Built 2026-10-06 22:21 UTC, rebuilt nightly Sister site kev.watch: exploitation reports ahead of CISA
kcv.watchKCV Watch™ by CVE Security

Possible exploit chains

KCV Watch™

Pairs of CVEs whose exploit steps connect, ranked each night.

An exploit chain joins two flaws so that the first supplies what the second needs, such as an authentication bypass that opens the way to a code execution bug. Known Chained Vulnerabilities (KCV)™ holds the chains that cited sources report. KCV Watch™ looks for the pairs no source has named yet. Each night it reads what each CVE's exploit needs and what it gains, pairs the CVEs whose steps connect or whose records tie them together, and places each pair in one of three tiers by how often pairs with the same signals turned out to be reported chains. The full list, the keyed API and the nightly download are on cve-security.com. This page carries tonight's strongest pairs, the Breaking watch and the rates behind the tiers.

01

Breaking watch

Connected pairs on one product where a CVE carries an exploitation report or field sighting. A pair joins the watch the day it qualifies and stays for a set time: 30 days from a joint disclosure, or 90 days from the second report when both CVEs carry one. The watch adds no rate of its own, so each pair keeps its tier. The newest eight of tonight's 100 are here.

  1. Tier CJoomshaper Com Easy Store Extension For JoomlaOn the watch 2026-10-02 to 2026-10-31
    CVECVE-2026-65760JoomShaper Easy Store order management information disclosure
    CVECVE-2026-65761Joomla extension joomshaper.com unauthenticated SQL injection in Easy Store extension

    CVE-2026-65760 and CVE-2026-65761 were disclosed the same day and share a third-party advisory; VulnCheck Known Exploited Vulnerabilities (VulnCheck KEV) added CVE-2026-65761 on Oct. 2, 2026. A successful chained exploit could combine the two.

  2. Tier BRejetto HfsOn the watch 2026-10-01 to 2026-10-30
    CVECVE-2026-61500Rejetto HFS Session Forgery via Predictable Signing Key
    CVECVE-2026-61502Rejetto HFS cross-site request forgery via GET requests

    CVE-2026-61500 and CVE-2026-61502 were disclosed the same day and share a patch and a fixed version; VulnCheck Known Exploited Vulnerabilities (VulnCheck KEV) added CVE-2026-61500 on Oct. 1, 2026. A successful chained exploit could combine the two.

  3. Tier BRejetto HfsOn the watch 2026-10-01 to 2026-10-30
    CVECVE-2026-61500Rejetto HFS Session Forgery via Predictable Signing Key
    CVECVE-2026-61503Rejetto HFS Username Enumeration via Login Response Differences

    CVE-2026-61500 and CVE-2026-61503 were disclosed the same day and share a patch and a fixed version; VulnCheck Known Exploited Vulnerabilities (VulnCheck KEV) added CVE-2026-61500 on Oct. 1, 2026. A successful chained exploit could combine the two.

  4. Tier CRejetto HfsOn the watch 2026-10-01 to 2026-10-30
    CVECVE-2026-61500Rejetto HFS Session Forgery via Predictable Signing Key
    CVECVE-2026-61504Rejetto HFS stored XSS via File Names in Basic Web Listing

    CVE-2026-61500 and CVE-2026-61504 were disclosed the same day and share a patch and a fixed version; VulnCheck Known Exploited Vulnerabilities (VulnCheck KEV) added CVE-2026-61500 on Oct. 1, 2026. A successful chained exploit could combine the two.

  5. Tier BYonyou U8 CrmOn the watch 2026-09-30 to 2026-12-28
    CVECVE-2023-54403Yonyou U8 CRM arbitrary file read via getemaildata.php
    CVECVE-2024-58385Yonyou U8 CRM SQL injection via fillbacksettingedit.php

    VulnCheck Known Exploited Vulnerabilities (VulnCheck KEV) added CVE-2024-58385 on Sept. 15, 2026, and VulnCheck KEV added CVE-2023-54403 on Sept. 30, 2026, 15 days later. A successful chained exploit could combine the two.

  6. Tier ANetscaler application delivery controllerOn the watch 2026-09-27 to 2026-12-25
    CVECVE-2026-8452 KEVCitrix NetScaler ADC and NetScaler Gateway improper restriction of operations within the bounds of a memory buffer
    CVECVE-2026-88772 KEVCitrix NetScaler improper restriction of operations within the bounds of a memory buffer

    VulnCheck Known Exploited Vulnerabilities (VulnCheck KEV) added CVE-2026-8452 on Aug. 17, 2026, and CISA KEV added CVE-2026-88772 on Sept. 27, 2026, 41 days later. A successful chained exploit could combine the two.

  7. Tier BGravOn the watch 2026-09-25 to 2026-10-24
    CVECVE-2026-42608Grav: Unauthenticated path traversal and arbitrary file write in FormFlash component
    CVECVE-2026-42609Grav: Administrative Account Disruption and Privilege De-escalation via User Overwrite Logic

    CVE-2026-42608 and CVE-2026-42609 were disclosed the same day and share a patch; VulnCheck Known Exploited Vulnerabilities (VulnCheck KEV) added CVE-2026-42608 on Sept. 25, 2026. A successful chained exploit could combine the two.

  8. Tier BGravOn the watch 2026-09-25 to 2026-10-24
    CVECVE-2026-42608Grav: Unauthenticated path traversal and arbitrary file write in FormFlash component
    CVECVE-2026-42610Grav: Sensitive information disclosure via Accounts Service Bypass

    CVE-2026-42608 and CVE-2026-42610 were disclosed the same day and share a patch; VulnCheck Known Exploited Vulnerabilities (VulnCheck KEV) added CVE-2026-42608 on Sept. 25, 2026. A successful chained exploit could combine the two.

All 100 pairs on the Breaking watch, with the rule that admits them

02

Tonight's top 24

Tier A pairs, ordered by how many of the two CVEs carry an exploitation report or field sighting and then by the newest disclosure. A product shows at most two pairs here. Where the capability analysis reads an entry step, the pair reads from it to the next step. Follow a CVE to its page on cve-security.com for its capabilities, sources and vendor fixes.

  1. Tier ANetscaler application delivery controllerExploitation report or field sighting on both CVEs
    Entry stepCVE-2026-88772 KEVCitrix NetScaler improper restriction of operations within the bounds of a memory buffer
    Next stepCVE-2026-8452 KEVCitrix NetScaler ADC and NetScaler Gateway improper restriction of operations within the bounds of a memory buffer

    CVE-2026-88772 yields code execution, and CVE-2026-8452 requires a control bypass. A successful chained exploit could advance the intrusion.

    Disclosed 2026-06-30 and 2026-09-27 · Entry over the network without credentials · Partial capability match

  2. Tier AGeonetwork Core GeonetworkExploitation report or field sighting on both CVEs
    Entry stepCVE-2026-63219geonetwork core-geonetwork unauthenticated file upload
    Next stepCVE-2026-58400GeoNetwork vulnerable to remote code execution

    CVE-2026-63219 yields a data write, and CVE-2026-58400 requires that privilege. A successful chained exploit could advance the intrusion.

    Disclosed together 2026-09-03 · Entry over the network without credentials · Partial capability match

  3. Tier ASharepoint serverExploitation report or field sighting on both CVEs
    Entry stepCVE-2026-63520Microsoft SharePoint server remote code execution
    Next stepCVE-2026-65660 KEVMicrosoft SharePoint code injection

    CVE-2026-63520 yields code execution, and CVE-2026-65660 requires that privilege. A successful chained exploit could advance the intrusion.

    Disclosed together 2026-08-11 · Entry over the network without credentials · Partial capability match

  4. Tier AFlowiseExploitation report or field sighting on both CVEs
    Entry stepCVE-2025-71324Flowise arbitrary file read via chatId parameter
    Next stepCVE-2025-71334Flowise arbitrary File Access via Missing Chat Flow ID Validation

    CVE-2025-71324 yields file access, and CVE-2025-71334 requires file access. A successful chained exploit could advance the intrusion.

    Disclosed together 2026-06-25 · Entry over the network without credentials · Partial capability match

  5. Tier ALitellmExploitation report or field sighting on both CVEs
    Entry stepCVE-2026-40217LiteLLM has a sandbox escape in custom-code guardrail
    Next stepCVE-2026-42271 KEVBerriAI LiteLLM command injection

    CVE-2026-40217 yields code execution, and CVE-2026-42271 requires that privilege. A successful chained exploit could advance the intrusion.

    Disclosed 2026-04-10 and 2026-05-08 · Entry over the network with credentials · Partial capability match

  6. Tier AActivemq brokerExploitation report or field sighting on both CVEs
    Entry stepCVE-2026-40466Apache ActiveMQ vulnerable to improper input validation and code injection
    Next stepCVE-2026-34197 KEVApache ActiveMQ improper input validation

    CVE-2026-40466 yields code execution, and CVE-2026-34197 requires credentials. A successful chained exploit could advance the intrusion.

    Disclosed 2026-04-07 and 2026-04-24 · Entry over the network with credentials · Partial capability match

  7. Tier AFortiwebExploitation report or field sighting on both CVEs
    Entry stepCVE-2025-59719Fortinet FortiWeb improper signature verification
    Next stepCVE-2025-58034 KEVFortinet FortiWeb OS command injection

    CVE-2025-59719 yields an elevated identity, and CVE-2025-58034 requires that privilege. A successful chained exploit could advance the intrusion.

    Disclosed 2025-11-18 and 2025-12-09 · Entry over the network without credentials · Exact capability match

  8. Tier AHikvision Csmp Isecure CenterExploitation report or field sighting on both CVEs
    Entry stepCVE-2024-58274Hikvision CSMP iSecure Center OS command injection
    Next stepCVE-2023-53691Hikvision CSMP iSecure Center path traversal

    CVE-2024-58274 yields code execution, and CVE-2023-53691 requires file access. A successful chained exploit could advance the intrusion.

    Disclosed together 2025-10-22 · Entry over the network without credentials · Partial capability match

  9. Tier AF5os-cExploitation report or field sighting on both CVEs
    Entry stepCVE-2025-61955F5OS privilege escalation
    Next stepCVE-2025-57780F5OS privilege escalation

    CVE-2025-61955 yields a privilege gain for a logged-in user, and CVE-2025-57780 requires that foothold. A successful chained exploit could advance the intrusion.

    Disclosed together 2025-10-15 · Entry over the network with credentials or with local access on the host · Partial capability match

  10. Tier ASecure firewall threat defenseExploitation report or field sighting on both CVEs
    Entry stepCVE-2025-20363Cisco IOS heap-based buffer overflow
    Next stepCVE-2025-20333 KEVCisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) buffer overflow

    CVE-2025-20363 yields code execution, and CVE-2025-20333 requires credentials. A successful chained exploit could advance the intrusion.

    Disclosed together 2025-09-25 · Entry over the network without credentials · Partial capability match

  11. Tier AManaged CloudExploitation report or field sighting on both CVEs
    Entry stepCVE-2025-53690 KEVSitecore Multiple Products deserialization of untrusted data
    Next stepCVE-2025-34510Sitecore XM, XC, and XP Post-Auth RCE via Zip Slip

    CVE-2025-53690 yields code execution, and CVE-2025-34510 requires that privilege. A successful chained exploit could advance the intrusion.

    Disclosed 2025-06-17 and 2025-09-03 · Entry over the network without credentials · Partial capability match

  12. Tier AManaged CloudExploitation report or field sighting on both CVEs
    Entry stepCVE-2025-53690 KEVSitecore Multiple Products deserialization of untrusted data
    Next stepCVE-2025-34511Sitecore PowerShell Extension RCE via unrestricted upload

    CVE-2025-53690 yields code execution, and CVE-2025-34511 requires that foothold. A successful chained exploit could advance the intrusion.

    Disclosed 2025-06-17 and 2025-09-03 · Entry over the network without credentials · Partial capability match

  13. Tier ANetscaler application delivery controllerExploitation report or field sighting on both CVEs
    Entry stepCVE-2025-7775 KEVCitrix NetScaler memory overflow
    Next stepCVE-2025-6543 KEVCitrix NetScaler ADC and Gateway buffer overflow

    CVE-2025-7775 yields code execution, and CVE-2025-6543 requires a control bypass. A successful chained exploit could advance the intrusion.

    Disclosed 2025-06-25 and 2025-08-26 · Entry over the network without credentials · Partial capability match

  14. Tier AMerit Lilin Dvr FirmwareExploitation report or field sighting on both CVEs
    Entry stepCVE-2025-34130LILIN DVR arbitrary file read via net_html.cgi
    Next stepCVE-2025-34129LILIN DVR RCE via Malicious FTP/NTP Configuration

    CVE-2025-34130 yields a reusable credential, and CVE-2025-34129 requires that foothold. A successful chained exploit could advance the intrusion.

    Disclosed together 2025-07-16 · Entry over the network without credentials · Partial capability match

  15. Tier ABlue angel software suiteExploitation report or field sighting on both CVEs
    Entry stepCVE-2025-340345VTechnologies Blue Angel Software Suite hard-coded credentials
    Next stepCVE-2025-340335VTechnologies Blue Angel Software Suite OS command injection

    CVE-2025-34034 yields an elevated identity, and CVE-2025-34033 requires that privilege. A successful chained exploit could advance the intrusion.

    Disclosed together 2025-06-24 · Entry over the network without credentials · Exact capability match

  16. Tier AOffice long term servicing channelExploitation report or field sighting on both CVEs
    Entry stepCVE-2025-47165Microsoft Excel remote code execution
    Next stepCVE-2025-47176Microsoft Outlook remote code execution

    CVE-2025-47165 yields code execution, and CVE-2025-47176 requires file access. A successful chained exploit could advance the intrusion.

    Disclosed together 2025-06-10 · Entry with local access on the host or through a victim opening something · Partial capability match

  17. Tier AOffice long term servicing channelExploitation report or field sighting on both CVEs
    Entry stepCVE-2025-47176Microsoft Outlook remote code execution
    Next stepCVE-2025-47170Microsoft Word remote code execution

    CVE-2025-47176 yields code execution, and CVE-2025-47170 requires that foothold. A successful chained exploit could advance the intrusion.

    Disclosed together 2025-06-10 · Entry over the network with credentials or with local access on the host · Partial capability match

  18. Tier ATelemessageExploitation report or field sighting on both CVEs
    Entry stepCVE-2025-48927 KEVTeleMessage TM SGNL initialization of a resource with an insecure default
    Next stepCVE-2025-48928 KEVTeleMessage TM SGNL core dump file exposure

    CVE-2025-48927 yields a reusable credential, and CVE-2025-48928 requires that foothold. A successful chained exploit could advance the intrusion.

    Disclosed together 2025-05-28 · Entry over the network without credentials · Partial capability match

  19. Tier ANetmriExploitation report or field sighting on both CVEs
    Entry stepCVE-2025-32814Infoblox Netmri SQL injection
    Next stepCVE-2025-32813Infoblox Netmri command injection

    CVE-2025-32814 yields a reusable credential, and CVE-2025-32813 requires that foothold. A successful chained exploit could advance the intrusion.

    Disclosed together 2025-05-22 · Entry over the network without credentials · Partial capability match

  20. Tier AMagnusbillingExploitation report or field sighting on both CVEs
    Entry stepCVE-2025-2609MagnusBilling stored cross-site scripting in Login Logs
    Next stepCVE-2025-2610MagnusBilling stored cross-site scripting in Alarm module

    CVE-2025-2609 yields a data write, and CVE-2025-2610 requires that privilege. A successful chained exploit could advance the intrusion.

    Disclosed together 2025-03-21 · Entry over the network without credentials or through a victim opening something · Partial capability match

  21. Tier ASmartosExploitation report or field sighting on both CVEs
    Entry stepCVE-2024-12084Rsync: Heap buffer overflow in rsync due to improper checksum length handling
    Next stepCVE-2024-12087Rsync: Path traversal vulnerability in rsync

    CVE-2024-12084 yields code execution, and CVE-2024-12087 requires file access. A successful chained exploit could advance the intrusion.

    Disclosed 2025-01-15 and 2025-01-14 · Entry over the network without credentials · Partial capability match

  22. Tier AI O Data Device Inc Ud Lt1Exploitation report or field sighting on both CVEs
    Entry stepCVE-2024-45841I-O DATA DEVICE UD-LT1 incorrect permission assignment
    Next stepCVE-2024-47133I-O DATA DEVICE UD-LT1 OS command injection

    CVE-2024-45841 yields a reusable credential, and CVE-2024-47133 requires that foothold. A successful chained exploit could advance the intrusion.

    Disclosed together 2024-12-05 · Entry over the network with credentials · Partial capability match

  23. Tier AI O Data Device Inc Ud Lt1Exploitation report or field sighting on both CVEs
    Entry stepCVE-2024-52564I-O DATA DEVICE UD-LT1 firewall function vulnerability
    Next stepCVE-2024-45841I-O DATA DEVICE UD-LT1 incorrect permission assignment

    CVE-2024-52564 yields code execution, and CVE-2024-45841 requires credentials. A successful chained exploit could advance the intrusion.

    Disclosed together 2024-12-05 · Entry over the network without credentials · Partial capability match

  24. Tier ASolrExploitation report or field sighting on both CVEs
    Entry stepCVE-2024-45216Apache Solr: Authentication bypass possible using a fake URL Path ending
    Next stepCVE-2023-50386Apache Solr: Backup/Restore APIs allow for deployment of executables in malicious ConfigSets

    CVE-2024-45216 yields an elevated identity, and CVE-2023-50386 requires that privilege. A successful chained exploit could advance the intrusion.

    Disclosed 2024-02-09 and 2024-10-16 · Entry over the network without credentials · Exact capability match

The whole list on cve-security.com: tiers A and B, filtered by product, bridge or capability

03

How often a tier holds a chain

Each tier is a measured rate. The build takes the pairs whose later CVE is at least 90 days old, so a source has had time to report a chain, and counts how many are known chains in KCV. A tier promises a floor, and the last measurement, on Oct. 7, 2026, sits beside it.

  1. Tier A521 pairs tonight
    At least one in 25About one in 20 at the last measurement
  2. Tier B7,856 pairs tonight
    At least one in 100About one in 40 at the last measurement
  3. Tier C51,672 pairs, in the download and the API
    At least one in 1,000About one in 350 at the last measurement

Each dot is one pair, and the lit dot is the chain the floor promises. A rate describes the group of pairs that share a row's signals and prints on no single row. A tier A pair may still fail in practice, and a pair outside the list may still chain.

04

What the list counts

A capability
For each CVE with a CVSS vector, a fixed rule reads the vector, the weakness class and the description for what an exploit needs to start and what it gains, on a fixed vocabulary. Where the dataset holds exploit code or a patch diff, a model reads those as well, and a second model answers what each flaw does on its own.
A pair
Two CVEs form a candidate when one CVE's gain meets what the other needs through a named bridge, such as an authentication bypass that opens the foothold a second flaw needs. The pair passes a fixed gate: the second step advances the attacker, at least one of the two can be reached without local access, and no cited source names the pair in a known chain yet. Other pairs enter on their records, such as exploitation reports on both CVEs within 90 days or a joint disclosure with a shared advisory, patch or fixed version.
The tiers
Four record facts set a pair's score: how close the two disclosure dates are, a shared advisory or patch, a shared fixed version, and how many of the two CVEs carry an exploitation report or field sighting. A pair reaches tier A only with a documented handoff between its two CVEs, and a pair across two products reaches tier B at most. This page and the list show tiers A and B; tier C is in the download and the API.
Exploitation
A report or field sighting comes from CISA KEV, VulnCheck Known Exploited Vulnerabilities (VulnCheck KEV) and the other trackers cve-security.com reads, plus sensor sightings. A KEV chip marks each CVE that CISA lists.
What a pair says
A pair on this page is a possible chain, published for teams to research. Confirmation belongs to Known Chained Vulnerabilities (KCV)™, where a cited source reports the two CVEs used together. Two CVEs named in one thread count as discussion until a source reports them used together.