Active-Exploitation
MikroTrick: Chained MikroTik RouterOS SSH Bugs Give Unauthenticated Root, 122,500 Devices Exposed
CERT Polska's MikroTrick chain (CVE-2026-67276 + CVE-2026-86060) lets attackers bypass SSH authentication and escalate to full admin on MikroTik RouterOS — exploited in the wild since September 2, before patches shipped.
StyleSmuggler: Unpatched Magento/Adobe Commerce Zero-Day Gives Unauthenticated RCE, No Fix Yet
Sansec disclosed StyleSmuggler, an unauthenticated remote code execution chain hitting all current Magento and Adobe Commerce builds, under active attack since September 4 with no CVE and no patch.
CVE-2026-9586: Unauthenticated SQLi-to-RCE in Sangoma Switchvox Under Active Exploitation
An unauthenticated SQL injection in Sangoma Switchvox's phone-provisioning endpoint escalates to root command execution and is now being used in the wild to plant reverse shells on internet-exposed VoIP servers.
CVE-2026-49869: Kestra OSS Auth-Bypass Lets Unauthenticated Attackers Get Root RCE, CISA Sets Today as Federal Deadline
A suffix-match flaw in Kestra OSS's AuthenticationFilter lets anyone skip Basic Auth entirely and reach unauthenticated remote code execution as root, CVSS 10.0, now on CISA's KEV list.
FalconFlank: Unpatched Local Privilege Escalation Zero-Day in CrowdStrike Falcon Sensor, PoC Public
A public PoC dubbed FalconFlank abuses CrowdStrike Falcon Sensor's malicious-macro remediation to escalate a local user to SYSTEM on fully patched Windows 11 and Server 2025. No CVE, no vendor fix yet — only a workaround.
CVE-2026-83548 & CVE-2026-83549: SonicWall SMA1000 Hit by Third Zero-Day Chain of 2026, CVSS 10.0 SSRF to Root RCE
SonicWall SMA1000 appliances are under active exploitation via a chained SSRF and OS command injection pair, CVE-2026-83548 and CVE-2026-83549, the product line's third zero-day incident this year.
CVE-2026-82329: Critical JFrog Artifactory Auth Bypass Under Active Exploitation for Admin Tokens
Attackers are exploiting CVE-2026-82329, a CVSS 9.8 authentication bypass in JFrog Artifactory, to mint themselves administrator tokens and enumerate credentials on internet-facing build-artifact repositories.
CVE-2026-0768: Unauthenticated Root RCE in Langflow's Validate Endpoint Under Mass Exploitation
CVE-2026-0768, an unauthenticated code-injection RCE in Langflow's custom component validator, is under active mass exploitation — VulnCheck honeypots logged 360 attacks since August 29 hunting for AWS and OpenAI keys.
CVE-2026-8452: 'DoS-Only' NetScaler Flaw Turns Out to Be Pre-Auth Root RCE, Now Under Active Exploitation
watchTowr Labs turned a Citrix NetScaler bug Citrix rated as a crash-only memory overflow into pre-auth root code execution; CISA confirms in-the-wild exploitation with web shells on unpatched appliances.
PaperCut Ships Emergency Out-of-Cycle Build After Zero-Day Hits Every Supported NG/MF Version
PaperCut confirmed active zero-day exploitation of an unpatched flaw affecting every currently supported PaperCut NG/MF release and shipped emergency out-of-cycle builds hours after a university's forensics team caught it in the wild.
CISA, NSA, FBI Warn of AI-Generated Exploit Scripts Targeting Siemens S7 PLCs
A joint advisory from NSA, CISA, FBI, DOE, and EPA warns that threat actors are pairing AI-assisted scripting with snap7 libraries to build custom reconnaissance and exploitation tools against internet-exposed Siemens S7 PLCs.
CVE-2026-60004: Gitea diffpatch Code Injection Now Under Active Exploitation, Added to CISA KEV
A critical Gitea flaw lets any repository writer install a malicious Git hook via the diffpatch endpoint and run shell commands as the Gitea OS user. CISA confirms in-the-wild exploitation and gave federal agencies until August 28 to patch.
CVE-2026-21962: Max-Severity Oracle HTTP Server / WebLogic Proxy Flaw Added to CISA KEV After Months of Exploitation
CISA added CVE-2026-21962, a CVSS 10.0 auth-bypass and path-traversal flaw in Oracle HTTP Server and the WebLogic Server Proxy Plug-in, to its KEV catalog on August 24 — seven months after Oracle patched it and after mass automated scanning had already begun.
CVE-2026-69836: Perfect-10 Entra ID Deserialization RCE Exploited in the Wild
Microsoft confirms in-the-wild exploitation of CVE-2026-69836, a maximum-severity unauthenticated deserialization RCE in Entra ID's backend — already patched server-side, but the identity plane behind Microsoft 365 and Azure was exposed with no customer visibility into the attack.
CVE-2026-73570: Unauthenticated Zimbra RCE via SNMP Notifications Under Active Exploitation
CERT Polska confirms in-the-wild exploitation of CVE-2026-73570, an unauthenticated OS command injection in Zimbra Collaboration's SNMP notification handling — patched in 10.1.20, but plenty of mail servers haven't updated.
Unauthenticated MLflow Webhook SSRF (CVE-2026-64849) Exploited Within Hours to Steal Cloud Credentials
An unauthenticated SSRF in MLflow's webhook-test endpoint, CVE-2026-64849, lets attackers bypass an existing SSRF guard via HTTP redirects to reach cloud metadata services — and exploitation began within hours of the CVE going public.
CVE-2026-19490: Critical NetScaler Auth Bypass Lets Attackers Skip the Login Screen Entirely
A critical CVSS 9.3 authentication bypass in Citrix NetScaler ADC and Gateway lets unauthenticated attackers reach protected resources behind SSL VPN, ICA Proxy, and AAA virtual servers — patch CTX696939 now.
CVE-2026-65400: macOS Screen Sharing Auth Bypass Exploited for Root Access, Added to CISA KEV
CISA added CVE-2026-65400, a pre-auth bypass in macOS Screen Sharing, to its KEV catalog after attackers used it to gain root on internet-exposed Macs and drop Monero miners; CVSS was raised to 9.8 following public PoC release.
CVE-2025-62593: Browser-Based DNS Rebinding RCE in Ray Added to CISA KEV Amid ShadowRay 2.0 Exploitation
CISA has added CVE-2025-62593, a critical DNS-rebinding RCE in the Ray AI compute framework, to its KEV catalog after RondoDox botnet operators weaponized it and ShadowRay 2.0 continued hijacking exposed clusters for GPU cryptomining.
SharePoint JWT Bypass (CVE-2026-55040) Chains With BCS Gadget Chain (CVE-2026-63520) for Unauthenticated RCE
A JWT validation bypass under active exploitation since mid-August now chains with a newly disclosed Business Connectivity Services gadget chain, giving unauthenticated attackers full RCE on on-prem SharePoint farms.