Live data

Exploited now: security holes under active attack

Thousands of vulnerabilities are published every month; only a few are ever used by attackers. This page lists the ones that are being used, according to the US cybersecurity agency CISA, and says in plain words who is affected and what to update.

Latest additions

1,739 in total
ProductWhat an attacker gainsConcernsSeverityAdded
StrapiCVE-2023-22894Code executionBusiness4.9
ONLYOFFICE DocsCVE-2021-3199File accessBusiness9.8
Apache StrutsCVE-2016-3081Code executionBusiness8.1
ISC BINDCVE-2015-5477Denial of serviceBusiness7.5
ProFTPDCVE-2015-3306Improper access controlBusiness10.0
Citrix NetScalerCVE-2026-88779Denial of serviceBusiness8.7
Zammad GmbH ZammadCVE-2026-102490Privilege escalationBusiness9.4
Zammad GmbH ZammadCVE-2026-102489Authentication bypassBusiness9.4
Fortinet FortiMailCVE-2026-104286File accessBusiness9.8
Cisco Catalyst SD-WAN ManagerCVE-2026-76504VulnerabilityBusiness9.8
Apple productsCVE-2026-86950Memory corruptionEveryone8.8
Citrix NetScalerCVE-2026-88772Code executionBusiness9.5
Citrix NetScalerCVE-2026-88771Improper access controlBusiness9.5
WordPress CoreCVE-2026-87902File accessBusiness8.1
MikroTik RouterOSCVE-2026-67279VulnerabilityHome network6.9
Microsoft SharePointCVE-2026-65660Code executionBusiness8.8
Adobe Commerce and MagentoCVE-2026-71362Improper access controlBusiness9.1
WSO2 productsCVE-2026-5430File accessEveryone10.0
F5 BIG-IP APMCVE-2026-94127Memory corruptionBusiness9.3
Arista VeloCloud OrchestratorCVE-2026-93952Improper access controlBusiness9.5
Check Point productsCVE-2026-93616File accessEveryone9.8
Check Point productsCVE-2026-85102Security bypassEveryone9.8
Zyxel GS1900 Series SwitchesCVE-2026-7273Memory corruptionHome network8.8
Linux KernelCVE-2026-53266Memory corruptionEveryone8.8
Linux KernelCVE-2025-39964Memory corruptionEveryone5.5
Linux KernelCVE-2025-39682Security bypassEveryone9.8
Acronis BackupCVE-2026-87886Privilege escalationBusiness7.8
Cisco Identity Services EngineCVE-2026-76460Security bypassBusiness10.0
Google PixelCVE-2026-58704Improper access controlEveryone8.8
Cisco Secure Email GatewayCVE-2026-76461SQL injectionBusiness9.8
GitLab Community Edition and Enterprise EditionCVE-2026-85706File accessBusiness10.0
ConnectWise ScreenConnectCVE-2026-84869Privilege escalationBusiness9.9
JFrog ArtifactoryCVE-2026-42018Authentication bypassBusiness7.5
JFrog ArtifactoryCVE-2026-42016Improper access controlBusiness8.8
MikroTik RouterOSCVE-2026-86060Privilege escalationHome network9.2
MikroTik RouterOSCVE-2026-67277Authentication bypassHome network8.8
Google Chromium V8CVE-2026-87491VulnerabilityEveryone8.8
Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementCVE-2026-20079Authentication bypassBusiness10.0
Citrix NetScalerCVE-2026-19490Authentication bypassBusiness9.3
Fortinet productsCVE-2025-25249Memory corruptionEveryone9.8
N-able N-centralCVE-2026-86218Code executionBusiness10.0
Microsoft WindowsCVE-2026-85880Memory corruptionEveryone7.8
Microsoft WindowsCVE-2026-81963File accessEveryone7.8
Adobe Commerce and MagentoCVE-2026-75650VulnerabilityBusiness10.0
Google Chromium V8CVE-2026-85046Memory corruptionEveryone8.8
Sangoma SwitchvoxCVE-2026-9586SQL injectionBusiness9.3
SonicWall SMA1000 AppliancesCVE-2026-83549Code executionBusiness7.8
SonicWall SMA1000 AppliancesCVE-2026-83548Server-side request forgeryBusiness10.0
JFrog ArtifactoryCVE-2026-82329Authentication bypassBusiness9.8
BerriAI LiteLLMCVE-2026-59822Authentication bypassBusiness8.8

Source: CISA Known Exploited Vulnerabilities catalogsource updated Oct 8, 2026, 20:09 UTC

Severity (CVSS): NIST NVD

New CVEs in the last 24 hours

418 published

A CVE is a catalogue number for a publicly disclosed security flaw. Most are never attacked. These are the newly published ones with the highest severity scores; they are not known to be exploited.

  • CVE-2026-9450310.0 criticalUnrestricted Upload of File with Dangerous Type vulnerability in PX-lab Zombify zombify allows Upload a Web Shell to a Web Server.This issue affects Zombify: from n/a through 1.7.7.
  • CVE-2026-1082639.9 criticalAstron Agent is an agentic workflow platform for building and running AI agents. Prior to 1.1.2, the default workflow code-node path through /console-api/workflow/code/run and /workflow/v1/run selects LocalExecutor in core/workflow/engine/nodes/code/code_node.py when CODE_EXEC_TYPE is not explicitly changed.…
  • CVE-2026-939459.8 criticalDeserialization of Untrusted Data vulnerability in Axiomthemes Balance balance allows Object Injection.This issue affects Balance: from n/a through 1.12.0.
  • CVE-2026-939449.8 criticalDeserialization of Untrusted Data vulnerability in ThemeREX Group Camelia camelia allows Object Injection.This issue affects Camelia: from n/a through 1.2.15.
  • CVE-2026-939439.8 criticalDeserialization of Untrusted Data vulnerability in ThemeREX Group Convex convex allows Object Injection.This issue affects Convex: from n/a through 1.16.0.
  • CVE-2026-939429.8 criticalDeserialization of Untrusted Data vulnerability in ThemeREX Group Dwell dwell allows Object Injection.This issue affects Dwell: from n/a through 1.16.0.
  • CVE-2026-939419.8 criticalDeserialization of Untrusted Data vulnerability in ThemeREX Group Edema edema allows Object Injection.This issue affects Edema: from n/a through 1.2.2.2.
  • CVE-2026-939409.8 criticalDeserialization of Untrusted Data vulnerability in ThemeREX Group Greeny greeny allows Object Injection.This issue affects Greeny: from n/a through 2.10.0.
  • CVE-2026-939389.8 criticalDeserialization of Untrusted Data vulnerability in ThemeREX Group Hogwords hogwords allows Object Injection.This issue affects Hogwords: from n/a through 1.2.7.
  • CVE-2026-939379.8 criticalDeserialization of Untrusted Data vulnerability in ThemeREX Group Hygia hygia allows Object Injection.This issue affects Hygia: from n/a through 1.21.0.
  • CVE-2026-939369.8 criticalDeserialization of Untrusted Data vulnerability in ThemeREX Group IPharm ipharm allows Object Injection.This issue affects IPharm: from n/a through 1.2.4.
  • CVE-2026-939359.8 criticalDeserialization of Untrusted Data vulnerability in ThemeREX Group Let's Play playhockey allows Object Injection.This issue affects Let's Play: from n/a through 1.1.15.

Source: NIST National Vulnerability Databasesource updated Oct 10, 2026, 08:33 UTCDescriptions are quoted from NVD.

5,448 members already hereReading, writing, commenting and voting. 0 verified · 173 joined this year