This page tracks the vulnerabilities most actively exploited in the wild right now. Each entry is a CVE added to the CISA Known Exploited Vulnerabilities (KEV) catalog within the last 30 days and confirmed as under active exploitation by our CVE Watchtower. The list is ranked by EPSS score, which estimates the probability of exploitation, alongside CVSS severity. It refreshes automatically throughout the day. If you only have time to patch a few things this month, start here.
Last updated: September 10, 2026 · Source: CISA KEV + Daily CyberSecurity CVE Watchtower
| # | CVE | Vendor / Product | CVSS | EPSS | Added to KEV |
|---|---|---|---|---|---|
| 1 |
CVE-2026-60004
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
|
Gitea Gitea | 9.8 | 86.8% | Aug 25, 2026 |
| 2 |
CVE-2021-23758
All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary…
|
Ajax.NET Professional Ajax.NET Professional | 8.1 | 83.6% | Aug 26, 2026 |
| 3 |
CVE-2026-20079
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker…
|
Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management | 10.0 | 74.7% | Sep 9, 2026 |
| 4 |
CVE-2026-33824
Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.
|
Microsoft Internet Key Exchange (IKE) Service Extensions | 9.8 | 72.7% | Aug 18, 2026 |
| 5 |
CVE-2019-1068
A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft…
|
Microsoft SQL Server | 8.8 | 52.8% | Aug 26, 2026 |
| 6 |
CVE-2026-59310
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this…
|
Broadcom VMware vCenter | 9.8 | 45.9% | Aug 18, 2026 |
| 7 |
CVE-2023-49105
An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication…
|
ownCloud ownCloud | 9.8 | 43.2% | Aug 27, 2026 |
| 8 |
CVE-2026-21962
Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy…
|
Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in | 10.0 | 42.0% | Aug 24, 2026 |
| 9 |
CVE-2026-55040
Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.
|
Microsoft SharePoint | 9.1 | 39.7% | Aug 18, 2026 |
| 10 |
CVE-2026-48710
Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being…
|
Kludex Starlette | 6.5 | 36.3% | Sep 2, 2026 |
| 11 |
CVE-2026-73570
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and…
|
Synacor Zimbra Collaboration Suite (ZCS) | 8.9 | 32.4% | Aug 21, 2026 |
| 12 |
CVE-2025-62593
Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be…
|
Ray-Project Ray | 9.4 | 16.9% | Aug 17, 2026 |
| 13 |
CVE-2026-64849
MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0,…
|
MLflow MLflow | 9.3 | 16.4% | Aug 19, 2026 |
| 14 |
CVE-2026-9586
An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with and directly…
|
Sangoma Switchvox | 9.3 | 11.8% | Sep 2, 2026 |
| 15 |
CVE-2026-65400
An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9,…
|
Apple macOS | 9.8 | 9.9% | Aug 18, 2026 |
Previous 30 days
| # | CVE | Vendor / Product | CVSS | EPSS | Added to KEV |
|---|---|---|---|---|---|
| 1 |
CVE-2026-8037
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary…
|
Progress LoadMaster | 9.6 | 99.6% | Aug 7, 2026 |
| 2 |
CVE-2026-34486
Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor.…
|
Apache Tomcat | 7.5 | 98.6% | Aug 4, 2026 |
| 3 |
CVE-2026-63030
WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which,…
|
WordPress Core | 9.8 | 95.6% | Jul 21, 2026 |
| 4 |
CVE-2026-72898
Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to…
|
Metabase Metabase | 10.0 | 94.2% | Aug 11, 2026 |
| 5 |
CVE-2026-39808
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through…
|
Fortinet FortiSandbox | 9.8 | 91.2% | Jul 16, 2026 |
| 6 |
CVE-2026-63077
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
|
JetBrains TeamCity | 9.8 | 86.5% | Aug 5, 2026 |
| 7 |
CVE-2026-60137
WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query,…
|
WordPress Core | 5.9 | 78.3% | Jul 21, 2026 |
| 8 |
CVE-2026-50522
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
|
Microsoft SharePoint | 9.8 | 77.0% | Jul 22, 2026 |
| 9 |
CVE-2026-15410
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC)…
|
SonicWall SMA1000 Appliances | 7.2 | 76.3% | Jul 14, 2026 |
| 10 |
CVE-2026-15409
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker…
|
SonicWall SMA1000 Appliances | 10.0 | 74.2% | Jul 14, 2026 |
| 11 |
CVE-2026-25089
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through…
|
Fortinet FortiSandbox | 9.8 | 73.6% | Jul 16, 2026 |
| 12 |
CVE-2026-16232
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application…
|
Check Point SmartConsole | 9.1 | 73.3% | Jul 22, 2026 |
| 13 |
CVE-2026-9198
IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with…
|
IBM Langflow | 9.8 | 60.6% | Aug 4, 2026 |
| 14 |
CVE-2026-0770
Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute…
|
Langflow Langflow | 9.8 | 56.9% | Jul 21, 2026 |
| 15 |
CVE-2026-18577
An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1
|
N-able N-central | 8.2 | 54.1% | Aug 3, 2026 |
Frequently Asked Questions
What does “actively exploited” mean?
It means attackers are using the vulnerability in real-world attacks right now, not just in theory. Confirmation comes from the CISA KEV catalog and our own CVE Watchtower tracking.
What is the CISA KEV catalog?
The Known Exploited Vulnerabilities (KEV) catalog is a list maintained by the U.S. Cybersecurity and Infrastructure Security Agency. It only includes CVEs with reliable evidence of exploitation in the wild, which makes it a strong patching baseline for any organization.
What is an EPSS score?
EPSS (Exploit Prediction Scoring System) estimates the probability that a vulnerability will be exploited within the next 30 days. A score of 90% means very high likelihood. We rank this list by EPSS because it reflects real-world risk better than severity alone.
How is this different from CVSS?
CVSS measures how severe a vulnerability could be if exploited. EPSS measures how likely exploitation actually is. A flaw can be critical on paper but rarely attacked, or moderate on paper yet heavily abused. We show both so defenders can prioritize correctly.
How often is this page updated?
The list refreshes automatically several times a day from the CISA KEV feed and our CVE Watchtower database. The “Last updated” line above the table shows the most recent refresh.
Should I patch everything on this list?
Yes, treat every entry as a priority. These CVEs are confirmed under active exploitation, so the usual “wait and assess” approach does not apply. If a patch is unavailable, apply the vendor’s mitigations immediately.
Can I cite or link to this list?
Yes. This page is free to reference in reports, advisories, and articles. Please credit Daily CyberSecurity and link back to this page so readers always see the current data.