Exploited vulnerabilities
CVEs published in the last 120 days, plus everything on CISA’s known-exploited list. Scores, exploit likelihood and exploitation status in one place.
| Score | CVE | Affected | EPSS | Published |
|---|---|---|---|---|
| 5.3 medium | CVE-2026-66384 KEV | jfrog artifactory An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions. | 0.66% | 12 Aug 2026 |
| 9.1 critical | CVE-2026-71362 KEV | Adobe Commerce Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue does not require user interaction. | 88% | 11 Aug 2026 |
| 7.0 high | CVE-2026-68820 KEV | Microsoft Windows 10 Version 1607 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0.33% | 11 Aug 2026 |
| 8.8 high | CVE-2026-65660 KEV | Microsoft SharePoint Enterprise Server 2016 Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 2.1% | 11 Aug 2026 |
| 8.6 high | CVE-2026-20349 KEV | Cisco Secure Firewall Adaptive Security Appliance (ASA) Software A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to insufficient error checking when processing HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. | 1.0% | 11 Aug 2026 |
| 10.0 critical | CVE-2026-72898 KEV | Metabase Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance. | 19% | 10 Aug 2026 |
| 9.8 critical | CVE-2026-65400 KEV | Apple macOS An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1, macOS Tahoe 26.7. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials. | 1.7% | 6 Aug 2026 |
| 10.0 critical | CVE-2026-5430 KEV | WSO2 Universal Gateway The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access. Successful exploitation of this vulnerability may result in unauthorized access to the system, including the potential compromise of administrative accounts and full account takeover. The CVSS score is adjusted to 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) in single-tenant deployments, reflecting that the impact is contained within a single security authority boundary. | 0.59% | 6 Aug 2026 |
| 8.2 high | CVE-2026-18577 KEV | N-able N-central An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1 | 15% | 2 Aug 2026 |
| 8.2 high | CVE-2026-18556 KEV | N-able N-central Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1. | 7.9% | 1 Aug 2026 |
| 9.8 critical | CVE-2026-59310 KEV | VMware Cloud Foundation VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code. | 2.6% | 30 Jul 2026 |
| 5.3 medium | CVE-2026-20316 KEV | Cisco Secure Firewall Management Center (FMC) A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the presence of static user credentials for a low-privileged account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user. Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced. Cisco has assigned this security advisory a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that this vulnerability can be used with other Cisco Secure FMC Software vulnerabilities to elevate privileges. | 35% | 29 Jul 2026 |
| 8.8 high | CVE-2026-42016 KEV | jfrog artifactory JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope. | 8.6% | 27 Jul 2026 |
| 9.8 critical | CVE-2026-63077 KEV | JetBrains TeamCity In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol | 90% | 27 Jul 2026 |
| 10.0 critical | CVE-2026-16812 KEV | Arista Networks VeloCloud Orchestrator On-Prem VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. This functionality was intended to be for internal use only and is not intended to be remotely accessible. Hosted and Dedicated versions of VCO have already been patched in advance of this notice going out. This issue was discovered externally and is known to be actively exploited. | 1.0% | 27 Jul 2026 |
| 9.3 critical | CVE-2026-16232 KEV | checkpoint Quantum Security Management An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers. | 78% | 22 Jul 2026 |
| 9.8 critical | CVE-2026-63030 KEV | WordPress WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution. | 10% | 17 Jul 2026 |
| 5.9 medium | CVE-2026-60137 KEV | WordPress WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter. | 5.9% | 17 Jul 2026 |
| 9.8 critical | CVE-2026-9198 KEV | IBM Langflow OSS IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments | 29% | 17 Jul 2026 |
| 9.3 critical | CVE-2026-9586 KEV | Sangoma Switchvox SMB Edition An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization or parameterization. An unauthenticated remote attacker can execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution. | 19% | 17 Jul 2026 |