📡 The most dangerous CVEs right now
A self-updating ranking that combines three signals: whether it is actively exploited (CISA KEV), the exploit probability (EPSS) and the severity (CVSS). Not "the latest published", but what actually matters to prioritize.
📬 This week in exploited CVEs, every Monday by email · 📡 Subscribe via RSS · 🧩 Embed the “CVE of the day” on your site · 🌉 Turn a CVE into detection
Analysis
🔴 Critical — actively exploited
Weakness: Insecure Deserialization (CWE-502). Untrusted serialized data leads to code execution.
How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, with high complexity.
Impact: Full compromise (confidentiality, integrity and availability).
Status: Active exploitation confirmed by CISA (KEV).
- Patch now: it is in CISA's actively-exploited catalog (KEV), with a deadline.
- Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
- Detect: turn this CVE into detection rules.
MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application · T1059 · Command and Scripting Interpreter
Practice it in the arsenal: WAF Bypass · PowerShell Decoder · Reverse Shells
Analysis
🟠 High — imminent exploitation
How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity. The flaw can pivot to other components (scope changed).
⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.
Impact: Full compromise (confidentiality, integrity and availability).
Status: Exploit probability (EPSS, 30 days): 100% — high.
- Apply the vendor patch according to risk priority.
- Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
- Detect: turn this CVE into detection rules.
Analysis
🟠 High — imminent exploitation
Weakness: Insecure Deserialization (CWE-502). Untrusted serialized data leads to code execution.
How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity. The flaw can pivot to other components (scope changed).
⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.
Impact: Full compromise (confidentiality, integrity and availability).
Status: Exploit probability (EPSS, 30 days): 100% — high.
- Apply the vendor patch according to risk priority.
- Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
- Detect: turn this CVE into detection rules.
MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application · T1059 · Command and Scripting Interpreter
Practice it in the arsenal: WAF Bypass · PowerShell Decoder · Reverse Shells
Analysis
🟠 High — imminent exploitation
Weakness: Path Traversal (CWE-22). Accesses files outside the intended directory (../).
How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity. The flaw can pivot to other components (scope changed).
⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.
Impact: Full compromise (confidentiality, integrity and availability).
Status: Exploit probability (EPSS, 30 days): 100% — high.
- Apply the vendor patch according to risk priority.
- Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
- Detect: turn this CVE into detection rules.
MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application
Practice it in the arsenal: WAF Bypass
Analysis
🟠 High — imminent exploitation
Weakness: Path Traversal (CWE-22). Accesses files outside the intended directory (../).
How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity.
⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.
Impact: Full compromise (confidentiality, integrity and availability).
Status: Exploit probability (EPSS, 30 days): 100% — high.
- Apply the vendor patch according to risk priority.
- Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
- Detect: turn this CVE into detection rules.
MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application
Practice it in the arsenal: WAF Bypass
Analysis
🟠 High — imminent exploitation
Weakness: Improper Authentication (CWE-287). Allows impersonation or login bypass.
How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity.
⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.
Impact: Full compromise (confidentiality, integrity and availability).
Status: Exploit probability (EPSS, 30 days): 100% — high.
- Apply the vendor patch according to risk priority.
- Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
- Detect: turn this CVE into detection rules.
MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application
Practice it in the arsenal: WAF Bypass
Analysis
🟠 High — imminent exploitation
Weakness: Improper Authentication (CWE-287). Allows impersonation or login bypass.
How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity.
⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.
Impact: Full compromise (confidentiality, integrity and availability).
Status: Exploit probability (EPSS, 30 days): 100% — high.
- Apply the vendor patch according to risk priority.
- Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
- Detect: turn this CVE into detection rules.
MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application
Practice it in the arsenal: WAF Bypass
Analysis
🟠 High — imminent exploitation
Weakness: Insecure Deserialization (CWE-502). Untrusted serialized data leads to code execution.
How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity.
⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.
Impact: Full compromise (confidentiality, integrity and availability).
Status: Exploit probability (EPSS, 30 days): 100% — high.
- Apply the vendor patch according to risk priority.
- Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
- Detect: turn this CVE into detection rules.
MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application · T1059 · Command and Scripting Interpreter
Practice it in the arsenal: WAF Bypass · PowerShell Decoder · Reverse Shells
Analysis
🟠 High — imminent exploitation
Weakness: Improper Access Control (CWE-284). Fails to properly restrict who can do what.
How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity.
⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.
Impact: Full compromise (confidentiality, integrity and availability).
Status: Exploit probability (EPSS, 30 days): 100% — high.
- Apply the vendor patch according to risk priority.
- Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
- Detect: turn this CVE into detection rules.
MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application
Practice it in the arsenal: WAF Bypass
Analysis
🟠 High — imminent exploitation
Weakness: Command Injection (CWE-77). Runs commands via unsanitized input.
How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity.
⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.
Impact: Full compromise (confidentiality, integrity and availability).
Status: Exploit probability (EPSS, 30 days): 100% — high.
- Apply the vendor patch according to risk priority.
- Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
- Detect: turn this CVE into detection rules.
MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application · T1059 · Command and Scripting Interpreter
Practice it in the arsenal: WAF Bypass · PowerShell Decoder · Reverse Shells
Analysis
🟠 High — imminent exploitation
Weakness: Expression Language Injection (CWE-917). Injects expressions the server evaluates (Log4Shell-style).
How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity.
⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.
Impact: Full compromise (confidentiality, integrity and availability).
Status: Exploit probability (EPSS, 30 days): 100% — high.
- Apply the vendor patch according to risk priority.
- Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
- Detect: turn this CVE into detection rules.
MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application · T1059 · Command and Scripting Interpreter
Practice it in the arsenal: WAF Bypass · PowerShell Decoder · Reverse Shells
Analysis
🟠 High — imminent exploitation
Weakness: Path Traversal (CWE-22). Accesses files outside the intended directory (../).
How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity.
⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.
Impact: Full compromise (confidentiality, integrity and availability).
Status: Exploit probability (EPSS, 30 days): 100% — high.
- Apply the vendor patch according to risk priority.
- Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
- Detect: turn this CVE into detection rules.
MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application
Practice it in the arsenal: WAF Bypass
Analysis
🟠 High — imminent exploitation
Weakness: Path Traversal (CWE-22). Accesses files outside the intended directory (../).
How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity.
⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.
Impact: Full compromise (confidentiality, integrity and availability).
Status: Exploit probability (EPSS, 30 days): 100% — high.
- Apply the vendor patch according to risk priority.
- Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
- Detect: turn this CVE into detection rules.
MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application
Practice it in the arsenal: WAF Bypass
Analysis
🟠 High — imminent exploitation
Weakness: Path Traversal (CWE-22). Accesses files outside the intended directory (../).
How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity.
⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.
Impact: Full compromise (confidentiality, integrity and availability).
Status: Exploit probability (EPSS, 30 days): 100% — high.
- Apply the vendor patch according to risk priority.
- Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
- Detect: turn this CVE into detection rules.
MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application
Practice it in the arsenal: WAF Bypass
Analysis
🟠 High — imminent exploitation
Weakness: Expression Language Injection (CWE-917). Injects expressions the server evaluates (Log4Shell-style).
How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity.
⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.
Impact: Full compromise (confidentiality, integrity and availability).
Status: Exploit probability (EPSS, 30 days): 100% — high.
- Apply the vendor patch according to risk priority.
- Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
- Detect: turn this CVE into detection rules.
MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application · T1059 · Command and Scripting Interpreter
Practice it in the arsenal: WAF Bypass · PowerShell Decoder · Reverse Shells
Analysis
🟠 High — imminent exploitation
Weakness: Insecure Deserialization (CWE-502). Untrusted serialized data leads to code execution.
How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity.
⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.
Impact: Full compromise (confidentiality, integrity and availability).
Status: Exploit probability (EPSS, 30 days): 100% — high.
- Apply the vendor patch according to risk priority.
- Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
- Detect: turn this CVE into detection rules.
MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application · T1059 · Command and Scripting Interpreter
Practice it in the arsenal: WAF Bypass · PowerShell Decoder · Reverse Shells
Analysis
🟠 High — imminent exploitation
Weakness: Server-Side Request Forgery (SSRF) (CWE-918). Forces the server to make requests to internal targets.
How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity.
⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.
Impact: Full compromise (confidentiality, integrity and availability).
Status: Exploit probability (EPSS, 30 days): 100% — high.
- Apply the vendor patch according to risk priority.
- Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
- Detect: turn this CVE into detection rules.
MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application
Practice it in the arsenal: WAF Bypass
Analysis
🟠 High — imminent exploitation
Weakness: OS Command Injection (CWE-78). Runs operating-system commands via unsanitized input.
How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity.
⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.
Impact: Full compromise (confidentiality, integrity and availability).
Status: Exploit probability (EPSS, 30 days): 100% — high.
- Apply the vendor patch according to risk priority.
- Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
- Detect: turn this CVE into detection rules.
MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application · T1059 · Command and Scripting Interpreter
Practice it in the arsenal: WAF Bypass · PowerShell Decoder · Reverse Shells
Analysis
🟠 High — imminent exploitation
Weakness: Path Traversal (CWE-22). Accesses files outside the intended directory (../).
How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity.
⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.
Impact: Full compromise (confidentiality, integrity and availability).
Status: Exploit probability (EPSS, 30 days): 100% — high.
- Apply the vendor patch according to risk priority.
- Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
- Detect: turn this CVE into detection rules.
MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application
Practice it in the arsenal: WAF Bypass
Analysis
🟠 High — imminent exploitation
Weakness: Path Traversal (CWE-22). Accesses files outside the intended directory (../).
How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity.
⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.
Impact: Full compromise (confidentiality, integrity and availability).
Status: Exploit probability (EPSS, 30 days): 100% — high.
- Apply the vendor patch according to risk priority.
- Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
- Detect: turn this CVE into detection rules.
MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application
Practice it in the arsenal: WAF Bypass
Analysis
🟠 High — imminent exploitation
Weakness: Use After Free (CWE-416). Uses freed memory; can lead to code execution.
How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity.
⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.
Impact: Full compromise (confidentiality, integrity and availability).
Status: Exploit probability (EPSS, 30 days): 100% — high.
- Apply the vendor patch according to risk priority.
- Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
- Detect: turn this CVE into detection rules.
Analysis
🟠 High — imminent exploitation
Weakness: Code Injection (CWE-94). Executes arbitrary code injected into the app.
How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity.
⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.
Impact: Full compromise (confidentiality, integrity and availability).
Status: Exploit probability (EPSS, 30 days): 100% — high.
- Apply the vendor patch according to risk priority.
- Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
- Detect: turn this CVE into detection rules.
MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application · T1059 · Command and Scripting Interpreter
Practice it in the arsenal: WAF Bypass · PowerShell Decoder · Reverse Shells
Analysis
🟠 High — imminent exploitation
Weakness: Improper Authentication (CWE-287). Allows impersonation or login bypass.
How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity.
⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.
Impact: Full compromise (confidentiality, integrity and availability).
Status: Exploit probability (EPSS, 30 days): 100% — high.
- Apply the vendor patch according to risk priority.
- Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
- Detect: turn this CVE into detection rules.
MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application
Practice it in the arsenal: WAF Bypass
Analysis
🟠 High — imminent exploitation
Weakness: OS Command Injection (CWE-78). Runs operating-system commands via unsanitized input.
How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity.
⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.
Impact: Full compromise (confidentiality, integrity and availability).
Status: Exploit probability (EPSS, 30 days): 100% — high.
- Apply the vendor patch according to risk priority.
- Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
- Detect: turn this CVE into detection rules.
MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application · T1059 · Command and Scripting Interpreter
Practice it in the arsenal: WAF Bypass · PowerShell Decoder · Reverse Shells
Analysis
🟠 High — imminent exploitation
Weakness: CWE-288.
How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity.
⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.
Impact: Full compromise (confidentiality, integrity and availability).
Status: Exploit probability (EPSS, 30 days): 100% — high.
- Apply the vendor patch according to risk priority.
- Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
- Detect: turn this CVE into detection rules.
Analysis
🟠 High — imminent exploitation
Weakness: Buffer Overflow (CWE-119). Writes past the buffer; memory corruption or RCE.
How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity.
⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.
Impact: Confidentiality high · Integrity high · Availability partial.
Status: Exploit probability (EPSS, 30 days): 100% — high.
- Apply the vendor patch according to risk priority.
- Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
- Detect: turn this CVE into detection rules.
Analysis
🟠 High — imminent exploitation
Weakness: Command Injection (CWE-77). Runs commands via unsanitized input.
How it's exploited: Exploitable over the network (internet-reachable), with high privileges, no user interaction, and with low complexity. The flaw can pivot to other components (scope changed).
Impact: Full compromise (confidentiality, integrity and availability).
Status: Exploit probability (EPSS, 30 days): 100% — high.
- Apply the vendor patch according to risk priority.
- Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
- Detect: turn this CVE into detection rules.
MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application · T1059 · Command and Scripting Interpreter
Practice it in the arsenal: WAF Bypass · PowerShell Decoder · Reverse Shells
Analysis
🟠 High — imminent exploitation
How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity.
⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.
Impact: Confidentiality high · Integrity high · Availability none.
Status: Exploit probability (EPSS, 30 days): 100% — high.
- Apply the vendor patch according to risk priority.
- Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
- Detect: turn this CVE into detection rules.
Analysis
🟠 High — imminent exploitation
Weakness: Path Traversal (CWE-22). Accesses files outside the intended directory (../).
How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity.
⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.
Impact: Confidentiality high · Integrity none · Availability high.
Status: Exploit probability (EPSS, 30 days): 100% — high.
- Apply the vendor patch according to risk priority.
- Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
- Detect: turn this CVE into detection rules.
MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application
Practice it in the arsenal: WAF Bypass
Analysis
🟠 High — imminent exploitation
Weakness: Server-Side Request Forgery (SSRF) (CWE-918). Forces the server to make requests to internal targets.
How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, with high complexity. The flaw can pivot to other components (scope changed).
Impact: Full compromise (confidentiality, integrity and availability).
Status: Exploit probability (EPSS, 30 days): 100% — high.
- Apply the vendor patch according to risk priority.
- Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
- Detect: turn this CVE into detection rules.
MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application
Practice it in the arsenal: WAF Bypass
Analysis
🔴 Critical — actively exploited
Weakness: Improper Input Validation (CWE-20). Fails to validate input before using it.
How it's exploited: Exploitable over the network (internet-reachable), with low privileges, no user interaction, and with low complexity.
Impact: Full compromise (confidentiality, integrity and availability).
Status: Active exploitation confirmed by CISA (KEV).
- Patch now: it is in CISA's actively-exploited catalog (KEV), with a deadline.
- Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
- Detect: turn this CVE into detection rules.
Analysis
🟠 High — imminent exploitation
Weakness: Command Injection (CWE-77). Runs commands via unsanitized input.
How it's exploited: Exploitable from the local network (adjacent), unauthenticated, no user interaction, and with low complexity.
Impact: Full compromise (confidentiality, integrity and availability).
Status: Exploit probability (EPSS, 30 days): 100% — high.
- Apply the vendor patch according to risk priority.
- Detect: turn this CVE into detection rules.
MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application · T1059 · Command and Scripting Interpreter
Practice it in the arsenal: WAF Bypass · PowerShell Decoder · Reverse Shells
Analysis
🔴 Critical — actively exploited
How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity.
⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.
Impact: Confidentiality high · Integrity none · Availability none.
Status: Active exploitation confirmed by CISA (KEV).
- Patch now: it is in CISA's actively-exploited catalog (KEV), with a deadline.
- Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
- Detect: turn this CVE into detection rules.
Analysis
🟠 High — imminent exploitation
Weakness: Path Traversal (CWE-22). Accesses files outside the intended directory (../).
How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity.
⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.
Impact: Confidentiality high · Integrity partial · Availability partial.
Status: Exploit probability (EPSS, 30 days): 100% — high.
- Apply the vendor patch according to risk priority.
- Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
- Detect: turn this CVE into detection rules.
MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application
Practice it in the arsenal: WAF Bypass
Analysis
🟠 High — imminent exploitation
Weakness: Server-Side Request Forgery (SSRF) (CWE-918). Forces the server to make requests to internal targets.
How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity.
⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.
Impact: Confidentiality high · Integrity partial · Availability none.
Status: Exploit probability (EPSS, 30 days): 100% — high.
- Apply the vendor patch according to risk priority.
- Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
- Detect: turn this CVE into detection rules.
MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application
Practice it in the arsenal: WAF Bypass
Analysis
🟠 High — imminent exploitation
Weakness: Uncontrolled Resource Consumption (CWE-400). Exhausts system resources (denial of service).
How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity.
⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.
Impact: Confidentiality none · Integrity none · Availability high.
Status: Exploit probability (EPSS, 30 days): 100% — high.
- Apply the vendor patch according to risk priority.
- Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
- Detect: turn this CVE into detection rules.
Analysis
🟠 High — imminent exploitation
Weakness: CWE-23.
How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity.
⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.
Impact: Confidentiality partial · Integrity partial · Availability partial.
Status: Exploit probability (EPSS, 30 days): 100% — high.
- Apply the vendor patch according to risk priority.
- Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
- Detect: turn this CVE into detection rules.
Analysis
🟠 High — imminent exploitation
Weakness: Insecure Deserialization (CWE-502). Untrusted serialized data leads to code execution.
How it's exploited: Exploitable over the network (internet-reachable), with high privileges, no user interaction, and with low complexity.
Impact: Full compromise (confidentiality, integrity and availability).
Status: Exploit probability (EPSS, 30 days): 100% — high.
- Apply the vendor patch according to risk priority.
- Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
- Detect: turn this CVE into detection rules.
MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application · T1059 · Command and Scripting Interpreter
Practice it in the arsenal: WAF Bypass · PowerShell Decoder · Reverse Shells
Analysis
🟠 High — imminent exploitation
Weakness: Improper Input Validation (CWE-20). Fails to validate input before using it.
How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, with high complexity.
Impact: Confidentiality none · Integrity none · Availability high.
Status: Exploit probability (EPSS, 30 days): 100% — high.
- Apply the vendor patch according to risk priority.
- Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
- Detect: turn this CVE into detection rules.
Analysis
🟠 High — imminent exploitation
Weakness: Path Traversal (CWE-22). Accesses files outside the intended directory (../).
How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity.
⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.
Impact: Confidentiality partial · Integrity none · Availability none.
Status: Exploit probability (EPSS, 30 days): 100% — high.
- Apply the vendor patch according to risk priority.
- Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
- Detect: turn this CVE into detection rules.
MITRE ATT&CK technique: T1190 · Exploit Public-Facing Application
Practice it in the arsenal: WAF Bypass
No CVEs match this filter.
Sources: CISA KEV · EPSS · FIRST.org · CIRCL · NVD. Data is informational only; always verify against the vendor's official advisory.