| 2026-09-25 | CVE-2026-67279 | MikroTik RouterOS Unauthenticated Session Bypass Carries Federal Remediation Deadline of September 28 | — | KEV |
| 2026-09-25 | CVE-2026-5430 | WSO2 API Gateway Path Traversal Reaches Federal Remediation Deadline of September 27 | — | KEV |
| 2026-09-24 | CVE-2026-9203 | MarkLogic SSRF Flaw Exposes Cloud Instance Credentials to Low-Privilege Users | 8.5 High | Updated |
| 2026-09-24 | CVE-2026-9195 | Crafted Links Let Attackers Hijack MarkLogic Administrator Sessions Through Query Console XSS | 9.3 Critical | Updated |
| 2026-09-24 | CVE-2026-9193 | Low-Privilege Hadoop Role Escalates to Full Control of MarkLogic's Security Database | 9.9 Critical | Updated |
| 2026-09-24 | CVE-2026-9192 | Unauthenticated Attackers Can Impersonate Any MarkLogic User Through ODBC Authentication Bypass | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-9190 | HTTP Request Smuggling Bypasses MarkLogic Authentication and Hijacks Sessions | 9.1 Critical | Updated |
| 2026-09-24 | CVE-2026-9089 | ConnectWise Automate agent trusts unverified plugin and update downloads, fixed in 2026.5 | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-8709 | MarkLogic's REST document-patch API lets low-privileged users seize administrator control | 9.9 Critical | Updated |
| 2026-09-24 | CVE-2026-7557 | Unauthenticated attackers impersonate any MarkLogic administrator through a SAML signature flaw | 9.1 Critical | Updated |
| 2026-09-24 | CVE-2026-7329 | MarkLogic's SQL, SPARQL, and Optic query interfaces open a path from low-privileged access to full admin | 9.9 Critical | Updated |
| 2026-09-24 | CVE-2026-7327 | MarkLogic's document-processing pipeline lets an administrative REST role escalate further, exposing server-side data | 8.1 High | Updated |
| 2026-09-24 | CVE-2026-7326 | A CSRF flaw in MarkLogic's Admin UI lets attackers hijack lured administrators for configuration changes | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-71474 | Red Hat insights-client logs a long-lived OpenShift pull-secret token that local pod-log access can expose | 7.1 High | Updated |
| 2026-09-24 | CVE-2026-68981 | Apache NiFi's gzip request handling bypasses size limits, opening a memory-exhaustion path, fixed in 2.11.0 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-68980 | Apache NiFi's asset-deletion API skips ownership checks across Parameter Contexts, fixed in 2.11.0 | 9.1 Critical | Updated |
| 2026-09-24 | CVE-2026-68979 | Missing authorization on Apache NiFi's Parameter Context updates can trigger code execution, fixed in 2.11.0 | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-68060 | Pre-authentication attackers can exhaust memory in Apache Qpid Broker-J via oversized type handling, fixed in 10.1.0 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-67589 | Apache Qpid ProtonJ2 lets pre-authentication attackers trigger oversized memory allocations, fixed in 1.2.0 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-67588 | Unbounded symbol caching in Apache Qpid ProtonJ2 lets pre-authentication attackers exhaust memory, fixed in 1.2.0 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-67551 | Apache Qpid Proton-Dotnet lets pre-authentication attackers trigger oversized memory allocations, fixed in 1.1.0 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-67465 | Unbounded symbol caching in Apache Qpid Proton-Dotnet lets pre-authentication attackers exhaust memory, fixed in 1.1.0 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-66756 | A critical alternate-path flaw in Apache Tika precedes the 4.0.0-beta-1 fix, CVSS 9.8 | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-66755 | Apache Tika's ISA-Tab parser lets crafted filenames leak arbitrary file contents into extracted text, fixed in 3.3.2 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-66273 | Apache Qpid Proton-J lets pre-authentication attackers trigger oversized memory allocations, fixed in 0.35.0 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-66257 | Unbounded symbol caching in Apache Qpid Proton-J lets pre-authentication attackers exhaust memory, fixed in 0.35.0 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-66015 | A JFrog Platform privilege-escalation flaw grants temporary admin access under admin-provisioned accounts | 7.2 High | New |
| 2026-09-24 | CVE-2026-66014 | An authentication weakness in JFrog Artifactory's internal request processing lets attackers escalate access | 8.8 High | New |
| 2026-09-24 | CVE-2026-65922 | Limited-access JFrog Artifactory users can write to restricted internal metadata under specific conditions | 7.1 High | New |
| 2026-09-24 | CVE-2026-65617 | A deserialization flaw in JFrog Artifactory package handling lets low-privileged users compromise confidentiality, integrity, and availability | 8.8 High | New |
| 2026-09-24 | CVE-2026-65616 | Flawed refresh-token signature validation lets non-admin JFrog users obtain a signed administrator token | 8.8 High | New |
| 2026-09-24 | CVE-2026-62391 | An incomplete fix for a prior Kyuubi flaw still lets clients bypass the local-directory allowlist via Spark config aliases, fixed in 1.12.0 | 8.1 High | Updated |
| 2026-09-24 | CVE-2026-61372 | A path traversal vulnerability in Apache Jena Fuseki is fixed in 6.2.0 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-6066 | ConnectWise Automate's Solution Center allowed unencrypted client-server traffic open to interception, fixed in 2026.4 | 7.1 High | Updated |
| 2026-09-24 | CVE-2026-60413 | An information-exposure flaw in Oracle Outside In Core lets a logged-in attacker take full control, CVSS 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-60412 | Insecure deserialization in Oracle Outside In Core lets a logged-in attacker take full control, CVSS 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-60393 | Unauthenticated network attackers can reach all Oracle Hyperion Infrastructure Technology data over HTTP, CVSS 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-60392 | Insecure deserialization in Oracle's Outside In PDF Export SDK lets a logged-in attacker take full control, CVSS 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-60391 | Unauthenticated network attackers can reach all Oracle Hyperion Financial Reporting data over HTTP, CVSS 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-6023 | Tampered RadFilter state in Telerik UI for ASP.NET AJAX enables server-side remote code execution | 8.1 High | Updated |
| 2026-09-24 | CVE-2026-6022 | Telerik UI for ASP.NET AJAX chunked upload flaw lets attackers bypass size limits and exhaust disk space | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-5483 | Red Hat OpenShift AI's odh-dashboard leaks Kubernetes service account tokens through a NodeJS endpoint | 8.5 High | New |
| 2026-09-24 | CVE-2026-54100 | Red Hat's Windows Machine Config Operator skips SSH host-key checks, letting adjacent attackers capture node bootstrap credentials | 8.3 High | Updated |
| 2026-09-24 | CVE-2026-54099 | A compromised Windows node can forge a cluster-administrator certificate through WMCO's CSR auto-approver, CVSS 8.8 | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-52680 | Path traversal in Apache Kyuubi's REST batch upload lets remote attackers write files outside the intended directory, fixed in 1.12.0 | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-5174 | Improper input validation in Progress MOVEit Automation opens a path to privilege escalation | 7.7 High | Updated |
| 2026-09-24 | CVE-2026-47629 | Improper input validation in NVIDIA Triton Inference Server on Linux can trigger denial of service | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-47628 | Unbounded resource allocation in NVIDIA Triton Inference Server on Linux opens a denial-of-service path | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-47627 | A critical path-traversal flaw in NVIDIA Triton Inference Server on Linux enables denial of service, CVSS 9.8 | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-4740 | Red Hat Advanced Cluster Management lets a managed-cluster admin forge certificates for cross-cluster privilege escalation | 8.2 High | Updated |
| 2026-09-24 | CVE-2026-42017 | An event-handling flaw in JFrog Artifactory exposes privileged authorization material to lower-privileged users | 8.8 High | New |
| 2026-09-24 | CVE-2026-41724 | Stored XSS in VMware Cloud Foundation Operations lets privileged users trigger admin actions via injected scripts | 8.0 High | Updated |
| 2026-09-24 | CVE-2026-41723 | A stored XSS spanning VMware Cloud Foundation Operations and vSphere lets privileged users trigger admin actions via injected scripts | 8.0 High | Updated |
| 2026-09-24 | CVE-2026-41722 | Another stored XSS across VMware Cloud Foundation Operations and vSphere lets privileged users trigger admin actions via injected scripts | 8.0 High | Updated |
| 2026-09-24 | CVE-2026-41702 | A TOCTOU flaw in a VMware Fusion SETUID binary lets local non-admin users escalate to root | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-4048 | Authenticated Command Injection in Progress LoadMaster UI Enables Remote Code Execution | 8.4 High | EPSS-Imminent |
| 2026-09-24 | CVE-2026-40141 | A critical query-injection flaw in BeyondTrust Remote Support lets low-privileged users reach unauthorized resources, CVSS 9.9 | 9.9 Critical | Updated |
| 2026-09-24 | CVE-2026-40140 | Unauthenticated attackers can crash BeyondTrust Remote Support appliances via a network-communication flaw | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-40139 | Critical Pre-Authentication Bypass in BeyondTrust Remote Support Allows Unauthorized Access | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-40138 | BeyondTrust Privileged Remote Access Shares Pre-Authentication Bypass Flaw with Remote Support | 8.1 High | Updated |
| 2026-09-24 | CVE-2026-39815 | SQL Injection in Fortinet FortiDDoS-F 7.2 May Allow Unauthorized Data Access | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-39304 | Apache ActiveMQ NIO SSL Transports Vulnerable to Denial-of-Service via Memory Exhaustion | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-3692 | Low-Privilege OS Command Injection in Progress Flowmon Reporting Component | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-35554 | Race Condition in Apache Kafka Producer Can Silently Deliver Messages to Wrong Topics | 8.7 High | Updated |
| 2026-09-24 | CVE-2026-3519 | Progress LoadMaster API Exposes Authenticated Command Injection for VS Administration Role | 8.4 High | EPSS-Imminent |
| 2026-09-24 | CVE-2026-34487 | Apache Tomcat Cloud Clustering Component Logs Kubernetes Credentials in Plain Text | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-34483 | Improper Output Encoding in Apache Tomcat JsonAccessLogValve Enables Log Injection | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-34478 | Apache Log4j RFC 5424 Layout Vulnerable to Log Injection in Versions 2.21 through 2.25 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-34020 | Apache OpenMeetings REST Login Exposes Credentials in URL Query String | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-33266 | Apache OpenMeetings Uses Default Hard-Coded Encryption Key for Remember-Me Cookies | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-33105 | Critical Authorization Bypass in Microsoft Azure Kubernetes Service Allows Network Privilege Escalation | 10.0 Critical | Updated |
| 2026-09-24 | CVE-2026-32590 | Unsafe Deserialization in Red Hat Quay Resumable Upload Handling | 7.1 High | Updated |
| 2026-09-24 | CVE-2026-32200 | Use-After-Free in Microsoft PowerPoint Enables Local Code Execution | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-32199 | Use-After-Free in Microsoft Office Excel Enables Local Code Execution | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-32198 | Microsoft Office Excel Use-After-Free Lets Local Attacker Execute Code | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-32197 | Local Code Execution via Use-After-Free in Microsoft Office Excel | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-32190 | Use-After-Free in Microsoft Office Enables Local Code Execution | 8.4 High | Updated |
| 2026-09-24 | CVE-2026-32189 | Microsoft Office Excel Carries Additional Use-After-Free Code Execution Risk | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-32188 | Out-of-Bounds Read in Microsoft Office Excel Discloses Information to Local Attackers | 7.1 High | Updated |
| 2026-09-24 | CVE-2026-32186 | Critical SSRF in Microsoft Bing Enables Network-Based Privilege Escalation | 10.0 Critical | Updated |
| 2026-09-24 | CVE-2026-32184 | Deserialization Flaw in Microsoft HPC Pack Allows Authorized User to Escalate Privileges | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-32153 | Use-After-Free in Windows Speech Component Allows Local Privilege Escalation | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-32091 | Race Condition in Microsoft Brokering File System Allows Unauthorized Privilege Escalation | 8.4 High | Updated |
| 2026-09-24 | CVE-2026-29145 | Apache Tomcat CLIENT_CERT Authentication Bypass When Soft Fail Is Disabled | 9.1 Critical | Updated |
| 2026-09-24 | CVE-2026-29129 | Apache Tomcat Fails to Preserve Configured Cipher Preference Order | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-28814 | Apache JSPWiki Renders Wiki Markup Without Authentication, Exposing Sensitive Data | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-28813 | JSON Hijacking in Apache JSPWiki Enables Cross-Site Request Forgery | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-28812 | Apache JSPWiki UserManager Spoofing Flaw Allows Attackers to Escalate Privileges | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-28811 | Apache JSPWiki Leaks Internal Information via Debug Messages | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-27914 | Improper Access Control in Microsoft Management Console Allows Local Privilege Escalation | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-27909 | Use-After-Free in Windows Search Component Allows Authorized Attacker to Escalate Privileges | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-27314 | Apache Cassandra 5.0 CREATE Permission Allows Privilege Escalation in mTLS Environments | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-26181 | Use-After-Free in Microsoft Brokering File System Lets Authorized User Escalate Privileges | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-26170 | Input Validation Flaw in Microsoft PowerShell Allows Local Privilege Escalation | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-26149 | Control Sequence Injection in Microsoft Power Apps Enables Network-Based Spoofing | 9.0 Critical | Updated |
| 2026-09-24 | CVE-2026-26143 | Improper Input Validation in Microsoft PowerShell Allows Unauthorized Security Feature Bypass | 7.8 High | New |
| 2026-09-24 | CVE-2026-24880 | Apache Tomcat Chunk Extension Parsing Allows HTTP Request Smuggling | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-24222 | NVIDIA NeMoClaw Sandbox Initialization Exposes System Information to Remote Attackers | 8.6 High | Updated |
| 2026-09-24 | CVE-2026-24217 | Path Traversal in NVIDIA BioNeMo Core Allows Malicious File to Escape Sandbox | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-24216 | Deserialization of Untrusted Data in NVIDIA BioNeMo Enables Code Execution | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-24214 | Integer Overflow in NVIDIA Triton Inference Server DALI Backend | 8.0 High | Updated |
| 2026-09-24 | CVE-2026-24213 | Out-of-Bounds Read in NVIDIA Triton Inference Server DALI Backend | 8.0 High | Updated |
| 2026-09-24 | CVE-2026-24210 | Integer Overflow in NVIDIA Triton Inference Server Allows Code Execution or Denial of Service | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-24209 | Path Traversal Vulnerability in NVIDIA Triton Inference Server | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-24207 | Critical Authentication Bypass in NVIDIA Triton Inference Server | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-24206 | NVIDIA Triton Inference Server Authentication Bypass via Alternate Path Scores 7.3 | 7.3 High | Updated |
| 2026-09-24 | CVE-2026-24188 | NVIDIA TensorRT Out-of-Bounds Write Scores 8.2 | 8.2 High | Updated |
| 2026-09-24 | CVE-2026-24186 | NVIDIA NVFlare Deserialization of Untrusted Data Scores 8.8 | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-24184 | NVIDIA Cumulus Linux Buffer Overflow Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-24183 | NVIDIA Cumulus Linux Excessive-Privilege Execution Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-24178 | Critical NVIDIA NVFlare Authorization Bypass via User-Controlled Key Scores 9.8 | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-24175 | NVIDIA Triton Inference Server Uncaught Exception Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-24174 | NVIDIA Triton Inference Server Numeric Type Conversion Error Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-24173 | NVIDIA Triton Inference Server Integer Overflow Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-24163 | NVIDIA TensorRT-LLM Deserialization Flaw Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-24156 | NVIDIA Data Loading Library Deserialization Vulnerability Scores 7.3 | 7.3 High | Updated |
| 2026-09-24 | CVE-2026-24146 | NVIDIA Triton Inference Server Oversized Allocation Request Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-23708 | Fortinet FortiSOAR Authentication Flaw Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-23657 | Microsoft Office LTSC Use-After-Free Vulnerability Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-23429 | Linux Kernel IOMMU SVA Use-After-Free in Unbind Path Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-23428 | Critical Linux Kernel ksmbd Use-After-Free in Compound Request Handling Scores 9.8 | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-23427 | Critical Linux Kernel ksmbd Use-After-Free in Durable Handle Replay Scores 9.8 | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-23425 | Linux Kernel KVM arm64 ID Register Initialization Flaw Scores 8.8 | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-23424 | Linux Kernel amdxdna Missing Command Buffer Validation Scores 7.1 | 7.1 High | Updated |
| 2026-09-24 | CVE-2026-23422 | Linux Kernel dpaa2-switch Out-of-Bounds Write from Malformed Interrupt Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-23415 | Linux Kernel Futex Use-After-Free between Key Lookup and VMA Policy Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-23414 | Linux Kernel TLS Memory Leak in Async Decrypt Wait Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-23413 | Linux Kernel clsact Use-After-Free in Init/Destroy Rollback Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-23412 | Linux Kernel Netfilter BPF Use-After-Free in Hook Memory Release Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-23411 | Linux Kernel AppArmor Race Condition Frees i_private Data Early Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-23410 | Linux Kernel AppArmor Race on Rawdata Dereference Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-23408 | Linux Kernel AppArmor Double Free of Namespace Name Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-23407 | Linux Kernel AppArmor Out-of-Bounds Read in DFA Verification Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-22828 | Fortinet FortiManager and FortiAnalyzer Cloud Heap Overflow Scores 8.1 | 8.1 High | Updated |
| 2026-09-24 | CVE-2026-22619 | Eaton Intelligent Power Protector Uncontrolled Search Path Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-22016 | Oracle Java SE JAXP Component Exposes Sensitive Information, Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-22011 | Oracle Applications DBA ADPatch Access Control Weakness Scores 7.6 | 7.6 High | Updated |
| 2026-09-24 | CVE-2026-22010 | Oracle Financial Services Infrastructure Platform Access Control Flaw Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-21997 | Oracle Life Sciences Empirica Signal Access Control Weakness Scores 8.5 | 8.5 High | Updated |
| 2026-09-24 | CVE-2026-21662 | Critical Johnson Controls FMS Employee Unrestricted File Upload Scores 9.8 | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-20160 | Critical Cisco Smart Software Manager On-Prem Resource Exposure Scores 9.8 | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-20155 | Cisco Evolved Programmable Network Manager Missing Authorization Scores 8.0 | 8.0 High | Updated |
| 2026-09-24 | CVE-2026-20151 | Cisco Smart Software Manager On-Prem Leaks Sensitive Data in Transmitted Requests | 7.3 High | Updated |
| 2026-09-24 | CVE-2026-20094 | Cisco UCS Command Injection Scores 8.8 | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-18381 | Red Hat Cost Management Metrics Operator SSRF via Crafted Custom Resource Scores 7.6 | 7.6 High | Updated |
| 2026-09-24 | CVE-2026-18378 | Red Hat Cost Management Metrics Operator SSRF via Arbitrary Upload URL Scores 7.6 | 7.6 High | Updated |
| 2026-09-24 | CVE-2026-17894 | Google Chrome on Linux Use-After-Free in Views via Crafted HTML Scores 8.8 | 8.8 High | New |
| 2026-09-24 | CVE-2026-17877 | Google Chrome on Linux Chromoting Flaw Enables Local Privilege Escalation, Scores 8.4 | 8.4 High | New |
| 2026-09-24 | CVE-2026-17744 | Google Chrome on Linux File Input Flaw Exposes Potential Sandbox Escape, Scores 7.1 | 7.1 High | New |
| 2026-09-24 | CVE-2026-16443 | Red Hat Build of Keycloak Cryptographic Signature Verification Flaw Scores 7.4 | 7.4 High | Updated |
| 2026-09-24 | CVE-2026-0288 | Palo Alto Networks PAN-OS Out-of-Bounds Write Scores 7.5 | 7.5 High | New |
| 2026-09-24 | CVE-2026-0273 | Palo Alto Networks PAN-OS OS Command Injection Scores 7.2 | 7.2 High | New |
| 2026-09-24 | CVE-2026-0272 | Palo Alto Networks PAN-OS Missing Authorization Scores 7.2 | 7.2 High | New |
| 2026-09-24 | CVE-2026-0271 | Palo Alto Networks Prisma Access Agent Permission Misconfiguration Scores 7.8 | 7.8 High | New |
| 2026-09-24 | CVE-2026-0270 | Palo Alto Networks Cortex XSOAR Path Traversal Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-0265 | Palo Alto Networks PAN-OS Authentication Bypass Affects Siemens RUGGEDCOM APE1808, Scores 8.1 | 8.1 High | Updated |
| 2026-09-24 | CVE-2026-0264 | Critical Palo Alto Networks PAN-OS DNS Heap Overflow Affects Siemens RUGGEDCOM APE1808, Scores 9.8 | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-0263 | Critical Palo Alto Networks PAN-OS Out-of-Bounds Write Scores 9.8 | 9.8 Critical | New |
| 2026-09-24 | CVE-2026-0262 | Palo Alto Networks PAN-OS Multiple Denial-of-Service Flaws Affect Siemens RUGGEDCOM APE1808 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-0261 | Palo Alto Networks PAN-OS Command Injection Affects Siemens RUGGEDCOM APE1808, Scores 7.2 | 7.2 High | Updated |
| 2026-09-24 | CVE-2026-0259 | Palo Alto Networks PAN-OS External File Path Control Scores 8.8 | 8.8 High | New |
| 2026-09-24 | CVE-2026-0258 | Palo Alto Networks PAN-OS IKEv2 SSRF Affects Siemens RUGGEDCOM APE1808, Scores 9.1 | 9.1 Critical | Updated |
| 2026-09-24 | CVE-2026-0251 | Palo Alto Networks GlobalProtect Untrusted Search Path Scores 7.8 | 7.8 High | New |
| 2026-09-24 | CVE-2026-0250 | Palo Alto Networks GlobalProtect Out-of-Bounds Write Scores 8.1 | 8.1 High | New |
| 2026-09-24 | CVE-2026-0246 | Palo Alto Networks Prisma Access Agent Missing Authorization Scores 7.8 | 7.8 High | New |
| 2026-09-24 | CVE-2026-0244 | Palo Alto Networks Prisma SD-WAN Certificate Validation Flaw Scores 8.1 | 8.1 High | Updated |
| 2026-09-24 | CVE-2026-0237 | Palo Alto Networks Prisma Browser Alternate Path Protection Flaw Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-0236 | Palo Alto Networks Prisma Browser Code Injection Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-0233 | Palo Alto Networks ADEM Certificate Validation Flaw Scores 8.8 | 8.8 High | Updated |
| 2026-09-24 | CVE-2025-7406 | Nokia MantaRay NM sudo Privilege Escalation Reaches Root, Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2025-65114 | Apache Traffic Server HTTP Request Smuggling Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2025-62188 | Apache DolphinScheduler Sensitive Information Exposure Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2025-61848 | Fortinet FortiManager SQL Injection Scores 7.2 | 7.2 High | Updated |
| 2026-09-24 | CVE-2025-58136 | Apache Traffic Server Incorrect Control Flow Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2025-53681 | Fortinet FortiMail SQL Injection Scores 7.2 | 7.2 High | Updated |
| 2026-09-24 | CVE-2025-33255 | NVIDIA TensorRT-LLM MPI Server Deserialization Flaw Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2025-24818 | Nokia MantaRay NM OS Command Injection in Log Search Scores 8.0 | 8.0 High | Updated |
| 2026-09-24 | CVE-2025-24817 | Nokia MantaRay NM OS Command Injection in Symptom Collector Scores 8.0 | 8.0 High | Updated |
| 2026-09-24 | CVE-2025-24815 | Nokia MantaRay NM Unrestricted File Upload Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2025-14774 | ABB T-MAC Plus Incorrect Authorization Scores 7.4 | 7.4 High | Updated |
| 2026-09-24 | CVE-2025-14773 | ABB T-MAC Plus Cross-Site Scripting Scores 8.0 | 8.0 High | Updated |
| 2026-09-24 | CVE-2025-14772 | ABB T-MAC Plus Authorization Bypass via User-Controlled Key Scores 8.8 | 8.8 High | Updated |
| 2026-09-24 | CVE-2025-14771 | ABB T-MAC Plus Exposes Files to External Parties, Scores 9.9 | 9.9 Critical | Updated |
| 2026-09-24 | CVE-2025-12694 | Forcepoint VPN Client Excessive-Privilege Execution Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2017-20236 | ProSoft ICX35-HWC OS Command Injection via Web UI Scores 9.8 | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2017-20235 | ProSoft ICX35-HWC Authentication Bypass in Web Interface Scores 9.1 | 9.1 Critical | Updated |
| 2026-09-23 | CVE-2026-3517 | Progress LoadMaster OS Command Injection via Geo Administration API Scores 8.4 | 8.4 High | EPSS-Imminent |
| 2026-09-23 | CVE-2026-29146 | Apache Tomcat EncryptInterceptor Padding Oracle Scores 7.5 | 7.5 High | EPSS-Imminent |
| 2026-09-23 | CVE-2026-20180 | Critical Cisco ISE Path Traversal Enables Remote Code Execution, Scores 9.9 | 9.9 Critical | EPSS-Imminent |
| 2026-09-23 | CVE-2026-39813 | Fortinet FortiSandbox Path Traversal Enables Privilege Escalation, Scores 9.8 | 9.8 Critical | EPSS-Imminent |
| 2026-09-23 | CVE-2026-40688 | Fortinet FortiWeb Out-of-Bounds Write Scores 7.2 | 7.2 High | EPSS-Imminent |
| 2026-09-23 | CVE-2026-4670 | Critical Progress MOVEit Automation Authentication Bypass Scores 9.8 | 9.8 Critical | EPSS-Imminent |
| 2026-09-23 | CVE-2026-59309 | Critical VMware vCenter Authentication Bypass in Directory Service Scores 9.8 | 9.8 Critical | EPSS-Imminent |
| 2026-09-23 | CVE-2026-3518 | Progress LoadMaster OS Command Injection via Full-Permission API Scores 8.4 | 8.4 High | EPSS-Imminent |
| 2026-09-23 | CVE-2026-20147 | Critical Cisco ISE and ISE-PIC Command Injection Scores 9.9 | 9.9 Critical | EPSS-Imminent |
| 2026-09-22 | CVE-2026-94127 | F5 BIG-IP APM Heap Overflow in OAuth/Access Policy Configuration Reaches KEV | — | KEV |
| 2026-09-22 | CVE-2026-85102 | Check Point VPN Certificate Validation Bypass Reaches KEV | — | KEV |
| 2026-09-22 | CVE-2026-93952 | Arista VeloCloud Orchestrator Input Validation Flaw Reaches KEV | — | KEV |
| 2026-09-22 | CVE-2026-93616 | Check Point Security Management Server Path Traversal Reaches KEV | — | KEV |
| 2026-09-22 | CVE-2026-31431 | Linux Kernel Resource Transfer Flaw Enables Privilege Escalation, Reaches KEV | — | KEV |
| 2026-09-22 | CVE-2026-8398 | Daemon Tools Lite Embedded Malicious Code Reaches KEV | — | KEV |
| 2026-09-22 | CVE-2024-21182 | Oracle WebLogic Server Reaches KEV for Unauthenticated Network Compromise via T3/IIOP | — | KEV |
| 2026-09-22 | CVE-2026-20262 | Cisco Catalyst SD-WAN Manager Path Traversal Allows File Overwrite, Reaches KEV | — | KEV |
| 2026-09-22 | CVE-2026-34910 | Ubiquiti UniFi OS Command Injection via Network Access Reaches KEV | — | KEV |
| 2026-09-22 | CVE-2021-27137 | DD-WRT UPnP Stack Buffer Overflow Reaches KEV | — | KEV |
| 2026-09-22 | CVE-2024-57726 | CVE-2024-57726: SimpleHelp Missing | — | KEV |
| 2026-09-22 | CVE-2026-48172 | CVE-2026-48172: LiteSpeed cPanel Plugin | — | KEV |
| 2026-09-22 | CVE-2026-56290 | CVE-2026-56290: Joomlack Page Builder | — | KEV |
| 2026-09-22 | CVE-2026-0257 | CVE-2026-0257: Palo Alto Networks PAN-OS | — | KEV |
| 2026-09-22 | CVE-2026-48908 | CVE-2026-48908: JoomShaper SP Page Builder | — | KEV |
| 2026-09-22 | CVE-2026-56291 | CVE-2026-56291: Balbooa Forms Unrestricted | — | KEV |
| 2026-09-22 | CVE-2022-0492 | CVE-2022-0492: Linux Kernel Improper | — | KEV |
| 2026-09-22 | CVE-2026-39987 | CVE-2026-39987: Marimo Remote Code Execution | — | KEV |
| 2026-09-22 | CVE-2024-7399 | CVE-2024-7399: Samsung MagicINFO 9 Server | — | KEV |
| 2026-09-22 | CVE-2026-34926 | CVE-2026-34926: Trend Micro Apex One | — | KEV |
| 2026-09-22 | CVE-2026-20316 | CVE-2026-20316: Cisco Secure Firewall | — | KEV |
| 2026-09-22 | CVE-2026-7473 | CVE-2026-7473: Arista Extensible Operating | — | KEV |
| 2026-09-22 | CVE-2026-48558 | CVE-2026-48558: SimpleHelp Authentication | — | KEV |
| 2026-09-22 | CVE-2026-54420 | CVE-2026-54420: LiteSpeed cPanel Plugin UNIX | — | KEV |
| 2026-09-22 | CVE-2026-48907 | CVE-2026-48907: Widget Factory Joomla Content | — | KEV |
| 2026-09-22 | CVE-2026-35616 | CVE-2026-35616: Fortinet FortiClient EMS | — | KEV |
| 2026-09-22 | CVE-2026-0300 | CVE-2026-0300: Palo Alto Networks PAN-OS | — | KEV |
| 2026-09-22 | CVE-2026-48939 | CVE-2026-48939: iCagenda Unrestricted Upload | — | KEV |
| 2026-09-22 | CVE-2026-20122 | CVE-2026-20122: Cisco Catalyst SD-WAN Manager | — | KEV |
| 2026-09-22 | CVE-2026-63030 | CVE-2026-63030: WordPress Core Interpretation | — | KEV |
| 2026-09-22 | CVE-2026-16812 | CVE-2026-16812: Arista VeloCloud Orchestrator | — | KEV |
| 2026-09-22 | CVE-2026-20128 | CVE-2026-20128: Cisco Catalyst SD-WAN Manager | — | KEV |
| 2026-09-22 | CVE-2026-48027 | CVE-2026-48027: Nx Console Embedded Malicious | — | KEV |
| 2026-09-22 | CVE-2026-15409 | CVE-2026-15409: SonicWall SMA1000 Appliances | — | KEV |
| 2026-09-22 | CVE-2026-60137 | CVE-2026-60137: WordPress Core SQL Injection | — | KEV |
| 2026-09-22 | CVE-2026-20230 | CVE-2026-20230: Cisco Unified Communications | — | KEV |
| 2026-09-22 | CVE-2009-0238 | CVE-2009-0238: Microsoft Office Remote Code | — | KEV |
| 2026-09-22 | CVE-2026-45321 | CVE-2026-45321: TanStack Unspecified | — | KEV |
| 2026-09-22 | CVE-2026-20133 | CVE-2026-20133: Cisco Catalyst SD-WAN Manager | — | KEV |
| 2026-09-22 | CVE-2026-28318 | CVE-2026-28318: SolarWinds Serv-U | — | KEV |
| 2026-09-22 | CVE-2026-42897 | CVE-2026-42897: Microsoft Exchange Server | — | KEV |
| 2026-09-22 | CVE-2010-0806 | CVE-2010-0806: Microsoft Internet Explorer | — | KEV |
| 2026-09-22 | CVE-2026-34197 | CVE-2026-34197: Apache ActiveMQ Improper | — | KEV |
| 2026-09-22 | CVE-2025-2749 | CVE-2025-2749: Kentico Xperience Path | — | KEV |
| 2026-09-22 | CVE-2026-25089 | CVE-2026-25089: Fortinet FortiSandbox OS | — | KEV |
| 2026-09-22 | CVE-2023-36424 | CVE-2023-36424: Microsoft Windows | — | KEV |
| 2026-09-22 | CVE-2025-60710 | CVE-2025-60710: Microsoft Windows Link | — | KEV |
| 2026-09-22 | CVE-2026-39808 | CVE-2026-39808: Fortinet FortiSandbox OS | — | KEV |
| 2026-09-22 | CVE-2026-12569 | CVE-2026-12569: PTC Windchill and FlexPLM | — | KEV |
| 2026-09-22 | CVE-2026-50751 | CVE-2026-50751: Check Point Security Gateway | — | KEV |
| 2026-09-22 | CVE-2026-15410 | CVE-2026-15410: SonicWall SMA1000 Appliances | — | KEV |
| 2026-09-22 | CVE-2008-4128 | CVE-2008-4128: Cisco IOS Cross-Site Request | — | KEV |
| 2026-09-22 | CVE-2012-1854 | CVE-2012-1854: Microsoft Visual Basic for | — | KEV |
| 2026-09-22 | CVE-2026-56155 | CVE-2026-56155: Microsoft Active Directory | — | KEV |
| 2026-09-22 | CVE-2026-34908 | CVE-2026-34908: Ubiquiti UniFi OS Improper | — | KEV |
| 2026-09-22 | CVE-2026-1340 | CVE-2026-1340: Ivanti Endpoint Manager | — | KEV |
| 2026-09-22 | CVE-2024-1708 | CVE-2024-1708: ConnectWise ScreenConnect | — | KEV |
| 2026-09-22 | CVE-2025-48595 | CVE-2025-48595: Android Framework Integer | — | KEV |
| 2026-09-22 | CVE-2026-34909 | CVE-2026-34909: Ubiquiti UniFi OS Path | — | KEV |
| 2026-09-22 | CVE-2026-33825 | CVE-2026-33825: Microsoft Defender | — | KEV |
| 2026-09-22 | CVE-2023-4346 | CVE-2023-4346: KNX Association KNX Protocol | — | KEV |
| 2026-09-22 | CVE-2025-68686 | CVE-2025-68686: Fortinet FortiOS Exposure of | — | KEV |
| 2026-09-22 | CVE-2026-41091 | CVE-2026-41091: Microsoft Defender Link | — | KEV |
| 2026-09-22 | CVE-2026-10520 | CVE-2026-10520: Ivanti Sentry OS Command | — | KEV |
| 2026-09-22 | CVE-2023-21529 | CVE-2023-21529: Microsoft Exchange Server | — | KEV |
| 2026-09-22 | CVE-2026-9082 | CVE-2026-9082: Drupal Core SQL Injection | — | KEV |
| 2026-09-22 | CVE-2009-1537 | CVE-2009-1537: Microsoft DirectX NULL Byte | — | KEV |
| 2026-09-22 | CVE-2026-21643 | CVE-2026-21643: Fortinet FortiClient EMS SQL | — | KEV |
| 2026-09-22 | CVE-2026-45247 | CVE-2026-45247: Mirasvit Full Page Cache | — | KEV |
| 2026-09-22 | CVE-2026-41940 | CVE-2026-41940: WebPros cPanel & WHM and WP2 | — | KEV |
| 2026-09-22 | CVE-2026-20182 | CVE-2026-20182: Cisco Catalyst SD-WAN | — | KEV |
| 2026-09-22 | CVE-2026-20245 | CVE-2026-20245: Cisco Catalyst SD-WAN Manager | — | KEV |
| 2026-09-22 | CVE-2024-57728 | CVE-2024-57728: SimpleHelp Path Traversal | — | KEV |
| 2026-09-22 | CVE-2008-4250 | CVE-2008-4250: Microsoft Windows Buffer | — | KEV |
| 2026-09-22 | CVE-2026-6973 | CVE-2026-6973: Ivanti Endpoint Manager | — | KEV |
| 2026-09-22 | CVE-2026-20253 | CVE-2026-20253: Splunk Enterprise Missing | — | KEV |
| 2026-09-22 | CVE-2026-35273 | CVE-2026-35273: Oracle PeopleSoft Enterprise | — | KEV |
| 2026-09-22 | CVE-2026-45498 | CVE-2026-45498: Microsoft Defender Denial of | — | KEV |
| 2026-09-22 | CVE-2025-29635 | CVE-2025-29635: D-Link DIR-823X Command | — | KEV |
| 2026-09-22 | CVE-2026-46817 | CVE-2026-46817: Oracle E-Business Suite | — | KEV |
| 2026-09-22 | CVE-2010-0249 | CVE-2010-0249: Microsoft Internet Explorer | — | KEV |
| 2026-09-22 | CVE-2025-67038 | CVE-2025-67038: Lantronix EDS5000 Code | — | KEV |
| 2026-09-22 | CVE-2025-32975 | CVE-2025-32975: Quest KACE Systems Management | — | KEV |
| 2026-09-22 | CVE-2026-16232 | CVE-2026-16232: Check Point SmartConsole | — | KEV |
| 2026-09-22 | CVE-2026-32202 | CVE-2026-32202: Microsoft Windows Protection | — | KEV |
| 2026-09-21 | CVE-2026-7273 | CVE-2026-7273: Zyxel GS1900 Series Switches | — | KEV |
| 2026-09-19 | CVE-2025-40582 | CVE-2025-40582 | 7.8 High | Updated |
| 2026-09-19 | CVE-2025-40581 | CVE-2025-40581 | 7.1 High | Updated |
| 2026-09-19 | CVE-2025-40574 | CVE-2025-40574 | 7.8 High | Updated |
| 2026-09-19 | CVE-2026-20270 | CVE-2026-20270 | 8.6 High | Updated |
| 2026-09-19 | CVE-2026-0301 | CVE-2026-0301 | 7.5 High | Updated |
| 2026-09-19 | CVE-2026-0299 | CVE-2026-0299 | 7.8 High | Updated |
| 2026-09-19 | CVE-2026-70468 | CVE-2026-70468 | 8.1 High | Updated |
| 2026-09-19 | CVE-2026-70465 | CVE-2026-70465 | 8.1 High | Updated |
| 2026-09-19 | CVE-2026-70332 | CVE-2026-70332 | 9.6 Critical | Updated |
| 2026-09-19 | CVE-2026-66322 | CVE-2026-66322 | 7.1 High | Updated |
| 2026-09-19 | CVE-2026-66321 | CVE-2026-66321 | 7.4 High | Updated |
| 2026-09-19 | CVE-2026-66318 | CVE-2026-66318 | 8.1 High | Updated |
| 2026-09-19 | CVE-2026-66315 | CVE-2026-66315 | 7.5 High | Updated |
| 2026-09-19 | CVE-2026-66310 | CVE-2026-66310 | 7.7 High | Updated |
| 2026-09-19 | CVE-2026-65802 | CVE-2026-65802 | 7.4 High | Updated |
| 2026-09-19 | CVE-2026-65668 | CVE-2026-65668 | 8.8 High | Updated |
| 2026-09-19 | CVE-2026-65667 | CVE-2026-65667 | 10.0 Critical | Updated |
| 2026-09-19 | CVE-2026-63508 | CVE-2026-63508 | 10.0 Critical | Updated |
| 2026-09-19 | CVE-2026-62918 | CVE-2026-62918 | 7.5 High | Updated |
| 2026-09-19 | CVE-2026-62896 | CVE-2026-62896 | 9.6 Critical | Updated |
| 2026-09-19 | CVE-2026-62873 | CVE-2026-62873 | 9.8 Critical | Updated |
| 2026-09-19 | CVE-2026-62870 | CVE-2026-62870 | 8.8 High | Updated |
| 2026-09-19 | CVE-2026-59115 | CVE-2026-59115 | 9.9 Critical | Updated |
| 2026-09-19 | CVE-2026-58612 | CVE-2026-58612 | 7.4 High | Updated |
| 2026-09-19 | CVE-2026-57105 | CVE-2026-57105 | 8.0 High | Updated |
| 2026-09-19 | CVE-2026-50516 | CVE-2026-50516 | 9.4 Critical | Updated |
| 2026-09-19 | CVE-2026-47623 | CVE-2026-47623 | 8.2 High | Updated |
| 2026-09-19 | CVE-2026-47618 | CVE-2026-47618 | 7.5 High | Updated |
| 2026-09-19 | CVE-2026-47617 | CVE-2026-47617 | 7.5 High | Updated |
| 2026-09-19 | CVE-2026-47616 | CVE-2026-47616 | 7.5 High | Updated |
| 2026-09-19 | CVE-2026-47615 | CVE-2026-47615 | 7.5 High | Updated |
| 2026-09-19 | CVE-2026-47614 | CVE-2026-47614 | 7.5 High | Updated |
| 2026-09-19 | CVE-2026-47613 | CVE-2026-47613 | 7.5 High | Updated |
| 2026-09-19 | CVE-2026-47612 | CVE-2026-47612 | 7.5 High | Updated |
| 2026-09-19 | CVE-2026-26035 | CVE-2026-26035 | 9.8 Critical | Updated |
| 2026-09-19 | CVE-2026-24255 | CVE-2026-24255 | 7.5 High | Updated |
| 2026-09-19 | CVE-2026-24254 | CVE-2026-24254 | 9.8 Critical | Updated |
| 2026-09-19 | CVE-2026-24253 | CVE-2026-24253 | 8.2 High | Updated |
| 2026-09-19 | CVE-2026-20301 | CVE-2026-20301 | 8.6 High | Updated |
| 2026-09-19 | CVE-2026-20273 | CVE-2026-20273 | 8.6 High | Updated |
| 2026-09-19 | CVE-2026-20272 | CVE-2026-20272 | 9.8 Critical | Updated |
| 2026-09-19 | CVE-2026-20271 | CVE-2026-20271 | 8.6 High | Updated |
| 2026-09-19 | CVE-2026-20269 | CVE-2026-20269 | 8.6 High | Updated |
| 2026-09-19 | CVE-2026-20268 | CVE-2026-20268 | 8.6 High | Updated |
| 2026-09-19 | CVE-2026-20267 | CVE-2026-20267 | 9.0 Critical | Updated |
| 2026-09-19 | CVE-2026-20200 | CVE-2026-20200 | 8.8 High | EPSS-Imminent |
| 2026-09-19 | CVE-2026-20124 | CVE-2026-20124 | 7.7 High | Updated |
| 2026-09-19 | CVE-2026-0298 | CVE-2026-0298 | 8.1 High | Updated |
| 2026-09-18 | CVE-2026-0297 | CVE-2026-0297 | 8.1 High | Updated |
| 2026-09-18 | CVE-2026-0296 | CVE-2026-0296 | 7.4 High | Updated |
| 2026-09-18 | CVE-2026-0295 | CVE-2026-0295 | 7.0 High | Updated |
| 2026-09-18 | CVE-2026-0294 | CVE-2026-0294 | 7.8 High | Updated |
| 2026-09-18 | CVE-2026-60004 | CVE-2026-60004: Gitea Code Injection | 9.8 Critical | KEV |
| 2026-09-18 | CVE-2015-3246 | CVE-2015-3246: Red Hat Libuser Race | 5.1 Medium | KEV |
| 2026-09-18 | CVE-2026-72898 | CVE-2026-72898: Metabase SQL Injection | 10.0 Critical | KEV |
| 2026-09-18 | CVE-2026-33824 | CVE-2026-33824: Microsoft Internet Key | 9.8 Critical | KEV |
| 2026-09-18 | CVE-2026-65400 | CVE-2026-65400: Apple macOS Improper | 9.8 Critical | KEV |
| 2026-09-18 | CVE-2026-53362 | CVE-2026-53362: Linux Kernel Unspecified | 7.8 High | KEV |
| 2026-09-18 | CVE-2026-63077 | CVE-2026-63077: JetBrains TeamCity | 9.8 Critical | KEV |
| 2026-09-18 | CVE-2023-49105 | CVE-2023-49105: ownCloud Improper | 9.8 Critical | KEV |
| 2026-09-18 | CVE-2022-0995 | CVE-2022-0995: Linux Kernel Out-of-Bounds | 7.8 High | KEV |
| 2026-09-18 | CVE-2019-1068 | CVE-2019-1068: Microsoft SQL Server Remote | 8.8 High | KEV |
| 2026-09-18 | CVE-2026-20349 | CVE-2026-20349: Cisco Secure Firewall | 8.6 High | KEV |
| 2026-09-18 | CVE-2026-9198 | CVE-2026-9198: IBM Langflow Code Injection | 9.8 Critical | KEV |
| 2026-09-18 | CVE-2026-21962 | CVE-2026-21962: Oracle HTTP Server and Oracle | 10.0 Critical | KEV |
| 2026-09-18 | CVE-2026-82078 | CVE-2026-82078: PaperCut NG/MF Unsafe | 9.1 Critical | KEV |
| 2026-09-18 | CVE-2026-55040 | CVE-2026-55040: Microsoft SharePoint Weak | 9.1 Critical | KEV |
| 2026-09-18 | CVE-2026-73570 | CVE-2026-73570: Zimbra Collaboration Suite | 8.9 High | KEV |
| 2026-09-18 | CVE-2026-59310 | CVE-2026-59310: Broadcom VMware vCenter Path | 9.8 Critical | KEV |
| 2026-09-18 | CVE-2026-81578 | CVE-2026-81578: PaperCut NG/MF Missing | 9.8 Critical | KEV |
| 2026-09-18 | CVE-2026-72530 | CVE-2026-72530: TrueConf Server Code | 9.0 Critical | KEV |
| 2026-09-18 | CVE-2021-23758 | CVE-2021-23758: Ajax.NET Professional | 8.1 High | KEV |
| 2026-09-18 | CVE-2026-64849 | CVE-2026-64849: MLflow Server-Side Request | 9.3 Critical | KEV |
| 2026-09-18 | CVE-2026-68820 | CVE-2026-68820: Microsoft Windows Ancillary | 7.0 High | KEV |
| 2026-09-18 | CVE-2025-62593 | CVE-2025-62593: Ray-Project Ray Code | 8.8 High | KEV |
| 2026-09-18 | CVE-2026-34486 | CVE-2026-34486: Apache Tomcat Missing | 7.5 High | KEV |
| 2026-09-18 | CVE-2026-72529 | CVE-2026-72529: TrueConf Server Missing | 9.8 Critical | KEV |
| 2026-09-18 | CVE-2026-8037 | CVE-2026-8037: Progress LoadMaster Command | 9.6 Critical | KEV |
| 2026-09-18 | CVE-2015-5287 | CVE-2015-5287: Red Hat Automatic Bug | 7.8 High | KEV |
| 2026-09-18 | CVE-2025-39682 | CVE-2025-39682: Linux Kernel Improper Check | 9.8 Critical | KEV |
| 2026-09-18 | CVE-2026-53266 | CVE-2026-53266: Linux Kernel Out-of-Bounds | 8.8 High | KEV |
| 2026-09-18 | CVE-2025-39964 | CVE-2025-39964: Linux Kernel Race Condition | 7.8 High | KEV |
| 2026-09-17 | CVE-2026-76460 | CVE-2026-76460: Cisco Identity Services | 10.0 Critical | KEV |
| 2026-09-17 | CVE-2026-49869 | CVE-2026-49869: Kestra OSS OS Command | 10.0 Critical | KEV |
| 2026-09-17 | CVE-2026-9586 | CVE-2026-9586: Sangoma Switchvox SQL | 9.8 Critical | KEV |
| 2026-09-17 | CVE-2026-87491 | CVE-2026-87491: Google Chromium V8 Out of | 8.8 High | KEV |
| 2026-09-17 | CVE-2025-25249 | CVE-2025-25249: Fortinet Multiple Products | 8.1 High | KEV |
| 2026-09-17 | CVE-2026-75650 | CVE-2026-75650: Adobe Commerce and Magento | 10.0 Critical | KEV |
| 2026-09-17 | CVE-2026-87886 | CVE-2026-87886: Acronis Backup Incorrect | 7.8 High | KEV |
| 2026-09-17 | CVE-2026-42016 | CVE-2026-42016: JFrog Artifactory Incorrect | 8.1 High | KEV |
| 2026-09-17 | CVE-2026-58704 | CVE-2026-58704: Google Pixel Improper | 8.8 High | KEV |
| 2026-09-17 | CVE-2026-42018 | CVE-2026-42018: JFrog Artifactory Improper | 7.5 High | KEV |
| 2026-09-17 | CVE-2026-67277 | CVE-2026-67277: MikroTik RouterOS Missing | 8.2 High | KEV |
| 2026-09-17 | CVE-2026-85046 | CVE-2026-85046: Google Chromium V8 Type | 8.8 High | KEV |
| 2026-09-17 | CVE-2026-76461 | CVE-2026-76461: Cisco Secure Email Gateway | 9.8 Critical | KEV |
| 2026-09-17 | CVE-2026-86218 | CVE-2026-86218: N-able N-central Static Code | 9.8 Critical | KEV |
| 2026-09-17 | CVE-2026-85706 | CVE-2026-85706: GitLab Community Edition and | 10.0 Critical | KEV |
| 2026-09-17 | CVE-2026-20079 | CVE-2026-20079: Cisco Firewall Management | 10.0 Critical | KEV |
| 2026-09-17 | CVE-2026-83549 | CVE-2026-83549: SonicWall SMA1000 Appliances | 7.8 High | KEV |
| 2026-09-17 | CVE-2026-85880 | CVE-2026-85880: Microsoft Windows Heap-Based | 7.8 High | KEV |
| 2026-09-17 | CVE-2026-48710 | CVE-2026-48710: Kludex Starlette HTTP | 6.5 Medium | KEV |
| 2026-09-17 | CVE-2026-59822 | CVE-2026-59822: BerriAI LiteLLM Improper | 8.2 High | KEV |
| 2026-09-17 | CVE-2026-83548 | CVE-2026-83548: SonicWall SMA1000 Appliances | 10.0 Critical | KEV |
| 2026-09-17 | CVE-2026-19490 | CVE-2026-19490: Citrix NetScaler | 9.8 Critical | KEV |
| 2026-09-17 | CVE-2026-82329 | CVE-2026-82329: JFrog Artifactory Improper | 9.8 Critical | KEV |
| 2026-09-17 | CVE-2026-81963 | CVE-2026-81963: Microsoft Windows Link | 7.8 High | KEV |
| 2026-09-17 | CVE-2026-86060 | CVE-2026-86060: MikroTik RouterOS Improper | 9.8 Critical | KEV |
| 2026-09-13 | CVE-2026-84869 | ConnectWise ScreenConnect Missing Authorization and Privilege Management Vulnerabilities (CISA KEV) | 9.9 Critical | KEV |