CyberSecurityBoardThreat Intel · CVEs · Products
Cyber News

Top 10 Attack Surface Exposures in 2026: Databases, Admin Panels, and Legacy Services Dominate

June 25, 2026

According to a new analysis by Intruder, 60% of organizations have at least one HTTP panel exposed, 49% have a risky port or service, 42% have an internet-facing database, and 30% have publicly accessible files or information that should not be. The top 10 exposures include MySQL (26%), Postgres (16%), API documentation (15%), WordPress admin panels (15%), RDP (11%), SNMP (9%), phpMyAdmin (8%), UPnP (8%), NTP (7%), and RPC Portmapper (7%). The report emphasizes that attack surface reduction—removing unnecessary exposures—is often overlooked compared to patching.

CVEs: CVE-2019-0708, CVE-2026-11645

Malware: PLEASE_READ_ME ransomware

Companies: Intruder

Products: MySQL, Postgres, WordPress, phpMyAdmin, MongoDB, Elasticsearch