Known exploited vulnerabilities
50The CISA Known Exploited Vulnerabilities catalogue, synced several times a day. These are being exploited in the wild right now.
| CVE | Vendor | Product | Added | Due |
|---|---|---|---|---|
| CVE-2026-76461Cisco Secure Email Gateway SQL Injection Vulnerability | Cisco | Secure Email Gateway | 2026-09-14 | 2026-09-17 |
| CVE-2026-85706GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability | GitLab | Community Edition and Enterprise Edition | 2026-09-11 | 2026-09-14 |
| CVE-2026-84869ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability | ConnectWise | ScreenConnect | 2026-09-11 | 2026-09-14 |
| CVE-2026-42018JFrog Artifactory Improper Authentication Vulnerability | JFrog | Artifactory | 2026-09-11 | 2026-09-25 |
| CVE-2026-42016JFrog Artifactory Incorrect Authorization Vulnerability | JFrog | Artifactory | 2026-09-11 | 2026-09-25 |
| CVE-2026-86060MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability | MikroTik | RouterOS | 2026-09-10 | 2026-09-13 |
| CVE-2026-67277MikroTik RouterOS Missing Authentication for Critical Function Vulnerability | MikroTik | RouterOS | 2026-09-10 | 2026-09-13 |
| CVE-2026-87491Google Chromium V8 Out of Bounds Write Vulnerability | Chromium V8 | 2026-09-09 | 2026-09-23 | |
| CVE-2026-20079Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability | Cisco | Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management | 2026-09-09 | 2026-09-12 |
| CVE-2026-19490Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability | Citrix | NetScaler | 2026-09-09 | 2026-09-12 |
| CVE-2025-25249Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability | Fortinet | Multiple Products | 2026-09-09 | 2026-09-12 |
| CVE-2026-86218N-able N-central Static Code Injection Vulnerability | N-able | N-central | 2026-09-08 | 2026-09-11 |
| CVE-2026-85880Microsoft Windows Heap-Based Buffer Overflow Vulnerability | Microsoft | Windows | 2026-09-08 | 2026-09-22 |
| CVE-2026-81963Microsoft Windows Link Following Vulnerability | Microsoft | Windows | 2026-09-08 | 2026-09-22 |
| CVE-2026-75650Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability | Adobe | Commerce and Magento | 2026-09-08 | 2026-09-11 |
| CVE-2026-85046Google Chromium V8 Type Confusion Vulnerability | Chromium V8 | 2026-09-04 | 2026-09-18 | |
| CVE-2026-9586Sangoma Switchvox SQL Injection Vulnerability | Sangoma | Switchvox | 2026-09-02 | 2026-09-05 |
| CVE-2026-83549SonicWall SMA1000 Appliances OS Command Injection Vulnerability | SonicWall | SMA1000 Appliances | 2026-09-02 | 2026-09-05 |
| CVE-2026-83548SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability | SonicWall | SMA1000 Appliances | 2026-09-02 | 2026-09-05 |
| CVE-2026-82329JFrog Artifactory Improper Authentication Vulnerability | JFrog | Artifactory | 2026-09-02 | 2026-09-05 |
| CVE-2026-59822BerriAI LiteLLM Improper Authentication Vulnerability | BerriAI | LiteLLM | 2026-09-02 | 2026-09-16 |
| CVE-2026-49869Kestra OSS OS Command Injection Vulnerability | Kestra | Kestra OSS | 2026-09-02 | 2026-09-05 |
| CVE-2026-48710Kludex Starlette HTTP Request/Response Smuggling Vulnerability | Kludex | Starlette | 2026-09-02 | 2026-09-16 |
| CVE-2026-82078PaperCut NG/MF Unsafe Reflection Vulnerability | PaperCut | NG/MF | 2026-08-31 | 2026-09-14 |
| CVE-2026-81578PaperCut NG/MF Missing Authentication for Critical Function Vulnerability | PaperCut | NG/MF | 2026-08-31 | 2026-09-14 |
| CVE-2026-66384JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability | JFrog | Artifactory | 2026-08-27 | 2026-09-10 |
| CVE-2026-53362Linux Kernel Unspecified Vulnerability | Linux | Kernel | 2026-08-27 | 2026-08-30 |
| CVE-2023-49105ownCloud Improper Authentication Vulnerability | ownCloud | ownCloud | 2026-08-27 | 2026-08-30 |
| CVE-2026-8452Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability | Citrix | NetScaler ADC and NetScaler Gateway | 2026-08-26 | 2026-08-29 |
| CVE-2022-0995Linux Kernel Out-of-Bounds Write Vulnerability | Linux | Kernel | 2026-08-26 | 2026-09-09 |
| CVE-2021-23758Ajax.NET Professional Deserialization of Untrusted Data Vulnerability | Ajax.NET Professional | Ajax.NET Professional | 2026-08-26 | 2026-09-09 |
| CVE-2019-1068Microsoft SQL Server Remote Code Execution Vulnerability | Microsoft | SQL Server | 2026-08-26 | 2026-08-29 |
| CVE-2015-5287Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability | Red Hat | Automatic Bug Reporting Tool | 2026-08-26 | 2026-09-09 |
| CVE-2015-3246Red Hat Libuser Race Condition Vulnerability | Red Hat | Libuser | 2026-08-26 | 2026-09-09 |
| CVE-2026-60004Gitea Code Injection Vulnerability | Gitea | Gitea | 2026-08-25 | 2026-08-28 |
| CVE-2026-21962Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability | Oracle | HTTP Server and Oracle Weblogic Server Proxy Plug-in | 2026-08-24 | 2026-08-27 |
| CVE-2026-73570Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability | Synacor | Zimbra Collaboration Suite (ZCS) | 2026-08-21 | 2026-08-24 |
| CVE-2026-72530TrueConf Server Code Injection Vulnerability | TrueConf | Server | 2026-08-20 | 2026-09-03 |
| CVE-2026-72529TrueConf Server Missing Authentication for Critical Function Vulnerability | TrueConf | Server | 2026-08-20 | 2026-08-23 |
| CVE-2026-64849MLflow Server-Side Request Forgery Vulnerability | MLflow | MLflow | 2026-08-19 | 2026-09-02 |
| CVE-2026-65400Apple macOS Improper Authentication Vulnerability | Apple | macOS | 2026-08-18 | 2026-08-21 |
| CVE-2026-59310[ransomware]Broadcom VMware vCenter Path Traversal Vulnerability | Broadcom | VMware vCenter | 2026-08-18 | 2026-08-21 |
| CVE-2026-55040Microsoft SharePoint Weak Authentication Vulnerability | Microsoft | SharePoint | 2026-08-18 | 2026-08-21 |
| CVE-2026-33824Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability | Microsoft | Internet Key Exchange (IKE) Service Extensions | 2026-08-18 | 2026-08-21 |
| CVE-2025-62593Ray-Project Ray Code Injection Vulnerability | Ray-Project | Ray | 2026-08-17 | 2026-08-20 |
| CVE-2026-72898Metabase SQL Injection Vulnerability | Metabase | Metabase | 2026-08-11 | 2026-08-14 |
| CVE-2026-68820Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability | Microsoft | Windows Ancillary Function Driver for WinSock | 2026-08-11 | 2026-08-25 |
| CVE-2026-20349Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability | Cisco | Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) | 2026-08-11 | 2026-08-14 |
| CVE-2026-8037Progress LoadMaster Command Injection Vulnerability | Progress | LoadMaster | 2026-08-07 | 2026-08-10 |
| CVE-2026-63077JetBrains TeamCity Deserialization of Untrusted Data Vulnerability | JetBrains | TeamCity | 2026-08-05 | 2026-08-08 |
Source: CISA. Each row links to the NVD entry.
This is what cymesh.net is for
Certificate and hostname problems are the ones you find out about from your users. cymesh.net finds them first.
monitorsTLS/SSL expiry, chain and hostnamealertsemail, ahead of the expiry datescopenon-intrusive, read-only checks