Skip to content
Weekly Signal

Confirmed attacker activity

Exploited Now

Vulnerabilities with confirmed exploitation evidence, ranked by the Cornish Geek Signal.

Updated 20 Aug 2026 · 12:00 UTC

1671Confirmed exploited
1671In CISA KEV
349Linked to ransomware
1671Guidance available
Clear

Exploitation priorities

1671 matching vulnerabilities

83Investigate

Ivanti

CVE-2024-13159

Endpoint Manager, Endpoint Manager (EPM)

Known exploitation is confirmed by CISA KEV. Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.

EPSS
99.8%
CVSS
7.5
Ransomware
Not reported
View evidence
83Investigate

D-Link, Dlink

CVE-2024-0769

Dir-859 Firmware, DIR-859 Router

Known exploitation is confirmed by CISA KEV. ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DIR-859 1.06B01. It has been rated as critical. Affected by this issue is some unknown functionality of the file /hedwig.cgi of…

EPSS
82.7%
CVSS
9.8
Ransomware
Not reported
View evidence
83Investigate

Adobe

CVE-2023-38205

ColdFusion

Known exploitation is confirmed by CISA KEV. Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could…

EPSS
99.7%
CVSS
7.5
Ransomware
Not reported
View evidence
83Investigate

Microsoft

CVE-2023-36025

Windows, Windows 10 1507, Windows 10 1607 +11 more

Known exploitation is confirmed by CISA KEV. Windows SmartScreen Security Feature Bypass Vulnerability

EPSS
88.2%
CVSS
8.8
Ransomware
Not reported
View evidence
83Investigate

Ignite Realtime, Igniterealtime

CVE-2023-32315

Openfire

Known exploitation is confirmed by CISA KEV. Openfire is an XMPP server licensed under the Open Source Apache License. Openfire's administrative console, a web-based application, was found to be vulnerable to a path traversal attack via the setup environment.…

EPSS
100.0%
CVSS
7.5
Ransomware
Not reported
View evidence
83Investigate

Adobe

CVE-2023-29298

ColdFusion

Known exploitation is confirmed by CISA KEV. Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could…

EPSS
99.8%
CVSS
7.5
Ransomware
Not reported
View evidence
83Investigate

Zyxel

CVE-2023-27992

Multiple Network-Attached Storage (NAS) Devices, Nas326 Firmware, Nas540 Firmware +1 more

Known exploitation is confirmed by CISA KEV. The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, NAS540 firmware versions prior to V5.21(AATB.11)C0, and NAS542 firmware versions prior to V5.21(ABAG.11)C0 could allow an unauthenticated attacker to execute some…

EPSS
84.2%
CVSS
9.8
Ransomware
Not reported
View evidence
83Investigate

Veeam

CVE-2023-27532

Backup & Replication, Veeam Backup & Replication

Known exploitation is confirmed by CISA KEV. Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained. This may lead to gaining access to the backup infrastructure hosts.

EPSS
77.6%
CVSS
7.5
Ransomware
Known
View evidence
83Investigate

PaperCut

CVE-2023-27351

NG/MF, Papercut Mf, Papercut Ng

Known exploitation is confirmed by CISA KEV. This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SecurityRequestFilter…

EPSS
77.4%
CVSS
7.5
Ransomware
Known
View evidence
83Investigate

Adobe

CVE-2023-26360

ColdFusion

Known exploitation is confirmed by CISA KEV. Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context…

EPSS
97.3%
CVSS
8.6
Ransomware
Not reported
View evidence
83Investigate

Oracle

CVE-2023-21839

WebLogic Server

Known exploitation is confirmed by CISA KEV. Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access…

EPSS
99.8%
CVSS
7.5
Ransomware
Not reported
View evidence
83Investigate

Apache

CVE-2022-33891

Spark

Known exploitation is confirmed by CISA KEV. The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access permissions to view or modify the…

EPSS
93.1%
CVSS
8.8
Ransomware
Not reported
View evidence
83Investigate

WatchGuard

CVE-2022-26318

Firebox and XTM Appliances, Fireware

Known exploitation is confirmed by CISA KEV. On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code, aka FBX-22786. This vulnerability impacts Fireware OS before 12.7.2_U2, 12.x before 12.1.3_U8, and 12.2.x through 12.5.x before 12.5.9_U2.

EPSS
78.2%
CVSS
9.8
Ransomware
Not reported
View evidence
83Investigate

Microsoft

CVE-2021-40449

Windows, Windows 10 1507, Windows 10 1607 +17 more

Known exploitation is confirmed by CISA KEV. Win32k Elevation of Privilege Vulnerability

EPSS
74.1%
CVSS
7.8
Ransomware
Known
View evidence
83Investigate

BeyondTrust, Debian +7 more

CVE-2021-3156

Active Iq Unified Manager, Cloud Backup, Communications Performance Intelligence Center +21 more

Known exploitation is confirmed by CISA KEV. Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a…

EPSS
99.3%
CVSS
7.8
Ransomware
Not reported
View evidence
83Investigate

Debian, Fedoraproject +3 more

CVE-2021-39144

Business Activity Monitoring, Commerce Guided Search, Communications Billing And Revenue Management Elastic Charging Engine +12 more

Known exploitation is confirmed by CISA KEV. XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has sufficient rights to execute commands of the host…

EPSS
98.1%
CVSS
8.5
Ransomware
Not reported
View evidence
83Investigate

October CMS, Octobercms

CVE-2021-32648

October, October CMS

Known exploitation is confirmed by CISA KEV. octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an attacker can request an account password reset and then gain access to the…

EPSS
90.4%
CVSS
9.1
Ransomware
Not reported
View evidence
83Investigate

Tenda

CVE-2021-31755

Ac11 Firmware, AC11 Router

Known exploitation is confirmed by CISA KEV. An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setmac allows attackers to execute arbitrary code on the system via a crafted post…

EPSS
85.8%
CVSS
9.8
Ransomware
Not reported
View evidence
83Investigate

Yealink

CVE-2021-27561

Device Management

Known exploitation is confirmed by CISA KEV. Yealink Device Management (DM) 3.6.0.20 allows command injection as root via the /sm/api/v1/firewall/zone/services URI, without authentication.

EPSS
82.9%
CVSS
9.8
Ransomware
Not reported
View evidence
83Investigate

Accellion

CVE-2021-27104

FTA

Known exploitation is confirmed by CISA KEV. Accellion FTA 9_12_370 and earlier is affected by OS command execution via a crafted POST request to various admin endpoints. The fixed version is FTA_9_12_380 and later.

EPSS
56.4%
CVSS
9.8
Ransomware
Known
View evidence
83Investigate

Atlassian

CVE-2021-26085

Confluence Data Center, Confluence Server

Known exploitation is confirmed by CISA KEV. Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vulnerability in the /s/ endpoint. The affected versions are before version 7.4.10, and…

EPSS
99.9%
CVSS
5.3
Ransomware
Known
View evidence
83Investigate

Debian, Exiftool Project +2 more

CVE-2021-22204

Debian Linux, Exiftool, Fedora

Known exploitation is confirmed by CISA KEV. Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malicious image

EPSS
100.0%
CVSS
7.8
Ransomware
Not reported
View evidence
83Investigate

PlaySMS

CVE-2020-8644

PlaySMS

Known exploitation is confirmed by CISA KEV. PlaySMS before 1.4.3 does not sanitize inputs from a malicious string.

EPSS
86.7%
CVSS
9.8
Ransomware
Not reported
View evidence
83Investigate

Synacor

CVE-2020-7796

Zimbra Collaboration Suite

Known exploitation is confirmed by CISA KEV. Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 allows SSRF when WebEx zimlet is installed and zimlet JSP is enabled.

EPSS
84.4%
CVSS
9.8
Ransomware
Not reported
View evidence
83Investigate

Grandstream

CVE-2020-5722

UCM6200, Ucm6200 Firmware

Known exploitation is confirmed by CISA KEV. The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. An attacker can use this vulnerability to execute shell commands as root…

EPSS
84.4%
CVSS
9.8
Ransomware
Not reported
View evidence