Skip to content
Weekly Signal

Confirmed attacker activity

Exploited Now

Vulnerabilities with confirmed exploitation evidence, ranked by the Cornish Geek Signal.

Updated 20 Aug 2026 · 08:13 UTC

1671Confirmed exploited
1671In CISA KEV
349Linked to ransomware
1671Guidance available
Clear

Exploitation priorities

1671 matching vulnerabilities

84Investigate

Ubiquiti, Ui

CVE-2026-34910

Enterprise Fortress Gateway Firmware, Enterprise Network Video Recorder Core Firmware, Enterprise Network Video Recorder Firmware +29 more

Known exploitation is confirmed by CISA KEV. A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.

EPSS
87.0%
CVSS
10.0
Ransomware
Not reported
View evidence
84Investigate

Ubiquiti, Ui

CVE-2026-34908

Enterprise Fortress Gateway Firmware, Enterprise Network Video Recorder Core Firmware, Enterprise Network Video Recorder Firmware +29 more

Known exploitation is confirmed by CISA KEV. A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.

EPSS
85.2%
CVSS
10.0
Ransomware
Not reported
View evidence
84Investigate

Drupal

CVE-2026-9082

Core, Drupal

Known exploitation is confirmed by CISA KEV. Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before…

EPSS
88.3%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

WordPress

CVE-2026-63030

Core, Wordpress

Known exploitation is confirmed by CISA KEV. WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker…

EPSS
95.6%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

Fortinet

CVE-2026-39808

FortiSandbox

Known exploitation is confirmed by CISA KEV. A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via

EPSS
91.2%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

ProjectSend

CVE-2024-11680

ProjectSend

Known exploitation is confirmed by CISA KEV. ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to options.php, enabling unauthorized modification of the application's…

EPSS
91.6%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

Progress

CVE-2024-1212

Kemp LoadMaster, LoadMaster

Known exploitation is confirmed by CISA KEV. Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.

EPSS
95.4%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

JoomShaper, Ollyo

CVE-2026-48908

SP Page Builder

Known exploitation is confirmed by CISA KEV. A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.

EPSS
88.1%
CVSS
10.0
Ransomware
Not reported
View evidence
84Investigate

Sangoma

CVE-2025-57819

FreePBX

Known exploitation is confirmed by CISA KEV. FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-supplied data allowing unauthenticated access to FreePBX Administrator leading to arbitrary database…

EPSS
88.3%
CVSS
10.0
Ransomware
Not reported
View evidence
84Investigate

Cisco

CVE-2026-20127

Catalyst SD-WAN Controller and Manager, Catalyst SD-WAN Manager, Sd-wan Vbond Orchestrator +1 more

Known exploitation is confirmed by CISA KEV. A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an…

EPSS
88.2%
CVSS
10.0
Ransomware
Not reported
View evidence
84Investigate

Cisco

CVE-2026-20182

Catalyst SD-WAN, Catalyst SD-WAN Manager, Sd-wan Vbond Orchestrator +1 more

Known exploitation is confirmed by CISA KEV. May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed in February 2026. This new advisory is for a…

EPSS
91.5%
CVSS
10.0
Ransomware
Not reported
View evidence
84Investigate

Coreweave, Marimo

CVE-2026-39987

Marimo

Known exploitation is confirmed by CISA KEV. marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability. The terminal WebSocket endpoint /terminal/ws lacks authentication validation, allowing an unauthenticated attacker to obtain a full PTY…

EPSS
96.6%
CVSS
9.3
Ransomware
Not reported
View evidence
84Investigate

Langflow

CVE-2026-33017

Langflow

Known exploitation is confirmed by CISA KEV. Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint allows building public flows without requiring authentication. When the optional data…

EPSS
96.2%
CVSS
9.3
Ransomware
Not reported
View evidence
84Investigate

Fortinet

CVE-2026-21643

FortiClient EMS, Forticlientems

Known exploitation is confirmed by CISA KEV. An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted…

EPSS
94.1%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

n8n

CVE-2025-68613

n8n

Known exploitation is confirmed by CISA KEV. n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4, 1.121.1, and 1.122.0 contain a critical Remote Code Execution (RCE) vulnerability in their workflow expression evaluation…

EPSS
98.0%
CVSS
8.8
Ransomware
Not reported
View evidence
84Investigate

Fortinet

CVE-2025-64446

FortiWeb

Known exploitation is confirmed by CISA KEV. A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an attacker to…

EPSS
91.8%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

Oracle

CVE-2025-61757

Fusion Middleware, Identity Manager

Known exploitation is confirmed by CISA KEV. Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via…

EPSS
88.3%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

CrushFTP

CVE-2025-54309

CrushFTP

Known exploitation is confirmed by CISA KEV. CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via HTTPS, as exploited…

EPSS
94.4%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

Adobe

CVE-2025-54253

Experience Manager (AEM) Forms, Experience Manager Forms

Known exploitation is confirmed by CISA KEV. Adobe Experience Manager versions 6.5.23 and earlier are affected by a Misconfiguration vulnerability that could result in arbitrary code execution. An attacker could leverage this vulnerability to bypass security mechanisms and execute…

EPSS
87.5%
CVSS
10.0
Ransomware
Not reported
View evidence
84Investigate

Adobe

CVE-2025-54236

Commerce, Commerce and Magento, Commerce B2b +1 more

Known exploitation is confirmed by CISA KEV. Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality,…

EPSS
94.5%
CVSS
9.1
Ransomware
Not reported
View evidence
84Investigate

Laravel

CVE-2025-54068

Livewire

Known exploitation is confirmed by CISA KEV. Livewire is a full-stack framework for Laravel. In Livewire v3 up to and including v3.6.3, a vulnerability allows unauthenticated attackers to achieve remote command execution in specific scenarios. The issue stems from…

EPSS
95.8%
CVSS
9.2
Ransomware
Not reported
View evidence
84Investigate

Debian, Roundcube

CVE-2025-49113

Debian Linux, Webmail

Known exploitation is confirmed by CISA KEV. Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.

EPSS
97.7%
CVSS
8.8
Ransomware
Not reported
View evidence
84Investigate

Control-webpanel, CWP

CVE-2025-48703

Control Web Panel, Webpanel

Known exploitation is confirmed by CISA KEV. CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager changePerm request. A valid non-root username…

EPSS
99.6%
CVSS
9.0
Ransomware
Not reported
View evidence
84Investigate

Hewlett Packard Enterprise (HPE), Hpe

CVE-2025-37164

OneView

Known exploitation is confirmed by CISA KEV. A remote code execution issue exists in HPE OneView.

EPSS
90.2%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

Commvault

CVE-2025-34028

Command Center, Commvault

Known exploitation is confirmed by CISA KEV. The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expanded by the target server, are vulnerable to path traversal vulnerability that…

EPSS
97.7%
CVSS
9.3
Ransomware
Not reported
View evidence