Critical
Visual Composer LFI is CVE-2026-12227
Wordfence disclosed an unauthenticated local file inclusion in the Visual Composer Website Builder WordPress plugin up to 45.16.0, CVSS 9.8. A public PoC repository exists. Exploitation in the wild and CISA KEV listing are not confirmed.
Published 55m ago
Critical
The Gitea diffpatch bug is listed by CISA
CVE-2026-60004 lets a user with repository write access run commands as the Gitea service account. Fixed in 1.27.1 on 27 July 2026. CISA listed it on 25 August 2026. NVD scores it 9.8 and does not mention the write-access requirement.
Published 1h ago
Critical
NetScaler command execution is CVE-2026-88771
Citrix bulletin CTX697096 confirms unauthenticated command execution on NetScaler in the default configuration. CISA listed CVE-2026-88771 on 27 September 2026. A later alert with no CVE id is this bulletin, not a new unnumbered bug.
Published 1h ago
Critical
OpenOffice Java bug has no released fix
CVE-2026-59265 can run code when a person opens a crafted document in Apache OpenOffice 4.1.16 or earlier. There is no CVSS score, no KEV listing, and no finished 4.1.17 release.
Published 3h ago
High
NetScaler SAML memory overflow is being exploited
CVE-2026-88779 is in the CISA KEV catalog. Citrix limits it to SAML service-provider or identity-provider configurations and describes denial of service. Earlier NetScaler fixes do not close it.
Published 3h ago
HighActive ExploitationKEV0-day
NetScaler SAML memory overflow
DoS
Published 2d ago
CriticalActive ExploitationKEV0-day
NetScaler unauthenticated command execution
RCE
Published 8d ago
CriticalPoC Available
Visual Composer unauthenticated local file inclusion
Other
Published 11d ago
HighPoC Available
PostgreSQL fuzzystrmatch integer wraparound
RCE
Published 13 Aug 2026
CriticalActive ExploitationKEV
Gitea diffpatch Git hook code execution
RCE
Published 27 Jul 2026
CriticalActive ExploitationKEV0-day
PAN-OS GlobalProtect command injection
RCE
Published 12 Apr 2024
CriticalExploit Available
xz Utils supply-chain backdoor
Supply chain
Published 29 Mar 2024
CriticalActive ExploitationKEV
Apache Log4j JNDI remote code execution
RCE
Published 10 Dec 2021