Recent Critical Vulnerabilities
The latest critical severity CVEs, sorted by publication date. 50 critical vulnerabilities tracked.
50
Critical CVEs
Oct 1
Latest Published
15
CVSS 10.0
CVE-2026-104286 Oct 1, 2026
FortiMail path traversal exploited in the wild (CVE-2026-104286) [PoC]
CVSS 9.8
CVE-2026-102427 Sep 30, 2026
Joomla CCK unauthenticated RCE (CVE-2026-102427) [PoC]
CVSS 10
CVE-2026-102489 Sep 30, 2026
Zammad session hijack RCE exploited in the wild (CVE-2026-102489)
CVSS 9.8 Zammad, Docker, Linux Kernel
CVE-2026-102490 Sep 30, 2026
Zammad local user to root, exploited (CVE-2026-102490)
CVSS 9.8 Zammad, Docker, Linux Kernel
CVE-2026-55494 Sep 30, 2026
Tugtainer agent auth bypass, no secret set (CVE-2026-55494) [PoC]
CVSS 9.8
CVE-2026-76504 Sep 30, 2026
Cisco Catalyst SD-WAN Manager auth bypass exploited (CVE-2026-76504) [PoC]
CVSS 9.8
CVE-2026-76570 Sep 30, 2026
Joomla JCTables SQLi reads and writes data (CVE-2026-76570) [PoC]
CVSS 10
CVE-2026-100752 Sep 28, 2026
Real Estate Manager SQLi lets attackers read DB (CVE-2026-100752) [PoC]
CVSS 9.3
CVE-2026-101108 Sep 28, 2026
Joomla Vehicle Manager SQLi leaks database (CVE-2026-101108) [PoC]
CVSS 9.3
CVE-2026-101110 Sep 28, 2026
Book Library SQLi leaks Joomla data, no auth (CVE-2026-101110) [PoC]
CVSS 9.3
CVE-2026-88771 Sep 27, 2026
NetScaler unauth RCE exploited in the wild (CVE-2026-88771) [PoC]
CVSS 9.5
CVE-2026-88772 Sep 27, 2026
NetScaler RCE exploited in the wild (CVE-2026-88772) [PoC]
CVSS 9.5
CVE-2026-82901 Sep 26, 2026
Contact Form 7 Addons unauth RCE (CVE-2026-82901) [PoC]
CVSS 9.8
CVE-2026-94130 Sep 26, 2026
Joomla YouTube Gallery SQLi reads database (CVE-2026-94130) [PoC]
CVSS 9.3
CVE-2026-94132 Sep 26, 2026
AcyMailing RCE, unauthenticated email upload (CVE-2026-94132) [PoC]
CVSS 9.5
CVE-2026-97163 Sep 26, 2026
Joomla UP plugin RCE, patch now (CVE-2026-97163) [PoC]
CVSS 10
CVE-2026-14281 Sep 25, 2026
WooCommerce OTP plugin grants admin, no patch (CVE-2026-14281) [PoC]
CVSS 9.8
CVE-2026-61732 Sep 24, 2026
Decepticon indirect prompt injection RCE (CVE-2026-61732) [PoC]
CVSS 10
CVE-2026-84388 Sep 22, 2026
FortiPAM Chrome Extension leaks credentials (CVE-2026-84388) [PoC]
CVSS 9.6
CVE-2026-93616 Sep 22, 2026
Check Point Management Server exploited in the wild (CVE-2026-93616) [PoC]
CVSS 9.8
CVE-2026-93952 Sep 22, 2026
VeloCloud Orchestrator unauth RCE, exploited (CVE-2026-93952)
CVSS 10
CVE-2026-94127 Sep 22, 2026
BIG-IP APM unauthenticated RCE exploited in the wild (CVE-2026-94127) [PoC]
CVSS 9.8
CVE-2026-76460 Sep 16, 2026
Cisco ISE auth bypass, exploited in wild (CVE-2026-76460) [PoC]
CVSS 10
CVE-2026-76461 Sep 14, 2026
Cisco Secure Email Gateway RCE exploited (CVE-2026-76461) [PoC]
CVSS 9.8
CVE-2026-85706 Sep 12, 2026
GitLab unauth file read, exploited (CVE-2026-85706) [PoC]
CVSS 10
CVE-2026-85102 Sep 9, 2026
Check Point Quantum VPN RCE exploited in the wild (CVE-2026-85102)
CVSS 9.8
CVE-2026-84869 Sep 8, 2026
ScreenConnect client RCE actively exploited (CVE-2026-84869)
CVSS 9.9 Connectwise Screenconnect
CVE-2026-75650 Sep 7, 2026
Adobe Commerce template RCE, exploited (CVE-2026-75650) [PoC]
CVSS 10 Adobe Commerce, Adobe Commerce B2B, Adobe Magento
CVE-2026-86218 Sep 6, 2026
N-central unauthenticated RCE, exploited (CVE-2026-86218) [PoC]
CVSS 10 N-Able N-Central
CVE-2026-86060 Sep 5, 2026
RouterOS SSH login privilege escalation, exploited (CVE-2026-86060) [PoC]
CVSS 9.2
CVE-2026-83548 Sep 1, 2026
SMA1000 SSRF exploited in the wild (CVE-2026-83548) [PoC]
CVSS 10
CVE-2026-81578 Aug 28, 2026
PaperCut MF/NG exploited, unauth config change (CVE-2026-81578) [PoC]
CVSS 9.8 Papercut Mf, Papercut Ng
CVE-2026-82078 Aug 28, 2026
PaperCut server RCE exploited in the wild (CVE-2026-82078)
CVSS 9.4 Papercut Mf, Papercut Ng
CVE-2026-82329 Aug 28, 2026
Artifactory grants admin, exploited (CVE-2026-82329) [PoC]
CVSS 9.8
CVE-2026-60004 Aug 26, 2026
Gitea unauthenticated RCE exploited in wild (CVE-2026-60004) [PoC]
CVSS 9.8
CVE-2026-69836 Aug 20, 2026
Entra ID unauthenticated RCE (CVE-2026-69836) [PoC]
CVSS 10
CVE-2026-19490 Aug 19, 2026
NetScaler ADC exploited in the wild RCE (CVE-2026-19490)
CVSS 9.3
CVE-2026-72529 Aug 19, 2026
TrueConf server RCE exploited in the wild (CVE-2026-72529)
CVSS 9.8 Trueconf Server
CVE-2026-72530 Aug 19, 2026
TrueConf server RCE exploited in the wild (CVE-2026-72530) [PoC]
CVSS 9.5 Trueconf Server
CVE-2026-64849 Aug 17, 2026
MLflow SSRF leaks cloud metadata (CVE-2026-64849) [PoC]
CVSS 9.3 Lfprojects Mlflow
CVE-2026-46670 Aug 11, 2026
YesWiki SQL injection leaks all credentials (CVE-2026-46670)
CVSS 9.8
CVE-2026-71362 Aug 11, 2026
Adobe Commerce privilege escalation exploited (CVE-2026-71362) [PoC]
CVSS 9.1 Adobe Commerce, Adobe Commerce B2B, Adobe Magento
CVE-2026-72898 Aug 10, 2026
Metabase SQL injection grants admin access (CVE-2026-72898) [PoC]
CVSS 10
CVE-2026-5430 Aug 6, 2026
JWT auth bypass exploited in the wild (CVE-2026-5430) [PoC]
CVSS 10 Wso2 Api Control Plane, Wso2 Api Manager, Wso2 Traffic Manager, Wso2 Universal Gateway
CVE-2026-65400 Aug 6, 2026
macOS Screen Sharing bypass exploited (CVE-2026-65400) [PoC]
CVSS 9.8 Apple Macos
CVE-2026-59310 Jul 30, 2026
VMware vCenter RCE exploited in wild (CVE-2026-59310)
CVSS 9.8 Vmware Vcenter Server, Vmware Telco Cloud Infrastructure, Vmware Telco Cloud Platform, Vmware Cloud Foundation, Vmware Vsphere Foundation
CVE-2026-16812 Jul 27, 2026
VCO orchestator unauth access exploited (CVE-2026-16812)
CVSS 10
CVE-2026-55579 Jul 27, 2026
Pheditor hardcoded admin RCE (CVE-2026-55579) [PoC]
CVSS 9.8
CVE-2026-63077 Jul 27, 2026
TeamCity RCE exploited in the wild (CVE-2026-63077) [PoC]
CVSS 9.8 Jetbrains Teamcity
CVE-2026-47668 Jul 23, 2026
DbGate unauthenticated RCE (CVE-2026-47668) [PoC]
CVSS 10