Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2981 articles · 185100 vulns · 37/41 feeds (7d)

Trending Vulnerabilities

Top vulnerabilities ranked by news velocity, CISA KEV status, EPSS exploitation probability, and independent source coverage.

1
9.8
jetbrains · CVE-2026-63077 — CVE-2026-63077: In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent pollinKEVEXPLOITEDPATCHED
teamcity· CVSS 9.8· CWE-502
135🔥
11 art.
0
Jul 27, 2026
2
9.8
microsoft · CVE-2026-50522 — Microsoft SharePoint Remote Code Execution VulnerabilityKEVEXPLOITEDPATCHED
sharepoint_server· CVSS 9.8· CWE-502
129🔥
11 art.
0
Jul 14, 2026
3
5.3
microsoft · CVE-2026-56164 — Microsoft SharePoint Server Elevation of Privilege VulnerabilityKEVEXPLOITEDPATCHED
sharepoint_server· CVSS 5.3· CWE-306
128🔥
21 art.
0
Jul 14, 2026
4
9.6
progress · CVE-2026-8037 — OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAFKEVEXPLOITEDPATCHED
connection_manager_for_objectscale· CVSS 9.6· CWE-77
125🔥
9 art.
0
Jun 4, 2026
5
9.8
langflow · CVE-2026-9198 — Unauthenticated Remote Code Execution via Auto-Login Bypass and Code ValidationKEVEXPLOITEDPATCHED
langflow· CVSS 9.8· CWE-94
123🔥
6 art.
0
Jul 17, 2026
6
9.3
checkpoint · CVE-2026-50751 — User Authentication Bypass in VPN Remote Access and Mobile AccessKEVEXPLOITEDPATCHED
gaia_os· CVSS 9.3· CWE-287
88
23 art.
0
Jun 8, 2026
7
8.5
red hat · CVE-2026-4480 — Samba: samba: remote code execution in printing subsystem via unescaped job descriptionKEVEXPLOITEDPATCHED
openshift_container_platform· CVSS 8.5· CWE-78
80
5 art.
0
May 26, 2026
8
6.1
alinto sogo · CVE-2026-8496 — A cross-site scripting (XSS) vulnerability in Alinto SOGo, version 5.12.7KEVEXPLOITEDPATCHED
sogo· CVSS 6.1· CWE-79
75
2 art.
0
May 13, 2026
9
9.8
exim · CVE-2026-45185 — CVE-2026-45185: Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing pEXPLOITEDPATCHED
exim· CVSS 9.8· EPSS 0.01· CWE-416
74
7 art.
0
May 12, 2026
10
10.0
arista · CVE-2026-16812 — VeloCloud Orchestrator OS Command InjectionPATCHED
velocloud_orchestrator· CVSS 10.0· CWE-78
74
8 art.
0
Jul 27, 2026
11
8.8
linux · CVE-2026-53359 — KVM: x86: Fix shadow paging use-after-free due to unexpected roleEXPLOITEDPATCHED
linux_kernel· CVSS 8.8
73
20 art.
0
Jul 4, 2026
12
7.8
linux · CVE-2026-46331 — net/sched: fix pedit partial COW leading to page cache corruptionEXPLOITEDPATCHED
linux_kernel· CVSS 7.8
72
16 art.
0
Jun 16, 2026
13
8.1
microsoft · CVE-2026-42897 — Microsoft Exchange Server Spoofing VulnerabilityKEVEXPLOITEDPATCHED
exchange_server· CVSS 8.1· CWE-79
72
30 art.
0
May 14, 2026
14
7.1
apple · CVE-2026-65400 — CVE-2026-65400: An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOSEXPLOITEDPATCHED
macos· CVSS 7.1· CWE-20
70
6 art.
0
Aug 6, 2026
15
10.0
brandexponents · CVE-2026-66665 — WordPress Type Hub plugin <= 2.0.6 - Arbitrary File Upload vulnerabilityKEVEXPLOITED
type hub· CVSS 10.0· CWE-434
68
1 art.
0
Aug 6, 2026
16
8.1
f5 · CVE-2026-42945 — NGINX ngx_http_rewrite_module vulnerabilityKEVEXPLOITEDPATCHED
dos· CVSS 8.1· CWE-122
65
25 art.
0
May 13, 2026
17
9.8
apache · CVE-2026-41293 — Apache Tomcat: HTTP/2 request headers not validatedEXPLOITEDPATCHED
tomcat· CVSS 9.8· CWE-20
64
10 art.
0
May 12, 2026
18
8.8
openssl · CVE-2026-45447 — Heap Use-After-Free in the PKCS7_verify() FunctionEXPLOITEDPATCHED
openssl· CVSS 8.8· CWE-416
64
14 art.
0
Jun 9, 2026
19
7.1
linux · CVE-2026-46243 — smb: client: reject userspace cifs.spnego descriptionsEXPLOITEDPATCHED
linux_kernel· CVSS 7.1
63
11 art.
0
Jun 1, 2026
20
7.8
linux · CVE-2026-64600 — xfs: resample the data fork mapping after cycling ILOCKEXPLOITEDPATCHED
linux kernel· CVSS 7.8
63
15 art.
0
Jul 23, 2026
21
9.1
arm · CVE-2025-10263 — CVE-2025-10263: Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4EXPLOITED
cortex· CVSS 9.1· CWE-362
62
17 art.
0
Jun 9, 2026
22
—
google · CVE-2026-12537 — Unauthenticated Remote Code Execution in Gemini CLI CI/CD WorkflowsEXPLOITEDPATCHED
gemini-cli· CWE-20
60
2 art.
0
Jun 24, 2026
23
7.8
linux · CVE-2026-43499 — rtmutex: Use waiter::task instead of current in remove_waiter()EXPLOITEDPATCHED
linux_kernel· CVSS 7.8
60
14 art.
0
May 21, 2026
24
7.5
isc · CVE-2026-5946 — Invalid handling of CLASS != INEXPLOITEDPATCHED
bind· CVSS 7.5· CWE-20
59
7 art.
0
May 20, 2026
25
9.1
archive\ · CVE-2026-42496 — Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directoryEXPLOITEDPATCHED
\· CVSS 9.1· EPSS 0.00· CWE-59
59
6 art.
0
May 26, 2026
26
5.3
cis · CVE-2026-20316 — Cisco Secure Firewall Management Center Software Static Credential Vulnerability
secure_firewall_management_center· CVSS 5.3· CWE-259
58
11 art.
0
Jul 29, 2026
27
9.8
cis · CVE-2026-20272 — Cisco IOS XE Software Security Hardening Release
cisco ios xe· CVSS 9.8· CWE-74
57
5 art.
0
Aug 5, 2026
28
7.5
perl · CVE-2026-48962 — IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output globEXPLOITEDPATCHED
io::compress· CVSS 7.5· CWE-95
57
6 art.
0
May 27, 2026
29
—
rubygems · CVE-2026-66066 — Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processingPATCHED
activestorage· CWE-1188
56
14 art.
0
Jul 30, 2026
30
7.5
archive\ · CVE-2026-42497 — Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directoryEXPLOITEDPATCHED
\· CVSS 7.5· CWE-59
56
5 art.
0
May 26, 2026
31
9.1
apache · CVE-2026-43515 — Apache Tomcat: Security constraints not correctly appliedEXPLOITEDPATCHED
tomcat· CVSS 9.1· CWE-285
56
10 art.
0
May 12, 2026
32
7.3
apache · CVE-2026-42498 — Apache Tomcat: WebSocket authentication header exposureEXPLOITEDPATCHED
tomcat· CVSS 7.3· CWE-200
55
7 art.
0
May 12, 2026
33
7.8
linux · CVE-2026-53366 — ipv4: account for fraggap on the paged allocation pathEXPLOITEDPATCHED
linux_kernel· CVSS 7.8
55
12 art.
0
Jul 16, 2026
34
8.1
fasterxml · CVE-2026-54512 — jackson-databind: PolymorphicTypeValidator bypass via generic type parameters allows arbitrary class instantiationEXPLOITEDPATCHED
jackson-databind· CVSS 8.1· CWE-184
55
6 art.
0
Jun 23, 2026
35
10.0
sonicwall · CVE-2026-15409 — CVE-2026-15409: A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A EXPLOITEDPATCHED
sma6210_firmware· CVSS 10.0· CWE-918
55
23 art.
0
Jul 14, 2026
36
7.5
apache · CVE-2026-41284 — Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handlingEXPLOITEDPATCHED
tomcat· CVSS 7.5· CWE-770
55
7 art.
0
May 12, 2026
37
7.5
isc · CVE-2026-3039 — BIND 9 server memory exhaustion during GSS-API TKEY negotiationEXPLOITEDPATCHED
bind· CVSS 7.5· CWE-771
54
5 art.
0
May 20, 2026
38
9.8
apache · CVE-2026-43512 — Apache Tomcat: Digest authenticator will authenticate any unknown userPATCHED
tomcat· CVSS 9.8· CWE-287
53
10 art.
0
May 12, 2026
39
7.3
dnsmasq · CVE-2026-2291 — CVE-2026-2291EXPLOITEDPATCHED
dnsmasq· CVSS 7.3
52
7 art.
0
May 11, 2026
40
7.8
palo alto networks · CVE-2026-0257 — PAN-OS: GlobalProtect Authentication Bypass VulnerabilitiesEXPLOITEDPATCHED
pan-os· CVSS 7.8· CWE-565
52
23 art.
0
May 13, 2026
41
8.8
Cisco · CVE-2026-20200 — Cisco Integrated Management Controller Argument Injection and Remote Code Execution Vulnerability
Cisco Unified Computing System (Standalone)· CVSS 8.8· CWE-141
52
7 art.
0
Aug 5, 2026
42
—
linux · CVE-2026-53306 — tty: hvc_iucv: fix off-by-one in number of supported devicesEXPLOITEDPATCHED
linux_kernel
52
7 art.
0
Jun 26, 2026
43
—
linux · CVE-2026-63836 — batman-adv: tp_meter: avoid divide-by-zero for dec_cwndEXPLOITEDPATCHED
linux kernel
52
6 art.
0
Jul 19, 2026
44
—
amd · CVE-2025-54518 — CVE-2025-54518: Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker toEXPLOITEDPATCHED
zen· CWE-1189
52
15 art.
0
May 13, 2026
45
10.0
microsoft · CVE-2026-56162 — Azure SQL Database Elevation of Privilege VulnerabilityPATCHED
azure_sql_database· CVSS 10.0· CWE-287
51
3 art.
0
Aug 6, 2026
46
9.9
Cisco · CVE-2026-20303 — Cisco Catalyst SD-WAN Security Hardening Release - Input Validation Vulnerabilities
Cisco Catalyst SD-WAN Controller· CVSS 9.9· CWE-20
51
6 art.
0
Aug 5, 2026
47
9.8
linux · CVE-2026-53309 — ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparisonEXPLOITEDPATCHED
linux_kernel· CVSS 9.8
51
5 art.
0
Jun 26, 2026
48
7.5
ietf · CVE-2026-4890 — CVE-2026-4890PATCHED
dnsmasq· CVSS 7.5
51
7 art.
0
May 11, 2026
49
—
linux · CVE-2026-53291 — ALSA: hda/conexant: Fix missing error check for jack detectionEXPLOITEDPATCHED
linux_kernel
51
5 art.
0
Jun 26, 2026
50
10.0
microsoft · CVE-2026-65667 — Microsoft Teams Elevation of Privilege VulnerabilityPATCHED
teams· CVSS 10.0· CWE-862
51
3 art.
0
Aug 6, 2026