cbcvebase.
← Exploited This Week

Exploited This Week — Aug 10–Aug 17, 2026

3 KEV · 47 newly weaponized · 0 EPSS surges

Patch now — added to CISA KEV

CVE-2026-72898
Metabase SQL Injection Vulnerability
CISA KEV (added 2026-08-11, due 2026-08-14) · CVSS 10 CRITICAL · EPSS 0.10 (95th pct)

Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.

Nuclei templatevuldb, vulncheck
CVE-2026-20349
Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability
CISA KEV (added 2026-08-11, due 2026-08-14) · CVSS 8.6 HIGH · EPSS 0.01 (56th pct)

A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the…

blogs_hackernews, vuldb, vulncheck
CVE-2026-68820
Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
CISA KEV (added 2026-08-11, due 2026-08-25) · CVSS 7 HIGH · EPSS 0.00 (26th pct)

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

blogs_checkpoint, blogs_crowdstrike, blogs_hackernews, blogs_krebs +8

Newly weaponized — exploit code appeared

CVE-2026-34908
Ubiquiti UniFi OS Improper Access Control Vulnerability
CISA KEV (added 2026-06-23, due 2026-06-26) · CVSS 10 CRITICAL · EPSS 0.85 (100th pct)

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.

Nuclei templateblogs_bleepingcomputer, blogs_checkpoint, blogs_hackernews, vuldb +1
CVE-2026-58644
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
CISA KEV (added 2026-07-16, due 2026-07-19) · CVSS 9.8 CRITICAL · EPSS 0.45 (99th pct)

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

Nuclei templateblogs_crowdstrike, blogs_hackernews, blogs_qualys, blogs_rapid7 +5
CVE-2026-49049
ollyo helix3 Improper Access Control
CVSS 7.5 HIGH · EPSS 0.28 (98th pct)

The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON files and update template parameters.

Nuclei templateblogs_wiz, vuldb, vulncheck
CVE-2026-50160
Hoppscotch is an API development ecosystem.
CVSS 10 CRITICAL · EPSS 0.18 (97th pct)

Hoppscotch is an API development ecosystem. In self-hosted deployments of hoppscotch-backend from version 2026.4.1 and earlier, the unauthenticated POST /v1/onboarding/config endpoint is vulnerable to mass assignment. The global NestJS…

Nuclei templateblogs_hackernews, vuldb
CVE-2026-58138
OrkesConductor 3.30.2 - Unauthenticated Remote Code Execution
CVSS 9.8 CRITICAL · EPSS 0.07 (94th pct)

Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary OS commands by submitting inline workflow definitions containing malicious JavaScript…

ExploitDB PoCNuclei templatevulncheck
CVE-2026-15733
A Remote Code Execution (RCE) vulnerability exist in WGDashboard version 4.2.3 and earlier.
CVSS 9.8 CRITICAL · EPSS 0.14 (96th pct)

A Remote Code Execution (RCE) vulnerability exist in WGDashboard version 4.2.3 and earlier. Multiple OS command injection allows authenticated attackers to execute arbitrary commands as root.

Nuclei template
CVE-2026-67208
Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote attackers to…
CVSS 9.8 CRITICAL · EPSS 0.04 (90th pct)

Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote attackers to execute arbitrary OS commands by connecting to the exposed H2 database web console using default shipped credentials.…

Nuclei templatevuldb
CVE-2026-3395
A flaw has been found in MaxSite CMS up to 109.1.
CVSS 9.8 CRITICAL · EPSS 0.03 (87th pct)

A flaw has been found in MaxSite CMS up to 109.1. This impacts the function eval of the file application/maxsite/admin/plugins/editor_markitup/preview-ajax.php of the component MarkItUp Preview AJAX Endpoint. Executing a manipulation can…

Nuclei templateblogs_hackernews, vulncheck
CVE-2025-13342
dynamiapps frontend_admin Missing Authorization
CVSS 9.8 CRITICAL · EPSS 0.02 (80th pct)

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthorized modification of arbitrary WordPress options in all versions up to, and including, 3.28.20. This is due to insufficient capability checks and input…

Nuclei templatevulncheck
CVE-2026-53519
Nezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_key
CVSS 9.1 CRITICAL · EPSS 0.02 (77th pct)

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Prior to version 2.0.13, fallbackToFrontend in the dashboard's NoRoute handler treats any URL whose raw string starts with /dashboard as an…

Nuclei templatevuldb

+34 more lower-signal CVEs gained public exploit code this week.

Get this every Monday

Free weekly digest for blue teams — what got weaponized, with detection coverage.