cbcvebase.
← Exploited This Week

Exploited This Week — May 25–Jun 01, 2026

5 KEV · 43 newly weaponized · 8 EPSS surges

Patch now — added to CISA KEV

CVE-2026-0257
Palo Alto Networks PAN-OS Authentication Bypass Vulnerability
CISA KEV (added 2026-05-29, due 2026-06-01) · CVSS 7.8 HIGH · EPSS 0.42 (97th pct)

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW…

blogs_bleepingcomputer, blogs_hackernews, blogs_rapid7, vuldb +1
CVE-2026-48027
Nx Console Embedded Malicious Code Vulnerability
CISA KEV (added 2026-05-27, due 2026-06-10) · 🦠 ransomware · CVSS 9.3 CRITICAL · EPSS 0.27 (96th pct)

Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was published at 12:30 PM UTC and removed soon after at 12:48 PM UTC, leaving it available for ~18 minutes in Visual Studio…

vuldb, vulncheck
CVE-2026-45321
TanStack Unspecified Vulnerability
CISA KEV (added 2026-05-27, due 2026-06-10) · 🦠 ransomware · CVSS 9.6 CRITICAL · EPSS 0.17 (95th pct)

On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher…

blogs_hackernews, blogs_sans_isc, blogs_tenable, vulncheck
CVE-2026-8398
Daemon Tools Lite Embedded Malicious Code Vulnerability
CISA KEV (added 2026-05-27, due 2026-05-30) · CVSS 9.3 CRITICAL · EPSS 0.15 (95th pct)

A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distributed from the legitimate website daemon-tools.cc between approximately April 8, 2026, and…

blogs_hackernews, vuldb, vulncheck
CVE-2026-48172
LiteSpeed cPanel Plugin Privilege Escalation Vulnerability
CISA KEV (added 2026-05-26, due 2026-05-29) · CVSS 10 CRITICAL · EPSS 0.08 (92th pct)

LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of grep -rE "cpanel_jsonapi_func=redisAble" /var/cpanel/logs…

blogs_bleepingcomputer, blogs_hackernews, vuldb, vulncheck

Newly weaponized — exploit code appeared

CVE-2026-32985
Xerte Online Toolkits versions 3.14 and earlier contain an unauthenticated arbitrary file upload vulnerability in the…
CVSS 9.3 CRITICAL · EPSS 0.70 (99th pct)

Xerte Online Toolkits versions 3.14 and earlier contain an unauthenticated arbitrary file upload vulnerability in the template import functionality that allows remote attackers to execute arbitrary code by uploading a crafted ZIP archive…

🔧 no public PoC or detection rule linked yet — detection gap
CVE-2026-32202
Microsoft Windows Protection Mechanism Failure Vulnerability
CISA KEV (added 2026-04-28, due 2026-05-12) · CVSS 4.3 MEDIUM · EPSS 0.57 (98th pct)

Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.

ExploitDB PoCblogs_bleepingcomputer, blogs_hackernews, blogs_qualys, blogs_rapid7 +4
CVE-2024-36420
Flowise Path Injection at /api/v1/openai-assistants-file
CVSS 7.5 HIGH · EPSS 0.57 (98th pct)

Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, the /api/v1/openai-assistants-file endpoint in index.ts is vulnerable to arbitrary file read due to lack of sanitization…

Nuclei template
CVE-2015-10144
The Responsive Thumbnail Slider plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type…
CVSS 8.8 HIGH · EPSS 0.71 (99th pct)

The Responsive Thumbnail Slider plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type sanitization in the via the image uploader in versions up to 1.0.1. This makes it possible for authenticated attackers…

🔧 no public PoC or detection rule linked yet — detection gap
CVE-2023-28459
pretalx vulnerable to path traversal in HTML export
CVSS 6.5 MEDIUM · EPSS 0.63 (98th pct)

pretalx 2.3.1 before 2.3.2 allows path traversal in HTML export (a non-default feature). Users were able to upload crafted HTML documents that trigger the reading of arbitrary files.

🔧 no public PoC or detection rule linked yet — detection gap
CVE-2020-36939
Cassandra Web 0.5.0 contains a directory traversal vulnerability that allows unauthenticated attackers to read…
CVSS 8.7 HIGH · EPSS 0.59 (98th pct)

Cassandra Web 0.5.0 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating path traversal parameters. Attackers can exploit the disabled Rack::Protection module to read…

🔧 no public PoC or detection rule linked yet — detection gap
CVE-2026-8679
The AudioIgniter plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and…
CVSS 7.5 HIGH · EPSS 0.28 (97th pct)

The AudioIgniter plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 2.0.2. This is due to the handle_playlist_endpoint() function (hooked to template_redirect) accepting a…

Nuclei templatevuldb
CVE-2024-9362
An unauthenticated directory traversal vulnerability exists in Polyaxon, affecting the latest version
CVSS 7.5 HIGH · EPSS 0.25 (96th pct)

An unauthenticated directory traversal vulnerability exists in Polyaxon, affecting the latest version. This vulnerability allows an attacker to retrieve directory information and file contents from the server without proper authorization…

Nuclei template
CVE-2019-19699
There is Authenticated remote code execution in Centreon Infrastructure Monitoring Software through 19.10 via Pollers…
CVSS 7.2 HIGH · EPSS 0.39 (97th pct)

There is Authenticated remote code execution in Centreon Infrastructure Monitoring Software through 19.10 via Pollers misconfiguration, leading to system compromise via apache crontab misconfiguration, This allows the apache user to…

🔧 no public PoC or detection rule linked yet — detection gap
CVE-2023-7327
Ozeki SMS Gateway versions up to and including 10.3.208 contain a path traversal vulnerability.
CVSS 8.7 HIGH · EPSS 0.18 (95th pct)

Ozeki SMS Gateway versions up to and including 10.3.208 contain a path traversal vulnerability. Successful exploitation allows an unauthenticated attacker to use URL-encoded traversal sequences to read arbitrary files from the underlying…

Nuclei template

+33 more lower-signal CVEs gained public exploit code this week.

EPSS surges — exploitation risk jumped

CVE-2018-16855
pdns-recursor - An issue has been found in PowerDNS Recursor before version 4.1.8 where a remote...
CVSS 7.5 HIGH · EPSS 0.71 (99th pct) · ↑ EPSS 0.20→0.71 (+0.51) over 7d

An issue has been found in PowerDNS Recursor before version 4.1.8 where a remote attacker sending a DNS query can trigger an out-of-bounds memory read while computing the hash of the query for a packet cache lookup, possibly leading to a…

🔧 no public PoC or detection rule linked yet — detection gap
CVE-2026-4257
The Contact Form by Supsystic plugin for WordPress is vulnerable to Server-Side Template Injection (SSTI) leading to…
CVSS 9.8 CRITICAL · EPSS 0.87 (99th pct) · ↑ EPSS 0.44→0.87 (+0.43) over 7d

The Contact Form by Supsystic plugin for WordPress is vulnerable to Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in all versions up to, and including, 1.7.36. This is due to the plugin using the Twig…

ExploitDB PoCNuclei templateblogs_rapid7, blogs_wiz
CVE-2026-43500
kernel: "Dirty Frag" RxRPC variant is a new universal Local Privilege Escalation (LPE) vulnerability in the Linux kernel
CVSS 7.8 HIGH · EPSS 0.40 (97th pct) · ↑ EPSS 0.01→0.40 (+0.39) over 7d

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present The DATA-packet handler in rxrpc_input_call_event() and the RESPONSE handler in…

ExploitDB PoCMetasploit moduleblogs_bleepingcomputer, blogs_hackernews, blogs_huntress, blogs_qualys +5
CVE-2026-43284
kernel: "Dirty Frag" is a new universal Local Privilege Escalation (LPE) vulnerability in the Linux kernel
CVSS 8.8 HIGH · EPSS 0.38 (97th pct) · ↑ EPSS 0.01→0.38 (+0.37) over 7d

In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP marks such skbs with SKBFL_SHARED_FRAG after…

ExploitDB PoCMetasploit moduleblogs_bleepingcomputer, blogs_hackernews, blogs_huntress, blogs_qualys +5
CVE-2014-125123
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSS 10 CRITICAL · EPSS 0.60 (98th pct) · ↑ EPSS 0.34→0.60 (+0.26) over 7d

An unauthenticated SQL injection vulnerability exists in the Kloxo web hosting control panel (developed by LXCenter) prior to version 6.1.12. The flaw resides in the login-name parameter passed to lbin/webcommand.php, which fails to…

Metasploit modulevulncheck
CVE-2012-2576
SolarWinds Storage Manager 5.1.0 - Remote SYSTEM SQL Injection
CVSS 9.8 CRITICAL · EPSS 0.67 (99th pct) · ↑ EPSS 0.41→0.67 (+0.26) over 7d

SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Profiler before 5.1.2, and SolarWinds Backup Profiler before 5.1.2 allows remote attackers to execute arbitrary SQL…

ExploitDB PoC
CVE-2021-27856
FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 "cmuser" Backdoor Account
CVSS 9.8 CRITICAL · EPSS 0.71 (99th pct) · ↑ EPSS 0.46→0.71 (+0.25) over 7d

FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 includes an account named "cmuser" that has administrative privileges and no password. Older versions of FatPipe software may also be vulnerable. The…

Nuclei templatevulncheck
CVE-2025-14611
Gladinet CentreStack and Triofox Hard Coded Cryptographic Vulnerability
CISA KEV (added 2025-12-15, due 2026-01-05) · CVSS 7.1 HIGH · EPSS 0.80 (99th pct) · ↑ EPSS 0.55→0.80 (+0.25) over 7d

Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of the AES cryptoscheme. This degrades security for public exposed endpoints that may make use of it and may offer…

Nuclei templatesuricata ruleblogs_huntress, blogs_recorded_future, blogs_wiz, vulncheck

Get this every Monday

Free weekly digest for blue teams — what got weaponized, with detection coverage.