Vulnerabilities

Summary — last 7 days

New vulnerabilities3,255▲ 261 vs. last week
Critical / high1,444▲ 70 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)607▲ 133 vs. last week
–

1,730 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
AnalyzedCritical (9.8)—⚠ Active exploitationCisco Catalyst Sd-wan Manager9/30/202610/1/2026A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system. A successful exploit could allow the attacker to bypass authentication and gain access to the API as the admin user.
AnalyzedHigh (8.8)1.2%⚠ Active exploitationApple IpadosApple Iphone OSApple Macos9/28/20269/30/2026An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.
AnalyzedCritical (9.5)1.3%⚠ Active exploitationCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway9/27/20269/28/2026Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service
AnalyzedCritical (9.5)1.1%⚠ Active exploitationCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway9/27/20269/29/2026Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.
AnalyzedHigh (8.1)20%⚠ Active exploitationWordpress9/22/20269/28/2026An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.
AnalyzedCritical (9.3)2.2%⚠ Active exploitationF5 Big-ip Access Policy Manager9/22/20269/23/2026When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected by this vulnerability. Impact: This vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AnalyzedCritical (9.8)20%⚠ Active exploitationCheckpoint Multi-domain Security ManagementCheckpoint Quantum Security Management9/22/20269/23/2026A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.
AnalyzedCritical (9.5)1.1%⚠ Active exploitationArista Velocloud Orchestrator9/22/20269/23/2026VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. Hosted, including Dedicated, versions of VCO were impacted and have already been patched.
AnalyzedHigh (7.8)0.23%⚠ Active exploitationAcronis Backup9/17/20269/18/2026Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux) before build 1.8.11.638, Acronis Backup plugin for DirectAdmin (Linux) before build 1.2.3.238.
AnalyzedCritical (10)14%⚠ Active exploitationCisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector9/16/20269/25/2026A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.
AnalyzedHigh (8.8)0.59%⚠ Active exploitationGoogle Android9/15/20269/17/2026In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
AnalyzedCritical (9.8)28%⚠ Active exploitationCisco Asyncos9/14/20269/15/2026A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.
AnalyzedCritical (10)91%⚠ Active exploitationGitlab9/12/20269/24/2026GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.11.12, 19.0 before 19.0.9, 19.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.
AnalyzedCritical (9.8)7.5%⚠ Active exploitationCheckpoint Gaia EmbeddedCheckpoint Gaia OS9/9/20269/23/2026Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.
AnalyzedHigh (8.8)3.1%⚠ Active exploitationGoogle Chrome9/9/20269/21/2026Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
AnalyzedCritical (9.9)0.92%⚠ Active exploitationConnectwise Screenconnect9/8/20269/12/2026A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.
AnalyzedHigh (7.8)3.6%⚠ Active exploitationMicrosoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+49/8/20269/24/2026Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.
AnalyzedHigh (7.8)0.39%⚠ Active exploitationMicrosoft Windows 11 23h2Microsoft Windows 11 24h2Microsoft Windows 11 25h2Microsoft Windows 11 26h1+19/8/20269/9/2026Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
AnalyzedCritical (10)3.9%⚠ Active exploitationAdobe CommerceAdobe Commerce B2BAdobe Magento9/7/20269/9/2026Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
AnalyzedCritical (10)13%⚠ Active exploitationN-able N-central9/6/20269/9/2026N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.
AnalyzedCritical (9.2)1.8%⚠ Active exploitationMikrotik Routeros9/5/20269/11/2026RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
AnalyzedMedium (6.9)1.0%⚠ Active exploitationMikrotik Routeros9/5/20269/26/2026RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request. On affected builds the server dispatches the command, enabling unauthenticated creation, overwrite, and reconstruction of files in the RouterOS managed file namespace, including support files containing configuration and diagnostic data.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
AnalyzedHigh (8.8)1.6%⚠ Active exploitationMikrotik Routeros9/5/20269/11/2026RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits an uninitialized tail from a kernel packet buffer. A separate unchecked, inverted packet-size interval causes unsigned integer underflow, anomalously large fragmented output, and can restart the RouterOS kernel. This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
AnalyzedHigh (8.8)49%⚠ Active exploitationGoogle ChromeGoogle V89/3/20269/21/2026Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
AnalyzedHigh (7.8)11%⚠ Active exploitationSonicwall Sma8200vSonicwall Sma6210 FirmwareSonicwall Sma7210 Firmware9/1/20269/21/2026Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.