Exploitation dashboard
Actively exploited vulnerabilities
Every vulnerability here has reliable evidence of exploitation in the wild, based on the CISA Known Exploited Vulnerabilities catalog. If you run an affected product, patch or mitigate it first.
1,734
Known exploited (all time)
39
Added in last 30 days
361
Used by ransomware
1,734 matching vulnerabilities
| CVE | Vendor / product | Vulnerability | Severity | Added | Ransomware |
|---|---|---|---|---|---|
| CVE-2026-88779 | Citrix | Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability | Severity: High CVSS 8.7 | Oct 4, 2026 | Not known |
| CVE-2026-102489 | Zammad GmbH | Zammad GmbH Zammad Session Fixation Vulnerability | Severity: Critical CVSS 9.4 | Oct 2, 2026 | Not known |
| CVE-2026-102490 | Zammad GmbH | Zammad GmbH Zammad Improper Privilege Management Vulnerability | Severity: Critical CVSS 9.4 | Oct 2, 2026 | Not known |
| CVE-2026-104286 | Fortinet | Fortinet FortiMail Path Traversal Vulnerability | Unscored | Oct 1, 2026 | Not known |
| CVE-2026-76504 | Cisco | Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability | Severity: Critical CVSS 9.8 | Sep 30, 2026 | Not known |
| CVE-2026-86950 | Apple | Apple Multiple Products Out-of-Bounds Write Vulnerability | Severity: High CVSS 8.8 | Sep 29, 2026 | Not known |
| CVE-2026-88771 | Citrix | Citrix NetScaler Improper Input Validation Vulnerability | Severity: Critical CVSS 9.5 | Sep 27, 2026 | Not known |
| CVE-2026-88772 | Citrix | Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability | Severity: Critical CVSS 9.5 | Sep 27, 2026 | Not known |
| CVE-2026-65660 | Microsoft | Microsoft SharePoint Code Injection Vulnerability | Severity: High CVSS 8.8 | Sep 25, 2026 | Not known |
| CVE-2026-87902 | WordPress | WordPress Core Remote File Inclusion Vulnerability | Severity: High CVSS 8.1 | Sep 25, 2026 | Not known |
| CVE-2026-67279 | MikroTik | Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability | Severity: Elevated CVSS 6.9 | Sep 25, 2026 | Not known |
| CVE-2026-5430 | WSO2 | WSO2 Multiple Products Path Traversal Vulnerability | Severity: Critical CVSS 10.0 | Sep 24, 2026 | Not known |
| CVE-2026-71362 | Adobe | Adobe Commerce and Magento Incorrect Authorization Vulnerability | Severity: Critical CVSS 9.1 | Sep 24, 2026 | Not known |
| CVE-2026-85102 | Check Point | Check Point Multiple Products Improper Certificate Validation Vulnerability | Severity: Critical CVSS 9.8 | Sep 22, 2026 | Not known |
| CVE-2026-93616 | Check Point | Check Point Multiple Products Path Traversal Vulnerability | Severity: Critical CVSS 9.8 | Sep 22, 2026 | Not known |
| CVE-2026-93952 | Arista | Arista VeloCloud Orchestrator Improper Input Validation Vulnerability | Severity: Critical CVSS 9.5 | Sep 22, 2026 | Not known |
| CVE-2026-94127 | F5 | F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability | Severity: Critical CVSS 9.3 | Sep 22, 2026 | Not known |
| CVE-2026-7273 | Zyxel | Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability | Severity: High CVSS 8.8 | Sep 21, 2026 | Not known |
| CVE-2025-39682 | Linux | Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability | Severity: Critical CVSS 9.8 | Sep 18, 2026 | Not known |
| CVE-2026-53266 | Linux | Linux Kernel Out-of-Bounds Write Vulnerability | Severity: High CVSS 8.8 | Sep 18, 2026 | Not known |
| CVE-2025-39964 | Linux | Linux Kernel Race Condition Vulnerability | Severity: Elevated CVSS 5.5 | Sep 18, 2026 | Not known |
| CVE-2026-76460 | Cisco | Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability | Severity: Critical CVSS 10.0 | Sep 16, 2026 | Not known |
| CVE-2026-58704 | Google Pixel Improper Authorization Vulnerability | Severity: High CVSS 8.8 | Sep 16, 2026 | Not known | |
| CVE-2026-87886 | Acronis | Acronis Backup Incorrect Default Permissions Vulnerability | Severity: High CVSS 7.8 | Sep 16, 2026 | Not known |
| CVE-2026-76461 | Cisco | Cisco Secure Email Gateway SQL Injection Vulnerability | Severity: Critical CVSS 9.8 | Sep 14, 2026 | Not known |
| CVE-2026-85706 | GitLab | GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability | Severity: Critical CVSS 10.0 | Sep 11, 2026 | Not known |
| CVE-2026-84869 | ConnectWise | ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability | Severity: Critical CVSS 9.9 | Sep 11, 2026 | Not known |
| CVE-2026-42016 | JFrog | JFrog Artifactory Incorrect Authorization Vulnerability | Severity: High CVSS 8.8 | Sep 11, 2026 | Not known |
| CVE-2026-42018 | JFrog | JFrog Artifactory Improper Authentication Vulnerability | Severity: High CVSS 7.5 | Sep 11, 2026 | Not known |
| CVE-2026-86060 | MikroTik | MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability | Severity: Critical CVSS 9.2 | Sep 10, 2026 | Not known |
| CVE-2026-67277 | MikroTik | MikroTik RouterOS Missing Authentication for Critical Function Vulnerability | Severity: High CVSS 8.8 | Sep 10, 2026 | Not known |
| CVE-2026-20079 | Cisco | Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability | Severity: Critical CVSS 10.0 | Sep 9, 2026 | Not known |
| CVE-2025-25249 | Fortinet | Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability | Severity: Critical CVSS 9.8 | Sep 9, 2026 | Not known |
| CVE-2026-19490 | Citrix | Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability | Severity: Critical CVSS 9.3 | Sep 9, 2026 | Not known |
| CVE-2026-87491 | Google Chromium V8 Out of Bounds Write Vulnerability | Severity: High CVSS 8.8 | Sep 9, 2026 | Not known | |
| CVE-2026-75650 | Adobe | Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability | Severity: Critical CVSS 10.0 | Sep 8, 2026 | Not known |
| CVE-2026-86218 | N-able | N-able N-central Static Code Injection Vulnerability | Severity: Critical CVSS 10.0 | Sep 8, 2026 | Not known |
| CVE-2026-81963 | Microsoft | Microsoft Windows Link Following Vulnerability | Severity: High CVSS 7.8 | Sep 8, 2026 | Not known |
| CVE-2026-85880 | Microsoft | Microsoft Windows Heap-Based Buffer Overflow Vulnerability | Severity: High CVSS 7.8 | Sep 8, 2026 | Not known |
| CVE-2026-85046 | Google Chromium V8 Type Confusion Vulnerability | Severity: High CVSS 8.8 | Sep 4, 2026 | Not known |
Source: CISA Known Exploited Vulnerabilities catalog (US government, public domain), refreshed hourly. CVSS scores from the NIST National Vulnerability Database are added as they are fetched.
