Vulnerability intelligence

Updated 2 hours ago

Feeds

Trending now

CVEs trending on social media within the last 24 hours

Hypemeter

120100

Current score

Cold bath

  1. 1

    CVE-2026-20262 Published Jun 15, 2026

    Hype score

    12

    medium 6.5

    Exploit known

    Zero-day

    CVE-2026-20262 is identified as a directory or path traversal vulnerability affecting Cisco Catalyst SD-WAN Manager, previously known as SD-WAN vManage. This flaw stems from insufficient validation of user-supplied input during file uploads. An authenticated, remote attacker can exploit this by sending a specially crafted HTTP request to an affected API endpoint of the system. Successful exploitation of CVE-2026-20262 allows an attacker to create or overwrite any file on the underlying operating system. This capability can then be leveraged to elevate privileges to root. The vulnerability impacts all deployment types of Cisco Catalyst SD-WAN Manager, including on-premise, cloud-based, and government deployments.

  2. 2

    CVE-2026-54420 Published Jun 14, 2026

    Hype score

    9

    high 8.5

    Exploit known

    Zero-dayServerPort (22)

    CVE-2026-54420 identifies a vulnerability within the LiteSpeed cPanel plugin, affecting versions prior to 2.4.8, which are included in LiteSpeed WHM PlugIn versions before 5.3.2.0. This flaw stems from the plugin's inadequate handling of symbolic links (symlinks). The vulnerability can be leveraged by a user possessing FTP or web shell access on a shared hosting server that utilizes CloudLinux/CageFS. Through the manipulation of symlinks, an attacker could potentially access or execute arbitrary files located outside of their designated directories, a scenario categorized as a path traversal vulnerability (CWE-61). This issue was actively exploited in May 2026.

  3. 3

    CVE-2026-27509 Published Feb 26, 2026

    Hype score

    7

    high 8.5

    CVE-2026-27509 describes a vulnerability found in specific firmware versions of the Unitree Go2 robot. This flaw stems from the absence of DDS (Data Distribution Service) authentication or authorization for the `rt/api/programming_actuator/request` topic, which is managed by `actuator_manager.py`. As a result, a network-adjacent and unauthenticated attacker can connect to DDS domain 0. They can then publish a specially crafted message containing arbitrary Python code. This code is subsequently written to the robot's disk under `/unitree/etc/programming/` and linked to a physical controller keybinding. When this keybinding is activated, the injected code executes with root privileges and persists even after the robot reboots. The affected firmware versions include V1.1.7 through V1.1.9, and V1.1.11 (EDU).

See more

Known exploited

Sourced from CISA's Known Exploited Vulnerability (KEV) catalog.

  1. CVE-2026-48907 Published Jun 5, 2026

    critical 10.0

    A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.

  2. CVE-2026-54420 Published Jun 14, 2026

    Hype score

    9

    high 8.5

    Exploit known

    ServerPort (22)Zero-day

    CVE-2026-54420 identifies a vulnerability within the LiteSpeed cPanel plugin, affecting versions prior to 2.4.8, which are included in LiteSpeed WHM PlugIn versions before 5.3.2.0. This flaw stems from the plugin's inadequate handling of symbolic links (symlinks). The vulnerability can be leveraged by a user possessing FTP or web shell access on a shared hosting server that utilizes CloudLinux/CageFS. Through the manipulation of symlinks, an attacker could potentially access or execute arbitrary files located outside of their designated directories, a scenario categorized as a path traversal vulnerability (CWE-61). This issue was actively exploited in May 2026.

  3. CVE-2026-20262 Published Jun 15, 2026

    Hype score

    12

    medium 6.5

    Exploit known

    Zero-day

    CVE-2026-20262 is identified as a directory or path traversal vulnerability affecting Cisco Catalyst SD-WAN Manager, previously known as SD-WAN vManage. This flaw stems from insufficient validation of user-supplied input during file uploads. An authenticated, remote attacker can exploit this by sending a specially crafted HTTP request to an affected API endpoint of the system. Successful exploitation of CVE-2026-20262 allows an attacker to create or overwrite any file on the underlying operating system. This capability can then be leveraged to elevate privileges to root. The vulnerability impacts all deployment types of Cisco Catalyst SD-WAN Manager, including on-premise, cloud-based, and government deployments.

See more

Insights

See more

Our Security Team's most recent CVE analysis

  1. CVE-2026-41940

    critical 9.3

    Exploit known

    Link to CVE page

    Intruder Insights

    Updated Apr 30, 2026

    cPanel is a very popular hosting framework which is often very difficult to avoid exposing to the internet. The exploit for this weakness gives the attacker root access to cPanel (and from there easy RCE on the system), and the exploit is reliable, well documented, and affects all versions of cPanel except the latest patch. There are well over a million hosts exposed, and though cPanel does have some automated self-upgrade functionality, it can be turned off, and the window before an upgrade (usually up to 24h) is long enough for attacker to have already exploited this weakness. cPanel have provided a script you can use to detect if compromise has already occurred, which can be found here.

    cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

  2. CVE-2026-1340

    critical 9.8

    Exploit known

    Link to CVE page

    Intruder Insights

    Updated Jan 30, 2026

    This and the similar vulnerability CVE-2026-1281 allow an unauthenticated attacker to execute code remotely on unpatched Ivanti EPMM instances.

    A patch is available from Ivanti here and should be installed immediately. There is a page for defenders who need to check if their instance has been compromised here, though this is a work in progress.

    Note that this is a temporary patch which will be removed with further version updates. If you update the version of your EPMM instance after patching, you must apply the patch again. A fully patched version of EPMM will be available in future which will permanently fix the vulnerability.

    This vulnerability was known to be used in the wild before being disclosed by the vendor. Proof of concept code is now available publicly, so increased attack activity is expected.

    A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

  3. CVE-2026-1281

    critical 9.8

    Exploit known

    Link to CVE page

    Intruder Insights

    Updated Jan 30, 2026

    This and the similar vulnerability CVE-2026-1340 allow an unauthenticated attacker to execute code remotely on unpatched Ivanti EPMM instances.

    A patch is available from Ivanti here and should be installed immediately. There is a page for defenders who need to check if their instance has been compromised here, though this is a work in progress.

    Note that this is a temporary patch which will be removed with further version updates. If you update the version of your EPMM instance after patching, you must apply the patch again. A fully patched version of EPMM will be available in future which will permanently fix the vulnerability.

    This vulnerability was known to be used in the wild before being disclosed by the vendor. Proof of concept code is now available publicly, so increased attack activity is expected.

    A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.