← Back to feed Patch nowTrending

🚫 Zero-Days & Active Exploits

Vulnerabilities being actively exploited in the wild right now, plus CVEs with public proof-of-concept code. Updated every 4 hours from CISA KEV and NVD.

Sources CISA KEV: U.S. Cybersecurity & Infrastructure Security Agency Known Exploited Vulnerabilities catalog — confirmed in-the-wild exploitation by threat actors.
PoC: Public proof-of-concept exploit code exists in the wild (Exploit-DB, GitHub, security research). Exploitation not yet confirmed by CISA but weaponized code is available.

Actively exploited in the wild (10 CVEs) CISA KEV confirmed

CVE / IDTitleSeverityCVSSEPSSWhy urgentSourceDate
CVE-2026-85706GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 1CRITICAL10.096%KEV — actively exploited PoC public EPSS 96%ileNVD2026-09-12
CVE-2026-76461A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticCRITICAL9.880%KEV — actively exploited EPSS 80%ileNVD2026-09-14
CVE-2026-76460A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypCRITICAL10.054%KEV — actively exploited EPSS 54%ileNVD2026-09-16
CVE-2026-42018JFrog Artifactory Improper Authentication VulnerabilityHIGH59%KEV — actively exploited EPSS 59%ileCISA-KEV2026-09-11
CVE-2026-42016JFrog Artifactory Incorrect Authorization VulnerabilityHIGH58%KEV — actively exploited EPSS 58%ileCISA-KEV2026-09-11
CVE-2026-84869ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization VulnerabilityHIGH51%KEV — actively exploited EPSS 51%ileCISA-KEV2026-09-11
CVE-2025-39964Linux Kernel Race Condition VulnerabilityHIGH26%KEV — actively exploited EPSS 26%ileCISA-KEV2026-09-18
CVE-2026-87886Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin HIGH7.821%KEV — actively exploited EPSS 21%ileNVD2026-09-17
CVE-2026-58704In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (prHIGH8.811%KEV — actively exploited EPSS 11%ileNVD2026-09-15
CVE-2026-53266netfilter: bridge: make ebt_snat ARP rewrite writableMEDIUM6.82%KEV — actively exploited EPSS 2%ileMicrosoft2026-06-09

Public exploit code available (53 CVEs) not yet KEV-listed

CVE / IDTitleSeverityCVSSEPSSWhy urgentSourceDate
CVE-2024-4577Argument Injection in PHP-CGICRITICAL9.8100%PoC public EPSS 100%ileMicrosoft2024-06-11
CVE-2023-21554Microsoft Message Queuing (MSMQ) Remote Code Execution VulnerabilityCRITICAL9.8100%PoC public EPSS 100%ileMicrosoft2023-04-11
CVE-2026-50522Microsoft SharePoint Remote Code Execution VulnerabilityCRITICAL9.8100%PoC public EPSS 100%ileMicrosoft2026-07-14
CVE-2026-41089Windows Netlogon Remote Code Execution VulnerabilityCRITICAL9.8100%PoC public EPSS 100%ileMicrosoft2026-05-12
CVE-2026-55040Microsoft SharePoint Server Security Feature Bypass VulnerabilityCRITICAL9.199%PoC public EPSS 99%ileMicrosoft2026-07-14
CVE-2025-50165Windows Graphics Component Remote Code Execution VulnerabilityCRITICAL9.895%PoC public EPSS 95%ileMicrosoft2025-08-12
CVE-2026-43284xfrm: esp: avoid in-place decrypt on shared skb fragsHIGH7.8100%PoC public EPSS 100%ileMicrosoft2026-05-12
CVE-2026-43500rxrpc: Also unshare DATA/RESPONSE packets when paged frags are presentHIGH7.8100%PoC public EPSS 100%ileMicrosoft2026-05-12
CVE-2023-50868MITRE: CVE-2023-50868 NSEC3 closest encloser proof can exhaust CPUHIGH7.5100%PoC public EPSS 100%ileMicrosoft2024-06-11
CVE-2026-45659Microsoft SharePoint Remote Code Execution VulnerabilityHIGH8.8100%PoC public EPSS 100%ileMicrosoft2026-05-12
CVE-2026-42897Microsoft Exchange Server Spoofing VulnerabilityHIGH8.199%PoC public EPSS 99%ileMicrosoft2026-05-12
CVE-2026-21509Microsoft Office Security Feature Bypass VulnerabilityHIGH7.899%PoC public EPSS 99%ileMicrosoft2026-01-13
CVE-2026-42945NGINX ngx_http_rewrite_module vulnerabilityHIGH8.199%PoC public EPSS 99%ileMicrosoft2026-05-12
CVE-2024-30088Windows Kernel Elevation of Privilege VulnerabilityHIGH7.099%PoC public EPSS 99%ileMicrosoft2024-06-11
CVE-2026-49160HTTP.sys Denial of Service VulnerabilityHIGH7.599%PoC public EPSS 99%ileMicrosoft2026-06-09
CVE-2026-23918Apache HTTP Server: http2: double free and possible RCE on early resetHIGH8.899%PoC public EPSS 99%ileMicrosoft2026-05-12
CVE-2023-28252Windows Common Log File System Driver Elevation of Privilege VulnerabilityHIGH7.899%PoC public EPSS 99%ileMicrosoft2023-04-11
CVE-2023-28231DHCP Server Service Remote Code Execution VulnerabilityHIGH8.898%PoC public EPSS 98%ileMicrosoft2023-04-11
CVE-2026-49975Apache HTTP Server: mod_http2 denial of serviceHIGH7.598%PoC public EPSS 98%ileMicrosoft2026-06-09
CVE-2026-21510Windows Shell Security Feature Bypass VulnerabilityHIGH8.898%PoC public EPSS 98%ileMicrosoft2026-02-10
CVE-2024-35250Windows Kernel-Mode Driver Elevation of Privilege VulnerabilityHIGH7.898%PoC public EPSS 98%ileMicrosoft2024-06-11
CVE-2025-53772Web Deploy Remote Code Execution VulnerabilityHIGH8.898%PoC public EPSS 98%ileMicrosoft2025-08-12
CVE-2025-55234Windows SMB Elevation of Privilege VulnerabilityHIGH8.897%PoC public EPSS 97%ileMicrosoft2025-09-09
CVE-2025-54897Microsoft SharePoint Remote Code Execution VulnerabilityHIGH8.897%PoC public EPSS 97%ileMicrosoft2025-09-09
CVE-2025-54918Windows NTLM Elevation of Privilege VulnerabilityHIGH8.897%PoC public EPSS 97%ileMicrosoft2025-09-09
CVE-2024-30085Windows Cloud Files Mini Filter Driver Elevation of Privilege VulnerabilityHIGH7.896%PoC public EPSS 96%ileMicrosoft2024-06-11
CVE-2023-28218Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityHIGH7.096%PoC public EPSS 96%ileMicrosoft2023-04-11
CVE-2026-20841Windows Notepad App Remote Code Execution VulnerabilityHIGH7.896%PoC public EPSS 96%ileMicrosoft2026-02-10
CVE-2026-50656Microsoft Defender Elevation of Privilege VulnerabilityHIGH7.896%PoC public EPSS 96%ileMicrosoft2026-06-09
CVE-2026-9256NGINX ngx_http_rewrite_module vulnerabilityHIGH8.196%PoC public EPSS 96%ileMicrosoft2026-05-12
CVE-2026-46300net: skbuff: preserve shared-frag marker during coalescingHIGH7.895%PoC public EPSS 95%ileMicrosoft2026-05-12
CVE-2025-41244VMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulnerabilities (CVE-2025-41244,CVE-202HIGH7.895%PoC public EPSS 95%ileMicrosoft2025-09-09
CVE-2026-41091Microsoft Defender Elevation of Privilege VulnerabilityHIGH7.895%PoC public EPSS 95%ileMicrosoft2026-05-12
CVE-2025-53786Microsoft Exchange Server Hybrid Deployment Elevation of Privilege VulnerabilityHIGH8.094%PoC public EPSS 94%ileMicrosoft2025-08-12
CVE-2026-42980NT OS Kernel Elevation of Privilege VulnerabilityHIGH7.894%PoC public EPSS 94%ileMicrosoft2026-06-09
CVE-2026-42055NGINX ngx_http_proxy_v2_module and ngx_http_grpc_module vulnerabilityHIGH8.194%PoC public EPSS 94%ileMicrosoft2026-06-09
CVE-2026-68820Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityHIGH7.093%PoC public EPSS 93%ileMicrosoft2026-08-11
CVE-2026-20817Windows Error Reporting Service Elevation of Privilege VulnerabilityHIGH7.892%PoC public EPSS 92%ileMicrosoft2026-01-13
CVE-2026-66804Microsoft Windows Cross Device Service Elevation of Privilege VulnerabilityHIGH7.892%PoC public EPSS 92%ileMicrosoft2026-08-11
CVE-2026-40369Windows Kernel Elevation of Privilege VulnerabilityHIGH7.891%PoC public EPSS 91%ileMicrosoft2026-05-12
CVE-2026-42533NGINX Map directive and Regex matching vulnerabilityHIGH8.191%PoC public EPSS 91%ileMicrosoft2026-07-14
CVE-2025-54110Windows Kernel Elevation of Privilege VulnerabilityHIGH8.890%PoC public EPSS 90%ileMicrosoft2025-09-09
CVE-2026-55200libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.cHIGH8.190%PoC public EPSS 90%ileMicrosoft2026-06-09
CVE-2026-21533Windows Remote Desktop Services Elevation of Privilege VulnerabilityHIGH7.890%PoC public EPSS 90%ileMicrosoft2026-02-10
CVE-2026-45447Heap Use-After-Free in the PKCS7_verify() FunctionHIGH8.889%PoC public EPSS 89%ileMicrosoft2026-06-09
CVE-2026-46242eventpoll: fix ep_remove struct eventpoll / struct file UAFHIGH7.887%PoC public EPSS 87%ileMicrosoft2026-05-12
CVE-2023-28244Windows Kerberos Elevation of Privilege VulnerabilityHIGH8.186%PoC public EPSS 86%ileMicrosoft2023-04-11
CVE-2026-63520Microsoft SharePoint Server Remote Code Execution VulnerabilityHIGH8.186%PoC public EPSS 86%ileMicrosoft2026-08-11
CVE-2026-62737Windows Kernel Elevation of Privilege VulnerabilityHIGH7.886%PoC public EPSS 86%ileMicrosoft2026-08-11
CVE-2024-36971net: fix __dst_negative_advice() raceHIGH7.885%PoC public EPSS 85%ileMicrosoft2024-06-11
CVE-2026-53359Januscape: KVM/x86 guest-to-host escape (Intel + AMD) — kvmCTF 0-dayHIGH7.060%PoC public EPSS 60%ileFeatured2026-07-06
CVE-2025-50154Microsoft Windows File Explorer Spoofing VulnerabilityMEDIUM6.598%PoC public EPSS 98%ileMicrosoft2025-08-12
CVE-2026-50507Windows BitLocker Security Feature Bypass VulnerabilityMEDIUM6.892%PoC public EPSS 92%ileMicrosoft2026-06-09

Updated 2026-09-18. KEV source: CISA KEV catalog. PoC data aggregated from Exploit-DB and GitHub advisories. JSON API available.