Skip to content
Weekly Signal

Confirmed attacker activity

Exploited Now

Vulnerabilities with confirmed exploitation evidence, ranked by the Cornish Geek Signal.

Updated 20 Aug 2026 · 13:46 UTC

1671Confirmed exploited
1671In CISA KEV
349Linked to ransomware
1671Guidance available
Clear

Exploitation priorities

1671 matching vulnerabilities

82Investigate

Cisco

CVE-2026-20230

Unified Communications Manager

Known exploitation is confirmed by CISA KEV. A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF)…

EPSS
83.2%
CVSS
8.6
Ransomware
Not reported
View evidence
82Investigate

BerriAI, Litellm +1 more

CVE-2026-42271

LiteLLM, Openshift Ai

Known exploitation is confirmed by CISA KEV. LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints used to preview an MCP server before…

EPSS
83.0%
CVSS
8.7
Ransomware
Not reported
View evidence
82Investigate

Sangoma

CVE-2025-64328

Filestore, Freepbx

Known exploitation is confirmed by CISA KEV. FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions 17.0.2.36 and above before 17.0.3, the filestore module within the Administrative interface is vulnerable to a post-authentication…

EPSS
84.6%
CVSS
8.6
Ransomware
Not reported
View evidence
82Investigate

Gogs

CVE-2025-8110

Gogs

Known exploitation is confirmed by CISA KEV. Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code.

EPSS
82.7%
CVSS
8.7
Ransomware
Not reported
View evidence
82Investigate

Rarlab

CVE-2025-6218

Winrar

Known exploitation is confirmed by CISA KEV. RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of RARLAB WinRAR. User interaction is required to exploit this vulnerability in…

EPSS
89.4%
CVSS
7.8
Ransomware
Not reported
View evidence
82Investigate

Ivanti

CVE-2025-4428

Endpoint Manager Mobile, Endpoint Manager Mobile (EPMM)

Known exploitation is confirmed by CISA KEV. Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers to execute arbitrary code via crafted API requests.

EPSS
86.2%
CVSS
8.8
Ransomware
Not reported
View evidence
82Investigate

Solarwinds

CVE-2025-40536

Web Help Desk

Known exploitation is confirmed by CISA KEV. SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated attacker to gain access to certain restricted functionality.

EPSS
71.5%
CVSS
9.8
Ransomware
Not reported
View evidence
82Investigate

Versa, Versa-networks

CVE-2025-34026

Concerto

Known exploitation is confirmed by CISA KEV. The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The internal Actuator endpoint can be leveraged…

EPSS
83.2%
CVSS
9.2
Ransomware
Not reported
View evidence
82Investigate

Microsoft

CVE-2025-33073

Windows, Windows 10 1507, Windows 10 1607 +13 more

Known exploitation is confirmed by CISA KEV. Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network.

EPSS
80.4%
CVSS
8.8
Ransomware
Not reported
View evidence
82Investigate

Microsoft

CVE-2025-33053

Windows, Windows 10 1507, Windows 10 1607 +13 more

Known exploitation is confirmed by CISA KEV. External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a network.

EPSS
85.3%
CVSS
8.8
Ransomware
Not reported
View evidence
82Investigate

Mongodb

CVE-2025-14847

Mongodb, MongoDB and MongoDB Server

Known exploitation is confirmed by CISA KEV. Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB…

EPSS
83.2%
CVSS
8.7
Ransomware
Not reported
View evidence
82Investigate

Gladinet

CVE-2025-11371

Centrestack, CentreStack and Triofox, Triofox

Known exploitation is confirmed by CISA KEV. In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusion Flaw that allows unintended disclosure of system files. Exploitation of this vulnerability has been…

EPSS
92.1%
CVSS
7.5
Ransomware
Not reported
View evidence
82Investigate

Roundcube

CVE-2024-42009

Webmail

Known exploitation is confirmed by CISA KEV. A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a…

EPSS
79.6%
CVSS
9.3
Ransomware
Not reported
View evidence
82Investigate

Microsoft

CVE-2024-29059

.net Framework

Known exploitation is confirmed by CISA KEV. .NET Framework Information Disclosure Vulnerability

EPSS
98.6%
CVSS
7.5
Ransomware
Not reported
View evidence
82Investigate

Adobe

CVE-2024-20767

Coldfusion

Known exploitation is confirmed by CISA KEV. ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. An attacker could leverage this vulnerability to access or modify…

EPSS
98.5%
CVSS
7.4
Ransomware
Not reported
View evidence
82Investigate

Ivanti

CVE-2024-13161

Endpoint Manager, Endpoint Manager (EPM)

Known exploitation is confirmed by CISA KEV. Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.

EPSS
90.1%
CVSS
7.5
Ransomware
Not reported
View evidence
82Investigate

Ivanti

CVE-2024-13160

Endpoint Manager, Endpoint Manager (EPM)

Known exploitation is confirmed by CISA KEV. Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.

EPSS
91.2%
CVSS
7.5
Ransomware
Not reported
View evidence
82Investigate

Draytek

CVE-2024-12987

Vigor Routers, Vigor2960 Firmware, Vigor300b Firmware

Known exploitation is confirmed by CISA KEV. A vulnerability, which was classified as critical, was found in DrayTek Vigor2960 and Vigor300B 1.5.1.4. Affected is an unknown function of the file /cgi-bin/mainfunction.cgi/apmcfgupload of the component Web Management Interface. The manipulation…

EPSS
98.1%
CVSS
6.9
Ransomware
Not reported
View evidence
82Investigate

Synacor

CVE-2023-34192

Zimbra Collaboration Suite, Zimbra Collaboration Suite (ZCS)

Known exploitation is confirmed by CISA KEV. Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary code via a crafted script to the /h/autoSaveDraft function.

EPSS
77.3%
CVSS
9.0
Ransomware
Not reported
View evidence
82Investigate

Sugarcrm

CVE-2023-22952

Multiple Products, Sugarcrm

Known exploitation is confirmed by CISA KEV. In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because of missing input validation.

EPSS
80.3%
CVSS
8.8
Ransomware
Not reported
View evidence
82Investigate

Hitachi, Hitachi Vantara

CVE-2022-43769

Pentaho Business Analytics (BA) Server, Vantara Pentaho Business Analytics Server

Known exploitation is confirmed by CISA KEV. Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain web services to set property values which contain Spring templates that are interpreted downstream.

EPSS
97.7%
CVSS
7.2
Ransomware
Not reported
View evidence
82Investigate

Microsoft

CVE-2022-26923

Active Directory, Windows 10 1507, Windows 10 1607 +12 more

Known exploitation is confirmed by CISA KEV. Active Directory Domain Services Elevation of Privilege Vulnerability

EPSS
83.0%
CVSS
8.8
Ransomware
Not reported
View evidence
82Investigate

Cisco

CVE-2022-20699

Rv340 Firmware, Rv340w Firmware, Rv345 Firmware +5 more

Known exploitation is confirmed by CISA KEV. Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass…

EPSS
72.5%
CVSS
9.8
Ransomware
Not reported
View evidence
82Investigate

Fedoraproject, Linux +5 more

CVE-2022-0847

Codeready Linux Builder, Enterprise Linux, Enterprise Linux Eus +27 more

Known exploitation is confirmed by CISA KEV. A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus…

EPSS
88.6%
CVSS
7.8
Ransomware
Not reported
View evidence
82Investigate

Metabase

CVE-2021-41277

Metabase

Known exploitation is confirmed by CISA KEV. Metabase is an open source data analytics platform. In affected versions a security issue has been discovered with the custom GeoJSON map (`admin->settings->maps->custom maps->add a map`) support and potential local file inclusion…

EPSS
97.2%
CVSS
7.5
Ransomware
Not reported
View evidence