Vulnerability Details
The Computer Network Defence Alert State is designed to give a granular and more dynamic visualisation of the current cyber security threat. Any increase in an alert state will occur immediately an issue is detected and it will drop again by one level each working day.
Our rationale for this agility is that vulnerabilities often occur in clusters, therefore reducing the alert state again quickly, will increase your visibility of new threats to the same product. Significant vulnerabilities may remain for longer. Vulnerabilities on this page are remotely executable.
Friday 04 September 2026
GeoNetwork

EXPLOITED
GeoNetwork manages spatial data catalogs; allows command execution via unsafe XSLT processing in uploaded formatters.
More Info...
CVSS Score v3 - 9.1
Exploitation Probability
30 Day EPSS: Pending
D-Link

EXPLOITED
D-Link DNS-340L network storage device; remote OS command injection via manipulated callback_url/sync_interval in /cgi-bin/dropbox.cgi CGI handler.
More Info...
CVSS Score v4: 9.9
Exploitation Probability
30 Day EPSS: Pending
MISP

Security
MISP threat intelligence platform: Auth bypass in LDAP and LinOTP allows attacker to impersonate users by submitting empty or invalid credentials.
More Info...
CVSS Score v4 - 9.5
Exploitation Probability
30 Day EPSS: Pending
Microsoft

Security
Microsoft Entra - identity and access management; Azure AD B2C flaw allows privilege escalation via user-controlled key, bypassing authorization.
More Info...
CVSS Score v3: 10.0
Exploitation Probability
30 Day EPSS: Pending
ASUS

Patch
ASUS Control Center Enterprise manages IT assets; lacks authentication, enabling SSRF and hardcoded creds to gain root access and control systems remotely.
More info....
CVSS Score v4 - 10.0
Exploitation Probability
30 Day EPSS: - Pending
Siemens

Patch
Siemens Mendix SAML enables single sign-on authentication; fails to validate SAML signatures, risking session hijacking by attackers.
More Info....
CVSS Score v4 - 8.8
Exploitation Probability
30 Day EPSS: - Pending
Thursday 03 September 2026
SonicWall

EXPLOITED
EXPLOITED: SonicWall SMA1000 Appliances contain a pre-authentication SSRF vulnerability enabling unauthorized access to sensitive functions and operations.
More Info...
CVSS Score v3 - 10.0
Exploitation Probability
30 Day EPSS: 0.27%
F5

Security
F5 reported BIG-IP, BIG-IQ, NGINX and APM vulnerabilities including privilege escalation, injection, authentication bypass, memory corruption and denial-of-service issues.
More Info...
CVSS Score v3: 3.1-8.8
Exploitation Probability
30 Day EPSS: Pending
Cisco

Patch
Cisco Nexus 9000 switches manage network traffic; vulnerability in TCP ports 43210/43211 allows remote code execution with root privileges.
More Info...
CVSS Score v3 - 9.8
Exploitation Probability
30 Day EPSS: Pending
RedHat

Patch
Red Hat Advanced Cluster Management for Kubernetes manages clusters; flaw in submariner cert-auth allows remote root code execution via config injection.
More Info....
CVSS Score: v3 - 9.1
Exploitation Probability
30 Day EPSS: Pending
Jenkins

Patch
Jenkins disclosed core and plugin vulnerabilities including RCE, deserialization, privilege abuse, SSRF, XSS, path traversal, command injection and ACL flaws.
More info....
CVSS Score v4 - 8.2
Exploitation Probability
30 Day EPSS: - Pending
Wednesday 02 September 2026
Rockwell

EXPLOITED
EXPLOITED: Rockwell Logix controllers contain an input validation flaw in CIP message processing that can trigger DoS conditions and major nonrecoverable faults.
More Info...
CVSS Score v4 - 8.7
Exploitation Probability
30 Day EPSS: Pending
Proxmox

Patch
Proxmox VE is a server virtualisation platform; has an auth bypass allowing login as any user without second factor.
More Info...
CVSS Score v4: 9.8
Exploitation Probability
30 Day EPSS: Pending
RedHat

Patch
GNOME virtual filesystem for accessing remote files; gvfs SFTP backend flaw allows heap corruption via oversized read, causing denial or code execution.
More Info...
CVSS Score v4 - 8.8
Exploitation Probability
30 Day EPSS: Pending
NASA

Patch
NASA-JPL ION-DTN (Interplanetary Overlay Network - Delay/Disruption Tolerant Networking) is a delay-tolerant networking software; has an out-of-bounds read flaw via truncated SDNV in decodeSdnv function.
More Info....
CVSS Score: v4 - 8.7
Exploitation Probability
30 Day EPSS: Pending
GitHub

Patch
GitHub Enterprise Server has a SSRF flaw lets unauthenticated attackers send crafted requests, risking token replay on management endpoints.
More info....
CVSS Score v4 - 8.2
Exploitation Probability
30 Day EPSS: - Pending
Schneider

Patch
Schneider Electric EcoStruxure OPC UA Server manages industrial communication; vulnerable to resource exhaustion causing denial of service from many requests.
More Info....
CVSS Score v4 - 8.2
Exploitation Probability
30 Day EPSS: - Pending
Tuesday 01 September 2026
D-Link

ZERO DAY
EXPLOITED: D-Link DNS series NAS devices; remote OS command injection. Publicly available exploit with no patch observed from the vendor.
More Info...
CVSS Score v4 - 9.9
Exploitation Probability
30 Day EPSS: Pending
PaperCut

EXPLOITED
PaperCut print management software; faces active exploitation of an authentication bypass and unsafe class loading vulnerability.
More Info...
CVSS Score v4: 8.8-9.3
Exploitation Probability
30 Day EPSS: Pending
GoPhish

Security
Gophish phishing simulation tool; API auth flaw allows attackers with valid keys to bypass lockout and password change, retaining full access.
More Info...
CVSS Score v4 - 8.6
Exploitation Probability
30 Day EPSS: Pending

Patch
Google Cloud Build automates software builds; an incorrect authorization flaw allowed remote code execution via webhook suppression.
More Info....
CVSS Score: v4 - 9.4
Exploitation Probability
30 Day EPSS: 0.2%
AWS

Patch
Amazon OpenSearch Service indexes and searches data; a flaw in SQL plugin cursor pagination allows remote code execution via crafted cursor parameter.
More info....
CVSS Score v4 - 8.8
Exploitation Probability
30 Day EPSS: - Pending
cPanel

Patch
WebPros cPanel web hosting control panel; eval injection lets remote authenticated users run code as root.
More Info....
CVSS Score v4 - 8.7
Exploitation Probability
30 Day EPSS: - Pending
Friday 28 August 2026
ownCloud

EXPLOITED
ownCloud contains an authentication bypass vulnerability that allows attackers to access, modify, or delete files without authentication.
More Info...
CVSS Score v3 - 9.8
Exploitation Probability
30 Day EPSS: 11.07%
WatchGuard

Security
WatchGuard Fireware OS manages network security; a stack-based buffer overflow in epm service allows remote code execution without authentication.
More Info...
CVSS Score v4: 9.3
Exploitation Probability
30 Day EPSS: Pending
Wazuh

Security
Wazuh provides unified XDR and SIEM for endpoints and cloud; cluster key holders can overwrite files in /var/ossec, enabling root remote code execution.
More Info...
CVSS Score v3 - 9.1
Exploitation Probability
30 Day EPSS: Pending
ServiceNow

Patch
ServiceNow AI platform manages enterprise workflows; code injection flaw allows unauthenticated users to execute code and access or alter data.
More Info....
CVSS Score: v4 - 10.0
Exploitation Probability
30 Day EPSS: Pending
MongoDB

Patch
MONGODB BI Connector: Enables BI tools to query MongoDB data. Unauthenticated clients can cause mongosqld to crash via crafted GSSAPI error, disrupting service.
More info....
CVSS Score v4 - 8.2
Exploitation Probability
30 Day EPSS: - Pending
GitLab

Patch
GitLab AI Gateway manages AI model requests; vulnerability allows authenticated users to redirect requests, exposing Google Vertex AI or AWS Bedrock credentials.
More Info....
CVSS Score v3 - 8.1
Exploitation Probability
30 Day EPSS: - Pending
Thursday 27 August 2026
Dell

Security
Dell PowerProtect One data protection system; OS command injection allows remote low-privilege attacker to execute code.
More Info...
CVSS Score v3 - 8.8
Exploitation Probability
30 Day EPSS: Pending
Citrix

EXPLOITED
Citrix NetScaler ADC and NetScaler Gateway contain a memory buffer overflow vulnerability that can cause denial of service and unpredictable system behavior when exposed services process crafted requests.
More Info...
CVSS Score v4: 8.8
Exploitation Probability
30 Day EPSS: 1.04%
Microsoft

EXPLOITED
Microsoft SQL Server contains an RCE vulnerability that allows authenticated attackers to execute arbitrary code in the context of the SQL Server Database Engine service account.
More Info...
CVSS Score v3 - 8.1
Exploitation Probability
30 Day EPSS: 44.66%
Linux

Patch
Linux kernel network driver: Fixes port_id extraction in am65-cpsw-nuss to prevent kernel crash from invalid memory access due to wrong MAC Port ID.
More Info....
CVSS Score: v3 - 9.8
Exploitation Probability
30 Day EPSS: Pending
Veeam

Patch
Veeam One monitors IT infrastructure; allows unauthenticated attacker to force SMB authentication from service account.
More info....
CVSS Score v4 - 9.3
Exploitation Probability
30 Day EPSS: - Pending
TeamViewer

Patch
TeamViewer Full Client enables remote desktop access; command injection via crafted URL in chat allows remote code execution if user clicks link.
More Info....
CVSS Score v3 - 8.8
Exploitation Probability
30 Day EPSS: - Pending
Definitions - Severity
GUARDED

This alert state represents the return towards normalisation of an alert state, indicating that there was a higher alert state due to a product vulnerability during the previous few days.
INCREASED

This alert state indicates that a product vulnerability has been identified within the last few days. The vulnerability is either difficult to exploit, or if exploited, results in reduced impact to the target system.
CVSS Score 7.1-8.0
HIGH

This alert state indicates a more serious vulnerability which is exploitable.
CVSS Score 8.1-9.0
CRITICAL

This alert state indicates a significant threat to the product, where exploits exist or where the vulnerability is potentially devastating.
CVSS Score 9.1-10.
Definitions - Type

Security
Vendors of cyber security products should know better and given their importance they are highlighted when vulnerable, often combined with critival severity

+24hrs
This bottom descriptor is used with Indicates an alert state which has been present for more than 24 hours.

Patch
This bottom descriptor indicates that patches are available for vulnerabilities, whether it is the initial report or a patch of a vulnerability that had been previously reported.

Exploit
This bottom descriptor indicates that an Exploit has been made public for a vulnerability, whether it is the initial report or an indication of an exploit for a vulnerability that had been previously reported.

OT
This bottom descriptor indicates that the vulnerable product is Operational Technology (OT) such as an Industrial Control System (ICS). OT is not to be confused with Information Technology (IT)

ZERO
This bottom descriptor indicates that a vulnerability has been announced without the opportunity for the vendor to patch it before the details are made known.

LOCAL
Whilst vulnerabilities reported are remotely exploitable, there are rare occasions when we will report on a vulnerability with a locally exploitable attack vector (AV:L)

Monthly
Several vendors release multiple patches on or around the same day each month.
The severity level will reflect the highest vulnerability