Internet Exposure Likelihood: VERY_HIGH
CVSS: 9.8
CVE-2026-85102 is a critical (CVSS 9.8) improper certificate validation vulnerability in Check Point Quantum Security Gateway affecting VPN negotiation. An unauthenticated remote attacker can exploit this flaw over the network without any user interaction to achieve arbitrary code execution directly on the gateway appliance. As a perimeter security device with VPN services that must be internet-exposed to function, virtually all affected deployments are directly reachable from the internet.
CVE ADDED: 2026-09-09
13 DAYS BETWEEN CVE AND KEV
1 DAY SINCE KEV
View Details →
Internet Exposure Likelihood: MEDIUM
CVSS: 9.8
CVE-2026-93616 is a critical (CVSS 9.8) directory traversal and arbitrary file upload vulnerability in Check Point Quantum Security Management Server that allows an unauthenticated remote attacker to upload and execute arbitrary scripts — including malicious Java classes — on the management server with no authentication or user interaction required. Active exploitation in the wild has been confirmed by Check Point. Successful exploitation grants full control over the management server, which in turn provides visibility into and control over the entire security infrastructure it manages.
CVE ADDED: 2026-09-22
0 DAY BETWEEN CVE AND KEV
1 DAY SINCE KEV
View Details →
Internet Exposure Likelihood: HIGH
CVSS: 10.0
CVE-2026-93952 is a CVSS 10.0 critical authentication bypass vulnerability in Arista Networks VeloCloud Orchestrator (VCO) On-Prem arising from improper input validation (CWE-20). A remote, unauthenticated attacker who can reach the VCO web interface can access privileged internal functionality and fully compromise the orchestrator host — impacting confidentiality, integrity, and availability. Active exploitation in the wild has been reported, with CISA SSVC rating the vulnerability as automatable with total technical impact.
CVE ADDED: 2026-09-22
0 DAY BETWEEN CVE AND KEV
1 DAY SINCE KEV
View Details →
Internet Exposure Likelihood: HIGH
CVSS: 9.8
CVE-2026-94127 is a critical heap-based buffer overflow (CWE-122) in F5 BIG-IP's Access Policy Manager (APM) module triggered when both an APM access policy and an OAuth profile are configured on a virtual server. An unauthenticated remote attacker can send specially crafted network traffic to achieve arbitrary code execution on the appliance with no authentication or user interaction required. Active exploitation in the wild has been confirmed, making this an immediate critical priority for any organisation running BIG-IP APM with OAuth.
CVE ADDED: 2026-09-22
0 DAY BETWEEN CVE AND KEV
1 DAY SINCE KEV
View Details →
Internet Exposure Likelihood: MEDIUM
CVSS: 10.0
CVE-2026-76460 is a critical (CVSS 10.0) authentication bypass vulnerability in Cisco Identity Services Engine (ISE) affecting a REST API endpoint, allowing unauthenticated remote attackers to gain full administrative access to the device without any credentials or user interaction. The flaw stems from insufficient authentication controls (CWE-648) on an API endpoint and has been confirmed actively exploited in the wild by Cisco PSIRT and added to the CISA KEV catalog. Successful exploitation grants root-level access to the ISE management interface and underlying OS, enabling complete compromise of the network access control infrastructure.
CVE ADDED: 2026-09-16
0 DAY BETWEEN CVE AND KEV
7 DAYS SINCE KEV
View Details →
Internet Exposure Likelihood: VERY_HIGH
CVSS: 9.8
CVE-2026-76461 is a critical (CVSS 9.8) SQL injection vulnerability in Cisco Secure Email Gateway (SEG) AsyncOS software that allows an unauthenticated remote attacker to execute arbitrary commands with root privileges by sending a specially crafted email message. No authentication, user interaction, or prior access is required — the attack vector is the SMTP email processing pipeline itself, which is inherently internet-facing by design. Active exploitation has been confirmed by Cisco PSIRT and the vulnerability is listed in the CISA Known Exploited Vulnerabilities catalog.
CVE ADDED: 2026-09-14
0 DAY BETWEEN CVE AND KEV
9 DAYS SINCE KEV
View Details →
Internet Exposure Likelihood: HIGH
CVSS: 7.5
CVE-2026-42018 is an improper authentication vulnerability in JFrog Artifactory that allows an unauthenticated remote attacker to obtain an internal anonymous-user token even when anonymous access is disabled, exposing sensitive resources. It is actively exploited in the wild (CISA KEV listed), commonly chained with CVE-2026-42016 and CVE-2026-82329 to achieve full administrative control of the Artifactory server.
CVE ADDED: 2026-08-12
30 DAYS BETWEEN CVE AND KEV
12 DAYS SINCE KEV
View Details →
Internet Exposure Likelihood: HIGH
CVSS: 10.0
CVE-2026-85706 is a maximum-severity (CVSS 10.0) path traversal vulnerability in GitLab CE/EE's repository commits API that allows unauthenticated remote attackers to read arbitrary files from the GitLab server filesystem. Due to improper path confinement and missing authentication enforcement, a single unauthenticated HTTP request can exfiltrate secrets, credentials, and source code from the server. It is actively exploited in the wild and listed in the CISA KEV catalog.
CVE ADDED: 2026-09-12
0 DAY BETWEEN CVE AND KEV
12 DAYS SINCE KEV
View Details →
Internet Exposure Likelihood: HIGH
CVSS: 8.8
CVE-2026-67277 is an unauthenticated pre-authentication flaw in MikroTik RouterOS's btest (bandwidth test) service (CWE-306, Missing Authentication) that allows a remote attacker to disclose kernel memory and trigger a denial-of-service kernel restart. It is remotely exploitable over the network without authentication or user interaction and is actively exploited in the wild (CISA KEV listed).
CVE ADDED: 2026-09-05
5 DAYS BETWEEN CVE AND KEV
13 DAYS SINCE KEV
View Details →
Internet Exposure Likelihood: HIGH
CVSS: 9.2
CVE-2026-86060 is a critical (CVSS 9.2) argument injection vulnerability in the SSH login path of MikroTik RouterOS. An unauthenticated attacker can supply a crafted username beginning with a prohibited character to manipulate the RouterOS trusted policy mask, achieving privilege escalation and full device compromise. It is actively exploited in the wild and listed in CISA KEV.
CVE ADDED: 2026-09-05
5 DAYS BETWEEN CVE AND KEV
13 DAYS SINCE KEV
View Details →
Internet Exposure Likelihood: VERY_HIGH
CVSS: 9.3
CVE-2026-19490 is a critical (CVSS 9.3) authentication bypass (CWE-288) in NetScaler ADC and NetScaler Gateway that allows unauthenticated attackers to forge sessions via the SAML HTTP-Redirect binding handler (/cgi/samlauth). It requires no privileges or user interaction, is actively exploited in the wild, and is listed in CISA KEV, making it a textbook T1190 initial-access vulnerability against internet-facing edge appliances.
CVE ADDED: 2026-08-19
21 DAYS BETWEEN CVE AND KEV
14 DAYS SINCE KEV
View Details →