<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/known-exploited-vulnerabilities-catalog/feed</id>
  <title>Previdian - Known Exploited Vulnerabilities Catalog</title>
  <updated>2026-10-02T10:48:23.360844+00:00</updated>
  <author>
    <name>Previdian</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org/known-exploited-vulnerabilities-catalog" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>KEV catalog conforming to GCVE BCP-07. Contains the most recent 20 entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/known-exploited-vulnerabilities-catalog/0b411d34-c6d6-4237-ac39-63754cdc5fc9</id>
    <title>CVE-2024-58387 - Confirmed Exploitation</title>
    <updated>2026-10-02T09:09:06.110367+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><h3>CVE-2024-58387</h3>
<p><strong>Status:</strong> Confirmed</p>
<p><strong>Exploited:</strong> Yes</p>
<p><strong>Status Updated:</strong> 2026-09-30 22:40 UTC</p>
<p><strong>Evidence Sources:</strong> 1</p>
<p><strong>First Seen:</strong> 2026-09-30</p>
<p><strong>Asserted:</strong> 2026-09-30</p>
<p><strong>Scope Notes:</strong> Inspur HCM Cloud Arbitrary File Read via file/download Endpoint | Affected: Inspur / Haiyue HCM Cloud | CVSS: 8.7 (HIGH) | EPSS: 0.00708 | Used in malware: unknown | Not yet in CISA KEV: True</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/CVE-2024-58387"/>
    <published>2026-09-30T22:40:21+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/known-exploited-vulnerabilities-catalog/d37f3a46-397b-4c5a-9a37-0739db246356</id>
    <title>CVE-2023-54403 - Confirmed Exploitation</title>
    <updated>2026-10-02T09:09:06.169914+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><h3>CVE-2023-54403</h3>
<p><strong>Status:</strong> Confirmed</p>
<p><strong>Exploited:</strong> Yes</p>
<p><strong>Status Updated:</strong> 2026-09-30 22:40 UTC</p>
<p><strong>Evidence Sources:</strong> 1</p>
<p><strong>First Seen:</strong> 2026-09-30</p>
<p><strong>Asserted:</strong> 2026-09-30</p>
<p><strong>Scope Notes:</strong> Yonyou U8 CRM Arbitrary File Read via getemaildata.php | Affected: Yonyou / U8 CRM | CVSS: 8.7 (HIGH) | EPSS: 0.00686 | Used in malware: unknown | Not yet in CISA KEV: True</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/CVE-2023-54403"/>
    <published>2026-09-30T22:40:20+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/known-exploited-vulnerabilities-catalog/433c935d-b150-4383-86ae-10596d09db9e</id>
    <title>CVE-2023-54402 - Confirmed Exploitation</title>
    <updated>2026-10-02T09:09:06.234775+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><h3>CVE-2023-54402</h3>
<p><strong>Status:</strong> Confirmed</p>
<p><strong>Exploited:</strong> Yes</p>
<p><strong>Status Updated:</strong> 2026-09-30 22:30 UTC</p>
<p><strong>Evidence Sources:</strong> 1</p>
<p><strong>First Seen:</strong> 2026-09-30</p>
<p><strong>Asserted:</strong> 2026-09-30</p>
<p><strong>Scope Notes:</strong> iDocView SSRF via /doc/upload Endpoint Hardcoded Token | Affected: iDocView / iDocView | CVSS: 8.7 (HIGH) | EPSS: 0.00791 | Used in malware: unknown | Not yet in CISA KEV: True</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/CVE-2023-54402"/>
    <published>2026-09-30T22:30:25+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/known-exploited-vulnerabilities-catalog/e1e0ab2c-a5bc-4e40-815f-d89539f046f9</id>
    <title>CVE-2018-17254 - Confirmed Exploitation</title>
    <updated>2026-10-02T09:09:12.275876+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><h3>CVE-2018-17254</h3>
<p><strong>Status:</strong> Confirmed</p>
<p><strong>Exploited:</strong> Yes</p>
<p><strong>Status Updated:</strong> 2026-09-30 22:26 UTC</p>
<p><strong>Evidence Sources:</strong> 1</p>
<p><strong>First Seen:</strong> 2026-09-30</p>
<p><strong>Asserted:</strong> 2026-09-30</p>
<p><strong>Scope Notes:</strong> The JCK Editor component 6.4.4 for Joomla! allows SQL Injection via the jtreelink/dialogs/links.php parent parameter. | Affected: Arkextensions / JCK Editor | CVSS: 9.8 (CRITICAL) | EPSS: 0.82976 | Used in malware: unknown | Not yet in CISA KEV: True</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/CVE-2018-17254"/>
    <published>2026-09-30T22:26:12+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/known-exploited-vulnerabilities-catalog/af86cad8-62fd-4054-a00a-e4d1dcb5f1f3</id>
    <title>CVE-2026-102490 - Confirmed Exploitation</title>
    <updated>2026-10-02T09:09:06.296601+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><h3>CVE-2026-102490</h3>
<p><strong>Status:</strong> Confirmed</p>
<p><strong>Exploited:</strong> Yes</p>
<p><strong>Status Updated:</strong> 2026-09-30 20:53 UTC</p>
<p><strong>Evidence Sources:</strong> 1</p>
<p><strong>First Seen:</strong> 2026-09-30</p>
<p><strong>Asserted:</strong> 2026-09-30</p>
<p><strong>Scope Notes:</strong> Undisclosed LPE in Zammad v1.5.0 to v7.1.0-alpha | Affected: Zammad / Zammad | CVSS: 8.5 (HIGH) | EPSS: 0.00319 | Used in malware: unknown | Not yet in CISA KEV: True</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/CVE-2026-102490"/>
    <published>2026-09-30T20:53:04+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/known-exploited-vulnerabilities-catalog/1d50c037-c9cd-4754-8ae9-1c69cfca26ae</id>
    <title>CVE-2026-102489 - Confirmed Exploitation</title>
    <updated>2026-10-02T09:09:06.360592+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><h3>CVE-2026-102489</h3>
<p><strong>Status:</strong> Confirmed</p>
<p><strong>Exploited:</strong> Yes</p>
<p><strong>Status Updated:</strong> 2026-09-30 20:52 UTC</p>
<p><strong>Evidence Sources:</strong> 1</p>
<p><strong>First Seen:</strong> 2026-09-30</p>
<p><strong>Asserted:</strong> 2026-09-30</p>
<p><strong>Scope Notes:</strong> Undisclosed RCE in Zammad v6.3 and higher | Affected: Zammad / Zammad | CVSS: 8.7 (HIGH) | EPSS: 0.00709 | Used in malware: unknown | Not yet in CISA KEV: True</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/CVE-2026-102489"/>
    <published>2026-09-30T20:52:45+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/known-exploited-vulnerabilities-catalog/191138e1-55dd-445d-b568-522bb956120b</id>
    <title>CVE-2026-76504 - Confirmed Exploitation</title>
    <updated>2026-10-02T09:09:06.403929+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><h3>CVE-2026-76504</h3>
<p><strong>Status:</strong> Confirmed</p>
<p><strong>Exploited:</strong> Yes</p>
<p><strong>Status Updated:</strong> 2026-09-30 15:49 UTC</p>
<p><strong>Evidence Sources:</strong> 1</p>
<p><strong>First Seen:</strong> 2026-09-30</p>
<p><strong>Asserted:</strong> 2026-09-30</p>
<p><strong>Scope Notes:</strong> Cisco Catalyst SD-WAN Manager System Account Authorization Bypass Vulnerability | Affected: Cisco / Cisco Catalyst SD-WAN Manager | CVSS: 9.8 (CRITICAL) | EPSS: 0.01096 | Used in malware: unknown | Listed 4 hours ahead of CISA KEV | Not yet in CISA KEV: False</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/CVE-2026-76504"/>
    <published>2026-09-30T15:49:09+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/known-exploited-vulnerabilities-catalog/a42b7560-a2fa-43c3-8c11-34788e35d438</id>
    <title>CVE-2023-54400 - Confirmed Exploitation</title>
    <updated>2026-10-02T09:09:06.446991+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><h3>CVE-2023-54400</h3>
<p><strong>Status:</strong> Confirmed</p>
<p><strong>Exploited:</strong> Yes</p>
<p><strong>Status Updated:</strong> 2026-09-29 17:30 UTC</p>
<p><strong>Evidence Sources:</strong> 1</p>
<p><strong>First Seen:</strong> 2026-09-29</p>
<p><strong>Asserted:</strong> 2026-09-29</p>
<p><strong>Scope Notes:</strong> Fumeng Cloud SQL Injection via AjaxMethod.ashx getEmpByname | Affected: Fumasoft / Fumeng Cloud | CVSS: 9.3 (CRITICAL) | EPSS: 0.00464 | Used in malware: unknown | Not yet in CISA KEV: True</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/CVE-2023-54400"/>
    <published>2026-09-29T17:30:26+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/known-exploited-vulnerabilities-catalog/f0b90996-2b29-4b73-9f28-fd30b15ec3a0</id>
    <title>CVE-2015-20122 - Confirmed Exploitation</title>
    <updated>2026-10-02T09:09:06.498050+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><h3>CVE-2015-20122</h3>
<p><strong>Status:</strong> Confirmed</p>
<p><strong>Exploited:</strong> Yes</p>
<p><strong>Status Updated:</strong> 2026-09-29 17:10 UTC</p>
<p><strong>Evidence Sources:</strong> 1</p>
<p><strong>First Seen:</strong> 2026-09-29</p>
<p><strong>Asserted:</strong> 2026-09-29</p>
<p><strong>Scope Notes:</strong> Seeyon A6 OA Unauthenticated SQL Injection via downloadAtt.jsp | Affected: Yonyou / A6 OA | CVSS: 8.7 (HIGH) | EPSS: 0.00476 | Used in malware: unknown | Not yet in CISA KEV: True</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/CVE-2015-20122"/>
    <published>2026-09-29T17:10:34+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/known-exploited-vulnerabilities-catalog/97856b10-7719-4920-badd-6c35612f58f5</id>
    <title>CVE-2026-85520 - Confirmed Exploitation</title>
    <updated>2026-10-02T09:09:06.539449+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><h3>CVE-2026-85520</h3>
<p><strong>Status:</strong> Confirmed</p>
<p><strong>Exploited:</strong> Yes</p>
<p><strong>Status Updated:</strong> 2026-09-29 13:40 UTC</p>
<p><strong>Evidence Sources:</strong> 1</p>
<p><strong>First Seen:</strong> 2026-09-29</p>
<p><strong>Asserted:</strong> 2026-09-29</p>
<p><strong>Scope Notes:</strong> Unauthenticated arbitrary file write leading to RCE in gmfeed PrestaShop module | Affected: MyPresta / Google Merchant Center Feed | CVSS: 9.3 (CRITICAL) | EPSS: 0.00991 | Used in malware: unknown | Not yet in CISA KEV: True</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/CVE-2026-85520"/>
    <published>2026-09-29T13:40:26+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/known-exploited-vulnerabilities-catalog/ef40094f-c47a-4656-bcbf-da930bf6f44d</id>
    <title>CVE-2025-62023 - Confirmed Exploitation</title>
    <updated>2026-10-02T09:09:06.582283+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><h3>CVE-2025-62023</h3>
<p><strong>Status:</strong> Confirmed</p>
<p><strong>Exploited:</strong> Yes</p>
<p><strong>Status Updated:</strong> 2026-09-29 09:10 UTC</p>
<p><strong>Evidence Sources:</strong> 1</p>
<p><strong>First Seen:</strong> 2026-09-29</p>
<p><strong>Asserted:</strong> 2026-09-29</p>
<p><strong>Scope Notes:</strong> WordPress s2Member plugin &lt;= 250905 - Remote Code Execution (RCE) vulnerability | Affected: Cristián Lávaque / s2Member | CVSS: 9.0 (CRITICAL) | EPSS: 0.00418 | Used in malware: unknown | Not yet in CISA KEV: True</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/CVE-2025-62023"/>
    <published>2026-09-29T09:10:24+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/known-exploited-vulnerabilities-catalog/b8a76ec3-6323-4c56-9360-6ab9c79bbd7f</id>
    <title>CVE-2026-86950 - Confirmed Exploitation</title>
    <updated>2026-10-02T09:09:06.622762+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><h3>CVE-2026-86950</h3>
<p><strong>Status:</strong> Confirmed</p>
<p><strong>Exploited:</strong> Yes</p>
<p><strong>Status Updated:</strong> 2026-09-28 21:30 UTC</p>
<p><strong>Evidence Sources:</strong> 1</p>
<p><strong>First Seen:</strong> 2026-09-28</p>
<p><strong>Asserted:</strong> 2026-09-28</p>
<p><strong>Scope Notes:</strong> An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia... | Affected: Apple / iOS and iPadOS, macOS | CVSS: 8.8 (HIGH) | EPSS: 0.01242 | Used in malware: unknown | Listed 19 hours ahead of CISA KEV | Not yet in CISA KEV: False</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/CVE-2026-86950"/>
    <published>2026-09-28T21:30:46+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/known-exploited-vulnerabilities-catalog/dda0a464-a61f-4baa-ab9a-59f97aa9098c</id>
    <title>CVE-2026-49076 - Confirmed Exploitation</title>
    <updated>2026-10-02T09:09:06.664024+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><h3>CVE-2026-49076</h3>
<p><strong>Status:</strong> Confirmed</p>
<p><strong>Exploited:</strong> Yes</p>
<p><strong>Status Updated:</strong> 2026-09-28 08:01 UTC</p>
<p><strong>Evidence Sources:</strong> 1</p>
<p><strong>First Seen:</strong> 2026-09-28</p>
<p><strong>Asserted:</strong> 2026-09-28</p>
<p><strong>Scope Notes:</strong> WordPress JetEngine plugin &lt;= 3.8.9.1 - SQL Injection vulnerability | Affected: Crocoblock / JetEngine | CVSS: 9.3 (CRITICAL) | EPSS: 0.004 | Used in malware: unknown | Not yet in CISA KEV: True</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/CVE-2026-49076"/>
    <published>2026-09-28T08:01:08+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/known-exploited-vulnerabilities-catalog/227780c0-4c0e-4a6b-b681-356f72c8c9a4</id>
    <title>CVE-2026-42608 - Confirmed Exploitation</title>
    <updated>2026-10-02T09:09:06.708050+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><h3>CVE-2026-42608</h3>
<p><strong>Status:</strong> Confirmed</p>
<p><strong>Exploited:</strong> Yes</p>
<p><strong>Status Updated:</strong> 2026-09-27 19:12 UTC</p>
<p><strong>Evidence Sources:</strong> 1</p>
<p><strong>First Seen:</strong> 2026-09-27</p>
<p><strong>Asserted:</strong> 2026-09-27</p>
<p><strong>Scope Notes:</strong> Grav: Unauthenticated Path Traversal &amp; Arbitrary File Write in FormFlash component. | Affected: Getgrav / grav | CVSS: 8.8 (HIGH) | EPSS: 0.00521 | Used in malware: unknown | Not yet in CISA KEV: True</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/CVE-2026-42608"/>
    <published>2026-09-27T19:12:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/known-exploited-vulnerabilities-catalog/8d44fc51-fba4-45cd-b0fe-4238152db271</id>
    <title>CVE-2026-88772 - Confirmed Exploitation</title>
    <updated>2026-10-02T09:09:06.751726+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><h3>CVE-2026-88772</h3>
<p><strong>Status:</strong> Confirmed</p>
<p><strong>Exploited:</strong> Yes</p>
<p><strong>Status Updated:</strong> 2026-09-27 18:45 UTC</p>
<p><strong>Evidence Sources:</strong> 1</p>
<p><strong>First Seen:</strong> 2026-09-27</p>
<p><strong>Asserted:</strong> 2026-09-27</p>
<p><strong>Scope Notes:</strong> Memory overflow vulnerability leading to Remote Code Execution or Denial of Service | Affected: Citrix NetScaler / ADC, Gateway | CVSS: 9.5 (CRITICAL) | EPSS: 0.01301 | Used in malware: unknown | Listed 5 hours ahead of CISA KEV | Not yet in CISA KEV: False</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/CVE-2026-88772"/>
    <published>2026-09-27T18:45:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/known-exploited-vulnerabilities-catalog/9a51539b-3eb6-4a05-8ad4-4da312baa092</id>
    <title>CVE-2026-88771 - Confirmed Exploitation</title>
    <updated>2026-10-02T09:09:06.796146+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><h3>CVE-2026-88771</h3>
<p><strong>Status:</strong> Confirmed</p>
<p><strong>Exploited:</strong> Yes</p>
<p><strong>Status Updated:</strong> 2026-09-27 18:44 UTC</p>
<p><strong>Evidence Sources:</strong> 1</p>
<p><strong>First Seen:</strong> 2026-09-27</p>
<p><strong>Asserted:</strong> 2026-09-27</p>
<p><strong>Scope Notes:</strong> A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands | Affected: Citrix NetScaler / ADC, Gateway | CVSS: 9.5 (CRITICAL) | EPSS: 0.01063 | Used in malware: unknown | Listed 5 hours ahead of CISA KEV | Not yet in CISA KEV: False</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/CVE-2026-88771"/>
    <published>2026-09-27T18:44:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/known-exploited-vulnerabilities-catalog/c54319c0-bd12-4409-b163-4308b7562b28</id>
    <title>CVE-2026-65660 - Confirmed Exploitation</title>
    <updated>2026-10-02T09:09:06.840547+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><h3>CVE-2026-65660</h3>
<p><strong>Status:</strong> Confirmed</p>
<p><strong>Exploited:</strong> Yes</p>
<p><strong>Status Updated:</strong> 2026-09-24 14:32 UTC</p>
<p><strong>Evidence Sources:</strong> 1</p>
<p><strong>First Seen:</strong> 2026-09-24</p>
<p><strong>Asserted:</strong> 2026-09-24</p>
<p><strong>Scope Notes:</strong> Microsoft SharePoint Server Remote Code Execution Vulnerability | Affected: Microsoft / Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition | CVSS: 8.8 (HIGH) | EPSS: 0.02101 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/CVE-2026-65660"/>
    <published>2026-09-24T14:32:16+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/known-exploited-vulnerabilities-catalog/26df2b4d-fe15-4c57-b8b5-64b0cfda1220</id>
    <title>CVE-2026-48842 - Confirmed Exploitation</title>
    <updated>2026-10-02T09:09:06.897990+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><h3>CVE-2026-48842</h3>
<p><strong>Status:</strong> Confirmed</p>
<p><strong>Exploited:</strong> Yes</p>
<p><strong>Status Updated:</strong> 2026-09-24 11:23 UTC</p>
<p><strong>Evidence Sources:</strong> 1</p>
<p><strong>First Seen:</strong> 2026-09-24</p>
<p><strong>Asserted:</strong> 2026-09-24</p>
<p><strong>Scope Notes:</strong> Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace()... | Affected: Roundcube / Webmail | CVSS: 8.1 (HIGH) | EPSS: 0.00891 | Used in malware: unknown | Not yet in CISA KEV: True</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/CVE-2026-48842"/>
    <published>2026-09-24T11:23:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/known-exploited-vulnerabilities-catalog/fabacc0d-7aa0-4ab5-a285-111379c4b6fa</id>
    <title>CVE-2026-67279 - Confirmed Exploitation</title>
    <updated>2026-10-02T09:09:06.940307+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><h3>CVE-2026-67279</h3>
<p><strong>Status:</strong> Confirmed</p>
<p><strong>Exploited:</strong> Yes</p>
<p><strong>Status Updated:</strong> 2026-09-23 19:08 UTC</p>
<p><strong>Evidence Sources:</strong> 1</p>
<p><strong>First Seen:</strong> 2026-09-23</p>
<p><strong>Asserted:</strong> 2026-09-23</p>
<p><strong>Scope Notes:</strong> SSH Pre-Authentication Rekey State Bypass in MikroTik RouterOS | Affected: Mikrotik / RouterOS | CVSS: 6.9 (MEDIUM) | EPSS: 0.01027 | Used in malware: unknown | Listed 2 days ahead of CISA KEV | Not yet in CISA KEV: False</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/CVE-2026-67279"/>
    <published>2026-09-23T19:08:47+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/known-exploited-vulnerabilities-catalog/e42957dd-1421-4eca-b481-e204d5b6f1d0</id>
    <title>CVE-2026-87902 - Confirmed Exploitation</title>
    <updated>2026-10-02T09:09:06.983893+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><h3>CVE-2026-87902</h3>
<p><strong>Status:</strong> Confirmed</p>
<p><strong>Exploited:</strong> Yes</p>
<p><strong>Status Updated:</strong> 2026-09-23 14:53 UTC</p>
<p><strong>Evidence Sources:</strong> 1</p>
<p><strong>First Seen:</strong> 2026-09-23</p>
<p><strong>Asserted:</strong> 2026-09-23</p>
<p><strong>Scope Notes:</strong> An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active... | Affected: WordPress / WordPress | CVSS: 8.1 (HIGH) | EPSS: 0.19756 | Used in malware: unknown | Listed 2 days ahead of CISA KEV | Not yet in CISA KEV: False</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/CVE-2026-87902"/>
    <published>2026-09-23T14:53:51+00:00</published>
  </entry>
</feed>
