Back to trending CVEs

Week of April 20, 2026

Trending* CVEs over the last 7 days (from April 13, 2026 to April 20, 2026)

1
CVE-2026-33032Nginxui / Nginx Web Server
SYRN Score95
CVSS9.8
Activity53
Published03/30/2026
StatusHighly Active

Nginx UI is a web user interface for the Nginx web server. In versions 2.3.5 and prior, the nginx-ui MCP (Model Context Protocol) integration exposes two HTTP endpoints: /mcp and /mcp_message. While /mcp requires both IP whitelisting and authentication (AuthRequired() middleware), the /mcp_message endpoint only applies IP whitelisting - and the default IP whitelist is empty, which the middleware treats as "allow all". This means any network attacker can invoke all MCP tools without authentication, including restarting nginx, creating/modifying/deleting nginx configuration files, and triggering automatic config reloads - achieving complete nginx service takeover. At time of publication, there are no publicly available patches.

2
CVE-2026-32201Microsoft / Microsoft SharePoint
NewKEV
SYRN Score92
CVSS6.5
Activity51
Published04/14/2026
StatusHighly Active

Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

3
CVE-2026-34197Apache Software Foundation / Activemq
KEV
SYRN Score96
CVSS8.8
Activity42
Published04/07/2026
StatusHighly Active

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ MBeans (org.apache.activemq:*), including BrokerService.addNetworkConnector(String) and BrokerService.addConnector(String). An authenticated attacker can invoke these operations with a crafted discovery URI that triggers the VM transport's brokerConfig parameter to load a remote Spring XML application context using ResourceXmlApplicationContext. Because Spring's ResourceXmlApplicationContext instantiates all singleton beans before the BrokerService validates the configuration, arbitrary code execution occurs on the broker's JVM through bean factory methods such as Runtime.exec(). This issue affects Apache ActiveMQ Broker: before 5.19.4, from 6.0.0 before 6.2.3; Apache ActiveMQ All: before 5.19.4, from 6.0.0 before 6.2.3; Apache ActiveMQ: before 5.19.4, from 6.0.0 before 6.2.3. Users are recommended to upgrade to version 5.19.4 or 6.2.3, which fixes the issue

4
CVE-2026-33825Microsoft / Microsoft Defender
New
SYRN Score55
CVSS7.8
Activity40
Published04/14/2026
StatusHighly Active

Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.

5
CVE-2026-33824Microsoft / Microsoft Windows
New
SYRN Score69
CVSS9.8
Activity24
Published04/14/2026
StatusActive

Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.

6
CVE-2026-34621Adobe / Acrobat
KEV
SYRN Score94
CVSS8.6
Activity23
Published04/11/2026
StatusActive

Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

7
CVE-2025-0520Showdoc / Showdoc
SYRN Score73
CVSS9.4
Activity23
Published04/29/2025
StatusActive

An unrestricted file upload vulnerability in ShowDoc caused by improper validation of file extension allows execution of arbitrary PHP, leading to remote code execution.This issue affects ShowDoc: before 2.8.7.

8
CVE-2026-39808Fortinet / Fortisandbox
New
SYRN Score80
CVSS9.1
Activity19
Published04/14/2026
StatusActive

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here>

9
CVE-2024-3721Tbk / Dvr-4104
SYRN Score95
CVSS6.3
Activity16
Published04/13/2024
StatusActive

A vulnerability was found in TBK DVR-4104 and DVR-4216 up to 20240412 and classified as critical. This issue affects some unknown processing of the file /device.rsp?opt=sys&cmd=___S_O_S_T_R_E_A_MAX___. The manipulation of the argument mdb/mdc leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-260573 was assigned to this vulnerability.

10
CVE-2026-20184Cisco Systems / Cisco Webex Meetings
New
SYRN Score53
CVSS9.8
Activity15
Published04/15/2026
StatusActive

A vulnerability in the integration of single sign-on (SSO) with Control Hub in Cisco Webex Services could have allowed an unauthenticated, remote attacker to impersonate any user within the service. This vulnerability existed because of improper certificate validation. Prior to this vulnerability being addressed, an attacker could have exploited this vulnerability by connecting to a service endpoint and supplying a crafted token. A successful exploit could have allowed the attacker to gain unauthorized access to legitimate Cisco Webex services.

* Trending is based on the number of sightings collected from SYRN's threat intelligence sources over the given period.

Monitor these vulnerabilities and get alerted when new threats target your stack.

Get Started Free