Security advisories

Vulnerabilities confirmed to be actively exploited, sourced from CISA's Known Exploited Vulnerabilities catalog. Updated automatically.

Remediation guidance below is AI-synthesized from CISA and NVD data. Verify against the vendor's own advisory before acting — this is a triage tool, not a substitute for the primary source.

Subscribe

RSS lets you follow this list in an app of your choice — no account or email needed. Slack has a native RSS app (/feed subscribe); for Teams, use the free Power Automate Workflows RSS trigger, since Teams retired its built-in RSS connector in 2026.

All advisories
Critical only (ransomware / overdue)
Per-vendor feeds (125)

Filter

Severity
Vendor (125)
Due soon CVE-2026-73570

Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability

Synacor — Zimbra Collaboration Suite (ZCS)

This vulnerability in Zimbra Collaboration Suite allows an unauthenticated attacker to inject and execute arbitrary operating system commands simply by sending crafted SMTP requests — no login required. Because Zimbra is widely used for enterprise email, a successful exploit could give attackers a foothold on the mail server running as the Zimbra user, potentially enabling data theft, lateral movement, or further compromise of the organization's messaging infrastructure.

Patch available

Next step: Review the Zimbra Security Advisories page (https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories) for available patches or guidance, and apply any updates immediately; no specific patch reference was identified in the source data at time of publication.

Added: 8/21/2026 Remediate by: 8/24/2026
Remediation overdue CVE-2026-72529

TrueConf Server Missing Authentication for Critical Function Vulnerability

TrueConf — Server

TrueConf Server has a critical flaw where attackers need no credentials whatsoever to reach a sensitive function exposed on port 4307/TCP. Anyone with network access to that port can execute arbitrary scripts on the server, effectively gaining the ability to run malicious code remotely without logging in. This is a high-impact, low-barrier attack — no stolen credentials or social engineering required, making it especially dangerous for any TrueConf Server instance reachable from untrusted networks.

No patch reference found

Next step: No vendor patch or advisory has been identified at this time. Organizations running TrueConf Server should be aware that no official fix is currently available and should evaluate whether continued use of the product is acceptable given the risk, in line with CISA's BOD 26-04 guidance.

Added: 8/20/2026 Remediate by: 8/23/2026
Actively exploited CVE-2026-72530

TrueConf Server Code Injection Vulnerability

TrueConf — Server

TrueConf Server contains a code injection flaw that lets an unauthenticated remote attacker exploit port 4307/TCP to escape the application's sandboxed environment and run arbitrary code directly on the underlying host. This means full host-level compromise is possible without any credentials, making internet-exposed TrueConf Server deployments particularly dangerous. The vulnerability effectively eliminates the containment boundary the server relies on for isolation.

No patch reference found

Next step: No patch or vendor advisory has been published at this time. Organizations should follow CISA's BOD 26-04 guidance, and if mitigations cannot be applied, CISA explicitly states that discontinuing use of the product should be considered.

Added: 8/20/2026 Remediate by: 9/3/2026
Actively exploited CVE-2026-64849

MLflow Server-Side Request Forgery Vulnerability

MLflow — MLflow

This Server-Side Request Forgery (SSRF) flaw in MLflow allows an attacker to make the MLflow server issue requests on their behalf to internal network resources or cloud metadata services — such as AWS IMDSv1 or similar endpoints. The attacker can then read the response status and body, potentially harvesting cloud credentials, internal service data, or other sensitive information that should never be externally accessible. Organizations running MLflow in cloud or hybrid environments face elevated risk.

Patch available

Next step: Apply the patch available in the MLflow commit (ba949522477cbd5915aa55d29b0cfad7d5ddf939) and review the vendor security advisory at https://github.com/mlflow/mlflow/security/advisories/GHSA-7gwp-5pfp-969j for full remediation guidance.

Interim mitigation: A related issue thread exists at https://github.com/mlflow/mlflow/issues/24179, which may contain interim guidance; review it for any compensating controls referenced by the project maintainers while patching is in progress.

Added: 8/19/2026 Remediate by: 9/2/2026
Remediation overdue CVE-2026-33824

Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability

Microsoft — Internet Key Exchange (IKE) Service Extensions

A double free vulnerability in Microsoft's Internet Key Exchange (IKE) Service Extensions could allow a remote attacker to execute arbitrary code on an affected system. IKE is a core component of IPsec VPN infrastructure, meaning this flaw sits in a network-facing service that organizations rely on for secure communications. Successful exploitation could give an attacker full control of the affected system without requiring physical access, making this a high-priority concern for any environment using Microsoft IKE-based VPN services.

Patch available

Next step: Review the Microsoft Security Response Center advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33824 for patch and remediation details, and apply any available updates immediately in accordance with CISA BOD 26-04 patching guidelines.

Added: 8/18/2026 Remediate by: 8/21/2026
Remediation overdue CVE-2026-55040

Microsoft SharePoint Weak Authentication Vulnerability

Microsoft — SharePoint

This vulnerability in Microsoft SharePoint allows an unauthenticated attacker to bypass authentication controls over a network, meaning they could potentially gain unauthorized access to SharePoint resources without valid credentials. SharePoint is widely used for internal collaboration and document management, so a successful exploit could expose sensitive organizational data or serve as an entry point for further compromise. No ransomware use has been confirmed, but authentication bypass flaws are high-value targets for attackers.

Patch available

Next step: Apply the patch provided by Microsoft immediately by following the guidance published in the Microsoft Security Response Center advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55040.

Added: 8/18/2026 Remediate by: 8/21/2026
Remediation overdue CVE-2026-59310

Broadcom VMware vCenter Path Traversal Vulnerability

Broadcom — VMware vCenter

This path traversal vulnerability in VMware vCenter is serious because vCenter is typically the administrative hub for entire virtualized environments. An attacker who can reach vCenter over the network — without needing to be inside a VPN or have credentials — could exploit this flaw to execute arbitrary code, potentially gaining control over every virtual machine and host managed by that vCenter instance. Compromise of vCenter is effectively compromise of the entire virtual infrastructure it manages.

Patch available

Next step: Review and apply the guidance provided in Broadcom's official security advisory at https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017 immediately, following BOD 26-04 patching timelines based on your asset's internet exposure.

Added: 8/18/2026 Remediate by: 8/21/2026
Remediation overdue CVE-2026-65400

Apple macOS Improper Authentication Vulnerability

Apple — macOS

This flaw in Apple macOS allows a network-based attacker to authenticate to Screen Sharing without supplying valid credentials. Screen Sharing grants interactive graphical access to the desktop, meaning a successful exploit could give an unauthorized user full visual and operational control of an affected Mac — equivalent to sitting in front of it. This is particularly dangerous in environments where Macs are reachable from broader networks or the internet.

Patch available

Next step: Review and apply the guidance detailed in Apple's official advisory at https://support.apple.com/en-us/148170 as the immediate priority step.

Added: 8/18/2026 Remediate by: 8/21/2026
Remediation overdue CVE-2025-62593

Ray-Project Ray Code Injection Vulnerability

Ray-Project — Ray

Ray is a popular open-source framework used by developers for distributed computing and AI/ML workloads. This code injection flaw allows remote attackers to execute arbitrary code on systems running Ray, and is specifically exploitable through Firefox and Safari browsers. Because Ray is often used in development and research environments that may lack hardened security controls, a successful exploit could give attackers full control over affected hosts and any data or workloads running on them.

Patch available

Next step: Apply the patch referenced in the official Ray security advisory (GHSA-q279-jhrf-cc6v) and confirmed in the linked GitHub commit (70e7c72); review the advisory at https://github.com/ray-project/ray/security/advisories/GHSA-q279-jhrf-cc6v and update your Ray installation immediately.

Added: 8/17/2026 Remediate by: 8/20/2026
Remediation overdue CVE-2026-20349

Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability

Cisco — Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)

This vulnerability affects Cisco's widely deployed ASA and FTD firewall products, which sit at the perimeter of many enterprise networks. An unauthenticated remote attacker can exploit a heap inspection flaw to crash the device, triggering a denial-of-service condition. Because no authentication is required, the attack surface is broad — any internet-exposed ASA or FTD appliance could be targeted, potentially taking down a critical network security boundary and disrupting connectivity for an entire organization.

Patch available

Next step: Review and apply guidance from Cisco's official security advisory at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-vpn-dos-dzv4mQFF, and follow CISA's BOD 26-04 patching prioritization requirements based on your asset's internet exposure.

Added: 8/11/2026 Remediate by: 8/14/2026
Due soon CVE-2026-68820

Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability

Microsoft — Windows Ancillary Function Driver for WinSock

This vulnerability in the Windows Ancillary Function Driver for WinSock (afd.sys) allows an attacker who already has local access to a Windows system to elevate their privileges through a use-after-free flaw. In practice, this means a low-privileged user or malware already running on a machine could gain SYSTEM-level control, making it a critical stepping stone in multi-stage attacks or insider threat scenarios, even though it requires prior local authentication.

Patch available

Next step: Apply the Microsoft security update referenced in the official advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68820 as soon as possible.

Added: 8/11/2026 Remediate by: 8/25/2026
Remediation overdue CVE-2026-72898

Metabase SQL Injection Vulnerability

Metabase — Metabase

This SQL injection flaw in Metabase requires no authentication, meaning any internet-accessible Metabase instance can be compromised without credentials. An attacker who exploits it gains administrator-level control, enabling them to alter application settings, harvest credentials for all connected databases, and exfiltrate any data those databases can reach. The breadth of potential data exposure — spanning the Metabase application itself and every downstream data source it connects to — makes this a high-priority risk for any organization running Metabase.

Patch available

Next step: Apply the patch or mitigations detailed in the Metabase security advisory at https://github.com/metabase/metabase/security/advisories/GHSA-vwf4-m7j8-wcjf immediately, and if mitigations cannot be applied, consider discontinuing use of the product until remediation is possible.

Interim mitigation: Mitigation guidance is provided directly in the Metabase security advisory at https://github.com/metabase/metabase/security/advisories/GHSA-vwf4-m7j8-wcjf — consult that source for any interim compensating controls referenced by the vendor.

Added: 8/11/2026 Remediate by: 8/14/2026
Remediation overdue CVE-2026-8037

Progress LoadMaster Command Injection Vulnerability

Progress — LoadMaster

This vulnerability in Progress LoadMaster, a widely used application delivery controller, allows unauthenticated attackers to inject and execute arbitrary operating system commands on the appliance. Because no credentials are required, any internet-exposed LoadMaster device is at direct risk of full compromise. A successful attack could give an adversary control over load balancing infrastructure, potentially disrupting services or enabling deeper network intrusion across environments that trust the appliance.

Patch available

Next step: Apply the vendor-supplied patch immediately by following the guidance in Progress's Critical Security Bulletin at https://community.progress.com/s/article/LoadMaster-Critical-Security-Bulletin-June-2026-CVE-2026-8037-CVE-2026-33691.

Added: 8/7/2026 Remediate by: 8/10/2026
Remediation overdue CVE-2026-63077

JetBrains TeamCity Deserialization of Untrusted Data Vulnerability

JetBrains — TeamCity

JetBrains TeamCity, a widely used CI/CD build server, contains a deserialization flaw in its agent polling protocol that lets unauthenticated attackers execute arbitrary code remotely. Because the vulnerable protocol is used by build agents to communicate with the server, an attacker who can reach that endpoint needs no credentials to potentially take full control of the TeamCity instance — and by extension, the build pipelines and artifacts it manages.

Patch available

Next step: Review the JetBrains security issues page at https://www.jetbrains.com/privacy-security/issues-fixed/ for any available patches or updated TeamCity versions and apply them immediately; no direct patch reference was identified in the advisory data at time of publication.

Added: 8/5/2026 Remediate by: 8/8/2026
Remediation overdue CVE-2026-18556

N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

N-able — N-central

N-able N-central is a widely used remote monitoring and management platform deployed by managed service providers to oversee client IT environments. This vulnerability allows an attacker to bypass authentication entirely through an alternate path or channel, meaning they could gain unauthorized access without valid credentials. Because N-central has privileged visibility into managed endpoints across many organizations, a successful exploit could give an attacker broad reach into multiple client networks simultaneously, making this a high-value target.

Patch available

Next step: No patch reference was identified in the available data; consult the N-able status page at https://uptime.n-able.com/ for vendor guidance, and follow CISA's BOD 26-04 patching guidelines — discontinuing use of the product if mitigations remain unavailable.

Added: 8/4/2026 Remediate by: 8/7/2026
Remediation overdue CVE-2026-34486

Apache Tomcat Missing Encryption of Sensitive Data Vulnerability

Apache — Tomcat

This Apache Tomcat flaw allows attackers to bypass the EncryptInterceptor, which is meant to protect sensitive data in transit between clustered Tomcat nodes. On its own this is serious, but the real danger is that it can be chained with CVE-2025-24813, a known exploitable vulnerability, potentially enabling remote code execution. Organizations running Apache Tomcat clusters with EncryptInterceptor enabled may be at elevated risk if both vulnerabilities are present in their environment.

Patch available

Next step: Review and apply the guidance published in the Apache mailing list advisory at https://lists.apache.org/thread/9510k5p5zdvt9pkkgtyp85mvwxo2qrly, and follow CISA's BOD 26-04 patching guidelines for your environment; note that no formal patch reference has been identified in the source data at this time.

Interim mitigation: A mitigation script has been referenced at https://www.vicarius.io/vsociety/posts/cve-2026-34486-mitigation-script-rce-on-apache-tomcat, which may provide interim compensating controls while a full patch is unavailable. Evaluate this resource carefully and ensure it aligns with your environment before deploying.

Added: 8/4/2026 Remediate by: 8/7/2026
Remediation overdue CVE-2026-9198

IBM Langflow Code Injection Vulnerability

IBM — Langflow

This critical flaw in IBM Langflow allows anyone on the network — without any login credentials — to execute arbitrary code on affected systems. Because it targets default deployments, organizations running Langflow out of the box are immediately at risk. Successful exploitation gives attackers full control over the host, enabling data theft, lateral movement, or ransomware deployment. The unauthenticated nature of the attack makes it especially dangerous for any internet-exposed instance.

Patch available

Next step: Review and apply guidance from IBM's official advisory at https://www.ibm.com/support/pages/node/7278927 as the immediate priority step.

Added: 8/4/2026 Remediate by: 8/7/2026
Remediation overdue CVE-2026-18577

N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

N-able — N-central

N-able N-central, a widely used remote monitoring and management platform, contains an authentication bypass flaw that lets attackers skip normal login controls and take over accounts. This is particularly dangerous because N-central typically has privileged access to many managed endpoints — a compromised instance could give attackers a foothold across an entire managed environment. The vulnerability is an incomplete fix for a prior related flaw (CVE-2026-18556), meaning organizations that already patched the earlier issue are still exposed.

Patch available

Next step: Apply the patch provided in the N-central 2026.3 HF1 release, as documented in the official release notes (https://documentation.n-able.com/N-central/Release_Notes/GA/Content/N-central_2026.3_HF1_Release_Notes.htm) and the N-able security advisory (https://www.n-able.com/blog/n-central-security-update-august-2-2026).

Added: 8/3/2026 Remediate by: 8/6/2026
Remediation overdue CVE-2026-20316

Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability

Cisco — Secure Firewall Management Center (FMC)

Cisco's Secure Firewall Management Center contains a hard-coded password that ships with the product itself — meaning an attacker who knows this credential (which can often be discovered through public research or reverse engineering) can remotely log in without any prior access. Because FMC is used to centrally manage firewall policies and security infrastructure, unauthorized access could expose sensitive network configuration data and potentially allow manipulation of security controls across an entire environment.

Patch available

Next step: Review and apply guidance from Cisco's official security advisory at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh immediately, as no standalone patch reference was identified in the source data.

Added: 7/29/2026 Remediate by: 8/1/2026
Remediation overdue CVE-2025-68686

Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability

Fortinet — FortiOS

This vulnerability in Fortinet FortiOS allows a remote, unauthenticated attacker to bypass a previously issued patch that addressed a symbolic link persistence mechanism — a technique attackers use to maintain access after an initial compromise. Critically, exploitation requires the attacker to have already gained filesystem-level access through a separate vulnerability. The danger is that defenders who believed the earlier patch fully closed the persistence gap may still have compromised systems that remain accessible to attackers.

Patch available

Next step: Review Fortinet's official PSIRT advisory at https://fortiguard.fortinet.com/psirt/FG-IR-25-934 and apply any patches or guidance provided there, in accordance with CISA's BOD 26-04 patching requirements including the associated forensics triage requirements.

Added: 7/27/2026 Remediate by: 8/10/2026
Remediation overdue CVE-2026-16812

Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability

Arista — VeloCloud Orchestrator

This vulnerability in Arista VeloCloud Orchestrator allows a remote attacker to inject operating system commands, potentially gaining access to privileged internal functions of the orchestrator. Because VeloCloud Orchestrator manages and coordinates SD-WAN infrastructure, a successful attack could compromise the confidentiality, integrity, and availability of both the orchestrator itself and all the network data and configurations it manages — making this a high-impact target for attackers.

Patch available

Next step: Review and apply the guidance provided in Arista's official security advisory at https://www.arista.com/en/support/advisories-notices/security-advisory/24364-security-advisory-0144 immediately.

Interim mitigation: Mitigation details are referenced in Arista's security advisory at https://www.arista.com/en/support/advisories-notices/security-advisory/24364-security-advisory-0144 — consult that document directly for any available compensating controls or workarounds specific to your deployment.

Added: 7/27/2026 Remediate by: 7/30/2026
Remediation overdue CVE-2026-16232

Check Point SmartConsole Improper Authentication Vulnerability

Check Point — SmartConsole

Check Point SmartConsole, used to manage network security policies, contains an authentication flaw that lets an unauthenticated remote attacker steal a login token and gain full administrative access. This means an outsider with no credentials could take complete control of your Check Point security infrastructure — potentially rewriting firewall rules, disabling protections, or pivoting deeper into your environment. Because SmartConsole is a central management plane, compromise here undermines every security control it governs.

Patch available

Next step: Apply the patch and follow remediation steps provided in Check Point's official advisory at https://support.checkpoint.com/results/sk/sk185169 immediately.

Interim mitigation: Check Point's advisory (https://support.checkpoint.com/results/sk/sk185169) references mitigations; consult that page directly for any interim compensating controls applicable to your environment while patching is underway.

Added: 7/22/2026 Remediate by: 7/25/2026
Remediation overdue CVE-2026-50522

Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

Microsoft — SharePoint

Microsoft SharePoint has a deserialization flaw that lets an unauthenticated attacker send specially crafted data across a network and execute arbitrary code on the server — without needing valid credentials. Because SharePoint is commonly internet-facing and central to business collaboration, a successful exploit could give attackers a foothold inside the corporate environment, potentially leading to data theft, lateral movement, or ransomware deployment.

Patch available

Next step: Apply the Microsoft security update immediately by following the guidance at the official Microsoft Security Response Center advisory: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50522.

Added: 7/22/2026 Remediate by: 7/25/2026
Remediation overdue CVE-2021-27137

DD-WRT Stack-Based Buffer Overflow Vulnerability

DD-WRT — DD-WRT

This vulnerability in DD-WRT router firmware allows an unauthenticated attacker — someone with no login credentials — to overflow a buffer in the UPnP service and potentially execute arbitrary code on the device. Because it requires no authentication and targets a widely deployed open-source router platform, a successful exploit could give an attacker full control over affected routers, enabling traffic interception, network pivoting, or further attacks on connected systems.

Patch available

Next step: Apply the patch available at the DD-WRT SVN changeset reference (https://svn.dd-wrt.com/changeset/45724) by updating to a DD-WRT build that includes this fix.

Added: 7/21/2026 Remediate by: 7/24/2026
Remediation overdue CVE-2026-0770

Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability

Langflow — Langflow

Langflow, an AI workflow development platform, contains a flaw that lets remote attackers run arbitrary code on affected systems without needing physical access. This is a critical risk because successful exploitation gives an attacker full control over the host, potentially enabling data theft, lateral movement, or ransomware deployment. Any internet-exposed Langflow installation should be treated as high-priority, as no authentication or local access appears to be required for exploitation.

No patch reference found

Next step: No vendor patch or advisory has been published at this time; if mitigations cannot be applied, CISA's guidance explicitly states you should discontinue use of the product until a fix is available.

Added: 7/21/2026 Remediate by: 7/24/2026
Remediation overdue CVE-2026-60137

WordPress Core SQL Injection Vulnerability

WordPress — Core

This SQL injection flaw in WordPress Core becomes critical because it can be chained with a second vulnerability (CVE-2026-63030) to give an unauthenticated attacker full remote code execution on default WordPress installations — no login required. Any internet-exposed WordPress site is potentially at risk. Successful exploitation could allow complete site takeover, data theft, or use of the server as a launchpad for further attacks. The broad deployment of WordPress makes this a high-priority issue for any organization running it.

Patch available

Next step: Review and apply the guidance published in the WordPress security advisory at https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-fpp7-x2x2-2mjf immediately, as no standalone patch reference was identified in the source data.

Added: 7/21/2026 Remediate by: 8/4/2026
Remediation overdue CVE-2026-63030

WordPress Core Interpretation Conflict Vulnerability

WordPress — Core

This WordPress Core flaw involves an interpretation conflict that enables SQL Injection, which can then be escalated to full Remote Code Execution on the server. When chained with CVE-2026-60137, the attack surface widens significantly. For organizations running WordPress — including self-hosted sites and managed instances — a successful exploit could allow an attacker to extract data, manipulate the database, and ultimately take complete control of the underlying server.

Patch available

Next step: Review and apply guidance from the vendor security advisory published at https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-ff9f-jf42-662q; no formal patch reference was identified in the source data, so closely monitor that advisory for updated remediation details.

Added: 7/21/2026 Remediate by: 7/24/2026
Remediation overdue CVE-2026-25089

Fortinet FortiSandbox OS Command Injection Vulnerability

Fortinet — FortiSandbox

This vulnerability allows an unauthenticated attacker — meaning no login credentials are required — to inject and execute arbitrary operating system commands on affected Fortinet FortiSandbox systems simply by sending crafted HTTP requests. FortiSandbox is a security product used to analyze suspicious files and network traffic, so a compromise of it could undermine an organization's entire threat detection capability and provide attackers a foothold in a sensitive part of the network.

Patch available

Next step: Review Fortinet's official security advisory at https://fortiguard.fortinet.com/psirt/FG-IR-26-141 and apply any patches or mitigations provided there; if no mitigations are available for your deployment, CISA guidance requires discontinuing use of the product.

Added: 7/16/2026 Remediate by: 7/19/2026
Remediation overdue CVE-2026-39808

Fortinet FortiSandbox OS Command Injection Vulnerability

Fortinet — FortiSandbox

This vulnerability in Fortinet FortiSandbox allows an unauthenticated attacker — meaning no login credentials are required — to inject and execute operating system commands by sending specially crafted HTTP requests. Because FortiSandbox is a security analysis platform often positioned at critical network chokepoints, a successful exploit could give attackers a foothold with significant privileges inside the environment, potentially undermining the very infrastructure meant to detect threats.

Patch available

Next step: Review and apply the guidance provided in Fortinet's official security advisory at https://fortiguard.fortinet.com/psirt/FG-IR-26-100 as the immediate next step.

Added: 7/16/2026 Remediate by: 7/19/2026
Remediation overdue CVE-2026-58644

Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

Microsoft — SharePoint

This vulnerability in Microsoft SharePoint allows an unauthenticated attacker to send maliciously crafted data across a network that SharePoint improperly deserializes, triggering arbitrary code execution. Because no authentication is required, the attack surface is broad — any internet-exposed SharePoint instance is at risk. Successful exploitation could give attackers full control over the affected server, potentially leading to data theft, lateral movement, or further compromise of internal systems.

Patch available

Next step: Apply the patch provided by Microsoft immediately by following the guidance at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58644.

Added: 7/16/2026 Remediate by: 7/19/2026
Remediation overdue CVE-2023-4346

KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability

KNX Association — KNX Protocol Connection Authorization Option 1

The KNX building automation protocol's Connection Authorization Option 1 contains a flaw in its account lockout mechanism. An attacker can exploit this to wipe all devices on a KNX installation and set a BCU key that effectively locks administrators out of their own devices — provided no additional security options are enabled. This is particularly serious in building control environments where KNX manages lighting, HVAC, access control, and other physical systems, meaning a successful attack could cause sustained operational disruption.

No patch reference found

Next step: No patch or vendor advisory has been identified for this vulnerability. Organizations using KNX Protocol Connection Authorization Option 1 should assess whether continued use is acceptable given the absence of available mitigations, and consider discontinuing use of the affected configuration if no fix becomes available.

Added: 7/15/2026 Remediate by: 7/29/2026
Remediation overdue CVE-2026-46817

Oracle E-Business Suite Improper Privilege Management Vulnerability

Oracle — E-Business Suite

This vulnerability in Oracle E-Business Suite allows an unauthenticated attacker to remotely compromise Oracle Payments over HTTP — no credentials required. A successful exploit can result in a full takeover of the Oracle Payments component, meaning an attacker could manipulate financial transactions, access sensitive payment data, or disrupt payment processing entirely. Because no authentication barrier exists, any internet-exposed instance is at heightened risk and should be treated as a priority.

Patch available

Next step: Review and apply the guidance published in Oracle's Critical Security Update at https://www.oracle.com/security-alerts/cspumay2026.html, and follow BOD 26-04 patching timelines based on your asset's internet exposure.

Added: 7/15/2026 Remediate by: 7/18/2026
Ransomware use CVE-2026-15409

SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability

SonicWall — SMA1000 Appliances

This server-side request forgery (SSRF) flaw in SonicWall SMA1000 appliances lets a remote attacker — without any login credentials — trick the device into making network requests to arbitrary internal or external destinations. In practice, this can be used to probe internal infrastructure, bypass perimeter controls, or pivot deeper into a network. The fact that ransomware groups are already known to exploit this vulnerability makes it an urgent priority for any organization running these appliances.

Patch available

Next step: Review and apply guidance from SonicWall's official security advisory at https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008 immediately, as this vulnerability is actively exploited in ransomware campaigns.

Added: 7/14/2026 Remediate by: 7/17/2026
Ransomware use CVE-2026-15410

SonicWall SMA1000 Appliances Code Injection Vulnerability

SonicWall — SMA1000 Appliances

This vulnerability in SonicWall SMA1000 appliances allows a remote attacker who has already gained administrator-level authentication to inject and execute arbitrary operating system commands under specific conditions. Because these are remote access appliances typically exposed to the internet, a compromised admin account could give an attacker full control over the device and potentially the network behind it. The fact that ransomware operators are already known to be exploiting this makes rapid response critical.

Patch available

Next step: Review SonicWall's official security advisory at https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008 and apply any patches or mitigations provided by the vendor immediately.

Added: 7/14/2026 Remediate by: 7/17/2026
Remediation overdue CVE-2026-56155

Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability

Microsoft — Active Directory Federation Services

Microsoft Active Directory Federation Services (AD FS) is a widely deployed identity and single sign-on solution used across enterprise environments. This vulnerability allows an attacker who already has some level of authorized access to escalate their privileges locally, potentially gaining broader control over federated identity infrastructure. Because AD FS is often central to authentication across many connected systems and applications, a successful privilege escalation here could have serious downstream consequences for organizational security.

Patch available

Next step: Review and apply any available guidance from Microsoft's official advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56155; note that no confirmed patch reference was identified in the source data at time of writing, so monitor that page closely for updates and follow BOD 26-04 patching guidelines as applicable.

Added: 7/14/2026 Remediate by: 7/28/2026
Remediation overdue CVE-2026-56164

Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability

Microsoft — SharePoint Server

This vulnerability in Microsoft SharePoint Server allows an unauthenticated attacker to elevate their privileges over the network without needing to log in first. Because SharePoint is commonly used to store sensitive documents and collaborate across organizations, an attacker exploiting this flaw could gain elevated access to critical content and functionality. The missing authentication check means there is no credential barrier to exploitation, making this especially dangerous for internet-facing SharePoint deployments.

Patch available

Next step: Review the Microsoft Security Response Center advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56164 and apply any available vendor-supplied patch or mitigation instructions immediately, following BOD 26-04 patching timelines based on your asset's internet exposure.

Added: 7/14/2026 Remediate by: 7/17/2026
Remediation overdue CVE-2008-4128

Cisco IOS Cross-Site Request Forgery Vulnerability

Cisco — IOS

This vulnerability affects Cisco IOS 12.4 routers running the HTTP management interface. An attacker can trick an authenticated administrator into unknowingly executing privileged commands — including configuration changes — simply by visiting a malicious page or clicking a crafted link. Because the attack exploits the router's trust in the administrator's browser session, it can lead to full device compromise without requiring the attacker to have credentials of their own.

No patch reference found

Next step: No patch or vendor advisory reference has been identified for this vulnerability. Organizations should evaluate whether continued use of affected Cisco IOS 12.4 devices is acceptable given that no remediation source is currently available.

Added: 7/13/2026 Remediate by: 7/16/2026
Remediation overdue CVE-2026-48939

iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability

iCagenda — iCagenda

iCagenda's file attachment feature fails to restrict what file types users can upload, allowing attackers to upload PHP files and execute arbitrary code on the server. This is a high-severity vulnerability because remote code execution gives an attacker full control over the affected system — they can steal data, install malware, pivot to internal networks, or establish persistent access. Any internet-facing deployment of iCagenda is at significant risk until this is resolved.

No patch reference found

Next step: No patch or vendor advisory has been identified at this time. If you are running iCagenda, be aware that no official fix is currently available and consider discontinuing use of the product until a patch is released, as directed by CISA's BOD 26-04 guidance.

Added: 7/10/2026 Remediate by: 7/13/2026
Remediation overdue CVE-2026-56291

Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability

Balbooa — Forms

This vulnerability in Balbooa Forms allows anyone — without logging in — to upload executable files to a affected system. Because there are no authentication checks blocking dangerous file types, an attacker can follow up by running that uploaded code on the server, achieving full remote code execution. This effectively hands an unauthenticated outsider complete control over the underlying system, making it a critical risk for any internet-facing deployment of the product.

No patch reference found

Next step: As of this advisory, no vendor patch or official advisory has been published for this vulnerability. Organizations using Balbooa Forms should be aware that no confirmed fix is currently available; per CISA guidance, consider discontinuing use of the product if mitigations cannot be applied.

Added: 7/10/2026 Remediate by: 7/13/2026
Remediation overdue CVE-2026-48282

Adobe ColdFusion Path Traversal Vulnerability

Adobe — ColdFusion

This vulnerability in Adobe ColdFusion allows an attacker to traverse directory paths outside of intended boundaries, ultimately enabling them to execute arbitrary code under the privileges of the current user. ColdFusion is widely used to build and serve web applications, so a successful exploit could give attackers a foothold on web servers, potentially leading to data theft, backdoor installation, or lateral movement within a network. The risk is elevated because it requires no elevated privileges to exploit.

Patch available

Next step: Review and apply the patch or security update detailed in Adobe's official security bulletin at https://helpx.adobe.com/security/products/coldfusion/apsb26-68.html as soon as possible.

Added: 7/7/2026 Remediate by: 7/10/2026
Remediation overdue CVE-2026-48908

JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability

JoomShaper — SP Page Builder

This vulnerability in JoomShaper's SP Page Builder allows anyone on the internet — no login required — to upload arbitrary files, including PHP scripts, to an affected server. Once a malicious PHP file is uploaded and executed, an attacker effectively gains remote code execution on the web server. This makes it a critical risk for any organization running this Joomla plugin, as full server compromise is achievable without any authentication barrier.

No patch reference found

Next step: No vendor patch or official advisory has been identified at this time; organizations running SP Page Builder should be aware that no confirmed fix is currently available and should evaluate whether continued use of this product is acceptable given the risk.

Added: 7/7/2026 Remediate by: 7/10/2026
Remediation overdue CVE-2026-55255

Langflow Authorization Bypass Through User-Controlled Key Vulnerability

Langflow — Langflow

Langflow, an AI workflow-building platform, has a flaw that lets any authenticated user run flows owned by other users simply by supplying a different flow ID in their request. This breaks tenant isolation — a malicious insider or compromised account can silently trigger another user's automated workflows, potentially exfiltrating data, abusing integrated services, or disrupting operations without needing elevated privileges beyond basic login credentials.

Patch available

Next step: Apply the patch committed at https://github.com/langflow-ai/langflow/commit/2c9f498d664a3c32698b57d7c5e752625291060e and review the official security advisory at https://github.com/langflow-ai/langflow/security/advisories/GHSA-qrpv-q767-xqq2 for full remediation guidance.

Interim mitigation: Refer to the vendor security advisory at https://github.com/langflow-ai/langflow/security/advisories/GHSA-qrpv-q767-xqq2 for any interim compensating controls. If mitigations are unavailable or cannot be applied, CISA guidance under BOD 26-04 recommends discontinuing use of the product.

Added: 7/7/2026 Remediate by: 7/10/2026
Remediation overdue CVE-2026-56290

Joomlack Page Builder Improper Access Control Vulnerability

Joomlack — Page Builder

This vulnerability in Joomlack's Page Builder extension allows unauthenticated attackers to upload arbitrary files to a target system, which can lead directly to remote code execution. Because no login is required to exploit it, the attack surface is effectively anyone who can reach the web server. A successful exploit gives an attacker the ability to run malicious code on the server, potentially leading to full system compromise, data theft, or use as a pivot point for deeper network access.

Patch available

Next step: Apply the updated version of Joomlack Page Builder referenced in the vendor's forum post at https://forum.joomlack.fr/index.php/page-builder-ck/21627-nouvelle-version-de-pbck-et-joomla-3 as soon as possible; if the patch cannot be applied, CISA guidance indicates you should consider discontinuing use of the product.

Added: 7/7/2026 Remediate by: 7/10/2026
Ransomware use CVE-2026-45659

Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability

Microsoft — SharePoint Server

This vulnerability in Microsoft SharePoint Server allows an attacker who already has some level of authorized access to exploit unsafe data deserialization and execute arbitrary code remotely. Because the attacker only needs to be 'authorized' rather than a full administrator, the bar for exploitation is lower than it might appear. Critically, this flaw has already been linked to ransomware campaigns, meaning real-world threat actors are actively weaponizing it to cause significant business disruption.

Patch available

Next step: Review and apply guidance from Microsoft's official advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659 immediately, as this vulnerability is actively exploited in ransomware attacks.

Added: 7/1/2026 Remediate by: 7/4/2026
Remediation overdue CVE-2026-48558

SimpleHelp Authentication Bypass Vulnerability

SimpleHelp — SimpleHelp

SimpleHelp's OIDC authentication flow fails to verify the cryptographic signatures of identity tokens at login. This means an unauthenticated attacker can craft a forged token with any identity claims they choose and receive a fully authenticated technician session in return. In some configurations, this also bypasses multi-factor authentication entirely. Since SimpleHelp is remote support software, a successful exploit gives attackers technician-level access to managed endpoints — a serious risk for any organization using OIDC-based login.

Patch available

Next step: Apply the vendor-issued security update immediately by following the guidance at https://simple-help.com/security/simplehelp-security-update-2026-05.

Added: 6/29/2026 Remediate by: 7/2/2026
Ransomware use CVE-2026-12569

PTC Windchill and FlexPLM Improper Input Validation Vulnerability

PTC — Windchill and FlexPLM

This critical flaw in PTC Windchill and FlexPLM — widely used product lifecycle management platforms — allows an unauthenticated attacker to remotely execute arbitrary code by simply sending a crafted network request. No credentials are required, meaning any exposed instance is at serious risk. The vulnerability has already been exploited in ransomware attacks, making it a high-priority threat for organizations running these PLM systems, particularly those with internet-facing deployments.

No patch reference found

Next step: No patch or vendor advisory reference has been identified in the available data; organizations should assess whether internet exposure of PTC Windchill or FlexPLM instances can be eliminated and monitor PTC's official channels for guidance, as CISA's required action directs discontinuing use if mitigations remain unavailable.

Added: 6/25/2026 Remediate by: 6/28/2026
Remediation overdue CVE-2026-20230

Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability

Cisco — Unified Communications Manager

This vulnerability in Cisco Unified Communications Manager allows an unauthenticated remote attacker to exploit a server-side request forgery flaw to write arbitrary files to the underlying operating system. Those written files could then be leveraged to escalate privileges all the way to root. Because no authentication is required, any internet-exposed Unified CM or Unified CM SME instance is at risk of full system compromise without any user interaction.

Patch available

Next step: Review and apply the guidance in Cisco's official security advisory at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-ssrf-cXPnHcW immediately, and follow BOD 26-04 patching timelines based on your asset's internet exposure.

Added: 6/25/2026 Remediate by: 6/28/2026
Remediation overdue CVE-2025-67038

Lantronix EDS5000 Code Injection Vulnerability

Lantronix — EDS5000

This vulnerability allows an attacker to inject arbitrary operating system commands through the username parameter of Lantronix EDS5000 devices. What makes this especially dangerous is that injected commands execute with root privileges, meaning a successful attacker gains full control of the affected device. EDS5000 units are serial-to-network device servers commonly used in industrial and enterprise environments, so compromise could expose connected serial devices and broader network segments.

No patch reference found

Next step: As of this advisory, no patch or vendor advisory has been published for this vulnerability. CISA advises applying vendor mitigations if and when they become available, or discontinuing use of the product if mitigations remain unavailable — operators should actively monitor Lantronix for any forthcoming guidance.

Added: 6/23/2026 Remediate by: 6/26/2026
Remediation overdue CVE-2026-34908

Ubiquiti UniFi OS Improper Access Control Vulnerability

Ubiquiti — UniFi OS

This vulnerability in Ubiquiti's UniFi OS allows an attacker who already has network access to make unauthorized changes to the system without proper authorization. Because UniFi OS underpins a wide range of Ubiquiti networking hardware, exploitation could let an insider threat or a lateral-moving attacker silently reconfigure network infrastructure — potentially redirecting traffic, disabling security controls, or setting up persistent footholds — without needing elevated credentials.

Patch available

Next step: Apply the patch referenced in Ubiquiti's Security Advisory Bulletin 064 (https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b) as soon as possible, following all vendor instructions provided there.

Added: 6/23/2026 Remediate by: 6/26/2026
Remediation overdue CVE-2026-34909

Ubiquiti UniFi OS Path Traversal Vulnerability

Ubiquiti — UniFi OS

This path traversal flaw in Ubiquiti UniFi OS lets an attacker on the same network read files outside intended directories on the underlying system. Those accessible files could expose credentials or configuration data that an attacker could then exploit to compromise system accounts. Because exploitation requires only network access rather than authentication, any device running a vulnerable UniFi OS version that is reachable on the network is at meaningful risk of account takeover.

Patch available

Next step: Apply the patch detailed in Ubiquiti's Security Advisory Bulletin 064 immediately, available at https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b.

Added: 6/23/2026 Remediate by: 6/26/2026
Remediation overdue CVE-2026-34910

Ubiquiti UniFi OS Improper Input Validation Vulnerability

Ubiquiti — UniFi OS

UniFi OS, the platform powering Ubiquiti's popular network management devices, fails to properly validate user input, opening a path for command injection. An attacker who can reach the device on the network — without needing physical access — could potentially execute arbitrary commands on the underlying system. This is serious for organizations using UniFi hardware for network infrastructure, as successful exploitation could give an attacker control over routing, switching, or wireless management functions.

Patch available

Next step: Apply the update referenced in Ubiquiti's Security Advisory Bulletin 064 (https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b) as soon as possible.

Added: 6/23/2026 Remediate by: 6/26/2026
Remediation overdue CVE-2026-20253

Splunk Enterprise Missing Authentication for Critical Function Vulnerability

Splunk — Enterprise

This flaw in Splunk Enterprise allows an unauthenticated attacker to create or truncate arbitrary files by targeting an exposed PostgreSQL sidecar service endpoint — no login required. For organizations running Splunk, this means an outsider could corrupt, destroy, or overwrite critical data or configuration files, potentially disrupting security monitoring operations entirely. Because Splunk is commonly used as a central security and logging platform, compromising it can blind defenders at exactly the wrong moment.

Patch available

Next step: Review and apply the mitigations and guidance detailed in Splunk's official advisory at https://advisory.splunk.com/advisories/SVD-2026-0603 immediately.

Interim mitigation: Splunk's vendor advisory (https://advisory.splunk.com/advisories/SVD-2026-0603) references mitigations for this vulnerability; consult it directly for compensating controls applicable to your environment. If mitigations cannot be applied, CISA guidance under BOD 26-04 requires evaluating whether to discontinue use of the product.

Added: 6/18/2026 Remediate by: 6/21/2026
Remediation overdue CVE-2026-48907

Widget Factory Joomla Content Editor Improper Access Control Vulnerability

Widget Factory — Joomla Content Editor

This vulnerability in the Joomla Content Editor (JCE) plugin allows unauthenticated users — meaning anyone, no login required — to create new editor profiles and exploit them to upload and execute arbitrary PHP code on the server. Remote code execution by an unauthenticated attacker represents a critical risk: a successful exploit gives an attacker direct control over the web server, enabling data theft, defacement, backdoor installation, or use as a launchpad for further attacks.

Patch available

Next step: Apply the security update immediately by reviewing the vendor's advisory and patch at https://www.joomlacontenteditor.net/news/jce-security-update-and-a-free-patch-for-older-sites, noting that a free patch is available even for older site versions.

Added: 6/16/2026 Remediate by: 6/19/2026
Remediation overdue CVE-2026-20262

Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability

Cisco — Catalyst SD-WAN Manager

This vulnerability in Cisco Catalyst SD-WAN Manager allows an authenticated remote attacker to traverse directory paths and either create new files or overwrite existing ones anywhere on the affected system's filesystem. Because attackers can manipulate critical system files, this could lead to privilege escalation, persistent backdoors, or system compromise. The fact that it only requires authentication — not administrative rights — makes it a significant risk in environments where SD-WAN Manager is internet-exposed.

Patch available

Next step: Review and apply guidance from Cisco's official security advisory at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-arbfw-c2rZvQ, and follow CISA's BOD 26-04 patching guidelines based on your asset's internet exposure.

Added: 6/15/2026 Remediate by: 6/29/2026
Remediation overdue CVE-2026-54420

LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability

LiteSpeed — cPanel Plugin

This vulnerability affects the LiteSpeed cPanel plugin on shared hosting servers running CloudLinux/CageFS. A user with FTP or web shell access could exploit a symlink-following flaw to escape their sandboxed environment, potentially accessing or manipulating files belonging to other users or the server itself. On shared hosting platforms, this is especially serious because multiple customers share the same underlying system, meaning one compromised or malicious tenant could impact everyone else.

Patch available

Next step: Review and apply the security update detailed in the LiteSpeed vendor advisory at https://blog.litespeedtech.com/2026/06/01/security-update-for-litespeed-cpanel-plugin-2/ as soon as possible.

Added: 6/15/2026 Remediate by: 6/18/2026
Ransomware use CVE-2026-35273

Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability

Oracle — PeopleSoft Enterprise PeopleTools

This vulnerability in Oracle PeopleSoft Enterprise PeopleTools allows an unauthenticated attacker — someone with no credentials whatsoever — to completely take over the affected system. PeopleSoft is widely used for HR, finance, and enterprise management, making a full takeover especially damaging. The flaw is already being exploited in ransomware campaigns, meaning real-world attacks are active and the window for remediation is narrow. Any internet-exposed PeopleSoft instance should be treated as critically at risk.

Patch available

Next step: Review Oracle's official security advisory at https://www.oracle.com/security-alerts/alert-cve-2026-35273.html and apply any available patches or vendor-specified mitigations immediately, prioritizing internet-exposed instances in accordance with CISA's BOD 26-04 guidance.

Added: 6/12/2026 Remediate by: 6/15/2026
Remediation overdue CVE-2026-10520

Ivanti Sentry OS Command Injection Vulnerability

Ivanti — Sentry

This critical flaw in Ivanti Sentry allows a remote attacker with no credentials to execute commands as root — the highest privilege level on the system. Because Sentry acts as a mobile device management gateway, a full compromise could expose MDM infrastructure and the devices it manages. The risk is highest when the appliance is unmanaged and its interfaces are publicly reachable. Deployments using mTLS with EPMM or restricted HTTPS access through Neurons for MDM have those interfaces shielded from external attackers.

Patch available

Next step: Apply the vendor-supplied patch immediately by following Ivanti's official security advisory at https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Sentry-CVE-2026-10520-CVE-2026-10523.

Added: 6/11/2026 Remediate by: 6/14/2026
Remediation overdue CVE-2026-11645

Google Chromium V8 Out-of-Bounds Read and Write Vulnerability

Google — Chromium V8

This vulnerability in Chromium's V8 JavaScript engine allows a remote attacker to execute arbitrary code by tricking a user into visiting a crafted HTML page. Because V8 powers Chrome, Edge, Opera, and other Chromium-based browsers, the attack surface is extremely broad. Although execution is confined within the browser sandbox, sandbox escapes are a known follow-on risk, making this a serious threat to any organization whose users browse the web.

Patch available

Next step: Apply the updated browser release documented in Google's stable channel advisory at https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0153744567.html — ensure all Chromium-based browsers in your environment (Chrome, Edge, Opera, etc.) are updated promptly.

Added: 6/9/2026 Remediate by: 6/23/2026
Remediation overdue CVE-2026-20245

Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability

Cisco — Catalyst SD-WAN Manager

This vulnerability in Cisco Catalyst SD-WAN Manager allows an authenticated local attacker to escalate privileges and execute arbitrary commands as root by supplying a crafted file to the system. Because root-level code execution can give an attacker complete control over the SD-WAN management plane, the blast radius is severe — potentially exposing the entire SD-WAN fabric to further compromise. The requirement for local, authenticated access limits exposure somewhat, but insider threats and compromised credentials remain realistic attack paths.

Patch available

Next step: Review and apply the guidance provided in Cisco's official security advisory at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-privesc-4uxFrdzx immediately.

Added: 6/9/2026 Remediate by: 6/23/2026
Remediation overdue CVE-2026-7473

Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability

Arista — Extensible Operating System

Arista EOS switches with tunnel decapsulation configured can incorrectly decapsulate and forward unexpected tunneled packets whose destination IP matches the switch's decapsulation IP. This means an attacker could craft malicious tunneled traffic that the switch processes and forwards when it should not, potentially bypassing network segmentation or security controls. Any environment running affected Arista EOS versions with tunnel decapsulation enabled is at risk of unintended packet forwarding.

Patch available

Next step: Review and apply the guidance provided in Arista's Security Advisory 0137 at https://www.arista.com/en/support/advisories-notices/security-advisory/24005-security-advisory-0137 immediately.

Interim mitigation: Arista's Security Advisory 0137 references mitigations and compensating controls — consult that advisory directly at https://www.arista.com/en/support/advisories-notices/security-advisory/24005-security-advisory-0137 for the specific steps applicable to your environment.

Added: 6/9/2026 Remediate by: 6/23/2026
Remediation overdue CVE-2026-42271

BerriAI LiteLLM Command Injection Vulnerability

BerriAI — LiteLLM

This vulnerability in BerriAI LiteLLM allows any authenticated user — even those with low-privilege internal-user keys — to inject and execute arbitrary commands directly on the underlying host system. This is a critical risk because it means attackers don't need administrative access to take control of the server. A compromised or malicious low-privilege account could be used to exfiltrate data, pivot to other systems, or fully compromise the host running LiteLLM.

Patch available

Next step: Review and apply the guidance published in the vendor's official security advisory at https://github.com/BerriAI/litellm/security/advisories/GHSA-v4p8-mg3p-g94g immediately.

Interim mitigation: Refer to the vendor's security advisory at https://github.com/BerriAI/litellm/security/advisories/GHSA-v4p8-mg3p-g94g for any interim mitigations. If mitigations are unavailable and the patch cannot be applied, CISA advises discontinuing use of the product.

Added: 6/8/2026 Remediate by: 6/22/2026
Ransomware use CVE-2026-50751

Check Point Security Gateway Improper Authentication Vulnerability

Check Point — Security Gateway

This flaw in Check Point Security Gateway allows an unauthenticated remote attacker to bypass password authentication by exploiting a weakness in the IKEv1 key exchange process, ultimately letting them establish a full remote access VPN connection without valid credentials. Because it requires no prior access and circumvents a core authentication control, it effectively hands attackers a legitimate-looking tunnel into protected networks. The confirmed use in ransomware campaigns makes this an urgent, high-priority threat for any organization running the affected product.

Patch available

Next step: Apply the patch and follow the vendor instructions detailed in Check Point's official advisory at https://support.checkpoint.com/results/sk/sk185033 immediately.

Interim mitigation: Check Point's advisory at https://support.checkpoint.com/results/sk/sk185033 references mitigations; consult that document directly for any compensating controls applicable if patching cannot be performed immediately.

Added: 6/8/2026 Remediate by: 6/11/2026
Remediation overdue CVE-2026-28318

SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability

SolarWinds — Serv-U

This vulnerability in SolarWinds Serv-U allows any unauthenticated attacker to crash the file transfer service by sending a specially crafted POST request using a deflate content-encoding header. Because no authentication is required, the attack surface is wide — anyone who can reach the Serv-U service over the network can trigger a denial of service, taking the service offline and disrupting file transfer operations until it is restarted or patched.

Patch available

Next step: Review the SolarWinds security advisory at https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28318 and apply any available patch or vendor-recommended fix as soon as possible.

Added: 6/5/2026 Remediate by: 6/19/2026
Remediation overdue CVE-2026-45247

Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability

Mirasvit — Mirasvit Full Page Cache Warmer

This vulnerability allows an unauthenticated attacker to send a specially crafted serialized PHP object via the CacheWarmer cookie, triggering PHP deserialization flaws that result in full remote code execution on the server. No login or privileges are required, meaning any internet-exposed Magento store running this extension is at risk of complete server compromise. The ease of exploitation and severity of the outcome make this a critical priority for any organization running the affected plugin.

No patch reference found

Next step: No patch or vendor advisory has been published at this time; if you cannot confirm a fix is available from Mirasvit, you should disable or remove the Mirasvit Full Page Cache Warmer extension immediately until a remediated version is released.

Added: 6/3/2026 Remediate by: 6/6/2026
Remediation overdue CVE-2022-0492

Linux Kernel Improper Authentication Vulnerability

Linux — Kernel

This Linux kernel flaw allows an unprivileged local user to escalate their privileges to root by abusing the cgroups v1 release_agent feature, which lacks proper authentication checks. In practice, this means any user with local access to an affected system — including container workloads — could potentially gain full system control. It is especially concerning in multi-tenant or containerized environments where privilege boundaries are critical security assumptions.

Patch available

Next step: Apply the upstream kernel patch identified in the official Linux kernel commit (git.kernel.org) and review the Red Hat bugzilla advisory at bugzilla.redhat.com/show_bug.cgi?id=2051505 for distribution-specific guidance and patched package versions.

Added: 6/2/2026 Remediate by: 6/5/2026
Remediation overdue CVE-2025-48595

Android Framework Integer Overflow Vulnerability

Android — Framework

An integer overflow in the Android Framework can be exploited by a malicious local application or actor to execute arbitrary code and escalate privileges on the device. Because this affects the core Android Framework, a successful exploit could give an attacker elevated control over the operating system and its data without needing physical access beyond an existing low-privileged foothold. Any Android device running a vulnerable version is at risk.

Patch available

Next step: Review the Android Security Bulletin at https://source.android.com/docs/security/bulletin/2026/2026-06-01 and apply the relevant security patches as soon as they are available from Google or your device manufacturer.

Added: 6/2/2026 Remediate by: 6/5/2026
Remediation overdue CVE-2024-21182

Oracle WebLogic Server Unspecified Vulnerability

Oracle — WebLogic Server

Oracle WebLogic Server contains a flaw reachable over the T3 and IIOP network protocols without any authentication. An attacker who can reach the server on these ports could silently read sensitive data or gain complete access to everything the server can access. Because no credentials are required, the attack surface extends to any network-exposed WebLogic instance, making this a high-priority risk for organizations running WebLogic in internet-facing or multi-tenant environments.

Patch available

Next step: Review and apply the fixes detailed in Oracle's July 2024 Critical Patch Update advisory at https://www.oracle.com/security-alerts/cpujul2024.html as soon as possible.

Added: 6/1/2026 Remediate by: 6/4/2026
Ransomware use CVE-2026-0257

Palo Alto Networks PAN-OS Authentication Bypass Vulnerability

Palo Alto Networks — PAN-OS

This authentication bypass in Palo Alto Networks PAN-OS allows attackers to circumvent security controls and establish unauthorized VPN connections without valid credentials. Because it bypasses authentication entirely, an attacker gains network-level access that would normally require legitimate user credentials. The vulnerability is already being exploited in ransomware campaigns, meaning active threat actors are using it to gain footholds inside enterprise networks right now, making rapid response critical.

Patch available

Next step: Consult the Palo Alto Networks security advisory at https://security.paloaltonetworks.com/CVE-2026-0257 for patch and remediation details, and apply any available fixes immediately given active ransomware exploitation.

Added: 5/29/2026 Remediate by: 6/1/2026
Ransomware use CVE-2026-45321

TanStack Unspecified Vulnerability

TanStack — TanStack

This vulnerability allowed attackers to publish malicious versions of TanStack packages to the npm registry under the project's trusted identity. Because developers and build pipelines inherently trust packages from known publishers, this created a supply-chain attack vector where credential-stealing malware could be silently introduced into downstream projects. The fact that ransomware actors have leveraged this makes it especially severe — any environment that pulled affected package versions may have had credentials compromised.

Patch available

Next step: Review the vendor security advisory at https://github.com/TanStack/router/security/advisories/GHSA-g7cv-rxg3-hmpx immediately for guidance on affected versions and required remediation steps.

Interim mitigation: Refer to the vendor advisory at https://github.com/TanStack/router/security/advisories/GHSA-g7cv-rxg3-hmpx for any interim compensating controls or mitigation guidance provided by the TanStack maintainers.

Added: 5/27/2026 Remediate by: 6/10/2026
Ransomware use CVE-2026-48027

Nx Console Embedded Malicious Code Vulnerability

Nx — Nx Console

A malicious version of the Nx Console extension was published, containing embedded malicious code that fetched an obfuscated payload capable of harvesting credentials from multiple sources — both on disk and in memory. This is a supply chain attack targeting developers who use Nx Console, meaning legitimate-looking tooling delivered the compromise. The threat is serious: credential theft enables lateral movement, privilege escalation, and ransomware deployment, and this vulnerability is already associated with known ransomware use.

Patch available

Next step: Review the vendor security advisory at https://github.com/nrwl/nx-console/security/advisories/GHSA-c9j4-9m59-847w immediately and follow all vendor instructions; if mitigations cannot be applied, discontinue use of Nx Console.

Interim mitigation: Refer to the vendor security advisory at https://github.com/nrwl/nx-console/security/advisories/GHSA-c9j4-9m59-847w for specific compensating controls and remediation steps; no additional mitigation details are available in the source data beyond what the vendor advisory provides.

Added: 5/27/2026 Remediate by: 6/10/2026
Remediation overdue CVE-2026-8398

Daemon Tools Lite Embedded Malicious Code Vulnerability

Daemon — Daemon Tools Lite

Daemon Tools Lite, a widely used virtual drive and disc imaging application, has been flagged for containing embedded malicious code. The vulnerability carries high impact ratings across confidentiality, integrity, and availability, meaning attackers could potentially access sensitive data, alter system files, and disrupt operations. Because the software runs with elevated privileges during installation and use, malicious code embedded within it poses a serious risk to any system where it is installed.

Patch available

Next step: Review the vendor's official security incident disclosure at https://blog.daemon-tools.cc/post/security-incident and follow any guidance provided there; if no remediated version or clear resolution is available, discontinue use of the product immediately.

Added: 5/27/2026 Remediate by: 5/30/2026
Remediation overdue CVE-2026-48172

LiteSpeed cPanel Plugin Privilege Escalation Vulnerability

LiteSpeed — cPanel Plugin

This vulnerability in the LiteSpeed cPanel Plugin allows any standard cPanel user account to run arbitrary scripts with root-level privileges on the server. In shared hosting environments, where many untrusted users share the same system, this is especially dangerous — a single compromised or malicious account could gain full control of the host, affecting all other tenants and the underlying infrastructure.

Patch available

Next step: Review and apply the security update detailed in the vendor's advisory at https://blog.litespeedtech.com/2026/05/21/security-update-for-litespeed-cpanel-plugin/ immediately.

Added: 5/26/2026 Remediate by: 5/29/2026
Remediation overdue CVE-2026-9082

Drupal Core SQL Injection Vulnerability

Drupal — Core

Drupal's database abstraction API contains a SQL injection flaw that attackers can exploit by sending specially crafted requests. Successful exploitation can lead to privilege escalation — allowing an attacker to gain higher-level access than intended — and potentially remote code execution, meaning an attacker could run arbitrary code on the server. Any organization running Drupal Core is at risk, and compromise of the web server or underlying data could follow.

Patch available

Next step: Apply the patch immediately by following the vendor security advisory at https://www.drupal.org/sa-core-2026-004.

Added: 5/22/2026 Remediate by: 5/27/2026
Remediation overdue CVE-2025-34291

Langflow Origin Validation Error Vulnerability

Langflow — Langflow

Langflow's overly permissive CORS configuration, combined with its refresh token cookie being set to SameSite=None, allows a malicious website to make credentialed cross-origin requests to the refresh endpoint. An attacker who tricks a logged-in user into visiting a malicious page can silently steal valid session tokens, then use those tokens to access authenticated endpoints and execute arbitrary code — potentially resulting in full system compromise. This is especially serious for organizations using Langflow to orchestrate AI agent workflows with access to sensitive data or infrastructure.

No patch reference found

Next step: No official vendor patch or advisory has been published as of this writing; administrators should review the Obsidian Security disclosure at https://www.obsidiansecurity.com/blog/cve-2025-34291-critical-account-takeover-and-rce-vulnerability-in-the-langflow-ai-agent-workflow-platform for available guidance, and seriously consider discontinuing use of the product until an official fix is released.

Interim mitigation: The Obsidian Security advisory linked above is the only currently available reference for compensating controls and remediation details; administrators should consult it directly for interim guidance while awaiting an official vendor response.

Added: 5/21/2026 Remediate by: 6/4/2026
Remediation overdue CVE-2026-34926

Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability

Trend Micro — Apex One

This vulnerability in Trend Micro Apex One (on-premise) allows a local attacker who has not yet authenticated to exploit a directory traversal flaw, enabling them to tamper with a key server-side table and inject malicious code. That code can then be pushed out to all managed agents across the deployment. The result is a potential full compromise of every endpoint Apex One manages, making this a high-impact threat in enterprise environments relying on centralized endpoint protection.

Patch available

Next step: Review and apply guidance from the Trend Micro advisory at https://success.trendmicro.com/en-US/solution/KA-0023430 immediately.

Added: 5/21/2026 Remediate by: 6/4/2026
Remediation overdue CVE-2008-4250

Microsoft Windows Buffer Overflow Vulnerability

Microsoft — Windows

This critical vulnerability in Microsoft's Windows Server Service allows an unauthenticated remote attacker to execute arbitrary code by sending a specially crafted RPC request. The flaw triggers a buffer overflow during path canonicalization, meaning no user interaction is required. Successful exploitation grants full system control, making this a high-priority risk for any Windows environment where the Server Service is reachable over a network — which includes most default Windows installations.

Patch available

Next step: Apply the patch referenced in the Secunia advisory (secunia.com/advisories/32326); this vulnerability has had a patch available since 2008 and any affected system still unpatched should be updated or decommissioned immediately.

Added: 5/20/2026 Remediate by: 6/3/2026
Remediation overdue CVE-2009-1537

Microsoft DirectX NULL Byte Overwrite Vulnerability

Microsoft — DirectX

This vulnerability in Microsoft DirectX's QuickTime Movie Parser Filter allows attackers to execute arbitrary code simply by tricking a user into opening a specially crafted QuickTime media file. Because DirectShow is widely used for media playback, the attack surface is broad — any system that processes QuickTime content through DirectX could be compromised remotely. Successful exploitation gives an attacker the same privileges as the logged-in user, making this a serious remote code execution risk.

Patch available

Next step: Apply the patch or mitigations detailed in Microsoft Security Advisory 971778, available at http://www.microsoft.com/technet/security/advisory/971778.mspx.

Added: 5/20/2026 Remediate by: 6/3/2026
Remediation overdue CVE-2009-3459

Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability

Adobe — Acrobat and Reader

This vulnerability in Adobe Acrobat and Reader allows an attacker to trigger a heap-based buffer overflow simply by convincing a user to open a malicious PDF file. Successful exploitation leads to memory corruption and arbitrary code execution — meaning an attacker can take full control of the affected system with no special privileges beyond getting the victim to open a file. PDF files are ubiquitous in business environments, making this a high-value attack vector with a low barrier to exploitation.

Patch available

Next step: Apply the patch provided by Adobe in security bulletin APSB09-15, available at http://www.adobe.com/support/security/bulletins/apsb09-15.html, immediately.

Added: 5/20/2026 Remediate by: 6/3/2026
Remediation overdue CVE-2010-0249

Microsoft Internet Explorer Use-After-Free Vulnerability

Microsoft — Internet Explorer

This use-after-free flaw in Microsoft Internet Explorer allows a remote attacker to execute arbitrary code simply by getting a user to visit a malicious web page. By manipulating a pointer to an already-deleted object, an attacker can gain full control of the affected system. The vulnerability is particularly concerning because Internet Explorer is likely end-of-life or end-of-service, meaning ongoing security support may no longer exist, leaving systems permanently exposed if the software continues to be used.

Patch available

Next step: Apply the patch documented in Microsoft Knowledge Base article 979352 (support.microsoft.com/kb/979352) and review the associated Microsoft Security Advisory 979352; if patching is not feasible, CISA explicitly recommends discontinuing use of the affected product.

Added: 5/20/2026 Remediate by: 6/3/2026
Remediation overdue CVE-2010-0806

Microsoft Internet Explorer Use-After-Free Vulnerability

Microsoft — Internet Explorer

This vulnerability in Microsoft Internet Explorer allows attackers to execute arbitrary code remotely by exploiting a use-after-free flaw — a memory corruption issue where the browser attempts to access a pointer to an object that has already been deleted. A successful attack could give an attacker full control of the affected system. CISA notes the product may be end-of-life or end-of-service, meaning it likely no longer receives security updates, leaving systems permanently exposed if the software remains in use.

Patch available

Next step: CISA explicitly recommends discontinuing use of the affected Internet Explorer version due to its likely end-of-life/end-of-service status; if immediate removal is not possible, review the CERT/CC advisory at http://www.kb.cert.org/vuls/id/744549 for any available patch guidance.

Added: 5/20/2026 Remediate by: 6/3/2026
Remediation overdue CVE-2026-41091

Microsoft Defender Link Following Vulnerability

Microsoft — Defender

This vulnerability in Microsoft Defender allows an attacker who already has some level of authorized access to a system to exploit a link following weakness and gain higher privileges locally. In practice, this means a low-privileged user or compromised account could leverage Defender itself — a trusted security tool — to escalate their access, potentially taking full control of the affected machine. Because Defender is widely deployed across Windows environments, the attack surface is broad.

Patch available

Next step: Review and apply the guidance provided in Microsoft's official advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41091, as no standalone patch reference was identified in the available source data.

Added: 5/20/2026 Remediate by: 6/3/2026
Remediation overdue CVE-2026-45498

Microsoft Defender Denial of Service Vulnerability

Microsoft — Defender

Microsoft Defender, the security software built into Windows environments, contains an unspecified flaw that can be exploited to cause a denial of service condition. This means an attacker could potentially disable or disrupt the endpoint protection that organizations rely on to detect and block threats. Losing Defender availability could leave systems exposed to malware or other attacks during the outage window, making this a meaningful risk even without direct code execution.

Patch available

Next step: Review the Microsoft Security Response Center advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45498 and apply any available patches or vendor-recommended mitigations as soon as possible.

Added: 5/20/2026 Remediate by: 6/3/2026
Remediation overdue CVE-2026-42897

Microsoft Exchange Server Cross-Site Scripting Vulnerability

Microsoft — Microsoft

This vulnerability affects Microsoft Exchange Server's Outlook Web Access (OWA) interface, allowing attackers to inject and execute arbitrary JavaScript in a victim's browser under specific interaction conditions. A successful exploit could let an attacker hijack user sessions, steal credentials, or perform actions on behalf of the user within OWA — all without needing direct server access. Because Exchange is commonly used for corporate email, a widely exploited XSS here could serve as an entry point into broader organizational compromise.

Patch available

Next step: Apply mitigations and review guidance per the Microsoft Security Response Center advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42897, as no standalone patch reference was separately identified in the source data.

Interim mitigation: Refer to the Microsoft Security Response Center advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42897 for any available compensating controls or interim mitigations; no specific workaround details beyond vendor instructions were present in the source data.

Added: 5/15/2026 Remediate by: 5/29/2026
Remediation overdue CVE-2026-20182

Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability

Cisco — Catalyst SD-WAN

This vulnerability allows an unauthenticated remote attacker to completely bypass authentication on Cisco Catalyst SD-WAN Controllers and Managers, gaining full administrative control. Because SD-WAN controllers sit at the heart of wide-area network infrastructure, a successful exploit could let an attacker reroute traffic, alter network configurations, or pivot deeper into the organization — all without needing any valid credentials. The wide network exposure of these management interfaces makes this a high-priority threat.

Patch available

Next step: Review the Cisco Security Advisory at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW for remediation guidance, and follow CISA's Emergency Directive 26-03 and CISA's Hunt & Hardening Guidance for Cisco SD-WAN Devices to assess exposure and act accordingly — discontinuing use of the product if mitigations are unavailable.

Added: 5/14/2026 Remediate by: 5/17/2026
Remediation overdue CVE-2026-42208

BerriAI LiteLLM SQL Injection Vulnerability

BerriAI — LiteLLM

BerriAI LiteLLM, a popular proxy for managing LLM API calls, contains a SQL injection flaw that lets an attacker read and potentially modify data in the proxy's underlying database. Because LiteLLM stores credentials for AI services, a successful exploit could expose API keys and access tokens for multiple LLM providers, leading to unauthorized use of those services and potential data exfiltration from any system the proxy touches.

Patch available

Next step: Review and apply the patch or mitigations detailed in the vendor's security advisory at https://github.com/BerriAI/litellm/security/advisories/GHSA-r75f-5x8p-qvmc immediately.

Interim mitigation: The vendor security advisory at https://github.com/BerriAI/litellm/security/advisories/GHSA-r75f-5x8p-qvmc is the authoritative source for any available compensating controls; consult it directly for interim mitigation steps if an immediate upgrade is not possible.

Added: 5/8/2026 Remediate by: 5/11/2026
Remediation overdue CVE-2026-6973

Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability

Ivanti — Endpoint Manager Mobile (EPMM)

This vulnerability in Ivanti Endpoint Manager Mobile allows an authenticated administrator-level attacker to remotely execute arbitrary code on the system. While requiring admin credentials raises the bar slightly, compromised admin accounts — through phishing or credential theft — are a realistic threat vector. EPMM is a mobile device management platform, meaning a successful exploit could give attackers control over the MDM infrastructure and, by extension, visibility into or control of managed mobile devices across an organization.

Patch available

Next step: Review and apply the guidance published in Ivanti's May 2026 Security Advisory at https://hub.ivanti.com/s/article/May-2026-Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-Multiple-CVEs immediately, as no standalone patch reference was identified in the available data.

Added: 5/7/2026 Remediate by: 5/10/2026
Remediation overdue CVE-2026-0300

Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability

Palo Alto Networks — PAN-OS

This critical flaw in Palo Alto Networks PAN-OS allows an unauthenticated attacker to send specially crafted packets to the User-ID Authentication Portal (Captive Portal) service and execute arbitrary code with root privileges on PA-Series and VM-Series firewalls. Because no authentication is required and the attacker gains full root access, a successful exploit could mean complete compromise of the firewall itself — the device meant to protect the network perimeter.

Patch available

Next step: Palo Alto Networks has released patches as of May 13, 2026; review the vendor advisory at https://security.paloaltonetworks.com/CVE-2026-0300 to identify the applicable patch for your PAN-OS version and apply it immediately.

Interim mitigation: Until patching is complete, restrict User-ID Authentication Portal access to only trusted zones, or disable the User-ID Authentication Portal entirely if it is not required in your environment.

Added: 5/6/2026 Remediate by: 5/9/2026
Remediation overdue CVE-2026-31431

Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability

Linux — Kernel

This Linux Kernel flaw involves incorrect resource transfer between security boundaries, a class of bug that attackers can exploit to gain elevated privileges on a compromised system. In practice, a local user or process with limited rights could leverage this vulnerability to escalate to root or kernel-level access, potentially taking full control of the affected host. Any Linux system running a vulnerable kernel version is at risk, making this particularly urgent for servers, cloud instances, and embedded Linux devices.

Patch available

Next step: Apply the patched kernel commit referenced at https://git.kernel.org/stable/c/19d43105a97be0810edbda875f2cd03f30dc130c and review the official announcement at https://lore.kernel.org/linux-cve-announce/2026042214-CVE-2026-31431-3d65@gregkh/ for version-specific guidance.

Added: 5/1/2026 Remediate by: 5/15/2026
Ransomware use CVE-2026-41940

WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability

WebPros — cPanel & WHM and WP2 (WordPress Squared)

This vulnerability allows unauthenticated remote attackers to bypass the login process entirely and gain full access to cPanel & WHM or WP2 control panels without valid credentials. Because these panels control web hosting environments — including DNS, email, databases, and file management — a successful attack can lead to complete server compromise. The fact that ransomware groups are already actively exploiting this flaw makes it an urgent, high-priority threat for any organization running affected WebPros products.

Patch available

Next step: Apply the security update immediately by following the vendor advisory published by cPanel at https://support.cpanel.net/hc/en-us/articles/40073787579671-cPanel-WHM-Security-Update-04-28-2026.

Added: 4/30/2026 Remediate by: 5/3/2026
Ransomware use CVE-2024-1708

ConnectWise ScreenConnect Path Traversal Vulnerability

ConnectWise — ScreenConnect

This path traversal flaw in ConnectWise ScreenConnect lets attackers break out of intended directory boundaries, potentially executing remote code or accessing sensitive data and critical systems without authorization. Critically, ransomware groups are known to have actively exploited this vulnerability, meaning unpatched systems face a realistic and documented threat of full compromise — not just theoretical risk.

Patch available

Next step: Review and apply the vendor's security bulletin immediately: https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8. If patching is not possible, CISA advises discontinuing use of the product.

Added: 4/28/2026 Remediate by: 5/12/2026
Remediation overdue CVE-2026-32202

Microsoft Windows Protection Mechanism Failure Vulnerability

Microsoft — Windows

This vulnerability in the Microsoft Windows Shell allows an unauthenticated attacker on a network to spoof content or identity by exploiting a failure in a protection mechanism. In practical terms, an attacker could manipulate what users or systems see as trustworthy, potentially enabling phishing, credential theft, or further compromise. Because it requires no authentication and operates over the network, the attack surface is broad and the barrier to exploitation is relatively low.

Patch available

Next step: Review and apply guidance from the Microsoft Security Response Center advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32202; no standalone patch reference was confirmed in the source data, so monitor that page closely for updates.

Interim mitigation: A mitigation script addressing this spoofing vulnerability in Windows Shell has been referenced at https://www.vicarius.io/vsociety/posts/cve-2026-32202-mitigation-script-spoofing-vulnerability-in-windows-shell — review and evaluate it for applicability in your environment while awaiting a confirmed vendor patch.

Added: 4/28/2026 Remediate by: 5/12/2026
Ransomware use CVE-2024-57726

SimpleHelp Missing Authorization Vulnerability

SimpleHelp — SimpleHelp

This flaw in SimpleHelp allows low-privileged technicians to generate API keys that carry far more permissions than their account should allow. By exploiting these over-privileged keys, an attacker can escalate all the way to full server administrator access. The vulnerability has already been linked to ransomware activity, meaning real-world attackers are actively leveraging it — making exposure through any internet-facing SimpleHelp deployment particularly dangerous.

No patch reference found

Next step: Apply mitigations per vendor instructions as directed by CISA; however, no specific patch or vendor advisory reference has been identified in available data, so administrators should contact SimpleHelp directly and monitor official channels urgently for guidance — or consider discontinuing use until a fix is confirmed available.

Added: 4/24/2026 Remediate by: 5/8/2026
Ransomware use CVE-2024-57728

SimpleHelp Path Traversal Vulnerability

SimpleHelp — SimpleHelp

SimpleHelp, a remote support tool, contains a path traversal flaw where admin-level users can upload a specially crafted zip file that places files anywhere on the server's filesystem — a classic 'zip slip' attack. This allows attackers to achieve arbitrary code execution running as the SimpleHelp server process. The vulnerability is already linked to active ransomware campaigns, making unpatched installations a high-priority target for significant business disruption.

Patch available

Next step: Apply the update referenced in SimpleHelp's January 2025 security advisory at https://simple-help.com/kb---security-vulnerabilities-01-2025, which addresses vulnerabilities in SimpleHelp 5.5.7 and earlier.

Added: 4/24/2026 Remediate by: 5/8/2026
Remediation overdue CVE-2024-7399

Samsung MagicINFO 9 Server Path Traversal Vulnerability

Samsung — MagicINFO 9 Server

Samsung MagicINFO 9 Server, a digital signage management platform, contains a path traversal flaw that lets unauthenticated or low-privilege attackers write arbitrary files with system-level authority. This is serious because writing files as the system account can enable full server compromise — attackers could plant web shells, overwrite configuration files, or stage further attacks across managed display infrastructure without needing elevated credentials.

Patch available

Next step: Consult Samsung's official security updates page at https://security.samsungtv.com/securityUpdates and apply any available patch or update for MagicINFO 9 Server immediately.

Added: 4/24/2026 Remediate by: 5/8/2026
Remediation overdue CVE-2025-29635

D-Link DIR-823X Command Injection Vulnerability

D-Link — DIR-823X

The D-Link DIR-823X router contains a command injection flaw that lets an authenticated attacker run arbitrary operating system commands on the device by sending a crafted POST request to a specific configuration endpoint. Because the device is likely end-of-life or end-of-service, no patch is expected from D-Link. This gives attackers who gain even basic authenticated access full control over the router, potentially exposing the entire network behind it.

No patch reference found

Next step: No patch or vendor advisory is available for this vulnerability. CISA explicitly states the product is likely end-of-life or end-of-service and recommends discontinuing use of the D-Link DIR-823X immediately and replacing it with a supported device.

Added: 4/24/2026 Remediate by: 5/8/2026
Remediation overdue CVE-2026-39987

Marimo Remote Code Execution Vulnerability

Marimo — Marimo

This vulnerability in Marimo allows an unauthenticated attacker to execute arbitrary system commands without any prior login or credentials — a pre-authorization remote code execution flaw. In practice, this means anyone who can reach a Marimo instance over the network could gain shell-level control of the underlying system, potentially leading to full server compromise, data exfiltration, or use as a foothold for further attacks. No user interaction or account is required, making this especially dangerous for internet-exposed deployments.

Patch available

Next step: Apply the patch referenced in the vendor security advisory immediately: review the GitHub Security Advisory at https://github.com/marimo-team/marimo/security/advisories/GHSA-2679-6mx9-h9xc and apply the fix from the linked commit.

Interim mitigation: Refer to the vendor's security advisory at https://github.com/marimo-team/marimo/security/advisories/GHSA-2679-6mx9-h9xc for any interim compensating controls or mitigations; if patching is not immediately possible and mitigations are unavailable, CISA guidance indicates discontinuing use of the product should be considered.

Added: 4/23/2026 Remediate by: 5/7/2026
Ransomware use CVE-2026-33825

Microsoft Defender Insufficient Granularity of Access Control Vulnerability

Microsoft — Defender

This vulnerability in Microsoft Defender allows an attacker who already has some level of authorized access to a system to gain higher privileges locally. Because Defender runs with elevated trust on virtually every modern Windows environment, a privilege escalation here can let an attacker move from a limited user account to full system control. The fact that ransomware groups are actively exploiting this makes it especially urgent for organizations of all sizes.

Patch available

Next step: Review the Microsoft Security Response Center advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33825 and apply any available patches or mitigations per vendor instructions immediately; no standalone patch reference was identified in the source data, so checking that advisory directly is the critical next step.

Added: 4/22/2026 Remediate by: 5/6/2026
Ransomware use CVE-2023-27351

PaperCut NG/MF Improper Authentication Vulnerability

PaperCut — NG/MF

PaperCut NG and MF, widely used print management software, contain an authentication bypass flaw in the SecurityRequestFilter class that allows remote attackers to access protected functionality without valid credentials. This is especially serious because ransomware groups have actively exploited this vulnerability in real-world attacks, meaning unpatched systems face a high and immediate risk of compromise, data theft, or full network takeover through a widely deployed enterprise application.

Patch available

Next step: Review and apply the guidance provided in PaperCut's official advisory at https://www.papercut.com/kb/Main/PO-1216-and-PO-1219 immediately, as this vulnerability is actively being exploited by ransomware actors.

Added: 4/20/2026 Remediate by: 5/4/2026
Ransomware use CVE-2024-27199

JetBrains TeamCity Relative Path Traversal Vulnerability

JetBrains — TeamCity

This path traversal flaw in JetBrains TeamCity lets attackers navigate outside intended directories to perform limited administrative actions without proper authorization. TeamCity is a widely used CI/CD build server, meaning it sits at the heart of software development pipelines and often holds sensitive credentials and source code access. The vulnerability is actively exploited in ransomware campaigns, making it an urgent risk for any organization running an unpatched TeamCity instance.

Patch available

Next step: Review and apply the fixes documented in JetBrains' security issues page at https://www.jetbrains.com/privacy-security/issues-fixed/ immediately, as this vulnerability is known to be exploited by ransomware operators.

Added: 4/20/2026 Remediate by: 5/4/2026
Remediation overdue CVE-2025-2749

Kentico Xperience Path Traversal Vulnerability

Kentico — Kentico Xperience

This vulnerability in Kentico Xperience allows an authenticated user to abuse the Staging Sync Server feature to write arbitrary data outside of intended directories via path traversal. In practice, this means an attacker with valid credentials could plant malicious files — such as web shells — in sensitive locations on the server, potentially leading to full system compromise. Because authentication is required, the immediate risk is somewhat contained, but insider threats or compromised accounts make this serious.

Patch available

Next step: Apply the available hotfix from Kentico's official hotfix download page at https://devnet.kentico.com/download/hotfixes as soon as possible.

Added: 4/20/2026 Remediate by: 5/4/2026
Remediation overdue CVE-2025-32975

Quest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability

Quest — KACE Systems Management Appliance (SMA)

Quest KACE SMA is a widely deployed endpoint and systems management platform used by IT teams to manage devices across an organization. This vulnerability allows attackers to bypass authentication entirely, impersonating legitimate users without needing valid credentials. In practice, this means an unauthenticated attacker could gain unauthorized access to the management appliance, potentially taking control of managed endpoints, deploying software, or accessing sensitive configuration data across the environment.

Patch available

Next step: Review and apply the guidance provided in Quest's official advisory at https://support.quest.com/kb/4379499/quest-response-to-kace-sma-vulnerabilities-cve-2025-32975-cve-2025-32976-cve-2025-32977-cve-2025-32978 immediately, as this vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog.

Added: 4/20/2026 Remediate by: 5/4/2026
Remediation overdue CVE-2025-48700

Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability

Synacor — Zimbra Collaboration Suite (ZCS)

This cross-site scripting (XSS) flaw in Zimbra Collaboration Suite lets attackers inject and run malicious JavaScript inside a victim's active session. Because Zimbra is a widely used enterprise email and collaboration platform, successful exploitation could allow attackers to steal session tokens, credentials, or other sensitive data without the user's knowledge. Organizations relying on Zimbra for internal or external communication face real risk of account compromise and data exposure.

Patch available

Next step: Review Synacor's official Zimbra Security Advisories at https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories for available patches or guidance, and apply any updates per vendor instructions immediately. No specific patch reference has been confirmed in current data, so actively monitor that page for new releases.

Added: 4/20/2026 Remediate by: 4/23/2026
Remediation overdue CVE-2026-20122

Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability

Cisco — Catalyst SD-WAN Manger

This flaw in Cisco Catalyst SD-WAN Manager lets an attacker abuse privileged APIs by uploading a malicious file through the API interface. If successful, the attacker can overwrite arbitrary files on the system and elevate their access to vmanage user privileges — effectively gaining administrative-level control over SD-WAN management infrastructure. Because SD-WAN managers are central to network orchestration, a compromise can have broad downstream impact across the managed network.

Patch available

Next step: Review Cisco's official security advisory at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v for remediation guidance, and follow CISA Emergency Directive 26-03 and CISA's Hunt & Hardening Guidance for Cisco SD-WAN Devices to assess exposure and reduce risk; if mitigations are not available, CISA directs organizations to consider discontinuing use of the product.

Added: 4/20/2026 Remediate by: 4/23/2026
Remediation overdue CVE-2026-20128

Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability

Cisco — Catalyst SD-WAN Manager

This flaw in Cisco Catalyst SD-WAN Manager stores passwords in a recoverable format, meaning a low-privileged local user can read a credential file on the filesystem and escalate to DCA user privileges. While an attacker needs existing local access, privilege escalation within SD-WAN management infrastructure is serious — SD-WAN managers control wide-area network policy and routing, so a compromised DCA account could have significant downstream impact across the network.

Patch available

Next step: Review the Cisco Security Advisory at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v for available fixes, and follow CISA Emergency Directive 26-03 and CISA's Hunt & Hardening Guidance for Cisco SD-WAN Devices to assess exposure and apply required mitigations; if mitigations are unavailable, CISA directs discontinuing use of the product.

Added: 4/20/2026 Remediate by: 4/23/2026
Remediation overdue CVE-2026-20133

Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability

Cisco — Catalyst SD-WAN Manager

This vulnerability in Cisco Catalyst SD-WAN Manager allows remote attackers to access sensitive information without authentication or authorization. SD-WAN Manager is a central control plane for wide-area network infrastructure, meaning exposed data could reveal network topology, credentials, or configuration details that attackers could exploit for deeper network compromise. CISA has issued an Emergency Directive (ED 26-03) reflecting the severity and active risk this poses to organizations running Cisco SD-WAN environments.

Patch available

Next step: Review the Cisco Security Advisory at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v and follow CISA's Emergency Directive 26-03 and accompanying Hunt & Hardening Guidance for Cisco SD-WAN Devices; if mitigations cannot be applied, CISA directs organizations to discontinue use of the product.

Added: 4/20/2026 Remediate by: 4/23/2026
Remediation overdue CVE-2026-34197

Apache ActiveMQ Improper Input Validation Vulnerability

Apache — ActiveMQ

Apache ActiveMQ, a widely deployed open-source message broker, contains an improper input validation flaw that enables code injection. Attackers who can reach the service could execute arbitrary code on the underlying system, potentially leading to full server compromise. Because ActiveMQ often sits at the heart of enterprise messaging infrastructure, exploitation could cascade across interconnected applications and services, making this a high-priority concern for any organization running the software.

Patch available

Next step: Review and apply the guidance provided in the Apache ActiveMQ security advisory at https://activemq.apache.org/security-advisories.data/CVE-2026-34197-announcement.txt immediately, as no separate patch reference was identified in the available data.

Added: 4/16/2026 Remediate by: 4/30/2026
Remediation overdue CVE-2009-0238

Microsoft Office Remote Code Execution

Microsoft — Office

This vulnerability in Microsoft Office Excel allows an attacker to execute arbitrary code simply by convincing a user to open a maliciously crafted Excel file containing a malformed object. If exploited, the attacker can gain complete control of the affected system — the same level of access as the logged-in user. Since opening a file is a routine action, social engineering via email or file sharing makes this a practical and dangerous attack vector for any organization using Excel.

Patch available

Next step: Review Microsoft's security advisory at http://www.microsoft.com/technet/security/advisory/968272.mspx and apply any available patches or mitigations per vendor instructions; if the product cannot be patched or updated, CISA guidance requires discontinuing its use.

Added: 4/14/2026 Remediate by: 4/28/2026
Remediation overdue CVE-2026-32201

Microsoft SharePoint Server Improper Input Validation Vulnerability

Microsoft — SharePoint Server

This vulnerability in Microsoft SharePoint Server allows an unauthenticated network attacker to perform spoofing attacks by exploiting improper input validation. In practice, this means an attacker could impersonate trusted users or systems within a SharePoint environment, potentially gaining access to sensitive content, manipulating workflows, or deceiving users and services that rely on SharePoint's identity assertions. SharePoint is widely deployed for collaboration and document management, making a spoofing flaw particularly dangerous in enterprise environments.

Patch available

Next step: Review and apply guidance from Microsoft's official advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32201, as no standalone patch reference was identified in the available data.

Added: 4/14/2026 Remediate by: 4/28/2026
Remediation overdue CVE-2012-1854

Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability

Microsoft — Visual Basic for Applications (VBA)

This vulnerability in Microsoft Visual Basic for Applications (VBA) allows an attacker to exploit insecure library loading behavior, potentially enabling remote code execution. Because VBA is embedded in Microsoft Office applications widely used across organizations, a successful exploit could let an attacker run arbitrary code with the privileges of the logged-in user — making it a significant risk in environments where Office macros are commonly used or where users open documents from untrusted sources.

Patch available

Next step: Review and apply the guidance and updates detailed in Microsoft Security Bulletin MS12-046, available at https://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-046.

Interim mitigation: Refer to Microsoft Security Bulletin MS12-046 for any interim mitigations or workarounds specified by the vendor alongside the primary fix.

Added: 4/13/2026 Remediate by: 4/27/2026
Remediation overdue CVE-2020-9715

Adobe Acrobat Use-After-Free Vulnerability

Adobe — Acrobat

This use-after-free flaw in Adobe Acrobat allows an attacker to execute arbitrary code on a victim's machine, likely by tricking a user into opening a malicious PDF. Use-after-free bugs occur when software continues referencing memory after it has been freed, enabling attackers to control program execution. Since Acrobat is widely deployed for everyday document handling, a successful exploit could result in full system compromise with minimal user interaction beyond opening a file.

Patch available

Next step: Apply the patch provided by Adobe in security bulletin APSB20-48, available at https://helpx.adobe.com/security/products/acrobat/apsb20-48.html.

Added: 4/13/2026 Remediate by: 4/27/2026
Ransomware use CVE-2023-21529

Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability

Microsoft — Exchange Server

Microsoft Exchange Server contains a flaw in how it handles deserialized data, meaning an attacker who has already authenticated to the server can send specially crafted data to trigger remote code execution. Because Exchange servers are central to email infrastructure, a compromised server can expose sensitive communications, serve as a pivot point into the broader network, and enable ransomware deployment — this vulnerability is confirmed to have been used in ransomware attacks.

Patch available

Next step: Apply Microsoft's security update for this vulnerability immediately by following the official guidance at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21529.

Added: 4/13/2026 Remediate by: 4/27/2026
Remediation overdue CVE-2023-36424

Microsoft Windows Out-of-Bounds Read Vulnerability

Microsoft — Windows

This vulnerability affects the Windows Common Log File System (CLFS) driver, a core component present across Windows environments. An out-of-bounds read flaw in this driver can be exploited by an attacker to escalate their privileges on a compromised system. In practice, this means a local attacker or malware with limited access could leverage this flaw to gain higher-level system control, significantly increasing the damage potential of an otherwise contained intrusion.

Patch available

Next step: Apply the Microsoft security update referenced in the official advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36424 as soon as possible.

Added: 4/13/2026 Remediate by: 4/27/2026
Ransomware use CVE-2025-60710

Microsoft Windows Link Following Vulnerability

Microsoft — Windows

This Windows vulnerability allows an attacker to follow symbolic links or similar path references to gain elevated privileges on a compromised system. Because it enables privilege escalation, an attacker with limited access can leverage it to gain full control. Its active use in ransomware campaigns makes it especially urgent — ransomware operators frequently chain privilege escalation flaws with initial access exploits to maximize damage and spread laterally across networks.

Patch available

Next step: Review the Microsoft Security Response Center advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-60710 and apply any available patch or vendor-recommended fix immediately, as this vulnerability is actively exploited in ransomware campaigns.

Interim mitigation: A mitigation script has been referenced at https://www.vicarius.io/vsociety/posts/cve-2025-60710-mitigation-script-eop-vulnerability-in-host-process-for-windows-tasks and may serve as a compensating control while a patch is evaluated or deployed.

Added: 4/13/2026 Remediate by: 4/27/2026
Remediation overdue CVE-2026-21643

Fortinet FortiClient EMS SQL Injection Vulnerability

Fortinet — FortiClient EMS

This SQL injection flaw in Fortinet FortiClient EMS allows an unauthenticated attacker to send crafted HTTP requests and execute arbitrary code or commands on the system — no credentials required. FortiClient EMS is widely used to manage endpoint security policies, so a compromise could give attackers control over endpoint configurations across an entire organization, potentially serving as a launchpad for broader network intrusion.

Patch available

Next step: Review the Fortinet PSIRT advisory at https://fortiguard.fortinet.com/psirt/FG-IR-25-1142 and apply any patches or mitigations specified by the vendor; if the product cannot be patched or mitigated per vendor instructions, CISA guidance directs organizations to discontinue use.

Added: 4/13/2026 Remediate by: 4/16/2026
Remediation overdue CVE-2026-34621

Adobe Acrobat and Reader Prototype Pollution Vulnerability

Adobe — Acrobat and Reader

Adobe Acrobat and Reader contain a prototype pollution flaw, meaning an attacker can manipulate the base properties of JavaScript objects within the application to execute arbitrary code on the victim's machine. Because Acrobat and Reader are widely deployed for opening PDF files — a ubiquitous document format — this vulnerability creates a practical path for attackers to compromise systems simply by getting a user to open a malicious PDF, making it a high-priority risk for any organization that handles PDF documents.

Patch available

Next step: Review and apply the patch or mitigations detailed in Adobe's official security bulletin at https://helpx.adobe.com/security/products/acrobat/apsb26-43.html as soon as possible.

Added: 4/13/2026 Remediate by: 4/27/2026
Remediation overdue CVE-2026-1340

Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability

Ivanti — Endpoint Manager Mobile (EPMM)

Ivanti Endpoint Manager Mobile (EPMM) contains a code injection flaw that allows unauthenticated attackers to execute arbitrary code remotely — no credentials required. EPMM is a mobile device management platform, meaning a successful exploit could give attackers control over a system that itself manages and has visibility into an organization's entire mobile device fleet. This makes the blast radius significant, potentially exposing corporate data, configurations, and enrolled devices across the environment.

Patch available

Next step: Review and apply vendor guidance immediately via the Ivanti security advisory at https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2026-1281-CVE-2026-1340; if remediation is not possible, CISA directs organizations to discontinue use of the product.

Added: 4/8/2026 Remediate by: 4/11/2026
Remediation overdue CVE-2026-35616

Fortinet FortiClient EMS Improper Access Control Vulnerability

Fortinet — FortiClient EMS

FortiClient EMS, Fortinet's endpoint management server, contains an improper access control flaw that lets unauthenticated attackers execute arbitrary code or commands by sending crafted requests. Because no credentials are required to exploit this, the attack surface is broad — any network-reachable EMS instance could be compromised. Successful exploitation gives an attacker control over the management plane, potentially affecting all endpoints managed by that EMS server.

Patch available

Next step: Apply the patch detailed in Fortinet's official advisory at https://fortiguard.fortinet.com/psirt/FG-IR-26-099 immediately, or discontinue use of FortiClient EMS if patching is not possible.

Added: 4/6/2026 Remediate by: 4/9/2026
Remediation overdue CVE-2026-3502

TrueConf Client Download of Code Without Integrity Check Vulnerability

TrueConf — Client

TrueConf Client fails to verify the integrity of update packages it downloads, meaning an attacker who can intercept or redirect the update delivery path — such as through a man-in-the-middle position or DNS manipulation — can swap in a malicious payload. If the updater installs or executes that tampered package, the attacker gains arbitrary code execution with the same privileges as the updating process or the logged-in user. This is a serious supply-chain-style risk affecting any system running TrueConf Client.

No patch reference found

Next step: As of this advisory, no patch or vendor advisory has been published by TrueConf. If mitigations are unavailable, CISA's required action states organizations should consider discontinuing use of the product until a fix is provided.

Added: 4/2/2026 Remediate by: 4/16/2026
Remediation overdue CVE-2026-5281

Google Dawn Use-After-Free Vulnerability

Google — Dawn

This use-after-free flaw in Google's Dawn graphics component allows an attacker who has already compromised a browser's renderer process to escalate that foothold into full arbitrary code execution — effectively breaking out of a key security boundary. Because Dawn is shared across Chromium-based browsers, the blast radius extends beyond Chrome to Microsoft Edge, Opera, and other derivatives. A crafted webpage is all that's needed to trigger the exploit, making drive-by attacks a realistic threat.

Patch available

Next step: Apply the update referenced in Google's official stable channel release advisory at https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_31.html, and ensure all Chromium-based browsers in your environment — including Microsoft Edge and Opera — are updated to their respective patched versions as soon as they become available.

Added: 4/1/2026 Remediate by: 4/15/2026
Remediation overdue CVE-2026-3055

Citrix NetScaler Out-of-Bounds Read Vulnerability

Citrix — NetScaler

This vulnerability affects Citrix NetScaler ADC, NetScaler Gateway, and their FIPS/NDcPP variants when configured as a SAML Identity Provider. An out-of-bounds read flaw allows an attacker to force the device to read beyond intended memory boundaries, potentially exposing sensitive data from memory. Because NetScaler devices typically sit at network edges handling authentication traffic, exploitation could compromise credentials or session data for a broad user population.

Patch available

Next step: Review and apply the patch or configuration guidance detailed in Citrix's official advisory at https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696300 as soon as possible.

Added: 3/30/2026 Remediate by: 4/2/2026
Remediation overdue CVE-2025-53521

F5 BIG-IP Stack-Based Buffer Overflow Vulnerability

F5 — BIG-IP

F5 BIG-IP APM, a widely deployed enterprise application delivery and access management platform, contains a stack-based buffer overflow that can be exploited remotely to execute arbitrary code. This class of vulnerability is serious because it can give attackers full control of a network-critical device, potentially exposing internal applications and user traffic. Organizations relying on BIG-IP for VPN or application access are at elevated risk if this device is internet-facing.

Patch available

Next step: Review and apply the guidance in F5's official advisory at https://my.f5.com/manage/s/article/K000156741 immediately, as this vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog and requires urgent attention.

Added: 3/27/2026 Remediate by: 3/30/2026
Remediation overdue CVE-2026-33634

Aquasecurity Trivy Embedded Malicious Code Vulnerability

Aquasecurity — Trivy

Trivy, a widely used open-source vulnerability scanner commonly embedded in CI/CD pipelines, has been found to contain malicious code. Because Trivy runs with access to pipeline environments, an attacker exploiting this could harvest every secret the pipeline touches — OAuth tokens, SSH keys, cloud provider credentials, database passwords, and sensitive in-memory configuration. Any organization using Trivy in automated build or deployment workflows should treat this as a high-priority supply chain compromise.

Patch available

Next step: No patch has been identified at this time; review the vendor discussion at https://github.com/aquasecurity/trivy/discussions/10425 for the latest guidance, and discontinue use of affected Trivy versions if mitigations are unavailable.

Interim mitigation: A related issue tracking compensating controls has been referenced at https://github.com/BerriAI/litellm/issues/24518; administrators should review that discussion for any interim guidance applicable to their environment.

Added: 3/26/2026 Remediate by: 4/9/2026
Remediation overdue CVE-2026-33017

Langflow Code Injection Vulnerability

Langflow — Langflow

Langflow, an AI workflow-building platform, contains a code injection flaw that lets attackers build and execute public flows without logging in. This means unauthenticated users could potentially run arbitrary code through the platform's flow functionality, bypassing access controls entirely. Organizations running Langflow — especially publicly accessible instances — face a serious risk of unauthorized code execution, data exposure, or system compromise without any credentials being required.

Patch available

Next step: Apply the patch referenced in the Langflow security advisory (GHSA-vwmf-pq79-vjvx) and the associated commit on GitHub (73b6612e3ef25fdae0a752d75b0fabd47328d4f0) immediately.

Interim mitigation: Refer to the vendor's security advisory at https://github.com/langflow-ai/langflow/security/advisories/GHSA-vwmf-pq79-vjvx for any interim compensating controls. If mitigations are unavailable or cannot be applied, CISA recommends discontinuing use of the product.

Added: 3/25/2026 Remediate by: 4/8/2026
Remediation overdue CVE-2025-31277

Apple Multiple Products Buffer Overflow Vulnerability

Apple — Multiple Products

A buffer overflow in Apple's web content processing engine affects a broad range of Apple platforms — Safari, iOS, iPadOS, macOS, watchOS, tvOS, and visionOS. Simply visiting or loading malicious web content could trigger memory corruption, potentially giving an attacker code execution or control over the affected device. The wide platform coverage means nearly every Apple device in an enterprise or personal environment could be at risk, making this a high-priority issue for IT teams managing Apple fleets.

Patch available

Next step: Apply the updates detailed in Apple's official security advisory at https://support.apple.com/en-us/124147 as soon as possible across all affected Apple platforms.

Added: 3/20/2026 Remediate by: 4/3/2026
Remediation overdue CVE-2025-32432

Craft CMS Code Injection Vulnerability

Craft CMS — Craft CMS

This vulnerability in Craft CMS allows unauthenticated remote attackers to inject and execute arbitrary code on affected servers. Because exploitation requires no credentials, any internet-facing Craft CMS installation is at serious risk of full server compromise. Successful exploitation could lead to data theft, site defacement, backdoor installation, or use of the server as a pivot point for further attacks within the network.

Patch available

Next step: Apply the patch immediately by updating to the fixed version of Craft CMS; the fix is documented in the vendor's security advisory at https://github.com/craftcms/cms/security/advisories/GHSA-f3gw-9ww9-jmc3 and the specific commit is available at https://github.com/craftcms/cms/commit/e1c85441fa47eeb7c688c2053f25419bc0547b47.

Added: 3/20/2026 Remediate by: 4/3/2026
Remediation overdue CVE-2025-43510

Apple Multiple Products Improper Locking Vulnerability

Apple — Multiple Products

This vulnerability affects a wide range of Apple platforms — watchOS, iOS, iPadOS, macOS, visionOS, and tvOS — meaning nearly the entire Apple ecosystem is exposed. A malicious app installed on an affected device could exploit improper memory locking to tamper with shared memory regions between processes, potentially allowing it to read or corrupt data belonging to other processes. This kind of cross-process interference can undermine application isolation, a core security boundary users depend on.

Patch available

Next step: Apply the updates detailed in Apple's official advisory at https://support.apple.com/en-us/125632 as soon as possible, as this vulnerability is actively tracked by CISA in its Known Exploited Vulnerabilities catalog.

Added: 3/20/2026 Remediate by: 4/3/2026
Remediation overdue CVE-2025-43520

Apple Multiple Products Classic Buffer Overflow Vulnerability

Apple — Multiple Products

A classic buffer overflow vulnerability affects Apple's entire product ecosystem — watchOS, iOS, iPadOS, macOS, visionOS, and tvOS. A malicious app installed on a vulnerable device could exploit this flaw to crash the system or write arbitrary data directly into kernel memory. Kernel-level write access is among the most serious outcomes possible, as it can enable privilege escalation or deeper system compromise, making this a high-priority concern for any organization managing Apple devices.

Patch available

Next step: Apply the updates detailed in Apple's official security advisory at https://support.apple.com/en-us/125632 for all affected platforms as soon as possible.

Added: 3/20/2026 Remediate by: 4/3/2026
Remediation overdue CVE-2025-54068

Laravel Livewire Code Injection Vulnerability

Laravel — Livewire

Laravel Livewire, a popular PHP framework component for building dynamic web interfaces, contains a code injection flaw that lets unauthenticated attackers execute arbitrary commands on the server in certain configurations. No login or credentials are required to exploit this, making it particularly dangerous for any internet-facing application built on Livewire. Successful exploitation could give an attacker full control of the underlying server, enabling data theft, ransomware deployment, or further lateral movement.

Patch available

Next step: Apply the patch immediately by updating to the fixed version of Laravel Livewire referenced in the GitHub commit (ef04be759da41b14d2d129e670533180a44987dc) and review the official security advisory at https://github.com/livewire/livewire/security/advisories/GHSA-29cq-5w36-x7w3 for full remediation details.

Added: 3/20/2026 Remediate by: 4/3/2026
Ransomware use CVE-2026-20131

Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability

Cisco — Secure Firewall Management Center (FMC)

This critical flaw in Cisco's Firewall Management Center and Security Cloud Control allows a completely unauthenticated remote attacker to execute arbitrary Java code with root-level privileges through the web management interface. Because no login is required and the attacker gains full system control, a successful exploit could lead to complete compromise of firewall policy management — effectively giving an adversary control over network security controls. This vulnerability is already known to be used in ransomware attacks, making rapid action essential.

Patch available

Next step: Review and apply guidance from Cisco's official security advisory at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-rce-NKhnULJh immediately, as this vulnerability is actively exploited in ransomware campaigns.

Added: 3/19/2026 Remediate by: 3/22/2026
Remediation overdue CVE-2025-66376

Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability

Synacor — Zimbra Collaboration Suite (ZCS)

This vulnerability in Zimbra Collaboration Suite's Classic UI allows attackers to inject malicious scripts via CSS @import directives embedded in HTML emails. When a user views a crafted email, the attacker's code can execute in the victim's browser session, potentially enabling session hijacking, credential theft, or further attacks against the user's Zimbra account. Because email is a universal attack surface, any organization running ZCS Classic UI is exposed to phishing-style exploitation without requiring any special user action beyond opening a message.

Patch available

Next step: Consult the Zimbra Security Center advisory at https://wiki.zimbra.com/wiki/Security_Center and apply any available vendor-supplied updates or instructions immediately, as no standalone patch reference has been separately confirmed at this time.

Added: 3/18/2026 Remediate by: 4/1/2026
Remediation overdue CVE-2026-20963

Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

Microsoft — SharePoint

Microsoft SharePoint has a deserialization flaw that lets an unauthenticated attacker execute arbitrary code remotely — no credentials required. Deserialization vulnerabilities are particularly dangerous because they can be triggered by sending specially crafted data to the server, potentially giving attackers full control over the SharePoint environment and any data or systems it connects to. With SharePoint often serving as a central collaboration hub, a successful exploit could have broad organizational impact.

Patch available

Next step: Consult Microsoft's Security Response Center advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20963 and apply any available patch or vendor-recommended fix immediately; no patch reference was confirmed in the source data at time of writing, so monitor that advisory closely for updates.

Added: 3/18/2026 Remediate by: 3/21/2026
Remediation overdue CVE-2025-47813

Wing FTP Server Information Disclosure Vulnerability

Wing FTP Server — Wing FTP Server

Wing FTP Server leaks sensitive information through error messages triggered by sending an oversized value in the UID cookie. Attackers can exploit this without needing valid credentials, potentially harvesting internal details — such as file paths, software versions, or configuration data — that help them map the environment and plan deeper attacks. Because this is an information disclosure flaw in a widely used FTP server product, it lowers the bar for follow-on compromise and is now tracked as an actively exploited vulnerability by CISA.

No patch reference found

Next step: No patch or vendor advisory has been identified at this time; organizations should follow CISA's BOD 22-01 guidance and, if no mitigations become available from the vendor, seriously evaluate discontinuing use of the affected Wing FTP Server product.

Added: 3/16/2026 Remediate by: 3/30/2026
Remediation overdue CVE-2026-3909

Google Skia Out-of-Bounds Write Vulnerability

Google — Skia

Google's Skia graphics library, used across Chrome, ChromeOS, Android, Flutter, and other products, contains an out-of-bounds write flaw. A remote attacker can exploit this simply by luring a user to a malicious HTML page, potentially gaining the ability to read or corrupt memory outside intended boundaries. Because Skia is embedded in widely deployed software, the attack surface is broad and the barrier to exploitation is low — just visiting a webpage can be enough.

Patch available

Next step: Review and apply the update detailed in Google's stable channel release advisory at https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_13.html as soon as possible.

Added: 3/13/2026 Remediate by: 3/27/2026
Remediation overdue CVE-2026-3910

Google Chromium V8 Improper Restriction of Operations Within the Bounds of a Memory Buffer Vulnerability

Google — Chromium V8

This vulnerability in Chromium's V8 JavaScript engine allows a remote attacker to execute arbitrary code within the browser sandbox simply by luring a user to a malicious webpage. Because V8 is shared across multiple major browsers — Chrome, Edge, and Opera among them — the attack surface is extremely broad. Sandbox escape potential makes this especially serious, as successful exploitation could be a stepping stone to deeper system compromise affecting a wide range of end users and enterprise environments.

Patch available

Next step: Review and apply the update detailed in Google's stable channel advisory at https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_12.html, and ensure all Chromium-based browsers in your environment are updated accordingly.

Added: 3/13/2026 Remediate by: 3/27/2026
Remediation overdue CVE-2025-68613

n8n Improper Control of Dynamically-Managed Code Resources Vulnerability

n8n — n8n

n8n is a popular workflow automation platform used to connect apps and automate business processes. This vulnerability exists in how n8n evaluates expressions within workflows, and it allows an attacker to execute arbitrary code remotely on the server hosting n8n. If exploited, an attacker could take full control of the host system, access sensitive data processed by workflows, or pivot deeper into the internal network — making this a critical risk for any organization running n8n.

Patch available

Next step: Apply the patch referenced in the n8n security advisory immediately: review the vendor advisory at https://github.com/n8n-io/n8n/security/advisories/GHSA-v98v-ff95-f3cp and apply the fix documented in the associated commit (08f332015153decdda3c37ad4fcb9f7ba13a7c79).

Added: 3/11/2026 Remediate by: 3/25/2026
Remediation overdue CVE-2021-22054

Omnissa Workspace ONE Server-Side Request Forgery

Omnissa — Workspace One UEM

This vulnerability in Omnissa (formerly VMware) Workspace ONE UEM allows an attacker with network access to the UEM console to send forged server-side requests without any authentication. In practice, this means an unauthenticated attacker on the same network can abuse the server to reach internal resources and potentially extract sensitive information, making it especially dangerous in environments where the UEM console is accessible from broader network segments.

Patch available

Next step: Apply the patch detailed in VMware Security Advisory VMSA-2021-0029, available at https://www.vmware.com/security/advisories/VMSA-2021-0029.html.

Added: 3/9/2026 Remediate by: 3/23/2026
Ransomware use CVE-2025-26399

SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability

SolarWinds — Web Help Desk

SolarWinds Web Help Desk contains a deserialization flaw in its AjaxProxy component that allows an attacker to execute arbitrary commands directly on the host machine. This is a critical remote code execution class vulnerability, and it has already been linked to real ransomware attacks in the wild. Any organization running Web Help Desk is at risk of full system compromise, making this an urgent priority for IT and security teams.

Patch available

Next step: Apply the patch immediately by following SolarWinds' official security advisory at https://www.solarwinds.com/trust-center/security-advisories/CVE-2025-26399 for remediation instructions.

Added: 3/9/2026 Remediate by: 3/12/2026
Remediation overdue CVE-2026-1603

Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability

Ivanti — Endpoint Manager (EPM)

This flaw in Ivanti Endpoint Manager allows a remote attacker with no credentials to bypass authentication via an alternate path or channel and extract stored credential data from the system. Because EPM manages endpoints across an organization, exposed credentials could give attackers a foothold to move laterally or compromise managed devices at scale. No evidence of ransomware exploitation is currently recorded, but credential leakage from an endpoint management platform represents serious organizational risk.

Patch available

Next step: Review and apply the fixes detailed in Ivanti's Security Advisory for EPM (February 2026) at https://hub.ivanti.com/s/article/Security-Advisory-EPM-February-2026-for-EPM-2024.

Added: 3/9/2026 Remediate by: 3/23/2026
Remediation overdue CVE-2017-7921

Hikvision Multiple Products Improper Authentication Vulnerability

Hikvision — Multiple Products

This vulnerability in multiple Hikvision products allows an attacker to bypass authentication controls, escalate their privileges, and access sensitive data. Because Hikvision cameras and recorders are widely deployed in physical security infrastructure, a successful exploit could give attackers unauthorized control over surveillance systems. This is particularly concerning given that many such devices are internet-facing, making them reachable without needing prior network access.

Patch available

Next step: Apply the patch or remediation detailed in Hikvision's official advisory at http://www.hikvision.com/us/about_10805.html immediately; if patching is not feasible, CISA guidance indicates discontinuing use of the product.

Added: 3/5/2026 Remediate by: 3/26/2026
Remediation overdue CVE-2021-22681

Rockwell Multiple Products Insufficient Protected Credentials Vulnerability

Rockwell — Multiple Products

Rockwell Automation's Studio 5000 Logix Designer software contains a hardcoded or insufficiently protected cryptographic key used to authenticate communications between design software and Logix controllers. If an attacker can discover this key — which requires network access to the controller — they could use an unauthorized application to connect to and potentially manipulate Logix controllers. These controllers are commonly used in industrial and operational technology environments, making unauthorized access a serious safety and operational risk.

No patch reference found

Next step: No patch or vendor advisory reference is currently available in the source data; administrators should be aware that no confirmed remediation link has been identified and should monitor Rockwell Automation's official channels directly for guidance.

Added: 3/5/2026 Remediate by: 3/26/2026
Remediation overdue CVE-2021-30952

Apple Multiple Products Integer Overflow or Wraparound Vulnerability

Apple — Multiple Products

This vulnerability affects a wide range of Apple products — tvOS, macOS, Safari, iPadOS, and watchOS — and can be triggered simply by visiting a malicious website. An integer overflow in the web content processing engine allows an attacker to potentially execute arbitrary code on the victim's device. Because exploitation requires only that a user view attacker-controlled web content, the attack surface is broad and the barrier to exploitation is low, making patching urgent.

Patch available

Next step: Apply the updates detailed in Apple's official advisory at https://support.apple.com/en-us/HT212975 as soon as possible across all affected Apple devices and platforms.

Added: 3/5/2026 Remediate by: 3/26/2026
Remediation overdue CVE-2023-41974

Apple iOS and iPadOS Use-After-Free Vulnerability

Apple — iOS and iPadOS

This use-after-free flaw in Apple iOS and iPadOS allows a malicious app to execute arbitrary code at the kernel level — the deepest layer of the operating system. Kernel-level code execution means an attacker's app could bypass all normal security boundaries, potentially accessing any data, installing persistent malware, or fully compromising the device. The fact that it requires only an app makes it a realistic threat for any user who installs software on their device.

Patch available

Next step: Apply the update referenced in Apple's vendor advisory at https://support.apple.com/en-us/120949 as soon as possible to address this kernel-level code execution vulnerability.

Added: 3/5/2026 Remediate by: 3/26/2026
Remediation overdue CVE-2023-43000

Apple Multiple products Use-After-Free Vulnerability

Apple — Multiple Products

This use-after-free flaw affects Apple macOS, iOS, iPadOS, and Safari, and can be triggered simply by processing maliciously crafted web content. Use-after-free bugs allow attackers to corrupt memory in ways that can lead to arbitrary code execution — meaning a user visiting a malicious site could have their device compromised without any other interaction. The broad scope across Apple's ecosystem makes this a high-priority issue for organizations relying on Apple hardware and Safari-based browsing.

Patch available

Next step: Apply the update referenced in Apple's official advisory at https://support.apple.com/en-us/120324 as soon as possible to address this vulnerability across affected Apple products.

Added: 3/5/2026 Remediate by: 3/26/2026
Remediation overdue CVE-2026-21385

Qualcomm Multiple Chipsets Memory Corruption Vulnerability

Qualcomm — Multiple Chipsets

Multiple Qualcomm chipsets contain a memory corruption flaw triggered during memory allocation alignment operations. Memory corruption vulnerabilities are serious because attackers can exploit them to crash systems, escalate privileges, or execute arbitrary code. Since Qualcomm chips power a wide range of devices — including smartphones, IoT hardware, and networking equipment — this vulnerability has a broad potential attack surface affecting many device categories and their users.

Patch available

Next step: Apply the patches detailed in Qualcomm's March 2026 Security Bulletin at https://docs.qualcomm.com/product/publicresources/securitybulletin/march-2026-bulletin.html as soon as possible, following your device manufacturer's update process.

Added: 3/3/2026 Remediate by: 3/24/2026
Remediation overdue CVE-2026-22719

Broadcom VMware Aria Operations Command Injection Vulnerability

Broadcom — VMware Aria Operations

This vulnerability in Broadcom VMware Aria Operations (formerly vRealize Operations) allows an unauthenticated attacker to inject commands that can lead to full remote code execution. No credentials are required to exploit it, making the attack surface broad. The flaw is triggered during support-assisted product migration workflows, meaning organizations actively migrating or receiving vendor support for migration may be at heightened risk. Successful exploitation could give attackers complete control over the affected system.

Patch available

Next step: Apply the vendor-supplied patch immediately by following Broadcom's official security advisory at https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947.

Interim mitigation: Broadcom has published a knowledge base article at https://knowledge.broadcom.com/external/article/430349 that may include interim guidance; administrators should review it for any compensating controls applicable to their environment while patching is completed.

Added: 3/3/2026 Remediate by: 3/24/2026
Remediation overdue CVE-2022-20775

Cisco SD-WAN Path Traversal Vulnerability

Cisco — SD-WAN

This vulnerability in Cisco SD-WAN's command-line interface allows an authenticated local attacker to traverse file paths and abuse improperly restricted CLI commands to escalate privileges all the way to root. While the attacker must already have local authenticated access, successful exploitation grants complete control over the device — a serious risk in SD-WAN environments where these devices sit at the heart of enterprise network infrastructure.

Patch available

Next step: Review and apply guidance from Cisco's official security advisory at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sd-wan-priv-E6e8tEdF, and follow CISA's Emergency Directive 26-03 and associated Hunt & Hardening Guidance for Cisco SD-WAN Devices; if mitigations cannot be applied, CISA directs organizations to consider discontinuing use of the affected product.

Added: 2/25/2026 Remediate by: 2/27/2026
Remediation overdue CVE-2026-20127

Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability

Cisco — Catalyst SD-WAN Controller and Manager

This vulnerability allows a remote, unauthenticated attacker to completely bypass login controls on Cisco Catalyst SD-WAN Controllers and Managers and gain high-privileged access. Once in, the attacker can use NETCONF to directly manipulate the network configuration of the entire SD-WAN fabric. Because SD-WAN controllers govern routing and policy for potentially thousands of sites, a successful exploit could give an attacker broad control over enterprise or carrier network infrastructure with no prior credentials required.

Patch available

Next step: Review Cisco's official security advisory at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa-EHchtZk and follow CISA's Emergency Directive 26-03 and the associated Hunt & Hardening Guidance for Cisco SD-WAN Devices to assess exposure and apply any available fixes; if mitigations cannot be implemented, CISA directs organizations to consider discontinuing use of the affected product.

Added: 2/25/2026 Remediate by: 2/27/2026
Remediation overdue CVE-2026-25108

Soliton Systems K.K FileZen OS Command Injection Vulnerability

Soliton Systems K.K — FileZen

FileZen, a file-sharing appliance from Soliton Systems, contains an OS command injection flaw that can be triggered after a user logs in and sends a specially crafted HTTP request. This means an authenticated attacker could execute arbitrary operating system commands on the underlying server, potentially leading to full system compromise, data theft, or use as a pivot point within the network. The vulnerability has been added to CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation.

Patch available

Next step: Review the vendor advisory at https://www.soliton.co.jp/support/2026/006657.html for remediation guidance, and apply any available fixes immediately; if no fix can be applied, CISA directs organizations to discontinue use of the product.

Added: 2/24/2026 Remediate by: 3/17/2026
Remediation overdue CVE-2025-49113

RoundCube Webmail Deserialization of Untrusted Data Vulnerability

Roundcube — Webmail

RoundCube Webmail contains a flaw where the '_from' parameter in a URL is not validated during file uploads, allowing any authenticated user to trigger deserialization of untrusted data and achieve remote code execution on the server. This means an attacker with only a standard webmail login can potentially take full control of the underlying system — no admin privileges required. Organizations running RoundCube as their webmail platform are directly at risk of server compromise.

Patch available

Next step: Apply the vendor's security updates immediately: upgrade to RoundCube Webmail version 1.6.11 or 1.5.10 as detailed in the official advisory at https://roundcube.net/news/2025/06/01/security-updates-1.6.11-and-1.5.10, which also corresponds to the patch committed at the referenced GitHub repository.

Interim mitigation: A mitigation script has been referenced by Vicarius at https://www.vicarius.io/vsociety/posts/cve-2025-49113-roundcube-mitigation-script for environments where immediate patching is not possible; consult that resource for interim compensating controls while preparing to apply the vendor's official updates.

Added: 2/20/2026 Remediate by: 3/13/2026
Remediation overdue CVE-2025-68461

RoundCube Webmail Cross-site Scripting Vulnerability

Roundcube — Webmail

This flaw allows attackers to inject malicious scripts into RoundCube Webmail by embedding JavaScript inside an SVG document's animate tag. Because webmail runs in the browser and handles untrusted email content, a successful exploit could let an attacker hijack a user's session, steal credentials, or perform actions on their behalf — all without any interaction beyond opening a crafted email. RoundCube is widely deployed in enterprise and hosting environments, making this a high-value target.

Patch available

Next step: Apply the vendor's security updates immediately by upgrading to RoundCube Webmail version 1.6.12 or 1.5.12, as detailed in the official advisory at https://roundcube.net/news/2025/12/13/security-updates-1.6.12-and-1.5.12.

Added: 2/20/2026 Remediate by: 3/13/2026
Remediation overdue CVE-2021-22175

GitLab Server-Side Request Forgery (SSRF) Vulnerability

GitLab — GitLab

This GitLab vulnerability allows attackers to abuse webhook functionality to make the GitLab server issue requests to internal network resources on their behalf — a classic SSRF attack. When webhooks pointing to internal addresses are permitted, an attacker could potentially reach services behind the firewall that should never be externally accessible, enabling reconnaissance or interaction with internal infrastructure. This is especially dangerous in environments where GitLab sits on a network with access to sensitive internal systems.

Patch available

Next step: Review the vendor advisory at https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22175.json and apply any patches or configuration changes specified there; no standalone patch reference was identified in the source data.

Added: 2/18/2026 Remediate by: 3/11/2026
Remediation overdue CVE-2026-22769

Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability

Dell — RecoverPoint for Virtual Machines (RP4VMs)

Dell RecoverPoint for Virtual Machines contains hard-coded credentials — fixed username/password combinations baked into the software itself. Because these credentials are static and likely discoverable through reverse engineering or public disclosure, any unauthenticated remote attacker who knows them can log directly into the underlying operating system with root-level access. This means complete system compromise without needing to steal or crack any credentials, making it a severe, easily exploitable vulnerability in a product designed for VM disaster recovery.

Patch available

Next step: Apply the patch immediately by following Dell's security advisory DSA-2026-079, available at https://www.dell.com/support/kbdoc/en-us/000426773/dsa-2026-079.

Added: 2/18/2026 Remediate by: 2/21/2026
Remediation overdue CVE-2008-0015

Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability

Microsoft — Windows

This vulnerability in Microsoft Windows' Video ActiveX Control allows attackers to execute arbitrary code simply by luring a user to a malicious web page. Because the attacker inherits the victim's user rights, a logged-in administrator could hand over full system control. The web-based delivery mechanism makes this especially dangerous, as no file download or complex interaction is required — just visiting a compromised or attacker-controlled page is enough to trigger exploitation.

Patch available

Next step: Review and apply guidance from Microsoft's security advisory at http://www.microsoft.com/technet/security/advisory/972890.mspx, as no formal patch reference was identified in the source data.

Added: 2/17/2026 Remediate by: 3/10/2026
Remediation overdue CVE-2020-7796

Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability

Synacor — Zimbra Collaboration Suite

This vulnerability in Zimbra Collaboration Suite allows an attacker to perform server-side request forgery (SSRF) when the WebEx zimlet is installed and its JSP component is enabled. SSRF lets attackers trick the server into making unauthorized requests to internal or external resources, potentially exposing internal services, bypassing network controls, or facilitating further attacks. Organizations running affected ZCS deployments with the WebEx zimlet active are at direct risk.

Patch available

Next step: Apply the patch available in Zimbra Collaboration Suite release 8.8.15 Patch 7, referenced in the vendor advisory at https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.15/P7.

Added: 2/17/2026 Remediate by: 3/10/2026
Remediation overdue CVE-2024-7694

TeamT5 ThreatSonar Anti-Ransomware Unrestricted Upload of File with Dangerous Type Vulnerability

TeamT5 — ThreatSonar Anti-Ransomware

ThreatSonar Anti-Ransomware, a security product meant to defend against ransomware, itself contains a dangerous file upload flaw. Because the platform fails to properly validate uploaded file content, an attacker who has gained administrator-level access to the platform can upload malicious files and use them to run arbitrary commands directly on the underlying server. This turns a defensive security tool into an attack vector, potentially giving an adversary full control over the host system.

No patch reference found

Next step: No vendor patch or advisory has been published at this time. Organizations using TeamT5 ThreatSonar Anti-Ransomware should contact TeamT5 directly for guidance, and if no mitigations are available, consider discontinuing use of the product as directed by CISA.

Added: 2/17/2026 Remediate by: 3/10/2026
Remediation overdue CVE-2026-2441

Google Chromium CSS Use-After-Free Vulnerability

Google — Chromium

This use-after-free flaw in Chromium's CSS handling allows a remote attacker to corrupt heap memory simply by luring a user to a malicious HTML page — no additional access required. Because Chromium is the engine behind Chrome, Edge, Opera, and other browsers, the attack surface is enormous. Successful exploitation could lead to arbitrary code execution on the victim's machine, making this a high-priority risk for any organization whose users browse the web.

No patch reference found

Next step: No patch or vendor advisory reference has been identified at this time; organizations should monitor Google, Microsoft, and Opera security channels closely and apply any updates as soon as they become available, or consider discontinuing use of affected Chromium-based browsers until a fix is confirmed.

Added: 2/17/2026 Remediate by: 3/10/2026
Ransomware use CVE-2026-1731

BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability

BeyondTrust — Remote Support (RS) and Privileged Remote Access (PRA)

This vulnerability allows an unauthenticated remote attacker to inject and execute arbitrary OS commands on affected BeyondTrust Remote Support and Privileged Remote Access systems, requiring no credentials or user interaction. Because these products are designed to provide privileged remote access, a successful attack can give adversaries deep control over managed systems, enabling unauthorized access, data theft, and service disruption. The vulnerability is already being used in ransomware campaigns, making rapid response critical for any organization running these products.

Patch available

Next step: Review and apply the guidance detailed in BeyondTrust's official security advisory at https://www.beyondtrust.com/trust-center/security-advisories/bt26-02 immediately, as ransomware operators are actively exploiting this vulnerability.

Added: 2/13/2026 Remediate by: 2/16/2026
Remediation overdue CVE-2024-43468

Microsoft Configuration Manager SQL Injection Vulnerability

Microsoft — Configuration Manager

Microsoft Configuration Manager, widely used by enterprises to manage endpoints and software deployments, contains an SQL injection flaw that requires no authentication to exploit. An attacker can send crafted requests to execute arbitrary commands on the server or its underlying database without any credentials. Because Configuration Manager typically has broad access across an enterprise environment, successful exploitation could give an attacker significant control over managed systems and sensitive infrastructure data.

Patch available

Next step: Apply the patch referenced in Microsoft's Security Response Center advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43468 as soon as possible.

Added: 2/12/2026 Remediate by: 3/5/2026
Remediation overdue CVE-2025-15556

Notepad++ Download of Code Without Integrity Check Vulnerability

Notepad++ — Notepad++

Notepad++'s built-in WinGUp update mechanism fails to verify the integrity of downloaded update packages. An attacker positioned to intercept or redirect that update traffic — for example, via a network-based man-in-the-middle attack — could substitute a malicious installer, resulting in arbitrary code execution under the victim's account privileges. Because Notepad++ is widely deployed across enterprise environments, this supply-chain-style attack path poses meaningful risk to large numbers of users.

Patch available

Next step: Apply the patch referenced in the official Notepad++ commit (github.com/notepad-plus-plus/notepad-plus-plus/commit/bcf2aa68ef414338d717e20e059459570ed6c5ab) and review the vendor's incident advisory at notepad-plus-plus.org/news/hijacked-incident-info-update/ for additional guidance.

Added: 2/12/2026 Remediate by: 3/5/2026
Remediation overdue CVE-2025-40536

SolarWinds Web Help Desk Security Control Bypass Vulnerability

SolarWinds — Web Help Desk

SolarWinds Web Help Desk has a flaw that lets unauthenticated attackers bypass security controls and reach functionality that should be restricted to authorized users. Because no login is required to exploit this, the attack surface is broad — anyone who can reach the application over the network is a potential threat actor. Help desk platforms typically handle sensitive tickets, credentials, and user data, making unauthorized access particularly damaging.

Patch available

Next step: Review SolarWinds' official security advisory at https://www.solarwinds.com/trust-center/security-advisories/CVE-2025-40536 and apply any patches or mitigations provided there; no patch details were available at the time of this writing.

Added: 2/12/2026 Remediate by: 2/15/2026
Remediation overdue CVE-2026-20700

Apple Multiple Buffer Overflow Vulnerability

Apple — Multiple Products

This vulnerability affects a wide range of Apple platforms — iOS, macOS, tvOS, watchOS, and visionOS — and stems from improper memory buffer bounds checking. An attacker who can write to memory could exploit this flaw to execute arbitrary code, potentially taking full control of an affected device. The breadth of impacted Apple products makes this a high-priority issue for organizations and individuals relying on any of these platforms in their environment.

Patch available

Next step: Review and apply the updates detailed in Apple's official security advisory at https://support.apple.com/en-us/126346 as soon as possible.

Added: 2/12/2026 Remediate by: 3/5/2026
Remediation overdue CVE-2026-21510

Microsoft Windows Shell Protection Mechanism Failure Vulnerability

Microsoft — Windows

This vulnerability in the Microsoft Windows Shell allows a remote, unauthorized attacker to bypass a built-in security feature over a network. Protection mechanism failures like this are serious because they can serve as stepping stones — letting attackers sidestep defenses that would otherwise block malicious activity. While ransomware use is not currently confirmed, network-exploitable security bypasses are frequently chained with other vulnerabilities to achieve full system compromise.

Patch available

Next step: Review Microsoft's official advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21510 and apply any available patches or mitigations per vendor instructions immediately.

Added: 2/10/2026 Remediate by: 3/3/2026
Remediation overdue CVE-2026-21513

Microsoft MSHTML Framework Protection Mechanism Failure Vulnerability

Microsoft — Windows

This vulnerability in Microsoft's MSHTML framework — the rendering engine underlying Internet Explorer and still present in modern Windows — allows a remote, unauthenticated attacker to bypass a built-in security feature over a network. MSHTML components remain active in many Windows environments even when IE is not used directly, meaning a wide range of systems could be exposed. A successful bypass could pave the way for further exploitation, making this a meaningful risk for organizations that have not applied vendor guidance.

Patch available

Next step: Review and apply mitigations per the Microsoft Security Response Center advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21513, as no standalone patch reference was identified in the source data.

Interim mitigation: A mitigation script addressing this security feature bypass vulnerability has been referenced at https://www.vicarius.io/vsociety/posts/cve-2026-21513-mitigation-script-security-feature-bypass-vulnerability-in-mshtml-framework; consult that resource for interim compensating controls while awaiting a full vendor patch.

Added: 2/10/2026 Remediate by: 3/3/2026
Remediation overdue CVE-2026-21514

Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability

Microsoft — Office

This vulnerability in Microsoft Office Word allows an attacker who already has some level of authorized access to a system to gain higher privileges locally. Because it involves the application trusting inputs it shouldn't, a logged-in user or process could exploit this to escalate their permissions beyond what they should have. While it requires existing access rather than remote exploitation, privilege escalation flaws are a common stepping stone in broader attacks and should not be treated as low priority.

Patch available

Next step: Apply the patch or update referenced in Microsoft's Security Response Center advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21514 as soon as possible.

Added: 2/10/2026 Remediate by: 3/3/2026
Remediation overdue CVE-2026-21519

Microsoft Windows Type Confusion Vulnerability

Microsoft — Windows

This vulnerability in Microsoft's Desktop Windows Manager allows an attacker who already has local access to a Windows system to elevate their privileges — meaning they could gain higher-level control than they're authorized to have. Type confusion flaws occur when software mishandles data types, potentially enabling malicious code execution at elevated permission levels. For organizations, this means a compromised or malicious insider account could be leveraged to take deeper control of affected systems.

Patch available

Next step: Review and apply any available update referenced in Microsoft's official advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21519, as no standalone patch reference was identified in the source data at time of publication.

Added: 2/10/2026 Remediate by: 3/3/2026
Remediation overdue CVE-2026-21525

Microsoft Windows NULL Pointer Dereference Vulnerability

Microsoft — Windows

This vulnerability affects the Windows Remote Access Connection Manager, a component that handles VPN and dial-up connections. An unauthenticated local attacker can trigger a NULL pointer dereference, crashing the service and causing a denial of service. While this requires local access and does not enable remote code execution, it could be abused to disrupt remote access services on servers or workstations, potentially interrupting business connectivity or masking other malicious activity.

Patch available

Next step: Review and apply guidance from Microsoft's official advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21525. No patch reference was confirmed in the source data, so check the Microsoft Security Response Center directly for available updates.

Interim mitigation: A mitigation script has been referenced at https://www.vicarius.io/vsociety/posts/cve-2026-21525-mitigation-script-dos-vulnerability-in-windows-remote-access-connection-manager, which may provide interim compensating controls while a full patch is evaluated or applied.

Added: 2/10/2026 Remediate by: 3/3/2026
Remediation overdue CVE-2026-21533

Microsoft Windows Improper Privilege Management Vulnerability

Microsoft — Windows

This vulnerability in Windows Remote Desktop Services allows an attacker who already has some level of authorized access to escalate their privileges locally. In practical terms, a low-privileged user or a compromised account could leverage this flaw to gain higher-level control over a system, potentially taking administrative actions they should not be permitted to perform. This makes it particularly dangerous in environments where Remote Desktop Services are widely used for remote administration or access.

Patch available

Next step: Consult the Microsoft Security Response Center advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21533 for patch and remediation guidance, and apply any available updates as directed by vendor instructions.

Interim mitigation: A mitigation script addressing this privilege escalation vulnerability in Windows Remote Desktop Services has been referenced at https://www.vicarius.io/vsociety/posts/cve-2026-21533-mitigation-script-privilege-escalation-vulnerability-in-windows-remote-desktop and may serve as a compensating control until a full patch is applied.

Added: 2/10/2026 Remediate by: 3/3/2026
Remediation overdue CVE-2025-11953

React Native Community CLI OS Command Injection Vulnerability

React Native Community — CLI

React Native Community CLI's Metro Development Server exposes an endpoint that accepts unauthenticated POST requests, allowing any attacker with network access to run arbitrary executables on the host machine. On Windows systems the risk is compounded, as attackers can also execute arbitrary shell commands with fully controlled arguments. Because this server is commonly run during development, any machine running Metro that is reachable on a shared or exposed network is potentially at risk of full system compromise.

Patch available

Next step: Apply the patch available in the official GitHub commit (15089907d1f1301b22c72d7f68846a2ef20df547) from the React Native Community CLI repository as soon as possible.

Interim mitigation: JFrog's advisory (https://jfrog.com/blog/cve-2025-11953-critical-react-native-community-cli-vulnerability) provides additional context on the vulnerability; review it for any interim guidance. If the patch cannot be applied immediately and mitigations are unavailable, CISA advises discontinuing use of the product.

Added: 2/5/2026 Remediate by: 2/26/2026
Ransomware use CVE-2026-24423

SmarterTools SmarterMail Missing Authentication for Critical Function Vulnerability

SmarterTools — SmarterMail

SmarterMail's ConnectToHub API method lacks authentication, meaning an unauthenticated attacker can redirect the mail server to a malicious HTTP server of their choosing and execute arbitrary OS commands on the underlying system. This is a critical server-side vulnerability with no user interaction required. It has already been linked to active ransomware campaigns, making exposed SmarterMail instances at immediate risk of full system compromise and data encryption.

No patch reference found

Next step: As of this advisory, no vendor patch or official advisory has been published by SmarterTools. If your organization runs SmarterMail, treat this as an active emergency — consider taking the service offline or isolating it from untrusted networks until a vendor fix becomes available.

Added: 2/5/2026 Remediate by: 2/26/2026
Remediation overdue CVE-2019-19006

Sangoma FreePBX Improper Authentication Vulnerability

Sangoma — FreePBX

FreePBX is a widely used web-based open-source GUI for managing Asterisk-based phone systems. This vulnerability allows attackers to bypass password authentication entirely, potentially gaining unauthorized access to the FreePBX admin interface. From there, an attacker could manipulate phone system configurations, intercept calls, redirect traffic, or pivot further into the network. Any internet-exposed FreePBX instance is at significant risk, making this a high-priority issue for organizations running VoIP infrastructure.

Patch available

Next step: Review the official FreePBX security advisory at https://community.freepbx.org/t/freepbx-security-vulnerability-sec-2019-001/62772 and apply any guidance or updates provided there immediately.

Added: 2/3/2026 Remediate by: 2/24/2026
Remediation overdue CVE-2021-39935

GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability

GitLab — Community and Enterprise Editions

This vulnerability in GitLab's Community and Enterprise Editions allows unauthorized external users to abuse the CI Lint API to trigger server-side requests. In practice, an attacker could use GitLab itself as a proxy to reach internal network resources, bypass perimeter controls, or probe services that should not be externally accessible. This is particularly dangerous in environments where GitLab can reach sensitive internal infrastructure, making it a potential pivot point for deeper network compromise.

Patch available

Next step: Review the vendor advisory at https://gitlab.com/gitlab-org/gitlab/-/issues/346187 for available fixes and apply any patches or configuration changes described there; no separately confirmed patch reference was identified in the source data.

Added: 2/3/2026 Remediate by: 2/24/2026
Remediation overdue CVE-2025-40551

SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability

SolarWinds — Web Help Desk

SolarWinds Web Help Desk contains a deserialization flaw that allows attackers to execute arbitrary commands on the underlying host machine without any credentials. Deserialization vulnerabilities are particularly dangerous because they can be triggered remotely and require no prior access or authentication, giving attackers a direct path to full system compromise. Any organization running this product is potentially exposed to complete server takeover.

Patch available

Next step: Review SolarWinds' official security advisory at https://www.solarwinds.com/trust-center/security-advisories/CVE-2025-40551 and apply any patches or mitigations per vendor instructions immediately.

Added: 2/3/2026 Remediate by: 2/6/2026
Remediation overdue CVE-2025-64328

Sangoma FreePBX OS Command Injection Vulnerability

Sangoma — FreePBX

Sangoma FreePBX Endpoint Manager contains a command injection flaw that authenticated users can exploit through the check_ssh_connect() function. Because FreePBX is widely used in business VoIP environments, a malicious insider or an attacker who has obtained valid credentials could execute arbitrary OS commands, potentially gaining remote shell access as the 'asterisk' system user — opening the door to full system compromise of the phone infrastructure.

Patch available

Next step: Review and apply any available fixes or guidance detailed in the FreePBX security advisory at https://github.com/FreePBX/security-reporting/security/advisories/GHSA-vm9p-46mv-5xvw; if mitigations are unavailable and no patch exists, consider discontinuing use of the affected Endpoint Manager component.

Interim mitigation: Refer to the FreePBX security advisory (https://github.com/FreePBX/security-reporting/security/advisories/GHSA-vm9p-46mv-5xvw) for any interim compensating controls or configuration guidance provided by the vendor.

Added: 2/3/2026 Remediate by: 2/24/2026
Remediation overdue CVE-2026-1281

Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability

Ivanti — Endpoint Manager Mobile (EPMM)

This vulnerability in Ivanti Endpoint Manager Mobile (EPMM) allows attackers to inject and execute arbitrary code without any authentication. Because EPMM is a mobile device management platform, it typically holds privileged access to corporate devices and sensitive configuration data. A successful exploit could give an attacker full remote control over the server and, by extension, visibility into or control over managed endpoints — making this a high-priority risk for any organization running this product.

Patch available

Next step: Apply the vendor-supplied patch immediately by following the guidance in Ivanti's official security advisory at https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2026-1281-CVE-2026-1340.

Added: 1/29/2026 Remediate by: 2/1/2026
Remediation overdue CVE-2026-24858

Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability

Fortinet — Multiple Products

This vulnerability affects Fortinet FortiAnalyzer, FortiManager, FortiOS, and FortiProxy when FortiCloud SSO authentication is enabled. An attacker who has a legitimate FortiCloud account and at least one registered device could exploit an authentication bypass flaw to log into devices registered under entirely different customer accounts. This cross-account access risk means a malicious or compromised FortiCloud user could gain unauthorized control over other organizations' Fortinet devices without needing their credentials.

Patch available

Next step: Review Fortinet's official PSIRT advisory at https://fortiguard.fortinet.com/psirt/FG-IR-26-060 and apply any mitigations or updates detailed there; no standalone patch reference was identified in the source data.

Interim mitigation: Fortinet has published analysis of SSO abuse on FortiOS at https://www.fortinet.com/blog/psirt-blogs/analysis-of-sso-abuse-on-fortios, which should be consulted for specific compensating controls. As the vulnerability is conditional on FortiCloud SSO authentication being enabled, reviewing whether that feature is necessary in your environment is warranted based on the vendor's guidance.

Added: 1/27/2026 Remediate by: 1/30/2026
Remediation overdue CVE-2018-14634

Linux Kernel Integer Overflow Vulnerability

Linux — Kernel

This Linux kernel flaw in the create_elf_tables() function allows a local, unprivileged user to trigger an integer overflow and escalate their privileges to root or other elevated levels. The attack vector requires access to a SUID or otherwise privileged binary, which are common on most Linux systems. Successful exploitation gives an attacker full control of the affected host, making this a serious risk in any multi-user or shared Linux environment.

Patch available

Next step: Apply the kernel patch referenced in the NetApp security advisory at https://security.netapp.com/advisory/ntap-20190204-0002/ and follow your Linux distribution vendor's guidance for updated kernel packages addressing CVE-2018-14634.

Added: 1/26/2026 Remediate by: 2/16/2026
Ransomware use CVE-2025-52691

SmarterTools SmarterMail Unrestricted Upload of File with Dangerous Type Vulnerability

SmarterTools — SmarterMail

SmarterMail contains a critical flaw allowing unauthenticated attackers to upload arbitrary files anywhere on the mail server. Because no authentication is required and files can land in any location, attackers can place executable content that runs with server privileges — achieving full remote code execution. This vulnerability is already being actively exploited in ransomware campaigns, making exposed mail servers an immediate, high-priority target with potential for complete system compromise.

No patch reference found

Next step: No vendor patch or official advisory has been published as of this writing; organizations running SmarterMail should strongly consider taking the product offline or isolating it from untrusted networks until SmarterTools releases a fix, per CISA's guidance to discontinue use if mitigations are unavailable.

Added: 1/26/2026 Remediate by: 2/16/2026
Remediation overdue CVE-2026-21509

Microsoft Office Security Feature Bypass Vulnerability

Microsoft — Office

This vulnerability in Microsoft Office allows a local attacker to bypass a security feature by exploiting the application's reliance on untrusted inputs in a security decision. While it requires local access, a successful exploit could undermine protections users rely on to stay safe when working with Office documents. The risk is elevated because some affected products may be end-of-life or end-of-service, meaning they may no longer receive security updates, leaving users permanently exposed.

Patch available

Next step: Review the Microsoft Security Response Center advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21509 for patch or update details, and if your version of Office is end-of-life or end-of-service, discontinue use and migrate to a supported version immediately.

Interim mitigation: A mitigation script has been referenced at https://www.vicarius.io/vsociety/posts/cve-2026-21509-mitigation-script-microsoft-office-security-feature-bypass-vulnerability for organizations that cannot immediately apply a fix; however, CISA advises following vendor instructions or discontinuing use of the product if mitigations are unavailable.

Added: 1/26/2026 Remediate by: 2/16/2026
Ransomware use CVE-2026-23760

SmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel Vulnerability

SmarterTools — SmarterMail

SmarterMail's password reset API has a critical flaw: the endpoint that forces a password reset on administrator accounts accepts anonymous requests and doesn't verify the existing password or a valid reset token. An attacker who knows only an admin username can remotely set a new password and take full control of the mail server. This vulnerability is already being exploited in ransomware attacks, making it an urgent threat to any organization running SmarterMail.

No patch reference found

Next step: No vendor patch or advisory has been published at this time. Organizations should assess whether SmarterMail can be taken offline or replaced, as CISA's guidance states to discontinue use if mitigations are unavailable.

Added: 1/26/2026 Remediate by: 2/16/2026
Remediation overdue CVE-2026-24061

GNU InetUtils Argument Injection Vulnerability

GNU — InetUtils

GNU InetUtils' telnetd daemon contains an argument injection flaw that lets a remote attacker bypass authentication entirely by supplying a specially crafted USER environment variable value of '-f root'. Because telnet is often used in legacy or embedded environments, a successful exploit grants an unauthenticated attacker access — potentially as root — without valid credentials. This is a critical risk for any system running the affected telnetd service, as it requires no prior foothold.

Patch available

Next step: Apply the patch available in the GNU InetUtils repository (commit ccba9f748aa8d50a38d7748e2e60362edd6a32cc) and review the vendor advisory at https://lists.gnu.org/archive/html/bug-inetutils/2026-01/msg00004.html for additional guidance.

Interim mitigation: The vendor advisory at https://lists.gnu.org/archive/html/bug-inetutils/2026-01/msg00004.html is the reference for both the patch and any interim guidance; consult it directly for compensating controls. If mitigations are unavailable or cannot be applied, CISA advises discontinuing use of the product.

Added: 1/26/2026 Remediate by: 2/16/2026
Remediation overdue CVE-2024-37079

Broadcom VMware vCenter Server Out-of-bounds Write Vulnerability

Broadcom — VMware vCenter Server

This vulnerability in VMware vCenter Server allows an attacker with basic network access to the vCenter Server to send maliciously crafted packets targeting the DCERPC protocol implementation. A successful exploit could result in remote code execution — meaning an attacker could run arbitrary code on the server without valid credentials. Since vCenter Server is the central management plane for VMware virtualized environments, compromise could give attackers control over an entire virtual infrastructure.

Patch available

Next step: Apply the patch immediately by following the vendor's security advisory at https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24453.

Added: 1/23/2026 Remediate by: 2/13/2026
Remediation overdue CVE-2025-31125

Vite Vitejs Improper Access Control Vulnerability

Vite — Vitejs

This flaw in Vite's development server allows attackers to read files that should be inaccessible by appending specially crafted query parameters such as ?inline&import or ?raw?import to requests. If your team runs Vite's dev server exposed to a network — via the --host flag or server.host configuration — arbitrary files on the host could be read by anyone who can reach that server. Production builds are not affected, but exposed dev environments present a real data-exposure risk.

Patch available

Next step: Apply the patch available in the official Vite security advisory and the linked commit at https://github.com/vitejs/vite/security/advisories/GHSA-4r4m-qw57-chr8 as soon as possible.

Added: 1/22/2026 Remediate by: 2/12/2026
Remediation overdue CVE-2025-34026

Versa Concerto Improper Authentication Vulnerability

Versa — Concerto

Versa Concerto, an SD-WAN orchestration platform, has a flaw in its Traefik reverse proxy configuration that lets unauthenticated attackers reach administrative endpoints. Once inside, attackers can access internal Actuator endpoints to pull heap dumps and trace logs, which can expose sensitive data including credentials or session tokens. Because SD-WAN orchestration platforms control wide network infrastructure, a compromise here could provide an attacker significant visibility into and control over enterprise network operations.

Patch available

Next step: Review the Versa Networks security advisory at https://security-portal.versa-networks.com/emailbulletins/6830f94328defa375486ff2e and apply any vendor-provided mitigations or patches immediately; if no fix can be applied, consider discontinuing use of the product as directed by CISA.

Interim mitigation: Compensating control details are referenced in a ProjectDiscovery disclosure at https://projectdiscovery.io/blog/versa-concerto-authentication-bypass-rce — administrators should review that resource for any documented interim mitigations while awaiting a full vendor patch.

Added: 1/22/2026 Remediate by: 2/12/2026
Remediation overdue CVE-2025-54313

Prettier eslint-config-prettier Embedded Malicious Code Vulnerability

Prettier — eslint-config-prettier

A malicious version of the popular eslint-config-prettier npm package was published containing embedded malware. When developers or automated pipelines install the compromised package, an install.js script executes automatically and drops a file called node-gyp.dll on Windows systems. This supply-chain attack is particularly dangerous because it triggers silently during routine dependency installation, potentially compromising developer workstations, CI/CD environments, and any systems where the package is installed.

No patch reference found

Next step: No official patch or vendor advisory has been published at this time. Organizations should immediately audit their environments for any installations of affected eslint-config-prettier versions and discontinue use of the package until a verified clean release is confirmed.

Added: 1/22/2026 Remediate by: 2/12/2026
Remediation overdue CVE-2025-68645

Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability

Synacor — Zimbra Collaboration Suite (ZCS)

This vulnerability in Zimbra Collaboration Suite lets remote attackers manipulate how the server processes requests to its /h/rest endpoint, tricking it into including arbitrary files from the WebRoot directory. Because no authentication barrier is implied as a prerequisite, attackers could potentially read sensitive files or execute malicious code, threatening the confidentiality and integrity of a widely-used enterprise email and collaboration platform.

Patch available

Next step: Review the Zimbra Security Center advisory at https://wiki.zimbra.com/wiki/Security_Center for available patches or guidance, and apply any updates immediately; no standalone patch reference has been confirmed in current tracking data.

Added: 1/22/2026 Remediate by: 2/12/2026
Remediation overdue CVE-2026-20045

Cisco Unified Communications Products Code Injection Vulnerability

Cisco — Unified Communications Manager

This vulnerability affects multiple widely-deployed Cisco Unified Communications products, including Unified CM, Unified CM SME, Unified CM IM&P, Unity Connection, and Webex Calling Dedicated Instance. An attacker who exploits it can inject code to gain initial user-level access to the underlying operating system, then escalate privileges all the way to root. Full root compromise means an attacker could exfiltrate data, pivot deeper into the network, or disrupt critical voice and messaging infrastructure.

Patch available

Next step: Review and apply guidance from Cisco's official security advisory at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-voice-rce-mORhqY4b immediately, as no standalone patch reference was identified in the available data.

Added: 1/21/2026 Remediate by: 2/11/2026
Remediation overdue CVE-2026-20805

Microsoft Windows Information Disclosure Vulnerability

Microsoft — Windows

This vulnerability in Windows Desktop Window Manager allows a locally authenticated attacker to access information they shouldn't be able to see. While exploitation requires the attacker to already have some level of local access, information disclosure flaws are commonly chained with other vulnerabilities to escalate an attack — for example, leaking memory addresses or sensitive data to bypass security controls and enable further compromise of the system.

Patch available

Next step: Review and apply the guidance published in Microsoft's Security Response Center advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20805; no patch reference was confirmed in the source data at time of publication, so monitor that advisory closely for updates.

Added: 1/13/2026 Remediate by: 2/3/2026
Remediation overdue CVE-2025-8110

Gogs Path Traversal Vulnerability

Gogs — Gogs

Gogs, a self-hosted Git service, has a path traversal flaw in its PutContents API caused by improper handling of symbolic links. An attacker who can craft API requests could escape intended directory boundaries, potentially writing or manipulating files outside the repository. This could lead to remote code execution on the host system, making it a serious risk for any organization running Gogs as part of their development infrastructure.

Patch available

Next step: Apply the fix referenced in the official patch commit (https://github.com/gogs/gogs/commit/553707f3fd5f68f47f531cfcff56aa3ec294c6f6) and review the associated pull request (https://github.com/gogs/gogs/pull/8078) for full details; update your Gogs installation as soon as possible.

Added: 1/12/2026 Remediate by: 2/2/2026
Remediation overdue CVE-2009-0556

Microsoft Office PowerPoint Code Injection Vulnerability

Microsoft — Office

A maliciously crafted PowerPoint file can trigger memory corruption in Microsoft Office PowerPoint through an invalid index value in an OutlineTextRefAtom, allowing an attacker to execute arbitrary code on the victim's machine. In practice, this means opening a booby-trapped .ppt file — received via email or downloaded from the web — could give an attacker full control of the system. This type of file-based code execution vulnerability is a common vector for targeted attacks and malware delivery.

Patch available

Next step: Apply the patch or follow the guidance detailed in Microsoft's Security Advisory 969136 at http://www.microsoft.com/technet/security/advisory/969136.mspx immediately.

Added: 1/7/2026 Remediate by: 1/28/2026
Remediation overdue CVE-2025-37164

Hewlett Packard Enterprise (HPE) OneView Code Injection Vulnerability

Hewlett Packard Enterprise (HPE) — OneView

HPE OneView, a data center infrastructure management platform, contains a code injection flaw that lets a remote attacker execute arbitrary code without any authentication. This means an attacker with network access to the management interface could fully compromise the platform — potentially gaining control over the servers, storage, and networking gear OneView manages. Because OneView sits at the heart of data center operations, a successful exploit could cascade into widespread infrastructure compromise.

Patch available

Next step: Review and apply the guidance in HPE's official security bulletin at https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbgn04985en_us&docLocale=en_US immediately, as this unauthenticated remote code execution vulnerability is actively tracked by CISA.

Added: 1/7/2026 Remediate by: 1/28/2026
Remediation overdue CVE-2025-14847

MongoDB and MongoDB Server Improper Handling of Length Parameter Inconsistency Vulnerability

MongoDB — MongoDB and MongoDB Server

MongoDB Server mishandles length parameters in Zlib-compressed protocol headers, allowing an unauthenticated remote client to read uninitialized heap memory. This is significant because no authentication is required to trigger the flaw, meaning any network-accessible MongoDB instance could leak sensitive memory contents to an attacker. Heap memory exposure can reveal credentials, query data, or internal state, potentially enabling further attacks or data breaches.

Patch available

Next step: Apply the patch referenced in MongoDB's official issue tracker at https://jira.mongodb.org/browse/SERVER-115508 as soon as possible, following MongoDB's vendor instructions for your affected version.

Added: 12/29/2025 Remediate by: 1/19/2026
Remediation overdue CVE-2023-52163

Digiever DS-2105 Pro Missing Authorization Vulnerability

Digiever — DS-2105 Pro

The Digiever DS-2105 Pro network video recorder fails to enforce proper authorization checks on its time_tzsetup.cgi endpoint, allowing an unauthenticated or unauthorized attacker to inject and execute arbitrary commands on the device. This means an attacker could fully compromise the NVR, potentially using it as a foothold into the broader network, disrupting surveillance operations, or recruiting the device into a botnet — all without needing valid credentials.

No patch reference found

Next step: No vendor patch or official advisory has been published for this vulnerability. Per CISA guidance, organizations should discontinue use of the Digiever DS-2105 Pro if no vendor-supplied mitigations become available.

Added: 12/22/2025 Remediate by: 1/12/2026
Remediation overdue CVE-2025-14733

WatchGuard Firebox Out of Bounds Write Vulnerability

WatchGuard — Firebox

This flaw in WatchGuard's Fireware OS allows a remote attacker with no credentials to write data outside intended memory boundaries in the iked process, potentially executing arbitrary code on the device. Because it targets the IKEv2 VPN handler, both mobile user VPN and branch office VPN configurations using IKEv2 with a dynamic gateway peer are exposed at the network perimeter — exactly where attackers look for initial footholds into an organization.

Patch available

Next step: Review and apply the guidance published in WatchGuard's official advisory at https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2025-00027 immediately, as no patch reference was independently confirmed in the source data but the vendor advisory is the authoritative source for remediation steps.

Added: 12/19/2025 Remediate by: 12/26/2025
Remediation overdue CVE-2025-20393

Cisco Multiple Products Improper Input Validation Vulnerability

Cisco — Multiple Products

This vulnerability in Cisco's Secure Email Gateway, Secure Email, AsyncOS Software, and Web Manager appliances allows attackers to inject malicious input that bypasses validation checks, ultimately executing arbitrary commands as root. Root-level access means a successful attacker has complete control over the underlying operating system — able to modify configurations, exfiltrate data, install backdoors, or pivot deeper into the network. These are perimeter security appliances, making compromise especially serious since they are trusted to inspect and filter traffic.

Patch available

Next step: Review and apply the guidance in Cisco's official security advisory at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sma-attack-N9bf4 immediately.

Added: 12/17/2025 Remediate by: 12/24/2025
Remediation overdue CVE-2025-40602

SonicWall SMA1000 Missing Authorization Vulnerability

SonicWall — SMA1000 appliance

SonicWall's SMA1000 appliances, which provide remote access for enterprise networks, contain a flaw where the system fails to properly verify a user's authorization before allowing certain actions. This means an attacker could exploit the gap to elevate their privileges within the Appliance Management Console, potentially gaining administrative control over the device. Because SMA1000 sits at the network perimeter and manages remote access, a compromised appliance could expose the broader internal network.

Patch available

Next step: Review SonicWall's official security advisory at https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0019 and apply any vendor-provided patches or instructions immediately.

Added: 12/17/2025 Remediate by: 12/24/2025
Remediation overdue CVE-2025-59374

ASUS Live Update Embedded Malicious Code Vulnerability

ASUS — Live Update

ASUS Live Update was compromised in a supply chain attack, meaning attackers tampered with the software before it reached end users. Distributed builds contained embedded malicious code that could cause targeted devices to perform unintended actions. Because the threat was introduced at the distribution level, users who installed what appeared to be a legitimate update were exposed. The product is potentially end-of-life or end-of-service, making future patching unlikely and increasing the risk to anyone still running it.

Patch available

Next step: Discontinue use of ASUS Live Update immediately, as the product is potentially EoL/EoS with no patch available; review the official ASUS advisory at https://www.asus.com/news/hqfgvuyz6uyayje1/ for vendor-specific guidance.

Added: 12/17/2025 Remediate by: 1/7/2026
Remediation overdue CVE-2025-59718

Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability

Fortinet — Multiple Products

This vulnerability allows an unauthenticated attacker to bypass FortiCloud SSO login by crafting a malicious SAML message — essentially forging proof of identity without valid credentials. Because SAML is used for single sign-on, a successful exploit could grant full access to Fortinet management interfaces across FortiOS, FortiSwitchMaster, FortiProxy, and FortiWeb without knowing any password. The breadth of affected products makes this a high-priority issue for any organization using Fortinet infrastructure with FortiCloud SSO enabled.

Patch available

Next step: Review the Fortinet PSIRT advisory at https://fortiguard.fortinet.com/psirt/FG-IR-25-647 and apply all patches referenced there, including those addressing the related CVE-2025-59719, as directed by Fortinet.

Added: 12/16/2025 Remediate by: 12/23/2025
Remediation overdue CVE-2025-14611

Gladinet CentreStack and Triofox Hard Coded Cryptographic Vulnerability

Gladinet — CentreStack and Triofox

Gladinet CentreStack and Triofox ship with hardcoded AES cryptographic keys, meaning any attacker who knows those keys — and they are not secret once discovered — can craft malicious requests against publicly exposed endpoints without needing any credentials. The practical result is unauthenticated local file inclusion, which allows attackers to read arbitrary files on the server. Any organization running these products on an internet-facing system is directly at risk.

No patch reference found

Next step: No vendor patch or advisory reference was identified in the source data at this time. Organizations should evaluate whether to discontinue use of affected Gladinet CentreStack and Triofox deployments, particularly any instances exposed to the public internet, until the vendor provides an official fix.

Added: 12/15/2025 Remediate by: 1/5/2026
Remediation overdue CVE-2025-43529

Apple Multiple Products Use-After-Free WebKit Vulnerability

Apple — Multiple Products

This use-after-free flaw in Apple's WebKit engine means that simply visiting a malicious webpage could trigger memory corruption on affected devices — no user interaction beyond browsing is required. Because WebKit is the underlying HTML rendering engine for iOS, iPadOS, macOS, Safari, and third-party apps that rely on WebKit for web content, the attack surface is broad. Successful exploitation could allow an attacker to execute arbitrary code or crash affected applications.

Patch available

Next step: Apply the update detailed in Apple's vendor advisory at https://support.apple.com/en-us/125884 as soon as possible across all affected Apple platforms.

Added: 12/15/2025 Remediate by: 1/5/2026
Remediation overdue CVE-2018-4063

Sierra Wireless AirLink ALEOS Unrestricted Upload of File with Dangerous Type Vulnerability

Sierra Wireless — AirLink ALEOS

This vulnerability in Sierra Wireless AirLink ALEOS allows an authenticated attacker to upload a dangerous file type via a crafted HTTP request. Once uploaded, that file is executable and reachable through the web server, meaning an attacker who gains valid credentials can achieve remote code execution on the device. Because these are cellular gateway devices often used in critical or industrial environments, a compromise could affect network connectivity and downstream systems.

No patch reference found

Next step: No patch or vendor advisory is available for this vulnerability, and the affected product may be end-of-life or end-of-service — organizations should discontinue use of Sierra Wireless AirLink ALEOS immediately.

Added: 12/12/2025 Remediate by: 1/2/2026
Remediation overdue CVE-2025-14174

Google Chromium Out of Bounds Memory Access Vulnerability

Google — Chromium

An out-of-bounds memory access flaw in ANGLE, the graphics abstraction layer used by Chromium-based browsers, can be triggered simply by visiting a malicious web page. Because ANGLE is shared across Google Chrome, Microsoft Edge, Opera, and other Chromium-based products, the attack surface is extremely broad. A remote attacker could exploit this without any user interaction beyond browsing, potentially leading to crashes, data exposure, or arbitrary code execution.

No patch reference found

Next step: No patch or vendor advisory reference was available at the time of this writing; check directly with your browser vendor (Google, Microsoft, Opera, etc.) for an updated release and apply it immediately once available.

Added: 12/12/2025 Remediate by: 1/2/2026
Remediation overdue CVE-2025-58360

OSGeo GeoServer Improper Restriction of XML External Entity Reference Vulnerability

OSGeo — GeoServer

GeoServer's WMS GetMap endpoint fails to properly restrict XML External Entity (XXE) references, meaning an attacker can craft a malicious XML request that causes the server to process external entities it shouldn't. This can expose sensitive files on the server, enable server-side request forgery, or potentially lead to data exfiltration — all without requiring authentication depending on how the endpoint is exposed. GeoServer is widely used in geospatial infrastructure, making this a high-value target.

Patch available

Next step: Review and apply guidance from the official vendor security advisory at https://github.com/geoserver/geoserver/security/advisories/GHSA-fjf5-xgmq-5525; no formal patch reference has been confirmed in the CISA KEV catalog at this time.

Added: 12/11/2025 Remediate by: 1/1/2026
Remediation overdue CVE-2025-6218

RARLAB WinRAR Path Traversal Vulnerability

RARLAB — WinRAR

WinRAR, a widely used archive utility, contains a path traversal flaw that lets an attacker manipulate file extraction paths to place malicious files in unintended locations, ultimately executing arbitrary code under the logged-in user's account. Because WinRAR is installed on millions of Windows systems and is routinely used to open untrusted archive files, a crafted archive sent via email or downloaded from the web could silently compromise a machine without any obvious warning to the user.

No patch reference found

Next step: No patch or vendor advisory has been publicly identified at this time; organizations should check RARLAB's official site for any newly released updates and be prepared to discontinue use of WinRAR if no fix becomes available.

Added: 12/9/2025 Remediate by: 12/30/2025
Remediation overdue CVE-2025-62221

Microsoft Windows Use After Free Vulnerability

Microsoft — Windows

A use-after-free flaw in the Windows Cloud Files Mini Filter Driver lets a locally authenticated attacker escalate their privileges on the affected system. This means an attacker who already has a foothold — even with limited user rights — could leverage this bug to gain higher-level access, potentially taking full control of the machine. This is especially concerning in shared or enterprise environments where lateral movement and privilege escalation are key steps in ransomware and targeted attack chains.

Patch available

Next step: Apply the patch and follow the guidance provided in Microsoft's official advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-62221 as soon as possible.

Added: 12/9/2025 Remediate by: 12/30/2025
Remediation overdue CVE-2022-37055

D-Link Routers Buffer Overflow Vulnerability

D-Link — Routers

This buffer overflow vulnerability in certain D-Link routers carries high impact across confidentiality, integrity, and availability — meaning an attacker could potentially read sensitive data, alter device behavior, or crash the device entirely. Making matters worse, the affected products may already be end-of-life or end-of-service, meaning D-Link may no longer issue security updates for them. Organizations still running these devices are exposed with limited options for a supported fix.

Patch available

Next step: Review the D-Link security advisory at https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10308 and apply any available patch; if the device is end-of-life and no viable patch applies, CISA explicitly recommends discontinuing use of the product.

Added: 12/8/2025 Remediate by: 12/29/2025
Remediation overdue CVE-2025-66644

Array Networks ArrayOS AG OS Command Injection Vulnerability

Array Networks — ArrayOS AG

Array Networks ArrayOS AG contains an OS command injection flaw, meaning an attacker could send maliciously crafted input to execute arbitrary operating system commands on the affected device. Array Networks AG appliances are typically used for SSL VPN and network access control, making them high-value targets — a successful exploit could give attackers deep access to a network gateway and the broader environment behind it.

No patch reference found

Next step: No patch or vendor advisory has been identified for this vulnerability at this time; organizations running Array Networks ArrayOS AG should contact the vendor directly for guidance and, per CISA's required action, consider discontinuing use of the product if no mitigations become available.

Added: 12/8/2025 Remediate by: 12/29/2025
Ransomware use CVE-2025-55182

Meta React Server Components Remote Code Execution Vulnerability

Meta — React Server Components

This vulnerability in Meta's React Server Components allows unauthenticated attackers to execute arbitrary code remotely by exploiting how React decodes payloads sent to React Server Function endpoints. Because no authentication is required, any internet-exposed application using React Server Components could be compromised without user interaction. Critically, this flaw is already being exploited by ransomware operators, meaning real-world attacks are active and the risk of full system compromise or data extortion is immediate and severe.

Patch available

Next step: Apply the patch immediately by following the guidance published in Meta's official security advisory at https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components.

Added: 12/5/2025 Remediate by: 12/12/2025
Remediation overdue CVE-2021-26828

OpenPLC ScadaBR Unrestricted Upload of File with Dangerous Type Vulnerability

OpenPLC — ScadaBR

This vulnerability in OpenPLC's ScadaBR allows any authenticated user to upload and execute arbitrary JSP files through a specific endpoint. In industrial control and SCADA environments, this is especially serious: an attacker with even low-level credentials can effectively take full control of the server, potentially manipulating or disrupting industrial processes. The fact that it requires authentication provides only a thin barrier, since credentials can be stolen, guessed, or obtained through phishing.

Patch available

Next step: Review and apply the fix documented in the GitHub pull request at https://github.com/SCADA-LTS/Scada-LTS/pull/2174 and consult the vendor forum advisory at http://forum.scadabr.com.br/t/report-falhas-de-seguranca-em-versoes-do-scadabr/3615/4; if patching is not feasible, CISA advises discontinuing use of the product.

Added: 12/3/2025 Remediate by: 12/24/2025
Remediation overdue CVE-2025-48572

Android Framework Privilege Escalation Vulnerability

Android — Framework

A privilege escalation flaw in the Android Framework means an attacker — potentially through a malicious app or local access — could gain elevated permissions beyond what is normally allowed, potentially taking control of a device. Because this affects Android's core framework layer, the impact is broad across the Android ecosystem. CISA has added it to the Known Exploited Vulnerabilities catalog, indicating confirmed real-world exploitation, making prompt action essential for organizations managing Android devices.

Patch available

Next step: Review and apply the fixes detailed in the Android Security Bulletin for December 2025 (https://source.android.com/security/bulletin/2025-12-01), and ensure all managed Android devices are updated as patches become available from device manufacturers.

Added: 12/2/2025 Remediate by: 12/23/2025
Remediation overdue CVE-2025-48633

Android Framework Information Disclosure Vulnerability

Android — Framework

A flaw in the Android Framework layer can expose sensitive information to attackers. Because the Framework underpins nearly every Android application and system service, a successful exploit could allow an attacker to read data they shouldn't have access to — potentially enabling further attacks or privacy violations. The exact mechanism is unspecified in public disclosures, but the vulnerability is significant enough to earn a place in CISA's Known Exploited Vulnerabilities catalog, indicating real-world exploitation.

Patch available

Next step: Apply the patch provided by Google: review the December 2025 Android Security Bulletin at https://source.android.com/security/bulletin/2025-12-01 and deploy the corresponding security update to all managed Android devices as soon as possible.

Added: 12/2/2025 Remediate by: 12/23/2025
Remediation overdue CVE-2021-26829

OpenPLC ScadaBR Cross-site Scripting Vulnerability

OpenPLC — ScadaBR

This cross-site scripting (XSS) vulnerability in OpenPLC's ScadaBR affects the system_settings.shtm page, a component used in industrial control and SCADA environments. An attacker who can deliver a malicious script through this endpoint could potentially hijack authenticated user sessions, steal credentials, or manipulate what operators see on their HMI dashboards. Because SCADA systems often control physical processes, compromised operator interfaces carry risks beyond typical IT environments.

Patch available

Next step: Review the vendor forum advisory at http://forum.scadabr.com.br/t/report-falhas-de-seguranca-em-versoes-do-scadabr/3615/4 for available guidance; if no patch or fix can be confirmed and applied, CISA advises discontinuing use of the affected product.

Added: 11/28/2025 Remediate by: 12/19/2025
Remediation overdue CVE-2025-61757

Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability

Oracle — Fusion Middleware

Oracle Fusion Middleware's Identity Manager can be fully taken over by an unauthenticated remote attacker due to a missing authentication check on a critical function. This means no credentials are required to exploit it — an internet-exposed instance could be compromised by anyone who can reach it. Identity Manager controls user provisioning and access across enterprise systems, so a takeover could lead to unauthorized account creation, privilege escalation, or broad lateral movement across the organization.

Patch available

Next step: Review and apply the fixes detailed in Oracle's October 2025 Critical Patch Update advisory at https://www.oracle.com/security-alerts/cpuoct2025.html immediately.

Added: 11/21/2025 Remediate by: 12/12/2025
Remediation overdue CVE-2025-13223

Google Chromium V8 Type Confusion Vulnerability

Google — Chromium V8

Google's V8 JavaScript engine, embedded in Chrome and other Chromium-based browsers, contains a type confusion flaw that can corrupt heap memory. Type confusion bugs allow attackers to trick the engine into treating data as the wrong type, which in a browser context typically enables arbitrary code execution — meaning a malicious webpage could silently compromise a visitor's system. Because Chromium is widely deployed across enterprises, this vulnerability represents a broad attack surface for credential theft, malware delivery, or lateral movement.

Patch available

Next step: Review and apply the update detailed in Google's stable channel release advisory at https://chromereleases.googleblog.com/2025/11/stable-channel-update-for-desktop_17.html as soon as possible.

Added: 11/19/2025 Remediate by: 12/10/2025
Remediation overdue CVE-2025-58034

Fortinet FortiWeb OS Command Injection Vulnerability

Fortinet — FortiWeb

This vulnerability in Fortinet's FortiWeb web application firewall allows an authenticated attacker to inject OS-level commands through crafted HTTP requests or CLI commands, resulting in unauthorized code execution on the underlying system. Because FortiWeb sits at the network perimeter protecting web applications, a compromised instance could give attackers deep footholds into infrastructure, potentially exposing backend systems and sensitive traffic to full attacker control.

Patch available

Next step: Review and apply guidance from Fortinet's official security advisory at https://fortiguard.fortinet.com/psirt/FG-IR-25-513 immediately, as no patch reference was independently confirmed in the source data.

Added: 11/18/2025 Remediate by: 11/25/2025
Remediation overdue CVE-2025-64446

Fortinet FortiWeb Path Traversal Vulnerability

Fortinet — FortiWeb

This vulnerability in Fortinet FortiWeb allows an unauthenticated attacker — meaning no credentials are required — to traverse file paths and execute administrative commands by sending specially crafted HTTP or HTTPS requests. Because it requires no authentication, the attack surface is broad: any FortiWeb instance reachable over the network could be targeted. Successful exploitation gives an attacker administrative control over the appliance, potentially exposing protected web applications and internal infrastructure behind it.

Patch available

Next step: Review and apply the guidance published in Fortinet's official advisory at https://fortiguard.fortinet.com/psirt/FG-IR-25-910; if mitigations are unavailable and a patch cannot be applied, CISA directs organizations to discontinue use of the product.

Added: 11/14/2025 Remediate by: 11/21/2025
Remediation overdue CVE-2025-12480

Gladinet Triofox Improper Access Control Vulnerability

Gladinet — Triofox

Gladinet Triofox, a file-sharing and collaboration platform, fails to properly restrict access to its initial setup pages after initial configuration is complete. This means an attacker could reach setup interfaces that should be locked down on a live system, potentially allowing unauthorized reconfiguration or takeover. Because setup pages typically carry elevated privileges and trust, exposure of these pages on a production system represents a serious risk of unauthorized access or system compromise.

No patch reference found

Next step: As of this writing, no vendor patch or official advisory has been published for this vulnerability. Organizations running Gladinet Triofox should consider discontinuing use of the product until a fix is available, as no vendor-provided mitigation or remediation guidance currently exists.

Added: 11/12/2025 Remediate by: 12/3/2025
Remediation overdue CVE-2025-62215

Microsoft Windows Race Condition Vulnerability

Microsoft — Windows

This vulnerability in the Windows Kernel allows a low-privileged local user to exploit a race condition and elevate their access to SYSTEM level — the highest privilege on a Windows machine. While an attacker needs an existing foothold on the system, this flaw is a critical stepping stone: it turns a limited compromise into full system control, enabling installation of malware, credential theft, or complete takeover without additional authentication.

Patch available

Next step: Review the Microsoft Security Response Center advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-62215 and apply any available patches or vendor instructions immediately, as no independently confirmed patch details were present in the source data at time of publication.

Added: 11/12/2025 Remediate by: 12/3/2025
Remediation overdue CVE-2025-9242

WatchGuard Firebox Out-of-Bounds Write Vulnerability

WatchGuard — Firebox

WatchGuard Firebox devices contain a flaw in the OS iked process — the component handling IKE (Internet Key Exchange) for VPN tunnels — that allows a remote, unauthenticated attacker to write data outside intended memory boundaries and potentially execute arbitrary code. Because no authentication is required, this is exposed to anyone who can reach the affected service, making it a high-priority risk for network perimeters relying on WatchGuard Firebox for security.

Patch available

Next step: Review and apply the guidance published in WatchGuard's official security advisory at https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2025-00015 immediately.

Added: 11/12/2025 Remediate by: 12/3/2025
Remediation overdue CVE-2025-21042

Samsung Mobile Devices Out-of-Bounds Write Vulnerability

Samsung — Mobile Devices

A flaw in Samsung's libimagecodec.quram.so library allows remote attackers to write data outside intended memory boundaries, potentially enabling arbitrary code execution on affected mobile devices. Because exploitation can be triggered remotely without physical access, a successful attack could give an attacker full control over the device — including access to sensitive data, communications, and corporate resources — making this a serious risk for any organization with Samsung devices in its environment.

Patch available

Next step: Review and apply the security updates detailed in Samsung's April 2025 security advisory at https://security.samsungmobile.com/securityUpdate.smsb?year=2025&month=04 as soon as possible.

Added: 11/10/2025 Remediate by: 12/1/2025
Remediation overdue CVE-2025-11371

Gladinet CentreStack and Triofox Files or Directories Accessible to External Parties Vulnerability

Gladinet — CentreStack and Triofox

Gladinet CentreStack and Triofox, which are file-sharing and remote access platforms used in enterprise environments, contain a vulnerability that exposes system files to unauthorized external parties. This means attackers could access sensitive files or directories on the server without proper authorization, potentially exposing credentials, configuration data, or other critical information that could enable further compromise of the environment.

No patch reference found

Next step: No patch or vendor advisory has been publicly identified at this time. Per CISA guidance, administrators should apply vendor-supplied mitigations if and when they become available, or discontinue use of the affected Gladinet CentreStack and Triofox products until a fix is confirmed.

Added: 11/4/2025 Remediate by: 11/25/2025
Remediation overdue CVE-2025-48703

CWP Control Web Panel OS Command Injection Vulnerability

CWP — Control Web Panel

CWP Control Web Panel, a widely used web hosting control panel, has a critical flaw allowing attackers with no credentials to execute arbitrary operating system commands remotely. The only prerequisite is knowing a valid non-root username on the system — information often obtainable through other means. Successful exploitation gives an attacker full command execution on the server, putting hosted websites, databases, and the underlying infrastructure at serious risk of compromise or ransomware deployment.

No patch reference found

Next step: No vendor patch or official advisory has been published at this time. If your organization runs CWP Control Web Panel, be aware that no vendor-supplied fix is currently available — consider discontinuing use of the product until a patch is released, in line with CISA's guidance.

Added: 11/4/2025 Remediate by: 11/25/2025
Remediation overdue CVE-2025-24893

XWiki Platform Eval Injection Vulnerability

XWiki — Platform

This vulnerability in XWiki Platform allows completely unauthenticated visitors — including anonymous internet users — to inject and execute arbitrary code on the server by crafting a malicious request to the SolrSearch endpoint. Because no login is required, the attack surface is wide open to anyone who can reach the instance. Successful exploitation gives an attacker remote code execution, meaning full control over the underlying server and any data it holds.

Patch available

Next step: Apply the patch immediately by updating XWiki Platform per the vendor's security advisory at https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-rr6p-3pfg-562j, which references the specific fix commit at https://github.com/xwiki/xwiki-platform/commit/67021db9b8ed26c2236a653269302a86bf01ef40.

Added: 10/30/2025 Remediate by: 11/20/2025
Remediation overdue CVE-2025-41244

Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability

Broadcom — VMware Aria Operations and VMware Tools

This vulnerability allows a local, non-administrative user inside a virtual machine to escalate their privileges all the way to root on that same VM. The attack requires VMware Tools to be installed and the VM to be managed by Aria Operations with SDMP enabled — conditions common in enterprise VMware environments. A compromised or malicious user account that would otherwise have limited access could leverage this flaw to gain full control of the guest OS, posing serious risk to workloads and data.

Patch available

Next step: Review and apply mitigations per the Broadcom security advisory at https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36149, as no standalone patch reference has been confirmed in available data.

Added: 10/30/2025 Remediate by: 11/20/2025
Remediation overdue CVE-2025-6204

Dassault Systèmes DELMIA Apriso Code Injection Vulnerability

Dassault Systèmes — DELMIA Apriso

DELMIA Apriso, an enterprise manufacturing operations management platform from Dassault Systèmes, contains a code injection flaw that lets an attacker execute arbitrary code on affected systems. Because this product is used to manage production and shop-floor operations, successful exploitation could disrupt manufacturing workflows, compromise sensitive operational data, or provide a foothold for deeper network intrusion. CISA has added this to its Known Exploited Vulnerabilities catalog, signaling active or high-risk exploitation concern.

Patch available

Next step: Review and apply the vendor's guidance immediately by consulting the Dassault Systèmes security advisory at https://www.3ds.com/trust-center/security/security-advisories/cve-2025-6204; if mitigations or patches are unavailable or cannot be applied, CISA instructs organizations to discontinue use of the product.

Added: 10/28/2025 Remediate by: 11/18/2025
Remediation overdue CVE-2025-6205

Dassault Systèmes DELMIA Apriso Missing Authorization Vulnerability

Dassault Systèmes — DELMIA Apriso

DELMIA Apriso, Dassault Systèmes' manufacturing operations management platform, contains a missing authorization flaw that lets attackers gain privileged access without proper credential checks. In practice, this means an unauthorized or low-privileged user could escalate their access within the application, potentially manipulating production data, workflows, or system configurations. Because DELMIA Apriso is used in industrial and manufacturing environments, unauthorized privileged access carries significant operational risk.

Patch available

Next step: Review and apply the vendor's guidance immediately by consulting the official Dassault Systèmes security advisory at https://www.3ds.com/trust-center/security/security-advisories/cve-2025-6205, and if no viable mitigation or patch can be applied, consider discontinuing use of the affected product as directed by CISA.

Added: 10/28/2025 Remediate by: 11/18/2025
Remediation overdue CVE-2025-54236

Adobe Commerce and Magento Improper Input Validation Vulnerability

Adobe — Commerce and Magento

This vulnerability in Adobe Commerce and Magento Open Source allows attackers to take over customer accounts by sending malicious input through the Commerce REST API. Because the REST API is typically internet-exposed and customer accounts can hold payment methods, order history, and personal data, successful exploitation could lead to fraud, data theft, or further compromise of the merchant's environment. Any business running an affected storefront faces direct risk to its customers.

Patch available

Next step: Review and apply the patches detailed in Adobe's security advisory at https://helpx.adobe.com/security/products/magento/apsb25-88.html as soon as possible.

Added: 10/24/2025 Remediate by: 11/14/2025
Remediation overdue CVE-2025-59287

Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability

Microsoft — Windows

WSUS is widely used by Windows environments to manage and distribute software updates across enterprise networks. A deserialization flaw in WSUS means an attacker can send specially crafted data that the service processes as trusted, leading to remote code execution. Because WSUS servers often hold privileged positions in enterprise networks and communicate with many endpoints, a compromise could have significant lateral movement and supply-chain-style impact across an organization.

Patch available

Next step: Review the Microsoft Security Response Center advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-59287 and apply any patch or vendor-recommended fix as soon as it becomes available; as of this writing, no confirmed patch reference was found in the source data.

Interim mitigation: A third-party mitigation script has been referenced at https://www.vicarius.io/vsociety/posts/cve-2025-59287-mitigation-script-rce-vulnerability-in-windows-server-update-service — administrators should review this resource for interim compensating controls while awaiting official vendor guidance.

Added: 10/24/2025 Remediate by: 11/14/2025
Remediation overdue CVE-2025-61932

Motex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel Vulnerability

Motex — LANSCOPE Endpoint Manager

LANSCOPE Endpoint Manager, a widely used endpoint management platform, fails to properly verify the source of incoming communication channels. An attacker who can send specially crafted packets to the software can leverage this flaw to execute arbitrary code — meaning they could take full control of managed endpoints without needing valid credentials. Because endpoint management tools typically run with elevated privileges and have broad reach across an organization's fleet, a compromise here can cascade quickly across the entire environment.

Patch available

Next step: Review and apply the guidance published in the Motex vendor advisory at https://www.motex.co.jp/news/notice/2025/release251020/ as the immediate priority action.

Added: 10/22/2025 Remediate by: 11/12/2025
Remediation overdue CVE-2022-48503

Apple Multiple Products Unspecified Vulnerability

Apple — Multiple Products

A flaw in Apple's JavaScriptCore engine — the component that powers JavaScript execution across macOS, iOS, tvOS, Safari, and watchOS — allows malicious web content to trigger arbitrary code execution. This means simply visiting a crafted webpage could give an attacker full control over the affected device. The broad reach across Apple's product lineup makes this high-priority, and CISA notes some affected products may be end-of-life, meaning no patch will ever arrive for those versions.

Patch available

Next step: Review Apple's advisory at https://support.apple.com/en-us/HT213340 and apply any available updates immediately; if your device is end-of-life and no patch is available, CISA explicitly recommends discontinuing use of the product.

Added: 10/20/2025 Remediate by: 11/10/2025
Remediation overdue CVE-2025-2746

Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability

Kentico — Xperience CMS

This vulnerability in Kentico Xperience CMS allows an attacker to bypass authentication by using an alternate path or channel, potentially giving them unauthorized control over administrative objects within the CMS. For organizations running this platform, that means an unauthenticated attacker could manipulate content, configurations, or user data at an administrative level — without needing valid credentials. The risk is significant for any internet-facing Kentico deployment.

Patch available

Next step: Apply the available hotfix from Kentico's official hotfix download page at https://devnet.kentico.com/download/hotfixes as soon as possible.

Added: 10/20/2025 Remediate by: 11/10/2025
Remediation overdue CVE-2025-2747

Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability

Kentico — Xperience CMS

This vulnerability in Kentico Xperience CMS allows an attacker to bypass authentication through an alternate path or channel, meaning they could gain unauthorized control over administrative objects without valid credentials. For organizations running this CMS, a successful exploit could let an attacker manipulate site content, configurations, or user data at an administrative level — a significant risk for any internet-facing deployment.

Patch available

Next step: Apply the available hotfix from Kentico's official download portal at https://devnet.kentico.com/download/hotfixes as soon as possible to remediate this authentication bypass vulnerability.

Added: 10/20/2025 Remediate by: 11/10/2025
Remediation overdue CVE-2025-33073

Microsoft Windows SMB Client Improper Access Control Vulnerability

Microsoft — Windows

This vulnerability in the Windows SMB Client allows an attacker to trick a victim machine into connecting back to an attacker-controlled system via SMB and authenticating, effectively leaking credentials or enabling privilege escalation. Because SMB is ubiquitous in Windows environments for file sharing and network communication, this flaw is broadly exploitable. A successful attack could let an attacker elevate their privileges on the network, potentially gaining access well beyond their initial foothold.

Patch available

Next step: Review and apply guidance from Microsoft's official advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-33073; no patch reference was confirmed in the source data, so monitor that page closely for updates and apply any released patch immediately.

Interim mitigation: A mitigation script has been referenced at https://www.vicarius.io/vsociety/posts/cve-2025-33073-mitigation-script-improper-access-control-in-windows-smb-affects-microsoft-products — administrators should review this resource for interim compensating controls while awaiting an official vendor patch.

Added: 10/20/2025 Remediate by: 11/10/2025
Ransomware use CVE-2025-61884

Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability

Oracle — E-Business Suite

This unauthenticated SSRF flaw in Oracle E-Business Suite's Configurator component allows a remote attacker to force the server to make arbitrary internal network requests without needing any credentials. In practice, this can be used to probe internal infrastructure, bypass network perimeter controls, or pivot deeper into an environment. The fact that ransomware operators are already exploiting this vulnerability makes it an urgent priority for any organization running Oracle E-Business Suite.

Patch available

Next step: Apply the patch or mitigation instructions provided in Oracle's official security advisory at https://www.oracle.com/security-alerts/alert-cve-2025-61884.html immediately, as this vulnerability is actively exploited by ransomware actors.

Added: 10/20/2025 Remediate by: 11/10/2025
Remediation overdue CVE-2025-54253

Adobe Experience Manager Forms Code Execution Vulnerability

Adobe — Experience Manager (AEM) Forms

Adobe Experience Manager Forms running on JEE (Java EE infrastructure) contains an unspecified flaw that enables arbitrary code execution. This means an attacker who exploits it could run malicious commands on the affected server, potentially leading to full system compromise, data theft, or use as a launchpad for deeper network intrusion. Because AEM Forms is commonly used in enterprise environments to handle sensitive form data and business processes, a successful exploit could have significant operational and data-security consequences.

Patch available

Next step: Review and apply the fixes detailed in Adobe's official security advisory at https://helpx.adobe.com/security/products/aem-forms/apsb25-82.html as the highest priority remediation step.

Added: 10/15/2025 Remediate by: 11/5/2025
Remediation overdue CVE-2016-7836

SKYSEA Client View Improper Authentication Vulnerability

SKYSEA — Client View

SKYSEA Client View, an IT asset management tool common in Japanese enterprises, contains an authentication flaw in how it handles TCP connections with its management console. An unauthenticated remote attacker can exploit this weakness to execute arbitrary code on affected systems without valid credentials. Because management software typically runs with elevated privileges and broad network access, a successful exploit could give an attacker deep control over managed endpoints across an organization.

Patch available

Next step: Review the vendor advisory published by Sky Co., LTD at http://www.skyseaclientview.net/news/161221/ and apply any patches or mitigations described there immediately.

Added: 10/14/2025 Remediate by: 11/4/2025
Remediation overdue CVE-2025-24990

Microsoft Windows Untrusted Pointer Dereference Vulnerability

Microsoft — Windows

This vulnerability in the Microsoft Windows Agere Modem Driver allows an attacker to exploit an untrusted pointer dereference, a flaw where the system follows a memory pointer it shouldn't trust, to escalate their privileges to administrator level. This means a low-privileged attacker who already has some access to a system could effectively take full control of it, making this a serious stepping-stone vulnerability in multi-stage attacks.

Patch available

Next step: Apply the vendor-supplied patch by reviewing and following Microsoft's official guidance at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24990.

Interim mitigation: A mitigation script for this vulnerability has been referenced at https://www.vicarius.io/vsociety/posts/cve-2025-24990-mitigation-script-elevation-of-privilege-vulnerability-in-agere-modem-driver-affecting-windows, which may provide interim compensating controls while a patch is applied.

Added: 10/14/2025 Remediate by: 11/4/2025
Remediation overdue CVE-2025-47827

IGEL OS Use of a Key Past its Expiration Date Vulnerability

IGEL — IGEL OS

IGEL OS uses an expired cryptographic key to verify its boot process, meaning the Secure Boot protection that should guarantee only trusted software runs at startup can be bypassed. An attacker who exploits this can mount a crafted, unverified root filesystem, effectively running arbitrary or malicious code at the operating system level before any other defenses are active. This is especially serious in enterprise thin-client environments where IGEL OS is commonly deployed, as it can undermine the integrity of every device running it.

No patch reference found

Next step: No patch or vendor advisory has been identified in the source data at this time; organizations should contact IGEL directly for guidance and consider discontinuing use of affected IGEL OS versions if no mitigations are available.

Added: 10/14/2025 Remediate by: 11/4/2025
Remediation overdue CVE-2025-59230

Microsoft Windows Improper Access Control Vulnerability

Microsoft — Windows

This vulnerability in Windows Remote Access Connection Manager (RASMAN) allows an already-authenticated local attacker to escalate their privileges on the affected system. In practical terms, this means a low-privileged user or compromised account could gain higher-level system access, making it a significant risk in environments where insider threats or initial-access scenarios are a concern. Privilege escalation flaws are commonly chained with other exploits to achieve full system compromise.

Patch available

Next step: Consult the Microsoft Security Response Center advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-59230 and apply any available patches or vendor-recommended mitigations immediately.

Interim mitigation: A mitigation script targeting this RASMAN elevation-of-privilege vulnerability has been published by Vicarius at https://www.vicarius.io/vsociety/posts/cve-2025-59230-mitigation-script-elevation-of-privilege-vulnerability-affecting-windows-rasman, which may serve as an interim compensating control until an official patch is applied.

Added: 10/14/2025 Remediate by: 11/4/2025
Remediation overdue CVE-2021-43798

Grafana Path Traversal Vulnerability

Grafana Labs — Grafana

Grafana, a widely deployed open-source analytics and monitoring platform, contains a path traversal flaw that lets an unauthenticated attacker request URLs crafted to escape the web root and read arbitrary local files on the server. This means sensitive files — including configuration files potentially containing credentials or secrets — could be exposed without any login required, making this a high-priority risk for any organization running a vulnerable Grafana instance.

Patch available

Next step: Apply the patch immediately by upgrading to a fixed version of Grafana as detailed in the vendor's security advisory at https://github.com/grafana/grafana/security/advisories/GHSA-8pjx-jj86-j47p.

Added: 10/9/2025 Remediate by: 10/30/2025
Remediation overdue CVE-2025-27915

Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability

Synacor — Zimbra Collaboration Suite (ZCS)

This vulnerability allows an attacker to embed malicious JavaScript inside a calendar invitation (ICS file) sent via email. When a Zimbra Classic Web Client user opens or previews the message, the script executes automatically within their authenticated session. The attacker can then perform actions as the victim, including creating email filters that silently redirect incoming messages to an attacker-controlled address — enabling ongoing data theft without the victim's knowledge.

No patch reference found

Next step: As of this writing, no vendor patch or official Zimbra advisory has been published; administrators should monitor Synacor's official channels closely and be prepared to act immediately once a fix is released, or consider discontinuing use of the Classic Web Client if the risk is unacceptable.

Added: 10/7/2025 Remediate by: 10/28/2025
Remediation overdue CVE-2010-3765

Mozilla Multiple Products Remote Code Execution Vulnerability

Mozilla — Multiple Products

This vulnerability in Firefox, SeaMonkey, and Thunderbird allows a remote attacker to execute arbitrary code on a victim's machine simply by having JavaScript enabled — a default browser setting. The flaw triggers memory corruption through flawed DOM manipulation logic, meaning a user visiting a malicious webpage could have their system fully compromised without any unusual interaction. Given how widely these Mozilla products were deployed, this represented a significant attack surface for drive-by download campaigns.

Patch available

Next step: Review the Mozilla security blog advisory at http://blog.mozilla.com/security/2010/10/26/critical-vulnerability-in-firefox-3-5-and-firefox-3-6/ and apply any patches or updated versions provided by Mozilla per vendor instructions.

Added: 10/6/2025 Remediate by: 10/27/2025
Remediation overdue CVE-2010-3962

Microsoft Internet Explorer Uninitialized Memory Corruption Vulnerability

Microsoft — Internet Explorer

This vulnerability in Microsoft Internet Explorer involves uninitialized memory corruption that can be exploited by attackers to execute arbitrary code on a victim's machine, likely through a malicious webpage. Because it enables remote code execution, an attacker could gain full control of an affected system with no physical access required. The affected IE versions may be end-of-life, meaning no further security updates are expected, making continued use a significant ongoing risk.

Patch available

Next step: Review Microsoft Security Advisory 2458511 at the referenced Microsoft TechNet link and apply any available mitigations or patches provided there; if the version of Internet Explorer in use is end-of-life and cannot be patched, CISA explicitly recommends discontinuing use of the product.

Added: 10/6/2025 Remediate by: 10/27/2025
Remediation overdue CVE-2011-3402

Microsoft Windows Remote Code Execution Vulnerability

Microsoft — Windows

A flaw in how Windows parses TrueType fonts, deep inside the kernel-mode graphics driver (win32k.sys), lets an attacker run arbitrary code simply by getting a user to open a malicious Word document or visit a crafted web page. Because the vulnerability lives in kernel-mode code, successful exploitation can grant an attacker full control of the affected system — making this a high-severity, low-interaction risk for any organization still running unpatched Windows endpoints.

Patch available

Next step: Review the Microsoft Security Advisory at http://blogs.technet.com/b/msrc/archive/2011/11/03/microsoft-releases-security-advisory-2639658.aspx and apply any available vendor-supplied patches or instructions immediately; no confirmed patch reference was identified in the source data, so consulting that advisory is the essential first step.

Added: 10/6/2025 Remediate by: 10/27/2025
Remediation overdue CVE-2013-3918

Microsoft Windows Out-of-Bounds Write Vulnerability

Microsoft — Windows

This decade-old flaw in a Windows ActiveX control (icardie.dll) lets attackers execute arbitrary code simply by tricking a user into visiting a malicious webpage. The attacker gains whatever privileges the logged-in user holds, meaning admin accounts face full system compromise. Because the affected product may be end-of-life, many environments could still be running vulnerable software without receiving further security updates, making exposure particularly serious.

Patch available

Next step: Apply the patch provided in Microsoft Security Bulletin MS13-090 immediately; if the affected Windows version is end-of-life and the patch cannot be applied, discontinue use of the product as directed by CISA.

Added: 10/6/2025 Remediate by: 10/27/2025
Remediation overdue CVE-2021-22555

Linux Kernel Heap Out-of-Bounds Write Vulnerability

Linux — Kernel

This Linux kernel vulnerability allows a local attacker to write data beyond the bounds of a heap memory buffer, exploitable through user namespaces. A successful attack can escalate privileges — potentially giving an unprivileged user root-level access — or crash the system via memory corruption. Because user namespaces are widely enabled on modern Linux distributions, this vulnerability is broadly relevant to servers, containers, and desktop systems running affected kernel versions.

Patch available

Next step: Apply the upstream Linux kernel patch referenced in the official commit to net/netfilter/x_tables.c (commit 9fa492cdc160cd27ce1046cb36f47d3b2b1efa21) by updating to a kernel version that includes this fix, following your distribution vendor's security update process.

Added: 10/6/2025 Remediate by: 10/27/2025
Ransomware use CVE-2021-43226

Microsoft Windows Privilege Escalation Vulnerability

Microsoft — Windows

This vulnerability in the Windows Common Log File System (CLFS) driver allows a local attacker with existing privileges to escalate further and bypass security mechanisms. It has been actively exploited in ransomware campaigns, meaning real-world threat actors are using it to gain deeper control over compromised systems. Because it requires only local access — something malware frequently achieves after initial infection — this flaw represents a significant risk in environments that haven't applied Microsoft's patch.

Patch available

Next step: Apply the official Microsoft patch immediately by reviewing and following the guidance at https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-43226.

Added: 10/6/2025 Remediate by: 10/27/2025
Ransomware use CVE-2025-61882

Oracle E-Business Suite Unspecified Vulnerability

Oracle — E-Business Suite

This vulnerability in Oracle E-Business Suite's BI Publisher Integration component allows an unauthenticated attacker over a standard HTTP connection to fully take over Oracle Concurrent Processing — the system that manages background jobs and batch operations. No credentials are required to exploit this, making it particularly dangerous on any internet-exposed or network-accessible EBS instance. It has already been linked to active ransomware campaigns, meaning real-world attackers are actively exploiting it.

Patch available

Next step: Review Oracle's official security alert at https://www.oracle.com/security-alerts/alert-cve-2025-61882.html and apply any available patches or mitigations per vendor instructions immediately, given confirmed ransomware exploitation in the wild.

Added: 10/6/2025 Remediate by: 10/27/2025
Remediation overdue CVE-2014-6278

GNU Bash OS Command Injection Vulnerability

GNU — GNU Bash

This is a Shellshock-era vulnerability in GNU Bash that allows remote attackers to inject and execute arbitrary operating system commands by crafting a malicious environment. Because Bash is widely used as a system shell across Linux and Unix-based systems, exploitation can give an attacker full control over affected hosts without requiring authentication. Any internet-facing service that invokes Bash — such as CGI scripts or DHCP clients — is a potential entry point.

Patch available

Next step: Apply the available patch immediately — an unofficial patch is referenced at lcamtuf.blogspot.com/2014/09/bash-bug-apply-unofficial-patch-now.html, and SUSE has published vendor-specific guidance at suse.com/support/shellshock/; check your Linux distribution's official package repositories for official updated Bash packages.

Added: 10/2/2025 Remediate by: 10/23/2025
Remediation overdue CVE-2015-7755

Juniper ScreenOS Improper Authentication Vulnerability

Juniper — ScreenOS

This flaw in Juniper's ScreenOS allows attackers to gain full administrative access to affected devices without valid credentials. Because these are network security appliances — firewalls and VPN gateways — a successful exploit effectively hands an attacker control over the perimeter security infrastructure itself, enabling traffic interception, configuration changes, or use of the device as a pivot point into protected networks. The authentication bypass requires no legitimate account, making it highly exploitable.

Patch available

Next step: Review and apply the guidance provided in Juniper's official security advisory at http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10713 immediately, as this vulnerability enables unauthenticated remote administrative access to affected ScreenOS devices.

Added: 10/2/2025 Remediate by: 10/23/2025
Remediation overdue CVE-2017-1000353

Jenkins Remote Code Execution Vulnerability

Jenkins — Jenkins

This Jenkins vulnerability allows remote attackers to execute arbitrary code by exploiting the CLI's deserialization handling. An attacker can send a specially crafted serialized Java SignedObject to the remoting-based Jenkins CLI, which then deserializes it through a new ObjectInputStream, completely sidestepping Jenkins' existing blocklist protections. Because Jenkins is widely used in CI/CD pipelines, successful exploitation could give attackers full control over build infrastructure and potentially the broader software supply chain.

Patch available

Next step: Apply the patch referenced in the Jenkins security advisory published 2017-04-26 at https://jenkins.io/security/advisory/2017-04-26/ and review the Oracle CPU April 2022 advisory at https://www.oracle.com/security-alerts/cpuapr2022.html if Oracle products are in scope.

Added: 10/2/2025 Remediate by: 10/23/2025
Remediation overdue CVE-2025-21043

Samsung Mobile Devices Out-of-Bounds Write Vulnerability

Samsung — Mobile Devices

An out-of-bounds write flaw in Samsung's libimagecodec.quram.so library allows remote attackers to execute arbitrary code on affected Samsung mobile devices without requiring physical access. This is a serious risk because successful exploitation could give attackers full control over a device, potentially exposing corporate email, credentials, sensitive data, and enabling further network compromise — all without user interaction beyond receiving or processing malicious content.

Patch available

Next step: Apply the security update detailed in Samsung's September 2025 security advisory at https://security.samsungmobile.com/securityUpdate.smsb?year=2025&month=09 as soon as it becomes available for your device.

Added: 10/2/2025 Remediate by: 10/23/2025
Remediation overdue CVE-2025-4008

Smartbedded Meteobridge Command Injection Vulnerability

Smartbedded — Meteobridge

Meteobridge is a weather data bridging device used to connect personal weather stations to online services. This vulnerability allows an unauthenticated attacker over the network to inject arbitrary commands that execute with root-level privileges — the highest access level on the device. Successful exploitation means complete device compromise, with no login required. Affected organizations using Meteobridge hardware should treat this as a critical exposure, particularly if the device management interface is reachable from untrusted networks.

Patch available

Next step: Review the vendor forum advisory at https://forum.meteohub.de/viewtopic.php?t=18687 for available guidance, and if no patch or fix can be applied, discontinue use of the product as directed by CISA.

Added: 10/2/2025 Remediate by: 10/23/2025
Remediation overdue CVE-2021-21311

Adminer Server-Side Request Forgery Vulnerability

Adminer — Adminer

Adminer, a popular web-based database management tool, contains a server-side request forgery (SSRF) flaw. SSRF lets an attacker trick the server into making HTTP requests on their behalf, potentially reaching internal services, metadata endpoints, or other resources that should never be publicly accessible. Because Adminer is often deployed with broad database access, an unauthenticated remote attacker exploiting this flaw could harvest sensitive internal network information without needing direct access.

Patch available

Next step: Apply the patch available in the official Adminer repository commit (github.com/vrana/adminer/commit/ccd2374b0b12bd547417bf0dacdf153826c83351) by upgrading to a patched version of Adminer as soon as possible.

Added: 9/29/2025 Remediate by: 10/20/2025
Ransomware use CVE-2025-10035

Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability

Fortra — GoAnywhere MFT

GoAnywhere MFT, a widely-used managed file transfer product, contains a deserialization flaw that can be exploited by an attacker who possesses a validly forged license response signature. If exploited, this allows arbitrary objects to be deserialized and can lead to command injection — effectively giving an attacker the ability to run commands on the affected system. This vulnerability is already associated with known ransomware activity, making rapid response critical for any organization running this product.

Patch available

Next step: Review and apply the guidance in Fortra's official security advisory at https://www.fortra.com/security/advisories/product-security/fi-2025-012 immediately, as this vulnerability is actively exploited in ransomware campaigns.

Added: 9/29/2025 Remediate by: 10/20/2025
Remediation overdue CVE-2025-20352

Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability

Cisco — IOS and IOS XE

A stack-based buffer overflow in the SNMP subsystem of Cisco IOS and IOS XE creates two serious risk scenarios: a low-privileged attacker can crash affected devices by forcing a reload (denial of service), while a high-privileged attacker can execute arbitrary code as root, gaining full system control. SNMP is widely deployed for network device management, making this a high-value target. Both network availability and complete device integrity are at stake.

Patch available

Next step: Review and apply the guidance detailed in Cisco's official security advisory at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snmp-x4LPhte, which includes both patch and mitigation information.

Interim mitigation: Cisco's security advisory references mitigation options for this vulnerability. Consult the advisory directly at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snmp-x4LPhte for the specific compensating controls Cisco has documented.

Added: 9/29/2025 Remediate by: 10/20/2025
Remediation overdue CVE-2025-32463

Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability

Sudo — Sudo

This vulnerability in Sudo allows a local attacker to abuse the -R (--chroot) option to execute arbitrary commands as root, completely bypassing the access restrictions defined in the sudoers file. This is particularly dangerous because sudoers is the primary mechanism administrators rely on to control who can run what with elevated privileges. Any local user who can invoke sudo with the chroot flag could silently escalate to full root access, undermining a foundational Linux/Unix security control.

Patch available

Next step: Review and apply guidance from the official Sudo security advisory at https://www.sudo.ws/security/advisories/ — no specific patch reference was identified in the source data, so monitor that page closely for updates and patch as soon as one becomes available.

Interim mitigation: A mitigation reference has been identified at https://www.vicarius.io/vsociety/posts/cve-2025-32463-mitigate-sudo-vulnerability — administrators should review that resource for interim compensating controls while awaiting an official patch.

Added: 9/29/2025 Remediate by: 10/20/2025
Remediation overdue CVE-2025-59689

Libraesva Email Security Gateway Command Injection Vulnerability

Libraesva — Email Security Gateway

Libraesva's Email Security Gateway contains a command injection flaw that can be triggered simply by sending a specially crafted compressed email attachment. Because the attack vector is email itself — the core function this product is designed to process — every inbound message is a potential delivery mechanism. Successful exploitation could allow an attacker to execute arbitrary commands on the gateway, potentially compromising the security appliance meant to protect the organization's email infrastructure.

Patch available

Next step: Review and apply the guidance published in Libraesva's official security advisory at https://docs.libraesva.com/knowledgebase/security-advisory-command-injection-vulnerability-cve-2025-59689/ immediately; if mitigations or patches are unavailable or cannot be applied, consider discontinuing use of the product as directed by CISA.

Added: 9/29/2025 Remediate by: 10/20/2025
Remediation overdue CVE-2025-20333

Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Buffer Overflow Vulnerability

Cisco — Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense

This buffer overflow flaw in Cisco's ASA and FTD VPN web server allows an unauthenticated remote attacker to execute arbitrary code on affected devices — essentially taking control of the firewall itself. The risk is compounded because it can be chained with a second vulnerability, CVE-2025-20362, potentially enabling more complex or reliable attacks. Perimeter security devices like these are high-value targets, and remote code execution at this layer can expose entire internal networks.

Patch available

Next step: Review and apply guidance from Cisco's official security advisory at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-z5xP8EUB immediately, and follow any additional steps outlined in CISA Emergency Directive ED 25-03.

Added: 9/25/2025 Remediate by: 9/26/2025
Remediation overdue CVE-2025-20362

Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Missing Authorization Vulnerability

Cisco — Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense

This vulnerability in Cisco's ASA and FTD products allows attackers to bypass authorization controls in the VPN web server component. Its real danger is amplified because it can be chained with a second vulnerability (CVE-2025-20333), meaning attackers could combine the two flaws to achieve a more severe exploit than either vulnerability allows alone. Organizations running ASA or FTD for remote access VPN are potentially exposed to unauthorized access to protected resources.

Patch available

Next step: Review and apply guidance from the Cisco security advisory at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-YROOTUW, and follow CISA's Emergency Directive ED 25-03 mitigation steps as required.

Added: 9/25/2025 Remediate by: 9/26/2025
Remediation overdue CVE-2025-10585

Google Chromium V8 Type Confusion Vulnerability

Google — Chromium V8

This type confusion flaw in Chrome's V8 JavaScript engine means an attacker can craft malicious web content that causes V8 to misinterpret the type of a data object, potentially leading to arbitrary code execution within the browser. Because V8 processes JavaScript on virtually every website, any user browsing with an unpatched version of Chrome is potentially exposed simply by visiting a compromised or attacker-controlled page. The practical risk is high: successful exploitation could compromise the user's system with no additional user interaction beyond normal browsing.

Patch available

Next step: Review and apply the update detailed in Google's stable channel advisory at https://chromereleases.googleblog.com/2025/09/stable-channel-update-for-desktop_17.html to ensure all Chromium-based browsers in your environment are running the patched version.

Added: 9/23/2025 Remediate by: 10/14/2025
Remediation overdue CVE-2025-5086

Dassault Systèmes DELMIA Apriso Deserialization of Untrusted Data Vulnerability

Dassault Systèmes — DELMIA Apriso

DELMIA Apriso, a manufacturing operations management platform from Dassault Systèmes, contains a deserialization vulnerability that allows remote code execution. Deserialization flaws are serious because an attacker can send crafted malicious data to the application, which then executes arbitrary code during processing — potentially giving the attacker full control of the affected system without requiring valid credentials. This type of vulnerability is especially dangerous in industrial and manufacturing environments where system availability is critical.

Patch available

Next step: Consult the Dassault Systèmes security advisories page at https://www.3ds.com/vulnerability/advisories for patch or remediation details, and apply any available fixes per vendor instructions immediately.

Added: 9/11/2025 Remediate by: 10/2/2025
Remediation overdue CVE-2025-38352

Linux Kernel Time-of-Check Time-of-Use (TOCTOU) Race Condition Vulnerability

Linux — Kernel

This Linux kernel vulnerability involves a race condition where an attacker can exploit the gap between when a resource is checked and when it is actually used. Because it affects the kernel itself, successful exploitation can compromise the entire system — impacting confidentiality (data exposure), integrity (data or system tampering), and availability (denial of service or crashes). Any system running a vulnerable kernel version is potentially at risk, making this a high-priority concern for Linux-based infrastructure.

Patch available

Next step: Apply the patch available in the Linux stable kernel repository at https://git.kernel.org/stable/c/2c72fe18cc5f9f1750f5bc148cf1c94c29e106ff as soon as possible, following your distribution's standard kernel update process.

Added: 9/4/2025 Remediate by: 9/25/2025
Remediation overdue CVE-2025-48543

Android Runtime Use-After-Free Vulnerability

Android — Runtime

This use-after-free flaw in Android's Runtime component is particularly dangerous because it can enable a Chrome sandbox escape — meaning an attacker who has already compromised the browser's sandboxed environment could break out and gain elevated privileges on the underlying device. Sandbox escapes are a critical class of vulnerability because they defeat a key layer of defense designed to contain browser-based attacks, potentially giving attackers broader control over the affected Android device.

Patch available

Next step: Apply the patch referenced in the Android Security Bulletin for September 2025 (source.android.com/security/bulletin/2025-09-01) and the corresponding code fix in Android's ART repository as soon as it is available through your device's update channel.

Added: 9/4/2025 Remediate by: 9/25/2025
Remediation overdue CVE-2025-53690

Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability

Sitecore — Multiple Products

Sitecore's XM, XP, XC, and Managed Cloud products ship with default ASP.NET machine keys that attackers can exploit to deserialize malicious data. Because machine keys are used to validate and decrypt data like view state and cookies, knowing these keys lets an unauthenticated attacker craft payloads the server will blindly process, resulting in remote code execution. Any internet-exposed Sitecore instance using default keys is effectively wide open to full server compromise.

Patch available

Next step: Review and apply the guidance in Sitecore's official knowledge base article at https://support.sitecore.com/kb?id=kb_article_view&sysparm_article=KB1003865 immediately, as no standalone patch has been identified in the available data.

Added: 9/4/2025 Remediate by: 9/25/2025
Remediation overdue CVE-2023-50224

TP-Link TL-WR841N Authentication Bypass by Spoofing Vulnerability

TP-Link — TL-WR841N

The TP-Link TL-WR841N router contains a flaw in its built-in web server (httpd) that allows an attacker to bypass authentication through spoofing, potentially exposing credentials stored on the device. Because this service listens on TCP port 80 by default, the attack surface is the router's standard management interface. This is especially concerning because the device may be at end-of-life, meaning no vendor-supported fix is likely forthcoming.

No patch reference found

Next step: No patch or vendor advisory is available for this vulnerability. CISA explicitly notes the device may be end-of-life or end-of-service, and recommends discontinuing use of the product entirely.

Added: 9/3/2025 Remediate by: 9/24/2025
Remediation overdue CVE-2025-9377

TP-Link Archer C7(EU) and TL-WR841N/ND(MS) OS Command Injection Vulnerability

TP-Link — Multiple Routers

TP-Link Archer C7(EU) and TL-WR841N/ND(MS) routers contain an OS command injection flaw in the Parental Control page, meaning an attacker who can reach that interface could execute arbitrary operating system commands on the device. Because these products are likely end-of-life or end-of-service, TP-Link may not issue a patch, leaving the vulnerability permanently unresolved. Compromised routers can be used to intercept traffic, pivot into internal networks, or join botnets.

Patch available

Next step: No patch has been identified for these end-of-life devices; consult the TP-Link advisory at https://www.tp-link.com/us/support/faq/4365/ and discontinue use of the affected routers, replacing them with supported hardware.

Added: 9/3/2025 Remediate by: 9/24/2025
Remediation overdue CVE-2020-24363

TP-link TL-WA855RE Missing Authentication for Critical Function Vulnerability

TP-Link — TL-WA855RE

This vulnerability in the TP-Link TL-WA855RE range extender allows anyone on the same network to send an unauthenticated request that factory-resets the device. Once reset, an attacker can set a new admin password and take full control. Because no login is required to trigger the reset, any network user — or attacker who has gained local network access — can effectively seize administrative ownership of the device, disrupting connectivity and potentially pivoting further into the network.

No patch reference found

Next step: No patch or vendor advisory is available for this vulnerability, and CISA indicates the product may be end-of-life or end-of-service. The recommended action is to discontinue use of the TL-WA855RE and replace it with a supported device.

Added: 9/2/2025 Remediate by: 9/23/2025
Remediation overdue CVE-2025-55177

Meta Platforms WhatsApp Incorrect Authorization Vulnerability

Meta Platforms — WhatsApp

This flaw in WhatsApp's linked device feature means an attacker who is not connected to a victim's account could still trick the victim's device into fetching and processing content from an arbitrary URL. Because linked device synchronization is a core WhatsApp feature, exploitation doesn't require any special relationship with the target. If that fetched content triggers further processing, the practical risk includes potential data exposure or code execution depending on how WhatsApp handles the retrieved content.

Patch available

Next step: Review Meta's official security advisory at https://www.facebook.com/security/advisories/cve-2025-55177 and apply any patch or update provided by Meta Platforms for WhatsApp; no standalone patch reference has been identified yet, so monitoring that advisory for updates is critical.

Added: 9/2/2025 Remediate by: 9/23/2025
Remediation overdue CVE-2025-57819

Sangoma FreePBX Authentication Bypass Vulnerability

Sangoma — FreePBX

This vulnerability in Sangoma FreePBX allows unauthenticated attackers to bypass the login process entirely due to improper sanitization of user-supplied data. Once inside, an attacker can manipulate the underlying database and execute arbitrary code remotely. For organizations running FreePBX — a widely used open-source PBX management platform — this means full system compromise is possible without any valid credentials, making it a critical risk to phone infrastructure and potentially broader network environments.

Patch available

Next step: Review and apply the guidance provided in the FreePBX community security advisory at https://community.freepbx.org/t/security-advisory-please-lock-down-your-administrator-access/107203 and the GitHub security advisory at https://github.com/FreePBX/security-reporting/security/advisories/GHSA-m42g-xg4c-5f3h immediately, as no formal patch reference was identified in available data.

Interim mitigation: The vendor's security advisory explicitly references locking down administrator access as a compensating control; consult the GitHub advisory at https://github.com/FreePBX/security-reporting/security/advisories/GHSA-m42g-xg4c-5f3h for specific interim steps while a full patch is awaited.

Added: 8/29/2025 Remediate by: 9/19/2025
Remediation overdue CVE-2025-7775

Citrix NetScaler Memory Overflow Vulnerability

Citrix — NetScaler

Citrix NetScaler ADC and NetScaler Gateway contain a memory overflow vulnerability that remote attackers could exploit to execute arbitrary code or crash affected systems. These are widely deployed network appliances controlling application delivery and VPN access, meaning a successful attack could give adversaries deep access to internal networks or knock out critical connectivity. CISA has added this to the Known Exploited Vulnerabilities catalog, signaling confirmed real-world exploitation.

Patch available

Next step: Review and apply the guidance in Citrix's official advisory at https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX694938 immediately, and follow any patch or update instructions provided there.

Added: 8/26/2025 Remediate by: 8/28/2025
Remediation overdue CVE-2024-8068

Citrix Session Recording Improper Privilege Management Vulnerability

Citrix — Session Recording

This vulnerability in Citrix Session Recording allows an authenticated attacker — already a member of the same Active Directory domain as the session recording server — to escalate their privileges to the NetworkService Account level. While the attacker must already have domain credentials, gaining NetworkService access can open pathways to broader system compromise, making this a meaningful risk in enterprise environments where Citrix Session Recording is deployed.

Patch available

Next step: Review and apply the guidance provided in Citrix's official security bulletin at https://support.citrix.com/s/article/CTX691941-citrix-session-recording-security-bulletin-for-cve20248068-and-cve20248069 as soon as possible.

Added: 8/25/2025 Remediate by: 9/15/2025
Remediation overdue CVE-2024-8069

Citrix Session Recording Deserialization of Untrusted Data Vulnerability

Citrix — Session Recording

Citrix Session Recording is vulnerable to deserialization of untrusted data, allowing an authenticated attacker on the same internal network to execute remote code with NetworkService Account privileges. While the attacker must already have internal network access and valid credentials — limiting the attack surface — successful exploitation could give an adversary a persistent foothold with system-level service privileges, enabling lateral movement or further compromise of recorded session data.

Patch available

Next step: Review and apply the guidance in Citrix's official security bulletin at https://support.citrix.com/s/article/CTX691941-citrix-session-recording-security-bulletin-for-cve20248068-and-cve20248069 immediately, and follow BOD 22-01 guidance if the product is cloud-hosted.

Added: 8/25/2025 Remediate by: 9/15/2025
Remediation overdue CVE-2025-48384

Git Link Following Vulnerability

Git — Git

This vulnerability in Git involves inconsistent handling of carriage return characters in configuration files, which can be exploited to perform link following attacks. In practice, this could allow an attacker to manipulate how Git resolves paths or configuration entries, potentially leading to unauthorized access to files outside intended directories. Any organization using Git for source control — including CI/CD pipelines and development workflows — is at risk if running an affected version.

Patch available

Next step: Review and apply the guidance published in the official Git security advisory at https://github.com/git/git/security/advisories/GHSA-vwqx-4fm8-6qc9, as no standalone patch reference was identified in the available data.

Added: 8/25/2025 Remediate by: 9/15/2025
Remediation overdue CVE-2025-43300

Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability

Apple — iOS, iPadOS, and macOS

An out-of-bounds write flaw in Apple's Image I/O framework — the component responsible for processing image files across iOS, iPadOS, and macOS — could allow an attacker to corrupt memory by crafting a malicious image. This class of vulnerability is serious because image parsing happens automatically in many contexts (email previews, web browsing, messaging apps), meaning exploitation may require little or no user interaction beyond viewing a file.

Patch available

Next step: Review and apply the updates detailed in Apple's official security advisory at https://support.apple.com/en-us/124925 as soon as possible.

Added: 8/21/2025 Remediate by: 9/11/2025
Remediation overdue CVE-2025-54948

Trend Micro Apex One OS Command Injection Vulnerability

Trend Micro — Apex One

This vulnerability in Trend Micro Apex One's on-premise management console allows a remote attacker to inject and execute OS commands without needing to log in first. Pre-authentication exploitation is particularly serious because it requires no credentials or user interaction — an attacker with network access to the console can potentially take full control of the system, making this a high-priority risk for any organization running the affected software.

Patch available

Next step: Apply the vendor-supplied patch immediately by following the guidance at https://success.trendmicro.com/en-US/solution/KA-0020652.

Added: 8/18/2025 Remediate by: 9/8/2025
Remediation overdue CVE-2025-8875

N-able N-Central Insecure Deserialization Vulnerability

N-able — N-Central

N-able N-Central is a remote monitoring and management platform widely used by managed service providers to oversee client infrastructure. An insecure deserialization flaw means an attacker can craft malicious serialized data that, when processed by the application, triggers arbitrary command execution on the server. Because N-Central typically has broad, privileged access to managed endpoints, a successful exploit could cascade across every client environment the platform manages — making this a high-value target.

No patch reference found

Next step: As of this writing, no vendor patch or official advisory has been published; administrators should check N-able's support portal and security advisories page directly and frequently, and be prepared to discontinue use of the product if mitigations remain unavailable.

Added: 8/13/2025 Remediate by: 8/20/2025
Remediation overdue CVE-2025-8876

N-able N-Central Command Injection Vulnerability

N-able — N-Central

N-able N-Central is a widely used remote monitoring and management platform deployed by managed service providers to oversee many client environments simultaneously. A command injection flaw caused by improper sanitization of user input means an attacker who can supply malicious input may execute arbitrary operating system commands on the underlying server. Because N-Central typically holds privileged access to numerous downstream customer networks, a successful exploit could cascade into broad, multi-organization compromise.

No patch reference found

Next step: As of this writing, no patch or vendor advisory has been publicly identified for this vulnerability. Organizations using N-able N-Central should monitor N-able's official security channels urgently for a patch or advisory, and consider whether continued operation of the product is acceptable given the absence of available mitigations.

Added: 8/13/2025 Remediate by: 8/20/2025
Remediation overdue CVE-2007-0671

Microsoft Office Excel Remote Code Execution Vulnerability

Microsoft — Office

This vulnerability in Microsoft Office Excel allows an attacker to execute arbitrary code on a victim's machine simply by getting them to open a malicious Excel file. Delivery methods include email attachments or drive-by downloads from compromised websites. Because code execution happens at the user's privilege level, a successful exploit could give an attacker full control of the affected system, making this a high-risk threat for any organization using the affected Excel version.

Patch available

Next step: No official Microsoft patch reference was identified in the source data; administrators should consult the Secunia advisory at http://secunia.com/advisories/24008 for available guidance, and consider discontinuing use of the affected product if no mitigation can be applied.

Added: 8/12/2025 Remediate by: 9/2/2025
Remediation overdue CVE-2013-3893

Microsoft Internet Explorer Resource Management Errors Vulnerability

Microsoft — Internet Explorer

This vulnerability in Microsoft Internet Explorer allows attackers to corrupt memory and execute arbitrary code remotely — meaning a user simply visiting a malicious website could give an attacker full control of their system. Because Internet Explorer is likely end-of-life or end-of-service in the affected versions, Microsoft will not issue further patches, leaving any remaining users permanently exposed. Organizations still running these IE versions face serious, unmitigated risk.

Patch available

Next step: Because the affected Internet Explorer versions are likely end-of-life with no patch available, the most critical step is to immediately discontinue use of the product and migrate to a supported browser, per CISA's guidance.

Added: 8/12/2025 Remediate by: 9/2/2025
Ransomware use CVE-2025-8088

RARLAB WinRAR Path Traversal Vulnerability

RARLAB — WinRAR

WinRAR, one of the most widely used archive utilities on Windows, contains a path traversal flaw that lets attackers craft malicious archive files capable of executing arbitrary code when opened. This vulnerability is already being exploited in ransomware campaigns, meaning real-world attackers are actively weaponizing it against organizations. Any user or system that opens a booby-trapped archive could trigger a full compromise without any other interaction required.

No patch reference found

Next step: As of this writing, no official patch or vendor advisory from RARLAB has been published; if no patch becomes available, organizations should consider discontinuing use of WinRAR until one is released, per CISA guidance.

Interim mitigation: A third-party mitigation guide references using Windows Software Restriction Policies (SRP) and Image File Execution Options (IFEO) as compensating controls to reduce exposure while no official patch exists; see https://www.vicarius.io/vsociety/posts/cve-2025-8088-mitigate-winrar-zero-day-using-srp-and-ifeo for details.

Added: 8/12/2025 Remediate by: 9/2/2025
Remediation overdue CVE-2020-25078

D-Link DCS-2530L and DCS-2670L Devices Unspecified Vulnerability

D-Link — DCS-2530L and DCS-2670L Devices

This vulnerability in D-Link DCS-2530L and DCS-2670L IP cameras allows remote attackers to obtain the administrator password without authentication. Since these are network-connected cameras, exploitation could give an attacker full administrative control, enabling surveillance feed access, device reconfiguration, or use of the camera as a foothold for further network attacks. The risk is compounded by the fact that these products are likely end-of-life, meaning D-Link may no longer provide ongoing security support.

Patch available

Next step: Review the D-Link security advisory at https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10180 for any available patches; if the devices are confirmed end-of-life with no patch available, discontinue use and replace them immediately.

Added: 8/5/2025 Remediate by: 8/26/2025
Remediation overdue CVE-2020-25079

D-Link DCS-2530L and DCS-2670L Command Injection Vulnerability

D-Link — DCS-2530L and DCS-2670L Devices

This vulnerability allows attackers to inject arbitrary operating system commands through the cgi-bin/ddns_enc.cgi interface on D-Link DCS-2530L and DCS-2670L IP cameras. Successful exploitation could give an attacker control over the device, potentially enabling surveillance access, network pivoting, or use in botnets. These devices are likely end-of-life or end-of-service, meaning ongoing vendor security support may no longer exist, making any deployment a persistent risk.

Patch available

Next step: Review the D-Link support announcement at https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10180 for available guidance, and strongly consider discontinuing use of affected devices, as they are potentially end-of-life with no guarantee of continued patching.

Added: 8/5/2025 Remediate by: 8/26/2025
Remediation overdue CVE-2022-40799

D-Link DNR-322L Download of Code Without Integrity Check Vulnerability

D-Link — DNR-322L

The D-Link DNR-322L network video recorder contains a flaw where firmware or code can be downloaded and executed without verifying its integrity. An authenticated attacker can exploit this to run arbitrary OS-level commands on the device, effectively taking full control. Because this product is likely end-of-life or end-of-service, D-Link is not expected to release a patch, leaving any deployed unit permanently exposed to this serious command execution risk.

No patch reference found

Next step: No patch or vendor advisory exists for this vulnerability. Because the D-Link DNR-322L is likely end-of-life or end-of-service, CISA explicitly recommends discontinuing use of the product immediately.

Added: 8/5/2025 Remediate by: 8/26/2025
Remediation overdue CVE-2023-2533

PaperCut NG/MF Cross-Site Request Forgery (CSRF) Vulnerability

PaperCut — NG/MF

This vulnerability in PaperCut NG/MF allows an attacker to forge requests on behalf of an authenticated user, potentially tricking them into unknowingly changing security settings or triggering arbitrary code execution. Print management software typically runs with elevated privileges across an organization, making this especially dangerous — a successful exploit could hand an attacker significant control over managed systems under the right conditions.

Patch available

Next step: Review and apply the guidance published in PaperCut's June 2023 security bulletin at https://www.papercut.com/kb/Main/SecurityBulletinJune2023 immediately.

Added: 7/28/2025 Remediate by: 8/18/2025
Remediation overdue CVE-2025-20281

Cisco Identity Services Engine Injection Vulnerability

Cisco — Identity Services Engine

Cisco Identity Services Engine (ISE) is a widely deployed network access control and policy platform. This vulnerability allows an unauthenticated attacker to send a specially crafted API request that bypasses input validation, resulting in remote code execution with root-level privileges. Because ISE controls network authentication and authorization decisions, a full compromise could give attackers the ability to manipulate access policies, move laterally, or pivot into broader network infrastructure.

Patch available

Next step: Review and apply the guidance detailed in Cisco's official security advisory at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-unauth-rce-ZAd2GnJ6 immediately, as this is the only remediation reference currently available.

Added: 7/28/2025 Remediate by: 8/18/2025
Remediation overdue CVE-2025-20337

Cisco Identity Services Engine Injection Vulnerability

Cisco — Identity Services Engine

Cisco Identity Services Engine (ISE) is a widely deployed network access control platform. This vulnerability allows an unauthenticated attacker to send a specially crafted API request that bypasses input validation, execute arbitrary code remotely, and ultimately gain root-level control of the device. Because ISE acts as a central policy and authentication hub, a full compromise could give attackers broad access to network resources and user credentials across the organization.

Patch available

Next step: Review and apply the guidance in Cisco's official security advisory at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-unauth-rce-ZAd2GnJ6 immediately, as this vulnerability enables unauthenticated remote code execution with root privileges.

Added: 7/28/2025 Remediate by: 8/18/2025
Remediation overdue CVE-2025-2775

SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability

SysAid — SysAid On-Prem

SysAid On-Prem's check-in processing functionality fails to properly restrict XML External Entity (XXE) references, a class of vulnerability where an attacker can manipulate XML parsing to access files on the server or trigger actions it shouldn't. In this case, exploitation can lead to full administrator account takeover and the ability to read arbitrary files — meaning an attacker could seize control of the SysAid platform and exfiltrate sensitive data from the underlying system.

No patch reference found

Next step: No vendor advisory or patch reference is currently available in public sources; organizations running SysAid On-Prem should contact SysAid directly for remediation guidance and consider whether continued operation of the product is acceptable given the unpatched administrator takeover risk.

Added: 7/22/2025 Remediate by: 8/12/2025
Remediation overdue CVE-2025-2776

SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability

SysAid — SysAid On-Prem

SysAid On-Prem's Server URL processing functionality fails to properly restrict XML External Entity (XXE) references, a class of vulnerability that lets attackers manipulate how the application parses XML input. In this case, exploitation can lead to full administrator account takeover and the ability to read arbitrary files from the server. Any organization running SysAid on-premises is at risk of complete system compromise through this flaw, making it a critical priority.

No patch reference found

Next step: No vendor patch or advisory has been publicly identified at this time. Organizations should check directly with SysAid for available fixes or guidance, and seriously evaluate discontinuing use of the affected on-premises product until a patch is confirmed available and applied.

Added: 7/22/2025 Remediate by: 8/12/2025
Ransomware use CVE-2025-49704

Microsoft SharePoint Code Injection Vulnerability

Microsoft — SharePoint

This SharePoint code injection flaw lets an authenticated attacker execute arbitrary code across the network — no physical access required. It has been exploited in ransomware attacks and can be chained with a second vulnerability (CVE-2025-49706) to amplify impact. A patch bypass (CVE-2025-53770) also exists, meaning the original fix alone is insufficient; organizations must apply the newer, more robust update that addresses both the original flaw and the bypass.

Patch available

Next step: Apply the updated patch that addresses CVE-2025-53770, which provides more robust protection than the original CVE-2025-49704 fix and supersedes it; refer to the Microsoft Security Response Center advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-49704 for patch details. Additionally, immediately disconnect any public-facing SharePoint Server instances running end-of-life versions such as SharePoint Server 2013 and earlier.

Added: 7/22/2025 Remediate by: 7/23/2025
Ransomware use CVE-2025-49706

Microsoft SharePoint Improper Authentication Vulnerability

Microsoft — SharePoint

This Microsoft SharePoint flaw lets an authenticated attacker impersonate other users over a network, potentially exposing sensitive data and allowing unauthorized modifications. It has been used in ransomware attacks, making it high priority. It can be chained with CVE-2025-49704 to amplify impact, and a patch bypass (CVE-2025-53771) already exists, meaning the original fix alone may be insufficient — the newer update for CVE-2025-53771 is described as providing stronger protection.

Patch available

Next step: Apply Microsoft's update for CVE-2025-53771, which supersedes and provides more robust protection than the original patch for CVE-2025-49706; refer to the Microsoft Security Response Center advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-49706 and follow CISA's guidance. Immediately disconnect any public-facing SharePoint Server instances running end-of-life versions (SharePoint Server 2013 and earlier).

Added: 7/22/2025 Remediate by: 7/23/2025
Remediation overdue CVE-2025-54309

CrushFTP Unprotected Alternate Channel Vulnerability

CrushFTP — CrushFTP

CrushFTP's DMZ proxy feature, when not in use, fails to properly validate AS2 protocol requests over HTTPS. This allows unauthenticated remote attackers to gain full administrator access to the CrushFTP server without any credentials. Admin-level access means an attacker can read, modify, or exfiltrate any data managed by the file transfer server, making this a critical exposure for organizations using CrushFTP for business file exchange.

Patch available

Next step: Review the vendor advisory at https://www.crushftp.com/crush11wiki/Wiki.jsp?page=CompromiseJuly2025 and apply any patches or configuration changes detailed there immediately, as no standalone patch reference has been separately confirmed in current catalog data.

Added: 7/22/2025 Remediate by: 8/12/2025
Remediation overdue CVE-2025-6558

Google Chromium ANGLE and GPU Improper Input Validation Vulnerability

Google — Chromium

This vulnerability in Chromium's ANGLE graphics layer and GPU handling allows a remote attacker to escape the browser sandbox simply by luring a user to a malicious webpage. A successful sandbox escape means attacker-controlled code can break out of the browser's isolation and potentially execute on the underlying operating system. Because the flaw lives in shared Chromium code, Chrome, Edge, Opera, and other Chromium-based browsers are all affected, making the attack surface very broad.

No patch reference found

Next step: No vendor advisory or patch reference is currently available in the source data; until an official fix is published, organizations should be aware that no verified remediation has been confirmed and should monitor vendor channels for an update.

Added: 7/22/2025 Remediate by: 8/12/2025
Ransomware use CVE-2025-53770

Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

Microsoft — SharePoint

This critical SharePoint Server flaw lets an unauthenticated attacker execute arbitrary code over the network by exploiting how SharePoint processes untrusted serialized data. It bypasses a previously issued patch (CVE-2025-49704), meaning organizations that already applied that fix are not fully protected. It can be chained with a second vulnerability (CVE-2025-53771) to amplify impact, and it is already being used in ransomware attacks, making rapid action essential for any organization running on-premises SharePoint.

Patch available

Next step: Immediately follow vendor and CISA mitigation guidance — consult the Microsoft Security Response Center advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53770 and the accompanying customer guidance blog post — and disconnect any public-facing SharePoint Server instances running end-of-life versions (SharePoint Server 2013 and earlier) from the network.

Interim mitigation: CISA and Microsoft have published specific interim mitigations for supported SharePoint Server versions at https://msrc.microsoft.com/blog/2025/07/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770/; organizations should follow those instructions precisely. SharePoint Server 2013 and earlier (EOL/EOS) must be disconnected from public-facing networks as no supported remediation path exists for those versions.

Added: 7/20/2025 Remediate by: 7/21/2025
Remediation overdue CVE-2025-25257

Fortinet FortiWeb SQL Injection Vulnerability

Fortinet — FortiWeb

This vulnerability in Fortinet FortiWeb allows an unauthenticated attacker to inject malicious SQL code through crafted HTTP or HTTPS requests, meaning no login credentials are required to exploit it. A successful attack could allow an adversary to read, modify, or delete database contents, potentially exposing sensitive configuration data or credentials. Because FortiWeb is a web application firewall, compromise could undermine protections it provides to downstream applications.

Patch available

Next step: Review and apply the guidance published in Fortinet's official security advisory at https://fortiguard.fortinet.com/psirt/FG-IR-25-151 immediately, as this is the vendor's authoritative source for patching and remediation instructions.

Added: 7/18/2025 Remediate by: 8/8/2025
Remediation overdue CVE-2025-47812

Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerability

Wing FTP Server — Wing FTP Server

Wing FTP Server fails to properly handle null bytes in user session files, allowing an attacker to inject arbitrary Lua code into those files. Because the FTP service typically runs as root on Linux or SYSTEM on Windows, successful exploitation gives an attacker full system-level command execution — effectively complete control of the host. Any organization running Wing FTP Server should treat this as a critical-severity, actively tracked vulnerability requiring immediate attention.

No patch reference found

Next step: No official vendor patch or advisory has been published at this time. If your organization cannot discontinue use of Wing FTP Server, consult CISA's BOD 22-01 guidance and monitor for a vendor-issued fix; do not assume the product is safe to operate in its current state.

Interim mitigation: A third-party mitigation script has been published by Vicarius at https://www.vicarius.io/vsociety/posts/cve-2025-47812-mitigation-script-remote-code-execution-vulnerability-in-wing-ftp-server, which administrators can review and consider applying as a compensating control until an official vendor patch is available.

Added: 7/14/2025 Remediate by: 8/4/2025
Ransomware use CVE-2025-5777

Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability

Citrix — NetScaler ADC and Gateway

Citrix NetScaler ADC and Gateway contain a flaw where insufficient input validation allows an attacker to read memory beyond intended boundaries. This affects appliances configured as VPN virtual servers, ICA Proxy, CVPN, RDP Proxy, or AAA virtual servers — common enterprise remote-access configurations. The vulnerability is actively being exploited by ransomware operators, meaning real-world attacks are already underway against organizations using these widely deployed network gateway products.

Patch available

Next step: Review and apply the guidance in Citrix's official advisory at https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX693420 immediately, as this vulnerability is confirmed to be in active ransomware use.

Added: 7/10/2025 Remediate by: 7/11/2025
Remediation overdue CVE-2014-3931

Multi-Router Looking Glass (MRLG) Buffer Overflow Vulnerability

Looking Glass — Multi-Router Looking Glass (MRLG)

Multi-Router Looking Glass (MRLG) contains a buffer overflow flaw that lets remote attackers write arbitrary data to memory and corrupt it. Tools like MRLG are commonly used by network operators to run diagnostic queries against routers, meaning they often sit in sensitive network infrastructure environments. A successful exploit could destabilize systems or enable further compromise, and the vulnerability has existed since 2014, giving attackers a long window of exposure.

No patch reference found

Next step: No patch or vendor advisory has been identified for this vulnerability. If your organization runs MRLG, you should evaluate whether continued use can be justified and consider discontinuing the product if no vendor-supplied fix is available.

Added: 7/7/2025 Remediate by: 7/28/2025
Remediation overdue CVE-2016-10033

PHPMailer Command Injection Vulnerability

PHP — PHPMailer

PHPMailer is one of the most widely used email-sending libraries in PHP applications. This vulnerability allows attackers to inject operating system commands through unsanitized user input passed to PHP's mail() function, meaning a malicious actor could execute arbitrary code on the server hosting the application — effectively taking control of it. Any web application using a vulnerable version of PHPMailer that accepts user-supplied data (such as contact forms) is at risk.

Patch available

Next step: Update PHPMailer to version 5.2.18 or later immediately, as a patched release is available at the official GitHub releases page (https://github.com/PHPMailer/PHPMailer/releases/tag/v5.2.18).

Added: 7/7/2025 Remediate by: 7/28/2025
Remediation overdue CVE-2019-5418

Rails Ruby on Rails Path Traversal Vulnerability

Rails — Ruby on Rails

This Rails vulnerability lets an attacker read arbitrary files from a server by sending a specially crafted HTTP Accept header when the application uses 'render file:'. Because web servers routinely expose sensitive system files, an unauthenticated attacker could potentially retrieve credentials, configuration data, or other critical content without any authentication. Any Rails application using that rendering pattern is at risk of full file-system disclosure, making this a serious data-exposure threat.

Patch available

Next step: Apply the patched Rails versions released by the vendor — 4.2.11.1, 5.1.6.2, or later — as detailed in the official Rails blog advisory at https://weblog.rubyonrails.org/2019/3/13/Rails-4-2-5-1-5-1-6-2-have-been-released/.

Interim mitigation: Interim mitigation details are referenced in the Openwall oss-security disclosure at http://www.openwall.com/lists/oss-security/2019/03/22/1; review that posting for any compensating controls applicable to your environment while patching is underway.

Added: 7/7/2025 Remediate by: 7/28/2025
Remediation overdue CVE-2019-9621

Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery (SSRF) Vulnerability

Synacor — Zimbra Collaboration Suite (ZCS)

This vulnerability in Zimbra Collaboration Suite's ProxyServlet component allows an attacker to forge server-side requests, meaning the Zimbra server can be manipulated into making HTTP requests on an attacker's behalf. This can expose internal network resources, bypass access controls, or allow attackers to pivot deeper into an organization's infrastructure — particularly dangerous given how widely ZCS is used as enterprise email and collaboration infrastructure.

Patch available

Next step: Review and apply the guidance provided in the Zimbra vendor advisory at https://blog.zimbra.com/2019/03/9826/ to address this SSRF vulnerability in affected ZCS installations.

Added: 7/7/2025 Remediate by: 7/28/2025
Remediation overdue CVE-2025-6554

Google Chromium V8 Type Confusion Vulnerability

Google — Chromium V8

This vulnerability in Chrome's V8 JavaScript engine lets a remote attacker perform arbitrary memory reads and writes simply by luring a user to a malicious web page. Because V8 is the engine shared across Chromium-based browsers — including Chrome, Edge, and Opera — the exposure is broad. Arbitrary read/write primitives are typically the foundation for full browser exploitation, meaning an attacker could potentially escape the browser sandbox and compromise the underlying system.

Patch available

Next step: Apply the updated build referenced in Google's stable channel release advisory at https://chromereleases.googleblog.com/2025/06/stable-channel-update-for-desktop_30.html — update all Chromium-based browsers (Chrome, Edge, Opera, etc.) to the patched version immediately.

Added: 7/2/2025 Remediate by: 7/23/2025
Remediation overdue CVE-2025-48927

TeleMessage TM SGNL Initialization of a Resource with an Insecure Default Vulnerability

TeleMessage — TM SGNL

TeleMessage TM SGNL ships with Spring Boot Actuator misconfigured so that its heap dump endpoint is publicly reachable at /heapdump. An attacker who can reach that URI can download a snapshot of the application's memory, which may contain credentials, session tokens, encryption keys, and sensitive message content. Because TM SGNL is a secure messaging application, exposure of heap memory is especially damaging — defeating the confidentiality guarantees users rely on.

No patch reference found

Next step: No patch or vendor advisory has been published at this time. If your organization uses TeleMessage TM SGNL, CISA's required action states to apply vendor mitigations when available or discontinue use of the product if mitigations remain unavailable.

Added: 7/1/2025 Remediate by: 7/22/2025
Remediation overdue CVE-2025-48928

TeleMessage TM SGNL Exposure of Core Dump File to an Unauthorized Control Sphere Vulnerability

TeleMessage — TM SGNL

TeleMessage TM SGNL, a modified Signal-like messaging app, exposes heap memory through a JSP application in a way that functions like a core dump. Because the app transmits passwords over HTTP, those plaintext credentials end up captured in this dump and become accessible to unauthorized parties. This means attackers who can reach that exposed endpoint could harvest account passwords, potentially compromising communications and connected systems well beyond the messaging app itself.

No patch reference found

Next step: No vendor patch or advisory has been published for this vulnerability. Organizations should discontinue use of TeleMessage TM SGNL until the vendor issues a remediated version and advisory, as CISA's own guidance notes discontinuing use if mitigations are unavailable.

Added: 7/1/2025 Remediate by: 7/22/2025
Remediation overdue CVE-2025-6543

Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerability

Citrix — NetScaler ADC and Gateway

This buffer overflow flaw in Citrix NetScaler ADC and Gateway allows attackers to disrupt control flow and cause a Denial of Service, effectively taking the affected device offline. It only applies when NetScaler is configured in specific roles — as a VPN virtual server, ICA Proxy, CVPN, RDP Proxy, or AAA virtual server. For organizations relying on these devices for remote access or authentication, an outage could cut off employees or customers from critical resources.

Patch available

Next step: Review and apply vendor guidance immediately by consulting the Citrix advisory at https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX694788 for patching or remediation instructions.

Added: 6/30/2025 Remediate by: 7/21/2025
Ransomware use CVE-2019-6693

Fortinet FortiOS Use of Hard-Coded Credentials Vulnerability

Fortinet — FortiOS

FortiOS contains a hard-coded encryption key embedded in the product, meaning anyone who knows that key — including attackers — can decrypt sensitive data from FortiOS configuration backup files. Configuration backups typically contain credentials, network topology, and policy details, making this a serious exposure. The vulnerability has been linked to ransomware campaigns, meaning real-world threat actors are actively exploiting it to compromise enterprise network infrastructure.

Patch available

Next step: Review and apply the guidance provided in Fortinet's official advisory at https://fortiguard.com/advisory/FG-IR-19-007, which covers both patching and mitigation steps for this vulnerability.

Interim mitigation: Fortinet's advisory at https://fortiguard.com/advisory/FG-IR-19-007 references available mitigations; consult it directly for compensating controls applicable to your environment while remediation is planned.

Added: 6/25/2025 Remediate by: 7/16/2025
Remediation overdue CVE-2024-0769

D-Link DIR-859 Router Path Traversal Vulnerability

D-Link — DIR-859 Router

D-Link DIR-859 routers have a path traversal flaw in the hedwig.cgi handler that lets an attacker manipulate HTTP POST requests to read sensitive session data from the device. With that session information, an attacker could escalate privileges and take full unauthorized control of the router. Critically, D-Link has declared all hardware revisions of this product end-of-life or end-of-service, meaning no security patches will be issued, leaving any deployed unit permanently exposed.

Patch available

Next step: Because all DIR-859 hardware revisions have reached end-of-life and no patch is available, D-Link's guidance is to retire and replace the device immediately. Review the vendor's announcement at https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10371 for official retirement guidance.

Added: 6/25/2025 Remediate by: 7/16/2025
Remediation overdue CVE-2024-54085

AMI MegaRAC SPx Authentication Bypass by Spoofing Vulnerability

AMI — MegaRAC SPx

AMI MegaRAC SPx is a baseboard management controller (BMC) firmware used in servers from many major manufacturers. This vulnerability allows an attacker to bypass authentication through spoofing on the Redfish Host Interface — a standard API used for out-of-band server management. Because BMCs operate independently of the main OS and have deep hardware-level access, a successful exploit could give an attacker persistent, low-level control over affected servers, risking full compromise of confidentiality, integrity, and availability.

Patch available

Next step: Review and apply the guidance in AMI's official security advisory at https://go.ami.com/hubfs/Security%20Advisories/2025/AMI-SA-2025003.pdf, and contact your server OEM for firmware updates specific to your hardware.

Added: 6/25/2025 Remediate by: 7/16/2025
Remediation overdue CVE-2023-0386

Linux Kernel Improper Ownership Management Vulnerability

Linux — Kernel

This Linux kernel flaw in the OverlayFS subsystem lets a local, unprivileged user escalate to root-level privileges. By copying a setuid file with special capabilities from a nosuid-mounted filesystem into another mount, the attacker exploits a UID mapping bug to gain capabilities they should never have. This is particularly dangerous on shared systems, containers, and cloud environments where local access by untrusted users is common — a foothold becomes full system compromise.

Patch available

Next step: Apply the upstream Linux kernel patch identified by commit 4f11ada10d0a, available at the official kernel.org repository, and update to a patched kernel version provided by your Linux distribution vendor as soon as possible.

Added: 6/17/2025 Remediate by: 7/8/2025
Remediation overdue CVE-2023-33538

TP-Link Multiple Routers Command Injection Vulnerability

TP-Link — Multiple Routers

Several older TP-Link routers contain a command injection flaw in their wireless network management interface, allowing an attacker to execute arbitrary operating system commands on the device. Because these models are likely end-of-life or end-of-service, TP-Link is not expected to release patches. A compromised router gives attackers a foothold into every device on that network, making this a serious threat for any organization still running this aging hardware.

No patch reference found

Next step: No patch or vendor advisory exists for these affected TP-Link models. Because the devices are likely end-of-life or end-of-service, CISA's guidance is to discontinue use of the product immediately.

Added: 6/16/2025 Remediate by: 7/7/2025
Remediation overdue CVE-2025-43200

Apple Multiple Products Unspecified Vulnerability

Apple — Multiple Products

This vulnerability affects Apple's major platforms — iOS, iPadOS, macOS, watchOS, and visionOS — and can be triggered simply by a user opening a maliciously crafted photo or video shared through an iCloud Link. The attack surface is significant because iCloud Links are a routine sharing mechanism, meaning exploitation could occur through seemingly normal user behavior with no obvious warning signs.

Patch available

Next step: Review and apply the updates detailed in Apple's official advisory at https://support.apple.com/en-us/122173 as soon as possible across all affected Apple platforms.

Added: 6/16/2025 Remediate by: 7/7/2025
Remediation overdue CVE-2025-24016

Wazuh Server Deserialization of Untrusted Data Vulnerability

Wazuh — Wazuh Server

Wazuh is a widely deployed open-source security monitoring platform used by organizations to detect threats and manage compliance. This vulnerability allows an attacker to send maliciously crafted serialized data to a Wazuh server, which the server processes without proper validation, resulting in remote code execution. Because Wazuh servers typically hold privileged access to monitored endpoints and security event data, a successful exploit could give an attacker deep visibility into — and control over — an organization's entire monitored infrastructure.

Patch available

Next step: Review and apply the guidance published in the Wazuh security advisory at https://github.com/wazuh/wazuh/security/advisories/GHSA-hcrc-79hj-m3qh immediately, as this is a remotely exploitable code execution vulnerability in a security-critical system.

Added: 6/10/2025 Remediate by: 7/1/2025
Remediation overdue CVE-2025-33053

Microsoft Windows External Control of File Name or Path Vulnerability

Microsoft — Windows

This vulnerability in Microsoft Windows allows an attacker to craft a malicious Internet Shortcut file (.url) that references a remote WebDAV server via the WorkingDirectory attribute. When a user interacts with such a file, Windows may execute code fetched from that attacker-controlled remote location. This is a practical, user-triggered attack path — commonly delivered via phishing or malicious downloads — that could result in full code execution on the victim's machine.

Patch available

Next step: Review the Microsoft Security Response Center advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-33053 and apply any available patch or vendor-recommended fix immediately; no standalone patch reference was confirmed in the source data, so monitoring the MSRC page for updates is essential.

Interim mitigation: A mitigation script targeting this vulnerability has been referenced at https://www.vicarius.io/vsociety/posts/cve-2025-33053-mitigation-script-remote-code-execution-vulnerability-in-microsoft-webdav — administrators should review and evaluate this script as an interim compensating control while awaiting official vendor guidance.

Added: 6/10/2025 Remediate by: 7/1/2025
Remediation overdue CVE-2024-42009

RoundCube Webmail Cross-Site Scripting Vulnerability

Roundcube — Webmail

This cross-site scripting flaw in Roundcube Webmail allows an attacker to craft a malicious email that, when viewed by a victim, exploits a desanitization bug in the mail display code. The practical result is serious: an attacker can silently steal the victim's emails or send emails on their behalf without any interaction beyond opening the message. Because Roundcube is widely used in enterprise and government environments, this flaw poses a significant risk of credential theft and data exfiltration.

Patch available

Next step: Apply the security updates released by Roundcube on August 4, 2024 — versions 1.6.8 or 1.5.8 — as detailed in the vendor advisory at https://roundcube.net/news/2024/08/04/security-updates-1.6.8-and-1.5.8.

Added: 6/9/2025 Remediate by: 6/30/2025
Remediation overdue CVE-2025-32433

Erlang Erlang/OTP SSH Server Missing Authentication for Critical Function Vulnerability

Erlang — Erlang/OTP

This critical flaw in Erlang/OTP's SSH server allows attackers to run arbitrary commands on affected systems without providing any valid credentials. Because Erlang/OTP is a foundational technology embedded in products from vendors like Cisco, NetApp, and SUSE, the blast radius extends well beyond standalone Erlang deployments. Unauthenticated remote code execution means a network-accessible SSH service could be fully compromised with no prior foothold, making this a high-priority threat for any environment running Erlang/OTP.

Patch available

Next step: Apply the patch provided in the official Erlang/OTP security advisory immediately: review the fix at https://github.com/erlang/otp/security/advisories/GHSA-37cp-fgq5-7wc2 and apply the commit referenced there, and check with vendors such as Cisco, NetApp, and SUSE for product-specific updates that incorporate the fix.

Added: 6/9/2025 Remediate by: 6/30/2025
Remediation overdue CVE-2025-5419

Google Chromium V8 Out-of-Bounds Read and Write Vulnerability

Google — Chromium V8

This flaw in Google's V8 JavaScript engine allows a remote attacker to read and write outside the bounds of allocated memory, potentially corrupting the heap simply by luring a user to a malicious webpage. Because V8 is the engine powering Chrome, Edge, Opera, and other Chromium-based browsers, the attack surface is extremely broad. Successful exploitation could enable arbitrary code execution on the victim's machine with no interaction beyond visiting a crafted page.

No patch reference found

Next step: No patch or vendor advisory reference has been identified in the source data at this time; organizations should monitor Google, Microsoft, and Opera security channels closely and apply any updates as soon as they become available, or consider discontinuing use of affected Chromium-based browsers until a fix is confirmed.

Added: 6/5/2025 Remediate by: 6/26/2025
Remediation overdue CVE-2025-21479

Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability

Qualcomm — Multiple Chipsets

Multiple Qualcomm chipsets contain an incorrect authorization flaw in GPU micronodes that allows unauthorized command execution when a specific sequence of commands is processed, leading to memory corruption. Because Qualcomm chips power a vast range of Android devices and embedded systems, this vulnerability could be exploited to corrupt memory at a low hardware level, potentially enabling privilege escalation or code execution on affected devices. The broad chipset scope makes widespread exposure likely.

Patch available

Next step: Review Qualcomm's June 2025 Security Bulletin at https://docs.qualcomm.com/product/publicresources/securitybulletin/june-2025-bulletin.html and apply any patches or firmware updates provided by your device OEM as soon as they become available.

Added: 6/3/2025 Remediate by: 6/24/2025
Remediation overdue CVE-2025-21480

Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability

Qualcomm — Multiple Chipsets

Multiple Qualcomm chipsets contain a flaw where commands sent to the GPU micronode can bypass authorization checks, leading to memory corruption. An attacker who can execute a specific sequence of GPU commands could exploit this to corrupt memory, potentially gaining elevated privileges or causing system instability. Because Qualcomm chips are widely deployed across mobile devices, embedded systems, and networking hardware, the attack surface for this vulnerability is broad.

Patch available

Next step: Review and apply the guidance published in Qualcomm's June 2025 Security Bulletin at https://docs.qualcomm.com/product/publicresources/securitybulletin/june-2025-bulletin.html to identify affected chipsets and obtain available patches.

Added: 6/3/2025 Remediate by: 6/24/2025
Remediation overdue CVE-2025-27038

Qualcomm Multiple Chipsets Use-After-Free Vulnerability

Qualcomm — Multiple Chipsets

A use-after-free flaw in Qualcomm's Adreno GPU drivers can corrupt memory during graphics rendering in Chrome, potentially allowing an attacker to execute arbitrary code or crash affected systems. Because this involves widely deployed Qualcomm chipsets — common in Android devices and embedded systems — the attack surface is broad. Memory corruption vulnerabilities of this class are frequently exploitable and can lead to full device compromise if triggered through malicious web content.

Patch available

Next step: Review Qualcomm's June 2025 security bulletin at https://docs.qualcomm.com/product/publicresources/securitybulletin/june-2025-bulletin.html and apply any available patches or firmware updates provided by your device OEM as soon as possible.

Added: 6/3/2025 Remediate by: 6/24/2025
Remediation overdue CVE-2021-32030

ASUS Routers Improper Authentication Vulnerability

ASUS — Routers

This vulnerability in ASUS Lyra Mini and GT-AC2900 routers allows an attacker to bypass authentication and gain full access to the administrative interface — without valid credentials. For organizations running these devices, this means an attacker could reconfigure the router, intercept traffic, or use it as a pivot point into the broader network. CISA has flagged these products as potentially end-of-life or end-of-service, meaning patches may never arrive.

No patch reference found

Next step: No vendor patch or advisory has been published. CISA explicitly advises discontinuing use of these products; organizations still running ASUS Lyra Mini or GT-AC2900 devices should plan to replace them immediately.

Added: 6/2/2025 Remediate by: 6/23/2025
Remediation overdue CVE-2023-39780

ASUS RT-AX55 Routers OS Command Injection Vulnerability

ASUS — RT-AX55 Routers

ASUS RT-AX55 routers contain an OS command injection flaw that lets a remote attacker who has valid credentials run arbitrary operating system commands on the device. Because routers sit at the network perimeter and control traffic flow, a compromised device can expose every connected system to interception, manipulation, or further attack. The vulnerability is tracked under both CVE-2023-39780 and CVE-2023-41346, indicating it has been confirmed serious enough for CISA to add to its Known Exploited Vulnerabilities catalog.

No patch reference found

Next step: No vendor patch or official advisory has been identified for this vulnerability at this time. CISA advises applying vendor mitigations if and when available, or discontinuing use of affected ASUS RT-AX55 devices if mitigations remain unavailable.

Added: 6/2/2025 Remediate by: 6/23/2025
Remediation overdue CVE-2024-56145

Craft CMS Code Injection Vulnerability

Craft CMS — Craft CMS

Craft CMS contains a code injection flaw that allows attackers to execute arbitrary code remotely on affected servers. The vulnerability is specifically exploitable when the PHP runtime setting `register_argc_argv` is enabled in `php.ini` — a non-default but not uncommon configuration. If exploited, an attacker could gain full control of the web server environment, making this a critical risk for any organization running a vulnerable Craft CMS version with that PHP setting active.

Patch available

Next step: Apply the patch immediately by reviewing the vendor security advisory at https://github.com/craftcms/cms/security/advisories/GHSA-2p6p-9rc9-62j9 and applying the fix referenced in the associated commit at https://github.com/craftcms/cms/commit/82e893fb794d30563da296bca31379c0df0079b3.

Added: 6/2/2025 Remediate by: 6/23/2025
Remediation overdue CVE-2025-35939

Craft CMS External Control of Assumed-Immutable Web Parameter Vulnerability

Craft CMS — Craft CMS

This Craft CMS flaw lets unauthenticated attackers manipulate web parameters to write arbitrary content — including PHP code — to known file locations on the server. On its own that's serious, but it becomes critical when chained with CVE-2024-58136 (tracked as CVE-2025-32432), which can turn this file-write primitive into full remote code execution. No login is required, meaning any internet-facing Craft CMS installation is at risk of complete server compromise.

Patch available

Next step: Apply the fix referenced in the Craft CMS pull request at https://github.com/craftcms/cms/pull/17220 as soon as possible, as this vulnerability is actively catalogued by CISA and can be chained for unauthenticated remote code execution.

Added: 6/2/2025 Remediate by: 6/23/2025
Remediation overdue CVE-2025-3935

ConnectWise ScreenConnect Improper Authentication Vulnerability

ConnectWise — ScreenConnect

ConnectWise ScreenConnect has an improper authentication flaw that enables ViewState code injection attacks. If an attacker obtains or guesses the application's machine keys, they can craft malicious ViewState payloads and achieve remote code execution on the server. Because ScreenConnect is widely used for remote support and access, a compromised instance effectively hands attackers a foothold into every endpoint managed through it — making this a high-priority risk for any organization running the software.

Patch available

Next step: Review the ConnectWise security advisory at https://www.connectwise.com/company/trust/advisories and apply any vendor-issued patches or instructions immediately; if mitigations or patches are unavailable and the system cannot be adequately protected, discontinue use of the affected product.

Added: 6/2/2025 Remediate by: 6/23/2025
Remediation overdue CVE-2025-4632

Samsung MagicINFO 9 Server Path Traversal Vulnerability

Samsung — MagicINFO 9 Server

Samsung MagicINFO 9 Server, a digital signage management platform, contains a path traversal flaw that lets an unauthenticated or remote attacker write arbitrary files with system-level authority. This is severe because writing files as the system account can enable full server compromise — attackers could plant web shells, overwrite configuration files, or establish persistent backdoors — affecting any organization running digital signage infrastructure on this platform.

Patch available

Next step: Apply the patch released by Samsung in their May 2025 security update, available at https://security.samsungtv.com/securityUpdates#SVP-MAY-2025, as soon as possible.

Added: 5/22/2025 Remediate by: 6/12/2025
Remediation overdue CVE-2023-38950

ZKTeco BioTime Path Traversal Vulnerability

ZKTeco — BioTime

ZKTeco BioTime, a workforce management and time-attendance platform, contains a path traversal flaw in its iclock API. An unauthenticated attacker — meaning no credentials are required — can craft a malicious request to read arbitrary files on the underlying system. This could expose sensitive configuration files, credentials, or other data, potentially enabling further compromise of the environment without any initial foothold.

No patch reference found

Next step: No vendor patch or official advisory has been identified at this time. Organizations using ZKTeco BioTime should seriously evaluate whether to discontinue use of the product until the vendor provides a fix, as CISA's own guidance acknowledges mitigations may be unavailable.

Added: 5/19/2025 Remediate by: 6/9/2025
Remediation overdue CVE-2024-11182

MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability

MDaemon — Email Server

MDaemon Email Server contains a cross-site scripting flaw that lets a remote attacker embed and execute arbitrary JavaScript in a victim's browser simply by sending a crafted HTML email. Because email is a universal attack vector requiring no special access, this vulnerability has a broad potential impact — any user who opens a malicious message could have their session hijacked, credentials stolen, or browser actions manipulated without any further interaction from the attacker.

No patch reference found

Next step: No patch or vendor advisory reference has been identified at this time; administrators should check MDaemon's official vendor channels directly for available updates or guidance, and consider discontinuing use of the product if no mitigations can be applied.

Added: 5/19/2025 Remediate by: 6/9/2025
Remediation overdue CVE-2024-27443

Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability

Synacor — Zimbra Collaboration Suite (ZCS)

This vulnerability in Zimbra's classic webmail interface allows attackers to execute arbitrary JavaScript in a victim's browser simply by sending a specially crafted calendar invite email. No user interaction beyond viewing the message is implied — the malicious code runs automatically via a manipulated calendar header. For organizations running Zimbra, this means an attacker could potentially hijack user sessions, steal credentials, or perform actions on behalf of the victim within the webmail application.

No patch reference found

Next step: No patch or vendor advisory reference has been identified in the available data; organizations should contact Synacor directly for guidance and consider whether continued use of the affected Zimbra classic webmail interface is acceptable given the active risk.

Added: 5/19/2025 Remediate by: 6/9/2025
Remediation overdue CVE-2025-27920

Srimax Output Messenger Directory Traversal Vulnerability

Srimax — Output Messenger

This directory traversal flaw in Output Messenger, a workplace messaging platform, lets an attacker step outside the application's intended file boundaries to read arbitrary files on the server — including configuration files that may contain credentials or sensitive settings. Notably, the vulnerability was exploited as a zero-day by a threat actor tracked as Marbled Dust in a regional espionage campaign, meaning real-world, targeted attacks occurred before a fix was publicly available.

Patch available

Next step: Review the vendor's official advisory at https://www.outputmessenger.com/cve-2025-27920/ and apply any patch or update instructions provided there immediately.

Interim mitigation: According to Microsoft's threat intelligence blog, this vulnerability was actively exploited in espionage operations by the Marbled Dust threat actor; administrators should consult both the vendor advisory and Microsoft's analysis at https://www.microsoft.com/en-us/security/blog/2025/05/12/marbled-dust-leverages-zero-day-in-output-messenger-for-regional-espionage/ for any interim guidance referenced there. If mitigations are unavailable, CISA advises discontinuing use of the product.

Added: 5/19/2025 Remediate by: 6/9/2025
Remediation overdue CVE-2025-4427

Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability

Ivanti — Endpoint Manager Mobile (EPMM)

Ivanti EPMM exposes an API component that can be accessed without valid credentials due to a flawed implementation of the Spring Framework library. Attackers can craft specific API requests to bypass authentication entirely, reaching protected resources as if they were legitimate administrators. Because EPMM manages mobile devices across an organization, unauthorized access could expose device configurations, credentials, and sensitive enterprise data — making this a high-priority issue for any organization running the product.

Patch available

Next step: Review and apply the guidance published in Ivanti's official security advisory at https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM immediately, as no standalone patch reference was identified in the source data.

Added: 5/19/2025 Remediate by: 6/9/2025
Remediation overdue CVE-2025-4428

Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability

Ivanti — Endpoint Manager Mobile (EPMM)

This vulnerability allows an authenticated attacker to remotely execute arbitrary code on Ivanti EPMM systems by sending specially crafted API requests. The flaw stems from an insecure implementation of the Hibernate Validator library. Because EPMM is a mobile device management platform, a successful exploit could give attackers control over the system that manages and enforces security policies across an organization's entire mobile device fleet — a high-value target with broad organizational access.

Patch available

Next step: Review and apply vendor instructions detailed in the Ivanti security advisory at https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM immediately.

Added: 5/19/2025 Remediate by: 6/9/2025