Known exploited vulnerabilities
50The CISA Known Exploited Vulnerabilities catalogue, synced several times a day. These are being exploited in the wild right now.
| CVE | Vendor | Product | Added | Due |
|---|---|---|---|---|
| CVE-2026-102490Zammad GmbH Zammad Improper Privilege Management Vulnerability | Zammad GmbH | Zammad | 2026-10-02 | 2026-10-05 |
| CVE-2026-102489Zammad GmbH Zammad Session Fixation Vulnerability | Zammad GmbH | Zammad | 2026-10-02 | 2026-10-05 |
| CVE-2026-104286Fortinet FortiMail Path Traversal Vulnerability | Fortinet | FortiMail | 2026-10-01 | 2026-10-04 |
| CVE-2026-76504Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability | Cisco | Catalyst SD-WAN Manager | 2026-09-30 | 2026-10-03 |
| CVE-2026-86950Apple Multiple Products Out-of-Bounds Write Vulnerability | Apple | Multiple Products | 2026-09-29 | 2026-10-02 |
| CVE-2026-88772Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability | Citrix | NetScaler | 2026-09-27 | 2026-09-30 |
| CVE-2026-88771Citrix NetScaler Improper Input Validation Vulnerability | Citrix | NetScaler | 2026-09-27 | 2026-09-30 |
| CVE-2026-87902WordPress Core Remote File Inclusion Vulnerability | WordPress | Core | 2026-09-25 | 2026-09-28 |
| CVE-2026-67279Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability | MikroTik | RouterOS | 2026-09-25 | 2026-09-28 |
| CVE-2026-65660Microsoft SharePoint Code Injection Vulnerability | Microsoft | SharePoint | 2026-09-25 | 2026-09-28 |
| CVE-2026-71362Adobe Commerce and Magento Incorrect Authorization Vulnerability | Adobe | Commerce and Magento | 2026-09-24 | 2026-09-27 |
| CVE-2026-5430WSO2 Multiple Products Path Traversal Vulnerability | WSO2 | Multiple Products | 2026-09-24 | 2026-09-27 |
| CVE-2026-94127F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability | F5 | BIG-IP APM | 2026-09-22 | 2026-09-25 |
| CVE-2026-93952Arista VeloCloud Orchestrator Improper Input Validation Vulnerability | Arista | VeloCloud Orchestrator | 2026-09-22 | 2026-09-25 |
| CVE-2026-93616Check Point Multiple Products Path Traversal Vulnerability | Check Point | Multiple Products | 2026-09-22 | 2026-09-25 |
| CVE-2026-85102Check Point Multiple Products Improper Certificate Validation Vulnerability | Check Point | Multiple Products | 2026-09-22 | 2026-09-25 |
| CVE-2026-7273Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability | Zyxel | GS1900 Series Switches | 2026-09-21 | 2026-09-24 |
| CVE-2026-53266Linux Kernel Out-of-Bounds Write Vulnerability | Linux | Kernel | 2026-09-18 | 2026-09-21 |
| CVE-2025-39964Linux Kernel Race Condition Vulnerability | Linux | Kernel | 2026-09-18 | 2026-09-21 |
| CVE-2025-39682Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability | Linux | Kernel | 2026-09-18 | 2026-09-21 |
| CVE-2026-87886Acronis Backup Incorrect Default Permissions Vulnerability | Acronis | Backup | 2026-09-16 | 2026-09-19 |
| CVE-2026-76460Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability | Cisco | Identity Services Engine | 2026-09-16 | 2026-09-19 |
| CVE-2026-58704Google Pixel Improper Authorization Vulnerability | Pixel | 2026-09-16 | 2026-09-19 | |
| CVE-2026-76461Cisco Secure Email Gateway SQL Injection Vulnerability | Cisco | Secure Email Gateway | 2026-09-14 | 2026-09-17 |
| CVE-2026-85706GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability | GitLab | Community Edition and Enterprise Edition | 2026-09-11 | 2026-09-14 |
| CVE-2026-84869ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability | ConnectWise | ScreenConnect | 2026-09-11 | 2026-09-14 |
| CVE-2026-42018JFrog Artifactory Improper Authentication Vulnerability | JFrog | Artifactory | 2026-09-11 | 2026-09-25 |
| CVE-2026-42016JFrog Artifactory Incorrect Authorization Vulnerability | JFrog | Artifactory | 2026-09-11 | 2026-09-25 |
| CVE-2026-86060MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability | MikroTik | RouterOS | 2026-09-10 | 2026-09-13 |
| CVE-2026-67277MikroTik RouterOS Missing Authentication for Critical Function Vulnerability | MikroTik | RouterOS | 2026-09-10 | 2026-09-13 |
| CVE-2026-87491Google Chromium V8 Out of Bounds Write Vulnerability | Chromium V8 | 2026-09-09 | 2026-09-23 | |
| CVE-2026-20079Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability | Cisco | Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management | 2026-09-09 | 2026-09-12 |
| CVE-2026-19490Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability | Citrix | NetScaler | 2026-09-09 | 2026-09-12 |
| CVE-2025-25249Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability | Fortinet | Multiple Products | 2026-09-09 | 2026-09-12 |
| CVE-2026-86218N-able N-central Static Code Injection Vulnerability | N-able | N-central | 2026-09-08 | 2026-09-11 |
| CVE-2026-85880Microsoft Windows Heap-Based Buffer Overflow Vulnerability | Microsoft | Windows | 2026-09-08 | 2026-09-22 |
| CVE-2026-81963Microsoft Windows Link Following Vulnerability | Microsoft | Windows | 2026-09-08 | 2026-09-22 |
| CVE-2026-75650Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability | Adobe | Commerce and Magento | 2026-09-08 | 2026-09-11 |
| CVE-2026-85046Google Chromium V8 Type Confusion Vulnerability | Chromium V8 | 2026-09-04 | 2026-09-18 | |
| CVE-2026-9586Sangoma Switchvox SQL Injection Vulnerability | Sangoma | Switchvox | 2026-09-02 | 2026-09-05 |
| CVE-2026-83549SonicWall SMA1000 Appliances OS Command Injection Vulnerability | SonicWall | SMA1000 Appliances | 2026-09-02 | 2026-09-05 |
| CVE-2026-83548SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability | SonicWall | SMA1000 Appliances | 2026-09-02 | 2026-09-05 |
| CVE-2026-82329JFrog Artifactory Improper Authentication Vulnerability | JFrog | Artifactory | 2026-09-02 | 2026-09-05 |
| CVE-2026-59822BerriAI LiteLLM Improper Authentication Vulnerability | BerriAI | LiteLLM | 2026-09-02 | 2026-09-16 |
| CVE-2026-49869Kestra OSS OS Command Injection Vulnerability | Kestra | Kestra OSS | 2026-09-02 | 2026-09-05 |
| CVE-2026-48710Kludex Starlette HTTP Request/Response Smuggling Vulnerability | Kludex | Starlette | 2026-09-02 | 2026-09-16 |
| CVE-2026-82078PaperCut NG/MF Unsafe Reflection Vulnerability | PaperCut | NG/MF | 2026-08-31 | 2026-09-14 |
| CVE-2026-81578PaperCut NG/MF Missing Authentication for Critical Function Vulnerability | PaperCut | NG/MF | 2026-08-31 | 2026-09-14 |
| CVE-2026-66384JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability | JFrog | Artifactory | 2026-08-27 | 2026-09-10 |
| CVE-2026-53362Linux Kernel Unspecified Vulnerability | Linux | Kernel | 2026-08-27 | 2026-08-30 |
Source: CISA. Each row links to the NVD entry.
This is what cymesh.net is for
Certificate and hostname problems are the ones you find out about from your users. cymesh.net finds them first.
monitorsTLS/SSL expiry, chain and hostnamealertsemail, ahead of the expiry datescopenon-intrusive, read-only checks