Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4500 articles · 223826 vulns · 37/41 feeds (7d)

Trending Vulnerabilities

Top vulnerabilities ranked by news velocity, CISA KEV status, EPSS exploitation probability, and independent source coverage.

1
9.8
checkpoint · CVE-2026-85102 — Improper Certificate Validation in Quantum Security GatewayKEVEXPLOITED
gaia_embedded· CVSS 9.8· CWE-295
156🔥
15 art.
0
Sep 9, 2026
2
9.8
checkpoint · CVE-2026-93616 — Directory Traversal and File upload allows execution of arbitrary script on the Management ServerKEVEXPLOITED
multi-domain_security_management· CVSS 9.8· CWE-22
152🔥
10 art.
0
Sep 22, 2026
3
8.1
WordPress · CVE-2026-87902 — CVE-2026-87902: An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.phKEVEXPLOITEDPATCHED
WordPress· CVSS 8.1· CWE-98
144🔥
13 art.
0
Sep 22, 2026
4
—
citrix netscaler · CVE-2026-88771 — A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commandsKEVEXPLOITEDPATCHED
adc· CWE-20
127🔥
2 art.
0
Sep 27, 2026
5
9.8
f5 · CVE-2026-94127 — BIG-IP APM OAuth vulnerabilityKEVEXPLOITEDPATCHED
big-ip_access_policy_manager· CVSS 9.8· CWE-122
120🔥
13 art.
0
Sep 22, 2026
6
—
citrix netscaler · CVE-2026-88772 — Memory overflow vulnerability leading to Remote Code Execution or Denial of ServiceKEVEXPLOITEDPATCHED
adc· CWE-119
117🔥
2 art.
0
Sep 27, 2026
7
10.0
gitlab · CVE-2026-85706 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLabKEVEXPLOITEDPATCHED
gitlab· CVSS 10.0· CWE-22
114🔥
9 art.
0
Sep 12, 2026
8
9.1
adobe · CVE-2026-71362 — Adobe Commerce | Incorrect Authorization (CWE-863)KEVEXPLOITEDPATCHED
commerce· CVSS 9.1· CWE-863
112🔥
8 art.
0
Aug 11, 2026
9
9.8
issabel foundation · CVE-2026-89026 — Issabel Framework Hard-coded JWT Key RCE via pbxapi/manager/originateKEVEXPLOITEDPATCHED
issabel framework· CVSS 9.8· CWE-321
107🔥
3 art.
0
Sep 15, 2026
10
10.0
cis · CVE-2026-76460 — Cisco Identity Services Engine Authentication Bypass VulnerabilityKEVEXPLOITED
identity_services_engine· CVSS 10.0· CWE-648
107🔥
17 art.
0
Sep 16, 2026
11
9.8
jetbrains · CVE-2026-63077 — CVE-2026-63077: In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent pollinKEVEXPLOITEDPATCHED
teamcity· CVSS 9.8· CWE-502
102🔥
14 art.
0
Jul 27, 2026
12
10.0
arista · CVE-2026-93952 — Security Advisory 0183KEVEXPLOITEDPATCHED
velocloud_orchestrator· CVSS 10.0· CWE-20
99
8 art.
0
Sep 22, 2026
13
7.8
linux · CVE-2026-53362 — ipv6: account for fraggap on the paged allocation pathKEVEXPLOITEDPATCHED
linux_kernel· CVSS 7.8
96
15 art.
0
Jul 4, 2026
14
10.0
sonicwall · CVE-2026-83548 — CVE-2026-83548: A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternKEVEXPLOITEDPATCHED
sma8200v· CVSS 10.0· CWE-918
91
19 art.
0
Sep 1, 2026
15
7.8
sonicwall · CVE-2026-83549 — CVE-2026-83549: Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerabiKEVEXPLOITEDPATCHED
sma8200v· CVSS 7.8· CWE-78
84
14 art.
0
Sep 1, 2026
16
—
mikrotik · CVE-2026-86060 — SSH session privilege manipulation via a crafted username in Mikrotik RouterOSKEVEXPLOITEDPATCHED
routeros· CWE-88
84
10 art.
0
Sep 5, 2026
17
—
citrix · CVE-2026-19490 — NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490
netscaler_application_delivery_controller
83
15 art.
0
Aug 19, 2026
18
7.8
microsoft · CVE-2026-85880 — Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege VulnerabilityKEVEXPLOITEDPATCHED
windows_10_1607· CVSS 7.8· CWE-122
81
20 art.
0
Sep 8, 2026
19
8.8
google · CVE-2026-87491 — CVE-2026-87491: Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inKEVEXPLOITEDPATCHED
chrome· CVSS 8.8· CWE-787
81
17 art.
0
Sep 9, 2026
20
9.8
apple · CVE-2026-65400 — CVE-2026-65400: An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOSKEVEXPLOITEDPATCHED
macos· CVSS 9.8
81
23 art.
0
Aug 6, 2026
21
8.8
google · CVE-2026-85046 — CVE-2026-85046: Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside KEVEXPLOITEDPATCHED
chrome· CVSS 8.8· CWE-843
81
24 art.
0
Sep 3, 2026
22
8.8
microsoft · CVE-2026-65660 — Microsoft SharePoint Server Remote Code Execution VulnerabilityPATCHED
sharepoint_server· CVSS 8.8· CWE-94
74
9 art.
0
Aug 11, 2026
23
—
mikrotik · CVE-2026-67279 — SSH Pre-Authentication Rekey State Bypass in MikroTik RouterOSKEVEXPLOITEDPATCHED
routeros· CWE-841
71
4 art.
0
Sep 5, 2026
24
9.8
vmware · CVE-2026-59309 — vCenter authentication-bypass vulnerabilityKEVEXPLOITEDPATCHED
vcenter_server· CVSS 9.8· CWE-303
67
9 art.
0
Jul 30, 2026
25
8.8
linux · CVE-2026-53359 — KVM: x86: Fix shadow paging use-after-free due to unexpected roleEXPLOITEDPATCHED
linux_kernel· CVSS 8.8
65
35 art.
0
Jul 4, 2026
26
9.8
cis · CVE-2026-76461 — Cisco Secure Email Gateway SQL Injection VulnerabilityKEVEXPLOITED
asyncos· CVSS 9.8· CWE-89
62
13 art.
0
Sep 14, 2026
27
—
citrix · CVE-2026-19489 — CVE-2026-19489: Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 thr
adc
61
9 art.
0
Aug 19, 2026
28
10.0
wso2 · CVE-2026-5430 — Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Account TakeoverPATCHED
api_control_plane· CVSS 10.0· CWE-347
55
5 art.
0
Aug 6, 2026
29
7.1
nicolaskulka · CVE-2026-93622 — WordPress WPS Limit Login plugin <= 1.5.9.3 - Cross Site Scripting (XSS) vulnerabilityKEVEXPLOITED
wps limit login· CVSS 7.1· CWE-79
52
1 art.
0
Sep 23, 2026
30
9.1
checkpoint · CVE-2026-16232 — Authentication Bypass in the SmartConsole Login Process Using an Application TokenEXPLOITED
multi-domain_security_management· CVSS 9.1· CWE-287
51
17 art.
0
Jul 22, 2026
31
7.8
linux · CVE-2026-53366 — ipv4: account for fraggap on the paged allocation pathEXPLOITEDPATCHED
linux_kernel· CVSS 7.8
50
20 art.
0
Jul 16, 2026
32
5.4
openclaw · CVE-2026-100604 — ClawHub Authentication Bypass via Former Publisher Skill ControlEXPLOITEDPATCHED
clawhub· CVSS 5.4· CWE-863
48
3 art.
0
Sep 26, 2026
33
9.8
checkpoint · CVE-2026-91843 — Stack overflow in login process to the Security Management and Log Servers
quantum security management· CVSS 9.8· CWE-121
48
10 art.
0
Sep 16, 2026
34
10.0
arista · CVE-2026-16812 — VeloCloud Orchestrator OS Command InjectionPATCHED
velocloud_orchestrator· CVSS 10.0· CWE-78
48
9 art.
0
Jul 27, 2026
35
8.8
linux · CVE-2026-53360 — KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in useEXPLOITEDPATCHED
linux_kernel· CVSS 8.8
47
12 art.
0
Jul 4, 2026
36
5.3
cis · CVE-2026-20316 — Cisco Secure Firewall Management Center Software Static Credential Vulnerability
secure_firewall_management_center· CVSS 5.3· CWE-259
47
20 art.
0
Jul 29, 2026
37
7.5
red hat · CVE-2026-96280 — Flatpak: flatpak: buffer overflow in oci delta stream path names on 32-bit systemsEXPLOITED
red hat enterprise linux· CVSS 7.5· CWE-197
46
1 art.
0
Sep 27, 2026
38
7.5
nodeca · CVE-2026-59869 — js-yaml: YAML merge-key chains can force quadratic CPU consumption
js-yaml· CVSS 7.5· CWE-407
46
9 art.
0
Jul 8, 2026
39
9.1
bouncycastle · CVE-2026-8763 — Name Constraints bypass via trailing dot in rfc822Name and URIPATCHED
bc-java· CVSS 9.1· CWE-295
46
7 art.
0
Aug 3, 2026
40
10.0
sap_ · CVE-2026-44756 — Memory Corruption vulnerability in SAP Extended Passport (EPP) Processing
sap extended passport (epp) processing· CVSS 10.0· CWE-120
46
9 art.
0
Sep 8, 2026
41
9.1
apache · CVE-2026-71290 — Apache HttpComponents Client: TLS hostname verification silently disabled on the async transport (default config, MITM)PATCHED
httpclient· CVSS 9.1· CWE-295
46
6 art.
0
Aug 11, 2026
42
7.8
linux · CVE-2026-64581 — xfrm: fix sk_dst_cache double-free in xfrm_user_policy()EXPLOITEDPATCHED
linux kernel· CVSS 7.8
45
10 art.
0
Aug 5, 2026
43
9.1
CVE-2026-92288 — Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow unauthenticated OAuth2 token introspection because checkEndPointAuthenticationCredentials does not verify the client secret of a public Relying PartyPATCHED
· CVSS 9.1· CWE-1390
45
2 art.
0
Sep 25, 2026
44
7.5
eclip · CVE-2026-9563 — CVE-2026-9563: In Eclipse Parsson published Maven Central artifacts before version 1.1.8, the JSON parser did not enforce a default max
parsson· CVSS 7.5· CWE-400
44
7 art.
0
Jul 2, 2026
45
9.8
solarwinds · CVE-2026-28324 — SolarWinds Observability Self-Hosted Remote Code Execution VulnerabilityPATCHED
observability self-hosted· CVSS 9.8· CWE-345
44
5 art.
0
Sep 22, 2026
46
—
linux · CVE-2026-53372 — iommu/vt-d: Block PASID attachment to nested domain with dirty trackingEXPLOITEDPATCHED
linux_kernel
44
6 art.
0
Jul 19, 2026
47
7.5
CVE-2026-69152 — brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigationPATCHED
brace-expansion· CVSS 7.5· CWE-400
44
7 art.
0
Aug 3, 2026
48
9.8
linux · CVE-2026-64564 — sctp: don't free the ASCONF's own transport in DEL-IP processingPATCHED
linux kernel· CVSS 9.8
44
19 art.
0
Aug 4, 2026
49
7.5
browserslist · CVE-2026-73088 — Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.json custom stats (normalizeStats)PATCHED
browserslist· CVSS 7.5· CWE-248
43
5 art.
0
Aug 11, 2026
50
6.2
red hat · CVE-2026-96281 — Flatpak: flatpak: unprivileged active user can bypass anti-downgrade checks for system apps/runtimesEXPLOITED
red hat enterprise linux· CVSS 6.2· CWE-284
43
1 art.
0
Sep 27, 2026