SignalSec: Vulns & Hacks

Known Exploited Vulnerabilities and latest CVEs

Exploited in wild
Vendor: MicrosoftProduct: Windows Ancillary Function Driver for WinSock 8/11/2026

Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.

CISA KEV Alert: Added on 8/11/2026. Action due: 8/25/2026.

AI/MLMicrosoft
View CISA Alert
Exploited in wild

CVE-2026-72898

CRITICAL (10)
Vendor: MetabaseProduct: Metabase8/11/2026

Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.

CISA KEV Alert: Added on 8/11/2026. Action due: 8/14/2026.

Exploited in wild

CVE-2026-20349

HIGH (8.6)
Vendor: CiscoProduct: Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) 8/11/2026

Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.

CISA KEV Alert: Added on 8/11/2026. Action due: 8/14/2026.

Exploited in wild

CVE-2026-8037

CRITICAL (9.6)
Vendor: ProgressProduct: LoadMaster8/7/2026

Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints.

CISA KEV Alert: Added on 8/7/2026. Action due: 8/10/2026.

Exploited in wild

CVE-2026-18577

HIGH (8.1)
Vendor: N-ableProduct: N-central8/3/2026

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

CISA KEV Alert: Added on 8/3/2026. Action due: 8/6/2026.

Exploited in wild

CVE-2026-18556

HIGH (7.4)
8/1/2026

Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.

CISA KEV Alert: Added on 8/4/2026. Action due: 8/7/2026.

Exploited in wild

CVE-2026-20316

MEDIUM (5.3)
Vendor: CiscoProduct: Secure Firewall Management Center (FMC)7/29/2026

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the presence of static user credentials for a low-privileged account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user.  Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.   Cisco has assigned this security advisory a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that this vulnerability can be used with other Cisco Secure FMC Software vulnerabilities to elevate privileges.

CISA KEV Alert: Added on 7/29/2026. Action due: 8/1/2026.

Exploited in wild

CVE-2026-63077

CRITICAL (9.8)
7/27/2026

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

CISA KEV Alert: Added on 8/5/2026. Action due: 8/8/2026.

Exploited in wild

CVE-2026-16812

CRITICAL (10)
Vendor: AristaProduct: VeloCloud Orchestrator7/27/2026

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. This functionality was intended to be for internal use only and is not intended to be remotely accessible. Hosted and Dedicated versions of VCO have already been patched in advance of this notice going out. This issue was discovered externally and is known to be actively exploited.

CISA KEV Alert: Added on 7/27/2026. Action due: 7/30/2026.

AI/MLCloud Security
View CISA Alert
Exploited in wild

CVE-2025-68686

MEDIUM (5.9)
Vendor: FortinetProduct: FortiOS7/27/2026

Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.

CISA KEV Alert: Added on 7/27/2026. Action due: 8/10/2026.

AI/MLData BreachApple
View CISA Alert
Exploited in wild

CVE-2026-16232

CRITICAL (9.1)
Vendor: Check PointProduct: SmartConsole7/22/2026

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers.

CISA KEV Alert: Added on 7/22/2026. Action due: 7/25/2026.

Exploited in wild

CVE-2026-50522

CRITICAL (9.8)
Vendor: MicrosoftProduct: SharePoint7/22/2026

Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.

CISA KEV Alert: Added on 7/22/2026. Action due: 7/25/2026.

AI/MLMicrosoft
View CISA Alert
Exploited in wild

CVE-2026-60137

MEDIUM (5.9)
Vendor: WordPressProduct: Core7/21/2026

WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations.

CISA KEV Alert: Added on 7/21/2026. Action due: 8/4/2026.

Exploited in wild

CVE-2026-0770

CRITICAL (9.8)
Vendor: LangflowProduct: Langflow7/21/2026

Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations.

CISA KEV Alert: Added on 7/21/2026. Action due: 7/24/2026.

Exploited in wild

CVE-2026-63030

CRITICAL (9.8)
Vendor: WordPressProduct: Core7/21/2026

WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.

CISA KEV Alert: Added on 7/21/2026. Action due: 7/24/2026.

Exploited in wild

CVE-2026-9198

CRITICAL (9.8)
7/17/2026

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments

CISA KEV Alert: Added on 8/4/2026. Action due: 8/7/2026.

Exploited in wild

CVE-2021-27137

HIGH (8.1)
7/16/2026

An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality allows an unauthenticated remote attacker to send a request that would overflow an internal fixed buffer. Exploitation requires the DD-WRT user to enable UPnP (which is off by default, and only listens on internal interfaces by default). This occurs in ssdp_msearch (reachable by an M-SEARCH request).

CISA KEV Alert: Added on 7/21/2026. Action due: 7/24/2026.

Exploited in wild

CVE-2026-39808

CRITICAL (9.8)
Vendor: FortinetProduct: FortiSandbox7/16/2026

Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.

CISA KEV Alert: Added on 7/16/2026. Action due: 7/19/2026.

Exploited in wild

CVE-2026-58644

CRITICAL (9.8)
Vendor: MicrosoftProduct: SharePoint7/16/2026

Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.

CISA KEV Alert: Added on 7/16/2026. Action due: 7/19/2026.

AI/MLMicrosoft
View CISA Alert
Exploited in wild

CVE-2023-4346

HIGH (7.5)
Vendor: KNX AssociationProduct: KNX Protocol Connection Authorization Option 17/15/2026

KNX Association KNX Protocol Connection Authorization Option 1 contains an overly restrictive account lockout mechanism vulnerability that could allow an attacker to purge all devices without additional security options enabled and set a BCU key to lock the device.

CISA KEV Alert: Added on 7/15/2026. Action due: 7/29/2026.

Exploited in wild

CVE-2026-15410

HIGH (7.2)
Vendor: SonicWallProduct: SMA1000 Appliances7/14/2026

Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.

CISA KEV Alert: Added on 7/14/2026. Action due: 7/17/2026.

Exploited in wild

CVE-2026-15409

CRITICAL (10)
Vendor: SonicWallProduct: SMA1000 Appliances7/14/2026

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.

CISA KEV Alert: Added on 7/14/2026. Action due: 7/17/2026.

Exploited in wild

CVE-2026-56155

HIGH (7.8)
Vendor: MicrosoftProduct: Active Directory Federation Services7/14/2026

Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally.

CISA KEV Alert: Added on 7/14/2026. Action due: 7/28/2026.

AI/MLMicrosoft
View CISA Alert
Exploited in wild

CVE-2026-56164

MEDIUM (5.3)
Vendor: MicrosoftProduct: SharePoint Server7/14/2026

Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network.

CISA KEV Alert: Added on 7/14/2026. Action due: 7/17/2026.

AI/MLMicrosoft
View CISA Alert
Exploited in wild

CVE-2008-4128

MEDIUM (4.3)
Vendor: CiscoProduct: IOS7/13/2026

Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI.

CISA KEV Alert: Added on 7/13/2026. Action due: 7/16/2026.

Exploited in wild

CVE-2026-56291

CRITICAL (9.8)
Vendor: BalbooaProduct: Forms7/10/2026

The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

CISA KEV Alert: Added on 7/10/2026. Action due: 7/13/2026.

Exploited in wild

CVE-2026-55255

CRITICAL (9.9)
Vendor: LangflowProduct: Langflow7/7/2026

Langflow contains an authorization bypass through user-controlled key vulnerability which allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request.

CISA KEV Alert: Added on 7/7/2026. Action due: 7/10/2026.

Exploited in wild

CVE-2026-56290

CRITICAL (9.8)
Vendor: JoomlackProduct: Page Builder7/7/2026

Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload.

CISA KEV Alert: Added on 7/7/2026. Action due: 7/10/2026.

Exploited in wild

CVE-2026-45659

HIGH (8.8)
Vendor: MicrosoftProduct: SharePoint Server7/1/2026

Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.

CISA KEV Alert: Added on 7/1/2026. Action due: 7/4/2026.

AI/MLMicrosoft
View CISA Alert
Exploited in wild

CVE-2026-48282

CRITICAL (10)
6/30/2026

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

CISA KEV Alert: Added on 7/7/2026. Action due: 7/10/2026.

Exploited in wild

CVE-2026-48939

CRITICAL (9.8)
6/20/2026

A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

CISA KEV Alert: Added on 7/10/2026. Action due: 7/13/2026.

Exploited in wild

CVE-2026-48908

CRITICAL (9.8)
6/20/2026

A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.

CISA KEV Alert: Added on 7/7/2026. Action due: 7/10/2026.

Exploited in wild

CVE-2026-12569

CRITICAL (9.8)
6/18/2026

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.  * This advisory also applies to all CPS versions * The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030

CISA KEV Alert: Added on 6/25/2026. Action due: 6/28/2026.

Exploited in wild

CVE-2026-54420

HIGH (8.5)
Vendor: LiteSpeedProduct: cPanel Plugin6/15/2026

LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS, as exploited in the wild in May 2026.

CISA KEV Alert: Added on 6/15/2026. Action due: 6/18/2026.

Cloud SecurityLinux
View CISA Alert
Exploited in wild

CVE-2026-20262

MEDIUM (6.5)
Vendor: CiscoProduct: Catalyst SD-WAN Manager6/15/2026

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system. This vulnerability exists because the affected software does not properly validate user-supplied input during a file upload process. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected API endpoint of the affected system. A successful exploit could allow the attacker to create or overwrite any file on the underlying operating system. This file could later be used to elevate to root. To exploit this vulnerability, the attacker must have valid credentials with at least a lower-privileged, single-task user account.

CISA KEV Alert: Added on 6/15/2026. Action due: 6/29/2026.

Exploited in wild

CVE-2026-48558

CRITICAL (10)
6/12/2026

SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication. No user interaction is required.

CISA KEV Alert: Added on 6/29/2026. Action due: 7/2/2026.

AI/MLCrypto
View CISA Alert
Exploited in wild

CVE-2026-35273

CRITICAL (9.8)
Vendor: OracleProduct: PeopleSoft Enterprise PeopleTools6/12/2026

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CISA KEV Alert: Added on 6/12/2026. Action due: 6/15/2026.

Exploited in wild

CVE-2026-10520

CRITICAL (10)
Vendor: IvantiProduct: Sentry6/11/2026

An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution

CISA KEV Alert: Added on 6/11/2026. Action due: 6/14/2026.

Exploited in wild

CVE-2026-20253

CRITICAL (9.8)
6/10/2026

In Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.3 and 10.2.2510.14, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint.<br><br>The vulnerability exists because the PostgreSQL sidecar service endpoint lacks authentication controls, allowing any network-reachable user to invoke file operations without credentials.

CISA KEV Alert: Added on 6/18/2026. Action due: 6/21/2026.

Exploited in wild

CVE-2026-25089

CRITICAL (9.8)
6/9/2026

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests

CISA KEV Alert: Added on 7/16/2026. Action due: 7/19/2026.

AI/MLCloud Security
View CISA Alert
Exploited in wild

CVE-2026-20245

HIGH (7.8)
Vendor: CiscoProduct: Catalyst SD-WAN Manager6/9/2026

Cisco Catalyst SD-WAN Manager formerly SD-WAN vManage contains an improper encoding or escaping of output vulnerability. This vulnerability could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system.

CISA KEV Alert: Added on 6/9/2026. Action due: 6/23/2026.

Exploited in wild

CVE-2026-11645

HIGH (8.8)
Vendor: GoogleProduct: Chromium V86/9/2026

Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CISA KEV Alert: Added on 6/9/2026. Action due: 6/23/2026.

Exploited in wild

CVE-2026-50751

CRITICAL (9.3)
Vendor: Check PointProduct: Security Gateway6/8/2026

A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.

CISA KEV Alert: Added on 6/8/2026. Action due: 6/11/2026.

Exploited in wild

CVE-2026-7473

MEDIUM (5.8)
6/5/2026

On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly decapsulate and forward other unexpected tunneled packet with a destination IP matching its configured decapsulation IP. This occurs because the switch does not verify the tunnel protocol type, potentially leading to the unexpected processing of non-configured tunnel traffic. This issue has been reported as being exploited in the wild.

CISA KEV Alert: Added on 6/9/2026. Action due: 6/23/2026.

Exploited in wild

CVE-2026-48907

CRITICAL (9.8)
6/5/2026

A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.

CISA KEV Alert: Added on 6/16/2026. Action due: 6/19/2026.

Exploited in wild

CVE-2026-28318

HIGH (7.5)
Vendor: SolarWindsProduct: Serv-U6/5/2026

SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate. Mitigation steps are provided to secure customer environments in the SolarWinds Trust Center if you are unable to deploy the update

CISA KEV Alert: Added on 6/5/2026. Action due: 6/19/2026.

Exploited in wild

CVE-2026-20230

HIGH (8.6)
6/3/2026

A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to write files to the underlying operating system that could be used later to elevate to root. Note: Cisco has assigned this security advisory a Security Impact Rating (SIR) of Critical rather than High as the score indicates. The reason is that exploitation of this vulnerability could result in an attacker elevating privileges to root. Note: To exploit this vulnerability, the WebDialer service must be enabled. WebDialer is disabled by default.

CISA KEV Alert: Added on 6/25/2026. Action due: 6/28/2026.

Exploited in wild

CVE-2022-0492

HIGH (7.8)
Vendor: LinuxProduct: Kernel6/2/2026

Linux Kernel contains an improper authentication vulnerability which could allow for privilege escalation via the cgroups v1 release_agent feature.

CISA KEV Alert: Added on 6/2/2026. Action due: 6/5/2026.

Exploited in wild

CVE-2025-48595

HIGH (8.4)
Vendor: AndroidProduct: Framework6/2/2026

In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CISA KEV Alert: Added on 6/2/2026. Action due: 6/5/2026.

Exploited in wild

CVE-2024-21182

HIGH (7.5)
Vendor: OracleProduct: WebLogic Server6/1/2026

Oracle WebLogic contains an unspecified vulnerability that could allow an unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data.

CISA KEV Alert: Added on 6/1/2026. Action due: 6/4/2026.