Known exploited vulnerabilities
Currently being targeted
CVE-2026-35273
Oracle PeopleSoft PeopleTools
A missing-authentication flaw being actively exploited by the ShinyHunters extortion crew to break into enterprise systems and steal data, hitting universities particularly hard.
View on CISA →CVE-2026-41089
Microsoft Windows Netlogon
A stack-based buffer overflow in Netlogon being exploited against Windows Server domain controllers, potentially handing attackers SYSTEM-level control of Active Directory environments.
View on CISA →CVE-2026-20262
Cisco Catalyst SD-WAN Manager
A directory/path traversal vulnerability added to CISA's Known Exploited Vulnerabilities catalog after evidence of active exploitation in the wild.
View on CISA →CVE-2026-54420
LiteSpeed cPanel Plugin
A symlink-following flaw on shared hosting servers that can let an attacker with FTP or web-shell access escalate beyond their own account.
View on CISA →CVE-2026-20230
Cisco Unified Communications Manager
A critical, unauthenticated flaw with a public proof-of-concept already released, allowing remote attackers to write files and escalate to root.
View on CISA →Ransomware & breach activity
Recent incidents worth knowing about
FortiBleed Campaign
A sweeping campaign attributed to Russian-speaking actors has compromised over 86,000 internet-exposed FortiGate appliances, largely through default and unrotated admin credentials. CISA is urging Fortinet customers to act.
Source: The Hacker News
The Gentlemen Ransomware
A fast-growing ransomware-as-a-service operation now linked to 478+ victims, distributing a custom EDR-killer toolkit to affiliates that disables security tools before the encryptor runs.
Source: The Hacker News
INC Ransomware
Originally a minor RaaS player, INC has expanded to 830+ victims since 2023 as affiliates migrated over following the disruption of LockBit and BlackCat.
Source: The Hacker News
DentaQuest / Sun Life Breach
A data breach affecting roughly 2.6 million accounts, with the ShinyHunters group leaking names, emails, government IDs, and health insurance details.
Source: Check Point Research
WFP Gaza Registration Breach
Unauthorized access to the UN World Food Programme's Gaza self-registration platform exposed identification and location data for roughly 600,000 households, prompting a platform suspension.
Source: Check Point Research
We monitor CISA's Known Exploited Vulnerabilities catalog and reputable security research sources, and refresh this page regularly. It's a snapshot, not an exhaustive feed — if you want to know how any of this applies to your own environment, that's exactly what we're here for.
Not sure if this affects you?
Get a free risk assessment and find out where your actual exposure is.
