Exploited Vulnerabilities

topic · security/exploited-vulns
DOC.
security/exploited-vulns
REV.
87 evt
DATE.
02-JUN-2026
SCOPE.
custom
§01

about

New entries in the CISA Known Exploited Vulnerabilities catalog (confirmed in-the-wild exploitation).

§02

recent events

LIVElast event 0s ago0 evt / 1h

showing 10 of 51 events in this window (87 total on topic). adjust the range or clear it with ALL.

range
iso 8601 utc
iso 8601 utc
01CVE-2026-54420: LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following VulnerabilityLiteSpeed cPanel plugin contains a UNIX symbolic link (Symlink) following vulnerability that could allow a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS.{"cve":"CVE-2026-54420","kev":true,"cwes":["CWE-61"],"notes":"https://blog.lites…
EVENT. cmqfm6j3ID. cmqfm6j3s2gt3nq0c84nxvx0rSRC. key:cmpxakb6
{
  "cve": "CVE-2026-54420",
  "kev": true,
  "cwes": [
    "CWE-61"
  ],
  "notes": "https://blog.litespeedtech.com/2026/06/01/security-update-for-litespeed-cpanel-plugin-2/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-54420",
  "vendor": "LiteSpeed",
  "product": "cPanel Plugin",
  "summary": "LiteSpeed cPanel plugin contains a UNIX symbolic link (Symlink) following vulnerability that could allow a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS.",
  "due_date": "2026-06-18T00:00:00.000Z",
  "notes_urls": [
    "https://blog.litespeedtech.com/2026/06/01/security-update-for-litespeed-cpanel-plugin-2/",
    "https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk",
    "https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-54420"
  ],
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-54420",
    "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
  ],
  "due_in_days": 2,
  "published_at": "2026-06-15T00:00:00.000Z",
  "ransomware_use": false,
  "catalog_version": "2026.06.15",
  "required_action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
  "ransomware_known": "Unknown",
  "vulnerability_name": "LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability",
  "catalog_released_at": "2026-06-15T19:00:14.579Z"
}
02CVE-2026-35273: Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function VulnerabilityOracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise{"cve":"CVE-2026-35273","kev":true,"cwes":["CWE-306"],"notes":"https://www.oracl…
EVENT. cmqb7qamID. cmqb7qamn1alxnq0cvi2vjb60SRC. key:cmpxakb6
{
  "cve": "CVE-2026-35273",
  "kev": true,
  "cwes": [
    "CWE-306"
  ],
  "notes": "https://www.oracle.com/security-alerts/alert-cve-2026-35273.html ; https://support.oracle.com/signin/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-35273",
  "vendor": "Oracle",
  "product": " PeopleSoft Enterprise PeopleTools",
  "summary": "Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise PeopleTools.",
  "due_date": "2026-06-15T00:00:00.000Z",
  "notes_urls": [
    "https://www.oracle.com/security-alerts/alert-cve-2026-35273.html",
    "https://support.oracle.com/signin/",
    "https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk",
    "https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-35273"
  ],
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-35273",
    "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
  ],
  "due_in_days": 2,
  "published_at": "2026-06-12T00:00:00.000Z",
  "ransomware_use": true,
  "catalog_version": "2026.06.12",
  "required_action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
  "ransomware_known": "Known",
  "vulnerability_name": "Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability",
  "catalog_released_at": "2026-06-12T16:46:48.054Z"
}
03CVE-2026-10520: Ivanti Sentry OS Command Injection VulnerabilityIvanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve root-level remote code execution. This vul{"cve":"CVE-2026-10520","kev":true,"cwes":["CWE-78"],"notes":"https://hub.ivanti…
EVENT. cmq9wi6fID. cmq9wi6f10xabnq0crw8x72giSRC. key:cmpxakb6
{
  "cve": "CVE-2026-10520",
  "kev": true,
  "cwes": [
    "CWE-78"
  ],
  "notes": "https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Sentry-CVE-2026-10520-CVE-2026-10523?language=en_US ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-10520",
  "vendor": "Ivanti",
  "product": "Sentry",
  "summary": "Ivanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve root-level remote code execution. This vulnerability can be successfully exploited in cases where the Sentry appliance is in an unmanaged state with its endpoints externally reachable. The use of mTLS with EPMM or restricted HTTPS access through Neurons for MDM makes interfaces inaccessible to external actors.",
  "due_date": "2026-06-14T00:00:00.000Z",
  "notes_urls": [
    "https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Sentry-CVE-2026-10520-CVE-2026-10523?language=en_US",
    "https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk",
    "https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-10520"
  ],
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-10520",
    "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
  ],
  "due_in_days": 2,
  "published_at": "2026-06-11T00:00:00.000Z",
  "ransomware_use": false,
  "catalog_version": "2026.06.11",
  "required_action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
  "ransomware_known": "Unknown",
  "vulnerability_name": "Ivanti Sentry OS Command Injection Vulnerability",
  "catalog_released_at": "2026-06-11T19:02:08.071Z"
}
04CVE-2026-20245: Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output VulnerabilityCisco Catalyst SD-WAN Manager formerly SD-WAN vManage contains an improper encoding or escaping of output vulnerability. This vulnerability could allow an authenticated, local attacker to execute arbi{"cve":"CVE-2026-20245","kev":true,"cwes":["CWE-116"],"notes":"https://sec.cloud…
EVENT. cmq71lgiID. cmq71lgir0439nq0cij4fq7c1SRC. key:cmpxakb6
{
  "cve": "CVE-2026-20245",
  "kev": true,
  "cwes": [
    "CWE-116"
  ],
  "notes": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-privesc-4uxFrdzx ; https://nvd.nist.gov/vuln/detail/CVE-2026-20245",
  "vendor": "Cisco",
  "product": "Catalyst SD-WAN Manager",
  "summary": "Cisco Catalyst SD-WAN Manager formerly SD-WAN vManage contains an improper encoding or escaping of output vulnerability. This vulnerability could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system.",
  "due_date": "2026-06-23T00:00:00.000Z",
  "notes_urls": [
    "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-privesc-4uxFrdzx",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-20245"
  ],
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-20245",
    "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
  ],
  "due_in_days": 13,
  "published_at": "2026-06-09T00:00:00.000Z",
  "ransomware_use": false,
  "catalog_version": "2026.06.09",
  "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "ransomware_known": "Unknown",
  "vulnerability_name": "Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability",
  "catalog_released_at": "2026-06-09T18:13:20.439Z"
}
05CVE-2026-7473: Arista Extensible Operating System Incomplete Comparison with Missing Factors VulnerabilityArista Extensible Operating System (EOS) contains an incomplete comparison with missing factors vulnerability when the switch incorrectly decapsulate and forwards other unexpected tunneled packet with{"cve":"CVE-2026-7473","kev":true,"cwes":["CWE-1023"],"notes":"https://www.arist…
EVENT. cmq6zhdwID. cmq6zhdwd03i7nq0cg7hqojmqSRC. key:cmpxakb6
{
  "cve": "CVE-2026-7473",
  "kev": true,
  "cwes": [
    "CWE-1023"
  ],
  "notes": "https://www.arista.com/en/support/advisories-notices/security-advisory/24005-security-advisory-0137 ; https://nvd.nist.gov/vuln/detail/CVE-2026-7473",
  "vendor": "Arista",
  "product": "Extensible Operating System",
  "summary": "Arista Extensible Operating System (EOS) contains an incomplete comparison with missing factors vulnerability when the switch incorrectly decapsulate and forwards other unexpected tunneled packet with a destination IP matching its configured decapsulation IP.",
  "due_date": "2026-06-23T00:00:00.000Z",
  "notes_urls": [
    "https://www.arista.com/en/support/advisories-notices/security-advisory/24005-security-advisory-0137",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-7473"
  ],
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-7473",
    "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
  ],
  "due_in_days": 13,
  "published_at": "2026-06-09T00:00:00.000Z",
  "ransomware_use": false,
  "catalog_version": "2026.06.09",
  "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "ransomware_known": "Unknown",
  "vulnerability_name": "Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability",
  "catalog_released_at": "2026-06-09T17:00:18.993Z"
}
06CVE-2026-11645: Google Chromium V8 Out-of-Bounds Read and Write VulnerabilityGoogle Chromium V8 out-of-bounds read and write vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect mul{"cve":"CVE-2026-11645","kev":true,"cwes":["CWE-787","CWE-125"],"notes":"https:/…
EVENT. cmq6zhdbID. cmq6zhdba03i5nq0cjt949o80SRC. key:cmpxakb6
{
  "cve": "CVE-2026-11645",
  "kev": true,
  "cwes": [
    "CWE-787",
    "CWE-125"
  ],
  "notes": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0153744567.html ; https://issues.chromium.org/issues/506689381 ; https://nvd.nist.gov/vuln/detail/CVE-2026-11645",
  "vendor": "Google",
  "product": "Chromium V8",
  "summary": "Google Chromium V8 out-of-bounds read and write vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.",
  "due_date": "2026-06-23T00:00:00.000Z",
  "notes_urls": [
    "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0153744567.html",
    "https://issues.chromium.org/issues/506689381",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-11645"
  ],
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-11645",
    "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
  ],
  "due_in_days": 13,
  "published_at": "2026-06-09T00:00:00.000Z",
  "ransomware_use": false,
  "catalog_version": "2026.06.09",
  "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "ransomware_known": "Unknown",
  "vulnerability_name": "Google Chromium V8 Out-of-Bounds Read and Write Vulnerability",
  "catalog_released_at": "2026-06-09T17:00:18.993Z"
}
07CVE-2026-50751: Check Point Security Gateway Improper Authentication VulnerabilityCheck Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a r{"cve":"CVE-2026-50751","kev":true,"cwes":["CWE-287"],"notes":"https://blog.chec…
EVENT. cmq5o5zcID. cmq5o5zce1ax3lg0cnnpwehcrSRC. key:cmpxakb6
{
  "cve": "CVE-2026-50751",
  "kev": true,
  "cwes": [
    "CWE-287"
  ],
  "notes": "https://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/ ; https://support.checkpoint.com/results/sk/sk185033?_gl=1*1wqeqhc*_gcl_au*MTI1MzE5MjI2LjE3ODA5MzQ1NTM. ; https://nvd.nist.gov/vuln/detail/CVE-2026-50751",
  "vendor": "Check Point",
  "product": "Security Gateway",
  "summary": "Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.",
  "due_date": "2026-06-11T00:00:00.000Z",
  "notes_urls": [
    "https://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/",
    "https://support.checkpoint.com/results/sk/sk185033?_gl=1*1wqeqhc*_gcl_au*MTI1MzE5MjI2LjE3ODA5MzQ1NTM",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-50751"
  ],
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-50751",
    "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
  ],
  "due_in_days": 2,
  "published_at": "2026-06-08T00:00:00.000Z",
  "ransomware_use": false,
  "catalog_version": "2026.06.08",
  "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "ransomware_known": "Unknown",
  "vulnerability_name": "Check Point Security Gateway Improper Authentication Vulnerability",
  "catalog_released_at": "2026-06-08T19:00:18.348Z"
}
08CVE-2026-42271: BerriAI LiteLLM Command Injection VulnerabilityBerriAI LiteLLM contains a command injection vulnerability that could allow any authenticated user, including holders of low-privilege internal-user keys, to run arbitrary commands on the host.{"cve":"CVE-2026-42271","kev":true,"cwes":["CWE-78","CWE-77"],"notes":"This vuln…
EVENT. cmq5iq2uID. cmq5iq2uf18lnlg0c29vfsg09SRC. key:cmpxakb6
{
  "cve": "CVE-2026-42271",
  "kev": true,
  "cwes": [
    "CWE-78",
    "CWE-77"
  ],
  "notes": "This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://github.com/BerriAI/litellm/security/advisories/GHSA-v4p8-mg3p-g94g ; https://github.com/BerriAI/litellm/releases/tag/v1.83.7-stable ; https://nvd.nist.gov/vuln/detail/CVE-2026-42271",
  "vendor": "BerriAI",
  "product": "LiteLLM",
  "summary": "BerriAI LiteLLM contains a command injection vulnerability that could allow any authenticated user, including holders of low-privilege internal-user keys, to run arbitrary commands on the host.",
  "due_date": "2026-06-22T00:00:00.000Z",
  "notes_urls": [
    "https://github.com/BerriAI/litellm/security/advisories/GHSA-v4p8-mg3p-g94g",
    "https://github.com/BerriAI/litellm/releases/tag/v1.83.7-stable",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-42271"
  ],
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-42271",
    "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
  ],
  "due_in_days": 13,
  "published_at": "2026-06-08T00:00:00.000Z",
  "ransomware_use": false,
  "catalog_version": "2026.06.08",
  "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "ransomware_known": "Unknown",
  "vulnerability_name": "BerriAI LiteLLM Command Injection Vulnerability",
  "catalog_released_at": "2026-06-08T17:02:09.138Z"
}
09CVE-2026-28318: SolarWinds Serv-U Uncontrolled Resource Consumption VulnerabilitySolarWinds Serv-U contains an uncontrolled resource consumption vulnerability that allows specially crafted POST requests using the Content-Encoding: deflate header to crash the Serv-U service without{"cve":"CVE-2026-28318","kev":true,"cwes":["CWE-400"],"notes":"https://www.solar…
EVENT. cmq18g8fID. cmq18g8fi083blg0c380lks39SRC. key:cmpxakb6
{
  "cve": "CVE-2026-28318",
  "kev": true,
  "cwes": [
    "CWE-400"
  ],
  "notes": "https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28318 ; https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_15-5-4-hotfix-1_release_notes.htm#link7 ; https://nvd.nist.gov/vuln/detail/CVE-2026-28318",
  "vendor": "SolarWinds",
  "product": "Serv-U",
  "summary": "SolarWinds Serv-U contains an uncontrolled resource consumption vulnerability that allows specially crafted POST requests using the Content-Encoding: deflate header to crash the Serv-U service without authentication.",
  "due_date": "2026-06-19T00:00:00.000Z",
  "notes_urls": [
    "https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28318",
    "https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_15-5-4-hotfix-1_release_notes.htm#link7",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-28318"
  ],
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-28318",
    "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
  ],
  "due_in_days": 13,
  "published_at": "2026-06-05T00:00:00.000Z",
  "ransomware_use": false,
  "catalog_version": "2026.06.05",
  "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "ransomware_known": "Unknown",
  "vulnerability_name": "SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability",
  "catalog_released_at": "2026-06-05T17:00:14.652Z"
}
10CVE-2026-45247: Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data VulnerabilityMirasvit Full Page Cache Warmer contains a deserialization of untrusted data vulnerability that could allow unauthenticated attackers to achieve remote code execution by supplying a crafted serialized{"cve":"CVE-2026-45247","kev":true,"cwes":["CWE-502"],"notes":"https://mirasvit.…
EVENT. cmpycx50ID. cmpycx50d0223o20cicmetaewSRC. key:cmpxakb6
{
  "cve": "CVE-2026-45247",
  "kev": true,
  "cwes": [
    "CWE-502"
  ],
  "notes": "https://mirasvit.com/package/changelog/?package=mirasvit/module-cache-warmer ; https://nvd.nist.gov/vuln/detail/CVE-2026-45247",
  "vendor": "Mirasvit",
  "product": "Mirasvit Full Page Cache Warmer",
  "summary": "Mirasvit Full Page Cache Warmer contains a deserialization of untrusted data vulnerability that could allow unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie.",
  "due_date": "2026-06-06T00:00:00.000Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-45247",
    "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
  ],
  "published_at": "2026-06-03T00:00:00.000Z",
  "ransomware_use": false,
  "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "vulnerability_name": "Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability"
}
showing 1–10 of 51older →
§03

subscribe

three pathways carry every event on this topic. pick the one that fits your agent.

GETrss feed
any reader · no auth
https://api.callsign.sh/v1/public/channels/security/topics/exploited-vulns/feed.xml
GETjson pull
poll on your schedule · optional since/until
https://api.callsign.sh/v1/public/channels/security/topics/exploited-vulns.json
POSTwebhook
push delivery · one POST per event
log in to subscribe →
subscribe by reader, by pull loop, or by webhook above