ZCyberNews
中文

#active-exploitation

16 articles

Between April and August 2026, ZCyberNews covered 17 instances of active exploitation, with ten critical and six high-severity flaws dominating the landscape. The most-covered vulnerability was CVE-2026-48907, carrying a CVSS score of 10, followed by CVE-2024-57726 at 9.9, and three 9.8-rated issues: CVE-2026-22679, CVE-2026-41089, and CVE-2026-60004. These attacks primarily hit government, technology, enterprise, and managed service provider sectors, with global impact across the United States, North America, Asia, and China. One medium-severity case was also documented. The archive tracks these incidents from April 14 to August 26, 2026.

Gitea repository interface with a red alert banner indicating a critical vulnerabilityCRITICAL
Vulnerabilities

CVE-2026-60004 Gitea RCE Exploited in the Wild, CISA Warns

CVE-2026-60004, a 9.8-CVSS Gitea RCE, is under active attack per CISA. Attackers with repo write access can run shell commands. Patch now.

CVE-2026-60004
4 min read
macOS system settings interface with a security warning overlayCRITICAL
Vulnerabilities

CVE-2026-65400 macOS Flaw Added to CISA KEV, Actively Exploited

CISA added CVE-2026-65400, a 9.8-CVSS macOS authentication bypass, to its KEV catalog on August 18, confirming active exploitation. No patch yet.

CVE-2026-65400
4 min read
Cisco firewall device with warning overlay indicating denial-of-service vulnerabilityHIGH
Vulnerabilities

Cisco Patches Actively Exploited ASA, FTD VPN DoS Flaw CVE-2026-20349

CVE-2026-20349 (CVSS 8.6) lets unauthenticated remote attackers crash Cisco ASA and FTD VPN devices via crafted HTTP requests. Active exploitation confirmed; hotfixes available.

CVE-2026-20349
4 min read
CISA KEV catalog entry with Joomla JCE flaw highlightedCRITICAL
Vulnerabilities

CISA Adds Joomla JCE Flaw CVE-2026-48907 to KEV Catalog

CISA warns of active exploitation of CVE-2026-48907, a CVSS 10.0 improper access control flaw in Widget Factory Joomla Content Editor (JCE) allowing unauthenticated PHP code...

CVE-2026-48907
3 min read
Screenshot of CISA Known Exploited Vulnerabilities catalog entry for CVE-2026-42271HIGH
Vulnerabilities

CVE-2026-42271: LiteLLM Flaw Exploited in the Wild, CISA Adds to KEV

CISA added CVE-2026-42271 (CVSS 8.7) to its Known Exploited Vulnerabilities catalog after evidence of active exploitation against BerriAI LiteLLM deployments.

CVE-2026-42271
4 min read
Windows domain controller and Netlogon authentication traffic under active exploitation alert for CVE-2026-41089.CRITICAL
Vulnerabilities

CVE-2026-41089: Windows Netlogon RCE Exploited in Wild

CVE-2026-41089 is a critical Windows Netlogon RCE now reported as exploited in the wild, with Microsoft CNA scoring it CVSS 9.8.

CVE-2026-41089
4 min read
CVE-2026-9082: Drupal Core SQL Injection Bug Added to CISA KEVMEDIUM
Vulnerabilities

CVE-2026-9082: Drupal Core SQL Injection Bug Added to CISA KEV

CISA added CVE-2026-9082 (CVSS 6.5) to its Known Exploited Vulnerabilities catalog after evidence of active exploitation against all supported Drupal Core versions.

CVE-2026-9082
3 min read
CVE-2025-2749: Kentico Xperience Path Traversal Under Active ExploitHIGH
Vulnerabilities

CVE-2025-2749: Kentico Xperience Path Traversal Under Active Exploit

CISA adds CVE-2025-2749 to KEV catalog: Kentico Xperience path traversal lets authenticated Staging Sync Server upload arbitrary files. Due date for federal agencies: May 4, 2026.

CVE-2025-2749
3 min read
Microsoft Warns of Exchange Zero-Day CVE-2026-42897 Exploited inHIGH
Vulnerabilities

Microsoft Warns of Exchange Zero-Day CVE-2026-42897 Exploited in

CVE-2026-42897 is a high-severity Exchange Server spoofing flaw exploited in the wild, enabling XSS-based code execution via Outlook on the web.

CVE-2026-42897
4 min read
Palo Alto PAN-OS CVE-2026-0300 Attacked via Captive PortalCRITICAL
Vulnerabilities

Palo Alto PAN-OS CVE-2026-0300 Attacked via Captive Portal

CVE-2026-0300 is a critical PAN-OS buffer overflow in the User-ID Authentication Portal. Fixed builds are upcoming, so disable or restrict the portal immediately.

CVE-2026-0300
4 min read
Weaver E-cology Zero-Day CVE-2026-22679 Exploited Since MarchCRITICAL
Vulnerabilities

Weaver E-cology Zero-Day CVE-2026-22679 Exploited Since March

CVE-2026-22679 (CVSS 9.8) in Weaver E-cology OA has been exploited in the wild since mid-March 2026. Attackers run discovery commands post-exploit. No patch available.

CVE-2026-22679
3 min read
CISA Adds Actively Exploited ConnectWise, Windows Flaws to KEVHIGH
Vulnerabilities

CISA Adds Actively Exploited ConnectWise, Windows Flaws to KEV

CISA added CVE-2024-1708 (ConnectWise ScreenConnect path traversal, CVSS 8.4) and an unnamed Windows flaw to its KEV catalog based on confirmed active exploitation.

CVE-2024-1708
3 min read
CISA Adds 4 Exploited Flaws to KEV, Sets May 2026 DeadlineCRITICAL
Vulnerabilities

CISA Adds 4 Exploited Flaws to KEV, Sets May 2026 Deadline

CISA added 4 actively exploited vulnerabilities to its KEV catalog — SimpleHelp, Samsung MagicINFO 9, and D-Link DIR-823X — with a May 2026 federal remediation deadline.

CVE-2024-57726
3 min read
LMDeploy SSRF Flaw CVE-2026-33626 Exploited 13 Hours After DisclosureHIGH
Vulnerabilities

LMDeploy SSRF Flaw CVE-2026-33626 Exploited 13 Hours After Disclosure

CVE-2026-33626 (CVSS 7.5) in LMDeploy, an open-source LLM toolkit, was exploited in the wild within 13 hours of public disclosure, enabling SSRF attacks to access sensitive…

CVE-2026-33626
3 min read
Critical Nginx UI Vulnerability Actively Exploited for Remote Server TakeoverCRITICAL
Vulnerabilities

Critical Nginx UI Vulnerability Actively Exploited for Remote Server Takeover

Attackers are actively exploiting CVE-2026-33032, a critical flaw in the Nginx UI management tool, to execute arbitrary code and gain full control of affected web servers.

CVE-2026-33032
3 min read
ShowDoc RCE Vulnerability CVE-2025-0520 Under Active ExploitationCRITICAL
Vulnerabilities

ShowDoc RCE Vulnerability CVE-2025-0520 Under Active Exploitation

Attackers are actively exploiting CVE-2025-0520, a critical RCE flaw in ShowDoc, to compromise unpatched servers via unrestricted file upload. The vulnerability has a CVSS score of 9.4.

CVE-2025-0520
3 min read

Stay Updated

Get the latest cybersecurity news delivered to your inbox.