CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

Actively Exploited Vulnerabilities

Every advisory below covers a vulnerability with exploitation observed in the wild, cross-referenced against the CISA Known Exploited Vulnerabilities (KEV) catalog and refreshed every 3 hours. If your patch queue is long, start here: KEV listing means real attacks are happening now, and US federal agencies are required to remediate these under BOD 22-01.

1,911 exploited-vulnerability advisories · page 1 / 39

Gitea security advisory (AV26-845)

Serial Number: AV26-845 Date: August 25, 2026 As of August 14, 2026, Gitea is affected by vulnerabilities in the following product: Gitea Prior to 1.27.1 On August 25, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-60004 to their Known Exploited Vuln

unknownexploitedCVE-2026-60004cccs2026-08-25

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-60004 Gitea Code Injection Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses sign

highexploitedCVE-2026-60004cisa2026-08-25

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-21962 Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability This type of vulnerability is a f

highexploitedCVE-2026-21962cisa2026-08-24

Zimbra security advisory (AV26-816) – Update 1

Serial number: AV26-816 Date: August 14, 2026 Updated: August 21, 2026 As of August 13, 2026, Zimbra is affected by vulnerabilities in the following product: Collaboration - Prior to 10.1.20 The Cyber Centre encourages users and administrators to review the provided web links and

unknownexploitedCVE-2026-73570cccs2026-08-21

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-73570 Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability This type of vulnerability is a frequent attack vector for mali

highexploitedCVE-2026-73570cisa2026-08-21

CVE-2026-31431

Bulletin ID: 2026-026-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/05/06 17:30 PM PDT Description: Amazon is aware of an issue in the Linux kernel (CVE-2026-31431) that could potentially allow an authenticated local user to escalate privilege

unknownexploitedCVE-2026-31431aws2026-08-20

Dirty Frag and other issues in Amazon Linux kernels

Bulletin ID: 2026-027-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/05/07 19:45 PM PDT Description: Amazon is aware of a class of issues in the Linux kernel related to the original issue (CVE-2026-31431). The issues commonly referred to as "Di

unknownexploitedCVE-2026-31431aws2026-08-20

TrueConf security advisory (AV26-835)

Serial Number: AV26-835 Date: August 20, 2026 As of August 19, 2026, TrueConf is affected by a vulnerability in the following product: TrueConf Server 5.3.x versions prior to 5.3.9 5.4.x versions prior to 5.4.9 5.5.x versions prior to 5.5.5 On August 20, 2026, Cybersecurity and I

unknownexploitedCVE-2026-72529CVE-2026-72530cccs2026-08-20

MLflow security advisory (AV26-832)

Serial Number: AV26-832 Date: August 19, 2026 As of August 17, 2026, MLflow is affected by vulnerabilities in the following product: MLflow Prior to 3.15.0 On August 19, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-64849 to their Known Exploited Vu

unknownexploitedCVE-2026-64849cccs2026-08-19

CVE-2026-72530: A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a special

A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host sy

criticalexploitedCVSS 9CVE-2026-72530nvd2026-08-19

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-64849 MLflow Server-Side Request Forgery Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors

highexploitedCVE-2026-64849cisa2026-08-19

Apple security advisory (AV26-823) – Update 1

Serial number: AV26-823 Date: August 17, 2026 Updated: August 18, 2026 As of August 6, 2026, Apple is affected by vulnerabilities in the following products: macOS Tahoe Prior to 26.6.1 macOS Sequoia Prior to 15.7.9 macOS Sonoma Prior to 14.8.9 Open-source reporting indicates that

unknownexploitedCVE-2026-65400cccs2026-08-18

CVE-2026-64849: MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/

MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in mlflow/utils/validation.py only for the original

criticalexploitedCVSS 9.3CVE-2026-64849nvd2026-08-17

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2025-62593 Ray-Project Ray Code Injection Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and

highexploitedCVE-2025-62593cisa2026-08-17
Older →