ZeroHour

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2009-0238
Remote Code Execution in Microsoft Office Excel via Crafted Spreadsheet

CVE-2009-0238 is a remote code execution vulnerability in Microsoft Office Excel involving improper handling of a malformed object embedded in a specially crafted spreadsheet (code-injection class flaw, CWE-94). It is triggered when a user opens the malicious Excel file; no authentication or user interaction beyond opening the document is required. A successful attack lets the attacker run code in the context of the logged-in user and potentially take complete control of the affected system. Any organization running the affected Microsoft Office/Excel versions is exposed, with risk concentrated where users open spreadsheets from untrusted sources. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-04-14, confirming exploitation in the wild; ransomware use is unknown, no public proof-of-concept is known, and EPSS assigns a 43.1% probability of exploitation within 30 days (99th percentile).

Do: Apply Microsoft's security update for Office/Excel across the estate, prioritizing legacy Office installs and endpoints that handle untrusted spreadsheets, and verify via inventory that no unpatched Excel versions remain; per the CISA KEV listing and BOD 22-01, federal agencies must apply vendor mitigations by the required deadline or discontinue use. Until patched, discourage opening Excel files from untrusted sources and consider blocking or sandboxing spreadsheet attachments in email.

43% KEV
  • Microsoft Office (Excel component)
masshundreds of millions of Office/Excel seats historically; current unpatched exposure likely in the hundreds of thousands, mainly legacy or unmanaged Office…
CVE-2012-1854
Insecure Library Loading (CWE-426) in Microsoft Visual Basic for Applications

Microsoft Visual Basic for Applications (VBA) fails to fully specify the search path used when loading dynamic-link libraries, so applications embedding VBA may load a library from an attacker-controlled directory rather than a trusted one (CWE-426). An attacker triggers the flaw by convincing a user to open a crafted document or file in a location the attacker controls, such as a network share or web-accessible folder, causing a malicious DLL placed alongside the file to be loaded. Successful exploitation yields remote code execution with the privileges of the logged-on user, potentially giving attackers a foothold for follow-on activity such as malware or ransomware deployment. Any environment running Microsoft products that embed VBA is potentially affected, and typical exposure is broad because VBA ships with Microsoft Office deployments. The flaw was added to the CISA Known Exploited Vulnerabilities catalog on 2026-04-13, indicating confirmed in-the-wild exploitation, with a 21% EPSS probability of exploitation in the next 30 days (97th percentile).

Do: Apply Microsoft's mitigations per the CISA KEV required action and applicable BOD 22-01 guidance, prioritizing patching of Microsoft Office/VBA components in line with Microsoft's advisory for this vulnerability. As interim mitigation, prevent applications from loading libraries from untrusted, user-writable directories (e.g., avoid opening untrusted documents from network shares, web folders, or download locations) and ensure system-wide DLL search safety settings are enabled. Because there is no known public PoC and exploitation is confirmed in the wild, treat this as a high-priority remediation item and check patch-management and vulnerability-management records for coverage across Office/VBA-bearing endpoints.

21% KEV
  • Microsoft Visual Basic for Applications (VBA)
masshundreds of millions of users potentially affected (VBA is embedded in Microsoft Office, which is deployed on the vast majority of enterprise and consumer…
CVE-2020-9715
Use-After-Free Code Execution Flaw in Adobe Acrobat

Adobe Acrobat contains a use-after-free memory-corruption flaw (CWE-416) that can lead to arbitrary code execution. The condition is triggered when the application processes specially crafted PDF content, freeing memory that is later reused, typically when a user opens a malicious PDF file. A successful exploit lets an attacker run code in the context of the current user, potentially enabling malware installation or further compromise of the workstation. Any environment running an unpatched version of Adobe Acrobat is affected, particularly fleets still on legacy or unmanaged builds. CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2026-04-13, confirming exploitation in the wild; its 48.6% EPSS score (99th percentile) signals a high likelihood of near-term exploitation, while no public proof-of-concept is known and ransomware association is unconfirmed.

Do: Update Adobe Acrobat to the latest release available from Adobe; the fix shipped in Adobe's 2020 security updates, so any installation not updated since then remains vulnerable. Because the flaw is now in the CISA KEV catalog, inventory installed Acrobat versions across the estate and treat unpatched hosts as actively targeted, following BOD 22-01 guidance for federal systems. As an interim mitigation, restrict opening of untrusted PDFs and use Acrobat's protected/preview mode until patching is complete.

7.849% KEV PoC
  • Adobe Acrobat
masshundreds of millions of desktop installations worldwide (dominant PDF-viewer installed base)
CVE-2023-21529
Authenticated Deserialization RCE in Microsoft Exchange Server (CVE-2023-21529)

CVE-2023-21529 is a deserialization-of-untrusted-data flaw (CWE-502) in on-premises Microsoft Exchange Server that allows remote code execution. Per its CVSS vector, an attacker with valid low-privileged credentials (PR:L) sends crafted untrusted serialized data to the server over the network, requiring no user interaction. Successful exploitation yields code execution on the Exchange server, exposing mail stores and providing a foothold for lateral movement, and related coverage ties it to the fast-moving Storm-1175 ransomware operation, with ransomware use listed as known in CISA's KEV entry. Organizations running self-hosted Exchange Server are in scope; the source data does not list specific affected builds, but the fix shipped in Microsoft's February 2023 Patch Tuesday updates. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-04-13, EPSS estimates a 62.1% probability of exploitation within 30 days (99th percentile), and no public proof-of-concept is known.

Do: Apply the February 2023 Exchange Server security updates to every on-premises Exchange server; U.S. federal agencies must mitigate or patch per BOD 22-01 following the KEV listing. Because exploitation requires authenticated low-privilege access, inventory exposed OWA/ECP endpoints, review and rotate credentials, and hunt for compromise indicators (unusual processes, webshells, unexpected mailbox activity) given known ransomware use.

8.862% KEV ransomware
  • Microsoft Exchange Server
mass≈50,000–100,000 internet-exposed on-prem Exchange servers; on-prem Exchange plausibly hosts 1M+ users worldwide
CVE-2023-27351
Authentication Bypass in PaperCut NG/MF Print Management Software

CVE-2023-27351 is an improper authentication flaw (CWE-287) in the SecurityRequestFilter class of PaperCut NG and MF print management software, where the authentication algorithm is improperly implemented. A remote, unauthenticated attacker can trigger it over the network with no user interaction or special privileges to bypass authentication on the affected server (CVSS 3.1: 7.5). Once authentication is bypassed, the attacker gains access to the PaperCut system; in observed campaigns this access was leveraged to deliver Cl0p and LockBit ransomware, as confirmed by Microsoft. Organizations running PaperCut NG (version 22.0.5, Build 63914, is cited in the advisory) or PaperCut MF are affected. The flaw was exploited as a zero-day, is CISA KEV-listed (added 2026-04-20) with known ransomware use, and EPSS places the 30-day exploitation probability at 78.1%.

Do: Upgrade PaperCut NG/MF to the fixed release per the vendor's emergency patch advisory, first confirming the running build (NG 22.0.5, Build 63914, is cited as affected). Restrict internet-facing access to PaperCut servers and hunt for signs of post-exploitation, given confirmed use to deliver Cl0p and LockBit ransomware. US federal agencies must apply mitigations per CISA BOD 22-01 (or vendor instructions) or discontinue use of the product if mitigations are unavailable.

7.578% KEV ransomware
  • PaperCut NG 22.0.5 (Build 63914) explicitly cited as affected; CISA lists PaperCut NG broadly without a full version range
  • PaperCut MF affected per CISA listing; no specific version range provided in the data
large≈75,000+ sites/organizations (PaperCut NG/MF is deployed at tens of thousands of organizations; public scans have found thousands of servers directly…
CVE-2023-36424
Local Privilege Escalation via Out-of-Bounds Read in Windows CLFS Driver

CVE-2023-36424 is an out-of-bounds read (CWE-125) in the Windows Common Log File System (CLFS) driver, a kernel component responsible for managing log files on Windows. A local attacker who can already execute limited-privilege code on an affected system can trigger the bug through crafted interaction with log file data, with no user interaction required. Successful exploitation yields elevation of privilege, giving the attacker high-privilege (typically SYSTEM-level) control of the host — a common post-exploitation step in broader intrusion and ransomware chains. All branches named in the advisory are affected — Windows 10 (1507, 1607, 1809, 21H2, 22H2), Windows 11 (21H2, 22H2, 23H2), and Windows Server 2008, 2012, 2016 and 2019 — making this effectively a fleet-wide Windows issue. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-04-13, confirming exploitation in the wild; EPSS puts the 30-day exploitation probability at 12.2% (96th percentile), while ransomware use is listed as unknown and no public proof-of-concept is known.

Do: Apply Microsoft's security update for CVE-2023-36424 across all affected Windows 10/11 and Windows Server versions, prioritizing servers and admin workstations where a local SYSTEM-level escalation directly enables lateral movement, and use patch inventory to confirm the cumulative update containing the CLFS fix is installed on every host. Federal agencies must meet the BOD 22-01 remediation deadline (two weeks after the 2026-04-13 KEV addition). Because there is no public proof-of-concept and detections are limited, patching — rather than monitoring — is the primary mitigation.

7.812% KEV
  • Microsoft Windows 10 1507, 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 21H2, 22H2, 23H2
  • Microsoft Windows Server 2008, 2012, 2016, 2019
mass≈1 billion+ installations (Windows 10/11 PCs and Windows Server hosts running the affected versions)
CVE-2024-1708
Path Traversal RCE in ConnectWise ScreenConnect (CVE-2024-1708)

ConnectWise ScreenConnect 23.9.7 and prior contain a path-traversal flaw (CWE-22, rated 8.4 high) that can allow an attacker to execute remote code or access confidential data and critical systems. Public analysis (Huntress) shows it is triggered by manipulating directory paths in the product's administrative setup wizard, and that it is typically chained with a companion authentication-bypass flaw (CVE-2024-1709) disclosed at the same time to achieve unauthenticated remote code execution on the ScreenConnect server. An attacker who compromises a ScreenConnect server gains control of the remote-access platform itself and can pivot to every endpoint that server manages, making it an efficient foothold for ransomware. Any organization running ScreenConnect 23.9.7 or earlier is affected, most commonly MSPs and IT teams that use the tool to manage client and internal machines. The flaw is being actively exploited in the wild: it is listed in CISA's Known Exploited Vulnerabilities catalog with known ransomware use, EPSS puts the 30-day exploitation probability at 95.5% (100th percentile), and recent reporting ties fast-moving exploitation to the Storm-1175 activity cluster, which drops Medusa ransomware.

Do: Immediately update all self-hosted ScreenConnect instances to a release newer than 23.9.7 per ConnectWise's advisory, and ensure the companion authentication-bypass flaw (CVE-2024-1709) is patched at the same time; federal agencies must follow BOD 22-01 mitigation timelines per the KEV listing. Because exploitation is fast-moving and linked to ransomware operations, hunt for signs of compromise such as unexpected new administrative accounts, setup-wizard activity, or unusual remote sessions on exposed servers. Separately, ConnectWise has disclosed a breach of its own infrastructure by a nation-state actor, so review vendor communications for any updated guidance.

8.495% KEV ransomware PoC
  • ConnectWise ScreenConnect 23.9.7 and prior
large≈ tens of thousands of ScreenConnect deployments (thousands of internet-exposed servers; millions of managed endpoints)
CVE-2024-27199
Path Traversal in JetBrains TeamCity Allows Limited Admin Actions

JetBrains TeamCity, a widely used continuous integration/continuous delivery (CI/CD) server, contains a relative path traversal vulnerability (CWE-23) in which the application fails to properly neutralize traversal sequences in file paths. An attacker who can reach the vulnerable component can supply crafted relative paths that escape the intended directory, gaining the ability to perform limited administrative actions on the TeamCity server. Any organization running an affected JetBrains TeamCity deployment, especially instances exposed to the internet or reachable by untrusted users, is potentially affected. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2026-04-20 with known ransomware use, and the EPSS model assigns it a 100% probability of exploitation within the next 30 days. No public proof-of-concept is known, but the KEV listing confirms active exploitation in the wild per CISA.

Do: Upgrade TeamCity to the patched release identified in JetBrains' security bulletin, or if patching is not immediately possible, apply vendor-recommended mitigations and restrict internet access to the server; federal agencies must follow BOD 22-01 guidance, including for cloud service offerings, or discontinue use if mitigations are unavailable. Given the known ransomware association, review TeamCity logs, admin accounts, and build-agent activity for signs of tampering as part of remediation.

7.3100% KEV ransomware PoC
  • JetBrains TeamCity Affected as listed by CISA; the source data provides no specific affected version ranges, so verify exact affected and patched versions in JetBrains' security b
large~10,000-30,000 TeamCity server deployments, with a meaningful share of those exposed directly to the internet (order of magnitude 10^4)
CVE-2024-3721
A vulnerability was found in TBK DVR-4104 and DVR-4216 up to 20240412 and classified as critical.

A vulnerability was found in TBK DVR-4104 and DVR-4216 up to 20240412 and classified as critical. This issue affects some unknown processing of the file /device.rsp?opt=sys&cmd=___S_O_S_T_R_E_A_MAX___. The manipulation of the argument mdb/mdc leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-260573 was assigned to this vulnerability.

NVD description · AI analysis pending
6.386%
CVE-2024-57726
+1 in the same advisory: …57728
Missing-Authorization Privilege Escalation in SimpleHelp Remote Support <= 5.5.7

SimpleHelp remote support software versions 5.5.7 and earlier contain a missing-authorization flaw (CWE-862) that lets low-privileged technicians create API keys with excessive permissions. A network attacker holding only a technician-level account can mint such an over-privileged API key and use it to escalate to the SimpleHelp server admin role, with no user interaction required (CVSS 3.1 score 9.9, scope changed). Successful exploitation yields full administrative control of the SimpleHelp server, the remote-access/RMM platform support staff use to reach endpoints, which can also expose downstream customer environments when the server is run by an MSP. Any organization running SimpleHelp 5.5.7 or earlier is affected, with MSPs at particular risk given their downstream reach. The flaw is confirmed exploited in the wild: it was added to CISA KEV on 2026-04-24 with known ransomware use, carries a 66.6% EPSS score (99th percentile), and public reporting describes ransomware operators chaining SimpleHelp flaws in double-extortion attacks against an MSP and its customers.

Do: Upgrade SimpleHelp to the latest vendor release newer than 5.5.7 and apply vendor mitigation guidance; federal agencies must meet BOD 22-01 requirements or discontinue use. Audit existing API keys (especially those created by technician accounts) for excessive permissions, review audit logs for unexpected key creation or admin activity, and restrict internet exposure of SimpleHelp servers. Organizations whose MSP uses SimpleHelp should confirm the MSP's instance is patched before trusting remote sessions.

9.9
group max
67% KEV ransomware
  • SimpleHelp remote support software 5.5.7 and earlier
moderatelow thousands of exposed self-hosted SimpleHelp server deployments (est.), amplified to many downstream endpoints where instances are run by MSPs
CVE-2024-7399
Unauthenticated Path Traversal File Write in Samsung MagicINFO 9 Server

CVE-2024-7399 is a critical path-traversal flaw (CWE-22, tracked alongside CWE-434 unrestricted file upload) in Samsung MagicINFO 9 Server, Samsung's on-premises digital signage content-management platform, affecting all versions before 21.1050. Because the server fails to properly constrain a user-supplied pathname, an unauthenticated remote attacker (CVSS: AV:N/AC:L/PR:N/UI:N) can submit a crafted path and have arbitrary files written outside the intended directory with system authority — typically enabling webshell or malicious payload placement and, in practice, full server compromise. Any organization running an affected MagicINFO 9 Server instance, especially one reachable from the internet, is exposed. Exploitation is confirmed: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2026-04-24 with a May 2026 federal patching deadline, EPSS assigns a 91.9% probability of exploitation within 30 days (100th percentile), and recent reporting describes threat actors exploiting MagicINFO 9 Server flaws — this traversal and the related CVE-2025-4632 — to deploy the Mirai botnet, though accounts of which specific CVE is in use have been mixed.

Do: Upgrade MagicINFO 9 Server to version 21.1050 or later per Samsung's advisory; as interim mitigation, restrict internet exposure of the server and inspect the host for unexpected files, webshells, or dropped binaries (e.g., Mirai artifacts) indicating post-exploitation. Federal agencies under BOD 22-01 must apply the update or remove the product by the May 2026 KEV deadline; given the near-certain EPSS score and confirmed in-the-wild use — despite no known public PoC — treat this as a priority patch.

9.892% KEV
  • Samsung MagicINFO 9 Server all versions before 21.1050
moderatelikely on the order of thousands of internet-exposed MagicINFO 9 Server instances; total on-premises installed base unknown
CVE-2025-2749
Path Traversal to Authenticated RCE in Kentico Xperience Through 13.0.178

CVE-2025-2749 is a path traversal and unrestricted file upload flaw (CWE-22/CWE-434) in the Staging Sync Server component of Kentico Xperience, exploitable by an authenticated user with staging sync privileges. The user can upload arbitrary data to path-relative locations, escaping the intended upload directory and writing attacker-controlled files — including executable server-side content such as script files — anywhere the application can reach, resulting in remote code execution on the server. Successful exploitation yields full confidentiality, integrity, and availability impact on the host (CVSS 3.1: 7.2 High, network-accessible with high privileges required). All Kentico Xperience versions through 13.0.178 are affected, primarily deployments where the Staging Sync Server endpoint is reachable by attackers or by accounts with weak or stolen credentials. The flaw is confirmed actively exploited — it was added to the CISA Known Exploited Vulnerabilities catalog on 2026-04-20 — and a public technical write-up with proof-of-concept details is available from watchTowr Labs.

Do: Upgrade Kentico Xperience to a hotfix release later than 13.0.178 per the vendor's instructions (federal agencies must follow BOD 22-01 guidance or the KEV-required action by the stated deadline). Until patched, restrict access to the Staging Sync Server endpoint (e.g., via VPN/firewall allowlisting) and review high-privilege staging/sync accounts for suspicious use. Hunt for signs of compromise such as unexpected executable or script files uploaded outside intended directories and webshells in the web root, since the vulnerability is listed in CISA's KEV as actively exploited.

7.24% KEV PoC
  • Kentico Xperience all versions through 13.0.178 (inclusive)
large≈ tens of thousands (10k–100k) of Kentico Xperience deployments, with an unknown but smaller subset exposing the staging sync endpoint to the internet
CVE-2025-29635
Authenticated Command Injection in D-Link DIR-823X Routers Exploited by Mirai Botnet

CVE-2025-29635 is a command injection flaw (CWE-77) in D-Link DIR-823X router firmware builds 240126 and 240802 that permits arbitrary command execution on the device. It is triggered by sending a crafted POST request to the /goform/set_prohibiting endpoint, and because the flaw requires high privileges (CVSS PR:H), the attacker must hold valid administrative credentials, which in botnet campaigns is typically achieved via default or weak passwords. Successful exploitation yields full remote command execution on the router, which in the observed campaign has been used by Mirai-variant botnets to enroll devices for DDoS activity. Any DIR-823X running the listed firmware builds is affected, with exposure concentrated in units whose web administration interface is reachable from the internet. The flaw was added to CISA's KEV catalog on 2026-04-24 after documented in-the-wild exploitation (an Akamai report on a Mirai campaign and a public PoC), and its EPSS score of 87.9% places it in the top percentile for near-term exploitation risk.

Do: Apply updated DIR-823X firmware per D-Link's guidance (a fixed build is not specified in this data) or the applicable BOD 22-01 mitigation deadline, reported as May 2026 for federal agencies. Until patched, ensure the router's admin interface is not exposed to the WAN and change default/weak credentials, since exploitation requires valid administrative access. Check devices for indicators of Mirai-style compromise (unexpected processes, outbound scanning or DDoS traffic) and review logs for POST requests to /goform/set_prohibiting from untrusted sources.

7.288% KEV PoC ×2
  • D-Link DIR-823X firmware 240126 and 240802 (the builds named in the advisory; no fixed version is specified in this data)
moderatelikely thousands of internet-exposed DIR-823X routers (roughly 1k-10k units directly attackable; installed base of the model could be higher)
CVE-2025-32975
Authentication Bypass in Quest KACE Systems Management Appliance (SSO)

Quest KACE Systems Management Appliance (SMA) versions in the 13.0.x through 14.1.x branches, prior to the fixed builds, contain an improper authentication flaw (CWE-287) in the SSO authentication handling mechanism. Because the bypass requires no valid credentials, privileges, or user interaction and is reachable over the network, an attacker who can reach the appliance can impersonate legitimate users and achieve complete administrative takeover. Any organization running an affected SMA build is exposed, particularly where the appliance's web interface is reachable from untrusted networks. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-04-20, and press reporting describes attackers hijacking unpatched SMA systems, with compromises at roughly 60 organizations cited; ransomware use is not yet confirmed.

Do: Upgrade affected SMA deployments to the fixed build for their branch — 13.0.385, 13.1.81, 13.2.183, 14.0.341 (Patch 5), or 14.1.101 (Patch 4) or later — prioritizing internet-facing appliances. Since the flaw is actively exploited and grants full admin takeover, review appliance logs and administrator accounts for signs of compromise (unexpected SSO sessions, new or altered accounts) and restrict access to the SMA web interface to trusted networks per Quest's guidance. U.S. federal agencies must apply the required mitigations or discontinue use under BOD 22-01 by the KEV deadline.

10.02% KEV
  • Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385
  • Quest KACE Systems Management Appliance (SMA) 13.1.x before 13.1.81
  • Quest KACE Systems Management Appliance (SMA) 13.2.x before 13.2.183
  • +2 more
largetens of thousands of deployed SMA appliances worldwide, with likely only a low-thousands subset internet-exposed
CVE-2025-48700
Cross-Site Scripting in Synacor Zimbra Collaboration Suite Classic UI

Zimbra Collaboration Suite (ZCS) 8.8.15, 9.0, 10.0, and 10.1 contain a cross-site scripting (XSS) flaw in the Classic UI caused by insufficient sanitization of HTML email content, involving crafted tag structures and attribute values that use @import directives and other script injection vectors. An attacker triggers it simply by getting a user to view a crafted email message in the Classic UI, with no additional user interaction required. Successful exploitation executes arbitrary JavaScript within the victim's session, potentially exposing sensitive mailbox information or enabling unauthorized actions under the victim's identity. Any organization running the affected ZCS branches — particularly internet-facing mail servers whose users receive untrusted email — is in scope. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-04-20, confirming active exploitation in the wild; no public proof-of-concept is known, and EPSS puts 30-day exploitation probability at about 1.7%.

Do: Upgrade ZCS to the latest patched builds of the affected 8.8.15/9.0/10.0/10.1 branches per Synacor/Zimbra's security advisory (no specific fixed version is listed here); federal agencies must apply vendor mitigations per BOD 22-01 or discontinue use. Because the flaw is specific to the Classic UI, having users work in the Modern UI instead of the Classic UI reduces exposure until patching is complete. Review mail server and web client logs for users who viewed suspicious HTML-formatted messages as an indicator of targeting.

6.12% KEV
  • Synacor Zimbra Collaboration Suite (ZCS) Classic UI 8.8.15, 9.0, 10.0, and 10.1
largeon the order of tens of thousands of internet-exposed Zimbra servers
CVE-2025-60710
Link Following Privilege Escalation in Microsoft Windows Host Process for Tasks

CVE-2025-60710 is a link-following flaw (CWE-59, improper link resolution before file access) in the Host Process for Windows Tasks on Microsoft Windows. A local attacker with limited (low-privilege) access can trigger the flaw by causing the host process to follow a manipulated link or junction/symlink during file access, redirecting its privileged file operations. Successful exploitation yields elevation of privilege on the local system, with high impact to confidentiality, integrity, and availability (CVSS 3.1: 7.8). Affected systems are Windows 11 24H2, Windows 11 25H2, and Windows Server 2025. The vulnerability is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-04-13 with known ransomware use, and EPSS estimates a 4.6% chance of exploitation in the next 30 days (91st percentile).

Do: Apply Microsoft's current security updates for Windows 11 24H2, Windows 11 25H2, and Windows Server 2025 as soon as possible, prioritizing servers and workstations accessible to ransomware operators; the local attack vector means any compromised low-privileged account or endpoint is sufficient. Federal agencies and BOD 22-01-covered organizations must remediate or apply vendor mitigations per the KEV required action within the standard KEV timeline. Inventory systems still running unpatched 24H2/25H2 and Server 2025 builds, and monitor for post-compromise local privilege escalation activity as part of ransomware incident response.

7.85% KEV ransomware
  • microsoft Windows 11 24H2 24H2 (all builds prior to the vendor security update; no specific version range provided in source data)
  • microsoft Windows 11 25H2 25H2 (all builds prior to the vendor security update; no specific version range provided in source data)
  • microsoft Windows Server 2025 2025 (all builds prior to the vendor security update; no specific version range provided in source data)
masshundreds of millions of endpoints (Windows 11 24H2/25H2 workstations plus Windows Server 2025 deployments)
CVE-2026-1340
Unauthenticated Code Injection RCE in Ivanti Endpoint Manager Mobile

CVE-2026-1340 is a code injection flaw (CWE-94) in Ivanti Endpoint Manager Mobile (EPMM), Ivanti's enterprise mobile device management platform, that permits unauthenticated remote code execution. Because the flaw is network-reachable and requires no privileges or user interaction (AV:N/AC:L/PR:N/UI:N), a remote attacker can send a crafted request to a vulnerable EPMM server and execute arbitrary code, with high impact to confidentiality, integrity, and availability. Any organization operating an affected EPMM server is affected, especially those exposing the management or device-enrollment interface to the internet. The flaw was added to CISA's KEV catalog on 2026-04-08 with an 86.2% probability of exploitation within 30 days; news reporting describes active zero-day attacks against EPMM (alongside related CVE-2026-6973), including a confirmed Dutch government incident exposing employee contact data, while ransomware use remains unconfirmed. A large share of observed exploit traffic has been traced to a single IP address on bulletproof hosting infrastructure.

Do: Apply Ivanti's patched EPMM release per the vendor advisory immediately and verify the fix on any internet-facing EPMM portal; US federal agencies must follow BOD 22-01 mitigation deadlines. Until patched, restrict EPMM portal access to trusted networks/VPNs and review access logs for suspicious requests or unrecognized source IPs, noting that much exploit activity has originated from a single bulletproof-hosting IP.

9.886% KEV
  • Ivanti Endpoint Manager Mobile (EPMM)
large≈ tens of thousands of EPMM server deployments, a large share of them internet-exposed
CVE-2026-20122
Arbitrary File Overwrite via Privileged APIs in Cisco Catalyst SD-WAN Manager

Cisco Catalyst SD-WAN Manager (the platform formerly known as vManage) contains an incorrect use of privileged APIs flaw (CWE-648) stemming from improper file handling on its API interface. An attacker exploits it by uploading a malicious file through the API interface onto the local file system of an affected system. A successful exploit allows the attacker to overwrite arbitrary files on the system and gain vmanage user privileges, which typically means administrative control of the SD-WAN management plane. Any organization running Catalyst SD-WAN Manager, whether on-premises appliances or virtual instances managing an SD-WAN overlay or instances hosted in Cisco's cloud, is potentially affected; CISA has not published affected version ranges or a CVSS score, and the flaw was disclosed alongside other Cisco product vulnerabilities. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2026-04-20, indicating exploitation in the wild, EPSS estimates a 24.6% probability of exploitation within 30 days (98th percentile), no public proof-of-concept is known, and ransomware use is unknown.

Do: Follow CISA's Emergency Directive 26-03 and the Hunt & Hardening Guidance for Cisco SD-WAN Devices to identify exposed SD-WAN Manager instances and hunt for signs of exploitation, and prioritize applying the fixed releases cited in Cisco's advisory once version ranges are published. Until patched, restrict and monitor access to the SD-WAN Manager API interface; organizations using Cisco's cloud-hosted SD-WAN service should adhere to the applicable BOD 22-01 cloud guidance or discontinue use if mitigations are unavailable.

5.425% KEV
  • Cisco Catalyst SD-WAN Manager
large≈ tens of thousands of deployed SD-WAN Manager (vManage) management nodes worldwide
CVE-2026-20133
+1 in the same advisory: …20128
Actively Exploited Information Disclosure in Cisco Catalyst SD-WAN Manager

Cisco Catalyst SD-WAN Manager, the central management and monitoring platform for Cisco SD-WAN fabrics (formerly known as vManage), contains a sensitive-information-exposure flaw (CWE-200) that allows remote attackers to view sensitive information on affected systems. The available data does not specify the exact trigger path or authentication requirements, but the flaw is remotely exploitable by unauthorized actors. An attacker gains access to sensitive information held on the management platform, which aggregates inventory, configuration, and telemetry for an entire SD-WAN overlay, potentially aiding follow-on attacks. Any organization running an affected release of Cisco Catalyst SD-WAN Manager is in scope. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on 2026-04-20, confirming exploitation in the wild, and EPSS assigns a 31.4% probability of exploitation within 30 days (98th percentile), although CVSS scoring is pending and no public proof-of-concept is known.

Do: Inventory your environment for internet-exposed Catalyst SD-WAN Manager instances and review access logs for signs of unauthorized retrieval of sensitive information, since the flaw is listed as exploited in the wild. Apply the vendor fix referenced in Cisco's advisory for CVE-2026-20133 when available, and follow CISA's Emergency Directive 26-03 and the CISA 'Hunt & Hardening Guidance for Cisco SD-WAN Devices'; federal agencies must adhere to applicable BOD 22-01 mitigation timelines or discontinue use of the product if mitigations are unavailable.

7.531% KEV
  • Cisco Catalyst SD-WAN Manager
large≈tens of thousands of deployments (Cisco has publicly cited 30,000+ SD-WAN customers, each operating at least one Manager controller)
CVE-2026-21643
Unauthenticated SQL Injection to Code Execution in Fortinet FortiClient EMS 7.4.4

CVE-2026-21643 is a critical SQL injection flaw (CWE-89, improper neutralization of special elements used in an SQL command) in Fortinet FortiClient EMS 7.4.4, scored 9.8 critical (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). An unauthenticated remote attacker can trigger it by sending specifically crafted HTTP requests to the EMS server, and successful injection allows execution of unauthorized code or commands, yielding high confidentiality, integrity, and availability impact. Any organization running the affected FortiClient EMS release is exposed, with internet-facing EMS management servers at greatest risk. Exploitation is confirmed: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2026-04-13, EPSS assigns a 94.1% probability of exploitation within 30 days (99.9th-plus percentile), and news reports describe active zero-day exploitation that prompted Fortinet to issue emergency patches, alongside related FortiClient EMS hotfixes (CVE-2026-35616).

Do: Upgrade affected FortiClient EMS 7.4.4 deployments using the emergency patch/hotfix Fortinet has released (see the Fortinet PSIRT advisory for fixed builds), prioritizing internet-exposed EMS servers; federal agencies must satisfy the BOD 22-01 requirement per the KEV listing. Until patched, restrict public exposure of the EMS web interface and review web access and database logs for signs of crafted HTTP requests or unexpected command execution.

9.894% KEV PoC
  • Fortinet FortiClient EMS 7.4.4 (version listed by CISA; fixed builds per the Fortinet PSIRT advisory/emergency patch)
largeon the order of tens of thousands of FortiClient EMS server deployments (estimate)
CVE-2026-32201
Improper Input Validation Spoofing Vulnerability in Microsoft SharePoint Server

Microsoft SharePoint Server contains an improper input validation flaw (CWE-20) that can be triggered by an unauthenticated, network-based attacker submitting crafted input to the server. Successful exploitation allows the attacker to perform spoofing over the network, impersonating a trusted user or source within SharePoint; detailed impact mechanics have not been published and no CVSS score or public proof-of-concept is available. Any organization running on-premises Microsoft SharePoint Server is potentially affected, and the available data does not specify affected version ranges. CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2026-04-14, indicating evidence of active exploitation, and EPSS assigns a 42.8% probability of exploitation within 30 days (99th percentile). Ransomware association is currently unknown.

Do: Apply Microsoft's security updates for SharePoint Server per the vendor advisory as soon as possible, and identify your SharePoint Server versions and builds since specific affected ranges are not provided here. Given the KEV listing, federal agencies must apply the vendor mitigations, follow applicable BOD 22-01 cloud guidance, or discontinue use by the established deadline. Until patched, limit network exposure of SharePoint servers and review authentication and access logs for signs of impersonation or spoofing activity.

6.543% KEV
  • Microsoft SharePoint Server
masslikely on the order of 100,000+ on-premises SharePoint Server installations, of which tens of thousands are directly internet-exposed
CVE-2026-32202
Spoofing Flaw in Windows Shell (CVE-2026-32202) Actively Exploited

A protection mechanism in the Windows Shell fails (CWE-693), allowing an unauthorized attacker to perform spoofing against the shell over a network. Per the CVSS vector, the attack is network-based, requires no privileges or special conditions, but does require the targeted user to interact with attacker-supplied content. The impact is limited to confidentiality: an attacker can misrepresent information presented through the Windows Shell, gaining a spoofing foothold rather than code execution, privilege escalation, or persistence. Any organization running the affected Windows 10, Windows 11, or Windows Server builds is exposed, which effectively means most Windows estates. Microsoft has confirmed active exploitation, CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2026-04-28, and a fix shipped in Microsoft's April 2026 Patch Tuesday release.

Do: Apply Microsoft's April 2026 security updates to all affected Windows 10, Windows 11, and Windows Server hosts as a priority; the flaw is on CISA's KEV catalog, so U.S. federal agencies must patch within BOD 22-01 timelines or apply vendor-recommended mitigations. Until patched, note that exploitation requires user interaction with spoofed shell content, so user awareness about verifying shell-rendered information is a partial mitigations. No public PoC is known, but confirmed in-the-wild exploitation warrants prioritizing user-facing and internet-reachable systems for patching.

4.364% KEV
  • microsoft Windows 10 1607
  • microsoft Windows 10 1809
  • microsoft Windows 10 21H2
  • +9 more
mass~1 billion+ Windows devices (affected builds span all supported Windows 10 and Windows 11 desktops plus Windows Server 2012-2022)
CVE-2026-33032
Unauthenticated MCP Endpoint Access in Nginx UI Enables Full Nginx Server Takeover

Nginx UI versions 2.3.5 and prior ship a Model Context Protocol (MCP) integration exposed via two HTTP endpoints, /mcp and /mcp_message; while /mcp requires authentication, /mcp_message enforces only IP whitelisting, and the default whitelist is empty, which the middleware treats as allow-all, so the endpoint accepts requests with no authentication (CWE-306, missing authentication for a critical function). An attacker with network reachability to /mcp_message can invoke all MCP tools unauthenticated, including restarting nginx, creating, modifying, or deleting nginx configuration files, and triggering automatic config reloads. This yields complete takeover of the nginx service on the affected host, with critical-severity impact across confidentiality, integrity, and availability (CVSS 3.1: 9.8). All Nginx UI deployments running 2.3.5 or earlier are affected, especially those where the MCP endpoints are reachable from untrusted networks. News reports indicate the flaw is being actively exploited in the wild; it is not yet in CISA KEV, EPSS is high at 36.3% (98th percentile), and no patched release was available at publication.

Do: No fixed release was available at publication — monitor the upstream advisory (GHSA-h6c2-x2m2-mwhf) and the Nginx UI project and upgrade as soon as a patched version ships. Until then, restrict exposure of /mcp_message by setting a non-empty IP whitelist, firewalling the MCP endpoints to trusted management addresses or localhost/VPN only, or disabling the MCP integration. Review access logs for unauthenticated requests to /mcp_message and check for unexpected nginx config changes or restarts, which would indicate exploitation.

9.836% PoC
  • nginxui Nginx UI 2.3.5 and prior (no fix available at publication)
large≈10,000–50,000 exposed Nginx UI instances (order of tens of thousands)
CVE-2026-33825
Local Privilege Escalation in Microsoft Defender Antimalware Platform

CVE-2026-33825 is an insufficient granularity of access control flaw (CWE-1220) in Microsoft Defender Antimalware Platform that allows an authorized attacker to elevate privileges locally. It is triggered by an attacker who already holds a low-privileged foothold on a machine running Defender, with no user interaction required. Successful exploitation has high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.8), granting elevated local rights that facilitate defense evasion, persistence, or ransomware activity. Any organization running Microsoft Defender on Windows endpoints and servers is potentially affected. The flaw is actively exploited in the wild, was added to CISA's Known Exploited Vulnerabilities catalog on 2026-04-22 with ransomware use confirmed, and is one of three Microsoft Defender zero-days reported as exploited, two of which were still unpatched at the time of reporting.

Do: Apply Microsoft's April 2026 Patch Tuesday updates for the Defender Antimalware Platform (platform/security intelligence updates) per vendor instructions, consistent with CISA BOD 22-01 timelines for KEV entries, and note reports that two of the three exploited Defender zero-days were still unpatched, so monitor for follow-up fixes. Prioritize patching internet-reachable and high-value Windows hosts, and hunt for signs of local privilege escalation and ransomware precursor activity on systems that cannot be updated immediately.

7.87% KEV ransomware
  • Microsoft Defender Antimalware Platform
masshundreds of millions of Windows endpoints and servers (Defender is the default antimalware on Windows)
CVE-2026-34197
Authenticated RCE in Apache ActiveMQ via Jolokia JMX-HTTP Bridge

Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on its web console, and the default Jolokia access policy allows authenticated users to invoke exec operations on all ActiveMQ MBeans, including BrokerService.addNetworkConnector(String) and BrokerService.addConnector(String). An authenticated attacker abuses these operations with a crafted discovery URI so that the VM transport's brokerConfig parameter loads a remote Spring XML application context; because ResourceXmlApplicationContext instantiates singleton beans before the BrokerService validates the configuration, arbitrary code runs in the broker's JVM (e.g., through Runtime.exec() bean factory methods), yielding code execution with the broker's privileges. Affected users are those running Apache ActiveMQ Broker, ActiveMQ All, or ActiveMQ (Classic) on versions before 5.19.4 or 6.x versions from 6.0.0 before 6.2.3. Authentication to the web console is required (CVSS privileges-required: low), but CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2026-04-16 amid reported active exploitation, and EPSS puts 30-day exploitation probability at 98.3%. No public proof-of-concept is known, and whether ransomware groups are using it is unknown.

Do: Upgrade Apache ActiveMQ to 5.19.4 (5.x line) or 6.2.3 (6.x line), which fix the issue; federal agencies must apply mitigations under BOD 22-01 timelines. As interim mitigation, restrict access to the web console /api/jolokia/ endpoint, tighten the Jolokia access policy so exec is not permitted on org.apache.activemq:* MBeans (especially BrokerService.addNetworkConnector/addConnector), and enforce strong authentication. Review broker logs for Jolokia calls to these operations and for unexpected VM-transport connector additions.

8.898% KEV
  • Apache ActiveMQ Broker before 5.19.4, and 6.0.0 through before 6.2.3 (fixed in 5.19.4 and 6.2.3)
  • Apache ActiveMQ All before 5.19.4, and 6.0.0 through before 6.2.3 (fixed in 5.19.4 and 6.2.3)
  • Apache ActiveMQ (Classic) before 5.19.4, and 6.0.0 through before 6.2.3 (fixed in 5.19.4 and 6.2.3)
large≈10,000–100,000 exposed systems, plausibly 100,000+ installations overall (public scans typically show tens of thousands of ActiveMQ web consoles;…
CVE-2026-34621
Actively Exploited Prototype Pollution RCE in Adobe Acrobat and Reader

Adobe Acrobat and Acrobat Reader are affected by a prototype pollution vulnerability (CWE-1321) in which improperly controlled modification of object prototype attributes can lead to arbitrary code execution in the context of the current user. Attackers trigger the flaw by convincing a victim to open a malicious file, typically a crafted PDF, so user interaction is required. Successful exploitation yields code execution as the victim, with the CVSS scope-changed metric indicating impact that extends beyond the vulnerable component. Anyone running Acrobat or Reader versions 24.001.30356 or earlier or 26.001.21367 or earlier is affected. The flaw is being actively exploited in the wild — reportedly via malicious PDFs since December 2025 as a zero-day — and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-04-13 after fixes shipped in Adobe's April 2026 Patch Tuesday release; EPSS assigns a 7.1% probability of exploitation within 30 days (94th percentile).

Do: Upgrade Acrobat and Reader to a version later than 24.001.30356 (24.001 series) or 26.001.21367 (26.001 series) via Adobe's April 2026 security update, and audit installed versions across all endpoints. As a CISA KEV entry, US federal agencies must apply the vendor mitigations per BOD 22-01 guidance or discontinue use of the product if mitigations are unavailable. Until patched, treat PDFs from untrusted sources with caution and monitor for suspicious child-process activity spawned by Acrobat/Reader when files are opened.

8.67% KEV
  • Adobe Acrobat Reader (Acrobat Reader DC) 24.001.30356 and earlier; 26.001.21367 and earlier
  • Adobe Acrobat (Acrobat DC) 24.001.30356 and earlier; 26.001.21367 and earlier
masshundreds of millions of Acrobat/Reader installations worldwide, with likely millions still unpatched
CVE-2026-3502
Arbitrary Code Execution via Unverified Updates in TrueConf Client

CVE-2026-3502 is a download-of-code-without-integrity-check flaw (CWE-494) in TrueConf Client: the application downloads update code and applies it without verifying its integrity. An attacker who can influence the update delivery path can substitute a tampered update payload, and if that payload is executed or installed by the updater, arbitrary code runs in the context of the updating process or the user. The flaw is rated 7.8 (high) on CVSS 3.1 and affects TrueConf Client deployments, which are concentrated in enterprise and government video conferencing environments. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-04-02, and public reporting describes it as a zero-day used against Southeast Asian government networks by actors attributed to Chinese hackers, with CISA giving agencies roughly two weeks to remediate. Ransomware use is unknown, and no public proof-of-concept is known beyond the observed attacks; EPSS estimates a 5.7% chance of exploitation within 30 days (93rd percentile).

Do: Apply the vendor's fix or mitigations per CISA's KEV required action and BOD 22-01; federal agencies had roughly two weeks from the 2026-04-02 KEV listing to remediate or discontinue use. Until patched, restrict and monitor the network path between TrueConf Clients and their update source, and check endpoints for unexpected update or installer activity and newly created processes. Identify which TrueConf Client versions are in use and confirm affected and fixed versions against the vendor's advisory, since the source data does not specify version ranges.

7.86% KEV
  • TrueConf Client
moderate~10k-100k endpoints (deployment-pattern estimate; no public install or scan counts available)
CVE-2026-35616
Unauthenticated Code Execution in Fortinet FortiClient EMS 7.4.5–7.4.6

Fortinet FortiClient EMS versions 7.4.5 through 7.4.6 contain an improper access control flaw (CWE-284) that allows an unauthenticated attacker to execute unauthorized code or commands by sending crafted requests over the network. The attack requires no authentication, privileges, or user interaction, making any reachable EMS management server a direct target. A successful attacker gains code execution on the EMS host, and reported campaigns have used the flaw to deploy a credential stealer. Any organization running FortiClient EMS 7.4.5 or 7.4.6 is affected. The flaw is being exploited in the wild: it was added to CISA KEV on 2026-04-06, carries a 90.7% EPSS probability of exploitation within 30 days, and Fortinet has released emergency hotfixes.

Do: Upgrade FortiClient EMS off 7.4.5/7.4.6 using the fixed release or emergency hotfix per Fortinet's advisory (the available data does not specify the fixed version number), prioritizing internet-exposed servers; U.S. federal agencies must follow BOD 22-01. Until patched, restrict EMS management access to trusted networks or VPN and monitor for credential-stealer activity on managed endpoints. Given confirmed in-the-wild exploitation, assume possible compromise and hunt for indicators on both EMS hosts and endpoints it manages.

9.891% KEV
  • Fortinet FortiClient EMS 7.4.5 through 7.4.6
large≈10,000–100,000 EMS deployments (order-of-magnitude estimate; exact counts not in the data)
CVE-2026-39987
Unauthenticated Remote Code Execution in Marimo Python Notebook

Marimo, a reactive Python notebook, contains an unauthenticated remote code execution flaw (CVE-2026-39987, CWE-306; CVSS 4.0: 9.3 Critical) because its terminal WebSocket endpoint /terminal/ws skips authentication entirely. Unlike other WebSocket endpoints such as /ws, which call validate_auth(), /terminal/ws only checks the running mode and platform support before accepting connections, so any unauthenticated attacker who can reach the server can obtain a full PTY shell and execute arbitrary system commands on the host. All marimo deployments running versions prior to 0.23.0 are affected, with internet-exposed instances at greatest risk. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV catalog on 2026-04-23, public PoCs exist, and reporting shows it was exploited within roughly 10 hours of disclosure, with observed post-exploitation activity involving LLM agents. EPSS assigns a 98.9% probability of exploitation within 30 days (100th percentile).

Do: Upgrade marimo to 0.23.0 or later; until patched, restrict access to the /terminal/ws WebSocket endpoint by binding the notebook to localhost, a VPN, or an authenticating reverse proxy. Identify whether any marimo instances are internet-exposed and review logs for connections to /terminal/ws and unexpected shell or process spawns, given reports of LLM-agent-driven post-exploitation on compromised instances. As a KEV entry (added 2026-04-23), this requires federal agencies to apply the vendor fix or mitigations per BOD 22-01 timelines.

9.399% KEV PoC ×4
  • Marimo (reactive Python notebook) all versions prior to 0.23.0
  • CoreWeave marimo all versions prior to 0.23.0
moderatelikely tens of thousands of users, with directly internet-exposed marimo servers plausibly in the low thousands
CVE-2026-41940
Missing-Authentication Bypass in WebPros cPanel & WHM (AuthBypass to RCE)

CVE-2026-41940 is a critical missing-authentication flaw (CWE-306) in the login flow of WebPros cPanel & WHM (versions after 11.40) and WP2 (WordPress Squared) that lets unauthenticated remote attackers bypass authentication and gain unauthorized access to the control panel. Because no privileges, user interaction, or special conditions are required, any attacker who can reach the login endpoint over the network can attempt it. Beyond control-panel account takeover, public proofs of concept — including watchTowr's 'AuthBypass to RCE' exploit — show the flaw can be chained to remote code execution, and reporting indicates a single hosting customer could obtain root control of an entire shared server. Any hosting provider, MSP, reseller, or organization running cPanel/WHM or WP Squared is affected; cPanel is the dominant commercial hosting control panel, implying a very large installed base of shared-hosting servers and hosted domains. Exploitation is confirmed in the wild: CISA added it to the KEV on 2026-04-30 with known ransomware use, EPSS assigns a 98.5% probability of exploitation within 30 days (100th percentile), and multiple threat actors are actively exploiting it, including against government and MSP networks.

Do: Patch immediately per WebPros' advisory — the source data does not specify fixed version numbers, so follow vendor instructions for exact patched releases; CISA KEV/BOD 22-01 requires federal agencies to apply mitigations or discontinue use by the stated deadline (reported as Sunday). Until patched, restrict access to the cPanel/WHM login interface (IP allowlisting, VPN, or limiting management-interface exposure) and hunt for indicators of compromise such as unexpected control-panel logins, new admin accounts, webshells, or ransomware artifacts. The referenced public PoCs can be used to validate whether your instances are exploitable.

9.399% KEV ransomware PoC ×4
  • WebPros cPanel versions after 11.40 (per CISA description)
  • WebPros WHM versions after 11.40 (per CISA description)
  • WebPros WP2 (WordPress Squared)
mass≈100,000+ internet-exposed cPanel/WHM servers, spanning tens of millions of hosted domains and millions of end users
CVE-2026-5281
Use-After-Free in Google Chrome's Dawn (WebGPU) Component Enables Arbitrary Code Execution

CVE-2026-5281 is a use-after-free vulnerability in Dawn, the WebGPU implementation in Google Chrome, that Google patched in Chrome 146.0.7680.178. It is triggered when a remote attacker serves a crafted HTML page and can leverage it after having already compromised the Chrome renderer process, escalating to arbitrary code execution beyond the initial foothold. Because the flaw requires a compromised renderer as a starting point, it is typically chained with another bug (such as a renderer-exploiting issue) to break out to arbitrary code execution with real impact on confidentiality, integrity, and availability. Any user or organization running Google Chrome on a version prior to 146.0.7680.178 is affected. The flaw is confirmed as exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-04-01, and its EPSS score of 4.9% (92nd percentile) indicates a meaningful near-term exploitation probability.

Do: Update Google Chrome to 146.0.7680.178 or later on all endpoints immediately, prioritizing internet-facing and high-risk user populations given the KEV listing. Because the bug requires a compromised renderer, treat it as part of a chained attack and ensure other browser-layer defenses (renderer sandbox enabled, prompt patching of related renderer bugs) are in place; federal agencies must follow BOD 22-01 remediation timelines or discontinue use if patching is unavailable.

8.85% KEV
  • Google Chrome prior to 146.0.7680.178
  • Google Dawn (WebGPU implementation bundled in Chrome) as shipped in Chrome prior to 146.0.7680.178
masseffectively all Chrome users on unpatched builds
Full article1,866 words · extracted from recordedfuture.com · click to collapse

In April 2026, Insikt Group® identified 37 high-impact vulnerabilities that should be prioritized for remediation, 35 of which had a Very Critical Recorded Future Risk Score. This represents a 19% increase from last month.

31 of the 37 were included in the US Cybersecurity and Infrastructure Security Agency (CISA)’s Known Exploited Vulnerabilities (KEV) catalog, and six were surfaced only through honeypot data. Those six CVEs associated with honeypots are available only to Recorded Future customers.

Those 37 vulnerabilities affected products from 23 vendors. Microsoft accounted for approximately 22%, while the remaining exposure was concentrated across a range of enterprise-facing vendors, particularly security and systems management tools, collaboration and server platforms, developer and application-delivery software, remote support tools, and network-edge infrastructure.

In April, Insikt Group created Nuclei templates for the missing authentication vulnerabilities in Nginx UI (CVE-2026-33032) and Marimo (CVE-2026-39987). These Nuclei templates are available to Recorded Future customers.

Quick Reference: April 2026 Vulnerability Table

All 31 vulnerabilities below were actively exploited in April 2026. This table does not include the 6 CVEs associated with honeypot activity. The table below also provides examples of public PoCs identified by Insikt Group®. These PoCs were not tested for accuracy or efficacy. Vulnerability management teams should exercise caution and verify the validity of PoCs before testing.

#

Vulnerability

Risk
Score

Vendor/Product

KEV

Malware Analysis

RCE

PoC

1

CVE-2009-0238

99

Microsoft Office Excel, Excel Viewer, Office Compatibility Pack, Office

(available to Recorded Future Customers)

2

CVE-2012-1854

99

Microsoft Office, Visual Basic for Applications

3

CVE-2020-9715

99

Adobe Acrobat, Acrobat Reader

4

CVE-2023-21529

99

Microsoft Exchange Server

5

CVE-2023-27351

99

PaperCut NG, MF

6

CVE-2023-36424

99

Microsoft Windows Server

7

CVE-2024-1708

99

ConnectWise ScreenConnect

8

CVE-2024-27199

99

JetBrains TeamCity On-Premises

9

CVE-2024-57726

99

SimpleHelp remote support software

10

CVE-2024-57728

99

SimpleHelp remote support software

11

CVE-2024-7399

99

Samsung MagicINFO Server

12

CVE-2025-2749

99

Kentico Xperience

13

CVE-2025-29635

99

D-Link DIR-823X

14

CVE-2025-32975

99

Quest KACE Systems Management Appliance

15

CVE-2025-48700

99

Synacor Zimbra Collaboration Suite (ZCS)

16

CVE-2025-60710

99

Windows Server Host Process for Windows Tasks

17

CVE-2026-1340

99

Ivanti Endpoint Manager Mobile

18

CVE-2026-20122

99

Cisco Catalyst SD-WAN Manager

19

CVE-2026-20128

99

Cisco Catalyst SD-WAN Manager

20

CVE-2026-20133

99

Cisco Catalyst SD-WAN Manager

21

CVE-2026-21643

99

Fortinet FortiClient EMS

22

CVE-2026-32201

99

Microsoft SharePoint Server

23

CVE-2026-32202

99

Windows Shell

24

CVE-2026-33825

99

Microsoft Defender

(available to Recorded Future Customers)

25

CVE-2026-34197

99

Apache ActiveMQ, ActiveMQ Broker

26

CVE-2026-34621

99

Adobe Acrobat, Acrobat Reader

27

CVE-2026-35616

99

Fortinet FortiClient EMS

28

CVE-2026-39987

99

Marimo

29

CVE-2026-41940

99

cPanel, WHM, WP Squared

30

CVE-2026-3502

89

TrueConf Client

31

CVE-2026-5281

89

Dawn in Google Chrome

Table 1: List of vulnerabilities that were actively exploited in April based on Recorded Future data (excluding honeypot-sourced CVEs).

Key Trends: March 2026

  • In April 2026, seven of the 37 vulnerabilities in this report were linked to ransomware activity.
    • Six are explicitly tied to Storm-1175's Medusa ransomware operations.
    • CISA has also linked CVE-2026-41940 with known ransomware use (Sorry Ransomware, per open source reporting).
    • Additionally, threat actors exploited CVE-2024-3721 in TBK DVR devices to deliver the Nexcorium botnet.
  • Sixteen of the 37 vulnerabilities enabled remote code execution (RCE), affecting products from twelve vendors: Adobe, Apache, D-Link, Fortinet, Google, Ivanti, Kentico, Marimo, Microsoft, SimpleHelp, TrueConf, and Wazuh.
  • Insikt Group® identified public proof-of-concept (PoC) exploits for 24 of the 37 vulnerabilities in this report.
  • The most commonly observed flaws this month were CWE-22 (Path Traversal), followed by CWE-94 (Code Injection), CWE-20 (Improper Input Validation), and CWE-306 (Missing Authentication for Critical Function).
  • Three of the 37 vulnerabilities are at least five years old, with the oldest approximately seventeen years old, reinforcing how attackers continue to exploit long-known weaknesses in environments where patching has lagged. Additionally, the fastest observed time from a vulnerability’s public disclosure to exploitation was two days.

Exploitation Analysis

This section highlights some of the highest-impact, actively exploited vulnerabilities this month, specifically those linked to known threat actor campaigns, that have public PoC exploits available, or for which Insikt Group® has created Nuclei templates to detect the vulnerability. Vulnerabilities with no meaningful public technical detail are summarized in the disclosures table only.

Threat Actors Exploit TBK DVR Vulnerability (CVE-2024-3721) to Deliver Nexcorium

On April 17, 2026, FortiGuard Labs (@FortiGuardLabs on X, formerly known as Twitter), associated with Fortinet (@Fortinet), published a technical analysis detailing a campaign that exploits TBK Digital Video Recorder (DVR) devices to deliver Nexcorium, a Mirai-based botnet. A TBK DVR device is a surveillance system recorder that captures, stores, and allows playback or remote viewing of video from connected security cameras. According to FortiGuard Labs, Nexcorium targets TBK DVR-4104 and DVR-4216 systems by exploiting CVE-2024-3721, an operating system (OS) command injection vulnerability that allows remote threat actors to execute arbitrary system commands.

Based on FortiGuard Labs’ analysis, the campaign begins with the exploitation of CVE-2024-3721 through crafted requests that manipulate the mdb and mdc arguments in TBK DVR devices, which delivers a downloader script named dvr. The exploit includes the HTTP header X-Hacked-By with the value Nexus Team - Exploited By Erratic. The dvr script retrieves Nexcorium binaries with filenames beginning with nexuscorp for architectures such as ARM, MIPS R3000, and x86-64. The dvr script then sets the Nexcorium binaries’ permissions to 777, and executes them with an argument that identifies the compromised system.

Further technical details associated with this activity, including sample analysis and IoCs, are available to Recorded Future customers via Insikt Group reporting.

Recorded Future customers can also access Malware Intelligence queries, which surface samples that connect to known network indicators.

Insikt® Validated TTP: Using Nuclei to Detect CVE-2026-33032, an Actively Exploited Missing Authentication Vulnerability Affecting Nginx UI

On March 28, 2026, GitHub user Jacky (0xJacky) published an advisory in the Nginx UI repository detailing CVE-2026-33032 and a PoC exploit. CVE-2026-33032 is a Missing Authentication for Critical Function vulnerability affecting all versions of Nginx UI. Nginx UI is a web-based management interface for Nginx that lets administrators view status, create and modify configuration files, and control operations such as reloads and restarts. Exploiting CVE-2026-33032 allows an unauthenticated remote threat actor to restart, create, modify, or delete configuration files, and trigger configuration reloads, resulting in a complete Nginx service takeover.

According to Recorded Future data, active exploitation of CVE-2026-33032 was observed on April 1, 2026, on deception technology honeypots, four days after Nginx’s advisory and published PoC. Public version metadata for CVE-2026-33032 is inconsistent. The GitHub advisory currently lists the affected range as “all versions” with no patched version, and downstream records such as NVD/OSV have reflected broader affected ranges. However, the vulnerability author’s later technical analysis states that those ranges are incorrect, that version 2.3.3 is the last vulnerable version, and that version 2.3.4 contains the fix. Accordingly, we assess the most accurate affected range to be version 2.3.3 and earlier, while noting that some third-party databases may still show broader ranges due to discrepancies in advisory metadata.

The vulnerability resides in Nginx UI's MCP router and IP allowlist middleware. The /mcp endpoint enforces both IP allowlisting and authentication, while the /mcpmessage endpoint enforces IP allowlisting. An empty default IP allowlist triggers fail-open behavior in the middleware, allowing unauthenticated requests to /mcpmessage to reach the same mcp. ServeHTTP() handler that processes all MCP tool invocations. As a result, an unauthenticated remote threat actor with network access can access privileged MCP functions via /mcpmessage and take over Nginx management operations without credentials.

Based on the advisory, the PoC requires an operator-supplied JSON-RPC request that specifies the MCP tool to invoke and its arguments. The example includes the JSON-RPC method tools/call, the tool name nginxconfigadd, and five tool arguments: name, content, basedir, overwrite, and syncnodeids. Once provided, the PoC sends the crafted request to /mcpmessage. The service accepts the request without an Authorization header under an IP allowlist check with an empty default allow-all list. The service forwards the request to mcp.ServeHTTP(), which dispatches the selected MCP tool. In the example, nginxconfigadd writes a new nginx configuration file to the supplied filename inside the chosen base directory. After writing the file, nginxconfigadd triggers an immediate nginx reload.

The advisory states that a successful exploit can give an operator control over nginx configuration management and traffic handling. The advisory describes a complete takeover of the nginx service, including the ability to create, modify, or delete configuration files within the config directory and trigger immediate reload or restart actions. The advisory also describes traffic interception, service disruption due to invalid configuration changes, configuration exfiltration via readable nginx config files, and credential harvesting via injected logging directives that capture Authorization headers to enable escalation to the REST API.

Insikt Group® created a Nuclei template to detect CVE-2026-33032, which is available to Recorded Future customers. At the time of writing, there were 3,002 exposed Nginx UI instances on Shodan, with the majority geolocated in China, the US, Indonesia, Germany, and Hong Kong. However, not all of these are specifically vulnerable, as their specific versions are unknown.

Figure 2: Risk Rules History from Vulnerability Intelligence Card® for CVE-2026-33032 in Recorded Future (Source: Recorded Future)

Take Action

Timely and relevant information on vulnerabilities in your environment and that of your vendors and suppliers is critical for reducing risk. Find out how Recorded Future can support your team by increasing visibility, improving efficiency, and enabling confident decisions.

Vulnerability Intelligence – Prioritize vulnerabilities based on the likelihood of exploitation – not just the severity. Easily understand the risk of exploitation alongside severity, and real-time contextualized intelligence to help you quickly make confident decisions, patch what matters, and prevent attacks.

Attack Surface Intelligence – Identify internet-facing assets vulnerable to a specific CVE. Attack Surface Intelligence provides an outside-in view of your organization to help you actively discover, prioritize, and respond to unknown, vulnerable, or misconfigured assets.

Third-Party Intelligence – Gain an external view of the security posture of your vendors and partners. Eliminate time-consuming research and vendor communication cycles with the ability to promptly assess vulnerabilities in their internet-facing systems.

Insikt Group® – Receive access to exclusive reports on new vulnerabilities and trends from Recorded Future’s team of experts, the Insikt Group®. Download Nuclei templates created by Insikt Group® for select CVEs to test potentially vulnerable instances.

Recorded Future Professional Services – Work with our Professional Services team on a Vulnerability Analysis Engagement. Designed to equip your team with advanced strategies for identifying, prioritizing, and mitigating threats effectively, this program delves into technologies and operations essential for a successful vulnerability management program. (Learn more about how our Professional Services team can help your elevate your team by watching our recent Vulnerability Prioritization Workshop)

About Iniskt Group®

Recorded Future’s Insikt Group®, the company’s threat research division, comprises analysts and security researchers with deep government, law enforcement, military, and intelligence agency experience. Their mission is to produce intelligence that reduces risk for customers, enables tangible outcomes, and prevents business disruption.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.recordedfuture.com/blog/april-cve-landscape