CVE Intelligence
Actively exploited vulnerabilities from CISA's Known Exploited Vulnerabilities catalog — with IT Intelligence's analysis of real-world impact and specific remediation steps.
Actively exploited vulnerabilities from CISA's Known Exploited Vulnerabilities catalog — with IT Intelligence's analysis of real-world impact and specific remediation steps.
Updated August 17, 2026
Patch Cisco Firewalls Against Denial of Service
A heap inspection vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly. This vulnerability is significant because it can be exploited by an unauthenticated attacker, potentially causing network disruptions. The vulnerability's impact is increased due to its ease of exploitation.
Update Windows to Prevent Privilege Escalation
A use-after-free vulnerability in Microsoft Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. This vulnerability is concerning because it can be used by an attacker to gain elevated access to sensitive information and systems. The vulnerability's impact is increased due to its potential for lateral movement within a network.
Patch Metabase Against SQL Injection Attacks
A SQL Injection vulnerability in Metabase allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database. This vulnerability is critical because it can be exploited by an unauthenticated attacker, potentially giving them administrator access to the instance. The vulnerability's impact is increased due to its ease of exploitation and potential for significant data breaches.
Update Progress LoadMaster to Prevent Command Injection
A command injection vulnerability in Progress LoadMaster allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance. This vulnerability is critical because it can be exploited by an unauthenticated attacker, potentially giving them complete control over the appliance. The vulnerability's impact is increased due to its ease of exploitation and potential for significant disruptions.
Patch JetBrains TeamCity Against Remote Code Execution
A deserialization of untrusted data vulnerability in JetBrains TeamCity allows unauthenticated remote code execution via the agent polling protocol. This vulnerability is critical because it can be exploited by an unauthenticated attacker, potentially giving them complete control over the system. The vulnerability's impact is increased due to its ease of exploitation and potential for significant disruptions.
Update N-able N-central to Prevent Authentication Bypass
An authentication bypass using an alternate path or channel vulnerability in N-able N-central allows for authentication bypass. This vulnerability is significant because it can be exploited by an attacker, potentially giving them unauthorized access to sensitive information and systems. The vulnerability's impact is increased due to its potential for lateral movement within a network.
Patch Apache Tomcat Against Sensitive Data Exposure
A missing encryption of sensitive data vulnerability in Apache Tomcat allows the bypass of the EncryptInterceptor. This vulnerability is significant because it can be exploited by an attacker, potentially giving them access to sensitive information. The vulnerability's impact is increased due to its potential for significant data breaches.
Update IBM Langflow to Prevent Remote Code Execution
A code injection vulnerability in IBM Langflow allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments. This vulnerability is critical because it can be exploited by an unauthenticated attacker, potentially giving them complete control over the system. The vulnerability's impact is increased due to its ease of exploitation and potential for significant disruptions.