Known exploited vulnerabilities
50The CISA Known Exploited Vulnerabilities catalogue, synced several times a day. These are being exploited in the wild right now.
| CVE | Vendor | Product | Added | Due |
|---|---|---|---|---|
| CVE-2026-20316Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability | Cisco | Secure Firewall Management Center (FMC) | 2026-07-29 | 2026-08-01 |
| CVE-2026-16812Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability | Arista | VeloCloud Orchestrator | 2026-07-27 | 2026-07-30 |
| CVE-2025-68686Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability | Fortinet | FortiOS | 2026-07-27 | 2026-08-10 |
| CVE-2026-50522Microsoft SharePoint Deserialization of Untrusted Data Vulnerability | Microsoft | SharePoint | 2026-07-22 | 2026-07-25 |
| CVE-2026-16232Check Point SmartConsole Improper Authentication Vulnerability | Check Point | SmartConsole | 2026-07-22 | 2026-07-25 |
| CVE-2026-63030WordPress Core Interpretation Conflict Vulnerability | WordPress | Core | 2026-07-21 | 2026-07-24 |
| CVE-2026-60137WordPress Core SQL Injection Vulnerability | WordPress | Core | 2026-07-21 | 2026-08-04 |
| CVE-2026-0770Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability | Langflow | Langflow | 2026-07-21 | 2026-07-24 |
| CVE-2021-27137DD-WRT Stack-Based Buffer Overflow Vulnerability | DD-WRT | DD-WRT | 2026-07-21 | 2026-07-24 |
| CVE-2026-58644Microsoft SharePoint Deserialization of Untrusted Data Vulnerability | Microsoft | SharePoint | 2026-07-16 | 2026-07-19 |
| CVE-2026-39808Fortinet FortiSandbox OS Command Injection Vulnerability | Fortinet | FortiSandbox | 2026-07-16 | 2026-07-19 |
| CVE-2026-25089Fortinet FortiSandbox OS Command Injection Vulnerability | Fortinet | FortiSandbox | 2026-07-16 | 2026-07-19 |
| CVE-2026-46817Oracle E-Business Suite Improper Privilege Management Vulnerability | Oracle | E-Business Suite | 2026-07-15 | 2026-07-18 |
| CVE-2023-4346KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability | KNX Association | KNX Protocol Connection Authorization Option 1 | 2026-07-15 | 2026-07-29 |
| CVE-2026-56164Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability | Microsoft | SharePoint Server | 2026-07-14 | 2026-07-17 |
| CVE-2026-56155Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability | Microsoft | Active Directory Federation Services | 2026-07-14 | 2026-07-28 |
| CVE-2026-15410SonicWall SMA1000 Appliances Code Injection Vulnerability | SonicWall | SMA1000 Appliances | 2026-07-14 | 2026-07-17 |
| CVE-2026-15409SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability | SonicWall | SMA1000 Appliances | 2026-07-14 | 2026-07-17 |
| CVE-2008-4128Cisco IOS Cross-Site Request Forgery Vulnerability | Cisco | IOS | 2026-07-13 | 2026-07-16 |
| CVE-2026-56291Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability | Balbooa | Forms | 2026-07-10 | 2026-07-13 |
| CVE-2026-48939iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability | iCagenda | iCagenda | 2026-07-10 | 2026-07-13 |
| CVE-2026-56290Joomlack Page Builder Improper Access Control Vulnerability | Joomlack | Page Builder | 2026-07-07 | 2026-07-10 |
| CVE-2026-55255Langflow Authorization Bypass Through User-Controlled Key Vulnerability | Langflow | Langflow | 2026-07-07 | 2026-07-10 |
| CVE-2026-48908JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability | JoomShaper | SP Page Builder | 2026-07-07 | 2026-07-10 |
| CVE-2026-48282Adobe ColdFusion Path Traversal Vulnerability | Adobe | ColdFusion | 2026-07-07 | 2026-07-10 |
| CVE-2026-45659Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability | Microsoft | SharePoint Server | 2026-07-01 | 2026-07-04 |
| CVE-2026-48558SimpleHelp Authentication Bypass Vulnerability | SimpleHelp | SimpleHelp | 2026-06-29 | 2026-07-02 |
| CVE-2026-20230Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability | Cisco | Unified Communications Manager | 2026-06-25 | 2026-06-28 |
| CVE-2026-12569[ransomware]PTC Windchill and FlexPLM Improper Input Validation Vulnerability | PTC | Windchill and FlexPLM | 2026-06-25 | 2026-06-28 |
| CVE-2026-34910Ubiquiti UniFi OS Improper Input Validation Vulnerability | Ubiquiti | UniFi OS | 2026-06-23 | 2026-06-26 |
| CVE-2026-34909Ubiquiti UniFi OS Path Traversal Vulnerability | Ubiquiti | UniFi OS | 2026-06-23 | 2026-06-26 |
| CVE-2026-34908Ubiquiti UniFi OS Improper Access Control Vulnerability | Ubiquiti | UniFi OS | 2026-06-23 | 2026-06-26 |
| CVE-2025-67038Lantronix EDS5000 Code Injection Vulnerability | Lantronix | EDS5000 | 2026-06-23 | 2026-06-26 |
| CVE-2026-20253Splunk Enterprise Missing Authentication for Critical Function Vulnerability | Splunk | Enterprise | 2026-06-18 | 2026-06-21 |
| CVE-2026-48907Widget Factory Joomla Content Editor Improper Access Control Vulnerability | Widget Factory | Joomla Content Editor | 2026-06-16 | 2026-06-19 |
| CVE-2026-54420LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability | LiteSpeed | cPanel Plugin | 2026-06-15 | 2026-06-18 |
| CVE-2026-20262Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability | Cisco | Catalyst SD-WAN Manager | 2026-06-15 | 2026-06-29 |
| CVE-2026-35273[ransomware]Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability | Oracle | PeopleSoft Enterprise PeopleTools | 2026-06-12 | 2026-06-15 |
| CVE-2026-10520Ivanti Sentry OS Command Injection Vulnerability | Ivanti | Sentry | 2026-06-11 | 2026-06-14 |
| CVE-2026-7473Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability | Arista | Extensible Operating System | 2026-06-09 | 2026-06-23 |
| CVE-2026-20245Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability | Cisco | Catalyst SD-WAN Manager | 2026-06-09 | 2026-06-23 |
| CVE-2026-11645Google Chromium V8 Out-of-Bounds Read and Write Vulnerability | Chromium V8 | 2026-06-09 | 2026-06-23 | |
| CVE-2026-50751[ransomware]Check Point Security Gateway Improper Authentication Vulnerability | Check Point | Security Gateway | 2026-06-08 | 2026-06-11 |
| CVE-2026-42271BerriAI LiteLLM Command Injection Vulnerability | BerriAI | LiteLLM | 2026-06-08 | 2026-06-22 |
| CVE-2026-28318SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability | SolarWinds | Serv-U | 2026-06-05 | 2026-06-19 |
| CVE-2026-45247Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability | Mirasvit | Mirasvit Full Page Cache Warmer | 2026-06-03 | 2026-06-06 |
| CVE-2025-48595Android Framework Integer Overflow Vulnerability | Android | Framework | 2026-06-02 | 2026-06-05 |
| CVE-2022-0492Linux Kernel Improper Authentication Vulnerability | Linux | Kernel | 2026-06-02 | 2026-06-05 |
| CVE-2024-21182Oracle WebLogic Server Unspecified Vulnerability | Oracle | WebLogic Server | 2026-06-01 | 2026-06-04 |
| CVE-2026-0257[ransomware]Palo Alto Networks PAN-OS Authentication Bypass Vulnerability | Palo Alto Networks | PAN-OS | 2026-05-29 | 2026-06-01 |
Source: CISA. Each row links to the NVD entry.
This is what cymesh.net is for
Certificate and hostname problems are the ones you find out about from your users. cymesh.net finds them first.
monitorsTLS/SSL expiry, chain and hostnamealertsemail, ahead of the expiry datescopenon-intrusive, read-only checks