Analyst Guidance
This week's verifiable vulnerability landscape is limited to two explicitly identified CVEs. and should be treated as actively exploited. CVE-2026-4020 affecting the Gravity SMTP WordPress plugin is being actively exploited to extract API keys and OAuth tokens from approximately 100,000 deployed sites. Organizations should prioritize patching both vulnerabilities immediately.
CVE Details & Remediation
How to read this report
🛡️Verified facts — NVD & CISA KEV
⏳Partially verified — awaiting NVD enrichment
🧠AI analysis — synthesis, verify before acting
🛡️Actionable · Verified facts
NVD-published · CISA KEV cross-checked🛡️CVE-2026-10520 – Ivanti Sentry ✓ NVD
CVSS10 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV
EPSS60% · P99
ActionPatch immediately
Remediation Steps
- Apply the vendor security update from Ivanti
- Verify successful patch deployment across all affected systems
- Review authentication logs for suspicious activity
References:
🛡️CVE-2026-20253 – Splunk Enterprise ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV
EPSS10% · P95
ActionPatch immediately
Remediation Steps
- Identify all Splunk instances in your environment
- Apply the vendor security patch for CVE-2026-20253 immediately
- Monitor logs for signs of exploitation
- Review access controls and authentication mechanisms
References:
🛡️CVE-2026-35273 – Oracle PeopleSoft Enterprise PeopleTools ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV
EPSS8% · P94
ActionPatch immediately
Remediation Steps
- Apply Oracle PeopleSoft Enterprise security patch
- Review Oracle security advisories for affected version guidance
- Prioritize patching systems accessible from external networks
References:
🛡️CVE-2026-45247 – Mirasvit Full Page Cache Warmer ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV
EPSS2% · P71
ActionPatch immediately
Remediation Steps
- Consult CISA Known Exploited Vulnerabilities catalog entry for full product and version details
- Apply vendor security patch
- Verify patch deployment across affected systems
- Review security logs for evidence of exploitation
References:
🛡️CVE-2026-48172 – LiteSpeed CPanel Plugin ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV
EPSS1% · P65
ActionPatch immediately
Remediation Steps
- Apply the latest security patch from LiteSpeed for the cPanel Plugin immediately
- Verify that only authorized cPanel users have access to affected systems
- Review system logs for evidence of exploitation or unauthorized script execution
- Restrict cPanel administrative access to trusted networks where feasible
References:
🛡️CVE-2026-9082 – Drupal Core ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV
EPSS34% · P98
ActionPatch immediately
Remediation Steps
- Update all supported Drupal Core versions to the latest patched release immediately
- Review database query logs for evidence of SQL injection attempts
- Ensure database user accounts are restricted to minimum required privileges
- Monitor for malicious activity on systems running affected Drupal versions
References:
🛡️CVE-2026-50751 – Check Point Security Gateway ✓ NVD
CVSS9.3 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV
EPSS41% · P98
ActionPatch immediately
AffectedTechnology Finance Government Defense
Remediation Steps
- Apply the vendor security update for Check Point Remote Access VPN / Mobile Access as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-0257 – Palo Alto Networks PAN-OS ✓ NVD
CVSS9.1 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV
EPSS19% · P97
ActionPatch immediately
AffectedGovernment Technology Finance Transportation
Remediation Steps
- Apply the vendor security update for Paloaltonetworks Pan-Os as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-39813 – Fortinet Fortisandbox ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild
EPSS19% · P97
ActionPatch within 48 hours
AffectedFinance Technology
Remediation Steps
- Apply the vendor security update for Fortinet Fortisandbox as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-39808 – Fortinet Fortisandbox ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild
EPSS66% · P99
ActionPatch within 48 hours
AffectedFinance Technology
Remediation Steps
- Apply the vendor security update for Fortinet Fortisandbox as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-25089 – Fortinet FortiSandbox ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild
EPSS3% · P84
ActionPatch within 48 hours
AffectedFinance Technology
Remediation Steps
- Apply the vendor security update for Fortinet FortiSandbox as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-42271 – BerriAI LiteLLM ✓ NVD
CVSS8.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV
EPSS54% · P99
ActionPatch immediately
Remediation Steps
- Check CISA's Known Exploited Vulnerabilities catalog for product-specific guidance
- Contact vendor for available security patches
- Apply patch or implement recommended mitigations from vendor advisory
- Verify patch installation and monitor for indicators of active exploitation
References:
🛡️CVE-2026-11645 – Google Chromium V8 ✓ NVD
CVSS8.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV
EPSS1% · P49
ActionPatch immediately
Remediation Steps
- Update Google Chrome to version 149.0.7827.103 or later
- Enable automatic updates to receive future security patches promptly
- Check for and remove any suspicious browser extensions
- Clear browser cache and temporary files after patching
References:
🛡️CVE-2026-54420 – LiteSpeed CPanel Plugin ✓ NVD
CVSS8.5 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV
EPSS1% · P46
ActionPatch immediately
Remediation Steps
- Apply the patch for the LiteSpeed cPanel user-end plugin to all cPanel servers
- Test patched plugin functionality in a staging environment before production deployment
- Review server logs for evidence of exploitation attempts
- Notify hosting customers of patch deployment timeline
References:
🛡️CVE-2025-48595 – Android Framework ✓ NVD
CVSS8.4 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV
EPSS<1% · P5
ActionPatch immediately
AffectedTechnology Government
Remediation Steps
- Apply the vendor security update for Google Android as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-20245 – Cisco Catalyst SD-WAN Manager ✓ NVD
CVSS7.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV
EPSS1% · P57
ActionPatch immediately
AffectedTechnology Defense
Remediation Steps
- Apply the vendor security update for Cisco as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2022-0492 – Linux Kernel ✓ NVD
CVSS7.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV
EPSS5% · P92
ActionPatch immediately
AffectedTechnology Government Energy
Remediation Steps
- Identify Linux systems running vulnerable kernel versions
- Apply the latest stable kernel update from your distribution's repository
- Reboot systems to activate patched kernel
- Verify kernel version post-reboot using 'uname -r'
- Prioritize kernel patching for systems exposed to untrusted local users or containers
References:
🛡️CVE-2026-28318 – SolarWinds Serv-U ✓ NVD
CVSS7.5 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV
EPSS1% · P60
ActionPatch immediately
Remediation Steps
- Check CISA's Known Exploited Vulnerabilities catalog for product-specific guidance
- Contact vendor for available security patches
- Apply patch or implement recommended mitigations from vendor advisory
- Verify patch installation and monitor for indicators of active exploitation
References:
🛡️CVE-2024-21182 – Oracle WebLogic Server ✓ NVD
CVSS7.5 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV
EPSS48% · P99
ActionPatch immediately
AffectedTechnology Government
Remediation Steps
- Apply the vendor security update for Oracle Weblogic Server as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-20262 – Cisco Catalyst SD-WAN Manager ✓ NVD
CVSS6.5 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV
EPSS1% · P63
ActionPatch immediately
AffectedDefense Technology
Remediation Steps
- Apply the vendor security update for Cisco Catalyst SD-WAN Manager as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-7473 – Arista Extensible Operating System ✓ NVD
CVSS5.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV
EPSS<1% · P29
ActionPatch immediately
Remediation Steps
- Apply the vendor security update from Arista
- Review network device access logs for unauthorized activity
- Restrict management access to network devices from trusted administrative networks
References:
🛡️CVE-2026-48907 – Widget Factory Joomla Content Editor ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV
EPSS7% · P93
ActionPatch immediately
Remediation Steps
- Apply security patch from Widget Factory/Joomla vendor immediately
- Disable the JCE plugin if patch is not immediately available
- Review access logs for evidence of exploitation attempts
References:
🛡️CVE-2026-42530 – F5 NGINX Open Source ✓ NVD
CVSS8.1 NVD 3.1
Triage statusNo Known Exploit
ExploitationNo exploitation reported
EPSS1% · P50
ActionPatch this week
AffectedTechnology Finance
Remediation Steps
- Apply the vendor security update for F5 NGINX Open Source as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-50656 – Microsoft Malware Protection Engine ✓ NVD
CVSS7.8 NVD 3.1
Triage statusNo Known Exploit
ExploitationNo exploitation reported
EPSS<1% · P26
ActionPatch this week
AffectedTechnology
Remediation Steps
- Apply the vendor security update for Microsoft Malware Protection Engine as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-4020 – Gravity SMTP WordPress Plugin ✓ NVD
CVSS7.5 NVD 3.1
Triage statusNo Known Exploit
ExploitationNo exploitation reported
EPSS3% · P86
ActionPatch this week
Remediation Steps
- Update Gravity SMTP plugin to the patched version immediately
- Review configuration files for exposed API keys and secrets
- Rotate all API keys, OAuth tokens, and sensitive credentials that may have been extracted
- Audit access logs for unauthorized API activity
- Implement access controls to restrict unauthenticated requests to plugin endpoints
References:
- https://plugins.trac.wordpress.org/browser/gravitysmtp/tags/2.1.4/vendor/gravityforms/gravity-tools/src/Providers/class-config-collection-service-provider.php#L86
- https://plugins.trac.wordpress.org/browser/gravitysmtp/tags/2.1.4/vendor/gravityforms/gravity-tools/src/Providers/class-config-collection-service-provider.php#L103
- https://docs.gravitysmtp.com/gravity-smtp-changelog/
🤖 This vulnerability report was compiled by defend.network using AI-powered analysis of vulnerability databases, vendor advisories, and threat intelligence feeds. Always verify remediation steps through official vendor channels before implementing changes in production environments.