Zero-Day & Actively Exploited Vulnerabilities

Other conventional threat types

Showing 41–60 of 258 threats, newest first

totolinkroutercgibuffer-overflowrceiotunauthenticatedpublic-exploit

A critical, publicly disclosed stack-based buffer overflow exists in TOTOLINK N600R routers (firmware 4.3.0cu.7647_B20210106) via the Hostname parameter in the setSystemConfig function of cstecgi.cgi. The flaw is remotely exploitable without authentication and carries a maximum CVSS score of 10.0, allowing attackers to potentially achieve remote code execution on affected devices.

Updated Aug 27, 2026 · CVSS 10

authentication-bypassidentity-spoofingdata-exposurecloud-storagealluxioagent-relevantrag-pipelinedata-lake

A critical authentication bypass exists in Alluxio's S3 REST proxy, where default configurations fail to validate AWS Signature Version 4 signatures. This allows unauthenticated attackers to extract usernames from unsigned Authorization headers and impersonate any user or service account, enabling unauthorized read, write, and delete access to arbitrary stored data.

Updated Aug 27, 2026 · CVSS 9.8

adobecampaign-classicos-command-injectionrceunauthenticatedcritical-vulnerability

A critical OS command injection vulnerability in Adobe Campaign Classic (CVE-2026-76197) allows attackers to achieve arbitrary code execution without requiring user interaction, and carries a maximum CVSS score of 10.0. Organizations running ACC for marketing automation should treat this as an urgent patching priority given the scope change and lack of required authentication or interaction.

Updated Aug 27, 2026 · CVSS 10

adobeos-command-injectionrcecampaign-classicunauthenticatedcritical-vulnerability

A critical OS Command Injection vulnerability in Adobe Campaign Classic (ACC) allows an attacker to achieve arbitrary code execution in the context of the current user without requiring any user interaction. With a maximum CVSS score of 10.0 and a changed scope, successful exploitation could allow attackers to pivot beyond the vulnerable component into connected infrastructure.

Updated Aug 27, 2026 · CVSS 10

citrixnetscalerdenial-of-servicecisa-kevedge-devicenetwork-applianceactive-exploitation

CVE-2026-8452 is an improper memory buffer restriction vulnerability in Citrix NetScaler ADC and NetScaler Gateway that can result in denial of service. CISA has added this CVE to its Known Exploited Vulnerabilities catalog with a short remediation window, indicating active exploitation in the wild. Organizations using NetScaler appliances as gateways or load balancers should prioritize patching due to the aggressive due date.

Updated Aug 27, 2026

linux-kernelprivilege-escalationlocal-exploitcisa-kevwatch_queueagent-relevant

CVE-2022-0995 is an out-of-bounds write vulnerability in the Linux Kernel's watch_queue event notification subsystem that allows a local attacker to escalate privileges or crash the system. It is listed in CISA's Known Exploited Vulnerabilities catalog, indicating confirmed active exploitation in the wild. Organizations running affected Linux kernel versions must remediate promptly per CISA's mandated due date.

Updated Aug 27, 2026 · CVSS 7.8

CISAKEVGiteacode-injectionactive-exploitationagent-relevantself-hosted-gitRCE

CISA added CVE-2026-60004, a code injection vulnerability in Gitea, to its Known Exploited Vulnerabilities catalog based on confirmed active exploitation. Federal agencies are required under BOD 26-04 to remediate this vulnerability on a prioritized basis, and CISA urges all organizations to do the same given the risk of total asset compromise.

Updated Aug 26, 2026

unrestricted-file-uploadweb-shellrcesoftware-repositorysupply-chain-riskagent-relevant

CVE-2026-16286 is a critical unrestricted file upload vulnerability in TRtek's Software Repository Management product, allowing unauthenticated attackers to upload malicious web shells to the underlying web server. Successful exploitation grants remote code execution, giving attackers full control over the affected host. Given the product's role as a software repository, this flaw poses supply-chain risk to any downstream systems, including AI agent pipelines, that pull artifacts from a compromised instance.

Updated Aug 26, 2026 · CVSS 9.8

giteacode-injectiongit-hooksrcerepository-write-accesscisa-kevagent-relevantci-cdsupply-chain-risk

Gitea, a widely deployed self-hosted Git service, contains a code injection vulnerability that lets an attacker with repository write access plant a malicious Git hook via the diffpatch API endpoint, resulting in arbitrary shell command execution as the Gitea service account. CISA has added this to its Known Exploited Vulnerabilities catalog with a short remediation window, indicating active exploitation in the wild.

Updated Aug 26, 2026

NAT bypassrouter vulnerabilityunpatchedresidential gatewayport forwardingbroadband ISPIoT exposurenetwork security

An unpatched vulnerability in Calix GS7 XGS (GS5239XG) residential routers allows remote, unauthenticated attackers to create arbitrary port-forwarding rules, bypassing NAT protections and exposing internal network devices directly to the internet. The flaw affects devices deployed by multiple U.S. broadband providers, putting a large base of residential and small-office networks at risk of direct exposure of internal systems such as NAS devices, cameras, and smart home hubs.

Updated Aug 25, 2026

oracleweblogichttp-serverknown-exploited-vulnerabilityCISAaccess-controlagent-relevant

CISA has added CVE-2026-21962, an improper access control vulnerability affecting Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in, to its Known Exploited Vulnerabilities (KEV) catalog based on confirmed active exploitation. Federal civilian agencies are required under BOD 26-04 to remediate this vulnerability on a priority basis, and CISA urges all organizations to do the same given the active exploitation in the wild.

Updated Aug 25, 2026

network-appliancecommand-injectionpre-authrceedge-devicecritical-infrastructure

A critical pre-authentication command injection vulnerability affects multiple DrayTek VigorSwitch models, allowing remote attackers to execute arbitrary commands with root privileges without any credentials. Given the CVSS score of 9.8 and the device's role as network infrastructure, this flaw poses an immediate risk of full network compromise. Organizations using DrayTek switches at network edges should treat this as an urgent patching priority.

Updated Aug 25, 2026 · CVSS 9.8

router-exploitrceunauthenticatedfirmware-vulnerabilityiotnetwork-infrastructurebuffer-overflow

A critical unauthenticated remote code execution vulnerability affects Netis NC63 router firmware through V3.0.0.3327, allowing attackers to gain root access via a crafted HTTP request to the device's web management interface. The vulnerability requires no authentication and no user interaction, making it highly exploitable for mass scanning and botnet recruitment. With a CVSS score of 9.8, this represents a severe risk to any network-edge device running the vulnerable firmware.

Updated Aug 25, 2026 · CVSS 9.8

iotrouterauthentication-bypassunpatchedpublic-exploitnetwork-infrastructure

A critical authentication bypass vulnerability exists in EFM ipTIME T24000M routers (up to firmware 14.20.0) affecting the httpcon_check_session_url function within the Session Validation Handler. The flaw allows remote attackers to bypass authentication without credentials, and a public exploit is already available. The vendor has not responded to disclosure attempts, leaving affected devices unpatched and exposed.

Updated Aug 25, 2026 · CVSS 9.8

oraclehttp-serverweblogicaccess-controlkevcisaexploited-in-the-wildagent-relevant

CVE-2026-21962 is an actively exploited improper access control vulnerability in Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in that allows unauthorized creation, deletion, or modification of critical data, as well as unauthorized full access to server-accessible data. CISA has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog with a short remediation window, indicating active in-the-wild exploitation and high urgency for patching.

Updated Aug 25, 2026

entra-ididentityazure-admicrosoftcvss-10privilege-escalationagent-relevant

Microsoft patched a maximum-severity (CVSS 10.0) vulnerability in Entra ID, its cloud identity and access management platform, that could allow remote code execution or full identity compromise. Microsoft initially flagged the flaw as exploited in the wild but later corrected this to confirm no active exploitation occurred prior to disclosure. The vulnerability's severity stems from Entra ID's central role in authentication for Microsoft 365, Azure, and third-party enterprise applications.

Updated Aug 24, 2026 · CVSS 10

gitlabcode-injectionactive-exploitationunauthenticatedci-cdsource-code-managementagent-relevant

A critical unauthenticated code injection vulnerability in GitLab (CVE-2026-19478, CVSS 9.4) is being actively exploited in the wild within days of public disclosure. The flaw allows attackers to modify or delete publicly accessible GitLab projects and rewrite repository data without authentication, posing severe risk to source code integrity and CI/CD pipeline trust.

Updated Aug 24, 2026 · CVSS 9.4

CISAKEVTrueConfself-hosted-communicationsfederal-mandateactive-exploitationRCE

CISA has added two actively exploited vulnerabilities in TrueConf Server, a self-hosted video conferencing and communications platform, to its Known Exploited Vulnerabilities catalog, mandating federal agencies to patch immediately. The flaws are being leveraged in the wild, indicating attackers have working exploits and are actively targeting exposed instances.

Updated Aug 24, 2026

buffer-overflowrouteriotweb-managementremote-code-executionpublic-exploit

A critical stack-based buffer overflow vulnerability affects the Web Management interface of Comfast CF-N1-S wireless routers version 2.6.0.1, exploitable remotely via the NTP timezone configuration endpoint. The exploit code is publicly available, significantly increasing the likelihood of active exploitation, and successful attacks could allow full device compromise.

Updated Aug 24, 2026 · CVSS 9.9

iotrouterbuffer-overflowremote-code-executiontrendnetcgiunauthenticatedpublic-exploit

A critical stack-based buffer overflow vulnerability exists in TRENDnet TEW-821DAP routers (firmware 2.2.01b05) within the NTP Timezone Configuration Handler's uci_safe_get function. The flaw is remotely exploitable without authentication via manipulated CGI parameters, and a public exploit is already available, making immediate exploitation likely.

Updated Aug 23, 2026 · CVSS 10