{
  "query": {
    "exploited": "1",
    "page": "6"
  },
  "count": 20,
  "total": 1734,
  "page": 6,
  "limit": 20,
  "updated": {
    "cves": "2026-10-06T02:45:17.993Z",
    "kev": "2026-10-06T03:44:20.273Z",
    "epss": "2026-10-06T00:57:13.818Z",
    "breaches": "2026-10-06T00:45:13.561Z",
    "posts": "2026-10-06T03:45:20.784Z"
  },
  "links": {
    "web": "https://spydr.io/threats?exploited=1&page=6",
    "next": "https://spydr.io/threats.json?exploited=1&page=7"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2026-45247",
      "url": "https://spydr.io/cve/CVE-2026-45247",
      "published": "2026-05-26T15:16:39.263Z",
      "modified": "2026-07-24T11:10:00.170Z",
      "score": 9.3,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "vulncheck.com",
      "epss": 0.02085,
      "epss_percentile": 0.80911,
      "exploited": true,
      "kev": {
        "added": "2026-06-03",
        "due": "2026-06-06",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Mirasvit"
      ],
      "products": [
        "Mirasvit Full Page Cache Warmer for Magento 2"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie. Attackers can exploit the unrestricted call to PHP's native unserialize() function combined with gadget chains available in Magento and its dependencies to execute arbitrary code on the server."
    },
    {
      "id": "CVE-2026-45659",
      "url": "https://spydr.io/cve/CVE-2026-45659",
      "published": "2026-05-22T23:16:56.273Z",
      "modified": "2026-07-23T11:10:00.120Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.02704,
      "epss_percentile": 0.85456,
      "exploited": true,
      "kev": {
        "added": "2026-07-01",
        "due": "2026-07-04",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft SharePoint Enterprise Server 2016",
        "Microsoft SharePoint Server 2019",
        "Microsoft SharePoint Server Subscription Edition"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network."
    },
    {
      "id": "CVE-2026-34910",
      "url": "https://spydr.io/cve/CVE-2026-34910",
      "published": "2026-05-22T02:16:34.527Z",
      "modified": "2026-07-23T16:10:00.137Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "hackerone.com",
      "epss": 0.45768,
      "epss_percentile": 0.98767,
      "exploited": true,
      "kev": {
        "added": "2026-06-23",
        "due": "2026-06-26",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Ubiquiti Inc"
      ],
      "products": [
        "Ubiquiti Inc UniFi OS Server",
        "Ubiquiti Inc UDM",
        "Ubiquiti Inc UDM-Pro",
        "Ubiquiti Inc UDM-SE",
        "Ubiquiti Inc UDM-Pro-Max",
        "Ubiquiti Inc UDM-Beast",
        "Ubiquiti Inc EFG",
        "Ubiquiti Inc UDW",
        "Ubiquiti Inc UDR",
        "Ubiquiti Inc UDR7",
        "Ubiquiti Inc UDR-5G",
        "Ubiquiti Inc Express 7",
        "Ubiquiti Inc UNVR",
        "Ubiquiti Inc UNVR-Pro",
        "Ubiquiti Inc UNVR-Instant",
        "Ubiquiti Inc UNVR-G2",
        "Ubiquiti Inc UNVR-G2-Pro",
        "Ubiquiti Inc ENVR",
        "Ubiquiti Inc ENVR-Core",
        "Ubiquiti Inc UNAS-2"
      ],
      "cwes": [
        "CWE-20"
      ],
      "description": "A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection."
    },
    {
      "id": "CVE-2026-34909",
      "url": "https://spydr.io/cve/CVE-2026-34909",
      "published": "2026-05-22T02:16:34.390Z",
      "modified": "2026-07-23T16:10:00.137Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "hackerone.com",
      "epss": 0.01793,
      "epss_percentile": 0.7766,
      "exploited": true,
      "kev": {
        "added": "2026-06-23",
        "due": "2026-06-26",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Ubiquiti Inc"
      ],
      "products": [
        "Ubiquiti Inc UniFi OS Server",
        "Ubiquiti Inc Express",
        "Ubiquiti Inc UDM",
        "Ubiquiti Inc UDM-Pro",
        "Ubiquiti Inc UDM-SE",
        "Ubiquiti Inc UDM-Pro-Max",
        "Ubiquiti Inc UDM-Beast",
        "Ubiquiti Inc EFG",
        "Ubiquiti Inc UDW",
        "Ubiquiti Inc UDR",
        "Ubiquiti Inc UDR7",
        "Ubiquiti Inc UDR-5G",
        "Ubiquiti Inc Express 7",
        "Ubiquiti Inc UNVR",
        "Ubiquiti Inc UNVR-Pro",
        "Ubiquiti Inc UNVR-Instant",
        "Ubiquiti Inc UNVR-G2",
        "Ubiquiti Inc UNVR-G2-Pro",
        "Ubiquiti Inc ENVR",
        "Ubiquiti Inc ENVR-Core"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account."
    },
    {
      "id": "CVE-2026-34908",
      "url": "https://spydr.io/cve/CVE-2026-34908",
      "published": "2026-05-22T02:16:34.240Z",
      "modified": "2026-07-23T16:10:00.137Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "hackerone.com",
      "epss": 0.15207,
      "epss_percentile": 0.96662,
      "exploited": true,
      "kev": {
        "added": "2026-06-23",
        "due": "2026-06-26",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Ubiquiti Inc"
      ],
      "products": [
        "Ubiquiti Inc UniFi OS Server",
        "Ubiquiti Inc UDM",
        "Ubiquiti Inc UDM-Pro",
        "Ubiquiti Inc UDM-SE",
        "Ubiquiti Inc UDM-Pro-Max",
        "Ubiquiti Inc UDM-Beast",
        "Ubiquiti Inc EFG",
        "Ubiquiti Inc UDW",
        "Ubiquiti Inc UDR",
        "Ubiquiti Inc UDR7",
        "Ubiquiti Inc UDR-5G",
        "Ubiquiti Inc Express 7",
        "Ubiquiti Inc UNVR",
        "Ubiquiti Inc UNVR-Pro",
        "Ubiquiti Inc UNVR-Instant",
        "Ubiquiti Inc UNVR-G2",
        "Ubiquiti Inc UNVR-G2-Pro",
        "Ubiquiti Inc ENVR",
        "Ubiquiti Inc ENVR-Core",
        "Ubiquiti Inc UNAS-2"
      ],
      "cwes": [
        "CWE-284"
      ],
      "description": "A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system."
    },
    {
      "id": "CVE-2026-34926",
      "url": "https://spydr.io/cve/CVE-2026-34926",
      "published": "2026-05-21T14:16:45.213Z",
      "modified": "2026-07-23T16:10:00.137Z",
      "score": 6.7,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:L",
      "score_source": "trendmicro.com",
      "epss": 0.00538,
      "epss_percentile": 0.43306,
      "exploited": true,
      "kev": {
        "added": "2026-05-21",
        "due": "2026-06-04",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Trend Micro, Inc."
      ],
      "products": [
        "Trend Micro, Inc. TrendAI Apex One",
        "Trend Micro, Inc. TrendAI Apex One as a Service"
      ],
      "cwes": [
        "CWE-23"
      ],
      "description": "A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations. This vulnerability is only exploitable on the on-premise version of Apex One and a potential attacker must have access to the Apex One Server and already obtained administrative credentials to the server via some other method to exploit this vulnerability."
    },
    {
      "id": "CVE-2026-48172",
      "url": "https://spydr.io/cve/CVE-2026-48172",
      "published": "2026-05-21T02:16:33.760Z",
      "modified": "2026-07-23T15:10:00.137Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "mitre.org",
      "epss": 0.01011,
      "epss_percentile": 0.6191,
      "exploited": true,
      "kev": {
        "added": "2026-05-26",
        "due": "2026-05-29",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "LiteSpeed Technologies"
      ],
      "products": [
        "LiteSpeed Technologies cPanel Plugin",
        "LiteSpeed Technologies WHM Plugin"
      ],
      "cwes": [
        "CWE-266"
      ],
      "description": "LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of grep -rE \"cpanel_jsonapi_func=redisAble\" /var/cpanel/logs /usr/local/cpanel/logs/ 2>/dev/null in Bash. If you get no output, you have not been hit with exploitation of the vulnerability. If there is output, we recommend you examine the IP addresses in the list, determine if they are valid IP addresses, and if not, block them. To determine damage done, examine the system logs for use by the detected IP addresses. The issue is related to mishandling of Redis enable/disable features. The recommended minimum version is 2.4.7."
    },
    {
      "id": "CVE-2026-9082",
      "url": "https://spydr.io/cve/CVE-2026-9082",
      "published": "2026-05-20T20:16:41.230Z",
      "modified": "2026-07-23T16:10:00.137Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "drupal.org",
      "epss": 0.15701,
      "epss_percentile": 0.96766,
      "exploited": true,
      "kev": {
        "added": "2026-05-22",
        "due": "2026-05-27",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Drupal"
      ],
      "products": [
        "Drupal core"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 10.6.0 before 10.6.9, from 11.0.0 before 11.1.10, from 11.2.0 before 11.2.12, from 11.3.0 before 11.3.10."
    },
    {
      "id": "CVE-2026-45498",
      "url": "https://spydr.io/cve/CVE-2026-45498",
      "published": "2026-05-20T13:16:36.780Z",
      "modified": "2026-07-23T12:10:00.110Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "score_source": "NVD",
      "epss": 0.01267,
      "epss_percentile": 0.68758,
      "exploited": true,
      "kev": {
        "added": "2026-05-20",
        "due": "2026-06-03",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Defender Antimalware Platform"
      ],
      "cwes": [
        "CWE-400"
      ],
      "description": "Microsoft Defender Denial of Service Vulnerability"
    },
    {
      "id": "CVE-2026-41091",
      "url": "https://spydr.io/cve/CVE-2026-41091",
      "published": "2026-05-20T13:16:29.173Z",
      "modified": "2026-07-24T10:10:00.197Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.00443,
      "epss_percentile": 0.36345,
      "exploited": true,
      "kev": {
        "added": "2026-05-20",
        "due": "2026-06-03",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Malware Protection Engine"
      ],
      "cwes": [
        "CWE-59"
      ],
      "description": "Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally."
    },
    {
      "id": "CVE-2026-8398",
      "url": "https://spydr.io/cve/CVE-2026-8398",
      "published": "2026-05-15T09:16:17.653Z",
      "modified": "2026-06-17T11:03:53.007Z",
      "score": 9.3,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "kaspersky.com",
      "epss": 0.00963,
      "epss_percentile": 0.60323,
      "exploited": true,
      "kev": {
        "added": "2026-05-27",
        "due": "2026-05-30",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "AVB Disc Soft"
      ],
      "products": [
        "AVB Disc Soft DAEMON Tools Lite"
      ],
      "cwes": [
        "CWE-506"
      ],
      "description": "A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distributed from the legitimate website daemon-tools.cc between approximately April 8, 2026, and May 5, 2026. Attackers gained unauthorized access to the vendor's (AVB Disc Soft) build or distribution infrastructure and trojanized three binaries: DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe. These files were digitally signed with the legitimate AVB Disc Soft code-signing certificate, allowing the malicious installers to appear trustworthy and bypass signature-based detection."
    },
    {
      "id": "CVE-2026-42897",
      "url": "https://spydr.io/cve/CVE-2026-42897",
      "published": "2026-05-14T18:16:49.360Z",
      "modified": "2026-06-17T10:48:34.893Z",
      "score": 6.1,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.00519,
      "epss_percentile": 0.42127,
      "exploited": true,
      "kev": {
        "added": "2026-05-15",
        "due": "2026-05-29",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Exchange Server 2016 Cumulative Update 23",
        "Microsoft Exchange Server 2019 Cumulative Update 14",
        "Microsoft Exchange Server 2019 Cumulative Update 15",
        "Microsoft Exchange Server Subscription Edition RTM"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network."
    },
    {
      "id": "CVE-2026-20182",
      "url": "https://spydr.io/cve/CVE-2026-20182",
      "published": "2026-05-14T17:16:19.387Z",
      "modified": "2026-06-17T15:06:02.767Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "cisco.com",
      "epss": 0.91522,
      "epss_percentile": 0.99812,
      "exploited": true,
      "kev": {
        "added": "2026-05-14",
        "due": "2026-05-17",
        "action": "Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlined in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco Catalyst SD-WAN Controller",
        "Cisco Catalyst SD-WAN Manager"
      ],
      "cwes": [
        "CWE-287"
      ],
      "description": "May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed in February 2026. This new advisory is for a new vulnerability in the control connection handshaking. The section of this advisory includes Show Control Connections guidance to help with system checks.&nbsp; A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to the affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric."
    },
    {
      "id": "CVE-2026-0257",
      "url": "https://spydr.io/cve/CVE-2026-0257",
      "published": "2026-05-13T19:17:01.040Z",
      "modified": "2026-06-17T10:10:37.953Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:N/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:A/V:D/RE:M/U:Red",
      "score_source": "paloaltonetworks.com",
      "epss": 0.96382,
      "epss_percentile": 0.9988,
      "exploited": true,
      "kev": {
        "added": "2026-05-29",
        "due": "2026-06-01",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Palo Alto Networks",
        "Siemens"
      ],
      "products": [
        "Palo Alto Networks Cloud NGFW",
        "Palo Alto Networks PAN-OS",
        "Palo Alto Networks Prisma Access",
        "Siemens RUGGEDCOM APE1808"
      ],
      "cwes": [
        "CWE-565"
      ],
      "description": "Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues."
    },
    {
      "id": "CVE-2026-45321",
      "url": "https://spydr.io/cve/CVE-2026-45321",
      "published": "2026-05-12T01:16:46.820Z",
      "modified": "2026-06-17T10:51:54.877Z",
      "score": 9.6,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
      "score_source": "github.com",
      "epss": 0.01054,
      "epss_percentile": 0.63188,
      "exploited": true,
      "kev": {
        "added": "2026-05-27",
        "due": "2026-06-10",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "@tanstack"
      ],
      "products": [
        "@tanstack arktype-adapter",
        "@tanstack eslint-plugin-router",
        "@tanstack eslint-plugin-start",
        "@tanstack history",
        "@tanstack nitro-v2-vite-plugin",
        "@tanstack react-router",
        "@tanstack react-router-devtools",
        "@tanstack react-router-ssr-query",
        "@tanstack react-start",
        "@tanstack react-start-client",
        "@tanstack react-start-rsc",
        "@tanstack react-start-server",
        "@tanstack router-cli",
        "@tanstack router-core",
        "@tanstack router-devtools",
        "@tanstack router-devtools-core",
        "@tanstack router-generator",
        "@tanstack router-plugin",
        "@tanstack router-ssr-query-core",
        "@tanstack router-utils"
      ],
      "cwes": [
        "CWE-506"
      ],
      "description": "On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The attacker chained three known vulnerability classes — a pull_request_target \"Pwn Request\" misconfiguration, GitHub Actions cache poisoning across the fork↔base trust boundary, and runtime memory extraction of the OIDC token from the Actions runner process — to publish credential-stealing malware under a trusted identity. Each affected package received exactly two malicious versions, published a few minutes apart."
    },
    {
      "id": "CVE-2026-42271",
      "url": "https://spydr.io/cve/CVE-2026-42271",
      "published": "2026-05-08T04:16:21.820Z",
      "modified": "2026-07-15T02:21:30.727Z",
      "score": 8.7,
      "severity": "high",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "github.com",
      "epss": 0.9257,
      "epss_percentile": 0.99825,
      "exploited": true,
      "kev": {
        "added": "2026-06-08",
        "due": "2026-06-22",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "BerriAI",
        "Red Hat"
      ],
      "products": [
        "BerriAI litellm",
        "Red Hat OpenShift AI 2.25",
        "Red Hat OpenShift AI 3.3",
        "Red Hat OpenShift AI 3.4",
        "Red Hat Exploit Intelligence",
        "Red Hat Ansible Automation Platform 2",
        "Red Hat OpenShift AI (RHOAI)"
      ],
      "cwes": [
        "CWE-77",
        "CWE-78"
      ],
      "description": "LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints used to preview an MCP server before saving it — POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list — accepted a full server configuration in the request body, including the command, args, and env fields used by the stdio transport. When called with a stdio configuration, the endpoints attempted to connect, which spawned the supplied command as a subprocess on the proxy host with the privileges of the proxy process. The endpoints were gated only by a valid proxy API key, with no role check. Any authenticated user — including holders of low-privilege internal-user keys — could therefore run arbitrary commands on the host. This issue has been patched in version 1.83.7."
    },
    {
      "id": "CVE-2026-42208",
      "url": "https://spydr.io/cve/CVE-2026-42208",
      "published": "2026-05-08T04:16:19.923Z",
      "modified": "2026-07-15T02:21:28.627Z",
      "score": 9.3,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "github.com",
      "epss": 0.05772,
      "epss_percentile": 0.92868,
      "exploited": true,
      "kev": {
        "added": "2026-05-08",
        "due": "2026-05-11",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "BerriAI",
        "Red Hat"
      ],
      "products": [
        "BerriAI litellm",
        "Red Hat Lightspeed Core",
        "Red Hat Ansible Automation Platform 2",
        "Red Hat OpenShift AI (RHOAI)"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query used during proxy API key checks mixed the caller-supplied key value into the query text instead of passing it as a separate parameter. An unauthenticated attacker could send a specially crafted Authorization header to any LLM API route (for example POST /chat/completions) and reach this query through the proxy's error-handling path. An attacker could read data from the proxy's database and may be able to modify it, leading to unauthorised access to the proxy and the credentials it manages. This issue has been patched in version 1.83.7."
    },
    {
      "id": "CVE-2026-6973",
      "url": "https://spydr.io/cve/CVE-2026-6973",
      "published": "2026-05-07T16:16:23.163Z",
      "modified": "2026-06-17T11:01:34.360Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "CNA",
      "epss": 0.02537,
      "epss_percentile": 0.84412,
      "exploited": true,
      "kev": {
        "added": "2026-05-07",
        "due": "2026-05-10",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Ivanti"
      ],
      "products": [
        "Ivanti Endpoint Manager Mobile"
      ],
      "cwes": [
        "CWE-20"
      ],
      "description": "An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative access to achieve remote code execution."
    },
    {
      "id": "CVE-2026-0300",
      "url": "https://spydr.io/cve/CVE-2026-0300",
      "published": "2026-05-06T19:16:35.730Z",
      "modified": "2026-06-17T10:10:43.073Z",
      "score": 9.3,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:M/U:Red",
      "score_source": "paloaltonetworks.com",
      "epss": 0.31725,
      "epss_percentile": 0.98252,
      "exploited": true,
      "kev": {
        "added": "2026-05-06",
        "due": "2026-05-09",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Until the vendor releases an official fix, the following workaround should be implemented: - Restrict User-ID Authentication Portal access to only trusted zones. - Disable User-ID Authentication Portal if not required. 5/13/2026: Palo Alto has released a variety of patches. If these are relevant to your environment, please apply the designated patch.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Palo Alto Networks",
        "Siemens"
      ],
      "products": [
        "Palo Alto Networks Cloud NGFW",
        "Palo Alto Networks PAN-OS",
        "Palo Alto Networks Prisma Access",
        "Siemens RUGGEDCOM APE1808"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. The risk of this issue is greatly reduced if you secure access to the User-ID™ Authentication Portal per the best practice guidelines https://knowledgebase.paloaltonetworks.com/KCSArticleDetail by restricting access to only trusted internal IP addresses. Prisma Access, Cloud NGFW and Panorama appliances are not impacted by this vulnerability."
    },
    {
      "id": "CVE-2026-41940",
      "url": "https://spydr.io/cve/CVE-2026-41940",
      "published": "2026-04-29T16:16:25.037Z",
      "modified": "2026-09-30T18:18:18.563Z",
      "score": 9.3,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "vulncheck.com",
      "epss": 0.98527,
      "epss_percentile": 0.9992,
      "exploited": true,
      "kev": {
        "added": "2026-04-30",
        "due": "2026-05-03",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "WebPros"
      ],
      "products": [
        "WebPros cPanel",
        "WebPros WP Squared",
        "WebPros WHM"
      ],
      "cwes": [
        "CWE-306"
      ],
      "description": "cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
