Vulnerabilities requiring immediate action — actively exploited in the wild or with public exploit code available. Updated every 4 hours.
| CVE / ID | Title | Severity | CVSS | EPSS | Why urgent | Source | Date |
|---|---|---|---|---|---|---|---|
| CVE-2026-85706 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 1 | CRITICAL | 10.0 | 96% | KEV PoC EPSS 96%ile | NVD | 2026-09-12 |
| CVE-2026-76461 | A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthentic | CRITICAL | 9.8 | 80% | KEV EPSS 80%ile | NVD | 2026-09-14 |
| CVE-2026-76460 | A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to byp | CRITICAL | 10.0 | 54% | KEV EPSS 54%ile | NVD | 2026-09-16 |
| CVE-2026-87886 | Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin | HIGH | 7.8 | 21% | KEV EPSS 21%ile | NVD | 2026-09-17 |
| CVE-2026-58704 | In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (pr | HIGH | 8.8 | 11% | KEV EPSS 11%ile | NVD | 2026-09-15 |
| CVE / ID | Title | Severity | CVSS | EPSS | Why urgent | Source | Date |
|---|---|---|---|---|---|---|---|
| CVE-2024-4577 | Argument Injection in PHP-CGI | CRITICAL | 9.8 | 100% | PoC EPSS 100%ile | Microsoft | 2024-06-11 |
| CVE-2023-21554 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | CRITICAL | 9.8 | 100% | PoC EPSS 100%ile | Microsoft | 2023-04-11 |
| CVE-2026-50522 | Microsoft SharePoint Remote Code Execution Vulnerability | CRITICAL | 9.8 | 100% | PoC EPSS 100%ile | Microsoft | 2026-07-14 |
| CVE-2026-41089 | Windows Netlogon Remote Code Execution Vulnerability | CRITICAL | 9.8 | 100% | PoC EPSS 100%ile | Microsoft | 2026-05-12 |
| CVE-2026-55040 | Microsoft SharePoint Server Security Feature Bypass Vulnerability | CRITICAL | 9.1 | 99% | PoC EPSS 99%ile | Microsoft | 2026-07-14 |
| CVE-2025-50165 | Windows Graphics Component Remote Code Execution Vulnerability | CRITICAL | 9.8 | 95% | PoC EPSS 95%ile | Microsoft | 2025-08-12 |
| CVE-2026-43284 | xfrm: esp: avoid in-place decrypt on shared skb frags | HIGH | 7.8 | 100% | PoC EPSS 100%ile | Microsoft | 2026-05-12 |
| CVE-2026-43500 | rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present | HIGH | 7.8 | 100% | PoC EPSS 100%ile | Microsoft | 2026-05-12 |
| CVE-2023-50868 | MITRE: CVE-2023-50868 NSEC3 closest encloser proof can exhaust CPU | HIGH | 7.5 | 100% | PoC EPSS 100%ile | Microsoft | 2024-06-11 |
| CVE-2026-45659 | Microsoft SharePoint Remote Code Execution Vulnerability | HIGH | 8.8 | 100% | PoC EPSS 100%ile | Microsoft | 2026-05-12 |
| CVE-2026-42897 | Microsoft Exchange Server Spoofing Vulnerability | HIGH | 8.1 | 99% | PoC EPSS 99%ile | Microsoft | 2026-05-12 |
| CVE-2026-21509 | Microsoft Office Security Feature Bypass Vulnerability | HIGH | 7.8 | 99% | PoC EPSS 99%ile | Microsoft | 2026-01-13 |
| CVE-2026-42945 | NGINX ngx_http_rewrite_module vulnerability | HIGH | 8.1 | 99% | PoC EPSS 99%ile | Microsoft | 2026-05-12 |
| CVE-2024-30088 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.0 | 99% | PoC EPSS 99%ile | Microsoft | 2024-06-11 |
| CVE-2026-49160 | HTTP.sys Denial of Service Vulnerability | HIGH | 7.5 | 99% | PoC EPSS 99%ile | Microsoft | 2026-06-09 |
| CVE-2026-23918 | Apache HTTP Server: http2: double free and possible RCE on early reset | HIGH | 8.8 | 99% | PoC EPSS 99%ile | Microsoft | 2026-05-12 |
| CVE-2023-28252 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 99% | PoC EPSS 99%ile | Microsoft | 2023-04-11 |
| CVE-2023-28231 | DHCP Server Service Remote Code Execution Vulnerability | HIGH | 8.8 | 98% | PoC EPSS 98%ile | Microsoft | 2023-04-11 |
| CVE-2026-49975 | Apache HTTP Server: mod_http2 denial of service | HIGH | 7.5 | 98% | PoC EPSS 98%ile | Microsoft | 2026-06-09 |
| CVE-2026-21510 | Windows Shell Security Feature Bypass Vulnerability | HIGH | 8.8 | 98% | PoC EPSS 98%ile | Microsoft | 2026-02-10 |
| CVE-2024-35250 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 98% | PoC EPSS 98%ile | Microsoft | 2024-06-11 |
| CVE-2025-53772 | Web Deploy Remote Code Execution Vulnerability | HIGH | 8.8 | 98% | PoC EPSS 98%ile | Microsoft | 2025-08-12 |
| CVE-2025-55234 | Windows SMB Elevation of Privilege Vulnerability | HIGH | 8.8 | 97% | PoC EPSS 97%ile | Microsoft | 2025-09-09 |
| CVE-2025-54897 | Microsoft SharePoint Remote Code Execution Vulnerability | HIGH | 8.8 | 97% | PoC EPSS 97%ile | Microsoft | 2025-09-09 |
| CVE-2025-54918 | Windows NTLM Elevation of Privilege Vulnerability | HIGH | 8.8 | 97% | PoC EPSS 97%ile | Microsoft | 2025-09-09 |
| CVE-2024-30085 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 96% | PoC EPSS 96%ile | Microsoft | 2024-06-11 |
| CVE-2023-28218 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.0 | 96% | PoC EPSS 96%ile | Microsoft | 2023-04-11 |
| CVE-2026-20841 | Windows Notepad App Remote Code Execution Vulnerability | HIGH | 7.8 | 96% | PoC EPSS 96%ile | Microsoft | 2026-02-10 |
| CVE-2026-50656 | Microsoft Defender Elevation of Privilege Vulnerability | HIGH | 7.8 | 96% | PoC EPSS 96%ile | Microsoft | 2026-06-09 |
| CVE-2026-9256 | NGINX ngx_http_rewrite_module vulnerability | HIGH | 8.1 | 96% | PoC EPSS 96%ile | Microsoft | 2026-05-12 |
| CVE-2026-46300 | net: skbuff: preserve shared-frag marker during coalescing | HIGH | 7.8 | 95% | PoC EPSS 95%ile | Microsoft | 2026-05-12 |
| CVE-2025-41244 | VMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulnerabilities (CVE-2025-41244,CVE-202 | HIGH | 7.8 | 95% | PoC EPSS 95%ile | Microsoft | 2025-09-09 |
| CVE-2026-41091 | Microsoft Defender Elevation of Privilege Vulnerability | HIGH | 7.8 | 95% | PoC EPSS 95%ile | Microsoft | 2026-05-12 |
| CVE-2025-53786 | Microsoft Exchange Server Hybrid Deployment Elevation of Privilege Vulnerability | HIGH | 8.0 | 94% | PoC EPSS 94%ile | Microsoft | 2025-08-12 |
| CVE-2026-42980 | NT OS Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 94% | PoC EPSS 94%ile | Microsoft | 2026-06-09 |
| CVE-2026-42055 | NGINX ngx_http_proxy_v2_module and ngx_http_grpc_module vulnerability | HIGH | 8.1 | 94% | PoC EPSS 94%ile | Microsoft | 2026-06-09 |
| CVE-2026-68820 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.0 | 93% | PoC EPSS 93%ile | Microsoft | 2026-08-11 |
| CVE-2026-20817 | Windows Error Reporting Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 92% | PoC EPSS 92%ile | Microsoft | 2026-01-13 |
| CVE-2026-66804 | Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 92% | PoC EPSS 92%ile | Microsoft | 2026-08-11 |
| CVE-2026-40369 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 91% | PoC EPSS 91%ile | Microsoft | 2026-05-12 |
| CVE-2026-42533 | NGINX Map directive and Regex matching vulnerability | HIGH | 8.1 | 91% | PoC EPSS 91%ile | Microsoft | 2026-07-14 |
| CVE-2025-54110 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 8.8 | 90% | PoC EPSS 90%ile | Microsoft | 2025-09-09 |
| CVE-2026-55200 | libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c | HIGH | 8.1 | 90% | PoC EPSS 90%ile | Microsoft | 2026-06-09 |
| CVE-2026-21533 | Windows Remote Desktop Services Elevation of Privilege Vulnerability | HIGH | 7.8 | 90% | PoC EPSS 90%ile | Microsoft | 2026-02-10 |
| CVE-2026-45447 | Heap Use-After-Free in the PKCS7_verify() Function | HIGH | 8.8 | 89% | PoC EPSS 89%ile | Microsoft | 2026-06-09 |
| CVE-2026-46242 | eventpoll: fix ep_remove struct eventpoll / struct file UAF | HIGH | 7.8 | 87% | PoC EPSS 87%ile | Microsoft | 2026-05-12 |
| CVE-2023-28244 | Windows Kerberos Elevation of Privilege Vulnerability | HIGH | 8.1 | 86% | PoC EPSS 86%ile | Microsoft | 2023-04-11 |
| CVE-2026-63520 | Microsoft SharePoint Server Remote Code Execution Vulnerability | HIGH | 8.1 | 86% | PoC EPSS 86%ile | Microsoft | 2026-08-11 |
| CVE-2026-62737 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 86% | PoC EPSS 86%ile | Microsoft | 2026-08-11 |
| CVE-2024-36971 | net: fix __dst_negative_advice() race | HIGH | 7.8 | 85% | PoC EPSS 85%ile | Microsoft | 2024-06-11 |
| CVE-2026-53359 | Januscape: KVM/x86 guest-to-host escape (Intel + AMD) — kvmCTF 0-day | HIGH | 7.0 | 60% | PoC EPSS 60%ile | Featured | 2026-07-06 |
| CVE-2026-45498 | Microsoft Defender Denial of Service Vulnerability | MEDIUM | 4.0 | 99% | PoC EPSS 99%ile | Microsoft | 2026-05-12 |
| CVE-2025-50154 | Microsoft Windows File Explorer Spoofing Vulnerability | MEDIUM | 6.5 | 98% | PoC EPSS 98%ile | Microsoft | 2025-08-12 |
| CVE-2026-56164 | Microsoft SharePoint Server Elevation of Privilege Vulnerability | MEDIUM | 5.3 | 98% | PoC EPSS 98%ile | Microsoft | 2026-07-14 |
| CVE-2026-20805 | Desktop Window Manager Information Disclosure Vulnerability | MEDIUM | 5.5 | 92% | PoC EPSS 92%ile | Microsoft | 2026-01-13 |
| CVE-2026-50507 | Windows BitLocker Security Feature Bypass Vulnerability | MEDIUM | 6.8 | 92% | PoC EPSS 92%ile | Microsoft | 2026-06-09 |
| CVE-2015-0204 | OSSN-0045: = Vulnerable clients allow a TLS protocol downgrade (FREAK)= | UNKNOWN | — | 100% | PoC EPSS 100%ile | OpenStack | 2026-08-27 |
| CVE-2017-14491 | OSSN-0082: = Heap and Stack based buffer overflows in dnsmasq prior to version 2.78 = | UNKNOWN | — | 100% | PoC EPSS 100%ile | OpenStack | 2026-08-27 |
| CVE-2017-11826 | Microsoft Office Remote Code Execution Vulnerability | UNKNOWN | — | 100% | PoC EPSS 100%ile | Microsoft | 2017-10-10 |
| CVE-2017-11774 | Microsoft Outlook Security Feature Bypass Vulnerability | UNKNOWN | — | 99% | PoC EPSS 99%ile | Microsoft | 2017-10-10 |
| CVE-2023-2033 | Chromium: CVE-2023-2033 Type Confusion in V8 | UNKNOWN | — | 99% | PoC EPSS 99%ile | Microsoft | 2023-04-11 |
| CVE-2024-21907 | VulnCheck: CVE-2024-21907 Improper Handling of Exceptional Conditions in Newtonsoft.Json | UNKNOWN | — | 98% | PoC EPSS 98%ile | Microsoft | 2025-09-09 |
| CVE-2026-2441 | Chromium: CVE-2026-2441 Use after free in CSS | UNKNOWN | — | 98% | PoC EPSS 98%ile | Microsoft | 2026-02-10 |
| CVE-2026-0628 | Chromium: CVE-2026-0628 Insufficient policy enforcement in WebView tag | UNKNOWN | — | 94% | PoC EPSS 94%ile | Microsoft | 2026-01-13 |
| CVE-2025-10585 | Chromium: CVE-2025-10585 Type Confusion in V8 | UNKNOWN | — | 92% | PoC EPSS 92%ile | Microsoft | 2025-09-09 |
| CVE-2026-25243 | redis-server RESTORE invalid memory access may allow remote code execution | UNKNOWN | — | 89% | PoC EPSS 89%ile | Microsoft | 2026-05-12 |
| CVE-2025-9478 | Chromium: CVE-2025-9478 Use after free in ANGLE | UNKNOWN | — | 89% | PoC EPSS 89%ile | Microsoft | 2025-08-12 |
| CVE-2026-23631 | redis-server Lua use-after-free may allow remote code execution | UNKNOWN | — | 86% | PoC EPSS 86%ile | Microsoft | 2026-05-12 |
Updated 2026-09-18. Source: NVD, CISA KEV, EPSS (FIRST.org). JSON API available for automation.