Software flaws under active attack
Watch19 actively exploited flaws added in the last 14 days, including products from MSFT, ADBE, FFIV, GOOGL, CSCO.
CISA, the US cyber-defence agency, lists flaws it has evidence attackers are already exploiting and orders federal agencies to patch them. A flaw in a widely used product means emergency patching for its customers and scrutiny for the vendor; this is also the threat security-software companies sell protection against.
- Microsoft SharePointMSFTCVE-2026-65660 · added 2026-09-25
- Adobe Commerce and Magento ADBECVE-2026-71362 · added 2026-09-24
- F5 BIG-IP APMFFIVCVE-2026-94127 · added 2026-09-22
- Google PixelGOOGLCVE-2026-58704 · added 2026-09-16
- Cisco Identity Services EngineCSCOCVE-2026-76460 · added 2026-09-16
- Cisco Secure Email GatewayCSCOCVE-2026-76461 · added 2026-09-14
- Citrix NetScalerCVE-2026-88772 · added 2026-09-27
- Citrix NetScalerCVE-2026-88771 · added 2026-09-27
- MikroTik RouterOSCVE-2026-67279 · added 2026-09-25
- WordPress CoreCVE-2026-87902 · added 2026-09-25
- WSO2 Multiple ProductsCVE-2026-5430 · added 2026-09-24
- Arista VeloCloud OrchestratorCVE-2026-93952 · added 2026-09-22
CISA Known Exploited Vulnerabilities catalog · checked 22:46 UTC · delay same day