{
  "name": "Exploited & Unpatchable",
  "description": "Actively exploited vulnerabilities (CISA KEV) affecting software versions that are past end-of-life and will never receive the fix. Curated and human-verified by endoflife.ai.",
  "definition": "An entry lists a CVE on CISA’s Known Exploited Vulnerabilities catalog that affects one or more product versions past their vendor end-of-life date, where the fix ships only in supported versions and no update is expected for the end-of-life line through the vendor’s normal support channels.",
  "methodology_url": "https://endoflife.ai/exploited-and-unpatchable",
  "license": "Aggregated from public sources (CISA KEV, NVD, vendor advisories) and endoflife.ai verified lifecycle data. Attribution required: endoflife.ai.",
  "generated_at": "2026-08-08T02:59:18.258Z",
  "entry_count": 12,
  "entries": [
    {
      "cve": "CVE-2026-63077",
      "product": "teamcity",
      "product_name": "JetBrains TeamCity",
      "vulnerability": "Unauthenticated remote code execution via the agent polling protocol",
      "weakness": "Deserialization of untrusted data",
      "cvss": 9.8,
      "cvss_source": "JetBrains (CNA); NVD not yet scored",
      "known_exploited": true,
      "kev_date_added": "2026-08-05",
      "kev_due_date": "2026-08-08",
      "affected_statement": "All releases prior to 2025.11.7, and 2026.1 through 2026.1.2",
      "fixed_versions": [
        "2025.11.7",
        "2026.1.3"
      ],
      "affected_eol_versions": [
        "2025.07",
        "2025.03",
        "2024.12",
        "2024.07",
        "2024.03",
        "2023.11",
        "2023.05",
        "2022.10",
        "2022.04"
      ],
      "unpatchable_reason": "JetBrains provides security fixes only for the current and immediately previous release lines. The fix exists solely in 2025.11.7 and 2026.1.3; every earlier line is past end of support and receives no update for this actively exploited flaw.",
      "sources": {
        "kev": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "advisory": "https://www.jetbrains.com/privacy-security/issues-fixed/",
        "nvd": "https://nvd.nist.gov/vuln/detail/CVE-2026-63077",
        "lifecycle": "https://endoflife.ai/teamcity"
      },
      "last_reviewed": "2026-08-07"
    },
    {
      "cve": "CVE-2025-68686",
      "product": "fortios",
      "product_name": "Fortinet FortiOS",
      "vulnerability": "Symlink-based persistence that survives patching — a post-exploitation weakness abused after a threat actor has already exploited a separate filesystem-level vulnerability. KEV-listed by CISA.",
      "weakness": "Improper link resolution / persistence",
      "cvss": 5.9,
      "cvss_source": "NVD (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N); Fortinet rates 5.3",
      "known_exploited": true,
      "kev_date_added": "2026-07-27",
      "kev_due_date": "2026-08-10",
      "affected_statement": "FortiOS 7.6.0–7.6.1, 7.4.0–7.4.6, all 7.2, all 7.0, all 6.4 (per FG-IR-25-934)",
      "fixed_versions": [
        "7.6.2",
        "7.4.7"
      ],
      "affected_eol_versions": [
        "7.0",
        "6.4"
      ],
      "unpatchable_reason": "Fortinet's advisory FG-IR-25-934 lists 'FortiOS 7.0 all versions' and '6.4 all versions' as affected, and gives their only remediation as 'Migrate to a fixed release' — no fixed build is or will be published for either branch. FortiOS 7.0 reached end of support 2025-09-30 and 6.4 on 2024-09-30. (The current 7.2 branch is also given no build but is excluded here because it remains supported until 2026-09-30.)",
      "sources": {
        "kev": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "advisory": "https://fortiguard.fortinet.com/psirt/FG-IR-25-934",
        "nvd": "https://nvd.nist.gov/vuln/detail/CVE-2025-68686",
        "lifecycle": "https://endoflife.ai/fortios"
      },
      "last_reviewed": "2026-08-07"
    },
    {
      "cve": "CVE-2026-34197",
      "product": "apache-activemq",
      "product_name": "Apache ActiveMQ",
      "vulnerability": "Remote code execution via the Jolokia JMX-HTTP bridge — effectively unauthenticated on the 6.0 and 6.1 lines (the console's Jolokia endpoint sits outside the security constraints per CVE-2024-32114), and authenticated on the 5.x lines",
      "weakness": "Exposure of a management interface (JMX via Jolokia)",
      "cvss": 8.8,
      "cvss_source": "NVD (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)",
      "known_exploited": true,
      "kev_date_added": "2026-04-16",
      "kev_due_date": "2026-04-30",
      "affected_statement": "All 5.x releases before 5.19.4 (NVD lists an open-ended upper bound with no lower bound), and 6.0.0 up to (excluding) 6.2.3",
      "fixed_versions": [
        "5.19.4",
        "6.2.3"
      ],
      "affected_eol_versions": [
        "6.1",
        "6.0",
        "5.18",
        "5.17",
        "5.16"
      ],
      "unpatchable_reason": "The fix ships only in the 5.19.x line (5.19.4) and in 6.2.3. Every ActiveMQ line below that — 6.0, 6.1, and 5.16 through 5.18 — is past end of life and receives no backport; all fall within the vendor's affected range with no available patch. The 6.0/6.1 lines are the most exposed, being effectively unauthenticated.",
      "sources": {
        "kev": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "advisory": "https://activemq.apache.org/security-advisories.data/CVE-2026-34197-announcement.txt",
        "nvd": "https://nvd.nist.gov/vuln/detail/CVE-2026-34197",
        "lifecycle": "https://endoflife.ai/apache-activemq"
      },
      "last_reviewed": "2026-08-07"
    },
    {
      "cve": "CVE-2025-49113",
      "product": "roundcube",
      "product_name": "Roundcube Webmail",
      "vulnerability": "Authenticated remote code execution via PHP object deserialization in the file-upload handler (the _from request parameter). The vulnerable code path had been present in the codebase for roughly a decade.",
      "weakness": "Deserialization of untrusted data (RCE)",
      "cvss": 9.9,
      "cvss_source": "MITRE 9.9; NVD/NIST 8.8",
      "known_exploited": true,
      "kev_date_added": "2026-02-20",
      "kev_due_date": "2026-03-13",
      "affected_statement": "NVD lists the affected range as all versions from 0 up to (excluding) 1.5.10, plus 1.6.0–1.6.11; fixed only in 1.5.10 and 1.6.11",
      "fixed_versions": [
        "1.5.10",
        "1.6.11"
      ],
      "affected_eol_versions": [
        "1.4",
        "1.3",
        "1.2"
      ],
      "unpatchable_reason": "The fix shipped only in 1.5.10 and 1.6.11. NVD's authoritative affected range (versionStartIncluding 0, versionEndExcluding 1.5.10) places the 1.4, 1.3 and 1.2 lines within scope, and no fixed point release was issued for any of them — all three are past end of life. Basis is stated explicitly (NVD range plus the documented decade-long presence of the deserialization path); the entry is removed if a backport later appears.",
      "sources": {
        "kev": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "advisory": "https://github.com/roundcube/roundcubemail/security/advisories/GHSA-8j8w-wwqc-x596",
        "nvd": "https://nvd.nist.gov/vuln/detail/CVE-2025-49113",
        "lifecycle": "https://endoflife.ai/roundcube"
      },
      "last_reviewed": "2026-08-07"
    },
    {
      "cve": "CVE-2024-37085",
      "product": "esxi",
      "product_name": "VMware ESXi",
      "vulnerability": "Active Directory integration authentication bypass — a member of a domain group named 'ESX Admins' gains full host administrative access. Exploited in the wild by ransomware operators (Akira, Black Basta).",
      "weakness": "Authentication bypass",
      "cvss": 6.8,
      "cvss_source": "VMware/Broadcom (CNA); NVD rates 7.2",
      "known_exploited": true,
      "kev_date_added": "2024-07-30",
      "kev_due_date": "2024-08-20",
      "affected_statement": "ESXi 8.0 and 7.0 (per VMSA-2024-0013)",
      "fixed_versions": [
        "ESXi 8.0 U3 (ESXi80U3-24022510)"
      ],
      "affected_eol_versions": [
        "7.0"
      ],
      "unpatchable_reason": "Broadcom's own advisory matrix (VMSA-2024-0013) lists ESXi 7.0 as affected with fixed version 'No Patch Planned' — the fix ships only in 8.0 U3, and Broadcom stated in writing that 7.0 will receive no patched build. Only a manual Active Directory reconfiguration workaround exists. ESXi 7.0 reached end of general support on 2025-10-02, so no update will come.",
      "sources": {
        "kev": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "advisory": "https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/securityadvisories/0/24505",
        "nvd": "https://nvd.nist.gov/vuln/detail/CVE-2024-37085",
        "lifecycle": "https://endoflife.ai/esxi"
      },
      "last_reviewed": "2026-08-07"
    },
    {
      "cve": "CVE-2023-22518",
      "product": "confluence",
      "product_name": "Atlassian Confluence Server & Data Center",
      "vulnerability": "Improper authorization allowing an unauthenticated attacker to reset Confluence and create an administrator account, leading to full compromise. Mass-exploited (including ransomware) since November 2023.",
      "weakness": "Improper authorization",
      "cvss": 9.8,
      "cvss_source": "NVD (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H); Atlassian revised to 10.0",
      "known_exploited": true,
      "kev_date_added": "2023-11-07",
      "kev_due_date": null,
      "affected_statement": "All versions prior to the fixed releases (per Atlassian advisory); the only fixes were 7.19.16 (7.x LTS), 8.3.4, 8.4.4, 8.5.3, 8.6.1",
      "fixed_versions": [
        "7.19.16",
        "8.3.4",
        "8.4.4",
        "8.5.3",
        "8.6.1"
      ],
      "affected_eol_versions": [
        "7.0–7.18 (non-LTS)",
        "6.x",
        "5.x"
      ],
      "unpatchable_reason": "The only 7.x fix shipped on the 7.19 LTS line (7.19.16); every earlier non-LTS 7.x branch and all of 6.x and 5.x fall under the advisory's 'all versions prior to the listed fix versions' and received no fixed release for this actively exploited authorization bypass. All are past end of life (Confluence Server as a whole reached end of life 2024-02-15). This is a distinct CVE from the other Confluence entries; the 8.0–8.2 branches are deliberately excluded as a normal non-LTS lifecycle case rather than an abandoned-branch one.",
      "sources": {
        "kev": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "advisory": "https://confluence.atlassian.com/security/cve-2023-22518-improper-authorization-vulnerability-in-confluence-data-center-and-server-1311473907.html",
        "nvd": "https://nvd.nist.gov/vuln/detail/CVE-2023-22518",
        "lifecycle": "https://endoflife.ai/confluence"
      },
      "last_reviewed": "2026-08-07"
    },
    {
      "cve": "CVE-2022-26134",
      "product": "confluence",
      "product_name": "Atlassian Confluence Server & Data Center",
      "vulnerability": "Unauthenticated OGNL injection allowing remote code execution. Mass-exploited in the wild since June 2022.",
      "weakness": "OGNL expression injection (RCE)",
      "cvss": 9.8,
      "cvss_source": "NVD (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)",
      "known_exploited": true,
      "kev_date_added": "2022-06-02",
      "kev_due_date": null,
      "affected_statement": "All supported versions at disclosure and every release after 1.3.0 (per Atlassian advisory 2022-06-02); fixes were issued only for the 7.4, 7.13–7.18 branches",
      "fixed_versions": [
        "7.4.17",
        "7.13.7",
        "7.14.3",
        "7.15.2",
        "7.16.4",
        "7.17.4",
        "7.18.1"
      ],
      "affected_eol_versions": [
        "6.x"
      ],
      "unpatchable_reason": "Atlassian's advisory names every release after 1.3.0 as affected but shipped fixes only on the 7.4 and 7.13–7.18 branches. Confluence 6.x was already past end of life at the June 2022 disclosure and received no fixed build for this actively exploited RCE. (Confluence Server as a whole reached end of life 2024-02-15.) Branches that did receive a per-branch backport are deliberately excluded.",
      "sources": {
        "kev": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "advisory": "https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html",
        "nvd": "https://nvd.nist.gov/vuln/detail/CVE-2022-26134",
        "lifecycle": "https://endoflife.ai/confluence"
      },
      "last_reviewed": "2026-08-07"
    },
    {
      "cve": "CVE-2019-10149",
      "product": "exim",
      "product_name": "Exim",
      "vulnerability": "Improper validation of the recipient address in deliver_message() allowing remote command execution as root ('Return of the WIZard'). Mass-exploited in the wild.",
      "weakness": "Improper input validation (RCE)",
      "cvss": 9.8,
      "cvss_source": "NVD (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)",
      "known_exploited": true,
      "kev_date_added": "2022-01-10",
      "kev_due_date": "2022-07-10",
      "affected_statement": "Exim 4.87 to 4.91 (per the Exim project advisory); Exim 4.92 is not vulnerable",
      "fixed_versions": [
        "4.92"
      ],
      "affected_eol_versions": [
        "4.91"
      ],
      "unpatchable_reason": "The Exim advisory names 4.87 through 4.91 as affected and delivers the fix only as the forward 4.92 release — no patched build was issued for the 4.91 line, which reached end of life 2019-02-10. Under Exim's model the only remediation is to upgrade off the dead branch.",
      "sources": {
        "kev": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "advisory": "https://www.exim.org/static/doc/security/CVE-2019-10149.txt",
        "nvd": "https://nvd.nist.gov/vuln/detail/CVE-2019-10149",
        "lifecycle": "https://endoflife.ai/exim"
      },
      "last_reviewed": "2026-08-07"
    },
    {
      "cve": "CVE-2019-0193",
      "product": "solr",
      "product_name": "Apache Solr",
      "vulnerability": "Remote code execution via the DataImportHandler dataConfig request parameter, which accepts a full DIH configuration including a script transformer.",
      "weakness": "Unsafe configuration accepted at request time (RCE)",
      "cvss": 7.2,
      "cvss_source": "NVD (CVSS:3.1); CVSS v2 rated 9.0",
      "known_exploited": true,
      "kev_date_added": "2021-12-10",
      "kev_due_date": "2022-06-10",
      "affected_statement": "All Apache Solr versions prior to 8.2.0 (per NVD). 8.2.0 mitigates by requiring the system property enable.dih.dataConfigParam=true",
      "fixed_versions": [
        "8.2.0"
      ],
      "affected_eol_versions": [
        "7",
        "6",
        "5"
      ],
      "unpatchable_reason": "The mitigation exists only from Solr 8.2.0 onward; no fixed release was issued for the 7.x, 6.x or 5.x lines, all past end of life. The DataImportHandler that carries the flaw shipped in every one of these versions, and none received a backport.",
      "sources": {
        "kev": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "advisory": "https://nvd.nist.gov/vuln/detail/CVE-2019-0193",
        "nvd": "https://nvd.nist.gov/vuln/detail/CVE-2019-0193",
        "lifecycle": "https://endoflife.ai/solr"
      },
      "last_reviewed": "2026-08-07"
    },
    {
      "cve": "CVE-2021-26084",
      "product": "confluence",
      "product_name": "Atlassian Confluence Server & Data Center",
      "vulnerability": "Unauthenticated OGNL injection allowing remote code execution. Widely exploited since 2021 and on CISA's KEV catalog.",
      "weakness": "OGNL expression injection (RCE)",
      "cvss": 9.8,
      "cvss_source": "NVD (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)",
      "known_exploited": true,
      "kev_date_added": "2021-11-03",
      "kev_due_date": null,
      "affected_statement": "Before 6.13.23; 6.14.0–<7.4.11; 7.5.0–<7.11.6; 7.12.0–<7.12.5 (per Atlassian advisory 2021-08-25); fixes issued on 6.13, 7.4, 7.11, 7.12, 7.13 only",
      "fixed_versions": [
        "6.13.23",
        "7.4.11",
        "7.11.6",
        "7.12.5",
        "7.13.0"
      ],
      "affected_eol_versions": [
        "6.0–6.12"
      ],
      "unpatchable_reason": "Atlassian's advisory lists the 4.x, 5.x and 6.0–6.12 lines among affected versions but issued fixed builds only on 6.13, 7.4, 7.11, 7.12 and 7.13. The 6.0–6.12 lines were past end of life at disclosure and received no fixed build for this actively exploited RCE. The 6.13 branch, which did receive a backport, is excluded.",
      "sources": {
        "kev": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "advisory": "https://confluence.atlassian.com/doc/confluence-security-advisory-2021-08-25-1077906215.html",
        "nvd": "https://nvd.nist.gov/vuln/detail/CVE-2021-26084",
        "lifecycle": "https://endoflife.ai/confluence"
      },
      "last_reviewed": "2026-08-07"
    },
    {
      "cve": "CVE-2020-17530",
      "product": "apache-struts",
      "product_name": "Apache Struts",
      "vulnerability": "Forced OGNL double-evaluation of attacker-supplied input allowing remote code execution (S2-061).",
      "weakness": "OGNL expression injection (RCE)",
      "cvss": 9.8,
      "cvss_source": "NVD (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)",
      "known_exploited": true,
      "kev_date_added": "2021-11-03",
      "kev_due_date": "2022-05-03",
      "affected_statement": "Struts 2.0.0 - Struts 2.5.25 (per Apache advisory S2-061); fixed only in Struts 2.5.26",
      "fixed_versions": [
        "2.5.26"
      ],
      "affected_eol_versions": [
        "2.3"
      ],
      "unpatchable_reason": "S2-061 lists the affected range as Struts 2.0.0 through 2.5.25 and ships the fix only in 2.5.26. The Struts 2.3 line ended at 2.3.37 and reached end of life on 2019-05-14 — eighteen months before this advisory — so no 2.3.x fix was ever released. A 2.3.x install cannot patch in place. (The 2.5 line is excluded: 2.5.26 is a same-line fix and 2.5 was supported until 2024-04-30.)",
      "sources": {
        "kev": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "advisory": "https://cwiki.apache.org/confluence/display/WW/S2-061",
        "nvd": "https://nvd.nist.gov/vuln/detail/CVE-2020-17530",
        "lifecycle": "https://endoflife.ai/apache-struts"
      },
      "last_reviewed": "2026-08-07"
    },
    {
      "cve": "CVE-2019-17558",
      "product": "solr",
      "product_name": "Apache Solr",
      "vulnerability": "Remote code execution via the VelocityResponseWriter when params.resource.loader.enabled is set, allowing a Velocity template to be supplied and executed.",
      "weakness": "Server-side template injection (RCE)",
      "cvss": 7.5,
      "cvss_source": "NVD (CVSS:3.1); historically reported as 9.8",
      "known_exploited": true,
      "kev_date_added": "2021-11-03",
      "kev_due_date": "2022-05-03",
      "affected_statement": "Apache Solr 5.0.0 to 8.3.1 (per NVD). The parameters-based resource loader was removed in 8.4",
      "fixed_versions": [
        "8.4"
      ],
      "affected_eol_versions": [
        "7",
        "6",
        "5"
      ],
      "unpatchable_reason": "The vulnerable parameters-based resource loader was removed only in Solr 8.4; no fixed release was issued for the 7.x, 6.x or 5.x lines (the 7.x line ended at 7.7.2), all past end of life. Every one of these versions is inside the vendor's 5.0.0–8.3.1 affected range with no available patch.",
      "sources": {
        "kev": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "advisory": "https://nvd.nist.gov/vuln/detail/CVE-2019-17558",
        "nvd": "https://nvd.nist.gov/vuln/detail/CVE-2019-17558",
        "lifecycle": "https://endoflife.ai/solr"
      },
      "last_reviewed": "2026-08-07"
    }
  ]
}