<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>ENISA - Known Exploited Vulnerabilities Catalog</title>
    <link>https://cve.radiocsirt.org/known-exploited-vulnerabilities-catalog</link>
    <description>KEV catalog conforming to GCVE BCP-07. Contains the most recent 20 entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 09:12:47 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-82329 - Confirmed Exploitation</title>
      <link>https://cve.radiocsirt.org/vuln/CVE-2026-82329</link>
      <description>&lt;h3&gt;CVE-2026-82329&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Status:&lt;/strong&gt; Confirmed&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Exploited:&lt;/strong&gt; Yes&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Status Updated:&lt;/strong&gt; 2026-10-02 08:52 UTC&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Evidence Sources:&lt;/strong&gt; 1&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Scope Notes:&lt;/strong&gt; Affected: JFrog / Artifactory | Description: Authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges. | Patched since: 2026/08/28 | Exploitation type: unknown | CWEs: CWE-287 | Origin source: ENISA | Notes: https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201&lt;/p&gt;</description>
      <content:encoded>&lt;h3&gt;CVE-2026-82329&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Status:&lt;/strong&gt; Confirmed&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Exploited:&lt;/strong&gt; Yes&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Status Updated:&lt;/strong&gt; 2026-10-02 08:52 UTC&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Evidence Sources:&lt;/strong&gt; 1&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Scope Notes:&lt;/strong&gt; Affected: JFrog / Artifactory | Description: Authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges. | Patched since: 2026/08/28 | Exploitation type: unknown | CWEs: CWE-287 | Origin source: ENISA | Notes: https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/known-exploited-vulnerabilities-catalog/02fe26a4-d026-463a-ab66-0a3f372b3417</guid>
      <pubDate>Fri, 02 Oct 2026 08:52:36 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-104286 - Confirmed Exploitation</title>
      <link>https://cve.radiocsirt.org/vuln/CVE-2026-104286</link>
      <description>&lt;h3&gt;CVE-2026-104286&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Status:&lt;/strong&gt; Confirmed&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Exploited:&lt;/strong&gt; Yes&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Status Updated:&lt;/strong&gt; 2026-10-01 02:00 UTC&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Evidence Sources:&lt;/strong&gt; 1&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;First Seen:&lt;/strong&gt; 2026-10-01&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Asserted:&lt;/strong&gt; 2026-10-01&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Scope Notes:&lt;/strong&gt; Affected: Fortinet / FortiMail | Description: Improper limitation of a pathname to a restricted directory (&amp;#39;path traversal&amp;#39;) vulnerability in Fortinet FortiMail may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests. Customers are urged to disable the IBE feature support or disable access to the FortiMail management interface from the internet or limit the access only from trusted private network. | Exploitation type: unknown | CWEs: CWE-22, CWE-158 | Origin source: CNW | Notes: https://fortiguard.fortinet.com/psirt/FG-IR-26-175&lt;/p&gt;</description>
      <content:encoded>&lt;h3&gt;CVE-2026-104286&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Status:&lt;/strong&gt; Confirmed&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Exploited:&lt;/strong&gt; Yes&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Status Updated:&lt;/strong&gt; 2026-10-01 02:00 UTC&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Evidence Sources:&lt;/strong&gt; 1&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;First Seen:&lt;/strong&gt; 2026-10-01&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Asserted:&lt;/strong&gt; 2026-10-01&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Scope Notes:&lt;/strong&gt; Affected: Fortinet / FortiMail | Description: Improper limitation of a pathname to a restricted directory (&amp;#39;path traversal&amp;#39;) vulnerability in Fortinet FortiMail may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests. Customers are urged to disable the IBE feature support or disable access to the FortiMail management interface from the internet or limit the access only from trusted private network. | Exploitation type: unknown | CWEs: CWE-22, CWE-158 | Origin source: CNW | Notes: https://fortiguard.fortinet.com/psirt/FG-IR-26-175&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/known-exploited-vulnerabilities-catalog/91594a1e-e5e5-4789-9f64-e088757548fe</guid>
      <pubDate>Thu, 01 Oct 2026 02:00:00 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-102489 - Confirmed Exploitation</title>
      <link>https://cve.radiocsirt.org/vuln/CVE-2026-102489</link>
      <description>&lt;h3&gt;CVE-2026-102489&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Status:&lt;/strong&gt; Confirmed&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Exploited:&lt;/strong&gt; Yes&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Status Updated:&lt;/strong&gt; 2026-09-30 02:00 UTC&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Evidence Sources:&lt;/strong&gt; 1&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;First Seen:&lt;/strong&gt; 2026-09-30&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Asserted:&lt;/strong&gt; 2026-09-30&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Scope Notes:&lt;/strong&gt; Affected: Zammad / Zammad | Description: Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions. | Patched since: 2026/04/08 | Exploitation type: unknown | Origin source: NCSC-NL | Notes: https://www.ncsc.nl/alerts/actief-misbruik-van-zeroday-kwetsbaarheden-in-zammad-update-nu&lt;/p&gt;</description>
      <content:encoded>&lt;h3&gt;CVE-2026-102489&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Status:&lt;/strong&gt; Confirmed&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Exploited:&lt;/strong&gt; Yes&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Status Updated:&lt;/strong&gt; 2026-09-30 02:00 UTC&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Evidence Sources:&lt;/strong&gt; 1&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;First Seen:&lt;/strong&gt; 2026-09-30&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Asserted:&lt;/strong&gt; 2026-09-30&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Scope Notes:&lt;/strong&gt; Affected: Zammad / Zammad | Description: Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions. | Patched since: 2026/04/08 | Exploitation type: unknown | Origin source: NCSC-NL | Notes: https://www.ncsc.nl/alerts/actief-misbruik-van-zeroday-kwetsbaarheden-in-zammad-update-nu&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/known-exploited-vulnerabilities-catalog/9741ca20-f574-4fc6-b899-a2fccb65c863</guid>
      <pubDate>Wed, 30 Sep 2026 02:00:00 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-102490 - Confirmed Exploitation</title>
      <link>https://cve.radiocsirt.org/vuln/CVE-2026-102490</link>
      <description>&lt;h3&gt;CVE-2026-102490&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Status:&lt;/strong&gt; Confirmed&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Exploited:&lt;/strong&gt; Yes&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Status Updated:&lt;/strong&gt; 2026-09-30 02:00 UTC&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Evidence Sources:&lt;/strong&gt; 1&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;First Seen:&lt;/strong&gt; 2026-09-30&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Asserted:&lt;/strong&gt; 2026-09-30&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Scope Notes:&lt;/strong&gt; Affected: Zammad / Zammad | Description: All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root. | Exploitation type: unknown | Origin source: NCSC-NL | Notes: https://www.ncsc.nl/alerts/actief-misbruik-van-zeroday-kwetsbaarheden-in-zammad-update-nu&lt;/p&gt;</description>
      <content:encoded>&lt;h3&gt;CVE-2026-102490&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Status:&lt;/strong&gt; Confirmed&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Exploited:&lt;/strong&gt; Yes&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Status Updated:&lt;/strong&gt; 2026-09-30 02:00 UTC&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Evidence Sources:&lt;/strong&gt; 1&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;First Seen:&lt;/strong&gt; 2026-09-30&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Asserted:&lt;/strong&gt; 2026-09-30&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Scope Notes:&lt;/strong&gt; Affected: Zammad / Zammad | Description: All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root. | Exploitation type: unknown | Origin source: NCSC-NL | Notes: https://www.ncsc.nl/alerts/actief-misbruik-van-zeroday-kwetsbaarheden-in-zammad-update-nu&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/known-exploited-vulnerabilities-catalog/f0eee4c5-f0aa-46f1-a762-8eb8fe37a9ba</guid>
      <pubDate>Wed, 30 Sep 2026 02:00:00 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-67279 - Confirmed Exploitation</title>
      <link>https://cve.radiocsirt.org/vuln/CVE-2026-67279</link>
      <description>&lt;h3&gt;CVE-2026-67279&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Status:&lt;/strong&gt; Confirmed&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Exploited:&lt;/strong&gt; Yes&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Status Updated:&lt;/strong&gt; 2026-09-27 02:00 UTC&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Evidence Sources:&lt;/strong&gt; 1&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;First Seen:&lt;/strong&gt; 2026-09-27&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Asserted:&lt;/strong&gt; 2026-09-27&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Scope Notes:&lt;/strong&gt; MikroTrick | Affected: MikroTik / RouterOS | Description: RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request. On affected builds the server dispatches the command, enabling unauthenticated creation, overwrite, and reconstruction of files in the RouterOS managed file namespace, including support files containing configuration and diagnostic data.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable) | Patched since: 2026/09/03 | Exploitation type: unknown | CWEs: CWE-841 | Origin source: CERT.PL | Notes: https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/&lt;/p&gt;</description>
      <content:encoded>&lt;h3&gt;CVE-2026-67279&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Status:&lt;/strong&gt; Confirmed&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Exploited:&lt;/strong&gt; Yes&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Status Updated:&lt;/strong&gt; 2026-09-27 02:00 UTC&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Evidence Sources:&lt;/strong&gt; 1&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;First Seen:&lt;/strong&gt; 2026-09-27&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Asserted:&lt;/strong&gt; 2026-09-27&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Scope Notes:&lt;/strong&gt; MikroTrick | Affected: MikroTik / RouterOS | Description: RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request. On affected builds the server dispatches the command, enabling unauthenticated creation, overwrite, and reconstruction of files in the RouterOS managed file namespace, including support files containing configuration and diagnostic data.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable) | Patched since: 2026/09/03 | Exploitation type: unknown | CWEs: CWE-841 | Origin source: CERT.PL | Notes: https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/known-exploited-vulnerabilities-catalog/83117a75-3bb0-4467-8d76-33dc5fef9117</guid>
      <pubDate>Sun, 27 Sep 2026 02:00:00 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-88772 - Confirmed Exploitation</title>
      <link>https://cve.radiocsirt.org/vuln/CVE-2026-88772</link>
      <description>&lt;h3&gt;CVE-2026-88772&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Status:&lt;/strong&gt; Confirmed&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Exploited:&lt;/strong&gt; Yes&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Status Updated:&lt;/strong&gt; 2026-09-27 02:00 UTC&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Evidence Sources:&lt;/strong&gt; 1&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;First Seen:&lt;/strong&gt; 2026-09-27&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Asserted:&lt;/strong&gt; 2026-09-27&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Scope Notes:&lt;/strong&gt; Affected: Citrix / NetScaler ADC, NetScaler Gateway | Description: Memory overflow vulnerability leading to Remote Code Execution or Denial of Service | Exploitation type: unknown | CWEs: CWE-119 | Origin source: CNW | Notes: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096&lt;/p&gt;</description>
      <content:encoded>&lt;h3&gt;CVE-2026-88772&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Status:&lt;/strong&gt; Confirmed&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Exploited:&lt;/strong&gt; Yes&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Status Updated:&lt;/strong&gt; 2026-09-27 02:00 UTC&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Evidence Sources:&lt;/strong&gt; 1&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;First Seen:&lt;/strong&gt; 2026-09-27&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Asserted:&lt;/strong&gt; 2026-09-27&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Scope Notes:&lt;/strong&gt; Affected: Citrix / NetScaler ADC, NetScaler Gateway | Description: Memory overflow vulnerability leading to Remote Code Execution or Denial of Service | Exploitation type: unknown | CWEs: CWE-119 | Origin source: CNW | Notes: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/known-exploited-vulnerabilities-catalog/cb0024fd-2cdc-4806-8090-a4669d70b476</guid>
      <pubDate>Sun, 27 Sep 2026 02:00:00 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-88771 - Confirmed Exploitation</title>
      <link>https://cve.radiocsirt.org/vuln/CVE-2026-88771</link>
      <description>&lt;h3&gt;CVE-2026-88771&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Status:&lt;/strong&gt; Confirmed&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Exploited:&lt;/strong&gt; Yes&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Status Updated:&lt;/strong&gt; 2026-09-27 02:00 UTC&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Evidence Sources:&lt;/strong&gt; 1&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;First Seen:&lt;/strong&gt; 2026-09-27&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Asserted:&lt;/strong&gt; 2026-09-27&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Scope Notes:&lt;/strong&gt; Affected: Citrix / NetScaler ADC, NetScaler Gateway | Description: A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands | Exploitation type: unknown | CWEs: CWE-20 | Origin source: CNW | Notes: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096&lt;/p&gt;</description>
      <content:encoded>&lt;h3&gt;CVE-2026-88771&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Status:&lt;/strong&gt; Confirmed&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Exploited:&lt;/strong&gt; Yes&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Status Updated:&lt;/strong&gt; 2026-09-27 02:00 UTC&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Evidence Sources:&lt;/strong&gt; 1&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;First Seen:&lt;/strong&gt; 2026-09-27&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Asserted:&lt;/strong&gt; 2026-09-27&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Scope Notes:&lt;/strong&gt; Affected: Citrix / NetScaler ADC, NetScaler Gateway | Description: A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands | Exploitation type: unknown | CWEs: CWE-20 | Origin source: CNW | Notes: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/known-exploited-vulnerabilities-catalog/dd665681-edea-4c21-bf97-025125d55fae</guid>
      <pubDate>Sun, 27 Sep 2026 02:00:00 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-65660 - Confirmed Exploitation</title>
      <link>https://cve.radiocsirt.org/vuln/CVE-2026-65660</link>
      <description>&lt;h3&gt;CVE-2026-65660&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Status:&lt;/strong&gt; Confirmed&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Exploited:&lt;/strong&gt; Yes&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Status Updated:&lt;/strong&gt; 2026-09-25 02:00 UTC&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Evidence Sources:&lt;/strong&gt; 1&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;First Seen:&lt;/strong&gt; 2026-09-25&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Asserted:&lt;/strong&gt; 2026-09-25&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Scope Notes:&lt;/strong&gt; Affected: Microsoft / Microsoft SharePoint Server 2019, Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server Subscription Edition | Description: Improper control of generation of code (&amp;#39;code injection&amp;#39;) in Microsoft Office SharePoint allows an authorized attacker to execute code over a user network | Exploitation type: unknown | CWEs: CWE-94 | Origin source: CSIRT-IE | Notes: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65660&lt;/p&gt;</description>
      <content:encoded>&lt;h3&gt;CVE-2026-65660&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Status:&lt;/strong&gt; Confirmed&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Exploited:&lt;/strong&gt; Yes&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Status Updated:&lt;/strong&gt; 2026-09-25 02:00 UTC&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Evidence Sources:&lt;/strong&gt; 1&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;First Seen:&lt;/strong&gt; 2026-09-25&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Asserted:&lt;/strong&gt; 2026-09-25&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Scope Notes:&lt;/strong&gt; Affected: Microsoft / Microsoft SharePoint Server 2019, Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server Subscription Edition | Description: Improper control of generation of code (&amp;#39;code injection&amp;#39;) in Microsoft Office SharePoint allows an authorized attacker to execute code over a user network | Exploitation type: unknown | CWEs: CWE-94 | Origin source: CSIRT-IE | Notes: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65660&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/known-exploited-vulnerabilities-catalog/ac91c0b7-abc5-4664-a4e6-00265df35960</guid>
      <pubDate>Fri, 25 Sep 2026 02:00:00 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-87902 - Confirmed Exploitation</title>
      <link>https://cve.radiocsirt.org/vuln/CVE-2026-87902</link>
      <description>&lt;h3&gt;CVE-2026-87902&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Status:&lt;/strong&gt; Confirmed&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Exploited:&lt;/strong&gt; Yes&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Status Updated:&lt;/strong&gt; 2026-09-23 02:00 UTC&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Evidence Sources:&lt;/strong&gt; 1&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;First Seen:&lt;/strong&gt; 2026-09-23&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Asserted:&lt;/strong&gt; 2026-09-23&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Scope Notes:&lt;/strong&gt; Affected: WordPress Foundation / WordPress | Description: The vulnerabilitycan be exploited by an attacker without login credentials to have a special file loaded outside the normal themes of WordPress. Active abuse has been observed. | Patched since: 2026/09/22 | Exploitation type: unknown | CWEs: CWE-98 | Origin source: NCSC-NL | Notes: https://www.ncsc.nl/alerts/kwetsbaarheid-in-wordpress-wordt-actief-misbruikt-update-nu&lt;/p&gt;</description>
      <content:encoded>&lt;h3&gt;CVE-2026-87902&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Status:&lt;/strong&gt; Confirmed&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Exploited:&lt;/strong&gt; Yes&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Status Updated:&lt;/strong&gt; 2026-09-23 02:00 UTC&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Evidence Sources:&lt;/strong&gt; 1&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;First Seen:&lt;/strong&gt; 2026-09-23&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Asserted:&lt;/strong&gt; 2026-09-23&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Scope Notes:&lt;/strong&gt; Affected: WordPress Foundation / WordPress | Description: The vulnerabilitycan be exploited by an attacker without login credentials to have a special file loaded outside the normal themes of WordPress. Active abuse has been observed. | Patched since: 2026/09/22 | Exploitation type: unknown | CWEs: CWE-98 | Origin source: NCSC-NL | Notes: https://www.ncsc.nl/alerts/kwetsbaarheid-in-wordpress-wordt-actief-misbruikt-update-nu&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/known-exploited-vulnerabilities-catalog/b6fa4f50-8947-4fb1-bf3d-7687796314e4</guid>
      <pubDate>Wed, 23 Sep 2026 02:00:00 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-93952 - Confirmed Exploitation</title>
      <link>https://cve.radiocsirt.org/vuln/CVE-2026-93952</link>
      <description>&lt;h3&gt;CVE-2026-93952&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Status:&lt;/strong&gt; Confirmed&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Exploited:&lt;/strong&gt; Yes&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Status Updated:&lt;/strong&gt; 2026-09-22 02:00 UTC&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Evidence Sources:&lt;/strong&gt; 1&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;First Seen:&lt;/strong&gt; 2026-09-22&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Asserted:&lt;/strong&gt; 2026-09-22&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Scope Notes:&lt;/strong&gt; Affected: Arista Networks / VeloCloud Orchestrator (VCO) On-Prem | Description: A security issue that may allow a remote attacker to access privileged internal functionality and impact the VCO host. | Exploitation type: unknown | CWEs: CWE-20 | Origin source: CSIRT-IE | Notes: https://www.arista.com/en/support/advisories-notices/security-advisory/24765-security-advisory-0183&lt;/p&gt;</description>
      <content:encoded>&lt;h3&gt;CVE-2026-93952&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Status:&lt;/strong&gt; Confirmed&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Exploited:&lt;/strong&gt; Yes&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Status Updated:&lt;/strong&gt; 2026-09-22 02:00 UTC&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Evidence Sources:&lt;/strong&gt; 1&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;First Seen:&lt;/strong&gt; 2026-09-22&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Asserted:&lt;/strong&gt; 2026-09-22&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Scope Notes:&lt;/strong&gt; Affected: Arista Networks / VeloCloud Orchestrator (VCO) On-Prem | Description: A security issue that may allow a remote attacker to access privileged internal functionality and impact the VCO host. | Exploitation type: unknown | CWEs: CWE-20 | Origin source: CSIRT-IE | Notes: https://www.arista.com/en/support/advisories-notices/security-advisory/24765-security-advisory-0183&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/known-exploited-vulnerabilities-catalog/1c057ea5-2fa3-498c-8789-dd03dbab856a</guid>
      <pubDate>Tue, 22 Sep 2026 02:00:00 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-93616 - Confirmed Exploitation</title>
      <link>https://cve.radiocsirt.org/vuln/CVE-2026-93616</link>
      <description>&lt;h3&gt;CVE-2026-93616&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Status:&lt;/strong&gt; Confirmed&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Exploited:&lt;/strong&gt; Yes&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Status Updated:&lt;/strong&gt; 2026-09-22 02:00 UTC&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Evidence Sources:&lt;/strong&gt; 1&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;First Seen:&lt;/strong&gt; 2026-09-22&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Asserted:&lt;/strong&gt; 2026-09-22&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Scope Notes:&lt;/strong&gt; Affected: checkpoint / Quantum Security Gateway | Description: A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server. | Patched since: 2026/09/09 | Exploitation type: unknown | CWEs: CWE-22 | Origin source: ENISA | Notes: https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-cve-2026-85102-and-a-management-pre-authentication-vulnerability-cve-2026-93616/&lt;/p&gt;</description>
      <content:encoded>&lt;h3&gt;CVE-2026-93616&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Status:&lt;/strong&gt; Confirmed&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Exploited:&lt;/strong&gt; Yes&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Status Updated:&lt;/strong&gt; 2026-09-22 02:00 UTC&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Evidence Sources:&lt;/strong&gt; 1&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;First Seen:&lt;/strong&gt; 2026-09-22&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Asserted:&lt;/strong&gt; 2026-09-22&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Scope Notes:&lt;/strong&gt; Affected: checkpoint / Quantum Security Gateway | Description: A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server. | Patched since: 2026/09/09 | Exploitation type: unknown | CWEs: CWE-22 | Origin source: ENISA | Notes: https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-cve-2026-85102-and-a-management-pre-authentication-vulnerability-cve-2026-93616/&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/known-exploited-vulnerabilities-catalog/28be858e-4226-490e-ba48-d8d3884fe8a2</guid>
      <pubDate>Tue, 22 Sep 2026 02:00:00 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-94127 - Confirmed Exploitation</title>
      <link>https://cve.radiocsirt.org/vuln/CVE-2026-94127</link>
      <description>&lt;h3&gt;CVE-2026-94127&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Status:&lt;/strong&gt; Confirmed&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Exploited:&lt;/strong&gt; Yes&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Status Updated:&lt;/strong&gt; 2026-09-22 02:00 UTC&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Evidence Sources:&lt;/strong&gt; 1&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;First Seen:&lt;/strong&gt; 2026-09-22&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Asserted:&lt;/strong&gt; 2026-09-22&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Scope Notes:&lt;/strong&gt; Affected: F5 / BIG-IP | Description: Unauthenticated RCE vulnerability present when BIG-IP APM is configured as an OAuth Authorization Server. | Exploitation type: unknown | CWEs: CWE-122 | Origin source: ENISA | Notes: https://my.f5.com/manage/s/article/K000162605&lt;/p&gt;</description>
      <content:encoded>&lt;h3&gt;CVE-2026-94127&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Status:&lt;/strong&gt; Confirmed&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Exploited:&lt;/strong&gt; Yes&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Status Updated:&lt;/strong&gt; 2026-09-22 02:00 UTC&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Evidence Sources:&lt;/strong&gt; 1&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;First Seen:&lt;/strong&gt; 2026-09-22&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Asserted:&lt;/strong&gt; 2026-09-22&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Scope Notes:&lt;/strong&gt; Affected: F5 / BIG-IP | Description: Unauthenticated RCE vulnerability present when BIG-IP APM is configured as an OAuth Authorization Server. | Exploitation type: unknown | CWEs: CWE-122 | Origin source: ENISA | Notes: https://my.f5.com/manage/s/article/K000162605&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/known-exploited-vulnerabilities-catalog/6c303b5c-9687-4e8d-a3bb-6fed70fc3721</guid>
      <pubDate>Tue, 22 Sep 2026 02:00:00 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-85102 - Confirmed Exploitation</title>
      <link>https://cve.radiocsirt.org/vuln/CVE-2026-85102</link>
      <description>&lt;h3&gt;CVE-2026-85102&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Status:&lt;/strong&gt; Confirmed&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Exploited:&lt;/strong&gt; Yes&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Status Updated:&lt;/strong&gt; 2026-09-22 02:00 UTC&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Evidence Sources:&lt;/strong&gt; 1&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;First Seen:&lt;/strong&gt; 2026-09-22&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Asserted:&lt;/strong&gt; 2026-09-22&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Scope Notes:&lt;/strong&gt; Affected: checkpoint / Quantum Security Gateway | Description: Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway. | Patched since: 2026/09/09 | Exploitation type: unknown | CWEs: CWE-295 | Origin source: ENISA | Notes: https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-cve-2026-85102-and-a-management-pre-authentication-vulnerability-cve-2026-93616/&lt;/p&gt;</description>
      <content:encoded>&lt;h3&gt;CVE-2026-85102&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Status:&lt;/strong&gt; Confirmed&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Exploited:&lt;/strong&gt; Yes&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Status Updated:&lt;/strong&gt; 2026-09-22 02:00 UTC&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Evidence Sources:&lt;/strong&gt; 1&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;First Seen:&lt;/strong&gt; 2026-09-22&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Asserted:&lt;/strong&gt; 2026-09-22&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Scope Notes:&lt;/strong&gt; Affected: checkpoint / Quantum Security Gateway | Description: Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway. | Patched since: 2026/09/09 | Exploitation type: unknown | CWEs: CWE-295 | Origin source: ENISA | Notes: https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-cve-2026-85102-and-a-management-pre-authentication-vulnerability-cve-2026-93616/&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/known-exploited-vulnerabilities-catalog/f60f28a6-3acb-4d13-a059-750ef042b0de</guid>
      <pubDate>Tue, 22 Sep 2026 02:00:00 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-60137 - Confirmed Exploitation</title>
      <link>https://cve.radiocsirt.org/vuln/CVE-2026-60137</link>
      <description>&lt;h3&gt;CVE-2026-60137&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Status:&lt;/strong&gt; Confirmed&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Exploited:&lt;/strong&gt; Yes&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Status Updated:&lt;/strong&gt; 2026-09-21 02:00 UTC&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Evidence Sources:&lt;/strong&gt; 1&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;First Seen:&lt;/strong&gt; 2026-09-21&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Asserted:&lt;/strong&gt; 2026-09-21&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Scope Notes:&lt;/strong&gt; Affected: WordPress Foundation / WordPress | Description: WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter. EU victimology. | Patched since: 2026/07/17 | Exploitation type: unknown | CWEs: CWE-89 | Origin source: ENISA | Notes: https://www.greynoise.io/blog/open-season-on-kapibala-attacker-steals-government-records-wordpress-exploitation#:~:text=GreyNoise%20discovered%20the%20MCA%20targeted%20ZyXEL%20GS1900%20Smart%20Managed%20Switches%20globally, https://www.wiz.io/blog/wp2shell-cve-2026-63030-cve-2026-60137&lt;/p&gt;</description>
      <content:encoded>&lt;h3&gt;CVE-2026-60137&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Status:&lt;/strong&gt; Confirmed&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Exploited:&lt;/strong&gt; Yes&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Status Updated:&lt;/strong&gt; 2026-09-21 02:00 UTC&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Evidence Sources:&lt;/strong&gt; 1&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;First Seen:&lt;/strong&gt; 2026-09-21&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Asserted:&lt;/strong&gt; 2026-09-21&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Scope Notes:&lt;/strong&gt; Affected: WordPress Foundation / WordPress | Description: WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter. EU victimology. | Patched since: 2026/07/17 | Exploitation type: unknown | CWEs: CWE-89 | Origin source: ENISA | Notes: https://www.greynoise.io/blog/open-season-on-kapibala-attacker-steals-government-records-wordpress-exploitation#:~:text=GreyNoise%20discovered%20the%20MCA%20targeted%20ZyXEL%20GS1900%20Smart%20Managed%20Switches%20globally, https://www.wiz.io/blog/wp2shell-cve-2026-63030-cve-2026-60137&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/known-exploited-vulnerabilities-catalog/c489a8e2-366c-439b-9534-23f7849c1324</guid>
      <pubDate>Mon, 21 Sep 2026 02:00:00 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-63030 - Confirmed Exploitation</title>
      <link>https://cve.radiocsirt.org/vuln/CVE-2026-63030</link>
      <description>&lt;h3&gt;CVE-2026-63030&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Status:&lt;/strong&gt; Confirmed&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Exploited:&lt;/strong&gt; Yes&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Status Updated:&lt;/strong&gt; 2026-09-21 02:00 UTC&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Evidence Sources:&lt;/strong&gt; 1&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;First Seen:&lt;/strong&gt; 2026-09-21&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Asserted:&lt;/strong&gt; 2026-09-21&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Scope Notes:&lt;/strong&gt; Affected: WordPress Foundation / WordPress | Description: WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution. EU victimology. | Patched since: 2026/07/17 | Exploitation type: unknown | CWEs: CWE-436 | Origin source: ENISA | Notes: https://www.greynoise.io/blog/open-season-on-kapibala-attacker-steals-government-records-wordpress-exploitation#:~:text=GreyNoise%20discovered%20the%20MCA%20targeted%20ZyXEL%20GS1900%20Smart%20Managed%20Switches%20globally, https://www.wiz.io/blog/wp2shell-cve-2026-63030-cve-2026-60137&lt;/p&gt;</description>
      <content:encoded>&lt;h3&gt;CVE-2026-63030&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Status:&lt;/strong&gt; Confirmed&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Exploited:&lt;/strong&gt; Yes&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Status Updated:&lt;/strong&gt; 2026-09-21 02:00 UTC&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Evidence Sources:&lt;/strong&gt; 1&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;First Seen:&lt;/strong&gt; 2026-09-21&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Asserted:&lt;/strong&gt; 2026-09-21&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Scope Notes:&lt;/strong&gt; Affected: WordPress Foundation / WordPress | Description: WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution. EU victimology. | Patched since: 2026/07/17 | Exploitation type: unknown | CWEs: CWE-436 | Origin source: ENISA | Notes: https://www.greynoise.io/blog/open-season-on-kapibala-attacker-steals-government-records-wordpress-exploitation#:~:text=GreyNoise%20discovered%20the%20MCA%20targeted%20ZyXEL%20GS1900%20Smart%20Managed%20Switches%20globally, https://www.wiz.io/blog/wp2shell-cve-2026-63030-cve-2026-60137&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/known-exploited-vulnerabilities-catalog/deeb0060-da4b-4174-8c7f-e6e0c780c90b</guid>
      <pubDate>Mon, 21 Sep 2026 02:00:00 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-20079 - Confirmed Exploitation</title>
      <link>https://cve.radiocsirt.org/vuln/CVE-2026-20079</link>
      <description>&lt;h3&gt;CVE-2026-20079&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Status:&lt;/strong&gt; Confirmed&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Exploited:&lt;/strong&gt; Yes&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Status Updated:&lt;/strong&gt; 2026-09-09 02:00 UTC&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Evidence Sources:&lt;/strong&gt; 1&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;First Seen:&lt;/strong&gt; 2026-09-09&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Asserted:&lt;/strong&gt; 2026-09-09&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Scope Notes:&lt;/strong&gt; Affected: Cisco / Cisco Secure Firewall Management Center (FMC) | Description: Vulnerability in the web interface could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. EU victimology was confirmed. Comprehensive hardening scheduled (Week of September 14th) | Patched since: 2026/08/05 | Exploitation type: ransomware | CWEs: CWE-288 | Origin source: ENISA | Notes: https://blog.talosintelligence.com/fmc-ongoing-exploitation/&lt;/p&gt;</description>
      <content:encoded>&lt;h3&gt;CVE-2026-20079&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Status:&lt;/strong&gt; Confirmed&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Exploited:&lt;/strong&gt; Yes&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Status Updated:&lt;/strong&gt; 2026-09-09 02:00 UTC&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Evidence Sources:&lt;/strong&gt; 1&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;First Seen:&lt;/strong&gt; 2026-09-09&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Asserted:&lt;/strong&gt; 2026-09-09&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Scope Notes:&lt;/strong&gt; Affected: Cisco / Cisco Secure Firewall Management Center (FMC) | Description: Vulnerability in the web interface could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. EU victimology was confirmed. Comprehensive hardening scheduled (Week of September 14th) | Patched since: 2026/08/05 | Exploitation type: ransomware | CWEs: CWE-288 | Origin source: ENISA | Notes: https://blog.talosintelligence.com/fmc-ongoing-exploitation/&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/known-exploited-vulnerabilities-catalog/4e9ffd58-44ea-4b18-bc85-18c18ffccc66</guid>
      <pubDate>Wed, 09 Sep 2026 02:00:00 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-20316 - Confirmed Exploitation</title>
      <link>https://cve.radiocsirt.org/vuln/CVE-2026-20316</link>
      <description>&lt;h3&gt;CVE-2026-20316&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Status:&lt;/strong&gt; Confirmed&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Exploited:&lt;/strong&gt; Yes&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Status Updated:&lt;/strong&gt; 2026-09-09 02:00 UTC&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Evidence Sources:&lt;/strong&gt; 1&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;First Seen:&lt;/strong&gt; 2026-09-09&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Asserted:&lt;/strong&gt; 2026-09-09&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Scope Notes:&lt;/strong&gt; Affected: Cisco / Cisco Secure Firewall Management Center (FMC) | Description: Vulnerability in the web interface could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. EU victimology was confirmed. Comprehensive hardening scheduled (Week of September 14th). | Patched since: 2026/08/05 | Exploitation type: ransomware | CWEs: CWE-259 | Origin source: ENISA | Notes: https://blog.talosintelligence.com/fmc-ongoing-exploitation/&lt;/p&gt;</description>
      <content:encoded>&lt;h3&gt;CVE-2026-20316&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Status:&lt;/strong&gt; Confirmed&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Exploited:&lt;/strong&gt; Yes&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Status Updated:&lt;/strong&gt; 2026-09-09 02:00 UTC&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Evidence Sources:&lt;/strong&gt; 1&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;First Seen:&lt;/strong&gt; 2026-09-09&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Asserted:&lt;/strong&gt; 2026-09-09&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Scope Notes:&lt;/strong&gt; Affected: Cisco / Cisco Secure Firewall Management Center (FMC) | Description: Vulnerability in the web interface could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. EU victimology was confirmed. Comprehensive hardening scheduled (Week of September 14th). | Patched since: 2026/08/05 | Exploitation type: ransomware | CWEs: CWE-259 | Origin source: ENISA | Notes: https://blog.talosintelligence.com/fmc-ongoing-exploitation/&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/known-exploited-vulnerabilities-catalog/845724eb-e774-4318-a9ff-2084a84c5946</guid>
      <pubDate>Wed, 09 Sep 2026 02:00:00 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-67277 - Confirmed Exploitation</title>
      <link>https://cve.radiocsirt.org/vuln/CVE-2026-67277</link>
      <description>&lt;h3&gt;CVE-2026-67277&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Status:&lt;/strong&gt; Confirmed&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Exploited:&lt;/strong&gt; Yes&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Status Updated:&lt;/strong&gt; 2026-09-05 02:00 UTC&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Evidence Sources:&lt;/strong&gt; 1&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;First Seen:&lt;/strong&gt; 2026-09-05&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Asserted:&lt;/strong&gt; 2026-09-05&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Scope Notes:&lt;/strong&gt; MikroTrick | Affected: MikroTik / RouterOS | Description: RouterOS accepts a &amp;#39;related&amp;#39; btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With &amp;#39;random-data=false&amp;#39;, the sender transmits an uninitialized tail from a kernel packet buffer. A separate unchecked, inverted packet-size interval causes unsigned integer underflow, anomalously large fragmented output, and can restart the RouterOS kernel. This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable) | Patched since: 2026/09/03 | Exploitation type: unknown | CWEs: CWE-306 | Origin source: CERT.PL | Notes: https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/&lt;/p&gt;</description>
      <content:encoded>&lt;h3&gt;CVE-2026-67277&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Status:&lt;/strong&gt; Confirmed&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Exploited:&lt;/strong&gt; Yes&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Status Updated:&lt;/strong&gt; 2026-09-05 02:00 UTC&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Evidence Sources:&lt;/strong&gt; 1&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;First Seen:&lt;/strong&gt; 2026-09-05&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Asserted:&lt;/strong&gt; 2026-09-05&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Scope Notes:&lt;/strong&gt; MikroTrick | Affected: MikroTik / RouterOS | Description: RouterOS accepts a &amp;#39;related&amp;#39; btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With &amp;#39;random-data=false&amp;#39;, the sender transmits an uninitialized tail from a kernel packet buffer. A separate unchecked, inverted packet-size interval causes unsigned integer underflow, anomalously large fragmented output, and can restart the RouterOS kernel. This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable) | Patched since: 2026/09/03 | Exploitation type: unknown | CWEs: CWE-306 | Origin source: CERT.PL | Notes: https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/known-exploited-vulnerabilities-catalog/29fcc6c6-4dd2-4a00-b26d-63ead3b47cf8</guid>
      <pubDate>Sat, 05 Sep 2026 02:00:00 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-86060 - Confirmed Exploitation</title>
      <link>https://cve.radiocsirt.org/vuln/CVE-2026-86060</link>
      <description>&lt;h3&gt;CVE-2026-86060&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Status:&lt;/strong&gt; Confirmed&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Exploited:&lt;/strong&gt; Yes&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Status Updated:&lt;/strong&gt; 2026-09-05 02:00 UTC&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Evidence Sources:&lt;/strong&gt; 1&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;First Seen:&lt;/strong&gt; 2026-09-05&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Asserted:&lt;/strong&gt; 2026-09-05&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Scope Notes:&lt;/strong&gt; MikroTrick | Affected: MikroTik / RouterOS | Description: RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable) | Patched since: 2026/09/03 | Exploitation type: unknown | CWEs: CWE-88 | Origin source: CERT.PL | Notes: https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/&lt;/p&gt;</description>
      <content:encoded>&lt;h3&gt;CVE-2026-86060&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Status:&lt;/strong&gt; Confirmed&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Exploited:&lt;/strong&gt; Yes&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Status Updated:&lt;/strong&gt; 2026-09-05 02:00 UTC&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Evidence Sources:&lt;/strong&gt; 1&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;First Seen:&lt;/strong&gt; 2026-09-05&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Asserted:&lt;/strong&gt; 2026-09-05&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Scope Notes:&lt;/strong&gt; MikroTrick | Affected: MikroTik / RouterOS | Description: RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable) | Patched since: 2026/09/03 | Exploitation type: unknown | CWEs: CWE-88 | Origin source: CERT.PL | Notes: https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/known-exploited-vulnerabilities-catalog/9e9a2427-13ee-42cf-9088-254bd7a706d1</guid>
      <pubDate>Sat, 05 Sep 2026 02:00:00 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-67276 - Confirmed Exploitation</title>
      <link>https://cve.radiocsirt.org/vuln/CVE-2026-67276</link>
      <description>&lt;h3&gt;CVE-2026-67276&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Status:&lt;/strong&gt; Confirmed&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Exploited:&lt;/strong&gt; Yes&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Status Updated:&lt;/strong&gt; 2026-09-05 02:00 UTC&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Evidence Sources:&lt;/strong&gt; 1&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;First Seen:&lt;/strong&gt; 2026-09-05&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Asserted:&lt;/strong&gt; 2026-09-05&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Scope Notes:&lt;/strong&gt; MikroTrick | Affected: MikroTik / RouterOS | Description: RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent. Because signature verification uses the client-supplied key, an attacker knowing an authorized RSA modulus can supply a key with exponent one, forge a valid signature, and open an SSH command channel as the target user without the private key.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable) | Patched since: 2026/09/03 | Exploitation type: unknown | CWEs: CWE-347 | Origin source: CERT.PL | Notes: https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/&lt;/p&gt;</description>
      <content:encoded>&lt;h3&gt;CVE-2026-67276&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Status:&lt;/strong&gt; Confirmed&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Exploited:&lt;/strong&gt; Yes&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Status Updated:&lt;/strong&gt; 2026-09-05 02:00 UTC&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Evidence Sources:&lt;/strong&gt; 1&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;First Seen:&lt;/strong&gt; 2026-09-05&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Asserted:&lt;/strong&gt; 2026-09-05&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Scope Notes:&lt;/strong&gt; MikroTrick | Affected: MikroTik / RouterOS | Description: RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent. Because signature verification uses the client-supplied key, an attacker knowing an authorized RSA modulus can supply a key with exponent one, forge a valid signature, and open an SSH command channel as the target user without the private key.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable) | Patched since: 2026/09/03 | Exploitation type: unknown | CWEs: CWE-347 | Origin source: CERT.PL | Notes: https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/known-exploited-vulnerabilities-catalog/ab4d1a9e-aa4a-42c5-9747-5978a66b4a1f</guid>
      <pubDate>Sat, 05 Sep 2026 02:00:00 +0000</pubDate>
    </item>
  </channel>
</rss>
