Skip to content
Weekly Signal

Confirmed attacker activity

Exploited Now

Vulnerabilities with confirmed exploitation evidence, ranked by the Cornish Geek Signal.

Updated 20 Aug 2026 · 10:54 UTC

1671Confirmed exploited
1671In CISA KEV
349Linked to ransomware
1671Guidance available
Clear

Exploitation priorities

1671 matching vulnerabilities

84Investigate

Oracle

CVE-2015-4852

Storagetek Tape Analytics Sw Tool, Virtual Desktop Infrastructure, WebLogic Server

Known exploitation is confirmed by CISA KEV. The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands via a crafted serialized Java object in T3 protocol traffic to TCP…

EPSS
96.0%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

D-Link, Dlink

CVE-2015-2051

Dir-645 Firmware, DIR-645 Router

Known exploitation is confirmed by CISA KEV. The D-Link DIR-645 Wired/Wireless Router Rev. Ax with firmware 1.04b12 and earlier allows remote attackers to execute arbitrary commands via a GetDeviceSettings action to the HNAP interface.

EPSS
96.9%
CVSS
8.8
Ransomware
Not reported
View evidence
84Investigate

Adobe, Microsoft +2 more

CVE-2015-0313

Edge, Evergreen, Flash Player +4 more

Known exploitation is confirmed by CISA KEV. Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote attackers to execute arbitrary code via…

EPSS
95.7%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

GNU

CVE-2014-6278

Bash, GNU Bash

Known exploitation is confirmed by CISA KEV. GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary commands via a crafted environment, as demonstrated by…

EPSS
99.6%
CVSS
8.8
Ransomware
Not reported
View evidence
84Investigate

Microsoft

CVE-2014-1776

Internet Explorer

Known exploitation is confirmed by CISA KEV. Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to the CMarkup::IsConnectedToPrimaryMarkup function, as…

EPSS
88.0%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

Microsoft

CVE-2013-2551

Internet Explorer

Known exploitation is confirmed by CISA KEV. Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, as demonstrated by VUPEN…

EPSS
74.1%
CVSS
8.8
Ransomware
Known
View evidence
84Investigate

Adobe

CVE-2013-0632

ColdFusion

Known exploitation is confirmed by CISA KEV. administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitrary code by logging in to the RDS component using the default empty password…

EPSS
93.7%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

Adobe

CVE-2013-0625

ColdFusion

Known exploitation is confirmed by CISA KEV. Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly execute arbitrary code via unspecified vectors, as exploited in the wild in…

EPSS
93.8%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

Oracle, Suse

CVE-2012-5076

Java SE, Jre, Linux Enterprise Desktop

Known exploitation is confirmed by CISA KEV. Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to JAX-WS.

EPSS
91.0%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

Oracle

CVE-2012-3152

Fusion Middleware

Known exploitation is confirmed by CISA KEV. Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and 11.1.2.0 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Report Server Component.…

EPSS
98.8%
CVSS
9.1
Ransomware
Not reported
View evidence
84Investigate

Microsoft

CVE-2012-0158

Biztalk Server, Commerce Server, Commerce Server 2009 +8 more

Known exploitation is confirmed by CISA KEV. The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1;…

EPSS
100.0%
CVSS
8.8
Ransomware
Not reported
View evidence
84Investigate

Canonical, Opensuse +1 more

CVE-2010-0840

Java Runtime Environment (JRE), Jre, Opensuse +1 more

Known exploitation is confirmed by CISA KEV. Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and…

EPSS
96.3%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

Debian, phpMyAdmin

CVE-2009-1151

Debian Linux, phpMyAdmin

Known exploitation is confirmed by CISA KEV. Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inject arbitrary PHP code into a configuration file via the save action.

EPSS
95.4%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

Adobe

CVE-2009-0927

Acrobat Reader, Reader and Acrobat

Known exploitation is confirmed by CISA KEV. Stack-based buffer overflow in Adobe Reader and Adobe Acrobat 9 before 9.1, 8 before 8.1.3 , and 7 before 7.1.1 allows remote attackers to execute arbitrary code via a crafted argument to…

EPSS
96.6%
CVSS
8.8
Ransomware
Not reported
View evidence
83Investigate

Microsoft

CVE-2021-42287

Active Directory, Windows Server 2004, Windows Server 2008 +5 more

Known exploitation is confirmed by CISA KEV. Active Directory Domain Services Elevation of Privilege Vulnerability

EPSS
74.3%
CVSS
7.5
Ransomware
Known
View evidence
83Investigate

Microsoft

CVE-2023-21529

Exchange Server

Known exploitation is confirmed by CISA KEV. Microsoft Exchange Server Remote Code Execution Vulnerability

EPSS
62.1%
CVSS
8.8
Ransomware
Known
View evidence
83Investigate

Microsoft

CVE-2026-33824

Internet Key Exchange (IKE) Service Extensions, Windows 10 1607, Windows 10 1809 +11 more

Known exploitation is confirmed by CISA KEV. Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.

EPSS
77.9%
CVSS
9.8
Ransomware
Not reported
View evidence
83Investigate

Microsoft

CVE-2018-8453

Win32k, Windows 10 1507, Windows 10 1607 +13 more

Known exploitation is confirmed by CISA KEV. An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012…

EPSS
70.0%
CVSS
7.8
Ransomware
Known
View evidence
83Investigate

VMware

CVE-2021-21975

Cloud Foundation, Vrealize Operations Manager, vRealize Operations Manager API +1 more

Known exploitation is confirmed by CISA KEV. Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side…

EPSS
78.3%
CVSS
7.5
Ransomware
Known
View evidence
83Investigate

Microsoft

CVE-2021-1732

Win32k, Windows 10 1803, Windows 10 1809 +7 more

Known exploitation is confirmed by CISA KEV. Windows Win32k Elevation of Privilege Vulnerability

EPSS
77.8%
CVSS
7.8
Ransomware
Known
View evidence
83Investigate

Microsoft

CVE-2019-1458

Win32k, Windows 10 1507, Windows 10 1607 +6 more

Known exploitation is confirmed by CISA KEV. An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.

EPSS
73.9%
CVSS
7.8
Ransomware
Known
View evidence
83Investigate

Cisco

CVE-2020-3580

Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD), Adaptive Security Appliance Software, Secure Firewall Threat Defense

Known exploitation is confirmed by CISA KEV. Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS)…

EPSS
85.6%
CVSS
6.1
Ransomware
Known
View evidence
83Investigate

Akka, Amazon +31 more

CVE-2023-44487

.net, 3scale Api Management Platform, Advanced Cluster Management For Kubernetes +162 more

Known exploitation is confirmed by CISA KEV. The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

EPSS
100.0%
CVSS
7.5
Ransomware
Not reported
View evidence
83Investigate

Cisco

CVE-2018-0296

Adaptive Security Appliance (ASA), Adaptive Security Appliance Software, Firepower Threat Defense +1 more

Known exploitation is confirmed by CISA KEV. A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of…

EPSS
99.9%
CVSS
7.5
Ransomware
Not reported
View evidence
83Investigate

Cisco

CVE-2020-3452

Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD), Adaptive Security Appliance Software, Secure Firewall Threat Defense

Known exploitation is confirmed by CISA KEV. A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks…

EPSS
100.0%
CVSS
7.5
Ransomware
Not reported
View evidence