Known exploited vulnerabilities

Vulnerabilities CISA has confirmed are being exploited, newest additions first — with the remediation deadline federal agencies must meet.

46,314 CVEs · 1,734 known exploited · CVE data updated 2 hours ago · EPSS 5 hours ago

1,734 results · page 2 of 87 EPSS = probability of exploitation in the next 30 days (FIRST)
Matching CVEs
Score CVE Affected EPSS Added to KEV
9.8 critical CVE-2025-39682 KEV Linux In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call must process either - only contiguous DATA records (any number of them) - one non-DATA record If the next record has different type than what has already been processed we break out of the main processing loop. If the record has already been decrypted (which may be the case for TLS 1.3 where we don't know type until decryption) we queue the pending record to the rx_list. Next recvmsg() will pick it up from there. Queuing the skb to rx_list after zero-copy decrypt is not possible, since in that case we decrypted directly to the user space buffer, and we don't have an skb to queue (darg.skb points to the ciphertext skb for access to metadata like length). Only data records are allowed zero-copy, and we break the processing loop after each non-data record. So we should never zero-copy and then find out that the record type has changed. The corner case we missed is when the initial record comes from rx_list, and it's zero length. 2.9% 18 Sept 2026
7.8 high CVE-2026-87886 KEV Acronis Backup plugin for cPanel & WHM Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux) before build 1.8.11.638, Acronis Backup plugin for DirectAdmin (Linux) before build 1.2.3.238. 0.23% 16 Sept 2026
10.0 critical CVE-2026-76460 KEV Cisco Identity Services Engine Software A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface. 14% 16 Sept 2026
8.8 high CVE-2026-58704 KEV Google Android In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. 0.59% 16 Sept 2026
9.8 critical CVE-2026-76461 KEV Cisco Secure Email A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system. 28% 14 Sept 2026
10.0 critical CVE-2026-85706 KEV GitLab GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.11.12, 19.0 before 19.0.9, 19.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API. 93% 11 Sept 2026
9.9 critical CVE-2026-84869 KEV ConnectWise ScreenConnect A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted. 0.92% 11 Sept 2026
7.5 high CVE-2026-42018 KEV jfrog artifactory JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources. 9.8% 11 Sept 2026
8.8 high CVE-2026-42016 KEV jfrog artifactory JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope. 8.6% 11 Sept 2026
9.2 critical CVE-2026-86060 KEV Mikrotik RouterOS RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable) 6.4% 10 Sept 2026
8.8 high CVE-2026-67277 KEV Mikrotik RouterOS RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits an uninitialized tail from a kernel packet buffer. A separate unchecked, inverted packet-size interval causes unsigned integer underflow, anomalously large fragmented output, and can restart the RouterOS kernel. This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable) 1.6% 10 Sept 2026
8.8 high CVE-2026-87491 KEV Google Chrome Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium) 3.1% 9 Sept 2026
9.3 critical CVE-2026-19490 KEV NetScaler ADC Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21. 23% 9 Sept 2026
10.0 critical CVE-2026-20079 KEV Cisco Secure Firewall Management Center (FMC) A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.  This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow root access to the device.  88% 9 Sept 2026
9.8 critical CVE-2025-25249 KEV Fortinet FortiSwitchManager A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets 3.9% 9 Sept 2026
7.8 high CVE-2026-85880 KEV Microsoft Windows 10 Version 1607 Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally. 3.6% 8 Sept 2026
7.8 high CVE-2026-81963 KEV Microsoft Windows 11 version 23H2 Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally. 0.39% 8 Sept 2026
10.0 critical CVE-2026-75650 KEV Adobe Commerce Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed. 3.9% 8 Sept 2026
10.0 critical CVE-2026-86218 KEV N-able N-central N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14. 13% 8 Sept 2026
8.8 high CVE-2026-85046 KEV Google Chrome Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) 49% 4 Sept 2026