| 2026-09-27 | CVE-2026-84388 | Fortinet FortiPAM Chrome Extension All 8.0 and 7.4 Versions Improperly Restricts Rendered UI Layers, Potentially Enabling Clickjacking Attacks Against Users of the PAM Interface | 9.6 Critical | New |
| 2026-09-26 | CVE-2026-80152 | Lantronix SLC8000, SLC9000, EMG, and SLB Series Set Script Schedule Command Passes Unsanitized Input to system(), Enabling Authenticated Users with Services Permission to Run Arbitrary Commands as Root | 9.1 Critical | New |
| 2026-09-26 | CVE-2026-80151 | Lantronix SLC8000, SLC9000, EMG, and SLB Series Set NFS Download Command Passes Unsanitized Input to system(), Enabling Authenticated Users with Services Permission to Run Arbitrary Commands as Root | 9.1 Critical | New |
| 2026-09-26 | CVE-2026-80146 | Lantronix SLC8000/SLC9000 and EMG Series Undocumented mfc eeprom read Command Copies Unbounded Input into a Stack Buffer Before system(), Enabling Authenticated Attackers to Execute Arbitrary Code as Root | 9.9 Critical | New |
| 2026-09-26 | CVE-2026-67279 | MikroTik RouterOS Unauthenticated Session Bypass Carries Federal Remediation Deadline of September 28 | 6.5 Medium | KEV |
| 2026-09-25 | CVE-2026-93616 | Path Traversal Across Check Point Management and Log Server Infrastructure Missed the September 25th CISA KEV Window; Covered Organizations Are Now Out of Compliance | 9.8 Critical | KEV |
| 2026-09-25 | CVE-2026-85046 | Google Chromium V8's Type Confusion Allows Remote Attackers to Execute Arbitrary Code or Escape the Browser Sandbox via a Crafted Web Page | 8.8 High | KEV |
| 2026-09-25 | CVE-2026-81578 | PaperCut NG/MF's Missing Authentication on a Critical Function Allows Unauthenticated Attackers to Perform Administrative Actions Without Logging In; CISA's September 14th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-25 | CVE-2026-76461 | Cisco Secure Email Gateway's SQL Injection Flaw Allows Unauthenticated Attackers to Execute Arbitrary Database Queries and Compromise the Email Security Platform | 9.8 Critical | KEV |
| 2026-09-25 | CVE-2026-76460 | Cisco Identity Services Engine's Incorrect Use of Privileged APIs Allows Unauthenticated Remote Attackers to Gain Full Administrative Control; CISA's September 19th KEV Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-25 | CVE-2026-75650 | Adobe Commerce and Magento's Template Engine Injection Flaw Allows Unauthenticated Remote Attackers to Execute Arbitrary Server-Side Code on the E-Commerce Platform | 10.0 Critical | KEV |
| 2026-09-25 | CVE-2026-98123 | Linux Kernel SCTP ASCONF-ACK Parameter Walk Loops Indefinitely on an Unpadded Short Parameter Due to SCTP_PAD4 Rounding, Causing a Soft Lockup | — | New |
| 2026-09-25 | CVE-2026-98044 | Linux Kernel BPF Verifier Fails to Reject Legacy Packet Loads from Callback Subprograms, Which Can Model a Failed BPF_LD_ABS as an Implicit Zero Return Causing Incorrect Program Behavior | — | New |
| 2026-09-25 | CVE-2026-93815 | Linux Kernel au1000 Ethernet Driver Calls free_irq While Holding a Spinlock with Interrupts Disabled, Which Can Sleep and Deadlock on Platforms Without Threaded IRQs | — | New |
| 2026-09-25 | CVE-2026-93804 | Linux Kernel mac80211 IBSS Leave Path Flushes Stations and Turns Off the Carrier Without Waiting for In-Flight TX to Complete, Leading to Use-After-Free on Concurrent Packet Transmission | — | New |
| 2026-09-25 | CVE-2026-67278 | MikroTik RouterOS Accepts Malformed RSA/PKCS#1 v1.5 Signatures Across TLS and SSH, and Its Trust Store Includes an e=3 Root CA, Letting a Network Attacker Forge Valid Signatures Without the Private Key | 9.1 Critical | Updated |
| 2026-09-25 | CVE-2026-5430 | WSO2 API Gateway Path Traversal Reaches Federal Remediation Deadline of September 27 | 10.0 Critical | KEV |
| 2026-09-24 | CVE-2026-9203 | MarkLogic SSRF Flaw Exposes Cloud Instance Credentials to Low-Privilege Users | 8.5 High | Updated |
| 2026-09-24 | CVE-2026-9195 | Crafted Links Let Attackers Hijack MarkLogic Administrator Sessions Through Query Console XSS | 9.3 Critical | Updated |
| 2026-09-24 | CVE-2026-9193 | Low-Privilege Hadoop Role Escalates to Full Control of MarkLogic's Security Database | 9.9 Critical | Updated |
| 2026-09-24 | CVE-2026-9192 | Unauthenticated Attackers Can Impersonate Any MarkLogic User Through ODBC Authentication Bypass | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-9190 | HTTP Request Smuggling Bypasses MarkLogic Authentication and Hijacks Sessions | 9.1 Critical | Updated |
| 2026-09-24 | CVE-2026-9089 | ConnectWise Automate agent trusts unverified plugin and update downloads, fixed in 2026.5 | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-8709 | MarkLogic's REST document-patch API lets low-privileged users seize administrator control | 9.9 Critical | Updated |
| 2026-09-24 | CVE-2026-7557 | Unauthenticated attackers impersonate any MarkLogic administrator through a SAML signature flaw | 9.1 Critical | Updated |
| 2026-09-24 | CVE-2026-7329 | MarkLogic's SQL, SPARQL, and Optic query interfaces open a path from low-privileged access to full admin | 9.9 Critical | Updated |
| 2026-09-24 | CVE-2026-7327 | MarkLogic's document-processing pipeline lets an administrative REST role escalate further, exposing server-side data | 8.1 High | Updated |
| 2026-09-24 | CVE-2026-7326 | A CSRF flaw in MarkLogic's Admin UI lets attackers hijack lured administrators for configuration changes | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-71474 | Red Hat insights-client logs a long-lived OpenShift pull-secret token that local pod-log access can expose | 7.1 High | Updated |
| 2026-09-24 | CVE-2026-68981 | Apache NiFi's gzip request handling bypasses size limits, opening a memory-exhaustion path, fixed in 2.11.0 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-68980 | Apache NiFi's asset-deletion API skips ownership checks across Parameter Contexts, fixed in 2.11.0 | 9.1 Critical | Updated |
| 2026-09-24 | CVE-2026-68979 | Missing authorization on Apache NiFi's Parameter Context updates can trigger code execution, fixed in 2.11.0 | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-68060 | Pre-authentication attackers can exhaust memory in Apache Qpid Broker-J via oversized type handling, fixed in 10.1.0 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-67589 | Apache Qpid ProtonJ2 lets pre-authentication attackers trigger oversized memory allocations, fixed in 1.2.0 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-67588 | Unbounded symbol caching in Apache Qpid ProtonJ2 lets pre-authentication attackers exhaust memory, fixed in 1.2.0 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-67551 | Apache Qpid Proton-Dotnet lets pre-authentication attackers trigger oversized memory allocations, fixed in 1.1.0 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-67465 | Unbounded symbol caching in Apache Qpid Proton-Dotnet lets pre-authentication attackers exhaust memory, fixed in 1.1.0 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-66756 | A critical alternate-path flaw in Apache Tika precedes the 4.0.0-beta-1 fix, CVSS 9.8 | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-66755 | Apache Tika's ISA-Tab parser lets crafted filenames leak arbitrary file contents into extracted text, fixed in 3.3.2 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-66273 | Apache Qpid Proton-J lets pre-authentication attackers trigger oversized memory allocations, fixed in 0.35.0 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-66257 | Unbounded symbol caching in Apache Qpid Proton-J lets pre-authentication attackers exhaust memory, fixed in 0.35.0 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-66015 | A JFrog Platform privilege-escalation flaw grants temporary admin access under admin-provisioned accounts | 7.2 High | New |
| 2026-09-24 | CVE-2026-66014 | An authentication weakness in JFrog Artifactory's internal request processing lets attackers escalate access | 8.8 High | New |
| 2026-09-24 | CVE-2026-65922 | Limited-access JFrog Artifactory users can write to restricted internal metadata under specific conditions | 7.1 High | New |
| 2026-09-24 | CVE-2026-65617 | A deserialization flaw in JFrog Artifactory package handling lets low-privileged users compromise confidentiality, integrity, and availability | 8.8 High | New |
| 2026-09-24 | CVE-2026-65616 | Flawed refresh-token signature validation lets non-admin JFrog users obtain a signed administrator token | 8.8 High | New |
| 2026-09-24 | CVE-2026-62391 | An incomplete fix for a prior Kyuubi flaw still lets clients bypass the local-directory allowlist via Spark config aliases, fixed in 1.12.0 | 8.1 High | Updated |
| 2026-09-24 | CVE-2026-61372 | A path traversal vulnerability in Apache Jena Fuseki is fixed in 6.2.0 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-6066 | ConnectWise Automate's Solution Center allowed unencrypted client-server traffic open to interception, fixed in 2026.4 | 7.1 High | Updated |
| 2026-09-24 | CVE-2026-60413 | An information-exposure flaw in Oracle Outside In Core lets a logged-in attacker take full control, CVSS 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-60412 | Insecure deserialization in Oracle Outside In Core lets a logged-in attacker take full control, CVSS 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-60393 | Unauthenticated network attackers can reach all Oracle Hyperion Infrastructure Technology data over HTTP, CVSS 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-60392 | Insecure deserialization in Oracle's Outside In PDF Export SDK lets a logged-in attacker take full control, CVSS 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-60391 | Unauthenticated network attackers can reach all Oracle Hyperion Financial Reporting data over HTTP, CVSS 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-6023 | Tampered RadFilter state in Telerik UI for ASP.NET AJAX enables server-side remote code execution | 8.1 High | Updated |
| 2026-09-24 | CVE-2026-6022 | Telerik UI for ASP.NET AJAX chunked upload flaw lets attackers bypass size limits and exhaust disk space | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-5483 | Red Hat OpenShift AI's odh-dashboard leaks Kubernetes service account tokens through a NodeJS endpoint | 8.5 High | New |
| 2026-09-24 | CVE-2026-54100 | Red Hat's Windows Machine Config Operator skips SSH host-key checks, letting adjacent attackers capture node bootstrap credentials | 8.3 High | Updated |
| 2026-09-24 | CVE-2026-54099 | A compromised Windows node can forge a cluster-administrator certificate through WMCO's CSR auto-approver, CVSS 8.8 | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-52680 | Path traversal in Apache Kyuubi's REST batch upload lets remote attackers write files outside the intended directory, fixed in 1.12.0 | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-5174 | Improper input validation in Progress MOVEit Automation opens a path to privilege escalation | 7.7 High | Updated |
| 2026-09-24 | CVE-2026-47629 | Improper input validation in NVIDIA Triton Inference Server on Linux can trigger denial of service | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-47628 | Unbounded resource allocation in NVIDIA Triton Inference Server on Linux opens a denial-of-service path | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-47627 | A critical path-traversal flaw in NVIDIA Triton Inference Server on Linux enables denial of service, CVSS 9.8 | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-4740 | Red Hat Advanced Cluster Management lets a managed-cluster admin forge certificates for cross-cluster privilege escalation | 8.2 High | Updated |
| 2026-09-24 | CVE-2026-42017 | An event-handling flaw in JFrog Artifactory exposes privileged authorization material to lower-privileged users | 8.8 High | New |
| 2026-09-24 | CVE-2026-41724 | Stored XSS in VMware Cloud Foundation Operations lets privileged users trigger admin actions via injected scripts | 8.0 High | Updated |
| 2026-09-24 | CVE-2026-41723 | A stored XSS spanning VMware Cloud Foundation Operations and vSphere lets privileged users trigger admin actions via injected scripts | 8.0 High | Updated |
| 2026-09-24 | CVE-2026-41722 | Another stored XSS across VMware Cloud Foundation Operations and vSphere lets privileged users trigger admin actions via injected scripts | 8.0 High | Updated |
| 2026-09-24 | CVE-2026-41702 | A TOCTOU flaw in a VMware Fusion SETUID binary lets local non-admin users escalate to root | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-4048 | Authenticated Command Injection in Progress LoadMaster UI Enables Remote Code Execution | 8.4 High | EPSS-Imminent |
| 2026-09-24 | CVE-2026-40141 | A critical query-injection flaw in BeyondTrust Remote Support lets low-privileged users reach unauthorized resources, CVSS 9.9 | 9.9 Critical | Updated |
| 2026-09-24 | CVE-2026-40140 | Unauthenticated attackers can crash BeyondTrust Remote Support appliances via a network-communication flaw | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-40139 | Critical Pre-Authentication Bypass in BeyondTrust Remote Support Allows Unauthorized Access | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-40138 | BeyondTrust Privileged Remote Access Shares Pre-Authentication Bypass Flaw with Remote Support | 8.1 High | Updated |
| 2026-09-24 | CVE-2026-39815 | SQL Injection in Fortinet FortiDDoS-F 7.2 May Allow Unauthorized Data Access | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-39304 | Apache ActiveMQ NIO SSL Transports Vulnerable to Denial-of-Service via Memory Exhaustion | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-3692 | Low-Privilege OS Command Injection in Progress Flowmon Reporting Component | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-35554 | Race Condition in Apache Kafka Producer Can Silently Deliver Messages to Wrong Topics | 8.7 High | Updated |
| 2026-09-24 | CVE-2026-3519 | Progress LoadMaster API Exposes Authenticated Command Injection for VS Administration Role | 8.4 High | EPSS-Imminent |
| 2026-09-24 | CVE-2026-34487 | Apache Tomcat Cloud Clustering Component Logs Kubernetes Credentials in Plain Text | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-34483 | Improper Output Encoding in Apache Tomcat JsonAccessLogValve Enables Log Injection | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-34478 | Apache Log4j RFC 5424 Layout Vulnerable to Log Injection in Versions 2.21 through 2.25 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-34020 | Apache OpenMeetings REST Login Exposes Credentials in URL Query String | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-33266 | Apache OpenMeetings Uses Default Hard-Coded Encryption Key for Remember-Me Cookies | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-33105 | Critical Authorization Bypass in Microsoft Azure Kubernetes Service Allows Network Privilege Escalation | 10.0 Critical | Updated |
| 2026-09-24 | CVE-2026-32590 | Unsafe Deserialization in Red Hat Quay Resumable Upload Handling | 7.1 High | Updated |
| 2026-09-24 | CVE-2026-32200 | Use-After-Free in Microsoft PowerPoint Enables Local Code Execution | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-32199 | Use-After-Free in Microsoft Office Excel Enables Local Code Execution | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-32198 | Microsoft Office Excel Use-After-Free Lets Local Attacker Execute Code | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-32197 | Local Code Execution via Use-After-Free in Microsoft Office Excel | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-32190 | Use-After-Free in Microsoft Office Enables Local Code Execution | 8.4 High | Updated |
| 2026-09-24 | CVE-2026-32189 | Microsoft Office Excel Carries Additional Use-After-Free Code Execution Risk | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-32188 | Out-of-Bounds Read in Microsoft Office Excel Discloses Information to Local Attackers | 7.1 High | Updated |
| 2026-09-24 | CVE-2026-32186 | Critical SSRF in Microsoft Bing Enables Network-Based Privilege Escalation | 10.0 Critical | Updated |
| 2026-09-24 | CVE-2026-32184 | Deserialization Flaw in Microsoft HPC Pack Allows Authorized User to Escalate Privileges | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-32153 | Use-After-Free in Windows Speech Component Allows Local Privilege Escalation | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-32091 | Race Condition in Microsoft Brokering File System Allows Unauthorized Privilege Escalation | 8.4 High | Updated |
| 2026-09-24 | CVE-2026-29145 | Apache Tomcat CLIENT_CERT Authentication Bypass When Soft Fail Is Disabled | 9.1 Critical | Updated |
| 2026-09-24 | CVE-2026-29129 | Apache Tomcat Fails to Preserve Configured Cipher Preference Order | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-28814 | Apache JSPWiki Renders Wiki Markup Without Authentication, Exposing Sensitive Data | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-28813 | JSON Hijacking in Apache JSPWiki Enables Cross-Site Request Forgery | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-28812 | Apache JSPWiki UserManager Spoofing Flaw Allows Attackers to Escalate Privileges | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-28811 | Apache JSPWiki Leaks Internal Information via Debug Messages | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-27914 | Improper Access Control in Microsoft Management Console Allows Local Privilege Escalation | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-27909 | Use-After-Free in Windows Search Component Allows Authorized Attacker to Escalate Privileges | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-27314 | Apache Cassandra 5.0 CREATE Permission Allows Privilege Escalation in mTLS Environments | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-26181 | Use-After-Free in Microsoft Brokering File System Lets Authorized User Escalate Privileges | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-26170 | Input Validation Flaw in Microsoft PowerShell Allows Local Privilege Escalation | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-26149 | Control Sequence Injection in Microsoft Power Apps Enables Network-Based Spoofing | 9.0 Critical | Updated |
| 2026-09-24 | CVE-2026-26143 | Improper Input Validation in Microsoft PowerShell Allows Unauthorized Security Feature Bypass | 7.8 High | New |
| 2026-09-24 | CVE-2026-24880 | Apache Tomcat Chunk Extension Parsing Allows HTTP Request Smuggling | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-24222 | NVIDIA NeMoClaw Sandbox Initialization Exposes System Information to Remote Attackers | 8.6 High | Updated |
| 2026-09-24 | CVE-2026-24217 | Path Traversal in NVIDIA BioNeMo Core Allows Malicious File to Escape Sandbox | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-24216 | Deserialization of Untrusted Data in NVIDIA BioNeMo Enables Code Execution | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-24214 | Integer Overflow in NVIDIA Triton Inference Server DALI Backend | 8.0 High | Updated |
| 2026-09-24 | CVE-2026-24213 | Out-of-Bounds Read in NVIDIA Triton Inference Server DALI Backend | 8.0 High | Updated |
| 2026-09-24 | CVE-2026-24210 | Integer Overflow in NVIDIA Triton Inference Server Allows Code Execution or Denial of Service | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-24209 | Path Traversal Vulnerability in NVIDIA Triton Inference Server | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-24207 | Critical Authentication Bypass in NVIDIA Triton Inference Server | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-24206 | NVIDIA Triton Inference Server Authentication Bypass via Alternate Path Scores 7.3 | 7.3 High | Updated |
| 2026-09-24 | CVE-2026-24188 | NVIDIA TensorRT Out-of-Bounds Write Scores 8.2 | 8.2 High | Updated |
| 2026-09-24 | CVE-2026-24186 | NVIDIA NVFlare Deserialization of Untrusted Data Scores 8.8 | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-24184 | NVIDIA Cumulus Linux Buffer Overflow Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-24183 | NVIDIA Cumulus Linux Excessive-Privilege Execution Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-24178 | Critical NVIDIA NVFlare Authorization Bypass via User-Controlled Key Scores 9.8 | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-24175 | NVIDIA Triton Inference Server Uncaught Exception Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-24174 | NVIDIA Triton Inference Server Numeric Type Conversion Error Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-24173 | NVIDIA Triton Inference Server Integer Overflow Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-24163 | NVIDIA TensorRT-LLM Deserialization Flaw Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-24156 | NVIDIA Data Loading Library Deserialization Vulnerability Scores 7.3 | 7.3 High | Updated |
| 2026-09-24 | CVE-2026-24146 | NVIDIA Triton Inference Server Oversized Allocation Request Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-23708 | Fortinet FortiSOAR Authentication Flaw Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-23657 | Microsoft Office LTSC Use-After-Free Vulnerability Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-23429 | Linux Kernel IOMMU SVA Use-After-Free in Unbind Path Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-23428 | Critical Linux Kernel ksmbd Use-After-Free in Compound Request Handling Scores 9.8 | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-23427 | Critical Linux Kernel ksmbd Use-After-Free in Durable Handle Replay Scores 9.8 | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-23425 | Linux Kernel KVM arm64 ID Register Initialization Flaw Scores 8.8 | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-23424 | Linux Kernel amdxdna Missing Command Buffer Validation Scores 7.1 | 7.1 High | Updated |
| 2026-09-24 | CVE-2026-23422 | Linux Kernel dpaa2-switch Out-of-Bounds Write from Malformed Interrupt Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-23415 | Linux Kernel Futex Use-After-Free between Key Lookup and VMA Policy Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-23414 | Linux Kernel TLS Memory Leak in Async Decrypt Wait Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-23413 | Linux Kernel clsact Use-After-Free in Init/Destroy Rollback Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-23412 | Linux Kernel Netfilter BPF Use-After-Free in Hook Memory Release Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-23411 | Linux Kernel AppArmor Race Condition Frees i_private Data Early Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-23410 | Linux Kernel AppArmor Race on Rawdata Dereference Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-23408 | Linux Kernel AppArmor Double Free of Namespace Name Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-23407 | Linux Kernel AppArmor Out-of-Bounds Read in DFA Verification Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-22828 | Fortinet FortiManager and FortiAnalyzer Cloud Heap Overflow Scores 8.1 | 8.1 High | Updated |
| 2026-09-24 | CVE-2026-22619 | Eaton Intelligent Power Protector Uncontrolled Search Path Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-22016 | Oracle Java SE JAXP Component Exposes Sensitive Information, Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-22011 | Oracle Applications DBA ADPatch Access Control Weakness Scores 7.6 | 7.6 High | Updated |
| 2026-09-24 | CVE-2026-22010 | Oracle Financial Services Infrastructure Platform Access Control Flaw Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-21997 | Oracle Life Sciences Empirica Signal Access Control Weakness Scores 8.5 | 8.5 High | Updated |
| 2026-09-24 | CVE-2026-21662 | Critical Johnson Controls FMS Employee Unrestricted File Upload Scores 9.8 | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-20160 | Critical Cisco Smart Software Manager On-Prem Resource Exposure Scores 9.8 | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-20155 | Cisco Evolved Programmable Network Manager Missing Authorization Scores 8.0 | 8.0 High | Updated |
| 2026-09-24 | CVE-2026-20151 | Cisco Smart Software Manager On-Prem Leaks Sensitive Data in Transmitted Requests | 7.3 High | Updated |
| 2026-09-24 | CVE-2026-20094 | Cisco UCS Command Injection Scores 8.8 | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-18381 | Red Hat Cost Management Metrics Operator SSRF via Crafted Custom Resource Scores 7.6 | 7.6 High | Updated |
| 2026-09-24 | CVE-2026-18378 | Red Hat Cost Management Metrics Operator SSRF via Arbitrary Upload URL Scores 7.6 | 7.6 High | Updated |
| 2026-09-24 | CVE-2026-17894 | Google Chrome on Linux Use-After-Free in Views via Crafted HTML Scores 8.8 | 8.8 High | New |
| 2026-09-24 | CVE-2026-17877 | Google Chrome on Linux Chromoting Flaw Enables Local Privilege Escalation, Scores 8.4 | 8.4 High | New |
| 2026-09-24 | CVE-2026-17744 | Google Chrome on Linux File Input Flaw Exposes Potential Sandbox Escape, Scores 7.1 | 7.1 High | New |
| 2026-09-24 | CVE-2026-16443 | Red Hat Build of Keycloak Cryptographic Signature Verification Flaw Scores 7.4 | 7.4 High | Updated |
| 2026-09-24 | CVE-2026-0288 | Palo Alto Networks PAN-OS Out-of-Bounds Write Scores 7.5 | 7.5 High | New |
| 2026-09-24 | CVE-2026-0273 | Palo Alto Networks PAN-OS OS Command Injection Scores 7.2 | 7.2 High | New |
| 2026-09-24 | CVE-2026-0272 | Palo Alto Networks PAN-OS Missing Authorization Scores 7.2 | 7.2 High | New |
| 2026-09-24 | CVE-2026-0271 | Palo Alto Networks Prisma Access Agent Permission Misconfiguration Scores 7.8 | 7.8 High | New |
| 2026-09-24 | CVE-2026-0270 | Palo Alto Networks Cortex XSOAR Path Traversal Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-0265 | Palo Alto Networks PAN-OS Authentication Bypass Affects Siemens RUGGEDCOM APE1808, Scores 8.1 | 8.1 High | Updated |
| 2026-09-24 | CVE-2026-0264 | Critical Palo Alto Networks PAN-OS DNS Heap Overflow Affects Siemens RUGGEDCOM APE1808, Scores 9.8 | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-0263 | Critical Palo Alto Networks PAN-OS Out-of-Bounds Write Scores 9.8 | 9.8 Critical | New |
| 2026-09-24 | CVE-2026-0262 | Palo Alto Networks PAN-OS Multiple Denial-of-Service Flaws Affect Siemens RUGGEDCOM APE1808 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-0261 | Palo Alto Networks PAN-OS Command Injection Affects Siemens RUGGEDCOM APE1808, Scores 7.2 | 7.2 High | Updated |
| 2026-09-24 | CVE-2026-0259 | Palo Alto Networks PAN-OS External File Path Control Scores 8.8 | 8.8 High | New |
| 2026-09-24 | CVE-2026-0258 | Palo Alto Networks PAN-OS IKEv2 SSRF Affects Siemens RUGGEDCOM APE1808, Scores 9.1 | 9.1 Critical | Updated |
| 2026-09-24 | CVE-2026-0251 | Palo Alto Networks GlobalProtect Untrusted Search Path Scores 7.8 | 7.8 High | New |
| 2026-09-24 | CVE-2026-0250 | Palo Alto Networks GlobalProtect Out-of-Bounds Write Scores 8.1 | 8.1 High | New |
| 2026-09-24 | CVE-2026-0246 | Palo Alto Networks Prisma Access Agent Missing Authorization Scores 7.8 | 7.8 High | New |
| 2026-09-24 | CVE-2026-0244 | Palo Alto Networks Prisma SD-WAN Certificate Validation Flaw Scores 8.1 | 8.1 High | Updated |
| 2026-09-24 | CVE-2026-0237 | Palo Alto Networks Prisma Browser Alternate Path Protection Flaw Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-0236 | Palo Alto Networks Prisma Browser Code Injection Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-0233 | Palo Alto Networks ADEM Certificate Validation Flaw Scores 8.8 | 8.8 High | Updated |
| 2026-09-24 | CVE-2025-7406 | Nokia MantaRay NM sudo Privilege Escalation Reaches Root, Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2025-65114 | Apache Traffic Server HTTP Request Smuggling Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2025-62188 | Apache DolphinScheduler Sensitive Information Exposure Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2025-61848 | Fortinet FortiManager SQL Injection Scores 7.2 | 7.2 High | Updated |
| 2026-09-24 | CVE-2025-58136 | Apache Traffic Server Incorrect Control Flow Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2025-53681 | Fortinet FortiMail SQL Injection Scores 7.2 | 7.2 High | Updated |
| 2026-09-24 | CVE-2025-33255 | NVIDIA TensorRT-LLM MPI Server Deserialization Flaw Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2025-24818 | Nokia MantaRay NM OS Command Injection in Log Search Scores 8.0 | 8.0 High | Updated |
| 2026-09-24 | CVE-2025-24817 | Nokia MantaRay NM OS Command Injection in Symptom Collector Scores 8.0 | 8.0 High | Updated |
| 2026-09-24 | CVE-2025-24815 | Nokia MantaRay NM Unrestricted File Upload Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2025-14774 | ABB T-MAC Plus Incorrect Authorization Scores 7.4 | 7.4 High | Updated |
| 2026-09-24 | CVE-2025-14773 | ABB T-MAC Plus Cross-Site Scripting Scores 8.0 | 8.0 High | Updated |
| 2026-09-24 | CVE-2025-14772 | ABB T-MAC Plus Authorization Bypass via User-Controlled Key Scores 8.8 | 8.8 High | Updated |
| 2026-09-24 | CVE-2025-14771 | ABB T-MAC Plus Exposes Files to External Parties, Scores 9.9 | 9.9 Critical | Updated |
| 2026-09-24 | CVE-2025-12694 | Forcepoint VPN Client Excessive-Privilege Execution Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2017-20236 | ProSoft ICX35-HWC OS Command Injection via Web UI Scores 9.8 | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2017-20235 | ProSoft ICX35-HWC Authentication Bypass in Web Interface Scores 9.1 | 9.1 Critical | Updated |
| 2026-09-24 | CVE-2026-80156 | Lantronix SLC8000, SLC9000, EMG, and SLB Series Upload Endpoint Strips Backslash Characters but Not Forward Slashes During Path Validation, Letting Authenticated Attackers Write Files to Arbitrary Filesystem Locations | 9.1 Critical | New |
| 2026-09-24 | CVE-2026-80155 | Lantronix SLC8000, SLC9000, EMG, and SLB Series Upload Endpoint Requires No Authentication, Allowing Unauthenticated Attackers to Read Configuration Files and Upload to Arbitrary Filesystem Locations, Scoring CVSS 10.0 | 10.0 Critical | New |
| 2026-09-24 | CVE-2026-80154 | Lantronix SLC8000, SLC9000, EMG, and SLB Series Web Portal Derives Session Tokens Deterministically from Device Model and Current Second, Letting Unauthenticated Attackers Predict and Forge Valid Sessions on All Firmware Versions | 9.6 Critical | New |
| 2026-09-24 | CVE-2026-80147 | Lantronix SLC8000/SLC9000 and EMG Series Undocumented mfc eeprom write Command Copies Unbounded Input into a Stack Buffer Before system(), Enabling Authenticated Attackers to Execute Arbitrary Code as Root | 9.9 Critical | New |
| 2026-09-24 | CVE-2026-80145 | Lantronix SLC8000/SLC9000 and EMG Series Set CIFS Password Command Passes User Input Unsanitized to system(), Enabling Authenticated Users with Services Permission to Run Commands as Root | 9.1 Critical | New |
| 2026-09-24 | CVE-2026-80144 | Lantronix SLC8000/SLC9000 and EMG Series Undocumented mfc eeprom write Command Passes Input Directly to system() via the CLI Interface, Reachable by Any Authenticated User for Root Command Execution | 9.9 Critical | New |
| 2026-09-24 | CVE-2026-80143 | Lantronix SLC8000/SLC9000 and EMG Series Undocumented mfc eeprom read Command Passes Input Directly to system() via the CLI Interface, Reachable by Any Authenticated User for Root Command Execution | 9.9 Critical | New |
| 2026-09-24 | CVE-2026-28324 | SolarWinds Observability Self-Hosted Insufficient Integrity Checks Allow Unauthenticated Remote Code Execution on Non-Default, Non-Hardened Installations | 9.8 Critical | New |
| 2026-09-24 | CVE-2026-13249 | Honeywell PD45 Industrial Printer F10.19.010040 Web Management Interface Allows Unauthenticated File Upload of Attacker-Controlled Files, Enabling Remote Code Execution Without Credentials | 9.8 Critical | New |
| 2026-09-24 | CVE-2008-4128 | Cisco IOS's Multiple Cross-Site Request Forgery Flaws Allow Remote Attackers to Execute Arbitrary Commands via Show Privilege and Alias Exec Requests; CISA's July 16th KEV Deadline Has Passed | 8.1 High | KEV |
| 2026-09-23 | CVE-2026-3517 | Progress LoadMaster OS Command Injection via Geo Administration API Scores 8.4 | 8.4 High | EPSS-Imminent |
| 2026-09-23 | CVE-2026-29146 | Apache Tomcat EncryptInterceptor Padding Oracle Scores 7.5 | 7.5 High | EPSS-Imminent |
| 2026-09-23 | CVE-2026-20180 | Critical Cisco ISE Path Traversal Enables Remote Code Execution, Scores 9.9 | 9.9 Critical | EPSS-Imminent |
| 2026-09-23 | CVE-2026-39813 | Fortinet FortiSandbox Path Traversal Enables Privilege Escalation, Scores 9.8 | 9.8 Critical | EPSS-Imminent |
| 2026-09-23 | CVE-2026-40688 | Fortinet FortiWeb Out-of-Bounds Write Scores 7.2 | 7.2 High | EPSS-Imminent |
| 2026-09-23 | CVE-2026-4670 | Critical Progress MOVEit Automation Authentication Bypass Scores 9.8 | 9.8 Critical | EPSS-Imminent |
| 2026-09-23 | CVE-2026-59309 | Critical VMware vCenter Authentication Bypass in Directory Service Scores 9.8 | 9.8 Critical | EPSS-Imminent |
| 2026-09-23 | CVE-2026-3518 | Progress LoadMaster OS Command Injection via Full-Permission API Scores 8.4 | 8.4 High | EPSS-Imminent |
| 2026-09-23 | CVE-2026-20147 | Critical Cisco ISE and ISE-PIC Command Injection Scores 9.9 | 9.9 Critical | EPSS-Imminent |
| 2026-09-23 | CVE-2026-94127 | CISA's September 25th Remediation Deadline for F5 BIG-IP APM's OAuth Profile Heap Overflow Has Passed; Covered Entities Running Affected Virtual Servers Are Out of Compliance | 9.8 Critical | KEV |
| 2026-09-23 | CVE-2026-93952 | Arista VeloCloud Orchestrator Input Validation Gap Lets Remote Attackers Reach Privileged APIs; CISA's September 25th KEV Deadline for Covered Entities Has Now Passed | 10.0 Critical | KEV |
| 2026-09-23 | CVE-2026-85102 | Check Point Firewall Certificate Validation Bypass Across Site-to-Site and Remote Access VPN Carries a Lapsed September 25th CISA KEV Requirement for Covered Entities | 9.8 Critical | KEV |
| 2026-09-23 | CVE-2026-73172 | Advantech EKI-1242EIMS Firmware V1.06.01 edgserver Management Service Passes Unsanitized Input to the OS Shell, Enabling Unauthenticated Remote Attackers to Execute Arbitrary Commands | 9.3 Critical | New |
| 2026-09-22 | CVE-2026-9586 | Sangoma Switchvox's SQL Injection Vulnerability Allows Unauthenticated Remote Attackers to Execute Arbitrary Database Queries and Compromise the Telephony Platform | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-9198 | IBM Langflow's Code Injection Flaw Allows Unauthenticated Remote Attackers to Execute Arbitrary Code on the AI Workflow Platform; CISA's August 7th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-9082 | Drupal Core's SQL Injection via Specially Crafted Database Abstraction API Requests Enables Privilege Escalation and Remote Code Execution; CISA's May 27th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-86218 | N-able N-central's Static Code Injection Flaw Allows Remote Attackers to Inject and Execute Arbitrary Code on the RMM Platform Without Prior Authentication | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-85706 | GitLab Community and Enterprise Edition's Path Traversal Flaw Allows Unauthenticated Remote Attackers to Read Arbitrary Files on the Server and Fully Compromise the GitLab Instance | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-83549 | SonicWall SMA1000 Appliances' OS Command Injection Allows Authenticated Local Attackers to Execute Arbitrary Commands with Root Privileges; CISA's September 5th KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-22 | CVE-2026-83548 | SonicWall SMA1000 Appliances' Server-Side Request Forgery Allows Unauthenticated Remote Attackers to Reach Internal Services and Compromise the Secure Mobile Access Gateway; CISA's September 5th KEV Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-82329 | JFrog Artifactory Carries a 9.8 Critical Improper Authentication Flaw That Lets Unauthenticated Attackers Bypass Login Controls on the Artifact Repository | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-8037 | Progress LoadMaster's Command Injection Flaw Allows Unauthenticated Remote Attackers to Execute Arbitrary OS Commands on the Load Balancer Appliance; CISA's August 10th KEV Deadline Has Passed | 9.6 Critical | KEV |
| 2026-09-22 | CVE-2026-73570 | Zimbra Collaboration Suite's OS Command Injection Allows Authenticated Attackers to Execute Arbitrary Commands on the Email Server with Elevated Privileges; CISA's August 24th KEV Deadline Has Passed | 8.9 High | KEV |
| 2026-09-22 | CVE-2026-72898 | Metabase's SQL Injection Flaw Allows Unauthenticated Attackers to Execute Arbitrary Database Queries and Achieve Full Platform Compromise; CISA's August 14th KEV Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-6973 | Ivanti Endpoint Manager Mobile's Improper Input Validation Allows a Remotely Authenticated Administrator to Execute Code Remotely; CISA's May 10th KEV Deadline Has Passed | 7.2 High | KEV |
| 2026-09-22 | CVE-2026-68820 | Microsoft Windows Ancillary Function Driver for WinSock's Use-After-Free Allows a Local Attacker to Gain Elevated Privileges via a Freed Memory Reference; CISA's August 25th KEV Deadline Has Passed | 7.0 High | KEV |
| 2026-09-22 | CVE-2026-65400 | Apple macOS's Improper Authentication Flaw Allows a Network Attacker to Bypass Login Controls and Gain Unauthorized Access to the Operating System; CISA's August 21st KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-64849 | MLflow's Server-Side Request Forgery Flaw Allows Remote Attackers to Use the ML Platform Server as a Proxy to Access Internal Services and Steal Credentials; CISA's September 2nd KEV Deadline Has Passed | 9.3 Critical | KEV |
| 2026-09-22 | CVE-2026-63077 | JetBrains TeamCity's Deserialization of Untrusted Data Allows Unauthenticated Remote Attackers to Execute Arbitrary Code on the CI/CD Server; CISA's August 8th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-63030 | WordPress Core Input Interpretation Conflict Exploited in the Wild Carries a Lapsed July 24th CISA KEV Mandate for Covered Entities | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-60137 | WordPress Core SQL Injection Enabling Database Access Joins CISA's Known Exploited Vulnerabilities Catalog; Covered Entities Past the August 4th Remediation Deadline | 5.9 Medium | KEV |
| 2026-09-22 | CVE-2026-60004 | Gitea's Code Injection Vulnerability Allows Unauthenticated Remote Attackers to Execute Arbitrary Code on the Repository Platform; CISA's August 28th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-59310 | Broadcom VMware vCenter's Path Traversal Flaw Allows Unauthenticated Remote Attackers to Access Files Outside the Web Root and Potentially Compromise the Virtualization Platform; CISA's August 21st KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-56291 | Balbooa Forms Unrestricted File Upload Requiring No Authentication Has Missed CISA's July 13th KEV Remediation Deadline; Covered Entities Are Now Out of Compliance | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-56290 | Joomlack Page Builder Lets Unauthenticated Users Upload Arbitrary Files, Enabling Remote Code Execution; CISA's July 10th KEV Mandate Has Lapsed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-55040 | Microsoft SharePoint's Weak Authentication Allows Attackers to Bypass Login Controls and Gain Unauthorized Access to SharePoint Sites and Data; CISA's August 21st KEV Deadline Has Passed | 9.1 Critical | KEV |
| 2026-09-22 | CVE-2026-50751 | Check Point Security Gateway's IKEv1 Key Exchange Flaw Lets Unauthenticated Attackers Establish Remote Access VPN Tunnels Without a Valid Password; CISA's June 11th KEV Deadline Has Passed | 9.3 Critical | KEV |
| 2026-09-22 | CVE-2026-48939 | iCagenda Joomla Event Calendar Extension Accepts Unrestricted File Uploads Without Authentication, Enabling Remote Code Execution; CISA's July 13th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-48908 | JoomShaper SP Page Builder Accepts Arbitrary File Uploads from Unauthenticated Users; CISA's July 10th KEV Deadline for Covered Entities Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-48907 | Joomla Content Editor Plugin Exposes Privileged Functions Without Proper Authorization; CISA's June 19th KEV Deadline for Covered Entities Has Lapsed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-48710 | Kludex Starlette's HTTP Request Smuggling Vulnerability Allows Network-Adjacent Attackers to Bypass Security Controls and Poison Shared HTTP Connections | 6.5 Medium | KEV |
| 2026-09-22 | CVE-2026-48558 | SimpleHelp Accepts Unverified Cryptographic Signatures, Letting Remote Attackers Bypass Authentication; CISA's July 2nd KEV Deadline for Covered Entities Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-48172 | Any cPanel User Can Escalate Privileges Through LiteSpeed's Plugin; CISA's May 29th KEV Remediation Requirement for Covered Entities Has Expired | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-46817 | Oracle E-Business Suite's Improper Privilege Management in Oracle Payments Allows an Unauthenticated Network Attacker to Take Over the Payments Module via HTTP; CISA's July 18th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-45498 | Microsoft Defender's Unspecified Vulnerability Allows for Denial of Service; CISA's June 3rd KEV Deadline Has Passed | 4.0 Medium | KEV |
| 2026-09-22 | CVE-2026-45247 | Mirasvit Full Page Cache Warmer's Deserialization Flaw Lets Unauthenticated Attackers Reach Remote Code Execution via a Crafted PHP Object in the CacheWarmer Cookie; CISA's June 6th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-42897 | Microsoft Exchange Server's Outlook Web Access Cross-Site Scripting Flaw Executes Arbitrary JavaScript When Interaction Conditions Are Met; CISA's May 29th KEV Deadline Has Passed | 8.1 High | KEV |
| 2026-09-22 | CVE-2026-42018 | JFrog Artifactory's Improper Authentication Allows Network-Based Attackers to Bypass Login Controls and Gain Unauthorized Access to the Artifact Repository | 7.5 High | KEV |
| 2026-09-22 | CVE-2026-42016 | JFrog Artifactory's Incorrect Authorization Allows Authenticated Users to Access Artifacts and Repositories Outside Their Permitted Scope | 8.1 High | KEV |
| 2026-09-22 | CVE-2026-41940 | WebPros cPanel and WHM's Login Flow Authentication Bypass Gives Unauthenticated Attackers Unauthorized Access to the Control Panel; CISA's May 3rd KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-41091 | Microsoft Defender's Link Following Flaw Enables an Authorized Attacker to Elevate Privileges Locally; CISA's June 3rd KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-22 | CVE-2026-39987 | Marimo's Pre-Authentication Flaw Gives Unauthenticated Attackers Shell Access and Arbitrary Command Execution; CISA's May 7th KEV Remediation Requirement for Covered Entities Has Long Lapsed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-39808 | Fortinet FortiSandbox's OS Command Injection Gives Unauthenticated Attackers Remote Code Execution via Crafted HTTP Requests; CISA's July 19th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-35616 | Fortinet FortiClient EMS Access Control Bypass Entered CISA's Known Exploited Vulnerabilities Catalog with an April 9th Federal Deadline That Has Long Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-35273 | Oracle PeopleSoft Enterprise PeopleTools' Missing Authentication for a Critical Function Allows Unauthenticated Attackers to Take Over the Platform; CISA's June 15th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-34926 | Pre-Authenticated Local Attackers Can Use Relative Path Traversal in Trend Micro Apex One to Modify Key Configuration Data; CISA's June 4th KEV Mandate for Covered Entities Has Lapsed | 6.7 Medium | KEV |
| 2026-09-22 | CVE-2026-34910 | Network-Adjacent Attackers Can Inject Commands into Ubiquiti UniFi OS Through an Input Validation Flaw; CISA's June 26th KEV Remediation Window Has Closed for Covered Entities | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-34909 | Ubiquiti UniFi OS's Path Traversal Lets a Network-Adjacent Attacker Access Files on the Underlying System and Manipulate an Underlying Account; CISA's June 26th KEV Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-34908 | Ubiquiti UniFi OS's Improper Access Control Lets a Network-Adjacent Attacker Make Unauthorized Changes to the System; CISA's June 26th KEV Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-34486 | Apache Tomcat's Missing Encryption of Sensitive Session Data Exposes Credentials and Tokens to Network Interception; CISA's August 7th KEV Deadline Has Passed | 7.5 High | KEV |
| 2026-09-22 | CVE-2026-34197 | Apache ActiveMQ's Improper Input Validation Enables Code Injection Affecting Both ActiveMQ and Broker Deployments; CISA's April 30th KEV Deadline Has Passed | 8.8 High | KEV |
| 2026-09-22 | CVE-2026-33825 | Microsoft Defender's Insufficient Access Control Allows an Authorized Attacker to Escalate Privileges Locally; CISA's May 6th KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-22 | CVE-2026-33824 | Microsoft Windows IKE Service Extensions' Double Free Enables Unauthenticated Remote Attackers to Execute Arbitrary Code; CISA's August 21st KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-32202 | Microsoft Windows Shell's Protection Mechanism Failure Allows an Unauthorized Attacker to Perform Spoofing Over the Network; CISA's May 12th KEV Deadline Has Passed | 4.3 Medium | KEV |
| 2026-09-22 | CVE-2026-31431 | Linux Kernel Resource Mishandling That Allows Privilege Escalation Carries a Lapsed May 15th CISA KEV Mandate; Covered Entities on Unpatched Kernels Remain Out of Compliance | 7.8 High | KEV |
| 2026-09-22 | CVE-2026-28318 | SolarWinds Serv-U File Transfer Server Resource Exhaustion Exploited in the Wild Carries a Lapsed June 19th CISA KEV Federal Deadline | 7.5 High | KEV |
| 2026-09-22 | CVE-2026-25089 | Fortinet FortiSandbox's Unauthenticated OS Command Injection via Crafted HTTP Requests Covers Cloud and PaaS Deployments; CISA's July 19th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-21962 | Oracle HTTP Server and WebLogic Server Proxy Plug-in's Improper Access Control Allows Unauthenticated Network Attackers to Fully Compromise the Middleware Platform; CISA's August 27th KEV Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-21643 | Fortinet FortiClient EMS's SQL Injection Allows Unauthenticated Attackers to Execute Unauthorized Code via Crafted HTTP Requests; CISA's April 16th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-20316 | Cisco Secure Firewall Management Center Hard-Coded Password Lets Attackers Bypass Authentication; CISA's August 1st KEV Deadline for Covered Entities Has Passed | 5.3 Medium | KEV |
| 2026-09-22 | CVE-2026-20262 | Authenticated Path Traversal in Cisco Catalyst SD-WAN Manager Lets Remote Attackers Write Files Outside Allowed Directories; CISA's June 29th KEV Deadline Has Passed | 6.5 Medium | KEV |
| 2026-09-22 | CVE-2026-20253 | Splunk Enterprise's Missing Authentication on a PostgreSQL Sidecar Service Endpoint Lets Unauthenticated Users Create or Truncate Arbitrary Files; CISA's June 21st KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-20245 | Cisco Catalyst SD-WAN Manager's Improper Encoding Allows an Authenticated Local Attacker to Execute Arbitrary Commands as Root via a Crafted File; CISA's June 23rd KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-22 | CVE-2026-20230 | Cisco Unified Communications Manager SSRF Flaw Routes Attacker Requests to Internal Resources; CISA's June 28th KEV Deadline for Covered Entities Has Lapsed | 8.6 High | KEV |
| 2026-09-22 | CVE-2026-20200 | Cisco Unified Computing System's Argument Delimiter Injection Allows an Authenticated Attacker to Execute Arbitrary Commands on the Management Controller | 8.8 High | Exploited |
| 2026-09-22 | CVE-2026-20182 | Cisco Catalyst SD-WAN Controller and Manager's Authentication Bypass Gives Unauthenticated Remote Attackers Administrative Privileges; CISA's May 17th KEV Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-20133 | Cisco Catalyst SD-WAN Manager Leaks Sensitive Configuration Data to Unauthorized Users; CISA's April 23rd KEV Remediation Requirement Has Expired for Covered Entities | 6.5 Medium | KEV |
| 2026-09-22 | CVE-2026-20128 | Cisco Catalyst SD-WAN Manager Stores Credentials in a Recoverable Format, Enabling Credential Theft; CISA's April 23rd KEV Mandate for Covered Entities Has Lapsed | 7.5 High | KEV |
| 2026-09-22 | CVE-2026-20122 | Cisco Catalyst SD-WAN Manager Exposes Privileged API Functions to Unauthorized Callers; CISA's April 23rd KEV Remediation Deadline for Covered Entities Has Long Passed | 5.4 Medium | KEV |
| 2026-09-22 | CVE-2026-20079 | Cisco Firewall Management Center's Authentication Bypass via an Alternate Path Grants Unauthenticated Remote Attackers Full Administrative Control; CISA's September 12th KEV Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-19490 | Citrix NetScaler's Authentication Bypass via an Alternate Path Allows Unauthenticated Remote Attackers to Access Protected Resources Without Valid Credentials | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-16232 | Check Point SmartConsole's Improper Authentication Allows Unauthenticated Remote Attackers to Obtain a Login Token and Authenticate with Full Administrative Privileges; CISA's July 25th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-15410 | SonicWall SMA1000's Code Injection Allows a Remote Authenticated Administrator to Execute Arbitrary OS Commands Under Specific Conditions; CISA's July 17th KEV Deadline Has Passed | 7.2 High | KEV |
| 2026-09-22 | CVE-2026-15409 | SonicWall SMA1000 Secure Access Appliances Accept Forged Server-Side Requests, Enabling Internal Network Pivoting; CISA's July 17th KEV Remediation Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-1340 | Ivanti Endpoint Manager Mobile's Code Injection Vulnerability Allows Attackers to Achieve Unauthenticated Remote Code Execution; CISA's April 11th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-12569 | PTC Windchill and FlexPLM's Improper Input Validation Allows Unauthenticated Remote Attackers to Execute Arbitrary Code via Malicious Network Requests; CISA's June 28th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-10520 | Ivanti Sentry's OS Command Injection Gives Remote Unauthenticated Attackers Root-Level Remote Code Execution; CISA's June 14th KEV Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-0300 | PAN-OS Out-of-Bounds Write Enabling Code Execution Affects Both Palo Alto Networks Firewalls and Siemens RUGGEDCOM APE1808 Industrial Appliances; CISA's May 9th KEV Window Has Closed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-0257 | PAN-OS Authentication Bypass Enabling Unauthorized VPN Tunnels Affects Palo Alto Networks Prisma Access and Siemens RUGGEDCOM APE1808; Now Listed in CISA's Known Exploited Vulnerabilities Catalog | 9.1 Critical | KEV |
| 2026-09-22 | CVE-2025-68686 | Fortinet FortiOS's Information Exposure Flaw Allows a Remote Unauthenticated Attacker to Bypass the Previously Issued Patch for Symbolic Link Persistency; CISA's August 10th KEV Deadline Has Passed | 5.9 Medium | KEV |
| 2026-09-22 | CVE-2025-67038 | Lantronix EDS5000's Code Injection via the Username Parameter Executes Injected OS Commands with Root Privileges; CISA's June 26th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2025-62593 | Ray-Project Ray's Code Injection Flaw Allows Remote Attackers to Execute Arbitrary Code on the Distributed ML Framework's Cluster Nodes; CISA's August 20th KEV Deadline Has Passed | 8.8 High | KEV |
| 2026-09-22 | CVE-2025-60710 | Microsoft Windows Link Following Flaw Enables Privilege Escalation; CISA's April 27th KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-22 | CVE-2025-29635 | D-Link DIR-823X's set_prohibiting POST Endpoint Accepts Injected Commands and Executes Them on Remote Devices; CISA's May 8th KEV Deadline Has Passed for This Potentially End-of-Life Router | 7.2 High | KEV |
| 2026-09-22 | CVE-2025-2749 | Kentico Xperience's Path Traversal in the Staging Sync Server Allows Authenticated Users to Upload Arbitrary Data Outside Expected Directories; CISA's May 4th KEV Deadline Has Passed | 7.2 High | KEV |
| 2026-09-22 | CVE-2024-7399 | Samsung MagicINFO 9 Path Traversal Enabling Arbitrary File Writes as System Authority Has Missed CISA's May 8th KEV Deadline; Covered Entities Remain Out of Compliance | 8.8 High | KEV |
| 2026-09-22 | CVE-2024-57728 | SimpleHelp's Zip Slip Path Traversal Lets Admin Users Write Arbitrary Files to Any Location on the Server and Execute Code as the Service Account; CISA's May 8th KEV Deadline Has Passed | 7.2 High | KEV |
| 2026-09-22 | CVE-2024-57726 | SimpleHelp Lets Low-Privilege Technicians Mint Overpowered API Keys Through a Missing Authorization Check; CISA's May 8th KEV Deadline for Covered Entities Has Lapsed | 9.9 Critical | KEV |
| 2026-09-22 | CVE-2024-21182 | Unauthenticated T3 and IIOP Network Access to Oracle WebLogic Enables System Compromise; CISA's June 4th KEV Mandate for Covered Entities Has Been Lapsed for Months | 7.5 High | KEV |
| 2026-09-22 | CVE-2024-1708 | ConnectWise ScreenConnect's Path Traversal Enables Remote Code Execution or Direct Access to Confidential Data and Critical Systems; CISA's May 12th KEV Deadline Has Passed | 8.4 High | KEV |
| 2026-09-22 | CVE-2023-49105 | ownCloud's Improper Authentication Allows Unauthenticated Remote Attackers to Gain Access to Protected Files Without Valid Credentials; CISA's August 30th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2023-36424 | Microsoft Windows Common Log File System Driver's Out-of-Bounds Read Enables Privilege Escalation; CISA's April 27th KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-22 | CVE-2023-21529 | Microsoft Exchange Server's Deserialization of Untrusted Data Enables Authenticated Attackers to Achieve Remote Code Execution; CISA's April 27th KEV Deadline Has Passed | 8.8 High | KEV |
| 2026-09-22 | CVE-2022-0995 | Linux Kernel's Out-of-Bounds Write Allows Local Attackers to Escalate Privileges or Cause a Kernel Crash; CISA's September 9th KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-22 | CVE-2022-0492 | Linux Kernel's cgroup v1 release_agent Feature Enables Privilege Escalation; CISA's June 5th KEV Deadline for Covered Entities Has Lapsed | 7.8 High | KEV |
| 2026-09-22 | CVE-2021-27137 | Unauthenticated Attackers Can Overflow DD-WRT's UPnP Stack Buffer; CISA's July 24th KEV Mandate for Covered Entities Has Lapsed | 8.1 High | KEV |
| 2026-09-22 | CVE-2021-23758 | Ajax.NET Professional's Deserialization of Untrusted Data Allows Unauthenticated Remote Attackers to Execute Arbitrary Code via a Crafted Serialized Object; CISA's September 9th KEV Deadline Has Passed | 8.1 High | KEV |
| 2026-09-22 | CVE-2019-1068 | Microsoft SQL Server's Unspecified Flaw Allows Authenticated Attackers to Execute Arbitrary Code on the Database Server; CISA's August 29th KEV Deadline Has Passed | 8.8 High | KEV |
| 2026-09-22 | CVE-2015-5287 | Red Hat Automatic Bug Reporting Tool's Privilege Escalation Flaw Allows Local Attackers to Gain Root Access on Affected Enterprise Linux Systems; CISA's September 9th KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-22 | CVE-2015-3246 | Red Hat Enterprise Linux's Libuser Race Condition in Password File Writes Allows Local Attackers to Corrupt System Files; CISA's September 9th KEV Deadline Has Passed | 5.1 Medium | KEV |
| 2026-09-22 | CVE-2012-1854 | Microsoft Visual Basic for Applications Loads Libraries Insecurely, Enabling Remote Code Execution; CISA's April 27th KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-22 | CVE-2010-0806 | Microsoft Internet Explorer's Use-After-Free Enables Remote Code Execution via Invalid Pointer Access After Object Deletion; CISA's June 3rd KEV Deadline Has Passed | 8.8 High | KEV |
| 2026-09-22 | CVE-2010-0249 | Microsoft Internet Explorer's Use-After-Free Gives Remote Attackers Code Execution via a Pointer to a Deleted Object; CISA's June 3rd KEV Deadline Has Passed for This End-of-Life Browser | 8.8 High | KEV |
| 2026-09-22 | CVE-2009-1537 | Microsoft DirectX's QuickTime Movie Parser Filter Lets Remote Attackers Execute Arbitrary Code via a Crafted Media File; CISA's June 3rd KEV Deadline Has Passed | 8.8 High | KEV |
| 2026-09-22 | CVE-2009-0238 | Microsoft Office Code Injection From 2009 Added to CISA's Known Exploited Vulnerabilities Catalog with an April 28th Federal Deadline That Has Since Passed | 8.8 High | KEV |
| 2026-09-22 | CVE-2008-4250 | Microsoft Windows Server Service's Path Canonicalization Buffer Overflow Enables Remote Code Execution via Crafted RPC Requests; CISA's June 3rd KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-7273 | Zyxel GS1900 Series Switches' CGI Program Stack-Based Buffer Overflow Allows a LAN-Side Unauthenticated Attacker to Execute OS Commands via Crafted HTTP Requests; CISA's September 24th KEV Deadline Has Passed | 8.8 High | KEV |
| 2026-09-20 | CVE-2026-87886 | Acronis Backup's Incorrect Default Permissions Allow a Local Attacker to Access Backup Files and Configurations Not Intended for Their Account; CISA's September 19th KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-20 | CVE-2026-86060 | MikroTik RouterOS's Argument Injection in a Command-Processing Component Allows Unauthenticated Attackers to Execute Arbitrary Commands on the Router; CISA's September 13th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-20 | CVE-2026-85880 | Microsoft Windows' Heap-Based Buffer Overflow Allows Local Attackers to Escalate Privileges by Corrupting Heap Memory; CISA's September 22nd KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-20 | CVE-2026-84869 | ConnectWise ScreenConnect's Improper Privilege Management and Missing Authorization Allow Unauthenticated Attackers to Gain Administrative Control of the Remote Support Platform; CISA's September 14th KEV Deadline Has Passed | 9.9 Critical | KEV |
| 2026-09-20 | CVE-2026-81963 | Microsoft Windows' Improper Link Resolution Before File Access Allows a Local Attacker to Follow Symbolic Links to Privileged Files and Gain Elevated Access; CISA's September 22nd KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-20 | CVE-2026-70468 | Fortinet FortiManager's Authentication Bypass via an Alternate Path Grants Unauthenticated Attackers Access to Management Functions | 8.1 High | Updated |
| 2026-09-20 | CVE-2026-70465 | Fortinet FortiClient's Classic Buffer Overflow Allows an Attacker to Corrupt Memory and Potentially Execute Arbitrary Code | 8.1 High | Updated |
| 2026-09-20 | CVE-2026-67277 | MikroTik RouterOS's Missing Authentication for a Critical Function Allows Unauthenticated Attackers to Access and Modify Router Configuration; CISA's September 13th KEV Deadline Has Passed | 8.2 High | KEV |
| 2026-09-20 | CVE-2026-53362 | Linux Kernel's Unspecified Flaw Allows Local Attackers to Gain Elevated Privileges on Affected Systems; CISA's August 30th KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-20 | CVE-2026-53266 | Linux Kernel's Out-of-Bounds Write Vulnerability Allows Local Attackers to Escalate Privileges or Cause a Kernel Crash; CISA's September 21st KEV Deadline Has Passed | 8.8 High | KEV |
| 2026-09-20 | CVE-2026-50516 | Microsoft Azure Kubernetes Service's Missing Authentication on a Critical Function Allows Unauthenticated Attackers to Interact with Privileged Cluster Management Endpoints | 9.4 Critical | Updated |
| 2026-09-20 | CVE-2026-26035 | Fortinet FortiWeb's Improper Authentication Allows Unauthenticated Attackers to Bypass Login Controls and Access the Web Application Firewall Management Interface | 9.8 Critical | Updated |
| 2026-09-20 | CVE-2026-20349 | Cisco Secure Firewall ASA and FTD's Heap Inspection Vulnerability Allows Remote Attackers to Extract Sensitive Memory Contents from the Firewall Device; CISA's August 14th KEV Deadline Has Passed | 8.6 High | KEV |
| 2026-09-20 | CVE-2026-20301 | Cisco IOS XE's Unchecked Loop Condition Input Allows Network-Accessible Devices to Be Crashed via a Specially Crafted Packet | 8.6 High | Exploited |
| 2026-09-20 | CVE-2026-20273 | Cisco IOS XE's Improper Input Validation Allows a Remote Attacker to Trigger a Device Crash or Disruption via a Specially Crafted Input | 8.6 High | Updated |
| 2026-09-20 | CVE-2026-20272 | Cisco IOS XE's Injection Flaw Allows Remote Attackers to Execute Arbitrary Commands via a Specially Crafted Input Reaching a Downstream Component | 9.8 Critical | Updated |
| 2026-09-20 | CVE-2026-20271 | Cisco IOS XE's Insufficient Control Flow Management Allows a Remote Attacker to Disrupt Device Operation via a Crafted Packet | 8.6 High | Updated |
| 2026-09-20 | CVE-2026-20270 | Cisco IOS XE's Incorrect Calculation Vulnerability Allows a Remote Attacker to Cause an Unrecoverable Device Condition via a Specially Crafted Input | 8.6 High | Updated |
| 2026-09-20 | CVE-2026-20269 | Cisco IOS XE's Improper Resource Lifetime Management Allows Remote Attackers to Exhaust Device Resources and Cause a Denial of Service | 8.6 High | Updated |
| 2026-09-20 | CVE-2026-20268 | Cisco IOS XE's Improper Restriction of Memory Buffer Operations Allows Remote Attackers to Potentially Execute Code or Crash the Device via a Malformed Packet | 8.6 High | Updated |
| 2026-09-20 | CVE-2026-20267 | Cisco IOS XE's Improper Access Control Allows Network-Based Attackers to Access Protected Functions or Data Without Proper Authorization | 9.0 Critical | Updated |
| 2026-09-20 | CVE-2026-20124 | Cisco IOS XE's Memory Resource Leak Allows Remote Attackers to Exhaust Device Memory and Cause a Denial of Service via Repeated Packet Transmission | 7.7 High | Exploited |
| 2026-09-20 | CVE-2026-0301 | Palo Alto Networks Cloud NGFW and Prisma Access Use of Uninitialized Resource Allows a Network-Based Attacker to Access Sensitive Information | 7.5 High | Exploited |
| 2026-09-20 | CVE-2026-0299 | Palo Alto Networks GlobalProtect's Untrusted Search Path Allows a Local Attacker to Load a Malicious Library and Execute Code in the Application's Context | 7.8 High | Exploited |
| 2026-09-20 | CVE-2026-0298 | Palo Alto Networks GlobalProtect's Code Injection Vulnerability Allows an Authenticated Remote Attacker to Execute Arbitrary Code in the Context of the VPN Client | 8.1 High | Exploited |
| 2026-09-20 | CVE-2026-0297 | Palo Alto Networks GlobalProtect's Out-of-Bounds Write Allows a Remote Attacker to Corrupt Memory and Execute Code or Crash the Application | 8.1 High | Exploited |
| 2026-09-20 | CVE-2026-0296 | Palo Alto Networks GlobalProtect's Improper Certificate Validation Allows a Network Adversary to Present a Forged Certificate and Intercept the VPN Connection | 7.4 High | Exploited |
| 2026-09-20 | CVE-2026-0295 | Palo Alto Networks GlobalProtect's Race Condition Allows a Local Attacker to Exploit a Timing Window and Gain Elevated Privileges | 7.0 High | Exploited |
| 2026-09-20 | CVE-2026-0294 | Palo Alto Networks Prisma Access Agent's Uncontrolled Search Path Allows a Local Attacker to Place a Malicious Library Where the Agent Will Load It | 7.8 High | Exploited |
| 2026-09-20 | CVE-2025-39964 | Linux Kernel's Race Condition Allows a Local Attacker to Exploit a Timing Window and Gain Elevated Privileges on the System; CISA's September 21st KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-20 | CVE-2025-39682 | Linux Kernel's Improper Check for Exceptional Conditions Allows Remote Attackers to Execute Arbitrary Code or Crash Affected Systems; CISA's September 21st KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-20 | CVE-2025-25249 | Fortinet Multiple Products' Heap-Based Buffer Overflow Allows Remote Attackers to Potentially Execute Arbitrary Code or Crash Affected Devices; CISA's September 12th KEV Deadline Has Passed | 8.1 High | KEV |
| 2026-09-20 | CVE-2026-82078 | PaperCut NG/MF's Unsafe Reflection Allows Remote Attackers to Manipulate Class Loading and Execute Arbitrary Code on the Print Management Server; CISA's September 14th KEV Deadline Has Passed | 9.1 Critical | KEV |
| 2026-09-20 | CVE-2026-72530 | TrueConf Server's Code Injection Vulnerability Allows Remote Attackers to Execute Arbitrary Code on the Video Conferencing Platform; CISA's September 3rd KEV Deadline Has Passed | 9.0 Critical | KEV |
| 2026-09-20 | CVE-2026-72529 | TrueConf Server's Missing Authentication on a Critical Function Allows Unauthenticated Remote Attackers to Access Administrative Capabilities; CISA's August 23rd KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-20 | CVE-2026-70332 | Microsoft SharePoint Online's Cross-Site Scripting Flaw Lets Attackers Execute Arbitrary JavaScript in the Victim's Browser Session | 9.6 Critical | Updated |
| 2026-09-20 | CVE-2026-66322 | Microsoft Edge's Origin Validation Error Allows a Cross-Origin Attacker to Bypass Boundary Enforcement and Access Content from a Different Origin | 7.1 High | Updated |
| 2026-09-20 | CVE-2026-66321 | Microsoft Edge's Type Confusion in the Browser Engine Allows a Remote Attacker to Execute Arbitrary Code via a Crafted Web Page | 7.4 High | Updated |
| 2026-09-20 | CVE-2026-66318 | Microsoft Edge's Origin Validation Error Exposes Protected Resources to Cross-Origin Content Access by a Network Attacker | 8.1 High | Updated |
| 2026-09-20 | CVE-2026-66315 | Microsoft Edge's Use After Free Vulnerability Lets a Remote Attacker Corrupt the Browser Heap and Potentially Execute Code via a Crafted Web Page | 7.5 High | Updated |
| 2026-09-20 | CVE-2026-66310 | Microsoft Edge's Externally Controlled File Path Allows a Crafted Web Page to Reference Arbitrary Files on the Local System | 7.7 High | Updated |
| 2026-09-20 | CVE-2026-65802 | Microsoft Edge's External Control of a File Path Flaw Allows Attackers to Read or Write Files Outside the Intended Browsing Sandbox via a Crafted Page | 7.4 High | Updated |
| 2026-09-20 | CVE-2026-65668 | Microsoft Purview eDiscovery's Improper Access Control Allows Authenticated Attackers to Access Data Outside Their Authorized Scope | 8.8 High | Updated |
| 2026-09-20 | CVE-2026-65667 | Microsoft Teams Carries a Critical 10.0 CVSS Score for a Missing Authorization Flaw That Lets Authenticated Users Access Privileged Functions | 10.0 Critical | Updated |
| 2026-09-20 | CVE-2026-63508 | Microsoft Planetary Computer's Missing Authentication on a Critical Endpoint Allows Unauthenticated Attackers to Access and Execute Privileged Functions | 10.0 Critical | Updated |
| 2026-09-20 | CVE-2026-62918 | Microsoft Teams' Improper Cryptographic Signature Verification Allows Attackers to Submit Forged Messages That the Application Accepts as Authentic | 7.5 High | Updated |
| 2026-09-20 | CVE-2026-62896 | Microsoft Teams' Improper Authentication Allows Unauthenticated Remote Attackers to Access the Platform Without Valid Credentials | 9.6 Critical | Updated |
| 2026-09-20 | CVE-2026-62873 | Microsoft Windows Admin Center's Improper Cryptographic Signature Verification Enables Unauthenticated Attackers to Forge Signed Requests and Gain Unauthorized Access | 9.8 Critical | Updated |
| 2026-09-20 | CVE-2026-62870 | Microsoft Excel's Use After Free Vulnerability Lets Remote Attackers Execute Arbitrary Code via a Specially Crafted Workbook | 8.8 High | Updated |
| 2026-09-20 | CVE-2026-59115 | Microsoft Entra Provisioning Service's Path Traversal Flaw Allows Attackers to Navigate Outside the Intended Directory and Access Provisioned Tenant Data | 9.9 Critical | Updated |
| 2026-09-20 | CVE-2026-58612 | Microsoft PowerShell's High-Severity Flaw Allows a Network-Based Attacker to Gain Unauthorized Access on Affected Installations | 7.4 High | Updated |
| 2026-09-20 | CVE-2026-57105 | Microsoft SharePoint Server's Unspecified Flaw Allows an Authenticated Attacker to Gain Unauthorized Access to Server Resources | 8.0 High | Updated |
| 2026-09-20 | CVE-2025-40582 | Siemens SCALANCE LPE9403's Configuration Parameter Handling Flaw Lets Non-Privileged Local Attackers Execute Commands as Root When SINEMA Remote Connect Edge Client Is Installed | 7.8 High | Updated |
| 2026-09-20 | CVE-2025-40581 | Siemens SCALANCE LPE9403's Authentication Bypass Allows Non-Privileged Local Attackers to Bypass Authentication Controls on Affected Versions | 7.1 High | Updated |
| 2026-09-20 | CVE-2025-40574 | Siemens SCALANCE LPE9403's Incorrect Permissions on Critical Resources Expose the Backup Manager Service to Non-Privileged Local Attackers | 7.8 High | Updated |
| 2026-09-18 | CVE-2026-87491 | Google Chromium V8's Out-of-Bounds Write Allows Remote Attackers to Corrupt the JavaScript Engine's Heap and Execute Arbitrary Code via a Crafted Web Page | 8.8 High | KEV |
| 2026-09-18 | CVE-2026-59822 | BerriAI LiteLLM's Improper Authentication Allows Unauthenticated Attackers to Access the AI Model Gateway and Interact with Configured LLM Endpoints Without Credentials | 8.2 High | KEV |
| 2026-09-18 | CVE-2026-58704 | Google Pixel's Improper Authorization Flaw Allows an Attacker with Physical or Local Access to Bypass Permission Controls and Access Protected Device Functions | 8.8 High | KEV |
| 2026-09-18 | CVE-2026-49869 | Kestra OSS's OS Command Injection Flaw Lets Unauthenticated Remote Attackers Execute Arbitrary Commands on the Workflow Orchestration Server with Full System Privileges | 10.0 Critical | KEV |
| 2026-09-18 | CVE-2026-15688 | Mitsubishi Electric GX Works3 and Motion Control Setting Authentication Algorithm Allows a Local Attacker to Successfully Authenticate with an Invalid Block Password by Modifying the Executable Module in Memory | 9.2 Critical | New |
| 2026-09-18 | CVE-2026-12745 | Ivanti Neurons for ITSM Before 2026.2 Deserialization of Untrusted Data Allows Unauthenticated Remote Attackers to Execute Arbitrary Code on the Server | 9.8 Critical | Updated |
| 2026-09-18 | CVE-2026-12744 | Ivanti Neurons for ITSM Before 2026.2 Deserialization of Untrusted Data Allows a Second Unauthenticated Remote Code Execution Path on the Server | 9.8 Critical | Updated |
| 2026-09-18 | CVE-2026-12650 | Ivanti Neurons for ITSM Before 2026.2 Deserialization of Untrusted Data Allows Authenticated Remote Attackers to Execute Arbitrary Code on the Server, Scoring CVSS 9.9 | 9.9 Critical | Updated |
| 2026-09-18 | CVE-2026-12647 | Ivanti Neurons for ITSM Before 2026.2 Missing Authorization Lets Authenticated Remote Attackers Execute Arbitrary Code on the Server, Scoring CVSS 9.9 | 9.9 Critical | Updated |
| 2026-09-18 | CVE-2026-12646 | Ivanti Neurons for ITSM Before 2026.2 Missing Authorization Lets Authenticated Remote Attackers Execute Arbitrary Code on the Server via a Second Unprotected Path | 9.9 Critical | Updated |
| 2026-09-18 | CVE-2026-12645 | Ivanti Neurons for ITSM Before 2026.2 Missing Authorization Lets Authenticated Remote Attackers Execute Arbitrary Code on the Server via a Third Unprotected Path | 9.9 Critical | Updated |
| 2026-09-17 | CVE-2026-93188 | Linux Kernel HID Roccat Driver Uses an 8-bit Device-Supplied Profile Value as an Array Index Without Bounds Checking, Enabling an Out-of-Bounds Memory Access via a Crafted USB Device | — | New |
| 2026-09-17 | CVE-2026-90099 | Linux Kernel TC Classifier Filter Allocations in the change() Path Use Plain GFP Flags Without Accounting to memcg, Allowing Container Workloads to Exhaust Host Memory Without Being Charged | — | New |
| 2026-09-17 | CVE-2026-90058 | Linux Kernel qdisc_calculate_pkt_len Amplifies User-Supplied Size Table Values Without Bounds Checking, Allowing a Crafted Size Table to Cause a Soft Lockup in the Packet Scheduler | — | New |
| 2026-09-17 | CVE-2026-73453 | Arista EOS P4Runtime Client Interface Allows Unauthenticated Arbitrary Code Execution Under Certain Conditions on Platforms Running EOS with P4Runtime Configured, Scoring CVSS 10.0 | 10.0 Critical | New |
| 2026-09-17 | CVE-2026-73447 | Arista EOS gRPC Network Security Interface Certz Service Lets a Privileged Authenticated User Execute Arbitrary Commands with Root Privileges, Leading to Full Device Compromise | 9.1 Critical | New |
| 2026-09-17 | CVE-2026-73437 | Arista EOS DHCP Relay Forwards Crafted Reply Packets From Non-Helper-Address Sources to Clients Without Validation, Letting Unauthenticated Network Attackers Inject Arbitrary DHCP Responses to Hosts | 9.6 Critical | New |
| 2026-09-14 | CVE-2026-89478 | Linux Kernel SCTP Authenticated ASCONF DEL-IP Removes a Transport While a Backlogged Chunk Still Holds a Pointer to It, Enabling Use-After-Free on the Next SACK | 9.8 Critical | New |
| 2026-09-11 | CVE-2026-84390 | Fortinet FortiMonitorOnSight 7.2.0 Through 7.2.7 Embeds Sensitive Information in Source Code, Potentially Allowing Attackers to Gain Unauthorized Access via Exposed Credentials | 9.8 Critical | New |
| 2026-09-11 | CVE-2026-79698 | Advantech WISE-6610 Series Management Interface Fails to Neutralize Special Elements in a Command Argument, Allowing Unauthenticated Remote Attackers to Inject Arbitrary Application Commands | 9.9 Critical | New |
| 2026-09-11 | CVE-2026-63298 | LXD NVIDIA Instance Configuration Handler Accepts Newline Characters in nvidia.driver.capabilities and nvidia.require.* Values, Letting Authenticated Attackers Inject Arbitrary Directives into the GPU Configuration | 9.9 Critical | Updated |
| 2026-09-10 | CVE-2026-69240 | Sequelize Before 6.37.4 Fails to Escape Quotes in the Oracle Dialect When a String Value Starts with TO_TIMESTAMP or TO_DATE, Enabling SQL Injection Against Oracle Databases | 9.8 Critical | New |
| 2026-09-08 | CVE-2026-81939 | SonicWall Network Security Manager On-Prem File Upload Extracts Archive Entries Without Validating Path Components, Enabling Zip Slip File Placement Outside the Intended Destination Directory | 9.1 Critical | New |
| 2026-09-08 | CVE-2026-79697 | Advantech WISE-6610 Series Management Interface Exposes a Second Special-Element Injection Path, Allowing Unauthenticated Remote Attackers to Manipulate Application Command Execution | 9.9 Critical | New |
| 2026-09-08 | CVE-2026-78328 | SonicWall Network Security Manager On-Prem Lets a Lower-Privileged Admin Escalate to SuperAdmin Due to a Missing Authorization Check | 9.1 Critical | New |
| 2026-09-08 | CVE-2026-78327 | SonicWall Network Security Manager On-Prem Management Interface Passes Authenticated User Input to the OS Shell, Enabling Arbitrary Command Execution | 9.1 Critical | New |
| 2026-09-08 | CVE-2026-75925 | IXON VPN Client Before 1.4.7 Writes Local Service Configuration Values to a File Without Stripping Line-Ending Sequences, Letting an Attacker Inject Commands That Execute as Root or SYSTEM via a Privileged Subprocess | 9.6 Critical | New |
| 2026-09-08 | CVE-2026-45538 | OpenSIPS 4.0.0 and Prior Stack Buffer Overflow in sip_to_json When a SIP Header Name Exceeds 255 Bytes, Enabling Remote Code Execution via Crafted SIP Messages | 9.8 Critical | New |
| 2026-09-08 | CVE-2026-26084 | Fortinet FortiSandbox 4.4.x and 5.0.x Improper Access Control Lets Attackers Access Sensitive Information via Crafted HTTP Requests | 9.9 Critical | New |
| 2026-09-08 | CVE-2026-10090 | Red Hat Advanced Cluster Management Application Subscription Controller Lets a User with Namespace-Scoped Edit Privileges Create a Channel Pointing to an Attacker-Controlled Helm Repository, Enabling Privilege Escalation | 9.0 Critical | New |
| 2026-09-04 | CVE-2026-85224 | D-Link DNS-320 ShareCenter 2.06B01 File Sharing CGI Passes the fileurl Parameter Unsanitized to the Shell, Enabling Remote Code Execution by Authenticated Admin Users | 9.1 Critical | New |
| 2026-09-04 | CVE-2026-85223 | D-Link DNS-340L 1.01B04 Dropbox CGI Injects the callback_url and sync_interval Fields Directly into the Shell, Allowing Low-Privileged Authenticated Attackers to Execute Remote Commands | 9.9 Critical | New |
| 2026-09-04 | CVE-2026-85222 | D-Link DNS-340L 1.01B04 Add-On Center CGI Passes f_name, f_url, and f_flag Unsanitized to the Shell, Enabling Authenticated Admin Remote Code Execution | 9.1 Critical | New |
| 2026-09-02 | CVE-2026-82691 | D-Link DNS-320L, DNS-327L, DNS-340L, and DNS-345 USB Device Handler Passes Unsanitized Input to the Shell, Enabling Authenticated Admin Remote Code Execution | 9.1 Critical | New |
| 2026-09-01 | CVE-2026-82688 | D-Link DNS-340L and DNS-345 Virtual Volume CGI Injects Input Arguments Unsanitized into the Shell, Enabling Authenticated Admin Remote Code Execution | 9.1 Critical | New |
| 2026-09-01 | CVE-2026-82593 | D-Link DIR-825M 1.1.8 LTE Fibocom Firmware Upgrade Handler Copies Unbounded User Input into a Fixed Stack Buffer, Enabling Unauthenticated Remote Code Execution | 9.9 Critical | New |
| 2026-08-31 | CVE-2026-82692 | D-Link DNS-340L and DNS-345 iSCSI Manager CGI Passes alias, username, and password Arguments Directly to the Shell, Allowing Low-Privileged Attackers to Execute Remote Code | 9.9 Critical | New |
| 2026-08-31 | CVE-2026-82690 | D-Link DNS-327L and DNS-340L Virtual Environment Manager CGI Injects Unsanitized User Arguments into the Shell, Enabling Authenticated Admin Remote Code Execution | 9.1 Critical | New |
| 2026-08-31 | CVE-2026-82689 | D-Link DNS-320L, DNS-327L, DNS-340L, and DNS-345 ISO Image Mount Handler Passes Mount Arguments Unsanitized to the Shell, Allowing Low-Privileged Attackers to Execute Remote Commands | 9.9 Critical | New |
| 2026-08-31 | CVE-2026-82592 | D-Link DIR-825M 1.1.8 Disk Format Handler Overflows a Stack Buffer When the manipulation Parameter Exceeds Its Declared Bounds, Enabling Unauthenticated Remote Code Execution | 9.9 Critical | New |
| 2026-08-31 | CVE-2026-71957 | D-Link DWR-M961 C1 app.cgi Overflows a Stack Buffer on a Long netAcc.addlist[].name Value, Enabling Unauthenticated Remote Code Execution | 9.8 Critical | New |
| 2026-08-31 | CVE-2026-71956 | D-Link DWR-M961 C1 app.cgi Injects the netDig.ping.dst Field Unsanitized into the Shell, Enabling Unauthenticated Remote Code Execution with Root Privileges | 9.8 Critical | New |
| 2026-08-31 | CVE-2026-71952 | D-Link DWR-M961 C1 PIN Management Setup Handler Injects the oldPIn Field Into the Shell Without Sanitization, Enabling Unauthenticated Remote Root Code Execution | 9.8 Critical | New |
| 2026-08-31 | CVE-2026-71951 | D-Link DWR-M961 C1 IMEI Setup Handler Passes the IMEI_value Field Unsanitized to the Shell, Enabling Unauthenticated Remote Root Code Execution | 9.8 Critical | New |
| 2026-08-31 | CVE-2026-71950 | D-Link DWR-M961 C1 SMS Management Handler Injects the action_value Field Directly into the Shell, Enabling Unauthenticated Remote Root Code Execution | 9.8 Critical | New |
| 2026-08-31 | CVE-2026-71947 | D-Link DWR-M961 C1 Traceroute Diagnostic Handler Injects the host and ipVer Fields into the Shell Without Sanitization, Enabling Unauthenticated Remote Root Code Execution | 9.8 Critical | New |
| 2026-08-31 | CVE-2026-71946 | D-Link DWR-M961 C1 Ping Diagnostic Run Handler Passes the host Field Unsanitized to the Shell, Enabling Unauthenticated Remote Root Code Execution | 9.8 Critical | New |
| 2026-08-28 | CVE-2026-80660 | Linux Kernel OCC hwmon Driver Unregisters sysfs Devices While Holding the OCC Lock, Causing a Deadlock When hwmon_device_unregister Tries to Flush sysfs Work Items | — | New |
| 2026-08-28 | CVE-2026-80659 | Linux Kernel MMC vub300 Driver Issues a Reset While Holding cmd_mutex, Blocking the Command Thread That Must Complete Before the Reset Can Proceed | — | New |
| 2026-08-28 | CVE-2026-71958 | D-Link DWR-M961 C1 quicksetup.cgi Overflows a Stack Buffer on Long test4, ssid2, or username Values, Enabling Unauthenticated Remote Code Execution | 9.8 Critical | New |
| 2026-08-28 | CVE-2026-71955 | D-Link DWR-M961 C1 formWsc Handler Injects localPin, targetAPSsid, peerPin, and peerRptPin Fields into the Shell Without Sanitization, Enabling Unauthenticated Remote Root Code Execution | 9.8 Critical | New |
| 2026-08-28 | CVE-2026-71954 | D-Link DWR-M961 C1 L2TPv3 Configuration Handler Injects tunnelid and sessionid Fields Directly into the Shell, Enabling Unauthenticated Remote Root Code Execution | 9.8 Critical | New |
| 2026-08-28 | CVE-2026-71953 | D-Link DWR-M961 C1 NTP Setup Handler Passes the ntpServerIp1 Field Unsanitized to the Shell, Enabling Unauthenticated Remote Root Code Execution | 9.8 Critical | New |
| 2026-08-28 | CVE-2026-71949 | D-Link DWR-M961 C1 USSD Setup Handler Injects ussdValue and selectMenuValue into the Shell Without Sanitization, Enabling Unauthenticated Remote Root Code Execution | 9.8 Critical | New |
| 2026-08-28 | CVE-2026-71948 | D-Link DWR-M961 C1 Debug Diagnostic Run Handler Passes the host Field Unsanitized to the Shell, Enabling Unauthenticated Remote Root Code Execution | 9.8 Critical | New |
| 2026-08-28 | CVE-2026-71945 | D-Link DWR-M961 C1 LTE Fibocom Firmware Upgrade Handler Injects the fota_url Field into the Shell Without Sanitization, Enabling Unauthenticated Remote Root Code Execution | 9.8 Critical | New |
| 2026-08-28 | CVE-2026-71944 | D-Link DWR-M961 C1 LTE Quectel Firmware Upgrade Handler Passes the fota_url Field Unsanitized to the Shell, Enabling Unauthenticated Remote Root Code Execution | 9.8 Critical | New |
| 2026-08-27 | CVE-2026-76312 | Splunk Enterprise Below 10.4.1 Exposes Session Material in the HTML Source of Pages Embedding Reports, Letting Unauthenticated Users Who Can Read That Source Access All Report Data and Affect System Integrity | 9.4 Critical | Updated |
| 2026-08-27 | CVE-2026-76311 | Splunk Enterprise Below 10.4.2 Lets an Unauthenticated User with an Embedded Report Token Download the Search Job Dispatch Archive and Recover Session Material for Full Report Data Access | 9.4 Critical | Updated |
| 2026-08-27 | CVE-2026-76310 | Splunk Enterprise Below 10.4.2 Lets an Unauthenticated User with an Embedded Report Token Download the Dispatch Archive and Recover Session Tokens That Grant Access to All Data Available to the Report Owner | 9.4 Critical | Updated |
| 2026-08-27 | CVE-2026-72508 | Red Hat Advanced Cluster Management Multicloud Subscription Component Lets a Namespace-Admin Tenant Abuse a Privileged ServiceAccount via Subscription CRs, Enabling a Confused-Deputy Attack Against Other Cluster Namespaces | 9.9 Critical | New |
| 2026-08-27 | CVE-2026-70398 | Red Hat Advanced Cluster Management GitOpsCluster Controller Lets an Authenticated Tenant Redirect Spoke Cluster Bearer Tokens to an Attacker-Controlled Endpoint, Enabling a Confused-Deputy Attack | 9.6 Critical | New |
| 2026-08-27 | CVE-2026-61272 | Oracle JD Edwards EnterpriseOne Tools Web Runtime SEC Component Allows Unauthenticated HTTP Attackers to Compromise the Application, Enabling Full Takeover of the EnterpriseOne Tools Instance | 9.8 Critical | Updated |
| 2026-08-26 | CVE-2026-13206 | Zyxel WAH7601 Through July 2026 Firmware OS Command Injection Allows Attackers to Execute Arbitrary OS Commands on Affected Devices | 9.8 Critical | New |
| 2026-08-25 | CVE-2026-74688 | Linux Kernel SCTP Heartbeat ACK Chunk Caches a Transport Without Taking a Reference, Enabling Use-After-Free When That Transport Is Concurrently Removed | 9.8 Critical | New |
| 2026-08-25 | CVE-2026-74588 | Linux Kernel SCTP Retransmit Path Moves a Gap-Acked Chunk to a New Transport Without Updating the Chunk's Cached Transport Pointer, Enabling Use-After-Free | 9.8 Critical | New |
| 2026-08-25 | CVE-2026-74587 | Linux Kernel SCTP Teardown Path Frees the Cached Outbound ASCONF Chunk Without Clearing the Cache Pointer, Exposing a Use-After-Free | 9.8 Critical | New |
| 2026-08-25 | CVE-2026-74586 | Linux Kernel SCTP Fails to Clear new_transport After DEL-IP Peer Removal, Leaving a Dangling Pointer That Subsequent ASCONF Processing Reads | 9.8 Critical | New |
| 2026-08-23 | CVE-2026-68136 | Linux Kernel GRO Path Performs Double Aggregation of flush-Marked Skbs Because skb_gro_receive_list Lacks the Flush Check Added to skb_gro_receive | 9.8 Critical | New |
| 2026-08-22 | CVE-2026-74677 | Linux Kernel ipheth USB Ethernet Driver Re-Arms carrier_work on Any Non-Zero URB Status After Disconnect Begins, Causing a Use-After-Free When the Work Item Runs After the Device Structure Is Freed | — | New |
| 2026-08-20 | CVE-2026-47865 | VMware Avi Load Balancer 31.x Through 31.2.2 and 30.x Through 30.2.6 Authentication Bypass Lets Network-Accessible Attackers Reach the Avi Control Plane Without Valid Credentials | 9.8 Critical | Updated |
| 2026-08-20 | CVE-2026-20231 | Cisco Secure Workload Improper Neutralization of Special Elements Vulnerabilities Allow Authenticated Attackers to Inject Directives into Application Commands, Scoring CVSS 9.9 | 9.9 Critical | New |
| 2026-08-20 | CVE-2026-20030 | Cisco Crosswork Multiple Internally Discovered SQL Injection Vulnerabilities Allow Authenticated Attackers to Execute Arbitrary SQL Against the Underlying Database, Scoring CVSS 10.0 | 10.0 Critical | New |
| 2026-08-19 | CVE-2026-74468 | Linux Kernel PCH GPIO Driver Acquires a Regular Spinlock in irq_set_type Which Can Be Called From a Non-IRQ Context, Leading to a Deadlock When Interrupts Are Disabled | — | New |
| 2026-08-19 | CVE-2026-72392 | Linux Kernel IPv6 FIB6 Walk Reuses a Stale Position Index Across Hash Chain Batches During a Multi-Batch Netlink Dump, Triggering a NULL Dereference in fib6_walk_continue | — | New |
| 2026-08-19 | CVE-2026-68369 | Linux Kernel USB Gadget Printer Driver printer_read Uses the Same Variable for Requested Copy Size and Bytes Copied, Looping Indefinitely When copy_to_user Fails to Copy Anything | — | New |
| 2026-08-19 | CVE-2026-68160 | Linux Kernel Ceph Cap Handler Reads snap_trace_len from the Wire and Uses It Without Bounds Checking, Enabling a Network-Controlled Out-of-Bounds Read Before Authentication | 9.8 Critical | New |
| 2026-08-19 | CVE-2026-68137 | Linux Kernel X.25 Drops the x25_list_lock Before Calling sock_hold During Neighbour Teardown, Allowing a Concurrent Free to Race and Produce a Use-After-Free | 9.8 Critical | New |
| 2026-08-19 | CVE-2026-68127 | Linux Kernel ILA Caches the IPv6 Header Pointer Before pskb_may_pull, Which Can Reallocate the Header on a Non-Linear skb, Producing a Stale Pointer in Checksum Adjust | 9.8 Critical | New |
| 2026-08-19 | CVE-2026-68117 | Linux Kernel TIPC Socket Creation Error Path Frees the sk While Leaving sock->sk Pointing at the Freed Object, Enabling a Use-After-Free on Subsequent Socket Operations | 9.8 Critical | New |
| 2026-08-19 | CVE-2026-64565 | Linux Kernel Input ims-pcu Driver ims_pcu_process_data Processes Incoming URB Data Without Checking Whether read_pos Exceeds IMS_PCU_BUF_SIZE, Enabling Heap Buffer Overflow via a Crafted USB Device | — | New |
| 2026-08-19 | CVE-2026-64564 | Linux Kernel SCTP DEL-IP Processing Frees the Transport Cached on the ASCONF Chunk Itself, Triggering Use-After-Free on the Chunk's Own Transport Pointer | 9.8 Critical | New |
| 2026-08-18 | CVE-2026-72585 | CVE-2026-72585 Rejected by Red Hat CNA-LR as Not a Valid Security Vulnerability Following Internal Review | — | New |
| 2026-08-17 | CVE-2026-74287 | Linux Kernel SCTP ASCONF Chunk Processing Skips Length Validation of Embedded Address Parameters, Allowing Network-Controlled Data to Trigger Out-of-Bounds Reads | 9.1 Critical | New |
| 2026-08-17 | CVE-2026-72568 | CVE-2026-72568 Rejected by Red Hat CNA-LR as Not a Valid Security Vulnerability Following Internal Review | — | New |
| 2026-08-17 | CVE-2026-72540 | CVE-2026-72540 Rejected by Red Hat CNA-LR as Not a Valid Security Vulnerability Following Internal Review | — | New |
| 2026-08-17 | CVE-2026-72293 | Linux Kernel KVM s390 VSIE Shadow Fault Handler Missing radix_tree_preload Call Can Block Forward Progress Under Memory Pressure During Fault Handling | — | New |
| 2026-08-17 | CVE-2026-72265 | Linux Kernel nvidiafb Driver nvidiafb_probe Error Path Leaks the modelist Memory Allocated by nvidia_set_fbinfo When Subsequent Initialization Steps Fail | — | New |
| 2026-08-17 | CVE-2026-71245 | CVE-2026-71245 Rejected by Red Hat CNA-LR as Not a Valid Security Vulnerability Following Internal Review | — | New |
| 2026-08-17 | CVE-2026-68170 | Linux Kernel MPTCP Cleans Up Subflow backlog References Outside the Lock That Guards the Backlog List, Leaving a Stale skb->sk Pointer After Subflow Close | 9.8 Critical | New |
| 2026-08-17 | CVE-2026-68122 | Linux Kernel OpenVPN Driver Peer Reference Count Leaks in the TCP Error Path When defer_del_work Is Already Pending, Preventing Timely Peer Cleanup | — | New |
| 2026-08-17 | CVE-2026-68092 | Linux Kernel Uses the jiffies Clocksource Before It Is Registered With the Clocksource Framework, Causing XEN HVM Guests to Experience Long Boot Delays Due to Negative Motion Reporting | — | New |
| 2026-08-17 | CVE-2026-68090 | Linux Kernel debugobjects OOM Disable Path Races Against a Concurrent hrtimer_fixup_assert_init Call, Producing a Spurious stub_timer Callback Warning | — | New |
| 2026-08-17 | CVE-2026-64603 | Linux Kernel Intel HID ACPI Notify Handler Can Run Concurrently on Multiple CPU Cores Since commit e2ffcda16290, Causing Race Conditions in the Hot-Plug Notification Handler | — | New |
| 2026-08-17 | CVE-2026-64593 | Linux Kernel btrfs Trim Path Calls blkdev_issue_discard on a Device Marked Read-Only During Degraded Mount, Dereferencing a NULL Device Pointer and Panicking | — | New |
| 2026-08-17 | CVE-2026-28323 | SolarWinds Web Help Desk SAML 2.0 Authentication Bypass Lets Attackers Authenticate Without Valid Credentials When SAML Is Enabled | 9.8 Critical | Updated |
| 2026-08-14 | CVE-2026-20310 | Cisco Catalyst SD-WAN Addresses Multiple Internally Discovered Improper Link Resolution Vulnerabilities That Could Allow Local Privilege Escalation via Symlink Following | 9.1 Critical | New |
| 2026-08-14 | CVE-2026-20304 | Cisco Catalyst SD-WAN Improper Access Control Vulnerabilities Allow Attackers to Perform Unauthorized Actions on Affected Systems, Scoring CVSS 9.9 | 9.9 Critical | New |
| 2026-08-14 | CVE-2026-20303 | Cisco Catalyst SD-WAN Improper Input Validation Vulnerabilities Enable Attackers to Cause Unintended System Behavior on Affected Deployments, Scoring CVSS 9.9 | 9.9 Critical | New |
| 2026-08-13 | CVE-2026-64125 | Linux Kernel bcmgenet Driver Enabling RBUF EEE and PM Bits Stops RX Traffic When MAC EEE Activates, Causing a Denial-of-Service Condition on Broadcom GENET Hardware | 9.8 Critical | Updated |
| 2026-08-12 | CVE-2026-3141 | FormGent WordPress Plugin Through 1.9.2 Missing Capability Check on the formgent/responses/attachments REST Endpoint Lets Any Authenticated User Delete Arbitrary Attachments | 9.1 Critical | New |
| 2026-08-07 | CVE-2026-67261 | Dell Virtual Storage Integrator for VMware vSphere Client IAPI Component Accepts Unauthenticated Remote Input and Passes It to the OS Shell, Enabling Arbitrary Command Execution on the Application Host | 9.8 Critical | Updated |
| 2026-08-07 | CVE-2026-56160 | Azure Red Hat OpenShift Improper Authorization Lets an Authorized Attacker Escalate Privileges Over the Network | 9.1 Critical | Updated |
| 2026-08-07 | CVE-2026-54489 | Dell Virtual Storage Integrator for VMware vSphere Client Exposes Sensitive Information to Unauthenticated Remote Attackers, Enabling Information Disclosure and Session Hijacking | 9.1 Critical | Updated |
| 2026-08-07 | CVE-2026-47623 | NVIDIA Dynamo's Deserialization of Untrusted Data Allows Remote Attackers to Execute Arbitrary Code via a Crafted Serialized Object | 8.2 High | Updated |
| 2026-08-07 | CVE-2026-47618 | NVIDIA Dynamo's Server-Side Request Forgery Flaw Lets Attackers Use the Inference Server as an HTTP Proxy to Reach Internal Services | 7.5 High | Updated |
| 2026-08-07 | CVE-2026-47617 | NVIDIA Dynamo Server-Side Request Forgery Flaw Allows Attackers to Make the Service Issue Requests to Arbitrary Hosts, Including Internal Resources | 7.5 High | Updated |
| 2026-08-07 | CVE-2026-47616 | NVIDIA Dynamo's SSRF Vulnerability Exposes Internal Network Infrastructure to Attackers Who Can Redirect the Server's Outbound HTTP Connections | 7.5 High | Updated |
| 2026-08-07 | CVE-2026-47615 | NVIDIA Dynamo's Unvalidated URL Handling Lets Attackers Steer the Inference Server's HTTP Requests Toward Internal Hosts and Retrieve Their Responses | 7.5 High | Updated |
| 2026-08-07 | CVE-2026-47614 | NVIDIA Dynamo Carries an SSRF Flaw That Enables Attackers to Probe Internal Services via the Dynamo Server's Request Mechanism | 7.5 High | Updated |
| 2026-08-07 | CVE-2026-47613 | NVIDIA Dynamo's Server-Side Request Forgery Vulnerability Allows Attackers to Redirect the AI Inference Server's HTTP Requests Toward Internal or External Targets | 7.5 High | Updated |
| 2026-08-07 | CVE-2026-47612 | NVIDIA Dynamo's Path Traversal Flaw Allows Attackers to Navigate Outside the Intended Directory and Read or Write Files in Restricted Locations | 7.5 High | Updated |
| 2026-08-07 | CVE-2026-24255 | NVIDIA Dynamo's Incomplete Input Comparison Allows Attackers to Bypass a Security Check by Supplying Input the Comparison Logic Fails to Fully Evaluate | 7.5 High | Updated |
| 2026-08-07 | CVE-2026-24254 | NVIDIA Dynamo's Authentication Bypass via an Alternate Path Allows Unauthenticated Remote Attackers to Access the AI Inference Platform Without Valid Credentials | 9.8 Critical | Updated |
| 2026-08-07 | CVE-2026-24253 | NVIDIA Dynamo's Out-of-Bounds Write Allows Remote Attackers to Corrupt Memory and Potentially Execute Arbitrary Code via a Crafted Request | 8.2 High | Updated |
| 2026-08-05 | CVE-2026-18574 | Check Point Security Management Server and Multi-Domain Management Server Authentication Bypass Lets Unauthenticated Remote Attackers Execute Arbitrary Commands via Management Service Network Access | 9.3 Critical | New |
| 2026-08-05 | CVE-2026-17566 | pgAdmin 4 Import/Export Data Tool Builds a psql \copy Command by Interpolating User-Supplied SQL into a Jinja Template Without Sufficient Escaping, Enabling Authenticated Attackers to Execute Arbitrary OS Commands | 9.9 Critical | Updated |
| 2026-08-04 | CVE-2026-13325 | CVE-2026-13325 Rejected by Red Hat Product Security After Concluding the CVE Record Is Not Needed | — | New |
| 2026-07-30 | CVE-2026-5433 | Honeywell Control Network Module Web Interface Allows Command Delimiter Injection, Potentially Enabling Remote Code Execution via the Web Management Interface | 9.1 Critical | New |
| 2026-07-30 | CVE-2026-47876 | VMware ESX VMXNET3 Virtual Network Adapter Contains an Out-of-Bounds Write Reachable by a Local VM Admin, Potentially Enabling Code Execution on the Underlying Host | 9.3 Critical | New |
| 2026-07-30 | CVE-2026-17191 | Arista EOS Orchestrator API Component Fails to Validate Input Before Building Backend Queries, Letting Authenticated Users Access Unauthorized Data and Trigger Unintended Outbound Network Connections | 9.1 Critical | New |
| 2026-07-30 | CVE-2022-4994 | Linux Kernel KVM x86 Fast IN Path Calls emulator_pio_in When __emulator_pio_in Could Be Used Directly, Causing Unnecessary Indirection in the PIO Emulation Path | — | New |
| 2026-07-28 | CVE-2026-16812 | Arista VeloCloud Orchestrator On-Prem Management Plane Executes Injected OS Commands; CISA's July 30th KEV Deadline Has Passed for Covered Entities | 10.0 Critical | KEV |
| 2026-07-27 | CVE-2026-63880 | Linux Kernel amdgpu GEM Op IOCTL Leaks a drm_exec Lock Held at the Time of a kvcalloc Failure in AMDGPU_GEM_OP_GET_MAPPING_INFO, Causing a Lock Imbalance | — | New |
| 2026-07-27 | CVE-2026-10517 | CVE-2026-10517 Retracted by Red Hat Product Security and Upstream Clair/Claircore Maintainer After Confirming the Described PSK Authentication Behavior Is Intentional and Implemented in a Separate Package | — | New |
| 2026-07-24 | CVE-2026-31405 | Linux Kernel DVB-net ULE Extension Handler Uses a Network-Controlled Index into a 255-Entry Table Without Bounds Checking, Enabling Out-of-Bounds Reads and Writes | 9.8 Critical | Updated |
| 2026-07-24 | CVE-2026-28321 | SolarWinds Serv-U Broken Access Control Allows a Domain Administrator to Read and Write Arbitrary Files, Then Escalate Privileges and Execute Code as Root | 9.1 Critical | Updated |
| 2026-07-24 | CVE-2026-28317 | SolarWinds Serv-U IDOR Vulnerability Lets a Domain Administrator Reference Objects Outside Their Authorized Scope to Escalate Privileges | 9.1 Critical | Updated |
| 2026-07-24 | CVE-2026-28316 | SolarWinds Serv-U IDOR Vulnerability Lets a Domain Account With Administrator Access Escalate to System Administrator and Execute Commands as Root | 9.1 Critical | Updated |
| 2026-07-24 | CVE-2026-28314 | SolarWinds Serv-U IDOR Vulnerability Allows Authenticated Users to Reference Objects Outside Their Authorized Scope, Leading to Account Takeover | 9.1 Critical | Updated |
| 2026-07-24 | CVE-2026-28313 | SolarWinds Serv-U IDOR Vulnerability Enables SMTP Configuration Hijacking, Allowing an Authenticated User to Take Over Arbitrary Accounts | 9.1 Critical | Updated |
| 2026-07-24 | CVE-2026-28312 | SolarWinds Serv-U Privilege Escalation Lets a Group's Access Be Elevated to System Administrator, Enabling Code Execution as Root | 9.1 Critical | Updated |
| 2026-07-24 | CVE-2026-28310 | SolarWinds Serv-U Privilege Escalation Allows a Domain Administrator to Elevate Their User Type to System Administrator | 9.1 Critical | Updated |
| 2026-07-24 | CVE-2026-28309 | SolarWinds Serv-U Broken Access Control Lets a Domain Administrator Create System Administrator Accounts Without Proper Authorization | 9.1 Critical | Updated |
| 2026-07-24 | CVE-2026-28308 | SolarWinds Serv-U IDOR Vulnerability Allows a Domain Administrator to Reference Objects Outside Authorized Scope, Leading to Remote Code Execution | 9.1 Critical | Updated |
| 2026-07-24 | CVE-2026-28307 | SolarWinds Serv-U Privilege Escalation Allows a Domain User Group to Be Elevated to Administrator Access Without Authorization | 9.1 Critical | Updated |
| 2026-07-24 | CVE-2026-28306 | SolarWinds Serv-U Privilege Escalation Allows a Domain Administrator to Elevate Their Privileges to System Administrator Level | 9.1 Critical | Updated |
| 2026-07-24 | CVE-2026-28305 | SolarWinds Serv-U IDOR Vulnerability Allows a Domain Administrator with Home Directory Access to Reference Out-of-Scope Objects, Enabling Remote Code Execution as Root | 9.1 Critical | Updated |
| 2026-07-24 | CVE-2026-28304 | SolarWinds Serv-U Remote Code Execution Vulnerability Allows Arbitrary Code to Run as Root on Affected Linux Installations | 9.1 Critical | Updated |
| 2026-07-24 | CVE-2026-28302 | SolarWinds Serv-U IDOR Vulnerability Lets Group Administrators Reference Out-of-Scope Objects to Escalate Privileges and Execute Code as Root | 9.1 Critical | Updated |
| 2026-07-24 | CVE-2026-23450 | Linux Kernel SMC-over-TCP SYN Receive Path Calls sock_hold Then Schedules a tcp_close Work Item Without Synchronizing Against Concurrent Stack Cleanup, Enabling Use-After-Free and Null Dereference | 9.8 Critical | Updated |
| 2026-07-24 | CVE-2025-58349 | Samsung Exynos L2 Layer Incorrect Handling of LTE MAC Packets Containing Many MAC Control Elements Leads to Uncontrolled Resource Consumption, Affecting Processors from Exynos 980 Through W1000 | 9.1 Critical | Updated |
| 2026-07-24 | CVE-2025-54328 | Samsung Exynos Modem SMS Processing Stack-Based Buffer Overflow, Scoring CVSS 10.0 and Affecting Processors from Exynos 980 Through Exynos 2500 and Multiple Modem Generations | 10.0 Critical | Updated |
| 2026-07-24 | CVE-2025-14816 | Mitsubishi Electric GENESIS64 and ICONICS Suite 10.97.3 and Prior Store Sensitive Information in Cleartext in the GUI, Potentially Allowing Local Attackers to Recover Credentials From Screen Captures or Memory | 9.3 Critical | New |
| 2026-07-24 | CVE-2025-14815 | Mitsubishi Electric GENESIS64 and ICONICS Suite 10.97.3 and Prior Store Sensitive Information in Cleartext in Persistent Storage, Potentially Allowing Local Attackers to Recover Credentials From Disk | 9.3 Critical | New |
| 2026-07-23 | CVE-2026-54420 | LiteSpeed's cPanel Plugin Follows Symlinks Across Security Boundaries to Escalate Privileges; CISA's June 18th KEV Remediation Window Has Closed for Covered Entities | 8.5 High | KEV |
| 2026-07-23 | CVE-2026-39834 | SSH Channel Write Path Overflows a Size Counter on Payloads Larger Than 4GB, Causing the Write Loop to Spin Indefinitely Sending Empty Packets Without Making Progress | 9.1 Critical | Updated |
| 2026-07-23 | CVE-2026-10523 | Ivanti Sentry Before R10.5.2 / R10.6.2 / R10.7.1 Authentication Bypass Lets Unauthenticated Remote Attackers Create Arbitrary Administrative Accounts and Obtain Full Administrative Access | 9.9 Critical | Updated |
| 2026-07-23 | CVE-2025-71211 | Trend Micro Apex One Management Console Path Traversal in a Second Executable Allows Remote Attackers to Upload Malicious Code and Execute Commands on Affected Installations | 9.8 Critical | Updated |
| 2026-07-23 | CVE-2025-71210 | Trend Micro Apex One Management Console Path Traversal Allows Remote Attackers to Upload Malicious Code and Execute Commands on Affected Installations | 9.8 Critical | Updated |
| 2026-07-22 | CVE-2025-48595 | Android Framework's Integer Overflow Enables Code Execution and Local Privilege Escalation; CISA's June 5th KEV Deadline Has Passed | 8.4 High | KEV |
| 2026-07-22 | CVE-2024-27892 | Arista EOS with OpenConfig Configured Fails to Reject Certain gNMI Set Requests That Should Not Execute, Potentially Allowing Unauthorized Configuration Changes on Affected Switches | 9.6 Critical | New |
| 2026-07-22 | CVE-2024-27890 | Arista EOS with OpenConfig Configured Fails to Reject a Second Class of gNMI Set Requests That Should Not Execute, Potentially Allowing Unauthorized Configuration Changes on Affected Switches | 9.6 Critical | New |
| 2026-07-21 | CVE-2026-9508 | Suprema BioStar 2 Exposes Backup ZIP Files Without Authentication When Administrator Places the Backup Path Inside the NGINX Webroot, Allowing Database Download and Server Impersonation | 10.0 Critical | New |
| 2026-07-16 | CVE-2023-4346 | KNX Protocol Connection Authorization Option 1's Overly Restrictive Lockout Mechanism Lets Attackers Purge Devices and Lock Out Authorized Users with a BCU Key; CISA's July 29th KEV Deadline Has Passed | 7.5 High | KEV |
| 2026-07-15 | CVE-2026-56155 | Microsoft Active Directory Federation Services Insufficient Access Control Allows an Authorized Attacker to Elevate Privileges Locally; CISA's July 28th KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-07-13 | CVE-2026-4769 | WAGO System I/O Field Series Activates an Undocumented Diagnostic Interface Without Authentication During Early Boot, Granting Unauthenticated Network Access for a Brief Window at Each Power Cycle | 9.8 Critical | New |
| 2026-07-07 | CVE-2026-0234 | Cortex XSOAR and XSIAM Microsoft Teams Integration Fails to Verify Cryptographic Signatures, Letting Unauthenticated Users Access and Modify Protected Resources | 9.1 Critical | Updated |
| 2026-07-03 | CVE-2026-50238 | CVE-2026-50238 Rejected by Red Hat Product Security as Not Required; Underlying Issue Reclassified as a Regular Bug to Be Fixed Through Standard Bug-Fixing Process | — | New |
| 2026-07-02 | CVE-2026-53225 | Linux Kernel SCTP ASCONF Lookup Reads Past the Validated Header Boundary, Exposing Uninitialized Memory to Downstream Address Parameter Processing | 9.1 Critical | Updated |
| 2026-06-30 | CVE-2026-14162 | Advantech Hospital Queuing Management System Exposes API Documentation to Unauthenticated Remote Attackers via a Specific URL, Facilitating Unauthorized Access to Internal API Details | 9.8 Critical | New |
| 2026-06-30 | CVE-2026-12819 | Delta Electronics DVP12SE PLC Modbus TCP Service Runs Without Authentication or Access Control, Granting Unauthenticated Network Access to Security-Sensitive PLC Functions | 9.3 Critical | New |
| 2026-06-30 | CVE-2026-12818 | Delta Electronics DVP12SE PLC Modbus TCP Service Has No Resource Allocation Limits, Making the PLC Susceptible to Denial-of-Service via Request Flooding | 9.3 Critical | New |
| 2026-06-26 | CVE-2026-46893 | Oracle JD Edwards EnterpriseOne General Ledger E1 Foundation Component Allows Low-Privileged SMB Attackers to Compromise the Application, With Attacks Potentially Spreading to Additional Oracle Products | 9.9 Critical | Updated |
| 2026-06-26 | CVE-2026-46892 | Oracle JD Edwards EnterpriseOne Human Resources Management Component Allows Unauthenticated HTTP Attackers to Read and Modify Data, Affecting Confidentiality and Integrity | 9.1 Critical | Updated |
| 2026-06-22 | CVE-2026-45177 | Idira Secrets Manager SaaS Edge Before 1.8 Improper Access Control in Internal Authentication Components Lets Unauthenticated Remote Attackers Access Protected Resources Under Specific Conditions | 9.1 Critical | Updated |
| 2026-06-22 | CVE-2026-39962 | MISP Before 2.5.36 ApacheAuthenticate Module Passes Unsanitized Username Values Into an LDAP Query, Enabling LDAP Injection by Unauthenticated Users When ApacheAuthenticate Is Enabled | 9.6 Critical | Updated |
| 2026-06-22 | CVE-2026-20266 | Splunk AI Toolkit Below 5.7.4 Constructs OS Command Strings from Dynamic btool Configuration Parameters Without Sanitization, Letting Admin-Role Users Execute Arbitrary OS Commands on the Host | 9.1 Critical | Updated |
| 2026-06-18 | CVE-2026-46913 | Oracle JD Edwards EnterpriseOne Tools Installation Security Component Allows Unauthenticated Local Attackers to Compromise the Application, With Attacks Potentially Impacting Additional Oracle Products | 9.3 Critical | Updated |
| 2026-06-18 | CVE-2026-46911 | Oracle JD Edwards EnterpriseOne Project Costing Job Costing Component Allows Low-Privileged JDENET Attackers to Compromise the Application, With Attacks Potentially Impacting Additional Oracle Products | 9.6 Critical | Updated |
| 2026-06-18 | CVE-2026-46909 | Oracle JD Edwards EnterpriseOne Tools Enterprise Infrastructure Security Allows Unauthenticated HTTP Attackers Full Takeover of the EnterpriseOne Tools Instance, Scoring CVSS 9.8 | 9.8 Critical | Updated |
| 2026-06-18 | CVE-2026-46908 | Oracle JD Edwards EnterpriseOne Accounts Payable Component Allows Low-Privileged HTTP Attackers to Compromise the Application, With Attacks Potentially Impacting Additional Oracle Products | 9.9 Critical | Updated |
| 2026-06-18 | CVE-2026-46907 | Oracle JD Edwards EnterpriseOne Order Promising Integration Component Allows Low-Privileged HTTP Attackers to Compromise the Application, With Attacks Potentially Spreading to Additional Oracle Products | 9.9 Critical | Updated |
| 2026-06-18 | CVE-2026-46906 | Oracle JD Edwards EnterpriseOne Tools Enterprise Infrastructure Security Allows Low-Privileged HTTP Attackers to Compromise the Application, With Attacks Potentially Impacting Additional Oracle Products | 9.6 Critical | Updated |
| 2026-06-18 | CVE-2026-46905 | Oracle JD Edwards EnterpriseOne Tools Web Runtime Security Component Allows Unauthenticated HTTP Attackers Full Takeover of the EnterpriseOne Tools Instance, Scoring CVSS 9.8 | 9.8 Critical | Updated |
| 2026-06-18 | CVE-2026-46904 | Oracle JD Edwards EnterpriseOne Tools Enterprise Infrastructure Security Allows Unauthenticated JDENET Attackers Full Takeover of the EnterpriseOne Tools Instance, Scoring CVSS 9.8 | 9.8 Critical | Updated |
| 2026-06-18 | CVE-2026-46883 | Oracle JD Edwards EnterpriseOne Tools Enterprise Infrastructure Security Allows Unauthenticated JDENET Attackers Full Takeover of the Tools Instance in Versions 9.2.0.0 Through 9.2.26.2, One of Six Related CVEs | 9.8 Critical | Updated |
| 2026-06-18 | CVE-2026-46882 | Oracle JD Edwards EnterpriseOne Tools Enterprise Infrastructure Security Allows Unauthenticated JDENET Attackers Full Takeover of the Tools Instance in Versions 9.2.0.0 Through 9.2.26.2, One of Six Related CVEs | 9.8 Critical | Updated |
| 2026-06-18 | CVE-2026-46881 | Oracle JD Edwards EnterpriseOne Tools Enterprise Infrastructure Security Allows Unauthenticated JDENET Attackers Full Takeover of the Tools Instance, Third in a Set of Six JDENET-Reachable Takeover Vulnerabilities | 9.8 Critical | Updated |
| 2026-06-18 | CVE-2026-46880 | Oracle JD Edwards EnterpriseOne Tools Enterprise Infrastructure Security Allows Unauthenticated JDENET Attackers Full Takeover of the Tools Instance, Fourth in a Set of Six JDENET-Reachable Takeover Vulnerabilities | 9.8 Critical | Updated |
| 2026-06-18 | CVE-2026-46879 | Oracle JD Edwards EnterpriseOne Tools Enterprise Infrastructure Security Allows Unauthenticated JDENET Attackers Full Takeover of the Tools Instance, Fifth in a Set of Six JDENET-Reachable Takeover Vulnerabilities | 9.8 Critical | Updated |
| 2026-06-18 | CVE-2026-46878 | Oracle JD Edwards EnterpriseOne Tools Enterprise Infrastructure Security Allows Unauthenticated JDENET Attackers Full Takeover of the Tools Instance, Sixth in a Set of Six JDENET-Reachable Takeover Vulnerabilities | 9.8 Critical | Updated |
| 2026-06-17 | CVE-2026-8398 | Daemon Tools Lite Contains Embedded Malicious Code; CISA Added It to KEV with a May 30th Deadline That Has Since Passed for Covered Entities | 9.8 Critical | KEV |
| 2026-06-17 | CVE-2026-8043 | Ivanti Xtraction Before 2026.2 Lets Authenticated Remote Attackers Supply Arbitrary File Paths to Read Sensitive Files or Write HTML Files into a Web-Accessible Directory | 9.6 Critical | Updated |
| 2026-06-17 | CVE-2026-7473 | Arista Extensible Operating System Validation Bypass Added to CISA's Known Exploited Vulnerabilities List; Federal Remediation Window for Covered Entities Closed June 23rd | 5.8 Medium | KEV |
| 2026-06-17 | CVE-2026-48027 | Nx Console Developer Tooling Published Packages Contain Embedded Malicious Code; CISA's June 10th KEV Mandate for Covered Entities Has Passed | 9.8 Critical | KEV |
| 2026-06-17 | CVE-2026-46912 | Oracle JD Edwards EnterpriseOne Tools Web Runtime Security Component Allows Unauthenticated HTTP Attackers to Compromise the Application, With High Impact on Confidentiality, Integrity, and Availability | 9.3 Critical | Updated |
| 2026-06-17 | CVE-2026-46910 | Oracle JD Edwards EnterpriseOne Tools Enterprise Infrastructure Security Allows Unauthenticated HTTP Attackers to Read and Write Data in a Way That Affects Confidentiality and Integrity | 9.1 Critical | Updated |
| 2026-06-17 | CVE-2026-45321 | TanStack JavaScript Library Suite Added to CISA's Known Exploited Vulnerabilities Catalog; Federal Remediation Deadline for Covered Entities Was June 10th | 9.6 Critical | KEV |
| 2026-06-17 | CVE-2026-41512 | ai-scanner 1.0.0 Through 1.4.0 Remote Code Execution via JavaScript Injection in BrowserAutomation PlaywrightService, Reachable Without Authentication | 9.9 Critical | Updated |
| 2026-06-17 | CVE-2026-35573 | ChurchCRM Before 6.5.3 Backup Restore Functionality Allows Authenticated Administrators to Upload Files to Arbitrary Paths via Path Traversal, Enabling Remote Code Execution | 9.1 Critical | Updated |
| 2026-06-17 | CVE-2026-20794 | Intel Data Center Graphics Driver for VMware ESXi Before 2.0.2 Ring 1 Device Driver Buffer Overflow Allows a Privileged System Software Adversary to Escalate Privileges and Execute Code Locally | 9.3 Critical | New |
| 2026-06-17 | CVE-2026-20184 | Cisco Webex SSO Integration with Control Hub Performed Improper Certificate Validation, Allowing Unauthenticated Attackers to Impersonate Any User Within the Service Prior to Patching | 9.8 Critical | New |
| 2026-06-17 | CVE-2026-20093 | Cisco Integrated Management Controller Change Password Handler Incorrectly Processes Password Change Requests, Letting Unauthenticated Remote Attackers Bypass Authentication and Gain Admin Access | 9.8 Critical | New |
| 2026-06-17 | CVE-2026-1952 | Delta Electronics AS320T Denial of Service via Undocumented Subfunction Call, Exploitable Remotely Without Authentication | 9.8 Critical | Updated |
| 2026-06-17 | CVE-2026-1951 | Delta Electronics AS320T Stack-Based Buffer Overflow Due to Missing Directory Name Length Check, Enabling Unauthenticated Remote Code Execution | 9.8 Critical | Updated |
| 2026-06-17 | CVE-2026-1950 | Delta Electronics AS320T Stack-Based Buffer Overflow Due to Missing File Name Length Check, Enabling Unauthenticated Remote Code Execution | 9.8 Critical | Updated |
| 2026-06-17 | CVE-2026-1949 | Delta Electronics AS320T GET/PUT Request Handler Incorrectly Calculates Stack Buffer Size, Enabling Unauthenticated Remote Code Execution via the Web Service | 9.8 Critical | Updated |
| 2026-06-17 | CVE-2025-62818 | Samsung Exynos Modem SMS Processing Out-of-Bounds Write Due to TP-UDHI Header Mismatch, Affecting Processors from Exynos 980 Through Exynos 2500 and Multiple Modem Generations | 9.8 Critical | Updated |
| 2026-06-17 | CVE-2025-52909 | Samsung Exynos Wi-Fi Driver NL80211 Vendor Command Handler Overflows a Buffer via a Crafted Packet, Affecting Exynos 980 Through W1000 Mobile and Wearable Processors | 9.8 Critical | Updated |
| 2026-06-17 | CVE-2025-52908 | Samsung Exynos Wi-Fi Driver NL80211 Vendor Command Handler Contains a Second Buffer Overflow Path via a Crafted Packet, Affecting Exynos 980 Through W1000 Mobile and Wearable Processors | 9.8 Critical | Updated |
| 2026-06-17 | CVE-2025-32975 | Quest KACE Systems Management Appliance's Improper Authentication Allows Attackers to Impersonate Legitimate Users Without Valid Credentials; CISA's May 4th KEV Deadline Has Passed | 10.0 Critical | KEV |