Independent reporting and reviews on artificial intelligence, software, hardware, security, and the companies building them.
CVEs named in our security coverage, matched against CISA's catalog of flaws known to be exploited in the wild.
| CVE | Vendor / product | Exploited | Our coverage |
|---|---|---|---|
| CVE-2026-76460 | Cisco Identity Services EngineCisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability | Known exploited | |
| CVE-2026-87886 | Acronis BackupAcronis Backup Incorrect Default Permissions Vulnerability | Known exploited | |
| CVE-2026-58704 | Google PixelGoogle Pixel Improper Authorization Vulnerability | Known exploited | |
| CVE-2026-76461 | Cisco Secure Email GatewayCisco Secure Email Gateway SQL Injection Vulnerability | Known exploited | |
| CVE-2025-25249 | Fortinet Multiple ProductsFortinet Multiple Products Heap-based Buffer Overflow Vulnerability | Known exploited | |
| CVE-2026-87491 | Google Chromium V8Google Chromium V8 Out of Bounds Write Vulnerability | Known exploited | |
| CVE-2026-85706 | GitLab Community Edition and Enterprise EditionGitLab Community Edition and Enterprise Edition Path Traversal Vulnerability | Known exploited | |
| CVE-2026-19490 | Citrix NetScalerCitrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability | Known exploited | |
| CVE-2026-18577 | N-able N-centralN-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability | Known exploited | |
| CVE-2026-86218 | N-able N-centralN-able N-central Static Code Injection Vulnerability | Known exploited | |
| CVE-2026-84869 | ConnectWise ScreenConnectConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability | Known exploited | |
| CVE-2026-82329 | JFrog ArtifactoryJFrog Artifactory Improper Authentication Vulnerability | Known exploited | |
| CVE-2026-42016 | JFrog ArtifactoryJFrog Artifactory Incorrect Authorization Vulnerability | Known exploited | |
| CVE-2026-42018 | JFrog ArtifactoryJFrog Artifactory Improper Authentication Vulnerability | Known exploited | |
| CVE-2026-20079 | Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementCisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability | Known exploited | |
| CVE-2026-20316 | Cisco Secure Firewall Management Center (FMC)Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability | Known exploitedRansomware | |
| CVE-2026-67277 | MikroTik RouterOSMikroTik RouterOS Missing Authentication for Critical Function Vulnerability | Known exploited | |
| CVE-2026-86060 | MikroTik RouterOSMikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability | Known exploited | |
| CVE-2026-11645 | Google Chromium V8Google Chromium V8 Out-of-Bounds Read and Write Vulnerability | Known exploited | |
| CVE-2026-2441 | Google ChromiumGoogle Chromium CSS Use-After-Free Vulnerability | Known exploited | |
| CVE-2026-3909 | Google SkiaGoogle Skia Out-of-Bounds Write Vulnerability | Known exploited | |
| CVE-2026-3910 | Google Chromium V8Google Chromium V8 Improper Restriction of Operations Within the Bounds of a Memory Buffer Vulnerability | Known exploited | |
| CVE-2026-5281 | Google DawnGoogle Dawn Use-After-Free Vulnerability | Known exploited | |
| CVE-2026-85046 | Google Chromium V8Google Chromium V8 Type Confusion Vulnerability | Known exploited | |
| CVE-2026-75650 | Adobe Commerce and MagentoAdobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability | Known exploited | |
| CVE-2026-81963 | Microsoft WindowsMicrosoft Windows Link Following Vulnerability | Known exploited | |
| CVE-2026-85880 | Microsoft WindowsMicrosoft Windows Heap-Based Buffer Overflow Vulnerability | Known exploited | |
| CVE-2026-77960 | — | ||
| CVE-2026-86520 | — | ||
| CVE-2026-86689 | — | ||
| CVE-2026-58113 | — | ||
| CVE-2026-62645 | — | ||
| CVE-2026-62647 | — | ||
| CVE-2026-62648 | — | ||
| CVE-2026-62650 | — | ||
| CVE-2026-62654 | — | ||
| CVE-2026-80465 | — | ||
| CVE-2026-43499 | — | ||
| CVE-2025-70994 | — | ||
| CVE-2026-1354 | — | ||
| CVE-2026-79708 | — | ||
| CVE-2026-86340 | — | ||
| CVE-2026-86341 | — | ||
| CVE-2026-87719 | — | ||
| CVE-2026-88765 | — | ||
| CVE-2026-19489 | — | ||
| CVE-2026-10528 | — | ||
| CVE-2026-5437 | — | ||
| CVE-2026-87020 | — | ||
| CVE-2026-86206 | — |
The newest flaws the U.S. Cybersecurity and Infrastructure Security Agency has confirmed are being exploited, whether or not we have written about them.
| Added | CVE | Vendor / product | Flaw |
|---|---|---|---|
| September 18, 2026 | CVE-2025-39964 | Linux Kernel | Linux Kernel Race Condition Vulnerability |
| September 18, 2026 | CVE-2026-53266 | Linux Kernel | Linux Kernel Out-of-Bounds Write Vulnerability |
| September 16, 2026 | CVE-2026-58704Covered | Google Pixel | Google Pixel Improper Authorization Vulnerability |
| September 16, 2026 | CVE-2026-76460Covered | Cisco Identity Services Engine | Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability |
| September 16, 2026 | CVE-2026-87886Covered | Acronis Backup | Acronis Backup Incorrect Default Permissions Vulnerability |
| September 14, 2026 | CVE-2026-76461Covered | Cisco Secure Email Gateway | Cisco Secure Email Gateway SQL Injection Vulnerability |
| September 11, 2026 | CVE-2026-84869Covered | ConnectWise ScreenConnect | ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability |
| September 11, 2026 | CVE-2026-42016Covered | JFrog Artifactory | JFrog Artifactory Incorrect Authorization Vulnerability |
| September 11, 2026 | CVE-2026-42018Covered | JFrog Artifactory | JFrog Artifactory Improper Authentication Vulnerability |
| September 11, 2026 | CVE-2026-85706Covered | GitLab Community Edition and Enterprise Edition | GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability |
| September 10, 2026 | CVE-2026-86060Covered | MikroTik RouterOS | MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability |
| September 10, 2026 | CVE-2026-67277Covered | MikroTik RouterOS | MikroTik RouterOS Missing Authentication for Critical Function Vulnerability |
| September 9, 2026 | CVE-2026-19490Covered | Citrix NetScaler | Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability |
| September 9, 2026 | CVE-2025-25249Covered | Fortinet Multiple Products | Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability |
| September 9, 2026 | CVE-2026-87491Covered | Google Chromium V8 | Google Chromium V8 Out of Bounds Write Vulnerability |