Skip to content
Weekly Signal

Confirmed attacker activity

Exploited Now

Vulnerabilities with confirmed exploitation evidence, ranked by the Cornish Geek Signal.

Updated 19 Aug 2026 · 23:00 UTC

1670Confirmed exploited
1670In CISA KEV
349Linked to ransomware
1670Guidance available
Clear

Exploitation priorities

1670 matching vulnerabilities

88Fix now

Adobe

CVE-2010-2861

Coldfusion

Known exploitation is confirmed by CISA KEV. Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read arbitrary files via the locale parameter to (1) CFIDE/administrator/settings/mappings.cfm, (2) logging/settings.cfm, (3) datasources/index.cfm,…

EPSS
99.7%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Debian, Oracle +2 more

CVE-2012-0507

Debian Linux, Java SE, Jre +4 more

Known exploitation is confirmed by CISA KEV. Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers…

EPSS
98.1%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Debian, Drupal

CVE-2018-7602

Core, Debian Linux, Drupal

Known exploitation is confirmed by CISA KEV. A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the…

EPSS
99.2%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Vmware

CVE-2021-21985

Cloud Foundation, Vcenter Server

Known exploitation is confirmed by CISA KEV. The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A…

EPSS
100.0%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Vmware

CVE-2021-21972

Cloud Foundation, Vcenter Server

Known exploitation is confirmed by CISA KEV. The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with…

EPSS
99.5%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Microsoft

CVE-2020-0796

SMBv3, Windows 10 1903, Windows 10 1909 +2 more

Known exploitation is confirmed by CISA KEV. A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'.

EPSS
99.8%
CVSS
10.0
Ransomware
Known
View evidence
88Fix now

Oracle

CVE-2019-2725

Agile Plm, Communications Converged Application Server, Peoplesoft Enterprise Peopletools +5 more

Known exploitation is confirmed by CISA KEV. Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access…

EPSS
100.0%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Citrix

CVE-2019-19781

Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance +3 more

Known exploitation is confirmed by CISA KEV. An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.

EPSS
100.0%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Apache, Apple +10 more

CVE-2021-44228

6bk1602-0aa12-0tp0 Firmware, 6bk1602-0aa22-0tp0 Firmware, 6bk1602-0aa32-0tp0 Firmware +140 more

Known exploitation is confirmed by CISA KEV. Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related…

EPSS
100.0%
CVSS
10.0
Ransomware
Known
View evidence
88Fix now

Rejetto

CVE-2024-23692

Http File Server

Known exploitation is confirmed by CISA KEV. Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands on the affected system…

EPSS
99.5%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Microsoft

CVE-2021-38647

Azure Automation State Configuration, Azure Automation Update Management, Azure Diagnostics (lad) +8 more

Known exploitation is confirmed by CISA KEV. Open Management Infrastructure (OMI) Remote Code Execution Vulnerability

EPSS
99.9%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Fortinet

CVE-2022-40684

Fortios, Fortiproxy, Fortiswitchmanager +1 more

Known exploitation is confirmed by CISA KEV. An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version…

EPSS
100.0%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Webmin

CVE-2019-15107

Webmin

Known exploitation is confirmed by CISA KEV. An issue was discovered in Webmin

EPSS
99.8%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Gitlab

CVE-2021-22205

Community and Enterprise Editions, Gitlab

Known exploitation is confirmed by CISA KEV. An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a…

EPSS
99.7%
CVSS
10.0
Ransomware
Known
View evidence
88Fix now

Oracle, Redhat

CVE-2012-4681

Enterprise Linux Desktop, Enterprise Linux Eus, Enterprise Linux Server +4 more

Known exploitation is confirmed by CISA KEV. Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager…

EPSS
98.5%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Fortinet

CVE-2024-55591

Fortios, FortiOS and FortiProxy, Fortiproxy

Known exploitation is confirmed by CISA KEV. An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain…

EPSS
98.3%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Citrix

CVE-2023-3519

NetScaler ADC and NetScaler Gateway, Netscaler Application Delivery Controller, Netscaler Gateway

Known exploitation is confirmed by CISA KEV. Unauthenticated remote code execution

EPSS
99.7%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Ivanti

CVE-2023-35078

Endpoint Manager Mobile, Endpoint Manager Mobile (EPMM)

Known exploitation is confirmed by CISA KEV. An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication.

EPSS
100.0%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Oracle

CVE-2025-61882

Concurrent Processing, E-business Suite

Known exploitation is confirmed by CISA KEV. Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via…

EPSS
99.7%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Facebook, Meta +1 more

CVE-2025-55182

Next.js, React, React Server Components

Known exploitation is confirmed by CISA KEV. A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from…

EPSS
99.6%
CVSS
10.0
Ransomware
Known
View evidence
88Fix now

Microsoft

CVE-2025-53770

SharePoint, Sharepoint Server

Known exploitation is confirmed by CISA KEV. Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft…

EPSS
100.0%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Sap

CVE-2025-31324

Netweaver

Known exploitation is confirmed by CISA KEV. SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly…

EPSS
99.5%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Ivanti

CVE-2025-22457

Connect Secure, Policy Secure, and ZTA Gateways +1 more

Known exploitation is confirmed by CISA KEV. A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to achieve remote…

EPSS
100.0%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Fortra

CVE-2025-10035

Goanywhere Managed File Transfer, GoAnywhere MFT

Known exploitation is confirmed by CISA KEV. A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.

EPSS
99.6%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Ivanti

CVE-2021-44529

Endpoint Manager Cloud Service Appliance (EPM CSA), Endpoint Manager Cloud Services Appliance

Known exploitation is confirmed by CISA KEV. A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).

EPSS
99.1%
CVSS
9.8
Ransomware
Known
View evidence