Critical Alert 4 Active Exploits Detected Today

CVE-2026-19490 Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability →
CVE-2025-25249 Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability →
CVE-2026-87491 Google Chromium V8 Out of Bounds Write Vulnerability →
CVE-2026-20079 Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability →
Powered by CVE Watchtower
×

Top Exploited CVEs This Month

most exploited vulnerabilities, actively exploited CVEs

This page tracks the vulnerabilities most actively exploited in the wild right now. Each entry is a CVE added to the CISA Known Exploited Vulnerabilities (KEV) catalog within the last 30 days and confirmed as under active exploitation by our CVE Watchtower. The list is ranked by EPSS score, which estimates the probability of exploitation, alongside CVSS severity. It refreshes automatically throughout the day. If you only have time to patch a few things this month, start here.

Last updated: September 10, 2026 · Source: CISA KEV + Daily CyberSecurity CVE Watchtower

#CVEVendor / ProductCVSSEPSSAdded to KEV
1 CVE-2026-60004
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
Gitea Gitea 9.8 86.8% Aug 25, 2026
2 CVE-2021-23758
All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary…
Ajax.NET Professional Ajax.NET Professional 8.1 83.6% Aug 26, 2026
3 CVE-2026-20079
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker…
Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management 10.0 74.7% Sep 9, 2026
4 CVE-2026-33824
Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.
Microsoft Internet Key Exchange (IKE) Service Extensions 9.8 72.7% Aug 18, 2026
5 CVE-2019-1068
A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft…
Microsoft SQL Server 8.8 52.8% Aug 26, 2026
6 CVE-2026-59310
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this…
Broadcom VMware vCenter 9.8 45.9% Aug 18, 2026
7 CVE-2023-49105
An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication…
ownCloud ownCloud 9.8 43.2% Aug 27, 2026
8 CVE-2026-21962
Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy…
Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in 10.0 42.0% Aug 24, 2026
9 CVE-2026-55040
Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.
Microsoft SharePoint 9.1 39.7% Aug 18, 2026
10 CVE-2026-48710
Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being…
Kludex Starlette 6.5 36.3% Sep 2, 2026
11 CVE-2026-73570
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and…
Synacor Zimbra Collaboration Suite (ZCS) 8.9 32.4% Aug 21, 2026
12 CVE-2025-62593
Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be…
Ray-Project Ray 9.4 16.9% Aug 17, 2026
13 CVE-2026-64849
MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0,…
MLflow MLflow 9.3 16.4% Aug 19, 2026
14 CVE-2026-9586
An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with and directly…
Sangoma Switchvox 9.3 11.8% Sep 2, 2026
15 CVE-2026-65400
An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9,…
Apple macOS 9.8 9.9% Aug 18, 2026
Previous 30 days
#CVEVendor / ProductCVSSEPSSAdded to KEV
1 CVE-2026-8037
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary…
Progress LoadMaster 9.6 99.6% Aug 7, 2026
2 CVE-2026-34486
Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor.…
Apache Tomcat 7.5 98.6% Aug 4, 2026
3 CVE-2026-63030
WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which,…
WordPress Core 9.8 95.6% Jul 21, 2026
4 CVE-2026-72898
Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to…
Metabase Metabase 10.0 94.2% Aug 11, 2026
5 CVE-2026-39808
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through…
Fortinet FortiSandbox 9.8 91.2% Jul 16, 2026
6 CVE-2026-63077
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
JetBrains TeamCity 9.8 86.5% Aug 5, 2026
7 CVE-2026-60137
WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query,…
WordPress Core 5.9 78.3% Jul 21, 2026
8 CVE-2026-50522
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Microsoft SharePoint 9.8 77.0% Jul 22, 2026
9 CVE-2026-15410
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC)…
SonicWall SMA1000 Appliances 7.2 76.3% Jul 14, 2026
10 CVE-2026-15409
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker…
SonicWall SMA1000 Appliances 10.0 74.2% Jul 14, 2026
11 CVE-2026-25089
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through…
Fortinet FortiSandbox 9.8 73.6% Jul 16, 2026
12 CVE-2026-16232
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application…
Check Point SmartConsole 9.1 73.3% Jul 22, 2026
13 CVE-2026-9198
IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with…
IBM Langflow 9.8 60.6% Aug 4, 2026
14 CVE-2026-0770
Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute…
Langflow Langflow 9.8 56.9% Jul 21, 2026
15 CVE-2026-18577
An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1
N-able N-central 8.2 54.1% Aug 3, 2026

Frequently Asked Questions

What does “actively exploited” mean?

It means attackers are using the vulnerability in real-world attacks right now, not just in theory. Confirmation comes from the CISA KEV catalog and our own CVE Watchtower tracking.

What is the CISA KEV catalog?

The Known Exploited Vulnerabilities (KEV) catalog is a list maintained by the U.S. Cybersecurity and Infrastructure Security Agency. It only includes CVEs with reliable evidence of exploitation in the wild, which makes it a strong patching baseline for any organization.

What is an EPSS score?

EPSS (Exploit Prediction Scoring System) estimates the probability that a vulnerability will be exploited within the next 30 days. A score of 90% means very high likelihood. We rank this list by EPSS because it reflects real-world risk better than severity alone.

How is this different from CVSS?

CVSS measures how severe a vulnerability could be if exploited. EPSS measures how likely exploitation actually is. A flaw can be critical on paper but rarely attacked, or moderate on paper yet heavily abused. We show both so defenders can prioritize correctly.

How often is this page updated?

The list refreshes automatically several times a day from the CISA KEV feed and our CVE Watchtower database. The “Last updated” line above the table shows the most recent refresh.

Should I patch everything on this list?

Yes, treat every entry as a priority. These CVEs are confirmed under active exploitation, so the usual “wait and assess” approach does not apply. If a patch is unavailable, apply the vendor’s mitigations immediately.

Can I cite or link to this list?

Yes. This page is free to reference in reports, advisories, and articles. Please credit Daily CyberSecurity and link back to this page so readers always see the current data.