Current threats

The newest entries in the CISA catalog of actively exploited vulnerabilities.

This is a public watch list from government-published data. It is not a scan of your network and it does not say whether you are affected.

  • 2026-09-25MikroTik RouterOSCVE-2026-67279

    Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060.

  • 2026-09-25Microsoft SharePointCVE-2026-65660

    Microsoft SharePoint contains a code injection vulnerability which could allow an authorized attacker to execute code over a network.

  • 2026-09-25WordPress CoreCVE-2026-87902

    WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local `.php` file outside the active theme directories, leading to remote code execution.

  • 2026-09-24WSO2 Multiple ProductsCVE-2026-5430

    WSO2 API Control Plane, API Manager, Traffic Manager & Universal Gateway contain a path traversal vulnerability that could allow for unrestricted file upload and lead to remote code execution.

  • 2026-09-24Adobe Commerce and Magento CVE-2026-71362

    Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction.

  • 2026-09-22Arista VeloCloud OrchestratorCVE-2026-93952

    Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.

  • 2026-09-22F5 BIG-IP APMCVE-2026-94127

    F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unauthenticated attacker to perform remote code execution.

  • 2026-09-22Check Point Multiple ProductsCVE-2026-93616

    Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent contain a path traversal vulnerability that allows an unauthenticated attacker to upload and execute arbitrary scripts.