Internet Exposure Likelihood: HIGH
CVSS: 10.0
Critical authentication bypass vulnerability in Cisco Catalyst SD-WAN Manager allowing unauthenticated remote attackers to gain administrative privileges. CISA has issued Emergency Directive ED 26-03 due to active exploitation in the wild.
CVE ADDED: 2026-02-25
0 DAY BETWEEN CVE AND KEV
2 DAYS SINCE KEV
View Details →
Internet Exposure Likelihood: HIGH
CVSS: 8.8
FileZen contains an OS command injection vulnerability allowing authenticated users to execute arbitrary OS commands via specially crafted HTTP requests when the Antivirus Check Option is enabled. This is a critical server-side vulnerability in a file sharing platform commonly deployed as internet-facing infrastructure.
CVE ADDED: 2026-02-13
11 DAYS BETWEEN CVE AND KEV
3 DAYS SINCE KEV
View Details →
Internet Exposure Likelihood: MEDIUM
CVSS: 10.0
Dell RecoverPoint for VMs contains hardcoded credentials allowing unauthenticated remote attackers to gain root-level access to the underlying OS. This critical vulnerability is under active exploitation in the wild.
CVE ADDED: 2026-02-17
1 DAY BETWEEN CVE AND KEV
9 DAYS SINCE KEV
View Details →
Internet Exposure Likelihood: HIGH
CVSS: 9.9
RANSOMWARE USE
Critical pre-authentication remote code execution vulnerability in BeyondTrust Remote Support and Privileged Remote Access allowing unauthenticated attackers to execute OS commands via specially crafted requests. Active exploitation confirmed with CISA KEV listing.
CVE ADDED: 2026-02-06
7 DAYS BETWEEN CVE AND KEV
14 DAYS SINCE KEV
View Details →
Internet Exposure Likelihood: VERY_HIGH
CVSS: 8.1
CVE-2025-40536 is a security control bypass vulnerability in SolarWinds Web Help Desk that allows unauthenticated attackers to gain access to restricted functionality. This vulnerability is being actively exploited in the wild against internet-facing WHD instances for initial access and lateral movement.
CVE ADDED: 2026-01-28
15 DAYS BETWEEN CVE AND KEV
15 DAYS SINCE KEV
View Details →
Internet Exposure Likelihood: VERY_HIGH
CVSS: 9.3
RANSOMWARE USE
Critical unauthenticated remote code execution vulnerability in SmarterMail servers through the ConnectToHub API method. Attackers can execute arbitrary OS commands by pointing the server to a malicious HTTP server, with active exploitation confirmed by CISA KEV listing.
CVE ADDED: 2026-01-23
13 DAYS BETWEEN CVE AND KEV
22 DAYS SINCE KEV
View Details →
Internet Exposure Likelihood: HIGH
CVSS: 9.8
Critical unauthenticated remote code execution vulnerability in SolarWinds Web Help Desk via untrusted data deserialization. Actively exploited in the wild with no authentication required.
CVE ADDED: 2026-01-28
6 DAYS BETWEEN CVE AND KEV
24 DAYS SINCE KEV
View Details →
Internet Exposure Likelihood: HIGH
CVSS: 9.8
Critical code injection vulnerability in Ivanti Endpoint Manager Mobile allowing unauthenticated remote code execution. This vulnerability is actively exploited in zero-day attacks and listed on CISA's KEV catalog.
CVE ADDED: 2026-01-29
0 DAY BETWEEN CVE AND KEV
29 DAYS SINCE KEV
View Details →