Exploit 2026 2025 2024 2023 2022 2021 2020 2019 2018 2017 2016 2015 2014 2013 2012 2011 2010 2009 2008 2007 2006 2005 2004 2003 2002 2001 2000
H Remote Web App Local&Privilege Escalation DoS & PoC ShellCode Exp. kit Typy Exploitů
|
6.8.26 |
TONTOU: On the Exploitability of Time-of-Neutralization to Time-of-Use Windows | Recently deployed Spectre v2 mitigations neutralize branch predictor state when switching privilege contexts or immediately prior to indirect branch execution, either through domain isolation or sanitization. These defenses assume that subsequent branch predictor behavior remains free from attacker influence until the neutralized state is used. | EXPLOIT | EXPLOIT |
|
4.8.26 |
Critical N-able N-central Vulnerability and Active Exploitation | N-able has disclosed a critical vulnerability impacting all current versions of N-central, including 2026.3, across both hosted and on‑prem deployments. The flaw can give attackers unauthenticated, "god-mode" access to the RMM console. | EXPLOIT | EXPLOIT |
|
3.8.26 |
SonicWall SMA Exploit Chain | From WSProxy to Root: INC ransomware and SonicWall SMA Exploit Chain | EXPLOIT | EXPLOIT |
|
3.8.26 |
DarkSword | DarkSword's Panel Sprawl: How One Body Hash Unravels a Six-Panel, Two-Codebase Operator Cluster | EXPLOIT | EXPLOIT |
|
25.7.26 |
Cl0p Exploitation of PTC Windchill & FlexPLM (CVE-2026-12569) | A coordinated Unified Threat Advisory covering active Cl0p ransomware affiliate exploitation of internet-exposed PTC Windchill and FlexPLM deployments — chaining a pre-auth FlexPLM WSDL information disclosure with a Windchill login servlet flaw for unauthenticated RCE, JSP webshell deployment, and double-extortion data theft. | EXPLOIT | EXPLOIT |
|
25.7.26 |
Fastjson RCE (≤1.2.83): Active Exploitation Detected — Detection & Mitigation | A remote code execution vulnerability in Fastjson affects every version up to and including 1.2.83. A remote attacker can run arbitrary code on a vulnerable server by sending it specially crafted JSON — no user privileges, no victim interaction, and no third-party libraries required. ThreatBook TDP® (Threat Detection Platform) has already captured this vulnerability being exploited in the wild, so if you run an affected version without SafeMode enabled, treat remediation as urgent. | EXPLOIT | EXPLOIT |
|
21.7.26 |
SonicWall Secure Mobile Access 0-day Exploitation | Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation | EXPLOIT | EXPLOIT |
| 20.6.26 | PoisonX BYOVD Driver Bypasses CrowdStrike EDR | Microsoft-signed kernel driver used in a BYOVD attack to kill CrowdStrike Falcon. Learn how the driver’s hidden IOCTL enables process termination from kernel mode and why modern EDR solutions can be bypassed. | EXPLOIT | EXPLOIT |
| 20.6.26 | Bomgar RMM Exploitation | Threat Advisory: Uptick in Bomgar RMM Exploitation | EXPLOIT | EXPLOIT |
| 20.6.26 | usbliter8 | An A12/A13 SecureROM exploit | EXPLOIT | EXPLOIT |
| 12.5.26 | Actively Exploits CVE-2026-41940 | CVE-2026-41940 is a high-severity unauthenticated authentication bypass vulnerability affecting cPanel & WHM. This product is widely used in Linux server operations and virtual hosting management. | EXPLOIT | EXPLOIT |
| 26.3.26 | Coruna | Coruna: the framework used in Operation Triangulation | EXPLOIT | EXPLOIT |
| 4.3.26 | Coruna | Coruna: The Mysterious Journey of a Powerful iOS Exploit Kit | EXPLOIT | EXPLOIT |
| 26.2.26 | RoguePilot | RoguePilot: Exploiting GitHub Copilot for a Repository Takeover | EXPLOIT | EXPLOIT |
| 13.2.26 | MOONSHINE Exploit Kit | MOONSHINE Exploit Kit and DarkNimbus Backdoor Enabling Earth Minotaur’s Multi-Platform Attacks | EXPLOIT | EXPLOIT KIT |
| 3.2.26 | Metro4Shell | Metro4Shell: Exploitation of React Native’s Metro Server in the Wild | EXPLOIT | EXPLOIT |