Vulnerability intelligence

Updated 18 minutes ago

Feeds

Trending now

CVEs trending on social media within the last 24 hours

Hypemeter

110100

Current score

Damp squib

  1. 1

    CVE-2026-61500 Published Jul 13, 2026

    Hype score

    11

    critical 9.3

    Rejetto HFS

    CVE-2026-61500 describes a vulnerability affecting Rejetto HFS versions 3.0.0 through 3.2.0. The flaw stems from the application's use of the non-cryptographic `Math.random()` generator to create session-cookie signing keys. Additionally, outputs from this same generator are disclosed to unauthenticated clients during the login process. A remote attacker can exploit this by collecting a small number of login responses to reconstruct the state of the `Math.random()` generator. This allows them to recover the session-cookie signing key and subsequently forge a valid administrator session cookie. With a forged administrator session, an attacker can gain full administrative access and achieve remote code execution via the `server_code` configuration feature.

  2. 2

    CVE-2026-88772 Published Sep 27, 2026

    Hype score

    8

    critical 9.5

    Exploit known

    VDICloudSystemSSLDnsMobile deviceTlsCitrix NetScaler ADCCitrix NetScaler Gateway

    CVE-2026-88772 is a memory overflow vulnerability impacting Citrix NetScaler ADC and NetScaler Gateway appliances. This flaw can result in remote code execution (RCE) or a denial-of-service (DoS) condition. The vulnerability specifically affects appliances where Datagram Transport Layer Security (DTLS) is enabled. DTLS is typically enabled by default for VPN virtual servers, meaning NetScaler Gateway deployments are susceptible unless DTLS has been explicitly disabled. Citrix has confirmed that this vulnerability, alongside CVE-2026-88771, has been actively exploited in unmitigated NetScaler deployments.

  3. 3

    CVE-2026-102676 Published Sep 29, 2026

    Hype score

    8

    high 8.3

    Node.jsElectron

    CVE-2026-102676 describes a vulnerability within the Electron framework, which is used for developing cross-platform desktop applications with JavaScript, HTML, and CSS. Prior to versions 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, an Electron `<webview>` guest could enable `nodeIntegrationInWorker` for its Web Workers. This was possible even if the unsandboxed embedder had Node.js integration disabled, potentially allowing untrusted guest content to create a Node-enabled worker with elevated privileges beyond what the embedder intended. Applications that do not utilize the `<webview>` tag or those that maintain a sandboxed embedder are not affected by this issue. The vulnerability has been addressed in the specified Electron versions.

See more

Known exploited

Sourced from CISA's Known Exploited Vulnerability (KEV) catalog.

  1. CVE-2026-76504 Published Sep 30, 2026

    Hype score

    4

    critical 9.8

    Exploit known

    Cisco Catalyst SD-WAN Manager

    CVE-2026-76504 is an API authentication bypass vulnerability affecting Cisco Catalyst SD-WAN Manager. The issue arises from the improper handling of URI/URL encoding in HTTP requests. An unauthenticated, remote attacker can exploit this flaw by sending a crafted HTTP request to the affected system's API. This allows the request to bypass an authentication rule designed to restrict access to a specific API endpoint, granting the attacker access to the API with administrative privileges without requiring any credentials. The vulnerability affects Cisco Catalyst SD-WAN Manager regardless of its system configuration. Cisco discovered the issue through a customer support case and confirmed that it is being actively exploited in the wild. Consequently, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-76504 to its Known Exploited Vulnerabilities (KEV) catalog on September 30, 2026. Cisco has released software updates to address the flaw, and because no workarounds are available, organizations are advised to apply the patches to secure their systems.

  2. CVE-2026-86950 Published Sep 28, 2026

    high 8.8

    Exploit known

    Supply chainMobile device

    CVE-2026-86950 is an out-of-bounds write vulnerability found within Apple's CoreGraphics framework. This flaw allows for memory corruption and can potentially lead to arbitrary code execution if a device processes a specially crafted file. The CoreGraphics component is fundamental to Apple operating systems, handling the rendering of 2D content such as images and PDF documents. Apple addressed this issue by implementing improved bounds checking in affected versions of iOS, iPadOS, and macOS. The vulnerability was reported to Apple by Meta Product Security. Apple has acknowledged reports suggesting that this issue may have been exploited in highly targeted attacks against specific individuals on older versions of iOS.

  3. CVE-2026-88772 Published Sep 27, 2026

    Hype score

    8

    critical 9.5

    Exploit known

    CloudSSLCitrix NetScaler ADCCitrix NetScaler GatewayVDIDnsTlsMobile deviceSystem

    CVE-2026-88772 is a memory overflow vulnerability impacting Citrix NetScaler ADC and NetScaler Gateway appliances. This flaw can result in remote code execution (RCE) or a denial-of-service (DoS) condition. The vulnerability specifically affects appliances where Datagram Transport Layer Security (DTLS) is enabled. DTLS is typically enabled by default for VPN virtual servers, meaning NetScaler Gateway deployments are susceptible unless DTLS has been explicitly disabled. Citrix has confirmed that this vulnerability, alongside CVE-2026-88771, has been actively exploited in unmitigated NetScaler deployments.

See more

Insights

See more

Our Security Team's most recent CVE analysis

  1. Link to CVE page

    Intruder Insights

    Updated Sep 10, 2026

    This is a serious vulnerability affecting all supported WordPress versions. It can be exploited by any unauthenticated attacker, and a working proof of concept is available. However, to achieve remote code execution an attacker must trick a WordPress admin into opening a malicious link as part of a social engineering attack. This vulnerability is patched in WordPress 7.0.3 (released Aug 6, 2026).

    WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE vulnerability with conditions outside of the attackers control. This requires successful social engineering of and explicit interaction by the target victim. This issue affects all versions of WordPress. Version 7.0.3 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7. Discovered and responsibly disclosed by [the team at pwn.ai](https://pwn.ai/).

  2. CVE-2026-50522

    critical 9.8

    Exploit known

    Link to CVE page

    Intruder Insights

    Updated Jul 21, 2026

    This vulnerability allows an unauthenticated attacker who can access a Sharepoint instance to gain code execution. A patch has been available since July 14th in Microsofts 'Patch Tuesday' security rollup.

    A proof of concept exploit has recently been published and this makes patching more urgent as attacks have now been seen in the wild.

    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

  3. CVE-2026-63030

    critical 9.8

    Exploit known

    Link to CVE page

    Intruder Insights

    Updated Jul 21, 2026

    This is one of two vulnerabilities in a combined chain that allows remote code execution on any stock WordPress installation. CVE-2026-63030 is the entry point — a route confusion bug in the REST API batch endpoint that bypasses authentication, allowing an attacker to invoke internal handlers without any permission check. When combined with CVE-2026-60137, the attacker gains the ability to read any data from the WordPress database with a single HTTP request. An exploit chain has been demonstrated which combines both of these bugs to achieve code execution.

    WordPress 6.9.0–6.9.4 and 7.0.0–7.0.1 are affected. Update to WordPress 6.9.5 or 7.0.2 immediately. No plugins, user interaction, or non-default configuration is required to exploit. Given WordPress powers approximately 43% of all websites, the attack surface is enormous.

    WordPress Core contains a pre-authentication route confusion vulnerability in the REST API batch endpoint that, combined with CVE-2026-60137, allows remote code execution.

    WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.