Skip to content
Weekly Signal

Confirmed attacker activity

Exploited Now

Vulnerabilities with confirmed exploitation evidence, ranked by the Cornish Geek Signal.

Updated 20 Aug 2026 · 01:30 UTC

1670Confirmed exploited
1670In CISA KEV
349Linked to ransomware
1670Guidance available
Clear

Exploitation priorities

1670 matching vulnerabilities

87Fix now

Mitel

CVE-2024-41713

Micollab

Known exploitation is confirmed by CISA KEV. A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input…

EPSS
98.1%
CVSS
9.1
Ransomware
Known
View evidence
87Fix now

Synacor

CVE-2022-37042

Zimbra Collaboration Suite, Zimbra Collaboration Suite (ZCS)

Known exploitation is confirmed by CISA KEV. Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing authentication (i.e., not having an authtoken), an attacker can upload…

EPSS
91.9%
CVSS
9.8
Ransomware
Known
View evidence
87Fix now

Palo Alto Networks, Paloaltonetworks

CVE-2024-0012

PAN-OS

Known exploitation is confirmed by CISA KEV. An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with…

EPSS
99.7%
CVSS
9.3
Ransomware
Known
View evidence
87Fix now

Oracle

CVE-2026-35273

Peoplesoft Enterprise Peopletools

Known exploitation is confirmed by CISA KEV. Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access…

EPSS
95.5%
CVSS
9.8
Ransomware
Known
View evidence
87Fix now

Apache, Broadcom +4 more

CVE-2018-1273

Financial Services Crime And Compliance Management Studio, Ignite, Spring Data Commons +1 more

Known exploitation is confirmed by CISA KEV. Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious…

EPSS
95.7%
CVSS
9.8
Ransomware
Known
View evidence
87Fix now

Cpanel, WebPros

CVE-2026-41940

Cpanel, cPanel & WHM and WP2 (WordPress Squared), Whm +1 more

Known exploitation is confirmed by CISA KEV. cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

EPSS
97.9%
CVSS
9.3
Ransomware
Known
View evidence
87Fix now

Beyondtrust

CVE-2026-1731

Privileged Remote Access, Remote Support, Remote Support (RS) and Privileged Remote Access (PRA)

Known exploitation is confirmed by CISA KEV. BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be…

EPSS
89.4%
CVSS
9.9
Ransomware
Known
View evidence
87Fix now

Smartertools

CVE-2025-52691

Smartermail

Known exploitation is confirmed by CISA KEV. Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.

EPSS
85.5%
CVSS
10.0
Ransomware
Known
View evidence
87Fix now

Microsoft

CVE-2025-49704

SharePoint, Sharepoint Server

Known exploitation is confirmed by CISA KEV. Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

EPSS
100.0%
CVSS
8.8
Ransomware
Known
View evidence
87Fix now

Solarwinds

CVE-2025-26399

Web Help Desk

Known exploitation is confirmed by CISA KEV. SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine.…

EPSS
88.3%
CVSS
9.8
Ransomware
Known
View evidence
87Fix now

Progress

CVE-2024-6670

Whatsup Gold

Known exploitation is confirmed by CISA KEV. In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password.

EPSS
94.7%
CVSS
9.8
Ransomware
Known
View evidence
87Fix now

Veeam

CVE-2024-40711

Backup & Replication, Veeam Backup & Replication

Known exploitation is confirmed by CISA KEV. A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).

EPSS
90.4%
CVSS
9.8
Ransomware
Known
View evidence
87Fix now

F5

CVE-2023-46747

Big-ip Access Policy Manager, Big-ip Advanced Firewall Manager, Big-ip Advanced Web Application Firewall +18 more

Known exploitation is confirmed by CISA KEV. Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands.  Note: Software versions…

EPSS
96.5%
CVSS
9.8
Ransomware
Known
View evidence
87Fix now

Microsoft

CVE-2022-41040

Exchange Server

Known exploitation is confirmed by CISA KEV. Microsoft Exchange Server Elevation of Privilege Vulnerability

EPSS
100.0%
CVSS
8.8
Ransomware
Known
View evidence
87Fix now

Dotcms

CVE-2022-26352

Dotcms

Known exploitation is confirmed by CISA KEV. An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02. Attackers can craft a multipart form request to post a file whose filename is not initially sanitized. This allows…

EPSS
91.1%
CVSS
9.8
Ransomware
Known
View evidence
87Fix now

Apache, Cvat +5 more

CVE-2021-45046

6bk1602-0aa12-0tp0 Firmware, 6bk1602-0aa22-0tp0 Firmware, 6bk1602-0aa32-0tp0 Firmware +53 more

Known exploitation is confirmed by CISA KEV. It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data…

EPSS
100.0%
CVSS
9.0
Ransomware
Known
View evidence
87Fix now

Solarwinds

CVE-2021-35211

Serv-u

Known exploitation is confirmed by CISA KEV. Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product utilizing a Remote Memory Escape Vulnerability. If exploited, a threat actor may be able to gain privileged access to…

EPSS
91.2%
CVSS
10.0
Ransomware
Known
View evidence
87Fix now

Microsoft

CVE-2020-0688

Exchange Server

Known exploitation is confirmed by CISA KEV. A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Memory Corruption Vulnerability'.

EPSS
100.0%
CVSS
8.8
Ransomware
Known
View evidence
87Fix now

Qnap

CVE-2019-7195

Photo Station

Known exploitation is confirmed by CISA KEV. This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.

EPSS
89.7%
CVSS
9.8
Ransomware
Known
View evidence
87Fix now

Qnap

CVE-2019-7192

Photo Station

Known exploitation is confirmed by CISA KEV. This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station to their latest versions.

EPSS
88.2%
CVSS
9.8
Ransomware
Known
View evidence
87Fix now

D-Link, Dlink

CVE-2019-16057

Dns-320 Firmware, DNS-320 Storage Device

Known exploitation is confirmed by CISA KEV. The login_mgr.cgi script in D-Link DNS-320 through 2.05.B10 is vulnerable to remote command injection.

EPSS
87.1%
CVSS
9.8
Ransomware
Known
View evidence
87Fix now

Atlassian

CVE-2019-11580

Crowd, Crowd and Crowd Data Center

Known exploitation is confirmed by CISA KEV. Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attackers who can send unauthenticated or authenticated requests to a Crowd or Crowd Data Center instance…

EPSS
95.4%
CVSS
9.8
Ransomware
Known
View evidence
86Fix now

Microsoft

CVE-2021-42321

Exchange, Exchange Server

Known exploitation is confirmed by CISA KEV. Microsoft Exchange Server Remote Code Execution Vulnerability

EPSS
90.4%
CVSS
8.8
Ransomware
Known
View evidence
86Fix now

Microsoft

CVE-2021-27065

Exchange Server

Known exploitation is confirmed by CISA KEV. Microsoft Exchange Server Remote Code Execution Vulnerability

EPSS
99.9%
CVSS
7.8
Ransomware
Known
View evidence
86Fix now

Microsoft, Siemens

CVE-2017-0145

Acuson P300 Firmware, Acuson P500 Firmware, Acuson Sc2000 Firmware +7 more

Known exploitation is confirmed by CISA KEV. The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10…

EPSS
89.9%
CVSS
8.8
Ransomware
Known
View evidence