Known Exploited Vulnerabilities Tracker
Not every vulnerability matters equally. This page tracks the ones that are confirmed to be under active attack: entries added to the CISA Known Exploited Vulnerabilities catalog in the last 90 days. US federal agencies are legally required to patch these by the listed due date; for everyone else they are the shortest useful patching queue in security.
Where we have reported on a vulnerability, the last column links to that coverage. The table refreshes daily from the official CISA feed.
| Added | CVE | Vendor / Product | Vulnerability | Ransomware | Patch due | Our coverage |
|---|---|---|---|---|---|---|
| 2026-08-04 | CVE-2026-18556 | N-able N-central | N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability | — | 2026-08-07 | N-central vulnerability: Why the first patch fell short |
| 2026-08-04 | CVE-2026-34486 | Apache Tomcat | Apache Tomcat Missing Encryption of Sensitive Data Vulnerability | — | 2026-08-07 | — |
| 2026-08-04 | CVE-2026-9198 | IBM Langflow | IBM Langflow Code Injection Vulnerability | — | 2026-08-07 | — |
| 2026-08-03 | CVE-2026-18577 | N-able N-central | N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability | — | 2026-08-06 | N-central vulnerability: Why the first patch fell short |
| 2026-07-29 | CVE-2026-20316 | Cisco Secure Firewall Management Center (FMC) | Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability | — | 2026-08-01 | Cisco FMC Zero-Day Exploited: Immediate Action Required |
| 2026-07-27 | CVE-2025-68686 | Fortinet FortiOS | Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability | — | 2026-08-10 | — |
| 2026-07-27 | CVE-2026-16812 | Arista VeloCloud Orchestrator | Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability | — | 2026-07-30 | Arista patches critical VeloCloud Orchestrator vulnerability |
| 2026-07-22 | CVE-2026-16232 | Check Point SmartConsole | Check Point SmartConsole Improper Authentication Vulnerability | — | 2026-07-25 | Check Point SmartConsole exploit: Critical patch details |
| 2026-07-22 | CVE-2026-50522 | Microsoft SharePoint | Microsoft SharePoint Deserialization of Untrusted Data Vulnerability | — | 2026-07-25 | — |
| 2026-07-21 | CVE-2026-60137 | WordPress Core | WordPress Core SQL Injection Vulnerability | — | 2026-08-04 | WordPress wp2shell exploit: RCE flaws and patches |
| 2026-07-21 | CVE-2026-63030 | WordPress Core | WordPress Core Interpretation Conflict Vulnerability | — | 2026-07-24 | WordPress wp2shell exploit: RCE flaws and patches |
| 2026-07-21 | CVE-2026-0770 | Langflow Langflow | Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability | — | 2026-07-24 | — |
| 2026-07-21 | CVE-2021-27137 | DD-WRT DD-WRT | DD-WRT Stack-Based Buffer Overflow Vulnerability | — | 2026-07-24 | — |
| 2026-07-16 | CVE-2026-58644 | Microsoft SharePoint | Microsoft SharePoint Deserialization of Untrusted Data Vulnerability | — | 2026-07-19 | — |
| 2026-07-16 | CVE-2026-25089 | Fortinet FortiSandbox | Fortinet FortiSandbox OS Command Injection Vulnerability | — | 2026-07-19 | — |
| 2026-07-16 | CVE-2026-39808 | Fortinet FortiSandbox | Fortinet FortiSandbox OS Command Injection Vulnerability | — | 2026-07-19 | — |
| 2026-07-15 | CVE-2026-46817 | Oracle E-Business Suite | Oracle E-Business Suite Improper Privilege Management Vulnerability | — | 2026-07-18 | — |
| 2026-07-15 | CVE-2023-4346 | KNX Association KNX Protocol Connection Authorization Option 1 | KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability | — | 2026-07-29 | — |
| 2026-07-14 | CVE-2026-56155 | Microsoft Active Directory Federation Services | Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability | — | 2026-07-28 | — |
| 2026-07-14 | CVE-2026-56164 | Microsoft SharePoint Server | Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability | — | 2026-07-17 | — |
| 2026-07-14 | CVE-2026-15409 | SonicWall SMA1000 Appliances | SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability | Known | 2026-07-17 | SonicWall zero-day exploits reveal custom malware chain |
| 2026-07-14 | CVE-2026-15410 | SonicWall SMA1000 Appliances | SonicWall SMA1000 Appliances Code Injection Vulnerability | Known | 2026-07-17 | SonicWall zero-day exploits reveal custom malware chain |
| 2026-07-13 | CVE-2008-4128 | Cisco IOS | Cisco IOS Cross-Site Request Forgery Vulnerability | — | 2026-07-16 | — |
| 2026-07-10 | CVE-2026-56291 | Balbooa Forms | Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability | — | 2026-07-13 | — |
| 2026-07-10 | CVE-2026-48939 | iCagenda iCagenda | iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability | — | 2026-07-13 | — |
| 2026-07-07 | CVE-2026-48908 | JoomShaper SP Page Builder | JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability | — | 2026-07-10 | — |
| 2026-07-07 | CVE-2026-55255 | Langflow Langflow | Langflow Authorization Bypass Through User-Controlled Key Vulnerability | — | 2026-07-10 | — |
| 2026-07-07 | CVE-2026-56290 | Joomlack Page Builder | Joomlack Page Builder Improper Access Control Vulnerability | — | 2026-07-10 | — |
| 2026-07-07 | CVE-2026-48282 | Adobe ColdFusion | Adobe ColdFusion Path Traversal Vulnerability | — | 2026-07-10 | — |
| 2026-07-01 | CVE-2026-45659 | Microsoft SharePoint Server | Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability | — | 2026-07-04 | — |
| 2026-06-29 | CVE-2026-48558 | SimpleHelp SimpleHelp | SimpleHelp Authentication Bypass Vulnerability | — | 2026-07-02 | — |
| 2026-06-25 | CVE-2026-12569 | PTC Windchill and FlexPLM | PTC Windchill and FlexPLM Improper Input Validation Vulnerability | Known | 2026-06-28 | Cl0p Exploits PTC Windchill RCE in New Ransomware Campaign |
| 2026-06-25 | CVE-2026-20230 | Cisco Unified Communications Manager | Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability | — | 2026-06-28 | — |
| 2026-06-23 | CVE-2025-67038 | Lantronix EDS5000 | Lantronix EDS5000 Code Injection Vulnerability | — | 2026-06-26 | — |
| 2026-06-23 | CVE-2026-34910 | Ubiquiti UniFi OS | Ubiquiti UniFi OS Improper Input Validation Vulnerability | — | 2026-06-26 | — |
| 2026-06-23 | CVE-2026-34909 | Ubiquiti UniFi OS | Ubiquiti UniFi OS Path Traversal Vulnerability | — | 2026-06-26 | — |
| 2026-06-23 | CVE-2026-34908 | Ubiquiti UniFi OS | Ubiquiti UniFi OS Improper Access Control Vulnerability | — | 2026-06-26 | — |
| 2026-06-18 | CVE-2026-20253 | Splunk Enterprise | Splunk Enterprise Missing Authentication for Critical Function Vulnerability | — | 2026-06-21 | — |
| 2026-06-16 | CVE-2026-48907 | Widget Factory Joomla Content Editor | Widget Factory Joomla Content Editor Improper Access Control Vulnerability | — | 2026-06-19 | — |
| 2026-06-15 | CVE-2026-54420 | LiteSpeed cPanel Plugin | LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability | — | 2026-06-18 | — |
| 2026-06-15 | CVE-2026-20262 | Cisco Catalyst SD-WAN Manager | Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability | — | 2026-06-29 | — |
| 2026-06-12 | CVE-2026-35273 | Oracle PeopleSoft Enterprise PeopleTools | Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability | Known | 2026-06-15 | — |
| 2026-06-11 | CVE-2026-10520 | Ivanti Sentry | Ivanti Sentry OS Command Injection Vulnerability | — | 2026-06-14 | — |
| 2026-06-09 | CVE-2026-11645 | Google Chromium V8 | Google Chromium V8 Out-of-Bounds Read and Write Vulnerability | — | 2026-06-23 | — |
| 2026-06-09 | CVE-2026-7473 | Arista Extensible Operating System | Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability | — | 2026-06-23 | — |
| 2026-06-09 | CVE-2026-20245 | Cisco Catalyst SD-WAN Manager | Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability | — | 2026-06-23 | — |
| 2026-06-08 | CVE-2026-42271 | BerriAI LiteLLM | BerriAI LiteLLM Command Injection Vulnerability | — | 2026-06-22 | — |
| 2026-06-08 | CVE-2026-50751 | Check Point Security Gateway | Check Point Security Gateway Improper Authentication Vulnerability | Known | 2026-06-11 | — |
| 2026-06-05 | CVE-2026-28318 | SolarWinds Serv-U | SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability | — | 2026-06-19 | — |
| 2026-06-03 | CVE-2026-45247 | Mirasvit Mirasvit Full Page Cache Warmer | Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability | — | 2026-06-06 | — |
| 2026-06-02 | CVE-2022-0492 | Linux Kernel | Linux Kernel Improper Authentication Vulnerability | — | 2026-06-05 | — |
| 2026-06-02 | CVE-2025-48595 | Android Framework | Android Framework Integer Overflow Vulnerability | — | 2026-06-05 | — |
| 2026-06-01 | CVE-2024-21182 | Oracle WebLogic Server | Oracle WebLogic Server Unspecified Vulnerability | — | 2026-06-04 | — |
| 2026-05-29 | CVE-2026-0257 | Palo Alto Networks PAN-OS | Palo Alto Networks PAN-OS Authentication Bypass Vulnerability | Known | 2026-06-01 | Qilin Ransomware Exploits PAN-OS Authentication Bypass |
| 2026-05-27 | CVE-2026-48027 | Nx Nx Console | Nx Console Embedded Malicious Code Vulnerability | Known | 2026-06-10 | — |
| 2026-05-27 | CVE-2026-45321 | TanStack TanStack | TanStack Unspecified Vulnerability | Known | 2026-06-10 | — |
| 2026-05-27 | CVE-2026-8398 | Daemon Daemon Tools Lite | Daemon Tools Lite Embedded Malicious Code Vulnerability | — | 2026-05-30 | — |
| 2026-05-26 | CVE-2026-48172 | LiteSpeed cPanel Plugin | LiteSpeed cPanel Plugin Privilege Escalation Vulnerability | — | 2026-05-29 | — |
| 2026-05-22 | CVE-2026-9082 | Drupal Core | Drupal Core SQL Injection Vulnerability | — | 2026-05-27 | — |
| 2026-05-21 | CVE-2025-34291 | Langflow Langflow | Langflow Origin Validation Error Vulnerability | — | 2026-06-04 | — |
| 2026-05-21 | CVE-2026-34926 | Trend Micro Apex One | Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability | — | 2026-06-04 | — |
| 2026-05-20 | CVE-2008-4250 | Microsoft Windows | Microsoft Windows Buffer Overflow Vulnerability | — | 2026-06-03 | — |
| 2026-05-20 | CVE-2009-1537 | Microsoft DirectX | Microsoft DirectX NULL Byte Overwrite Vulnerability | — | 2026-06-03 | — |
| 2026-05-20 | CVE-2009-3459 | Adobe Acrobat and Reader | Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability | — | 2026-06-03 | — |
| 2026-05-20 | CVE-2010-0249 | Microsoft Internet Explorer | Microsoft Internet Explorer Use-After-Free Vulnerability | — | 2026-06-03 | — |
| 2026-05-20 | CVE-2010-0806 | Microsoft Internet Explorer | Microsoft Internet Explorer Use-After-Free Vulnerability | — | 2026-06-03 | — |
| 2026-05-20 | CVE-2026-41091 | Microsoft Defender | Microsoft Defender Link Following Vulnerability | — | 2026-06-03 | — |
| 2026-05-20 | CVE-2026-45498 | Microsoft Defender | Microsoft Defender Denial of Service Vulnerability | — | 2026-06-03 | — |
| 2026-05-15 | CVE-2026-42897 | Microsoft Microsoft | Microsoft Exchange Server Cross-Site Scripting Vulnerability | — | 2026-05-29 | Microsoft Exchange Zero-Day Exploited in OWA Attacks |
| 2026-05-14 | CVE-2026-20182 | Cisco Catalyst SD-WAN | Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability | — | 2026-05-17 | CISA Flags Cisco SD-WAN Flaw Exploited in Wild |
| 2026-05-08 | CVE-2026-42208 | BerriAI LiteLLM | BerriAI LiteLLM SQL Injection Vulnerability | — | 2026-05-11 | — |
| 2026-05-07 | CVE-2026-6973 | Ivanti Endpoint Manager Mobile (EPMM) | Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability | — | 2026-05-10 | CISA Orders Ivanti Patch in 4 Days Amid Zero-Day Exploits |
Source: CISA Known Exploited Vulnerabilities catalog (version 2026.08.04). Last updated 05 August 2026, 09:35 UTC. Patch due dates apply to US federal civilian agencies under BOD 22-01; other organisations should treat them as a recommended maximum.

