Exploited Vulnerabilities

topic · security/exploited-vulns
DOC.
security/exploited-vulns
REV.
87 evt
DATE.
02-JUN-2026
SCOPE.
custom
§01

about

New entries in the CISA Known Exploited Vulnerabilities catalog (confirmed in-the-wild exploitation).

§02

recent events

LIVElast event 0s ago0 evt / 1h

showing 10 of 15 events in this window (87 total on topic). adjust the range or clear it with ALL.

range
iso 8601 utc
iso 8601 utc
01CVE-2010-0249: Microsoft Internet Explorer Use-After-Free VulnerabilityMicrosoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object. The impacted p{"cve":"CVE-2010-0249","kev":true,"cwes":["CWE-416"],"notes":"https://learn.micr…
EVENT. cmpxaqaqID. cmpxaqaqk00tooc0cu64jvbamSRC. key:cmpxakb6
{
  "cve": "CVE-2010-0249",
  "kev": true,
  "cwes": [
    "CWE-416"
  ],
  "notes": "https://learn.microsoft.com/en-us/security-updates/SecurityAdvisories/2010/979352 ; https://nvd.nist.gov/vuln/detail/CVE-2010-0249",
  "vendor": "Microsoft",
  "product": "Internet Explorer",
  "summary": "Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.",
  "due_date": "2026-06-03T00:00:00.000Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2010-0249",
    "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
  ],
  "published_at": "2026-05-20T00:00:00.000Z",
  "ransomware_use": false,
  "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "vulnerability_name": "Microsoft Internet Explorer Use-After-Free Vulnerability"
}
02CVE-2009-3459: Adobe Acrobat and Reader Heap-Based Buffer Overflow VulnerabilityAdobe Acrobat and Reader contain a heap-based buffer overflow vulnerability which could allow remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption.{"cve":"CVE-2009-3459","kev":true,"cwes":["CWE-119"],"notes":"https://www.cisa.g…
EVENT. cmpxaqa7ID. cmpxaqa7m00tcoc0c7yasjnbuSRC. key:cmpxakb6
{
  "cve": "CVE-2009-3459",
  "kev": true,
  "cwes": [
    "CWE-119"
  ],
  "notes": "https://www.cisa.gov/news-events/alerts/2009/10/13/adobe-reader-and-acrobat-vulnerabilities ; https://web.archive.org/web/20120324170253/http://www.adobe.com/support/security/bulletins/apsb09-15.html#:~:text=CVE%2D2009%2D3459).-,NOTE%3A,-There%20are%20reports ; https://nvd.nist.gov/vuln/detail/CVE-2009-3459",
  "vendor": "Adobe",
  "product": "Acrobat and Reader",
  "summary": "Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability which could allow remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption.",
  "due_date": "2026-06-03T00:00:00.000Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2009-3459",
    "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
  ],
  "published_at": "2026-05-20T00:00:00.000Z",
  "ransomware_use": false,
  "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "vulnerability_name": "Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability"
}
03CVE-2009-1537: Microsoft DirectX NULL Byte Overwrite VulnerabilityMicrosoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitrary code via a craft{"cve":"CVE-2009-1537","kev":true,"cwes":[],"notes":"https://learn.microsoft.com…
EVENT. cmpxaq9oID. cmpxaq9oc00syoc0c9a9wwxz4SRC. key:cmpxakb6
{
  "cve": "CVE-2009-1537",
  "kev": true,
  "cwes": [],
  "notes": "https://learn.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-028 ; https://nvd.nist.gov/vuln/detail/CVE-2009-1537",
  "vendor": "Microsoft",
  "product": "DirectX",
  "summary": "Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitrary code via a crafted QuickTime media file.",
  "due_date": "2026-06-03T00:00:00.000Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2009-1537",
    "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
  ],
  "published_at": "2026-05-20T00:00:00.000Z",
  "ransomware_use": false,
  "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "vulnerability_name": "Microsoft DirectX NULL Byte Overwrite Vulnerability"
}
04CVE-2008-4250: Microsoft Windows Buffer Overflow VulnerabilityMicrosoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow duri{"cve":"CVE-2008-4250","kev":true,"cwes":["CWE-94"],"notes":"https://learn.micro…
EVENT. cmpxaq94ID. cmpxaq94200smoc0c7pn8bf06SRC. key:cmpxakb6
{
  "cve": "CVE-2008-4250",
  "kev": true,
  "cwes": [
    "CWE-94"
  ],
  "notes": "https://learn.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-067 ; https://nvd.nist.gov/vuln/detail/CVE-2008-4250",
  "vendor": "Microsoft",
  "product": "Windows",
  "summary": "Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization.",
  "due_date": "2026-06-03T00:00:00.000Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2008-4250",
    "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
  ],
  "published_at": "2026-05-20T00:00:00.000Z",
  "ransomware_use": false,
  "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "vulnerability_name": "Microsoft Windows Buffer Overflow Vulnerability"
}
05CVE-2026-34926: Trend Micro Apex One (On-Premise) Directory Traversal VulnerabilityTrend Micro Apex One (on-premise) contains a directory traversal vulnerability that could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deplo{"cve":"CVE-2026-34926","kev":true,"cwes":["CWE-23"],"notes":"https://success.tr…
EVENT. cmpxaq8kID. cmpxaq8k800s8oc0c5aee2oxwSRC. key:cmpxakb6
{
  "cve": "CVE-2026-34926",
  "kev": true,
  "cwes": [
    "CWE-23"
  ],
  "notes": "https://success.trendmicro.com/en-US/solution/KA-0023430 ; https://nvd.nist.gov/vuln/detail/CVE-2026-34926",
  "vendor": "Trend Micro",
  "product": "Apex One",
  "summary": "Trend Micro Apex One (on-premise) contains a directory traversal vulnerability that could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations.",
  "due_date": "2026-06-04T00:00:00.000Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-34926",
    "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
  ],
  "published_at": "2026-05-21T00:00:00.000Z",
  "ransomware_use": false,
  "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "vulnerability_name": "Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability"
}
06CVE-2025-34291: Langflow Origin Validation Error VulnerabilityLangflow contains an origin validation error vulnerability in which an overly permissive CORS configuration combined with a refresh token cookie configured as SameSite=None allows a malicious webpage {"cve":"CVE-2025-34291","kev":true,"cwes":["CWE-346"],"notes":"This vulnerabilit…
EVENT. cmpxaq7iID. cmpxaq7it00ryoc0cfbrvuuzoSRC. key:cmpxakb6
{
  "cve": "CVE-2025-34291",
  "kev": true,
  "cwes": [
    "CWE-346"
  ],
  "notes": "This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/langflow-ai/langflow ; https://github.com/langflow-ai/langflow/releases/tag/v1.9.3; https://github.com/langflow-ai/langflow/issues/11465#event-25774545848 ; https://nvd.nist.gov/vuln/detail/CVE-2025-34291",
  "vendor": "Langflow",
  "product": "Langflow",
  "summary": "Langflow contains an origin validation error vulnerability in which an overly permissive CORS configuration combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform cross-origin requests that include credentials and successfully call the refresh endpoint. This could allow the attacker to execute arbitrary code and achieve full system compromise via obtained tokens that permit access to authenticated endpoints.",
  "due_date": "2026-06-04T00:00:00.000Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2025-34291",
    "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
  ],
  "published_at": "2026-05-21T00:00:00.000Z",
  "ransomware_use": false,
  "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "vulnerability_name": "Langflow Origin Validation Error Vulnerability"
}
07CVE-2026-9082: Drupal Core SQL Injection VulnerabilityDrupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.{"cve":"CVE-2026-9082","kev":true,"cwes":["CWE-89"],"notes":"https://www.drupal.…
EVENT. cmpxaq6sID. cmpxaq6sj00rkoc0cvqpyo5vmSRC. key:cmpxakb6
{
  "cve": "CVE-2026-9082",
  "kev": true,
  "cwes": [
    "CWE-89"
  ],
  "notes": "https://www.drupal.org/sa-core-2026-004 ; https://nvd.nist.gov/vuln/detail/CVE-2026-9082",
  "vendor": "Drupal",
  "product": "Core",
  "summary": "Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.",
  "due_date": "2026-05-27T00:00:00.000Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-9082",
    "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
  ],
  "published_at": "2026-05-22T00:00:00.000Z",
  "ransomware_use": false,
  "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "vulnerability_name": "Drupal Core SQL Injection Vulnerability"
}
08CVE-2026-48172: LiteSpeed cPanel Plugin Privilege Escalation VulnerabilityLiteSpeed cPanel Plugin contains privilege escalation vulnerability that is exposed via the user-end cPanel plugin, which can be abused by any cPanel user account to execute arbitrary scripts with roo{"cve":"CVE-2026-48172","kev":true,"cwes":["CWE-266"],"notes":"https://blog.lite…
EVENT. cmpxaq67ID. cmpxaq67y00raoc0cytywmg7dSRC. key:cmpxakb6
{
  "cve": "CVE-2026-48172",
  "kev": true,
  "cwes": [
    "CWE-266"
  ],
  "notes": "https://blog.litespeedtech.com/2026/05/21/security-update-for-litespeed-cpanel-plugin/ ; https://nvd.nist.gov/vuln/detail/CVE-2026-48172",
  "vendor": "LiteSpeed",
  "product": "cPanel Plugin",
  "summary": "LiteSpeed cPanel Plugin contains privilege escalation vulnerability that is exposed via the user-end cPanel plugin, which can be abused by any cPanel user account to execute arbitrary scripts with root privileges.",
  "due_date": "2026-05-29T00:00:00.000Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-48172",
    "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
  ],
  "published_at": "2026-05-26T00:00:00.000Z",
  "ransomware_use": false,
  "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "vulnerability_name": "LiteSpeed cPanel Plugin Privilege Escalation Vulnerability"
}
09CVE-2026-8398: Daemon Tools Lite Embedded Malicious Code VulnerabilityDaemon Tools contains an unspecified vulnerability that has a high impact on confidentiality, integrity, and availability.{"cve":"CVE-2026-8398","kev":true,"cwes":["CWE-506"],"notes":"https://blog.daemo…
EVENT. cmpxaq5oID. cmpxaq5or00r0oc0crr4azfygSRC. key:cmpxakb6
{
  "cve": "CVE-2026-8398",
  "kev": true,
  "cwes": [
    "CWE-506"
  ],
  "notes": "https://blog.daemon-tools.cc/post/security-incident ; https://nvd.nist.gov/vuln/detail/CVE-2026-8398",
  "vendor": "Daemon",
  "product": "Daemon Tools Lite",
  "summary": "Daemon Tools contains an unspecified vulnerability that has a high impact on confidentiality, integrity, and availability.",
  "due_date": "2026-05-30T00:00:00.000Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-8398",
    "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
  ],
  "published_at": "2026-05-27T00:00:00.000Z",
  "ransomware_use": false,
  "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "vulnerability_name": "Daemon Tools Lite Embedded Malicious Code Vulnerability"
}
10CVE-2026-45321: TanStack Unspecified VulnerabilityTanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a trusted identity.{"cve":"CVE-2026-45321","kev":true,"cwes":[],"notes":"This vulnerability could a…
EVENT. cmpxaq4uID. cmpxaq4ui00qkoc0czeq75ojlSRC. key:cmpxakb6
{
  "cve": "CVE-2026-45321",
  "kev": true,
  "cwes": [],
  "notes": "This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/TanStack/router/security/advisories/GHSA-g7cv-rxg3-hmpx ; https://nvd.nist.gov/vuln/detail/CVE-2026-45321",
  "vendor": "TanStack",
  "product": "TanStack",
  "summary": "TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a trusted identity.",
  "due_date": "2026-06-10T00:00:00.000Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-45321",
    "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
  ],
  "published_at": "2026-05-27T00:00:00.000Z",
  "ransomware_use": true,
  "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "vulnerability_name": "TanStack Unspecified Vulnerability"
}
showing 1–10 of 15older →
§03

subscribe

three pathways carry every event on this topic. pick the one that fits your agent.

GETrss feed
any reader · no auth
https://api.callsign.sh/v1/public/channels/security/topics/exploited-vulns/feed.xml
GETjson pull
poll on your schedule · optional since/until
https://api.callsign.sh/v1/public/channels/security/topics/exploited-vulns.json
POSTwebhook
push delivery · one POST per event
log in to subscribe →
subscribe by reader, by pull loop, or by webhook above