<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>CVE Brief · Rising Risk</title>
    <link>https://cvebrief.com/</link>
    <atom:link href="https://cvebrief.com/feeds/rising.xml" rel="self" type="application/rss+xml"/>
    <description>Vulnerabilities whose predicted exploitation probability (EPSS) is climbing fast. A forecast, not confirmed exploitation — see the Actively Exploited section for that.</description>
    <language>en-us</language>
    <lastBuildDate>Mon, 31 Aug 2026 09:55:10 GMT</lastBuildDate>
    <item>
      <title>CVE-2026-33112 · Microsoft Office SharePoint · exploitation probability 3.1% → 32.7%</title>
      <link>https://cvebrief.com/cve/cve-2026-33112/</link>
      <guid isPermaLink="false">epss-rising-CVE-2026-33112-2026-08-29</guid>
      <pubDate>Sat, 29 Aug 2026 12:00:00 GMT</pubDate>
      <description>Predicted probability of exploitation in the next 30 days rose from 3.1% to 32.7% over 7 days (98.3% percentile of all CVEs). Microsoft Office SharePoint is vulnerable to remote code execution due to the insecure deserialization of untrusted data. EPSS is a forecast from FIRST.org, not evidence of exploitation.</description>
    </item>
    <item>
      <title>CVE-2026-64638 · WordPress · exploitation probability 0.9% → 31.2%</title>
      <link>https://cvebrief.com/cve/cve-2026-64638/</link>
      <guid isPermaLink="false">epss-rising-CVE-2026-64638-2026-08-29</guid>
      <pubDate>Sat, 29 Aug 2026 12:00:00 GMT</pubDate>
      <description>Predicted probability of exploitation in the next 30 days rose from 0.9% to 31.2% over 7 days (98.2% percentile of all CVEs). WordPress contains a reflected cross-site scripting vulnerability on the login screen that allows unauthenticated attackers to execute malicious scripts in the context of a user session. EPSS is a forecast from FIRST.org, not evidence of exploitation.</description>
    </item>
    <item>
      <title>CVE-2026-53435 · Jenkins · exploitation probability 19.0% → 53.1%</title>
      <link>https://cvebrief.com/cve/cve-2026-53435/</link>
      <guid isPermaLink="false">epss-rising-CVE-2026-53435-2026-08-29</guid>
      <pubDate>Sat, 29 Aug 2026 12:00:00 GMT</pubDate>
      <description>Predicted probability of exploitation in the next 30 days rose from 19.0% to 53.1% over 7 days (98.9% percentile of all CVEs). Jenkins 2 is subject to a high-severity vulnerability involving the deserialization of arbitrary data. EPSS is a forecast from FIRST.org, not evidence of exploitation.</description>
    </item>
    <item>
      <title>CVE-2025-71257 · BMC Software FootPrints · exploitation probability 5.2% → 44.6%</title>
      <link>https://cvebrief.com/cve/cve-2025-71257/</link>
      <guid isPermaLink="false">epss-rising-CVE-2025-71257-2026-08-29</guid>
      <pubDate>Sat, 29 Aug 2026 12:00:00 GMT</pubDate>
      <description>Predicted probability of exploitation in the next 30 days rose from 5.2% to 44.6% over 7 days (98.7% percentile of all CVEs). BMC FootPrints ITSM contains an authentication bypass vulnerability in restricted REST API endpoints and servlets, allowing unauthenticated remote attackers to access sensitive application data. EPSS is a forecast from FIRST.org, not evidence of exploitation.</description>
    </item>
    <item>
      <title>CVE-2026-6875 · ServiceNow ServiceNow AI Platform · exploitation probability 26.7% → 77.6%</title>
      <link>https://cvebrief.com/cve/cve-2026-6875/</link>
      <guid isPermaLink="false">epss-rising-CVE-2026-6875-2026-08-29</guid>
      <pubDate>Sat, 29 Aug 2026 12:00:00 GMT</pubDate>
      <description>Predicted probability of exploitation in the next 30 days rose from 26.7% to 77.6% over 7 days (99.5% percentile of all CVEs). A remote code execution vulnerability in the ServiceNow AI Platform allows unauthenticated users to execute arbitrary code, necessitating an immediate security update. EPSS is a forecast from FIRST.org, not evidence of exploitation.</description>
    </item>
    <item>
      <title>CVE-2026-61511 · vBulletin · exploitation probability 1.7% → 70.8%</title>
      <link>https://cvebrief.com/cve/cve-2026-61511/</link>
      <guid isPermaLink="false">epss-rising-CVE-2026-61511-2026-08-29</guid>
      <pubDate>Sat, 29 Aug 2026 12:00:00 GMT</pubDate>
      <description>Predicted probability of exploitation in the next 30 days rose from 1.7% to 70.8% over 7 days (99.4% percentile of all CVEs). vBulletin contains an eval injection vulnerability in the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code via the pagenav[pagenumber] parameter. EPSS is a forecast from FIRST.org, not evidence of exploitation.</description>
    </item>
  </channel>
</rss>
