The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2026-86724: Cross-Site Request Forgery (CSRF)6.5 Medium7.1 High0%Sep 8, 2026
CVE-2026-86719: Cross-Site Request Forgery (CSRF)5.4 Medium5.3 Medium0%Sep 8, 2026
CVE-2026-86718: Cross-Site Request Forgery (CSRF)7.1 High7.1 High0%Sep 8, 2026
CVE-2026-86135: Cross-Site Request Forgery (CSRF)N/A7.0 High0%Sep 8, 2026
CVE-2026-84282: Undefined Security Weakness6.5 MediumN/A0%Sep 8, 2026
CVE-2026-83527: Authentication Bypass Using an Alternate Path or Channel8.1 HighN/A1%Sep 8, 2026
CVE-2026-61517: Improper Neutralization of Special Elements used in an OS Command7.2 High8.6 High2%Sep 8, 2026
CVE-2026-61516: Insufficiently Protected Credentials9.8 Critical9.3 Critical0%Sep 8, 2026
CVE-2026-74239: Improper Limitation of a Pathname to a Restricted Directory7.2 High8.6 High1%Sep 8, 2026
CVE-2026-73318: Incorrect Authorization3.8 Low5.1 Medium0%Sep 8, 2026
CVE-2026-73317: Incorrect Authorization2.7 Low5.1 Medium0%Sep 8, 2026
CVE-2026-17509: Improper Neutralization of Special Elements used in an SQL Command6.5 MediumN/A0%Sep 8, 2026
CVE-2026-85400: Missing AuthorizationN/A7.5 High0%Sep 8, 2026
CVE-2026-62650: Authentication Bypass Using an Alternate Path or Channel8.8 High8.7 High0%Sep 8, 2026
CVE-2026-76561: Improper Neutralization of Special Elements used in an OS Command7.2 HighN/A1%Sep 8, 2026
CVE-2026-76968: Exposure of Sensitive System Information to an Unauthorized Control Sphere6.5 MediumN/A0%Sep 8, 2026
CVE-2026-86438: Missing Authorization7.2 High8.6 High1%Sep 7, 2026
CVE-2026-86437: Incorrect Authorization7.2 High8.6 High0%Sep 7, 2026
CVE-2026-86497: Insertion of Sensitive Information Into Sent Data6.8 MediumN/A0%Sep 7, 2026
CVE-2026-19843: Improper Neutralization of Special Elements used in an OS Command8.4 HighN/A0%Sep 7, 2026
CVE-2026-14444: Improper Privilege Management7.5 HighN/A0%Sep 7, 2026
CVE-2026-86426: Improper Authentication9.8 Critical9.2 Critical1%Sep 7, 2026
CVE-2026-86417: Exposure of Sensitive Information to an Unauthorized Actor4.3 Medium5.3 Medium0%Sep 7, 2026
CVE-2026-86408: Missing Authorization6.5 Medium7.1 High0%Sep 7, 2026
CVE-2026-76578: Missing Authentication for Critical Function9.8 CriticalN/A1%Sep 7, 2026
1001-1025 of 17376