Threat intel
// cisa.kev_feedTwo live feeds for defenders. Up top: CISA's Known Exploited Vulnerabilities catalog — CVEs with confirmed active exploitation. Below: abuse.ch ThreatFox — fresh IOCs (C2 IPs, malicious URLs, payload hashes) tied to named malware families. Click any row to open the source entry.
- CVE-2026-7273·Zyxel / GS1900 Series Switches
Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability
Zyxel GS1900 series switches contain a stack-based buffer overflow vulnerability in the CGI program which could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.
added 2026-09-21 · due 2026-09-24 · CWE-121
- CVE-2025-39964·Linux / Kernel
Linux Kernel Race Condition Vulnerability
Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state.
added 2026-09-18 · due 2026-09-21 · CWE-362
- CVE-2026-53266·Linux / Kernel
Linux Kernel Out-of-Bounds Write Vulnerability
Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.
added 2026-09-18 · due 2026-09-21 · CWE-787
- CVE-2025-39682·Linux / Kernel
Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability
Linux Kernel contains an improper check for unusual or exceptional conditions vulnerability in the TLS receive path which allows a zero-length record retrieved from the rx_list to bypass the intended recvmsg() record-type handling, potentially causing subsequent TLS records to be processed using incorrect zero-copy and queuing assumptions. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.
added 2026-09-18 · due 2026-09-21 · CWE-754
- CVE-2026-58704·Google / Pixel
Google Pixel Improper Authorization Vulnerability
Google Pixel devices contain an improper authorization vulnerability in the cellular modem. A logic error may allow an attacker to bypass permission checks and escalate privileges.
added 2026-09-16 · due 2026-09-19 · CWE-693
- CVE-2026-76460·Cisco / Identity Services Engine
Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability
Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.
added 2026-09-16 · due 2026-09-19 · CWE-648
- CVE-2026-87886·Acronis / Backup
Acronis Backup Incorrect Default Permissions Vulnerability
Acronis Backup plugin for cPanel & WHM and extension for Plesk contains an incorrect default permissions vulnerability that could allow for privilege escalation.
added 2026-09-16 · due 2026-09-19 · CWE-276
- CVE-2026-76461·Cisco / Secure Email Gateway
Cisco Secure Email Gateway SQL Injection Vulnerability
Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.
added 2026-09-14 · due 2026-09-17 · CWE-89
- CVE-2026-84869·ConnectWise / ScreenConnect
ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to transfer and execute files through an active remote session without authorization or host confirmation.
added 2026-09-11 · due 2026-09-14 · CWE-269, CWE-862
- CVE-2026-42016·JFrog / Artifactory
JFrog Artifactory Incorrect Authorization Vulnerability
JFrog Artifactory contains an incorrect authorization vulnerability that leads to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.
added 2026-09-11 · due 2026-09-25 · CWE-863
Recent IOCs
// abuse_ch.threatfox- domainimpact.hjdeboer.com
FAKEUPDATES · Indicator that identifies a botnet command&control server (C&C)
first seen 2026-09-21 17:10 UTC · confidence 100% · monitorsg
- ip:port109.74.195.111:22
Cobalt Strike · Indicator that identifies a botnet command&control server (C&C)
first seen 2026-09-21 17:05 UTC · confidence 100% · anonymous
- ip:port101.201.109.2:8080
AdaptixC2 · Indicator that identifies a botnet command&control server (C&C)
first seen 2026-09-21 17:05 UTC · confidence 100% · anonymous
- ip:port60.205.223.45:8088
Cobalt Strike · Indicator that identifies a botnet command&control server (C&C)
first seen 2026-09-21 17:05 UTC · confidence 100% · anonymous
- ip:port101.201.109.2:80
AdaptixC2 · Indicator that identifies a botnet command&control server (C&C)
first seen 2026-09-21 17:05 UTC · confidence 100% · anonymous
- ip:port101.201.109.2:443
AdaptixC2 · Indicator that identifies a botnet command&control server (C&C)
first seen 2026-09-21 17:05 UTC · confidence 100% · anonymous
- domain5qflb4vy.usa--lipogummy.com
ClearFake · Indicator that identifies a malware distribution server (payload delivery)
first seen 2026-09-21 17:04 UTC · confidence 100% · anonymous
- domaindome.beatdropkec.com
ClearFake · Indicator that identifies a botnet command&control server (C&C)
first seen 2026-09-21 17:01 UTC · confidence 100% · penislandrocket
- ip:port128.90.103.184:2015
Remcos · Indicator that identifies a botnet command&control server (C&C)
first seen 2026-09-21 16:42 UTC · confidence 100% · Bitsight
- sha2564701f196c74af42b5ced01592bf4a74d54437b1c63b8aabfe1f92e9beabec769
AMOS · Indicator that identifies a malware sample (payload)
first seen 2026-09-21 16:40 UTC · confidence 100% · c4ffeine