Latest CVEs & known exploited flaws

We pull recent advisories from the NIST NVD and CISA’s Known Exploited Vulnerabilities catalog, store them locally, and refresh this page regularly — so you can spot risks that matter for websites.

17,896tracked CVEs
1,735known exploited
Freepublic feed

Worried one of these affects your site? Run a free Korisec scan — plain-English results, no signup.

Showing 1–20 of 17,896

high Known exploited

CVE-2026-88779

Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway) contain an improper restriction of operations within the…

NetScaler

high Known exploited

CVE-2026-104286

Fortinet FortiMail Path Traversal Vulnerability

Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated…

FortiMail

high Known exploited

CVE-2026-102490

Zammad GmbH Zammad Improper Privilege Management Vulnerability

Zammad GmbH Zammad contains an improper privilege management vulnerability that can allow the local zammad user to escalate privileges to root. This…

Zammad

high Known exploited

CVE-2026-102489

Zammad GmbH Zammad Session Fixation Vulnerability

Zammad GmbH Zammad contains a session fixation vulnerability that can lead to remote code execution as the zammad user. This vulnerability can be chained with…

Zammad

high Known exploited

CVE-2026-76504

Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability

Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with…

Catalyst SD-WAN Manager

high Known exploited

CVE-2026-86950

Apple Multiple Products Out-of-Bounds Write Vulnerability

Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution.

Multiple Products

high Known exploited

CVE-2026-88772

Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow…

NetScaler

high Known exploited

CVE-2026-88771

Citrix NetScaler Improper Input Validation Vulnerability

Citrix NetScaler ADC and NetScaler Gateway contain an improper input validation vulnerability that could allow an unauthenticated attacker to execute…

NetScaler

high Known exploited

CVE-2026-65660

Microsoft SharePoint Code Injection Vulnerability

Microsoft SharePoint contains a code injection vulnerability which could allow an authorized attacker to execute code over a network.

SharePoint

high Known exploited

CVE-2026-87902

WordPress Core Remote File Inclusion Vulnerability

WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen…

Core

high Known exploited

CVE-2026-93952

Arista VeloCloud Orchestrator Improper Input Validation Vulnerability

Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal…

VeloCloud Orchestrator

high Known exploited

CVE-2026-94127

F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability

F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This…

BIG-IP APM

high Known exploited

CVE-2026-93616

Check Point Multiple Products Path Traversal Vulnerability

Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent contain a path traversal…

Multiple Products

high Known exploited

CVE-2026-85102

Check Point Multiple Products Improper Certificate Validation Vulnerability

Check Point Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN contain an improper certificate validation…

Multiple Products

high Known exploited

CVE-2026-7273

Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability

Zyxel GS1900 series switches contain a stack-based buffer overflow vulnerability in the CGI program which could allow a LAN-based, unauthenticated attacker to…

GS1900 Series Switches

high Known exploited

CVE-2026-53266

Linux Kernel Out-of-Bounds Write Vulnerability

Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly…

Kernel

high Known exploited

CVE-2025-39964

Linux Kernel Race Condition Vulnerability

Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and…

Kernel

high Known exploited

CVE-2025-39682

Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability

Linux Kernel contains an improper check for unusual or exceptional conditions vulnerability in the TLS receive path which allows a zero-length record…

Kernel

high Known exploited

CVE-2026-87886

Acronis Backup Incorrect Default Permissions Vulnerability

Acronis Backup plugin for cPanel & WHM and extension for Plesk contains an incorrect default permissions vulnerability that could allow for privilege…

Backup

high Known exploited

CVE-2026-76460

Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability

Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could…

Identity Services Engine

Sources: NIST NVD and CISA KEV. This tracker is informational — always verify against vendor advisories.