<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom"><title>Exploit Reality — New KEV entries</title><link href="https://xploitwatch.com/feed/kev.xml" rel="self"/><link href="https://xploitwatch.com/"/><id>https://xploitwatch.com/feed/kev.xml</id><updated>2026-09-30T00:00:00Z</updated><author><name>Exploit Reality</name></author><entry><title>CVE-2026-76504 — Cisco Catalyst SD-WAN Manager</title><link href="https://xploitwatch.com/cve/CVE-2026-76504"/><id>https://xploitwatch.com/cve/CVE-2026-76504</id><updated>2026-09-30T00:00:00Z</updated><summary>Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability</summary></entry><entry><title>CVE-2026-86950 — Apple Multiple Products</title><link href="https://xploitwatch.com/cve/CVE-2026-86950"/><id>https://xploitwatch.com/cve/CVE-2026-86950</id><updated>2026-09-29T00:00:00Z</updated><summary>Apple Multiple Products Out-of-Bounds Write Vulnerability</summary></entry><entry><title>CVE-2026-88772 — Citrix NetScaler</title><link href="https://xploitwatch.com/cve/CVE-2026-88772"/><id>https://xploitwatch.com/cve/CVE-2026-88772</id><updated>2026-09-27T00:00:00Z</updated><summary>Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability</summary></entry><entry><title>CVE-2026-88771 — Citrix NetScaler</title><link href="https://xploitwatch.com/cve/CVE-2026-88771"/><id>https://xploitwatch.com/cve/CVE-2026-88771</id><updated>2026-09-27T00:00:00Z</updated><summary>Citrix NetScaler Improper Input Validation Vulnerability</summary></entry><entry><title>CVE-2026-87902 — WordPress Core</title><link href="https://xploitwatch.com/cve/CVE-2026-87902"/><id>https://xploitwatch.com/cve/CVE-2026-87902</id><updated>2026-09-25T00:00:00Z</updated><summary>WordPress Core Remote File Inclusion Vulnerability</summary></entry><entry><title>CVE-2026-67279 — MikroTik RouterOS</title><link href="https://xploitwatch.com/cve/CVE-2026-67279"/><id>https://xploitwatch.com/cve/CVE-2026-67279</id><updated>2026-09-25T00:00:00Z</updated><summary>Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability</summary></entry><entry><title>CVE-2026-65660 — Microsoft SharePoint</title><link href="https://xploitwatch.com/cve/CVE-2026-65660"/><id>https://xploitwatch.com/cve/CVE-2026-65660</id><updated>2026-09-25T00:00:00Z</updated><summary>Microsoft SharePoint Code Injection Vulnerability</summary></entry><entry><title>CVE-2026-71362 — Adobe Commerce and Magento </title><link href="https://xploitwatch.com/cve/CVE-2026-71362"/><id>https://xploitwatch.com/cve/CVE-2026-71362</id><updated>2026-09-24T00:00:00Z</updated><summary>Adobe Commerce and Magento Incorrect Authorization Vulnerability </summary></entry><entry><title>CVE-2026-5430 — WSO2 Multiple Products</title><link href="https://xploitwatch.com/cve/CVE-2026-5430"/><id>https://xploitwatch.com/cve/CVE-2026-5430</id><updated>2026-09-24T00:00:00Z</updated><summary>WSO2 Multiple Products Path Traversal Vulnerability </summary></entry><entry><title>CVE-2026-94127 — F5 BIG-IP APM</title><link href="https://xploitwatch.com/cve/CVE-2026-94127"/><id>https://xploitwatch.com/cve/CVE-2026-94127</id><updated>2026-09-22T00:00:00Z</updated><summary>F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability</summary></entry><entry><title>CVE-2026-93952 — Arista VeloCloud Orchestrator</title><link href="https://xploitwatch.com/cve/CVE-2026-93952"/><id>https://xploitwatch.com/cve/CVE-2026-93952</id><updated>2026-09-22T00:00:00Z</updated><summary>Arista VeloCloud Orchestrator Improper Input Validation Vulnerability</summary></entry><entry><title>CVE-2026-93616 — Check Point Multiple Products</title><link href="https://xploitwatch.com/cve/CVE-2026-93616"/><id>https://xploitwatch.com/cve/CVE-2026-93616</id><updated>2026-09-22T00:00:00Z</updated><summary>Check Point Multiple Products Path Traversal Vulnerability</summary></entry><entry><title>CVE-2026-85102 — Check Point Multiple Products</title><link href="https://xploitwatch.com/cve/CVE-2026-85102"/><id>https://xploitwatch.com/cve/CVE-2026-85102</id><updated>2026-09-22T00:00:00Z</updated><summary>Check Point Multiple Products Improper Certificate Validation Vulnerability</summary></entry><entry><title>CVE-2026-7273 — Zyxel GS1900 Series Switches</title><link href="https://xploitwatch.com/cve/CVE-2026-7273"/><id>https://xploitwatch.com/cve/CVE-2026-7273</id><updated>2026-09-21T00:00:00Z</updated><summary>Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability</summary></entry><entry><title>CVE-2026-53266 — Linux Kernel</title><link href="https://xploitwatch.com/cve/CVE-2026-53266"/><id>https://xploitwatch.com/cve/CVE-2026-53266</id><updated>2026-09-18T00:00:00Z</updated><summary>Linux Kernel Out-of-Bounds Write Vulnerability</summary></entry><entry><title>CVE-2025-39964 — Linux Kernel</title><link href="https://xploitwatch.com/cve/CVE-2025-39964"/><id>https://xploitwatch.com/cve/CVE-2025-39964</id><updated>2026-09-18T00:00:00Z</updated><summary>Linux Kernel Race Condition Vulnerability</summary></entry><entry><title>CVE-2025-39682 — Linux Kernel</title><link href="https://xploitwatch.com/cve/CVE-2025-39682"/><id>https://xploitwatch.com/cve/CVE-2025-39682</id><updated>2026-09-18T00:00:00Z</updated><summary>Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability</summary></entry><entry><title>CVE-2026-87886 — Acronis Backup</title><link href="https://xploitwatch.com/cve/CVE-2026-87886"/><id>https://xploitwatch.com/cve/CVE-2026-87886</id><updated>2026-09-16T00:00:00Z</updated><summary>Acronis Backup Incorrect Default Permissions Vulnerability</summary></entry><entry><title>CVE-2026-76460 — Cisco Identity Services Engine</title><link href="https://xploitwatch.com/cve/CVE-2026-76460"/><id>https://xploitwatch.com/cve/CVE-2026-76460</id><updated>2026-09-16T00:00:00Z</updated><summary>Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability</summary></entry><entry><title>CVE-2026-58704 — Google Pixel</title><link href="https://xploitwatch.com/cve/CVE-2026-58704"/><id>https://xploitwatch.com/cve/CVE-2026-58704</id><updated>2026-09-16T00:00:00Z</updated><summary>Google Pixel Improper Authorization Vulnerability</summary></entry><entry><title>CVE-2026-76461 — Cisco Secure Email Gateway</title><link href="https://xploitwatch.com/cve/CVE-2026-76461"/><id>https://xploitwatch.com/cve/CVE-2026-76461</id><updated>2026-09-14T00:00:00Z</updated><summary>Cisco Secure Email Gateway SQL Injection Vulnerability</summary></entry><entry><title>CVE-2026-85706 — GitLab Community Edition and Enterprise Edition</title><link href="https://xploitwatch.com/cve/CVE-2026-85706"/><id>https://xploitwatch.com/cve/CVE-2026-85706</id><updated>2026-09-11T00:00:00Z</updated><summary>GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability</summary></entry><entry><title>CVE-2026-84869 — ConnectWise ScreenConnect</title><link href="https://xploitwatch.com/cve/CVE-2026-84869"/><id>https://xploitwatch.com/cve/CVE-2026-84869</id><updated>2026-09-11T00:00:00Z</updated><summary>ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability</summary></entry><entry><title>CVE-2026-42018 — JFrog Artifactory</title><link href="https://xploitwatch.com/cve/CVE-2026-42018"/><id>https://xploitwatch.com/cve/CVE-2026-42018</id><updated>2026-09-11T00:00:00Z</updated><summary>JFrog Artifactory Improper Authentication Vulnerability</summary></entry><entry><title>CVE-2026-42016 — JFrog Artifactory</title><link href="https://xploitwatch.com/cve/CVE-2026-42016"/><id>https://xploitwatch.com/cve/CVE-2026-42016</id><updated>2026-09-11T00:00:00Z</updated><summary>JFrog Artifactory Incorrect Authorization Vulnerability</summary></entry><entry><title>CVE-2026-86060 — MikroTik RouterOS</title><link href="https://xploitwatch.com/cve/CVE-2026-86060"/><id>https://xploitwatch.com/cve/CVE-2026-86060</id><updated>2026-09-10T00:00:00Z</updated><summary>MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability</summary></entry><entry><title>CVE-2026-67277 — MikroTik RouterOS</title><link href="https://xploitwatch.com/cve/CVE-2026-67277"/><id>https://xploitwatch.com/cve/CVE-2026-67277</id><updated>2026-09-10T00:00:00Z</updated><summary>MikroTik RouterOS Missing Authentication for Critical Function Vulnerability</summary></entry><entry><title>CVE-2026-87491 — Google Chromium V8</title><link href="https://xploitwatch.com/cve/CVE-2026-87491"/><id>https://xploitwatch.com/cve/CVE-2026-87491</id><updated>2026-09-09T00:00:00Z</updated><summary>Google Chromium V8 Out of Bounds Write Vulnerability</summary></entry><entry><title>CVE-2026-20079 — Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management</title><link href="https://xploitwatch.com/cve/CVE-2026-20079"/><id>https://xploitwatch.com/cve/CVE-2026-20079</id><updated>2026-09-09T00:00:00Z</updated><summary>Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability</summary></entry><entry><title>CVE-2026-19490 — Citrix NetScaler</title><link href="https://xploitwatch.com/cve/CVE-2026-19490"/><id>https://xploitwatch.com/cve/CVE-2026-19490</id><updated>2026-09-09T00:00:00Z</updated><summary>Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability</summary></entry><entry><title>CVE-2025-25249 — Fortinet Multiple Products</title><link href="https://xploitwatch.com/cve/CVE-2025-25249"/><id>https://xploitwatch.com/cve/CVE-2025-25249</id><updated>2026-09-09T00:00:00Z</updated><summary>Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability</summary></entry><entry><title>CVE-2026-86218 — N-able N-central</title><link href="https://xploitwatch.com/cve/CVE-2026-86218"/><id>https://xploitwatch.com/cve/CVE-2026-86218</id><updated>2026-09-08T00:00:00Z</updated><summary>N-able N-central Static Code Injection Vulnerability</summary></entry><entry><title>CVE-2026-85880 — Microsoft Windows</title><link href="https://xploitwatch.com/cve/CVE-2026-85880"/><id>https://xploitwatch.com/cve/CVE-2026-85880</id><updated>2026-09-08T00:00:00Z</updated><summary>Microsoft Windows Heap-Based Buffer Overflow Vulnerability</summary></entry><entry><title>CVE-2026-81963 — Microsoft Windows</title><link href="https://xploitwatch.com/cve/CVE-2026-81963"/><id>https://xploitwatch.com/cve/CVE-2026-81963</id><updated>2026-09-08T00:00:00Z</updated><summary>Microsoft Windows Link Following Vulnerability</summary></entry><entry><title>CVE-2026-75650 — Adobe Commerce and Magento</title><link href="https://xploitwatch.com/cve/CVE-2026-75650"/><id>https://xploitwatch.com/cve/CVE-2026-75650</id><updated>2026-09-08T00:00:00Z</updated><summary>Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability</summary></entry><entry><title>CVE-2026-85046 — Google Chromium V8</title><link href="https://xploitwatch.com/cve/CVE-2026-85046"/><id>https://xploitwatch.com/cve/CVE-2026-85046</id><updated>2026-09-04T00:00:00Z</updated><summary>Google Chromium V8 Type Confusion Vulnerability</summary></entry><entry><title>CVE-2026-9586 — Sangoma Switchvox</title><link href="https://xploitwatch.com/cve/CVE-2026-9586"/><id>https://xploitwatch.com/cve/CVE-2026-9586</id><updated>2026-09-02T00:00:00Z</updated><summary>Sangoma Switchvox SQL Injection Vulnerability</summary></entry><entry><title>CVE-2026-83549 — SonicWall SMA1000 Appliances</title><link href="https://xploitwatch.com/cve/CVE-2026-83549"/><id>https://xploitwatch.com/cve/CVE-2026-83549</id><updated>2026-09-02T00:00:00Z</updated><summary>SonicWall SMA1000 Appliances OS Command Injection Vulnerability</summary></entry><entry><title>CVE-2026-83548 — SonicWall SMA1000 Appliances</title><link href="https://xploitwatch.com/cve/CVE-2026-83548"/><id>https://xploitwatch.com/cve/CVE-2026-83548</id><updated>2026-09-02T00:00:00Z</updated><summary>SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability</summary></entry><entry><title>CVE-2026-82329 — JFrog Artifactory</title><link href="https://xploitwatch.com/cve/CVE-2026-82329"/><id>https://xploitwatch.com/cve/CVE-2026-82329</id><updated>2026-09-02T00:00:00Z</updated><summary>JFrog Artifactory Improper Authentication Vulnerability</summary></entry><entry><title>CVE-2026-59822 — BerriAI LiteLLM</title><link href="https://xploitwatch.com/cve/CVE-2026-59822"/><id>https://xploitwatch.com/cve/CVE-2026-59822</id><updated>2026-09-02T00:00:00Z</updated><summary>BerriAI LiteLLM Improper Authentication Vulnerability</summary></entry><entry><title>CVE-2026-49869 — Kestra Kestra OSS</title><link href="https://xploitwatch.com/cve/CVE-2026-49869"/><id>https://xploitwatch.com/cve/CVE-2026-49869</id><updated>2026-09-02T00:00:00Z</updated><summary>Kestra OSS OS Command Injection Vulnerability</summary></entry><entry><title>CVE-2026-48710 — Kludex Starlette</title><link href="https://xploitwatch.com/cve/CVE-2026-48710"/><id>https://xploitwatch.com/cve/CVE-2026-48710</id><updated>2026-09-02T00:00:00Z</updated><summary>Kludex Starlette HTTP Request/Response Smuggling Vulnerability</summary></entry><entry><title>CVE-2026-82078 — PaperCut NG/MF</title><link href="https://xploitwatch.com/cve/CVE-2026-82078"/><id>https://xploitwatch.com/cve/CVE-2026-82078</id><updated>2026-08-31T00:00:00Z</updated><summary>PaperCut NG/MF Unsafe Reflection Vulnerability</summary></entry><entry><title>CVE-2026-81578 — PaperCut NG/MF</title><link href="https://xploitwatch.com/cve/CVE-2026-81578"/><id>https://xploitwatch.com/cve/CVE-2026-81578</id><updated>2026-08-31T00:00:00Z</updated><summary>PaperCut NG/MF Missing Authentication for Critical Function Vulnerability</summary></entry><entry><title>CVE-2026-66384 — JFrog Artifactory</title><link href="https://xploitwatch.com/cve/CVE-2026-66384"/><id>https://xploitwatch.com/cve/CVE-2026-66384</id><updated>2026-08-27T00:00:00Z</updated><summary>JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability</summary></entry><entry><title>CVE-2026-53362 — Linux Kernel</title><link href="https://xploitwatch.com/cve/CVE-2026-53362"/><id>https://xploitwatch.com/cve/CVE-2026-53362</id><updated>2026-08-27T00:00:00Z</updated><summary>Linux Kernel Unspecified Vulnerability</summary></entry><entry><title>CVE-2023-49105 — ownCloud ownCloud</title><link href="https://xploitwatch.com/cve/CVE-2023-49105"/><id>https://xploitwatch.com/cve/CVE-2023-49105</id><updated>2026-08-27T00:00:00Z</updated><summary>ownCloud Improper Authentication Vulnerability</summary></entry><entry><title>CVE-2026-8452 — Citrix NetScaler ADC and NetScaler Gateway</title><link href="https://xploitwatch.com/cve/CVE-2026-8452"/><id>https://xploitwatch.com/cve/CVE-2026-8452</id><updated>2026-08-26T00:00:00Z</updated><summary>Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability</summary></entry><entry><title>CVE-2022-0995 — Linux Kernel</title><link href="https://xploitwatch.com/cve/CVE-2022-0995"/><id>https://xploitwatch.com/cve/CVE-2022-0995</id><updated>2026-08-26T00:00:00Z</updated><summary>Linux Kernel Out-of-Bounds Write Vulnerability</summary></entry></feed>
