Skip to content

// CVE Tracker

152 active CVEs โ€” page 2 of 7, sorted unpatched-first by CVSS

85

CRITICAL

66

HIGH

152

TOTAL ACTIVE

146

PATCHED

CVSS Scale: 9.0โ€“10.0 CRITICAL ยท 7.0โ€“8.9 HIGH ยท 4.0โ€“6.9 MEDIUM ยท 0.1โ€“3.9 LOW
9.9
CVSS

CVE-2026-21515

Azure IoT Central โ€” Privilege Escalation via Sensitive Data Exposure

CRITICAL โœ“ Patch Available

CVE-2026-21515 is a near-maximum severity privilege escalation vulnerability in Azure IoT Central. A low-privilege authenticated attacker can access sensitive platform configuration data โ€” including device provisioning credentials and shared access signatures โ€” that should be restricted to administrative accounts, then leverage that data to escalate to full tenant administrative control. Microsoft patched the vulnerability in the April 2026 Patch Tuesday release.

Azure IoT Central (cloud-managed; patched April 2026 Patch Tuesday)
9.9
CVSS

CVE-2026-27681

SAP Business Planning and Consolidation SQL Injection โ€” Authenticated Low-Privilege RCE on ERP Database

CRITICAL โœ“ Patch Available

A SQL injection vulnerability in SAP Business Planning and Consolidation (BPC) and SAP BW/4HANA allows an authenticated user with low-privilege access to execute arbitrary SQL against the underlying database. Exploiting the flaw gives the attacker full read and write access to financial planning data, consolidated accounts, and audit records stored in the ERP database tier. The vulnerability was patched in SAP's April 2026 Security Patch Day. SAP BPC and BW/4HANA are deployed in large enterprise environments for financial close processes, regulatory reporting, and management consolidation โ€” making the database tier a high-value target for financial fraud, data manipulation, and ransomware operators seeking maximum leverage.

SAP Business Planning and Consolidation (BPC) โ€” all versions prior to April 2026 patch SAP BW/4HANA โ€” all versions prior to April 2026 patch
9.9
CVSS

CVE-2026-44748

SAP NetWeaver ABAP SAML Authentication Bypass (CVSS 9.9)

CRITICAL โœ“ Patch Available

A validation failure in SAP NetWeaver Application Server ABAP's SAML 2.0 assertion processing allows unauthenticated remote attackers to forge SAML assertions and impersonate any user including system administrators without valid credentials. Affects all SAP NetWeaver ABAP systems with SAML authentication enabled. Patched by SAP Security Note 3578412 in the June 2026 Security Patch Day.

SAP NetWeaver Application Server ABAP (all versions with SAML 2.0 enabled)
9.8
CVSS

CVE-2024-57726

SimpleHelp Remote Management Tool โ€” Missing Authorisation Unauthenticated Admin Access

CRITICAL โœ“ Patch Available

A missing authorisation check in the SimpleHelp remote management and monitoring (RMM) server allows an unauthenticated remote attacker to enumerate user accounts, extract active session tokens, and escalate to full administrator access without credentials. The vulnerability exists in the server's API layer where administrative endpoints fail to validate caller authentication. Exploitation enables complete takeover of the SimpleHelp server and authenticated access to all managed endpoints connected to it.

SimpleHelp Server all versions prior to patched release
9.8
CVSS

CVE-2024-7399

Samsung MagicINFO Digital Signage Server โ€” Authenticated Remote Code Execution via Arbitrary File Upload

CRITICAL โœ“ Patch Available

An arbitrary file upload vulnerability in Samsung MagicINFO, the content and device management server for Samsung commercial displays and digital signage, allows an authenticated attacker with any user-level account to upload and execute arbitrary files on the server. The flaw exists in the content management component's lack of upload type validation. Successful exploitation provides full server compromise with code execution in the context of the MagicINFO service.

Samsung MagicINFO 9 Server all versions prior to patched release Samsung MagicINFO 8 Server
9.8
CVSS

CVE-2025-53521

F5 BIG-IP APM Remote Code Execution via apmd Process

CRITICAL โœ“ Patch Available

A remote code execution vulnerability in F5 BIG-IP Access Policy Manager (APM) affecting the apmd process. Initially disclosed in October 2025 as a denial-of-service flaw, F5 reclassified the vulnerability in March 2026 after new exploitation information emerged. An unauthenticated remote attacker can exploit the flaw to achieve code execution on the BIG-IP appliance. CISA confirmed active exploitation and added CVE-2025-53521 to its Known Exploited Vulnerabilities catalogue on 27 March 2026, issuing a three-day patch mandate to federal agencies.

F5 BIG-IP APM 17.5.0 โ€“ 17.5.1 F5 BIG-IP APM 17.1.0 โ€“ 17.1.2 F5 BIG-IP APM 16.1.0 โ€“ 16.1.6 +1 more
9.8
CVSS

CVE-2026-1281

Ivanti EPMM Apache URL Rewriting Code Injection โ€” Unauthenticated RCE

CRITICAL โœ“ Patch Available

A code injection vulnerability in legacy bash scripts used by Ivanti EPMM's Apache web server for URL rewriting allows unauthenticated remote attackers to execute arbitrary commands. This is the primary initial-access vector in the Ivanti EPMM exploit chain, typically followed by CVE-2026-1340 for further capability extension. CISA added this vulnerability to the KEV catalogue in January 2026 with exploitation confirmed in the wild targeting government and enterprise MDM deployments.

Ivanti Endpoint Manager Mobile (EPMM) all supported versions through 12.7.x
9.8
CVSS

CVE-2026-1340

Ivanti EPMM Android File Transfer Code Injection โ€” Unauthenticated RCE

CRITICAL โœ“ Patch Available

A code injection vulnerability in Ivanti Endpoint Manager Mobile (EPMM)'s Android File Transfer mechanism allows unauthenticated remote attackers to execute arbitrary code on internet-exposed appliances. The flaw is frequently chained with CVE-2026-1281 to achieve full appliance compromise. Active exploitation has been confirmed since January 2026, and CISA added the vulnerability to its Known Exploited Vulnerabilities catalogue on 8 April 2026 with a federal agency patch deadline of 11 April.

Ivanti Endpoint Manager Mobile (EPMM) all supported versions through 12.7.x
9.8
CVSS

CVE-2026-20093

Cisco Integrated Management Controller Authentication Bypass

CRITICAL โœ“ Patch Available

A critical authentication bypass in the Cisco Integrated Management Controller (IMC) allows an unauthenticated remote attacker to bypass authentication entirely and gain elevated access to the affected system. The vulnerability is caused by incorrect handling of password change requests โ€” an attacker sends a crafted HTTP request to the IMC management interface to bypass authentication, reset the password of any local user including administrators, and gain full control of the server's out-of-band management plane. IMC access is equivalent to physical console access to the server.

Cisco UCS C-Series and E-Series Standalone Rack Servers (IMC firmware prior to patched release) Cisco HyperFlex HX Series Nodes with unpatched IMC
9.8
CVSS

CVE-2026-20160

Cisco Smart Software Manager On-Prem Unauthenticated RCE

CRITICAL โœ“ Patch Available

A critical vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) allows an unauthenticated remote attacker to execute arbitrary commands on the underlying operating system. The flaw stems from the unintentional exposure of an internal administrative service that was not designed to accept external connections โ€” an attacker who reaches this service can invoke OS-level commands without authentication. SSM On-Prem is used by enterprises to manage Cisco software licences on-premises, without sending licence data to Cisco's cloud.

Cisco Smart Software Manager On-Prem (SSM On-Prem) prior to version 9-202601
9.8
CVSS

CVE-2026-20184

Cisco Webex Services โ€” Unauthenticated SSO User Impersonation via Certificate Validation Bypass

CRITICAL โœ“ Patch Available

An improper certificate validation flaw (CWE-295) in Cisco Webex Services' SSO integration with Control Hub allows unauthenticated remote attackers to supply crafted SAML tokens and be authenticated as any user within an enterprise's Webex tenant. Cisco has patched the cloud infrastructure, but enterprise administrators using SSO must manually regenerate and upload a new IdP SAML certificate to Control Hub to complete remediation.

Cisco Webex Services (all enterprise SSO-enabled deployments)
9.8
CVSS

CVE-2026-20253

Splunk Enterprise Unauthenticated RCE via PostgreSQL Sidecar Service

CRITICAL โœ“ Patch Available

Unauthenticated remote code execution in Splunk Enterprise via an exposed PostgreSQL sidecar service that binds to a network port without enforcing application-layer authentication. An attacker with network access to the Splunk host can send crafted database queries to trigger file operations resulting in arbitrary OS command execution โ€” with no credentials required at any stage. Splunk Cloud Platform is not affected. SIEM compromise carries exceptional impact: attackers gain complete visibility into defender detection coverage, can disable or modify detection rules to suppress alerting, and can extract credentials stored in forwarder authentication configurations. Discovered and disclosed by Orca Security.

Splunk Enterprise 9.2.x and earlier (Windows) Splunk Enterprise 9.2.x and earlier (Linux)
9.8
CVSS

CVE-2026-21643

Fortinet FortiClient EMS 7.4.4 โ€” Pre-Authentication SQL Injection RCE

CRITICAL โœ“ Patch Available

A critical pre-authentication SQL injection vulnerability (CWE-89) in Fortinet FortiClient EMS 7.4.4 allows an unauthenticated remote attacker to execute arbitrary code via the /api/v1/init_consts endpoint. The flaw was introduced when the multi-tenant database connection layer was refactored in 7.4.4, replacing parameterised queries with raw string interpolation. Because the PostgreSQL database user runs with superuser privileges in Fortinet's shipped VM image, successful SQL injection escalates to OS command execution via COPY ... TO/FROM PROGRAM. The vulnerability enables extraction of admin password hashes, API tokens, JWT secrets, and the complete endpoint inventory of all managed FortiClient deployments. CISA added CVE-2026-21643 to the KEV catalogue on 13 April 2026.

Fortinet FortiClient EMS 7.4.4
9.8
CVSS

CVE-2026-21992

Oracle Identity Manager Pre-Authentication Remote Code Execution

CRITICAL โœ“ Patch Available

A critical pre-authentication remote code execution vulnerability in Oracle Identity Manager (OIM) and Oracle Web Services Manager (WSM) allows unauthenticated attackers to execute arbitrary code via HTTP by exploiting missing authentication on a critical REST WebServices component. The flaw has a CVSS score of 9.8, requires no credentials or user interaction, and is remotely exploitable with low attack complexity over a network. Oracle released an out-of-band emergency patch in March 2026 โ€” only the second such emergency release Oracle has issued for Identity Manager.

Oracle Identity Manager 12.2.1.4.0 Oracle Identity Manager 14.1.2.1.0 Oracle Web Services Manager 12.2.1.4.0 +1 more
9.8
CVSS

CVE-2026-25089

Fortinet FortiSandbox Unauthenticated Command Injection via Web UI

CRITICAL โœ“ Patch Available

Unauthenticated command injection in the FortiSandbox web management interface allows a remote attacker to execute arbitrary system commands with no credentials required. The vulnerability is in the input handling routines for system configuration parameters; crafted HTTP requests to the management port trigger OS command execution. No workaround is available โ€” patching is the only remediation. Compromise of the sandboxing appliance is especially consequential as it allows an attacker to suppress malware detections and manipulate analysis verdicts, effectively disabling a critical security layer while it appears to function normally.

Fortinet FortiSandbox 5.4.0 โ€“ 5.4.5 (fixed: 5.4.6) Fortinet FortiSandbox 5.2.x (fixed: 5.2.8) Fortinet FortiSandbox 4.4.x (fixed: 4.4.13)
9.8
CVSS

CVE-2026-26210

KTransformers โ€” Unauthenticated RCE via Pickle Deserialization on ZMQ Scheduler Socket

CRITICAL โœ“ Patch Available

CVE-2026-26210 is a critical pre-authentication remote code execution vulnerability in the KTransformers AI inference acceleration framework. The scheduler's ZeroMQ ROUTER socket binds to all network interfaces by default with no authentication, and deserialises incoming messages using Python's pickle.loads() without validation. Any network-reachable attacker can supply a crafted pickle payload to execute arbitrary code as the process owner โ€” typically a privileged GPU server. No exploitation in the wild has been confirmed at time of publication.

KTransformers (all versions prior to patched release)
9.8
CVSS

CVE-2026-26956

vm2 Node.js Sandbox โ€” WebAssembly Exception Handling Escape Allows Host Code Execution

CRITICAL โœ“ Patch Available

A critical sandbox escape vulnerability in vm2 โ€” one of the most widely used Node.js sandbox libraries with approximately 1.3 million weekly npm downloads โ€” allows code executing inside the vm2 sandbox to escape isolation and execute arbitrary code on the host Node.js process. The vulnerability exploits WebAssembly exception handling (the 'exnref' proposal) which was introduced in V8 and bypasses vm2's sandbox enforcement mechanisms. Any application using vm2 to execute untrusted or user-supplied JavaScript is at risk of complete host process compromise. Fixed in vm2 3.9.22.

vm2 prior to 3.9.22
9.8
CVSS

CVE-2026-31414

Linux Kernel Netfilter Conntrack โ€” Privilege Escalation / Denial of Service

CRITICAL โœ“ Patch Available

A vulnerability in the Linux kernel netfilter connection tracking (conntrack) expectations mechanism allows a local attacker with access to netfilter configuration to trigger unsafe memory access, leading to kernel memory corruption, system crashes, or potential privilege escalation. In container environments with user namespaces enabled, the attack surface extends to unprivileged container processes that can configure netfilter rules within their namespace, potentially affecting the host kernel. Affects Linux kernel versions 6.1 through 6.10; patches backported to stable branches. Part of an April 2026 batch addressing multiple netfilter subsystem flaws (CVE-2026-31422, CVE-2026-31416).

Linux kernel 6.1 through 6.10 RHEL/CentOS/Rocky/AlmaLinux 8 and 9 (affected kernel branches) Ubuntu LTS 22.04 (5.15 kernel) and 24.04 (6.8 kernel) +2 more
9.8
CVSS

CVE-2026-3197

Palo Alto PAN-OS GlobalProtect SAML Authentication Bypass

CRITICAL โœ“ Patch Available

A critical authentication bypass in the Palo Alto Networks PAN-OS GlobalProtect SAML authentication handler allows unauthenticated remote attackers to forge a valid SAML assertion and gain full administrative access to the firewall management plane. The vulnerability exploits a signature verification flaw in the XML SAML response parser, enabling an attacker to send a crafted assertion that PAN-OS accepts as legitimate without contacting the configured identity provider. Exploitation grants the attacker the ability to modify firewall policy, create persistent accounts, and extract VPN configuration data. When chained with CVE-2026-3201 (post-authentication command injection), the combined attack achieves unauthenticated root-level OS code execution.

Palo Alto Networks PAN-OS 11.2.x prior to 11.2.4 Palo Alto Networks PAN-OS 11.1.x prior to 11.1.5 Palo Alto Networks PAN-OS 11.0.x prior to 11.0.6 +2 more
9.8
CVSS

CVE-2026-32644

Milesight AIOT Cameras โ€” Hard-Coded Shared SSL Private Key Enables Fleet-Wide Silent MITM

CRITICAL โœ“ Patch Available

All cameras within a Milesight AIOT model family share a single factory-embedded SSL private key that cannot be changed through the management interface. An attacker who extracts this key from any unit โ€” achievable through firmware extraction or from publicly available firmware images โ€” can perform silent man-in-the-middle attacks against all cameras in that model family, intercepting video streams, management credentials, and configuration traffic without triggering any certificate validation failure. Affects 18-plus model families; CISA advisory ICSA-26-113-03.

Milesight MS-C52x4-FPB/FPC firmware < 59.6.0.80 Milesight MS-C59xx-PA/PB firmware < 59.6.0.80 Milesight MS-N72xx NVR firmware < 45.9.0.4 +1 more
9.8
CVSS

CVE-2026-33032

nginx-ui MCP Endpoint Authentication Bypass (MCPwn)

CRITICAL โœ“ Patch Available

A critical authentication bypass in nginx-ui's Model Context Protocol (MCP) endpoint allows unauthenticated remote attackers to invoke all MCP tools including creating, modifying, and deleting Nginx configuration files and restarting the Nginx service. The /mcp_message endpoint applies only IP allowlisting with an empty default whitelist (effectively allow-all), bypassing the application's authentication layer entirely. Exploitation requires two HTTP requests and takes seconds to execute, resulting in full Nginx server takeover.

nginx-ui prior to 2.3.4
9.8
CVSS

CVE-2026-33626

LMDeploy LLM Inference Framework โ€” Unauthenticated Remote Code Execution via Deserialization

CRITICAL โœ“ Patch Available

A deserialization vulnerability in LMDeploy's model loading API allows an unauthenticated remote attacker to execute arbitrary operating system commands as the service account running the inference server. The flaw exists in the absence of input validation during model configuration and adapter ingestion โ€” a crafted payload triggers unsafe deserialization and achieves code execution. Active exploitation was confirmed within 13 hours of public disclosure on April 24 2026.

LMDeploy all versions prior to 0.8.4
9.8
CVSS

CVE-2026-33824

Windows Internet Key Exchange (IKE) โ€” Unauthenticated Remote Code Execution

CRITICAL โœ“ Patch Available

A critical remote code execution vulnerability in the Windows Internet Key Exchange Service Extensions allows an unauthenticated remote attacker to execute arbitrary code without user interaction. The network-accessible attack vector and complete absence of authentication requirements place this among the most severe vulnerabilities in the April 2026 Patch Tuesday release. Systems running Windows with IPsec/IKE services exposed to untrusted networks are at immediate risk.

Windows Server 2025 Windows Server 2022 Windows Server 2019 +3 more
9.8
CVSS

CVE-2026-34197

Apache ActiveMQ Unauthenticated RCE via Jolokia API

CRITICAL โœ“ Patch Available

A critical remote code execution vulnerability in Apache ActiveMQ's Jolokia JMX-over-HTTP bridge allows unauthenticated remote attackers to execute arbitrary OS commands by invoking the addNetworkConnector MBean operation with a crafted URI. The flaw causes the broker to fetch and parse an attacker-controlled XML configuration file, enabling arbitrary Java class instantiation and OS command execution under the service account context. Present since ActiveMQ 5.x, this design weakness was not addressed in the 6.x rewrite and is unauthenticated by default in ActiveMQ 6.0.0โ€“6.1.1. When chained with CVE-2024-32114, the combined exploit achieves full unauthenticated root-level code execution in seconds.

Apache ActiveMQ 6.0.0 โ€“ 6.1.1 (Jolokia unauthenticated by default) Apache ActiveMQ 5.x prior to 5.19.4 (if Jolokia explicitly enabled)
9.8
CVSS

CVE-2026-35273

Oracle PeopleSoft Campus Solutions Authentication Bypass โ€” Student Records Exposed

CRITICAL โœ“ Patch Available

Critical authentication bypass in Oracle PeopleSoft's PIA (PeopleSoft Internet Architecture) web tier affecting the Campus Community module. An unauthenticated remote attacker can send a crafted HTTP request to the PIA endpoint to trigger an authentication token validation error, receiving an administrative-level authenticated session without supplying credentials. The flaw affects all PeopleSoft PeopleTools versions 8.54 through 8.60 with the Campus Solutions module. Actively exploited by ShinyHunters since at least 9 June 2026; at least twelve universities in the US, UK, and Australia confirmed breached with student PII (SSNs, financial aid records, academic transcripts) exfiltrated. Oracle released an out-of-band emergency patch (Doc ID 2026-35273.8) on 15 June 2026.

Oracle PeopleSoft PeopleTools 8.54 through 8.60 with Campus Solutions module

Note: CVE data is curated manually from NVD, vendor advisories, and security research. CVSS scores reflect NVD base scores at time of entry. Always verify with official vendor advisories before actioning.