cbcvebase.
← Exploited This Week

Exploited This Week — Jun 29–Jul 06, 2026

2 KEV · 7 newly weaponized · 2 EPSS surges

Patch now — added to CISA KEV

CVE-2026-45659
Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability
CISA KEV (added 2026-07-01, due 2026-07-04) · CVSS 8.8 HIGH · EPSS 0.03 (87th pct)

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

blogs_hackernews, vuldb, vulncheck
CVE-2026-48558
SimpleHelp Authentication Bypass Vulnerability
CISA KEV (added 2026-06-29, due 2026-07-02) · CVSS 10 CRITICAL · EPSS 0.01 (63th pct)

SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted…

blogs_bleepingcomputer, blogs_hackernews, blogs_talos, vuldb +1

Newly weaponized — exploit code appeared

CVE-2026-8037
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated…
CVSS 9.6 CRITICAL · EPSS 0.30 (98th pct)

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command…

Nuclei templateblogs_hackernews, vuldb, vulncheck
CVE-2026-56782
Gorse before 0.5.10 contains an authentication bypass vulnerability in the /api/dump and /api/restore endpoints that…
CVSS 9.8 CRITICAL · EPSS 0.03 (86th pct)

Gorse before 0.5.10 contains an authentication bypass vulnerability in the /api/dump and /api/restore endpoints that allows unauthenticated attackers to access protected functionality when admin_api_key is empty, which is the default…

Nuclei templatevuldb
CVE-2026-33691
modsecurity-crs - The OWASP core rule set (CRS) is a set of generic attack detection rules for use...
CVSS 7.5 HIGH · EPSS 0.02 (80th pct)

The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 3.3.9 and 4.25.0, a bypass was identified in OWASP CRS that allows uploading files with…

Nuclei templateblogs_hackernews, blogs_wiz
CVE-2026-30958
OneUptime is a solution for monitoring and managing online services.
CVSS 8.6 HIGH · EPSS 0.01 (62th pct)

OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, an unauthenticated path traversal in the /workflow/docs/:componentName endpoint allows reading arbitrary files from the server filesystem. The…

Nuclei template
CVE-2026-10823
The YMC Filter WordPress plugin before 3.11.3 does not properly authorize access to one of its REST API endpoints and…
CVSS 7.5 HIGH · EPSS 0.01 (56th pct)

The YMC Filter WordPress plugin before 3.11.3 does not properly authorize access to one of its REST API endpoints and does not validate a user-supplied query parameter, allowing unauthenticated attackers to retrieve the titles and content…

Nuclei template
CVE-2026-41264
Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability
CVSS 9.8 CRITICAL · EPSS 0.01 (59th pct)

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the specific flaw exists within the run method of the CSV_Agents class. The issue results from the lack of proper sandboxing when…

vuldb
CVE-2026-1890
Vulnerability
CVSS 5.3 MEDIUM · EPSS 0.01 (46th pct)

The LeadConnector WordPress plugin before 3.0.22 does not have authorization in a REST route, allowing unauthenticated users to call it and overwrite existing data

blogs_wiz, vulncheck

EPSS surges — exploitation risk jumped

CVE-2025-29635
D-Link DIR-823X Command Injection Vulnerability
CISA KEV (added 2026-04-24, due 2026-05-08) · CVSS 7.2 HIGH · EPSS 0.87 (100th pct) · ↑ EPSS 0.35→0.87 (+0.52) over 7d

A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function…

Nuclei templateblogs_bleepingcomputer, blogs_checkpoint, blogs_hackernews, vulncheck
CVE-2022-35977
Redis vulnerabilities
CVSS 5.5 MEDIUM · EPSS 0.33 (98th pct) · ↑ EPSS 0.12→0.33 (+0.21) over 7d

Redis is an in-memory database that persists on disk. Authenticated users issuing specially crafted SETRANGE and SORT(_RO) commands can trigger an integer overflow, resulting with Redis attempting to allocate impossible amounts of memory…

🔧 no public PoC or detection rule linked yet — detection gap

Get this every Monday

Free weekly digest for blue teams — what got weaponized, with detection coverage.