{
  "query": {
    "kev": "1",
    "page": "3"
  },
  "count": 20,
  "total": 1734,
  "page": 3,
  "limit": 20,
  "updated": {
    "cves": "2026-10-06T00:45:13.875Z",
    "kev": "2026-10-06T01:44:15.693Z",
    "epss": "2026-10-06T00:57:13.818Z",
    "breaches": "2026-10-06T00:45:13.561Z",
    "posts": "2026-10-06T01:45:15.769Z"
  },
  "links": {
    "web": "https://spydr.io/threats?kev=1&page=3",
    "next": "https://spydr.io/threats.json?kev=1&page=4"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2026-83549",
      "url": "https://spydr.io/cve/CVE-2026-83549",
      "published": "2026-09-01T22:17:13.290Z",
      "modified": "2026-09-21T14:17:21.703Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.1076,
      "epss_percentile": 0.95712,
      "exploited": true,
      "kev": {
        "added": "2026-09-02",
        "due": "2026-09-05",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "SonicWall"
      ],
      "products": [
        "SonicWall SMA1000"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution."
    },
    {
      "id": "CVE-2026-83548",
      "url": "https://spydr.io/cve/CVE-2026-83548",
      "published": "2026-09-01T22:17:13.170Z",
      "modified": "2026-09-03T13:06:16.053Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.08757,
      "epss_percentile": 0.95021,
      "exploited": true,
      "kev": {
        "added": "2026-09-02",
        "due": "2026-09-05",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "SonicWall"
      ],
      "products": [
        "SonicWall SMA1000"
      ],
      "cwes": [
        "CWE-441",
        "CWE-918"
      ],
      "description": "A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations."
    },
    {
      "id": "CVE-2026-82329",
      "url": "https://spydr.io/cve/CVE-2026-82329",
      "published": "2026-08-28T20:20:21.293Z",
      "modified": "2026-09-03T13:06:15.630Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "jfrog.com",
      "epss": 0.14121,
      "epss_percentile": 0.96474,
      "exploited": true,
      "kev": {
        "added": "2026-09-02",
        "due": "2026-09-05",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "jfrog"
      ],
      "products": [
        "jfrog artifactory"
      ],
      "cwes": [
        "CWE-287"
      ],
      "description": "JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges."
    },
    {
      "id": "CVE-2026-9586",
      "url": "https://spydr.io/cve/CVE-2026-9586",
      "published": "2026-07-17T17:17:18.150Z",
      "modified": "2026-09-03T13:06:25.427Z",
      "score": 9.3,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "CNA",
      "epss": 0.18979,
      "epss_percentile": 0.97228,
      "exploited": true,
      "kev": {
        "added": "2026-09-02",
        "due": "2026-09-05",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Sangoma"
      ],
      "products": [
        "Sangoma Switchvox SMB Edition"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization or parameterization. An unauthenticated remote attacker can execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution."
    },
    {
      "id": "CVE-2026-59822",
      "url": "https://spydr.io/cve/CVE-2026-59822",
      "published": "2026-07-08T20:16:57.683Z",
      "modified": "2026-09-03T13:05:59.573Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "github.com",
      "epss": 0.00836,
      "epss_percentile": 0.56262,
      "exploited": true,
      "kev": {
        "added": "2026-09-02",
        "due": "2026-09-16",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "BerriAI"
      ],
      "products": [
        "BerriAI litellm"
      ],
      "cwes": [
        "CWE-287",
        "CWE-306"
      ],
      "description": "LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to use a fabricated Authorization header to trigger an OAuth2 passthrough fallback path that replaced failed LiteLLM key validation with an empty UserAPIKeyAuth() object, allowing requests to reach MCP tooling without a valid LiteLLM key. This issue is fixed in version 1.84.0."
    },
    {
      "id": "CVE-2026-49869",
      "url": "https://spydr.io/cve/CVE-2026-49869",
      "published": "2026-06-26T22:16:32.113Z",
      "modified": "2026-09-03T13:05:55.387Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "github.com",
      "epss": 0.02095,
      "epss_percentile": 0.81006,
      "exploited": true,
      "kev": {
        "added": "2026-09-02",
        "due": "2026-09-05",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "kestra-io"
      ],
      "products": [
        "kestra-io kestra"
      ],
      "cwes": [
        "CWE-78",
        "CWE-184",
        "CWE-287",
        "CWE-918"
      ],
      "description": "Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().endsWith(\"/configs\") to whitelist the public configuration endpoint from Basic Auth. Because the check is a suffix match rather than an exact path match, any API path whose last segment is configs bypasses authentication entirely. An unauthenticated remote attacker can exploit this to create and execute arbitrary workflows without credentials. Because Kestra ships with script execution plugins (plugin-script-shell, plugin-script-python, etc.) enabled by default, this directly results in unauthenticated Remote Code Execution as root inside the Kestra worker container. This vulnerability is fixed in 1.0.45 and 1.3.21."
    },
    {
      "id": "CVE-2026-48710",
      "url": "https://spydr.io/cve/CVE-2026-48710",
      "published": "2026-05-26T22:16:44.020Z",
      "modified": "2026-10-01T18:17:18.153Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.07056,
      "epss_percentile": 0.9402,
      "exploited": true,
      "kev": {
        "added": "2026-09-02",
        "due": "2026-09-16",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Kludex",
        "Red Hat"
      ],
      "products": [
        "Kludex starlette",
        "Red Hat AI Inference Server 3.3",
        "Red Hat Ansible Automation Platform 2.6",
        "Red Hat Ansible Automation Platform 2.7",
        "Red Hat Migration Toolkit for Applications 8.2",
        "Red Hat OpenShift AI 3.3",
        "Red Hat OpenShift AI 3.4",
        "Red Hat Satellite 6.17",
        "Red Hat Satellite 6.18",
        "Red Hat Satellite 6.19",
        "Red Hat Exploit Intelligence",
        "Red Hat OpenShift Lightspeed",
        "Red Hat AI Inference Server",
        "Red Hat Ansible Automation Platform 2",
        "Red Hat Enterprise Linux AI (RHEL AI) 3",
        "Red Hat OpenShift AI (RHOAI)"
      ],
      "cwes": [
        "CWE-444",
        "CWE-1289"
      ],
      "description": "Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `request.url` is rebuilt from the `Host` header, a malformed header could make `request.url.path` differ from the path that was actually requested. Middleware and endpoints that apply security restrictions based on `request.url` (rather than the raw `scope` path) could therefore be bypassed. Users should upgrade to a version greater than or equal to version 1.0.1, which validates the `Host` header against the grammar of RFC 9112 §3.2 / RFC 3986 §3.2.2 when constructing `request.url` and falls back to `scope[\"server\"]` for malformed values."
    },
    {
      "id": "CVE-2026-82078",
      "url": "https://spydr.io/cve/CVE-2026-82078",
      "published": "2026-08-28T16:18:31.240Z",
      "modified": "2026-09-14T00:16:56.777Z",
      "score": 9.4,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "CNA",
      "epss": 0.61394,
      "epss_percentile": 0.99143,
      "exploited": true,
      "kev": {
        "added": "2026-08-31",
        "due": "2026-09-14",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "PaperCut"
      ],
      "products": [
        "PaperCut MF/NG"
      ],
      "cwes": [
        "CWE-470"
      ],
      "description": "An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process."
    },
    {
      "id": "CVE-2026-81578",
      "url": "https://spydr.io/cve/CVE-2026-81578",
      "published": "2026-08-28T16:18:29.600Z",
      "modified": "2026-09-14T00:16:56.207Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "CNA",
      "epss": 0.84594,
      "epss_percentile": 0.99699,
      "exploited": true,
      "kev": {
        "added": "2026-08-31",
        "due": "2026-09-14",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "PaperCut"
      ],
      "products": [
        "PaperCut MF/NG"
      ],
      "cwes": [
        "CWE-305"
      ],
      "description": "An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations."
    },
    {
      "id": "CVE-2026-66384",
      "url": "https://spydr.io/cve/CVE-2026-66384",
      "published": "2026-08-12T16:17:14.520Z",
      "modified": "2026-08-28T12:21:47.053Z",
      "score": 5.3,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N",
      "score_source": "jfrog.com",
      "epss": 0.00665,
      "epss_percentile": 0.50055,
      "exploited": true,
      "kev": {
        "added": "2026-08-27",
        "due": "2026-09-10",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "jfrog"
      ],
      "products": [
        "jfrog artifactory"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions."
    },
    {
      "id": "CVE-2026-53362",
      "url": "https://spydr.io/cve/CVE-2026-53362",
      "published": "2026-07-04T12:17:02.113Z",
      "modified": "2026-08-28T20:18:10.133Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "CNA",
      "epss": 0.00709,
      "epss_percentile": 0.51891,
      "exploited": true,
      "kev": {
        "added": "2026-08-27",
        "due": "2026-08-30",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Linux"
      ],
      "products": [
        "Linux"
      ],
      "cwes": [
        "CWE-787",
        "CWE-122"
      ],
      "description": "In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocation path In __ip6_append_data(), when the paged-allocation branch is taken (MSG_MORE / NETIF_F_SG / large fraglen), alloclen and pagedlen are computed as alloclen = fragheaderlen + transhdrlen; pagedlen = datalen - transhdrlen; datalen already includes fraggap (datalen = length + fraggap). When fraggap is non-zero, this is not the first skb and transhdrlen is zero. The fraggap bytes carried over from the previous skb are copied just past the fragment headers in the new skb's linear area. The linear area is therefore undersized by fraggap bytes while pagedlen is overstated by the same amount, and the copy writes past skb->end into the trailing skb_shared_info. An unprivileged user can trigger this via a UDPv6 socket using MSG_MORE together with MSG_SPLICE_PAGES. The bad accounting was introduced by commit 773ba4fe9104 (\"ipv6: avoid partial copy for zc\"). Before commit ce650a166335 (\"udp6: Fix __ip6_append_data()'s handling of MSG_SPLICE_PAGES\"), the negative copy value caused -EINVAL to be returned. That later commit allowed MSG_SPLICE_PAGES to proceed in this case, making the corruption triggerable. The non-paged branch sets alloclen to fraglen, which already accounts for fraggap because datalen does. Bring the paged branch in line by adding fraggap to alloclen and subtracting it from pagedlen. After this adjustment, copy no longer collapses to -fraggap on the paged path, so remove the stale comment describing that old arithmetic. Since a negative copy is no longer expected for a valid MSG_SPLICE_PAGES case, remove the MSG_SPLICE_PAGES exception from the negative copy check."
    },
    {
      "id": "CVE-2023-49105",
      "url": "https://spydr.io/cve/CVE-2023-49105",
      "published": "2023-11-21T22:15:08.613Z",
      "modified": "2026-08-28T12:21:09.753Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.42919,
      "epss_percentile": 0.98684,
      "exploited": true,
      "kev": {
        "added": "2026-08-27",
        "due": "2026-08-30",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "owncloud"
      ],
      "products": [
        "owncloud server"
      ],
      "cwes": [
        "CWE-287"
      ],
      "description": "An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs because pre-signed URLs can be accepted even when no signing-key is configured for the owner of the files. The earliest affected version is 10.6.0."
    },
    {
      "id": "CVE-2026-8452",
      "url": "https://spydr.io/cve/CVE-2026-8452",
      "published": "2026-06-30T13:19:33.450Z",
      "modified": "2026-08-27T04:18:00.787Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "CNA",
      "epss": 0.01011,
      "epss_percentile": 0.61922,
      "exploited": true,
      "kev": {
        "added": "2026-08-26",
        "due": "2026-08-29",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "NetScaler"
      ],
      "products": [
        "NetScaler ADC",
        "NetScaler Gateway"
      ],
      "cwes": [
        "CWE-119"
      ],
      "description": "Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server"
    },
    {
      "id": "CVE-2022-0995",
      "url": "https://spydr.io/cve/CVE-2022-0995",
      "published": "2022-03-25T19:15:10.520Z",
      "modified": "2026-08-27T04:16:39.223Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.08788,
      "epss_percentile": 0.95035,
      "exploited": true,
      "kev": {
        "added": "2026-08-26",
        "due": "2026-09-09",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "linux",
        "fedoraproject",
        "netapp"
      ],
      "products": [
        "kernel"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged access or cause a denial of service on the system."
    },
    {
      "id": "CVE-2021-23758",
      "url": "https://spydr.io/cve/CVE-2021-23758",
      "published": "2021-12-03T20:15:07.557Z",
      "modified": "2026-08-27T04:16:38.863Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.82578,
      "epss_percentile": 0.99659,
      "exploited": true,
      "kev": {
        "added": "2026-08-26",
        "due": "2026-09-09",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "ajaxpro.2 project",
        "michaelschwarz"
      ],
      "products": [
        "AjaxPro.2"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution."
    },
    {
      "id": "CVE-2019-1068",
      "url": "https://spydr.io/cve/CVE-2019-1068",
      "published": "2019-07-15T19:15:16.983Z",
      "modified": "2026-08-27T04:16:38.583Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.56999,
      "epss_percentile": 0.99045,
      "exploited": true,
      "kev": {
        "added": "2026-08-26",
        "due": "2026-08-29",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft SQL Server 2014 Service Pack 2 for 32-bit Systems (GDR)",
        "Microsoft SQL Server",
        "Microsoft SQL Server 2014 Service Pack 2 for x64-based Systems (GDR)",
        "Microsoft SQL Server 2016 for x64-based Systems Service Pack 1 (GDR)",
        "Microsoft SQL Server 2017 for x64-based Systems (GDR)",
        "Microsoft SQL Server 2016 for x64-based Systems Service Pack 2 (GDR)",
        "Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (GDR)",
        "Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (CU)",
        "Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (GDR)",
        "Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (CU)"
      ],
      "cwes": [
        "CWE-20"
      ],
      "description": "A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'."
    },
    {
      "id": "CVE-2015-5287",
      "url": "https://spydr.io/cve/CVE-2015-5287",
      "published": "2015-12-07T18:59:02.230Z",
      "modified": "2026-08-27T04:16:38.280Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.04962,
      "epss_percentile": 0.91932,
      "exploited": true,
      "kev": {
        "added": "2026-08-26",
        "due": "2026-09-09",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "redhat",
        "oracle"
      ],
      "products": [
        "redhat automatic bug reporting tool",
        "oracle linux",
        "redhat enterprise linux",
        "redhat enterprise linux desktop",
        "redhat enterprise linux hpc node",
        "redhat enterprise linux server",
        "redhat enterprise linux workstation"
      ],
      "cwes": [
        "CWE-59"
      ],
      "description": "The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name, as demonstrated by /var/tmp/abrt/abrt-hax-coredump or /var/spool/abrt/abrt-hax-coredump."
    },
    {
      "id": "CVE-2015-3246",
      "url": "https://spydr.io/cve/CVE-2015-3246",
      "published": "2015-08-11T14:59:07.040Z",
      "modified": "2026-10-02T11:33:29.473Z",
      "score": 7.4,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.08434,
      "epss_percentile": 0.94848,
      "exploited": true,
      "kev": {
        "added": "2026-08-26",
        "due": "2026-09-09",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "redhat",
        "opensuse",
        "libuser project"
      ],
      "products": [
        "redhat enterprise linux",
        "opensuse",
        "libuser project libuser"
      ],
      "cwes": [
        "CWE-264",
        "CWE-367"
      ],
      "description": "libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error during the modification. NOTE: this issue can be combined with CVE-2015-3245 to gain privileges."
    },
    {
      "id": "CVE-2026-60004",
      "url": "https://spydr.io/cve/CVE-2026-60004",
      "published": "2026-08-26T20:17:56.010Z",
      "modified": "2026-08-27T11:41:19.230Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "mitre.org",
      "epss": 0.23988,
      "epss_percentile": 0.97779,
      "exploited": true,
      "kev": {
        "added": "2026-08-25",
        "due": "2026-08-28",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Gitea"
      ],
      "products": [
        "Gitea"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation."
    },
    {
      "id": "CVE-2026-21962",
      "url": "https://spydr.io/cve/CVE-2026-21962",
      "published": "2026-01-20T22:15:59.110Z",
      "modified": "2026-08-25T04:18:11.067Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N",
      "score_source": "oracle.com",
      "epss": 0.73192,
      "epss_percentile": 0.99447,
      "exploited": true,
      "kev": {
        "added": "2026-08-24",
        "due": "2026-08-27",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Oracle Corporation"
      ],
      "products": [
        "Oracle Corporation Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in"
      ],
      "cwes": [
        "CWE-284"
      ],
      "description": "Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in. While the vulnerability is in Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data. Note: Affected version for Weblogic Server Proxy Plug-in for IIS is 12.2.1.4.0 only. CVSS 3.1 Base Score 10.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N)."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
