Exploited vulnerabilities
CVEs published in the last 120 days, plus everything on CISA’s known-exploited list. Scores, exploit likelihood and exploitation status in one place.
| Score | CVE | Affected | EPSS | Published |
|---|---|---|---|---|
| 7.8 high | CVE-2026-85880 KEV | Microsoft Windows 10 Version 1607 Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally. | 3.6% | 8 Sept 2026 |
| 7.8 high | CVE-2026-81963 KEV | Microsoft Windows 11 version 23H2 Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally. | 0.39% | 8 Sept 2026 |
| 10.0 critical | CVE-2026-75650 KEV | Adobe Commerce Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed. | 3.9% | 7 Sept 2026 |
| 10.0 critical | CVE-2026-86218 KEV | N-able N-central N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14. | 13% | 6 Sept 2026 |
| 9.2 critical | CVE-2026-86060 KEV | Mikrotik RouterOS RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable) | 6.4% | 5 Sept 2026 |
| 6.9 medium | CVE-2026-67279 KEV | Mikrotik RouterOS RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request. On affected builds the server dispatches the command, enabling unauthenticated creation, overwrite, and reconstruction of files in the RouterOS managed file namespace, including support files containing configuration and diagnostic data.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable) | 1.0% | 5 Sept 2026 |
| 8.8 high | CVE-2026-67277 KEV | Mikrotik RouterOS RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits an uninitialized tail from a kernel packet buffer. A separate unchecked, inverted packet-size interval causes unsigned integer underflow, anomalously large fragmented output, and can restart the RouterOS kernel. This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable) | 1.6% | 5 Sept 2026 |
| 8.8 high | CVE-2026-85046 KEV | Google Chrome Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | 49% | 3 Sept 2026 |
| 7.8 high | CVE-2026-83549 KEV | SonicWall SMA1000 Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution. | 11% | 1 Sept 2026 |
| 10.0 critical | CVE-2026-83548 KEV | SonicWall SMA1000 A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations. | 8.8% | 1 Sept 2026 |
| 9.8 critical | CVE-2026-82329 KEV | jfrog artifactory JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges. | 14% | 28 Aug 2026 |
| 9.4 critical | CVE-2026-82078 KEV | PaperCut MF/NG An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process. | 61% | 28 Aug 2026 |
| 8.8 high | CVE-2026-81578 KEV | PaperCut MF/NG An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations. | 85% | 28 Aug 2026 |
| 9.8 critical | CVE-2026-60004 KEV | Gitea Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation. | 24% | 26 Aug 2026 |
| 9.5 critical | CVE-2026-72530 KEV | TrueConf Server A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system. | 1.7% | 19 Aug 2026 |
| 9.3 critical | CVE-2026-72529 KEV | TrueConf Server A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function. | 1.5% | 19 Aug 2026 |
| 9.3 critical | CVE-2026-19490 KEV | NetScaler ADC Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21. | 23% | 19 Aug 2026 |
| 9.3 critical | CVE-2026-64849 KEV | mlflow MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Starting in 3.3.0 and prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in mlflow/utils/validation.py only for the original URL while mlflow/webhooks/delivery.py follows redirects and re-resolves the hostname without pinning the validated address, allowing attackers to reach internal or cloud metadata services and receive response_status and response_body. This issue is fixed in version 3.15.0. | 9.8% | 17 Aug 2026 |
| 8.9 high | CVE-2026-73570 KEV | Zimbra Collaboration A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user. | 12% | 13 Aug 2026 |
| 7.5 high | CVE-2026-42018 KEV | jfrog artifactory JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources. | 9.8% | 12 Aug 2026 |