<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Exploited &amp; Unpatchable — endoflife.ai</title>
    <link>https://endoflife.ai/exploited-and-unpatchable</link>
    <atom:link href="https://endoflife.ai/exploited-and-unpatchable.xml" rel="self" type="application/rss+xml"/>
    <description>Actively exploited vulnerabilities (CISA KEV) affecting software versions that are past end-of-life and are not expected to receive a fix. Curated and human-verified by endoflife.ai.</description>
    <language>en</language>
    <lastBuildDate>Tue, 22 Sep 2026 04:07:51 GMT</lastBuildDate>
    <item>
      <title>CVE-2026-53266 — Linux kernel (kernel.org upstream branches) 5.4 (exploited, no patch coming)</title>
      <link>https://endoflife.ai/exploited-and-unpatchable#CVE-2026-53266</link>
      <guid isPermaLink="false">endoflife.ai:eu:linux:CVE-2026-53266</guid>
      <pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate>
      <description>Out-of-bounds write in the ebtables SNAT target of the bridge netfilter code: the optional ARP sender hardware address rewrite writes into a socket buffer range that was never made writable, so it can write into a nonlinear fragment backed by a splice-imported file page. The kernel CNA published the record on 2026-06-25 under the title 'netfilter: bridge: make ebt_snat ARP rewrite writable'. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-09-18 with a 2026-09-21 due date, and CISA's description notes that the impacted products could be end of life. Scope: this entry is about the kernel.org upstream longterm branches only. Linux distributions (Red Hat, Ubuntu, Debian, SUSE, Oracle, Amazon and device vendors) ship their own kernels and backport fixes on their own schedule, so a distribution kernel whose version string starts with the same number may already carry the fix; check the distributor's advisory for a distribution kernel. Why unpatchable: Two facts, stated separately. First, the kernel CNA record names 5.4.73 and every later 5.4 release as affected and lists no fixed 5.4 version. Second, the 5.4 longterm branch ended with 5.4.302 on 2025-12-03 (the date served on our Linux kernel page, and kernel.org no longer lists 5.4 among its longterm branches), while the fix was first shipped in stable on 2026-06-19 in 5.10.259: the branch was closed about six months before the fix existed. Checked directly on 2026-09-19: the kernel.org changelogs for 5.4.300, 5.4.301 and 5.4.302 do not contain the fix, and the changelog for 5.10.259 does. 5.4.0 to 5.4.72 are not affected, and 4.19 and older upstream branches are not affected. The short-lived 5.8 and 5.9 branches named in the record ended in 2020 and are not tracked as cycles here. Deletion test: if kernel.org ever publishes a 5.4 release containing this fix, this entry is removed.</description>
    </item>
    <item>
      <title>CVE-2025-39964 — Linux kernel (kernel.org upstream branches) 5.4, 4.19 (exploited, no patch coming)</title>
      <link>https://endoflife.ai/exploited-and-unpatchable#CVE-2025-39964</link>
      <guid isPermaLink="false">endoflife.ai:eu:linux:CVE-2025-39964</guid>
      <pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate>
      <description>Race condition in the kernel crypto user-space interface (AF_ALG): two concurrent writes to the same AF_ALG socket can interleave data and leave the socket's internal state inconsistent. The kernel CNA published the record on 2025-10-13 under the title 'crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg'. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-09-18 with a 2026-09-21 due date. Scope: this entry is about the kernel.org upstream longterm branches only. Linux distributions (Red Hat, Ubuntu, Debian, SUSE, Oracle, Amazon and device vendors) ship their own kernels and backport fixes on their own schedule, so a distribution kernel whose version string starts with the same number may already carry the fix; check the distributor's advisory for a distribution kernel. Why unpatchable: Two facts, stated separately. First, the kernel CNA record marks 5.4 and 4.19 as affected (everything from 2.6.38) and lists no fixed version for either. Second, neither branch received the fix before it ended. For 5.4 this is the stronger case: the branch was still maintained when the fix shipped (5.10.245 and 5.4.300 were released on the same day, 2025-10-02), and 5.4.300, 5.4.301 and the final 5.4.302 of 2025-12-03 were all released without it. 4.19 ended with 4.19.325 on 2024-12-05, about nine months before the fix was written. Checked directly on 2026-09-19: the kernel.org changelogs for 5.4.300, 5.4.301, 5.4.302 and 4.19.325 do not contain the fix, and the changelog for 5.10.245 does; kernel.org lists neither branch among its longterm branches. Older end-of-life upstream branches (4.14, 4.9 and earlier) are also inside the record's affected range with no fix listed, but their code differs and we have not verified them, so they are not listed here. Deletion test: if kernel.org ever publishes a 5.4 or 4.19 release containing this fix, the branch is removed from this entry.</description>
    </item>
    <item>
      <title>CVE-2026-20079 — Cisco Secure Firewall Management Center 7.3, 7.1 (exploited, no patch coming)</title>
      <link>https://endoflife.ai/exploited-and-unpatchable#CVE-2026-20079</link>
      <guid isPermaLink="false">endoflife.ai:eu:cisco-fmc:CVE-2026-20079</guid>
      <pubDate>Wed, 16 Sep 2026 00:00:00 GMT</pubDate>
      <description>Authentication bypass in the web interface of Cisco Secure Firewall Management Center (FMC) Software: an improper system process created at boot lets an unauthenticated, remote attacker send crafted HTTP requests, bypass authentication, execute script files and obtain root on the underlying operating system. Cisco (the CNA) scores it CVSS 10.0. First published 2026-03-04; hot fixes and indicators of compromise added 2026-07-31; on 2026-09-09 Cisco updated the advisory to state that its PSIRT became aware of active exploitation in August 2026, and CISA added it to the KEV catalog the same day with a 2026-09-12 due date. Cisco Talos described three intrusion clusters on FMC appliances the same day. No workarounds. Why unpatchable: Two facts, stated separately. First, Cisco's own CVE record lists the 7.3.x and 7.1.x releases as affected. Second, Cisco's fixed-release table, as rewritten for the 2026-09-16 hardening release, covers seven trains and not these two, and Cisco's per-train lifecycle bulletins (as served on our FMC page) put 7.3's End of Vulnerability/Security Support at 2026-05-18 and 7.1's at 2024-12-21; under Cisco's lifecycle policy a train past that milestone receives no further security fixes. The fix pattern follows the calendar rather than the version number: 7.0 and 7.2, both older than 7.3, received full builds because their security support runs to 2026-11-18. The deletion test was run on 2026-09-16: Cisco Talos had said a comprehensive hardening release would follow the week of 2026-09-14, it shipped on 2026-09-16 with full builds for seven trains, and it contains no 7.3 or 7.1 build, so the feed's deletion rule is not triggered and the entry stands. The migration path is any of the seven fixed trains, with 7.4, 7.6, 10.0 and 10.1 carrying no announced end date.</description>
    </item>
    <item>
      <title>CVE-2026-85706 — GitLab CE/EE 19.0, 18.11, 18.10, 18.9, 18.8, 18.7 (exploited, no patch coming)</title>
      <link>https://endoflife.ai/exploited-and-unpatchable#CVE-2026-85706</link>
      <guid isPermaLink="false">endoflife.ai:eu:gitlab:CVE-2026-85706</guid>
      <pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate>
      <description>Path traversal with missing authentication enforcement in the GitLab repository commits API: under certain conditions an unauthenticated user can read arbitrary files from the GitLab server. GitLab (the CNA) scores it CVSS 10.0. Published in GitLab's critical patch release of 2026-09-10 (19.3.2, 19.2.6, 19.1.8); CISA added it to the KEV catalog on 2026-09-11 with a 2026-09-14 due date. Why unpatchable: GitLab's maintenance policy (docs.gitlab.com/policy/maintenance, read live 2026-09-12) states: 'Backporting security fixes to the previous two monthly releases in addition to the current stable release', and lists the maintained versions as 19.3 (bug and security fixes), 19.2 (security fixes) and 19.1 (security fixes). The patch release ships fixed builds for exactly those three lines. Six lines inside GitLab's own impacted range, 19.0 and 18.7 through 18.11, have no fixed build: every one of them had left GitLab's maintenance window before the patch release (19.0 on 2026-08-20, 18.11 on 2026-07-16, 18.10 on 2026-06-18, 18.9 on 2026-05-21, 18.8 on 2026-04-16, 18.7 on 2026-03-19, our data from GitLab's release schedule). The policy allows an exception 'in rare cases' to backport further; none was announced with this release. The two facts are kept separate: the lines are past GitLab's maintenance window, and GitLab's fix list stops at 19.1.8. Lines before 18.7 are outside the impacted range and are not on this feed. The upgrade path from these lines is to 19.1.8 or later via GitLab's documented upgrade paths, and 19.1 itself leaves security support on 2026-09-17.</description>
    </item>
    <item>
      <title>CVE-2026-86060 — MikroTik RouterOS 6.48, 6.47, 6.46, 6.45, 6.44, 6.43, 6.42, 6.41, 6.40, 6.39, 6.38, 6.37, 6.36, 6.35, 6.34, 6.33, 6.32, 6.30, 6.29, 6.28, 6.27, 6.26, 6.25, 6.24, 6.23, 6.22, 6.20, 6.19, 6.18, 6.17, 6.16, 6.15, 6.14, 6.13, 6.12, 6.11, 6.10, 6.9, 6.7, 6.6, 6.5, 6.4, 6.3, 6.2, 6.1, 6.0 (exploited, no patch coming)</title>
      <link>https://endoflife.ai/exploited-and-unpatchable#CVE-2026-86060</link>
      <guid isPermaLink="false">endoflife.ai:eu:routeros:CVE-2026-86060</guid>
      <pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate>
      <description>SSH session privilege manipulation via a crafted username: an argument-handling flaw in the RouterOS SSH login path lets a username beginning with a prohibited character change the trusted RouterOS policy mask, ending in a session with full administrative rights. Exploitation requires an unauthenticated SSH session that can reach the RouterOS login helper. CERT Polska (the CNA) scores it CVSS 4.0 9.2. Fixed by MikroTik on 2026-09-03; CISA added it to the KEV catalog on 2026-09-10 with a 2026-09-13 due date. On RouterOS 7.9 and later it is the second half of the chain CERT Polska named MikroTrick (entry via CVE-2026-67276, then this flaw for administrator rights); CVE-2026-67276 does not exist on 6.x, so on a 6.x device this flaw stands alone as a privilege escalation for anyone who can reach SSH. Why unpatchable: The affected range starts at 6.0.0 and MikroTik's only 6.x fix is 6.49.21, on the 6.49 long-term line, the one 6.x line MikroTik still releases builds for. Every other 6.x line on our RouterOS page, 6.48 and earlier, is marked end of life (source: endoflife.date, which tracks MikroTik's changelog); 6.48's last build, 6.48.7, shipped on 2023-05-23 and no 6.48 or earlier release has followed, so no build in those lines carries the fix. MikroTik publishes no dated end-of-life calendar for RouterOS lines; the end-of-life status is the absence of releases, and this entry says so rather than inferring a date. The path off an affected 6.x device is 6.49.21 within the 6.x major, or a fixed 7.x release, both of which are new lines, not patches to the line the device runs.</description>
    </item>
    <item>
      <title>CVE-2026-67277 — MikroTik RouterOS 6.48, 6.47, 6.46, 6.45, 6.44, 6.43, 6.42, 6.41, 6.40, 6.39, 6.38, 6.37, 6.36, 6.35, 6.34, 6.33, 6.32, 6.30, 6.29, 6.28, 6.27, 6.26, 6.25, 6.24, 6.23, 6.22, 6.20, 6.19, 6.18, 6.17, 6.16, 6.15, 6.14, 6.13, 6.12, 6.11, 6.10, 6.9, 6.7, 6.6, 6.5, 6.4, 6.3, 6.2, 6.1, 6.0 (exploited, no patch coming)</title>
      <link>https://endoflife.ai/exploited-and-unpatchable#CVE-2026-67277</link>
      <guid isPermaLink="false">endoflife.ai:eu:routeros:CVE-2026-67277</guid>
      <pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate>
      <description>Kernel memory disclosure and denial of service in the RouterOS bandwidth-test (btest) service: RouterOS accepts a 'related' btest connection before the primary session has authenticated, so an unauthenticated client can start an IPv4 UDP test; with random-data=false the sender transmits an uninitialised tail of a kernel packet buffer, and a separate unchecked packet-size interval causes an integer underflow that can restart the RouterOS kernel. CERT Polska (the CNA) scores it CVSS 4.0 8.8. This is not code execution: standalone impact is information disclosure and a router restart. Fixed by MikroTik on 2026-09-03; CISA added it to the KEV catalog on 2026-09-10 with a 2026-09-13 due date. Why unpatchable: Same lifecycle facts as CVE-2026-86060: the affected range starts at 6.0.0, MikroTik's only 6.x fix is 6.49.21 on the 6.49 long-term line, and every earlier 6.x line on our RouterOS page is marked end of life with no release since its last build (6.48.7 on 2023-05-23 for the newest of them). MikroTik publishes no dated end-of-life calendar for RouterOS lines; the status is the absence of releases. Exposure is the bandwidth-test service reachable from untrusted networks; MikroTik's and CERT Polska's advice is the same for this flaw as for the SSH one, keep management and test services off the internet, but the fix itself exists only on 6.49.21 and 7.x.</description>
    </item>
    <item>
      <title>CVE-2024-0769 — D-Link DIR-859 DIR-859 (exploited, no patch coming)</title>
      <link>https://endoflife.ai/exploited-and-unpatchable#CVE-2024-0769</link>
      <guid isPermaLink="false">endoflife.ai:eu:dlink-routers:CVE-2024-0769</guid>
      <pubDate>Fri, 04 Sep 2026 00:00:00 GMT</pubDate>
      <description>Path traversal in the D-Link DIR-859 (firmware 1.06B01) HTTP POST handler /hedwig.cgi: manipulating the 'service' argument reads arbitrary files such as the DHCP configuration, exposing credentials and enabling further compromise. NVD scores it 9.8; the CVE record itself is marked 'UNSUPPORTED WHEN ASSIGNED' with the note that the vendor 'confirmed immediately that the product is end-of-life. It should be retired and replaced.' CISA added it to the KEV catalog on 2025-06-25. Why unpatchable: D-Link answered this specific CVE with an end-of-life notice rather than a firmware release: SAP10371 names CVE-2024-0769 and states that firmware development for the DIR-859 has ceased and the device should be retired. The model's end of support (2020-12-10) predates the CVE by three years. Contrast the model's earlier flaw CVE-2019-17621, which D-Link did patch while the DIR-859 was supported (SAP10146, 'confirmed and released patches') and which is therefore deliberately NOT on this feed.</description>
    </item>
    <item>
      <title>CVE-2023-20118 — Cisco Small Business RV Series Routers RV320, RV325, RV042, RV042G, RV082 (exploited, no patch coming)</title>
      <link>https://endoflife.ai/exploited-and-unpatchable#CVE-2023-20118</link>
      <guid isPermaLink="false">endoflife.ai:eu:cisco-rv:CVE-2023-20118</guid>
      <pubDate>Fri, 04 Sep 2026 00:00:00 GMT</pubDate>
      <description>Command injection in the web-based management interface of the Cisco Small Business RV016, RV042, RV042G, RV082, RV320 and RV325 routers: improper validation of user input in incoming HTTP packets lets an authenticated, remote attacker send a crafted request and execute arbitrary commands with root-level privileges. Valid administrative credentials are required, which is why NVD rates it 7.2 rather than 9.8; CISA confirmed exploitation in the wild when it added the CVE to the KEV catalog on 2025-03-03, and CISA's required action includes 'discontinue use of the product if mitigations are unavailable.' Why unpatchable: Cisco names six models as vulnerable and states in the advisory that it will not release software updates for them; the only mitigation is disabling remote management or restricting access to the affected feature. Every named model with a Cisco end-of-life bulletin is past its Last Date of Support (RV320/RV325 and RV042/RV042G on 2025-01-31, RV082 on 2021-05-31); RV016 is named by Cisco but carries no separate bulletin and is not modelled here. No fixed firmware exists for any of them and Cisco says none will come. The vendor's decision not to patch (stated January 2023) and the models' end-of-support dates are separate facts: the advisory predates the RV320/RV325/RV042 end of support by two years.</description>
    </item>
    <item>
      <title>CVE-2022-26258 — D-Link DIR-820L DIR-820L (exploited, no patch coming)</title>
      <link>https://endoflife.ai/exploited-and-unpatchable#CVE-2022-26258</link>
      <guid isPermaLink="false">endoflife.ai:eu:dlink-routers:CVE-2022-26258</guid>
      <pubDate>Fri, 04 Sep 2026 00:00:00 GMT</pubDate>
      <description>Remote command execution in the D-Link DIR-820L (firmware 1.05B03, the last release): an unauthenticated HTTP POST to the get/set ccp handler injects OS commands (CWE-78). NVD scores it 9.8. CISA added it to the KEV catalog on 2022-09-08 with the required action 'The impacted product is end-of-life and should be disconnected if still in use.' Why unpatchable: 1.05B03 is the final DIR-820L firmware and the version NVD names as affected. D-Link's EOL notice states that all firmware development for the model ceased, and its June 2026 notice SAP10508 lists DIR-820L again among the legacy EOL/EOS routers being compromised by the AryStinger botnet, with the same instruction: retire and replace. CISA's required action for this CVE is to disconnect the device. The model's end of support (2017-11-01) predates the CVE by more than four years; D-Link has never issued a fix and says it will not develop one.</description>
    </item>
    <item>
      <title>CVE-2026-81578 — PaperCut NG/MF 23 and earlier (exploited, no patch coming)</title>
      <link>https://endoflife.ai/exploited-and-unpatchable#CVE-2026-81578</link>
      <guid isPermaLink="false">endoflife.ai:eu:papercut-ng-mf:CVE-2026-81578</guid>
      <pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate>
      <description>Missing authentication for critical function in the web management interface: under specific conditions, unauthenticated remote requests targeting administrative functions trigger backend actions before access validation completes, letting an unauthenticated remote attacker modify certain system configurations. Chains with CVE-2026-82078 (unsafe dynamic class loading) into pre-auth remote code execution. Why unpatchable: Same vendor decision as CVE-2026-82078, with which this chains: PaperCut publishes no end-of-life calendar, and its September 2026 advisory states the path for everything before v24 is upgrade - Emergency Patch Release 3 shipped for v24/v25/v26 only. The two CVEs together are the exploited-in-the-wild chain (unauthenticated configuration modification feeding unsafe class loading); a v23-or-earlier server exposed to the internet has no patch coming for either half. CISA's required action includes discontinuing use where mitigations are unavailable.</description>
    </item>
    <item>
      <title>CVE-2026-82078 — PaperCut NG/MF 23 and earlier (exploited, no patch coming)</title>
      <link>https://endoflife.ai/exploited-and-unpatchable#CVE-2026-82078</link>
      <guid isPermaLink="false">endoflife.ai:eu:papercut-ng-mf:CVE-2026-82078</guid>
      <pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate>
      <description>Unsafe dynamic class loading in the database connection utilities: the application instantiates database driver classes from configurable driver names without an allowlist, letting an attacker who can modify configuration execute arbitrary Java bytecode on the classpath under the PaperCut server process. Chains with CVE-2026-81578 (unauthenticated configuration modification) into pre-auth remote code execution. Why unpatchable: PaperCut publishes no end-of-life calendar - support rides Maintenance &amp; Support contracts, and whether an old line gets a fix is decided per release. This time the vendor decided in writing: the September 2026 advisory's stated path for everything before v24 is upgrade, and Emergency Patch Release 3 shipped for v24/v25/v26 only, against attacks PaperCut says it has 'observed being exploited in the wild.' The no-fix status of 23 and earlier is the vendor's declared position, not an end-of-life inference - notable because PaperCut HAS backported before (the coordinated March 2024 security release covered lines 20-22). CISA's required action includes discontinuing use where mitigations are unavailable.</description>
    </item>
    <item>
      <title>CVE-2025-5777 — NetScaler ADC 13.0 (all builds), 12.1 (standard; the separately-dated 12.1-FIPS variant received a build) (exploited, no patch coming)</title>
      <link>https://endoflife.ai/exploited-and-unpatchable#CVE-2025-5777</link>
      <guid isPermaLink="false">endoflife.ai:eu:netscaler-adc:CVE-2025-5777</guid>
      <pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate>
      <description>Out-of-bounds read in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server - insufficient input validation lets unauthenticated requests leak memory contents, including session tokens usable for session hijacking (the 'CitrixBleed 2' pattern). Widely exploited against internet-facing appliances. Why unpatchable: Cloud Software Group's own bulletin declares the end-of-life lines vulnerable and offers them no build: standard 12.1 (EOL May 30, 2023) and all of 13.0 (EOL July 15, 2024) are stated to be vulnerable with upgrade as the only path - precision note: the 12.1-FIPS compliance variant, which carries its own later lifecycle dates, did receive a fixed build, underscoring that the standard-line omission is a lifecycle decision rather than technical impossibility. CISA added the CVE to KEV with a one-day federal remediation window (added July 10, due July 11, 2025), among the shortest on record.</description>
    </item>
    <item>
      <title>CVE-2025-22457 — Ivanti Connect Secure Pulse Connect Secure 9.1x (9.1R18.9 and prior) (exploited, no patch coming)</title>
      <link>https://endoflife.ai/exploited-and-unpatchable#CVE-2025-22457</link>
      <guid isPermaLink="false">endoflife.ai:eu:ivanti-connect-secure:CVE-2025-22457</guid>
      <pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate>
      <description>Stack-based buffer overflow in Ivanti Connect Secure / Pulse Connect Secure allowing a remote unauthenticated attacker to achieve remote code execution on the VPN appliance. Initially triaged by Ivanti as a non-exploitable product bug, later confirmed exploitable 'through sophisticated means' with active exploitation in the wild. Why unpatchable: Ivanti's advisory is unusually explicit for this case: 'Pulse Connect Secure 9.1x reached End-of-Support on December 31, 2024, and no longer receives any code changes. Ivanti cannot provide guidance to customers to stay on an unsupported version. Customers' only option is to migrate to a secure platform.' Rarer still, the vendor confirmed exploitation observed on the end-of-support line itself - not inferred exposure. Ivanti's FAQ adds that reporting on EoS products is discretionary and 'Ivanti will not provide any troubleshooting or code change for products that are no longer supported.'</description>
    </item>
    <item>
      <title>CVE-2015-3246 — Red Hat Enterprise Linux 5 (exploited, no patch coming)</title>
      <link>https://endoflife.ai/exploited-and-unpatchable#CVE-2015-3246</link>
      <guid isPermaLink="false">endoflife.ai:eu:rhel:CVE-2015-3246</guid>
      <pubDate>Thu, 27 Aug 2026 00:00:00 GMT</pubDate>
      <description>libuser /etc/passwd race condition - a local authenticated user can corrupt /etc/passwd via a libuser-compiled application (such as userhelper), causing denial of service; chained with CVE-2015-3245 (fixed in the same errata pair) it escalates privileges to root. CISA's KEV entry describes the outcome as denial of service or privilege escalation. Why unpatchable: Red Hat's own CVE record states the flaw 'affects the versions of libuser as shipped with Red Hat Enterprise Linux 5' and 'is not currently planned to be addressed in future updates' - the fix shipped only for RHEL 6 (RHSA-2015:1482) and RHEL 7 (RHSA-2015:1483). That decision was made in 2015, while RHEL 5 was in its Production 3 phase; RHEL 5 has since exited every support phase (end of production 2017-03-31, Extended Life-cycle Support ended 2020-11-30), so no fix will ever exist.</description>
    </item>
    <item>
      <title>CVE-2025-24813 — Apache Tomcat 8.5 (exploited, no patch coming)</title>
      <link>https://endoflife.ai/exploited-and-unpatchable#CVE-2025-24813</link>
      <guid isPermaLink="false">endoflife.ai:eu:tomcat:CVE-2025-24813</guid>
      <pubDate>Thu, 27 Aug 2026 00:00:00 GMT</pubDate>
      <description>Path-equivalence flaw in the default servlet's partial PUT handling. Under specific configurations an unauthenticated remote attacker can view or inject content into uploaded files; with file-based session persistence at the default location plus a deserialization-gadget library on the classpath, it escalates to remote code execution. Exploitation requires writes enabled on the default servlet (disabled by default) and partial PUT support (enabled by default) - not every default install is exposed, but exploitation in the wild is established (KEV). CISA notes it can be chained with CVE-2026-34486. Why unpatchable: Apache's own CVE record names Tomcat 8.5.0 through 8.5.100 - the entire 8.5 line, through its final release - as known affected, while the recommended fixes are 11.0.3, 10.1.35 and 9.0.99 only. Tomcat 8.5 had reached end of life on 2024-03-31, nearly a year before this CVE was published, and its final release (8.5.100) shipped 2024-03-19. Apache's 8.x security page states that vulnerabilities reported after 31 March 2024 'are not listed below and will not be fixed.' No fixed 8.5 release exists and none will come.</description>
    </item>
    <item>
      <title>CVE-2026-73570 — Zimbra Collaboration Suite (ZCS) 10.0 (End of General Support 2025-06-30; last patch 10.0.18 on 2025-11-06), 9.0 (End of Technical Guidance 2025-06-30; last patch 9.0.0 P46 on 2025-06-18), 8.8.15 LTS (End of Technical Guidance 2024-12-31) (exploited, no patch coming)</title>
      <link>https://endoflife.ai/exploited-and-unpatchable#CVE-2026-73570</link>
      <guid isPermaLink="false">endoflife.ai:eu:zimbra:CVE-2026-73570</guid>
      <pubDate>Sat, 22 Aug 2026 00:00:00 GMT</pubDate>
      <description>OS command injection in the SNMP monitoring component (optional zimbra-snmp package, SNMP notifications enabled): unauthenticated attacker sends specially crafted SMTP requests that result in arbitrary OS command execution as the zimbra user. Active exploitation campaign confirmed by CERT Polska 2026-08-17. Why unpatchable: The only fix release is 10.1.20. Zimbra's release index marks 10.0, 9.0 and 8.8.15 as past support, and the 2026 advisory history confirms the backport window is closed: of sixteen CVE-2026 advisory rows, fifteen list a 10.1.x fix only; the single 10.0.x fix (10.0.18, 2025-11-06) was 10.0's last patch. Framing guardrail: the defensible claim is 'no fix exists for these lines and they are past vendor support' — NOT 'these lines are confirmed exploited'. The vulnerable code path requires the optional SNMP package plus notifications enabled, which an operator can verify and disable as a stopgap; that mitigation is vendor-documented only as a precondition, not as an advisory-recommended workaround.</description>
    </item>
    <item>
      <title>CVE-2026-64849 — MLflow 2, 1 (exploited, no patch coming)</title>
      <link>https://endoflife.ai/exploited-and-unpatchable#CVE-2026-64849</link>
      <guid isPermaLink="false">endoflife.ai:eu:mlflow:CVE-2026-64849</guid>
      <pubDate>Thu, 20 Aug 2026 00:00:00 GMT</pubDate>
      <description>Unauthenticated full-read server-side request forgery in webhook delivery; URL validation bypassed via unvalidated HTTP redirects or DNS rebinding, reaching internal and cloud metadata services Why unpatchable: MLflow publishes no lifecycle policy and has never announced end of life for the 2.x line. Separately: 2.x has been silent since 2.22.5 (2026-05-12) and the fix for this actively exploited flaw ships only in 3.15.0 - no 2.x release containing it exists, and no commercial extended-support vendor covers MLflow. End of life here is de facto, evidenced by release behaviour, not vendor declaration; the affected-but-never-fixed status of 2.x is documented fact.</description>
    </item>
    <item>
      <title>CVE-2026-63077 — JetBrains TeamCity 2025.07, 2025.03, 2024.12, 2024.07, 2024.03, 2023.11, 2023.05, 2022.10, 2022.04 (exploited, no patch coming)</title>
      <link>https://endoflife.ai/exploited-and-unpatchable#CVE-2026-63077</link>
      <guid isPermaLink="false">endoflife.ai:eu:teamcity:CVE-2026-63077</guid>
      <pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate>
      <description>Unauthenticated remote code execution via the agent polling protocol Why unpatchable: JetBrains provides security fixes only for the current and immediately previous release lines. The fix exists solely in 2025.11.7 and 2026.1.3; every earlier line is past end of support and receives no update for this actively exploited flaw.</description>
    </item>
    <item>
      <title>CVE-2025-68686 — Fortinet FortiOS 7.0, 6.4 (exploited, no patch coming)</title>
      <link>https://endoflife.ai/exploited-and-unpatchable#CVE-2025-68686</link>
      <guid isPermaLink="false">endoflife.ai:eu:fortios:CVE-2025-68686</guid>
      <pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate>
      <description>Symlink-based persistence that survives patching — a post-exploitation weakness abused after a threat actor has already exploited a separate filesystem-level vulnerability. KEV-listed by CISA. Why unpatchable: Fortinet's advisory FG-IR-25-934 lists 'FortiOS 7.0 all versions' and '6.4 all versions' as affected, and gives their only remediation as 'Migrate to a fixed release' — no fixed build is or will be published for either branch. FortiOS 7.0 reached end of support 2025-09-30 and 6.4 on 2024-09-30. (The current 7.2 branch is also given no build but is excluded here because it remains supported until 2026-09-30.)</description>
    </item>
    <item>
      <title>CVE-2026-34197 — Apache ActiveMQ 6.1, 6.0, 5.18, 5.17, 5.16 (exploited, no patch coming)</title>
      <link>https://endoflife.ai/exploited-and-unpatchable#CVE-2026-34197</link>
      <guid isPermaLink="false">endoflife.ai:eu:apache-activemq:CVE-2026-34197</guid>
      <pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate>
      <description>Remote code execution via the Jolokia JMX-HTTP bridge — effectively unauthenticated on the 6.0 and 6.1 lines (the console's Jolokia endpoint sits outside the security constraints per CVE-2024-32114), and authenticated on the 5.x lines Why unpatchable: The fix ships only in the 5.19.x line (5.19.4) and in 6.2.3. Every ActiveMQ line below that — 6.0, 6.1, and 5.16 through 5.18 — is past end of life and receives no backport; all fall within the vendor's affected range with no available patch. The 6.0/6.1 lines are the most exposed, being effectively unauthenticated.</description>
    </item>
    <item>
      <title>CVE-2025-49113 — Roundcube Webmail 1.4, 1.3, 1.2 (exploited, no patch coming)</title>
      <link>https://endoflife.ai/exploited-and-unpatchable#CVE-2025-49113</link>
      <guid isPermaLink="false">endoflife.ai:eu:roundcube:CVE-2025-49113</guid>
      <pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate>
      <description>Authenticated remote code execution via PHP object deserialization in the file-upload handler (the _from request parameter). The vulnerable code path had been present in the codebase for roughly a decade. Why unpatchable: The fix shipped only in 1.5.10 and 1.6.11. NVD's authoritative affected range (versionStartIncluding 0, versionEndExcluding 1.5.10) places the 1.4, 1.3 and 1.2 lines within scope, and no fixed point release was issued for any of them — all three are past end of life. Basis is stated explicitly (NVD range plus the documented decade-long presence of the deserialization path); the entry is removed if a backport later appears.</description>
    </item>
    <item>
      <title>CVE-2024-37085 — VMware ESXi 7.0 (exploited, no patch coming)</title>
      <link>https://endoflife.ai/exploited-and-unpatchable#CVE-2024-37085</link>
      <guid isPermaLink="false">endoflife.ai:eu:esxi:CVE-2024-37085</guid>
      <pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate>
      <description>Active Directory integration authentication bypass — a member of a domain group named 'ESX Admins' gains full host administrative access. Exploited in the wild by ransomware operators (Akira, Black Basta). Why unpatchable: Broadcom's own advisory matrix (VMSA-2024-0013) lists ESXi 7.0 as affected with fixed version 'No Patch Planned' — the fix ships only in 8.0 U3, and Broadcom stated in writing that 7.0 will receive no patched build. Only a manual Active Directory reconfiguration workaround exists. ESXi 7.0 reached end of general support on 2025-10-02, so no update will come.</description>
    </item>
    <item>
      <title>CVE-2023-22518 — Atlassian Confluence Server &amp; Data Center 7.0–7.18 (non-LTS), 6.x, 5.x (exploited, no patch coming)</title>
      <link>https://endoflife.ai/exploited-and-unpatchable#CVE-2023-22518</link>
      <guid isPermaLink="false">endoflife.ai:eu:confluence:CVE-2023-22518</guid>
      <pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate>
      <description>Improper authorization allowing an unauthenticated attacker to reset Confluence and create an administrator account, leading to full compromise. Mass-exploited (including ransomware) since November 2023. Why unpatchable: The only 7.x fix shipped on the 7.19 LTS line (7.19.16); every earlier non-LTS 7.x branch and all of 6.x and 5.x fall under the advisory's 'all versions prior to the listed fix versions' and received no fixed release for this actively exploited authorization bypass. All are past end of life (Confluence Server as a whole reached end of life 2024-02-15). This is a distinct CVE from the other Confluence entries; the 8.0–8.2 branches are deliberately excluded as a normal non-LTS lifecycle case rather than an abandoned-branch one.</description>
    </item>
    <item>
      <title>CVE-2022-26134 — Atlassian Confluence Server &amp; Data Center 6.x (exploited, no patch coming)</title>
      <link>https://endoflife.ai/exploited-and-unpatchable#CVE-2022-26134</link>
      <guid isPermaLink="false">endoflife.ai:eu:confluence:CVE-2022-26134</guid>
      <pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate>
      <description>Unauthenticated OGNL injection allowing remote code execution. Mass-exploited in the wild since June 2022. Why unpatchable: Atlassian's advisory names every release after 1.3.0 as affected but shipped fixes only on the 7.4 and 7.13–7.18 branches. Confluence 6.x was already past end of life at the June 2022 disclosure and received no fixed build for this actively exploited RCE. (Confluence Server as a whole reached end of life 2024-02-15.) Branches that did receive a per-branch backport are deliberately excluded.</description>
    </item>
    <item>
      <title>CVE-2019-10149 — Exim 4.91 (exploited, no patch coming)</title>
      <link>https://endoflife.ai/exploited-and-unpatchable#CVE-2019-10149</link>
      <guid isPermaLink="false">endoflife.ai:eu:exim:CVE-2019-10149</guid>
      <pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate>
      <description>Improper validation of the recipient address in deliver_message() allowing remote command execution as root ('Return of the WIZard'). Mass-exploited in the wild. Why unpatchable: The Exim advisory names 4.87 through 4.91 as affected and delivers the fix only as the forward 4.92 release — no patched build was issued for the 4.91 line, which reached end of life 2019-02-10. Under Exim's model the only remediation is to upgrade off the dead branch.</description>
    </item>
    <item>
      <title>CVE-2019-0193 — Apache Solr 7, 6, 5 (exploited, no patch coming)</title>
      <link>https://endoflife.ai/exploited-and-unpatchable#CVE-2019-0193</link>
      <guid isPermaLink="false">endoflife.ai:eu:solr:CVE-2019-0193</guid>
      <pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate>
      <description>Remote code execution via the DataImportHandler dataConfig request parameter, which accepts a full DIH configuration including a script transformer. Why unpatchable: The mitigation exists only from Solr 8.2.0 onward; no fixed release was issued for the 7.x, 6.x or 5.x lines, all past end of life. The DataImportHandler that carries the flaw shipped in every one of these versions, and none received a backport.</description>
    </item>
    <item>
      <title>CVE-2021-26084 — Atlassian Confluence Server &amp; Data Center 6.0–6.12 (exploited, no patch coming)</title>
      <link>https://endoflife.ai/exploited-and-unpatchable#CVE-2021-26084</link>
      <guid isPermaLink="false">endoflife.ai:eu:confluence:CVE-2021-26084</guid>
      <pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate>
      <description>Unauthenticated OGNL injection allowing remote code execution. Widely exploited since 2021 and on CISA's KEV catalog. Why unpatchable: Atlassian's advisory lists the 4.x, 5.x and 6.0–6.12 lines among affected versions but issued fixed builds only on 6.13, 7.4, 7.11, 7.12 and 7.13. The 6.0–6.12 lines were past end of life at disclosure and received no fixed build for this actively exploited RCE. The 6.13 branch, which did receive a backport, is excluded.</description>
    </item>
    <item>
      <title>CVE-2020-17530 — Apache Struts 2.3 (exploited, no patch coming)</title>
      <link>https://endoflife.ai/exploited-and-unpatchable#CVE-2020-17530</link>
      <guid isPermaLink="false">endoflife.ai:eu:apache-struts:CVE-2020-17530</guid>
      <pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate>
      <description>Forced OGNL double-evaluation of attacker-supplied input allowing remote code execution (S2-061). Why unpatchable: S2-061 lists the affected range as Struts 2.0.0 through 2.5.25 and ships the fix only in 2.5.26. The Struts 2.3 line ended at 2.3.37 and reached end of life on 2019-05-14 — eighteen months before this advisory — so no 2.3.x fix was ever released. A 2.3.x install cannot patch in place. (The 2.5 line is excluded: 2.5.26 is a same-line fix and 2.5 was supported until 2024-04-30.)</description>
    </item>
    <item>
      <title>CVE-2019-17558 — Apache Solr 7, 6, 5 (exploited, no patch coming)</title>
      <link>https://endoflife.ai/exploited-and-unpatchable#CVE-2019-17558</link>
      <guid isPermaLink="false">endoflife.ai:eu:solr:CVE-2019-17558</guid>
      <pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate>
      <description>Remote code execution via the VelocityResponseWriter when params.resource.loader.enabled is set, allowing a Velocity template to be supplied and executed. Why unpatchable: The vulnerable parameters-based resource loader was removed only in Solr 8.4; no fixed release was issued for the 7.x, 6.x or 5.x lines (the 7.x line ended at 7.7.2), all past end of life. Every one of these versions is inside the vendor's 5.0.0–8.3.1 affected range with no available patch.</description>
    </item>
  </channel>
</rss>
