Vulnary
(the landscape)

The critical picture, at a glance.

What’s landing, who’s most exposed, and how dangerous it really is right now.

Spiking now

what’s blowing up
CVE-2026-16232Critical· 9.1

An authentication bypass in Check Point SmartConsole lets an attacker obtain an admin login token without credentials. The flaw can be exploited remotely to change security policies and configurations. It is rated critical due to its high impact and ease of exploitation.

  • added to CISA KEV
  • EPSS jumped +57 pts
  • 70% likely to be exploited
CVE-2026-10520Critical· 10

Ivanti Sentry software has a critical OS command injection flaw that lets anyone on the internet run commands as root. The vulnerability exists in versions before R10.5.2, R10.6.2, and R10.7.1. An attacker could take full control of the affected system.

  • added to CISA KEV
  • 100% likely to be exploited
CVE-2026-63030Critical· 9.8

A flaw in the WordPress REST API allows for route confusion, which can be combined with a separate SQL injection vulnerability. This combination allows an attacker to execute malicious commands on the server.

  • added to CISA KEV
  • 98% likely to be exploited
CVE-2026-20253Critical· 9.8

An unauthenticated attacker can create or delete any file on a Splunk Enterprise system by calling a PostgreSQL sidecar service that lacks authentication. The flaw exists in versions 10.2 and 10 before 10.2.4 and 10.0.7, respectively. Upgrading to a fixed release or disabling the sidecar service stops the attack.

  • added to CISA KEV
  • 96% likely to be exploited
CVE-2026-35273Critical· 9.8

Oracle PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62 contain a critical flaw that lets anyone on the network take full control of the system via HTTP. The vulnerability can expose, alter, or delete data and disrupt services. It is highly exploitable and requires immediate attention.

  • added to CISA KEV
  • 94% likely to be exploited
CVE-2026-39808Critical· 9.8

CVE-2026-39808 is a critical command injection vulnerability in Fortinet FortiSandbox 4.4.0–4.4.8, allowing attackers to execute unauthorized code via improperly neutralized OS commands. CISA KEV confirms exploitation risk, requiring immediate mitigation per vendor instructions or product discontinuation if fixes are unavailable.

  • added to CISA KEV
  • 90% likely to be exploited
0
critical tracked
0.0
average CVSS
0
known-exploited
0
with public exploit

New criticals over time

last 30 days
Jun 30, 2026Jul 30, 2026

Most-affected vendors

oracle
159
linux
143
apple
96
microsoft
95
google
73
mozilla
47
debian
26
apache
20

How likely to be exploited

EPSS
1358
<1%
106
1–10%
19
10–50%
22
50%+

Known-exploited rate

in CISA KEV
1%23 of 1541 are known-exploited