<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<title>Senserva: vulnerabilities exploited this week (CISA KEV additions, all vendors)</title>
<link>https://senserva.com/exploited-this-week.html</link>
<atom:link href="https://senserva.com/feed/exploited-this-week.xml" rel="self" type="application/rss+xml"/>
<description>Every vulnerability newly confirmed exploited in the wild: CISA KEV catalog additions from the last 30 days, all vendors, Microsoft included, with CVSS and ransomware flags. From Senserva. Use is subject to the Senserva EULA: https://senserva.com/eula.html; rules at https://senserva.com/feeds.html.</description>
<language>en-us</language>
<generator>Provided by Senserva.com</generator>
<copyright>Provided by Senserva.com. Free to use; please credit Senserva.com and link back to https://senserva.com/.</copyright>
<webMaster>hello@senserva.com (Senserva)</webMaster>
<lastBuildDate>Thu, 23 Jul 2026 00:00:00 GMT</lastBuildDate>
<ttl>720</ttl>
<item>
<title>Check Point SmartConsole: Check Point SmartConsole Improper Authentication Vulnerability</title>
<link>https://senserva.com/cve/CVE-2026-16232.html</link>
<guid isPermaLink="false">etw-CVE-2026-16232</guid>
<pubDate>Wed, 22 Jul 2026 00:00:00 GMT</pubDate>
<category>Exploited</category>
<description>CVE-2026-16232, CVSS 9.1. Newly confirmed exploited in the wild (CISA KEV), added 2026-07-22.</description>
</item>
<item>
<title>Microsoft SharePoint: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability</title>
<link>https://senserva.com/cve/CVE-2026-50522.html</link>
<guid isPermaLink="false">etw-CVE-2026-50522</guid>
<pubDate>Wed, 22 Jul 2026 00:00:00 GMT</pubDate>
<category>Exploited</category>
<description>CVE-2026-50522, CVSS n/a. Newly confirmed exploited in the wild (CISA KEV), added 2026-07-22.</description>
</item>
<item>
<title>DD-WRT DD-WRT: DD-WRT Stack-Based Buffer Overflow Vulnerability</title>
<link>https://senserva.com/cve/CVE-2021-27137.html</link>
<guid isPermaLink="false">etw-CVE-2021-27137</guid>
<pubDate>Tue, 21 Jul 2026 00:00:00 GMT</pubDate>
<category>Exploited</category>
<description>CVE-2021-27137, CVSS 8.1. Newly confirmed exploited in the wild (CISA KEV), added 2026-07-21.</description>
</item>
<item>
<title>Langflow Langflow: Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability</title>
<link>https://senserva.com/cve/CVE-2026-0770.html</link>
<guid isPermaLink="false">etw-CVE-2026-0770</guid>
<pubDate>Tue, 21 Jul 2026 00:00:00 GMT</pubDate>
<category>Exploited</category>
<description>CVE-2026-0770, CVSS 9.8. Newly confirmed exploited in the wild (CISA KEV), added 2026-07-21.</description>
</item>
<item>
<title>WordPress Core: WordPress Core SQL Injection Vulnerability</title>
<link>https://senserva.com/cve/CVE-2026-60137.html</link>
<guid isPermaLink="false">etw-CVE-2026-60137</guid>
<pubDate>Tue, 21 Jul 2026 00:00:00 GMT</pubDate>
<category>Exploited</category>
<description>CVE-2026-60137, CVSS 5.9. Newly confirmed exploited in the wild (CISA KEV), added 2026-07-21.</description>
</item>
<item>
<title>WordPress Core: WordPress Core Interpretation Conflict Vulnerability</title>
<link>https://senserva.com/cve/CVE-2026-63030.html</link>
<guid isPermaLink="false">etw-CVE-2026-63030</guid>
<pubDate>Tue, 21 Jul 2026 00:00:00 GMT</pubDate>
<category>Exploited</category>
<description>CVE-2026-63030, CVSS 9.8. Newly confirmed exploited in the wild (CISA KEV), added 2026-07-21.</description>
</item>
<item>
<title>Fortinet FortiSandbox: Fortinet FortiSandbox OS Command Injection Vulnerability</title>
<link>https://senserva.com/cve/CVE-2026-25089.html</link>
<guid isPermaLink="false">etw-CVE-2026-25089</guid>
<pubDate>Thu, 16 Jul 2026 00:00:00 GMT</pubDate>
<category>Exploited</category>
<description>CVE-2026-25089, CVSS 9.8. Newly confirmed exploited in the wild (CISA KEV), added 2026-07-16.</description>
</item>
<item>
<title>Fortinet FortiSandbox: Fortinet FortiSandbox OS Command Injection Vulnerability</title>
<link>https://senserva.com/cve/CVE-2026-39808.html</link>
<guid isPermaLink="false">etw-CVE-2026-39808</guid>
<pubDate>Thu, 16 Jul 2026 00:00:00 GMT</pubDate>
<category>Exploited</category>
<description>CVE-2026-39808, CVSS 9.8. Newly confirmed exploited in the wild (CISA KEV), added 2026-07-16.</description>
</item>
<item>
<title>Microsoft SharePoint: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability</title>
<link>https://senserva.com/cve/CVE-2026-58644.html</link>
<guid isPermaLink="false">etw-CVE-2026-58644</guid>
<pubDate>Thu, 16 Jul 2026 00:00:00 GMT</pubDate>
<category>Exploited</category>
<description>CVE-2026-58644, CVSS n/a. Newly confirmed exploited in the wild (CISA KEV), added 2026-07-16.</description>
</item>
<item>
<title>KNX Association KNX Protocol Connection Authorization Option 1: KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability</title>
<link>https://senserva.com/cve/CVE-2023-4346.html</link>
<guid isPermaLink="false">etw-CVE-2023-4346</guid>
<pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
<category>Exploited</category>
<description>CVE-2023-4346, CVSS 7.5. Newly confirmed exploited in the wild (CISA KEV), added 2026-07-15.</description>
</item>
<item>
<title>Oracle E-Business Suite: Oracle E-Business Suite Improper Privilege Management Vulnerability</title>
<link>https://senserva.com/cve/CVE-2026-46817.html</link>
<guid isPermaLink="false">etw-CVE-2026-46817</guid>
<pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
<category>Exploited</category>
<description>CVE-2026-46817, CVSS 9.8. Newly confirmed exploited in the wild (CISA KEV), added 2026-07-15.</description>
</item>
<item>
<title>SonicWall SMA1000 Appliances: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability</title>
<link>https://senserva.com/cve/CVE-2026-15409.html</link>
<guid isPermaLink="false">etw-CVE-2026-15409</guid>
<pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate>
<category>Exploited</category>
<description>CVE-2026-15409, CVSS 10. Newly confirmed exploited in the wild (CISA KEV), added 2026-07-14.</description>
</item>
<item>
<title>SonicWall SMA1000 Appliances: SonicWall SMA1000 Appliances Code Injection Vulnerability</title>
<link>https://senserva.com/cve/CVE-2026-15410.html</link>
<guid isPermaLink="false">etw-CVE-2026-15410</guid>
<pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate>
<category>Exploited</category>
<description>CVE-2026-15410, CVSS 7.2. Newly confirmed exploited in the wild (CISA KEV), added 2026-07-14.</description>
</item>
<item>
<title>Microsoft Active Directory Federation Services: Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability</title>
<link>https://senserva.com/cve/CVE-2026-56155.html</link>
<guid isPermaLink="false">etw-CVE-2026-56155</guid>
<pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate>
<category>Exploited</category>
<description>CVE-2026-56155, CVSS n/a. Newly confirmed exploited in the wild (CISA KEV), added 2026-07-14.</description>
</item>
<item>
<title>Microsoft SharePoint Server: Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability</title>
<link>https://senserva.com/cve/CVE-2026-56164.html</link>
<guid isPermaLink="false">etw-CVE-2026-56164</guid>
<pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate>
<category>Exploited</category>
<description>CVE-2026-56164, CVSS n/a. Newly confirmed exploited in the wild (CISA KEV), added 2026-07-14.</description>
</item>
<item>
<title>Cisco IOS: Cisco IOS Cross-Site Request Forgery Vulnerability</title>
<link>https://senserva.com/cve/CVE-2008-4128.html</link>
<guid isPermaLink="false">etw-CVE-2008-4128</guid>
<pubDate>Mon, 13 Jul 2026 00:00:00 GMT</pubDate>
<category>Exploited</category>
<description>CVE-2008-4128, CVSS 4.3. Newly confirmed exploited in the wild (CISA KEV), added 2026-07-13.</description>
</item>
<item>
<title>iCagenda iCagenda: iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability</title>
<link>https://senserva.com/cve/CVE-2026-48939.html</link>
<guid isPermaLink="false">etw-CVE-2026-48939</guid>
<pubDate>Fri, 10 Jul 2026 00:00:00 GMT</pubDate>
<category>Exploited</category>
<description>CVE-2026-48939, CVSS 9.8. Newly confirmed exploited in the wild (CISA KEV), added 2026-07-10.</description>
</item>
<item>
<title>Balbooa Forms: Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability</title>
<link>https://senserva.com/cve/CVE-2026-56291.html</link>
<guid isPermaLink="false">etw-CVE-2026-56291</guid>
<pubDate>Fri, 10 Jul 2026 00:00:00 GMT</pubDate>
<category>Exploited</category>
<description>CVE-2026-56291, CVSS 9.8. Newly confirmed exploited in the wild (CISA KEV), added 2026-07-10.</description>
</item>
<item>
<title>Adobe ColdFusion: Adobe ColdFusion Path Traversal Vulnerability</title>
<link>https://senserva.com/cve/CVE-2026-48282.html</link>
<guid isPermaLink="false">etw-CVE-2026-48282</guid>
<pubDate>Tue, 07 Jul 2026 00:00:00 GMT</pubDate>
<category>Exploited</category>
<description>CVE-2026-48282, CVSS 10. Newly confirmed exploited in the wild (CISA KEV), added 2026-07-07.</description>
</item>
<item>
<title>JoomShaper SP Page Builder: JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability</title>
<link>https://senserva.com/cve/CVE-2026-48908.html</link>
<guid isPermaLink="false">etw-CVE-2026-48908</guid>
<pubDate>Tue, 07 Jul 2026 00:00:00 GMT</pubDate>
<category>Exploited</category>
<description>CVE-2026-48908, CVSS 9.8. Newly confirmed exploited in the wild (CISA KEV), added 2026-07-07.</description>
</item>
<item>
<title>Langflow Langflow: Langflow Authorization Bypass Through User-Controlled Key Vulnerability</title>
<link>https://senserva.com/cve/CVE-2026-55255.html</link>
<guid isPermaLink="false">etw-CVE-2026-55255</guid>
<pubDate>Tue, 07 Jul 2026 00:00:00 GMT</pubDate>
<category>Exploited</category>
<description>CVE-2026-55255, CVSS 9.9. Newly confirmed exploited in the wild (CISA KEV), added 2026-07-07.</description>
</item>
<item>
<title>Joomlack Page Builder: Joomlack Page Builder Improper Access Control Vulnerability</title>
<link>https://senserva.com/cve/CVE-2026-56290.html</link>
<guid isPermaLink="false">etw-CVE-2026-56290</guid>
<pubDate>Tue, 07 Jul 2026 00:00:00 GMT</pubDate>
<category>Exploited</category>
<description>CVE-2026-56290, CVSS 9.8. Newly confirmed exploited in the wild (CISA KEV), added 2026-07-07.</description>
</item>
<item>
<title>Microsoft SharePoint Server: Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability</title>
<link>https://senserva.com/cve/CVE-2026-45659.html</link>
<guid isPermaLink="false">etw-CVE-2026-45659</guid>
<pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate>
<category>Exploited</category>
<description>CVE-2026-45659, CVSS n/a. Newly confirmed exploited in the wild (CISA KEV), added 2026-07-01.</description>
</item>
<item>
<title>SimpleHelp SimpleHelp: SimpleHelp Authentication Bypass Vulnerability</title>
<link>https://senserva.com/cve/CVE-2026-48558.html</link>
<guid isPermaLink="false">etw-CVE-2026-48558</guid>
<pubDate>Mon, 29 Jun 2026 00:00:00 GMT</pubDate>
<category>Exploited</category>
<description>CVE-2026-48558, CVSS 10. Newly confirmed exploited in the wild (CISA KEV), added 2026-06-29.</description>
</item>
<item>
<title>PTC Windchill and FlexPLM: PTC Windchill and FlexPLM Improper Input Validation Vulnerability</title>
<link>https://senserva.com/cve/CVE-2026-12569.html</link>
<guid isPermaLink="false">etw-CVE-2026-12569</guid>
<pubDate>Thu, 25 Jun 2026 00:00:00 GMT</pubDate>
<category>Exploited</category>
<description>CVE-2026-12569, CVSS 9.8. Newly confirmed exploited in the wild (CISA KEV), added 2026-06-25.</description>
</item>
<item>
<title>Cisco Unified Communications Manager: Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability</title>
<link>https://senserva.com/cve/CVE-2026-20230.html</link>
<guid isPermaLink="false">etw-CVE-2026-20230</guid>
<pubDate>Thu, 25 Jun 2026 00:00:00 GMT</pubDate>
<category>Exploited</category>
<description>CVE-2026-20230, CVSS 8.6. Newly confirmed exploited in the wild (CISA KEV), added 2026-06-25.</description>
</item>
<item>
<title>Lantronix EDS5000: Lantronix EDS5000 Code Injection Vulnerability</title>
<link>https://senserva.com/cve/CVE-2025-67038.html</link>
<guid isPermaLink="false">etw-CVE-2025-67038</guid>
<pubDate>Tue, 23 Jun 2026 00:00:00 GMT</pubDate>
<category>Exploited</category>
<description>CVE-2025-67038, CVSS 9.8. Newly confirmed exploited in the wild (CISA KEV), added 2026-06-23.</description>
</item>
<item>
<title>Ubiquiti UniFi OS: Ubiquiti UniFi OS Improper Access Control Vulnerability</title>
<link>https://senserva.com/cve/CVE-2026-34908.html</link>
<guid isPermaLink="false">etw-CVE-2026-34908</guid>
<pubDate>Tue, 23 Jun 2026 00:00:00 GMT</pubDate>
<category>Exploited</category>
<description>CVE-2026-34908, CVSS 10. Newly confirmed exploited in the wild (CISA KEV), added 2026-06-23.</description>
</item>
<item>
<title>Ubiquiti UniFi OS: Ubiquiti UniFi OS Path Traversal Vulnerability</title>
<link>https://senserva.com/cve/CVE-2026-34909.html</link>
<guid isPermaLink="false">etw-CVE-2026-34909</guid>
<pubDate>Tue, 23 Jun 2026 00:00:00 GMT</pubDate>
<category>Exploited</category>
<description>CVE-2026-34909, CVSS 10. Newly confirmed exploited in the wild (CISA KEV), added 2026-06-23.</description>
</item>
<item>
<title>Ubiquiti UniFi OS: Ubiquiti UniFi OS Improper Input Validation Vulnerability</title>
<link>https://senserva.com/cve/CVE-2026-34910.html</link>
<guid isPermaLink="false">etw-CVE-2026-34910</guid>
<pubDate>Tue, 23 Jun 2026 00:00:00 GMT</pubDate>
<category>Exploited</category>
<description>CVE-2026-34910, CVSS 10. Newly confirmed exploited in the wild (CISA KEV), added 2026-06-23.</description>
</item>
</channel>
</rss>
