May 2026 CVE Landscape
ID: 0498c2fb-4b8a-5eef-a5bb-cce8b41550b9
STIX ID: report--0498c2fb-4b8a-5eef-a5bb-cce8b41550b9
Feed Name: Recorded Future Blog
**Executive summary:** Recorded Future’s Insikt Group identified 41 high-impact vulnerabilities actively exploited or observed in May 2026 (an 11% increase month-over-month), including multiple critical RCE and SQL injection flaws; notable items include large-scale Ghost CMS SQL injection campaigns (CVE-2026-26980) compromising over 700 sites to deliver ClickFix/FakeCaptcha social-engineering attacks, a rapidly exploited BerriAI LiteLLM SQL injection (CVE-2026-42208) with an alleged PoC, and malware dropper analysis (UtilifySetup.exe) with associated IoCs and remediation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
