CVE-2026-41091
Microsoft · Defender
Added May 20, 2026
Security Bulletins
Active threat advisories and known exploited vulnerabilities.
Pulled daily from the CISA Known Exploited Vulnerabilities catalog. Every entry has confirmed active exploitation in the wild. Last synced Jun 12, 2026.
Critical
Critical
CVE-2026-45498
Microsoft · Defender
Added May 20, 2026
Microsoft Defender Denial of Service Vulnerability
Critical
CVE-2026-42897
Microsoft · Microsoft
Added May 15, 2026
Microsoft Exchange Server Cross-Site Scripting Vulnerability
Critical
CVE-2026-20182
Cisco · Catalyst SD-WAN
Added May 14, 2026
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
Critical
CVE-2026-42208
BerriAI · LiteLLM
Added May 8, 2026
BerriAI LiteLLM SQL Injection Vulnerability
Critical
CVE-2026-6973
Ivanti · Endpoint Manager Mobile (EPMM)
Added May 7, 2026
Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability
Critical
CVE-2026-0300
Palo Alto Networks · PAN-OS
Added May 6, 2026
Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability
Critical
CVE-2026-31431
Linux · Kernel
Added May 1, 2026
Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability
Critical
CVE-2026-41940
WebPros · cPanel & WHM and WP2 (WordPress Squared)
Added Apr 30, 2026
WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability
Critical
CVE-2024-1708
ConnectWise · ScreenConnect
Added Apr 28, 2026
ConnectWise ScreenConnect Path Traversal Vulnerability
Critical
CVE-2026-32202
Microsoft · Windows
Added Apr 28, 2026
Microsoft Windows Protection Mechanism Failure Vulnerability
Critical
CVE-2025-29635
D-Link · DIR-823X
Added Apr 24, 2026
D-Link DIR-823X Command Injection Vulnerability
Critical
CVE-2024-7399
Samsung · MagicINFO 9 Server
Added Apr 24, 2026
Samsung MagicINFO 9 Server Path Traversal Vulnerability
Critical
CVE-2024-57728
SimpleHelp · SimpleHelp
Added Apr 24, 2026
SimpleHelp Path Traversal Vulnerability
Critical
CVE-2024-57726
SimpleHelp · SimpleHelp
Added Apr 24, 2026
SimpleHelp Missing Authorization Vulnerability
Critical
CVE-2026-39987
Marimo · Marimo
Added Apr 23, 2026
Marimo Remote Code Execution Vulnerability
Critical
CVE-2026-33825
Microsoft · Defender
Added Apr 22, 2026
Microsoft Defender Insufficient Granularity of Access Control Vulnerability
Critical
CVE-2026-20122
Cisco · Catalyst SD-WAN Manger
Added Apr 20, 2026
Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability
Critical
CVE-2024-27199
JetBrains · TeamCity
Added Apr 20, 2026
JetBrains TeamCity Relative Path Traversal Vulnerability
Critical
CVE-2025-32975
Quest · KACE Systems Management Appliance (SMA)
Added Apr 20, 2026
Quest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability
Critical
CVE-2026-20128
Cisco · Catalyst SD-WAN Manager
Added Apr 20, 2026
Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability
Critical
CVE-2023-27351
PaperCut · NG/MF
Added Apr 20, 2026
PaperCut NG/MF Improper Authentication Vulnerability
Critical
CVE-2025-48700
Synacor · Zimbra Collaboration Suite (ZCS)
Added Apr 20, 2026
Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability
Critical
CVE-2026-20133
Cisco · Catalyst SD-WAN Manager
Added Apr 20, 2026
Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
Critical
CVE-2025-2749
Kentico · Kentico Xperience
Added Apr 20, 2026
Kentico Xperience Path Traversal Vulnerability
Need help prioritizing these vulnerabilities?
ThreatGrid can assess your environment and map active CVEs to your monitored assets.