Exploit Security News

Public exploit code, proof-of-concept releases, and technical exploitation write-ups for known vulnerabilities.

Once a vulnerability is disclosed, the risk changes sharply the moment working exploit code becomes public — turning a theoretical bug into something any attacker can weaponize. This feed tracks proof-of-concept releases, exploitation write-ups and additions to exploit frameworks as they appear. A published exploit is usually the signal that patching moves from "should" to "urgent".

Recent Exploit items

CVE-2026-73844CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, error paths reflect raw upstream response bodies and internal exception messages back to the caller inste…
@cveNotify · Aug 14, 2026
CVE-2026-49986The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to version 3.17.1 treats the `CLAUDE_PROJECT_DIR` environment variable — automatically set by…
@cveNotify · Aug 14, 2026
CVE-2026-47192kas is a setup tool for bitbake based projects. Starting in version 4.8 and prior to version 5.3, kas checks out and processes repositories regarding configuration includes prior to vali…
@cveNotify · Aug 14, 2026
CVE-2026-46439compliance-trestle is a tooling platform for managing compliance as code. Versions prior to 3.12.2 and 4.0.3 have a Server-Side Template Injection (SSTI) vulnerability exists in the `tre…
@cveNotify · Aug 14, 2026
CVE-2026-19845A vulnerability was determined in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function setStaticDhcpConfig of the file /cgi-bin/cstecgi.cgi of the component lan.so. Executing…
@cveNotify · Aug 14, 2026
CVE-2026-19844A vulnerability was found in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted element is the function setRadvdCfg of the file /cgi-bin/cstecgi.cgi of the component ipv6.so. Performing…
@cveNotify · Aug 14, 2026
CVE-2026-19839A vulnerability was detected in SourceCodester Simple Doctors Appointment System 1.0. This issue affects the function save_doctor of the file /save_file.php. The manipulation results in…
@cveNotify · Aug 14, 2026
CVE-2026-19838A security vulnerability has been detected in Webkul Bagisto up to 2.4.4. This vulnerability affects unknown code of the file /admin/reporting/sales/ of the component Backend Reporting E…
@cveNotify · Aug 14, 2026
CVE-2026-19628A command injection vulnerability exists in Tenable Security Center. An authenticated administrator could modify application configuration values to achieve arbitrary command execution o…
@cveNotify · Aug 14, 2026
CVE-2026-19626A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authenticated, non-administrative user could exploit this issue by supplying…
@cveNotify · Aug 14, 2026
CVE-2026-66271Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote access coul…
@cveNotify · Aug 14, 2026
CVE-2026-70130Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.🎖@cveNotify
@cveNotify · Aug 14, 2026
CVE-2026-66807Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.🎖@cveNotify
@cveNotify · Aug 14, 2026
CVE-2026-66272Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could p…
@cveNotify · Aug 14, 2026
CVE-2026-66271Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote access coul…
@cveNotify · Aug 14, 2026
CVE-2026-66270Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote access coul…
@cveNotify · Aug 14, 2026
CVE-2026-63702Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain a Use of Hard-coded Credentials vulnerability. A low privileged attacker with local access could potentially exploit…
@cveNotify · Aug 14, 2026
CVE-2026-63701Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Improper Deserialization of Untrusted Data vulnerability. A low privileged attacker with local access could poten…
@cveNotify · Aug 14, 2026
CVE-2026-63700Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Incorrect Default Permission vulnerability. A low privileged attacker with local access could potentially exploit…
@cveNotify · Aug 14, 2026
CVE-2026-57472Nozomi Networks Labs identified a CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the file management functionality of the XML-RPC…
@cveNotify · Aug 14, 2026
CVE-2026-57471Nozomi Networks Labs identified a CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the file management functionality of the XML-RPC…
@cveNotify · Aug 14, 2026
CVE-2026-19837A weakness has been identified in Webkul Bagisto up to 2.4.4. This affects an unknown part of the file /admin/customers/search of the component Customer Search. Executing a manipulation…
@cveNotify · Aug 14, 2026
CVE-2026-19836A security flaw has been discovered in Webkul Bagisto up to 2.4.4. Affected by this issue is some unknown functionality of the file /admin/customers/view of the component Backend Custome…
@cveNotify · Aug 14, 2026
CVE-2026-19835A vulnerability was identified in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an unknown functionality of the component Customer Item Deletion Endpoint. Such manipulati…
@cveNotify · Aug 14, 2026
CVE-2026-19834A vulnerability was determined in Webkul Bagisto up to 2.4.4. Affected is an unknown function of the file /admin/customers/login-as-customer/ of the component Admin Customer Impersonatio…
@cveNotify · Aug 14, 2026
CVE-2026-13197Nozomi Networks Labs identified a CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in the configuration and process-imag…
@cveNotify · Aug 14, 2026
CVE-2026-69101Datavane TIS v5.0.0 contains an XML external entity (XXE) injection vulnerability that allows authenticated attackers to perform server-side request forgery and out-of-band file exfiltra…
@cveNotify · Aug 14, 2026
CVE-2026-19879A flaw was found in Undertow, an HTTP server, within its HTTP response header writing path. The `writeString()` method performs a silent narrowing cast from 16-bit Unicode characters to…
@cveNotify · Aug 14, 2026
CVE-2026-53472A flaw was found in migration-planner. Insufficient validation of the `AgentStatusUpdate.CredentialUrl` field allows an authenticated attacker to store a malicious `javascript:` URL. Whe…
@cveNotify · Aug 14, 2026
CVE-2026-1621Authentication bypass by primary weakness vulnerability in Universal Software Inc. E-Municipality allows Exploitation of Trusted Identifiers.This issue affects E-Municipality: from 202511…
@cveNotify · Aug 14, 2026

Other topics

CVE
Recent CVE identifiers and vulnerability disclosures aggregated from security feeds — new CVE IDs, published advisories, and the vendors and products they affect.
Ransomware
Ransomware attacks, extortion group activity, victim disclosures and decryptor releases tracked as they are reported.
Phishing
Phishing campaigns, credential-harvesting kits, and social-engineering techniques used to compromise users and organizations.
Zero-Day
Zero-day vulnerabilities being actively exploited before a patch exists, and the fixes that follow.
Data Breach
Confirmed and reported data breaches — what was exposed, which organizations were affected, and how the incident came to light.
Patch
Vendor patches, security updates and fix releases for previously disclosed vulnerabilities.