Recent Critical Vulnerabilities
The latest critical severity CVEs, sorted by publication date. 50 critical vulnerabilities tracked.
50
Critical CVEs
Aug 11
Latest Published
15
CVSS 10.0
CVE-2026-46670 Aug 11, 2026
YesWiki SQL injection leaks all credentials (CVE-2026-46670)
CVSS 9.8
CVE-2026-72898 Aug 10, 2026
Metabase SQL injection grants admin access (CVE-2026-72898)
CVSS 10
CVE-2026-16812 Jul 27, 2026
VCO orchestator unauth access exploited (CVE-2026-16812)
CVSS 10
CVE-2026-55579 Jul 27, 2026
Pheditor hardcoded admin RCE (CVE-2026-55579) [PoC]
CVSS 9.8
CVE-2026-63077 Jul 27, 2026
TeamCity RCE exploited in the wild (CVE-2026-63077) [PoC]
CVSS 9.8 Jetbrains Teamcity
CVE-2026-47668 Jul 23, 2026
DbGate unauthenticated RCE (CVE-2026-47668) [PoC]
CVSS 10
CVE-2026-16232 Jul 22, 2026
Check Point SmartConsole auth bypass exploited (CVE-2026-16232) [PoC]
CVSS 9.1
CVE-2026-60137 Jul 17, 2026
WordPress SQLi exploited in the wild (CVE-2026-60137) [PoC]
CVSS 9.1
CVE-2026-63030 Jul 17, 2026
WordPress REST API unauth RCE (CVE-2026-63030) [PoC]
CVSS 9.8
CVE-2026-9198 Jul 17, 2026
Langflow unauthenticated RCE exploited in wild (CVE-2026-9198) [PoC]
CVSS 9.8 Langflow
CVE-2026-15409 Jul 14, 2026
SMA1000 Appliance SSRF exploited in wild (CVE-2026-15409) [PoC]
CVSS 10
CVE-2026-50522 Jul 14, 2026
SharePoint unauthenticated RCE actively exploited (CVE-2026-50522) [PoC]
CVSS 9.8 Microsoft Sharepoint Server
CVE-2026-56164 Jul 14, 2026
SharePoint privilege escalation exploited (CVE-2026-56164) [PoC]
CVSS 9.8 Microsoft Sharepoint Server
CVE-2026-58644 Jul 14, 2026
SharePoint unauthenticated RCE exploited (CVE-2026-58644)
CVSS 9.8 Microsoft Sharepoint Server
CVE-2026-56291 Jul 9, 2026
Balbooa Forms unauthenticated RCE exploited (CVE-2026-56291) [PoC]
CVSS 10 Balbooa Forms
CVE-2026-34038 Jul 6, 2026
Coolify RCE leaks secrets (CVE-2026-34038) [PoC]
CVSS 9.9
CVE-2026-48282 Jun 30, 2026
ColdFusion RCE exploited in wild (CVE-2026-48282) [PoC]
CVSS 10 Adobe Coldfusion
CVE-2026-58138 Jun 30, 2026
Orkes Conductor unauth RCE (CVE-2026-58138) [PoC]
CVSS 9.8
CVE-2026-56290 Jun 29, 2026
Page Builder CK unauth RCE exploited (CVE-2026-56290) [PoC]
CVSS 10 Joomlack Page Builder Ck
CVE-2026-48908 Jun 20, 2026
SP Page Builder unauth file upload (CVE-2026-48908) [PoC]
CVSS 10 Ollyo Sp Page Builder
CVE-2026-48939 Jun 20, 2026
iCagenda file upload unauth RCE (CVE-2026-48939) [PoC]
CVSS 10 Joomlic Icagenda
CVE-2026-12569 Jun 18, 2026
Windchill RCE exploited in the wild (CVE-2026-12569)
CVSS 9.3
CVE-2026-48558 Jun 12, 2026
SimpleHelp OIDC auth bypass actively exploited (CVE-2026-48558) [PoC]
CVSS 10
CVE-2026-35273 Jun 11, 2026
PeopleSoft Enterprise unauth takeover (CVE-2026-35273) [PoC]
CVSS 9.8 Oracle Peoplesoft Enterprise Peopletools
CVE-2026-10520 Jun 9, 2026
Ivanti Sentry RCE actively exploited (CVE-2026-10520) [PoC]
CVSS 10
CVE-2026-25089 Jun 9, 2026
FortiSandbox unauth RCE (CVE-2026-25089) [PoC]
CVSS 9.8
CVE-2026-50751 Jun 8, 2026
Remote Access VPN bypass exploited in wild (CVE-2026-50751) [PoC]
CVSS 9.3
CVE-2026-48907 Jun 5, 2026
JCE Editor unauth RCE exploited (CVE-2026-48907) [PoC]
CVSS 10
CVE-2026-8037 Jun 4, 2026
Progress ADC exploited for unauthenticated RCE (CVE-2026-8037) [PoC]
CVSS 9.8 Progress Connection Manager For Objectscale, Progress Ecs Connection Manager, Progress Loadmaster
CVE-2026-46817 May 28, 2026
Oracle E-Business Suite takeover (CVE-2026-46817) [PoC]
CVSS 9.8 Oracle E-Business Suite
CVE-2026-44590 May 27, 2026
Sherlock leaks CI tokens via command inj (CVE-2026-44590) [PoC]
CVSS 9.3
CVE-2026-48027 May 27, 2026
Nx Console supply chain attack actively exploited (CVE-2026-48027)
CVSS 9.8 Nx Console
CVE-2026-45247 May 26, 2026
Mirasvit FPC Warmer RCE exploited in wild (CVE-2026-45247) [PoC]
CVSS 9.8
CVE-2026-48172 May 21, 2026
LiteSpeed cPanel privilege escalation (CVE-2026-48172) [PoC]
CVSS 10
CVE-2026-8398 May 15, 2026
DAEMON Tools Lite supply chain attack (CVE-2026-8398)
CVSS 9.8
CVE-2026-20182 May 14, 2026
Catalyst SD-WAN bypass grants admin access (CVE-2026-20182) [PoC]
CVSS 10
CVE-2026-0257 May 13, 2026
PAN-OS GlobalProtect auth bypass (CVE-2026-0257) [PoC]
CVSS 9.1 Paloaltonetworks Pan-Os, Paloaltonetworks Prisma Access
CVE-2026-42945 May 13, 2026
NGINX Plus heap overflow, unauth (CVE-2026-42945) [PoC]
CVSS 9.2
CVE-2026-45321 May 12, 2026
TanStack npm packages leak credentials (CVE-2026-45321) [PoC]
CVSS 9.6 Tanstack Tanstack\\/Arktype-Adapter, Tanstack Tanstack\\/Eslint-Plugin-Router, Tanstack Tanstack\\/Eslint-Plugin-Start, Tanstack Tanstack\\/History, Tanstack Tanstack\\/Nitro-V2-Vite-Plugin
CVE-2021-47932 May 10, 2026
WordPress TheCartPress creates admin accounts (CVE-2021-47932)
CVSS 9.8
CVE-2021-47933 May 10, 2026
WordPress MStore API unauth RCE (CVE-2021-47933)
CVSS 9.8
CVE-2021-47936 May 10, 2026
OpenCATS unauthenticated RCE (CVE-2021-47936)
CVSS 9.8
CVE-2026-6722 May 10, 2026
PHP SOAP unauthenticated RCE (CVE-2026-6722)
CVSS 9.5
CVE-2026-37431 May 8, 2026
Beauty Parlour SQLi reads database (CVE-2026-37431)
CVSS 9.8
CVE-2026-41070 May 8, 2026
openvpn-auth-oauth2 bypasses SSO auth (CVE-2026-41070)
CVSS 10
CVE-2026-41497 May 8, 2026
PraisonAI RCE, no auth needed (CVE-2026-41497)
CVSS 9.8 Praison Praisonai
CVE-2026-41500 May 8, 2026
electerm unauth command injection (CVE-2026-41500)
CVSS 9.8 Electerm Project Electerm
CVE-2026-41501 May 8, 2026
electerm unauthenticated RCE (CVE-2026-41501)
CVSS 9.8 Electerm Project Electerm
CVE-2026-41512 May 8, 2026
ai-scanner RCE via JavaScript injection (CVE-2026-41512)
CVSS 9.9
CVE-2026-41574 May 8, 2026
Nhost account takeover via OAuth (CVE-2026-41574)
CVSS 9.3