Not every vulnerability matters equally. This page tracks the ones that are confirmed to be under active attack: entries added to the CISA Known Exploited Vulnerabilities catalog in the last 90 days. US federal agencies are legally required to patch these by the listed due date; for everyone else they are the shortest useful patching queue in security.
Where we have reported on a vulnerability, the last column links to that coverage. The table refreshes daily from the official CISA feed.
Where we have written a full remediation guide for an entry, the last column links to it. Every guide we have published is indexed here.
Everything here is confirmed exploited. For the other side of the question — recent vulnerabilities that exploitation models rate as highly likely to be attacked but that CISA has not listed yet — see our exploit likelihood watchlist.
| Added | CVE | Vendor / Product | Vulnerability | Ransomware | Patch due | Our coverage |
|---|---|---|---|---|---|---|
| 2026-09-27 | CVE-2026-88772 | Citrix NetScaler | Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability | — | 2026-09-30 | — |
| 2026-09-27 | CVE-2026-88771 | Citrix NetScaler | Citrix NetScaler Improper Input Validation Vulnerability | — | 2026-09-30 | — |
| 2026-09-25 | CVE-2026-67279 | MikroTik RouterOS | Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability | — | 2026-09-28 | — |
| 2026-09-25 | CVE-2026-65660 | Microsoft SharePoint | Microsoft SharePoint Code Injection Vulnerability | — | 2026-09-28 | — |
| 2026-09-25 | CVE-2026-87902 | WordPress Core | WordPress Core Remote File Inclusion Vulnerability | — | 2026-09-28 | — |
| 2026-09-24 | CVE-2026-5430 | WSO2 Multiple Products | WSO2 Multiple Products Path Traversal Vulnerability | — | 2026-09-27 | — |
| 2026-09-24 | CVE-2026-71362 | Adobe Commerce and Magento | Adobe Commerce and Magento Incorrect Authorization Vulnerability | — | 2026-09-27 | — |
| 2026-09-22 | CVE-2026-93952 | Arista VeloCloud Orchestrator | Arista VeloCloud Orchestrator Improper Input Validation Vulnerability | — | 2026-09-25 | — |
| 2026-09-22 | CVE-2026-94127 | F5 BIG-IP APM | F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability | — | 2026-09-25 | — |
| 2026-09-22 | CVE-2026-93616 | Check Point Multiple Products | Check Point Multiple Products Path Traversal Vulnerability | — | 2026-09-25 | — |
| 2026-09-22 | CVE-2026-85102 | Check Point Multiple Products | Check Point Multiple Products Improper Certificate Validation Vulnerability | — | 2026-09-25 | — |
| 2026-09-21 | CVE-2026-7273 | Zyxel GS1900 Series Switches | Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability | — | 2026-09-24 | — |
| 2026-09-18 | CVE-2025-39964 | Linux Kernel | Linux Kernel Race Condition Vulnerability | — | 2026-09-21 | — |
| 2026-09-18 | CVE-2026-53266 | Linux Kernel | Linux Kernel Out-of-Bounds Write Vulnerability | — | 2026-09-21 | — |
| 2026-09-18 | CVE-2025-39682 | Linux Kernel | Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability | — | 2026-09-21 | — |
| 2026-09-16 | CVE-2026-58704 | Google Pixel | Google Pixel Improper Authorization Vulnerability | — | 2026-09-19 | — |
| 2026-09-16 | CVE-2026-76460 | Cisco Identity Services Engine | Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability | — | 2026-09-19 | — |
| 2026-09-16 | CVE-2026-87886 | Acronis Backup | Acronis Backup Incorrect Default Permissions Vulnerability | — | 2026-09-19 | — |
| 2026-09-14 | CVE-2026-76461 | Cisco Secure Email Gateway | Cisco Secure Email Gateway SQL Injection Vulnerability | — | 2026-09-17 | — |
| 2026-09-11 | CVE-2026-84869 | ConnectWise ScreenConnect | ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability | — | 2026-09-14 | — |
| 2026-09-11 | CVE-2026-42016 | JFrog Artifactory | JFrog Artifactory Incorrect Authorization Vulnerability | — | 2026-09-25 | — |
| 2026-09-11 | CVE-2026-42018 | JFrog Artifactory | JFrog Artifactory Improper Authentication Vulnerability | — | 2026-09-25 | — |
| 2026-09-11 | CVE-2026-85706 | GitLab Community Edition and Enterprise Edition | GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability | — | 2026-09-14 | — |
| 2026-09-10 | CVE-2026-86060 | MikroTik RouterOS | MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability | — | 2026-09-13 | — |
| 2026-09-10 | CVE-2026-67277 | MikroTik RouterOS | MikroTik RouterOS Missing Authentication for Critical Function Vulnerability | — | 2026-09-13 | — |
| 2026-09-09 | CVE-2026-19490 | Citrix NetScaler | Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability | — | 2026-09-12 | — |
| 2026-09-09 | CVE-2025-25249 | Fortinet Multiple Products | Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability | — | 2026-09-12 | — |
| 2026-09-09 | CVE-2026-87491 | Google Chromium V8 | Google Chromium V8 Out of Bounds Write Vulnerability | — | 2026-09-23 | — |
| 2026-09-09 | CVE-2026-20079 | Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management | Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability | — | 2026-09-12 | — |
| 2026-09-08 | CVE-2026-75650 | Adobe Commerce and Magento | Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability | — | 2026-09-11 | — |
| 2026-09-08 | CVE-2026-81963 | Microsoft Windows | Microsoft Windows Link Following Vulnerability | — | 2026-09-22 | — |
| 2026-09-08 | CVE-2026-86218 | N-able N-central | N-able N-central Static Code Injection Vulnerability | — | 2026-09-11 | — |
| 2026-09-08 | CVE-2026-85880 | Microsoft Windows | Microsoft Windows Heap-Based Buffer Overflow Vulnerability | — | 2026-09-22 | — |
| 2026-09-04 | CVE-2026-85046 | Google Chromium V8 | Google Chromium V8 Type Confusion Vulnerability | — | 2026-09-18 | — |
| 2026-09-02 | CVE-2026-59822 | BerriAI LiteLLM | BerriAI LiteLLM Improper Authentication Vulnerability | — | 2026-09-16 | — |
| 2026-09-02 | CVE-2026-48710 | Kludex Starlette | Kludex Starlette HTTP Request/Response Smuggling Vulnerability | — | 2026-09-16 | — |
| 2026-09-02 | CVE-2026-49869 | Kestra Kestra OSS | Kestra OSS OS Command Injection Vulnerability | — | 2026-09-05 | — |
| 2026-09-02 | CVE-2026-82329 | JFrog Artifactory | JFrog Artifactory Improper Authentication Vulnerability | — | 2026-09-05 | — |
| 2026-09-02 | CVE-2026-9586 | Sangoma Switchvox | Sangoma Switchvox SQL Injection Vulnerability | — | 2026-09-05 | — |
| 2026-09-02 | CVE-2026-83548 | SonicWall SMA1000 Appliances | SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability | — | 2026-09-05 | — |
| 2026-09-02 | CVE-2026-83549 | SonicWall SMA1000 Appliances | SonicWall SMA1000 Appliances OS Command Injection Vulnerability | — | 2026-09-05 | — |
| 2026-08-31 | CVE-2026-82078 | PaperCut NG/MF | PaperCut NG/MF Unsafe Reflection Vulnerability | — | 2026-09-14 | — |
| 2026-08-31 | CVE-2026-81578 | PaperCut NG/MF | PaperCut NG/MF Missing Authentication for Critical Function Vulnerability | — | 2026-09-14 | — |
| 2026-08-27 | CVE-2023-49105 | ownCloud ownCloud | ownCloud Improper Authentication Vulnerability | — | 2026-08-30 | — |
| 2026-08-27 | CVE-2026-53362 | Linux Kernel | Linux Kernel Unspecified Vulnerability | — | 2026-08-30 | — |
| 2026-08-27 | CVE-2026-66384 | JFrog Artifactory | JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability | — | 2026-09-10 | — |
| 2026-08-26 | CVE-2021-23758 | Ajax.NET Professional Ajax.NET Professional | Ajax.NET Professional Deserialization of Untrusted Data Vulnerability | — | 2026-09-09 | — |
| 2026-08-26 | CVE-2015-3246 | Red Hat Libuser | Red Hat Libuser Race Condition Vulnerability | — | 2026-09-09 | — |
| 2026-08-26 | CVE-2015-5287 | Red Hat Automatic Bug Reporting Tool | Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability | — | 2026-09-09 | — |
| 2026-08-26 | CVE-2022-0995 | Linux Kernel | Linux Kernel Out-of-Bounds Write Vulnerability | — | 2026-09-09 | — |
| 2026-08-26 | CVE-2026-8452 | Citrix NetScaler ADC and NetScaler Gateway | Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability | — | 2026-08-29 | — |
| 2026-08-26 | CVE-2019-1068 | Microsoft SQL Server | Microsoft SQL Server Remote Code Execution Vulnerability | — | 2026-08-29 | — |
| 2026-08-25 | CVE-2026-60004 | Gitea Gitea | Gitea Code Injection Vulnerability | — | 2026-08-28 | — |
| 2026-08-24 | CVE-2026-21962 | Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in | Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability | — | 2026-08-27 | — |
| 2026-08-21 | CVE-2026-73570 | Synacor Zimbra Collaboration Suite (ZCS) | Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability | — | 2026-08-24 | — |
| 2026-08-20 | CVE-2026-72530 | TrueConf Server | TrueConf Server Code Injection Vulnerability | — | 2026-09-03 | — |
| 2026-08-20 | CVE-2026-72529 | TrueConf Server | TrueConf Server Missing Authentication for Critical Function Vulnerability | — | 2026-08-23 | — |
| 2026-08-19 | CVE-2026-64849 | MLflow MLflow | MLflow Server-Side Request Forgery Vulnerability | — | 2026-09-02 | — |
| 2026-08-18 | CVE-2026-33824 | Microsoft Internet Key Exchange (IKE) Service Extensions | Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability | — | 2026-08-21 | — |
| 2026-08-18 | CVE-2026-59310 | Broadcom VMware vCenter | Broadcom VMware vCenter Path Traversal Vulnerability | Known | 2026-08-21 | — |
| 2026-08-18 | CVE-2026-55040 | Microsoft SharePoint | Microsoft SharePoint Weak Authentication Vulnerability | — | 2026-08-21 | — |
| 2026-08-18 | CVE-2026-65400 | Apple macOS | Apple macOS Improper Authentication Vulnerability | — | 2026-08-21 | — |
| 2026-08-17 | CVE-2025-62593 | Ray-Project Ray | Ray-Project Ray Code Injection Vulnerability | — | 2026-08-20 | — |
| 2026-08-11 | CVE-2026-20349 | Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) | Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability | — | 2026-08-14 | — |
| 2026-08-11 | CVE-2026-68820 | Microsoft Windows Ancillary Function Driver for WinSock | Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability | — | 2026-08-25 | — |
| 2026-08-11 | CVE-2026-72898 | Metabase Metabase | Metabase SQL Injection Vulnerability | — | 2026-08-14 | — |
| 2026-08-07 | CVE-2026-8037 | Progress LoadMaster | Progress LoadMaster Command Injection Vulnerability | — | 2026-08-10 | — |
| 2026-08-05 | CVE-2026-63077 | JetBrains TeamCity | JetBrains TeamCity Deserialization of Untrusted Data Vulnerability | Known | 2026-08-08 | — |
| 2026-08-04 | CVE-2026-18556 | N-able N-central | N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability | — | 2026-08-07 | — |
| 2026-08-04 | CVE-2026-34486 | Apache Tomcat | Apache Tomcat Missing Encryption of Sensitive Data Vulnerability | — | 2026-08-07 | — |
| 2026-08-04 | CVE-2026-9198 | IBM Langflow | IBM Langflow Code Injection Vulnerability | — | 2026-08-07 | — |
| 2026-08-03 | CVE-2026-18577 | N-able N-central | N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability | — | 2026-08-06 | — |
| 2026-07-29 | CVE-2026-20316 | Cisco Secure Firewall Management Center (FMC) | Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability | Known | 2026-08-01 | — |
| 2026-07-27 | CVE-2025-68686 | Fortinet FortiOS | Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability | — | 2026-08-10 | — |
| 2026-07-27 | CVE-2026-16812 | Arista VeloCloud Orchestrator | Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability | — | 2026-07-30 | — |
| 2026-07-22 | CVE-2026-16232 | Check Point SmartConsole | Check Point SmartConsole Improper Authentication Vulnerability | — | 2026-07-25 | — |
| 2026-07-22 | CVE-2026-50522 | Microsoft SharePoint | Microsoft SharePoint Deserialization of Untrusted Data Vulnerability | — | 2026-07-25 | — |
| 2026-07-21 | CVE-2026-60137 | WordPress Core | WordPress Core SQL Injection Vulnerability | — | 2026-08-04 | — |
| 2026-07-21 | CVE-2026-63030 | WordPress Core | WordPress Core Interpretation Conflict Vulnerability | — | 2026-07-24 | — |
| 2026-07-21 | CVE-2026-0770 | Langflow Langflow | Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability | — | 2026-07-24 | — |
| 2026-07-21 | CVE-2021-27137 | DD-WRT DD-WRT | DD-WRT Stack-Based Buffer Overflow Vulnerability | — | 2026-07-24 | — |
| 2026-07-16 | CVE-2026-58644 | Microsoft SharePoint | Microsoft SharePoint Deserialization of Untrusted Data Vulnerability | — | 2026-07-19 | — |
| 2026-07-16 | CVE-2026-25089 | Fortinet FortiSandbox | Fortinet FortiSandbox OS Command Injection Vulnerability | — | 2026-07-19 | — |
| 2026-07-16 | CVE-2026-39808 | Fortinet FortiSandbox | Fortinet FortiSandbox OS Command Injection Vulnerability | — | 2026-07-19 | — |
| 2026-07-15 | CVE-2026-46817 | Oracle E-Business Suite | Oracle E-Business Suite Improper Privilege Management Vulnerability | — | 2026-07-18 | — |
| 2026-07-15 | CVE-2023-4346 | KNX Association KNX Protocol Connection Authorization Option 1 | KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability | — | 2026-07-29 | — |
| 2026-07-14 | CVE-2026-56155 | Microsoft Active Directory Federation Services | Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability | — | 2026-07-28 | — |
| 2026-07-14 | CVE-2026-56164 | Microsoft SharePoint Server | Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability | — | 2026-07-17 | — |
| 2026-07-14 | CVE-2026-15409 | SonicWall SMA1000 Appliances | SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability | Known | 2026-07-17 | — |
| 2026-07-14 | CVE-2026-15410 | SonicWall SMA1000 Appliances | SonicWall SMA1000 Appliances Code Injection Vulnerability | Known | 2026-07-17 | — |
| 2026-07-13 | CVE-2008-4128 | Cisco IOS | Cisco IOS Cross-Site Request Forgery Vulnerability | — | 2026-07-16 | — |
| 2026-07-10 | CVE-2026-56291 | Balbooa Forms | Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability | — | 2026-07-13 | — |
| 2026-07-10 | CVE-2026-48939 | iCagenda iCagenda | iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability | — | 2026-07-13 | — |
| 2026-07-07 | CVE-2026-48908 | JoomShaper SP Page Builder | JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability | — | 2026-07-10 | — |
| 2026-07-07 | CVE-2026-55255 | Langflow Langflow | Langflow Authorization Bypass Through User-Controlled Key Vulnerability | — | 2026-07-10 | — |
| 2026-07-07 | CVE-2026-56290 | Joomlack Page Builder | Joomlack Page Builder Improper Access Control Vulnerability | — | 2026-07-10 | — |
| 2026-07-07 | CVE-2026-48282 | Adobe ColdFusion | Adobe ColdFusion Path Traversal Vulnerability | — | 2026-07-10 | — |
| 2026-07-01 | CVE-2026-45659 | Microsoft SharePoint Server | Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability | Known | 2026-07-04 | CVE-2025-53770 SharePoint Server – Immediate Action Guide |
Source: CISA Known Exploited Vulnerabilities catalog (version 2026.09.27). Last updated 28 September 2026, 05:15 UTC. Patch due dates apply to US federal civilian agencies under BOD 22-01; other organisations should treat them as a recommended maximum.
Get this list when it changes
One email when a vulnerability enters or leaves this watchlist. No digest of things you already read, no daily noise — only the change, with the reasoning.

