cbcvebase.
← Exploited This Week

Exploited This Week — Jun 22–Jun 29, 2026

6 KEV · 14 newly weaponized · 8 EPSS surges

Patch now — added to CISA KEV

CVE-2026-34910
Ubiquiti UniFi OS Improper Input Validation Vulnerability
CISA KEV (added 2026-06-23, due 2026-06-26) · CVSS 10 CRITICAL · EPSS 0.79 (100th pct)

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.

Nuclei templateblogs_bleepingcomputer, blogs_hackernews, vuldb, vulncheck
CVE-2026-20230
Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability
CISA KEV (added 2026-06-25, due 2026-06-28) · CVSS 8.6 HIGH · EPSS 0.42 (99th pct)

A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request…

blogs_bleepingcomputer, blogs_checkpoint, blogs_hackernews, vuldb +1
CVE-2026-34908
Ubiquiti UniFi OS Improper Access Control Vulnerability
CISA KEV (added 2026-06-23, due 2026-06-26) · CVSS 10 CRITICAL · EPSS 0.02 (82th pct)

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.

blogs_bleepingcomputer, blogs_hackernews, vuldb, vulncheck
CVE-2026-34909
Ubiquiti UniFi OS Path Traversal Vulnerability
CISA KEV (added 2026-06-23, due 2026-06-26) · CVSS 10 CRITICAL · EPSS 0.02 (81th pct)

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account.

blogs_bleepingcomputer, blogs_hackernews, vuldb, vulncheck
CVE-2025-67038
Lantronix EDS5000 Code Injection Vulnerability
CISA KEV (added 2026-06-23, due 2026-06-26) · CVSS 9.8 CRITICAL · EPSS 0.01 (62th pct)

An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authantication fails. The username is directly concatenated with the command without any sanitization. This…

blogs_bleepingcomputer, blogs_hackernews, vuldb, vulncheck
CVE-2026-12569
PTC Windchill and FlexPLM Improper Input Validation Vulnerability
CISA KEV (added 2026-06-25, due 2026-06-28) · CVSS 9.8 CRITICAL · EPSS 0.01 (62th pct)

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. * This advisory also applies to all CPS…

blogs_bleepingcomputer, blogs_hackernews, vuldb, vulncheck

Newly weaponized — exploit code appeared

CVE-2026-22557
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in the UniFi Network…
CVSS 10 CRITICAL · EPSS 0.16 (96th pct)

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in the UniFi Network Application to access files on the underlying system that could be manipulated to access an underlying account.

Nuclei templateblogs_bleepingcomputer, blogs_checkpoint, blogs_hackernews, blogs_wiz
CVE-2025-29635
D-Link DIR-823X Command Injection Vulnerability
CISA KEV (added 2026-04-24, due 2026-05-08) · CVSS 7.2 HIGH · EPSS 0.35 (98th pct)

A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function…

blogs_bleepingcomputer, blogs_checkpoint, blogs_hackernews, vulncheck
CVE-2026-4480
Samba vulnerabilities
CVSS 9.8 CRITICAL · EPSS 0.13 (96th pct)

A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping shell meta…

Nuclei templateblogs_hackernews, blogs_wiz
CVE-2026-22778
vllm: vLLM: Information Disclosure via Incomplete Error Message Sanitization
CVSS 9.8 CRITICAL · EPSS 0.04 (88th pct)

vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid image is sent to vLLM's multimodal endpoint, PIL throws an error. vLLM returns this error to the client, leaking a heap…

Nuclei templateblogs_wiz
CVE-2026-28496
fossbilling fossbilling Improper Neutralization of Special Elements Used in a Template Engine
CVSS 9.4 CRITICAL · EPSS 0.02 (77th pct)

FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 have a Server-Side Template Injection (SSTI) vulnerability in the template rendering system. Administrators with access to features that…

Nuclei templatevulncheck
CVE-2026-54157
LobeHub: Unauthenticated SSRF in /webapi/proxy
CVSS 9 CRITICAL · EPSS 0.02 (75th pct)

LobeHub is a work-and-lifestyle space to find, build, and collaborate with agent teammates that grow with you. Prior to 2.1.57, the /webapi/proxy endpoint on app.lobehub.com accepts a URL in the POST body and fetches it server-side…

Nuclei templateblogs_hackernews
CVE-2026-45087
Dalfox Server Mode Vulnerable to Unauthenticated Remote Code Execution via found-action
CVSS 10 CRITICAL · EPSS 0.01 (63th pct)

Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is started in REST API server mode (dalfox server), the server binds to 0.0.0.0:6664 by default and requires no API key unless…

Metasploit moduleblogs_rapid7, vuldb
CVE-2026-53787
Amasty Order Attributes for Magento 2 before version 4.0.0 contains an unauthenticated arbitrary file upload…
CVSS 9.8 CRITICAL · EPSS 0.04 (88th pct)

Amasty Order Attributes for Magento 2 before version 4.0.0 contains an unauthenticated arbitrary file upload vulnerability that allows unauthenticated attackers to write arbitrary files to the store's media directory by submitting files…

Nuclei template
CVE-2025-25205
Audiobookshelf Unauthenticated API Authentication Bypass Scanner
CVSS 8.2 HIGH · EPSS 0.04 (89th pct)

Audiobookshelf is a self-hosted audiobook and podcast server. Starting in version 2.17.0 and prior to version 2.19.1, a flaw in the authentication bypass logic allows unauthenticated requests to match certain unanchored regex patterns in…

Metasploit moduleblogs_rapid7
CVE-2026-52815
Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API
CVSS 5.5 MEDIUM · EPSS 0.02 (72th pct)

Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs has an unauthenticated information disclosure vulnerability. The GET /api/v1/orgs/:orgname/teams endpoint at internal/route/api/v1/org_team.go:8 returns all teams for…

Nuclei template

+4 more lower-signal CVEs gained public exploit code this week.

EPSS surges — exploitation risk jumped

CVE-2026-35273
Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability
CISA KEV (added 2026-06-12, due 2026-06-15) · 🦠 ransomware · CVSS 9.8 CRITICAL · EPSS 0.90 (100th pct) · ↑ EPSS 0.08→0.90 (+0.82) over 7d

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows…

Nuclei templateblogs_bleepingcomputer, blogs_checkpoint, blogs_hackernews, blogs_mandiant +3
CVE-2026-20253
Splunk Enterprise Missing Authentication for Critical Function Vulnerability
CISA KEV (added 2026-06-18, due 2026-06-21) · CVSS 9.8 CRITICAL · EPSS 0.88 (100th pct) · ↑ EPSS 0.10→0.88 (+0.78) over 7d

In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint. The vulnerability exists because the PostgreSQL…

Nuclei templateblogs_bleepingcomputer, blogs_checkpoint, blogs_hackernews, vuldb +1
CVE-2026-48907
Widget Factory Joomla Content Editor Improper Access Control Vulnerability
CISA KEV (added 2026-06-16, due 2026-06-19) · CVSS 10 CRITICAL · EPSS 0.80 (100th pct) · ↑ EPSS 0.07→0.80 (+0.74) over 7d

A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.

Nuclei templateblogs_bleepingcomputer, blogs_hackernews, vuldb, vulncheck
CVE-2026-2041
Nagios Host zabbixagent_configwizard_func Command Injection Remote Code Execution Vulnerability
CVSS 8.8 HIGH · EPSS 0.75 (99th pct) · ↑ EPSS 0.06→0.75 (+0.69) over 7d

Nagios Host zabbixagent_configwizard_func Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Nagios Host. Authentication is required to…

blogs_wiz
CVE-2026-0257
Palo Alto Networks PAN-OS Authentication Bypass Vulnerability
CISA KEV (added 2026-05-29, due 2026-06-01) · CVSS 9.1 CRITICAL · EPSS 0.87 (100th pct) · ↑ EPSS 0.19→0.87 (+0.68) over 7d

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW…

Nuclei templateblogs_bleepingcomputer, blogs_checkpoint, blogs_hackernews, blogs_rapid7 +3
CVE-2026-45498
Microsoft Defender Denial of Service Vulnerability
CISA KEV (added 2026-05-20, due 2026-06-03) · CVSS 7.5 HIGH · EPSS 0.63 (99th pct) · ↑ EPSS 0.03→0.63 (+0.61) over 7d

Microsoft Defender Denial of Service Vulnerability

blogs_bleepingcomputer, blogs_checkpoint, blogs_hackernews, blogs_rapid7 +2
CVE-2025-34291
Langflow Origin Validation Error Vulnerability
CISA KEV (added 2026-05-21, due 2026-06-04) · CVSS 8.8 HIGH · EPSS 0.79 (100th pct) · ↑ EPSS 0.25→0.79 (+0.54) over 7d

Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS configuration (allow_origins='*' with allow_credentials=True) combined with a…

Nuclei templateblogs_hackernews, vuldb, vulncheck
CVE-2026-26980
Ghost has a SQL injection in Content API
CVSS 7.5 HIGH · EPSS 0.70 (99th pct) · ↑ EPSS 0.16→0.70 (+0.54) over 7d

Ghost is a Node.js content management system. Versions 3.24.0 through 6.19.0 allow unauthenticated attackers to perform arbitrary reads from the database. This issue has been fixed in version 6.19.1.

ExploitDB PoCNuclei templateblogs_bleepingcomputer, blogs_checkpoint, blogs_hackernews, blogs_recorded_future +3

Get this every Monday

Free weekly digest for blue teams — what got weaponized, with detection coverage.