| 2026-10-03 | CVE-2026-86060 | MikroTik RouterOS's Argument Injection in a Command-Processing Component Allows Unauthenticated Attackers to Execute Arbitrary Commands on the Router; CISA's September 13th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-10-03 | CVE-2026-85102 | Check Point Firewall Certificate Validation Bypass Across Site-to-Site and Remote Access VPN Carries a Lapsed September 25th CISA KEV Requirement for Covered Entities | 9.8 Critical | KEV |
| 2026-10-03 | CVE-2026-82078 | PaperCut NG/MF's Unsafe Reflection Allows Remote Attackers to Manipulate Class Loading and Execute Arbitrary Code on the Print Management Server; CISA's September 14th KEV Deadline Has Passed | 9.1 Critical | KEV |
| 2026-10-03 | CVE-2026-67276 | CVE-2026-67276 | 8.1 High | EPSS-Imminent |
| 2026-10-03 | CVE-2026-20181 | CVE-2026-20181 | 9.1 Critical | EPSS-Imminent |
| 2026-10-03 | CVE-2026-98154 | CVE-2026-98154 | 7.0 High | Updated |
| 2026-10-03 | CVE-2026-98130 | CVE-2026-98130 | 8.1 High | Updated |
| 2026-10-03 | CVE-2026-98122 | CVE-2026-98122 | 7.8 High | Updated |
| 2026-10-03 | CVE-2026-98116 | CVE-2026-98116 | 7.8 High | Updated |
| 2026-10-03 | CVE-2026-98108 | CVE-2026-98108 | 7.5 High | Updated |
| 2026-10-03 | CVE-2026-98096 | CVE-2026-98096 | 7.4 High | Updated |
| 2026-10-03 | CVE-2026-98083 | CVE-2026-98083 | 7.0 High | Updated |
| 2026-10-03 | CVE-2026-98070 | CVE-2026-98070 | 8.1 High | Updated |
| 2026-10-03 | CVE-2026-98069 | CVE-2026-98069 | 8.1 High | Updated |
| 2026-10-03 | CVE-2026-98052 | CVE-2026-98052 | 7.8 High | Updated |
| 2026-10-03 | CVE-2026-98030 | CVE-2026-98030 | 7.0 High | Updated |
| 2026-10-03 | CVE-2026-98027 | CVE-2026-98027 | 7.0 High | Updated |
| 2026-10-03 | CVE-2026-98023 | CVE-2026-98023 | 7.8 High | Updated |
| 2026-10-03 | CVE-2026-98017 | CVE-2026-98017 | 7.8 High | Updated |
| 2026-10-03 | CVE-2026-97991 | CVE-2026-97991 | 7.8 High | Updated |
| 2026-10-03 | CVE-2026-97990 | CVE-2026-97990 | 7.5 High | Updated |
| 2026-10-03 | CVE-2026-97957 | CVE-2026-97957 | 8.8 High | Updated |
| 2026-10-03 | CVE-2026-97509 | CVE-2026-97509 | 8.8 High | Updated |
| 2026-10-03 | CVE-2026-97508 | CVE-2026-97508 | 7.5 High | Updated |
| 2026-10-03 | CVE-2026-97497 | CVE-2026-97497 | 7.8 High | Updated |
| 2026-10-03 | CVE-2026-97496 | CVE-2026-97496 | 7.1 High | Updated |
| 2026-10-03 | CVE-2026-97455 | CVE-2026-97455 | 8.4 High | Updated |
| 2026-10-03 | CVE-2026-97454 | CVE-2026-97454 | 7.7 High | Updated |
| 2026-10-03 | CVE-2026-97452 | CVE-2026-97452 | 8.4 High | Updated |
| 2026-10-03 | CVE-2026-97451 | CVE-2026-97451 | 8.4 High | Updated |
| 2026-10-03 | CVE-2026-97450 | CVE-2026-97450 | 8.4 High | Updated |
| 2026-10-03 | CVE-2026-97448 | CVE-2026-97448 | 7.7 High | Updated |
| 2026-10-03 | CVE-2026-93196 | CVE-2026-93196 | 8.4 High | Updated |
| 2026-10-03 | CVE-2026-90030 | CVE-2026-90030 | 7.8 High | Updated |
| 2026-10-03 | CVE-2026-90016 | CVE-2026-90016 | 7.1 High | Updated |
| 2026-10-03 | CVE-2026-90013 | CVE-2026-90013 | 7.8 High | Updated |
| 2026-10-03 | CVE-2026-90002 | CVE-2026-90002 | 7.8 High | Updated |
| 2026-10-03 | CVE-2026-89972 | CVE-2026-89972 | 9.8 Critical | Updated |
| 2026-10-03 | CVE-2026-89971 | CVE-2026-89971 | 7.5 High | Updated |
| 2026-10-03 | CVE-2026-89840 | CVE-2026-89840 | 7.1 High | Updated |
| 2026-10-03 | CVE-2026-89838 | CVE-2026-89838 | 7.1 High | Updated |
| 2026-10-03 | CVE-2026-89832 | CVE-2026-89832 | 7.8 High | Updated |
| 2026-10-03 | CVE-2026-89806 | CVE-2026-89806 | 8.4 High | Updated |
| 2026-10-03 | CVE-2026-89795 | CVE-2026-89795 | 8.4 High | Updated |
| 2026-10-03 | CVE-2026-89792 | CVE-2026-89792 | 7.1 High | Updated |
| 2026-10-03 | CVE-2026-89560 | CVE-2026-89560 | 8.4 High | Updated |
| 2026-10-03 | CVE-2026-89520 | CVE-2026-89520 | 7.8 High | Updated |
| 2026-10-03 | CVE-2026-89503 | CVE-2026-89503 | 7.8 High | Updated |
| 2026-10-03 | CVE-2026-89500 | CVE-2026-89500 | 7.8 High | Updated |
| 2026-10-03 | CVE-2026-89452 | CVE-2026-89452 | 8.4 High | Updated |
| 2026-10-03 | CVE-2026-89445 | CVE-2026-89445 | 8.8 High | Updated |
| 2026-10-03 | CVE-2026-89441 | CVE-2026-89441 | 7.8 High | Updated |
| 2026-10-03 | CVE-2026-81016 | CVE-2026-81016 | 7.7 High | Updated |
| 2026-10-03 | CVE-2026-81015 | CVE-2026-81015 | 7.8 High | Updated |
| 2026-10-03 | CVE-2026-80980 | CVE-2026-80980 | 9.8 Critical | Updated |
| 2026-10-03 | CVE-2026-80937 | CVE-2026-80937 | 8.8 High | Updated |
| 2026-10-03 | CVE-2026-80935 | CVE-2026-80935 | 8.8 High | Updated |
| 2026-10-03 | CVE-2026-80926 | CVE-2026-80926 | 9.8 Critical | Updated |
| 2026-10-03 | CVE-2026-80726 | CVE-2026-80726 | 9.3 Critical | Updated |
| 2026-10-03 | CVE-2026-80521 | CVE-2026-80521 | 7.8 High | Updated |
| 2026-10-03 | CVE-2026-76504 | CVE-2026-76504: Cisco Catalyst SD-WAN Manager | 9.8 Critical | KEV |
| 2026-10-03 | CVE-2026-74743 | CVE-2026-74743 | 9.8 Critical | Updated |
| 2026-10-03 | CVE-2026-74521 | CVE-2026-74521 | 9.1 Critical | Updated |
| 2026-10-03 | CVE-2026-74496 | CVE-2026-74496 | 7.8 High | Updated |
| 2026-10-03 | CVE-2026-74347 | CVE-2026-74347 | 7.8 High | Updated |
| 2026-10-03 | CVE-2026-74294 | CVE-2026-74294 | 7.3 High | Updated |
| 2026-10-03 | CVE-2026-74289 | CVE-2026-74289 | 7.8 High | Updated |
| 2026-10-03 | CVE-2026-74258 | CVE-2026-74258 | 7.8 High | Updated |
| 2026-10-03 | CVE-2026-72496 | CVE-2026-72496 | 9.2 Critical | Updated |
| 2026-10-03 | CVE-2026-72485 | CVE-2026-72485 | 7.8 High | Updated |
| 2026-10-03 | CVE-2026-72334 | CVE-2026-72334 | 8.8 High | Updated |
| 2026-10-03 | CVE-2026-68391 | CVE-2026-68391 | 7.8 High | Updated |
| 2026-10-03 | CVE-2026-68287 | CVE-2026-68287 | 7.5 High | Updated |
| 2026-10-03 | CVE-2026-68236 | CVE-2026-68236 | 7.8 High | Updated |
| 2026-10-03 | CVE-2026-68161 | CVE-2026-68161 | 9.8 Critical | Updated |
| 2026-10-03 | CVE-2026-68155 | CVE-2026-68155 | 7.5 High | Updated |
| 2026-10-03 | CVE-2026-68097 | CVE-2026-68097 | 8.8 High | Updated |
| 2026-10-03 | CVE-2026-53359 | CVE-2026-53359 | 8.8 High | Updated |
| 2026-10-03 | CVE-2026-53005 | Linux Kernel AF_UNIX SOCKMAP Redirect Hides Inflight File Descriptors from the Garbage Collector, Leaking Inflight Sockets Indefinitely | 7.8 High | Updated |
| 2026-10-03 | CVE-2026-52988 | CVE-2026-52988 | 7.1 High | Updated |
| 2026-10-03 | CVE-2026-46242 | CVE-2026-46242 | 7.8 High | Updated |
| 2026-10-03 | CVE-2026-46113 | CVE-2026-46113 | 8.8 High | Updated |
| 2026-10-03 | CVE-2026-20273 | Cisco IOS XE's Improper Input Validation Allows a Remote Attacker to Trigger a Device Crash or Disruption via a Specially Crafted Input | 8.6 High | Updated |
| 2026-10-03 | CVE-2026-20272 | Cisco IOS XE's Injection Flaw Allows Remote Attackers to Execute Arbitrary Commands via a Specially Crafted Input Reaching a Downstream Component | 9.8 Critical | Updated |
| 2026-10-03 | CVE-2026-20271 | Cisco IOS XE's Insufficient Control Flow Management Allows a Remote Attacker to Disrupt Device Operation via a Crafted Packet | 8.6 High | Updated |
| 2026-10-03 | CVE-2026-20270 | Cisco IOS XE's Incorrect Calculation Vulnerability Allows a Remote Attacker to Cause an Unrecoverable Device Condition via a Specially Crafted Input | 8.6 High | Updated |
| 2026-10-03 | CVE-2026-20269 | Cisco IOS XE's Improper Resource Lifetime Management Allows Remote Attackers to Exhaust Device Resources and Cause a Denial of Service | 8.6 High | Updated |
| 2026-10-03 | CVE-2026-20268 | Cisco IOS XE's Improper Restriction of Memory Buffer Operations Allows Remote Attackers to Potentially Execute Code or Crash the Device via a Malformed Packet | 8.6 High | Updated |
| 2026-10-03 | CVE-2026-20267 | Cisco IOS XE's Improper Access Control Allows Network-Based Attackers to Access Protected Functions or Data Without Proper Authorization | 9.0 Critical | Updated |
| 2026-10-02 | CVE-2026-98163 | CVE-2026-98163 | 7.0 High | Updated |
| 2026-10-02 | CVE-2026-98115 | CVE-2026-98115 | 8.8 High | Updated |
| 2026-10-02 | CVE-2026-97415 | CVE-2026-97415 | 7.8 High | Updated |
| 2026-10-02 | CVE-2026-86326 | CVE-2026-86326 | 8.6 High | Updated |
| 2026-10-02 | CVE-2026-86325 | CVE-2026-86325 | 9.4 Critical | Updated |
| 2026-10-02 | CVE-2026-84411 | CVE-2026-84411 | 9.8 Critical | Updated |
| 2026-10-02 | CVE-2026-75937 | CVE-2026-75937 | 9.4 Critical | Updated |
| 2026-10-02 | CVE-2026-71452 | CVE-2026-71452 | 7.2 High | Updated |
| 2026-10-02 | CVE-2026-71449 | CVE-2026-71449 | 9.3 Critical | Updated |
| 2026-10-02 | CVE-2026-64893 | CVE-2026-64893 | 7.3 High | Updated |
| 2026-10-02 | CVE-2026-64008 | CVE-2026-64008 | 7.8 High | Updated |
| 2026-10-02 | CVE-2026-64001 | CVE-2026-64001 | 7.8 High | Updated |
| 2026-10-02 | CVE-2026-63996 | CVE-2026-63996 | 7.8 High | Updated |
| 2026-10-02 | CVE-2026-63993 | CVE-2026-63993 | 9.8 Critical | Updated |
| 2026-10-02 | CVE-2026-63975 | CVE-2026-63975 | 8.8 High | Updated |
| 2026-10-02 | CVE-2026-63972 | CVE-2026-63972 | 7.5 High | Updated |
| 2026-10-02 | CVE-2026-63971 | CVE-2026-63971 | 7.8 High | Updated |
| 2026-10-02 | CVE-2026-63970 | CVE-2026-63970 | 7.8 High | Updated |
| 2026-10-02 | CVE-2026-58016 | CVE-2026-58016 | 7.5 High | Updated |
| 2026-10-02 | CVE-2026-58014 | CVE-2026-58014 | 7.3 High | Updated |
| 2026-10-02 | CVE-2026-55396 | CVE-2026-55396 | 8.5 High | Updated |
| 2026-10-02 | CVE-2026-55395 | CVE-2026-55395 | 9.4 Critical | Updated |
| 2026-10-02 | CVE-2026-55393 | CVE-2026-55393 | 10.0 Critical | Updated |
| 2026-10-02 | CVE-2026-48864 | CVE-2026-48864 | 7.8 High | Updated |
| 2026-10-02 | CVE-2026-42010 | CVE-2026-42010 | 7.1 High | Updated |
| 2026-10-02 | CVE-2026-42009 | CVE-2026-42009 | 7.5 High | Updated |
| 2026-10-02 | CVE-2026-34494 | CVE-2026-34494 | 7.2 High | Updated |
| 2026-10-02 | CVE-2026-34493 | CVE-2026-34493 | 7.2 High | Updated |
| 2026-10-02 | CVE-2026-33845 | CVE-2026-33845 | 7.5 High | Updated |
| 2026-10-02 | CVE-2026-17523 | CVE-2026-17523 | 7.8 High | Updated |
| 2026-10-02 | CVE-2026-14984 | CVE-2026-14984 | 9.4 Critical | Updated |
| 2026-10-02 | CVE-2026-14983 | CVE-2026-14983 | 7.1 High | Updated |
| 2026-10-02 | CVE-2026-104286 | CVE-2026-104286: Fortinet FortiMail Path | 9.8 Critical | KEV |
| 2026-10-02 | CVE-2026-102490 | CVE-2026-102490: Zammad GmbH Zammad Improper | 9.8 Critical | KEV |
| 2026-10-02 | CVE-2026-102489 | CVE-2026-102489: Zammad GmbH Zammad Session | 9.8 Critical | KEV |
| 2026-10-02 | CVE-2026-100075 | CVE-2026-100075 | 9.8 Critical | Updated |
| 2026-10-01 | CVE-2026-8037 | Progress LoadMaster's Command Injection Flaw Allows Unauthenticated Remote Attackers to Execute Arbitrary OS Commands on the Load Balancer Appliance; CISA's August 10th KEV Deadline Has Passed | 9.6 Critical | KEV |
| 2026-10-01 | CVE-2026-69594 | CVE-2026-69594 | 7.8 High | Updated |
| 2026-10-01 | CVE-2026-69576 | CVE-2026-69576 | 7.8 High | Updated |
| 2026-10-01 | CVE-2026-69549 | CVE-2026-69549 | 7.0 High | Updated |
| 2026-10-01 | CVE-2026-69546 | CVE-2026-69546 | 8.1 High | Updated |
| 2026-10-01 | CVE-2026-69541 | CVE-2026-69541 | 7.8 High | Updated |
| 2026-10-01 | CVE-2026-69524 | CVE-2026-69524 | 8.1 High | Updated |
| 2026-10-01 | CVE-2026-48710 | Kludex Starlette's HTTP Request Smuggling Vulnerability Allows Network-Adjacent Attackers to Bypass Security Controls and Poison Shared HTTP Connections | 6.5 Medium | KEV |
| 2026-10-01 | CVE-2026-42965 | CVE-2026-42965 | 7.7 High | Updated |
| 2026-10-01 | CVE-2026-3012 | CVE-2026-3012 | 8.0 High | Updated |
| 2026-10-01 | CVE-2026-1784 | CVE-2026-1784 | 8.8 High | Updated |
| 2026-10-01 | CVE-2025-41753 | CVE-2025-41753 | 9.8 Critical | Updated |
| 2026-09-30 | CVE-2026-41940 | WebPros cPanel and WHM's Login Flow Authentication Bypass Gives Unauthenticated Attackers Unauthorized Access to the Control Panel; CISA's May 3rd KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-28 | CVE-2026-20263 | Cisco IOS XE BEEP SOAP request parsing flaw causes unexpected device reload | 8.6 High | Updated |
| 2026-09-26 | CVE-2026-80152 | Lantronix SLC8000, SLC9000, EMG, and SLB Series Set Script Schedule Command Passes Unsanitized Input to system(), Enabling Authenticated Users with Services Permission to Run Arbitrary Commands as Root | 9.1 Critical | Updated |
| 2026-09-26 | CVE-2026-80151 | Lantronix SLC8000, SLC9000, EMG, and SLB Series Set NFS Download Command Passes Unsanitized Input to system(), Enabling Authenticated Users with Services Permission to Run Arbitrary Commands as Root | 9.1 Critical | Updated |
| 2026-09-26 | CVE-2026-80150 | Lantronix Serial Console Servers Allow Unauthenticated Attackers to Redirect WebTelnet Connections to Arbitrary Hosts via a Tampered rooturl Parameter | 7.5 High | Updated |
| 2026-09-26 | CVE-2026-80149 | Lantronix Serial Console Servers Allow Unauthenticated Attackers to Redirect WebSSH Connections to Arbitrary Hosts via a Tampered rooturl Parameter | 8.6 High | Updated |
| 2026-09-26 | CVE-2026-80148 | Overlong Username in Lantronix Serial Console Server WebSSH Truncates the Device IP Suffix in snprintf, Redirecting SSH Connections to Attacker-Controlled Hosts | 8.6 High | Updated |
| 2026-09-26 | CVE-2026-80146 | Lantronix SLC8000/SLC9000 and EMG Series Undocumented mfc eeprom read Command Copies Unbounded Input into a Stack Buffer Before system(), Enabling Authenticated Attackers to Execute Arbitrary Code as Root | 9.9 Critical | Updated |
| 2026-09-26 | CVE-2026-67279 | MikroTik RouterOS Unauthenticated Session Bypass Carries Federal Remediation Deadline of September 28 | 6.5 Medium | KEV |
| 2026-09-25 | CVE-2026-93616 | Path Traversal Across Check Point Management and Log Server Infrastructure Missed the September 25th CISA KEV Window; Covered Organizations Are Now Out of Compliance | 9.8 Critical | KEV |
| 2026-09-25 | CVE-2026-85046 | Google Chromium V8's Type Confusion Allows Remote Attackers to Execute Arbitrary Code or Escape the Browser Sandbox via a Crafted Web Page | 8.8 High | KEV |
| 2026-09-25 | CVE-2026-81578 | PaperCut NG/MF's Missing Authentication on a Critical Function Allows Unauthenticated Attackers to Perform Administrative Actions Without Logging In; CISA's September 14th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-25 | CVE-2026-76461 | Cisco Secure Email Gateway's SQL Injection Flaw Allows Unauthenticated Attackers to Execute Arbitrary Database Queries and Compromise the Email Security Platform | 9.8 Critical | KEV |
| 2026-09-25 | CVE-2026-76460 | Cisco Identity Services Engine's Incorrect Use of Privileged APIs Allows Unauthenticated Remote Attackers to Gain Full Administrative Control; CISA's September 19th KEV Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-25 | CVE-2026-75650 | Adobe Commerce and Magento's Template Engine Injection Flaw Allows Unauthenticated Remote Attackers to Execute Arbitrary Server-Side Code on the E-Commerce Platform | 10.0 Critical | KEV |
| 2026-09-25 | CVE-2026-97941 | CVE-2026-97941 | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-97940 | CVE-2026-97940 | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-97937 | CVE-2026-97937 | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-97931 | CVE-2026-97931 | 7.0 High | Updated |
| 2026-09-25 | CVE-2026-97926 | CVE-2026-97926 | 7.0 High | Updated |
| 2026-09-25 | CVE-2026-97911 | CVE-2026-97911 | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-97910 | CVE-2026-97910 | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-97903 | CVE-2026-97903 | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-97612 | CVE-2026-97612 | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-97611 | CVE-2026-97611 | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-97609 | CVE-2026-97609 | 7.0 High | Updated |
| 2026-09-25 | CVE-2026-97608 | CVE-2026-97608 | 7.0 High | Updated |
| 2026-09-25 | CVE-2026-97602 | CVE-2026-97602 | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-97595 | CVE-2026-97595 | 7.5 High | Updated |
| 2026-09-25 | CVE-2026-97594 | CVE-2026-97594 | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-97589 | CVE-2026-97589 | 7.0 High | Updated |
| 2026-09-25 | CVE-2026-97584 | CVE-2026-97584 | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-97583 | CVE-2026-97583 | 7.5 High | Updated |
| 2026-09-25 | CVE-2026-97580 | CVE-2026-97580 | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-97579 | CVE-2026-97579 | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-97578 | CVE-2026-97578 | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-97577 | CVE-2026-97577 | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-97576 | CVE-2026-97576 | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-97575 | CVE-2026-97575 | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-97573 | CVE-2026-97573 | 8.1 High | Updated |
| 2026-09-25 | CVE-2026-97570 | CVE-2026-97570 | 8.1 High | Updated |
| 2026-09-25 | CVE-2026-97562 | CVE-2026-97562 | 7.5 High | Updated |
| 2026-09-25 | CVE-2026-97557 | CVE-2026-97557 | 7.5 High | Updated |
| 2026-09-25 | CVE-2026-97555 | CVE-2026-97555 | 8.8 High | Updated |
| 2026-09-25 | CVE-2026-97548 | CVE-2026-97548 | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-97536 | CVE-2026-97536 | 7.5 High | Updated |
| 2026-09-25 | CVE-2026-97531 | CVE-2026-97531 | 7.5 High | Updated |
| 2026-09-25 | CVE-2026-97528 | CVE-2026-97528 | 8.8 High | Updated |
| 2026-09-25 | CVE-2026-97527 | CVE-2026-97527 | 8.8 High | Updated |
| 2026-09-25 | CVE-2026-97525 | CVE-2026-97525 | 8.2 High | Updated |
| 2026-09-25 | CVE-2026-97524 | CVE-2026-97524 | 7.5 High | Updated |
| 2026-09-25 | CVE-2026-97523 | CVE-2026-97523 | 7.5 High | Updated |
| 2026-09-25 | CVE-2026-97445 | CVE-2026-97445 | 7.7 High | Updated |
| 2026-09-25 | CVE-2026-97444 | CVE-2026-97444 | 7.7 High | Updated |
| 2026-09-25 | CVE-2026-97442 | CVE-2026-97442 | 8.8 High | Updated |
| 2026-09-25 | CVE-2026-97438 | CVE-2026-97438 | 7.1 High | Updated |
| 2026-09-25 | CVE-2026-97437 | CVE-2026-97437 | 7.1 High | Updated |
| 2026-09-25 | CVE-2026-97433 | CVE-2026-97433 | 8.2 High | Updated |
| 2026-09-25 | CVE-2026-97429 | CVE-2026-97429 | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-97428 | CVE-2026-97428 | 7.7 High | Updated |
| 2026-09-25 | CVE-2026-97421 | CVE-2026-97421 | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-97417 | CVE-2026-97417 | 7.5 High | Updated |
| 2026-09-25 | CVE-2026-97413 | CVE-2026-97413 | 9.8 Critical | Updated |
| 2026-09-25 | CVE-2026-97409 | CVE-2026-97409 | 8.8 High | Updated |
| 2026-09-25 | CVE-2026-93830 | CVE-2026-93830 | 7.5 High | Updated |
| 2026-09-25 | CVE-2026-93827 | CVE-2026-93827 | 8.4 High | Updated |
| 2026-09-25 | CVE-2026-93826 | CVE-2026-93826 | 7.5 High | Updated |
| 2026-09-25 | CVE-2026-93817 | CVE-2026-93817 | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-93816 | CVE-2026-93816 | 7.1 High | Updated |
| 2026-09-25 | CVE-2026-93813 | CVE-2026-93813 | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-93810 | CVE-2026-93810 | 7.0 High | Updated |
| 2026-09-25 | CVE-2026-93806 | CVE-2026-93806 | 8.8 High | Updated |
| 2026-09-25 | CVE-2026-93801 | CVE-2026-93801 | 7.0 High | Updated |
| 2026-09-25 | CVE-2026-93799 | CVE-2026-93799 | 8.8 High | Updated |
| 2026-09-25 | CVE-2026-93798 | CVE-2026-93798 | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-93796 | CVE-2026-93796 | 7.0 High | Updated |
| 2026-09-25 | CVE-2026-93793 | CVE-2026-93793 | 8.8 High | Updated |
| 2026-09-25 | CVE-2026-93790 | CVE-2026-93790 | 8.8 High | Updated |
| 2026-09-25 | CVE-2026-93787 | CVE-2026-93787 | 8.1 High | Updated |
| 2026-09-25 | CVE-2026-93786 | CVE-2026-93786 | 8.1 High | Updated |
| 2026-09-25 | CVE-2026-93782 | CVE-2026-93782 | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-93345 | MikroTik RouterOS Labelled-VPN NLRI Prefix-Length Underflow Holds the BGP Plane Down Indefinitely; Fix Is Only in a Development Build | 7.5 High | Updated |
| 2026-09-25 | CVE-2026-93288 | CVE-2026-93288 | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-93287 | CVE-2026-93287 | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-93284 | CVE-2026-93284 | 8.8 High | Updated |
| 2026-09-25 | CVE-2026-93282 | CVE-2026-93282 | 8.1 High | Updated |
| 2026-09-25 | CVE-2026-93280 | CVE-2026-93280 | 8.8 High | Updated |
| 2026-09-25 | CVE-2026-93277 | CVE-2026-93277 | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-93265 | CVE-2026-93265 | 7.7 High | Updated |
| 2026-09-25 | CVE-2026-93262 | CVE-2026-93262 | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-93260 | CVE-2026-93260 | 7.4 High | Updated |
| 2026-09-25 | CVE-2026-93250 | CVE-2026-93250 | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-93237 | CVE-2026-93237 | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-93229 | CVE-2026-93229 | 7.1 High | Updated |
| 2026-09-25 | CVE-2026-93228 | CVE-2026-93228 | 9.1 Critical | Updated |
| 2026-09-25 | CVE-2026-93225 | CVE-2026-93225 | 7.4 High | Updated |
| 2026-09-25 | CVE-2026-93224 | CVE-2026-93224 | 8.1 High | Updated |
| 2026-09-25 | CVE-2026-93221 | CVE-2026-93221 | 8.1 High | Updated |
| 2026-09-25 | CVE-2026-93207 | CVE-2026-93207 | 9.8 Critical | Updated |
| 2026-09-25 | CVE-2026-72463 | CVE-2026-72463 | 9.8 Critical | Updated |
| 2026-09-25 | CVE-2026-72315 | CVE-2026-72315 | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-69458 | CVE-2026-69458 | 8.0 High | Updated |
| 2026-09-25 | CVE-2026-69456 | CVE-2026-69456 | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-69455 | CVE-2026-69455 | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-69451 | CVE-2026-69451 | 7.1 High | Updated |
| 2026-09-25 | CVE-2026-69448 | CVE-2026-69448 | 7.0 High | Updated |
| 2026-09-25 | CVE-2026-69447 | CVE-2026-69447 | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-69445 | CVE-2026-69445 | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-69444 | CVE-2026-69444 | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-69441 | CVE-2026-69441 | 7.0 High | Updated |
| 2026-09-25 | CVE-2026-69440 | CVE-2026-69440 | 7.0 High | Updated |
| 2026-09-25 | CVE-2026-69436 | CVE-2026-69436 | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-69434 | CVE-2026-69434 | 8.8 High | Updated |
| 2026-09-25 | CVE-2026-69433 | CVE-2026-69433 | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-69396 | CVE-2026-69396 | 7.1 High | Updated |
| 2026-09-25 | CVE-2026-69394 | CVE-2026-69394 | 7.0 High | Updated |
| 2026-09-25 | CVE-2026-69392 | CVE-2026-69392 | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-69391 | CVE-2026-69391 | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-69389 | CVE-2026-69389 | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-67281 | CVE-2026-67281 | 7.5 High | Updated |
| 2026-09-25 | CVE-2026-67278 | MikroTik RouterOS Accepts Malformed RSA/PKCS#1 v1.5 Signatures Across TLS and SSH, and Its Trust Store Includes an e=3 Root CA, Letting a Network Attacker Forge Valid Signatures Without the Private Key | 9.1 Critical | Updated |
| 2026-09-25 | CVE-2026-5430 | WSO2 API Gateway Path Traversal Reaches Federal Remediation Deadline of September 27 | 10.0 Critical | KEV |
| 2026-09-25 | CVE-2026-33824 | Microsoft Windows IKE Service Extensions' Double Free Enables Unauthenticated Remote Attackers to Execute Arbitrary Code; CISA's August 21st KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-25 | CVE-2026-32157 | CVE-2026-32157 | 8.8 High | Updated |
| 2026-09-25 | CVE-2026-26174 | CVE-2026-26174 | 7.0 High | Updated |
| 2026-09-25 | CVE-2026-20190 | CVE-2026-20190 | 7.5 High | Updated |
| 2026-09-25 | CVE-2026-20147 | Critical Cisco ISE and ISE-PIC Command Injection Scores 9.9 | 9.9 Critical | EPSS-Imminent |
| 2026-09-24 | CVE-2026-71474 | Red Hat insights-client logs a long-lived OpenShift pull-secret token that local pod-log access can expose | 7.1 High | Updated |
| 2026-09-24 | CVE-2026-54100 | Red Hat's Windows Machine Config Operator skips SSH host-key checks, letting adjacent attackers capture node bootstrap credentials | 8.3 High | Updated |
| 2026-09-24 | CVE-2026-54099 | A compromised Windows node can forge a cluster-administrator certificate through WMCO's CSR auto-approver, CVSS 8.8 | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-4740 | Red Hat Advanced Cluster Management lets a managed-cluster admin forge certificates for cross-cluster privilege escalation | 8.2 High | Updated |
| 2026-09-24 | CVE-2026-40141 | A critical query-injection flaw in BeyondTrust Remote Support lets low-privileged users reach unauthorized resources, CVSS 9.9 | 9.9 Critical | Updated |
| 2026-09-24 | CVE-2026-40140 | Unauthenticated attackers can crash BeyondTrust Remote Support appliances via a network-communication flaw | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-40139 | Critical Pre-Authentication Bypass in BeyondTrust Remote Support Allows Unauthorized Access | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-40138 | BeyondTrust Privileged Remote Access Shares Pre-Authentication Bypass Flaw with Remote Support | 8.1 High | Updated |
| 2026-09-24 | CVE-2026-33105 | Critical Authorization Bypass in Microsoft Azure Kubernetes Service Allows Network Privilege Escalation | 10.0 Critical | Updated |
| 2026-09-24 | CVE-2026-32590 | Unsafe Deserialization in Red Hat Quay Resumable Upload Handling | 7.1 High | Updated |
| 2026-09-24 | CVE-2026-32153 | Use-After-Free in Windows Speech Component Allows Local Privilege Escalation | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-32091 | Race Condition in Microsoft Brokering File System Allows Unauthorized Privilege Escalation | 8.4 High | Updated |
| 2026-09-24 | CVE-2026-27914 | Improper Access Control in Microsoft Management Console Allows Local Privilege Escalation | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-27909 | Use-After-Free in Windows Search Component Allows Authorized Attacker to Escalate Privileges | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-26181 | Use-After-Free in Microsoft Brokering File System Lets Authorized User Escalate Privileges | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-26170 | Input Validation Flaw in Microsoft PowerShell Allows Local Privilege Escalation | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-23429 | Linux Kernel IOMMU SVA Use-After-Free in Unbind Path Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-23428 | Critical Linux Kernel ksmbd Use-After-Free in Compound Request Handling Scores 9.8 | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-23427 | Critical Linux Kernel ksmbd Use-After-Free in Durable Handle Replay Scores 9.8 | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-23425 | Linux Kernel KVM arm64 ID Register Initialization Flaw Scores 8.8 | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-23424 | Linux Kernel amdxdna Missing Command Buffer Validation Scores 7.1 | 7.1 High | Updated |
| 2026-09-24 | CVE-2026-23422 | Linux Kernel dpaa2-switch Out-of-Bounds Write from Malformed Interrupt Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-23415 | Linux Kernel Futex Use-After-Free between Key Lookup and VMA Policy Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-23414 | Linux Kernel TLS Memory Leak in Async Decrypt Wait Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-23413 | Linux Kernel clsact Use-After-Free in Init/Destroy Rollback Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-23412 | Linux Kernel Netfilter BPF Use-After-Free in Hook Memory Release Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-23411 | Linux Kernel AppArmor Race Condition Frees i_private Data Early Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-23410 | Linux Kernel AppArmor Race on Rawdata Dereference Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-23408 | Linux Kernel AppArmor Double Free of Namespace Name Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-23407 | Linux Kernel AppArmor Out-of-Bounds Read in DFA Verification Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-22619 | Eaton Intelligent Power Protector Uncontrolled Search Path Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-21662 | Critical Johnson Controls FMS Employee Unrestricted File Upload Scores 9.8 | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-20160 | Critical Cisco Smart Software Manager On-Prem Resource Exposure Scores 9.8 | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-20155 | Cisco Evolved Programmable Network Manager Missing Authorization Scores 8.0 | 8.0 High | Updated |
| 2026-09-24 | CVE-2026-20151 | Cisco Smart Software Manager On-Prem Leaks Sensitive Data in Transmitted Requests | 7.3 High | Updated |
| 2026-09-24 | CVE-2026-20094 | Cisco UCS Command Injection Scores 8.8 | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-16443 | Red Hat Build of Keycloak Cryptographic Signature Verification Flaw Scores 7.4 | 7.4 High | Updated |
| 2026-09-24 | CVE-2026-0265 | Palo Alto Networks PAN-OS Authentication Bypass Affects Siemens RUGGEDCOM APE1808, Scores 8.1 | 8.1 High | Updated |
| 2026-09-24 | CVE-2026-0264 | Critical Palo Alto Networks PAN-OS DNS Heap Overflow Affects Siemens RUGGEDCOM APE1808, Scores 9.8 | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-0262 | Palo Alto Networks PAN-OS Multiple Denial-of-Service Flaws Affect Siemens RUGGEDCOM APE1808 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-0261 | Palo Alto Networks PAN-OS Command Injection Affects Siemens RUGGEDCOM APE1808, Scores 7.2 | 7.2 High | Updated |
| 2026-09-24 | CVE-2026-0258 | Palo Alto Networks PAN-OS IKEv2 SSRF Affects Siemens RUGGEDCOM APE1808, Scores 9.1 | 9.1 Critical | Updated |
| 2026-09-24 | CVE-2026-89028 | MikroTik RouterOS SMB1 SessionSetupAndX Handler Integer Underflow in uniPwdLen Corrupts Adjacent Heap Memory | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-85880 | Microsoft Windows' Heap-Based Buffer Overflow Allows Local Attackers to Escalate Privileges by Corrupting Heap Memory; CISA's September 22nd KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-24 | CVE-2026-80156 | Lantronix SLC8000, SLC9000, EMG, and SLB Series Upload Endpoint Strips Backslash Characters but Not Forward Slashes During Path Validation, Letting Authenticated Attackers Write Files to Arbitrary Filesystem Locations | 9.1 Critical | Updated |
| 2026-09-24 | CVE-2026-80155 | Lantronix SLC8000, SLC9000, EMG, and SLB Series Upload Endpoint Requires No Authentication, Allowing Unauthenticated Attackers to Read Configuration Files and Upload to Arbitrary Filesystem Locations, Scoring CVSS 10.0 | 10.0 Critical | Updated |
| 2026-09-24 | CVE-2026-80154 | Lantronix SLC8000, SLC9000, EMG, and SLB Series Web Portal Derives Session Tokens Deterministically from Device Model and Current Second, Letting Unauthenticated Attackers Predict and Forge Valid Sessions on All Firmware Versions | 9.6 Critical | Updated |
| 2026-09-24 | CVE-2026-80147 | Lantronix SLC8000/SLC9000 and EMG Series Undocumented mfc eeprom write Command Copies Unbounded Input into a Stack Buffer Before system(), Enabling Authenticated Attackers to Execute Arbitrary Code as Root | 9.9 Critical | Updated |
| 2026-09-24 | CVE-2026-80145 | Lantronix SLC8000/SLC9000 and EMG Series Set CIFS Password Command Passes User Input Unsanitized to system(), Enabling Authenticated Users with Services Permission to Run Commands as Root | 9.1 Critical | Updated |
| 2026-09-24 | CVE-2026-80144 | Lantronix SLC8000/SLC9000 and EMG Series Undocumented mfc eeprom write Command Passes Input Directly to system() via the CLI Interface, Reachable by Any Authenticated User for Root Command Execution | 9.9 Critical | Updated |
| 2026-09-24 | CVE-2026-80143 | Lantronix SLC8000/SLC9000 and EMG Series Undocumented mfc eeprom read Command Passes Input Directly to system() via the CLI Interface, Reachable by Any Authenticated User for Root Command Execution | 9.9 Critical | Updated |
| 2026-09-24 | CVE-2026-69571 | Windows USB Audio Class driver (usbaudio.sys) Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-69567 | Windows NTFS Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69564 | Windows Online Certificate Status Protocol (OCSP) Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69563 | Windows Program Compatibility Assistant Service Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69561 | Windows CD-ROM Driver Out-of-bounds read Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-69560 | Windows Work Folder Service Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69553 | Windows Hyper-V Missing authorization Lets Authorized Attackers Escalate Privileges over the Network (CVSS 7.1) | 7.1 High | Updated |
| 2026-09-24 | CVE-2026-69551 | Windows DNS Use after free Lets Authorized Attackers Execute Code over the Network (CVSS 8.8) | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-69547 | Windows DHCP Server Heap-based buffer overflow Lets Authorized Attackers Execute Code over the Network (CVSS 8.8) | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-69544 | Windows SMB Client Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-69542 | Windows Camera Frame Server Monitor Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-69540 | Windows Audio Service Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69539 | Windows Remote Desktop Services Use after free Lets Authorized Attackers Execute Code over the Network (CVSS 7.5) | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-69538 | Windows Spaceport.sys Out-of-bounds read Lets Authorized Attackers Execute Code Locally (CVSS 7.8) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-69535 | Windows Spaceport.sys Numeric Truncation Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-69534 | Windows Program Compatibility Assistant Service Command Injection Lets Authorized Attackers Escalate Privileges Locally | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-69532 | Windows NTFS Out-of-bounds read Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-69525 | Windows Remote Desktop Services Use after free Lets Unauthenticated Attackers Execute Code over the Network (CVSS 9.8) | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-69518 | Windows Remote Desktop Heap-based buffer overflow Lets Unauthenticated Attackers Execute Code over the Network (CVSS 8.8) | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-69514 | Windows Remote Desktop Services Heap-based buffer overflow Lets Authorized Attackers Execute Code over the Network (CVSS 7.5) | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-69511 | Microsoft Windows Media Foundation Heap-based buffer overflow Lets Unauthenticated Attackers Execute Code over the Network (CVSS 8.8) | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-69510 | Windows DHCP Server Stack-based buffer overflow Lets Unauthenticated Attackers Execute Code over the Network (CVSS 8.1) | 8.1 High | Updated |
| 2026-09-24 | CVE-2026-69509 | Windows Fax Service Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-69505 | Windows NTFS Out-of-Bounds Read Lets Authorized Attackers Escalate Privileges over the Network (CVSS 8.0) | 8.0 High | Updated |
| 2026-09-24 | CVE-2026-69500 | Windows Image Acquisition Use after free Lets Authorized Attackers Escalate Privileges Locally (CVE-2026-69500) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69496 | Windows Compressed Folder Heap-based buffer overflow Lets Unauthenticated Attackers Execute Code over the Network (CVSS 9.8) | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-69491 | Windows Microsoft DirectMusic Heap-based buffer overflow Lets Unauthenticated Attackers Execute Code over the Network (CVSS 9.8) | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-69479 | Windows NTFS Heap-based buffer overflow Lets Unauthenticated Attackers Execute Code Locally (CVSS 8.4) | 8.4 High | Updated |
| 2026-09-24 | CVE-2026-69475 | Windows Remote Desktop Services Untrusted Pointer Dereference Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-69473 | Windows Kernel Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69466 | Windows Kernel TOCTOU Race Condition Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69463 | Windows NTFS Heap-based buffer overflow Lets Unauthenticated Attackers Execute Code over the Network (CVSS 9.8) | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-69461 | Windows NTFS Stack-based buffer overflow Lets Unauthenticated Attackers Execute Code over the Network (CVSS 8.8) | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-69450 | Windows Error Reporting Out-of-bounds read Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-69430 | Windows Embedded Mode Service Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69429 | Windows IKE Extension Heap-based buffer overflow Lets Authorized Attackers Execute Code over the Network (CVSS 7.5) | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-69428 | Windows LDAP - Lightweight Directory Access Protocol Out-of-bounds read Lets Unauthenticated Attackers Disclose Sensitive Information over the Network (CVSS 7.5) | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-69427 | Windows VOLSNAP.SYS Out-of-bounds read Lets Authorized Attackers Escalate Privileges over the Network (CVSS 8.0) | 8.0 High | Updated |
| 2026-09-24 | CVE-2026-69426 | Windows VOLSNAP.SYS Heap-based buffer overflow Lets Authorized Attackers Execute Code Locally (CVSS 7.8) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-69424 | Windows Distributed File System (DFS) Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-69423 | Windows USB Video Driver Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges over the Network (CVSS 8.0) | 8.0 High | Updated |
| 2026-09-24 | CVE-2026-69421 | Windows Kernel Mode Driver Integer Underflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-69420 | Windows VOLSNAP.SYS Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-69413 | Windows USB Audio Class driver (usbaudio.sys) Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69412 | Windows DHCP Server Stack-based buffer overflow Lets Authorized Attackers Execute Code (CVSS 8.0) | 8.0 High | Updated |
| 2026-09-24 | CVE-2026-69410 | Windows Win32K Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69408 | Microsoft Windows Media Foundation Integer overflow or wraparound Lets Unauthenticated Attackers Execute Code over the Network (CVSS 9.8) | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-69404 | Windows TCP/IP Race Condition Lets Authorized Attackers Execute Code over the Network (CVSS 8.1) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69398 | Windows Bluetooth Service Race Condition Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69397 | OpenSSH for Windows Use after free Lets Unauthenticated Attackers Execute Code over the Network (CVSS 7.5) | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-69388 | Windows Bluetooth Service Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69386 | Microsoft Windows Media Foundation Heap-based buffer overflow Lets Unauthenticated Attackers Execute Code over the Network (CVSS 8.8) | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-69385 | Windows TCP/IP Race Condition Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69383 | Windows Shell Arbitrary File Path Control Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69377 | Windows Modern Device Management (MDM) Missing authorization Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-69371 | Windows Overlay Filter Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges over the Network (CVSS 8.0) | 8.0 High | Updated |
| 2026-09-24 | CVE-2026-69368 | Windows Overlay Filter Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-69366 | Windows Kernel Use after free Lets Authorized Attackers Escalate Privileges over the Network (CVSS 7.1) | 7.1 High | Updated |
| 2026-09-24 | CVE-2026-69364 | Windows Print Spooler Components Race Condition Lets Authorized Attackers Escalate Privileges over the Network (CVSS 7.1) | 7.1 High | Updated |
| 2026-09-24 | CVE-2026-69362 | Windows Error Reporting Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69357 | Windows NDIS Use after free Lets Authorized Attackers Escalate Privileges over the Network (CVSS 7.1) | 7.1 High | Updated |
| 2026-09-24 | CVE-2026-69347 | Windows Fast FAT Driver Heap-based buffer overflow Lets Unauthenticated Attackers Execute Code Locally (CVSS 7.4) | 7.4 High | Updated |
| 2026-09-24 | CVE-2026-69346 | Windows Print Spooler Components Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges over the Network (CVSS 8.0) | 8.0 High | Updated |
| 2026-09-24 | CVE-2026-69342 | Windows DHCP Server Out-of-bounds read Lets Unauthenticated Attackers Disclose Sensitive Information over the Network (CVSS 7.5) | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-69341 | Windows Image Acquisition Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69340 | Windows NTFS Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges over the Network (CVSS 7.1) | 7.1 High | Updated |
| 2026-09-24 | CVE-2026-69337 | Windows Registry Double free Lets Authorized Attackers Escalate Privileges over the Network (CVSS 7.1) | 7.1 High | Updated |
| 2026-09-24 | CVE-2026-69335 | Windows Win32K Use after free Lets Authorized Attackers Escalate Privileges Locally (CVE-2026-69335) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69334 | Windows Volume Manager Extension Driver Heap-based buffer overflow Lets Unauthenticated Attackers Execute Code over the Network (CVSS 8.8) | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-69332 | Windows NTFS Out-of-bounds read Lets Authorized Attackers Escalate Privileges over the Network (CVSS 8.0) | 8.0 High | Updated |
| 2026-09-24 | CVE-2026-69331 | Windows Remote Access Connection Manager Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69328 | Windows Storage Untrusted search path Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-69324 | Windows Performance Monitor Type Confusion Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-69322 | Microsoft Windows Search Component Double free Lets Authorized Attackers Escalate Privileges over the Network (CVSS 8.0) | 8.0 High | Updated |
| 2026-09-24 | CVE-2026-69319 | Windows USB Video Driver Race Condition Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69312 | Windows NTFS Out-of-Bounds Read Lets Authorized Attackers Escalate Privileges Locally (CVE-2026-69312) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-69311 | Windows Audio Service Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69310 | Windows DNS Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69309 | Windows Print Spooler Components Double free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69307 | Windows USB Audio Class driver (usbaudio.sys) Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-69305 | Microsoft Windows Search Component Use after free Lets Authorized Attackers Escalate Privileges over the Network (CVSS 7.1) | 7.1 High | Updated |
| 2026-09-24 | CVE-2026-69301 | Windows Win32K Stack-based buffer overflow Lets Authorized Attackers Escalate Privileges over the Network (CVSS 8.0) | 8.0 High | Updated |
| 2026-09-24 | CVE-2026-69300 | Windows Push Notifications Use after free Lets Authorized Attackers Escalate Privileges Locally (CVE-2026-69300) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69299 | Microsoft COM for Windows Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69296 | Windows Device Association Service Use after free Lets Authorized Attackers Escalate Privileges over the Network (CVSS 7.1) | 7.1 High | Updated |
| 2026-09-24 | CVE-2026-69295 | Windows USB Driver Out-of-bounds read Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-69291 | Windows Volume Manager Extension Driver Heap-based buffer overflow Lets Unauthenticated Attackers Execute Code over the Network (CVSS 8.8) | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-69290 | Windows Storage Spaces Controller Stack-based buffer overflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-69289 | Windows Setup Files Cleanup Symbolic Link Following Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-69287 | Windows Remote Desktop Services Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69284 | Windows DCOM Server Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-69283 | Windows CD-ROM Driver Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-69281 | Windows License Manager Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69280 | Windows Push Notifications Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69279 | Windows Cloud Files Mini Filter Driver Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69274 | Windows Win32K Use after free Lets Authorized Attackers Escalate Privileges over the Network (CVSS 7.1) | 7.1 High | Updated |
| 2026-09-24 | CVE-2026-69270 | Windows USB Audio Class driver (usbaudio.sys) Heap-based buffer overflow Lets Authorized Attackers Execute Code Locally (CVSS 7.8) (CVE-2026-69270) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-69266 | Windows DHCP Server Integer Overflow or Wraparound Lets Unauthenticated Attackers Execute Code over the Network | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-69265 | Windows NTFS Out-of-Bounds Read Lets Authorized Attackers Escalate Privileges Locally (CVE-2026-69265) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-68896 | Microsoft Windows Search Component Absolute path traversal Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-68894 | Windows Error Reporting Heap-Based Buffer Overflow Lets Authorized Attackers Escalate Privileges over the Network | 8.0 High | Updated |
| 2026-09-24 | CVE-2026-68893 | Windows Remote Desktop Licensing Service Use after free Lets Authorized Attackers Escalate Privileges over the Network (CVSS 7.1) | 7.1 High | Updated |
| 2026-09-24 | CVE-2026-68887 | Windows Message Queuing Queue Manager Out-of-Bounds Read Lets Unauthenticated Attackers Access Sensitive Data over the Network | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-68880 | Windows Win32K Heap-Based Buffer Overflow Lets Authorized Attackers Escalate Privileges over the Network | 8.0 High | Updated |
| 2026-09-24 | CVE-2026-68878 | Windows Fast FAT Driver Stack-Based Buffer Overflow Lets Authorized Attackers Escalate Privileges over the Network | 8.0 High | Updated |
| 2026-09-24 | CVE-2026-68877 | Windows Storage Spaces Controller Heap-Based Buffer Overflow Lets Authorized Attackers Execute Code Locally (CVE-2026-68877) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-68876 | Windows Program Compatibility Assistant Service Heap-Based Buffer Overflow Lets Authorized Attackers Escalate Privileges over the Network | 8.0 High | Updated |
| 2026-09-24 | CVE-2026-68875 | Windows NTFS Buffer Over-read Lets Authorized Attackers Execute Code Locally | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-68848 | Windows Print Spooler Components Heap-Based Buffer Overflow Lets Authorized Attackers Escalate Privileges Locally | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-68846 | Windows Kernel Use after free Lets Authorized Attackers Escalate Privileges over the Network (CVSS 7.1) | 7.1 High | Updated |
| 2026-09-24 | CVE-2026-68845 | Windows Program Compatibility Assistant Service Heap-Based Buffer Overflow Lets Authorized Attackers Escalate Privileges Locally | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-68844 | Windows Storage Spaces Controller Heap-Based Buffer Overflow Lets Authorized Attackers Execute Code Locally | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-68841 | Windows NTFS Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-68840 | Windows USB Driver Concurrent execution using shared resource with improper synchronization ('race condition') Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-68839 | Windows USB Mass Storage Class Driver Heap-based buffer overflow Lets Unauthenticated Attackers Execute Code over the Network (CVSS 9.8) | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-68838 | Windows NTFS Stack-based buffer overflow Lets Authorized Attackers Escalate Privileges over the Network (CVSS 8.0) | 8.0 High | Updated |
| 2026-09-24 | CVE-2026-68835 | Windows Print Spooler Components Use-After-Free Lets Authorized Attackers Escalate Privileges over the Network | 7.1 High | Updated |
| 2026-09-24 | CVE-2026-68834 | Windows NTFS Stack-Based Buffer Overflow Lets Authorized Attackers Escalate Privileges over the Network (CVE-2026-68834) | 8.0 High | Updated |
| 2026-09-24 | CVE-2026-68832 | Windows NTFS Integer Overflow Lets Authorized Attackers Escalate Privileges Locally | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-68827 | Windows GDI+ Integer Underflow Lets Authorized Attackers Escalate Privileges over the Network | 8.0 High | Updated |
| 2026-09-24 | CVE-2026-62759 | Windows Netlogon Authentication Bypass Lets Unauthenticated Attackers Compromise the System Locally | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-62706 | Microsoft Windows Media Foundation Out-of-Bounds Read Lets Unauthenticated Attackers Execute Code over the Network | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-62694 | Windows Installer Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-5857 | Contiki-NG MQTT Client parse_publish_vhdr Persists a Flag Past an Over-Length Topic, Skipping the Length Guard on the Next Segment and Overflowing the Topic Buffer | 8.1 High | Updated |
| 2026-09-24 | CVE-2026-50349 | Windows Ancillary Function Driver for WinSock Race Condition Lets Authorized Attackers Escalate Privileges Locally | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-19654 | Privilege Escalation in Enterprise Linux 9, Allowing Privilege Escalation | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-13249 | Honeywell PD45 Industrial Printer F10.19.010040 Web Management Interface Allows Unauthenticated File Upload of Attacker-Controlled Files, Enabling Remote Code Execution Without Credentials | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-13248 | Honeywell PD45 Industrial Printer Fingerprint command interface allows authenticated admin to write arbitrary files and execute code | 8.8 High | Updated |
| 2026-09-23 | CVE-2026-20180 | Critical Cisco ISE Path Traversal Enables Remote Code Execution, Scores 9.9 | 9.9 Critical | EPSS-Imminent |
| 2026-09-23 | CVE-2026-94127 | CISA's September 25th Remediation Deadline for F5 BIG-IP APM's OAuth Profile Heap Overflow Has Passed; Covered Entities Running Affected Virtual Servers Are Out of Compliance | 9.8 Critical | KEV |
| 2026-09-23 | CVE-2026-93952 | Arista VeloCloud Orchestrator Input Validation Gap Lets Remote Attackers Reach Privileged APIs; CISA's September 25th KEV Deadline for Covered Entities Has Now Passed | 10.0 Critical | KEV |
| 2026-09-23 | CVE-2026-83998 | Remote Desktop Client Heap-Based Buffer Overflow Lets Unauthenticated Attackers Execute Code over the Network | 8.8 High | Updated |
| 2026-09-23 | CVE-2026-82028 | absmach magistrala SQL Injection Reachable by Authenticated Remote Attackers with High Severity (CVSS 8.8) | 8.8 High | Updated |
| 2026-09-23 | CVE-2026-73176 | Advantech EKI-1242IEIMS Web Management Interface Passes Request Parameters to OS Commands Without Sanitization, Enabling Root Execution for Authenticated Administrators | 8.6 High | Updated |
| 2026-09-23 | CVE-2026-73175 | Adjacent Unauthenticated Attacker Can Exhaust the Advantech EKI-1242EIMS OPC UA Session Pool by Opening Multiple Anonymous Connections | 7.1 High | Updated |
| 2026-09-23 | CVE-2026-73174 | Advantech EKI-1242EIMS edgserver Management Protocol Transmits Device Identity and Network Metadata in Cleartext, Recoverable by a Network-Adjacent Passive Observer | 8.7 High | Updated |
| 2026-09-23 | CVE-2026-73173 | Advantech EKI-1242EIMS edgserver on TCP Port 5058 Requires No Authentication, Allowing Remote Attackers to Reconfigure the Network, Reboot, Reset, or Replace Firmware | 8.8 High | Updated |
| 2026-09-23 | CVE-2026-73172 | Advantech EKI-1242EIMS Firmware V1.06.01 edgserver Management Service Passes Unsanitized Input to the OS Shell, Enabling Unauthenticated Remote Attackers to Execute Arbitrary Commands | 9.3 Critical | Updated |
| 2026-09-23 | CVE-2026-73171 | Advantech EKI-1242EIMS Backup-Restore Workflow Accepts Crafted Archives That Overwrite Arbitrary Files on the Device Filesystem | 8.6 High | Updated |
| 2026-09-23 | CVE-2026-73170 | Advantech EKI-1242EIMS Modbus CSV Import Evaluates Crafted File Content as Lua, Allowing Authenticated Administrators to Execute Arbitrary Code | 8.6 High | Updated |
| 2026-09-23 | CVE-2026-73167 | Authenticated Administrator Can Inject OS Commands as Root via Crafted Request Parameters in the Advantech EKI-1242IEIMS Web Management Interface | 8.6 High | Updated |
| 2026-09-23 | CVE-2026-73166 | Advantech EKI-1242IEIMS Web Management Interface Evaluates Code from Request Parameters, Giving Authenticated Administrators Root-Level Code Execution | 8.6 High | Updated |
| 2026-09-23 | CVE-2026-73165 | Advantech EKI-1242IEIMS Web Management Endpoint Executes Attacker-Supplied OS Commands as Root When Request Parameters Are Not Sanitized | 8.6 High | Updated |
| 2026-09-23 | CVE-2026-73164 | Crafted HTTP Request Parameters Reach Root-Level OS Execution in Advantech EKI-1242IEIMS Due to Unsanitized Web Interface Input | 8.6 High | Updated |
| 2026-09-23 | CVE-2026-73163 | Advantech EKI-1242IEIMS Web Interface OS Command Injection Grants Root Access to Authenticated Administrators | 8.6 High | Updated |
| 2026-09-23 | CVE-2026-73014 | Data Sharing Service Client Missing authorization Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8) | 7.8 High | Updated |
| 2026-09-23 | CVE-2026-70584 | Windows Core Messaging Type Confusion Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8) | 7.8 High | Updated |
| 2026-09-23 | CVE-2026-69528 | Windows Shell Missing Authentication Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8) | 7.8 High | Updated |
| 2026-09-23 | CVE-2026-69517 | Windows Wireless Networking Use-After-Free Lets Authorized Attackers Escalate Privileges Locally | 7.0 High | Updated |
| 2026-09-23 | CVE-2026-69512 | Windows Spaceport.sys Heap-Based Buffer Overflow Lets Authorized Attackers Escalate Privileges over the Network | 8.0 High | Updated |
| 2026-09-23 | CVE-2026-69508 | Windows MIDI Service Module Stack-Based Buffer Overflow Lets Authorized Attackers Escalate Privileges Locally | 7.8 High | Updated |
| 2026-09-23 | CVE-2026-69443 | Microsoft Azure Attestation service and Device Health Attestation Service Out-of-Bounds Read Lets Unauthenticated Attackers Access Sensitive Data over the Network | 7.5 High | Updated |
| 2026-09-23 | CVE-2026-53983 | Ground Station Socket.IO Server Accepts Attacker-Supplied Orbital Source URLs Without Authentication, Enabling Unauthenticated SSRF via the Orbital Sync Trigger | 8.6 High | Updated |
| 2026-09-23 | CVE-2026-19535 | Advantech EKI-1242IEIMS LuCI admin interface CSRF allows unauthenticated attacker to trigger privileged management actions | 8.6 High | Updated |
| 2026-09-23 | CVE-2026-19438 | ABB Mint Workbench I Path Traversal Lets Unauthenticated Remote Attackers Access Sensitive Files (CVSS 7.5) | 7.5 High | Updated |
| 2026-09-23 | CVE-2026-12974 | Forcepoint NGFW security policy bypass affects versions across 7.1, 7.3, 7.4, and 7.5 branches | 7.9 High | Updated |
| 2026-09-22 | CVE-2026-9586 | Sangoma Switchvox's SQL Injection Vulnerability Allows Unauthenticated Remote Attackers to Execute Arbitrary Database Queries and Compromise the Telephony Platform | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-9198 | IBM Langflow's Code Injection Flaw Allows Unauthenticated Remote Attackers to Execute Arbitrary Code on the AI Workflow Platform; CISA's August 7th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-9082 | Drupal Core's SQL Injection via Specially Crafted Database Abstraction API Requests Enables Privilege Escalation and Remote Code Execution; CISA's May 27th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-86218 | N-able N-central's Static Code Injection Flaw Allows Remote Attackers to Inject and Execute Arbitrary Code on the RMM Platform Without Prior Authentication | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-85706 | GitLab Community and Enterprise Edition's Path Traversal Flaw Allows Unauthenticated Remote Attackers to Read Arbitrary Files on the Server and Fully Compromise the GitLab Instance | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-83549 | SonicWall SMA1000 Appliances' OS Command Injection Allows Authenticated Local Attackers to Execute Arbitrary Commands with Root Privileges; CISA's September 5th KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-22 | CVE-2026-83548 | SonicWall SMA1000 Appliances' Server-Side Request Forgery Allows Unauthenticated Remote Attackers to Reach Internal Services and Compromise the Secure Mobile Access Gateway; CISA's September 5th KEV Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-82329 | JFrog Artifactory Carries a 9.8 Critical Improper Authentication Flaw That Lets Unauthenticated Attackers Bypass Login Controls on the Artifact Repository | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-73570 | Zimbra Collaboration Suite's OS Command Injection Allows Authenticated Attackers to Execute Arbitrary Commands on the Email Server with Elevated Privileges; CISA's August 24th KEV Deadline Has Passed | 8.9 High | KEV |
| 2026-09-22 | CVE-2026-72898 | Metabase's SQL Injection Flaw Allows Unauthenticated Attackers to Execute Arbitrary Database Queries and Achieve Full Platform Compromise; CISA's August 14th KEV Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-6973 | Ivanti Endpoint Manager Mobile's Improper Input Validation Allows a Remotely Authenticated Administrator to Execute Code Remotely; CISA's May 10th KEV Deadline Has Passed | 7.2 High | KEV |
| 2026-09-22 | CVE-2026-68820 | Microsoft Windows Ancillary Function Driver for WinSock's Use-After-Free Allows a Local Attacker to Gain Elevated Privileges via a Freed Memory Reference; CISA's August 25th KEV Deadline Has Passed | 7.0 High | KEV |
| 2026-09-22 | CVE-2026-65400 | Apple macOS's Improper Authentication Flaw Allows a Network Attacker to Bypass Login Controls and Gain Unauthorized Access to the Operating System; CISA's August 21st KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-64849 | MLflow's Server-Side Request Forgery Flaw Allows Remote Attackers to Use the ML Platform Server as a Proxy to Access Internal Services and Steal Credentials; CISA's September 2nd KEV Deadline Has Passed | 9.3 Critical | KEV |
| 2026-09-22 | CVE-2026-63077 | JetBrains TeamCity's Deserialization of Untrusted Data Allows Unauthenticated Remote Attackers to Execute Arbitrary Code on the CI/CD Server; CISA's August 8th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-63030 | WordPress Core Input Interpretation Conflict Exploited in the Wild Carries a Lapsed July 24th CISA KEV Mandate for Covered Entities | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-60137 | WordPress Core SQL Injection Enabling Database Access Joins CISA's Known Exploited Vulnerabilities Catalog; Covered Entities Past the August 4th Remediation Deadline | 5.9 Medium | KEV |
| 2026-09-22 | CVE-2026-60004 | Gitea's Code Injection Vulnerability Allows Unauthenticated Remote Attackers to Execute Arbitrary Code on the Repository Platform; CISA's August 28th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-59310 | Broadcom VMware vCenter's Path Traversal Flaw Allows Unauthenticated Remote Attackers to Access Files Outside the Web Root and Potentially Compromise the Virtualization Platform; CISA's August 21st KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-56291 | Balbooa Forms Unrestricted File Upload Requiring No Authentication Has Missed CISA's July 13th KEV Remediation Deadline; Covered Entities Are Now Out of Compliance | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-56290 | Joomlack Page Builder Lets Unauthenticated Users Upload Arbitrary Files, Enabling Remote Code Execution; CISA's July 10th KEV Mandate Has Lapsed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-55040 | Microsoft SharePoint's Weak Authentication Allows Attackers to Bypass Login Controls and Gain Unauthorized Access to SharePoint Sites and Data; CISA's August 21st KEV Deadline Has Passed | 9.1 Critical | KEV |
| 2026-09-22 | CVE-2026-50751 | Check Point Security Gateway's IKEv1 Key Exchange Flaw Lets Unauthenticated Attackers Establish Remote Access VPN Tunnels Without a Valid Password; CISA's June 11th KEV Deadline Has Passed | 9.3 Critical | KEV |
| 2026-09-22 | CVE-2026-48939 | iCagenda Joomla Event Calendar Extension Accepts Unrestricted File Uploads Without Authentication, Enabling Remote Code Execution; CISA's July 13th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-48908 | JoomShaper SP Page Builder Accepts Arbitrary File Uploads from Unauthenticated Users; CISA's July 10th KEV Deadline for Covered Entities Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-48907 | Joomla Content Editor Plugin Exposes Privileged Functions Without Proper Authorization; CISA's June 19th KEV Deadline for Covered Entities Has Lapsed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-48558 | SimpleHelp Accepts Unverified Cryptographic Signatures, Letting Remote Attackers Bypass Authentication; CISA's July 2nd KEV Deadline for Covered Entities Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-48172 | Any cPanel User Can Escalate Privileges Through LiteSpeed's Plugin; CISA's May 29th KEV Remediation Requirement for Covered Entities Has Expired | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-46817 | Oracle E-Business Suite's Improper Privilege Management in Oracle Payments Allows an Unauthenticated Network Attacker to Take Over the Payments Module via HTTP; CISA's July 18th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-45498 | Microsoft Defender's Unspecified Vulnerability Allows for Denial of Service; CISA's June 3rd KEV Deadline Has Passed | 4.0 Medium | KEV |
| 2026-09-22 | CVE-2026-45247 | Mirasvit Full Page Cache Warmer's Deserialization Flaw Lets Unauthenticated Attackers Reach Remote Code Execution via a Crafted PHP Object in the CacheWarmer Cookie; CISA's June 6th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-42897 | Microsoft Exchange Server's Outlook Web Access Cross-Site Scripting Flaw Executes Arbitrary JavaScript When Interaction Conditions Are Met; CISA's May 29th KEV Deadline Has Passed | 8.1 High | KEV |
| 2026-09-22 | CVE-2026-42018 | JFrog Artifactory's Improper Authentication Allows Network-Based Attackers to Bypass Login Controls and Gain Unauthorized Access to the Artifact Repository | 7.5 High | KEV |
| 2026-09-22 | CVE-2026-42016 | JFrog Artifactory's Incorrect Authorization Allows Authenticated Users to Access Artifacts and Repositories Outside Their Permitted Scope | 8.1 High | KEV |
| 2026-09-22 | CVE-2026-41091 | Microsoft Defender's Link Following Flaw Enables an Authorized Attacker to Elevate Privileges Locally; CISA's June 3rd KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-22 | CVE-2026-39987 | Marimo's Pre-Authentication Flaw Gives Unauthenticated Attackers Shell Access and Arbitrary Command Execution; CISA's May 7th KEV Remediation Requirement for Covered Entities Has Long Lapsed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-39808 | Fortinet FortiSandbox's OS Command Injection Gives Unauthenticated Attackers Remote Code Execution via Crafted HTTP Requests; CISA's July 19th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-35616 | Fortinet FortiClient EMS Access Control Bypass Entered CISA's Known Exploited Vulnerabilities Catalog with an April 9th Federal Deadline That Has Long Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-35273 | Oracle PeopleSoft Enterprise PeopleTools' Missing Authentication for a Critical Function Allows Unauthenticated Attackers to Take Over the Platform; CISA's June 15th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-34926 | Pre-Authenticated Local Attackers Can Use Relative Path Traversal in Trend Micro Apex One to Modify Key Configuration Data; CISA's June 4th KEV Mandate for Covered Entities Has Lapsed | 6.7 Medium | KEV |
| 2026-09-22 | CVE-2026-34910 | Network-Adjacent Attackers Can Inject Commands into Ubiquiti UniFi OS Through an Input Validation Flaw; CISA's June 26th KEV Remediation Window Has Closed for Covered Entities | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-34909 | Ubiquiti UniFi OS's Path Traversal Lets a Network-Adjacent Attacker Access Files on the Underlying System and Manipulate an Underlying Account; CISA's June 26th KEV Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-34908 | Ubiquiti UniFi OS's Improper Access Control Lets a Network-Adjacent Attacker Make Unauthorized Changes to the System; CISA's June 26th KEV Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-34486 | Apache Tomcat's Missing Encryption of Sensitive Session Data Exposes Credentials and Tokens to Network Interception; CISA's August 7th KEV Deadline Has Passed | 7.5 High | KEV |
| 2026-09-22 | CVE-2026-34197 | Apache ActiveMQ's Improper Input Validation Enables Code Injection Affecting Both ActiveMQ and Broker Deployments; CISA's April 30th KEV Deadline Has Passed | 8.8 High | KEV |
| 2026-09-22 | CVE-2026-33825 | Microsoft Defender's Insufficient Access Control Allows an Authorized Attacker to Escalate Privileges Locally; CISA's May 6th KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-22 | CVE-2026-32202 | Microsoft Windows Shell's Protection Mechanism Failure Allows an Unauthorized Attacker to Perform Spoofing Over the Network; CISA's May 12th KEV Deadline Has Passed | 4.3 Medium | KEV |
| 2026-09-22 | CVE-2026-31431 | Linux Kernel Resource Mishandling That Allows Privilege Escalation Carries a Lapsed May 15th CISA KEV Mandate; Covered Entities on Unpatched Kernels Remain Out of Compliance | 7.8 High | KEV |
| 2026-09-22 | CVE-2026-28318 | SolarWinds Serv-U File Transfer Server Resource Exhaustion Exploited in the Wild Carries a Lapsed June 19th CISA KEV Federal Deadline | 7.5 High | KEV |
| 2026-09-22 | CVE-2026-25089 | Fortinet FortiSandbox's Unauthenticated OS Command Injection via Crafted HTTP Requests Covers Cloud and PaaS Deployments; CISA's July 19th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-21962 | Oracle HTTP Server and WebLogic Server Proxy Plug-in's Improper Access Control Allows Unauthenticated Network Attackers to Fully Compromise the Middleware Platform; CISA's August 27th KEV Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-21643 | Fortinet FortiClient EMS's SQL Injection Allows Unauthenticated Attackers to Execute Unauthorized Code via Crafted HTTP Requests; CISA's April 16th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-20316 | Cisco Secure Firewall Management Center Hard-Coded Password Lets Attackers Bypass Authentication; CISA's August 1st KEV Deadline for Covered Entities Has Passed | 5.3 Medium | KEV |
| 2026-09-22 | CVE-2026-20262 | Authenticated Path Traversal in Cisco Catalyst SD-WAN Manager Lets Remote Attackers Write Files Outside Allowed Directories; CISA's June 29th KEV Deadline Has Passed | 6.5 Medium | KEV |
| 2026-09-22 | CVE-2026-20253 | Splunk Enterprise's Missing Authentication on a PostgreSQL Sidecar Service Endpoint Lets Unauthenticated Users Create or Truncate Arbitrary Files; CISA's June 21st KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-20245 | Cisco Catalyst SD-WAN Manager's Improper Encoding Allows an Authenticated Local Attacker to Execute Arbitrary Commands as Root via a Crafted File; CISA's June 23rd KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-22 | CVE-2026-20230 | Cisco Unified Communications Manager SSRF Flaw Routes Attacker Requests to Internal Resources; CISA's June 28th KEV Deadline for Covered Entities Has Lapsed | 8.6 High | KEV |
| 2026-09-22 | CVE-2026-20200 | Cisco Unified Computing System's Argument Delimiter Injection Allows an Authenticated Attacker to Execute Arbitrary Commands on the Management Controller | 8.8 High | Exploited |
| 2026-09-22 | CVE-2026-20182 | Cisco Catalyst SD-WAN Controller and Manager's Authentication Bypass Gives Unauthenticated Remote Attackers Administrative Privileges; CISA's May 17th KEV Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-20133 | Cisco Catalyst SD-WAN Manager Leaks Sensitive Configuration Data to Unauthorized Users; CISA's April 23rd KEV Remediation Requirement Has Expired for Covered Entities | 6.5 Medium | KEV |
| 2026-09-22 | CVE-2026-20128 | Cisco Catalyst SD-WAN Manager Stores Credentials in a Recoverable Format, Enabling Credential Theft; CISA's April 23rd KEV Mandate for Covered Entities Has Lapsed | 7.5 High | KEV |
| 2026-09-22 | CVE-2026-20122 | Cisco Catalyst SD-WAN Manager Exposes Privileged API Functions to Unauthorized Callers; CISA's April 23rd KEV Remediation Deadline for Covered Entities Has Long Passed | 5.4 Medium | KEV |
| 2026-09-22 | CVE-2026-20079 | Cisco Firewall Management Center's Authentication Bypass via an Alternate Path Grants Unauthenticated Remote Attackers Full Administrative Control; CISA's September 12th KEV Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-19490 | Citrix NetScaler's Authentication Bypass via an Alternate Path Allows Unauthenticated Remote Attackers to Access Protected Resources Without Valid Credentials | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-16232 | Check Point SmartConsole's Improper Authentication Allows Unauthenticated Remote Attackers to Obtain a Login Token and Authenticate with Full Administrative Privileges; CISA's July 25th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-15410 | SonicWall SMA1000's Code Injection Allows a Remote Authenticated Administrator to Execute Arbitrary OS Commands Under Specific Conditions; CISA's July 17th KEV Deadline Has Passed | 7.2 High | KEV |
| 2026-09-22 | CVE-2026-15409 | SonicWall SMA1000 Secure Access Appliances Accept Forged Server-Side Requests, Enabling Internal Network Pivoting; CISA's July 17th KEV Remediation Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-1340 | Ivanti Endpoint Manager Mobile's Code Injection Vulnerability Allows Attackers to Achieve Unauthenticated Remote Code Execution; CISA's April 11th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-12569 | PTC Windchill and FlexPLM's Improper Input Validation Allows Unauthenticated Remote Attackers to Execute Arbitrary Code via Malicious Network Requests; CISA's June 28th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-10520 | Ivanti Sentry's OS Command Injection Gives Remote Unauthenticated Attackers Root-Level Remote Code Execution; CISA's June 14th KEV Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-0300 | PAN-OS Out-of-Bounds Write Enabling Code Execution Affects Both Palo Alto Networks Firewalls and Siemens RUGGEDCOM APE1808 Industrial Appliances; CISA's May 9th KEV Window Has Closed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-0257 | PAN-OS Authentication Bypass Enabling Unauthorized VPN Tunnels Affects Palo Alto Networks Prisma Access and Siemens RUGGEDCOM APE1808; Now Listed in CISA's Known Exploited Vulnerabilities Catalog | 9.1 Critical | KEV |
| 2026-09-22 | CVE-2026-95862 | Ubiquiti Inc Dream Wall Out-of-Bounds Write Reachable by Unauthenticated Remote Attackers | 7.5 High | Updated |
| 2026-09-22 | CVE-2026-95861 | Ubiquiti Inc Dream Wall Denial of Service Reachable by Unauthenticated Remote Attackers in Ubiquiti Inc Dream Wall | 7.5 High | Updated |
| 2026-09-22 | CVE-2026-95675 | D-Link DAP-1360 Remote Code Execution Reachable by Unauthenticated Remote Attackers at Critical Severity (CVSS 9.8) | 9.8 Critical | Updated |
| 2026-09-22 | CVE-2026-94089 | D-Link DIR-868L Buffer Overflow Reachable by Unauthenticated Remote Attackers at Critical Severity (CVSS 10.0) | 10.0 Critical | Updated |
| 2026-09-22 | CVE-2026-77558 | Ubiquiti UniFi Dream Wall Out-of-Bounds Read Lets Unauthenticated Network Attackers Cause Denial of Service (CVSS 7.5) | 7.5 High | Updated |
| 2026-09-22 | CVE-2026-77556 | Ubiquiti UniFi Dream Wall Out-of-Bounds Read Lets Network-Adjacent Attackers Read Sensitive Data (CVSS 7.5) | 7.5 High | Updated |
| 2026-09-22 | CVE-2026-77555 | Ubiquiti Inc Dream Wall Out-of-Bounds Write Reachable by Unauthenticated Remote Attackers (CVE-2026-77555) | 7.5 High | Updated |
| 2026-09-22 | CVE-2026-77544 | Ubiquiti Inc Dream Wall Out-of-Bounds Write Reachable by Unauthenticated Remote Attackers in Ubiquiti Inc Dream Wall | 7.5 High | Updated |
| 2026-09-22 | CVE-2026-72946 | CVE-2026-72946 | 7.8 High | Updated |
| 2026-09-22 | CVE-2026-72940 | CVE-2026-72940 | 8.8 High | Updated |
| 2026-09-22 | CVE-2026-72936 | CVE-2026-72936 | 8.1 High | Updated |
| 2026-09-22 | CVE-2026-72929 | CVE-2026-72929 | 7.8 High | Updated |
| 2026-09-22 | CVE-2026-72926 | CVE-2026-72926 | 7.0 High | Updated |
| 2026-09-22 | CVE-2026-7273 | Zyxel GS1900 Series Switches' CGI Program Stack-Based Buffer Overflow Allows a LAN-Side Unauthenticated Attacker to Execute OS Commands via Crafted HTTP Requests; CISA's September 24th KEV Deadline Has Passed | 8.8 High | KEV |
| 2026-09-22 | CVE-2026-71221 | CVE-2026-71221 | 7.0 High | Updated |
| 2026-09-22 | CVE-2026-71220 | CVE-2026-71220 | 7.0 High | Updated |
| 2026-09-22 | CVE-2026-69791 | CVE-2026-69791 | 7.0 High | Updated |
| 2026-09-22 | CVE-2026-69790 | CVE-2026-69790 | 7.8 High | Updated |
| 2026-09-22 | CVE-2026-69784 | Windows Hello Use-After-Free Lets Authorized Attackers Escalate Privileges Locally | 8.8 High | Updated |
| 2026-09-22 | CVE-2026-69775 | CVE-2026-69775 | 7.1 High | Updated |
| 2026-09-22 | CVE-2026-69762 | CVE-2026-69762 | 8.0 High | Updated |
| 2026-09-22 | CVE-2026-69760 | CVE-2026-69760 | 7.5 High | Updated |
| 2026-09-22 | CVE-2026-69757 | CVE-2026-69757 | 7.1 High | Updated |
| 2026-09-22 | CVE-2026-69744 | CVE-2026-69744 | 7.5 High | Updated |
| 2026-09-22 | CVE-2026-69740 | CVE-2026-69740 | 8.8 High | Updated |
| 2026-09-22 | CVE-2026-69735 | CVE-2026-69735 | 7.0 High | Updated |
| 2026-09-22 | CVE-2026-69729 | CVE-2026-69729 | 8.8 High | Updated |
| 2026-09-22 | CVE-2026-69725 | CVE-2026-69725 | 7.8 High | Updated |
| 2026-09-22 | CVE-2026-69720 | CVE-2026-69720 | 7.8 High | Updated |
| 2026-09-22 | CVE-2026-69711 | Windows Device Association Service Use-After-Free Lets Authorized Attackers Escalate Privileges Locally | 7.0 High | Updated |
| 2026-09-22 | CVE-2026-69710 | Windows Hello Race Condition Lets Authorized Attackers Escalate Privileges Locally | 7.5 High | Updated |
| 2026-09-22 | CVE-2026-69708 | CVE-2026-69708 | 7.0 High | Updated |
| 2026-09-22 | CVE-2026-69694 | CVE-2026-69694 | 7.0 High | Updated |
| 2026-09-22 | CVE-2026-69693 | CVE-2026-69693 | 7.0 High | Updated |
| 2026-09-22 | CVE-2026-69689 | CVE-2026-69689 | 8.0 High | Updated |
| 2026-09-22 | CVE-2026-69682 | CVE-2026-69682 | 7.0 High | Updated |
| 2026-09-22 | CVE-2026-69654 | CVE-2026-69654 | 7.0 High | Updated |
| 2026-09-22 | CVE-2026-69652 | CVE-2026-69652 | 7.0 High | Updated |
| 2026-09-22 | CVE-2026-31278 | Suprema BioStar 2 Active Directory service account credentials exposed in cleartext via GET request | 7.7 High | Updated |
| 2026-09-21 | CVE-2026-94036 | D-Link DIR-X1860Z Improper Access Control Reachable by Adjacent-Network Attackers | 8.8 High | Updated |
| 2026-09-21 | CVE-2026-93958 | CVE-2026-93958 | 9.1 Critical | Updated |
| 2026-09-21 | CVE-2026-90042 | CVE-2026-90042 | 9.8 Critical | Updated |
| 2026-09-21 | CVE-2026-90041 | CVE-2026-90041 | 8.8 High | Updated |
| 2026-09-21 | CVE-2026-90037 | CVE-2026-90037 | 9.8 Critical | Updated |
| 2026-09-21 | CVE-2026-90036 | CVE-2026-90036 | 9.8 Critical | Updated |
| 2026-09-21 | CVE-2026-89815 | Linux Kernel drm/ttm: Memory Safety Issue Allows Local Privilege Escalation | 7.8 High | Updated |
| 2026-09-21 | CVE-2026-89799 | CVE-2026-89799 | 7.8 High | Updated |
| 2026-09-21 | CVE-2026-89763 | CVE-2026-89763 | 7.8 High | Updated |
| 2026-09-21 | CVE-2026-89755 | CVE-2026-89755 | 7.8 High | Updated |
| 2026-09-21 | CVE-2026-89731 | Linux Kernel cxl/ras: Out-of-Bounds Read Allows Local Privilege Escalation | 7.1 High | Updated |
| 2026-09-21 | CVE-2026-89708 | CVE-2026-89708 | 9.8 Critical | Updated |
| 2026-09-21 | CVE-2026-89685 | CVE-2026-89685 | 7.5 High | Updated |
| 2026-09-21 | CVE-2026-89676 | Linux Kernel nfsd: Reference Count Error Enables Remote Code Execution (CVSS 9.8) | 9.8 Critical | Updated |
| 2026-09-21 | CVE-2026-89667 | CVE-2026-89667 | 8.1 High | Updated |
| 2026-09-21 | CVE-2026-89660 | CVE-2026-89660 | 9.8 Critical | Updated |
| 2026-09-21 | CVE-2026-89659 | CVE-2026-89659 | 9.8 Critical | Updated |
| 2026-09-21 | CVE-2026-89624 | CVE-2026-89624 | 7.8 High | Updated |
| 2026-09-21 | CVE-2026-89622 | CVE-2026-89622 | 7.8 High | Updated |
| 2026-09-21 | CVE-2026-89602 | CVE-2026-89602 | 7.8 High | Updated |
| 2026-09-21 | CVE-2026-89564 | CVE-2026-89564 | 7.8 High | Updated |
| 2026-09-21 | CVE-2026-89561 | CVE-2026-89561 | 7.5 High | Updated |
| 2026-09-21 | CVE-2026-89545 | CVE-2026-89545 | 7.8 High | Updated |
| 2026-09-21 | CVE-2026-89544 | CVE-2026-89544 | 7.5 High | Updated |
| 2026-09-21 | CVE-2026-89535 | CVE-2026-89535 | 8.1 High | Updated |
| 2026-09-21 | CVE-2026-89492 | CVE-2026-89492 | 9.8 Critical | Updated |
| 2026-09-21 | CVE-2026-80945 | CVE-2026-80945 | 9.1 Critical | Updated |
| 2026-09-21 | CVE-2026-80734 | CVE-2026-80734 | 8.8 High | Updated |
| 2026-09-21 | CVE-2026-80685 | CVE-2026-80685 | 7.1 High | Updated |
| 2026-09-21 | CVE-2026-74407 | CVE-2026-74407 | 8.8 High | Updated |
| 2026-09-21 | CVE-2026-74269 | CVE-2026-74269 | 9.8 Critical | Updated |
| 2026-09-21 | CVE-2026-72989 | CVE-2026-72989 | 7.5 High | Updated |
| 2026-09-21 | CVE-2026-72962 | CVE-2026-72962 | 8.2 High | Updated |
| 2026-09-21 | CVE-2026-72961 | CVE-2026-72961 | 8.2 High | Updated |
| 2026-09-21 | CVE-2026-72960 | CVE-2026-72960 | 8.8 High | Updated |
| 2026-09-21 | CVE-2026-72958 | CVE-2026-72958 | 8.2 High | Updated |
| 2026-09-21 | CVE-2026-72953 | CVE-2026-72953 | 7.8 High | Updated |
| 2026-09-21 | CVE-2026-72952 | CVE-2026-72952 | 7.0 High | Updated |
| 2026-09-21 | CVE-2026-72949 | CVE-2026-72949 | 7.5 High | Updated |
| 2026-09-21 | CVE-2026-72494 | CVE-2026-72494 | 9.8 Critical | Updated |
| 2026-09-21 | CVE-2026-72438 | CVE-2026-72438 | 7.5 High | Updated |
| 2026-09-21 | CVE-2026-72355 | CVE-2026-72355 | 9.8 Critical | Updated |
| 2026-09-21 | CVE-2026-71226 | CVE-2026-71226 | 7.3 High | Updated |
| 2026-09-21 | CVE-2026-69648 | CVE-2026-69648 | 7.0 High | Updated |
| 2026-09-21 | CVE-2026-69625 | CVE-2026-69625 | 8.0 High | Updated |
| 2026-09-21 | CVE-2026-69617 | CVE-2026-69617 | 7.0 High | Updated |
| 2026-09-21 | CVE-2026-69606 | CVE-2026-69606 | 7.0 High | Updated |
| 2026-09-21 | CVE-2026-69602 | CVE-2026-69602 | 7.1 High | Updated |
| 2026-09-21 | CVE-2026-69597 | CVE-2026-69597 | 7.1 High | Updated |
| 2026-09-21 | CVE-2026-69586 | CVE-2026-69586 | 9.8 Critical | Updated |
| 2026-09-21 | CVE-2026-69575 | CVE-2026-69575 | 7.0 High | Updated |
| 2026-09-21 | CVE-2026-54230 | CVE-2026-54230 | 7.0 High | Updated |
| 2026-09-20 | CVE-2026-87886 | Acronis Backup's Incorrect Default Permissions Allow a Local Attacker to Access Backup Files and Configurations Not Intended for Their Account; CISA's September 19th KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-20 | CVE-2026-84869 | ConnectWise ScreenConnect's Improper Privilege Management and Missing Authorization Allow Unauthenticated Attackers to Gain Administrative Control of the Remote Support Platform; CISA's September 14th KEV Deadline Has Passed | 9.9 Critical | KEV |
| 2026-09-20 | CVE-2026-81963 | Windows Update Stack Symbolic Link Following Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8) | 7.8 High | KEV |
| 2026-09-20 | CVE-2026-67277 | MikroTik RouterOS's Missing Authentication for a Critical Function Allows Unauthenticated Attackers to Access and Modify Router Configuration; CISA's September 13th KEV Deadline Has Passed | 8.2 High | KEV |
| 2026-09-20 | CVE-2026-53362 | Linux Kernel's Unspecified Flaw Allows Local Attackers to Gain Elevated Privileges on Affected Systems; CISA's August 30th KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-20 | CVE-2026-53266 | Linux Kernel's Out-of-Bounds Write Vulnerability Allows Local Attackers to Escalate Privileges or Cause a Kernel Crash; CISA's September 21st KEV Deadline Has Passed | 8.8 High | KEV |
| 2026-09-20 | CVE-2026-50516 | Microsoft Azure Kubernetes Service's Missing Authentication on a Critical Function Allows Unauthenticated Attackers to Interact with Privileged Cluster Management Endpoints | 9.4 Critical | Updated |
| 2026-09-20 | CVE-2026-20349 | Cisco Secure Firewall ASA and FTD's Heap Inspection Vulnerability Allows Remote Attackers to Extract Sensitive Memory Contents from the Firewall Device; CISA's August 14th KEV Deadline Has Passed | 8.6 High | KEV |
| 2026-09-20 | CVE-2026-20301 | Cisco IOS XE's Unchecked Loop Condition Input Allows Network-Accessible Devices to Be Crashed via a Specially Crafted Packet | 8.6 High | Exploited |
| 2026-09-20 | CVE-2026-20124 | Cisco IOS XE's Memory Resource Leak Allows Remote Attackers to Exhaust Device Memory and Cause a Denial of Service via Repeated Packet Transmission | 7.7 High | Exploited |
| 2026-09-20 | CVE-2026-72530 | TrueConf Server's Code Injection Vulnerability Allows Remote Attackers to Execute Arbitrary Code on the Video Conferencing Platform; CISA's September 3rd KEV Deadline Has Passed | 9.0 Critical | KEV |
| 2026-09-20 | CVE-2026-72529 | TrueConf Server's Missing Authentication on a Critical Function Allows Unauthenticated Remote Attackers to Access Administrative Capabilities; CISA's August 23rd KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-18 | CVE-2026-87491 | Google Chromium V8's Out-of-Bounds Write Allows Remote Attackers to Corrupt the JavaScript Engine's Heap and Execute Arbitrary Code via a Crafted Web Page | 8.8 High | KEV |
| 2026-09-18 | CVE-2026-59822 | BerriAI LiteLLM's Improper Authentication Allows Unauthenticated Attackers to Access the AI Model Gateway and Interact with Configured LLM Endpoints Without Credentials | 8.2 High | KEV |
| 2026-09-18 | CVE-2026-58704 | Google Pixel's Improper Authorization Flaw Allows an Attacker with Physical or Local Access to Bypass Permission Controls and Access Protected Device Functions | 8.8 High | KEV |
| 2026-09-18 | CVE-2026-49869 | Kestra OSS's OS Command Injection Flaw Lets Unauthenticated Remote Attackers Execute Arbitrary Commands on the Workflow Orchestration Server with Full System Privileges | 10.0 Critical | KEV |
| 2026-09-18 | CVE-2026-27563 | Crafted GET Request to the Datastorage API Lets Admin Credentials Trigger Root Command Execution on Pepperl+Fuchs ICE-Series IO-Link Masters | 7.2 High | Updated |
| 2026-09-18 | CVE-2026-27558 | Operator Access to the IODD File Removal Endpoint on Pepperl+Fuchs ICE-Series IO-Link Masters Allows Root Command Injection | 8.8 High | Updated |
| 2026-09-18 | CVE-2026-27548 | Command Injection in the IODD Port Info Endpoint Grants Root Access on Pepperl+Fuchs ICE-Series IO-Link Masters to Any User or Operator Account | 8.8 High | Updated |
| 2026-09-16 | CVE-2026-27565 | Unauthenticated IODD File Upload on Pepperl+Fuchs ICE-Series IO-Link Masters Executes a Root Shell Script That Persists Across Reboots | 9.8 Critical | Updated |
| 2026-09-16 | CVE-2026-27564 | Pepperl+Fuchs ICE-Series IO-Link Masters Run Injected Root Commands When Admin Credentials Submit a Crafted PUT Request to the Datastorage API | 7.2 High | Updated |
| 2026-09-16 | CVE-2026-27562 | Admin-Level PUT Requests to the IODD Configuration API Execute Injected Commands as Root on Pepperl+Fuchs ICE-Series IO-Link Masters | 7.2 High | Updated |
| 2026-09-16 | CVE-2026-27561 | Admin Credentials Enable Root Command Injection via the IODD Config GET API on Pepperl+Fuchs ICE-Series IO-Link Masters | 7.2 High | Updated |
| 2026-09-16 | CVE-2026-27560 | Admin-Credentialed DELETE Requests to Pepperl+Fuchs ICE-Series IO-Link Masters' Status API Carry Injected Commands Executed at Root | 7.2 High | Updated |
| 2026-09-16 | CVE-2026-27559 | User Credentials Are Enough to Inject Root-Level Commands via the Status Data API on Pepperl+Fuchs ICE-Series IO-Link Masters | 8.8 High | Updated |
| 2026-09-16 | CVE-2026-27557 | Unauthenticated Path Traversal in Pepperl+Fuchs ICE-Series IO-Link Masters Exposes the Device's SSH Server Private Keys | 7.5 High | Updated |
| 2026-09-16 | CVE-2026-27556 | Operator Cookie Enables Arbitrary PHP Code Execution on Pepperl+Fuchs ICE-Series IO-Link Masters via Local File Inclusion in the IODD Parameter Save Endpoint | 8.8 High | Updated |
| 2026-09-16 | CVE-2026-27555 | A Valid User Cookie Triggers Arbitrary PHP Code Execution on Pepperl+Fuchs ICE-Series IO-Link Masters via Local File Inclusion in the IODD Port Info Endpoint | 8.8 High | Updated |
| 2026-09-16 | CVE-2026-27554 | IODD Parameter Save Endpoint on Pepperl+Fuchs ICE-Series IO-Link Masters Accepts Injected Commands from Operator-Level Accounts, Yielding Root Access | 8.8 High | Updated |
| 2026-09-16 | CVE-2026-27552 | Pepperl+Fuchs ICE-Series IO-Link Masters Allow Low-Privileged Users to Upload Arbitrary IODD Files via a Missing Authorization Check, Enabling Device Manipulation or Crashes | 8.1 High | Updated |
| 2026-09-16 | CVE-2026-27551 | User-Level Credentials Give Root Shell on Pepperl+Fuchs ICE-Series IO-Link Masters via the Parameter Management Endpoint | 8.8 High | Updated |
| 2026-09-16 | CVE-2026-27550 | Operator Credentials Can Inject Root-Level OS Commands via the Field_Shadow_Password Handler on Pepperl+Fuchs ICE-Series IO-Link Masters | 8.8 High | Updated |
| 2026-09-16 | CVE-2026-27549 | Operator-Level Credentials Suffice to Run Root Commands on Pepperl+Fuchs ICE-Series IO-Link Masters via the IODD Upload Endpoint | 8.8 High | Updated |
| 2026-09-16 | CVE-2026-27547 | IODD Menu Info Request on Pepperl+Fuchs ICE-Series IO-Link Masters Passes Unvalidated Parameters to Root-Level Commands, Reachable with User-Level Credentials | 8.8 High | Updated |
| 2026-09-16 | CVE-2026-27546 | The _account_log Function in Pepperl+Fuchs ICE-Series IO-Link Masters Lets Unauthenticated Attackers Log In as Admin Regardless of Account Configuration | 9.8 Critical | Updated |
| 2026-09-11 | CVE-2026-63298 | LXD NVIDIA Instance Configuration Handler Accepts Newline Characters in nvidia.driver.capabilities and nvidia.require.* Values, Letting Authenticated Attackers Inject Arbitrary Directives into the GPU Configuration | 9.9 Critical | Updated |
| 2026-09-10 | CVE-2026-32589 | Red Hat Quay authenticated push access enables interference with other users' in-progress image uploads across repositories | 7.4 High | Updated |
| 2026-08-13 | CVE-2026-64125 | Linux Kernel bcmgenet Driver Enabling RBUF EEE and PM Bits Stops RX Traffic When MAC EEE Activates, Causing a Denial-of-Service Condition on Broadcom GENET Hardware | 9.8 Critical | Updated |
| 2026-07-28 | CVE-2026-16812 | Arista VeloCloud Orchestrator On-Prem Management Plane Executes Injected OS Commands; CISA's July 30th KEV Deadline Has Passed for Covered Entities | 10.0 Critical | KEV |
| 2026-07-24 | CVE-2026-31405 | Linux Kernel DVB-net ULE Extension Handler Uses a Network-Controlled Index into a 255-Entry Table Without Bounds Checking, Enabling Out-of-Bounds Reads and Writes | 9.8 Critical | Updated |
| 2026-07-24 | CVE-2026-23458 | Linux kernel ctnetlink multi-round dump dereferences freed conntrack pointer in second callback invocation | 7.8 High | Updated |
| 2026-07-24 | CVE-2026-23450 | Linux Kernel SMC-over-TCP SYN Receive Path Calls sock_hold Then Schedules a tcp_close Work Item Without Synchronizing Against Concurrent Stack Cleanup, Enabling Use-After-Free and Null Dereference | 9.8 Critical | Updated |
| 2026-07-24 | CVE-2026-23419 | Linux kernel rds_tcp_tune circular locking dependency causes deadlock via sk_net_refcnt_upgrade | 7.5 High | Updated |
| 2026-07-23 | CVE-2026-54420 | LiteSpeed's cPanel Plugin Follows Symlinks Across Security Boundaries to Escalate Privileges; CISA's June 18th KEV Remediation Window Has Closed for Covered Entities | 8.5 High | KEV |
| 2026-07-23 | CVE-2026-42542 | CVE-2026-42542 | 7.5 High | Updated |
| 2026-07-15 | CVE-2026-56155 | Microsoft Active Directory Federation Services Insufficient Access Control Allows an Authorized Attacker to Elevate Privileges Locally; CISA's July 28th KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-07-14 | CVE-2026-31446 | Linux kernel ext4 use-after-free in update_super_work races with unmount after sysfs unregistration | 7.8 High | Updated |
| 2026-07-08 | CVE-2026-46279 | Linux Kernel Page Extension Initialization Leaves Codetag Uninitialized for Pages Allocated Before page_ext Is Ready | 7.8 High | Updated |
| 2026-07-02 | CVE-2026-53225 | Linux Kernel SCTP ASCONF Lookup Reads Past the Validated Header Boundary, Exposing Uninitialized Memory to Downstream Address Parameter Processing | 9.1 Critical | Updated |
| 2026-06-17 | CVE-2026-8398 | Daemon Tools Lite Contains Embedded Malicious Code; CISA Added It to KEV with a May 30th Deadline That Has Since Passed for Covered Entities | 9.8 Critical | KEV |
| 2026-06-17 | CVE-2026-7473 | Arista Extensible Operating System Validation Bypass Added to CISA's Known Exploited Vulnerabilities List; Federal Remediation Window for Covered Entities Closed June 23rd | 5.8 Medium | KEV |
| 2026-06-17 | CVE-2026-48027 | Nx Console Developer Tooling Published Packages Contain Embedded Malicious Code; CISA's June 10th KEV Mandate for Covered Entities Has Passed | 9.8 Critical | KEV |
| 2026-06-17 | CVE-2026-45321 | TanStack JavaScript Library Suite Added to CISA's Known Exploited Vulnerabilities Catalog; Federal Remediation Deadline for Covered Entities Was June 10th | 9.6 Critical | KEV |
| 2026-06-17 | CVE-2026-43296 | Linux Kernel octeontx2-af NIC SQ Manager Sticky Mode Causes Stalls and Potential PSE Deadlock When Multiple Queues Share an SMQ | 7.5 High | Updated |
| 2026-06-17 | CVE-2026-4116 | SonicWall SMA1000 Mishandles Unicode Encoding in TOTP Validation, Allowing an Authenticated SSLVPN User to Bypass Two-Factor Authentication | 7.2 High | Updated |
| 2026-06-17 | CVE-2026-4113 | SonicWall SMA1000 Distinguishable Authentication Error Responses Allow a Remote Attacker to Enumerate SSL VPN User Accounts | 7.2 High | Updated |
| 2026-06-17 | CVE-2026-4112 | SonicWall SMA1000 SQL Injection in the SSLVPN Component Allows a Read-Only Administrator to Escalate to Primary Administrator | 7.2 High | Updated |
| 2026-06-17 | CVE-2026-31693 | Linux kernel CIFS replay path missing variable reinitializations causes undefined behavior on request retry | 7.8 High | Updated |
| 2026-06-17 | CVE-2026-31568 | Linux kernel s390/mm missing secure storage access fixups for donated pages causes kernel context exceptions | 7.1 High | Updated |
| 2026-06-17 | CVE-2026-31426 | Linux kernel ACPI EC address space handler persists after probe failure leaves dangling pointer | 7.0 High | Updated |
| 2026-06-17 | CVE-2026-23406 | Linux kernel AppArmor match_char macro evaluates pointer multiple times and skips input characters during DFA traversal | 7.8 High | Updated |
| 2026-06-17 | CVE-2026-1952 | Delta Electronics AS320T Denial of Service via Undocumented Subfunction Call, Exploitable Remotely Without Authentication | 9.8 Critical | Updated |
| 2026-06-17 | CVE-2026-1951 | Delta Electronics AS320T Stack-Based Buffer Overflow Due to Missing Directory Name Length Check, Enabling Unauthenticated Remote Code Execution | 9.8 Critical | Updated |
| 2026-06-17 | CVE-2026-1950 | Delta Electronics AS320T Stack-Based Buffer Overflow Due to Missing File Name Length Check, Enabling Unauthenticated Remote Code Execution | 9.8 Critical | Updated |
| 2026-06-17 | CVE-2026-1949 | Delta Electronics AS320T GET/PUT Request Handler Incorrectly Calculates Stack Buffer Size, Enabling Unauthenticated Remote Code Execution via the Web Service | 9.8 Critical | Updated |