cbcvebase.
← Exploited This Week

Exploited This Week — Aug 24–Aug 31, 2026

10 KEV · 38 newly weaponized · 8 EPSS surges

Patch now — added to CISA KEV

CVE-2026-60004
Gitea Code Injection Vulnerability
CISA KEV (added 2026-08-25, due 2026-08-28) · CVSS 9.8 CRITICAL · EPSS 0.85 (100th pct)

Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

Nuclei templateblogs_hackernews, vuldb, vulncheck
CVE-2021-23758
Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
CISA KEV (added 2026-08-26, due 2026-09-09) · CVSS 9.8 CRITICAL · EPSS 0.84 (100th pct)

All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.

Metasploit modulesuricata ruleblogs_hackernews, blogs_talos, vuldb, vulncheck
CVE-2019-1068
Microsoft SQL Server Remote Code Execution Vulnerability
CISA KEV (added 2026-08-26, due 2026-08-29) · CVSS 8.8 HIGH · EPSS 0.53 (99th pct)

A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'.

blogs_hackernews, blogs_qualys, blogs_securelist, blogs_sentinelone +2
CVE-2023-49105
ownCloud Improper Authentication Vulnerability
CISA KEV (added 2026-08-27, due 2026-08-30) · CVSS 9.8 CRITICAL · EPSS 0.43 (99th pct)

An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs…

Nuclei templatesuricata ruleblogs_greynoiseio, blogs_hackernews, blogs_wiz, vulncheck
CVE-2026-21962
Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability
CISA KEV (added 2026-08-24, due 2026-08-27) · CVSS 10 CRITICAL · EPSS 0.42 (99th pct)

Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versions…

suricata ruleblogs_bleepingcomputer, blogs_greynoiseio, blogs_hackernews, blogs_wiz +2
CVE-2022-0995
Linux Kernel Out-of-Bounds Write Vulnerability
CISA KEV (added 2026-08-26, due 2026-09-09) · CVSS 7.8 HIGH · EPSS 0.10 (95th pct)

An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged access or cause a…

Metasploit modulesuricata ruleblogs_hackernews, blogs_talos, vuldb, vulncheck
CVE-2015-3246
Red Hat Libuser Race Condition Vulnerability
CISA KEV (added 2026-08-26, due 2026-09-09) · CVSS 5.1 MEDIUM · EPSS 0.09 (95th pct)

libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error…

ExploitDB PoCMetasploit moduleblogs_hackernews, blogs_talos, vuldb, vulncheck
CVE-2015-5287
Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
CISA KEV (added 2026-08-26, due 2026-09-09) · CVSS 7.8 HIGH · EPSS 0.05 (92th pct)

The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name, as demonstrated by…

ExploitDB PoCMetasploit moduleblogs_hackernews, blogs_talos, vuldb, vulncheck
CVE-2026-8452
Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
CISA KEV (added 2026-08-26, due 2026-08-29) · CVSS 9.8 CRITICAL · EPSS 0.02 (74th pct)

Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server

blogs_hackernews, vuldb, vulncheck
CVE-2026-66384
JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability
CISA KEV (added 2026-08-27, due 2026-09-10) · CVSS 5.3 MEDIUM · EPSS 0.01 (45th pct)

An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.

blogs_hackernews

Newly weaponized — exploit code appeared

CVE-2026-61511
vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the…
CVSS 9.8 CRITICAL · EPSS 0.71 (99th pct)

vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP…

Nuclei templateblogs_hackernews, vuldb
CVE-2026-18577
N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
CISA KEV (added 2026-08-03, due 2026-08-06) · CVSS 8.1 HIGH · EPSS 0.54 (99th pct)

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

blogs_hackernews, blogs_huntress, blogs_rapid7, vuldb +1
CVE-2026-55040
Microsoft SharePoint Weak Authentication Vulnerability
CISA KEV (added 2026-08-18, due 2026-08-21) · CVSS 9.1 CRITICAL · EPSS 0.40 (99th pct)

Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.

blogs_crowdstrike, blogs_hackernews, blogs_qualys, blogs_rapid7 +5
CVE-2026-66066
activestorage: Active Storage: Remote Code Execution via Unsafe libvips Operations
CVSS 9.5 CRITICAL · EPSS 0.28 (98th pct)

Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload…

Metasploit moduleblogs_checkpoint, blogs_hackernews, blogs_rapid7, vuldb +1
CVE-2026-18556
N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
CISA KEV (added 2026-08-04, due 2026-08-07) · CVSS 7.4 HIGH · EPSS 0.40 (99th pct)

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

blogs_hackernews, blogs_huntress, blogs_rapid7, vuldb +1
CVE-2026-40217
LiteLLM: LiteLLM: Arbitrary Code Execution via bytecode rewriting
CVSS 8.8 HIGH · EPSS 0.15 (96th pct)

LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/test_custom_code URI.

Nuclei templateblogs_hackernews, vulncheck
CVE-2026-18963
keycloak-services: keycloak-services: Unauthenticated account takeover via reset-credentials flow bypass
CVSS 9.1 CRITICAL · EPSS 0.03 (87th pct)

A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the…

Nuclei templateblogs_hackernews, vulncheck
CVE-2026-19681
An authenticated command injection vulnerability exists in Security Center related to file upload processing.
CVSS 9.9 CRITICAL · EPSS 0.08 (94th pct)

An authenticated command injection vulnerability exists in Security Center related to file upload processing. An attacker could exploit this issue by uploading a specially crafted file, potentially resulting in arbitrary command execution…

Metasploit moduleblogs_rapid7, vuldb
CVE-2026-19598
The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via…
CVSS 9.8 CRITICAL · EPSS 0.03 (85th pct)

The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to, and including, 3.3.9. The vulnerability exists because the pods_admin AJAX router…

Nuclei templateblogs_hackernews, vuldb, vulncheck
CVE-2025-14998
wpmudev branda Authorization Bypass Through User-Controlled Key
CVSS 9.8 CRITICAL · EPSS 0.02 (77th pct)

The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.24. This is due to the plugin not properly validating a user's identity prior to updating their password.…

Nuclei templateblogs_wiz, vulncheck

+26 more lower-signal CVEs gained public exploit code this week.

EPSS surges — exploitation risk jumped

CVE-2026-63077
JetBrains TeamCity Deserialization of Untrusted Data Vulnerability
CISA KEV (added 2026-08-05, due 2026-08-08) · CVSS 9.8 CRITICAL · EPSS 0.88 (100th pct) · ↑ EPSS 0.12→0.88 (+0.76) over 7d

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

Nuclei templateblogs_checkpoint, blogs_hackernews, blogs_rapid7, vuldb +1
CVE-2026-72898
Metabase SQL Injection Vulnerability
CISA KEV (added 2026-08-11, due 2026-08-14) · CVSS 10 CRITICAL · EPSS 0.79 (100th pct) · ↑ EPSS 0.10→0.79 (+0.69) over 7d

Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.

Nuclei templatevuldb, vulncheck
CVE-2026-45659
Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability
CISA KEV (added 2026-07-01, due 2026-07-04) · 🦠 ransomware · CVSS 8.8 HIGH · EPSS 0.76 (99th pct) · ↑ EPSS 0.10→0.76 (+0.66) over 7d

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Nuclei templateblogs_hackernews, blogs_tenable, vuldb, vulncheck
CVE-2016-3251
Windows GDI Information Disclosure Vulnerability
CVSS 2.8 LOW · EPSS 0.58 (99th pct) · ↑ EPSS 0.03→0.58 (+0.55) over 7d

The GDI component in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users…

blogs_zscaler
CVE-2026-6875
ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform.
CVSS 9.5 CRITICAL · EPSS 0.78 (100th pct) · ↑ EPSS 0.27→0.78 (+0.51) over 7d

ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute code within the ServiceNow…

Nuclei templateblogs_hackernews, vuldb, vulncheck
CVE-2017-3191
D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 are vulnerable to authentication bypass of the…
CVSS 9.8 CRITICAL · EPSS 0.63 (99th pct) · ↑ EPSS 0.14→0.63 (+0.48) over 7d

D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 are vulnerable to authentication bypass of the remote login page. A remote attacker that can access the remote management login page can manipulate the POST request in…

🔧 no public PoC or detection rule linked yet — detection gap
CVE-2026-59310
Broadcom VMware vCenter Path Traversal Vulnerability
CISA KEV (added 2026-08-18, due 2026-08-21) · CVSS 9.8 CRITICAL · EPSS 0.46 (99th pct) · ↑ EPSS 0.02→0.46 (+0.43) over 7d

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

blogs_checkpoint, blogs_hackernews, blogs_rapid7, vuldb +1
CVE-2020-10221
rConfig OS Command Injection Vulnerability
CISA KEV (added 2021-11-03, due 2022-05-03) · CVSS 8.8 HIGH · EPSS 0.80 (100th pct) · ↑ EPSS 0.37→0.80 (+0.43) over 7d

lib/ajaxHandlers/ajaxAddTemplate.php in rConfig through 3.94 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the fileName POST parameter.

ExploitDB PoCvulncheck

Get this every Monday

Free weekly digest for blue teams — what got weaponized, with detection coverage.