CODE RED

PUBLIC CYBER SECURITY MONITOR

Know what needs
your attention.

Source-backed advisories. Deterministic severity. Human review for claims.

85 advisories

P5Verified

CVE-2023-2976 in com.google.guava:guava - Patched by Root

CVE-2023-2976 · com.google.guava:guava

CVE-2023-2976 affects com.google.guava:guava. EPSS 0.00248 (percentile 0.1458), scored 2026-10-03. Fixed version: 28.2-jre-aikido.3. Fixed version: 28.2-jre-aikido.4. Fixed version: 31.1-android-aikido.1. Fixed version: 21.0-aikido.1. Fixed version: 30.1.1-jre-aikido.1. Fixed version: 21.0-aikido.2. Fixed version: 30.1-jre-aikido.1. Fixed version: 31.0.1-jre-aikido.1. Fixed version: 30.1.1-jre-aikido.2. Fixed version: 31.1-android-aikido.2. Fixed version: 31.0.1-jre-aikido.2. Fixed version: 30.1-jre-aikido.2. Fixed version: 28.2-jre-root.io.1. Fixed version: 28.2-jre-root.io.2.

EPSS 0.00248 · KEV no · 2026-10-04 09:27:46.047644+00:00 · OSV.dev

P5Verified

PyJWT: ReDoS vulnerability when calling the `is_pem_format` function.

CVE-2026-102270 · azl3 python-jwt 2.13.0-1 on Azure Linux 3.0

CVE-2026-102270 affects azl3 python-jwt 2.13.0-1 on Azure Linux 3.0. CVSS base score 4.4 (msrc). EPSS 0.00192 (percentile 0.07997), scored 2026-10-03. Fixed version: 2.13.0-1+e2. Fixed version: 2.14.0.

CVSS 4.4 · EPSS 0.00192 · KEV no · 2026-10-04 07:08:49.022374+00:00 · Microsoft MSRC Security Update Guide (CVRF), OSV.dev

P4Verified

PyJWT: Asymmetric-PEM detection bypass: whitespace/line-ending-mutated public keys skip the HS/asymmetric confusion guard

CVE-2026-102268 · azl3 python-jwt 2.13.0-1 on Azure Linux 3.0

CVE-2026-102268 affects azl3 python-jwt 2.13.0-1 on Azure Linux 3.0. CVSS base score 9.1 (msrc). EPSS 0.00196 (percentile 0.08369), scored 2026-10-03. Fixed version: 2.13.0-1+e2. Fixed version: 2.14.0.

CVSS 9.1 · EPSS 0.00196 · KEV no · 2026-10-04 07:08:49.022374+00:00 · Microsoft MSRC Security Update Guide (CVRF), OSV.dev

P5Verified

BELL-CVE-2026-98164

CVE-2026-98164 · linux-lts

CVE-2026-98164 affects linux-lts. EPSS 0.00145 (percentile 0.03216), scored 2026-10-03. Fixed version: 6.12.111-r0. Fixed version: 6.18.53-r0.

EPSS 0.00145 · KEV no · 2026-10-04 08:10:59.885464+00:00 · OSV.dev

P5Verified

BELL-CVE-2026-98162

CVE-2026-98162 ·

CVE-2026-98162. EPSS 0.001 (percentile 0.00799), scored 2026-10-03.

EPSS 0.001 · KEV no · 2026-10-04 08:10:59.885464+00:00 · OSV.dev

P5Verified

BELL-CVE-2026-98160

CVE-2026-98160 · linux-lts

CVE-2026-98160 affects linux-lts. EPSS 0.00114 (percentile 0.01358), scored 2026-10-03. Fixed version: 6.12.111-r0. Fixed version: 6.18.53-r0.

EPSS 0.00114 · KEV no · 2026-10-04 08:10:59.885464+00:00 · OSV.dev

P5Verified

BELL-CVE-2026-98152

CVE-2026-98152 · linux-lts

CVE-2026-98152 affects linux-lts. EPSS 0.00114 (percentile 0.01346), scored 2026-10-03. Fixed version: 6.12.111-r0. Fixed version: 6.18.53-r0.

EPSS 0.00114 · KEV no · 2026-10-04 08:10:59.885464+00:00 · OSV.dev

P5Verified

BELL-CVE-2026-98062

CVE-2026-98062 · linux-lts

CVE-2026-98062 affects linux-lts. EPSS 0.00121 (percentile 0.0167), scored 2026-10-03. Fixed version: 6.18.53-r0.

EPSS 0.00121 · KEV no · 2026-10-04 08:10:59.885464+00:00 · OSV.dev

P5Verified

UTMStack < 11.2.16 SSRF via IdentityProviderService

CVE-2026-82040 ·

CVE-2026-82040. EPSS 0.00193 (percentile 0.08089), scored 2026-10-03. Fixed version: a310ff00d4f699cf0ae687573f43b69ad9906cdb. Fixed version: 4e7a727c3b8d8e2ad020d3b4f982a6d085dbecdd.

EPSS 0.00193 · KEV no · 2026-10-04 08:10:59.885464+00:00 · OSV.dev

P5Verified

CVE-2026-79113

CVE-2026-79113 ·

CVE-2026-79113. EPSS 0.0014 (percentile 0.02781), scored 2026-10-03. Fixed version: 9cd81ac7b99b5149580460c259bdfff73157607e. Fixed version: b5cc54bc786040ba3ac54020e7320e0add51e107.

EPSS 0.0014 · KEV no · 2026-10-04 08:10:59.885464+00:00 · OSV.dev

P5Verified

BELL-CVE-2026-64001

CVE-2026-64001 · linux-lts

CVE-2026-64001 affects linux-lts. EPSS 0.00129 (percentile 0.02132), scored 2026-10-03. Fixed version: 6.12.95-r0. Fixed version: 6.18.35-r1.

EPSS 0.00129 · KEV no · 2026-10-04 08:10:59.885464+00:00 · OSV.dev

P5Verified

BELL-CVE-2026-63973

CVE-2026-63973 · linux-lts

CVE-2026-63973 affects linux-lts. EPSS 0.0016 (percentile 0.04517), scored 2026-10-03. Fixed version: 6.1.177-r0. Fixed version: 6.12.95-r0. Fixed version: 6.18.35-r1.

EPSS 0.0016 · KEV no · 2026-10-04 08:10:59.885464+00:00 · OSV.dev

P5Verified

CVE-2026-51936

CVE-2026-51936 ·

CVE-2026-51936. EPSS 0.0018 (percentile 0.0681), scored 2026-10-03. Fixed version: 0b4d16090a71579c4c88220b7fb67bb7396f1434. Fixed version: 30842cda35c88cdfc7a8adba1c9b20821d2c08d1.

EPSS 0.0018 · KEV no · 2026-10-04 08:10:59.885464+00:00 · OSV.dev

P5Verified

Electron: Sandboxed preload code cache can be poisoned by a compromised renderer

CVE-2026-102677 ·

CVE-2026-102677. EPSS 0.0009 (percentile 0.00415), scored 2026-10-03. Fixed version: 9f0109679540320c5dc5b7bef0aa94733058e8c2. Fixed version: 87cd122b5de69555831cd752578b810dd6e504d8. Fixed version: d5940d84eb9a4c73cc6b0a0c20cbfd1cfe437fa2. Fixed version: 000453e399bd1dee5e86376cdd9ece5fc071e601. Fixed version: 25ba8be57c65a83d8c14ebb8aa37693df17a04f3. Fixed version: c38d6fd68756f04647ea857bdb6a2abec332e217.

EPSS 0.0009 · KEV no · 2026-10-04 08:10:59.885464+00:00 · OSV.dev

P5Verified

BELL-CVE-2026-100076

CVE-2026-100076 · linux-lts

CVE-2026-100076 affects linux-lts. EPSS 0.00112 (percentile 0.01278), scored 2026-10-03. Fixed version: 6.18.53-r0.

EPSS 0.00112 · KEV no · 2026-10-04 08:10:59.885464+00:00 · OSV.dev

P5Verified

UTMStack < 11.2.16 JPQL Injection via searchPropertyValues

CVE-2026-82045 ·

CVE-2026-82045. EPSS 0.00257 (percentile 0.15762), scored 2026-10-03. Fixed version: a310ff00d4f699cf0ae687573f43b69ad9906cdb. Fixed version: 4e7a727c3b8d8e2ad020d3b4f982a6d085dbecdd.

EPSS 0.00257 · KEV no · 2026-10-04 08:10:59.885464+00:00 · OSV.dev

P5Verified

UTMStack < 11.2.16 Server-Side Request Forgery via downloadPdf

CVE-2026-82044 ·

CVE-2026-82044. EPSS 0.00256 (percentile 0.15675), scored 2026-10-03. Fixed version: a310ff00d4f699cf0ae687573f43b69ad9906cdb. Fixed version: 4e7a727c3b8d8e2ad020d3b4f982a6d085dbecdd.

EPSS 0.00256 · KEV no · 2026-10-04 08:10:59.885464+00:00 · OSV.dev

P5Verified

UTMStack < 11.2.16 Account Enumeration via Password Reset Endpoint

CVE-2026-82043 ·

CVE-2026-82043. EPSS 0.00247 (percentile 0.14499), scored 2026-10-03. Fixed version: a310ff00d4f699cf0ae687573f43b69ad9906cdb. Fixed version: 4e7a727c3b8d8e2ad020d3b4f982a6d085dbecdd.

EPSS 0.00247 · KEV no · 2026-10-04 08:10:59.885464+00:00 · OSV.dev

P5Verified

UTMStack < 11.2.16 Authentication Bypass via InternalApiKeyFilter

CVE-2026-82042 ·

CVE-2026-82042. EPSS 0.00546 (percentile 0.4384), scored 2026-10-03. Fixed version: a310ff00d4f699cf0ae687573f43b69ad9906cdb. Fixed version: 4e7a727c3b8d8e2ad020d3b4f982a6d085dbecdd.

EPSS 0.00546 · KEV no · 2026-10-04 08:10:59.885464+00:00 · OSV.dev

P5Verified

UTMStack < 11.2.16 Missing Authorization via Command WebSocket

CVE-2026-82041 ·

CVE-2026-82041. EPSS 0.00439 (percentile 0.35936), scored 2026-10-03. Fixed version: a310ff00d4f699cf0ae687573f43b69ad9906cdb. Fixed version: 4e7a727c3b8d8e2ad020d3b4f982a6d085dbecdd.

EPSS 0.00439 · KEV no · 2026-10-04 08:10:59.885464+00:00 · OSV.dev

P5Verified

UTMStack < 11.2.16 SQL Injection via searchGroupsByFilter

CVE-2026-82039 ·

CVE-2026-82039. EPSS 0.00339 (percentile 0.25008), scored 2026-10-03. Fixed version: a310ff00d4f699cf0ae687573f43b69ad9906cdb. Fixed version: 4e7a727c3b8d8e2ad020d3b4f982a6d085dbecdd.

EPSS 0.00339 · KEV no · 2026-10-04 08:10:59.885464+00:00 · OSV.dev

P5Verified

U-Boot before 2026.10-rc5 Use-After-Free in lwIP wget Receive Callback

CVE-2026-74222 ·

CVE-2026-74222. EPSS 0.00303 (percentile 0.20907), scored 2026-10-03. Fixed version: a06e89ab05eaa2b8344d521319399333cd760ae5. Fixed version: 2d94618a58aeb7630f18eee33419ce48d0fd3616.

EPSS 0.00303 · KEV no · 2026-10-04 08:10:59.885464+00:00 · OSV.dev

P5Verified

Password-based KDF cost parameters honoured unbounded from untrusted input across the remaining PBE entry points

CVE-2026-17508 ·

CVE-2026-17508. EPSS 0.00436 (percentile 0.35644), scored 2026-10-03. Fixed version: eacda831fbe15b272933e40841d8b0827b556fae. Fixed version: 20ed9e203caec91d25cd386ceb6d364e9b068f67. Fixed version: 442393bf187c914b1e66fbed4fab532a1fe06c6a. Fixed version: 480d878aa6f7dc8b20403064f304bbe0decbbb1a. Fixed version: 766a31026ac24ed3c6cad8662058ba450c338da1. Fixed version: 882fdab53f6c4c150a5d6a4e6ef1fc05d382385a. Fixed version: e72bc0681ff4227fced912ef7394daf7b7d57bb3. Fixed version: 43d27611d3b82e54050d1def60b516f8295e485b.

EPSS 0.00436 · KEV no · 2026-10-04 08:10:59.885464+00:00 · OSV.dev

P5Verified

BELL-CVE-2026-15806

CVE-2026-15806 · python3

CVE-2026-15806 affects python3. EPSS 0.00464 (percentile 0.37967), scored 2026-10-03. Fixed version: 3.11.17-r0. Fixed version: 3.12.15-r0. Fixed version: 3.14.8-r3. Fixed version: 3.11.17-r0. Fixed version: 3.12.15-r0. Fixed version: 3.14.8-r3.

EPSS 0.00464 · KEV no · 2026-10-04 08:10:59.885464+00:00 · OSV.dev

P5Verified

CVE-2026-104480

CVE-2026-104480 ·

CVE-2026-104480. EPSS 0.00397 (percentile 0.31597), scored 2026-10-03. Fixed version: 9686fbaea864aa19f0675e486672b6a77811b6a1.

EPSS 0.00397 · KEV no · 2026-10-04 08:10:59.885464+00:00 · OSV.dev

P5Verified

Mooncake before 0.3.12 Out-of-Bounds Read via P2P Handshake readString

CVE-2026-104433 ·

CVE-2026-104433. EPSS 0.00366 (percentile 0.28161), scored 2026-10-03. Fixed version: c7ae97fd24251ed0aaaa613e8251859f170f1ae7. Fixed version: c142b40590259360196d8e504b2193382529e7b4.

EPSS 0.00366 · KEV no · 2026-10-04 08:10:59.885464+00:00 · OSV.dev

P5Verified

Capacitor Android and iOS: remote content can be loaded at the app origin via the internal HTTP proxy path

CVE-2026-103922 ·

CVE-2026-103922. EPSS 0.00213 (percentile 0.10517), scored 2026-10-03. Fixed version: 4d377eb2d3eabf83f9e6d1c07cb50d92c06db523. Fixed version: 60a677eae8bb27667e8c5c518b38e855c7228968. Fixed version: 82428936581035795b1640e60dc92b2a8d5eeed3. Fixed version: 0c9e35dec13a99ec4a582a2edc536cbec96bf27d. Fixed version: 430356a91e1419fc66862dc09835081aa501677e. Fixed version: 80b6c5e81d062e1e158914040f49e044d95b7ccb. Fixed version: 85ccc44151fdd5ae5e0d806d875766ef4b84ad5d. Fixed version: af9a287fef45f0ac68ce640cb42fed2d06b0f1b4. Fixed version: d5e3170ba0ff155fc542b7e6d16cff5201406540.

EPSS 0.00213 · KEV no · 2026-10-04 08:10:59.885464+00:00 · OSV.dev

P5Verified

pgvector buffer overflow in IVFFlat index build

CVE-2026-103484 ·

CVE-2026-103484. EPSS 0.00422 (percentile 0.34325), scored 2026-10-03. Fixed version: ee00d39ab30c2a7cf9510abf9288c624d91db156.

EPSS 0.00422 · KEV no · 2026-10-04 08:10:59.885464+00:00 · OSV.dev

P5Verified

PX4 Autopilot through 1.17.0 NULL Pointer Dereference via sd_stress

CVE-2026-102808 ·

CVE-2026-102808. EPSS 0.00244 (percentile 0.14145), scored 2026-10-03. Fixed version: d6f12ad1c4f70ad3230afd7d86e971421e02fef4. Fixed version: c865dc9fde14d1391916775153aa271603c3c592.

EPSS 0.00244 · KEV no · 2026-10-04 08:10:59.885464+00:00 · OSV.dev

P5Verified

Netty 4.2.11 through 4.2.17 QUIC Hostname Verification Bypass

CVE-2026-100665 ·

CVE-2026-100665. EPSS 0.00291 (percentile 0.19642), scored 2026-10-03. Fixed version: 2521f494432e27415a567d3a81a9eb907abf20b3. Fixed version: 09e72c4fd8007277121ed48db63a124b112b96fe. Fixed version: 994e887ed9.

EPSS 0.00291 · KEV no · 2026-10-04 08:10:59.885464+00:00 · OSV.dev

P5Verified

CVE-2021-40828

CVE-2021-40828 ·

CVE-2021-40828. EPSS 0.00411 (percentile 0.32984), scored 2026-10-03. Fixed version: 81aee4c69ca8b7d61b5eb9c1e658af568f81bccc.

EPSS 0.00411 · KEV no · 2026-10-04 08:10:59.885464+00:00 · OSV.dev

P5Verified

CVE-2018-13407

CVE-2018-13407 ·

CVE-2018-13407. EPSS 0.00384 (percentile 0.3007), scored 2026-10-03. Fixed version: 3b2a1a41d7a3b45c6d16e91e953e83149370d5b9.

EPSS 0.00384 · KEV no · 2026-10-04 08:10:59.885464+00:00 · OSV.dev

P5Verified

CVE-2018-11349

CVE-2018-11349 ·

CVE-2018-11349. EPSS 0.00523 (percentile 0.42315), scored 2026-10-03. Fixed version: 3b2a1a41d7a3b45c6d16e91e953e83149370d5b9.

EPSS 0.00523 · KEV no · 2026-10-04 08:10:59.885464+00:00 · OSV.dev

P5Verified

DEBIAN-CVE-2026-79310

CVE-2026-79310 ·

CVE-2026-79310. EPSS 0.00716 (percentile 0.52155), scored 2026-10-03.

EPSS 0.00716 · KEV no · 2026-10-04 08:10:59.885464+00:00 · OSV.dev

P5Verified

BELL-CVE-2026-17084

CVE-2026-17084 · python3

CVE-2026-17084 affects python3. EPSS 0.00721 (percentile 0.52331), scored 2026-10-03. Fixed version: 3.11.17-r0. Fixed version: 3.12.15-r0. Fixed version: 3.14.8-r3. Fixed version: 3.11.17-r0. Fixed version: 3.12.15-r0. Fixed version: 3.14.8-r3.

EPSS 0.00721 · KEV no · 2026-10-04 08:10:59.885464+00:00 · OSV.dev

P5Verified

CVE-2021-40824

CVE-2021-40824 ·

CVE-2021-40824. EPSS 0.00662 (percentile 0.49922), scored 2026-10-03. Fixed version: 672cf1a46ed84766a5d772169d50afacba23286d. Fixed version: fed6f406354dbca41402378d380efceba19d80f4.

EPSS 0.00662 · KEV no · 2026-10-04 08:10:59.885464+00:00 · OSV.dev

P5Verified

CVE-2020-15151

CVE-2020-15151 ·

CVE-2020-15151. EPSS 0.00931 (percentile 0.59294), scored 2026-10-03. Fixed version: f77f7ee16d7613b956775c014cf9d6c729e44578. Fixed version: e878064ce20a0cdb2049598d2d362b48d6b6e866. Fixed version: 7c526bc6a6a51b57a1bab4c60f104dc36cde347a.

EPSS 0.00931 · KEV no · 2026-10-04 08:10:59.885464+00:00 · OSV.dev

P5Verified

CVE-2018-13409

CVE-2018-13409 ·

CVE-2018-13409. EPSS 0.00707 (percentile 0.51775), scored 2026-10-03. Fixed version: 3b2a1a41d7a3b45c6d16e91e953e83149370d5b9.

EPSS 0.00707 · KEV no · 2026-10-04 08:10:59.885464+00:00 · OSV.dev

P5Verified

CVE-2018-13408

CVE-2018-13408 ·

CVE-2018-13408. EPSS 0.00707 (percentile 0.51775), scored 2026-10-03. Fixed version: 3b2a1a41d7a3b45c6d16e91e953e83149370d5b9.

EPSS 0.00707 · KEV no · 2026-10-04 08:10:59.885464+00:00 · OSV.dev

P5Verified

CVE-2018-11350

CVE-2018-11350 ·

CVE-2018-11350. EPSS 0.00712 (percentile 0.51975), scored 2026-10-03. Fixed version: 3b2a1a41d7a3b45c6d16e91e953e83149370d5b9.

EPSS 0.00712 · KEV no · 2026-10-04 08:10:59.885464+00:00 · OSV.dev

P5Verified

DEBIAN-CVE-2023-46120

CVE-2023-46120 ·

CVE-2023-46120. EPSS 0.01061 (percentile 0.63367), scored 2026-10-03.

EPSS 0.01061 · KEV no · 2026-10-04 08:10:59.885464+00:00 · OSV.dev

P5Verified

CVE-2020-8664

CVE-2020-8664 ·

CVE-2020-8664. EPSS 0.013 (percentile 0.69455), scored 2026-10-03.

EPSS 0.013 · KEV no · 2026-10-04 08:10:59.885464+00:00 · OSV.dev

P5Verified

CVE-2018-11351

CVE-2018-11351 ·

CVE-2018-11351. EPSS 0.01208 (percentile 0.67333), scored 2026-10-03. Fixed version: 3b2a1a41d7a3b45c6d16e91e953e83149370d5b9.

EPSS 0.01208 · KEV no · 2026-10-04 08:10:59.885464+00:00 · OSV.dev

P5Verified

CVE-2022-0891

CVE-2022-0891 ·

CVE-2022-0891. EPSS 0.01542 (percentile 0.74074), scored 2026-10-03. Fixed version: 232282fd8f9c21eefe8d2d2b96cdbbb172fe7b7c.

EPSS 0.01542 · KEV no · 2026-10-04 08:10:59.885464+00:00 · OSV.dev

P5Verified

CVE-2017-1000190

CVE-2017-1000190 ·

CVE-2017-1000190. EPSS 0.0466 (percentile 0.91477), scored 2026-10-03.

EPSS 0.0466 · KEV no · 2026-10-04 08:10:59.885464+00:00 · OSV.dev

P4Verified

CVE-2023-44487

CVE-2023-44487 ·

CVE-2023-44487. EPSS 0.99999 (percentile 0.99998), scored 2026-10-03. Fixed version: 1a3b131141fed9468d9da1167c7fcb37902935ed. Fixed version: a7081f551473ba57ace1d5e10c8cf486c1e715a1. Fixed version: 1a6238dbb383b68833499b4425342900e8fd6abd. Fixed version: 8048373d9a8bd8c7237829b56a06485d5f5bf2e4. Fixed version: 71e101bb37497f730078d9afe1991b60d10bfe96. Fixed version: 796ffd3a329b4b1f2ec0dd51158e62c94914c4ca. Fixed version: b4e3c73354d2a104ed6f00379eeb9f121a85e8bb. Fixed version: 3798fe5f1564f27461390b4f6163f6ddfb21fd2d. Fixed version: 7e11c65e70778a3c6757dab45b56e579c539050b.

EPSS 0.99999 · KEV no · 2026-10-04 08:10:59.885464+00:00 · OSV.dev

P5Verified

Missing Authorization Check in Vaadin Spreadsheet Allows Cell Comments to Be Written to Protected Sheets and Locked Cells

CVE-2026-93547 ·

CVE-2026-93547. EPSS 0.00363 (percentile 0.27816), scored 2026-10-03. Fixed version: 41da1428d6c458919f7effaeca8b8317d2d1bc74. Fixed version: 7e3951a1ef87880b6994dc69966c5969dd730c8a. Fixed version: b2210855d02d7e09d2e4c2b27bfe4f3f0ce99ae3. Fixed version: 47cf689e61827dc711be69dba6a9d8d04b74a375. Fixed version: 8c5c6348444a0b10a0d6e00f9a7490a8a3b63d18.

EPSS 0.00363 · KEV no · 2026-10-04 07:06:47.357040+00:00 · OSV.dev

P5Verified

xdg-dbus-proxy: message filtering bypass via reply serial allows sandbox escape

CVE-2026-94422 ·

CVE-2026-94422. EPSS 0.00693 (percentile 0.5125), scored 2026-10-03. Fixed version: 72b40c8f6d9d585cfbdb249690724f740d207087. Fixed version: e4465a0dfe96da3b39929a30a1ac3a22b16223e3. Fixed version: e5702fca4dba9600721921fbca2dbc39dc5ca400. Fixed version: fc027f759316fb2a6c45648200b6f100202eb84e.

EPSS 0.00693 · KEV no · 2026-10-04 07:06:47.357040+00:00 · OSV.dev

P1Verified

Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability

CVE-2026-67279 · MikroTik RouterOS

CVE-2026-67279 affects MikroTik RouterOS. EPSS 0.01027 (percentile 0.62388), scored 2026-10-03. Listed in CISA KEV, added 2026-09-25.

EPSS 0.01027 · KEV yes · 2026-10-04 05:55:03.893835+00:00 · CISA Known Exploited Vulnerabilities Catalog (JSON), FIRST EPSS daily exploit-probability

P1Verified

Microsoft SharePoint Code Injection Vulnerability

CVE-2026-65660 · Microsoft SharePoint

CVE-2026-65660 affects Microsoft SharePoint. EPSS 0.02101 (percentile 0.81063), scored 2026-10-03. Listed in CISA KEV, added 2026-09-25.

EPSS 0.02101 · KEV yes · 2026-10-04 05:55:03.893835+00:00 · CISA Known Exploited Vulnerabilities Catalog (JSON), FIRST EPSS daily exploit-probability

P1Verified

Google Pixel Improper Authorization Vulnerability

CVE-2026-58704 · Google Pixel

CVE-2026-58704 affects Google Pixel. EPSS 0.00591 (percentile 0.46391), scored 2026-10-03. Listed in CISA KEV, added 2026-09-16.

EPSS 0.00591 · KEV yes · 2026-10-04 05:55:03.893835+00:00 · CISA Known Exploited Vulnerabilities Catalog (JSON), FIRST EPSS daily exploit-probability

P1Verified

WSO2 Multiple Products Path Traversal Vulnerability

CVE-2026-5430 · WSO2 Multiple Products

CVE-2026-5430 affects WSO2 Multiple Products. EPSS 0.00588 (percentile 0.46253), scored 2026-10-03. Listed in CISA KEV, added 2026-09-24.

EPSS 0.00588 · KEV yes · 2026-10-04 05:55:03.893835+00:00 · CISA Known Exploited Vulnerabilities Catalog (JSON), FIRST EPSS daily exploit-probability

P1Verified

Linux Kernel Out-of-Bounds Write Vulnerability

CVE-2026-53266 · Linux Kernel

CVE-2026-53266 affects Linux Kernel. EPSS 0.00827 (percentile 0.55987), scored 2026-10-03. Listed in CISA KEV, added 2026-09-18.

EPSS 0.00827 · KEV yes · 2026-10-04 05:55:03.893835+00:00 · CISA Known Exploited Vulnerabilities Catalog (JSON), FIRST EPSS daily exploit-probability

P1Verified

Fortinet warns of critical FortiMail flaw exploited in zero-day attacks

CVE-2026-104286 · Fortinet FortiMail

CVE-2026-104286 affects Fortinet FortiMail. EPSS 0.02201 (percentile 0.81912), scored 2026-10-03. Listed in CISA KEV, added 2026-10-01.

EPSS 0.02201 · KEV yes · 2026-10-04 05:55:03.893835+00:00 · BleepingComputer, CISA Known Exploited Vulnerabilities Catalog (JSON), FIRST EPSS daily exploit-probability

P1Verified

Zammad GmbH Zammad Improper Privilege Management Vulnerability

CVE-2026-102490 · Zammad GmbH Zammad

CVE-2026-102490 affects Zammad GmbH Zammad. EPSS 0.00629 (percentile 0.48335), scored 2026-10-03. Listed in CISA KEV, added 2026-10-02.

EPSS 0.00629 · KEV yes · 2026-10-04 05:55:03.893835+00:00 · CISA Known Exploited Vulnerabilities Catalog (JSON), FIRST EPSS daily exploit-probability

P1Verified

Zammad GmbH Zammad Session Fixation Vulnerability

CVE-2026-102489 · Zammad GmbH Zammad

CVE-2026-102489 affects Zammad GmbH Zammad. EPSS 0.01396 (percentile 0.71464), scored 2026-10-03. Listed in CISA KEV, added 2026-10-02.

EPSS 0.01396 · KEV yes · 2026-10-04 05:55:03.893835+00:00 · CISA Known Exploited Vulnerabilities Catalog (JSON), FIRST EPSS daily exploit-probability

P1Verified

Linux Kernel Race Condition Vulnerability

CVE-2025-39964 · Linux Kernel

CVE-2025-39964 affects Linux Kernel. EPSS 0.00996 (percentile 0.61394), scored 2026-10-03. Listed in CISA KEV, added 2026-09-18.

EPSS 0.00996 · KEV yes · 2026-10-04 05:55:03.893835+00:00 · CISA Known Exploited Vulnerabilities Catalog (JSON), FIRST EPSS daily exploit-probability

P1Verified

Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability

CVE-2025-39682 · Linux Kernel

CVE-2025-39682 affects Linux Kernel. EPSS 0.0288 (percentile 0.86382), scored 2026-10-03. Listed in CISA KEV, added 2026-09-18.

EPSS 0.0288 · KEV yes · 2026-10-04 05:55:03.893835+00:00 · CISA Known Exploited Vulnerabilities Catalog (JSON), FIRST EPSS daily exploit-probability