Skip to content
Weekly Signal

Confirmed attacker activity

Exploited Now

Vulnerabilities with confirmed exploitation evidence, ranked by the Cornish Geek Signal.

Updated 19 Aug 2026 · 23:42 UTC

1670Confirmed exploited
1670In CISA KEV
349Linked to ransomware
1670Guidance available
Clear

Exploitation priorities

1670 matching vulnerabilities

88Fix now

Fortinet

CVE-2022-42475

Fortios, Fortiproxy

Known exploitation is confirmed by CISA KEV. A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier and FortiProxy SSL-VPN 7.2.0 through 7.2.1, 7.0.7 and earlier…

EPSS
99.5%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Wso2

CVE-2022-29464

Api Manager, Enterprise Integrator, Identity Server +6 more

Known exploitation is confirmed by CISA KEV. Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web…

EPSS
100.0%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Atlassian

CVE-2022-26134

Confluence Data Center, Confluence Server, Confluence Server/Data Center

Known exploitation is confirmed by CISA KEV. In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance.…

EPSS
100.0%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Vmware

CVE-2022-22954

Cloud Foundation, Identity Manager, Vrealize Automation +3 more

Known exploitation is confirmed by CISA KEV. VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may…

EPSS
100.0%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Oracle

CVE-2022-21587

E-business Suite

Known exploitation is confirmed by CISA KEV. Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). Supported versions that are affected are 12.2.3-12.2.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via…

EPSS
98.3%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

F5

CVE-2022-1388

BIG-IP, Big-ip Access Policy Manager, Big-ip Advanced Firewall Manager +9 more

Known exploitation is confirmed by CISA KEV. On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x versions, undisclosed requests may…

EPSS
100.0%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Apache, Fedoraproject +2 more

CVE-2021-42013

Cloud Backup, Fedora, Http Server +3 more

Known exploitation is confirmed by CISA KEV. It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the directories configured…

EPSS
100.0%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Apache, Fedoraproject +2 more

CVE-2021-41773

Cloud Backup, Fedora, Http Server +1 more

Known exploitation is confirmed by CISA KEV. A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories…

EPSS
100.0%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Zoho, Zohocorp

CVE-2021-40539

ManageEngine, Manageengine Adselfservice Plus

Known exploitation is confirmed by CISA KEV. Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution.

EPSS
99.0%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Facade, Laravel

CVE-2021-3129

Ignition

Known exploitation is confirmed by CISA KEV. Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of insecure usage of file_get_contents() and file_put_contents(). This is exploitable on sites using…

EPSS
99.9%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Forgerock

CVE-2021-35464

Access Management, Access Management (AM), Openam

Known exploitation is confirmed by CISA KEV. ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages. The exploitation does not require authentication, and remote code execution can be triggered by sending…

EPSS
100.0%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Atlassian

CVE-2021-26084

Confluence Data Center, Confluence Server, Confluence Server and Data Center

Known exploitation is confirmed by CISA KEV. In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance.…

EPSS
100.0%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

F5

CVE-2021-22986

Big-ip Access Policy Manager, Big-ip Advanced Firewall Manager, Big-ip Advanced Web Application Firewall +13 more

Known exploitation is confirmed by CISA KEV. On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.2, the iControl REST interface…

EPSS
99.9%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Vmware

CVE-2021-22005

Cloud Foundation, Vcenter Server

Known exploitation is confirmed by CISA KEV. The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to execute code…

EPSS
100.0%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Sonicwall

CVE-2021-20038

SMA 100 Appliances, Sma 200 Firmware, Sma 210 Firmware +3 more

Known exploitation is confirmed by CISA KEV. A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows a remote unauthenticated attacker to potentially execute code as a 'nobody' user in the appliance. This vulnerability…

EPSS
99.9%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

F5

CVE-2020-5902

BIG-IP, Big-ip Access Policy Manager, Big-ip Advanced Firewall Manager +12 more

Known exploitation is confirmed by CISA KEV. In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has a Remote Code Execution (RCE) vulnerability in undisclosed pages.

EPSS
100.0%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Fedoraproject, Openslp +2 more

CVE-2019-5544

Enterprise Linux Desktop, Enterprise Linux For Ibm Z Systems, Enterprise Linux For Ibm Z Systems Eus +14 more

Known exploitation is confirmed by CISA KEV. OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a…

EPSS
96.8%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Atlassian

CVE-2019-3396

Confluence Server, Confluence Server and Data Server

Known exploitation is confirmed by CISA KEV. The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.12.3 (the fixed version for 6.12.x), from version 6.13.0 before 6.13.3 (the…

EPSS
99.9%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Progress, Telerik

CVE-2019-18935

Telerik Ui For Asp.net Ajax, Ui For Asp.net Ajax

Known exploitation is confirmed by CISA KEV. Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function. This is exploitable when the encryption keys are known due to the presence of CVE-2017-11317…

EPSS
99.7%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Ivanti

CVE-2019-11510

Connect Secure, Pulse Connect Secure

Known exploitation is confirmed by CISA KEV. In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can send a specially crafted URI to perform an arbitrary file…

EPSS
100.0%
CVSS
10.0
Ransomware
Known
View evidence
88Fix now

Canonical, Debian +4 more

CVE-2019-11043

Debian Linux, Enterprise Linux, Enterprise Linux Desktop +21 more

Known exploitation is confirmed by CISA KEV. In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into…

EPSS
99.4%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Huawei, Microsoft +1 more

CVE-2019-0708

Agile Controller-campus Firmware, Aptio Firmware, Atellica Solution Firmware +65 more

Known exploitation is confirmed by CISA KEV. A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka…

EPSS
100.0%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Microsoft

CVE-2019-0604

SharePoint, Sharepoint Enterprise Server, Sharepoint Foundation +1 more

Known exploitation is confirmed by CISA KEV. A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID…

EPSS
99.8%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Debian, Drupal

CVE-2018-7600

Debian Linux, Drupal, Drupal Core

Known exploitation is confirmed by CISA KEV. Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module…

EPSS
100.0%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

D-Link, Dlink

CVE-2018-6530

Dir-860l Firmware, Dir-865l Firmware, Dir-868l Firmware +2 more

Known exploitation is confirmed by CISA KEV. OS command injection vulnerability in soap.cgi (soapcgi_main in cgibin) in D-Link DIR-880L DIR-880L_REVA_FIRMWARE_PATCH_1.08B04 and previous versions, DIR-868L DIR868LA1_FW112b04 and previous versions, DIR-65L DIR-865L_REVA_FIRMWARE_PATCH_1.08.B01 and previous versions, and DIR-860L DIR860LA1_FW110b04 and previous versions…

EPSS
96.7%
CVSS
9.8
Ransomware
Known
View evidence