ZeroHour

Vulnerabilities

64 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-34908
Improper Access Control in Ubiquiti UniFi OS Devices (CVE-2026-34908)

CVE-2026-34908 is an improper access control flaw (CWE-284) in Ubiquiti UniFi OS, the operating system running on UniFi gateways, Dream Machine appliances, and UniFi network video recorders. An attacker who can reach the device over the network — with no privileges or user interaction required per the CVSS vector — can make unauthorized changes to the system. The CVSS 3.1 score of 10.0 with a changed scope (S:C) indicates a successful attack can compromise the device beyond its intended security boundary, with high impact to confidentiality, integrity, and availability. Any organization running the affected UniFi OS products, including UniFi OS Server and the Dream Machine, Cloud Gateway, Enterprise Fortress, Dream Router, Express, and UNVR lines, is affected; specific vulnerable and fixed firmware versions are not specified in the available data. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2026-06-23, confirming active exploitation, and EPSS assigns an 85.2% probability of exploitation within 30 days (100th percentile); ransomware use is unknown.

Do: Apply the patched UniFi OS firmware from Ubiquiti's advisory immediately (exact fixed versions are not given in this data) and review affected consoles for unauthorized configuration changes, as the KEV listing requires action under CISA BOD 26-04. Restrict UniFi OS management interfaces and SSH from internet exposure, and isolate or discontinue use of any device that cannot be patched. The same release addresses sibling UniFi OS flaws CVE-2026-34909 and CVE-2026-34910, with CVE-2026-34910 reported exploited in the wild to build a Mirai botnet, so patching covers the full batch.

10.085% KEV PoC
  • Ubiquiti UniFi OS Server
  • Ubiquiti UniFi Cloud Gateway Industrial firmware
  • Ubiquiti UniFi Dream Machine firmware
  • +9 more
masson the order of 1M+ deployed UniFi OS consoles/gateways, with 100k+ internet-exposed management interfaces
CVE-2026-33824
Unauthenticated Double-Free RCE in Microsoft Windows IKE Extension

A double-free memory-corruption flaw (CWE-415) in the Microsoft Windows Internet Key Exchange (IKE) service extension allows a remote, unauthenticated attacker to trigger the bug with crafted network traffic, with no privileges or user interaction required. Successful exploitation yields remote code execution with full system impact, reflected in the critical 9.8 CVSS score (high confidentiality, integrity, and availability). The vulnerable IKE component is present in Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2, 26H1), and Windows Server 2016, 2019, and 2022 (including 23H2), which ship it as a built-in feature. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2026-08-18, and security reporting confirms it is being actively exploited in the wild, though ransomware use is not yet confirmed. No public proof-of-concept is known, but the high EPSS score (72.7%, 99th percentile) signals a very strong likelihood of imminent or ongoing exploitation.

Do: Apply Microsoft's security updates for CVE-2026-33824 to all affected Windows 10, Windows 11, and Windows Server releases, prioritizing internet-exposed systems where IKE/VPN is reachable (UDP 500/4500), per BOD 26-04 requirements. Organizations unable to patch promptly should restrict or discontinue use of exposed IKE/VPN services on affected hosts until updated. Triage VPN endpoints and remote-access servers for crashes or suspicious IKE traffic given confirmed in-the-wild exploitation.

9.873% KEV
  • Microsoft Windows 10 1607
  • Microsoft Windows 10 1809
  • Microsoft Windows 10 21H2
  • +9 more
masswell over 1B Windows devices include the built-in IKE extension; internet-exposed VPN/IKE endpoints plausibly number in the hundreds of thousands
CVE-2026-39808
Unauthenticated OS Command Injection in Fortinet FortiSandbox 4.4

CVE-2026-39808 is an OS command injection flaw (CWE-78) in Fortinet FortiSandbox versions 4.4.0 through 4.4.8, caused by improper neutralization of special elements passed to OS commands. The vulnerability is network-reachable, requires no privileges or user interaction (CVSS 3.1: 9.8, AV:N/AC:L/PR:N/UI:N), though CISA's description does not specify the exact entry point that a remote unauthenticated attacker abuses to trigger it. Successful exploitation lets the attacker execute unauthorized code or commands on the appliance, with high impact to confidentiality, integrity, and availability. Any organization running FortiSandbox 4.4.0-4.4.8 is affected; these sandboxing appliances are typically deployed as add-ons to enterprise FortiGate security estates. The flaw was added to CISA's KEV on 2026-07-16, and press coverage describes critical FortiSandbox bugs coming under active attack, so in-the-wild exploitation should be assumed.

Do: Upgrade all FortiSandbox appliances out of the affected 4.4.0-4.4.8 range to a fixed release per Fortinet's advisory, prioritizing internet-exposed units and complying with the CISA KEV required action (added 2026-07-16) and BOD 26-04 guidance. Until patched, restrict network access to the appliance's management and analysis interfaces and triage for signs of command execution such as unexpected processes or outbound connections. Confirm the specific fixed 4.4.x build in Fortinet's PSIRT advisory before scheduling upgrades.

9.893% KEV PoC
  • Fortinet FortiSandbox 4.4.0 through 4.4.8
moderate≈1,000-10,000 deployed FortiSandbox appliances (est.), of which a low thousands are likely internet-exposed
CVE-2026-34486
EncryptInterceptor Bypass Exposes Cluster Traffic in Apache Tomcat

CVE-2026-34486 is a missing-encryption vulnerability in Apache Tomcat in which the EncryptInterceptor, the component that encrypts Tomcat cluster communication, can be bypassed in a fail-open manner; the flaw was introduced as a regression by the fix for CVE-2026-29146. It affects Tomcat 11.0.20, 10.1.53 and 9.0.116, and is triggered when cluster communication is expected to be encrypted: an attacker positioned on the network path between cluster nodes receives inter-node traffic in cleartext. By reading that unencrypted traffic, the attacker can obtain sensitive data such as session payloads, potentially enabling session theft and authentication bypass as indicated by related reporting. Only deployments running the affected point releases with the EncryptInterceptor in use are impacted, including Tomcat shipped in Red Hat JBoss Web Server and Red Hat Enterprise Linux channels. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-08-04, EPSS places 30-day exploitation probability at 98.6%, though no public proof-of-concept is known and ransomware use is unconfirmed.

Do: Upgrade Apache Tomcat to 11.0.21, 10.1.54 or 9.0.117, and apply the corresponding Red Hat JBoss Web Server / Enterprise Linux updates when published. Audit Tomcat cluster configurations for EncryptInterceptor usage, and until patched restrict or encrypt the network segment carrying inter-node cluster traffic. Because the flaw is in CISA's KEV catalog, federal agencies must patch per BOD 26-04 timelines and should review cluster nodes for signs of session data interception.

7.599% KEV
  • Apache Tomcat 11.0.20, 10.1.53, 9.0.116 (fixed in 11.0.21, 10.1.54, 9.0.117)
  • Red Hat JBoss Web Server (ships affected Tomcat)
  • Red Hat Enterprise Linux (including ELS, EUS, TUS, and Update Services for SAP Solutions)
largetens of thousands of Tomcat deployments on the affected point releases
CVE-2025-67038
Unauthenticated Root Command Injection in Lantronix EDS5000 Device Servers

CVE-2025-67038 is an OS command injection flaw (CWE-78) in the HTTP RPC module of Lantronix EDS5000 series device servers, with firmware 2.1.0.0R3 confirmed affected. When a login attempt fails, the module writes a log entry by building a shell command that directly concatenates the username from the request without any sanitization, so an attacker who sends a crafted username in an authentication request gets their commands appended to it. Because the log-writing command runs as root, an unauthenticated, network-reachable attacker gains full command execution with the highest privileges on the device. Any organization running network-exposed Lantronix EDS5000 device/console servers (EDS5008, EDS5016, EDS5032, and the G526/G527-series variants) is affected. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2026-06-23 and reports it is being actively exploited; the EPSS score of 19.3% (97th percentile) reflects a high near-term exploitation risk.

Do: Upgrade EDS5000-series firmware to a patched release per Lantronix's guidance, since no fixed version is specified in the available data and 2.1.0.0R3 is confirmed vulnerable; if patching is not yet possible, restrict HTTP access to the device's management interface at the network level. Federal agencies must apply vendor mitigations per CISA BOD 26-04 requirements following the 2026-06-23 KEV listing. Check device logs and configs for signs of compromise, since successful injection yields root-level command execution.

9.319% KEV
  • lantronix eds5008 firmware EDS5000-series firmware; 2.1.0.0R3 confirmed affected, no fixed version specified in available data
  • lantronix eds5016 firmware EDS5000-series firmware; 2.1.0.0R3 confirmed affected, no fixed version specified in available data
  • lantronix eds5032 firmware EDS5000-series firmware; 2.1.0.0R3 confirmed affected, no fixed version specified in available data
  • +9 more
moderate≈ several thousand internet-exposed devices (public reporting on related research cites thousands of exposed Lantronix/Silex serial-to-Ethernet devices)
CVE-2026-20079
Authentication bypass to root access in Cisco Secure Firewall Management Center

CVE-2026-20079 is an authentication bypass (CWE-288) in the web interface of Cisco Secure Firewall Management Center (FMC) Software, caused by an improper system process created at boot time. An unauthenticated, remote attacker can exploit it by sending crafted HTTP requests to the FMC web interface, which allows the execution of script files and commands on the device. A successful exploit grants the attacker root access to the underlying operating system, giving full control of the management platform (CVSS 3.1: 10.0, network-exploitable, no privileges or user interaction required, scope changed). The flaw affects Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management deployments. Cisco has confirmed the vulnerability is being exploited in active attacks, it carries a 35.9% EPSS score (98th percentile), and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-09-09.

Do: Upgrade FMC (and SCC Firewall Management tenants) to the fixed release specified in Cisco's advisory, prioritizing internet-exposed or externally reachable management interfaces; CISA KEV action applies to federal agencies under BOD 26-04. Until patching, restrict FMC web interface access to trusted management networks and VPNs and check devices for signs of exploitation such as unexpected script execution, unfamiliar processes, or root-level changes. Triage per CISA's Forensics Triage Requirements if compromise is suspected.

10.076% KEV PoC ×2
  • Cisco Secure Firewall Management Center (FMC) Software (web interface)
  • Cisco Security Cloud Control (SCC) Firewall Management
largeplausibly tens of thousands of FMC deployments worldwide (internet-exposed instances likely a smaller subset, likely thousands)
CVE-2025-68686
Unauthenticated Info-Exposure Bypass of Symlink Patch in Fortinet FortiOS

CVE-2025-68686 is a sensitive-information-exposure flaw (CWE-200) in Fortinet FortiOS that allows a remote, unauthenticated attacker to bypass the vendor's patch for the symbolic-link (symlink) persistency mechanism seen in some post-exploitation cases. It is triggered by crafted HTTP requests sent to a device that has already been compromised through another vulnerability at the filesystem level, for example where symlinks were planted to maintain access to files. By bypassing the patch, the attacker can keep retrieving sensitive information from an otherwise remediated FortiGate device. Any organization running an affected FortiOS release is potentially affected; the CISA data does not enumerate specific versions, so administrators should consult Fortinet's advisory for the affected branches. The flaw was added to CISA's KEV catalog on 2026-07-27, confirming real-world exploitation, and EPSS assigns a 29.6% probability of exploitation within 30 days (98th percentile), with ransomware use currently unknown.

Do: Patch affected FortiOS devices per Fortinet's current advisory, following BOD 26-04 timelines for federal agencies (apply mitigations per vendor instructions or discontinue use where mitigations are unavailable). Because this flaw defeats the earlier symlink-persistence fix, re-check previously remediated devices for residual or recreated symlinks and hunt for indicators of prior filesystem-level compromise, such as unexpected symlinks and anomalous SSL-VPN activity. Review logs for crafted HTTP requests and prioritize internet-facing FortiGate assets for patching and triage.

5.930% KEV
  • Fortinet FortiOS
mass~300,000+ internet-exposed FortiGate/FortiOS devices
CVE-2026-0770
Unauthenticated Remote Code Execution in Langflow validate Endpoint

CVE-2026-0770 is an unauthenticated remote code execution vulnerability in Langflow, an open-source visual builder for LLM and AI agent workflows. The flaw, categorized as CWE-829 (inclusion of functionality from an untrusted control sphere), resides in how the exec_globals parameter supplied to the validate endpoint is handled, allowing code or resources from an untrusted control sphere to be included and executed. A remote attacker with no credentials can send a crafted request to that endpoint and execute arbitrary code in the context of root on the affected installation. Any deployment of an affected Langflow version is exposed, with internet-facing self-hosted or containerized instances at greatest risk. The issue was disclosed through Trend Micro's Zero Day Initiative (ZDI-CAN-27325) and was added to CISA's Known Exploited Vulnerabilities catalog on 2026-07-21, confirming active in-the-wild exploitation; no public proof-of-concept is known.

Do: Apply the vendor's patched Langflow release and any prescribed mitigations per CISA guidance; because exploitation requires no authentication and executes as root, prioritize internet-exposed instances immediately (EPSS is high at 63.4%). Per BOD 26-04, if mitigations or updates are unavailable for a given deployment, discontinue use of the product. Review access logs for unexpected unauthenticated requests to the validate endpoint containing crafted exec_globals parameters, and restrict network exposure of Langflow instances until patched.

9.863% KEV
  • Langflow
moderate≈10,000–100,000 deployments (estimate; no official install count available)
CVE-2026-21962
Unauthenticated Access Control Bypass in Oracle HTTP Server and WebLogic Proxy Plug-in

CVE-2026-21962 is an improper access control flaw (CWE-284) in Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in (components: the plug-in for Apache HTTP Server and the plug-in for IIS), part of Oracle Fusion Middleware. An unauthenticated attacker with network access via HTTP can trivially exploit it, and the scope-change designation means a successful attack can significantly impact additional products beyond the plug-in itself. The attacker gains unauthorized access to critical data (potentially all accessible data) as well as the ability to create, delete, or modify critical data, reflected in the maximum CVSS 10.0 score with high confidentiality and integrity impacts and no availability impact. Organizations running the affected versions - 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0 for Oracle HTTP Server and the Apache plug-in, and 12.2.1.4.0 only for the IIS plug-in - especially those with internet-facing Apache/IIS/OHS front ends proxying WebLogic applications, are exposed. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-08-24, and EPSS assigns a 42% probability of exploitation within 30 days, though no public proof-of-concept is known.

Do: Apply the fixes from Oracle's January 2026 quarterly update (advisory AV26-042) or later for Oracle HTTP Server and the WebLogic Server Proxy Plug-in on all affected versions - 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0 (IIS plug-in affected at 12.2.1.4.0 only). Prioritize internet-facing OHS, Apache and IIS front ends per CISA BOD 26-04 and the KEV required actions, and where patching is delayed, restrict HTTP access to trusted networks and review logs for signs of unauthorized data access or modification.

10.042% KEV
  • Oracle HTTP Server (Oracle Fusion Middleware) 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0
  • Oracle WebLogic Server Proxy Plug-in for Apache HTTP Server 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0
  • Oracle WebLogic Server Proxy Plug-in for IIS 12.2.1.4.0
large~10,000-100,000 internet-exposed Oracle HTTP Server / WebLogic proxy front ends
CVE-2025-62593
Actively Exploited Browser-Based RCE in Ray AI Compute Engine

Ray, the open-source AI compute engine, is vulnerable to a critical remote code execution flaw (CVE-2025-62593, CWE-94/CWE-352) in versions prior to 2.52.0, caused by an insufficient guard against browser-based attacks: the software distinguishes browser traffic only by checking that the User-Agent header starts with 'Mozilla', but the fetch specification allows that header to be modified. An attacker can combine DNS rebinding with a crafted User-Agent so that a developer's Firefox or Safari browser silently sends malicious requests to locally running Ray services after the developer visits an attacker-controlled website or is served a malicious advertisement (malvertising). Successful exploitation yields full remote code execution on the machine running Ray, with high confidentiality, integrity and availability impact reflected in the CVSS 4.0 score of 9.4. Affected users are developers running Ray as a development tool on any version before 2.52.0, which is the fixed release. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-08-17, a public proof of concept is available in the project's GitHub security advisory (GHSA-q279-jhrf-cc6v), and EPSS estimates a 16.9% probability of exploitation in the next 30 days.

Do: Upgrade Ray to version 2.52.0 or later immediately, in line with CISA KEV and BOD 26-04 patching requirements. Until patched, avoid browsing untrusted websites (including ad-serving pages) while Ray development services are running, and restrict network access to locally running Ray services. Focus triage on machines where developers use Firefox or Safari alongside Ray, and hunt for signs of compromise since the flaw is actively exploited.

9.417% KEV PoC
  • Ray-Project (Anyscale) Ray All versions prior to 2.52.0 (patched in 2.52.0)
largeTens of thousands of developer machines/environments running vulnerable Ray (estimate)
CVE-2023-49105
Improper Authentication in ownCloud Server Allows Unauthenticated File Access

ownCloud Server versions from 10.6.0 up to (but not including) 10.13.1 accept WebDAV pre-signed URLs even when no signing key is configured for the file owner, an improper authentication flaw (CWE-287). A remote attacker who knows a victim's username can therefore access, modify, or delete that user's files without any credentials, with no privileges or user interaction required (CVSS 9.8). Any organization running a self-hosted ownCloud Server instance in the affected version range is exposed, especially internet-facing deployments. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2026-08-27, confirming exploitation in the wild, and EPSS assigns a 43.2% probability of exploitation within 30 days (99th percentile). No public proof-of-concept code is known, but recent press reports of attacks against ownCloud (including theft of records at a Philippine research body) indicate active targeting of ownCloud flaws.

Do: Upgrade to ownCloud Server 10.13.1 or later immediately, prioritizing internet-facing instances, as the flaw is on CISA's KEV list with BOD 26-04 patching deadlines. Until patched, configure signing keys for users where possible and restrict internet exposure of the pre-signed URL/WebDAV endpoints, and review server logs for unauthenticated file access, modification, or deletion tied to known usernames. If mitigations are not available for a given deployment, follow BOD 26-04 guidance for cloud services or discontinue use of the product.

9.843% KEV
  • ownCloud Server (owncloud/core) 10.6.0 through all versions before 10.13.1; fixed in 10.13.1
largelikely on the order of tens of thousands of self-hosted server deployments worldwide (no authoritative public install counts)
CVE-2021-23758
Unauthenticated .NET Deserialization RCE in Ajax.NET Professional (ajaxpro.2)

Ajax.NET Professional (distributed as the ajaxpro.2 package) is vulnerable to insecure deserialization (CWE-502): it deserializes arbitrary .NET classes supplied by the client without validating which types may be instantiated. Because AjaxPro exposes HTTP endpoints for browser-to-server AJAX calls, a remote, unauthenticated attacker can send a crafted serialized payload to any reachable AjaxPro endpoint and abuse .NET deserialization gadget chains to execute code on the server. Successful exploitation yields full remote code execution with high impact on confidentiality, integrity, and availability (CVSS 3.1 score of 9.8, network vector, no privileges or user interaction required). Any application running any version of ajaxpro.2 / Ajax.NET Professional is affected; the provided data specifies no fixed version, so defenders must rely on vendor guidance for patched releases. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-08-26, carries an EPSS 30-day exploitation probability of 83.6%, has public PoC code available, and Talos Intelligence reporting links it to the Chinese-speaking threat actor UAT-10147, which deploys the SPECTRE malware with an EDR bypass and a Linux rootkit in post-compromise operations.

Do: Inventory your ASP.NET estate for AjaxPro usage (web.config references, AjaxPro HTTP handlers) and prioritize any internet-facing instance for remediation. Upgrade ajaxpro.2 to the latest vendor release per vendor instructions — the provided data specifies no fixed version — or, if patching is not immediately possible, restrict or block access to AjaxPro endpoints from the internet. Because the flaw is on CISA's KEV under BOD 26-04, apply mitigations within the required timeline and hunt exposed servers for post-compromise tooling, as Talos reports UAT-10147 deploying SPECTRE with an EDR bypass and a Linux rootkit.

9.884% KEV PoC ×2
  • michaelschwarz (ajaxpro.2 project) ajaxpro.2 (package) All versions are vulnerable; no fixed version specified in the provided data
  • michaelschwarz Ajax.NET Professional All versions are vulnerable; no fixed version specified in the provided data
unknown (no public install-base or internet-exposure counts available for this legacy library)
CVE-2019-1068
Remote Code Execution in Microsoft SQL Server 2016 and 2017

CVE-2019-1068 is a remote code execution vulnerability in Microsoft SQL Server caused by improper handling of the processing of internal functions (CWE-20, improper input validation). An attacker who can reach SQL Server over the network with low-privileged credentials can trigger the flawed code path and execute arbitrary code, gaining high confidentiality, integrity, and availability impact on the database host. Any organization running affected Microsoft SQL Server versions — including SQL Server 2016 and SQL Server 2017 — is affected. The flaw carries a high EPSS score (52.8% probability of exploitation within 30 days, 99th percentile) and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-08-26, with headlines reporting it being exploited in active attacks. No public proof-of-concept is known, but the in-the-wild exploitation documented by CISA makes patching urgent; the fix shipped in Microsoft's July 2019 Patch Tuesday security updates.

Do: Apply Microsoft's July 2019 security updates (cumulative updates) for SQL Server 2016 and SQL Server 2017 as directed in the vendor advisory, and inventory all SQL Server instances — especially those reachable on TCP 1433 from the internet — prioritizing exposed or low-privilege-accessible instances. Given the KEV listing, CISA's BOD 26-04 requires patching per vendor instructions (or discontinuing use if mitigation is unavailable) on a prioritized timeline; restrict network access to SQL Server and confirm no unexpected low-privileged accounts or unusual process activity on database hosts as a triage check.

8.853% KEV
  • Microsoft SQL Server
  • microsoft SQL Server 2016
  • microsoft SQL Server 2017
massmillions of SQL Server deployments worldwide, with roughly 1M+ instances exposed on TCP 1433 in public internet scans
CVE-2008-4128
Cross-Site Request Forgery in Cisco IOS 12.4 HTTP Management Interface

Cisco IOS 12.4 contains multiple cross-site request forgery (CWE-352) flaws in the IOS HTTP management web interface that allow a remote attacker to execute arbitrary commands on the device. The flaws are triggered when an attacker induces an already-authenticated privileged (level 15) administrator's browser to send crafted HTTP requests to the router's web server, for example a "show privilege" command via the /level/15/exec/- URI or an "alias exec" configuration command via the /level/15/exec/-/configure/http URI, letting the attacker run commands with the administrator's privileges, potentially including device reconfiguration. Any Cisco IOS 12.4 device with the HTTP/HTTPS management server enabled and reachable from an administrator's browser is affected. CISA added the issue to the Known Exploited Vulnerabilities catalog on 2026-07-13, indicating known exploitation in the wild, and EPSS assigns a 33.9% probability of exploitation in the next 30 days (98th percentile); no public proof-of-concept is known and ransomware use is not confirmed.

Do: Inventory Cisco IOS devices for the 'ip http server' / 'ip http secure-server' configuration, and disable the HTTP/HTTPS management server where it is not needed or restrict it to management networks via access control lists. Apply Cisco's vendor-recommended fixed IOS release for CVE-2008-4128 in line with CISA BOD 26-04 deadlines, prioritizing internet-facing routers. Because exploitation is confirmed, also review device configurations and logs for unauthorized 'alias exec' entries or unexpected configuration changes.

34% KEV
  • Cisco IOS 12.4 (the only version specified in the source data)
largelikely tens of thousands of internet-exposed Cisco IOS devices with the HTTP management server enabled (unknown exact count)