Live data
Exploited now: security holes under active attack
Thousands of vulnerabilities are published every month; only a few are ever used by attackers. This page lists the ones that are being used, according to the US cybersecurity agency CISA, and says in plain words who is affected and what to update.
Latest additions
1,739 in total| Product | What an attacker gains | Concerns | Severity | Added |
|---|---|---|---|---|
StrapiCVE-2023-22894 | Code execution | Business | 4.9 | |
ONLYOFFICE DocsCVE-2021-3199 | File access | Business | 9.8 | |
Apache StrutsCVE-2016-3081 | Code execution | Business | 8.1 | |
ISC BINDCVE-2015-5477 | Denial of service | Business | 7.5 | |
ProFTPDCVE-2015-3306 | Improper access control | Business | 10.0 | |
Citrix NetScalerCVE-2026-88779 | Denial of service | Business | 8.7 | |
Zammad GmbH ZammadCVE-2026-102490 | Privilege escalation | Business | 9.4 | |
Zammad GmbH ZammadCVE-2026-102489 | Authentication bypass | Business | 9.4 | |
Fortinet FortiMailCVE-2026-104286 | File access | Business | 9.8 | |
Cisco Catalyst SD-WAN ManagerCVE-2026-76504 | Vulnerability | Business | 9.8 | |
Apple productsCVE-2026-86950 | Memory corruption | Everyone | 8.8 | |
Citrix NetScalerCVE-2026-88772 | Code execution | Business | 9.5 | |
Citrix NetScalerCVE-2026-88771 | Improper access control | Business | 9.5 | |
WordPress CoreCVE-2026-87902 | File access | Business | 8.1 | |
MikroTik RouterOSCVE-2026-67279 | Vulnerability | Home network | 6.9 | |
Microsoft SharePointCVE-2026-65660 | Code execution | Business | 8.8 | |
Adobe Commerce and MagentoCVE-2026-71362 | Improper access control | Business | 9.1 | |
WSO2 productsCVE-2026-5430 | File access | Everyone | 10.0 | |
F5 BIG-IP APMCVE-2026-94127 | Memory corruption | Business | 9.3 | |
Arista VeloCloud OrchestratorCVE-2026-93952 | Improper access control | Business | 9.5 | |
Check Point productsCVE-2026-93616 | File access | Everyone | 9.8 | |
Check Point productsCVE-2026-85102 | Security bypass | Everyone | 9.8 | |
Zyxel GS1900 Series SwitchesCVE-2026-7273 | Memory corruption | Home network | 8.8 | |
Linux KernelCVE-2026-53266 | Memory corruption | Everyone | 8.8 | |
Linux KernelCVE-2025-39964 | Memory corruption | Everyone | 5.5 | |
Linux KernelCVE-2025-39682 | Security bypass | Everyone | 9.8 | |
Acronis BackupCVE-2026-87886 | Privilege escalation | Business | 7.8 | |
Cisco Identity Services EngineCVE-2026-76460 | Security bypass | Business | 10.0 | |
Google PixelCVE-2026-58704 | Improper access control | Everyone | 8.8 | |
Cisco Secure Email GatewayCVE-2026-76461 | SQL injection | Business | 9.8 | |
GitLab Community Edition and Enterprise EditionCVE-2026-85706 | File access | Business | 10.0 | |
ConnectWise ScreenConnectCVE-2026-84869 | Privilege escalation | Business | 9.9 | |
JFrog ArtifactoryCVE-2026-42018 | Authentication bypass | Business | 7.5 | |
JFrog ArtifactoryCVE-2026-42016 | Improper access control | Business | 8.8 | |
MikroTik RouterOSCVE-2026-86060 | Privilege escalation | Home network | 9.2 | |
MikroTik RouterOSCVE-2026-67277 | Authentication bypass | Home network | 8.8 | |
Google Chromium V8CVE-2026-87491 | Vulnerability | Everyone | 8.8 | |
Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementCVE-2026-20079 | Authentication bypass | Business | 10.0 | |
Citrix NetScalerCVE-2026-19490 | Authentication bypass | Business | 9.3 | |
Fortinet productsCVE-2025-25249 | Memory corruption | Everyone | 9.8 | |
N-able N-centralCVE-2026-86218 | Code execution | Business | 10.0 | |
Microsoft WindowsCVE-2026-85880 | Memory corruption | Everyone | 7.8 | |
Microsoft WindowsCVE-2026-81963 | File access | Everyone | 7.8 | |
Adobe Commerce and MagentoCVE-2026-75650 | Vulnerability | Business | 10.0 | |
Google Chromium V8CVE-2026-85046 | Memory corruption | Everyone | 8.8 | |
Sangoma SwitchvoxCVE-2026-9586 | SQL injection | Business | 9.3 | |
SonicWall SMA1000 AppliancesCVE-2026-83549 | Code execution | Business | 7.8 | |
SonicWall SMA1000 AppliancesCVE-2026-83548 | Server-side request forgery | Business | 10.0 | |
JFrog ArtifactoryCVE-2026-82329 | Authentication bypass | Business | 9.8 | |
BerriAI LiteLLMCVE-2026-59822 | Authentication bypass | Business | 8.8 |
Source: CISA Known Exploited Vulnerabilities catalogsource updated Oct 8, 2026, 20:09 UTC
Severity (CVSS): NIST NVD
New CVEs in the last 24 hours
418 publishedA CVE is a catalogue number for a publicly disclosed security flaw. Most are never attacked. These are the newly published ones with the highest severity scores; they are not known to be exploited.
CVE-2026-9450310.0 criticalUnrestricted Upload of File with Dangerous Type vulnerability in PX-lab Zombify zombify allows Upload a Web Shell to a Web Server.This issue affects Zombify: from n/a through 1.7.7.CVE-2026-1082639.9 criticalAstron Agent is an agentic workflow platform for building and running AI agents. Prior to 1.1.2, the default workflow code-node path through /console-api/workflow/code/run and /workflow/v1/run selects LocalExecutor in core/workflow/engine/nodes/code/code_node.py when CODE_EXEC_TYPE is not explicitly changed.…CVE-2026-939459.8 criticalDeserialization of Untrusted Data vulnerability in Axiomthemes Balance balance allows Object Injection.This issue affects Balance: from n/a through 1.12.0.CVE-2026-939449.8 criticalDeserialization of Untrusted Data vulnerability in ThemeREX Group Camelia camelia allows Object Injection.This issue affects Camelia: from n/a through 1.2.15.CVE-2026-939439.8 criticalDeserialization of Untrusted Data vulnerability in ThemeREX Group Convex convex allows Object Injection.This issue affects Convex: from n/a through 1.16.0.CVE-2026-939429.8 criticalDeserialization of Untrusted Data vulnerability in ThemeREX Group Dwell dwell allows Object Injection.This issue affects Dwell: from n/a through 1.16.0.CVE-2026-939419.8 criticalDeserialization of Untrusted Data vulnerability in ThemeREX Group Edema edema allows Object Injection.This issue affects Edema: from n/a through 1.2.2.2.CVE-2026-939409.8 criticalDeserialization of Untrusted Data vulnerability in ThemeREX Group Greeny greeny allows Object Injection.This issue affects Greeny: from n/a through 2.10.0.CVE-2026-939389.8 criticalDeserialization of Untrusted Data vulnerability in ThemeREX Group Hogwords hogwords allows Object Injection.This issue affects Hogwords: from n/a through 1.2.7.CVE-2026-939379.8 criticalDeserialization of Untrusted Data vulnerability in ThemeREX Group Hygia hygia allows Object Injection.This issue affects Hygia: from n/a through 1.21.0.CVE-2026-939369.8 criticalDeserialization of Untrusted Data vulnerability in ThemeREX Group IPharm ipharm allows Object Injection.This issue affects IPharm: from n/a through 1.2.4.CVE-2026-939359.8 criticalDeserialization of Untrusted Data vulnerability in ThemeREX Group Let's Play playhockey allows Object Injection.This issue affects Let's Play: from n/a through 1.1.15.
Source: NIST National Vulnerability Databasesource updated Oct 10, 2026, 08:33 UTCDescriptions are quoted from NVD.