Possible exploit chains
KCV Watch™
Pairs of CVEs whose exploit steps connect, ranked each night.
An exploit chain joins two flaws so that the first supplies what the second needs, such as an authentication bypass that opens the way to a code execution bug. Known Chained Vulnerabilities (KCV)™ holds the chains that cited sources report. KCV Watch™ looks for the pairs no source has named yet. Each night it reads what each CVE's exploit needs and what it gains, pairs the CVEs whose steps connect or whose records tie them together, and places each pair in one of three tiers by how often pairs with the same signals turned out to be reported chains. The full list, the keyed API and the nightly download are on cve-security.com. This page carries tonight's strongest pairs, the Breaking watch and the rates behind the tiers.
Breaking watch
Connected pairs on one product where a CVE carries an exploitation report or field sighting. A pair joins the watch the day it qualifies and stays for a set time: 30 days from a joint disclosure, or 90 days from the second report when both CVEs carry one. The watch adds no rate of its own, so each pair keeps its tier. The newest eight of tonight's 100 are here.
- Tier CJoomshaper Com Easy Store Extension For JoomlaOn the watch 2026-10-02 to 2026-10-31CVECVE-2026-65761Joomla extension joomshaper.com unauthenticated SQL injection in Easy Store extension
CVE-2026-65760 and CVE-2026-65761 were disclosed the same day and share a third-party advisory; VulnCheck Known Exploited Vulnerabilities (VulnCheck KEV) added CVE-2026-65761 on Oct. 2, 2026. A successful chained exploit could combine the two.
- Tier BRejetto HfsOn the watch 2026-10-01 to 2026-10-30
CVE-2026-61500 and CVE-2026-61502 were disclosed the same day and share a patch and a fixed version; VulnCheck Known Exploited Vulnerabilities (VulnCheck KEV) added CVE-2026-61500 on Oct. 1, 2026. A successful chained exploit could combine the two.
- Tier BRejetto HfsOn the watch 2026-10-01 to 2026-10-30
CVE-2026-61500 and CVE-2026-61503 were disclosed the same day and share a patch and a fixed version; VulnCheck Known Exploited Vulnerabilities (VulnCheck KEV) added CVE-2026-61500 on Oct. 1, 2026. A successful chained exploit could combine the two.
- Tier CRejetto HfsOn the watch 2026-10-01 to 2026-10-30
CVE-2026-61500 and CVE-2026-61504 were disclosed the same day and share a patch and a fixed version; VulnCheck Known Exploited Vulnerabilities (VulnCheck KEV) added CVE-2026-61500 on Oct. 1, 2026. A successful chained exploit could combine the two.
- Tier BYonyou U8 CrmOn the watch 2026-09-30 to 2026-12-28
VulnCheck Known Exploited Vulnerabilities (VulnCheck KEV) added CVE-2024-58385 on Sept. 15, 2026, and VulnCheck KEV added CVE-2023-54403 on Sept. 30, 2026, 15 days later. A successful chained exploit could combine the two.
- CVECVE-2026-8452 KEVCitrix NetScaler ADC and NetScaler Gateway improper restriction of operations within the bounds of a memory bufferCVECVE-2026-88772 KEVCitrix NetScaler improper restriction of operations within the bounds of a memory buffer
VulnCheck Known Exploited Vulnerabilities (VulnCheck KEV) added CVE-2026-8452 on Aug. 17, 2026, and CISA KEV added CVE-2026-88772 on Sept. 27, 2026, 41 days later. A successful chained exploit could combine the two.
- CVECVE-2026-42608Grav: Unauthenticated path traversal and arbitrary file write in FormFlash componentCVECVE-2026-42609Grav: Administrative Account Disruption and Privilege De-escalation via User Overwrite Logic
CVE-2026-42608 and CVE-2026-42609 were disclosed the same day and share a patch; VulnCheck Known Exploited Vulnerabilities (VulnCheck KEV) added CVE-2026-42608 on Sept. 25, 2026. A successful chained exploit could combine the two.
- CVECVE-2026-42608Grav: Unauthenticated path traversal and arbitrary file write in FormFlash component
CVE-2026-42608 and CVE-2026-42610 were disclosed the same day and share a patch; VulnCheck Known Exploited Vulnerabilities (VulnCheck KEV) added CVE-2026-42608 on Sept. 25, 2026. A successful chained exploit could combine the two.
All 100 pairs on the Breaking watch, with the rule that admits them
Tonight's top 24
Tier A pairs, ordered by how many of the two CVEs carry an exploitation report or field sighting and then by the newest disclosure. A product shows at most two pairs here. Where the capability analysis reads an entry step, the pair reads from it to the next step. Follow a CVE to its page on cve-security.com for its capabilities, sources and vendor fixes.
- Entry stepCVE-2026-88772 KEVCitrix NetScaler improper restriction of operations within the bounds of a memory bufferConnects through code execution on the hostNext stepCVE-2026-8452 KEVCitrix NetScaler ADC and NetScaler Gateway improper restriction of operations within the bounds of a memory buffer
CVE-2026-88772 yields code execution, and CVE-2026-8452 requires a control bypass. A successful chained exploit could advance the intrusion.
- Tier AGeonetwork Core GeonetworkExploitation report or field sighting on both CVEsConnects through related capability the next step could use
CVE-2026-63219 yields a data write, and CVE-2026-58400 requires that privilege. A successful chained exploit could advance the intrusion.
- Connects through related capability the next step could use
CVE-2026-63520 yields code execution, and CVE-2026-65660 requires that privilege. A successful chained exploit could advance the intrusion.
- Connects through related capability the next step could use
CVE-2025-71324 yields file access, and CVE-2025-71334 requires file access. A successful chained exploit could advance the intrusion.
- Connects through related capability the next step could use
CVE-2026-40217 yields code execution, and CVE-2026-42271 requires that privilege. A successful chained exploit could advance the intrusion.
- Connects through code execution on the host
CVE-2026-40466 yields code execution, and CVE-2026-34197 requires credentials. A successful chained exploit could advance the intrusion.
- Connects through privilege gain inside the product
CVE-2025-59719 yields an elevated identity, and CVE-2025-58034 requires that privilege. A successful chained exploit could advance the intrusion.
- Tier AHikvision Csmp Isecure CenterExploitation report or field sighting on both CVEsConnects through code execution on the host
CVE-2024-58274 yields code execution, and CVE-2023-53691 requires file access. A successful chained exploit could advance the intrusion.
- Connects through privilege gain by a logged-in user
CVE-2025-61955 yields a privilege gain for a logged-in user, and CVE-2025-57780 requires that foothold. A successful chained exploit could advance the intrusion.
- Connects through code execution on the hostNext stepCVE-2025-20333 KEVCisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) buffer overflow
CVE-2025-20363 yields code execution, and CVE-2025-20333 requires credentials. A successful chained exploit could advance the intrusion.
- Connects through related capability the next step could use
CVE-2025-53690 yields code execution, and CVE-2025-34510 requires that privilege. A successful chained exploit could advance the intrusion.
- Connects through related capability the next step could use
CVE-2025-53690 yields code execution, and CVE-2025-34511 requires that foothold. A successful chained exploit could advance the intrusion.
- Connects through related capability the next step could use
CVE-2025-7775 yields code execution, and CVE-2025-6543 requires a control bypass. A successful chained exploit could advance the intrusion.
- Tier AMerit Lilin Dvr FirmwareExploitation report or field sighting on both CVEsConnects through reusable credential
CVE-2025-34130 yields a reusable credential, and CVE-2025-34129 requires that foothold. A successful chained exploit could advance the intrusion.
- Connects through privilege gain inside the product
CVE-2025-34034 yields an elevated identity, and CVE-2025-34033 requires that privilege. A successful chained exploit could advance the intrusion.
- Connects through code execution on the host
CVE-2025-47165 yields code execution, and CVE-2025-47176 requires file access. A successful chained exploit could advance the intrusion.
- Connects through related capability the next step could use
CVE-2025-47176 yields code execution, and CVE-2025-47170 requires that foothold. A successful chained exploit could advance the intrusion.
- Entry stepCVE-2025-48927 KEVTeleMessage TM SGNL initialization of a resource with an insecure defaultConnects through reusable credential
CVE-2025-48927 yields a reusable credential, and CVE-2025-48928 requires that foothold. A successful chained exploit could advance the intrusion.
- Connects through reusable credential
CVE-2025-32814 yields a reusable credential, and CVE-2025-32813 requires that foothold. A successful chained exploit could advance the intrusion.
- Connects through related capability the next step could use
CVE-2025-2609 yields a data write, and CVE-2025-2610 requires that privilege. A successful chained exploit could advance the intrusion.
- Entry stepCVE-2024-12084Rsync: Heap buffer overflow in rsync due to improper checksum length handlingConnects through code execution on the host
CVE-2024-12084 yields code execution, and CVE-2024-12087 requires file access. A successful chained exploit could advance the intrusion.
- Tier AI O Data Device Inc Ud Lt1Exploitation report or field sighting on both CVEsConnects through reusable credential
CVE-2024-45841 yields a reusable credential, and CVE-2024-47133 requires that foothold. A successful chained exploit could advance the intrusion.
- Tier AI O Data Device Inc Ud Lt1Exploitation report or field sighting on both CVEsConnects through code execution on the host
CVE-2024-52564 yields code execution, and CVE-2024-45841 requires credentials. A successful chained exploit could advance the intrusion.
- Connects through privilege gain inside the productNext stepCVE-2023-50386Apache Solr: Backup/Restore APIs allow for deployment of executables in malicious ConfigSets
CVE-2024-45216 yields an elevated identity, and CVE-2023-50386 requires that privilege. A successful chained exploit could advance the intrusion.
The whole list on cve-security.com: tiers A and B, filtered by product, bridge or capability
How often a tier holds a chain
Each tier is a measured rate. The build takes the pairs whose later CVE is at least 90 days old, so a source has had time to report a chain, and counts how many are known chains in KCV. A tier promises a floor, and the last measurement, on Oct. 7, 2026, sits beside it.
- Tier A521 pairs tonightAt least one in 25About one in 20 at the last measurement
- Tier B7,856 pairs tonightAt least one in 100About one in 40 at the last measurement
- Tier C51,672 pairs, in the download and the APIAt least one in 1,000About one in 350 at the last measurement
Each dot is one pair, and the lit dot is the chain the floor promises. A rate describes the group of pairs that share a row's signals and prints on no single row. A tier A pair may still fail in practice, and a pair outside the list may still chain.
What the list counts
- A capability
- For each CVE with a CVSS vector, a fixed rule reads the vector, the weakness class and the description for what an exploit needs to start and what it gains, on a fixed vocabulary. Where the dataset holds exploit code or a patch diff, a model reads those as well, and a second model answers what each flaw does on its own.
- A pair
- Two CVEs form a candidate when one CVE's gain meets what the other needs through a named bridge, such as an authentication bypass that opens the foothold a second flaw needs. The pair passes a fixed gate: the second step advances the attacker, at least one of the two can be reached without local access, and no cited source names the pair in a known chain yet. Other pairs enter on their records, such as exploitation reports on both CVEs within 90 days or a joint disclosure with a shared advisory, patch or fixed version.
- The tiers
- Four record facts set a pair's score: how close the two disclosure dates are, a shared advisory or patch, a shared fixed version, and how many of the two CVEs carry an exploitation report or field sighting. A pair reaches tier A only with a documented handoff between its two CVEs, and a pair across two products reaches tier B at most. This page and the list show tiers A and B; tier C is in the download and the API.
- Exploitation
- A report or field sighting comes from CISA KEV, VulnCheck Known Exploited Vulnerabilities (VulnCheck KEV) and the other trackers cve-security.com reads, plus sensor sightings. A KEV chip marks each CVE that CISA lists.
- What a pair says
- A pair on this page is a possible chain, published for teams to research. Confirmation belongs to Known Chained Vulnerabilities (KCV)™, where a cited source reports the two CVEs used together. Two CVEs named in one thread count as discussion until a source reports them used together.