An unauthenticated attacker with network access to Microsoft Office SharePoint can bypass authentication controls and read data that should be protected, no login or user action needed.
Every CISA KEV addition, plus critical-severity flaws in the kit that sits at the edge of a network: firewalls, VPN gateways, load balancers, routers, switches and management consoles.
Colour on the left of each entry is the CVSS severity. A pink CISA KEV badge means the flaw is being exploited right now — treat those first, whatever the score says. How each post is sourced and checked is set out in the methodology.
Ray-Project Ray Code Injection Vulnerability
Ray’s local developer interface trusts a spoofable browser header as its only defence, letting a malicious webpage combine DNS rebinding with Firefox or Safari to run code on a developer’s machine.
Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability
An unauthenticated attacker can trigger a heap memory fault over the network on Cisco ASA and FTD firewalls, forcing an unplanned reload and knocking down the firewall’s availability.
Metabase SQL Injection Vulnerability
An unauthenticated attacker can send crafted SQL through Metabase’s own password-reset endpoint and walk away with full administrator control of the instance, no login required.
Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
A kernel-level flaw in Windows’ WinSock driver lets an attacker who already has a foothold on a machine escalate to full SYSTEM control, and it’s already being exploited.
Progress LoadMaster Command Injection Vulnerability
An unauthenticated attacker on the adjacent network can run arbitrary OS commands on Progress LoadMaster appliances through unsanitised API endpoints, and the flaw is already being exploited.
Cisco Catalyst SD-WAN Software Security Hardening Release: August 2026
Cisco’s internal security review of Catalyst SD-WAN Manager and Controller software uncovered five separate flaws, one rated 9.9, that a low-privileged network attacker could exploit without any user interaction.
Cisco IOS XE Software Security Hardening Release: August 2026
Cisco’s own engineers found seven flaws in IOS XE running in autonomous or controller mode, including a critical injection bug reachable over the network with no login needed, and there is no workaround short of upgrading.
Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability
An unauthenticated attacker who can reach the FMC web interface can exploit a flawed boot-time process to run scripts and gain root on the underlying operating system, no credentials needed.
JetBrains TeamCity Deserialization of Untrusted Data Vulnerability
An unauthenticated attacker who can reach a TeamCity server’s agent polling endpoint can trigger deserialization of malicious data and run arbitrary code on the server, with no login required.