BreachRisk Insights
Plain-spoken writing on attacker-grade testing, breach-risk scoring, and cyber insurance.
Pick a thread.
Recent writing.
Three ways to measure cyber risk — and why only one proves anything
Scanners, ratings services, and pen-test firms each see part of the picture. Here's why a proven, attacker's-eye view is the only one you can actually price a decision on.
CVE-2026-15410: SonicWall SMA1000 command injection, actively exploited
A post-authentication command-injection flaw in SonicWall's SMA1000 access appliances is being exploited in the wild, chained with a companion bug. Here's what you need to know — and how BreachRisk surfaces exposed appliances.
When CVSS (and EPSS / KEV) still belong in the room
Breach risk isn't a CVSS average — but CVE context still earns a seat once a path is real. Here's how to use CVSS, EPSS, and KEV without letting them run the whole program.
So HIPAA is on your plate — here's where to start
A healthcare customer or product decision just made HIPAA your problem. Clarify whether you're a covered entity or business associate, what PHI you actually touch, and how to spend the next 30 days without guessing regulatory details.
So you're being asked for ISO 27001 — here's where to start
An international customer asked for ISO 27001. Before you buy a binder or book a stage audit, clarify whether they want certification, a statement of applicability story, or 'aligned' — then follow this 30-day start plan.
CVE-2026-35273: Oracle PeopleSoft PeopleTools unauthenticated RCE, exploited as a zero-day
A missing-authentication flaw in PeopleSoft PeopleTools' Environment Management component lets an unauthenticated attacker take over the server — exploited as a zero-day by an extortion group against 100+ organizations. It's in CISA's KEV catalog. Here's the risk, and how BreachRisk finds and safely confirms exposed PeopleSoft.
CVE-2026-44277: Fortinet FortiAuthenticator improper access control, patched before exploitation
An improper-access-control flaw in Fortinet FortiAuthenticator could let an unauthenticated attacker reach protected API functionality. It was found internally and patched, with no known exploitation yet. Here's a level-headed read, and how BreachRisk finds exposed FortiAuthenticator.
CVE-2026-34909: Ubiquiti UniFi OS path traversal, actively exploited
A path-traversal flaw in UniFi OS devices lets an unauthenticated attacker reach internal handlers and read files that lead to account access. It's in CISA's KEV catalog with active exploitation. Here's what to do, and how BreachRisk finds exposed devices.
CVE-2026-22557: Ubiquiti UniFi Network Application path traversal
A path-traversal flaw in the UniFi Network Application lets an actor with network access read files off the system, which can be leveraged toward account access. A fix exists; here's the honest severity, and how BreachRisk finds exposed controllers.
CVE-2024-21182: Oracle WebLogic unauthenticated data exposure via T3/IIOP, exploited
A flaw in Oracle WebLogic's core lets an unauthenticated attacker reach critical data over the T3 and IIOP protocols — now in CISA's KEV catalog on evidence of active exploitation. Here's the risk, and how BreachRisk finds exposed WebLogic.
Talk to clients about breach risk without scaring them
A BreachRisk Score in a QBR should build trust, not theater. Here's how service providers can present outside-in findings — calm, ranked, and actionable — so clients lean in instead of tuning out.
CVE-2026-28318: SolarWinds Serv-U unauthenticated denial-of-service, KEV-listed
A crafted request can crash SolarWinds Serv-U without authentication, taking file transfer offline. It's in CISA's KEV catalog. The impact is availability, not data loss — here's the honest read, and how BreachRisk flags exposed servers.
CVE-2025-53020: Apache HTTP Server memory-leak denial of service
A memory-management flaw in Apache HTTP Server can be pushed toward denial of service — availability only, not code execution, and not known to be exploited. Here's the honest read, and how BreachRisk finds affected servers.
CVE-2026-45659: Microsoft SharePoint Server authenticated deserialization RCE, in CISA KEV
A deserialization flaw in on-premises SharePoint Server lets an authenticated attacker run code over the network. It's an 8.8 and it's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed SharePoint.
CVE-2026-26980: Ghost CMS unauthenticated SQL injection reads the database
A SQL injection flaw in Ghost CMS lets an unauthenticated attacker read arbitrary data straight from the database. A fix is out in 6.19.1. Here's the risk, and how BreachRisk finds exposed Ghost sites.
CVE-2026-26194: Gogs release-deletion argument injection
An argument-injection flaw in Gogs' release-deletion handling lets a low-privileged user smuggle Git options via a crafted tag name. A fix is out in 0.14.2. Here's the risk, and how BreachRisk finds exposed Gogs instances.
CVE-2026-22679: Weaver (Fanwei) E-cology unauthenticated RCE via exposed debug endpoint, exploited in the wild
A missing-authentication flaw in Weaver E-cology exposes a debug endpoint that lets an unauthenticated attacker run OS commands — a 9.8 with confirmed in-the-wild exploitation. Here's what to do, and how BreachRisk finds exposed servers.
CVE-2025-8110: Gogs symlink path traversal leads to code execution, in CISA KEV
Improper symbolic-link handling in Gogs' PutContents API lets an authenticated user traverse outside the repo and reach code execution. It's in CISA KEV. Here's what to do, and how BreachRisk finds exposed instances.
CVE-2024-39932: Gogs argument-injection flaws in change preview and release tagging
Two argument-injection flaws in Gogs let an authenticated user smuggle Git options into server-side commands — one during change previews, one during release tagging. Here's the risk, and how BreachRisk finds exposed Gogs instances.
CVE-2024-39930: Gogs built-in SSH server argument injection leads to RCE
An argument-injection flaw in the built-in SSH server of Gogs lets an authenticated user run commands on the host. A fix is available. Here's the risk, and how BreachRisk finds exposed Gogs instances.
CVE-2023-38646: Metabase pre-authentication remote code execution
A flaw in Metabase lets an unauthenticated attacker run arbitrary commands on the server at its privilege level. It was widely exploited after a public proof-of-concept. Here's what to do, and how BreachRisk finds exposed Metabase.
CVE-2024-42009: Roundcube Webmail cross-site scripting that can steal and send a victim's email
A cross-site scripting flaw in Roundcube's message rendering lets a crafted email read, exfiltrate, and send mail as the victim. It's in CISA's KEV catalog and scored 9.3. Here's the risk, and how BreachRisk finds exposed Roundcube instances.
CVE-2023-43770: Roundcube Webmail cross-site scripting, used for credential theft
A cross-site scripting flaw in how Roundcube renders links in plaintext email lets an attacker run script in a victim's session. It's in CISA's KEV catalog. Here's the risk, and how BreachRisk finds exposed Roundcube instances.
CVE-2021-44026: Roundcube Webmail SQL injection, exploited by state-linked actors
A SQL injection in Roundcube's search handling lets an authenticated user reach the mail database. It's in CISA's KEV catalog and tied to espionage against webmail servers. Here's the risk, and how BreachRisk finds exposed Roundcube instances.
CVE-2026-0257: Palo Alto PAN-OS GlobalProtect authentication bypass, actively exploited
An authentication-bypass flaw in the PAN-OS GlobalProtect portal and gateway lets an attacker establish an unauthorized VPN connection. It's in CISA KEV with limited in-the-wild exploitation. Here's what to do, and how BreachRisk finds exposed portals.
Portfolio heat vs one account: how carriers watch cyber risk
Underwriting a single company is only half the job. Carriers and MGAs also watch books — industries, technologies, accumulations, and correlated loss. Why 'the market' feels like weather, and what portfolio heat means for your renewal.
So you have to do PCI DSS — here's where to start
Card data or a payment flow just made PCI DSS your problem. Before you memorize requirements, clarify scope, who is assessing you, and what 'done' means for your business — then use this 30-day starter map.
CVE-2026-0300: Palo Alto PAN-OS User-ID Authentication Portal unauthenticated RCE, root-level
A buffer overflow in the PAN-OS User-ID Authentication Portal lets an unauthenticated attacker run code as root by sending crafted packets. It's in CISA KEV with in-the-wild exploitation. Here's what to do, and how BreachRisk finds exposed portals.
How to brief the board on breach risk without fear-mongering
Scare decks burn credibility. A calm BreachRisk briefing — score, trend, top verified paths, progress, one ask — builds it. Here's a pattern you can reuse every quarter.
CVE-2026-34197: Apache ActiveMQ code execution via the Jolokia API
A code-injection flaw in Apache ActiveMQ's Jolokia JMX-HTTP bridge lets an attacker load a remote Spring context and run code on the broker's JVM. It's in CISA KEV. Authentication is usually required — but default and missing credentials often remove that barrier. Here's what to do, and how BreachRisk finds exposed brokers.
CVE-2026-20133: Cisco Catalyst SD-WAN Manager information disclosure, exploited in the wild
An access-restriction flaw in Cisco Catalyst SD-WAN Manager lets an unauthenticated attacker read sensitive files via the API. It's in CISA's KEV catalog and has been exploited in the wild, chained with two related bugs. Here's what to do, and how BreachRisk finds exposed SD-WAN Manager.
CVE-2025-48700: Zimbra Collaboration Classic UI XSS, exploited in the wild
A cross-site scripting flaw in Zimbra's Classic Web Client runs attacker JavaScript when a victim simply views a crafted email — no clicking required. It's in CISA's KEV catalog. Here's the risk, and how BreachRisk finds exposed Zimbra.
CVE-2025-2749: Kentico Xperience path traversal and file upload leading to RCE
A flaw in Kentico Xperience's Staging Sync Server lets an attacker write files to path-relative locations and reach remote code execution. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed Kentico.
CVE-2024-7399: Samsung MagicINFO 9 Server path traversal, actively exploited
A path-traversal flaw in Samsung MagicINFO 9 Server lets an unauthenticated attacker write files with system authority — a direct route to remote code execution. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed servers.
CVE-2024-3721: TBK DVR OS command injection, swept up by botnets
A command-injection flaw in TBK DVR video recorders lets attackers run OS commands on the device. A public exploit exists and these internet-facing recorders are routine botnet fodder. Here's the risk, and how BreachRisk finds exposed units.
Exposed VMware ESXi logins and password spraying
A VMware ESXi login on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into control of your hypervisor — a favorite ransomware target. Here's the risk, and how BreachRisk safely tests whether those logins hold.
Exposed phpMyAdmin logins and password spraying
A phpMyAdmin login on the public internet is a standing target for password spraying, and one weak or reused credential can hand an attacker direct access to your database. Here's the risk, and how BreachRisk safely tests whether those logins hold.
Exposed Nextcloud logins and password spraying
A Nextcloud login on the public internet is a standing target for password spraying, and one weak or reused credential can hand an attacker the files and collaboration data it holds. Here's the risk, and how BreachRisk safely tests whether those logins hold.
Exposed MOVEit Transfer logins and password spraying
A MOVEit Transfer login on the public internet is a standing target for password spraying, and one weak or reused credential can hand an attacker a managed-file-transfer system known to hold sensitive data. Here's the risk, and how BreachRisk safely tests whether those logins hold.
Exposed Cisco router logins and password spraying
A Cisco router login on the public internet is a standing target for password spraying, and one weak or reused credential turns that exposure into control of a device that steers your traffic. Here's the risk — and how BreachRisk safely tests whether those logins hold.
CVE-2025-10035: Fortra GoAnywhere MFT deserialization to command injection, actively exploited
A deserialization flaw in GoAnywhere MFT's License Servlet lets an attacker with a forged license signature run commands on the server. It's a 10.0, it's in CISA KEV, and it was exploited as a zero-day by a ransomware group. Here's what to do, and how BreachRisk finds exposed GoAnywhere.
CVE-2024-57726 (with CVE-2024-57728): SimpleHelp privilege escalation to remote code execution
A missing-authorization flaw in SimpleHelp lets a low-privilege user escalate to admin, and a companion file-upload bug turns admin access into code execution. Both are in CISA KEV and tied to real intrusions. Here's what to do, and how BreachRisk finds exposed SimpleHelp servers.
CVE-2024-27198: JetBrains TeamCity authentication bypass, mass-exploited
A pair of flaws in on-premises JetBrains TeamCity let an unauthenticated attacker bypass authentication and take administrative control of the build server. Both are in CISA's KEV catalog and were exploited at scale. Here's what to do, and how BreachRisk finds exposed TeamCity.
Why underwriters obsess over a short list of controls
MFA, EDR, backups that restore, privileged access, email security — not a random security sermon. How those asks map to claim patterns, show up as warranties and subjectivities, and what 'checkbox compliance' still misses.
CVE-2026-35616: Fortinet FortiClient EMS improper access control, exploited as a zero-day
An access-control flaw in Fortinet FortiClient EMS lets an unauthenticated attacker bypass API authorization and run commands on the management server. It was exploited as a zero-day and is in CISA KEV with a three-day deadline. Here's what to do, and how BreachRisk finds exposed EMS.
CVE-2026-2699: ShareFile Storage Zones Controller improper access control
An access-control flaw in customer-managed ShareFile Storage Zones Controller lets an unauthenticated attacker reach restricted configuration pages — a path to changing system settings and potentially remote code execution. A proof-of-concept is public. Here's what to do, and how BreachRisk finds exposed SZC instances.
CVE-2025-32975: Quest KACE SMA authentication bypass, now in CISA KEV
An authentication-bypass flaw in Quest KACE Systems Management Appliance lets an attacker impersonate legitimate users through the SSO handler — up to full administrative takeover. It's a 10.0 and now KEV-listed. Here's what to do, and how BreachRisk finds exposed KACE appliances.
CVE-2026-3564: ConnectWise ScreenConnect privilege escalation via server cryptographic material
A ScreenConnect flaw could let an attacker who already holds the server's authentication cryptographic material gain elevated access. It carries a high vendor CVSS but has no known exploitation and is not in KEV. Here's a measured read, and how BreachRisk finds exposed ScreenConnect servers.
CVE-2026-27685: SAP NetWeaver Enterprise Portal deserialization of untrusted data
A deserialization flaw in SAP NetWeaver Enterprise Portal Administration lets a privileged user upload content that, when deserialized, can fully compromise the host. It's serious on impact but requires privileged access and isn't known-exploited yet. Here's what to do, and how BreachRisk finds exposed NetWeaver portals.
CVE-2026-20963: Microsoft SharePoint unauthenticated deserialization RCE, actively exploited
A deserialization flaw in on-premises SharePoint lets an unauthenticated attacker run code over the network — a 9.8, in CISA's KEV catalog with a same-week deadline. Here's what to do, and how BreachRisk finds exposed SharePoint.
CVE-2025-3935: ConnectWise ScreenConnect ViewState code injection, exploited in targeted intrusions
A ViewState deserialization flaw in ScreenConnect can lead to code execution — but only for an attacker who already holds the server's machine keys. It's in CISA's KEV catalog. Here's the real risk, and how BreachRisk finds exposed ScreenConnect servers.
CVE-2026-3055: Citrix NetScaler SAML IdP memory over-read, actively exploited
Another NetScaler memory over-read — this one reachable when the appliance is configured as a SAML Identity Provider, a common single-sign-on setup. It's unauthenticated, in CISA's KEV catalog, and being exploited. Here's what to do, and how BreachRisk finds exposed appliances.
CVE-2026-21992: Oracle Identity Manager unauthenticated RCE (out-of-band fix)
A missing-authentication flaw in Oracle Identity Manager and Web Services Manager lets an unauthenticated attacker take over the server — serious enough that Oracle shipped a rare out-of-band Security Alert. Here's the risk, and how BreachRisk finds exposed instances.
CVE-2017-7921: Hikvision camera authentication bypass, actively exploited
An authentication bypass in a range of Hikvision IP cameras lets an unauthenticated attacker escalate privileges and pull sensitive data, including credentials. It's in CISA KEV. Here's what to do, and how BreachRisk finds exposed cameras.
CVE-2026-22720: VMware Aria Operations stored cross-site scripting, patch available
A stored cross-site scripting flaw in VMware Aria Operations lets a privileged user inject script that runs administrative actions in another user's session. It needs an authenticated foothold, a fix is out, and it isn't being exploited. Here's the honest read, and how BreachRisk finds exposed Aria panels.
CVE-2025-40536: SolarWinds Help Desk Security Control Bypass Vulnerability Exploitation (CVE-2025-40536)
SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated attacker to gain access to certain restricted functionality.
CVE-2025-40538: SolarWinds Serv-U privilege escalation requiring admin access
A broken-access-control flaw in SolarWinds Serv-U lets an existing admin create a system administrator and run code — but it needs admin privileges to begin with. Here's the honest read, and how BreachRisk flags exposed instances.
CVE-2025-40536: SolarWinds Web Help Desk security-control bypass, actively exploited
A security-control bypass in SolarWinds Web Help Desk lets an unauthenticated attacker reach restricted functionality. It's in CISA's KEV catalog with a very short remediation window. Here's what to do, and how BreachRisk finds exposed Web Help Desk instances.
CVE-2025-68645: Zimbra Collaboration file inclusion, actively exploited
A file-inclusion flaw in Zimbra Collaboration's Webmail Classic UI lets a remote attacker influence internal request dispatching and include arbitrary files from the web root. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed servers.
CVE-2024-37079: VMware vCenter Server heap-overflow RCE, in CISA KEV
Another heap-overflow in vCenter Server's DCERPC implementation lets a network attacker run code on your virtualization control plane. It's a 9.8 and it's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed vCenter.
CVE-2025-68461: Roundcube Webmail cross-site scripting via SVG animate tag, in KEV
A cross-site scripting flaw via the SVG animate tag lets a crafted email run script in a Roundcube user's session. It's in CISA's KEV catalog. Here's the risk, and how BreachRisk finds exposed Roundcube instances.
CVE-2025-49113: Roundcube Webmail post-authentication remote code execution, actively exploited
A PHP object-deserialization flaw lets an authenticated Roundcube user run code on the mail server. It's in CISA's KEV catalog and exploitation went wide within days of disclosure. Here's what to do, and how BreachRisk finds exposed Roundcube instances.
CVE-2025-40551: SolarWinds Web Help Desk unauthenticated deserialization RCE
An untrusted-data deserialization flaw in SolarWinds Web Help Desk allows unauthenticated remote code execution. It's in CISA's KEV catalog with a very short remediation window. Here's what to do, and how BreachRisk finds exposed Web Help Desk instances.
CVE-2025-26399: SolarWinds Web Help Desk unauthenticated deserialization RCE (patch-bypass)
An unauthenticated AjaxProxy deserialization flaw in SolarWinds Web Help Desk allows remote code execution — and it's the third turn of a patch-bypass chain. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed Web Help Desk instances.
CVE-2023-5631: Roundcube Webmail stored cross-site scripting, exploited as a zero-day by an APT
A stored cross-site scripting flaw via a crafted SVG in HTML email let attackers run script in a Roundcube session. It was exploited as a zero-day for espionage and is in CISA's KEV catalog. Here's the risk, and how BreachRisk finds exposed Roundcube instances.
Exposed UniFi Network logins and password spraying
A UniFi Network controller login on the public internet is a standing target for password spraying, and one weak or reused credential turns that exposure into control of your network infrastructure. Here's the risk — and how BreachRisk safely tests whether those logins hold.
Exposed SonarQube logins and password spraying
A SonarQube login on the public internet is a standing target for password spraying, and one weak or reused credential turns that exposure into access to source code and CI secrets. Here's the risk — and how BreachRisk safely tests whether those logins hold.
Exposed SolarWinds Help Desk logins and password spraying
A SolarWinds Help Desk login on the public internet is a standing target for password spraying, and one weak or reused credential turns that exposure into access to tickets and administrative controls. Here's the risk — and how BreachRisk safely tests whether those logins hold.
Exposed SAP Fiori logins and password spraying
An SAP Fiori launchpad login on the public internet is a standing target for password spraying, and one weak or reused credential turns that exposure into access to business-critical ERP data. Here's the risk — and how BreachRisk safely tests whether those logins hold.
Exposed Proofpoint email security logins and password spraying
A Proofpoint email security login on the public internet is a standing target for password spraying, and one weak or reused credential turns that exposure into access to email flow and controls. Here's the risk — and how BreachRisk safely tests whether those logins hold.
Exposed JFrog logins and password spraying
A JFrog login on the public internet is a standing target for password spraying, and one weak or reused credential can hand an attacker your artifacts, packages, and build outputs. Here's the risk, and how BreachRisk safely tests whether those logins hold.
Exposed Cisco ISE logins and password spraying
A Cisco Identity Services Engine login on the public internet is a standing target for password spraying, and one weak or reused credential can hand over the system that decides who gets on your network. Here's the risk — and how BreachRisk safely tests whether those logins hold.
Exposed 3CX Webclient logins and password spraying
A 3CX Webclient login on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into access to your phone system and its data. Here's the risk, and how BreachRisk safely tests whether that login holds.
Likelihood × impact — the risk language boards already understand
Boards don't need a CVE tutorial. They need breach risk in the same shape as every other enterprise risk: how likely, how bad, what we're doing. Here's how to use that frame without drowning them in formula.
CVE-2026-1603: Ivanti Endpoint Manager authentication bypass, unauthenticated credential-data leak
An authentication bypass in Ivanti Endpoint Manager lets a remote, unauthenticated attacker leak specific stored credential data. It's in CISA's KEV catalog. Here's the honest read, and how BreachRisk finds exposed servers.
Application → bind → renew: the cyber insurance lifecycle
What actually happens between 'we need cyber' and 'you're on risk' — then what renewals reopen. A practical lifecycle map for CISOs and finance leaders on their first or fifth policy.
Exposed Jenkins logins and password spraying
A Jenkins login on the public internet is a standing target for password spraying, and one weak or reused credential turns your build server — and the secrets and source it holds — into an attacker's foothold. Here's the risk, and how BreachRisk safely tests whether those logins hold.
CVE-2026-1281: Ivanti Endpoint Manager Mobile code injection, unauthenticated RCE
A code-injection flaw in Ivanti Endpoint Manager Mobile lets a remote, unauthenticated attacker run code on the server that manages your mobile fleet. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed servers.
Exposed Progress WhatsUp Gold logins and password spraying
Progress WhatsUp Gold is a network monitoring platform, so an exposed login is a high-value target with broad visibility into — and stored credentials for — your infrastructure. Here's the risk, and how BreachRisk safely tests whether that login holds.
Exposed Kaseya VSA logins and password spraying
Kaseya VSA is a remote monitoring and management platform, so an exposed login is a high-value target with reach across every managed endpoint. Here's the risk, and how BreachRisk safely tests whether that login holds.
Exposed Webmin logins and password spraying
Webmin is a browser-based server administration panel, and an exposed one is a high-value login to spray. Weak or reused credentials turn that exposure into hands-on server control. Here's the risk, and how BreachRisk safely tests whether the login holds.
Exposed VMware Cloud Orchestrator logins and password spraying
A VMware Cloud Orchestrator login on the public internet is a standing target for password spraying, and one weak or reused credential turns that exposure into access to automation that reaches across your virtual infrastructure. Here's the risk — and how BreachRisk safely tests whether those logins hold.
Exposed Verint Experience Management logins and password spraying
A Verint Experience Management login on the public internet is a standing target for password spraying, and one weak or reused credential turns that exposure into access to customer-experience data. Here's the risk — and how BreachRisk safely tests whether those logins hold.
Exposed TP-Link router logins and password spraying
A TP-Link router admin login on the public internet is a standing target for password spraying, and one weak or default credential turns that exposure into control of your network edge. Here's the risk — and how BreachRisk safely tests whether those logins hold.
Exposed Tableau logins and password spraying
A Tableau login on the public internet is a standing target for password spraying, and one weak or reused credential turns that exposure into access to dashboards and the data behind them. Here's the risk — and how BreachRisk safely tests whether those logins hold.
SonicWall Network Security Appliance Password Spraying
Attempt authentication to SonicWall Network Security Appliance using exposed or weak credentials.
Exposed SonicWall Network Security Appliance logins and password spraying
A SonicWall Network Security Appliance management login on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into control of the firewall itself. Here's the risk, and how BreachRisk safely tests whether those logins hold.
Exposed Signals Gateway logins and password spraying
A Signals Gateway login on the public internet is a standing target for password spraying, and one weak or reused credential turns that exposure into access. Here's the risk — and how BreachRisk safely tests whether those logins hold.
Exposed ServiceNow logins and password spraying
A ServiceNow login on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into access to tickets, records, and workflows. Here's the risk — and how BreachRisk safely tests whether those logins hold.
Exposed Salesforce logins and password spraying
A Salesforce login on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into access to customer and business data. Here's the risk — and how BreachRisk safely tests whether those logins hold.
Exposed Plesk Obsidian logins and password spraying
A Plesk Obsidian hosting control panel on the public internet is a standing target for password spraying, and one weak or reused credential turns that exposure into access. Here's the risk, and how BreachRisk safely tests whether those logins hold.
Exposed Parallels HTML5 Client logins and password spraying
A Parallels HTML5 Client login on the public internet is a standing target for password spraying, and one weak or reused credential can hand an attacker a remote-access gateway into your desktops and apps. Here's the risk, and how BreachRisk safely tests whether those logins hold.
Exposed PaperCut logins and password spraying
A PaperCut print-management login on the public internet is a standing target for password spraying, and one weak or reused credential turns that exposure into access. Here's the risk, and how BreachRisk safely tests whether those logins hold.
Exposed Oracle Application Server logins and password spraying
An Oracle Application Server login on the public internet is a standing target for password spraying, and one weak or reused credential turns that exposure into access. Here's the risk, and how BreachRisk safely tests whether those logins hold.
Exposed MiScout SCADA logins and password spraying
A MiScout SCADA login on the public internet is a standing target for password spraying, and one weak or reused credential can hand an attacker an industrial control system. Here's the risk, and how BreachRisk safely tests whether those logins hold.
Exposed mFusion logins and password spraying
An mFusion management login on the public internet is a standing target for password spraying, and one weak or reused credential turns that exposure into access. Here's the risk, and how BreachRisk safely tests whether those logins hold.
Exposed Lenel S2 logins and password spraying
A Lenel S2 access-control login on the public internet is a standing target for password spraying, and one weak or reused credential can hand an attacker your physical-security management system. Here's the risk, and how BreachRisk safely tests whether those logins hold.
Exposed KeyHelp logins and password spraying
A KeyHelp hosting control panel on the public internet is a standing target for password spraying, and one weak or reused credential turns that exposure into access. Here's the risk, and how BreachRisk safely tests whether those logins hold.
Exposed InterWorx (NodeWorx/SiteWorx) logins and password spraying
An InterWorx web hosting control panel on the public internet is a standing target for password spraying, and one weak or reused credential turns that exposure into access. Here's the risk — and how BreachRisk safely tests whether those logins hold.
Exposed HCL Volt MX logins and password spraying
An HCL Volt MX login on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into access to your app platform and its data. Here's the risk — and how BreachRisk safely tests whether those logins hold.
Exposed GitLab logins and password spraying
A GitLab login on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into access to source code, secrets, and CI/CD pipelines. Here's the risk — and how BreachRisk safely tests whether those logins hold.
Exposed Follett Aspen SIS logins and password spraying
A Follett Aspen student information system login on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into access to sensitive student records. Here's the risk, and how BreachRisk safely tests whether that login holds.
Exposed F5 BIG-IP logins and password spraying
An F5 BIG-IP login on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into access. Here's the risk — and how BreachRisk safely tests whether those logins hold.
Exposed eHealth server logins and password spraying
An eHealth server login on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into access. Here's the risk — and how BreachRisk safely tests whether those logins hold.
CVE-2025-58360: GeoServer XXE file-disclosure flaw, in CISA KEV
An XML External Entity flaw in GeoServer's WMS GetMap endpoint lets an unauthenticated attacker coax the server into reading local files and reaching internal systems. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed instances.
CVE-2025-30406: Gladinet CentreStack hard-coded machineKey RCE, exploited as a zero-day
A hard-coded machineKey in Gladinet CentreStack lets an unauthenticated attacker forge a serialized payload and run code on the server. It was exploited as a zero-day and it's in CISA KEV. Here's what to do, and how BreachRisk finds exposed instances.
CVE-2025-14611: Gladinet CentreStack & Triofox hard-coded crypto, actively exploited
Gladinet CentreStack and Triofox shipped hard-coded values in their AES implementation, giving unauthenticated attackers a path to arbitrary local file inclusion. It's being exploited and it's in CISA KEV. Here's what to do, and how BreachRisk finds exposed instances.
CVE-2025-12480: Gladinet Triofox access-control bypass, actively exploited
An improper access-control flaw in Gladinet Triofox lets an unauthenticated attacker reach setup pages that should be locked after install — a path attackers have used in the wild to take over servers. It's in CISA KEV. Here's what to do, and how BreachRisk finds exposed instances.
CVE-2025-0994: Trimble Cityworks deserialization RCE, actively exploited
A deserialization flaw in Trimble Cityworks lets an authenticated user run code on the underlying IIS web server. It's been exploited in the wild against local-government systems and is in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed instances.
Exposed Cerberus FTP web client logins and password spraying
A Cerberus FTP web-client login on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into access to transferred files. Here's the risk — and how BreachRisk safely tests whether those logins hold.
Exposed CareStar CMS logins and password spraying
A CareStar CMS login on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into access to sensitive case-management data. Here's the risk — and how BreachRisk safely tests whether those logins hold.
Exposed Bomgar remote-support logins and password spraying
A Bomgar remote-support login on the public internet is a high-value target for password spraying, and one weak credential can hand an attacker privileged remote access. Here's the risk — and how BreachRisk safely tests whether those logins hold.
Exposed BeyondTrust Remote Support logins and password spraying
A BeyondTrust Remote Support login on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into access to a powerful remote-support platform. Here's the risk, and how BreachRisk safely tests whether that login holds.
Exposed AutomatedLogic WebCTRL logins and password spraying
An AutomatedLogic WebCTRL login on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into control of building automation systems. Here's the risk, and how BreachRisk safely tests whether that login holds.
Exposed atMail webmail logins and password spraying
An atMail webmail login on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into access to a user's email. Here's the risk, and how BreachRisk safely tests whether that login holds.
Exposed Apache Guacamole logins and password spraying
An Apache Guacamole login on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into a remote-desktop gateway onto your internal systems. Here's the risk, and how BreachRisk safely tests whether that login holds.
Exposed Adobe Experience Manager logins and password spraying
An Adobe Experience Manager login on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into control of the platform that runs your website. Here's the risk, and how BreachRisk safely tests whether that login holds.
Attestation vs evidence: why "yes we patch" isn't underwriting data
Applicants answer questionnaires hopefully. Attackers don't read the PDF. Here's how to map cyber-insurance questions to outside-in evidence — and why verified exposure beats another checkbox.
What is loss ratio? (and why cyber insurance people won't stop saying it)
Loss ratio is incurred losses divided by earned premium — the basic scoreboard for whether an insurance book is paying out more than it takes in. Here's the plain definition, its cousins, and how to hear it in a cyber conversation without mythology.
Identified vs verified vs safe — why the middle word matters
Scanners identify maybes. Ratings estimate from signals. Proof starts when a finding is verified the way an attacker would care about it. 'Safe' is a state you earn — not a slide.
Tenants, not tickets: running many customers in one console
You can't hire three pen testers for every book of business. Multi-tenant delivery lets service providers run continuous assessments across clients — separate data, shared ops — without building an exploit shop.
Kill the questionnaire — what underwriters actually need instead
The cyber insurance questionnaire was always a proxy for one question: can an attacker get in? Here's what replaces the form when you can prove outside-in exposure instead of asking applicants to attest to it.
Pack continuous assessment into an MSP offer
Monitoring and tickets keep the lights on. A continuous, attacker-grade risk assessment — delivered under your brand — is a reason clients stay, expand, and come to you before they go shopping for a pen-test firm.
Why verified findings are the only questionnaire replacement that sticks
If what replaces the cyber questionnaire cries wolf — immaterial perimeter noise, unverified estimates — underwriters go back to the form. Verification is how Kill the Questionnaire earns trust.
CVE-2025-64446: Fortinet FortiWeb path traversal authentication bypass, actively exploited
A relative path-traversal flaw in Fortinet FortiWeb lets an attacker bypass authentication and run administrative commands — including creating rogue admin accounts. It's in CISA KEV and actively exploited. Here's what to do, and how BreachRisk finds exposed FortiWeb.
The white-label report is the product
Clients don't buy your console — they buy the artifact they can send to a board, broker, or auditor. For service providers, the white-label report (and share link) under your brand is the offer.
Cyber insurance from the carrier's perspective
Premium is the input. Claims are the cost. Capacity, appetite, accumulations, and wording are the constraints. Why a strong security story still gets declined — and what carriers are actually optimizing for.
From application to bind: less friction, better signal
Kill the Questionnaire as a process — what gets flagged before bind, what applicants stop typing, and how brokers and carriers move faster without swallowing unverified ratings noise.
CVE-2025-61884: Oracle E-Business Suite unauthenticated SSRF, in CISA KEV
An unauthenticated server-side request forgery flaw in Oracle E-Business Suite lets a remote attacker reach sensitive resources over HTTP with no login. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed EBS.
What a broker should ask for beyond the form
A practical checklist for brokers: continuous external proof, verified findings, and a trendable breach-risk view — questions that separate claim-relevant signal from ratings noise and questionnaire hope.
CVE-2025-2775: SysAid On-Prem unauthenticated XXE, chains to admin takeover
An unauthenticated XML External Entity flaw in on-premises SysAid gives attackers file-read and, chained further, administrator takeover. It's in CISA's KEV catalog; here's what to do, and how BreachRisk finds exposed servers.
CVE-2023-47246: SysAid On-Prem path traversal to code execution, exploited in the wild
A path-traversal flaw in on-premises SysAid let attackers write a file into the web server and run code — exploited as a zero-day by a ransomware-linked group. A fix exists; here's what to do, and how BreachRisk finds exposed servers.
CVE-2022-21587: Oracle E-Business Suite unauthenticated file-upload RCE, exploited
A missing-authentication flaw in Oracle E-Business Suite's upload component lets an unauthenticated attacker write files and reach remote code execution. It's in CISA's KEV catalog and exploited in the wild. Here's the risk, and how BreachRisk finds exposed EBS.
So you have to align to NIST 800-53 — here's where to start
A government-adjacent customer or RFP just said NIST SP 800-53. Before you drown in control IDs, decode whether this is a contractual baseline, a gap assessment ask, or 'be FedRAMP-ish' — then use this 30-day orientation.
CVE-2025-61882: Oracle E-Business Suite unauthenticated RCE, exploited as a zero-day
An unauthenticated flaw in Oracle E-Business Suite lets an attacker run code and take over the server — exploited as a zero-day in a mass extortion campaign. It's in CISA's KEV catalog, and Oracle shipped an emergency Security Alert. Here's the risk, and how BreachRisk finds exposed EBS.
CVE-2024-6670: Progress WhatsUp Gold SQL injection, unauthenticated credential theft
A SQL-injection flaw in Progress WhatsUp Gold lets an unauthenticated attacker retrieve a stored, encrypted user password. It's in CISA's KEV catalog and ransomware-associated. Here's what to do, and how BreachRisk finds exposed instances.
CVE-2024-4885: Progress WhatsUp Gold path traversal to unauthenticated RCE
A path-traversal flaw in Progress WhatsUp Gold lets an unauthenticated attacker run commands on the monitoring server. It's in CISA's KEV catalog with a public exploit. Here's what to do, and how BreachRisk finds exposed instances.
CVE-2023-43208: NextGen Mirth Connect unauthenticated remote code execution
A flaw in NextGen Healthcare Mirth Connect lets an unauthenticated attacker run commands on the server — on a system that sits at the heart of healthcare data exchange. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed Mirth Connect.
What a BreachRisk Score is (and isn't)
One number leaders can trend — built from assessed surface and verified exposure. Here's what the BreachRisk Score measures, what it deliberately isn't, and how to talk about it without overselling.
Who's who in cyber insurance: carrier, MGA, broker, reinsurer
Why three people ask for the same questionnaire — and still aren't the same job. A plain map of carriers, MGAs, brokers, and reinsurers for security leaders buying cyber for the first time (and a sanity check for insurance readers).
Ratings estimate risk. Attackers exploit paths.
Outside-in letter grades are easy to consume — and easy to pad with findings that aren't material to a breach or a claim. Underwriting needs verified break-in paths, not another estimate built from soft perimeter signals.
Turn assessments into recurring revenue — without becoming a pen-test firm
Annual point-in-time testing is a project. Continuous assessment is a retainer. How service providers position renewal, quarterly reviews, and expansion — while the platform does the attacker-grade work.
CVE-2025-55182: React Server Components unauthenticated RCE via unsafe deserialization
A deserialization flaw in React Server Components lets an unauthenticated attacker send a crafted payload to a Server Function endpoint and execute code. It's a 10.0, it's in CISA KEV, and it reaches a very large install base. Here's what to do, and how BreachRisk finds exposed apps.
CVE-2024-48248: NAKIVO Backup & Replication arbitrary file read, actively exploited
A file-read flaw in NAKIVO Backup & Replication lets an unauthenticated attacker read any file on the appliance — including stored, cleartext credentials that can extend an attack across the enterprise. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed NAKIVO.
CVE-2024-26331: ReCrystallize Server authentication bypass via a spoofable cookie
ReCrystallize Server trusts a cookie value that isn't bound to a real session, so an attacker can set it and walk into the admin interface. Here's the honest risk — and how BreachRisk finds exposed ReCrystallize servers.
CVE-2024-2389: Progress Flowmon unauthenticated command injection, root-level RCE
A command-injection flaw in Progress Flowmon lets an unauthenticated attacker run system commands through the management interface — a 10.0 with a public exploit. Here's what to do, and how BreachRisk finds exposed appliances.
CVE-2023-52251: Provectus Kafka UI code injection leading to remote code execution
A code-injection flaw in the open-source Provectus Kafka UI lets an attacker run arbitrary code on the server through the message-filter parameter. Here's the honest severity, and how BreachRisk finds exposed Kafka UI instances.
CVE-2022-36537: ZK Framework information disclosure, exploited for RCE downstream
A crafted POST to the ZK Framework's AuUploader leaks restricted internal files — and it was chained into remote code execution in products that embed ZK, like ConnectWise R1Soft. It's in CISA's KEV catalog. Here's the risk, and how BreachRisk finds and safely confirms it.
CVE-2024-6782: Calibre content server improper access control leading to unauthenticated RCE
An access-control flaw in Calibre's content server lets an unauthenticated attacker reach privileged functionality and achieve remote code execution — a 9.8 with a public exploit. Here's what to do, and how BreachRisk finds exposed servers.
CVE-2021-20124: DrayTek VigorConnect path traversal in WebServlet, unauthenticated root file read, in CISA KEV
A second path-traversal flaw in DrayTek VigorConnect — this one in the WebServlet endpoint — lets an unauthenticated attacker read arbitrary files as root. A 7.5 in CISA's KEV catalog. Here's what it exposes, and how BreachRisk finds affected systems.
CVE-2021-20123: DrayTek VigorConnect path traversal, unauthenticated root file read, in CISA KEV
A path-traversal flaw in DrayTek VigorConnect's DownloadFileServlet lets an unauthenticated attacker read arbitrary files as root — a 7.5 that's in CISA's KEV catalog. Here's what it exposes, and how BreachRisk finds affected systems.
CVE-2021-39226: Grafana snapshot authentication bypass, actively exploited
A flaw in Grafana lets unauthenticated users view dashboard snapshots by walking predictable paths — exposing whatever those snapshots contain. It's in CISA KEV with near-certain exploitation activity. Here's what to do, and how BreachRisk finds exposed instances.
CVE-2021-36260: Hikvision unauthenticated command injection, actively exploited
A command-injection flaw in the web server of many Hikvision products lets an unauthenticated attacker run commands on the device. It's in CISA KEV with widespread exploitation. Here's what to do, and how BreachRisk finds exposed cameras.
CVE-2021-35464: ForgeRock AM (OpenAM) unauthenticated Java deserialization RCE, ransomware-exploited
A Java deserialization flaw in ForgeRock AM lets an unauthenticated attacker run code with a single crafted request — a 9.8, exploited by ransomware operators, and in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed identity gateways.
CVE-2021-44515: Zoho ManageEngine Desktop Central auth bypass to RCE, actively exploited
An authentication bypass in ManageEngine Desktop Central lets an attacker skip login and execute code on the endpoint-management server — exploited in the wild and in CISA KEV. Here's what to do, and how BreachRisk finds and safely confirms exposed Desktop Central.
CVE-2021-44077: Zoho ManageEngine ServiceDesk Plus unauthenticated RCE, actively exploited
A missing-authentication flaw in ManageEngine ServiceDesk Plus lets an attacker upload files and drop a web shell for unauthenticated remote code execution — exploited by APT actors and in CISA KEV. Here's what to do, and how BreachRisk finds and safely confirms exposed ServiceDesk Plus.
So you have to get SOC 2 — here's where to start
Sales just told you enterprise buyers need SOC 2. Before you hire anyone or buy a binder of policies, clarify what was actually asked for — and use this as your first-30-days map.
Exposed Active! mail logins and password spraying
An Active! mail webmail login on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into access to a user's email. Here's the risk, and how BreachRisk safely tests whether that login holds.
Critical CVE ≠ your breach risk
A CVSS 9.8 on something attackers can't reach is a different problem than a moderate finding on a live internet path. Severity labels aren't organizational breach risk — stop letting them set the whole queue.
Exposed Sophos VPN and firewall logins and password spraying
A Sophos VPN or firewall login on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into VPN access to your network. Here's the risk, and how BreachRisk safely tests whether those logins hold.
CVE-2023-2533: PaperCut NG/MF cross-site request forgery, now actively exploited
A cross-site request forgery flaw in PaperCut NG/MF can let an attacker ride a logged-in admin's session to change security settings — or reach code execution. It sat quietly until CISA added it to KEV. Here's what to do, and how BreachRisk finds exposed PaperCut consoles.
CVE-2025-4632: Samsung MagicINFO 9 Server path traversal, patch-bypass exploited in the wild
A path-traversal flaw in Samsung MagicINFO 9 Server lets an unauthenticated attacker write files with system authority — and it bypasses the earlier fix for CVE-2024-7399. It's in CISA's KEV catalog and exploited by botnets. Here's what to do, and how BreachRisk finds exposed servers.
When to sell Business vs Application (and when Portfolio)
A simple partner playbook: lead with continuous external risk (Business), add web-app/API depth (Application) when the surface calls for it, and use Portfolio when the client is really many entities.
Exposed Roundcube webmail logins and password spraying
A Roundcube webmail login on the public internet is a standing target for password spraying, and one weak or reused credential turns that exposure into access to a live mailbox. Here's the risk — and how BreachRisk safely tests whether those logins hold.
Exposed Redmine logins and password spraying
A Redmine project portal on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into access to your projects, issues, and files. Here's the risk — and how BreachRisk safely tests whether those logins hold.
Exposed EasyPanel logins and password spraying
An EasyPanel login on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into control of your deployed applications and servers. Here's the risk — and how BreachRisk safely tests whether those logins hold.
Exposed cPanel logins and password spraying
A cPanel login on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into control of a hosting account. Here's the risk — and how BreachRisk safely tests whether those logins hold.
CVE-2025-5777 (Citrix Bleed 2): NetScaler memory over-read that leaks session material
"Citrix Bleed 2" leaks memory from NetScaler ADC/Gateway to an unauthenticated attacker — echoing the original CitrixBleed, where leaked session material meant hijacked sessions. NVD calls it a 7.5; the real world treats it as far worse. Here's why, and how BreachRisk finds exposed appliances.
CVE-2023-38950: ZKTeco BioTime path traversal, unauthenticated file read, in CISA KEV
A path-traversal flaw in ZKTeco BioTime lets an unauthenticated attacker read arbitrary files off the server — a 7.5 that's in CISA's KEV catalog. Here's what it exposes, and how BreachRisk finds affected systems.
CVE-2025-6543: Citrix NetScaler memory overflow, unauthenticated and exploited in the wild
A memory-overflow flaw in NetScaler ADC and Gateway causes unintended control flow and denial of service when the device is a Gateway or AAA server — exploited as a zero-day and in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed NetScalers.
CVE-2025-47812: Wing FTP Server null-byte flaw to root/SYSTEM RCE, exploited in the wild
A null-byte handling flaw in Wing FTP Server lets an attacker inject code and execute commands as root or SYSTEM — even via an anonymous account. It's exploited in the wild and in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed servers.
CVE-2025-42999: SAP NetWeaver Visual Composer deserialization, exploited in the wild
An insecure-deserialization flaw in SAP NetWeaver Visual Composer was chained with a companion upload bug and used in real attacks on internet-facing SAP systems. It's in CISA KEV. Here's what to do, and how BreachRisk finds exposed NetWeaver instances.
CVE-2024-57727: SimpleHelp unauthenticated path traversal, actively exploited
A path-traversal flaw in SimpleHelp lets an unauthenticated attacker download server files — including the configuration file with secrets and hashed passwords. It's the entry point of a takeover chain, it's mass-exploited, and it's in CISA KEV. Here's what to do, and how BreachRisk finds exposed SimpleHelp servers.
Understanding the terms in your cyber insurance quote
Limit, retention, sublimits, aggregates, waiting periods, named insured — the quote PDF is a coverage design, not just a price. Here's how to read it before you compare premiums.
CVE-2022-29464: WSO2 unrestricted file upload to unauthenticated RCE
An unrestricted file-upload flaw across several WSO2 products lets an unauthenticated attacker drop a web shell and run code. It's in CISA's KEV catalog, ransomware-associated, and mass-exploited. Here's what to do, and how BreachRisk finds exposed instances.
CVE-2022-29303: SolarView Compact unauthenticated command injection, actively exploited
A command-injection flaw in Contec SolarView Compact solar-monitoring devices lets an unauthenticated attacker run OS commands via conf_mail.php. It's a 9.8, botnets have used it, and it's in CISA KEV. Here's what to do, and how BreachRisk finds exposed SolarView devices.
CVE-2022-27926: Zimbra Collaboration reflected XSS, exploited by nation-state actors
A reflected cross-site scripting flaw in Zimbra Collaboration's webmail lets an attacker run script in a victim's session with one crafted link — and it was used against government targets. Here's the risk, and how BreachRisk finds and safely confirms exposed Zimbra.
CVE-2022-24990: TerraMaster NAS admin-password disclosure, a step to full compromise
A flaw in TerraMaster NAS leaks the administrative password to an unauthenticated request — and chained with a second bug, it becomes remote code execution. It's ransomware-associated and in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed devices.
CVE-2022-23134: Zabbix Frontend setup.php improper access control
A weak access check in the Zabbix Frontend setup process lets an unauthenticated user reach configuration steps meant for administrators. It's in CISA's KEV catalog. Here's the honest severity, and how BreachRisk finds exposed instances.
CVE-2022-22954: VMware Workspace ONE Access unauthenticated remote code execution
A server-side template injection in VMware Workspace ONE Access and Identity Manager lets an unauthenticated attacker run code on the server. A 9.8, in CISA KEV, exploited in the wild. Here's what to do, and how BreachRisk finds exposed instances.
CVE-2023-41266: Qlik Sense path traversal that mints an anonymous session
A path-traversal flaw in Qlik Sense Enterprise for Windows lets an unauthenticated attacker generate an anonymous session and reach restricted endpoints — the first link in a chain that ransomware operators used for full compromise. Here's what to do, and how BreachRisk finds exposed Qlik servers.
CVE-2023-32315: Openfire admin console path traversal, actively exploited
A path-traversal flaw in Openfire's admin console lets an unauthenticated attacker reach restricted admin pages — a known stepping stone to plugin-upload code execution. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed Openfire.
CVE-2023-27350: PaperCut NG/MF authentication bypass to remote code execution, actively exploited
A flaw in PaperCut NG/MF lets an unauthenticated attacker bypass authentication and run code as SYSTEM. It was exploited in the wild, including by ransomware operators, and it's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed PaperCut.
CVE-2023-49103: ownCloud graphapi credential disclosure, actively exploited
A flaw in the ownCloud graphapi app exposes the server's PHP environment — and in containerized deployments that includes the admin password and other secrets — to an unauthenticated request. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed ownCloud.
CVE-2023-42793: JetBrains TeamCity authentication bypass to RCE, exploited by ransomware and APTs
An authentication bypass in JetBrains TeamCity lets an unauthenticated attacker run code on the CI/CD server. It's in CISA KEV, used in ransomware and nation-state campaigns. Here's what to do, and how BreachRisk finds exposed servers.
CVE-2023-35082: Ivanti EPMM / MobileIron Core authentication bypass, actively exploited
A second authentication bypass in Ivanti Endpoint Manager Mobile — reaching back into older MobileIron Core releases — lets a remote, unauthenticated attacker hit protected API endpoints. It's a perfect 10.0, exploited in the wild and in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed servers.
CVE-2023-35078: Ivanti EPMM (MobileIron) authentication bypass, actively exploited
An authentication bypass in Ivanti Endpoint Manager Mobile (formerly MobileIron Core) lets a remote, unauthenticated attacker reach protected API endpoints — including user and device data. It's a perfect 10.0, exploited in the wild and in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed servers.
CVE-2023-28432: MinIO information disclosure that leaks admin credentials
A flaw in clustered MinIO deployments returns all environment variables — including the root user and password — to an unauthenticated request. It's in CISA's KEV catalog. Here's why an information leak here is worse than it sounds, and how BreachRisk finds exposed MinIO.
CVE-2022-35914: GLPI unauthenticated command execution, actively exploited
A bundled test endpoint in GLPI lets an unauthenticated attacker inject PHP and run commands on the server. It's in CISA KEV with near-certain exploitation activity. Here's what to do, and how BreachRisk finds exposed instances.
Exposed Cerbo patient-portal logins and password spraying
A Cerbo patient-portal login on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into access to protected health information. Here's the risk — and how BreachRisk safely tests whether those logins hold.
CVE-2023-43177: CrushFTP unauthenticated command execution via attacker-controlled attributes
A flaw in CrushFTP lets an unauthenticated attacker manipulate object attributes to reach control of the server. It scores 9.8 and file-transfer servers are prime targets — though it isn't currently in CISA's KEV catalog. Here's the honest read, and how BreachRisk finds exposed CrushFTP servers.
CVE-2023-22527: Atlassian Confluence template injection to unauthenticated RCE, actively exploited
A template-injection flaw in out-of-date Confluence Data Center and Server lets an unauthenticated attacker run code on the instance. It's in CISA's KEV catalog and tied to ransomware. Here's what to do, and how BreachRisk finds exposed Confluence.
CVE-2022-36804: Atlassian Bitbucket command injection, remote code execution, actively exploited
A command-injection flaw in Bitbucket Server and Data Center lets an attacker with read access to a repository — public or private — run code by sending a crafted request. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed Bitbucket.
CVE-2022-26138: Atlassian Questions for Confluence hard-coded password, actively exploited
The Questions for Confluence app creates a hidden account with a hard-coded, now-public password — handing any unauthenticated attacker a login. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed Confluence.
CVE-2023-49070: Apache OFBiz pre-auth remote code execution via legacy XML-RPC
Leftover XML-RPC code in Apache OFBiz gives an unauthenticated attacker a path to remote code execution. It's a critical-class flaw in an ERP platform. Here's what to do, and how BreachRisk finds exposed OFBiz.
CVE-2023-38205: Adobe ColdFusion access-control bypass (the patch-bypass fix), actively exploited
This is the flaw that let attackers slip past the first fix for ColdFusion's access-control bypass and keep reaching administrator endpoints — exploited in the wild and in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed ColdFusion servers.
CVE-2023-29300: Adobe ColdFusion unauthenticated deserialization RCE, actively exploited
A deserialization flaw in Adobe ColdFusion lets an unauthenticated attacker run arbitrary code on the server — a 9.8, exploited in the wild to drop web shells, and in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed ColdFusion servers.
CVE-2023-29298: Adobe ColdFusion access-control bypass, actively exploited
An access-control bypass in Adobe ColdFusion lets an unauthenticated attacker reach administrator endpoints — and in the wild it was the front half of an exploit chain that dropped web shells. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed ColdFusion servers.
CVE-2023-27524: Apache Superset default SECRET_KEY authentication bypass, actively exploited
Apache Superset instances left on the default SECRET_KEY let an attacker forge their own session cookies and log in as any user — often the path to full takeover. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed Superset.
CVE-2023-26360: Adobe ColdFusion unauthenticated file read and code execution, actively exploited
An access-control flaw in Adobe ColdFusion lets an unauthenticated attacker read sensitive files and run code — it's in CISA's KEV catalog and was used to breach government servers. Here's what to do, and how BreachRisk finds exposed ColdFusion.
CVE-2022-33891: Apache Spark UI command injection via user impersonation, actively exploited
When ACLs are enabled, a flaw in the Apache Spark UI lets an attacker impersonate an arbitrary user and run shell commands as the Spark process. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed Spark UIs.
CVE-2022-24706: Apache CouchDB insecure default leads to unauthenticated admin and RCE
An insecure default in Apache CouchDB lets an attacker reach an improperly secured install without authenticating and escalate to admin — and, via Erlang, to code execution. A 9.8 in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed nodes.
CVE-2022-24112: Apache APISIX Admin API bypass leading to remote code execution, actively exploited
A batch-requests flaw in Apache APISIX lets an attacker bypass the Admin API's IP restriction and, with the default admin key, reach unauthenticated remote code execution. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed gateways.
CVE-2024-29824: Ivanti Endpoint Manager SQL injection to code execution, in CISA KEV
An unauthenticated SQL injection in the Ivanti Endpoint Manager core server lets an attacker on the same network run arbitrary commands on the box that manages your endpoints. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed EPM servers.
CVE-2024-13160: Ivanti Endpoint Manager path traversal and credential coercion, unauthenticated
An absolute path-traversal flaw in Ivanti Endpoint Manager lets a remote, unauthenticated attacker leak sensitive data — and researchers showed it can coerce the EPM machine-account credential. It's one of three related CVEs, all in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed servers.
CVE-2024-10914: D-Link NAS command injection on end-of-life devices D-Link won't patch
A command-injection flaw in several end-of-life D-Link NAS models lets an attacker inject OS commands via the account-management endpoint — and D-Link won't fix it. The only real remedy is retirement. Here's the risk, and how BreachRisk finds exposed devices.
CVE-2024-53704: SonicWall SonicOS SSLVPN authentication bypass, actively exploited
An authentication-bypass flaw in SonicWall's SSLVPN lets a remote attacker step past login with a crafted session cookie. A public exploit exists and it's being used. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds and safely confirms exposed firewalls.
CVE-2024-38819: Spring Framework path traversal in functional static-resource routes
A path-traversal flaw in Spring Framework can let an attacker read files off the server — but only when an app serves static resources through the functional web frameworks in a specific way. Here's who's actually affected, and how BreachRisk checks.
CVE-2024-29973: Zyxel NAS unauthenticated command injection, exploited by botnets
A command-injection flaw in Zyxel NAS326 and NAS542 lets an unauthenticated attacker run OS commands with a crafted HTTP request — on end-of-life devices already being swept up by botnets. Here's the risk, and how BreachRisk finds and safely confirms exposed NAS.
CVE-2024-29895: Cacti unauthenticated command injection in the 1.3.x dev branch
A command-injection flaw in Cacti's development branch lets an unauthenticated attacker run OS commands — a 10.0 on paper, but it only affects the unreleased 1.3.x dev code. Here's the real risk, and how BreachRisk finds exposed Cacti.
CVE-2025-32432: Craft CMS unauthenticated remote code execution, exploited in the wild
An unauthenticated remote code execution flaw in Craft CMS — a perfect 10.0 — was exploited in the wild before many sites patched. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed Craft installs.
CVE-2025-31161: CrushFTP authentication bypass and admin account takeover
An authentication-bypass flaw in CrushFTP lets an unauthenticated attacker take over the crushadmin account and, with it, the file server. A 9.8, in CISA KEV, exploited in the wild. Here's what to do, and how BreachRisk finds exposed servers.
CVE-2025-28367: mojoPortal directory traversal exposing Web.config and the machine key
A directory-traversal flaw in mojoPortal lets an unauthenticated attacker read the Web.config file and lift the ASP.NET machine key. Here's why that matters more than a file read, and how BreachRisk finds exposed mojoPortal.
CVE-2024-9465: Palo Alto Expedition unauthenticated SQL injection, actively exploited
An unauthenticated SQL injection in Palo Alto's Expedition migration tool lets an attacker dump password hashes, usernames, and device API keys — the keys to your firewalls. It's in CISA KEV. Here's what to do, and how BreachRisk finds exposed Expedition.
CVE-2024-8963: Ivanti Cloud Services Appliance path traversal, unauthenticated and exploited
A path-traversal flaw in the Ivanti Cloud Services Appliance lets an unauthenticated attacker reach restricted functionality — and chained with a companion bug it enabled remote code execution. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed appliances.
CVE-2024-56145: Craft CMS remote code execution via register_argc_argv
A remote code execution flaw in Craft CMS affects sites whose PHP has register_argc_argv enabled — a common default. It's in CISA's KEV catalog and being exploited. Here's what to do, and how BreachRisk finds exposed Craft installs.
CVE-2024-4879 (with CVE-2024-5217): ServiceNow Now Platform unauthenticated RCE, actively exploited
Input-validation flaws in the ServiceNow Now Platform let an unauthenticated attacker inject Jelly template code and execute commands. The pair was mass-exploited after disclosure and both are in CISA KEV. Here's what to do, and how BreachRisk finds exposed ServiceNow instances.
CVE-2024-46938: Sitecore unauthenticated arbitrary file read
A path-traversal flaw in Sitecore XP/XM/XC lets an unauthenticated attacker read arbitrary files — including web.config, whose secrets can be turned into remote code execution via ViewState. Here's what to do, and how BreachRisk finds exposed Sitecore servers.
CVE-2024-4358: Progress Telerik Report Server authentication bypass, actively exploited
An unauthenticated attacker can bypass authentication on Progress Telerik Report Server and reach restricted functionality — and it's been chained to remote code execution. It's in CISA KEV. Here's what to do, and how BreachRisk finds exposed servers.
CVE-2024-41713: Mitel MiCollab path traversal, actively exploited
A path-traversal flaw in Mitel MiCollab lets an unauthenticated attacker read files and reach data and configuration they shouldn't. It's in CISA's KEV catalog and ransomware-associated. Here's what to do, and how BreachRisk finds exposed MiCollab.
CVE-2024-36991: Splunk Enterprise on Windows path traversal, unauthenticated file read
A path-traversal flaw in Splunk Enterprise on Windows lets an unauthenticated attacker read files off the server — including material that can lead to account access. A fix exists; here's what to check, and how BreachRisk finds exposed instances.
CVE-2024-35286: Mitel MiCollab SQL injection, unauthenticated
A SQL-injection flaw in Mitel MiCollab lets an unauthenticated attacker read sensitive data and run database and management operations. Here's what to do, and how BreachRisk finds exposed MiCollab.
CVE-2024-20440: Cisco Smart Licensing Utility log leaks credentials to unauthenticated attackers
An overly verbose debug log in Cisco's Smart Licensing Utility can be pulled by an unauthenticated attacker — and it contains credentials that unlock the API. It pairs naturally with the CSLU static-credential flaw. Here's the risk, and how BreachRisk finds exposed instances.
CVE-2024-20439: Cisco Smart Licensing Utility static-credential backdoor, actively exploited
Cisco's Smart Licensing Utility shipped with an undocumented static admin credential — anyone who knows it can log into the API with full rights. It's in CISA's KEV catalog and being exploited. Here's what to do, and how BreachRisk finds exposed instances.
CVE-2024-1212: Progress Kemp LoadMaster unauthenticated OS command injection, actively exploited
An unauthenticated attacker who can reach the Progress Kemp LoadMaster management interface can run arbitrary system commands — potentially as root. It scores a 10 and is in CISA KEV. Here's what to do, and how BreachRisk finds exposed LoadMasters.
CVE-2024-11680: ProjectSend unauthenticated authentication bypass, actively exploited
An improper-authentication flaw in ProjectSend lets an unauthenticated attacker change the app's configuration, create accounts, and plant web shells. It's a 9.8, mass-exploited, and in CISA KEV. Here's what to do, and how BreachRisk finds exposed ProjectSend instances.
CVE-2024-45507: Apache OFBiz unauthenticated remote code execution
A missing-authorization flaw in Apache OFBiz lets an unauthenticated attacker reach code injection and SSRF — a critical, network-reachable path into an ERP platform. Here's what to do, and how BreachRisk finds exposed OFBiz.
CVE-2024-45195: Apache OFBiz forced-browsing patch bypass to remote code execution, actively exploited
A forced-browsing flaw in Apache OFBiz bypasses earlier patches to reach restricted functionality — and, in practice, code execution. NVD scores it 7.5; the real world put it in KEV. Here's why, and how BreachRisk finds exposed OFBiz.
CVE-2024-38856: Apache OFBiz authorization bypass to remote code execution, actively exploited
An incorrect-authorization flaw in Apache OFBiz lets an unauthenticated attacker reach screen-rendering code and execute commands — it's in CISA's KEV catalog with public exploits. Here's what to do, and how BreachRisk finds exposed OFBiz.
CVE-2024-20767: Adobe ColdFusion arbitrary file read via exposed admin panel, actively exploited
An access-control flaw in Adobe ColdFusion lets an unauthenticated attacker read arbitrary files when the admin panel is internet-exposed — it's in CISA's KEV catalog with a public proof-of-concept. Here's what to do, and how BreachRisk finds exposed ColdFusion.
Exposed SMB file sharing on the public internet
An SMB service exposed to the public internet is a standing target for credential attacks and a protocol that was never meant to face the open internet. Here's the risk, and how BreachRisk safely tests whether those credentials hold.
Exposed Apache Tomcat Manager logins and password spraying
An Apache Tomcat Manager login on the public internet is a high-value target for password spraying — a working credential can mean deploying code and full server compromise. Here's the risk, and how BreachRisk safely tests whether that login holds.
CVE-2024-4956: Sonatype Nexus Repository path traversal, unauthenticated file read
A path-traversal flaw in Sonatype Nexus Repository 3 lets an unauthenticated attacker read system files — with a public exploit and easy discovery. Here's what to do, and how BreachRisk finds and safely confirms exposed servers.
CVE-2024-31982: XWiki unauthenticated remote code execution via database search
A code-injection flaw in XWiki's database search lets any visitor run code on the server through the search text — no login required. It's a 9.8 with a public exploit. Here's what to do, and how BreachRisk finds and safely confirms exposed XWiki.
CVE-2024-1709: ConnectWise ScreenConnect authentication bypass, mass-exploited
An authentication-bypass flaw in ConnectWise ScreenConnect lets an unauthenticated attacker walk into the admin setup and create an administrator — a perfect 10.0, mass-exploited within days. Here's what to do, and how BreachRisk finds exposed ScreenConnect servers.
CVE-2022-1040: Sophos Firewall authentication bypass to RCE, exploited in the wild
An authentication-bypass flaw in Sophos Firewall's User Portal and Webadmin lets a remote attacker reach code execution, and it was exploited as a targeted zero-day. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds and safely confirms exposed firewalls.
Exposed Nexus smart-meter logins and password spraying
A Nexus smart-meter login on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into access to an internet-facing metering device. Here's the risk — and how BreachRisk safely tests whether those logins hold.
CVE-2024-23897: Jenkins Path Traversal Vulnerability Exploitation (CVE-2024-23897)
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthentic…
Exposed Hikvision router logins and password spraying
A Hikvision router login on the public internet is a standing target for password spraying, and weak or default credentials turn that exposure into control of a network device. Here's the risk, and how BreachRisk safely tests whether that login holds.
Exposed Hikvision IP camera logins and password spraying
A Hikvision IP camera login on the public internet is a standing target for password spraying, and weak or default credentials turn that exposure into a live view of your premises. Here's the risk, and how BreachRisk safely tests whether that login holds.
CVE-2024-7593: Ivanti Virtual Traffic Manager authentication bypass, admin takeover
A broken authentication algorithm in Ivanti Virtual Traffic Manager lets a remote, unauthenticated attacker bypass the admin panel and create a rogue administrator. It's in CISA's KEV catalog with a public exploit. Here's what to do, and how BreachRisk finds exposed appliances.
CVE-2024-50623: Cleo Harmony, VLTrader & LexiCom unrestricted file upload RCE, ransomware-exploited
An unrestricted file-upload flaw in Cleo's managed-file-transfer products lets an unauthenticated attacker upload and run code — a 9.8, exploited at scale by ransomware crews, and in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed servers.
CVE-2024-37383: Roundcube Webmail cross-site scripting, exploited in government phishing
A cross-site scripting flaw via SVG animate attributes lets a crafted email run script in a Roundcube user's session. It's in CISA's KEV catalog and was used in phishing against government agencies. Here's the risk, and how BreachRisk finds exposed Roundcube instances.
CVE-2024-31849: CData Connect path traversal, unauthenticated admin access
A path-traversal flaw in the Java build of CData Connect running on the embedded Jetty server lets an unauthenticated attacker reach administrative functionality. Rated 9.8 by the reporting researcher. Here's what to do, and how BreachRisk finds exposed CData.
CVE-2024-23692: Rejetto HTTP File Server unauthenticated RCE, actively exploited
A template-injection flaw in Rejetto HTTP File Server (HFS) 2.3m and earlier lets an unauthenticated attacker run commands with a single crafted request. It's exploited in the wild, it's in CISA KEV, and the affected version is end-of-life. Here's what to do, and how BreachRisk finds exposed HFS servers.
CVE-2024-0204: Fortra GoAnywhere MFT authentication bypass, create-admin flaw
An authentication bypass in Fortra's GoAnywhere MFT lets an unauthenticated attacker create a new administrator account through the admin portal. It scores 9.8 and has public exploits. Here's what to do, and how BreachRisk finds exposed GoAnywhere.
CVE-2023-0669: Fortra GoAnywhere MFT deserialization RCE — the Clop mass-exploitation flaw
A deserialization flaw in GoAnywhere MFT's License Response Servlet gave attackers remote code execution — and the Clop ransomware group used it as a zero-day to steal data from scores of organizations. NVD rates it 7.2; the real world made it far worse. Here's why, and how BreachRisk finds exposed GoAnywhere.
CVE-2022-26134: Atlassian Confluence OGNL injection, unauthenticated RCE, exploited as a zero-day
A second OGNL injection flaw in Confluence Server and Data Center — this one exploited as a zero-day before the patch. Unauthenticated, remote, code execution, a 9.8, and in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed Confluence.
CVE-2021-41773: Apache HTTP Server path traversal, actively exploited
A path-traversal flaw in a single Apache HTTP Server release lets attackers read files outside the web root and, where CGI is enabled, run code. It's in CISA's KEV catalog and tied to ransomware. Here's what to do, and how BreachRisk finds affected servers.
CVE-2021-33558: Boa web server information disclosure (disputed)
An information-disclosure issue reported against the Boa web server — but disputed, and Boa itself is long unmaintained and common in embedded devices. Here's the honest picture, and how BreachRisk finds exposed Boa on your attack surface.
CVE-2021-26084: Atlassian Confluence OGNL injection, unauthenticated RCE, actively exploited
An OGNL injection flaw in Confluence Server and Data Center lets an unauthenticated attacker run code on the server. It's a 9.8, it's in CISA's KEV catalog, and it was mass-exploited for coin miners and ransomware. Here's what to do, and how BreachRisk finds exposed Confluence.
CVE-2021-20021: SonicWall Email Security admin-account creation, actively exploited
A flaw in SonicWall Email Security lets an unauthenticated attacker create an administrator account with a single crafted request, and it was chained as a zero-day by ransomware actors. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed appliances.
CVE-2019-7481: SonicWall SMA100 SQL injection, unauthenticated data access
A SQL-injection flaw in SonicWall SMA100 lets an unauthenticated attacker read data they shouldn't, and it's tied to ransomware campaigns against these appliances. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds and safely confirms exposed devices.
CVE-2018-13382: Fortinet FortiOS SSL VPN improper authorization — vendor-disputed
A reported authorization flaw in the FortiOS SSL VPN portal — the so-called 'magic backdoor' — that Fortinet has publicly disputed. Only old, mostly end-of-life FortiOS is affected. Here's an honest read on the evidence, and how BreachRisk finds exposed FortiGates.
CVE-2014-6271 (Shellshock): Bash command injection on exposed SonicWall appliances
Shellshock is a decade-old Bash flaw that still turns up on legacy appliances, letting an unauthenticated attacker run commands via a crafted request. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds and safely confirms exposed SonicWall devices.
CVE-2025-31324: SAP NetWeaver Visual Composer unauthenticated file upload to RCE, actively exploited
A missing authorization check in SAP NetWeaver's Visual Composer lets an unauthenticated attacker upload an executable and take over the host — a perfect 10.0, exploited in the wild. Here's what to do, and how BreachRisk finds and safely verifies exposed NetWeaver.
CVE-2022-21371: Oracle WebLogic path traversal that leaks internal files
A path-traversal flaw in Oracle WebLogic lets an unauthenticated attacker read deployment descriptors and other internal files — no takeover, but the leaked config can enable the next attack. Here's the honest severity, and how BreachRisk finds and safely confirms exposed WebLogic.
CVE-2022-1388: F5 BIG-IP iControl REST authentication bypass, unauthenticated RCE
An authentication-bypass flaw in F5 BIG-IP's iControl REST interface lets an unauthenticated attacker run commands as root. It scores 9.8, has public exploits, and is in CISA's KEV catalog with ransomware use. Here's what to do, and how BreachRisk finds exposed BIG-IP devices.
CVE-2021-35587: Oracle Access Manager unauthenticated takeover, actively exploited
A missing-authentication flaw in Oracle Access Manager lets an unauthenticated attacker take over the SSO gatekeeper itself — create superusers, run code. It's in CISA's KEV catalog and exploited in the wild. Here's the risk, and how BreachRisk finds and safely confirms exposed OAM.
CVE-2021-22986: F5 BIG-IP iControl REST unauthenticated remote code execution
A server-side request forgery in BIG-IP's iControl REST interface lets an unauthenticated attacker run commands on the appliance. It scores 9.8, it's in CISA KEV, and public exploits followed disclosure within days. Here's what to do, and how BreachRisk finds exposed BIG-IPs.
CVE-2020-5902: F5 BIG-IP TMUI unauthenticated remote code execution
A path-traversal flaw in the BIG-IP configuration interface (TMUI) lets an unauthenticated attacker run commands on the appliance. It scored 9.8, it's in CISA KEV, and it was mass-exploited within days. Here's what to do, and how BreachRisk finds exposed BIG-IPs.
CVE-2020-14882: Oracle WebLogic Console unauthenticated RCE, trivially exploited
A flaw in the Oracle WebLogic administration console lets an unauthenticated attacker run code with a single crafted request — weaponized within a week of the patch and swept up by botnets. It's in CISA's KEV catalog. Here's the risk, and how BreachRisk finds and safely confirms exposed WebLogic.
CVE-2019-2729: Oracle WebLogic unauthenticated deserialization RCE (a 2725 bypass)
A deserialization flaw in Oracle WebLogic's Web Services lets an unauthenticated attacker run code and take over the server — it emerged as a bypass of the CVE-2019-2725 patch and was exploited as a zero-day. Here's the risk, and how BreachRisk finds and safely confirms exposed WebLogic.
CVE-2019-2725: Oracle WebLogic unauthenticated deserialization RCE, widely exploited
A deserialization flaw in Oracle WebLogic's Web Services lets an unauthenticated attacker run code and take over the server — one of the most heavily exploited WebLogic bugs, used by cryptominers and ransomware. It's in CISA's KEV catalog. Here's the risk, and how BreachRisk finds and safely confirms exposed WebLogic.
CVE-2024-38812: VMware vCenter Server unauthenticated RCE, in CISA KEV
A heap-overflow flaw in vCenter Server's DCERPC implementation lets a network attacker run code on the appliance that manages your entire virtual estate. It's a 9.8 and it's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed vCenter.
CVE-2023-34048: VMware vCenter Server out-of-bounds write RCE, actively exploited
An out-of-bounds write in vCenter Server's DCERPC implementation gives an unauthenticated network attacker code execution on your virtualization control plane — used in real-world espionage intrusions and listed in CISA KEV. Here's what to do, and how BreachRisk finds exposed vCenter.
CVE-2022-47966: Zoho ManageEngine SAML unauthenticated RCE, actively exploited
An unsafe third-party XML library gives dozens of ManageEngine products an unauthenticated remote code execution flaw when SAML single sign-on is (or ever was) configured — exploited in the wild and in CISA KEV. Here's what to do, and how BreachRisk finds exposed ManageEngine.
CVE-2022-35405: Zoho ManageEngine Password Manager Pro / PAM360 unauthenticated RCE, actively exploited
A Java deserialization flaw in ManageEngine Password Manager Pro and PAM360 allows unauthenticated remote code execution on a server that holds privileged credentials — exploited in the wild and in CISA KEV. Here's what to do, and how BreachRisk finds and safely confirms exposed instances.
CVE-2021-40539: Zoho ManageEngine ADSelfService Plus auth bypass to RCE, actively exploited
A REST API authentication bypass in ManageEngine ADSelfService Plus leads to unauthenticated remote code execution — exploited by APT actors and in CISA KEV. Here's what to do, and how BreachRisk finds and safely confirms exposed ADSelfService Plus.
CVE-2021-21974: VMware ESXi OpenSLP heap overflow, mass-exploited by ESXiArgs
A heap-overflow flaw in the OpenSLP service on VMware ESXi lets an attacker on the same network run code on the hypervisor — the bug behind the ESXiArgs ransomware wave. Here's what to do, and how BreachRisk finds exposed ESXi hosts.
CVE-2021-21972: VMware vCenter unauthenticated RCE via vSphere Client plugin
A flaw in a default vCenter Server plugin lets an unauthenticated attacker with access to port 443 run commands on the host. It was mass-exploited and is in CISA's KEV catalog. Here's what to do, and how BreachRisk finds and safely confirms exposed servers.
CVE-2024-28987: SolarWinds Web Help Desk hardcoded credentials, actively exploited
SolarWinds Web Help Desk shipped with a hardcoded credential that lets an unauthenticated attacker read and modify help-desk data. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds and safely confirms exposed instances.
CVE-2021-22005: VMware vCenter arbitrary file upload to RCE, exploited in the wild
A file-upload flaw in vCenter's Analytics service lets an attacker with access to port 443 execute code on the host — regardless of configuration. It was exploited in the wild and is in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed servers.
CVE-2021-21985: VMware vCenter unauthenticated RCE via vSAN Health plugin
A flaw in vCenter's vSAN Health Check plugin — enabled by default even without vSAN — lets an attacker with access to port 443 run commands on the host. It's mass-exploited and in CISA's KEV catalog. Here's what to do, and how BreachRisk finds and safely confirms exposed servers.
CVE-2021-35211: SolarWinds Serv-U remote code execution, exploited in the wild
A memory flaw in SolarWinds Serv-U lets a remote attacker run code on the host with high privileges, and it was exploited as a targeted zero-day. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed servers.
CVE-2021-22900: Ivanti Connect Secure File Upload Vulnerability Exploitation (CVE-2021-22900)
A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an authenticated administrator to perform a file write via a maliciously crafted archive upload in the admi…
CVE-2025-42599: Qualitia Active! Mail unauthenticated buffer-overflow RCE, exploited in the wild
A stack buffer overflow in the Active! Mail webmail server lets an unauthenticated attacker run code or crash the service — a 9.8, exploited in the wild, and in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed servers.
CVE-2024-22024: Ivanti Connect Secure XXE exposing restricted resources without authentication
An XML External Entity flaw in the SAML component of Ivanti Connect Secure lets an unauthenticated attacker reach restricted resources. It surfaced during the intense early-2024 targeting of Ivanti appliances and has a public proof-of-concept. Here's what to do, and how BreachRisk finds exposed gateways.
CVE-2022-20829: Cisco ASA/ASDM unsigned image code execution
A packaging-and-validation flaw lets an administrator upload a malicious ASDM image to a Cisco ASA that later runs code on management users' machines. It requires admin privileges on the device, which caps the risk. Here's the honest severity, and how BreachRisk finds exposed ASDM.
CVE-2021-22899: Pulse/Ivanti Connect Secure command injection, authenticated RCE
A command-injection flaw in Pulse Connect Secure (now Ivanti Connect Secure) lets an authenticated attacker run code on the VPN appliance via the Windows Resource Profiles feature. It's older and needs a login, but it's in CISA's KEV catalog. Here's the read, and how BreachRisk finds exposed appliances.
CVE-2021-22894: Pulse/Ivanti Connect Secure buffer overflow, authenticated RCE as root
A buffer overflow in Pulse Connect Secure (now Ivanti Connect Secure) lets an authenticated attacker run code as root on the VPN appliance. It's older and requires a login, but it's in CISA's KEV catalog. Here's the honest read, and how BreachRisk finds exposed appliances.
CVE-2021-22893: Ivanti (Pulse) Connect Secure authentication bypass, exploited by nation-state actors
A flaw in Pulse Connect Secure (now Ivanti) let unauthenticated attackers run code on the VPN gateway and slip past authentication — exploited as a zero-day by suspected nation-state actors. It's a perfect 10.0 and in CISA KEV. Here's what to do, and how BreachRisk finds exposed gateways.
CVE-2019-11510: Pulse/Ivanti Connect Secure arbitrary file read, unauthenticated and mass-exploited
A path-traversal flaw in Pulse Connect Secure (now Ivanti Connect Secure) lets an unauthenticated attacker read any file on the appliance — including credentials and session data. It was mass-exploited and tied to ransomware. Here's what to do, and how BreachRisk finds exposed appliances.
CVE-2021-30118: Kaseya VSA File Upload Vulnerability Exploitation (CVE-2021-30118)
An attacker can upload files with the privilege of the Web Server process for Kaseya VSA Unified Remote Monitoring & Management (RMM) 9.5.4.2149 and subsequently use these files to execute asp commands The api /SystemTab…
CVE-2021-30119: Kaseya VSA Cross-site Scripting Vulnerability Exploitation (CVE-2021-30119)
Affected Kaseya VSA servers are vulnerable to an authenticated reflective XSS in the HelpDeskTab/rcResults.asp endpoint. The parameter result of /HelpDeskTab/rcResults.asp is insecurely returned in the requested web page…
CVE-2021-30201: Kaseya VSA XML External Entity Reference ('XXE') Vulnerability Exploitation (CVE-2021-30201)
The API endpoint /vsaWS/KaseyaWS.asmx can be used to submit XML to the system. When this XML is processed (external) entities are insecurely processed and fetched by the system and returned to the attacker. Using this vu…
CVE-2021-30117: Kaseya VSA SQL Injection Vulnerability Exploitation (CVE-2021-30117)
The API call /InstallTab/exportFldr.asp is vulnerable to a semi-authenticated boolean-based blind SQL injection in the parameter fldrId. A valid session id is required for exploitation.
CVE-2021-30121: Kaseya VSA LFI Vulnerability Exploitation (CVE-2021-30121)
Semi-authenticated local file inclusion The contents of arbitrary files can be returned by the webserver Example request: `https://x.x.x.x/KLC/js/Kaseya.SB.JS/js.aspx?path=C:\Kaseya\WebPages\dl.asp` A valid sessionId is …
CVE-2021-301120: Kaseya 2FA Bypass Vulnerability Exploitation (CVE-2021-30120)
Kaseya VSA before 9.5.7 allows attackers to bypass the 2FA requirement. During the login process, after the user authenticates with username and password, the server sends a response to the client with the booleans MFARe…
CVE-2023-23752: Joomla! Information Disclosure Vulnerability Exploitation (CVE-2023-23752)
An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.
CVE-2024-23917: JetBrains TeamCity authentication bypass leading to RCE
An authentication bypass in JetBrains TeamCity lets an unauthenticated attacker reach remote code execution on the CI/CD server. A fix is out in 2023.11.3. Here's the risk, and how BreachRisk finds exposed servers.
CVE-2023-6549: Citrix NetScaler unauthenticated denial of service and memory over-read
A memory-buffer flaw in NetScaler ADC and Gateway lets an unauthenticated attacker crash the appliance and read out-of-bounds memory when it's configured as a Gateway or AAA server. It's in CISA's KEV catalog. Here's the risk, and how BreachRisk finds exposed NetScalers.
CVE-2023-6548: Citrix NetScaler authenticated code injection via the management interface
A code-injection flaw in NetScaler ADC and Gateway that needs low-privilege access to the management interface. It's in CISA's KEV catalog, but the preconditions are real — and they're the reason the management plane should never face the internet. Here's the honest read, and how BreachRisk finds exposed NetScalers.
CVE-2023-4966 (CitrixBleed): NetScaler session-token leak that bypasses MFA
"CitrixBleed" leaks memory from NetScaler ADC/Gateway — including valid session tokens an attacker can replay to hijack sessions and skip MFA entirely. NVD calls it a 7.5; in the real world it was ransomware's front door. Here's why, and how BreachRisk finds exposed appliances.
CVE-2023-3519: Citrix NetScaler unauthenticated remote code execution
An unauthenticated code-injection flaw in NetScaler ADC and Gateway lets an attacker run code on the appliance with no credentials — exploited as a zero-day and tied to web-shell campaigns. Here's what to do, and how BreachRisk finds exposed NetScalers.
CVE-2022-27593: QNAP Photo Station externally controlled reference, exploited by DeadBolt ransomware
An externally controlled reference flaw in QNAP's Photo Station let attackers modify system files on internet-facing NAS devices — the vector behind a DeadBolt ransomware campaign. It's in CISA KEV. Here's what to do, and how BreachRisk finds exposed NAS.
CVE-2021-30116: Kaseya VSA Credential Disclosure Vulnerability Exploitation (CVE-2021-30116)
Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on premise offers a download page where the clients for the installation can be downloaded. The default U…
CVE-2020-36195: QNAP NAS SQL injection in Multimedia Console / Media Streaming
An unauthenticated SQL injection in QNAP's Multimedia Console and Media Streaming add-on can expose application data on internet-facing NAS devices — patched just before the Qlocker ransomware wave. Here's what to do, and how BreachRisk finds exposed NAS.
CVE-2019-19781: Citrix ADC/Gateway path traversal leading to unauthenticated code execution
A directory-traversal flaw in Citrix ADC and Gateway ("Shitrix") lets an unauthenticated attacker reach restricted paths and run code on the appliance. A 9.8, in CISA KEV, tied to ransomware. Here's what to do, and how BreachRisk finds exposed appliances.
A milestone: Lloyd's backs BreachBits
We took attacker-grade tech we'd already built into Lloyd's Lab — and learned the cyber insurance market's real pain points so we could apply it where underwriting needs proof, not paperwork. Lloyd's has now made a strategic investment in BreachBits.
CVE-2017-12637: SAP NetWeaver AS Java directory traversal, unauthenticated file read
A directory-traversal flaw in SAP NetWeaver AS Java lets an unauthenticated attacker read arbitrary files from the server. It's in CISA's KEV catalog and has been exploited since 2017. Here's what to do, and how BreachRisk finds and safely verifies exposed NetWeaver.
Exposed WordPress admin logins and password spraying
Every WordPress site ships with a well-known admin login, which makes it a favorite target for password spraying. Weak or reused credentials turn that exposure into full control of the site. Here's the risk, and how BreachRisk safely tests whether the login holds.
Exposed web logins and password spraying
Any web application with a login on the public internet is a standing target for password spraying, and one weak or reused credential turns that exposure into access. Here's the risk — and how BreachRisk safely tests whether those logins hold.
Exposed WatchGuard VPN logins and password spraying
A WatchGuard VPN portal on the public internet is a standing target for password spraying, and one weak or reused credential turns that exposure into a direct foothold on your internal network. Here's the risk — and how BreachRisk safely tests whether those logins hold.
Exposed UniFi management logins and password spraying
A UniFi management portal on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into control of your network gear. Here's the risk, and how BreachRisk safely tests whether those logins hold.
Exposed Telnet on the public internet
Telnet sends everything — including passwords — in cleartext, and an internet-facing Telnet service is both a credential-attack target and a live eavesdropping risk. Here's why it should be retired, and how BreachRisk finds it.
Exposed SSH and password-based brute forcing
An internet-facing SSH service that accepts password authentication is a standing target for brute-force and credential attacks. The fix is largely a configuration choice. Here's the risk, and how BreachRisk safely tests whether those credentials hold.
Exposed SonicWall Virtual Office logins and password spraying
A SonicWall Virtual Office portal on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into VPN access to your network. Here's the risk, and how BreachRisk safely tests whether those logins hold.
Exposed Remote Desktop (RDP) on the public internet
An RDP service reachable from the public internet is a standing target for brute-force and password-spraying attacks — and one of the most common ways ransomware gets in. Here's the risk, and how BreachRisk finds exposed RDP.
PostgreSQL exposed to the internet
A PostgreSQL database reachable directly from the internet is a target it should never have been — open to credential brute-forcing against default and weak logins. Here's the risk, and how BreachRisk safely tests whether it holds.
Exposed Palo Alto management interface and password spraying
A Palo Alto firewall management interface on the public internet is a login that controls the firewall itself, and weak or reused credentials hand that control to an attacker. Here's the risk, and how BreachRisk safely tests whether it holds.
Exposed Palo Alto GlobalProtect VPN logins and password spraying
A Palo Alto GlobalProtect VPN portal is a door into the internal network, and weak or reused credentials open it. Here's the risk, and how BreachRisk safely tests whether that login holds.
MySQL exposed to the internet
A MySQL or MariaDB database reachable directly from the internet is a target it should never have been — open to credential brute-forcing against default and weak logins. Here's the risk, and how BreachRisk safely tests whether it holds.
Microsoft SQL Server exposed to the internet
A Microsoft SQL Server database reachable directly from the internet is a target it should never have been — open to credential brute-forcing against default and weak logins. Here's the risk, and how BreachRisk safely tests whether it holds.
Microsoft 365 password spraying against exposed logins
Applications that authenticate against Microsoft 365 inherit one of the most heavily sprayed login surfaces on the internet. Weak or reused credentials without MFA turn that into cloud account access. Here's the risk, and how BreachRisk safely tests whether it holds.
CVE-2021-26855: Microsoft Exchange ProxyLogon Vulnerability (CVE-2021-26855) Exploitation
Attempt to gain access to emails, sensitive files and internal network using a combination of Microsoft Exchange vulnerabilities.
Exposed Outlook on the web (OWA) and password spraying
An internet-facing Outlook Web Access / Exchange login is a well-known target for password spraying, and one weak credential opens a mailbox full of sensitive data. Here's the risk, and how BreachRisk safely tests whether that login holds.
Exposed LiquidFiles logins and password spraying
A LiquidFiles secure-file-transfer login on the public internet is a standing target for password spraying, and one weak or reused credential can hand an attacker the files it moves. Here's the risk, and how BreachRisk safely tests whether those logins hold.
Exposed Ivanti Connect Secure VPN logins and password spraying
An Ivanti Connect Secure (Pulse Secure) VPN login is a door straight into the internal network, and weak or reused credentials open it. Here's the risk, and how BreachRisk safely tests whether that login holds.
Exposed Ivanti Connect Secure admin portals and password spraying
The administrator portal of an Ivanti Connect Secure (Pulse Secure) VPN is a high-value login on the edge of your network. Weak or reused credentials turn that exposure into administrative control of the gateway. Here's the risk, and how BreachRisk safely tests whether it holds.
HTTP Basic Authentication exposed to the internet
A web resource protected only by HTTP Basic Authentication is a simple username-and-password prompt facing the internet — easy to spray, and only as strong as the password behind it. Here's the risk, and how BreachRisk safely tests whether it holds.
Exposed Gigapod file-storage logins and password spraying
A Gigapod file-storage login on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into access to stored and shared files. Here's the risk — and how BreachRisk safely tests whether those logins hold.
FTP brute force against internet-facing file servers
An internet-facing FTP service is a standing target for credential guessing, and default, weak, or reused passwords turn that exposure into access. Here's the risk, and how BreachRisk safely tests whether those logins hold.
Anonymous FTP access on internet-facing file servers
An internet-facing FTP server that accepts anonymous logins hands unauthenticated strangers a foothold in your files — and sometimes a place to upload their own. No CVE, just a setting. Here's the risk, and how BreachRisk verifies it safely.
Fortinet Management Interface Password Spraying
Attempt authentication to Fortinet Management Interface using exposed or weak credentials.
Exposed Fortinet SSL VPN logins and password spraying
A Fortinet SSL VPN portal on the public internet is a standing target for password spraying, and one weak or reused credential turns that exposure into a foothold on your network. Here's the risk — and how BreachRisk safely tests whether those logins hold.
Exposed Fortinet FortiManager logins and password spraying
A Fortinet FortiManager login on the public internet is a standing target for password spraying, and one weak or reused credential can hand over central control of every firewall it manages. Here's the risk — and how BreachRisk safely tests whether those logins hold.
Exposed FortiGate logins and password spraying
A FortiGate login on the public internet is a standing target for password spraying, and one weak or reused credential turns that exposure into access through your firewall. Here's the risk — and how BreachRisk safely tests whether those logins hold.
Exposed FortiGate management logins and password spraying
A FortiGate management interface on the public internet is a standing target for password spraying, and one weak or reused credential can hand over administrative control of your firewall. Here's the risk — and how BreachRisk safely tests whether those logins hold.
Exposed FortiClient EMS logins and password spraying
A FortiClient Endpoint Management Server login on the public internet is a standing target for password spraying, and one weak or reused credential can hand over the console that manages your endpoint agents. Here's the risk — and how BreachRisk safely tests whether those logins hold.
Exposed Fortinet FortiAnalyzer logins and password spraying
A Fortinet FortiAnalyzer login on the public internet is a standing target for password spraying, and one weak or reused credential can expose the logs and analytics from across your Fortinet fabric. Here's the risk — and how BreachRisk safely tests whether those logins hold.
Exposed Django admin logins and password spraying
A Django administrator portal on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into privileged control of the application. Here's the risk — and how BreachRisk safely tests whether those logins hold.
CVE-2025-24813: Apache Tomcat path-equivalence flaw leading to RCE, actively exploited
A path-equivalence flaw in Apache Tomcat can expose sensitive files and, on a write-enabled default servlet, reach remote code execution via unsafe deserialization. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds affected Tomcat.
CVE-2025-24472: Fortinet FortiOS authentication bypass via CSF proxy requests, exploited
A second FortiOS/FortiProxy authentication bypass — this one via crafted Security Fabric proxy requests — that can grant super-admin. It's in CISA KEV and was chained with CVE-2024-55591 in ransomware activity. Here's what to do, and how BreachRisk finds exposed FortiGates.
CVE-2025-22457: Ivanti Connect Secure stack buffer overflow, unauthenticated RCE, actively exploited
A stack-based buffer overflow in Ivanti Connect Secure lets a remote, unauthenticated attacker run code on the appliance — and it's been exploited in the wild. Here's what to do, and how BreachRisk finds exposed appliances.
CVE-2025-0282: Ivanti Connect Secure unauthenticated RCE, exploited as a zero-day
A stack-based buffer overflow in Ivanti Connect Secure lets an unauthenticated attacker run code on the VPN — and it was exploited as a zero-day before the fix shipped. Here's what to do, and how BreachRisk surfaces exposed appliances.
CVE-2025-0111: Palo Alto PAN-OS authenticated file read, chained to root
An authenticated file-read flaw in PAN-OS lets a low-privileged user read files on the firewall — modest alone, but it's being chained with an auth bypass and a privilege-escalation bug to reach root. It's in CISA KEV. Here's what to do, and how BreachRisk finds exposed interfaces.
CVE-2025-0108: Palo Alto PAN-OS management-interface authentication bypass, actively exploited
A path-confusion flaw between Nginx and Apache lets an unauthenticated attacker bypass authentication on the PAN-OS management interface — and it's being chained to root. It's in CISA KEV. Here's what to do, and how BreachRisk finds exposed interfaces.
CVE-2024-9474: Palo Alto PAN-OS privilege escalation to root, actively exploited
A PAN-OS administrator can escalate to root command execution on the firewall — and attackers chained it with an unauthenticated auth bypass to take over exposed devices. It's in CISA KEV. Here's what to do, and how BreachRisk finds exposed interfaces.
CVE-2024-6387 (regreSSHion): OpenSSH pre-auth RCE that's real but hard to exploit
regreSSHion is an unauthenticated remote code execution flaw in OpenSSH's server — serious on paper, but slow and unreliable to exploit in practice, and not in CISA's KEV catalog. Here's the honest severity, and how BreachRisk finds affected SSH.
CVE-2024-55591: Fortinet FortiOS authentication bypass to super-admin, actively exploited
An authentication-bypass flaw in FortiOS and FortiProxy lets a remote attacker reach super-admin via crafted Node.js websocket requests. It's in CISA KEV and tied to ransomware activity. Here's what to do, and how BreachRisk finds exposed FortiGates.
CVE-2024-4040: CrushFTP server-side template injection, unauthenticated and exploited
A server-side template injection flaw in CrushFTP lets an unauthenticated attacker read files outside the sandbox, bypass authentication, and reach code execution. It was a zero-day and is in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed CrushFTP servers.
CVE-2024-3400: Palo Alto PAN-OS GlobalProtect unauthenticated RCE, root-level
A command-injection flaw in PAN-OS GlobalProtect lets an unauthenticated attacker run commands as root on the firewall — a perfect 10.0, exploited in the wild before the fix. Here's what to do, and how BreachRisk finds exposed firewalls.
CVE-2024-3393: Palo Alto PAN-OS DNS Security denial-of-service, actively exploited
A malicious DNS packet can reboot a PAN-OS firewall, and repeated attempts push it into maintenance mode — an outage of your perimeter. It's in CISA KEV and exploited in the wild. Here's what to do, and how BreachRisk finds exposed devices.
CVE-2024-28995: SolarWinds Serv-U directory traversal, actively exploited
A path-traversal flaw in SolarWinds Serv-U lets an unauthenticated attacker read files off the host, and it was exploited within days of disclosure. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds and safely confirms exposed servers.
CVE-2024-24919: Check Point Security Gateway information disclosure, exploited in the wild
An arbitrary-file-read flaw in Check Point Security Gateways with remote-access VPN enabled lets an unauthenticated attacker pull sensitive files — including material that leads to full compromise. It was a zero-day and it's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed gateways.
CVE-2024-21893: Ivanti Connect Secure SSRF, chained for unauthenticated access and actively exploited
A server-side request forgery flaw in the SAML component of Ivanti Connect Secure lets an unauthenticated attacker reach restricted internal resources — and it was used to defeat Ivanti's own mitigation during the early-2024 exploitation wave. It's in CISA's KEV. Here's what to do, and how BreachRisk finds exposed appliances.
CVE-2024-21888: Ivanti Connect Secure privilege escalation to administrator
A privilege-escalation flaw in Ivanti Connect Secure and Policy Secure lets a lower-privileged user become an administrator. It's serious on a perimeter appliance, but unlike its siblings it isn't in CISA's KEV catalog. Here's the honest read, and how BreachRisk finds exposed appliances.
CVE-2024-21887: Ivanti Connect Secure command injection, actively exploited and chained to unauthenticated RCE
A command-injection flaw in Ivanti Connect Secure and Policy Secure lets crafted requests run arbitrary commands on the appliance — and paired with CVE-2023-46805 it became unauthenticated, in-the-wild remote code execution. Here's what to do, and how BreachRisk finds exposed appliances.
CVE-2024-21762: Fortinet FortiOS SSL VPN remote code execution, actively exploited
An unauthenticated remote-code-execution flaw in Fortinet's FortiOS SSL VPN has been exploited in the wild and sits in CISA's KEV catalog. Here's what matters — and how BreachRisk finds exposed FortiGate appliances before an attacker does.
CVE-2024-21683: Atlassian Confluence authenticated remote code execution
A code-injection flaw in Confluence Data Center and Server lets an authenticated user with the right privilege run code on the server via the 'Add a new language' feature. Public exploit code exists. Here's what to do, and how BreachRisk finds exposed Confluence.
CVE-2024-0012: Palo Alto PAN-OS management-interface authentication bypass, actively exploited
An unauthenticated attacker who can reach a PAN-OS management web interface can bypass authentication and gain administrator access — then chain to root. It was exploited in the wild and is in CISA KEV. Here's what to do, and how BreachRisk finds exposed interfaces.
CVE-2023-46805: Ivanti Connect Secure authentication bypass, actively exploited and chained to RCE
An authentication bypass in Ivanti Connect Secure and Policy Secure lets a remote attacker skip access checks — and paired with CVE-2024-21887 it became unauthenticated remote code execution, exploited at scale as a zero-day. Here's what to do, and how BreachRisk finds exposed appliances.
CVE-2023-22515: Atlassian Confluence broken access control, unauthenticated admin creation, actively exploited
A broken-access-control flaw in Confluence Data Center and Server lets a remote attacker create their own administrator account. It was a nation-state zero-day, it's a 9.8, and it's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed Confluence.
CVE-2023-20198: Cisco IOS XE Web UI unauthenticated admin account creation, mass-exploited
A flaw in the Cisco IOS XE Web UI lets an unauthenticated attacker create a privilege-15 account and take over the device. It's a perfect 10.0, it was mass-exploited across tens of thousands of routers and switches, and it's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed IOS XE.
CVE-2022-42475: Fortinet FortiOS SSL-VPN heap overflow, unauthenticated RCE exploited as a zero-day
A heap buffer overflow in the FortiOS SSL-VPN lets an unauthenticated attacker run code on the device. It scores 9.8, it's in CISA KEV, and it was exploited as a zero-day. Here's what to do, and how BreachRisk finds exposed FortiGates.
CVE-2022-40684: Fortinet FortiOS/FortiProxy authentication bypass, actively exploited
An authentication-bypass flaw in Fortinet FortiOS, FortiProxy, and FortiSwitchManager lets an unauthenticated attacker operate the administrative interface directly. It's in CISA KEV, tied to ransomware, and trivially reachable. Here's what to do, and how BreachRisk finds exposed appliances.
CVE-2022-39952: Fortinet FortiNAC unauthenticated remote code execution
A file-path control flaw in Fortinet FortiNAC lets an unauthenticated attacker write files and execute code on the appliance. It scores 9.8 and has a public exploit. Here's what to do, and how BreachRisk finds exposed FortiNAC.
CVE-2022-22965 (Spring4Shell): Spring Framework RCE on Tomcat WAR deployments, actively exploited
Spring4Shell lets an unauthenticated attacker execute code against Spring MVC/WebFlux apps on JDK 9+ deployed as a WAR on Tomcat. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed Spring apps.
CVE-2022-0028: Palo Alto PAN-OS URL-filtering misconfiguration enabling reflected DoS
A URL-filtering policy misconfiguration can let an attacker abuse a PAN-OS firewall as a reflector for amplified TCP denial-of-service attacks against a target of their choosing. It's in CISA KEV. Here's the real picture, and how BreachRisk finds exposed devices.
CVE-2021-44529: Ivanti EPM Cloud Services Appliance code injection, unauthenticated RCE
A code-injection flaw in the Ivanti EPM Cloud Services Appliance lets an unauthenticated attacker run code on the internet-facing gateway. It's in CISA's KEV catalog and tied to ransomware. Here's what to do, and how BreachRisk finds exposed appliances.
CVE-2021-31207: Microsoft Exchange ProxyShell Vulnerability (CVE-2021-34473) Exploitation
Attempt to gain access to emails, sensitive files and internal network using a combination of Microsoft Exchange vulnerabilities.
CVE-2021-1585: Cisco ASDM Launcher code execution via man-in-the-middle
A signature-verification flaw in the Cisco ASDM Launcher lets a network attacker in a man-in-the-middle position run code on an administrator's machine. It targets the admin's client, not the appliance, and needs a privileged network position. Here's the honest severity, and how BreachRisk finds exposed ASDM.
CVE-2020-3452: Cisco ASA/FTD web-services path traversal, unauthenticated file read
A path-traversal flaw in the web services of Cisco ASA and Firepower Threat Defense lets an unauthenticated attacker read files from the appliance. It's read-only and bounded — but it's mass-scanned and in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed devices.
CVE-2020-2021: Palo Alto PAN-OS SAML authentication bypass, in CISA KEV
When SAML is enabled and certificate validation is turned off, a PAN-OS device can be tricked into accepting a forged assertion — bypassing authentication. It scores a 10.0 but depends on a specific misconfiguration. Here's the real picture, and how BreachRisk finds exposed devices.
CVE-2020-14181: Atlassian Jira user enumeration, unauthenticated
A low-impact flaw in Jira Server and Data Center lets an unauthenticated visitor enumerate valid usernames via the ViewUserHover endpoint. Harmless alone, but it feeds password spraying. Here's the honest severity, and how BreachRisk finds exposed Jira.
CVE-2020-14179: Atlassian Jira information disclosure, unauthenticated field enumeration
A low-impact information-disclosure flaw in Jira Server and Data Center lets an unauthenticated visitor view custom field and SLA names. It's not a breach on its own, but it's useful reconnaissance. Here's the honest severity, and how BreachRisk finds exposed Jira.
CVE-2019-3396: Atlassian Confluence Widget Connector template injection, unauthenticated RCE
A server-side template injection flaw in the Confluence Widget Connector macro lets an unauthenticated attacker read files and run code on the server. It's a 9.8, it's in CISA's KEV catalog, and it was used to deliver ransomware. Here's what to do, and how BreachRisk finds exposed Confluence.
CVE-2018-13379: Fortinet FortiOS SSL VPN pre-auth file read, still exploited years on
A path-traversal flaw in the FortiOS SSL VPN lets an unauthenticated attacker read system files — including session data with plaintext VPN credentials. It's in CISA KEV and still being exploited years after the fix. Here's what to do, and how BreachRisk finds exposed FortiGates.
CVE-2025-2825: CrushFTP Authentication Bypass Vulnerability Exploitation (CVE-2025-2825)
A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, b…
CVE-2025-2825: CrushFTP Authentication Bypass Vulnerability Exploitation (CVE-2025-2825)
CrushFTP versions 10.0.0 through 10.8.3 and 11.0.0 through 11.3.0 are affected by a vulnerability that may result in unauthenticated access. Remote and unauthenticated HTTP requests to CrushFTP may allow attackers to gai…
Exposed Citrix VPN logins and password spraying
A Citrix VPN login on the public internet is a high-value target for password spraying, and one weak credential can hand an attacker a foothold inside your network. Here's the risk — and how BreachRisk safely tests whether those logins hold.
Exposed Cisco TelePresence logins and password spraying
A Cisco TelePresence login on the public internet is a standing target for password spraying, and one weak or reused credential can expose your conferencing systems and the meetings they carry. Here's the risk — and how BreachRisk safely tests whether those logins hold.
Exposed Cisco Systems logins and password spraying
A Cisco Systems login on the public internet is a standing target for password spraying, and one weak or reused credential turns that exposure into a foothold on your network gear. Here's the risk — and how BreachRisk safely tests whether those logins hold.
Exposed Cisco ServiceGrid logins and password spraying
A Cisco ServiceGrid login on the public internet is a standing target for password spraying, and one weak or reused credential can expose the service data and integrations it brokers. Here's the risk — and how BreachRisk safely tests whether those logins hold.
Exposed Cisco SD-WAN Manager logins and password spraying
A Cisco SD-WAN Manager login on the public internet is a standing target for password spraying, and one weak or reused credential can hand over the controller for your entire WAN fabric. Here's the risk — and how BreachRisk safely tests whether those logins hold.
Exposed Cisco Prime Infrastructure logins and password spraying
A Cisco Prime Infrastructure login on the public internet is a standing target for password spraying, and one weak or reused credential can hand over the platform that manages your network devices. Here's the risk — and how BreachRisk safely tests whether those logins hold.
Exposed Cisco Meraki management logins and password spraying
A Cisco Meraki management panel on the public internet is a standing target for password spraying, and one weak or reused credential turns that exposure into control of network devices. Here's the risk — and how BreachRisk safely tests whether those logins hold.
Exposed Cisco IOS XE web logins and password spraying
A Cisco IOS XE web interface on the public internet is a standing target for password spraying, and one weak or reused credential turns that exposure into access to the device that runs your network. Here's the risk — and how BreachRisk safely tests whether those logins hold.
Exposed Cisco ASA VPN logins and password spraying
A Cisco ASA VPN portal on the public internet is a standing target for password spraying, and one weak or reused credential turns that exposure into remote access to your network. Here's the risk — and how BreachRisk safely tests whether those logins hold.
Exposed Centricity PLL portal logins and password spraying
A Centricity permitting-and-licensing portal on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into access to sensitive citizen and permit records. Here's the risk — and how BreachRisk safely tests whether those logins hold.
Exposed BOSSDesk help-desk logins and password spraying
A BOSSDesk help-desk login on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into access to sensitive support data. Here's the risk — and how BreachRisk safely tests whether those logins hold.
Exposed Atlassian Jira logins and password spraying
A Jira login on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into access to your projects, tickets, and the sensitive detail they hold. Here's the risk, and how BreachRisk safely tests whether that login holds.
CVE-2025-24893: XWiki unauthenticated RCE via SolrSearch, actively exploited
A code-injection flaw in XWiki's SolrSearch lets any guest run code on the server with a single unauthenticated request. It's a 9.8, it's in CISA KEV, and EPSS is near the ceiling. Here's what to do, and how BreachRisk finds and safely confirms exposed XWiki.