Skip to content
Weekly Signal

Confirmed attacker activity

Exploited Now

Vulnerabilities with confirmed exploitation evidence, ranked by the Cornish Geek Signal.

Updated 20 Aug 2026 · 15:29 UTC

1671Confirmed exploited
1671In CISA KEV
349Linked to ransomware
1671Guidance available
Clear

Exploitation priorities

1671 matching vulnerabilities

82Investigate

Microsoft

CVE-2012-4792

Internet Explorer

Known exploitation is confirmed by CISA KEV. Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly…

EPSS
78.8%
CVSS
8.8
Ransomware
Not reported
View evidence
82Investigate

Microsoft

CVE-2012-1889

Xml Core Services

Known exploitation is confirmed by CISA KEV. Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted…

EPSS
83.6%
CVSS
8.8
Ransomware
Not reported
View evidence
82Investigate

Adobe

CVE-2012-0754

Flash Player

Known exploitation is confirmed by CISA KEV. Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and before 11.1.115.6 on Android 4.x allows attackers…

EPSS
92.0%
CVSS
8.1
Ransomware
Not reported
View evidence
82Investigate

Apache

CVE-2012-0391

Struts, Struts 2

Known exploitation is confirmed by CISA KEV. The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling for mismatched data types of properties, which allows remote attackers to execute arbitrary Java…

EPSS
75.1%
CVSS
9.8
Ransomware
Not reported
View evidence
82Investigate

Microsoft

CVE-2011-3402

Windows, Windows 7, Windows Server 2003 +3 more

Known exploitation is confirmed by CISA KEV. Unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2,…

EPSS
78.3%
CVSS
8.8
Ransomware
Not reported
View evidence
82Investigate

Canonical, Debian +2 more

CVE-2010-4344

Debian Linux, Exim, Opensuse +1 more

Known exploitation is confirmed by CISA KEV. Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with…

EPSS
71.9%
CVSS
9.8
Ransomware
Not reported
View evidence
82Investigate

Microsoft

CVE-2010-3333

Office, Open Xml File Format Converter

Known exploitation is confirmed by CISA KEV. Stack-based buffer overflow in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2008 for Mac, Office for Mac 2011, and Open XML File Format Converter…

EPSS
89.5%
CVSS
7.8
Ransomware
Not reported
View evidence
82Investigate

Microsoft

CVE-2010-2568

Windows, Windows 7, Windows Server 2003 +3 more

Known exploitation is confirmed by CISA KEV. Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users or remote attackers to execute arbitrary code…

EPSS
91.3%
CVSS
7.8
Ransomware
Not reported
View evidence
82Investigate

Netapp, Red Hat +1 more

CVE-2010-1871

Jboss Enterprise Application Platform, JBoss Seam 2, Oncommand Balance +2 more

Known exploitation is confirmed by CISA KEV. JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for JBoss Expression Language (EL) expressions, which allows remote attackers to…

EPSS
83.4%
CVSS
8.8
Ransomware
Not reported
View evidence
82Investigate

Microsoft

CVE-2010-0806

Internet Explorer

Known exploitation is confirmed by CISA KEV. Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via vectors involving access to an invalid…

EPSS
82.2%
CVSS
8.8
Ransomware
Not reported
View evidence
82Investigate

Adobe, Opensuse +1 more

CVE-2009-3953

Acrobat, Acrobat and Reader, Linux Enterprise +2 more

Known exploitation is confirmed by CISA KEV. The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remote attackers to execute arbitrary code via…

EPSS
83.9%
CVSS
8.8
Ransomware
Not reported
View evidence
82Investigate

Adobe

CVE-2009-3459

Acrobat, Acrobat and Reader, Acrobat Reader

Known exploitation is confirmed by CISA KEV. Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to execute arbitrary code via a crafted PDF file that triggers…

EPSS
86.6%
CVSS
8.8
Ransomware
Not reported
View evidence
82Investigate

Adobe

CVE-2007-5659

Acrobat, Acrobat and Reader, Acrobat Reader

Known exploitation is confirmed by CISA KEV. Multiple buffer overflows in Adobe Reader and Acrobat 8.1.1 and earlier allow remote attackers to execute arbitrary code via a PDF file with long arguments to unspecified JavaScript methods. NOTE: this issue…

EPSS
94.2%
CVSS
7.8
Ransomware
Not reported
View evidence
82Investigate

Hewlett Packard (HP), Hp

CVE-2005-2773

OpenView Network Node Manager

Known exploitation is confirmed by CISA KEV. HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) node parameter to connectedNodes.ovpl, (2) cdpView.ovpl, (3) freeIPaddrs.ovpl, and (4) ecscmg.ovpl.

EPSS
74.1%
CVSS
9.8
Ransomware
Not reported
View evidence
81Investigate

Microsoft

CVE-2022-21882

Win32k, Windows 10 1809, Windows 10 1909 +7 more

Known exploitation is confirmed by CISA KEV. Win32k Elevation of Privilege Vulnerability

EPSS
54.6%
CVSS
7.8
Ransomware
Known
View evidence
81Investigate

Microsoft

CVE-2015-1701

Win32k, Windows 2003 Server, Windows 7 +2 more

Known exploitation is confirmed by CISA KEV. Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild…

EPSS
56.2%
CVSS
7.8
Ransomware
Known
View evidence
81Investigate

Red Hat, Redhat

CVE-2010-1428

JBoss, Jboss Enterprise Application Platform

Known exploitation is confirmed by CISA KEV. The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the…

EPSS
62.3%
CVSS
7.5
Ransomware
Known
View evidence
81Investigate

Red Hat, Redhat

CVE-2010-0738

JBoss, Jboss Enterprise Application Platform

Known exploitation is confirmed by CISA KEV. The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET…

EPSS
79.4%
CVSS
5.3
Ransomware
Known
View evidence
81Investigate

Check Point, Checkpoint

CVE-2026-16232

Multi-domain Security Management, Quantum Security Management, SmartConsole

Known exploitation is confirmed by CISA KEV. An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful…

EPSS
73.3%
CVSS
9.3
Ransomware
Not reported
View evidence
81Investigate

Microsoft

CVE-2024-21338

Windows, Windows 10 1809, Windows 10 21h2 +7 more

Known exploitation is confirmed by CISA KEV. Windows Kernel Elevation of Privilege Vulnerability

EPSS
59.8%
CVSS
7.8
Ransomware
Known
View evidence
81Investigate

Apache, Redhat

CVE-2026-34486

Enterprise Linux, Enterprise Linux Els, Enterprise Linux Eus +4 more

Known exploitation is confirmed by CISA KEV. Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to…

EPSS
82.9%
CVSS
7.5
Ransomware
Not reported
View evidence
81Investigate

Ubiquiti, Ui

CVE-2026-34909

Enterprise Fortress Gateway Firmware, Enterprise Network Video Recorder Core Firmware, Enterprise Network Video Recorder Firmware +30 more

Known exploitation is confirmed by CISA KEV. A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access…

EPSS
63.9%
CVSS
10.0
Ransomware
Not reported
View evidence
81Investigate

Zkteco

CVE-2023-38950

Biotime

Known exploitation is confirmed by CISA KEV. A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload. This vulnerability was fixed in version 9.0.120240617.19506 of…

EPSS
84.7%
CVSS
7.5
Ransomware
Not reported
View evidence
81Investigate

Nagios

CVE-2021-25298

Nagios Xi

Known exploitation is confirmed by CISA KEV. Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/cloud-vm/cloud-vm.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can…

EPSS
75.0%
CVSS
8.8
Ransomware
Not reported
View evidence
81Investigate

Nagios

CVE-2021-25296

Nagios Xi

Known exploitation is confirmed by CISA KEV. Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/windowswmi/windowswmi.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can…

EPSS
71.5%
CVSS
8.8
Ransomware
Not reported
View evidence