cbcvebase.
← Exploited This Week

Exploited This Week — Jul 27–Aug 03, 2026

3 KEV · 18 newly weaponized · 8 EPSS surges

Patch now — added to CISA KEV

CVE-2025-68686
Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
CISA KEV (added 2026-07-27, due 2026-08-10) · CVSS 5.9 MEDIUM · EPSS 0.01 (67th pct)

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all…

blogs_hackernews, blogs_wiz, vuldb, vulncheck
CVE-2026-16812
Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability
CISA KEV (added 2026-07-27, due 2026-07-30) · CVSS 10 CRITICAL · EPSS 0.01 (56th pct)

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality…

blogs_hackernews, vuldb, vulncheck
CVE-2026-20316
Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability
CISA KEV (added 2026-07-29, due 2026-08-01) · CVSS 5.3 MEDIUM · EPSS 0.01 (53th pct)

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within…

blogs_hackernews, vuldb, vulncheck

Newly weaponized — exploit code appeared

CVE-2026-16232
Check Point SmartConsole Improper Authentication Vulnerability
CISA KEV (added 2026-07-22, due 2026-07-25) · CVSS 9.1 CRITICAL · EPSS 0.71 (99th pct)

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful…

blogs_checkpoint, blogs_hackernews, blogs_rapid7, vuldb +1
CVE-2025-68493
org.apache.struts: Apache Struts: Information disclosure and denial of service via missing XML validation
CVSS 8.1 HIGH · EPSS 0.37 (98th pct)

Missing XML Validation vulnerability in Apache Struts, Apache Struts. This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0. Users are recommended to upgrade to version 6.1.1, which fixes the…

suricata ruleblogs_greynoiseio, blogs_wiz, vulncheck
CVE-2026-55450
Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak
CVSS 9.3 CRITICAL · EPSS 0.12 (96th pct)

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, unauthenticated users can upload any amount of data to the server without any limitations. No need for any prior knowledge, only network access…

vuldb
CVE-2025-71334
FlowiseAI Flowise External Control of File Name or Path
CVSS 9.8 CRITICAL · EPSS 0.04 (89th pct)

Flowise before 3.0.6 (affected versions 2.2.8 and earlier) contains an arbitrary file access vulnerability due to missing validation that the chatflowId and chatId parameters are UUIDs or numbers in file handling operations. By supplying…

vuldb, vulncheck
CVE-2026-8713
The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path…
CVSS 9.1 CRITICAL · EPSS 0.03 (84th pct)

The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the maybe_delete_files function in all versions up to, and including, 3.15.3. This makes it possible for…

blogs_bleepingcomputer, blogs_hackernews, vulncheck
CVE-2026-44825
solr: Apache Solr: Remote attacker gains administrative access via hardcoded credentials in Basic Authentication setup.
CVSS 9.8 CRITICAL · EPSS 0.02 (80th pct)

Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 through 9.10.1 and 10.0.0 allows a remote attacker to gain full administrative access to the cluster via publicly known…

vuldb, vulncheck
CVE-2026-30623
litellm: LiteLLM: Remote code execution via unvalidated MCP server configuration
CVSS 9.8 CRITICAL · EPSS 0.02 (75th pct)

LiteLLM 1.18.10 contains a remote code execution vulnerability in its MCP server creation functionality. The application allows users to add MCP servers via a JSON configuration specifying arbitrary command and args values. LiteLLM…

blogs_hackernews, vuldb
CVE-2025-2505
The Age Gate plugin for WordPress is vulnerable to Local PHP File Inclusion in all versions up to, and including…
CVSS 9.8 CRITICAL · EPSS 0.01 (66th pct)

The Age Gate plugin for WordPress is vulnerable to Local PHP File Inclusion in all versions up to, and including, 3.5.3 via the 'lang' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary PHP…

vulncheck
CVE-2026-65694
Microweber CMS through 2.0.20 contains a path traversal vulnerability in the static file controller that allows…
CVSS 7.5 HIGH · EPSS 0.02 (83th pct)

Microweber CMS through 2.0.20 contains a path traversal vulnerability in the static file controller that allows unauthenticated remote attackers to read arbitrary files by supplying directory traversal sequences in the path query…

vuldb
CVE-2025-14675
Meta Box Plugin for WordPress: Authenticated (Contributor+) Arbitrary File Deletion via ajax_delete_file
CVSS 7.2 HIGH · EPSS 0.02 (82th pct)

The Meta Box plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'ajax_delete_file' function in all versions up to, and including, 5.11.1. This makes it possible for authenticated…

blogs_wiz

+7 more lower-signal CVEs gained public exploit code this week.

EPSS surges — exploitation risk jumped

CVE-2007-2815
The "hit-highlighting" functionality in webhits
CVSS 10 CRITICAL · EPSS 0.72 (99th pct) · ↑ EPSS 0.39→0.72 (+0.33) over 7d

The "hit-highlighting" functionality in webhits.dll in Microsoft Internet Information Services (IIS) Web Server 5.0 only uses Windows NT ACL configuration, which allows remote attackers to bypass NTLM and basic authentication mechanisms…

ExploitDB PoC
CVE-2025-46618
In JetBrains TeamCity before 2025
CVSS 6.1 MEDIUM · EPSS 0.59 (99th pct) · ↑ EPSS 0.29→0.59 (+0.30) over 7d

In JetBrains TeamCity before 2025.03.1 stored XSS was possible on Data Directory tab

🔧 no public PoC or detection rule linked yet — detection gap
CVE-2025-22037
Linux kernel (Azure) vulnerabilities
CVSS 5.5 MEDIUM · EPSS 0.66 (99th pct) · ↑ EPSS 0.37→0.66 (+0.29) over 7d

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix null pointer dereference in alloc_preauth_hash() The Client send malformed smb2 negotiate request. ksmbd return error response. Subsequently, the client can…

vuldb
CVE-2025-49132
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
CVSS 10 CRITICAL · EPSS 0.41 (99th pct) · ↑ EPSS 0.13→0.41 (+0.28) over 7d

Pterodactyl is a free, open-source game server management panel. Prior to version 1.11.11, using the /locales/locale.json with the locale and namespace query parameters, a malicious actor is able to execute arbitrary code without being…

ExploitDB PoCMetasploit moduleNuclei templateblogs_greynoiseio, vulncheck
CVE-2026-12569
PTC Windchill and FlexPLM Improper Input Validation Vulnerability
CISA KEV (added 2026-06-25, due 2026-06-28) · 🦠 ransomware · CVSS 9.8 CRITICAL · EPSS 0.30 (98th pct) · ↑ EPSS 0.02→0.30 (+0.28) over 7d

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. * This advisory also applies to all CPS…

blogs_bleepingcomputer, blogs_hackernews, vuldb, vulncheck
CVE-2000-0884
Microsoft IIS 4.0 and 5.0 Folder Traversal Vulnerability
CVSS 7.5 HIGH · EPSS 0.71 (99th pct) · ↑ EPSS 0.45→0.71 (+0.25) over 7d

IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary commands, via malformed URLs that contain UNICODE encoded characters, aka the "Web Server Folder Traversal" vulnerability.

ExploitDB PoCsuricata rulevulncheck
CVE-2002-0079
Microsoft IIS Vulnerabilities in Cisco Products - MS02-018
CVSS 7.5 HIGH · EPSS 0.71 (99th pct) · ↑ EPSS 0.46→0.71 (+0.25) over 7d

Buffer overflow in the chunked encoding transfer mechanism in Internet Information Server (IIS) 4.0 and 5.0 Active Server Pages allows attackers to cause a denial of service or execute arbitrary code.

ExploitDB PoC
CVE-2025-21760
Linux kernel (Azure) vulnerabilities
CVSS 8.1 HIGH · EPSS 0.33 (98th pct) · ↑ EPSS 0.09→0.33 (+0.24) over 7d

In the Linux kernel, the following vulnerability has been resolved: ndisc: extend RCU protection in ndisc_send_skb() ndisc_send_skb() can be called without RTNL or RCU held. Acquire rcu_read_lock() earlier, so that we can use…

suricata rule

Get this every Monday

Free weekly digest for blue teams — what got weaponized, with detection coverage.