Known Exploited Vulnerabilities Catalog
For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source for vulnerabilities exploited in the wild. When these vulnerabilities impact services or applications on campus, we send an email to security professionals and post them here.
Critical Vulnerabilities in React and Next.js
A critical vulnerability has been identified in the React Server Components (RSC) "Flight" protocol, a core feature of the modern React 19 ecosystem. This flaw, tracked as CVE-2025-55182 (React) and impacting the popular framework Next.js, allows an attacker to achieve unauthenticated Remote Code Execution (RCE) on the server due to insecure deserialization. The vulnerability exists in the default configuration of affected applications, meaning standard deployments are immediately at risk.
CVE-2026-23550 Wordpress Modular DS flaw
ISO is aware of a critical vulnerability that affects the Modular DS WordPress plugin[1]. This vulnerability, CVE-2026-23550, allows unauthenticated users to gain Administrator privileges due to a flaw in the “direct request” mode of the plugin.
CVE-2025-14847 MongoDB
ISO is aware of a high severity vulnerability that affects MongoDB Server and is being actively exploited. The MongoDB vulnerability allows attackers to gain access to information in the program's memory without the need to authenticate.
Atlassian (Jira and Confluence) vulnerabilities - March 2026
ISO is aware of a vulnerability that affects Confluence Data Center and Server[2]. CVE-2025-64756 is a high-severity OS Command Injection vulnerability that allows an authenticated attacker to gain access and possibly execute arbitrary commands on the target system.
ISO is also aware of multiple high-severity vulnerabilities that affect Jira Data Center and Server. These vulnerabilities include path traversal, file overwrite, and denial of service. These vulnerabilities could allow an attacker to gain knowledge of file system layout, and potentially replace existing files or execute arbitrary files.
CVE-2026-31431 Linux Kernel Local Privilege Escalation
ISO is aware of two critical vulnerabilities that affect Linux systems. At this time, it is believed that nearly all Linux distributions and kernels are universally affected until confirmed otherwise.
The vulnerabilities, together called Dirty Frag [1], can be chained to obtain Local Privilege Escalation that allows any local user to escalate their privileges to root. Similar to its predecessors, Dirty Pipe and Copy Fail, Dirty Frag exploits the Linux kernel's page cache. The affected kernel modules are esp4 & esp6 (IPSec ESP), and rxrpc (AFS distributed filesystem).
Working exploits were published on May 7th, 2026, and currently there are no assigned CVE numbers or official security patches from Linux distributions.
Dirty Frag - Universal Local Privilege Escalation in Linux
ISO is aware of two critical vulnerabilities that affect Linux systems. At this time, it is believed that nearly all Linux distributions and kernels are universally affected until confirmed otherwise.
The vulnerabilities, together called Dirty Frag [1], can be chained to obtain Local Privilege Escalation that allows any local user to escalate their privileges to root. Similar to its predecessors, Dirty Pipe and Copy Fail, Dirty Frag exploits the Linux kernel's page cache. The affected kernel modules are esp4 & esp6 (IPSec ESP), and rxrpc (AFS distributed filesystem).
Working exploits were published on May 7th, 2026, and currently there are no assigned CVE numbers or official security patches from Linux distributions.
Critical Apache 2.4.66 HTTP/2 Flaw Allows RCE & DoS (CVE-2026-23918)
A critical double-free vulnerability in Apache HTTP Server's HTTP/2 module is vulnerable to unauthenticated Remote Code Execution (RCE) and Denial of Service (DoS) attacks. [1]
ISO Security Notice: NGINX Rift
ISO is aware of a critical vulnerability, codenamed NGINX Rift, that affects NGINX Plus and NGINX Open’s ngx_http_rewrite_module module, which is part of every standard NGINX build. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?).
Drupal Core Vulnerability PSA-2026-05-18
ISO is aware of an upcoming critical security update that affects Drupal core. The Drupal Security Team has issued a heads-up (PSA-2026-05-18) about a highly critical security update coming out for Drupal core[1].
Drupal Core SQL Injection Vulnerability CVE-2026-9082
This is a follow-up to a notice alerting you to a critical vulnerability affecting sites running the Drupal Content Management System [1]. Please share this alert internally with IT admins and service owners who run the product so they are aware and know what actions to take to address this vulnerability.