Skip to content
Weekly Signal

Confirmed attacker activity

Exploited Now

Vulnerabilities with confirmed exploitation evidence, ranked by the Cornish Geek Signal.

Updated 20 Aug 2026 · 08:54 UTC

1671Confirmed exploited
1671In CISA KEV
349Linked to ransomware
1671Guidance available
Clear

Exploitation priorities

1671 matching vulnerabilities

84Investigate

Gladinet

CVE-2025-30406

CentreStack

Known exploitation is confirmed by CISA KEV. Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the CentreStack portal's hardcoded machineKey use, as exploited in the wild in March 2025. This enables threat actors (who…

EPSS
93.8%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

Kentico

CVE-2025-2747

Xperience, Xperience CMS

Known exploitation is confirmed by CISA KEV. An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server component password handling for the server defined None type. Authentication bypass allows an attacker to control administrative…

EPSS
92.2%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

Wazuh

CVE-2025-24016

Wazuh, Wazuh Server

Known exploitation is confirmed by CISA KEV. Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.4.0 and prior to version 4.9.1, an unsafe deserialization vulnerability allows for remote code…

EPSS
93.8%
CVSS
9.9
Ransomware
Not reported
View evidence
84Investigate

React Native Community

CVE-2025-11953

CLI, React Native Community Cli

Known exploitation is confirmed by CISA KEV. The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpoint that is vulnerable to OS command injection. This…

EPSS
94.0%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

Palo Alto Networks, Paloaltonetworks

CVE-2025-0108

PAN-OS

Known exploitation is confirmed by CISA KEV. An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to bypass the authentication otherwise required by the PAN-OS management…

EPSS
98.5%
CVSS
8.8
Ransomware
Not reported
View evidence
84Investigate

Palo Alto Networks, Paloaltonetworks

CVE-2024-9465

Expedition

Known exploitation is confirmed by CISA KEV. An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. With this, attackers…

EPSS
99.6%
CVSS
9.2
Ransomware
Not reported
View evidence
84Investigate

Ivanti

CVE-2024-8963

Cloud Services Appliance (CSA), Endpoint Manager Cloud Services Appliance

Known exploitation is confirmed by CISA KEV. Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.

EPSS
98.6%
CVSS
9.1
Ransomware
Not reported
View evidence
84Investigate

Samsung

CVE-2024-7399

MagicINFO 9 Server

Known exploitation is confirmed by CISA KEV. Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to write arbitrary file as system authority.

EPSS
91.9%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

Palo Alto Networks, Paloaltonetworks

CVE-2024-5910

Expedition

Known exploitation is confirmed by CISA KEV. Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attackers with network access to Expedition. Note: Expedition is a tool aiding…

EPSS
91.8%
CVSS
9.3
Ransomware
Not reported
View evidence
84Investigate

ServiceNow

CVE-2024-5217

Servicenow, Utah, Vancouver +1 more

Known exploitation is confirmed by CISA KEV. ServiceNow has addressed an input validation vulnerability that was identified in the Washington DC, Vancouver, and earlier Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within…

EPSS
99.6%
CVSS
9.2
Ransomware
Not reported
View evidence
84Investigate

Simple-help, SimpleHelp

CVE-2024-57726

SimpleHelp

Known exploitation is confirmed by CISA KEV. SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the…

EPSS
66.6%
CVSS
9.9
Ransomware
Known
View evidence
84Investigate

Craft CMS, Craftcms

CVE-2024-56145

Craft CMS

Known exploitation is confirmed by CISA KEV. Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Users of affected versions are affected by this vulnerability if their php.ini configuration has `register_argc_argv` enabled.…

EPSS
97.4%
CVSS
9.3
Ransomware
Not reported
View evidence
84Investigate

ServiceNow

CVE-2024-4879

Servicenow, Utah, Vancouver +1 more

Known exploitation is confirmed by CISA KEV. ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context…

EPSS
100.0%
CVSS
9.3
Ransomware
Not reported
View evidence
84Investigate

Fortinet

CVE-2024-47575

FortiManager, Fortimanager Cloud

Known exploitation is confirmed by CISA KEV. A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager 7.0.0 through 7.0.12, FortiManager 6.4.0 through 6.4.14, FortiManager 6.2.0 through 6.2.12, Fortinet FortiManager Cloud…

EPSS
95.0%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

Apache, Netapp +1 more

CVE-2024-38475

HTTP Server, Ontap 9, Sma 200 Firmware +4 more

Known exploitation is confirmed by CISA KEV. Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are…

EPSS
100.0%
CVSS
9.1
Ransomware
Not reported
View evidence
84Investigate

Ivanti

CVE-2024-29824

Endpoint Manager, Endpoint Manager (EPM)

Known exploitation is confirmed by CISA KEV. An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.

EPSS
100.0%
CVSS
8.8
Ransomware
Not reported
View evidence
84Investigate

Cisco

CVE-2024-20439

Smart License Utility, Smart Licensing Utility

Known exploitation is confirmed by CISA KEV. A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an affected system by using a static administrative credential. This vulnerability is due to an…

EPSS
92.1%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

BeyondTrust

CVE-2024-12356

Privileged Remote Access, Privileged Remote Access (PRA) and Remote Support (RS), Remote Support

Known exploitation is confirmed by CISA KEV. A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that are run as a site user.

EPSS
88.0%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

GitLab

CVE-2023-7028

GitLab, GitLab CE/EE

Known exploitation is confirmed by CISA KEV. An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6,…

EPSS
94.6%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

Digiever

CVE-2023-52163

DS-2105 Pro, Ds-2105 Pro+ Firmware

Known exploitation is confirmed by CISA KEV. Digiever DS-2105 Pro 3.1.0.71-11 devices allow time_tzsetup.cgi Command Injection. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

EPSS
96.9%
CVSS
8.8
Ransomware
Not reported
View evidence
84Investigate

Bandisoft, Bentley +7 more

CVE-2023-4863

Active Iq Unified Manager, Chrome, Chromium WebP +10 more

Known exploitation is confirmed by CISA KEV. Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium…

EPSS
99.7%
CVSS
8.8
Ransomware
Not reported
View evidence
84Investigate

Juniper

CVE-2023-36845

Junos, Junos OS

Known exploitation is confirmed by CISA KEV. A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series and SRX Series allows an unauthenticated, network-based attacker to remotely execute code. Using a crafted request…

EPSS
93.7%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

Barracuda, Barracuda Networks

CVE-2023-2868

Email Security Gateway (ESG) Appliance, Email Security Gateway 300 Firmware, Email Security Gateway 400 Firmware +3 more

Known exploitation is confirmed by CISA KEV. A remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor only) product effecting versions 5.1.3.001-9.2.0.006. The vulnerability arises out of a failure to comprehensively sanitize the processing…

EPSS
87.4%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

Microsoft

CVE-2023-24955

Sharepoint Enterprise Server, SharePoint Server

Known exploitation is confirmed by CISA KEV. Microsoft SharePoint Server Remote Code Execution Vulnerability

EPSS
85.4%
CVSS
7.2
Ransomware
Known
View evidence
84Investigate

Citrix

CVE-2023-24489

Content Collaboration, Sharefile Storage Zones Controller

Known exploitation is confirmed by CISA KEV. A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated attacker to remotely compromise the customer-managed ShareFile storage zones controller.

EPSS
94.4%
CVSS
9.8
Ransomware
Not reported
View evidence