Daily brief

Current threat signal

Source-linked reporting, sorted by publication date. Updated July 18, 2026.

unknown

Klue Integration Abused in Salesforce Data Theft | Threat Spotlight

In June 2026, a compromised Klue competitive-intelligence platform integration was exploited to exfiltrate customer relationship management data from enterprise Salesforce environments. Attackers authenticated through compromised Klue service accounts, generated OAuth tokens, and executed automated Python scripts to conduct bulk data extraction via Salesforce REST API queries over approximately 24 hours. The activity included concentrated bursts of nearly a thousand queries within 15 minutes and sustained extraction windows exceeding 6 hours. This incident follows similar third-party OAuth-abuse campaigns targeting Salesforce through Salesloft Drift and Gainsight integrations throughout 2025 and 2026. While the tactics resemble operations attributed to ShinyHunters and UNC6395 threat groups, attribution remains uncertain. The initial access vector, full scope of exfiltration, and attacker intent are still under investigation, with no extortion demands observed to date.

api exfiltrationcrm data theftklue integration
AlienVault OTX ↗ · unattributed attribution
unknown

Botnet Analysis: A Product-Grade Threat for the AI Service Era

NadMesh is an industrial-grade Go-based botnet observed in July 2026 that autonomously scans and exploits AI infrastructure and cloud services. The botnet integrates scanning, exploitation, and intelligence harvesting into a single platform targeting over 90 cloud provider address ranges. It employs 20+ exploitation vectors against Redis, Docker, MCP, Kubernetes, and other services, with particular focus on AI platforms like ComfyUI, Ollama, and Gradio discovered via Shodan API. NadMesh features a web-based management panel, polymorphic builds using Garble obfuscation and UPX packing, and redundant persistence mechanisms including SSH backdoors, agent processes, and cron watchdogs. The operation demonstrates clear commercial intent with conversion funnel statistics, canary updates, and automated task supply loops that amplify high-yield subnets. It harvests cloud credentials, Kubernetes tokens, AI model access, and MCP service intelligence.

CVE-2016-0638EPSS 62.9%ai infrastructure targetingautonomous scanningbotnet
AlienVault OTX ↗ · unattributed attribution · 5 IOCs
unknown

Contagious Interview malware in SVG images: DPRK campaign

A DPRK-aligned threat group is targeting developers through fake job postings and coding challenges in a campaign tracked as REF9403. Attackers post fake job offers in developer forums, then send trojanized repositories containing fully functional e-commerce projects with malicious code hidden using steganography inside SVG flag images. When developers run these projects, the malware deploys four-stage payloads aligned with OTTERCOOKIE: a browser credential and cryptocurrency wallet stealer, a file exfiltration module, a Socket.IO-based remote access trojan, and a clipboard stealer. The campaign was discovered after targeting Elastic's community Slack workspace. Multiple trojanized repositories were found with zero antivirus detections at the time of discovery, demonstrating the sophistication of this supply chain attack vector against software developers.

beavertailcryptocurrency wallet theftdeveloper targeting
AlienVault OTX ↗ · unattributed attribution · 14 IOCs
unknown

Behind the Refund: From GST Phishing to Remcos RAT Through a Multi-Stage .NET Infection Chain

A sophisticated phishing campaign targeting Indian businesses and taxpayers leverages GST-related themes to distribute Remcos RAT through a multi-stage .NET framework. Threat actors impersonate Government of India GST communications using fraudulent refund notifications with convincing ARN references. The attack chain begins with a malicious RAR archive containing a .NET executable that employs bitmap-based payload concealment techniques. Through successive stages including Windows Health Optimizer Plus.dll and perfgurd.dll, the malware deploys Remcos RAT entirely in memory, establishing persistence via PowerShell scripts and registry modifications. Command-and-control infrastructure utilizes dynamic DNS services with randomized subdomains under aofmokighoig.hath.network. The deployed Remcos RAT enables remote command execution, keylogging, credential harvesting, file manipulation, and comprehensive system reconnaissance capabilities, representing a financially motivated cybercrime ope

bitmap steganographycredential theftdynamic dns
AlienVault OTX ↗ · unattributed attribution · 9 IOCs
unknown

ClickFix Campaign Generated Via AI Delivers SmartRAT

In March 2026, threat actors leveraged AI-powered website builders to create typosquatting domains impersonating a Brazilian bank. The campaign employed ClickFix techniques, presenting victims with fake CAPTCHA and BSOD screens to trick them into executing malicious PowerShell commands. This delivered SmartRAT, a PowerShell-based banking trojan with capabilities including encrypted C2 communications, remote control of screen/keyboard/mouse, credential theft through keylogging and banking overlays, and QR code interception for transaction fraud. The malware establishes persistence via scheduled tasks and Windows services, and targets Brazilian financial institutions, payment platforms, and cryptocurrency exchanges. The threat actors' C2 panel contained critical authentication flaws allowing client-side bypass, suggesting deployment without adequate security review.

banana ratbanking trojanbrazil
AlienVault OTX ↗ · unattributed attribution · 11 IOCs
unknown

ACR Stealer: Two observed intrusion chains amid increased threat activity

Between late April and mid-June 2026, Microsoft observed heightened ACR Stealer activity targeting enterprise environments through ClickFix social engineering lures. This information-stealing malware, associated with Amatera Stealer rebranding and offered as malware-as-a-service, deployed through two distinct campaigns. The first utilized WebDAV-delivered payloads with Python loaders and blockchain-based command-and-control resolution. The second employed a fileless approach using MSHTA and steganography-concealed payloads within images. Both campaigns harvested browser credentials, authentication tokens, and sensitive documents from compromised systems. Threat actors leveraged obfuscated PowerShell scripts, scheduled task persistence, and in-memory execution techniques to evade detection. Notable tactics included masquerading as legitimate software updates, utilizing Windows DPAPI for credential decryption, and targeting PDF and Microsoft 365 documents. The blockchain dead-drop techni

acr stealeramatera stealerblockchain c2
AlienVault OTX ↗ · unattributed attribution · 16 IOCs
unknown

Novel Starland RAT and bespoke WLDR C2 implant deployed in financially motivated campaign

A sophisticated Russian-speaking financially motivated adversary designated UAT-11795 has been conducting malicious operations targeting users in the United States and Europe since June 2025. The campaign delivers a Python-based remote access tool called Starland RAT and a PowerShell-based command-and-control memory implant known as the WLDR agent. The actor distributes trojanized installers disguised as legitimate software including MobaXterm, WebEx, Zoom, DBeaver, and FACEIT through likely ClickFix social engineering techniques. The operation targets victims' credentials and cryptocurrency wallet assets while establishing persistent connections for additional payload delivery. Alternative payloads include CastleStealer and Remcos RAT. The infrastructure utilizes distributed staging and C2 domains, Telegram bots for notifications, and a Polygon smart contract as a fallback mechanism for C2 domain resolution. The WLDR agent features encrypted beaconing, task queuing, and a Runspace exe

castlestealerclickfixcredential harvesting
AlienVault OTX ↗ · unattributed attribution · 49 IOCs
unknown

The Patch Wars have begun

Microsoft released an unprecedented 622 vulnerability patches in July's Patch Tuesday, with 62 critical severity issues and three zero-days, two actively exploited. This represents more vulnerabilities than all of 2018 combined and marks a dramatic shift from the typical five patches issued in July two years prior. Microsoft attributes this surge to AI frontier model-accelerated vulnerability research. While major vendors like Microsoft possess resources to handle this volume, smaller companies face significant challenges. The concern extends beyond discovery to deployment, as traditional IT patch testing and stability review processes struggle under this unprecedented load. Organizations must differentiate between temporary surges and the new normal operational tempo, as continuous high-volume patching may become standard. This situation places extraordinary pressure on IT administrators and change management teams who must adapt to a sustained flood of KEV and EPSS notifications whil

castlestealerclickfixcryptocurrency theft
AlienVault OTX ↗ · unattributed attribution · 11 IOCs
unknown

GoSerpent backdoor attacks in Southeast Asia

Since late 2025, government and diplomatic entities in Southeast Asia have been targeted by sophisticated attacks involving GoSerpent, a Go-based RAT with proxy capabilities. The malware receives encrypted arguments and deploys additional tools for data collection and credential dumping. GoSerpent has been active since 2021, with newer variants using AES-CBC encryption and ChaCha20 for communications. The campaign involves multiple stages: initial deployment of GoSerpent and ThumbcacheService to collect sensitive files, credential dumping via Mimikatz and QuarksDumpLocalHash, followed by deployment of Stowaway RAT in May 2026 and TmcLoader/TmcPayload for stealthy data exfiltration through network shares. The integrated toolset demonstrates sophisticated operational planning, with attackers leveraging Alibaba Cloud and UCLOUD HK infrastructure while exhibiting possible connections to the TetrisPhantom threat actor.

credential dumpingdata exfiltrationdiplomatic entities
AlienVault OTX ↗ · unattributed attribution · 14 IOCs
unknown

HelloNet campaign: a threat via the ViPNet update system

An active APT campaign discovered in May 2026 exploits the ViPNet update system to deploy previously unknown tooling against large Russian organizations. Attackers achieve persistence through DLL sideloading, placing malicious wtsapi32.dll in ViPNet directories. The campaign employs multiple components: HelloInjector loader, HelloProxy for traffic proxying and payload delivery, HelloExecutor backdoor for command execution, HelloCleaner for log file sanitization, and HelloBackdoor written in Rust for file manipulation. Attackers conduct reconnaissance activities, establish SSH tunnels using renamed PuTTY utilities, and target government, energy, transport, education, logistics, and industrial sectors. Attribution points to an unknown Chinese-speaking APT group with low confidence based on strings referencing sina.com and Chinese package repositories.

chinese aptdll sideloadinghellobackdoor
AlienVault OTX ↗ · unattributed attribution · 15 IOCs
unknown

The TTF Trap: A Global Campaign of a Low-Detection Lua Loader

Since late March 2026, a large-scale phishing campaign has been deploying malware including Agent Tesla, Remcos, XWorm, and Best Private LOGGER through fileless techniques and low-detection Lua-based loaders. Attackers impersonate well-known companies using business cooperation lures to distribute malicious archives containing obfuscated JavaScript files. These scripts deploy either AutoIt or LuaJIT interpreters alongside disguised scripts masquerading as TrueType Font (.ttf) files. The Lua loaders employ sophisticated anti-analysis techniques including custom ROT ciphers, decoy memory allocation, and Donut shellcode generation for reflective in-memory payload execution. The campaign evolved from simpler implementations in October 2025 to highly complex versions by June 2026, incorporating API unhooking and advanced debugging countermeasures. Victims are ultimately infected with Remote Access Trojans and infostealers that enable full system control and extensive data exfiltration.

agent teslaautoitbest private logger
AlienVault OTX ↗ · unattributed attribution · 49 IOCs
unknown

Spirals: New Stealthy Ransomware Deployed Against Asian IT Company

A previously unseen ransomware family named Spirals was deployed in a double extortion attack against an IT services company in South Asia in June 2026. The Rust-based payload demonstrated sophisticated capabilities including defense evasion, encryption, lateral movement, and privilege escalation. Attackers gained initial access through a compromised internet-facing IIS web server via an ASP.NET web shell, moving rapidly to deploy ransomware within 24 hours. They established persistence using multiple tunneling tools, disabled endpoint security, harvested credentials through SAM hive and LSASS dumps, and deployed reverse-SOCKS proxies for covert command-and-control. The ransomware was distributed across the network using PsExec, encrypting files with AES-128 keys and threatening data publication within six days. The skilled execution suggests potential for wider campaigns, though the threat actor remains unidentified.

asp.net web shellchiselcloudflare tunnel
AlienVault OTX ↗ · unattributed attribution · 15 IOCs
unknown

ClickLock Stealer: Paste Once, Lose Everything

A new modular macOS information stealer named ClickLock Stealer has been discovered targeting users primarily in Europe, North America, and the Middle East. The malware is likely distributed via ClickFix social engineering pages that trick victims into pasting malicious commands into Terminal. Once executed, it deploys four components: a credential stealer, a Keychain stealer targeting Chrome's encryption key, a comprehensive crypto wallet harvester, and a persistent GSocket-based backdoor. The malware employs an aggressive 'locker' technique, killing all visible applications except password dialogs to force user compliance. It targets data from eight browsers, 31 crypto wallet extensions, seven password managers, desktop wallets, macOS Keychain, and shell history. The campaign has compromised at least 100 victims across 33 countries since May 2026, using compromised WordPress domains and Telegram for command and control and exfiltration.

atomic stealerclickfixclicklock stealer
AlienVault OTX ↗ · unattributed attribution · 18 IOCs
unknown

Attackers Weaponize Microsoft Teams Relays to Stay Hidden

Attackers deploying DragonForce ransomware against a major U.S. services firm concealed their command-and-control traffic within Microsoft Teams relay infrastructure using Backdoor.Turn, a custom Go-based remote access trojan. This novel technique leverages anonymous Teams visitor tokens and TURN relay servers to mask malicious communications as legitimate Microsoft traffic. The intrusion lasted one to two months, beginning in December 2025 with exploitation of an SQL server vulnerability. Attackers employed sophisticated defense evasion tactics including DLL side-loading with VirtualBox executables and multiple Bring Your Own Vulnerable Driver techniques. They exploited a previously unknown vulnerability in Huawei's HWAuidoOs2Ec.sys driver, along with several other vulnerable drivers, to terminate security processes at kernel level. The campaign demonstrates DragonForce's evolution into a highly capable ransomware cartel with advanced operational maturity.

CVE-2023-52271CVE-2025-1055EPSS 0.3%backdoor.turnbyovdcredential theft
AlienVault OTX ↗ · unattributed attribution · 29 IOCs
unknown

Potemkin Loader & RMMProject The Anatomy of a ClickFix Attack

A ClickFix social engineering attack on an unmonitored endpoint led to a multi-stage intrusion affecting over 11 hosts. The infection chain began with a malicious HTA payload that silently installed an MSI package containing Potemkin, a custom loader with a deterministic DGA. Potemkin delivered RMMProject, a 4.4 MB Lua-scriptable RAT featuring browser credential theft with Chrome App-Bound Encryption bypass, hidden-desktop remote control, and 15 distinct task types. The attacker deployed EtherRAT, a Node.js backdoor resolving C2 addresses from Ethereum blockchain, and established a Cloudflare tunnel for persistent access. Hands-on-keyboard activity included battling Windows Defender through AMSI patches, registry modifications, and service termination, followed by lateral movement via WMIExec and SMBExec to deploy malware across the network and reach the domain controller.

blockchain c2chiselclickfix
AlienVault OTX ↗ · unattributed attribution · 23 IOCs
unknown

Gamers beware: malicious wallpapers on Steam found stealing accounts

Since late 2025, cybercriminals have been exploiting Wallpaper Engine, a popular live wallpaper application on Steam, to distribute malware through Steam Workshop. Attackers target primarily Chinese and Russian gamers by embedding malicious code within application wallpapers shared on the platform. These compromised wallpapers deliver various malware types including infostealers, backdoors, crypto miners, and ransomware. One analyzed sample dropped DarkKomet backdoor while hijacking Steam sessions to steal account credentials. The malware modifies system libraries to locate Steam installations and exfiltrate data to attacker-controlled servers. Compromised accounts are then used to upload additional malicious wallpapers. The diverse malware families suggest multiple independent hacking groups are exploiting this distribution method. Infected wallpapers received thousands of downloads before removal, with 89% of infections occurring in China.

account hijackingcredential theftcrypto miner
AlienVault OTX ↗ · unattributed attribution · 14 IOCs
unknown

Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery

On July 14, 2026, a coordinated supply chain attack compromised the @asyncapi npm organization, affecting five package versions across four packages. The attack originated from a GitHub Actions workflow vulnerability that exposed privileged credentials, enabling unauthorized code injection. Unlike typical postinstall attacks, this campaign executes at module import time, bypassing common npm install --ignore-scripts protections. The malicious code spawned hidden processes that fetched a second-stage payload from IPFS, deploying the Miasma modular runtime with command-and-control capabilities, persistence mechanisms, and credential harvesting features. The payload included disabled modules for supply-chain propagation, AI-tool poisoning, and sandbox evasion. All compromised packages were published through legitimate GitHub OIDC workflows with valid provenance signatures, masking the malicious activity within trusted release processes.

asyncapibluerabbitgigawiper
AlienVault OTX ↗ · unattributed attribution · 19 IOCs
unknown

TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains

TELEPUZ is a newly emerged modular malware-as-a-service first detected in April 2026, spreading through CLICKFIX-VIDAR infection chains. The lightweight, full-featured threat employs sophisticated evasion techniques including indirect syscalls, NTDLL unhooking, and anti-VM checks. It establishes persistence through service installation, communicates via WebSockets with C2 servers, and downloads additional modules for keylogging, credential theft, and web injection. The infection begins with social engineering tricks prompting victims to execute PowerShell commands, deploying VIDAR as a second stage which then delivers TELEPUZ components. Despite limited C2 infrastructure, high daily build volumes indicate active development and expanding operations by likely a small team or solo developer offering malware-as-a-service.

clickfixmaastelepuz
AlienVault OTX ↗ · unattributed attribution · 13 IOCs
unknown

​​Kratos PhaaS Targets US and EU: How to Reduce Microsoft 365 Account Takeover Risk​

Kratos is a mature Phishing-as-a-Service operation targeting Microsoft 365 users across the United States, Europe, and other regions. The platform enables attackers to steal credentials through trusted platforms, anti-bot verification, and convincing login pages. Researchers traced three generations of the kit and uncovered 1,484 previously unattributed detonations. The operation targets organizations across more than 20 countries with particularly strong concentration in the US, Spain, and Southern Europe. Kratos includes an operator panel allowing deployment of phishing domains, configurable Telegram or email delivery, geographic restrictions, and multiple anti-bot systems. The kit has evolved through three page generations (V0, V1, V2) with different exfiltration code. Activity has been visible since January 2026, with the operator panel active since September 2025.

account takeovercredential thefteurope
AlienVault OTX ↗ · unattributed attribution · 24 IOCs
unknown

Introducing CylindricalCanine: The GoldenEyeDog subgroup responsible for the April DigiCert incident

Chinese cybercrime group GoldenEyeDog has been active since 2015, regularly updating malware and leveraging code-signing certificates to bypass Windows SmartScreen since 2024. A subgroup called CylindricalCanine uses Golden Gh0st Loader and Golden Gh0st RAT, modified versions of the 2008 Gh0st RAT, primarily targeting finance organizations in the Asia Pacific region through phishing campaigns. In April 2026, these actors compromised a DigiCert support member's device and stole code-signing certificates intended for customers, which they used to sign their own malware. The malware uses DLL sideloading, custom WebSocket protocols for command and control, and includes capabilities for remote access, credential theft, keylogging, SOCKS proxy tunneling, and RDP backdoor creation. Analysis reveals consistent tactics including using legitimate executables to load malicious DLLs that decrypt payloads from files disguised as logs.

cylindricalcaninegh0st ratgolden gh0st loader
AlienVault OTX ↗ · unattributed attribution · 19 IOCs
unknown

Investigation of email-based attack delivering MediaFire ZIP file with execution chain analysis

An investigation revealed a malicious email campaign directing victims to download a ZIP file from MediaFire. The infection chain began with a Python setup executable (Setu.exe) that side-loaded a malicious 400 MB python37.dll containing repeated byte padding. The DLL performed process injection into dllhost.exe, establishing communication with a C2 server at 138.124.186.2:7000. The threat actor deployed three persistence mechanisms: a PowerShell-based path, a fake EdgeUpdate Python executable with scheduled task, and NetSupport RMM as a third access method. The analysis highlights the importance of comparing file timestamps during triage to identify malicious artifacts within compressed archives.

dll hijackingemail deliverymediafire
AlienVault OTX ↗ · unattributed attribution · 6 IOCs
unknown

WebAssembly Malware Found in Trojanized Open VSX Extensions

Trojanized Visual Studio Code extensions distributed via the Open VSX marketplace deliver a sophisticated WebAssembly-based attack chain. The extensions ship ChaCha20-encrypted TinyGo-compiled WebAssembly modules that poll the Solana blockchain for command-and-control instructions embedded in transaction memos. This novel dead-drop technique allows attackers to rotate infrastructure without hardcoded servers. Once activated, the modules read attacker instructions from a monitored Solana wallet address, then execute platform-specific download-and-execute commands via Node.js child_process to deploy second-stage payloads. The campaign impersonates legitimate extensions on Open VSX, exploiting cross-registry trust gaps to target VSCodium, Cursor, Windsurf, and other VS Code forks. Attribution points to GlassWorm-associated tradecraft with medium confidence, representing a new WebAssembly-based variant of previously documented supply chain compromise techniques.

chacha20 encryptioncryptocurrency targetingdead-drop c2
AlienVault OTX ↗ · unattributed attribution · 18 IOCs
high

CVE-2026-58644: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVE-2026-58644EPSS 1.5%MicrosoftSharePoint
CISA KEV ↗ · unattributed attribution
high

CVE-2026-25089: Fortinet FortiSandbox OS Command Injection Vulnerability

Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVE-2026-25089EPSS 36.1%FortiSandboxFortinet
CISA KEV ↗ · unattributed attribution
high

CVE-2026-39808: Fortinet FortiSandbox OS Command Injection Vulnerability

Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVE-2026-39808EPSS 84.2%FortiSandboxFortinet
CISA KEV ↗ · unattributed attribution
unknown

Fake crypto scams try to piggyback off SpaceX IPO

Scammers are exploiting public interest in the SpaceX IPO through fraudulent investment portals impersonating SpaceX, Elon Musk, and major financial brands including Fidelity and Robinhood. The campaign uses themed domains to lure victims into fake onboarding processes that mimic legitimate investment procedures, including W-8BEN tax forms for non-U.S. investors. Victims are asked to select investment tiers and ultimately directed to deposit funds via cryptocurrency wallets for Bitcoin, Ethereum, and USDT. The operation mirrors techniques used by threat actor TA2730 but focuses on direct cryptocurrency theft rather than credential harvesting. One Bitcoin wallet associated with the campaign received approximately $8,700. The infrastructure includes randomized domains and SpaceX-themed domains designed to appear legitimate during the investment process.

brand impersonationcryptocurrency theftfake portals
AlienVault OTX ↗ · unattributed attribution · 18 IOCs
unknown

Operation Fake KickOff: Attackers Abuse Recruiters and SaaS to Harvest Work Credentials

A sophisticated multi-stage phishing operation has been active since April 2025, systematically exploiting legitimate SaaS platforms and cloud services to steal corporate credentials. The campaign utilizes 232 phishing domains and 80 command-and-control servers, primarily impersonating human resources consulting firms, with Robert Half Inc. and Aquent LLC representing 50% of targeted brands. Attackers leverage legitimate platforms like Salesforce, SendGrid, and Zoho for email delivery, directing victims to fake Calendly interview pages that mimic real recruiter identities. The operation deploys an adversary-in-the-middle toolkit using browser-in-the-box techniques to create replica Google sign-in pages, capable of harvesting credentials and bypassing MFA through email, SMS, Google Authenticator, and prompt notifications. The campaign specifically targets corporate email accounts, filtering out personal providers, with stolen data exfiltrated to Render-hosted servers and Telegram bots.

aitmbrowser-in-the-boxcredential theft
AlienVault OTX ↗ · unattributed attribution · 2 IOCs
unknown

11 Malicious NuGet Tools Pose as Game Cheats to Drop a Windows Host-Surveillance Payload

Eleven malicious NuGet packages distributed as .NET command-line tools masquerade as game utilities and cheats for popular games including Albion Online, GTA5RP, GrandRP, and Throne and Liberty. Each package functions as a first-stage downloader that uses DNS-over-HTTPS to bypass local controls, requests UAC elevation to resync system time, and fetches a second-stage PyInstaller payload named pepesoft.exe from GitHub and Hugging Face under username pepegit666. The payload binds to hardware fingerprints, enforces licensing through Google Sheets telemetry, honors remote ban-lists, and in three variants exposes Telegram bot commands enabling screenshot capture and remote control. All packages share identical AWS credentials and mutex identifiers, linking them to a single Russian-speaking operator running a commercial game-automation service marketed through pepesoft.ru and Telegram channel pepesoft777.

dns-over-https evasiongame cheatsgoogle sheets telemetry
AlienVault OTX ↗ · unattributed attribution · 41 IOCs
unknown

Shared Claude Chats Meet ClickFix

A ClickFix campaign has been identified that abuses Anthropic's Claude platform through shareable chat links to distribute MacSync Stealer targeting macOS users. Attackers utilized malvertising with paid Google ads to direct victims searching for Claude-related terms to malicious shared Claude chats falsely labeled as 'Apple Support.' These chats contained obfuscated installation commands that, when executed, deployed a multi-stage infection chain. The malware steals credentials from browsers and password managers, cryptocurrency wallet data, sensitive files, and system information. The campaign ran from June 12-19, 2026, targeting primarily Mac users with Russian-language comments in the code suggesting Russian-speaking threat actors. Domains used adopted themes related to U.S. local services to appear legitimate.

claude platform abuseclickfixcredential stealing
AlienVault OTX ↗ · unattributed attribution · 211 IOCs
unknown

June 2026 Infostealer Trend Report

During June 2026, multiple infostealer families including Remus, ACRStealer, LummaC2, and Vidar were distributed through SEO poisoning techniques, disguised as illegal software such as cracks and keygens. Attacks utilized EXE files (84.5%) and DLL side-loading (15.5%) methods, with distribution primarily through Mediafire, Mega, and cloud storage platforms. Microsoft Corporation was the most frequently impersonated entity. MacOS environments were targeted through ClickFix techniques and malicious Bash scripts, with one variant dynamically obtaining C2 addresses via Polygon smart contracts. Email-based campaigns distributed AgentTesla and DarkCloud through compressed attachments, with both variants exfiltrating data via SMTP. The stolen credentials pose significant risks for dark web trading and secondary attacks.

acrstealeragentteslaamos
AlienVault OTX ↗ · unattributed attribution · 12 IOCs
unknown

OkoBot framework infection chain

In January 2026, researchers identified a sophisticated malware framework dubbed OkoBot that targets cryptocurrency users through a multi-stage infection chain. The campaign begins with TookPS PowerShell scripts delivered via ClickFix attacks or fake software on GitHub. An automated SSH bot deploys over 20 malicious modules including HDUtil launcher, browser extension injectors installing Rilide stealer, and specialized tools like SeedHunter for wallet seed phrase theft and OkoSpyware for window capture. The framework uses VMProtect obfuscation, UAC bypass techniques, and maintains persistence through RDP access and scheduled tasks. Victims span more than 25 countries with concentrations in Brazil, Vietnam, Canada, Mexico, and Turkey. Attribution suggests Russian-speaking threat actors based on geoblocking patterns and Russian language artifacts.

browser extensioncryptocurrency thefthdutil
AlienVault OTX ↗ · unattributed attribution · 21 IOCs
unknown

Daxin Returns: Stealthy Malware Resurfaces in Taiwan Alongside a New Backdoor

Backdoor.Daxin, a sophisticated China-linked kernel-mode rootkit first exposed in 2022, was discovered operating on a Taiwan manufacturing firm's network in 2026. The malware was found alongside Backdoor.Stupig, a previously unknown backdoor that uses a novel technique involving a Trojanized keyboard-layout DLL loaded by winlogon.exe, enabling command execution as System from the Windows logon screen without authentication. Both samples carry compile timestamps from early 2013, but the compromised host only began reporting telemetry in May 2026, suggesting a possible 13-year undetected intrusion. The victim was a Taiwan-based subsidiary of a multinational high-tech manufacturer. Daxin's defining characteristic is its ability to hijack legitimate TCP connections for command-and-control traffic, making it exceptionally difficult to detect through conventional network monitoring.

backdoorchina-linked espionagedaxin
AlienVault OTX ↗ · unattributed attribution · 5 IOCs
unknown

How attackers are jailbreaking LLMs with CTF framing and how to catch them

Threat actors are bypassing AI model safety guardrails by framing exploit requests as legitimate security research, such as capture-the-flag challenges or CVE-hunting exercises. This technique manipulates upstream LLMs into generating working exploit code that attackers deploy against real targets. Multiple independent operators have been observed targeting five applications—PraisonAI, LiteLLM, FastGPT, Open-WebUI, and Gotenberg—using CVE-templated User-Agent strings and similar framing across multiple fields including passwords and AWS session names. The jailbreak framing leaks into every LLM-generated field because the model incorporates the prompt context into its output. This pattern represents a shift from manually written scanners to LLM-assisted exploit generation, creating detectable fingerprints across request headers, account aliases, and IAM session names that legitimate traffic rarely exhibits.

CVE-2026-39987CVE-2026-42208EPSS 95.6%ai platform targetingcve exploitationcve-2026-39987
AlienVault OTX ↗ · unattributed attribution
unknown

Public and Private Medical Community Targeted by Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, and National Defense Research

A sophisticated espionage campaign attributed to UNC6508, a China-nexus threat actor, targeted North American academic, medical, and military research institutions for over a year. The adversary exploited REDCap servers, deployed custom INFINITERED malware to harvest credentials, and maintained persistent access through trojanized legitimate files that survived software upgrades. After remaining undetected for more than a year, the threat actor pivoted to administrative accounts and created malicious content compliance rules to silently exfiltrate emails containing defense intelligence, Indo-Pacific command operations, artificial intelligence research, uncrewed vehicle systems, cyber programs, and medical research data. The operation employed sophisticated techniques including obfuscation networks routing through US-based infrastructure, compromised routers, and dedicated exfiltration accounts, demonstrating advanced operational security aligned with strategic intelligence collection r

china-nexuscontent compliance abusecredential harvesting
AlienVault OTX ↗ · unattributed attribution · 7 IOCs
unknown

Inside an IoT Botnet Framework With LLM-Assisted Development

A previously undocumented modular IoT botnet framework has been identified with code partially generated using large language models. The framework consists of C-based bot agents compiled for 17 architectures, a Go-based command-and-control server with DDoS-for-hire panel, and custom exploit capabilities. Bot agents brute-force Telnet access using 1,496 credential pairs and target over 30 IoT device families. While core infection mechanisms function properly, several features are broken due to LLM-generated bugs that were shipped without manual review. The framework includes multiple fallback C2 mechanisms including domain generation algorithms, peer-to-peer gossip, IRC, and DNS TXT queries. Infrastructure analysis links this operation to the Keksec ecosystem through shared dropper servers. Development timeline spans from January 2025 to April 2026, with active C2 infrastructure observed since March 2026.

aisuruddos-for-hiregafgyt
AlienVault OTX ↗ · unattributed attribution · 50 IOCs
unknown

Miasma Worm Returns to npm

Four AsyncAPI npm packages were compromised in July 2026, delivering Miasma v3, a new variant of the worm previously found in Red Hat packages. The malicious versions (@asyncapi/generator, @asyncapi/generator-helpers, @asyncapi/generator-components, and @asyncapi/specs) were published through AsyncAPI's legitimate GitHub Actions workflow using npm's OIDC integration, creating packages with valid provenance attestations. Unlike previous variants, this attack triggers when applications load the poisoned library rather than during installation. The payload downloads a second stage from IPFS, establishing a persistent Node.js backdoor with arbitrary shell command execution capabilities. While the codebase contains credential theft, propagation, and AI-tool poisoning modules, this deployment primarily functions as a remote access trojan. The attack began with an unauthorized commit to the repository's release branch, highlighting the importance of branch protection even when using trusted-p

asyncapimiasma v3npm hijacking
AlienVault OTX ↗ · unattributed attribution · 6 IOCs
unknown

Six Minutes to Compromise: How 'Patriot Bait' Actor Used AI to Build and Deploy a C&C Botnet

A Russian-speaking threat actor known as 'bandcampro' leveraged Google Gemini CLI to migrate and operate a command-and-control botnet in six minutes, with the AI handling 89% of all work including architecture, coding, deployment, and debugging. Analysis of 200 Gemini CLI session logs from March-April 2026 revealed the actor controlled eight computers in a dental clinic, accessing OpenDental databases. The actor communicated intentions in plain Russian while AI executed technical operations. The entire C&C infrastructure fits in three plain-text files totaling 5KB, making it highly portable and disposable. Beyond botnet operations, the actor used AI for password cracking, WordPress compromise, and planning cryptocurrency fraud targeting elderly victims in the US and Canada. The AI proactively suggested improvements 59 times unprompted, demonstrating how AI lowers barriers for threat actors by replacing technical skill requirements with simple natural-language instructions.

ai-assisted hackingbotnet operationscryptocurrency fraud
AlienVault OTX ↗ · unattributed attribution · 2 IOCs
unknown

Threat Spotlight: The Jalisco Toolkit and AI-Powered Phishing Surge

Phishing attacks have surged in 2026 as AI-powered phishing-as-a-service kits enable threat actors to bypass multi-factor authentication and harvest OAuth tokens at scale. Two phishing tools were identified in active campaigns: Jalisco, a device code phishing toolkit that provisions fresh OAuth codes in real time to defeat time-based security controls, and OmegaLord, a credential harvester that captures phone numbers alongside passwords to intercept MFA. Both tools demonstrate that attackers are engineering sophisticated methods to defeat authentication controls. These toolkits are part of a broader ecosystem that includes AI-powered PhaaS kits like EvilTokens and Kali365, which leverage legitimate cloud platforms to evade detection. Following compromise, attackers establish persistence by enrolling multiple devices to victim Entra ID tenants, enabling access that survives password resets and extends the window for data exfiltration and extortion.

darculajaliscokali365
AlienVault OTX ↗ · unattributed attribution · 7 IOCs
unknown

Suspected Chinese Operators Use Claude Code and DeepSeek to Breach Government Systems Across Four Countries

In June 2026, infrastructure pivoting from TencShell C2 nodes revealed an active intrusion campaign utilizing AI language models for attack automation. Thirteen Hong Kong-based servers across four ASNs exposed an open directory containing victim source code, custom exploits, operational logs, and cloned login pages with notes in Simplified Chinese. The operation employed Claude Code for execution and DeepSeek-v4-pro for attack logic, targeting government systems in Afghanistan, Thailand, and Taiwan, along with reconnaissance against U.S. government portals. The campaign also pursued financial services firms across Europe, Australia, and Asia. Attackers deployed TencShell implants, webshells, and custom exploits including SQL injection and Laravel deserialization attacks, successfully compromising administrative systems and exfiltrating sensitive data including citizen complaints and government employee information.

claude codedeepseekgshell
AlienVault OTX ↗ · unattributed attribution · 30 IOCs
unknown

LabubaRAT: A Rust Based Remote Access Tool Masquerading as NVIDIA Software

A previously undocumented remote access tool named LabubaRAT has been identified, masquerading as NVIDIA software through fake metadata and runtime artifacts. This Rust-based malware creates persistent footholds enabling hands-on operator activity including host profiling, security tool identification, command execution, file transfers, screenshot capture, and traffic proxying. The implant supports multiple communication methods including HTTPS polling, WebView2-based communication, and DNS tunneling. It uses a configurable framework model with organization, group, server, and API key parameters suggesting a Malware-as-a-Service platform. The malware maintains local state in SQLite databases and provides comprehensive remote access capabilities including PowerShell and JavaScript execution, SOCKS5 proxy support, and user-level persistence through registry autoruns. Infrastructure analysis revealed LabubaPanel branding with associated command and control servers hosted on German provide

dns tunnelinglabubapanellabubarat
AlienVault OTX ↗ · unattributed attribution · 8 IOCs
unknown

Analysis of APT37 NarwhalRAT Leveraging MS-Themed Phishing and Dead-drop C2

A sophisticated Python-based RAT targeting Korean users through spear phishing emails disguised as Microsoft security alerts. The attack chain employs LNK files embedded in ZIP archives, BAT-based obfuscation, and multi-stage loaders culminating in NarwhalRAT deployment. This advanced malware features keylogging, screen capture, microphone recording, and USB data collection capabilities. It utilizes a dual C2 infrastructure combining Korean relay servers (daehoat.com, novel21.co.kr) with pCloud API as a dead-drop resolver. The malware creates encrypted configuration files, implements anti-VM techniques, and establishes persistence through scheduled tasks. It operates as a manually-controlled RAT with selective function activation via C2 commands, employing in-memory execution to evade file-based detection.

anti-vmdead-drop-resolverkorean-targeting
AlienVault OTX ↗ · unattributed attribution · 11 IOCs
unknown

The Devil, Eight Million Emails, and a Whole Lot of Milk | Phishing Stager Exposed

On May 15, 2026, Huntress agents detected an intrusion where threat actors compromised a terminal server to stage a massive phishing campaign rather than deploy ransomware. The attacker used legitimate bulk email software (Gammadyne Mailer) with a project file named 'dracii' (Romanian for 'the devils') and six recipient lists containing 8,894,920 email addresses. Operating from Romanian IP addresses, the actor impersonated UK pharmacy chain Boots through a fake customer satisfaction survey designed to harvest personal and payment card data. The phishing kit was hosted on a compromised Bolivian government website (ipelc.gob.bo), which Huntress reported to Bolivia's national CSIRT. The campaign used direct-to-MX delivery to bypass mail relays, with the mailer configured to send from 666 threads simultaneously. Evidence suggests this Romanian operator has been running multiple UK-targeting campaigns since at least July 2025, rotating between retail, tax, and cryptocurrency themes.

bulk email abusecompromised government websitecredential theft
AlienVault OTX ↗ · unattributed attribution · 11 IOCs
unknown

One Misconfigured Server, Three Active Campaigns: Full exposure of three AiTM Phishing Operators

A misconfigured Python HTTP server on a Budapest VPS exposed the complete operational infrastructure of three distinct phishing operators. The investigation uncovered codemado, an Egyptian threat actor operating since 2018, running a full AiTM platform with custom tools including MaDoO Blaster; saroula01, deploying OAuth Device Code Flow attacks that accumulated 218 victims across 12 countries over a year; and mail-argenta, a Nigerian operator identified through infostealer logs containing his own credentials. All three actors leveraged customized Evilginx forks and AI-assisted development to build MFA-bypass infrastructure from public GitHub repositories. The campaigns targeted Microsoft 365 accounts primarily, with codemado maintaining ties to RockyBelling's "The Quarry" cybercrime ecosystem. The exposed server contained phishing configurations, credential logs, RMM installers, combolists, and Telegram session files, revealing sustained operations from at least January 2025 through M

aitmasyncratevilginx
AlienVault OTX ↗ · unattributed attribution · 69 IOCs
high

CVE-2026-46817: Oracle E-Business Suite Improper Privilege Management Vulnerability

Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVE-2026-46817EPSS 1.0%E-Business SuiteOracle
CISA KEV ↗ · unattributed attribution
high

CVE-2023-4346: KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability

KNX Association KNX Protocol Connection Authorization Option 1 contains an overly restrictive account lockout mechanism vulnerability that could allow an attacker to purge all devices without additional security options enabled and set a BCU key to lock the device. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVE-2023-4346EPSS 0.9%KNX AssociationKNX Protocol Connection Authorization Option 1
CISA KEV ↗ · unattributed attribution
unknown

The Scam Will Go On: Beware of Fake Offers for Celine Dion Concert Tickets

A sophisticated multi-layered scam operation targets fans seeking tickets for Celine Dion's French tour through two primary vectors. Fraudsters embed themselves in Facebook Groups and Marketplace, using social engineering to create artificial urgency and selling tickets before official presale dates. They exploit Ticketmaster's legitimate transfer feature to resell identical digital tickets to multiple victims, accepting direct bank transfers from compromised accounts. Simultaneously, threat actors deploy fraudulent websites impersonating official distributors like AXS and Ticketmaster, exploiting Shopify's payment infrastructure to appear legitimate. These sites share common technical indicators suggesting use of a recycled phishing kit previously deployed for other major concert events, including Oasis and Taylor Swift tours. The scheme combines emotional manipulation with technical deception to defraud victims desperate for concert access.

celine dion concertfacebook scamfrance
AlienVault OTX ↗ · unattributed attribution · 67 IOCs
unknown

Compromised npm Packages in the AsyncAPI Namespace Deliver Miasma Botnet Loader

Four npm packages in the AsyncAPI namespace were compromised to distribute a multi-stage botnet loader called Miasma. The attack utilized trusted GitHub Actions publishing but originated from a poisoned source commit. Malicious code was injected into legitimate source files that execute when imported, launching a detached Node.js process to download an 8.25 MB encrypted payload from IPFS. The final payload is a sophisticated tasking framework supporting multiple command-and-control channels including REST, Nostr relays, IPFS, Ethereum smart contracts, and BitTorrent DHT. The framework establishes persistence via systemd services on Linux and fake NodeJS directories, supporting file operations, shell execution, data collection, and cross-ecosystem propagation capabilities for npm, PyPI, RubyGems, and Cargo ecosystems.

asyncapicross-platformipfs delivery
AlienVault OTX ↗ · unattributed attribution · 19 IOCs
unknown

Supply Chain Compromise via GitHub Actions

On July 14, 2026, an attacker exploited a misconfigured GitHub Actions workflow in the AsyncAPI generator repository through a 'pwn request' vulnerability. The attacker opened 37 pull requests, with one containing obfuscated JavaScript that exfiltrated a highly privileged Personal Access Token belonging to asyncapi-bot. Using the stolen credentials, the attacker published five malicious npm package versions under the @asyncapi namespace, which collectively receive over three million downloads weekly. The malware features a multi-stage payload that establishes persistence and connects to command and control infrastructure, executing on import rather than install. It includes capabilities for credential theft targeting browsers, SSH keys, cloud credentials, and cryptocurrency wallets. The payload shares technical characteristics with the Miasma malware framework but shows unique features including a comprehensive command framework.

asyncapicredential theftgithub actions
AlienVault OTX ↗ · unattributed attribution · 5 IOCs
unknown

Lucide Proxy: Turning Student Web Proxies into DDoS Bots

A sophisticated campaign deployed 148 malicious npm packages disguised as student web proxy applications under brands like Riverbend Tutoring and Northstar Tutoring. Published by accounts terminal3airport and eerikakirk, these packages weaponized visitor browsers into distributed denial-of-service botnets while generating advertising revenue. The applications functioned as working proxies but secretly executed mutable remote code and high-performance WebSocket traffic generators compatible with the Wisp protocol. During a critical two-week period in May 2026, active deployments launched HTTP floods generating 2GB/s aggregate traffic and control-plane attacks establishing 10,240 socket connections per second against target servers. The campaign abused npm as a content delivery network, affecting users who visited proxy instances rather than through traditional dependency infection.

adwarebrowser-based attackddos botnet
AlienVault OTX ↗ · unattributed attribution · 10 IOCs
unknown

Operation ShadowRecruit: A Recruitment-Themed Malware Campaign Leveraging ControlR and Google Sheets to Target Indian Job Seekers

A sophisticated cyber campaign targets Indian government job seekers using fake recruitment advertisements for Senior Field Officer positions in the Cabinet Secretariat. The attack chain begins with a malicious ZIP archive containing a disguised LNK file, PowerShell script, and .NET executable. Attackers abuse the legitimate ControlR remote management tool for persistent access and deploy SheetAgent RAT, a custom .NET malware that uses Google Sheets as a command-and-control channel. The malware employs multiple persistence mechanisms including scheduled tasks and startup folder entries, while incorporating extensive anti-analysis checks to detect virtualized environments. Infrastructure analysis reveals multiple web-based management panels and connections to APT36 based on targeting patterns and tradecraft similarities.

anti-virtualizationcontrolr abusegoogle sheets c2
AlienVault OTX ↗ · unattributed attribution · 14 IOCs
unknown

ModHeader Malware: Inside the Chrome Spyware Google Removed

ModHeader, a popular Chrome developer extension with over 800,000 users, was flagged and removed by Google for containing hidden spyware. Version 7.0.18 included a covert SDK disguised as a date library (dayjs) that harvested visited domain names, encrypted them using AES-GCM, and was configured to upload the data daily to api.stanfordstudies.com. Although the collection remained dormant due to an empty allowlist, the complete exfiltration infrastructure was present and operational. Additionally, the extension displayed active adware behavior, opening affiliate tabs on every update including on enterprise-managed machines. The malicious code shipped with official Chrome Web Store signatures, affecting both Chrome and Edge users. Forensic analysis revealed the extension locally stored 178MB of sensitive HTTP headers from all browsing activity, though no data was successfully exfiltrated from analyzed systems.

adwarebrowser extensionchrome web store
AlienVault OTX ↗ · unattributed attribution · 2 IOCs
unknown

CrashStealer: C++ macOS Infostealer Posing as Crash Reporter

A newly discovered macOS infostealer, implemented in native C++, impersonates Apple's crash-reporting framework to harvest sensitive data. The malware is distributed through a signed and notarized dropper application that bypasses Gatekeeper, then downloads and installs the payload from attacker infrastructure. The stealer validates victim passwords locally using dscl, unlocks the login keychain, and collects browser credentials, cryptocurrency wallet extensions, password manager data, and keychain material. Collected data is encrypted using AES-GCM before being packaged into hidden ZIP archives and exfiltrated to a command-and-control server. The malware establishes persistence by copying itself to a hidden directory and installing a LaunchAgent. It employs control-flow flattening, encrypted strings, and anti-debugging techniques to resist analysis. The campaign uses GitHub for initial staging and multiple fake collaboration software domains as lures.

crashstealerinfostealermacos
AlienVault OTX ↗ · unattributed attribution · 33 IOCs
unknown

Tomorrowland 2026, Belgium: People of Tomorrow, Targets of Today

Tomorrowland Belgium 2026, spanning two weekends in July at De Schorre in Boom, sold out rapidly, creating opportunities for cybercriminals. Investigation uncovered approximately a dozen fraudulent websites impersonating the festival brand to target ticket seekers and travellers. These scams include fake ticket shops mimicking official sales with countdown timers and fraudulent biometric checks, travel sites offering bogus accommodation and transport packages, and affiliate schemes. The operations harvest complete identity data, payment credentials, and personal information through sophisticated social engineering. Victims lose money with no recourse, face identity theft risks, and ultimately receive invalid or non-existent tickets. The scammers exploit high demand, tight supply, and rushed purchasing decisions, with sites registered weeks in advance and pushed hardest when official tickets are sold out.

fake-ticket-shopsfestival-scampayment-fraud
AlienVault OTX ↗ · unattributed attribution · 20 IOCs
unknown

Defending SaaS-based applications against ShinyHunters OAuth abuse

Between mid-2025 and mid-2026, threat actors using tradecraft associated with ShinyHunters targeted customer SaaS applications, particularly Salesforce instances, through three primary intrusion paths. Voice phishing campaigns impersonated IT support to trick employees into authorizing malicious OAuth applications. Supply chain compromises leveraged trusted integrations including Salesloft, Gainsight, and Klue to obtain OAuth tokens for downstream customer access. Misconfigured guest access enabled exploitation of Aura framework functionality for unauthorized data queries. These techniques abused legitimate OAuth relationships to inherit user and application privileges, enabling enumeration and exfiltration of CRM data while evading authentication detections. The campaigns targeted multiple industries including retail, education, and manufacturing, highlighting risks in OAuth-connected applications and third-party integrations.

oauth abusesaas securitysalesforce
AlienVault OTX ↗ · unattributed attribution · 4 IOCs
high

CVE-2026-56155: Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability

Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVE-2026-56155EPSS 0.4%Active Directory Federation ServicesMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2026-56164: Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability

Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVE-2026-56164EPSS 5.6%MicrosoftSharePoint Server
CISA KEV ↗ · unattributed attribution
high

CVE-2026-15409: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability

SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVE-2026-15409EPSS 1.3%SMA1000 AppliancesSonicWall
CISA KEV ↗ · unattributed attribution
high

CVE-2026-15410: SonicWall SMA1000 Appliances Code Injection Vulnerability

SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVE-2026-15410EPSS 1.5%SMA1000 AppliancesSonicWall
CISA KEV ↗ · unattributed attribution
unknown

Threat Actors Achieve Persistence After SQL Injection

Threat actors gaining initial access through SQL injection exploited a web application vulnerability in a technology sector organization. After compromising an MSSQL instance via inadequate input validation, the attackers deployed base64-encoded PowerShell scripts to conduct reconnaissance using tasklist commands and exfiltrated results to an external server. They established persistence by enabling Remote Desktop Services, creating an administratively privileged user account named adminweb2$, and disabling Windows Defender. The attackers installed BadIIS modules for SEO fraud, deployed XMRig cryptocurrency miner with hidden file attributes, and utilized service creation tools. Multiple PowerShell scripts and batch files were downloaded throughout the attack to facilitate various malicious operations and maintain access.

badiisbadiis modulescncrypt protect
AlienVault OTX ↗ · unattributed attribution · 2 IOCs
high

CVE-2008-4128: Cisco IOS Cross-Site Request Forgery Vulnerability

Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVE-2008-4128EPSS 23.9%CiscoIOS
CISA KEV ↗ · unattributed attribution
high

CVE-2026-56291: Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability

Balbooa Forms contains an unrestricted upload of file with dangerous type vulnerability that allows an unauthenticated arbitrary file upload which could allow uploading of executable files leading to full RCE. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVE-2026-56291EPSS 0.8%BalbooaForms
CISA KEV ↗ · unattributed attribution
high

CVE-2026-48939: iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability

iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVE-2026-48939EPSS 1.5%iCagenda
CISA KEV ↗ · unattributed attribution
high

CVE-2026-48908: JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability

JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVE-2026-48908EPSS 1.6%JoomShaperSP Page Builder
CISA KEV ↗ · unattributed attribution
high

CVE-2026-55255: Langflow Authorization Bypass Through User-Controlled Key Vulnerability

Langflow contains an authorization bypass through user-controlled key vulnerability which allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVE-2026-55255EPSS 0.6%Langflow
CISA KEV ↗ · unattributed attribution
high

CVE-2026-56290: Joomlack Page Builder Improper Access Control Vulnerability

Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVE-2026-56290EPSS 2.9%JoomlackPage Builder
CISA KEV ↗ · unattributed attribution
high

CVE-2026-48282: Adobe ColdFusion Path Traversal Vulnerability

Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVE-2026-48282EPSS 28.6%AdobeColdFusion
CISA KEV ↗ · unattributed attribution
unknown

Cyber Brief 26-07 - June 2026

Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:CLEAR.

CERT-EU Threat Intelligence ↗ · unattributed attribution
high

CVE-2026-45659: Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability

Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVE-2026-45659EPSS 3.2%MicrosoftSharePoint Server
CISA KEV ↗ · unattributed attribution
high

CVE-2026-48558: SimpleHelp Authentication Bypass Vulnerability

SimpleHelp contains an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guideline

CVE-2026-48558EPSS 1.2%SimpleHelpSimpleHelp
CISA KEV ↗ · unattributed attribution
high

CVE-2026-12569: PTC Windchill and FlexPLM Improper Input Validation Vulnerability

PTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attacker to execute arbitrary code by sending a malicious request to the network. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVE-2026-12569EPSS 1.2%PTCWindchill and FlexPLM
CISA KEV ↗ · unattributed attribution
high

CVE-2026-20230: Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability

Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) contain a server-side request forgery (SSRF) Vulnerability that could allow an unauthenticated, remote attacker to write files to the underlying operating system that could be used later to elevate to root. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVE-2026-20230EPSS 41.7%CiscoUnified Communications Manager
CISA KEV ↗ · unattributed attribution
high

CVE-2025-67038: Lantronix EDS5000 Code Injection Vulnerability

Lantronix EDS5000 contains a code injection vulnerability that could allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVE-2025-67038EPSS 0.9%EDS5000Lantronix
CISA KEV ↗ · unattributed attribution
high

CVE-2026-34910: Ubiquiti UniFi OS Improper Input Validation Vulnerability

Ubiquiti UniFi OS contains an improper input validation vulnerability which could allow a malicious actor with access to the network to conduct command injection. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVE-2026-34910EPSS 78.6%UbiquitiUniFi OS
CISA KEV ↗ · unattributed attribution
high

CVE-2026-34909: Ubiquiti UniFi OS Path Traversal Vulnerability

Ubiquiti UniFi OS contains a path traversal vulnerability which could allow a malicious actor with access to the network to access files on the underlying system that could be manipulated to access an underlying account. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVE-2026-34909EPSS 2.3%UbiquitiUniFi OS
CISA KEV ↗ · unattributed attribution
high

CVE-2026-34908: Ubiquiti UniFi OS Improper Access Control Vulnerability

Ubiquiti UniFi OS contains an improper access control vulnerability which could allow a malicious actor with access to the network to make unauthorized changes to the system. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVE-2026-34908EPSS 2.5%UbiquitiUniFi OS
CISA KEV ↗ · unattributed attribution
high

CVE-2026-20253: Splunk Enterprise Missing Authentication for Critical Function Vulnerability

Splunk Enterprise contains a missing authentication for critical function vulnerability which could allow an unauthenticated user to create or truncate arbitrary files through a PostgreSQL sidecar service endpoint. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVE-2026-20253EPSS 88.2%EnterpriseSplunk
CISA KEV ↗ · unattributed attribution
high

CVE-2026-48907: Widget Factory Joomla Content Editor Improper Access Control Vulnerability

Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticated users. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVE-2026-48907EPSS 80.4%Joomla Content Editor Widget Factory
CISA KEV ↗ · unattributed attribution
high

CVE-2026-54420: LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability

LiteSpeed cPanel plugin contains a UNIX symbolic link (Symlink) following vulnerability that could allow a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVE-2026-54420EPSS 1.3%LiteSpeedcPanel Plugin
CISA KEV ↗ · unattributed attribution
high

CVE-2026-20262: Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability

Cisco Catalyst SD-WAN Manager contains a directory or path traversal vulnerability that could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVE-2026-20262EPSS 7.7%Catalyst SD-WAN ManagerCisco
CISA KEV ↗ · unattributed attribution
high

CVE-2026-35273: Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability

Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise PeopleTools. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVE-2026-35273EPSS 92.3% PeopleSoft Enterprise PeopleToolsOracle
CISA KEV ↗ · unattributed attribution
high

CVE-2026-10520: Ivanti Sentry OS Command Injection Vulnerability

Ivanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve root-level remote code execution. This vulnerability can be successfully exploited in cases where the Sentry appliance is in an unmanaged state with its endpoints externally reachable. The use of mTLS with EPMM or restricted HTTPS access through Neurons for MDM makes interfaces inaccessible to external actors. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVE-2026-10520EPSS 99.0%IvantiSentry
CISA KEV ↗ · unattributed attribution
high

CVE-2026-11645: Google Chromium V8 Out-of-Bounds Read and Write Vulnerability

Google Chromium V8 out-of-bounds read and write vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-11645EPSS 1.7%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2026-7473: Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability

Arista Extensible Operating System (EOS) contains an incomplete comparison with missing factors vulnerability when the switch incorrectly decapsulate and forwards other unexpected tunneled packet with a destination IP matching its configured decapsulation IP. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-7473EPSS 0.8%AristaExtensible Operating System
CISA KEV ↗ · unattributed attribution
high

CVE-2026-20245: Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability

Cisco Catalyst SD-WAN Manager formerly SD-WAN vManage contains an improper encoding or escaping of output vulnerability. This vulnerability could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-20245EPSS 25.3%Catalyst SD-WAN ManagerCisco
CISA KEV ↗ · unattributed attribution
high

CVE-2026-42271: BerriAI LiteLLM Command Injection Vulnerability

BerriAI LiteLLM contains a command injection vulnerability that could allow any authenticated user, including holders of low-privilege internal-user keys, to run arbitrary commands on the host. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-42271EPSS 80.2%BerriAILiteLLM
CISA KEV ↗ · unattributed attribution
high

CVE-2026-50751: Check Point Security Gateway Improper Authentication Vulnerability

Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-50751EPSS 70.1%Check PointSecurity Gateway
CISA KEV ↗ · unattributed attribution
high

CVE-2026-28318: SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability

SolarWinds Serv-U contains an uncontrolled resource consumption vulnerability that allows specially crafted POST requests using the Content-Encoding: deflate header to crash the Serv-U service without authentication. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-28318EPSS 10.7%Serv-USolarWinds
CISA KEV ↗ · unattributed attribution
high

CVE-2026-45247: Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability

Mirasvit Full Page Cache Warmer contains a deserialization of untrusted data vulnerability that could allow unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-45247EPSS 27.5%MirasvitMirasvit Full Page Cache Warmer
CISA KEV ↗ · unattributed attribution
unknown

Cyber Brief 26-06 - May 2026

Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:CLEAR.

CERT-EU Threat Intelligence ↗ · unattributed attribution
high

CVE-2022-0492: Linux Kernel Improper Authentication Vulnerability

Linux Kernel contains an improper authentication vulnerability which could allow for privilege escalation via the cgroups v1 release_agent feature. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2022-0492EPSS 5.5%KernelLinux
CISA KEV ↗ · unattributed attribution
high

CVE-2025-48595: Android Framework Integer Overflow Vulnerability

Android Framework contains an integer overflow vulnerability that allows for code execution that could allow for local privilege escalation. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-48595EPSS 1.7%AndroidFramework
CISA KEV ↗ · unattributed attribution
high

CVE-2024-21182: Oracle WebLogic Server Unspecified Vulnerability

Oracle WebLogic contains an unspecified vulnerability that could allow an unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2024-21182EPSS 49.7%OracleWebLogic Server
CISA KEV ↗ · unattributed attribution
high

CVE-2026-0257: Palo Alto Networks PAN-OS Authentication Bypass Vulnerability

Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-0257EPSS 86.7%PAN-OSPalo Alto Networks
CISA KEV ↗ · unattributed attribution
high

CVE-2026-48027: Nx Console Embedded Malicious Code Vulnerability

Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload that could harvested credentials from multiple sources on disk and in memory. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-48027EPSS 1.8%NxNx Console
CISA KEV ↗ · unattributed attribution
high

CVE-2026-45321: TanStack Unspecified Vulnerability

TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a trusted identity. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-45321EPSS 2.3%TanStack
CISA KEV ↗ · unattributed attribution
high

CVE-2026-8398: Daemon Tools Lite Embedded Malicious Code Vulnerability

Daemon Tools contains an unspecified vulnerability that has a high impact on confidentiality, integrity, and availability. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-8398EPSS 1.5%DaemonDaemon Tools Lite
CISA KEV ↗ · unattributed attribution
high

CVE-2026-48172: LiteSpeed cPanel Plugin Privilege Escalation Vulnerability

LiteSpeed cPanel Plugin contains privilege escalation vulnerability that is exposed via the user-end cPanel plugin, which can be abused by any cPanel user account to execute arbitrary scripts with root privileges. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-48172EPSS 18.9%LiteSpeedcPanel Plugin
CISA KEV ↗ · unattributed attribution
high

CVE-2026-9082: Drupal Core SQL Injection Vulnerability

Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-9082EPSS 84.6%CoreDrupal
CISA KEV ↗ · unattributed attribution
high

CVE-2025-34291: Langflow Origin Validation Error Vulnerability

Langflow contains an origin validation error vulnerability in which an overly permissive CORS configuration combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform cross-origin requests that include credentials and successfully call the refresh endpoint. This could allow the attacker to execute arbitrary code and achieve full system compromise via obtained tokens that permit access to authenticated endpoints. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-34291EPSS 78.9%Langflow
CISA KEV ↗ · unattributed attribution
high

CVE-2026-34926: Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability

Trend Micro Apex One (on-premise) contains a directory traversal vulnerability that could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-34926EPSS 12.7%Apex OneTrend Micro
CISA KEV ↗ · unattributed attribution
high

CVE-2008-4250: Microsoft Windows Buffer Overflow Vulnerability

Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2008-4250EPSS 98.8%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2009-1537: Microsoft DirectX NULL Byte Overwrite Vulnerability

Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitrary code via a crafted QuickTime media file. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2009-1537EPSS 51.2%DirectXMicrosoft
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2009-3459: Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability

Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability which could allow remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2009-3459EPSS 86.6%Acrobat and ReaderAdobe
CISA KEV ↗ · unattributed attribution
high

CVE-2010-0249: Microsoft Internet Explorer Use-After-Free Vulnerability

Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2010-0249EPSS 91.9%Internet ExplorerMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2010-0806: Microsoft Internet Explorer Use-After-Free Vulnerability

Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2010-0806EPSS 82.2%Internet ExplorerMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2026-41091: Microsoft Defender Link Following Vulnerability

Microsoft Defender contains a link following vulnerability that allows an authorized attacker to elevate privileges locally. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-41091EPSS 8.4%DefenderMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2026-45498: Microsoft Defender Denial of Service Vulnerability

Microsoft Defender contains an unspecified vulnerability that allows for denial of service. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-45498EPSS 63.1%DefenderMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2026-42897: Microsoft Exchange Server Cross-Site Scripting Vulnerability

Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-42897EPSS 5.6%Microsoft
CISA KEV ↗ · unattributed attribution
high

CVE-2026-20182: Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability

Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. Required action: Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlined in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.

CVE-2026-20182EPSS 88.5%Catalyst SD-WANCisco
CISA KEV ↗ · unattributed attribution
unknown

ATT&CK profile: APT28

[APT28](https://attack.mitre.org/groups/G0007) is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165.(Citation: NSA/FBI Drovorub August 2020)(Citation: Cybersecurity Advisory GRU Brute Force Campaign July 2021) This group has been active since at least 2004.(Citation: DOJ GRU Indictment Jul 2018)(Citation: Ars Technica GRU indictment Jul 2018)(Citation: Crowdstrike DNC June 2016)(Citation: FireEye APT28)(Citation: SecureWorks TG-4127)(Citation: FireEye APT28 January 2017)(Citation: GRIZZLY STEPPE JAR)(Citation: Sofacy DealersChoice)(Citation: Palo Alto Sofacy 06-2018)(Citation: Symantec APT28 Oct 2018)(Citation: ESET Zebrocy May 2019) [APT28](https://attack.mitre.org/groups/G0007) reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U.S. president

Sandworm TeamAPT28Group 74IRON TWILIGHT
MITRE ATT&CK ↗ · confirmed attribution · 1 IOC
high

CVE-2026-42208: BerriAI LiteLLM SQL Injection Vulnerability

BerriAI LiteLLM contains a SQL injection vulnerability that allows an attacker to read data from the proxy's database and potentially modify it, leading to unauthorized access to the proxy and the credentials it manages. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-42208EPSS 86.6%BerriAILiteLLM
CISA KEV ↗ · unattributed attribution
high

CVE-2026-6973: Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability

Ivanti Endpoint Manager Mobile (EPMM) contains an improper input validation vulnerability that allows a remotely authenticated user with administrative access to achieve remote code execution. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-6973EPSS 34.5%Endpoint Manager Mobile (EPMM)Ivanti
CISA KEV ↗ · unattributed attribution
high

CVE-2026-0300: Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability

Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Until the vendor releases an official fix, the following workaround should be implemented: - Restrict User-ID Authentication Portal access to only trusted zones. - Disable User-ID Authentication Portal if not required. 5/13/2026: Palo Alto has released a variety of patches. If these are relevant to your environment, please apply the designated patch.

CVE-2026-0300EPSS 32.1%PAN-OSPalo Alto Networks
CISA KEV ↗ · unattributed attribution
unknown

Cyber Brief 26-05 - April 2026

Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:CLEAR.

CERT-EU Threat Intelligence ↗ · unattributed attribution
high

CVE-2026-31431: Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability

Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation. Required action: "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-31431EPSS 96.3%KernelLinux
CISA KEV ↗ · unattributed attribution
high

CVE-2026-41940: WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability

WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-41940EPSS 98.1%WebProscPanel & WHM and WP2 (WordPress Squared)
CISA KEV ↗ · unattributed attribution
high

CVE-2024-1708: ConnectWise ScreenConnect Path Traversal Vulnerability

ConnectWise ScreenConnect contains a path traversal vulnerability which could allow an attacker to execute remote code or directly impact confidential data and critical systems. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2024-1708EPSS 87.6%ConnectWiseScreenConnect
CISA KEV ↗ · unattributed attribution
high

CVE-2026-32202: Microsoft Windows Protection Mechanism Failure Vulnerability

Microsoft Windows Shell contains a protection mechanism failure vulnerability that allows an unauthorized attacker to perform spoofing over a network. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-32202EPSS 64.1%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-29635: D-Link DIR-823X Command Injection Vulnerability

D-Link DIR-823X contains a command injection vulnerability that allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-29635EPSS 87.2%D-LinkDIR-823X
CISA KEV ↗ · unattributed attribution
high

CVE-2024-7399: Samsung MagicINFO 9 Server Path Traversal Vulnerability

Samsung MagicINFO 9 Server contains a path traversal vulnerability that could allow an attacker to write arbitrary files as system authority. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2024-7399EPSS 91.9%MagicINFO 9 ServerSamsung
CISA KEV ↗ · unattributed attribution
high

CVE-2024-57728: SimpleHelp Path Traversal Vulnerability

SimpleHelp contains a path traversal vulnerability that allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2024-57728EPSS 7.5%SimpleHelpSimpleHelp
CISA KEV ↗ · unattributed attribution
high

CVE-2024-57726: SimpleHelp Missing Authorization Vulnerability

SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2024-57726EPSS 9.3%SimpleHelpSimpleHelp
CISA KEV ↗ · unattributed attribution
high

CVE-2026-39987: Marimo Remote Code Execution Vulnerability

Marimo contains an pre-authorization remote code execution vulnerability, allowing an unauthenticated attacked to shell access and execute arbitrary system commands. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-39987EPSS 95.6%Marimo
CISA KEV ↗ · unattributed attribution
high

CVE-2026-33825: Microsoft Defender Insufficient Granularity of Access Control Vulnerability

Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-33825EPSS 6.7%DefenderMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2026-20122: Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability

Cisco Catalyst SD-WAN Manager contains an incorrect use of privileged APIs vulnerability due to improper file handling on the API interface of an affected system. An attacker could exploit this vulnerability by uploading a malicious file on the local file system. A successful exploit could allow the attacker to overwrite arbitrary files on the affected system and gain vmanage user privileges. Required action: Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.

CVE-2026-20122EPSS 7.0%Catalyst SD-WAN MangerCisco
CISA KEV ↗ · unattributed attribution
high

CVE-2026-20133: Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability

Cisco Catalyst SD-WAN Manager contains an exposure of sensitive information to an unauthorized actor vulnerability that could allow remote attackers to view sensitive information on affected systems. Required action: Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.

CVE-2026-20133EPSS 10.2%Catalyst SD-WAN ManagerCisco
CISA KEV ↗ · unattributed attribution
high

CVE-2025-2749: Kentico Xperience Path Traversal Vulnerability

Kentico Xperience contains a path traversal vulnerability that could allow an authenticated user's Staging Sync Server to upload arbitrary data to path relative locations. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-2749EPSS 3.9%KenticoKentico Xperience
CISA KEV ↗ · unattributed attribution
high

CVE-2023-27351: PaperCut NG/MF Improper Authentication Vulnerability

PaperCut NG/MF contains an improper authentication vulnerability that could allow remote attackers to bypass authentication on affected installations via the SecurityRequestFilter class. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2023-27351EPSS 77.4%NG/MFPaperCut
CISA KEV ↗ · unattributed attribution
high

CVE-2025-48700: Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability

Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that could allow attackers to execute arbitrary JavaScript within the user's session, potentially leading to unauthorized access to sensitive information. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-48700EPSS 1.8%SynacorZimbra Collaboration Suite (ZCS)
CISA KEV ↗ · unattributed attribution
high

CVE-2026-20128: Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability

Cisco Catalyst SD-WAN Manager contains a storing passwords in a recoverable format vulnerability that allows an authenticated, local attacker to gain DCA user privileges by accessing a credential file for the DCA user on the filesystem as a low-privileged user. Required action: Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.

CVE-2026-20128EPSS 5.3%Catalyst SD-WAN ManagerCisco
CISA KEV ↗ · unattributed attribution
high

CVE-2025-32975: Quest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability

Quest KACE Systems Management Appliance (SMA) contains an improper authentication vulnerability that could allow attackers to impersonate legitimate users without valid credentials. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-32975EPSS 2.4%KACE Systems Management Appliance (SMA)Quest
CISA KEV ↗ · unattributed attribution
high

CVE-2024-27199: JetBrains TeamCity Relative Path Traversal Vulnerability

JetBrains TeamCity contains a relative path traversal vulnerability that could allow limited admin actions to be performed. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2024-27199EPSS 100.0%JetBrainsTeamCity
CISA KEV ↗ · unattributed attribution
high

CVE-2026-34197: Apache ActiveMQ Improper Input Validation Vulnerability

Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-34197EPSS 96.7%ActiveMQApache
CISA KEV ↗ · unattributed attribution
high

CVE-2009-0238: Microsoft Office Remote Code Execution

Microsoft Office Excel contains a remote code execution vulnerability that could allow an attacker to take complete control of an affected system if a user opens a specially crafted Excel file that includes a malformed object. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2009-0238EPSS 43.1%MicrosoftOffice
CISA KEV ↗ · unattributed attribution
high

CVE-2026-32201: Microsoft SharePoint Server Improper Input Validation Vulnerability

Microsoft SharePoint Server contains an improper input validation vulnerability that allows an unauthorized attacker to perform spoofing over a network. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-32201EPSS 22.8%MicrosoftSharePoint Server
CISA KEV ↗ · unattributed attribution
high

CVE-2012-1854: Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability

Microsoft Visual Basic for Applications (VBA) contains an insecure library loading vulnerability that could allow for remote code execution. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2012-1854EPSS 21.0%MicrosoftVisual Basic for Applications (VBA)
CISA KEV ↗ · unattributed attribution
high

CVE-2025-60710: Microsoft Windows Link Following Vulnerability

Microsoft Windows contains a link following vulnerability that allows for privilege escalation Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-60710EPSS 4.7%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2023-21529: Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability

Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2023-21529EPSS 62.1%Exchange ServerMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2023-36424: Microsoft Windows Out-of-Bounds Read Vulnerability

Microsoft Windows Common Log File System Driver contains an out-of-bounds read vulnerability that could allow a threat actor for privileges escalation Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2023-36424EPSS 12.2%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2020-9715: Adobe Acrobat Use-After-Free Vulnerability

Adobe Acrobat contains a use-after-free vulnerability that allows for code execution Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2020-9715EPSS 48.4%AcrobatAdobe
CISA KEV ↗ · unattributed attribution
high

CVE-2026-21643: Fortinet FortiClient EMS SQL Injection Vulnerability

Fortinet FortiClient EMS contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-21643EPSS 94.1%FortiClient EMSFortinet
CISA KEV ↗ · unattributed attribution
high

CVE-2026-34621: Adobe Acrobat and Reader Prototype Pollution Vulnerability

Adobe Acrobat and Reader contain a prototype pollution vulnerability that allows for arbitrary code execution. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-34621EPSS 7.1%Acrobat and ReaderAdobe
CISA KEV ↗ · unattributed attribution
high

CVE-2026-1340: Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability

Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-1340EPSS 84.0%Endpoint Manager Mobile (EPMM)Ivanti
CISA KEV ↗ · unattributed attribution
high

CVE-2026-35616: Fortinet FortiClient EMS Improper Access Control Vulnerability

Fortinet FortiClient EMS contains an improper access control vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-35616EPSS 88.5%FortiClient EMSFortinet
CISA KEV ↗ · unattributed attribution
high

CVE-2026-3502: TrueConf Client Download of Code Without Integrity Check Vulnerability

TrueConf Client contains a download of code without integrity check vulnerability. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the payload is executed or installed by the updater, this may result in arbitrary code execution in the context of the updating process or user. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-3502EPSS 5.8%ClientTrueConf
CISA KEV ↗ · unattributed attribution
unknown

Cyber Brief 26-04 - March 2026

Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:CLEAR.

CERT-EU Threat Intelligence ↗ · unattributed attribution
high

CVE-2026-5281: Google Dawn Use-After-Free Vulnerability

Google Dawn contains an use-after-free vulnerability that could allow a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. This vulnerability could affect multiple Chromium-based products including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-5281EPSS 5.0%DawnGoogle
CISA KEV ↗ · unattributed attribution
high

CVE-2026-3055: Citrix NetScaler Out-of-Bounds Read Vulnerability

Citrix NetScaler ADC (formerly Citrix ADC), NetScaler Gateway (formerly Citrix Gateway) and NetScaler ADC FIPS and NDcPP contain an out-of-bounds reads vulnerability when configured as a SAML IDP leading to memory overread. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-3055EPSS 84.0%CitrixNetScaler
CISA KEV ↗ · unattributed attribution
high

CVE-2025-53521: F5 BIG-IP Stack-Based Buffer Overflow Vulnerability

F5 BIG-IP APM contains a stack-based buffer overflow vulnerability that could allow a threat actor to achieve remote code execution. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-53521EPSS 2.2%BIG-IPF5
CISA KEV ↗ · unattributed attribution
high

CVE-2026-33634: Aquasecurity Trivy Embedded Malicious Code Vulnerability

Aquasecurity Trivy contains an embedded malicious code vulnerability that could allow an attacker to gain access to everything in the CI/CD environment, including all tokens, SSH keys, cloud credentials, database passwords, and any sensitive configuration in memory. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-33634EPSS 60.4%AquasecurityTrivy
CISA KEV ↗ · unattributed attribution
high

CVE-2026-33017: Langflow Code Injection Vulnerability

Langflow contains a code injection vulnerability that could allow building public flows without requiring authentication. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-33017EPSS 98.2%Langflow
CISA KEV ↗ · unattributed attribution
high

CVE-2025-32432: Craft CMS Code Injection Vulnerability

Craft CMS contains a code injection vulnerability that allows a remote attacker to execute arbitrary code. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-32432EPSS 99.8%Craft CMS
CISA KEV ↗ · unattributed attribution
high

CVE-2025-54068: Laravel Livewire Code Injection Vulnerability

Laravel Livewire contain a code injection vulnerability that could allow unauthenticated attackers to achieve remote command execution in specific scenarios. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-54068EPSS 95.4%LaravelLivewire
CISA KEV ↗ · unattributed attribution
high

CVE-2025-43510: Apple Multiple Products Improper Locking Vulnerability

Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain an improper locking vulnerability that could allow a malicious application to cause unexpected changes in memory shared between processes. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-43510EPSS 0.4%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2025-43520: Apple Multiple Products Classic Buffer Overflow Vulnerability

Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain a classic buffer overflow vulnerability which could allow a malicious application to cause unexpected system termination or write kernel memory. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-43520EPSS 0.4%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2025-31277: Apple Multiple Products Buffer Overflow Vulnerability

Apple Safari, iOS, watchOS, visionOS, iPadOS, macOS, and tvOS contain a buffer overflow vulnerability that could allow the processing of maliciously crafted web content which may lead to memory corruption. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-31277EPSS 1.5%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2026-20131: Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability

Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain a deserialization of untrusted data vulnerability in the web-based management interface that could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-20131EPSS 27.6%CiscoSecure Firewall Management Center (FMC)
CISA KEV ↗ · unattributed attribution
high

CVE-2025-66376: Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability

Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability in the Classic UI where attackers could abuse Cascading Style Sheets (CSS) @import directives in email HTML. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-66376EPSS 12.0%SynacorZimbra Collaboration Suite (ZCS)
CISA KEV ↗ · unattributed attribution
high

CVE-2026-20963: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-20963EPSS 29.4%MicrosoftSharePoint
CISA KEV ↗ · unattributed attribution
high

CVE-2025-47813: Wing FTP Server Information Disclosure Vulnerability

Wing FTP Server contains a generation of error message containing sensitive information vulnerability when using a long value in the UID cookie. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-47813EPSS 56.4%Wing FTP Server
CISA KEV ↗ · unattributed attribution
high

CVE-2026-3910: Google Chromium V8 Improper Restriction of Operations Within the Bounds of a Memory Buffer Vulnerability

Google Chromium V8 contains an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-3910EPSS 2.0%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2026-3909: Google Skia Out-of-Bounds Write Vulnerability

Google Skia contains an out-of-bounds write vulnerability that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability affects Google Chrome and ChromeOS, Android, Flutter, and possibly other products. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-3909EPSS 1.6%GoogleSkia
CISA KEV ↗ · unattributed attribution
high

CVE-2025-68613: n8n Improper Control of Dynamically-Managed Code Resources Vulnerability

n8n contains an improper control of dynamically managed code resources vulnerability in its workflow expression evaluation system that allows for remote code execution. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-68613EPSS 97.9%n8n
CISA KEV ↗ · unattributed attribution
high

CVE-2021-22054: Omnissa Workspace ONE Server-Side Request Forgery

Omnissa Workspace One UEM formerly known as VMware Workspace One UEM contains a server-side request forgery (SSRF) vulnerability that could allow a malicious actor with network access to UEM to send their requests without authentication and to gain access to sensitive information. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2021-22054EPSS 97.7%OmnissaWorkspace One UEM
CISA KEV ↗ · unattributed attribution
high

CVE-2025-26399: SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability

SolarWinds Web Help Desk contain a deserialization of untrusted data vulnerability in AjaxProxy that could allow an attacker to run commands on the host machine. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-26399EPSS 88.3%SolarWindsWeb Help Desk
CISA KEV ↗ · unattributed attribution
high

CVE-2026-1603: Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability

Ivanti Endpoint Manager (EPM) contains an authentication bypass using an alternate path or channel vulnerability that could allow a remote unauthenticated attacker to leak specific stored credential data. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-1603EPSS 80.6% Endpoint Manager (EPM)Ivanti
CISA KEV ↗ · unattributed attribution
high

CVE-2017-7921: Hikvision Multiple Products Improper Authentication Vulnerability

Multiple Hikvision products contain an improper authentication vulnerability that could allow a malicious user to escalate privileges on the system and gain access to sensitive information. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2017-7921EPSS 100.0%HikvisionMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2021-22681: Rockwell Multiple Products Insufficient Protected Credentials Vulnerability

Multiple Rockwell products contain an insufficient protected credentials vulnerability. Studio 5000 Logix Designer software may allow a key to be discovered. This key is used to verify Logix controllers are communicating with Rockwell Automation design software. If successfully exploited, this vulnerability could allow an unauthorized application to connect with Logix controllers. To leverage this vulnerability, an unauthorized user would require network access to the controller. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2021-22681EPSS 25.5%Multiple ProductsRockwell
CISA KEV ↗ · unattributed attribution
high

CVE-2023-43000: Apple Multiple products Use-After-Free Vulnerability

Apple macOS, iOS, iPadOS, and Safari 16.6 contain a use-after-free vulnerability due to the processing of maliciously crafted web content that may lead to memory corruption. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2023-43000EPSS 4.0%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2021-30952: Apple Multiple Products Integer Overflow or Wraparound Vulnerability

Apple tvOS, macOS, Safari, iPadOS and watchOS contain an integer overflow or wraparound vulnerability due to the processing of maliciously crafted web content that may lead to arbitrary code execution. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2021-30952EPSS 7.6%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2023-41974: Apple iOS and iPadOS Use-After-Free Vulnerability

Apple iOS and iPadOS contain a use-after-free vulnerability. An app may be able to execute arbitrary code with kernel privileges. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2023-41974EPSS 1.4%AppleiOS and iPadOS
CISA KEV ↗ · unattributed attribution
high

CVE-2026-22719: Broadcom VMware Aria Operations Command Injection Vulnerability

Broadcom VMware Aria Operations formerly known as vRealize Operations (vROps) contains a command injection vulnerability that allows an unauthenticated attacker to execute arbitrary commands, potentially leading to remote code execution during support‑assisted product migration. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-22719EPSS 17.4%BroadcomVMware Aria Operations
CISA KEV ↗ · unattributed attribution
high

CVE-2026-21385: Qualcomm Multiple Chipsets Memory Corruption Vulnerability

Multiple Qualcomm chipsets contain a memory corruption vulnerability while using alignments for memory allocation. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-21385EPSS 1.1%Multiple ChipsetsQualcomm
CISA KEV ↗ · unattributed attribution
unknown

Cyber Brief 26-03 - February 2026

Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:CLEAR.

CERT-EU Threat Intelligence ↗ · unattributed attribution
high

CVE-2022-20775: Cisco SD-WAN Path Traversal Vulnerability

Cisco SD-WAN CLI contains a path traversal vulnerability that could allow an authenticated local attacker to gain elevated privileges via improper access controls on commands within the application CLI. A successful exploit could allow the attacker to execute arbitrary commands as the root user. Required action: Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.

CVE-2022-20775EPSS 12.5%CiscoSD-WAN
CISA KEV ↗ · unattributed attribution
high

CVE-2026-20127: Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability

Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, contain an authentication bypass vulnerability could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to an affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric. Required action: Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (UR

CVE-2026-20127EPSS 57.8%Catalyst SD-WAN Controller and ManagerCisco
CISA KEV ↗ · unattributed attribution
high

CVE-2026-25108: Soliton Systems K.K FileZen OS Command Injection Vulnerability

Soliton Systems K.K FileZen contains an OS command injection vulnerability when an user logs-in to the affected product and sends a specially crafted HTTP request. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-25108EPSS 5.0%FileZenSoliton Systems K.K
CISA KEV ↗ · unattributed attribution
high

CVE-2025-49113: RoundCube Webmail Deserialization of Untrusted Data Vulnerability

RoundCube Webmail contains a deserialization of untrusted data vulnerability that allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-49113EPSS 94.7%RoundcubeWebmail
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2025-68461: RoundCube Webmail Cross-site Scripting Vulnerability

RoundCube Webmail contains a cross-site scripting vulnerability via the animate tag in an SVG document. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-68461EPSS 20.1%RoundcubeWebmail
CISA KEV ↗ · unattributed attribution
high

CVE-2021-22175: GitLab Server-Side Request Forgery (SSRF) Vulnerability

GitLab contains a server-side request forgery (SSRF) vulnerability when requests to the internal network for webhooks are enabled. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2021-22175EPSS 53.4%GitLab
CISA KEV ↗ · unattributed attribution
high

CVE-2026-22769: Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability

Dell RecoverPoint for Virtual Machines (RP4VMs) contains an use of hard-coded credentials vulnerability that could allow an unauthenticated remote attacker to gain unauthorized access to the underlying operating system and root-level persistence. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-22769EPSS 13.1%DellRecoverPoint for Virtual Machines (RP4VMs)
CISA KEV ↗ · unattributed attribution
high

CVE-2020-7796: Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability

Synacor Zimbra Collaboration Suite (ZCS) contains a server-side request forgery vulnerability if WebEx zimlet installed and zimlet JSP is enabled. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2020-7796EPSS 84.6%SynacorZimbra Collaboration Suite
CISA KEV ↗ · unattributed attribution
high

CVE-2024-7694: TeamT5 ThreatSonar Anti-Ransomware Unrestricted Upload of File with Dangerous Type Vulnerability

TeamT5 ThreatSonar Anti-Ransomware contains an unrestricted upload of file with dangerous type vulnerability. ThreatSonar Anti-Ransomware does not properly validate the content of uploaded files. Remote attackers with administrator privileges on the product platform can upload malicious files, which can be used to execute arbitrary system commands on the server. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2024-7694EPSS 1.8%TeamT5ThreatSonar Anti-Ransomware
CISA KEV ↗ · unattributed attribution
high

CVE-2008-0015: Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability

Microsoft Windows Video ActiveX Control contains a remote code execution vulnerability. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2008-0015EPSS 76.7%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2026-2441: Google Chromium CSS Use-After-Free Vulnerability

Google Chromium CSS contains a use-after-free vulnerability that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-2441EPSS 22.0%ChromiumGoogle
CISA KEV ↗ · unattributed attribution
high

CVE-2026-1731: BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability

BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)contain an OS command injection vulnerability. Successful exploitation could allow an unauthenticated remote attacker to execute operating system commands in the context of the site user. Successful exploitation requires no authentication or user interaction and may lead to system compromise, including unauthorized access, data exfiltration, and service disruption. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-1731EPSS 88.1%BeyondTrustRemote Support (RS) and Privileged Remote Access (PRA)
CISA KEV ↗ · unattributed attribution
high

CVE-2026-20700: Apple Multiple Buffer Overflow Vulnerability

Apple iOS, macOS, tvOS, watchOS, and visionOS contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow an attacker with memory write the capability to execute arbitrary code. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-20700EPSS 1.3%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2024-43468: Microsoft Configuration Manager SQL Injection Vulnerability

Microsoft Configuration Manager contains an SQL injection vulnerability. An unauthenticated attacker could exploit this vulnerability by sending specially crafted requests to the target environment which are processed in an unsafe manner enabling the attacker to execute commands on the server and/or underlying database. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2024-43468EPSS 61.1%Configuration ManagerMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2025-15556: Notepad++ Download of Code Without Integrity Check Vulnerability

Notepad++ when using the WinGUp updater, contains a download of code without integrity check vulnerability that could allow an attacker to intercept or redirect update traffic to download and execute an attacker-controlled installer. This could lead to arbitrary code execution with the privileges of the user. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-15556EPSS 1.3%Notepad++
CISA KEV ↗ · unattributed attribution
high

CVE-2025-40536: SolarWinds Web Help Desk Security Control Bypass Vulnerability

SolarWinds Web Help Desk contains a security control bypass vulnerability that could allow an unauthenticated attacker to gain access to certain restricted functionality. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-40536EPSS 81.6%SolarWindsWeb Help Desk
CISA KEV ↗ · unattributed attribution
high

CVE-2026-21513: Microsoft MSHTML Framework Protection Mechanism Failure Vulnerability

Microsoft MSHTML Framework contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-21513EPSS 15.4%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2026-21525: Microsoft Windows NULL Pointer Dereference Vulnerability

Microsoft Windows Remote Access Connection Manager contains a NULL pointer dereference that could allow an unauthorized attacker to deny service locally. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-21525EPSS 5.0%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2026-21510: Microsoft Windows Shell Protection Mechanism Failure Vulnerability

Microsoft Windows Shell contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-21510EPSS 25.8%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2026-21533: Microsoft Windows Improper Privilege Management Vulnerability

Microsoft Windows Remote Desktop Services contains an improper privilege management vulnerability that could allow an authorized attacker to elevate privileges locally. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-21533EPSS 3.8%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2026-21519: Microsoft Windows Type Confusion Vulnerability

Microsoft Desktop Windows Manager contains a type confusion vulnerability that could allow an authorized attacker to elevate privileges locally. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-21519EPSS 2.4%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2026-21514: Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability

Microsoft Office Word contains a reliance on untrusted inputs in a security decision vulnerability that could allow an authorized attacker to elevate privileges locally. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-21514EPSS 1.5%MicrosoftOffice
CISA KEV ↗ · unattributed attribution
high

CVE-2025-11953: React Native Community CLI OS Command Injection Vulnerability

React Native Community CLI contains an OS command injection vulnerability which could allow unauthenticated network attackers to send POST requests to the Metro Development Server and run arbitrary executables via a vulnerable endpoint exposed by the server. On Windows, attackers can also execute arbitrary shell commands with fully controlled arguments. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-11953EPSS 62.4%CLIReact Native Community
CISA KEV ↗ · unattributed attribution
high

CVE-2026-24423: SmarterTools SmarterMail Missing Authentication for Critical Function Vulnerability

SmarterTools SmarterMail contains a missing authentication for critical function vulnerability in the ConnectToHub API method. This could allow the attacker to point the SmarterMail instance to a malicious HTTP server which serves the malicious OS command and could lead to command execution. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-24423EPSS 87.7%SmarterMailSmarterTools
CISA KEV ↗ · unattributed attribution
high

CVE-2021-39935: GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability

GitLab Community and Enterprise Editions contain a server-side request forgery vulnerability which could allow unauthorized external users to perform Server Side Requests via the CI Lint API. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2021-39935EPSS 35.6%Community and Enterprise EditionsGitLab
CISA KEV ↗ · unattributed attribution
high

CVE-2025-64328: Sangoma FreePBX OS Command Injection Vulnerability

Sangoma FreePBX Endpoint Manager contains an OS command injection vulnerability that could allow for a post-authentication command injection by an authenticated known user via the testconnection -> check_ssh_connect() function. An attacker can leverage this vulnerability to potentially obtain remote access to the system as an asterisk user. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-64328EPSS 84.6%FreePBX Sangoma
CISA KEV ↗ · unattributed attribution
high

CVE-2019-19006: Sangoma FreePBX Improper Authentication Vulnerability

Sangoma FreePBX contains an improper authentication vulnerability that potentially allows unauthorized users to bypass password authentication and access services provided by the FreePBX admin. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2019-19006EPSS 36.6%FreePBXSangoma
CISA KEV ↗ · unattributed attribution
high

CVE-2025-40551: SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability

SolarWinds Web Help Desk contains a deserialization of untrusted data vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-40551EPSS 84.1%SolarWindsWeb Help Desk
CISA KEV ↗ · unattributed attribution
unknown

Cyber Brief 26-02 - January 2026

Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:CLEAR.

CERT-EU Threat Intelligence ↗ · unattributed attribution
high

CVE-2026-1281: Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability

Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-1281EPSS 81.2%Endpoint Manager Mobile (EPMM)Ivanti
CISA KEV ↗ · unattributed attribution
high

CVE-2026-24858: Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability

Fortinet FortiAnalyzer, FortiManager, FortiOS, and FortiProxy contain an authentication bypass using an alternate path or channel that could allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-24858EPSS 85.8%FortinetMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2018-14634: Linux Kernel Integer Overflow Vulnerability

Linux Kernel contains an integer overflow vulnerability in the create_elf_tables() function which could allow an unprivileged local user with access to SUID (or otherwise privileged) binary to escalate their privileges on the system. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2018-14634EPSS 14.8%KernelLinux
CISA KEV ↗ · unattributed attribution
high

CVE-2025-52691: SmarterTools SmarterMail Unrestricted Upload of File with Dangerous Type Vulnerability

SmarterTools SmarterMail contains an unrestricted upload of file with dangerous type vulnerability that could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-52691EPSS 85.5%SmarterMailSmarterTools
CISA KEV ↗ · unattributed attribution
high

CVE-2026-23760: SmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel Vulnerability

SmarterTools SmarterMail contains an authentication bypass using an alternate path or channel vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a reset token when resetting system administrator accounts. This could allow an unauthenticated attacker to supply a target administrator username and a new password to reset the account, resulting in full administrative compromise of the SmarterMail instance. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-23760EPSS 96.3%SmarterMailSmarterTools
CISA KEV ↗ · unattributed attribution
high

CVE-2026-24061: GNU InetUtils Argument Injection Vulnerability

GNU InetUtils contains an argument injection vulnerability in telnetd that could allow for remote authentication bypass via a "-f root" value for the USER environment variable. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-24061EPSS 98.9%GNUInetUtils
CISA KEV ↗ · unattributed attribution
high

CVE-2026-21509: Microsoft Office Security Feature Bypass Vulnerability

Microsoft Office contains a security feature bypass vulnerability in which reliance on untrusted inputs in a security decision in Microsoft Office could allow an unauthorized attacker to bypass a security feature locally. Some of the impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-21509EPSS 72.2%MicrosoftOffice
CISA KEV ↗ · unattributed attribution
high

CVE-2024-37079: Broadcom VMware vCenter Server Out-of-bounds Write Vulnerability

Broadcom VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. This could allow a malicious actor with network access to vCenter Server to send specially crafted network packets, potentially leading to remote code execution. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2024-37079EPSS 22.4%BroadcomVMware vCenter Server
CISA KEV ↗ · unattributed attribution
high

CVE-2025-68645: Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability

Synacor Zimbra Collaboration Suite (ZCS) contains a PHP remote file inclusion vulnerability that could allow for remote attackers to craft requests to the /h/rest endpoint to influence internal request dispatching, allowing inclusion of arbitrary files from the WebRoot directory. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-68645EPSS 31.8% Zimbra Collaboration Suite (ZCS)Synacor
CISA KEV ↗ · unattributed attribution
high

CVE-2025-34026: Versa Concerto Improper Authentication Vulnerability

Versa Concerto SD-WAN orchestration platform contains an improper authentication vulnerability in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The internal Actuator endpoint can be leveraged for access to heap dumps and trace logs. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-34026EPSS 83.5%ConcertoVersa
CISA KEV ↗ · unattributed attribution
high

CVE-2025-31125: Vite Vitejs Improper Access Control Vulnerability

Vite Vitejs contains an improper access control vulnerability that exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicitly exposing the Vite dev server to the network (using --host or server.host config option) are affected. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-31125EPSS 58.8%ViteVitejs
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2025-54313: Prettier eslint-config-prettier Embedded Malicious Code Vulnerability

Prettier eslint-config-prettier contains an embedded malicious code vulnerability. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-54313EPSS 4.1%Prettiereslint-config-prettier
CISA KEV ↗ · unattributed attribution · 2 IOCs
high

CVE-2026-20045: Cisco Unified Communications Products Code Injection Vulnerability

Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unity Connection, and Cisco Webex Calling Dedicated Instance contain a code injection vulnerability that could allow the attacker to obtain user-level access to the underlying operating system and then elevate privileges to root. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-20045EPSS 4.3%CiscoUnified Communications Manager
CISA KEV ↗ · unattributed attribution
high

CVE-2026-20805: Microsoft Windows Information Disclosure Vulnerability

Microsoft Windows Desktop Windows Manager contains an information disclosure vulnerability that allows an authorized attacker to disclose information locally. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-20805EPSS 5.0%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-8110: Gogs Path Traversal Vulnerability

Gogs contains a path traversal vulnerability affecting improper Symbolic link handling in the PutContents API that could allow for code execution. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-8110EPSS 76.5%Gogs
CISA KEV ↗ · unattributed attribution
high

CVE-2009-0556: Microsoft Office PowerPoint Code Injection Vulnerability

Microsoft Office PowerPoint contains a code injection vulnerability that allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing an invalid index value that triggers memory corruption. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2009-0556EPSS 67.5%MicrosoftOffice
CISA KEV ↗ · unattributed attribution
high

CVE-2025-37164: Hewlett Packard Enterprise (HPE) OneView Code Injection Vulnerability

Hewlett Packard Enterprise (HPE) OneView contains a code injection vulnerability that allows a remote unauthenticated user to perform remote code execution. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-37164EPSS 89.7%Hewlett Packard Enterprise (HPE)OneView
CISA KEV ↗ · unattributed attribution
unknown

Cyber Brief 26-01 - December 2025

Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:CLEAR.

CERT-EU Threat Intelligence ↗ · unattributed attribution
high

CVE-2025-14847: MongoDB and MongoDB Server Improper Handling of Length Parameter Inconsistency Vulnerability

MongoDB Server contains an improper handling of length parameter inconsistency vulnerability in Zlib compressed protocol headers. This vulnerability may allow a read of uninitialized heap memory by an unauthenticated client. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-14847EPSS 83.0%MongoDBMongoDB and MongoDB Server
CISA KEV ↗ · unattributed attribution
high

CVE-2023-52163: Digiever DS-2105 Pro Missing Authorization Vulnerability

Digiever DS-2105 Pro contains a missing authorization vulnerability which could allow for command injection via time_tzsetup.cgi. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2023-52163EPSS 97.0%DS-2105 ProDigiever
CISA KEV ↗ · unattributed attribution
high

CVE-2025-14733: WatchGuard Firebox Out of Bounds Write Vulnerability

WatchGuard Fireware OS iked process contains an out of bounds write vulnerability in the OS iked process. This vulnerability may allow a remote unauthenticated attacker to execute arbitrary code and affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-14733EPSS 18.0%FireboxWatchGuard
CISA KEV ↗ · unattributed attribution
high

CVE-2025-59374: ASUS Live Update Embedded Malicious Code Vulnerability

ASUS Live Update contains an embedded malicious code vulnerability client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause devices meeting specific targeting conditions to perform unintended actions. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-59374EPSS 1.1%ASUSLive Update
CISA KEV ↗ · unattributed attribution
high

CVE-2025-40602: SonicWall SMA1000 Missing Authorization Vulnerability

SonicWall SMA1000 contains a missing authorization vulnerability that could allow for privilege escalation appliance management console (AMC) of affected devices. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable

CVE-2025-40602EPSS 1.9%SMA1000 applianceSonicWall
CISA KEV ↗ · unattributed attribution
high

CVE-2025-20393: Cisco Multiple Products Improper Input Validation Vulnerability

Cisco Secure Email Gateway, Secure Email, AsyncOS Software, and Web Manager appliances contains an improper input validation vulnerability that allows threat actors to execute arbitrary commands with root privileges on the underlying operating system of an affected appliance. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-20393EPSS 29.5%CiscoMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2025-59718: Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability

Fortinet FortiOS, FortiSwitchMaster, FortiProxy, and FortiWeb contain an improper verification of cryptographic signature vulnerability that may allow an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML message. Please be aware that CVE-2025-59719 pertains to the same problem and is mentioned in the same vendor advisory. Ensure to apply all patches mentioned in the advisory. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-59718CVE-2025-59719EPSS 66.3%FortinetMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2025-14611: Gladinet CentreStack and Triofox Hard Coded Cryptographic Vulnerability

Gladinet CentreStack and TrioFox contain a hardcoded cryptographic keys vulnerability for their implementation of the AES cryptoscheme. This vulnerability degrades security for public exposed endpoints that may make use of it and may offer arbitrary local file inclusion when provided a specially crafted request without authentication. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-14611EPSS 50.9%CentreStack and TriofoxGladinet
CISA KEV ↗ · unattributed attribution
high

CVE-2025-43529: Apple Multiple Products Use-After-Free WebKit Vulnerability

Apple iOS, iPadOS, macOS, and other Apple products contain a use-after-free vulnerability in WebKit. Processing maliciously crafted web content may lead to memory corruption. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-43529EPSS 8.6%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2018-4063: Sierra Wireless AirLink ALEOS Unrestricted Upload of File with Dangerous Type Vulnerability

Sierra Wireless AirLink ALEOS contains an unrestricted upload of file with dangerous type vulnerability. A specially crafted HTTP request can upload a file, resulting in executable code being uploaded, and routable, to the webserver. An attacker can make an authenticated HTTP request to trigger this vulnerability. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2018-4063EPSS 27.9%AirLink ALEOSSierra Wireless
CISA KEV ↗ · unattributed attribution
high

CVE-2025-14174: Google Chromium Out of Bounds Memory Access Vulnerability

Google Chromium contains an out of bounds memory access vulnerability in ANGLE that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-14174EPSS 22.7%ChromiumGoogle
CISA KEV ↗ · unattributed attribution
high

CVE-2025-58360: OSGeo GeoServer Improper Restriction of XML External Entity Reference Vulnerability

OSGeo GeoServer contains an improper restriction of XML external entity reference vulnerability that occurs when the application accepts XML input through a specific endpoint /geoserver/wms operation GetMap and could allow an attacker to define external entities within the XML request. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-58360EPSS 67.4%GeoServerOSGeo
CISA KEV ↗ · unattributed attribution
high

CVE-2025-6218: RARLAB WinRAR Path Traversal Vulnerability

RARLAB WinRAR contains a path traversal vulnerability allowing an attacker to execute code in the context of the current user. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-6218EPSS 86.2%RARLABWinRAR
CISA KEV ↗ · unattributed attribution
high

CVE-2025-62221: Microsoft Windows Use After Free Vulnerability

Microsoft Windows Cloud Files Mini Filter Driver contains a use after free vulnerability that can allow an authorized attacker to elevate privileges locally. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-62221EPSS 2.4%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2022-37055: D-Link Routers Buffer Overflow Vulnerability

D-Link Routers contains a buffer overflow vulnerability that has a high impact on confidentiality, integrity, and availability. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2022-37055EPSS 57.0%D-LinkRouters
CISA KEV ↗ · unattributed attribution
high

CVE-2025-66644: Array Networks ArrayOS AG OS Command Injection Vulnerability

Array Networks ArrayOS AG contains an OS command injection vulnerability that could allow an attacker to execute arbitrary commands. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-66644EPSS 3.1%Array Networks ArrayOS AG
CISA KEV ↗ · unattributed attribution
high

CVE-2025-55182: Meta React Server Components Remote Code Execution Vulnerability

Meta React Server Components contains a remote code execution vulnerability that could allow unauthenticated remote code execution by exploiting a flaw in how React decodes payloads sent to React Server Function endpoints. Please note CVE-2025-66478 has been rejected, but it is associated with CVE-2025- 55182. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-55182CVE-2025-66478EPSS 99.6%MetaReact Server Components
CISA KEV ↗ · unattributed attribution
high

CVE-2021-26828: OpenPLC ScadaBR Unrestricted Upload of File with Dangerous Type Vulnerability

OpenPLC ScadaBR contains an unrestricted upload of file with dangerous type vulnerability that allows remote authenticated users to upload and execute arbitrary JSP files via view_edit.shtm. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2021-26828EPSS 39.1%OpenPLCScadaBR
CISA KEV ↗ · unattributed attribution
unknown

Cyber Brief 25-12 - November 2025

Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:CLEAR.

CERT-EU Threat Intelligence ↗ · unattributed attribution
high

CVE-2025-48633: Android Framework Information Disclosure Vulnerability

Android Framework contains an unspecified vulnerability that allows for information disclosure. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-48633EPSS 0.2%AndroidFramework
CISA KEV ↗ · unattributed attribution
high

CVE-2025-48572: Android Framework Privilege Escalation Vulnerability

Android Framework contains an unspecified vulnerability that allows for privilege escalation. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-48572EPSS 0.2%AndroidFramework
CISA KEV ↗ · unattributed attribution
high

CVE-2021-26829: OpenPLC ScadaBR Cross-site Scripting Vulnerability

OpenPLC ScadaBR contains a cross-site scripting vulnerability via system_settings.shtm. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2021-26829EPSS 48.0%OpenPLCScadaBR
CISA KEV ↗ · unattributed attribution
high

CVE-2025-61757: Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability

Oracle Fusion Middleware contains a missing authentication for critical function vulnerability, allowing unauthenticated remote attackers to take over Identity Manager. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-61757EPSS 88.3%Fusion MiddlewareOracle
CISA KEV ↗ · unattributed attribution
high

CVE-2025-13223: Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 contains a type confusion vulnerability that allows for heap corruption. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-13223EPSS 4.9%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2025-58034: Fortinet FortiWeb OS Command Injection Vulnerability

Fortinet FortiWeb contains an OS command Injection vulnerability that may allow an authenticated attacker to execute unauthorized code on the underlying system via crafted HTTP requests or CLI commands. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-58034EPSS 55.6%FortiWebFortinet
CISA KEV ↗ · unattributed attribution
high

CVE-2025-64446: Fortinet FortiWeb Path Traversal Vulnerability

Fortinet FortiWeb contains a relative path traversal vulnerability that may allow an unauthenticated attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-64446EPSS 89.4%FortiWebFortinet
CISA KEV ↗ · unattributed attribution
high

CVE-2025-12480: Gladinet Triofox Improper Access Control Vulnerability

Gladinet Triofox contains an improper access control vulnerability that allows access to initial setup pages even after setup is complete. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-12480EPSS 90.5%GladinetTriofox
CISA KEV ↗ · unattributed attribution
high

CVE-2025-62215: Microsoft Windows Race Condition Vulnerability

Microsoft Windows Kernel contains a race condition vulnerability that allows a local attacker with low-level privileges to escalate privileges. Successful exploitation of this vulnerability could enable the attacker to gain SYSTEM-level access. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-62215EPSS 6.1%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-9242: WatchGuard Firebox Out-of-Bounds Write Vulnerability

WatchGuard Firebox contains an out-of-bounds write vulnerability in the OS iked process that may allow a remote unauthenticated attacker to execute arbitrary code. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-9242EPSS 86.4%FireboxWatchGuard
CISA KEV ↗ · unattributed attribution
high

CVE-2025-21042: Samsung Mobile Devices Out-of-Bounds Write Vulnerability

Samsung mobile devices contain an out-of-bounds write vulnerability in libimagecodec.quram.so. This vulnerability could allow remote attackers to execute arbitrary code. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-21042EPSS 11.6%Mobile DevicesSamsung
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2025-48703: CWP Control Web Panel OS Command Injection Vulnerability

CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command Injection vulnerability that allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager changePerm request. A valid non-root username must be known. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-48703EPSS 99.6%CWPControl Web Panel
CISA KEV ↗ · unattributed attribution
high

CVE-2025-11371: Gladinet CentreStack and Triofox Files or Directories Accessible to External Parties Vulnerability

Gladinet CentreStack and Triofox contains a files or directories accessible to external parties vulnerability that allows unintended disclosure of system files. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-11371EPSS 92.1%CentreStack and TriofoxGladinet
CISA KEV ↗ · unattributed attribution
high

CVE-2025-41244: Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability

Broadcom VMware Aria Operations and VMware Tools contain a privilege defined with unsafe actions vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-41244EPSS 7.9%BroadcomVMware Aria Operations and VMware Tools
CISA KEV ↗ · unattributed attribution
high

CVE-2025-24893: XWiki Platform Eval Injection Vulnerability

XWiki Platform contains an eval injection vulnerability that could allow any guest to perform arbitrary remote code execution through a request to SolrSearch. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-24893EPSS 99.9%PlatformXWiki
CISA KEV ↗ · unattributed attribution
high

CVE-2025-6204: Dassault Systèmes DELMIA Apriso Code Injection Vulnerability

Dassault Systèmes DELMIA Apriso contains a code injection vulnerability that could allow an attacker to execute arbitrary code. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-6204EPSS 76.1%DELMIA AprisoDassault Systèmes
CISA KEV ↗ · unattributed attribution
high

CVE-2025-6205: Dassault Systèmes DELMIA Apriso Missing Authorization Vulnerability

Dassault Systèmes DELMIA Apriso contains a missing authorization vulnerability that could allow an attacker to gain privileged access to the application. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-6205EPSS 71.1%DELMIA AprisoDassault Systèmes
CISA KEV ↗ · unattributed attribution
high

CVE-2025-54236: Adobe Commerce and Magento Improper Input Validation Vulnerability

Adobe Commerce and Magento Open Source contain an improper input validation vulnerability that could allow an attacker to take over customer accounts through the Commerce REST API. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-54236EPSS 96.7%AdobeCommerce and Magento
CISA KEV ↗ · unattributed attribution
high

CVE-2025-59287: Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability

Microsoft Windows Server Update Service (WSUS) contains a deserialization of untrusted data vulnerability that allows for remote code execution. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-59287EPSS 100.0%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-61932: Motex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel Vulnerability

Motex LANSCOPE Endpoint Manager contains an improper verification of source of a communication channel vulnerability allowing an attacker to execute arbitrary code by sending specially crafted packets. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-61932EPSS 2.6%LANSCOPE Endpoint ManagerMotex
CISA KEV ↗ · unattributed attribution
high

CVE-2022-48503: Apple Multiple Products Unspecified Vulnerability

Apple macOS, iOS, tvOS, Safari, and watchOS contain an unspecified vulnerability in JavaScriptCore that when processing web content may lead to arbitrary code execution. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2022-48503EPSS 3.2%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2025-2746: Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability

Kentico Xperience CMS contains an authentication bypass using an alternate path or channel vulnerability that could allow an attacker to control administrative objects. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-2746EPSS 58.4%KenticoXperience CMS
CISA KEV ↗ · unattributed attribution
high

CVE-2025-2747: Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability

Kentico Xperience CMS contains an authentication bypass using an alternate path or channel vulnerability that could allow an attacker to control administrative objects. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-2747EPSS 92.2%KenticoXperience CMS
CISA KEV ↗ · unattributed attribution
high

CVE-2025-33073: Microsoft Windows SMB Client Improper Access Control Vulnerability

Microsoft Windows SMB Client contains an improper access control vulnerability that could allow for privilege escalation. An attacker could execute a specially crafted malicious script to coerce the victim machine to connect back to the attack system using SMB and authenticate. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-33073EPSS 65.0%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-61884: Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability

Oracle E-Business Suite contains a server-side request forgery (SSRF) vulnerability in the Runtime component of Oracle Configurator. This vulnerability is remotely exploitable without authentication. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-61884EPSS 97.8%E-Business SuiteOracle
CISA KEV ↗ · unattributed attribution
high

CVE-2025-54253: Adobe Experience Manager Forms Code Execution Vulnerability

Adobe Experience Manager Forms in JEE contains an unspecified vulnerability that allows for arbitrary code execution. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-54253EPSS 87.5%AdobeExperience Manager (AEM) Forms
CISA KEV ↗ · unattributed attribution
high

CVE-2025-47827: IGEL OS Use of a Key Past its Expiration Date Vulnerability

IGEL OS contains a use of a key past its expiration date vulnerability that allows for Secure Boot bypass. The igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a crafted root filesystem can be mounted from an unverified SquashFS image. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-47827EPSS 3.8%IGELIGEL OS
CISA KEV ↗ · unattributed attribution
high

CVE-2025-24990: Microsoft Windows Untrusted Pointer Dereference Vulnerability

Microsoft Windows Agere Modem Driver contains an untrusted pointer dereference vulnerability that allows for privilege escalation. An attacker who successfully exploited this vulnerability could gain administrator privileges. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-24990EPSS 6.0%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-59230: Microsoft Windows Improper Access Control Vulnerability

Microsoft Windows contains an improper access control vulnerability in Windows Remote Access Connection Manager which could allow an authorized attacker to elevate privileges locally. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-59230EPSS 2.7%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2016-7836: SKYSEA Client View Improper Authentication Vulnerability

SKYSEA Client View contains an improper authentication vulnerability that allows remote code execution via a flaw in processing authentication on the TCP connection with the management console program. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2016-7836EPSS 19.4%Client ViewSKYSEA
CISA KEV ↗ · unattributed attribution
high

CVE-2021-43798: Grafana Path Traversal Vulnerability

Grafana contains a path traversal vulnerability that could allow access to local files. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2021-43798EPSS 88.8%GrafanaGrafana Labs
CISA KEV ↗ · unattributed attribution
high

CVE-2025-27915: Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability

Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that exists in the Classic Web Client due to insufficient sanitization of HTML content in ICS files. When a user views an e-mail message containing a malicious ICS entry, its embedded JavaScript executes via an ontoggle event inside a tag. This allows an attacker to run arbitrary JavaScript within the victim's session, potentially leading to unauthorized actions such as setting e-mail filters to redirect messages to an attacker-controlled address. As a result, an attacker can perform unauthorized actions on the victim's account, including e-mail redirection and data exfiltration. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-27915EPSS 4.3%SynacorZimbra Collaboration Suite (ZCS)
CISA KEV ↗ · unattributed attribution
high

CVE-2021-22555: Linux Kernel Heap Out-of-Bounds Write Vulnerability

Linux Kernel contains a heap out-of-bounds write vulnerability that could allow an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2021-22555EPSS 78.7%KernelLinux
CISA KEV ↗ · unattributed attribution
high

CVE-2010-3962: Microsoft Internet Explorer Uninitialized Memory Corruption Vulnerability

Microsoft Internet Explorer contains an uninitialized memory corruption vulnerability that could allow for remote code execution. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2010-3962EPSS 96.9%Internet ExplorerMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2021-43226: Microsoft Windows Privilege Escalation Vulnerability

Microsoft Windows Common Log File System Driver contains a privilege escalation vulnerability that could allow a local, privileged attacker to bypass certain security mechanisms. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2021-43226EPSS 3.1%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2013-3918: Microsoft Windows Out-of-Bounds Write Vulnerability

Microsoft Windows contains an out-of-bounds write vulnerability in the InformationCardSigninHelper Class ActiveX control, icardie.dll. An attacker could exploit the vulnerability by constructing a specially crafted webpage. When a user views the webpage, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the current user. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2013-3918EPSS 73.9%MicrosoftWindows
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2011-3402: Microsoft Windows Remote Code Execution Vulnerability

Microsoft Windows Kernel contains an unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers that allows remote attackers to execute arbitrary code via crafted font data in a Word document or web page. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2011-3402EPSS 78.3%MicrosoftWindows
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2010-3765: Mozilla Multiple Products Remote Code Execution Vulnerability

Mozilla Firefox, SeaMonkey, and Thunderbird contain an unspecified vulnerability when JavaScript is enabled. This allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the creation of multiple frames, which triggers memory corruption. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2010-3765EPSS 83.3%MozillaMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2025-61882: Oracle E-Business Suite Unspecified Vulnerability

Oracle E-Business Suite contains an unspecified vulnerability in the BI Publisher Integration component. The vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Concurrent Processing. Successful attacks can result in takeover of Oracle Concurrent Processing. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-61882EPSS 99.7%E-Business SuiteOracle
CISA KEV ↗ · unattributed attribution
high

CVE-2014-6278: GNU Bash OS Command Injection Vulnerability

GNU Bash contains an OS command injection vulnerability which allows remote attackers to execute arbitrary commands via a crafted environment. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2014-6278EPSS 99.6%GNUGNU Bash
CISA KEV ↗ · unattributed attribution
high

CVE-2017-1000353: Jenkins Remote Code Execution Vulnerability

Jenkins contains a remote code execution vulnerability. This vulnerability that could allowed attackers to transfer a serialized Java SignedObject object to the remoting-based Jenkins CLI, that would be deserialized using a new ObjectInputStream, bypassing the existing blocklist-based protection mechanism. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2017-1000353EPSS 99.7%Jenkins
CISA KEV ↗ · unattributed attribution
high

CVE-2015-7755: Juniper ScreenOS Improper Authentication Vulnerability

Juniper ScreenOS contains an improper authentication vulnerability that could allow unauthorized remote administrative access to the device. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2015-7755EPSS 61.4%JuniperScreenOS
CISA KEV ↗ · unattributed attribution
high

CVE-2025-21043: Samsung Mobile Devices Out-of-Bounds Write Vulnerability

Samsung mobile devices contain an out-of-bounds write vulnerability in libimagecodec.quram.so which allows remote attackers to execute arbitrary code. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-21043EPSS 1.4%Mobile DevicesSamsung
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2025-4008: Smartbedded Meteobridge Command Injection Vulnerability

Smartbedded Meteobridge contains a command injection vulnerability that could allow remote unauthenticated attackers to gain arbitrary command execution with elevated privileges (root) on affected devices. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-4008EPSS 94.9%MeteobridgeSmartbedded
CISA KEV ↗ · unattributed attribution
high

CVE-2025-32463: Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability

Sudo contains an inclusion of functionality from untrusted control sphere vulnerability. This vulnerability could allow local attacker to leverage sudo’s -R (--chroot) option to run arbitrary commands as root, even if they are not listed in the sudoers file. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-32463EPSS 47.5%Sudo
CISA KEV ↗ · unattributed attribution
high

CVE-2025-59689: Libraesva Email Security Gateway Command Injection Vulnerability

Libraesva Email Security Gateway (ESG) contains a command injection vulnerability which allows command injection via a compressed e-mail attachment. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-59689EPSS 1.9%Email Security GatewayLibraesva
CISA KEV ↗ · unattributed attribution
high

CVE-2025-10035: Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability

Fortra GoAnywhere MFT contains a deserialization of untrusted data vulnerability allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-10035EPSS 99.6%FortraGoAnywhere MFT
CISA KEV ↗ · unattributed attribution
high

CVE-2025-20352: Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability

Cisco IOS and IOS XE contains a stack-based buffer overflow vulnerability in the Simple Network Management Protocol (SNMP) subsystem that could allow for denial of service or remote code execution. A successful exploit could allow a low-privileged attacker to cause the affected system to reload, resulting in a DoS condition, or allow a high-privileged attacker to execute arbitrary code as the root user and obtain full control of the affected system. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-20352EPSS 37.6%CiscoIOS and IOS XE
CISA KEV ↗ · unattributed attribution
high

CVE-2021-21311: Adminer Server-Side Request Forgery Vulnerability

Adminer contains a server-side request forgery vulnerability that, when exploited, allows a remote attacker to obtain potentially sensitive information. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2021-21311EPSS 90.1%Adminer
CISA KEV ↗ · unattributed attribution
high

CVE-2025-20362: Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Missing Authorization Vulnerability

Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Software VPN Web Server contain a missing authorization vulnerability. This vulnerability could be chained with CVE-2025-20333. Required action: The KEV due date refers to the deadline by which FCEB agencies are expected to review and begin implementing the guidance outlined in Emergency Directive (ED) 25-03 (URL listed below in Notes). Agencies must follow the mitigation steps provided by CISA (URL listed below in Notes) and vendor’s instructions (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.

CVE-2025-20333CVE-2025-20362EPSS 85.5%CiscoSecure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense
CISA KEV ↗ · unattributed attribution
high

CVE-2025-20333: Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Buffer Overflow Vulnerability

Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Software VPN Web Server contain a buffer overflow vulnerability that allows for remote code execution. This vulnerability could be chained with CVE-2025-20362. Required action: The KEV due date refers to the deadline by which FCEB agencies are expected to review and begin implementing the guidance outlined in Emergency Directive (ED) 25-03 (URL listed below in Notes). Agencies must follow the mitigation steps provided by CISA (URL listed below in Notes) and vendor’s instructions (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.

CVE-2025-20333CVE-2025-20362EPSS 85.5%CiscoSecure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense
CISA KEV ↗ · unattributed attribution
high

CVE-2025-10585: Google Chromium V8 Type Confusion Vulnerability

Google Chromium contains a type confusion vulnerability in the V8 JavaScript and WebAssembly engine. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-10585EPSS 5.4%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2025-5086: Dassault Systèmes DELMIA Apriso Deserialization of Untrusted Data Vulnerability

Dassault Systèmes DELMIA Apriso contains a deserialization of untrusted data vulnerability that could lead to a remote code execution. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-5086EPSS 89.7%DELMIA AprisoDassault Systèmes
CISA KEV ↗ · unattributed attribution
high

CVE-2025-38352: Linux Kernel Time-of-Check Time-of-Use (TOCTOU) Race Condition Vulnerability

Linux kernel contains a time-of-check time-of-use (TOCTOU) race condition vulnerability that has a high impact on confidentiality, integrity, and availability. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-38352EPSS 1.3%KernelLinux
CISA KEV ↗ · unattributed attribution
high

CVE-2025-48543: Android Runtime Use-After-Free Vulnerability

Android Runtime contains a use-after-free vulnerability potentially allowing a chrome sandbox escape leading to local privilege escalation. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-48543EPSS 0.5%AndroidRuntime
CISA KEV ↗ · unattributed attribution
high

CVE-2025-53690: Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability

Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud contain a deserialization of untrusted data vulnerability involving the use of default machine keys. This flaw allows attackers to exploit exposed ASP.NET machine keys to achieve remote code execution. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-53690EPSS 30.8%Multiple ProductsSitecore
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2023-50224: TP-Link TL-WR841N Authentication Bypass by Spoofing Vulnerability

TP-Link TL-WR841N contains an authentication bypass by spoofing vulnerability within the httpd service, which listens on TCP port 80 by default, leading to the disclose of stored credentials. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2023-50224EPSS 17.4%TL-WR841NTP-Link
CISA KEV ↗ · unattributed attribution
high

CVE-2025-9377: TP-Link Archer C7(EU) and TL-WR841N/ND(MS) OS Command Injection Vulnerability

TP-Link Archer C7(EU) and TL-WR841N/ND(MS) contain an OS command injection vulnerability that exists in the Parental Control page. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-9377EPSS 11.7%Multiple RoutersTP-Link
CISA KEV ↗ · unattributed attribution
high

CVE-2020-24363: TP-link TL-WA855RE Missing Authentication for Critical Function Vulnerability

TP-link TL-WA855RE contains a missing authentication for critical function vulnerability. This vulnerability could allow an unauthenticated attacker (on the same network) to submit a TDDP_RESET POST request for a factory reset and reboot. The attacker can then obtain incorrect access control by setting a new administrative password. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2020-24363EPSS 20.7%TL-WA855RETP-Link
CISA KEV ↗ · unattributed attribution
high

CVE-2025-55177: Meta Platforms WhatsApp Incorrect Authorization Vulnerability

Meta Platforms WhatsApp contains an incorrect authorization vulnerability due to an incomplete authorization of linked device synchronization messages. This vulnerability could allow an unrelated user to trigger processing of content from an arbitrary URL on a target’s device. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-55177EPSS 4.1%Meta PlatformsWhatsApp
CISA KEV ↗ · unattributed attribution
high

CVE-2025-57819: Sangoma FreePBX Authentication Bypass Vulnerability

Sangoma FreePBX contains an authentication bypass vulnerability due to insufficiently sanitized user-supplied data allows unauthenticated access to FreePBX Administrator leading to arbitrary database manipulation and remote code execution. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-57819EPSS 93.3%FreePBXSangoma
CISA KEV ↗ · unattributed attribution
high

CVE-2025-7775: Citrix NetScaler Memory Overflow Vulnerability

Citrix NetScaler ADC and NetScaler Gateway contain a memory overflow vulnerability that could allow for remote code execution and/or denial of service. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-7775EPSS 19.0%CitrixNetScaler
CISA KEV ↗ · unattributed attribution
high

CVE-2025-48384: Git Link Following Vulnerability

Git contains a link following vulnerability that stems from Git’s inconsistent handling of carriage return characters in configuration files. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-48384EPSS 2.8%Git
CISA KEV ↗ · unattributed attribution
high

CVE-2024-8068: Citrix Session Recording Improper Privilege Management Vulnerability

Citrix Session Recording contains an improper privilege management vulnerability that could allow for privilege escalation to NetworkService Account access. An attacker must be an authenticated user in the same Windows Active Directory domain as the session recording server domain. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2024-8068EPSS 1.4%CitrixSession Recording
CISA KEV ↗ · unattributed attribution
high

CVE-2024-8069: Citrix Session Recording Deserialization of Untrusted Data Vulnerability

Citrix Session Recording contains a deserialization of untrusted data vulnerability that allows limited remote code execution with privilege of a NetworkService Account access. Attacker must be an authenticated user on the same intranet as the session recording server. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2024-8069EPSS 14.7%CitrixSession Recording
CISA KEV ↗ · unattributed attribution
high

CVE-2025-43300: Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability

Apple iOS, iPadOS, and macOS contain an out-of-bounds write vulnerability in the Image I/O framework. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-43300EPSS 20.0%AppleiOS, iPadOS, and macOS
CISA KEV ↗ · unattributed attribution
high

CVE-2025-54948: Trend Micro Apex One OS Command Injection Vulnerability

Trend Micro Apex One Management Console (on-premise) contains an OS command injection vulnerability that could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-54948EPSS 20.8%Apex OneTrend Micro
CISA KEV ↗ · unattributed attribution
high

CVE-2025-8876: N-able N-Central Command Injection Vulnerability

N-able N-Central contains a command injection vulnerability via improper sanitization of user input. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-8876EPSS 3.1%N-CentralN-able
CISA KEV ↗ · unattributed attribution
high

CVE-2025-8875: N-able N-Central Insecure Deserialization Vulnerability

N-able N-Central contains an insecure deserialization vulnerability that could lead to command execution. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-8875EPSS 1.6%N-CentralN-able
CISA KEV ↗ · unattributed attribution
high

CVE-2025-8088: RARLAB WinRAR Path Traversal Vulnerability

RARLAB WinRAR contains a path traversal vulnerability affecting the Windows version of WinRAR. This vulnerability could allow an attacker to execute arbitrary code by crafting malicious archive files. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-8088EPSS 80.9%RARLABWinRAR
CISA KEV ↗ · unattributed attribution
high

CVE-2007-0671: Microsoft Office Excel Remote Code Execution Vulnerability

Microsoft Office Excel contains a remote code execution vulnerability that can be exploited when a specially crafted Excel file is opened. This malicious file could be delivered as an email attachment or hosted on a malicious website. An attacker could leverage this vulnerability by creating a specially crafted Excel file, which, when opened, allowing an attacker to execute remote code on the affected system. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2007-0671EPSS 42.1%MicrosoftOffice
CISA KEV ↗ · unattributed attribution
high

CVE-2013-3893: Microsoft Internet Explorer Resource Management Errors Vulnerability

Microsoft Internet Explorer contains a memory corruption vulnerability that allows for remote code execution. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2013-3893EPSS 85.9%Internet ExplorerMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2020-25078: D-Link DCS-2530L and DCS-2670L Devices Unspecified Vulnerability

D-Link DCS-2530L and DCS-2670L devices contains an unspecified vulnerability that could allow for remote administrator password disclosure. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2020-25078EPSS 97.9%D-LinkDCS-2530L and DCS-2670L Devices
CISA KEV ↗ · unattributed attribution
high

CVE-2020-25079: D-Link DCS-2530L and DCS-2670L Command Injection Vulnerability

D-Link DCS-2530L and DCS-2670L devices contains a command injection vulnerability in the cgi-bin/ddns_enc.cgi. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2020-25079EPSS 52.7%D-LinkDCS-2530L and DCS-2670L Devices
CISA KEV ↗ · unattributed attribution
high

CVE-2022-40799: D-Link DNR-322L Download of Code Without Integrity Check Vulnerability

D-Link DNR-322L contains a download of code without integrity check vulnerability that could allow an authenticated attacker to execute OS level commands on the device. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2022-40799EPSS 31.3%D-LinkDNR-322L
CISA KEV ↗ · unattributed attribution
high

CVE-2023-2533: PaperCut NG/MF Cross-Site Request Forgery (CSRF) Vulnerability

PaperCut NG/MF contains a cross-site request forgery (CSRF) vulnerability, which, under specific conditions, could potentially enable an attacker to alter security settings or execute arbitrary code. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2023-2533EPSS 29.2%NG/MFPaperCut
CISA KEV ↗ · unattributed attribution
high

CVE-2025-20337: Cisco Identity Services Engine Injection Vulnerability

Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing an attacker to exploit this vulnerability by submitting a crafted API request. Successful exploitation could allow an attacker to perform remote code execution and obtaining root privileges on an affected device. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-20337EPSS 65.1%CiscoIdentity Services Engine
CISA KEV ↗ · unattributed attribution
high

CVE-2025-20281: Cisco Identity Services Engine Injection Vulnerability

Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing an attacker to exploit this vulnerability by submitting a crafted API request. Successful exploitation could allow an attacker to perform remote code execution and obtaining root privileges on an affected device. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-20281EPSS 96.7%CiscoIdentity Services Engine
CISA KEV ↗ · unattributed attribution
high

CVE-2025-2775: SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability

SysAid On-Prem contains an improper restriction of XML external entity reference vulnerability in the Checkin processing functionality, allowing for administrator account takeover and file read primitives. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-2775EPSS 54.6%SysAidSysAid On-Prem
CISA KEV ↗ · unattributed attribution
high

CVE-2025-2776: SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability

SysAid On-Prem contains an improper restriction of XML external entity reference vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read primitives. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-2776EPSS 73.0%SysAidSysAid On-Prem
CISA KEV ↗ · unattributed attribution
high

CVE-2025-6558: Google Chromium ANGLE and GPU Improper Input Validation Vulnerability

Google Chromium contains an improper input validation vulnerability in ANGLE and GPU. This vulnerability could allow a remote attacker to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-6558EPSS 9.2%ChromiumGoogle
CISA KEV ↗ · unattributed attribution
high

CVE-2025-54309: CrushFTP Unprotected Alternate Channel Vulnerability

CrushFTP contains an unprotected alternate channel vulnerability. When the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via HTTPS. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-54309EPSS 92.0%CrushFTP
CISA KEV ↗ · unattributed attribution
high

CVE-2025-49704: Microsoft SharePoint Code Injection Vulnerability

Microsoft SharePoint contains a code injection vulnerability that could allow an authorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-49706. CVE-2025-53770 is a patch bypass for CVE-2025-49704, and the updates for CVE-2025-53770 include more robust protection than those for CVE-2025-49704. Required action: Disconnect public-facing versions of SharePoint Server that have reached their end-of-life (EOL) or end-of-service (EOS) to include SharePoint Server 2013 and earlier versions. For supported versions, please follow the mitigations according to CISA (URL listed below in Notes) and vendor instructions (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.

CVE-2025-49704CVE-2025-49706EPSS 100.0%MicrosoftSharePoint
CISA KEV ↗ · unattributed attribution
high

CVE-2025-49706: Microsoft SharePoint Improper Authentication Vulnerability

Microsoft SharePoint contains an improper authentication vulnerability that allows an authorized attacker to perform spoofing over a network. Successfully exploitation could allow an attacker to view sensitive information and make some changes to disclosed information. This vulnerability could be chained with CVE-2025-49704. CVE-2025-53771 is a patch bypass for CVE-2025-49706, and the updates for CVE-2025-53771 include more robust protection than those for CVE-2025-49706. Required action: Disconnect public-facing versions of SharePoint Server that have reached their end-of-life (EOL) or end-of-service (EOS) to include SharePoint Server 2013 and earlier versions. For supported versions, please follow the mitigations according to CISA (URL listed below in Notes) and vendor instructions (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.

CVE-2025-49704CVE-2025-49706EPSS 99.9%MicrosoftSharePoint
CISA KEV ↗ · unattributed attribution
high

CVE-2025-53770: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

Microsoft SharePoint Server on-premises contains a deserialization of untrusted data vulnerability that could allow an unauthorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-53771. CVE-2025-53770 is a patch bypass for CVE-2025-49704, and the updates for CVE-2025-53770 include more robust protection than those for CVE-2025-49704. Required action: Disconnect public-facing versions of SharePoint Server that have reached their end-of-life (EOL) or end-of-service (EOS) to include SharePoint Server 2013 and earlier versions. For supported versions, please follow the mitigations according to CISA (URL listed below in Notes) and vendor instructions (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.

CVE-2025-49704CVE-2025-53770EPSS 100.0%MicrosoftSharePoint
CISA KEV ↗ · unattributed attribution
high

CVE-2025-25257: Fortinet FortiWeb SQL Injection Vulnerability

Fortinet FortiWeb contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-25257EPSS 96.7%FortiWebFortinet
CISA KEV ↗ · unattributed attribution
high

CVE-2025-47812: Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerability

Wing FTP Server contains an improper neutralization of null byte or NUL character vulnerability that can allow injection of arbitrary Lua code into user session files. This can be used to execute arbitrary system commands with the privileges of the FTP service (root or SYSTEM by default). Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-47812EPSS 95.3%Wing FTP Server
CISA KEV ↗ · unattributed attribution
high

CVE-2025-5777: Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability

Citrix NetScaler ADC and Gateway contain an out-of-bounds read vulnerability due to insufficient input validation. This vulnerability can lead to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-5777EPSS 99.9%CitrixNetScaler ADC and Gateway
CISA KEV ↗ · unattributed attribution
high

CVE-2019-9621: Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery (SSRF) Vulnerability

Synacor Zimbra Collaboration Suite (ZCS) contains a server-side request forgery (SSRF) vulnerability via the ProxyServlet component. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2019-9621EPSS 80.9%SynacorZimbra Collaboration Suite (ZCS)
CISA KEV ↗ · unattributed attribution
high

CVE-2019-5418: Rails Ruby on Rails Path Traversal Vulnerability

Rails Ruby on Rails contains a path traversal vulnerability in Action View. Specially crafted accept headers in combination with calls to `render file:` can cause arbitrary files on the target server to be rendered, disclosing the file contents. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2019-5418EPSS 98.5%RailsRuby on Rails
CISA KEV ↗ · unattributed attribution
high

CVE-2016-10033: PHPMailer Command Injection Vulnerability

PHPMailer contains a command injection vulnerability because it fails to sanitize user-supplied input. Specifically, this issue affects the 'mail()' function of 'class.phpmailer.php' script. An attacker can exploit this issue to execute arbitrary code within the context of the application. Failed exploit attempts will result in a denial-of-service condition. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2016-10033EPSS 99.7%PHPPHPMailer
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2014-3931: Multi-Router Looking Glass (MRLG) Buffer Overflow Vulnerability

Multi-Router Looking Glass (MRLG) contains a buffer overflow vulnerability that could allow remote attackers to cause an arbitrary memory write and memory corruption. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2014-3931EPSS 26.6%Looking GlassMulti-Router Looking Glass (MRLG)
CISA KEV ↗ · unattributed attribution
high

CVE-2025-6554: Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 contains a type confusion vulnerability that could allow a remote attacker to perform arbitrary read/write via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-6554EPSS 6.6%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2025-48928: TeleMessage TM SGNL Exposure of Core Dump File to an Unauthorized Control Sphere Vulnerability

TeleMessage TM SGNL contains an exposure of core dump file to an unauthorized control sphere Vulnerability. This vulnerability is based on a JSP application in which the heap content is roughly equivalent to a "core dump" in which a password previously sent over HTTP would be included in this dump. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-48928EPSS 0.4%TM SGNLTeleMessage
CISA KEV ↗ · unattributed attribution
high

CVE-2025-48927: TeleMessage TM SGNL Initialization of a Resource with an Insecure Default Vulnerability

TeleMessage TM SGNL contains an initialization of a resource with an insecure default vulnerability. This vulnerability relies on how the Spring Boot Actuator is configured with an exposed heap dump endpoint at a /heapdump URI. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-48927EPSS 8.5%TM SGNLTeleMessage
CISA KEV ↗ · unattributed attribution
high

CVE-2025-6543: Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerability

Citrix NetScaler ADC and Gateway contain a buffer overflow vulnerability leading to unintended control flow and Denial of Service. NetScaler must be configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-6543EPSS 9.8%CitrixNetScaler ADC and Gateway
CISA KEV ↗ · unattributed attribution
high

CVE-2019-6693: Fortinet FortiOS Use of Hard-Coded Credentials Vulnerability

Fortinet FortiOS contains a use of hard-coded credentials vulnerability that could allow an attacker to cipher sensitive data in FortiOS configuration backup file via knowledge of the hard-coded key. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2019-6693EPSS 5.7%FortiOSFortinet
CISA KEV ↗ · unattributed attribution
high

CVE-2024-0769: D-Link DIR-859 Router Path Traversal Vulnerability

D-Link DIR-859 routers contain a path traversal vulnerability in the file /hedwig.cgi of the component HTTP POST Request Handler. Manipulation of the argument service with the input ../../../../htdocs/webinc/getcfg/DHCPS6.BRIDGE-1.xml allows for the leakage of session data potentially enabling privilege escalation and unauthorized control of the device. This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2024-0769EPSS 82.7%D-LinkDIR-859 Router
CISA KEV ↗ · unattributed attribution · 2 IOCs
high

CVE-2024-54085: AMI MegaRAC SPx Authentication Bypass by Spoofing Vulnerability

AMI MegaRAC SPx contains an authentication bypass by spoofing vulnerability in the Redfish Host Interface. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2024-54085EPSS 61.5%AMIMegaRAC SPx
CISA KEV ↗ · unattributed attribution
high

CVE-2023-0386: Linux Kernel Improper Ownership Management Vulnerability

Linux Kernel contains an improper ownership management vulnerability, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2023-0386EPSS 7.9%KernelLinux
CISA KEV ↗ · unattributed attribution
high

CVE-2023-33538: TP-Link Multiple Routers Command Injection Vulnerability

TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 contain a command injection vulnerability via the component /userRpm/WlanNetworkRpm. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2023-33538EPSS 41.9%Multiple RoutersTP-Link
CISA KEV ↗ · unattributed attribution
high

CVE-2025-43200: Apple Multiple Products Unspecified Vulnerability

Apple iOS, iPadOS, macOS, watchOS, and visionOS, contain an unspecified vulnerability when processing a maliciously crafted photo or video shared via an iCloud Link. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-43200EPSS 1.0%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2025-33053: Microsoft Windows External Control of File Name or Path Vulnerability

Microsoft Windows contains an external control of file name or path vulnerability that could allow an attacker to execute code from a remote WebDAV location specified by the WorkingDirectory attribute of Internet Shortcut files. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-33053EPSS 81.6%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-24016: Wazuh Server Deserialization of Untrusted Data Vulnerability

Wazuh contains a deserialization of untrusted data vulnerability that allows for remote code execution on Wazuh servers. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-24016EPSS 93.0%WazuhWazuh Server
CISA KEV ↗ · unattributed attribution
high

CVE-2024-42009: RoundCube Webmail Cross-Site Scripting Vulnerability

RoundCube Webmail contains a cross-site scripting vulnerability. This vulnerability could allow a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions/mail/show.php. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2024-42009EPSS 84.4%RoundcubeWebmail
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2025-32433: Erlang Erlang/OTP SSH Server Missing Authentication for Critical Function Vulnerability

Erlang Erlang/OTP SSH server contains a missing authentication for critical function vulnerability. This could allow an attacker to execute arbitrary commands without valid credentials, potentially leading to unauthenticated remote code execution (RCE). By exploiting a flaw in how SSH protocol messages are handled, a malicious actor could gain unauthorized access to affected systems. This vulnerability could affect various products that implement Erlang/OTP SSH server, including—but not limited to—Cisco, NetApp, and SUSE. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-32433EPSS 97.9%ErlangErlang/OTP
CISA KEV ↗ · unattributed attribution
high

CVE-2025-5419: Google Chromium V8 Out-of-Bounds Read and Write Vulnerability

Google Chromium V8 contains an out-of-bounds read and write vulnerability that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-5419EPSS 6.5%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2025-21479: Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability

Multiple Qualcomm chipsets contain an incorrect authorization vulnerability. This vulnerability allows for memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-21479EPSS 0.8%Multiple ChipsetsQualcomm
CISA KEV ↗ · unattributed attribution
high

CVE-2025-21480: Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability

Multiple Qualcomm chipsets contain an incorrect authorization vulnerability. This vulnerability allows for memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-21480EPSS 0.4%Multiple ChipsetsQualcomm
CISA KEV ↗ · unattributed attribution
high

CVE-2025-27038: Qualcomm Multiple Chipsets Use-After-Free Vulnerability

Multiple Qualcomm chipsets contain a use-after-free vulnerability. This vulnerability allows for memory corruption while rendering graphics using Adreno GPU drivers in Chrome. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-27038EPSS 0.8%Multiple ChipsetsQualcomm
CISA KEV ↗ · unattributed attribution
high

CVE-2021-32030: ASUS Routers Improper Authentication Vulnerability

ASUS Lyra Mini and ASUS GT-AC2900 devices contain an improper authentication vulnerability that allows an attacker to gain unauthorized access to the administrative interface. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2021-32030EPSS 99.4%ASUSRouters
CISA KEV ↗ · unattributed attribution
high

CVE-2025-3935: ConnectWise ScreenConnect Improper Authentication Vulnerability

ConnectWise ScreenConnect contains an improper authentication vulnerability. This vulnerability could allow a ViewState code injection attack, which could allow remote code execution if machine keys are compromised. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-3935EPSS 3.4%ConnectWiseScreenConnect
CISA KEV ↗ · unattributed attribution
high

CVE-2025-35939: Craft CMS External Control of Assumed-Immutable Web Parameter Vulnerability

Craft CMS contains an external control of assumed-immutable web parameter vulnerability. This vulnerability could allow an unauthenticated client to introduce arbitrary values, such as PHP code, to a known local file location on the server. This vulnerability could be chained with CVE-2024-58136 as represented by CVE-2025-32432. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2024-58136CVE-2025-32432EPSS 99.8%Craft CMS
CISA KEV ↗ · unattributed attribution
high

CVE-2024-56145: Craft CMS Code Injection Vulnerability

Craft CMS contains a code injection vulnerability. Users with affected versions are vulnerable to remote code execution if their php.ini configuration has `register_argc_argv` enabled. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2024-56145EPSS 97.4%Craft CMS
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2023-39780: ASUS RT-AX55 Routers OS Command Injection Vulnerability

ASUS RT-AX55 devices contain an OS command injection vulnerability that could allow a remote, authenticated attacker to execute arbitrary commands. As represented by CVE-2023-41346. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2023-39780CVE-2023-41346EPSS 33.6%ASUSRT-AX55 Routers
CISA KEV ↗ · unattributed attribution
high

CVE-2025-4632: Samsung MagicINFO 9 Server Path Traversal Vulnerability

Samsung MagicINFO 9 Server contains a path traversal vulnerability that allows an attacker to write arbitrary file as system authority. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-4632EPSS 24.0%MagicINFO 9 ServerSamsung
CISA KEV ↗ · unattributed attribution
high

CVE-2023-38950: ZKTeco BioTime Path Traversal Vulnerability

ZKTeco BioTime contains a path traversal vulnerability in the iclock API that allows an unauthenticated attacker to read arbitrary files via supplying a crafted payload. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2023-38950EPSS 84.9%BioTimeZKTeco
CISA KEV ↗ · unattributed attribution
high

CVE-2024-27443: Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability

Zimbra Collaboration contains a cross-site scripting (XSS) vulnerability in the CalendarInvite feature of the Zimbra webmail classic user interface. An attacker can exploit this vulnerability via an email message containing a crafted calendar header, leading to the execution of arbitrary JavaScript code. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2024-27443EPSS 19.5%SynacorZimbra Collaboration Suite (ZCS)
CISA KEV ↗ · unattributed attribution
high

CVE-2025-27920: Srimax Output Messenger Directory Traversal Vulnerability

Srimax Output Messenger contains a directory traversal vulnerability that allows an attacker to access sensitive files outside the intended directory, potentially leading to configuration leakage or arbitrary file access. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-27920EPSS 1.8%Output MessengerSrimax
CISA KEV ↗ · unattributed attribution
high

CVE-2024-11182: MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability

MDaemon Email Server contains a cross-site scripting (XSS) vulnerability that allows a remote attacker to load arbitrary JavaScript code via an HTML e-mail message. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2024-11182EPSS 17.1%Email ServerMDaemon
CISA KEV ↗ · unattributed attribution
high

CVE-2025-4428: Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability

Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability in the API component that allows an authenticated attacker to remotely execute arbitrary code via crafted API requests. This vulnerability results from an insecure implementation of the Hibernate Validator open-source library, as represented by CVE-2025-35036. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-35036CVE-2025-4428EPSS 84.8%Endpoint Manager Mobile (EPMM)Ivanti
CISA KEV ↗ · unattributed attribution
high

CVE-2025-4427: Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability

Ivanti Endpoint Manager Mobile (EPMM) contains an authentication bypass vulnerability in the API component that allows an attacker to access protected resources without proper credentials via crafted API requests. This vulnerability results from an insecure implementation of the Spring Framework open-source library. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-4427EPSS 99.9%Endpoint Manager Mobile (EPMM)Ivanti
CISA KEV ↗ · unattributed attribution
high

CVE-2025-42999: SAP NetWeaver Deserialization Vulnerability

SAP NetWeaver Visual Composer Metadata Uploader contains a deserialization vulnerability that allows a privileged attacker to compromise the confidentiality, integrity, and availability of the host system by deserializing untrusted or malicious content. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-42999EPSS 12.5%NetWeaverSAP
CISA KEV ↗ · unattributed attribution
high

CVE-2024-12987: DrayTek Vigor Routers OS Command Injection Vulnerability

DrayTek Vigor2960, Vigor300B, and Vigor3900 routers contain an OS command injection vulnerability due to an unknown function of the file /cgi-bin/mainfunction.cgi/apmcfgupload of the component web management interface. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2024-12987EPSS 98.1%DrayTekVigor Routers
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2025-32756: Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability

Fortinet FortiFone, FortiVoice, FortiNDR and FortiMail contain a stack-based overflow vulnerability that may allow a remote unauthenticated attacker to execute arbitrary code or commands via crafted HTTP requests. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-32756EPSS 32.0%FortinetMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2025-32709: Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability

Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to escalate privileges to administrator. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-32709EPSS 1.7%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-30397: Microsoft Windows Scripting Engine Type Confusion Vulnerability

Microsoft Windows Scripting Engine contains a type confusion vulnerability that allows an unauthorized attacker to execute code over a network via a specially crafted URL. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-30397EPSS 21.2%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-32706: Microsoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow Vulnerability

Microsoft Windows Common Log File System (CLFS) Driver contains a heap-based buffer overflow vulnerability that allows an authorized attacker to elevate privileges locally. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-32706EPSS 2.1%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-32701: Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability

Microsoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-32701EPSS 1.3%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-30400: Microsoft Windows DWM Core Library Use-After-Free Vulnerability

Microsoft Windows DWM Core Library contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-30400EPSS 1.8%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-47729: TeleMessage TM SGNL Hidden Functionality Vulnerability

TeleMessage TM SGNL contains a hidden functionality vulnerability in which the archiving backend holds cleartext copies of messages from TM SGNL application users. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-47729EPSS 0.4%TM SGNLTeleMessage
CISA KEV ↗ · unattributed attribution
high

CVE-2024-11120: GeoVision Devices OS Command Injection Vulnerability

Multiple GeoVision devices contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to inject and execute arbitrary system commands. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2024-11120EPSS 28.6%GeoVisionMultiple Devices
CISA KEV ↗ · unattributed attribution
high

CVE-2024-6047: GeoVision Devices OS Command Injection Vulnerability

Multiple GeoVision devices contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to inject and execute arbitrary system commands. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2024-6047EPSS 10.1%GeoVisionMultiple Devices
CISA KEV ↗ · unattributed attribution
high

CVE-2025-27363: FreeType Out-of-Bounds Write Vulnerability

FreeType contains an out-of-bounds write vulnerability when attempting to parse font subglyph structures related to TrueType GX and variable font files that may allow for arbitrary code execution. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-27363EPSS 26.0%FreeType
CISA KEV ↗ · unattributed attribution
high

CVE-2025-3248: Langflow Missing Authentication Vulnerability

Langflow contains a missing authentication vulnerability in the /api/v1/validate/code endpoint that allows a remote, unauthenticated attacker to execute arbitrary code via crafted HTTP requests. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-3248EPSS 100.0%Langflow
CISA KEV ↗ · unattributed attribution
high

CVE-2025-34028: Commvault Command Center Path Traversal Vulnerability

Commvault Command Center contains a path traversal vulnerability that allows a remote, unauthenticated attacker to execute arbitrary code. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-34028EPSS 97.3%Command CenterCommvault
CISA KEV ↗ · unattributed attribution
high

CVE-2024-58136: Yiiframework Yii Improper Protection of Alternate Path Vulnerability

Yii Framework contains an improper protection of alternate path vulnerability that may allow a remote attacker to execute arbitrary code. This vulnerability could affect other products that implement Yii, including—but not limited to—Craft CMS, as represented by CVE-2025-32432. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2024-58136CVE-2025-32432EPSS 99.8%YiiYiiframework
CISA KEV ↗ · unattributed attribution
high

CVE-2024-38475: Apache HTTP Server Improper Escaping of Output Vulnerability

Apache HTTP Server contains an improper escaping of output vulnerability in mod_rewrite that allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source code disclosure. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2024-38475EPSS 100.0%ApacheHTTP Server
CISA KEV ↗ · unattributed attribution
high

CVE-2023-44221: SonicWall SMA100 Appliances OS Command Injection Vulnerability

SonicWall SMA100 appliances contain an OS command injection vulnerability in the SSL-VPN management interface that allows a remote, authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2023-44221EPSS 74.9%SMA100 AppliancesSonicWall
CISA KEV ↗ · unattributed attribution
high

CVE-2025-31324: SAP NetWeaver Unrestricted File Upload Vulnerability

SAP NetWeaver Visual Composer Metadata Uploader contains an unrestricted file upload vulnerability that allows an unauthenticated agent to upload potentially malicious executable binaries. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-31324EPSS 99.4%NetWeaverSAP
CISA KEV ↗ · unattributed attribution
high

CVE-2025-1976: Broadcom Brocade Fabric OS Code Injection Vulnerability

Broadcom Brocade Fabric OS contains a code injection vulnerability that allows a local user with administrative privileges to execute arbitrary code with full root privileges. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-1976EPSS 0.8%BroadcomBrocade Fabric OS
CISA KEV ↗ · unattributed attribution
high

CVE-2025-42599: Qualitia Active! Mail Stack-Based Buffer Overflow Vulnerability

Qualitia Active! Mail contains a stack-based buffer overflow vulnerability that allows a remote, unauthenticated attacker to execute arbitrary or trigger a denial-of-service via a specially crafted request. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-42599EPSS 3.1%Active! MailQualitia
CISA KEV ↗ · unattributed attribution
high

CVE-2025-3928: Commvault Web Server Unspecified Vulnerability

Commvault Web Server contains an unspecified vulnerability that allows a remote, authenticated attacker to create and execute webshells. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-3928EPSS 2.0%CommvaultWeb Server
CISA KEV ↗ · unattributed attribution
high

CVE-2025-24054: Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerability

Microsoft Windows NTLM contains an external control of file name or path vulnerability that allows an unauthorized attacker to perform spoofing over a network. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-24054EPSS 59.0%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-31201: Apple Multiple Products Arbitrary Read and Write Vulnerability

Apple iOS, iPadOS, macOS, and other Apple products contain an arbitrary read and write vulnerability that allows an attacker to bypass Pointer Authentication. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-31201EPSS 12.8%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2025-31200: Apple Multiple Products Memory Corruption Vulnerability

Apple iOS, iPadOS, macOS, and other Apple products contain a memory corruption vulnerability that allows for code execution when processing an audio stream in a maliciously crafted media file. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-31200EPSS 21.9%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2021-20035: SonicWall SMA100 Appliances OS Command Injection Vulnerability

SonicWall SMA100 appliances contain an OS command injection vulnerability in the management interface that allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user, which could potentially lead to code execution. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2021-20035EPSS 3.9%SMA100 AppliancesSonicWall
CISA KEV ↗ · unattributed attribution
high

CVE-2024-53150: Linux Kernel Out-of-Bounds Read Vulnerability

Linux Kernel contains an out-of-bounds read vulnerability in the USB-audio driver that allows a local, privileged attacker to obtain potentially sensitive information. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2024-53150EPSS 1.3%KernelLinux
CISA KEV ↗ · unattributed attribution
high

CVE-2024-53197: Linux Kernel Out-of-Bounds Access Vulnerability

Linux Kernel contains an out-of-bounds access vulnerability in the USB-audio driver that allows an attacker with physical access to the system to use a malicious USB device to potentially manipulate system memory, escalate privileges, or execute arbitrary code. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2024-53197EPSS 3.6%KernelLinux
CISA KEV ↗ · unattributed attribution
high

CVE-2025-29824: Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability

Microsoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-29824EPSS 13.5%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-30406: Gladinet CentreStack and Triofox Use of Hard-coded Cryptographic Key Vulnerability

Gladinet CentreStack and Triofox contains a use of hard-coded cryptographic key vulnerability in the way that the application manages keys used for ViewState integrity verification. Successful exploitation allows an attacker to forge ViewState payloads for server-side deserialization, allowing for remote code execution. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-30406EPSS 93.8%CentreStackGladinet
CISA KEV ↗ · unattributed attribution
high

CVE-2025-31161: CrushFTP Authentication Bypass Vulnerability

CrushFTP contains an authentication bypass vulnerability in the HTTP authorization header that allows a remote unauthenticated attacker to authenticate to any known or guessable user account (e.g., crushadmin), potentially leading to a full compromise. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-31161EPSS 99.9%CrushFTP
CISA KEV ↗ · unattributed attribution
high

CVE-2025-22457: Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability

Ivanti Connect Secure, Policy Secure, and ZTA Gateways contains a stack-based buffer overflow vulnerability that allows a remote unauthenticated attacker to achieve remote code execution. Required action: Apply mitigations as set forth in the CISA instructions linked below.

CVE-2025-22457EPSS 100.0%Connect Secure, Policy Secure, and ZTA GatewaysIvanti
CISA KEV ↗ · unattributed attribution
high

CVE-2025-24813: Apache Tomcat Path Equivalence Vulnerability

Apache Tomcat contains a path equivalence vulnerability that allows a remote attacker to execute code, disclose information, or inject malicious content via a partial PUT request. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-24813EPSS 99.9%ApacheTomcat
CISA KEV ↗ · unattributed attribution
high

CVE-2024-20439: Cisco Smart Licensing Utility Static Credential Vulnerability

Cisco Smart Licensing Utility contains a static credential vulnerability that allows an unauthenticated, remote attacker to log in to an affected system and gain administrative credentials. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2024-20439EPSS 91.9%CiscoSmart Licensing Utility
CISA KEV ↗ · unattributed attribution
high

CVE-2025-2783: Google Chromium Mojo Sandbox Escape Vulnerability

Google Chromium Mojo on Windows contains a sandbox escape vulnerability caused by a logic error, which results from an incorrect handle being provided in unspecified circumstances. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-2783EPSS 8.4%Chromium MojoGoogle
CISA KEV ↗ · unattributed attribution
high

CVE-2019-9875: Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability

Sitecore CMS and Experience Platform (XP) contain a deserialization vulnerability in the Sitecore.Security.AntiCSRF module that allows an authenticated attacker to execute arbitrary code by sending a serialized .NET object in the HTTP POST parameter __CSRFTOKEN. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2019-9875EPSS 14.2%CMS and Experience Platform (XP)Sitecore
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2019-9874: Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability

Sitecore CMS and Experience Platform (XP) contain a deserialization vulnerability in the Sitecore.Security.AntiCSRF module that allows an unauthenticated attacker to execute arbitrary code by sending a serialized .NET object in the HTTP POST parameter __CSRFTOKEN. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2019-9874EPSS 83.9%CMS and Experience Platform (XP)Sitecore
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2025-30154: reviewdog/action-setup GitHub Action Embedded Malicious Code Vulnerability

reviewdog action-setup GitHub Action contains an embedded malicious code vulnerability that dumps exposed secrets to Github Actions Workflow Logs. Required action: Apply mitigations as set forth in the CISA instructions linked below. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-30154EPSS 2.3%action-setup GitHub Actionreviewdog
CISA KEV ↗ · unattributed attribution
high

CVE-2017-12637: SAP NetWeaver Directory Traversal Vulnerability

SAP NetWeaver Application Server (AS) Java contains a directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS that allows a remote attacker to read arbitrary files via a .. (dot dot) in the query string. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2017-12637EPSS 94.6%NetWeaverSAP
CISA KEV ↗ · unattributed attribution
high

CVE-2024-48248: NAKIVO Backup and Replication Absolute Path Traversal Vulnerability

NAKIVO Backup and Replication contains an absolute path traversal vulnerability that enables an attacker to read arbitrary files. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2024-48248EPSS 94.1%Backup and ReplicationNAKIVO
CISA KEV ↗ · unattributed attribution
high

CVE-2025-1316: Edimax IC-7100 IP Camera OS Command Injection Vulnerability

Edimax IC-7100 IP camera contains an OS command injection vulnerability due to improper input sanitization that allows an attacker to achieve remote code execution via specially crafted requests. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-1316EPSS 72.3%EdimaxIC-7100 IP Camera
CISA KEV ↗ · unattributed attribution
high

CVE-2025-30066: tj-actions/changed-files GitHub Action Embedded Malicious Code Vulnerability

tj-actions/changed-files GitHub Action contains an embedded malicious code vulnerability that allows a remote attacker to discover secrets by reading Github Actions Workflow Logs. These secrets may include, but are not limited to, valid AWS access keys, GitHub personal access tokens (PATs), npm tokens, and private RSA keys. Required action: Apply mitigations as set forth in the CISA instructions linked below. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-30066EPSS 41.0%changed-files GitHub Actiontj-actions
CISA KEV ↗ · unattributed attribution
high

CVE-2025-24472: Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability

Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that allows a remote attacker to gain super-admin privileges via crafted CSF proxy requests. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-24472EPSS 3.1%FortiOS and FortiProxyFortinet
CISA KEV ↗ · unattributed attribution
high

CVE-2025-21590: Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability

Juniper Junos OS contains an improper isolation or compartmentalization vulnerability. This vulnerability could allows a local attacker with high privileges to inject arbitrary code. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-21590EPSS 1.7%JuniperJunos OS
CISA KEV ↗ · unattributed attribution
high

CVE-2025-24201: Apple Multiple Products WebKit Out-of-Bounds Write Vulnerability

Apple iOS, iPadOS, macOS, and other Apple products contain an out-of-bounds write vulnerability in WebKit that may allow maliciously crafted web content to break out of Web Content sandbox. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-24201EPSS 4.2%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2025-24993: Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability

Microsoft Windows New Technology File System (NTFS) contains a heap-based buffer overflow vulnerability that allows an unauthorized attacker to execute code locally. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-24993EPSS 2.1%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-24991: Microsoft Windows NTFS Out-Of-Bounds Read Vulnerability

Microsoft Windows New Technology File System (NTFS) contains an out-of-bounds read vulnerability that allows an authorized attacker to disclose information locally. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-24991EPSS 1.9%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-24985: Microsoft Windows Fast FAT File System Driver Integer Overflow Vulnerability

Microsoft Windows Fast FAT File System Driver contains an integer overflow or wraparound vulnerability that allows an unauthorized attacker to execute code locally. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-24985EPSS 3.7%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-24984: Microsoft Windows NTFS Information Disclosure Vulnerability

Microsoft Windows New Technology File System (NTFS) contains an insertion of sensitive Information into log file vulnerability that allows an unauthorized attacker to disclose information with a physical attack. An attacker who successfully exploited this vulnerability could potentially read portions of heap memory. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-24984EPSS 1.8%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-24983: Microsoft Windows Win32k Use-After-Free Vulnerability

Microsoft Windows Win32 Kernel Subsystem contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-24983EPSS 1.3%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-26633: Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability

Microsoft Windows Management Console (MMC) contains an improper neutralization vulnerability that allows an unauthorized attacker to bypass a security feature locally. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-26633EPSS 31.9%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2024-13161: Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability

Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2024-13161EPSS 89.8%Endpoint Manager (EPM)Ivanti
CISA KEV ↗ · unattributed attribution
high

CVE-2024-13160: Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability

Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2024-13160EPSS 91.0%Endpoint Manager (EPM)Ivanti
CISA KEV ↗ · unattributed attribution
high

CVE-2024-13159: Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability

Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2024-13159EPSS 99.8%Endpoint Manager (EPM)Ivanti
CISA KEV ↗ · unattributed attribution
high

CVE-2024-57968: Advantive VeraCore Unrestricted File Upload Vulnerability

Advantive VeraCore contains an unrestricted file upload vulnerability that allows a remote unauthenticated attacker to upload files to unintended folders via upload.apsx. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2024-57968EPSS 32.5%AdvantiveVeraCore
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2025-25181: Advantive VeraCore SQL Injection Vulnerability

Advantive VeraCore contains a SQL injection vulnerability in timeoutWarning.asp that allows a remote attacker to execute arbitrary SQL commands via the PmSess1 parameter. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-25181EPSS 50.9%AdvantiveVeraCore
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2025-22226: VMware ESXi, Workstation, and Fusion Information Disclosure Vulnerability

VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. Successful exploitation allows an attacker with administrative privileges to a virtual machine to leak memory from the vmx process. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-22226EPSS 1.7%ESXi, Workstation, and FusionVMware
CISA KEV ↗ · unattributed attribution
high

CVE-2025-22225: VMware ESXi Arbitrary Write Vulnerability

VMware ESXi contains an arbitrary write vulnerability. Successful exploitation allows an attacker with privileges within the VMX process to trigger an arbitrary kernel write leading to an escape of the sandbox. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-22225EPSS 1.0%ESXiVMware
CISA KEV ↗ · unattributed attribution
high

CVE-2025-22224: VMware ESXi and Workstation TOCTOU Race Condition Vulnerability

VMware ESXi and Workstation contain a time-of-check time-of-use (TOCTOU) race condition vulnerability that leads to an out-of-bounds write. Successful exploitation enables an attacker with local administrative privileges on a virtual machine to execute code as the virtual machine's VMX process running on the host. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-22224EPSS 1.5%ESXi and WorkstationVMware
CISA KEV ↗ · unattributed attribution
high

CVE-2024-50302: Linux Kernel Use of Uninitialized Resource Vulnerability

The Linux kernel contains a use of uninitialized resource vulnerability that allows an attacker to leak kernel memory via a specially crafted HID report. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2024-50302EPSS 0.8%KernelLinux
CISA KEV ↗ · unattributed attribution
high

CVE-2024-4885: Progress WhatsUp Gold Path Traversal Vulnerability

Progress WhatsUp Gold contains a path traversal vulnerability that allows an unauthenticated attacker to achieve remote code execution. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2024-4885EPSS 99.3%ProgressWhatsUp Gold
CISA KEV ↗ · unattributed attribution
high

CVE-2018-8639: Microsoft Windows Win32k Improper Resource Shutdown or Release Vulnerability

Microsoft Windows Win32k contains an improper resource shutdown or release vulnerability that allows for local, authenticated privilege escalation. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2018-8639EPSS 22.3%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2022-43769: Hitachi Vantara Pentaho BA Server Special Element Injection Vulnerability

Hitachi Vantara Pentaho BA Server contains a special element injection vulnerability that allows an attacker to inject Spring templates into properties files, allowing for arbitrary command execution. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2022-43769EPSS 97.7%Hitachi VantaraPentaho Business Analytics (BA) Server
CISA KEV ↗ · unattributed attribution
high

CVE-2022-43939: Hitachi Vantara Pentaho BA Server Authorization Bypass Vulnerability

Hitachi Vantara Pentaho BA Server contains a use of non-canonical URL paths for authorization decisions vulnerability that enables an attacker to bypass authorization. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2022-43939EPSS 92.3%Hitachi VantaraPentaho Business Analytics (BA) Server
CISA KEV ↗ · unattributed attribution
high

CVE-2023-20118: Cisco Small Business RV Series Routers Command Injection Vulnerability

Multiple Cisco Small Business RV Series Routers contains a command injection vulnerability in the web-based management interface. Successful exploitation could allow an authenticated, remote attacker to gain root-level privileges and access unauthorized data. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2023-20118EPSS 54.1%CiscoSmall Business RV Series Routers
CISA KEV ↗ · unattributed attribution
high

CVE-2023-34192: Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability

Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting (XSS) vulnerability that allows a remote authenticated attacker to execute arbitrary code via a crafted script to the /h/autoSaveDraft function. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2023-34192EPSS 77.3%SynacorZimbra Collaboration Suite (ZCS)
CISA KEV ↗ · unattributed attribution
high

CVE-2024-49035: Microsoft Partner Center Improper Access Control Vulnerability

Microsoft Partner Center contains an improper access control vulnerability that allows an attacker to escalate privileges. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2024-49035EPSS 1.3%MicrosoftPartner Center
CISA KEV ↗ · unattributed attribution
high

CVE-2024-20953: Oracle Agile Product Lifecycle Management (PLM) Deserialization Vulnerability

Oracle Agile Product Lifecycle Management (PLM) contains a deserialization vulnerability that allows a low-privileged attacker with network access via HTTP to compromise the system. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-20953EPSS 3.4%Agile Product Lifecycle Management (PLM)Oracle
CISA KEV ↗ · unattributed attribution
high

CVE-2017-3066: Adobe ColdFusion Deserialization Vulnerability

Adobe ColdFusion contains a deserialization vulnerability in the Apache BlazeDS library that allows for arbitrary code execution. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2017-3066EPSS 90.6%AdobeColdFusion
CISA KEV ↗ · unattributed attribution
high

CVE-2025-24989: Microsoft Power Pages Improper Access Control Vulnerability

Microsoft Power Pages contains an improper access control vulnerability that allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control. Required action: Apply mitigations per vendor instructions, follow BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-24989EPSS 1.7%MicrosoftPower Pages
CISA KEV ↗ · unattributed attribution
high

CVE-2025-0111: Palo Alto Networks PAN-OS File Read Vulnerability

Palo Alto Networks PAN-OS contains an external control of file name or path vulnerability. Successful exploitation enables an authenticated attacker with network access to the management web interface to read files on the PAN-OS filesystem that are readable by the “nobody” user. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2025-0111EPSS 1.9%PAN-OSPalo Alto Networks
CISA KEV ↗ · unattributed attribution
high

CVE-2025-23209: Craft CMS Code Injection Vulnerability

Craft CMS contains a code injection vulnerability caused by improper validation of the database backup path, ultimately enabling remote code execution. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2025-23209EPSS 4.7%Craft CMS
CISA KEV ↗ · unattributed attribution
high

CVE-2025-0108: Palo Alto Networks PAN-OS Authentication Bypass Vulnerability

Palo Alto Networks PAN-OS contains an authentication bypass vulnerability in its management web interface. This vulnerability allows an unauthenticated attacker with network access to the management web interface to bypass the authentication normally required and invoke certain PHP scripts. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2025-0108EPSS 98.4%PAN-OSPalo Alto Networks
CISA KEV ↗ · unattributed attribution
high

CVE-2024-53704: SonicWall SonicOS SSLVPN Improper Authentication Vulnerability

SonicWall SonicOS contains an improper authentication vulnerability in the SSLVPN authentication mechanism that allows a remote attacker to bypass authentication. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-53704EPSS 95.1%SonicOSSonicWall
CISA KEV ↗ · unattributed attribution
high

CVE-2024-57727: SimpleHelp Path Traversal Vulnerability

SimpleHelp remote support software contains multiple path traversal vulnerabilities that allow unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files may include server configuration files and hashed user passwords. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-57727EPSS 95.2%SimpleHelpSimpleHelp
CISA KEV ↗ · unattributed attribution
high

CVE-2025-24200: Apple iOS and iPadOS Incorrect Authorization Vulnerability

Apple iOS and iPadOS contains an incorrect authorization vulnerability that allows a physical attacker to disable USB Restricted Mode on a locked device. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2025-24200EPSS 4.4%AppleiOS and iPadOS
CISA KEV ↗ · unattributed attribution
high

CVE-2024-41710: Mitel SIP Phones Argument Injection Vulnerability

Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, contain an argument injection vulnerability due to insufficient parameter sanitization during the boot process. Successful exploitation may allow an attacker to execute arbitrary commands within the context of the system. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-41710EPSS 41.6%MitelSIP Phones
CISA KEV ↗ · unattributed attribution
high

CVE-2024-40891: Zyxel DSL CPE OS Command Injection Vulnerability

Multiple Zyxel DSL CPE devices contain a post-authentication command injection vulnerability in the management commands that could allow an authenticated attacker to execute OS commands via Telnet. Required action: The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.

CVE-2024-40891EPSS 22.0%DSL CPE DevicesZyxel
CISA KEV ↗ · unattributed attribution
high

CVE-2024-40890: Zyxel DSL CPE OS Command Injection Vulnerability

Multiple Zyxel DSL CPE devices contain a post-authentication command injection vulnerability in the CGI program that could allow an authenticated attacker to execute OS commands via a crafted HTTP request. Required action: The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.

CVE-2024-40890EPSS 22.4%DSL CPE DevicesZyxel
CISA KEV ↗ · unattributed attribution
high

CVE-2025-21418: Microsoft Windows Ancillary Function Driver for WinSock Heap-Based Buffer Overflow Vulnerability

Microsoft Windows Ancillary Function Driver for WinSock contains a heap-based buffer overflow vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2025-21418EPSS 1.5%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-21391: Microsoft Windows Storage Link Following Vulnerability

Microsoft Windows Storage contains a link following vulnerability that could allow for privilege escalation. This vulnerability could allow an attacker to delete data including data that results in the service being unavailable. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2025-21391EPSS 2.3%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-0994: Trimble Cityworks Deserialization Vulnerability

Trimble Cityworks contains a deserialization vulnerability. This could allow an authenticated user to perform a remote code execution attack against a customer's Microsoft Internet Information Services (IIS) web server. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2025-0994EPSS 31.3%CityworksTrimble
CISA KEV ↗ · unattributed attribution
high

CVE-2020-15069: Sophos XG Firewall Buffer Overflow Vulnerability

Sophos XG Firewall contains a buffer overflow vulnerability that allows for remote code execution via the "HTTP/S bookmark" feature. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2020-15069EPSS 10.7%SophosXG Firewall
CISA KEV ↗ · unattributed attribution
high

CVE-2020-29574: CyberoamOS (CROS) SQL Injection Vulnerability

CyberoamOS (CROS) contains a SQL injection vulnerability in the WebAdmin that allows an unauthenticated attacker to execute arbitrary SQL statements remotely. Required action: The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.

CVE-2020-29574EPSS 4.7%CyberoamOSSophos
CISA KEV ↗ · unattributed attribution
high

CVE-2024-21413: Microsoft Outlook Improper Input Validation Vulnerability

Microsoft Outlook contains an improper input validation vulnerability that allows for remote code execution. Successful exploitation of this vulnerability would allow an attacker to bypass the Office Protected View and open in editing mode rather than protected mode. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-21413EPSS 94.7%MicrosoftOffice Outlook
CISA KEV ↗ · unattributed attribution
high

CVE-2022-23748: Dante Discovery Process Control Vulnerability

Dante Discovery contains a process control vulnerability in mDNSResponder.exe that all allows for a DLL sideloading attack. A local attacker can leverage this vulnerability in the Dante Application Library to execute arbitrary code. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2022-23748EPSS 9.1%AudinateDante Discovery
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2025-0411: 7-Zip Mark of the Web Bypass Vulnerability

7-Zip contains a protection mechanism failure vulnerability that allows remote attackers to bypass the Mark-of-the-Web security feature to execute arbitrary code in the context of the current user. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2025-0411EPSS 67.1%7-Zip
CISA KEV ↗ · unattributed attribution
high

CVE-2024-53104: Linux Kernel Out-of-Bounds Write Vulnerability

Linux kernel contains an out-of-bounds write vulnerability in the uvc_parse_streaming component of the USB Video Class (UVC) driver that could allow for physical escalation of privilege. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-53104EPSS 3.3%KernelLinux
CISA KEV ↗ · unattributed attribution
high

CVE-2018-19410: Paessler PRTG Network Monitor Local File Inclusion Vulnerability

Paessler PRTG Network Monitor contains a local file inclusion vulnerability that allows a remote, unauthenticated attacker to create users with read-write privileges (including administrator). Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2018-19410EPSS 86.5%PRTG Network MonitorPaessler
CISA KEV ↗ · unattributed attribution
high

CVE-2018-9276: Paessler PRTG Network Monitor OS Command Injection Vulnerability

Paessler PRTG Network Monitor contains an OS command injection vulnerability that allows an attacker with administrative privileges to execute commands via the PRTG System Administrator web console. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2018-9276EPSS 87.2%PRTG Network MonitorPaessler
CISA KEV ↗ · unattributed attribution
high

CVE-2024-29059: Microsoft .NET Framework Information Disclosure Vulnerability

Microsoft .NET Framework contains an information disclosure vulnerability that exposes the ObjRef URI to an attacker, ultimately enabling remote code execution. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-29059EPSS 98.6%.NET FrameworkMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2024-45195: Apache OFBiz Forced Browsing Vulnerability

Apache OFBiz contains a forced browsing vulnerability that allows a remote attacker to obtain unauthorized access. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-45195EPSS 100.0%ApacheOFBiz
CISA KEV ↗ · unattributed attribution
high

CVE-2025-24085: Apple Multiple Products Use-After-Free Vulnerability

Apple iOS, macOS, and other Apple products contain a user-after-free vulnerability that could allow a malicious application to elevate privileges. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2025-24085EPSS 18.7%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2025-23006: SonicWall SMA1000 Appliances Deserialization Vulnerability

SonicWall SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC) contain a deserialization of untrusted data vulnerability, which can enable a remote, unauthenticated attacker to execute arbitrary OS commands. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2025-23006EPSS 23.4%SMA1000 AppliancesSonicWall
CISA KEV ↗ · unattributed attribution
high

CVE-2020-11023: JQuery Cross-Site Scripting (XSS) Vulnerability

JQuery contains a persistent cross-site scripting (XSS) vulnerability. When passing maliciously formed, untrusted input enclosed in HTML tags, JQuery's DOM manipulators can execute untrusted code in the context of the user's browser. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2020-11023EPSS 83.8%JQuery
CISA KEV ↗ · unattributed attribution
high

CVE-2024-50603: Aviatrix Controllers OS Command Injection Vulnerability

Aviatrix Controllers contain an OS command injection vulnerability that could allow an unauthenticated attacker to execute arbitrary code. Shell metacharacters can be sent to /v1/api in cloud_type for list_flightpath_destination_instances, or src_cloud_type for flightpath_connection_test. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-50603EPSS 98.5%AviatrixControllers
CISA KEV ↗ · unattributed attribution
high

CVE-2024-55591: Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability

Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that may allow an unauthenticated, remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-55591EPSS 98.3%FortiOS and FortiProxyFortinet
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2023-48365: Qlik Sense HTTP Tunneling Vulnerability

Qlik Sense contains an HTTP tunneling vulnerability that allows an attacker to escalate privileges and execute HTTP requests on the backend server hosting the software. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-48365EPSS 24.7%QlikSense
CISA KEV ↗ · unattributed attribution
high

CVE-2024-12686: BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) OS Command Injection Vulnerability

BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain an OS command injection vulnerability that can be exploited by an attacker with existing administrative privileges to upload a malicious file. Successful exploitation of this vulnerability can allow a remote attacker to execute underlying operating system commands within the context of the site user. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-12686EPSS 13.8%BeyondTrustPrivileged Remote Access (PRA) and Remote Support (RS)
CISA KEV ↗ · unattributed attribution
high

CVE-2025-0282: Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability

Ivanti Connect Secure, Policy Secure, and ZTA Gateways contain a stack-based buffer overflow which can lead to unauthenticated remote code execution. Required action: Apply mitigations as set forth in the CISA instructions linked below to include conducting hunt activities, taking remediation actions if applicable, and applying updates prior to returning a device to service.

CVE-2025-0282EPSS 100.0%Connect Secure, Policy Secure, and ZTA GatewaysIvanti
CISA KEV ↗ · unattributed attribution
high

CVE-2020-2883: Oracle WebLogic Server Unspecified Vulnerability

Oracle WebLogic Server, a product within the Fusion Middleware suite, contains an unspecified vulnerability exploitable by an unauthenticated attacker with network access via IIOP or T3. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2020-2883EPSS 94.9%OracleWebLogic Server
CISA KEV ↗ · unattributed attribution
high

CVE-2024-55550: Mitel MiCollab Path Traversal Vulnerability

Mitel MiCollab contains a path traversal vulnerability that could allow an authenticated attacker with administrative privileges to read local files within the system due to insufficient input sanitization. This vulnerability can be chained with CVE-2024-41713, which allows an unauthenticated, remote attacker to read arbitrary files on the server. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-41713CVE-2024-55550EPSS 98.1%MiCollabMitel
CISA KEV ↗ · unattributed attribution
high

CVE-2024-41713: Mitel MiCollab Path Traversal Vulnerability

Mitel MiCollab contains a path traversal vulnerability that could allow an attacker to gain unauthorized and unauthenticated access. This vulnerability can be chained with CVE-2024-55550, which allows an unauthenticated, remote attacker to read arbitrary files on the server. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-41713CVE-2024-55550EPSS 98.1%MiCollabMitel
CISA KEV ↗ · unattributed attribution
high

CVE-2024-3393: Palo Alto Networks PAN-OS Malicious DNS Packet Vulnerability

Palo Alto Networks PAN-OS contains a vulnerability in parsing and logging malicious DNS packets in the DNS Security feature that, when exploited, allows an unauthenticated attacker to remotely reboot the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-3393EPSS 26.6%PAN-OSPalo Alto Networks
CISA KEV ↗ · unattributed attribution
high

CVE-2021-44207: Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability

Acclaim Systems USAHERDS contains a hard-coded credentials vulnerability that could allow an attacker to achieve remote code execution on the system that runs the application. The MachineKey must be obtained via a separate vulnerability or other channel. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Please contact the product developer for support and vulnerability mitigation.

CVE-2021-44207EPSS 17.6%Acclaim SystemsUSAHERDS
CISA KEV ↗ · unattributed attribution
high

CVE-2024-12356: BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) Command Injection Vulnerability

BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain a command injection vulnerability, which can allow an unauthenticated attacker to inject commands that are run as a site user. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-12356EPSS 88.0%BeyondTrustPrivileged Remote Access (PRA) and Remote Support (RS)
CISA KEV ↗ · unattributed attribution
high

CVE-2021-40407: Reolink RLC-410W IP Camera OS Command Injection Vulnerability

Reolink RLC-410W IP cameras contain an authenticated OS command injection vulnerability in the device network settings functionality. Required action: The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.

CVE-2021-40407EPSS 47.9%RLC-410W IP CameraReolink
CISA KEV ↗ · unattributed attribution
high

CVE-2019-11001: Reolink Multiple IP Cameras OS Command Injection Vulnerability

Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W IP cameras contain an authenticated OS command injection vulnerability. This vulnerability allows an authenticated admin to use the "TestEmail" functionality to inject and run OS commands as root. Required action: The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.

CVE-2019-11001EPSS 38.4%Multiple IP CamerasReolink
CISA KEV ↗ · unattributed attribution
high

CVE-2022-23227: NUUO NVRmini2 Devices Missing Authentication Vulnerability

NUUO NVRmini2 devices contain a missing authentication vulnerability that allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users. Required action: The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.

CVE-2022-23227EPSS 49.4%NUUONVRmini2 Devices
CISA KEV ↗ · unattributed attribution
high

CVE-2018-14933: NUUO NVRmini Devices OS Command Injection Vulnerability

NUUO NVRmini devices contain an OS command injection vulnerability. This vulnerability allows remote command execution via shell metacharacters in the uploaddir parameter for a writeuploaddir command. Required action: The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.

CVE-2018-14933EPSS 93.7%NUUONVRmini Devices
CISA KEV ↗ · unattributed attribution
high

CVE-2024-55956: Cleo Multiple Products Unauthenticated File Upload Vulnerability

Cleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload vulnerability that could allow an unauthenticated user to import and execute arbitrary bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-55956EPSS 93.8%CleoMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2024-20767: Adobe ColdFusion Improper Access Control Vulnerability

Adobe ColdFusion contains an improper access control vulnerability that could allow an attacker to access or modify restricted files via an internet-exposed admin panel. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-20767EPSS 98.5%AdobeColdFusion
CISA KEV ↗ · unattributed attribution
high

CVE-2024-50623: Cleo Multiple Products Unrestricted File Upload Vulnerability

Cleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload and download vulnerability that can lead to remote code execution with elevated privileges. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-50623EPSS 98.5%CleoMultiple Products
CISA KEV ↗ · unattributed attribution
unknown

ATT&CK profile: Sandworm Team

[Sandworm Team](https://attack.mitre.org/groups/G0034) is a destructive threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) Main Center for Special Technologies (GTsST) military unit 74455.(Citation: US District Court Indictment GRU Unit 74455 October 2020)(Citation: UK NCSC Olympic Attacks October 2020) This group has been active since at least 2009.(Citation: iSIGHT Sandworm 2014)(Citation: CrowdStrike VOODOO BEAR)(Citation: USDOJ Sandworm Feb 2020)(Citation: NCSC Sandworm Feb 2020) In October 2020, the US indicted six GRU Unit 74455 officers associated with [Sandworm Team](https://attack.mitre.org/groups/G0034) for the following cyber operations: the 2015 and 2016 attacks against Ukrainian electrical companies and government organizations, the 2017 worldwide [NotPetya](https://attack.mitre.org/software/S0368) attack, targeting of the 2017 French presidential campaign, the 2018 [Olympic Destroyer](https://attack.mitre.org/software/S0365

Sandworm TeamBlackEnergy (Group)ELECTRUMIRIDIUM
MITRE ATT&CK ↗ · confirmed attribution · 3 IOCs
high

CVE-2024-51378: CyberPanel Incorrect Default Permissions Vulnerability

CyberPanel contains an incorrect default permissions vulnerability that allows for authentication bypass and the execution of arbitrary commands using shell metacharacters in the statusfile property. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-51378EPSS 94.8%CyberPanelCyberPersons
CISA KEV ↗ · unattributed attribution
high

CVE-2024-11667: Zyxel Multiple Firewalls Path Traversal Vulnerability

Multiple Zyxel firewalls contain a path traversal vulnerability in the web management interface that could allow an attacker to download or upload files via a crafted URL. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-11667EPSS 3.0%Multiple FirewallsZyxel
CISA KEV ↗ · unattributed attribution
high

CVE-2024-11680: ProjectSend Improper Authentication Vulnerability

ProjectSend contains an improper authentication vulnerability that allows a remote, unauthenticated attacker to enable unauthorized modification of the application's configuration via crafted HTTP requests to options.php. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-11680EPSS 91.6%ProjectSend
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2023-45727: North Grid Proself Improper Restriction of XML External Entity (XXE) Reference Vulnerability

North Grid Proself Enterprise/Standard, Gateway, and Mail Sanitize contain an improper restriction of XML External Entity (XXE) reference vulnerability, which could allow a remote, unauthenticated attacker to conduct an XXE attack. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-45727EPSS 3.5%North GridProself
CISA KEV ↗ · unattributed attribution
high

CVE-2023-28461: Array Networks AG and vxAG ArrayOS Missing Authentication for Critical Function Vulnerability

Array Networks AG and vxAG ArrayOS contain a missing authentication for critical function vulnerability that allows an attacker to read local files and execute code on the SSL VPN gateway. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-28461EPSS 67.6%AG/vxAG ArrayOSArray Networks
CISA KEV ↗ · unattributed attribution
high

CVE-2024-21287: Oracle Agile Product Lifecycle Management (PLM) Incorrect Authorization Vulnerability

Oracle Agile Product Lifecycle Management (PLM) contains an incorrect authorization vulnerability in the Process Extension component of the Software Development Kit. Successful exploitation of this vulnerability may result in unauthenticated file disclosure. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-21287EPSS 1.5%Agile Product Lifecycle Management (PLM)Oracle
CISA KEV ↗ · unattributed attribution
high

CVE-2024-44309: Apple Multiple Products Cross-Site Scripting (XSS) Vulnerability

Apple iOS, macOS, and other Apple products contain an unspecified vulnerability when processing maliciously crafted web content that may lead to a cross-site scripting (XSS) attack. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-44309EPSS 22.7%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2024-44308: Apple Multiple Products Code Execution Vulnerability

Apple iOS, macOS, and other Apple products contain an unspecified vulnerability when processing maliciously crafted web content that may lead to arbitrary code execution. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-44308EPSS 9.2%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2024-38813: VMware vCenter Server Privilege Escalation Vulnerability

VMware vCenter contains an improper check for dropped privileges vulnerability. This vulnerability could allow an attacker with network access to the vCenter Server to escalate privileges to root by sending a specially crafted packet. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-38813EPSS 16.7%VMwarevCenter Server
CISA KEV ↗ · unattributed attribution
high

CVE-2024-38812: VMware vCenter Server Heap-Based Buffer Overflow Vulnerability

VMware vCenter Server contains a heap-based buffer overflow vulnerability in the implementation of the DCERPC protocol. This vulnerability could allow an attacker with network access to the vCenter Server to execute remote code by sending a specially crafted packet. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-38812EPSS 54.1%VMwarevCenter Server
CISA KEV ↗ · unattributed attribution
high

CVE-2024-9474: Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability

Palo Alto Networks PAN-OS contains an OS command injection vulnerability that allows for privilege escalation through the web-based management interface for several PAN products, including firewalls and VPN concentrators. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Additionally, the management interfaces for affected devices should not be exposed to untrusted networks, including the internet.

CVE-2024-9474EPSS 94.8%PAN-OSPalo Alto Networks
CISA KEV ↗ · unattributed attribution
high

CVE-2024-0012: Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability

Palo Alto Networks PAN-OS contains an authentication bypass vulnerability in the web-based management interface for several PAN-OS products, including firewalls and VPN concentrators. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Additionally, management interface for affected devices should not be exposed to untrusted networks, including the internet.

CVE-2024-0012EPSS 99.7%PAN-OSPalo Alto Networks
CISA KEV ↗ · unattributed attribution
high

CVE-2024-1212: Progress Kemp LoadMaster OS Command Injection Vulnerability

Progress Kemp LoadMaster contains an OS command injection vulnerability that allows an unauthenticated, remote attacker to access the system through the LoadMaster management interface, enabling arbitrary system command execution. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-1212EPSS 95.4%Kemp LoadMasterProgress
CISA KEV ↗ · unattributed attribution
high

CVE-2024-9465: Palo Alto Networks Expedition SQL Injection Vulnerability

Palo Alto Networks Expedition contains a SQL injection vulnerability that allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. With this, attackers can also create and read arbitrary files on the Expedition system. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-9465EPSS 99.6%ExpeditionPalo Alto Networks
CISA KEV ↗ · unattributed attribution
high

CVE-2024-9463: Palo Alto Networks Expedition OS Command Injection Vulnerability

Palo Alto Networks Expedition contains an OS command injection vulnerability that allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-9463EPSS 98.5%ExpeditionPalo Alto Networks
CISA KEV ↗ · unattributed attribution
high

CVE-2021-26086: Atlassian Jira Server and Data Center Path Traversal Vulnerability

Atlassian Jira Server and Data Center contain a path traversal vulnerability that allows a remote attacker to read particular files in the /WEB-INF/web.xml endpoint. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2021-26086EPSS 100.0%AtlassianJira Server and Data Center
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2014-2120: Cisco Adaptive Security Appliance (ASA) Cross-Site Scripting (XSS) Vulnerability

Cisco Adaptive Security Appliance (ASA) contains a cross-site scripting (XSS) vulnerability in the WebVPN login page. This vulnerability allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2014-2120EPSS 14.0%Adaptive Security Appliance (ASA)Cisco
CISA KEV ↗ · unattributed attribution
high

CVE-2021-41277: Metabase GeoJSON API Local File Inclusion Vulnerability

Metabase contains a local file inclusion vulnerability in the custom map support in the API to read GeoJSON formatted data. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2021-41277EPSS 97.2%Metabase
CISA KEV ↗ · unattributed attribution
high

CVE-2024-43451: Microsoft Windows NTLMv2 Hash Disclosure Spoofing Vulnerability

Microsoft Windows contains an NTLMv2 hash spoofing vulnerability that could result in disclosing a user's NTLMv2 hash to an attacker via a file open operation. The attacker could then leverage this hash to impersonate that user. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-43451EPSS 81.8%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2024-49039: Microsoft Windows Task Scheduler Privilege Escalation Vulnerability

Microsoft Windows Task Scheduler contains a privilege escalation vulnerability that can allow an attacker-provided, local application to escalate privileges outside of its AppContainer, and access privileged RPC functions. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-49039EPSS 13.7%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2019-16278: Nostromo nhttpd Directory Traversal Vulnerability

Nostromo nhttpd contains a directory traversal vulnerability in the http_verify() function in a non-chrooted nhttpd server allowing for remote code execution. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2019-16278EPSS 99.1%Nostromonhttpd
CISA KEV ↗ · unattributed attribution
high

CVE-2024-51567: CyberPanel Incorrect Default Permissions Vulnerability

CyberPanel contains an incorrect default permissions vulnerability that allows a remote, unauthenticated attacker to execute commands as root. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-51567EPSS 86.7%CyberPanelCyberPersons
CISA KEV ↗ · unattributed attribution
high

CVE-2024-5910: Palo Alto Networks Expedition Missing Authentication Vulnerability

Palo Alto Networks Expedition contains a missing authentication vulnerability that allows an attacker with network access to takeover an Expedition admin account and potentially access configuration secrets, credentials, and other data. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-5910EPSS 91.8%ExpeditionPalo Alto Networks
CISA KEV ↗ · unattributed attribution
high

CVE-2024-8956: PTZOptics PT30X-SDI/NDI Cameras Authentication Bypass Vulnerability

PTZOptics PT30X-SDI/NDI cameras contain an insecure direct object reference (IDOR) vulnerability that allows a remote, attacker to bypass authentication for the /cgi-bin/param.cgi CGI script. If combined with CVE-2024-8957, this can lead to remote code execution as root. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-8956CVE-2024-8957EPSS 82.0%PT30X-SDI/NDI CamerasPTZOptics
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2024-8957: PTZOptics PT30X-SDI/NDI Cameras OS Command Injection Vulnerability

PTZOptics PT30X-SDI/NDI cameras contain an OS command injection vulnerability that allows a remote, authenticated attacker to escalate privileges to root via a crafted payload with the ntp_addr parameter of the /cgi-bin/param.cgi CGI script. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-8957EPSS 82.0%PT30X-SDI/NDI CamerasPTZOptics
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2024-37383: RoundCube Webmail Cross-Site Scripting (XSS) Vulnerability

RoundCube Webmail contains a cross-site scripting (XSS) vulnerability in the handling of SVG animate attributes that allows a remote attacker to run malicious JavaScript code. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-37383EPSS 73.3%RoundcubeWebmail
CISA KEV ↗ · unattributed attribution
high

CVE-2024-20481: Cisco ASA and FTD Denial-of-Service Vulnerability

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain a missing release of resource after effective lifetime vulnerability that could allow an unauthenticated, remote attacker to cause a denial-of-service (DoS) of the RAVPN service. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-20481EPSS 16.0%Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)Cisco
CISA KEV ↗ · unattributed attribution
high

CVE-2024-47575: Fortinet FortiManager Missing Authentication Vulnerability

Fortinet FortiManager contains a missing authentication vulnerability in the fgfmd daemon that allows a remote, unauthenticated attacker to execute arbitrary code or commands via specially crafted requests. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-47575EPSS 94.8%FortiManagerFortinet
CISA KEV ↗ · unattributed attribution
high

CVE-2024-38094: Microsoft SharePoint Deserialization Vulnerability

Microsoft SharePoint contains a deserialization vulnerability that allows for remote code execution. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-38094EPSS 47.8%MicrosoftSharePoint
CISA KEV ↗ · unattributed attribution
high

CVE-2024-9537: ScienceLogic SL1 Unspecified Vulnerability

ScienceLogic SL1 (formerly EM7) is affected by an unspecified vulnerability involving an unspecified third-party component. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-9537EPSS 3.9%SL1ScienceLogic
CISA KEV ↗ · unattributed attribution
high

CVE-2024-40711: Veeam Backup and Replication Deserialization Vulnerability

Veeam Backup and Replication contains a deserialization vulnerability allowing an unauthenticated user to perform remote code execution. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-40711EPSS 90.2%Backup & ReplicationVeeam
CISA KEV ↗ · unattributed attribution
high

CVE-2024-28987: SolarWinds Web Help Desk Hardcoded Credential Vulnerability

SolarWinds Web Help Desk contains a hardcoded credential vulnerability that could allow a remote, unauthenticated user to access internal functionality and modify data. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-28987EPSS 93.3%SolarWindsWeb Help Desk
CISA KEV ↗ · unattributed attribution
high

CVE-2024-9680: Mozilla Firefox Use-After-Free Vulnerability

Mozilla Firefox and Firefox ESR contain a use-after-free vulnerability in Animation timelines that allows for code execution in the content process. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-9680EPSS 23.2%FirefoxMozilla
CISA KEV ↗ · unattributed attribution
high

CVE-2024-30088: Microsoft Windows Kernel TOCTOU Race Condition Vulnerability

Microsoft Windows Kernel contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that could allow for privilege escalation. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-30088EPSS 68.2%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2024-9380: Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability

Ivanti Cloud Services Appliance (CSA) contains an OS command injection vulnerability in the administrative console which can allow an authenticated attacker with application admin privileges to pass commands to the underlying OS. Required action: As Ivanti CSA 4.6.x has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line, or later, of supported solution.

CVE-2024-9380EPSS 62.8%Cloud Services Appliance (CSA)Ivanti
CISA KEV ↗ · unattributed attribution
high

CVE-2024-9379: Ivanti Cloud Services Appliance (CSA) SQL Injection Vulnerability

Ivanti Cloud Services Appliance (CSA) contains a SQL injection vulnerability in the admin web console in versions prior to 5.0.2, which can allow a remote attacker authenticated as administrator to run arbitrary SQL statements. Required action: As Ivanti CSA 4.6.x has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line, or later, of supported solution.

CVE-2024-9379EPSS 43.4%Cloud Services Appliance (CSA)Ivanti
CISA KEV ↗ · unattributed attribution
high

CVE-2024-23113: Fortinet Multiple Products Format String Vulnerability

Fortinet FortiOS, FortiPAM, FortiProxy, and FortiWeb contain a format string vulnerability that allows a remote, unauthenticated attacker to execute arbitrary code or commands via specially crafted requests. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-23113EPSS 61.7%FortinetMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2024-43573: Microsoft Windows MSHTML Platform Spoofing Vulnerability

Microsoft Windows MSHTML Platform contains an unspecified spoofing vulnerability which can lead to a loss of confidentiality. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-43573EPSS 43.7%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2024-43047: Qualcomm Multiple Chipsets Use-After-Free Vulnerability

Multiple Qualcomm chipsets contain a use-after-free vulnerability due to memory corruption in DSP Services while maintaining memory maps of HLOS memory. Required action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.

CVE-2024-43047EPSS 0.7%Multiple Chipsets Qualcomm
CISA KEV ↗ · unattributed attribution
high

CVE-2024-45519: Synacor Zimbra Collaboration Suite (ZCS) Command Execution Vulnerability

Synacor Zimbra Collaboration Suite (ZCS) contains an unspecified vulnerability in the postjournal service that may allow an unauthenticated user to execute commands. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-45519EPSS 99.9%SynacorZimbra Collaboration Suite (ZCS)
CISA KEV ↗ · unattributed attribution
high

CVE-2024-29824: Ivanti Endpoint Manager (EPM) SQL Injection Vulnerability

Ivanti Endpoint Manager (EPM) contains a SQL injection vulnerability in Core server that allows an unauthenticated attacker within the same network to execute arbitrary code. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-29824EPSS 100.0%Endpoint Manager (EPM)Ivanti
CISA KEV ↗ · unattributed attribution
high

CVE-2019-0344: SAP Commerce Cloud Deserialization of Untrusted Data Vulnerability

SAP Commerce Cloud (formerly known as Hybris) contains a deserialization of untrusted data vulnerability within the mediaconversion and virtualjdbc extension that allows for code injection. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2019-0344EPSS 7.1%Commerce CloudSAP
CISA KEV ↗ · unattributed attribution
high

CVE-2020-15415: DrayTek Multiple Vigor Routers OS Command Injection Vulnerability

DrayTek Vigor3900, Vigor2960, and Vigor300B devices contain an OS command injection vulnerability in cgi-bin/mainfunction.cgi/cvmcfgupload that allows for remote code execution via shell metacharacters in a filename when the text/x-python-script content type is used. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2020-15415EPSS 84.2%DrayTekMultiple Vigor Routers
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2023-25280: D-Link DIR-820 Router OS Command Injection Vulnerability

D-Link DIR-820 routers contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp. Required action: The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.

CVE-2023-25280EPSS 98.1%D-LinkDIR-820 Router
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2024-7593: Ivanti Virtual Traffic Manager Authentication Bypass Vulnerability

Ivanti Virtual Traffic Manager contains an authentication bypass vulnerability that allows a remote, unauthenticated attacker to create a chosen administrator account. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-7593EPSS 100.0%IvantiVirtual Traffic Manager
CISA KEV ↗ · unattributed attribution
high

CVE-2024-8963: Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability

Ivanti Cloud Services Appliance (CSA) contains a path traversal vulnerability that could allow a remote, unauthenticated attacker to access restricted functionality. If CVE-2024-8963 is used in conjunction with CVE-2024-8190, an attacker could bypass admin authentication and execute arbitrary commands on the appliance. Required action: As Ivanti CSA has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line of supported solutions, as future vulnerabilities on the 4.6.x version of CSA are unlikely to receive security updates.

CVE-2024-8190CVE-2024-8963EPSS 98.6%Cloud Services Appliance (CSA)Ivanti
CISA KEV ↗ · unattributed attribution
high

CVE-2020-14644: Oracle WebLogic Server Remote Code Execution Vulnerability

Oracle WebLogic Server, a product within the Fusion Middleware suite, contains a deserialization vulnerability. Unauthenticated attackers with network access via T3 or IIOP can exploit this vulnerability to achieve remote code execution. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2020-14644EPSS 94.5%OracleWebLogic Server
CISA KEV ↗ · unattributed attribution
high

CVE-2022-21445: Oracle ADF Faces Deserialization of Untrusted Data Vulnerability

Oracle ADF Faces library, included with Oracle JDeveloper Distribution, contains a deserialization of untrusted data vulnerability leading to unauthenticated remote code execution. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2022-21445EPSS 62.5%ADF FacesOracle
CISA KEV ↗ · unattributed attribution
high

CVE-2020-0618: Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability

Microsoft SQL Server Reporting Services contains a deserialization vulnerability when handling page requests incorrectly. An authenticated attacker can exploit this vulnerability to execute code in the context of the Report Server service account. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2020-0618EPSS 99.0%MicrosoftSQL Server
CISA KEV ↗ · unattributed attribution
high

CVE-2024-27348: Apache HugeGraph-Server Improper Access Control Vulnerability

Apache HugeGraph-Server contains an improper access control vulnerability that could allow a remote attacker to execute arbitrary code. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-27348EPSS 99.2%ApacheHugeGraph-Server
CISA KEV ↗ · unattributed attribution
high

CVE-2014-0502: Adobe Flash Player Double Free Vulnerablity

Adobe Flash Player contains a double free vulnerability that allows a remote attacker to execute arbitrary code. Required action: The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.

CVE-2014-0502EPSS 24.2%AdobeFlash Player
CISA KEV ↗ · unattributed attribution
high

CVE-2013-0648: Adobe Flash Player Code Execution Vulnerability

Adobe Flash Player contains an unspecified vulnerability in the ExternalInterface ActionScript functionality that allows a remote attacker to execute arbitrary code via crafted SWF content. Required action: The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.

CVE-2013-0648EPSS 11.1%AdobeFlash Player
CISA KEV ↗ · unattributed attribution
high

CVE-2013-0643: Adobe Flash Player Incorrect Default Permissions Vulnerability

Adobe Flash Player contains an incorrect default permissions vulnerability in the Firefox sandbox that allows a remote attacker to execute arbitrary code via crafted SWF content. Required action: The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.

CVE-2013-0643EPSS 10.5%AdobeFlash Player
CISA KEV ↗ · unattributed attribution
high

CVE-2014-0497: Adobe Flash Player Integer Underflow Vulnerablity

Adobe Flash Player contains an integer underflow vulnerability that allows a remote attacker to execute arbitrary code. Required action: The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.

CVE-2014-0497EPSS 99.9%AdobeFlash Player
CISA KEV ↗ · unattributed attribution
high

CVE-2024-6670: Progress WhatsUp Gold SQL Injection Vulnerability

Progress WhatsUp Gold contains a SQL injection vulnerability that allows an unauthenticated attacker to retrieve the user's encrypted password if the application is configured with only a single user. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-6670EPSS 94.7%ProgressWhatsUp Gold
CISA KEV ↗ · unattributed attribution
high

CVE-2024-43461: Microsoft Windows MSHTML Platform Spoofing Vulnerability

Microsoft Windows MSHTML Platform contains a user interface (UI) misrepresentation of critical information vulnerability that allows an attacker to spoof a web page. This vulnerability was exploited in conjunction with CVE-2024-38112. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-38112CVE-2024-43461EPSS 84.3%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2024-8190: Ivanti Cloud Services Appliance OS Command Injection Vulnerability

Ivanti Cloud Services Appliance (CSA) contains an OS command injection vulnerability in the administrative console which can allow an authenticated attacker with application admin privileges to pass commands to the underlying OS. Required action: As Ivanti CSA has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line of supported solutions, as future vulnerabilities on the 4.6.x version of CSA are unlikely to receive future security updates.

CVE-2024-8190EPSS 89.0%Cloud Services ApplianceIvanti
CISA KEV ↗ · unattributed attribution
high

CVE-2024-38217: Microsoft Windows Mark of the Web (MOTW) Protection Mechanism Failure Vulnerability

Microsoft Windows Mark of the Web (MOTW) contains a protection mechanism failure vulnerability that allows an attacker to bypass MOTW-based defenses. This can result in a limited loss of integrity and availability of security features such as Protected View in Microsoft Office, which rely on MOTW tagging. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-38217EPSS 9.8%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2024-38226: Microsoft Publisher Protection Mechanism Failure Vulnerability

Microsoft Publisher contains a protection mechanism failure vulnerability that allows attacker to bypass Office macro policies used to block untrusted or malicious files. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-38226EPSS 2.7%MicrosoftPublisher
CISA KEV ↗ · unattributed attribution
high

CVE-2024-40766: SonicWall SonicOS Improper Access Control Vulnerability

SonicWall SonicOS contains an improper access control vulnerability that could lead to unauthorized resource access and, under certain conditions, may cause the firewall to crash. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-40766EPSS 15.6%SonicOSSonicWall
CISA KEV ↗ · unattributed attribution
high

CVE-2017-1000253: Linux Kernel PIE Stack Buffer Corruption Vulnerability

Linux kernel contains a position-independent executable (PIE) stack buffer corruption vulnerability in load_elf_ binary() that allows a local attacker to escalate privileges. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2017-1000253EPSS 10.7%KernelLinux
CISA KEV ↗ · unattributed attribution
high

CVE-2016-3714: ImageMagick Improper Input Validation Vulnerability

ImageMagick contains an improper input validation vulnerability that affects the EPHEMERAL, HTTPS, MVG, MSL, TEXT, SHOW, WIN, and PLT coders. This allows a remote attacker to execute arbitrary code via shell metacharacters in a crafted image. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2016-3714EPSS 97.5%ImageMagick
CISA KEV ↗ · unattributed attribution
high

CVE-2024-7262: Kingsoft WPS Office Path Traversal Vulnerability

Kingsoft WPS Office contains a path traversal vulnerability in promecefpluginhost.exe on Windows that allows an attacker to load an arbitrary Windows library. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-7262EPSS 1.8%KingsoftWPS Office
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2021-20124: Draytek VigorConnect Path Traversal Vulnerability

Draytek VigorConnect contains a path traversal vulnerability in the file download functionality of the WebServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2021-20124EPSS 69.2%DrayTekVigorConnect
CISA KEV ↗ · unattributed attribution
high

CVE-2021-20123: Draytek VigorConnect Path Traversal Vulnerability

Draytek VigorConnect contains a path traversal vulnerability in the DownloadFileServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2021-20123EPSS 74.3%DrayTekVigorConnect
CISA KEV ↗ · unattributed attribution
high

CVE-2024-7965: Google Chromium V8 Inappropriate Implementation Vulnerability

Google Chromium V8 contains an inappropriate implementation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-7965EPSS 17.2%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2024-38856: Apache OFBiz Incorrect Authorization Vulnerability

Apache OFBiz contains an incorrect authorization vulnerability that could allow remote code execution via a Groovy payload in the context of the OFBiz user process by an unauthenticated attacker. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-38856EPSS 99.4%ApacheOFBiz
CISA KEV ↗ · unattributed attribution
high

CVE-2024-7971: Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-7971EPSS 19.3%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2024-39717: Versa Director Dangerous File Type Upload Vulnerability

The Versa Director GUI contains an unrestricted upload of file with dangerous type vulnerability that allows administrators with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin privileges to customize the user interface. The “Change Favicon” (Favorite Icon) enables the upload of a .png file, which can be exploited to upload a malicious file with a .png extension disguised as an image. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-39717EPSS 4.0%DirectorVersa
CISA KEV ↗ · unattributed attribution
high

CVE-2022-0185: Linux Kernel Heap-Based Buffer Overflow Vulnerability

Linux kernel contains a heap-based buffer overflow vulnerability in the legacy_parse_param function in the Filesystem Context functionality. This allows an attacker to open a filesystem that does not support the Filesystem Context API and ultimately escalate privileges. Required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.

CVE-2022-0185EPSS 25.2%KernelLinux
CISA KEV ↗ · unattributed attribution
high

CVE-2021-33045: Dahua IP Camera Authentication Bypass Vulnerability

Dahua IP cameras and related products contain an authentication bypass vulnerability when the loopback device is specified by the client during authentication. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2021-33045EPSS 99.6%DahuaIP Camera Firmware
CISA KEV ↗ · unattributed attribution
high

CVE-2021-33044: Dahua IP Camera Authentication Bypass Vulnerability

Dahua IP cameras and related products contain an authentication bypass vulnerability when the NetKeyboard type argument is specified by the client during authentication. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2021-33044EPSS 99.9%DahuaIP Camera Firmware
CISA KEV ↗ · unattributed attribution
high

CVE-2024-23897: Jenkins Command Line Interface (CLI) Path Traversal Vulnerability

Jenkins Command Line Interface (CLI) contains a path traversal vulnerability that allows attackers limited read access to certain files, which can lead to code execution. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-23897EPSS 100.0%JenkinsJenkins Command Line Interface (CLI)
CISA KEV ↗ · unattributed attribution
high

CVE-2024-38107: Microsoft Windows Power Dependency Coordinator Privilege Escalation Vulnerability

Microsoft Windows Power Dependency Coordinator contains an unspecified vulnerability that allows for privilege escalation, enabling a local attacker to obtain SYSTEM privileges. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-38107EPSS 1.6%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2024-38106: Microsoft Windows Kernel Privilege Escalation Vulnerability

Microsoft Windows Kernel contains an unspecified vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges. Successful exploitation of this vulnerability requires an attacker to win a race condition. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-38106EPSS 6.3%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2024-38193: Microsoft Windows Ancillary Function Driver for WinSock Privilege Escalation Vulnerability

Microsoft Windows Ancillary Function Driver for WinSock contains an unspecified vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-38193EPSS 27.6%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2024-38213: Microsoft Windows SmartScreen Security Feature Bypass Vulnerability

Microsoft Windows SmartScreen contains a security feature bypass vulnerability that allows an attacker to bypass the SmartScreen user experience via a malicious file. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-38213EPSS 13.4%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2024-38178: Microsoft Windows Scripting Engine Memory Corruption Vulnerability

Microsoft Windows Scripting Engine contains a memory corruption vulnerability that allows unauthenticated attacker to initiate remote code execution via a specially crafted URL. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-38178EPSS 39.2%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2024-38189: Microsoft Project Remote Code Execution Vulnerability

Microsoft Project contains an unspecified vulnerability that allows for remote code execution via a malicious file. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-38189EPSS 7.9%MicrosoftProject
CISA KEV ↗ · unattributed attribution
high

CVE-2024-32113: Apache OFBiz Path Traversal Vulnerability

Apache OFBiz contains a path traversal vulnerability that could allow for remote code execution. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-32113EPSS 99.4%ApacheOFBiz
CISA KEV ↗ · unattributed attribution
high

CVE-2024-36971: Android Kernel Remote Code Execution Vulnerability

Android contains an unspecified vulnerability in the kernel that allows for remote code execution. This vulnerability resides in Linux Kernel and could impact other products, including but not limited to Android OS. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-36971EPSS 2.7%AndroidKernel
CISA KEV ↗ · unattributed attribution
high

CVE-2018-0824: Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability

Microsoft COM for Windows contains a deserialization of untrusted data vulnerability that allows for privilege escalation and remote code execution via a specially crafted file or script. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2018-0824EPSS 73.2%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2024-37085: VMware ESXi Authentication Bypass Vulnerability

VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management by re-creating the configured AD group ('ESXi Admins' by default) after it was deleted from AD. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-37085EPSS 26.8%ESXiVMware
CISA KEV ↗ · unattributed attribution
high

CVE-2024-5217: ServiceNow Incomplete List of Disallowed Inputs Vulnerability

ServiceNow Washington DC, Vancouver, and earlier Now Platform releases contain an incomplete list of disallowed inputs vulnerability in the GlideExpression script. An unauthenticated user could exploit this vulnerability to execute code remotely. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-5217EPSS 99.6%ServiceNowUtah, Vancouver, and Washington DC Now Platform
CISA KEV ↗ · unattributed attribution
high

CVE-2024-4879: ServiceNow Improper Input Validation Vulnerability

ServiceNow Utah, Vancouver, and Washington DC Now Platform releases contain a jelly template injection vulnerability in UI macros. An unauthenticated user could exploit this vulnerability to execute code remotely. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-4879EPSS 100.0%ServiceNowUtah, Vancouver, and Washington DC Now Platform
CISA KEV ↗ · unattributed attribution
high

CVE-2024-39891: Twilio Authy Information Disclosure Vulnerability

Twilio Authy contains an information disclosure vulnerability in its API that allows an unauthenticated endpoint to accept a request containing a phone number and respond with information about whether the phone number was registered with Authy. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-39891EPSS 1.5%AuthyTwilio
CISA KEV ↗ · unattributed attribution
high

CVE-2012-4792: Microsoft Internet Explorer Use-After-Free Vulnerability

Microsoft Internet Explorer contains a use-after-free vulnerability that allows a remote attacker to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly allocated or (2) is deleted, as demonstrated by a CDwnBindInfo object. Required action: The impacted product is end-of-life and should be disconnected if still in use.

CVE-2012-4792EPSS 78.8%Internet ExplorerMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2024-28995: SolarWinds Serv-U Path Traversal Vulnerability

SolarWinds Serv-U contains a path traversal vulnerability that allows an attacker access to read sensitive files on the host machine. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-28995EPSS 99.6%Serv-USolarWinds
CISA KEV ↗ · unattributed attribution
high

CVE-2024-34102: Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability

Adobe Commerce and Magento Open Source contain an improper restriction of XML external entity reference (XXE) vulnerability that allows for remote code execution. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-34102EPSS 100.0%AdobeCommerce and Magento Open Source
CISA KEV ↗ · unattributed attribution
high

CVE-2024-36401: OSGeo GeoServer GeoTools Eval Injection Vulnerability

OSGeo GeoServer GeoTools contains an improper neutralization of directives in dynamically evaluated code vulnerability due to unsafely evaluating property names as XPath expressions. This allows unauthenticated attackers to conduct remote code execution via specially crafted input. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-36401EPSS 99.8%GeoServerOSGeo
CISA KEV ↗ · unattributed attribution
high

CVE-2024-23692: Rejetto HTTP File Server Improper Neutralization of Special Elements Used in a Template Engine Vulnerability

Rejetto HTTP File Server contains an improper neutralization of special elements used in a template engine vulnerability. This allows a remote, unauthenticated attacker to execute commands on the affected system by sending a specially crafted HTTP request. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-23692EPSS 99.5%HTTP File ServerRejetto
CISA KEV ↗ · unattributed attribution
high

CVE-2024-38080: Microsoft Windows Hyper-V Privilege Escalation Vulnerability

Microsoft Windows Hyper-V contains a privilege escalation vulnerability that allows a local attacker with user permissions to gain SYSTEM privileges. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-38080EPSS 7.1%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2024-38112: Microsoft Windows MSHTML Platform Spoofing Vulnerability

Microsoft Windows MSHTML Platform contains a spoofing vulnerability that has a high impact to confidentiality, integrity, and availability. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-38112EPSS 84.3%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2024-20399: Cisco NX-OS Command Injection Vulnerability

Cisco NX-OS contains a command injection vulnerability in the command line interface (CLI) that could allow an authenticated, local attacker to execute commands as root on the underlying operating system of an affected device. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-20399EPSS 4.3%CiscoNX-OS
CISA KEV ↗ · unattributed attribution
high

CVE-2020-13965: Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability

Roundcube Webmail contains a cross-site scripting (XSS) vulnerability that allows a remote attacker to manipulate data via a malicious XML attachment. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2020-13965EPSS 76.6%RoundcubeWebmail
CISA KEV ↗ · unattributed attribution
high

CVE-2022-2586: Linux Kernel Use-After-Free Vulnerability

Linux Kernel contains a use-after-free vulnerability in the nft_object, allowing local attackers to escalate privileges. Required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.

CVE-2022-2586EPSS 12.7%KernelLinux
CISA KEV ↗ · unattributed attribution
high

CVE-2022-24816: OSGeo GeoServer JAI-EXT Code Injection Vulnerability

OSGeo GeoServer JAI-EXT contains a code injection vulnerability that, when programs use jt-jiffle and allow Jiffle script to be provided via network request, could allow remote code execution. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2022-24816EPSS 98.7%JAI-EXTOSGeo
CISA KEV ↗ · unattributed attribution
high

CVE-2024-32896: Android Pixel Privilege Escalation Vulnerability

Android Pixel contains an unspecified vulnerability in the firmware that allows for privilege escalation. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-32896EPSS 3.0%AndroidPixel
CISA KEV ↗ · unattributed attribution
high

CVE-2024-4577: PHP-CGI OS Command Injection Vulnerability

PHP, specifically Windows-based PHP used in CGI mode, contains an OS command injection vulnerability that allows for arbitrary code execution. This vulnerability is a patch bypass for CVE-2012-1823. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2012-1823CVE-2024-4577EPSS 100.0%PHPPHP Group
CISA KEV ↗ · unattributed attribution
high

CVE-2024-4610: Arm Mali GPU Kernel Driver Use-After-Free Vulnerability

Arm Bifrost and Valhall GPU kernel drivers contain a use-after-free vulnerability that allows a local, non-privileged user to make improper GPU memory processing operations to gain access to already freed memory. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-4610EPSS 0.8%ArmMali GPU Kernel Driver
CISA KEV ↗ · unattributed attribution
high

CVE-2017-3506: Oracle WebLogic Server OS Command Injection Vulnerability

Oracle WebLogic Server, a product within the Fusion Middleware suite, contains an OS command injection vulnerability that allows an attacker to execute arbitrary code via a specially crafted HTTP request that includes a malicious XML document. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2017-3506EPSS 96.3%OracleWebLogic Server
CISA KEV ↗ · unattributed attribution
high

CVE-2024-1086: Linux Kernel Use-After-Free Vulnerability

Linux kernel contains a use-after-free vulnerability in the netfilter: nf_tables component that allows an attacker to achieve local privilege escalation. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-1086EPSS 28.1%KernelLinux
CISA KEV ↗ · unattributed attribution
high

CVE-2024-24919: Check Point Quantum Security Gateways Information Disclosure Vulnerability

Check Point Quantum Security Gateways contain an unspecified information disclosure vulnerability. The vulnerability potentially allows an attacker to access information on Gateways connected to the internet, with IPSec VPN, Remote Access VPN or Mobile Access enabled. This issue affects several product lines from Check Point, including CloudGuard Network, Quantum Scalable Chassis, Quantum Security Gateways, and Quantum Spark Appliances. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-24919EPSS 100.0%Check PointQuantum Security Gateways
CISA KEV ↗ · unattributed attribution
high

CVE-2024-4978: Justice AV Solutions (JAVS) Viewer Installer Embedded Malicious Code Vulnerability

Justice AV Solutions (JAVS) Viewer installer contains a malicious version of ffmpeg.exe, named fffmpeg.exe (SHA256: 421a4ad2615941b177b6ec4ab5e239c14e62af2ab07c6df1741e2a62223223c4). When run, this creates a backdoor connection to a malicious C2 server. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-4978EPSS 26.9%Justice AV SolutionsViewer
CISA KEV ↗ · unattributed attribution · 3 IOCs
high

CVE-2024-5274: Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-5274EPSS 10.0%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2020-17519: Apache Flink Improper Access Control Vulnerability

Apache Flink contains an improper access control vulnerability that allows an attacker to read any file on the local filesystem of the JobManager through its REST interface. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2020-17519EPSS 97.9%ApacheFlink
CISA KEV ↗ · unattributed attribution
high

CVE-2024-4947: Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-4947EPSS 15.1%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2023-43208: NextGen Healthcare Mirth Connect Deserialization of Untrusted Data Vulnerability

NextGen Healthcare Mirth Connect contains a deserialization of untrusted data vulnerability that allows for unauthenticated remote code execution via a specially crafted request. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-43208EPSS 82.7%Mirth ConnectNextGen Healthcare
CISA KEV ↗ · unattributed attribution
high

CVE-2024-4761: Google Chromium V8 Out-of-Bounds Memory Write Vulnerability

Google Chromium V8 Engine contains an unspecified out-of-bounds memory write vulnerability via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-4761EPSS 11.0%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2021-40655: D-Link DIR-605 Router Information Disclosure Vulnerability

D-Link DIR-605 routers contain an information disclosure vulnerability that allows attackers to obtain a username and password by forging a post request to the /getcfg.php page. Required action: This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions.

CVE-2021-40655EPSS 87.0%D-LinkDIR-605 Router
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2014-100005: D-Link DIR-600 Router Cross-Site Request Forgery (CSRF) Vulnerability

D-Link DIR-600 routers contain a cross-site request forgery (CSRF) vulnerability that allows an attacker to change router configurations by hijacking an existing administrator session. Required action: This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions.

CVE-2014-100005EPSS 42.4%D-LinkDIR-600 Router
CISA KEV ↗ · unattributed attribution
high

CVE-2024-4671: Google Chromium Visuals Use-After-Free Vulnerability

Google Chromium Visuals contains a use-after-free vulnerability that allows a remote attacker to exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-4671EPSS 8.3%ChromiumGoogle
CISA KEV ↗ · unattributed attribution
high

CVE-2023-7028: GitLab Community and Enterprise Editions Improper Access Control Vulnerability

GitLab Community and Enterprise Editions contain an improper access control vulnerability. This allows an attacker to trigger password reset emails to be sent to an unverified email address to ultimately facilitate an account takeover. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-7028EPSS 95.0%GitLabGitLab CE/EE
CISA KEV ↗ · unattributed attribution
high

CVE-2024-29988: Microsoft SmartScreen Prompt Security Feature Bypass Vulnerability

Microsoft SmartScreen Prompt contains a security feature bypass vulnerability that allows an attacker to bypass the Mark of the Web (MotW) feature. This vulnerability can be chained with CVE-2023-38831 and CVE-2024-21412 to execute a malicious file. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-38831CVE-2024-21412EPSS 97.8%MicrosoftSmartScreen Prompt
CISA KEV ↗ · unattributed attribution
high

CVE-2024-4040: CrushFTP VFS Sandbox Escape Vulnerability

CrushFTP contains an unspecified sandbox escape vulnerability that allows a remote attacker to escape the CrushFTP virtual file system (VFS). Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-4040EPSS 99.5%CrushFTP
CISA KEV ↗ · unattributed attribution
high

CVE-2024-20359: Cisco ASA and FTD Privilege Escalation Vulnerability

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain a privilege escalation vulnerability that can allow local privilege escalation from Administrator to root. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-20359EPSS 19.4%Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)Cisco
CISA KEV ↗ · unattributed attribution
high

CVE-2024-20353: Cisco ASA and FTD Denial of Service Vulnerability

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an infinite loop vulnerability that can lead to remote denial of service condition. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-20353EPSS 70.7%Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)Cisco
CISA KEV ↗ · unattributed attribution
high

CVE-2022-38028: Microsoft Windows Print Spooler Privilege Escalation Vulnerability

Microsoft Windows Print Spooler service contains a privilege escalation vulnerability. An attacker may modify a JavaScript constraints file and execute it with SYSTEM-level permissions. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2022-38028EPSS 14.9%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2024-3400: Palo Alto Networks PAN-OS Command Injection Vulnerability

Palo Alto Networks PAN-OS GlobalProtect feature contains a command injection vulnerability that allows an unauthenticated attacker to execute commands with root privileges on the firewall. Required action: Apply mitigations per vendor instructions as they become available. Otherwise, users with vulnerable versions of affected devices should enable Threat Prevention IDs available from the vendor. See the vendor bulletin for more details and a patch release schedule.

CVE-2024-3400EPSS 100.0%PAN-OSPalo Alto Networks
CISA KEV ↗ · unattributed attribution
high

CVE-2024-3273: D-Link Multiple NAS Devices Command Injection Vulnerability

D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L contain a command injection vulnerability. When combined with CVE-2024-3272, this can lead to remote, unauthorized code execution. Required action: This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions.

CVE-2024-3272CVE-2024-3273EPSS 100.0%D-LinkMultiple NAS Devices
CISA KEV ↗ · unattributed attribution
high

CVE-2024-3272: D-Link Multiple NAS Devices Use of Hard-Coded Credentials Vulnerability

D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L contains a hard-coded credential that allows an attacker to conduct authenticated command injection, leading to remote, unauthorized code execution. Required action: This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions.

CVE-2024-3272EPSS 98.0%D-LinkMultiple NAS Devices
CISA KEV ↗ · unattributed attribution
high

CVE-2024-29748: Android Pixel Privilege Escalation Vulnerability

Android Pixel contains a privilege escalation vulnerability that allows an attacker to interrupt a factory reset triggered by a device admin app. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-29748EPSS 0.7%AndroidPixel
CISA KEV ↗ · unattributed attribution
high

CVE-2024-29745: Android Pixel Information Disclosure Vulnerability

Android Pixel contains an information disclosure vulnerability in the fastboot firmware used to support unlocking, flashing, and locking affected devices. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-29745EPSS 0.5%AndroidPixel
CISA KEV ↗ · unattributed attribution
high

CVE-2023-24955: Microsoft SharePoint Server Code Injection Vulnerability

Microsoft SharePoint Server contains a code injection vulnerability that allows an authenticated attacker with Site Owner privileges to execute code remotely. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-24955EPSS 85.4%MicrosoftSharePoint Server
CISA KEV ↗ · unattributed attribution
high

CVE-2021-44529: Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) Code Injection Vulnerability

Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) contains a code injection vulnerability that allows an unauthenticated user to execute malicious code with limited permissions (nobody). Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2021-44529EPSS 99.1%Endpoint Manager Cloud Service Appliance (EPM CSA)Ivanti
CISA KEV ↗ · unattributed attribution
high

CVE-2023-48788: Fortinet FortiClient EMS SQL Injection Vulnerability

Fortinet FortiClient EMS contains a SQL injection vulnerability that allows an unauthenticated attacker to execute commands as SYSTEM via specifically crafted requests. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-48788EPSS 97.6%FortiClient EMSFortinet
CISA KEV ↗ · unattributed attribution
high

CVE-2024-27198: JetBrains TeamCity Authentication Bypass Vulnerability

JetBrains TeamCity contains an authentication bypass vulnerability that allows an attacker to perform admin actions. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-27198EPSS 99.9%JetBrainsTeamCity
CISA KEV ↗ · unattributed attribution
high

CVE-2024-23225: Apple Multiple Products Memory Corruption Vulnerability

Apple iOS, iPadOS, macOS, tvOS, watchOS, and visionOS kernel contain a memory corruption vulnerability that allows an attacker with arbitrary kernel read and write capability to bypass kernel memory protections. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-23225EPSS 1.5%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2024-23296: Apple Multiple Products Memory Corruption Vulnerability

Apple iOS, iPadOS, macOS, tvOS, and watchOS RTKit contain a memory corruption vulnerability that allows an attacker with arbitrary kernel read and write capability to bypass kernel memory protections. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-23296EPSS 1.4%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2023-21237: Android Pixel Information Disclosure Vulnerability

Android Pixel contains a vulnerability in the Framework component, where the UI may be misleading or insufficient, providing a means to hide a foreground service notification. This could enable a local attacker to disclose sensitive information. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-21237EPSS 0.3%AndroidPixel
CISA KEV ↗ · unattributed attribution
high

CVE-2021-36380: Sunhillo SureLine OS Command Injection Vulnerablity

Sunhillo SureLine contains an OS command injection vulnerability that allows an attacker to cause a denial-of-service or utilize the device for persistence on the network via shell metacharacters in ipAddr or dnsAddr in /cgi/networkDiag.cgi. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2021-36380EPSS 97.6%SunhilloSureLine
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2024-21338: Microsoft Windows Kernel Exposed IOCTL with Insufficient Access Control Vulnerability

Microsoft Windows Kernel contains an exposed IOCTL with insufficient access control vulnerability within the IOCTL (input and output control) dispatcher in appid.sys that allows a local attacker to achieve privilege escalation. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-21338EPSS 51.9%MicrosoftWindows
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2023-29360: Microsoft Streaming Service Untrusted Pointer Dereference Vulnerability

Microsoft Streaming Service contains an untrusted pointer dereference vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-29360EPSS 22.1%MicrosoftStreaming Service
CISA KEV ↗ · unattributed attribution
high

CVE-2024-1709: ConnectWise ScreenConnect Authentication Bypass Vulnerability

ConnectWise ScreenConnect contains an authentication bypass vulnerability that allows an attacker with network access to the management interface to create a new, administrator-level account on affected devices. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-1709EPSS 100.0%ConnectWiseScreenConnect
CISA KEV ↗ · unattributed attribution
high

CVE-2020-3259: Cisco ASA and FTD Information Disclosure Vulnerability

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an information disclosure vulnerability. An attacker could retrieve memory contents on an affected device, which could lead to the disclosure of confidential information due to a buffer tracking issue when the software parses invalid URLs that are requested from the web services interface. This vulnerability affects only specific AnyConnect and WebVPN configurations. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2020-3259EPSS 71.8%Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)Cisco
CISA KEV ↗ · unattributed attribution
high

CVE-2024-21351: Microsoft Windows SmartScreen Security Feature Bypass Vulnerability

Microsoft Windows SmartScreen contains a security feature bypass vulnerability that allows an attacker to bypass the SmartScreen user experience and inject code to potentially gain code execution, which could lead to some data exposure, lack of system availability, or both. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-21351EPSS 30.3%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2023-43770: Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability

Roundcube Webmail contains a persistent cross-site scripting (XSS) vulnerability that can lead to information disclosure via malicious link references in plain/text messages. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-43770EPSS 58.5%RoundcubeWebmail
CISA KEV ↗ · unattributed attribution
high

CVE-2024-21762: Fortinet FortiOS Out-of-Bound Write Vulnerability

Fortinet FortiOS contains an out-of-bound write vulnerability that allows a remote unauthenticated attacker to execute code or commands via specially crafted HTTP requests. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-21762EPSS 83.4%FortiOSFortinet
CISA KEV ↗ · unattributed attribution
high

CVE-2023-4762: Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-4762EPSS 38.0%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2022-48618: Apple Multiple Products Memory Corruption Vulnerability

Apple iOS, iPadOS, macOS, tvOS, and watchOS contain a time-of-check/time-of-use (TOCTOU) memory corruption vulnerability that allows an attacker with read and write capabilities to bypass Pointer Authentication. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2022-48618EPSS 0.5%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2024-21893: Ivanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) Vulnerability

Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure), Ivanti Policy Secure, and Ivanti Neurons contain a server-side request forgery (SSRF) vulnerability in the SAML component that allows an attacker to access certain restricted resources without authentication. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-21893EPSS 100.0%Connect Secure, Policy Secure, and NeuronsIvanti
CISA KEV ↗ · unattributed attribution
high

CVE-2024-23222: Apple Multiple Products WebKit Type Confusion Vulnerability

Apple iOS, iPadOS, macOS, tvOS, and Safari WebKit contain a type confusion vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-23222EPSS 10.6%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2023-34048: VMware vCenter Server Out-of-Bounds Write Vulnerability

VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol that allows an attacker to conduct remote code execution. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-34048EPSS 99.4%VMwarevCenter Server
CISA KEV ↗ · unattributed attribution
high

CVE-2023-35082: Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass Vulnerability

Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core contain an authentication bypass vulnerability that allows unauthorized users to access restricted functionality or resources of the application. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-35082EPSS 100.0%Endpoint Manager Mobile (EPMM) and MobileIron CoreIvanti
CISA KEV ↗ · unattributed attribution
high

CVE-2024-0519: Google Chromium V8 Out-of-Bounds Memory Access Vulnerability

Google Chromium V8 Engine contains an out-of-bounds memory access vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-0519EPSS 3.8%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2023-6549: Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability

Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for a denial-of-service when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-6549EPSS 57.6%CitrixNetScaler ADC and NetScaler Gateway
CISA KEV ↗ · unattributed attribution
high

CVE-2023-6548: Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability

Citrix NetScaler ADC and NetScaler Gateway contain a code injection vulnerability that allows for authenticated remote code execution on the management interface with access to NSIP, CLIP, or SNIP. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-6548EPSS 3.2%CitrixNetScaler ADC and NetScaler Gateway
CISA KEV ↗ · unattributed attribution
high

CVE-2018-15133: Laravel Deserialization of Untrusted Data Vulnerability

Laravel Framework contains a deserialization of untrusted data vulnerability, allowing for remote command execution. This vulnerability may only be exploited if a malicious user has accessed the application encryption key (APP_KEY environment variable). Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2018-15133EPSS 76.8%LaravelLaravel Framework
CISA KEV ↗ · unattributed attribution
high

CVE-2023-29357: Microsoft SharePoint Server Privilege Escalation Vulnerability

Microsoft SharePoint Server contains an unspecified vulnerability that allows an unauthenticated attacker, who has gained access to spoofed JWT authentication tokens, to use them for executing a network attack. This attack bypasses authentication, enabling the attacker to gain administrator privileges. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-29357EPSS 99.6%MicrosoftSharePoint Server
CISA KEV ↗ · unattributed attribution
high

CVE-2023-46805: Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability

Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure gateways contain an authentication bypass vulnerability in the web component that allows an attacker to access restricted resources by bypassing control checks. This vulnerability can be leveraged in conjunction with CVE-2024-21887, a command injection vulnerability. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-46805CVE-2024-21887EPSS 100.0%Connect Secure and Policy SecureIvanti
CISA KEV ↗ · unattributed attribution
high

CVE-2024-21887: Ivanti Connect Secure and Policy Secure Command Injection Vulnerability

Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure contain a command injection vulnerability in the web components of these products, which can allow an authenticated administrator to send crafted requests to execute code on affected appliances. This vulnerability can be leveraged in conjunction with CVE-2023-46805, an authenticated bypass issue. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-46805CVE-2024-21887EPSS 100.0%Connect Secure and Policy SecureIvanti
CISA KEV ↗ · unattributed attribution
high

CVE-2023-23752: Joomla! Improper Access Control Vulnerability

Joomla! contains an improper access control vulnerability that allows unauthorized access to webservice endpoints. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-23752EPSS 99.8%Joomla!
CISA KEV ↗ · unattributed attribution
high

CVE-2016-20017: D-Link DSL-2750B Devices Command Injection Vulnerability

D-Link DSL-2750B devices contain a command injection vulnerability that allows remote, unauthenticated command injection via the login.cgi cli parameter. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2016-20017EPSS 60.4%D-LinkDSL-2750B Devices
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2023-41990: Apple Multiple Products Code Execution Vulnerability

Apple iOS, iPadOS, macOS, tvOS, and watchOS contain an unspecified vulnerability that allows for code execution when processing a font file. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-41990EPSS 1.1%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2023-27524: Apache Superset Insecure Default Initialization of Resource Vulnerability

Apache Superset contains an insecure default initialization of a resource vulnerability that allows an attacker to authenticate and access unauthorized resources on installations that have not altered the default configured SECRET_KEY according to installation instructions. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-27524EPSS 97.4%ApacheSuperset
CISA KEV ↗ · unattributed attribution
high

CVE-2023-7101: Spreadsheet::ParseExcel Remote Code Execution Vulnerability

Spreadsheet::ParseExcel contains a remote code execution vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Number format strings within the Excel parsing logic. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-7101EPSS 16.8%Spreadsheet::ParseExcel
CISA KEV ↗ · unattributed attribution
high

CVE-2023-7024: Google Chromium WebRTC Heap Buffer Overflow Vulnerability

Google Chromium WebRTC, an open-source project providing web browsers with real-time communication, contains a heap buffer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could impact web browsers using WebRTC, including but not limited to Google Chrome. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-7024EPSS 7.4%Chromium WebRTCGoogle
CISA KEV ↗ · unattributed attribution
high

CVE-2023-49897: FXC AE1021, AE1021PE OS Command Injection Vulnerability

FXC AE1021 and AE1021PE contain an OS command injection vulnerability that allows authenticated users to execute commands via a network. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-49897EPSS 50.7%AE1021, AE1021PEFXC
CISA KEV ↗ · unattributed attribution
high

CVE-2023-47565: QNAP VioStor NVR OS Command Injection Vulnerability

QNAP VioStar NVR contains an OS command injection vulnerability that allows authenticated users to execute commands via a network. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-47565EPSS 73.3%QNAPVioStor NVR
CISA KEV ↗ · unattributed attribution
high

CVE-2023-41266: Qlik Sense Path Traversal Vulnerability

Qlik Sense contains a path traversal vulnerability that allows a remote, unauthenticated attacker to create an anonymous session by sending maliciously crafted HTTP requests. This anonymous session could allow the attacker to send further requests to unauthorized endpoints. Required action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.

CVE-2023-41266EPSS 82.6%QlikSense
CISA KEV ↗ · unattributed attribution
high

CVE-2023-41265: Qlik Sense HTTP Tunneling Vulnerability

Qlik Sense contains an HTTP tunneling vulnerability that allows an attacker to escalate privileges and execute HTTP requests on the backend server hosting the software. Required action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.

CVE-2023-41265EPSS 85.0%QlikSense
CISA KEV ↗ · unattributed attribution
high

CVE-2023-33107: Qualcomm Multiple Chipsets Integer Overflow Vulnerability

Multiple Qualcomm chipsets contain an integer overflow vulnerability due to memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call. Required action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.

CVE-2023-33107EPSS 0.9%Multiple ChipsetsQualcomm
CISA KEV ↗ · unattributed attribution
high

CVE-2023-33106: Qualcomm Multiple Chipsets Use of Out-of-Range Pointer Offset Vulnerability

Multiple Qualcomm chipsets contain a use of out-of-range pointer offset vulnerability due to memory corruption in Graphics while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND. Required action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.

CVE-2023-33106EPSS 0.9%Multiple ChipsetsQualcomm
CISA KEV ↗ · unattributed attribution
high

CVE-2023-33063: Qualcomm Multiple Chipsets Use-After-Free Vulnerability

Multiple Qualcomm chipsets contain a use-after-free vulnerability due to memory corruption in DSP Services during a remote call from HLOS to DSP. Required action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.

CVE-2023-33063EPSS 0.7%Multiple ChipsetsQualcomm
CISA KEV ↗ · unattributed attribution
high

CVE-2022-22071: Qualcomm Multiple Chipsets Use-After-Free Vulnerability

Multiple Qualcomm chipsets contain a use-after-free vulnerability when process shell memory is freed using IOCTL munmap call and process initialization is in progress. Required action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.

CVE-2022-22071EPSS 0.4%Multiple ChipsetsQualcomm
CISA KEV ↗ · unattributed attribution
high

CVE-2023-42917: Apple Multiple Products WebKit Memory Corruption Vulnerability

Apple iOS, iPadOS, macOS, and Safari WebKit contain a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Required action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.

CVE-2023-42917EPSS 9.4%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2023-42916: Apple Multiple Products WebKit Out-of-Bounds Read Vulnerability

Apple iOS, iPadOS, macOS, and Safari WebKit contain an out-of-bounds read vulnerability that may disclose sensitive information when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Required action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.

CVE-2023-42916EPSS 17.8%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2023-6345: Google Skia Integer Overflow Vulnerability

Google Chromium Skia contains an integer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a malicious file. This vulnerability affects Google Chrome and ChromeOS, Android, Flutter, and possibly other products. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-6345EPSS 19.6%Chromium SkiaGoogle
CISA KEV ↗ · unattributed attribution
high

CVE-2023-49103: ownCloud graphapi Information Disclosure Vulnerability

ownCloud graphapi contains an information disclosure vulnerability that can reveal sensitive data stored in phpinfo() via GetPhpInfo.php, including administrative credentials. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-49103EPSS 78.4%ownCloudownCloud graphapi
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2023-4911: GNU C Library Buffer Overflow Vulnerability

GNU C Library's dynamic loader ld.so contains a buffer overflow vulnerability when processing the GLIBC_TUNABLES environment variable, allowing a local attacker to execute code with elevated privileges. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-4911EPSS 81.4%GNUGNU C Library
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2023-1671: Sophos Web Appliance Command Injection Vulnerability

Sophos Web Appliance contains a command injection vulnerability in the warn-proceed handler that allows for remote code execution. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-1671EPSS 100.0%SophosWeb Appliance
CISA KEV ↗ · unattributed attribution
high

CVE-2020-2551: Oracle Fusion Middleware Unspecified Vulnerability

Oracle Fusion Middleware contains an unspecified vulnerability in the WLS Core Components that allows an unauthenticated attacker with network access via IIOP to compromise the WebLogic Server. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2020-2551EPSS 93.2%Fusion MiddlewareOracle
CISA KEV ↗ · unattributed attribution
high

CVE-2023-36025: Microsoft Windows SmartScreen Security Feature Bypass Vulnerability

Microsoft Windows SmartScreen contains a security feature bypass vulnerability that could allow an attacker to bypass Windows Defender SmartScreen checks and their associated prompts. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-36025EPSS 88.2%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2023-47246: SysAid Server Path Traversal Vulnerability

SysAid Server (on-premises version) contains a path traversal vulnerability that leads to code execution. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-47246EPSS 98.9%SysAidSysAid Server
CISA KEV ↗ · unattributed attribution
high

CVE-2023-36844: Juniper Junos OS EX Series PHP External Variable Modification Vulnerability

Juniper Junos OS on EX Series contains a PHP external variable modification vulnerability that allows an unauthenticated, network-based attacker to control certain, important environment variables. Using a crafted request an attacker is able to modify certain PHP environment variables, leading to partial loss of integrity, which may allow chaining to other vulnerabilities. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-36844EPSS 91.0%JuniperJunos OS
CISA KEV ↗ · unattributed attribution
high

CVE-2023-36845: Juniper Junos OS EX Series and SRX Series PHP External Variable Modification Vulnerability

Juniper Junos OS on EX Series and SRX Series contains a PHP external variable modification vulnerability that allows an unauthenticated, network-based attacker to control an important environment variable. Using a crafted request, which sets the variable PHPRC, an attacker is able to modify the PHP execution environment allowing the injection und execution of code. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-36845EPSS 93.5%JuniperJunos OS
CISA KEV ↗ · unattributed attribution
high

CVE-2023-36846: Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability

Juniper Junos OS on SRX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to user.php that doesn't require authentication, an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-36846EPSS 94.2%JuniperJunos OS
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2023-36847: Juniper Junos OS EX Series Missing Authentication for Critical Function Vulnerability

Juniper Junos OS on EX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to installAppPackage.php that doesn't require authentication, an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-36847EPSS 84.7%JuniperJunos OS
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2023-36851: Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability

Juniper Junos OS on SRX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to webauth_operation.php that doesn't require authentication, an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-36851EPSS 1.1%JuniperJunos OS
CISA KEV ↗ · unattributed attribution
high

CVE-2023-29552: Service Location Protocol (SLP) Denial-of-Service Vulnerability

The Service Location Protocol (SLP) contains a denial-of-service (DoS) vulnerability that could allow an unauthenticated, remote attacker to register services and use spoofed UDP traffic to conduct a denial-of-service (DoS) attack with a significant amplification factor. Required action: Apply mitigations per vendor instructions or disable SLP service or port 427/UDP on all systems running on untrusted networks, including those directly connected to the Internet.

CVE-2023-29552EPSS 65.9%IETFService Location Protocol (SLP)
CISA KEV ↗ · unattributed attribution
high

CVE-2023-22518: Atlassian Confluence Data Center and Server Improper Authorization Vulnerability

Atlassian Confluence Data Center and Server contain an improper authorization vulnerability that can result in significant data loss when exploited by an unauthenticated attacker. There is no impact on confidentiality since the attacker cannot exfiltrate any data. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-22518EPSS 100.0%AtlassianConfluence Data Center and Server
CISA KEV ↗ · unattributed attribution
high

CVE-2023-46604: Apache ActiveMQ Deserialization of Untrusted Data Vulnerability

Apache ActiveMQ contains a deserialization of untrusted data vulnerability that may allow a remote attacker with network access to a broker to run shell commands by manipulating serialized class types in the OpenWire protocol to cause the broker to instantiate any class on the classpath. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-46604EPSS 99.7%ActiveMQApache
CISA KEV ↗ · unattributed attribution
high

CVE-2023-46748: F5 BIG-IP Configuration Utility SQL Injection Vulnerability

F5 BIG-IP Configuration utility contains an SQL injection vulnerability that may allow an authenticated attacker with network access through the BIG-IP management port and/or self IP addresses to execute system commands. This vulnerability can be used in conjunction with CVE-2023-46747. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-46747CVE-2023-46748EPSS 96.5%BIG-IP Configuration UtilityF5
CISA KEV ↗ · unattributed attribution
high

CVE-2023-46747: F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability

F5 BIG-IP Configuration utility contains an authentication bypass using an alternate path or channel vulnerability due to undisclosed requests that may allow an unauthenticated attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute system commands. This vulnerability can be used in conjunction with CVE-2023-46748. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-46747CVE-2023-46748EPSS 96.5%BIG-IP Configuration UtilityF5
CISA KEV ↗ · unattributed attribution
high

CVE-2023-20273: Cisco IOS XE Web UI Command Injection Vulnerability

Cisco IOS XE contains a command injection vulnerability in the web user interface. When chained with CVE-2023-20198, the attacker can leverage the new local user to elevate privilege to root and write the implant to the file system. Cisco identified CVE-2023-20273 as the vulnerability exploited to deploy the implant. CVE-2021-1435, previously associated with the exploitation events, is no longer believed to be related to this activity. Required action: Verify that instances of Cisco IOS XE Web UI are in compliance with BOD 23-02 and apply mitigations per vendor instructions. For affected products (Cisco IOS XE Web UI exposed to the internet or to untrusted networks), follow vendor instructions to determine if a system may have been compromised and immediately report positive findings to CISA.

CVE-2021-1435CVE-2023-20198EPSS 99.6%CiscoCisco IOS XE Web UI
CISA KEV ↗ · unattributed attribution
high

CVE-2023-4966: Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability

Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for sensitive information disclosure when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. Required action: Apply mitigations and kill all active and persistent sessions per vendor instructions [https://www.netscaler.com/blog/news/cve-2023-4966-critical-security-update-now-available-for-netscaler-adc-and-netscaler-gateway/] OR discontinue use of the product if mitigations are unavailable.

CVE-2023-4966EPSS 100.0%CitrixNetScaler ADC and NetScaler Gateway
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2023-20198: Cisco IOS XE Web UI Privilege Escalation Vulnerability

Cisco IOS XE Web UI contains a privilege escalation vulnerability in the web user interface that could allow a remote, unauthenticated attacker to create an account with privilege level 15 access. The attacker can then use that account to gain control of the affected device. Required action: Verify that instances of Cisco IOS XE Web UI are in compliance with BOD 23-02 and apply mitigations per vendor instructions. For affected products (Cisco IOS XE Web UI exposed to the internet or to untrusted networks), follow vendor instructions to determine if a system may have been compromised and immediately report positive findings to CISA.

CVE-2023-20198EPSS 99.6%CiscoIOS XE Web UI
CISA KEV ↗ · unattributed attribution
high

CVE-2023-21608: Adobe Acrobat and Reader Use-After-Free Vulnerability

Adobe Acrobat and Reader contains a use-after-free vulnerability that allows for code execution in the context of the current user. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-21608EPSS 61.5%Acrobat and ReaderAdobe
CISA KEV ↗ · unattributed attribution
high

CVE-2023-20109: Cisco IOS and IOS XE Group Encrypted Transport VPN Out-of-Bounds Write Vulnerability

Cisco IOS and IOS XE contain an out-of-bounds write vulnerability in the Group Encrypted Transport VPN (GET VPN) feature that could allow an authenticated, remote attacker who has administrative control of either a group member or a key server to execute malicious code or cause a device to crash. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-20109EPSS 2.3%CiscoIOS and IOS XE
CISA KEV ↗ · unattributed attribution
high

CVE-2023-44487: HTTP/2 Rapid Reset Attack Vulnerability

HTTP/2 contains a rapid reset vulnerability that allows for a distributed denial-of-service attack (DDoS). Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2023-44487EPSS 100.0%HTTP/2IETF
CISA KEV ↗ · unattributed attribution
high

CVE-2023-22515: Atlassian Confluence Data Center and Server Broken Access Control Vulnerability

Atlassian Confluence Data Center and Server contains a broken access control vulnerability that allows an attacker to create unauthorized Confluence administrator accounts and access Confluence. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Check all affected Confluence instances for evidence of compromise per vendor instructions and report any positive findings to CISA.

CVE-2023-22515EPSS 99.2%AtlassianConfluence Data Center and Server
CISA KEV ↗ · unattributed attribution
high

CVE-2023-40044: Progress WS_FTP Server Deserialization of Untrusted Data Vulnerability

Progress WS_FTP Server contains a deserialization of untrusted data vulnerability in the Ad Hoc Transfer module that allows an authenticated attacker to execute remote commands on the underlying operating system. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-40044EPSS 90.1%ProgressWS_FTP Server
CISA KEV ↗ · unattributed attribution
high

CVE-2023-42793: JetBrains TeamCity Authentication Bypass Vulnerability

JetBrains TeamCity contains an authentication bypass vulnerability that allows for remote code execution on TeamCity Server. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-42793EPSS 100.0%JetBrainsTeamCity
CISA KEV ↗ · unattributed attribution
high

CVE-2023-28229: Microsoft Windows CNG Key Isolation Service Privilege Escalation Vulnerability

Microsoft Windows Cryptographic Next Generation (CNG) Key Isolation Service contains an unspecified vulnerability that allows an attacker to gain specific limited SYSTEM privileges. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-28229EPSS 1.9%MicrosoftWindows CNG Key Isolation Service
CISA KEV ↗ · unattributed attribution
high

CVE-2023-4211: Arm Mali GPU Kernel Driver Use-After-Free Vulnerability

Arm Mali GPU Kernel Driver contains a use-after-free vulnerability that allows a local, non-privileged user to make improper GPU memory processing operations to gain access to already freed memory. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-4211EPSS 1.4%ArmMali GPU Kernel Driver
CISA KEV ↗ · unattributed attribution
high

CVE-2023-5217: Google Chromium libvpx Heap Buffer Overflow Vulnerability

Google Chromium libvpx contains a heap buffer overflow vulnerability in vp8 encoding that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could impact web browsers using libvpx, including but not limited to Google Chrome. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-5217EPSS 49.0%Chromium libvpxGoogle
CISA KEV ↗ · unattributed attribution
high

CVE-2018-14667: Red Hat JBoss RichFaces Framework Expression Language Injection Vulnerability

Red Hat JBoss RichFaces Framework contains an expression language injection vulnerability via the UserResource resource. A remote, unauthenticated attacker could exploit this vulnerability to execute malicious code using a chain of Java serialized objects via org.ajax4jsf.resource.UserResource$UriData. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2018-14667EPSS 74.2%JBoss RichFaces FrameworkRed Hat
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2023-41993: Apple Multiple Products WebKit Code Execution Vulnerability

Apple iOS, iPadOS, macOS, and Safari WebKit contain an unspecified vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-41993EPSS 29.2%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2023-41179: Trend Micro Apex One and Worry-Free Business Security Remote Code Execution Vulnerability

Trend Micro Apex One and Worry-Free Business Security contain an unspecified vulnerability in the third-party anti-virus uninstaller that could allow an attacker to manipulate the module to conduct remote code execution. An attacker must first obtain administrative console access on the target system in order to exploit this vulnerability. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-41179EPSS 4.7%Apex One and Worry-Free Business SecurityTrend Micro
CISA KEV ↗ · unattributed attribution
high

CVE-2023-28434: MinIO Security Feature Bypass Vulnerability

MinIO contains a security feature bypass vulnerability that allows an attacker to use crafted requests to bypass metadata bucket name checking and put an object into any bucket while processing `PostPolicyBucket` to conduct privilege escalation. To carry out this attack, the attacker requires credentials with `arn:aws:s3:::*` permission, as well as enabled Console API access. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-28434EPSS 6.7%MinIO
CISA KEV ↗ · unattributed attribution
high

CVE-2022-22265: Samsung Mobile Devices Use-After-Free Vulnerability

Samsung devices with selected Exynos chipsets contain a use-after-free vulnerability that allows malicious memory write and code execution. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2022-22265EPSS 0.4%Mobile DevicesSamsung
CISA KEV ↗ · unattributed attribution
high

CVE-2014-8361: Realtek SDK Improper Input Validation Vulnerability

Realtek SDK contains an improper input validation vulnerability in the miniigd SOAP service that allows remote attackers to execute malicious code via a crafted NewInternalClient request. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2014-8361EPSS 100.0%RealtekSDK
CISA KEV ↗ · unattributed attribution
high

CVE-2017-6884: Zyxel EMG2926 Routers Command Injection Vulnerability

Zyxel EMG2926 routers contain a command injection vulnerability located in the diagnostic tools, specifically the nslookup function. A malicious user may exploit numerous vectors to execute malicious commands on the router, such as the ping_ip parameter to the expert/maintenance/diagnostic/nslookup URI. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2017-6884EPSS 37.6%EMG2926 RoutersZyxel
CISA KEV ↗ · unattributed attribution
high

CVE-2021-3129: Laravel Ignition File Upload Vulnerability

Laravel Ignition contains a file upload vulnerability that allows unauthenticated remote attackers to execute malicious code due to insecure usage of file_get_contents() and file_put_contents(). Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2021-3129EPSS 99.9%IgnitionLaravel
CISA KEV ↗ · unattributed attribution
high

CVE-2023-20269: Cisco Adaptive Security Appliance and Firepower Threat Defense Unauthorized Access Vulnerability

Cisco Adaptive Security Appliance and Firepower Threat Defense contain an unauthorized access vulnerability that could allow an unauthenticated, remote attacker to conduct a brute force attack in an attempt to identify valid username and password combinations or establish a clientless SSL VPN session with an unauthorized user. Required action: Apply mitigations per vendor instructions for group-lock and vpn-simultaneous-logins or discontinue use of the product for unsupported devices.

CVE-2023-20269EPSS 21.6%Adaptive Security Appliance and Firepower Threat DefenseCisco
CISA KEV ↗ · unattributed attribution
high

CVE-2023-4863: Google Chromium WebP Heap-Based Buffer Overflow Vulnerability

Google Chromium WebP contains a heap-based buffer overflow vulnerability that allows a remote attacker to perform an out-of-bounds memory write via a crafted HTML page. This vulnerability can affect applications that use the WebP Codec. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-4863EPSS 99.7%Chromium WebPGoogle
CISA KEV ↗ · unattributed attribution
high

CVE-2023-41064: Apple iOS, iPadOS, and macOS ImageIO Buffer Overflow Vulnerability

Apple iOS, iPadOS, and macOS contain a buffer overflow vulnerability in ImageIO when processing a maliciously crafted image, which may lead to code execution. This vulnerability was chained with CVE-2023-41061. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-41061CVE-2023-41064EPSS 15.3%AppleiOS, iPadOS, and macOS
CISA KEV ↗ · unattributed attribution
high

CVE-2023-41061: Apple iOS, iPadOS, and watchOS Wallet Code Execution Vulnerability

Apple iOS, iPadOS, and watchOS contain an unspecified vulnerability due to a validation issue affecting Wallet in which a maliciously crafted attachment may result in code execution. This vulnerability was chained with CVE-2023-41064. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-41061CVE-2023-41064EPSS 15.3%AppleiOS, iPadOS, and watchOS
CISA KEV ↗ · unattributed attribution
high

CVE-2023-33246: Apache RocketMQ Command Execution Vulnerability

Several components of Apache RocketMQ, including NameServer, Broker, and Controller, are exposed to the extranet and lack permission verification. An attacker can exploit this vulnerability by using the update configuration function to execute commands as the system users that RocketMQ is running as or achieve the same effect by forging the RocketMQ protocol content. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-33246EPSS 96.6%ApacheRocketMQ
CISA KEV ↗ · unattributed attribution
high

CVE-2023-38831: RARLAB WinRAR Code Execution Vulnerability

RARLAB WinRAR contains an unspecified vulnerability that allows an attacker to execute code when a user attempts to view a benign file within a ZIP archive. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-38831EPSS 97.8%RARLABWinRAR
CISA KEV ↗ · unattributed attribution
high

CVE-2023-32315: Ignite Realtime Openfire Path Traversal Vulnerability

Ignite Realtime Openfire contains a path traversal vulnerability that allows an unauthenticated attacker to access restricted pages in the Openfire Admin Console reserved for administrative users. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-32315EPSS 100.0%Ignite RealtimeOpenfire
CISA KEV ↗ · unattributed attribution
high

CVE-2023-38035: Ivanti Sentry Authentication Bypass Vulnerability

Ivanti Sentry, formerly known as MobileIron Sentry, contains an authentication bypass vulnerability that may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTTPD configuration. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-38035EPSS 99.9%IvantiSentry
CISA KEV ↗ · unattributed attribution
high

CVE-2023-27532: Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function Vulnerability

Veeam Backup & Replication Cloud Connect component contains a missing authentication for critical function vulnerability that allows an unauthenticated user operating within the backup infrastructure network perimeter to obtain encrypted credentials stored in the configuration database. This may lead to an attacker gaining access to the backup infrastructure hosts. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-27532EPSS 77.6%Backup & ReplicationVeeam
CISA KEV ↗ · unattributed attribution
high

CVE-2023-24489: Citrix Content Collaboration ShareFile Improper Access Control Vulnerability

Citrix Content Collaboration contains an improper access control vulnerability that could allow an unauthenticated attacker to remotely compromise customer-managed ShareFile storage zones controllers. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-24489EPSS 95.1%CitrixContent Collaboration
CISA KEV ↗ · unattributed attribution
high

CVE-2017-18368: Zyxel P660HN-T1A Routers Command Injection Vulnerability

Zyxel P660HN-T1A routers contain a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user and exploited via the remote_host parameter of the ViewLog.asp page. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2017-18368EPSS 94.5%P660HN-T1A RoutersZyxel
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2023-35081: Ivanti Endpoint Manager Mobile (EPMM) Path Traversal Vulnerability

Ivanti Endpoint Manager Mobile (EPMM) contains a path traversal vulnerability that enables an authenticated administrator to perform malicious file writes to the EPMM server. This vulnerability can be used in conjunction with CVE-2023-35078 to bypass authentication and ACLs restrictions (if applicable). Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-35078CVE-2023-35081EPSS 100.0%Endpoint Manager Mobile (EPMM)Ivanti
CISA KEV ↗ · unattributed attribution
high

CVE-2023-38606: Apple Multiple Products Kernel Unspecified Vulnerability

Apple iOS, iPadOS, macOS, tvOS, and watchOS contain an unspecified vulnerability allowing an app to modify a sensitive kernel state. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-38606EPSS 1.0%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2023-35078: Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability

Ivanti Endpoint Manager Mobile (EPMM, previously branded MobileIron Core) contains an authentication bypass vulnerability that allows unauthenticated access to specific API paths. An attacker with access to these API paths can access personally identifiable information (PII) such as names, phone numbers, and other mobile device details for users on a vulnerable system. An attacker can also make other configuration changes including installing software and modifying security profiles on registered devices. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-35078EPSS 100.0%Endpoint Manager Mobile (EPMM)Ivanti
CISA KEV ↗ · unattributed attribution
high

CVE-2023-36884: Microsoft Windows Search Remote Code Execution Vulnerability

Microsoft Windows Search contains an unspecified vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file, leading to remote code execution. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-36884EPSS 99.0%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2022-29303: SolarView Compact Command Injection Vulnerability

SolarView Compact contains a command injection vulnerability due to improper validation of input values on the send test mail console of the product's web server. Required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.

CVE-2022-29303EPSS 98.0%CompactSolarView
CISA KEV ↗ · unattributed attribution
high

CVE-2023-37450: Apple Multiple Products WebKit Code Execution Vulnerability

Apple iOS, iPadOS, macOS, and Safari WebKit contain an unspecified vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.

CVE-2023-37450EPSS 18.9%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2023-35311: Microsoft Outlook Security Feature Bypass Vulnerability

Microsoft Outlook contains a security feature bypass vulnerability that allows an attacker to bypass the Microsoft Outlook Security Notice prompt. Required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.

CVE-2023-35311EPSS 15.5%MicrosoftOutlook
CISA KEV ↗ · unattributed attribution
high

CVE-2022-31199: Netwrix Auditor Insecure Object Deserialization Vulnerability

Netwrix Auditor User Activity Video Recording component contains an insecure objection deserialization vulnerability that allows an unauthenticated, remote attacker to execute code as the NT AUTHORITY\SYSTEM user. Successful exploitation requires that the attacker is able to reach port 9004/TCP, which is commonly blocked by standard enterprise firewalling. Required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.

CVE-2022-31199EPSS 36.0%AuditorNetwrix
CISA KEV ↗ · unattributed attribution
high

CVE-2021-29256: Arm Mali GPU Kernel Driver Use-After-Free Vulnerability

Arm Mali GPU Kernel Driver contains a use-after-free vulnerability that may allow a non-privileged user to gain root privilege and/or disclose information. Required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.

CVE-2021-29256EPSS 3.0%ArmMali Graphics Processing Unit (GPU)
CISA KEV ↗ · unattributed attribution
high

CVE-2019-17621: D-Link DIR-859 Router Command Execution Vulnerability

D-Link DIR-859 router contains a command execution vulnerability in the UPnP endpoint URL, /gena.cgi. Exploitation allows an unauthenticated remote attacker to execute system commands as root by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connecting to the local network. Required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.

CVE-2019-17621EPSS 89.6%D-LinkDIR-859 Router
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2019-20500: D-Link DWL-2600AP Access Point Command Injection Vulnerability

D-Link DWL-2600AP access point contains an authenticated command injection vulnerability via the Save Configuration functionality in the Web interface, using shell metacharacters in the admin.cgi?action=config_save configBackup or downloadServerip parameter. Required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.

CVE-2019-20500EPSS 97.1%D-LinkDWL-2600AP Access Point
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2021-25487: Samsung Mobile Devices Out-of-Bounds Read Vulnerability

Samsung mobile devices contain an out-of-bounds read vulnerability within the modem interface driver due to a lack of boundary checking of a buffer in set_skb_priv(), leading to remote code execution by dereference of an invalid function pointer. Required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable

CVE-2021-25487EPSS 0.6%Mobile DevicesSamsung
CISA KEV ↗ · unattributed attribution
high

CVE-2021-25489: Samsung Mobile Devices Improper Input Validation Vulnerability

Samsung mobile devices contain an improper input validation vulnerability within the modem interface driver that results in a format string bug leading to kernel panic. Required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable

CVE-2021-25489EPSS 0.5%Mobile DevicesSamsung
CISA KEV ↗ · unattributed attribution
high

CVE-2021-25394: Samsung Mobile Devices Race Condition Vulnerability

Samsung mobile devices contain a race condition vulnerability within the MFC charger driver that leads to a use-after-free allowing for a write given a radio privilege is compromised. Required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable

CVE-2021-25394EPSS 0.4%Mobile DevicesSamsung
CISA KEV ↗ · unattributed attribution
high

CVE-2021-25395: Samsung Mobile Devices Race Condition Vulnerability

Samsung mobile devices contain a race condition vulnerability within the MFC charger driver that leads to a use-after-free allowing for a write given a radio privilege is compromised. Required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable

CVE-2021-25395EPSS 0.4%Mobile DevicesSamsung
CISA KEV ↗ · unattributed attribution
high

CVE-2021-25371: Samsung Mobile Devices Unspecified Vulnerability

Samsung mobile devices contain an unspecified vulnerability within DSP driver that allows attackers to load ELF libraries inside DSP. Required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable

CVE-2021-25371EPSS 0.8%Mobile DevicesSamsung
CISA KEV ↗ · unattributed attribution
high

CVE-2023-32435: Apple Multiple Products WebKit Memory Corruption Vulnerability

Apple iOS, iPadOS, macOS, and Safari WebKit contain a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Required action: Apply updates per vendor instructions.

CVE-2023-32435EPSS 23.0%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2023-32439: Apple Multiple Products WebKit Type Confusion Vulnerability

Apple iOS, iPadOS, macOS, and Safari WebKit contain a type confusion vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Required action: Apply updates per vendor instructions.

CVE-2023-32439EPSS 23.8%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2023-20867: VMware Tools Authentication Bypass Vulnerability

VMware Tools contains an authentication bypass vulnerability in the vgauth module. A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine. An attacker must have root access over ESXi to exploit this vulnerability. Required action: Apply updates per vendor instructions.

CVE-2023-20867EPSS 13.6%ToolsVMware
CISA KEV ↗ · unattributed attribution
high

CVE-2023-27992: Zyxel Multiple NAS Devices Command Injection Vulnerability

Multiple Zyxel network-attached storage (NAS) devices contain a pre-authentication command injection vulnerability that could allow an unauthenticated attacker to execute commands remotely via a crafted HTTP request. Required action: Apply updates per vendor instructions.

CVE-2023-27992EPSS 84.2%Multiple Network-Attached Storage (NAS) DevicesZyxel
CISA KEV ↗ · unattributed attribution
high

CVE-2023-20887: Vmware Aria Operations for Networks Command Injection Vulnerability

VMware Aria Operations for Networks (formerly vRealize Network Insight) contains a command injection vulnerability that allows a malicious actor with network access to perform an attack resulting in remote code execution. Required action: Apply updates per vendor instructions.

CVE-2023-20887EPSS 98.3%Aria Operations for NetworksVMware
CISA KEV ↗ · unattributed attribution
high

CVE-2020-35730: Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability

Roundcube Webmail contains a cross-site scripting (XSS) vulnerability that allows an attacker to send a plain text e-mail message with Javascript in a link reference element that is mishandled by linkref_addinindex in rcube_string_replacer.php. Required action: Apply updates per vendor instructions.

CVE-2020-35730EPSS 32.8%RoundcubeRoundcube Webmail
CISA KEV ↗ · unattributed attribution
high

CVE-2020-12641: Roundcube Webmail Remote Code Execution Vulnerability

Roundcube Webmail contains an remote code execution vulnerability that allows attackers to execute code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path. Required action: Apply updates per vendor instructions.

CVE-2020-12641EPSS 84.5%RoundcubeRoundcube Webmail
CISA KEV ↗ · unattributed attribution
high

CVE-2023-3079: Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2023-3079EPSS 32.7%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2023-33009: Zyxel Multiple Firewalls Buffer Overflow Vulnerability

Zyxel ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and ZyWALL/USG firewalls contain a buffer overflow vulnerability in the notification function that could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and remote code execution on an affected device. Required action: Apply updates per vendor instructions.

CVE-2023-33009EPSS 28.1%Multiple FirewallsZyxel
CISA KEV ↗ · unattributed attribution
high

CVE-2023-33010: Zyxel Multiple Firewalls Buffer Overflow Vulnerability

Zyxel ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and ZyWALL/USG firewalls contain a buffer overflow vulnerability in the ID processing function that could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and remote code execution on an affected device. Required action: Apply updates per vendor instructions.

CVE-2023-33010EPSS 28.8%Multiple FirewallsZyxel
CISA KEV ↗ · unattributed attribution
high

CVE-2023-34362: Progress MOVEit Transfer SQL Injection Vulnerability

Progress MOVEit Transfer contains a SQL injection vulnerability that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database in addition to executing SQL statements that alter or delete database elements. Required action: Apply updates per vendor instructions.

CVE-2023-34362EPSS 99.9%MOVEit TransferProgress
CISA KEV ↗ · unattributed attribution
high

CVE-2023-28771: Zyxel Multiple Firewalls OS Command Injection Vulnerability

Zyxel ATP, USG FLEX, VPN, and ZyWALL/USG firewalls allow for improper error message handling which could allow an unauthenticated attacker to execute OS commands remotely by sending crafted packets to an affected device. Required action: Apply updates per vendor instructions.

CVE-2023-28771EPSS 99.3%Multiple FirewallsZyxel
CISA KEV ↗ · unattributed attribution
high

CVE-2023-32409: Apple Multiple Products WebKit Sandbox Escape Vulnerability

Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit contain an unspecified vulnerability that can allow a remote attacker to break out of the Web Content sandbox. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Required action: Apply updates per vendor instructions.

CVE-2023-32409EPSS 16.5%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2023-28204: Apple Multiple Products WebKit Out-of-Bounds Read Vulnerability

Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit contain an out-of-bounds read vulnerability that may disclose sensitive information when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Required action: Apply updates per vendor instructions.

CVE-2023-28204EPSS 14.3%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2023-32373: Apple Multiple Products WebKit Use-After-Free Vulnerability

Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Required action: Apply updates per vendor instructions.

CVE-2023-32373EPSS 12.2%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2004-1464: Cisco IOS Denial-of-Service Vulnerability

Cisco IOS contains an unspecified vulnerability that may block further telnet, reverse telnet, Remote Shell (RSH), Secure Shell (SSH), and in some cases, Hypertext Transport Protocol (HTTP) access to the Cisco device. Required action: Apply updates per vendor instructions.

CVE-2004-1464EPSS 5.1%CiscoIOS
CISA KEV ↗ · unattributed attribution
high

CVE-2016-6415: Cisco IOS, IOS XR, and IOS XE IKEv1 Information Disclosure Vulnerability

Cisco IOS, IOS XR, and IOS XE contain insufficient condition checks in the part of the code that handles Internet Key Exchange version 1 (IKEv1) security negotiation requests. contains an information disclosure vulnerability in the Internet Key Exchange version 1 (IKEv1) that could allow an attacker to retrieve memory contents. Successful exploitation could allow the attacker to retrieve memory contents, which can lead to information disclosure. Required action: Apply updates per vendor instructions.

CVE-2016-6415EPSS 87.3%CiscoIOS, IOS XR, and IOS XE
CISA KEV ↗ · unattributed attribution
high

CVE-2023-25717: Multiple Ruckus Wireless Products CSRF and RCE Vulnerability

Ruckus Wireless Access Point (AP) software contains an unspecified vulnerability in the web services component. If the web services component is enabled on the AP, an attacker can perform cross-site request forgery (CSRF) or remote code execution (RCE). This vulnerability impacts Ruckus ZoneDirector, SmartZone, and Solo APs. Required action: Apply updates per vendor instructions or disconnect product if it is end-of-life.

CVE-2023-25717EPSS 95.3%Multiple ProductsRuckus Wireless
CISA KEV ↗ · unattributed attribution
high

CVE-2014-0196: Linux Kernel Race Condition Vulnerability

Linux Kernel contains a race condition vulnerability within the n_tty_write function that allows local users to cause a denial-of-service (DoS) or gain privileges via read and write operations with long strings. Required action: The impacted product is end-of-life and should be disconnected if still in use.

CVE-2014-0196EPSS 22.5%KernelLinux
CISA KEV ↗ · unattributed attribution
high

CVE-2010-3904: Linux Kernel Improper Input Validation Vulnerability

Linux Kernel contains an improper input validation vulnerability in the Reliable Datagram Sockets (RDS) protocol implementation that allows local users to gain privileges via crafted use of the sendmsg and recvmsg system calls. Required action: The impacted product is end-of-life and should be disconnected if still in use.

CVE-2010-3904EPSS 12.2%KernelLinux
CISA KEV ↗ · unattributed attribution
high

CVE-2016-3427: Oracle Java SE and JRockit Unspecified Vulnerability

Oracle Java SE and JRockit contains an unspecified vulnerability that allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Java Management Extensions (JMX). This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. Required action: Apply updates per vendor instructions.

CVE-2016-3427EPSS 92.3%Java SE and JRockitOracle
CISA KEV ↗ · unattributed attribution
high

CVE-2016-8735: Apache Tomcat Remote Code Execution Vulnerability

Apache Tomcat contains an unspecified vulnerability that allows for remote code execution if JmxRemoteLifecycleListener is used and an attacker can reach Java Management Extension (JMX) ports. This CVE exists because this listener wasn't updated for consistency with the Oracle patched issues for CVE-2016-3427 which affected credential types. Required action: Apply updates per vendor instructions.

CVE-2016-3427CVE-2016-8735EPSS 92.3%ApacheTomcat
CISA KEV ↗ · unattributed attribution
high

CVE-2021-45046: Apache Log4j2 Deserialization of Untrusted Data Vulnerability

Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations. Required action: Apply updates per vendor instructions.

CVE-2021-44228CVE-2021-45046EPSS 100.0%ApacheLog4j2
CISA KEV ↗ · unattributed attribution
high

CVE-2023-21839: Oracle WebLogic Server Unspecified Vulnerability

Oracle WebLogic Server contains an unspecified vulnerability that allows an unauthenticated attacker with network access via T3, IIOP, to compromise Oracle WebLogic Server. Required action: Apply updates per vendor instructions.

CVE-2023-21839EPSS 99.8%OracleWebLogic Server
CISA KEV ↗ · unattributed attribution
high

CVE-2023-27350: PaperCut MF/NG Improper Access Control Vulnerability

PaperCut MF/NG contains an improper access control vulnerability within the SetupCompleted class that allows authentication bypass and code execution in the context of system. Required action: Apply updates per vendor instructions.

CVE-2023-27350EPSS 100.0%MF/NGPaperCut
CISA KEV ↗ · unattributed attribution
high

CVE-2023-2136: Google Chrome Skia Integer Overflow Vulnerability

Google Chromium Skia contains an integer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability affects Google Chrome and ChromeOS, Android, Flutter, and possibly other products. Required action: Apply updates per vendor instructions.

CVE-2023-2136EPSS 5.8%Chromium SkiaGoogle
CISA KEV ↗ · unattributed attribution
high

CVE-2017-6742: Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. Required action: Apply updates per vendor instructions.

CVE-2017-6742EPSS 21.4%CiscoIOS and IOS XE Software
CISA KEV ↗ · unattributed attribution
high

CVE-2023-2033: Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2023-2033EPSS 40.8%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2023-20963: Android Framework Privilege Escalation Vulnerability

Android Framework contains an unspecified vulnerability that allows for privilege escalation after updating an app to a higher Target SDK with no additional execution privileges needed. Required action: Apply updates per vendor instructions.

CVE-2023-20963EPSS 1.4%AndroidFramework
CISA KEV ↗ · unattributed attribution
high

CVE-2023-28205: Apple Multiple Products WebKit Use-After-Free Vulnerability

Apple iOS, iPadOS, macOS, and Safari WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Required action: Apply updates per vendor instructions.

CVE-2023-28205EPSS 27.1%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2021-27876: Veritas Backup Exec Agent File Access Vulnerability

Veritas Backup Exec (BE) Agent contains a file access vulnerability that could allow an attacker to specially craft input parameters on a data management protocol command to access files on the BE Agent machine. Required action: Apply updates per vendor instructions.

CVE-2021-27876EPSS 13.4%Backup Exec AgentVeritas
CISA KEV ↗ · unattributed attribution
high

CVE-2021-27878: Veritas Backup Exec Agent Command Execution Vulnerability

Veritas Backup Exec (BE) Agent contains a command execution vulnerability that could allow an attacker to use a data management protocol command to execute a command on the BE Agent machine. Required action: Apply updates per vendor instructions.

CVE-2021-27878EPSS 24.0%Backup Exec AgentVeritas
CISA KEV ↗ · unattributed attribution
high

CVE-2013-3163: Microsoft Internet Explorer Memory Corruption Vulnerability

Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code or cause a denial of service via a crafted website. Required action: The impacted product is end-of-life and should be disconnected if still in use.

CVE-2013-3163EPSS 70.7%Internet ExplorerMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2017-7494: Samba Remote Code Execution Vulnerability

Samba contains a remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share and then cause the server to load and execute it. Required action: Apply updates per vendor instructions.

CVE-2017-7494EPSS 99.4%Samba
CISA KEV ↗ · unattributed attribution
high

CVE-2023-0266: Linux Kernel Use-After-Free Vulnerability

Linux kernel contains a use-after-free vulnerability that allows for privilege escalation to gain ring0 access from the system user. Required action: Apply updates per vendor instructions.

CVE-2023-0266EPSS 3.7%KernelLinux
CISA KEV ↗ · unattributed attribution
high

CVE-2022-3038: Google Chromium Network Service Use-After-Free Vulnerability

Google Chromium Network Service contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2022-3038EPSS 24.7%Chromium Network ServiceGoogle
CISA KEV ↗ · unattributed attribution
high

CVE-2022-41328: Fortinet FortiOS Path Traversal Vulnerability

Fortinet FortiOS contains a path traversal vulnerability that may allow a local privileged attacker to read and write files via crafted CLI commands. Required action: Apply updates per vendor instructions.

CVE-2022-41328EPSS 12.3%FortiOSFortinet
CISA KEV ↗ · unattributed attribution
high

CVE-2021-39144: XStream Remote Code Execution Vulnerability

XStream contains a remote code execution vulnerability that allows an attacker to manipulate the processed input stream and replace or inject objects that result in the execution of a local command on the server. This vulnerability can affect multiple products, including but not limited to VMware Cloud Foundation. Required action: Apply updates per vendor instructions.

CVE-2021-39144EPSS 98.1%XStream
CISA KEV ↗ · unattributed attribution
high

CVE-2020-5741: Plex Media Server Remote Code Execution Vulnerability

Plex Media Server contains a remote code execution vulnerability that allows an attacker with access to the server administrator's Plex account to upload a malicious file via the Camera Upload feature and have the media server execute it. Required action: Apply updates per vendor instructions.

CVE-2020-5741EPSS 72.8%Media ServerPlex
CISA KEV ↗ · unattributed attribution
high

CVE-2022-36537: ZK Framework AuUploader Unspecified Vulnerability

ZK Framework AuUploader servlets contain an unspecified vulnerability that could allow an attacker to retrieve the content of a file located in the web context. The ZK Framework is an open-source Java framework. This vulnerability can impact multiple products, including but not limited to ConnectWise R1Soft Server Backup Manager. Required action: Apply updates per vendor instructions.

CVE-2022-36537EPSS 95.3%AuUploaderZK Framework
CISA KEV ↗ · unattributed attribution
high

CVE-2022-41223: Mitel MiVoice Connect Code Injection Vulnerability

The Director component in Mitel MiVoice Connect allows an authenticated attacker with internal network access to execute code within the context of the application. Required action: Apply updates per vendor instructions.

CVE-2022-41223EPSS 10.6%MiVoice ConnectMitel
CISA KEV ↗ · unattributed attribution
high

CVE-2023-23529: Apple Multiple Products WebKit Type Confusion Vulnerability

Apple iOS, MacOS, Safari and iPadOS WebKit contain a type confusion vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Required action: Apply updates per vendor instructions.

CVE-2023-23529EPSS 9.5%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2023-0669: Fortra GoAnywhere MFT Remote Code Execution Vulnerability

Fortra (formerly, HelpSystems) GoAnywhere MFT contains a pre-authentication remote code execution vulnerability in the License Response Servlet due to deserializing an attacker-controlled object. Required action: Apply updates per vendor instructions.

CVE-2023-0669EPSS 100.0%FortraGoAnywhere MFT
CISA KEV ↗ · unattributed attribution
high

CVE-2022-21587: Oracle E-Business Suite Unspecified Vulnerability

Oracle E-Business Suite contains an unspecified vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator. Required action: Apply updates per vendor instructions.

CVE-2022-21587EPSS 98.3%E-Business SuiteOracle
CISA KEV ↗ · unattributed attribution
high

CVE-2022-44877: CWP Control Web Panel OS Command Injection Vulnerability

CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command injection vulnerability that allows remote attackers to execute commands via shell metacharacters in the login parameter. Required action: Apply updates per vendor instructions.

CVE-2022-44877EPSS 100.0%CWPControl Web Panel
CISA KEV ↗ · unattributed attribution
high

CVE-2022-41080: Microsoft Exchange Server Privilege Escalation Vulnerability

Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation. This vulnerability is chainable with CVE-2022-41082, which allows for remote code execution. Required action: Apply updates per vendor instructions.

CVE-2022-41080CVE-2022-41082EPSS 100.0%Exchange ServerMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2022-42475: Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability

Multiple versions of Fortinet FortiOS SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker to execute arbitrary code or commands via specifically crafted requests. Required action: Apply updates per vendor instructions.

CVE-2022-42475EPSS 99.5%FortiOSFortinet
CISA KEV ↗ · unattributed attribution
high

CVE-2022-27518: Citrix Application Delivery Controller (ADC) and Gateway Authentication Bypass Vulnerability

Citrix Application Delivery Controller (ADC) and Gateway, when configured with SAML SP or IdP configuration, contain an authentication bypass vulnerability that allows an attacker to execute code as administrator. Required action: Apply updates per vendor instructions.

CVE-2022-27518EPSS 6.9%Application Delivery Controller (ADC) and GatewayCitrix
CISA KEV ↗ · unattributed attribution
high

CVE-2022-26500: Veeam Backup & Replication Remote Code Execution Vulnerability

The Veeam Distribution Service in the Backup & Replication application allows unauthenticated users to access internal API functions. A remote attacker can send input to the internal API which may lead to uploading and executing of malicious code. Required action: Apply updates per vendor instructions.

CVE-2022-26500EPSS 5.9%Backup & ReplicationVeeam
CISA KEV ↗ · unattributed attribution
high

CVE-2022-26501: Veeam Backup & Replication Remote Code Execution Vulnerability

The Veeam Distribution Service in the Backup & Replication application allows unauthenticated users to access internal API functions. A remote attacker can send input to the internal API which may lead to uploading and executing of malicious code. Required action: Apply updates per vendor instructions.

CVE-2022-26501EPSS 4.3%Backup & ReplicationVeeam
CISA KEV ↗ · unattributed attribution
high

CVE-2022-4262: Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2022-4262EPSS 16.1%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2022-4135: Google Chromium GPU Heap Buffer Overflow Vulnerability

Google Chromium GPU contains a heap buffer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2022-4135EPSS 31.9%Chromium GPUGoogle
CISA KEV ↗ · unattributed attribution
high

CVE-2021-25337: Samsung Mobile Devices Improper Access Control Vulnerability

Samsung mobile devices contain an improper access control vulnerability in clipboard service which allows untrusted applications to read or write arbitrary files. This vulnerability was chained with CVE-2021-25369 and CVE-2021-25370. Required action: Apply updates per vendor instructions.

CVE-2021-25337CVE-2021-25369EPSS 2.8%Mobile DevicesSamsung
CISA KEV ↗ · unattributed attribution
high

CVE-2021-25369: Samsung Mobile Devices Improper Access Control Vulnerability

Samsung mobile devices using Mali GPU contains an improper access control vulnerability in sec_log file. Exploitation of the vulnerability exposes sensitive kernel information to the userspace. This vulnerability was chained with CVE-2021-25337 and CVE-2021-25370. Required action: Apply updates per vendor instructions.

CVE-2021-25337CVE-2021-25369EPSS 2.8%Mobile DevicesSamsung
CISA KEV ↗ · unattributed attribution
high

CVE-2021-25370: Samsung Mobile Devices Memory Corruption Vulnerability

Samsung mobile devices using Mali GPU contain an incorrect implementation handling file descriptor in dpu driver. This incorrect implementation results in memory corruption, leading to kernel panic. This vulnerability was chained with CVE-2021-25337 and CVE-2021-25369. Required action: Apply updates per vendor instructions.

CVE-2021-25337CVE-2021-25369EPSS 2.8%Mobile DevicesSamsung
CISA KEV ↗ · unattributed attribution
high

CVE-2022-3723: Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2022-3723EPSS 6.8%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2020-3433: Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability

Cisco AnyConnect Secure Mobility Client for Windows interprocess communication (IPC) channel allows for insufficient validation of resources that are loaded by the application at run time. An attacker with valid credentials on Windows could execute code on the affected machine with SYSTEM privileges. Required action: Apply updates per vendor instructions.

CVE-2020-3433EPSS 10.0%AnyConnect SecureCisco
CISA KEV ↗ · unattributed attribution
high

CVE-2020-3153: Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability

Cisco AnyConnect Secure Mobility Client for Windows allows for incorrect handling of directory paths. An attacker with valid credentials on Windows would be able to copy malicious files to arbitrary locations with system level privileges. This could include DLL pre-loading, DLL hijacking, and other related attacks. Required action: Apply updates per vendor instructions.

CVE-2020-3153EPSS 28.3%AnyConnect SecureCisco
CISA KEV ↗ · unattributed attribution
high

CVE-2018-19323: GIGABYTE Multiple Products Privilege Escalation Vulnerability

The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges. Required action: Apply updates per vendor instructions.

CVE-2018-19323EPSS 8.5%GIGABYTEMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2018-19322: GIGABYTE Multiple Products Code Execution Vulnerability

The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read/write data from/to IO ports. This could be leveraged in a number of ways to ultimately run code with elevated privileges. Required action: Apply updates per vendor instructions.

CVE-2018-19322EPSS 1.9%GIGABYTEMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2018-19321: GIGABYTE Multiple Products Privilege Escalation Vulnerability

The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges. Required action: Apply updates per vendor instructions.

CVE-2018-19321EPSS 3.7%GIGABYTEMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2018-19320: GIGABYTE Multiple Products Unspecified Vulnerability

The GDrv low-level driver in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II exposes ring0 memcpy-like functionality that could allow a local attacker to take complete control of the affected system. Required action: Apply updates per vendor instructions.

CVE-2018-19320EPSS 3.6%GIGABYTEMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2021-3493: Linux Kernel Privilege Escalation Vulnerability

The overlayfs stacking file system in Linux kernel does not properly validate the application of file capabilities against user namespaces, which could lead to privilege escalation. Required action: Apply updates per vendor instructions.

CVE-2021-3493EPSS 44.0%KernelLinux
CISA KEV ↗ · unattributed attribution
high

CVE-2022-40684: Fortinet Multiple Products Authentication Bypass Vulnerability

Fortinet FortiOS, FortiProxy, and FortiSwitchManager contain an authentication bypass vulnerability that could allow an unauthenticated attacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests. Required action: Apply updates per vendor instructions.

CVE-2022-40684EPSS 100.0%FortinetMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2022-41082: Microsoft Exchange Server Remote Code Execution Vulnerability

Microsoft Exchange Server contains an unspecified vulnerability that allows for authenticated remote code execution. Dubbed "ProxyNotShell," this vulnerability is chainable with CVE-2022-41040 which allows for the remote code execution. Required action: Apply updates per vendor instructions.

CVE-2022-41040CVE-2022-41082EPSS 100.0%Exchange ServerMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2022-36804: Atlassian Bitbucket Server and Data Center Command Injection Vulnerability

Multiple API endpoints of Atlassian Bitbucket Server and Data Center contain a command injection vulnerability where an attacker with access to a public Bitbucket repository, or with read permissions to a private one, can execute code by sending a malicious HTTP request. Required action: Apply updates per vendor instructions.

CVE-2022-36804EPSS 99.1%AtlassianBitbucket Server and Data Center
CISA KEV ↗ · unattributed attribution
high

CVE-2013-6282: Linux Kernel Improper Input Validation Vulnerability

The get_user and put_user API functions of the Linux kernel fail to validate the target address when being used on ARM v6k/v7 platforms. This allows an application to read and write kernel memory which could lead to privilege escalation. Required action: Apply updates per vendor instructions.

CVE-2013-6282EPSS 39.7%KernelLinux
CISA KEV ↗ · unattributed attribution
high

CVE-2013-2094: Linux Kernel Privilege Escalation Vulnerability

Linux kernel fails to check all 64 bits of attr.config passed by user space, resulting to out-of-bounds access of the perf_swevent_enabled array in sw_perf_event_destroy(). Explotation allows for privilege escalation. Required action: Apply updates per vendor instructions.

CVE-2013-2094EPSS 47.7%KernelLinux
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2010-2568: Microsoft Windows Remote Code Execution Vulnerability

Microsoft Windows incorrectly parses shortcuts in such a way that malicious code may be executed when the operating system displays the icon of a malicious shortcut file. An attacker who successfully exploited this vulnerability could execute code as the logged-on user. Required action: Apply updates per vendor instructions.

CVE-2010-2568EPSS 91.3%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2022-3075: Google Chromium Mojo Insufficient Data Validation Vulnerability

Google Chromium Mojo contains an insufficient data validation vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2022-3075EPSS 5.7%Chromium MojoGoogle
CISA KEV ↗ · unattributed attribution
high

CVE-2022-27593: QNAP Photo Station Externally Controlled Reference Vulnerability

Certain QNAP NAS running Photo Station with internet exposure contain an externally controlled reference to a resource vulnerability which can allow an attacker to modify system files. This vulnerability was observed being utilized in a Deadbolt ransomware campaign. Required action: Apply updates per vendor instructions.

CVE-2022-27593EPSS 87.9%Photo StationQNAP
CISA KEV ↗ · unattributed attribution
high

CVE-2022-26258: D-Link DIR-820L Remote Code Execution Vulnerability

D-Link DIR-820L contains an unspecified vulnerability in Device Name parameter in /lan.asp which allows for remote code execution. Required action: The impacted product is end-of-life and should be disconnected if still in use.

CVE-2022-26258EPSS 81.1%D-LinkDIR-820L
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2018-7445: MikroTik RouterOS Stack-Based Buffer Overflow Vulnerability

In MikroTik RouterOS, a stack-based buffer overflow occurs when processing NetBIOS session request messages. Remote attackers with access to the service can exploit this vulnerability and gain code execution on the system. Required action: Apply updates per vendor instructions.

CVE-2018-7445EPSS 61.0%MikroTikRouterOS
CISA KEV ↗ · unattributed attribution
high

CVE-2018-6530: D-Link Multiple Routers OS Command Injection Vulnerability

Multiple D-Link routers contain an unspecified vulnerability that allows for execution of OS commands. Required action: The vendor D-Link published an advisory stating the fix under CVE-2018-20114 properly patches KEV entry CVE-2018-6530. If the device is still supported, apply updates per vendor instructions. If the affected device has since entered its end-of-life, it should be disconnected if still in use.

CVE-2018-20114CVE-2018-6530EPSS 96.7%D-LinkMultiple Routers
CISA KEV ↗ · unattributed attribution
high

CVE-2018-2628: Oracle WebLogic Server Unspecified Vulnerability

Oracle WebLogic Server contains an unspecified vulnerability which can allow an unauthenticated attacker with T3 network access to compromise the server. Required action: Apply updates per vendor instructions.

CVE-2018-2628EPSS 99.4%OracleWebLogic Server
CISA KEV ↗ · unattributed attribution
high

CVE-2018-13374: Fortinet FortiOS and FortiADC Improper Access Control Vulnerability

Fortinet FortiOS and FortiADC contain an improper access control vulnerability that allows attackers to obtain the LDAP server login credentials configured in FortiGate by pointing a LDAP server connectivity test request to a rogue LDAP server. Required action: Apply updates per vendor instructions.

CVE-2018-13374EPSS 38.1%FortiOS and FortiADCFortinet
CISA KEV ↗ · unattributed attribution
high

CVE-2011-1823: Android OS Privilege Escalation Vulnerability

The vold volume manager daemon in Android kernel trusts messages from a PF_NETLINK socket, which allows an attacker to execute code and gain root privileges. This vulnerability is associated with GingerBreak and Exploit.AndroidOS.Lotoor. Required action: Apply updates per vendor instructions.

CVE-2011-1823EPSS 41.6%AndroidAndroid OS
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2022-26352: dotCMS Unrestricted Upload of File Vulnerability

dotCMS ContentResource API contains an unrestricted upload of file with a dangerous type vulnerability that allows for directory traversal, in which the file is saved outside of the intended storage location. Exploitation allows for remote code execution. Required action: Apply updates per vendor instructions.

CVE-2022-26352EPSS 91.5%dotCMS
CISA KEV ↗ · unattributed attribution
high

CVE-2022-2294: WebRTC Heap Buffer Overflow Vulnerability

WebRTC, an open-source project providing web browsers with real-time communication, contains a heap buffer overflow vulnerability that allows an attacker to perform shellcode execution. This vulnerability impacts web browsers using WebRTC including but not limited to Google Chrome. Required action: Apply updates per vendor instructions.

CVE-2022-2294EPSS 70.5%WebRTC
CISA KEV ↗ · unattributed attribution
high

CVE-2021-39226: Grafana Authentication Bypass Vulnerability

Grafana contains an authentication bypass vulnerability that allows authenticated and unauthenticated users to view and delete all snapshot data, potentially resulting in complete snapshot data loss. Required action: Apply updates per vendor instructions.

CVE-2021-39226EPSS 99.9%GrafanaGrafana Labs
CISA KEV ↗ · unattributed attribution
high

CVE-2021-38406: Delta Electronics DOPSoft 2 Improper Input Validation Vulnerability

Delta Electronics DOPSoft 2 lacks proper validation of user-supplied data when parsing specific project files (improper input validation) resulting in an out-of-bounds write that allows for code execution. Required action: The impacted product is end-of-life and should be disconnected if still in use.

CVE-2021-38406EPSS 77.9%DOPSoft 2Delta Electronics
CISA KEV ↗ · unattributed attribution
high

CVE-2020-36193: PEAR Archive_Tar Improper Link Resolution Vulnerability

PEAR Archive_Tar Tar.php allows write operations with directory traversal due to inadequate checking of symbolic links. PEAR stands for PHP Extension and Application Repository and it is an open-source framework and distribution system for reusable PHP components with known usage in third-party products such as Drupal Core and Red Hat Linux. Required action: Apply updates per vendor instructions.

CVE-2020-36193EPSS 70.6%Archive_TarPEAR
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2020-28949: PEAR Archive_Tar Deserialization of Untrusted Data Vulnerability

PEAR Archive_Tar allows an unserialization attack because phar: is blocked but PHAR: is not blocked. PEAR stands for PHP Extension and Application Repository and it is an open-source framework and distribution system for reusable PHP components with known usage in third-party products such as Drupal Core and Red Hat Linux. Required action: Apply updates per vendor instructions.

CVE-2020-28949EPSS 84.6%Archive_TarPEAR
CISA KEV ↗ · unattributed attribution
high

CVE-2022-22536: SAP Multiple Products HTTP Request Smuggling Vulnerability

SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server and SAP Web Dispatcher allow HTTP request smuggling. An unauthenticated attacker can prepend a victim's request with arbitrary data, allowing for function execution impersonating the victim or poisoning intermediary Web caches. Required action: Apply updates per vendor instructions.

CVE-2022-22536EPSS 97.9%Multiple ProductsSAP
CISA KEV ↗ · unattributed attribution
high

CVE-2022-2856: Google Chromium Intents Insufficient Input Validation Vulnerability

Google Chromium Intents contains an insufficient validation of untrusted input vulnerability that allows a remote attacker to browse to a malicious website via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2022-2856EPSS 4.5%Chromium IntentsGoogle
CISA KEV ↗ · unattributed attribution
high

CVE-2022-27925: Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability

Synacor Zimbra Collaboration Suite (ZCS) contains flaw in the mboximport functionality, allowing an authenticated attacker to upload arbitrary files to perform remote code execution. This vulnerability was chained with CVE-2022-37042 which allows for unauthenticated remote code execution. Required action: Apply updates per vendor instructions.

CVE-2022-27925CVE-2022-37042EPSS 98.6%SynacorZimbra Collaboration Suite (ZCS)
CISA KEV ↗ · unattributed attribution
high

CVE-2022-37042: Synacor Zimbra Collaboration Suite (ZCS) Authentication Bypass Vulnerability

Synacor Zimbra Collaboration Suite (ZCS) contains an authentication bypass vulnerability in MailboxImportServlet. This vulnerability was chained with CVE-2022-27925 which allows for unauthenticated remote code execution. Required action: Apply updates per vendor instructions.

CVE-2022-27925CVE-2022-37042EPSS 98.6%SynacorZimbra Collaboration Suite (ZCS)
CISA KEV ↗ · unattributed attribution
high

CVE-2022-26138: Atlassian Questions For Confluence App Hard-coded Credentials Vulnerability

Atlassian Questions For Confluence App has hard-coded credentials, exposing the username and password in plaintext. A remote unauthenticated attacker can use these credentials to log into Confluence and access all content accessible to users in the confluence-users group. Required action: Apply updates per vendor instructions.

CVE-2022-26138EPSS 98.2%AtlassianConfluence
CISA KEV ↗ · unattributed attribution
high

CVE-2022-26925: Microsoft Windows LSA Spoofing Vulnerability

Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability where an attacker can coerce the domain controller to authenticate to the attacker using NTLM. Required action: Apply remediation actions outlined in CISA guidance [https://www.cisa.gov/guidance-applying-june-microsoft-patch].

CVE-2022-26925EPSS 10.5%MicrosoftWindows
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2021-30533: Google Chromium PopupBlocker Security Bypass Vulnerability

Google Chromium PopupBlocker contains an insufficient policy enforcement vulnerability that allows a remote attacker to bypass navigation restrictions via a crafted iframe. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2021-30533EPSS 16.6%Chromium PopupBlockerGoogle
CISA KEV ↗ · unattributed attribution
high

CVE-2022-30190: Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability

A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run code with the privileges of the calling application. Required action: Apply updates per vendor instructions.

CVE-2022-30190EPSS 99.4%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2016-2386: SAP NetWeaver SQL Injection Vulnerability

SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. Required action: Apply updates per vendor instructions.

CVE-2016-2386EPSS 71.1%NetWeaverSAP
CISA KEV ↗ · unattributed attribution
high

CVE-2019-7195: QNAP Photo Station Path Traversal Vulnerability

QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files. Required action: Apply updates per vendor instructions.

CVE-2019-7195EPSS 89.7%Photo StationQNAP
CISA KEV ↗ · unattributed attribution
high

CVE-2019-7194: QNAP Photo Station Path Traversal Vulnerability

QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files. Required action: Apply updates per vendor instructions.

CVE-2019-7194EPSS 83.0%Photo StationQNAP
CISA KEV ↗ · unattributed attribution
high

CVE-2019-5825: Google Chromium V8 Out-of-Bounds Write Vulnerability

Google Chromium V8 Engine contains an out-of-bounds write vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2019-5825EPSS 55.9%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2018-6065: Google Chromium V8 Integer Overflow Vulnerability

Google Chromium V8 Engine contains an integer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2018-6065EPSS 60.3%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2018-17480: Google Chromium V8 Out-of-Bounds Write Vulnerability

Google Chromium V8 Engine contains out-of-bounds write vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2018-17480EPSS 34.3%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2018-17463: Google Chromium V8 Remote Code Execution Vulnerability

Google Chromium V8 Engine contains an unspecified vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2018-17463EPSS 84.6%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2017-5070: Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2017-5070EPSS 31.2%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2017-5030: Google Chromium V8 Memory Corruption Vulnerability

Google Chromium V8 Engine contains a memory corruption vulnerability that allows a remote attacker to execute code via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2017-5030EPSS 41.6%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2016-5198: Google Chromium V8 Out-of-Bounds Memory Vulnerability

Google Chromium V8 Engine contains an out-of-bounds memory access vulnerability that allows a remote attacker to perform read/write operations, leading to code execution, via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2016-5198EPSS 34.7%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2016-1646: Google Chromium V8 Out-of-Bounds Read Vulnerability

Google Chromium V8 Engine contains an out-of-bounds read vulnerability that allows a remote attacker to cause a denial of service or possibly have another unspecified impact via crafted JavaScript code. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2016-1646EPSS 48.1%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2012-5054: Adobe Flash Player Integer Overflow Vulnerability

Adobe Flash Player contains an integer overflow vulnerability that allows remote attackers to execute code via malformed arguments. Required action: The impacted product is end-of-life and should be disconnected if still in use.

CVE-2012-5054EPSS 21.2%AdobeFlash Player
CISA KEV ↗ · unattributed attribution
high

CVE-2012-0754: Adobe Flash Player Memory Corruption Vulnerability

Adobe Flash Player contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS). Required action: The impacted product is end-of-life and should be disconnected if still in use.

CVE-2012-0754EPSS 92.0%AdobeFlash Player
CISA KEV ↗ · unattributed attribution
high

CVE-2011-0609: Adobe Flash Player Unspecified Vulnerability

Adobe Flash Player contains an unspecified vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS). Required action: The impacted product is end-of-life and should be disconnected if still in use.

CVE-2011-0609EPSS 66.8%AdobeFlash Player
CISA KEV ↗ · unattributed attribution
high

CVE-2010-1297: Adobe Flash Player Memory Corruption Vulnerability

Adobe Flash Player contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS). Required action: The impacted product is end-of-life and should be disconnected if still in use.

CVE-2010-1297EPSS 82.4%AdobeFlash Player
CISA KEV ↗ · unattributed attribution
high

CVE-2009-1862: Adobe Acrobat and Reader, Flash Player Unspecified Vulnerability

Adobe Acrobat and Reader and Adobe Flash Player allows remote attackers to execute code or cause denial-of-service (DoS). Required action: For Adobe Acrobat and Reader, apply updates per vendor instructions. For Adobe Flash Player, the impacted product is end-of-life and should be disconnected if still in use.

CVE-2009-1862EPSS 25.0%Acrobat and Reader, Flash PlayerAdobe
CISA KEV ↗ · unattributed attribution
high

CVE-2009-0563: Microsoft Office Buffer Overflow Vulnerability

Microsoft Office contains a buffer overflow vulnerability that allows remote attackers to execute code via a Word document with a crafted tag containing an invalid length field. Required action: Apply updates per vendor instructions.

CVE-2009-0563EPSS 63.1%MicrosoftOffice
CISA KEV ↗ · unattributed attribution
high

CVE-2008-0655: Adobe Acrobat and Reader Unspecified Vulnerability

Adobe Acrobat and Reader contains an unespecified vulnerability described as a design flaw which could allow a specially crafted file to be printed silently an arbitrary number of times. Required action: Apply updates per vendor instructions.

CVE-2008-0655EPSS 36.8%Acrobat and ReaderAdobe
CISA KEV ↗ · unattributed attribution
high

CVE-2007-5659: Adobe Acrobat and Reader Buffer Overflow Vulnerability

Adobe Acrobat and Reader contain a buffer overflow vulnerability that allows remote attackers to execute code via a PDF file with long arguments to unspecified JavaScript methods. Required action: Apply updates per vendor instructions.

CVE-2007-5659EPSS 94.2%Acrobat and ReaderAdobe
CISA KEV ↗ · unattributed attribution
high

CVE-2022-26134: Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability

Atlassian Confluence Server and Data Center contain a remote code execution vulnerability that allows for an unauthenticated attacker to perform remote code execution. Required action: Immediately block all internet traffic to and from affected products AND apply the update per vendor instructions [https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html] OR remove the affected products by the due date on the right. Note: Once the update is successfully deployed, agencies can reassess the internet blocking rules.

CVE-2022-26134EPSS 100.0%AtlassianConfluence Server/Data Center
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2015-0310: Adobe Flash Player ASLR Bypass Vulnerability

Adobe Flash Player does not properly restrict discovery of memory addresses, which allows attackers to bypass the address space layout randomization (ASLR) protection mechanism. Required action: The impacted product is end-of-life and should be disconnected if still in use.

CVE-2015-0310EPSS 15.2%AdobeFlash Player
CISA KEV ↗ · unattributed attribution
high

CVE-2014-4077: Microsoft IME Japanese Privilege Escalation Vulnerability

Microsoft Input Method Editor (IME) Japanese is a keyboard with Japanese characters that can be enabled on Windows systems as it is included by default (with the default set as disabled). IME Japanese contains an unspecified vulnerability when IMJPDCT.EXE (IME for Japanese) is installed which allows attackers to bypass a sandbox and perform privilege escalation. Required action: Apply updates per vendor instructions.

CVE-2014-4077EPSS 47.7%Input Method Editor (IME) JapaneseMicrosoft
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2014-3153: Linux Kernel Privilege Escalation Vulnerability

The futex_requeue function in kernel/futex.c in Linux kernel does not ensure that calls have two different futex addresses, which allows local users to gain privileges. Required action: Apply updates per vendor instructions.

CVE-2014-3153EPSS 37.2%KernelLinux
CISA KEV ↗ · unattributed attribution
high

CVE-2013-3993: IBM InfoSphere BigInsights Invalid Input Vulnerability

Certain APIs within BigInsights can take invalid input that might allow attackers unauthorized access to read, write, modify, or delete data. Required action: The impacted product is end-of-life and should be disconnected if still in use.

CVE-2013-3993EPSS 5.2%IBMInfoSphere BigInsights
CISA KEV ↗ · unattributed attribution
high

CVE-2013-3896: Microsoft Silverlight Information Disclosure Vulnerability

Microsoft Silverlight does not properly validate pointers during access to Silverlight elements, which allows remote attackers to obtain sensitive information via a crafted Silverlight application. Required action: The impacted product is end-of-life and should be disconnected if still in use.

CVE-2013-3896EPSS 69.6%MicrosoftSilverlight
CISA KEV ↗ · unattributed attribution
high

CVE-2013-2423: Oracle JRE Unspecified Vulnerability

Unspecified vulnerability in hotspot for Java Runtime Environment (JRE) allows remote attackers to affect integrity. Required action: Apply updates per vendor instructions.

CVE-2013-2423EPSS 85.3%Java Runtime Environment (JRE)Oracle
CISA KEV ↗ · unattributed attribution
high

CVE-2013-0431: Oracle JRE Sandbox Bypass Vulnerability

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle allows remote attackers to bypass the Java security sandbox. Required action: Apply updates per vendor instructions.

CVE-2013-0431EPSS 90.0%Java Runtime Environment (JRE)Oracle
CISA KEV ↗ · unattributed attribution
high

CVE-2013-0422: Oracle JRE Remote Code Execution Vulnerability

A vulnerability in the way Java restricts the permissions of Java applets could allow an attacker to execute commands on a vulnerable system. Required action: Apply updates per vendor instructions.

CVE-2013-0422EPSS 97.6%Java Runtime Environment (JRE)Oracle
CISA KEV ↗ · unattributed attribution
high

CVE-2013-0074: Microsoft Silverlight Double Dereference Vulnerability

Microsoft Silverlight does not properly validate pointers during HTML object rendering, which allows remote attackers to execute code via a crafted Silverlight application. Required action: The impacted product is end-of-life and should be disconnected if still in use.

CVE-2013-0074EPSS 81.9%MicrosoftSilverlight
CISA KEV ↗ · unattributed attribution
high

CVE-2012-1710: Oracle Fusion Middleware Unspecified Vulnerability

Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to Designer. Required action: Apply updates per vendor instructions.

CVE-2012-1710EPSS 11.6%Fusion MiddlewareOracle
CISA KEV ↗ · unattributed attribution
high

CVE-2010-1428: Red Hat JBoss Information Disclosure Vulnerability

Unauthenticated access to the JBoss Application Server Web Console (/web-console) is blocked by default. However, it was found that this block was incomplete, and only blocked GET and POST HTTP verbs. A remote attacker could use this flaw to gain access to sensitive information. Required action: Apply updates per vendor instructions.

CVE-2010-1428EPSS 62.3%JBossRed Hat
CISA KEV ↗ · unattributed attribution
high

CVE-2010-0840: Oracle JRE Unspecified Vulnerability

Unspecified vulnerability in the Java Runtime Environment (JRE) in Java SE component allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors. Required action: Apply updates per vendor instructions.

CVE-2010-0840EPSS 96.3%Java Runtime Environment (JRE)Oracle
CISA KEV ↗ · unattributed attribution
high

CVE-2010-0738: Red Hat JBoss Authentication Bypass Vulnerability

The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method. Required action: Apply updates per vendor instructions.

CVE-2010-0738EPSS 79.4%JBossRed Hat
CISA KEV ↗ · unattributed attribution
high

CVE-2017-18362: Kaseya VSA SQL Injection Vulnerability

ConnectWise ManagedITSync integration for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database. Required action: The impacted product is end-of-life and should be disconnected if still in use.

CVE-2017-18362EPSS 86.7%KaseyaVirtual System/Server Administrator (VSA)
CISA KEV ↗ · unattributed attribution
high

CVE-2016-4656: Apple iOS Memory Corruption Vulnerability

A memory corruption vulnerability in Apple iOS kernel allows attackers to execute code in a privileged context or cause a denial-of-service (DoS) via a crafted application. Required action: Apply updates per vendor instructions.

CVE-2016-4656EPSS 23.6%AppleiOS
CISA KEV ↗ · unattributed attribution
high

CVE-2016-4657: Apple iOS Webkit Memory Corruption Vulnerability

Apple iOS WebKit contains a memory corruption vulnerability that allows attackers to execute remote code or cause a denial-of-service (DoS) via a crafted web site. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Required action: Apply updates per vendor instructions.

CVE-2016-4657EPSS 66.8%AppleiOS
CISA KEV ↗ · unattributed attribution
high

CVE-2016-3298: Microsoft Internet Explorer Messaging API Information Disclosure Vulnerability

An information disclosure vulnerability exists when the Microsoft Internet Messaging API improperly handles objects in memory. An attacker who successfully exploited this vulnerability could allow the attacker to test for the presence of files on disk. Required action: Apply updates per vendor instructions.

CVE-2016-3298EPSS 32.8%Internet ExplorerMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2022-20821: Cisco IOS XR Open Port Vulnerability

Cisco IOS XR software health check opens TCP port 6379 by default on activation. An attacker can connect to the Redis instance on the open port and allow access to the Redis instance that is running within the NOSi container. Required action: Apply updates per vendor instructions.

CVE-2022-20821EPSS 11.8%CiscoIOS XR
CISA KEV ↗ · unattributed attribution
high

CVE-2021-0920: Android Kernel Race Condition Vulnerability

Android kernel contains a race condition, which allows for a use-after-free vulnerability. Exploitation can allow for privilege escalation. Required action: Apply updates per vendor instructions.

CVE-2021-0920EPSS 0.8%AndroidKernel
CISA KEV ↗ · unattributed attribution
high

CVE-2020-1027: Microsoft Windows Kernel Privilege Escalation Vulnerability

An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. Required action: Apply updates per vendor instructions.

CVE-2020-1027EPSS 4.4%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2019-0676: Microsoft Internet Explorer Information Disclosure Vulnerability

An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory. An attacker who successfully exploited this vulnerability could test for the presence of files on disk. Required action: Apply updates per vendor instructions.

CVE-2019-0676EPSS 7.5%Internet ExplorerMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2019-5786: Google Chrome Blink Use-After-Free Vulnerability

Google Chrome Blink contains a heap use-after-free vulnerability that allows an attacker to potentially perform out of bounds memory access via a crafted HTML page. Required action: Apply updates per vendor instructions.

CVE-2019-5786EPSS 61.5%Chrome BlinkGoogle
CISA KEV ↗ · unattributed attribution
high

CVE-2019-0880: Microsoft Windows Privilege Escalation Vulnerability

A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls. An attacker who successfully exploited the vulnerability could elevate privileges on an affected system from low-integrity to medium-integrity. Required action: Apply updates per vendor instructions.

CVE-2019-0880EPSS 2.4%MicrosoftWindows
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2019-11707: Mozilla Firefox and Thunderbird Type Confusion Vulnerability

Mozilla Firefox and Thunderbird contain a type confusion vulnerability that can occur when manipulating JavaScript objects due to issues in Array.pop, allowing for an exploitable crash. Required action: Apply updates per vendor instructions.

CVE-2019-11707EPSS 38.0%Firefox and ThunderbirdMozilla
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2018-8589: Microsoft Win32k Privilege Escalation Vulnerability

A privilege escalation vulnerability exists when Windows improperly handles calls to Win32k.sys. An attacker who successfully exploited this vulnerability could run remote code in the security context of the local system. Required action: Apply updates per vendor instructions.

CVE-2018-8589EPSS 3.0%MicrosoftWin32k
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2022-1388: F5 BIG-IP Missing Authentication Vulnerability

F5 BIG-IP contains a missing authentication in critical function vulnerability which can allow for remote code execution, creation or deletion of files, or disabling services. Required action: Apply updates per vendor instructions.

CVE-2022-1388EPSS 100.0%BIG-IPF5
CISA KEV ↗ · unattributed attribution
high

CVE-2014-0160: OpenSSL Information Disclosure Vulnerability

The TLS and DTLS implementations in OpenSSL do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information. Required action: Apply updates per vendor instructions.

CVE-2014-0160EPSS 100.0%OpenSSL
CISA KEV ↗ · unattributed attribution
high

CVE-2022-0847: Linux Kernel Privilege Escalation Vulnerability

Linux kernel contains an improper initialization vulnerability where an unprivileged local user could escalate their privileges on the system. This vulnerability has the moniker of "Dirty Pipe." Required action: Apply updates per vendor instructions.

CVE-2022-0847EPSS 89.1%KernelLinux
CISA KEV ↗ · unattributed attribution
high

CVE-2019-3568: WhatsApp VOIP Stack Buffer Overflow Vulnerability

A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number. Required action: Apply updates per vendor instructions.

CVE-2019-3568EPSS 39.2%Meta PlatformsWhatsApp
CISA KEV ↗ · unattributed attribution
high

CVE-2022-1364: Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2022-1364EPSS 13.7%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2019-3929: Crestron Multiple Products Command Injection Vulnerability

Multiple Crestron products are vulnerable to command injection via the file_transfer.cgi HTTP endpoint. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root. Required action: Apply updates per vendor instructions.

CVE-2019-3929EPSS 99.0%CrestronMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2018-7841: Schneider Electric U.motion Builder SQL Injection Vulnerability

A SQL Injection vulnerability exists in U.motion Builder software which could cause unwanted code execution when an improper set of characters is entered. Required action: The impacted product is end-of-life and should be disconnected if still in use.

CVE-2018-7841EPSS 72.5%Schneider ElectricU.motion Builder
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2018-7602: Drupal Core Remote Code Execution Vulnerability

A remote code execution vulnerability exists within multiple subsystems of Drupal that can allow attackers to exploit multiple attack vectors on a Drupal site. Required action: Apply updates per vendor instructions.

CVE-2018-7602EPSS 99.2%CoreDrupal
CISA KEV ↗ · unattributed attribution
high

CVE-2015-5123: Adobe Flash Player Use-After-Free Vulnerability

Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS). Required action: The impacted product is end-of-life and should be disconnected if still in use.

CVE-2015-5123EPSS 18.5%AdobeFlash Player
CISA KEV ↗ · unattributed attribution
high

CVE-2015-5122: Adobe Flash Player Use-After-Free Vulnerability

Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS). Required action: The impacted product is end-of-life and should be disconnected if still in use.

CVE-2015-5122EPSS 93.7%AdobeFlash Player
CISA KEV ↗ · unattributed attribution
high

CVE-2021-27852: Checkbox Survey Deserialization of Untrusted Data Vulnerability

Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute arbitrary code. Required action: Versions 6 and earlier for this product are end-of-life and must be removed from agency networks. Versions 7 and later are not considered vulnerable.

CVE-2021-27852EPSS 31.9%CheckboxCheckbox Survey
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2021-22600: Linux Kernel Privilege Escalation Vulnerability

Linux Kernel contains a flaw in the packet socket (AF_PACKET) implementation which could lead to incorrectly freeing memory. A local user could exploit this for denial-of-service (DoS) or possibly for privilege escalation. Required action: Apply updates per vendor instructions.

CVE-2021-22600EPSS 5.9%KernelLinux
CISA KEV ↗ · unattributed attribution
high

CVE-2021-28799: QNAP NAS Improper Authorization Vulnerability

QNAP NAS running HBS 3 contains an improper authorization vulnerability which can allow remote attackers to log in to a device. Required action: Apply updates per vendor instructions.

CVE-2021-28799EPSS 78.3%Network Attached Storage (NAS)QNAP
CISA KEV ↗ · unattributed attribution
high

CVE-2018-10562: Dasan GPON Routers Command Injection Vulnerability

Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10561, exploitation can allow an attacker to perform remote code execution. Required action: The impacted product is end-of-life and should be disconnected if still in use.

CVE-2018-10561CVE-2018-10562EPSS 99.9%DasanGigabit Passive Optical Network (GPON) Routers
CISA KEV ↗ · unattributed attribution
high

CVE-2018-10561: Dasan GPON Routers Authentication Bypass Vulnerability

Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10562, exploitation can allow an attacker to perform remote code execution. Required action: The impacted product is end-of-life and should be disconnected if still in use.

CVE-2018-10561CVE-2018-10562EPSS 99.9%DasanGigabit Passive Optical Network (GPON) Routers
CISA KEV ↗ · unattributed attribution
high

CVE-2022-1096: Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2022-1096EPSS 24.2%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2019-7483: SonicWall SMA100 Directory Traversal Vulnerability

In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of a file on the server. Required action: Apply updates per vendor instructions.

CVE-2019-7483EPSS 4.0%SMA100SonicWall
CISA KEV ↗ · unattributed attribution
high

CVE-2016-7201: Microsoft Edge Memory Corruption Vulnerability

The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site. Required action: Apply updates per vendor instructions.

CVE-2016-7201EPSS 79.7%EdgeMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2016-7200: Microsoft Edge Memory Corruption Vulnerability

The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site. Required action: Apply updates per vendor instructions.

CVE-2016-7200EPSS 82.5%EdgeMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2016-0189: Microsoft Internet Explorer Memory Corruption Vulnerability

The Microsoft JScript nd VBScript engines, as used in Internet Explorer and other products, allow attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site. Required action: Apply updates per vendor instructions.

CVE-2016-0189EPSS 93.2%Internet ExplorerMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2013-3660: Microsoft Win32k Privilege Escalation Vulnerability

The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft does not properly initialize a pointer for the next object in a certain list, which allows local users to gain privileges. Required action: Apply updates per vendor instructions.

CVE-2013-3660EPSS 39.6%MicrosoftWin32k
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2013-2465: Oracle Java SE Unspecified Vulnerability

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to 2D Required action: Apply updates per vendor instructions.

CVE-2013-2465EPSS 98.7%Java SEOracle
CISA KEV ↗ · unattributed attribution
high

CVE-2013-1690: Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability

Mozilla Firefox and Thunderbird do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial-of-service (DoS) or possibly execute malicious code via a crafted web site. Required action: Apply updates per vendor instructions.

CVE-2013-1690EPSS 69.0%Firefox and ThunderbirdMozilla
CISA KEV ↗ · unattributed attribution
high

CVE-2012-5076: Oracle Java SE Sandbox Bypass Vulnerability

The default Java security properties configuration did not restrict access to the com.sun.org.glassfish.external and com.sun.org.glassfish.gmbal packages. An untrusted Java application or applet could use these flaws to bypass Java sandbox restrictions. Required action: Apply updates per vendor instructions.

CVE-2012-5076EPSS 91.0%Java SEOracle
CISA KEV ↗ · unattributed attribution · 2 IOCs
high

CVE-2012-2034: Adobe Flash Player Memory Corruption Vulnerability

Adobe Flash Player contains a memory corruption vulnerability that allows for remote code execution or denial-of-service (DoS). Required action: The impacted product is end-of-life and should be disconnected if still in use.

CVE-2012-2034EPSS 7.8%AdobeFlash Player
CISA KEV ↗ · unattributed attribution
high

CVE-2012-0518: Oracle Fusion Middleware Unspecified Vulnerability

Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware allows remote attackers to affect integrity via Unknown vectors Required action: Apply updates per vendor instructions.

CVE-2012-0518EPSS 4.7%Fusion MiddlewareOracle
CISA KEV ↗ · unattributed attribution
high

CVE-2022-26143: MiCollab, MiVoice Business Express Access Control Vulnerability

A vulnerability has been identified in MiCollab and MiVoice Business Express that may allow a malicious actor to gain unauthorized access to sensitive information and services, cause performance degradations or a denial of service condition on the affected system. Required action: Apply updates per vendor instructions.

CVE-2022-26143EPSS 87.6%MiCollab, MiVoice Business ExpressMitel
CISA KEV ↗ · unattributed attribution
high

CVE-2020-9054: Zyxel Multiple NAS Devices OS Command Injection Vulnerability

Multiple Zyxel network-attached storage (NAS) devices contain a pre-authentication command injection vulnerability, which may allow a remote, unauthenticated attacker to execute arbitrary code. Required action: Apply updates per vendor instructions.

CVE-2020-9054EPSS 100.0%Multiple Network-Attached Storage (NAS) DevicesZyxel
CISA KEV ↗ · unattributed attribution
high

CVE-2020-7247: OpenSMTPD Remote Code Execution Vulnerability

smtp_mailaddr in smtp_session.c in OpenSMTPD, as used in OpenBSD and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP session. Required action: Apply updates per vendor instructions.

CVE-2020-7247EPSS 98.9%OpenBSDOpenSMTPD
CISA KEV ↗ · unattributed attribution
high

CVE-2020-1631: Juniper Junos OS Path Traversal Vulnerability

A path traversal vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication Pass-Through with Web-Redirect, and Zero Touch Provisioning (ZTP) allows an unauthenticated attacker to perform remote code execution. Required action: Apply updates per vendor instructions.

CVE-2020-1631EPSS 4.7%JuniperJunos OS
CISA KEV ↗ · unattributed attribution
high

CVE-2019-2616: Oracle BI Publisher Unauthorized Access Vulnerability

Oracle BI Publisher, formerly XML Publisher, contains an unspecified vulnerability that allows for various unauthorized actions. Open-source reporting attributes this vulnerability to allowing for authentication bypass. Required action: Apply updates per vendor instructions.

CVE-2019-2616EPSS 92.2%BI Publisher (Formerly XML Publisher)Oracle
CISA KEV ↗ · unattributed attribution
high

CVE-2019-0903: Microsoft GDI Remote Code Execution Vulnerability

A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory. An attacker who successfully exploited this vulnerability could take control of the affected system. Required action: Apply updates per vendor instructions.

CVE-2019-0903EPSS 21.7%Graphics Device Interface (GDI)Microsoft
CISA KEV ↗ · unattributed attribution
high

CVE-2018-0147: Cisco Secure Access Control System Java Deserialization Vulnerability

A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software. Required action: Apply updates per vendor instructions.

CVE-2018-0147EPSS 18.3%CiscoSecure Access Control System (ACS)
CISA KEV ↗ · unattributed attribution
high

CVE-2018-0125: Cisco VPN Routers Remote Code Execution Vulnerability

A vulnerability in the web interface of the Cisco VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as root and gain full control of an affected system. Required action: Apply updates per vendor instructions.

CVE-2018-0125EPSS 55.4%CiscoVPN Routers
CISA KEV ↗ · unattributed attribution
high

CVE-2017-6334: NETGEAR DGN2200 Devices OS Command Injection Vulnerability

dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands Required action: The impacted product is end-of-life and should be disconnected if still in use.

CVE-2017-6334EPSS 72.2%DGN2200 DevicesNETGEAR
CISA KEV ↗ · unattributed attribution · 2 IOCs
high

CVE-2017-6316: Citrix Multiple Products Remote Code Execution Vulnerability

A vulnerability has been identified in the management interface of Citrix NetScaler SD-WAN Enterprise and Standard Edition and Citrix CloudBridge Virtual WAN Edition that could result in an unauthenticated, remote attacker being able to execute arbitrary code as a root user. This vulnerability also affects XenMobile Server. Required action: Apply updates per vendor instructions.

CVE-2017-6316EPSS 72.6%CitrixNetScaler SD-WAN Enterprise, CloudBridge Virtual WAN, and XenMobile Server
CISA KEV ↗ · unattributed attribution
high

CVE-2017-3881: Cisco IOS and IOS XE Remote Code Execution Vulnerability

A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device or remotely execute code with elevated privileges. Required action: Apply updates per vendor instructions.

CVE-2017-3881EPSS 99.0%CiscoIOS and IOS XE
CISA KEV ↗ · unattributed attribution
high

CVE-2017-12617: Apache Tomcat Remote Code Execution Vulnerability

When running Apache Tomcat, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server. Required action: Apply updates per vendor instructions.

CVE-2017-12617EPSS 100.0%ApacheTomcat
CISA KEV ↗ · unattributed attribution
high

CVE-2017-12615: Apache Tomcat on Windows Remote Code Execution Vulnerability

When running Apache Tomcat on Windows with HTTP PUTs enabled, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server. Required action: Apply updates per vendor instructions.

CVE-2017-12615EPSS 99.6%ApacheTomcat
CISA KEV ↗ · unattributed attribution
high

CVE-2016-1555: NETGEAR Multiple WAP Devices Command Injection Vulnerability

Multiple NETGEAR Wireless Access Point devices allows unauthenticated web pages to pass form input directly to the command-line interface. Exploitation allows for arbitrary code execution. Required action: Apply updates per vendor instructions.

CVE-2016-1555EPSS 98.3%NETGEARWireless Access Point (WAP) Devices
CISA KEV ↗ · unattributed attribution
high

CVE-2014-0130: Ruby on Rails Directory Traversal Vulnerability

Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails allows remote attackers to read arbitrary files via a crafted request. Required action: Apply updates per vendor instructions.

CVE-2014-0130EPSS 53.7%RailsRuby on Rails
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2013-4810: HP Multiple Products Remote Code Execution Vulnerability

HP ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to (1) EJBInvokerServlet or (2) JMXInvokerServlet. Required action: Apply updates per vendor instructions.

CVE-2013-4810EPSS 79.0%Hewlett Packard (HP)ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management
CISA KEV ↗ · unattributed attribution
high

CVE-2012-1823: PHP-CGI Query String Parameter Vulnerability

sapi/cgi/cgi_main.c in PHP, when configured as a CGI script, does not properly handle query strings, which allows remote attackers to execute arbitrary code. Required action: Apply updates per vendor instructions.

CVE-2012-1823EPSS 100.0%PHP
CISA KEV ↗ · unattributed attribution
high

CVE-2010-4345: Exim Privilege Escalation Vulnerability

Exim allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands. Required action: Apply updates per vendor instructions.

CVE-2010-4345EPSS 17.8%Exim
CISA KEV ↗ · unattributed attribution
high

CVE-2010-4344: Exim Heap-Based Buffer Overflow Vulnerability

Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session. Required action: Apply updates per vendor instructions.

CVE-2010-4344EPSS 71.9%Exim
CISA KEV ↗ · unattributed attribution
high

CVE-2020-5135: SonicWall SonicOS Buffer Overflow Vulnerability

A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a malicious request to the firewall. Required action: Apply updates per vendor instructions.

CVE-2020-5135EPSS 26.9%SonicOSSonicWall
CISA KEV ↗ · unattributed attribution
high

CVE-2019-1322: Microsoft Windows Privilege Escalation Vulnerability

A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context. Required action: Apply updates per vendor instructions.

CVE-2019-1322EPSS 19.2%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2019-0543: Microsoft Windows Privilege Escalation Vulnerability

A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context. Required action: Apply updates per vendor instructions.

CVE-2019-0543EPSS 4.7%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2016-3309: Microsoft Windows Kernel Privilege Escalation Vulnerability

A privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. Required action: Apply updates per vendor instructions.

CVE-2016-3309EPSS 20.6%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2022-26485: Mozilla Firefox Use-After-Free Vulnerability

Mozilla Firefox contains a use-after-free vulnerability in XSLT parameter processing which can be exploited to perform arbitrary code execution. Required action: Apply updates per vendor instructions.

CVE-2022-26485EPSS 14.3%FirefoxMozilla
CISA KEV ↗ · unattributed attribution
high

CVE-2020-8218: Pulse Connect Secure Code Injection Vulnerability

A code injection vulnerability exists in Pulse Connect Secure that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface. Required action: Apply updates per vendor instructions.

CVE-2020-8218EPSS 32.7%Pulse Connect SecurePulse Secure
CISA KEV ↗ · unattributed attribution
high

CVE-2022-20708: Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability

A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS). Required action: Apply updates per vendor instructions.

CVE-2022-20708EPSS 14.9%CiscoSmall Business RV160, RV260, RV340, and RV345 Series Routers
CISA KEV ↗ · unattributed attribution
high

CVE-2022-20703: Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability

A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS). Required action: Apply updates per vendor instructions.

CVE-2022-20703EPSS 9.2%CiscoSmall Business RV160, RV260, RV340, and RV345 Series Routers
CISA KEV ↗ · unattributed attribution
high

CVE-2022-20701: Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability

A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS). Required action: Apply updates per vendor instructions.

CVE-2022-20701EPSS 9.7%CiscoSmall Business RV160, RV260, RV340, and RV345 Series Routers
CISA KEV ↗ · unattributed attribution
high

CVE-2022-20700: Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability

A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS). Required action: Apply updates per vendor instructions.

CVE-2022-20700EPSS 5.7%CiscoSmall Business RV160, RV260, RV340, and RV345 Series Routers
CISA KEV ↗ · unattributed attribution
high

CVE-2022-20699: Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability

A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS). Required action: Apply updates per vendor instructions.

CVE-2022-20699EPSS 72.5%CiscoSmall Business RV160, RV260, RV340, and RV345 Series Routers
CISA KEV ↗ · unattributed attribution
high

CVE-2020-1938: Apache Tomcat Improper Privilege Management Vulnerability

Apache Tomcat treats Apache JServ Protocol (AJP) connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited. Required action: Apply updates per vendor instructions.

CVE-2020-1938EPSS 99.3%ApacheTomcat
CISA KEV ↗ · unattributed attribution
high

CVE-2019-1652: Cisco Small Business Routers Improper Input Validation Vulnerability

A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker with administrative privileges on an affected device to execute arbitrary commands. Required action: Apply updates per vendor instructions.

CVE-2019-1652EPSS 95.9%CiscoSmall Business RV320 and RV325 Dual Gigabit WAN VPN Routers
CISA KEV ↗ · unattributed attribution
high

CVE-2018-8581: Microsoft Exchange Server Privilege Escalation Vulnerability

A privilege escalation vulnerability exists in Microsoft Exchange Server. An attacker who successfully exploited this vulnerability could attempt to impersonate any other user of the Exchange server. Required action: Apply updates per vendor instructions.

CVE-2018-8581EPSS 27.4%Exchange ServerMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2018-0180: Cisco IOS Software Denial-of-Service Vulnerability

A vulnerability in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition. Required action: Apply updates per vendor instructions.

CVE-2018-0180EPSS 5.0%CiscoIOS Software
CISA KEV ↗ · unattributed attribution
high

CVE-2018-0179: Cisco IOS Software Denial-of-Service Vulnerability

A vulnerability in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition. Required action: Apply updates per vendor instructions.

CVE-2018-0179EPSS 5.0%CiscoIOS Software
CISA KEV ↗ · unattributed attribution
high

CVE-2018-0175: Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability

Format string vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device. Required action: Apply updates per vendor instructions.

CVE-2018-0175EPSS 3.5%CiscoIOS, XR, and XE Software
CISA KEV ↗ · unattributed attribution
high

CVE-2018-0167: Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability

There is a buffer overflow vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software which could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code. Required action: Apply updates per vendor instructions.

CVE-2018-0167EPSS 3.4%CiscoIOS, XR, and XE Software
CISA KEV ↗ · unattributed attribution
high

CVE-2018-0161: Cisco IOS Software Resource Management Errors Vulnerability

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software running on certain models of Cisco Catalyst Switches could allow an authenticated, remote attacker to cause a denial-of-service (DoS) condition. Required action: Apply updates per vendor instructions.

CVE-2018-0161EPSS 4.7%CiscoIOS Software
CISA KEV ↗ · unattributed attribution
high

CVE-2018-0159: Cisco IOS and XE Software Internet Key Exchange Version 1 Denial-of-Service Vulnerability

A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial-of-service (DoS) condition. Required action: Apply updates per vendor instructions.

CVE-2018-0159EPSS 7.0%CiscoIOS Software and Cisco IOS XE Software
CISA KEV ↗ · unattributed attribution
high

CVE-2018-0158: Cisco IOS and XE Software Internet Key Exchange Memory Leak Vulnerability

A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial-of-service (DoS) condition. Required action: Apply updates per vendor instructions.

CVE-2018-0158EPSS 7.3%CiscoIOS Software and Cisco IOS XE Software
CISA KEV ↗ · unattributed attribution
high

CVE-2018-0156: Cisco IOS Software and Cisco IOS XE Software Smart Install Denial-of-Service Vulnerability

A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial-of-service (DoS) condition. Required action: Apply updates per vendor instructions.

CVE-2018-0156EPSS 8.3%CiscoIOS Software and Cisco IOS XE Software
CISA KEV ↗ · unattributed attribution
high

CVE-2018-0155: Cisco Catalyst Bidirectional Forwarding Detection Denial-of-Service Vulnerability

A vulnerability in the Bidirectional Forwarding Detection (BFD) offload implementation of Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches could allow an unauthenticated, remote attacker to cause a crash of the iosd process, causing a denial-of-service (DoS) condition. Required action: Apply updates per vendor instructions.

CVE-2018-0155EPSS 7.9%Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series SwitchesCisco
CISA KEV ↗ · unattributed attribution
high

CVE-2018-0151: Cisco IOS Software and Cisco IOS XE Software Quality of Service Remote Code Execution Vulnerability

A vulnerability in the quality of service (QoS) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges. Required action: Apply updates per vendor instructions.

CVE-2018-0151EPSS 14.5%CiscoIOS and IOS XE Software
CISA KEV ↗ · unattributed attribution
high

CVE-2017-8540: Microsoft Malware Protection Engine Improper Restriction of Operations Vulnerability

The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions.

CVE-2017-8540EPSS 72.0%Malware Protection EngineMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2017-6744: Cisco IOS Software SNMP Remote Code Execution Vulnerability

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS 1 contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities by sending a crafted SNMP packet to an affected system via IPv4 or IPv6. Required action: Apply updates per vendor instructions.

CVE-2017-6744EPSS 7.2%CiscoIOS software
CISA KEV ↗ · unattributed attribution
high

CVE-2017-6740: Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. Required action: Apply updates per vendor instructions.

CVE-2017-6740EPSS 10.8%CiscoIOS and IOS XE Software
CISA KEV ↗ · unattributed attribution
high

CVE-2017-6739: Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. Required action: Apply updates per vendor instructions.

CVE-2017-6739EPSS 10.5%CiscoIOS and IOS XE Software
CISA KEV ↗ · unattributed attribution
high

CVE-2017-6663: Cisco IOS Software and Cisco IOS XE Software Denial-of-Service Vulnerability

A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause autonomic nodes of an affected system to reload, resulting in denial-of-service (DoS). Required action: Apply updates per vendor instructions.

CVE-2017-6663EPSS 2.1%CiscoIOS and IOS XE Software
CISA KEV ↗ · unattributed attribution
high

CVE-2017-6627: Cisco IOS Software and Cisco IOS XE Software UDP Packet Processing Denial-of-Service Vulnerability

A vulnerability in the UDP processing code of Cisco IOS and IOS XE could allow an unauthenticated, remote attacker to cause the input queue of an affected system to hold UDP packets, causing an interface queue wedge and denial of service. Required action: Apply updates per vendor instructions.

CVE-2017-6627EPSS 6.0%CiscoIOS and IOS XE Software
CISA KEV ↗ · unattributed attribution
high

CVE-2017-12319: Cisco IOS XE Software Ethernet Virtual Private Network Border Gateway Protocol Denial-of-Service Vulnerability

A vulnerability in the Border Gateway Protocol (BGP) over an Ethernet Virtual Private Network (EVPN) for Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload, resulting in a denial of service (DoS) condition, or potentially corrupt the BGP routing table, which could result in network instability. Required action: Apply updates per vendor instructions.

CVE-2017-12319EPSS 5.3%CiscoIOS XE Software
CISA KEV ↗ · unattributed attribution
high

CVE-2017-12240: Cisco IOS and IOS XE Software DHCP Remote Code Execution Vulnerability

The Dynamic Host Configuration Protocol (DHCP) relay subsystem of Cisco IOS and Cisco IOS XE Software contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code and gain full control of an affected system. Required action: Apply updates per vendor instructions.

CVE-2017-12240EPSS 13.9%CiscoIOS and IOS XE Software
CISA KEV ↗ · unattributed attribution
high

CVE-2017-12237: Cisco IOS and IOS XE Software Internet Key Exchange Denial-of-Service Vulnerability

A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS and Cisco IOS XE could allow an unauthenticated, remote attacker to cause high CPU utilization, traceback messages, or a reload of an affected device that leads to a denial of service. Required action: Apply updates per vendor instructions.

CVE-2017-12237EPSS 7.1%CiscoIOS and IOS XE Software
CISA KEV ↗ · unattributed attribution
high

CVE-2017-12235: Cisco IOS Software for Cisco Industrial Ethernet Switches PROFINET Denial-of-Service Vulnerability

A vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP) for Cisco IOS could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service. Required action: Apply updates per vendor instructions.

CVE-2017-12235EPSS 7.1%CiscoIOS software
CISA KEV ↗ · unattributed attribution
high

CVE-2017-12232: Cisco IOS Software for Cisco Integrated Services Routers Denial-of-Service Vulnerability

A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers running Cisco IOS could allow an unauthenticated, adjacent attacker to cause an affected device to reload, resulting in a denial of service. Required action: Apply updates per vendor instructions.

CVE-2017-12232EPSS 2.2%CiscoIOS software
CISA KEV ↗ · unattributed attribution
high

CVE-2017-11826: Microsoft Office Remote Code Execution Vulnerability

A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. Required action: Apply updates per vendor instructions.

CVE-2017-11826EPSS 81.5%MicrosoftOffice
CISA KEV ↗ · unattributed attribution
high

CVE-2017-0001: Microsoft Graphics Device Interface (GDI) Privilege Escalation Vulnerability

The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges Required action: Apply updates per vendor instructions.

CVE-2017-0001EPSS 3.1%Graphics Device Interface (GDI)Microsoft
CISA KEV ↗ · unattributed attribution
high

CVE-2016-7855: Adobe Flash Player Use-After-Free Vulnerability

Use-after-free vulnerability in Adobe Flash Player Windows and OS and Linux allows remote attackers to execute arbitrary code. Required action: The impacted product is end-of-life and should be disconnected if still in use.

CVE-2016-7855EPSS 25.2%AdobeFlash Player
CISA KEV ↗ · unattributed attribution
high

CVE-2016-7262: Microsoft Office Security Feature Bypass Vulnerability

A security feature bypass vulnerability exists when Microsoft Office improperly handles input. An attacker who successfully exploited the vulnerability could execute arbitrary commands. Required action: Apply updates per vendor instructions.

CVE-2016-7262EPSS 58.2%ExcelMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2016-4117: Adobe Flash Player Arbitrary Code Execution Vulnerability

An access of resource using incompatible type vulnerability exists within Adobe Flash Player that allows an attacker to perform remote code execution. Required action: The impacted product is end-of-life and should be disconnected if still in use.

CVE-2016-4117EPSS 94.4%AdobeFlash Player
CISA KEV ↗ · unattributed attribution
high

CVE-2016-0099: Microsoft Windows Secondary Logon Service Privilege Escalation Vulnerability

A privilege escalation vulnerability exists in Microsoft Windows if the Windows Secondary Logon Service fails to properly manage request handles in memory. An attacker who successfully exploited this vulnerability could run arbitrary code as an administrator. Required action: Apply updates per vendor instructions.

CVE-2016-0099EPSS 37.2%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2015-5119: Adobe Flash Player Use-After-Free Vulnerability

A use-after-free vulnerability exists within the ActionScript 3 ByteArray class in Adobe Flash Player that allows an attacker to perform remote code execution. Required action: The impacted product is end-of-life and should be disconnected if still in use.

CVE-2015-5119EPSS 99.3%AdobeFlash Player
CISA KEV ↗ · unattributed attribution
high

CVE-2015-3043: Adobe Flash Player Memory Corruption Vulnerability

A memory corruption vulnerability exists in Adobe Flash Player that allows an attacker to perform remote code execution. Required action: The impacted product is end-of-life and should be disconnected if still in use.

CVE-2015-3043EPSS 79.8%AdobeFlash Player
CISA KEV ↗ · unattributed attribution
high

CVE-2015-1701: Microsoft Win32k Privilege Escalation Vulnerability

An unspecified vulnerability exists in the Win32k.sys kernel-mode driver in Microsoft Windows Server that allows a local attacker to execute arbitrary code with elevated privileges. Required action: Apply updates per vendor instructions.

CVE-2015-1701EPSS 56.2%MicrosoftWin32k
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2013-1675: Mozilla Firefox Information Disclosure Vulnerability

Mozilla Firefox does not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site. Required action: Apply updates per vendor instructions.

CVE-2013-1675EPSS 6.7%FirefoxMozilla
CISA KEV ↗ · unattributed attribution
high

CVE-2012-1856: Microsoft Office MSCOMCTL.OCX Remote Code Execution Vulnerability

The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office allows remote attackers to execute arbitrary code via a crafted (1) document or (2) web page that triggers system-state corruption. Required action: Apply updates per vendor instructions.

CVE-2012-1856EPSS 72.1%MicrosoftOffice
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2012-1535: Adobe Flash Player Arbitrary Code Execution Vulnerability

Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute arbitrary code or cause a denial of service via crafted SWF content. Required action: The impacted product is end-of-life and should be disconnected if still in use.

CVE-2012-1535EPSS 70.4%AdobeFlash Player
CISA KEV ↗ · unattributed attribution
high

CVE-2011-1889: Microsoft Forefront TMG Remote Code Execution Vulnerability

A remote code execution vulnerability exists in the Forefront Threat Management Gateway (TMG) Firewall Client Winsock provider that could allow code execution in the security context of the client application. Required action: Apply updates per vendor instructions.

CVE-2011-1889EPSS 48.4%Forefront Threat Management Gateway (TMG)Microsoft
CISA KEV ↗ · unattributed attribution
high

CVE-2011-0611: Adobe Flash Player Remote Code Execution Vulnerability

Adobe Flash Player contains a vulnerability that allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content. Required action: The impacted product is end-of-life and should be disconnected if still in use.

CVE-2011-0611EPSS 99.4%AdobeFlash Player
CISA KEV ↗ · unattributed attribution
high

CVE-2010-0232: Microsoft Windows Kernel Exception Handler Vulnerability

The kernel in Microsoft Windows, when access to 16-bit applications is enabled on a 32-bit x86 platform, does not properly validate certain BIOS calls, which allows local users to gain privileges. Required action: Apply updates per vendor instructions.

CVE-2010-0232EPSS 29.3%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2002-0367: Microsoft Windows Privilege Escalation Vulnerability

smss.exe debugging subsystem in Microsoft Windows does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges. Required action: Apply updates per vendor instructions.

CVE-2002-0367EPSS 5.2%MicrosoftWindows
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2022-0609: Google Chromium Animation Use-After-Free Vulnerability

Google Chromium Animation contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2022-0609EPSS 23.5%Chromium AnimationGoogle
CISA KEV ↗ · unattributed attribution
high

CVE-2017-9841: PHPUnit Command Injection Vulnerability

PHPUnit allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring, as demonstrated by an attack on a site with an exposed /vendor folder, i.e., external access to the /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php URI. Required action: Apply updates per vendor instructions.

CVE-2017-9841EPSS 100.0%PHPUnit
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2022-22620: Apple iOS, iPadOS, and macOS Webkit Use-After-Free Vulnerability

Apple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Required action: Apply updates per vendor instructions.

CVE-2022-22620EPSS 16.3%AppleiOS, iPadOS, and macOS
CISA KEV ↗ · unattributed attribution
high

CVE-2020-0796: Microsoft SMBv3 Remote Code Execution Vulnerability

A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests. An attacker who successfully exploited the vulnerability could gain the ability to execute code on the target server or client. Required action: Apply updates per vendor instructions.

CVE-2020-0796EPSS 99.8%MicrosoftSMBv3
CISA KEV ↗ · unattributed attribution
high

CVE-2015-2051: D-Link DIR-645 Router Remote Code Execution Vulnerability

D-Link DIR-645 Wired/Wireless Router allows remote attackers to execute arbitrary commands via a GetDeviceSettings action to the HNAP interface. Required action: The impacted product is end-of-life and should be disconnected if still in use.

CVE-2015-2051EPSS 97.1%D-LinkDIR-645 Router
CISA KEV ↗ · unattributed attribution
high

CVE-2014-4404: Apple OS X Heap-Based Buffer Overflow Vulnerability

Heap-based buffer overflow in IOHIDFamily in Apple OS X, which affects, iOS before 8 and Apple TV before 7, allows attackers to execute arbitrary code in a privileged context. Required action: Apply updates per vendor instructions.

CVE-2014-4404EPSS 49.0%AppleOS X
CISA KEV ↗ · unattributed attribution
high

CVE-2022-22587: Apple Memory Corruption Vulnerability

Apple IOMobileFrameBuffer contains a memory corruption vulnerability which can allow a malicious application to execute arbitrary code with kernel privileges. Required action: Apply updates per vendor instructions.

CVE-2022-22587EPSS 11.6%AppleiOS and macOS
CISA KEV ↗ · unattributed attribution
high

CVE-2014-7169: GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability

GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute code. This CVE correctly remediates the vulnerability in CVE-2014-6271. Required action: Apply updates per vendor instructions.

CVE-2014-6271CVE-2014-7169EPSS 100.0%Bourne-Again Shell (Bash)GNU
CISA KEV ↗ · unattributed attribution
high

CVE-2021-32648: October CMS Improper Authentication

In affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially crafted request. Required action: Apply updates per vendor instructions.

CVE-2021-32648EPSS 90.4%October CMS
CISA KEV ↗ · unattributed attribution
high

CVE-2021-25296: Nagios XI OS Command Injection

Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server. Required action: Apply updates per vendor instructions.

CVE-2021-25296EPSS 71.5%NagiosNagios XI
CISA KEV ↗ · unattributed attribution
high

CVE-2021-25297: Nagios XI OS Command Injection

Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server. Required action: Apply updates per vendor instructions.

CVE-2021-25297EPSS 56.4%NagiosNagios XI
CISA KEV ↗ · unattributed attribution
high

CVE-2021-25298: Nagios XI OS Command Injection

Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server. Required action: Apply updates per vendor instructions.

CVE-2021-25298EPSS 75.0%NagiosNagios XI
CISA KEV ↗ · unattributed attribution
high

CVE-2021-40870: Aviatrix Controller Unrestricted Upload of File

Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal. Required action: Apply updates per vendor instructions.

CVE-2021-40870EPSS 93.0%AviatrixAviatrix Controller
CISA KEV ↗ · unattributed attribution
high

CVE-2021-33766: Microsoft Exchange Server Information Disclosure

Microsoft Exchange Server contains an information disclosure vulnerability which can allow an unauthenticated attacker to steal email traffic from target. Required action: Apply updates per vendor instructions.

CVE-2021-33766EPSS 97.5%Exchange ServerMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2021-21975: VMware Server Side Request Forgery in vRealize Operations Manager API

Server Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API to perform a SSRF attack to steal administrative credentials. Required action: Apply updates per vendor instructions.

CVE-2021-21975EPSS 78.3%VMwarevRealize Operations Manager API
CISA KEV ↗ · unattributed attribution
high

CVE-2021-21315: System Information Library for Node.JS Command Injection

In this vulnerability, an attacker can send a malicious payload that will exploit the name parameter. After successful exploitation, attackers can execute remote. Required action: Apply updates per vendor instructions.

CVE-2021-21315EPSS 90.2%Npm packageSystem Information Library for Node.JS
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2020-11978: Apache Airflow Command Injection

A remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow. Required action: Apply updates per vendor instructions.

CVE-2020-11978EPSS 99.1%AirflowApache
CISA KEV ↗ · unattributed attribution
high

CVE-2021-36260: Hikvision Improper Input Validation

A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation. Required action: Apply updates per vendor instructions.

CVE-2021-36260EPSS 99.9%HikvisionSecurity cameras web server
CISA KEV ↗ · unattributed attribution
high

CVE-2019-2725: Oracle WebLogic Server, Injection

Injection vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Required action: Apply updates per vendor instructions.

CVE-2019-2725EPSS 100.0%OracleWebLogic Server
CISA KEV ↗ · unattributed attribution
high

CVE-2021-27860: FatPipe WARP, IPVPN, and MPVPN Configuration Upload exploit

A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software allows a remote, unauthenticated attacker to upload a file to any location on the filesystem. Required action: Apply updates per vendor instructions.

CVE-2021-27860EPSS 39.8%FatPipeWARP, IPVPN, and MPVPN software
CISA KEV ↗ · unattributed attribution
high

CVE-2021-4102: Google Chromium V8 Use-After-Free Vulnerability

Google Chromium V8 Engine contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2021-4102EPSS 7.8%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2021-44168: Fortinet FortiOS Arbitrary File Download

Fortinet FortiOS "execute restore src-vis" downloads code without integrity checking, allowing an attacker to arbitrarily download files. Required action: Apply updates per vendor instructions.

CVE-2021-44168EPSS 0.9%FortiOSFortinet
CISA KEV ↗ · unattributed attribution
high

CVE-2010-1871: Red Hat Linux JBoss Seam 2 Remote Code Execution Vulnerability

JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, allows attackers to perform remote code execution. This vulnerability can only be exploited when the Java Security Manager is not properly configured. Required action: Apply updates per vendor instructions.

CVE-2010-1871EPSS 83.4%JBoss Seam 2Red Hat
CISA KEV ↗ · unattributed attribution
high

CVE-2020-17463: Fuel CMS SQL Injection Vulnerability

FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items. Required action: Apply updates per vendor instructions.

CVE-2020-17463EPSS 90.0%Fuel CMS
CISA KEV ↗ · unattributed attribution
high

CVE-2021-44228: Apache Log4j2 Remote Code Execution Vulnerability

Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution. Required action: For all affected software assets for which updates exist, the only acceptable remediation actions are: 1) Apply updates; OR 2) remove affected assets from agency networks. Temporary mitigations using one of the measures provided at https://www.cisa.gov/uscert/ed-22-02-apache-log4j-recommended-mitigation-measures are only acceptable until updates are available.

CVE-2021-44228EPSS 100.0%ApacheLog4j2
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2020-11261: Qualcomm Multiple Chipsets Improper Input Validation Vulnerability

Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables Required action: Apply updates per vendor instructions.

CVE-2020-11261EPSS 1.8%QualcommSnapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
CISA KEV ↗ · unattributed attribution
high

CVE-2018-14847: MikroTik Router OS Directory Traversal Vulnerability

MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface. Required action: Apply updates per vendor instructions.

CVE-2018-14847EPSS 96.1%MikroTikRouterOS
CISA KEV ↗ · unattributed attribution
high

CVE-2021-40438: Apache HTTP Server-Side Request Forgery (SSRF)

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. Required action: Apply updates per vendor instructions.

CVE-2021-40438EPSS 100.0%Apache
CISA KEV ↗ · unattributed attribution
high

CVE-2021-22204: ExifTool Remote Code Execution Vulnerability

Improper neutralization of user data in the DjVu file format in Exiftool versions 7.44 and up allows arbitrary code execution when parsing the malicious image Required action: Apply updates per vendor instructions.

CVE-2021-22204EPSS 100.0%ExiftoolPerl
CISA KEV ↗ · unattributed attribution
high

CVE-2021-28550: Adobe Acrobat and Reader Use-After-Free Vulnerability

Adobe Acrobat and Reader contains a use-after-free vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user. Required action: Apply updates per vendor instructions.

CVE-2021-28550EPSS 52.0%Acrobat and ReaderAdobe
CISA KEV ↗ · unattributed attribution
high

CVE-2019-2215: Android Kernel Use-After-Free Vulnerability

Android Kernel contains a use-after-free vulnerability in binder.c that allows for privilege escalation from an application to the Linux Kernel. This vulnerability was observed chained with CVE-2020-0041 and CVE-2020-0069 under exploit chain "AbstractEmu." Required action: Apply updates per vendor instructions.

CVE-2019-2215CVE-2020-0041EPSS 72.1%AndroidAndroid Kernel
CISA KEV ↗ · unattributed attribution
high

CVE-2020-0041: Android Kernel Out-of-Bounds Write Vulnerability

Android Kernel binder_transaction of binder.c contains an out-of-bounds write vulnerability due to an incorrect bounds check that could allow for local privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0069 under exploit chain "AbstractEmu." Required action: Apply updates per vendor instructions.

CVE-2019-2215CVE-2020-0041EPSS 72.1%AndroidAndroid Kernel
CISA KEV ↗ · unattributed attribution
high

CVE-2020-0069: Mediatek Multiple Chipsets Insufficient Input Validation Vulnerability

Multiple MediaTek chipsets contain an insufficient input validation vulnerability and have missing SELinux restrictions in the Command Queue drivers ioctl handlers. This causes an out-of-bounds write leading to privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0041 under exploit chain "AbstractEmu." Required action: Apply updates per vendor instructions.

CVE-2019-2215CVE-2020-0041EPSS 72.1%MediaTekMultiple Chipsets
CISA KEV ↗ · unattributed attribution
high

CVE-2021-42013: Apache HTTP Server Path Traversal Vulnerability

Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default require all denied or if CGI scripts are enabled. This CVE ID resolves an incomplete patch for CVE-2021-41773. Required action: Apply updates per vendor instructions.

CVE-2021-41773CVE-2021-42013EPSS 100.0%ApacheHTTP Server
CISA KEV ↗ · unattributed attribution
high

CVE-2021-41773: Apache HTTP Server Path Traversal Vulnerability

Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default �require all denied� or if CGI scripts are enabled. The original patch issued under this CVE ID is insufficient, please review remediation information under CVE-2021-42013. Required action: Apply updates per vendor instructions.

CVE-2021-41773CVE-2021-42013EPSS 100.0%ApacheHTTP Server
CISA KEV ↗ · unattributed attribution
high

CVE-2019-0211: Apache HTTP Server Privilege Escalation Vulnerability

Apache HTTP Server, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute code with the privileges of the parent process (usually root) by manipulating the scoreboard. Required action: Apply updates per vendor instructions.

CVE-2019-0211EPSS 65.0%ApacheHTTP Server
CISA KEV ↗ · unattributed attribution
high

CVE-2016-4437: Apache Shiro Code Execution Vulnerability

Apache Shiro contains a vulnerability which may allow remote attackers to execute code or bypass intended access restrictions via an unspecified request parameter when a cipher key has not been configured for the "remember me" feature. Required action: Apply updates per vendor instructions.

CVE-2016-4437EPSS 93.0%ApacheShiro
CISA KEV ↗ · unattributed attribution
high

CVE-2018-11776: Apache Struts Remote Code Execution Vulnerability

Apache Struts contains a vulnerability that allows for remote code execution under two circumstances. One, where the alwaysSelectFullNamespace option is true and the value isn't set for a result defined in underlying configurations and in same time, its upper package configuration have no or wildcard namespace. Or, using URL tag which doesn't have value and action set and in same time, its upper package configuration have no or wildcard namespace. Required action: Apply updates per vendor instructions.

CVE-2018-11776EPSS 100.0%ApacheStruts
CISA KEV ↗ · unattributed attribution
high

CVE-2021-30858: Apple iOS, iPadOS, macOS Use-After-Free Vulnerability

Apple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Required action: Apply updates per vendor instructions.

CVE-2021-30858EPSS 13.5%AppleiOS, iPadOS, and macOS
CISA KEV ↗ · unattributed attribution
high

CVE-2019-6223: Apple iOS and macOS Group Facetime Vulnerability

Apple iOS and macOS Group FaceTime contains an unspecified vulnerability where the call initiator can cause the recipient's Apple device to answer unknowingly or without user interaction. Required action: Apply updates per vendor instructions.

CVE-2019-6223EPSS 2.6%AppleiOS and macOS
CISA KEV ↗ · unattributed attribution
high

CVE-2021-30860: Apple Multiple Products Integer Overflow Vulnerability

Apple iOS, iPadOS, macOS, and watchOS CoreGraphics contain an integer overflow vulnerability which may allow code execution when processing a maliciously crafted PDF. The vulnerability is also known under the moniker of FORCEDENTRY. Required action: Apply updates per vendor instructions.

CVE-2021-30860EPSS 76.0%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2021-30762: Apple iOS WebKit Use-After-Free Vulnerability

Apple iOS WebKit contains a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Required action: Apply updates per vendor instructions.

CVE-2021-30762EPSS 11.0%AppleiOS
CISA KEV ↗ · unattributed attribution
high

CVE-2021-1870: Apple iOS, iPadOS, and macOS WebKit Remote Code Execution Vulnerability

Apple iOS, iPadOS, and macOS WebKit contain an unspecified logic vulnerability that allows a remote attacker to execute code. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Required action: Apply updates per vendor instructions.

CVE-2021-1870EPSS 7.9%AppleiOS, iPadOS, and macOS
CISA KEV ↗ · unattributed attribution
high

CVE-2021-1871: Apple iOS, iPadOS, and macOS WebKit Remote Code Execution Vulnerability

Apple iOS, iPadOS, and macOS WebKit contain an unspecified logic vulnerability that allows a remote attacker to execute code. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Required action: Apply updates per vendor instructions.

CVE-2021-1871EPSS 7.1%AppleiOS, iPadOS, and macOS
CISA KEV ↗ · unattributed attribution
high

CVE-2021-1879: Apple iOS, iPadOS, and watchOS WebKit Cross-Site Scripting (XSS) Vulnerability

Apple iOS, iPadOS, and watchOS WebKit contain an unspecified vulnerability that allows for universal cross-site scripting (XSS) when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Required action: Apply updates per vendor instructions.

CVE-2021-1879EPSS 7.1%AppleiOS, iPadOS, and watchOS
CISA KEV ↗ · unattributed attribution
high

CVE-2021-30661: Apple Multiple Products WebKit Storage Use-After-Free Vulnerability

Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit Storage contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Required action: Apply updates per vendor instructions.

CVE-2021-30661EPSS 4.5%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2021-30666: Apple iOS WebKit Buffer Overflow Vulnerability

Apple iOS WebKit contains a buffer-overflow vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Required action: Apply updates per vendor instructions.

CVE-2021-30666EPSS 3.0%AppleiOS
CISA KEV ↗ · unattributed attribution
high

CVE-2021-30713: Apple macOS Unspecified Vulnerability

Apple macOS Transparency, Consent, and Control (TCC) contains an unspecified permissions issue which may allow a malicious application to bypass privacy preferences. Required action: Apply updates per vendor instructions.

CVE-2021-30713EPSS 6.6%ApplemacOS
CISA KEV ↗ · unattributed attribution
high

CVE-2021-30657: Apple macOS Unspecified Vulnerability

Apple macOS contains an unspecified logic issue in System Preferences that may allow a malicious application to bypass Gatekeeper checks. Required action: Apply updates per vendor instructions.

CVE-2021-30657EPSS 68.5%ApplemacOS
CISA KEV ↗ · unattributed attribution
high

CVE-2021-30665: Apple Multiple Products WebKit Memory Corruption Vulnerability

Apple iOS, iPadOS, macOS, watchOS, and tvOS WebKit contain a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Required action: Apply updates per vendor instructions.

CVE-2021-30665EPSS 3.7%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2021-30663: Apple Multiple Products WebKit Integer Overflow Vulnerability

Apple iOS, iPadOS, macOS, tvOS, and Safari WebKit contain an integer overflow vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Required action: Apply updates per vendor instructions.

CVE-2021-30663EPSS 3.7%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2021-30761: Apple iOS WebKit Memory Corruption Vulnerability

Apple iOS WebKit contains a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Required action: Apply updates per vendor instructions.

CVE-2021-30761EPSS 10.6%AppleiOS
CISA KEV ↗ · unattributed attribution
high

CVE-2021-20090: Arcadyan Buffalo Firmware Path Traversal Vulnerability

Arcadyan Buffalo firmware contains a path traversal vulnerability that could allow unauthenticated, remote attackers to bypass authentication and access sensitive information. This vulnerability affects multiple routers across several different vendors. Required action: Apply updates per vendor instructions.

CVE-2021-20090EPSS 100.0%ArcadyanBuffalo Firmware
CISA KEV ↗ · unattributed attribution
high

CVE-2021-27562: Arm Trusted Firmware Out-of-Bounds Write Vulnerability

Arm Trusted Firmware contains an out-of-bounds write vulnerability allowing the non-secure (NS) world to trigger a system halt, overwrite secure data, or print out secure data when calling secure functions under the non-secure processing environment (NSPE) handler mode. This vulnerability affects Yealink Device Management servers. Required action: Apply updates per vendor instructions.

CVE-2021-27562EPSS 3.1%ArmTrusted Firmware
CISA KEV ↗ · unattributed attribution
high

CVE-2021-28664: Arm Mali Graphics Processing Unit (GPU) Unspecified Vulnerability

Arm Mali Graphics Processing Unit (GPU) kernel driver contains an unspecified vulnerability that may allow a non-privileged user to gain write access to read-only memory, gain root privilege, corrupt memory, and modify the memory of other processes. Required action: Apply updates per vendor instructions.

CVE-2021-28664EPSS 5.5%ArmMali Graphics Processing Unit (GPU)
CISA KEV ↗ · unattributed attribution
high

CVE-2021-28663: Arm Mali Graphics Processing Unit (GPU) Use-After-Free Vulnerability

Arm Mali Graphics Processing Unit (GPU) kernel driver contains a use-after-free vulnerability that may allow a non-privileged user to make improper operations on GPU memory to gain root privilege, and/or disclose information. Required action: Apply updates per vendor instructions.

CVE-2021-28663EPSS 12.1%ArmMali Graphics Processing Unit (GPU)
CISA KEV ↗ · unattributed attribution
high

CVE-2019-3398: Atlassian Confluence Server and Data Center Path Traversal Vulnerability

Atlassian Confluence Server and Data Center contain a path traversal vulnerability in the downloadallattachments resource that may allow a privileged, remote attacker to write files. Exploitation can lead to remote code execution. Required action: Apply updates per vendor instructions.

CVE-2019-3398EPSS 97.2%AtlassianConfluence Server and Data Center
CISA KEV ↗ · unattributed attribution
high

CVE-2020-3452: Cisco ASA and FTD Read-Only Path Traversal Vulnerability

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an improper input validation vulnerability when HTTP requests process URLs. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences to an affected device. A successful exploit could allow the attacker to view arbitrary files within the web services file system on the targeted device. Required action: Apply updates per vendor instructions.

CVE-2020-3452EPSS 100.0%Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)Cisco
CISA KEV ↗ · unattributed attribution
high

CVE-2020-3580: Cisco ASA and FTD Cross-Site Scripting (XSS) Vulnerability

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an insufficient input validation vulnerability for user-supplied input by the web services interface. Successful exploitation could allow an attacker to perform cross-site scripting (XSS) in the context of the interface or access sensitive browser-based information. Required action: Apply updates per vendor instructions.

CVE-2020-3580EPSS 85.4%Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)Cisco
CISA KEV ↗ · unattributed attribution
high

CVE-2020-3118: Cisco IOS XR Software Discovery Protocol Format String Vulnerability

Cisco IOS XR improperly validates string input from certain fields in Cisco Discovery Protocol messages. Exploitation could allow an unauthenticated, adjacent attacker to execute code with administrative privileges or cause a reload on an affected device. Required action: Apply updates per vendor instructions.

CVE-2020-3118EPSS 11.7%CiscoIOS XR
CISA KEV ↗ · unattributed attribution
high

CVE-2020-3566: Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability

Cisco IOS XR Distance Vector Multicast Routing Protocol (DVMRP) incorrectly handles Internet Group Management Protocol (IGMP) packets. Exploitation could allow an unauthenticated, remote attacker to immediately crash the IGMP process or make it consume available memory and eventually crash. Required action: Apply updates per vendor instructions.

CVE-2020-3566EPSS 3.6%CiscoIOS XR
CISA KEV ↗ · unattributed attribution
high

CVE-2020-3569: Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability

Cisco IOS XR Distance Vector Multicast Routing Protocol (DVMRP) incorrectly handles Internet Group Management Protocol (IGMP) packets. Exploitation could allow an unauthenticated, remote attacker to immediately crash the IGMP process or make it consume available memory and eventually crash. Required action: Apply updates per vendor instructions.

CVE-2020-3569EPSS 3.3%CiscoIOS XR
CISA KEV ↗ · unattributed attribution
high

CVE-2020-8193: Citrix ADC, Gateway, and SD-WAN WANOP Appliance Authorization Bypass Vulnerability

Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an authorization bypass vulnerability that may allow unauthenticated access to certain URL endpoints. The attacker must have access to the NetScaler IP (NSIP) in order to perform exploitation. Required action: Apply updates per vendor instructions.

CVE-2020-8193EPSS 88.4%Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP ApplianceCitrix
CISA KEV ↗ · unattributed attribution
high

CVE-2019-19781: Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution Vulnerability

Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an unspecified vulnerability that could allow an unauthenticated attacker to perform code execution. Required action: Apply updates per vendor instructions.

CVE-2019-19781EPSS 100.0%Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP ApplianceCitrix
CISA KEV ↗ · unattributed attribution
high

CVE-2018-18325: DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability

DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters. This CVE ID resolves an incomplete patch for CVE-2018-15811. Required action: Apply updates per vendor instructions.

CVE-2018-15811CVE-2018-18325EPSS 74.0%DotNetNuke (DNN)
CISA KEV ↗ · unattributed attribution
high

CVE-2019-15752: Docker Desktop Community Edition Privilege Escalation Vulnerability

Docker Desktop Community Edition contains a vulnerability that may allow local users to escalate privileges by placing a trojan horse docker-credential-wincred.exe file in %PROGRAMDATA%\DockerDesktop\version-bin\. Required action: Apply updates per vendor instructions.

CVE-2019-15752EPSS 29.6%Desktop Community EditionDocker
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2018-7600: Drupal Core Remote Code Execution Vulnerability

Drupal Core contains a remote code execution vulnerability that could allow an attacker to exploit multiple attack vectors on a Drupal site, resulting in complete site compromise. Required action: Apply updates per vendor instructions.

CVE-2018-7600EPSS 100.0%DrupalDrupal Core
CISA KEV ↗ · unattributed attribution
high

CVE-2021-22205: GitLab Community and Enterprise Editions Remote Code Execution Vulnerability

GitHub Community and Enterprise Editions that utilize the ability to upload images through GitLab Workhorse are vulnerable to remote code execution. Workhorse passes image file extensions through ExifTool, which improperly validates the image files. Required action: Apply updates per vendor instructions.

CVE-2021-22205EPSS 99.7%Community and Enterprise EditionsGitLab
CISA KEV ↗ · unattributed attribution
high

CVE-2018-6789: Exim Buffer Overflow Vulnerability

Exim contains a buffer overflow vulnerability in the base64d function part of the SMTP listener that may allow for remote code execution. Required action: Apply updates per vendor instructions.

CVE-2018-6789EPSS 82.2%Exim
CISA KEV ↗ · unattributed attribution
high

CVE-2021-22986: F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution Vulnerability

F5 BIG-IP and BIG-IQ Centralized Management contain a remote code execution vulnerability in the iControl REST interface that allows unauthenticated attackers with network access to execute system commands, create or delete files, and disable services. Required action: Apply updates per vendor instructions.

CVE-2021-22986EPSS 99.9%BIG-IP and BIG-IQ Centralized ManagementF5
CISA KEV ↗ · unattributed attribution
high

CVE-2021-35464: ForgeRock Access Management (AM) Core Server Remote Code Execution Vulnerability

ForgeRock Access Management (AM) Core Server allows an attacker who sends a specially crafted HTTP request to one of three endpoints (/ccversion/Version, /ccversion/Masthead, or /ccversion/ButtonFrame) to execute code in the context of the current user (unless ForgeRock AM is running as root user, which the vendor does not recommend). Required action: Apply updates per vendor instructions.

CVE-2021-35464EPSS 100.0%Access Management (AM)ForgeRock
CISA KEV ↗ · unattributed attribution
high

CVE-2019-5591: Fortinet FortiOS Default Configuration Vulnerability

Fortinet FortiOS contains a default configuration vulnerability that may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the Lightweight Directory Access Protocol (LDAP) server. Required action: Apply updates per vendor instructions.

CVE-2019-5591EPSS 18.6%FortiOSFortinet
CISA KEV ↗ · unattributed attribution
high

CVE-2020-12812: Fortinet FortiOS SSL VPN Improper Authentication Vulnerability

Fortinet FortiOS SSL VPN contains an improper authentication vulnerability that may allow a user to login successfully without being prompted for the second factor of authentication (FortiToken) if they change the case in their username. Required action: Apply updates per vendor instructions.

CVE-2020-12812EPSS 49.3%FortiOSFortinet
CISA KEV ↗ · unattributed attribution
high

CVE-2018-13379: Fortinet FortiOS SSL VPN Path Traversal Vulnerability

Fortinet FortiOS SSL VPN web portal contains a path traversal vulnerability that may allow an unauthenticated attacker to download FortiOS system files through specially crafted HTTP resource requests. Required action: Apply updates per vendor instructions.

CVE-2018-13379EPSS 100.0%FortiOSFortinet
CISA KEV ↗ · unattributed attribution
high

CVE-2020-16010: Google Chrome for Android UI Heap Buffer Overflow Vulnerability

Google Chrome for Android UI contains a heap buffer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. Required action: Apply updates per vendor instructions.

CVE-2020-16010EPSS 6.4%Chrome for Android UIGoogle
CISA KEV ↗ · unattributed attribution
high

CVE-2020-15999: Google Chrome FreeType Heap Buffer Overflow Vulnerability

Google Chrome uses FreeType, an open-source software library to render fonts, which contains a heap buffer overflow vulnerability in the function Load_SBit_Png when processing PNG images embedded into fonts. This vulnerability is part of an exploit chain with CVE-2020-17087 on Windows and CVE-2020-16010 on Android. Required action: Apply updates per vendor instructions.

CVE-2020-15999CVE-2020-16010EPSS 50.6%Chrome FreeTypeGoogle
CISA KEV ↗ · unattributed attribution
high

CVE-2021-21166: Google Chromium Race Condition Vulnerability

Google Chromium contains a race condition vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2021-21166EPSS 26.5%ChromiumGoogle
CISA KEV ↗ · unattributed attribution
high

CVE-2020-16017: Google Chrome Use-After-Free Vulnerability

Google Chrome contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. Required action: Apply updates per vendor instructions.

CVE-2020-16017EPSS 2.7%ChromeGoogle
CISA KEV ↗ · unattributed attribution
high

CVE-2021-37976: Google Chromium Information Disclosure Vulnerability

Google Chromium contains an information disclosure vulnerability within the core memory component that allows a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2021-37976EPSS 19.9%ChromiumGoogle
CISA KEV ↗ · unattributed attribution
high

CVE-2020-16009: Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2020-16009EPSS 48.6%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2021-30632: Google Chromium V8 Out-of-Bounds Write Vulnerability

Google Chromium V8 Engine contains an out-of-bounds write vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2021-30632EPSS 64.5%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2020-16013: Google Chromium V8 Incorrect Implementation Vulnerabililty

Google Chromium V8 Engine contains an inappropriate implementation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2020-16013EPSS 2.8%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2021-30633: Google Chromium Indexed DB API Use-After-Free Vulnerability

Google Chromium Indexed DB API contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2021-30633EPSS 32.7%Chromium Indexed DB APIGoogle
CISA KEV ↗ · unattributed attribution
high

CVE-2021-21148: Google Chromium V8 Heap Buffer Overflow Vulnerability

Google Chromium V8 Engine contains a heap buffer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2021-21148EPSS 19.8%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2021-37973: Google Chromium Portals Use-After-Free Vulnerability

Google Chromium Portals contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability affects web browsers that utilize Chromium, including Google Chrome and Microsoft Edge. Required action: Apply updates per vendor instructions.

CVE-2021-37973EPSS 11.7%Chromium PortalsGoogle
CISA KEV ↗ · unattributed attribution
high

CVE-2021-30551: Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2021-30551EPSS 64.7%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2021-37975: Google Chromium V8 Use-After-Free Vulnerability

Google Chromium V8 Engine contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2021-37975EPSS 34.9%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2020-6418: Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 Engine contains a type confusion vulnerability allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2020-6418EPSS 78.8%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2021-30554: Google Chromium WebGL Use-After-Free Vulnerability

Google Chromium WebGL contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2021-30554EPSS 7.4%Chromium WebGLGoogle
CISA KEV ↗ · unattributed attribution
high

CVE-2021-21206: Google Chromium Blink Use-After-Free Vulnerability

Google Chromium Blink contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2021-21206EPSS 9.4%Chromium BlinkGoogle
CISA KEV ↗ · unattributed attribution
high

CVE-2021-38000: Google Chromium Intents Improper Input Validation Vulnerability

Google Chromium Intents contains an improper input validation vulnerability that allows a remote attacker to arbitrarily browser to a malicious URL via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2021-38000EPSS 4.5%Chromium IntentsGoogle
CISA KEV ↗ · unattributed attribution
high

CVE-2021-38003: Google Chromium V8 Memory Corruption Vulnerability

Google Chromium V8 Engine has a bug in JSON.stringify, where the internal TheHole value can leak to script code, causing memory corruption. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2021-38003EPSS 36.2%Chromium V8Google
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2021-21224: Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2021-21224EPSS 57.7%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2021-21193: Google Chromium Blink Use-After-Free Vulnerability

Google Chromium Blink contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2021-21193EPSS 9.9%Chromium BlinkGoogle
CISA KEV ↗ · unattributed attribution
high

CVE-2021-21220: Google Chromium V8 Improper Input Validation Vulnerability

Google Chromium V8 Engine contains an improper input validation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2021-21220EPSS 70.4%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2021-30563: Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2021-30563EPSS 8.9%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2020-4430: IBM Data Risk Manager Directory Traversal Vulnerability

IBM Data Risk Manager contains a directory traversal vulnerability that could allow a remote authenticated attacker to traverse directories and send a specially crafted URL request to download arbitrary files from the system. Required action: Apply updates per vendor instructions.

CVE-2020-4430EPSS 68.5%Data Risk ManagerIBM
CISA KEV ↗ · unattributed attribution
high

CVE-2020-4427: IBM Data Risk Manager Security Bypass Vulnerability

IBM Data Risk Manager contains a security bypass vulnerability that could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sending a specially crafted HTTP request, an attacker could exploit this vulnerability to bypass the authentication process and gain full administrative access to the system. Required action: Apply updates per vendor instructions.

CVE-2020-4427EPSS 70.0%Data Risk ManagerIBM
CISA KEV ↗ · unattributed attribution
high

CVE-2016-3715: ImageMagick Arbitrary File Deletion Vulnerability

ImageMagick contains an unspecified vulnerability that could allow users to delete files by using ImageMagick's 'ephemeral' pseudo protocol, which deletes files after reading. Required action: Apply updates per vendor instructions.

CVE-2016-3715EPSS 75.4%ImageMagick
CISA KEV ↗ · unattributed attribution
high

CVE-2014-1812: Microsoft Windows Group Policy Preferences Password Privilege Escalation Vulnerability

Microsoft Windows Active Directory contains a privilege escalation vulnerability due to the way it distributes passwords that are configured using Group Policy preferences. An authenticated attacker who successfully exploits the vulnerability could decrypt the passwords and use them to elevate privileges on the domain. Required action: Apply updates per vendor instructions.

CVE-2014-1812EPSS 65.1%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2020-0938: Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability

Microsoft Windows Adobe Font Manager Library contains an unspecified vulnerability when handling specially crafted multi-master fonts (Adobe Type 1 PostScript format) that allows for remote code execution for all systems except Windows 10. For systems running Windows 10, an attacker who successfully exploited the vulnerability could execute code in an AppContainer sandbox context with limited privileges and capabilities. Required action: Apply updates per vendor instructions.

CVE-2020-0938EPSS 69.2%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2020-1020: Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability

Microsoft Windows Adobe Font Manager Library contains an unspecified vulnerability when handling specially crafted multi-master fonts (Adobe Type 1 PostScript format) that allows for remote code execution for all systems except Windows 10. For systems running Windows 10, an attacker who successfully exploited the vulnerability could execute code in an AppContainer sandbox context with limited privileges and capabilities. Required action: Apply updates per vendor instructions.

CVE-2020-1020EPSS 65.0%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2017-7269: Microsoft Windows Server Buffer Overflow Vulnerability

Microsoft Windows Server 2003 R2 contains a buffer overflow vulnerability in Internet Information Services (IIS) 6.0 which allows remote attackers to execute code via a long header beginning with "If: <http://" in a PROPFIND request. Required action: Apply updates per vendor instructions.

CVE-2017-7269EPSS 99.8%Internet Information Services (IIS)Microsoft
CISA KEV ↗ · unattributed attribution
high

CVE-2016-7255: Microsoft Win32k Privilege Escalation Vulnerability

Microsoft Win32k kernel-mode driver fails to properly handle objects in memory which allows for privilege escalation. Successful exploitation allows an attacker to run code in kernel mode. Required action: Apply updates per vendor instructions.

CVE-2016-7255EPSS 81.0%MicrosoftWin32k
CISA KEV ↗ · unattributed attribution
high

CVE-2019-0708: Microsoft Remote Desktop Services Remote Code Execution Vulnerability

Microsoft Remote Desktop Services, formerly known as Terminal Service, contains an unspecified vulnerability that allows an unauthenticated attacker to connect to the target system using RDP and send specially crafted requests. Successful exploitation allows for remote code execution. The vulnerability is also known under the moniker of BlueKeep. Required action: Apply updates per vendor instructions.

CVE-2019-0708EPSS 100.0%MicrosoftRemote Desktop Services
CISA KEV ↗ · unattributed attribution
high

CVE-2020-1464: Microsoft Windows Spoofing Vulnerability

Microsoft Windows contains a spoofing vulnerability when Windows incorrectly validates file signatures, allowing an attacker to bypass security features and load improperly signed files. Required action: Apply updates per vendor instructions.

CVE-2020-1464EPSS 41.1%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2021-34527: Microsoft Windows Print Spooler Remote Code Execution Vulnerability

Microsoft Windows Print Spooler contains an unspecified vulnerability due to the Windows Print Spooler service improperly performing privileged file operations. Successful exploitation allows an attacker to perform remote code execution with SYSTEM privileges. The vulnerability is also known under the moniker of PrintNightmare. Required action: Apply updates per vendor instructions.

CVE-2021-34527EPSS 99.8%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2019-0803: Microsoft Win32k Privilege Escalation Vulnerability

Microsoft Win32k contains an unspecified vulnerability due to it failing to properly handle objects in memory causing privilege escalation. Successful exploitation allows an attacker to run code in kernel mode. Required action: Apply updates per vendor instructions.

CVE-2019-0803EPSS 45.2%MicrosoftWin32k
CISA KEV ↗ · unattributed attribution
high

CVE-2020-1040: Microsoft Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability

Microsoft Hyper-V RemoteFX vGPU contains an improper input validation vulnerability due to the host server failing to properly validate input from an authenticated user on a guest operating system. Successful exploitation allows for remote code execution on the host operating system. Required action: Apply updates per vendor instructions.

CVE-2020-1040EPSS 6.9%Hyper-V RemoteFXMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2020-1350: Microsoft Windows DNS Server Remote Code Execution Vulnerability

Microsoft Windows DNS Servers fail to properly handle requests, allowing an attacker to perform remote code execution in the context of the Local System Account. The vulnerability is also known under the moniker of SIGRed. Required action: Apply updates per vendor instructions.

CVE-2020-1350EPSS 92.2%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2019-0797: Microsoft Win32k Privilege Escalation Vulnerability

Microsoft Win32k contains a privilege escalation vulnerability when the Win32k component fails to properly handle objects in memory. Successful exploitation allows an attacker to execute code in kernel mode. Required action: Apply updates per vendor instructions.

CVE-2019-0797EPSS 1.9%MicrosoftWin32k
CISA KEV ↗ · unattributed attribution
high

CVE-2019-1215: Microsoft Windows Privilege Escalation Vulnerability

Microsoft Windows contains an unspecified vulnerability due to the way ws2ifsl.sys (Winsock) handles objects in memory, allowing for privilege escalation. Successful exploitation allows an attacker to execute code with elevated privileges. Required action: Apply updates per vendor instructions.

CVE-2019-1215EPSS 19.3%MicrosoftWindows
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2018-0798: Microsoft Office Memory Corruption Vulnerability

Microsoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code execution in the context of the current user. This vulnerability is known to be chained with CVE-2018-0802. Required action: Apply updates per vendor instructions.

CVE-2018-0798CVE-2018-0802EPSS 95.1%MicrosoftOffice
CISA KEV ↗ · unattributed attribution
high

CVE-2018-0802: Microsoft Office Memory Corruption Vulnerability

Microsoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code execution in the context of the current user. This vulnerability is known to be chained with CVE-2018-0798. Required action: Apply updates per vendor instructions.

CVE-2018-0798CVE-2018-0802EPSS 95.1%MicrosoftOffice
CISA KEV ↗ · unattributed attribution
high

CVE-2012-0158: Microsoft MSCOMCTL.OCX Remote Code Execution Vulnerability

Microsoft MSCOMCTL.OCX contains an unspecified vulnerability that allows for remote code execution, allowing an attacker to take complete control of an affected system under the context of the current user. Required action: Apply updates per vendor instructions.

CVE-2012-0158EPSS 100.0%MSCOMCTL.OCXMicrosoft
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2015-1641: Microsoft Office Memory Corruption Vulnerability

Microsoft Office contains a memory corruption vulnerability due to failure to properly handle rich text format files in memory. Successful exploitation allows for remote code execution in the context of the current user. Required action: Apply updates per vendor instructions.

CVE-2015-1641EPSS 96.8%MicrosoftOffice
CISA KEV ↗ · unattributed attribution
high

CVE-2020-1472: Microsoft Netlogon Privilege Escalation Vulnerability

Microsoft's Netlogon Remote Protocol (MS-NRPC) contains a privilege escalation vulnerability when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller. An attacker who successfully exploits the vulnerability could run a specially crafted application on a device on the network. The vulnerability is also known under the moniker of Zerologon. Required action: Apply updates per vendor instructions.

CVE-2020-1472EPSS 99.5%MicrosoftNetlogon
CISA KEV ↗ · unattributed attribution
high

CVE-2020-1054: Microsoft Win32k Privilege Escalation Vulnerability

Microsoft Win32k contains a privilege escalation vulnerability when the Windows kernel-mode driver fails to properly handle objects in memory. Successful exploitation allows an attacker to execute code in kernel mode. Required action: Apply updates per vendor instructions.

CVE-2020-1054EPSS 52.8%MicrosoftWin32k
CISA KEV ↗ · unattributed attribution
high

CVE-2020-0601: Microsoft Windows CryptoAPI Spoofing Vulnerability

Microsoft Windows CryptoAPI (Crypt32.dll) contains a spoofing vulnerability in the way it validates Elliptic Curve Cryptography (ECC) certificates. An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source. A successful exploit could also allow the attacker to conduct man-in-the-middle attacks and decrypt confidential information on user connections to the affected software. The vulnerability is also known under the moniker of CurveBall. Required action: Apply updates per vendor instructions.

CVE-2020-0601EPSS 89.4%MicrosoftWindows
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2019-0604: Microsoft SharePoint Remote Code Execution Vulnerability

Microsoft SharePoint fails to check the source markup of an application package. An attacker who successfully exploits the vulnerability could run remote code in the context of the SharePoint application pool and the SharePoint server farm account. Required action: Apply updates per vendor instructions.

CVE-2019-0604EPSS 99.9%MicrosoftSharePoint
CISA KEV ↗ · unattributed attribution
high

CVE-2019-0808: Microsoft Win32k Privilege Escalation Vulnerability

Microsoft Win32k contains a privilege escalation vulnerability due to the component failing to properly handle objects in memory. Successful exploitation allows an attacker to run code in kernel mode. Required action: Apply updates per vendor instructions.

CVE-2019-0808EPSS 53.3%MicrosoftWin32k
CISA KEV ↗ · unattributed attribution
high

CVE-2020-1147: Microsoft .NET Framework, SharePoint, and Visual Studio Remote Code Execution Vulnerability

Microsoft .NET Framework, Microsoft SharePoint, and Visual Studio contain a remote code execution vulnerability when the software fails to check the source markup of XML file input. Successful exploitation allows an attacker to execute code in the context of the process responsible for deserialization of the XML content. Required action: Apply updates per vendor instructions.

CVE-2020-1147EPSS 94.2%.NET Framework, SharePoint, Visual StudioMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2016-3235: Microsoft Office OLE DLL Side Loading Vulnerability

Microsoft Office Object Linking & Embedding (OLE) dynamic link library (DLL) contains a side loading vulnerability due to it improperly validating input before loading libraries. Successful exploitation allows for remote code execution. Required action: Apply updates per vendor instructions.

CVE-2016-3235EPSS 43.4%MicrosoftOffice
CISA KEV ↗ · unattributed attribution
high

CVE-2020-6819: Mozilla Firefox And Thunderbird Use-After-Free Vulnerability

Mozilla Firefox and Thunderbird contain a race condition vulnerability when running the nsDocShell destructor under certain conditions. The race condition creates a use-after-free vulnerability, causing unspecified impacts. Required action: Apply updates per vendor instructions.

CVE-2020-6819EPSS 3.0%Firefox and ThunderbirdMozilla
CISA KEV ↗ · unattributed attribution
high

CVE-2020-6820: Mozilla Firefox And Thunderbird Use-After-Free Vulnerability

Mozilla Firefox and Thunderbird contain a race condition vulnerability when handling a ReadableStream under certain conditions. The race condition creates a use-after-free vulnerability, causing unspecified impacts. Required action: Apply updates per vendor instructions.

CVE-2020-6820EPSS 6.3%Firefox and ThunderbirdMozilla
CISA KEV ↗ · unattributed attribution
high

CVE-2019-15949: Nagios XI Remote Code Execution Vulnerability

Nagios XI contains a remote code execution vulnerability in which a user can modify the check_plugin executable and insert malicious commands to execute as root. Required action: Apply updates per vendor instructions.

CVE-2019-15949EPSS 77.7%NagiosNagios XI
CISA KEV ↗ · unattributed attribution
high

CVE-2020-2555: Oracle Multiple Products Remote Code Execution Vulnerability

Multiple Oracle products contain a remote code execution vulnerability that allows an unauthenticated attacker with network access via T3 or HTTP to takeover the affected system. Impacted Oracle products: Oracle Coherence in Fusion Middleware, Oracle Utilities Framework, Oracle Retail Assortment Planning, Oracle Commerce, Oracle Communications Diameter Signaling Router (DSR). Required action: Apply updates per vendor instructions.

CVE-2020-2555EPSS 97.1%Multiple ProductsOracle
CISA KEV ↗ · unattributed attribution
high

CVE-2012-3152: Oracle Fusion Middleware Unspecified Vulnerability

Oracle Fusion Middleware Reports Developer contains an unspecified vulnerability that allows remote attackers to affect confidentiality and integrity of affected systems. Required action: Apply updates per vendor instructions.

CVE-2012-3152EPSS 98.7%Fusion MiddlewareOracle
CISA KEV ↗ · unattributed attribution
high

CVE-2020-14750: Oracle WebLogic Server Remote Code Execution Vulnerability

Oracle WebLogic Server contains an unspecified vulnerability allowing an unauthenticated attacker to perform remote code execution. This vulnerability is related to CVE-2020-14882. Required action: Apply updates per vendor instructions.

CVE-2020-14750CVE-2020-14882EPSS 100.0%OracleWebLogic Server
CISA KEV ↗ · unattributed attribution
high

CVE-2020-14883: Oracle WebLogic Server Unspecified Vulnerability

Oracle WebLogic Server contains an unspecified vulnerability in the Console component with high impacts to confidentilaity, integrity, and availability. Required action: Apply updates per vendor instructions.

CVE-2020-14883EPSS 97.9%OracleWebLogic Server
CISA KEV ↗ · unattributed attribution
high

CVE-2020-8243: Ivanti Pulse Connect Secure Code Execution Vulnerability

Ivanti Pulse Connect Secure contains an unspecified vulnerability in the admin web interface that could allow an authenticated attacker to upload a custom template to perform code execution. Required action: Apply updates per vendor instructions.

CVE-2020-8243EPSS 90.8%IvantiPulse Connect Secure
CISA KEV ↗ · unattributed attribution
high

CVE-2021-22900: Ivanti Pulse Connect Secure Unrestricted File Upload Vulnerability

Ivanti Pulse Connect Secure contains an unrestricted file upload vulnerability that allows an authenticated administrator to perform a file write via a maliciously crafted archive upload in the administrator web interface. Required action: Apply updates per vendor instructions.

CVE-2021-22900EPSS 14.1%IvantiPulse Connect Secure
CISA KEV ↗ · unattributed attribution
high

CVE-2020-10221: rConfig OS Command Injection Vulnerability

rConfig lib/ajaxHandlers/ajaxAddTemplate.php contains an OS command injection vulnerability that allows remote attackers to execute OS commands via shell metacharacters in the fileName POST parameter. Required action: Apply updates per vendor instructions.

CVE-2020-10221EPSS 36.8%rConfig
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2021-35395: Realtek AP-Router SDK Buffer Overflow Vulnerability

Realtek AP-Router SDK HTTP web server boa contains a buffer overflow vulnerability due to unsafe copies of some overly long parameters submitted in the form that lead to denial-of-service (DoS). Required action: Apply updates per vendor instructions.

CVE-2021-35395EPSS 98.0%AP-Router SDKRealtek
CISA KEV ↗ · unattributed attribution
high

CVE-2017-16651: Roundcube Webmail File Disclosure Vulnerability

Roundcube Webmail contains a file disclosure vulnerability caused by insufficient input validation in conjunction with file-based attachment plugins, which are used by default. Required action: Apply updates per vendor instructions.

CVE-2017-16651EPSS 36.9%RoundcubeRoundcube Webmail
CISA KEV ↗ · unattributed attribution
high

CVE-2020-11652: SaltStack Salt Path Traversal Vulnerability

SaltStack Salt contains a path traversal vulnerability in the salt-master process ClearFuncs which allows directory access to authenticated users. Salt users who follow fundamental internet security guidelines and best practices are not affected by this vulnerability. Required action: Apply updates per vendor instructions.

CVE-2020-11652EPSS 86.1%SaltSaltStack
CISA KEV ↗ · unattributed attribution
high

CVE-2020-11651: SaltStack Salt Authentication Bypass Vulnerability

SaltStack Salt contains an authentication bypass vulnerability in the salt-master process ClearFuncs due to improperly validating method calls. The vulnerability allows a remote user to access some methods without authentication, which can be used to retrieve user tokens from the salt master and/or run commands on salt minions. Salt users who follow fundamental internet security guidelines and best practices are not affected by this vulnerability. Required action: Apply updates per vendor instructions.

CVE-2020-11651EPSS 96.4%SaltSaltStack
CISA KEV ↗ · unattributed attribution
high

CVE-2020-16846: SaltStack Salt Shell Injection Vulnerability

SaltStack Salt allows an unauthenticated user with network access to the Salt API to use shell injections to run code on the Salt API using the SSH client. This vulnerability affects any users running the Salt API. Required action: Apply updates per vendor instructions.

CVE-2020-16846EPSS 99.6%SaltSaltStack
CISA KEV ↗ · unattributed attribution
high

CVE-2016-9563: SAP NetWeaver XML External Entity (XXE) Vulnerability

SAP NetWeaver Application Server Java Platforms contains an unspecified vulnerability in BC-BMT-BPM-DSK which allows remote, authenticated users to conduct XML External Entity (XXE) attacks. Required action: Apply updates per vendor instructions.

CVE-2016-9563EPSS 23.8%NetWeaverSAP
CISA KEV ↗ · unattributed attribution
high

CVE-2016-3976: SAP NetWeaver Directory Traversal Vulnerability

SAP NetWeaver Application Server Java Platforms contains a directory traversal vulnerability via a ..\ (dot dot backslash) in the fileName parameter to CrashFileDownloadServlet. This allows remote attackers to read files. Required action: Apply updates per vendor instructions.

CVE-2016-3976EPSS 46.6%NetWeaverSAP
CISA KEV ↗ · unattributed attribution
high

CVE-2019-16256: SIMalliance Toolbox Browser Command Injection Vulnerability

SIMalliance Toolbox Browser contains an command injection vulnerability that could allow remote attackers to retrieve location and IMEI information or execute a range of other attacks by modifying the attack message. Required action: Apply updates per vendor instructions.

CVE-2019-16256EPSS 4.9%SIMallianceToolbox Browser
CISA KEV ↗ · unattributed attribution
high

CVE-2021-20021: SonicWall Email Security Improper Privilege Management Vulnerability

SonicWall Email Security contains an improper privilege management vulnerability that allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20022 and CVE-2021-20023 to achieve privilege escalation. Required action: Apply updates per vendor instructions.

CVE-2021-20021CVE-2021-20022EPSS 83.4%SonicWallSonicWall Email Security
CISA KEV ↗ · unattributed attribution
high

CVE-2019-7481: SonicWall SMA100 SQL Injection Vulnerability

SonicWall SMA100 contains a SQL injection vulnerability allowing an unauthenticated user to gain read-only access to unauthorized resources. Required action: Apply updates per vendor instructions.

CVE-2019-7481EPSS 99.9%SMA100SonicWall
CISA KEV ↗ · unattributed attribution
high

CVE-2021-20022: SonicWall Email Security Unrestricted Upload of File Vulnerability

SonicWall Email Security contains an unrestricted upload of file with dangerous type vulnerability that allows a post-authenticated attacker to upload a file to the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20023 to achieve privilege escalation. Required action: Apply updates per vendor instructions.

CVE-2021-20021CVE-2021-20022EPSS 83.4%SonicWallSonicWall Email Security
CISA KEV ↗ · unattributed attribution
high

CVE-2021-20023: SonicWall Email Security Path Traversal Vulnerability

SonicWall Email Security contains a path traversal vulnerability that allows a post-authenticated attacker to read files on the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20022 to achieve privilege escalation. Required action: Apply updates per vendor instructions.

CVE-2021-20021CVE-2021-20022EPSS 83.4%SonicWallSonicWall Email Security
CISA KEV ↗ · unattributed attribution
high

CVE-2020-12271: Sophos SFOS SQL Injection Vulnerability

Sophos Firewall operating system (SFOS) firmware contains a SQL injection vulnerability when configured with either the administration (HTTPS) service or the User Portal is exposed on the WAN zone. Successful exploitation may cause remote code execution to exfiltrate usernames and hashed passwords for the local device admin(s), portal admins, and user accounts used for remote access (but not external Active Directory or LDAP passwords). Required action: Apply updates per vendor instructions.

CVE-2020-12271EPSS 42.2%SFOSSophos
CISA KEV ↗ · unattributed attribution
high

CVE-2020-10181: Sumavision EMR Cross-Site Request Forgery (CSRF) Vulnerability

Sumavision Enhanced Multimedia Router (EMR) contains a cross-site request forgery (CSRF) vulnerability allowing the creation of users with elevated privileges as administrator on a device. Required action: Apply updates per vendor instructions.

CVE-2020-10181EPSS 14.2%Enhanced Multimedia Router (EMR)Sumavision
CISA KEV ↗ · unattributed attribution
high

CVE-2017-6327: Symantec Messaging Gateway Remote Code Execution Vulnerability

Symantec Messaging Gateway contains an unspecified vulnerability which can allow for remote code execution. With the ability to perform remote code execution, an attacker may also desire to perform privilege escalating actions. Required action: Apply updates per vendor instructions.

CVE-2017-6327EPSS 35.3%SymantecSymantec Messaging Gateway
CISA KEV ↗ · unattributed attribution
high

CVE-2019-18988: TeamViewer Desktop Bypass Remote Login Vulnerability

TeamViewer Desktop allows for bypass of remote-login access control because the same AES key is used for different customers' installations. If an attacker were to know this key, they could decrypt protected information stored in registry or configuration files or decryption of the Unattended Access password to the system (which allows for remote login to the system). Required action: Apply updates per vendor instructions.

CVE-2019-18988EPSS 4.7%DesktopTeamViewer
CISA KEV ↗ · unattributed attribution
high

CVE-2017-9248: Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability

Progress Telerik UI for ASP.NET AJAX and Sitefinity have a cryptographic weakness in Telerik.Web.UI.dll that can be exploited to disclose encryption keys (Telerik.Web.UI.DialogParametersEncryptionKey and/or the MachineKey), perform cross-site-scripting (XSS) attacks, compromise the ASP.NET ViewState, and/or upload and download files. Required action: Apply updates per vendor instructions.

CVE-2017-9248EPSS 75.1%ASP.NET AJAX and SitefinityProgress
CISA KEV ↗ · unattributed attribution · 3 IOCs
high

CVE-2018-14558: Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability

Tenda AC7, AC9, and AC10 devices contain a command injection vulnerability due to the "formsetUsbUnload" function executes a dosystemCmd function with untrusted input. Successful exploitation allows an attacker to execute OS commands via a crafted goform/setUsbUnload request. Required action: Apply updates per vendor instructions.

CVE-2018-14558EPSS 8.7%AC7, AC9, and AC10 RoutersTenda
CISA KEV ↗ · unattributed attribution
high

CVE-2019-9082: ThinkPHP Remote Code Execution Vulnerability

ThinkPHP contains an unspecified vulnerability that allows for remote code execution via public//?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed by the command. Required action: Apply updates per vendor instructions.

CVE-2019-9082EPSS 97.4%ThinkPHP
CISA KEV ↗ · unattributed attribution
high

CVE-2019-18187: Trend Micro OfficeScan Directory Traversal Vulnerability

Trend Micro OfficeScan contains a directory traversal vulnerability by extracting files from a zip file to a specific folder on the OfficeScan server, leading to remote code execution. Required action: Apply updates per vendor instructions.

CVE-2019-18187EPSS 25.1%OfficeScanTrend Micro
CISA KEV ↗ · unattributed attribution
high

CVE-2020-8468: Trend Micro Multiple Products Content Validation Escape Vulnerability

Trend Micro Apex One, OfficeScan, and Worry-Free Business Security agents contain a content validation escape vulnerability that could allow an attacker to manipulate certain agent client components. Required action: Apply updates per vendor instructions.

CVE-2020-8468EPSS 5.8%Apex One, OfficeScan and Worry-Free Business Security AgentsTrend Micro
CISA KEV ↗ · unattributed attribution
high

CVE-2020-24557: Trend Micro Multiple Products Improper Access Control Vulnerability

Trend Micro Apex One, OfficeScan, and Worry-Free Business Security on Microsoft Windows contain an improper access control vulnerability that may allow an attacker to manipulate a particular product folder to disable the security temporarily, abuse a specific Windows function, and attain privilege escalation. Required action: Apply updates per vendor instructions.

CVE-2020-24557EPSS 2.6%Apex One, OfficeScan, and Worry-Free Business SecurityTrend Micro
CISA KEV ↗ · unattributed attribution
high

CVE-2020-5849: Unraid Authentication Bypass Vulnerability

Unraid contains an authentication bypass vulnerability that allows attackers to gain access to the administrative interface. This CVE is chainable with CVE-2020-5847 for remote code execution. Required action: Apply updates per vendor instructions.

CVE-2020-5847CVE-2020-5849EPSS 95.8%Unraid
CISA KEV ↗ · unattributed attribution
high

CVE-2020-5847: Unraid Remote Code Execution Vulnerability

Unraid contains a vulnerability due to the insecure use of the extract PHP function that can be abused to execute remote code as root. This CVE is chainable with CVE-2020-5849 for initial access. Required action: Apply updates per vendor instructions.

CVE-2020-5847CVE-2020-5849EPSS 95.8%Unraid
CISA KEV ↗ · unattributed attribution
high

CVE-2020-17496: vBulletin PHP Module Remote Code Execution Vulnerability

The PHP module within vBulletin contains an unspecified vulnerability that allows for remote code execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. This CVE ID resolves an incomplete patch for CVE-2019-16759. Required action: Apply updates per vendor instructions.

CVE-2019-16759CVE-2020-17496EPSS 99.7%vBulletin
CISA KEV ↗ · unattributed attribution
high

CVE-2019-5544: VMware ESXi and Horizon DaaS OpenSLP Heap-Based Buffer Overflow Vulnerability

VMware ESXi and Horizon Desktop as a Service (DaaS) OpenSLP contains a heap-based buffer overflow vulnerability that allows an attacker with network access to port 427 to overwrite the heap of the OpenSLP service to perform remote code execution. Required action: Apply updates per vendor instructions.

CVE-2019-5544EPSS 96.8%VMwareVMware ESXi and Horizon DaaS
CISA KEV ↗ · unattributed attribution
high

CVE-2020-3992: VMware ESXi OpenSLP Use-After-Free Vulnerability

VMware ESXi OpenSLP contains a use-after-free vulnerability that allows an attacker residing in the management network with access to port 427 to perform remote code execution. Required action: Apply updates per vendor instructions.

CVE-2020-3992EPSS 83.0%ESXiVMware
CISA KEV ↗ · unattributed attribution
high

CVE-2020-3950: VMware Multiple Products Privilege Escalation Vulnerability

VMware Fusion, Remote Console (VMRC) for Mac, and Horizon Client for Mac contain a privilege escalation vulnerability due to improper use of setuid binaries that allows attackers to escalate privileges to root. Required action: Apply updates per vendor instructions.

CVE-2020-3950EPSS 7.3%Multiple ProductsVMware
CISA KEV ↗ · unattributed attribution
high

CVE-2021-22005: VMware vCenter Server File Upload Vulnerability

VMware vCenter Server contains a file upload vulnerability in the Analytics service that allows a user with network access to port 443 to execute code. Required action: Apply updates per vendor instructions.

CVE-2021-22005EPSS 100.0%VMwarevCenter Server
CISA KEV ↗ · unattributed attribution
high

CVE-2020-3952: VMware vCenter Server Information Disclosure Vulnerability

VMware vCenter Server contains an information disclosure vulnerability in the VMware Directory Service (vmdir) when the Platform Services Controller (PSC) does not correctly implement access controls. Successful exploitation allows an attacker with network access to port 389 to extract sensitive information. Required action: Apply updates per vendor instructions.

CVE-2020-3952EPSS 90.4%VMwarevCenter Server
CISA KEV ↗ · unattributed attribution
high

CVE-2021-21972: VMware vCenter Server Remote Code Execution Vulnerability

VMware vCenter Server vSphere Client contains a remote code execution vulnerability in a vCenter Server plugin which allows an attacker with network access to port 443 to execute commands with unrestricted privileges on the underlying operating system. Required action: Apply updates per vendor instructions.

CVE-2021-21972EPSS 99.6%VMwarevCenter Server
CISA KEV ↗ · unattributed attribution
high

CVE-2020-4006: Multiple VMware Products Command Injection Vulnerability

VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector contain a command injection vulnerability. An attacker with network access to the administrative configurator on port 8443 and a valid password for the configurator administrator account can execute commands with unrestricted privileges on the underlying operating system. Required action: Apply updates per vendor instructions.

CVE-2020-4006EPSS 23.8%Multiple ProductsVMware
CISA KEV ↗ · unattributed attribution
high

CVE-2020-11738: WordPress Snap Creek Duplicator Plugin File Download Vulnerability

WordPress Snap Creek Duplicator plugin contains a file download vulnerability when an administrator creates a new copy of their site that allows an attacker to download the generated files from their Wordpress dashboard. This vulnerability affects Duplicator and Dulplicator Pro. Required action: Apply updates per vendor instructions.

CVE-2020-11738EPSS 97.8%Snap Creek Duplicator PluginWordPress
CISA KEV ↗ · unattributed attribution
critical

Ukraine electric power disruption

Sandworm-linked activity disrupted electricity distribution, a landmark cyberattack against civilian infrastructure.

Sandworm TeamICSUkrainecritical infrastructure
MITRE ATT&CK ↗ · confirmed attribution