An official Admiresty Corporation service
How to verify
Official Admiresty services use admiresty.co

Admiresty Corporation operates ThreatGrid and its full service ecosystem from admiresty.co. All official platforms run from this domain or a verified subdomain. If you’re unsure, visit admiresty.co directly to confirm.

Secure Admiresty services always use HTTPS

A padlock and https:// in your address bar confirm a safe, encrypted connection. Never enter credentials or share sensitive data on any page without a valid HTTPS connection to an Admiresty domain.

Security Bulletins

Active threat advisories and known exploited vulnerabilities.

Pulled daily from the CISA Known Exploited Vulnerabilities catalog. Every entry has confirmed active exploitation in the wild. Last synced Sep 11, 2026.

1,709 total bulletins 1,709 critical or high severity Source: CISA KEV + NVD
Critical CVE-2026-56290 Joomlack · Page Builder Added Jul 7, 2026

Joomlack Page Builder Improper Access Control Vulnerability

Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-55255 Langflow · Langflow Added Jul 7, 2026

Langflow Authorization Bypass Through User-Controlled Key Vulnerability

Langflow contains an authorization bypass through user-controlled key vulnerability which allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-48908 JoomShaper · SP Page Builder Added Jul 7, 2026

JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability

JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-45659 Microsoft · SharePoint Server Added Jul 1, 2026

Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability

Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-48558 SimpleHelp · SimpleHelp Added Jun 29, 2026

SimpleHelp Authentication Bypass Vulnerability

SimpleHelp contains an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-20230 Cisco · Unified Communications Manager Added Jun 25, 2026

Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability

Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) contain a server-side request forgery (SSRF) Vulnerability that could allow an unauthenticated, remote attacker to write files to the underlying operating system that could be used later to elevate to root.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-12569 PTC · Windchill and FlexPLM Added Jun 25, 2026

PTC Windchill and FlexPLM Improper Input Validation Vulnerability

PTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attacker to execute arbitrary code by sending a malicious request to the network.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-34908 Ubiquiti · UniFi OS Added Jun 23, 2026

Ubiquiti UniFi OS Improper Access Control Vulnerability

Ubiquiti UniFi OS contains an improper access control vulnerability which could allow a malicious actor with access to the network to make unauthorized changes to the system.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-34909 Ubiquiti · UniFi OS Added Jun 23, 2026

Ubiquiti UniFi OS Path Traversal Vulnerability

Ubiquiti UniFi OS contains a path traversal vulnerability which could allow a malicious actor with access to the network to access files on the underlying system that could be manipulated to access an underlying account.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-34910 Ubiquiti · UniFi OS Added Jun 23, 2026

Ubiquiti UniFi OS Improper Input Validation Vulnerability

Ubiquiti UniFi OS contains an improper input validation vulnerability which could allow a malicious actor with access to the network to conduct command injection.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-67038 Lantronix · EDS5000 Added Jun 23, 2026

Lantronix EDS5000 Code Injection Vulnerability

Lantronix EDS5000 contains a code injection vulnerability that could allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-20253 Splunk · Enterprise Added Jun 18, 2026

Splunk Enterprise Missing Authentication for Critical Function Vulnerability

Splunk Enterprise contains a missing authentication for critical function vulnerability which could allow an unauthenticated user to create or truncate arbitrary files through a PostgreSQL sidecar service endpoint.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-48907 Widget Factory · Joomla Content Editor Added Jun 16, 2026

Widget Factory Joomla Content Editor Improper Access Control Vulnerability

Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticated users.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-20262 Cisco · Catalyst SD-WAN Manager Added Jun 15, 2026

Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability

Cisco Catalyst SD-WAN Manager contains a directory or path traversal vulnerability that could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-54420 LiteSpeed · cPanel Plugin Added Jun 15, 2026

LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability

LiteSpeed cPanel plugin contains a UNIX symbolic link (Symlink) following vulnerability that could allow a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-35273 Oracle · PeopleSoft Enterprise PeopleTools Added Jun 12, 2026

Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability

Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise PeopleTools.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-10520 Ivanti · Sentry Added Jun 11, 2026

Ivanti Sentry OS Command Injection Vulnerability

Ivanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve root-level remote code execution. This vulnerability can be successfully exploited in cases where the Sentry appliance is in an unmanaged state with its endpoints externally reachable. The use of mTLS with EPMM or restricted HTTPS access through Neurons for MDM makes interfaces inaccessible to external actors.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-7473 Arista · Extensible Operating System Added Jun 9, 2026

Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability

Arista Extensible Operating System (EOS) contains an incomplete comparison with missing factors vulnerability when the switch incorrectly decapsulate and forwards other unexpected tunneled packet with a destination IP matching its configured decapsulation IP.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-20245 Cisco · Catalyst SD-WAN Manager Added Jun 9, 2026

Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability

Cisco Catalyst SD-WAN Manager formerly SD-WAN vManage contains an improper encoding or escaping of output vulnerability. This vulnerability could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-11645 Google · Chromium V8 Added Jun 9, 2026

Google Chromium V8 Out-of-Bounds Read and Write Vulnerability

Google Chromium V8 out-of-bounds read and write vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-42271 BerriAI · LiteLLM Added Jun 8, 2026

BerriAI LiteLLM Command Injection Vulnerability

BerriAI LiteLLM contains a command injection vulnerability that could allow any authenticated user, including holders of low-privilege internal-user keys, to run arbitrary commands on the host.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-50751 Check Point · Security Gateway Added Jun 8, 2026

Check Point Security Gateway Improper Authentication Vulnerability

Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-28318 SolarWinds · Serv-U Added Jun 5, 2026

SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability

SolarWinds Serv-U contains an uncontrolled resource consumption vulnerability that allows specially crafted POST requests using the Content-Encoding: deflate header to crash the Serv-U service without authentication.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-45247 Mirasvit · Mirasvit Full Page Cache Warmer Added Jun 3, 2026

Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability

Mirasvit Full Page Cache Warmer contains a deserialization of untrusted data vulnerability that could allow unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2022-0492 Linux · Kernel Added Jun 2, 2026

Linux Kernel Improper Authentication Vulnerability

Linux Kernel contains an improper authentication vulnerability which could allow for privilege escalation via the cgroups v1 release_agent feature.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed

Need help prioritizing these vulnerabilities?

ThreatGrid can assess your environment and map active CVEs to your monitored assets.