This page tracks the vulnerabilities most actively exploited in the wild right now. Each entry is a CVE added to the CISA Known Exploited Vulnerabilities (KEV) catalog within the last 30 days and confirmed as under active exploitation by our CVE Watchtower. The list is ranked by EPSS score, which estimates the probability of exploitation, alongside CVSS severity. It refreshes automatically throughout the day. If you only have time to patch a few things this month, start here.
Last updated: August 1, 2026 · Source: CISA KEV + Daily CyberSecurity CVE Watchtower
| # | CVE | Vendor / Product | CVSS | EPSS | Added to KEV |
|---|---|---|---|---|---|
| 1 |
CVE-2026-48282
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path…
|
Adobe ColdFusion | 10.0 | 99.2% | Jul 7, 2026 |
| 2 |
CVE-2026-63030
WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which,…
|
WordPress Core | 9.8 | 98.4% | Jul 21, 2026 |
| 3 |
CVE-2026-39808
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through…
|
Fortinet FortiSandbox | 9.8 | 89.7% | Jul 16, 2026 |
| 4 |
CVE-2026-48908
A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload…
|
JoomShaper SP Page Builder | 10.0 | 88.1% | Jul 7, 2026 |
| 5 |
CVE-2026-56290
Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page…
|
Joomlack Page Builder | 10.0 | 83.3% | Jul 7, 2026 |
| 6 |
CVE-2026-60137
WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query,…
|
WordPress Core | 5.9 | 79.0% | Jul 21, 2026 |
| 7 |
CVE-2026-15409
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker…
|
SonicWall SMA1000 Appliances | 10.0 | 78.4% | Jul 14, 2026 |
| 8 |
CVE-2026-15410
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC)…
|
SonicWall SMA1000 Appliances | 7.2 | 76.3% | Jul 14, 2026 |
| 9 |
CVE-2026-56291
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms…
|
Balbooa Forms | 10.0 | 76.1% | Jul 10, 2026 |
| 10 |
CVE-2026-50522
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
|
Microsoft SharePoint | 9.8 | 75.8% | Jul 22, 2026 |
| 11 |
CVE-2026-16232
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application…
|
Check Point SmartConsole | 9.1 | 70.0% | Jul 22, 2026 |
| 12 |
CVE-2026-25089
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through…
|
Fortinet FortiSandbox | 9.8 | 69.8% | Jul 16, 2026 |
| 13 |
CVE-2026-0770
Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute…
|
Langflow Langflow | 9.8 | 56.3% | Jul 21, 2026 |
| 14 |
CVE-2008-4128
Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services…
|
Cisco IOS | 4.3 | 33.0% | Jul 13, 2026 |
| 15 |
CVE-2026-55255
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object Reference…
|
Langflow Langflow | 8.4 | 29.1% | Jul 7, 2026 |
Previous 30 days
| # | CVE | Vendor / Product | CVSS | EPSS | Added to KEV |
|---|---|---|---|---|---|
| 1 |
CVE-2026-10520
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution
|
Ivanti Sentry | 10.0 | 99.9% | Jun 11, 2026 |
| 2 |
CVE-2026-20253
In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary…
|
Splunk Enterprise | 9.8 | 96.2% | Jun 18, 2026 |
| 3 |
CVE-2026-35273
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are…
|
Oracle PeopleSoft Enterprise PeopleTools | 9.8 | 95.5% | Jun 12, 2026 |
| 4 |
CVE-2026-34910
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices…
|
Ubiquiti UniFi OS | 10.0 | 87.0% | Jun 23, 2026 |
| 5 |
CVE-2026-20230
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME)…
|
Cisco Unified Communications Manager | 8.6 | 83.2% | Jun 25, 2026 |
| 6 |
CVE-2026-50751
A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated…
|
Check Point Security Gateway | 9.3 | 82.6% | Jun 8, 2026 |
| 7 |
CVE-2026-48907
A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately…
|
Widget Factory Joomla Content Editor | 10.0 | 80.4% | Jun 16, 2026 |
| 8 |
CVE-2026-42271
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to…
|
BerriAI LiteLLM | 8.8 | 80.2% | Jun 8, 2026 |
| 9 |
CVE-2026-34908
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices…
|
Ubiquiti UniFi OS | 10.0 | 58.4% | Jun 23, 2026 |
| 10 |
CVE-2026-34909
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to…
|
Ubiquiti UniFi OS | 10.0 | 56.9% | Jun 23, 2026 |
| 11 |
CVE-2026-20262
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker…
|
Cisco Catalyst SD-WAN Manager | 6.5 | 28.2% | Jun 15, 2026 |
| 12 |
CVE-2026-45247
Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated…
|
Mirasvit Mirasvit Full Page Cache Warmer | 9.8 | 27.5% | Jun 3, 2026 |
| 13 |
CVE-2026-20245
A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage,…
|
Cisco Catalyst SD-WAN Manager | 7.8 | 25.3% | Jun 9, 2026 |
| 14 |
CVE-2025-67038
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when…
|
Lantronix EDS5000 | 9.8 | 14.3% | Jun 23, 2026 |
| 15 |
CVE-2026-48558
SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When…
|
SimpleHelp SimpleHelp | 10.0 | 11.5% | Jun 29, 2026 |
Frequently Asked Questions
What does “actively exploited” mean?
It means attackers are using the vulnerability in real-world attacks right now, not just in theory. Confirmation comes from the CISA KEV catalog and our own CVE Watchtower tracking.
What is the CISA KEV catalog?
The Known Exploited Vulnerabilities (KEV) catalog is a list maintained by the U.S. Cybersecurity and Infrastructure Security Agency. It only includes CVEs with reliable evidence of exploitation in the wild, which makes it a strong patching baseline for any organization.
What is an EPSS score?
EPSS (Exploit Prediction Scoring System) estimates the probability that a vulnerability will be exploited within the next 30 days. A score of 90% means very high likelihood. We rank this list by EPSS because it reflects real-world risk better than severity alone.
How is this different from CVSS?
CVSS measures how severe a vulnerability could be if exploited. EPSS measures how likely exploitation actually is. A flaw can be critical on paper but rarely attacked, or moderate on paper yet heavily abused. We show both so defenders can prioritize correctly.
How often is this page updated?
The list refreshes automatically several times a day from the CISA KEV feed and our CVE Watchtower database. The “Last updated” line above the table shows the most recent refresh.
Should I patch everything on this list?
Yes, treat every entry as a priority. These CVEs are confirmed under active exploitation, so the usual “wait and assess” approach does not apply. If a patch is unavailable, apply the vendor’s mitigations immediately.
Can I cite or link to this list?
Yes. This page is free to reference in reports, advisories, and articles. Please credit Daily CyberSecurity and link back to this page so readers always see the current data.