#active exploitation
18 stories taggedactive exploitation.

Arista Says a VeloCloud Orchestrator Bug Is Already Being Exploited
A remote attacker with no login can reach privileged functions on the server that runs an entire SD-WAN network. On-prem customers using certificate authentication need to act now.

Hackers Are Actively Exploiting a Critical Flaw in Cisco's Email Security Appliance
A zero-day vulnerability in Cisco Secure Email Gateway lets an unauthenticated attacker run any command they like as the most powerful user on the system. No login required.

Hackers Are Forging Admin Tokens to Take Over WSO2 API Manager
A critical signature-verification bug tracked as CVE-2026-5430 lets attackers forge login tokens and seize administrator accounts. Exploitation is already under way.

Hackers Are Actively Exploiting a Critical Issabel Flaw That Hands Over Full Server Control
CVE-2026-89026 lets unauthenticated attackers run any command they want on vulnerable phone-system servers. Attacks are already happening.

CISA Flags Critical Oracle WebLogic Flaw as Attackers Hit Unpatched Servers
The bug, rated a perfect 10 on the severity scale, lets attackers reach sensitive data without needing a password.

Check Point Rushes Fix for SmartConsole Flaw Already Being Exploited
A critical authentication bypass in Check Point's management console let attackers walk past the login screen. The vendor confirms real-world attacks are already happening.

Third SharePoint Flaw From July Patch Batch Is Now Being Attacked
CVE-2026-50522 lets unauthenticated attackers run code on SharePoint servers. A public proof-of-concept dropped, and the exploitation followed.

Adobe ColdFusion flaw now under attack, Canada's cyber agency warns
A critical bug in Adobe's web platform is being exploited days after patches shipped. Roughly 800 servers sit exposed online.

Cisco admits hackers are breaking into its phone system software — here's what that means
A flaw in Cisco Unified Communications Manager, the software that runs office phone systems, is now being actively abused after a patch and public exploit code lit the fuse.

Cisco Phone System Flaw Now Being Actively Exploited — Patch Immediately
A security hole in Cisco's business phone software is being used in real attacks. Millions of offices run this software. The fix has existed since June.

Oracle E-Business Suite Payments Bug Hits CVSS 9.8, Already Being Hit
CVE-2026-46817 lets unauthenticated attackers take over Oracle Payments. Exploitation is confirmed now.

CVE-2025-67038: Lantronix Serial-to-IP Flaw Moves From Research to Active Exploitation
A vulnerability disclosed through the BRIDGE:BREAK project is now seeing exploitation in the wild, raising fresh concerns about attacker interest in operational technology network edges.

Cisco Unified CM SSRF Flaw Hits Active Exploitation Three Weeks After Patch Drop
A file-write chain rooted in CVE-2026-20230 is now being probed in the wild. PoC was already public when Cisco shipped the fix.

Cisco Unified CM Bug Under Active Exploit After PoC Drops Root File-Write Chain
CVE-2026-20230 (CVSS 8.6) lets unauthenticated attackers smuggle crafted HTTP requests into Unified CM. Cisco's PSIRT confirms in-the-wild attempts following public PoC release.

Cisco Patches Catalyst SD-WAN Manager Bug Already Seeing In-the-Wild Abuse
CVE-2026-20262 lets an authenticated remote user write files on the appliance. Cisco confirms exploitation. Severity is rated medium, but the access it enables is not.