Analyst Guidance
This week saw rapid escalation of actively exploited vulnerabilities across critical infrastructure and identity platforms. Security teams should prioritize patching actively exploited flaws in communications and authentication systems, and monitor PLC/OT environments for ongoing threat activity.
CVE Details & Remediation
How to read this report
🛡️Verified facts — NVD & CISA KEV
⏳Partially verified — awaiting NVD enrichment
🧠AI analysis — synthesis, verify before acting
🛡️Actionable · Verified facts
NVD-published · CISA KEV cross-checked🛡️CVE-2026-21962 – Oracle HTTP Server And Oracle Weblogic Server Proxy Plug-In ✓ NVD
CVSS10 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ● New this week ★ Added to KEV this week
EPSS43% · P99
ActionPatch immediately
Remediation Steps
- Apply the vendor patch from GitHub
- Review recent authentication logs for anomalous access patterns
- Verify repository access controls and permissions
- Consider rotating authentication tokens and API keys
References:
🛡️CVE-2026-16812 – Arista VeloCloud Orchestrator ✓ NVD
CVSS10 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS2% · P73
ActionPatch immediately
AffectedTechnology
Remediation Steps
- Apply the vendor security update for Arista VeloCloud Orchestrator On-Prem as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-72898 – Metabase ✓ NVD
CVSS10 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS79% · P100
ActionPatch immediately
Remediation Steps
- Apply the vendor security update for Metabase Metabase as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-72529 – TrueConf Server ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV
EPSS2% · P73
ActionPatch immediately
Remediation Steps
- Apply the vendor security patch
- Review system logs for evidence of exploitation
- Verify affected systems are fully patched
- Monitor for suspicious activity post-remediation
References:
🛡️CVE-2026-33824 – Microsoft Internet Key Exchange (IKE) Service Extensions ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV
EPSS73% · P99
ActionPatch immediately
Remediation Steps
- Consult CISA Known Exploited Vulnerabilities Catalog for affected product details
- Apply vendor patch when available
- Verify patch deployment across affected systems
References:
🛡️CVE-2026-59310 – Broadcom VMware VCenter ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS46% · P99
ActionPatch immediately
AffectedHealthcare Government
Remediation Steps
- Apply the vendor security update for Vmware Vcenter Server as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-65400 – Apple MacOS ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS10% · P95
ActionPatch immediately
AffectedHealthcare Government
Remediation Steps
- Apply the vendor security update for Apple Macos as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-8037 – Progress LoadMaster ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS100% · P100
ActionPatch immediately
AffectedTechnology
Remediation Steps
- Apply the vendor security update for Progress Connection Manager For Objectscale as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-63077 – JetBrains TeamCity ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS85% · P100
ActionPatch immediately
Remediation Steps
- Check CISA's Known Exploited Vulnerabilities catalog for confirmation that this CVE affects your systems
- Apply the vendor patch immediately
- Monitor systems for evidence of exploitation
- Review access logs for suspicious activity on affected assets
References:
🛡️CVE-2026-9198 – IBM Langflow ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS37% · P98
ActionPatch immediately
Remediation Steps
- Consult CISA Known Exploited Vulnerabilities catalog for affected product details
- Identify affected systems in your environment
- Apply vendor patch as soon as available
- Verify patch installation across all instances
References:
🛡️CVE-2026-64849 – Lfprojects Mlflow ✓ NVD
CVSS9.3 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV
EPSS16% · P97
ActionPatch immediately
Remediation Steps
- Apply the vendor security patch
- Review system logs for evidence of exploitation
- Verify affected systems are fully patched
- Monitor for suspicious activity post-remediation
References:
🛡️CVE-2026-55040 – Microsoft SharePoint ✓ NVD
CVSS9.1 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS6% · P92
ActionPatch immediately
AffectedHealthcare Government
Remediation Steps
- Apply the vendor security update for Microsoft Sharepoint Server as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-72530 – TrueConf Server ✓ NVD
CVSS9 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS2% · P77
ActionPatch immediately
AffectedTransportation Technology Finance
Remediation Steps
- Apply the vendor security update for Trueconf Server as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-19478 – GitLab ✓ NVD
CVSS9.4 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild
EPSS6% · P93
ActionPatch within 48 hours
Remediation Steps
- Apply the latest GitLab security patch addressing CVE-2026-19478 immediately
- Review audit logs for evidence of unauthorized project modifications or deletions
- Restrict public project visibility to trusted users pending patch deployment
- Monitor GitLab instances for suspicious code injection activity
References:
🛡️CVE-2026-73570 – Synacor Zimbra Collaboration Suite (ZCS) ✓ NVD
CVSS8.9 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV
EPSS2% · P72
ActionPatch immediately
AffectedGovernment
Remediation Steps
- Apply the vendor patch for Zimbra Collaboration Suite immediately
- Monitor all user accounts for unauthorized access or password reset activity
- Verify integrity of recent user account changes and communications
- Restrict access to Zimbra administrative interfaces to trusted networks
References:
🛡️CVE-2025-62593 – Ray-Project Ray ✓ NVD
CVSS8.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS17% · P97
ActionPatch immediately
AffectedTechnology Manufacturing Energy
Remediation Steps
- Apply the vendor security update for Anyscale Ray as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-20349 – Cisco Secure Firewall Adaptive Security Appliance (ASA) And Secure Firewall Threat Defense (FTD) ✓ NVD
CVSS8.6 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS2% · P81
ActionPatch immediately
AffectedTechnology Government
Remediation Steps
- Apply the vendor security update for Cisco Adaptive Security Appliance Software as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-18577 – N-Able N-Central ✓ NVD
CVSS8.1 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS6% · P93
ActionPatch immediately
AffectedGovernment Technology
Remediation Steps
- Apply the vendor security update for N-Able N-Central as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-34486 – Apache Tomcat ✓ NVD
CVSS7.5 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS99% · P100
ActionPatch immediately
AffectedTechnology Government
Remediation Steps
- Apply the vendor security update for Apache Tomcat as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-18556 – N-Able N-Central ✓ NVD
CVSS7.4 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS4% · P90
ActionPatch immediately
AffectedTechnology Government
Remediation Steps
- Apply the vendor security update for N-Able N-Central as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-68820 – Microsoft Windows Ancillary Function Driver For WinSock ✓ NVD
CVSS7 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS6% · P93
ActionPatch immediately
AffectedTechnology Government
Remediation Steps
- Apply the vendor security update for Microsoft Windows 10 1607 as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2025-68686 – Fortinet FortiOS ✓ NVD
CVSS5.9 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS29% · P98
ActionPatch immediately
AffectedTechnology
Remediation Steps
- Apply the vendor security update for Fortinet Fortios as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-20316 – Cisco Secure Firewall Management Center (FMC) ✓ NVD
CVSS5.3 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS10% · P95
ActionPatch immediately
AffectedTechnology
Remediation Steps
- Apply the vendor security update for Cisco Secure Firewall Management Center as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-18963 – Red Hat Keycloak ✓ NVD
CVSS9.1 NVD 3.1
Triage statusNo Known Exploit
ExploitationNo exploitation reported
EPSS1% · P42
ActionPatch within 48 hours
Remediation Steps
- Apply Red Hat security patch for Keycloak immediately
- Verify that password reset flows require proper authentication
- Audit recent account activity and password reset requests
- Consider implementing additional MFA controls for sensitive accounts
References:
🤖 This vulnerability report was compiled by defend.network using AI-powered analysis of vulnerability databases, vendor advisories, and threat intelligence feeds. Always verify remediation steps through official vendor channels before implementing changes in production environments.