{
  "query": {
    "kev": "1",
    "page": "4"
  },
  "count": 20,
  "total": 1734,
  "page": 4,
  "limit": 20,
  "updated": {
    "cves": "2026-10-06T02:45:17.993Z",
    "kev": "2026-10-06T02:44:17.983Z",
    "epss": "2026-10-06T00:57:13.818Z",
    "breaches": "2026-10-06T00:45:13.561Z",
    "posts": "2026-10-06T02:45:17.993Z"
  },
  "links": {
    "web": "https://spydr.io/threats?kev=1&page=4",
    "next": "https://spydr.io/threats.json?kev=1&page=5"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2026-73570",
      "url": "https://spydr.io/cve/CVE-2026-73570",
      "published": "2026-08-13T16:19:06.003Z",
      "modified": "2026-08-24T13:19:17.577Z",
      "score": 8.9,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L",
      "score_source": "mitre.org",
      "epss": 0.11946,
      "epss_percentile": 0.96006,
      "exploited": true,
      "kev": {
        "added": "2026-08-21",
        "due": "2026-08-24",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Zimbra"
      ],
      "products": [
        "Zimbra Collaboration"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user."
    },
    {
      "id": "CVE-2026-72530",
      "url": "https://spydr.io/cve/CVE-2026-72530",
      "published": "2026-08-19T17:21:01.130Z",
      "modified": "2026-08-21T04:18:15.903Z",
      "score": 9.5,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "kaspersky.com",
      "epss": 0.01686,
      "epss_percentile": 0.76229,
      "exploited": true,
      "kev": {
        "added": "2026-08-20",
        "due": "2026-09-03",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "TrueConf"
      ],
      "products": [
        "TrueConf Server"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system."
    },
    {
      "id": "CVE-2026-72529",
      "url": "https://spydr.io/cve/CVE-2026-72529",
      "published": "2026-08-19T17:21:00.990Z",
      "modified": "2026-08-21T04:18:15.753Z",
      "score": 9.3,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "kaspersky.com",
      "epss": 0.01464,
      "epss_percentile": 0.72754,
      "exploited": true,
      "kev": {
        "added": "2026-08-20",
        "due": "2026-08-23",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "TrueConf"
      ],
      "products": [
        "TrueConf Server"
      ],
      "cwes": [
        "CWE-306"
      ],
      "description": "A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function."
    },
    {
      "id": "CVE-2026-64849",
      "url": "https://spydr.io/cve/CVE-2026-64849",
      "published": "2026-08-17T22:17:23.580Z",
      "modified": "2026-10-05T13:35:35.850Z",
      "score": 9.3,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N",
      "score_source": "github.com",
      "epss": 0.09839,
      "epss_percentile": 0.95429,
      "exploited": true,
      "kev": {
        "added": "2026-08-19",
        "due": "2026-09-02",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "mlflow"
      ],
      "products": [
        "mlflow"
      ],
      "cwes": [
        "CWE-918"
      ],
      "description": "MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Starting in 3.3.0 and prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in mlflow/utils/validation.py only for the original URL while mlflow/webhooks/delivery.py follows redirects and re-resolves the hostname without pinning the validated address, allowing attackers to reach internal or cloud metadata services and receive response_status and response_body. This issue is fixed in version 3.15.0."
    },
    {
      "id": "CVE-2026-65400",
      "url": "https://spydr.io/cve/CVE-2026-65400",
      "published": "2026-08-06T22:18:14.533Z",
      "modified": "2026-09-15T12:47:12.333Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.01723,
      "epss_percentile": 0.76727,
      "exploited": true,
      "kev": {
        "added": "2026-08-18",
        "due": "2026-08-21",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple macOS"
      ],
      "cwes": [
        "CWE-287"
      ],
      "description": "An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1, macOS Tahoe 26.7. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials."
    },
    {
      "id": "CVE-2026-59310",
      "url": "https://spydr.io/cve/CVE-2026-59310",
      "published": "2026-07-30T13:16:53.993Z",
      "modified": "2026-08-19T04:17:24.940Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "vmware.com",
      "epss": 0.02565,
      "epss_percentile": 0.84596,
      "exploited": true,
      "kev": {
        "added": "2026-08-18",
        "due": "2026-08-21",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "VMware"
      ],
      "products": [
        "VMware Cloud Foundation",
        "VMware vSphere Foundation",
        "VMware vCenter",
        "VMware Telco Cloud Infrastructure",
        "VMware Telco Cloud Platform"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code."
    },
    {
      "id": "CVE-2026-55040",
      "url": "https://spydr.io/cve/CVE-2026-55040",
      "published": "2026-07-14T18:18:15.413Z",
      "modified": "2026-08-19T04:17:23.540Z",
      "score": 9.1,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
      "score_source": "microsoft.com",
      "epss": 0.69536,
      "epss_percentile": 0.99347,
      "exploited": true,
      "kev": {
        "added": "2026-08-18",
        "due": "2026-08-21",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft SharePoint Enterprise Server 2016",
        "Microsoft SharePoint Server 2019",
        "Microsoft SharePoint Server Subscription Edition"
      ],
      "cwes": [
        "CWE-1390"
      ],
      "description": "Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network."
    },
    {
      "id": "CVE-2026-33824",
      "url": "https://spydr.io/cve/CVE-2026-33824",
      "published": "2026-04-14T18:17:34.767Z",
      "modified": "2026-09-25T18:17:25.133Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.01619,
      "epss_percentile": 0.75243,
      "exploited": true,
      "kev": {
        "added": "2026-08-18",
        "due": "2026-08-21",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 23H2",
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows 11 Version 25H2",
        "Microsoft Windows 11 version 26H1",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)",
        "Microsoft Windows Server 2025",
        "Microsoft Windows Server 2025 (Server Core installation)"
      ],
      "cwes": [
        "CWE-415"
      ],
      "description": "Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network."
    },
    {
      "id": "CVE-2025-62593",
      "url": "https://spydr.io/cve/CVE-2025-62593",
      "published": "2025-11-26T23:15:47.927Z",
      "modified": "2026-10-01T19:17:15.957Z",
      "score": 9.4,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "github.com",
      "epss": 0.62459,
      "epss_percentile": 0.99167,
      "exploited": true,
      "kev": {
        "added": "2026-08-17",
        "due": "2026-08-20",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "ray-project"
      ],
      "products": [
        "ray-project ray"
      ],
      "cwes": [
        "CWE-94",
        "CWE-352"
      ],
      "description": "Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerability exploitable via Firefox and Safari. This vulnerability is due to an insufficient guard against browser-based attacks, as the current defense uses the User-Agent header starting with the string \"Mozilla\" as a defense mechanism. This defense is insufficient as the fetch specification allows the User-Agent header to be modified. Combined with a DNS rebinding attack against the browser, and this vulnerability is exploitable against a developer running Ray who inadvertently visits a malicious website, or is served a malicious advertisement (malvertising). This issue has been patched in version 2.52.0."
    },
    {
      "id": "CVE-2026-68820",
      "url": "https://spydr.io/cve/CVE-2026-68820",
      "published": "2026-08-11T17:19:06.357Z",
      "modified": "2026-08-16T19:17:24.183Z",
      "score": 7,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.00332,
      "epss_percentile": 0.2414,
      "exploited": true,
      "kev": {
        "added": "2026-08-11",
        "due": "2026-08-25",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 23H2",
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows 11 Version 25H2",
        "Microsoft Windows 11 version 26H1",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows Server 2025",
        "Microsoft Windows Server 2025 (Server Core installation)"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally."
    },
    {
      "id": "CVE-2026-20349",
      "url": "https://spydr.io/cve/CVE-2026-20349",
      "published": "2026-08-11T17:17:48.833Z",
      "modified": "2026-09-16T21:17:12.103Z",
      "score": 8.6,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H",
      "score_source": "cisco.com",
      "epss": 0.0101,
      "epss_percentile": 0.61895,
      "exploited": true,
      "kev": {
        "added": "2026-08-11",
        "due": "2026-08-14",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco Secure Firewall Adaptive Security Appliance (ASA) Software",
        "Cisco Secure Firewall Threat Defense (FTD) Software"
      ],
      "cwes": [
        "CWE-244"
      ],
      "description": "A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.&nbsp; This vulnerability is due to insufficient error checking when processing HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition."
    },
    {
      "id": "CVE-2026-72898",
      "url": "https://spydr.io/cve/CVE-2026-72898",
      "published": "2026-08-10T18:18:53.300Z",
      "modified": "2026-08-12T15:18:30.347Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "CNA",
      "epss": 0.19048,
      "epss_percentile": 0.97237,
      "exploited": true,
      "kev": {
        "added": "2026-08-11",
        "due": "2026-08-14",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Metabase"
      ],
      "products": [
        "Metabase"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance."
    },
    {
      "id": "CVE-2026-8037",
      "url": "https://spydr.io/cve/CVE-2026-8037",
      "published": "2026-06-04T14:16:45.177Z",
      "modified": "2026-10-01T18:17:28.647Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.77362,
      "epss_percentile": 0.99546,
      "exploited": true,
      "kev": {
        "added": "2026-08-07",
        "due": "2026-08-10",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Progress Software"
      ],
      "products": [
        "Progress Software LoadMaster",
        "Progress Software ECS Connections Manager",
        "Progress Software Object Scale Connection Manager",
        "Progress Software MOVEit WAF"
      ],
      "cwes": [
        "CWE-77"
      ],
      "description": "OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints"
    },
    {
      "id": "CVE-2026-63077",
      "url": "https://spydr.io/cve/CVE-2026-63077",
      "published": "2026-07-27T17:16:38.830Z",
      "modified": "2026-08-06T05:17:05.170Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "jetbrains.com",
      "epss": 0.8957,
      "epss_percentile": 0.99784,
      "exploited": true,
      "kev": {
        "added": "2026-08-05",
        "due": "2026-08-08",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "JetBrains"
      ],
      "products": [
        "JetBrains TeamCity"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol"
    },
    {
      "id": "CVE-2026-18556",
      "url": "https://spydr.io/cve/CVE-2026-18556",
      "published": "2026-08-01T20:16:37.157Z",
      "modified": "2026-08-05T05:16:46.967Z",
      "score": 8.2,
      "severity": "high",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "CNA",
      "epss": 0.07882,
      "epss_percentile": 0.94547,
      "exploited": true,
      "kev": {
        "added": "2026-08-04",
        "due": "2026-08-07",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "N-able"
      ],
      "products": [
        "N-able N-central"
      ],
      "cwes": [
        "CWE-288"
      ],
      "description": "Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1."
    },
    {
      "id": "CVE-2026-9198",
      "url": "https://spydr.io/cve/CVE-2026-9198",
      "published": "2026-07-17T18:17:17.340Z",
      "modified": "2026-08-17T20:16:48.010Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "us.ibm.com",
      "epss": 0.28658,
      "epss_percentile": 0.9809,
      "exploited": true,
      "kev": {
        "added": "2026-08-04",
        "due": "2026-08-07",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "IBM"
      ],
      "products": [
        "IBM Langflow OSS"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments"
    },
    {
      "id": "CVE-2026-34486",
      "url": "https://spydr.io/cve/CVE-2026-34486",
      "published": "2026-04-09T20:16:25.063Z",
      "modified": "2026-09-21T19:17:04.670Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "CISA ADP",
      "epss": 0.06561,
      "epss_percentile": 0.93622,
      "exploited": true,
      "kev": {
        "added": "2026-08-04",
        "due": "2026-08-07",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apache Software Foundation",
        "Red Hat"
      ],
      "products": [
        "Apache Software Foundation Apache Tomcat",
        "Red Hat Enterprise Linux 10",
        "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
        "Red Hat Enterprise Linux 8",
        "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "Red Hat Enterprise Linux 9",
        "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
        "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "Red Hat JBoss Web Server 7.0.0",
        "Red Hat JBoss Web Server 7.0 on RHEL 10",
        "Red Hat JBoss Web Server 7.0 on RHEL 8",
        "Red Hat JBoss Web Server 7.0 on RHEL 9",
        "Red Hat Enterprise Linux 6",
        "Red Hat JBoss Web Server 5",
        "Red Hat JBoss Web Server 6"
      ],
      "cwes": [
        "CWE-311",
        "CWE-807"
      ],
      "description": "Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue."
    },
    {
      "id": "CVE-2026-18577",
      "url": "https://spydr.io/cve/CVE-2026-18577",
      "published": "2026-08-02T23:16:26.210Z",
      "modified": "2026-08-04T14:27:12.530Z",
      "score": 8.2,
      "severity": "high",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:L/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "CNA",
      "epss": 0.14622,
      "epss_percentile": 0.96562,
      "exploited": true,
      "kev": {
        "added": "2026-08-03",
        "due": "2026-08-06",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "N-able"
      ],
      "products": [
        "N-able N-central"
      ],
      "cwes": [
        "CWE-288"
      ],
      "description": "An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1"
    },
    {
      "id": "CVE-2026-20316",
      "url": "https://spydr.io/cve/CVE-2026-20316",
      "published": "2026-07-29T17:16:51.840Z",
      "modified": "2026-09-16T21:17:10.150Z",
      "score": 5.3,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
      "score_source": "cisco.com",
      "epss": 0.35096,
      "epss_percentile": 0.98399,
      "exploited": true,
      "kev": {
        "added": "2026-07-29",
        "due": "2026-08-01",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco Secure Firewall Management Center (FMC)"
      ],
      "cwes": [
        "CWE-259"
      ],
      "description": "A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the presence of static user credentials for a low-privileged&nbsp;account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user.&nbsp; Note:&nbsp;If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.&nbsp;&nbsp; Cisco has assigned this security advisory a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that this vulnerability can be used with other Cisco Secure FMC Software vulnerabilities to elevate privileges."
    },
    {
      "id": "CVE-2026-16812",
      "url": "https://spydr.io/cve/CVE-2026-16812",
      "published": "2026-07-27T16:17:03.640Z",
      "modified": "2026-07-28T14:50:33.960Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "arista.com",
      "epss": 0.01001,
      "epss_percentile": 0.61556,
      "exploited": true,
      "kev": {
        "added": "2026-07-27",
        "due": "2026-07-30",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Arista Networks"
      ],
      "products": [
        "Arista Networks VeloCloud Orchestrator On-Prem"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. This functionality was intended to be for internal use only and is not intended to be remotely accessible. Hosted and Dedicated versions of VCO have already been patched in advance of this notice going out. This issue was discovered externally and is known to be actively exploited."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
