrueConf Server Remote Code Execution
CISA confirms active exploitation of CVE-2026-72530, a TrueConf Server code injection flaw leading to remote code execution. Immediate patching is critical.
CVE-2026-33824: Microsoft IKE Double Free RCE Exploit
CISA confirms active exploitation of CVE-2026-33824 in Microsoft Internet Key Exchange (IKE) Service Extensions, enabling remote code execution.
CVE-2025-62593: Ray-Project Ray RCE Exploited In Wild
CISA confirms active exploitation of CVE-2025-62593, a critical code injection vulnerability in Ray-Project Ray allowing remote code execution. Developers are targeted.
CVE-2026-72898: Metabase SQL Injection Active Exploitation
CISA adds Metabase CVE-2026-72898 SQL injection to its KEV catalog, enabling unauthenticated remote attackers to gain admin access.
CVE-2026-20349: Cisco ASA/FTD DoS Vulnerability Under Active Exploit
CISA warns of active exploitation of CVE-2026-20349, a heap inspection vulnerability causing DoS in Cisco ASA and FTD devices.
CVE-2026-63077: JetBrains TeamCity RCE via Deserialization
CISA adds CVE-2026-63077 to KEV, indicating active exploitation of a JetBrains TeamCity deserialization RCE vulnerability.
CVE-2026-8037: Progress LoadMaster Command Injection RCE
Progress LoadMaster command injection (CVE-2026-8037) allows unauthenticated attackers to execute arbitrary commands. Active exploitation confirmed by CISA.
CISA Warns: Actively Exploited Langflow, N-central, and Tomcat Vulnerabilities
CISA warns federal agencies and organizations about active exploitation of critical vulnerabilities in IBM Langflow, N-able N-central, and Apache Tomcat.
CVE-2026-18556: N-able N-central Authentication Bypass Actively Exploited
CISA added CVE-2026-18556 to its KEV catalog, confirming active exploitation of an N-able N-central authentication bypass vulnerability.
CVE-2026-50522: SharePoint RCE via Deserialization — Patch Now
CISA confirmed active exploitation of CVE-2026-50522 in Microsoft SharePoint. Attackers leverage a deserialization vulnerability to execute code remotely. Patch…
CVE-2026-60137: WordPress Core SQL Injection to RCE — Patch Now
CISA warns of active exploitation for CVE-2026-60137, a WordPress Core SQL Injection vulnerability chaining to RCE for unauthenticated attackers.
CVE-2026-16232: Check Point SmartConsole Admin Bypass via Auth Flaw
CISA warns of active exploitation for CVE-2026-16232, an improper authentication vulnerability in Check Point SmartConsole allowing unauthenticated admin access…
CVE-2025-68686: Fortinet FortiOS Patch Bypass for Post-Exploit Persistence
CISA warns of active exploitation of CVE-2025-68686 in Fortinet FortiOS, allowing attackers to bypass a patch for post-exploit persistence and expose sensitive data.
CVE-2026-20316: Cisco Secure FMC Hard-coded Password Vulnerability
CISA confirms active exploitation of CVE-2026-20316, a hard-coded password vulnerability in Cisco Secure Firewall Management Center.
Cisco FMC CVE-2026-20316: Static Credentials Actively Exploited
CISA adds CVE-2026-20316 to its Known Exploited Vulnerabilities catalog following active exploitation of static credentials in Cisco Firewall Management Center.