CISA Adds Zyxel Switch Buffer Overflow to Known Exploited Vulnerabilities Catalog
CISA added CVE-2026-7273, a stack-based buffer overflow in Zyxel GS1900 switches, to its Known Exploited Vulnerabilities Catalog after evidence of active exploitation.
Category
122 published analyses.
CISA added CVE-2026-7273, a stack-based buffer overflow in Zyxel GS1900 switches, to its Known Exploited Vulnerabilities Catalog after evidence of active exploitation.
CISA has issued an alert about active exploitation of three Linux kernel vulnerabilities, including one critical severity flaw affecting Linux systems.
CISA has added three critical Linux kernel vulnerabilities with active exploit evidence to its Known Exploited Vulnerabilities catalog, including a severe TLS receive path flaw scored 9.8.
A critical unauthenticated remote code execution vulnerability (CVE-2026-58138) in Orkes Conductor affecting versions prior to 3.30.2 is actively exploited and presents severe security risks.
CISA has identified two Linux Kernel vulnerabilities, CVE-2025-39964 and CVE-2026-53266, as actively exploited and added them to its Known Exploited Vulnerabilities Catalog, urging high-priority remediation.
Check Point Software disclosed and patched a critical vulnerability enabling attackers to execute code as root on management systems, risking full enterprise system compromise.
A high-severity authentication vulnerability in Mitsubishi Electric GX Works3 and its Motion Control Settings allows local attackers to bypass password checks and manipulate control programs.
A critical heap overflow vulnerability in Unbound DNSSEC validator before version 1.26.1 allows remote code execution via malicious DNS zones.
Multiple critical vulnerabilities with CVSS scores up to 9.9 impact Hitachi Energy's FACTS Control Platform, risking confidentiality, integrity, and availability in energy sector control systems.
A critical vulnerability in the Issabel Framework allows unauthenticated remote OS command execution, actively exploited and posing a severe security risk.
CISA reports active exploitation of a critical vulnerability in ConnectWise ScreenConnect that risks unauthorized remote access.
CISA warns that ransomware gangs have begun exploiting a critical remote code execution vulnerability in VMware vCenter that was patched in July.
Two critical vulnerabilities in mySCADA myPRO Manager allow unauthenticated attackers to access privileged management functions and send arbitrary SMS via connected GSM modems, affecting versions through 2.1.
CISA has listed CVE-2026-76461, a SQL injection flaw in Cisco Secure Email Gateway, as actively exploited and requires urgent remediation by federal agencies.
Microsoft released out-of-band updates to address Remote Desktop Services failures and issues affecting Hyper-V and USB audio on certain Windows versions.
The Dutch Nationaal Cyber Security Centrum warns of imminent exploitation of critical vulnerabilities CVE-2026-85102 and CVE-2026-85103 affecting Check Point VPN appliances.
Attackers exploit chained critical vulnerabilities in JFrog Artifactory to bypass authentication, gain admin access, and deploy Rust-based backdoors on self-hosted servers.
GitLab issued patches for a critical CVSS 10.0 path traversal flaw in its repository commits API that allows unauthenticated file reads and is being actively probed in the wild.
CISA has listed two critical actively exploited MikroTik RouterOS vulnerabilities in its Known Exploited Vulnerabilities Catalog, highlighting the need for prioritized remediation.
Two patched vulnerabilities in Cisco Secure Firewall Management Center are actively exploited by ransomware gangs and state-sponsored hackers, threatening critical network security infrastructure.
Cisco has confirmed active exploitation of a critical authentication bypass vulnerability (CVE-2026-20079) in its Secure Firewall Management Center software, risking enterprise defenses.
Microsoft's September 2026 Patch Tuesday addresses 966 vulnerabilities including two actively exploited zero-day flaws.
N-able has released an emergency hotfix for a critical remote code execution vulnerability in its N-central RMM platform that is actively exploited.
MikroTik released a patch for an SSH authentication bypass vulnerability currently exploited to create unauthorized accounts on devices.
Broadcom patched two vulnerabilities in VMware Workstation and Fusion, including a critical integer overflow allowing local VM admins to execute arbitrary host code.
CISA has added CVE-2026-85046, a type confusion vulnerability in Google Chromium V8, to its Known Exploited Vulnerabilities Catalog due to active exploitation, requiring urgent attention for remediation.
Attackers are actively exploiting a critical authentication bypass vulnerability in Citrix NetScaler, significantly impacting enterprise security.
Cisco released a patch for a critical vulnerability in Silicon One-based Nexus 9000 switches that allows unauthenticated remote code execution as root, identified as CVE-2026-20212 with a 9.8 CVSS score.
A critical vulnerability (CVE-2026-32475) in Elementor Pro is actively exploited to deliver webshells and execute commands on WordPress servers.
Two zero-day vulnerabilities in SonicWall SMA 1000 VPN appliances, including a critical pre-authentication SSRF flaw, are being exploited in the wild.
Attackers are actively exploiting CVE-2026-82329, a critical authentication bypass in JFrog Artifactory, shortly after its public disclosure and patch release.
An unauthenticated remote code execution vulnerability in Langflow is exploited to steal sensitive OpenAI and AWS credentials, posing substantial risks to cloud and AI security.
A critical vulnerability in the GiveWP donation plugin for WordPress allows unauthenticated attackers to execute arbitrary commands on the hosting server.
A critical vulnerability in cPanel & WHM's domain parking and addon domain features enables a hosting customer to gain root access, posing a significant threat to server security.
A critical ownCloud vulnerability tracked as CVE-2023-49105 has been added to CISA's KEV catalog following exploitation by a Chinese-speaking threat actor targeting a Philippine nuclear research organization.
PaperCut released a second emergency patch addressing two actively exploited vulnerabilities in its NG and MF print management software after initial mitigations were bypassed.
ServiceNow fixed four security flaws in its AI Platform, including three critical CVSS 10.0 vulnerabilities that allow unauthenticated code execution and SQL injection.
Multiple critical vulnerabilities in Xiiaozet LK100W devices could allow attackers to remotely gain full control, with version 2.1.240 addressing these risks.
A critical zero-day vulnerability in all versions of PaperCut NG and MF print management software is actively exploited in attacks, affecting organizations using these products.
A critical zero-click remote code execution vulnerability in the Avada WordPress theme allows unauthenticated attackers to execute arbitrary PHP code on affected servers.
Attackers are actively exploiting a critical code injection vulnerability in Gitea, a widely used self-hosted Git service, prompting warnings from U.S. CISA.
Multiple critical vulnerabilities in Ebyte NE2-D11 devices allow unauthorized administrative access, data exposure, and operational disruption, affecting critical infrastructure controls.
Over 270 Zimbra Collaboration Suite servers have been breached through exploitation of a critical remote code execution vulnerability, exposing organizations to significant security risks.
CISA has added CVE-2026-21962, an Oracle HTTP Server and WebLogic Server Proxy Plug-in vulnerability, to its Known Exploited Vulnerabilities Catalog due to active exploitation.
A critical vulnerability rated 9.1 CVSS in Keycloak allows unauthenticated attackers to hijack user accounts by forcing password resets, with patches released by Red Hat and the Keycloak project.
A critical code injection vulnerability in GitLab, CVE-2026-19478, is actively exploited shortly after disclosure, enabling unauthenticated attackers to modify or delete certain publicly accessible projects.
CISA added CVE-2026-73570, an OS command injection vulnerability in Zimbra Collaboration Suite, to its Known Exploited Vulnerabilities Catalog after active exploitation was observed.
Microsoft released a patch for a critical vulnerability in Entra ID that is actively exploited in targeted attacks, affecting identity and access management security.
CISA has included two actively exploited TrueConf Server vulnerabilities in its Known Exploited Vulnerabilities Catalog, emphasizing critical risks to federal agencies and beyond.
CISA warns that threat actors are actively exploiting a critical vulnerability in the MLflow AI engineering platform, posing risks to federal agencies and beyond.
Citrix has patched critical authentication bypass vulnerabilities affecting NetScaler ADC and Gateway, impacting specific FIPS and NDcPP builds used on gateway and AAA servers.
US government agencies warn of an active cyber threat exploiting Siemens S7 Series programmable logic controllers using AI-assisted scripts, risking critical infrastructure disruption and safety.
CISA warns of active exploitation of a critical remote code execution vulnerability in the Windows Internet Key Exchange Service Extensions, enabling attacker code execution without user interaction.
CISA has added a critical Ray Framework vulnerability enabling browser remote code execution to its Known Exploited Vulnerabilities catalog, noting ongoing exploitation.
CISA confirms ransomware groups are actively exploiting a high-severity Windows Task Host vulnerability, posing increased risk to enterprise environments.
CISA added the actively exploited Ray-Project code injection vulnerability CVE-2025-62593 to its Known Exploited Vulnerabilities catalog, highlighting urgent remediation needs.
CVE-2026-54121 enables a standard domain user to escalate privileges by exploiting an Enterprise Certificate Authority to become a Domain Controller, exposing risks in PKI infrastructure trust models.
A high-severity out-of-bounds read vulnerability in Siemens Parasolid parsing X_T files allows potential arbitrary code execution, affecting versions prior to V38.0.235 and V38.1.230.
Two medium-to-high severity vulnerabilities in Johnson Controls Airwall could allow attackers to decrypt sensitive data and read arbitrary files, impacting critical infrastructure security.
A maximum-severity remote code execution vulnerability in SAP Commerce Cloud patched just three days ago is now actively exploited, posing a critical security risk.
Siemens patched a critical remote code execution vulnerability in multiple versions of its Siveillance Video Management Servers that threatens critical infrastructure.
Threat actors are exploiting the critical directory traversal vulnerability CVE-2026-59310 in VMware vCenter, enabling remote code execution and requiring immediate attention from defenders.
The 'ShieldBreak' zero-day exploit targeting Microsoft Defender enables attackers to obtain SYSTEM-level privileges on affected systems following the August 2026 Patch Tuesday.
A critical SharePoint vulnerability (CVE-2026-55040) enables unauthenticated remote code execution, facilitated by AI, affecting several SharePoint Server versions.
Cisco alerts on a high-severity denial-of-service vulnerability in Secure Firewall ASA and Threat Defense VPN software actively exploited to crash devices, threatening enterprise network stability.
Microsoft's August 2026 Patch Tuesday addresses 400 security flaws, including one actively exploited zero-day and two publicly disclosed zero-day vulnerabilities.
CISA has added CVE-2026-8037, a critical Progress LoadMaster command injection vulnerability actively exploited in the wild, to its Known Exploited Vulnerabilities Catalog, requiring prioritized remediation by federal agencies under BOD 26-04.
A critical zero-day SQL injection vulnerability in Metabase has been exploited to breach customer instances, impacting Framework and Tally by enabling data theft.
Cisco released patches for 12 critical vulnerabilities in Catalyst SD-WAN and IOS XE software impacting devices in all configurations.
High-severity vulnerabilities in ABB Ability Zenon IIoT services using MongoDB 4.2 allow unauthorized access, denial of service, and potential data compromise.
HashiCorp, Veeam, and the Django Software Foundation released patches for 11 vulnerabilities, including a critical CVSS 10.0 cross-tenant bug affecting Terraform MCP Server, Veeam Service Provider Console, and Django software.
A critical vulnerability in cPanel (CVE-2026-58048) allowed authenticated hosting customers to execute SQL commands with root database privileges, risking full database control.
A high-severity vulnerability in Thermo Fisher Applied Biosystems Genetic Analyzers allows modification of DNA data output files, risking inaccurate test results in healthcare settings.
CISA added CVE-2026-18577, an authentication bypass vulnerability in N-able N-central, to its Known Exploited Vulnerabilities Catalog due to active exploitation, prioritizing federal agency remediation under BOD 26-04.
A firmware vulnerability in Coldcard hardware wallets enabled attackers to steal approximately $70 million in Bitcoin by draining over 1,000 addresses in under an hour.
Adobe Campaign Classic includes a critical CVSS 10.0 vulnerability (CVE-2026-48449) that allows arbitrary code execution without user interaction.
A critical vulnerability in Azure Cosmos DB enabled attackers to escape the Gremlin query sandbox and gain full read/write access to multiple customer databases.
JetBrains disclosed a critical authentication bypass vulnerability in TeamCity On-Premises that enables remote code execution, posing significant risk to enterprise environments.
Cisco disclosed a high-severity zero-day vulnerability in its Secure Firewall Management Center involving static credentials, actively exploited to gain unauthorized access.
A critical Active Storage vulnerability in Ruby on Rails allows unauthenticated attackers to read arbitrary server files through malicious image uploads, risking exposure of sensitive data.
A critical vulnerability in the Ruflo open-source agent platform allows unauthenticated remote code execution and poisoning of AI memory, posing significant risks to AI model operations.
Broadcom published updates for critical VMware vulnerabilities in ESX, vCenter, Workstation, and Fusion enabling authentication bypass and VM escape with high severity.
Arista released a patch for a critical command injection zero-day vulnerability currently exploited in on-premises VeloCloud Orchestrator deployments, affecting enterprise network management.
A critical stack buffer overflow in OpenSSL affects Siemens Desigo CC versions V7, V8, and V9 before 9.0.1, posing risks of remote code execution or denial of service.
A critical DHCPv6 stack overflow vulnerability in OpenWrt's default network service odhcpd allows unauthenticated remote root code execution.
A zero-day remote code execution vulnerability in the FastJson Java library is actively exploited by hackers against US organizations, posing a critical threat to enterprise applications.
A critical pre-authentication remote code execution vulnerability in vBulletin forum software has been patched following the public release of an exploit, enabling unauthenticated attackers to execute arbitrary PHP code.
Attackers are exploiting a critical remote code execution vulnerability in Fastjson 1.x used in Spring Boot applications, enabling unauthenticated code execution with Java process privileges and no patch currently available.
The Certighost exploit enables low-privileged Active Directory users to obtain Domain Controller certificates and authenticate as domain controllers, risking critical Kerberos credential compromise.
A crafted SVG submitted to Bing image search can execute commands as NT AUTHORITY\SYSTEM on Microsoft’s production servers, impacting multiple hosts with critical security implications.
Multiple high-severity vulnerabilities in Weintek cMT3092X HMI may allow attackers to escalate privileges and steal credentials, impacting critical manufacturing environments.
CISA has added CVE-2026-16232 and CVE-2026-50522 to its Known Exploited Vulnerabilities Catalog following evidence of active exploitation targeting Check Point SmartConsole and Microsoft SharePoint.
CISA has mandated U.S. federal agencies to urgently address a remote code execution vulnerability actively exploited in Langflow, posing critical risks to infrastructure security.
A critical authentication bypass vulnerability in Tycon Systems TPDIN-Monitor-WEB2 allows unauthenticated attackers full administrative control, risking critical infrastructure disruptions.
Microsoft patched a critical SharePoint Server vulnerability, CVE-2026-50522, now actively exploited after a public proof-of-concept was released, enabling remote code execution via deserialization of untrusted data.
A critical SQL injection vulnerability identified as CVE-2026-63030 affects WordPress Core and is actively exploited, allowing unauthenticated remote code execution.
F5 released patches for CVE-2026-42533, a critical nginx flaw allowing remote, unauthenticated attackers to trigger a heap buffer overflow that can crash workers or enable remote code execution.
A zero-day vulnerability named LegacyHive enables privilege escalation on fully updated Windows systems, allowing attackers to gain admin-level access.
CISA has directed federal agencies to urgently patch two actively exploited vulnerabilities in Fortinet FortiSandbox, highlighting critical risks to government and enterprise environments.
A critical vulnerability in WordPress core enables unauthenticated attackers to execute code on default installations, prompting urgent patch releases.
CISA issued a warning about three actively exploited vulnerabilities in Internet-exposed on-premises SharePoint Server instances that allow remote compromise.
Zoom has disclosed a critical vulnerability in its Windows desktop client and SDK that enables unauthenticated attackers to hijack user accounts, posing a significant security risk.
Microsoft released its largest Patch Tuesday, addressing 622 security flaws including two actively exploited zero-day vulnerabilities, critical for millions of affected systems.
SAP released updates fixing a critical CVSS 9.9 out-of-bounds write vulnerability in NetWeaver ABAP that may allow authenticated attackers to corrupt memory and manipulate data.
SonicWall disclosed two critical zero-day vulnerabilities in SMA1000 devices being exploited in active attacks, highlighting urgent risk to enterprise network security.
CISA warns that remote code execution vulnerabilities are actively exploited in Joomla iCagenda and Balbooa Forms extensions through arbitrary file uploads, risking full compromise of affected sites.
Progress Software advises ShareFile customers to shut down Windows servers running Storage Zone Controllers due to a credible security threat, disabling account access as a precaution.
OpenPLC v3 contains a critical authenticated arbitrary file write vulnerability that can lead to native code execution through compiling malicious files. This affects critical infrastructure sectors worldwide and requires urgent mitigation.
Researchers tested 281 popular free Android VPN apps and discovered many leak user traffic, transmit unencrypted data, and include tracking. These apps, collectively installed over 2.4 billion times, fail to meet basic privacy and security standards.
Ubiquiti released updates to fix critical vulnerabilities in UniFi Connect, Talk, Access, Protect, and OS. These flaws could allow privilege escalation and arbitrary command execution.
Threat actors are actively attempting to exploit a critical vulnerability in Gitea Docker images less than two weeks after it was patched. The flaw allows unauthenticated clients to escalate privileges by abusing the 'X-WEBAUTH-USER' header.
A critical use-after-free flaw in Linux's KVM hypervisor allows guest VMs on Intel and AMD systems to corrupt host kernel memory, potentially escaping the virtual environment. The vulnerability, known as Januscape (CVE-2026-53359), includes a public PoC that crashes hosts with a more impactful exploit reportedly in development.
A critical Adobe ColdFusion vulnerability, CVE-2026-48282, is now being actively exploited in cyberattacks, according to KEVIntel. This flaw demands immediate attention due to its maximum severity rating.
A new Linux kernel vulnerability, Bad Epoll (CVE-2026-46242), allows unprivileged users to escalate to root, impacting Linux desktops, servers, and Android devices. A patch has already been released.
Security firm runZero disclosed seven vulnerabilities in FatFs, a widely used filesystem library in embedded devices including security cameras and drones. These flaws pose a risk due to FatFs's ubiquity in consumer and industrial firmware.
Attackers have started exploiting a critical CVE-2026-46817 vulnerability in the Oracle E-Business Suite financial application, as reported by Defused. This flaw poses significant risk to enterprises using Oracle EBS.
Hackers are actively exploiting a critical vulnerability in SimpleHelp (CVE-2026-48558) to distribute Djinn Stealer, a new cross-platform information stealer targeting Windows, macOS, and Linux. This campaign represents a novel threat leveraging an undocumented malware strain.
CISA has set a Sunday deadline for federal agencies to patch a critical vulnerability in Cisco Unified Communications Manager Server actively exploited in attacks. Immediate action is urged to prevent further compromise.
CISA has issued a warning about an actively exploited critical code injection vulnerability, CVE-2025-67038, affecting Lantronix EDS5000 Series devices. Federal agencies are urged to apply patches by June 26, 2026, to prevent potential remote code execution.
CISA has issued a warning about hackers actively exploiting severe vulnerabilities in Ubiquiti UniFi OS and Lantronix serial-to-ethernet servers. These flaws carry a maximum severity rating and pose significant risk to affected organizations.
Mandiant has exposed how attackers exploited a zero-day CVE-2026-20245 in Cisco Catalyst SD-WAN to create rogue root accounts on devices, raising serious security concerns. This vulnerability enables full control of targeted network appliances, potentially impacting enterprise operations.
A high-severity Server-Side Request Forgery vulnerability in Cisco Unified Communications Manager Server, tracked as CVE-2026-20230, is actively being exploited in the wild. Security teams should prioritize detection and mitigation to prevent potential compromise.