| 2026-09-26 | CVE-2026-67279 | MikroTik RouterOS Unauthenticated Session Bypass Carries Federal Remediation Deadline of September 28 | 6.5 Medium | KEV |
| 2026-09-25 | CVE-2026-93616 | Path Traversal Across Check Point Management and Log Server Infrastructure Missed the September 25th CISA KEV Window; Covered Organizations Are Now Out of Compliance | 9.8 Critical | KEV |
| 2026-09-25 | CVE-2026-85046 | Google Chromium V8's Type Confusion Allows Remote Attackers to Execute Arbitrary Code or Escape the Browser Sandbox via a Crafted Web Page | 8.8 High | KEV |
| 2026-09-25 | CVE-2026-81578 | PaperCut NG/MF's Missing Authentication on a Critical Function Allows Unauthenticated Attackers to Perform Administrative Actions Without Logging In; CISA's September 14th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-25 | CVE-2026-76461 | Cisco Secure Email Gateway's SQL Injection Flaw Allows Unauthenticated Attackers to Execute Arbitrary Database Queries and Compromise the Email Security Platform | 9.8 Critical | KEV |
| 2026-09-25 | CVE-2026-76460 | Cisco Identity Services Engine's Incorrect Use of Privileged APIs Allows Unauthenticated Remote Attackers to Gain Full Administrative Control; CISA's September 19th KEV Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-25 | CVE-2026-75650 | Adobe Commerce and Magento's Template Engine Injection Flaw Allows Unauthenticated Remote Attackers to Execute Arbitrary Server-Side Code on the E-Commerce Platform | 10.0 Critical | KEV |
| 2026-09-25 | CVE-2026-5430 | WSO2 API Gateway Path Traversal Reaches Federal Remediation Deadline of September 27 | 10.0 Critical | KEV |
| 2026-09-24 | CVE-2026-9203 | MarkLogic SSRF Flaw Exposes Cloud Instance Credentials to Low-Privilege Users | 8.5 High | Updated |
| 2026-09-24 | CVE-2026-9195 | Crafted Links Let Attackers Hijack MarkLogic Administrator Sessions Through Query Console XSS | 9.3 Critical | Updated |
| 2026-09-24 | CVE-2026-9193 | Low-Privilege Hadoop Role Escalates to Full Control of MarkLogic's Security Database | 9.9 Critical | Updated |
| 2026-09-24 | CVE-2026-9192 | Unauthenticated Attackers Can Impersonate Any MarkLogic User Through ODBC Authentication Bypass | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-9190 | HTTP Request Smuggling Bypasses MarkLogic Authentication and Hijacks Sessions | 9.1 Critical | Updated |
| 2026-09-24 | CVE-2026-9089 | ConnectWise Automate agent trusts unverified plugin and update downloads, fixed in 2026.5 | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-8709 | MarkLogic's REST document-patch API lets low-privileged users seize administrator control | 9.9 Critical | Updated |
| 2026-09-24 | CVE-2026-7557 | Unauthenticated attackers impersonate any MarkLogic administrator through a SAML signature flaw | 9.1 Critical | Updated |
| 2026-09-24 | CVE-2026-7329 | MarkLogic's SQL, SPARQL, and Optic query interfaces open a path from low-privileged access to full admin | 9.9 Critical | Updated |
| 2026-09-24 | CVE-2026-7327 | MarkLogic's document-processing pipeline lets an administrative REST role escalate further, exposing server-side data | 8.1 High | Updated |
| 2026-09-24 | CVE-2026-7326 | A CSRF flaw in MarkLogic's Admin UI lets attackers hijack lured administrators for configuration changes | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-71474 | Red Hat insights-client logs a long-lived OpenShift pull-secret token that local pod-log access can expose | 7.1 High | Updated |
| 2026-09-24 | CVE-2026-68981 | Apache NiFi's gzip request handling bypasses size limits, opening a memory-exhaustion path, fixed in 2.11.0 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-68980 | Apache NiFi's asset-deletion API skips ownership checks across Parameter Contexts, fixed in 2.11.0 | 9.1 Critical | Updated |
| 2026-09-24 | CVE-2026-68979 | Missing authorization on Apache NiFi's Parameter Context updates can trigger code execution, fixed in 2.11.0 | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-68060 | Pre-authentication attackers can exhaust memory in Apache Qpid Broker-J via oversized type handling, fixed in 10.1.0 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-67589 | Apache Qpid ProtonJ2 lets pre-authentication attackers trigger oversized memory allocations, fixed in 1.2.0 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-67588 | Unbounded symbol caching in Apache Qpid ProtonJ2 lets pre-authentication attackers exhaust memory, fixed in 1.2.0 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-67551 | Apache Qpid Proton-Dotnet lets pre-authentication attackers trigger oversized memory allocations, fixed in 1.1.0 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-67465 | Unbounded symbol caching in Apache Qpid Proton-Dotnet lets pre-authentication attackers exhaust memory, fixed in 1.1.0 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-66756 | A critical alternate-path flaw in Apache Tika precedes the 4.0.0-beta-1 fix, CVSS 9.8 | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-66755 | Apache Tika's ISA-Tab parser lets crafted filenames leak arbitrary file contents into extracted text, fixed in 3.3.2 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-66273 | Apache Qpid Proton-J lets pre-authentication attackers trigger oversized memory allocations, fixed in 0.35.0 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-66257 | Unbounded symbol caching in Apache Qpid Proton-J lets pre-authentication attackers exhaust memory, fixed in 0.35.0 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-66015 | A JFrog Platform privilege-escalation flaw grants temporary admin access under admin-provisioned accounts | 7.2 High | New |
| 2026-09-24 | CVE-2026-66014 | An authentication weakness in JFrog Artifactory's internal request processing lets attackers escalate access | 8.8 High | New |
| 2026-09-24 | CVE-2026-65922 | Limited-access JFrog Artifactory users can write to restricted internal metadata under specific conditions | 7.1 High | New |
| 2026-09-24 | CVE-2026-65617 | A deserialization flaw in JFrog Artifactory package handling lets low-privileged users compromise confidentiality, integrity, and availability | 8.8 High | New |
| 2026-09-24 | CVE-2026-65616 | Flawed refresh-token signature validation lets non-admin JFrog users obtain a signed administrator token | 8.8 High | New |
| 2026-09-24 | CVE-2026-62391 | An incomplete fix for a prior Kyuubi flaw still lets clients bypass the local-directory allowlist via Spark config aliases, fixed in 1.12.0 | 8.1 High | Updated |
| 2026-09-24 | CVE-2026-61372 | A path traversal vulnerability in Apache Jena Fuseki is fixed in 6.2.0 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-6066 | ConnectWise Automate's Solution Center allowed unencrypted client-server traffic open to interception, fixed in 2026.4 | 7.1 High | Updated |
| 2026-09-24 | CVE-2026-60413 | An information-exposure flaw in Oracle Outside In Core lets a logged-in attacker take full control, CVSS 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-60412 | Insecure deserialization in Oracle Outside In Core lets a logged-in attacker take full control, CVSS 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-60393 | Unauthenticated network attackers can reach all Oracle Hyperion Infrastructure Technology data over HTTP, CVSS 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-60392 | Insecure deserialization in Oracle's Outside In PDF Export SDK lets a logged-in attacker take full control, CVSS 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-60391 | Unauthenticated network attackers can reach all Oracle Hyperion Financial Reporting data over HTTP, CVSS 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-6023 | Tampered RadFilter state in Telerik UI for ASP.NET AJAX enables server-side remote code execution | 8.1 High | Updated |
| 2026-09-24 | CVE-2026-6022 | Telerik UI for ASP.NET AJAX chunked upload flaw lets attackers bypass size limits and exhaust disk space | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-5483 | Red Hat OpenShift AI's odh-dashboard leaks Kubernetes service account tokens through a NodeJS endpoint | 8.5 High | New |
| 2026-09-24 | CVE-2026-54100 | Red Hat's Windows Machine Config Operator skips SSH host-key checks, letting adjacent attackers capture node bootstrap credentials | 8.3 High | Updated |
| 2026-09-24 | CVE-2026-54099 | A compromised Windows node can forge a cluster-administrator certificate through WMCO's CSR auto-approver, CVSS 8.8 | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-52680 | Path traversal in Apache Kyuubi's REST batch upload lets remote attackers write files outside the intended directory, fixed in 1.12.0 | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-5174 | Improper input validation in Progress MOVEit Automation opens a path to privilege escalation | 7.7 High | Updated |
| 2026-09-24 | CVE-2026-47629 | Improper input validation in NVIDIA Triton Inference Server on Linux can trigger denial of service | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-47628 | Unbounded resource allocation in NVIDIA Triton Inference Server on Linux opens a denial-of-service path | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-47627 | A critical path-traversal flaw in NVIDIA Triton Inference Server on Linux enables denial of service, CVSS 9.8 | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-4740 | Red Hat Advanced Cluster Management lets a managed-cluster admin forge certificates for cross-cluster privilege escalation | 8.2 High | Updated |
| 2026-09-24 | CVE-2026-42017 | An event-handling flaw in JFrog Artifactory exposes privileged authorization material to lower-privileged users | 8.8 High | New |
| 2026-09-24 | CVE-2026-41724 | Stored XSS in VMware Cloud Foundation Operations lets privileged users trigger admin actions via injected scripts | 8.0 High | Updated |
| 2026-09-24 | CVE-2026-41723 | A stored XSS spanning VMware Cloud Foundation Operations and vSphere lets privileged users trigger admin actions via injected scripts | 8.0 High | Updated |
| 2026-09-24 | CVE-2026-41722 | Another stored XSS across VMware Cloud Foundation Operations and vSphere lets privileged users trigger admin actions via injected scripts | 8.0 High | Updated |
| 2026-09-24 | CVE-2026-41702 | A TOCTOU flaw in a VMware Fusion SETUID binary lets local non-admin users escalate to root | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-4048 | Authenticated Command Injection in Progress LoadMaster UI Enables Remote Code Execution | 8.4 High | EPSS-Imminent |
| 2026-09-24 | CVE-2026-40141 | A critical query-injection flaw in BeyondTrust Remote Support lets low-privileged users reach unauthorized resources, CVSS 9.9 | 9.9 Critical | Updated |
| 2026-09-24 | CVE-2026-40140 | Unauthenticated attackers can crash BeyondTrust Remote Support appliances via a network-communication flaw | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-40139 | Critical Pre-Authentication Bypass in BeyondTrust Remote Support Allows Unauthorized Access | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-40138 | BeyondTrust Privileged Remote Access Shares Pre-Authentication Bypass Flaw with Remote Support | 8.1 High | Updated |
| 2026-09-24 | CVE-2026-39815 | SQL Injection in Fortinet FortiDDoS-F 7.2 May Allow Unauthorized Data Access | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-39304 | Apache ActiveMQ NIO SSL Transports Vulnerable to Denial-of-Service via Memory Exhaustion | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-3692 | Low-Privilege OS Command Injection in Progress Flowmon Reporting Component | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-35554 | Race Condition in Apache Kafka Producer Can Silently Deliver Messages to Wrong Topics | 8.7 High | Updated |
| 2026-09-24 | CVE-2026-3519 | Progress LoadMaster API Exposes Authenticated Command Injection for VS Administration Role | 8.4 High | EPSS-Imminent |
| 2026-09-24 | CVE-2026-34487 | Apache Tomcat Cloud Clustering Component Logs Kubernetes Credentials in Plain Text | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-34483 | Improper Output Encoding in Apache Tomcat JsonAccessLogValve Enables Log Injection | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-34478 | Apache Log4j RFC 5424 Layout Vulnerable to Log Injection in Versions 2.21 through 2.25 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-34020 | Apache OpenMeetings REST Login Exposes Credentials in URL Query String | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-33266 | Apache OpenMeetings Uses Default Hard-Coded Encryption Key for Remember-Me Cookies | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-33105 | Critical Authorization Bypass in Microsoft Azure Kubernetes Service Allows Network Privilege Escalation | 10.0 Critical | Updated |
| 2026-09-24 | CVE-2026-32590 | Unsafe Deserialization in Red Hat Quay Resumable Upload Handling | 7.1 High | Updated |
| 2026-09-24 | CVE-2026-32200 | Use-After-Free in Microsoft PowerPoint Enables Local Code Execution | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-32199 | Use-After-Free in Microsoft Office Excel Enables Local Code Execution | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-32198 | Microsoft Office Excel Use-After-Free Lets Local Attacker Execute Code | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-32197 | Local Code Execution via Use-After-Free in Microsoft Office Excel | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-32190 | Use-After-Free in Microsoft Office Enables Local Code Execution | 8.4 High | Updated |
| 2026-09-24 | CVE-2026-32189 | Microsoft Office Excel Carries Additional Use-After-Free Code Execution Risk | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-32188 | Out-of-Bounds Read in Microsoft Office Excel Discloses Information to Local Attackers | 7.1 High | Updated |
| 2026-09-24 | CVE-2026-32186 | Critical SSRF in Microsoft Bing Enables Network-Based Privilege Escalation | 10.0 Critical | Updated |
| 2026-09-24 | CVE-2026-32184 | Deserialization Flaw in Microsoft HPC Pack Allows Authorized User to Escalate Privileges | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-32153 | Use-After-Free in Windows Speech Component Allows Local Privilege Escalation | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-32091 | Race Condition in Microsoft Brokering File System Allows Unauthorized Privilege Escalation | 8.4 High | Updated |
| 2026-09-24 | CVE-2026-29145 | Apache Tomcat CLIENT_CERT Authentication Bypass When Soft Fail Is Disabled | 9.1 Critical | Updated |
| 2026-09-24 | CVE-2026-29129 | Apache Tomcat Fails to Preserve Configured Cipher Preference Order | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-28814 | Apache JSPWiki Renders Wiki Markup Without Authentication, Exposing Sensitive Data | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-28813 | JSON Hijacking in Apache JSPWiki Enables Cross-Site Request Forgery | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-28812 | Apache JSPWiki UserManager Spoofing Flaw Allows Attackers to Escalate Privileges | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-28811 | Apache JSPWiki Leaks Internal Information via Debug Messages | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-27914 | Improper Access Control in Microsoft Management Console Allows Local Privilege Escalation | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-27909 | Use-After-Free in Windows Search Component Allows Authorized Attacker to Escalate Privileges | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-27314 | Apache Cassandra 5.0 CREATE Permission Allows Privilege Escalation in mTLS Environments | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-26181 | Use-After-Free in Microsoft Brokering File System Lets Authorized User Escalate Privileges | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-26170 | Input Validation Flaw in Microsoft PowerShell Allows Local Privilege Escalation | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-26149 | Control Sequence Injection in Microsoft Power Apps Enables Network-Based Spoofing | 9.0 Critical | Updated |
| 2026-09-24 | CVE-2026-26143 | Improper Input Validation in Microsoft PowerShell Allows Unauthorized Security Feature Bypass | 7.8 High | New |
| 2026-09-24 | CVE-2026-24880 | Apache Tomcat Chunk Extension Parsing Allows HTTP Request Smuggling | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-24222 | NVIDIA NeMoClaw Sandbox Initialization Exposes System Information to Remote Attackers | 8.6 High | Updated |
| 2026-09-24 | CVE-2026-24217 | Path Traversal in NVIDIA BioNeMo Core Allows Malicious File to Escape Sandbox | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-24216 | Deserialization of Untrusted Data in NVIDIA BioNeMo Enables Code Execution | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-24214 | Integer Overflow in NVIDIA Triton Inference Server DALI Backend | 8.0 High | Updated |
| 2026-09-24 | CVE-2026-24213 | Out-of-Bounds Read in NVIDIA Triton Inference Server DALI Backend | 8.0 High | Updated |
| 2026-09-24 | CVE-2026-24210 | Integer Overflow in NVIDIA Triton Inference Server Allows Code Execution or Denial of Service | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-24209 | Path Traversal Vulnerability in NVIDIA Triton Inference Server | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-24207 | Critical Authentication Bypass in NVIDIA Triton Inference Server | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-24206 | NVIDIA Triton Inference Server Authentication Bypass via Alternate Path Scores 7.3 | 7.3 High | Updated |
| 2026-09-24 | CVE-2026-24188 | NVIDIA TensorRT Out-of-Bounds Write Scores 8.2 | 8.2 High | Updated |
| 2026-09-24 | CVE-2026-24186 | NVIDIA NVFlare Deserialization of Untrusted Data Scores 8.8 | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-24184 | NVIDIA Cumulus Linux Buffer Overflow Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-24183 | NVIDIA Cumulus Linux Excessive-Privilege Execution Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-24178 | Critical NVIDIA NVFlare Authorization Bypass via User-Controlled Key Scores 9.8 | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-24175 | NVIDIA Triton Inference Server Uncaught Exception Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-24174 | NVIDIA Triton Inference Server Numeric Type Conversion Error Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-24173 | NVIDIA Triton Inference Server Integer Overflow Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-24163 | NVIDIA TensorRT-LLM Deserialization Flaw Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-24156 | NVIDIA Data Loading Library Deserialization Vulnerability Scores 7.3 | 7.3 High | Updated |
| 2026-09-24 | CVE-2026-24146 | NVIDIA Triton Inference Server Oversized Allocation Request Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-23708 | Fortinet FortiSOAR Authentication Flaw Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-23657 | Microsoft Office LTSC Use-After-Free Vulnerability Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-23429 | Linux Kernel IOMMU SVA Use-After-Free in Unbind Path Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-23428 | Critical Linux Kernel ksmbd Use-After-Free in Compound Request Handling Scores 9.8 | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-23427 | Critical Linux Kernel ksmbd Use-After-Free in Durable Handle Replay Scores 9.8 | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-23425 | Linux Kernel KVM arm64 ID Register Initialization Flaw Scores 8.8 | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-23424 | Linux Kernel amdxdna Missing Command Buffer Validation Scores 7.1 | 7.1 High | Updated |
| 2026-09-24 | CVE-2026-23422 | Linux Kernel dpaa2-switch Out-of-Bounds Write from Malformed Interrupt Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-23415 | Linux Kernel Futex Use-After-Free between Key Lookup and VMA Policy Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-23414 | Linux Kernel TLS Memory Leak in Async Decrypt Wait Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-23413 | Linux Kernel clsact Use-After-Free in Init/Destroy Rollback Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-23412 | Linux Kernel Netfilter BPF Use-After-Free in Hook Memory Release Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-23411 | Linux Kernel AppArmor Race Condition Frees i_private Data Early Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-23410 | Linux Kernel AppArmor Race on Rawdata Dereference Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-23408 | Linux Kernel AppArmor Double Free of Namespace Name Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-23407 | Linux Kernel AppArmor Out-of-Bounds Read in DFA Verification Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-22828 | Fortinet FortiManager and FortiAnalyzer Cloud Heap Overflow Scores 8.1 | 8.1 High | Updated |
| 2026-09-24 | CVE-2026-22619 | Eaton Intelligent Power Protector Uncontrolled Search Path Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-22016 | Oracle Java SE JAXP Component Exposes Sensitive Information, Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-22011 | Oracle Applications DBA ADPatch Access Control Weakness Scores 7.6 | 7.6 High | Updated |
| 2026-09-24 | CVE-2026-22010 | Oracle Financial Services Infrastructure Platform Access Control Flaw Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-21997 | Oracle Life Sciences Empirica Signal Access Control Weakness Scores 8.5 | 8.5 High | Updated |
| 2026-09-24 | CVE-2026-21662 | Critical Johnson Controls FMS Employee Unrestricted File Upload Scores 9.8 | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-20160 | Critical Cisco Smart Software Manager On-Prem Resource Exposure Scores 9.8 | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-20155 | Cisco Evolved Programmable Network Manager Missing Authorization Scores 8.0 | 8.0 High | Updated |
| 2026-09-24 | CVE-2026-20151 | Cisco Smart Software Manager On-Prem Leaks Sensitive Data in Transmitted Requests | 7.3 High | Updated |
| 2026-09-24 | CVE-2026-20094 | Cisco UCS Command Injection Scores 8.8 | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-18381 | Red Hat Cost Management Metrics Operator SSRF via Crafted Custom Resource Scores 7.6 | 7.6 High | Updated |
| 2026-09-24 | CVE-2026-18378 | Red Hat Cost Management Metrics Operator SSRF via Arbitrary Upload URL Scores 7.6 | 7.6 High | Updated |
| 2026-09-24 | CVE-2026-17894 | Google Chrome on Linux Use-After-Free in Views via Crafted HTML Scores 8.8 | 8.8 High | New |
| 2026-09-24 | CVE-2026-17877 | Google Chrome on Linux Chromoting Flaw Enables Local Privilege Escalation, Scores 8.4 | 8.4 High | New |
| 2026-09-24 | CVE-2026-17744 | Google Chrome on Linux File Input Flaw Exposes Potential Sandbox Escape, Scores 7.1 | 7.1 High | New |
| 2026-09-24 | CVE-2026-16443 | Red Hat Build of Keycloak Cryptographic Signature Verification Flaw Scores 7.4 | 7.4 High | Updated |
| 2026-09-24 | CVE-2026-0288 | Palo Alto Networks PAN-OS Out-of-Bounds Write Scores 7.5 | 7.5 High | New |
| 2026-09-24 | CVE-2026-0273 | Palo Alto Networks PAN-OS OS Command Injection Scores 7.2 | 7.2 High | New |
| 2026-09-24 | CVE-2026-0272 | Palo Alto Networks PAN-OS Missing Authorization Scores 7.2 | 7.2 High | New |
| 2026-09-24 | CVE-2026-0271 | Palo Alto Networks Prisma Access Agent Permission Misconfiguration Scores 7.8 | 7.8 High | New |
| 2026-09-24 | CVE-2026-0270 | Palo Alto Networks Cortex XSOAR Path Traversal Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-0265 | Palo Alto Networks PAN-OS Authentication Bypass Affects Siemens RUGGEDCOM APE1808, Scores 8.1 | 8.1 High | Updated |
| 2026-09-24 | CVE-2026-0264 | Critical Palo Alto Networks PAN-OS DNS Heap Overflow Affects Siemens RUGGEDCOM APE1808, Scores 9.8 | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-0263 | Critical Palo Alto Networks PAN-OS Out-of-Bounds Write Scores 9.8 | 9.8 Critical | New |
| 2026-09-24 | CVE-2026-0262 | Palo Alto Networks PAN-OS Multiple Denial-of-Service Flaws Affect Siemens RUGGEDCOM APE1808 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-0261 | Palo Alto Networks PAN-OS Command Injection Affects Siemens RUGGEDCOM APE1808, Scores 7.2 | 7.2 High | Updated |
| 2026-09-24 | CVE-2026-0259 | Palo Alto Networks PAN-OS External File Path Control Scores 8.8 | 8.8 High | New |
| 2026-09-24 | CVE-2026-0258 | Palo Alto Networks PAN-OS IKEv2 SSRF Affects Siemens RUGGEDCOM APE1808, Scores 9.1 | 9.1 Critical | Updated |
| 2026-09-24 | CVE-2026-0251 | Palo Alto Networks GlobalProtect Untrusted Search Path Scores 7.8 | 7.8 High | New |
| 2026-09-24 | CVE-2026-0250 | Palo Alto Networks GlobalProtect Out-of-Bounds Write Scores 8.1 | 8.1 High | New |
| 2026-09-24 | CVE-2026-0246 | Palo Alto Networks Prisma Access Agent Missing Authorization Scores 7.8 | 7.8 High | New |
| 2026-09-24 | CVE-2026-0244 | Palo Alto Networks Prisma SD-WAN Certificate Validation Flaw Scores 8.1 | 8.1 High | Updated |
| 2026-09-24 | CVE-2026-0237 | Palo Alto Networks Prisma Browser Alternate Path Protection Flaw Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-0236 | Palo Alto Networks Prisma Browser Code Injection Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-0233 | Palo Alto Networks ADEM Certificate Validation Flaw Scores 8.8 | 8.8 High | Updated |
| 2026-09-24 | CVE-2025-7406 | Nokia MantaRay NM sudo Privilege Escalation Reaches Root, Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2025-65114 | Apache Traffic Server HTTP Request Smuggling Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2025-62188 | Apache DolphinScheduler Sensitive Information Exposure Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2025-61848 | Fortinet FortiManager SQL Injection Scores 7.2 | 7.2 High | Updated |
| 2026-09-24 | CVE-2025-58136 | Apache Traffic Server Incorrect Control Flow Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2025-53681 | Fortinet FortiMail SQL Injection Scores 7.2 | 7.2 High | Updated |
| 2026-09-24 | CVE-2025-33255 | NVIDIA TensorRT-LLM MPI Server Deserialization Flaw Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2025-24818 | Nokia MantaRay NM OS Command Injection in Log Search Scores 8.0 | 8.0 High | Updated |
| 2026-09-24 | CVE-2025-24817 | Nokia MantaRay NM OS Command Injection in Symptom Collector Scores 8.0 | 8.0 High | Updated |
| 2026-09-24 | CVE-2025-24815 | Nokia MantaRay NM Unrestricted File Upload Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2025-14774 | ABB T-MAC Plus Incorrect Authorization Scores 7.4 | 7.4 High | Updated |
| 2026-09-24 | CVE-2025-14773 | ABB T-MAC Plus Cross-Site Scripting Scores 8.0 | 8.0 High | Updated |
| 2026-09-24 | CVE-2025-14772 | ABB T-MAC Plus Authorization Bypass via User-Controlled Key Scores 8.8 | 8.8 High | Updated |
| 2026-09-24 | CVE-2025-14771 | ABB T-MAC Plus Exposes Files to External Parties, Scores 9.9 | 9.9 Critical | Updated |
| 2026-09-24 | CVE-2025-12694 | Forcepoint VPN Client Excessive-Privilege Execution Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2017-20236 | ProSoft ICX35-HWC OS Command Injection via Web UI Scores 9.8 | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2017-20235 | ProSoft ICX35-HWC Authentication Bypass in Web Interface Scores 9.1 | 9.1 Critical | Updated |
| 2026-09-24 | CVE-2008-4128 | Cisco IOS's Multiple Cross-Site Request Forgery Flaws Allow Remote Attackers to Execute Arbitrary Commands via Show Privilege and Alias Exec Requests; CISA's July 16th KEV Deadline Has Passed | 8.1 High | KEV |
| 2026-09-23 | CVE-2026-3517 | Progress LoadMaster OS Command Injection via Geo Administration API Scores 8.4 | 8.4 High | EPSS-Imminent |
| 2026-09-23 | CVE-2026-29146 | Apache Tomcat EncryptInterceptor Padding Oracle Scores 7.5 | 7.5 High | EPSS-Imminent |
| 2026-09-23 | CVE-2026-20180 | Critical Cisco ISE Path Traversal Enables Remote Code Execution, Scores 9.9 | 9.9 Critical | EPSS-Imminent |
| 2026-09-23 | CVE-2026-39813 | Fortinet FortiSandbox Path Traversal Enables Privilege Escalation, Scores 9.8 | 9.8 Critical | EPSS-Imminent |
| 2026-09-23 | CVE-2026-40688 | Fortinet FortiWeb Out-of-Bounds Write Scores 7.2 | 7.2 High | EPSS-Imminent |
| 2026-09-23 | CVE-2026-4670 | Critical Progress MOVEit Automation Authentication Bypass Scores 9.8 | 9.8 Critical | EPSS-Imminent |
| 2026-09-23 | CVE-2026-59309 | Critical VMware vCenter Authentication Bypass in Directory Service Scores 9.8 | 9.8 Critical | EPSS-Imminent |
| 2026-09-23 | CVE-2026-3518 | Progress LoadMaster OS Command Injection via Full-Permission API Scores 8.4 | 8.4 High | EPSS-Imminent |
| 2026-09-23 | CVE-2026-20147 | Critical Cisco ISE and ISE-PIC Command Injection Scores 9.9 | 9.9 Critical | EPSS-Imminent |
| 2026-09-23 | CVE-2026-94127 | CISA's September 25th Remediation Deadline for F5 BIG-IP APM's OAuth Profile Heap Overflow Has Passed; Covered Entities Running Affected Virtual Servers Are Out of Compliance | 9.8 Critical | KEV |
| 2026-09-23 | CVE-2026-93952 | Arista VeloCloud Orchestrator Input Validation Gap Lets Remote Attackers Reach Privileged APIs; CISA's September 25th KEV Deadline for Covered Entities Has Now Passed | 10.0 Critical | KEV |
| 2026-09-23 | CVE-2026-85102 | Check Point Firewall Certificate Validation Bypass Across Site-to-Site and Remote Access VPN Carries a Lapsed September 25th CISA KEV Requirement for Covered Entities | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-9586 | Sangoma Switchvox's SQL Injection Vulnerability Allows Unauthenticated Remote Attackers to Execute Arbitrary Database Queries and Compromise the Telephony Platform | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-9198 | IBM Langflow's Code Injection Flaw Allows Unauthenticated Remote Attackers to Execute Arbitrary Code on the AI Workflow Platform; CISA's August 7th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-9082 | Drupal Core's SQL Injection via Specially Crafted Database Abstraction API Requests Enables Privilege Escalation and Remote Code Execution; CISA's May 27th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-86218 | N-able N-central's Static Code Injection Flaw Allows Remote Attackers to Inject and Execute Arbitrary Code on the RMM Platform Without Prior Authentication | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-85706 | GitLab Community and Enterprise Edition's Path Traversal Flaw Allows Unauthenticated Remote Attackers to Read Arbitrary Files on the Server and Fully Compromise the GitLab Instance | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-83549 | SonicWall SMA1000 Appliances' OS Command Injection Allows Authenticated Local Attackers to Execute Arbitrary Commands with Root Privileges; CISA's September 5th KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-22 | CVE-2026-83548 | SonicWall SMA1000 Appliances' Server-Side Request Forgery Allows Unauthenticated Remote Attackers to Reach Internal Services and Compromise the Secure Mobile Access Gateway; CISA's September 5th KEV Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-82329 | JFrog Artifactory Carries a 9.8 Critical Improper Authentication Flaw That Lets Unauthenticated Attackers Bypass Login Controls on the Artifact Repository | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-8037 | Progress LoadMaster's Command Injection Flaw Allows Unauthenticated Remote Attackers to Execute Arbitrary OS Commands on the Load Balancer Appliance; CISA's August 10th KEV Deadline Has Passed | 9.6 Critical | KEV |
| 2026-09-22 | CVE-2026-73570 | Zimbra Collaboration Suite's OS Command Injection Allows Authenticated Attackers to Execute Arbitrary Commands on the Email Server with Elevated Privileges; CISA's August 24th KEV Deadline Has Passed | 8.9 High | KEV |
| 2026-09-22 | CVE-2026-72898 | Metabase's SQL Injection Flaw Allows Unauthenticated Attackers to Execute Arbitrary Database Queries and Achieve Full Platform Compromise; CISA's August 14th KEV Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-6973 | Ivanti Endpoint Manager Mobile's Improper Input Validation Allows a Remotely Authenticated Administrator to Execute Code Remotely; CISA's May 10th KEV Deadline Has Passed | 7.2 High | KEV |
| 2026-09-22 | CVE-2026-68820 | Microsoft Windows Ancillary Function Driver for WinSock's Use-After-Free Allows a Local Attacker to Gain Elevated Privileges via a Freed Memory Reference; CISA's August 25th KEV Deadline Has Passed | 7.0 High | KEV |
| 2026-09-22 | CVE-2026-65400 | Apple macOS's Improper Authentication Flaw Allows a Network Attacker to Bypass Login Controls and Gain Unauthorized Access to the Operating System; CISA's August 21st KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-64849 | MLflow's Server-Side Request Forgery Flaw Allows Remote Attackers to Use the ML Platform Server as a Proxy to Access Internal Services and Steal Credentials; CISA's September 2nd KEV Deadline Has Passed | 9.3 Critical | KEV |
| 2026-09-22 | CVE-2026-63077 | JetBrains TeamCity's Deserialization of Untrusted Data Allows Unauthenticated Remote Attackers to Execute Arbitrary Code on the CI/CD Server; CISA's August 8th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-63030 | WordPress Core Input Interpretation Conflict Exploited in the Wild Carries a Lapsed July 24th CISA KEV Mandate for Covered Entities | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-60137 | WordPress Core SQL Injection Enabling Database Access Joins CISA's Known Exploited Vulnerabilities Catalog; Covered Entities Past the August 4th Remediation Deadline | 5.9 Medium | KEV |
| 2026-09-22 | CVE-2026-60004 | Gitea's Code Injection Vulnerability Allows Unauthenticated Remote Attackers to Execute Arbitrary Code on the Repository Platform; CISA's August 28th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-59310 | Broadcom VMware vCenter's Path Traversal Flaw Allows Unauthenticated Remote Attackers to Access Files Outside the Web Root and Potentially Compromise the Virtualization Platform; CISA's August 21st KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-56291 | Balbooa Forms Unrestricted File Upload Requiring No Authentication Has Missed CISA's July 13th KEV Remediation Deadline; Covered Entities Are Now Out of Compliance | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-56290 | Joomlack Page Builder Lets Unauthenticated Users Upload Arbitrary Files, Enabling Remote Code Execution; CISA's July 10th KEV Mandate Has Lapsed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-55040 | Microsoft SharePoint's Weak Authentication Allows Attackers to Bypass Login Controls and Gain Unauthorized Access to SharePoint Sites and Data; CISA's August 21st KEV Deadline Has Passed | 9.1 Critical | KEV |
| 2026-09-22 | CVE-2026-50751 | Check Point Security Gateway's IKEv1 Key Exchange Flaw Lets Unauthenticated Attackers Establish Remote Access VPN Tunnels Without a Valid Password; CISA's June 11th KEV Deadline Has Passed | 9.3 Critical | KEV |
| 2026-09-22 | CVE-2026-48939 | iCagenda Joomla Event Calendar Extension Accepts Unrestricted File Uploads Without Authentication, Enabling Remote Code Execution; CISA's July 13th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-48908 | JoomShaper SP Page Builder Accepts Arbitrary File Uploads from Unauthenticated Users; CISA's July 10th KEV Deadline for Covered Entities Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-48907 | Joomla Content Editor Plugin Exposes Privileged Functions Without Proper Authorization; CISA's June 19th KEV Deadline for Covered Entities Has Lapsed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-48710 | Kludex Starlette's HTTP Request Smuggling Vulnerability Allows Network-Adjacent Attackers to Bypass Security Controls and Poison Shared HTTP Connections | 6.5 Medium | KEV |
| 2026-09-22 | CVE-2026-48558 | SimpleHelp Accepts Unverified Cryptographic Signatures, Letting Remote Attackers Bypass Authentication; CISA's July 2nd KEV Deadline for Covered Entities Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-48172 | Any cPanel User Can Escalate Privileges Through LiteSpeed's Plugin; CISA's May 29th KEV Remediation Requirement for Covered Entities Has Expired | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-46817 | Oracle E-Business Suite's Improper Privilege Management in Oracle Payments Allows an Unauthenticated Network Attacker to Take Over the Payments Module via HTTP; CISA's July 18th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-45498 | Microsoft Defender's Unspecified Vulnerability Allows for Denial of Service; CISA's June 3rd KEV Deadline Has Passed | 4.0 Medium | KEV |
| 2026-09-22 | CVE-2026-45247 | Mirasvit Full Page Cache Warmer's Deserialization Flaw Lets Unauthenticated Attackers Reach Remote Code Execution via a Crafted PHP Object in the CacheWarmer Cookie; CISA's June 6th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-42897 | Microsoft Exchange Server's Outlook Web Access Cross-Site Scripting Flaw Executes Arbitrary JavaScript When Interaction Conditions Are Met; CISA's May 29th KEV Deadline Has Passed | 8.1 High | KEV |
| 2026-09-22 | CVE-2026-42018 | JFrog Artifactory's Improper Authentication Allows Network-Based Attackers to Bypass Login Controls and Gain Unauthorized Access to the Artifact Repository | 7.5 High | KEV |
| 2026-09-22 | CVE-2026-42016 | JFrog Artifactory's Incorrect Authorization Allows Authenticated Users to Access Artifacts and Repositories Outside Their Permitted Scope | 8.1 High | KEV |
| 2026-09-22 | CVE-2026-41940 | WebPros cPanel and WHM's Login Flow Authentication Bypass Gives Unauthenticated Attackers Unauthorized Access to the Control Panel; CISA's May 3rd KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-41091 | Microsoft Defender's Link Following Flaw Enables an Authorized Attacker to Elevate Privileges Locally; CISA's June 3rd KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-22 | CVE-2026-39987 | Marimo's Pre-Authentication Flaw Gives Unauthenticated Attackers Shell Access and Arbitrary Command Execution; CISA's May 7th KEV Remediation Requirement for Covered Entities Has Long Lapsed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-39808 | Fortinet FortiSandbox's OS Command Injection Gives Unauthenticated Attackers Remote Code Execution via Crafted HTTP Requests; CISA's July 19th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-35616 | Fortinet FortiClient EMS Access Control Bypass Entered CISA's Known Exploited Vulnerabilities Catalog with an April 9th Federal Deadline That Has Long Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-35273 | Oracle PeopleSoft Enterprise PeopleTools' Missing Authentication for a Critical Function Allows Unauthenticated Attackers to Take Over the Platform; CISA's June 15th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-34926 | Pre-Authenticated Local Attackers Can Use Relative Path Traversal in Trend Micro Apex One to Modify Key Configuration Data; CISA's June 4th KEV Mandate for Covered Entities Has Lapsed | 6.7 Medium | KEV |
| 2026-09-22 | CVE-2026-34910 | Network-Adjacent Attackers Can Inject Commands into Ubiquiti UniFi OS Through an Input Validation Flaw; CISA's June 26th KEV Remediation Window Has Closed for Covered Entities | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-34909 | Ubiquiti UniFi OS's Path Traversal Lets a Network-Adjacent Attacker Access Files on the Underlying System and Manipulate an Underlying Account; CISA's June 26th KEV Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-34908 | Ubiquiti UniFi OS's Improper Access Control Lets a Network-Adjacent Attacker Make Unauthorized Changes to the System; CISA's June 26th KEV Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-34486 | Apache Tomcat's Missing Encryption of Sensitive Session Data Exposes Credentials and Tokens to Network Interception; CISA's August 7th KEV Deadline Has Passed | 7.5 High | KEV |
| 2026-09-22 | CVE-2026-34197 | Apache ActiveMQ's Improper Input Validation Enables Code Injection Affecting Both ActiveMQ and Broker Deployments; CISA's April 30th KEV Deadline Has Passed | 8.8 High | KEV |
| 2026-09-22 | CVE-2026-33825 | Microsoft Defender's Insufficient Access Control Allows an Authorized Attacker to Escalate Privileges Locally; CISA's May 6th KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-22 | CVE-2026-33824 | Microsoft Windows IKE Service Extensions' Double Free Enables Unauthenticated Remote Attackers to Execute Arbitrary Code; CISA's August 21st KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-32202 | Microsoft Windows Shell's Protection Mechanism Failure Allows an Unauthorized Attacker to Perform Spoofing Over the Network; CISA's May 12th KEV Deadline Has Passed | 4.3 Medium | KEV |
| 2026-09-22 | CVE-2026-31431 | Linux Kernel Resource Mishandling That Allows Privilege Escalation Carries a Lapsed May 15th CISA KEV Mandate; Covered Entities on Unpatched Kernels Remain Out of Compliance | 7.8 High | KEV |
| 2026-09-22 | CVE-2026-28318 | SolarWinds Serv-U File Transfer Server Resource Exhaustion Exploited in the Wild Carries a Lapsed June 19th CISA KEV Federal Deadline | 7.5 High | KEV |
| 2026-09-22 | CVE-2026-25089 | Fortinet FortiSandbox's Unauthenticated OS Command Injection via Crafted HTTP Requests Covers Cloud and PaaS Deployments; CISA's July 19th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-21962 | Oracle HTTP Server and WebLogic Server Proxy Plug-in's Improper Access Control Allows Unauthenticated Network Attackers to Fully Compromise the Middleware Platform; CISA's August 27th KEV Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-21643 | Fortinet FortiClient EMS's SQL Injection Allows Unauthenticated Attackers to Execute Unauthorized Code via Crafted HTTP Requests; CISA's April 16th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-20316 | Cisco Secure Firewall Management Center Hard-Coded Password Lets Attackers Bypass Authentication; CISA's August 1st KEV Deadline for Covered Entities Has Passed | 5.3 Medium | KEV |
| 2026-09-22 | CVE-2026-20262 | Authenticated Path Traversal in Cisco Catalyst SD-WAN Manager Lets Remote Attackers Write Files Outside Allowed Directories; CISA's June 29th KEV Deadline Has Passed | 6.5 Medium | KEV |
| 2026-09-22 | CVE-2026-20253 | Splunk Enterprise's Missing Authentication on a PostgreSQL Sidecar Service Endpoint Lets Unauthenticated Users Create or Truncate Arbitrary Files; CISA's June 21st KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-20245 | Cisco Catalyst SD-WAN Manager's Improper Encoding Allows an Authenticated Local Attacker to Execute Arbitrary Commands as Root via a Crafted File; CISA's June 23rd KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-22 | CVE-2026-20230 | Cisco Unified Communications Manager SSRF Flaw Routes Attacker Requests to Internal Resources; CISA's June 28th KEV Deadline for Covered Entities Has Lapsed | 8.6 High | KEV |
| 2026-09-22 | CVE-2026-20200 | Cisco Unified Computing System's Argument Delimiter Injection Allows an Authenticated Attacker to Execute Arbitrary Commands on the Management Controller | 8.8 High | Exploited |
| 2026-09-22 | CVE-2026-20182 | Cisco Catalyst SD-WAN Controller and Manager's Authentication Bypass Gives Unauthenticated Remote Attackers Administrative Privileges; CISA's May 17th KEV Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-20133 | Cisco Catalyst SD-WAN Manager Leaks Sensitive Configuration Data to Unauthorized Users; CISA's April 23rd KEV Remediation Requirement Has Expired for Covered Entities | 6.5 Medium | KEV |
| 2026-09-22 | CVE-2026-20128 | Cisco Catalyst SD-WAN Manager Stores Credentials in a Recoverable Format, Enabling Credential Theft; CISA's April 23rd KEV Mandate for Covered Entities Has Lapsed | 7.5 High | KEV |
| 2026-09-22 | CVE-2026-20122 | Cisco Catalyst SD-WAN Manager Exposes Privileged API Functions to Unauthorized Callers; CISA's April 23rd KEV Remediation Deadline for Covered Entities Has Long Passed | 5.4 Medium | KEV |
| 2026-09-22 | CVE-2026-20079 | Cisco Firewall Management Center's Authentication Bypass via an Alternate Path Grants Unauthenticated Remote Attackers Full Administrative Control; CISA's September 12th KEV Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-19490 | Citrix NetScaler's Authentication Bypass via an Alternate Path Allows Unauthenticated Remote Attackers to Access Protected Resources Without Valid Credentials | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-16232 | Check Point SmartConsole's Improper Authentication Allows Unauthenticated Remote Attackers to Obtain a Login Token and Authenticate with Full Administrative Privileges; CISA's July 25th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-15410 | SonicWall SMA1000's Code Injection Allows a Remote Authenticated Administrator to Execute Arbitrary OS Commands Under Specific Conditions; CISA's July 17th KEV Deadline Has Passed | 7.2 High | KEV |
| 2026-09-22 | CVE-2026-15409 | SonicWall SMA1000 Secure Access Appliances Accept Forged Server-Side Requests, Enabling Internal Network Pivoting; CISA's July 17th KEV Remediation Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-1340 | Ivanti Endpoint Manager Mobile's Code Injection Vulnerability Allows Attackers to Achieve Unauthenticated Remote Code Execution; CISA's April 11th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-12569 | PTC Windchill and FlexPLM's Improper Input Validation Allows Unauthenticated Remote Attackers to Execute Arbitrary Code via Malicious Network Requests; CISA's June 28th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-10520 | Ivanti Sentry's OS Command Injection Gives Remote Unauthenticated Attackers Root-Level Remote Code Execution; CISA's June 14th KEV Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-0300 | PAN-OS Out-of-Bounds Write Enabling Code Execution Affects Both Palo Alto Networks Firewalls and Siemens RUGGEDCOM APE1808 Industrial Appliances; CISA's May 9th KEV Window Has Closed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-0257 | PAN-OS Authentication Bypass Enabling Unauthorized VPN Tunnels Affects Palo Alto Networks Prisma Access and Siemens RUGGEDCOM APE1808; Now Listed in CISA's Known Exploited Vulnerabilities Catalog | 9.1 Critical | KEV |
| 2026-09-22 | CVE-2025-68686 | Fortinet FortiOS's Information Exposure Flaw Allows a Remote Unauthenticated Attacker to Bypass the Previously Issued Patch for Symbolic Link Persistency; CISA's August 10th KEV Deadline Has Passed | 5.9 Medium | KEV |
| 2026-09-22 | CVE-2025-67038 | Lantronix EDS5000's Code Injection via the Username Parameter Executes Injected OS Commands with Root Privileges; CISA's June 26th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2025-62593 | Ray-Project Ray's Code Injection Flaw Allows Remote Attackers to Execute Arbitrary Code on the Distributed ML Framework's Cluster Nodes; CISA's August 20th KEV Deadline Has Passed | 8.8 High | KEV |
| 2026-09-22 | CVE-2025-60710 | Microsoft Windows Link Following Flaw Enables Privilege Escalation; CISA's April 27th KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-22 | CVE-2025-29635 | D-Link DIR-823X's set_prohibiting POST Endpoint Accepts Injected Commands and Executes Them on Remote Devices; CISA's May 8th KEV Deadline Has Passed for This Potentially End-of-Life Router | 7.2 High | KEV |
| 2026-09-22 | CVE-2025-2749 | Kentico Xperience's Path Traversal in the Staging Sync Server Allows Authenticated Users to Upload Arbitrary Data Outside Expected Directories; CISA's May 4th KEV Deadline Has Passed | 7.2 High | KEV |
| 2026-09-22 | CVE-2024-7399 | Samsung MagicINFO 9 Path Traversal Enabling Arbitrary File Writes as System Authority Has Missed CISA's May 8th KEV Deadline; Covered Entities Remain Out of Compliance | 8.8 High | KEV |
| 2026-09-22 | CVE-2024-57728 | SimpleHelp's Zip Slip Path Traversal Lets Admin Users Write Arbitrary Files to Any Location on the Server and Execute Code as the Service Account; CISA's May 8th KEV Deadline Has Passed | 7.2 High | KEV |
| 2026-09-22 | CVE-2024-57726 | SimpleHelp Lets Low-Privilege Technicians Mint Overpowered API Keys Through a Missing Authorization Check; CISA's May 8th KEV Deadline for Covered Entities Has Lapsed | 9.9 Critical | KEV |
| 2026-09-22 | CVE-2024-21182 | Unauthenticated T3 and IIOP Network Access to Oracle WebLogic Enables System Compromise; CISA's June 4th KEV Mandate for Covered Entities Has Been Lapsed for Months | 7.5 High | KEV |
| 2026-09-22 | CVE-2024-1708 | ConnectWise ScreenConnect's Path Traversal Enables Remote Code Execution or Direct Access to Confidential Data and Critical Systems; CISA's May 12th KEV Deadline Has Passed | 8.4 High | KEV |
| 2026-09-22 | CVE-2023-49105 | ownCloud's Improper Authentication Allows Unauthenticated Remote Attackers to Gain Access to Protected Files Without Valid Credentials; CISA's August 30th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2023-36424 | Microsoft Windows Common Log File System Driver's Out-of-Bounds Read Enables Privilege Escalation; CISA's April 27th KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-22 | CVE-2023-21529 | Microsoft Exchange Server's Deserialization of Untrusted Data Enables Authenticated Attackers to Achieve Remote Code Execution; CISA's April 27th KEV Deadline Has Passed | 8.8 High | KEV |
| 2026-09-22 | CVE-2022-0995 | Linux Kernel's Out-of-Bounds Write Allows Local Attackers to Escalate Privileges or Cause a Kernel Crash; CISA's September 9th KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-22 | CVE-2022-0492 | Linux Kernel's cgroup v1 release_agent Feature Enables Privilege Escalation; CISA's June 5th KEV Deadline for Covered Entities Has Lapsed | 7.8 High | KEV |
| 2026-09-22 | CVE-2021-27137 | Unauthenticated Attackers Can Overflow DD-WRT's UPnP Stack Buffer; CISA's July 24th KEV Mandate for Covered Entities Has Lapsed | 8.1 High | KEV |
| 2026-09-22 | CVE-2021-23758 | Ajax.NET Professional's Deserialization of Untrusted Data Allows Unauthenticated Remote Attackers to Execute Arbitrary Code via a Crafted Serialized Object; CISA's September 9th KEV Deadline Has Passed | 8.1 High | KEV |
| 2026-09-22 | CVE-2019-1068 | Microsoft SQL Server's Unspecified Flaw Allows Authenticated Attackers to Execute Arbitrary Code on the Database Server; CISA's August 29th KEV Deadline Has Passed | 8.8 High | KEV |
| 2026-09-22 | CVE-2015-5287 | Red Hat Automatic Bug Reporting Tool's Privilege Escalation Flaw Allows Local Attackers to Gain Root Access on Affected Enterprise Linux Systems; CISA's September 9th KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-22 | CVE-2015-3246 | Red Hat Enterprise Linux's Libuser Race Condition in Password File Writes Allows Local Attackers to Corrupt System Files; CISA's September 9th KEV Deadline Has Passed | 5.1 Medium | KEV |
| 2026-09-22 | CVE-2012-1854 | Microsoft Visual Basic for Applications Loads Libraries Insecurely, Enabling Remote Code Execution; CISA's April 27th KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-22 | CVE-2010-0806 | Microsoft Internet Explorer's Use-After-Free Enables Remote Code Execution via Invalid Pointer Access After Object Deletion; CISA's June 3rd KEV Deadline Has Passed | 8.8 High | KEV |
| 2026-09-22 | CVE-2010-0249 | Microsoft Internet Explorer's Use-After-Free Gives Remote Attackers Code Execution via a Pointer to a Deleted Object; CISA's June 3rd KEV Deadline Has Passed for This End-of-Life Browser | 8.8 High | KEV |
| 2026-09-22 | CVE-2009-1537 | Microsoft DirectX's QuickTime Movie Parser Filter Lets Remote Attackers Execute Arbitrary Code via a Crafted Media File; CISA's June 3rd KEV Deadline Has Passed | 8.8 High | KEV |
| 2026-09-22 | CVE-2009-0238 | Microsoft Office Code Injection From 2009 Added to CISA's Known Exploited Vulnerabilities Catalog with an April 28th Federal Deadline That Has Since Passed | 8.8 High | KEV |
| 2026-09-22 | CVE-2008-4250 | Microsoft Windows Server Service's Path Canonicalization Buffer Overflow Enables Remote Code Execution via Crafted RPC Requests; CISA's June 3rd KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-7273 | Zyxel GS1900 Series Switches' CGI Program Stack-Based Buffer Overflow Allows a LAN-Side Unauthenticated Attacker to Execute OS Commands via Crafted HTTP Requests; CISA's September 24th KEV Deadline Has Passed | 8.8 High | KEV |
| 2026-09-20 | CVE-2026-87886 | Acronis Backup's Incorrect Default Permissions Allow a Local Attacker to Access Backup Files and Configurations Not Intended for Their Account; CISA's September 19th KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-20 | CVE-2026-86060 | MikroTik RouterOS's Argument Injection in a Command-Processing Component Allows Unauthenticated Attackers to Execute Arbitrary Commands on the Router; CISA's September 13th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-20 | CVE-2026-85880 | Microsoft Windows' Heap-Based Buffer Overflow Allows Local Attackers to Escalate Privileges by Corrupting Heap Memory; CISA's September 22nd KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-20 | CVE-2026-84869 | ConnectWise ScreenConnect's Improper Privilege Management and Missing Authorization Allow Unauthenticated Attackers to Gain Administrative Control of the Remote Support Platform; CISA's September 14th KEV Deadline Has Passed | 9.9 Critical | KEV |
| 2026-09-20 | CVE-2026-81963 | Microsoft Windows' Improper Link Resolution Before File Access Allows a Local Attacker to Follow Symbolic Links to Privileged Files and Gain Elevated Access; CISA's September 22nd KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-20 | CVE-2026-67277 | MikroTik RouterOS's Missing Authentication for a Critical Function Allows Unauthenticated Attackers to Access and Modify Router Configuration; CISA's September 13th KEV Deadline Has Passed | 8.2 High | KEV |
| 2026-09-20 | CVE-2026-53362 | Linux Kernel's Unspecified Flaw Allows Local Attackers to Gain Elevated Privileges on Affected Systems; CISA's August 30th KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-20 | CVE-2026-53266 | Linux Kernel's Out-of-Bounds Write Vulnerability Allows Local Attackers to Escalate Privileges or Cause a Kernel Crash; CISA's September 21st KEV Deadline Has Passed | 8.8 High | KEV |
| 2026-09-20 | CVE-2026-20349 | Cisco Secure Firewall ASA and FTD's Heap Inspection Vulnerability Allows Remote Attackers to Extract Sensitive Memory Contents from the Firewall Device; CISA's August 14th KEV Deadline Has Passed | 8.6 High | KEV |
| 2026-09-20 | CVE-2026-20301 | Cisco IOS XE's Unchecked Loop Condition Input Allows Network-Accessible Devices to Be Crashed via a Specially Crafted Packet | 8.6 High | Exploited |
| 2026-09-20 | CVE-2026-20124 | Cisco IOS XE's Memory Resource Leak Allows Remote Attackers to Exhaust Device Memory and Cause a Denial of Service via Repeated Packet Transmission | 7.7 High | Exploited |
| 2026-09-20 | CVE-2026-0301 | Palo Alto Networks Cloud NGFW and Prisma Access Use of Uninitialized Resource Allows a Network-Based Attacker to Access Sensitive Information | 7.5 High | Exploited |
| 2026-09-20 | CVE-2026-0299 | Palo Alto Networks GlobalProtect's Untrusted Search Path Allows a Local Attacker to Load a Malicious Library and Execute Code in the Application's Context | 7.8 High | Exploited |
| 2026-09-20 | CVE-2026-0298 | Palo Alto Networks GlobalProtect's Code Injection Vulnerability Allows an Authenticated Remote Attacker to Execute Arbitrary Code in the Context of the VPN Client | 8.1 High | Exploited |
| 2026-09-20 | CVE-2026-0297 | Palo Alto Networks GlobalProtect's Out-of-Bounds Write Allows a Remote Attacker to Corrupt Memory and Execute Code or Crash the Application | 8.1 High | Exploited |
| 2026-09-20 | CVE-2026-0296 | Palo Alto Networks GlobalProtect's Improper Certificate Validation Allows a Network Adversary to Present a Forged Certificate and Intercept the VPN Connection | 7.4 High | Exploited |
| 2026-09-20 | CVE-2026-0295 | Palo Alto Networks GlobalProtect's Race Condition Allows a Local Attacker to Exploit a Timing Window and Gain Elevated Privileges | 7.0 High | Exploited |
| 2026-09-20 | CVE-2026-0294 | Palo Alto Networks Prisma Access Agent's Uncontrolled Search Path Allows a Local Attacker to Place a Malicious Library Where the Agent Will Load It | 7.8 High | Exploited |
| 2026-09-20 | CVE-2025-39964 | Linux Kernel's Race Condition Allows a Local Attacker to Exploit a Timing Window and Gain Elevated Privileges on the System; CISA's September 21st KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-20 | CVE-2025-39682 | Linux Kernel's Improper Check for Exceptional Conditions Allows Remote Attackers to Execute Arbitrary Code or Crash Affected Systems; CISA's September 21st KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-20 | CVE-2025-25249 | Fortinet Multiple Products' Heap-Based Buffer Overflow Allows Remote Attackers to Potentially Execute Arbitrary Code or Crash Affected Devices; CISA's September 12th KEV Deadline Has Passed | 8.1 High | KEV |
| 2026-09-20 | CVE-2026-82078 | PaperCut NG/MF's Unsafe Reflection Allows Remote Attackers to Manipulate Class Loading and Execute Arbitrary Code on the Print Management Server; CISA's September 14th KEV Deadline Has Passed | 9.1 Critical | KEV |
| 2026-09-20 | CVE-2026-72530 | TrueConf Server's Code Injection Vulnerability Allows Remote Attackers to Execute Arbitrary Code on the Video Conferencing Platform; CISA's September 3rd KEV Deadline Has Passed | 9.0 Critical | KEV |
| 2026-09-20 | CVE-2026-72529 | TrueConf Server's Missing Authentication on a Critical Function Allows Unauthenticated Remote Attackers to Access Administrative Capabilities; CISA's August 23rd KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-19 | CVE-2025-40582 | CVE-2025-40582 | 7.8 High | Updated |
| 2026-09-19 | CVE-2025-40581 | CVE-2025-40581 | 7.1 High | Updated |
| 2026-09-19 | CVE-2025-40574 | CVE-2025-40574 | 7.8 High | Updated |
| 2026-09-19 | CVE-2026-20270 | CVE-2026-20270 | 8.6 High | Updated |
| 2026-09-19 | CVE-2026-70468 | CVE-2026-70468 | 8.1 High | Updated |
| 2026-09-19 | CVE-2026-70465 | CVE-2026-70465 | 8.1 High | Updated |
| 2026-09-19 | CVE-2026-70332 | CVE-2026-70332 | 9.6 Critical | Updated |
| 2026-09-19 | CVE-2026-66322 | CVE-2026-66322 | 7.1 High | Updated |
| 2026-09-19 | CVE-2026-66321 | CVE-2026-66321 | 7.4 High | Updated |
| 2026-09-19 | CVE-2026-66318 | CVE-2026-66318 | 8.1 High | Updated |
| 2026-09-19 | CVE-2026-66315 | CVE-2026-66315 | 7.5 High | Updated |
| 2026-09-19 | CVE-2026-66310 | CVE-2026-66310 | 7.7 High | Updated |
| 2026-09-19 | CVE-2026-65802 | CVE-2026-65802 | 7.4 High | Updated |
| 2026-09-19 | CVE-2026-65668 | CVE-2026-65668 | 8.8 High | Updated |
| 2026-09-19 | CVE-2026-65667 | CVE-2026-65667 | 10.0 Critical | Updated |
| 2026-09-19 | CVE-2026-63508 | CVE-2026-63508 | 10.0 Critical | Updated |
| 2026-09-19 | CVE-2026-62918 | CVE-2026-62918 | 7.5 High | Updated |
| 2026-09-19 | CVE-2026-62896 | CVE-2026-62896 | 9.6 Critical | Updated |
| 2026-09-19 | CVE-2026-62873 | CVE-2026-62873 | 9.8 Critical | Updated |
| 2026-09-19 | CVE-2026-62870 | CVE-2026-62870 | 8.8 High | Updated |
| 2026-09-19 | CVE-2026-59115 | CVE-2026-59115 | 9.9 Critical | Updated |
| 2026-09-19 | CVE-2026-58612 | CVE-2026-58612 | 7.4 High | Updated |
| 2026-09-19 | CVE-2026-57105 | CVE-2026-57105 | 8.0 High | Updated |
| 2026-09-19 | CVE-2026-50516 | CVE-2026-50516 | 9.4 Critical | Updated |
| 2026-09-19 | CVE-2026-47623 | CVE-2026-47623 | 8.2 High | Updated |
| 2026-09-19 | CVE-2026-47618 | CVE-2026-47618 | 7.5 High | Updated |
| 2026-09-19 | CVE-2026-47617 | CVE-2026-47617 | 7.5 High | Updated |
| 2026-09-19 | CVE-2026-47616 | CVE-2026-47616 | 7.5 High | Updated |
| 2026-09-19 | CVE-2026-47615 | CVE-2026-47615 | 7.5 High | Updated |
| 2026-09-19 | CVE-2026-47614 | CVE-2026-47614 | 7.5 High | Updated |
| 2026-09-19 | CVE-2026-47613 | CVE-2026-47613 | 7.5 High | Updated |
| 2026-09-19 | CVE-2026-47612 | CVE-2026-47612 | 7.5 High | Updated |
| 2026-09-19 | CVE-2026-26035 | CVE-2026-26035 | 9.8 Critical | Updated |
| 2026-09-19 | CVE-2026-24255 | CVE-2026-24255 | 7.5 High | Updated |
| 2026-09-19 | CVE-2026-24254 | CVE-2026-24254 | 9.8 Critical | Updated |
| 2026-09-19 | CVE-2026-24253 | CVE-2026-24253 | 8.2 High | Updated |
| 2026-09-19 | CVE-2026-20273 | CVE-2026-20273 | 8.6 High | Updated |
| 2026-09-19 | CVE-2026-20272 | CVE-2026-20272 | 9.8 Critical | Updated |
| 2026-09-19 | CVE-2026-20271 | CVE-2026-20271 | 8.6 High | Updated |
| 2026-09-19 | CVE-2026-20269 | CVE-2026-20269 | 8.6 High | Updated |
| 2026-09-19 | CVE-2026-20268 | CVE-2026-20268 | 8.6 High | Updated |
| 2026-09-19 | CVE-2026-20267 | CVE-2026-20267 | 9.0 Critical | Updated |
| 2026-09-18 | CVE-2026-87491 | Google Chromium V8's Out-of-Bounds Write Allows Remote Attackers to Corrupt the JavaScript Engine's Heap and Execute Arbitrary Code via a Crafted Web Page | 8.8 High | KEV |
| 2026-09-18 | CVE-2026-59822 | BerriAI LiteLLM's Improper Authentication Allows Unauthenticated Attackers to Access the AI Model Gateway and Interact with Configured LLM Endpoints Without Credentials | 8.2 High | KEV |
| 2026-09-18 | CVE-2026-58704 | Google Pixel's Improper Authorization Flaw Allows an Attacker with Physical or Local Access to Bypass Permission Controls and Access Protected Device Functions | 8.8 High | KEV |
| 2026-09-18 | CVE-2026-49869 | Kestra OSS's OS Command Injection Flaw Lets Unauthenticated Remote Attackers Execute Arbitrary Commands on the Workflow Orchestration Server with Full System Privileges | 10.0 Critical | KEV |
| 2026-07-28 | CVE-2026-16812 | Arista VeloCloud Orchestrator On-Prem Management Plane Executes Injected OS Commands; CISA's July 30th KEV Deadline Has Passed for Covered Entities | 10.0 Critical | KEV |
| 2026-07-23 | CVE-2026-54420 | LiteSpeed's cPanel Plugin Follows Symlinks Across Security Boundaries to Escalate Privileges; CISA's June 18th KEV Remediation Window Has Closed for Covered Entities | 8.5 High | KEV |
| 2026-07-22 | CVE-2025-48595 | Android Framework's Integer Overflow Enables Code Execution and Local Privilege Escalation; CISA's June 5th KEV Deadline Has Passed | 8.4 High | KEV |
| 2026-07-16 | CVE-2023-4346 | KNX Protocol Connection Authorization Option 1's Overly Restrictive Lockout Mechanism Lets Attackers Purge Devices and Lock Out Authorized Users with a BCU Key; CISA's July 29th KEV Deadline Has Passed | 7.5 High | KEV |
| 2026-07-15 | CVE-2026-56155 | Microsoft Active Directory Federation Services Insufficient Access Control Allows an Authorized Attacker to Elevate Privileges Locally; CISA's July 28th KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-06-17 | CVE-2026-8398 | Daemon Tools Lite Contains Embedded Malicious Code; CISA Added It to KEV with a May 30th Deadline That Has Since Passed for Covered Entities | 9.8 Critical | KEV |
| 2026-06-17 | CVE-2026-7473 | Arista Extensible Operating System Validation Bypass Added to CISA's Known Exploited Vulnerabilities List; Federal Remediation Window for Covered Entities Closed June 23rd | 5.8 Medium | KEV |
| 2026-06-17 | CVE-2026-48027 | Nx Console Developer Tooling Published Packages Contain Embedded Malicious Code; CISA's June 10th KEV Mandate for Covered Entities Has Passed | 9.8 Critical | KEV |
| 2026-06-17 | CVE-2026-45321 | TanStack JavaScript Library Suite Added to CISA's Known Exploited Vulnerabilities Catalog; Federal Remediation Deadline for Covered Entities Was June 10th | 9.6 Critical | KEV |
| 2026-06-17 | CVE-2025-32975 | Quest KACE Systems Management Appliance's Improper Authentication Allows Attackers to Impersonate Legitimate Users Without Valid Credentials; CISA's May 4th KEV Deadline Has Passed | 10.0 Critical | KEV |