| PaperCut MF/NG Auth Bypass + RCE Chain (CVE-2026-81578 / CVE-2026-82078)
new CVE-2026-81578, CVE-2026-82078
web
Unverified | CVE-2026-81578, CVE-2026-82078 | web | CRITICAL 9.8 | Unverified | 2026-09-05 |
| UniFi OS -- Unauthenticated Command Injection RCE (CVE-2026-34910)
new
KEV
EPSS 87% CVE-2026-34910, CVE-2026-34909, CVE-2026-34908
network
Patched | CVE-2026-34910, CVE-2026-34909, CVE-2026-34908 | network | CRITICAL 10 | Patched | 2026-08-16 |
| Oracle E-Business Suite Pre-Authentication RCE Chain (CVE-2025-61882)
new
KEV
RW
EPSS 100% CVE-2025-61882 (Oracle Security Alert, out-of-band, October 2025)
web
Patched | CVE-2025-61882 | web | CRITICAL 9.8 | Patched | 2026-08-09 |
| Xiongmai XM530 IP Camera ONVIF Authentication Bypass (CVE-2025-65856)
new CVE-2025-65856
hardware
Unverified | CVE-2025-65856 | hardware | CRITICAL 9.8 | Unverified | 2026-07-06 |
| Twonky Server 8.5.2 Unauthenticated `/nmc/rpc/` Auth Bypass & Admin Credential Log Leak (CVE-2025-13315)
new
EPSS 33% CVE-2025-13315
network
Unpatched | CVE-2025-13315 | network | CRITICAL 9.8 | Unpatched | 2026-07-06 |
| FlowiseAI Account-Takeover via Forgot-Password Token Leak (CVE-2025-58434)
new
EPSS 50% CVE-2025-58434
web
Patched | CVE-2025-58434 | web | CRITICAL 9.8 | Patched | 2026-07-06 |
| ZTE ZXHN H188A Unauthenticated Wizard Handler Credential Disclosure / Auth Bypass (CVE-2026-34472)
new CVE-2026-34472
network
Unverified | CVE-2026-34472 | network | CRITICAL | Unverified | 2026-07-05 |
| WP Captcha PRO Subscriber-to-Administrator Authentication Bypass — CVE-2026-5415
new CVE-2026-5415
web
Unverified | CVE-2026-5415 | web | HIGH 8.8 | Unverified | 2026-07-05 |
| WordPress SignUp/SignIn & Invoice Generator Password-Reset Account Takeover (CVE-2026-12416 / CVE-2026-12417)
new CVE-2026-12416, CVE-2026-12417
web
Unverified | CVE-2026-12416, CVE-2026-12417 | web | CRITICAL 9.8 | Unverified | 2026-07-05 |
| SmarterMail Unauthenticated Admin Password Reset (CVE-2026-0001 / WT-2026-0001)
new CVE-2026-0001 (tracked publicly as WT-2026-0001)
web
Patched | CVE-2026-0001 | web | CRITICAL 9 | Patched | 2026-07-05 |
| SimpleHelp OIDC Authentication Bypass (CVE-2026-48558)
new
KEV
EPSS 12% CVE-2026-48558
web
Patched | CVE-2026-48558 | web | CRITICAL 9.8 | Patched | 2026-07-05 |
| pac4j JWT Authentication Bypass via Unsigned Token in JWE Wrapper — CVE-2026-29000
new CVE-2026-29000
web
Patched | CVE-2026-29000 | web | CRITICAL 9.8 | Patched | 2026-07-05 |
| OpenClaw Gateway WebSocket Authentication Bypass RCE — CVE-2026-28466
new CVE-2026-28466
network
Patched | CVE-2026-28466 | network | CRITICAL | Patched | 2026-07-05 |
| NVIDIA Triton Inference Server SageMaker Auth Bypass to Unauthenticated RCE (CVE-2026-24207)
new CVE-2026-24207 (sibling: CVE-2026-24206, Vertex AI, analysis only)
network
Patched | CVE-2026-24207 | network | CRITICAL 9.8 | Patched | 2026-07-05 |
| MantisBT SOAP `mc_issue_add` Authentication Bypass (Type Juggling) — CVE-2026-30849
new CVE-2026-30849
web
Patched | CVE-2026-30849 | web | HIGH | Patched | 2026-07-05 |
| LiteLLM Proxy Unauthenticated Auth Bypass via Host-Header Route Confusion (CVE-2026-49468)
new CVE-2026-49468
web
Patched | CVE-2026-49468 | web | CRITICAL 9.8 | Patched | 2026-07-05 |
| Gitea Container Registry Anonymous Auth Bypass (CVE-2026-27771)
new CVE-2026-27771
web
Patched | CVE-2026-27771 | web | CRITICAL | Patched | 2026-07-05 |
| Flowise NVIDIA NIM Endpoint Authentication Bypass — CVE-2026-30824
new
EPSS 36% CVE-2026-30824
web
Patched | CVE-2026-30824 | web | CRITICAL 9.8 | Patched | 2026-07-05 |
| Budibase Authentication Bypass to Plugin-Upload Reverse Shell — CVE-2026-31816
new
EPSS 15% CVE-2026-31816
web
Unverified | CVE-2026-31816 | web | CRITICAL | Unverified | 2026-07-05 |
| Apache Tomcat Split-Collection Security Constraint Bypass (CVE-2026-43515)
new CVE-2026-43515
web
Patched | CVE-2026-43515 | web | HIGH | Patched | 2026-07-05 |
| Apache Tomcat Mutual TLS OCSP Soft-Fail Authentication Bypass — CVE-2026-29145
new CVE-2026-29145
web
Patched | CVE-2026-29145 | web | CRITICAL 9.1 | Patched | 2026-07-05 |
| AdminPanel 4.0 CSRF File Deletion / Setup-Mode Reset — CVE-2026-30498
new CVE-2026-30498 (reserved by MITRE)
web
Unverified | CVE-2026-30498 | web | HIGH | Unverified | 2026-07-05 |
| PAN-OS GlobalProtect Authentication Bypass via Forged Cookie (CVE-2026-0257)
new
KEV
RW
EPSS 94% CVE-2026-0257
web
Unverified | CVE-2026-0257 | web | HIGH 7.8 | Unverified | 2026-07-01 |
| Ivanti Sentry Pre-Auth RCE + Auth Bypass (CVE-2026-10520 / CVE-2026-10523)
new
KEV
EPSS 100% CVE-2026-10520, CVE-2026-10523
network
Patched | CVE-2026-10520, CVE-2026-10523 | network | CRITICAL 10 | Patched | 2026-06-28 |
| Check Point Remote Access VPN IKEv1 Auth Bypass (CVE-2026-50751)
new
KEV
RW
EPSS 84% CVE-2026-50751
network
Patched | CVE-2026-50751 | network | CRITICAL 9.3 | Patched | 2026-06-28 |
| ToolShell - SharePoint Unauthenticated RCE Chain
new
KEV
RW
EPSS 100% CVE-2025-53770, CVE-2025-53771, CVE-2025-49704, CVE-2025-49706
web
Patched | CVE-2025-53770, CVE-2025-53771, CVE-2025-49704, CVE-2025-49706 | web | CRITICAL | Patched | 2026-05-17 |
| Next.js Dynamic Route Injection Auth Bypass (CVE-2026-44574)
new CVE-2026-44574
web
Patched | CVE-2026-44574 | web | HIGH 8.1 | Patched | 2026-05-17 |
| Fortinet FortiCloud SSO Authentication Bypass
new
KEV
EPSS 69% CVE-2025-59718, CVE-2025-59719 (Advisory: FG-IR-25-647)
network
Unverified | CVE-2025-59718, CVE-2025-59719 | network | CRITICAL 9.8 | Unverified | 2026-05-17 |
| VMware ESXi Active Directory Authentication Bypass (CVE-2024-37085)
new
KEV
RW
EPSS 27% CVE-2024-37085
network
Patched | CVE-2024-37085 | network | MEDIUM 6.8 | Patched | 2026-05-16 |
| Palo Alto PAN-OS Management Interface Authentication Bypass (CVE-2025-0108)
new
KEV
EPSS 98% CVE-2025-0108
web
Patched | CVE-2025-0108 | web | CRITICAL 9.1 | Patched | 2026-05-16 |
| Fortinet FortiOS / FortiProxy Authentication Bypass (CVE-2024-55591)
new
KEV
RW
EPSS 98% CVE-2024-55591 (Fortinet FG-IR-24-535)
web
Unverified | CVE-2024-55591 | web | CRITICAL 9.6 | Unverified | 2026-05-16 |
| cPanel & WHM Authentication Bypass via Session-File CRLF Injection (CVE-2026-41940)
new
KEV
RW
EPSS 99% CVE-2026-41940
web
Patched | CVE-2026-41940 | web | CRITICAL 10 | Patched | 2026-05-16 |
| Next.js Corrupt Middleware Auth Bypass (CVE-2025-29927)
new
EPSS 99% CVE-2025-29927
web
Patched | CVE-2025-29927 | web | CRITICAL 9.1 | Patched | 2026-05-15 |