// THREAT RADAR

📡 The most dangerous CVEs right now

A self-updating ranking that combines three signals: whether it is actively exploited (CISA KEV), the exploit probability (EPSS) and the severity (CVSS). Not "the latest published", but what actually matters to prioritize.

On radar40
Exploited (KEV)16
Updated16h ago
🎯 How it is ranked: score = EPSS + CVSS + KEV + recency. The KEV badge means active exploitation confirmed by CISA. Each CVE links to its NVD record and to the CVSS and patch prioritization tools.

📬 This week in exploited CVEs, every Monday by email · 📡 Subscribe via RSS · 🧩 Embed the “CVE of the day” on your site · 🌉 Turn a CVE into detection

Filter
#1
CVE-2026-85706 Critical 10.0 Exploited (KEV)
GitLab GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.11.12, 19.0 before 19.0.9, 19.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user cou…
Analysis

🔴 Critical — actively exploited

Weakness: Path Traversal (CWE-22). Accesses files outside the intended directory (../).

How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity. The flaw can pivot to other components (scope changed).

⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.

Impact: Confidentiality high · Integrity high · Availability none.

Status: Active exploitation confirmed by CISA (KEV).

How to defend:
  • Patch now: it is in CISA's actively-exploited catalog (KEV), with a deadline.
  • Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
  • Detect: turn this CVE into detection rules.

MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application

Practice it in the arsenal: WAF Bypass

93%EPSS
10.0CVSS
#2
CVE-2026-20079 Critical 10.0 Exploited (KEV)
Cisco Cisco Secure Firewall Management Center (FMC)
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to…
Analysis

🔴 Critical — actively exploited

Weakness: CWE-288.

How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity. The flaw can pivot to other components (scope changed).

⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.

Impact: Full compromise (confidentiality, integrity and availability).

Status: Active exploitation confirmed by CISA (KEV).

How to defend:
  • Patch now: it is in CISA's actively-exploited catalog (KEV), with a deadline.
  • Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
  • Detect: turn this CVE into detection rules.
88%EPSS
10.0CVSS
#3
CVE-2026-10520 Critical 10.0 Exploited (KEV)
ivanti Sentry
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution
Analysis

🔴 Critical — actively exploited

Weakness: OS Command Injection (CWE-78). Runs operating-system commands via unsanitized input.

How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity. The flaw can pivot to other components (scope changed).

⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.

Impact: Full compromise (confidentiality, integrity and availability).

Status: Active exploitation confirmed by CISA (KEV).

How to defend:
  • Patch now: it is in CISA's actively-exploited catalog (KEV), with a deadline.
  • Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
  • Detect: turn this CVE into detection rules.

MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application · T1059 · Command and Scripting Interpreter

Practice it in the arsenal: WAF Bypass · PowerShell Decoder · Reverse Shells

100%EPSS
10.0CVSS
#4
CVE-2026-20253 Critical 9.8 Exploited (KEV)
Splunk Splunk Enterprise
In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint. The vulnerability exists because the PostgreSQL s…
Analysis

🔴 Critical — actively exploited

Weakness: Missing Authentication (CWE-306). Critical function reachable without authentication.

How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity.

⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.

Impact: Full compromise (confidentiality, integrity and availability).

Status: Active exploitation confirmed by CISA (KEV).

How to defend:
  • Patch now: it is in CISA's actively-exploited catalog (KEV), with a deadline.
  • Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
  • Detect: turn this CVE into detection rules.

MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application

Practice it in the arsenal: WAF Bypass

97%EPSS
9.8CVSS
#5
CVE-2026-63077 Critical 9.8 Exploited (KEV) Ransomware
JetBrains TeamCity
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
Analysis

🔴 Critical — used in ransomware

Weakness: Insecure Deserialization (CWE-502). Untrusted serialized data leads to code execution.

How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity.

⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.

Impact: Full compromise (confidentiality, integrity and availability).

Status: Used in ransomware campaigns (CISA KEV).

How to defend:
  • Patch now: it is in CISA's actively-exploited catalog (KEV), with a deadline.
  • Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
  • Detect: turn this CVE into detection rules.

MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application · T1059 · Command and Scripting Interpreter

Practice it in the arsenal: WAF Bypass · PowerShell Decoder · Reverse Shells

90%EPSS
9.8CVSS
#6
CVE-2026-48908 Critical 10.0 Exploited (KEV)
joomshaper.net SP Page Builder extension for Joomla
A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.
Analysis

🔴 Critical — actively exploited

Weakness: Unrestricted File Upload (CWE-434). Allows uploading dangerous files (e.g. webshells).

How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity.

⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.

Impact: Full compromise (confidentiality, integrity and availability).

Status: Active exploitation confirmed by CISA (KEV).

How to defend:
  • Patch now: it is in CISA's actively-exploited catalog (KEV), with a deadline.
  • Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
  • Detect: turn this CVE into detection rules.

MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application

Practice it in the arsenal: WAF Bypass

89%EPSS
10.0CVSS
#7
CVE-2026-81578 High 8.8 Exploited (KEV)
PaperCut PaperCut MF/NG
An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior…
Analysis

🔴 Critical — actively exploited

Weakness: CWE-305.

How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity.

⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.

Impact: Confidentiality partial · Integrity high · Availability partial.

Status: Active exploitation confirmed by CISA (KEV).

How to defend:
  • Patch now: it is in CISA's actively-exploited catalog (KEV), with a deadline.
  • Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
  • Detect: turn this CVE into detection rules.
85%EPSS
8.8CVSS
#8
CVE-2026-42271 High 8.7 Exploited (KEV)
BerriAI litellm
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints used to preview an MCP server before saving it — POST /mcp-rest/test/connection and POST /mcp…
Analysis

🔴 Critical — actively exploited

Weakness: Command Injection (CWE-77). Runs commands via unsanitized input.

How it's exploited: Exploitable over the network (internet-reachable), with low privileges, no user interaction, and with low complexity.

Impact: Full compromise (confidentiality, integrity and availability).

Status: Active exploitation confirmed by CISA (KEV).

How to defend:
  • Patch now: it is in CISA's actively-exploited catalog (KEV), with a deadline.
  • Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
  • Detect: turn this CVE into detection rules.

MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application · T1059 · Command and Scripting Interpreter

Practice it in the arsenal: WAF Bypass · PowerShell Decoder · Reverse Shells

93%EPSS
8.7CVSS
#9
CVE-2026-20230 High 8.6 Exploited (KEV)
Cisco Cisco Unified Communications Manager
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forger…
Analysis

🔴 Critical — actively exploited

Weakness: Server-Side Request Forgery (SSRF) (CWE-918). Forces the server to make requests to internal targets.

How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity. The flaw can pivot to other components (scope changed).

⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.

Impact: Confidentiality none · Integrity high · Availability none.

Status: Active exploitation confirmed by CISA (KEV).

How to defend:
  • Patch now: it is in CISA's actively-exploited catalog (KEV), with a deadline.
  • Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
  • Detect: turn this CVE into detection rules.

MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application

Practice it in the arsenal: WAF Bypass

88%EPSS
8.6CVSS
#10
CVE-2026-21962 Critical 10.0 Exploited (KEV)
Oracle Corporation Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in
Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versions…
Analysis

🔴 Critical — actively exploited

How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity. The flaw can pivot to other components (scope changed).

⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.

Impact: Confidentiality high · Integrity high · Availability none.

Status: Active exploitation confirmed by CISA (KEV).

How to defend:
  • Patch now: it is in CISA's actively-exploited catalog (KEV), with a deadline.
  • Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
  • Detect: turn this CVE into detection rules.
71%EPSS
10.0CVSS
#11
CVE-2021-23758 High 8.1 Exploited (KEV)
n/a AjaxPro.2
All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.
Analysis

🔴 Critical — actively exploited

Weakness: Insecure Deserialization (CWE-502). Untrusted serialized data leads to code execution.

How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, with high complexity.

Impact: Full compromise (confidentiality, integrity and availability).

Status: Active exploitation confirmed by CISA (KEV).

How to defend:
  • Patch now: it is in CISA's actively-exploited catalog (KEV), with a deadline.
  • Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
  • Detect: turn this CVE into detection rules.

MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application · T1059 · Command and Scripting Interpreter

Practice it in the arsenal: WAF Bypass · PowerShell Decoder · Reverse Shells

83%EPSS
8.1CVSS
#12
CVE-2026-8037 Critical 9.6 Exploited (KEV)
Progress Software LoadMaster
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endp…
Analysis

🔴 Critical — actively exploited

Weakness: Command Injection (CWE-77). Runs commands via unsanitized input.

How it's exploited: Exploitable from the local network (adjacent), unauthenticated, no user interaction, and with low complexity. The flaw can pivot to other components (scope changed).

Impact: Full compromise (confidentiality, integrity and availability).

Status: Active exploitation confirmed by CISA (KEV).

How to defend:
  • Patch now: it is in CISA's actively-exploited catalog (KEV), with a deadline.
  • Detect: turn this CVE into detection rules.

MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application · T1059 · Command and Scripting Interpreter

Practice it in the arsenal: WAF Bypass · PowerShell Decoder · Reverse Shells

77%EPSS
9.6CVSS
#13
CVE-2026-16232 Critical 9.3 Exploited (KEV)
checkpoint Quantum Security Management
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful…
Analysis

🔴 Critical — actively exploited

Weakness: Improper Authentication (CWE-287). Allows impersonation or login bypass.

How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity.

⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.

Impact: Full compromise (confidentiality, integrity and availability).

Status: Active exploitation confirmed by CISA (KEV).

How to defend:
  • Patch now: it is in CISA's actively-exploited catalog (KEV), with a deadline.
  • Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
  • Detect: turn this CVE into detection rules.

MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application

Practice it in the arsenal: WAF Bypass

78%EPSS
9.3CVSS
#14
CVE-2026-25089 Critical 9.1 Exploited (KEV)
Fortinet FortiSandbox
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.…
Analysis

🔴 Critical — actively exploited

Weakness: OS Command Injection (CWE-78). Runs operating-system commands via unsanitized input.

How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity.

⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.

Impact: Full compromise (confidentiality, integrity and availability).

Status: Active exploitation confirmed by CISA (KEV).

How to defend:
  • Patch now: it is in CISA's actively-exploited catalog (KEV), with a deadline.
  • Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
  • Detect: turn this CVE into detection rules.

MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application · T1059 · Command and Scripting Interpreter

Practice it in the arsenal: WAF Bypass · PowerShell Decoder · Reverse Shells

76%EPSS
9.1CVSS
#15
CVE-2026-82078 Critical 9.4 Exploited (KEV)
PaperCut PaperCut MF/NG
An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an…
Analysis

🔴 Critical — actively exploited

Weakness: CWE-470.

How it's exploited: Exploitable over the network (internet-reachable), with high privileges, no user interaction, and with low complexity.

Impact: Full compromise (confidentiality, integrity and availability).

Status: Active exploitation confirmed by CISA (KEV).

How to defend:
  • Patch now: it is in CISA's actively-exploited catalog (KEV), with a deadline.
  • Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
  • Detect: turn this CVE into detection rules.
61%EPSS
9.4CVSS
#16
CVE-2024-3400 Critical 10.0
Palo Alto Networks PAN-OS
A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated atta…
Analysis

🟠 High — imminent exploitation

Weakness: Command Injection (CWE-77). Runs commands via unsanitized input.

How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity. The flaw can pivot to other components (scope changed).

⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.

Impact: Full compromise (confidentiality, integrity and availability).

Status: Exploit probability (EPSS, 30 days): 100% — high.

How to defend:
  • Apply the vendor patch according to risk priority.
  • Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
  • Detect: turn this CVE into detection rules.

MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application · T1059 · Command and Scripting Interpreter

Practice it in the arsenal: WAF Bypass · PowerShell Decoder · Reverse Shells

100%EPSS
10.0CVSS
#17
CVE-2023-22518 Critical 10.0
Atlassian Confluence Data Center
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an unauthenticated attacker to reset Confluence and create a Confluence instance administrat…
Analysis

🟠 High — imminent exploitation

How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity. The flaw can pivot to other components (scope changed).

⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.

Impact: Full compromise (confidentiality, integrity and availability).

Status: Exploit probability (EPSS, 30 days): 100% — high.

How to defend:
  • Apply the vendor patch according to risk priority.
  • Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
  • Detect: turn this CVE into detection rules.
100%EPSS
10.0CVSS
#18
CVE-2023-35082 Critical 10.0
Ivanti EPMM
An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of the application without proper authentication. This vulnerability is unique to CVE-2023-350…
Analysis

🟠 High — imminent exploitation

Weakness: Improper Authentication (CWE-287). Allows impersonation or login bypass.

How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity. The flaw can pivot to other components (scope changed).

⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.

Impact: Full compromise (confidentiality, integrity and availability).

Status: Exploit probability (EPSS, 30 days): 100% — high.

How to defend:
  • Apply the vendor patch according to risk priority.
  • Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
  • Detect: turn this CVE into detection rules.

MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application

Practice it in the arsenal: WAF Bypass

100%EPSS
10.0CVSS
#19
CVE-2021-44228 Critical 10.0
Apache Software Foundation Apache Log4j2
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoin…
Analysis

🟠 High — imminent exploitation

Weakness: Insecure Deserialization (CWE-502). Untrusted serialized data leads to code execution.

How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity. The flaw can pivot to other components (scope changed).

⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.

Impact: Full compromise (confidentiality, integrity and availability).

Status: Exploit probability (EPSS, 30 days): 100% — high.

How to defend:
  • Apply the vendor patch according to risk priority.
  • Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
  • Detect: turn this CVE into detection rules.

MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application · T1059 · Command and Scripting Interpreter

Practice it in the arsenal: WAF Bypass · PowerShell Decoder · Reverse Shells

100%EPSS
10.0CVSS
#20
CVE-2025-53770 Critical 9.8
Microsoft Microsoft SharePoint Enterprise Server 2016
Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing a…
Analysis

🟠 High — imminent exploitation

Weakness: Insecure Deserialization (CWE-502). Untrusted serialized data leads to code execution.

How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity.

⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.

Impact: Full compromise (confidentiality, integrity and availability).

Status: Exploit probability (EPSS, 30 days): 100% — high.

How to defend:
  • Apply the vendor patch according to risk priority.
  • Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
  • Detect: turn this CVE into detection rules.

MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application · T1059 · Command and Scripting Interpreter

Practice it in the arsenal: WAF Bypass · PowerShell Decoder · Reverse Shells

100%EPSS
9.8CVSS
#21
CVE-2024-7593 Critical 9.8
Ivanti vTM
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the admin panel.
Analysis

🟠 High — imminent exploitation

Weakness: Improper Authentication (CWE-287). Allows impersonation or login bypass.

How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity.

⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.

Impact: Full compromise (confidentiality, integrity and availability).

Status: Exploit probability (EPSS, 30 days): 100% — high.

How to defend:
  • Apply the vendor patch according to risk priority.
  • Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
  • Detect: turn this CVE into detection rules.

MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application

Practice it in the arsenal: WAF Bypass

100%EPSS
9.8CVSS
#22
CVE-2024-23897 Critical 9.8
Jenkins Project Jenkins
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to r…
Analysis

🟠 High — imminent exploitation

Weakness: Path Traversal (CWE-22). Accesses files outside the intended directory (../).

How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity.

⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.

Impact: Full compromise (confidentiality, integrity and availability).

Status: Exploit probability (EPSS, 30 days): 100% — high.

How to defend:
  • Apply the vendor patch according to risk priority.
  • Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
  • Detect: turn this CVE into detection rules.

MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application

Practice it in the arsenal: WAF Bypass

100%EPSS
9.8CVSS
#23
CVE-2023-27350 Critical 9.8
PaperCut NG
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SetupCompl…
Analysis

🟠 High — imminent exploitation

Weakness: Improper Access Control (CWE-284). Fails to properly restrict who can do what.

How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity.

⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.

Impact: Full compromise (confidentiality, integrity and availability).

Status: Exploit probability (EPSS, 30 days): 100% — high.

How to defend:
  • Apply the vendor patch according to risk priority.
  • Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
  • Detect: turn this CVE into detection rules.

MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application

Practice it in the arsenal: WAF Bypass

100%EPSS
9.8CVSS
#24
CVE-2023-1671 Critical 9.8
Sophos Sophos Web Appliance
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution of arbitrary code.
Analysis

🟠 High — imminent exploitation

Weakness: Command Injection (CWE-77). Runs commands via unsanitized input.

How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity.

⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.

Impact: Full compromise (confidentiality, integrity and availability).

Status: Exploit probability (EPSS, 30 days): 100% — high.

How to defend:
  • Apply the vendor patch according to risk priority.
  • Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
  • Detect: turn this CVE into detection rules.

MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application · T1059 · Command and Scripting Interpreter

Practice it in the arsenal: WAF Bypass · PowerShell Decoder · Reverse Shells

100%EPSS
9.8CVSS
#25
CVE-2022-26134 Critical 9.8
Atlassian Confluence Data Center
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions…
Analysis

🟠 High — imminent exploitation

Weakness: Expression Language Injection (CWE-917). Injects expressions the server evaluates (Log4Shell-style).

How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity.

⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.

Impact: Full compromise (confidentiality, integrity and availability).

Status: Exploit probability (EPSS, 30 days): 100% — high.

How to defend:
  • Apply the vendor patch according to risk priority.
  • Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
  • Detect: turn this CVE into detection rules.

MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application · T1059 · Command and Scripting Interpreter

Practice it in the arsenal: WAF Bypass · PowerShell Decoder · Reverse Shells

100%EPSS
9.8CVSS
#26
CVE-2022-29464 Critical 9.8
n/a n/a
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such a…
Analysis

🟠 High — imminent exploitation

Weakness: Path Traversal (CWE-22). Accesses files outside the intended directory (../).

How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity.

⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.

Impact: Full compromise (confidentiality, integrity and availability).

Status: Exploit probability (EPSS, 30 days): 100% — high.

How to defend:
  • Apply the vendor patch according to risk priority.
  • Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
  • Detect: turn this CVE into detection rules.

MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application

Practice it in the arsenal: WAF Bypass

100%EPSS
9.8CVSS
#27
CVE-2022-22954 Critical 9.8
n/a VMware Workspace ONE Access and Identity Manager
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in rem…
Analysis

🟠 High — imminent exploitation

Weakness: Code Injection (CWE-94). Executes arbitrary code injected into the app.

How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity.

⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.

Impact: Full compromise (confidentiality, integrity and availability).

Status: Exploit probability (EPSS, 30 days): 100% — high.

How to defend:
  • Apply the vendor patch according to risk priority.
  • Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
  • Detect: turn this CVE into detection rules.

MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application · T1059 · Command and Scripting Interpreter

Practice it in the arsenal: WAF Bypass · PowerShell Decoder · Reverse Shells

100%EPSS
9.8CVSS
#28
CVE-2021-26084 Critical 9.8
Atlassian Confluence Server
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions…
Analysis

🟠 High — imminent exploitation

Weakness: Expression Language Injection (CWE-917). Injects expressions the server evaluates (Log4Shell-style).

How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity.

⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.

Impact: Full compromise (confidentiality, integrity and availability).

Status: Exploit probability (EPSS, 30 days): 100% — high.

How to defend:
  • Apply the vendor patch according to risk priority.
  • Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
  • Detect: turn this CVE into detection rules.

MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application · T1059 · Command and Scripting Interpreter

Practice it in the arsenal: WAF Bypass · PowerShell Decoder · Reverse Shells

100%EPSS
9.8CVSS
#29
CVE-2021-1498 Critical 9.8
Cisco Cisco HyperFlex HX Data Platform
Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerab…
Analysis

🟠 High — imminent exploitation

Weakness: OS Command Injection (CWE-78). Runs operating-system commands via unsanitized input.

How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity.

⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.

Impact: Full compromise (confidentiality, integrity and availability).

Status: Exploit probability (EPSS, 30 days): 100% — high.

How to defend:
  • Apply the vendor patch according to risk priority.
  • Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
  • Detect: turn this CVE into detection rules.

MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application · T1059 · Command and Scripting Interpreter

Practice it in the arsenal: WAF Bypass · PowerShell Decoder · Reverse Shells

100%EPSS
9.8CVSS
#30
CVE-2020-5902 Critical 9.8
n/a BIG-IP
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has a Remote Code Execution (RCE) vuln…
Analysis

🟠 High — imminent exploitation

Weakness: Path Traversal (CWE-22). Accesses files outside the intended directory (../).

How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity.

⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.

Impact: Full compromise (confidentiality, integrity and availability).

Status: Exploit probability (EPSS, 30 days): 100% — high.

How to defend:
  • Apply the vendor patch according to risk priority.
  • Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
  • Detect: turn this CVE into detection rules.

MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application

Practice it in the arsenal: WAF Bypass

100%EPSS
9.8CVSS
#31
CVE-2017-7921 Critical 9.8
n/a Hikvision Cameras
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530, DS-2CD2xx0F-I Series V5.2.0 build 140721 to V5.4.0 Build 160401, DS-2CD2xx2FWD Series V5.3.1 build 150410 to V5.4…
Analysis

🟠 High — imminent exploitation

Weakness: Improper Authentication (CWE-287). Allows impersonation or login bypass.

How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity.

⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.

Impact: Full compromise (confidentiality, integrity and availability).

Status: Exploit probability (EPSS, 30 days): 100% — high.

How to defend:
  • Apply the vendor patch according to risk priority.
  • Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
  • Detect: turn this CVE into detection rules.

MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application

Practice it in the arsenal: WAF Bypass

100%EPSS
9.8CVSS
#32
CVE-2014-6271 Critical 9.8
n/a n/a
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the…
Analysis

🟠 High — imminent exploitation

Weakness: OS Command Injection (CWE-78). Runs operating-system commands via unsanitized input.

How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity.

⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.

Impact: Full compromise (confidentiality, integrity and availability).

Status: Exploit probability (EPSS, 30 days): 100% — high.

How to defend:
  • Apply the vendor patch according to risk priority.
  • Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
  • Detect: turn this CVE into detection rules.

MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application · T1059 · Command and Scripting Interpreter

Practice it in the arsenal: WAF Bypass · PowerShell Decoder · Reverse Shells

100%EPSS
9.8CVSS
#33
CVE-2025-62593 Critical 9.4 Exploited (KEV)
ray-project ray
Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerability exploitable via Firefox and Safari. This vulnerability is due to an insufficient guar…
Analysis

🔴 Critical — actively exploited

Weakness: Code Injection (CWE-94). Executes arbitrary code injected into the app.

How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, if the victim interacts (open a file/click), and with low complexity.

Impact: Full compromise (confidentiality, integrity and availability).

Status: Active exploitation confirmed by CISA (KEV).

How to defend:
  • Patch now: it is in CISA's actively-exploited catalog (KEV), with a deadline.
  • Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
  • Awareness: the attack needs victim interaction (phishing/file).
  • Detect: turn this CVE into detection rules.

MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application · T1059 · Command and Scripting Interpreter

Practice it in the arsenal: WAF Bypass · PowerShell Decoder · Reverse Shells

62%EPSS
9.4CVSS
#34
CVE-2023-4966 Critical 9.4
Citrix NetScaler ADC
Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA  virtual server.
Analysis

🟠 High — imminent exploitation

Weakness: Buffer Overflow (CWE-119). Writes past the buffer; memory corruption or RCE.

How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity.

⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.

Impact: Confidentiality high · Integrity high · Availability partial.

Status: Exploit probability (EPSS, 30 days): 100% — high.

How to defend:
  • Apply the vendor patch according to risk priority.
  • Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
  • Detect: turn this CVE into detection rules.
100%EPSS
9.4CVSS
#35
CVE-2024-21887 Critical 9.1
Ivanti ICS
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the ap…
Analysis

🟠 High — imminent exploitation

Weakness: Command Injection (CWE-77). Runs commands via unsanitized input.

How it's exploited: Exploitable over the network (internet-reachable), with high privileges, no user interaction, and with low complexity. The flaw can pivot to other components (scope changed).

Impact: Full compromise (confidentiality, integrity and availability).

Status: Exploit probability (EPSS, 30 days): 100% — high.

How to defend:
  • Apply the vendor patch according to risk priority.
  • Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
  • Detect: turn this CVE into detection rules.

MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application · T1059 · Command and Scripting Interpreter

Practice it in the arsenal: WAF Bypass · PowerShell Decoder · Reverse Shells

100%EPSS
9.1CVSS
#36
CVE-2018-13379 Critical 9.1
Fortinet Fortinet FortiOS, FortiProxy
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web…
Analysis

🟠 High — imminent exploitation

Weakness: Path Traversal (CWE-22). Accesses files outside the intended directory (../).

How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity.

⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.

Impact: Confidentiality high · Integrity none · Availability high.

Status: Exploit probability (EPSS, 30 days): 100% — high.

How to defend:
  • Apply the vendor patch according to risk priority.
  • Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
  • Detect: turn this CVE into detection rules.

MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application

Practice it in the arsenal: WAF Bypass

100%EPSS
9.1CVSS
#37
CVE-2023-1389 High 8.8
n/a TP-Link Archer AX21 (AX1800)
TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form of the /cgi-bin/luci;stok=/locale endpoint on the web management interface. Specifically, the countr…
Analysis

🟠 High — imminent exploitation

Weakness: Command Injection (CWE-77). Runs commands via unsanitized input.

How it's exploited: Exploitable from the local network (adjacent), unauthenticated, no user interaction, and with low complexity.

Impact: Full compromise (confidentiality, integrity and availability).

Status: Exploit probability (EPSS, 30 days): 100% — high.

How to defend:
  • Apply the vendor patch according to risk priority.
  • Detect: turn this CVE into detection rules.

MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application · T1059 · Command and Scripting Interpreter

Practice it in the arsenal: WAF Bypass · PowerShell Decoder · Reverse Shells

100%EPSS
8.8CVSS
#38
CVE-2024-21893 High 8.2
Ivanti ICS
A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authen…
Analysis

🟠 High — imminent exploitation

Weakness: Server-Side Request Forgery (SSRF) (CWE-918). Forces the server to make requests to internal targets.

How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity.

⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.

Impact: Confidentiality high · Integrity partial · Availability none.

Status: Exploit probability (EPSS, 30 days): 100% — high.

How to defend:
  • Apply the vendor patch according to risk priority.
  • Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
  • Detect: turn this CVE into detection rules.

MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application

Practice it in the arsenal: WAF Bypass

100%EPSS
8.2CVSS
#39
CVE-2024-3273 High 7.3
D-Link DNS-320L
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. Affected is an unknown function of the file /cgi-bin/nas_sharing.cgi of the com…
Analysis

🟠 High — imminent exploitation

Weakness: Command Injection (CWE-77). Runs commands via unsanitized input.

How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity.

⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.

Impact: Confidentiality partial · Integrity partial · Availability partial.

Status: Exploit probability (EPSS, 30 days): 100% — high.

How to defend:
  • Apply the vendor patch according to risk priority.
  • Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
  • Detect: turn this CVE into detection rules.

MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application · T1059 · Command and Scripting Interpreter

Practice it in the arsenal: WAF Bypass · PowerShell Decoder · Reverse Shells

100%EPSS
7.3CVSS
#40
CVE-2023-0669 High 7.2
Fortra Goanywhere MFT
Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object. This issue was patched in version…
Analysis

🟠 High — imminent exploitation

Weakness: Insecure Deserialization (CWE-502). Untrusted serialized data leads to code execution.

How it's exploited: Exploitable over the network (internet-reachable), with high privileges, no user interaction, and with low complexity.

Impact: Full compromise (confidentiality, integrity and availability).

Status: Exploit probability (EPSS, 30 days): 100% — high.

How to defend:
  • Apply the vendor patch according to risk priority.
  • Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
  • Detect: turn this CVE into detection rules.

MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application · T1059 · Command and Scripting Interpreter

Practice it in the arsenal: WAF Bypass · PowerShell Decoder · Reverse Shells

100%EPSS
7.2CVSS

Sources: CISA KEV · EPSS · FIRST.org · CIRCL · NVD. Data is informational only; always verify against the vendor's official advisory.