cbcvebase.
← Exploited This Week

Exploited This Week — Aug 17–Aug 24, 2026

9 KEV · 43 newly weaponized · 8 EPSS surges

Patch now — added to CISA KEV

CVE-2026-33824
Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability
CISA KEV (added 2026-08-18, due 2026-08-21) · CVSS 9.8 CRITICAL · EPSS 0.78 (100th pct)

Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.

blogs_bleepingcomputer, blogs_crowdstrike, blogs_hackernews, blogs_qualys +7
CVE-2026-64849
MLflow Server-Side Request Forgery Vulnerability
CISA KEV (added 2026-08-19, due 2026-09-02) · CVSS 9.3 CRITICAL · EPSS 0.08 (95th pct)

MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in…

blogs_hackernews, vuldb, vulncheck
CVE-2026-55040
Microsoft SharePoint Weak Authentication Vulnerability
CISA KEV (added 2026-08-18, due 2026-08-21) · CVSS 9.1 CRITICAL · EPSS 0.05 (92th pct)

Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.

blogs_crowdstrike, blogs_hackernews, blogs_qualys, blogs_rapid7 +5
CVE-2026-59310
Broadcom VMware vCenter Path Traversal Vulnerability
CISA KEV (added 2026-08-18, due 2026-08-21) · CVSS 9.8 CRITICAL · EPSS 0.02 (83th pct)

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

blogs_checkpoint, blogs_hackernews, blogs_rapid7, vuldb +1
CVE-2026-73570
Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability
CISA KEV (added 2026-08-21, due 2026-08-24) · CVSS 8.9 HIGH · EPSS 0.01 (61th pct)

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP…

blogs_hackernews, vuldb, vulncheck
CVE-2025-62593
Ray-Project Ray Code Injection Vulnerability
CISA KEV (added 2026-08-17, due 2026-08-20) · CVSS 8.8 HIGH · EPSS 0.01 (60th pct)

Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerability exploitable via Firefox and Safari. This vulnerability is due to an insufficient…

blogs_hackernews, vulncheck
CVE-2026-72530
TrueConf Server Code Injection Vulnerability
CISA KEV (added 2026-08-20, due 2026-09-03) · CVSS 9 CRITICAL · EPSS 0.01 (59th pct)

A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment…

vuldb, vulncheck
CVE-2026-72529
TrueConf Server Missing Authentication for Critical Function Vulnerability
CISA KEV (added 2026-08-20, due 2026-08-23) · CVSS 9.8 CRITICAL · EPSS 0.01 (53th pct)

A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.

vulncheck
CVE-2026-65400
Apple macOS Improper Authentication Vulnerability
CISA KEV (added 2026-08-18, due 2026-08-21) · CVSS 9.8 CRITICAL · EPSS 0.01 (52th pct)

An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may be able to authenticate to Screen Sharing without…

blogs_checkpoint, blogs_hackernews, blogs_huntress, vuldb +1

Newly weaponized — exploit code appeared

CVE-2026-20896
Gitea Docker image: REVERSE_PROXY_TRUSTED_PROXIES = * default lets any source IP impersonate any user via X-WEBAUTH-USER
CVSS 9.8 CRITICAL · EPSS 0.62 (99th pct)

Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are enabled.

blogs_hackernews, vulncheck
CVE-2026-32255
Kan is an open-source project management tool.
CVSS 8.6 HIGH · EPSS 0.19 (97th pct)

Kan is an open-source project management tool. In versions 0.5.4 and below, the /api/download/attatchment endpoint has no authentication and no URL validation. The Attachment Download endpoint accepts a user-supplied URL query parameter…

blogs_greynoiseio
CVE-2026-58058
nmap: Nmap: Denial of Service via crafted IPv6 response
CVSS 6.5 MEDIUM · EPSS 0.01 (56th pct)

Nmap through 7.99 does not keep the IPv6 extension-header walk within the captured packet in ipv6_get_data_primitive (libnetutil/netutil.cc), so the pointer advances past the buffer and the remaining-length computation underflows to a…

ExploitDB PoCvuldb
CVE-2026-14620
webpack-dev-server: webpack-dev-server: Arbitrary file opening and denial of service via exposed developer endpoints
CVSS 4.7 MEDIUM · EPSS 0.01 (42th pct)

webpack-dev-server versions 5.2.5 and earlier expose two internal developer endpoints, /webpack-dev-server/open-editor and /webpack-dev-server/invalidate, that perform state-changing actions on any GET request without verifying that the…

ExploitDB PoCvuldb
CVE-2026-55780
NanaZip 6.5 - DoS
CVSS 2.4 LOW · EPSS 0.00 (24th pct)

NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's .NET single-file bundle handler in NanaZip.Codecs.Archive.DotNetSingleFile.cpp sizes its extraction buffer from the bundle entry…

ExploitDB PoCvuldb
CVE-2026-6402
webpack-dev-server: webpack-dev-server: Information disclosure due to cross-origin source code exposure
CVSS 6.5 MEDIUM · EPSS 0.00 (12th pct)

webpack-dev-server versions up to and including 5.2.3 are vulnerable to cross-origin source code exposure when serving over a non-potentially trustworthy origin such as plain HTTP. The previous fix relied on the Sec-Fetch-Mode and…

ExploitDB PoCvuldb
CVE-2025-4871
PCMan 2.0.7 - Buffer Overflow
CVSS 9.8 CRITICAL · EPSS 0.02 (74th pct)

A vulnerability, which was classified as critical, has been found in PCMan FTP Server 2.0.7. This issue affects some unknown processing of the component REST Command Handler. The manipulation leads to buffer overflow. The attack may be…

ExploitDB PoC
CVE-2026-15748
The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including…
CVSS 9.8 CRITICAL · EPSS 0.03 (88th pct)

The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upload function. This is due to insufficient file type validation in handle_file_upload…

blogs_hackernews
CVE-2026-56265
Crawl4AI before 0.8.7 contains an authentication bypass vulnerability due to a hardcoded default JWT signing key in…
CVSS 9.8 CRITICAL · EPSS 0.03 (84th pct)

Crawl4AI before 0.8.7 contains an authentication bypass vulnerability due to a hardcoded default JWT signing key in the Docker API server. Attackers who know the default key can forge valid authentication tokens for any user, bypassing…

vuldb
CVE-2026-15826
cozmoslabs profile_builder Incorrect Type Conversion or Cast
CVSS 9.8 CRITICAL · EPSS 0.02 (83th pct)

The User Profile Builder plugin for WordPress is vulnerable to Authentication Bypass via Type Confusion in versions up to, and including, 3.16.4. This is due to the wppb_log_in_user() function calling absint() on the return value of…

blogs_hackernews, vulncheck

+28 more lower-signal CVEs gained public exploit code this week.

EPSS surges — exploitation risk jumped

CVE-2024-57726
SimpleHelp Missing Authorization Vulnerability
CISA KEV (added 2026-04-24, due 2026-05-08) · 🦠 ransomware · CVSS 9.9 CRITICAL · EPSS 0.67 (99th pct) · ↑ EPSS 0.09→0.67 (+0.58) over 7d

SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.

blogs_bleepingcomputer, blogs_hackernews, blogs_securelist, vuldb +1
CVE-2001-0506
Buffer overflow in ssinc
CVSS 7.2 HIGH · EPSS 0.69 (99th pct) · ↑ EPSS 0.30→0.69 (+0.39) over 7d

Buffer overflow in ssinc.dll in IIS 5.0 and 4.0 allows local users to gain system privileges via a Server-Side Includes (SSI) directive for a long filename, which triggers the overflow when the directory name is added, aka the "SSI…

ExploitDB PoC
CVE-2018-11139
The '/common/ajax_email_connection_test
CVSS 8.8 HIGH · EPSS 0.77 (100th pct) · ↑ EPSS 0.43→0.77 (+0.35) over 7d

The '/common/ajax_email_connection_test.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by any authenticated user and can be abused to execute arbitrary commands on the system. This script is vulnerable to…

🔧 no public PoC or detection rule linked yet — detection gap
CVE-2018-11132
In order to perform actions that require higher privileges, the Quest KACE System Management Appliance 8.0.318 relies…
CVSS 8.8 HIGH · EPSS 0.53 (99th pct) · ↑ EPSS 0.18→0.53 (+0.34) over 7d

In order to perform actions that require higher privileges, the Quest KACE System Management Appliance 8.0.318 relies on a message queue that runs daemonized with root privileges and only allows a set of commands to be executed. A command…

🔧 no public PoC or detection rule linked yet — detection gap
CVE-2018-8033
Apache ofbiz:
CVSS 7.5 HIGH · EPSS 0.60 (99th pct) · ↑ EPSS 0.26→0.60 (+0.34) over 7d

In Apache OFBiz 16.11.01 to 16.11.04, the OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for HTTP services via the /webtools/control/httpService endpoint. Both POST and GET requests to the httpService…

Nuclei templateblogs_greynoiseio
CVE-2017-3241
OpenJDK 6 vulnerabilities
CVSS 9 CRITICAL · EPSS 0.62 (99th pct) · ↑ EPSS 0.33→0.62 (+0.29) over 7d

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 6u131, 7u121 and 8u112; Java SE Embedded: 8u111; JRockit: R28.3.12. Difficult to…

ExploitDB PoC
CVE-2018-5925
A security vulnerability has been identified with certain HP Inkjet printers
CVSS 7.8 HIGH · EPSS 0.39 (99th pct) · ↑ EPSS 0.11→0.39 (+0.28) over 7d

A security vulnerability has been identified with certain HP Inkjet printers. A maliciously crafted file sent to an affected device can cause a static buffer overflow, which could allow remote code execution.

blogs_checkpoint, blogs_tenable
CVE-2019-13510
Rockwell Automation Arena Simulation Software (Update B)
CVSS 7.8 HIGH · EPSS 0.39 (99th pct) · ↑ EPSS 0.12→0.39 (+0.27) over 7d

Rockwell Automation Arena Simulation Software versions 16.00.00 and earlier contain a USE AFTER FREE CWE-416. A maliciously crafted Arena file opened by an unsuspecting user may result in the application crashing or the execution of…

🔧 no public PoC or detection rule linked yet — detection gap

Get this every Monday

Free weekly digest for blue teams — what got weaponized, with detection coverage.