Zero-Day & Actively Exploited Vulnerabilities

Other conventional threat types

Showing 141–160 of 270 threats, newest first

browser-vulnerabilitytype-confusionrcemicrosoft-edgechromiumagent-relevant

CVE-2026-66321 is a type confusion vulnerability in Microsoft Edge (Chromium-based) that allows an unauthorized remote attacker to execute arbitrary code, typically via a malicious or compromised web page. Exploitation requires a victim to interact with attacker-controlled content, but successful attacks can lead to full code execution within the browser context.

Updated Aug 7, 2026 · CVSS 7.4

CISAKEVJetBrainsTeamCitydeserializationCI/CDagent-relevantactive-exploitationfederal-mandate

CISA has added CVE-2026-63077, a deserialization of untrusted data vulnerability in JetBrains TeamCity, to its Known Exploited Vulnerabilities catalog based on confirmed active exploitation. Under BOD 26-04, FCEB agencies must prioritize remediation of this vulnerability on publicly exposed assets, as it may grant attackers total control of affected systems post-exploitation. All organizations, including those outside federal scope, are strongly encouraged to remediate promptly given the severity of CI/CD compromise.

Updated Aug 6, 2026

deserializationrceunauthenticatedci-cdteamcitykevagent-relevantbuild-pipeline

A critical unauthenticated remote code execution vulnerability has been identified in JetBrains TeamCity, exploitable via insecure deserialization in the agent polling protocol. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog with an unusually short remediation window, indicating active or imminent exploitation. Organizations running TeamCity build servers should treat this as an urgent patching priority.

Updated Aug 6, 2026

TP-LinkOmadaZTPnetwork-infrastructureRCEvulnerability-chainIoTfirmware

TP-Link has patched 15 vulnerabilities in the zero-touch provisioning mechanism of its Omada network devices. These flaws can be chained with previously disclosed vulnerabilities to achieve remote code execution, potentially allowing attackers to breach entire networks through compromised network infrastructure.

Updated Aug 5, 2026

cmsrceunauthenticatedphp-injectionweb-applicationconfig-injection

A critical unauthenticated remote code execution vulnerability affects MaxSite CMS, allowing attackers to inject arbitrary PHP code into the application's configuration file via the install endpoint. Exploitation results in persistent RCE as the web-server process user, requiring no authentication and enabling full compromise of the affected host.

Updated Aug 5, 2026 · CVSS 9.8

rcedeserializationunauthenticatedrag-pipelinellm-toolingagent-relevantpython

kotaemon, an open-source RAG (retrieval-augmented generation) UI and document QA toolkit through version 0.12.0, contains a critical unauthenticated insecure deserialization vulnerability in its check_connection endpoint. Attackers can supply crafted YAML/JSON payloads with a manipulated __type__ field to instantiate arbitrary Python classes, ultimately achieving remote code execution via subprocess.check_output injection.

Updated Aug 5, 2026 · CVSS 9.8

iotcommand-injectionunauthenticated-rceip-camerafirmware-vulnerabilitynetwork-device

A critical unauthenticated command injection vulnerability affects Puwell IP Camera firmware versions 2.x through 4.x, allowing remote attackers to achieve root-level code execution via a crafted JSON payload sent to the exposed DebugShell service on TCP port 34567. Given the CVSS score of 9.8 and lack of any authentication barrier, this vulnerability is likely to be rapidly weaponized by botnet operators and IoT malware families for mass exploitation.

Updated Aug 5, 2026 · CVSS 9.8

sql-injectionrceadobecampaign-classiccritical-vulnerabilityunauthenticatedscope-change

A critical SQL Injection vulnerability in Adobe Campaign Classic (CVE-2026-48330) allows an unauthenticated attacker to execute arbitrary SQL commands and achieve remote code execution in the context of the current user, with no user interaction required. With a maximum CVSS score of 10.0 and a scope change, successful exploitation could grant attackers elevated access, full control over the marketing automation platform, and lateral movement into connected infrastructure.

Updated Aug 5, 2026 · CVSS 10

passkeyscredential-theftWindowsChromeGoogle-Password-Managerlocal-malwareauthentication-bypassagent-relevant

Unit 42 researchers disclosed three attack techniques against Chrome's Google Password Manager cloud authenticator that allow user-level malware on a compromised Windows machine to sign into passkey-protected accounts without any biometric, PIN, or user-visible prompt. The strongest variant, Golden Pass-ta-key, targets the underlying master key, enabling silent, persistent account takeover even after remediation. This undermines the core phishing-resistance promise of passkeys when the endpoint itself is compromised.

Updated Aug 4, 2026

CISAKEVauthentication-bypassN-ableN-centralRMMvulnerability-managementfederal-directive

CISA has added CVE-2026-18577, an authentication bypass vulnerability in N-able N-central, to its Known Exploited Vulnerabilities Catalog based on confirmed active exploitation. Federal civilian agencies are required under BOD 26-04 to remediate this vulnerability on a prioritized timeline, and CISA urges all organizations to apply the same urgency.

Updated Aug 4, 2026

command-injectionrouteriotnetwork-devicercepublic-exploitgl-inet

A critical command injection vulnerability affects GL-iNet GL-MT3000 routers up to firmware version 4.4.5, residing in the server.set_peer function of the wg-server.so native plugin exposed via /cgi-bin/glc. The flaw allows unauthenticated or low-privilege remote attackers to inject arbitrary OS commands through the public_key parameter, and a public exploit is already available, significantly increasing the risk of active exploitation.

Updated Aug 4, 2026 · CVSS 9.8

command-injectioniotrouterrcepublic-exploitnetwork-appliance

A critical command injection vulnerability affects the s2s.enable_echo_server function within the s2s.so native plugin on GL-iNet GL-MT3000 routers up to version 4.4.5. The flaw allows unauthenticated remote attackers to inject arbitrary OS commands via the 'port' argument, and a public exploit is already available. Given the CVSS score of 9.8 and remote exploitability, affected devices are at immediate risk of full compromise.

Updated Aug 4, 2026 · CVSS 9.8

authentication-bypassrmmpatch-bypasscisa-kevaccount-takeovern-central

CVE-2026-18577 is an authentication bypass in N-able N-central, a widely deployed remote monitoring and management (RMM) platform, resulting from an incomplete fix for the prior vulnerability CVE-2026-18556. CISA has added this flaw to its Known Exploited Vulnerabilities catalog with an unusually short remediation window, indicating active or imminent exploitation. Successful exploitation allows attackers to bypass authentication entirely and take over accounts within N-central.

Updated Aug 4, 2026

adobecampaign-classicrceauthorization-bypassunauthenticatedcritical-vulnerability

Adobe has issued an emergency patch for a maximum-severity flaw (CVSS 10.0) in Campaign Classic, its enterprise marketing automation platform, caused by incorrect authorization checks. The vulnerability allows arbitrary code execution without any user interaction, making it a high-priority target for exploitation once details or a proof-of-concept become public.

Updated Aug 3, 2026 · CVSS 10

arcadedbauthorization-bypassdatabaserce-adjacenttime-seriesagent-relevant

ArcadeDB versions prior to 26.7.2 contain a critical authorization bypass vulnerability affecting HTTP handlers for time series, batch, Prometheus, and Grafana endpoints. Unauthenticated or under-privileged attackers can access and manipulate arbitrary databases by directly invoking these endpoints with crafted database parameters, bypassing intended access controls. Given the CVSS score of 9.8, this vulnerability poses a severe risk of data theft, tampering, and destruction on any exposed ArcadeDB instance.

Updated Aug 3, 2026 · CVSS 9.8

arcadedbrceprivilege-escalationdatabasejavascript-injectionagent-relevant

ArcadeDB versions prior to 26.7.2 contain a critical authorization flaw allowing any database user to execute arbitrary JavaScript via the SQL DEFINE FUNCTION statement with LANGUAGE js, bypassing intended admin-only scripting restrictions. This effectively grants remote code execution to any actor with database access, regardless of assigned privilege level.

Updated Aug 3, 2026 · CVSS 9.8

arcadedbrcesandbox-escapejavascript-injectionprivilege-abusedatabaseagent-relevant

ArcadeDB before version 26.7.2 contains a critical flaw in its ScriptTriggerExecutor that improperly whitelists java.lang.* packages, allowing an authenticated user with UPDATE_SCHEMA permission to craft a malicious JavaScript trigger. This trigger can invoke Java.type to access Runtime.getRuntime().exec() or ProcessBuilder, resulting in arbitrary OS command execution when the trigger fires.

Updated Aug 3, 2026 · CVSS 9.8

railsrubyactive-storagercefile-readweb-frameworkagent-relevant

A critical vulnerability in Ruby on Rails' Active Storage framework allows unauthenticated attackers to read arbitrary files from an affected application, with a potential escalation path to remote code execution. Rails maintainers have released patches, and organizations running unpatched Active Storage implementations should prioritize updates given the severity and ease of exploitation typically associated with such flaws.

Updated Aug 2, 2026

rcedeserializationpicklepytorchcomfyuiunauthenticatedagent-relevantai-infrastructuresupply-chain-risk

CVE-2026-68771 is a critical unauthenticated remote code execution vulnerability in ComfyUI v0.23.0, a widely used node-based interface for AI/ML pipelines including Stable Diffusion and generative workflows. Attackers can upload a malicious pickle file and trigger deserialization via the LoadTrainingDataset node, achieving arbitrary code execution as the ComfyUI process user with no authentication required.

Updated Aug 1, 2026 · CVSS 9.8

azurecosmos-dbcloud-vulnerabilitysandbox-escapegremlinprivilege-escalationmulti-tenantcloud-securityagent-relevant

Security researchers at Wiz disclosed a now-patched vulnerability chain in Azure Cosmos DB, dubbed CosmosEscape, that allowed an attacker to escape the Gremlin query sandbox and obtain a platform-wide key granting full read/write access to databases across multiple customer tenants. The flaw originated from a crafted, attacker-controlled Gremlin query that achieved code execution on the underlying host, breaking multi-tenant isolation. Microsoft has remediated the issue; no evidence of in-the-wild exploitation was reported.

Updated Jul 31, 2026