The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2026-89807: Undefined Security WeaknessN/AN/A0%Sep 16, 2026
CVE-2026-89806: Undefined Security Weakness8.4 HighN/A0%Sep 16, 2026
CVE-2026-89805: Undefined Security Weakness7.8 HighN/A0%Sep 16, 2026
CVE-2026-89804: Undefined Security Weakness8.8 HighN/A0%Sep 16, 2026
CVE-2026-89803: Undefined Security Weakness7.8 HighN/A0%Sep 16, 2026
CVE-2026-89802: Undefined Security WeaknessN/AN/A0%Sep 16, 2026
CVE-2026-89801: Undefined Security Weakness7.8 HighN/A0%Sep 16, 2026
CVE-2026-89800: Undefined Security WeaknessN/AN/A0%Sep 16, 2026
CVE-2026-89799: Undefined Security Weakness7.8 HighN/A0%Sep 16, 2026
CVE-2026-89798: Undefined Security WeaknessN/AN/A0%Sep 16, 2026
CVE-2026-89797: Undefined Security WeaknessN/AN/A0%Sep 16, 2026
CVE-2026-89796: Undefined Security WeaknessN/AN/A0%Sep 16, 2026
CVE-2026-89795: Undefined Security Weakness8.4 HighN/A0%Sep 16, 2026
CVE-2026-89794: Undefined Security WeaknessN/AN/A0%Sep 16, 2026
CVE-2026-86585: Improper Verification of Cryptographic SignatureN/A7.7 High0%Sep 16, 2026
CVE-2026-86107: Out-of-bounds Write5.9 Medium8.2 High0%Sep 16, 2026
CVE-2026-86106: Missing Authentication for Critical Function9.6 Critical8.7 High0%Sep 16, 2026
CVE-2026-14916: Improper Handling of Unexpected Data TypeN/A7.7 High1%Sep 16, 2026
CVE-2026-89793: Undefined Security Weakness7.8 HighN/A0%Sep 16, 2026
CVE-2026-86792: Use of Externally-Controlled Input to Select Classes or Code8.8 HighN/A1%Sep 16, 2026
CVE-2026-86474: Improper Certificate ValidationN/A7.7 High0%Sep 16, 2026
CVE-2026-86466: Origin Validation Error8.1 HighN/A0%Sep 16, 2026
CVE-2026-86443: Cleartext Storage of Sensitive InformationN/A6.9 Medium0%Sep 16, 2026
CVE-2026-85628: Cleartext Transmission of Sensitive InformationN/A7.0 High0%Sep 16, 2026
CVE-2026-84501: Improper Output Neutralization for Logs5.3 MediumN/A1%Sep 16, 2026
2751-2775 of 691462