Trending vulnerabilities

Trending 25
Critical 11
In KEV 6
Peak EPSS 79%
Posts 564
#1 CVE-2026-66066
hype LIKELY HACK · 78 hack

Rails patching + downstream backports + credential exposure = urgent triage signal; KEV-listing pending.

What: Arbitrary file read to RCE in Rails Active Storage via libvips image processing; affects Rails applications using Active Storage with untrusted image uploads (CVSS 9.5).

Why it matters: Rails maintainers have patched; NixOS/Mastodon backports confirm real-world deployments triaging. Post #6 documents credential exposure (secret_key_base, database passwords, cloud storage credentials, API tokens). Unauthenticated attack surface (crafted image uploads). No KEV-listed status yet, but urgency reflected in vendor patching and security blog coverage.

Where it's seen: Security research writeups (Ethiack, GMO Flatt Security Blog), Hacker News coverage, GitHub patch PRs across downstream consumers (Mastodon, NixOS), social amplification on Bluesky. Posts reference both libvips and Active Storage as attack vector.

score 29 63 posts
#2 CVE-2026-63077
CRITICAL · 9.8
hype MIXED · 62 hack

Real critical vuln, patches live, but no KEV, no PoC signal, chatter mostly recycled concern.

What: JetBrains TeamCity unauthenticated remote code execution via the agent polling protocol (CVSS 9.8 CRITICAL). Affects versions before 2026.1.3 and 2025.11.7.

Why it matters: CRITICAL severity and zero authentication requirement make this high-impact for CI/CD infrastructure. Published 2026-07-27; patches already available. Not yet KEV-listed but EPSS 0.47% reflects low current exploitation prevalence. Social chatter emphasizes urgency and patch applicability.

Where it's seen: Blog posts and social media amplifying urgency ("Patch Now"), vendor advisory coverage, debate around patch completeness and prior exploitation gaps. No PoC public in supplied posts; chatter is alarm-driven rather than proof-driven.

score 27 59 posts
#3 CVE-2026-20316
MEDIUM · 5.3 KEV
hype LIKELY HACK · 78 hack

KEV-listed, active exploitation confirmed, vendor patches available; chaining detail adds credibility.

What: Hardcoded low-privileged credentials in Cisco Secure Firewall Management Center (FMC) web interface allows unauthenticated remote login and sensitive data access (CVSS 5.3 MEDIUM, elevated by chaining risk).

Why it matters: KEV-listed as of 2026-07-29; multiple sources confirm active in-the-wild exploitation. Chatter emphasizes chainability with CVE-2026-20079 (CVSS 10.0) for privilege escalation to root. Cisco issued hotfixes; CISA remediation deadline Aug 19. Defender triaging underway.

Where it's seen: Security news aggregators, threat intel feeds, and practitioner social media all report confirmed exploitation and KEV addition within hours of advisory. No public PoC code shared, but active attacks documented by vendors and CISA.

score 22 56 posts

Also trending

  1. 4 CVE-2026-16812 CRITICAL · 10.0 KEV score 15 · 54 posts
    hype ACTIVE HACK · 92 hack

    What: Remote command injection in Arista VeloCloud Orchestrator (on-prem) allowing unauthenticated attackers to execute arbitrary code and compromise confidentiality, integrity, and availability. CVSS 10.0 CRITICAL.

    Why it matters: KEV-listed same day as publication. NVD explicitly states "actively exploited" in the wild. Vendor has already patched Hosted/Dedicated versions; on-prem users face immediate risk. Affected versions span 5.2.x through 7.0.x. Social chatter reflects defender urgency and vendor transparency concerns.

    Where it's seen: CISA threat stream alerts, security researcher posts detailing vulnerable version ranges, and broad social commentary questioning Arista's patch timeline and oversight. No public PoC drop observed yet, but active exploitation confirmed by vendor disclosure.

  2. 5 CVE-2026-42897 HIGH · 8.1 KEV score 14 · 27 posts
    hype LIKELY HACK · 72 hack

    What: Cross-site scripting (XSS) in Microsoft Exchange Server on-premises allowing email spoofing; CVSS 8.1 HIGH.

    Why it matters: Microsoft confirmed active exploitation in-the-wild as of 2026-05-14. Posts cite emergency patching and mitigation guidance. Not yet KEV-listed but vendor advisory + confirmed active abuse signals immediate triage priority for on-prem Exchange operators.

    Where it's seen: Coordinated social chatter across security news outlets (HelpNetSecurity, The Hacker News) and Bluesky; consistent framing of "actively exploited zero-day" with remediation paths (EOMT, service updates). No public PoC mentioned, but threat actor activity confirmed by Microsoft.

  3. 6 CVE-2026-16232 KEV EPSS 70% score 13 · 27 posts
    hype ACTIVE HACK · 92 hack

    What: Authentication bypass in Check Point SmartConsole login allows unauthenticated remote attackers to obtain administrative tokens and modify security policies (KEV-listed, 2026-07-22).

    Why it matters: CISA added CVE-2026-16232 to KEV catalog based on confirmed active exploitation. Check Point acknowledges in-the-wild attacks affecting a small number of customers. Attackers gain full admin control without credentials, enabling policy tampering on exposed Management Servers. Vendor issued emergency July 22 hotfix.

    Where it's seen: CISA KEV advisory, vendor confirmation of exploitation, security news coverage, blue-team chatter about limiting management access and applying patches immediately.

  4. 7 CVE-2026-54121 HIGH · 8.8 score 13 · 45 posts
    hype LIKELY HACK · 78 hack

    What: Improper authorization in Active Directory Certificate Services (AD CS) allowing authenticated attackers to elevate privileges and potentially compromise Windows domains; CVSS 8.8 (HIGH).

    Why it matters: Public PoC released 24 July 2026 by H0j3n and Aniq F; Microsoft patched on 14 July; Microsoft Defender already detecting exploitation attempts (malicious certificate requests). Social signal shows working exploitation in lab environments and active defender alerting—not theoretical.

    Where it's seen: PoC posted to GitHub gist; security news outlets (HelpNetSecurity) covering; defenders reporting successful lab reproduction; Microsoft Defender generating detection alerts for AD CS abuse; domain-takeover impact framing driving urgency.

  5. 8 CVE-2026-47876 CRITICAL · 9.3 score 12 · 21 posts
    hype LIKELY HACK · 72 hack

    What: Out-of-bounds write in VMware ESXi VMXNET3 virtual network adapter enabling VM escape; affects ESX, vCenter, Workstation, and Fusion (CVSS critical, up to 9.8).

    Why it matters: Vendor advisory (VMSA-2026-0006) published with patches available; critical severity and VM escape class warrant immediate remediation. No public PoC or in-the-wild exploitation confirmed yet, but urgency messaging from security outlets and vendors signals active patch deployment phase.

    Where it's seen: SecurityWeek and IT-Connect coverage, vendor advisory aggregation on Vulnerability-Lookup, repeated social emphasis on "patch urgency" and bundled advisory. Moderate engagement across Bluesky infosec accounts; inclusion in top CVEs for the week.

  6. 9 CVE-2026-59726 CRITICAL · 10.0 score 10 · 14 posts
    hype LIKELY HACK · 72 hack

    What: Ruflo (Claude Code/Codex agent harness) versions <3.16.3 expose unauthenticated MCP bridge endpoints allowing remote code execution, shell access, API key theft, and agent memory poisoning. CVSS 10.0.

    Why it matters: Patch released 21 days ago (3.16.3 fixes it); mass coverage across security media and developer platforms; no KEV listing yet but threat is real — unauthenticated RCE on a system touching AI credentials and agent state. Active chatter shows defenders and teams aware of exposure window.

    Where it's seen: Bluesky posts from security researchers and outlets (HackerNews, OffSeq, BlindThoughts); links to threat intel; multilingual discussion; upgrade guidance circulating. No confirmed in-the-wild exploitation reported, but CVSS 10.0 and simple attack surface drive urgency.

  7. 10 CVE-2026-64531 score 9 · 8 posts
    hype LIKELY HACK · 72 hack

    What: Linux kernel Open vSwitch netlink attribute handling flaw allowing oversized nested action attributes to bypass validation, enabling local privilege escalation via malformed CLONE/CT actions (CVSS unavailable; EPSS 0.00161).

    Why it matters: Public PoC and patch released within hours of embargo lift; multiple distributions racing to deploy fixes. Local-only attack surface limits immediate remote risk, but kernel privilege escalation bugs warrant urgent triage in multi-tenant environments.

    Where it's seen: Security mailing lists and distro advisory channels; vendor patches shipped within 3 hours; social media tracks as trending CVE with PoC labeled "OVSwrap"; defenders already integrating fixes.

  8. 11 CVE-2026-59310 CRITICAL · 9.8 score 9 · 13 posts
    hype LIKELY HACK · 72 hack

    What: VMware vCenter Syslog server directory traversal vulnerability allowing unauthenticated remote code execution (CVSS 9.8 CRITICAL).

    Why it matters: Broadcom released security advisory VMSA-2026-0006 on 2026-07-29 addressing this flaw alongside CVE-2026-59309 (auth bypass). Multiple credible sources (Rapid7, Bleeping Computer) confirm vendor patch availability and severity. No public PoC or KEV listing yet, but urgent patching signals active vendor remediation and likely high defender priority.

    Where it's seen: Social media aggregating Broadcom advisory; security research blogs flagging as critical in multi-CVE bundles; no PoC chatter or scanning reports observed.

  9. 12 CVE-2026-16723 CRITICAL · 9.0 score 9 · 28 posts
    hype MIXED · 52 hack

    What: Remote code execution in Alibaba Fastjson 1.2.68–1.2.83 via malicious JSON payloads under default configuration (CVSS 9.0, EPSS 0.34%).

    Why it matters: Posts claim active exploitation in Spring Boot applications with no patch available for 1.x branch. Default-enabled RCE without AutoType or gadgets widens attack surface. However, KEV is not listed, and EPSS is extremely low (0.34th percentile), signaling limited real-world traction despite rhetoric.

    Where it's seen: Bluesky chatter emphasizes "actively exploited" and "zero-day" framing; posts reference threat intelligence sites and HackerNews. Vendor guidance (SafeMode, migration) is cited but no official patch advisory or PoC confirmation appears in metadata.

  10. 13 CVE-2026-59309 CRITICAL · 9.8 score 9 · 13 posts
    hype LIKELY HACK · 72 hack

    What: VMware vCenter authentication bypass in Directory Service (CVSS 9.8 CRITICAL); network-accessible, no credentials required for unauthorized system access.

    Why it matters: Broadcom issued urgent security advisory VMSA-2026-0006 on 29 July 2026 addressing this flaw alongside CVE-2026-59310 (RCE, 9.8). Rapid7 published analysis same day. No KEV listing yet, but patch availability and immediate vendor urgency signal active remediation posture. Multiple critical VMware flaws bundled suggest coordinated disclosure.

    Where it's seen: Security advisories, vendor patch announcements, security researcher blogs (Rapid7 ETR), aggregator posts and threat feeds. Chatter focuses on patch urgency and attack surface (vCenter appliances exposed to network). No public PoC or in-the-wild exploitation reported.

  11. 14 CVE-2026-3141 CRITICAL · 9.1 score 8 · 8 posts
    hype LIKELY HACK · 72 hack

    What: FormGent WordPress plugin (≤1.9.2) allows unauthenticated arbitrary file deletion via unauth REST API endpoint; path traversal can delete wp-config.php, enabling site takeover. CVSS 9.1 CRITICAL.

    Why it matters: Published today with high CVSS score and clear exploitation path (no auth required, REST endpoint exposed). NVD details confirm complete site takeover risk on default Linux installs. Not yet KEV-listed but imminent risk to thousands of WordPress sites running the plugin.

    Where it's seen: Multilingual social chatter (Hebrew, Russian, Japanese) on Bluesky amplifying disclosure same-day; posts describe practical exploitation scenarios. No public PoC or in-the-wild reports visible yet, but vulnerability is trivial to exploit (REST endpoint + file deletion + no checks).

  12. 15 CVE-2026-17543 score 8 · 10 posts
    hype MIXED · 42 hack

    What: Improper backslash escaping in PHP 8.2–8.5 allows SQL injection in PostgreSQL queries via ext-pgsql. No CVSS/EPSS assigned yet.

    Why it matters: PHP maintainers patched actively (8.2.33, 8.3.33, 8.4.24, 8.5.9 released); backports rolled to 7.4 and 8.0–8.1 within hours. Vuln is trivial to trigger but KEV not yet listed. No public PoC or in-the-wild reports in chatter; signal is vendor advisory + coordinated patching across versions.

    Where it's seen: Security news aggregators amplifying patch notices; package maintainers (Remi repos) backporting fixes across unsupported PHP versions same day. No defender questions or exploitation claims yet.

  13. 16 CVE-2025-68686 MEDIUM · 5.9 KEV score 8 · 16 posts
    hype LIKELY HACK · 78 hack

    What: Fortinet FortiOS sensitive information disclosure (CWE-200) in versions 6.4–7.6.1 allowing remote unauthenticated bypass of post-exploit symbolic link persistence patch via crafted HTTP requests; requires prior compromise. CVSS 5.9 (medium).

    Why it matters: KEV-listed as of 27 July 2026 (yesterday) with confirmed active exploitation. Fortinet immediately patching; defenders triaging affected FortiOS instances. Low EPSS (0.38%) reflects exploitation complexity—requires prior filesystem access—but KEV status signals threat actors weaponizing the bypass chain.

    Where it's seen: CISA alert coverage across infosec social channels (Bluesky, Mastodon) in multiple languages; vendor advisories circulating. Chatter emphasizes "actively exploited" and urgent patching but no public PoC drops mentioned.

  14. 17 CVE-2026-48449 CRITICAL · 10.0 score 8 · 9 posts
    hype MIXED · 52 hack

    What: Incorrect Authorization vulnerability in Adobe Campaign Classic enabling arbitrary code execution without user interaction; CVSS 10.0 critical severity.

    Why it matters: Published yesterday with perfect CVSS score and no-interaction RCE capability across scope. However, not yet KEV-listed and no public PoC or confirmed in-the-wild exploitation reported. Social chatter reflects severity but lacks concrete exploitation signal. Adobe patch (build 9398) referenced but not yet verified as official/available.

    Where it's seen: High-engagement posts on security social media highlighting CVSS 10 and RCE potential; aggregator sites republishing; calls for immediate patching. No researcher PoC drops, no defender triage reports, no advisory confirmation visible yet.

  15. 18 CVE-2026-10702 score 8 · 12 posts
    hype MIXED · 52 hack

    What: JIT miscompilation in Firefox's IonMonkey JavaScript engine; instruction-modeling flaw affecting Firefox <151.0.3 (EPSS 0.002, low base score).

    Why it matters: Firefox patched promptly (v151.0.3); security researcher disclosed "IonStack" chain pairing this CVE with CVE-2026-43499 for Android browser-to-kernel exploit. No public PoC yet, not KEV-listed. Chatter emphasizes severity of exploit chain rather than standalone CVE risk.

    Where it's seen: Researcher posts detailing technical nature (IonMonkey flaw); Android exploit chain claims circulating; no vendor emergency advisory beyond standard patch release; low engagement outside specialist circles.

  16. 19 CVE-2026-6875 score 8 · 11 posts
    hype MIXED · 52 hack

    What: Unauthenticated remote code execution in ServiceNow AI Platform via sandbox escape (CVSS 9.5). Affects self-hosted and SaaS instances.

    Why it matters: Social posts claim active exploitation since July 17, but ServiceNow's official advisory (July 13) states "not currently aware of exploitation." No KEV listing. EPSS is extremely low (0.40th percentile). Patches deployed immediately to hosted instances; self-hosted updates available. Credibility gap: threat intelligence vendor cited ("Defused") but advisory from vendor contradicts exploitation claims.

    Where it's seen: Bluesky amplification of "critical sandbox escape RCE" narratives, with posts referencing Defused and HackerNews; some claim July 17 in-the-wild activity despite no vendor confirmation. No PoC code visible.

  17. 20 CVE-2026-57356 HIGH · 7.1 score 7 · 14 posts
    hype MOSTLY HYPE · 18 hack

    What: Unauthenticated Cross-Site Scripting (XSS) in MC Woocommerce Wishlist plugin <= 1.9.19 affecting WordPress installations (CVSS 7.1 HIGH).

    Why it matters: Top 8 posts are identical templated bluesky repeats mentioning "proofofconcept" hashtag but no actual PoC link, working exploit, or vendor patch details provided. Not KEV-listed. Low EPSS (0.09%). Chatter is high-volume but entirely derivative; no defender activity or threat intel grounding the noise.

    Where it's seen: Bluesky hashtag spam—eight near-identical posts with keyword stuffing (#redteam #malware #proofofconcept) but zero substantive analysis, links, or evidence of active exploitation.

  18. 21 CVE-2026-57366 HIGH · 7.1 score 7 · 14 posts
    hype MOSTLY HYPE · 18 hack

    What: Unauthenticated Cross-Site Scripting (XSS) in WPAdverts WordPress plugin ≤2.3.1 (CVSS 7.1, HIGH).

    Why it matters: No KEV listing, no public PoC referenced in posts, no vendor advisory evidence provided. Low EPSS (0.0904th percentile) suggests minimal observed exploitation signals. Chatter is identical boilerplate repeated across 8 posts with no actionable detail—hashtag spam ("proofofconcept") without substantive analysis or exploit demonstration.

    Where it's seen: Pure social amplification on Bluesky: eight identical posts mentioning the CVE ID and plugin name with generic cybersecurity hashtags. No researcher commentary, no plugin update advisory links, no defender triage signals.

  19. 22 CVE-2013-4786 HIGH · 7.5 EPSS 79% score 7 · 10 posts
    hype LIKELY HACK · 72 hack

    What: IPMI 2.0 BMC authentication flaw (CVE-2013-4786) allows unauthenticated attackers to extract password hashes via RAKP handshake before login (CVSS 7.5).

    Why it matters: A 13-year-old protocol-level vulnerability with no patch possible; recent reconnaissance found 24,650+ internet-exposed BMCs (iLO, iDRAC, Supermicro) leaking hashes. Active scanning and weak credential abuse reported on HPE systems. No KEV listing, but scale and defender urgency (rotate factory passwords, air-gap BMCs) signal real triage activity.

    Where it's seen: Threat intel reports citing 36k+ exposed BMCs; Bluesky debate over vendor-sponsored research; defenders discussing mitigation (network isolation, credential rotation); no working exploit PoC or 0-day claims, but operational reconnaissance widely documented.

  20. 23 CVE-2026-3545 CRITICAL · 9.6 score 7 · 8 posts
    hype MOSTLY HYPE · 28 hack

    What: Insufficient data validation in Chrome navigation prior to v145.0.7632.159 permits sandbox escape via crafted HTML; CVSS 9.6 (CRITICAL), EPSS 0.18%.

    Why it matters: Fixed in Chrome 145+. Not KEV-listed. Social chatter focuses heavily on Google's AI-driven detection narrative and speculative "13-year-old flaw" claims rather than exploitation evidence or urgent patching signals. No public PoC or in-the-wild activity reported in posts.

    Where it's seen: Bluesky posts dominate, centering on AI detection story and vendor marketing angles. Minimal defender triage signals; mostly clickbait and speculation around detection methodology and oversight risks.

  21. 24 CVE-2026-50522 CRITICAL · 9.8 KEV EPSS 76% score 7 · 10 posts
    hype LIKELY HACK · 82 hack

    What: Unauthenticated deserialization in Microsoft Office SharePoint on-premises (2016, 2019, Subscription Edition) allows remote code execution; CVSS 9.8 CRITICAL, EPSS 0.97.

    Why it matters: Social chatter confirms active in-the-wild exploitation with public PoC within 24 hours of posts. WatchTowr and defender reports document attackers stealing IIS machine keys for persistence—a post-patch persistence vector. No KEV listing yet, but urgency and specificity suggest real triage activity.

    Where it's seen: Security news outlets (HelpNetSecurity, TheHackerNews), threat intel feeds, defender alerts emphasizing machine key rotation. Posts span multiple languages and regions, indicating broad awareness and coordinated response.

  22. 25 CVE-2026-57355 MEDIUM · 6.5 score 7 · 14 posts
    hype PURE HYPE · 8 hack

    What: Broken access control in Classified Listing WordPress plugin versions ≤5.4.2 allowing subscribers to access restricted content (CVSS 6.5 medium).

    Why it matters: Not KEV-listed; EPSS near zero (0.22%); no PoC or in-the-wild exploitation confirmed. Social posts are identical boilerplate repeats mentioning a mismatched CVSS (4.3 vs actual 6.5), suggesting automated spam rather than genuine researcher signal.

    Where it's seen: Eight near-duplicate Bluesky posts with generic hashtags and no substantive analysis, technical detail, or exploit code. No vendor advisory or defender triage activity observed.