Skip to content
Weekly Signal

Confirmed attacker activity

Exploited Now

Vulnerabilities with confirmed exploitation evidence, ranked by the Cornish Geek Signal.

Updated 20 Aug 2026 · 09:30 UTC

1671Confirmed exploited
1671In CISA KEV
349Linked to ransomware
1671Guidance available
Clear

Exploitation priorities

1671 matching vulnerabilities

84Investigate

TP-Link

CVE-2023-1389

Archer AX21, Archer Ax21 Firmware

Known exploitation is confirmed by CISA KEV. TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form of the /cgi-bin/luci;stok=/locale endpoint on the web management interface. Specifically, the country parameter…

EPSS
100.0%
CVSS
8.8
Ransomware
Not reported
View evidence
84Investigate

Hitachi, Hitachi Vantara

CVE-2022-43939

Pentaho Business Analytics (BA) Server, Vantara Pentaho Business Analytics Server

Known exploitation is confirmed by CISA KEV. Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x contain security restrictions using non-canonical URLs which can be circumvented.

EPSS
92.3%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

Synacor

CVE-2022-41352

Zimbra Collaboration Suite, Zimbra Collaboration Suite (ZCS)

Known exploitation is confirmed by CISA KEV. An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access…

EPSS
95.5%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

Atlassian

CVE-2022-36804

Bitbucket, Bitbucket Server and Data Center

Known exploitation is confirmed by CISA KEV. Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from version 7.18.0 before version 7.21.4, from version 8.0.0 before version 8.0.3,…

EPSS
99.1%
CVSS
8.8
Ransomware
Not reported
View evidence
84Investigate

Mitel

CVE-2022-26143

MiCollab, MiVoice Business Express, Mivoice Business Express

Known exploitation is confirmed by CISA KEV. The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain sensitive information and cause a denial of service (performance…

EPSS
87.2%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

Terra-master, TerraMaster

CVE-2022-24990

Terramaster Operating System, TerraMaster OS

Known exploitation is confirmed by CISA KEV. TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to module/api.php?mobile/webNasIPS and then reading the PWD field in the response.

EPSS
83.4%
CVSS
7.5
Ransomware
Known
View evidence
84Investigate

Apache

CVE-2022-24706

CouchDB

Known exploitation is confirmed by CISA KEV. In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommendations for properly securing an…

EPSS
92.4%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

Apache

CVE-2022-24112

APISIX

Known exploitation is confirmed by CISA KEV. An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX (with default API key) is vulnerable to remote…

EPSS
96.0%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

Zabbix

CVE-2022-23131

Frontend, Zabbix

Known exploitation is confirmed by CISA KEV. In the case of instances where the SAML SSO authentication is enabled (non-default), session data can be modified by a malicious actor, because a user login stored in the session was not…

EPSS
95.7%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

Zoho, Zohocorp

CVE-2021-44077

Manageengine Servicedesk Plus, ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus, Manageengine Servicedesk Plus Msp +1 more

Known exploitation is confirmed by CISA KEV. Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution. This is related to /RestAPI URLs in a servlet,…

EPSS
93.3%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

Aviatrix

CVE-2021-40870

Aviatrix Controller, Controller

Known exploitation is confirmed by CISA KEV. An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory…

EPSS
93.0%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

Oracle

CVE-2021-35587

Access Manager, Fusion Middleware

Known exploitation is confirmed by CISA KEV. Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported versions that are affected are 11.1.2.3.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network…

EPSS
96.3%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

Veritas

CVE-2021-27877

Backup Exec, Backup Exec Agent

Known exploitation is confirmed by CISA KEV. An issue was discovered in Veritas Backup Exec before 21.2. It supports multiple authentication schemes: SHA authentication is one of these. This authentication scheme is no longer used in current versions of…

EPSS
64.9%
CVSS
9.8
Ransomware
Known
View evidence
84Investigate

EyesOfNetwork

CVE-2020-8657

EyesOfNetwork

Known exploitation is confirmed by CISA KEV. An issue was discovered in EyesOfNetwork 5.3. The installation uses the same API key (hardcoded as EONAPI_KEY in include/api_functions.php for API version 2.4.2) by default for all installations, hence allowing an attacker…

EPSS
91.9%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

Unraid

CVE-2020-5847

Unraid

Known exploitation is confirmed by CISA KEV. Unraid through 6.8.0 allows Remote Code Execution.

EPSS
95.8%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

VMware

CVE-2020-3952

vCenter Server

Known exploitation is confirmed by CISA KEV. Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does not correctly implement access controls.

EPSS
90.4%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

Oracle

CVE-2020-2883

WebLogic Server

Known exploitation is confirmed by CISA KEV. Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network…

EPSS
94.9%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

Oracle

CVE-2020-2551

Fusion Middleware, WebLogic Server

Known exploitation is confirmed by CISA KEV. Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker…

EPSS
93.2%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

Zyxel

CVE-2020-29583

Atp100 Firmware, Atp100w Firmware, Atp200 Firmware +28 more

Known exploitation is confirmed by CISA KEV. Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can be found in cleartext in the firmware. This account can…

EPSS
90.2%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

Apache

CVE-2020-1956

Kylin

Known exploitation is confirmed by CISA KEV. Apache Kylin 2.3.0, and releases up to 2.6.5 and 3.0.1 has some restful apis which will concatenate os command with the user input string, a user is likely to be able to…

EPSS
97.3%
CVSS
8.8
Ransomware
Not reported
View evidence
84Investigate

Canonical, Debian +6 more

CVE-2020-1472

Debian Linux, Directory Server, Fedora +13 more

Known exploitation is confirmed by CISA KEV. An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successfully exploited the…

EPSS
99.5%
CVSS
5.5
Ransomware
Known
View evidence
84Investigate

Microsoft

CVE-2020-1350

Windows, Windows Server 2008, Windows Server 2012 +2 more

Known exploitation is confirmed by CISA KEV. A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle requests, aka 'Windows DNS Server Remote Code Execution Vulnerability'.

EPSS
91.4%
CVSS
10.0
Ransomware
Not reported
View evidence
84Investigate

Apache, Oracle

CVE-2020-17530

Business Intelligence, Communications Diameter Intelligence Hub, Communications Policy Management +5 more

Known exploitation is confirmed by CISA KEV. Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25.

EPSS
95.6%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

vBulletin

CVE-2020-17496

vBulletin

Known exploitation is confirmed by CISA KEV. vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. NOTE: this issue exists because of an incomplete fix for CVE-2019-16759.

EPSS
87.7%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

Fuel CMS, Thedaylightstudio

CVE-2020-17463

Fuel CMS

Known exploitation is confirmed by CISA KEV. FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items.

EPSS
90.0%
CVSS
9.8
Ransomware
Not reported
View evidence