cPanel is a very popular hosting framework which is often very difficult to avoid exposing to the internet. The exploit for this weakness gives the attacker root access to cPanel (and from there easy RCE on the system), and the exploit is reliable, well documented, and affects all versions of cPanel except the latest patch. There are well over a million hosts exposed, and though cPanel does have some automated self-upgrade functionality, it can be turned off, and the window before an upgrade (usually up to 24h) is long enough for attacker to have already exploited this weakness. cPanel have provided a script you can use to detect if compromise has already occurred, which can be found here.
Vulnerability intelligence
Updated 14 minutes ago
FeedsTrending now
CVEs trending on social media within the last 24 hours
Hypemeter
Current score
Cold bath
1
CVE-2024-21338 Published Feb 13, 2024Hype score
6
high 7.8
Exploit known
CloudZero-dayICSCVE-2024-21338 is an elevation of privilege vulnerability found within the Windows kernel, specifically residing in the `appid.sys` AppLocker driver. This flaw allows an attacker with low-privileged local code execution to escalate their privileges to SYSTEM-level by exploiting an exposed Input/Output Control (IOCTL) handler. The vulnerability stems from insufficient validation of user-supplied input within the `AppHashComputeImageHashInternal()` function, which can be invoked by sending a specially crafted IOCTL request to the `\Device\Appid` device object. By manipulating this IOCTL request, an attacker can cause the driver to execute an attacker-chosen routine in kernel context, effectively crossing the admin-to-kernel security boundary. This vulnerability affects supported versions of Windows 10, Windows 11, and Windows Server.
2
CVE-2026-33557 Published Apr 20, 2026Hype score
3
critical 9.1
Apache KafkaKafkaCVE-2026-33557 describes an authentication bypass vulnerability found in Apache Kafka. The flaw stems from the default configuration of the `sasl.oauthbearer.jwt.validator.class` property, which is set to `org.apache.kafka.common.security.oauthbearer.DefaultJwtValidator`. This default validator fails to properly validate JSON Web Token (JWT) signatures, issuers, or audiences. As a result, a remote attacker can exploit this weakness by crafting a malicious JWT token containing an arbitrary `preferred_username`. This allows the attacker to bypass authentication and gain unauthorized access to the Kafka broker. Apache Kafka versions 4.1.0 and 4.1.1 are affected, with the issue resolved in versions 4.1.2, 4.2.0, and later, which correctly validate JWT tokens. A recommended workaround for affected versions is to explicitly configure `sasl.oauthbearer.jwt.validator.class` to `org.apache.kafka.common.security.oauthbearer.BrokerJwtValidator`.
3
CVE-2026-13753 Published Jul 6, 2026Hype score
3
high 7.5
HP Deskjet 2800 Series PrintersHP DeskjetCVE-2026-13753 describes a missing authorization vulnerability found in the embedded web server of HP Deskjet 2800 Series Printers running firmware version TBP1CN2612AR and earlier. This flaw allows an unauthenticated attacker with network access to send direct GET requests to specific administrative API endpoints. Through this method, the attacker can retrieve sensitive configuration data that would normally require administrator credentials when accessed via the printer's web interface. The exposed information includes plaintext Wi-Fi Direct credentials, unique device identity details, and other administrative security state information. This bypasses the intended web interface security by failing to validate session states at the backend API layer.
Known exploited
Sourced from CISA's Known Exploited Vulnerability (KEV) catalog.
- CVE-2008-4128 Published Sep 18, 2008
medium 4.3
Exploit known
Cisco IOS871 Integrated Services RouterMultiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router allow remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI. NOTE: some of these details are obtained from third party information.
- CVE-2026-56291 Published Jul 9, 2026
critical 10.0
Exploit known
JoomlaBalbooa FormsCVE-2026-56291 is a vulnerability found in the Joomla extension Balbooa Forms. It is categorized as an unauthenticated arbitrary file upload flaw, meaning an attacker can upload executable files without needing to authenticate to the system. This capability can lead to full Remote Code Execution (RCE) on affected systems. The vulnerability has been added to CISA's Known Exploited Vulnerabilities Catalog, indicating that it is being actively exploited in the wild.
- CVE-2026-48939 Published Jun 20, 2026
critical 10.0
Exploit known
JoomlaiCagendaCVE-2026-48939 describes an unrestricted file upload vulnerability found within the iCagenda extension for Joomla. This flaw permits the upload of arbitrary files through the file attachment feature. The vulnerability ultimately enables the upload and execution of PHP code on the affected server. This issue has been added to CISA's Known Exploited Vulnerabilities Catalog, indicating that it is being actively exploited.
Insights
See moreOur Security Team's most recent CVE analysis
- Link to CVE page
CVE-2026-41940
critical 9.3
Exploit known
Intruder Insights
Updated Apr 30, 2026
- Link to CVE page
CVE-2026-1340
critical 9.8
Exploit known
Intruder Insights
Updated Jan 30, 2026
This and the similar vulnerability CVE-2026-1281 allow an unauthenticated attacker to execute code remotely on unpatched Ivanti EPMM instances.
A patch is available from Ivanti here and should be installed immediately. There is a page for defenders who need to check if their instance has been compromised here, though this is a work in progress.
Note that this is a temporary patch which will be removed with further version updates. If you update the version of your EPMM instance after patching, you must apply the patch again. A fully patched version of EPMM will be available in future which will permanently fix the vulnerability.
This vulnerability was known to be used in the wild before being disclosed by the vendor. Proof of concept code is now available publicly, so increased attack activity is expected.
- Link to CVE page
CVE-2026-1281
critical 9.8
Exploit known
Intruder Insights
Updated Jan 30, 2026
This and the similar vulnerability CVE-2026-1340 allow an unauthenticated attacker to execute code remotely on unpatched Ivanti EPMM instances.
A patch is available from Ivanti here and should be installed immediately. There is a page for defenders who need to check if their instance has been compromised here, though this is a work in progress.
Note that this is a temporary patch which will be removed with further version updates. If you update the version of your EPMM instance after patching, you must apply the patch again. A fully patched version of EPMM will be available in future which will permanently fix the vulnerability.
This vulnerability was known to be used in the wild before being disclosed by the vendor. Proof of concept code is now available publicly, so increased attack activity is expected.