Recent Critical Vulnerabilities

The latest critical severity CVEs, sorted by publication date. 50 critical vulnerabilities tracked.

50
Critical CVEs
Oct 1
Latest Published
15
CVSS 10.0
CVE-2026-104286 Oct 1, 2026

FortiMail path traversal exploited in the wild (CVE-2026-104286) [PoC]

CVSS 9.8
CVE-2026-102427 Sep 30, 2026

Joomla CCK unauthenticated RCE (CVE-2026-102427) [PoC]

CVSS 10
CVE-2026-102489 Sep 30, 2026

Zammad session hijack RCE exploited in the wild (CVE-2026-102489)

CVSS 9.8 Zammad, Docker, Linux Kernel
CVE-2026-102490 Sep 30, 2026

Zammad local user to root, exploited (CVE-2026-102490)

CVSS 9.8 Zammad, Docker, Linux Kernel
CVE-2026-55494 Sep 30, 2026

Tugtainer agent auth bypass, no secret set (CVE-2026-55494) [PoC]

CVSS 9.8
CVE-2026-76504 Sep 30, 2026

Cisco Catalyst SD-WAN Manager auth bypass exploited (CVE-2026-76504) [PoC]

CVSS 9.8
CVE-2026-76570 Sep 30, 2026

Joomla JCTables SQLi reads and writes data (CVE-2026-76570) [PoC]

CVSS 10
CVE-2026-100752 Sep 28, 2026

Real Estate Manager SQLi lets attackers read DB (CVE-2026-100752) [PoC]

CVSS 9.3
CVE-2026-101108 Sep 28, 2026

Joomla Vehicle Manager SQLi leaks database (CVE-2026-101108) [PoC]

CVSS 9.3
CVE-2026-101110 Sep 28, 2026

Book Library SQLi leaks Joomla data, no auth (CVE-2026-101110) [PoC]

CVSS 9.3
CVE-2026-88771 Sep 27, 2026

NetScaler unauth RCE exploited in the wild (CVE-2026-88771) [PoC]

CVSS 9.5
CVE-2026-88772 Sep 27, 2026

NetScaler RCE exploited in the wild (CVE-2026-88772) [PoC]

CVSS 9.5
CVE-2026-82901 Sep 26, 2026

Contact Form 7 Addons unauth RCE (CVE-2026-82901) [PoC]

CVSS 9.8
CVE-2026-94130 Sep 26, 2026

Joomla YouTube Gallery SQLi reads database (CVE-2026-94130) [PoC]

CVSS 9.3
CVE-2026-94132 Sep 26, 2026

AcyMailing RCE, unauthenticated email upload (CVE-2026-94132) [PoC]

CVSS 9.5
CVE-2026-97163 Sep 26, 2026

Joomla UP plugin RCE, patch now (CVE-2026-97163) [PoC]

CVSS 10
CVE-2026-14281 Sep 25, 2026

WooCommerce OTP plugin grants admin, no patch (CVE-2026-14281) [PoC]

CVSS 9.8
CVE-2026-61732 Sep 24, 2026

Decepticon indirect prompt injection RCE (CVE-2026-61732) [PoC]

CVSS 10
CVE-2026-84388 Sep 22, 2026

FortiPAM Chrome Extension leaks credentials (CVE-2026-84388) [PoC]

CVSS 9.6
CVE-2026-93616 Sep 22, 2026

Check Point Management Server exploited in the wild (CVE-2026-93616) [PoC]

CVSS 9.8
CVE-2026-93952 Sep 22, 2026

VeloCloud Orchestrator unauth RCE, exploited (CVE-2026-93952)

CVSS 10
CVE-2026-94127 Sep 22, 2026

BIG-IP APM unauthenticated RCE exploited in the wild (CVE-2026-94127) [PoC]

CVSS 9.8
CVE-2026-76460 Sep 16, 2026

Cisco ISE auth bypass, exploited in wild (CVE-2026-76460) [PoC]

CVSS 10
CVE-2026-76461 Sep 14, 2026

Cisco Secure Email Gateway RCE exploited (CVE-2026-76461) [PoC]

CVSS 9.8
CVE-2026-85706 Sep 12, 2026

GitLab unauth file read, exploited (CVE-2026-85706) [PoC]

CVSS 10
CVE-2026-85102 Sep 9, 2026

Check Point Quantum VPN RCE exploited in the wild (CVE-2026-85102)

CVSS 9.8
CVE-2026-84869 Sep 8, 2026

ScreenConnect client RCE actively exploited (CVE-2026-84869)

CVSS 9.9 Connectwise Screenconnect
CVE-2026-75650 Sep 7, 2026

Adobe Commerce template RCE, exploited (CVE-2026-75650) [PoC]

CVSS 10 Adobe Commerce, Adobe Commerce B2B, Adobe Magento
CVE-2026-86218 Sep 6, 2026

N-central unauthenticated RCE, exploited (CVE-2026-86218) [PoC]

CVSS 10 N-Able N-Central
CVE-2026-86060 Sep 5, 2026

RouterOS SSH login privilege escalation, exploited (CVE-2026-86060) [PoC]

CVSS 9.2
CVE-2026-83548 Sep 1, 2026

SMA1000 SSRF exploited in the wild (CVE-2026-83548) [PoC]

CVSS 10
CVE-2026-81578 Aug 28, 2026

PaperCut MF/NG exploited, unauth config change (CVE-2026-81578) [PoC]

CVSS 9.8 Papercut Mf, Papercut Ng
CVE-2026-82078 Aug 28, 2026

PaperCut server RCE exploited in the wild (CVE-2026-82078)

CVSS 9.4 Papercut Mf, Papercut Ng
CVE-2026-82329 Aug 28, 2026

Artifactory grants admin, exploited (CVE-2026-82329) [PoC]

CVSS 9.8
CVE-2026-60004 Aug 26, 2026

Gitea unauthenticated RCE exploited in wild (CVE-2026-60004) [PoC]

CVSS 9.8
CVE-2026-69836 Aug 20, 2026

Entra ID unauthenticated RCE (CVE-2026-69836) [PoC]

CVSS 10
CVE-2026-19490 Aug 19, 2026

NetScaler ADC exploited in the wild RCE (CVE-2026-19490)

CVSS 9.3
CVE-2026-72529 Aug 19, 2026

TrueConf server RCE exploited in the wild (CVE-2026-72529)

CVSS 9.8 Trueconf Server
CVE-2026-72530 Aug 19, 2026

TrueConf server RCE exploited in the wild (CVE-2026-72530) [PoC]

CVSS 9.5 Trueconf Server
CVE-2026-64849 Aug 17, 2026

MLflow SSRF leaks cloud metadata (CVE-2026-64849) [PoC]

CVSS 9.3 Lfprojects Mlflow
CVE-2026-46670 Aug 11, 2026

YesWiki SQL injection leaks all credentials (CVE-2026-46670)

CVSS 9.8
CVE-2026-71362 Aug 11, 2026

Adobe Commerce privilege escalation exploited (CVE-2026-71362) [PoC]

CVSS 9.1 Adobe Commerce, Adobe Commerce B2B, Adobe Magento
CVE-2026-72898 Aug 10, 2026

Metabase SQL injection grants admin access (CVE-2026-72898) [PoC]

CVSS 10
CVE-2026-5430 Aug 6, 2026

JWT auth bypass exploited in the wild (CVE-2026-5430) [PoC]

CVSS 10 Wso2 Api Control Plane, Wso2 Api Manager, Wso2 Traffic Manager, Wso2 Universal Gateway
CVE-2026-65400 Aug 6, 2026

macOS Screen Sharing bypass exploited (CVE-2026-65400) [PoC]

CVSS 9.8 Apple Macos
CVE-2026-59310 Jul 30, 2026

VMware vCenter RCE exploited in wild (CVE-2026-59310)

CVSS 9.8 Vmware Vcenter Server, Vmware Telco Cloud Infrastructure, Vmware Telco Cloud Platform, Vmware Cloud Foundation, Vmware Vsphere Foundation
CVE-2026-16812 Jul 27, 2026

VCO orchestator unauth access exploited (CVE-2026-16812)

CVSS 10
CVE-2026-55579 Jul 27, 2026

Pheditor hardcoded admin RCE (CVE-2026-55579) [PoC]

CVSS 9.8
CVE-2026-63077 Jul 27, 2026

TeamCity RCE exploited in the wild (CVE-2026-63077) [PoC]

CVSS 9.8 Jetbrains Teamcity
CVE-2026-47668 Jul 23, 2026

DbGate unauthenticated RCE (CVE-2026-47668) [PoC]

CVSS 10
Browse all advisories

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.