Zero-Day & Actively Exploited Vulnerabilities

Vulnerabilities that are being exploited before or shortly after a patch exists. Most entries here originate from the CISA Known Exploited Vulnerabilities catalog and high-CVSS NVD records, rewritten into a summary, affected systems, and prioritized fixes.

Other conventional threat types

Showing 1–20 of 258 threats, newest first

cisconexus-9000ios-xrrceunauthenticatednetwork-infrastructureroot-accessagent-relevant

Cisco disclosed a critical unauthenticated remote code execution vulnerability (CVE-2026-20212, CVSS 9.8) affecting 10 Silicon One-based Nexus 9000 switch models, allowing attackers to execute code as root without credentials. Alongside this, Cisco released an IOS XR hardening bundle addressing 7 CVEs, two rated 9.8, with no available workarounds for any affected IOS XR version, making immediate patching the only mitigation.

Updated Sep 4, 2026 · CVSS 9.8

network-infrastructurearubaos-cxrcehpepatch-availableagent-relevant

HPE has released patches for a critical remote code execution vulnerability in ArubaOS-CX, the network operating system powering Aruba switches. Exploitation could allow attackers to gain control over network infrastructure, potentially enabling lateral movement and traffic interception across enterprise environments.

Updated Sep 4, 2026

mozillathunderbirdfirefoxmemory-corruptionbrowser-securityemail-client

A set of internally discovered memory corruption bugs affecting Thunderbird and its ESR branches could potentially be exploited to achieve code execution. Mozilla has patched the issue across Firefox and Thunderbird release and ESR channels, and no public exploitation has been confirmed at this time.

Updated Sep 4, 2026 · CVSS 9.8

thunderbirdfirefoxmemory-corruptionmozillabrowser-securityemail-client

Internal security research identified multiple memory corruption bugs in Thunderbird 154 that could potentially be exploited by attackers. Mozilla has patched these issues in Thunderbird 155 and Firefox 155, though no public exploitation has been confirmed. The high CVSS score reflects the potential severity if these flaws were weaponized.

Updated Sep 4, 2026 · CVSS 9.8

browser-vulnerabilityinteger-overflowfirefoxthunderbirdmemory-corruptionrceagent-relevant

A critical integer overflow vulnerability has been identified in the Graphics: ImageLib component of Mozilla Firefox and Thunderbird, carrying a CVSS score of 9.8. The flaw could allow attackers to achieve memory corruption and potentially remote code execution through crafted image content. Mozilla has released patches in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

Updated Sep 4, 2026 · CVSS 9.8

browser-vulnerabilitysite-isolationfirefoxthunderbirdmozillarce-potentialagent-relevant

A critical site isolation flaw in the DOM Navigation component affects Firefox, Firefox ESR, and Thunderbird, potentially allowing cross-origin data leakage or sandbox bypass. With a CVSS score of 9.8, successful exploitation could let attackers bypass browser security boundaries to access sensitive cross-site data. Mozilla has released patches in Firefox 155, Firefox ESR 153.2, and Thunderbird 155/153.2.

Updated Sep 4, 2026 · CVSS 9.8

authentication-bypassartifactorytoken-forgerysupply-chainagent-relevantci-cdprivilege-escalation

A critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory is being actively exploited to forge tokens granting administrative access. Attackers exploiting this flaw can gain full control over artifact repositories used in software build and deployment pipelines, enabling malicious package injection and data exfiltration.

Updated Sep 3, 2026

wordpresssql-injectionplugin-vulnerabilityrcewebsite-takeoverunauthenticated-attack

A critical SQL injection vulnerability in the widely-used All-in-One WP Migration and Backup WordPress plugin allows unauthenticated attackers to execute remote code and fully compromise affected sites. With millions of active installations, this flaw poses a significant risk of mass exploitation, website defacement, and data theft.

Updated Sep 3, 2026 · CVSS 9.8

VoIPSQL-injectionRCEreverse-shellSangomaSwitchvoxunauthenticatedexploitation-in-the-wild

Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection flaw in the Sangoma Switchvox VoIP platform, to achieve remote code execution and deploy reverse shells. The vulnerability allows attackers to gain full control of vulnerable systems without credentials, posing a serious risk to organizations running exposed Switchvox deployments.

Updated Sep 3, 2026

sonicwallcommand-injectionrceremote-accessvpn-appliancecisa-kevedge-device

CVE-2026-83549 is an OS command injection vulnerability in SonicWall SMA1000 Appliances that allows an authenticated remote attacker with administrative privileges to execute arbitrary OS commands, leading to full remote code execution. CISA has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog with an unusually short three-day remediation window, indicating active exploitation or imminent risk. Organizations using SMA1000 appliances for secure remote access should prioritize immediate patching.

Updated Sep 3, 2026

SonicWallSSRFCISA-KEVremote-accessVPN-applianceunauthenticated-exploit

CVE-2026-83548 is a server-side request forgery vulnerability in SonicWall SMA1000 Appliances that allows a remote, unauthenticated attacker to reach sensitive internal functionality and perform unauthorized operations. CISA has added this CVE to its Known Exploited Vulnerabilities catalog with a compressed remediation window, indicating active or imminent exploitation in the wild. Organizations using SMA1000 for secure remote access should treat this as an urgent patching priority.

Updated Sep 3, 2026

sql-injectionunauthenticated-rcevoipcisa-kevpostgresqlnetwork-appliance

Sangoma Switchvox, a VoIP PBX platform, contains an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request. This flaw has been added to CISA's Known Exploited Vulnerabilities catalog with an extremely tight remediation window, indicating active exploitation in the wild. Successful exploitation can lead to database compromise and remote code execution on the underlying host.

Updated Sep 3, 2026 · CVSS 9.8

kestraos-command-injectionunauthenticated-rceworkflow-orchestrationcisa-kevagent-relevant

Kestra OSS, an open-source workflow and orchestration platform, contains an OS command injection vulnerability (CVE-2026-49869) that allows unauthenticated remote attackers to create and execute arbitrary workflows without credentials. This vulnerability has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation in the wild, with a remediation due date of September 5, 2026.

Updated Sep 3, 2026

starlettepythonasgirequest-smugglingauthentication-bypassagent-relevantsupply-chaincisa-kev

A HTTP request/response smuggling flaw in the Starlette ASGI framework allows attackers to inject paths into the host portion of a request, causing URL reconstruction that can bypass authentication logic dependent on the reconstructed path. CISA has added this to the KEV catalog, and it may be chained with CVE-2026-42271 to escalate impact. Organizations running Starlette-based web services, including those exposing agent APIs, should prioritize patching before the September 16, 2026 due date.

Updated Sep 3, 2026

artifactoryauthentication-bypasssupply-chainci-cddevopsagent-relevantexploitation-in-the-wild

Threat actors are actively exploiting a critical authentication bypass vulnerability (CVE-2026-82329, CVSS 9.8) in JFrog Artifactory just days after public disclosure, allowing attackers to mint administrative access tokens under default configurations. This provides full administrative control over artifact repositories, enabling malicious package injection, credential theft, and downstream supply-chain compromise.

Updated Sep 2, 2026 · CVSS 9.8

authentication-bypassproxmoxvirtualizationprivilege-escalationagent-relevanteol-softwareapi-vulnerability

A critical authentication bypass vulnerability in Proxmox Virtual Environment allows unauthenticated attackers to log in as any enabled user, including root@pam, by supplying an arbitrary value in the tfa-challenge parameter during API login. This completely circumvents password verification and two-factor authentication, granting full administrative control over the hypervisor. All affected versions are end of life and will not receive official patches, making immediate upgrade the only viable remediation path.

Updated Sep 2, 2026 · CVSS 9.8

wordpressprivilege-escalationaccount-takeoverauthentication-bypasscmsweb-application

The Nokri Job Board WordPress theme (versions up to 1.6.6) contains a critical authentication bypass vulnerability that allows unauthenticated attackers to take over any user account, including administrators. The flaw stems from improper validation of password reset tokens, enabling attackers to reset passwords using empty token values matched against empty or unset user meta fields.

Updated Sep 2, 2026 · CVSS 9.8

path-traversaldokploytraefikrceunauthenticatedpublic-exploitagent-relevantself-hosted-paasdevops-tooling

A critical unauthenticated path traversal vulnerability affects Dokploy up to version 0.29.7, specifically in the writeTraefikConfigInPath function used by the Settings component to generate Traefik configuration files. The flaw allows remote attackers to manipulate the path argument to write files outside intended directories, potentially leading to configuration overwrite, service disruption, or remote code execution. A public exploit is available and the vendor has not responded to disclosure, leaving deployments unpatched and exposed.

Updated Sep 2, 2026 · CVSS 9.9

d-linknasos-command-injectioncginetwork-storagepublicly-disclosedremote-exploitiot

A critical OS command injection vulnerability affects multiple D-Link NAS devices (DNS-320L, DNS-327L, DNS-340L, DNS-345) through the usb_device.cgi CGI handler. The flaw allows unauthenticated remote attackers to execute arbitrary OS commands via the f_ups_ip parameter, and a public exploit is already available, making immediate exploitation highly likely.

Updated Sep 2, 2026 · CVSS 9.1

iotrouterbuffer-overflowrcetotolinkpublic-exploitunauthenticated

A critical stack-based buffer overflow vulnerability affects the TOTOLINK NR1800X router firmware, exploitable remotely via the setUploadSetting function without authentication. A public exploit exists, making this an immediate risk for internet-exposed devices.

Updated Sep 1, 2026 · CVSS 9.9