Zero-Day & Actively Exploited Vulnerabilities

Other conventional threat types

Showing 261–270 of 270 threats, newest first

patch-tuesdaymicrosoftwindowsvulnerability-managementrcepublic-exploitagent-relevant

Microsoft released fixes for nearly 200 vulnerabilities in June 2026, its largest Patch Tuesday to date, with roughly 34 rated critical. Public exploit code exists for at least three of the flaws, creating urgent risk of active exploitation against unpatched Windows systems.

Updated Jul 5, 2026

embedded-systemsfirmwareiotsupply-chainunpatchedmemory-corruptionfat-exfat

Security firm runZero disclosed seven unpatched vulnerabilities in FatFs, a widely embedded filesystem library used to read and write FAT/exFAT formats on USB drives and SD cards. Because FatFs is bundled into firmware across security cameras, drones, industrial controllers, and hardware crypto wallets, these flaws could enable attackers with physical or logical access to removable media to trigger memory corruption or logic errors in a huge range of downstream devices.

Updated Jul 5, 2026

ssrfazurecloudprivilege-escalationopenaiagent-relevantapi-abuse

CVE-2026-45499 is a critical server-side request forgery (SSRF) vulnerability in Azure OpenAI that allows an authorized attacker to escalate privileges remotely over a network. With a CVSS score of 9.9, exploitation could grant attackers access beyond their intended scope within Azure's OpenAI service infrastructure. This poses significant risk to organizations relying on Azure OpenAI for production workloads, including internal tooling and AI-driven applications.

Updated Jul 5, 2026 · CVSS 9.9

open-redirectprivilege-escalationmicrosoft-365copilotagent-relevantcloud-security

CVE-2026-41106 is a critical open redirect vulnerability in Microsoft 365 Copilot that allows an unauthenticated attacker to elevate privileges over a network. Given the 9.3 CVSS score and network attack vector, this flaw could be leveraged to hijack authentication flows or session tokens tied to Copilot's integrated services.

Updated Jul 5, 2026 · CVSS 9.3

CASSSOcryptographic-flawAES-GCMIV-reuseauthentication-bypassunauthenticatedagent-relevant

Apereo CAS versions 7.3.0 before 8.0.0-RC6 use a fixed all-zero initialization vector with AES-GCM to encrypt webflow conversation state, allowing unauthenticated remote attackers to collect tokens from the login page and perform known-plaintext cryptanalysis to recover the encryption keystream. This can lead to full decryption of session state and potentially enable authentication bypass or session manipulation within enterprise SSO infrastructure.

Updated Jul 5, 2026 · CVSS 9.1

rcecommand-injectionauthentication-bypassdockercontainer-securityagent-relevant

Dockwatch versions through 0.6.567 contain a critical unauthenticated command injection vulnerability enabling full remote host compromise. Attackers can bypass authentication via a missing exit() call after an auth redirect in loader.php, then inject arbitrary shell commands through the composePath parameter in ajax/compose.php. Given Dockwatch's typical deployment with a mounted Docker socket, successful exploitation grants attackers control over the entire container host and all managed containers.

Updated Jul 5, 2026 · CVSS 9.8

CISAKEVSharePointdeserializationactive-exploitationBOD-26-04federal-agencies

CISA added CVE-2026-45659, a deserialization of untrusted data vulnerability in Microsoft SharePoint Server, to its Known Exploited Vulnerabilities catalog due to confirmed active exploitation. Federal civilian agencies are required under BOD 26-04 to remediate this vulnerability on an expedited basis given its potential for full system compromise on publicly exposed assets. All organizations, not just federal agencies, are strongly encouraged to prioritize patching.

Updated Jul 4, 2026

containerdCRICDIkubernetescontainer-escapeprivilege-escalationcheckpoint-restoredevice-injection

A critical vulnerability in containerd's CRI implementation allows users with pod creation permissions to bypass Kubernetes resource allocation and device plugin enforcement by injecting arbitrary Container Device Interface (CDI) edits through malicious checkpoint image metadata. This can result in unauthorized access to host device nodes and mounts, potentially leading to container breakout or privilege escalation on affected nodes. Exploitation requires CDI to be enabled on the node with matching host CDI specifications for the targeted device.

Updated Jul 4, 2026 · CVSS 9.6

authentication-bypassOIDCremote-code-execution-riskCISA-KEVprivilege-escalationMFA-bypass

A critical authentication bypass vulnerability exists in SimpleHelp's OIDC authentication flow, where identity tokens are accepted without cryptographic signature verification. This allows a remote, unauthenticated attacker to forge tokens and gain fully authenticated technician-level access, potentially bypassing multi-factor authentication safeguards. The vulnerability has been added to CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation.

Updated Jul 4, 2026

Zero-DayVPNEdge Device

Two chained zero-days in Ivanti VPN appliances enabling unauthenticated remote code execution. Mass exploitation targeting government and defense across 12 countries.

Updated Jul 3, 2026 · CVSS 9.1