May 29, 2026 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Palo Alto Networks PAN-OS added to CISA KEV — confirmed in-the-wild exploitation.
  • Wftpserver Wing Ftp Server: public exploit or PoC linked (RCE)
  • WordPress plugin RCE/exploit activity: 2 CVEs flagged today.
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2026-0257 Palo Alto Networks PAN-OS Authentication Bypass

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV
  • Authentication bypass — unauthenticated access risk

Palo Alto Networks PAN-OS Auth Bypass is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Active exploit activity

CVE-2026-0770 Langflow RCE

  • Public exploit or PoC available
  • Exploit activity linked
  • Remote code execution exposure

Langflow RCE now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Critical exposure

CVE-2026-45372 cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library.

  • CVSS 9.9

New critical disclosure (CVSS 9.9) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Palo Alto Networks PAN-OS Authentication Bypass

View KEV additions

Exploit & PoC activity

CVE-2026-46522 Exploit

ImageMagick is free and open-source software used for editing and manipulating digital images.

CVE-2026-44680 Exploit

MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns.

CVE-2026-46300 Exploit

In the Linux kernel, the following vulnerability has been resolved: net: skbuff: preserve shared-frag marker during coalescing skb_try_co...

CVE-2026-44403 Exploit

Wing FTP Server before 8.1.3 contains an authenticated remote code execution vulnerability in the session serialization mechanism that al...

CVE-2026-43500 Exploit

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Also unshare DATA/RESPONSE packets when paged frags are presen...

CVE-2026-43284 Exploit

In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGE...

CVE-2026-34473 Exploit

Unauthenticated DoS in ZTE H8102E, H168N, H167A, H199A, H288A, H198A, H267A, H267N, H268A, H388X, H196A, H369A, H268N, H208N, H367N, H181...

CVE-2026-34474 Exploit

Sensitive data exposure leading to admin/WLAN credential leak in ZTE ZXHN H298A 1.1 and H108N 2.6.

CVE-2026-42471 Exploit

Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17.

CVE-2026-32202 Exploit

Microsoft Windows Protection Mechanism Failure

CVE-2026-1830 Exploit

The Quick Playground plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.1.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2026-44649 CVSS 9.8

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generat...

CVE-2026-44650 CVSS 9.1

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generat...

CVE-2026-45372 CVSS 9.9

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library.

CVE-2026-45661 CVSS 9.9

Dokploy is a free, self-hostable Platform as a Service (PaaS).

CVE-2026-45668 CVSS 9.3

Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases.

CVE-2026-45697 CVSS 9.8

Formie is a Craft CMS plugin for creating forms.

CVE-2026-47744 CVSS 9.9

Shopper is a Headless e-commerce Admin Panel.

CVE-2026-5386 CVSS 9.1

The affected KMW CCTV Security Cameras are vulnerable to a critical unauthenticated password reset.

CVE-2026-7786 CVSS 9.8

Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter device firmware contains plaintext administrative...

CVE-2026-9051 CVSS 9.3

There is an authentication bypass vulnerability in the NI SystemLink Enterprise Dashboard application that may allow an unauthenticated r...

View critical disclosures

cvelogic Threat Intelligence