⚠️ Active Threat Intelligence · 2026-07-12

Cybersecurity Intelligence Briefings

AI-synthesized threat briefings from 18 sources · CVSS + EPSS + CISA KEV · Signal DNA · Vendor Risk

39 briefings 32 KEV-confirmed Updated 2026-07-12
7,222 CVE objects1,752 vendors16,300 source articles— every object has a UUID · query it live via MCP
⚡ Every CVE on this page is a live object — query CVEs, KEV alerts & vendor risk via MCP API. Free trial, 50 calls, no card.cyber.mcp.brunosan.de →
Latest Briefing CVE-2026-59928WATCH

CVE-2026-59856 in Vim: Arbitrary Code Execution via PHP Omni-Completion — Patch Available, No Active Exploitation

CVE-2026-59856: Vim arbitrary code execution via PHP omni-completion. Patch available. No active exploitation. CVSS 8.4, EPSS 0.00169.

July 12, 2026 Score 32/100 · Risk 0.003 · 18 sources Full Analysis →
Query CVE-2026-59928 via MCP →
July 11, 2026
CVE-2026-0257KEV

CVE-2026-0257 in Palo Alto Networks PAN-OS GlobalProtect: CISA KEV-Listed Auth Bypass Under Active Exploitation

CVE-2026-0257 in Palo Alto PAN-OS GlobalProtect is a CISA KEV-listed authentication bypass under active exploitation; patch internet-exposed appliances immediately.

Full Analysis → Query CVE-2026-0257 via MCP →
June 01, 2026
CVE-2026-0257KEV

CVE-2026-0257 in Palo Alto Networks PAN-OS: Actively Exploited Authentication Bypass Added to CISA KEV

An authentication bypass vulnerability, CVE-2026-0257, affects the GlobalProtect feature in Palo Alto Networks PAN-OS.. CONFIRMED active exploitation in the wild has led to its addition to the CISA Known Exploited Vulne…

Full Analysis → Query CVE-2026-0257 via MCP →
May 27, 2026
CVE-2026-41091KEV

CVE-2026-41091 in Unspecified Microsoft Product: Confirmed Exploitation (CISA KEV)

CVE-2026-41091 is an unspecified vulnerability in a Microsoft product with no public technical details.. CONFIRMED: The vulnerability was added to the CISA Known Exploited Vulnerabilities (KEV) catalog on 2026-05-20, in…

Full Analysis → Query CVE-2026-41091 via MCP →
May 23, 2026
CVE-2026-9082KEV

CVE-2026-9082 in Unspecified Product: Actively Exploited and Added to CISA KEV Catalog

CVE-2026-9082 is a critical vulnerability (CVSS 9.5) in an unspecified product that is under active exploitation.. CONFIRMED: CISA added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on May 22,…

Full Analysis → Query CVE-2026-9082 via MCP →
May 22, 2026
CVE-2026-41091KEV

CVE-2026-41091 in Microsoft Defender: Actively Exploited Zero-Day Added to CISA KEV

Two vulnerabilities, CVE-2026-41091 and CVE-2026-45498, affect Microsoft Defender.. CONFIRMED: Both vulnerabilities are being actively exploited in the wild and have been added to the CISA KEV catalog.

Full Analysis → Query CVE-2026-41091 via MCP →
May 21, 2026
CVE-2026-41091KEV

CVE-2026-41091 in Microsoft Windows BitLocker: Confirmed Exploitation (KEV)

A security feature bypass vulnerability exists in the Microsoft Windows BitLocker feature.. CONFIRMED exploitation in the wild. CISA added CVE-2026-41091 to its Known Exploited Vulnerabilities (KEV) catalog on 2026-05-2…

Full Analysis → Query CVE-2026-41091 via MCP →
May 16, 2026
CVE-2026-20182KEV

CVE-2026-20182 in Cisco Catalyst SD-WAN Controller: Actively Exploited, Added to CISA KEV

A critical vulnerability in Cisco Catalyst SD-WAN Controller is being exploited to gain administrative access.. CONFIRMED: This vulnerability was added to the CISA Known Exploited Vulnerabilities (KEV) catalog on 2026-0…

Full Analysis → Query CVE-2026-20182 via MCP →
May 15, 2026
CVE-2026-20182KEV

CVE-2026-20182 in Cisco Catalyst SD-WAN Controller: Actively Exploited Zero-Day Authentication Bypass

An authentication bypass vulnerability in Cisco Catalyst SD-WAN Controller allows unauthenticated, remote attackers to gain administrator access.. CONFIRMED exploitation in the wild. This vulnerability was added to the …

Full Analysis → Query CVE-2026-20182 via MCP →
May 10, 2026
CVE-2026-31431KEV

CVE-2026-31431 in Linux Kernel: 'Dirty Frag' LPE Vulnerability Actively Exploited, Affects Juniper and Major Distributions

A Local Privilege Escalation (LPE) vulnerability, named 'Dirty Frag', exists in the Linux Kernel, allowing a local unprivileged user to gain root access.. CONFIRMED EXPLOITATION: This vulnerability was added to the CISA…

Full Analysis → Query CVE-2026-31431 via MCP →
May 09, 2026
CVE-2026-31431KEV

CVE-2026-31431 in Linux Kernel: Actively Exploited LPE Affecting Multiple Distributions and Juniper Products

CVE-2026-31431 is a Local Privilege Escalation (LPE) vulnerability, nicknamed 'Dirty Frag', within the Linux Kernel, affecting major distributions and downstream vendor products like those from Juniper.. CONFIRMED explo…

Full Analysis → Query CVE-2026-31431 via MCP →
May 08, 2026
CVE-2026-6973KEV

CVE-2026-6973 in Ivanti EPMM: Actively Exploited RCE Added to CISA KEV Catalog

CVE-2026-6973 is a remote code execution (RCE) vulnerability in Ivanti Endpoint Manager Mobile (EPMM), formerly MobileIron Core.. CONFIRMED exploitation in the wild. CISA added this vulnerability to its Known Exploited …

Full Analysis → Query CVE-2026-6973 via MCP →
CVE-2026-0300KEV

CVE-2026-0300 in Palo Alto Networks PAN-OS: Actively Exploited Zero-Day Added to CISA KEV

A remote code execution (RCE) vulnerability, CVE-2026-0300, affects Palo Alto Networks PAN-OS.. CONFIRMED: The vulnerability is under active exploitation and has been added to the CISA Known Exploited Vulnerabilities (K…

Full Analysis → Query CVE-2026-0300 via MCP →
May 07, 2026
CVE-2026-31431KEV

CVE-2026-31431 in Linux Kernel: Actively Exploited Zero-Day Added to CISA KEV

CVE-2026-31431, named 'Copy Fail', is a vulnerability in the Linux Kernel, with Debian confirmed to be affected.. CONFIRMED exploitation in the wild. This vulnerability was added to the CISA Known Exploited Vulnerabilit…

Full Analysis → Query CVE-2026-31431 via MCP →
CVE-2026-0300KEV

CVE-2026-0300 in Palo Alto Networks PAN-OS: Actively Exploited Zero-Day RCE Added to CISA KEV

An unauthenticated Remote Code Execution (RCE) zero-day vulnerability, CVE-2026-0300, affects Palo Alto Networks PAN-OS firewalls.. CONFIRMED: The vulnerability is under active exploitation in the wild and has been adde…

Full Analysis → Query CVE-2026-0300 via MCP →
May 06, 2026
CVE-2026-29014KEV

CVE-2026-29014 in Apache HTTP Server: Critical Vulnerability with High Exploit Potential

A critical vulnerability, CVE-2026-29014, with a CVSS score of 9.8 has been reported in a product from The Apache Software Foundation, likely the Apache HTTP Server.. Exploitation is not confirmed in the wild (not in CI…

Full Analysis → Query CVE-2026-29014 via MCP →
May 05, 2026
CVE-2026-31431KEV

CVE-2026-31431 in QNAP NAS: Confirmed Exploitation of Privilege Escalation Vulnerability

CVE-2026-31431 is a local privilege escalation (LPE) vulnerability affecting QNAP NAS devices, likely within the underlying Linux kernel.. CONFIRMED exploitation in the wild. CISA added this vulnerability to its Known E…

Full Analysis → Query CVE-2026-31431 via MCP →
May 04, 2026
CVE-2026-31431KEV

CVE-2026-31431 in Linux Kernel: Actively Exploited Privilege Escalation Vulnerability Added to CISA KEV

CVE-2026-31431 is a local privilege escalation (LPE) vulnerability in the Linux Kernel, allowing an attacker with initial access to gain root privileges.. CONFIRMED active exploitation in the wild. CISA added this vulne…

Full Analysis → Query CVE-2026-31431 via MCP →
May 01, 2026
CVE-2026-41940KEV

CVE-2026-41940 in cPanel/WHM: Actively Exploited RCE Added to CISA KEV Catalog

CVE-2026-41940 is a critical vulnerability, reportedly enabling Remote Code Execution (RCE) in cPanel and WHM. Some reports also link it to Google Gemini CLI.. CONFIRMED: The vulnerability is under active exploitation a…

Full Analysis → Query CVE-2026-41940 via MCP →
April 30, 2026
CVE-2024-1708KEV

CVE-2024-1708 in ConnectWise ScreenConnect: CISA KEV Confirms Active Exploitation

CVE-2024-1708 is an authentication bypass vulnerability in ConnectWise ScreenConnect versions 23.9.7 and earlier.. CONFIRMED active exploitation in the wild, leading to its addition to the CISA Known Exploited Vulnerabi…

Full Analysis → Query CVE-2024-1708 via MCP →
April 16, 2026
CVE-2026-40175

CVE-2026-40175 in Axios: Critical (CVSS 10.0) Header Injection Vulnerability Disclosed

A critical (CVSS 10.0) header injection vulnerability in the Axios HTTP client library, CVE-2026-40175, can be chained with a proxy bypass (CVE-2025-62718) to enable Server-Side Request Forgery (SSRF) and cloud metadata…

Full Analysis → Query CVE-2026-40175 via MCP →
April 15, 2026
CVE-2009-0238KEV

CVE-2009-0238 in Microsoft Products: Actively Exploited, Added to CISA KEV

CVE-2009-0238, a legacy vulnerability in an unspecified Microsoft product, has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation.. The vulnerability has a high EPSS sco…

Full Analysis → Query CVE-2009-0238 via MCP →
April 14, 2026
CVE-2026-34621KEV

CVE-2026-34621 in Adobe Acrobat and Reader: Actively Exploited Zero-Day (KEV)

A critical Remote Code Execution (RCE) vulnerability, CVE-2026-34621, affects Adobe Acrobat and Reader.. CONFIRMED exploitation in the wild. CISA added this vulnerability to its Known Exploited Vulnerabilities (KEV) cat…

Full Analysis → Query CVE-2026-34621 via MCP →
April 11, 2026
CVE-2026-5914

CVE-2026-5914 in Microsoft Product: High CVSS Score with Low Exploitation Probability

Microsoft has disclosed CVE-2026-5914, a high-severity vulnerability with a CVSS score of 8.8.. There is no evidence of active exploitation (Not in CISA KEV) and the statistical probability of exploitation in the next 3…

Full Analysis → Query CVE-2026-5914 via MCP →
April 09, 2026
CVE-2026-1340KEV

CVE-2026-1340 in IBM Product: Actively Exploited, Added to CISA KEV

An unspecified vulnerability in an IBM product, CVE-2026-1340, is under active exploitation.. CONFIRMED: The vulnerability was added to the CISA Known Exploited Vulnerabilities (KEV) catalog on 2026-04-08. EPSS score is…

Full Analysis → Query CVE-2026-1340 via MCP →
April 08, 2026
CVE-2025-59528

CVE-2025-59528 in Flowise AI: Critical RCE with Reported Active Exploitation

A critical remote code execution (RCE) vulnerability, CVE-2025-59528, affects Flowise AI Agent Builder, assigned a CVSS score of 10.0.. Active exploitation is REPORTED in the wild. The vulnerability has a high EPSS scor…

Full Analysis → Query CVE-2025-59528 via MCP →
April 04, 2026
CVE-2026-5281KEV

CVE-2026-5281 in Microsoft Edge (Chromium-based): Actively Exploited Zero-Day

A high-severity use-after-free vulnerability (CVE-2026-5281) exists in the underlying Chromium engine used by Microsoft Edge.. CONFIRMED: This vulnerability is under active exploitation in the wild and has been added to…

Full Analysis → Query CVE-2026-5281 via MCP →
April 03, 2026
CVE-2026-5281KEV

CVE-2026-5281 in Microsoft Product: Actively Exploited, CISA KEV Added

CVE-2026-5281 is a high-severity (CVSS 7.5) vulnerability in an unspecified Microsoft product.. CONFIRMED: The vulnerability was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2026-04-01, indicating ac…

Full Analysis → Query CVE-2026-5281 via MCP →
April 02, 2026
CVE-2026-5281KEV

CVE-2026-5281 in Google Chrome: Confirmed Exploitation in CISA KEV Catalog

A high-severity vulnerability, CVE-2026-5281, affects Google Chrome.. The vulnerability is confirmed to be actively exploited in the wild and has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog.

Full Analysis → Query CVE-2026-5281 via MCP →
April 01, 2026
CVE-2026-33895

CVE-2026-33895 in Forge: High-Severity Cryptographic Flaws with Low Exploitation Probability

Two high-severity vulnerabilities, CVE-2026-33895 and CVE-2026-33896, have been disclosed in Forge's cryptographic libraries, affecting Ed25519 signature validation and certificate chain verification.. There is no evide…

Full Analysis → Query CVE-2026-33895 via MCP →
March 30, 2026
CVE-2026-32922

CVE-2026-32922: Critical Vulnerability Published with 9.9 CVSS, Lacks Technical Details and Vendor Confirmation

A critical vulnerability, CVE-2026-32922, has been published with a CVSS score of 9.9. The affected vendor and product are currently unknown.. There is no evidence of active exploitation. The vulnerability is not listed…

Full Analysis → Query CVE-2026-32922 via MCP →
March 29, 2026
CVE-2026-30302KEV

CVE-2026-30302 in Cisa Product: Critical Vulnerability with Low Current Exploitation Probability

A critical vulnerability, CVE-2026-30302, with a CVSS score of 10.0 has been disclosed in a Cisa product. Specific product and version details are not yet available.. CONFIRMED: The vulnerability is not listed on CISA's…

Full Analysis → Query CVE-2026-30302 via MCP →
March 28, 2026
CVE-2026-4680

CVE-2026-4680 in Microsoft Edge (Chromium-based): High-Severity Vulnerability in Routine Patch

CVE-2026-4680 is a high-severity (CVSS 8.8) Use-After-Free vulnerability in Microsoft Edge, inherited from the upstream Chromium project.. CONFIRMED exploitation has not been observed. The vulnerability is not listed in…

Full Analysis → Query CVE-2026-4680 via MCP →
March 24, 2026
CVE-2024-37085KEV

CVE-2024-37085 in Microsoft Products: Actively Exploited in GPO-Based Ransomware Attacks (KEV Confirmed)

CVE-2024-37085 is an unspecified vulnerability in Microsoft products, confirmed by CISA to be actively exploited in the wild.. The vulnerability is leveraged in ransomware campaigns that manipulate Group Policy Objects …

Full Analysis → Query CVE-2024-37085 via MCP →
CVE-2023-23397KEV

CVE-2023-23397 in Microsoft Outlook: Critical Elevation of Privilege Under Persistent Exploitation

CVE-2023-23397 is a critical (CVSS 9.8) Elevation of Privilege vulnerability in Microsoft Outlook that can be exploited with zero user interaction.. CONFIRMED exploitation in the wild. This vulnerability is listed on CI…

Full Analysis → Query CVE-2023-23397 via MCP →
CVE-2022-42475KEV

CVE-2022-42475 in Fortinet FortiOS: Confirmed Exploitation Mandates Immediate Action

CVE-2022-42475 is a heap-based buffer overflow vulnerability in Fortinet's FortiOS SSL-VPN.. CONFIRMED exploitation in the wild. This vulnerability is listed on CISA's KEV catalog and has an EPSS score of 93.98%, indica…

Full Analysis → Query CVE-2022-42475 via MCP →
March 23, 2026
CVE-2024-37085KEV

CVE-2024-37085 in Microsoft Product: Confirmed Exploitation in GPO-Based Ransomware Attacks

CVE-2024-37085 is a vulnerability in an unspecified Microsoft product, confirmed by CISA to be actively exploited in the wild.. Exploitation is linked to ransomware campaigns that leverage Group Policy Objects (GPOs) fo…

Full Analysis → Query CVE-2024-37085 via MCP →
CVE-2023-22518KEV

CVE-2023-22518 in Schneider Electric Products: Critical, Actively Exploited Persistent Threat

A critical vulnerability, identified as CVE-2023-22518, is reported to affect multiple Schneider Electric industrial control system (ICS) products, including the EcoStruxure and SCADAPack lines.. The vulnerability is co…

Full Analysis → Query CVE-2023-22518 via MCP →
CVE-2022-42475KEV

CVE-2022-42475 in Fortinet FortiOS SSL-VPN: Actively Exploited RCE Demands Immediate Patching

CVE-2022-42475 is a critical (CVSS 9.8) heap-based buffer overflow vulnerability in Fortinet's FortiOS SSL-VPN service.. CONFIRMED exploitation in the wild. The vulnerability is listed on CISA's KEV catalog and has a hi…

Full Analysis → Query CVE-2022-42475 via MCP →