Skip to content
Weekly Signal

Confirmed attacker activity

Exploited Now

Vulnerabilities with confirmed exploitation evidence, ranked by the Cornish Geek Signal.

Updated 20 Aug 2026 · 07:29 UTC

1671Confirmed exploited
1671In CISA KEV
349Linked to ransomware
1671Guidance available
Clear

Exploitation priorities

1671 matching vulnerabilities

85Fix now

Elastic, Redhat

CVE-2015-1427

Elasticsearch, Fuse

Known exploitation is confirmed by CISA KEV. The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.

EPSS
99.9%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

Aterm, Dlink +1 more

CVE-2014-8361

Dir-501 Firmware, Dir-515 Firmware, Dir-600l Firmware +24 more

Known exploitation is confirmed by CISA KEV. The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.

EPSS
100.0%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

Apple, Arista +15 more

CVE-2014-7169

Arx Firmware, Bash, Big-ip Access Policy Manager +72 more

Known exploitation is confirmed by CISA KEV. GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other…

EPSS
99.9%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

Rejetto

CVE-2014-6287

HTTP File Server, HTTP File Server (HFS)

Known exploitation is confirmed by CISA KEV. The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c allows remote attackers to execute arbitrary programs via a %00 sequence in a search action.

EPSS
99.3%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

Apple, Arista +15 more

CVE-2014-6271

Arx Firmware, Bash, Big-ip Access Policy Manager +72 more

Known exploitation is confirmed by CISA KEV. GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors…

EPSS
100.0%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

Adobe, Google +3 more

CVE-2014-0497

Chrome, Enterprise Linux Desktop, Enterprise Linux Eus +6 more

Known exploitation is confirmed by CISA KEV. Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote attackers to execute arbitrary code…

EPSS
99.9%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

Apache, Fujitsu +1 more

CVE-2013-2251

Archiva, Interstage Business Process Manager Analytics, Siebel Apps - E-billing +1 more

Known exploitation is confirmed by CISA KEV. Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix.

EPSS
100.0%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

Apple, Debian +6 more

CVE-2012-1823

Application Stack, Debian Linux, Enterprise Linux Desktop +14 more

Known exploitation is confirmed by CISA KEV. sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows…

EPSS
100.0%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

Canonical, Oracle +2 more

CVE-2011-3544

Java SE JDK and JRE, Jdk, Jre +4 more

Known exploitation is confirmed by CISA KEV. Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remote untrusted Java Web Start applications and untrusted Java…

EPSS
96.7%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

Microsoft

CVE-2008-4250

Windows, Windows 2000, Windows Server 2003 +3 more

Known exploitation is confirmed by CISA KEV. The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary…

EPSS
98.8%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

Al-enterprise, Alcatel

CVE-2007-3010

OmniPCX Enterprise, Omnipcx Enterprise Communication Server

Known exploitation is confirmed by CISA KEV. masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the user parameter during a ping…

EPSS
97.4%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

Microsoft

CVE-2013-0074

Silverlight

Known exploitation is confirmed by CISA KEV. Microsoft Silverlight 5, and 5 Developer Runtime, before 5.1.20125.0 does not properly validate pointers during HTML object rendering, which allows remote attackers to execute arbitrary code via a crafted Silverlight application, aka…

EPSS
81.9%
CVSS
7.8
Ransomware
Known
View evidence
84Investigate

Microsoft

CVE-2018-8174

Windows, Windows 10 1607, Windows 10 1703 +8 more

Known exploitation is confirmed by CISA KEV. A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012…

EPSS
88.5%
CVSS
7.5
Ransomware
Known
View evidence
84Investigate

Adobe, Redhat

CVE-2018-15982

Enterprise Linux Desktop, Enterprise Linux Server, Enterprise Linux Workstation +2 more

Known exploitation is confirmed by CISA KEV. Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

EPSS
82.5%
CVSS
7.8
Ransomware
Known
View evidence
84Investigate

Microsoft

CVE-2021-1675

Windows, Windows 10 1507, Windows 10 1607 +13 more

Known exploitation is confirmed by CISA KEV. Windows Print Spooler Remote Code Execution Vulnerability

EPSS
84.8%
CVSS
7.8
Ransomware
Known
View evidence
84Investigate

Microsoft

CVE-2019-0752

Internet Explorer

Known exploitation is confirmed by CISA KEV. A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from…

EPSS
81.6%
CVSS
7.5
Ransomware
Known
View evidence
84Investigate

Microsoft

CVE-2024-21413

365 Apps, Office 2016, Office 2019 +2 more

Known exploitation is confirmed by CISA KEV. Microsoft Outlook Remote Code Execution Vulnerability

EPSS
94.7%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

Microsoft

CVE-2022-41080

Exchange Server

Known exploitation is confirmed by CISA KEV. Microsoft Exchange Server Elevation of Privilege Vulnerability

EPSS
77.3%
CVSS
8.8
Ransomware
Known
View evidence
84Investigate

Adobe

CVE-2009-3960

BlazeDS, ColdFusion, Flex Data Services +2 more

Known exploitation is confirmed by CISA KEV. Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.0.1, and…

EPSS
90.0%
CVSS
6.5
Ransomware
Known
View evidence
84Investigate

Array Networks, Arraynetworks

CVE-2023-28461

AG/vxAG ArrayOS, Arrayos Ag

Known exploitation is confirmed by CISA KEV. Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in an HTTP…

EPSS
67.9%
CVSS
9.8
Ransomware
Known
View evidence
84Investigate

Apache

CVE-2026-34197

ActiveMQ, Activemq Broker

Known exploitation is confirmed by CISA KEV. Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console.…

EPSS
97.2%
CVSS
8.8
Ransomware
Not reported
View evidence
84Investigate

Palo Alto Networks, Paloaltonetworks

CVE-2024-9474

PAN-OS

Known exploitation is confirmed by CISA KEV. A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW…

EPSS
94.8%
CVSS
6.9
Ransomware
Known
View evidence
84Investigate

Apple, Fedoraproject +5 more

CVE-2022-2294

Chrome, Extra Packages For Enterprise Linux, Fedora +9 more

Known exploitation is confirmed by CISA KEV. Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

EPSS
70.5%
CVSS
8.8
Ransomware
Known
View evidence
84Investigate

Synacor

CVE-2022-27924

Zimbra Collaboration Suite, Zimbra Collaboration Suite (ZCS)

Known exploitation is confirmed by CISA KEV. Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance. These memcache commands becomes unescaped, causing an overwrite of arbitrary cached entries.

EPSS
85.4%
CVSS
7.5
Ransomware
Known
View evidence
84Investigate

Fortinet

CVE-2026-35616

FortiClient EMS, Forticlientems

Known exploitation is confirmed by CISA KEV. A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.

EPSS
90.7%
CVSS
9.8
Ransomware
Not reported
View evidence