PatchNow

Content last updated: Less than a minute ago
10
Critical Vulnerabilities
1
Days Since Newest Entry

☕ Support This Service

+

These automated vulnerability intelligence briefings are provided free of charge to help security teams stay ahead of critical threats. The service monitors CISA KEV additions, performs AI-powered risk analysis, and generates actionable alerts 24/7.

Monthly Running Costs: ~£14 Claude AI (Risk Analysis): £7 • Kagi Search (Threat Intel): £7
🎁 Buy me a coffee

🧠 Vulnerability Classification Logic

+

🔴 HIGH RISK vulnerabilities are those that meet all of the following criteria:

  • MITRE ATT&CK T1190 Classification: The vulnerability enables "Exploit Public-Facing Application" attacks, meaning it can be directly exploited over the internet without user interaction
  • Network Attack Vector: CVSS analysis confirms the vulnerability has a NETWORK attack vector (not LOCAL, ADJACENT, or PHYSICAL)
  • Internet-Facing Deployment Analysis: Claude AI assesses that the vulnerable software is commonly deployed as an internet-facing service with HIGH or VERY_HIGH likelihood
  • Added to CISA KEV quickly: The CVE was issued less than 30 days prior to it being added to the KEV list. Otherwise you would have already patched it, right?
  • Added to KEV recently: The CVE was added to the KEV list in the last 14 days. Because you've patched it by the time it has been in active exploitation for 14 days, haven't you?

Each vulnerability undergoes deployment pattern analysis where Claude AI evaluates the typical deployment scenarios, and internet-facing likelihood.

CVE-2026-76461 - Cisco Secure Email Gateway - AsyncOS 16.x, Cisco Secure Email Gateway - AsyncOS 15.5.x, Cisco Secure Email Gateway - AsyncOS 15.0.x (+2 more)

Internet Exposure Likelihood: VERY_HIGH CVSS: 9.8
CVE-2026-76461 is a critical (CVSS 9.8) SQL injection vulnerability in Cisco Secure Email Gateway (SEG) AsyncOS software that allows an unauthenticated remote attacker to execute arbitrary commands with root privileges by sending a specially crafted email message. No authentication, user interaction, or prior access is required — the attack vector is the SMTP email processing pipeline itself, which is inherently internet-facing by design. Active exploitation has been confirmed by Cisco PSIRT and the vulnerability is listed in the CISA Known Exploited Vulnerabilities catalog.
CVE ADDED: 2026-09-14 0 DAY BETWEEN CVE AND KEV 1 DAY SINCE KEV
View Details →

CVE-2026-42018 - JFrog Artifactory <, JFrog Artifactory 7.117.0 –, JFrog Artifactory 7.125.0 – (+2 more)

Internet Exposure Likelihood: HIGH CVSS: 7.5
CVE-2026-42018 is an improper authentication vulnerability in JFrog Artifactory that allows an unauthenticated remote attacker to obtain an internal anonymous-user token even when anonymous access is disabled, exposing sensitive resources. It is actively exploited in the wild (CISA KEV listed), commonly chained with CVE-2026-42016 and CVE-2026-82329 to achieve full administrative control of the Artifactory server.
CVE ADDED: 2026-08-12 30 DAYS BETWEEN CVE AND KEV 4 DAYS SINCE KEV
View Details →

CVE-2026-85706 - GitLab CE/EE 18.7 before, GitLab CE/EE 19.2 before, GitLab CE/EE 19.3 before

Internet Exposure Likelihood: HIGH CVSS: 10.0
CVE-2026-85706 is a maximum-severity (CVSS 10.0) path traversal vulnerability in GitLab CE/EE's repository commits API that allows unauthenticated remote attackers to read arbitrary files from the GitLab server filesystem. Due to improper path confinement and missing authentication enforcement, a single unauthenticated HTTP request can exfiltrate secrets, credentials, and source code from the server. It is actively exploited in the wild and listed in the CISA KEV catalog.
CVE ADDED: 2026-09-12 0 DAY BETWEEN CVE AND KEV 4 DAYS SINCE KEV
View Details →

CVE-2026-67277 - MikroTik RouterOS 6.x, MikroTik RouterOS 7.0.0–7.23.x, MikroTik RouterOS 7.24–7.24.1

Internet Exposure Likelihood: HIGH CVSS: 8.8
CVE-2026-67277 is an unauthenticated pre-authentication flaw in MikroTik RouterOS's btest (bandwidth test) service (CWE-306, Missing Authentication) that allows a remote attacker to disclose kernel memory and trigger a denial-of-service kernel restart. It is remotely exploitable over the network without authentication or user interaction and is actively exploited in the wild (CISA KEV listed).
CVE ADDED: 2026-09-05 5 DAYS BETWEEN CVE AND KEV 5 DAYS SINCE KEV
View Details →

CVE-2026-86060 - MikroTik RouterOS 7.24, MikroTik RouterOS 7.0.0, MikroTik RouterOS 6.0.0

Internet Exposure Likelihood: HIGH CVSS: 9.2
CVE-2026-86060 is a critical (CVSS 9.2) argument injection vulnerability in the SSH login path of MikroTik RouterOS. An unauthenticated attacker can supply a crafted username beginning with a prohibited character to manipulate the RouterOS trusted policy mask, achieving privilege escalation and full device compromise. It is actively exploited in the wild and listed in CISA KEV.
CVE ADDED: 2026-09-05 5 DAYS BETWEEN CVE AND KEV 5 DAYS SINCE KEV
View Details →

CVE-2026-19490 - NetScaler Gateway, NetScaler ADC

Internet Exposure Likelihood: VERY_HIGH CVSS: 9.3
CVE-2026-19490 is a critical (CVSS 9.3) authentication bypass (CWE-288) in NetScaler ADC and NetScaler Gateway that allows unauthenticated attackers to forge sessions via the SAML HTTP-Redirect binding handler (/cgi/samlauth). It requires no privileges or user interaction, is actively exploited in the wild, and is listed in CISA KEV, making it a textbook T1190 initial-access vulnerability against internet-facing edge appliances.
CVE ADDED: 2026-08-19 21 DAYS BETWEEN CVE AND KEV 6 DAYS SINCE KEV
View Details →

CVE-2026-75650 - Magento Open Source, Adobe Commerce, Adobe Commerce B2B

Internet Exposure Likelihood: VERY_HIGH CVSS: 10.0
CVE-2026-75650 ('StyleSmuggler') is a CVSS 10.0 server-side template injection (CWE-1336) vulnerability in Adobe Commerce and Magento Open Source that enables unauthenticated remote code execution on the underlying server. It is actively exploited in the wild, listed in CISA KEV, and requires no user interaction or authentication. E-commerce platforms are almost universally internet-facing, making this a critical direct-exploitation risk.
CVE ADDED: 2026-09-07 1 DAY BETWEEN CVE AND KEV 7 DAYS SINCE KEV
View Details →

CVE-2026-86218 - N-able N-central

Internet Exposure Likelihood: HIGH CVSS: 10.0
CVE-2026-86218 is a critical (CVSS 10.0) pre-authentication remote code execution vulnerability in N-able N-central, an RMM platform widely used by MSPs. Unauthenticated remote attackers can achieve full code execution on the server over the network with no user interaction, and the flaw is confirmed to be actively exploited in the wild (CISA KEV listed). This is a textbook T1190 initial access vulnerability granting complete server takeover.
CVE ADDED: 2026-09-06 2 DAYS BETWEEN CVE AND KEV 7 DAYS SINCE KEV
View Details →

CVE-2026-82329 - JFrog Artifactory, JFrog Artifactory 7.117.x, JFrog Artifactory 7.125.x (+3 more)

Internet Exposure Likelihood: HIGH CVSS: 9.8
CVE-2026-82329 is a critical authentication bypass vulnerability (CWE-287) in JFrog Artifactory that allows unauthenticated remote attackers to obtain administrative privileges under default configuration. With a CVSS score of 9.8, no privileges or user interaction required, and confirmed active exploitation by CISA KEV listing, this represents an immediately weaponisable internet-facing threat. Successful exploitation gives the attacker full administrative control over the Artifactory server, its artifact repositories, and any integrated build/CI-CD pipeline credentials.
CVE ADDED: 2026-08-28 5 DAYS BETWEEN CVE AND KEV 13 DAYS SINCE KEV
View Details →

CVE-2026-83548 - SonicWall SMA1000, SonicWall SMA1000 platform-hotfix 12.4.3-03453 and older, SonicWall SMA1000 platform-hotfix 12.5.0-02835 and older

Internet Exposure Likelihood: VERY_HIGH CVSS: 10.0
CVE-2026-83548 is a pre-authentication SSRF vulnerability in the SonicWall SMA1000 Work Place interface, exploitable remotely without authentication or user interaction, with a maximum CVSS score of 10.0. It is actively exploited in the wild and listed in CISA KEV, allowing unauthenticated attackers to reach internal sensitive functionality via an unintended alternate access path, effectively compromising the appliance itself.
CVE ADDED: 2026-09-01 1 DAY BETWEEN CVE AND KEV 13 DAYS SINCE KEV
View Details →