An official Admiresty Corporation service
How to verify
Official Admiresty services use admiresty.co

Admiresty Corporation operates ThreatGrid and its full service ecosystem from admiresty.co. All official platforms run from this domain or a verified subdomain. If you’re unsure, visit admiresty.co directly to confirm.

Secure Admiresty services always use HTTPS

A padlock and https:// in your address bar confirm a safe, encrypted connection. Never enter credentials or share sensitive data on any page without a valid HTTPS connection to an Admiresty domain.

Security Bulletins

Active threat advisories and known exploited vulnerabilities.

Pulled daily from the CISA Known Exploited Vulnerabilities catalog. Every entry has confirmed active exploitation in the wild. Last synced Jul 27, 2026.

1,655 total bulletins 1,655 critical or high severity Source: CISA KEV + NVD
Critical CVE-2026-45321 TanStack · TanStack Added May 27, 2026

TanStack Unspecified Vulnerability

TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a trusted identity.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-8398 Daemon · Daemon Tools Lite Added May 27, 2026

Daemon Tools Lite Embedded Malicious Code Vulnerability

Daemon Tools contains an unspecified vulnerability that has a high impact on confidentiality, integrity, and availability.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-48172 LiteSpeed · cPanel Plugin Added May 26, 2026

LiteSpeed cPanel Plugin Privilege Escalation Vulnerability

LiteSpeed cPanel Plugin contains privilege escalation vulnerability that is exposed via the user-end cPanel plugin, which can be abused by any cPanel user account to execute arbitrary scripts with root privileges.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-9082 Drupal · Core Added May 22, 2026

Drupal Core SQL Injection Vulnerability

Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-34291 Langflow · Langflow Added May 21, 2026

Langflow Origin Validation Error Vulnerability

Langflow contains an origin validation error vulnerability in which an overly permissive CORS configuration combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform cross-origin requests that include credentials and successfully call the refresh endpoint. This could allow the attacker to execute arbitrary code and achieve full system compromise via obtained tokens that permit access to authenticated endpoints.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-34926 Trend Micro · Apex One Added May 21, 2026

Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability

Trend Micro Apex One (on-premise) contains a directory traversal vulnerability that could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2008-4250 Microsoft · Windows Added May 20, 2026

Microsoft Windows Buffer Overflow Vulnerability

Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2009-1537 Microsoft · DirectX Added May 20, 2026

Microsoft DirectX NULL Byte Overwrite Vulnerability

Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitrary code via a crafted QuickTime media file.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2009-3459 Adobe · Acrobat and Reader Added May 20, 2026

Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability

Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability which could allow remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2010-0249 Microsoft · Internet Explorer Added May 20, 2026

Microsoft Internet Explorer Use-After-Free Vulnerability

Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2010-0806 Microsoft · Internet Explorer Added May 20, 2026

Microsoft Internet Explorer Use-After-Free Vulnerability

Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-41091 Microsoft · Defender Added May 20, 2026

Microsoft Defender Link Following Vulnerability

Microsoft Defender contains a link following vulnerability that allows an authorized attacker to elevate privileges locally.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-45498 Microsoft · Defender Added May 20, 2026

Microsoft Defender Denial of Service Vulnerability

Microsoft Defender contains an unspecified vulnerability that allows for denial of service.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-42897 Microsoft · Microsoft Added May 15, 2026

Microsoft Exchange Server Cross-Site Scripting Vulnerability

Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-20182 Cisco · Catalyst SD-WAN Added May 14, 2026

Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability

Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-42208 BerriAI · LiteLLM Added May 8, 2026

BerriAI LiteLLM SQL Injection Vulnerability

BerriAI LiteLLM contains a SQL injection vulnerability that allows an attacker to read data from the proxy's database and potentially modify it, leading to unauthorized access to the proxy and the credentials it manages.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-6973 Ivanti · Endpoint Manager Mobile (EPMM) Added May 7, 2026

Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability

Ivanti Endpoint Manager Mobile (EPMM) contains an improper input validation vulnerability that allows a remotely authenticated user with administrative access to achieve remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-0300 Palo Alto Networks · PAN-OS Added May 6, 2026

Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability

Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-31431 Linux · Kernel Added May 1, 2026

Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability

Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-41940 WebPros · cPanel & WHM and WP2 (WordPress Squared) Added Apr 30, 2026

WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability

WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2024-1708 ConnectWise · ScreenConnect Added Apr 28, 2026

ConnectWise ScreenConnect Path Traversal Vulnerability

ConnectWise ScreenConnect contains a path traversal vulnerability which could allow an attacker to execute remote code or directly impact confidential data and critical systems.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-32202 Microsoft · Windows Added Apr 28, 2026

Microsoft Windows Protection Mechanism Failure Vulnerability

Microsoft Windows Shell contains a protection mechanism failure vulnerability that allows an unauthorized attacker to perform spoofing over a network.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-29635 D-Link · DIR-823X Added Apr 24, 2026

D-Link DIR-823X Command Injection Vulnerability

D-Link DIR-823X contains a command injection vulnerability that allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2024-7399 Samsung · MagicINFO 9 Server Added Apr 24, 2026

Samsung MagicINFO 9 Server Path Traversal Vulnerability

Samsung MagicINFO 9 Server contains a path traversal vulnerability that could allow an attacker to write arbitrary files as system authority.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2024-57728 SimpleHelp · SimpleHelp Added Apr 24, 2026

SimpleHelp Path Traversal Vulnerability

SimpleHelp contains a path traversal vulnerability that allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed

Need help prioritizing these vulnerabilities?

ThreatGrid can assess your environment and map active CVEs to your monitored assets.