Skip to content
Rapid7 Vulnerability & Exploit Database

Rapid7 Vulnerability & Exploit Database

Rapid7 • September 28, 2026

Zero-Day Exploitation of Citrix NetScaler ADC and Gateway: CVE-2026-88771 and CVE-2026-88772

Zero-Day Exploitation of Citrix NetScaler ADC and Gateway: CVE-2026-88771 and CVE-2026-88772

Critical Unauthenticated RCE in F5 BIG-IP APM

Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild

Critical GitLab Path Traversal Exploited in the Wild

Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild

PaperCut NG/MF Critical Zero-Day Exploited in the Wild

Critical Unauthenticated RCE in F5 BIG-IP APM

Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild

Critical GitLab Path Traversal Exploited in the Wild

Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild

PaperCut NG/MF Critical Zero-Day Exploited in the Wild

CVE-2018-16356: Improper Neutralization of Special Elements used in an SQL Command

CVE-2020-8778: Improper Neutralization of Input During Web Page Generation

CVE-2020-8777: Improper Neutralization of Input During Web Page Generation

CVE-2020-8776: Improper Neutralization of Input During Web Page Generation

CVE-2018-15820: Improper Neutralization of Input During Web Page Generation

CVE-2019-19608: Improper Neutralization of Special Elements used in an SQL Command

CVE-2019-19607: Improper Neutralization of Special Elements used in an SQL Command

CVE-2019-19371: Improper Neutralization of Input During Web Page Generation

CVE-2019-19370: Improper Neutralization of Input During Web Page Generation

CVE-2019-18863: Inadequate Encryption Strength

CVE-2020-8013: Improper Link Resolution Before File Access

CVE-2018-14384: Improper Neutralization of Input During Web Page Generation

CVE-2019-14892: Deserialization of Untrusted Data

CVE-2020-1731: Predictable from Observable State

CVE-2019-18901: Improper Link Resolution Before File Access

CVE-2018-11675: Undefined Security Weakness

CVE-2015-1583: Cross-Site Request Forgery (CSRF)

CVE-2020-6764: Undefined Security Weakness

CVE-2019-18897: Improper Link Resolution Before File Access

CVE-2020-5249: Improper Neutralization of CRLF Sequences in HTTP Headers