Internet Exposure Likelihood: VERY_HIGH
CVSS: 9.5
CVE-2026-88771 is a critical improper input validation vulnerability (CWE-20) in Citrix NetScaler ADC and NetScaler Gateway that allows an unauthenticated remote attacker to execute arbitrary commands on the affected appliance without any user interaction. With a CVSS v4.0 score of 9.5, the vulnerability has been confirmed as actively exploited in the wild and is listed in CISA's Known Exploited Vulnerabilities catalog. NetScaler ADC and Gateway are by design internet-facing load balancing and remote access appliances, making virtually all unpatched deployments directly exposed to this attack.
CVE ADDED: 2026-09-27
0 DAY BETWEEN CVE AND KEV
1 DAY SINCE KEV
View Details →
Internet Exposure Likelihood: VERY_HIGH
CVSS: 9.5
CVE-2026-88772 is a critical memory overflow vulnerability (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway that allows unauthenticated remote attackers to achieve Remote Code Execution or Denial of Service without any user interaction. The vulnerability is triggered via the DTLS protocol, which is enabled by default on VPN virtual servers, meaning a large proportion of internet-facing deployments are exposed out-of-the-box. CISA has confirmed active exploitation in the wild and added this CVE to its Known Exploited Vulnerabilities catalog.
CVE ADDED: 2026-09-27
0 DAY BETWEEN CVE AND KEV
1 DAY SINCE KEV
View Details →
Internet Exposure Likelihood: HIGH
CVSS: 6.9
CVE-2026-67279 is a pre-authentication SSH state machine bypass in MikroTik RouterOS (versions 6.x < 6.49.21 and 7.x < 7.23.4/7.24.2) that allows an unauthenticated remote attacker to open a session channel and execute arbitrary commands by triggering a rekey before authentication is completed. This results in unauthorized file creation, overwrite, and reconstruction within the RouterOS file namespace, including configuration and diagnostic files. MikroTik routers are widely deployed as internet-facing network infrastructure, making this a high-impact, directly exploitable vulnerability with a CVSS 4.0 score of 6.9 and confirmed PoC availability.
CVE ADDED: 2026-09-05
20 DAYS BETWEEN CVE AND KEV
3 DAYS SINCE KEV
View Details →
Internet Exposure Likelihood: VERY_HIGH
CVSS: 8.1
CVE-2026-87902 is a critical unauthenticated Local File Inclusion (LFI) vulnerability in WordPress Core (versions 4.7 through 7.1.1) that allows attackers to manipulate the page-template resolution mechanism to include arbitrary local PHP files outside the active theme directory. Under server conditions where exploitable PHP files (e.g., pearcmd.php) are accessible, this LFI can be chained to achieve full Remote Code Execution on the server. Active exploitation in the wild has been confirmed within hours of public disclosure, with working PoC code publicly available.
CVE ADDED: 2026-09-22
3 DAYS BETWEEN CVE AND KEV
3 DAYS SINCE KEV
View Details →
Internet Exposure Likelihood: VERY_HIGH
CVSS: 9.8
CVE-2026-85102 is a critical (CVSS 9.8) improper certificate validation vulnerability in Check Point Quantum Security Gateway affecting VPN negotiation. An unauthenticated remote attacker can exploit this flaw over the network without any user interaction to achieve arbitrary code execution directly on the gateway appliance. As a perimeter security device with VPN services that must be internet-exposed to function, virtually all affected deployments are directly reachable from the internet.
CVE ADDED: 2026-09-09
13 DAYS BETWEEN CVE AND KEV
6 DAYS SINCE KEV
View Details →
Internet Exposure Likelihood: MEDIUM
CVSS: 9.8
CVE-2026-93616 is a critical (CVSS 9.8) directory traversal and arbitrary file upload vulnerability in Check Point Quantum Security Management Server that allows an unauthenticated remote attacker to upload and execute arbitrary scripts — including malicious Java classes — on the management server with no authentication or user interaction required. Active exploitation in the wild has been confirmed by Check Point. Successful exploitation grants full control over the management server, which in turn provides visibility into and control over the entire security infrastructure it manages.
CVE ADDED: 2026-09-22
0 DAY BETWEEN CVE AND KEV
6 DAYS SINCE KEV
View Details →
Internet Exposure Likelihood: HIGH
CVSS: 10.0
CVE-2026-93952 is a CVSS 10.0 critical authentication bypass vulnerability in Arista Networks VeloCloud Orchestrator (VCO) On-Prem arising from improper input validation (CWE-20). A remote, unauthenticated attacker who can reach the VCO web interface can access privileged internal functionality and fully compromise the orchestrator host — impacting confidentiality, integrity, and availability. Active exploitation in the wild has been reported, with CISA SSVC rating the vulnerability as automatable with total technical impact.
CVE ADDED: 2026-09-22
0 DAY BETWEEN CVE AND KEV
6 DAYS SINCE KEV
View Details →
Internet Exposure Likelihood: HIGH
CVSS: 9.8
CVE-2026-94127 is a critical heap-based buffer overflow (CWE-122) in F5 BIG-IP's Access Policy Manager (APM) module triggered when both an APM access policy and an OAuth profile are configured on a virtual server. An unauthenticated remote attacker can send specially crafted network traffic to achieve arbitrary code execution on the appliance with no authentication or user interaction required. Active exploitation in the wild has been confirmed, making this an immediate critical priority for any organisation running BIG-IP APM with OAuth.
CVE ADDED: 2026-09-22
0 DAY BETWEEN CVE AND KEV
6 DAYS SINCE KEV
View Details →
Internet Exposure Likelihood: MEDIUM
CVSS: 10.0
CVE-2026-76460 is a critical (CVSS 10.0) authentication bypass vulnerability in Cisco Identity Services Engine (ISE) affecting a REST API endpoint, allowing unauthenticated remote attackers to gain full administrative access to the device without any credentials or user interaction. The flaw stems from insufficient authentication controls (CWE-648) on an API endpoint and has been confirmed actively exploited in the wild by Cisco PSIRT and added to the CISA KEV catalog. Successful exploitation grants root-level access to the ISE management interface and underlying OS, enabling complete compromise of the network access control infrastructure.
CVE ADDED: 2026-09-16
0 DAY BETWEEN CVE AND KEV
12 DAYS SINCE KEV
View Details →
Internet Exposure Likelihood: VERY_HIGH
CVSS: 9.8
CVE-2026-76461 is a critical (CVSS 9.8) SQL injection vulnerability in Cisco Secure Email Gateway (SEG) AsyncOS software that allows an unauthenticated remote attacker to execute arbitrary commands with root privileges by sending a specially crafted email message. No authentication, user interaction, or prior access is required — the attack vector is the SMTP email processing pipeline itself, which is inherently internet-facing by design. Active exploitation has been confirmed by Cisco PSIRT and the vulnerability is listed in the CISA Known Exploited Vulnerabilities catalog.
CVE ADDED: 2026-09-14
0 DAY BETWEEN CVE AND KEV
14 DAYS SINCE KEV
View Details →