// CVE TrackerSHOWING 50 OF 50
39CRITICAL
8HIGH
3MEDIUM
0LOW
24KEV LISTED
1NO PATCH
| CVE ID | VULNERABILITY | VENDOR | CVSS | SEVERITY | PATCH | EXPLOIT | PUBLISHED | |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-20131KEV | Cisco Secure FMC Insecure Deserialization Unauthenticated RCE | Cisco | 10 | ■ CRITICAL | AVAILABLE | PUBLIC | 2026-03-04 | ▶ |
| CVE-2026-20079 | Cisco FMC Authentication Bypass to Root RCE | Cisco | 10 | ■ CRITICAL | AVAILABLE | POC | 2026-03-04 | ▶ |
| CVE-2026-16812KEV | Arista VeloCloud Orchestrator Unauthenticated OS Command Injection | Arista Networks | 10 | ■ CRITICAL | AVAILABLE | LIMITED | 2026-07-28 | ▶ |
| CVE-2026-15409KEV | SonicWall SMA1000 Unauthenticated SSRF Zero-Day | SonicWall | 10 | ■ CRITICAL | AVAILABLE | LIMITED | 2026-07-14 | ▶ |
| CVE-2026-50746 | Ubiquiti UniFi Connect Application Improper Access Control / Command Injection | Ubiquiti | 10 | ■ CRITICAL | AVAILABLE | NONE | 2026-07-02 | ▶ |
| CVE-2026-48286 | Adobe Campaign Classic Incorrect Authorization Unauthenticated RCE | Adobe | 10 | ■ CRITICAL | AVAILABLE | NONE | 2026-07-01 | ▶ |
| CVE-2026-48282KEV | Adobe ColdFusion RDS FILEIO Path Traversal to Unauthenticated RCE | Adobe | 10 | ■ CRITICAL | AVAILABLE | PUBLIC | 2026-06-30 | ▶ |
| CVE-2026-48908KEV | JoomShaper SP Page Builder Unauthenticated File Upload / RCE (Zero-Day) | JoomShaper | 10 | ■ CRITICAL | AVAILABLE | PUBLIC | 2026-06-20 | ▶ |
| CVE-2026-56290KEV | Joomla Page Builder CK Unauthenticated Arbitrary File Upload — RCE | Joomlack | 10 | ■ CRITICAL | AVAILABLE | PUBLIC | 2026-06-27 | ▶ |
| CVE-2026-48558KEV | SimpleHelp RMM OIDC Authentication Bypass | SimpleHelp | 10 | ■ CRITICAL | AVAILABLE | LIMITED | 2026-06-05 | ▶ |
| CVE-2026-34908KEV | Ubiquiti UniFi OS NGINX Auth Bypass + Command Injection Chain (CVSS 10.0 Trio) | Ubiquiti | 10 | ■ CRITICAL | AVAILABLE | PUBLIC | 2026-05-22 | ▶ |
| CVE-2026-57092 | Windows VMSwitch Use-After-Free Hyper-V Guest-to-Host Escape | Microsoft | 9.9 | ■ CRITICAL | AVAILABLE | NONE | 2026-07-14 | ▶ |
| CVE-2026-10523 | Ivanti Sentry Pre-Auth Authentication Bypass — Arbitrary Admin Account Creation | Ivanti | 9.9 | ■ CRITICAL | AVAILABLE | POC | 2026-06-09 | ▶ |
| CVE-2026-53359 | Januscape Linux KVM x86 Guest-to-Host Escape (Use-After-Free) | Linux | 9.9 | ■ CRITICAL | AVAILABLE | POC | 2026-07-06 | ▶ |
| CVE-2026-55255KEV | Langflow AI Platform IDOR Authorization Bypass (First AI Agent Platform in KEV) | Langflow (langflow-ai) | 9.9 | ■ CRITICAL | AVAILABLE | LIMITED | 2026-06-19 | ▶ |
| CVE-2026-25089KEV | Fortinet FortiSandbox Web UI OS Command Injection Unauthenticated RCE | Fortinet | 9.8 | ■ CRITICAL | AVAILABLE | LIMITED | 2026-04-14 | ▶ |
| CVE-2026-59309 | VMware vCenter Authentication Bypass in Directory Service | Broadcom (VMware) | 9.8 | ■ CRITICAL | AVAILABLE | NONE | 2026-07-29 | ▶ |
| CVE-2026-59310 | VMware vCenter Directory Traversal RCE in Syslog Server | Broadcom (VMware) | 9.8 | ■ CRITICAL | AVAILABLE | NONE | 2026-07-29 | ▶ |
| CVE-2026-63077 | JetBrains TeamCity On-Premises Unauthenticated RCE via Agent Polling Protocol | JetBrains | 9.8 | ■ CRITICAL | AVAILABLE | NONE | 2026-07-27 | ▶ |
| CVE-2026-53921 | OpenWrt odhcpd DHCPv6 Stack Buffer Overflow — Unauthenticated RCE as Root | OpenWrt | 9.8 | ■ CRITICAL | AVAILABLE | POC | 2026-07-28 | ▶ |
| CVE-2026-63030KEV | WordPress wp2shell Pre-Auth RCE Chain | WordPress (Automattic) | 9.8 | ■ CRITICAL | AVAILABLE | PUBLIC | 2026-07-17 | ▶ |
| CVE-2026-56190 | Windows RDP Server Unauthenticated RCE (Uninitialized Resource) | Microsoft | 9.8 | ■ CRITICAL | AVAILABLE | NONE | 2026-07-14 | ▶ |
| CVE-2026-50522KEV | Microsoft SharePoint Server Unauthenticated RCE via Deserialization (Post-PoC Active Exploitation) | Microsoft | 9.8 | ■ CRITICAL | AVAILABLE | PUBLIC | 2026-07-14 | ▶ |
| CVE-2026-46817KEV | Oracle E-Business Suite Payments Unauthenticated Takeover | Oracle | 9.8 | ■ CRITICAL | AVAILABLE | LIMITED | 2026-05-20 | ▶ |
| CVE-2026-56188 | Windows Server Network Driver Unauthenticated Remote Code Execution | Microsoft | 9.8 | ■ CRITICAL | AVAILABLE | NONE | 2026-07-14 | ▶ |
| CVE-2026-55944 | Microsoft Dynamics NAV / 365 Business Central Unauthenticated RCE via Deserialization | Microsoft | 9.8 | ■ CRITICAL | AVAILABLE | NONE | 2026-07-14 | ▶ |
| CVE-2026-50518 | Windows DHCP Server Unauthenticated RCE Heap Buffer Overflow | Microsoft | 9.8 | ■ CRITICAL | AVAILABLE | NONE | 2026-07-14 | ▶ |
| CVE-2026-58644KEV | Microsoft SharePoint Server Unauthenticated Deserialization RCE (KEV) | Microsoft | 9.8 | ■ CRITICAL | AVAILABLE | PUBLIC | 2026-07-14 | ▶ |
| CVE-2026-39808KEV | Fortinet FortiSandbox OS Command Injection Unauthenticated RCE | Fortinet | 9.8 | ■ CRITICAL | AVAILABLE | PUBLIC | 2026-04-14 | ▶ |
| CVE-2026-9103 | IBM Langflow OSS Default Auto-Login Authentication Bypass | IBM | 9.8 | ■ CRITICAL | AVAILABLE | PUBLIC | 2026-07-17 | ▶ |
| CVE-2026-48939KEV | iCagenda Joomla Extension Unauthenticated Arbitrary File Upload RCE | icagenda.com (JoomliC) | 9.8 | ■ CRITICAL | AVAILABLE | PUBLIC | 2026-06-20 | ▶ |
| CVE-2026-56291KEV | Balbooa Forms Joomla Extension Unauthenticated File Upload RCE (Zero-Day) | Balbooa | 9.8 | ■ CRITICAL | AVAILABLE | LIMITED | 2026-07-09 | ▶ |
| CVE-2026-20896 | Gitea Docker Reverse-Proxy Authentication Bypass | Gitea | 9.8 | ■ CRITICAL | AVAILABLE | PUBLIC | 2026-07-03 | ▶ |
| CVE-2026-12569KEV | PTC Windchill / FlexPLM Unauthenticated RCE via Deserialization | PTC | 9.8 | ■ CRITICAL | AVAILABLE | LIMITED | 2026-06-18 | ▶ |
| CVE-2026-59792 | JetBrains IntelliJ IDEA Path Traversal Code Execution via Project Workspace ID | JetBrains | 9.6 | ■ CRITICAL | AVAILABLE | NONE | 2026-07-10 | ▶ |
| CVE-2026-6875 | ServiceNow AI Platform Pre-Auth Sandbox Escape RCE | ServiceNow | 9.5 | ■ CRITICAL | AVAILABLE | PUBLIC | 2026-07-13 | ▶ |
| CVE-2026-16232KEV | Check Point SmartConsole Authentication Bypass Zero-Day (KEV) | Check Point | 9.3 | ■ CRITICAL | AVAILABLE | PUBLIC | 2026-07-22 | ▶ |
| CVE-2026-55040 | Microsoft SharePoint JWT Token Authentication Bypass (RCE Chain — Patch 2 of 2 Due August 2026) | Microsoft | 9.1 | ■ CRITICAL | PARTIAL | POC | 2026-07-14 | ▶ |
| CVE-2026-16723 | Alibaba Fastjson 1.x Zero-Day Unauthenticated RCE — No Patch Available | Alibaba | 9 | ■ CRITICAL | NO PATCH | PUBLIC | 2026-07-21 | ▶ |
| CVE-PENDING-ZIMBRA-2026 | Zimbra Collaboration Classic Web Client Critical Stored XSS (No CVE Assigned Yet) | Zimbra (Synacor) | 8.8 | ■ HIGH | AVAILABLE | NONE | 2026-07-11 | ▶ |
| CVE-2026-43503 | Linux Kernel 'DirtyClone' LPE via Cloned Packet Page-Cache Write (DirtyFrag Family) | Linux Kernel | 8.8 | ■ HIGH | AVAILABLE | POC | 2026-05-23 | ▶ |
| CVE-2026-20230KEV | Cisco Unified CM WebDialer SSRF to Root File Write | Cisco | 8.6 | ■ HIGH | AVAILABLE | PUBLIC | 2026-06-03 | ▶ |
| CVE-2026-53264 | Linux Kernel net/sched Use-After-Free LPE — AI-Assisted Public Exploit Released | Linux | 7.8 | ■ HIGH | AVAILABLE | PUBLIC | 2026-07-28 | ▶ |
| CVE-2026-8933 | Ubuntu snap-confine Race Condition Local Privilege Escalation | Canonical | 7.8 | ■ HIGH | AVAILABLE | POC | 2026-07-21 | ▶ |
| CVE-2026-56155KEV | Microsoft AD FS Privilege Escalation Zero-Day Exploited in the Wild (KEV) | Microsoft | 7.8 | ■ HIGH | AVAILABLE | LIMITED | 2026-07-14 | ▶ |
| CVE-2026-46331 | Linux Kernel 'pedit COW' Local Privilege Escalation via Page-Cache Corruption | Linux Kernel | 7.8 | ■ HIGH | AVAILABLE | POC | 2026-06-16 | ▶ |
| CVE-2026-47729 | Squidbleed — Squid Proxy FTP Gateway Heap Overread Credential Leak | Squid-cache.org | 6.5 | ■ MEDIUM | AVAILABLE | POC | 2026-06-12 | ▶ |
| CVE-2026-20316KEV | Cisco FMC Hard-Coded Password Zero-Day (KEV) | Cisco | 5.3 | ■ MEDIUM | AVAILABLE | LIMITED | 2026-07-29 | ▶ |
| CVE-2025-68686KEV | Fortinet FortiOS SSL-VPN Symlink Persistence Patch Bypass | Fortinet | 5.3 | ■ MEDIUM | AVAILABLE | LIMITED | 2026-02-10 | ▶ |
| CVE-2026-56164KEV | Microsoft SharePoint Server Missing Auth EoP Zero-Day (KEV) | Microsoft | 5.3 | ■ HIGH | AVAILABLE | LIMITED | 2026-07-14 | ▶ |