Skip to content
Weekly Signal

Confirmed attacker activity

Exploited Now

Vulnerabilities with confirmed exploitation evidence, ranked by the Cornish Geek Signal.

Updated 20 Aug 2026 · 03:05 UTC

1671Confirmed exploited
1671In CISA KEV
349Linked to ransomware
1671Guidance available
Clear

Exploitation priorities

1671 matching vulnerabilities

86Fix now

QNAP

CVE-2019-7194

Photo Station

Known exploitation is confirmed by CISA KEV. This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.

EPSS
83.1%
CVSS
9.8
Ransomware
Known
View evidence
86Fix now

Canonical, Debian +1 more

CVE-2018-6789

Debian Linux, Exim, Ubuntu Linux

Known exploitation is confirmed by CISA KEV. An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted message, a buffer overflow may happen. This can be used to execute…

EPSS
81.7%
CVSS
9.8
Ransomware
Known
View evidence
86Fix now

Dnnsoftware, DotNetNuke (DNN)

CVE-2017-9822

Dotnetnuke, DotNetNuke (DNN)

Known exploitation is confirmed by CISA KEV. DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN sites."

EPSS
94.8%
CVSS
8.8
Ransomware
Known
View evidence
86Fix now

Microsoft

CVE-2017-11882

Office

Known exploitation is confirmed by CISA KEV. Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Microsoft Office 2016 allow an attacker to run arbitrary code in the context…

EPSS
99.9%
CVSS
7.8
Ransomware
Known
View evidence
86Fix now

Microsoft, Philips

CVE-2017-0199

Intellispace Portal, Office, Office and WordPad +4 more

Known exploitation is confirmed by CISA KEV. Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, Windows 8.1 allow remote attackers to…

EPSS
99.9%
CVSS
7.8
Ransomware
Known
View evidence
86Fix now

Microsoft, Siemens

CVE-2017-0148

Acuson P300 Firmware, Acuson P500 Firmware, Acuson Sc2000 Firmware +7 more

Known exploitation is confirmed by CISA KEV. The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10…

EPSS
99.4%
CVSS
8.1
Ransomware
Known
View evidence
86Fix now

Microsoft, Siemens

CVE-2017-0146

Acuson P300 Firmware, Acuson P500 Firmware, Acuson Sc2000 Firmware +7 more

Known exploitation is confirmed by CISA KEV. The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10…

EPSS
89.9%
CVSS
8.8
Ransomware
Known
View evidence
86Fix now

Microsoft, Siemens

CVE-2017-0147

Acuson P300 Firmware, Acuson P500 Firmware, Acuson Sc2000 Firmware +16 more

Known exploitation is confirmed by CISA KEV. The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10…

EPSS
99.7%
CVSS
7.5
Ransomware
Known
View evidence
86Fix now

Microsoft, Philips +1 more

CVE-2017-0143

Acuson P300 Firmware, Acuson P500 Firmware, Acuson Sc2000 Firmware +8 more

Known exploitation is confirmed by CISA KEV. The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10…

EPSS
93.3%
CVSS
8.8
Ransomware
Known
View evidence
86Fix now

Adobe, Oracle

CVE-2008-2992

Acrobat, Acrobat and Reader, Acrobat Reader +1 more

Known exploitation is confirmed by CISA KEV. Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a PDF file that calls the util.printf JavaScript function with a crafted format…

EPSS
98.5%
CVSS
7.8
Ransomware
Known
View evidence
85Fix now

Microsoft

CVE-2021-26858

Exchange Server

Known exploitation is confirmed by CISA KEV. Microsoft Exchange Server Remote Code Execution Vulnerability

EPSS
89.5%
CVSS
7.8
Ransomware
Known
View evidence
85Fix now

Microsoft

CVE-2021-26857

Exchange Server

Known exploitation is confirmed by CISA KEV. Microsoft Exchange Server Remote Code Execution Vulnerability

EPSS
94.0%
CVSS
7.8
Ransomware
Known
View evidence
85Fix now

Microsoft

CVE-2021-26411

Edge, Internet Explorer

Known exploitation is confirmed by CISA KEV. Internet Explorer Memory Corruption Vulnerability

EPSS
80.7%
CVSS
8.8
Ransomware
Known
View evidence
85Fix now

Canonical, Oracle +6 more

CVE-2021-4034

Command Center, Enterprise Linux, Enterprise Linux Desktop +27 more

Known exploitation is confirmed by CISA KEV. A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies.…

EPSS
94.9%
CVSS
7.8
Ransomware
Known
View evidence
85Fix now

Progress, Telerik

CVE-2017-11357

Telerik UI for ASP.NET AJAX, User Interface (UI) for ASP.NET AJAX

Known exploitation is confirmed by CISA KEV. Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.

EPSS
75.7%
CVSS
9.8
Ransomware
Known
View evidence
85Fix now

Adobe

CVE-2010-0188

Acrobat, Acrobat Reader, Reader and Acrobat

Known exploitation is confirmed by CISA KEV. Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.

EPSS
88.2%
CVSS
7.8
Ransomware
Known
View evidence
85Fix now

RARLAB

CVE-2018-20250

WinRAR

Known exploitation is confirmed by CISA KEV. In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field is manipulated with specific…

EPSS
96.3%
CVSS
7.8
Ransomware
Known
View evidence
85Fix now

Progress

CVE-2026-8037

Connection Manager For Objectscale, Ecs Connection Manager, LoadMaster +1 more

Known exploitation is confirmed by CISA KEV. OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command…

EPSS
99.3%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

Microsoft

CVE-2023-36884

Windows, Windows 10 1507, Windows 10 1607 +10 more

Known exploitation is confirmed by CISA KEV. Windows Search Remote Code Execution Vulnerability

EPSS
98.9%
CVSS
7.5
Ransomware
Known
View evidence
85Fix now

Fortra

CVE-2023-0669

Goanywhere Managed File Transfer, GoAnywhere MFT

Known exploitation is confirmed by CISA KEV. Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object. This issue was patched in version 7.1.2.

EPSS
100.0%
CVSS
7.2
Ransomware
Known
View evidence
85Fix now

Oracle

CVE-2025-61884

Configurator, E-Business Suite

Known exploitation is confirmed by CISA KEV. Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…

EPSS
97.8%
CVSS
7.5
Ransomware
Known
View evidence
85Fix now

Microsoft

CVE-2025-49706

SharePoint, Sharepoint Enterprise Server, SharePoint Server

Known exploitation is confirmed by CISA KEV. Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

EPSS
99.9%
CVSS
6.5
Ransomware
Known
View evidence
85Fix now

Simple-help, SimpleHelp

CVE-2024-57727

SimpleHelp

Known exploitation is confirmed by CISA KEV. SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These…

EPSS
95.2%
CVSS
7.5
Ransomware
Known
View evidence
85Fix now

Synacor

CVE-2022-27925

Zimbra Collaboration Suite, Zimbra Collaboration Suite (ZCS)

Known exploitation is confirmed by CISA KEV. Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary…

EPSS
98.6%
CVSS
7.2
Ransomware
Known
View evidence
85Fix now

Debian, RARLAB

CVE-2022-30333

Debian Linux, UnRAR

Known exploitation is confirmed by CISA KEV. RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android…

EPSS
99.1%
CVSS
7.5
Ransomware
Known
View evidence