Exploited
CVE-2026-85046
Sep 4, 2026
A type confusion flaw added to the catalog on 4 September 2026. The record itself states that it could affect multiple Chromium-based browsers, naming Chrome, Edge and Opera.
- A type confusion vulnerability in V8, the JavaScript engine in Chromium, reachable through a crafted HTML page.
- The record itself states the flaw could affect several Chromium-based browsers, naming Chrome, Edge and Opera.
- V8 appears 40 times in the catalog, and 20 of those are the same weakness, CWE-843.
Read more
Exploited
Ransomware use CVE-2026-59310
Aug 18, 2026
VMware vCenter, the management server for a virtualized estate, contains a flaw in how it validates pathnames. An attacker with network access to vCenter can execute arbitrary code. CISA added it to the KEV catalog on 2026-08-18 with a due date of 2026-08-21 — three days after listing.
- The affected product is Broadcom VMware vCenter; CWE-22, improper limitation of a pathname (path traversal).
- The catalog records that a threat actor with network access to vCenter can execute arbitrary code.
- vCenter is the management plane of a virtualized environment — the layer that creates, moves, clones, and deletes virtual machines.
Read more
Exploited
Ransomware use CVE-2026-20316
Jul 29, 2026
A use of hard-coded password vulnerability in Cisco Secure Firewall Management Center has been added to CISA's Known Exploited Vulnerabilities catalog. An unauthenticated remote attacker can log in with a low-privileged account.
- A hard-coded password (CWE-259) lets an unauthenticated remote attacker log in with a low-privileged account.
- A credential embedded in a product does not differ between environments, so once known it reaches widely.
- The subject is an appliance centrally managing firewalls - the defending machinery itself as the way in.
Read more
Exploited
Ransomware use CVE-2026-15409
Jul 14, 2026
SonicWall SMA1000 appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to cause the appliance to make requests to unintended locations. It was added to the CISA Known Exploited Vulnerabilities catalog on 2026-07-14 with a due date three days later, and use in ransomware campaigns is known.
- SonicWall SMA1000 appliances contain a server-side request forgery (CWE-918) exploitable without authentication.
- Added to KEV on 2026-07-14 with a due date of 2026-07-17, a three-day grace period. Use in ransomware campaigns is known.
- Among the 1,687 records this site holds as of 2026-09-02, vendors with at least 8 records show ransomware shares of QNAP 81.8% (9/11), SonicWall 76.5% (13/17), Atlassian 61.5% (8/13), Fortinet 48.3% (14/29).
Read more
Exploited
Ransomware use CVE-2026-15410
Jul 14, 2026
SonicWall SMA1000, a remote access appliance, contains a code injection flaw allowing a remote attacker authenticated as administrator to execute arbitrary OS commands. CISA added it to the KEV catalog on 2026-07-14 with a due date of 2026-07-17 — three days. This entry is recorded as known to be used in ransomware campaigns.
- The affected product is SonicWall SMA1000 Appliances; CWE-94, improper control of code generation.
- Under specific conditions a remote attacker authenticated as administrator can execute arbitrary OS commands.
- Use in ransomware campaigns is recorded as known — unlike most entries this site holds.
Read more
High
Ransomware use CVE-2026-45659
Jul 1, 2026
Microsoft SharePoint Server, the widely used document-collaboration platform, contains a deserialization-of-untrusted-data vulnerability that lets an authorized attacker execute code over the network. CISA added it to the KEV (Known Exploited Vulnerabilities) catalog on July 1, 2026, setting the remediation deadline just three days later, on July 4.
- Deserialization of untrusted data (CWE-502) in SharePoint Server — crafted data injected into the restore process can execute code remotely
- Requires authorization (login) — the classic post-intrusion pattern: a stolen account or existing foothold becomes full server takeover
- Microsoft's NVD-registered assessment: CVSS 8.8 (HIGH) — low privileges, no user interaction
Read more
Critical
Ransomware use CVE-2026-12569
Jun 25, 2026
PTC Windchill / FlexPLM, product lifecycle management (PLM) platforms for manufacturing, contain an improper-input-validation flaw (CWE-20/CWE-502). An unauthenticated remote attacker can execute arbitrary code just by sending a crafted request. The official NVD score is CVSS 9.8 (CRITICAL). CISA added it to KEV on June 25, 2026, with remediation due three days later, June 28.
- Improper input validation (CWE-20/CWE-502) in manufacturing PLM platforms PTC Windchill / FlexPLM
- No authentication, no user interaction, remote code execution — the dangerous "pre-auth RCE"
- Official NVD score: CVSS 9.8 (CRITICAL)
Read more
Critical
Ransomware use CVE-2026-35273
Jun 12, 2026
Oracle PeopleSoft Enterprise PeopleTools — the platform under the PeopleSoft ERP (HR, finance) — has a missing-authentication-for-critical-function flaw (CWE-306). A remote, unauthenticated attacker can take over PeopleTools. CISA listed it as known-exploited (KEV) and confirmed ransomware use (CVSS 9.8 Critical, per NVD).
- Missing authentication for a critical function (CWE-306) in PeopleTools, the platform under PeopleSoft
- A remote, unauthenticated attacker can take over PeopleTools
- Listed in CISA KEV = exploitation confirmed; also confirmed used in ransomware
Read more
Critical
Ransomware use CVE-2026-50751
Jun 8, 2026
Check Point's Security Gateway products have an improper-authentication vulnerability in IKEv1 key exchange that lets an unauthenticated remote attacker bypass user authentication and establish a remote-access VPN connection without a valid user password. CISA listed it as known-exploited (KEV) (CVSS 9.3 Critical).
- IKEv1 authentication bypass (CWE-287) in Check Point Security Gateway
- An unauthenticated remote attacker establishes a remote-access VPN connection without a valid password
- Compromise of a perimeter VPN/firewall = a foothold for internal intrusion. CVSS 9.3 (Critical)
Read more
Critical
Ransomware use CVE-2026-0257
May 29, 2026
An authentication-bypass vulnerability in Palo Alto Networks' firewall OS, PAN-OS, lets an attacker bypass security restrictions and establish an unauthorized VPN connection. CISA listed it as known-exploited (KEV) (CVSS 9.1 Critical).
- Authentication-bypass vulnerability in PAN-OS (the OS for Palo Alto firewall products)
- An attacker can bypass security restrictions and establish an unauthorized VPN connection
- Compromise of a perimeter device = a foothold for internal intrusion. Listed in CISA KEV (CVSS 9.1 Critical)
Read more
Critical
Ransomware use CVE-2026-48027
May 27, 2026
A malicious version of "Nx Console," a popular IDE extension for the Nx build system, was published; it fetches an obfuscated payload and harvests credentials (tokens and keys) from disk and memory. CISA listed it as known-exploited (KEV) with confirmed ransomware use (CVSS 9.8 Critical).
- A tampered build of Nx Console (an IDE extension for the Nx build system) fetched and ran an obfuscated payload
- It stole credentials from disk and memory (GitHub/npm tokens, SSH keys, cloud credentials, etc.)
- Listed in CISA KEV = exploitation confirmed; ransomware use also confirmed (CVSS 9.8 Critical)
Read more
Critical
Ransomware use CVE-2026-45321
May 27, 2026
Malicious versions of the widely used TanStack (a family of React libraries) were published to the npm registry, distributing credential-stealing malware under a trusted publisher identity. CISA listed it as known-exploited (KEV) with confirmed ransomware use (CVSS 9.6 Critical).
- Malicious versions of TanStack (popular React libraries) were published to npm
- A trusted publisher (maintainer identity) was abused to distribute credential-stealing malware
- Listed in CISA KEV = exploitation confirmed; ransomware use also confirmed (CVSS 9.6 Critical)
Read more
Critical
Ransomware use CVE-2026-41940
Apr 30, 2026
cPanel & WHM and WP2, a widely used web-hosting control panel, have a missing-authentication flaw in the login flow that lets an unauthenticated remote attacker gain unauthorized access to the control panel. CISA listed it as known-exploited (KEV) with confirmed ransomware use (CVSS 9.8 Critical).
- Missing authentication (CWE-306) in the login flow of cPanel & WHM / WP2
- An unauthenticated remote attacker gains unauthorized access to the control panel
- cPanel/WHM is the most widely used hosting control panel = one compromise ripples to many sites
Read more
High
Ransomware use CVE-2024-1708
Apr 28, 2026
ConnectWise ScreenConnect, a remote-management (RMM) / remote-support tool, has a path-traversal vulnerability that could let an attacker execute remote code or directly impact confidential data and critical systems. CISA listed it as known-exploited (KEV) with confirmed ransomware use (CVSS 8.4 High).
- Path traversal (CWE-22) in ConnectWise ScreenConnect (an RMM tool that remotely manages many endpoints)
- Can lead to remote code execution (RCE) or direct impact on confidential data and critical systems
- RMM compromise = a "lever" to push malware to many managed endpoints at once
Read more
Critical
Ransomware use CVE-2024-57726
Apr 24, 2026
The remote support/RMM tool SimpleHelp has a missing-authorization flaw that lets a low-privilege technician create an overly privileged API key and escalate to server administrator. It is listed in CISA's Known Exploited Vulnerabilities catalog and has been used in ransomware campaigns.
- Affects SimpleHelp's remote support / RMM product SimpleHelp (CVE-2024-57726).
- The weakness type is Missing Authorization.
- A low-privilege technician can create an overly privileged API key and escalate to server administrator.
Read more
High
Ransomware use CVE-2023-27351
Apr 20, 2026
PaperCut NG/MF, a print management product, contains a flaw that may allow authentication (the identity-verification step) to be bypassed, potentially letting an attacker reach administrative functions without a valid login.
- Affects PaperCut NG/MF print management software through an improper authentication flaw that may allow the identity check to be bypassed.
- The KEV record states authentication may be bypassed via the SecurityRequestFilter class, potentially leading to unauthorized access to administrative functions.
- Listed by CISA in its Known Exploited Vulnerabilities (KEV) catalog (added 2026-04-20, remediation due 2026-05-04).
Read more
High
Ransomware use CVE-2024-27199
Apr 20, 2026
JetBrains TeamCity, a CI/CD server that automates building and distributing software, contains a relative path traversal flaw that can lead to limited admin actions, and CISA has added it to its Known Exploited Vulnerabilities (KEV) catalog.
- Affected product is JetBrains TeamCity, a CI/CD server that automates building and distributing software.
- The flaw is relative path traversal (reaching paths that were not meant to be accessible) and can lead to limited admin actions.
- CISA added it to the KEV catalog on 2026-04-20, with a remediation due date of 2026-05-04.
Read more
Exploited
Ransomware use CVE-2025-60710
Apr 13, 2026
A privilege escalation flaw added to the CISA exploited-vulnerabilities catalog on 13 April 2026. Windows appears in that catalog 172 times, more than any other product in these records.
- A privilege escalation flaw in Windows from link following (CWE-59), added to the catalog on 13 April 2026.
- The remediation date was 27 April 2026, a fourteen-day window, and ransomware use is confirmed.
- Of the 1,695 KEV records this site holds as of 2026-09-06, across 711 products, Windows accounts for 172.
Read more
High
Ransomware use CVE-2023-21529
Apr 13, 2026
Microsoft Exchange Server, an email backbone, contains a deserialization of untrusted data flaw (CWE-502) that lets an authenticated attacker run arbitrary code remotely. It has been confirmed used in ransomware attacks, and CISA added it to the KEV on 2026-04-13. The CVSS published on NVD is 8.8 (HIGH).
- Deserialization (CWE-502) in Microsoft Exchange Server — reconstructing crafted data leads to remote arbitrary code execution.
- The vector is PR:L (some privilege required), but stepping-stone attacks from stolen low-privilege accounts are standard, so "authenticated only" is no comfort.
- Confirmed use in ransomware attacks (per CISA's record).
Read more
Exploited
Ransomware use CVE-2026-20131
Mar 19, 2026
Added on 19 March 2026 with a remediation date of 22 March. The record states that an unauthenticated remote attacker could execute arbitrary Java code as root through the management interface.
- A deserialization of untrusted data flaw in Cisco Secure Firewall Management Center and related management.
- An unauthenticated remote attacker could execute arbitrary Java code as root through the management interface.
- Added 19 March 2026 with a 22 March deadline, a three-day window, with ransomware use confirmed.
Read more
Exploited
Ransomware use CVE-2025-26399
Mar 9, 2026
A deserialization vulnerability in SolarWinds Web Help Desk. Restoring untrusted data to its original form is described as allowing commands to be run on the host machine. The remediation deadline was set three days after listing.
- The affected product is SolarWinds Web Help Desk, classified as CWE-502, deserialization of untrusted data.
- A component of the product is described as allowing commands to be run on the host machine.
- Deserialization restores data converted for storage or transmission, and what runs during that rebuilding depends on the content.
Read more
Exploited
Ransomware use CVE-2026-1731
Feb 13, 2026
BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) contain an OS command injection flaw. With neither authentication nor user interaction required, a remote attacker can execute operating system commands in the context of the site user. CISA added it to the KEV catalog on 2026-02-13 with a due date of 2026-02-16 — three days. Use in ransomware campaigns is recorded as known.
- The affected products are BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA); CWE-78, OS command injection.
- Exploitation requires neither authentication nor user interaction, allowing a remote attacker to execute OS commands in the context of the site user.
- The catalog states it may lead to system compromise including unauthorized access, data exfiltration and service disruption.
Read more
Exploited
Ransomware use CVE-2026-23760
Jan 26, 2026
SmarterTools SmarterMail contains an authentication bypass in its password reset API. The force-reset-password endpoint permits anonymous requests and does not verify an existing password or a reset token when resetting system administrator accounts, so an unauthenticated attacker supplying a target administrator username and a new password can take full administrative control of the instance.
- The affected product is SmarterTools SmarterMail; CWE-288, authentication bypass using an alternate path or channel.
- The force-reset-password endpoint permits anonymous requests and verifies neither the existing password nor a reset token for administrator accounts.
- An unauthenticated attacker supplying a target administrator username and a new password can take full administrative control of the instance.
Read more
Exploited
Ransomware use CVE-2025-55182
Dec 5, 2025
Meta React Server Components contains a remote code execution flaw. Exploiting a defect in how React decodes payloads sent to React Server Function endpoints can yield unauthenticated remote code execution. CISA added it to the KEV catalog on 2025-12-05 with a due date of 2025-12-12 — seven days.
- The affected product is Meta React Server Components, the framework beneath a great many web applications.
- A defect in how React decodes payloads sent to Server Function endpoints can yield unauthenticated remote code execution.
- The catalog notes that CVE-2025-66478 has been rejected but is associated with this record.
Read more
Exploited
Ransomware use CVE-2025-61882
Oct 6, 2025
An unspecified vulnerability in the core business system Oracle E-Business Suite. Both the name and the description say unspecified, and the records this site holds carry no class of flaw. It appears in the catalog nonetheless because exploitation was confirmed.
- The affected product is Oracle E-Business Suite, with the name given as an unspecified vulnerability and no class recorded.
- The catalog collects what has been confirmed as actually exploited, so an entry can appear with the class undetermined.
- It sits in a named component, and an unauthenticated party with network access via HTTP is described as able to compromise a processing component.
Read more
Exploited
Ransomware use CVE-2025-10035
Sep 29, 2025
Fortra GoAnywhere MFT contains a deserialization of untrusted data flaw. An actor holding a validly forged license response signature can deserialize an arbitrary object under their control, possibly leading to command injection. CISA added it to the KEV catalog on 2025-09-29.
- The affected product is Fortra GoAnywhere MFT; CWE-502 (deserialization of untrusted data) and CWE-77 (command injection).
- An actor with a validly forged license response signature can deserialize an arbitrary object under their control.
- The catalog states this may lead to command injection.
Read more
Exploited
Ransomware use CVE-2025-8088
Aug 12, 2025
The Windows version of RARLAB WinRAR contains a path traversal flaw. An attacker can execute arbitrary code by crafting malicious archive files. CISA added it to the KEV catalog on 2025-08-12 with a due date of 2025-09-02. Use in ransomware campaigns is recorded as known.
- The affected product is the Windows version of RARLAB WinRAR; CWE-35, path traversal.
- A maliciously crafted archive file can let an attacker execute arbitrary code.
- An archive carries information about where contents go; where that specification reaches outside the destination, files can be placed at will.
Read more
Exploited
Ransomware use CVE-2025-49704
Jul 22, 2025
A code injection vulnerability in Microsoft SharePoint. The CISA Known Exploited Vulnerabilities catalog listed it on July 22, 2025 with a remediation due date of July 23. It is described as chainable with a separate authentication vulnerability, and use in ransomware campaigns is known.
- The affected product is Microsoft SharePoint, classified as CWE-94, improper control of generation of code.
- It is described as allowing an authorized attacker to execute code over a network.
- The catalog records expressly that it could be chained with a separate authentication vulnerability.
Read more
Exploited
Ransomware use CVE-2025-5777
Jul 10, 2025
Citrix NetScaler ADC and Gateway contain an out-of-bounds read vulnerability caused by insufficient input validation, which can lead to memory overread when configured as a Gateway or AAA virtual server. It was added to the CISA Known Exploited Vulnerabilities catalog on 2025-07-10 with a due date of 2025-07-11 — one day later. Use in ransomware campaigns is known.
- Citrix NetScaler ADC and Gateway contain an out-of-bounds read (CWE-125) caused by insufficient input validation.
- Memory overread can occur when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or as an AAA virtual server.
- Added to KEV on 2025-07-10 with a due date of 2025-07-11 — a one-day grace period. Use in ransomware campaigns is known.
Read more
Exploited
Ransomware use CVE-2025-31324
Apr 29, 2025
The SAP NetWeaver Visual Composer Metadata Uploader contains an unrestricted file upload flaw allowing an unauthenticated agent to upload potentially malicious executable binaries. CISA added it to the KEV catalog on 2025-04-29 with a due date of 2025-05-20.
- The affected component is the SAP NetWeaver Visual Composer Metadata Uploader; CWE-434, unrestricted upload of file with dangerous type.
- An unauthenticated agent can upload potentially malicious executable binaries.
- Unrestricted signals that checks on extension and content and limits on the destination — the machinery keeping a placed file from executing — are not working.
Read more