Zero-Day & Actively Exploited Vulnerabilities

Other conventional threat types

Showing 181–200 of 270 threats, newest first

path-traversalrceunauthenticatedllm-servingh2oGPTagent-relevantapi-key-exposure

h2oGPT through version 0.2.1 contains an unauthenticated path traversal vulnerability in its OpenAI-compatible files API that allows attackers to read, write, and delete arbitrary files on the host. Because the default API key is empty and the bearer token is used unsanitized as a path component, attackers can bypass authentication entirely and achieve remote code execution by overwriting startup hooks or application-loaded files.

Updated Jul 25, 2026 · CVSS 9.8

zimbrazero-dayaptrussiaemail-compromise2fa-bypasscredential-theftespionageagent-relevant

A Russian state-sponsored espionage group exploited an unpatched zero-day vulnerability in Zimbra's webmail client to conduct a months-long mail collection campaign against Western targets. The exploit required no user interaction beyond opening a malicious email, and enabled theft of 90 days of mail history, full address book contents, browser-saved passwords, and 2FA recovery codes. NSA, CISA, and partner agencies have issued a joint advisory on the campaign.

Updated Jul 24, 2026

oracleldapdirectory-serviceunauthenticated-rceidentity-infrastructureagent-relevant

A maximum-severity vulnerability (CVSS 10.0) exists in Oracle Unified Directory's OUD Core component, allowing an unauthenticated attacker with network access via LDAP to fully compromise the directory service. The vulnerability's scope change indicates successful exploitation can impact additional connected products and systems beyond OUD itself.

Updated Jul 24, 2026 · CVSS 10

oracleaccess-managementauthentication-bypassunauthenticated-rcecritical-infrastructureidentity-provideragent-relevant

A maximum-severity (CVSS 10.0) vulnerability in Oracle Access Manager's Authentication Engine allows unauthenticated, network-based attackers to fully compromise the identity and access management system. The flaw has a scope change, meaning successful exploitation can cascade to impact other integrated applications and services relying on OAM for authentication.

Updated Jul 24, 2026 · CVSS 10

oracleaccess-managerfusion-middlewareunauthenticated-rceauthentication-bypassidentity-managementagent-relevant

A critical unauthenticated vulnerability (CVE-2026-60355) in Oracle Access Manager's Authentication Engine allows remote attackers to fully compromise the identity and access management system over HTTP with no credentials required. Given the CVSS 9.8 score and full confidentiality, integrity, and availability impact, successful exploitation could grant attackers complete control over enterprise authentication infrastructure. Organizations using Oracle Access Manager for SSO or identity federation are at severe risk of large-scale account takeover and downstream system compromise.

Updated Jul 24, 2026 · CVSS 9.8

oracleaccess-managerauthentication-bypassscope-changeidentity-providerssocritical-infrastructureagent-relevant

A critical vulnerability (CVSS 9.9) in Oracle Access Manager's Authentication Engine allows a low-privileged attacker with only network access via HTTP to fully compromise the identity and access management system. Due to a scope change, successful exploitation can impact additional connected products beyond Oracle Access Manager itself, making this a high-priority patching target for any organization relying on Oracle Fusion Middleware for SSO and access control.

Updated Jul 24, 2026 · CVSS 9.9

oraclecoherencerceunauthenticatedmiddlewarecritical-infrastructureagent-relevant

CVE-2026-60296 is a critical, easily exploitable vulnerability in Oracle Coherence (Oracle Fusion Middleware) that allows an unauthenticated attacker with network access to fully compromise the affected server over TCP. With a CVSS score of 9.8 and no authentication or user interaction required, this flaw poses severe risk to any organization running affected Coherence versions, including those used as caching/data grid layers behind enterprise and AI-driven applications.

Updated Jul 24, 2026 · CVSS 9.8

browser-extensionadobe-acrobatwhatsapp-webcross-origindata-exposurechrome-extensionprivacy

A now-patched vulnerability chain in the Adobe Acrobat Chrome extension, dubbed HermeticReader by Guardio Labs and tracked as CVE-2026-48294, could allow malicious websites to silently read a user's WhatsApp Web data. The extension, installed by over 314 million users, contained a flaw that broke cross-origin isolation, enabling covert hijacking of session data without user interaction.

Updated Jul 23, 2026 · CVSS 7.4

linuxprivilege-escalationubuntusnaplpeagent-relevant

A high-severity local privilege escalation vulnerability in Ubuntu's snap-confine component allows an unprivileged local user to gain full root access on default Ubuntu Desktop installations. The flaw affects Ubuntu Desktop 24.04, 25.10, and 26.04 out of the box, making it a significant risk for any multi-user or shared Linux host.

Updated Jul 23, 2026 · CVSS 7.8

CISAKEVCheck PointSmartConsoleSharePointdeserializationauthentication-bypassactive-exploitationfederal-agenciesagent-relevant

CISA has added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities Catalog: an improper authentication flaw in Check Point SmartConsole (CVE-2026-16232) and a deserialization of untrusted data vulnerability in Microsoft SharePoint (CVE-2026-50522). Both are confirmed to be exploited in the wild, prompting mandatory remediation timelines for FCEB agencies under BOD 26-04 and a strong recommendation for all organizations to patch immediately.

Updated Jul 23, 2026

ssrfagent-relevantllm-servingcloud-metadata-exposureunauthenticated-rce-precursorapi-vulnerabilitylmdeploy

CVE-2026-63764 is a critical unauthenticated SSRF vulnerability in lmdeploy's OpenAI-compatible API server, exploitable via the image_url parameter in chat completions requests. Attackers can chain HTTP redirects to bypass initial URL validation and reach internal services or cloud instance metadata endpoints, potentially exfiltrating cloud credentials. This directly threatens organizations self-hosting lmdeploy to serve multimodal LLMs behind agent or RAG pipelines.

Updated Jul 23, 2026 · CVSS 9.3

sharepointdeserializationrcecisa-kevunauthenticatedagent-relevant

CVE-2026-50522 is a deserialization of untrusted data vulnerability in Microsoft SharePoint that allows unauthorized attackers to achieve remote code execution over the network. CISA has added this CVE to its Known Exploited Vulnerabilities catalog with a compressed three-day remediation window, indicating active exploitation in the wild. Organizations running on-premises SharePoint should treat this as an urgent patching priority.

Updated Jul 23, 2026

authentication-bypassprivilege-escalationnetwork-securityCISA-KEVtoken-theftedge-device

CVE-2026-16232 is an improper authentication vulnerability in Check Point SmartConsole that allows an unauthenticated remote attacker to obtain an application login token and authenticate with full administrative privileges. This flaw has been added to CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild, with a remediation due date of 2026-07-25. Successful exploitation grants an attacker complete administrative control over the security management platform governing an organization's firewall and gateway policies.

Updated Jul 23, 2026

CVE-2026-65008GravCMSRCEcall_user_func_arrayunauthenticatedweb-shellagent-relevant

Grav CMS 2.0.4 contains a critical RCE vulnerability in its Blueprint::dynamicData() function, which passes attacker-controlled callable strings directly to call_user_func_array() without an allowlist. An authenticated user with page-write permissions can plant a malicious callable in page frontmatter that executes as the web-server user whenever any visitor loads the page, effectively converting low-privilege access into full server compromise.

Updated Jul 22, 2026 · CVSS 9.8

dd-wrtrouterupnpbuffer-overflowrcecisa-kevfirmwarenetwork-device

DD-WRT firmware contains a stack-based buffer overflow in its UPnP handling that allows unauthenticated remote attackers to execute arbitrary code. The vulnerability has been added to CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild. Organizations running DD-WRT on routers or edge devices should patch immediately given the short remediation window.

Updated Jul 22, 2026 · CVSS 9.8

wordpresssql-injectionrcecmscisa-kevunauthenticatedchained-exploitagent-relevant

WordPress Core contains a SQL injection flaw triggered when plugins or themes pass untrusted input to an affected parameter, and this has been added to CISA's Known Exploited Vulnerabilities catalog indicating active exploitation. When chained with CVE-2026-63030, it enables unauthenticated remote code execution on default WordPress installations, posing a severe risk to any internet-facing WordPress site.

Updated Jul 22, 2026

vpnzero-daysonicwallremote-accessedge-devicemalwarenetwork-perimeter

Threat actors exploited two previously undisclosed vulnerabilities in SonicWall SMA1000 series VPN appliances as zero-days for several weeks before public disclosure, deploying custom malware on compromised devices. The attacks targeted internet-facing remote access infrastructure, giving attackers a persistent foothold into victim networks.

Updated Jul 21, 2026

command-injectionrceunpatched-fixweb-applicationphpcve-2026-64625cve-2026-45578

AVideo before version 29.0 contains an incomplete patch for a previously disclosed command injection vulnerability, allowing attackers to execute arbitrary OS commands via the Live plugin's on_publish.php endpoint. Despite the use of escapeshellarg(), the execAsync() function re-wraps escaped commands in a double-quoted sh -c shell, enabling command substitution through $() and backticks. This flaw carries a critical CVSS score of 9.8 and requires no authentication for exploitation.

Updated Jul 21, 2026 · CVSS 9.8

agent-relevantrcepickle-deserializationllm-infrastructureunauthenticatedzmqai-inference-framework

A critical unauthenticated remote code execution vulnerability exists in ktransformers, a popular LLM inference acceleration framework, affecting versions through 0.6.3. Attackers can send crafted pickle payloads to the SchedulerServer's ZMQ ROUTER socket, which is bound to all network interfaces by default, to achieve arbitrary command execution as the server process with no authentication required.

Updated Jul 21, 2026 · CVSS 9.8

command-injectiongradiorceunauthenticatedai-toolingtext-to-speechagent-relevantsupply-chain-risk

GPT-SoVITS, a popular open-source voice cloning/text-to-speech toolkit, contains a critical unauthenticated OS command injection vulnerability (CVSS 9.8) in its Gradio-based web UI. Attackers can execute arbitrary shell commands as the server process user by injecting shell metacharacters into ASR, slicing, denoising, or UVR5 path parameters, with no authentication required.

Updated Jul 21, 2026 · CVSS 9.8