PROJECT

CTI-AI

CTI Workbench

LIVE OPERATIONS

CVE & Vulnerability Intelligence Center

CISA KEV & MANDIANT RADAR

Real-Time Exploited Vulnerability Matrix • Affected Servers, Target Components, Risk Scores & Multi-SIEM Queries

← Back to Workbench
Total Tracked CVEs8
🚨 CISA KEV Exploited7
🔥 Critical CVSS 9.0+7
📈 High EPSS (>80%)6
Executive Environmental Telemetry Scanner (Beyond CVE IDs)Application, Service & Port Pivot Engine
Scans 100% of internal endpoints by service fingerprint & listening port

Executive Defense Strategy: CVE-only scanners miss zero-day variants and unauthenticated endpoints. Use the quick-chips below to instantly scan your enterprise telemetry by Application / Service, Host Group / Server Name, or Target Port.

Quick Application Filters:
#CVE ID & Vulnerability TitleRisk ScoresAffected System / Server NameTarget Component & PortAttributed Threat ActorsCISA KEV / Patch DeadlineSIEM Rule
1
CVE-2024-27198JetBrains
JetBrains TeamCity Web Server Authentication Bypass & Remote Code Execution
CVSS 9.8EPSS 96.4%
TeamCity CI/CD Build ServerTeamCity On-Premises < 2023.11.4
Web Controller REST Dispatcher (/app/rest/users)Port: 8111 / 443 (Java/Tomcat)
Lazarus GroupUNC6671 (BlackFile)BianLian Ransomware
CISA KEVDue: 2026-03-25
2
CVE-2025-5777Citrix
Citrix NetScaler ADC & Gateway Memory Overread (CitrixBleed2)
CVSS 9.4EPSS 91.2%
Citrix NetScaler Appliance GatewayCitrix NetScaler ADC & Gateway 13.1, 14.1
AAA Authentication Module (/oauth/idp/logout)Port: 443 (FreeBSD Kernel)
DragonForce RansomwareInitial Access Brokers (IABs)
CISA KEVDue: 2026-07-25
3
CVE-2025-3248Langflow
Langflow AI Framework Unauthenticated Remote Code Execution
CVSS 9.8EPSS 88.5%
Langflow AI Graph OrchestratorLangflow AI Engine <= v1.2.4
Custom Component Exec Endpoint (/api/v1/custom_component)Port: 7860 (Python/FastAPI)
JadePuffer AI AgentStorm-1988
CISA KEVDue: 2026-08-15
4
CVE-2024-3400Palo Alto Networks
Palo Alto Networks PAN-OS OS Command Injection
CVSS 10EPSS 97.4%
GlobalProtect Firewall GatewayPAN-OS 10.2, 11.0, 11.1 GlobalProtect Gateways
GlobalProtect Session Management (pan_cmd)Port: 443 (PAN-OS Linux Kernel)
UTA0218State-Sponsored Espionage
CISA KEVDue: 2026-04-19
5
CVE-2023-34362Progress Software
Progress MOVEit Transfer SQL Injection Remote Code Execution
CVSS 9.8EPSS 96.8%
MOVEit Transfer Web Application ServerMOVEit Transfer all versions before 2023.0.1
MOVEit.DMZ.WebApp (/moveitisapi/moveitisapi.dll)Port: 80 / 443 (Windows IIS)
CL0P Ransomware (TA505)
CISA KEVDue: 2026-06-15
6
CVE-2026-46817Oracle
Oracle WebLogic Server Remote Command Execution
CVSS 9.8EPSS 82.4%
Oracle WebLogic App ServerWebLogic Server 12.2.1.4, 14.1.1.0
T3 / IIOP Protocol ListenerPort: 7001 (Java RMI)
UNC6671 (BlackFile)FIN7
CISA KEVDue: 2026-08-30
7
CVE-2026-55200LibSSH2
LibSSH2 Channel Request Memory Corruption
CVSS 8.8EPSS 64.5%
Linux / macOS Developer EndpointsLibSSH2 <= v1.11.0
SSH Channel Request Handler (libssh2_channel_process_startup)Port: 22 (C Library)
Lazarus GroupUNC6671
Unlisted in KEV
8
CVE-2026-2910Microsoft
Microsoft Entra ID OAuth Administrative Scope Escalation
CVSS 9.1EPSS 78.9%
Microsoft Entra ID Cloud IdentityEntra ID / Azure AD OAuth Consent Workflows
Graph API Multi-Tenant OAuth Handler (/oauth2/v2.0/authorize)Port: 443 (Cloud API)
ShinyHuntersStorm-0875
CISA KEVDue: 2026-08-20
LIVE OSINT FEED
[--:--:--]RansomHub infrastructure detected actively scanning public repositories for secrets.[--:--:--]New leak: 14k internal developer credentials tied to corporate git repos posted on BreachForums.[--:--:--]OSINT Warning: Known ShinyHunters OAuth app redirect domains resurfacing via dynamic DNS.[--:--:--]Active exploit attempting to abuse Salesforce Experience Cloud Aura endpoints detected on multiple enterprise portals.[--:--:--]AI Security Alert: Abnormal volume of OpenAI API token requests from hijacked cloud GPU instances.[--:--:--]Threat group UNC6780 (Team PCP) observed pushing poisoned NPM package updates.[--:--:--]GitHub Breach Alert: Actor selling access to compromised corporate developer repositories.[--:--:--]RansomHub infrastructure detected actively scanning public repositories for secrets.[--:--:--]New leak: 14k internal developer credentials tied to corporate git repos posted on BreachForums.[--:--:--]OSINT Warning: Known ShinyHunters OAuth app redirect domains resurfacing via dynamic DNS.[--:--:--]Active exploit attempting to abuse Salesforce Experience Cloud Aura endpoints detected on multiple enterprise portals.[--:--:--]AI Security Alert: Abnormal volume of OpenAI API token requests from hijacked cloud GPU instances.[--:--:--]Threat group UNC6780 (Team PCP) observed pushing poisoned NPM package updates.[--:--:--]GitHub Breach Alert: Actor selling access to compromised corporate developer repositories.[--:--:--]RansomHub infrastructure detected actively scanning public repositories for secrets.[--:--:--]New leak: 14k internal developer credentials tied to corporate git repos posted on BreachForums.[--:--:--]OSINT Warning: Known ShinyHunters OAuth app redirect domains resurfacing via dynamic DNS.[--:--:--]Active exploit attempting to abuse Salesforce Experience Cloud Aura endpoints detected on multiple enterprise portals.[--:--:--]AI Security Alert: Abnormal volume of OpenAI API token requests from hijacked cloud GPU instances.[--:--:--]Threat group UNC6780 (Team PCP) observed pushing poisoned NPM package updates.[--:--:--]GitHub Breach Alert: Actor selling access to compromised corporate developer repositories.