See what’s actually being exploited right now.

Discover Live Exploit Tracker

VulnTracking

Explore key insights on emerging vulnerabilities and CVE exploitation trends, as spotted by the CrowdSec Network

CVE-2026-23744

CVE-2026-23744: Critical RCE in MCPJam Inspector Targeting Developers

CrowdSec detects a surge of exploitation attempts targeting CVE-2026-23744, a critical RCE vulnerability in MCPJam Inspector exposing AI development environments.

Matthieu Mazzolini
CVE-2025-20281: Critical Cisco ISE RCE Vulnerability Sees New Exploitation Wave

CVE-2025-20281: Critical Cisco ISE RCE Vulnerability Sees New Exploitation Wave

CVE-2025-20281 is a critical CVSS 10.0 RCE vulnerability in Cisco Identity Services Engine (ISE). CrowdSec observes a new surge of exploitation attempts targeting exposed REST APIs

Emanuel Seemann
CVE-2026-21859

CVE-2026-21859: Critical SSRF in Mailpit Exposes Internal Networks

CVE-2026-21859 is a critical SSRF vulnerability in Mailpit actively exploited in targeted attacks. Learn how it exposes internal networks.

Matthieu Mazzolini
CVE-2025-14528

CVE-2025-14528: Watch next week’s botnet being built on D-Link routers

CVE-2025-14528 is a vulnerability in EoL D-Link routers. Learn why and how it is used to build botnets.

Emanuel Seemann
CVE-2025-56520

Dify Under Attack: Unfixed CVE-2025-56520 Exploited in the Wild

CVE-2025-56520 is actively exploited in Dify, exposing AI platforms to SSRF-driven reconnaissance, internal scanning, and potential credential theft.

Matthieu Mazzolini
CVE-2026-1281

CVE-2026-1281: How a Single Flaw Can Compromise Entire Mobile Fleets

CVE-2026-1281 is an actively exploited RCE vulnerability in Ivanti EPMM. Learn how to detect, mitigate, and protect your infrastructure.

Emanuel Seemann
Zimbra Collaboration attack

Zimbra Collaboration Hit by Coordinated Attack Campaign

Mass exploitation targets Zimbra via new LFI (CVE-2025-68645) and persistent XSS flaws. Learn attack trends, risks, and how to protect.

Matthieu Mazzolini
CVE-2025-34291

CVE-2025-34291 Exploited in the Wild: LangFlow AI Framework Under Fire

CVE-2025-34291 is an actively exploited RCE vulnerability in LangFlow. Learn how to detect, mitigate, and protect your AI infrastructure.

Emanuel Seemann
CVE-2025-59287

CVE-2025-59287: When a Critical Windows Server RCE Turns Patches Into Malware

Critical WSUS RCE CVE-2025-59287 is under active exploitation. Learn how attackers target Windows update infrastructure and how to defend your systems.

Matthieu Mazzolini
CVE-2024-20767

CVE-2024-20767 Exploited in the Wild: Adobe ColdFusion Under Attack

CVE-2024-20767 is actively exploited in Adobe ColdFusion. CrowdSec observed a surge in attacks & explains impact, trends, & how to protect your systems.

Emanuel Seemann
CVE-2025-59718

Fortinet’s Early Christmas Gift to Attackers: SAML Authentication Bypass

Active exploitation targets CVE-2025-59718, a critical Fortinet auth bypass. See detection insights and mitigation steps.

Matthieu Mazzolini
React2Shell

React2Shell Now Among the Most Exploited Vulnerabilities Worldwide (Part 2)

React2Shell (CVE-2025-55182) attacks surged from 500 to 10K+ daily. Learn what changed, attacker trends, and how to protect with CrowdSec.

Emanuel Seemann
cve-2025-55182

React2Shell: The Frontend Vulnerability That Gives Attackers a Backend Pass

Learn about CVE-2025-55182, the React2Shell vulnerability that turns a frontend flaw into backend access. Discover its impact & how to protect your apps.

Matthieu Mazzolini
CVE-2025-64095

CVE-2025-64095: Ransomware-Style Defacement Attacks Likely as DNN Flaw is Probed

CVE-2025-64095 is being actively probed, allowing attackers to upload and overwrite files on DNN sites. CrowdSec intelligence reveals early exploitation trends.

Emanuel Seemann
CVE-2025-54236

CVE-2025-54236: SessionReaper Exploit Hits 130K+ Magento Stores in Massive Hijacking Wave

CVE-2025-54236 enables attackers to seize Magento sessions & escalate to RCE. See CrowdSec’s exploitation data, timeline, & protection guidance.

Matthieu Mazzolini
CVE-2025-64446

CVE-2025-64446: FortiWeb Zero-Day Under Active Exploitation

CVE-2025-64446 allows attackers to bypass authentication in FortiWeb. Deploy CrowdSec WAF to secure your systems.

Emanuel Seemann
CVE-2025-55748

CVE-2025-55748: Path Traversal in XWiki Sees Rising Exploitation Activity

CrowdSec detects rising exploitation of XWiki CVE-2025-55748, a path traversal flaw exposing sensitive configs, not yet in CISA KEV.

Matthieu Mazzolini
CVE-2025-54249

CVE-2025-54249: SSRF in Adobe Experience Manager Exposes Internal Services

CrowdSec detects active exploitation of CVE-2025-54249 in Adobe Experience Manager (AEM), an SSRF flaw exposing internal services.

Emanuel Seemann
vulntracking report september 2025

CrowdSec VulnTracking Report: September 2025

Discover key insights on emerging CVEs and exploitation attempts in the September edition of the CrowdSec VulnTracking Report.

Thibault Koechlin
crowdsec vulntracking report july 2025

CrowdSec VulnTracking Report: July 2025

Discover key insights on emerging CVEs and exploitation attempts in the July edition of the CrowdSec VulnTracking Report.

Thibault Koechlin
vulntracking june 2025

CrowdSec VulnTracking Report: June 2025

Discover key insights on emerging CVEs and exploitation attempts in the June edition of the CrowdSec VulnTracking Report.

Thibault Koechlin
crowdsec vulntracking report april 2025

CrowdSec VulnTracking Report: May 2025

Discover key insights on emerging CVEs and exploitation attempts in the May edition of the CrowdSec VulnTracking Report.

Thibault Koechlin
crowdsec vulntracking report april 2025

CrowdSec VulnTracking Report: April 2025

Discover key insights on emerging CVEs and exploitation attempts in the April edition of the CrowdSec VulnTracking Report.

Thibault Koechlin
crowdsec vulntracking report march 2025

CrowdSec VulnTracking Report: March 2025

We are excited to launch our latest series, the CrowdSec VulnTracking Reports. In these monthly reports, we will be exploring key insights on emerging vulnerabilities and CVE exploitation trends, as spotted by the CrowdSec Network. In March 2025, we added detection for 34 vulnerabilities and/or exploits to our database — translating into scenarios for the […]