Internet Exposure Likelihood: HIGH
CVSS: 8.1
CVE-2026-42016 is a critical incorrect authorization flaw in JFrog Artifactory Self-Hosted (before 7.133.11) where token validation checks signature/issuer but not scope, allowing low-privileged authenticated users to escalate privileges to admin. It is being actively exploited in the wild, chained with other CVEs, and is listed in the CISA KEV catalog, making it a direct T1190 threat against internet-facing Artifactory instances.
CVE ADDED: 2026-07-27
46 DAYS BETWEEN CVE AND KEV
3 DAYS SINCE KEV
View Details →
Internet Exposure Likelihood: HIGH
CVSS: 7.5
CVE-2026-42018 is an improper authentication vulnerability in JFrog Artifactory that allows an unauthenticated remote attacker to obtain an internal anonymous-user token even when anonymous access is disabled, exposing sensitive resources. It is actively exploited in the wild (CISA KEV listed), commonly chained with CVE-2026-42016 and CVE-2026-82329 to achieve full administrative control of the Artifactory server.
CVE ADDED: 2026-08-12
30 DAYS BETWEEN CVE AND KEV
3 DAYS SINCE KEV
View Details →
Internet Exposure Likelihood: HIGH
CVSS: 10.0
CVE-2026-85706 is a maximum-severity (CVSS 10.0) path traversal vulnerability in GitLab CE/EE's repository commits API that allows unauthenticated remote attackers to read arbitrary files from the GitLab server filesystem. Due to improper path confinement and missing authentication enforcement, a single unauthenticated HTTP request can exfiltrate secrets, credentials, and source code from the server. It is actively exploited in the wild and listed in the CISA KEV catalog.
CVE ADDED: 2026-09-12
0 DAY BETWEEN CVE AND KEV
3 DAYS SINCE KEV
View Details →
Internet Exposure Likelihood: HIGH
CVSS: 8.8
CVE-2026-67277 is an unauthenticated pre-authentication flaw in MikroTik RouterOS's btest (bandwidth test) service (CWE-306, Missing Authentication) that allows a remote attacker to disclose kernel memory and trigger a denial-of-service kernel restart. It is remotely exploitable over the network without authentication or user interaction and is actively exploited in the wild (CISA KEV listed).
CVE ADDED: 2026-09-05
5 DAYS BETWEEN CVE AND KEV
4 DAYS SINCE KEV
View Details →
Internet Exposure Likelihood: HIGH
CVSS: 9.2
CVE-2026-86060 is a critical (CVSS 9.2) argument injection vulnerability in the SSH login path of MikroTik RouterOS. An unauthenticated attacker can supply a crafted username beginning with a prohibited character to manipulate the RouterOS trusted policy mask, achieving privilege escalation and full device compromise. It is actively exploited in the wild and listed in CISA KEV.
CVE ADDED: 2026-09-05
5 DAYS BETWEEN CVE AND KEV
4 DAYS SINCE KEV
View Details →
Internet Exposure Likelihood: VERY_HIGH
CVSS: 9.3
CVE-2026-19490 is a critical (CVSS 9.3) authentication bypass (CWE-288) in NetScaler ADC and NetScaler Gateway that allows unauthenticated attackers to forge sessions via the SAML HTTP-Redirect binding handler (/cgi/samlauth). It requires no privileges or user interaction, is actively exploited in the wild, and is listed in CISA KEV, making it a textbook T1190 initial-access vulnerability against internet-facing edge appliances.
CVE ADDED: 2026-08-19
21 DAYS BETWEEN CVE AND KEV
5 DAYS SINCE KEV
View Details →
Internet Exposure Likelihood: VERY_HIGH
CVSS: 10.0
CVE-2026-75650 ('StyleSmuggler') is a CVSS 10.0 server-side template injection (CWE-1336) vulnerability in Adobe Commerce and Magento Open Source that enables unauthenticated remote code execution on the underlying server. It is actively exploited in the wild, listed in CISA KEV, and requires no user interaction or authentication. E-commerce platforms are almost universally internet-facing, making this a critical direct-exploitation risk.
CVE ADDED: 2026-09-07
1 DAY BETWEEN CVE AND KEV
6 DAYS SINCE KEV
View Details →
Internet Exposure Likelihood: HIGH
CVSS: 10.0
CVE-2026-86218 is a critical (CVSS 10.0) pre-authentication remote code execution vulnerability in N-able N-central, an RMM platform widely used by MSPs. Unauthenticated remote attackers can achieve full code execution on the server over the network with no user interaction, and the flaw is confirmed to be actively exploited in the wild (CISA KEV listed). This is a textbook T1190 initial access vulnerability granting complete server takeover.
CVE ADDED: 2026-09-06
2 DAYS BETWEEN CVE AND KEV
6 DAYS SINCE KEV
View Details →
Internet Exposure Likelihood: HIGH
CVSS: 8.8
CVE-2026-59822 is a critical authentication bypass in LiteLLM's MCP Streamable HTTP endpoint, where a fabricated Authorization header triggers an OAuth2 passthrough fallback that replaces failed key validation with an empty auth object. This allows unauthenticated remote attackers to reach MCP tooling without valid credentials. It is confirmed exploited in the wild and listed in CISA KEV.
CVE ADDED: 2026-07-08
56 DAYS BETWEEN CVE AND KEV
12 DAYS SINCE KEV
View Details →
Internet Exposure Likelihood: HIGH
CVSS: 9.8
CVE-2026-82329 is a critical authentication bypass vulnerability (CWE-287) in JFrog Artifactory that allows unauthenticated remote attackers to obtain administrative privileges under default configuration. With a CVSS score of 9.8, no privileges or user interaction required, and confirmed active exploitation by CISA KEV listing, this represents an immediately weaponisable internet-facing threat. Successful exploitation gives the attacker full administrative control over the Artifactory server, its artifact repositories, and any integrated build/CI-CD pipeline credentials.
CVE ADDED: 2026-08-28
5 DAYS BETWEEN CVE AND KEV
12 DAYS SINCE KEV
View Details →
Internet Exposure Likelihood: VERY_HIGH
CVSS: 10.0
CVE-2026-83548 is a pre-authentication SSRF vulnerability in the SonicWall SMA1000 Work Place interface, exploitable remotely without authentication or user interaction, with a maximum CVSS score of 10.0. It is actively exploited in the wild and listed in CISA KEV, allowing unauthenticated attackers to reach internal sensitive functionality via an unintended alternate access path, effectively compromising the appliance itself.
CVE ADDED: 2026-09-01
1 DAY BETWEEN CVE AND KEV
12 DAYS SINCE KEV
View Details →
Internet Exposure Likelihood: MEDIUM
CVSS: 9.3
CVE-2026-9586 is a critical unauthenticated SQL injection vulnerability in Sangoma Switchvox SMB Edition versions prior to 8.4.0.2, affecting the /pa endpoint which processes PolycomIPPhone XML content. A remote unauthenticated attacker can send a single crafted HTTP request to inject arbitrary PostgreSQL commands, achieving remote code execution on the PBX server. This vulnerability is confirmed in CISA's Known Exploited Vulnerabilities catalog with active exploitation in the wild.
CVE ADDED: 2026-07-17
47 DAYS BETWEEN CVE AND KEV
12 DAYS SINCE KEV
View Details →
Internet Exposure Likelihood: MEDIUM
CVSS: 8.8
CVE-2026-81578 is an unauthenticated improper access control / authentication bypass vulnerability in the web management interface of PaperCut MF/NG. Remote attackers can trigger administrative backend actions before access validation completes, modifying server configurations. It is actively exploited in the wild, listed in CISA KEV, and is frequently chained with CVE-2026-82078 to achieve pre-authentication RCE on the PaperCut Application Server.
CVE ADDED: 2026-08-28
3 DAYS BETWEEN CVE AND KEV
14 DAYS SINCE KEV
View Details →
Internet Exposure Likelihood: HIGH
CVSS: 9.4
CVE-2026-82078 is a critical unsafe dynamic class loading (CWE-470) vulnerability in the database connector of PaperCut MF/NG that enables arbitrary Java bytecode execution in the security context of the PaperCut server process. While it nominally requires high privileges to manipulate configuration, it is actively exploited in the wild and chainable with CVE-2026-81578 to achieve pre-authentication remote code execution against internet-facing print management servers. It is listed in the CISA KEV catalog with a public Metasploit module available.
CVE ADDED: 2026-08-28
3 DAYS BETWEEN CVE AND KEV
14 DAYS SINCE KEV
View Details →
Internet Exposure Likelihood: VERY_HIGH
CVSS: 8.8
CVE-2026-8452 is a memory overflow (CWE-119) vulnerability in Citrix NetScaler ADC and NetScaler Gateway appliances configured as Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual servers. It is unauthenticated, network-reachable, and has demonstrated pre-authentication remote code execution as root, with active in-the-wild exploitation and CISA KEV listing. This represents a critical, direct T1190 perimeter compromise risk.
CVE ADDED: 2026-06-30
57 DAYS BETWEEN CVE AND KEV
19 DAYS SINCE KEV
View Details →
Internet Exposure Likelihood: HIGH
CVSS: 9.8
CVE-2026-60004 is a critical (CVSS 9.8) remote code execution vulnerability in Gitea before 1.27.1, exploitable via the diffpatch API through Git hook installation. Successful exploitation allows an attacker to execute arbitrary shell commands with the privileges of the Gitea service account, resulting in full server compromise. It is listed in CISA KEV with confirmed active exploitation and public PoC availability.
CVE ADDED: 2026-08-26
0 DAY BETWEEN CVE AND KEV
20 DAYS SINCE KEV
View Details →
Internet Exposure Likelihood: VERY_HIGH
CVSS: 8.9
CVE-2026-73570 is an unauthenticated OS command injection (RCE) vulnerability in Zimbra Collaboration Suite (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. An attacker can send specially crafted SMTP requests that trigger arbitrary OS command execution as the Zimbra user. This is a server-side RCE in an internet-facing mail collaboration platform, actively exploited in the wild and listed in CISA KEV.
CVE ADDED: 2026-08-13
8 DAYS BETWEEN CVE AND KEV
24 DAYS SINCE KEV
View Details →
Internet Exposure Likelihood: HIGH
CVSS: 9.8
CVE-2026-72529 is a critical missing-authentication flaw in TrueConf Server that allows a remote, unauthenticated attacker to execute arbitrary scripts by calling an undocumented function over TCP port 4307. This is a server-side vulnerability in internet-facing video conferencing infrastructure, actively exploited in the wild by the Head Mare threat actor group and listed in CISA KEV.
CVE ADDED: 2026-08-19
1 DAY BETWEEN CVE AND KEV
25 DAYS SINCE KEV
View Details →
Internet Exposure Likelihood: HIGH
CVSS: 9.5
CVE-2026-72530 is a critical unauthenticated code injection vulnerability in TrueConf Server that allows a remote attacker with network access to TCP port 4307 to break out of an isolated environment and execute arbitrary code on the host. The flaw requires no authentication or user interaction and is confirmed to be actively exploited in the wild (CISA KEV listed). This is a textbook T1190 case delivering direct server-side RCE.
CVE ADDED: 2026-08-19
1 DAY BETWEEN CVE AND KEV
25 DAYS SINCE KEV
View Details →
Internet Exposure Likelihood: MEDIUM
CVSS: 9.3
CVE-2026-64849 is a critical unauthenticated Server-Side Request Forgery (SSRF) vulnerability in MLflow's webhook delivery feature. The unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint validates only the original URL while following redirects and re-resolving hostnames without pinning validated addresses, allowing attackers to reach internal services and cloud metadata endpoints (e.g., 169.254.169.254) to steal cloud credentials. It is actively exploited and listed in CISA KEV.
CVE ADDED: 2026-08-17
2 DAYS BETWEEN CVE AND KEV
26 DAYS SINCE KEV
View Details →
Internet Exposure Likelihood: HIGH
CVSS: 9.1
CVE-2026-55040 is a critical authentication bypass (weak authentication in JWT token validation) in Microsoft SharePoint Server, allowing an unauthenticated remote attacker to bypass authentication over the network and gain access to the SharePoint server and its data. With a CVSS 9.1, active exploitation, public PoC, and CISA KEV listing, this is a high-risk, directly internet-exploitable server-side vulnerability that clearly maps to T1190.
CVE ADDED: 2026-07-14
35 DAYS BETWEEN CVE AND KEV
27 DAYS SINCE KEV
View Details →
Internet Exposure Likelihood: MEDIUM
CVSS: 9.8
RANSOMWARE USE
CVE-2026-59310 is a critical (CVSS 9.8) directory traversal vulnerability in the Syslog server component of VMware vCenter that allows an unauthenticated remote attacker with network access to execute arbitrary code with root-level privileges. This grants direct server compromise of the central virtualization management plane, and it is under active exploitation and listed in CISA KEV.
CVE ADDED: 2026-07-30
19 DAYS BETWEEN CVE AND KEV
27 DAYS SINCE KEV
RANSOMWARE TAGGED AFTER 27 DAYS
View Details →
Internet Exposure Likelihood: MEDIUM
CVSS: 9.8
CVE-2026-65400 is a critical improper authentication vulnerability (CWE-287) in the macOS Screen Sharing (VNC/ARD) service that allows a remote, unauthenticated network attacker to authenticate without valid credentials. Because the service runs with root-level privileges and requires no user interaction, exploitation grants direct server access. It is actively exploited in the wild and listed in CISA KEV, making it a HIGH_RISK internet-facing threat where the Screen Sharing port (TCP/5900) is exposed.
CVE ADDED: 2026-08-06
12 DAYS BETWEEN CVE AND KEV
27 DAYS SINCE KEV
View Details →