Trending vulnerabilities

Trending 25
Critical 17
In KEV 8
Peak EPSS 99%
Posts 150
#1 CVE-2026-76461
CRITICAL · 9.8 KEV
hype ACTIVE HACK · 92 hack

Confirmed in-the-wild exploitation, KEV-listed same day as disclosure, urgent vendor patching, multi-region media coverage.

What: Cisco AsyncOS for Secure Email Gateway suffers a critical (CVSS 9.8) unauthenticated remote code execution flaw via malformed email parsing, allowing root command execution.

Why it matters: KEV-listed on 2026-09-14; Cisco confirmed active exploitation in the wild before disclosure. No workaround available; patches released same day. Global security orgs (JPCERT, CISA) flagged as high-risk. This is a zero-day with confirmed threat actor use.

Where it's seen: International media coverage (Japanese, Dutch, English), security digest aggregators, and vendor advisory citations across social platforms. Defenders are being urged to patch immediately.

score 16 47 posts
#2 CVE-2026-85706
CRITICAL · 10.0 KEV
hype ACTIVE HACK · 92 hack

KEV-listed, confirmed in-the-wild probes, patches released, CISA warning.

What: Unauthenticated path traversal in GitLab CE/EE repository commits API (versions 18.7–19.3.1) enabling arbitrary file read; CVSS 10.0 CRITICAL.

Why it matters: KEV-listed as of 2026-09-11; CISA confirmed active exploitation within hours of disclosure. Patches released (19.1.8, 19.2.6, 19.3.2). In-the-wild reconnaissance probes observed immediately post-patch. No authentication required; affects all self-managed deployments in vulnerable ranges.

Where it's seen: Security news outlets and threat intel platforms reporting confirmed exploitation; CISA advisory; vendor patch releases; defenders triaging urgently across social channels.

score 13 23 posts
#3 CVE-2026-39364
HIGH · 7.5
hype LIKELY HACK · 74 hack

F5 Labs telemetry and mass scanning claims credible, but KEV absent; PoC unclear.

What: Vite dev server (v7.1.0–7.3.1, v8.0.0–8.0.4) file-access bypass via query parameters (?raw, ?import&raw, etc.) bypasses server.fs.deny protections, exposing .env, .crt, and sensitive config files. CVSS 7.5 HIGH.

Why it matters: Mass scanning observed by F5 Labs (32,000+ events) targeting exposed dev servers to harvest AWS/Azure credentials and infrastructure secrets. Patches available (7.3.2, 8.0.5). Not yet KEV-listed but active in-the-wild exploitation reported with high-engagement social signal from security researchers and vendors.

Where it's seen: Multiple Bluesky posts citing F5 Labs telemetry on mass scanning campaigns, credential harvesting tactics, and urgent patching guidance. Coverage emphasizes cloud credential theft and exposed port 5173 scanning.

score 5 6 posts

Also trending

  1. 4 CVE-2026-27540 CRITICAL · 9.0 score 5 · 5 posts
    hype LIKELY HACK · 78 hack

    What: Unrestricted file upload vulnerability in WooCommerce Wholesale Lead Capture plugin (≤2.0.3.1) allows unauthenticated PHP webshell uploads on WordPress sites. CVSS 9.0 CRITICAL.

    Why it matters: Wordfence reports 100k+ active exploitation attempts blocked; patch released (v2.0.3.2); mass scanning and PHP backdoor deployment observed in the wild. Not yet KEV-listed but defender triage and vendor patching underway confirm real-world weaponization.

    Where it's seen: Security vendor (Wordfence) telemetry, urgent patch advisories, multi-language social amplification calling for immediate updates, practitioner warning threads.

  2. 5 CVE-2026-51990 score 5 · 5 posts
    hype LIKELY HACK · 78 hack

    What: Remote code execution in Tencent Sogou Input Method for Windows via malicious sgbiz: URI links; enables one-click RCE and GrayRabbit backdoor deployment.

    Why it matters: Active in-the-wild exploitation by UNC3569 (China-aligned espionage group) confirmed across multiple threat intelligence sources. Vendor (Tencent) has patched in version 16.3. No KEV listing yet, but real-world weaponization and defender remediation guidance present. Social chatter consistently cites threat actor activity and malware payload.

    Where it's seen: Threat intelligence reports (SecurityCyber, BleepingComputer, TheHackerNews), defender alerts recommending client isolation, vulnerability aggregator posts tracking GrayRabbit deployment chain.

  3. 6 CVE-2026-89308 score 4 · 4 posts
    hype MIXED · 42 hack

    What: Unauthenticated OS command injection in TrxTimeAttendance ping.php endpoint (versions 1.0.5–1.9.5) enabling remote code execution. CVSS reported as 9.3 in social posts, though NVD lists n/a.

    Why it matters: Published today with immediate social amplification flagging RCE risk in widely-deployed time-attendance software. No KEV listing yet; no confirmed public PoC or active exploitation reported. Chatter emphasizes "patch or restrict access now" but lacks defender triage feedback or vendor advisory confirmation.

    Where it's seen: Same-day coordinated posts across Bluesky citing CVSS 9.3 and urging immediate mitigation. References to threat intelligence aggregators (stackflag, stemshop, offseq, radar) indicate rapid feed syndication rather than organic discovery.

  4. 7 CVE-2026-39987 CRITICAL · 9.8 KEV EPSS 99% score 4 · 4 posts
    hype ACTIVE HACK · 92 hack

    What: Pre-auth remote code execution in marimo (Python reactive notebook) via unauthenticated WebSocket endpoint /terminal/ws; CVSS 9.8 CRITICAL, EPSS 0.82 (99th percentile).

    Why it matters: KEV-listed 2026-04-23. Confirmed in-the-wild exploitation within 10 hours of public disclosure (2026-04-09). Multiple threat actors observed chaining RCE with LLM-driven post-exploitation (credential theft, database exfiltration, lateral movement to AWS/SSH). Marimo 0.23.0+ required; patch window critically narrow.

    Where it's seen: Infosec community posts document active attacks with telemetry (Sysdig), C2 traffic established within 14 hours. Posts reference real-world compromises (PostgreSQL data loss, AWS Secrets access). No apparent speculation or FUD — chatter tied to defender observations and incident reporting.

  5. 8 CVE-2023-54398 CRITICAL · 9.8 score 4 · 3 posts
    hype LIKELY HACK · 78 hack

    What: Unauthenticated Java deserialization RCE in Yonyou U8 Cloud FileManageServlet (CVSS 9.8 CRITICAL). Remote attackers bypass authentication to execute arbitrary OS commands via malicious serialized payloads.

    Why it matters: Exploitation observed in the wild by Shadowserver Foundation on 2025-02-13. CVSS 9.8 critical severity, unauthenticated attack surface, and confirmed real-world detection signal indicate active weaponization. No KEV-listing yet, but ground-truth exploitation evidence exists.

    Where it's seen: Social media aggregating vulnerability details and linking to exploit resources; chatter emphasizes critical rating and public exploit availability; Shadowserver's earlier detection validates the threat.

  6. 9 CVE-2026-90711 CRITICAL · 9.1 score 4 · 4 posts
    hype MIXED · 42 hack

    What: proxy-addr Node.js module (versions 1.1.0–2.0.7) misinterprets IPv4-mapped IPv6 CIDR notation, trusting all IPv4 addresses instead of intended subnets; CVSS 9.1 CRITICAL.

    Why it matters: Regression defeats IP-based access control, rate limiting, geolocation, and audit logging via forged X-Forwarded-For headers. Fix available in 2.0.8. No KEV listing or public PoC reported yet, but advisory and patched release published same day; widely used in Express.js ecosystems.

    Where it's seen: Aggregator alerts (stemshop, hackerwire, stackflag) and GitHub release notifications dominating chatter; no active exploitation chatter, mostly vendor advisory amplification.

  7. 10 CVE-2026-91001 CRITICAL · 9.9 score 4 · 4 posts
    hype LIKELY HACK · 78 hack

    What: Stack-based buffer overflow in D-Link DI-8400 16.07 DDNS configuration (CVE-2026-91001, CVSS 9.9 CRITICAL) allowing remote code execution via manipulation of multiple DDNS parameters.

    Why it matters: Public exploit released same day as CVE publication; CVSS 9.9 indicates unauthenticated remote RCE on widely-deployed router hardware. Not yet KEV-listed but exploitation barrier is eliminated. Defenders managing D-Link deployments must triage immediately.

    Where it's seen: Threat intelligence feeds and security media amplifying advisory within hours of publication; multiple posts emphasizing public exploit availability and criticality; limited but direct defender guidance (access restriction recommendations appearing).

  8. 11 CVE-2024-53920 HIGH · 7.8 score 4 · 3 posts
    hype MOSTLY HYPE · 28 hack

    What: GNU Emacs before 30.1 allows arbitrary code execution when elisp-completion-at-point or on-the-fly byte-compile diagnosis is invoked on untrusted Lisp source code via unsafe macro expansion (CVSS 7.8 HIGH).

    Why it matters: Requires user interaction (code completion or diagnostic opt-in on untrusted code), so real-world risk depends on developer workflows. Not KEV-listed. No public PoC or in-the-wild exploitation reported. Chatter is limited to NixOS package patches.

    Where it's seen: Three NixOS GitHub pull requests backporting the patch across multiple Emacs versions; no broader security discussion, vendor advisories, or researcher PoCs visible.

  9. 12 CVE-2026-63696 CRITICAL · 9.1 score 4 · 3 posts
    hype MOSTLY HYPE · 28 hack

    What: Dell SmartFabric OS10 versions before 10.6.1.3 fail to verify software update integrity, allowing remote code execution. CVSS 9.1 CRITICAL.

    Why it matters: Requires high privilege and remote access (not unauthenticated). Not KEV-listed. No public PoC or in-the-wild exploitation reported yet. No urgent vendor patching signals in metadata. Social chatter amplifies CVSS score but lacks defender triage or exploitation evidence.

    Where it's seen: Generic social amplification of CVE metadata across Bluesky; posts link to aggregator sites but cite no incident data, working exploit, or defender activity.

  10. 13 CVE-2026-63695 CRITICAL · 9.8 score 4 · 3 posts
    hype MIXED · 62 hack

    What: Session fixation vulnerability in Dell SmartFabric OS10 prior to 10.6.1.3 allowing unauthenticated remote session theft (CVSS 9.8 CRITICAL).

    Why it matters: Dell has released a patch same-day (10.6.1.3); CRITICAL severity and unauthenticated remote access vector drive urgent triage. No KEV listing yet or public PoC observed in posts, but patch availability and vendor advisory confirm real vulnerability requiring immediate deployment.

    Where it's seen: Social posts reference Dell's patched version and urge SmartFabric OS10 switch updates; chatter emphasizes severity and remediation path rather than exploitation details or working exploits.

  11. 14 CVE-2026-91998 CRITICAL · 9.9 score 4 · 3 posts
    hype MIXED · 42 hack

    What: Casdoor ≤4.4.0 authorization bypass in /api/mcp endpoint allows attackers with any app's clientId/clientSecret to gain unrestricted cross-organization user admin access (CVSS 9.9 CRITICAL).

    Why it matters: Published today with CVSS 9.9; enables user enumeration, password salt extraction, admin account creation, and deletion across all orgs. Not yet KEV-listed but severity and ease of exploitation (valid credentials only) warrant immediate triage by Casdoor deployments.

    Where it's seen: Same-day social amplification on Bluesky with CVE aggregators resharing NVD data; no public PoC confirmed, no vendor patch announcement yet visible, no defender incident reports.

  12. 15 CVE-2026-91995 CRITICAL · 9.1 score 4 · 3 posts
    hype MIXED · 58 hack

    What: Authentication bypass in pig (pig-mesh) <4.1.0 allows remote attackers to reset any account password, including admin, via the /register/password endpoint by submitting any value as the current password. CVSS 9.1 CRITICAL.

    Why it matters: Same-day disclosure (published 2026-09-15); critical CVSS score; direct path to full administrative takeover. No KEV listing yet, no public PoC confirmed in posts, but vulnerability is trivial to exploit and immediately actionable for attackers. Defenders should assume rapid weaponization.

    Where it's seen: Early social chatter on Bluesky summarizing NVD details; no vendor advisory or patch confirmation visible yet; no working PoC drops reported; mostly awareness/alert posts linking to CVE aggregators.

  13. 16 CVE-2026-59310 CRITICAL · 9.8 KEV score 4 · 3 posts
    hype MIXED · 58 hack

    What: Directory traversal in VMware vCenter Syslog Server allowing unauthenticated remote code execution (CVSS 9.8 CRITICAL).

    Why it matters: Social chatter reports active exploitation campaigns deploying reverse SSH tools for persistence. Multiple security news outlets covering in-the-wild attacks. VMware has patched (advisory issued 2026-07-30). However, CVE is NOT yet on CISA KEV list, and EPSS remains extremely low (0.63 percentile), suggesting limited observed exploitation despite claimed global campaign reports.

    Where it's seen: Security blogs, Bluesky posts, and threat intelligence feeds claiming "active global intrusion campaign" and "scanning in the wild." Posts link to Bleeping Computer and HackerNews coverage amplifying the threat narrative.

  14. 17 CVE-2026-12944 CRITICAL · 9.6 score 3 · 4 posts
    hype LIKELY HACK · 72 hack

    What: IBM Langflow OSS 1.0.0–1.10.0 allows unauthenticated arbitrary Python code execution as root via socket/urllib imports in components, enabling credential theft, file exfiltration, and lateral movement. CVSS 9.6 CRITICAL.

    Why it matters: Published yesterday; affects widely-used open-source LLM orchestration tool. NVD confirms root RCE with AWS IMDSv1 SSRF chain and container escape potential. No KEV-listing yet, but CRITICAL CVSS and immediate patch urgency signal real exposure in deployed instances.

    Where it's seen: Bluesky infosec community amplifying NVD data and threat intel aggregators (Radar, HackerWire, StackFlag) within 24 hours of publication. No public PoC or in-the-wild exploitation reported; chatter is advisory-driven awareness-raising.

  15. 18 CVE-2024-21762 CRITICAL · 9.8 KEV EPSS 84% score 3 · 3 posts
    hype ACTIVE HACK · 92 hack

    What: Out-of-bounds write in Fortinet FortiOS and FortiProxy SSL VPN (versions 6.0–7.4) enabling unauthenticated remote code execution; CVSS 9.8 CRITICAL, EPSS 84.3%.

    Why it matters: KEV-listed on day of publication (2024-02-09); confirmed in-the-wild exploitation documented against Thai ISP 3BB with MeshCentral backdoor deployment; actively exploited by multiple threat actors including Qilin ransomware gang using it for initial access; defenders triaging mass VPN exposure across customer base.

    Where it's seen: Security researchers and threat intel vendors posting exploitation timelines and IOCs; ransomware playbook references; incident reports linking 3BB breach to active toolkit deployment; patching urgency emphasized by CISO-facing threat feeds.

  16. 19 CVE-2026-91200 HIGH · 8.8 score 3 · 3 posts
    hype MOSTLY HYPE · 28 hack

    What: DevSpace versions up to 6.3.21 allow path traversal in tar extraction from in-pod sync streams, enabling arbitrary file write and code execution on developer workstations (CVSS 8.8).

    Why it matters: Published yesterday; high CVSS score reflects code execution risk. No KEV listing yet, no public PoC confirmed in chatter, no vendor advisory visible in posts. Social signal is pure NVD/metadata amplification with no defender triage or exploitation reports.

    Where it's seen: Three near-identical posts on Bluesky quoting NVD description verbatim; references to aggregator sites. No security researcher PoC, no vendor patch announcement, no defender discussion of active exploitation.

  17. 20 CVE-2026-91003 CRITICAL · 9.1 score 3 · 3 posts
    hype LIKELY HACK · 72 hack

    What: Stack-based buffer overflow in D-Link DI-8300 16.07 CGI service (rzgl_asp function, redirct_url parameter) enabling remote code execution. CVSS 9.1 CRITICAL.

    Why it matters: Public exploit available same day as disclosure. Remote unauthenticated RCE on network appliance. No KEV listing yet but exploit publication and CRITICAL score warrant immediate triage by D-Link device owners.

    Where it's seen: Coordinated social amplification across threat intel feeds (Vulnsea, Hacker Wire, OffSeq radar) flagging exploit availability and RCE risk. Chatter focuses on patch urgency and network access restriction.

  18. 21 CVE-2026-45051 score 3 · 3 posts
    hype MIXED · 52 hack

    What: OpenAM <16.1.1 WebAuthnAuthentication module deserializes untrusted AuthenticatorImpl objects without validation, enabling RCE via classpath gadgets if attacker can write to userAttribute (CVE-2026-45051).

    Why it matters: Published same-day with vendor patch (16.1.1); exploitability requires non-default preconditions (prior attribute write access + WebAuthn reachable), limiting widespread immediate risk but affecting access management deployments. Not yet KEV-listed; CVSS claims ~9.2 in chatter but unconfirmed in official metadata.

    Where it's seen: Social posts cite CVSS 9.2 and RCE, recommend immediate upgrade to 16.1.1; no public PoC observed yet; vendor patch available; defender triage likely underway in OpenAM shops.

  19. 22 CVE-2026-20079 CRITICAL · 10.0 KEV EPSS 76% score 3 · 3 posts
    hype ACTIVE HACK · 92 hack

    What: Unauthenticated authentication bypass and remote code execution in Cisco Secure Firewall Management Center (FMC) web interface, allowing root access. CVSS 10.0, EPSS 97.4th percentile.

    Why it matters: KEV-listed as of 2026-09-09; Cisco confirmed active in-the-wild exploitation by nation-state and ransomware actors. CISA federal remediation deadline 2026-09-12. No workaround; patch mandatory. Originally disclosed March 2026 but exploitation began recently, triggering urgent defender triage.

    Where it's seen: Major security news outlets (BleepingComputer, HelpNetSecurity), CISA/Cisco advisories, international security communities (French CERT, Dutch reporting). Consistent high-signal chatter across multiple languages and regions.

  20. 23 CVE-2026-85880 HIGH · 7.8 KEV score 3 · 3 posts
    hype ACTIVE HACK · 88 hack

    What: Heap-based buffer overflow in Windows ALPC allowing local privilege escalation (CVSS 7.8 HIGH); affects authorized attackers on Windows systems.

    Why it matters: KEV-listed as exploited in-the-wild zero-day as of 2026-09-08. Microsoft patched it same day in Patch Tuesday alongside CVE-2026-81963; multiple vendor advisories (Tenable, Talos, Krebs) confirm active exploitation. Part of larger LPE chains targeting older Windows builds; requires initial foothold but escalates to SYSTEM.

    Where it's seen: Patch Tuesday coverage across security blogs and news outlets; exploit chains documented involving Chromium V8 RCE + Windows kernel LPE; defender alerts on Bluesky discussing triage priority and mitigation.

  21. 24 CVE-2026-60004 CRITICAL · 9.8 KEV EPSS 87% score 3 · 3 posts
    hype ACTIVE HACK · 92 hack

    What: Code injection / remote code execution in Gitea (self-hosted Git service) affecting authenticated users via the diffpatch API; CVSS 9.8 reported.

    Why it matters: KEV-listed as of 2026-08-25 with confirmed in-the-wild exploitation. Multiple sources cite active attacks against Gitea instances. Patch available (v1.27.1+). Self-hosted deployments with open registration particularly at risk, often positioned near build and OT networks.

    Where it's seen: CISA KEV announcement driving coordinated social signal across security media. Posts cite threat intelligence reports, urgent patching guidance, and technical details (signup form → shell access via diffpatch). No public PoC linked in posts, but exploitation confirmed by threat feeds.

  22. 25 CVE-2026-89022 HIGH · 7.4 score 3 · 2 posts
    hype MIXED · 58 hack

    What: BookStack before 26.05.5 has an authentication bypass in social login; attackers can sign in as any user by exploiting driver_id namespace collision across different social providers (CVSS 7.4).

    Why it matters: Same-day advisory with working vulnerability logic published; no KEV listing yet but likely forthcoming. Core auth bypass affecting multi-tenant or organization deployments. Patch (26.05.5) is available. No confirmed in-the-wild exploitation reported in posts, but social chatter is active and accurate.

    Where it's seen: Security social media (Bluesky) circulating NVD description and advisory; one post inflates CVSS to 9.1 (misreporting). No PoC code shared, no defender triage signals yet.