The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2026-92081: fastify is a fast and low-overhead web framework for Node.js5.9 MediumN/AN/ASep 16, 2026
CVE-2026-89792: In the Linux kernel, the following vulnerability has been resolved: ksmbd: prevent out-of-bounds reads in share config…N/AN/AN/ASep 16, 2026
CVE-2026-89791: In the Linux kernel, the following vulnerability has been resolved: perf: Fix use-after-free when perf mmap() revival…N/AN/AN/ASep 16, 2026
CVE-2026-89790: In the Linux kernel, the following vulnerability has been resolved: ipv6: avoid divide by zero in…N/AN/AN/ASep 16, 2026
CVE-2026-89789: In the Linux kernel, the following vulnerability has been resolved: gtp: add synchronize_net() in gtp_newlink() error…N/AN/AN/ASep 16, 2026
CVE-2026-89788: In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix tree connection use-after-free in…N/AN/AN/ASep 16, 2026
CVE-2026-89787: In the Linux kernel, the following vulnerability has been resolved: ext4: check dir entry fits before reading the hash…N/AN/AN/ASep 16, 2026
CVE-2026-89786: In the Linux kernel, the following vulnerability has been resolved: ext4: fix out-of-bounds read in…N/AN/AN/ASep 16, 2026
CVE-2026-89785: In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix out-of-bounds read of INDEX_ROOT in…N/AN/AN/ASep 16, 2026
CVE-2026-89784: In the Linux kernel, the following vulnerability has been resolved: SUNRPC: check rpc_sockaddr2uaddr() return value in…N/AN/AN/ASep 16, 2026
CVE-2026-89783: In the Linux kernel, the following vulnerability has been resolved: xfrm6: fix out-of-bounds write in…N/AN/AN/ASep 16, 2026
CVE-2026-89782: In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: reject restart table growth beyond…N/AN/AN/ASep 16, 2026
CVE-2026-89781: In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix out-of-bounds read in…N/AN/AN/ASep 16, 2026
CVE-2026-89780: In the Linux kernel, the following vulnerability has been resolved: net: qualcomm: rmnet: restore skb->dev on…N/AN/AN/ASep 16, 2026
CVE-2026-89779: In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: validate ef->size covers the record's…N/AN/AN/ASep 16, 2026
CVE-2026-89778: In the Linux kernel, the following vulnerability has been resolved: isofs: fix out-of-bounds page array access on empty…N/AN/AN/ASep 16, 2026
CVE-2026-89777: In the Linux kernel, the following vulnerability has been resolved: vfio/pci: clear vdev->msi_perm after freeing it on…N/AN/AN/ASep 16, 2026
CVE-2026-89776: In the Linux kernel, the following vulnerability has been resolved: vxlan: vnifilter: enforce exact length of…N/AN/AN/ASep 16, 2026
CVE-2026-89775: In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Handle negative S1 walk levels in VNCR…N/AN/AN/ASep 16, 2026
CVE-2026-89774: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SCO: hold sk properly in sco_conn_ready…N/AN/AN/ASep 16, 2026
CVE-2026-89186: Use of Cache Containing Sensitive InformationN/A6.3 MediumN/ASep 16, 2026
CVE-2026-88255: Improper Validation of Unsafe Equivalence in InputN/A6.3 MediumN/ASep 16, 2026
CVE-2026-86465: Authorization Bypass Through User-Controlled KeyN/AN/AN/ASep 16, 2026
CVE-2026-86462: Insufficient Session ExpirationN/AN/AN/ASep 16, 2026
CVE-2026-86338: Insufficient Granularity of Access ControlN/A6.0 MediumN/ASep 16, 2026
1-25 of 398637