Skip to content
Weekly Signal

Confirmed attacker activity

Exploited Now

Vulnerabilities with confirmed exploitation evidence, ranked by the Cornish Geek Signal.

Updated 20 Aug 2026 · 04:00 UTC

1671Confirmed exploited
1671In CISA KEV
349Linked to ransomware
1671Guidance available
Clear

Exploitation priorities

1671 matching vulnerabilities

85Fix now

Splunk

CVE-2026-20253

Enterprise, Splunk

Known exploitation is confirmed by CISA KEV. In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint. The vulnerability exists because the…

EPSS
96.9%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

Ivanti

CVE-2026-10520

Sentry, Standalone Sentry

Known exploitation is confirmed by CISA KEV. An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution

EPSS
99.9%
CVSS
10.0
Ransomware
Not reported
View evidence
85Fix now

SonicWall

CVE-2026-15409

SMA1000 Appliances, Sma6210 Firmware, Sma7210 Firmware +1 more

Known exploitation is confirmed by CISA KEV. A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.

EPSS
74.2%
CVSS
10.0
Ransomware
Known
View evidence
85Fix now

Adobe

CVE-2026-48282

ColdFusion

Known exploitation is confirmed by CISA KEV. ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context…

EPSS
99.2%
CVSS
10.0
Ransomware
Not reported
View evidence
85Fix now

Debian, GNU

CVE-2026-24061

Debian Linux, InetUtils

Known exploitation is confirmed by CISA KEV. telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.

EPSS
97.9%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

Palo Alto Networks, Paloaltonetworks +1 more

CVE-2026-0257

PAN-OS, Prisma Access, Ruggedcom Ape1808 Firmware

Known exploitation is confirmed by CISA KEV. Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW…

EPSS
93.9%
CVSS
7.8
Ransomware
Known
View evidence
85Fix now

Microsoft

CVE-2025-59287

Windows, Windows Server 2012, Windows Server 2016 +4 more

Known exploitation is confirmed by CISA KEV. Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.

EPSS
99.9%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

Wftpserver, Wing FTP Server

CVE-2025-47812

Wing FTP Server

Known exploitation is confirmed by CISA KEV. In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection of arbitrary Lua code into user session files. This can be used to execute…

EPSS
95.5%
CVSS
10.0
Ransomware
Not reported
View evidence
85Fix now

Cisco, Debian +1 more

CVE-2025-32433

Cloud Native Broadband Network Gateway, Confd Basic, Debian Linux +20 more

Known exploitation is confirmed by CISA KEV. Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE).…

EPSS
98.6%
CVSS
10.0
Ransomware
Not reported
View evidence
85Fix now

Craft CMS, Craftcms

CVE-2025-32432

Craft CMS

Known exploitation is confirmed by CISA KEV. Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, and 5.0.0-RC1 to before 5.6.17,…

EPSS
99.8%
CVSS
10.0
Ransomware
Not reported
View evidence
85Fix now

Fortinet

CVE-2025-25257

FortiWeb

Known exploitation is confirmed by CISA KEV. An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.0 through 7.4.7, FortiWeb 7.2.0 through 7.2.10, FortiWeb 7.0.0…

EPSS
99.8%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

XWiki

CVE-2025-24893

Platform, Xwiki

Known exploitation is confirmed by CISA KEV. XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any guest can perform arbitrary remote code execution through a request to `SolrSearch`. This impacts…

EPSS
99.9%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

Apache, Debian +1 more

CVE-2025-24813

Bootstrap Os, Debian Linux, Tomcat

Known exploitation is confirmed by CISA KEV. Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through…

EPSS
99.9%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

Cisco

CVE-2025-20281

Identity Services Engine, Identity Services Engine Passive Identity Connector

Known exploitation is confirmed by CISA KEV. A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does…

EPSS
97.1%
CVSS
10.0
Ransomware
Not reported
View evidence
85Fix now

Palo Alto Networks, Paloaltonetworks

CVE-2024-9463

Expedition

Known exploitation is confirmed by CISA KEV. An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations,…

EPSS
98.5%
CVSS
9.9
Ransomware
Not reported
View evidence
85Fix now

Ivanti

CVE-2024-7593

Virtual Traffic Manager

Known exploitation is confirmed by CISA KEV. Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the admin panel.

EPSS
100.0%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

Aviatrix

CVE-2024-50603

Controller, Controllers

Known exploitation is confirmed by CISA KEV. An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutralization of special elements used in an OS command, an unauthenticated attacker is able to…

EPSS
98.5%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

Progress

CVE-2024-4885

WhatsUp Gold

Known exploitation is confirmed by CISA KEV. In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold.  The WhatsUp.ExportUtilities.Export.GetFileWithoutZip allows execution of commands with iisapppool\nmconsole privileges.

EPSS
99.3%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

Progress, Telerik

CVE-2024-4358

Report Server 2024, Telerik Report Server

Known exploitation is confirmed by CISA KEV. In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Server restricted functionality via an authentication bypass vulnerability.

EPSS
97.5%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

CrushFTP

CVE-2024-4040

CrushFTP

Known exploitation is confirmed by CISA KEV. A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS…

EPSS
99.5%
CVSS
10.0
Ransomware
Not reported
View evidence
85Fix now

Synacor

CVE-2024-45519

Zimbra Collaboration Suite, Zimbra Collaboration Suite (ZCS)

Known exploitation is confirmed by CISA KEV. The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.1.1 sometimes allows unauthenticated users to execute commands.

EPSS
99.9%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

D-Link, Dlink

CVE-2024-3273

Dnr-202l Firmware, Dnr-322l Firmware, Dnr-326 Firmware +18 more

Known exploitation is confirmed by CISA KEV. ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. Affected is an unknown function of the file…

EPSS
100.0%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

D-Link, Dlink

CVE-2024-3272

Dnr-202l Firmware, Dnr-322l Firmware, Dnr-326 Firmware +18 more

Known exploitation is confirmed by CISA KEV. ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as very critical, has been found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. This issue affects some unknown processing…

EPSS
98.0%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

Apache

CVE-2024-38856

OFBiz

Known exploitation is confirmed by CISA KEV. Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are recommended to upgrade to version 18.12.15, which fixes the issue. Unauthenticated endpoints could allow execution of screen…

EPSS
99.4%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

Geoserver, Geotools +1 more

CVE-2024-36401

GeoServer, Geotools

Known exploitation is confirmed by CISA KEV. GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.22.6, 2.23.6, 2.24.4, and 2.25.2, multiple OGC request parameters allow Remote Code Execution (RCE)…

EPSS
99.8%
CVSS
9.8
Ransomware
Not reported
View evidence