Insights de Segurança — Incidentes reais e lições 2024–2026

Centro de inteligência da GSAFE: casos reais, CVEs CISA KEV, catálogo de exploração ativa e materiais para download.

Incidentes e cases

Materiais para download

Catálogo CVE · CISA KEV

Atualizado automaticamente a partir do Known Exploited Vulnerabilities Catalog. Última sync: 2026-09-03T19:57:52.884Z.

Destaques GSAFE

CVE-2026-63077 — TeamCity: desserialização e RCE sem autenticação

Adicionada ao KEV em 05/08/2026. Falha no protocolo de polling de agentes pode permitir execução remota de código sem autenticação — risco direto a pipelines e segredos de build.

Impacto: Compromisso de CI/CD costuma virar acesso a repositórios, cloud credentials e produção em cadeia.

  • Atualize TeamCity imediatamente conforme advisory JetBrains.
  • Isole o servidor de build da internet; restrinja agent polling.
  • Rotacione secrets expostos em pipelines após patch.
  • Revise logs de agentes e builds anômalos no período de exposição.

CVE-2026-18556 — N-able N-central: bypass de autenticação

KEV 04/08/2026. Bypass via caminho/canal alternativo em plataforma RMM amplamente usada por MSPs — superfície privilegiada sobre dezenas de clientes.

Impacto: RMM comprometido é acesso administrativo em massa a endpoints de clientes.

  • Aplique patch N-central e valide MFA/SSO.
  • Restrinja acesso admin por IP/ZTNA.
  • Audite sessões e contas de técnicos.
  • Notifique clientes se houver indício de abuso.

CVE-2026-34486 — Apache Tomcat: exposição de dados sensíveis

KEV 04/08/2026. Falha de criptografia/exposição de dados sensíveis em Tomcat — runtime ubiquo em apps Java empresariais.

Impacto: Middleware legado sem patch é alvo recorrente de scanners e ransomware affiliates.

  • Atualize Tomcat para versão corrigida.
  • Desabilite conectores/manager expostos.
  • Force TLS e headers de segurança.
  • Inclua Tomcat no inventário SCA/SBOM.

CVE-2026-9198 — Langflow (IBM): injeção de código sem autenticação

KEV 04/08/2026. Code injection em Langflow permite atacantes não autenticados — plataforma de fluxos LLM cada vez mais presente em empresas.

Impacto: AI tooling sem AppSec vira ponte para dados internos e credenciais de modelos.

  • Patche Langflow e remova exposição pública.
  • Exija autenticação forte e rede privada.
  • Monitore execução de código/ferramentas do agente.
  • Inclua stacks LLMOps no threat model.

CVE-2026-50522 — SharePoint: desserialização explorada

KEV julho/2026. Desserialização em SharePoint — superfície on-prem ainda comum e historicamente abusada em campanhas.

Impacto: SharePoint exposto é portal para Active Directory, arquivos e identidade corporativa.

  • Aplique atualizações Microsoft de segurança.
  • Remova SharePoint da internet quando possível.
  • Monitore webshells e IIS anômalo.
  • Valide AMSI/Defender em servidores.

CVE-2026-20316 — Cisco FMC: risco no plano de gerenciamento

KEV 29/07/2026. Vulnerabilidade no Cisco Secure Firewall Management Center — compromisso do management plane afeta a defesa da rede inteira.

Impacto: Quem controla o FMC controla políticas de firewall e visibilidade.

  • Patche FMC conforme Cisco PSIRT.
  • Segmente management plane (fora da LAN de usuários).
  • MFA + jump hosts para admins de rede.
  • Audite mudanças de política recentes.

CVE-2025-68686 — Fortinet FortiOS: exposição de informação

KEV 27/07/2026. Exposição de informação sensível a ator não autorizado em FortiOS — appliances de borda continuam alvos prioritários.

Impacto: Vazamento em firewall pode revelar topologia, usuários ou material para próximo estágio.

  • Aplique firmware Fortinet recomendado.
  • Desabilite interfaces de admin na WAN.
  • Monitore scans e logins falhos na borda.
  • Revise regras e certificados após patch.

CVE-2026-60137 — WordPress Core: SQL injection via plugin/tema

KEV 21/07/2026. SQLi quando plugin/tema passa input não confiável — ecossistema massivo e frequentemente desatualizado.

Impacto: SQLi em CMS = dump de usuários, takeover e webshell em minutos.

  • Atualize WordPress core, temas e plugins.
  • Remova plugins abandonados.
  • WAF com regras SQLi + least privilege no DB.
  • Monitore file integrity em wp-content.

Vulnerabilidades exploradas (KEV)

  1. CVE-2026-83549 — SonicWall SMA1000 Appliances OS Command Injection Vulnerability (SonicWall / SMA1000 Appliances). SonicWall SMA1000 Appliances contains an OS command injection vulnerability that could enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution. NVD
  2. CVE-2026-83548 — SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability (SonicWall / SMA1000 Appliances). SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations. NVD
  3. CVE-2026-9586 — Sangoma Switchvox SQL Injection Vulnerability (Sangoma / Switchvox). Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution. NVD
  4. CVE-2026-82329 — JFrog Artifactory Improper Authentication Vulnerability (JFrog / Artifactory). JFrog Artifactory contains an improper authentication vulnerability that under default configuration can allow an unauthenticated attacker with network access to obtain administrative privileges. NVD
  5. CVE-2026-49869 — Kestra OSS OS Command Injection Vulnerability (Kestra / Kestra OSS). Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials. NVD
  6. CVE-2026-48710 — Kludex Starlette HTTP Request/Response Smuggling Vulnerability (Kludex / Starlette). Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentication bypass when the authentication depends on the reconstructed URL’s path. This vulnerability could be chaned with CVE-2026-42271. NVD
  7. CVE-2026-59822 — BerriAI LiteLLM Improper Authentication Vulnerability (BerriAI / LiteLLM). BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token. NVD
  8. CVE-2026-81578 — PaperCut NG/MF Missing Authentication for Critical Function Vulnerability (PaperCut / NG/MF). PaperCut NG/MF contains a missing authentication for critical function vulnerability which allows an unauthenticated remote attacker to modify certain system configurations. This vulnerability can be chained with CVE-2026-82078. NVD
  9. CVE-2026-82078 — PaperCut NG/MF Unsafe Reflection Vulnerability (PaperCut / NG/MF). PaperCut NG/MF contains an unsafe reflection vulnerability that allows an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process. This vulnerability can be chained with CVE-2026-81578. NVD
  10. CVE-2026-66384 — JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability (JFrog / Artifactory). JFrog Artifactory contains an improper limitation of a pathname to a restricted directory vulnerability. This can allow an authenticated user to write data outside the intended Docker cache path under specific remote-repository conditions. NVD
  11. CVE-2026-53362 — Linux Kernel Unspecified Vulnerability (Linux / Kernel). Linux Kernel contains an unspecified vulnerability that can allow for privilege escalation via IPv6 networking subsystem. This vulnerability can impact multiple products, including but not limited to Suse, Red Hat, and other products using Linux. NVD
  12. CVE-2023-49105 — ownCloud Improper Authentication Vulnerability (ownCloud / ownCloud). ownCloud contains an improper authentication vulnerability that allows an attacker to access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. NVD
  13. CVE-2019-1068 — Microsoft SQL Server Remote Code Execution Vulnerability (Microsoft / SQL Server). Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine service account. NVD
  14. CVE-2026-8452 — Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (Citrix / NetScaler ADC and NetScaler Gateway). Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability which could lead to denial of service. NVD
  15. CVE-2022-0995 — Linux Kernel Out-of-Bounds Write Vulnerability (Linux / Kernel). Linux Kernel contains an out-of-bounds memory write vulnerability which could allow a local user to gain privileged access or cause a denial of service on the system. NVD
  16. CVE-2015-5287 — Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability (Red Hat / Automatic Bug Reporting Tool). Red Hat Automatic Bug Reporting Tool (ABRT) contains a privilege escalation vulnerability that could allow local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. NVD
  17. CVE-2015-3246 — Red Hat Libuser Race Condition Vulnerability (Red Hat / Libuser). Red Hat libuser contains a race condition vulnerability that allows authenticated local users to corrupt the /etc/passwd file to cause a denial of service or privilege escalation. NVD
  18. CVE-2021-23758 — Ajax.NET Professional Deserialization of Untrusted Data Vulnerability (Ajax.NET Professional / Ajax.NET Professional). Ajax.NET Professional (AjaxPro) contains a deserialization of untrusted data vulnerability that could allow for remote code execution via arbitrary .NET classes. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. NVD
  19. CVE-2026-60004 — Gitea Code Injection Vulnerability (Gitea / Gitea). Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account. NVD
  20. CVE-2026-21962 — Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability (Oracle / HTTP Server and Oracle Weblogic Server Proxy Plug-in). Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in contain an improper access control vulnerability that can result in unauthorized creation, deletion or modification access to critical data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in accessible data. NVD
  21. CVE-2026-73570 — Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability (Synacor / Zimbra Collaboration Suite (ZCS)). Zimbra Collaboration Suite (ZCS) contains an OS command injection vulnerability which could allow an unauthenticated attacker to send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user. NVD
  22. CVE-2026-72529 — TrueConf Server Missing Authentication for Critical Function Vulnerability (TrueConf / Server). TrueConf Server contains a missing authentication for critical function vulnerability which could allow a remote unauthorized attacker with network access via port 4307/TCP to execute an arbitrary script. NVD
  23. CVE-2026-72530 — TrueConf Server Code Injection Vulnerability (TrueConf / Server). TrueConf Server contains a code injection vulnerability that could allow an unauthorized remote attacker with network access via port 4307/TCP to use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system. NVD
  24. CVE-2026-64849 — MLflow Server-Side Request Forgery Vulnerability (MLflow / MLflow). MLflow contains a server-side request forgery vulnerability that can allow attackers to reach internal or cloud metadata services and receive response_status and response_body. NVD
  25. CVE-2026-65400 — Apple macOS Improper Authentication Vulnerability (Apple / macOS). Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials. NVD
  26. CVE-2026-55040 — Microsoft SharePoint Weak Authentication Vulnerability (Microsoft / SharePoint). Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network. NVD
  27. CVE-2026-59310 — Broadcom VMware vCenter Path Traversal Vulnerability (Broadcom / VMware vCenter). Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code. NVD
  28. CVE-2026-33824 — Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability (Microsoft / Internet Key Exchange (IKE) Service Extensions). Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution. NVD
  29. CVE-2025-62593 — Ray-Project Ray Code Injection Vulnerability (Ray-Project / Ray). Ray-Project Ray contains a code injection vulnerability that could allow remote code execution. Developers using Ray as a development tool may be exposed to this vulnerability exploitable through Firefox and Safari. NVD
  30. CVE-2026-72898 — Metabase SQL Injection Vulnerability (Metabase / Metabase). Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data. NVD
  31. CVE-2026-68820 — Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability (Microsoft / Windows Ancillary Function Driver for WinSock ). Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally. NVD
  32. CVE-2026-20349 — Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability (Cisco / Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) ). Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. NVD
  33. CVE-2026-8037 — Progress LoadMaster Command Injection Vulnerability (Progress / LoadMaster). Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints. NVD
  34. CVE-2026-63077 — JetBrains TeamCity Deserialization of Untrusted Data Vulnerability (JetBrains / TeamCity). JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol. NVD
  35. CVE-2026-9198 — IBM Langflow Code Injection Vulnerability (IBM / Langflow). Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments. NVD
  36. CVE-2026-34486 — Apache Tomcat Missing Encryption of Sensitive Data Vulnerability (Apache / Tomcat). Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813. NVD
  37. CVE-2026-18556 — N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability (N-able / N-central). N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass. NVD
  38. CVE-2026-18577 — N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability (N-able / N-central). N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for CVE-2026-18556. NVD
  39. CVE-2026-20316 — Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability (Cisco / Secure Firewall Management Center (FMC)). Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. NVD
  40. CVE-2026-16812 — Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability (Arista / VeloCloud Orchestrator). Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. NVD
  41. CVE-2025-68686 — Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (Fortinet / FortiOS). Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level. NVD
  42. CVE-2026-50522 — Microsoft SharePoint Deserialization of Untrusted Data Vulnerability (Microsoft / SharePoint). Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network. NVD
  43. CVE-2026-16232 — Check Point SmartConsole Improper Authentication Vulnerability (Check Point / SmartConsole). Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. NVD
  44. CVE-2021-27137 — DD-WRT Stack-Based Buffer Overflow Vulnerability (DD-WRT / DD-WRT). DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability. NVD
  45. CVE-2026-0770 — Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability (Langflow / Langflow). Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations. NVD
  46. CVE-2026-63030 — WordPress Core Interpretation Conflict Vulnerability (WordPress / Core). WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137. NVD
  47. CVE-2026-60137 — WordPress Core SQL Injection Vulnerability (WordPress / Core). WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations. NVD
  48. CVE-2026-39808 — Fortinet FortiSandbox OS Command Injection Vulnerability (Fortinet / FortiSandbox). Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests. NVD
  49. CVE-2026-25089 — Fortinet FortiSandbox OS Command Injection Vulnerability (Fortinet / FortiSandbox). Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests. NVD
  50. CVE-2026-58644 — Microsoft SharePoint Deserialization of Untrusted Data Vulnerability (Microsoft / SharePoint). Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network. NVD
  51. CVE-2023-4346 — KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability (KNX Association / KNX Protocol Connection Authorization Option 1). KNX Association KNX Protocol Connection Authorization Option 1 contains an overly restrictive account lockout mechanism vulnerability that could allow an attacker to purge all devices without additional security options enabled and set a BCU key to lock the device. NVD
  52. CVE-2026-46817 — Oracle E-Business Suite Improper Privilege Management Vulnerability (Oracle / E-Business Suite). Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. NVD
  53. CVE-2026-15410 — SonicWall SMA1000 Appliances Code Injection Vulnerability (SonicWall / SMA1000 Appliances). SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands. NVD
  54. CVE-2026-15409 — SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability (SonicWall / SMA1000 Appliances). SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location. NVD
  55. CVE-2026-56164 — Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability (Microsoft / SharePoint Server). Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network. NVD
  56. CVE-2026-56155 — Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability (Microsoft / Active Directory Federation Services). Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally. NVD
  57. CVE-2008-4128 — Cisco IOS Cross-Site Request Forgery Vulnerability (Cisco / IOS). Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI. NVD
  58. CVE-2026-48939 — iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability (iCagenda / iCagenda). iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution. NVD
  59. CVE-2026-56291 — Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability (Balbooa / Forms). Balbooa Forms contains an unrestricted upload of file with dangerous type vulnerability that allows an unauthenticated arbitrary file upload which could allow uploading of executable files leading to full RCE. NVD
  60. CVE-2026-48282 — Adobe ColdFusion Path Traversal Vulnerability (Adobe / ColdFusion). Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user. NVD
  61. CVE-2026-56290 — Joomlack Page Builder Improper Access Control Vulnerability (Joomlack / Page Builder). Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload. NVD
  62. CVE-2026-55255 — Langflow Authorization Bypass Through User-Controlled Key Vulnerability (Langflow / Langflow). Langflow contains an authorization bypass through user-controlled key vulnerability which allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request. NVD
  63. CVE-2026-48908 — JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability (JoomShaper / SP Page Builder). JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code. NVD
  64. CVE-2026-45659 — Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability (Microsoft / SharePoint Server). Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network. NVD
  65. CVE-2026-48558 — SimpleHelp Authentication Bypass Vulnerability (SimpleHelp / SimpleHelp). SimpleHelp contains an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication. NVD
  66. CVE-2026-20230 — Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability (Cisco / Unified Communications Manager). Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) contain a server-side request forgery (SSRF) Vulnerability that could allow an unauthenticated, remote attacker to write files to the underlying operating system that could be used later to elevate to root. NVD
  67. CVE-2026-12569 — PTC Windchill and FlexPLM Improper Input Validation Vulnerability (PTC / Windchill and FlexPLM). PTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attacker to execute arbitrary code by sending a malicious request to the network. NVD
  68. CVE-2026-34908 — Ubiquiti UniFi OS Improper Access Control Vulnerability (Ubiquiti / UniFi OS). Ubiquiti UniFi OS contains an improper access control vulnerability which could allow a malicious actor with access to the network to make unauthorized changes to the system. NVD
  69. CVE-2026-34909 — Ubiquiti UniFi OS Path Traversal Vulnerability (Ubiquiti / UniFi OS). Ubiquiti UniFi OS contains a path traversal vulnerability which could allow a malicious actor with access to the network to access files on the underlying system that could be manipulated to access an underlying account. NVD
  70. CVE-2026-34910 — Ubiquiti UniFi OS Improper Input Validation Vulnerability (Ubiquiti / UniFi OS). Ubiquiti UniFi OS contains an improper input validation vulnerability which could allow a malicious actor with access to the network to conduct command injection. NVD
  71. CVE-2025-67038 — Lantronix EDS5000 Code Injection Vulnerability (Lantronix / EDS5000). Lantronix EDS5000 contains a code injection vulnerability that could allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges. NVD
  72. CVE-2026-20253 — Splunk Enterprise Missing Authentication for Critical Function Vulnerability (Splunk / Enterprise). Splunk Enterprise contains a missing authentication for critical function vulnerability which could allow an unauthenticated user to create or truncate arbitrary files through a PostgreSQL sidecar service endpoint. NVD
  73. CVE-2026-48907 — Widget Factory Joomla Content Editor Improper Access Control Vulnerability (Widget Factory / Joomla Content Editor ). Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticated users. NVD
  74. CVE-2026-20262 — Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability (Cisco / Catalyst SD-WAN Manager). Cisco Catalyst SD-WAN Manager contains a directory or path traversal vulnerability that could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system. NVD
  75. CVE-2026-54420 — LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability (LiteSpeed / cPanel Plugin). LiteSpeed cPanel plugin contains a UNIX symbolic link (Symlink) following vulnerability that could allow a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS. NVD
  76. CVE-2026-35273 — Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability (Oracle / PeopleSoft Enterprise PeopleTools). Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise PeopleTools. NVD
  77. CVE-2026-10520 — Ivanti Sentry OS Command Injection Vulnerability (Ivanti / Sentry). Ivanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve root-level remote code execution. This vulnerability can be successfully exploited in cases where the Sentry appliance is in an unmanaged state with its endpoints externally reachable. The use of mTLS with EPMM or restricted HTTPS access through Neurons for MDM makes interfaces inaccessible to external actors. NVD
  78. CVE-2026-20245 — Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability (Cisco / Catalyst SD-WAN Manager). Cisco Catalyst SD-WAN Manager formerly SD-WAN vManage contains an improper encoding or escaping of output vulnerability. This vulnerability could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system. NVD
  79. CVE-2026-7473 — Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability (Arista / Extensible Operating System). Arista Extensible Operating System (EOS) contains an incomplete comparison with missing factors vulnerability when the switch incorrectly decapsulate and forwards other unexpected tunneled packet with a destination IP matching its configured decapsulation IP. NVD
  80. CVE-2026-11645 — Google Chromium V8 Out-of-Bounds Read and Write Vulnerability (Google / Chromium V8). Google Chromium V8 out-of-bounds read and write vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. NVD

Catálogo de exploits · referência

Metadados públicos de exploração ativa (KEV + EPSS). A GSAFE não publica PoCs nem payloads.

  1. CVE-2026-8037 — Progress LoadMaster Command Injection Vulnerability · EPSS 0.996 · Progress / LoadMaster · Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints.
  2. CVE-2026-35273 — Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability · EPSS 0.955 · Oracle / PeopleSoft Enterprise PeopleTools · Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise PeopleTools.
  3. CVE-2026-63077 — JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · EPSS 0.877 · JetBrains / TeamCity · JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol.
  4. CVE-2026-60004 — Gitea Code Injection Vulnerability · EPSS 0.868 · Gitea / Gitea · Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account.
  5. CVE-2026-15409 — SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability · EPSS 0.837 · SonicWall / SMA1000 Appliances · SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.
  6. CVE-2021-23758 — Ajax.NET Professional Deserialization of Untrusted Data Vulnerability · EPSS 0.836 · Ajax.NET Professional / Ajax.NET Professional · Ajax.NET Professional (AjaxPro) contains a deserialization of untrusted data vulnerability that could allow for remote code execution via arbitrary .NET classes. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.
  7. CVE-2026-72898 — Metabase SQL Injection Vulnerability · EPSS 0.823 · Metabase / Metabase · Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data.
  8. CVE-2026-45659 — Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability · EPSS 0.761 · Microsoft / SharePoint Server · Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.
  9. CVE-2026-33824 — Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability · EPSS 0.727 · Microsoft / Internet Key Exchange (IKE) Service Extensions · Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.
  10. CVE-2019-1068 — Microsoft SQL Server Remote Code Execution Vulnerability · EPSS 0.528 · Microsoft / SQL Server · Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine service account.
  11. CVE-2026-59310 — Broadcom VMware vCenter Path Traversal Vulnerability · EPSS 0.459 · Broadcom / VMware vCenter · Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code.
  12. CVE-2023-49105 — ownCloud Improper Authentication Vulnerability · EPSS 0.432 · ownCloud / ownCloud · ownCloud contains an improper authentication vulnerability that allows an attacker to access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured.
  13. CVE-2026-21962 — Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability · EPSS 0.420 · Oracle / HTTP Server and Oracle Weblogic Server Proxy Plug-in · Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in contain an improper access control vulnerability that can result in unauthorized creation, deletion or modification access to critical data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in accessible data.
  14. CVE-2026-12569 — PTC Windchill and FlexPLM Improper Input Validation Vulnerability · EPSS 0.406 · PTC / Windchill and FlexPLM · PTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attacker to execute arbitrary code by sending a malicious request to the network.
  15. CVE-2026-18556 — N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · EPSS 0.402 · N-able / N-central · N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.
  16. CVE-2026-55040 — Microsoft SharePoint Weak Authentication Vulnerability · EPSS 0.397 · Microsoft / SharePoint · Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network.
  17. CVE-2026-73570 — Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability · EPSS 0.324 · Synacor / Zimbra Collaboration Suite (ZCS) · Zimbra Collaboration Suite (ZCS) contains an OS command injection vulnerability which could allow an unauthenticated attacker to send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.
  18. CVE-2025-62593 — Ray-Project Ray Code Injection Vulnerability · EPSS 0.169 · Ray-Project / Ray · Ray-Project Ray contains a code injection vulnerability that could allow remote code execution. Developers using Ray as a development tool may be exposed to this vulnerability exploitable through Firefox and Safari.
  19. CVE-2026-64849 — MLflow Server-Side Request Forgery Vulnerability · EPSS 0.164 · MLflow / MLflow · MLflow contains a server-side request forgery vulnerability that can allow attackers to reach internal or cloud metadata services and receive response_status and response_body.
  20. CVE-2026-9586 — Sangoma Switchvox SQL Injection Vulnerability · EPSS 0.118 · Sangoma / Switchvox · Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.
  21. CVE-2026-15410 — SonicWall SMA1000 Appliances Code Injection Vulnerability · EPSS 0.118 · SonicWall / SMA1000 Appliances · SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.
  22. CVE-2026-48710 — Kludex Starlette HTTP Request/Response Smuggling Vulnerability · EPSS 0.110 · Kludex / Starlette · Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentication bypass when the authentication depends on the reconstructed URL’s path. This vulnerability could be chaned with CVE-2026-42271.
  23. CVE-2026-65400 — Apple macOS Improper Authentication Vulnerability · EPSS 0.099 · Apple / macOS · Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials.
  24. CVE-2022-0995 — Linux Kernel Out-of-Bounds Write Vulnerability · EPSS 0.095 · Linux / Kernel · Linux Kernel contains an out-of-bounds memory write vulnerability which could allow a local user to gain privileged access or cause a denial of service on the system.
  25. CVE-2015-3246 — Red Hat Libuser Race Condition Vulnerability · EPSS 0.088 · Red Hat / Libuser · Red Hat libuser contains a race condition vulnerability that allows authenticated local users to corrupt the /etc/passwd file to cause a denial of service or privilege escalation.
  26. CVE-2026-82329 — JFrog Artifactory Improper Authentication Vulnerability · EPSS 0.077 · JFrog / Artifactory · JFrog Artifactory contains an improper authentication vulnerability that under default configuration can allow an unauthenticated attacker with network access to obtain administrative privileges.
  27. CVE-2026-68820 — Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability · EPSS 0.062 · Microsoft / Windows Ancillary Function Driver for WinSock · Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.
  28. CVE-2015-5287 — Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability · EPSS 0.050 · Red Hat / Automatic Bug Reporting Tool · Red Hat Automatic Bug Reporting Tool (ABRT) contains a privilege escalation vulnerability that could allow local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.
  29. CVE-2026-20349 — Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability · EPSS 0.022 · Cisco / Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) · Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.
  30. CVE-2026-49869 — Kestra OSS OS Command Injection Vulnerability · EPSS 0.019 · Kestra / Kestra OSS · Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials.
  31. CVE-2026-72530 — TrueConf Server Code Injection Vulnerability · EPSS 0.018 · TrueConf / Server · TrueConf Server contains a code injection vulnerability that could allow an unauthorized remote attacker with network access via port 4307/TCP to use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.
  32. CVE-2026-83549 — SonicWall SMA1000 Appliances OS Command Injection Vulnerability · EPSS 0.016 · SonicWall / SMA1000 Appliances · SonicWall SMA1000 Appliances contains an OS command injection vulnerability that could enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.
  33. CVE-2026-8452 — Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability · EPSS 0.016 · Citrix / NetScaler ADC and NetScaler Gateway · Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability which could lead to denial of service.
  34. CVE-2026-72529 — TrueConf Server Missing Authentication for Critical Function Vulnerability · EPSS 0.016 · TrueConf / Server · TrueConf Server contains a missing authentication for critical function vulnerability which could allow a remote unauthorized attacker with network access via port 4307/TCP to execute an arbitrary script.
  35. CVE-2026-82078 — PaperCut NG/MF Unsafe Reflection Vulnerability · EPSS 0.009 · PaperCut / NG/MF · PaperCut NG/MF contains an unsafe reflection vulnerability that allows an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process. This vulnerability can be chained with CVE-2026-81578.
  36. CVE-2026-59822 — BerriAI LiteLLM Improper Authentication Vulnerability · EPSS 0.009 · BerriAI / LiteLLM · BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token.
  37. CVE-2026-81578 — PaperCut NG/MF Missing Authentication for Critical Function Vulnerability · EPSS 0.008 · PaperCut / NG/MF · PaperCut NG/MF contains a missing authentication for critical function vulnerability which allows an unauthenticated remote attacker to modify certain system configurations. This vulnerability can be chained with CVE-2026-82078.
  38. CVE-2026-83548 — SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability · EPSS 0.007 · SonicWall / SMA1000 Appliances · SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations.
  39. CVE-2026-66384 — JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability · EPSS 0.006 · JFrog / Artifactory · JFrog Artifactory contains an improper limitation of a pathname to a restricted directory vulnerability. This can allow an authenticated user to write data outside the intended Docker cache path under specific remote-repository conditions.
  40. CVE-2026-53362 — Linux Kernel Unspecified Vulnerability · EPSS 0.005 · Linux / Kernel · Linux Kernel contains an unspecified vulnerability that can allow for privilege escalation via IPv6 networking subsystem. This vulnerability can impact multiple products, including but not limited to Suse, Red Hat, and other products using Linux.

Feed de notícias de segurança