Exploited Vulnerabilities

topic · security/exploited-vulns
DOC.
security/exploited-vulns
REV.
87 evt
DATE.
02-JUN-2026
SCOPE.
custom
§01

about

New entries in the CISA Known Exploited Vulnerabilities catalog (confirmed in-the-wild exploitation).

§02

recent events

LIVElast event 0s ago0 evt / 1h

showing 10 of 33 events in this window (87 total on topic). adjust the range or clear it with ALL.

range
iso 8601 utc
iso 8601 utc
01CVE-2026-33825: Microsoft Defender Insufficient Granularity of Access Control VulnerabilityMicrosoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally.{"cve":"CVE-2026-33825","kev":true,"cwes":["CWE-1220"],"notes":"https://msrc.mic…
EVENT. cmpxaqk8ID. cmpxaqk8g00zqoc0c4vtmm8ttSRC. key:cmpxakb6
{
  "cve": "CVE-2026-33825",
  "kev": true,
  "cwes": [
    "CWE-1220"
  ],
  "notes": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33825 ; https://nvd.nist.gov/vuln/detail/CVE-2026-33825",
  "vendor": "Microsoft",
  "product": "Defender",
  "summary": "Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally.",
  "due_date": "2026-05-06T00:00:00.000Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-33825",
    "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
  ],
  "published_at": "2026-04-22T00:00:00.000Z",
  "ransomware_use": false,
  "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "vulnerability_name": "Microsoft Defender Insufficient Granularity of Access Control Vulnerability"
}
02CVE-2026-39987: Marimo Remote Code Execution VulnerabilityMarimo contains an pre-authorization remote code execution vulnerability, allowing an unauthenticated attacked to shell access and execute arbitrary system commands.{"cve":"CVE-2026-39987","kev":true,"cwes":["CWE-306"],"notes":"https://github.co…
EVENT. cmpxaqjoID. cmpxaqjoq00zgoc0cwhnba4gzSRC. key:cmpxakb6
{
  "cve": "CVE-2026-39987",
  "kev": true,
  "cwes": [
    "CWE-306"
  ],
  "notes": "https://github.com/marimo-team/marimo/security/advisories/GHSA-2679-6mx9-h9xc ; https://nvd.nist.gov/vuln/detail/CVE-2026-39987",
  "vendor": "Marimo",
  "product": "Marimo",
  "summary": "Marimo contains an pre-authorization remote code execution vulnerability, allowing an unauthenticated attacked to shell access and execute arbitrary system commands.",
  "due_date": "2026-05-07T00:00:00.000Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-39987",
    "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
  ],
  "published_at": "2026-04-23T00:00:00.000Z",
  "ransomware_use": false,
  "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "vulnerability_name": "Marimo Remote Code Execution Vulnerability"
}
03CVE-2024-57726: SimpleHelp Missing Authorization VulnerabilitySimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges t{"cve":"CVE-2024-57726","kev":true,"cwes":["CWE-862"],"notes":"https://simple-he…
EVENT. cmpxaqj5ID. cmpxaqj5w00z6oc0ca2tuaqbsSRC. key:cmpxakb6
{
  "cve": "CVE-2024-57726",
  "kev": true,
  "cwes": [
    "CWE-862"
  ],
  "notes": "https://simple-help.com/kb---security-vulnerabilities-01-2025#security-vulnerabilities-in-simplehelp-5-5-7-and-earlier ; https://nvd.nist.gov/vuln/detail/CVE-2024-57726",
  "vendor": "SimpleHelp ",
  "product": "SimpleHelp",
  "summary": "SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.",
  "due_date": "2026-05-08T00:00:00.000Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2024-57726",
    "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
  ],
  "published_at": "2026-04-24T00:00:00.000Z",
  "ransomware_use": true,
  "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "vulnerability_name": "SimpleHelp Missing Authorization Vulnerability"
}
04CVE-2024-57728: SimpleHelp Path Traversal VulnerabilitySimpleHelp contains a path traversal vulnerability that allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited {"cve":"CVE-2024-57728","kev":true,"cwes":["CWE-22"],"notes":"https://simple-hel…
EVENT. cmpxaqimID. cmpxaqimx00ywoc0clbpmlay3SRC. key:cmpxakb6
{
  "cve": "CVE-2024-57728",
  "kev": true,
  "cwes": [
    "CWE-22"
  ],
  "notes": "https://simple-help.com/kb---security-vulnerabilities-01-2025#security-vulnerabilities-in-simplehelp-5-5-7-and-earlier ; https://nvd.nist.gov/vuln/detail/CVE-2024-57728",
  "vendor": "SimpleHelp ",
  "product": "SimpleHelp",
  "summary": "SimpleHelp contains a path traversal vulnerability that allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user.",
  "due_date": "2026-05-08T00:00:00.000Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2024-57728",
    "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
  ],
  "published_at": "2026-04-24T00:00:00.000Z",
  "ransomware_use": true,
  "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "vulnerability_name": "SimpleHelp Path Traversal Vulnerability"
}
05CVE-2024-7399: Samsung MagicINFO 9 Server Path Traversal VulnerabilitySamsung MagicINFO 9 Server contains a path traversal vulnerability that could allow an attacker to write arbitrary files as system authority.{"cve":"CVE-2024-7399","kev":true,"cwes":["CWE-22","CWE-434"],"notes":"https://s…
EVENT. cmpxaqi3ID. cmpxaqi3a00ykoc0cia2uqij5SRC. key:cmpxakb6
{
  "cve": "CVE-2024-7399",
  "kev": true,
  "cwes": [
    "CWE-22",
    "CWE-434"
  ],
  "notes": "https://security.samsungtv.com/securityUpdates ; https://nvd.nist.gov/vuln/detail/CVE-2024-7399",
  "vendor": "Samsung",
  "product": "MagicINFO 9 Server",
  "summary": "Samsung MagicINFO 9 Server contains a path traversal vulnerability that could allow an attacker to write arbitrary files as system authority.",
  "due_date": "2026-05-08T00:00:00.000Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2024-7399",
    "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
  ],
  "published_at": "2026-04-24T00:00:00.000Z",
  "ransomware_use": false,
  "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "vulnerability_name": "Samsung MagicINFO 9 Server Path Traversal Vulnerability"
}
06CVE-2025-29635: D-Link DIR-823X Command Injection VulnerabilityD-Link DIR-823X contains a command injection vulnerability that allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via t{"cve":"CVE-2025-29635","kev":true,"cwes":["CWE-77"],"notes":"https://supportann…
EVENT. cmpxaqhjID. cmpxaqhjt00y8oc0cc0c50reqSRC. key:cmpxakb6
{
  "cve": "CVE-2025-29635",
  "kev": true,
  "cwes": [
    "CWE-77"
  ],
  "notes": "https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10469 ; https://nvd.nist.gov/vuln/detail/CVE-2025-29635",
  "vendor": "D-Link",
  "product": "DIR-823X",
  "summary": "D-Link DIR-823X contains a command injection vulnerability that allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.",
  "due_date": "2026-05-08T00:00:00.000Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2025-29635",
    "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
  ],
  "published_at": "2026-04-24T00:00:00.000Z",
  "ransomware_use": false,
  "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "vulnerability_name": "D-Link DIR-823X Command Injection Vulnerability"
}
07CVE-2026-32202: Microsoft Windows Protection Mechanism Failure VulnerabilityMicrosoft Windows Shell contains a protection mechanism failure vulnerability that allows an unauthorized attacker to perform spoofing over a network.{"cve":"CVE-2026-32202","kev":true,"cwes":["CWE-693"],"notes":"https://msrc.micr…
EVENT. cmpxaqh1ID. cmpxaqh1500xwoc0c257gh9vrSRC. key:cmpxakb6
{
  "cve": "CVE-2026-32202",
  "kev": true,
  "cwes": [
    "CWE-693"
  ],
  "notes": "https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-32202 ; https://nvd.nist.gov/vuln/detail/CVE-2026-32202",
  "vendor": "Microsoft",
  "product": "Windows",
  "summary": "Microsoft Windows Shell contains a protection mechanism failure vulnerability that allows an unauthorized attacker to perform spoofing over a network.",
  "due_date": "2026-05-12T00:00:00.000Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-32202",
    "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
  ],
  "published_at": "2026-04-28T00:00:00.000Z",
  "ransomware_use": false,
  "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "vulnerability_name": "Microsoft Windows Protection Mechanism Failure Vulnerability"
}
08CVE-2024-1708: ConnectWise ScreenConnect Path Traversal VulnerabilityConnectWise ScreenConnect contains a path traversal vulnerability which could allow an attacker to execute remote code or directly impact confidential data and critical systems.{"cve":"CVE-2024-1708","kev":true,"cwes":["CWE-22"],"notes":"https://www.connect…
EVENT. cmpxaqgiID. cmpxaqgi800xkoc0c9lpiovxwSRC. key:cmpxakb6
{
  "cve": "CVE-2024-1708",
  "kev": true,
  "cwes": [
    "CWE-22"
  ],
  "notes": "https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8 ; https://nvd.nist.gov/vuln/detail/CVE-2024-1708",
  "vendor": "ConnectWise",
  "product": "ScreenConnect",
  "summary": "ConnectWise ScreenConnect contains a path traversal vulnerability which could allow an attacker to execute remote code or directly impact confidential data and critical systems.",
  "due_date": "2026-05-12T00:00:00.000Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2024-1708",
    "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
  ],
  "published_at": "2026-04-28T00:00:00.000Z",
  "ransomware_use": true,
  "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "vulnerability_name": "ConnectWise ScreenConnect Path Traversal Vulnerability"
}
09CVE-2026-41940: WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function VulnerabilityWebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized ac{"cve":"CVE-2026-41940","kev":true,"cwes":["CWE-306"],"notes":"https://support.c…
EVENT. cmpxaqfyID. cmpxaqfyr00x8oc0cl0bl2t4vSRC. key:cmpxakb6
{
  "cve": "CVE-2026-41940",
  "kev": true,
  "cwes": [
    "CWE-306"
  ],
  "notes": "https://support.cpanel.net/hc/en-us/articles/40073787579671-cPanel-WHM-Security-Update-04-28-2026 ; https://docs.cpanel.net/release-notes/release-notes/ ; https://docs.wpsquared.com/changelogs/versions/changelog/#13617 ; https://nvd.nist.gov/vuln/detail/CVE-2026-41940\"",
  "vendor": "WebPros",
  "product": "cPanel & WHM and WP2 (WordPress Squared)",
  "summary": "WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.",
  "due_date": "2026-05-03T00:00:00.000Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-41940",
    "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
  ],
  "published_at": "2026-04-30T00:00:00.000Z",
  "ransomware_use": true,
  "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "vulnerability_name": "WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability"
}
10CVE-2026-31431: Linux Kernel Incorrect Resource Transfer Between Spheres VulnerabilityLinux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation.{"cve":"CVE-2026-31431","kev":true,"cwes":["CWE-669"],"notes":"https://lore.kern…
EVENT. cmpxaqffID. cmpxaqffc00wwoc0c35fhsep9SRC. key:cmpxakb6
{
  "cve": "CVE-2026-31431",
  "kev": true,
  "cwes": [
    "CWE-669"
  ],
  "notes": "https://lore.kernel.org/linux-cve-announce/2026042214-CVE-2026-31431-3d65@gregkh/; https://xint.io/blog/copy-fail-linux-distributions#the-fix-6 ; https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/about/ ; https://nvd.nist.gov/vuln/detail/CVE-2026-31431",
  "vendor": "Linux",
  "product": "Kernel",
  "summary": "Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation.",
  "due_date": "2026-05-15T00:00:00.000Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-31431",
    "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
  ],
  "published_at": "2026-05-01T00:00:00.000Z",
  "ransomware_use": false,
  "required_action": "\"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "vulnerability_name": "Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability"
}
showing 1–10 of 33older →
§03

subscribe

three pathways carry every event on this topic. pick the one that fits your agent.

GETrss feed
any reader · no auth
https://api.callsign.sh/v1/public/channels/security/topics/exploited-vulns/feed.xml
GETjson pull
poll on your schedule · optional since/until
https://api.callsign.sh/v1/public/channels/security/topics/exploited-vulns.json
POSTwebhook
push delivery · one POST per event
log in to subscribe →
subscribe by reader, by pull loop, or by webhook above