Careful interpretation: Absence from KEV does not mean CISA is unaware of a vulnerability or that it is definitively emerging.

Current queue

Signals before KEV inclusion

01
·

CVE-2015-7501

Metadata pending authoritative retrieval.

Public exploitationCONFIRMED
Exploit maturityPOC
VelocitySTABLE
VTP threat58.1/ 100
02
paperclip·paperclipai

CVE-2026-41679

Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Prior to version 2026.416.0, an unauthenticated attacker can achieve full remote code execution on any network-accessible Paperclip instance running in `authenticated` mode with default configuration. No user interaction, no credentials, just the target's address. The chain consists of six API calls. The attack is fully automated, requires no user interaction, and works against the default deployment configuration. Version 2026.416.0 patches the issue.

Public exploitationCONFIRMED
Exploit maturityPOC
VelocitySTABLE
VTP threat42.5/ 100
03
·

CVE-2025-59719

Metadata pending authoritative retrieval.

Public exploitationCONFIRMED
Exploit maturityTECHNICAL DETAILS
VelocitySTABLE
VTP threat41.8/ 100
04
rails·rails

CVE-2026-66066

Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to invoke such an operation. Consuming applications are affected when configured to use libvips and accept image uploads from untrusted users. An unauthenticated attacker may exploit this behavior to read arbitrary files accessible to the Rails process, including environment variables and application secrets. Exposure of credentials such as secret_key_base or external-service tokens may enable remote code execution or lateral movement. This issue has been fixed in versions 7.2.3.2, 8.0.5.1 and 8.1.3.1.

EPSS changed materially from 0.28 to 0.02
Public exploitationCONFIRMED
Exploit maturityPOC
VelocitySTABLE
VTP threat41.4/ 100
05
·

CVE-2025-25231

Metadata pending authoritative retrieval.

Public exploitationCONFIRMED
Exploit maturityTECHNICAL DETAILS
VelocitySTABLE
VTP threat40.5/ 100
06
Zbtlink·WE1326

CVE-2026-74233

Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE2426-C firmware 19.1112, Zbtlink WE5926-EC_QP firmware 20.0516, Zbtlink WF3526-P firmware 19.051, CTN720-W1, LF-1541, and MT7620N firmware 19.1101, and WRC1 firmware 20.0622 contain an unauthenticated command injection in the infosrvd service (UDP/9992). A remote unauthenticated attacker can send a crafted UDP packet to execute arbitrary commands as root. The service's authentication uses a hardcoded salt and an all-zero wildcard MAC bypass, rendering it ineffective.

Public exploitationCONFIRMED
Exploit maturityTECHNICAL DETAILS
VelocitySTABLE
VTP threat36.7/ 100
07
redhat·jboss enterprise application platform

CVE-2011-4085

The servlets invoked by httpha-invoker in JBoss Enterprise Application Platform before 5.1.2, SOA Platform before 5.2.0, BRMS Platform before 5.3.0, and Portal Platform before 4.3 CP07 perform access control only for the GET and POST methods, which allow remote attackers to bypass authentication by sending a request with a different method. NOTE: this vulnerability exists because of a CVE-2010-0738 regression.

Public exploitationCONFIRMED
Exploit maturityTECHNICAL DETAILS
VelocitySTABLE
VTP threat36.6/ 100
08
microsoft·sharepoint server

CVE-2026-63520

Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

Public exploitationCONFIRMED
Exploit maturityTECHNICAL DETAILS
VelocitySTABLE
VTP threat36.2/ 100
09
ollyo·helix3

CVE-2026-49049

The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON files and update template parameters.

Public exploitationCONFIRMED
Exploit maturityTECHNICAL DETAILS
VelocitySTABLE
VTP threat36.2/ 100
10
metabase·metabase

CVE-2023-38646

Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the server's privilege level. Authentication is not required for exploitation. The other fixed versions are 0.45.4.1, 1.45.4.1, 0.44.7.1, 1.44.7.1, 0.43.7.2, and 1.43.7.2.

Public exploitationREPORTED
Exploit maturityTECHNICAL DETAILS
VelocitySTABLE
VTP threat36.2/ 100
11
Zbtlink·L3_V2_8

CVE-2026-74232

Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007, Zbtlink ZBT-ZBT7621 firmware 1.0.0.3.001, MoreQuick MQAC-7620, MQAC-7620A, MQAP-7620, MQAP-7620A, and MQAP-7628 firmware 1.0.0.2.000, AP522 firmware 1.0.0.2.014, AP7628 and HC5661A firmware 3.0.0.4.380, APG721B firmware 19.0809, HK300 firmware 1.0.0.2.032, and MAP-N10 firmware 1.0.0.2.044 ship a backdoor command-and-control implant (yunmgrd) reachable over an unauthenticated cleartext UDP channel to a hardcoded C2 server. A remote unauthenticated attacker on the network path can hijack the channel and execute arbitrary commands as root. The attacker can also modify DNS entries, exfiltrate PPPoE credentials, and open reverse SSH tunnels.

Public exploitationCONFIRMED
Exploit maturityTECHNICAL DETAILS
VelocitySTABLE
VTP threat36.2/ 100
12
geonetwork·core-geonetwork

CVE-2026-58400

GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the Saxon XSLT processor used to render formatters is configured without secure processing (`FEATURE_SECURE_PROCESSING`) and without disabling Java extension functions (`ALLOW_EXTERNAL_FUNCTIONS`). Any stylesheet loaded by GeoNetwork can therefore invoke `java.lang.Runtime.exec()` or `java.lang.ProcessBuilder` directly, achieving arbitrary command execution as the GeoNetwork process user. A user with sufficient privileges to upload a formatter can deliver a `.xsl` file containing Java extension call that execute arbitrary OS commands with the privileges of the GeoNetwork process. The issue is patched in GeoNetwork versions 4.4.12 and 4.2.17.

Public exploitationCONFIRMED
Exploit maturityTECHNICAL DETAILS
VelocitySTABLE
VTP threat36.2/ 100
13
mikrotik·routeros

CVE-2026-67276

RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent. Because signature verification uses the client-supplied key, an attacker knowing an authorized RSA modulus can supply a key with exponent one, forge a valid signature, and open an SSH command channel as the target user without the private key.This issue affects only 7.x branch was fixed in versions: 7.23.4 (Long-term) and 7.24.2 (Stable)

Public exploitationCONFIRMED
Exploit maturityTECHNICAL DETAILS
VelocitySTABLE
VTP threat36.1/ 100
14
geonetwork·core-geonetwork

CVE-2026-63219

GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the API endpoint for creating a new formatter via file upload is unprotected and allows the upload of external uncontrolled files. An unauthenticated attacker can upload arbitrary `.xsl` or `.zip` formatter files to the server. An unauthenticated attacker can write arbitrary files into the GeoNetwork formatter directory. On its own this constitutes unauthorized write access to server storage. The issue is patched in GeoNetwork versions 4.4.12 and 4.2.17.

Public exploitationCONFIRMED
Exploit maturityTECHNICAL DETAILS
VelocitySTABLE
VTP threat36.1/ 100
15
gitlab·gitlab

CVE-2026-19478

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive.

EPSS changed materially from 0.06 to 0.60
Public exploitationREPORTED
Exploit maturityPOC
VelocitySTABLE
VTP threat35.5/ 100
16
Roundcube·Webmail

CVE-2026-48842

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass.

Public exploitationREPORTED
Exploit maturityTECHNICAL DETAILS
VelocitySTABLE
VTP threat24.7/ 100
17
microsoft·entra id

CVE-2026-69836

Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.

Public exploitationCONFIRMED
Exploit maturityNONE KNOWN
VelocitySTABLE
VTP threat24.3/ 100
18
conductor-oss·conductor

CVE-2026-58138

Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary OS commands by submitting inline workflow definitions containing malicious JavaScript or Python expressions to the workflow API endpoint prior to authentication. Attackers can exploit unsandboxed GraalVM evaluators configured with HostAccess.ALL or allowAllAccess(true) through INLINE, LAMBDA, DO_WHILE, and SWITCH task types to invoke arbitrary system commands via Java reflection or direct subprocess calls.

Public exploitationREPORTED
Exploit maturityTECHNICAL DETAILS
VelocitySTABLE
VTP threat23.4/ 100
19
langflow·langflow

CVE-2026-0769

Langflow eval_custom_component_code Eval Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of eval_custom_component_code function. The issue results from the lack of proper validation of a user-supplied string before using it to execute python code. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-26972.

Public exploitationREPORTED
Exploit maturityTECHNICAL DETAILS
VelocitySTABLE
VTP threat23.0/ 100
20
langflow·langflow

CVE-2026-5027

The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an attacker to write files to arbitrary locations on the filesystem using path traversal sequences ('../').

EPSS changed materially from 0.36 to 0.05
Public exploitationREPORTED
Exploit maturityPOC
VelocitySTABLE
VTP threat22.4/ 100
21
Elementor·Elementor Pro

CVE-2026-32475

Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files. This issue affects Elementor Pro: from n/a through 4.2.1.

Public exploitationREPORTED
Exploit maturityPOC
VelocitySTABLE
VTP threat21.8/ 100
22
apple·macos

CVE-2024-54529

A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges.

Public exploitationUNKNOWN
Exploit maturityFUNCTIONAL EXPLOIT
VelocitySTABLE
VTP threat20.6/ 100
23
flowiseai·flowise

CVE-2026-56271

Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets ('auth_token', 'refresh_token') and default audience and issuer values ('AUDIENCE', 'ISSUER') in the enterprise passport authentication middleware (packages/server/src/enterprise/middleware/passport/index.ts). When the corresponding environment variables (JWT_AUTH_TOKEN_SECRET, JWT_REFRESH_TOKEN_SECRET, JWT_AUDIENCE, JWT_ISSUER) are not set, the application silently falls back to these publicly known defaults, allowing an attacker to forge valid JWTs and impersonate any user, including administrators, resulting in authentication bypass.

Public exploitationREPORTED
Exploit maturityTECHNICAL DETAILS
VelocitySTABLE
VTP threat20.6/ 100
24
Veeam·Backup and Replication

CVE-2026-32996

This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.

Public exploitationREPORTED
Exploit maturityTECHNICAL DETAILS
VelocitySTABLE
VTP threat20.5/ 100
25
microsoft·windows app

CVE-2026-59124

Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network.

Public exploitationREPORTED
Exploit maturityTECHNICAL DETAILS
VelocitySTABLE
VTP threat16.8/ 100
26
Rymera Web Co Pty Ltd.·Woocommerce Wholesale Lead Capture

CVE-2026-27540

Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wholesale-lead-capture allows Using Malicious Files.This issue affects Woocommerce Wholesale Lead Capture: from n/a through <= 2.0.3.1.

Public exploitationREPORTED
Exploit maturityTECHNICAL DETAILS
VelocitySTABLE
VTP threat16.8/ 100
27
microsoft·windows 10 1607

CVE-2026-62893

Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.

Public exploitationREPORTED
Exploit maturityTECHNICAL DETAILS
VelocitySTABLE
VTP threat16.7/ 100
28
SAP_SE·SAP Commerce Cloud (Data Hub Adapter)

CVE-2026-58231

SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.

Public exploitationREPORTED
Exploit maturityTECHNICAL DETAILS
VelocitySTABLE
VTP threat16.7/ 100
29
Cisco·Cisco Identity Services Engine Software

CVE-2026-20176

A vulnerability in Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid high-privileged administrative credentials. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain system-level access to the underlying operating system and then elevate privileges to root. In single-node deployments, successful exploitation of this vulnerability could cause the affected ISE node to become unavailable, resulting in a DoS condition. In that condition, endpoints that have not already authenticated would be unable to access the network until the node is restored.

Public exploitationREPORTED
Exploit maturityTECHNICAL DETAILS
VelocitySTABLE
VTP threat16.7/ 100
30
Cisco·Cisco Identity Services Engine Software

CVE-2026-20307

A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have at least low-privileged administrative credentials. This vulnerability is due to insecure deserialization of a user-supplied Java byte stream. An attacker could exploit this vulnerability by sending a crafted serialized Java object to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the device and elevate privileges to root. In single-node deployments, successful exploitation of this vulnerability could cause the affected ISE node to become unavailable, resulting in a denial of service (DoS) condition. In that condition, endpoints that have not already authenticated would be unable to access the network until the node is restored.

Public exploitationREPORTED
Exploit maturityTECHNICAL DETAILS
VelocitySTABLE
VTP threat16.7/ 100
31
microsoft·windows 11 23h2

CVE-2026-62815

Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.

Public exploitationREPORTED
Exploit maturityTECHNICAL DETAILS
VelocitySTABLE
VTP threat16.7/ 100
32
vitejs·vite

CVE-2024-45811

Vite a frontend build tooling framework for javascript. In affected versions the contents of arbitrary files can be returned to the browser. `@fs` denies access to files outside of Vite serving allow list. Adding `?import&raw` to the URL bypasses this limitation and returns the file content if it exists. This issue has been patched in versions 5.4.6, 5.3.6, 5.2.14, 4.5.5, and 3.2.11. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Public exploitationREPORTED
Exploit maturityTECHNICAL DETAILS
VelocitySTABLE
VTP threat16.7/ 100
33
microsoft·windows 10 1607

CVE-2026-62878

Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.

Public exploitationREPORTED
Exploit maturityTECHNICAL DETAILS
VelocitySTABLE
VTP threat16.7/ 100
34
·

CVE-2026-51990

An issue in Sogou Sogou Input Method < 16.3.0.3498 (fixed in 16.3.0.3498) allows a remote attacker to execute arbitrary code via the biz_helper.exe component

Public exploitationREPORTED
Exploit maturityTECHNICAL DETAILS
VelocitySTABLE
VTP threat16.7/ 100
35
Cisco·Cisco Secure Firewall Adaptive Security Appliance (ASA) Software

CVE-2026-20332

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. &nbsp; The vulnerabilities tracked by CVE-2026-20332 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-284.

Public exploitationREPORTED
Exploit maturityTECHNICAL DETAILS
VelocitySTABLE
VTP threat16.6/ 100
36
checkpoint·Quantum Security Management

CVE-2026-91843

A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges.

Public exploitationREPORTED
Exploit maturityTECHNICAL DETAILS
VelocitySTABLE
VTP threat16.6/ 100
37
Cisco·Cisco Identity Services Engine Software

CVE-2026-20284

A vulnerability in the SXP REST API of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks. This vulnerability is due to insufficient validation of user-supplied input in REST API calls. An attacker could exploit this vulnerability by sending crafted input to an affected device. A successful exploit could allow the attacker to view or modify data on the underlying database for the affected device. In single-node deployments, successful exploitation of this vulnerability could cause the affected ISE node to become unavailable, resulting in a DoS condition. In that condition, endpoints that have not already authenticated would be unable to access the network until the node is restored. To exploit this vulnerability, the attacker must have valid administrative credentials, have the SXP service enabled, and have at least one SXP connection configured.

Public exploitationREPORTED
Exploit maturityTECHNICAL DETAILS
VelocitySTABLE
VTP threat16.6/ 100
38
microsoft·exchange server

CVE-2026-62911

Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

Public exploitationREPORTED
Exploit maturityTECHNICAL DETAILS
VelocitySTABLE
VTP threat16.6/ 100
39
Cisco·Cisco Identity Services Engine Software

CVE-2026-20211

A vulnerability in Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid high-privileged administrative credentials. This vulnerability is due to insecure deserialization of Java objects by the affected software. An attacker could exploit this vulnerability by sending a crafted serialized Java object to an affected device. A successful exploit could allow the attacker to obtain user-level access to the underlying operating system and then elevate privileges to&nbsp;root. In single-node deployments, successful exploitation of this vulnerability could cause the affected ISE node to become unavailable, resulting in a DoS condition. In that condition, endpoints that have not already authenticated would be unable to access the network until the node is restored.

Public exploitationREPORTED
Exploit maturityTECHNICAL DETAILS
VelocitySTABLE
VTP threat16.6/ 100
40
·

CVE-2026-76443

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76443 are related to issues with improper neutralization that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-707.

Public exploitationREPORTED
Exploit maturityTECHNICAL DETAILS
VelocitySTABLE
VTP threat16.6/ 100
41
Cisco·Cisco Secure Email

CVE-2026-20353

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20353 are related to issues with improper control of a resource through its lifetime that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-664.

Public exploitationREPORTED
Exploit maturityTECHNICAL DETAILS
VelocitySTABLE
VTP threat16.6/ 100
42
microsoft·windows 11 26h1

CVE-2026-72971

Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to perform tampering locally.

Public exploitationREPORTED
Exploit maturityTECHNICAL DETAILS
VelocitySTABLE
VTP threat16.6/ 100
43
·

CVE-2026-76441

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76441 are related to issues with improper access control that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-284.

Public exploitationREPORTED
Exploit maturityTECHNICAL DETAILS
VelocitySTABLE
VTP threat16.6/ 100
44
Issabel Foundation·Issabel Framework

CVE-2026-89026

The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowing unauthenticated remote attackers to forge valid bearer tokens. Attackers can use the forged token to call the manager originate endpoint with the System application parameter, causing Asterisk to execute arbitrary OS commands as the Asterisk user. Exploitation evidence was first observed by the Shadowserver Foundation on 2026-09-09.

Public exploitationREPORTED
Exploit maturityTECHNICAL DETAILS
VelocitySTABLE
VTP threat16.6/ 100
45
·

CVE-2026-76440

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76440 are related to path traversal issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-23.

Public exploitationREPORTED
Exploit maturityTECHNICAL DETAILS
VelocitySTABLE
VTP threat16.6/ 100