An official Admiresty Corporation service
How to verify
Official Admiresty services use admiresty.co

Admiresty Corporation operates ThreatGrid and its full service ecosystem from admiresty.co. All official platforms run from this domain or a verified subdomain. If you’re unsure, visit admiresty.co directly to confirm.

Secure Admiresty services always use HTTPS

A padlock and https:// in your address bar confirm a safe, encrypted connection. Never enter credentials or share sensitive data on any page without a valid HTTPS connection to an Admiresty domain.

Security Bulletins

Active threat advisories and known exploited vulnerabilities.

Pulled daily from the CISA Known Exploited Vulnerabilities catalog. Every entry has confirmed active exploitation in the wild. Last synced Sep 11, 2026.

1,709 total bulletins 1,709 critical or high severity Source: CISA KEV + NVD
Critical CVE-2026-53362 Linux · Kernel Added Aug 27, 2026

Linux Kernel Unspecified Vulnerability

Linux Kernel contains an unspecified vulnerability that can allow for privilege escalation via IPv6 networking subsystem. This vulnerability can impact multiple products, including but not limited to Suse, Red Hat, and other products using Linux.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-49105 ownCloud · ownCloud Added Aug 27, 2026

ownCloud Improper Authentication Vulnerability

ownCloud contains an improper authentication vulnerability that allows an attacker to access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2019-1068 Microsoft · SQL Server Added Aug 26, 2026

Microsoft SQL Server Remote Code Execution Vulnerability

Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine service account.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-8452 Citrix · NetScaler ADC and NetScaler Gateway Added Aug 26, 2026

Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability which could lead to denial of service.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2022-0995 Linux · Kernel Added Aug 26, 2026

Linux Kernel Out-of-Bounds Write Vulnerability

Linux Kernel contains an out-of-bounds memory write vulnerability which could allow a local user to gain privileged access or cause a denial of service on the system.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2015-5287 Red Hat · Automatic Bug Reporting Tool Added Aug 26, 2026

Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability

Red Hat Automatic Bug Reporting Tool (ABRT) contains a privilege escalation vulnerability that could allow local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2015-3246 Red Hat · Libuser Added Aug 26, 2026

Red Hat Libuser Race Condition Vulnerability

Red Hat libuser contains a race condition vulnerability that allows authenticated local users to corrupt the /etc/passwd file to cause a denial of service or privilege escalation.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-23758 Ajax.NET Professional · Ajax.NET Professional Added Aug 26, 2026

Ajax.NET Professional Deserialization of Untrusted Data Vulnerability

Ajax.NET Professional (AjaxPro) contains a deserialization of untrusted data vulnerability that could allow for remote code execution via arbitrary .NET classes. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-60004 Gitea · Gitea Added Aug 25, 2026

Gitea Code Injection Vulnerability

Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-21962 Oracle · HTTP Server and Oracle Weblogic Server Proxy Plug-in Added Aug 24, 2026

Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability

Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in contain an improper access control vulnerability that can result in unauthorized creation, deletion or modification access to critical data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in accessible data.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-73570 Synacor · Zimbra Collaboration Suite (ZCS) Added Aug 21, 2026

Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability

Zimbra Collaboration Suite (ZCS) contains an OS command injection vulnerability which could allow an unauthenticated attacker to send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-72529 TrueConf · Server Added Aug 20, 2026

TrueConf Server Missing Authentication for Critical Function Vulnerability

TrueConf Server contains a missing authentication for critical function vulnerability which could allow a remote unauthorized attacker with network access via port 4307/TCP to execute an arbitrary script.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-72530 TrueConf · Server Added Aug 20, 2026

TrueConf Server Code Injection Vulnerability

TrueConf Server contains a code injection vulnerability that could allow an unauthorized remote attacker with network access via port 4307/TCP to use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-64849 MLflow · MLflow Added Aug 19, 2026

MLflow Server-Side Request Forgery Vulnerability

MLflow contains a server-side request forgery vulnerability that can allow attackers to reach internal or cloud metadata services and receive response_status and response_body.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-65400 Apple · macOS Added Aug 18, 2026

Apple macOS Improper Authentication Vulnerability

Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-55040 Microsoft · SharePoint Added Aug 18, 2026

Microsoft SharePoint Weak Authentication Vulnerability

Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-59310 Broadcom · VMware vCenter Added Aug 18, 2026

Broadcom VMware vCenter Path Traversal Vulnerability

Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-33824 Microsoft · Internet Key Exchange (IKE) Service Extensions Added Aug 18, 2026

Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability

Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-62593 Ray-Project · Ray Added Aug 17, 2026

Ray-Project Ray Code Injection Vulnerability

Ray-Project Ray contains a code injection vulnerability that could allow remote code execution. Developers using Ray as a development tool may be exposed to this vulnerability exploitable through Firefox and Safari.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-72898 Metabase · Metabase Added Aug 11, 2026

Metabase SQL Injection Vulnerability

Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-20349 Cisco · Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Added Aug 11, 2026

Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability

Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-68820 Microsoft · Windows Ancillary Function Driver for WinSock Added Aug 11, 2026

Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability

Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-8037 Progress · LoadMaster Added Aug 7, 2026

Progress LoadMaster Command Injection Vulnerability

Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-63077 JetBrains · TeamCity Added Aug 5, 2026

JetBrains TeamCity Deserialization of Untrusted Data Vulnerability

JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-9198 IBM · Langflow Added Aug 4, 2026

IBM Langflow Code Injection Vulnerability

Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed

Need help prioritizing these vulnerabilities?

ThreatGrid can assess your environment and map active CVEs to your monitored assets.