Skip to content
Weekly Signal

Confirmed attacker activity

Exploited Now

Vulnerabilities with confirmed exploitation evidence, ranked by the Cornish Geek Signal.

Updated 20 Aug 2026 · 13:06 UTC

1671Confirmed exploited
1671In CISA KEV
349Linked to ransomware
1671Guidance available
Clear

Exploitation priorities

1671 matching vulnerabilities

83Investigate

Microsoft

CVE-2014-6324

Kerberos Key Distribution Center (KDC), Windows 7, Windows 8 +4 more

Known exploitation is confirmed by CISA KEV. The Kerberos Key Distribution Center (KDC) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server…

EPSS
87.4%
CVSS
8.8
Ransomware
Not reported
View evidence
83Investigate

Microsoft

CVE-2014-1812

Windows, Windows 7, Windows 8 +4 more

Known exploitation is confirmed by CISA KEV. The Group Policy implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 does not…

EPSS
65.1%
CVSS
8.8
Ransomware
Known
View evidence
83Investigate

Broadcom, Canonical +11 more

CVE-2014-0160

Application Processing Engine Firmware, Cp 1543-1 Firmware, Debian Linux +25 more

Known exploitation is confirmed by CISA KEV. The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted…

EPSS
100.0%
CVSS
7.5
Ransomware
Not reported
View evidence
83Investigate

Hewlett Packard (HP), Hp

CVE-2013-4810

Application Lifecycle Management, Procurve Manager, ProCurve Manager (PCM) +3 more

Known exploitation is confirmed by CISA KEV. HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, Identity Driven Manager (IDM) 4.0, and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to…

EPSS
79.0%
CVSS
9.8
Ransomware
Not reported
View evidence
83Investigate

Adobe

CVE-2013-3346

Acrobat, Acrobat Reader, Reader and Acrobat

Known exploitation is confirmed by CISA KEV. Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a…

EPSS
78.6%
CVSS
9.8
Ransomware
Not reported
View evidence
83Investigate

Adobe

CVE-2011-2462

Acrobat, Acrobat Reader, Reader and Acrobat

Known exploitation is confirmed by CISA KEV. Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Adobe Reader 9.x through 9.4.6 on UNIX, allows remote attackers to…

EPSS
86.6%
CVSS
9.8
Ransomware
Not reported
View evidence
83Investigate

Adobe, Google +2 more

CVE-2011-0611

Acrobat, Acrobat Reader, Adobe Air +4 more

Known exploitation is confirmed by CISA KEV. Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader 9.x before…

EPSS
94.2%
CVSS
8.8
Ransomware
Not reported
View evidence
83Investigate

Microsoft

CVE-2010-3962

Internet Explorer

Known exploitation is confirmed by CISA KEV. Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code via vectors related to Cascading Style Sheets (CSS) token sequences and the clip attribute, aka…

EPSS
96.0%
CVSS
8.1
Ransomware
Not reported
View evidence
83Investigate

Mozilla

CVE-2010-3765

Firefox, Multiple Products, Seamonkey +1 more

Known exploitation is confirmed by CISA KEV. Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when JavaScript is enabled, allows remote attackers to execute arbitrary…

EPSS
83.3%
CVSS
9.8
Ransomware
Not reported
View evidence
83Investigate

Microsoft

CVE-2010-0249

Internet Explorer

Known exploitation is confirmed by CISA KEV. Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP2; Windows…

EPSS
91.9%
CVSS
8.8
Ransomware
Not reported
View evidence
82Investigate

Microsoft

CVE-2021-42278

Active Directory, Windows Server 2004, Windows Server 2008 +5 more

Known exploitation is confirmed by CISA KEV. Active Directory Domain Services Elevation of Privilege Vulnerability

EPSS
70.2%
CVSS
7.5
Ransomware
Known
View evidence
82Investigate

Microsoft

CVE-2016-0034

Silverlight

Known exploitation is confirmed by CISA KEV. Microsoft Silverlight 5 before 5.1.41212.0 mishandles negative offsets during decoding, which allows remote attackers to execute arbitrary code or cause a denial of service (object-header corruption) via a crafted web site, aka…

EPSS
58.5%
CVSS
8.8
Ransomware
Known
View evidence
82Investigate

Oracle

CVE-2013-0431

Java Runtime Environment (JRE), Jre, Openjdk

Known exploitation is confirmed by CISA KEV. Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows user-assisted remote attackers to bypass the Java security sandbox via unspecified…

EPSS
90.0%
CVSS
5.3
Ransomware
Known
View evidence
82Investigate

Microsoft

CVE-2018-8120

Win32k, Windows 7, Windows Server 2008

Known exploitation is confirmed by CISA KEV. An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows Server 2008, Windows 7,…

EPSS
73.7%
CVSS
7.0
Ransomware
Known
View evidence
82Investigate

Ivanti

CVE-2021-22893

Connect Secure, Pulse Connect Secure

Known exploitation is confirmed by CISA KEV. Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can allow…

EPSS
47.2%
CVSS
10.0
Ransomware
Known
View evidence
82Investigate

Cisco

CVE-2020-3259

Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD), Adaptive Security Appliance Software, Secure Firewall Threat Defense

Known exploitation is confirmed by CISA KEV. A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to retrieve memory contents on…

EPSS
69.3%
CVSS
7.5
Ransomware
Known
View evidence
82Investigate

Fortinet

CVE-2020-12812

Fortios

Known exploitation is confirmed by CISA KEV. An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted for the…

EPSS
49.3%
CVSS
9.8
Ransomware
Known
View evidence
82Investigate

Cisco

CVE-2025-20362

Adaptive Security Appliance Software, Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense, Secure Firewall Threat Defense

Known exploitation is confirmed by CISA KEV. Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTD Software releases that are affected by CVE-2025-20333 and…

EPSS
86.9%
CVSS
8.6
Ransomware
Not reported
View evidence
82Investigate

Microsoft

CVE-2021-36942

Windows, Windows Server 2004, Windows Server 2008 +4 more

Known exploitation is confirmed by CISA KEV. Windows LSA Spoofing Vulnerability

EPSS
66.0%
CVSS
7.5
Ransomware
Known
View evidence
82Investigate

Microsoft

CVE-2021-33766

Exchange Server

Known exploitation is confirmed by CISA KEV. Microsoft Exchange Server Information Disclosure Vulnerability

EPSS
98.2%
CVSS
7.3
Ransomware
Not reported
View evidence
82Investigate

Microsoft

CVE-2024-30088

Windows, Windows 10 1507, Windows 10 1607 +10 more

Known exploitation is confirmed by CISA KEV. Windows Kernel Elevation of Privilege Vulnerability

EPSS
68.2%
CVSS
7.0
Ransomware
Known
View evidence
82Investigate

Balbooa

CVE-2026-56291

Forms

Known exploitation is confirmed by CISA KEV. Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable…

EPSS
76.1%
CVSS
10.0
Ransomware
Not reported
View evidence
82Investigate

Microsoft

CVE-2026-50522

SharePoint, Sharepoint Server

Known exploitation is confirmed by CISA KEV. Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

EPSS
77.0%
CVSS
9.8
Ransomware
Not reported
View evidence
82Investigate

Fortinet

CVE-2026-25089

Fortisandbox, Fortisandbox Cloud, Fortisandbox Paas

Known exploitation is confirmed by CISA KEV. A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4…

EPSS
73.6%
CVSS
9.8
Ransomware
Not reported
View evidence
82Investigate

Widget Factory, Widgetfactorylimited

CVE-2026-48907

Jce, Joomla Content Editor

Known exploitation is confirmed by CISA KEV. A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.

EPSS
68.8%
CVSS
10.0
Ransomware
Not reported
View evidence