Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: actively-exploited (105 articles)Clear

Attackers exploit a critical JFrog Artifactory flaw to mint admin tokens

Days after disclosure, attackers are exploiting a critical authentication-bypass flaw in JFrog Artifactory, the widely used repository manager for binaries, packages, containers, and build artifacts. Tracked as CVE-2026-82329 and scored 9.8, the flaw lets an unauthenticated attacker with network access gain administrative privileges under Artifactory's default configuration. Researchers at watchTowr observed exploitation beginning September 1, with attackers minting admin tokens for themselves and enumerating users, groups, and credentials. Because Artifactory sits at the center of software supply chains and CI/CD pipelines, admin access lets attackers tamper with build pipelines, poison trusted dependencies, and push malicious code downstream to customers. JFrog patched it in version 7.161.20 on August 28.

Check
Patch self-managed JFrog Artifactory to 7.161.20 or later immediately, prioritizing internet-exposed instances, then inspect audit logs for unexpected admin tokens, user enumeration, and any changes to hosted artifacts.
Affected
Organizations running self-managed JFrog Artifactory in default configuration (CVE-2026-82329); an unauthenticated attacker with network access can gain admin, mint tokens, harvest credentials, and tamper with the supply chain, and exploitation is active.
Fix
Patch now, rotate Artifactory credentials and tokens, review hosted packages and build pipelines for tampering, restrict network exposure of the service, and treat any exposed unpatched instance as a supply-chain compromise.

Attackers exploit critical Langflow and Rails flaws to harvest secrets

VulnCheck reported active exploitation of two critical flaws, one in the AI workflow builder Langflow and one in Ruby on Rails. The Langflow bug, CVE-2026-0768, scored 9.8, lets an attacker run arbitrary Python code as root through improper input validation. The Rails bug, CVE-2026-66066 and nicknamed KindaRails2Shell at 9.5, lets an unauthenticated attacker read arbitrary files by uploading a crafted image that exploits a mismatch between Active Storage and the libvips image library, leaking secrets like the Rails master key and cloud credentials and ultimately enabling code execution. Detections jumped from about 50 to 360 within a day, with attackers querying environment variables for OpenAI and AWS keys and probing SSH access.

Check
Patch Langflow and Ruby on Rails to fixed versions now, and rotate any secrets an attacker could have read, including the Rails master key, database passwords, cloud credentials, and API keys.
Affected
Internet-facing Langflow servers (CVE-2026-0768) and Rails apps using Active Storage with libvips (CVE-2026-66066); attackers can run code as root or read files leaking the master key, cloud credentials, and API tokens.
Fix
Update both immediately, rotate exposed secrets, restrict internet exposure of Langflow, review logs for environment-variable probing and image-upload abuse, and treat any exposed instance as potentially credential-compromised.

Attackers exploit PaperCut print server zero-days affecting all NG and MF versions

PaperCut warned that attackers are actively exploiting vulnerabilities in all versions of its widely deployed NG and MF print-management software, and confirmed real customer incidents. Two flaws are involved: CVE-2026-82078, unsafe dynamic class loading in the database connection utilities that lets an attacker run arbitrary Java bytecode, and CVE-2026-81578, an access-control flaw in the web management interface that lets an unauthenticated attacker change system configuration. PaperCut released emergency out-of-cycle patches for its version 25 and 26 branches, with a version 24 build still in progress, and later issued a hardened second release. PaperCut servers have a history of being targeted by ransomware crews.

Check
Install PaperCut's emergency patch, specifically Release 2, on all NG and MF servers now, and if a server is internet-facing, immediately restrict its web interface to trusted IP addresses.
Affected
Organizations running PaperCut NG or MF, especially internet-facing print servers (CVE-2026-82078, CVE-2026-81578); attackers are actively exploiting the flaws to change configuration and execute code, and all versions are affected.
Fix
Apply the emergency Release 2 patch, keep the Application Server off the public internet or limited to trusted IPs, investigate the pc-app process, and treat exposed unpatched servers as compromised.

Attackers exploit a critical Gitea flaw to run code on self-hosted Git servers

CISA warned that attackers are exploiting a critical flaw in Gitea, the popular self-hosted Git service, and added it to its exploited-vulnerabilities catalog. Tracked as CVE-2026-60004 and scored 9.8, the code-injection bug lets a user with repository write access send a malicious patch to the diffpatch API endpoint, planting an executable Git hook that runs shell commands as the Gitea service account. Crucially, default installations have open self-registration, so an unauthenticated attacker can simply register, create a repository, and gain code execution. It affects versions 1.17 through 1.27.0 and was fixed in July, and reports describe attackers dropping cryptocurrency miners, with one intrusion taking about eleven seconds.

Check
Upgrade Gitea to 1.27.1 or later immediately, disable open self-registration on internet-facing instances, and treat any exposed, registration-enabled server as an incident-response case rather than just a patch.
Affected
Organizations running self-hosted Gitea 1.17 through 1.27.0 (CVE-2026-60004); an attacker with repository write access, obtainable through default open registration, can execute shell commands as the Gitea service account.
Fix
Patch to a fixed release, turn off self-registration where not needed, restrict internet exposure of Gitea, and hunt patched servers for rogue Git hooks, miner processes, and other signs of compromise.

Attackers chain two miniOrange WordPress SSO flaws to forge admin logins

Attackers are exploiting two critical authentication-bypass flaws in the miniOrange SAML 2.0 Single Sign On plugin for WordPress, chaining them to forge login responses and sign in as an administrator. The first flaw, CVE-2026-61979, lets the plugin accept an attacker-chosen signature algorithm, so the identity provider's public key can be abused as a shared secret to forge a valid signature; the second, CVE-2026-15981, makes the plugin treat a signature-verification error as success. Both were fixed in July, but the vendor only alerted free-edition users, leaving paid editions unpatched. Security firm Patchstack traced an attack in mid-August where the two were chained to steal an administrator session cookie.

Check
Update the miniOrange SAML Single Sign On plugin on all WordPress sites, including paid editions that were not alerted, and audit for unexpected administrator accounts and sessions.
Affected
WordPress sites using the miniOrange SAML 2.0 Single Sign On plugin (CVE-2026-61979, CVE-2026-15981); chaining the two lets an unauthenticated attacker forge a SAML response and obtain an administrator session.
Fix
Patch or remove the plugin, rotate WordPress salts and admin passwords to invalidate stolen sessions, check for rogue admins, and put a web application firewall in front of login endpoints.

Attackers exploit unauthenticated Zimbra SNMP flaw for remote code execution

Poland's national CERT warned that attackers are exploiting a now-patched flaw in Zimbra Collaboration to run commands on mail servers without authentication. Tracked as CVE-2026-73570 and scored 8.9, it is an OS command injection bug in Zimbra's SNMP monitoring feature: when the optional SNMP package is installed and notification traps are enabled, improper input handling lets an unauthenticated attacker send crafted requests that execute commands as the Zimbra user. The monitoring service involved is on by default where SNMP is used, widening exposure. Zimbra fixed it in version 10.1.20 in July, and Zimbra servers are a long-standing target, so unpatched instances should be treated as urgent.

Check
Update Zimbra Collaboration to 10.1.20 or later now, and check whether the SNMP package is installed with notifications enabled, which is the exposed configuration under active attack.
Affected
Organizations running Zimbra Collaboration before 10.1.20 with the SNMP package installed and notifications enabled (CVE-2026-73570); an unauthenticated attacker can execute operating-system commands as the Zimbra user, and exploitation is underway.
Fix
Patch to 10.1.20, and if you ran an exposed version, inspect the Zimbra log for suspicious service restarts and recently created files, since patching alone will not evict a foothold.

CISA flags exploited Ray flaw that lets a website run code on developer machines

CISA added a critical flaw in Ray, the open-source framework for scaling AI and machine-learning workloads, to its exploited-vulnerabilities catalog and gave federal agencies just three days to fix it. Tracked as CVE-2025-62593 and scored 9.4, the bug stems from Ray leaving key dashboard and job endpoints unauthenticated; its only browser defense checked that the request's user-agent began with Mozilla, which attackers can forge. Combined with a DNS rebinding attack, a malicious website or advertisement viewed while running Ray can execute code on the developer's machine. A DDoS botnet adopted it before public disclosure, and a separate campaign has been turning unpatched Ray clusters with GPUs into cryptocurrency miners.

Check
Upgrade Ray to version 2.52.0 or later, and treat the risk as immediate given the three-day federal deadline and ongoing campaigns against exposed clusters, including developer machines running Ray locally.
Affected
Anyone running Ray before 2.52.0 (CVE-2025-62593); unauthenticated dashboard endpoints plus a browser and DNS rebinding attack let a malicious page run code on the machine, and it is exploited in the wild.
Fix
Patch to 2.52.0, keep Ray dashboards and APIs off untrusted networks and behind authentication, restrict who can reach them, and check GPU clusters for unauthorized cryptomining and other signs of compromise.

Exploited MLflow SSRF flaw lets attackers steal cloud credentials from ML servers

Attackers began exploiting a critical unauthenticated flaw in MLflow, the popular open-source machine-learning platform, within hours of its disclosure. Tracked as CVE-2026-64849 and scored 9.3, the server-side request forgery bug lives in the model-registry webhook testing feature: an attacker hosts an endpoint that passes validation, then redirects MLflow to internal targets such as the cloud metadata service or loopback addresses, and MLflow returns their responses. That exposes cloud credentials, API tokens, and secrets. Because MLflow sits close to training data, artifacts, object storage, CI/CD, and inference pipelines, a compromise offers both credentials and a foothold for lateral movement. watchTowr's honeypots saw exploitation attempts almost immediately.

Check
Upgrade MLflow to version 3.15.0 or later immediately, and treat any internet-exposed instance on an earlier version as potentially probed, checking for signs of metadata access.
Affected
Organizations running MLflow before 3.15.0, especially cloud-hosted and internet-exposed (CVE-2026-64849); an unauthenticated attacker can coerce it into fetching internal targets and leak cloud credentials, tokens, and secrets.
Fix
Patch to 3.15.0, review webhook configurations for attacker URLs, inspect logs for webhook-test requests and metadata or loopback addresses, rotate credentials the server could reach, and restrict its network exposure.

Critical SAP Commerce Cloud flaw exploited days after patch with no public exploit

Attackers began exploiting a critical SAP Commerce Cloud flaw within days of its patch, even though no public proof-of-concept exists. Tracked as CVE-2026-58231 and scored 10.0, the improper-authorization bug in the Data Hub Adapter lets an unauthenticated attacker abuse a default authentication client and send crafted input to reach arbitrary code execution. Threat intelligence firm Defused saw the first exploitation attempts hit its honeypots three days after SAP's August patch, classified as automated mass scanning of internet-facing deployments. Shadowserver tracks more than 4,200 exposed SAP Commerce Cloud systems, mostly in Europe and North America. Prior critical SAP flaws have been used by state actors and ransomware crews.

Check
Apply SAP's August patch for Commerce Cloud immediately per Security Note 3771065, then re-deploy the updated version, and prioritize any internet-facing or hybrid deployment as an emergency.
Affected
Organizations running unpatched SAP Commerce Cloud (CVE-2026-58231); an unauthenticated attacker can reach arbitrary code execution with low complexity, and exploitation is already underway despite no public exploit code.
Fix
Patch and re-deploy now, restrict access to Commerce Cloud from untrusted networks, review the Data Hub Adapter and application logs for suspicious requests and code execution, and monitor for follow-on compromise.

Exploited macOS Screen Sharing flaw gives attackers root to plant miners

The Netherlands cyber agency warned that attackers are exploiting a recently patched macOS flaw to gain root on internet-exposed Macs and install cryptocurrency miners. Tracked as CVE-2026-65400 and scored 9.8, the authentication flaw in the Screen Sharing component lets a network attacker authenticate to the built-in remote desktop service, which uses VNC on port 5900, without valid credentials due to flawed state management. Apple fixed it in emergency updates on August 6 for macOS Tahoe, Sequoia, and Sonoma. Screen Sharing is off by default, but any Mac with it enabled and reachable from the internet is at high risk, and several have already been compromised to run Monero miners.

Check
Install Apple's August macOS updates on all Macs, and confirm Screen Sharing is disabled or that port 5900 is not reachable from the internet on any system where remote desktop is enabled.
Affected
Macs with Screen Sharing enabled and reachable from the internet on unpatched macOS Tahoe, Sequoia, or Sonoma (CVE-2026-65400); a network attacker can authenticate without credentials and gain root.
Fix
Update macOS, disable Screen Sharing where it is not needed, restrict remote desktop access to trusted networks or a VPN, and check exposed Macs for unauthorized access and cryptominer processes.