Zero-Day & Actively Exploited Vulnerabilities

Other conventional threat types

Showing 101–120 of 266 threats, newest first

wordpressplugin-vulnerabilityauthentication-bypasstype-confusionprivilege-escalationcmsweb-application

The User Profile Builder plugin for WordPress (versions up to 3.16.4) contains a critical authentication bypass vulnerability caused by improper error handling during user registration. An unauthenticated attacker can exploit a type confusion flaw to obtain an autologin nonce bound to user ID 1, effectively logging in as the site's Administrator and achieving full site takeover.

Updated Aug 17, 2026 · CVSS 9.8

microsoft-defenderpatch-bypassprivilege-escalationwindowsSYSTEM-accesszero-dayproof-of-conceptagent-relevant

A researcher known as Chaotic Eclipse released a public proof-of-concept called ShieldBreak that bypasses Microsoft's patch for CVE-2026-50656 (RoguePlanet), a Windows Defender vulnerability. The PoC reportedly grants SYSTEM-level access, meaning organizations that applied the original patch may still be exposed to full local privilege escalation.

Updated Aug 16, 2026 · CVSS 7.8

SAPRCEactive-exploitationenterprise-softwarecommerce-platform

A maximum-severity remote code execution vulnerability in SAP Commerce Cloud, patched only three days prior, is already being actively exploited in the wild according to threat intelligence firm Defused. Organizations running unpatched instances face immediate risk of full system compromise, making rapid patching or mitigation critical.

Updated Aug 16, 2026 · CVSS 9.8

wordpressauthentication-bypassplugin-vulnerabilityprivilege-escalationunauthenticated-rce-adjacentagent-relevant

The 6Storage Rentals WordPress plugin (versions up to 2.27.0) contains a critical authentication bypass vulnerability allowing unauthenticated attackers to log in as any existing WordPress user, including administrators, simply by supplying that user's email address. This flaw stems from an insecure AJAX handler exposed to unauthenticated users that lacks nonce, capability, or ownership checks before establishing a full authenticated session.

Updated Aug 16, 2026 · CVSS 9.8

ibmdb2rcepath-traversalibm-icritical-infrastructure

A critical vulnerability in IBM Db2 Mirror for i (versions 7.4, 7.5, 7.6) allows remote attackers to execute arbitrary code by exploiting external control of file name or path. With a CVSS score of 9.8, this flaw poses severe risk to organizations running IBM i systems for high-availability database replication.

Updated Aug 16, 2026 · CVSS 9.8

SAPCommerce CloudRCEunauthenticatedinput-validationauthorization-bypasspatch-now

SAP has patched a maximum-severity (CVSS 10.0) vulnerability in Commerce Cloud's Data Hub Adapter that allows unauthenticated attackers to execute arbitrary code due to insufficient authorization checks and input validation. Given the flaw requires no authentication and results in full code execution, organizations running affected SAP Commerce Cloud deployments should prioritize immediate patching.

Updated Aug 15, 2026 · CVSS 10

vmwarevcenterrcedirectory-traversalvirtualizationpersistent-accessagent-relevant

Threat actors are actively exploiting a critical directory-traversal vulnerability (CVE-2026-59310, CVSS 9.8) in Broadcom VMware vCenter to achieve remote code execution and establish persistent access. The flaw affects any attacker with network access to the vCenter management interface, making unpatched instances high-value targets for post-exploitation activity including lateral movement and infrastructure takeover.

Updated Aug 15, 2026 · CVSS 9.8

macOSauthentication-bypasscryptominingmoneroexploit-code-publicagent-relevant

Hackers are actively exploiting a macOS Screen Sharing authentication bypass vulnerability following the release of public exploit code, according to the Netherlands' NCSC. Attackers use the flaw to gain unauthorized remote access to macOS systems and deploy Monero (XMR) cryptocurrency miners. Organizations running exposed macOS Screen Sharing services are at immediate risk of unauthorized access and resource hijacking.

Updated Aug 15, 2026 · CVSS 8.1

path-traversalibm-db2remote-code-executionibm-iunauthenticateddatabase

A critical path traversal vulnerability in IBM Db2 Mirror for i allows remote attackers to write arbitrary files to unintended filesystem locations. With a CVSS score of 9.3, successful exploitation could lead to arbitrary code execution, data corruption, or full system compromise on affected IBM i platforms.

Updated Aug 15, 2026 · CVSS 9.3

path-traversalrceibmunauthenticatedagent-relevant

A critical vulnerability (CVE-2026-17482) in IBM Documentation Offline versions 1.0.0 through 1.4.1 allows remote attackers to execute arbitrary code due to improper control of file paths. With a CVSS score of 9.8, this flaw is likely exploitable without authentication and poses severe risk to any host running the affected software. Organizations should treat this as an urgent patching priority given the potential for full system compromise.

Updated Aug 15, 2026 · CVSS 9.8

adobecoldfusionrcecommand-injectionprivilege-escalationpatch-tuesdayagent-relevant

Adobe has released patches for multiple critical vulnerabilities affecting ColdFusion, Commerce, and Campaign Classic, including at least one flaw rated a maximum CVSS score of 10.0. Successful exploitation could allow unauthenticated attackers to achieve arbitrary OS command execution and privilege escalation on affected servers.

Updated Aug 14, 2026 · CVSS 10

sharepointauthentication-bypasspoc-exploitmicrosofton-premisesrce-riskagent-relevant

Threat actors are actively exploiting CVE-2026-55040, a critical SharePoint authentication bypass vulnerability, following the public release of proof-of-concept code. The flaw, patched in Microsoft's July 2026 Patch Tuesday, stems from weak authentication controls and carries a CVSS score of 9.1, allowing attackers to bypass security controls on unpatched SharePoint servers.

Updated Aug 14, 2026 · CVSS 9.1

rsyncaccess-control-bypassip-spoofingunauthenticatednetwork-protocolagent-relevant

A critical vulnerability in rsync daemon versions prior to 3.5.0 allows unauthenticated remote attackers to spoof source IP addresses via a crafted PROXY protocol header, bypassing IP-based hosts allow/deny access controls. This enables attackers who can reach the rsync daemon port to gain unauthorized access to file shares that would otherwise be restricted by network-level trust policies.

Updated Aug 14, 2026 · CVSS 9.1

lazarusnorth-koreaaptzero-daywindowsoperation-dream-jobdefense-sectoraerospaceprivilege-escalationbackdoor

The North Korea-linked Lazarus Group exploited a zero-day vulnerability in Microsoft Windows to gain SYSTEM-level privileges and deploy a previously unseen backdoor. The campaign, part of the long-running Operation Dream Job cyber espionage effort, targeted defense and aerospace organizations in France, Germany, Brazil, and India. The vulnerability has since been patched by Microsoft.

Updated Aug 13, 2026

adobe-commercemagentoecommerceaccount-takeoveractive-exploitationcve-2026-71362

Attackers are actively exploiting a critical vulnerability in Adobe Commerce and Magento platforms that allows hijacking of customer accounts. The flaw is being targeted in the wild shortly after disclosure, putting online retailers and their customer data at risk of unauthorized access and fraud.

Updated Aug 13, 2026

patch-tuesdaymicrosoftwindowszero-dayvulnerability-managementagent-relevant

Microsoft's August 2026 Patch Tuesday addresses nearly 398 vulnerabilities across Windows and supported software, including one flaw already under active exploitation and two others that were publicly disclosed prior to patching. Organizations should prioritize patching the actively exploited vulnerability to reduce risk of compromise.

Updated Aug 12, 2026

zoomzero-clickannotation-toolvideo-conferencingclient-hijackrcescreen-sharing

A flaw in Zoom's screen annotation feature could have allowed any meeting participant to hijack the client of another attendee, including the presenter, without any user interaction. The vulnerability required no click, download, or visible prompt, making it a fully zero-click, in-meeting attack vector. This poses significant risk to organizations relying on Zoom for internal and external communications, including those coordinating distributed teams or automated workflows via meeting integrations.

Updated Aug 12, 2026

adobecampaign-classicrceauthorization-bypassunauthenticatedmarketing-platform

A critical Incorrect Authorization vulnerability in Adobe Campaign Classic (ACC) allows attackers to achieve arbitrary code execution in the context of the current user without any user interaction. With a CVSS score of 10.0 and a changed scope, successful exploitation could lead to full compromise of the marketing automation platform and downstream systems it integrates with.

Updated Aug 12, 2026 · CVSS 10

authentication-bypassjwt-forgeryssohard-coded-secretunauthenticated-rce-pathidentity-provideragent-relevant

MaxKey SSO contains a hard-coded JWT signing secret that allows unauthenticated attackers to forge valid admin-level JWT tokens and bypass authentication entirely via the password-skipped login endpoint. This grants full access to SSO application configuration and downstream application secrets, effectively compromising every service federated through the affected MaxKey instance.

Updated Aug 12, 2026 · CVSS 9.8

sql-injectionmetabaseunauthenticated-rcedata-exfiltrationcisa-kevagent-relevant

Metabase, a widely used open-source business intelligence and analytics platform, contains an unauthenticated SQL injection vulnerability that can grant attackers full administrative access to the application. CISA has added this CVE to its Known Exploited Vulnerabilities catalog with a short remediation window, indicating active exploitation in the wild. Successful exploitation exposes connected database credentials and any data accessible through those connections.

Updated Aug 12, 2026