The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2026-36468: n/a: Cross-site Scripting (XSS) in index.php in CuteNews v.2.1.2 allows remote unauthenticated attackers to supply an…6.1 MediumN/AN/ASep 21, 2026
CVE-2026-36467: n/a: Unrestricted Upload of File with Dangerous Type in core/modules/media.php in CuteNews v.2.1.2 allows remote…7.2 HighN/AN/ASep 21, 2026
CVE-2026-94301: Apache Software Foundation Apache MINA: The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via…9.8 CriticalN/AN/ASep 21, 2026
CVE-2026-94184: Red Hat: A stack-based buffer overflow flaw was found in fetchmail when built with NTLM support8.1 HighN/AN/ASep 21, 2026
CVE-2026-93339: Metaphor Creations Ditty: Metaphor Creations Ditty (ditty-news-ticker) before 3.1.70 contains a stored cross-site scripting vulnerability that…5.4 Medium5.1 MediumN/ASep 21, 2026
CVE-2026-86473: Apache Software Foundation Apache Airflow: Apache Airflow: the Core API logout endpoint revokes only a session token presented as the _token cookie9.1 CriticalN/AN/ASep 21, 2026
CVE-2026-82355: Apache Software Foundation Apache Airflow: When a request to the Airflow core API carries both a session cookie and an explicit `Authorization: Bearer` token,…4.2 MediumN/AN/ASep 21, 2026
CVE-2026-80110: Red Hat: A flaw was found in pki-core8.1 HighN/AN/ASep 21, 2026
CVE-2026-75939: Red Hat Red Hat OpenShift Container Platform 4: A flaw was found in openshift/oc-mirror7.4 HighN/AN/ASep 21, 2026
CVE-2026-75158: Apache Software Foundation Apache Airflow: Apache Airflow's `/assets/events` API returned asset events for every Dag in the deployment, with no filter restricting…4.3 MediumN/AN/ASep 21, 2026
CVE-2026-71543: openbao: OpenBao is an open source identity-based secrets management systemN/A7.5 HighN/ASep 21, 2026
CVE-2026-68919: gocd: GoCD is a continuous deliver serverN/A7.0 HighN/ASep 21, 2026
CVE-2026-61630: lucasdillmann nginx-ignition: nginx ignition is a user interface for the nginx web server4.2 MediumN/AN/ASep 21, 2026
CVE-2026-61629: lucasdillmann nginx-ignition: nginx ignition is a user interface for the nginx web server7.5 HighN/AN/ASep 21, 2026
CVE-2026-61628: lucasdillmann nginx-ignition: nginx ignition is a user interface for the nginx web server8.1 HighN/AN/ASep 21, 2026
CVE-2026-55870: gocd: GoCD is a continuous deliver serverN/A2.3 LowN/ASep 21, 2026
CVE-2026-55625: gocd: GoCD is a continuous deliver server4.9 MediumN/AN/ASep 21, 2026
CVE-2026-55567: bleachbit: BleachBit cleans files to free disk space and to maintain privacy7.8 HighN/AN/ASep 21, 2026
CVE-2026-55074: chofstede ansible_jailexec: Ansible FreeBSD Jail Connection Plugin is an Ansible connection plugin for FreeBSD Jails via jexecN/A8.2 HighN/ASep 21, 2026
CVE-2026-55071: SepineTam mcp-for-stata: MCP-for-Stata is a MCP server for integrating Stata into agent loops with a safety-first design8.4 HighN/AN/ASep 21, 2026
CVE-2026-55060: gocd: GoCD is a continuous deliver server3.7 LowN/AN/ASep 21, 2026
CVE-2026-54584: MidnightBSD mport: mport is the MidnightBSD Package ManagerN/A5.3 MediumN/ASep 21, 2026
CVE-2026-52743: gocd: GoCD is a continuous deliver server4.3 MediumN/AN/ASep 21, 2026
CVE-2026-52742: gocd: GoCD is a continuous deliver serverN/A5.1 MediumN/ASep 21, 2026
CVE-2026-52741: gocd: GoCD is a continuous deliver serverN/A7.5 HighN/ASep 21, 2026
276-300 of 788572