• Home  
  • Known Exploited Vulnerabilities Tracker

Known Exploited Vulnerabilities Tracker

Not every vulnerability matters equally. This page tracks the ones that are confirmed to be under active attack: entries added to the CISA Known Exploited Vulnerabilities catalog in the last 90 days. US federal agencies are legally required to patch these by the listed due date; for everyone else they are the shortest useful patching queue in security.

Where we have reported on a vulnerability, the last column links to that coverage. The table refreshes daily from the official CISA feed.

Where we have written a full remediation guide for an entry, the last column links to it. Every guide we have published is indexed here.

Everything here is confirmed exploited. For the other side of the question — recent vulnerabilities that exploitation models rate as highly likely to be attacked but that CISA has not listed yet — see our exploit likelihood watchlist.

43Added in last 30 days
98Added in last 90 days
6Used in ransomware
1728Total in catalog
Added CVE Vendor / Product Vulnerability Ransomware Patch due Our coverage
2026-09-27 CVE-2026-88772 Citrix NetScaler Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability — 2026-09-30 —
2026-09-27 CVE-2026-88771 Citrix NetScaler Citrix NetScaler Improper Input Validation Vulnerability — 2026-09-30 —
2026-09-25 CVE-2026-67279 MikroTik RouterOS Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability — 2026-09-28 —
2026-09-25 CVE-2026-65660 Microsoft SharePoint Microsoft SharePoint Code Injection Vulnerability — 2026-09-28 —
2026-09-25 CVE-2026-87902 WordPress Core WordPress Core Remote File Inclusion Vulnerability — 2026-09-28 —
2026-09-24 CVE-2026-5430 WSO2 Multiple Products WSO2 Multiple Products Path Traversal Vulnerability — 2026-09-27 —
2026-09-24 CVE-2026-71362 Adobe Commerce and Magento Adobe Commerce and Magento Incorrect Authorization Vulnerability — 2026-09-27 —
2026-09-22 CVE-2026-93952 Arista VeloCloud Orchestrator Arista VeloCloud Orchestrator Improper Input Validation Vulnerability — 2026-09-25 —
2026-09-22 CVE-2026-94127 F5 BIG-IP APM F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability — 2026-09-25 —
2026-09-22 CVE-2026-93616 Check Point Multiple Products Check Point Multiple Products Path Traversal Vulnerability — 2026-09-25 —
2026-09-22 CVE-2026-85102 Check Point Multiple Products Check Point Multiple Products Improper Certificate Validation Vulnerability — 2026-09-25 —
2026-09-21 CVE-2026-7273 Zyxel GS1900 Series Switches Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability — 2026-09-24 —
2026-09-18 CVE-2025-39964 Linux Kernel Linux Kernel Race Condition Vulnerability — 2026-09-21 —
2026-09-18 CVE-2026-53266 Linux Kernel Linux Kernel Out-of-Bounds Write Vulnerability — 2026-09-21 —
2026-09-18 CVE-2025-39682 Linux Kernel Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability — 2026-09-21 —
2026-09-16 CVE-2026-58704 Google Pixel Google Pixel Improper Authorization Vulnerability — 2026-09-19 —
2026-09-16 CVE-2026-76460 Cisco Identity Services Engine Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability — 2026-09-19 —
2026-09-16 CVE-2026-87886 Acronis Backup Acronis Backup Incorrect Default Permissions Vulnerability — 2026-09-19 —
2026-09-14 CVE-2026-76461 Cisco Secure Email Gateway Cisco Secure Email Gateway SQL Injection Vulnerability — 2026-09-17 —
2026-09-11 CVE-2026-84869 ConnectWise ScreenConnect ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability — 2026-09-14 —
2026-09-11 CVE-2026-42016 JFrog Artifactory JFrog Artifactory Incorrect Authorization Vulnerability — 2026-09-25 —
2026-09-11 CVE-2026-42018 JFrog Artifactory JFrog Artifactory Improper Authentication Vulnerability — 2026-09-25 —
2026-09-11 CVE-2026-85706 GitLab Community Edition and Enterprise Edition GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability — 2026-09-14 —
2026-09-10 CVE-2026-86060 MikroTik RouterOS MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability — 2026-09-13 —
2026-09-10 CVE-2026-67277 MikroTik RouterOS MikroTik RouterOS Missing Authentication for Critical Function Vulnerability — 2026-09-13 —
2026-09-09 CVE-2026-19490 Citrix NetScaler Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability — 2026-09-12 —
2026-09-09 CVE-2025-25249 Fortinet Multiple Products Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability — 2026-09-12 —
2026-09-09 CVE-2026-87491 Google Chromium V8 Google Chromium V8 Out of Bounds Write Vulnerability — 2026-09-23 —
2026-09-09 CVE-2026-20079 Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability — 2026-09-12 —
2026-09-08 CVE-2026-75650 Adobe Commerce and Magento Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability — 2026-09-11 —
2026-09-08 CVE-2026-81963 Microsoft Windows Microsoft Windows Link Following Vulnerability — 2026-09-22 —
2026-09-08 CVE-2026-86218 N-able N-central N-able N-central Static Code Injection Vulnerability — 2026-09-11 —
2026-09-08 CVE-2026-85880 Microsoft Windows Microsoft Windows Heap-Based Buffer Overflow Vulnerability — 2026-09-22 —
2026-09-04 CVE-2026-85046 Google Chromium V8 Google Chromium V8 Type Confusion Vulnerability — 2026-09-18 —
2026-09-02 CVE-2026-59822 BerriAI LiteLLM BerriAI LiteLLM Improper Authentication Vulnerability — 2026-09-16 —
2026-09-02 CVE-2026-48710 Kludex Starlette Kludex Starlette HTTP Request/Response Smuggling Vulnerability — 2026-09-16 —
2026-09-02 CVE-2026-49869 Kestra Kestra OSS Kestra OSS OS Command Injection Vulnerability — 2026-09-05 —
2026-09-02 CVE-2026-82329 JFrog Artifactory JFrog Artifactory Improper Authentication Vulnerability — 2026-09-05 —
2026-09-02 CVE-2026-9586 Sangoma Switchvox Sangoma Switchvox SQL Injection Vulnerability — 2026-09-05 —
2026-09-02 CVE-2026-83548 SonicWall SMA1000 Appliances SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability — 2026-09-05 —
2026-09-02 CVE-2026-83549 SonicWall SMA1000 Appliances SonicWall SMA1000 Appliances OS Command Injection Vulnerability — 2026-09-05 —
2026-08-31 CVE-2026-82078 PaperCut NG/MF PaperCut NG/MF Unsafe Reflection Vulnerability — 2026-09-14 —
2026-08-31 CVE-2026-81578 PaperCut NG/MF PaperCut NG/MF Missing Authentication for Critical Function Vulnerability — 2026-09-14 —
2026-08-27 CVE-2023-49105 ownCloud ownCloud ownCloud Improper Authentication Vulnerability — 2026-08-30 —
2026-08-27 CVE-2026-53362 Linux Kernel Linux Kernel Unspecified Vulnerability — 2026-08-30 —
2026-08-27 CVE-2026-66384 JFrog Artifactory JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability — 2026-09-10 —
2026-08-26 CVE-2021-23758 Ajax.NET Professional Ajax.NET Professional Ajax.NET Professional Deserialization of Untrusted Data Vulnerability — 2026-09-09 —
2026-08-26 CVE-2015-3246 Red Hat Libuser Red Hat Libuser Race Condition Vulnerability — 2026-09-09 —
2026-08-26 CVE-2015-5287 Red Hat Automatic Bug Reporting Tool Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability — 2026-09-09 —
2026-08-26 CVE-2022-0995 Linux Kernel Linux Kernel Out-of-Bounds Write Vulnerability — 2026-09-09 —
2026-08-26 CVE-2026-8452 Citrix NetScaler ADC and NetScaler Gateway Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability — 2026-08-29 —
2026-08-26 CVE-2019-1068 Microsoft SQL Server Microsoft SQL Server Remote Code Execution Vulnerability — 2026-08-29 —
2026-08-25 CVE-2026-60004 Gitea Gitea Gitea Code Injection Vulnerability — 2026-08-28 —
2026-08-24 CVE-2026-21962 Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability — 2026-08-27 —
2026-08-21 CVE-2026-73570 Synacor Zimbra Collaboration Suite (ZCS) Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability — 2026-08-24 —
2026-08-20 CVE-2026-72530 TrueConf Server TrueConf Server Code Injection Vulnerability — 2026-09-03 —
2026-08-20 CVE-2026-72529 TrueConf Server TrueConf Server Missing Authentication for Critical Function Vulnerability — 2026-08-23 —
2026-08-19 CVE-2026-64849 MLflow MLflow MLflow Server-Side Request Forgery Vulnerability — 2026-09-02 —
2026-08-18 CVE-2026-33824 Microsoft Internet Key Exchange (IKE) Service Extensions Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability — 2026-08-21 —
2026-08-18 CVE-2026-59310 Broadcom VMware vCenter Broadcom VMware vCenter Path Traversal Vulnerability Known 2026-08-21 —
2026-08-18 CVE-2026-55040 Microsoft SharePoint Microsoft SharePoint Weak Authentication Vulnerability — 2026-08-21 —
2026-08-18 CVE-2026-65400 Apple macOS Apple macOS Improper Authentication Vulnerability — 2026-08-21 —
2026-08-17 CVE-2025-62593 Ray-Project Ray Ray-Project Ray Code Injection Vulnerability — 2026-08-20 —
2026-08-11 CVE-2026-20349 Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability — 2026-08-14 —
2026-08-11 CVE-2026-68820 Microsoft Windows Ancillary Function Driver for WinSock Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability — 2026-08-25 —
2026-08-11 CVE-2026-72898 Metabase Metabase Metabase SQL Injection Vulnerability — 2026-08-14 —
2026-08-07 CVE-2026-8037 Progress LoadMaster Progress LoadMaster Command Injection Vulnerability — 2026-08-10 —
2026-08-05 CVE-2026-63077 JetBrains TeamCity JetBrains TeamCity Deserialization of Untrusted Data Vulnerability Known 2026-08-08 —
2026-08-04 CVE-2026-18556 N-able N-central N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability — 2026-08-07 —
2026-08-04 CVE-2026-34486 Apache Tomcat Apache Tomcat Missing Encryption of Sensitive Data Vulnerability — 2026-08-07 —
2026-08-04 CVE-2026-9198 IBM Langflow IBM Langflow Code Injection Vulnerability — 2026-08-07 —
2026-08-03 CVE-2026-18577 N-able N-central N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability — 2026-08-06 —
2026-07-29 CVE-2026-20316 Cisco Secure Firewall Management Center (FMC) Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability Known 2026-08-01 —
2026-07-27 CVE-2025-68686 Fortinet FortiOS Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability — 2026-08-10 —
2026-07-27 CVE-2026-16812 Arista VeloCloud Orchestrator Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability — 2026-07-30 —
2026-07-22 CVE-2026-16232 Check Point SmartConsole Check Point SmartConsole Improper Authentication Vulnerability — 2026-07-25 —
2026-07-22 CVE-2026-50522 Microsoft SharePoint Microsoft SharePoint Deserialization of Untrusted Data Vulnerability — 2026-07-25 —
2026-07-21 CVE-2026-60137 WordPress Core WordPress Core SQL Injection Vulnerability — 2026-08-04 —
2026-07-21 CVE-2026-63030 WordPress Core WordPress Core Interpretation Conflict Vulnerability — 2026-07-24 —
2026-07-21 CVE-2026-0770 Langflow Langflow Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability — 2026-07-24 —
2026-07-21 CVE-2021-27137 DD-WRT DD-WRT DD-WRT Stack-Based Buffer Overflow Vulnerability — 2026-07-24 —
2026-07-16 CVE-2026-58644 Microsoft SharePoint Microsoft SharePoint Deserialization of Untrusted Data Vulnerability — 2026-07-19 —
2026-07-16 CVE-2026-25089 Fortinet FortiSandbox Fortinet FortiSandbox OS Command Injection Vulnerability — 2026-07-19 —
2026-07-16 CVE-2026-39808 Fortinet FortiSandbox Fortinet FortiSandbox OS Command Injection Vulnerability — 2026-07-19 —
2026-07-15 CVE-2026-46817 Oracle E-Business Suite Oracle E-Business Suite Improper Privilege Management Vulnerability — 2026-07-18 —
2026-07-15 CVE-2023-4346 KNX Association KNX Protocol Connection Authorization Option 1 KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability — 2026-07-29 —
2026-07-14 CVE-2026-56155 Microsoft Active Directory Federation Services Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability — 2026-07-28 —
2026-07-14 CVE-2026-56164 Microsoft SharePoint Server Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability — 2026-07-17 —
2026-07-14 CVE-2026-15409 SonicWall SMA1000 Appliances SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability Known 2026-07-17 —
2026-07-14 CVE-2026-15410 SonicWall SMA1000 Appliances SonicWall SMA1000 Appliances Code Injection Vulnerability Known 2026-07-17 —
2026-07-13 CVE-2008-4128 Cisco IOS Cisco IOS Cross-Site Request Forgery Vulnerability — 2026-07-16 —
2026-07-10 CVE-2026-56291 Balbooa Forms Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability — 2026-07-13 —
2026-07-10 CVE-2026-48939 iCagenda iCagenda iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability — 2026-07-13 —
2026-07-07 CVE-2026-48908 JoomShaper SP Page Builder JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability — 2026-07-10 —
2026-07-07 CVE-2026-55255 Langflow Langflow Langflow Authorization Bypass Through User-Controlled Key Vulnerability — 2026-07-10 —
2026-07-07 CVE-2026-56290 Joomlack Page Builder Joomlack Page Builder Improper Access Control Vulnerability — 2026-07-10 —
2026-07-07 CVE-2026-48282 Adobe ColdFusion Adobe ColdFusion Path Traversal Vulnerability — 2026-07-10 —
2026-07-01 CVE-2026-45659 Microsoft SharePoint Server Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability Known 2026-07-04 CVE-2025-53770 SharePoint Server – Immediate Action Guide

Source: CISA Known Exploited Vulnerabilities catalog (version 2026.09.27). Last updated 28 September 2026, 05:15 UTC. Patch due dates apply to US federal civilian agencies under BOD 22-01; other organisations should treat them as a recommended maximum.

Get this list when it changes

One email when a vulnerability enters or leaves this watchlist. No digest of things you already read, no daily noise — only the change, with the reasoning.

Your address is stored on our own server, never sold or shared, and every email carries a working unsubscribe link.

About AI Post Daily

Independent coverage of artificial intelligence, machine learning, cybersecurity, and the technology shaping our future.

Contact: Get in touch

Known Exploited Vulnerabilities Tracker·Exploit Likelihood Watchlist·Does EPSS Predict KEV?·Does a GitHub PoC Predict KEV?·AI Attack Tracker·CVE Remediation Guides — updated daily

How we research, write and correct our reporting — editorial policy

Security Guides

We use cookies to personalize content and ads, and to analyze traffic. By using this site, you agree to our Privacy Policy.