Zero-Day & Actively Exploited Vulnerabilities

Other conventional threat types

Showing 61–80 of 266 threats, newest first

router-exploitrceunauthenticatedfirmware-vulnerabilityiotnetwork-infrastructurebuffer-overflow

A critical unauthenticated remote code execution vulnerability affects Netis NC63 router firmware through V3.0.0.3327, allowing attackers to gain root access via a crafted HTTP request to the device's web management interface. The vulnerability requires no authentication and no user interaction, making it highly exploitable for mass scanning and botnet recruitment. With a CVSS score of 9.8, this represents a severe risk to any network-edge device running the vulnerable firmware.

Updated Aug 25, 2026 · CVSS 9.8

iotrouterauthentication-bypassunpatchedpublic-exploitnetwork-infrastructure

A critical authentication bypass vulnerability exists in EFM ipTIME T24000M routers (up to firmware 14.20.0) affecting the httpcon_check_session_url function within the Session Validation Handler. The flaw allows remote attackers to bypass authentication without credentials, and a public exploit is already available. The vendor has not responded to disclosure attempts, leaving affected devices unpatched and exposed.

Updated Aug 25, 2026 · CVSS 9.8

oraclehttp-serverweblogicaccess-controlkevcisaexploited-in-the-wildagent-relevant

CVE-2026-21962 is an actively exploited improper access control vulnerability in Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in that allows unauthorized creation, deletion, or modification of critical data, as well as unauthorized full access to server-accessible data. CISA has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog with a short remediation window, indicating active in-the-wild exploitation and high urgency for patching.

Updated Aug 25, 2026

entra-ididentityazure-admicrosoftcvss-10privilege-escalationagent-relevant

Microsoft patched a maximum-severity (CVSS 10.0) vulnerability in Entra ID, its cloud identity and access management platform, that could allow remote code execution or full identity compromise. Microsoft initially flagged the flaw as exploited in the wild but later corrected this to confirm no active exploitation occurred prior to disclosure. The vulnerability's severity stems from Entra ID's central role in authentication for Microsoft 365, Azure, and third-party enterprise applications.

Updated Aug 24, 2026 · CVSS 10

gitlabcode-injectionactive-exploitationunauthenticatedci-cdsource-code-managementagent-relevant

A critical unauthenticated code injection vulnerability in GitLab (CVE-2026-19478, CVSS 9.4) is being actively exploited in the wild within days of public disclosure. The flaw allows attackers to modify or delete publicly accessible GitLab projects and rewrite repository data without authentication, posing severe risk to source code integrity and CI/CD pipeline trust.

Updated Aug 24, 2026 · CVSS 9.4

CISAKEVTrueConfself-hosted-communicationsfederal-mandateactive-exploitationRCE

CISA has added two actively exploited vulnerabilities in TrueConf Server, a self-hosted video conferencing and communications platform, to its Known Exploited Vulnerabilities catalog, mandating federal agencies to patch immediately. The flaws are being leveraged in the wild, indicating attackers have working exploits and are actively targeting exposed instances.

Updated Aug 24, 2026

buffer-overflowrouteriotweb-managementremote-code-executionpublic-exploit

A critical stack-based buffer overflow vulnerability affects the Web Management interface of Comfast CF-N1-S wireless routers version 2.6.0.1, exploitable remotely via the NTP timezone configuration endpoint. The exploit code is publicly available, significantly increasing the likelihood of active exploitation, and successful attacks could allow full device compromise.

Updated Aug 24, 2026 · CVSS 9.9

iotrouterbuffer-overflowremote-code-executiontrendnetcgiunauthenticatedpublic-exploit

A critical stack-based buffer overflow vulnerability exists in TRENDnet TEW-821DAP routers (firmware 2.2.01b05) within the NTP Timezone Configuration Handler's uci_safe_get function. The flaw is remotely exploitable without authentication via manipulated CGI parameters, and a public exploit is already available, making immediate exploitation likely.

Updated Aug 23, 2026 · CVSS 10

CISAKEVZimbraOS-command-injectionactive-exploitationemail-serverfederal-agenciesagent-relevant

CISA has added CVE-2026-73570, an OS command injection vulnerability in Zimbra Collaboration Suite (ZCS), to its Known Exploited Vulnerabilities Catalog based on confirmed active exploitation. Federal Civilian Executive Branch agencies are required under BOD 26-04 to remediate this vulnerability on an expedited timeline, and CISA urges all organizations to prioritize patching.

Updated Aug 22, 2026

iotrouterbuffer-overflowrcepublic-exploitnetwork-devicefirmware

A critical stack-based buffer overflow exists in the mycli binary of TRENDnet TEW-755AP wireless access points, triggered by unsanitized input in the SSID parameter. The vulnerability is remotely exploitable and a public exploit is available, making it an immediate risk for exposed devices. CVSS 9.9 reflects the potential for full device compromise without authentication.

Updated Aug 22, 2026 · CVSS 9.9

zimbracommand-injectionunauthenticated-rcesmtpemail-servercisa-kevagent-relevant

CVE-2026-73570 is an unauthenticated OS command injection vulnerability in Synacor Zimbra Collaboration Suite that can be triggered via specially crafted SMTP requests, leading to arbitrary command execution as the Zimbra user. CISA has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog with an unusually short remediation window, indicating active exploitation in the wild. Organizations running ZCS mail servers should treat this as an imminent compromise risk.

Updated Aug 22, 2026

wordpresselementorrcefile-uploadweb-plugincms-securityagent-relevant

A critical vulnerability in the Elementor Pro WordPress plugin allows unauthenticated or low-privileged attackers to upload executable files, leading to full remote code execution on the underlying server. Given Elementor Pro's massive install base, this flaw poses a significant risk of mass exploitation against WordPress-hosted sites and infrastructure.

Updated Aug 21, 2026 · CVSS 9.8

CISAKEVTrueConfauthentication-bypasscode-injectionactive-exploitationfederal-mandatevideo-conferencing

CISA has added two actively exploited vulnerabilities affecting TrueConf Server to its Known Exploited Vulnerabilities catalog: a missing authentication for critical function flaw (CVE-2026-72529) and a code injection vulnerability (CVE-2026-72530). These vulnerabilities pose significant risk as they can be chained to bypass authentication and execute arbitrary code, with BOD 26-04 requiring FCEB agencies to remediate rapidly.

Updated Aug 21, 2026

oracleweblogicrmiunauthenticated-rcefusion-middlewareagent-relevant

CVE-2026-60977 is a critical, easily exploitable vulnerability in Oracle WebLogic Server that allows an unauthenticated attacker with network access via RMI to fully compromise the server. With a CVSS score of 9.8, successful exploitation can lead to complete takeover of confidentiality, integrity, and availability. Organizations running affected WebLogic versions should prioritize immediate patching due to the low attack complexity and lack of authentication requirements.

Updated Aug 21, 2026 · CVSS 9.8

browser-securityuse-after-freemozillafirefoxthunderbirdrcememory-corruptionagent-relevant

A critical use-after-free vulnerability in the DOM Core & HTML component of Firefox and Thunderbird could allow attackers to execute arbitrary code via crafted web content. The flaw has been patched in Firefox 154, Firefox ESR 140.14/153.1, and Thunderbird 154, 140.14, and 153.1. With a CVSS score of 9.8, unpatched systems are at severe risk of remote exploitation.

Updated Aug 21, 2026 · CVSS 9.8

browser-vulnerabilityuse-after-freefirefoxthunderbirdmozillarceagent-relevant

A critical use-after-free vulnerability exists in the Graphics: ImageLib component of Firefox and Thunderbird, carrying a CVSS score of 9.8. Successful exploitation could allow remote code execution via crafted image content rendered by the affected browser or mail client, posing significant risk to any endpoint running unpatched versions.

Updated Aug 21, 2026 · CVSS 9.8

browser-vulnerabilityuse-after-freefirefoxthunderbirdmemory-corruptionrce-potentialagent-relevant

A critical use-after-free vulnerability (CVE-2026-74940) exists in the Graphics: Text rendering component of Firefox and Thunderbird, carrying a CVSS score of 9.8. Successful exploitation could allow remote code execution, potentially enabling attackers to compromise systems that browse untrusted content or process malicious documents/emails.

Updated Aug 21, 2026 · CVSS 9.8

browser-vulnerabilityuse-after-freewebassemblyfirefoxthunderbirdrceagent-relevant

A critical use-after-free vulnerability (CVE-2026-74936) exists in the WebAssembly component of Firefox's JavaScript engine, carrying a CVSS score of 9.8. The flaw affects multiple Firefox and Thunderbird release channels and has been patched in the latest versions, indicating high urgency for organizations to update immediately.

Updated Aug 21, 2026 · CVSS 9.8

CISA-KEVcode-injectionRCEsandbox-escapevideo-conferencingnetwork-exposed-service

TrueConf Server is vulnerable to a code injection flaw that allows an unauthenticated remote attacker to escape an isolated execution environment and run arbitrary code on the host via port 4307/TCP. The vulnerability has been added to CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild, with remediation required by September 3, 2026.

Updated Aug 21, 2026

spectreside-channelcloudflare-workersserverlessjwt-theftspeculative-executionagent-relevant

Researchers demonstrated a remote Spectre-class microarchitectural side-channel attack against Cloudflare Workers that allows a malicious Worker to leak secret data, including JSON Web Tokens, from a co-located victim Worker in production at up to 12 bits per second. This represents a 360x throughput improvement over a 2021 proof-of-concept and confirms that multi-tenant serverless/edge compute platforms remain vulnerable to cross-tenant speculative execution leakage despite existing mitigations.

Updated Aug 20, 2026