CISA KEV — Actively Exploited Collection
Vulnerabilities confirmed to be under active exploitation in the wild.
2026-07-21 · MEDIUMWindows LegacyHive zero-day flaw gets free, unofficial patches
2026-07-21 · MEDIUMXSSer v.1.9 - "Bl4ck Swarm!" released
2026-07-21 · MEDIUMNew Release: UFONet v2.0 - "R3DST4R!"...
2026-07-21 · HIGHExploit for CVE-2026-23550 exploit
CVE-2026-23550
2026-07-21 · HIGH
fastjson-jsontype-rce-lab exploit
2026-07-21 · HIGHExploit for Out-of-bounds Write in Watchguard Fireware exploit
2026-07-21 · HIGHwp2shell-Wordpress-TOWN exploit
2026-07-21 · HIGHExploit for CVE-2026-12191 exploit
CVE-2026-12191
2026-07-21 · HIGH
Exploit for CVE-2026-44680 exploit
CVE-2026-44680
2026-07-21 · HIGH
Exploit for CVE-2026-11374 exploit
CVE-2026-11374
2026-07-20 · MEDIUM
Estée Lauder discloses data breach via Oracle E-Business flaw
2026-07-20 · MEDIUMSonicWall SMA1000 flaws exploited as zero-days to push custom malware
2026-07-20 · MEDIUMIs web penetration testing still a good career to invest in, or should I pivot while I'm still a junior?
2026-07-20 · MEDIUMOpen Directory Stages NGINX Rift and Ghost CMS Exploits Against Government and Finance Across Eleven Countries
2026-07-20 · CRITICALCritical wp2shell RCE Vulnerability Complete Coverage Including PoC and Active Exploitation Details
2026-07-20 · HIGHCritical ServiceNow code execution flaw now exploited in attacks
2026-07-20 · HIGHzero-copy-web-application-firewall exploit
2026-07-20 · HIGHExploit for Path Traversal in Jenkins exploit
2026-07-20 · HIGHeverything-claude-code exploit
2026-07-20 · HIGHappsec-audit exploit
2026-07-20 · HIGHExploit for CVE-2026-61498 exploit
CVE-2026-61498
2026-07-20 · HIGH
vibesec-static exploit
2026-07-20 · CRITICALMicrosoft SharePoint Vulnerabilities Actively Exploited for RCE, Web Shells, and IIS Key Theft
2026-07-20 · MEDIUM⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
2026-07-20 · HIGHCloudflare’s CAA flaw looks impractical for criminals — but what about actors who control the network?
CVE-2026-14440
2026-07-20 · HIGH
TP-Link-TL-WR841ND-Security-Audit exploit
2026-07-20 · HIGHExploit for CVE-2025-9951 exploit
CVE-2025-9951
2026-07-20 · HIGH
PLUGINS-DETECTOR exploit
2026-07-20 · HIGHfz-b2-rootshell exploit
2026-07-20 · CRITICALWP2Shell WordPress Vulnerabilities Exploited in the Wild
2026-07-20 · MEDIUMExploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6 Sol Ultra and $25
2026-07-20 · MEDIUMCapital One Open Sources AI-Powered ‘VulnHunter’ Security Tool
2026-07-20 · HIGHCritical ServiceNow code execution flaw now exploited in attacks
CVE-2026-6875
2026-07-19 · HIGH
CVE-2026-13445: IBM Langflow OSS 1.0.0 through 1.10.1 can allow an authenticated attacker to exploit the SaveToFile component to read an
CVE-2026-13445
2026-07-19 · MEDIUM
Recovering from a malicious APK installation on CMF Phone. HELP!
2026-07-19 · MEDIUMWhat AI cyber security platforms are spearheading the field.
2026-07-19 · HIGHBythosEngine exploit
2026-07-19 · HIGHDarkSword-PROV2 exploit
2026-07-19 · HIGHreact2shell-poc exploit
2026-07-19 · HIGHExploit for CVE-2026-46420 exploit
CVE-2026-46420
2026-07-19 · MEDIUM
I resurrected a classic 2013 Active Defense tool (Honeyports), Rewritten in Python 3 with a Web UI and Threading 👍
2026-07-19 · MEDIUMBreaking into the industry
2026-07-19 · HIGHAttackers Can Take Over WordPress Sites Using Newly Released wp2shell Exploits
2026-07-19 · HIGHAPEX_FRAMEWORK exploit
2026-07-19 · HIGHwp2shell_stock_chain exploit
2026-07-19 · HIGHExploit for CVE-2026-60137 exploit
CVE-2026-60137
2026-07-19 · HIGH
Exploit for Unrestricted Upload of File with Dangerous Type in Templaza Astroid_Framework exploit
2026-07-19 · MEDIUMFrom 50 to 703: Expanding Unit 42's Gameograf Adware Chrome Extension Campaign
2026-07-18 · MEDIUMUpdate now: 7-Zip fixes RCE flaw exploitable with malicious archives
2026-07-18 · MEDIUMWordPress Core "wp2shell" RCE flaws get public exploits, patch now
2026-07-18 · MEDIUMWhite House launches AI-driven "Gold Eagle" clearinghouse to centralize public-private vulnerability coordination
2026-07-17 · MEDIUMClickLock macOS stealer relies on a pasted Terminal command, not an exploit
2026-07-17 · MEDIUMOpenwrt pre-auth remote root exploit
2026-07-17 · HIGHCVE lookup that shows the actual fix (KB / package version / Apple train), plus a no-key API. Built partly because NVD's API keeps flaking out
CVE-2021-44228
2026-07-17 · MEDIUM
can anyone help me solve exploit development challenge.
2026-07-17 · MEDIUMIn Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint
2026-07-17 · MEDIUMNew Windows LegacyHive zero-day gives hackers admin privileges
2026-07-17 · MEDIUMIs MITRE is biased towards the historically what techniques are used rather then what's being used actively?
2026-07-17 · MEDIUMWindows Server 2022 reach end of mainstream support in 90 days
2026-07-17 · MEDIUMFresh SharePoint Vulnerability Exploited Soon After Disclosure
2026-07-17 · MEDIUMCISA urges immediate action on actively exploited Fortinet flaws
2026-07-16 · MEDIUMNew Exploitable BOLA Found in Immich (self-hosted media platform)
2026-07-16 · MEDIUMCISA orders feds to patch actively exploited Oracle flaw by Saturday
2026-07-16 · MEDIUMF5 Patches Multiple NGINX, BIG-IP Vulnerabilities
2026-07-16 · MEDIUMAI Agent for reconaissasion
2026-07-16 · MEDIUMNightmare Eclipse Drops ‘LegacyHive’ Windows Zero-Day
2026-07-16 · HIGHASUS bsitf.sys (CVE-2026-13585): Arbitrary Physical Memory Mapping via Unvalidated IOCTL
CVE-2026-13585
2026-07-16 · MEDIUM
i get stuck
2026-07-16 · MEDIUMSubject: Advisory Submission: EZ Game Booster - Cleartext Storage of Sensitive Credentials (CWE-312)
2026-07-15 · MEDIUMZoom warns of critical account takeover vulnerability
2026-07-15 · MEDIUMFile-Binding, Process-Binding, and Silo-Binding - new process impersonation techniques for EDR evasion
2026-07-15 · MEDIUMCoverage-First SOC: why domains and telemetry matter as much as threat intel
2026-07-15 · MEDIUMRuntime detection for ECS/EC2, what are people actually using?
2026-07-15 · MEDIUMCISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities
2026-07-15 · MEDIUMKQL Queries for new Chaotic Eclipse Zero day 'Legacy Hive'
2026-07-15 · MEDIUM2-Click Cursor Exploit Enables Dev Environment Takeover
2026-07-15 · MEDIUMCISA warns admins to patch actively exploited SharePoint flaws
2026-07-15 · MEDIUMProgress Confirms Zero-Day Vulnerability Behind ShareFile Disruption
2026-07-15 · MEDIUMCritical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates
2026-07-14 · HIGHSonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now
CVE-2026-15409CVE-2026-15410
2026-07-14 · MEDIUM
Microsoft Patch Tuesday July 2026 - The AI Acopolypse is Here , (Tue, Jul 14th)
2026-07-14 · MEDIUM🇨🇳 Suspected Chinese Operators Use Claude Code and DeepSeek to Breach Government Systems Across Four Countries
2026-07-14 · MEDIUMMicrosoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-Days
2026-07-14 · MEDIUMMicrosoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days
2026-07-14 · MEDIUMProgress confirms ShareFile zero-day flaw behind Storage Zone shutdown
2026-07-14 · MEDIUMLastPass, Bitwarden users targeted with fake security alerts
2026-07-14 · MEDIUMESET discovered 11 vulnerable UEFI shim bootloaders signed by Microsoft that allow attackers to bypass Secure Boot by exploiting decade-old vulnerabilities
2026-07-14 · MEDIUM7 Severe Vulnerabilities Patched in VMware Avi Load Balancer
2026-07-14 · MEDIUMYou Don't Have to Run an Exploit to Know If You're Vulnerable
2026-07-14 · MEDIUMCybersecurity projects
2026-07-14 · MEDIUMCursor IDE Auto-Executes Malicious Code in Poisoned Repos
2026-07-14 · MEDIUMNightmare Eclipse could be dropping his big promised exploit today
2026-07-14 · MEDIUMZimbra Classic Web Client has a critical stored XSS, patched in ZCS 10.1.19 (reported by Google TAG, no CVE yet, not flagged as exploited in the wild)
2026-07-13 · MEDIUMI vibed an Application Inventory Service
2026-07-13 · MEDIUMCISA warns of actively exploited RCE flaws in Joomla extensions
2026-07-13 · MEDIUMOrganizations Warned of Exploited Joomla Extension Vulnerabilities
2026-07-13 · MEDIUMPassed OSCP from Rajasthan things nobody told me about preparation
2026-07-13 · MEDIUMLarge-scale exploitation campaign targeting website content management systems (CMS)
2026-07-13 · MEDIUMParticipants Needed: Master's Research on AI Governance & the EU AI Act
2026-07-12 · MEDIUMPassive security measurement of 10,020 .it domains: CSP, cookies, TLS and email authentication
2026-07-11 · MEDIUMBloodBash Feedback Needed Before DEF CON 34 Red Team Village Talk - AD/hybrid Recon Tool
2026-07-11 · MEDIUMAustralia warns of global campaign targeting vulnerable CMS platforms
2026-07-10 · MEDIUMHow do you keep archived firewall logs usable during a threat hunt?
2026-07-10 · MEDIUMClosing the Timing Gap: Defensive Temporal Observability
2026-07-10 · MEDIUMHackers exploit critical auth bypass in Gitea Docker image
2026-07-10 · MEDIUMCISA KEV Threat Intel Orchestrator
2026-07-09 · MEDIUMMOD REQUEST: Can you ban the excessive AI posters please?
2026-07-09 · MEDIUM12 Million Impacted by Data Breach at Japanese Telco KDDI
2026-07-09 · MEDIUMMicrosoft patches RoguePlanet Defender zero-day vulnerability
2026-07-08 · MEDIUMLone Attacker Uses AI to Breach AWS Cloud Environment in 72 Hours
2026-07-08 · MEDIUMAI agents went from "cool demo" to "exploiting CVEs in 10 hours"
2026-07-08 · MEDIUMHackers exploit Roundcube flaw to spy on academic researchers
2026-07-08 · MEDIUMDrift Corpus: binary diffs of 240+ 2026 Windows kernel patches
2026-07-08 · MEDIUMCISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws
2026-07-08 · MEDIUMCISA orders feds to prioritize patching Langflow auth bypass flaw
2026-07-08 · MEDIUMChina-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware
2026-07-08 · MEDIUMUbiquiti warns of new max severity UniFi OS vulnerability
2026-07-08 · MEDIUMCISA orders feds to patch max severity ColdFusion flaw by Friday
2026-07-07 · MEDIUMSafer-dependencies: A toolkit for claude code to ensure dependencies used aren't vuln, don't use abandoned packages, implement cooldown to avoid supply chain attacks, etc...
2026-07-07 · MEDIUMChinese hackers develop LONGLEASH malware to expand ORB network
2026-07-07 · MEDIUMCybersecurity statistics of the week (June 29th - July 5th)
2026-07-07 · MEDIUMSpain arrests suspected member of pro-Russian hacktivist groups
2026-07-07 · MEDIUMSuspected Chinese espionage group used a Roundcube exploit chain to burrow into universities
2026-07-06 · HIGHJanuscape (CVE-2026-53359): 16 year old Critical Linux KVM Guest-to-Host Escape, PoC Public
CVE-2026-53359
2026-07-06 · MEDIUM
CitrixBleed-ing Again? NetScaler Vulnerability Under Attack
2026-07-06 · MEDIUMAnyone know these listening ports/vendors used?
2026-07-06 · HIGHExploitarium coverage update: CVE-2026-20896 Gitea probing confirmed + 10 new rules added
CVE-2026-20896
2026-07-06 · MEDIUM
I feel like a fraud and I don't know what to do
2026-07-06 · HIGHMax severity Adobe ColdFusion flaw now exploited in attacks
CVE-2026-48282
2026-07-06 · MEDIUM
Proof-of-Concept Exploit Released for Linux ‘Bad Epoll’ Root Access Vulnerability
2026-07-06 · MEDIUMVale a pena estudar cibersegurança para quem trabalha com manutenção de notebooks?
2026-07-06 · MEDIUMPrompt Injection Attacks Trick AI Agents Into Making Crypto Payments
2026-07-06 · MEDIUMCyber Security Analyst vs. Insider Threat / DLP Analyst?
2026-07-05 · MEDIUMBuilding an interactive career simulator for network engineers: From CCNA basics to SOC and Pentest operations.
2026-07-05 · MEDIUMDid global cybersecurity tightening make my university VPN stop working?
2026-07-05 · MEDIUMSsl cert renewal every 200days
2026-07-05 · HIGHPatch now: CISA warns of actively exploited Linux kernel zero-day (CVE-2026-43456)
CVE-2026-43456