Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
A critical remote code execution vulnerability in Microsoft Windows Internet Key Exchange (IKE), tracked as CVE-2026-33824, is being actively exploited. This double-free memory corruption issue affects all supported versions of Windows 10, Windows 11, and Windows Server. Attackers can exploit the vu...
A critical vulnerability in VMware vCenter, tracked as CVE-2026-59310, is being actively exploited, allowing attackers to execute arbitrary code via a path traversal flaw in the Syslog Server. This vulnerability, disclosed on July 30, 2026, was added to CISA's Known Exploited Vulnerabilities Catalog...
Two significant zero-day vulnerabilities have emerged, affecting VMware vCenter and Cisco ASA/FTD systems. CVE-2026-59310, published on July 30, 2026, is actively exploited in 47 nations, with a proof-of-concept released on August 17, 2026. Meanwhile, CVE-2026-20349, disclosed on August 11, 2026, is...
On September 15, 2026, CISA confirmed that ransomware gangs are actively exploiting a critical remote code execution vulnerability in VMware vCenter Server, tracked as CVE-2026-59310, which has a CVSS score of 9.8. This flaw, residing in the vCenter Syslog server, allows unauthenticated attackers wi...