• Skip to primary navigation
  • Skip to main content
  • Skip to footer
Sq Magazine LogoSQ Magazine

Smarter Insights for a Fast-Moving Digital World

  • Latest News
  • Statistics
  • About
  • Contact
Subscribe

SQ Magazine » The Threat Index » CISA KEV Tracker

CISA KEV Tracker

Every vulnerability CISA has cataloged as exploited in the wild, mirrored weekly from the agency's own feed: what was added when, the remediation deadline CISA set, and how the year's entries distribute across vendors.

242 records · updated through 25 Sep 2026 · next review by 2 Oct 2026

Sofia Ramirez
Maintained By
Sofia Ramirez
Sofia Ramirez
Senior Tech Writer • 619 Articles
Sofia Ramirez is a technology and cybersecurity writer at SQ Magazine. With a keen eye on emerging threats and innovations, she helps reader...
LATEST POSTS:
ServiceNow Security Alert: Patch These Critical Flaws
Microsoft Will Deprecate Windows Deployment Services After Server 2025
Manus AI Agent Exposed by Prompt-Injection Bug

At a glance

Most recent addition
CVE-2026-87902 · 25 Sep 2026
Next federal due date
CVE-2026-71362 · 27 Sep 2026
Most recent ransomware-linked addition
CVE-2026-59310 · 18 Aug 2026

Latest change Deterministic sync against CISA catalog 2026.09.25: 3 added, 0 revised, 0 removed. (25 Sep 2026) All changes

All records

242 vulnerabilities, newest addition first. Filter or search below.

What is in scope Every entry CISA added to the Known Exploited Vulnerabilities catalog during 2026. Earlier additions remain in CISA's catalog and are not carried here.

242 entries across 94 vendors. Microsoft accounts for 39 of them, 16% of the catalog year to date. CISA records 27 as known ransomware-campaign use and 215 as unknown, which states that the use is unestablished rather than absent. CISA gives federal agencies a median of 14 days to remediate a listed flaw, ranging from 2 to 21. That window is how urgently it treats what it lists.

Entries as published in CISA’s Known Exploited Vulnerabilities catalog, verbatim; the due date is the federal remediation deadline CISA set for that entry, under the directive in force when it was added. Exploitation status is CISA’s statement, not our assessment. Informational only, not remediation advice.
CVE Vendor / Product Added Due (federal) Ransomware use Source Record detail
CVE-2026-87902 WordPress WordPress Core 25 Sep 2026 28 Sep 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗
Vulnerability
WordPress Core Remote File Inclusion Vulnerability
CISA description
WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local `.php` file outside the active theme directories, leading to remote code execution.
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVE record
CVE-2026-87902 ↗
Primary source
CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗
Last confirmed
25 Sep 2026
Recent change
Added from CISA catalog 2026.09.25 by the deterministic sync.
CVE-2026-65660 Microsoft Microsoft SharePoint 25 Sep 2026 28 Sep 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗
Vulnerability
Microsoft SharePoint Code Injection Vulnerability
CISA description
Microsoft SharePoint contains a code injection vulnerability which could allow an authorized attacker to execute code over a network.
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVE record
CVE-2026-65660 ↗
Primary source
CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗
Last confirmed
25 Sep 2026
Recent change
Added from CISA catalog 2026.09.25 by the deterministic sync.
CVE-2026-67279 MikroTik MikroTik RouterOS 25 Sep 2026 28 Sep 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗
Vulnerability
Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability
CISA description
Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060.
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVE record
CVE-2026-67279 ↗
Primary source
CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗
Last confirmed
25 Sep 2026
Recent change
Added from CISA catalog 2026.09.25 by the deterministic sync.
CVE-2026-71362 Adobe Adobe Commerce and Magento 24 Sep 2026 27 Sep 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗
Vulnerability
Adobe Commerce and Magento Incorrect Authorization Vulnerability
CISA description
Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction.
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVE record
CVE-2026-71362 ↗
Primary source
CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗
Last confirmed
25 Sep 2026
Recent change
Added from CISA catalog 2026.09.24 by the deterministic sync.
CVE-2026-5430 WSO2 WSO2 Multiple Products 24 Sep 2026 27 Sep 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗
Vulnerability
WSO2 Multiple Products Path Traversal Vulnerability
CISA description
WSO2 API Control Plane, API Manager, Traffic Manager & Universal Gateway contain a path traversal vulnerability that could allow for unrestricted file upload and lead to remote code execution.
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVE record
CVE-2026-5430 ↗
Primary source
CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗
Last confirmed
25 Sep 2026
Recent change
Added from CISA catalog 2026.09.24 by the deterministic sync.
CVE-2026-85102 Check Point Check Point Multiple Products 22 Sep 2026 25 Sep 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗
Vulnerability
Check Point Multiple Products Improper Certificate Validation Vulnerability
CISA description
Check Point Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN contain an improper certificate validation vulnerability which could allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVE record
CVE-2026-85102 ↗
Primary source
CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗
Last confirmed
25 Sep 2026
Recent change
Added from CISA catalog 2026.09.22 by the deterministic sync.
CVE-2026-93616 Check Point Check Point Multiple Products 22 Sep 2026 25 Sep 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗
Vulnerability
Check Point Multiple Products Path Traversal Vulnerability
CISA description
Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent contain a path traversal vulnerability that allows an unauthenticated attacker to upload and execute arbitrary scripts.
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVE record
CVE-2026-93616 ↗
Primary source
CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗
Last confirmed
25 Sep 2026
Recent change
Added from CISA catalog 2026.09.22 by the deterministic sync.
CVE-2026-94127 F5 F5 BIG-IP APM 22 Sep 2026 25 Sep 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗
Vulnerability
F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability
CISA description
F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unauthenticated attacker to perform remote code execution.
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVE record
CVE-2026-94127 ↗
Primary source
CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗
Last confirmed
25 Sep 2026
Recent change
Added from CISA catalog 2026.09.22 by the deterministic sync.
CVE-2026-93952 Arista Arista VeloCloud Orchestrator 22 Sep 2026 25 Sep 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗
Vulnerability
Arista VeloCloud Orchestrator Improper Input Validation Vulnerability
CISA description
Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVE record
CVE-2026-93952 ↗
Primary source
CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗
Last confirmed
25 Sep 2026
Recent change
Added from CISA catalog 2026.09.22 by the deterministic sync.
CVE-2026-7273 Zyxel Zyxel GS1900 Series Switches 21 Sep 2026 24 Sep 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗
Vulnerability
Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability
CISA description
Zyxel GS1900 series switches contain a stack-based buffer overflow vulnerability in the CGI program which could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVE record
CVE-2026-7273 ↗
Primary source
CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗
Last confirmed
25 Sep 2026
Recent change
Added from CISA catalog 2026.09.21 by the deterministic sync.
CVE-2025-39682 Linux Linux Kernel 18 Sep 2026 21 Sep 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗
Vulnerability
Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability
CISA description
Linux Kernel contains an improper check for unusual or exceptional conditions vulnerability in the TLS receive path which allows a zero-length record retrieved from the rx_list to bypass the intended recvmsg() record-type handling, potentially causing subsequent TLS records to be processed using incorrect zero-copy and queuing assumptions. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVE record
CVE-2025-39682 ↗
Primary source
CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗
Last confirmed
25 Sep 2026
Recent change
Added from CISA catalog 2026.09.18 by the deterministic sync.
CVE-2026-53266 Linux Linux Kernel 18 Sep 2026 21 Sep 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗
Vulnerability
Linux Kernel Out-of-Bounds Write Vulnerability
CISA description
Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVE record
CVE-2026-53266 ↗
Primary source
CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗
Last confirmed
25 Sep 2026
Recent change
Added from CISA catalog 2026.09.18 by the deterministic sync.
CVE-2025-39964 Linux Linux Kernel 18 Sep 2026 21 Sep 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗
Vulnerability
Linux Kernel Race Condition Vulnerability
CISA description
Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state.
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVE record
CVE-2025-39964 ↗
Primary source
CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗
Last confirmed
25 Sep 2026
Recent change
Added from CISA catalog 2026.09.18 by the deterministic sync.
CVE-2026-87886 Acronis Acronis Backup 16 Sep 2026 19 Sep 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗
Vulnerability
Acronis Backup Incorrect Default Permissions Vulnerability
CISA description
Acronis Backup plugin for cPanel & WHM and extension for Plesk contains an incorrect default permissions vulnerability that could allow for privilege escalation.
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVE record
CVE-2026-87886 ↗
Primary source
CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗
Last confirmed
25 Sep 2026
Recent change
Added from CISA catalog 2026.09.16 by the deterministic sync.
CVE-2026-76460 Cisco Cisco Identity Services Engine 16 Sep 2026 19 Sep 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗
Vulnerability
Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability
CISA description
Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVE record
CVE-2026-76460 ↗
Primary source
CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗
Last confirmed
25 Sep 2026
Recent change
Added from CISA catalog 2026.09.16 by the deterministic sync.
CVE-2026-58704 Google Google Pixel 16 Sep 2026 19 Sep 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗
Vulnerability
Google Pixel Improper Authorization Vulnerability
CISA description
Google Pixel devices contain an improper authorization vulnerability in the cellular modem. A logic error may allow an attacker to bypass permission checks and escalate privileges.
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVE record
CVE-2026-58704 ↗
Primary source
CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗
Last confirmed
25 Sep 2026
Recent change
Added from CISA catalog 2026.09.16 by the deterministic sync.
CVE-2026-76461 Cisco Cisco Secure Email Gateway 14 Sep 2026 17 Sep 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗
Vulnerability
Cisco Secure Email Gateway SQL Injection Vulnerability
CISA description
Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVE record
CVE-2026-76461 ↗
Primary source
CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗
Last confirmed
25 Sep 2026
Recent change
Added from CISA catalog 2026.09.14 by the deterministic sync.
CVE-2026-85706 GitLab GitLab Community Edition and Enterprise Edition 11 Sep 2026 14 Sep 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗
Vulnerability
GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability
CISA description
GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability that allows an unauthenticated user to read arbitrary files due to an improper path confinement and missing authentication enforcement in the repository commits API.
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVE record
CVE-2026-85706 ↗
Primary source
CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗
Last confirmed
25 Sep 2026
Recent change
Added from CISA catalog 2026.09.11 by the deterministic sync.
CVE-2026-42018 JFrog JFrog Artifactory 11 Sep 2026 25 Sep 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗
Vulnerability
JFrog Artifactory Improper Authentication Vulnerability
CISA description
JFrog Artifactory contains an improper authentication vulnerability that could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVE record
CVE-2026-42018 ↗
Primary source
CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗
Last confirmed
25 Sep 2026
Recent change
Added from CISA catalog 2026.09.11 by the deterministic sync.
CVE-2026-42016 JFrog JFrog Artifactory 11 Sep 2026 25 Sep 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗
Vulnerability
JFrog Artifactory Incorrect Authorization Vulnerability
CISA description
JFrog Artifactory contains an incorrect authorization vulnerability that leads to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVE record
CVE-2026-42016 ↗
Primary source
CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗
Last confirmed
25 Sep 2026
Recent change
CISA revised description in catalog 2026.09.16; mirrored by the deterministic sync.
CVE-2026-84869 ConnectWise ConnectWise ScreenConnect 11 Sep 2026 14 Sep 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗
Vulnerability
ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
CISA description
ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to transfer and execute files through an active remote session without authorization or host confirmation.
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVE record
CVE-2026-84869 ↗
Primary source
CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗
Last confirmed
25 Sep 2026
Recent change
CISA revised description in catalog 2026.09.16; mirrored by the deterministic sync.
CVE-2026-67277 MikroTik MikroTik RouterOS 10 Sep 2026 13 Sep 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗
Vulnerability
MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
CISA description
MikroTik RouterOS contains a missing authentication for critical function vulnerability which allows kernel memory disclosure and denial of service in the btest service.
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVE record
CVE-2026-67277 ↗
Primary source
CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗
Last confirmed
25 Sep 2026
Recent change
CISA revised description in catalog 2026.09.16; mirrored by the deterministic sync.
CVE-2026-86060 MikroTik MikroTik RouterOS 10 Sep 2026 13 Sep 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗
Vulnerability
MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
CISA description
MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacker to change the trusted RouterOS policy mask, leading to privilege escalation.
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVE record
CVE-2026-86060 ↗
Primary source
CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗
Last confirmed
25 Sep 2026
Recent change
CISA revised description in catalog 2026.09.16; mirrored by the deterministic sync.
CVE-2026-20079 Cisco Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewa… 9 Sep 2026 12 Sep 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗
Vulnerability
Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability
CISA description
Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication Bypass using an alternate path or channel vulnerability that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVE record
CVE-2026-20079 ↗
Primary source
CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗
Last confirmed
25 Sep 2026
Recent change
Added from CISA catalog 2026.09.09 by the deterministic sync.
CVE-2026-87491 Google Google Chromium V8 9 Sep 2026 23 Sep 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗
Vulnerability
Google Chromium V8 Out of Bounds Write Vulnerability
CISA description
Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVE record
CVE-2026-87491 ↗
Primary source
CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗
Last confirmed
25 Sep 2026
Recent change
Added from CISA catalog 2026.09.09 by the deterministic sync.
CVE-2025-25249 Fortinet Fortinet Multiple Products 9 Sep 2026 12 Sep 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2025-25249 ↗ · CISA KEV entry ↗

CVE-2026-19490 Citrix Citrix NetScaler 9 Sep 2026 12 Sep 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-19490 ↗ · CISA KEV entry ↗

CVE-2026-85880 Microsoft Microsoft Windows 8 Sep 2026 22 Sep 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-85880 ↗ · CISA KEV entry ↗

CVE-2026-86218 N-able N-able N-central 8 Sep 2026 11 Sep 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-86218 ↗ · CISA KEV entry ↗

CVE-2026-81963 Microsoft Microsoft Windows 8 Sep 2026 22 Sep 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-81963 ↗ · CISA KEV entry ↗

CVE-2026-75650 Adobe Adobe Commerce and Magento 8 Sep 2026 11 Sep 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-75650 ↗ · CISA KEV entry ↗

CVE-2026-85046 Google Google Chromium V8 4 Sep 2026 18 Sep 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-85046 ↗ · CISA KEV entry ↗

CVE-2026-83549 SonicWall SonicWall SMA1000 Appliances 2 Sep 2026 5 Sep 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-83549 ↗ · CISA KEV entry ↗

CVE-2026-83548 SonicWall SonicWall SMA1000 Appliances 2 Sep 2026 5 Sep 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-83548 ↗ · CISA KEV entry ↗

CVE-2026-9586 Sangoma Sangoma Switchvox 2 Sep 2026 5 Sep 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-9586 ↗ · CISA KEV entry ↗

CVE-2026-82329 JFrog JFrog Artifactory 2 Sep 2026 5 Sep 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-82329 ↗ · CISA KEV entry ↗

CVE-2026-49869 Kestra Kestra OSS 2 Sep 2026 5 Sep 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-49869 ↗ · CISA KEV entry ↗

CVE-2026-48710 Kludex Kludex Starlette 2 Sep 2026 16 Sep 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-48710 ↗ · CISA KEV entry ↗

CVE-2026-59822 BerriAI BerriAI LiteLLM 2 Sep 2026 16 Sep 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-59822 ↗ · CISA KEV entry ↗

CVE-2026-81578 PaperCut PaperCut NG/MF 31 Aug 2026 14 Sep 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-81578 ↗ · CISA KEV entry ↗

CVE-2026-82078 PaperCut PaperCut NG/MF 31 Aug 2026 14 Sep 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-82078 ↗ · CISA KEV entry ↗

CVE-2026-66384 JFrog JFrog Artifactory 27 Aug 2026 10 Sep 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-66384 ↗ · CISA KEV entry ↗

CVE-2026-53362 Linux Linux Kernel 27 Aug 2026 30 Aug 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-53362 ↗ · CISA KEV entry ↗

CVE-2023-49105 ownCloud ownCloud 27 Aug 2026 30 Aug 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2023-49105 ↗ · CISA KEV entry ↗

CVE-2019-1068 Microsoft Microsoft SQL Server 26 Aug 2026 29 Aug 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2019-1068 ↗ · CISA KEV entry ↗

CVE-2026-8452 Citrix Citrix NetScaler ADC and NetScaler Gateway 26 Aug 2026 29 Aug 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-8452 ↗ · CISA KEV entry ↗

CVE-2022-0995 Linux Linux Kernel 26 Aug 2026 9 Sep 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2022-0995 ↗ · CISA KEV entry ↗

CVE-2015-5287 Red Hat Red Hat Automatic Bug Reporting Tool 26 Aug 2026 9 Sep 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2015-5287 ↗ · CISA KEV entry ↗

CVE-2015-3246 Red Hat Red Hat Libuser 26 Aug 2026 9 Sep 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2015-3246 ↗ · CISA KEV entry ↗

CVE-2021-23758 Ajax.NET Professional Ajax.NET Professional 26 Aug 2026 9 Sep 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2021-23758 ↗ · CISA KEV entry ↗

CVE-2026-60004 Gitea Gitea 25 Aug 2026 28 Aug 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-60004 ↗ · CISA KEV entry ↗

CVE-2026-21962 Oracle Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in 24 Aug 2026 27 Aug 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-21962 ↗ · CISA KEV entry ↗

CVE-2026-73570 Synacor Synacor Zimbra Collaboration Suite (ZCS) 21 Aug 2026 24 Aug 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-73570 ↗ · CISA KEV entry ↗

CVE-2026-72529 TrueConf TrueConf Server 20 Aug 2026 23 Aug 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-72529 ↗ · CISA KEV entry ↗

CVE-2026-72530 TrueConf TrueConf Server 20 Aug 2026 3 Sep 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-72530 ↗ · CISA KEV entry ↗

CVE-2026-64849 MLflow MLflow 19 Aug 2026 2 Sep 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-64849 ↗ · CISA KEV entry ↗

CVE-2026-65400 Apple Apple macOS 18 Aug 2026 21 Aug 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-65400 ↗ · CISA KEV entry ↗

CVE-2026-55040 Microsoft Microsoft SharePoint 18 Aug 2026 21 Aug 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-55040 ↗ · CISA KEV entry ↗

CVE-2026-59310 Broadcom Broadcom VMware vCenter 18 Aug 2026 21 Aug 2026 Known CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-59310 ↗ · CISA KEV entry ↗

CVE-2026-33824 Microsoft Microsoft Internet Key Exchange (IKE) Service Extensions 18 Aug 2026 21 Aug 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-33824 ↗ · CISA KEV entry ↗

CVE-2025-62593 Ray-Project Ray-Project Ray 17 Aug 2026 20 Aug 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2025-62593 ↗ · CISA KEV entry ↗

CVE-2026-72898 Metabase Metabase 11 Aug 2026 14 Aug 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-72898 ↗ · CISA KEV entry ↗

CVE-2026-68820 Microsoft Microsoft Windows Ancillary Function Driver for WinSock 11 Aug 2026 25 Aug 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-68820 ↗ · CISA KEV entry ↗

CVE-2026-20349 Cisco Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat De… 11 Aug 2026 14 Aug 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-20349 ↗ · CISA KEV entry ↗

CVE-2026-8037 Progress Progress LoadMaster 7 Aug 2026 10 Aug 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-8037 ↗ · CISA KEV entry ↗

CVE-2026-63077 JetBrains JetBrains TeamCity 5 Aug 2026 8 Aug 2026 Known CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-63077 ↗ · CISA KEV entry ↗

CVE-2026-9198 IBM IBM Langflow 4 Aug 2026 7 Aug 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-9198 ↗ · CISA KEV entry ↗

CVE-2026-34486 Apache Apache Tomcat 4 Aug 2026 7 Aug 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-34486 ↗ · CISA KEV entry ↗

CVE-2026-18556 N-able N-able N-central 4 Aug 2026 7 Aug 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-18556 ↗ · CISA KEV entry ↗

CVE-2026-18577 N-able N-able N-central 3 Aug 2026 6 Aug 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-18577 ↗ · CISA KEV entry ↗

CVE-2026-20316 Cisco Cisco Secure Firewall Management Center (FMC) 29 Jul 2026 1 Aug 2026 Known CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-20316 ↗ · CISA KEV entry ↗

CVE-2026-16812 Arista Arista VeloCloud Orchestrator 27 Jul 2026 30 Jul 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-16812 ↗ · CISA KEV entry ↗

CVE-2025-68686 Fortinet Fortinet FortiOS 27 Jul 2026 10 Aug 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2025-68686 ↗ · CISA KEV entry ↗

CVE-2026-50522 Microsoft Microsoft SharePoint 22 Jul 2026 25 Jul 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-50522 ↗ · CISA KEV entry ↗

CVE-2026-16232 Check Point Check Point SmartConsole 22 Jul 2026 25 Jul 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-16232 ↗ · CISA KEV entry ↗

CVE-2021-27137 DD-WRT DD-WRT 21 Jul 2026 24 Jul 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2021-27137 ↗ · CISA KEV entry ↗

CVE-2026-0770 Langflow Langflow 21 Jul 2026 24 Jul 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-0770 ↗ · CISA KEV entry ↗

CVE-2026-63030 WordPress WordPress Core 21 Jul 2026 24 Jul 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-63030 ↗ · CISA KEV entry ↗

CVE-2026-60137 WordPress WordPress Core 21 Jul 2026 4 Aug 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-60137 ↗ · CISA KEV entry ↗

CVE-2026-39808 Fortinet Fortinet FortiSandbox 16 Jul 2026 19 Jul 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-39808 ↗ · CISA KEV entry ↗

CVE-2026-25089 Fortinet Fortinet FortiSandbox 16 Jul 2026 19 Jul 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-25089 ↗ · CISA KEV entry ↗

CVE-2026-58644 Microsoft Microsoft SharePoint 16 Jul 2026 19 Jul 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-58644 ↗ · CISA KEV entry ↗

CVE-2023-4346 KNX Association KNX Association KNX Protocol Connection Authorization Option 1 15 Jul 2026 29 Jul 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2023-4346 ↗ · CISA KEV entry ↗

CVE-2026-46817 Oracle Oracle E-Business Suite 15 Jul 2026 18 Jul 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-46817 ↗ · CISA KEV entry ↗

CVE-2026-15410 SonicWall SonicWall SMA1000 Appliances 14 Jul 2026 17 Jul 2026 Known CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-15410 ↗ · CISA KEV entry ↗

CVE-2026-15409 SonicWall SonicWall SMA1000 Appliances 14 Jul 2026 17 Jul 2026 Known CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-15409 ↗ · CISA KEV entry ↗

CVE-2026-56164 Microsoft Microsoft SharePoint Server 14 Jul 2026 17 Jul 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-56164 ↗ · CISA KEV entry ↗

CVE-2026-56155 Microsoft Microsoft Active Directory Federation Services 14 Jul 2026 28 Jul 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-56155 ↗ · CISA KEV entry ↗

CVE-2008-4128 Cisco Cisco IOS 13 Jul 2026 16 Jul 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2008-4128 ↗ · CISA KEV entry ↗

CVE-2026-48939 iCagenda iCagenda 10 Jul 2026 13 Jul 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-48939 ↗ · CISA KEV entry ↗

CVE-2026-56291 Balbooa Balbooa Forms 10 Jul 2026 13 Jul 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-56291 ↗ · CISA KEV entry ↗

CVE-2026-48282 Adobe Adobe ColdFusion 7 Jul 2026 10 Jul 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-48282 ↗ · CISA KEV entry ↗

CVE-2026-56290 Joomlack Joomlack Page Builder 7 Jul 2026 10 Jul 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-56290 ↗ · CISA KEV entry ↗

CVE-2026-55255 Langflow Langflow 7 Jul 2026 10 Jul 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-55255 ↗ · CISA KEV entry ↗

CVE-2026-48908 JoomShaper JoomShaper SP Page Builder 7 Jul 2026 10 Jul 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-48908 ↗ · CISA KEV entry ↗

CVE-2026-45659 Microsoft Microsoft SharePoint Server 1 Jul 2026 4 Jul 2026 Known CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-45659 ↗ · CISA KEV entry ↗

CVE-2026-48558 SimpleHelp SimpleHelp 29 Jun 2026 2 Jul 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-48558 ↗ · CISA KEV entry ↗

CVE-2026-20230 Cisco Cisco Unified Communications Manager 25 Jun 2026 28 Jun 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-20230 ↗ · CISA KEV entry ↗

CVE-2026-12569 PTC PTC Windchill and FlexPLM 25 Jun 2026 28 Jun 2026 Known CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-12569 ↗ · CISA KEV entry ↗

CVE-2026-34908 Ubiquiti Ubiquiti UniFi OS 23 Jun 2026 26 Jun 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-34908 ↗ · CISA KEV entry ↗

CVE-2026-34909 Ubiquiti Ubiquiti UniFi OS 23 Jun 2026 26 Jun 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-34909 ↗ · CISA KEV entry ↗

CVE-2026-34910 Ubiquiti Ubiquiti UniFi OS 23 Jun 2026 26 Jun 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-34910 ↗ · CISA KEV entry ↗

CVE-2025-67038 Lantronix Lantronix EDS5000 23 Jun 2026 26 Jun 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2025-67038 ↗ · CISA KEV entry ↗

CVE-2026-20253 Splunk Splunk Enterprise 18 Jun 2026 21 Jun 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-20253 ↗ · CISA KEV entry ↗

CVE-2026-48907 Widget Factory Widget Factory Joomla Content Editor 16 Jun 2026 19 Jun 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-48907 ↗ · CISA KEV entry ↗

CVE-2026-20262 Cisco Cisco Catalyst SD-WAN Manager 15 Jun 2026 29 Jun 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-20262 ↗ · CISA KEV entry ↗

CVE-2026-54420 LiteSpeed LiteSpeed cPanel Plugin 15 Jun 2026 18 Jun 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-54420 ↗ · CISA KEV entry ↗

CVE-2026-35273 Oracle Oracle PeopleSoft Enterprise PeopleTools 12 Jun 2026 15 Jun 2026 Known CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-35273 ↗ · CISA KEV entry ↗

CVE-2026-10520 Ivanti Ivanti Sentry 11 Jun 2026 14 Jun 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-10520 ↗ · CISA KEV entry ↗

CVE-2026-20245 Cisco Cisco Catalyst SD-WAN Manager 9 Jun 2026 23 Jun 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-20245 ↗ · CISA KEV entry ↗

CVE-2026-7473 Arista Arista Extensible Operating System 9 Jun 2026 23 Jun 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-7473 ↗ · CISA KEV entry ↗

CVE-2026-11645 Google Google Chromium V8 9 Jun 2026 23 Jun 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-11645 ↗ · CISA KEV entry ↗

CVE-2026-50751 Check Point Check Point Security Gateway 8 Jun 2026 11 Jun 2026 Known CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-50751 ↗ · CISA KEV entry ↗

CVE-2026-42271 BerriAI BerriAI LiteLLM 8 Jun 2026 22 Jun 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-42271 ↗ · CISA KEV entry ↗

CVE-2026-28318 SolarWinds SolarWinds Serv-U 5 Jun 2026 19 Jun 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-28318 ↗ · CISA KEV entry ↗

CVE-2026-45247 Mirasvit Mirasvit Full Page Cache Warmer 3 Jun 2026 6 Jun 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-45247 ↗ · CISA KEV entry ↗

CVE-2025-48595 Android Android Framework 2 Jun 2026 5 Jun 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2025-48595 ↗ · CISA KEV entry ↗

CVE-2022-0492 Linux Linux Kernel 2 Jun 2026 5 Jun 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2022-0492 ↗ · CISA KEV entry ↗

CVE-2024-21182 Oracle Oracle WebLogic Server 1 Jun 2026 4 Jun 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2024-21182 ↗ · CISA KEV entry ↗

CVE-2026-0257 Palo Alto Networks Palo Alto Networks PAN-OS 29 May 2026 1 Jun 2026 Known CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-0257 ↗ · CISA KEV entry ↗

CVE-2026-8398 Daemon Daemon Tools Lite 27 May 2026 30 May 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-8398 ↗ · CISA KEV entry ↗

CVE-2026-45321 TanStack TanStack 27 May 2026 10 Jun 2026 Known CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-45321 ↗ · CISA KEV entry ↗

CVE-2026-48027 Nx Nx Console 27 May 2026 10 Jun 2026 Known CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-48027 ↗ · CISA KEV entry ↗

CVE-2026-48172 LiteSpeed LiteSpeed cPanel Plugin 26 May 2026 29 May 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-48172 ↗ · CISA KEV entry ↗

CVE-2026-9082 Drupal Drupal Core 22 May 2026 27 May 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-9082 ↗ · CISA KEV entry ↗

CVE-2026-34926 Trend Micro Trend Micro Apex One 21 May 2026 4 Jun 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-34926 ↗ · CISA KEV entry ↗

CVE-2025-34291 Langflow Langflow 21 May 2026 4 Jun 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2025-34291 ↗ · CISA KEV entry ↗

CVE-2026-45498 Microsoft Microsoft Defender 20 May 2026 3 Jun 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-45498 ↗ · CISA KEV entry ↗

CVE-2026-41091 Microsoft Microsoft Defender 20 May 2026 3 Jun 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-41091 ↗ · CISA KEV entry ↗

CVE-2010-0806 Microsoft Microsoft Internet Explorer 20 May 2026 3 Jun 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2010-0806 ↗ · CISA KEV entry ↗

CVE-2010-0249 Microsoft Microsoft Internet Explorer 20 May 2026 3 Jun 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2010-0249 ↗ · CISA KEV entry ↗

CVE-2009-3459 Adobe Adobe Acrobat and Reader 20 May 2026 3 Jun 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2009-3459 ↗ · CISA KEV entry ↗

CVE-2009-1537 Microsoft Microsoft DirectX 20 May 2026 3 Jun 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2009-1537 ↗ · CISA KEV entry ↗

CVE-2008-4250 Microsoft Microsoft Windows 20 May 2026 3 Jun 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2008-4250 ↗ · CISA KEV entry ↗

CVE-2026-42897 Microsoft Microsoft 15 May 2026 29 May 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-42897 ↗ · CISA KEV entry ↗

CVE-2026-20182 Cisco Cisco Catalyst SD-WAN 14 May 2026 17 May 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-20182 ↗ · CISA KEV entry ↗

CVE-2026-42208 BerriAI BerriAI LiteLLM 8 May 2026 11 May 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-42208 ↗ · CISA KEV entry ↗

CVE-2026-6973 Ivanti Ivanti Endpoint Manager Mobile (EPMM) 7 May 2026 10 May 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-6973 ↗ · CISA KEV entry ↗

CVE-2026-0300 Palo Alto Networks Palo Alto Networks PAN-OS 6 May 2026 9 May 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-0300 ↗ · CISA KEV entry ↗

CVE-2026-31431 Linux Linux Kernel 1 May 2026 15 May 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-31431 ↗ · CISA KEV entry ↗

CVE-2026-41940 WebPros WebPros cPanel & WHM and WP2 (WordPress Squared) 30 Apr 2026 3 May 2026 Known CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-41940 ↗ · CISA KEV entry ↗

CVE-2026-32202 Microsoft Microsoft Windows 28 Apr 2026 12 May 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-32202 ↗ · CISA KEV entry ↗

CVE-2024-1708 ConnectWise ConnectWise ScreenConnect 28 Apr 2026 12 May 2026 Known CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2024-1708 ↗ · CISA KEV entry ↗

CVE-2024-57726 SimpleHelp SimpleHelp 24 Apr 2026 8 May 2026 Known CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2024-57726 ↗ · CISA KEV entry ↗

CVE-2024-57728 SimpleHelp SimpleHelp 24 Apr 2026 8 May 2026 Known CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2024-57728 ↗ · CISA KEV entry ↗

CVE-2024-7399 Samsung Samsung MagicINFO 9 Server 24 Apr 2026 8 May 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2024-7399 ↗ · CISA KEV entry ↗

CVE-2025-29635 D-Link D-Link DIR-823X 24 Apr 2026 8 May 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2025-29635 ↗ · CISA KEV entry ↗

CVE-2026-39987 Marimo Marimo 23 Apr 2026 7 May 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-39987 ↗ · CISA KEV entry ↗

CVE-2026-33825 Microsoft Microsoft Defender 22 Apr 2026 6 May 2026 Known CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-33825 ↗ · CISA KEV entry ↗

CVE-2024-27199 JetBrains JetBrains TeamCity 20 Apr 2026 4 May 2026 Known CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2024-27199 ↗ · CISA KEV entry ↗

CVE-2025-32975 Quest Quest KACE Systems Management Appliance (SMA) 20 Apr 2026 4 May 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2025-32975 ↗ · CISA KEV entry ↗

CVE-2026-20128 Cisco Cisco Catalyst SD-WAN Manager 20 Apr 2026 23 Apr 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-20128 ↗ · CISA KEV entry ↗

CVE-2025-48700 Synacor Synacor Zimbra Collaboration Suite (ZCS) 20 Apr 2026 23 Apr 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2025-48700 ↗ · CISA KEV entry ↗

CVE-2023-27351 PaperCut PaperCut NG/MF 20 Apr 2026 4 May 2026 Known CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2023-27351 ↗ · CISA KEV entry ↗

CVE-2025-2749 Kentico Kentico Xperience 20 Apr 2026 4 May 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2025-2749 ↗ · CISA KEV entry ↗

CVE-2026-20133 Cisco Cisco Catalyst SD-WAN Manager 20 Apr 2026 23 Apr 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-20133 ↗ · CISA KEV entry ↗

CVE-2026-20122 Cisco Cisco Catalyst SD-WAN Manger 20 Apr 2026 23 Apr 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-20122 ↗ · CISA KEV entry ↗

CVE-2026-34197 Apache Apache ActiveMQ 16 Apr 2026 30 Apr 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-34197 ↗ · CISA KEV entry ↗

CVE-2026-32201 Microsoft Microsoft SharePoint Server 14 Apr 2026 28 Apr 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-32201 ↗ · CISA KEV entry ↗

CVE-2009-0238 Microsoft Microsoft Office 14 Apr 2026 28 Apr 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2009-0238 ↗ · CISA KEV entry ↗

CVE-2026-34621 Adobe Adobe Acrobat and Reader 13 Apr 2026 27 Apr 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-34621 ↗ · CISA KEV entry ↗

CVE-2026-21643 Fortinet Fortinet FortiClient EMS 13 Apr 2026 16 Apr 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-21643 ↗ · CISA KEV entry ↗

CVE-2020-9715 Adobe Adobe Acrobat 13 Apr 2026 27 Apr 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2020-9715 ↗ · CISA KEV entry ↗

CVE-2023-36424 Microsoft Microsoft Windows 13 Apr 2026 27 Apr 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2023-36424 ↗ · CISA KEV entry ↗

CVE-2023-21529 Microsoft Microsoft Exchange Server 13 Apr 2026 27 Apr 2026 Known CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2023-21529 ↗ · CISA KEV entry ↗

CVE-2025-60710 Microsoft Microsoft Windows 13 Apr 2026 27 Apr 2026 Known CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2025-60710 ↗ · CISA KEV entry ↗

CVE-2012-1854 Microsoft Microsoft Visual Basic for Applications (VBA) 13 Apr 2026 27 Apr 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2012-1854 ↗ · CISA KEV entry ↗

CVE-2026-1340 Ivanti Ivanti Endpoint Manager Mobile (EPMM) 8 Apr 2026 11 Apr 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-1340 ↗ · CISA KEV entry ↗

CVE-2026-35616 Fortinet Fortinet FortiClient EMS 6 Apr 2026 9 Apr 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-35616 ↗ · CISA KEV entry ↗

CVE-2026-3502 TrueConf TrueConf Client 2 Apr 2026 16 Apr 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-3502 ↗ · CISA KEV entry ↗

CVE-2026-5281 Google Google Dawn 1 Apr 2026 15 Apr 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-5281 ↗ · CISA KEV entry ↗

CVE-2026-3055 Citrix Citrix NetScaler 30 Mar 2026 2 Apr 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-3055 ↗ · CISA KEV entry ↗

CVE-2025-53521 F5 F5 BIG-IP 27 Mar 2026 30 Mar 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2025-53521 ↗ · CISA KEV entry ↗

CVE-2026-33634 Aquasecurity Aquasecurity Trivy 26 Mar 2026 9 Apr 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-33634 ↗ · CISA KEV entry ↗

CVE-2026-33017 Langflow Langflow 25 Mar 2026 8 Apr 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-33017 ↗ · CISA KEV entry ↗

CVE-2025-31277 Apple Apple Multiple Products 20 Mar 2026 3 Apr 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2025-31277 ↗ · CISA KEV entry ↗

CVE-2025-43520 Apple Apple Multiple Products 20 Mar 2026 3 Apr 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2025-43520 ↗ · CISA KEV entry ↗

CVE-2025-43510 Apple Apple Multiple Products 20 Mar 2026 3 Apr 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2025-43510 ↗ · CISA KEV entry ↗

CVE-2025-54068 Laravel Laravel Livewire 20 Mar 2026 3 Apr 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2025-54068 ↗ · CISA KEV entry ↗

CVE-2025-32432 Craft CMS Craft CMS 20 Mar 2026 3 Apr 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2025-32432 ↗ · CISA KEV entry ↗

CVE-2026-20131 Cisco Cisco Secure Firewall Management Center (FMC) 19 Mar 2026 22 Mar 2026 Known CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-20131 ↗ · CISA KEV entry ↗

CVE-2026-20963 Microsoft Microsoft SharePoint 18 Mar 2026 21 Mar 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-20963 ↗ · CISA KEV entry ↗

CVE-2025-66376 Synacor Synacor Zimbra Collaboration Suite (ZCS) 18 Mar 2026 1 Apr 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2025-66376 ↗ · CISA KEV entry ↗

CVE-2025-47813 Wing FTP Server Wing FTP Server 16 Mar 2026 30 Mar 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2025-47813 ↗ · CISA KEV entry ↗

CVE-2026-3909 Google Google Skia 13 Mar 2026 27 Mar 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-3909 ↗ · CISA KEV entry ↗

CVE-2026-3910 Google Google Chromium V8 13 Mar 2026 27 Mar 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-3910 ↗ · CISA KEV entry ↗

CVE-2025-68613 n8n n8n 11 Mar 2026 25 Mar 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2025-68613 ↗ · CISA KEV entry ↗

CVE-2026-1603 Ivanti Ivanti Endpoint Manager (EPM) 9 Mar 2026 23 Mar 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-1603 ↗ · CISA KEV entry ↗

CVE-2025-26399 SolarWinds SolarWinds Web Help Desk 9 Mar 2026 12 Mar 2026 Known CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2025-26399 ↗ · CISA KEV entry ↗

CVE-2021-22054 Omnissa Omnissa Workspace One UEM 9 Mar 2026 23 Mar 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2021-22054 ↗ · CISA KEV entry ↗

CVE-2023-41974 Apple Apple iOS and iPadOS 5 Mar 2026 26 Mar 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2023-41974 ↗ · CISA KEV entry ↗

CVE-2021-30952 Apple Apple Multiple Products 5 Mar 2026 26 Mar 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2021-30952 ↗ · CISA KEV entry ↗

CVE-2023-43000 Apple Apple Multiple Products 5 Mar 2026 26 Mar 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2023-43000 ↗ · CISA KEV entry ↗

CVE-2021-22681 Rockwell Rockwell Multiple Products 5 Mar 2026 26 Mar 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2021-22681 ↗ · CISA KEV entry ↗

CVE-2017-7921 Hikvision Hikvision Multiple Products 5 Mar 2026 26 Mar 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2017-7921 ↗ · CISA KEV entry ↗

CVE-2026-21385 Qualcomm Qualcomm Multiple Chipsets 3 Mar 2026 24 Mar 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-21385 ↗ · CISA KEV entry ↗

CVE-2026-22719 Broadcom Broadcom VMware Aria Operations 3 Mar 2026 24 Mar 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-22719 ↗ · CISA KEV entry ↗

CVE-2026-20127 Cisco Cisco Catalyst SD-WAN Controller and Manager 25 Feb 2026 27 Feb 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-20127 ↗ · CISA KEV entry ↗

CVE-2022-20775 Cisco Cisco SD-WAN 25 Feb 2026 27 Feb 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2022-20775 ↗ · CISA KEV entry ↗

CVE-2026-25108 Soliton Systems K.K Soliton Systems K.K FileZen 24 Feb 2026 17 Mar 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-25108 ↗ · CISA KEV entry ↗

CVE-2025-68461 Roundcube Roundcube Webmail 20 Feb 2026 13 Mar 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2025-68461 ↗ · CISA KEV entry ↗

CVE-2025-49113 Roundcube Roundcube Webmail 20 Feb 2026 13 Mar 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2025-49113 ↗ · CISA KEV entry ↗

CVE-2026-22769 Dell Dell RecoverPoint for Virtual Machines (RP4VMs) 18 Feb 2026 21 Feb 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-22769 ↗ · CISA KEV entry ↗

CVE-2021-22175 GitLab GitLab 18 Feb 2026 11 Mar 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2021-22175 ↗ · CISA KEV entry ↗

CVE-2026-2441 Google Google Chromium 17 Feb 2026 10 Mar 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-2441 ↗ · CISA KEV entry ↗

CVE-2008-0015 Microsoft Microsoft Windows 17 Feb 2026 10 Mar 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2008-0015 ↗ · CISA KEV entry ↗

CVE-2024-7694 TeamT5 TeamT5 ThreatSonar Anti-Ransomware 17 Feb 2026 10 Mar 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2024-7694 ↗ · CISA KEV entry ↗

CVE-2020-7796 Synacor Synacor Zimbra Collaboration Suite 17 Feb 2026 10 Mar 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2020-7796 ↗ · CISA KEV entry ↗

CVE-2026-1731 BeyondTrust BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) 13 Feb 2026 16 Feb 2026 Known CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-1731 ↗ · CISA KEV entry ↗

CVE-2025-40536 SolarWinds SolarWinds Web Help Desk 12 Feb 2026 15 Feb 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2025-40536 ↗ · CISA KEV entry ↗

CVE-2025-15556 Notepad++ Notepad++ 12 Feb 2026 5 Mar 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2025-15556 ↗ · CISA KEV entry ↗

CVE-2024-43468 Microsoft Microsoft Configuration Manager 12 Feb 2026 5 Mar 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2024-43468 ↗ · CISA KEV entry ↗

CVE-2026-20700 Apple Apple Multiple Products 12 Feb 2026 5 Mar 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-20700 ↗ · CISA KEV entry ↗

CVE-2026-21514 Microsoft Microsoft Office 10 Feb 2026 3 Mar 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-21514 ↗ · CISA KEV entry ↗

CVE-2026-21519 Microsoft Microsoft Windows 10 Feb 2026 3 Mar 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-21519 ↗ · CISA KEV entry ↗

CVE-2026-21533 Microsoft Microsoft Windows 10 Feb 2026 3 Mar 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-21533 ↗ · CISA KEV entry ↗

CVE-2026-21510 Microsoft Microsoft Windows 10 Feb 2026 3 Mar 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-21510 ↗ · CISA KEV entry ↗

CVE-2026-21525 Microsoft Microsoft Windows 10 Feb 2026 3 Mar 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-21525 ↗ · CISA KEV entry ↗

CVE-2026-21513 Microsoft Microsoft Windows 10 Feb 2026 3 Mar 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-21513 ↗ · CISA KEV entry ↗

CVE-2026-24423 SmarterTools SmarterTools SmarterMail 5 Feb 2026 26 Feb 2026 Known CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-24423 ↗ · CISA KEV entry ↗

CVE-2025-11953 React Native Community React Native Community CLI 5 Feb 2026 26 Feb 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2025-11953 ↗ · CISA KEV entry ↗

CVE-2025-40551 SolarWinds SolarWinds Web Help Desk 3 Feb 2026 6 Feb 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2025-40551 ↗ · CISA KEV entry ↗

CVE-2019-19006 Sangoma Sangoma FreePBX 3 Feb 2026 24 Feb 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2019-19006 ↗ · CISA KEV entry ↗

CVE-2025-64328 Sangoma Sangoma FreePBX 3 Feb 2026 24 Feb 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2025-64328 ↗ · CISA KEV entry ↗

CVE-2021-39935 GitLab GitLab Community and Enterprise Editions 3 Feb 2026 24 Feb 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2021-39935 ↗ · CISA KEV entry ↗

CVE-2026-1281 Ivanti Ivanti Endpoint Manager Mobile (EPMM) 29 Jan 2026 1 Feb 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-1281 ↗ · CISA KEV entry ↗

CVE-2026-24858 Fortinet Fortinet Multiple Products 27 Jan 2026 30 Jan 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-24858 ↗ · CISA KEV entry ↗

CVE-2026-21509 Microsoft Microsoft Office 26 Jan 2026 16 Feb 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-21509 ↗ · CISA KEV entry ↗

CVE-2026-24061 GNU GNU InetUtils 26 Jan 2026 16 Feb 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-24061 ↗ · CISA KEV entry ↗

CVE-2026-23760 SmarterTools SmarterTools SmarterMail 26 Jan 2026 16 Feb 2026 Known CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-23760 ↗ · CISA KEV entry ↗

CVE-2025-52691 SmarterTools SmarterTools SmarterMail 26 Jan 2026 16 Feb 2026 Known CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2025-52691 ↗ · CISA KEV entry ↗

CVE-2018-14634 Linux Linux Kernel 26 Jan 2026 16 Feb 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2018-14634 ↗ · CISA KEV entry ↗

CVE-2024-37079 Broadcom Broadcom VMware vCenter Server 23 Jan 2026 13 Feb 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2024-37079 ↗ · CISA KEV entry ↗

CVE-2025-54313 Prettier Prettier eslint-config-prettier 22 Jan 2026 12 Feb 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2025-54313 ↗ · CISA KEV entry ↗

CVE-2025-31125 Vite Vitejs 22 Jan 2026 12 Feb 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2025-31125 ↗ · CISA KEV entry ↗

CVE-2025-34026 Versa Versa Concerto 22 Jan 2026 12 Feb 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2025-34026 ↗ · CISA KEV entry ↗

CVE-2025-68645 Synacor Synacor Zimbra Collaboration Suite (ZCS) 22 Jan 2026 12 Feb 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2025-68645 ↗ · CISA KEV entry ↗

CVE-2026-20045 Cisco Cisco Unified Communications Manager 21 Jan 2026 11 Feb 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-20045 ↗ · CISA KEV entry ↗

CVE-2026-20805 Microsoft Microsoft Windows 13 Jan 2026 3 Feb 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2026-20805 ↗ · CISA KEV entry ↗

CVE-2025-8110 Gogs Gogs 12 Jan 2026 2 Feb 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2025-8110 ↗ · CISA KEV entry ↗

CVE-2025-37164 Hewlett Packard Enterprise (HPE) Hewlett Packard Enterprise (HPE) OneView 7 Jan 2026 28 Jan 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2025-37164 ↗ · CISA KEV entry ↗

CVE-2009-0556 Microsoft Microsoft Office 7 Jan 2026 28 Jan 2026 Unknown CISA Known Exploited Vulnerabilities Catalog (2026.09.25) ↗

Full CISA detail loads when opened. Canonical records: CVE-2009-0556 ↗ · CISA KEV entry ↗

No records match the current filters.

What the data shows

The charts below redraw the table above as the trends and comparisons a table cannot show.

Catalog additions by monthEntries CISA added to its catalog each month, the latest twelve. The catalog is read in full, so a month with no bar had no additions.010203040Jan 2026: 1717Jan 2026Feb 2026: 2828Mar 2026: 2626Mar 2026Apr 2026: 3131May 2026: 2121May 2026Jun 2026: 2323Jul 2026: 2626Jul 2026Aug 2026: 3131Sep 2026: 3939Sep 2026
Linked to ransomwareCISA's own flag on each entry. Unknown means CISA has not tied the flaw to a campaign, not that none exists.Ransomware use unknown: 215Ransomware use unknown 215Known ransomware use: 27Known ransomware use 27

Verification ledger

5 most recent of 23 logged updates
  • Deterministic sync against CISA catalog 2026.09.25: 3 added, 0 revised, 0 removed. 25 Sep 2026
  • Deterministic sync against CISA catalog 2026.09.24: 2 added, 0 revised, 0 removed. 24 Sep 2026
  • Deterministic sync against CISA catalog 2026.09.23: 0 added, 1 revised, 0 removed. 23 Sep 2026
  • Deterministic sync against CISA catalog 2026.09.22: 4 added, 0 revised, 0 removed. 22 Sep 2026
  • Deterministic sync against CISA catalog 2026.09.21: 1 added, 0 revised, 0 removed. 21 Sep 2026

More trackers from The Threat Index

Data Breach Tracker →

Major breaches as they are disclosed: organization, records, vector, and the notice itself.

26breaches as disclosed

Patch Tuesday Dashboard →

Monthly CVE counts by vendor and severity, from the vendors' own bulletins.

61bulletins monthly

Privacy Fines Tracker →

Data-protection penalties as the authorities publish them, in the currency they stated.

21penalties monthly

How this tracker is maintained

Every entry mirrors CISA’s own catalog, and nothing is added on our judgment.

  1. 01

    Sourced

    Entries come from CISA’s Known Exploited Vulnerabilities catalog, the machine-readable feed the agency publishes itself. The vendor, product, description and required action are CISA’s wording, not a paraphrase; a vulnerability CISA has not listed does not appear here however widely it is discussed.

  2. 02

    Dated

    Each row carries the date CISA added it and the remediation date CISA set for it. Both are the agency’s dates, and the gap between them is CISA’s judgment of urgency rather than ours.

  3. 03

    Re-checked

    The catalog is re-read weekly and the page rebuilt from it. Entries CISA revises are updated in place; entries CISA removes are removed here.

Why use this instead of CISA’s own page?
For a single lookup, use CISA. This page exists for the questions the catalog does not answer on its own: how the year’s additions distribute across vendors, how long a remediation window actually is, and how many entries carry a confirmed ransomware link. The rows are CISA’s; the summary is what we add.
What does the remediation deadline mean for me?
Legally, nothing unless you are a US federal civilian agency: the deadlines bind them under a binding operational directive. For everyone else it is a signal of how seriously the agency treats a flaw, not a schedule you inherit.
Why is ransomware use often “unknown”?
Because that is what CISA records. Unknown means the agency has not established a ransomware link, not that it has ruled one out, and this page keeps the distinction rather than reporting only the confirmed cases.

This is informational content, not patching guidance for your environment. CISA’s remediation deadlines bind US federal civilian agencies; they are not a statement about your own risk or priority. Prioritize using the linked advisory, the vendor’s own fix, and your asset inventory.

Quoting a figure with a link to this page needs no permission. Cite it as you would any source. Reuse of the compiled dataset itself is licensed under CC BY 4.0: credit SQ Magazine and link back. Download CSV · Follow updates (RSS)

Sources

  • CISA Known Exploited Vulnerabilities Catalog (2026.09.25)

Footer

SQ Magazine Logo

Smarter Insights for a Fast-Moving Digital World

Connect With Us

Follow Us on Google News

Editorial & Trust

  • About
  • Publishing Principles
  • Fact-Check Policy
  • Corrections Policy
  • Ethics Policy
  • Disclaimer
  • Cookie Policy

Worth Checking

  • The Tech Index
  • The Threat Index
  • Social Media Attention Span Stats
  • Instagram Followers Stats
  • Google Usage Stats
  • LLM Hallucination Stats
  • Gen Z Social Media Stats
Contact Us
13570 Grove Dr #189,
Maple Grove, MN 55311,
United States
10 a.m. to 6 p.m. | Every day

Copyright © 2022–2026 SQ Magazine. All Rights Reserved. Powered by the Neural Stack.

  • Privacy Policy
  • Terms
  • Accessibility Statement
Company
  • About Us
  • Our Team
  • Our Mission
  • Core Values
Discover
  • Brand Assets
    Brand Assets
  • Stats Methodology
    Stats Research Process
  • Glossary
    Glossary
Categories
  • Internet
  • Technology
  • Artificial Intelligence
  • Gaming
  • Cryptocurrency
Internet
How Many Videos Are on YouTube Statistics
How Many Videos Are on YouTube Statistics 2026: Key Data
How Many People Work at WhatsApp
How Many People Work at WhatsApp 2026: Employee Count and History
Spotify Listening Statistics
Spotify Listening Statistics 2026: Average Listening Time
How Many Subscribers Does MrBeast Have
How Many Subscribers Does MrBeast Have in 2026? Channel Growth Statistics
WhatsApp Business Statistics
WhatsApp Business Statistics 2026: Real Market Insights
Udemy Statistics
Udemy Statistics 2026: Revenue and Learner Data
Technology
Aptoide Statistics 2026: Downloads, Users and App Store Share
Aptoide Statistics 2026: Downloads, Users and App Store Share
AppsFlyer Statistics Customers Revenue and Market Position
AppsFlyer Statistics 2026: Customers, Revenue and Market Position
How Many iPhones Has Apple Sold
How Many iPhones Has Apple Sold in 2026? Units Sold by Year
How Many Employees Does Amazon Have
How Many Employees Does Amazon Have 2026: Workforce Growth
Netflix vs. Hulu Statistics
Netflix vs Hulu Statistics 2026: Viewer Growth Data
TripAdvisor Statistics
TripAdvisor Statistics 2026: Revenue, Reviews, Viator and TheFork Data
Artificial Intelligence
AI Search Engine Statistics Usage Market Share and Adoption
AI Search Engine Statistics 2026: Usage, Market Share and Adoption
AI Music Statistics
AI Music Statistics 2026: Generation, Adoption and Industry Impact
AI Coding Statistics
AI Coding Statistics 2026: Adoption, Productivity and Market Data
How Much Content on Social Media Is AI Generated Statistics
How Much Content on Social Media Is AI Generated Statistics 2026: Hidden Truths
ChatGPT vs DeepSeek Statistics
ChatGPT vs DeepSeek Statistics 2026: Users, Benchmarks & Pricing
ChatGPT vs Claude vs Gemini vs Perplexity Statistics
ChatGPT vs Claude vs Gemini vs Perplexity Statistics 2026: Users, Revenue & Market Share
Gaming
Gaming Statistics
Gaming Statistics 2026: Market Size, Players, Revenue, and Platforms
Roblox vs Minecraft Statistics
Roblox vs Minecraft Statistics 2026: Players, Revenue, Creators
Online Gambling Regulations Statistics
Online Gambling Regulations Statistics 2026: Global Compliance and Enforcement Data
Fantasy Sports Statistics
Fantasy Sports Statistics 2026: Users, Revenue & Trends
Apex Legends Statistics 2026: Players, Revenue, and Esports
Apex Legends Statistics 2026: Players, Revenue, and Esports
Fortnite Statistics
Fortnite Statistics 2026: Players, Revenue, Esports, and Engagement
Cryptocurrency
How Many Bitcoins Are There
How Many Bitcoins Are There in 2026? Supply, Mined and Remaining Statistics
Stablecoin Usage Statistics
Stablecoin Usage Statistics 2026: Explosive Growth
Cryptocurrency Adoption Statistics
Cryptocurrency Adoption Statistics 2026: Shocking Trends Now
Coinbase Wallet Statistics
Coinbase Wallet Statistics 2026: Users, Security
Dogecoin Statistics
Dogecoin Statistics 2026: Annual Supply Increase, Circulating Supply, and Inflation Rate
BONK Coin Statistics
BONK Coin Statistics 2026: Risk, Reward, and ROI
Categories
  • Artificial Intelligence
  • Cybersecurity
  • Technology
  • Internet
  • Cryptocurrency
Artificial Intelligence
Microsoft Copilot Complete Overhaul Adds Code and Autopilot
Microsoft Copilot Complete Overhaul Adds Code and Autopilot
Gemini Call For Me Feature Pixel 11
Google Gemini Can Now Call Businesses for Pixel 11 Owners
Adobe Creative Tools Gemini Claude Addition
Adobe Unlocks New Creative Tools in Gemini and Claude
Youtube Music Ask Music Ai Feature
YouTube Music Adds Smart AI Features for Songs and Podcasts
OpenAI Launches GPT-6 Sol and Luna at Half the API Price
OpenAI Launches GPT-6 Sol and Luna at Half the API Price
Claude Opus 5 5 Launched
Claude Opus 5.5 Debuts With Powerful Cyber Defenses
Cybersecurity
Servicenow Cve Vulnerability Patches
ServiceNow Security Alert: Patch These Critical Flaws
Manus Ai Prompt Injection
Manus AI Agent Exposed by Prompt-Injection Bug
Arista Velocloud Flaw Patched
Arista VeloCloud Flaw Hits CVSS 10.0: Patch Now
Microsoft Takes Down Eviltokens Ai Phishing Service
Microsoft Takes Down EvilTokens AI Phishing Service
Microsoft Patches Azure Ai Foundry Cvss 10 Flaw Featured 1
Microsoft Patches 18 Azure and Copilot Security Vulnerabilities
Chatgpt Billing Phishing Scam Active
ChatGPT Billing Scam Exposes Critical OpenAI Account Risk
Technology
Microsoft Windows Deployment Service Deprecation
Microsoft Will Deprecate Windows Deployment Services After Server 2025
Youtube Custom Feeds With Gemini Ai
YouTube’s AI Feed Builder Changes Video Discovery
Iphone 18 Pro Face Id Bug Reboot Crash
New iPhone 18 Pro Bug Makes Face ID Crash and Reboot
Googlebook With Gemini Ai Launched
Googlebook’s Bold Laptop Launch Starts at $899 in the US
New Samsung Patent Reveals Galaxy Watch Glucose Tracking
New Samsung Patent Reveals Galaxy Watch Glucose Tracking
Microsoft Kb5002914 Breaks Excel Copypaste
Microsoft Confirms KB5002914 Breaks Excel Copy and Paste
Internet
Meta Launched Meta One Subscription
Meta One Bundles Instagram, Facebook, WhatsApp Into One AI Subscription
Apple Wallet Ids Launch In Oklahoma
Apple Wallet IDs Launch in Oklahoma in Major Expansion
Meta to Pay 18 Billion in Landmark Teen Safety Deal
Meta to Pay $18 Billion in Landmark Teen Safety Deal
Whatsapp Brings Passkeys 2fa
WhatsApp Hits 1 Billion Passkey Users, Adds 2FA Passwords
Apple Eu App Store Fee Reduction
Apple Sets New EU App Store Fees, Effective October 1
Github Outage Aug 2026
GitHub Down: Outage Hits Thousands of Users Worldwide
Cryptocurrency
Sonic Labs Launch Ussd Stablecoin
Sonic Launches USSD Stablecoin Backed by US Treasuries
Bhutan Moves 12m In Bitcoins
Bhutan Moves $12 Million in Bitcoin from Primary Wallets
Curve Finance Accuses Pancakeswap For Code Stealing
Curve Accuses PancakeSwap of Copying StableSwap Code
Strike Receives Bitlicense In New York
Strike Gets New York BitLicense for Bitcoin Financial Services
Scotiabank Multi Crypto Etf 3iqlogos
Scotiabank Launches Multi Crypto ETF With 3iQ in Canada
Nyse Parent Invests In Okx Crypto Exchange
ICE Invests in OKX to Bridge Crypto and Traditional Finance