// CVE Tracker

Critical vulnerabilities currently doing the rounds โ€” sorted by CVSS score.

60

CRITICAL

53

HIGH

114

TOTAL ACTIVE

110

PATCHED

CVSS Scale: 9.0โ€“10.0 CRITICAL ยท 7.0โ€“8.9 HIGH ยท 4.0โ€“6.9 MEDIUM ยท 0.1โ€“3.9 LOW
9.3
CVSS

CVE-2026-25874

Hugging Face LeRobot โ€” Unauthenticated Remote Code Execution via Pickle Deserialization in gRPC Server

CRITICAL โœ• No Patch

CVE-2026-25874 is a critical unauthenticated remote code execution vulnerability in Hugging Face's LeRobot robotics AI framework caused by the use of Python pickle deserialization to process attacker-controlled data in the gRPC remote control and dataset streaming server. The gRPC server binds to all interfaces by default, exposing the endpoint to any network-accessible host. A remote unauthenticated attacker can send a crafted pickle payload to execute arbitrary operating system commands in the context of the LeRobot server process. No patch is available at time of disclosure.

Hugging Face LeRobot v2.4.1 and all prior releases
~7.8
EST.

CVE-2026-43284

Linux Kernel โ€” xfrm/ESP Page-Cache Race Condition Enables Deterministic Local Privilege Escalation (Dirty Frag)

HIGH โœ• No Patch

CVE-2026-43284 is the xfrm/ESP component of the 'Dirty Frag' Linux kernel privilege escalation chain. A race condition in the xfrm (IPsec transform) subsystem's page-cache management allows a local user to corrupt kernel memory in a deterministic manner โ€” unlike most Linux kernel race conditions, this path does not require timing luck. Exploitation reliably escalates a local user account to root. The vulnerability affects all major Linux distributions running kernel versions 5.10 through 6.9. This CVE is the first of two constituent components of the Dirty Frag exploit chain; the second is CVE-2026-43500 (RxRPC page-cache corruption).

Linux kernel 5.10 through 6.9 (all distributions) Ubuntu 22.04 LTS, 24.04 LTS Red Hat Enterprise Linux 9 +3 more
~7.8
EST.

CVE-2026-43500

Linux Kernel โ€” RxRPC Page-Cache Corruption Enables Deterministic Local Privilege Escalation (Dirty Frag)

HIGH โœ• No Patch

CVE-2026-43500 is the RxRPC component of the 'Dirty Frag' Linux kernel privilege escalation chain. A page-cache corruption vulnerability in the RxRPC (AFS/Kerberos transport) subsystem allows a local user to achieve controlled kernel memory corruption as part of the chained Dirty Frag exploit. In combination with CVE-2026-43284 (xfrm/ESP race condition), the full chain reliably escalates a local user to root on a deterministic, single-attempt basis across all major Linux distributions running kernel 5.10โ€“6.9. A working public proof-of-concept exploit exists. No kernel patch is available.

Linux kernel 5.10 through 6.9 (all distributions) Ubuntu 22.04 LTS, 24.04 LTS Red Hat Enterprise Linux 9 +3 more
7.2
CVSS

CVE-2025-29635

D-Link DIR-823X โ€” Authenticated OS Command Injection via /goform/set_prohibiting (EOL, No Patch)

HIGH โœ• No Patch

OS command injection in the D-Link DIR-823X web management interface via the SiteList parameter of the /goform/set_prohibiting endpoint. Authenticated attackers can inject shell commands executing as root. D-Link DIR-823X reached end of life in January 2025 โ€” no patch will be issued. Actively exploited by Mirai botnet campaigns documented by Akamai; added to CISA Known Exploited Vulnerabilities catalogue April 2026. Federal deadline for FCEB agencies: May 19, 2026. Only remediation is device replacement.

D-Link DIR-823X (all firmware versions โ€” EOL, no patch available)
10.0
CVSS

CVE-2025-32432

Craft CMS โ€” Unauthenticated Remote Code Execution via Code Injection

CRITICAL โœ“ Patch Available

A maximum-severity code injection vulnerability (CWE-94) in Craft CMS allows unauthenticated remote attackers to execute arbitrary PHP code on any accessible Craft installation. The vulnerability affects all major version branches from 3.0.0-RC1 through the respective unpatched minor versions. Orange Cyberdefense SensePost assessed exploitation began as a zero-day approximately February 2025. The Mimo intrusion set (aka Hezb) actively exploits this CVE to deploy cryptocurrency miners and residential proxy malware on compromised servers. CISA added CVE-2025-32432 to the Known Exploited Vulnerabilities catalogue on 20 March 2026, with a federal patch deadline of 3 April 2026.

Craft CMS 3.0.0-RC1 through 3.9.14 Craft CMS 4.0.0-RC1 through 4.14.14 Craft CMS 5.0.0-RC1 through 5.6.16
10.0
CVSS

CVE-2025-32975

Quest KACE Systems Management Appliance โ€” Unauthenticated SQL Injection (CVSS 10.0)

CRITICAL โœ“ Patch Available

A SQL injection vulnerability in Quest KACE Systems Management Appliance (SMA) allows an unauthenticated, network-accessible attacker to execute arbitrary SQL against the appliance database without any credentials. KACE SMA is an enterprise endpoint management and patch deployment platform โ€” its database contains device inventories, software deployment records, patch compliance status, credentials used by managed agents, and configuration data for all managed endpoints. The vulnerability was added to the CISA Known Exploited Vulnerabilities catalogue, confirming active exploitation in the wild. Federal agencies face a remediation deadline of May 4, 2026.

Quest KACE Systems Management Appliance (SMA) โ€” versions prior to 13.2 patch
10.0
CVSS

CVE-2025-59528

Flowise CustomMCP Node Unauthenticated Remote Code Execution

CRITICAL โœ“ Patch Available

A code injection vulnerability in the CustomMCP node of Flowise, the open-source AI workflow builder, allows unauthenticated remote attackers to execute arbitrary JavaScript on the host machine. The node processes user-supplied mcpServerConfig parameters without sanitisation or sandboxing, enabling full system compromise. Over 12,000 internet-exposed Flowise instances remain unpatched and are actively targeted. Exploits are publicly available including a Metasploit module.

Flowise 2.x through 3.0.5
10.0
CVSS

CVE-2026-20127

Cisco Catalyst SD-WAN Controller Authentication Bypass

CRITICAL โœ“ Patch Available

A maximum-severity (CVSS 10.0) authentication bypass vulnerability in the Cisco Catalyst SD-WAN Controller and Manager allows an unauthenticated remote attacker to gain full administrative access by exploiting a broken peering authentication mechanism in the control-plane workflow. The exploit sends a forged CHALLENGE_ACK_ACK message to force the server to treat an unauthenticated connection as verified, enabling injection of malicious SSH keys and full control of the SD-WAN fabric. Cisco Talos attributes sustained exploitation since at least 2023 to a tracked threat actor designated UAT-8616, assessed with high confidence as a sophisticated, likely nation-state-aligned group. The vulnerability is included in CISA Emergency Directive 26-03.

Cisco Catalyst SD-WAN Controller / Manager 20.11.x before 20.12.6.1 Cisco Catalyst SD-WAN Controller / Manager 20.12.5.x before 20.12.5.3 Cisco Catalyst SD-WAN Controller / Manager 20.12.6.x before 20.12.6.1
10.0
CVSS

CVE-2026-20131

Cisco Secure Firewall Management Center โ€” Unauthenticated Deserialization RCE (Root Access)

CRITICAL โœ“ Patch Available

A maximum-severity insecure deserialization vulnerability in Cisco Secure Firewall Management Center (FMC) allows unauthenticated remote attackers to send a crafted serialised Java object to the management interface, resulting in arbitrary Java code execution as root. CVE-2026-20131 was exploited as a zero-day by Interlock ransomware for 36 days before Cisco patched it on 4 March 2026. Compromising Cisco FMC gives attackers full control over firewall policy, segmentation rules, VPN configuration, and all managed Firepower sensors โ€” effectively compromising the organisation's network security enforcement layer.

Cisco Secure Firewall Management Center (FMC) versions prior to SA-FMC-2026-0001 patch
10.0
CVSS

CVE-2026-22557

Ubiquiti UniFi Network Application โ€” Unauthenticated Path Traversal Leading to Account Takeover

CRITICAL โœ“ Patch Available

A maximum-severity path traversal vulnerability in the Ubiquiti UniFi Network Application allows unauthenticated remote attackers to read arbitrary files from the underlying operating system, including the controller's database credentials and user session tokens, enabling full account takeover without any authentication. No user interaction or special conditions are required. Approximately 87,000 internet-exposed UniFi controllers were identified by Censys at time of disclosure. The vulnerability is commonly chained with CVE-2026-22558 (NoSQL injection) for immediate administrative access.

Ubiquiti UniFi Network Application prior to 10.1.89 (stable) Ubiquiti UniFi Network Application prior to 10.2.97 (release candidate) Ubiquiti UniFi Express firmware prior to 4.0.13
10.0
CVSS

CVE-2026-22769

Dell RecoverPoint Hardcoded Apache Tomcat Credentials โ€” Nation-State Exploitation

CRITICAL โœ“ Patch Available

Dell RecoverPoint data replication appliances ship with hardcoded Apache Tomcat administrative credentials that cannot be changed through standard configuration. Remote unauthenticated attackers who discover the hardcoded credentials gain full administrative access to the appliance management interface. The China-nexus threat cluster UNC6201 exploited this vulnerability from at least mid-2024 to deploy the BRICKSTORM backdoor and GRIMBOLT loader via the SLAYSTYLE web shell, targeting organisations in financial services, defence contracting, and critical infrastructure.

Dell RecoverPoint for Virtual Machines โ€” versions prior to November 2025 patch (DSA-2026-079) Dell RecoverPoint โ€” all versions prior to DSA-2026-079
10.0
CVSS

CVE-2026-33819

Microsoft Bing โ€” Unauthenticated Remote Code Execution via Deserialization

CRITICAL โœ“ Patch Available

CVE-2026-33819 is a critical deserialization vulnerability in a Microsoft Bing backend service exposed over the network. An unauthenticated attacker can send a crafted payload to the vulnerable endpoint to achieve remote code execution with scope change, earning the vulnerability a maximum CVSS score of 10.0. No workaround exists; the April 2026 Patch Tuesday update is the only remediation.

Microsoft Bing (backend service โ€” April 2026 Patch Tuesday) Microsoft 365 Copilot (integrated Bing backend) Azure Cognitive Services (Bing-integrated components)
10.0
CVSS

CVE-2026-35431

Microsoft Entra ID Entitlement Management โ€” Unauthenticated SSRF (CVSS 10.0)

CRITICAL โœ“ Patch Available

A server-side request forgery vulnerability in Microsoft Entra ID Entitlement Management allows an unauthenticated, network-accessible attacker to cause Microsoft's cloud identity governance service to issue arbitrary requests on behalf of the attacker. Entitlement Management controls access request workflows, approval policies, and periodic access reviews for Azure resources, SharePoint sites, and Entra-connected applications across enterprise tenants. Microsoft applied a server-side fix; no customer patch or configuration change is required. The exposure window between discovery and fix is not publicly disclosed.

Microsoft Entra ID (all tenants using Entitlement Management) Azure Active Directory Entitlement Management (cloud service)
10.0
CVSS

CVE-2026-4681

PTC Windchill and FlexPLM โ€” Unauthenticated Remote Code Execution via Insecure Deserialization

CRITICAL โœ“ Patch Available

A critical remote code execution vulnerability in PTC Windchill (product lifecycle management) and PTC FlexPLM (retail PLM) arises from insecure deserialisation of trusted data in the application server. An unauthenticated attacker with network access can send a malicious serialised object and achieve arbitrary code execution. No patch was available at time of initial disclosure; the severity prompted German federal police (BKA) and state police (LKA) to physically dispatch officers to affected companies on the weekend of 27 March 2026. PTC provided a temporary web server rule workaround while developing a permanent fix.

PTC Windchill โ€” most supported versions and all critical patch sets (CPS) PTC FlexPLM โ€” most supported versions
10.0
CVSS

CVE-2026-7411

Eclipse BaSyx โ€” Unauthenticated Arbitrary File Upload and Remote Code Execution (CVSS 10.0)

CRITICAL โœ“ Patch Available

A maximum-severity path traversal and arbitrary file upload vulnerability in Eclipse BaSyx โ€” industrial automation software used in Industry 4.0 programmes โ€” allows an unauthenticated remote attacker to upload any file to the server and achieve code execution. BaSyx sits at the IT/OT boundary in smart factory deployments, making exploitation capable of reaching operational technology systems protected by network segmentation. A companion vulnerability (CVE-2026-7412) allows blind SSRF to probe and communicate with factory network equipment from the internet.

Eclipse BaSyx Java Server SDK prior to v2.0.0-milestone-10 Eclipse BaSyx AAS Server component (all versions prior to milestone-10)
9.9
CVSS

CVE-2026-20147

Cisco Identity Services Engine โ€” Full Admin to Root OS Command Injection

CRITICAL โœ“ Patch Available

An authenticated attacker in possession of full ISE administrative credentials can send crafted HTTP requests to execute arbitrary OS commands with root privileges on the ISE appliance. While the exploitation bar is higher than CVE-2026-20180 (requires full admin rather than read-only admin), the vulnerability represents an unauthorised escalation from the ISE management plane to full OS-level control. Affects the same ISE version range as CVE-2026-20180 and CVE-2026-20186.

Cisco Identity Services Engine (ISE) prior to 3.2 Cisco Identity Services Engine (ISE) 3.2, 3.3, 3.4, 3.5 (unpatched)
9.9
CVSS

CVE-2026-20180

Cisco Identity Services Engine โ€” Read-Only Admin to Root OS Command Injection

CRITICAL โœ“ Patch Available

Insufficient validation of user-supplied input in Cisco ISE's web interface allows an authenticated attacker with read-only administrator credentials to send crafted HTTP requests and execute arbitrary OS commands with root privileges. Successful exploitation grants full operating system access. In single-node ISE deployments, exploitation may also cause a denial-of-service condition. Affects all ISE branches from 3.2 through 3.5 and versions prior to 3.2.

Cisco Identity Services Engine (ISE) prior to 3.2 Cisco Identity Services Engine (ISE) 3.2, 3.3, 3.4, 3.5 (unpatched)
9.9
CVSS

CVE-2026-20186

Cisco Identity Services Engine โ€” Read-Only Admin to Root via Path Traversal and Command Injection

CRITICAL โœ“ Patch Available

A related but distinct variant of CVE-2026-20180 in Cisco ISE. Insufficient input validation allows an authenticated attacker with read-only administrator credentials to send crafted HTTP requests that execute arbitrary OS commands as root. Shares the same affected version range and exploitation prerequisites as CVE-2026-20180, and should be patched simultaneously.

Cisco Identity Services Engine (ISE) prior to 3.2 Cisco Identity Services Engine (ISE) 3.2, 3.3, 3.4, 3.5 (unpatched)
9.9
CVSS

CVE-2026-21515

Azure IoT Central โ€” Privilege Escalation via Sensitive Data Exposure

CRITICAL โœ“ Patch Available

CVE-2026-21515 is a near-maximum severity privilege escalation vulnerability in Azure IoT Central. A low-privilege authenticated attacker can access sensitive platform configuration data โ€” including device provisioning credentials and shared access signatures โ€” that should be restricted to administrative accounts, then leverage that data to escalate to full tenant administrative control. Microsoft patched the vulnerability in the April 2026 Patch Tuesday release.

Azure IoT Central (cloud-managed; patched April 2026 Patch Tuesday)
9.9
CVSS

CVE-2026-27681

SAP Business Planning and Consolidation SQL Injection โ€” Authenticated Low-Privilege RCE on ERP Database

CRITICAL โœ“ Patch Available

A SQL injection vulnerability in SAP Business Planning and Consolidation (BPC) and SAP BW/4HANA allows an authenticated user with low-privilege access to execute arbitrary SQL against the underlying database. Exploiting the flaw gives the attacker full read and write access to financial planning data, consolidated accounts, and audit records stored in the ERP database tier. The vulnerability was patched in SAP's April 2026 Security Patch Day. SAP BPC and BW/4HANA are deployed in large enterprise environments for financial close processes, regulatory reporting, and management consolidation โ€” making the database tier a high-value target for financial fraud, data manipulation, and ransomware operators seeking maximum leverage.

SAP Business Planning and Consolidation (BPC) โ€” all versions prior to April 2026 patch SAP BW/4HANA โ€” all versions prior to April 2026 patch
9.8
CVSS

CVE-2024-57726

SimpleHelp Remote Management Tool โ€” Missing Authorisation Unauthenticated Admin Access

CRITICAL โœ“ Patch Available

A missing authorisation check in the SimpleHelp remote management and monitoring (RMM) server allows an unauthenticated remote attacker to enumerate user accounts, extract active session tokens, and escalate to full administrator access without credentials. The vulnerability exists in the server's API layer where administrative endpoints fail to validate caller authentication. Exploitation enables complete takeover of the SimpleHelp server and authenticated access to all managed endpoints connected to it.

SimpleHelp Server all versions prior to patched release
9.8
CVSS

CVE-2024-7399

Samsung MagicINFO Digital Signage Server โ€” Authenticated Remote Code Execution via Arbitrary File Upload

CRITICAL โœ“ Patch Available

An arbitrary file upload vulnerability in Samsung MagicINFO, the content and device management server for Samsung commercial displays and digital signage, allows an authenticated attacker with any user-level account to upload and execute arbitrary files on the server. The flaw exists in the content management component's lack of upload type validation. Successful exploitation provides full server compromise with code execution in the context of the MagicINFO service.

Samsung MagicINFO 9 Server all versions prior to patched release Samsung MagicINFO 8 Server
9.8
CVSS

CVE-2025-53521

F5 BIG-IP APM Remote Code Execution via apmd Process

CRITICAL โœ“ Patch Available

A remote code execution vulnerability in F5 BIG-IP Access Policy Manager (APM) affecting the apmd process. Initially disclosed in October 2025 as a denial-of-service flaw, F5 reclassified the vulnerability in March 2026 after new exploitation information emerged. An unauthenticated remote attacker can exploit the flaw to achieve code execution on the BIG-IP appliance. CISA confirmed active exploitation and added CVE-2025-53521 to its Known Exploited Vulnerabilities catalogue on 27 March 2026, issuing a three-day patch mandate to federal agencies.

F5 BIG-IP APM 17.5.0 โ€“ 17.5.1 F5 BIG-IP APM 17.1.0 โ€“ 17.1.2 F5 BIG-IP APM 16.1.0 โ€“ 16.1.6 +1 more
9.8
CVSS

CVE-2026-1281

Ivanti EPMM Apache URL Rewriting Code Injection โ€” Unauthenticated RCE

CRITICAL โœ“ Patch Available

A code injection vulnerability in legacy bash scripts used by Ivanti EPMM's Apache web server for URL rewriting allows unauthenticated remote attackers to execute arbitrary commands. This is the primary initial-access vector in the Ivanti EPMM exploit chain, typically followed by CVE-2026-1340 for further capability extension. CISA added this vulnerability to the KEV catalogue in January 2026 with exploitation confirmed in the wild targeting government and enterprise MDM deployments.

Ivanti Endpoint Manager Mobile (EPMM) all supported versions through 12.7.x
9.8
CVSS

CVE-2026-1340

Ivanti EPMM Android File Transfer Code Injection โ€” Unauthenticated RCE

CRITICAL โœ“ Patch Available

A code injection vulnerability in Ivanti Endpoint Manager Mobile (EPMM)'s Android File Transfer mechanism allows unauthenticated remote attackers to execute arbitrary code on internet-exposed appliances. The flaw is frequently chained with CVE-2026-1281 to achieve full appliance compromise. Active exploitation has been confirmed since January 2026, and CISA added the vulnerability to its Known Exploited Vulnerabilities catalogue on 8 April 2026 with a federal agency patch deadline of 11 April.

Ivanti Endpoint Manager Mobile (EPMM) all supported versions through 12.7.x
9.8
CVSS

CVE-2026-20093

Cisco Integrated Management Controller Authentication Bypass

CRITICAL โœ“ Patch Available

A critical authentication bypass in the Cisco Integrated Management Controller (IMC) allows an unauthenticated remote attacker to bypass authentication entirely and gain elevated access to the affected system. The vulnerability is caused by incorrect handling of password change requests โ€” an attacker sends a crafted HTTP request to the IMC management interface to bypass authentication, reset the password of any local user including administrators, and gain full control of the server's out-of-band management plane. IMC access is equivalent to physical console access to the server.

Cisco UCS C-Series and E-Series Standalone Rack Servers (IMC firmware prior to patched release) Cisco HyperFlex HX Series Nodes with unpatched IMC
9.8
CVSS

CVE-2026-20160

Cisco Smart Software Manager On-Prem Unauthenticated RCE

CRITICAL โœ“ Patch Available

A critical vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) allows an unauthenticated remote attacker to execute arbitrary commands on the underlying operating system. The flaw stems from the unintentional exposure of an internal administrative service that was not designed to accept external connections โ€” an attacker who reaches this service can invoke OS-level commands without authentication. SSM On-Prem is used by enterprises to manage Cisco software licences on-premises, without sending licence data to Cisco's cloud.

Cisco Smart Software Manager On-Prem (SSM On-Prem) prior to version 9-202601
9.8
CVSS

CVE-2026-20184

Cisco Webex Services โ€” Unauthenticated SSO User Impersonation via Certificate Validation Bypass

CRITICAL โœ“ Patch Available

An improper certificate validation flaw (CWE-295) in Cisco Webex Services' SSO integration with Control Hub allows unauthenticated remote attackers to supply crafted SAML tokens and be authenticated as any user within an enterprise's Webex tenant. Cisco has patched the cloud infrastructure, but enterprise administrators using SSO must manually regenerate and upload a new IdP SAML certificate to Control Hub to complete remediation.

Cisco Webex Services (all enterprise SSO-enabled deployments)
9.8
CVSS

CVE-2026-21643

Fortinet FortiClient EMS 7.4.4 โ€” Pre-Authentication SQL Injection RCE

CRITICAL โœ“ Patch Available

A critical pre-authentication SQL injection vulnerability (CWE-89) in Fortinet FortiClient EMS 7.4.4 allows an unauthenticated remote attacker to execute arbitrary code via the /api/v1/init_consts endpoint. The flaw was introduced when the multi-tenant database connection layer was refactored in 7.4.4, replacing parameterised queries with raw string interpolation. Because the PostgreSQL database user runs with superuser privileges in Fortinet's shipped VM image, successful SQL injection escalates to OS command execution via COPY ... TO/FROM PROGRAM. The vulnerability enables extraction of admin password hashes, API tokens, JWT secrets, and the complete endpoint inventory of all managed FortiClient deployments. CISA added CVE-2026-21643 to the KEV catalogue on 13 April 2026.

Fortinet FortiClient EMS 7.4.4
9.8
CVSS

CVE-2026-21992

Oracle Identity Manager Pre-Authentication Remote Code Execution

CRITICAL โœ“ Patch Available

A critical pre-authentication remote code execution vulnerability in Oracle Identity Manager (OIM) and Oracle Web Services Manager (WSM) allows unauthenticated attackers to execute arbitrary code via HTTP by exploiting missing authentication on a critical REST WebServices component. The flaw has a CVSS score of 9.8, requires no credentials or user interaction, and is remotely exploitable with low attack complexity over a network. Oracle released an out-of-band emergency patch in March 2026 โ€” only the second such emergency release Oracle has issued for Identity Manager.

Oracle Identity Manager 12.2.1.4.0 Oracle Identity Manager 14.1.2.1.0 Oracle Web Services Manager 12.2.1.4.0 +1 more
9.8
CVSS

CVE-2026-26210

KTransformers โ€” Unauthenticated RCE via Pickle Deserialization on ZMQ Scheduler Socket

CRITICAL โœ“ Patch Available

CVE-2026-26210 is a critical pre-authentication remote code execution vulnerability in the KTransformers AI inference acceleration framework. The scheduler's ZeroMQ ROUTER socket binds to all network interfaces by default with no authentication, and deserialises incoming messages using Python's pickle.loads() without validation. Any network-reachable attacker can supply a crafted pickle payload to execute arbitrary code as the process owner โ€” typically a privileged GPU server. No exploitation in the wild has been confirmed at time of publication.

KTransformers (all versions prior to patched release)
9.8
CVSS

CVE-2026-26956

vm2 Node.js Sandbox โ€” WebAssembly Exception Handling Escape Allows Host Code Execution

CRITICAL โœ“ Patch Available

A critical sandbox escape vulnerability in vm2 โ€” one of the most widely used Node.js sandbox libraries with approximately 1.3 million weekly npm downloads โ€” allows code executing inside the vm2 sandbox to escape isolation and execute arbitrary code on the host Node.js process. The vulnerability exploits WebAssembly exception handling (the 'exnref' proposal) which was introduced in V8 and bypasses vm2's sandbox enforcement mechanisms. Any application using vm2 to execute untrusted or user-supplied JavaScript is at risk of complete host process compromise. Fixed in vm2 3.9.22.

vm2 prior to 3.9.22
9.8
CVSS

CVE-2026-31414

Linux Kernel Netfilter Conntrack โ€” Privilege Escalation / Denial of Service

CRITICAL โœ“ Patch Available

A vulnerability in the Linux kernel netfilter connection tracking (conntrack) expectations mechanism allows a local attacker with access to netfilter configuration to trigger unsafe memory access, leading to kernel memory corruption, system crashes, or potential privilege escalation. In container environments with user namespaces enabled, the attack surface extends to unprivileged container processes that can configure netfilter rules within their namespace, potentially affecting the host kernel. Affects Linux kernel versions 6.1 through 6.10; patches backported to stable branches. Part of an April 2026 batch addressing multiple netfilter subsystem flaws (CVE-2026-31422, CVE-2026-31416).

Linux kernel 6.1 through 6.10 RHEL/CentOS/Rocky/AlmaLinux 8 and 9 (affected kernel branches) Ubuntu LTS 22.04 (5.15 kernel) and 24.04 (6.8 kernel) +2 more
9.8
CVSS

CVE-2026-3197

Palo Alto PAN-OS GlobalProtect SAML Authentication Bypass

CRITICAL โœ“ Patch Available

A critical authentication bypass in the Palo Alto Networks PAN-OS GlobalProtect SAML authentication handler allows unauthenticated remote attackers to forge a valid SAML assertion and gain full administrative access to the firewall management plane. The vulnerability exploits a signature verification flaw in the XML SAML response parser, enabling an attacker to send a crafted assertion that PAN-OS accepts as legitimate without contacting the configured identity provider. Exploitation grants the attacker the ability to modify firewall policy, create persistent accounts, and extract VPN configuration data. When chained with CVE-2026-3201 (post-authentication command injection), the combined attack achieves unauthenticated root-level OS code execution.

Palo Alto Networks PAN-OS 11.2.x prior to 11.2.4 Palo Alto Networks PAN-OS 11.1.x prior to 11.1.5 Palo Alto Networks PAN-OS 11.0.x prior to 11.0.6 +2 more
9.8
CVSS

CVE-2026-32644

Milesight AIOT Cameras โ€” Hard-Coded Shared SSL Private Key Enables Fleet-Wide Silent MITM

CRITICAL โœ“ Patch Available

All cameras within a Milesight AIOT model family share a single factory-embedded SSL private key that cannot be changed through the management interface. An attacker who extracts this key from any unit โ€” achievable through firmware extraction or from publicly available firmware images โ€” can perform silent man-in-the-middle attacks against all cameras in that model family, intercepting video streams, management credentials, and configuration traffic without triggering any certificate validation failure. Affects 18-plus model families; CISA advisory ICSA-26-113-03.

Milesight MS-C52x4-FPB/FPC firmware < 59.6.0.80 Milesight MS-C59xx-PA/PB firmware < 59.6.0.80 Milesight MS-N72xx NVR firmware < 45.9.0.4 +1 more
9.8
CVSS

CVE-2026-33032

nginx-ui MCP Endpoint Authentication Bypass (MCPwn)

CRITICAL โœ“ Patch Available

A critical authentication bypass in nginx-ui's Model Context Protocol (MCP) endpoint allows unauthenticated remote attackers to invoke all MCP tools including creating, modifying, and deleting Nginx configuration files and restarting the Nginx service. The /mcp_message endpoint applies only IP allowlisting with an empty default whitelist (effectively allow-all), bypassing the application's authentication layer entirely. Exploitation requires two HTTP requests and takes seconds to execute, resulting in full Nginx server takeover.

nginx-ui prior to 2.3.4
9.8
CVSS

CVE-2026-33626

LMDeploy LLM Inference Framework โ€” Unauthenticated Remote Code Execution via Deserialization

CRITICAL โœ“ Patch Available

A deserialization vulnerability in LMDeploy's model loading API allows an unauthenticated remote attacker to execute arbitrary operating system commands as the service account running the inference server. The flaw exists in the absence of input validation during model configuration and adapter ingestion โ€” a crafted payload triggers unsafe deserialization and achieves code execution. Active exploitation was confirmed within 13 hours of public disclosure on April 24 2026.

LMDeploy all versions prior to 0.8.4
9.8
CVSS

CVE-2026-33824

Windows Internet Key Exchange (IKE) โ€” Unauthenticated Remote Code Execution

CRITICAL โœ“ Patch Available

A critical remote code execution vulnerability in the Windows Internet Key Exchange Service Extensions allows an unauthenticated remote attacker to execute arbitrary code without user interaction. The network-accessible attack vector and complete absence of authentication requirements place this among the most severe vulnerabilities in the April 2026 Patch Tuesday release. Systems running Windows with IPsec/IKE services exposed to untrusted networks are at immediate risk.

Windows Server 2025 Windows Server 2022 Windows Server 2019 +3 more
9.8
CVSS

CVE-2026-34197

Apache ActiveMQ Unauthenticated RCE via Jolokia API

CRITICAL โœ“ Patch Available

A critical remote code execution vulnerability in Apache ActiveMQ's Jolokia JMX-over-HTTP bridge allows unauthenticated remote attackers to execute arbitrary OS commands by invoking the addNetworkConnector MBean operation with a crafted URI. The flaw causes the broker to fetch and parse an attacker-controlled XML configuration file, enabling arbitrary Java class instantiation and OS command execution under the service account context. Present since ActiveMQ 5.x, this design weakness was not addressed in the 6.x rewrite and is unauthenticated by default in ActiveMQ 6.0.0โ€“6.1.1. When chained with CVE-2024-32114, the combined exploit achieves full unauthenticated root-level code execution in seconds.

Apache ActiveMQ 6.0.0 โ€“ 6.1.1 (Jolokia unauthenticated by default) Apache ActiveMQ 5.x prior to 5.19.4 (if Jolokia explicitly enabled)
9.8
CVSS

CVE-2026-3854

GitHub Enterprise Server โ€” Unauthenticated RCE via Malicious Git Push (Pre-Auth, Single Request)

CRITICAL โœ“ Patch Available

Pre-authentication remote code execution in GitHub Enterprise Server's Git protocol handler. A crafted pack-file transmitted during a git push triggers a memory corruption condition in the Git protocol parsing layer, achieving code execution in the context of the Git service process before authentication is completed. No credentials required. Affects all supported GHES versions prior to the hotfix releases. Fixed in GHES 3.12.8, 3.13.4, 3.14.2, 3.15.1.

GitHub Enterprise Server 3.12.0โ€“3.12.7 GitHub Enterprise Server 3.13.0โ€“3.13.3 GitHub Enterprise Server 3.14.0โ€“3.14.1 +1 more
9.8
CVSS

CVE-2026-41940

cPanel and WHM โ€” Authentication Bypass in Login Flow (Zero-Day, PoC Public)

CRITICAL โœ“ Patch Available

Authentication logic flaw in the cPanel and WHM web hosting control panel software allowing unauthenticated remote attackers to bypass credential verification and gain full administrative access. Exploited as a zero-day for approximately six days before vendor patched; public proof-of-concept now available. Affects all cPanel/WHM versions from 11.40 onwards. WHM administrative compromise provides root-level server access; cPanel compromise provides full hosting account control. Fixed in cPanel LTS 120.0.24, Stable 122.0.16, Current 124.0.6.

cPanel & WHM 11.40 through 120.0.23 (LTS) cPanel & WHM 11.40 through 122.0.15 (Stable) cPanel & WHM 11.40 through 124.0.5 (Current)
9.8
CVSS

CVE-2026-4670

MOVEit Automation โ€” Critical Pre-Authentication Authentication Bypass

CRITICAL โœ“ Patch Available

A critical authentication bypass vulnerability in Progress MOVEit Automation allows a remote unauthenticated attacker to authenticate as any user without valid credentials, gaining full administrative access to the MOVEit Automation management interface. The vulnerability is pre-authentication and requires no prior account knowledge or network positioning. MOVEit Automation is an enterprise managed file transfer platform used by organisations in financial services, healthcare, and government to automate regulated data transfers. Progress Software released patches on 4 May 2026; MOVEit Cloud customers were patched automatically. This is the fourth critical vulnerability in the MOVEit product family since the mass-exploitation campaign of 2023.

MOVEit Automation 2025.0.x prior to 2025.0.10 MOVEit Automation 2024.0.x prior to 2024.1.9 MOVEit Automation 2023.x and earlier (all versions)
9.4
CVSS

CVE-2024-57728

SimpleHelp Remote Management Tool โ€” Path Traversal Unauthenticated File Read/Write

CRITICAL โœ“ Patch Available

A path traversal vulnerability in the SimpleHelp RMM server enables an unauthenticated remote attacker to read and write arbitrary files on the underlying server filesystem. By crafting requests that escape the intended directory scope, an attacker can exfiltrate configuration files containing credentials, overwrite application files to establish persistent access, or modify server configuration to create new administrative accounts. No authentication is required to exploit this vulnerability.

SimpleHelp Server all versions prior to patched release
9.4
CVSS

CVE-2025-0520

ShowDoc โ€” Unauthenticated Remote Code Execution via Unrestricted File Upload

CRITICAL โœ“ Patch Available

An unauthenticated unrestricted file upload vulnerability (CWE-434) in ShowDoc, a self-hosted IT documentation platform, allows remote attackers to upload arbitrary PHP files through the file attachment endpoint without authentication. Uploaded files are stored in a web-accessible directory and can be executed by requesting them directly, granting the attacker arbitrary code execution under the web server process account. Patched in October 2020 (version 2.8.7), the flaw has been actively exploited since at least April 2026 against the large population of installations that were never upgraded. Over 2,000 internet-exposed instances remain vulnerable.

ShowDoc versions prior to 2.8.7
9.4
CVSS

CVE-2025-20362

Cisco ASA Web Management Interface โ€” Authentication Bypass

CRITICAL โœ“ Patch Available

An authentication bypass vulnerability in the web management interface of Cisco Adaptive Security Appliance (ASA) software allows an unauthenticated remote attacker to authenticate to the administrative interface without valid credentials. The flaw stems from an improper state validation in the session establishment process. Exploitation allows an attacker to access the ASA management plane with administrator privileges, and is used in conjunction with CVE-2025-20333 as part of the FIRESTARTER campaign to deploy a firmware-persistent backdoor.

Cisco ASA Software all versions prior to patched release (Q4 2025) Cisco ASA 5500-X Series firewalls Cisco Firepower 1000, 2100, 4100, and 9300 Series running ASA software
9.4
CVSS

CVE-2026-33634

Aqua Security Trivy โ€” Embedded Malicious Code in Official GitHub Actions and Releases

CRITICAL โœ“ Patch Available

Threat actor TeamPCP compromised the Aqua Security Trivy vulnerability scanner ecosystem on 19 March 2026, force-pushing malicious code to 75 of 77 version tags in the official aquasecurity/trivy-action and all tags in aquasecurity/setup-trivy GitHub Actions repositories. A second attack wave on 22 March replaced DockerHub images. The malicious code embedded in affected versions deployed an infostealer targeting plain-text secrets in CI/CD runner process memory, exfiltrating cloud credentials, API tokens, Kubernetes configurations, and SSH keys. CISA added CVE-2026-33634 to the Known Exploited Vulnerabilities catalogue on 26 March 2026.

aquasecurity/trivy-action GitHub Action (all tags except those predating March 19) aquasecurity/setup-trivy GitHub Action (all tags as of March 19) Aqua Security Trivy v0.69.4 through v0.69.6 (DockerHub images)
9.3
CVSS

CVE-2026-0300

PAN-OS โ€” Unauthenticated RCE via User-ID Authentication Portal Buffer Overflow (Actively Exploited)

CRITICAL โœ“ Patch Available

A critical buffer overflow in Palo Alto Networks PAN-OS User-ID authentication portal allows a remote unauthenticated attacker to execute arbitrary code as root on the management plane. Exploitation began approximately 6 April 2026 โ€” six weeks before public disclosure. CISA added CVE-2026-0300 to the KEV catalogue on 6 May 2026. Post-exploitation activity includes deployment of novel implant toolkits and credential interception on compromised management planes. Espionage-motivated threat actors are targeting government and critical infrastructure organisations.

PAN-OS 9.1.x prior to 9.1.22 PAN-OS 10.1.x prior to 10.1.15 PAN-OS 10.2.x prior to 10.2.14 +2 more
9.3
CVSS

CVE-2026-23760

SmarterMail Authentication Bypass Allowing Admin Account Takeover

CRITICAL โœ“ Patch Available

An authentication bypass vulnerability in SmarterTools SmarterMail email server allows unauthenticated remote attackers to bypass the authentication mechanism and gain administrative access. The flaw was exploited as a zero-day by Storm-1175, a China-linked ransomware affiliate, prior to public disclosure, and was subsequently used to deploy Medusa ransomware. SmarterMail is used by tens of thousands of organisations globally as an on-premises email and collaboration platform.

SmarterMail (versions prior to patched build โ€” see SmarterTools advisory)
9.3
CVSS

CVE-2026-3055

Citrix NetScaler ADC/Gateway Unauthenticated Memory Overread via SAML

CRITICAL โœ“ Patch Available

An insufficient input validation flaw in the SAML Identity Provider endpoint of Citrix NetScaler ADC and NetScaler Gateway allows an unauthenticated remote attacker to trigger an out-of-bounds memory read. The appliance leaks sensitive memory contents โ€” including session tokens and authentication credentials โ€” through the NSC_TASS response cookie when a crafted SAMLRequest omitting the AssertionConsumerServiceURL field is submitted to /saml/login. Only appliances configured as SAML IDPs are affected; default configurations are not vulnerable. CISA added this CVE to the Known Exploited Vulnerabilities catalogue on 30 March 2026 following confirmed in-the-wild exploitation.

Citrix NetScaler ADC and Gateway prior to 14.1-66.59 Citrix NetScaler ADC and Gateway 14.1 prior to 14.1-60.58 Citrix NetScaler ADC and Gateway 13.1 prior to 13.1-62.23 +1 more
9.3
CVSS

CVE-2026-33017

Langflow AI Pipeline Builder โ€” Unauthenticated Remote Code Execution

CRITICAL โœ“ Patch Available

An unauthenticated remote code execution vulnerability in Langflow's public flow build endpoint allows attackers to inject arbitrary Python code into flow node definitions, which Langflow executes server-side without sandboxing. No credentials or user interaction are required. Within 20 hours of public disclosure on 17 March 2026, active exploitation was confirmed with attackers harvesting LLM provider API keys (OpenAI, Anthropic, AWS) from compromised instances. CISA added the vulnerability to its Known Exploited Vulnerabilities catalogue on 26 March 2026.

Langflow all versions through 1.8.1
9.3
CVSS

CVE-2026-39987

Marimo Python Notebook Unauthenticated Terminal RCE via WebSocket

CRITICAL โœ“ Patch Available

A pre-authentication remote code execution vulnerability in Marimo, an open-source Python notebook widely used in data science and AI/ML workflows, allows any network-accessible attacker to obtain a full PTY shell on the server. The /terminal/ws WebSocket endpoint fails to call authenticate() before accepting connections, unlike all other protected endpoints. An attacker connects to the endpoint and is immediately granted interactive OS-level access. Exploitation was observed within 10 hours of public disclosure, with attackers building working exploits directly from the advisory.

Marimo prior to 0.23.0 (all versions up to and including 0.20.4)
9.3
CVSS

CVE-2026-5194

wolfSSL Improper Certificate Signature Validation โ€” TLS Forgery in 5 Billion Devices

CRITICAL โœ“ Patch Available

A critical improper certificate validation vulnerability in wolfSSL allows attackers to present forged X.509 certificates with truncated digests that pass ECDSA, DSA, ML-DSA, Ed25519, and Ed448 signature verification without a legitimate private key. An attacker positioned between a vulnerable device and its server can exploit this to conduct TLS man-in-the-middle attacks, intercepting and modifying supposedly encrypted traffic. wolfSSL is an embedded TLS library present in an estimated 5 billion IoT, industrial, automotive, and network devices. Patched in wolfSSL 5.9.1 released 8 April 2026.

wolfSSL prior to 5.9.1 (all platforms) Embedded devices and firmware using wolfSSL (vendor-specific)
9.3
CVSS

CVE-2026-5752

Cohere Terrarium โ€” JavaScript Prototype Chain Traversal Sandbox Escape to Host Root RCE

CRITICAL โœ“ Patch Available

A critical vulnerability in Cohere Terrarium's JavaScript bridge layer allows an attacker to escape the Pyodide WebAssembly sandbox through JavaScript prototype chain traversal. By constructing a Python object that traverses the prototype chain across the Pyodide serialisation boundary into the host JavaScript context, an attacker can reach the Function constructor and execute arbitrary code as root on the host Node.js process. The vulnerability affects all Terrarium deployments processing externally-controlled or LLM-generated Python code. No public proof-of-concept has been released; Cohere has issued a patched version. The attack requires the ability to influence Python code submitted to Terrarium โ€” achievable through direct API access, indirect prompt injection, or LLM output manipulation.

Cohere Terrarium (all versions prior to patched release, April 2026)
9.1
CVSS

CVE-2025-20333

Cisco Firepower Threat Defence โ€” Management Interface Command Injection RCE

CRITICAL โœ“ Patch Available

A command injection vulnerability in the management interface of Cisco Firepower Threat Defence (FTD) software allows an unauthenticated remote attacker to execute arbitrary OS commands with root privileges on the underlying device. The flaw exists in the input handling of the FTD management plane and requires no authentication to exploit. Successful exploitation provides full device compromise, enabling the FIRESTARTER implant campaign documented in the joint CISA/NCSC advisory published April 2026.

Cisco Firepower Threat Defence (FTD) all versions prior to patched release (Q4 2025) Cisco Secure Firewall appliances running FTD software
9.1
CVSS

CVE-2026-2699

Progress ShareFile Storage Zones Controller Authentication Bypass

CRITICAL โœ“ Patch Available

A critical authentication bypass vulnerability in Progress ShareFile Storage Zones Controller (SZC) arises from improper handling of execution-after-redirect behaviour in the /ConfigService/Admin.aspx administrative endpoint. An unauthenticated remote attacker can exploit the redirect logic to gain access to restricted administrative functions without supplying valid credentials. When chained with CVE-2026-2701 (arbitrary file upload), this vulnerability enables fully unauthenticated remote code execution. Progress released a fix in SZC version 5.12.4 on 10 March 2026; watchTowr Labs published full technical details on 2 April, significantly lowering the exploitation barrier. Approximately 30,000 SZC instances are internet-exposed.

Progress ShareFile Storage Zones Controller 5.12.3 and earlier
9.1
CVSS

CVE-2026-35616

Fortinet FortiClient EMS Pre-Authentication API Bypass and Privilege Escalation

CRITICAL โœ“ Patch Available

A critical improper access control vulnerability (CWE-284) in Fortinet FortiClient Endpoint Management Server allows an unauthenticated remote attacker to bypass API authentication and execute arbitrary code or commands on the server via crafted HTTP requests. Carrying a CVSS score of 9.1, this flaw affects the management plane responsible for deploying and enforcing endpoint security policy, ZTNA, and VPN access controls across managed fleets. Active exploitation was confirmed by multiple researchers beginning 31 March 2026, and CISA added CVE-2026-35616 to its KEV catalogue on 6 April with a federal remediation deadline of 9 April โ€” one of the shortest timelines CISA issues.

Fortinet FortiClient EMS 7.4.5 Fortinet FortiClient EMS 7.4.6
9.1
CVSS

CVE-2026-39808

Fortinet FortiSandbox โ€” Unauthenticated OS Command Injection (Root RCE)

CRITICAL โœ“ Patch Available

An OS command injection vulnerability in Fortinet FortiSandbox's job detail endpoint allows unauthenticated remote attackers to execute arbitrary commands as root via crafted HTTP requests. The endpoint at /fortisandbox/job-detail/tracer-behavior passes user-supplied input to an OS command context without sanitisation. Fortinet silently patched the vulnerability in November 2025 but did not disclose the CVE publicly until April 2026. A public proof-of-concept demonstrating one-command unauthenticated root RCE was released by security researcher Samuel de Lucas in April 2026.

Fortinet FortiSandbox 4.4.0 through 4.4.8
9.1
CVSS

CVE-2026-40372

Microsoft ASP.NET Core โ€” DataProtection Encryption Key Exposure on Linux (Security Regression)

CRITICAL โœ“ Patch Available

A security regression in Microsoft.AspNetCore.DataProtection introduced in .NET 10.0.0 causes the DataProtection key storage provider to write encryption key material to world-readable file system paths or log it to standard output on Linux deployments when no explicit key repository is configured. Applications using cookie authentication, anti-forgery tokens, or TempData โ€” all of which rely on DataProtection โ€” are at risk of session key theft, enabling authentication cookie forgery, CSRF bypass, and decryption of protected payloads. The regression does not affect Windows deployments using DPAPI-backed storage. Microsoft released an out-of-band patch (.NET 10.0.7) on 21โ€“22 April 2026.

Microsoft.AspNetCore.DataProtection 10.0.0 โ€“ 10.0.6 Microsoft .NET 10.0.0 โ€“ 10.0.6 (Linux/macOS deployments)
9.1
CVSS

CVE-2026-40976

Spring Boot 4.0 โ€” Actuator Auth Bypass When spring-boot-health Dependency Absent

CRITICAL โœ“ Patch Available

Spring Boot 4.0.0 through 4.0.5 exposes all Actuator management endpoints without authentication when applications include spring-boot-actuator-autoconfigure but omit the spring-boot-health dependency โ€” a common configuration in applications migrating from Spring Boot 3.x. The security filter chain mapping silently fails to apply, leaving /actuator/heapdump, /actuator/env, /actuator/loggers, and other endpoints accessible to unauthenticated network peers. No error or warning is logged. Patched in Spring Boot 4.0.6.

Spring Boot 4.0.0โ€“4.0.5
9.1
CVSS

CVE-2026-6074

Intrado 911 Emergency Gateway โ€” Unauthenticated Path Traversal Enables Arbitrary File Access

CRITICAL โœ“ Patch Available

CVE-2026-6074 is an unauthenticated path traversal vulnerability in the Intrado 911 Emergency Gateway (EGW) management interface affecting versions 5.x through 7.x. An attacker with network access to the management interface can traverse outside the web root to read, write, or delete arbitrary files on the underlying system โ€” no credentials or prior authentication required. Successful exploitation could allow modification of 911 call routing configuration, deployment of persistent web shells, or disabling of emergency call processing. Intrado patched the vulnerability on March 2 2026 and is directly contacting affected PSAP customers.

Intrado 911 Emergency Gateway (EGW) v5.x Intrado 911 Emergency Gateway (EGW) v6.x Intrado 911 Emergency Gateway (EGW) v7.x
9.0
CVSS

CVE-2026-30893

Wazuh SIEM/XDR Manager โ€” Unauthenticated RCE via Deserialization in Agent Registration API

CRITICAL โœ“ Patch Available

Deserialization vulnerability in the Wazuh manager's agent registration API endpoint (TCP 55000). An attacker who can reach the API port can send a crafted registration request containing a malicious serialised payload that executes arbitrary code in the context of the Wazuh manager process, which typically runs with root or high-privilege service account credentials. No authentication is required. Affects Wazuh 4.0.0 through 4.11.1. Fixed in Wazuh 4.11.2.

Wazuh 4.0.0โ€“4.11.1
~9.0
EST.

CVE-2026-40050

CrowdStrike Falcon LogScale โ€” Server-Side Request Forgery via Authenticated User

CRITICAL โœ“ Patch Available

A server-side request forgery (SSRF) vulnerability in CrowdStrike Falcon LogScale (formerly Humio) allows an authenticated user with any role to cause the LogScale server to issue arbitrary HTTP requests to internal network resources. The vulnerability exists in a data processing component that handles user-supplied URLs without adequate validation. Because LogScale has broad network connectivity to collect log data, this SSRF can be used to reach internal APIs, cloud metadata services, and protected network segments inaccessible from an external position.

CrowdStrike Falcon LogScale (on-premises/self-hosted) all versions prior to April 25 2026 release
9.0
CVSS

CVE-2026-42523

Jenkins GitHub Plugin โ€” Stored XSS via Job URL Processing Enables Session Hijacking

CRITICAL โœ“ Patch Available

Stored cross-site scripting (XSS) in Jenkins GitHub Plugin 1.46.0 and earlier via insufficient escaping of GitHub repository URL values in JavaScript rendered on job configuration and build result pages. An attacker with Item/Configure permission can inject a malicious JavaScript payload via the GitHub URL field; the payload executes in the browser of any Jenkins administrator who views the affected job, providing access to administrator session cookies, CSRF tokens, and the ability to extract pipeline credentials or modify pipeline definitions. Fixed in GitHub Plugin 1.46.1.

Jenkins GitHub Plugin 1.46.0 and earlier
8.8
CVSS

CVE-2025-31277

Apple WebKit Buffer Overflow โ€” DarkSword Exploit Chain Entry Point

HIGH โœ“ Patch Available

A buffer overflow vulnerability in Apple's WebKit browser engine serves as the initial entry point of the DarkSword multi-stage iOS and macOS exploit chain. An attacker can trigger the overflow by delivering a malicious webpage via Safari or any WebKit-based application, achieving initial code execution within the browser process without requiring user interaction beyond page load. This CVE affects iOS, iPadOS, macOS, watchOS, tvOS, and visionOS. CISA added CVE-2025-31277 to the Known Exploited Vulnerabilities catalogue on 20 March 2026, confirming active exploitation as part of the DarkSword framework.

Apple iOS and iPadOS prior to patched versions (2025) Apple macOS prior to patched versions (2025) Apple watchOS prior to patched versions (2025) +2 more
8.8
CVSS

CVE-2026-25177

Active Directory Domain Services Privilege Escalation via SPN/UPN Name Validation Flaw

HIGH โœ“ Patch Available

An elevation-of-privilege vulnerability in Windows Active Directory Domain Services caused by improper restriction and validation of Service Principal Names (SPNs) and User Principal Names (UPNs). A low-privileged authenticated domain user can exploit Unicode normalisation edge cases in name handling to escalate to domain administrator privileges over the network with no user interaction required. Patched in the March 2026 Patch Tuesday (10 March). Added to CISA Known Exploited Vulnerabilities catalogue following confirmed active exploitation approximately three weeks after the patch was released.

Windows Server 2022 Windows Server 2019 Windows Server 2016 +3 more
8.8
CVSS

CVE-2026-2701

Progress ShareFile Storage Zones Controller Arbitrary File Upload to Webroot

HIGH โœ“ Patch Available

An arbitrary file upload vulnerability in Progress ShareFile Storage Zones Controller allows an attacker with administrative session access to upload and extract archive content into the IIS web root, enabling placement of malicious ASPX webshells that execute with the web server's privileges. When chained with the authentication bypass in CVE-2026-2699, this vulnerability can be exploited without any authentication, yielding full remote code execution on the server. The full attack chain was publicly documented by watchTowr Labs on 2 April 2026 following coordinated disclosure, and Progress has issued a fix in version 5.12.4.

Progress ShareFile Storage Zones Controller 5.12.3 and earlier
8.8
CVSS

CVE-2026-3909

Google Chrome Skia Out-of-Bounds Write

HIGH โœ“ Patch Available

An out-of-bounds write vulnerability in Chrome's Skia graphics library allows a remote attacker to achieve arbitrary code execution within the sandboxed renderer process via a crafted web page. The flaw provides a reliable memory corruption primitive that, when chained with a sandbox escape, enables full OS-level code execution. Confirmed exploited in the wild before Google's emergency patch on 13 March 2026.

Google Chrome prior to 146.0.7680.75 (Linux/Mac) Google Chrome prior to 146.0.7680.76 (Windows) Chromium-based browsers (Microsoft Edge, Brave, Opera) โ€” vendor-specific patches required
8.8
CVSS

CVE-2026-3910

Google Chrome V8 Inappropriate Implementation โ€” Sandbox Escape

HIGH โœ“ Patch Available

An inappropriate implementation vulnerability in Chrome's V8 JavaScript engine allows an attacker to escape the renderer sandbox. When chained with CVE-2026-3909 (Skia out-of-bounds write), this forms a complete renderer-to-OS exploitation chain delivering arbitrary code execution on the underlying operating system without additional user interaction. Both vulnerabilities were exploited together in targeted attacks prior to the 13 March 2026 emergency patch.

Google Chrome prior to 146.0.7680.75 (Linux/Mac) Google Chrome prior to 146.0.7680.76 (Windows) Chromium-based browsers (Microsoft Edge, Brave, Opera) โ€” vendor-specific patches required
8.8
CVSS

CVE-2026-40978

Spring AI CosmosDBVectorStore โ€” SQL Injection via Unsanitised Metadata Filter Values

HIGH โœ“ Patch Available

SQL injection in Spring AI's CosmosDBVectorStore component via the SiteList parameter used in vector similarity search queries. The component constructs Azure Cosmos DB SQL queries using string concatenation without parameterisation or sanitisation of metadata filter values from SearchRequest objects. Attackers who control filter parameters โ€” common when filter values derive from user input in RAG pipelines โ€” can read out-of-scope documents or exfiltrate stored embeddings. Patched in Spring AI 1.1.5.

Spring AI 1.0.0โ€“1.0.4 Spring AI 1.1.0โ€“1.1.4
8.8
CVSS

CVE-2026-42208

LiteLLM โ€” SQL Injection Allows AI Provider API Key Theft (CISA KEV)

HIGH โœ“ Patch Available

A SQL injection vulnerability in LiteLLM โ€” an open-source AI gateway proxy used by enterprises to route requests to OpenAI, Anthropic, Azure OpenAI, and other AI providers โ€” allows an attacker to read and modify LiteLLM's backend database. The database contains the API keys LiteLLM holds for connected AI providers, enabling theft of credentials equivalent to prepaid AI compute budgets. LiteLLM request logs may also contain sensitive business context submitted to LLMs by the organisation. CISA added CVE-2026-42208 to the Known Exploited Vulnerabilities catalogue on 7 May 2026 โ€” the first AI infrastructure component to be confirmed exploited and listed in KEV.

LiteLLM prior to version 1.42.2
8.8
CVSS

CVE-2026-4747

FreeBSD NFS Server โ€” Unauthenticated Remote Code Execution in NFSv4 nfsd (17-Year Vulnerability)

HIGH โœ“ Patch Available

An unauthenticated remote code execution vulnerability in FreeBSD's NFS server daemon (nfsd) allows a network-accessible attacker to execute arbitrary code without credentials. The vulnerability originates in the NFSv4 implementation introduced in FreeBSD 8.x and has been present for approximately 17 years. It was discovered by Anthropic's Claude Mythos AI vulnerability research model and disclosed through Project Glasswing in April 2026. FreeBSD NFS is widely deployed in NetApp storage appliances, BSD-based NAS devices, enterprise file servers, and network equipment. A patch is available in FreeBSD security advisories issued following Project Glasswing coordinated disclosure.

FreeBSD 8.0 โ€“ 14.1 (nfsd, NFSv4 server implementation) NetApp appliances and other embedded FreeBSD NFS implementations (vendor patches pending)
8.8
CVSS

CVE-2026-5281

Google Chrome Dawn/WebGPU โ€” Use-After-Free Remote Code Execution

HIGH โœ“ Patch Available

A use-after-free vulnerability in Dawn, Chrome's cross-platform WebGPU implementation, allows a remote attacker to execute arbitrary code in the renderer process via a malicious web page. The flaw is the fourth Chrome zero-day exploited in attacks in 2026, following use-after-free and out-of-bounds write vulnerabilities in CSS, Skia, and V8 earlier in the year. CISA added CVE-2026-5281 to the Known Exploited Vulnerabilities catalogue on 1 April 2026 with a deadline of 15 April for federal agencies.

Google Chrome prior to 146.0.7680.177 (Linux) Google Chrome prior to 146.0.7680.177/178 (Windows, macOS) Chromium-based browsers using affected Dawn versions
8.7
CVSS

CVE-2025-14847

MongoDB Server โ€” Unauthenticated Heap Memory Disclosure (MongoBleed)

HIGH โœ“ Patch Available

An improper handling of length parameter inconsistency in MongoDB Server's zlib compressed protocol headers allows unauthenticated clients to trigger the server to respond with content from uninitialised heap memory. Since zlib compression is enabled by default, any internet-exposed MongoDB instance is potentially vulnerable with no authentication required. Heap memory contents may include fragments of recently processed queries, cached credentials, API keys, session tokens, and application data from collections. Approximately 87,000 internet-exposed MongoDB instances remain vulnerable globally. CISA added CVE-2025-14847 to the Known Exploited Vulnerabilities catalogue on 29 December 2025 with a federal remediation deadline of 19 January 2026.

MongoDB Server prior to 8.2.3 MongoDB Server 8.0.x prior to 8.0.17 MongoDB Server 7.0.x prior to 7.0.28 +3 more
8.6
CVSS

CVE-2025-43510

Apple OS Improper Locking โ€” DarkSword Sandbox Escape Component

HIGH โœ“ Patch Available

An improper locking vulnerability in Apple operating systems allows attackers who have achieved initial code execution via the WebKit entry point (CVE-2025-31277) to escape sandbox confinement and access broader OS capabilities. CVE-2025-43510 is the second stage of the DarkSword exploit chain, enabling the transition from browser-process execution to OS-level access. CISA added this CVE to the Known Exploited Vulnerabilities catalogue on 20 March 2026 as part of the confirmed DarkSword active exploitation advisory.

Apple iOS and iPadOS prior to patched versions (2025) Apple macOS prior to patched versions (2025) Apple watchOS prior to patched versions (2025) +1 more
8.6
CVSS

CVE-2025-43520

Apple OS Kernel Buffer Overflow โ€” DarkSword Full Kernel Compromise Stage

HIGH โœ“ Patch Available

A classic buffer overflow vulnerability in Apple operating system core components is the final stage of the DarkSword exploit chain, enabling attackers to write directly to kernel memory and achieve complete control over the compromised device. CVE-2025-43520 converts the OS-level access obtained via CVE-2025-43510 into full kernel compromise, allowing persistent implant installation, data exfiltration, and surveillance capabilities that survive reboots. CISA added CVE-2025-43520 to the Known Exploited Vulnerabilities catalogue on 20 March 2026.

Apple iOS and iPadOS prior to patched versions (2025) Apple macOS prior to patched versions (2025) Apple watchOS prior to patched versions (2025) +1 more
8.6
CVSS

CVE-2026-1603

Ivanti Endpoint Manager โ€” Unauthenticated Authentication Bypass and Credential Vault Access

HIGH โœ“ Patch Available

An authentication bypass vulnerability in Ivanti Endpoint Manager (EPM) prior to version 2024 SU5 allows unauthenticated remote attackers to bypass login controls entirely by submitting a crafted HTTP request containing a specific magic number value. Successful exploitation grants direct access to the EPM Credential Vault, exposing Domain Administrator NTLM password hashes and service account credentials stored within the management system. CISA added CVE-2026-1603 to the Known Exploited Vulnerabilities catalogue on 9 March 2026 with a federal agency remediation deadline of 23 March 2026.

Ivanti Endpoint Manager (EPM) all versions prior to 2024 SU5
8.6
CVSS

CVE-2026-34621

Adobe Acrobat Reader โ€” Prototype Pollution RCE via Crafted PDF

HIGH โœ“ Patch Available

A prototype pollution vulnerability in Adobe Acrobat Reader allows arbitrary code execution when a user opens a specially crafted PDF file. The embedded JavaScript exploit executes automatically upon opening โ€” no macros or additional interaction required. Exploitation since at least November 2025 followed a staged C2-driven model: the PDF contacts an attacker server, which fingerprints the victim's environment and delivers tailored RCE and sandbox escape payloads to selected targets. This staging made the malicious PDFs appear benign in automated analysis. CISA added CVE-2026-34621 to the KEV catalogue on 13 April 2026. Patched in Adobe Security Bulletin APSB26-43 released 13 April 2026.

Adobe Acrobat DC and Acrobat Reader DC prior to v26.001.21411 (Windows, macOS) Adobe Acrobat 2024 prior to v24.001.30362 (Windows) Adobe Acrobat 2024 prior to v24.001.30360 (macOS)
8.6
CVSS

CVE-2026-39813

Fortinet FortiSandbox โ€” JRPC API Authentication Bypass via Path Traversal

HIGH โœ“ Patch Available

A path traversal vulnerability in Fortinet FortiSandbox's JRPC (JSON Remote Procedure Call) API allows unauthenticated remote attackers to bypass authentication controls and invoke privileged API functions without valid credentials. The flaw enables administrative access to sandboxing configuration, policy settings, and verdict data without authentication. Disclosed as part of Fortinet's April 2026 advisory cycle alongside CVE-2026-39808.

Fortinet FortiSandbox 4.4.0 through 4.4.8 Fortinet FortiSandbox 5.0.0 through 5.0.5
8.6
CVSS

CVE-2026-40967

Spring AI FilterExpressionConverter โ€” Filter Expression Injection Across Multiple Vector Store Backends

HIGH โœ“ Patch Available

Filter expression injection in Spring AI's FilterExpressionConverter, the shared filter translation layer used by Pinecone, Weaviate, Qdrant, Milvus, and CosmosDB vector store backends. String values containing quote characters and boolean operators are not escaped before being embedded in backend query strings, allowing attackers to inject arbitrary filter logic. In RAG applications, this can bypass document-level access controls implemented through metadata filters. Patched in Spring AI 1.1.5.

Spring AI 1.0.0โ€“1.0.4 Spring AI 1.1.0โ€“1.1.4
8.4
CVSS

CVE-2026-3201

Palo Alto PAN-OS Management Interface Command Injection

HIGH โœ“ Patch Available

A command injection vulnerability in the Palo Alto Networks PAN-OS management interface allows an authenticated administrator to execute arbitrary OS commands with root privileges. While requiring authentication in isolation, CVE-2026-3201 is being actively chained with CVE-2026-3197 (SAML authentication bypass) to produce an unauthenticated root-level remote code execution attack against internet-exposed GlobalProtect portals. The combined exploit has been confirmed in Unit 42 incident response engagements and proof-of-concept code is publicly available.

Palo Alto Networks PAN-OS 11.2.x prior to 11.2.4 Palo Alto Networks PAN-OS 11.1.x prior to 11.1.5 Palo Alto Networks PAN-OS 11.0.x prior to 11.0.6 +2 more
8.2
CVSS

CVE-2023-27351

PaperCut NG/MF โ€” Unauthenticated Information Disclosure and Authentication Bypass

HIGH โœ“ Patch Available

An improper authentication vulnerability in PaperCut NG and MF allows unauthenticated remote attackers to access protected functionality and extract user account information including usernames, email addresses, department information, and hashed passwords from internal user accounts. Patched in 2023 but added to CISA KEV on 20 April 2026, confirming ongoing exploitation of unpatched PaperCut deployments across enterprise and education environments.

PaperCut MF prior to 20.1.7, 21.2.11, and 22.0.9 PaperCut NG prior to 20.1.7, 21.2.11, and 22.0.9
8.1
CVSS

CVE-2026-22719

VMware Aria Operations โ€” Unauthenticated Command Injection

HIGH โœ“ Patch Available

A command injection vulnerability in VMware Aria Operations (formerly vRealize Operations) allows unauthenticated remote attackers to execute arbitrary operating system commands on the management appliance when support-assisted product migration is in use. The vulnerability was patched by Broadcom on 24 February 2026 as part of advisory VMSA-2026-0001. CISA added CVE-2026-22719 to the Known Exploited Vulnerabilities catalogue with a federal agency remediation deadline of 24 March 2026, confirming active exploitation.

VMware Aria Operations versions prior to those in VMSA-2026-0001
8.1
CVSS

CVE-2026-33827

Windows TCP/IP Race Condition โ€” Wormable Unauthenticated RCE via IPv6/IPSec

HIGH โœ“ Patch Available

A race condition in the Windows TCP/IP network driver allows an unauthenticated, network-adjacent attacker to achieve remote code execution without user interaction on systems with IPv6 or IPSec enabled. The vulnerability was demonstrated at Pwn2Own 2026 prior to the April Patch Tuesday release. Its wormable characteristics โ€” autonomous spread from host to host without attacker involvement โ€” place it in the same risk category as the EternalBlue class of vulnerabilities. IPv6 is enabled by default on all modern Windows installations, making the attack surface universal across unpatched Windows environments.

Windows 10 (all versions) Windows 11 (all versions) Windows Server 2016 +3 more
8.1
CVSS

CVE-2026-35414

OpenSSH โ€” Certificate Authentication Bypass via Malformed SAN Field ('SplitSSHell')

HIGH โœ“ Patch Available

A certificate authentication bypass vulnerability in OpenSSH, nicknamed SplitSSHell, allows an attacker to authenticate to an SSH server configured for certificate-based authentication by presenting a specially crafted certificate with a comma character in the Subject Alternative Name field. The comma is misinterpreted as a field separator, causing OpenSSH's certificate validation logic to incorrectly evaluate the principal validation check. Environments relying on SSH certificates for zero-trust access โ€” including HashiCorp Vault SSH, Teleport, and similar certificate-issuing infrastructure โ€” are at elevated risk. Fixed in OpenSSH 9.9p1.

OpenSSH prior to 9.9p1
8.0
CVSS

CVE-2026-33826

Windows Active Directory RCE via Crafted RPC Calls

HIGH โœ“ Patch Available

An improper input validation vulnerability (CWE-20) in the Windows Active Directory RPC interface allows an authenticated attacker within the same AD domain to execute arbitrary code on domain controllers and member servers by sending specially crafted RPC calls. The attacker must hold a valid domain user account but requires no administrative privileges; successful exploitation achieves code execution with the permissions of the RPC host service. Microsoft rates exploitation as 'More Likely' and patched the vulnerability in the April 2026 Patch Tuesday release on 14 April 2026.

Microsoft Windows Server 2012 R2 Microsoft Windows Server 2016 Microsoft Windows Server 2019 +3 more
7.8
CVSS

CVE-2022-20775

Cisco SD-WAN CLI Path Traversal Privilege Escalation to Root

HIGH โœ“ Patch Available

A path traversal vulnerability in the Cisco SD-WAN Software CLI allows an authenticated local attacker to gain elevated privileges and execute arbitrary commands as root. Though first disclosed in 2022, this vulnerability has been actively weaponised since early 2026 as the second stage of an attack chain paired with CVE-2026-20127. Threat actors obtain unauthenticated remote access via CVE-2026-20127, then deliberately downgrade the SD-WAN Controller to a version where CVE-2022-20775 remains present, escalate to root, and restore the original software version to conceal the downgrade. CISA includes this vulnerability in Emergency Directive 26-03.

Cisco SD-WAN Software (vSmart, vBond, vManage, vEdge) unpatched versions Cisco Catalyst SD-WAN Controller versions vulnerable to software downgrade
7.8
CVSS

CVE-2025-60710

Windows Host Process for Tasks Privilege Escalation to SYSTEM

HIGH โœ“ Patch Available

A link-following vulnerability (CWE-59) in the Windows Host Process for Tasks allows a local attacker with standard user privileges to substitute a symbolic link or junction at a path used by the Task Host service during a privileged file operation. Because the Task Host service operates under the SYSTEM account, successful exploitation grants the attacker complete SYSTEM-level control of the compromised device. Patched in November 2025; CISA confirmed active exploitation and added CVE-2025-60710 to the Known Exploited Vulnerabilities catalogue on 13 April 2026. Four public proof-of-concept exploits are available on GitHub.

Windows 11 24H2 Windows 11 25H2 Windows Server 2025
7.8
CVSS

CVE-2026-21385

Qualcomm Snapdragon Firmware Integer Overflow โ€” Targeted Mobile Exploitation

HIGH โœ“ Patch Available

An integer overflow (CWE-190) in Qualcomm chipset firmware allows an attacker with local access to achieve memory corruption and potentially arbitrary code execution within the firmware subsystem context. Qualcomm confirmed limited, targeted exploitation consistent with commercial spyware or nation-state intelligence collection operations. Addressed in Google's March 2026 Android Security Bulletin (patch level 2026-03-05).

Android devices with Qualcomm Snapdragon chipsets โ€” patch level prior to 2026-03-05 Samsung Galaxy series (Snapdragon variants) OnePlus, Motorola, Xiaomi, and other Qualcomm-based Android manufacturers
7.8
CVSS

CVE-2026-23856

Dell iDRAC Service Module Privilege Escalation via Improper Access Control

HIGH โœ“ Patch Available

A privilege escalation vulnerability in the Dell iDRAC Service Module (iSM), the OS-level software agent that bridges server operating systems with the iDRAC out-of-band management controller on PowerEdge servers. The flaw arises from improper access control (CWE-284) in iSM's exposed interfaces. A local user with standard OS privileges can exploit the vulnerability to escalate to SYSTEM or root, as iSM operates with elevated privileges required for hardware management communication. Affects Windows iSM versions prior to 6.0.3.1 and Linux iSM versions prior to 5.4.1.1.

Dell iDRAC Service Module (iSM) for Windows prior to 6.0.3.1 Dell iDRAC Service Module (iSM) for Linux prior to 5.4.1.1 All Dell PowerEdge servers with iSM installed
7.8
CVSS

CVE-2026-26117

Azure Arc Connected Machine Agent โ€” Local Privilege Escalation to SYSTEM and Managed Identity Token Theft

HIGH โœ“ Patch Available

CVE-2026-26117 is a race condition in the Azure Arc Connected Machine Agent for Windows that allows an unprivileged domain user to obtain a handle to an internal named pipe before access controls are applied during service startup or metadata refresh. Through this handle, the attacker can request the machine's Azure managed identity access token, which can then be used to authenticate to Azure resources the machine identity has been granted access to โ€” potentially including Key Vaults, storage accounts, and Azure RBAC-controlled APIs.

Azure Arc Connected Machine Agent for Windows < version 1.39
7.8
CVSS

CVE-2026-29642

Huawei VRP OS Local Privilege Escalation via CLI Command Injection

HIGH โœ“ Patch Available

A privilege escalation vulnerability in Huawei's Versatile Routing Platform (VRP) operating system allows an authenticated local attacker with operator-level access to execute arbitrary commands as a higher-privileged system process via CLI input validation bypass. Affected platforms include Huawei enterprise switches and routers running VRP V200R021 through V200R025. An attacker with network device operator credentials can escalate to full administrative control of the device, enabling configuration tampering, credential extraction, or persistent backdoor installation.

Huawei VRP V200R021 (multiple product lines) Huawei VRP V200R022 (multiple product lines) Huawei VRP V200R023 (multiple product lines) +4 more
~7.8
EST.

CVE-2026-31394

Linux Kernel AP VLAN Driver Privilege Escalation via Network Namespace Boundary Condition

HIGH โœ“ Patch Available

A privilege escalation vulnerability in the Linux kernel's AP VLAN (access point virtual LAN) network driver. A local user with access to a network namespace can exploit a boundary condition in the AP VLAN driver to escalate privileges to the host kernel context. Particularly significant in containerised and virtualised environments where container processes have network namespace access by default, creating a container escape path. Affects multiple kernel release lines across Red Hat Enterprise Linux, Ubuntu, Debian, and SUSE distributions.

Linux kernel (multiple release lines prior to patch โ€” see distribution advisories) Red Hat Enterprise Linux 8 and 9 Ubuntu 22.04 LTS and 24.04 LTS +2 more
~7.8
EST.

CVE-2026-31429

Linux Kernel SKB Memory Management Use-After-Free in Network Stack

HIGH โœ“ Patch Available

A use-after-free vulnerability in the Linux kernel network stack's socket buffer (SKB) memory management subsystem allows an unprivileged local attacker to escalate privileges to root. The flaw arises from improper reference counting in the SKB clone operation path under concurrent network I/O conditions, resulting in a freed memory region being accessible to attacker-controlled data. Successful exploitation requires local code execution on an affected system. Affects Linux kernel versions 5.15 through 6.12-rc; a patch has been merged into kernel mainline.

Linux kernel 5.15.x Linux kernel 6.1.x (LTS) Linux kernel 6.6.x (LTS) +6 more
7.8
CVSS

CVE-2026-31431

Linux Kernel โ€” Copy-on-Write Race Condition Local Privilege Escalation (CopyFail)

HIGH โœ“ Patch Available

A race condition in the Linux kernel's copy-on-write (CoW) page fault handling path allows an unprivileged local user to obtain a writable reference to a page marked read-only, enabling overwrite of kernel memory structures and privilege escalation to root. Affects kernel versions 4.15 through the unfixed 6.18 and 6.19 series. All major Linux distributions have issued patched kernel updates. CISA added this vulnerability to the Known Exploited Vulnerabilities catalogue on 1 May 2026 following confirmation of active exploitation in post-initial-access privilege escalation chains.

Linux Kernel 4.15 through 6.18.21 Linux Kernel 6.19 through 6.19.11 RHEL 8 / CentOS Stream 8 (fixed in RHSA-2026:2341) +4 more
7.8
CVSS

CVE-2026-33694

Tenable Nessus Agent โ€” Local Privilege Escalation to Service Account

HIGH โœ“ Patch Available

A privilege escalation vulnerability in the Tenable Nessus Agent component allows a locally authenticated user to elevate their privileges to the account under which the Nessus service runs. The flaw exists in the agent's inter-process communication handling, which fails to enforce adequate access controls on local service operations. In enterprise deployments where the Nessus service account holds elevated domain or local administrator privileges for scanning purposes, this vulnerability enables an attacker with local access to escalate to those privileged credentials.

Tenable Nessus all versions prior to patched release (April 2026) Tenable Nessus Agent all versions prior to patched release (April 2026)
7.8
CVSS

CVE-2026-33825

Windows Defender TOCTOU Privilege Escalation (BlueHammer)

HIGH โœ“ Patch Available

A local privilege escalation vulnerability in the Windows Defender antimalware signature-update mechanism allows any authenticated local user to gain SYSTEM-level code execution. The flaw combines a time-of-check to time-of-use (TOCTOU) race condition with a path-confusion issue in the Defender update staging path, enabling an attacker to substitute a temporary update file with a malicious DLL loaded under the SYSTEM-privileged Defender service context. A working public exploit was available and active exploitation was observed in post-compromise scenarios preceding ransomware deployment. Patched in Microsoft's April 2026 Patch Tuesday.

Microsoft Windows 10 (all supported editions) Microsoft Windows 11 (all editions) Microsoft Windows Server 2016, 2019, 2022
7.8
CVSS

CVE-2026-42482

Hashcat โ€” Heap Buffer Overflow in Binary Hash File Parser

HIGH โœ“ Patch Available

A heap buffer overflow vulnerability in Hashcat's binary hash file parser allows a specially crafted hash input file or .hcmask wordlist to trigger an out-of-bounds write to heap memory, potentially enabling code execution in the context of the Hashcat process. The vulnerability affects all Hashcat versions prior to 7.2.0 and is triggered at parse time without requiring the cracking session to complete. Fixed in Hashcat 7.2.0.

Hashcat prior to 7.2.0
7.8
CVSS

CVE-2026-42483

Hashcat โ€” Stack Buffer Overflow in Rule Engine Parser

HIGH โœ“ Patch Available

A stack buffer overflow in Hashcat's rule engine parser is triggered by rule files containing specially crafted function chain sequences. The overflow allows an attacker who can supply a malicious rule file to a Hashcat instance to potentially achieve code execution in the Hashcat process context. Affects all versions prior to 7.2.0. Fixed in Hashcat 7.2.0.

Hashcat prior to 7.2.0
7.8
CVSS

CVE-2026-5656

Wireshark โ€” Heap Buffer Overflow in PCAP/PCAPNG Parser Leads to Code Execution

HIGH โœ“ Patch Available

A heap buffer overflow in Wireshark's PCAP and PCAPNG file parser can be triggered by a specially crafted capture file, leading to arbitrary code execution on the analyst's workstation. The vulnerability resides in the per-packet dissector state processing during file load. Affects all Wireshark versions prior to 4.4.6 on Windows, macOS, and Linux; TShark is equally affected. Fixed in Wireshark 4.4.6.

Wireshark prior to 4.4.6 (Windows, macOS, Linux) TShark prior to 4.4.6
7.7
CVSS

CVE-2026-22558

Ubiquiti UniFi Network Application โ€” NoSQL Injection Privilege Escalation

HIGH โœ“ Patch Available

A NoSQL injection vulnerability in the Ubiquiti UniFi Network Application allows authenticated attackers to escalate their privileges to administrative level within the controller. While requiring authentication, this vulnerability is primarily exploited as the second step in a two-stage attack chain with CVE-2026-22557: the unauthenticated path traversal flaw provides initial access, and this injection flaw converts that access to full administrator rights. Both vulnerabilities were disclosed together in Ubiquiti's security advisory on 18 March 2026.

Ubiquiti UniFi Network Application prior to 10.1.89 (stable) Ubiquiti UniFi Network Application prior to 10.2.97 (release candidate) Ubiquiti UniFi Express firmware prior to 4.0.13
7.7
CVSS

CVE-2026-4368

Citrix NetScaler Gateway Race Condition on Gateway/AAA Virtual Server

HIGH โœ“ Patch Available

A race condition vulnerability in Citrix NetScaler ADC and NetScaler Gateway affects appliances configured as a gateway (ICA Proxy, RDP Proxy, SSL VPN, or CVPN) or as an AAA virtual server. The flaw is present in version 14.1-66.54 specifically. No exploitation in the wild has been confirmed at time of disclosure; the vulnerability was patched in the same advisory release as CVE-2026-3055.

Citrix NetScaler ADC and Gateway 14.1-66.54
7.5
CVSS

CVE-2026-20128

Cisco Catalyst SD-WAN Manager โ€” DCA Credential Exposure and Privilege Escalation

HIGH โœ“ Patch Available

A credential storage flaw in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager allows a sufficiently positioned attacker to retrieve DCA credential files stored on disk and use them to authenticate within the SD-WAN management environment. Confirmed exploited in the wild by Cisco PSIRT in March 2026 and added to CISA KEV on 20 April 2026.

Cisco Catalyst SD-WAN Manager (affected versions per Cisco advisory)
7.5
CVSS

CVE-2026-20133

Cisco Catalyst SD-WAN Manager โ€” Unauthenticated Sensitive File Read via vshell API

HIGH โœ“ Patch Available

Insufficient filesystem restrictions in the vshell subsystem of Cisco Catalyst SD-WAN Manager (formerly vManage) allow unauthenticated remote attackers to read sensitive files from the SD-WAN Manager host OS, including configuration files, authentication tokens, and WAN edge certificate material. Added to CISA Known Exploited Vulnerabilities catalogue April 2026; FCEB remediation deadline May 12, 2026. Fixed in SD-WAN Manager 20.15.1.

Cisco Catalyst SD-WAN Manager (vManage) < 20.15.1 Cisco SD-WAN Manager 20.12.x (without specific SMU patch) Cisco SD-WAN Manager 20.13.x (without specific SMU patch)
7.5
CVSS

CVE-2026-23231

Linux Kernel nf_tables Use-After-Free โ€” Local Privilege Escalation

HIGH โœ“ Patch Available

A use-after-free vulnerability in the Linux kernel's nf_tables netfilter subsystem arises from improper synchronisation in the nft_chain_release_hook() function during concurrent chain deletion and packet traversal. An unprivileged local attacker who can create network namespaces can exploit the race condition to corrupt kernel memory and escalate to root. A public proof-of-concept targeting Ubuntu 24.04 LTS has been published alongside the CVE disclosure.

Linux kernel 5.14 through 6.9.26 RHEL / AlmaLinux / Rocky Linux 9 (kernel-5.14.0 < 5.14.0-570.el9) Ubuntu 24.04 LTS (linux-image < 6.8.0-61) +3 more
7.5
CVSS

CVE-2026-24297

Windows Kerberos Security Feature Bypass via Race Condition

HIGH โœ“ Patch Available

A security feature bypass vulnerability in the Windows Kerberos authentication implementation caused by a race condition in concurrent request processing. An unauthenticated remote attacker with network access to a Kerberos-speaking service can exploit the race condition to bypass security validation checks in the authentication flow. Requires no user interaction. Patched in the March 2026 Patch Tuesday. No active exploitation confirmed at time of disclosure.

Windows Server 2022 Windows Server 2019 Windows Server 2016 +3 more
7.5
CVSS

CVE-2026-35385

OpenSSH SCP Setuid/Setgid Bit Preservation Privilege Escalation

HIGH โœ“ Patch Available

In OpenSSH before 10.3, files downloaded via scp in legacy mode (-O flag) as root without the -p (preserve modes) flag may retain setuid or setgid permission bits from the remote source. If an attacker controls the remote server, they can upload a crafted file with setuid bits set; when an administrator downloads and another user executes it, arbitrary privilege escalation becomes possible. The flaw is fixed in OpenSSH 10.3.

OpenSSH prior to 10.3 (all platforms)
7.5
CVSS

CVE-2026-41604

Apache Thrift โ€” Out-of-Bounds Read in Binary Protocol Parser (All Language Bindings)

HIGH โœ“ Patch Available

Out-of-bounds read in the Apache Thrift binary protocol parser when processing a container field with a size value exceeding available buffer bytes. Affects all language bindings. C++ and native bindings may expose adjacent heap memory or crash; JVM-based bindings throw an exception causing service DoS; Go returns an error without crashing. Any client that can send Thrift requests to the service can trigger this flaw. Patched in Apache Thrift 0.23.0.

Apache Thrift < 0.23.0 (all language bindings)
7.3
CVSS

CVE-2024-27199

JetBrains TeamCity โ€” Unauthenticated Path Traversal Enabling Certificate Replacement and Limited Data Access

HIGH โœ“ Patch Available

A path traversal vulnerability (CWE-22) in JetBrains TeamCity's web component allows unauthenticated attackers to bypass authentication by using path segments containing '../' to reach protected endpoints. Exploitation allows limited information disclosure and limited system modification, including replacement of the HTTPS certificate served by the TeamCity instance with an attacker-supplied certificate. When chained with CVE-2024-27198 (CVSS 9.8), full authentication bypass and administrative access can be achieved. Added to CISA KEV on 20 April 2026.

JetBrains TeamCity prior to 2023.11.4
7.3
CVSS

CVE-2026-41636

Apache Thrift Node.js Library โ€” Uncontrolled Recursion DoS via Deeply Nested Structures

HIGH โœ“ Patch Available

Uncontrolled recursion in the Apache Thrift JavaScript/Node.js library's deserialisation path for nested Thrift structures. No depth limit is enforced on recursive calls processing nested structs or container types. A remote attacker can send a crafted request with approximately 8,000โ€“12,000 levels of nesting to exhaust the V8 call stack, causing an unhandled RangeError that terminates the process. Affects all Apache Thrift versions prior to 0.23.0. Patched in 0.23.0 with a configurable recursion depth limit defaulting to 64 levels.

Apache Thrift Node.js library < 0.23.0
7.2
CVSS

CVE-2026-42484

Hashcat โ€” Integer Overflow in Potfile Parser Leading to Heap Overflow

HIGH โœ“ Patch Available

An integer overflow in Hashcat's potfile (.pot) parser can lead to a heap buffer overflow when processing large potfile entries from untrusted sources. The vulnerability is triggered when Hashcat loads a potfile containing entries crafted to exceed expected size boundaries, causing heap memory corruption. Affects all versions prior to 7.2.0. Fixed in Hashcat 7.2.0.

Hashcat prior to 7.2.0
7.2
CVSS

CVE-2026-6973

Ivanti Endpoint Manager Mobile (EPMM) โ€” Authenticated RCE via Management Console (CISA KEV)

HIGH โœ“ Patch Available

A remote code execution vulnerability in Ivanti Endpoint Manager Mobile (EPMM) allows an attacker with administrator-level access to the management console to execute arbitrary commands on the underlying server. EPMM manages the enrolled mobile device fleet for an organisation โ€” a compromised server provides access to the configuration, certificates, and management functions for all enrolled devices. CISA added CVE-2026-6973 to the Known Exploited Vulnerabilities catalogue on 7 May 2026. Ivanti EPMM has been targeted repeatedly by nation-state actors since 2023, including the Norwegian government breach and three subsequent campaigns.

Ivanti Endpoint Manager Mobile (EPMM) prior to 12.6.1.1 Ivanti Endpoint Manager Mobile (EPMM) prior to 12.7.0.1 Ivanti Endpoint Manager Mobile (EPMM) prior to 12.8.0.1
7.1
CVSS

CVE-2026-20122

Cisco Catalyst SD-WAN Manager โ€” Arbitrary File Overwrite Granting vManage Privileges

HIGH โœ“ Patch Available

An authenticated remote attacker can exploit incorrect use of privileged APIs in Cisco Catalyst SD-WAN Manager to upload a malicious file and overwrite arbitrary files on the local filesystem, resulting in vManage user privilege acquisition. vManage access provides control over the entire SD-WAN orchestration plane. Confirmed exploited in the wild by Cisco PSIRT in March 2026 and added to CISA KEV on 20 April 2026.

Cisco Catalyst SD-WAN Manager (affected versions per Cisco advisory)
7.1
CVSS

CVE-2026-34256

SAP NetWeaver ABAP Server โ€” Authenticated Code-Overwrite Enables ERP Business Logic Sabotage

HIGH โœ“ Patch Available

CVE-2026-34256 is an authorisation bypass in SAP NetWeaver ABAP Server's Workbench object transport handling that allows an authenticated user with standard developer authorisations to overwrite compiled ABAP load objects in production systems, bypassing the transport system's write-lock. The vulnerability requires authentication but no special administrative role, enabling an attacker with inadvertently assigned developer authorisation objects to modify payroll, financial reporting, or procurement ABAP programmes.

SAP NetWeaver ABAP Server and ABAP Platform (all releases through Q1 2026 support patch) SAP S/4HANA (all releases through Q1 2026) SAP BW/4HANA (all releases through Q1 2026)
6.5
CVSS

CVE-2026-32201

Microsoft SharePoint Server โ€” Spoofing / Information Disclosure (Actively Exploited Zero-Day)

MEDIUM โœ“ Patch Available

A spoofing vulnerability in Microsoft SharePoint Server allows an authenticated attacker to view sensitive information beyond their authorised scope and make unauthorised modifications to disclosed content, bypassing SharePoint's information barrier and permission controls. The vulnerability was under active exploitation before a patch was available; CISA added it to the Known Exploited Vulnerabilities catalogue on 14 April 2026, the day before Microsoft released the patch in April 2026 Patch Tuesday. The one-day gap between KEV addition and patch release required organisations to make explicit risk acceptance or compensating control decisions.

Microsoft SharePoint Server 2019 Microsoft SharePoint Server Subscription Edition Microsoft SharePoint Foundation 2013 SP1

Note: CVE data is curated manually from NVD, vendor advisories, and security research. CVSS scores reflect NVD base scores at time of entry. Always verify with official vendor advisories before actioning.