Analyst Guidance
with CVE-2026-59346 (VMware) and. Organizations should prioritize patching VMware Workstation/Fusion, PaperCut authentication/RCE chains in education, and PostgreSQL logical decoding flaw, while monitoring Citrix NetScaler for in-the-wild abuse of the recently disclosed auth bypass.
CVE Details & Remediation
How to read this report
🛡️Verified facts — NVD & CISA KEV
⏳Partially verified — awaiting NVD enrichment
🧠AI analysis — synthesis, verify before acting
🛡️Actionable · Verified facts
NVD-published · CISA KEV cross-checked🛡️CVE-2026-49869 – Kestra OSS ✓ NVD
CVSS10 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ● New this week ★ Added to KEV this week
EPSS2% · P78
ActionPatch immediately
AffectedTechnology Finance Healthcare
Remediation Steps
- Apply the vendor security update for Kestra OSS as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-83548 – SonicWall SMA1000 Appliances ✓ NVD
CVSS10 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ● New this week ★ Added to KEV this week
EPSS1% · P51
ActionPatch immediately
Remediation Steps
- Apply SonicWall security updates for SMA 1000 series VPN appliances as released by vendor
- If patching cannot be completed immediately, isolate affected SMA 1000 appliances from untrusted networks
- Monitor appliance logs for unusual SSRF or authentication bypass attempts
- Enforce network access restrictions to administrative interfaces
- Review and revoke any suspicious user sessions or API tokens created on affected appliances
References:
🛡️CVE-2026-21962 – Oracle HTTP Server And Oracle Weblogic Server Proxy Plug-In ✓ NVD
CVSS10 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS42% · P99
ActionPatch immediately
AffectedTechnology Finance Government
Remediation Steps
- Apply the vendor security update for Oracle HTTP Server And Oracle Weblogic Server Proxy Plug-In as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-72898 – Metabase ✓ NVD
CVSS10 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS82% · P100
ActionPatch immediately
Remediation Steps
- Apply the vendor security update for Metabase Metabase as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-81578 – PaperCut NG/MF ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ● New this week ★ Added to KEV this week
EPSS2% · P74
ActionPatch immediately
AffectedEducation
Remediation Steps
- Apply PaperCut security patches to address authentication bypass
- Review access logs for suspicious authentication attempts
- Rotate credentials used in compromised environments
References:
🛡️CVE-2026-9586 – Sangoma Switchvox ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ● New this week ★ Added to KEV this week
EPSS12% · P96
ActionPatch immediately
AffectedTechnology
Remediation Steps
- Apply the vendor security update for Sangoma Switchvox as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-82329 – JFrog Artifactory ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ● New this week ★ Added to KEV this week
EPSS8% · P94
ActionPatch immediately
AffectedTechnology Healthcare Finance
Remediation Steps
- Apply the vendor security update for JFrog Artifactory as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2023-49105 – Owncloud Server ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV
EPSS43% · P99
ActionPatch immediately
Remediation Steps
- Apply ownCloud security patch for CVE-2023-49105 immediately
- Review access logs for indicators of compromise targeting file repositories
- Restrict network access to ownCloud instances to trusted networks where possible
- Monitor for unauthorized file access or exfiltration activity
References:
🛡️CVE-2021-23758 – Ajaxpro.2 Project Ajaxpro.2 (also: Michaelschwarz) ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS84% · P100
ActionPatch immediately
AffectedTechnology
Remediation Steps
- Apply the vendor security update for Ajaxpro.2 Project Ajaxpro.2 as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-72529 – TrueConf Server ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS2% · P73
ActionPatch immediately
Remediation Steps
- Apply the vendor security patch
- Review system logs for evidence of exploitation
- Verify affected systems are fully patched
- Monitor for suspicious activity post-remediation
References:
🛡️CVE-2026-33824 – Microsoft Internet Key Exchange (IKE) Service Extensions ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS73% · P99
ActionPatch immediately
Remediation Steps
- Consult CISA Known Exploited Vulnerabilities Catalog for affected product details
- Apply vendor patch when available
- Verify patch deployment across affected systems
References:
🛡️CVE-2026-59310 – Broadcom VMware VCenter ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS46% · P99
ActionPatch immediately
AffectedHealthcare Government
Remediation Steps
- Apply the vendor security update for Vmware Vcenter Server as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-65400 – Apple MacOS ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS10% · P95
ActionPatch immediately
AffectedHealthcare Government
Remediation Steps
- Apply the vendor security update for Apple Macos as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-8037 – Progress LoadMaster ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS100% · P100
ActionPatch immediately
AffectedTechnology
Remediation Steps
- Apply the vendor security update for Progress Connection Manager For Objectscale as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-63077 – JetBrains TeamCity ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS87% · P100
ActionPatch immediately
Remediation Steps
- Check CISA's Known Exploited Vulnerabilities catalog for confirmation that this CVE affects your systems
- Apply the vendor patch immediately
- Monitor systems for evidence of exploitation
- Review access logs for suspicious activity on affected assets
References:
🛡️CVE-2026-9198 – IBM Langflow ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS57% · P99
ActionPatch immediately
Remediation Steps
- Consult CISA Known Exploited Vulnerabilities catalog for affected product details
- Identify affected systems in your environment
- Apply vendor patch as soon as available
- Verify patch installation across all instances
References:
🛡️CVE-2026-60004 – Gitea ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS87% · P100
ActionPatch immediately
Remediation Steps
- Apply the vendor security update for Gitea Gitea as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-8452 – Citrix NetScaler ADC And NetScaler Gateway ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS2% · P74
ActionPatch immediately
Remediation Steps
- Apply the vendor security update for Citrix NetScaler ADC and NetScaler Gateway as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-64849 – Lfprojects Mlflow ✓ NVD
CVSS9.3 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS16% · P97
ActionPatch immediately
Remediation Steps
- Apply the vendor security patch
- Review system logs for evidence of exploitation
- Verify affected systems are fully patched
- Monitor for suspicious activity post-remediation
References:
🛡️CVE-2026-82078 – PaperCut NG/MF ✓ NVD
CVSS9.1 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ● New this week ★ Added to KEV this week
EPSS2% · P75
ActionPatch immediately
AffectedEducation
Remediation Steps
- Apply PaperCut security patches to address remote code execution
- Implement network segmentation to limit exposure of PaperCut services
- Monitor for command execution and reconnaissance activity in logs
References:
🛡️CVE-2026-55040 – Microsoft SharePoint ✓ NVD
CVSS9.1 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS40% · P99
ActionPatch immediately
AffectedHealthcare Government
Remediation Steps
- Apply the vendor security update for Microsoft Sharepoint Server as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-72530 – TrueConf Server ✓ NVD
CVSS9 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS2% · P77
ActionPatch immediately
AffectedTransportation Technology Finance
Remediation Steps
- Apply the vendor security update for Trueconf Server as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-32475 – Elementor Pro (WordPress plugin) ✓ NVD
CVSS9 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild
EPSS2% · P83
ActionPatch within 48 hours
Remediation Steps
- Update Elementor Pro plugin to the latest patched version immediately
- Scan WordPress sites for webshell artifacts and malicious scripts injected by exploitation
- Review server logs for unauthorized command execution activity
- Implement Web Application Firewall (WAF) rules to detect and block exploitation attempts
References:
- https://patchstack.com/database/wordpress/plugin/elementor-pro/vulnerability/wordpress-elementor-pro-plugin-4-2-1-arbitrary-file-upload-vulnerability?_s_id=cve
- https://patchstack.com/articles/critical-unauthenticated-file-upload-to-rce-in-elementor-pro-plugin?_s_id=cve
- https://nvd.nist.gov/vuln/detail/CVE-2026-32475
🛡️CVE-2026-73570 – Synacor Zimbra Collaboration Suite (ZCS) ✓ NVD
CVSS8.9 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS32% · P98
ActionPatch immediately
AffectedTechnology Finance
Remediation Steps
- Apply the vendor security update for Synacor Zimbra Collaboration Suite as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-85046 – Google Chromium V8 ✓ NVD
CVSS8.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ● New this week ★ Added to KEV this week
EPSS1% · P56
ActionPatch immediately
Remediation Steps
- Consult CISA's Known Exploited Vulnerabilities catalog for affected product details and vendor guidance
- Apply vendor patch as soon as available
- Monitor systems for indicators of exploitation
References:
🛡️CVE-2025-62593 – Ray-Project Ray ✓ NVD
CVSS8.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS17% · P97
ActionPatch immediately
AffectedTechnology Manufacturing Energy
Remediation Steps
- Apply the vendor security update for Anyscale Ray as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2019-1068 – Microsoft SQL Server ✓ NVD
CVSS8.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS53% · P99
ActionPatch immediately
Remediation Steps
- Apply the vendor security update for Microsoft SQL Server as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-20349 – Cisco Secure Firewall Adaptive Security Appliance (ASA) And Secure Firewall Threat Defense (FTD) ✓ NVD
CVSS8.6 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS2% · P81
ActionPatch immediately
AffectedTechnology Government
Remediation Steps
- Apply the vendor security update for Cisco Adaptive Security Appliance Software as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-59822 – BerriAI LiteLLM ✓ NVD
CVSS8.2 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ● New this week ★ Added to KEV this week
EPSS1% · P56
ActionPatch immediately
Remediation Steps
- Apply the vendor security update for BerriAI LiteLLM as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-18577 – N-Able N-Central ✓ NVD
CVSS8.1 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS54% · P99
ActionPatch immediately
AffectedGovernment Technology
Remediation Steps
- Apply the vendor security update for N-Able N-Central as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-53362 – Linux Kernel ✓ NVD
CVSS7.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS1% · P42
ActionPatch immediately
AffectedTechnology Finance Government
Remediation Steps
- Apply the vendor security update for Linux Kernel as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2015-5287 – Red Hat Automatic Bug Reporting Tool ✓ NVD
CVSS7.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS5% · P92
ActionPatch immediately
Remediation Steps
- Apply the vendor security update for Red Hat Automatic Bug Reporting Tool as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2022-0995 – Linux Kernel ✓ NVD
CVSS7.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS10% · P95
ActionPatch immediately
Remediation Steps
- Apply the vendor security update for Linux Kernel as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-83549 – SonicWall SMA1000 Appliances ✓ NVD
CVSS7.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ● New this week ★ Added to KEV this week
EPSS2% · P74
ActionPatch immediately
Remediation Steps
- Apply the vendor security update for SonicWall SMA1000 Appliances as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-34486 – Apache Tomcat ✓ NVD
CVSS7.5 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS99% · P100
ActionPatch immediately
AffectedTechnology Government
Remediation Steps
- Apply the vendor security update for Apache Tomcat as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-18556 – N-Able N-Central ✓ NVD
CVSS7.4 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS40% · P99
ActionPatch immediately
AffectedTechnology Government
Remediation Steps
- Apply the vendor security update for N-Able N-Central as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-68820 – Microsoft Windows Ancillary Function Driver For WinSock ✓ NVD
CVSS7 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS6% · P93
ActionPatch immediately
AffectedTechnology Government
Remediation Steps
- Apply the vendor security update for Microsoft Windows 10 1607 as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-48710 – Kludex Starlette ✓ NVD
CVSS6.5 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ● New this week ★ Added to KEV this week
EPSS36% · P98
ActionPatch immediately
Remediation Steps
- Apply the vendor security update for Kludex Starlette as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-66384 – JFrog Artifactory ✓ NVD
CVSS5.3 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS1% · P45
ActionPatch immediately
AffectedTechnology Finance Government
Remediation Steps
- Apply the vendor security update for Jfrog Artifactory as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2015-3246 – Red Hat Libuser ✓ NVD
CVSS5.1 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS9% · P95
ActionPatch immediately
Remediation Steps
- Apply the vendor security update for Red Hat Libuser as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🤖 This vulnerability report was compiled by defend.network using AI-powered analysis of vulnerability databases, vendor advisories, and threat intelligence feeds. Always verify remediation steps through official vendor channels before implementing changes in production environments.