An unauthenticated attacker can trigger a heap memory fault over the network on Cisco ASA and FTD firewalls, forcing an unplanned reload and knocking down the firewall’s availability.
Every CISA KEV addition, plus critical-severity flaws in the kit that sits at the edge of a network: firewalls, VPN gateways, load balancers, routers, switches and management consoles.
Colour on the left of each entry is the CVSS severity. A pink CISA KEV badge means the flaw is being exploited right now — treat those first, whatever the score says. How each post is sourced and checked is set out in the methodology.
Metabase SQL Injection Vulnerability
An unauthenticated attacker can inject SQL into Metabase’s own application database, gain admin control, and pivot to steal credentials for every connected data source.
Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
A kernel-mode use-after-free in Windows’ WinSock driver lets a logged-in low-privilege user escalate to SYSTEM control, and it’s already being exploited in the wild.
Progress LoadMaster Command Injection Vulnerability
An unauthenticated attacker on the adjacent network can inject commands into LoadMaster’s management endpoints and take full control of the appliance, and it’s already being exploited.
Cisco Catalyst SD-WAN Software Security Hardening Release: August 2026
Cisco’s internal security review of Catalyst SD-WAN Manager and Controller software uncovered five separate flaws, one rated 9.9, that a low-privileged network attacker could exploit without any user interaction.
Cisco IOS XE Software Security Hardening Release: August 2026
Cisco’s own engineers found seven flaws in IOS XE running in autonomous or controller mode, including a critical injection bug reachable over the network with no login needed, and there is no workaround short of upgrading.
Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability
An unauthenticated attacker who can reach the FMC web interface can exploit a flawed boot-time process to run scripts and gain root on the underlying operating system, no credentials needed.
JetBrains TeamCity Deserialization of Untrusted Data Vulnerability
An unauthenticated attacker can send crafted data to TeamCity’s agent polling protocol and gain full code execution on the server, with no login or user interaction needed.
Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
Tomcat’s EncryptInterceptor, meant to protect cluster traffic, can be bypassed, letting an attacker read sensitive data that should have been encrypted, no credentials needed.
IBM Langflow Code Injection Vulnerability
An unauthenticated attacker can send a single network request to a default Langflow install and run arbitrary code, fully compromising the host with no login or user action needed.