← Back to feed TrendingZero-days

🚫 Patch This Week

Vulnerabilities requiring immediate action — actively exploited in the wild or with public exploit code available. Updated every 4 hours.

How this list is built Tier 1 — Patch now: On CISA Known Exploited Vulnerabilities (KEV) list — confirmed in-the-wild exploitation.
Tier 2 — Patch soon: Public proof-of-concept exploit exists with CVSS ≥7.0 or EPSS ≥70th percentile.

Tier 1 — Patch immediately (3 CVEs) CISA KEV confirmed

CVE / IDTitleSeverityCVSSEPSSWhy urgentSourceDate
CVE-2026-34486Apache Tomcat Missing Encryption of Sensitive Data VulnerabilityHIGH99%KEV PoC EPSS 99%ileCISA-KEV2026-08-04
CVE-2026-18577An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions throuHIGH8.283%KEV EPSS 83%ileNVD2026-08-02
CVE-2026-18556Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass.HIGH8.219%KEV EPSS 19%ileNVD2026-08-01

Tier 2 — Patch soon (80 CVEs) public exploit code

CVE / IDTitleSeverityCVSSEPSSWhy urgentSourceDate
CVE-2025-53770Microsoft SharePoint Server Remote Code Execution VulnerabilityCRITICAL9.8100%PoC EPSS 100%ileMicrosoft2025-07-08
CVE-2026-41089Windows Netlogon Remote Code Execution VulnerabilityCRITICAL9.8100%PoC EPSS 100%ileMicrosoft2026-05-12
CVE-2026-50522Microsoft SharePoint Remote Code Execution VulnerabilityCRITICAL9.8100%PoC EPSS 100%ileMicrosoft2026-07-14
CVE-2026-33824Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution VulnerabilityCRITICAL9.899%PoC EPSS 99%ileMicrosoft2026-04-14
CVE-2022-41903Integer overflow in `git archive` `git log --format` leading to RCE in gitCRITICAL9.899%PoC EPSS 99%ileMicrosoft2023-01-10
CVE-2024-1874Command injection via array-ish $command parameter of proc_open()CRITICAL9.498%PoC EPSS 98%ileMicrosoft2024-04-09
CVE-2024-32002GitHub: CVE-2024-32002 Recursive clones on case-insensitive filesystems that support symlinks are susceptible to RemoteCRITICAL9.098%PoC EPSS 98%ileMicrosoft2024-05-14
CVE-2024-4323Fluent Bit Memory Corruption VulnerabilityCRITICAL9.898%PoC EPSS 98%ileMicrosoft2024-05-14
CVE-2024-24576Rusts's `std::process::Command` did not properly escape arguments of batch files on WindowsCRITICAL10.097%PoC EPSS 97%ileMicrosoft2024-04-09
CVE-2025-29972Azure Storage Resource Provider Spoofing VulnerabilityCRITICAL9.985%PoC EPSS 85%ileMicrosoft2025-05-13
CVE-2026-43284xfrm: esp: avoid in-place decrypt on shared skb fragsHIGH7.8100%PoC EPSS 100%ileMicrosoft2026-05-12
CVE-2026-43500rxrpc: Also unshare DATA/RESPONSE packets when paged frags are presentHIGH7.8100%PoC EPSS 100%ileMicrosoft2026-05-12
CVE-2024-27316Apache HTTP Server: HTTP/2 DoS by memory exhaustion on endless continuation framesHIGH7.5100%PoC EPSS 100%ileMicrosoft2024-04-09
CVE-2023-45288HTTP/2 CONTINUATION flood in net/httpHIGH7.5100%PoC EPSS 100%ileMicrosoft2024-04-09
CVE-2024-2961The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4HIGH7.3100%PoC EPSS 100%ileMicrosoft2024-04-09
CVE-2024-27983An attacker can make the Node.js HTTP/2 server completely unavailable by sending a small amount of HTTP/2 frames packetsHIGH8.2100%PoC EPSS 100%ileMicrosoft2024-04-09
CVE-2023-50868MITRE: CVE-2023-50868 NSEC3 closest encloser proof can exhaust CPUHIGH7.5100%PoC EPSS 100%ileMicrosoft2024-06-11
CVE-2026-21509Microsoft Office Security Feature Bypass VulnerabilityHIGH7.899%PoC EPSS 99%ileMicrosoft2026-01-13
CVE-2026-42897Microsoft Exchange Server Spoofing VulnerabilityHIGH8.199%PoC EPSS 99%ileMicrosoft2026-05-12
CVE-2024-30088Windows Kernel Elevation of Privilege VulnerabilityHIGH7.099%PoC EPSS 99%ileMicrosoft2024-06-11
CVE-2023-21768Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityHIGH7.899%PoC EPSS 99%ileMicrosoft2023-01-10
CVE-2026-42945NGINX ngx_http_rewrite_module vulnerabilityHIGH8.199%PoC EPSS 99%ileMicrosoft2026-05-12
CVE-2023-21742Microsoft SharePoint Server Remote Code Execution VulnerabilityHIGH8.899%PoC EPSS 99%ileMicrosoft2023-01-10
CVE-2023-22809In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmenHIGH7.899%PoC EPSS 99%ileMicrosoft2023-01-10
CVE-2026-49160HTTP.sys Denial of Service VulnerabilityHIGH7.599%PoC EPSS 99%ileMicrosoft2026-06-09
CVE-2026-23918Apache HTTP Server: http2: double free and possible RCE on early resetHIGH8.899%PoC EPSS 99%ileMicrosoft2026-05-12
CVE-2024-29988SmartScreen Prompt Security Feature Bypass VulnerabilityHIGH8.899%PoC EPSS 99%ileMicrosoft2024-04-09
CVE-2023-21674Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege VulnerabilityHIGH8.899%PoC EPSS 99%ileMicrosoft2023-01-10
CVE-2026-49975Apache HTTP Server: mod_http2 denial of serviceHIGH7.598%PoC EPSS 98%ileMicrosoft2026-06-09
CVE-2024-35250Windows Kernel-Mode Driver Elevation of Privilege VulnerabilityHIGH7.898%PoC EPSS 98%ileMicrosoft2024-06-11
CVE-2024-26230Windows Telephony Server Elevation of Privilege VulnerabilityHIGH7.898%PoC EPSS 98%ileMicrosoft2024-04-09
CVE-2025-30397Scripting Engine Memory Corruption VulnerabilityHIGH7.597%PoC EPSS 97%ileMicrosoft2025-05-13
CVE-2025-54918Windows NTLM Elevation of Privilege VulnerabilityHIGH8.897%PoC EPSS 97%ileMicrosoft2025-09-09
CVE-2025-55234Windows SMB Elevation of Privilege VulnerabilityHIGH8.897%PoC EPSS 97%ileMicrosoft2025-09-09
CVE-2024-30085Windows Cloud Files Mini Filter Driver Elevation of Privilege VulnerabilityHIGH7.896%PoC EPSS 96%ileMicrosoft2024-06-11
CVE-2024-26218Windows Kernel Elevation of Privilege VulnerabilityHIGH7.896%PoC EPSS 96%ileMicrosoft2024-04-09
CVE-2025-40775DNS message with invalid TSIG causes an assertion failureHIGH7.596%PoC EPSS 96%ileMicrosoft2025-05-13
CVE-2026-50656Microsoft Defender Elevation of Privilege VulnerabilityHIGH7.895%PoC EPSS 95%ileMicrosoft2026-06-09
CVE-2026-9256NGINX ngx_http_rewrite_module vulnerabilityHIGH8.195%PoC EPSS 95%ileMicrosoft2026-05-12
CVE-2026-41091Microsoft Defender Elevation of Privilege VulnerabilityHIGH7.895%PoC EPSS 95%ileMicrosoft2026-05-12
CVE-2024-26229Windows CSC Service Elevation of Privilege VulnerabilityHIGH7.895%PoC EPSS 95%ileMicrosoft2024-04-09
CVE-2026-45659Microsoft SharePoint Remote Code Execution VulnerabilityHIGH8.895%PoC EPSS 95%ileMicrosoft2026-05-12
CVE-2025-41244VMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulnerabilities (CVE-2025-41244,CVE-202HIGH7.894%PoC EPSS 94%ileMicrosoft2025-09-09
CVE-2026-46300net: skbuff: preserve shared-frag marker during coalescingHIGH7.894%PoC EPSS 94%ileMicrosoft2026-05-12
CVE-2026-42980NT OS Kernel Elevation of Privilege VulnerabilityHIGH7.894%PoC EPSS 94%ileMicrosoft2026-06-09
CVE-2026-33825Microsoft Defender Elevation of Privilege VulnerabilityHIGH7.893%PoC EPSS 93%ileMicrosoft2026-04-14
CVE-2024-30051Windows DWM Core Library Elevation of Privilege VulnerabilityHIGH7.892%PoC EPSS 92%ileMicrosoft2024-05-14
CVE-2026-20817Windows Error Reporting Service Elevation of Privilege VulnerabilityHIGH7.892%PoC EPSS 92%ileMicrosoft2026-01-13
CVE-2023-21752Windows Backup Service Elevation of Privilege VulnerabilityHIGH7.192%PoC EPSS 92%ileMicrosoft2023-01-10
CVE-2026-40369Windows Kernel Elevation of Privilege VulnerabilityHIGH7.891%PoC EPSS 91%ileMicrosoft2026-05-12
CVE-2025-53020Apache HTTP Server: HTTP/2 DoS by Memory IncreaseHIGH7.591%PoC EPSS 91%ileMicrosoft2025-07-08
CVE-2025-32023Redis allows out of bounds writes in hyperloglog commands leading to RCEHIGH7.089%PoC EPSS 89%ileMicrosoft2025-07-08
CVE-2023-38709Apache HTTP Server: HTTP response splittingHIGH7.389%PoC EPSS 89%ileMicrosoft2024-04-09
CVE-2025-54110Windows Kernel Elevation of Privilege VulnerabilityHIGH8.889%PoC EPSS 89%ileMicrosoft2025-09-09
CVE-2023-0266Use after free in SNDRV_CTL_IOCTL_ELEM in Linux KernelHIGH7.889%PoC EPSS 89%ileMicrosoft2023-01-10
CVE-2026-42533NGINX Map directive and Regex matching vulnerabilityHIGH8.188%PoC EPSS 88%ileMicrosoft2026-07-14
CVE-2026-50343Microsoft Install Service Elevation of Privilege VulnerabilityHIGH7.888%PoC EPSS 88%ileMicrosoft2026-07-14
CVE-2026-46242eventpoll: fix ep_remove struct eventpoll / struct file UAFHIGH7.887%PoC EPSS 87%ileMicrosoft2026-05-12
CVE-2026-5172CVE-2026-5172HIGH7.384%PoC EPSS 84%ileMicrosoft2026-05-12
CVE-2025-49706Microsoft SharePoint Server Spoofing VulnerabilityMEDIUM6.5100%PoC EPSS 100%ileMicrosoft2025-07-08
CVE-2026-31431crypto: algif_aead - Revert to operating out-of-placeMEDIUM5.5100%PoC EPSS 100%ileMicrosoft2026-04-14
CVE-2026-32202Windows Shell Spoofing VulnerabilityMEDIUM4.399%PoC EPSS 99%ileMicrosoft2026-04-14
CVE-2026-45498Microsoft Defender Denial of Service VulnerabilityMEDIUM4.099%PoC EPSS 99%ileMicrosoft2026-05-12
CVE-2024-30043Microsoft SharePoint Server Information Disclosure VulnerabilityMEDIUM6.599%PoC EPSS 99%ileMicrosoft2024-05-14
CVE-2026-56164Microsoft SharePoint Server Elevation of Privilege VulnerabilityMEDIUM5.398%PoC EPSS 98%ileMicrosoft2026-07-14
CVE-2026-50507Windows BitLocker Security Feature Bypass VulnerabilityMEDIUM6.891%PoC EPSS 91%ileMicrosoft2026-06-09
CVE-2026-33829Windows Snipping Tool Spoofing VulnerabilityMEDIUM4.388%PoC EPSS 88%ileMicrosoft2026-04-14
CVE-2025-49844Security Advisory 0139UNKNOWN100%PoC EPSS 100%ileArista2026-05-18
CVE-2024-21907VulnCheck: CVE-2024-21907 Improper Handling of Exceptional Conditions in Newtonsoft.JsonUNKNOWN98%PoC EPSS 98%ileMicrosoft2025-09-09
CVE-2024-4947Chromium: CVE-2024-4947 Type Confusion in V8UNKNOWN96%PoC EPSS 96%ileMicrosoft2024-05-14
CVE-2024-4761Chromium: CVE-2024-4761 Out of bounds write in V8UNKNOWN96%PoC EPSS 96%ileMicrosoft2024-05-14
CVE-2024-5274Chromium: CVE-2024-5274 Type Confusion in V8UNKNOWN95%PoC EPSS 95%ileMicrosoft2024-05-14
CVE-2025-6558Chromium: CVE-2025-6558 Incorrect validation of untrusted input in ANGLE and GPUUNKNOWN95%PoC EPSS 95%ileMicrosoft2025-07-08
CVE-2025-6554Chromium: CVE-2025-6554 Type Confusion in V8UNKNOWN95%PoC EPSS 95%ileMicrosoft2025-07-08
CVE-2025-10585Chromium: CVE-2025-10585 Type Confusion in V8UNKNOWN92%PoC EPSS 92%ileMicrosoft2025-09-09
CVE-2025-4664Chromium: CVE-2025-4664 Insufficient policy enforcement in LoaderUNKNOWN92%PoC EPSS 92%ileMicrosoft2025-05-13
CVE-2026-5281Chromium: CVE-2026-5281 Use after free in DawnUNKNOWN91%PoC EPSS 91%ileMicrosoft2026-04-14
CVE-2026-25243redis-server RESTORE invalid memory access may allow remote code executionUNKNOWN87%PoC EPSS 87%ileMicrosoft2026-05-12
CVE-2025-48384GitHub: CVE-2025-48384 Git Symlink VulnerabilityUNKNOWN85%PoC EPSS 85%ileMicrosoft2025-07-08
CVE-2026-23631redis-server Lua use-after-free may allow remote code executionUNKNOWN85%PoC EPSS 85%ileMicrosoft2026-05-12

Updated 2026-08-04. Source: NVD, CISA KEV, EPSS (FIRST.org). JSON API available for automation.