Skip to content
Weekly Signal

Confirmed attacker activity

Exploited Now

Vulnerabilities with confirmed exploitation evidence, ranked by the Cornish Geek Signal.

Updated 20 Aug 2026 · 00:37 UTC

1670Confirmed exploited
1670In CISA KEV
349Linked to ransomware
1670Guidance available
Clear

Exploitation priorities

1670 matching vulnerabilities

88Fix now

Fortinet

CVE-2018-13379

Fortios, Fortiproxy

Known exploitation is confirmed by CISA KEV. An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0…

EPSS
100.0%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Dasan, Dasannetworks

CVE-2018-10562

Gigabit Passive Optical Network (GPON) Routers, Gpon Router Firmware

Known exploitation is confirmed by CISA KEV. An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_action=ping request to a GponForm/diag_Form URI. Because the router saves ping results in…

EPSS
99.9%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Debian, Samba

CVE-2017-7494

Debian Linux, Samba

Known exploitation is confirmed by CISA KEV. Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share, and then…

EPSS
99.4%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Apache, Arubanetworks +5 more

CVE-2017-5638

Clearpass Policy Manager, Oncommand Balance, Server Automation +6 more

Known exploitation is confirmed by CISA KEV. The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary…

EPSS
100.0%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Oracle, Sun +1 more

CVE-2013-2465

Java SE, Jre, Linux Enterprise Desktop +3 more

Known exploitation is confirmed by CISA KEV. Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7,…

EPSS
98.7%
CVSS
9.8
Ransomware
Known
View evidence
88Fix now

Canonical, Opensuse +1 more

CVE-2013-0422

Java Runtime Environment (JRE), Jdk, Jre +2 more

Known exploitation is confirmed by CISA KEV. Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public getMBeanInstantiator method in the JmxMBeanServer class to obtain a reference to…

EPSS
97.6%
CVSS
9.8
Ransomware
Known
View evidence
87Fix now

Microsoft

CVE-2021-26855

Exchange Server

Known exploitation is confirmed by CISA KEV. Microsoft Exchange Server Remote Code Execution Vulnerability

EPSS
100.0%
CVSS
9.1
Ransomware
Known
View evidence
87Fix now

Microsoft

CVE-2020-0618

Sql Server

Known exploitation is confirmed by CISA KEV. A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'.

EPSS
99.0%
CVSS
8.8
Ransomware
Known
View evidence
87Fix now

Microsoft, Siemens

CVE-2017-0144

Acuson P300 Firmware, Acuson P500 Firmware, Acuson Sc2000 Firmware +7 more

Known exploitation is confirmed by CISA KEV. The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10…

EPSS
99.2%
CVSS
8.8
Ransomware
Known
View evidence
87Fix now

Red Hat, Redhat

CVE-2017-12149

JBoss Application Server, Jboss Enterprise Application Platform

Known exploitation is confirmed by CISA KEV. In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for…

EPSS
90.7%
CVSS
9.8
Ransomware
Known
View evidence
87Fix now

Quest

CVE-2018-11138

Kace System Management Appliance

Known exploitation is confirmed by CISA KEV. The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be abused to execute arbitrary commands on the system.

EPSS
92.1%
CVSS
9.8
Ransomware
Known
View evidence
87Fix now

Microsoft

CVE-2021-40444

MSHTML, Windows 10 1507, Windows 10 1607 +15 more

Known exploitation is confirmed by CISA KEV. Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks that attempt to exploit this vulnerability by using specially-crafted Microsoft…

EPSS
97.5%
CVSS
8.8
Ransomware
Known
View evidence
87Fix now

Microsoft

CVE-2021-34527

Windows, Windows 10 1507, Windows 10 1607 +13 more

Known exploitation is confirmed by CISA KEV. A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An…

EPSS
99.8%
CVSS
8.8
Ransomware
Known
View evidence
87Fix now

Microsoft

CVE-2021-34523

Exchange Server

Known exploitation is confirmed by CISA KEV. Microsoft Exchange Server Elevation of Privilege Vulnerability

EPSS
100.0%
CVSS
9.0
Ransomware
Known
View evidence
87Fix now

Microsoft

CVE-2021-34473

Exchange Server

Known exploitation is confirmed by CISA KEV. Microsoft Exchange Server Remote Code Execution Vulnerability

EPSS
100.0%
CVSS
9.1
Ransomware
Known
View evidence
87Fix now

Apache, Broadcom +9 more

CVE-2021-40438

Apache, Brocade Fabric Operating System Firmware, Cloud Backup +36 more

Known exploitation is confirmed by CISA KEV. A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.

EPSS
100.0%
CVSS
9.0
Ransomware
Known
View evidence
87Fix now

Oracle, Redhat

CVE-2012-1723

Enterprise Linux Desktop, Enterprise Linux Eus, Enterprise Linux Server +6 more

Known exploitation is confirmed by CISA KEV. Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier…

EPSS
93.7%
CVSS
9.8
Ransomware
Known
View evidence
87Fix now

Cleo

CVE-2024-55956

Harmony, Lexicom, Multiple Products +1 more

Known exploitation is confirmed by CISA KEV. In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default…

EPSS
93.8%
CVSS
9.8
Ransomware
Known
View evidence
87Fix now

Check Point, Checkpoint

CVE-2024-24919

Cloudguard Network Security, Quantum Security Gateway Firmware, Quantum Security Gateways +1 more

Known exploitation is confirmed by CISA KEV. Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix…

EPSS
100.0%
CVSS
8.6
Ransomware
Known
View evidence
87Fix now

Cyberpanel, CyberPersons

CVE-2024-51378

CyberPanel

Known exploitation is confirmed by CISA KEV. getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or /ftp/getresetstatus by bypassing secMiddleware (which is only…

EPSS
94.7%
CVSS
9.8
Ransomware
Known
View evidence
87Fix now

Smartertools

CVE-2026-23760

Smartermail

Known exploitation is confirmed by CISA KEV. SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a…

EPSS
96.3%
CVSS
9.3
Ransomware
Known
View evidence
87Fix now

Citrix

CVE-2025-5777

NetScaler ADC and Gateway, Netscaler Application Delivery Controller, Netscaler Gateway

Known exploitation is confirmed by CISA KEV. Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server

EPSS
100.0%
CVSS
9.3
Ransomware
Known
View evidence
87Fix now

Ivanti

CVE-2025-0282

Connect Secure, Policy Secure, and ZTA Gateways +1 more

Known exploitation is confirmed by CISA KEV. A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to…

EPSS
100.0%
CVSS
9.0
Ransomware
Known
View evidence
87Fix now

Sonicwall

CVE-2024-53704

Sonicos

Known exploitation is confirmed by CISA KEV. An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.

EPSS
95.1%
CVSS
9.8
Ransomware
Known
View evidence
87Fix now

Ivanti

CVE-2024-21887

Connect Secure, Connect Secure and Policy Secure, Policy Secure

Known exploitation is confirmed by CISA KEV. A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands…

EPSS
100.0%
CVSS
9.1
Ransomware
Known
View evidence