cbcvebase.
← Exploited This Week

Exploited This Week — Aug 03–Aug 10, 2026

6 KEV · 17 newly weaponized · 2 EPSS surges

Patch now — added to CISA KEV

CVE-2026-8037
Progress LoadMaster Command Injection Vulnerability
CISA KEV (added 2026-08-07, due 2026-08-10) · CVSS 9.8 CRITICAL · EPSS 0.99 (100th pct)

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command…

Nuclei templateblogs_checkpoint, blogs_hackernews, vuldb, vulncheck
CVE-2026-34486
Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
CISA KEV (added 2026-08-04, due 2026-08-07) · CVSS 7.5 HIGH · EPSS 0.81 (100th pct)

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to…

Nuclei templateblogs_hackernews, blogs_unit42, vuldb, vulncheck
CVE-2026-9198
IBM Langflow Code Injection Vulnerability
CISA KEV (added 2026-08-04, due 2026-08-07) · CVSS 9.8 CRITICAL · EPSS 0.17 (97th pct)

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default…

Nuclei templateblogs_hackernews, vuldb, vulncheck
CVE-2026-18577
N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
CISA KEV (added 2026-08-03, due 2026-08-06) · CVSS 8.1 HIGH · EPSS 0.04 (90th pct)

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

blogs_hackernews, blogs_rapid7, vuldb, vulncheck
CVE-2026-63077
JetBrains TeamCity Deserialization of Untrusted Data Vulnerability
CISA KEV (added 2026-08-05, due 2026-08-08) · CVSS 9.8 CRITICAL · EPSS 0.01 (60th pct)

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

blogs_checkpoint, blogs_hackernews, blogs_rapid7, vuldb +1
CVE-2026-18556
N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
CISA KEV (added 2026-08-04, due 2026-08-07) · CVSS 7.4 HIGH · EPSS 0.00 (40th pct)

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

blogs_hackernews, blogs_rapid7, vuldb, vulncheck

Newly weaponized — exploit code appeared

CVE-2025-11953
React Native Community CLI OS Command Injection Vulnerability
CISA KEV (added 2026-02-05, due 2026-02-26) · CVSS 9.8 CRITICAL · EPSS 0.94 (100th pct)

The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpoint that is vulnerable to OS command injection. This allows unauthenticated network…

blogs_bleepingcomputer, blogs_checkpoint, blogs_greynoiseio, vulncheck
CVE-2025-6389
The Sneeit Framework plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including…
CVSS 9.8 CRITICAL · EPSS 0.73 (99th pct)

The Sneeit Framework plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.3 via the sneeit_articles_pagination_callback() function. This is due to the function accepting user input and then…

Nuclei templatesuricata ruleblogs_hackernews, vulncheck
CVE-2026-48939
iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability
CISA KEV (added 2026-07-10, due 2026-07-13) · CVSS 9.8 CRITICAL · EPSS 0.83 (100th pct)

A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

blogs_hackernews, vuldb, vulncheck
CVE-2025-20282
Cisco Identity Services Engine Unauthenticated Remote Code Execution Vulnerabilities
CVSS 10 CRITICAL · EPSS 0.27 (98th pct)

A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to upload arbitrary files to an affected device and then execute those files on the underlying operating system as root.…

blogs_bleepingcomputer, blogs_checkpoint, blogs_greynoiseio, vulncheck
CVE-2026-60004
Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup An unauthenticated attacker…
CVSS 9.8 CRITICAL

Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup An unauthenticated attacker can read any file the service account can access on Gitea , the self-hosted Git platform, in versions 1.22.1 through…

Nuclei templateblogs_hackernews
CVE-2026-14894
Unrestricted Upload of File with Dangerous Type
CVSS 9.8 CRITICAL · EPSS 0.03 (85th pct)

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 6.3.313 via the submit_form function. This is due to missing file type validation and the absence…

blogs_wiz, vulncheck
CVE-2026-53576
Kestra is an open-source, event-driven orchestration platform.
CVSS 10 CRITICAL · EPSS 0.02 (81th pct)

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the authentication filter for the REST API (@Filter("/api/v1/**")) treats any request whose path ends in /configs as the public instance-config…

vuldb, vulncheck
CVE-2026-29053
Ghost Vulnerable to Remote Code Execution via Malicious Themes
CVSS 9.8 CRITICAL · EPSS 0.01 (59th pct)

Ghost is a Node.js content management system. From version 0.7.2 to 6.19.0, specifically crafted malicious themes can execute arbitrary code on the server running Ghost. This issue has been patched in version 6.19.1.

blogs_wiz
CVE-2026-48030
Pheditor: OS Command Injection in terminal handler via unsanitized 'dir' parameter
CVSS 9.9 CRITICAL · EPSS 0.05 (92th pct)

Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.4, an OS Command Injection vulnerability in the terminal action handler allows any authenticated user to execute arbitrary OS…

🔧 no public PoC or detection rule linked yet — detection gap
CVE-2025-71324
FlowiseAI Flowise External Control of File Name or Path
CVSS 7.5 HIGH · EPSS 0.01 (70th pct)

Flowise before 3.0.6 contains an arbitrary file read vulnerability in the chatId parameter of the /api/v1/get-upload-file and /api/v1/openai-assistants-file/download endpoints. The chatId value is not validated and is passed to…

vuldb, vulncheck

+5 more lower-signal CVEs gained public exploit code this week.

EPSS surges — exploitation risk jumped

CVE-2026-42897
Microsoft Exchange Server Cross-Site Scripting Vulnerability
CISA KEV (added 2026-05-15, due 2026-05-29) · CVSS 6.1 MEDIUM · EPSS 0.70 (99th pct) · ↑ EPSS 0.06→0.70 (+0.65) over 7d

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

blogs_bleepingcomputer, blogs_checkpoint, blogs_hackernews, blogs_recorded_future +2
CVE-2025-6197
grafana: Open Redirect in Grafana
CVSS 4.2 MEDIUM · EPSS 0.67 (99th pct) · ↑ EPSS 0.04→0.67 (+0.63) over 7d

An open redirect vulnerability has been identified in Grafana OSS organization switching functionality. Prerequisites for exploitation: Multiple organizations must exist in the Grafana instance Victim must be on a different organization…

Nuclei template

Get this every Monday

Free weekly digest for blue teams — what got weaponized, with detection coverage.