WIRE OPENINGEST 08:30ZTODAY 23 new · 368,591 updatedKEV 1,695 · catalog 2026.09.06EPSS refreshed 07:42ZLAG 6m
The wire···
Top of the wire

PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect

🚨 An unauthenticated attacker can run arbitrary code on your firewall like it’s a playground swing! This command injection vulnerability in Palo Alto Networks PAN-OS is a serious threat—time to take action! 🔥 Think of your firewall as a high-security vault. If a crafty thief finds a way to create a new key (by exploiting this command injection), they could waltz right in and access everything inside—a nightmare for your digital assets! An attacker can execute any code as a root user on the firewall, potentially leading to a complete compromise of your network’s security. This could mean unauthorized access to sensitive data, manipulation of configurations, and even full control over your network. The implications are absolutely devastating!

CVSS
10
EPSS
100%
In the wild
Confirmed
Actively exploited · ranked by exploitation evidence
10.0cvss
CVE-2024-3400

PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect

🚨 An unauthenticated attacker can run arbitrary code on your firewall like it’s a playground swing! This command injection vulnerability in Palo Alto Networks PAN-OS is a serious threat—time to take action! 🔥 Think of your firewall as a high-security vault. If a crafty thief finds a way to create a new key (by exploiting this command injection), they could waltz right in and access everything inside—a nightmare for your digital assets! An attacker can execute any code as a root user on the firewall, potentially leading to a complete compromise of your network’s security. This could mean unauthorized access to sensitive data, manipulation of configurations, and even full control over your network. The implications are absolutely devastating!

KEV · OVERDUECRITICAL
100%
epss
8.2cvss
CVE-2024-21893

Ivanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) Vulnerability

🚨 An attacker only needs to craft a specific request to gain unauthorized access to restricted resources in Ivanti Connect Secure and Policy Secure! ⚡ Think of it like a sneaky delivery person who knows how to trick the receptionist into handing over the keys to the restricted areas of a building, bypassing the security checks entirely. An attacker can exploit this vulnerability to access sensitive information or restricted resources without ever needing to authenticate, exposing critical data to unauthorized users. The potential for data breaches and unauthorized actions can lead to devastating consequences for your organization.

KEV · OVERDUEHIGH
100%
epss
9.8cvss
CVE-2024-23897

Jenkins Command Line Interface (CLI) Path Traversal Vulnerability

🚨 An unauthenticated user can read ANY file on your Jenkins server just by sending a crafty command! This vulnerability is absolutely devastating! 🔥 Think of Jenkins like a bustling library where anyone can borrow a book without showing ID. Now imagine someone discovers a loophole that lets them read any book on the shelf, including all the secret documents hidden away in the archives—yikes! An attacker could easily exploit this flaw to access sensitive configuration files, user data, and even secrets that should remain locked away. This could lead to unauthorized access to your systems, exposing critical information and putting your entire infrastructure at risk—definitely not the kind of thing you want!

KEV · OVERDUECRITICAL
100%
epss
9.1cvss
CVE-2024-21887

Ivanti Connect Secure and Policy Secure Command Injection Vulnerability

🚨 An authenticated admin can launch a command injection attack with just a specially crafted request! This vulnerability in Ivanti Connect Secure and Ivanti Policy Secure is like leaving a trusted staff member the key to the safe — but it turns out the safe has a hidden trapdoor! 🔥 Think of it like a hotel concierge who can not only check you into your room but also has access to the entire building's security system. If that concierge (the authenticated admin) is given a magic password (the crafted request), they could open any door, even the ones that should be off-limits. This critical vulnerability allows an attacker to execute arbitrary commands on the appliance, potentially leading to complete control over sensitive configurations. The stakes are high: attackers could steal data, manipulate security settings, or shut down services. In the wrong hands, this could spell absolute disaster for the organization!

KEV · OVERDUECRITICAL
100%
epss
10.0cvss
CVE-2023-22518

Atlassian Confluence Data Center and Server Improper Authorization Vulnerability

🚨 An unauthenticated attacker can reset your Confluence instance and create an admin account — that’s like letting a stranger into your office and handing them the keys! 🔥 Think of it like leaving the front door of your office unlocked while you’re out. If someone just waltzes in, they could grab the office keys and access everything inside, including sensitive documents and confidential conversations. With this vulnerability, the attacker could gain complete control over your Confluence instance, leading to total loss of confidentiality, integrity, and availability. Imagine the chaos: unauthorized access to sensitive information, unexplained changes to documents, and even system downtime. Your data would be at the mercy of an intruder!

KEV · OVERDUECRITICAL
100%
epss
9.4cvss
CVE-2023-4966

Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability

🚨 Sensitive data could spill out like a secret recipe gone rogue! The misconfiguration in NetScaler ADC and Gateway allows attackers to snag sensitive info under certain conditions. 🔥 Think of it as a hotel that accidentally leaves its guest list out in the lobby—anyone could see the VIPs and their room numbers. This vulnerability lets attackers peek at sensitive information that should stay private, similar to a misplaced guest register. This could lead to devastating consequences, such as unauthorized access to confidential user information, credentials, or sensitive corporate data. Attackers exploiting this vulnerability might infiltrate your network, exposing your organization to severe risks and potential data breaches.

KEV · OVERDUECRITICAL
100%
epss
7.5cvss
CVE-2023-44487

HTTP/2 Rapid Reset Attack Vulnerability

🚨 A crafty request cancellation can lead to a server resource drain faster than you can say "HTTP/2!" ⚡️ Think of it like a chaotic restaurant where customers keep canceling their orders at the last minute — the kitchen gets swamped trying to process new requests while still juggling the old ones, leading to a complete standstill! If an attacker exploits this vulnerability, they could quickly overwhelm your server, causing significant downtime and service interruptions. This could lead to all sorts of chaos, from frustrated users to potential revenue loss as your site becomes inaccessible. It's a situation you definitely want to avoid!

KEV · OVERDUEHIGH
100%
epss
10.0cvss
CVE-2023-35082

Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass Vulnerability

🚨 An authentication bypass is lurking in Ivanti EPMM 11.10 and older! This flaw lets unauthorized users access sensitive parts of the application like a VIP crashing a private party. 🔥 Think of it like a concert where someone sneaks in through the backstage door. They can wander around areas meant only for performers, potentially causing chaos without a ticket or permission! This vulnerability could lead to unauthorized access to critical functionalities within the application. Imagine an intruder being able to change settings, access sensitive data, or even manipulate user accounts without anyone knowing—absolutely devastating!

KEV · OVERDUECRITICAL
100%
epss