Threat Library
A continuously updated catalog of the credential, misconfiguration, and vulnerability threats BreachRisk tests for — with plain-spoken write-ups of what each one is and how we verify it.
Just added.
CVE-2026-15410: SonicWall SMA1000 command injection, actively exploited
CVE-2026-35273: Oracle PeopleSoft PeopleTools unauthenticated RCE, exploited as a zero-day
CVE-2026-44277: Fortinet FortiAuthenticator improper access control, patched before exploitation
CVE-2026-34909: Ubiquiti UniFi OS path traversal, actively exploited
CVE-2026-22557: Ubiquiti UniFi Network Application path traversal
CVE-2024-21182: Oracle WebLogic unauthenticated data exposure via T3/IIOP, exploited
Search by type or date.
352 threats
CVE-2026-15410: SonicWall SMA1000 command injection, actively exploited
A post-authentication command-injection flaw in SonicWall's SMA1000 access appliances is being exploited in the wild, chained with a companion bug. Here's what you need to know — and how BreachRisk surfaces exposed appliances.
CVE-2026-35273: Oracle PeopleSoft PeopleTools unauthenticated RCE, exploited as a zero-day
A missing-authentication flaw in PeopleSoft PeopleTools' Environment Management component lets an unauthenticated attacker take over the server — exploited as a zero-day by an extortion group against 100+ organizations. It's in CISA's KEV catalog. Here's the risk, and how BreachRisk finds and safely confirms exposed PeopleSoft.
CVE-2024-21182: Oracle WebLogic unauthenticated data exposure via T3/IIOP, exploited
A flaw in Oracle WebLogic's core lets an unauthenticated attacker reach critical data over the T3 and IIOP protocols — now in CISA's KEV catalog on evidence of active exploitation. Here's the risk, and how BreachRisk finds exposed WebLogic.
CVE-2026-22557: Ubiquiti UniFi Network Application path traversal
A path-traversal flaw in the UniFi Network Application lets an actor with network access read files off the system, which can be leveraged toward account access. A fix exists; here's the honest severity, and how BreachRisk finds exposed controllers.
CVE-2026-34909: Ubiquiti UniFi OS path traversal, actively exploited
A path-traversal flaw in UniFi OS devices lets an unauthenticated attacker reach internal handlers and read files that lead to account access. It's in CISA's KEV catalog with active exploitation. Here's what to do, and how BreachRisk finds exposed devices.
CVE-2026-44277: Fortinet FortiAuthenticator improper access control, patched before exploitation
An improper-access-control flaw in Fortinet FortiAuthenticator could let an unauthenticated attacker reach protected API functionality. It was found internally and patched, with no known exploitation yet. Here's a level-headed read, and how BreachRisk finds exposed FortiAuthenticator.
CVE-2025-53020: Apache HTTP Server memory-leak denial of service
A memory-management flaw in Apache HTTP Server can be pushed toward denial of service — availability only, not code execution, and not known to be exploited. Here's the honest read, and how BreachRisk finds affected servers.
CVE-2026-28318: SolarWinds Serv-U unauthenticated denial-of-service, KEV-listed
A crafted request can crash SolarWinds Serv-U without authentication, taking file transfer offline. It's in CISA's KEV catalog. The impact is availability, not data loss — here's the honest read, and how BreachRisk flags exposed servers.
CVE-2023-38646: Metabase pre-authentication remote code execution
A flaw in Metabase lets an unauthenticated attacker run arbitrary commands on the server at its privilege level. It was widely exploited after a public proof-of-concept. Here's what to do, and how BreachRisk finds exposed Metabase.
CVE-2024-39930: Gogs built-in SSH server argument injection leads to RCE
An argument-injection flaw in the built-in SSH server of Gogs lets an authenticated user run commands on the host. A fix is available. Here's the risk, and how BreachRisk finds exposed Gogs instances.
CVE-2024-39932: Gogs argument-injection flaws in change preview and release tagging
Two argument-injection flaws in Gogs let an authenticated user smuggle Git options into server-side commands — one during change previews, one during release tagging. Here's the risk, and how BreachRisk finds exposed Gogs instances.
CVE-2025-8110: Gogs symlink path traversal leads to code execution, in CISA KEV
Improper symbolic-link handling in Gogs' PutContents API lets an authenticated user traverse outside the repo and reach code execution. It's in CISA KEV. Here's what to do, and how BreachRisk finds exposed instances.
CVE-2026-22679: Weaver (Fanwei) E-cology unauthenticated RCE via exposed debug endpoint, exploited in the wild
A missing-authentication flaw in Weaver E-cology exposes a debug endpoint that lets an unauthenticated attacker run OS commands — a 9.8 with confirmed in-the-wild exploitation. Here's what to do, and how BreachRisk finds exposed servers.
CVE-2026-26194: Gogs release-deletion argument injection
An argument-injection flaw in Gogs' release-deletion handling lets a low-privileged user smuggle Git options via a crafted tag name. A fix is out in 0.14.2. Here's the risk, and how BreachRisk finds exposed Gogs instances.
CVE-2026-26980: Ghost CMS unauthenticated SQL injection reads the database
A SQL injection flaw in Ghost CMS lets an unauthenticated attacker read arbitrary data straight from the database. A fix is out in 6.19.1. Here's the risk, and how BreachRisk finds exposed Ghost sites.
CVE-2026-45659: Microsoft SharePoint Server authenticated deserialization RCE, in CISA KEV
A deserialization flaw in on-premises SharePoint Server lets an authenticated attacker run code over the network. It's an 8.8 and it's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed SharePoint.
CVE-2021-44026: Roundcube Webmail SQL injection, exploited by state-linked actors
A SQL injection in Roundcube's search handling lets an authenticated user reach the mail database. It's in CISA's KEV catalog and tied to espionage against webmail servers. Here's the risk, and how BreachRisk finds exposed Roundcube instances.
CVE-2023-43770: Roundcube Webmail cross-site scripting, used for credential theft
A cross-site scripting flaw in how Roundcube renders links in plaintext email lets an attacker run script in a victim's session. It's in CISA's KEV catalog. Here's the risk, and how BreachRisk finds exposed Roundcube instances.
CVE-2024-42009: Roundcube Webmail cross-site scripting that can steal and send a victim's email
A cross-site scripting flaw in Roundcube's message rendering lets a crafted email read, exfiltrate, and send mail as the victim. It's in CISA's KEV catalog and scored 9.3. Here's the risk, and how BreachRisk finds exposed Roundcube instances.
CVE-2026-0257: Palo Alto PAN-OS GlobalProtect authentication bypass, actively exploited
An authentication-bypass flaw in the PAN-OS GlobalProtect portal and gateway lets an attacker establish an unauthorized VPN connection. It's in CISA KEV with limited in-the-wild exploitation. Here's what to do, and how BreachRisk finds exposed portals.
CVE-2026-0300: Palo Alto PAN-OS User-ID Authentication Portal unauthenticated RCE, root-level
A buffer overflow in the PAN-OS User-ID Authentication Portal lets an unauthenticated attacker run code as root by sending crafted packets. It's in CISA KEV with in-the-wild exploitation. Here's what to do, and how BreachRisk finds exposed portals.
CVE-2024-3721: TBK DVR OS command injection, swept up by botnets
A command-injection flaw in TBK DVR video recorders lets attackers run OS commands on the device. A public exploit exists and these internet-facing recorders are routine botnet fodder. Here's the risk, and how BreachRisk finds exposed units.
CVE-2024-7399: Samsung MagicINFO 9 Server path traversal, actively exploited
A path-traversal flaw in Samsung MagicINFO 9 Server lets an unauthenticated attacker write files with system authority — a direct route to remote code execution. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed servers.
CVE-2025-2749: Kentico Xperience path traversal and file upload leading to RCE
A flaw in Kentico Xperience's Staging Sync Server lets an attacker write files to path-relative locations and reach remote code execution. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed Kentico.