Zero-Day & Actively Exploited Vulnerabilities

Other conventional threat types

Showing 81–100 of 266 threats, newest first

CISAKEVSSRFMLflowMLOpsagent-relevantvulnerability-managementBOD-26-04

CISA has added CVE-2026-64849, a Server-Side Request Forgery (SSRF) vulnerability in MLflow, to its Known Exploited Vulnerabilities Catalog based on confirmed active exploitation. Federal agencies are required under BOD 26-04 to remediate this vulnerability on a prioritized basis, and CISA urges all organizations to do the same given active in-the-wild attacks.

Updated Aug 20, 2026

oraclefusion-middlewareunauthenticated-rceweb-servicescve-2026-60737agent-relevant

A critical, easily exploitable vulnerability exists in Oracle Web Services Manager (Web Services Security component) affecting versions 12.2.1.4.0 and 14.1.2.0.0. An unauthenticated attacker with network access via HTTP can compromise the product, gaining unauthorized creation, deletion, modification, and full read access to all data accessible to Oracle Web Services Manager.

Updated Aug 20, 2026 · CVSS 9.1

oracleidentity-managementunauthenticated-rcefusion-middlewareiamcritical-infrastructureagent-relevant

A critical unauthenticated remote vulnerability affects Oracle Identity Manager's Legacy UI component within Oracle Fusion Middleware, allowing full compromise via simple HTTP requests. With a CVSS score of 9.8, this flaw requires no authentication or user interaction, making it highly attractive for mass exploitation once technical details or proof-of-concept code emerge. Organizations running affected versions face risk of complete identity infrastructure takeover, including provisioning, credential, and access control data.

Updated Aug 20, 2026 · CVSS 9.8

oracleidentity-managementprivilege-escalationfusion-middlewareiamagent-relevant

A critical vulnerability (CVE-2026-60720, CVSS 9.9) affects the OIM Legacy UI component of Oracle Identity Manager within Oracle Fusion Middleware, allowing a low-privileged attacker with network HTTP access to fully compromise the system. Due to a scope change, successful exploitation can impact other connected products beyond Oracle Identity Manager itself, making this a high-priority patching target for any organization running affected versions.

Updated Aug 20, 2026 · CVSS 9.9

oracleweblogicrceunauthenticatedt3iiopmiddlewareagent-relevant

A critical, easily exploitable vulnerability in Oracle WebLogic Server allows unauthenticated attackers with network access via the T3 or IIOP protocols to fully compromise the server. With a CVSS score of 9.8 and no required user interaction or privileges, this flaw is highly likely to be weaponized rapidly, as historical WebLogic T3/IIOP vulnerabilities have been favored targets for mass exploitation and ransomware precursor activity.

Updated Aug 20, 2026 · CVSS 9.8

MLflowSSRFcloud-credential-theftMLOpsagent-relevantFUXASCADAactive-exploitation

Threat actors are actively scanning for and exploiting a critical Server-Side Request Forgery (SSRF) vulnerability in MLflow, an open-source AI/ML lifecycle platform, to steal cloud credentials and secrets from exposed metadata services. A separate but related campaign is targeting FUXA, an open-source SCADA/HMI platform used in industrial automation. Both flaws are being weaponized in the wild according to watchTowr and VulnCheck.

Updated Aug 19, 2026

microsoft-copilotLLM-vulnerabilityone-click-exploitdata-exfiltrationprompt-injectionagent-relevantai-security

Varonis Threat Labs disclosed three vulnerabilities, collectively named CoSnitch, in Microsoft Copilot Personal that could allow an attacker to exfiltrate data from a victim's connected apps and Copilot session with a single click on a crafted link. The flaws exploit an undocumented URL parameter surfaced by the assistant itself, enabling silent data leakage without further user interaction.

Updated Aug 19, 2026

known-exploited-vulnerabilitiesCISAKEVvulnerability-managementfederalpatch-nowagent-relevant

CISA added four vulnerabilities to its Known Exploited Vulnerabilities catalog based on confirmed active exploitation: a Microsoft IKE double-free flaw, a SharePoint authentication bypass, a VMware vCenter path traversal bug, and a macOS improper authentication issue. Under BOD 26-04, FCEB agencies must remediate these on an expedited timeline, and CISA urges all organizations to prioritize patching given evidence of in-the-wild exploitation.

Updated Aug 19, 2026

iotnetwork-appliancebuffer-overflowrcepublic-exploitnginxembedded-device

A critical stack-based buffer overflow vulnerability has been discovered in the nginx binary bundled with TRENDnet TEW-WLC100 wireless LAN controllers, triggered by manipulation of the HTTP Server header. The flaw allows unauthenticated remote attackers to execute arbitrary code on the device, and a public exploit is already available, making active exploitation highly likely.

Updated Aug 19, 2026 · CVSS 10

kubernetesopenshiftacmprivilege-escalationcommand-injectionsql-injectionrcepostgresagent-relevant

A critical injection vulnerability in Red Hat Advanced Cluster Management's acm-search-v2-rhel9 component allows authenticated users, including hub administrators or Search Custom Resource editors, to execute arbitrary shell commands and SQL statements. The flaw stems from improper validation of the WORK_MEM string in the Search CR before it is embedded in a bash script and SQL query, enabling code execution within the privileged postgres pod.

Updated Aug 19, 2026 · CVSS 9.1

macOSauthentication-bypassscreen-sharingremote-accessCISA-KEVagent-relevant

CVE-2026-65400 is an improper authentication vulnerability in Apple macOS that allows a network-based attacker to authenticate to Screen Sharing without valid credentials. The flaw has been added to CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild. Organizations running macOS with Screen Sharing enabled face an urgent risk of unauthorized remote access.

Updated Aug 19, 2026

CISA-KEVRCEwindowsIKEIPsecVPNnetwork-servicedouble-freeagent-relevant

CVE-2026-33824 is a double free vulnerability in Microsoft's Internet Key Exchange (IKE) Service Extensions that can be exploited remotely to achieve code execution. It has been added to CISA's Known Exploited Vulnerabilities catalog with a short remediation window, indicating active or imminent exploitation in the wild.

Updated Aug 19, 2026

wordpressrceunauthenticatedfile-uploadplugin-vulnerabilityforminatorcms

A critical unauthenticated remote code execution vulnerability (CVE-2026-15748) has been disclosed in Forminator Forms, a WordPress plugin installed on over 600,000 sites. The flaw allows attackers to upload malicious PHP files without authentication, potentially leading to full site compromise. Given the plugin's massive install base, this represents a high-priority patching target for WordPress site operators.

Updated Aug 18, 2026 · CVSS 9.8

gitlabgraphqlvulnerabilityunauthenticatedrcesupply-chainagent-relevantci-cdsource-code-management

GitLab disclosed a critical flaw (CVE-2026-19478, CVSS 9.4) in its GraphQL API affecting both Community Edition and Enterprise Edition, allowing unauthenticated attackers to remotely modify or delete public projects and user data. Organizations running self-managed GitLab instances are urged to patch immediately to prevent destructive attacks against source code repositories.

Updated Aug 18, 2026 · CVSS 9.4

CISAKEVcode-injectionrayagent-relevantML-infrastructurefederal-mandate

CISA added CVE-2025-62593, a code injection vulnerability in Ray-Project Ray, to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation. Federal agencies are required under BOD 26-04 to remediate this vulnerability on a prioritized basis due to its potential to grant full control of affected assets.

Updated Aug 18, 2026

routerauthentication-bypassunpatchedpublic-exploitIoTnetwork-infrastructureno-vendor-response

A critical authentication bypass vulnerability exists in the httpcon_check_session_url function of EFM ipTIME A3004T routers (firmware 14.19.0), allowing remote attackers to circumvent session validation without credentials. A working exploit is publicly available and the vendor has not responded to disclosure, leaving affected devices permanently exposed.

Updated Aug 18, 2026 · CVSS 10

routerfirmwarebuffer-overflowrceiotunpatchedpublic-exploitedimax

A critical unauthenticated remote code execution vulnerability exists in Edimax EW-7478APC routers running firmware 1.04, caused by a stack-based buffer overflow in the formWanTcpipSetup CGI handler. Public exploit code is available and the vendor has not responded to disclosure, meaning no patch is expected. Organizations using this device on network edges face significant risk of full device compromise and pivoting into internal networks.

Updated Aug 18, 2026 · CVSS 9.9

wordpressplugin-vulnerabilityunauthenticated-rcefile-uploadcmsweb-application-security

The ProSolution WP Client WordPress plugin (versions up to 2.0.10) contains a critical unauthenticated arbitrary file upload vulnerability that allows remote attackers to achieve remote code execution. A publicly exposed nonce combined with insufficient filename validation lets attackers bypass access controls and upload executable files directly to the server.

Updated Aug 18, 2026 · CVSS 9.8

agent-relevantraycode-injectionrceml-infrastructuredistributed-computingbrowser-exploitCISA-KEV

CVE-2025-62593 is a code injection vulnerability in Ray-Project Ray, a widely used distributed computing framework for scaling AI/ML and Python workloads, that can lead to remote code execution. The flaw is exploitable via Firefox and Safari when developers interact with Ray's tooling, and it has been added to CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild.

Updated Aug 18, 2026

siyuanpdf-annotationrceelectronnode-jsstored-xssagent-relevantknowledge-managementrag-pipeline

SiYuan, an open-source Electron-based note-taking and knowledge management application, fails to sanitize annotation fields written via the setFileAnnotation endpoint prior to v3.7.4. This allows an attacker to embed malicious markup that executes as script with full Node.js privileges when a victim opens an annotated PDF, enabling complete host compromise.

Updated Aug 17, 2026 · CVSS 9