Zero-Day & Actively Exploited Vulnerabilities

Other conventional threat types

Showing 241–260 of 270 threats, newest first

firmwarebootloaderu-bootembedded-systemspersistencesupply-chainagent-relevant

Six newly disclosed vulnerabilities in the widely used U-Boot bootloader could allow attackers with local or physical access to execute malicious code during the boot process. Exploitation could bypass secure boot protections and enable stealthy, persistent firmware-level malware that survives OS reinstalls and standard remediation. The flaws pose a significant risk to embedded devices, IoT systems, and edge hardware that rely on U-Boot for initialization.

Updated Jul 11, 2026

CISAKEVAdobeColdFusionpath-traversalactive-exploitationfederal-agenciesBOD-26-04

CISA has added CVE-2026-48282, a path traversal vulnerability in Adobe ColdFusion, to its Known Exploited Vulnerabilities catalog based on confirmed active exploitation in the wild. Federal civilian agencies must remediate per BOD 26-04, and CISA urges all organizations to prioritize patching this flaw due to its demonstrated attractiveness to threat actors.

Updated Jul 11, 2026

wordpressfile-uploadrceunauthenticatedplugin-vulnerabilityweb-application

The Instant Appointment plugin for WordPress (versions up to 1.2) contains a critical arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files, potentially leading to remote code execution. Given the CVSS score of 9.8 and lack of authentication requirement, this vulnerability is highly likely to be targeted by automated exploitation once public details are available.

Updated Jul 11, 2026 · CVSS 9.8

open-webuipyodidesandbox-escapecsrfprivilege-escalationself-hosted-llmagent-relevantragllm-tool-use

Open WebUI versions prior to 0.10.0 execute client-side Python via Pyodide inside a same-origin web worker, which lacks proper isolation from the host page's authenticated session. A malicious stored chat payload can leverage pyodide.http.pyfetch or JS-exposed fetch/XMLHttpRequest APIs to make authenticated same-origin requests when a victim runs the code, enabling access to admin-only endpoints and server-side tool execution. This effectively turns a chat message into a stored XSRF/RCE primitive against self-hosted AI deployments.

Updated Jul 11, 2026 · CVSS 7.3

sql-injectionapi-gatewayibmunauthenticatedapi-connectagent-relevant

IBM API Connect versions 10.0.8.0-10.0.8.9 and 12.1.0.0-12.1.0.3 contain an unauthenticated SQL injection vulnerability in the password reset functionality, rated critical with a CVSS score of 9.1. An attacker can exploit this remotely without credentials to access, modify, or exfiltrate backend database contents.

Updated Jul 11, 2026 · CVSS 9.1

CISA-KEVunauthenticated-RCEfile-uploadplugin-vulnerabilityweb-applicationCMSJoomlaWordPresspatch-priority

Balbooa Forms, a form-builder component/plugin, contains an unrestricted file upload vulnerability allowing unauthenticated attackers to upload malicious executable files and achieve remote code execution. The flaw has been added to CISA's Known Exploited Vulnerabilities catalog with a compressed three-day remediation window, indicating active exploitation in the wild.

Updated Jul 11, 2026

ICSOTPLCarbitrary-file-writeremote-code-executionpath-traversalcritical-infrastructureend-of-life-software

OpenPLC v3's legacy web UI program-upload workflow allows an authenticated user to write arbitrary files anywhere on the filesystem due to unsanitized handling of the prog_file parameter. This flaw can be escalated to full native code execution as the OpenPLC runtime user by planting a malicious C++ source file that gets auto-compiled during normal program build operations, posing a severe risk to industrial control environments in Critical Manufacturing, Energy, Transportation, and Water/Wastewater sectors.

Updated Jul 10, 2026 · CVSS 9.9

rceunauthenticatedwebuiterminal-apiagent-relevantpty-hijackcritical-infrastructure-exposure

Hermes WebUI versions before 0.51.788 expose an embedded terminal API that lacks authentication, allowing remote attackers to open a PTY session and execute arbitrary shell commands with only four HTTP requests. Given the CVSS score of 9.8 and the trivial exploitation path, this vulnerability poses a severe risk to any internet-facing or internally exposed Hermes deployment.

Updated Jul 10, 2026 · CVSS 9.8

authentication-bypassssrfapi-key-theftoauth-abuseagent-relevantllm-provider-hijackcloud-metadata-exposurewebui-vulnerability

A critical authentication bypass in Hermes WebUI (versions before 0.51.307) allows unauthenticated attackers to spoof local-origin IP restrictions using a forged X-Forwarded-For header, gaining access to onboarding endpoints intended only for local administrators. This enables server-side request forgery against internal infrastructure, hijacking of LLM provider configurations and API keys, and abuse of OAuth device-code flows to mint persistent access tokens. Given the CVSS score of 9.1, this vulnerability poses severe risk to any deployment exposing Hermes WebUI to untrusted networks.

Updated Jul 10, 2026 · CVSS 9.1

opensshuse-after-freeclient-sidesshmemory-corruptionagent-relevant

CVE-2026-60002 is a use-after-free vulnerability in OpenSSH clients prior to version 10.4, triggered when a malicious or compromised server changes its host key during a key re-exchange. Exploitation could lead to client-side memory corruption, potentially enabling denial of service or code execution on systems initiating SSH connections.

Updated Jul 10, 2026 · CVSS 7.7

microsoft-defenderzero-daypatch-tuesdaywindowsendpoint-security

Microsoft disclosed and patched a zero-day vulnerability in Microsoft Defender, dubbed 'RoguePlanet', following the June 2026 Patch Tuesday cycle. The vulnerability was actively exploited or publicly known prior to patch release, prompting an out-of-band advisory. Organizations relying on Defender for endpoint protection should prioritize patching to prevent detection evasion or compromise of protected hosts.

Updated Jul 9, 2026

wordpressrceplugin-vulnerabilityunauthenticatedwoocommercecve-2026-14345web-application-security

The WPFunnels WordPress plugin (versions up to 3.12.7) contains a critical unauthenticated RCE vulnerability caused by unsanitized handling of the 'postData' parameter, which allows attackers to inject PHP code into a log file that is later executed via include_once. With a CVSS score of 9.8, this flaw enables full server compromise on any WordPress site running the vulnerable plugin with logging enabled.

Updated Jul 8, 2026 · CVSS 9.8

authentication-bypassprivileged-accessremote-access-softwarepre-auth-rceagent-relevant

A critical pre-authentication vulnerability in BeyondTrust Remote Support allows unauthenticated attackers to bypass access controls and gain unauthorized access, including to privileged accounts, when a specific authentication configuration is enabled. Given the 9.8 CVSS score and lack of authentication requirement, this flaw is highly likely to be weaponized quickly by opportunistic and targeted threat actors. Organizations using this remote support appliance should treat this as an urgent patching priority.

Updated Jul 8, 2026 · CVSS 9.8

path-traversaladobe-coldfusionrcecisa-kevknown-exploitedweb-server

CVE-2026-48282 is a path traversal vulnerability in Adobe ColdFusion that can lead to arbitrary code execution in the context of the current user. It has been added to CISA's Known Exploited Vulnerabilities catalog with an aggressive three-day remediation window, indicating active exploitation in the wild.

Updated Jul 8, 2026

CISA-KEVunauthenticated-rcearbitrary-file-uploadjoomla-extensionweb-applicationcms

Joomlack Page Builder, a Joomla CMS extension, contains an improper access control flaw that allows unauthenticated attackers to upload arbitrary files and achieve remote code execution. The vulnerability has been added to CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild, with a remediation due date of July 10, 2026.

Updated Jul 8, 2026

CISA-KEVweb-shellunauthenticated-RCECMSJoomlafile-uploadactive-exploitation

CVE-2026-48908 is an unauthenticated arbitrary file upload vulnerability in JoomShaper SP Page Builder, a popular page-building extension for Joomla CMS. Attackers can upload and execute malicious PHP files without authentication, leading to full remote code execution on affected servers. The vulnerability is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation in the wild.

Updated Jul 8, 2026 · CVSS 9.8

giteadockerauthentication-bypassheader-spoofingdevopsci-cdagent-relevantsource-code-managementself-hosted-git

Threat actors are actively probing internet-facing Gitea Docker deployments to exploit CVE-2026-20896, a critical authentication bypass flaw disclosed just 13 days prior. The vulnerability allows unauthenticated attackers to spoof the X-WEBAUTH-USER header and gain elevated privileges, potentially leading to full repository compromise.

Updated Jul 7, 2026 · CVSS 9.8

kvmhypervisor-escapelinux-kerneluse-after-freevirtualizationcloud-infrastructureagent-relevant

A 16-year-old use-after-free vulnerability in the Linux KVM hypervisor's shared shadow MMU code allows a malicious guest VM to corrupt host kernel memory on both Intel and AMD x86 systems. Tracked as CVE-2026-53359 and dubbed 'Januscape,' the flaw currently has a public proof-of-concept that crashes the host, while the researcher claims a working, unreleased exploit exists that could achieve full guest-to-host escape.

Updated Jul 7, 2026 · CVSS 8.8

linuxkernelprivilege-escalationandroidepollagent-relevant

A newly disclosed Linux kernel vulnerability dubbed 'Bad Epoll' (CVE-2026-46242) allows an unprivileged local user to escalate privileges to root, affecting Linux desktops, servers, and Android devices. A patch has already been released, but unpatched systems remain fully exploitable by any local user or process with code execution.

Updated Jul 6, 2026 · CVSS 7.8

linuxprint-spoolerprivilege-escalationrceincomplete-patchhplipcve-2026-14544agent-relevant

CVE-2026-14544 is an incomplete fix for the previously patched CVE-2026-8631, leaving an integer overflow in HPLIP's hpcups print-processing path exploitable via specially crafted print jobs. A remote attacker able to submit print data can trigger memory corruption leading to privilege escalation or arbitrary code execution on the host. With a CVSS score of 9.8, this represents a critical, low-complexity threat to any Linux system with HPLIP installed.

Updated Jul 6, 2026 · CVSS 9.8