cbcvebase.
← Exploited This Week

Exploited This Week — Jul 20–Jul 27, 2026

6 KEV · 27 newly weaponized · 8 EPSS surges

Patch now — added to CISA KEV

CVE-2026-63030
WordPress Core Interpretation Conflict Vulnerability
CISA KEV (added 2026-07-21, due 2026-07-24) · CVSS 9.8 CRITICAL · EPSS 0.98 (100th pct)

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL…

Nuclei templateblogs_checkpoint, blogs_hackernews, blogs_rapid7, blogs_sans_isc +5
CVE-2026-60137
WordPress Core SQL Injection Vulnerability
CISA KEV (added 2026-07-21, due 2026-08-04) · CVSS 5.9 MEDIUM · EPSS 0.78 (100th pct)

WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.

Nuclei templateblogs_checkpoint, blogs_hackernews, blogs_talos, blogs_tenable +3
CVE-2026-50522
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
CISA KEV (added 2026-07-22, due 2026-07-25) · CVSS 9.8 CRITICAL · EPSS 0.57 (99th pct)

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

blogs_crowdstrike, blogs_hackernews, blogs_qualys, blogs_rapid7 +4
CVE-2026-0770
Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability
CISA KEV (added 2026-07-21, due 2026-07-24) · CVSS 9.8 CRITICAL · EPSS 0.53 (99th pct)

Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication…

ExploitDB PoCNuclei templateblogs_bleepingcomputer, blogs_greynoiseio, blogs_hackernews, blogs_wiz +2
CVE-2021-27137
DD-WRT Stack-Based Buffer Overflow Vulnerability
CISA KEV (added 2026-07-21, due 2026-07-24) · CVSS 8.1 HIGH · EPSS 0.16 (97th pct)

An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality allows an unauthenticated remote attacker to send a request that would overflow an internal fixed buffer.…

suricata ruleblogs_bleepingcomputer, blogs_hackernews, blogs_recorded_future, vuldb +1
CVE-2026-16232
Check Point SmartConsole Improper Authentication Vulnerability
CISA KEV (added 2026-07-22, due 2026-07-25) · CVSS 9.1 CRITICAL · EPSS 0.13 (96th pct)

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful…

blogs_hackernews, blogs_rapid7, vuldb, vulncheck

Newly weaponized — exploit code appeared

CVE-2026-48908
JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability
CISA KEV (added 2026-07-07, due 2026-07-10) · CVSS 9.8 CRITICAL · EPSS 0.88 (100th pct)

A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.

Nuclei templateblogs_hackernews, vuldb, vulncheck
CVE-2026-15409
SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
CISA KEV (added 2026-07-14, due 2026-07-17) · CVSS 10 CRITICAL · EPSS 0.78 (100th pct)

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.

Nuclei templateblogs_checkpoint, blogs_hackernews, blogs_rapid7, blogs_tenable +1
CVE-2026-15410
SonicWall SMA1000 Appliances Code Injection Vulnerability
CISA KEV (added 2026-07-14, due 2026-07-17) · CVSS 7.2 HIGH · EPSS 0.76 (99th pct)

Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated…

Nuclei templateblogs_checkpoint, blogs_hackernews, blogs_rapid7, blogs_tenable +1
CVE-2026-6875
ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform.
CVSS 9.5 CRITICAL · EPSS 0.24 (98th pct)

ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute code within the ServiceNow…

Nuclei templateblogs_hackernews, vuldb, vulncheck
CVE-2026-8732
libxml2 vulnerabilities
CVSS 9.8 CRITICAL · EPSS 0.19 (97th pct)

The WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via Administrator Account Creation in all versions up to, and including, 6.1.0. This is due to the wpgmp_temp_access_ajax AJAX action being registered with…

Nuclei templateblogs_bleepingcomputer, blogs_hackernews, vulncheck
CVE-2026-23696
Windmill CE and EE versions 1.276.0 through 1.603.2 contain an SQL injection vulnerability in the folder ownership…
CVSS 9.9 CRITICAL · EPSS 0.16 (97th pct)

Windmill CE and EE versions 1.276.0 through 1.603.2 contain an SQL injection vulnerability in the folder ownership management functionality that allows authenticated attackers to inject SQL through the owner parameter. An attacker can use…

Nuclei templateblogs_hackernews
CVE-2026-33497
langflow: /profile_pictures/{folder_name}/{file_name} endpoint file reading
CVSS 7.5 HIGH · EPSS 0.20 (97th pct)

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.1, in the download_profile_picture function of the /profile_pictures/{folder_name}/{file_name} endpoint, the folder_name and file_name…

Nuclei templateblogs_wiz
CVE-2026-58455
Dockwatch through 0.6.567 contains an unauthenticated OS command injection vulnerability that allows remote attackers…
CVSS 9.8 CRITICAL · EPSS 0.05 (91th pct)

Dockwatch through 0.6.567 contains an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary shell commands by exploiting a missing exit() after an authentication redirect in loader.php…

Nuclei templatevuldb, vulncheck
CVE-2026-46442
FlowiseAI: Authenticated Host RCE via POST /api/v1/node-custom-function and NodeVM Sandbox Escape
CVSS 9.9 CRITICAL · EPSS 0.03 (88th pct)

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, POST /api/v1/node-custom-function lacks route-level authorization, allowing any authenticated user or API key to submit…

Nuclei templatevuldb, vulncheck
CVE-2026-3296
wpeverest everest_forms Deserialization of Untrusted Data
CVSS 9.8 CRITICAL · EPSS 0.03 (88th pct)

The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.3 via deserialization of untrusted input from form entry metadata. This is due to the html-admin-page-entries-view.php…

Nuclei templateblogs_wiz, vulncheck

+13 more lower-signal CVEs gained public exploit code this week.

EPSS surges — exploitation risk jumped

CVE-2026-56290
Joomlack Page Builder Improper Access Control Vulnerability
CISA KEV (added 2026-07-07, due 2026-07-10) · CVSS 9.8 CRITICAL · EPSS 0.83 (100th pct) · ↑ EPSS 0.03→0.83 (+0.80) over 7d

Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and…

ExploitDB PoCNuclei templateblogs_hackernews, vuldb, vulncheck
CVE-2022-42904
Zoho ManageEngine ADManager Plus through 7151 allows authenticated admin users to execute the commands in proxy settings
CVSS 7.2 HIGH · EPSS 0.83 (100th pct) · ↑ EPSS 0.08→0.83 (+0.75) over 7d

Zoho ManageEngine ADManager Plus through 7151 allows authenticated admin users to execute the commands in proxy settings.

🔧 no public PoC or detection rule linked yet — detection gap
CVE-2026-48282
Adobe ColdFusion Path Traversal Vulnerability
CISA KEV (added 2026-07-07, due 2026-07-10) · CVSS 10 CRITICAL · EPSS 0.99 (100th pct) · ↑ EPSS 0.29→0.99 (+0.71) over 7d

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current…

Nuclei templateblogs_hackernews, vuldb, vulncheck
CVE-2026-56291
Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability
CISA KEV (added 2026-07-10, due 2026-07-13) · CVSS 9.8 CRITICAL · EPSS 0.76 (99th pct) · ↑ EPSS 0.09→0.76 (+0.67) over 7d

Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and…

Nuclei templateblogs_hackernews, vuldb, vulncheck
CVE-2023-39475
Inductive Automation Ignition ParameterVersionJavaSerializationCodec Deserialization of Untrusted Data Remote Code…
CVSS 9.8 CRITICAL · EPSS 0.62 (99th pct) · ↑ EPSS 0.03→0.62 (+0.59) over 7d

Inductive Automation Ignition ParameterVersionJavaSerializationCodec Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of…

🔧 no public PoC or detection rule linked yet — detection gap
CVE-2023-51448
cacti - Cacti provides an operational monitoring and fault management framework. Version...
CVSS 8.8 HIGH · EPSS 0.67 (99th pct) · ↑ EPSS 0.09→0.67 (+0.58) over 7d

Cacti provides an operational monitoring and fault management framework. Version 1.2.25 has a Blind SQL Injection (SQLi) vulnerability within the SNMP Notification Receivers feature in the file ‘managers.php’. An authenticated attacker…

🔧 no public PoC or detection rule linked yet — detection gap
CVE-2023-27293
Improper neutralization of input during web page generation allows an unauthenticated attacker to submit malicious…
CVSS 6.1 MEDIUM · EPSS 0.57 (99th pct) · ↑ EPSS 0.01→0.57 (+0.56) over 7d

Improper neutralization of input during web page generation allows an unauthenticated attacker to submit malicious Javascript as the answer to a questionnaire which would then be executed when an authenticated user reviews the candidate's…

🔧 no public PoC or detection rule linked yet — detection gap
CVE-2026-34908
Ubiquiti UniFi OS Improper Access Control Vulnerability
CISA KEV (added 2026-06-23, due 2026-06-26) · CVSS 10 CRITICAL · EPSS 0.58 (99th pct) · ↑ EPSS 0.02→0.58 (+0.56) over 7d

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.

blogs_bleepingcomputer, blogs_checkpoint, blogs_hackernews, vuldb +1

Get this every Monday

Free weekly digest for blue teams — what got weaponized, with detection coverage.