What's new

Latest updates

New analyses, newly exploited CVEs and the latest vendor advisories, newest first.

New analyses

Newly exploited

Added to CISA's Known Exploited Vulnerabilities catalog in the last six months.

Added to KEVCVEVendor / productIssue
1 Oct 2026CVE-2026-104286Fortinet · FortiMailFortiMail Path Traversal
22 Sept 2026CVE-2026-93616Check Point · Security Management and SmartConsoleDirectory Traversal and File upload allows execution of arbitrary script on the Management Server
22 Sept 2026CVE-2026-85102Check Point · Quantum Security GatewayImproper Certificate Validation in Quantum Security Gateway
9 Sept 2026CVE-2025-25249Fortinet · FortiOSHeap-based buffer overflow in FortiOS, FortiSwitchManager
27 Jul 2026CVE-2025-68686Fortinet · FortiOSFortiOS Exposure of Sensitive Information to an Unauthorized Actor
22 Jul 2026CVE-2026-16232Check Point · Security Management and SmartConsoleAuthentication Bypass in the SmartConsole Login Process Using an Application Token
16 Jul 2026CVE-2026-25089Fortinet · FortiSandboxFortiSandbox OS Command Injection
16 Jul 2026CVE-2026-39808Fortinet · FortiSandboxFortiSandbox OS Command Injection
8 Jun 2026CVE-2026-50751Check Point · Quantum Security GatewayUser Authentication Bypass in VPN Remote Access and Mobile AccessRansomware
29 May 2026CVE-2026-0257Palo Alto Networks · PAN-OSGlobalProtect Authentication Bypass VulnerabilitiesRansomware
6 May 2026CVE-2026-0300Palo Alto Networks · PAN-OSUnauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal
13 Apr 2026CVE-2026-21643Fortinet · FortiClient and EMSFortiClient EMS SQL Injection

Latest vendor advisories

PublishedCVEVendor / productIssueSeverityEPSS
1 Oct 2026CVE-2026-104286Fortinet · FortiMailFortiMail Path TraversalCRITICAL2.2%
22 Sept 2026CVE-2026-84388Fortinet · Other security productsImproper restriction of rendered ui layers or frames in FortiPAM Chrome ExtensionCRITICAL0.38%
22 Sept 2026CVE-2026-93616Check Point · Security Management and SmartConsoleDirectory Traversal and File upload allows execution of arbitrary script on the Management ServerCRITICAL20%
16 Sept 2026CVE-2026-91843Check Point · Security Management and SmartConsoleStack overflow in login process to the Security Management and Log ServersCRITICAL0.52%
15 Sept 2026CVE-2026-40058CrowdStrike · Falcon sensorVulnerability Affecting Office Macro Removal in CrowdStrike Falcon Sensor for WindowsHIGH0.08%
11 Sept 2026CVE-2026-15710Netskope · Netskope Client and Endpoint DLPNetskope Client Endpoint DLP Kernel Driver Information LeakageMEDIUM0.10%
10 Sept 2026CVE-2026-16174Netskope · Netskope Client and Endpoint DLPNetskope Endpoint DLP Driver Integer Overflow Leading to Kernel Pool OverflowHIGH0.13%
10 Sept 2026CVE-2026-16172Netskope · Netskope Client and Endpoint DLPNetskope Endpoint DLP Service Out-of-Bounds Read Leading to Process CrashMEDIUM0.11%
9 Sept 2026CVE-2026-0310Palo Alto Networks · PAN-OSBuffer Overflow Vulnerability via XML ProcessingHIGH0.37%
9 Sept 2026CVE-2026-0309Palo Alto Networks · PAN-OSAuthenticated Command Injection in CLI with Luna HSM ConfigurationMEDIUM0.45%
9 Sept 2026CVE-2026-0308Palo Alto Networks · PAN-OSStored Cross-Site Scripting (XSS) Vulnerability in the Web InterfaceLOW0.27%
9 Sept 2026CVE-2026-0307Palo Alto Networks · GlobalProtect AppLocal Privilege Escalation VulnerabilitiesMEDIUM0.10%
9 Sept 2026CVE-2026-0306Palo Alto Networks · Prisma AccessEndPoint DLP Bypass Vulnerability on WindowsMEDIUM0.10%
9 Sept 2026CVE-2026-0305Palo Alto Networks · Prisma AccessInformation Disclosure Vulnerability on LinuxMEDIUM0.10%
9 Sept 2026CVE-2026-0304Palo Alto Networks · Cortex XDRPrivilege Escalation VulnerabilityMEDIUM0.22%

Get alerts

A notification when we publish a new analysis or a covered vendor gets a new actively exploited CVE. No account, no email.