The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2026-77582: tinyauthapp tinyauth: Tinyauth is an authentication and authorization serverN/A6.9 Medium0%Sep 21, 2026
CVE-2026-77561: tinyauthapp tinyauth: Tinyauth is an authentication and authorization server5.3 MediumN/A0%Sep 21, 2026
CVE-2026-77560: tinyauthapp tinyauth: Tinyauth is an authentication and authorization server8.1 HighN/A0%Sep 21, 2026
CVE-2026-76898: jgraph drawio: draw.io is a configurable diagramming and whiteboarding applicationN/A7.7 High0%Sep 21, 2026
CVE-2026-63416: jgraph drawio: draw.io is a configurable diagramming and whiteboarding application3.7 LowN/A0%Sep 21, 2026
CVE-2026-63373: jgraph drawio: draw.io is a configurable diagramming and whiteboarding application4.2 MediumN/A0%Sep 21, 2026
CVE-2026-63334: jgraph drawio: draw.io is a configurable diagramming and whiteboarding application6.8 MediumN/A0%Sep 21, 2026
CVE-2026-63116: deepstreamIO deepstream.io: deepstream is a server that allows clients and backend services to sync data, send messages and make rpcs at scale8.8 HighN/A0%Sep 21, 2026
CVE-2026-62987: fabiolb fabio: Fabio is an HTTP(S) and TCP router for deploying applications managed by consul5.8 MediumN/A0%Sep 21, 2026
CVE-2026-62866: TomWright dasel: Dasel is a command-line tool and library for querying, modifying, and transforming data structures6.2 MediumN/A0%Sep 21, 2026
CVE-2026-62371: kubeedge: KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at…8.8 HighN/A0%Sep 21, 2026
CVE-2026-62370: kubeedge: KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at…6.5 MediumN/A1%Sep 21, 2026
CVE-2026-61674: fluent fluent-bit: Fluent Bit is a fast and lightweight logs, metrics, and traces processor for Linux, BSD, macOS, and WindowsN/A9.2 Critical1%Sep 21, 2026
CVE-2026-59168: TomWright dasel: Dasel is a command-line tool and library for querying, modifying, and transforming data structures6.2 MediumN/A0%Sep 21, 2026
CVE-2026-58504: jgraph drawio: draw.io is a configurable diagramming and whiteboarding application6.1 MediumN/A0%Sep 21, 2026
CVE-2026-17051: zephyrproject zephyr: The Intel SEDI IPM (inter-processor mailbox) driver in drivers/ipm/ipm_sedi.c handles an inbound message interrupt in…6.0 MediumN/A0%Sep 21, 2026
CVE-2026-17050: zephyrproject zephyr: The experimental USB host stack allocates a per-device configuration-descriptor buffer, udev->cfg_desc, from the…5.7 MediumN/A0%Sep 21, 2026
CVE-2026-88978: hatchet-dev hatchet: Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale4.3 MediumN/A0%Sep 21, 2026
CVE-2026-85751: Mailu: Mailu is a mail server distributed as a set of Docker images9.8 CriticalN/A1%Sep 21, 2026
CVE-2026-84298: hatchet-dev hatchet: Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale3.1 LowN/A0%Sep 21, 2026
CVE-2026-82412: ntop ntopng: ntopng is a web-based network traffic monitoring application8.8 HighN/A0%Sep 21, 2026
CVE-2026-77166: Nextcloud Collectives: The emoji field in the page emoji update endpoint does not properly validate user input2.4 LowN/A0%Sep 21, 2026
CVE-2026-77165: Nextcloud Server: File owners were unable to unlock TYPE_TOKEN locks placed by other users, leaving files permanently locked with no…6.5 MediumN/A0%Sep 21, 2026
CVE-2026-63342: hatchet-dev hatchet: Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale6.3 MediumN/A0%Sep 21, 2026
CVE-2026-61687: hatchet-dev hatchet: Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale7.1 HighN/A0%Sep 21, 2026
326-350 of 391577