Exploited Vulnerabilities
topic · security/exploited-vulns
§01
about
New entries in the CISA Known Exploited Vulnerabilities catalog (confirmed in-the-wild exploitation).
§02
recent events
LIVElast event 0s ago0 evt / 1h
showing 10 of 24 events in this window (87 total on topic). adjust the range or clear it with ALL.
range
01CVE-2026-31431: Linux Kernel Incorrect Resource Transfer Between Spheres VulnerabilityLinux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation.{"cve":"CVE-2026-31431","kev":true,"cwes":["CWE-669"],"notes":"https://lore.kern…
EVENT. cmpxaqffID. cmpxaqffc00wwoc0c35fhsep9SRC. key:cmpxakb6…
{
"cve": "CVE-2026-31431",
"kev": true,
"cwes": [
"CWE-669"
],
"notes": "https://lore.kernel.org/linux-cve-announce/2026042214-CVE-2026-31431-3d65@gregkh/; https://xint.io/blog/copy-fail-linux-distributions#the-fix-6 ; https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/about/ ; https://nvd.nist.gov/vuln/detail/CVE-2026-31431",
"vendor": "Linux",
"product": "Kernel",
"summary": "Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation.",
"due_date": "2026-05-15T00:00:00.000Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-31431",
"https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
],
"published_at": "2026-05-01T00:00:00.000Z",
"ransomware_use": false,
"required_action": "\"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"vulnerability_name": "Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability"
}02CVE-2026-0300: Palo Alto Networks PAN-OS Out-of-bounds Write VulnerabilityPalo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an unauthenticated attacker to execute arbitrar{"cve":"CVE-2026-0300","kev":true,"cwes":["CWE-787"],"notes":"https://security.p…
EVENT. cmpxaqewID. cmpxaqewr00wkoc0cdreo2dmoSRC. key:cmpxakb6…
{
"cve": "CVE-2026-0300",
"kev": true,
"cwes": [
"CWE-787"
],
"notes": "https://security.paloaltonetworks.com/CVE-2026-0300 ; https://nvd.nist.gov/vuln/detail/CVE-2026-0300",
"vendor": "Palo Alto Networks",
"product": "PAN-OS",
"summary": "Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets.",
"due_date": "2026-05-09T00:00:00.000Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-0300",
"https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
],
"published_at": "2026-05-06T00:00:00.000Z",
"ransomware_use": false,
"required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Until the vendor releases an official fix, the following workaround should be implemented: - Restrict User-ID Authentication Portal access to only trusted zones. - Disable User-ID Authentication Portal if not required. 5/13/2026: Palo Alto has released a variety of patches. If these are relevant to your environment, please apply the designated patch.",
"vulnerability_name": "Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability"
}03CVE-2026-6973: Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation VulnerabilityIvanti Endpoint Manager Mobile (EPMM) contains an improper input validation vulnerability that allows a remotely authenticated user with administrative access to achieve remote code execution.{"cve":"CVE-2026-6973","kev":true,"cwes":["CWE-20"],"notes":"https://hub.ivanti.…
EVENT. cmpxaqeeID. cmpxaqee200w8oc0c8uquz4nkSRC. key:cmpxakb6…
{
"cve": "CVE-2026-6973",
"kev": true,
"cwes": [
"CWE-20"
],
"notes": "https://hub.ivanti.com/s/article/May-2026-Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-Multiple-CVEs?language=en_US ; https://nvd.nist.gov/vuln/detail/CVE-2026-6973",
"vendor": "Ivanti",
"product": "Endpoint Manager Mobile (EPMM)",
"summary": "Ivanti Endpoint Manager Mobile (EPMM) contains an improper input validation vulnerability that allows a remotely authenticated user with administrative access to achieve remote code execution.",
"due_date": "2026-05-10T00:00:00.000Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-6973",
"https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
],
"published_at": "2026-05-07T00:00:00.000Z",
"ransomware_use": false,
"required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"vulnerability_name": "Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability"
}04CVE-2026-42208: BerriAI LiteLLM SQL Injection VulnerabilityBerriAI LiteLLM contains a SQL injection vulnerability that allows an attacker to read data from the proxy's database and potentially modify it, leading to unauthorized access to the proxy and the cre{"cve":"CVE-2026-42208","kev":true,"cwes":["CWE-89"],"notes":"https://github.com…
EVENT. cmpxaqdvID. cmpxaqdvo00vwoc0c0hwchxxzSRC. key:cmpxakb6…
{
"cve": "CVE-2026-42208",
"kev": true,
"cwes": [
"CWE-89"
],
"notes": "https://github.com/BerriAI/litellm/security/advisories/GHSA-r75f-5x8p-qvmc ; https://nvd.nist.gov/vuln/detail/CVE-2026-42208",
"vendor": "BerriAI",
"product": "LiteLLM",
"summary": "BerriAI LiteLLM contains a SQL injection vulnerability that allows an attacker to read data from the proxy's database and potentially modify it, leading to unauthorized access to the proxy and the credentials it manages.",
"due_date": "2026-05-11T00:00:00.000Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-42208",
"https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
],
"published_at": "2026-05-08T00:00:00.000Z",
"ransomware_use": false,
"required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"vulnerability_name": "BerriAI LiteLLM SQL Injection Vulnerability"
}05CVE-2026-20182: Cisco Catalyst SD-WAN Controller Authentication Bypass VulnerabilityCisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges {"cve":"CVE-2026-20182","kev":true,"cwes":["CWE-287"],"notes":"CISA Mitigation I…
EVENT. cmpxaqdcID. cmpxaqdcc00vioc0cd1xbjbuvSRC. key:cmpxakb6…
{
"cve": "CVE-2026-20182",
"kev": true,
"cwes": [
"CWE-287"
],
"notes": "CISA Mitigation Instructions: https://www.cisa.gov/news-events/directives/ed-26-03-mitigate-vulnerabilities-cisco-sd-wan-systems ; https://www.cisa.gov/news-events/directives/supplemental-direction-ed-26-03-hunt-and-hardening-guidance-cisco-sd-wan-systems ; https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW ; https://nvd.nist.gov/vuln/detail/CVE-2026-20182",
"vendor": "Cisco",
"product": "Catalyst SD-WAN",
"summary": "Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.",
"due_date": "2026-05-17T00:00:00.000Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-20182",
"https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
],
"published_at": "2026-05-14T00:00:00.000Z",
"ransomware_use": false,
"required_action": "Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlined in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.",
"vulnerability_name": "Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability"
}06CVE-2026-42897: Microsoft Exchange Server Cross-Site Scripting VulnerabilityMicrosoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditions are met, arbitrary JavaScript can be ex{"cve":"CVE-2026-42897","kev":true,"cwes":["CWE-79"],"notes":"https://msrc.micro…
EVENT. cmpxaqcsID. cmpxaqcsq00v4oc0crdcyjkxpSRC. key:cmpxakb6…
{
"cve": "CVE-2026-42897",
"kev": true,
"cwes": [
"CWE-79"
],
"notes": "https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-42897 ; https://learn.microsoft.com/en-us/exchange/plan-and-deploy/post-installation-tasks/security-best-practices/exchange-emergency-mitigation-service ; https://nvd.nist.gov/vuln/detail/CVE-2026-42897",
"vendor": "Microsoft",
"product": "Microsoft",
"summary": "Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context.",
"due_date": "2026-05-29T00:00:00.000Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-42897",
"https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
],
"published_at": "2026-05-15T00:00:00.000Z",
"ransomware_use": false,
"required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"vulnerability_name": "Microsoft Exchange Server Cross-Site Scripting Vulnerability"
}07CVE-2026-45498: Microsoft Defender Denial of Service VulnerabilityMicrosoft Defender contains an unspecified vulnerability that allows for denial of service.{"cve":"CVE-2026-45498","kev":true,"cwes":[],"notes":"https://msrc.microsoft.com…
EVENT. cmpxaqc9ID. cmpxaqc9t00uqoc0ci7ncej0cSRC. key:cmpxakb6…
{
"cve": "CVE-2026-45498",
"kev": true,
"cwes": [],
"notes": "https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-45498 ; https://nvd.nist.gov/vuln/detail/CVE-2026-45498",
"vendor": "Microsoft",
"product": "Defender",
"summary": "Microsoft Defender contains an unspecified vulnerability that allows for denial of service.",
"due_date": "2026-06-03T00:00:00.000Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-45498",
"https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
],
"published_at": "2026-05-20T00:00:00.000Z",
"ransomware_use": false,
"required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"vulnerability_name": "Microsoft Defender Denial of Service Vulnerability"
}08CVE-2026-41091: Microsoft Defender Link Following VulnerabilityMicrosoft Defender contains a link following vulnerability that allows an authorized attacker to elevate privileges locally.{"cve":"CVE-2026-41091","kev":true,"cwes":["CWE-59"],"notes":"https://msrc.micro…
EVENT. cmpxaqbrID. cmpxaqbr500ucoc0cpqqz9qh9SRC. key:cmpxakb6…
{
"cve": "CVE-2026-41091",
"kev": true,
"cwes": [
"CWE-59"
],
"notes": "https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-41091 ; https://nvd.nist.gov/vuln/detail/CVE-2026-41091",
"vendor": "Microsoft",
"product": "Defender",
"summary": "Microsoft Defender contains a link following vulnerability that allows an authorized attacker to elevate privileges locally.",
"due_date": "2026-06-03T00:00:00.000Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-41091",
"https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
],
"published_at": "2026-05-20T00:00:00.000Z",
"ransomware_use": false,
"required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"vulnerability_name": "Microsoft Defender Link Following Vulnerability"
}09CVE-2010-0806: Microsoft Internet Explorer Use-After-Free VulnerabilityMicrosoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion o{"cve":"CVE-2010-0806","kev":true,"cwes":["CWE-399"],"notes":"https://learn.micr…
EVENT. cmpxaqb8ID. cmpxaqb8q00u0oc0cynzpkw0rSRC. key:cmpxakb6…
{
"cve": "CVE-2010-0806",
"kev": true,
"cwes": [
"CWE-399"
],
"notes": "https://learn.microsoft.com/en-us/security-updates/securityadvisories/2010/981374 ; https://nvd.nist.gov/vuln/detail/CVE-2010-0806",
"vendor": "Microsoft",
"product": "Internet Explorer",
"summary": "Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.",
"due_date": "2026-06-03T00:00:00.000Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2010-0806",
"https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
],
"published_at": "2026-05-20T00:00:00.000Z",
"ransomware_use": false,
"required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"vulnerability_name": "Microsoft Internet Explorer Use-After-Free Vulnerability"
}10CVE-2010-0249: Microsoft Internet Explorer Use-After-Free VulnerabilityMicrosoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object. The impacted p{"cve":"CVE-2010-0249","kev":true,"cwes":["CWE-416"],"notes":"https://learn.micr…
EVENT. cmpxaqaqID. cmpxaqaqk00tooc0cu64jvbamSRC. key:cmpxakb6…
{
"cve": "CVE-2010-0249",
"kev": true,
"cwes": [
"CWE-416"
],
"notes": "https://learn.microsoft.com/en-us/security-updates/SecurityAdvisories/2010/979352 ; https://nvd.nist.gov/vuln/detail/CVE-2010-0249",
"vendor": "Microsoft",
"product": "Internet Explorer",
"summary": "Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.",
"due_date": "2026-06-03T00:00:00.000Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2010-0249",
"https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
],
"published_at": "2026-05-20T00:00:00.000Z",
"ransomware_use": false,
"required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"vulnerability_name": "Microsoft Internet Explorer Use-After-Free Vulnerability"
}showing 1–10 of 24older →
§03
subscribe
three pathways carry every event on this topic. pick the one that fits your agent.
GETrss feed
any reader · no authhttps://api.callsign.sh/v1/public/channels/security/topics/exploited-vulns/feed.xmlGETjson pull
poll on your schedule · optional since/untilhttps://api.callsign.sh/v1/public/channels/security/topics/exploited-vulns.jsonPOSTwebhook
push delivery · one POST per eventsubscribe by reader, by pull loop, or by webhook above