August 1, 2026

Top Exploited CVEs This Month

most exploited vulnerabilities, actively exploited CVEs

This page tracks the vulnerabilities most actively exploited in the wild right now. Each entry is a CVE added to the CISA Known Exploited Vulnerabilities (KEV) catalog within the last 30 days and confirmed as under active exploitation by our CVE Watchtower. The list is ranked by EPSS score, which estimates the probability of exploitation, alongside CVSS severity. It refreshes automatically throughout the day. If you only have time to patch a few things this month, start here.

Last updated: August 1, 2026 · Source: CISA KEV + Daily CyberSecurity CVE Watchtower

#CVEVendor / ProductCVSSEPSSAdded to KEV
1 CVE-2026-48282
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path…
Adobe ColdFusion 10.0 99.2% Jul 7, 2026
2 CVE-2026-63030
WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which,…
WordPress Core 9.8 98.4% Jul 21, 2026
3 CVE-2026-39808
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through…
Fortinet FortiSandbox 9.8 89.7% Jul 16, 2026
4 CVE-2026-48908
A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload…
JoomShaper SP Page Builder 10.0 88.1% Jul 7, 2026
5 CVE-2026-56290
Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page…
Joomlack Page Builder 10.0 83.3% Jul 7, 2026
6 CVE-2026-60137
WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query,…
WordPress Core 5.9 79.0% Jul 21, 2026
7 CVE-2026-15409
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker…
SonicWall SMA1000 Appliances 10.0 78.4% Jul 14, 2026
8 CVE-2026-15410
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC)…
SonicWall SMA1000 Appliances 7.2 76.3% Jul 14, 2026
9 CVE-2026-56291
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms…
Balbooa Forms 10.0 76.1% Jul 10, 2026
10 CVE-2026-50522
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Microsoft SharePoint 9.8 75.8% Jul 22, 2026
11 CVE-2026-16232
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application…
Check Point SmartConsole 9.1 70.0% Jul 22, 2026
12 CVE-2026-25089
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through…
Fortinet FortiSandbox 9.8 69.8% Jul 16, 2026
13 CVE-2026-0770
Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute…
Langflow Langflow 9.8 56.3% Jul 21, 2026
14 CVE-2008-4128
Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services…
Cisco IOS 4.3 33.0% Jul 13, 2026
15 CVE-2026-55255
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object Reference…
Langflow Langflow 8.4 29.1% Jul 7, 2026
Previous 30 days
#CVEVendor / ProductCVSSEPSSAdded to KEV
1 CVE-2026-10520
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution
Ivanti Sentry 10.0 99.9% Jun 11, 2026
2 CVE-2026-20253
In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary…
Splunk Enterprise 9.8 96.2% Jun 18, 2026
3 CVE-2026-35273
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are…
Oracle PeopleSoft Enterprise PeopleTools 9.8 95.5% Jun 12, 2026
4 CVE-2026-34910
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices…
Ubiquiti UniFi OS 10.0 87.0% Jun 23, 2026
5 CVE-2026-20230
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME)…
Cisco Unified Communications Manager 8.6 83.2% Jun 25, 2026
6 CVE-2026-50751
A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated…
Check Point Security Gateway 9.3 82.6% Jun 8, 2026
7 CVE-2026-48907
A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately…
Widget Factory Joomla Content Editor 10.0 80.4% Jun 16, 2026
8 CVE-2026-42271
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to…
BerriAI LiteLLM 8.8 80.2% Jun 8, 2026
9 CVE-2026-34908
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices…
Ubiquiti UniFi OS 10.0 58.4% Jun 23, 2026
10 CVE-2026-34909
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to…
Ubiquiti UniFi OS 10.0 56.9% Jun 23, 2026
11 CVE-2026-20262
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker…
Cisco Catalyst SD-WAN Manager 6.5 28.2% Jun 15, 2026
12 CVE-2026-45247
Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated…
Mirasvit Mirasvit Full Page Cache Warmer 9.8 27.5% Jun 3, 2026
13 CVE-2026-20245
A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage,…
Cisco Catalyst SD-WAN Manager 7.8 25.3% Jun 9, 2026
14 CVE-2025-67038
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when…
Lantronix EDS5000 9.8 14.3% Jun 23, 2026
15 CVE-2026-48558
SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When…
SimpleHelp SimpleHelp 10.0 11.5% Jun 29, 2026

Frequently Asked Questions

What does “actively exploited” mean?

It means attackers are using the vulnerability in real-world attacks right now, not just in theory. Confirmation comes from the CISA KEV catalog and our own CVE Watchtower tracking.

What is the CISA KEV catalog?

The Known Exploited Vulnerabilities (KEV) catalog is a list maintained by the U.S. Cybersecurity and Infrastructure Security Agency. It only includes CVEs with reliable evidence of exploitation in the wild, which makes it a strong patching baseline for any organization.

What is an EPSS score?

EPSS (Exploit Prediction Scoring System) estimates the probability that a vulnerability will be exploited within the next 30 days. A score of 90% means very high likelihood. We rank this list by EPSS because it reflects real-world risk better than severity alone.

How is this different from CVSS?

CVSS measures how severe a vulnerability could be if exploited. EPSS measures how likely exploitation actually is. A flaw can be critical on paper but rarely attacked, or moderate on paper yet heavily abused. We show both so defenders can prioritize correctly.

How often is this page updated?

The list refreshes automatically several times a day from the CISA KEV feed and our CVE Watchtower database. The “Last updated” line above the table shows the most recent refresh.

Should I patch everything on this list?

Yes, treat every entry as a priority. These CVEs are confirmed under active exploitation, so the usual “wait and assess” approach does not apply. If a patch is unavailable, apply the vendor’s mitigations immediately.

Can I cite or link to this list?

Yes. This page is free to reference in reports, advisories, and articles. Please credit Daily CyberSecurity and link back to this page so readers always see the current data.