Microsoft Outlook RCE needs only one bad email
A remote code execution flaw in Outlook rated HIGH at CVSS 8.8 lets an attacker run code as the user once a crafted message is opened or previewed.
113 of 113 advisories
A remote code execution flaw in Outlook rated HIGH at CVSS 8.8 lets an attacker run code as the user once a crafted message is opened or previewed.
SigNoz before 0.143.0 signed session tokens with an empty key when no JWT secret was configured, letting unauthenticated attackers forge admin session tokens.
A remote attacker with no credentials can execute arbitrary code on IBM Financial Transaction Manager for RedHat OpenShift because user-controlled input reaches the new Function constructor.
IBM Financial Transaction Manager for RedHat OpenShift deserializes untrusted data, letting a remote attacker with no credentials execute arbitrary code.
A remote authenticated attacker can bypass symbolic-link validation in IBM Financial Transaction Manager for RedHat OpenShift to read sensitive files, rated critical at CVSS 9.9.
IBM Concert 1.0.0 through 3.0.0 incorporates specially crafted input into OS commands, allowing an unauthenticated remote attacker to execute arbitrary commands with the application's privileges.
Improper bounds checking in IBM Concert 1.0.0 through 3.0.0 lets a local user overflow a buffer and execute arbitrary code on the system.
IBM Concert 1.0.0 through 3.0.0 accesses memory after it has been freed, allowing an attacker who can influence program input to corrupt memory, crash the application, or execute arbitrary code.
An incomplete blocklist on the AWX container group pod_spec_override field lets an AAP platform administrator inject initContainers and service account overrides, escalating to OpenShift namespace-level access and secret exfiltration.
The AWX CopyAPIView POST handler never performs the object-level read check that the GET handler does, letting users copy job templates they are not allowed to read.
IBM DataStage on Cloud Pak for Data 5.4.0.0 fails to neutralize special elements in OS commands, letting a remote authenticated attacker execute arbitrary commands.
Improper escaping of connector property values during OSH script generation in IBM DataStage on Cloud Pak for Data 5.4.0.0 lets a remote authenticated attacker execute arbitrary code.
A further OS command injection in IBM DataStage on Cloud Pak for Data 5.4.0.0 lets a remote authenticated attacker execute arbitrary commands through improperly neutralized special elements.
The automation controller's job output view expands ANSI OSC 8 hyperlinks into clickable anchors without filtering schemes, letting a low-privilege user plant javascript: links that execute in a higher-privileged viewer's session.
An administrator-controlled log message template in automation controller is rendered with a live user object, allowing format string traversal that reads the Django secret key and database password into forwardable logs.
Copying a WorkflowJobTemplate in automation controller skips permission checks on instance groups, letting a workflow admin launch attacker-influenced automation in the control-plane execution context.
A compromised Flatpak repository can write attacker-controlled content to arbitrary host filesystem locations through extract_extra_data, running as root on system installs via symlink following and unsanitized path traversal.
An apostrophe in an OpenAPI path segment breaks out of single-quoted route literals in @orval/hono output, injecting arbitrary JavaScript that executes when the generated module is imported.
Schema defaults containing ${...} syntax are converted into template literals by the @orval/effect generator, executing injected JavaScript at module scope when the generated code is built or imported.
orval emits the operationId into generated TanStack Query mutator metadata without escaping, so a crafted operationId in an OpenAPI spec injects JavaScript that runs when the generated hooks are called.
A chained authorization flaw in Meta Box AIO (and the standalone Meta Box Frontend Submission and Meta Box User Profile plugins) lets unauthenticated attackers overwrite any page with a crafted shortcode and register an Administrator account. Fixed in Meta Box AIO 3.12.0.
SolarWinds Observability Self-Hosted contains an unauthenticated remote code execution flaw from insufficient integrity checks, affecting non-default, non-secure configurations. CVSS 9.8.
SolarWinds Observability Self-Hosted is affected by an unauthenticated remote code execution flaw from deserialization of untrusted data in a specific communication mode. CVSS 8.8.
A path traversal flaw in Adobe Connect lets an unauthenticated attacker read arbitrary files outside the intended scope. CVSS 8.6.
Adobe Campaign Classic is affected by an unauthenticated improper code-generation flaw that can lead to arbitrary code execution with scope changed. CVSS 10.0.
A SQL injection flaw in Adobe Connect lets a low-privileged attacker execute arbitrary SQL and reach code execution with changed scope. CVSS 9.9.
A stored cross-site scripting flaw in Adobe Connect lets an attacker run malicious JavaScript in a victim's browser and potentially take over accounts or sessions. CVSS 9.3.
A stored cross-site scripting flaw in Adobe Connect lets an attacker run malicious JavaScript in a victim's browser and potentially take over accounts or sessions. CVSS 9.3.
A reflected cross-site scripting flaw in Adobe Connect lets an attacker run malicious JavaScript in a victim's browser and potentially take over accounts or sessions. CVSS 9.3.
Adobe Campaign Classic is affected by an unauthenticated improper code-generation flaw that can lead to arbitrary code execution with scope changed. CVSS 10.0.
Adobe Campaign Classic is affected by an unauthenticated improper code-generation flaw that can lead to arbitrary code execution with scope changed. CVSS 10.0.
An incorrect authorization flaw in Adobe Campaign Classic lets an unauthenticated attacker reach arbitrary code execution without user interaction. CVSS 9.1.
An incorrect authorization flaw in Adobe Experience Manager Forms JEE lets an unauthenticated attacker execute arbitrary code with changed scope. CVSS 10.0.
An unauthenticated-facing but credentialed command injection via the undocumented mfc eeprom write command lets any authenticated user run arbitrary shell commands as root on Lantronix SLC8000, EMG8500/7500 and sibling out-of-band management devices. CVSS 9.9.
A command injection in the set cifs password command on Lantronix out-of-band devices lets authenticated users with the services permission run arbitrary commands as root. CVSS 9.1.
A stack-based buffer overflow in the undocumented mfc eeprom read command on Lantronix out-of-band devices lets any authenticated user potentially execute arbitrary code by supplying oversized input. CVSS 9.9.
A server-side request forgery in the WebSSH/WebTelnet listener of Lantronix out-of-band devices lets an unauthenticated attacker redirect SSH terminal connections to arbitrary hosts and probe internal networks. CVSS 8.6.
An OS command injection in the set nfs download command on Lantronix out-of-band devices lets authenticated users with the services permission execute arbitrary commands as root. CVSS 9.1.
An OS command injection in the set script schedule command on Lantronix out-of-band devices lets authenticated users with the services permission execute arbitrary commands as root. CVSS 9.1.
A path-truncation flaw in the web management portal of Lantronix out-of-band devices lets unauthenticated attackers bypass session checks, read sensitive config files, and upload files anywhere, leading to remote code execution. CVSS 10.0.
A path traversal flaw in the web management upload endpoint of Lantronix out-of-band devices lets authenticated attackers write arbitrary files anywhere on the filesystem, leading to remote code execution. CVSS 9.1.
An improper input validation flaw in Adobe Experience Manager Forms JEE lets an attacker with high privileges execute arbitrary code. CVSS 9.1.
A server-side request forgery flaw in Adobe Experience Manager Forms JEE lets a low-privileged attacker reach internal resources and escalate privileges. CVSS 9.6.
An improper input validation flaw in Adobe Campaign Classic lets a low-privileged attacker execute arbitrary code, though exploitation depends on conditions beyond the attacker's control. CVSS 8.5.
A SQL injection flaw in Adobe Campaign Classic lets an attacker with high privileges execute arbitrary SQL commands and reach code execution. CVSS 9.1.
A SQL injection flaw in Adobe Campaign Classic lets a low-privileged attacker bypass security measures and gain unauthorized read and limited write access. CVSS 9.1.
A server-side request forgery flaw in Adobe Campaign Classic lets a low-privileged attacker reach internal resources and escalate privileges. CVSS 9.9.
A server-side request forgery flaw in Adobe Campaign Classic can be exploited without authentication to escalate privileges against internal resources. CVSS 9.9.
Adobe Campaign Classic is affected by an unauthenticated improper code-generation flaw that can lead to arbitrary code execution with scope changed. CVSS 10.0.
An improper code-generation flaw in Adobe Campaign Classic lets a low-privileged attacker execute arbitrary code with changed scope. CVSS 9.9.
An unauthenticated local file inclusion flaw in the HUSKY Products Filter for WooCommerce Professional plugin lets visitors include and execute arbitrary .php files via the 'shortcode' parameter, because the only nonce check uses a value emitted into every front-end page.
A privilege escalation flaw in CUPS with the cups-filters serial backend lets a local user in the lpadmin group point a printer's device URI at an arbitrary path, so the root-privileged backend writes attacker-controlled data to any file. A public proof of concept exists.
Vaultwarden through 1.37.3 fails to validate organization membership status in cipher access queries, so revoked and unconfirmed members retain read, write, delete, and attachment access to organization secrets. CVSS 8.6.
CRI-O's container checkpoint/restore feature validates restore metadata insufficiently, so a privileged user restoring from crafted checkpoint content can perform unintended operations on the host filesystem. The feature is not enabled by default.
A tie-breaking bug in the pki-core v2 REST ACL filter resolves colliding literal and wildcard ACL keys by lexicographic comparison instead of specificity, letting the Certificate Manager Agents group's lower-privileged profiles.approve override the Administrator-only profiles.create required by POST /v2/profiles/raw.
Kamailio's CDP Diameter receiver has a heap-based buffer overflow in shm_malloc that can be triggered remotely with a crafted message. A public exploit exists. Fixed in 6.0.8 with upstream patch commits available for other branches.
Expat through 2.8.4 fails to validate low surrogates after high surrogates in UTF-16 input, letting lone high surrogates swallow following code units and hide markup from the parser. Fixed upstream via PR #1282.
Argo Workflows 4.1.0 through 4.1.3 skips cluster-scoped access review in ListArchivedWorkflows when the metadata.namespace selector uses the NotEquals operator, letting namespace-scoped users read archived workflows from other namespaces. Fixed in 4.1.4.
Mistral Vibe before 2.25.5 executes git hooks during worktree creation before trust validation, so opening a crafted repository can run arbitrary shell commands with the user's privileges. Fixed in 2.25.5.
getID3 before 1.9.26 concatenates media filenames into shell commands without escaping, letting attackers inject arbitrary OS commands that run with the PHP process's privileges. Fixed in 1.9.26.
OpenShift's console exposes devfile endpoints that let remote attackers force internal requests or exhaust console memory.
Deserialization of untrusted data can let a remote unauthenticated attacker execute arbitrary code on IBM Guardium Data Protection 12.2.
A flaw in vm2's bridge lets sandboxed code reach the host global object and execute arbitrary commands when a non-strict host function is exposed.
NodeVM's denylist omits child_process, so sandboxed code can execute arbitrary host commands when builtins are broadly allowed.
A logic error in the Pixel cellular modem allows adjacent-network privilege escalation with no user interaction; the September 2026 patch level fixes it.
An unauthenticated API request can bypass authentication on Cisco Identity Services Engine and ISE Passive Identity Connector, and Cisco warns successful exploitation can lead to root command execution.
A SQL injection flaw in the email parsing of Cisco AsyncOS for Secure Email Gateway lets an unauthenticated attacker execute arbitrary commands with root privileges by sending a malicious email.
JFrog Artifactory validates token signatures but not token scopes, so an attacker with a low-privileged token can escalate to administrative privileges. Wiz observed in-the-wild chaining into full admin takeover.
A missing-authorization flaw in the ScreenConnect client lets an attacker transfer and execute files through an active remote session without host confirmation. ConnectWise fixed it in ScreenConnect 26.6.5; CISA confirms active exploitation.
A path traversal flaw in GitLab's repository commits API lets an unauthenticated attacker read arbitrary files from a self-managed server. Fixed in GitLab 19.1.8, 19.2.6, and 19.3.2; CISA confirms active exploitation.
A heap-based buffer overflow in FortiOS, FortiSwitchManager, and FortiSASE lets an attacker execute code via crafted packets. SOCRadar links in-the-wild exploitation to the PivotC2 malware campaign; CISA confirms active exploitation.
An authentication bypass in NetScaler ADC and Gateway lets an unauthenticated remote attacker skip authentication on Gateway and AAA deployments. Fixed in builds 14.1-73.32 and 13.1-63.21; CISA confirms active exploitation.
An authentication bypass in Cisco Secure Firewall Management Center lets an unauthenticated remote attacker execute scripts as root. Cisco confirms active exploitation by multiple threat clusters, including ransomware and state-sponsored actors.
An out-of-bounds write in Chrome's V8 engine lets a remote attacker run code inside the browser sandbox via a crafted page. Fixed in Chrome 153.0.8010.36; Google confirms an exploit exists in the wild.
A template-engine flaw in Adobe Commerce and Magento Open Source lets an unauthenticated attacker inject PHP and get code execution during email rendering. Adobe shipped emergency hotfix VULN-39341; exploitation began before the patch.
A link-following flaw in the Windows Update Stack lets a local attacker escalate to SYSTEM. Microsoft patched it on September 8, 2026, and confirms it was exploited as a zero-day.
A heap-based buffer overflow in Windows ALPC lets code running in a low-privilege AppContainer escalate to SYSTEM. Microsoft patched it on September 8, 2026, and confirms in-the-wild exploitation.
Starlette versions before 1.0.1 rebuild request.url from an unvalidated Host header, so middleware gating on the URL path can be bypassed with a crafted header.
An OAuth2 passthrough fallback in LiteLLM's MCP Streamable HTTP endpoint lets an unauthenticated attacker use a fabricated Bearer token to establish an authenticated MCP session and reach configured tools.
An unsafe dynamic class loading flaw in PaperCut NG/MF lets attackers execute Java bytecode on the server; PaperCut confirms active exploitation and customer incidents.
ownCloud core 10.6.0 through 10.13.0 accepts pre-signed URLs even when no signing key is configured, allowing unauthenticated access to any user's files.
CVE-2019-1068, a remote code execution flaw in SQL Server from 2019, was added to the KEV catalog in 2026: unpatched legacy database servers are being hit.
An attacker with write access to a Gitea repository can abuse the diffpatch API to plant an executable Git hook and run arbitrary commands as the Gitea service account.
A URI-normalization inconsistency between Oracle HTTP Server and the WebLogic proxy plug-in lets an unauthenticated attacker bypass access controls and reach or modify backend application data.
An unauthenticated attacker can send specially crafted SMTP requests to Zimbra Collaboration Suite and trigger OS command injection through SNMP notification processing when the zimbra-snmp package is installed.
An unauthenticated MLflow webhook test can follow redirects into internal services or cloud metadata endpoints and return their responses.
A critical double-free flaw in the Windows IKE service can allow an unauthenticated network attacker to execute code on a reachable system.
A critical JWT authentication weakness can let an unauthenticated network attacker bypass SharePoint security controls and access protected data.
A critical directory-traversal flaw in the vCenter Syslog server can allow an unauthenticated network attacker to execute arbitrary code.
A critical state-management flaw can let a network attacker authenticate to macOS Screen Sharing without valid credentials.
Ray's browser-based request protection relies on a User-Agent check that Firefox and Safari can bypass, and combined with DNS rebinding it lets a malicious website execute code on a developer's Ray instance.
A heap-inspection flaw in the Remote Access SSL VPN service of Cisco Secure Firewall ASA and FTD lets an unauthenticated attacker force the device to reload, causing a denial of service.
A use-after-free race in the Windows AFD driver let local attackers escalate to SYSTEM. Microsoft patched it August 11, 2026; Check Point attributes zero-day exploitation to the Lazarus Group's Operation Dream Job.
An unauthenticated SQL-injection path can lead to Metabase administrator access, exposed database credentials, and data theft.
An incomplete earlier fix lets attackers bypass Apache Tomcat's EncryptInterceptor, sending unencrypted cluster messages that reach Java deserialization and enable unauthenticated remote code execution.
Attackers who previously compromised a FortiGate at the filesystem level can bypass the patch for Fortinet's symlink persistence mitigation and read sensitive files via crafted HTTPS requests.
CISA reports that unsafe deserialization in the TeamCity agent polling protocol can permit unauthenticated remote code execution.
An improper authentication vulnerability in Azure Key Vault allows an unauthorized attacker to elevate privileges over the network, rated CVSS 10.0.
A sandbox escape in TeamCity's Kotlin DSL handling allows code execution on the server, fixed in TeamCity 2025.11.6 and 2026.1.2.
An unauthenticated attacker can obtain an application login token from an internet-exposed Check Point Management Server and log in via SmartConsole with full administrative privileges.
Deserialization of untrusted data in SharePoint lets an unauthorized attacker execute code over the network with no authentication, rated CVSS 9.8.
An invalid pointer in Firefox's Disability Access APIs allows a sandbox escape, fixed in Firefox 153 and Thunderbird 153.
A SQL injection in WordPress's author__not_in query parameter, chained with a REST API flaw, gives unauthenticated remote code execution on default installs.
Insufficient access control granularity in AD FS allows an authorized local attacker to elevate to administrator; Microsoft reports functional exploit code and detected exploitation.
A CVSS 10.0 path traversal in ColdFusion 2025.9 / 2023.20 and earlier allows unauthenticated remote code execution, and Adobe confirms limited in-the-wild exploitation.
CISA says default Langflow deployments may permit unauthenticated attackers to achieve full remote code execution.
SimpleHelp 5.5.15 and earlier accept OIDC identity tokens without verifying their signature, letting an unauthenticated attacker log in as any user.
Gemini CLI in headless CI mode auto-trusted workspace folders, so a malicious .gemini/.env file could execute code on the host before sandboxing applied.
Traefik's StripPrefix middleware normalizes crafted paths after routing, letting unauthenticated requests reach backends that a separate router meant to protect.
When @n8n/mcp-browser runs in HTTP transport mode, its MCP endpoint accepts session and tool requests with no authentication, exposing browser control to any network client.
Langflow OSS combines a Python builtins injection flaw with default auto-login, giving unauthenticated attackers remote code execution on the host.
An improper authentication flaw in Azure Active Directory lets an unauthorized attacker elevate privileges over the network, with a CVSS 10.0 rating.
CISA says an unauthenticated attacker can execute arbitrary commands through unsanitized input in multiple LoadMaster command endpoints.
| Published | Advisory | Technology | Signal | Priority |
|---|---|---|---|---|
Microsoft Microsoft OutlookCVE-2026-70125 | Email client, Office productivity | Disclosed | Act now | |
SigNoz SigNozCVE-2026-97055 | Observability, Monitoring, Developer infrastructure | Disclosed | Act now | |
IBM Financial Transaction Manager (FTM) for RedHat OpenShiftCVE-2026-18162 | Financial services, OpenShift, Kubernetes | Disclosed | Act now | |
IBM Financial Transaction Manager (FTM) for RedHat OpenShiftCVE-2026-18163 | Financial services, OpenShift, Kubernetes | Disclosed | Act now | |
IBM Financial Transaction Manager (FTM) for RedHat OpenShiftCVE-2026-18169 | Financial services, OpenShift, Kubernetes | Disclosed | Act now | |
IBM IBM ConcertCVE-2026-6721 | Enterprise software, AI operations | Disclosed | Act now | |
IBM IBM ConcertCVE-2026-6730 | Enterprise software, AI operations | Disclosed | Act now | |
IBM IBM ConcertCVE-2026-6928 | Enterprise software, AI operations | Disclosed | Act now | |
Red Hat Red Hat Ansible Automation Platform 2CVE-2026-75884 | Kubernetes, OpenShift, Automation | Disclosed | Act now | |
Red Hat Red Hat Ansible Automation Platform 2CVE-2026-76648 | Automation, API security | Disclosed | High priority | |
IBM IBM DataStage on Cloud Pak for DataCVE-2026-80379 | Data engineering, Enterprise software | Disclosed | High priority | |
IBM IBM DataStage on Cloud Pak for DataCVE-2026-80412 | Data engineering, Enterprise software | Disclosed | High priority | |
IBM IBM DataStage on Cloud Pak for DataCVE-2026-80425 | Data engineering, Enterprise software | Disclosed | High priority | |
Red Hat Red Hat Ansible Automation Platform 2CVE-2026-84683 | Automation, Web application | Disclosed | High priority | |
Red Hat Red Hat Ansible Automation Platform 2CVE-2026-84691 | Automation, Logging | Disclosed | High priority | |
Red Hat Red Hat Ansible Automation Platform 2CVE-2026-84719 | Automation, Kubernetes, OpenShift | Disclosed | Act now | |
Flatpak FlatpakCVE-2026-96275 | Linux, Package management, Sandboxing | Disclosed | High priority | |
orval-labs orvalCVE-2026-96754 | JavaScript, TypeScript, Developer infrastructure, API tooling | Disclosed | Act now | |
orval-labs orvalCVE-2026-96755 | JavaScript, TypeScript, Developer infrastructure, API tooling | Disclosed | Act now | |
orval-labs orvalCVE-2026-96759 | JavaScript, TypeScript, Developer infrastructure, API tooling | Disclosed | Act now | |
Meta Box Meta Box AIOCVE-2026-13355 | WordPress, CMS plugins, Developer infrastructure | Disclosed | Act now | |
SolarWinds Observability Self-HostedCVE-2026-28324 | IT monitoring, Observability | Disclosed | Act now | |
SolarWinds Observability Self-HostedCVE-2026-28325 | IT monitoring, Observability | Disclosed | High priority | |
Adobe Adobe ConnectCVE-2026-34689 | Collaboration, Web applications | Disclosed | High priority | |
Adobe Adobe Campaign ClassicCVE-2026-73369 | Marketing automation, Web applications | Disclosed | Act now | |
Adobe Adobe ConnectCVE-2026-75682 | Collaboration, Web applications | Disclosed | High priority | |
Adobe Adobe ConnectCVE-2026-75684 | Collaboration, Web applications | Disclosed | High priority | |
Adobe Adobe ConnectCVE-2026-75689 | Collaboration, Web applications | Disclosed | High priority | |
Adobe Adobe ConnectCVE-2026-75698 | Collaboration, Web applications | Disclosed | High priority | |
Adobe Adobe Campaign ClassicCVE-2026-75699 | Marketing automation, Web applications | Disclosed | Act now | |
Adobe Adobe Campaign ClassicCVE-2026-75721 | Marketing automation, Web applications | Disclosed | Act now | |
Adobe Adobe Campaign ClassicCVE-2026-75728 | Marketing automation, Web applications | Disclosed | High priority | |
Adobe AEM 6.5 Forms JEECVE-2026-75745 | Content management, Web applications | Disclosed | Act now | |
Lantronix SLC8000 / EMG8500 / EMG7500 out-of-band devicesCVE-2026-80144 | Out-of-band management, Data center infrastructure | Disclosed | High priority | |
Lantronix SLC8000 / EMG8500 / EMG7500 out-of-band devicesCVE-2026-80145 | Out-of-band management, Data center infrastructure | Disclosed | High priority | |
Lantronix SLC8000 / EMG8500 / EMG7500 out-of-band devicesCVE-2026-80146 | Out-of-band management, Data center infrastructure | Disclosed | High priority | |
Lantronix SLC8000 / EMG8500 / EMG7500 out-of-band devicesCVE-2026-80149 | Out-of-band management, Data center infrastructure | Disclosed | High priority | |
Lantronix SLC8000 / EMG8500 / EMG7500 out-of-band devicesCVE-2026-80151 | Out-of-band management, Data center infrastructure | Disclosed | High priority | |
Lantronix SLC8000 / EMG8500 / EMG7500 out-of-band devicesCVE-2026-80152 | Out-of-band management, Data center infrastructure | Disclosed | High priority | |
Lantronix SLC8000 / EMG8500 / EMG7500 out-of-band devicesCVE-2026-80155 | Out-of-band management, Data center infrastructure | Disclosed | Act now | |
Lantronix SLC8000 / EMG8500 / EMG7500 out-of-band devicesCVE-2026-80156 | Out-of-band management, Data center infrastructure | Disclosed | High priority | |
Adobe AEM 6.5 Forms JEECVE-2026-81995 | Content management, Web applications | Disclosed | High priority | |
Adobe AEM 6.5 Forms JEECVE-2026-82000 | Content management, Web applications | Disclosed | High priority | |
Adobe Adobe Campaign ClassicCVE-2026-82003 | Marketing automation, Web applications | Disclosed | High priority | |
Adobe Adobe Campaign ClassicCVE-2026-82009 | Marketing automation, Web applications | Disclosed | High priority | |
Adobe Adobe Campaign ClassicCVE-2026-82011 | Marketing automation, Web applications | Disclosed | High priority | |
Adobe Adobe Campaign ClassicCVE-2026-82013 | Marketing automation, Web applications | Disclosed | High priority | |
Adobe Adobe Campaign ClassicCVE-2026-83660 | Marketing automation, Web applications | Disclosed | High priority | |
Adobe Adobe Campaign ClassicCVE-2026-89275 | Marketing automation, Web applications | Disclosed | Act now | |
Adobe Adobe Campaign ClassicCVE-2026-89276 | Marketing automation, Web applications | Disclosed | High priority | |
realmag777 HUSKY – Products Filter for WooCommerce ProfessionalCVE-2026-92969 | WordPress, WooCommerce, CMS plugins | Disclosed | High priority | |
OpenPrinting CUPSCVE-2026-95511 | Linux, Printing infrastructure, Open source | Disclosed | High priority | |
Vaultwarden VaultwardenCVE-2026-95814 | Password management, Self-hosted | Disclosed | High priority | |
Red Hat CRI-OCVE-2026-15801 | Kubernetes, Containers, Cloud infrastructure | Disclosed | High priority | |
Red Hat Red Hat Certificate SystemCVE-2026-80110 | Certificate authority, Linux servers, Identity infrastructure | Disclosed | High priority | |
Kamailio KamailioCVE-2026-93962 | Telecommunications, SIP infrastructure, VoIP | Disclosed | High priority | |
libexpat ExpatCVE-2026-93990 | Parsing libraries, Developer infrastructure, XML | Disclosed | High priority | |
argoproj Argo WorkflowsCVE-2026-93991 | Kubernetes, CI/CD, Developer infrastructure | Disclosed | High priority | |
mistralai Mistral VibeCVE-2026-93993 | AI, Developer tools, Agentic coding | Disclosed | High priority | |
James Heinrich getID3CVE-2026-94106 | Media processing, PHP libraries, Developer infrastructure | Disclosed | High priority | |
Red Hat Red Hat OpenShift Container Platform 4CVE-2026-75885 | Kubernetes, OpenShift, Container platforms | Disclosed | Act now | |
IBM Guardium Data ProtectionCVE-2026-81657 | Data security, Database monitoring, Enterprise infrastructure | Disclosed | Act now | |
vm2 vm2CVE-2026-93603 | JavaScript, Node.js, Developer infrastructure | Disclosed | Act now | |
vm2 vm2CVE-2026-93605 | JavaScript, Node.js, Developer infrastructure | Disclosed | Act now | |
Google PixelCVE-2026-58704 | Mobile devices, Android, Cellular baseband | Known exploited | Act now | |
Cisco Identity Services EngineCVE-2026-76460 | Identity and access management, Network security | Known exploited | Act now | |
Cisco Secure Email GatewayCVE-2026-76461 | Email security, Network security | Known exploited | Act now | |
JFrog ArtifactoryCVE-2026-42016 | Developer infrastructure, Artifact management, Supply chain | Known exploited | Act now | |
ConnectWise ScreenConnectCVE-2026-84869 | Remote access, IT support, Managed services | Known exploited | Act now | |
GitLab GitLabCVE-2026-85706 | DevOps, CI/CD, Source control | Known exploited | Act now | |
Fortinet FortiOSCVE-2025-25249 | Firewalls, Network security, SD-WAN | Known exploited | Act now | |
Citrix NetScalerCVE-2026-19490 | VPN, Network infrastructure, Remote access | Known exploited | Act now | |
Cisco Secure Firewall Management CenterCVE-2026-20079 | Firewalls, Network management, Security operations | Known exploited | Act now | |
Google ChromeCVE-2026-87491 | Web browsers, End-user devices | Known exploited | Act now | |
Adobe Adobe CommerceCVE-2026-75650 | E-commerce, Web applications, Payment processing | Known exploited | Act now | |
Microsoft WindowsCVE-2026-81963 | Operating systems, Endpoints | Known exploited | Act now | |
Microsoft WindowsCVE-2026-85880 | Operating systems, Endpoints | Known exploited | Act now | |
Kludex StarletteCVE-2026-48710 | Python, Web frameworks, ASGI, Developer infrastructure | Known exploited | Act now | |
BerriAI LiteLLMCVE-2026-59822 | AI, Developer infrastructure, API gateway | Known exploited | Act now | |
PaperCut PaperCut NG/MFCVE-2026-82078 | Print management, Enterprise applications, Java | Known exploited | Act now | |
ownCloud ownCloudCVE-2023-49105 | File sharing, WebDAV, Self-hosted services | Known exploited | Act now | |
Microsoft SQL ServerCVE-2019-1068 | Databases, Windows Server, Enterprise applications | Known exploited | Act now | |
Gitea GiteaCVE-2026-60004 | Developer infrastructure, Source control | Known exploited | Act now | |
Oracle Oracle HTTP ServerCVE-2026-21962 | Application servers, Enterprise middleware | Known exploited | Act now | |
Synacor Zimbra Collaboration SuiteCVE-2026-73570 | Email infrastructure, Collaboration | Known exploited | Act now | |
MLflow MLflowCVE-2026-64849 | AI, Machine learning, Developer infrastructure | Known exploited | Act now | |
Microsoft Windows IKE Service ExtensionsCVE-2026-33824 | Windows, IPsec, VPN infrastructure | Known exploited | Act now | |
Microsoft SharePoint ServerCVE-2026-55040 | Collaboration, Document management, On-premises infrastructure | Known exploited | Act now | |
Broadcom VMware vCenterCVE-2026-59310 | Virtualization, Infrastructure management | Known exploited | Act now | |
Apple macOSCVE-2026-65400 | Endpoints, Remote access, macOS | Known exploited | Act now | |
Ray-Project RayCVE-2025-62593 | AI, Machine learning, Developer infrastructure | Known exploited | Act now | |
Cisco Secure Firewall ASA and FTDCVE-2026-20349 | Network security, VPN | Known exploited | Act now | |
Microsoft WindowsCVE-2026-68820 | Operating systems, Endpoints, Kernel drivers | Known exploited | Act now | |
Metabase MetabaseCVE-2026-72898 | Analytics, Data platforms | Active exploitation | Act now | |
Apache TomcatCVE-2026-34486 | Java, Application servers | Known exploited | Act now | |
Fortinet FortiOSCVE-2025-68686 | Network security, VPN, Firewall infrastructure | Known exploited | Act now | |
JetBrains TeamCityCVE-2026-63077 | CI/CD, Developer infrastructure | Known exploited | Act now | |
Microsoft Azure Key VaultCVE-2026-62825 | Cloud, Secrets management, Microsoft Azure | Disclosed | Act now | |
JetBrains TeamCityCVE-2026-65906 | CI/CD, Developer infrastructure, Build systems | Disclosed | High priority | |
Check Point SmartConsoleCVE-2026-16232 | Network security, Security management, Firewall infrastructure | Known exploited | Act now | |
Microsoft SharePointCVE-2026-50522 | Collaboration, Enterprise applications, Windows Server | Known exploited | Act now | |
Mozilla FirefoxCVE-2026-16367 | Web browser, End-user devices, Email client | Disclosed | High priority | |
WordPress WordPress CoreCVE-2026-60137 | Content management, Web applications, PHP | Known exploited | Act now | |
Microsoft Active Directory Federation ServicesCVE-2026-56155 | Identity and access management, Active Directory, Windows Server | Known exploited | Act now | |
Adobe ColdFusionCVE-2026-48282 | Web application servers, Enterprise applications, Java | Known exploited | Act now | |
IBM LangflowCVE-2026-9198 | AI, Agent workflows | Known exploited | Act now | |
SimpleHelp SimpleHelpCVE-2026-48558 | Remote access, IT support tooling, Identity and access management | Known exploited | Act now | |
Google Gemini CLICVE-2026-12537 | AI, Developer infrastructure, CI/CD | Disclosed | High priority | |
Traefik TraefikCVE-2026-48020 | Networking, Reverse proxy, Cloud infrastructure | Disclosed | Act now | |
n8n n8nCVE-2026-54309 | Automation, AI, Developer infrastructure | Disclosed | Act now | |
IBM LangflowCVE-2026-10561 | AI, Machine learning, Developer infrastructure | Disclosed | Act now | |
Microsoft Azure Active DirectoryCVE-2026-45480 | Cloud, Identity and access management, Microsoft Azure | Disclosed | Act now | |
Progress LoadMasterCVE-2026-8037 | Infrastructure, Load balancers | Known exploited | Act now |
Either the filters are too specific, or security has finally been solved. Probably the filters.