SignalSec: Vulns & Hacks

Known Exploited Vulnerabilities and latest CVEs

Exploited in wild

CVE-2026-88771

CRITICAL (9.8)
Vendor: CitrixProduct: NetScaler9/27/2026

Citrix NetScaler ADC and NetScaler Gateway contain an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands.

CISA KEV Alert: Added on 9/27/2026. Action due: 9/30/2026.

Exploited in wild

CVE-2026-88772

HIGH (8.1)
Vendor: CitrixProduct: NetScaler9/27/2026

Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial of service

CISA KEV Alert: Added on 9/27/2026. Action due: 9/30/2026.

Exploited in wild

CVE-2026-65660

HIGH (8.8)
Vendor: MicrosoftProduct: SharePoint9/25/2026

Microsoft SharePoint contains a code injection vulnerability which could allow an authorized attacker to execute code over a network.

CISA KEV Alert: Added on 9/25/2026. Action due: 9/28/2026.

AI/MLMicrosoft
View CISA Alert
Exploited in wild

CVE-2026-87902

HIGH (8.1)
Vendor: WordPressProduct: Core9/25/2026

WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local `.php` file outside the active theme directories, leading to remote code execution.

CISA KEV Alert: Added on 9/25/2026. Action due: 9/28/2026.

Exploited in wild

CVE-2026-5430

CRITICAL (10)
Vendor: WSO2Product: Multiple Products9/24/2026

WSO2 API Control Plane, API Manager, Traffic Manager & Universal Gateway contain a path traversal vulnerability that could allow for unrestricted file upload and lead to remote code execution.

CISA KEV Alert: Added on 9/24/2026. Action due: 9/27/2026.

Exploited in wild

CVE-2026-71362

CRITICAL (9.1)
Vendor: AdobeProduct: Commerce and Magento 9/24/2026

Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction.

CISA KEV Alert: Added on 9/24/2026. Action due: 9/27/2026.

Exploited in wild

CVE-2026-93616

CRITICAL (9.8)
Vendor: Check PointProduct: Multiple Products9/22/2026

A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.

CISA KEV Alert: Added on 9/22/2026. Action due: 9/25/2026.

Exploited in wild

CVE-2026-94127

CRITICAL (9.8)
Vendor: F5Product: BIG-IP APM9/22/2026

F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unauthenticated attacker to perform remote code execution.

CISA KEV Alert: Added on 9/22/2026. Action due: 9/25/2026.

Exploited in wild

CVE-2026-93952

CRITICAL (10)
Vendor: AristaProduct: VeloCloud Orchestrator9/22/2026

Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.

CISA KEV Alert: Added on 9/22/2026. Action due: 9/25/2026.

AI/MLCloud Security
View CISA Alert
Exploited in wild

CVE-2026-7273

HIGH (8.8)
Vendor: ZyxelProduct: GS1900 Series Switches9/21/2026

Zyxel GS1900 series switches contain a stack-based buffer overflow vulnerability in the CGI program which could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.

CISA KEV Alert: Added on 9/21/2026. Action due: 9/24/2026.

Exploited in wild

CVE-2026-53266

HIGH (8.8)
Vendor: LinuxProduct: Kernel9/18/2026

Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.

CISA KEV Alert: Added on 9/18/2026. Action due: 9/21/2026.

AI/MLRansomwareHardware/IoT
View CISA Alert
Exploited in wild

CVE-2025-39964

HIGH (7.8)
Vendor: LinuxProduct: Kernel9/18/2026

Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state.

CISA KEV Alert: Added on 9/18/2026. Action due: 9/21/2026.

Exploited in wild

CVE-2025-39682

CRITICAL (9.8)
Vendor: LinuxProduct: Kernel9/18/2026

Linux Kernel contains an improper check for unusual or exceptional conditions vulnerability in the TLS receive path which allows a zero-length record retrieved from the rx_list to bypass the intended recvmsg() record-type handling, potentially causing subsequent TLS records to be processed using incorrect zero-copy and queuing assumptions. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.

CISA KEV Alert: Added on 9/18/2026. Action due: 9/21/2026.

AI/MLRansomwareLinux
View CISA Alert
Exploited in wild

CVE-2026-76460

CRITICAL (10)
Vendor: CiscoProduct: Identity Services Engine9/16/2026

Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.

CISA KEV Alert: Added on 9/16/2026. Action due: 9/19/2026.

Exploited in wild
Vendor: GoogleProduct: Pixel9/16/2026

Google Pixel devices contain an improper authorization vulnerability in the cellular modem. A logic error may allow an attacker to bypass permission checks and escalate privileges.

CISA KEV Alert: Added on 9/16/2026. Action due: 9/19/2026.

Exploited in wild

CVE-2026-87886

HIGH (7.8)
Vendor: AcronisProduct: Backup9/16/2026

Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux) before build 1.8.11.638, Acronis Backup plugin for DirectAdmin (Linux) before build 1.2.3.238.

CISA KEV Alert: Added on 9/16/2026. Action due: 9/19/2026.

Exploited in wild

CVE-2026-76461

CRITICAL (9.8)
Vendor: CiscoProduct: Secure Email Gateway9/14/2026

Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.

CISA KEV Alert: Added on 9/14/2026. Action due: 9/17/2026.

Exploited in wild

CVE-2026-42018

HIGH (7.5)
Vendor: JFrogProduct: Artifactory9/11/2026

JFrog Artifactory contains an improper authentication vulnerability that could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.

CISA KEV Alert: Added on 9/11/2026. Action due: 9/25/2026.

Exploited in wild

CVE-2026-85706

CRITICAL (10)
Vendor: GitLabProduct: Community Edition and Enterprise Edition9/11/2026

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.

CISA KEV Alert: Added on 9/11/2026. Action due: 9/14/2026.

Exploited in wild

CVE-2026-84869

CRITICAL (9.9)
Vendor: ConnectWiseProduct: ScreenConnect9/11/2026

ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to file transfer and execution through an active remote sessions without authorization or host confirmation.

CISA KEV Alert: Added on 9/11/2026. Action due: 9/14/2026.

Exploited in wild

CVE-2026-85102

CRITICAL (9.8)
9/9/2026

Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.

CISA KEV Alert: Added on 9/22/2026. Action due: 9/25/2026.

Exploited in wild

CVE-2025-25249

HIGH (8.1)
Vendor: FortinetProduct: Multiple Products9/9/2026

Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets.

CISA KEV Alert: Added on 9/9/2026. Action due: 9/12/2026.

Exploited in wild

CVE-2026-87491

HIGH (8.8)
Vendor: GoogleProduct: Chromium V89/9/2026

Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CISA KEV Alert: Added on 9/9/2026. Action due: 9/23/2026.

AI/MLMicrosoft
View CISA Alert
Exploited in wild

CVE-2026-20079

CRITICAL (10)
Vendor: CiscoProduct: Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management9/9/2026

Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication Bypass using an alternate path or channel vulnerability that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.

CISA KEV Alert: Added on 9/9/2026. Action due: 9/12/2026.

AI/MLCloud Security
View CISA Alert
Exploited in wild

CVE-2026-81963

HIGH (7.8)
Vendor: MicrosoftProduct: Windows9/8/2026

Microsoft Windows Update Stack contains a link following vulnerability that allows a local attacker to escalate privileges locally up to SYSTEM.

CISA KEV Alert: Added on 9/8/2026. Action due: 9/22/2026.

AI/MLMicrosoft
View CISA Alert
Exploited in wild

CVE-2026-75650

CRITICAL (10)
Vendor: AdobeProduct: Commerce and Magento9/8/2026

Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

CISA KEV Alert: Added on 9/8/2026. Action due: 9/11/2026.

Exploited in wild

CVE-2026-85880

HIGH (7.8)
Vendor: MicrosoftProduct: Windows9/8/2026

Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally.

CISA KEV Alert: Added on 9/8/2026. Action due: 9/22/2026.

AI/MLMicrosoft
View CISA Alert
Exploited in wild

CVE-2026-86218

CRITICAL (9.8)
Vendor: N-ableProduct: N-central9/8/2026

N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.

CISA KEV Alert: Added on 9/8/2026. Action due: 9/11/2026.

Exploited in wild

CVE-2026-86060

CRITICAL (9.8)
9/5/2026

RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)

CISA KEV Alert: Added on 9/10/2026. Action due: 9/13/2026.

AI/MLHardware/IoT
View CISA Alert
Exploited in wild

CVE-2026-67279

MEDIUM (6.5)
9/5/2026

RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request. On affected builds the server dispatches the command, enabling unauthenticated creation, overwrite, and reconstruction of files in the RouterOS managed file namespace, including support files containing configuration and diagnostic data.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)

CISA KEV Alert: Added on 9/25/2026. Action due: 9/28/2026.

AI/MLHardware/IoT
View CISA Alert
Exploited in wild

CVE-2026-67277

HIGH (8.2)
9/5/2026

RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits an uninitialized tail from a kernel packet buffer. A separate unchecked, inverted packet-size interval causes unsigned integer underflow, anomalously large fragmented output, and can restart the RouterOS kernel. This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)

CISA KEV Alert: Added on 9/10/2026. Action due: 9/13/2026.

AI/MLHardware/IoTLinux
View CISA Alert
Exploited in wild

CVE-2026-85046

HIGH (8.8)
Vendor: GoogleProduct: Chromium V89/4/2026

Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CISA KEV Alert: Added on 9/4/2026. Action due: 9/18/2026.

Exploited in wild

CVE-2026-9586

CRITICAL (9.8)
Vendor: SangomaProduct: Switchvox9/2/2026

Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.

CISA KEV Alert: Added on 9/2/2026. Action due: 9/5/2026.

Exploited in wild

CVE-2026-83549

HIGH (7.8)
Vendor: SonicWallProduct: SMA1000 Appliances9/2/2026

Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.

CISA KEV Alert: Added on 9/2/2026. Action due: 9/5/2026.

Exploited in wild

CVE-2026-59822

HIGH (8.2)
Vendor: BerriAIProduct: LiteLLM9/2/2026

BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token.

CISA KEV Alert: Added on 9/2/2026. Action due: 9/16/2026.

Exploited in wild

CVE-2026-83548

CRITICAL (10)
Vendor: SonicWallProduct: SMA1000 Appliances9/2/2026

A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.

CISA KEV Alert: Added on 9/2/2026. Action due: 9/5/2026.

Exploited in wild

CVE-2026-82329

CRITICAL (9.8)
Vendor: JFrogProduct: Artifactory9/2/2026

JFrog Artifactory contains an improper authentication vulnerability that under default configuration can allow an unauthenticated attacker with network access to obtain administrative privileges.

CISA KEV Alert: Added on 9/2/2026. Action due: 9/5/2026.

Exploited in wild

CVE-2026-48710

MEDIUM (6.5)
Vendor: KludexProduct: Starlette9/2/2026

Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentication bypass when the authentication depends on the reconstructed URL’s path. This vulnerability could be chaned with CVE-2026-42271.

CISA KEV Alert: Added on 9/2/2026. Action due: 9/16/2026.

Exploited in wild

CVE-2026-82078

CRITICAL (9.1)
Vendor: PaperCutProduct: NG/MF8/28/2026

PaperCut NG/MF contains an unsafe reflection vulnerability that allows an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process. This vulnerability can be chained with CVE-2026-81578.

CISA KEV Alert: Added on 8/28/2026. Action due: 9/11/2026.

Exploited in wild

CVE-2026-81578

CRITICAL (9.8)
Vendor: PaperCutProduct: NG/MF8/28/2026

PaperCut NG/MF contains a missing authentication for critical function vulnerability which allows an unauthenticated remote attacker to modify certain system configurations. This vulnerability can be chained with CVE-2026-82078.

CISA KEV Alert: Added on 8/28/2026. Action due: 9/11/2026.

Exploited in wild

CVE-2026-66384

MEDIUM (5.3)
Vendor: JFrogProduct: Artifactory8/27/2026

JFrog Artifactory contains an improper limitation of a pathname to a restricted directory vulnerability. This can allow an authenticated user to write data outside the intended Docker cache path under specific remote-repository conditions.

CISA KEV Alert: Added on 8/27/2026. Action due: 9/10/2026.

AI/MLCloud Security
View CISA Alert
Exploited in wild

CVE-2023-49105

CRITICAL (9.8)
Vendor: ownCloudProduct: ownCloud8/27/2026

ownCloud contains an improper authentication vulnerability that allows an attacker to access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured.

CISA KEV Alert: Added on 8/27/2026. Action due: 8/30/2026.

AI/MLCloud Security
View CISA Alert
Exploited in wild

CVE-2015-5287

MEDIUM (6.9)
Vendor: Red HatProduct: Automatic Bug Reporting Tool8/26/2026

Red Hat Automatic Bug Reporting Tool (ABRT) contains a privilege escalation vulnerability that could allow local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.

CISA KEV Alert: Added on 8/26/2026. Action due: 9/9/2026.

AI/MLRansomware
View CISA Alert
Exploited in wild

CVE-2026-8452

CRITICAL (9.8)
Vendor: CitrixProduct: NetScaler ADC and NetScaler Gateway8/26/2026

Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability which could lead to denial of service.

CISA KEV Alert: Added on 8/26/2026. Action due: 8/29/2026.

Exploited in wild

CVE-2021-23758

HIGH (8.1)
Vendor: Ajax.NET ProfessionalProduct: Ajax.NET Professional8/26/2026

Ajax.NET Professional (AjaxPro) contains a deserialization of untrusted data vulnerability that could allow for remote code execution via arbitrary .NET classes. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.

CISA KEV Alert: Added on 8/26/2026. Action due: 9/9/2026.

AI/MLRansomware
View CISA Alert
Exploited in wild

CVE-2022-0995

HIGH (7.8)
Vendor: LinuxProduct: Kernel8/26/2026

Linux Kernel contains an out-of-bounds memory write vulnerability which could allow a local user to gain privileged access or cause a denial of service on the system.

CISA KEV Alert: Added on 8/26/2026. Action due: 9/9/2026.

Exploited in wild

CVE-2015-3246

HIGH (7.2)
Vendor: Red HatProduct: Libuser8/26/2026

Red Hat libuser contains a race condition vulnerability that allows authenticated local users to corrupt the /etc/passwd file to cause a denial of service or privilege escalation.

CISA KEV Alert: Added on 8/26/2026. Action due: 9/9/2026.

Exploited in wild

CVE-2019-1068

HIGH (8.8)
Vendor: MicrosoftProduct: SQL Server8/26/2026

Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine service account.

CISA KEV Alert: Added on 8/26/2026. Action due: 8/29/2026.

AI/MLMicrosoft
View CISA Alert
Exploited in wild

CVE-2026-60004

CRITICAL (9.8)
Vendor: GiteaProduct: Gitea8/25/2026

Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

CISA KEV Alert: Added on 8/25/2026. Action due: 8/28/2026.

Exploited in wild

CVE-2026-21962

CRITICAL (10)
Vendor: OracleProduct: HTTP Server and Oracle Weblogic Server Proxy Plug-in8/24/2026

Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in contain an improper access control vulnerability that can result in unauthorized creation, deletion or modification access to critical data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in accessible data.

CISA KEV Alert: Added on 8/24/2026. Action due: 8/27/2026.