Skip to content
Weekly Signal

Confirmed attacker activity

Exploited Now

Vulnerabilities with confirmed exploitation evidence, ranked by the Cornish Geek Signal.

Updated 20 Aug 2026 · 16:45 UTC

1671Confirmed exploited
1671In CISA KEV
349Linked to ransomware
1671Guidance available
Clear

Exploitation priorities

1671 matching vulnerabilities

81Investigate

Debian, Drupal +3 more

CVE-2020-28949

Archive Tar, Archive_Tar, Debian Linux +2 more

Known exploitation is confirmed by CISA KEV. Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed.

EPSS
84.6%
CVSS
7.8
Ransomware
Not reported
View evidence
81Investigate

Sophos

CVE-2020-12271

SFOS

Known exploitation is confirmed by CISA KEV. A SQL injection issue was found in SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 on Sophos XG Firewall devices, as exploited in the wild in April 2020. This affected devices configured…

EPSS
42.4%
CVSS
9.8
Ransomware
Known
View evidence
81Investigate

Microsoft

CVE-2020-0674

Internet Explorer

Known exploitation is confirmed by CISA KEV. A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from…

EPSS
86.9%
CVSS
7.5
Ransomware
Not reported
View evidence
81Investigate

Synacor

CVE-2019-9621

Zimbra Collaboration Suite, Zimbra Collaboration Suite (ZCS)

Known exploitation is confirmed by CISA KEV. Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3 allows SSRF via the ProxyServlet component.

EPSS
81.0%
CVSS
7.5
Ransomware
Not reported
View evidence
81Investigate

Oracle

CVE-2019-2616

BI Publisher (Formerly XML Publisher), Business Intelligence Publisher

Known exploitation is confirmed by CISA KEV. Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated…

EPSS
92.2%
CVSS
7.2
Ransomware
Not reported
View evidence
81Investigate

Nagios

CVE-2019-15949

Nagios XI

Known exploitation is confirmed by CISA KEV. Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios user, or access as the admin user via the web interface. The…

EPSS
77.0%
CVSS
8.8
Ransomware
Not reported
View evidence
81Investigate

Citrix

CVE-2019-12991

Netscaler Sd-wan, Sd-wan, SD-WAN and NetScaler

Known exploitation is confirmed by CISA KEV. Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of 6).

EPSS
74.1%
CVSS
8.8
Ransomware
Not reported
View evidence
81Investigate

Apache, Debian

CVE-2019-0193

Debian Linux, Solr

Known exploitation is confirmed by CISA KEV. In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the whole DIH configuration can come from a…

EPSS
83.5%
CVSS
7.2
Ransomware
Not reported
View evidence
81Investigate

Paessler

CVE-2018-9276

PRTG Network Monitor

Known exploitation is confirmed by CISA KEV. An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administrator web console with administrative privileges can exploit an OS command injection vulnerability…

EPSS
87.2%
CVSS
7.2
Ransomware
Not reported
View evidence
81Investigate

Microsoft

CVE-2018-8414

Windows, Windows 10 1703, Windows 10 1709 +3 more

Known exploitation is confirmed by CISA KEV. A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths, aka "Windows Shell Remote Code Execution Vulnerability." This affects Windows 10 Servers, Windows 10.

EPSS
74.0%
CVSS
8.8
Ransomware
Not reported
View evidence
81Investigate

Adobe

CVE-2018-4939

ColdFusion

Known exploitation is confirmed by CISA KEV. Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Deserialization of Untrusted Data vulnerability. Successful exploitation could lead to arbitrary code execution.

EPSS
62.9%
CVSS
9.8
Ransomware
Not reported
View evidence
81Investigate

Laravel

CVE-2018-15133

Laravel, Laravel Framework

Known exploitation is confirmed by CISA KEV. In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unserialize call on a potentially untrusted X-XSRF-TOKEN value. This involves the decrypt method…

EPSS
76.8%
CVSS
8.1
Ransomware
Not reported
View evidence
81Investigate

Microsoft

CVE-2018-0824

Windows, Windows 10 1507, Windows 10 1607 +11 more

Known exploitation is confirmed by CISA KEV. A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized objects, aka "Microsoft COM for Windows Remote Code Execution Vulnerability." This affects Windows 7,…

EPSS
72.4%
CVSS
8.8
Ransomware
Not reported
View evidence
81Investigate

Microsoft

CVE-2017-8759

.NET Framework

Known exploitation is confirmed by CISA KEV. Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely via a malicious document or application, aka ".NET Framework Remote Code Execution Vulnerability."

EPSS
86.8%
CVSS
7.8
Ransomware
Not reported
View evidence
81Investigate

Microsoft

CVE-2017-8570

Office

Known exploitation is confirmed by CISA KEV. Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0243.

EPSS
85.6%
CVSS
7.8
Ransomware
Not reported
View evidence
81Investigate

Microsoft

CVE-2017-8543

Windows, Windows 10 1507, Windows 10 1511 +8 more

Known exploitation is confirmed by CISA KEV. Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8, Windows 8.1 and Windows RT 8.1,…

EPSS
64.9%
CVSS
9.8
Ransomware
Not reported
View evidence
81Investigate

Cisco

CVE-2017-6736

IOS, IOS and IOS XE Software, Ios Xe

Known exploitation is confirmed by CISA KEV. The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system…

EPSS
70.6%
CVSS
8.8
Ransomware
Not reported
View evidence
81Investigate

NETGEAR

CVE-2017-6334

DGN2200 Devices, Dgn2200 Series Firmware

Known exploitation is confirmed by CISA KEV. dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the host_name field of an HTTP POST request, a different…

EPSS
72.2%
CVSS
8.8
Ransomware
Not reported
View evidence
81Investigate

NETGEAR

CVE-2017-6077

Dgn2200 Firmware, Wireless Router DGN2200

Known exploitation is confirmed by CISA KEV. ping.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ping_IPAddr field of an HTTP POST request.

EPSS
68.2%
CVSS
9.8
Ransomware
Not reported
View evidence
81Investigate

Microsoft

CVE-2017-11826

Office, Office Compatibility Pack, Office Online Server +5 more

Known exploitation is confirmed by CISA KEV. Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer, Word 2007, 2010, 2013 and 2016, Word Automation Services, and Office…

EPSS
81.5%
CVSS
7.8
Ransomware
Not reported
View evidence
81Investigate

Microsoft

CVE-2017-0262

Office

Known exploitation is confirmed by CISA KEV. Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability".…

EPSS
81.0%
CVSS
7.8
Ransomware
Not reported
View evidence
81Investigate

Microsoft

CVE-2017-0261

Office

Known exploitation is confirmed by CISA KEV. Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability".…

EPSS
78.1%
CVSS
7.8
Ransomware
Not reported
View evidence
81Investigate

Microsoft

CVE-2017-0101

Windows, Windows 7, Windows Server 2008 +1 more

Known exploitation is confirmed by CISA KEV. The kernel-mode drivers in Transaction Manager in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1; Windows…

EPSS
57.5%
CVSS
7.8
Ransomware
Known
View evidence
81Investigate

Microsoft

CVE-2017-0037

Edge, Edge and Internet Explorer, Internet Explorer

Known exploitation is confirmed by CISA KEV. Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::HandleColumnBreakOnColumnSpanningElement function in mshtml.dll, which allows remote attackers to execute arbitrary code via vectors involving a…

EPSS
80.4%
CVSS
8.1
Ransomware
Not reported
View evidence
81Investigate

Debian, Mozilla +2 more

CVE-2016-9079

Debian Linux, Enterprise Linux, Enterprise Linux Desktop +9 more

Known exploitation is confirmed by CISA KEV. A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users on Windows. This vulnerability affects…

EPSS
87.4%
CVSS
7.5
Ransomware
Not reported
View evidence