LIVE, READERS

Global Network Activity Map

Real-time global network and scanning activity from open, public data sets. Updated periodically.

Sources: abuse.ch, SANS Internet Storm Center

i Real-time network and scanning activity indicators from open, public data sets. Last update: -

EUROPEAN, ENISA EUVD

European vulnerability database (ENISA EUVD)

ENISA's EU vulnerability database - critical and actively used vulnerabilities from European sources (CIRCL, CERT-EU, etc.) is complemented by the possibility of using EPSS.

Source: ENISA EUVD

CVE
unique Vulnerabilities and Exposure.
CWE
vulnerability type classification: Common Weakness Enumeration.
EPSS
the estimated probability that vulnerability will be used in the next 30 days (Exploit Predication Scoring System).

Critical CVSS 9.0-10.0

Highest severity. Large potential effects - immediate updating is recommended, even without known use.

9.3 CVSS EUVD-2026-76938 Critical

Tonec - Critical vulnerability

CVE-2026-90493 EPSS 0.0%
9.1 CVSS EUVD-2026-76916 Critical

Kalkitech - Critical vulnerability

CVE-2026-90647 EPSS 0.0%
9.3 CVSS EUVD-2026-76903 Critical

irontec - Critical vulnerability

CVE-2026-90558 EPSS 0.0%
9.8 CVSS EUVD-2026-76832 Critical

StellarWP - Critical vulnerability

CVE-2026-78006 EPSS 0.0%
9.8 CVSS EUVD-2026-76833 Critical

StellarWP - Critical vulnerability

CVE-2026-78159 EPSS 0.0%
9.6 CVSS EUVD-2026-76814 Critical

Unknown - Critical vulnerability

CVE-2026-77006 EPSS 0.0%
9.6 CVSS EUVD-2026-76815 Critical

Unknown - Critical vulnerability

CVE-2026-77005 EPSS 0.0%
9.8 CVSS EUVD-2026-76816 Critical

Unknown - Critical vulnerability

CVE-2026-75800 EPSS 19.0%
9.9 CVSS EUVD-2026-76778 Critical

GitLab - Critical vulnerability

CVE-2026-87719 EPSS 0.0%
10.0 CVSS EUVD-2026-76779 Critical √ Assets used

GitLab - Critical vulnerability

CVE-2026-85706 EPSS 100.0%
9.6 CVSS EUVD-2026-42968 Critical

prowler-cloud - Critical vulnerability

CVE-2026-59151 EPSS 32.0%
9.8 CVSS EUVD-2026-76192 Critical

n/a - Critical vulnerability

CVE-2026-79395 EPSS 0.0%
9.8 CVSS EUVD-2026-76197 Critical

themerex - Critical vulnerability

CVE-2026-62105 EPSS 0.0%
9.8 CVSS EUVD-2026-76214 Critical

WPEverest - Critical vulnerability

CVE-2026-62103 EPSS 0.0%
9.3 CVSS EUVD-2026-76130 Critical

WAVLINK Technology - Critical vulnerability

CVE-2026-89010 EPSS 0.0%

Assets used in real environment

Imperfections already used by attackers in real attacks (EUVD marked with date of use). Prevent priority regardless of CVSS.

10.0 CVSS EUVD-2026-76779 Critical √ Assets used

GitLab - Critical vulnerability

CVE-2026-85706 EPSS 100.0%
8.8 CVSS EUVD-2026-74529 High √ Assets used

Google - High risk vulnerability

CVE-2026-87491 EPSS 76.0%
9.9 CVSS EUVD-2026-74053 Critical √ Assets used

ConnectWise - Critical vulnerability

CVE-2026-84869 EPSS 69.0%
7.8 CVSS EUVD-2026-73889 High √ Assets used

Microsoft - High risk vulnerability

CVE-2026-81963 EPSS 0.0%
7.8 CVSS EUVD-2026-73365 High √ Assets used

Microsoft - High risk vulnerability

CVE-2026-85880 EPSS 0.0%
10.0 CVSS EUVD-2026-72530 Critical √ Assets used

Adobe - Critical vulnerability

CVE-2026-75650 EPSS 68.0%
10.0 CVSS EUVD-2026-72041 Critical √ Assets used

N-Able - Critical vulnerability

CVE-2026-86218 EPSS 41.0%
9.2 CVSS EUVD-2026-72029 Critical √ Assets used

MikroTik - Critical vulnerability

CVE-2026-86060 EPSS 100.0%
8.8 CVSS EUVD-2026-72025 High √ Assets used

MikroTik - High risk vulnerability

CVE-2026-67277 EPSS 86.0%
9.2 CVSS EUVD-2026-72024 Critical √ Assets used

MikroTik - Critical vulnerability

CVE-2026-67276 EPSS 24.0%
8.8 CVSS EUVD-2026-70702 High √ Assets used

Google - High risk vulnerability

CVE-2026-85046 EPSS 100.0%
9.3 CVSS EUVD-2026-62395 Critical √ Assets used

NetScaler - Critical vulnerability

CVE-2026-19490 EPSS 100.0%
7.5 CVSS EUVD-2026-57388 High √ Assets used

JFrog - High risk vulnerability

CVE-2026-42018 EPSS 92.0%
5.3 CVSS EUVD-2026-50404 Medium √ Assets used

Cisco - Medium risk vulnerability

CVE-2026-20316 EPSS 100.0%
8.1 CVSS EUVD-2026-49566 High √ Assets used

JFrog - High risk vulnerability

CVE-2026-42016 EPSS 89.0%

i The list shall be updated periodically from the ENISA EUVD. The same CVE can also appear in the list of NSAs below - these are different sources.

PRIORITY, CISA KEV

Priority Anti-Risks (CISA KEV)

Imperfections listed by CISA as a priority in the avoidable catalogue. The federal authorities must eliminate them within a certain timeframe - good practice for others too. Updated periodically.

Source: CISA KEV katalogs

CVE-2026-84869

ConnectWise ScreenConnect - Incorrect management of privileges

Deadline: 2026-09-14
CVE-2026-42016

JFrog Artifictory - Incorrect authorization

Deadline: 2026-09-25
CVE-2026-42018

JFrog Artifictory - Incorrect authentication

Deadline: 2026-09-25
CVE-2026-85706

GitLab Community Edition and Enterprise Edition - Actively used vulnerability

Deadline: 2026-09-14
CVE-2026-86060

MikroTik RouterOS - Actively used vulnerability

Deadline: 2026-09-13
CVE-2026-67277

MikroTik RouterOS - Missing authentication for critical function

Deadline: 2026-09-13
CVE-2026-19490

Citrix NetSclarer - Circulation of authentication along the adjacent road

Deadline: 2026-09-12
CVE-2025-25249

Fortinet Multiple Products - Dynamic memory overflow

Deadline: 2026-09-12
CVE-2026-87491

Google Chromium V8 - Cross border recording in memory

Deadline: 2026-09-23
CVE-2026-20079

Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) - Circulation of authentication along the adjacent road

Deadline: 2026-09-12
CVE-2026-81963

Microsoft Windows - Tracking the link without checking

Deadline: 2026-09-22
CVE-2026-86218

N-able N-central - Actively used vulnerability

Deadline: 2026-09-11
CVE-2026-75650

Adobe Commerce and Magento - Actively used vulnerability

Deadline: 2026-09-11
CVE-2026-85880

Microsoft Windows - Dynamic memory overflow

Deadline: 2026-09-22
CVE-2026-85046

Google Chromium V8 - Tips mismatch in resource handling

Deadline: 2026-09-18
CVE-2026-49869

Kestra Kestra OSS - Injection of operating system commands

Deadline: 2026-09-05
CVE-2026-59822

Berriai LiteLM - Incorrect authentication

Deadline: 2026-09-16
CVE-2026-48710

Kludex Starlette - Inadequate processing of requests

Deadline: 2026-09-16
CVE-2026-82329

JFrog Artifictory - Incorrect authentication

Deadline: 2026-09-05
CVE-2026-9586

Sangoma Switchvox - SQL injection

Deadline: 2026-09-05

i CISA KEV - catalogue of priority avoidable vulnerabilities The spoon in the CVE list below indicates overlap with the latest injuries.

REALLY, CVE

Top 20 latest vulnerabilities

Published CVE vulnerabilities from public sources. The list contains only those that already know the manufacturer or the product - without it the record does not say what is directly vulnerable. Updated periodically.

Source: NVD - National Vulnerability Database (NIST)

6.4 CVSS CVE-2026-19634 Medium

DALIBO PostgreSQL Anonymizer < 3.1.4 - SQL injection

The database query is composed of unverified data that can allow you to read or change the contents of the database.

CWE-89
8.8 CVSS CVE-2026-19633 High

DALIBO PostgreSQL Anonymizer < 3.1.4 - SQL injection

The database query is composed of unverified data that can allow you to read or change the contents of the database.

CWE-89
- CVSS CVE-2026-86283 Waiting for CVSS

MISP ≤ 2.5.45 - New vulnerability

Awaiting assessment of severity.

CWE-285
5.3 CVSS CVE-2026-86217 Medium

code-projects Hotel and Tourism Reservation in PHP 1.0 - Sensitive disclosures

The system shall disclose sensitive information to parties for whom it is not intended.

CWE-200
4.3 CVSS CVE-2026-86216 Medium

code-projects Hotel and Tourism Reservation in PHP 1.0 - Intersite scripting

The web page gets unverified content that can execute a foreign script and steal a session in the user browser.

CWE-79
4.3 CVSS CVE-2026-86215 Medium

Mstfakts College-Management-System - Medium risk vulnerability

Plan an update.

CWE-613
7.5 CVSS CVE-2026-86259 High

THU-MAIC OpenMAIC < 1.0.1 - Missing authentication for critical function

A critical function is available without authentication.

CWE-306
5.9 CVSS CVE-2026-86258 Medium

jupyter nbviewer ≤ 1.0.1 - Crossing the road

Insufficient file path check allows access to files outside the allowed folder.

CWE-22
7.3 CVSS CVE-2026-86214 High

Mstfakts College-Management-System - Incorrect authentication

Identity checks are insufficient to allow access without valid accreditation data.

CWE-287
7.3 CVSS CVE-2026-86213 High

Mstfakts College-Management-System - Lack of neutralisation of special symbols

Data are transferred to another system without separation from control symbols, so they can be interpreted as a command.

CWE-74
5.4 CVSS CVE-2026-86257 Medium

wger-project wger < 2.6 - Medium risk vulnerability

Plan an update.

CWE-1236
5.4 CVSS CVE-2026-86256 Medium

wger-project wger < 2.6 - Medium risk vulnerability

Plan an update.

CWE-601
6.5 CVSS CVE-2026-86255 Medium

wger-project wger < 2.5 - Uncontrolled consumption of resources

Resource consumption is not limited, which may impair access to the service.

CWE-400
6.8 CVSS CVE-2026-86254 Medium

wger-project wger ≤ master - Missing authorization

The right of access is not verified which can allow access to foreign resources.

CWE-862
5.9 CVSS CVE-2026-86253 Medium

h3js h3 < 1.15.6 - Crossing the road

Insufficient file path check allows access to files outside the allowed folder.

CWE-22
5.3 CVSS CVE-2026-86252 Medium

h3js h3 < 1.15.9 - Lack of neutralisation of special symbols

Data are transferred to another system without separation from control symbols, so they can be interpreted as a command.

CWE-74
5.9 CVSS CVE-2026-86251 Medium

h3js h3 < 1.15.9 - Crossing the road

Insufficient file path check allows access to files outside the allowed folder.

CWE-22
7.5 CVSS CVE-2026-86250 High

h3js h3 < 2.0.1-rc.18 - Uncontrolled consumption of resources

Resource consumption is not limited, which may impair access to the service.

CWE-400
8.1 CVSS CVE-2026-86242 High

maximhq Bifrost < 2.0.0 - Involuntary code injection

Unverified data are interpreted as a program code that can change the application's performance.

CWE-94
4.3 CVSS CVE-2026-86212 Medium

Open5GS 2.7.7 Unjustified rights

The component is given more rights than it requires.

CWE-266

i The list is updated periodically from public CVE sources.

TECH NEWS

Top 20 technology news

Most popular news from global technology, security and software stories. Updated periodically.

Source: Hacker News

  1. 01
  2. 02
    The Interim Computer Museum
    ▲ 44 dulmen 💬 4
  3. 03
    Don't call yourself an artisanal programmer
    ▲ 11 emschwartz 💬 5
  4. 04
  5. 05
  6. 06
  7. 07
    Align AI and Mathematics
    ▲ 30 nitrogenpuddle 💬 19
  8. 08
  9. 09
  10. 10
    Recurrent Loaned Transformer
    ▲ 14 MayCXC 💬 7
  11. 11
  12. 12
    AgentsDock: An IDE Designed for AI research
    ▲ 20 ZhuiGeorgia 💬 10
  13. 13
  14. 14
  15. 15
  16. 16
  17. 17
    P (doom)
    ▲ 29 loop 💬 8
  18. 18
    Financial Times' 404 Page not Found
    ▲ 47 sans souse 💬 5
  19. 19
  20. 20

i The list is updated periodically from public sources of technology news.