Skip to content
Weekly Signal

Confirmed attacker activity

Exploited Now

Vulnerabilities with confirmed exploitation evidence, ranked by the Cornish Geek Signal.

Updated 19 Aug 2026 · 23:00 UTC

1670Confirmed exploited
1670In CISA KEV
349Linked to ransomware
1670Guidance available
Clear

Exploitation priorities

1670 matching vulnerabilities

88Fix now

Cleo

CVE-2024-50623

Harmony, Lexicom, Multiple Products +1 more

Known exploitation is confirmed by CISA KEV. In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.

EPSS
98.6%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Sysaid

CVE-2023-47246

Sysaid, SysAid Server

Known exploitation is confirmed by CISA KEV. In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023.

EPSS
98.9%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Zoho, Zohocorp

CVE-2022-47966

ManageEngine, Manageengine Access Manager Plus, Manageengine Ad360 +20 more

Known exploitation is confirmed by CISA KEV. Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT…

EPSS
99.8%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Langflow

CVE-2025-3248

Langflow

Known exploitation is confirmed by CISA KEV. Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.

EPSS
100.0%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Sitecore

CVE-2021-42237

Experience Platform, XP

Known exploitation is confirmed by CISA KEV. Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine. No authentication or…

EPSS
97.9%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Crushftp

CVE-2025-31161

Crushftp

Known exploitation is confirmed by CISA KEV. CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unless a DMZ proxy instance is used), as exploited in the wild in March and…

EPSS
99.9%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Fedoraproject, Php +1 more

CVE-2024-4577

Fedora, PHP

Known exploitation is confirmed by CISA KEV. In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use…

EPSS
100.0%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Palo Alto Networks, Paloaltonetworks

CVE-2024-3400

PAN-OS

Known exploitation is confirmed by CISA KEV. A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an…

EPSS
100.0%
CVSS
10.0
Ransomware
Known
View evidence
88Fix now

Jetbrains

CVE-2024-27198

Teamcity

Known exploitation is confirmed by CISA KEV. In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible

EPSS
99.9%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Jenkins

CVE-2024-23897

Jenkins, Jenkins Command Line Interface (CLI)

Known exploitation is confirmed by CISA KEV. Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with…

EPSS
100.0%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Connectwise

CVE-2024-1709

Screenconnect

Known exploitation is confirmed by CISA KEV. ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may allow an attacker direct access to confidential information or critical systems.

EPSS
100.0%
CVSS
10.0
Ransomware
Known
View evidence
88Fix now

Fortinet

CVE-2023-48788

FortiClient EMS, Forticlient Enterprise Management Server

Known exploitation is confirmed by CISA KEV. A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 allows attacker to execute unauthorized code or commands…

EPSS
97.6%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Apache, Debian +1 more

CVE-2023-46604

Activemq, Activemq Legacy Openwire Module, Debian Linux +3 more

Known exploitation is confirmed by CISA KEV. The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to either a Java-based OpenWire broker or client to run arbitrary…

EPSS
99.7%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Jetbrains

CVE-2023-42793

Teamcity

Known exploitation is confirmed by CISA KEV. In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible

EPSS
100.0%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Adobe

CVE-2023-38203

Coldfusion

Known exploitation is confirmed by CISA KEV. Adobe ColdFusion versions 2018u17 (and earlier), 2021u7 (and earlier) and 2023u1 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this…

EPSS
96.7%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Ivanti

CVE-2023-38035

Mobileiron Sentry, Sentry

Known exploitation is confirmed by CISA KEV. A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently…

EPSS
100.0%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Ivanti

CVE-2023-35082

Endpoint Manager Mobile, Endpoint Manager Mobile (EPMM) and MobileIron Core

Known exploitation is confirmed by CISA KEV. An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of the application without proper authentication. This vulnerability is unique to CVE-2023-35078 announced…

EPSS
100.0%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Progress

CVE-2023-34362

Moveit Cloud, Moveit Transfer

Known exploitation is confirmed by CISA KEV. In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL injection vulnerability has been found in the MOVEit Transfer web application that could allow…

EPSS
99.9%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Microsoft

CVE-2023-29357

Sharepoint Server

Known exploitation is confirmed by CISA KEV. Microsoft SharePoint Server Elevation of Privilege Vulnerability

EPSS
99.6%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Adobe

CVE-2023-29300

Coldfusion

Known exploitation is confirmed by CISA KEV. Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this…

EPSS
100.0%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Papercut

CVE-2023-27350

MF/NG, Papercut Mf, Papercut Ng

Known exploitation is confirmed by CISA KEV. This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SetupCompleted…

EPSS
100.0%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Atlassian

CVE-2023-22527

Confluence Data Center, Confluence Data Center and Server, Confluence Server

Known exploitation is confirmed by CISA KEV. A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected instance. Customers using an affected version must take immediate…

EPSS
100.0%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Atlassian

CVE-2023-22518

Confluence Data Center, Confluence Data Center and Server, Confluence Server

Known exploitation is confirmed by CISA KEV. All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an unauthenticated attacker to reset Confluence and create a Confluence instance administrator account.…

EPSS
100.0%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Atlassian

CVE-2023-22515

Confluence Data Center, Confluence Data Center and Server, Confluence Server

Known exploitation is confirmed by CISA KEV. Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server…

EPSS
99.2%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Ibm

CVE-2022-47986

Aspera Faspex

Known exploitation is confirmed by CISA KEV. IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserialization flaw. By sending a specially crafted…

EPSS
100.0%
CVSS
9.8
Ransomware
Known
View evidence