Skip to content

// CVE Tracker

152 active CVEs โ€” page 3 of 7, sorted unpatched-first by CVSS

85

CRITICAL

66

HIGH

152

TOTAL ACTIVE

146

PATCHED

CVSS Scale: 9.0โ€“10.0 CRITICAL ยท 7.0โ€“8.9 HIGH ยท 4.0โ€“6.9 MEDIUM ยท 0.1โ€“3.9 LOW
9.8
CVSS

CVE-2026-3854

GitHub Enterprise Server โ€” Unauthenticated RCE via Malicious Git Push (Pre-Auth, Single Request)

CRITICAL โœ“ Patch Available

Pre-authentication remote code execution in GitHub Enterprise Server's Git protocol handler. A crafted pack-file transmitted during a git push triggers a memory corruption condition in the Git protocol parsing layer, achieving code execution in the context of the Git service process before authentication is completed. No credentials required. Affects all supported GHES versions prior to the hotfix releases. Fixed in GHES 3.12.8, 3.13.4, 3.14.2, 3.15.1.

GitHub Enterprise Server 3.12.0โ€“3.12.7 GitHub Enterprise Server 3.13.0โ€“3.13.3 GitHub Enterprise Server 3.14.0โ€“3.14.1 +1 more
9.8
CVSS

CVE-2026-41089

Windows Netlogon Remote Protocol Stack Buffer Overflow โ€” Unauthenticated SYSTEM RCE on Domain Controllers (CVSS 9.8)

CRITICAL โœ“ Patch Available

A stack-based buffer overflow in the Windows Netlogon Remote Protocol (MS-NRPC) service allows an unauthenticated attacker with network access to a Windows domain controller to execute arbitrary code with SYSTEM privileges. The vulnerability exists in the NetrLogonSendToSam RPC function, which fails to validate the size of an input parameter before copying it to a fixed-size stack buffer. A specially crafted RPC request causes the buffer to overflow into adjacent stack memory, overwriting a return address and redirecting execution to attacker-controlled code. The attack requires no credentials, no user interaction, and no prior foothold. It requires only network access to TCP 445 (SMB, which hosts the Netlogon named pipe) on the domain controller. Active exploitation confirmed by Belgium's Centre for Cybersecurity (CCB) on 29 May 2026. Public PoC exploit available. Successful exploitation results in complete Active Directory domain compromise.

Windows Server 2025 โ€” all builds prior to May 2026 security update Windows Server 2022 โ€” all builds prior to May 2026 security update Windows Server 2019 โ€” all builds prior to May 2026 security update +3 more
~9.8
EST.

CVE-2026-41096

Windows DNS Client Remote Code Execution โ€” Memory Corruption via Crafted DNS Response

CRITICAL โœ“ Patch Available

A memory corruption vulnerability in the Windows DNS Client allows an attacker who controls or can spoof a DNS server to send a specially crafted DNS response that corrupts memory on the resolving Windows host. The flaw is triggered during standard DNS resolution activity requiring no user interaction. Successful exploitation could enable remote code execution in the context of the DNS Client service. All supported Windows versions are affected. No active exploitation has been confirmed at time of disclosure, but the network-based, zero-interaction attack vector makes this a candidate for rapid weaponisation.

Windows 10 21H2 and 22H2 (all editions) Windows 11 22H2, 23H2, and 24H2 (all editions) Windows Server 2019 +2 more
9.8
CVSS

CVE-2026-41940

cPanel and WHM โ€” Authentication Bypass in Login Flow (Zero-Day, PoC Public)

CRITICAL โœ“ Patch Available

Authentication logic flaw in the cPanel and WHM web hosting control panel software allowing unauthenticated remote attackers to bypass credential verification and gain full administrative access. Exploited as a zero-day for approximately six days before vendor patched; public proof-of-concept now available. Affects all cPanel/WHM versions from 11.40 onwards. WHM administrative compromise provides root-level server access; cPanel compromise provides full hosting account control. Fixed in cPanel LTS 120.0.24, Stable 122.0.16, Current 124.0.6.

cPanel & WHM 11.40 through 120.0.23 (LTS) cPanel & WHM 11.40 through 122.0.15 (Stable) cPanel & WHM 11.40 through 124.0.5 (Current)
9.8
CVSS

CVE-2026-44815

Windows DHCP Client Stack Buffer Overflow via Rogue DHCP Server

CRITICAL โœ“ Patch Available

A stack buffer overflow in the Windows DHCP Client service allows an attacker operating a rogue DHCP server on the same Layer 2 broadcast domain to achieve SYSTEM-level remote code execution on Windows systems performing DHCP discovery. No authentication or user interaction required from the victim. Affects all Windows versions using DHCP. Patched in the June 2026 cumulative update. DHCP Snooping on access-layer switches is an effective compensating control.

Windows 10 Windows 11 Windows Server 2016 +3 more
9.8
CVSS

CVE-2026-45185

Exim MTA Remote Code Execution โ€” Use-After-Free in GnuTLS TLS Session Shutdown

CRITICAL โœ“ Patch Available

A use-after-free vulnerability in Exim's GnuTLS TLS session cleanup code path allows an unauthenticated remote attacker to trigger memory corruption during the SMTP STARTTLS negotiation phase. The freed TLS session structure continues to be referenced after deallocation, and with suitable heap manipulation the corruption can be elevated to arbitrary code execution. The attack requires only network access to port 25 or 587 โ€” no credentials and no prior session state. All Exim versions compiled with GnuTLS support are affected prior to the patched release.

Exim with GnuTLS support, all versions prior to patched release (May 2026) Debian default Exim4 installations (all supported releases) Ubuntu default Exim4 installations (all supported LTS releases)
9.8
CVSS

CVE-2026-45247

CVE-2026-45247 โ€” Mirasvit Full Page Cache Warmer for Magento 2 Unauthenticated RCE

CRITICAL โœ“ Patch Available

Unauthenticated remote code execution via PHP deserialization in the Mirasvit Full Page Cache Warmer extension for Magento 2. Attackers exploit a malicious serialised cookie value without authentication. CISA added to KEV 3 June 2026; actively exploited in Magecart-style and credential harvesting campaigns.

Mirasvit Full Page Cache Warmer for Magento 2 (all versions prior to 1.11.12)
9.8
CVSS

CVE-2026-45657

Windows Kernel Use-After-Free Remote Code Execution (Actively Exploited)

CRITICAL โœ“ Patch Available

A use-after-free vulnerability in a Windows kernel memory management component allows unauthenticated attackers to execute arbitrary code at SYSTEM privilege. Microsoft confirmed active exploitation before patch release as part of the June 2026 Patch Tuesday. Affects all supported Windows versions (10/11 and Server 2016โ€“2025). Patched in the June 2026 cumulative update.

Windows 10 Windows 11 Windows Server 2016 +3 more
9.8
CVSS

CVE-2026-4670

MOVEit Automation โ€” Critical Pre-Authentication Authentication Bypass

CRITICAL โœ“ Patch Available

A critical authentication bypass vulnerability in Progress MOVEit Automation allows a remote unauthenticated attacker to authenticate as any user without valid credentials, gaining full administrative access to the MOVEit Automation management interface. The vulnerability is pre-authentication and requires no prior account knowledge or network positioning. MOVEit Automation is an enterprise managed file transfer platform used by organisations in financial services, healthcare, and government to automate regulated data transfers. Progress Software released patches on 4 May 2026; MOVEit Cloud customers were patched automatically. This is the fourth critical vulnerability in the MOVEit product family since the mass-exploitation campaign of 2023.

MOVEit Automation 2025.0.x prior to 2025.0.10 MOVEit Automation 2024.0.x prior to 2024.1.9 MOVEit Automation 2023.x and earlier (all versions)
9.8
CVSS

CVE-2026-47288

Windows Kerberos KDC Remote Code Execution โ€” Active Directory Domain Controllers

CRITICAL โœ“ Patch Available

A memory corruption vulnerability in the Windows Kerberos Key Distribution Centre (KDC) service allows network-adjacent unauthenticated attackers to execute arbitrary code on Active Directory domain controllers. The vulnerable code path is in the AS-REQ (pre-authentication) handling, reachable without credentials. Successful exploitation achieves SYSTEM privilege on the domain controller โ€” equivalent to full domain compromise. Affects all supported Windows Server versions acting as AD domain controllers. Patched in the June 2026 cumulative update.

Windows Server 2008 R2 (Active Directory KDC) Windows Server 2012/2012 R2 (Active Directory KDC) Windows Server 2016 (Active Directory KDC) +3 more
9.8
CVSS

CVE-2026-47291

Windows HTTP.sys Wormable Remote Code Execution

CRITICAL โœ“ Patch Available

An integer overflow in the HTTP/2 protocol parser of Windows HTTP.sys (the kernel-mode HTTP driver) allows an unauthenticated remote attacker to execute arbitrary code at SYSTEM privilege on any Windows Server with HTTP services enabled. The vulnerability is wormable โ€” no authentication or user interaction required โ€” affecting IIS, Exchange, SharePoint, WSUS, WinRM, and any HTTP API application on Windows Server 2008 R2 through 2025. Patched in the June 2026 cumulative update.

Windows Server 2008 R2 Windows Server 2012/2012 R2 Windows Server 2016 +4 more
9.6
CVSS

CVE-2026-34260

SAP S/4HANA Enterprise Search SQL Injection โ€” Authenticated Database Compromise

CRITICAL โœ“ Patch Available

A SQL injection vulnerability in SAP S/4HANA's Enterprise Search ABAP component allows an authenticated user with standard business privileges to manipulate database queries via unsanitised search parameters. No elevated SAP permissions are required beyond a valid user account. Successful exploitation provides full read and write access to the underlying HANA database, exposing the complete financial, HR, and operational dataset of the affected SAP system. The vulnerability was patched in SAP Security Note 3733041, released on SAP's May 2026 Security Patch Day.

SAP S/4HANA (Enterprise Search component, all versions prior to May 2026 patch)
9.6
CVSS

CVE-2026-34263

SAP Commerce Cloud Unauthenticated RCE via Spring Security Misconfiguration

CRITICAL โœ“ Patch Available

An improper Spring Security configuration in SAP Commerce Cloud leaves specific API endpoints unauthenticated, allowing a completely unauthenticated remote attacker to inject malicious input that results in arbitrary server-side code execution. No credentials are required. The vulnerability impacts the full confidentiality, integrity, and availability triad of the Commerce Cloud instance. Given that SAP Commerce Cloud is commonly internet-facing as the transactional e-commerce platform, the external attack surface is broad. Patched via SAP Security Note 3733064, released May 2026.

SAP Commerce Cloud (all versions prior to May 2026 patch, SAP Note 3733064)
9.6
CVSS

CVE-2026-45321

TanStack npm Supply Chain Attack โ€” GitHub Actions OIDC Token Hijack via Pwn Request

CRITICAL โœ“ Patch Available

A chained GitHub Actions misconfiguration vulnerability in the TanStack project allowed an attacker to hijack the npm OIDC trusted publisher token and publish 84 malicious package versions across 42 @tanstack/* packages. The attack combined a pull_request_target Pwn Request misconfiguration, Actions cache poisoning across the fork/base boundary, and runtime OIDC token extraction to operate under TanStack's trusted publisher identity. Malicious packages executed credential-stealing code via npm postinstall hooks. Affected versions were published to npm on 2026-05-11 between 19:20โ€“19:26 UTC.

@tanstack/react-router (malicious versions published 2026-05-11) @tanstack/react-query (malicious versions published 2026-05-11) @tanstack/react-table (malicious versions published 2026-05-11) +2 more
9.4
CVSS

CVE-2024-57728

SimpleHelp Remote Management Tool โ€” Path Traversal Unauthenticated File Read/Write

CRITICAL โœ“ Patch Available

A path traversal vulnerability in the SimpleHelp RMM server enables an unauthenticated remote attacker to read and write arbitrary files on the underlying server filesystem. By crafting requests that escape the intended directory scope, an attacker can exfiltrate configuration files containing credentials, overwrite application files to establish persistent access, or modify server configuration to create new administrative accounts. No authentication is required to exploit this vulnerability.

SimpleHelp Server all versions prior to patched release
9.4
CVSS

CVE-2025-20362

Cisco ASA Web Management Interface โ€” Authentication Bypass

CRITICAL โœ“ Patch Available

An authentication bypass vulnerability in the web management interface of Cisco Adaptive Security Appliance (ASA) software allows an unauthenticated remote attacker to authenticate to the administrative interface without valid credentials. The flaw stems from an improper state validation in the session establishment process. Exploitation allows an attacker to access the ASA management plane with administrator privileges, and is used in conjunction with CVE-2025-20333 as part of the FIRESTARTER campaign to deploy a firmware-persistent backdoor.

Cisco ASA Software all versions prior to patched release (Q4 2025) Cisco ASA 5500-X Series firewalls Cisco Firepower 1000, 2100, 4100, and 9300 Series running ASA software
9.4
CVSS

CVE-2026-33634

Aqua Security Trivy โ€” Embedded Malicious Code in Official GitHub Actions and Releases

CRITICAL โœ“ Patch Available

Threat actor TeamPCP compromised the Aqua Security Trivy vulnerability scanner ecosystem on 19 March 2026, force-pushing malicious code to 75 of 77 version tags in the official aquasecurity/trivy-action and all tags in aquasecurity/setup-trivy GitHub Actions repositories. A second attack wave on 22 March replaced DockerHub images. The malicious code embedded in affected versions deployed an infostealer targeting plain-text secrets in CI/CD runner process memory, exfiltrating cloud credentials, API tokens, Kubernetes configurations, and SSH keys. CISA added CVE-2026-33634 to the Known Exploited Vulnerabilities catalogue on 26 March 2026.

aquasecurity/trivy-action GitHub Action (all tags except those predating March 19) aquasecurity/setup-trivy GitHub Action (all tags as of March 19) Aqua Security Trivy v0.69.4 through v0.69.6 (DockerHub images)
9.4
CVSS

CVE-2026-44963

Veeam Backup & Replication Remote Code Execution via Domain User Credentials

CRITICAL โœ“ Patch Available

An insufficient authorisation check in the Veeam Backup Service API allows any Active Directory domain user to invoke privileged backup service operations and achieve remote code execution on the Veeam Backup & Replication server. Exploitation grants code execution with the Veeam service account's privileges (typically Local System). Actively targeted by ransomware groups to neutralise backup infrastructure. Fixed in Veeam Backup & Replication 12.2.

Veeam Backup & Replication 12.1 and earlier
~9.4
EST.

CVE-2026-9082

Drupal Core SQL Injection via Database Abstraction API โ€” PostgreSQL Backends

CRITICAL โœ“ Patch Available

A SQL injection vulnerability in Drupal core's database abstraction API (SA-CORE-2026-004) affecting all Drupal sites using PostgreSQL as the database backend. An unauthenticated attacker can inject arbitrary SQL via a crafted HTTP request, without any user interaction required. Impact includes database read and write access (site content, user credentials, configuration) and potentially OS command execution via PostgreSQL's COPY TO/FROM PROGRAM function where database permissions allow. Rated 'Highly Critical' (20/25) on Drupal's risk scale. MySQL and MariaDB backends are not affected by this specific CVE. CISA added to KEV 22 May 2026 following confirmed exploitation.

Drupal 10.x prior to 10.4.8 (PostgreSQL backend) Drupal 11.x prior to 11.1.12 (PostgreSQL backend) Drupal 9.x (end-of-life โ€” no fix available)
9.3
CVSS

CVE-2026-0300

PAN-OS โ€” Unauthenticated RCE via User-ID Authentication Portal Buffer Overflow (Actively Exploited)

CRITICAL โœ“ Patch Available

A critical buffer overflow in Palo Alto Networks PAN-OS User-ID authentication portal allows a remote unauthenticated attacker to execute arbitrary code as root on the management plane. Exploitation began approximately 6 April 2026 โ€” six weeks before public disclosure. CISA added CVE-2026-0300 to the KEV catalogue on 6 May 2026. Post-exploitation activity includes deployment of novel implant toolkits and credential interception on compromised management planes. Espionage-motivated threat actors are targeting government and critical infrastructure organisations.

PAN-OS 9.1.x prior to 9.1.22 PAN-OS 10.1.x prior to 10.1.15 PAN-OS 10.2.x prior to 10.2.14 +2 more
9.3
CVSS

CVE-2026-23760

SmarterMail Authentication Bypass Allowing Admin Account Takeover

CRITICAL โœ“ Patch Available

An authentication bypass vulnerability in SmarterTools SmarterMail email server allows unauthenticated remote attackers to bypass the authentication mechanism and gain administrative access. The flaw was exploited as a zero-day by Storm-1175, a China-linked ransomware affiliate, prior to public disclosure, and was subsequently used to deploy Medusa ransomware. SmarterMail is used by tens of thousands of organisations globally as an on-premises email and collaboration platform.

SmarterMail (versions prior to patched build โ€” see SmarterTools advisory)
9.3
CVSS

CVE-2026-3055

Citrix NetScaler ADC/Gateway Unauthenticated Memory Overread via SAML

CRITICAL โœ“ Patch Available

An insufficient input validation flaw in the SAML Identity Provider endpoint of Citrix NetScaler ADC and NetScaler Gateway allows an unauthenticated remote attacker to trigger an out-of-bounds memory read. The appliance leaks sensitive memory contents โ€” including session tokens and authentication credentials โ€” through the NSC_TASS response cookie when a crafted SAMLRequest omitting the AssertionConsumerServiceURL field is submitted to /saml/login. Only appliances configured as SAML IDPs are affected; default configurations are not vulnerable. CISA added this CVE to the Known Exploited Vulnerabilities catalogue on 30 March 2026 following confirmed in-the-wild exploitation.

Citrix NetScaler ADC and Gateway prior to 14.1-66.59 Citrix NetScaler ADC and Gateway 14.1 prior to 14.1-60.58 Citrix NetScaler ADC and Gateway 13.1 prior to 13.1-62.23 +1 more
9.3
CVSS

CVE-2026-33017

Langflow AI Pipeline Builder โ€” Unauthenticated Remote Code Execution

CRITICAL โœ“ Patch Available

An unauthenticated remote code execution vulnerability in Langflow's public flow build endpoint allows attackers to inject arbitrary Python code into flow node definitions, which Langflow executes server-side without sandboxing. No credentials or user interaction are required. Within 20 hours of public disclosure on 17 March 2026, active exploitation was confirmed with attackers harvesting LLM provider API keys (OpenAI, Anthropic, AWS) from compromised instances. CISA added the vulnerability to its Known Exploited Vulnerabilities catalogue on 26 March 2026.

Langflow all versions through 1.8.1
9.3
CVSS

CVE-2026-39987

Marimo Python Notebook Unauthenticated Terminal RCE via WebSocket

CRITICAL โœ“ Patch Available

A pre-authentication remote code execution vulnerability in Marimo, an open-source Python notebook widely used in data science and AI/ML workflows, allows any network-accessible attacker to obtain a full PTY shell on the server. The /terminal/ws WebSocket endpoint fails to call authenticate() before accepting connections, unlike all other protected endpoints. An attacker connects to the endpoint and is immediately granted interactive OS-level access. Exploitation was observed within 10 hours of public disclosure, with attackers building working exploits directly from the advisory.

Marimo prior to 0.23.0 (all versions up to and including 0.20.4)
9.3
CVSS

CVE-2026-50751

CVE-2026-50751 โ€” Check Point Security Gateway IKEv1 Authentication Bypass

CRITICAL โœ“ Patch Available

Authentication bypass in Check Point Security Gateway's IKEv1 VPN protocol handling allows unauthenticated attackers to completely bypass remote access VPN authentication, gaining internal network access. CISA added to KEV 8 June 2026 with confirmed ransomware campaign use and a 3-day remediation deadline.

Check Point Security Gateway R81.10 Check Point Security Gateway R81.20 Check Point Quantum Spark (SMB Firewall) with IKEv1 enabled

Note: CVE data is curated manually from NVD, vendor advisories, and security research. CVSS scores reflect NVD base scores at time of entry. Always verify with official vendor advisories before actioning.