Skip to content
Weekly Signal

Confirmed attacker activity

Exploited Now

Vulnerabilities with confirmed exploitation evidence, ranked by the Cornish Geek Signal.

Updated 20 Aug 2026 · 11:25 UTC

1671Confirmed exploited
1671In CISA KEV
349Linked to ransomware
1671Guidance available
Clear

Exploitation priorities

1671 matching vulnerabilities

83Investigate

WatchGuard

CVE-2025-9242

Firebox, Fireware

Known exploitation is confirmed by CISA KEV. An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and…

EPSS
91.3%
CVSS
9.3
Ransomware
Not reported
View evidence
83Investigate

Mitel

CVE-2022-29499

MiVoice Connect

Known exploitation is confirmed by CISA KEV. The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The Service Appliances are SA 100, SA 400, and Virtual SA.

EPSS
55.4%
CVSS
9.8
Ransomware
Known
View evidence
83Investigate

Qlik

CVE-2023-41266

Qlik Sense, Sense

Known exploitation is confirmed by CISA KEV. A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and…

EPSS
82.1%
CVSS
6.5
Ransomware
Known
View evidence
83Investigate

Amazon, Arista +8 more

CVE-2026-31431

Amazon Linux, Basesystem Module, Caas Platform +41 more

Known exploitation is confirmed by CISA KEV. In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is…

EPSS
99.9%
CVSS
7.8
Ransomware
Not reported
View evidence
83Investigate

Joomlack

CVE-2026-56290

Page Builder, Page Builder Ck

Known exploitation is confirmed by CISA KEV. Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows…

EPSS
83.3%
CVSS
10.0
Ransomware
Not reported
View evidence
83Investigate

SonicWall

CVE-2026-15410

SMA1000 Appliances, Sma6210 Firmware, Sma7210 Firmware +1 more

Known exploitation is confirmed by CISA KEV. Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as…

EPSS
76.3%
CVSS
7.2
Ransomware
Known
View evidence
83Investigate

BerriAI, Litellm

CVE-2026-42208

LiteLLM

Known exploitation is confirmed by CISA KEV. LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query used during proxy API key checks…

EPSS
89.4%
CVSS
9.3
Ransomware
Not reported
View evidence
83Investigate

Langflow

CVE-2025-34291

Langflow

Known exploitation is confirmed by CISA KEV. Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS configuration (allow_origins='*' with allow_credentials=True) combined with a refresh token…

EPSS
83.8%
CVSS
9.4
Ransomware
Not reported
View evidence
83Investigate

iCagenda, Joomlic

CVE-2026-48939

iCagenda

Known exploitation is confirmed by CISA KEV. A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

EPSS
82.5%
CVSS
10.0
Ransomware
Not reported
View evidence
83Investigate

D-Link, Dlink

CVE-2022-26258

DIR-820L, Dir-820l Firmware

Known exploitation is confirmed by CISA KEV. D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp.

EPSS
79.8%
CVSS
9.8
Ransomware
Not reported
View evidence
83Investigate

Citrix

CVE-2026-3055

NetScaler, Netscaler Application Delivery Controller, Netscaler Gateway

Known exploitation is confirmed by CISA KEV. Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread

EPSS
84.5%
CVSS
9.3
Ransomware
Not reported
View evidence
83Investigate

Fortinet, Siemens

CVE-2026-24858

Fortianalyzer, FortiManager, Fortinac-f +5 more

Known exploitation is confirmed by CISA KEV. An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiManager 7.6.0…

EPSS
85.8%
CVSS
9.8
Ransomware
Not reported
View evidence
83Investigate

Ivanti

CVE-2026-1340

Endpoint Manager Mobile, Endpoint Manager Mobile (EPMM)

Known exploitation is confirmed by CISA KEV. A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

EPSS
86.0%
CVSS
9.8
Ransomware
Not reported
View evidence
83Investigate

Ivanti

CVE-2026-1281

Endpoint Manager Mobile, Endpoint Manager Mobile (EPMM)

Known exploitation is confirmed by CISA KEV. A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

EPSS
81.5%
CVSS
9.8
Ransomware
Not reported
View evidence
83Investigate

3ds, Dassault Systèmes

CVE-2025-5086

DELMIA Apriso

Known exploitation is confirmed by CISA KEV. A deserialization of untrusted data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could lead to a remote code execution.

EPSS
89.8%
CVSS
9.0
Ransomware
Not reported
View evidence
83Investigate

Ivanti

CVE-2025-4427

Endpoint Manager Mobile, Endpoint Manager Mobile (EPMM)

Known exploitation is confirmed by CISA KEV. An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources without proper credentials via the API.

EPSS
99.9%
CVSS
7.5
Ransomware
Not reported
View evidence
83Investigate

Smartbedded

CVE-2025-4008

Meteobridge, Meteobridge Firmware, Meteobridge Vm

Known exploitation is confirmed by CISA KEV. The Meteobridge web interface let meteobridge administrator manage their weather station data collection and administer their meteobridge system through a web application written in CGI shell scripts and C. This web interface…

EPSS
94.2%
CVSS
8.7
Ransomware
Not reported
View evidence
83Investigate

SolarWinds

CVE-2025-40551

Web Help Desk

Known exploitation is confirmed by CISA KEV. SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the…

EPSS
83.6%
CVSS
9.8
Ransomware
Not reported
View evidence
83Investigate

Gladinet

CVE-2025-12480

Triofox

Known exploitation is confirmed by CISA KEV. Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even after setup is complete.

EPSS
90.5%
CVSS
9.1
Ransomware
Not reported
View evidence
83Investigate

Yiiframework

CVE-2024-58136

Yii

Known exploitation is confirmed by CISA KEV. Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025.

EPSS
84.6%
CVSS
9.8
Ransomware
Not reported
View evidence
83Investigate

NAKIVO

CVE-2024-48248

Backup & Replication Director, Backup and Replication

Known exploitation is confirmed by CISA KEV. NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /c/router (this may lead to remote code execution across the enterprise because PhysicalDiscovery has cleartext credentials).

EPSS
94.4%
CVSS
8.6
Ransomware
Not reported
View evidence
83Investigate

Apache

CVE-2024-45195

OFBiz

Known exploitation is confirmed by CISA KEV. Direct Request ('Forced Browsing') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade to version 18.12.16, which fixes the issue.

EPSS
100.0%
CVSS
7.5
Ransomware
Not reported
View evidence
83Investigate

SolarWinds

CVE-2024-28995

Serv-U

Known exploitation is confirmed by CISA KEV. SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine.

EPSS
99.6%
CVSS
7.5
Ransomware
Not reported
View evidence
83Investigate

SolarWinds

CVE-2024-28986

Web Help Desk

Known exploitation is confirmed by CISA KEV. SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. While…

EPSS
84.6%
CVSS
9.8
Ransomware
Not reported
View evidence
83Investigate

SolarWinds

CVE-2024-28987

Web Help Desk

Known exploitation is confirmed by CISA KEV. The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify data.

EPSS
93.2%
CVSS
9.1
Ransomware
Not reported
View evidence