{
  "source": "https://genztech.blog/cve-watchlist/",
  "license": "Free to cite with attribution + link",
  "updated": "2026-09-11",
  "items": [
    {
      "id": "CVE-2026-20079",
      "product": "Cisco Secure Firewall Management Center (FMC), on-premises software versions affected by the flaw per Cisco advisory cisco-sa-onprem-fmc-authbypass-5JPp45V2. Confirmed under active exploitation by Cisco PSIRT in August 2026, publicly confirmed September 10, 2026.",
      "type": "Authentication bypass leading to unauthenticated remote code execution as root (CVSS 10.0). An improper system process created at boot time leaves a partial session in the sfsnort.sessions database that persists until a user authenticates; an attacker who sends crafted HTTP requests before anyone logs in can upgrade that session into root-level access on the FMC web interface.",
      "cvss": 10,
      "status": "actively exploited",
      "kev": false,
      "action": "Apply Cisco's fix from advisory cisco-sa-onprem-fmc-authbypass-5JPp45V2 immediately and audit FMC logs for the three known attack patterns Talos identified: a web-shell/JAR credential harvester, Sandworm's Cyclops Blink malware, and generic ransomware-affiliate access. Any internet-facing FMC instance should be treated as compromised until confirmed otherwise.",
      "date": "2026-09-10",
      "note": "Distinct from CVE-2026-20316, the hardcoded-credentials flaw in Cisco FMC GenZTech covered August 1, 2026: this is a separate, more severe unauthenticated root RCE. Cisco's Talos group identified three distinct exploitation clusters, one linked to the Russian state-sponsored APT group Sandworm deploying Cyclops Blink malware, alongside a web-shell credential harvester and financially-motivated ransomware activity. Not yet confirmed on CISA's KEV catalog at time of writing (kev: false reflects that, not a claim exploitation is unconfirmed). See /p/cisco-secure-fmc-cve-2026-20079-sandworm-exploited/.",
      "post": "/p/cisco-secure-fmc-cve-2026-20079-sandworm-exploited/"
    },
    {
      "id": "CVE-2026-87491",
      "product": "Google Chrome, all channels prior to 153.0.8010.36/.37 (Windows/macOS) and 153.0.8010.36 (Linux). Fixed in the Chrome 153 stable channel release, rolled out September 8-9, 2026.",
      "type": "Out-of-bounds write in V8, Chrome's JavaScript and WebAssembly engine (medium severity). Loading a rigged webpage can corrupt engine memory and let an attacker run code in the browser process, no download or click beyond the page load itself.",
      "cvss": null,
      "status": "actively exploited",
      "kev": false,
      "action": "Open chrome://settings/help, confirm the version reads 153.0.8010.36/.37 (Windows/macOS) or 153.0.8010.36 (Linux) or later, then relaunch the browser immediately rather than waiting for the background auto-updater to apply it on its own schedule.",
      "date": "2026-09-10",
      "note": "The seventh actively-exploited Chrome zero-day Google has patched in 2026, after CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281, CVE-2026-11645, and CVE-2026-85046. Reported by Jihyeon Jeong of Compsec Lab, Seoul National University, who received a $2,500 bug bounty. Not yet confirmed on CISA's KEV catalog at time of writing (kev: false reflects that, not a claim exploitation is unconfirmed). See /p/chrome-153-seventh-zero-day-cve-2026-87491/.",
      "post": "/p/chrome-153-seventh-zero-day-cve-2026-87491/"
    },
    {
      "id": "CVE-2026-75650",
      "product": "Adobe Commerce 2.4.4-2.4.9, Adobe Commerce B2B 1.3.3-1.5.3, Magento Open Source 2.4.4-2.4.9. Fixed in emergency out-of-band advisory APSB26-146, released September 7, 2026.",
      "type": "Unauthenticated remote code execution (\"StyleSmuggler\"), CVSS 10.0. Attackers inject malicious PHP into Magento's template-processing pipeline, then deliberately trigger a \"Payment Transaction Failed Reminder\" email so the template engine executes the injected code as it renders the message.",
      "cvss": 10,
      "status": "actively exploited",
      "kev": false,
      "action": "Apply APSB26-146 immediately, then rotate all encryption keys regardless of patch status since RCE could have exposed stored secrets. Audit for the Rust backdoor (C2 disguised as NTP traffic) and PHP web shell Sansec documented. Treat any internet-facing unpatched instance between September 4-7 as potentially compromised, not just vulnerable.",
      "date": "2026-09-09",
      "note": "Discovered in the wild by e-commerce security firm Sansec, which traced first exploitation to September 4, three days before Adobe's hotfix shipped on September 7. Not yet confirmed on CISA's KEV catalog at time of writing (kev: false reflects that, not a claim exploitation is unconfirmed). See /p/adobe-commerce-magento-stylesmuggler-zero-day/.",
      "post": "/p/adobe-commerce-magento-stylesmuggler-zero-day/"
    },
    {
      "id": "CVE-2026-81963, CVE-2026-85880",
      "product": "Windows, all supported versions and editions receiving the September 2026 Patch Tuesday cumulative updates. Fixed in KB5122871 and KB5122876, released September 8, 2026.",
      "type": "Two elevation-of-privilege flaws in Microsoft's September 2026 Patch Tuesday, both CVSS 7.8. CVE-2026-81963 is improper link resolution (link-following) in the Windows Update Stack; CVE-2026-85880 is a heap-based buffer overflow in the Windows ALPC (Advanced Local Procedure Call) subsystem. Neither is remotely exploitable alone, both require an attacker who already has local code execution, and both hand that attacker full SYSTEM privileges.",
      "cvss": 7.8,
      "status": "actively exploited",
      "kev": false,
      "action": "Install KB5122871 and KB5122876 within 24 hours, the accelerated window Microsoft itself is recommending rather than the usual patch-this-week cadence. Treat any machine already showing signs of a foothold, such as unexpected local accounts or unfamiliar scheduled tasks, as a priority for investigation, since these two bugs are exactly how an attacker turns that foothold into full control.",
      "date": "2026-09-08",
      "note": "Part of Microsoft's largest Patch Tuesday ever: 966 vulnerabilities total, more than any prior 2026 release (200 in June, 570 in July). CVE-2026-81963 is credited to Romain Deperne and Microsoft's own MSTIC team; CVE-2026-85880 was found by Volexity and researchers at Proofpoint. Not yet confirmed on CISA's KEV catalog at time of writing (kev: false reflects that, not a claim exploitation is unconfirmed). See /p/microsoft-966-flaw-patch-tuesday-zero-days/.",
      "post": "/p/microsoft-966-flaw-patch-tuesday-zero-days/"
    },
    {
      "id": "CVE-2026-86218",
      "product": "N-able N-central, on-premises deployments running hotfix HF3 or earlier. Cloud-hosted (NCOD) instances have already been patched by N-able; on-premises customers must apply hotfix HF4 immediately.",
      "type": "Pre-authentication remote code execution in the N-central RMM console (CVSS 10.0). Lets an unauthenticated remote attacker gain full 'god-mode' administrative access to the platform MSPs use to manage large numbers of client endpoints from one place.",
      "cvss": 10,
      "status": "actively exploited",
      "kev": false,
      "action": "On-premises N-central admins must apply hotfix HF4 immediately; cloud-hosted NCOD customers are already protected. Because N-central manages downstream client networks, treat a compromised console as a potential foothold into every customer it administers, not just the MSP itself.",
      "date": "2026-09-06",
      "note": "Disclosed roughly a month after CVE-2026-18577, an N-central auth bypass caused by an incomplete fix for CVE-2026-18556, which CISA added to its KEV catalog with an unusually short 3-day federal patch deadline (August 6, 2026) under Binding Operational Directive 26-04. Huntress also published proof-of-concept detail for a related flaw, CVE-2026-86207, that lets attackers bypass access controls to create unauthorized admin accounts. CVE-2026-86218 has not yet appeared in the CISA KEV catalog as of this writing. See /p/n-able-n-central-cve-2026-86218-godmode-rce/.",
      "post": "/p/n-able-n-central-cve-2026-86218-godmode-rce/"
    },
    {
      "id": "CVE-2026-85046",
      "product": "Google Chrome, all platforms. Fixed in Stable Channel 152.0.7977.82/.83 (Windows, macOS) and 152.0.7977.82 (Linux), released September 3, 2026. Chromium-based browsers (Edge, Brave, Opera, Vivaldi) typically inherit the same V8 fix within days.",
      "type": "Type confusion vulnerability in V8, Chrome's JavaScript and WebAssembly engine (CVSS 8.8). Crafted HTML or JavaScript can make V8 misidentify the type of a memory object, giving an attacker a controlled read/write primitive inside the renderer sandbox that can be escalated toward code execution.",
      "cvss": 8.8,
      "status": "actively exploited",
      "kev": true,
      "action": "Update Chrome (or your Chromium-based browser) to the latest version now and restart the browser, since the update does not take effect until relaunch. Federal agencies must remediate by CISA's September 16, 2026 KEV deadline.",
      "date": "2026-09-03",
      "note": "Reported by researcher Salvatore Gulizia on August 4, 2026 and patched September 3, 2026 with an in-the-wild exploit already confirmed, making it a genuine zero-day. CISA added it to the KEV catalog September 4, 2026. It is the sixth V8 zero-day Google has patched in 2026, underscoring how often the JIT compiler keeps producing exploitable type-confusion bugs. See /p/chrome-v8-zero-day-cve-2026-85046-sixth-patch/.",
      "post": "/p/chrome-v8-zero-day-cve-2026-85046-sixth-patch/"
    },
    {
      "id": "CVE-2026-83548, CVE-2026-83549",
      "product": "SonicWall SMA 1000 series secure remote access appliances, models 6210, 7210, and 8200v. Affected firmware 12.4.3-03453/12.5.0-02835 (platform-hotfix) and older. Fixed in 12.4.3-03526/12.5.0-02952 (platform-hotfix) and later, released September 1, 2026.",
      "type": "CVE-2026-83548 is a pre-authentication SSRF flaw in the Appliance Work Place interface (CVSS 10.0), exploitable remotely with no credentials. CVE-2026-83549 is OS command injection in the Appliance Management Console (CVSS 7.8), normally requiring an authenticated admin session. Chained together via the SSRF, the pair gives an unauthenticated attacker full remote code execution. Both were confirmed under active exploitation before SonicWall's advisory went public.",
      "cvss": 10,
      "status": "actively exploited",
      "kev": false,
      "action": "Update to firmware 12.4.3-03526 or 12.5.0-02952 (or later) immediately, and separately rotate or reissue MFA seeds and tokens for every SMA 1000 user: researchers found stolen seeds from before the patch remain valid after it, so patching alone does not evict an attacker who already grabbed a seed.",
      "date": "2026-09-04",
      "note": "Third distinct attack chain against the SMA 1000 product line in under a year, following a separate incident involving threat actor UTA0533 on 2026-07-22. Not yet confirmed on CISA's KEV catalog at time of writing (kev: false reflects that, not a claim exploitation is unconfirmed). See /p/sonicwall-sma1000-third-zero-day-mfa-seeds-persist/.",
      "post": "/p/sonicwall-sma1000-third-zero-day-mfa-seeds-persist/"
    },
    {
      "id": "CVE-2026-82329",
      "product": "JFrog Artifactory, self-managed (self-hosted) deployments only; JFrog's SaaS platform is unaffected. Fixed in Artifactory version 7.161.20, released August 28, 2026.",
      "type": "Unauthenticated authentication bypass in Artifactory's default configuration that lets an attacker forge a valid administrator token with no credentials, no privileges, and no user interaction. Security researchers at watchTowr observed attackers exploiting it in the wild to mint themselves admin tokens, gaining full administrative control, which enables token theft, user enumeration, and tampering with stored build artifacts and packages.",
      "cvss": 9.8,
      "status": "actively exploited",
      "kev": false,
      "action": "Upgrade self-managed Artifactory to 7.161.20 or later immediately. If you can't patch today, restrict network access to the admin API, rotate all issued tokens, and audit for administrator accounts nobody on your team remembers creating.",
      "date": "2026-09-03",
      "note": "JFrog shipped the fix on August 28, 2026; in-the-wild exploitation began just days after public disclosure, another case of the disclosure-to-weaponization window shrinking to days rather than weeks. Because Artifactory stores an organization's build artifacts and packages, a compromised instance opens a direct route into the software supply chain: an attacker with forged admin access can plant malicious binaries alongside legitimate ones for downstream builds to pull without suspicion. Not yet confirmed on CISA's KEV catalog at time of writing (kev: false reflects that, not a claim exploitation is unconfirmed). See /p/jfrog-artifactory-cve-2026-82329-exploited/.",
      "post": "/p/jfrog-artifactory-cve-2026-82329-exploited/"
    },
    {
      "id": "CVE-2026-8452",
      "product": "Citrix NetScaler ADC and Gateway. Fixed builds are 14.1-73.32 and later, or 13.1-63.21 and later (including the corresponding FIPS and NDcPP builds). Citrix shipped the fix in the June 2026 CTX696604 cumulative release.",
      "type": "Pre-authentication heap memory overflow in the SAML single sign-on parser inside the AAA (authentication, authorization, auditing) service. A malformed SAML SSO message triggers the overflow before any login check runs, giving an unauthenticated attacker a path to remote code execution. CVSS v4.0 score 8.8. Security firm WatchTowr independently analyzed the flaw and demonstrated it can be turned into full unauthenticated RCE, not just a crash.",
      "cvss": 8.8,
      "status": "actively exploited",
      "kev": true,
      "action": "Confirm your NetScaler build is 14.1-73.32 or later, or 13.1-63.21 or later (FIPS/NDcPP variants included), and patch immediately if not. Search the appliance filesystem for web shells named x.php or z.php, review AAA/SAML authentication logs for malformed or oversized SSO requests, and take exposed management interfaces off the public internet where possible.",
      "date": "2026-08-31",
      "note": "Citrix fixed this in June 2026, roughly two months before exploitation was observed in August, which is the real story here: every compromised organization was running code with a known fix already available. Attackers have been seen dropping PHP web shells named x.php and z.php on compromised appliances, then running basic discovery commands (id, echo) to map out what they landed on. CISA added it to the Known Exploited Vulnerabilities catalog on August 26, 2026, with a federal remediation deadline of August 29, 2026 that has already passed. This is the second serious NetScaler CVE in two months: GenZTech covered the separate CitrixBleed-style CVE-2026-8451 on July 8, 2026, a different flaw in the same product line. See /p/citrix-netscaler-cve-2026-8452-saml-webshells/.",
      "post": "/p/citrix-netscaler-cve-2026-8452-saml-webshells/"
    },
    {
      "id": "Multiple (2)",
      "product": "PaperCut NG and PaperCut MF, the print-management software widely deployed at universities, school districts, and large enterprises. All versions are currently considered potentially impacted. PaperCut shipped emergency, out-of-cycle patches for versions 25 and 26 on August 28, 2026 at 02:10 AEST, followed later the same day by a patch for version 24, covering Windows, Linux, and macOS installers.",
      "type": "A chained attack: CVE-2026-81578 (CVSS 8.8) is an improper access control bypass in PaperCut's web management interface, and CVE-2026-82078 (CVSS 9.4) is an unsafe dynamic class loading flaw in the database connection utilities. Chained, an unauthenticated request can bypass the access control gap and land on a code execution primitive against the PaperCut Application Server.",
      "cvss": 9.4,
      "status": "actively exploited",
      "kev": false,
      "action": "Apply PaperCut's emergency patch for your branch (25/26 or 24) immediately. If your Application Server is internet-facing, restrict access to trusted IPs even if you've seen no signs of compromise, and check server.log for indicators Huntress has published: unusual activity around pc-app.exe, truncated log entries, and errors referencing an unexpected JDBC driver.",
      "date": "2026-08-29",
      "note": "PaperCut published an URGENT security advisory on August 27, 2026 confirming active exploitation and confirmed customer incidents. Huntress has documented exploitation on at least two customer environments, where attackers ran base64-encoded whoami/ver commands, early reconnaissance rather than a confirmed full breach in the cases published so far. Not yet confirmed on CISA's KEV catalog at time of writing (kev: false reflects that, not a claim exploitation is unconfirmed). PaperCut's 2023 flaw in the same product line, CVE-2023-27350, was later weaponized by Bl00dy- and LockBit-affiliated ransomware actors against schools and universities, the precedent security teams are watching for here. See /p/papercut-ng-mf-zero-day-emergency-patch/.",
      "post": "/p/papercut-ng-mf-zero-day-emergency-patch/"
    },
    {
      "id": "CVE-2026-21962",
      "product": "Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in, used with both Apache HTTP Server and Microsoft IIS. Affects Oracle WebLogic Server 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0. Oracle patched it in the January 2026 Critical Patch Update.",
      "type": "Unauthenticated remote code execution. The proxy plug-in fails to properly validate incoming HTTP requests before forwarding them to the backend WebLogic server, allowing path traversal and header manipulation that bypass proxy access controls and can lead to full compromise of the backend instance. CVSS 10.0.",
      "cvss": 10,
      "status": "actively exploited",
      "kev": true,
      "action": "Apply Oracle's January 2026 Critical Patch Update immediately if not already installed. Do not treat the patch as the finish line: pull logs since January 22, 2026 (when a public PoC surfaced) and look for anomalous unauthenticated requests to internal WebLogic paths, unexpected access to protected application resources, and unexplained changes to data exposed through the proxy tier, per CISA BOD 26-04's forensic triage requirement.",
      "date": "2026-08-27",
      "note": "CloudSEK honeypot telemetry recorded exploitation attempts beginning January 22, 2026, days after a public proof-of-concept leaked, despite Oracle's patch having shipped that same month. CISA added it to the KEV catalog on August 24, 2026; under BOD 26-04's four-variable risk model, this CVE tripped every criterion, producing the shortest remediation tier (a 3-calendar-day deadline) and a first-of-its-kind mandatory forensic triage requirement, not just a patch mandate. Tech Times reported August 26 that a China-linked threat actor has used this flaw against 100+ government targets worldwide. See /p/cisa-oracle-weblogic-cve-2026-21962-patch-deadline/.",
      "post": "/p/cisa-oracle-weblogic-cve-2026-21962-patch-deadline/"
    },
    {
      "id": "CVE-2026-73570",
      "product": "Zimbra Collaboration Suite (ZCS), the open-source enterprise email and collaboration server. Affects installs with the optional zimbra-snmp package installed and SNMP notifications enabled, running versions older than 10.1.20. Zimbra shipped the fix in ZCS 10.1.20 on July 20, 2026.",
      "type": "Unauthenticated remote code execution. When the optional zimbra-snmp package is installed and SNMP notifications are enabled, Zimbra's notification-processing code fails to sanitize untrusted input. An attacker sends a specially crafted SMTP request, no login or session required, and the unsanitized input reaches a command execution path, running arbitrary OS commands with the privileges of the zimbra service account.",
      "cvss": null,
      "status": "actively exploited",
      "kev": true,
      "action": "Patch to ZCS 10.1.20 or later immediately. If you can't patch right away, disable the zimbra-snmp package or turn off SNMP notifications to remove the attack surface. Check logs for unexpected Zimbra service restarts and for new files in /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, and /tmp/ created by the zimbra user in the last 30 days, and rotate credentials if you find any.",
      "date": "2026-08-25",
      "note": "Tracked as CVE-2026-73570. CERT Polska first flagged active exploitation on August 19, 2026, about a month after the patch shipped. Shadowserver has counted more than 270 compromised ZCS instances against a base of over 12,000 internet-exposed servers. CISA added it to the Known Exploited Vulnerabilities catalog on August 21, 2026, giving federal civilian executive branch agencies until August 24, 2026 to patch, a three-day window that has already passed. No CVSS score has been published by our sources as of coverage; treat as critical given unauthenticated RCE plus confirmed in-the-wild exploitation. Prior Zimbra vulnerabilities have been exploited by APT28, APT29 and Winter Vivern against government and NATO-linked organizations. See /p/zimbra-cve-2026-73570-rce-actively-exploited/.",
      "post": "/p/zimbra-cve-2026-73570-rce-actively-exploited/"
    },
    {
      "id": "CVE-2026-72898",
      "product": "Metabase, the open-source business intelligence and analytics tool, self-hosted and Cloud deployments. Affects every release from version 1.58 onward (spanning the 0.58 through 0.63 branches). A fix is available; Metabase disclosed the flaw on August 6, 2026 after its own Cloud environment was attacked using what was then an unknown zero-day.",
      "type": "Unauthenticated SQL injection in the publicly accessible /api/session/reset_password endpoint. An attacker adds an extra user-id key to the JSON request body, supplied as a HoneySQL object; because that value reaches a database query without type validation, it compiles into raw SQL instead of being treated as data. Successful exploitation grants full administrator access to the Metabase instance with no authentication, from which an attacker can change the app configuration, steal the stored credentials for every connected database, and read or export any reachable data.",
      "cvss": 10,
      "status": "exploited, patched",
      "kev": true,
      "action": "Upgrade self-hosted Metabase to the patched release immediately, then rotate the credentials for every database Metabase was connected to and audit access logs for requests to /api/session/reset_password carrying an unexpected user-id field.",
      "date": "2026-08-22",
      "note": "Tracked as CVE-2026-72898, CVSS v3.1 10.0 (maximum severity). Two customers, Framework and Tally, separately disclosed unauthorized access to customer data (names, addresses, phone numbers, emails) resulting from this flaw. CISA added it to the Known Exploited Vulnerabilities catalog on August 11, 2026, requiring federal civilian agencies to patch by August 14, 2026 under Binding Operational Directive 26-04. Status is exploited, patched rather than actively exploited because a fix now exists and Metabase urged all self-hosted users to upgrade; the risk that remains is unpatched instances and any credentials stolen before the fix shipped. See /p/metabase-sql-injection-zero-day-cve-2026-72898/.",
      "post": "/p/metabase-sql-injection-zero-day-cve-2026-72898/"
    },
    {
      "id": "CVE-2026-58231",
      "product": "SAP Commerce Cloud, specifically the Data Hub Adapter. Commerce Cloud 2211 deployments are the named affected line. Fixed in SAP Security Note 3771065, shipped on SAP's August 2026 Patch Day.",
      "type": "Unauthenticated remote code execution built from two stacked defects. An authorization gap lets an attacker abuse a default authentication client, one that ships in a usable state rather than locked down by the operator, and an input validation gap lets certain functions accept specially crafted input without checking it. Chained, an anonymous network request is accepted as legitimate and then turned into arbitrary code execution against internal components. No user interaction, no prior foothold and no privilege requirement anywhere in the chain, which is why it scores a flat 10.0 rather than the high-8s where most critical enterprise flaws land.",
      "cvss": 10,
      "status": "actively exploited",
      "kev": false,
      "action": "Apply Security Note 3771065, then rebuild and redeploy the application and confirm the environment actually serving traffic has moved to a fixed release, because marking the note applied does not change the running build; if a redeploy cannot happen immediately, configure an IP Filter Set to restrict access to the vulnerable endpoint as a stopgap and hunt backwards through logs from patch day onward.",
      "date": "2026-08-17",
      "note": "The number that matters here is three, not ten. SAP shipped the fix on its August 2026 Patch Day and threat intelligence firm Defused Cyber logged exploitation attempts against its honeypot sensors three days later, while its own tracking entry still read that the flaw had no public proof-of-concept and was not known to be exploited. Both of those statements were true and neither was protective: no exploit was ever published, because the patch itself is the map. Pulling the fixed release, diffing it against the previous one and reading which functions changed is roughly three days of work on a well-understood enterprise product, which means the usual \"wait for a PoC before treating it as urgent\" heuristic offered no grace period at all. kev is false because CISA KEV listing was not confirmed at time of writing, not because exploitation is in doubt. Remediation guidance from Onapsis stresses the rebuild-and-redeploy step, which is the most likely place for this to go wrong in practice: Commerce Cloud is a built and deployed application, so a team can close the ticket while the vulnerable build keeps serving. Precedent for what follows: CVE-2025-31324, a prior SAP maximum-severity flaw, was weaponized by China-nexus espionage clusters and by ordinary cybercrime groups.",
      "post": "/p/sap-commerce-cloud-rce-exploited-three-days-after-patch/"
    },
    {
      "id": "GHSA-mqjf-5f49-2fjh",
      "product": "GeoServer, and the underlying GeoTools PostGIS JDBC datastore. Fixed in GeoServer 3.0.1, 2.28.5 and 2.27.6. For direct consumers of the library, org.geotools:gt-jdbc-postgis 35.0 is fixed in 35.1, 34.0 and later in 34.5, and 33.1 and later in 33.6.",
      "type": "Unauthenticated SQL injection with a path to remote code execution. The jsonArrayContains(<column>, <pointer>, <value>) function writes its third argument into generated SQL without escaping, so any caller who can submit an OGC filter can submit SQL instead. Preconditions narrow the real exposure: it requires the PostGIS DataStore implementation, PostGIS 12 or later, and a String or JSON field reachable through the filter. The code execution path specifically involves certain H2 database deployments rather than every install.",
      "cvss": 9.8,
      "status": "exploited, patched",
      "kev": false,
      "action": "Update GeoServer to 3.0.1, 2.28.5 or 2.27.6, or bump gt-jdbc-postgis to 35.1, 34.5 or 33.6, then hunt backwards through access logs from August 12 for filter requests containing jsonArrayContains alongside SQL syntax, because exploitation began before any fix existed.",
      "date": "2026-08-16",
      "note": "Disclosed publicly on August 12, 2026 at 10:46 UTC by a researcher posting as @q1uf3ng, before a patch was available. Exploitation attempts followed within hours, with watchTowr observing hundreds of attempts from a small pool of IP addresses, a pattern consistent with a few operators scanning broadly rather than a wide campaign. Public reporting had not described any confirmed compromise as of August 13, which is worth reading as detection lag rather than as an all-clear. No CVE number was assigned initially, so scanners keyed on CVE identifiers may not flag this yet; it is tracked under the GitHub advisory id. kev is false because CISA KEV listing was not confirmed at time of writing. GeoServer has a real exploitation history rather than just a vulnerability history, including the 2024 compromise of a large United States federal agency, and it is commonly internet-facing by design in public-sector mapping deployments.",
      "post": "/p/geoserver-jsonarraycontains-zero-day-exploited/"
    },
    {
      "id": "CVE-2026-59310",
      "product": "VMware vCenter Server. Fixed builds are 9.1.0.0300, 9.0.2.0100, 8.0 U3k and 8.0 U2f; every supported build below those is affected. Disclosed by Broadcom in advisory VMSA-2026-0006 alongside CVE-2026-59309, an authentication bypass in the same product.",
      "type": "Path traversal in the vCenter Syslog server leading to arbitrary code execution. Exploitable by an unauthenticated attacker with only network access to the vCenter Server, with no user interaction. Observed in-the-wild chain: path traversal against the Syslog service, then a malicious cron job written to the appliance for persistence, then reverse_ssh (an open-source tool for SSH connections back to attacker infrastructure) for an outbound command and control channel. Broadcom states there is no workaround, so the update is the only remediation for the entry point.",
      "cvss": 9.8,
      "status": "actively exploited",
      "kev": false,
      "action": "Update vCenter to 9.1.0.0300, 9.0.2.0100, 8.0 U3k or 8.0 U2f now, then hunt for the persistence the patch does not remove: audit appliance cron for entries you did not create, review outbound SSH sessions from vCenter to unrecognised infrastructure, and treat any estate whose Syslog service was network-reachable between July 29 and patch day as scanned.",
      "date": "2026-08-14",
      "note": "Disclosed July 29, 2026; exploitation observed in the wild by August 3, a five-day gap that is shorter than a typical vCenter change window. German digital forensics firm Quirso found the chain during an incident response engagement and published August 10, attributing it to a suspected APT actor and counting 361 victim IP addresses across 47 countries by August 5, of which 185 sat in Germany, the United States, Turkey, Iran and France. kev is false here because CISA KEV listing was not confirmed at time of writing, not because the flaw is unexploited. The important operational detail is that patching closes only the entry point: the cron job and reverse_ssh channel survive the update and require separate eviction.",
      "post": "/p/vcenter-cve-2026-59310-exploited-five-days/"
    },
    {
      "id": "LiteLLM 1.82.7 / 1.82.8 (no CVE assigned)",
      "product": "LiteLLM, the open-source LLM proxy and Python SDK, versions 1.82.7 and 1.82.8 as distributed on PyPI. Any CI/CD pipeline, container build or developer machine that resolved LiteLLM during the 40-minute window the poisoned releases were live in March 2026.",
      "type": "Software supply chain compromise reached through a third dependency rather than a vulnerability in LiteLLM itself. The threat actor TeamPCP compromised a release of Aqua Security's Trivy scanner; LiteLLM's CI pipeline installed that Trivy build automatically and unpinned, which exposed LiteLLM's package publishing credentials and let the attacker push malicious releases to PyPI. The payload executed on every Python invocation, not only at install time, and harvested cloud keys, SSH keys, registry publishing tokens, database connection strings, AI provider API keys and CI runner memory.",
      "cvss": null,
      "status": "exploited, patched",
      "kev": false,
      "action": "Treat every secret readable by the LiteLLM process as compromised and rotate it now: cloud access keys, SSH keys, package registry tokens, database connection strings and all AI provider API keys. Then pin build tooling to hashes rather than floating tags, and scope CI credentials to the job that needs them.",
      "date": "2026-08-13",
      "note": "The compromise itself was in March 2026 and the malicious versions were pulled after roughly 40 minutes, but the blast radius was only measured on August 12, 2026, when CloudSEK attributed 118,829 CI runner memory dumps to 2,488 corporate domains across an estimated 434,000 CI/CD pipelines. Named among the exposed: Nvidia, AWS, Samsung, Salesforce, Cisco, ServiceNow, Siemens, London Stock Exchange Group, FedEx, Volkswagen, HP and Zscaler. Listed here despite carrying no CVE identifier because the required action is concrete and five months overdue for most affected environments. Scanning would not have caught it: the compromised artifact was itself a vulnerability scanner, shipped as a legitimately signed release.",
      "post": "/p/litellm-supply-chain-blast-radius-2488-companies/"
    },
    {
      "id": "CVE-2026-68820",
      "product": "Microsoft Windows, all supported versions. The flaw is in afd.sys, the kernel-mode Ancillary Function Driver for WinSock, which is loaded on every Windows host and reachable by any process that opens a socket without requiring elevated privileges.",
      "type": "Use-after-free in the Windows Sockets kernel driver. A locally authenticated attacker runs a crafted application that triggers a race condition between two threads touching the same driver object: one frees it while the other retains a reference and keeps operating on the freed memory. Reclaiming that allocation with attacker-controlled data lets the driver act on attacker-shaped structures in kernel context, yielding NT AUTHORITY\\SYSTEM. This is the fourth exploited afd.sys zero-day since 2022, after CVE-2024-38193, CVE-2025-21418 and CVE-2025-32709.",
      "cvss": 7,
      "status": "actively exploited",
      "kev": true,
      "action": "Apply the August 2026 Patch Tuesday updates now, prioritising developer workstations and any fleet where standard-user accounts are relied on as a security boundary, since that boundary is exactly what this bug removes.",
      "date": "2026-08-12",
      "note": "CISA added it to the Known Exploited Vulnerabilities catalog on August 11, 2026. Check Point Research attributes in-the-wild exploitation to Lazarus within the Operation Dream Job campaign, which targets engineers at defence and aerospace employers through fake recruiter outreach. The CVSS score of 7.0 understates the operational risk: local privilege escalation loses CVSS points for requiring local access, but it is the second half of every two-stage intrusion.",
      "post": "/p/windows-afd-sys-zero-day-lazarus-cve-2026-68820/"
    },
    {
      "id": "CVE-2026-63077",
      "product": "JetBrains TeamCity, on-premise servers. The flaw is reachable through the agent polling protocol, which internet-facing build servers commonly expose.",
      "type": "Deserialization of untrusted data leading to unauthenticated remote code execution. The XStream allowlist was built additively: it registered TeamCity protocol classes without first removing XStream's existing default permissions, so the effective permission set stayed a permissive union rather than an exclusive allowlist. Rapid7's Stephen Fewer traced the root cause; the patch inserts NoTypePermission.NONE ahead of the allowlist. A published proof of concept writes .JSPWS files, executes OS commands with the TeamCity server process privileges, then deletes the files from disk, so no web shell remains for a later file scan to find.",
      "cvss": 9.8,
      "status": "actively exploited",
      "kev": true,
      "action": "Patch on-premise TeamCity immediately, then treat any internet-facing server left unpatched after August 5 as compromised: rotate source control tokens, registry keys, cloud roles and signing keys the server could reach, review recent build artifacts and pipeline definitions for unauthorised changes, and move the agent polling protocol off the public internet.",
      "date": "2026-08-11",
      "note": "CISA added it to the Known Exploited Vulnerabilities catalog on August 5, 2026 with a federal remediation deadline of August 8 under BOD 26-04, a three-day window. Rapid7 published root cause analysis on August 7. Neither attribution nor the scale of exploitation has been made public.",
      "post": "/p/teamcity-cve-2026-63077-xstream-rce-kev/"
    },
    {
      "id": "No CVE assigned (Coldcard firmware RNG)",
      "product": "Coinkite Coldcard hardware wallets. Seeds generated on Mk2/Mk3 firmware 4.0.0 through 4.1.9, Mk4/Mk5 before 5.6.0, Q before 1.5.0Q, and Edge builds before 6.6.0X (Mk4/Mk5) or 6.6.0QX (Q).",
      "type": "Weak key generation from a build-configuration error. Coldcard's firmware set MICROPY_HW_ENABLE_RNG to zero because Coinkite supplied its own RNG wrapper, but the cryptographic support library tested whether the macro was defined rather than whether its value was non-zero. A macro set to zero is still defined, so the library concluded hardware randomness was active and bound seed generation to MicroPython's Yasmarang fallback PRNG instead of the STM32 hardware RNG. Yasmarang was initialised from the chip's unique ID and timer registers, neither of which is secret, and collected no fresh entropy afterwards. Coinkite estimates effective entropy at roughly 40 bits on the Mk3 and about 72 bits on Mk4, Mk5 and Q, against 128 bits for a correctly generated seed. Introduced in firmware 4.0.0 in March 2021 and undetected for five years.",
      "cvss": null,
      "status": "actively exploited",
      "kev": false,
      "action": "Install the patched firmware, then treat that as step one of two: the update does NOT repair an existing seed. Generate a completely new seed on the patched build and move every coin to addresses derived from it. Do not restore the old seed onto new firmware. Any seed created on an affected version must be treated as compromised, because weak-key exposure offers no reliable self-test.",
      "date": "2026-08-02",
      "note": "Exploited in the wild on July 30, 2026: Galaxy Research mapped 1,196 addresses drained between 01:10 and 01:51 UTC, roughly 1,082.65 BTC or about $70.2 million at the time. CoinDesk separately reported roughly 594 BTC (about $38 million) from around 500 wallets, which is the confirmed-victim-report figure rather than total swept volume; Galaxy cautioned that an on-chain sweep pattern 'identifies the operator, not the theft', since a defensive self-evacuation looks identical. Coinkite disclosed, took public responsibility and shipped emergency firmware on July 31. No CVE had been assigned as of August 2, 2026, which is unusual for a flaw of this reach. Status is 'actively exploited' rather than 'exploited, patched' because the patch does not remediate already-generated seeds, so every unmigrated wallet stays exploitable. The defective defined-versus-value check lived in shared library code, so other MicroPython-based embedded products that set the same macro to zero warrant an audit.",
      "post": "/p/coldcard-rng-firmware-bug-1082-btc-drained/"
    },
    {
      "id": "CVE-2026-20316",
      "product": "Cisco Secure Firewall Management Center (FMC) software, trains 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0.",
      "type": "Static credentials for a low-privilege account compiled into the shipped software image. Every installation of an affected version carries the same username and password, with no per-device derivation and no first-boot rotation, so an unauthenticated attacker who can reach the management interface simply logs in. The account cannot administer the appliance, but on a firewall management console read access covers access-control policy, object groups, network topology as expressed in rules, and device names and versions. Cisco assigned a Security Impact Rating of High despite the modest CVSS base score, because the leaked data is reconnaissance input for a follow-on attack and the flaw is expected to be chained with a privilege-escalation issue.",
      "cvss": 5.3,
      "status": "actively exploited",
      "kev": true,
      "action": "Apply the Cisco hotfix for your FMC train immediately; there is no configuration workaround because the credential lives in the binary. Then hunt for prior compromise by searching the appliance message log for license activity (cat /var/log/messages | grep license) and looking for references to /var/tmp/license.tmp, pulling archived log files too since exploitation dates to early July and rotation may have aged out the evidence. Independently, restrict the management interface to an out-of-band VLAN or jump host.",
      "date": "2026-08-01",
      "note": "Discovered by Jimi Sebree of Horizon3.ai. Exploited in the wild from early July 2026, roughly three weeks before any public advisory existed. Cisco published its advisory and CISA added the CVE to the Known Exploited Vulnerabilities catalog on July 29, 2026, setting a federal remediation deadline of August 1, 2026. cvss is 5.3 because the flaw leaks confidentiality only, with no integrity or availability impact; that number materially understates the operational risk, which is why Cisco's own Security Impact Rating is High. Absence of the license.tmp indicator is weak evidence rather than a clean result, given the gap between first exploitation and disclosure.",
      "post": "/p/cisco-fmc-hardcoded-credentials-cve-2026-20316/"
    },
    {
      "id": "Multiple (7)",
      "product": "Langflow, n8n, Citrix NetScaler ADC, Apache Tomcat, Marimo Notebook, Palo Alto PAN-OS User-ID Portal and Windows IKE Extensions, as used together in one AI-orchestrated campaign documented by Palo Alto Networks Unit 42.",
      "type": "Not a single flaw but a toolkit: seven already-public CVEs assembled into one campaign in which DeepSeek, running inside the open-source Hermes Agent framework and tasked over Telegram, autonomously enumerated exposed hosts through FOFA, pulled proof-of-concept code from GitHub, ranked targets by CVSS and repository popularity, and probed them without operator input. The set is CVE-2026-33017 (Langflow, 9.8), CVE-2026-21858 with CVE-2025-68613 (n8n, 10.0 and 9.9), CVE-2026-3055 (NetScaler ADC out-of-bounds read, 9.8), CVE-2026-34486 (Tomcat, 7.5), CVE-2026-39987 (Marimo, 9.8), CVE-2026-0300 (PAN-OS, 9.8, non-functional PoC only) and CVE-2026-33824 (Windows IKE Extensions, 9.8). Both fully autonomous exploitation attempts, against Langflow and n8n, failed on authentication requirements; every confirmed compromise came from the operator working manually.",
      "cvss": null,
      "status": "actively exploited",
      "kev": false,
      "action": "Patch the NetScaler ADC and Marimo Notebook flaws first, since those are the two with confirmed impact in this campaign, then work through the remaining five. Separately, audit internal tooling exposed to the internet with convenience toggles enabled: Langflow's auto_login being off and n8n requiring form authentication are what stopped the autonomous half of this campaign, so those defaults are functioning as a security control.",
      "date": "2026-07-31",
      "note": "Unit 42 recovered a complete Hermes Agent session log dated 7 May 2026, which is why the attack chain is documented step by step rather than inferred. The operator, tracked as knaithe and KnYuan and assessed to be in Zhuhai, China, attempted exploitation against more than 460 targets. Confirmed impact: memory data exfiltrated from three organisations via CVE-2026-3055, command execution on 11 Marimo instances, Java deserialization reverse shells fired at 9 Tomcat servers and callbacks aimed at 3 IKE VPN endpoints. cvss is null because this row covers seven flaws scoring between 7.5 and 10.0; the individual scores are listed above. kev is false because CISA KEV listing was not confirmed for these identifiers at time of writing, not because they are known to be absent. Notably the agent's own autonomy caused the campaign's largest exposure: it started python3 -m http.server 8888 from /home/worker, publishing the operator's API keys, exploit scripts, target lists and session logs to the internet.",
      "post": "/p/unit-42-deepseek-autonomous-attack-campaign/"
    },
    {
      "id": "CVE-2026-16812",
      "product": "Arista VeloCloud Orchestrator On-Prem (self-hosted SD-WAN management plane). Cloud-hosted VeloCloud is not affected.",
      "type": "Unauthenticated OS command injection. A crafted HTTP request to an exposed orchestrator endpoint passes attacker-controlled input into a shell command, giving privileged code execution with no credentials required. Because the orchestrator holds the credentials and tunnel configuration for every managed branch, data-centre and cloud edge, compromise of it means control of the policy applied across the whole SD-WAN. The management web interface is exposed by default and no supported configuration removes that exposure entirely, so there is no mitigation that substitutes for patching.",
      "cvss": 10,
      "status": "actively exploited",
      "kev": true,
      "action": "Patch VeloCloud Orchestrator On-Prem to 5.2.3.14, 6.1.3.4 or 6.4.2.4 immediately, then rotate orchestrator credentials and API tokens and diff edge policy against a known-good backup, since this was exploited as a zero-day before the fix shipped.",
      "date": "2026-07-29",
      "note": "Exploited in the wild as a zero-day before Arista shipped a patch. CISA added it to the Known Exploited Vulnerabilities catalog, starting a federal remediation deadline. CVSS 10.0 is the maximum score, reflecting unauthenticated network access, no user interaction and full compromise of confidentiality, integrity and availability on a device that centrally controls network policy.",
      "post": "/p/arista-velocloud-cve-2026-16812-zero-day/"
    },
    {
      "id": "CVE-2026-63030, CVE-2026-60137",
      "product": "WordPress Core (versions before 7.0.2, 6.9.5, 6.8.6)",
      "type": "An authentication bypass (CVE-2026-60137) chained with a remote code execution flaw in the REST API batch-processing feature (CVE-2026-63030), letting an unauthenticated attacker send one crafted request to the /batch endpoint and run arbitrary code on the server. The flaw is in WordPress Core itself, so it affects the base install regardless of plugins or theme.",
      "cvss": null,
      "status": "actively exploited",
      "kev": false,
      "action": "Update to WordPress 7.0.2, 6.9.5 or 6.8.6 immediately; automatic updates cover supported installs. Audit the plugin directory and active REST endpoints for webshells disguised as plugins, and treat any site left unpatched during the exploitation window as potentially compromised, not merely at risk.",
      "date": "2026-07-24",
      "note": "Disclosed by SearchLight Cyber, which logged the first probing of the batch endpoint on July 17 at 23:29 UTC, with SQL-injection attempts 13 minutes later and internet-wide mass scanning confirmed within days. Post-exploitation drops feature-rich obfuscated webshells disguised as legitimate plugins and registers rogue REST API endpoints for remote command execution. In a tracked sample of 124,580 sites, 81.6% had patched, leaving nearly one in five exposed; across the tens of millions of WordPress installs (~40% of all websites) the unpatched surface is large. WordPress pushed the fixes to supported installations automatically. CISA KEV listing not confirmed at time of writing.",
      "post": "/p/wordpress-core-rest-api-rce-webshell-exploited/"
    },
    {
      "id": "CVE-2026-6875",
      "product": "ServiceNow AI Platform (formerly Now Platform)",
      "type": "Sandbox escape to unauthenticated remote code execution",
      "cvss": 9.5,
      "status": "actively exploited",
      "kev": false,
      "action": "Apply the July 13 ServiceNow patch to every self-hosted and on-premise instance immediately, then hunt for prior compromise rather than assuming the patch closed the incident, and rotate the downstream credentials and API tokens the instance holds for the systems it orchestrates.",
      "date": "2026-07-21",
      "note": "Reported to ServiceNow on April 1, 2026 by Adam Kues of Assetnote (Searchlight Cyber). ServiceNow remediated its own hosted fleet in April but self-hosted customers only received patches when the advisory published on July 13, leaving roughly a three-month window for self-managed deployments. Defused observed the first in-the-wild exploitation attempts on July 18, five days after disclosure, and subsequently confirmed a second sandbox-escape gadget chain that bypasses detection tuned to the published proof of concept, so signature-based blocking alone is not sufficient. The flaw is reachable pre-authentication, requiring no credentials. ServiceNow says it has seen no evidence of compromise in instances it hosts, a statement that does not cover self-managed deployments. Scope matters here: the platform runs workflows for roughly 85% of the Fortune 500 and typically stores credentials for the systems it orchestrates, making code execution a pivot rather than an endpoint.",
      "post": "/p/servicenow-cve-2026-6875-sandbox-escape-exploited/"
    },
    {
      "id": "CVE-2026-20230",
      "product": "Cisco Unified Communications Manager",
      "type": "Server-side request forgery (SSRF)",
      "cvss": null,
      "status": "actively exploited",
      "kev": true,
      "action": "Apply Cisco's fixed Unified Communications Manager release immediately, treating it as an incident-response task rather than routine patching. Until patched, restrict network access to the CUCM administrative and web interfaces, segment voice infrastructure away from sensitive internal services, and monitor the server for anomalous outbound requests that would indicate SSRF abuse.",
      "date": "2026-07-16",
      "note": "Cisco confirmed active in-the-wild exploitation of CVE-2026-20230, a server-side request forgery flaw in Unified Communications Manager, the enterprise call-control platform, and CISA added it to the Known Exploited Vulnerabilities catalog. SSRF lets an attacker coax the trusted internal server into making requests on their behalf, turning a mid-severity bug into a pivot toward internal APIs, management interfaces, and metadata endpoints that are not directly exposed. Because CUCM sits deep inside the network, the flaw's real risk exceeds its score.",
      "post": "/p/cisco-ucm-ssrf-cve-2026-20230-exploited/"
    },
    {
      "id": "CVE-2024-42009",
      "product": "Roundcube Webmail",
      "type": "Cross-site scripting (XSS), near-zero interaction",
      "cvss": 9.3,
      "status": "actively exploited",
      "kev": false,
      "action": "Update Roundcube to a fixed release immediately; the patch has existed since 2024 and closes the flaw outright. Put webmail behind SSO with phishing-resistant MFA, enforce a strict content-security policy to blunt XSS, monitor for anomalous or mass mailbox reads, and rotate credentials and session tokens for any account that opened a suspicious message.",
      "date": "2026-07-15",
      "note": "A China-aligned threat cluster is actively exploiting CVE-2024-42009 (CVSS 9.3), a critical Roundcube webmail XSS flaw, against U.S. and Canadian universities. A crafted email runs attacker-controlled JavaScript in the victim's session on view, with almost no interaction, letting intruders read mail and harvest credentials. The fix has been available since 2024; the exposure is unpatched self-hosted Roundcube instances, a reminder that a patched CVE is only closed on the servers that actually applied it.",
      "post": "/p/roundcube-cve-2024-42009-exploited-universities/"
    },
    {
      "id": "CVE-2026-56155 / CVE-2026-56164",
      "product": "Microsoft ADFS & SharePoint Server",
      "type": "Elevation of privilege (identity federation; unauthenticated network)",
      "cvss": null,
      "status": "actively exploited",
      "kev": false,
      "action": "Patch both before anything else in July's Patch Tuesday. If a SharePoint server cannot be updated at once, apply Microsoft's interim mitigation: enable the Antimalware Scan Interface (AMSI) and set Request Body Scan to Full. Review ADFS and SharePoint logs for anomalous privilege elevation during the exposure window.",
      "date": "2026-07-14",
      "note": "Two of the three zero-days in Microsoft's record 570-flaw July 2026 Patch Tuesday are under active exploitation. CVE-2026-56155 is an elevation-of-privilege flaw in Active Directory Federation Services (Important), credited to Microsoft's DART team (typically found during live-intrusion response); it lets an authorized attacker elevate locally, and ADFS brokers org-wide single sign-on. CVE-2026-56164 is a SharePoint Server elevation-of-privilege bug (Moderate) exploitable over the network by an unauthenticated attacker. A third zero-day, CVE-2026-50661, is a publicly disclosed BitLocker security-feature bypass requiring physical access.",
      "post": "/p/microsoft-570-flaw-patch-tuesday-zero-days/"
    },
    {
      "id": "ShareFile Storage Zone zero-day (CVE pending)",
      "product": "Progress ShareFile Storage Zone Controller",
      "type": "Path traversal (arbitrary file read/write, filesystem enumeration)",
      "cvss": null,
      "status": "actively exploited",
      "kev": false,
      "action": "Apply Progress's new Storage Zone Controller update before bringing any server back online, keep the controller off the public internet, and assume-breach on anything that was exposed: hunt for files written to unexpected directories, unfamiliar accounts, and outbound connections, and rotate every credential the service account could reach. Install February's 5.12.4/v6 updates too if you skipped them.",
      "date": "2026-07-14",
      "note": "Progress confirmed a high-severity path traversal zero-day in all 5.x and 6.x ShareFile Storage Zone Controllers is behind last week's emergency shutdown order, and has shipped a patch. An authenticated admin can read arbitrary files, write attacker content to any directory, and enumerate the filesystem under the service account. Only the hybrid on-premises deployment is affected; cloud-only ShareFile is not. watchTowr honeypots flagged active zero-day exploitation indicators, and internet-exposed controllers dropped from ~30,000 in April to ~1,000 after the shutdown. The CVE number is held ~2 weeks; researchers suspect the Clop group, echoing the MOVEit crisis.",
      "post": "/p/progress-sharefile-zero-day-server-shutdown/"
    },
    {
      "id": "CVE-2026-25089 / CVE-2026-39808 / CVE-2026-39813",
      "product": "Fortinet FortiSandbox",
      "type": "Auth bypass + OS command injection to unauthenticated RCE",
      "cvss": null,
      "status": "actively exploited",
      "kev": false,
      "action": "Apply Fortinet's April and June FortiSandbox updates immediately (all three are patched). Keep FortiSandbox management interfaces off the internet, and assume-breach on any appliance that was exposed and unpatched: review for unexpected accounts, tasks, and outbound connections, and rotate every credential the box could reach.",
      "date": "2026-07-14",
      "note": "Defused honeypots are seeing in-the-wild exploitation attempts against three patched FortiSandbox flaws. CVE-2026-39813 (auth bypass) chains with CVE-2026-39808 (OS command injection) into remote code execution; CVE-2026-25089 reaches unauthenticated command execution on its own. The exploit for CVE-2026-25089 appears AI-authored and did not work correctly when first observed, a preview of machine-generated exploits raising the volume of near-miss attempts. A malware-analysis appliance is a high-value target: it sees the samples, sits deep in the network, and is trusted.",
      "post": "/p/fortisandbox-cves-exploited-ai-generated-poc/"
    },
    {
      "id": "CVE-2026-55255",
      "product": "Langflow (AI agent orchestration platform)",
      "type": "Cross-tenant IDOR / authorization bypass via user-controlled flow ID",
      "cvss": 6.1,
      "status": "actively exploited",
      "kev": true,
      "action": "Update to Langflow 1.9.2 or later, then rotate every API key, LLM provider credential and cloud key stored in any flow; audit /api/v1/responses logs for cross-user flow IDs",
      "date": "2026-07-10",
      "note": "First AI agent platform on CISA's KEV. An authenticated request to /api/v1/responses with a victim's flow UUID runs their flow and reads its data, with no ownership check. Sysdig observed in-the-wild exploitation from June 25, chained after the CVE-2026-33017 RCE, to steal LLM provider and AWS keys. CVSS 6.1 understates it: on multi-tenant deployments the IDOR is the only cross-tenant path and it leaves almost no log trace. CISA added it July 7 with a July 10 federal deadline.",
      "post": "/p/langflow-cve-2026-55255-first-ai-agent-kev/"
    },
    {
      "id": "CVE-2026-8037",
      "product": "Progress Kemp LoadMaster",
      "type": "Command injection → RCE",
      "cvss": 9.6,
      "status": "actively exploited",
      "kev": false,
      "action": "Patch now; take management interfaces off the internet",
      "date": "2026-07-06",
      "note": "Attacks on internet-facing load balancers observed from June 29.",
      "post": "/p/kemp-loadmaster-cve-2026-8037-exploited/"
    },
    {
      "id": "CVE-2026-45659",
      "product": "Microsoft SharePoint Server (on-prem)",
      "type": "Unsafe deserialization → RCE",
      "cvss": 8.8,
      "status": "actively exploited",
      "kev": true,
      "action": "Apply the May 2026 patch — every unpatched on-prem server is a target",
      "date": "2026-07-05",
      "note": "Added to CISA's Known Exploited Vulnerabilities catalog July 2 after confirmed exploitation.",
      "post": "/p/sharepoint-cve-2026-45659-actively-exploited/"
    }
  ]
}