Vulnerability intelligence

Updated 38 minutes ago

Feeds

Trending now

CVEs trending on social media within the last 24 hours

Hypemeter

340100

Current score

Tepid

  1. 1

    CVE-2026-3227 Published Mar 16, 2026

    Hype score

    34

    high 8.5

    CVE-2026-3227 is a command injection vulnerability affecting specific TP-Link router models, including the TL-WR802N v4, TL-WR841N v14, and TL-WR840N v6. This flaw stems from the improper neutralization of special elements within an operating system command. The vulnerability allows an authenticated attacker to upload a specially crafted configuration file via the router's import function. During the processing of this file, specifically during port-trigger processing, the embedded malicious commands are executed with root privileges.

  2. 2

    CVE-2026-24207 Published May 20, 2026

    Hype score

    16

    critical 9.8

    CVE-2026-24207 is an authentication bypass vulnerability found in the NVIDIA Triton Inference Server. This flaw allows an attacker to circumvent security mechanisms, potentially leading to unauthorized access to affected systems. Successful exploitation of this vulnerability could result in various outcomes, including code execution, escalation of privileges, data tampering, denial of service, or information disclosure. The vulnerability can be exploited remotely over a network without requiring authentication or user interaction.

  3. 3

    CVE-2026-23111 Published Feb 13, 2026

    Hype score

    6

    high 7.8

    UbuntuAWS

    CVE-2026-23111 is a local privilege escalation vulnerability found in the Linux kernel's `nf_tables` subsystem, which is responsible for packet filtering. The flaw stems from a logic error within the `nft_map_catchall_activate()` function, specifically an inverted `genmask` check during the abort path of a failed transaction. This incorrect check prevents the proper reactivation of catchall map elements and, for `NFT_GOTO` verdict elements, can lead to a permanently decremented reference count for `nf_tables` chain objects. This issue can result in a use-after-free condition, where a chain can be prematurely freed while other `nf_tables` state still holds a stale reference to it. An unprivileged local user can exploit this vulnerability on systems where user namespaces and `nftables` are enabled, potentially gaining root access. The vulnerability was patched by removing a single character (an exclamation mark) that caused the inverted logic.

See more

Known exploited

Sourced from CISA's Known Exploited Vulnerability (KEV) catalog.

  1. CVE-2026-20230 Published Jun 3, 2026

    Hype score

    1

    high 8.6

    Exploit known

    CVE-2026-20230 is an unauthenticated Server-Side Request Forgery (SSRF) vulnerability found in the WebDialer component of Cisco Unified Communications Manager (Unified CM) and Unified CM Session Management Edition. This flaw stems from improper input validation of specific HTTP requests, allowing a remote, unauthenticated attacker to send crafted requests. Successful exploitation of this vulnerability enables an attacker to write arbitrary files to the underlying operating system. These files can subsequently be used to escalate privileges to root on the affected system. While proof-of-concept exploit code is publicly available, Cisco has not observed active exploitation of this vulnerability. The affected WebDialer service is disabled by default, meaning only deployments where it has been explicitly enabled are susceptible.

  2. CVE-2026-12569 Published Jun 18, 2026

    Hype score

    1

    critical 9.3

    Exploit known

    CVE-2026-12569 is a remote code execution (RCE) vulnerability found in PTC Windchill PDMlink and PTC FlexPLM. This flaw arises from improper input validation and the deserialization of untrusted data. An unauthenticated, remote attacker can exploit this vulnerability by sending specially crafted requests to the affected systems, enabling them to execute arbitrary code. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-12569 to its Known Exploited Vulnerabilities (KEV) catalog, indicating that it is being actively exploited in the wild. Attackers have been observed deploying persistent JSP webshells to facilitate remote command execution and data exfiltration.

  3. CVE-2026-34910 Published May 22, 2026

    critical 10.0

    Exploit known

    IoTICSServer

    A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.

See more

Insights

See more

Our Security Team's most recent CVE analysis

  1. CVE-2026-41940

    critical 9.3

    Exploit known

    Link to CVE page

    Intruder Insights

    Updated Apr 30, 2026

    cPanel is a very popular hosting framework which is often very difficult to avoid exposing to the internet. The exploit for this weakness gives the attacker root access to cPanel (and from there easy RCE on the system), and the exploit is reliable, well documented, and affects all versions of cPanel except the latest patch. There are well over a million hosts exposed, and though cPanel does have some automated self-upgrade functionality, it can be turned off, and the window before an upgrade (usually up to 24h) is long enough for attacker to have already exploited this weakness. cPanel have provided a script you can use to detect if compromise has already occurred, which can be found here.

    cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

  2. CVE-2026-1340

    critical 9.8

    Exploit known

    Link to CVE page

    Intruder Insights

    Updated Jan 30, 2026

    This and the similar vulnerability CVE-2026-1281 allow an unauthenticated attacker to execute code remotely on unpatched Ivanti EPMM instances.

    A patch is available from Ivanti here and should be installed immediately. There is a page for defenders who need to check if their instance has been compromised here, though this is a work in progress.

    Note that this is a temporary patch which will be removed with further version updates. If you update the version of your EPMM instance after patching, you must apply the patch again. A fully patched version of EPMM will be available in future which will permanently fix the vulnerability.

    This vulnerability was known to be used in the wild before being disclosed by the vendor. Proof of concept code is now available publicly, so increased attack activity is expected.

    A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

  3. CVE-2026-1281

    critical 9.8

    Exploit known

    Link to CVE page

    Intruder Insights

    Updated Jan 30, 2026

    This and the similar vulnerability CVE-2026-1340 allow an unauthenticated attacker to execute code remotely on unpatched Ivanti EPMM instances.

    A patch is available from Ivanti here and should be installed immediately. There is a page for defenders who need to check if their instance has been compromised here, though this is a work in progress.

    Note that this is a temporary patch which will be removed with further version updates. If you update the version of your EPMM instance after patching, you must apply the patch again. A fully patched version of EPMM will be available in future which will permanently fix the vulnerability.

    This vulnerability was known to be used in the wild before being disclosed by the vendor. Proof of concept code is now available publicly, so increased attack activity is expected.

    A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.