Articles tagged KEV
-
NewsExploited Zammad helpdesk chain runs from session hijack to root
CISA added two chained Zammad flaws to its KEV catalog: a session hijack giving code execution and a local root escalation, with a 5 October federal deadline.
-
NewsExploited FortiMail flaw lets attackers write files with no fix out yet
CISA added an unauthenticated FortiMail path traversal to its KEV catalog with a three-day deadline and a compromise check, while fixed builds are still pending.
-
NewsApple CoreGraphics zero-day exploited in targeted attacks, CISA says
CISA added an Apple CoreGraphics memory flaw to its KEV catalog after reports of targeted attacks, with a 2 October deadline and forensic triage for iOS and macOS.
-
NewsExploited Cisco SD-WAN Manager flaw gives attackers admin API access
CISA added a critical Cisco Catalyst SD-WAN Manager authentication bypass to its KEV catalog with a three-day federal deadline and a required compromise check.
-
NewsTwo Citrix NetScaler zero-days under active attack, CISA and NCSC warn
CISA and the UK NCSC confirm attackers are exploiting two critical NetScaler ADC and Gateway flaws as zero-days. Check for compromise, then patch by 30 September.
-
NewsCISA confirms exploitation of SharePoint and MikroTik RouterOS flaws
CISA added a SharePoint code injection flaw and a MikroTik RouterOS SSH bug that completes a known router takeover chain to KEV, with a 28 September deadline.
-
NewsCISA flags six exploited flaws in VPN, SD-WAN and commerce platforms
CISA added six actively exploited CVEs in Check Point, F5 BIG-IP APM, Arista VeloCloud, WSO2 and Adobe Commerce to KEV this week, with deadlines of 25 and 27 September.
-
NewsCISA confirms attacks on WordPress core file inclusion flaw
CISA added a WordPress core file inclusion bug that can lead to code execution to its KEV catalog, set a three-day federal deadline and required forensic triage.
-
VulnerabilityArista VeloCloud OrchestratorOn-Prem Input Validation Flaw (CVE-2026-93952)
CVE-2026-93952 is a CVSS 10.0 input-validation flaw in on-prem Arista VeloCloud Orchestrator, added to CISA's KEV catalog as exploited on September 22, 2026.
-
Vulnerability2 CVEs: Check Point Quantum Security Gateway & Check Point Quantum Security Management (CVE-2026-85102)
Two CVSS 9.8 Check Point flaws, a VPN-negotiation RCE in Quantum Security Gateway and a pre-auth upload bug in Management, were CISA KEV-listed September 22.
-
VulnerabilityF5 BIG-IP APM Vulnerability (CVE-2026-94127)
CVE-2026-94127 is a CVSS 9.8 heap overflow in F5 BIG-IP APM enabling unauthenticated RCE when APM acts as an OAuth Authorization Server; CISA KEV-listed.
-
VulnerabilityACPT- Custom Post Types Plugin for WordPress Privilege Escalation (CVE-2026-32566)
CVE-2026-32566 is a CVSS 9.8 unauthenticated privilege escalation flaw in the ACPT Pro WordPress plugin, reported exploited by VulnCheck KEV.
-
VulnerabilityAcronis Backup plugin for cPanel & WHM Privilege Escalation (CVE-2026-87886)
CVE-2026-87886 is a CVSS 7.8 local privilege escalation in Acronis Backup control-panel plugins, confirmed exploited per CISA KEV.
-
VulnerabilityAcyMailing SMTP Newsletter SQL Injection (CVE-2026-57739)
CVE-2026-57739 is a CVSS 9.3 blind SQL injection flaw in the AcyMailing WordPress newsletter plugin, reported exploited by VulnCheck KEV.
-
VulnerabilityAdobe Commerce Privilege Escalation (CVE-2026-71362)
CVE-2026-71362 is a CVSS 9.1 incorrect authorization flaw in Adobe Commerce enabling privilege escalation, reported exploited by VulnCheck KEV.
-
VulnerabilityAffiliate Pro - Affiliate Program for WooCommerce & WordPress Privilege Escalation (CVE-2026-32558)
CVE-2026-32558 is a CVSS 9.8 unauthenticated privilege escalation flaw in the Affiliate Pro WordPress plugin, reported exploited by VulnCheck KEV.
-
VulnerabilityAjax.NET Professional Insecure Deserialization (CVE-2021-23758)
CVE-2021-23758 is a 2021 CVSS 8.1 deserialization RCE in Ajax.NET Professional, added to CISA KEV in August 2026.
-
VulnerabilityAmelia Privilege Escalation (CVE-2026-9055)
CVE-2026-9055 is a CVSS 9.8 flaw in the Amelia WordPress plugin allowing account takeover via password overwrite, reported exploited by VulnCheck.
-
VulnerabilityCheck Point Quantum Security Gateway Vulnerability (CVE-2026-50752)
CVE-2026-50752 is a CVSS 7.4 certificate-validation flaw in Check Point VPN gateways, reported exploited by VulnCheck alone.
-
VulnerabilityCKAN SQL Injection (CVE-2026-42031)
CVE-2026-42031 is a CVSS 9.8 SQL injection flaw in the datastore_search_sql API of open-source data portal platform CKAN, reported exploited by VulnCheck KEV.
-
VulnerabilityD-Link DIR-882 Vulnerability (CVE-2025-60698)
CVE-2025-60698 is a CVSS 7.3 unauthenticated command injection in D-Link DIR-882 router firmware, per VulnCheck alone.
-
VulnerabilityDify Path Traversal (CVE-2026-41948)
CVE-2026-41948 is a CVSS 9.4 path traversal flaw in Dify allowing cross-tenant access to internal debug endpoints, reported exploited by VulnCheck.
-
VulnerabilityDivi Ajax Filter Vulnerability (CVE-2026-11613)
CVE-2026-11613 is a CVSS 9.8 local file inclusion flaw in the Divi Ajax Filter WordPress plugin through 5.1.2, reported exploited by VulnCheck's KEV catalog.
-
VulnerabilityDolibarr ERP/CRM Vulnerability (CVE-2026-89013)
CVE-2026-89013 is a CVSS 7.5 unauthenticated authorization bypass in Dolibarr document endpoints, per VulnCheck alone.
-
VulnerabilityDrag and Drop Multiple File Upload for Contact Form 7 Code Injection (CVE-2026-18781)
CVE-2026-18781 is a CVSS 8.1 code injection in a Contact Form 7 WordPress add-on, reported exploited by VulnCheck alone.
-
VulnerabilityRed Hat OpenShift AI— Feast Feature Server Path Traversal (CVE-2026-23536)
CVE-2026-23536 is a CVSS 7.5 unauthenticated path traversal in the Feast Feature Server shipped with Red Hat OpenShift AI.
-
VulnerabilityFlowise Code Injection (CVE-2026-69255)
CVE-2026-69255 is a CVSS 8.8 code injection flaw in Flowise letting authenticated attackers run OS commands as root, reported exploited by VulnCheck.
-
VulnerabilityFooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel Vulnerability (CVE-2025-6068)
CVE-2025-6068 is a CVSS 6.4 stored XSS in the FooGallery WordPress plugin, exploitable by Contributor-level accounts, per VulnCheck alone.
-
VulnerabilityGeoDirectory SQL Injection (CVE-2026-84813)
CVE-2026-84813 is a CVSS 9.3 unauthenticated SQL injection flaw in the GeoDirectory WordPress plugin, reported exploited by VulnCheck KEV.
-
VulnerabilityGeoNetwork opensource Vulnerability (CVE-2026-63219)
CVE-2026-63219 is a CVSS 8.6 missing-authorization flaw letting unauthenticated attackers write files into GeoNetwork, per VulnCheck.
-
VulnerabilityGeoNetwork Code Injection (CVE-2026-58400)
CVE-2026-58400 is a CVSS 9.1 code injection flaw in GeoNetwork via unsecured XSLT processing, fixed in 4.4.12/4.2.17, reported exploited by VulnCheck.
-
VulnerabilityGeoTools SQL Injection (CVE-2026-76904)
CVE-2026-76904 is a CVSS 9.8 SQL injection flaw in GeoTools PostGIS integration via jsonArrayContains, reported exploited by VulnCheck KEV.
-
VulnerabilityGitea Code Injection (CVE-2026-60004)
CVE-2026-60004 is a CVSS 9.8 code injection flaw in Gitea allowing RCE via the diffpatch API, confirmed exploited by both CISA and VulnCheck KEV.
-
VulnerabilityGoogle Pixel Privilege Escalation (CVE-2026-58704)
CVE-2026-58704 is a CVSS 8.8 permission bypass in the Pixel cellular modem, confirmed exploited per CISA and VulnCheck KEV.
-
VulnerabilityGravity Forms Vulnerability (CVE-2026-84434)
CVE-2026-84434 is an unauthenticated arbitrary file upload flaw in the Gravity Forms WordPress plugin, per VulnCheck alone.
-
VulnerabilityHUSKY – Products Filter Professional for WooCommerce Vulnerability (CVE-2026-18562)
CVE-2026-18562 is a CVSS 6.1 reflected XSS in the HUSKY Products Filter plugin for WooCommerce, per VulnCheck alone.
-
VulnerabilityJetFormBuilder Privilege Escalation (CVE-2026-54196)
CVE-2026-54196 is a CVSS 6.8 privilege escalation in the JetFormBuilder WordPress plugin, per VulnCheck alone.
-
VulnerabilityJFrog Artifactory Path Traversal (CVE-2026-66384)
CVE-2026-66384 is a CVSS 5.3 path traversal in JFrog Artifactory affecting the Docker cache, confirmed exploited per CISA KEV.
-
VulnerabilityKGUARD DVR devices Vulnerability (CVE-2026-87827)
CVE-2026-87827 is an unauthenticated command execution flaw in KGUARD DVR devices, exploited by Mirai-family botnets since 2016.
-
VulnerabilityKirki Vulnerability (CVE-2026-16747)
CVE-2026-16747 is a CVSS 6.5 unauthenticated shortcode-injection flaw in the Kirki WordPress plugin, per VulnCheck alone.
-
Vulnerabilityknowns Path Traversal (CVE-2026-86538)
CVE-2026-86538 is a CVSS 7.5 unauthenticated path traversal in the knowns application, reported exploited by VulnCheck alone.
-
VulnerabilityKopia Command Injection (CVE-2026-45695)
CVE-2026-45695 is a CVSS 9.8 OS command injection flaw enabling unauthenticated RCE in the Kopia backup tool before 0.23.0, reported exploited by VulnCheck KEV.
-
VulnerabilityLangflow Code Injection (CVE-2026-0768)
CVE-2026-0768 is a CVSS 9.8 code injection flaw in Langflow allowing unauthenticated remote code execution as root, reported exploited by VulnCheck KEV.
-
VulnerabilityLinux Kernel Vulnerability (CVE-2026-53362)
CVE-2026-53362 is a CVSS 7.8 Linux kernel memory-corruption flaw in IPv6 UDP fragment handling, confirmed exploited per CISA KEV.
-
VulnerabilityLinux Kernel Vulnerability (CVE-2026-43494)
CVE-2026-43494 is a CVSS 7.8 Linux kernel double-free in the RDS networking subsystem, reported exploited by VulnCheck alone.
-
VulnerabilityLinux Kernel Vulnerability (CVE-2026-46331)
CVE-2026-46331 is a CVSS 7.8 integer-overflow flaw in the Linux kernel packet-editing traffic control action, per VulnCheck.
-
VulnerabilityLinux Kernel Privilege Escalation (CVE-2026-31635)
CVE-2026-31635 is a CVSS 7.5 Linux kernel flaw in the rxrpc/rxgk network protocol, reported exploited by VulnCheck alone.
-
VulnerabilityLinux Kernel Out-of-Bounds Write (CVE-2022-0995)
CVE-2022-0995 is a 2022 CVSS 7.8 out-of-bounds write in the Linux kernel watch_queue subsystem, added to CISA KEV in August 2026.
-
VulnerabilityMail Mint Vulnerability (CVE-2026-84755)
CVE-2026-84755 is a CVSS 6.5 unauthenticated broken access control in the Mail Mint WordPress plugin, per VulnCheck alone.
-
VulnerabilityMailgun for WordPress SSRF (CVE-2026-78003)
CVE-2026-78003 is a CVSS 9.8 SSRF flaw in Mailgun for WordPress enabling admin takeover via intercepted password resets, reported exploited by VulnCheck.
-
VulnerabilityMicrosoft SharePoint Input Validation Flaw (CVE-2026-63520)
CVE-2026-63520 is a CVSS 8.1 improper input validation flaw in Microsoft SharePoint, reported exploited by VulnCheck alone.
-
VulnerabilityMicrosoft SQL Server Vulnerability (CVE-2019-1068)
CVE-2019-1068 is a 2019 CVSS 8.8 remote code execution flaw in Microsoft SQL Server, added to CISA KEV in August 2026 for newly observed exploitation.
-
VulnerabilityMikroTik RouterOS Vulnerability (CVE-2026-67276)
CVE-2026-67276 is an incomplete SSH public-key signature verification flaw in MikroTik RouterOS, publicly exploited per VulnCheck.
-
VulnerabilityMiniOrange SAML SP Single Sign On Privilege Escalation (CVE-2026-61979)
CVE-2026-61979 is a CVSS 8.1 unauthenticated privilege escalation in a WordPress SAML SSO plugin, per VulnCheck alone.
-
VulnerabilitySAML Single Sign On – SSO Login Authentication Bypass (CVE-2026-15981)
CVE-2026-15981 is a CVSS 9.8 authentication bypass in the MiniOrange SAML SSO WordPress plugin allowing login as any user, reported exploited by VulnCheck.
-
VulnerabilityMLflow Path Traversal (CVE-2026-2614)
CVE-2026-2614 is a CVSS 7.5 unauthenticated path traversal in MLflow model registry, reported exploited by VulnCheck alone.
-
VulnerabilityMonsta FTP SSRF (CVE-2026-60105)
CVE-2026-60105 is a CVSS 8.6 SSRF in Monsta FTP via an IP-blocklist bypass, reported exploited by VulnCheck alone.
-
VulnerabilityN-able N-central Access Control Flaw (CVE-2026-86206)
CVE-2026-86206 is an internal API access-control bypass in N-able N-central RMM software, per VulnCheck alone.
-
VulnerabilityN-able N-central Authentication Bypass (CVE-2026-86207)
CVE-2026-86207 is an authentication bypass affecting internal APIs in N-able N-central RMM software, per VulnCheck alone.
-
VulnerabilityNewfold WP Plugin Web Authentication Bypass (CVE-2026-80099)
CVE-2026-80099 is a CVSS 8.8 authentication bypass in Newfold WordPress plugins, reported exploited by VulnCheck alone.
-
VulnerabilityOPSWAT AppRemover Driverv2017.10.02.1551 and earlier Privilege Escalation (CVE-2026-36425)
CVE-2026-36425 is a CVSS 6.5 improper privilege management flaw in the OPSWAT AppRemover kernel driver, per VulnCheck alone.
-
VulnerabilityownCloud Authentication Bypass (CVE-2023-49105)
CVE-2023-49105 is a CVSS 9.8 authentication bypass in ownCloud core allowing unauthenticated file access via pre-signed URLs, confirmed exploited per CISA KEV.
-
VulnerabilityEvents Manager Privilege Escalation (CVE-2026-18366)
CVE-2026-18366 is a CVSS 9.8 flaw in the Events Manager WordPress plugin allowing unauthenticated Administrator takeover, reported exploited by VulnCheck.
-
VulnerabilityProfilePress Vulnerability (CVE-2026-66047)
CVE-2026-66047 is a CVSS 8.1 unauthenticated RCE in the ProfilePress WordPress plugin, reported exploited by VulnCheck alone.
-
VulnerabilityRuby on Rails / Action Pack Vulnerability (CVE-2026-66066)
CVE-2026-66066 is an unauthenticated arbitrary file read in Rails Active Storage via unsafe libvips operations, per VulnCheck.
-
VulnerabilityAutomatic Bug Reporting Tool Privilege Escalation (CVE-2015-5287)
CVE-2015-5287 is a 2015 CVSS 7.8 symlink privilege escalation in Red Hat ABRT, added to CISA KEV in August 2026.
-
VulnerabilityRed Hat Build of Keycloak Authentication Bypass (CVE-2026-18963)
CVE-2026-18963 is a CVSS 9.1 flaw in Red Hat Build of Keycloak letting attackers force password resets without email verification, per VulnCheck.
-
Vulnerabilitylibuser Vulnerability (CVE-2015-3246)
CVE-2015-3246 is a CVSS 5.1 race condition in libuser affecting /etc/passwd, confirmed exploited per CISA KEV.
-
VulnerabilityShenzhen Aitemi E Commerce Co., Ltd. Command Injection (CVE-2026-58457)
CVE-2026-58457 is a CVSS 9.8 unauthenticated command injection flaw in the Shenzhen Aitemi M300 Wi-Fi repeater, reported exploited by VulnCheck.
-
VulnerabilitySogou Input Method Code Execution (CVE-2026-51990)
CVE-2026-51990 is a CVSS 9.8 remote code execution flaw in the biz_helper component of Sogou Input Method, reported exploited by VulnCheck KEV.
-
VulnerabilitySPIP Code Injection (CVE-2026-77806)
CVE-2026-77806 is a CVSS 9.8 code injection flaw in the SPIP CMS allowing unauthenticated RCE, with NVD itself noting exploitation in the wild.
-
VulnerabilityStarlette Vulnerability (CVE-2026-48710)
CVE-2026-48710 is a CVSS 6.5 Host-header request smuggling flaw in the Starlette ASGI framework, confirmed exploited per CISA KEV.
-
VulnerabilityThe Events Calendar Code Injection (CVE-2026-78159)
CVE-2026-78159 is a CVSS 9.8 code injection flaw enabling unauthenticated RCE in WordPress plugin The Events Calendar, reported exploited by VulnCheck KEV.
-
VulnerabilityThe Events Calendar Insecure Deserialization (CVE-2026-78006)
CVE-2026-78006 is a CVSS 9.8 deserialization flaw enabling unauthenticated RCE in WordPress plugin The Events Calendar, reported exploited by VulnCheck KEV.
-
VulnerabilityTelesquare TLR-2005KSH Vulnerability (CVE-2025-9603)
CVE-2025-9603 is a CVSS 6.3 command injection in Telesquare TLR-2005KSH router firmware, publicly exploited per VulnCheck.
-
VulnerabilityTenda CH22 Vulnerability (CVE-2026-78141)
CVE-2026-78141 is a CVSS 7.4 command injection in the Tenda CH22 router firmware, with a public exploit per NVD.
-
VulnerabilityTenda CH22 Vulnerability (CVE-2026-5153)
CVE-2026-5153 is a CVSS 6.3 command injection in Tenda CH22 router firmware, publicly exploited per VulnCheck.
-
VulnerabilityTOTOLINK A7000R Vulnerability (CVE-2026-1547)
CVE-2026-1547 is a CVSS 6.3 command injection in TOTOLINK A7000R router firmware, publicly exploited per VulnCheck.
-
VulnerabilityTOTOLINK A950RG Vulnerability (CVE-2025-60702)
CVE-2025-60702 is a CVSS 6.5 unauthenticated command injection in TOTOLINK A950RG router firmware, per VulnCheck alone.
-
VulnerabilityTOTOLINK LR1200GB Vulnerability (CVE-2025-60687)
CVE-2025-60687 is a CVSS 6.5 unauthenticated command injection in TOTOLINK LR1200GB router firmware, per VulnCheck alone.
-
VulnerabilityTranslatePress – Translate Multilingual sites with AI Translation Vulnerability (CVE-2026-75981)
CVE-2026-75981 is a CVSS 7.2 unauthenticated stored XSS in the TranslatePress WordPress plugin, per VulnCheck alone.
-
VulnerabilityTranslatePress – Translate Multilingual sites with AI Translation Vulnerability (CVE-2026-19632)
CVE-2026-19632 is a CVSS 9.8 flaw in the TranslatePress WordPress plugin exposing admin password-reset URLs, reported exploited by VulnCheck.
-
VulnerabilityTutor LMS – eLearning and online course solution Code Execution (CVE-2026-16759)
CVE-2026-16759 is a CVSS 6.5 unauthenticated remote code execution flaw in the Tutor LMS WordPress plugin, per VulnCheck alone.
-
VulnerabilityTYPO3 Extension "powermail" Vulnerability (CVE-2026-77136)
CVE-2026-77136 is an unauthenticated server-side template injection flaw in the TYPO3 Powermail extension, actively exploited per VulnCheck.
-
VulnerabilityvBulletin Vulnerability (CVE-2026-61511)
CVE-2026-61511 is a CVSS 9.8 eval injection flaw in vBulletin allowing unauthenticated RCE, reported exploited by VulnCheck with a near-maximum EPSS score.
-
VulnerabilityVite Path Traversal (CVE-2026-39364)
CVE-2026-39364 is a CVSS 7.5 file-restriction bypass in the Vite dev server, reported exploited by VulnCheck alone.
-
VulnerabilityCustom User Registration Fields for WooCommerce Privilege Escalation (CVE-2026-15369)
CVE-2026-15369 is a CVSS 9.8 flaw in a WooCommerce checkout plugin allowing unauthenticated Administrator account creation, reported exploited by VulnCheck.
-
VulnerabilityWooCommerce Lottery SQL Injection (CVE-2026-18884)
CVE-2026-18884 is a CVSS 7.5 unauthenticated SQL injection in the WooCommerce Lottery WordPress plugin, per VulnCheck alone.
-
VulnerabilityGift Cards For WooCommerce Pro Vulnerability (CVE-2026-15039)
CVE-2026-15039 is a CVSS 9.8 unrestricted file upload flaw in a WooCommerce gift-card plugin allowing unauthenticated RCE, reported exploited by VulnCheck.
-
VulnerabilityWPMU DEV Dashboard Authentication Bypass (CVE-2026-76581)
CVE-2026-76581 is a CVSS 9.8 authentication bypass in the WPMU DEV Dashboard plugin allowing administrator session forgery, reported exploited by VulnCheck.
-
VulnerabilityYITH WooCommerce Waitlist Premium Privilege Escalation (CVE-2026-14359)
CVE-2026-14359 is a CVSS 8.8 privilege escalation in YITH WooCommerce Waitlist Premium, reported exploited by VulnCheck alone.
-
Vulnerability2 CVEs Across 3 Vendors (CVE-2026-74233)
CVE-2026-74233 and CVE-2026-74232 are two CVSS 9.8 unauthenticated RCE flaws in Zbtlink router firmware, reported exploited by VulnCheck KEV.
-
VulnerabilityZimbra Collaboration Suite Command Injection (CVE-2026-73570)
CVE-2026-73570 is a CVSS 8.9 OS command injection in Zimbra Collaboration Suite via SNMP notification handling, confirmed exploited per CISA KEV.
-
ResearchCISA Advisory Explained: A Guide for Security Teams
How CISA cybersecurity advisories are structured, who co-authors them, and how they differ from a vendor advisory or the CISA KEV catalog.
-
ResearchHow to Respond to a CISA Advisory Before Attackers Strike
A step-by-step response process for a new CISA advisory or KEV catalog addition, sized for a team without a dedicated intel analyst.
-
ResearchWhat Is a CISA Advisory and Why Should You Act on It?
What a CISA advisory actually is, the different types CISA publishes, and why security teams should treat them as a priority signal, not just another alert.
-
VulnerabilityArelle Code Execution (CVE-2026-42796)
CVE-2026-42796 is a CVSS 9.8 unauthenticated RCE in Arelle before 2.39.10: the REST configure endpoint loads plugins from a caller-supplied URL. VulnCheck KEV.
-
VulnerabilityAutoAgent Code Execution (CVE-2026-86124)
CVE-2026-86124 is a CVSS 9.8 unauthenticated RCE in HKUDS AutoAgent: the sandbox TCP server runs commands as root. VulnCheck KEV-listed Sept. 18, 2026.
-
VulnerabilityCisco Identity Services Engine Authentication Bypass (CVE-2026-76460)
CVE-2026-76460 is a CVSS 10.0 unauthenticated API authentication bypass in Cisco ISE and ISE-PIC, CISA KEV-listed Sept. 16, 2026, with no vendor workaround.
-
Vulnerability2 CVEs: Kan & Arcane (CVE-2026-32255)
Kan (CVE-2026-32255, CVSS 8.6) and Arcane (CVE-2026-40242, 7.2) each expose an unauthenticated URL-fetching endpoint. Both VulnCheck KEV-listed Sept. 17, 2026.
-
Vulnerability3 Linux Kernel CVEs (CVE-2025-39682)
CISA added three Linux kernel flaws to KEV on Sept. 18, 2026: CVE-2025-39682 (9.8, kTLS), CVE-2026-53266 (8.8, netfilter), CVE-2025-39964 (7.8, af_alg).
-
VulnerabilityIssabel Framework Authentication Bypass (CVE-2026-89026)
CVE-2026-89026 is a CVSS 9.8 hard-coded JWT signing key in Issabel Framework, VulnCheck KEV-listed Sept. 15, 2026; CISA has not listed it as of our data.
-
VulnerabilityCisco Secure Email Gateway SQL Injection (CVE-2026-76461)
CVE-2026-76461 is a CVSS 9.8 SQL injection flaw in Cisco Secure Email Gateway's AsyncOS email parsing that allows unauthenticated root command execution.
-
VulnerabilityGiveWP Insecure Deserialization (CVE-2026-82222)
CVE-2026-82222 is a CVSS 10.0 deserialization flaw in the GiveWP WordPress donation plugin through 4.16.7.1, reported as exploited by VulnCheck's KEV catalog.
-
VulnerabilityJFrog Artifactory Authentication Bypass (CVE-2026-82329)
CVE-2026-82329 is a CVSS 9.8 authentication flaw letting an unauthenticated attacker gain JFrog Artifactory admin rights. Added to CISA KEV Sept. 2, 2026.
-
VulnerabilityKestra OSS Authentication Bypass (CVE-2026-49869)
CVE-2026-49869 is a CVSS 10.0 authentication-filter bypass in Kestra OSS, KEV-listed Sept. 2, 2026 as exploited. NVD reports fixes in 1.0.45 and 1.3.21.
-
VulnerabilityMicrosoft Entra ID Insecure Deserialization (CVE-2026-69836)
CVE-2026-69836 is a CVSS 10.0 deserialization RCE in Microsoft Entra ID that Microsoft confirms was never exploited, despite its VulnCheck KEV listing.
-
VulnerabilityOracle HTTP Server Access Control Flaw (CVE-2026-21962)
CVE-2026-21962 is a CVSS 10.0 access control flaw in Oracle HTTP Server and the WebLogic Proxy Plug-in, KEV-listed Aug. 24, 2026, EPSS at the 98th percentile.
-
VulnerabilitySangoma Switchvox SMB Edition SQL Injection (CVE-2026-9586)
CVE-2026-9586 is a CVSS 9.8 unauthenticated SQL injection in Sangoma Switchvox SMB Edition 8.3 enabling remote code execution. KEV-listed Sept. 2, 2026.
-
Vulnerability2 SonicWall SMA1000 Appliances CVEs (CVE-2026-83548)
CVE-2026-83548 is a CVSS 10.0 pre-auth SSRF in SonicWall SMA1000 appliances, KEV-listed Sept. 2, 2026 beside CVE-2026-83549, a post-auth command injection.
-
VulnerabilityWP Compress Code Injection (CVE-2026-73343)
CVE-2026-73343 is a CVSS 10.0 code injection flaw enabling unauthenticated RCE in WP Compress before 7.20.01, reported as exploited by VulnCheck's KEV catalog.
-
VulnerabilityWP Cookie Notice Vulnerability (CVE-2026-82970)
CVE-2026-82970 is a CVSS 10.0 unrestricted file upload flaw in the WP Cookie Notice WordPress plugin through 4.4.1, reported as exploited by VulnCheck KEV.
-
Vulnerability2 CVEs: Azure AI Language & Milvus (CVE-2026-70352)
A VulnCheck KEV-listed Milvus flaw and a maximum CVSS 10.0 Azure AI Language elevation-of-privilege CVE, both single-sourced with minimal technical detail.
-
Vulnerability2 Ollama CVEs (CVE-2026-7482)
Two Ollama CVEs from 2026: a VulnCheck KEV-listed heap out-of-bounds read (CVSS 9.1) that can leak API keys and user data, plus a lower-severity crash bug.
-
VulnerabilityGitLab Community Edition Path Traversal (CVE-2026-85706)
CVE-2026-85706 is a maximum-severity CVSS 10.0 path traversal flaw in GitLab CE/EE, added to CISA's KEV catalog on September 11, 2026 as actively exploited.
-
VulnerabilityJFrog Artifactory Self-Hosted Authentication Bypass (CVE-2026-42018)
CVE-2026-42018 can leak an internal anonymous-user token to unauthenticated callers in JFrog Artifactory even when anonymous access is disabled. Added to CISA KEV Sept. 11, 2026.
-
VulnerabilityMicrosoft Windows Privilege Escalation (CVE-2026-81963)
CVE-2026-81963 lets a local attacker elevate privileges via improper link resolution in the Windows Update Stack. Added to CISA KEV Sept. 8, 2026.
-
VulnerabilityBerriAI LiteLLM Authentication Bypass (CVE-2026-59822)
CVE-2026-59822 lets attackers bypass LiteLLM key validation via a fabricated Authorization header, reaching MCP tooling unauthenticated. Added to CISA KEV Sept. 2, 2026.
-
VulnerabilityGoogle Chrome Out-of-Bounds Write (CVE-2026-87491)
CVE-2026-87491, a CVSS 8.8 V8 out-of-bounds write, was added to CISA KEV Sept. 9, 2026 — the second exploited V8 flaw in Chrome within a week.
-
VulnerabilityConnectWise ScreenConnect Privilege Escalation (CVE-2026-84869)
CVE-2026-84869 lets attackers transfer and execute files through an active ScreenConnect remote session without Host confirmation. Added to CISA KEV Sept. 11, 2026.
-
VulnerabilityJFrog Artifactory Self-Hosted Privilege Escalation (CVE-2026-42016)
CVE-2026-42016 lets attackers escalate privileges in JFrog Artifactory via a token-scope validation gap. CISA added it to KEV Sept. 11, 2026; Wiz reports in-the-wild exploitation.
-
VulnerabilityN-able N-central Code Injection (CVE-2026-86218)
CVE-2026-86218 is a CVSS 9.8 static code injection in N-able N-central allowing pre-authentication remote code execution. CISA added it to KEV on Sept. 8, 2026.
-
ResearchTwo MikroTik RouterOS Flaws Added to CISA KEV List
CISA added two MikroTik RouterOS flaws, CVE-2026-86060 (CVSS 9.8) and CVE-2026-67277 (CVSS 8.2), to its KEV catalog Sept. 10, 2026 as actively exploited.
-
VulnerabilityCisco Secure Firewall Management Center Authentication Bypass (CVE-2026-20079)
CVE-2026-20079 is a maximum-severity CVSS 10 authentication bypass in Cisco Secure Firewall Management Center, added to CISA KEV Sept. 9, 2026 as actively exploited.
-
VulnerabilityAdobe Commerce Authentication Bypass (CVE-2026-75650)
CVE-2026-75650 is a maximum-severity CVSS 10 template injection flaw in Adobe Commerce and Magento, added to CISA KEV Sept. 8, 2026 as actively exploited.
-
VulnerabilityCitrix NetScaler ADC Authentication Bypass (CVE-2026-19490)
CVE-2026-19490 is a critical CVSS 9.8 authentication bypass in Citrix NetScaler ADC and Gateway, added to CISA's KEV catalog Sept. 9, 2026 as actively exploited.
-
VulnerabilityMicrosoft Windows Privilege Escalation (CVE-2026-85880)
CVE-2026-85880 is a heap-based buffer overflow in Windows ALPC allowing local privilege escalation. Added to CISA KEV Sept. 8, 2026, the same day as CVE-2026-81963.
-
VulnerabilityFortinet FortiOS Vulnerability (CVE-2025-25249)
CVE-2025-25249, a high-severity CVSS 8.1 heap-based buffer overflow across multiple FortiOS versions, was added to CISA's KEV catalog on September 9, 2026.
-
VulnerabilityGoogle Chrome Type Confusion (CVE-2026-85046)
CVE-2026-85046 is a CVSS 8.8 V8 type-confusion flaw in Chrome allowing sandboxed code execution via a crafted HTML page. Added to CISA KEV Sept. 4, 2026.