the watchlist
| CVE | Type | Severity | Status | Do this | Story |
|---|---|---|---|---|---|
| CVE-2026-87491Google Chrome, all channels prior to 153.0.8010.36/.37 (Windows/macOS) and 153.0.8010.36 (Linux). Fixed in the Chrome 153 stable channel release, rolled out September 8-9, 2026. | Out-of-bounds write in V8, Chrome's JavaScript and WebAssembly engine (medium severity). Loading a rigged webpage can corrupt engine memory and let an attacker run code in the browser process, no download or click beyond the page load itself. | — | exploited | Open chrome://settings/help, confirm the version reads 153.0.8010.36/.37 (Windows/macOS) or 153.0.8010.36 (Linux) or later, then relaunch the browser immediately rather than waiting for the background auto-updater to apply it on its own schedule. | ↗ story |
| CVE-2026-20079Cisco Secure Firewall Management Center (FMC), on-premises software versions affected by the flaw per Cisco advisory cisco-sa-onprem-fmc-authbypass-5JPp45V2. Confirmed under active exploitation by Cisco PSIRT in August 2026, publicly confirmed September 10, 2026. | Authentication bypass leading to unauthenticated remote code execution as root (CVSS 10.0). An improper system process created at boot time leaves a partial session in the sfsnort.sessions database that persists until a user authenticates; an attacker who sends crafted HTTP requests before anyone logs in can upgrade that session into root-level access on the FMC web interface. | CVSS 10 | exploited | Apply Cisco's fix from advisory cisco-sa-onprem-fmc-authbypass-5JPp45V2 immediately and audit FMC logs for the three known attack patterns Talos identified: a web-shell/JAR credential harvester, Sandworm's Cyclops Blink malware, and generic ransomware-affiliate access. Any internet-facing FMC instance should be treated as compromised until confirmed otherwise. | ↗ story |
| CVE-2026-75650Adobe Commerce 2.4.4-2.4.9, Adobe Commerce B2B 1.3.3-1.5.3, Magento Open Source 2.4.4-2.4.9. Fixed in emergency out-of-band advisory APSB26-146, released September 7, 2026. | Unauthenticated remote code execution ("StyleSmuggler"), CVSS 10.0. Attackers inject malicious PHP into Magento's template-processing pipeline, then deliberately trigger a "Payment Transaction Failed Reminder" email so the template engine executes the injected code as it renders the message. | CVSS 10 | exploited | Apply APSB26-146 immediately, then rotate all encryption keys regardless of patch status since RCE could have exposed stored secrets. Audit for the Rust backdoor (C2 disguised as NTP traffic) and PHP web shell Sansec documented. Treat any internet-facing unpatched instance between September 4-7 as potentially compromised, not just vulnerable. | ↗ story |
| CVE-2026-81963, CVE-2026-85880Windows, all supported versions and editions receiving the September 2026 Patch Tuesday cumulative updates. Fixed in KB5122871 and KB5122876, released September 8, 2026. | Two elevation-of-privilege flaws in Microsoft's September 2026 Patch Tuesday, both CVSS 7.8. CVE-2026-81963 is improper link resolution (link-following) in the Windows Update Stack; CVE-2026-85880 is a heap-based buffer overflow in the Windows ALPC (Advanced Local Procedure Call) subsystem. Neither is remotely exploitable alone, both require an attacker who already has local code execution, and both hand that attacker full SYSTEM privileges. | CVSS 7.8 | exploited | Install KB5122871 and KB5122876 within 24 hours, the accelerated window Microsoft itself is recommending rather than the usual patch-this-week cadence. Treat any machine already showing signs of a foothold, such as unexpected local accounts or unfamiliar scheduled tasks, as a priority for investigation, since these two bugs are exactly how an attacker turns that foothold into full control. | ↗ story |
| CVE-2026-86218N-able N-central, on-premises deployments running hotfix HF3 or earlier. Cloud-hosted (NCOD) instances have already been patched by N-able; on-premises customers must apply hotfix HF4 immediately. | Pre-authentication remote code execution in the N-central RMM console (CVSS 10.0). Lets an unauthenticated remote attacker gain full 'god-mode' administrative access to the platform MSPs use to manage large numbers of client endpoints from one place. | CVSS 10 | exploited | On-premises N-central admins must apply hotfix HF4 immediately; cloud-hosted NCOD customers are already protected. Because N-central manages downstream client networks, treat a compromised console as a potential foothold into every customer it administers, not just the MSP itself. | ↗ story |
| CVE-2026-83548, CVE-2026-83549SonicWall SMA 1000 series secure remote access appliances, models 6210, 7210, and 8200v. Affected firmware 12.4.3-03453/12.5.0-02835 (platform-hotfix) and older. Fixed in 12.4.3-03526/12.5.0-02952 (platform-hotfix) and later, released September 1, 2026. | CVE-2026-83548 is a pre-authentication SSRF flaw in the Appliance Work Place interface (CVSS 10.0), exploitable remotely with no credentials. CVE-2026-83549 is OS command injection in the Appliance Management Console (CVSS 7.8), normally requiring an authenticated admin session. Chained together via the SSRF, the pair gives an unauthenticated attacker full remote code execution. Both were confirmed under active exploitation before SonicWall's advisory went public. | CVSS 10 | exploited | Update to firmware 12.4.3-03526 or 12.5.0-02952 (or later) immediately, and separately rotate or reissue MFA seeds and tokens for every SMA 1000 user: researchers found stolen seeds from before the patch remain valid after it, so patching alone does not evict an attacker who already grabbed a seed. | ↗ story |
| CVE-2026-82329JFrog Artifactory, self-managed (self-hosted) deployments only; JFrog's SaaS platform is unaffected. Fixed in Artifactory version 7.161.20, released August 28, 2026. | Unauthenticated authentication bypass in Artifactory's default configuration that lets an attacker forge a valid administrator token with no credentials, no privileges, and no user interaction. Security researchers at watchTowr observed attackers exploiting it in the wild to mint themselves admin tokens, gaining full administrative control, which enables token theft, user enumeration, and tampering with stored build artifacts and packages. | CVSS 9.8 | exploited | Upgrade self-managed Artifactory to 7.161.20 or later immediately. If you can't patch today, restrict network access to the admin API, rotate all issued tokens, and audit for administrator accounts nobody on your team remembers creating. | ↗ story |
| CVE-2026-85046Google Chrome, all platforms. Fixed in Stable Channel 152.0.7977.82/.83 (Windows, macOS) and 152.0.7977.82 (Linux), released September 3, 2026. Chromium-based browsers (Edge, Brave, Opera, Vivaldi) typically inherit the same V8 fix within days. | Type confusion vulnerability in V8, Chrome's JavaScript and WebAssembly engine (CVSS 8.8). Crafted HTML or JavaScript can make V8 misidentify the type of a memory object, giving an attacker a controlled read/write primitive inside the renderer sandbox that can be escalated toward code execution. | CVSS 8.8 | exploited · KEV | Update Chrome (or your Chromium-based browser) to the latest version now and restart the browser, since the update does not take effect until relaunch. Federal agencies must remediate by CISA's September 16, 2026 KEV deadline. | ↗ story |
| CVE-2026-8452Citrix NetScaler ADC and Gateway. Fixed builds are 14.1-73.32 and later, or 13.1-63.21 and later (including the corresponding FIPS and NDcPP builds). Citrix shipped the fix in the June 2026 CTX696604 cumulative release. | Pre-authentication heap memory overflow in the SAML single sign-on parser inside the AAA (authentication, authorization, auditing) service. A malformed SAML SSO message triggers the overflow before any login check runs, giving an unauthenticated attacker a path to remote code execution. CVSS v4.0 score 8.8. Security firm WatchTowr independently analyzed the flaw and demonstrated it can be turned into full unauthenticated RCE, not just a crash. | CVSS 8.8 | exploited · KEV | Confirm your NetScaler build is 14.1-73.32 or later, or 13.1-63.21 or later (FIPS/NDcPP variants included), and patch immediately if not. Search the appliance filesystem for web shells named x.php or z.php, review AAA/SAML authentication logs for malformed or oversized SSO requests, and take exposed management interfaces off the public internet where possible. | ↗ story |
| Multiple (2)PaperCut NG and PaperCut MF, the print-management software widely deployed at universities, school districts, and large enterprises. All versions are currently considered potentially impacted. PaperCut shipped emergency, out-of-cycle patches for versions 25 and 26 on August 28, 2026 at 02:10 AEST, followed later the same day by a patch for version 24, covering Windows, Linux, and macOS installers. | A chained attack: CVE-2026-81578 (CVSS 8.8) is an improper access control bypass in PaperCut's web management interface, and CVE-2026-82078 (CVSS 9.4) is an unsafe dynamic class loading flaw in the database connection utilities. Chained, an unauthenticated request can bypass the access control gap and land on a code execution primitive against the PaperCut Application Server. | CVSS 9.4 | exploited | Apply PaperCut's emergency patch for your branch (25/26 or 24) immediately. If your Application Server is internet-facing, restrict access to trusted IPs even if you've seen no signs of compromise, and check server.log for indicators Huntress has published: unusual activity around pc-app.exe, truncated log entries, and errors referencing an unexpected JDBC driver. | ↗ story |
| CVE-2026-21962Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in, used with both Apache HTTP Server and Microsoft IIS. Affects Oracle WebLogic Server 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0. Oracle patched it in the January 2026 Critical Patch Update. | Unauthenticated remote code execution. The proxy plug-in fails to properly validate incoming HTTP requests before forwarding them to the backend WebLogic server, allowing path traversal and header manipulation that bypass proxy access controls and can lead to full compromise of the backend instance. CVSS 10.0. | CVSS 10 | exploited · KEV | Apply Oracle's January 2026 Critical Patch Update immediately if not already installed. Do not treat the patch as the finish line: pull logs since January 22, 2026 (when a public PoC surfaced) and look for anomalous unauthenticated requests to internal WebLogic paths, unexpected access to protected application resources, and unexplained changes to data exposed through the proxy tier, per CISA BOD 26-04's forensic triage requirement. | ↗ story |
| CVE-2026-73570Zimbra Collaboration Suite (ZCS), the open-source enterprise email and collaboration server. Affects installs with the optional zimbra-snmp package installed and SNMP notifications enabled, running versions older than 10.1.20. Zimbra shipped the fix in ZCS 10.1.20 on July 20, 2026. | Unauthenticated remote code execution. When the optional zimbra-snmp package is installed and SNMP notifications are enabled, Zimbra's notification-processing code fails to sanitize untrusted input. An attacker sends a specially crafted SMTP request, no login or session required, and the unsanitized input reaches a command execution path, running arbitrary OS commands with the privileges of the zimbra service account. | — | exploited · KEV | Patch to ZCS 10.1.20 or later immediately. If you can't patch right away, disable the zimbra-snmp package or turn off SNMP notifications to remove the attack surface. Check logs for unexpected Zimbra service restarts and for new files in /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, and /tmp/ created by the zimbra user in the last 30 days, and rotate credentials if you find any. | ↗ story |
| CVE-2026-58231SAP Commerce Cloud, specifically the Data Hub Adapter. Commerce Cloud 2211 deployments are the named affected line. Fixed in SAP Security Note 3771065, shipped on SAP's August 2026 Patch Day. | Unauthenticated remote code execution built from two stacked defects. An authorization gap lets an attacker abuse a default authentication client, one that ships in a usable state rather than locked down by the operator, and an input validation gap lets certain functions accept specially crafted input without checking it. Chained, an anonymous network request is accepted as legitimate and then turned into arbitrary code execution against internal components. No user interaction, no prior foothold and no privilege requirement anywhere in the chain, which is why it scores a flat 10.0 rather than the high-8s where most critical enterprise flaws land. | CVSS 10 | exploited | Apply Security Note 3771065, then rebuild and redeploy the application and confirm the environment actually serving traffic has moved to a fixed release, because marking the note applied does not change the running build; if a redeploy cannot happen immediately, configure an IP Filter Set to restrict access to the vulnerable endpoint as a stopgap and hunt backwards through logs from patch day onward. | ↗ story |
| CVE-2026-59310VMware vCenter Server. Fixed builds are 9.1.0.0300, 9.0.2.0100, 8.0 U3k and 8.0 U2f; every supported build below those is affected. Disclosed by Broadcom in advisory VMSA-2026-0006 alongside CVE-2026-59309, an authentication bypass in the same product. | Path traversal in the vCenter Syslog server leading to arbitrary code execution. Exploitable by an unauthenticated attacker with only network access to the vCenter Server, with no user interaction. Observed in-the-wild chain: path traversal against the Syslog service, then a malicious cron job written to the appliance for persistence, then reverse_ssh (an open-source tool for SSH connections back to attacker infrastructure) for an outbound command and control channel. Broadcom states there is no workaround, so the update is the only remediation for the entry point. | CVSS 9.8 | exploited | Update vCenter to 9.1.0.0300, 9.0.2.0100, 8.0 U3k or 8.0 U2f now, then hunt for the persistence the patch does not remove: audit appliance cron for entries you did not create, review outbound SSH sessions from vCenter to unrecognised infrastructure, and treat any estate whose Syslog service was network-reachable between July 29 and patch day as scanned. | ↗ story |
| CVE-2026-68820Microsoft Windows, all supported versions. The flaw is in afd.sys, the kernel-mode Ancillary Function Driver for WinSock, which is loaded on every Windows host and reachable by any process that opens a socket without requiring elevated privileges. | Use-after-free in the Windows Sockets kernel driver. A locally authenticated attacker runs a crafted application that triggers a race condition between two threads touching the same driver object: one frees it while the other retains a reference and keeps operating on the freed memory. Reclaiming that allocation with attacker-controlled data lets the driver act on attacker-shaped structures in kernel context, yielding NT AUTHORITY\SYSTEM. This is the fourth exploited afd.sys zero-day since 2022, after CVE-2024-38193, CVE-2025-21418 and CVE-2025-32709. | CVSS 7 | exploited · KEV | Apply the August 2026 Patch Tuesday updates now, prioritising developer workstations and any fleet where standard-user accounts are relied on as a security boundary, since that boundary is exactly what this bug removes. | ↗ story |
| CVE-2026-63077JetBrains TeamCity, on-premise servers. The flaw is reachable through the agent polling protocol, which internet-facing build servers commonly expose. | Deserialization of untrusted data leading to unauthenticated remote code execution. The XStream allowlist was built additively: it registered TeamCity protocol classes without first removing XStream's existing default permissions, so the effective permission set stayed a permissive union rather than an exclusive allowlist. Rapid7's Stephen Fewer traced the root cause; the patch inserts NoTypePermission.NONE ahead of the allowlist. A published proof of concept writes .JSPWS files, executes OS commands with the TeamCity server process privileges, then deletes the files from disk, so no web shell remains for a later file scan to find. | CVSS 9.8 | exploited · KEV | Patch on-premise TeamCity immediately, then treat any internet-facing server left unpatched after August 5 as compromised: rotate source control tokens, registry keys, cloud roles and signing keys the server could reach, review recent build artifacts and pipeline definitions for unauthorised changes, and move the agent polling protocol off the public internet. | ↗ story |
| No CVE assigned (Coldcard firmware RNG)Coinkite Coldcard hardware wallets. Seeds generated on Mk2/Mk3 firmware 4.0.0 through 4.1.9, Mk4/Mk5 before 5.6.0, Q before 1.5.0Q, and Edge builds before 6.6.0X (Mk4/Mk5) or 6.6.0QX (Q). | Weak key generation from a build-configuration error. Coldcard's firmware set MICROPY_HW_ENABLE_RNG to zero because Coinkite supplied its own RNG wrapper, but the cryptographic support library tested whether the macro was defined rather than whether its value was non-zero. A macro set to zero is still defined, so the library concluded hardware randomness was active and bound seed generation to MicroPython's Yasmarang fallback PRNG instead of the STM32 hardware RNG. Yasmarang was initialised from the chip's unique ID and timer registers, neither of which is secret, and collected no fresh entropy afterwards. Coinkite estimates effective entropy at roughly 40 bits on the Mk3 and about 72 bits on Mk4, Mk5 and Q, against 128 bits for a correctly generated seed. Introduced in firmware 4.0.0 in March 2021 and undetected for five years. | — | exploited | Install the patched firmware, then treat that as step one of two: the update does NOT repair an existing seed. Generate a completely new seed on the patched build and move every coin to addresses derived from it. Do not restore the old seed onto new firmware. Any seed created on an affected version must be treated as compromised, because weak-key exposure offers no reliable self-test. | ↗ story |
| CVE-2026-20316Cisco Secure Firewall Management Center (FMC) software, trains 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0. | Static credentials for a low-privilege account compiled into the shipped software image. Every installation of an affected version carries the same username and password, with no per-device derivation and no first-boot rotation, so an unauthenticated attacker who can reach the management interface simply logs in. The account cannot administer the appliance, but on a firewall management console read access covers access-control policy, object groups, network topology as expressed in rules, and device names and versions. Cisco assigned a Security Impact Rating of High despite the modest CVSS base score, because the leaked data is reconnaissance input for a follow-on attack and the flaw is expected to be chained with a privilege-escalation issue. | CVSS 5.3 | exploited · KEV | Apply the Cisco hotfix for your FMC train immediately; there is no configuration workaround because the credential lives in the binary. Then hunt for prior compromise by searching the appliance message log for license activity (cat /var/log/messages | grep license) and looking for references to /var/tmp/license.tmp, pulling archived log files too since exploitation dates to early July and rotation may have aged out the evidence. Independently, restrict the management interface to an out-of-band VLAN or jump host. | ↗ story |
| Multiple (7)Langflow, n8n, Citrix NetScaler ADC, Apache Tomcat, Marimo Notebook, Palo Alto PAN-OS User-ID Portal and Windows IKE Extensions, as used together in one AI-orchestrated campaign documented by Palo Alto Networks Unit 42. | Not a single flaw but a toolkit: seven already-public CVEs assembled into one campaign in which DeepSeek, running inside the open-source Hermes Agent framework and tasked over Telegram, autonomously enumerated exposed hosts through FOFA, pulled proof-of-concept code from GitHub, ranked targets by CVSS and repository popularity, and probed them without operator input. The set is CVE-2026-33017 (Langflow, 9.8), CVE-2026-21858 with CVE-2025-68613 (n8n, 10.0 and 9.9), CVE-2026-3055 (NetScaler ADC out-of-bounds read, 9.8), CVE-2026-34486 (Tomcat, 7.5), CVE-2026-39987 (Marimo, 9.8), CVE-2026-0300 (PAN-OS, 9.8, non-functional PoC only) and CVE-2026-33824 (Windows IKE Extensions, 9.8). Both fully autonomous exploitation attempts, against Langflow and n8n, failed on authentication requirements; every confirmed compromise came from the operator working manually. | — | exploited | Patch the NetScaler ADC and Marimo Notebook flaws first, since those are the two with confirmed impact in this campaign, then work through the remaining five. Separately, audit internal tooling exposed to the internet with convenience toggles enabled: Langflow's auto_login being off and n8n requiring form authentication are what stopped the autonomous half of this campaign, so those defaults are functioning as a security control. | ↗ story |
| CVE-2026-16812Arista VeloCloud Orchestrator On-Prem (self-hosted SD-WAN management plane). Cloud-hosted VeloCloud is not affected. | Unauthenticated OS command injection. A crafted HTTP request to an exposed orchestrator endpoint passes attacker-controlled input into a shell command, giving privileged code execution with no credentials required. Because the orchestrator holds the credentials and tunnel configuration for every managed branch, data-centre and cloud edge, compromise of it means control of the policy applied across the whole SD-WAN. The management web interface is exposed by default and no supported configuration removes that exposure entirely, so there is no mitigation that substitutes for patching. | CVSS 10 | exploited · KEV | Patch VeloCloud Orchestrator On-Prem to 5.2.3.14, 6.1.3.4 or 6.4.2.4 immediately, then rotate orchestrator credentials and API tokens and diff edge policy against a known-good backup, since this was exploited as a zero-day before the fix shipped. | ↗ story |
| CVE-2026-63030, CVE-2026-60137WordPress Core (versions before 7.0.2, 6.9.5, 6.8.6) | An authentication bypass (CVE-2026-60137) chained with a remote code execution flaw in the REST API batch-processing feature (CVE-2026-63030), letting an unauthenticated attacker send one crafted request to the /batch endpoint and run arbitrary code on the server. The flaw is in WordPress Core itself, so it affects the base install regardless of plugins or theme. | — | exploited | Update to WordPress 7.0.2, 6.9.5 or 6.8.6 immediately; automatic updates cover supported installs. Audit the plugin directory and active REST endpoints for webshells disguised as plugins, and treat any site left unpatched during the exploitation window as potentially compromised, not merely at risk. | ↗ story |
| CVE-2026-6875ServiceNow AI Platform (formerly Now Platform) | Sandbox escape to unauthenticated remote code execution | CVSS 9.5 | exploited | Apply the July 13 ServiceNow patch to every self-hosted and on-premise instance immediately, then hunt for prior compromise rather than assuming the patch closed the incident, and rotate the downstream credentials and API tokens the instance holds for the systems it orchestrates. | ↗ story |
| CVE-2026-20230Cisco Unified Communications Manager | Server-side request forgery (SSRF) | — | exploited · KEV | Apply Cisco's fixed Unified Communications Manager release immediately, treating it as an incident-response task rather than routine patching. Until patched, restrict network access to the CUCM administrative and web interfaces, segment voice infrastructure away from sensitive internal services, and monitor the server for anomalous outbound requests that would indicate SSRF abuse. | ↗ story |
| CVE-2024-42009Roundcube Webmail | Cross-site scripting (XSS), near-zero interaction | CVSS 9.3 | exploited | Update Roundcube to a fixed release immediately; the patch has existed since 2024 and closes the flaw outright. Put webmail behind SSO with phishing-resistant MFA, enforce a strict content-security policy to blunt XSS, monitor for anomalous or mass mailbox reads, and rotate credentials and session tokens for any account that opened a suspicious message. | ↗ story |
| CVE-2026-25089 / CVE-2026-39808 / CVE-2026-39813Fortinet FortiSandbox | Auth bypass + OS command injection to unauthenticated RCE | — | exploited | Apply Fortinet's April and June FortiSandbox updates immediately (all three are patched). Keep FortiSandbox management interfaces off the internet, and assume-breach on any appliance that was exposed and unpatched: review for unexpected accounts, tasks, and outbound connections, and rotate every credential the box could reach. | ↗ story |
| ShareFile Storage Zone zero-day (CVE pending)Progress ShareFile Storage Zone Controller | Path traversal (arbitrary file read/write, filesystem enumeration) | — | exploited | Apply Progress's new Storage Zone Controller update before bringing any server back online, keep the controller off the public internet, and assume-breach on anything that was exposed: hunt for files written to unexpected directories, unfamiliar accounts, and outbound connections, and rotate every credential the service account could reach. Install February's 5.12.4/v6 updates too if you skipped them. | ↗ story |
| CVE-2026-56155 / CVE-2026-56164Microsoft ADFS & SharePoint Server | Elevation of privilege (identity federation; unauthenticated network) | — | exploited | Patch both before anything else in July's Patch Tuesday. If a SharePoint server cannot be updated at once, apply Microsoft's interim mitigation: enable the Antimalware Scan Interface (AMSI) and set Request Body Scan to Full. Review ADFS and SharePoint logs for anomalous privilege elevation during the exposure window. | ↗ story |
| CVE-2026-55255Langflow (AI agent orchestration platform) | Cross-tenant IDOR / authorization bypass via user-controlled flow ID | CVSS 6.1 | exploited · KEV | Update to Langflow 1.9.2 or later, then rotate every API key, LLM provider credential and cloud key stored in any flow; audit /api/v1/responses logs for cross-user flow IDs | ↗ story |
| CVE-2026-8037Progress Kemp LoadMaster | Command injection → RCE | CVSS 9.6 | exploited | Patch now; take management interfaces off the internet | ↗ story |
| CVE-2026-45659Microsoft SharePoint Server (on-prem) | Unsafe deserialization → RCE | CVSS 8.8 | exploited · KEV | Apply the May 2026 patch — every unpatched on-prem server is a target | ↗ story |
| CVE-2026-72898Metabase, the open-source business intelligence and analytics tool, self-hosted and Cloud deployments. Affects every release from version 1.58 onward (spanning the 0.58 through 0.63 branches). A fix is available; Metabase disclosed the flaw on August 6, 2026 after its own Cloud environment was attacked using what was then an unknown zero-day. | Unauthenticated SQL injection in the publicly accessible /api/session/reset_password endpoint. An attacker adds an extra user-id key to the JSON request body, supplied as a HoneySQL object; because that value reaches a database query without type validation, it compiles into raw SQL instead of being treated as data. Successful exploitation grants full administrator access to the Metabase instance with no authentication, from which an attacker can change the app configuration, steal the stored credentials for every connected database, and read or export any reachable data. | CVSS 10 | was exploited · KEV | Upgrade self-hosted Metabase to the patched release immediately, then rotate the credentials for every database Metabase was connected to and audit access logs for requests to /api/session/reset_password carrying an unexpected user-id field. | ↗ story |
| GHSA-mqjf-5f49-2fjhGeoServer, and the underlying GeoTools PostGIS JDBC datastore. Fixed in GeoServer 3.0.1, 2.28.5 and 2.27.6. For direct consumers of the library, org.geotools:gt-jdbc-postgis 35.0 is fixed in 35.1, 34.0 and later in 34.5, and 33.1 and later in 33.6. | Unauthenticated SQL injection with a path to remote code execution. The jsonArrayContains(<column>, <pointer>, <value>) function writes its third argument into generated SQL without escaping, so any caller who can submit an OGC filter can submit SQL instead. Preconditions narrow the real exposure: it requires the PostGIS DataStore implementation, PostGIS 12 or later, and a String or JSON field reachable through the filter. The code execution path specifically involves certain H2 database deployments rather than every install. | CVSS 9.8 | was exploited | Update GeoServer to 3.0.1, 2.28.5 or 2.27.6, or bump gt-jdbc-postgis to 35.1, 34.5 or 33.6, then hunt backwards through access logs from August 12 for filter requests containing jsonArrayContains alongside SQL syntax, because exploitation began before any fix existed. | ↗ story |
| LiteLLM 1.82.7 / 1.82.8 (no CVE assigned)LiteLLM, the open-source LLM proxy and Python SDK, versions 1.82.7 and 1.82.8 as distributed on PyPI. Any CI/CD pipeline, container build or developer machine that resolved LiteLLM during the 40-minute window the poisoned releases were live in March 2026. | Software supply chain compromise reached through a third dependency rather than a vulnerability in LiteLLM itself. The threat actor TeamPCP compromised a release of Aqua Security's Trivy scanner; LiteLLM's CI pipeline installed that Trivy build automatically and unpinned, which exposed LiteLLM's package publishing credentials and let the attacker push malicious releases to PyPI. The payload executed on every Python invocation, not only at install time, and harvested cloud keys, SSH keys, registry publishing tokens, database connection strings, AI provider API keys and CI runner memory. | — | was exploited | Treat every secret readable by the LiteLLM process as compromised and rotate it now: cloud access keys, SSH keys, package registry tokens, database connection strings and all AI provider API keys. Then pin build tooling to hashes rather than floating tags, and scope CI credentials to the job that needs them. | ↗ story |
how to read this
exploited means confirmed in-the-wild attacks are happening now — patch out of cycle, today. was exploited means attacks happened before a patch shipped; if you were exposed unpatched, assume compromise and investigate, don't just update. disclosed means details are public but no confirmed exploitation yet — attackers read the same write-ups, so patch on an accelerated cadence.
Curated from our coverage, not an exhaustive CVE database — for completeness use CISA KEV alongside this list.
cite & embed
Free to cite and embed with attribution. Raw data: JSON · CSV. Embedding this live table adds it to your site and credits GENZ TECH.
GENZ TECH. (2026). CVE Watchlist. https://genztech.blog/cve-watchlist/<iframe src="https://genztech.blog/cve-watchlist/embed/" width="100%" height="470" loading="lazy" title="CVE Watchlist by GENZ TECH" style="border:1px solid #26282b;border-radius:10px;max-width:560px"></iframe>