<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://exploit-radar.com/en/flux/tout.xml</id>
  <title>Exploit Radar: actively exploited vulnerabilities</title>
  <subtitle>The latest additions to CISA’s catalog of exploited vulnerabilities, across all products.</subtitle>
  <link rel="self" type="application/atom+xml" href="https://exploit-radar.com/en/flux/tout.xml"/>
  <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/a-corriger/"/>
  <updated>2026-09-29T00:00:00Z</updated>
  <author><name>Exploit Radar</name></author>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-86950/</id>
    <title>CVE-2026-86950 — Apple iOS / iPadOS / macOS</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-86950/"/>
    <updated>2026-09-29T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Apple; if none are available, stop using the product. Start with internet-facing devices. CISA also asks you to hunt for signs of compromise: patching is not enough if the device has already been breached. CISA deadline: 3 days. Added to CISA’s catalog of exploited vulnerabilities on September 29, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-88771/</id>
    <title>CVE-2026-88771 — Citrix NetScaler ADC / Gateway</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-88771/"/>
    <updated>2026-09-27T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Citrix; if none are available, stop using the product. Start with internet-facing devices. CISA also asks you to hunt for signs of compromise: patching is not enough if the device has already been breached. CISA deadline: 3 days. Active CERT-FR alert. Added to CISA’s catalog of exploited vulnerabilities on September 27, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-88772/</id>
    <title>CVE-2026-88772 — Citrix NetScaler ADC / Gateway</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-88772/"/>
    <updated>2026-09-27T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Citrix; if none are available, stop using the product. Start with internet-facing devices. CISA also asks you to hunt for signs of compromise: patching is not enough if the device has already been breached. CISA deadline: 3 days. Active CERT-FR alert. Added to CISA’s catalog of exploited vulnerabilities on September 27, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-65660/</id>
    <title>CVE-2026-65660 — Microsoft SharePoint Server</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-65660/"/>
    <updated>2026-09-25T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Microsoft; if none are available, stop using the product. Start with internet-facing devices. CISA also asks you to hunt for signs of compromise: patching is not enough if the device has already been breached. CISA deadline: 3 days. Added to CISA’s catalog of exploited vulnerabilities on September 25, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-87902/</id>
    <title>CVE-2026-87902 — WordPress Core</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-87902/"/>
    <updated>2026-09-25T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from WordPress; if none are available, stop using the product. Start with internet-facing devices. CISA also asks you to hunt for signs of compromise: patching is not enough if the device has already been breached. CISA deadline: 3 days. Added to CISA’s catalog of exploited vulnerabilities on September 25, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-67279/</id>
    <title>CVE-2026-67279 — MikroTik RouterOS</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-67279/"/>
    <updated>2026-09-25T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from MikroTik; if none are available, stop using the product. Start with internet-facing devices. CISA deadline: 3 days. Added to CISA’s catalog of exploited vulnerabilities on September 25, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-5430/</id>
    <title>CVE-2026-5430 — WSO2 API Manager, Identity Server, Integrator</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-5430/"/>
    <updated>2026-09-24T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from WSO2; if none are available, stop using the product. Start with internet-facing devices. CISA also asks you to hunt for signs of compromise: patching is not enough if the device has already been breached. CISA deadline: 3 days. Added to CISA’s catalog of exploited vulnerabilities on September 24, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-71362/</id>
    <title>CVE-2026-71362 — Adobe Commerce (Magento)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-71362/"/>
    <updated>2026-09-24T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Adobe; if none are available, stop using the product. Start with internet-facing devices. CISA also asks you to hunt for signs of compromise: patching is not enough if the device has already been breached. CISA deadline: 3 days. Added to CISA’s catalog of exploited vulnerabilities on September 24, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-93952/</id>
    <title>CVE-2026-93952 — Arista SD-WAN (VeloCloud)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-93952/"/>
    <updated>2026-09-22T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Arista; if none are available, stop using the product. Start with internet-facing devices. CISA also asks you to hunt for signs of compromise: patching is not enough if the device has already been breached. CISA deadline: 3 days. Added to CISA’s catalog of exploited vulnerabilities on September 22, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-85102/</id>
    <title>CVE-2026-85102 — Check Point Quantum Security Gateway</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-85102/"/>
    <updated>2026-09-22T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Check Point; if none are available, stop using the product. Start with internet-facing devices. CISA also asks you to hunt for signs of compromise: patching is not enough if the device has already been breached. CISA deadline: 3 days. Added to CISA’s catalog of exploited vulnerabilities on September 22, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-93616/</id>
    <title>CVE-2026-93616 — Check Point Security Management / SmartConsole</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-93616/"/>
    <updated>2026-09-22T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Check Point; if none are available, stop using the product. Start with internet-facing devices. CISA also asks you to hunt for signs of compromise: patching is not enough if the device has already been breached. CISA deadline: 3 days. Added to CISA’s catalog of exploited vulnerabilities on September 22, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-94127/</id>
    <title>CVE-2026-94127 — F5 BIG-IP</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-94127/"/>
    <updated>2026-09-22T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from F5; if none are available, stop using the product. Start with internet-facing devices. CISA also asks you to hunt for signs of compromise: patching is not enough if the device has already been breached. CISA deadline: 3 days. Added to CISA’s catalog of exploited vulnerabilities on September 22, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-7273/</id>
    <title>CVE-2026-7273 — Zyxel Switches (GS, XGS)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-7273/"/>
    <updated>2026-09-21T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Zyxel; if none are available, stop using the product. Start with internet-facing devices. CISA also asks you to hunt for signs of compromise: patching is not enough if the device has already been breached. CISA deadline: 3 days. Added to CISA’s catalog of exploited vulnerabilities on September 21, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2025-39682/</id>
    <title>CVE-2025-39682 — Linux Kernel</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2025-39682/"/>
    <updated>2026-09-18T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Linux; if none are available, stop using the product. Start with internet-facing devices. CISA also asks you to hunt for signs of compromise: patching is not enough if the device has already been breached. CISA deadline: 3 days. Added to CISA’s catalog of exploited vulnerabilities on September 18, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-53266/</id>
    <title>CVE-2026-53266 — Linux Kernel</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-53266/"/>
    <updated>2026-09-18T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Linux; if none are available, stop using the product. Start with internet-facing devices. CISA also asks you to hunt for signs of compromise: patching is not enough if the device has already been breached. CISA deadline: 3 days. Added to CISA’s catalog of exploited vulnerabilities on September 18, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2025-39964/</id>
    <title>CVE-2025-39964 — Linux Kernel</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2025-39964/"/>
    <updated>2026-09-18T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Linux; if none are available, stop using the product. Start with internet-facing devices. CISA also asks you to hunt for signs of compromise: patching is not enough if the device has already been breached. CISA deadline: 3 days. Added to CISA’s catalog of exploited vulnerabilities on September 18, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-76460/</id>
    <title>CVE-2026-76460 — Cisco Identity Services Engine (ISE)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-76460/"/>
    <updated>2026-09-16T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Cisco; if none are available, stop using the product. Start with internet-facing devices. CISA also asks you to hunt for signs of compromise: patching is not enough if the device has already been breached. CISA deadline: 3 days. Added to CISA’s catalog of exploited vulnerabilities on September 16, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-58704/</id>
    <title>CVE-2026-58704 — Google Pixel</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-58704/"/>
    <updated>2026-09-16T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Google; if none are available, stop using the product. Start with internet-facing devices. CISA also asks you to hunt for signs of compromise: patching is not enough if the device has already been breached. CISA deadline: 3 days. Added to CISA’s catalog of exploited vulnerabilities on September 16, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-87886/</id>
    <title>CVE-2026-87886 — Acronis Backup</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-87886/"/>
    <updated>2026-09-16T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Acronis; if none are available, stop using the product. Start with internet-facing devices. CISA also asks you to hunt for signs of compromise: patching is not enough if the device has already been breached. CISA deadline: 3 days. Added to CISA’s catalog of exploited vulnerabilities on September 16, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-76461/</id>
    <title>CVE-2026-76461 — Cisco Secure Email Gateway</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-76461/"/>
    <updated>2026-09-14T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Cisco; if none are available, stop using the product. Start with internet-facing devices. CISA also asks you to hunt for signs of compromise: patching is not enough if the device has already been breached. CISA deadline: 3 days. Added to CISA’s catalog of exploited vulnerabilities on September 14, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-85706/</id>
    <title>CVE-2026-85706 — GitLab Community / Enterprise Edition (CE/EE)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-85706/"/>
    <updated>2026-09-11T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from GitLab; if none are available, stop using the product. Start with internet-facing devices. CISA also asks you to hunt for signs of compromise: patching is not enough if the device has already been breached. CISA deadline: 3 days. Added to CISA’s catalog of exploited vulnerabilities on September 11, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-84869/</id>
    <title>CVE-2026-84869 — ConnectWise ScreenConnect</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-84869/"/>
    <updated>2026-09-11T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from ConnectWise; if none are available, stop using the product. Start with internet-facing devices. CISA also asks you to hunt for signs of compromise: patching is not enough if the device has already been breached. CISA deadline: 3 days. Added to CISA’s catalog of exploited vulnerabilities on September 11, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-42016/</id>
    <title>CVE-2026-42016 — JFrog Artifactory</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-42016/"/>
    <updated>2026-09-11T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from JFrog; if none are available, stop using the product. Start with internet-facing devices. CISA deadline: 14 days. Added to CISA’s catalog of exploited vulnerabilities on September 11, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-42018/</id>
    <title>CVE-2026-42018 — JFrog Artifactory</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-42018/"/>
    <updated>2026-09-11T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from JFrog; if none are available, stop using the product. Start with internet-facing devices. CISA deadline: 14 days. Added to CISA’s catalog of exploited vulnerabilities on September 11, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-86060/</id>
    <title>CVE-2026-86060 — MikroTik RouterOS</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-86060/"/>
    <updated>2026-09-10T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from MikroTik; if none are available, stop using the product. Start with internet-facing devices. CISA also asks you to hunt for signs of compromise: patching is not enough if the device has already been breached. CISA deadline: 3 days. Added to CISA’s catalog of exploited vulnerabilities on September 10, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-67277/</id>
    <title>CVE-2026-67277 — MikroTik RouterOS</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-67277/"/>
    <updated>2026-09-10T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from MikroTik; if none are available, stop using the product. Start with internet-facing devices. CISA deadline: 3 days. Added to CISA’s catalog of exploited vulnerabilities on September 10, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-20079/</id>
    <title>CVE-2026-20079 — Cisco Secure Firewall Management Center (FMC)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-20079/"/>
    <updated>2026-09-09T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Cisco; if none are available, stop using the product. Start with internet-facing devices. CISA also asks you to hunt for signs of compromise: patching is not enough if the device has already been breached. CISA deadline: 3 days. Added to CISA’s catalog of exploited vulnerabilities on September 9, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2025-25249/</id>
    <title>CVE-2025-25249 — Fortinet FortiOS / FortiProxy (FortiGate)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2025-25249/"/>
    <updated>2026-09-09T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Fortinet; if none are available, stop using the product. Start with internet-facing devices. CISA also asks you to hunt for signs of compromise: patching is not enough if the device has already been breached. CISA deadline: 3 days. Added to CISA’s catalog of exploited vulnerabilities on September 9, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-19490/</id>
    <title>CVE-2026-19490 — Citrix NetScaler ADC / Gateway</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-19490/"/>
    <updated>2026-09-09T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Citrix; if none are available, stop using the product. Start with internet-facing devices. CISA also asks you to hunt for signs of compromise: patching is not enough if the device has already been breached. CISA deadline: 3 days. Added to CISA’s catalog of exploited vulnerabilities on September 9, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-87491/</id>
    <title>CVE-2026-87491 — Google Chrome / Chromium</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-87491/"/>
    <updated>2026-09-09T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Google; if none are available, stop using the product. Start with internet-facing devices. CISA deadline: 14 days. Added to CISA’s catalog of exploited vulnerabilities on September 9, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-75650/</id>
    <title>CVE-2026-75650 — Adobe Commerce (Magento)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-75650/"/>
    <updated>2026-09-08T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Adobe; if none are available, stop using the product. Start with internet-facing devices. CISA also asks you to hunt for signs of compromise: patching is not enough if the device has already been breached. CISA deadline: 3 days. Added to CISA’s catalog of exploited vulnerabilities on September 8, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-86218/</id>
    <title>CVE-2026-86218 — N-able N-central</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-86218/"/>
    <updated>2026-09-08T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from N-able; if none are available, stop using the product. Start with internet-facing devices. CISA also asks you to hunt for signs of compromise: patching is not enough if the device has already been breached. CISA deadline: 3 days. Added to CISA’s catalog of exploited vulnerabilities on September 8, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-81963/</id>
    <title>CVE-2026-81963 — Microsoft Windows</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-81963/"/>
    <updated>2026-09-08T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Microsoft; if none are available, stop using the product. Start with internet-facing devices. CISA deadline: 14 days. Added to CISA’s catalog of exploited vulnerabilities on September 8, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-85880/</id>
    <title>CVE-2026-85880 — Microsoft Windows</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-85880/"/>
    <updated>2026-09-08T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Microsoft; if none are available, stop using the product. Start with internet-facing devices. CISA deadline: 14 days. Added to CISA’s catalog of exploited vulnerabilities on September 8, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-85046/</id>
    <title>CVE-2026-85046 — Google Chrome / Chromium</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-85046/"/>
    <updated>2026-09-04T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Google; if none are available, stop using the product. Start with internet-facing devices. CISA deadline: 14 days. Added to CISA’s catalog of exploited vulnerabilities on September 4, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-49869/</id>
    <title>CVE-2026-49869 — Kestra OSS</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-49869/"/>
    <updated>2026-09-02T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Kestra; if none are available, stop using the product. Start with internet-facing devices. CISA also asks you to hunt for signs of compromise: patching is not enough if the device has already been breached. CISA deadline: 3 days. Added to CISA’s catalog of exploited vulnerabilities on September 2, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-83548/</id>
    <title>CVE-2026-83548 — SonicWall SMA 1000</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-83548/"/>
    <updated>2026-09-02T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from SonicWall; if none are available, stop using the product. Start with internet-facing devices. CISA also asks you to hunt for signs of compromise: patching is not enough if the device has already been breached. CISA deadline: 3 days. Active CERT-FR alert. Added to CISA’s catalog of exploited vulnerabilities on September 2, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-82329/</id>
    <title>CVE-2026-82329 — JFrog Artifactory</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-82329/"/>
    <updated>2026-09-02T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from JFrog; if none are available, stop using the product. Start with internet-facing devices. CISA also asks you to hunt for signs of compromise: patching is not enough if the device has already been breached. CISA deadline: 3 days. Added to CISA’s catalog of exploited vulnerabilities on September 2, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-9586/</id>
    <title>CVE-2026-9586 — Sangoma Switchvox</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-9586/"/>
    <updated>2026-09-02T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Sangoma; if none are available, stop using the product. Start with internet-facing devices. CISA also asks you to hunt for signs of compromise: patching is not enough if the device has already been breached. CISA deadline: 3 days. Added to CISA’s catalog of exploited vulnerabilities on September 2, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-59822/</id>
    <title>CVE-2026-59822 — BerriAI LiteLLM</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-59822/"/>
    <updated>2026-09-02T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from BerriAI; if none are available, stop using the product. Start with internet-facing devices. CISA deadline: 14 days. Added to CISA’s catalog of exploited vulnerabilities on September 2, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-83549/</id>
    <title>CVE-2026-83549 — SonicWall SMA 1000</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-83549/"/>
    <updated>2026-09-02T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from SonicWall; if none are available, stop using the product. Start with internet-facing devices. CISA also asks you to hunt for signs of compromise: patching is not enough if the device has already been breached. CISA deadline: 3 days. Active CERT-FR alert. Added to CISA’s catalog of exploited vulnerabilities on September 2, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-48710/</id>
    <title>CVE-2026-48710 — Starlette</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-48710/"/>
    <updated>2026-09-02T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Starlette; if none are available, stop using the product. Start with internet-facing devices. CISA deadline: 14 days. Added to CISA’s catalog of exploited vulnerabilities on September 2, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-81578/</id>
    <title>CVE-2026-81578 — PaperCut NG / MF</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-81578/"/>
    <updated>2026-08-31T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from PaperCut; if none are available, stop using the product. Start with internet-facing devices. CISA deadline: 14 days. Added to CISA’s catalog of exploited vulnerabilities on August 31, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-82078/</id>
    <title>CVE-2026-82078 — PaperCut NG / MF</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-82078/"/>
    <updated>2026-08-31T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from PaperCut; if none are available, stop using the product. Start with internet-facing devices. CISA deadline: 14 days. Added to CISA’s catalog of exploited vulnerabilities on August 31, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2023-49105/</id>
    <title>CVE-2023-49105 — ownCloud Server</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2023-49105/"/>
    <updated>2026-08-27T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from ownCloud; if none are available, stop using the product. Start with internet-facing devices. CISA also asks you to hunt for signs of compromise: patching is not enough if the device has already been breached. CISA deadline: 3 days. Added to CISA’s catalog of exploited vulnerabilities on August 27, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-53362/</id>
    <title>CVE-2026-53362 — Linux Kernel</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-53362/"/>
    <updated>2026-08-27T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Linux; if none are available, stop using the product. Start with internet-facing devices. CISA also asks you to hunt for signs of compromise: patching is not enough if the device has already been breached. CISA deadline: 3 days. Added to CISA’s catalog of exploited vulnerabilities on August 27, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-66384/</id>
    <title>CVE-2026-66384 — JFrog Artifactory</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-66384/"/>
    <updated>2026-08-27T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from JFrog; if none are available, stop using the product. Start with internet-facing devices. CISA deadline: 14 days. Added to CISA’s catalog of exploited vulnerabilities on August 27, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2021-23758/</id>
    <title>CVE-2021-23758 — Ajax.NET Professional</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2021-23758/"/>
    <updated>2026-08-26T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Ajax.NET Professional; if none are available, stop using the product. Start with internet-facing devices. CISA deadline: 14 days. Added to CISA’s catalog of exploited vulnerabilities on August 26, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-8452/</id>
    <title>CVE-2026-8452 — Citrix NetScaler ADC / Gateway</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-8452/"/>
    <updated>2026-08-26T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Citrix; if none are available, stop using the product. Start with internet-facing devices. CISA deadline: 3 days. Added to CISA’s catalog of exploited vulnerabilities on August 26, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2019-1068/</id>
    <title>CVE-2019-1068 — Microsoft SQL Server</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2019-1068/"/>
    <updated>2026-08-26T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Microsoft; if none are available, stop using the product. Start with internet-facing devices. CISA also asks you to hunt for signs of compromise: patching is not enough if the device has already been breached. CISA deadline: 3 days. Added to CISA’s catalog of exploited vulnerabilities on August 26, 2026.</summary>
  </entry>
</feed>
