Historical Authority Record

Hall of Fame: Annual Leaderboard

A definitive ranking of history's most critical and routinely exploited vulnerabilities. Sourced from the CISA KEV catalog and ranked by technical severity.

Impact-First Ranking

Prioritizes vulnerabilities formally documented as 'Ransomware Used' in the CISA KEV catalog. Rankings are calculated based on their proven impact on the global threat landscape.

Green Rank

[CVE-2026-15409]SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability

Critical
CVSS 10
Ransomware Used

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.

Affected Infrastructure:Sma6210 firmware
#2Orange Rank

[CVE-2026-20131]Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability

Critical
CVSS 10
Ransomware Used

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device. This vulnerability is due to insecure deserialization of a user-supplied Java byte stream. An attacker could exploit this vulnerability by sending a crafted serialized Java object to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the device and elevate privileges to root. Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.

Affected Infrastructure:Secure firewall management center
#3Purple Rank

[CVE-2026-83548]SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability

Critical
CVSS 10

A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.

Affected Infrastructure:Sma8200v
#4Rank #4

[CVE-2026-72898]Metabase SQL Injection Vulnerability

Critical
CVSS 10

Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.

Affected Infrastructure:Metabase
#5Rank #5

[CVE-2026-16812]Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability

Critical
CVSS 10

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. This functionality was intended to be for internal use only and is not intended to be remotely accessible. Hosted and Dedicated versions of VCO have already been patched in advance of this notice going out. This issue was discovered externally and is known to be actively exploited.

Affected Infrastructure:Velocloud orchestrator
#6Rank #6

[CVE-2026-48282]Adobe ColdFusion Path Traversal Vulnerability

Critical
CVSS 10

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

Affected Infrastructure:Coldfusion
#7Rank #7

[CVE-2026-49869]Kestra OSS OS Command Injection Vulnerability

Critical
CVSS 10

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().endsWith("/configs") to whitelist the public configuration endpoint from Basic Auth. Because the check is a suffix match rather than an exact path match, any API path whose last segment is configs bypasses authentication entirely. An unauthenticated remote attacker can exploit this to create and execute arbitrary workflows without credentials. Because Kestra ships with script execution plugins (plugin-script-shell, plugin-script-python, etc.) enabled by default, this directly results in unauthenticated Remote Code Execution as root inside the Kestra worker container. This vulnerability is fixed in 1.0.45 and 1.3.21.

Affected Infrastructure:Kestra
#8Rank #8

[CVE-2026-48558]SimpleHelp Authentication Bypass Vulnerability

Critical
CVSS 10

SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication. No user interaction is required.

Affected Infrastructure:Simplehelp
#9Rank #9

[CVE-2026-10520]Ivanti Sentry OS Command Injection Vulnerability

Critical
CVSS 10

An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution

Affected Infrastructure:Standalone sentry
#10Rank #10

[CVE-2026-34910]Ubiquiti UniFi OS Improper Input Validation Vulnerability

Critical
CVSS 10

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.

Affected Infrastructure:Unifi os server
#11Rank #11

[CVE-2026-34909]Ubiquiti UniFi OS Path Traversal Vulnerability

Critical
CVSS 10

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account.

Affected Infrastructure:Unifi os server
#12Rank #12

[CVE-2026-34908]Ubiquiti UniFi OS Improper Access Control Vulnerability

Critical
CVSS 10

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.

Affected Infrastructure:Unifi os server
#13Rank #13

[CVE-2026-20182]Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability

Critical
CVSS 10

May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed in February 2026. This new advisory is for a new vulnerability in the control connection handshaking. The section of this advisory includes Show Control Connections guidance to help with system checks.  A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to the affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric.

Affected Infrastructure:Catalyst sd-wan manager
#14Rank #14

[CVE-2026-20127]Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability

Critical
CVSS 10

A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to an affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric. 

Affected Infrastructure:Catalyst sd-wan manager
#15Rank #15

[CVE-2026-22769]Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability

Critical
CVSS 10

Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability. This is considered critical as an unauthenticated remote attacker with knowledge of the hardcoded credential could potentially exploit this vulnerability leading to unauthorized access to the underlying operating system and root-level persistence. Dell recommends that customers upgrade or apply one of the remediations as soon as possible.

Affected Infrastructure:Recoverpoint for virtual machines
#16Rank #16

[CVE-2026-21962]Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability

Critical
CVSS 10

Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in. While the vulnerability is in Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data. Note: Affected version for Weblogic Server Proxy Plug-in for IIS is 12.2.1.4.0 only. CVSS 3.1 Base Score 10.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).

Affected Infrastructure:Http server
#17Rank #17

[CVE-2026-82329]JFrog Artifactory Improper Authentication Vulnerability

Critical
CVSS 9.8

JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.

Affected Infrastructure:Artifactory
#18Rank #18

[CVE-2026-81578]PaperCut NG/MF Missing Authentication for Critical Function Vulnerability

Critical
CVSS 9.8

An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations.

Affected Infrastructure:Papercut mf
#19Rank #19

[CVE-2026-60004]Gitea Code Injection Vulnerability

Critical
CVSS 9.8

Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

Affected Infrastructure:Gitea
#20Rank #20

[CVE-2026-72529]TrueConf Server Missing Authentication for Critical Function Vulnerability

Critical
CVSS 9.8

A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.

Affected Infrastructure:Trueconf server