The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2026-90054: Linux: In the Linux kernel, the following vulnerability has been resolved: tcp: fix corruption of urgent data on multi-segment…N/AN/AN/ASep 17, 2026
CVE-2026-90053: Linux: In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_htb: limit htb_classify inner-class…N/AN/AN/ASep 17, 2026
CVE-2026-90052: Linux: In the Linux kernel, the following vulnerability has been resolved: dm-integrity: fix buffer overflow with keyed…N/AN/AN/ASep 17, 2026
CVE-2026-90051: Linux: In the Linux kernel, the following vulnerability has been resolved: tcp: reject non zerocopy devmem tx Devmem tcp tx…N/AN/AN/ASep 17, 2026
CVE-2026-90050: Linux: In the Linux kernel, the following vulnerability has been resolved: net/sched: fq: clamp quantum and initial_quantum in…N/AN/AN/ASep 17, 2026
CVE-2026-8674: The GNU C Library glibc: Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search…5.3 MediumN/AN/ASep 17, 2026
CVE-2026-85720: AsyncHttpClient async-http-client: The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process…5.9 MediumN/AN/ASep 17, 2026
CVE-2026-85716: AsyncHttpClient async-http-client: The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process…3.7 LowN/AN/ASep 17, 2026
CVE-2026-54587: MidnightBSD mport: mport is the MidnightBSD Package ManagerN/A5.8 MediumN/ASep 17, 2026
CVE-2026-54586: MidnightBSD mport: mport is the MidnightBSD Package ManagerN/A6.0 MediumN/ASep 17, 2026
CVE-2026-54585: MidnightBSD mport: mport is the MidnightBSD Package ManagerN/A6.0 MediumN/ASep 17, 2026
CVE-2026-54583: MidnightBSD mport: mport is the MidnightBSD Package ManagerN/A8.3 HighN/ASep 17, 2026
CVE-2026-54582: MidnightBSD mport: mport is the MidnightBSD Package ManagerN/A6.0 MediumN/ASep 17, 2026
CVE-2026-54581: MidnightBSD mport: mport is the MidnightBSD Package ManagerN/A8.3 HighN/ASep 17, 2026
CVE-2026-54580: MidnightBSD mport: mport is the MidnightBSD Package ManagerN/A8.3 HighN/ASep 17, 2026
CVE-2026-54579: MidnightBSD mport: mport is the MidnightBSD Package ManagerN/A2.3 LowN/ASep 17, 2026
CVE-2026-54578: MidnightBSD mport: mport is the MidnightBSD Package ManagerN/A2.0 LowN/ASep 17, 2026
CVE-2026-54577: MidnightBSD mport: mport is the MidnightBSD Package ManagerN/A2.0 LowN/ASep 17, 2026
CVE-2026-54576: MidnightBSD mport: mport is the MidnightBSD Package ManagerN/A5.8 MediumN/ASep 17, 2026
CVE-2026-54575: MidnightBSD mport: mport is the MidnightBSD Package ManagerN/A5.8 MediumN/ASep 17, 2026
CVE-2026-28326: SolarWinds Access Rights Manager: SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability8.8 HighN/AN/ASep 17, 2026
CVE-2026-93015: BlueKitchen GmbH BTstack: BlueKitchen BTstack through 1.8.2 fails to validate the peer-reported endpoint count against table bounds in A2DP…6.3 Medium7.0 HighN/ASep 17, 2026
CVE-2026-93014: RosarioSIS: RosarioSIS versions before 12.9 fail to validate the filename request parameter in Users and Students modules, allowing…7.1 High7.1 HighN/ASep 17, 2026
CVE-2026-93013: infiniflow ragflow: RAGFlow through 0.27.2 contains a path traversal vulnerability in the dev_insert_chunks_from_file and…4.3 Medium5.3 MediumN/ASep 17, 2026
CVE-2026-92881: n/a vgmstream: A security vulnerability has been detected in vgmstream4.3 Medium5.3 MediumN/ASep 17, 2026
926-950 of 482177