Skip to content
Weekly Signal

Confirmed attacker activity

Exploited Now

Vulnerabilities with confirmed exploitation evidence, ranked by the Cornish Geek Signal.

Updated 20 Aug 2026 · 02:18 UTC

1671Confirmed exploited
1671In CISA KEV
349Linked to ransomware
1671Guidance available
Clear

Exploitation priorities

1671 matching vulnerabilities

86Fix now

Kaseya

CVE-2021-30116

Virtual System/Server Administrator (VSA), Vsa Agent, Vsa Server

Known exploitation is confirmed by CISA KEV. Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on premise offers a download page where the clients for the installation can…

EPSS
85.7%
CVSS
9.8
Ransomware
Known
View evidence
86Fix now

ConnectWise, Kaseya

CVE-2017-18362

Manageditsync, Virtual System/Server Administrator (VSA)

Known exploitation is confirmed by CISA KEV. ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database. In February 2019, attackers have actively exploited this…

EPSS
86.8%
CVSS
9.8
Ransomware
Known
View evidence
86Fix now

Oracle

CVE-2017-10271

WebLogic Server

Known exploitation is confirmed by CISA KEV. Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with…

EPSS
100.0%
CVSS
7.5
Ransomware
Known
View evidence
86Fix now

SonicWall

CVE-2021-20021

Email Security, Email Security Appliance 3300 Firmware, Email Security Appliance 4300 Firmware +9 more

Known exploitation is confirmed by CISA KEV. A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.

EPSS
83.4%
CVSS
9.8
Ransomware
Known
View evidence
86Fix now

VMware

CVE-2020-3992

Cloud Foundation, ESXi

Known exploitation is confirmed by CISA KEV. OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free issue. A malicious actor residing in the management network who has access to port…

EPSS
83.0%
CVSS
9.8
Ransomware
Known
View evidence
86Fix now

SonicWall

CVE-2019-7481

Sma 100 Firmware, SMA100

Known exploitation is confirmed by CISA KEV. Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources. This vulnerablity impacted SMA100 version 9.0.0.3 and earlier.

EPSS
99.9%
CVSS
7.5
Ransomware
Known
View evidence
86Fix now

Dtsearch, RARLAB

CVE-2025-8088

Dtsearch, WinRAR

Known exploitation is confirmed by CISA KEV. A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered…

EPSS
94.6%
CVSS
8.4
Ransomware
Known
View evidence
86Fix now

Microsoft

CVE-2024-21412

Windows, Windows 10 1809, Windows 10 21h2 +7 more

Known exploitation is confirmed by CISA KEV. Internet Shortcut Files Security Feature Bypass Vulnerability

EPSS
95.4%
CVSS
8.1
Ransomware
Known
View evidence
86Fix now

Microsoft

CVE-2022-30190

Windows, Windows 10 1507, Windows 10 1607 +14 more

Known exploitation is confirmed by CISA KEV. A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run arbitrary code…

EPSS
99.2%
CVSS
7.8
Ransomware
Known
View evidence
86Fix now

Apache, Netapp +1 more

CVE-2017-12615

7-mode Transition Tool, Enterprise Linux Desktop, Enterprise Linux Eus +19 more

Known exploitation is confirmed by CISA KEV. When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP…

EPSS
99.6%
CVSS
8.1
Ransomware
Known
View evidence
86Fix now

Qlik

CVE-2023-41265

Qlik Sense, Sense

Known exploitation is confirmed by CISA KEV. An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier,…

EPSS
84.5%
CVSS
9.9
Ransomware
Known
View evidence
86Fix now

RARLAB

CVE-2023-38831

WinRAR

Known exploitation is confirmed by CISA KEV. RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because a ZIP archive may include…

EPSS
97.8%
CVSS
7.8
Ransomware
Known
View evidence
86Fix now

Check Point, Checkpoint

CVE-2026-50751

Gaia Embedded, Gaia Os, Security Gateway

Known exploitation is confirmed by CISA KEV. A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN…

EPSS
82.6%
CVSS
9.3
Ransomware
Known
View evidence
86Fix now

SmarterTools

CVE-2026-24423

SmarterMail

Known exploitation is confirmed by CISA KEV. SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. The attacker could point the SmarterMail to the malicious HTTP server, which serves…

EPSS
87.7%
CVSS
9.3
Ransomware
Known
View evidence
86Fix now

Cyberpanel, CyberPersons

CVE-2024-51567

CyberPanel

Known exploitation is confirmed by CISA KEV. upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBases/upgrademysqlstatus by bypassing secMiddleware (which is only for a POST request)…

EPSS
86.5%
CVSS
9.8
Ransomware
Known
View evidence
86Fix now

Fortinet

CVE-2024-21762

FortiOS, Fortiproxy

Known exploitation is confirmed by CISA KEV. A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through…

EPSS
84.3%
CVSS
9.8
Ransomware
Known
View evidence
86Fix now

Ivanti

CVE-2024-21893

Connect Secure, Policy Secure, and Neurons +1 more

Known exploitation is confirmed by CISA KEV. A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain…

EPSS
100.0%
CVSS
8.2
Ransomware
Known
View evidence
86Fix now

Ivanti

CVE-2023-46805

Connect Secure, Connect Secure and Policy Secure, Policy Secure

Known exploitation is confirmed by CISA KEV. An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.

EPSS
100.0%
CVSS
8.2
Ransomware
Known
View evidence
86Fix now

Citrix

CVE-2023-4966

NetScaler ADC and NetScaler Gateway, Netscaler Application Delivery Controller, Netscaler Gateway

Known exploitation is confirmed by CISA KEV. Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA  virtual server.

EPSS
100.0%
CVSS
7.5
Ransomware
Known
View evidence
86Fix now

Fortinet

CVE-2023-27997

FortiOS, FortiOS and FortiProxy SSL-VPN, Fortiproxy

Known exploitation is confirmed by CISA KEV. A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 and below, version 7.0.9…

EPSS
85.7%
CVSS
9.8
Ransomware
Known
View evidence
86Fix now

Nextgen, NextGen Healthcare

CVE-2023-43208

Mirth Connect

Known exploitation is confirmed by CISA KEV. NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that this vulnerability is caused by the incomplete patch of CVE-2023-37679.

EPSS
82.7%
CVSS
9.8
Ransomware
Known
View evidence
86Fix now

Progress

CVE-2023-40044

WS_FTP Server

Known exploitation is confirmed by CISA KEV. In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Transfer module to execute remote commands on the underlying WS_FTP…

EPSS
90.1%
CVSS
8.8
Ransomware
Known
View evidence
86Fix now

Microsoft

CVE-2022-41082

Exchange Server

Known exploitation is confirmed by CISA KEV. Microsoft Exchange Server Remote Code Execution Vulnerability

EPSS
100.0%
CVSS
8.0
Ransomware
Known
View evidence
86Fix now

QNAP

CVE-2022-27593

Photo Station

Known exploitation is confirmed by CISA KEV. An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, This could allow an attacker to modify system files. We have already…

EPSS
87.9%
CVSS
9.1
Ransomware
Known
View evidence
86Fix now

QNAP

CVE-2021-28799

Hybrid Backup Sync, Network Attached Storage (NAS)

Known exploitation is confirmed by CISA KEV. An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exploited, the vulnerability allows remote attackers to log in to a device. This…

EPSS
78.3%
CVSS
9.8
Ransomware
Known
View evidence