Critical Vulnerabilities to Address: May 2026 Insights

Jun 08, 2026 771 views

In May 2026, the Insikt Group identified 41 high-impact vulnerabilities that warrant immediate remediation, each receiving a Very Critical Recorded Future Risk Score. This marks an 11% increase compared to April. The vulnerabilities span products from 20 different vendors, reflecting a noteworthy trend in cybersecurity risks.

Among the identified vulnerabilities, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) recognized 21 as part of its Known Exploited Vulnerabilities (KEV) catalog. The remaining vulnerabilities were disclosed via honeypot data and independent reports from cybersecurity vendors. Notably, approximately 27% of these vulnerabilities originated from Vercel, driven predominantly by activity linked to the Next.js framework.

Overview of Vulnerabilities

This month's analysis provides a detailed reference table for vulnerability management teams, focusing on 22 actively exploited vulnerabilities. This list excludes 19 CVEs associated with honeypot data, which are accessible through Records Future’s CVE Monthly Report. The table also includes examples of public Proofs of Concept (PoCs) identified by Insikt Group, emphasizing the need for verification before any testing occurs due to varying accuracy and efficacy.

#
Vulnerability
Risk
Score
Vendor/Product
KEV
Malware Analysis
RCE
PoC

Table 1: This table displays a list of vulnerabilities actively exploited in May 2026, based on Recorded Future data (excluding honeypot-sourced CVEs).

Key Trends in Vulnerability Exploitation

  • Threat actors exhibited heightened activity around vulnerabilities in the Ghost CMS, particularly targeting CVE-2026-26980 in expansive ClickFix and FakeCaptcha poisoning campaigns. Exploitation relied on compromised sites to inject malicious JavaScript, redirecting users toward social engineering traps.
  • Twelve of the identified vulnerabilities enabled remote code execution (RCE) and affected a variety of products from prominent vendors including Microsoft, Adobe, and Palo Alto Networks.
  • Insikt Group discovered public PoC exploits for 32 of the 41 vulnerabilities, demonstrating a clear trend toward readily available exploitation methods.
  • Common weaknesses identified this month included CWE-79 (Cross-site Scripting), CWE-506 (Embedded Malicious Code), and CWE-89 (SQL Injection), with each type corresponding to three CVEs.
  • Interestingly, five vulnerabilities disclosed between 2008 and 2010 remain exploitable today, underlining an industry-wide challenge where outdated patching efforts leave systems vulnerable.

Exploitation Analysis

The following analysis outlines the highest-impact vulnerabilities exploited in May 2026, particularly those correlated with active threat actor campaigns or those with publicly available PoCs.

CVE-2026-26980: A Case Study in Exploitation

On May 21, 2026, XLab published a detailed analysis focusing on how CVE-2026-26980 was exploited within the Ghost CMS framework to conduct large-scale ClickFix poisoning attacks. Ghost CMS provides a platform for users to publish diverse content types and was found vulnerable through a critical SQL injection flaw.

This specific vulnerability allows unauthenticated attackers to retrieve sensitive data such as Ghost Admin API Keys, enabling significant control over website content. Exploited by at least two threat groups, the attack compromised over 700 Ghost CMS websites across multiple sectors, manipulating them to facilitate social engineering scams that coerced users into executing malicious actions.

Insikt Group secured a malicious sample, UtilifySetup.exe, which was analyzed using Recorded Future's Malware Intelligence resources. The sample matched indicators for malicious behavior and displayed capabilities such as DLL injection, system information retrieval, and the execution of additional payloads, facilitating deeper infiltration into compromised machines. Below is a summarized account of the actions performed by this malware:

  • Executes DLL injection routines
  • Captures system language and geolocation
  • Creates files for executing further commands
  • Employs various evasion techniques

Further analysis categorized the file as malicious, noting its propensity to execute itself upon system login, thus compromising the targeted environments. Additional details, including various techniques and indicators of compromise (IoCs), are available for Recorded Future clients through detailed reporting.

Figure 1: Risk Rules History for CVE-2026-26980, as captured by Recorded Future (Source: Recorded Future)

As cybersecurity professionals navigate the evolving threat landscape, a comprehensive strategy addressing both new and legacy vulnerabilities is essential to minimize risk exposure and safeguard critical systems.

Source: Thomas Davis · www.recordedfuture.com

Comments

Sign in to comment.
No comments yet. Be the first to comment.

Related Articles

May 2026 CVE Landscape