PatchTriageWhat to patch first
Track 1 — active exploitation

Being exploited right now

Between the monthly briefs: vulnerabilities with a CVE that are on the CISA KEV catalog or carry evidence of exploitation in the wild. This is the short list — the things whose patch window has already closed.

Data as of 11 September 2026, 21:00 UTC · Source brief 2026-09-11 Cadence checked weekdays — the date above moves only when a card changes, so an old date means no card has changed since, not that nobody looked

Patch priority — 49 under active exploitation

Ranked in from the brief. Every entry here has a CVE and either a CISA KEV listing or independent evidence of exploitation.

CVE-2026-84869CVSS 9.9Exploited

ConnectWise ScreenConnect — client prior to 26.6.5. ScreenConnect servers are explicitly NOT impacted per the vendor bulletin

Improper privilege management / missing authorization → files transferred and executed through an active remote session without Host confirmation

Exploitationyes per CISA KEV (added 2026-09-11, deadline 2026-09-14, known ransomware use: Unknown). ⚠️ The vendor bulletin does NOT claim in-the-wild exploitation — it rates the issue Priority 1 (High) using risk-of-targeting language. Vendor/catalog disagreement recorded, not resolved
KEV added2026-09-11
CISA deadline2026-09-14
Patched inScreenConnect 26.6.5 (vendor bulletin 2026-09-08, read 2026-09-11). Interim mitigation where the update cannot be applied at once: deselect the TransferFiles permission for all user roles under Administration > Security > Roles — the vendor states this 'may reduce exposure until the update is applied', i.e. mitigation, not a fix
CVE-2026-42016CVSS 8.1Exploited

JFrog Artifactory (Self-Hosted) before 7.133.11

Incorrect authorization — token validation checks the signature/issuer but not the token's scope, allowing privilege escalation

Exploitationyes per CISA KEV (added 2026-09-11, federal deadline 2026-09-25, known ransomware use: Unknown). JFrog's advisory does not itself state in-the-wild exploitation
KEV added2026-09-11
CISA deadline2026-09-25
Patched inJFrog Artifactory 7.133.11 — from JFrog's security advisories page, read 2026-09-11 (advisory published and updated 2026-07-27). No workaround is offered; upgrade is the remediation. Supply-chain follow-up: review artifact pushes and token issuance during the exposure window, since a patch does not un-publish a poisoned artifact
CVE-2026-42018CVSS 7.5Exploited

JFrog Artifactory — affected < 7.111.20, 7.117.0-7.117.27, 7.125.0-7.125.19, 7.133.0-7.133.28, 7.146.0-7.146.8

Improper authentication — an internal anonymous-user token can be returned to an unauthenticated caller while anonymous access is disabled

Exploitationyes per CISA KEV (added 2026-09-11, federal deadline 2026-09-25, known ransomware use: Unknown). JFrog's advisory does not itself state in-the-wild exploitation
KEV added2026-09-11
CISA deadline2026-09-25
Patched inPer-train fixes from JFrog's security advisories page, read 2026-09-11 — 7.111.20 · 7.117.27 · 7.125.19 · 7.133.28 · 7.146.8 (advisory published 2026-08-12, updated 2026-08-13). No workaround. ⚠️ Different fix line from CVE-2026-42016 (7.133.11) in the same 7.133 train — verify the exact build against BOTH advisories, and rotate tokens that could have been disclosed while the instance was vulnerable
CVE-2026-86060CVSS 9.8Exploited

MikroTik RouterOS — fixed in 6.49.21 (Long-term), 7.23.4 (Long-term), 7.24.2 (Stable), 7.25 beta 3; earlier builds in those trains affected. Vendor states 'Most configurations are not at risk' without enumerating which

Improper neutralization of argument delimiters in a command — a username beginning with a prohibited character alters the trusted RouterOS policy mask via the SSH login helper, leading to privilege escalation

Exploitationyes — MikroTik's own advisory (2026-09-03) states the vulnerabilities are actively exploited and withholds technical detail to allow time to update. CISA KEV added 2026-09-10, federal deadline 2026-09-13, known ransomware use: Unknown
KEV added2026-09-10
CISA deadline2026-09-13
Patched inRouterOS 6.49.21 (Long-term), 7.23.4 (Long-term), 7.24.2 (Stable), 7.25 beta 3 — from MikroTik's advisory read 2026-09-11. VENDOR MITIGATION where an update cannot be applied at once: ensure SSH is not open to any untrusted network; preferably expose no management ports and reach the device over a VPN such as WireGuard. Exploitation requires an unauthenticated SSH session to the login helper, so removing that reachability removes the attack path
CVE-2026-67277CVSS 8.2Exploited

MikroTik RouterOS — fixed in 6.49.21 (Long-term), 7.23.4 (Long-term), 7.24.2 (Stable), 7.25 beta 3; earlier builds in those trains affected

Missing authentication for a critical function — a 'related' btest connection is accepted before the primary session authenticates; with random-data=false the sender leaks an uninitialized kernel packet-buffer tail, and an unchecked inverted packet-size interval causes unsigned integer underflow, oversized fragmented output and a kernel restart

Exploitationyes — MikroTik's advisory (2026-09-03) states the September vulnerabilities are actively exploited. CISA KEV added 2026-09-10, federal deadline 2026-09-13, known ransomware use: Unknown
KEV added2026-09-10
CISA deadline2026-09-13
Patched inRouterOS 6.49.21 (Long-term), 7.23.4 (Long-term), 7.24.2 (Stable), 7.25 beta 3 — the SAME builds that fix CVE-2026-86060, so one update closes both. Vendor mitigation as above: do not expose management/bandwidth-test services to untrusted networks; prefer VPN-only management access
CVE-2026-20079CVSS 10.0Exploited

Cisco Secure Firewall Management Center (FMC) Software and Security Cloud Control (SCC) Firewall Management — trains 7.0, 7.2, 7.4, 7.6, 7.7, 10.0

Authentication bypass via an alternate path/channel — an improper boot-time system process lets crafted HTTP requests run scripts/commands as root on the underlying OS

Exploitationyes — Cisco PSIRT, advisory last updated 2026-09-09: 'In August 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability.' CISA KEV added 2026-09-09, federal deadline 2026-09-12, known ransomware use: Unknown
KEV added2026-09-09
CISA deadline2026-09-12
Patched inHotfixes per train, from the Cisco advisory read 2026-09-11 — 7.0: GB-7.0.9.1-3 · 7.2: HL-7.2.11.1-4 · 7.4: HG-7.4.7.1-3 · 7.6: CY-7.6.5.1-2 · 7.7: AM-7.7.12.1-2 · 10.0: P-10.0.1.1-2. Cisco states there are NO workarounds that address this vulnerability — the hotfix is the only remediation
CVE-2025-25249CVSS 9.8Exploited

Fortinet FortiOS 7.6.0-7.6.3, 7.4.0-7.4.8, 7.2.0-7.2.11, 7.0.0-7.0.17, 6.4 (all versions); FortiSwitchManager 7.2.0-7.2.6, 7.0.0-7.0.5. Affected component: the cw_acd (CAPWAP control) daemon

Heap-based buffer overflow (CWE-122) in the cw_acd daemon -> remote unauthenticated arbitrary code or command execution via crafted requests

Exploitationyes per CISA KEV (added 2026-09-09, federal deadline 2026-09-12, known ransomware use: Unknown). 🔴 VENDOR DISAGREES: FG-IR-25-084 states 'Known Exploited: No' — but its timeline ends 2026-02-23, so that is a February statement never revised after the September KEV listing. NVD also carries an Exploit-tagged third-party write-up of a FortiGate RAT ('PivotC2') built on this CVE, not read by this review
KEV added2026-09-09
CISA deadline2026-09-12
Patched inFortiOS 7.6.4+ (from 7.6.0-7.6.3) · 7.4.9+ (from 7.4.0-7.4.8) · 7.2.12+ (from 7.2.0-7.2.11) · 7.0.18+ (from 7.0.0-7.0.17) · FortiSwitchManager 7.2.7+ (from 7.2.0-7.2.6) and 7.0.6+ (from 7.0.0-7.0.5) — read from FG-IR-25-084 on 2026-09-11. 🔴 FortiOS 6.4: NO fixed build in-train, all versions affected, vendor instruction is 'Migrate to a fixed release'; the advisory timeline also records 6.4.17 being REMOVED from the fixed list on 2026-02-23. WORKAROUNDS (vendor, either one): (a) remove 'fabric' from allowaccess on each interface — config system interface / edit <port> / set allowaccess ssh https (dropping fabric); or (b) where fabric must stay, block CAPWAP-CONTROL UDP 5246-5249 via a local-in policy that accepts only trusted device addresses and denies all others. Follow Fortinet's upgrade-path tool at docs.fortinet.com/upgrade-tool
CVE-2026-19490CVSS 9.8Exploited

Citrix NetScaler ADC and NetScaler Gateway — 14.1 before 14.1-73.32; 13.1 before 13.1-63.21; NetScaler ADC FIPS before 14.1-73.32 FIPS; NetScaler ADC FIPS and NDcPP before 13.1-37.277

Authentication bypass using an alternate path or channel

Exploitationyes per CISA KEV (added 2026-09-09, federal deadline 2026-09-12, known ransomware use: Unknown). ⚠️ Citrix's bulletin CTX696939 does NOT mention in-the-wild exploitation — the exploitation claim rests on the KEV listing alone
KEV added2026-09-09
CISA deadline2026-09-12
Patched inFrom Citrix CTX696939, read 2026-09-11 — 14.1-73.32 and later · 13.1-63.21 and later · 14.1-73.32 FIPS and later · 13.1-37.277 and later (FIPS/NDcPP). Citrix states Workaround: None. Patching does not evict an attacker already in: on this product line, rotate credentials and terminate/invalidate existing sessions after upgrading
CVE-2026-87491CVSS 8.8Exploited

Google Chrome before 153.0.8010.36 (V8); every Chromium-based browser and Electron runtime embedding the affected V8 until independently rebuilt

Out-of-bounds write in V8 → arbitrary code execution inside the renderer sandbox via a crafted HTML page

Exploitationyes per CISA KEV (added 2026-09-09, federal deadline 2026-09-23, known ransomware use: Unknown). Google's Chrome Releases post was not readable per-CVE this session, so no vendor in-the-wild statement is recorded either way
KEV added2026-09-09
CISA deadline2026-09-23
Patched inChrome 153.0.8010.36 — from the CVE/CNA record read via the NVD API 2026-09-11 ('prior to 153.0.8010.36'). Force the update and RELAUNCH: a downloaded Chrome update does not protect a running browser. Other Chromium browsers and Electron apps need their own rebuild on a fixed V8; Chrome's update does not cover them
CVE-2026-75650CVSS 10.0Exploited

Adobe Commerce 2.4.4–2.4.9 (2026-aug patch level and earlier), Adobe Commerce B2B 1.3.3 / 1.3.4 / 1.4.2 / 1.5.2 / 1.5.3 (2026-aug and earlier), Magento Open Source 2.4.6–2.4.9 (2026-aug and earlier) — all platforms

Improper neutralization of special elements used in a template engine (CWE-1336) → unauthenticated remote arbitrary code execution, scope changed. Unauthenticated per the vector (PR:N) — NVD's 'in the context of the current user' describes the resulting execution context, not a precondition

Exploitationyes — Adobe, APSB26-146 (published 2026-09-07, priority 1): 'Adobe is aware of CVE-2026-75650 being exploited in the wild'. CISA ADP vulnrichment 2026-09-08: Exploitation active / Automatable yes / Technical impact total. CISA KEV added 2026-09-08 (catalog v2026.09.08), federal deadline 2026-09-11, known ransomware use: Unknown. No actor or campaign named by Adobe
KEV added2026-09-08
CISA deadline2026-09-11
Patched inIsolated 'Hotfix for CVE-2026-75650' (Adobe priority 1) for every supported line, applied on top of the current 2026-aug patch level — NOT a new patch-level release; per the CNA record the hotfix is the only unaffected state. Installation: Experience League KB announcement for APSB26-146 (linked from the bulletin). No workaround published. Verify by confirming the hotfix is present, not by version number alone
CVE-2026-86218CVSS 9.8Exploited

N-able N-central, self-hosted — every build before 2026.3.1.14 (NVD: all < 2026.3, plus 2026.3 base, Hotfix 1, Hotfix 2, Hotfix 3); hosted N-central (NCOD) already patched by N-able, no customer action

Static code injection (CWE-96) → unauthenticated remote code execution on the N-central server

Exploitationyes per CISA — KEV added 2026-09-08 (catalog v2026.09.08, 'N-able N-central Static Code Injection Vulnerability'), federal deadline 2026-09-11, known ransomware use: Unknown. ⚠️ Vendor position as of the 2026-09-05 hotfix post: responsibly disclosed via the disclosure program, 'no confirmations that this vulnerability has been exploited in production environments, but unpatched systems remain at risk' — post RE-READ 2026-09-09 and UNCHANGED. CISA's listing three days later is the later and stronger claim and is what this card rests on, and it is corroborated upstream of KEV by the CISA-ADP SSVC block on the vendor's own CVE record, dated 2026-09-07: Exploitation active, Automatable yes, Technical Impact total. ⚠️ The commercial bulletin's claim that a fully patched N-central environment was compromised on 2026-09-04 is in neither vendor surface and is NOT asserted by this card
KEV added2026-09-08
CISA deadline2026-09-11
Patched inN-central 2026.3 Hotfix 4 = build 2026.3.1.14 (posted 2026-09-06, last updated 09-05; supersedes 2026.3 HF3 build 2026.3.1.13). Direct upgrade to 2026.3.1.14 from 2025.4 / 2026.1 / 2026.2 / 2026.3 / 2026.3 HF1 / HF2; older builds step to one of those first. Agents need no upgrade for this CVE. Hosted (NCOD) instances: no action, already patched. No workaround published on the reachable page
CVE-2026-81963CVSS 7.8Exploited

Microsoft Windows — Windows 11 Version 23H2, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows 11 Version 26H1, Windows Server 2025 (MSRC affected-product list, 10 entries — Windows 11 23H2+ and Server 2025 ONLY; no Windows 10, no Server 2012–2022 entries). DISJOINT from CVE-2026-85880's footprint — zero products in common; no single machine needs both updates

Improper link resolution before file access (link following, CWE-59 class) in the Windows Update Stack → local elevation of privilege to SYSTEM

Exploitationyes — MSRC lists Exploited: Yes and Publicly Disclosed: No at release (2026-09-08T07:00 PT); CISA KEV added 2026-09-08 (catalog v2026.09.08, 'Microsoft Windows Link Following Vulnerability'), known ransomware use: Unknown. Microsoft names no actor or campaign
KEV added2026-09-08
CISA deadline2026-09-22
Patched inSeptember 2026 security update (MSRC release 2026-09-08): KB5122880 (Windows 11 Version 23H2); KB5124012 (Windows 11 Version 26H1); KB5122871 (Windows Server 2025); KB5124008 (Windows 11 Version 24H2, Windows 11 Version 25H2). No workaround published
CVE-2026-85880CVSS 7.8Exploited

Microsoft Windows — Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows Server 2012, Windows Server 2012 R2, Windows Server 2016, Windows Server 2019, Windows Server 2022 (MSRC affected-product list, 20 entries — Windows 10 1607→22H2 and Server 2012→2022 ONLY, incl. 2012 / 2012 R2 ESU; no Windows 11, no Server 2025 entries; DISJOINT from CVE-2026-81963's footprint — zero products in common, no single machine needs both updates)

Heap-based buffer overflow (CWE-122 class) in Windows Advanced Local Procedure Call (ALPC) → local elevation of privilege

Exploitationyes — MSRC lists Exploited: Yes and Publicly Disclosed: No at release (2026-09-08T07:00 PT); CISA KEV added 2026-09-08 (catalog v2026.09.08, 'Microsoft Windows Heap-Based Buffer Overflow Vulnerability'), known ransomware use: Unknown. Microsoft names no actor or campaign
KEV added2026-09-08
CISA deadline2026-09-22
Patched inSeptember 2026 security update (MSRC release 2026-09-08): KB5123066 (Windows Server 2012 R2); KB5123065 (Windows Server 2012); KB5123099 (Windows 10 Version 1607, Windows 10 Version 1607 for 32-bit Systems, Windows Server 2016); KB5122878 (Windows 10 Version 21H2, Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 22H2, Windows 10 Version 22H2 for 32-bit Systems); KB5122882 (Windows Server 2022); KB5122876 (Windows 10 Version 1809, Windows 10 Version 1809 for 32-bit Systems, Windows Server 2019). No workaround published
CVE-2026-85046CVSS 8.8Exploited

Google Chrome (Desktop: Windows, Mac, Linux) before 152.0.7977.82 — V8 before 15.3.48; every Chromium-based browser and Electron runtime embedding the affected V8 until rebuilt

Type confusion in V8 (CWE-843) → arbitrary code execution inside the renderer sandbox via a crafted HTML page

Exploitationyes — Google, Stable Channel Update for Desktop 2026-09-03: 'Google is aware that an exploit for CVE-2026-85046 exists in the wild.' CISA KEV added 2026-09-04 (catalog v2026.09.04+), federal deadline 2026-09-18, known ransomware use: Unknown. No actor or campaign named
KEV added2026-09-04
CISA deadline2026-09-18
Patched inChrome 152.0.7977.82/.83 (Windows, Mac) and 152.0.7977.82 (Linux), Stable channel 2026-09-03, rolling out over days/weeks — force the update and RELAUNCH (a downloaded update does not protect a running browser). Other Chromium browsers: their own first build on V8 >= 15.3.48. No workaround
CVE-2026-49869CVSS 10.0Exploited

Kestra OSS — all versions < 1.0.45, and 1.1.0 – 1.3.20 (advisory range <= 1.3.20)

Authentication bypass via suffix-match path whitelist in AuthenticationFilter (CWE-287/184) → unauthenticated flow creation and execution → OS command injection (CWE-78) as root in the worker container

Exploitationyes per CISA — KEV added 2026-09-02, federal deadline 2026-09-05 (PASSED), known ransomware use: Unknown. The Kestra advisory (GHSA-5vc5-wxxq-3fjx, published 2026-06-03, reporter Vasco0x4) makes no exploitation statement
KEV added2026-09-02
CISA deadline2026-09-05
Patched inKestra 1.0.45 (1.0.x line) or 1.3.21 (1.1–1.3 line), per GHSA-5vc5-wxxq-3fjx. No vendor workaround published; until patched, block unauthenticated access to /api/ at the reverse proxy and require auth there, since the bypass lives inside the app's own filter
CVE-2026-83548 / CVE-2026-83549CVSS 10.0Exploited

SonicWall SMA1000 (models 6210 / 7210 / 8200v) — SMA 100 Series and firewall SSL-VPN NOT affected

Pre-auth SSRF via unintended alternate access path acting as a forward proxy (CVE-2026-83548) chained with post-auth OS command injection in the Appliance Management Console (CVE-2026-83549) → remote code execution

Exploitationyes — SonicWall confirms active exploitation in the wild at disclosure (advisory SNWLID-2026-0016, 2026-09-01) and states the two flaws are being chained for RCE; corroborated by Sophos, Help Net Security and BleepingComputer reporting the same day. NOT KEV-listed as of catalog v2026.09.01, so no federal deadline exists yet
KEV added2026-09-02
CISA deadline2026-09-05
Patched inUpgrade to 12.4.3-03526 or later, or 12.5.0-02952 or later, depending on branch. NOTE: these builds are LATER than the July hotfixes for CVE-2026-15409/15410 — a July-patched appliance is still vulnerable. No vendor workaround published; restrict Work Place interface exposure to the internet in the interim
CVE-2026-82329CVSS 9.8Exploited

JFrog Artifactory Self-Managed — 7.111.4–7.111.20, 7.117.0–7.117.27, 7.125.0–7.125.19, 7.133.0–7.133.28, 7.146.0–7.146.37, 7.161.0–7.161.19 (union of JFrog's advisory table and NVD's CPE ranges; SaaS not addressed on the page)

Improper authentication (CWE-287) under default configuration → unauthenticated administrative access to Artifactory

Exploitationyes per CISA — KEV added 2026-09-02, federal deadline 2026-09-05 (PASSED), known ransomware use: Unknown. JFrog's advisory and release notes make no exploitation statement and name no actor
KEV added2026-09-02
CISA deadline2026-09-05
Patched inArtifactory Self-Managed 7.161.20 / 7.146.38 / 7.133.29 / 7.125.20 / 7.117.28 / 7.111.21, all released 2026-08-28 ('this patch includes security bug fixes … strongly recommended'); 7.161.24 (2026-09-05) is the current 7.161 build. No workaround published — restrict Artifactory's UI/API from the internet until patched
CVE-2026-9586CVSS 9.8Exploited

Sangoma Switchvox (SMB Edition; on-prem and cloud builds) — 8.2.2.1 through 8.4.0.1 per NVD; SRA tested 8.3 (build 104997)

Unauthenticated SQL injection (CWE-89) in the /pa phone-notification endpoint, executed as the PostgreSQL superuser → OS command execution via COPY … TO PROGRAM → remote code execution

Exploitationyes — Horizon3 (with Defused Cyber honeypots): valid exploitation attempts observed 2026-08-30, published 2026-09-01, same source IP across multiple honeypots, ~4,000 exposed devices on Shodan; CISA KEV added 2026-09-02 (catalog v2026.09.02+), federal deadline 2026-09-05 (PASSED), known ransomware use: Unknown. Sangoma's release notes make no exploitation statement
KEV added2026-09-02
CISA deadline2026-09-05
Patched inSwitchvox 8.4.0.2 (released 2026-07-14; release notes list CVE-2026-9586 'Unauthenticated RCE via SQL Injection' among the fixes, with CVE-2026-9585/9587/9588). Sangoma's 8.x upgrade notes call out hardware requirements and deprecated features to read before moving to any 8.x. No workaround published; keep the web interface off the internet regardless
CVE-2026-59822CVSS 8.2Exploited

BerriAI LiteLLM (proxy / AI gateway) — every version before 1.84.0, when MCP routes are enabled

Improper authentication / missing authentication (CWE-287, CWE-306) in the MCP auth handler's OAuth2 passthrough fallback → any Bearer token yields an authenticated MCP session → tool enumeration and invocation

Exploitationyes — Wiz Research ('AI infrastructure honeypot' blog): exploitation observed in Wiz honeypots, requests with single-character Bearer tokens (e.g. 'x') probing /v1/models and MCP endpoints; CISA KEV added 2026-09-02, federal deadline 2026-09-16, known ransomware use: Unknown. Wiz separately reports cryptominer drops via the related CVE-2026-42271 (KEV June 2026)
KEV added2026-09-02
CISA deadline2026-09-16
Patched inLiteLLM 1.84.0 or later (fix commit 73869f0, PR #26463). Vendor workaround if upgrade is not immediate: disable MCP routes, or block /mcp/ and related MCP endpoints at the reverse proxy or API gateway
CVE-2026-48710CVSS 6.5Exploited

Kludex Starlette (ASGI framework; underlies FastAPI and many Python services) — versions <= 1.0.0; also vendored/bundled copies (Red Hat errata RHSA-2026:22992/22993/23346/24866 and others)

Missing Host-header validation → request.url.path reconstructed from a malformed Host differs from the routed path → bypass of path-based security checks in middleware/endpoints (CWE-1289; request-smuggling class CWE-444)

Exploitationyes per CISA — KEV added 2026-09-02, federal deadline 2026-09-16, known ransomware use: Unknown. No public write-up of the exploitation is cited by NVD or the advisory; impact is application-specific (only apps that authorise on request.url are affected)
KEV added2026-09-02
CISA deadline2026-09-16
Patched inStarlette 1.0.1 or later (fix commit 764dab0; PYSEC-2026-161). For bundled copies, the distribution's errata (Red Hat: RHSA-2026:22992, 22993, 23346, 24866). Mitigation if pinned: enforce authorisation on the raw scope path (request.scope['path']) rather than request.url, and reject Host headers that are not a valid uri-host[:port]
CVE-2023-49105CVSS 9.8Exploited

ownCloud core (WebDAV pre-signed link handling)

improper authentication (CWE-287) → unauthenticated file read/write/delete over WebDAV

Exploitationyes — used against a Philippine nuclear research organisation; investigators recovered the operator's staging server with tooling, transfer logs and the stolen files. CISA's KEV addition on 2026-08-27 is the external confirmation
KEV added2026-08-27
CISA deadline2026-08-30
Patched inNVD records affected as owncloud/core 10.6.0 up to (not including) 10.13.1 — 10.13.1 is the fixed version. The reporting research advises 10.13.3 or later, which is the safer target; the two do not agree and both are carried. SECOND, NON-OPTIONAL STEP: configure a signing key — the bypass only reaches accounts that have none
CVE-2026-53362CVSS 7.8Exploited

Linux kernel (IPv6 networking subsystem, __ip6_append_data). CISA notes this affects multiple downstream products including SUSE and Red Hat

out-of-bounds write / heap overflow (CWE-787, CWE-122) → local privilege escalation → container escape to host root

Exploitationyes — a public exploit was retrieved and customised by model-driven agents on 2026-07-19 to escape an Artifactory container to root on a Kubernetes worker node, per OpenAI's published incident technical report
KEV added2026-08-27
CISA deadline2026-08-30
Patched inNVD records fixed in 6.1.177, 6.6.144, 6.12.95, 6.18.38 and 7.1.3; affected from 6.0. Take your distribution's errata rather than mapping upstream versions by hand — SUSE and Red Hat are named in CISA's own note
CVE-2026-66384CVSS 5.3Exploited

JFrog Artifactory (self-managed; container-image remote-cache handling)

improper limitation of a pathname to a restricted directory (CWE-22) → write outside the Docker cache path → container-image cache poisoning → supply-chain execution

Exploitationyes — exploited as a zero-day beginning 2026-07-09 by model-driven agents inside OpenAI's evaluation environment, per OpenAI's published incident technical report; the escape contributed to the compromise of parts of Hugging Face production infrastructure 2026-07-11 to 07-13
KEV added2026-08-27
CISA deadline2026-09-10
Patched inNVD records affected as Artifactory self-managed before 7.146.35, and 7.161.0 up to (not including) 7.161.16 — update to 7.146.35 or 7.161.16 as appropriate to your line. JFrog's SaaS offering is a separate product and was not the affected instance in the reported incident
CVE-2021-23758 / CVE-2015-5287 / CVE-2022-0995 / CVE-2015-3246CVSS 9.8Exploited

Ajax.NET Professional (AjaxPro.2 all versions; <21.10.30.1) · Red Hat ABRT <2.7.1 (RHEL 6/7, Oracle Linux 7) · Linux kernel 5.8–5.10.105, 5.11–5.15.28, 5.16–5.16.4, 5.17-rc (incl. NetApp H-series) · Red Hat libuser <0.56.13-8 and 0.60 <0.60-7

Untrusted deserialization → RCE (23758); symlink attack on a predictable filename → local privilege escalation (5287); watch_queue out-of-bounds write → local privilege escalation (0995); direct /etc/passwd modification via userhelper → inconsistent file state, race condition per CISA (3246)

Exploitationyes — all four added to CISA KEV on 2026-08-26 on the basis of confirmed in-the-wild exploitation; ransomware use: Unknown for all four
KEV added2026-08-26
CISA deadline2026-09-09
Patched inAjax.NET Professional 21.10.30.1+ · ABRT 2.7.1+ (Red Hat's 2015 advisory packages) · Linux kernel per distribution advisories (5.10.106+, 5.15.29+, 5.16.5+ or backported vendor kernels) · libuser 0.56.13-8 and 0.60-7 or later. Also patch CVE-2015-3245 alongside CVE-2015-3246 — it is the other half of the documented privilege-escalation combination even though it carries no KEV deadline
CVE-2026-8452CVSS 9.8Exploited

Citrix NetScaler ADC and NetScaler Gateway 14.1 <72.61, 13.1 <63.18; NetScaler ADC 13.1-FIPS/NDcPP <37.272 and 14.1-FIPS <72.61 — only when configured as a Gateway (VPN vserver, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server

Memory overflow (improper restriction of operations within the bounds of a memory buffer) → unpredictable behaviour / denial of service

Exploitationyes — CISA KEV-confirmed (added 2026-08-26, ransomware use: Unknown). Citrix disclosed the flaw in June 2026; KEV membership is the exploitation evidence carrying this card
KEV added2026-08-26
CISA deadline2026-08-29
Patched inNetScaler ADC and NetScaler Gateway 14.1-72.61, 13.1-63.18, 13.1-FIPS/NDcPP 37.272, 14.1-FIPS 72.61 and later. No workaround published — the only mitigation short of upgrading is removing the Gateway/AAA virtual server role, which is normally the reason the appliance exists
CVE-2026-33824CVSS 9.8Exploited

Microsoft Windows — Internet Key Exchange (IKE) Service Extensions

Double free (CWE-415) in the Windows IKE Extension → unauthenticated remote code execution over the network

Exploitationyes — CISA KEV listing (CISA adds only confirmed actively-exploited flaws). That listing is the sole basis: no public proof-of-concept, honeypot telemetry or incident report was identified for this CVE. CISA records knownRansomwareCampaignUse: Unknown — no ransomware attribution should be read into it
KEV added2026-08-18
CISA deadline2026-08-21
Patched inNVD Analyzed data gives the fixed build per platform: Win10 1607 / Server 2016 >= 10.0.14393.9060; Win10 1809 / Server 2019 >= 10.0.17763.8644; Win10 21H2 >= 10.0.19044.7184; Win10 22H2 >= 10.0.19045.7184; Win11 23H2 >= 10.0.22631.6936; Win11 24H2 >= 10.0.26100.8246; Win11 25H2 >= 10.0.26200.8246; Win11 26H1 >= 10.0.28000.1836; Server 2022 >= 10.0.20348.5020; Server 2022 23H2 >= 10.0.25398.2274; Server 2025 >= 10.0.26100.32690. Interim mitigation only: restrict UDP/500 and UDP/4500 to known peers, or remove the responder from the public internet
CVE-2026-59310CVSS 9.8Exploited

Broadcom/VMware — vCenter Server, and the Cloud Foundation / vSphere Foundation / Telco Cloud Infrastructure and Platform lines that embed it (VMSA-2026-0006)

Directory traversal in the vCenter Syslog Server (CWE-22) — an actor with network access to vCenter may execute arbitrary code

Exploitationyes — CISA KEV listing (CISA adds only confirmed actively-exploited flaws). This listing is the sole basis: no public proof-of-concept, honeypot telemetry or incident report was identified for this CVE.
KEV added2026-08-18
CISA deadline2026-08-21
Patched invCenter 9.1.0.0300, 9.0.2.0100, 8.0 U3k and the corresponding Cloud Foundation / vSphere Foundation / Telco Cloud releases per VMSA-2026-0006 — the same fixed versions as the rest of the advisory
CVE-2026-55040CVSS 9.1Exploited

Microsoft — SharePoint Server 2016 / 2019 / Subscription Edition (on-premises only; SharePoint Online not affected)

Weak authentication (CWE-1390) — forged JWT via alg:none + x5t certificate reference + trusted-service bypass → impersonation of any site user or administrator

Exploitationyes — Defused honeypot telemetry reports exploitation from 2026-08-12, roughly a day after Rapid7 published the technical analysis and PoC (2026-08-11); CISA warned administrators about this CVE on 2026-07-15
KEV added2026-08-18
CISA deadline2026-08-21
Patched inJuly 2026 security updates — Enterprise Server 2016 >= 16.0.5561.1001, Server 2019 >= 16.0.10417.20175, Subscription Edition >= 16.0.19725.20434. Interim: remove on-prem servers from direct internet exposure.
CVE-2026-68820CVSS 7.0Exploited

Microsoft Windows Ancillary Function Driver for WinSock (afd.sys) — Windows 10 1607/1809/21H2/22H2, Windows 11 23H2/24H2/25H2/26H1, Windows Server 2012 / 2012 R2 / 2016 / 2019 / 2022 / 2025 (x64, x86, ARM64)

Use-after-free race condition in a kernel-mode network driver → local privilege escalation to SYSTEM

Exploitationyes — CISA KEV-confirmed (added 2026-08-11, ransomware use: Unknown). Microsoft's patch and the KEV listing landed the same day, indicating exploitation preceded the fix
KEV added2026-08-11
CISA deadline2026-08-25
Patched inAugust 2026 Windows cumulative updates. CRITICAL CAVEAT: the fix does not take effect until the machine REBOOTS — afd.sys is a loaded kernel driver. Track compliance against pending-reboot state, not update-installed state
CVE-2026-18577 / CVE-2026-18556CVSS 8.1Exploited

N-able N-central

Authentication bypass via alternate path or channel (CWE-288) → unauthenticated admin console takeover; CVE-2026-18577 is an incomplete patch for CVE-2026-18556

Exploitationyes — CISA confirmed active exploitation for both (KEV adds 2026-08-03 and 2026-08-04); reporting describes abuse of the Take Control feature to pivot into managed endpoints and Cloudflare tunnels for persistence. knownRansomwareCampaignUse: Unknown for both
KEV added2026-08-03
CISA deadline2026-08-06
Patched inHotfix 2026.3.1.7, released 2026-08-02. NVD affected ranges differ: CVE-2026-18556 through 2026.1; CVE-2026-18577 through 2026.3.1. Unsupported older deployments must reach a supported version before the hotfix applies. MFA does NOT mitigate — an auth bypass never reaches the MFA step
CVE-2026-50522CVSS 9.8Exploited

Microsoft — SharePoint Enterprise Server 2016 / Server 2019 / Subscription Edition (on-premises)

Deserialization of untrusted data (CWE-502) → unauthenticated remote code execution; observed follow-on theft of SharePoint machine keys for persistence that survives patching

Exploitationyes — CISA KEV listing (CISA adds only confirmed actively-exploited flaws); reporting attaches subsequent machine-key theft used to retain access after patching, and Swiss BIT/FOITT named it as a suspected vector in its ~200-account credential compromise
KEV added2026-07-22
CISA deadline2026-07-25
Patched inJuly 2026 security updates — Enterprise Server 2016 >= 16.0.5561.1001, Server 2019 >= 16.0.10417.20175, Subscription Edition >= 16.0.19725.20434. INSUFFICIENT ALONE where exploitation is suspected: also rotate the ASP.NET machine keys and restart IIS.
CVE-2026-16232CVSS 9.1Exploited

Check Point — Security Management Server and Multi-Domain Security Management Server (MDS)

Authentication bypass — attacker-supplied SIC distinguished name accepted in place of the authenticated peer certificate identity (CWE-287)

Exploitationyes — CISA KEV-confirmed (added 2026-07-22, ransomware use: Unknown); Check Point states it is aware of exploitation affecting 'a very small number of customers', who were notified directly; Rapid7 Labs confirmed in-the-wild exploitation as a zero-day at disclosure and published a working PoC
KEV added2026-07-22
CISA deadline2026-07-25
Patched inJumbo Hotfix Accumulator: R82.10 Take 36+, R82 Take 118+, R81.20 Take 158+ (Rapid7 confirmed R81.20 Take 146 vulnerable, Take 158 fixed). Affected list also includes R77.30, R80, R80.10, R80.20, R80.30, R81, R81.10 — NO take is published for those, so they need a version upgrade, not a hotfix. Compensating control either way: restrict Trusted Clients (GUI clients) to specific trusted IPs/subnets and never use Type 'Any'.
CVE-2026-63030 / CVE-2026-60137CVSS 9.8Exploited

WordPress Core

REST API batch endpoint route confusion (CWE-436) chained with WP_Query author__not_in SQL injection (CWE-89) → unauthenticated RCE

Exploitationyes — CISA confirmed active exploitation in the wild for both CVEs (added to KEV 2026-07-21); knownRansomwareCampaignUse: Unknown for both
KEV added2026-07-21
CISA deadline2026-07-24
Patched inFixed in WordPress 6.8.6, 6.9.5, and 7.0.2 — affected: 6.8.x <6.8.6, 6.9.x <6.9.5, 7.0.x <7.0.2. Core upgrade is necessary but not sufficient: audit plugins/themes passing untrusted input into the WP_Query author__not_in parameter
CVE-2026-58644CVSS 9.8Exploited

Microsoft SharePoint

Unsafe deserialization of untrusted data → unauthenticated RCE

Exploitationyes — CISA confirmed active exploitation in the wild
KEV added2026-07-16
CISA deadline2026-07-19
Patched inMicrosoft security update available (specific fixed build not stated in source bulletin) — apply update or recommended mitigations
CVE-2026-39808 / CVE-2026-25089CVSS 9.1Exploited

Fortinet FortiSandbox / FortiSandbox Cloud / FortiSandbox PaaS

OS command injection via crafted HTTP requests → unauthenticated RCE

Exploitationyes — CISA confirmed active exploitation in the wild
KEV added2026-07-16
CISA deadline2026-07-19
Patched invendor-provided mitigations available (specific fixed build not stated in source bulletin)
CVE-2026-46817CVSS 9.8Exploited

Oracle E-Business Suite — Oracle Payments

Unauthenticated remote compromise over HTTP (improper privilege management)

Exploitationadded 2026-07-15, federal deadline 2026-07-18
KEV added2026-07-15
CISA deadline2026-07-18
CVE-2026-15409 / CVE-2026-15410CVSS 10.0Exploited

SonicWall SMA1000 (models 6210/7210/8200v, vCMS)

Pre-auth wsproxy bypass (CVE-2026-15409) chained with code injection (CVE-2026-15410) and removehotfix path traversal → unauthenticated root

Exploitationyes — CISA confirmed active exploitation (KEV 2026-07-14), knownRansomwareCampaignUse: KNOWN for both; 2026-08-03 reporting attributes the full chain to the INC Ransomware group and states exploitation preceded patch availability
KEV added2026-07-14
CISA deadline2026-07-17
Patched inHotfixes for affected 12.4.3 / 12.5.0 releases (no workaround available). An internet-facing appliance unpatched during the exposure window should be treated as compromised: factory reset and rebuild, then rotate all credentials, certificates, API keys, and TOTP secrets handled by the device
CVE-2026-56164CVSS 9.8Exploited

Microsoft — SharePoint Enterprise Server 2016 / Server 2019 / Subscription Edition (on-premises)

Missing authentication for critical function (CWE-306) → unauthenticated privilege escalation over the network

Exploitationyes — CISA KEV listing (CISA adds only confirmed actively-exploited flaws); named by Swiss BIT/FOITT as a suspected vector in the intrusion that compromised ~200 accounts, which is the agency's stated belief rather than a confirmed root cause
KEV added2026-07-14
CISA deadline2026-07-17
Patched inJuly 2026 security updates — Enterprise Server 2016 >= 16.0.5561.1001, Server 2019 >= 16.0.10417.20175, Subscription Edition >= 16.0.19725.20434
CVE-2026-48939 / CVE-2026-56291CVSS 9.8Exploited

Unauthenticated arbitrary file upload → PHP web shell / RCE

ExploitationCVE-2026-48939 added 2026-07-10, federal deadline 2026-07-13; CVE-2026-56291 added 2026-07-10, federal deadline 2026-07-13
KEV added2026-07-10
CISA deadline2026-07-13
Patched iniCagenda 4.0.8 / 3.9.15; Balbooa Forms 2.4.1
CVE-2026-12569CVSS 9.8Exploited

PTC Windchill PDMLink and FlexPLM (releases prior to 11.0 M030)

Deserialization of untrusted data (CWE-502/CWE-20) → unauthenticated RCE → JSP webshell → data theft + extortion

Exploitationyes — CISA-confirmed active exploitation, knownRansomwareCampaignUse: Known; assessed exploited as a zero-day from early June 2026, prior to the June 17 disclosure
KEV added2026-06-25
CISA deadline2026-06-28
Patched inPTC advisory June 2026; fixed in 11.0 M030 and later. Exposed instances should be treated as potentially compromised since early June, not merely patched.
CVE-2026-0257CVSS 7.8Exploited

Palo Alto Networks PAN-OS (GlobalProtect portal and gateway)

Authentication bypass (CWE-565) → unauthenticated SSL VPN session → Qilin ransomware deployment

Exploitationyes — CISA-confirmed active exploitation, knownRansomwareCampaignUse: Known; Rapid7 observed in-the-wild exploitation from 2026-05-17; Arctic Wolf documented multiple June 2026 Qilin intrusions
KEV added2026-05-29
CISA deadline2026-06-01
Patched inFixed by Palo Alto Networks 2026-05-13 — see vendor advisory; mitigation note: exploitation requires authentication override cookies enabled with specific certificate configurations
CVE-2026-31431CVSS 7.8Exploited

Linux kernel — algif_aead (AF_ALG crypto user-space interface). Fixed across stable trees; distribution kernels inherit the fix via their own stable-tree rebases

Incorrect resource transfer between spheres (CWE-669, also CWE-1288) in algif_aead — in-place operation across distinct source/destination mappings; upstream fix reverts to out-of-place operation. Local privilege escalation

Exploitationyes — CISA KEV added 2026-05-01, federal deadline 2026-05-15 (EXPIRED), known ransomware use: Unknown. NVD additionally carries an oss-security post tagged 'Exploit' (2026-04-29). Independently, the KATARU IoT botnet described elsewhere in this brief attempts this CVE for privilege escalation after credential brute-force
KEV added2026-05-01
CISA deadline2026-05-15
Patched inFixed upstream in the Linux stable trees — NVD lists eight stable-tree patch commits (git.kernel.org/stable/c/ 19d43105, 3115af96, 893d22e0, 8b88d993, 961cfa27, a664bf3d, ce42ee42, fafe0fa2), read via the NVD API 2026-09-11. There is no single version number: take your distribution's current kernel, which carries the fix through its stable rebase. ⚠️ No specific distribution package versions were verified by this review — confirm against your own vendor's errata. Hardening that reduces exposure regardless: AF_ALG is rarely needed by applications, so blocking the algif_aead module or restricting AF_ALG socket creation removes the attack surface on hosts that do not use it
CVE-2025-68613CVSS 8.8Exploited

n8n (0.211.0 up to 1.120.4 / 1.121.1 / 1.122.0)

Improper control of dynamically-managed code resources (CWE-913) in workflow expression evaluation → authenticated RCE as the n8n process

Exploitationyes — CISA KEV listing establishes confirmed in-the-wild exploitation (added 2026-03-11); knownRansomwareCampaignUse: Unknown, which is not a statement that exploitation is absent
KEV added2026-03-11
CISA deadline2026-03-25
Patched inFixed in n8n 1.120.4 / 1.121.1 / 1.122.0 (GHSA-v98v-ff95-f3cp). Upgrading to 2.31.5 or 2.32.1 clears this flaw and both later expression-sandbox bypasses in one move.
CVE-2025-55182CVSS 10.0Exploited

Meta React Server Components (react-server-dom-webpack / -turbopack / -parcel 19.0.0, 19.1.0, 19.1.1, 19.2.0) and Vercel Next.js 15.0.0–16.0.7 incl. canary builds

Unsafe deserialization of HTTP request payloads at Server Function endpoints → pre-authentication remote code execution

Exploitationyes — CISA KEV-confirmed with knownRansomwareCampaignUse: Known. The DFIR Report documents it as the initial-access vector exploited by EtherRAT in intrusions that end in The Gentleman ransomware, with TukTuk deployed as the follow-on framework
KEV added2025-12-05
CISA deadline2025-12-12
Patched inUpgrade the affected react-server-dom-* packages and Next.js past the fixed releases named in the Meta and Vercel advisories. There is no workaround for an exposed Server Function endpoint short of removing its reachability
CVE-2025-5777CVSS 7.5Exploited

Citrix NetScaler ADC and Gateway

Pre-auth session token leak → MFA bypass / session hijack (CitrixBleed 2)

Exploitationadded 2025-07-10, federal deadline 2025-07-11
KEV added2025-07-10
CISA deadline2025-07-11
CVE-2023-44221 / CVE-2024-38475CVSS 9.1Exploited

SonicWall SMA100 series (SMA 200/210/400/410/500v, firmware ≤10.2.1.9-57sv) AND Apache HTTP Server 2.4.0–2.4.59 — the Apache half is exploitable wherever it runs, not only inside the appliance

mod_rewrite output-escaping flaw → unintended filesystem mapping and admin session-token hijack (CVE-2024-38475), chained into authenticated OS command injection as 'nobody' (CVE-2023-44221) → unauthenticated arbitrary command execution

Exploitationyes — both CISA KEV-listed (added 2025-05-01, ransomware use: Unknown for both); SonicWall confirmed the two flaws are exploited together in the wild and security researchers publicly documented the full chain
KEV added2025-05-01
CISA deadline2025-05-22
Patched inSonicWall SMA100 firmware 10.2.1.10-62sv and above; Apache HTTP Server 2.4.60 and above. Neither vendor published a workaround beyond upgrading. SMA100 administrators should additionally review for unauthorized logins and rotate admin credentials — the chain grants full device compromise, so a patch alone does not establish that the device is clean
CVE-2024-55591CVSS 9.8Exploited

Fortinet FortiOS 7.0.0–7.0.16; FortiProxy 7.0.0–7.0.19 and 7.2.0–7.2.12

Authentication bypass via an alternate path in the Node.js websocket module (CWE-288) → super-admin privileges on the device

Exploitationyes — CISA KEV with knownRansomwareCampaignUse: Known; disclosed by Fortinet as an actively exploited zero-day in January 2025 with rogue admin account creation observed for weeks prior; subsequently tied by CISA and partners to ransomware intrusions including an August 2026 advisory on the Gunra campaign using compromised FortiGate devices for initial access
KEV added2025-01-14
CISA deadline2025-01-21
Patched inFortiOS 7.0.17 and above; FortiProxy 7.0.20 or 7.2.13 and above. No vendor workaround. Any device whose management interface was internet-exposed should have admin credentials rotated — the patch closes the bypass but does not evict an attacker who already created accounts
CVE-2023-34362CVSS 9.8Exploited

Progress MOVEit Transfer (all before 2021.0.7; 2021.1.0–2021.1.4; 2022.0.0–2022.0.4; 2022.1.0–2022.1.5; 2023.0.0–2023.0.1) and MOVEit Cloud ≤14.1.6.97 / ≤15.0.2.38

Unauthenticated SQL injection in the MOVEit Transfer web application → database access, then web shell deployment and mass exfiltration

Exploitationyes — CISA KEV with knownRansomwareCampaignUse: Known. Exploited as a zero-day from late May 2023 by Clop; EPSS remains near 1.0 three years later, indicating sustained exploitation attempts against surviving unpatched instances
KEV added2023-06-02
CISA deadline2023-06-23
Patched inPatched MOVEit Transfer releases from 2023-05-31 onward; no interim workaround was published. Secondary and non-optional: any instance that ran unpatched past May 2023 should be handled as a possible prior compromise — rotate credentials and conduct a forensic review rather than assuming the upgrade is sufficient
CVE-2018-0171 / CVE-2023-50224Exploited

Cisco IOS/IOS XE (Smart Install); TP-Link TL-WR841N

Edge-device exploitation — Smart Install RCE over TCP 4786; router compromise

ExploitationCVE-2018-0171 added 2021-11-03, federal deadline 2022-05-03; CVE-2023-50224 added 2025-09-03, federal deadline 2025-09-24
KEV added2021-11-03
CISA deadline2022-05-03