Vulnerability threat dossier

CVE-2026-20079

ciscosecure firewall management center

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.  This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow root access to the device. 

VTP deterministic threat72.1of 100 · CVSS excluded

VTP analyst assessment

Cisco FMC authentication bypass can yield root access

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateCANDIDATE CREATED
AI priorityCRITICAL
AI confidence95%
Public exploitation · VTP factKEV

Assessment

CVE-2026-20079 affects Cisco Secure Firewall Management Center web interfaces. An unauthenticated remote attacker can bypass authentication and execute script files through an improper boot-time process, obtaining root access. CISA KEV records global exploitation.

Why it matters

  • FMC manages security infrastructure, so compromise could give an attacker control over a high-value management plane.
  • Press reporting describes exploitation and zero-day use, while CISA KEV confirms exploitation globally.

Evidence

3 record references and 2 source references passed trusted post-response validation. The current deterministic record contains 2 independent evidence groups.

Uncertainties

The mapped press reporting does not identify the affected customer environments or exploit chain.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

If you use affected Cisco FMC releases, apply Cisco's security update immediately.

AI baseline history (16)
  1. BASELINE ASSESSED
    Cisco FMC authentication bypass can yield root accessgpt-5.6-terra · low
  2. BASELINE ASSESSED
    Cisco FMC authentication bypass and root accessgpt-5.6-terra · low
  3. BASELINE ASSESSED
    Cisco FMC authentication bypass is known exploitedgpt-5.6-terra · low
  4. BASELINE ASSESSED
    Cisco FMC authentication bypass with root accessgpt-5.6-terra · low
  5. BASELINE ASSESSED
    Cisco FMC authentication bypass to rootgpt-5.6-terra · low
  6. BASELINE ASSESSED
    Cisco FMC authentication bypass and root accessgpt-5.6-terra · low
  7. BASELINE ASSESSED
    Cisco FMC authentication bypass with reported exploitationgpt-5.6-terra · low
  8. BASELINE ASSESSED
    Cisco FMC authentication bypass with root accessgpt-5.6-terra · low
  9. BASELINE ASSESSED
    Cisco FMC authentication bypass is known exploitedgpt-5.6-terra · low
  10. BASELINE ASSESSED
    Cisco FMC authentication bypass under active attackgpt-5.6-terra · low
  11. BASELINE ASSESSED
    Cisco FMC authentication bypass with root accessgpt-5.6-terra · low
  12. BASELINE ASSESSED
    Cisco Secure Firewall Management Center authentication bypassgpt-5.6-terra · low
  13. BASELINE ASSESSED
    Cisco Secure FMC authentication bypassgpt-5.6-terra · low
  14. BASELINE ASSESSED
    Cisco FMC authentication bypass with reported attacksgpt-5.6-terra · low
  15. BASELINE ASSESSED
    Critical Cisco FMC authentication bypassgpt-5.6-terra · low
  16. BASELINE ASSESSED
    Cisco FMC unauthenticated authentication bypass to rootgpt-5.6-sol · high

Previous AI priority: CRITICAL → current: CRITICAL. Inspect the evidence preserved for each run before treating this as a threat transition.

Technical severityCRITICALCVSS 10.0 · technical context
Public exploitationKEVGlobal public evidence
Exploit maturityPOCReliability not implied
EPSS0.88100th percentile · prediction
Evidence confidence95%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    CISA KEV lists this vulnerability as known to be exploited globally.

  2. 02

    A proof of concept is reported; functional reliability is not established.

  3. 03

    2 independent sources support material claims.

  4. 04

    EPSS is 0.88; this is predictive context, not exploitation evidence.

  5. 05

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

RESEARCH PUBLICATIONNew technical research
EPSS MATERIAL INCREASEEPSS changed materially from 0.36 to 0.75
RESEARCH PUBLICATIONNew technical research
ACTIVE EXPLOITATIONActive Exploitation
EXPLOIT TEMPLATE AVAILABLEPublic exploit-oriented template available
RESEARCH PUBLICATIONNew technical research
ACTIVE EXPLOITATIONENISA EU KEV entry added
03

Claim provenance

Evidence and source independence

18publications detected
18underlying evidence chains

4 primary sources · 0 dependent secondary reports · 12 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimEXPLOITATION REPORTEDPUBLICATION REPORTS EXPLOITATION
60%claim confidence
UNKNOWNreport:3efb05e0937b9d9a104b4559ec7e82f05f85a2d234a15475c35932ae847f0393ACTIVE
Evidence
Source claimZERO DAYPUBLICATION REPORTS ZERO DAY
64%claim confidence
UNKNOWNreport:3b3366899fc0ff5fe16f5e1cffd57049d2a18ac70347d40ab993104558f71fbcACTIVE
Evidence
Source claimEXPLOITATION REPORTEDPUBLICATION REPORTS EXPLOITATION
60%claim confidence
UNKNOWNreport:3b3366899fc0ff5fe16f5e1cffd57049d2a18ac70347d40ab993104558f71fbcACTIVE
Evidence
Source claimEXPLOITATION REPORTEDPUBLICATION REPORTS EXPLOITATION
60%claim confidence
UNKNOWNreport:9a6ed2932804f1649c85753b3b86a70ba08b4610d63e4b09db684632f6ffff9fACTIVE
Evidence
Source claimACTIVE EXPLOITATIONSOURCE REPORTS ACTIVE EXPLOITATION
82%claim confidence
INDEPENDENTreport:743f6277d97825230a0a39155c8353593c65ce176599758789af331d710ca566ACTIVE
Evidence
Source claimEXPLOITATION REPORTEDPUBLICATION REPORTS EXPLOITATION
60%claim confidence
UNKNOWNreport:ecf9519e430f07f4204572b1c269a6aee87e5c8388c9763aeb9536fb1d35a26eACTIVE
Evidence
Source claimEXPLOITATION REPORTEDPUBLICATION REPORTS EXPLOITATION
60%claim confidence
UNKNOWNreport:498384f7820683fca71b05ea1f56c44a1be5a049a1583e93b08f98fbd8f3a8d7ACTIVE
Evidence
Source claimZERO DAYPUBLICATION REPORTS ZERO DAY
64%claim confidence
UNKNOWNreport:15985fc0a5354500b49760f4374da54b2950399c2ccd545b66afe4cff54322daACTIVE
Evidence
Source claimEXPLOITATION REPORTEDPUBLICATION REPORTS EXPLOITATION
60%claim confidence
UNKNOWNreport:15985fc0a5354500b49760f4374da54b2950399c2ccd545b66afe4cff54322daACTIVE
Evidence
Source claimEXPLOITATION REPORTEDPUBLICATION REPORTS EXPLOITATION
60%claim confidence
UNKNOWNreport:9aad1d53c5c41600b7eb6cb7c99ee2f8b655e84a84ecf4c1426a56096d5eecd7ACTIVE
Evidence
Source claimEXPLOIT TEMPLATE AVAILABLEPUBLIC EXPLOIT TEMPLATE
90%claim confidence
PRIMARYcorpus:METASPLOIT:e3d30c45cb4d92c009c5db75eac048d57fdfc42cACTIVE
Evidence
Source claimACTIVE EXPLOITATIONENISA EU KEV LISTED
95%claim confidence
INDEPENDENTcatalog:enisa-eu-kev:CVE-2026-20079ACTIVE
Evidence
04

Event history

Threat timeline

  1. 12:1717 Sept
    EXPLOITATION REPORTED

    Exploitation Reported

    SecurityWeek supplied a deterministically extracted signal; review the linked evidence before escalation.

  2. 07:3115 Sept
    EXPLOITATION REPORTED

    Exploitation Reported

    BleepingComputer supplied a deterministically extracted signal; review the linked evidence before escalation.

  3. 07:3115 Sept
    ZERO DAY

    Zero Day

    BleepingComputer supplied a deterministically extracted signal; review the linked evidence before escalation.

  4. 20:3614 Sept
    EXPLOITATION REPORTED

    Exploitation Reported

    BleepingComputer supplied a deterministically extracted signal; review the linked evidence before escalation.

  5. 13:3511 Sept
    RESEARCH PUBLICATION

    New technical research

    Rapid7 Research published evidence linked to CVE-2026-20079.

  6. 07:2211 Sept
    EPSS MATERIAL INCREASE

    EPSS changed materially from 0.36 to 0.75

    Predictive context changed; this is not exploitation evidence.

  7. 18:0010 Sept
    RESEARCH PUBLICATION

    New technical research

    Cisco Talos published evidence linked to CVE-2026-20079.

  8. 18:0010 Sept
    ACTIVE EXPLOITATION

    Active Exploitation

    Cisco Talos supplied a deterministically extracted signal; review the linked evidence before escalation.

  9. 15:4310 Sept
    EXPLOITATION REPORTED

    Exploitation Reported

    BleepingComputer supplied a deterministically extracted signal; review the linked evidence before escalation.

  10. 10:3610 Sept
    EXPLOITATION REPORTED

    Exploitation Reported

    The Hacker News supplied a deterministically extracted signal; review the linked evidence before escalation.

  11. 10:0610 Sept
    EXPLOITATION REPORTED

    Exploitation Reported

    SecurityWeek supplied a deterministically extracted signal; review the linked evidence before escalation.

  12. 10:0610 Sept
    ZERO DAY

    Zero Day

    SecurityWeek supplied a deterministically extracted signal; review the linked evidence before escalation.

  13. 21:4009 Sept
    EXPLOITATION REPORTED

    Exploitation Reported

    BleepingComputer supplied a deterministically extracted signal; review the linked evidence before escalation.

  14. 20:0509 Sept
    EXPLOIT TEMPLATE AVAILABLE

    Public exploit-oriented template available

    Rapid7 Metasploit Framework published new or materially changed exploit-oriented tooling for this CVE. This is availability evidence, not evidence of exploitation in the wild.

  15. 16:0809 Sept
    RESEARCH PUBLICATION

    New technical research

    Cisco Talos published evidence linked to CVE-2026-20079.

  16. 00:0009 Sept
    ACTIVE EXPLOITATION

    ENISA EU KEV entry added

    ENISA EU KEV reports known exploitation. This is public intelligence, not a VTP sensor observation.

  17. 00:0009 Sept
    KEV ADDED

    CISA KEV entry added

    CISA lists global known exploitation. This is not a VTP sensor observation.

  18. 14:3705 Aug
    VENDOR ADVISORY

    New vendor advisory

    Cisco Product Security Incident Response Team published evidence linked to CVE-2026-20079.

  19. 13:5815 Apr
    EXPLOIT SOURCE UPDATE

    New exploit-source update

    ProjectDiscovery Nuclei Templates Releases published evidence linked to CVE-2026-20079.

05

Original publications

Source record

InfraTrust report warns network management systems under attack

Attackers are increasingly targeting the management systems used to control enterprise infrastructure, with several critical vulnerabilities actively exploited before or shortly after vendors disclosed them. [...]

CVE-2026-20079CVE-2026-20212CVE-2026-20293CVE-2026-20316CVE-2026-31431CVE-2026-33197CVE-2026-6485CVE-2026-73453CVE-2026-73456CVE-2026-76460CVE-2026-83548CVE-2026-83549CVE-2026-85102CVE-2026-85103CVE-2026-91843
Separate evidence group
Original

ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories

Attackers keep finding new keys. The funny part is that defenders keep inventing where to store them. This week, those keys sit in AI tools, exposed services, old bugs, weak logins, and software sold like a monthly subscription. Some attacks use new tricks. Others just reuse what was already lying around. Both work often enough. So the threat landscape is not getting cleaner. It is just

CVE-2026-20079CVE-2026-20316CVE-2026-59310
Separate evidence group
Original

Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard

The vulnerabilities may lead to root access, command execution, bypasses, SQL injection, and remote code execution. The post Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard appeared first on SecurityWeek .

CVE-2026-20079CVE-2026-20282CVE-2026-20283CVE-2026-20284CVE-2026-20316CVE-2026-20332
Separate evidence group
Original

Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.  This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow  root access to the device.  Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2 This advisory is part of the March 2026 release of the Cisco Secure Firewall ASA, Secure FMC, and Secure FTD Software Security Advisory Bundled Publication. For a complete list of the advisories and links to them, see  Cisco Event Response: March 2026 Semiannual Cisco Secure Firewall ASA, Secure FMC, and Secure FTD Software Security Advisory Bundled Publication . <br/>Security Impact Rating: Critical <br/>CVE: CVE-2026-20079

CVE-2026-20079
Separate evidence group
Original

Cisco patches Secure Email Gateway zero-day exploited in attacks

Cisco warned customers to patch a critical Secure Email Gateway zero-day security flaw that threat actors have been exploiting in attacks. [...]

CVE-2025-20393CVE-2026-20079CVE-2026-20353CVE-2026-76440CVE-2026-76441CVE-2026-76443CVE-2026-76461
Separate evidence group
Original

Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation

An unauthenticated attacker can exploit CVE-2026-76461 to execute arbitrary commands on the underlying OS with root privileges. The post Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation appeared first on SecurityWeek .

CVE-2025-20393CVE-2026-20079CVE-2026-20316CVE-2026-76461
Separate evidence group
Original

Japan's Digital Agency says VPN flaw exposed 246,000 personnel records

Japan's Digital Agency has discovered a data breach that may have exposed around 246,000 record rows containing personal information of government employees. [...]

CVE-2026-20079
Separate evidence group
Original

Metasploit Wrap Up: This One Goes to Sixteen!

This One Goes to Sixteen! Another banger from Metasploit with sixteen new modules, including ten exploit modules, with five on the CISA KEV list. Cisco, Papercut, Sonicwall, Jetbrains, and Langflow all have exploit modules, and not to be outdone, we even have a Metasploit scanner to watch the watchers! New module content (16) Elasticsearch ingest-attachment Apache Tika XFA XXE Local File Read Authors: Bourbon Offensive Security Services and Jean-Marie Bourbon Type: Auxiliary Pull request: #21739 contributed by kmkz Path: scanner/http/elasticsearch_tika_xfa_xxe CVE reference: CVE-2025-66516 Description: Adds an auxiliary scanner module for CVE-2025-54988/CVE-2025-66516. The module validates an XML External Entity (XXE) vulnerability in Apache Tika's XFA parser exposed through the Elasticsearch attachment ingest processor. SPIP Unauthenticated Blind SQLi via Date Field Escaping Bypass Authors: Benoit Hua, Franck Chevalier, Julien Voisin, and ka3n1x Type: Auxiliary Pull request: #21791 contributed by jvoisin Path: scanner/http/spip_annee_sqli Description: Adds modules/auxiliary/scanner/http/spip_annee_sqli.rb which exploits a blind SQL injection in SPIP's date column escaping logic. Metasploit Payload Handler Detection (TCP/UDP/HTTP/HTTPS) Author: h00die Type: Auxiliary Pull request: #21551 contributed by h00die Path: scanner/msf/handler_detect Description: Adds a scanner module to enumerate ports on a host and determine if they're a Metasploit Reverse Handler or not, and if they are, what kind of shell they were going to land. ESC8 Relay: SMB to HTTP(S) via Kerberos Author: Pushpender Rathore Type: Auxiliary Pull request: #21709 contributed by Pushpenderrathore Path: server/relay/esc8_kerberos CVE reference: CVE-2026-20929 Description: This introduces native Kerberos authentication relay capabilities to the framework's relay stack. It includes a new auxiliary module (esc8_kerberos) that exploits CVE-2026-20929 by targeting AD CS Web Enrollment (ESC8). The module captures an SMB2 AP-REQ from a coerced client and seamlessly replays the authentication to the target certificate server over HTTP. This chain ultimately allows an attacker to issue a certificate for the coerced victim and obtain a valid Kerberos TGT without requiring their credentials. Linux x64 Sandbox Environment Gate Author: Massimo Bertocchi Type: Evasion Pull request: #21642 contributed by litemars Path: linux/x64/sandbox_gate Description: Adds a Linux x64 sandbox‑evasion module that performs lightweight runtime environment checks and aborts execution when a likely sandbox or VM is detected. Cisco Secure Firewall Management Center Authentication Bypass RCE Authors: Arian Eidizadeh, Brandon Sakai, and Cale Black Type: Exploit Pull request: #21796 contributed by CyberAuth Path: linux/http/cisco_fmc_auth_bypass_rce CVE reference: CVE-2026-20079 Description: Adds a native Metasploit exploit module for CVE-2026-20079, an unauthenticated authentication bypass in Cisco Secure Firewall Management Center (FMC). SonicWall SMA1000 WorkPlace SSRF to Root Remote Code Execution Authors: Adam Babis, William Perry, and sfewer-r7 Type: Exploit Pull request: #21883 contributed by sfewer-r7 Path: linux/http/sonicwall_sma1000_couchdb_rce CVE reference: CVE-2026-83549 Description: This adds an exploit module for the recent SonicWall SMA1000 zero-day exploit chain that was disclosed in the first week of September as being exploited in-the-wild. CVE-2026-83548 is an SSRF used to bypass auth. SMA1000-9427 is an RCE with low privileges via CouchDB read/write primitives. CVE-2026-83549 is a command injection in cmsSnmpTrap.sh for RCE with root privs. The patched version 12.5.0-02952 has been verified to successfully remediate this exploit chain. JetBrains TeamCity Agent Polling Unauthenticated Remote Code Execution Authors: Antoni Tremblay and sfewer-r7 Type: Exploit Pull request: #21775 contributed by sfewer-r7 Path: multi/http/jetbrains_teamcity_rce_cve_2026_63077 CVE reference: CVE-2026-

CVE-2025-54988CVE-2025-66516CVE-2026-19295CVE-2026-20079CVE-2026-20929CVE-2026-23744CVE-2026-48558CVE-2026-63077CVE-2026-75604CVE-2026-81578CVE-2026-82078CVE-2026-83548CVE-2026-83549
Separate evidence group
Original

Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware

Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities. The attacks leverage CVE-2026-20079 (CVSS score: 10.0), an authentication bypass vulnerability in the web interface of FMC software that could allow an unauthenticated, remote attacker to bypass

CVE-2026-20079CVE-2026-20316
Separate evidence group
Original

We've got one word for it, and it's usually the wrong one

In this week's Threat Source newsletter, Joe explores why the word "burnout" often fails to capture the true toll of working in the cybersecurity industry and why we need better language to address it.

CVE-2026-20079CVE-2026-20316
Separate evidence group
Original

Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers

Cisco Talos says two recently patched Secure Firewall Management Center (FMC) vulnerabilities have been exploited by three separate threat clusters linked to ransomware and state-sponsored attacks. [...]

CVE-2026-20079CVE-2026-20316
Separate evidence group
Original

CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026. The vulnerabilities are listed below - CVE-2026-20079 (CVSS score: 10.0) - An authentication

CVE-2025-25249CVE-2026-19490CVE-2026-20079
Separate evidence group
Original

Organizations Warned of Cisco Secure FMC Exploitation

Cisco and CISA have flagged exploitation of CVE-2026-20079, a vulnerability disclosed in March 2026. The post Organizations Warned of Cisco Secure FMC Exploitation appeared first on SecurityWeek .

CVE-2026-20079CVE-2026-20131CVE-2026-20316
Separate evidence group
Original

Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks

Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being actively exploited in attacks. [...]

CVE-2026-20079CVE-2026-20316
Separate evidence group
Original

Exploit tooling coverage changed for 1 CVE

Rapid7 Metasploit Framework recorded exploit-tooling coverage changes for 1 CVE in this pinned revision. 1 have an active availability assertion for this revision. Tooling evidence does not establish exploitation in the wild or successful execution.

CVE-2026-20079
Separate evidence group
Original

Active exploitation of Cisco Secure Firewall Management Center vulnerabilities

Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software.

CVE-2026-20079CVE-2026-20316
Separate evidence group
Original

ENISA EU KEV catalog membership for CVE-2026-20079

ENISA EU KEV lists this vulnerability as known to be exploited. This is public intelligence, not a VTP sensor observation.

CVE-2026-20079
Separate evidence group
Original

Nuclei Templates v10.4.2 – Release Notes

New Templates Added: 121 | CVEs Added: 61 | First-time contributions: 15 🔥 Release Highlights 🔥 [ CVE-2026-21643 ] Fortinet FortiClientEMS 7.4.4 - SQL Injection ( @ritikchaddha ) [critical] 🔥 (kev) (vKEV) [ CVE-2026-35616 ] FortiClient EMS - Authentication Bypass ( @ritikchaddha ) [high] 🔥 (kev) (vKEV) [ CVE-2026-39987 ] Marimo <= 0.20.4 - Pre-Auth Terminal WebSocket RCE ( @ritikchaddha ) [critical] 🔥 (vKEV) [ CVE-2025-59528 ] Flowise - Remote Code Execution (@xtr0nix) [critical] 🔥 (vKEV) [ CVE-2026-3584 ] WordPress Kali Forms <= 2.4.9 - Remote Code Execution ( @pussycat0x ) [critical] 🔥 (vKEV) [ CVE-2026-4020 ] Gravity SMTP WordPress Plugin - Sensitive Information Exposure ( @theamanrawat ) [high] 🔥 (vKEV) [ CVE-2026-34197 ] Apache ActiveMQ - Remote Code Execution ( @dhiyaneshdk , @horizon3 ) [critical] 🔥 [ CVE-2026-34156 ] NocoBase - VM Sandbox Escape to Remote Code Execution ( @theamanrawat ) [critical] 🔥 [ CVE-2026-20079 ] Cisco Secure Firewall Management Center - Authentication Bypass ( @theamanrawat ) [critical] 🔥 [ CVE-2026-26980 ] Ghost CMS Content API - SQL Injection ( @domwhewell-sage ) [critical] 🔥 [ CVE-2026-4257 ] WordPress Contact Form by Supsystic - Server-Side Template Injection ( @theamanrawat ) [critical] 🔥 [ CVE-2026-2699 ] Progress ShareFile Storage Zones Controller - Authentication Bypass ( @dhiyaneshdk ) [critical] 🔥 [CVE-2026-33340] LoLLMs WEBUI - Server-Side Request Forgery ( @theamanrawat ) [critical] 🔥 [ CVE-2025-67303 ] ComfyUI-Manager < 3.38 - Configuration Overwrite ( @maciejklimek ) [critical] 🔥 [ CVE-2024-38819 ] Spring Framework Path Traversal in Functional Web Frameworks ( @dhiyaneshdk ) [high] 🔥 What's Changed Bug Fixes Moved CVE-2026-23829 template from incorrect http folder to the network folder (Issue #15633 , PR #15738 ). Fixed CVE-ID mismatches in template metadata (PR #15850 ). Fixed invalid CPE formats across multiple HTTP templates (PR #15751 ). Fixed tag formatting in CVE-2023-38875 , CVE-2025-11307 , CVE-2023-24322 , and CVE-2025-4210 templates (PRs #15897 , #15898 , #15899 , #15900 ). Updated CVE-2023-6825 template to correct detection logic (PR #15877 ). Corrected template author attribution from PentesterTN to 0xBassia (PR #15827 ). False Negatives Fixed false negatives in CVE-2024-8529 (LearnPress SQLi): body matchers were unreliable for blind SQLi responses and a randstr bypass was added to defeat DB query cache (Issue #15768 , PR #15844 ). False Positives Reduced extremely high false positives in credentials-disclosure template caused by over-permissive [\w-]+ value regex with no minimum length enforcement, flagging short UI strings like "ClientSecret":"Client" as credential leaks (Issue #15563 , PR #15845 ). Reduced false positives in the Apache ActiveMQ Artemis Console Default Login template; tightened matcher to require a valid JSON login response with expected artemis username (Issue #15762 , PR #15861 ). Resolved false positives in molgenis-default-login template triggered by JSESSIONID cookies on custom 404 pages (Issue #12603 ). Removed false positive subdomain takeover detection templates for Netlify, Shopify, Azure Azurewebsites, Cloudapp, and Trafficmanager - these services are no longer vulnerable due to enforced TXT verification, deprecation, or claimed namespace blocking (PR #15724 ). Fixed false positive webpack-config detection triggered by SPA catch-all routing (PR #15869 ). Improved CVE-2022-3254 matchers to reduce false positives on HTML error responses (PR #15840 ). Fixed false positives in CVE-2024-52762 (PR #15833 ). Fixed false positives in CVE-2025-49113 (PR #15777 ). Enhancements Refactored matchers in CVE-2024-42009 for improved detection accuracy (PR #15835 ). Added and normalized CWE metadata across HTTP templates (PR #15804 ). Added additional EOL version entries to end-of-life detection templates (PR #15891 ). Updated CVE-2025-30208 detection coverage (PR #15784 ). Templates Added [ CVE-2026-39987 ] Marimo <= 0.20.4 - Pre-Auth Terminal W

CVE-2021-23337CVE-2021-46371CVE-2022-3254CVE-2022-41678CVE-2023-24322CVE-2023-38875CVE-2023-40924CVE-2023-49293CVE-2023-6592CVE-2023-6750CVE-2023-6825CVE-2023-7165CVE-2024-28752CVE-2024-38819CVE-2024-42009CVE-2024-49357CVE-2024-52762CVE-2024-8252CVE-2024-8529CVE-2025-11307CVE-2025-12536CVE-2025-13652CVE-2025-14124CVE-2025-14340CVE-2025-2221CVE-2025-2558CVE-2025-30208CVE-2025-32614CVE-2025-4210CVE-2025-49113CVE-2025-50578CVE-2025-5350CVE-2025-53533CVE-2025-54597CVE-2025-55150CVE-2025-59528CVE-2025-64500CVE-2025-67303CVE-2026-20079CVE-2026-21643CVE-2026-23829CVE-2026-2416CVE-2026-25616CVE-2026-26980CVE-2026-2699CVE-2026-28358CVE-2026-28414CVE-2026-29014CVE-2026-29066CVE-2026-29183CVE-2026-30824CVE-2026-31807CVE-2026-31809CVE-2026-33340CVE-2026-33478CVE-2026-3396CVE-2026-34156CVE-2026-34197CVE-2026-34453CVE-2026-34605CVE-2026-34885CVE-2026-35616CVE-2026-3584CVE-2026-39364CVE-2026-39365CVE-2026-39987CVE-2026-4020CVE-2026-4106CVE-2026-4257CVE-2026-5615CVE-2026-6118CVE-2026-6203
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score72.1vtp-threat-v1-public
Public exploitation30 / 30
EPSS prediction17.64 / 20
Exploit availability7.5 / 15
Source independence15 / 15
Intelligence recency2 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
10 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE
CWE-288
CPE records
72
Deterministic history records
20
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.