DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:09:16ZSOURCES: 14CRITICAL: 39
⚠ ACTIVE ALERTS
@MsftSecIntel CRITICAL — Microsoft Defender Experts tracked increased ACR Stealer activity from late April through… /// @TalosSecurity CRITICAL — Qilin RaaS remains the most active ransomware operation globally in 2026 with 500+… /// @CrowdStrike CRITICAL — VECT ransomware + TeamPCP supply chain credential theft + BreachForums mass affiliate… /// @MandiantThreats CRITICAL — Tracking Qilin affiliate recruitment activity on Russian-language cybercrime forums… /// @FalconFeedsio CRITICAL — Dark web monitoring alert: FIFA World Cup 2026 credential ecosystem fully operational on…
39Critical Threats
18Active CVEs
8IOCs Tracked
11New Advisories
SHOWING 50 OF 50
39CRITICAL
8HIGH
3MEDIUM
0LOW
24KEV LISTED
1NO PATCH
⌕
CVE IDVULNERABILITYVENDORCVSSSEVERITYPATCHEXPLOITPUBLISHED
CVE-2026-20131KEVCisco Secure FMC Insecure Deserialization Unauthenticated RCECisco10■ CRITICALAVAILABLEPUBLIC2026-03-04▶
CVE-2026-20079Cisco FMC Authentication Bypass to Root RCECisco10■ CRITICALAVAILABLEPOC2026-03-04▶
CVE-2026-16812KEVArista VeloCloud Orchestrator Unauthenticated OS Command InjectionArista Networks10■ CRITICALAVAILABLELIMITED2026-07-28▶
CVE-2026-15409KEVSonicWall SMA1000 Unauthenticated SSRF Zero-DaySonicWall10■ CRITICALAVAILABLELIMITED2026-07-14▶
CVE-2026-50746Ubiquiti UniFi Connect Application Improper Access Control / Command InjectionUbiquiti10■ CRITICALAVAILABLENONE2026-07-02▶
CVE-2026-48286Adobe Campaign Classic Incorrect Authorization Unauthenticated RCEAdobe10■ CRITICALAVAILABLENONE2026-07-01▶
CVE-2026-48282KEVAdobe ColdFusion RDS FILEIO Path Traversal to Unauthenticated RCEAdobe10■ CRITICALAVAILABLEPUBLIC2026-06-30▶
CVE-2026-48908KEVJoomShaper SP Page Builder Unauthenticated File Upload / RCE (Zero-Day)JoomShaper10■ CRITICALAVAILABLEPUBLIC2026-06-20▶
CVE-2026-56290KEVJoomla Page Builder CK Unauthenticated Arbitrary File Upload — RCEJoomlack10■ CRITICALAVAILABLEPUBLIC2026-06-27▶
CVE-2026-48558KEVSimpleHelp RMM OIDC Authentication BypassSimpleHelp10■ CRITICALAVAILABLELIMITED2026-06-05▶
CVE-2026-34908KEVUbiquiti UniFi OS NGINX Auth Bypass + Command Injection Chain (CVSS 10.0 Trio)Ubiquiti10■ CRITICALAVAILABLEPUBLIC2026-05-22▶
CVE-2026-57092Windows VMSwitch Use-After-Free Hyper-V Guest-to-Host EscapeMicrosoft9.9■ CRITICALAVAILABLENONE2026-07-14▶
CVE-2026-10523Ivanti Sentry Pre-Auth Authentication Bypass — Arbitrary Admin Account CreationIvanti9.9■ CRITICALAVAILABLEPOC2026-06-09▶
CVE-2026-53359Januscape Linux KVM x86 Guest-to-Host Escape (Use-After-Free)Linux9.9■ CRITICALAVAILABLEPOC2026-07-06▶
CVE-2026-55255KEVLangflow AI Platform IDOR Authorization Bypass (First AI Agent Platform in KEV)Langflow (langflow-ai)9.9■ CRITICALAVAILABLELIMITED2026-06-19▶
CVE-2026-25089KEVFortinet FortiSandbox Web UI OS Command Injection Unauthenticated RCEFortinet9.8■ CRITICALAVAILABLELIMITED2026-04-14▶
CVE-2026-59309VMware vCenter Authentication Bypass in Directory ServiceBroadcom (VMware)9.8■ CRITICALAVAILABLENONE2026-07-29▶
CVE-2026-59310VMware vCenter Directory Traversal RCE in Syslog ServerBroadcom (VMware)9.8■ CRITICALAVAILABLENONE2026-07-29▶
CVE-2026-63077JetBrains TeamCity On-Premises Unauthenticated RCE via Agent Polling ProtocolJetBrains9.8■ CRITICALAVAILABLENONE2026-07-27▶
CVE-2026-53921OpenWrt odhcpd DHCPv6 Stack Buffer Overflow — Unauthenticated RCE as RootOpenWrt9.8■ CRITICALAVAILABLEPOC2026-07-28▶
CVE-2026-63030KEVWordPress wp2shell Pre-Auth RCE ChainWordPress (Automattic)9.8■ CRITICALAVAILABLEPUBLIC2026-07-17▶
CVE-2026-56190Windows RDP Server Unauthenticated RCE (Uninitialized Resource)Microsoft9.8■ CRITICALAVAILABLENONE2026-07-14▶
CVE-2026-50522KEVMicrosoft SharePoint Server Unauthenticated RCE via Deserialization (Post-PoC Active Exploitation)Microsoft9.8■ CRITICALAVAILABLEPUBLIC2026-07-14▶
CVE-2026-46817KEVOracle E-Business Suite Payments Unauthenticated TakeoverOracle9.8■ CRITICALAVAILABLELIMITED2026-05-20▶
CVE-2026-56188Windows Server Network Driver Unauthenticated Remote Code ExecutionMicrosoft9.8■ CRITICALAVAILABLENONE2026-07-14▶
CVE-2026-55944Microsoft Dynamics NAV / 365 Business Central Unauthenticated RCE via DeserializationMicrosoft9.8■ CRITICALAVAILABLENONE2026-07-14▶
CVE-2026-50518Windows DHCP Server Unauthenticated RCE Heap Buffer OverflowMicrosoft9.8■ CRITICALAVAILABLENONE2026-07-14▶
CVE-2026-58644KEVMicrosoft SharePoint Server Unauthenticated Deserialization RCE (KEV)Microsoft9.8■ CRITICALAVAILABLEPUBLIC2026-07-14▶
CVE-2026-39808KEVFortinet FortiSandbox OS Command Injection Unauthenticated RCEFortinet9.8■ CRITICALAVAILABLEPUBLIC2026-04-14▶
CVE-2026-9103IBM Langflow OSS Default Auto-Login Authentication BypassIBM9.8■ CRITICALAVAILABLEPUBLIC2026-07-17▶
CVE-2026-48939KEViCagenda Joomla Extension Unauthenticated Arbitrary File Upload RCEicagenda.com (JoomliC)9.8■ CRITICALAVAILABLEPUBLIC2026-06-20▶
CVE-2026-56291KEVBalbooa Forms Joomla Extension Unauthenticated File Upload RCE (Zero-Day)Balbooa9.8■ CRITICALAVAILABLELIMITED2026-07-09▶
CVE-2026-20896Gitea Docker Reverse-Proxy Authentication BypassGitea9.8■ CRITICALAVAILABLEPUBLIC2026-07-03▶
CVE-2026-12569KEVPTC Windchill / FlexPLM Unauthenticated RCE via DeserializationPTC9.8■ CRITICALAVAILABLELIMITED2026-06-18▶
CVE-2026-59792JetBrains IntelliJ IDEA Path Traversal Code Execution via Project Workspace IDJetBrains9.6■ CRITICALAVAILABLENONE2026-07-10▶
CVE-2026-6875ServiceNow AI Platform Pre-Auth Sandbox Escape RCEServiceNow9.5■ CRITICALAVAILABLEPUBLIC2026-07-13▶
CVE-2026-16232KEVCheck Point SmartConsole Authentication Bypass Zero-Day (KEV)Check Point9.3■ CRITICALAVAILABLEPUBLIC2026-07-22▶
CVE-2026-55040Microsoft SharePoint JWT Token Authentication Bypass (RCE Chain — Patch 2 of 2 Due August 2026)Microsoft9.1■ CRITICALPARTIALPOC2026-07-14▶
CVE-2026-16723Alibaba Fastjson 1.x Zero-Day Unauthenticated RCE — No Patch AvailableAlibaba9■ CRITICALNO PATCHPUBLIC2026-07-21▶
CVE-PENDING-ZIMBRA-2026Zimbra Collaboration Classic Web Client Critical Stored XSS (No CVE Assigned Yet)Zimbra (Synacor)8.8■ HIGHAVAILABLENONE2026-07-11▶
CVE-2026-43503Linux Kernel 'DirtyClone' LPE via Cloned Packet Page-Cache Write (DirtyFrag Family)Linux Kernel8.8■ HIGHAVAILABLEPOC2026-05-23▶
CVE-2026-20230KEVCisco Unified CM WebDialer SSRF to Root File WriteCisco8.6■ HIGHAVAILABLEPUBLIC2026-06-03▶
CVE-2026-53264Linux Kernel net/sched Use-After-Free LPE — AI-Assisted Public Exploit ReleasedLinux7.8■ HIGHAVAILABLEPUBLIC2026-07-28▶
CVE-2026-8933Ubuntu snap-confine Race Condition Local Privilege EscalationCanonical7.8■ HIGHAVAILABLEPOC2026-07-21▶
CVE-2026-56155KEVMicrosoft AD FS Privilege Escalation Zero-Day Exploited in the Wild (KEV)Microsoft7.8■ HIGHAVAILABLELIMITED2026-07-14▶
CVE-2026-46331Linux Kernel 'pedit COW' Local Privilege Escalation via Page-Cache CorruptionLinux Kernel7.8■ HIGHAVAILABLEPOC2026-06-16▶
CVE-2026-47729Squidbleed — Squid Proxy FTP Gateway Heap Overread Credential LeakSquid-cache.org6.5■ MEDIUMAVAILABLEPOC2026-06-12▶
CVE-2026-20316KEVCisco FMC Hard-Coded Password Zero-Day (KEV)Cisco5.3■ MEDIUMAVAILABLELIMITED2026-07-29▶
CVE-2025-68686KEVFortinet FortiOS SSL-VPN Symlink Persistence Patch BypassFortinet5.3■ MEDIUMAVAILABLELIMITED2026-02-10▶
CVE-2026-56164KEVMicrosoft SharePoint Server Missing Auth EoP Zero-Day (KEV)Microsoft5.3■ HIGHAVAILABLELIMITED2026-07-14▶