Progress, Check Point, and Microsoft Flaws Actively Exploited
Progress LoadMaster and Check Point SmartConsole vulnerabilities are actively exploited, alongside WinRAR flaws linked to Ukraine attacks. Microsoft Exchange and OMI flaws also added to KEV.

A critical command injection vulnerability in Progress ADC Products' LoadMaster appliance, CVE-2026-8037, is being actively exploited in the wild. This flaw allows unauthenticated attackers to execute arbitrary commands on the appliance by exploiting unsanitized input in multiple command endpoints. CISA has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, urging immediate patching. The exploitability of this vulnerability has been highlighted by numerous security news outlets, including Cyber Security News and The Hacker News.
Check Point's SmartConsole login process is affected by CVE-2026-16232, a critical authentication bypass vulnerability. This flaw enables unauthenticated remote attackers to obtain an application login token, which can then be used to authenticate with full administrative privileges. A public Proof of Concept (PoC) has been released, and the vulnerability is being actively exploited, as reported by Cyber Security News and BleepingComputer. Rapid7 has provided a detailed technical analysis of this vulnerability.
CVE-2025-8088, a path traversal vulnerability in the Windows version of WinRAR, is being exploited in the wild, allowing attackers to execute arbitrary code by crafting malicious archive files. This vulnerability has been linked to the STOCKSTAY backdoor, which is being used by Russia-linked threat actors like Turla and Gamaredon to target Ukraine. Cyber Security News and SecurityWeek have reported on its use in ongoing cyberattacks.
Microsoft's Known Exploited Vulnerabilities (KEV) catalog has seen significant additions, including several critical vulnerabilities affecting Microsoft Exchange Server (CVE-2021-34473, CVE-2021-34523) and Open Management Infrastructure (CVE-2021-38647). These vulnerabilities allow for remote code execution and elevation of privilege, respectively. Additionally, a Windows Print Spooler vulnerability (CVE-2021-34527) enabling SYSTEM-level code execution and an MSHTML remote code execution flaw (CVE-2021-40444) are also on the KEV list, indicating active exploitation. Other Microsoft vulnerabilities added include privilege escalation flaws in the LSA (CVE-2021-36942) and the Common Log File System Driver (CVE-2021-36955), along with an information disclosure vulnerability in Exchange Server (CVE-2021-33766).
Critical vulnerabilities have been identified in WatchGuard Fireware OS, specifically CVE-2025-9242 and CVE-2025-14733. These out-of-bounds write vulnerabilities within the iked process could allow remote, unauthenticated attackers to execute arbitrary code. Both mobile user VPNs using IKEv2 and branch office VPNs are affected by these flaws, underscoring the potential impact on network security infrastructure.
Rejetto HTTP File Server (up to v2.3m) is vulnerable to CVE-2024-23692, a critical template injection flaw that allows unauthenticated, remote attackers to execute arbitrary commands on the affected system. This vulnerability poses a significant risk to systems running this file server software.
Siemens SIMATIC IoT2050 Advanced devices with Node-RED installed are affected by CVE-2026-58115, a critical vulnerability where authentication is not enforced on the Node-RED HTTP interface. This could allow unauthorized access and potential compromise of the affected devices.
Metabase is vulnerable to CVE-2026-72899, a critical SQL injection flaw that can be exploited by unauthenticated attackers through publicly shared cards or dashboards with exposed field-filter parameters. This could lead to unauthorized access and manipulation of sensitive data.
SAP NetWeaver Visual Composer Metadata Uploader is affected by CVE-2025-42999, a critical vulnerability that could lead to a compromise of confidentiality, integrity, and availability if a privileged user uploads malicious content that is then deserialized.