Vulnerability of the week
Week of Oct 5, 2026 · exploited since Oct 8
ProFTPD
CVE-2015-3306 · CVSS 10.0 critical
Attackers can read and write any file on the server.
My take
This bug is from 2015 and it just made the "actively exploited" list. Someone out there is still running that old FTP server, and attackers found it
- Does anyone still need FTP in 2026?
Show the official descriptionHide the official description
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.
Week of Sep 28, 2026 · exploited since Sep 30
Cisco Catalyst SD-WAN Manager
CVE-2026-76504 · CVSS 9.8 critical
Attackers skip the login and get admin.
My take
No password needed, and you're admin on the box that runs the whole company network
- SD-WAN managers are the control room for every branch office, so one bug here hits all of them
- I keep wondering how many of these admin panels are reachable straight from the internet. Probably more than should be
Show the official descriptionHide the official description
A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system. A successful exploit could allow the attacker to bypass authentication and gain access to the API as the admin user.
Week of Sep 21, 2026 · exploited since Sep 24
WSO2 Multiple Products
CVE-2026-5430 · CVSS 10.0 critical
Attackers can forge a login token and the server accepts it.
My take
The login token says which lock it uses, and the server just believed it. Classic JWT algorithm confusion, still scoring a 10.0 in 2026
- If you build auth: pin the algorithm on the server. Never let the token pick
- CISA's name for it says path traversal, but NVD's description is all about the JWT part
Show the official descriptionHide the official description
The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access. Successful exploitation of this vulnerability may result in unauthorized access to the system, including the potential compromise of administrative accounts and full account takeover. The CVSS score is adjusted to 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) in single-tenant deployments, reflecting that the impact is contained within a single security authority boundary.
Week of Sep 14, 2026 · exploited since Sep 16
Cisco Identity Services Engine
CVE-2026-76460 · CVSS 10.0 critical
Admin access with no credentials at all.
My take
Cisco ISE decides who's allowed on the network. One of its APIs forgot to check who was asking
- Security appliances need patching like everything else
Show the official descriptionHide the official description
A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.
Week of Sep 7, 2026 · exploited since Sep 9
Cisco Firewall Management Center
CVE-2026-20079 · CVSS 10.0 critical
Anyone who can reach it can get admin access without logging in.
My take
The firewall manager let strangers skip the login and handed them root
- Firewall admin pages belong behind a VPN, not on the open internet
Show the official descriptionHide the official description
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow root access to the device.
Week of Aug 31, 2026 · exploited since Sep 2
Kestra OSS
CVE-2026-49869 · CVSS 10.0 critical
A crafted URL gets attackers around the login check.
My take
The auth check was literally "does the URL end in /configs". Put /configs at the end of your request and you're in. Then it runs your commands
- Match exact routes instead of checking how a string ends
- Orchestration tools usually hold every API key and password a team has, so even a small open-source one is a big target
Show the official descriptionHide the official description
Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().endsWith("/configs") to whitelist the public configuration endpoint from Basic Auth. Because the check is a suffix match rather than an exact path match, any API path whose last segment is configs bypasses authentication entirely. An unauthenticated remote attacker can exploit this to create and execute arbitrary workflows without credentials. Because Kestra ships with script execution plugins (plugin-script-shell, plugin-script-python, etc.) enabled by default, this directly results in unauthenticated Remote Code Execution as root inside the Kestra worker container. This vulnerability is fixed in 1.0.45 and 1.3.21.
Week of Aug 24, 2026 · exploited since Aug 24
Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in
CVE-2026-21962 · CVSS 10.0 critical
Show the official descriptionHide the official description
Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in. While the vulnerability is in Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data. Note: Affected version for Weblogic Server Proxy Plug-in for IIS is 12.2.1.4.0 only. CVSS 3.1 Base Score 10.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).
Week of Aug 17, 2026 · exploited since Aug 18
Microsoft Internet Key Exchange (IKE) Service Extensions
CVE-2026-33824 · CVSS 9.8 critical
A memory bug, the classic way to take over a device remotely.
My take
A double free in the Windows service that sets up VPN connections. Reachable over the network, no login needed
- Memory bugs like this are why "just turn on the VPN" isn't the whole security plan
Show the official descriptionHide the official description
Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.
Week of Aug 10, 2026 · exploited since Aug 11
Metabase
CVE-2026-72898 · CVSS 10.0 critical
Attackers can talk to the database directly and read or change data.
My take
SQL injection through the reset-password endpoint. The one page built for people who can't log in, and it gave out admin
- If you self-host Metabase, this was not a "patch it Monday" update
Show the official descriptionHide the official description
Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.
Week of Aug 3, 2026 · exploited since Aug 4
IBM Langflow
CVE-2026-9198 · CVSS 9.8 critical
Attackers can run their own commands on the machine.
Show the official descriptionHide the official description
IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments
Week of Jul 27, 2026 · exploited since Jul 27
Arista VeloCloud Orchestrator On-Prem
CVE-2026-16812 · CVSS 10.0 critical
Attackers can do things their account shouldn't be allowed to do.
Show the official descriptionHide the official description
VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. This functionality was intended to be for internal use only and is not intended to be remotely accessible. Hosted and Dedicated versions of VCO have already been patched in advance of this notice going out. This issue was discovered externally and is known to be actively exploited.
Week of Jul 20, 2026 · exploited since Jul 21
Langflow Inclusion of Functionality from Untrusted Control Sphere
CVE-2026-0770 · CVSS 9.8 critical
Attackers found a way in and used it before most people patched.
Show the official descriptionHide the official description
Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the exec_globals parameter provided to the validate endpoint. The issue results from the inclusion of a resource from an untrusted control sphere. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-27325.
Week of Jul 13, 2026 · exploited since Jul 14
SonicWall SMA1000 Appliances
CVE-2026-15409 · CVSS 10.0 critical
Attackers can make the server send requests for them, often into internal systems.
Show the official descriptionHide the official description
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.
Week of Jul 6, 2026 · exploited since Jul 7
JoomShaper SP Page Builder
CVE-2026-48908 · CVSS 10.0 critical
Any file on the server is open to read or overwrite.
Show the official descriptionHide the official description
A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.
Week of Jun 29, 2026 · exploited since Jun 29
SimpleHelp
CVE-2026-48558 · CVSS 9.5 critical
Attackers can skip the login.
Show the official descriptionHide the official description
SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication. No user interaction is required.
Week of Jun 22, 2026 · exploited since Jun 23
Ubiquiti UniFi
CVE-2026-34908 · CVSS 10.0 critical
Exploited in the wild before most people had patched.
Show the official descriptionHide the official description
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.
Week of Jun 15, 2026 · exploited since Jun 16
Widget Factory Joomla Content Editor
CVE-2026-48907 · CVSS 10.0 critical
Show the official descriptionHide the official description
A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.
Week of Jun 8, 2026 · exploited since Jun 11
Ivanti Sentry
CVE-2026-10520 · CVSS 10.0 critical
Attackers get it to run commands they choose.
Show the official descriptionHide the official description
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution
Week of Jun 1, 2026 · exploited since Jun 3
Mirasvit Full Page Cache Warmer
CVE-2026-45247 · CVSS 9.3 critical
Attackers send a booby-trapped file or object that runs their code when it's opened.
Show the official descriptionHide the official description
Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie. Attackers can exploit the unrestricted call to PHP's native unserialize() function combined with gadget chains available in Magento and its dependencies to execute arbitrary code on the server.
Week of May 25, 2026 · exploited since May 26
LiteSpeed cPanel Plugin
CVE-2026-48172 · CVSS 10.0 critical
An account gets more access than it's supposed to have.
Show the official descriptionHide the official description
LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of grep -rE "cpanel_jsonapi_func=redisAble" /var/cpanel/logs /usr/local/cpanel/logs/ 2>/dev/null in Bash. If you get no output, you have not been hit with exploitation of the vulnerability. If there is output, we recommend you examine the IP addresses in the list, determine if they are valid IP addresses, and if not, block them. To determine damage done, examine the system logs for use by the detected IP addresses. The issue is related to mishandling of Redis enable/disable features. The recommended minimum version is 2.4.7.
Week of May 18, 2026 · exploited since May 20
Microsoft Windows
CVE-2008-4250 · CVSS 9.8 critical
Memory corruption that can be used to take over the device remotely.
Show the official descriptionHide the official description
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary code via a crafted RPC request that triggers the overflow during path canonicalization, as exploited in the wild by Gimmiv.A in October 2008, aka "Server Service Vulnerability."
Week of May 11, 2026 · exploited since May 14
Cisco Catalyst SD-WAN Controller
CVE-2026-20182 · CVSS 10.0 critical
Show the official descriptionHide the official description
May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed in February 2026. This new advisory is for a new vulnerability in the control connection handshaking. The section of this advisory includes Show Control Connections guidance to help with system checks. A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to the affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric.
Week of May 4, 2026 · exploited since May 6
Palo Alto Networks PAN-OS
CVE-2026-0300 · CVSS 9.3 critical
Show the official descriptionHide the official description
A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. The risk of this issue is greatly reduced if you secure access to the User-ID™ Authentication Portal per the best practice guidelines https://knowledgebase.paloaltonetworks.com/KCSArticleDetail by restricting access to only trusted internal IP addresses. Prisma Access, Cloud NGFW and Panorama appliances are not impacted by this vulnerability.
Week of Apr 27, 2026 · exploited since Apr 30
WebPros cPanel & WHM and WP2 (WordPress Squared)
CVE-2026-41940 · CVSS 9.3 critical
Show the official descriptionHide the official description
cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
Week of Apr 20, 2026 · exploited since Apr 20
Quest KACE Systems Management Appliance (SMA)
CVE-2025-32975 · CVSS 10.0 critical
The login check can be skipped.
Show the official descriptionHide the official description
Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) contains an authentication bypass vulnerability that allows attackers to impersonate legitimate users without valid credentials. The vulnerability exists in the SSO authentication handling mechanism and can lead to complete administrative takeover.
Week of Apr 13, 2026 · exploited since Apr 13
Fortinet FortiClient EMS
CVE-2026-21643 · CVSS 9.8 critical
SQL injection, so the database is open to reads and changes.
Show the official descriptionHide the official description
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
Source: NIST NVD and CISA's known exploited list.