CISA Known Exploited Vulnerabilities
Vulnerabilities CISA has confirmed are being actively exploited. These are the top priority — federal agencies have a mandated patch-by date, and so should you. 1,716 entries.
| CVE | Added | Patch by | EPSS | CVSS | Ransomware | What |
|---|---|---|---|---|---|---|
| CVE-2025-39682 | 2026-09-18 | 2026-09-21 | 0.5% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: t… | |
| CVE-2025-39964 | 2026-09-18 | 2026-09-21 | 0.3% | 7.8 | In the Linux kernel, the following vulnerability has been resolved: c… | |
| CVE-2026-53266 | 2026-09-18 | 2026-09-21 | 0.1% | 8.8 | In the Linux kernel, the following vulnerability has been resolved: n… | |
| CVE-2026-58704 | 2026-09-16 | 2026-09-19 | 0.2% | — | Google Pixel devices contain an improper authorization vulnerability i… | |
| CVE-2026-76460 | 2026-09-16 | 2026-09-19 | 0.8% | — | Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Co… | |
| CVE-2026-87886 | 2026-09-16 | 2026-09-19 | 0.3% | 7.8 | Local privilege escalation due to insecure file permissions. The follo… | |
| CVE-2026-76461 | 2026-09-14 | 2026-09-17 | 2.0% | 9.8 | A vulnerability in the email parsing of Cisco AsyncOS Software for Cis… | |
| CVE-2026-84869 | 2026-09-11 | 2026-09-14 | 0.7% | 9.9 | A condition in the ScreenConnect client may allow files to be transfer… | |
| CVE-2026-85706 | 2026-09-11 | 2026-09-14 | 14.6% | 10.0 | GitLab has remediated an issue in GitLab CE/EE affecting all versions … | |
| CVE-2026-42016 | 2026-09-11 | 2026-09-25 | 0.9% | 8.1 | JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerabl… | |
| CVE-2026-42018 | 2026-09-11 | 2026-09-25 | 0.9% | 7.5 | JFrog Artifactory could return an internal anonymous-user token to an … | |
| CVE-2026-86060 | 2026-09-10 | 2026-09-13 | 1.1% | 9.8 | RouterOS contains an argument-handling flaw in the SSH login path invo… | |
| CVE-2026-67277 | 2026-09-10 | 2026-09-13 | 0.9% | 8.2 | RouterOS accepts a "related" btest connection before the corresponding… | |
| CVE-2026-87491 | 2026-09-09 | 2026-09-23 | 1.0% | 8.8 | Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allo… | |
| CVE-2026-19490 | 2026-09-09 | 2026-09-12 | 5.6% | 9.8 | Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affe… | |
| CVE-2026-20079 | 2026-09-09 | 2026-09-12 | 75.8% | 10.0 | A vulnerability in the web interface of Cisco Secure Firewall Manageme… | |
| CVE-2025-25249 | 2026-09-09 | 2026-09-12 | 2.4% | 8.1 | A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 t… | |
| CVE-2026-86218 | 2026-09-08 | 2026-09-11 | 0.7% | 9.8 | N-central is vulnerable to a pre-auth remote code execution This issue… | |
| CVE-2026-85880 | 2026-09-08 | 2026-09-22 | 0.6% | 7.8 | Heap-based buffer overflow in Windows ALPC allows an authorized attack… | |
| CVE-2026-81963 | 2026-09-08 | 2026-09-22 | 0.6% | 7.8 | Improper link resolution before file access ('link following') in Wind… | |
| CVE-2026-75650 | 2026-09-08 | 2026-09-11 | 2.1% | 10.0 | Adobe Commerce is affected by an Improper Neutralization of Special El… | |
| CVE-2026-85046 | 2026-09-04 | 2026-09-18 | 1.5% | 8.8 | Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a… | |
| CVE-2026-9586 | 2026-09-02 | 2026-09-05 | 11.8% | 9.8 | An unauthenticated SQL injection vulnerability exists in Sangoma Switc… | |
| CVE-2026-82329 | 2026-09-02 | 2026-09-05 | 7.7% | 9.8 | JFrog Artifactory contains an authentication weakness that, under defa… | |
| CVE-2026-83548 | 2026-09-02 | 2026-09-05 | 4.7% | 10.0 | A Pre-authentication SSRF vulnerability exists in the SMA1000 Applianc… | |
| CVE-2026-83549 | 2026-09-02 | 2026-09-05 | 8.5% | 7.8 | Post-authentication Improper Neutralization of Special Elements used i… | |
| CVE-2026-59822 | 2026-09-02 | 2026-09-16 | 0.9% | 8.2 | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or … | |
| CVE-2026-48710 | 2026-09-02 | 2026-09-16 | 36.3% | 6.5 | Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.… | |
| CVE-2026-49869 | 2026-09-02 | 2026-09-05 | 1.9% | 10.0 | Kestra is an open-source, event-driven orchestration platform. Prior t… | |
| CVE-2026-81578 | 2026-08-31 | 2026-09-14 | 3.3% | 9.8 | An improper access control vulnerability exists in the web management … | |
| CVE-2026-82078 | 2026-08-31 | 2026-09-14 | 3.6% | 9.1 | An unsafe dynamic class loading vulnerability exists in the database c… | |
| CVE-2026-66384 | 2026-08-27 | 2026-09-10 | 0.6% | 5.3 | An authenticated user may write data outside the intended Docker cache… | |
| CVE-2026-53362 | 2026-08-27 | 2026-08-30 | 0.5% | 7.8 | In the Linux kernel, the following vulnerability has been resolved: i… | |
| CVE-2023-49105 | 2026-08-27 | 2026-08-30 | 43.2% | 9.8 | An issue was discovered in ownCloud owncloud/core before 10.13.1. An a… | |
| CVE-2026-8452 | 2026-08-26 | 2026-08-29 | 1.6% | 9.8 | Memory overflow vulnerability NetScaler ADC and NetScaler Gateway lead… | |
| CVE-2015-3246 | 2026-08-26 | 2026-09-09 | 8.8% | 5.1 | libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhe… | |
| CVE-2015-5287 | 2026-08-26 | 2026-09-09 | 5.0% | 7.8 | The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT)… | |
| CVE-2019-1068 | 2026-08-26 | 2026-08-29 | 52.8% | 8.8 | A remote code execution vulnerability exists in Microsoft SQL Server w… | |
| CVE-2021-23758 | 2026-08-26 | 2026-09-09 | 83.6% | 8.1 | All versions of package ajaxpro.2 are vulnerable to Deserialization of… | |
| CVE-2022-0995 | 2026-08-26 | 2026-09-09 | 9.5% | 7.8 | An out-of-bounds (OOB) memory write flaw was found in the Linux kernel… | |
| CVE-2026-60004 | 2026-08-25 | 2026-08-28 | 86.8% | 9.8 | Gitea before 1.27.1 allows remote code execution via the diffpatch API… | |
| CVE-2026-21962 | 2026-08-24 | 2026-08-27 | 42.5% | 10.0 | Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy … | |
| CVE-2026-73570 | 2026-08-21 | 2026-08-24 | 32.4% | 8.9 | A remote code execution vulnerability exists in Zimbra Collaboration (… | |
| CVE-2026-72529 | 2026-08-20 | 2026-08-23 | 1.6% | 9.8 | A remote unauthorized attacker with network access via port 4307/TCP t… | |
| CVE-2026-72530 | 2026-08-20 | 2026-09-03 | 1.8% | 9.0 | A remote unauthorized attacker with network access via port 4307/TCP t… | |
| CVE-2026-64849 | 2026-08-19 | 2026-09-02 | 16.4% | 9.3 | MLflow is an open source AI engineering platform for agents, large lan… | |
| CVE-2026-65400 | 2026-08-18 | 2026-08-21 | 10.5% | 9.8 | An authentication issue was addressed with improved state management. … | |
| CVE-2026-59310 | 2026-08-18 | 2026-08-21 | 49.7% | 9.8 | yes | VMware vCenter contains a directory traversal vulnerability in the Sys… |
| CVE-2026-55040 | 2026-08-18 | 2026-08-21 | 50.6% | 9.1 | Weak authentication in Microsoft Office SharePoint allows an unauthori… | |
| CVE-2026-33824 | 2026-08-18 | 2026-08-21 | 72.7% | 9.8 | Double free in Windows IKE Extension allows an unauthorized attacker t… | |
| CVE-2025-62593 | 2026-08-17 | 2026-08-20 | 16.9% | 8.8 | Ray is an AI compute engine. Prior to version 2.52.0, developers worki… | |
| CVE-2026-20349 | 2026-08-11 | 2026-08-14 | 2.2% | 8.6 | A vulnerability in the Remote Access SSL VPN service for Cisco Secure … | |
| CVE-2026-72898 | 2026-08-11 | 2026-08-14 | 94.2% | 10.0 | Metabase allows a remote, unauthenticated attacker to inject arbitrary… | |
| CVE-2026-68820 | 2026-08-11 | 2026-08-25 | 6.2% | 7.0 | Use after free in Windows Ancillary Function Driver for WinSock allows… | |
| CVE-2026-8037 | 2026-08-07 | 2026-08-10 | 99.6% | 9.6 | OS Command Injection Remote Code Execution Vulnerability in API in Pro… | |
| CVE-2026-63077 | 2026-08-05 | 2026-08-08 | 86.5% | 9.8 | In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remot… | |
| CVE-2026-9198 | 2026-08-04 | 2026-08-07 | 60.6% | 9.8 | IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers… | |
| CVE-2026-34486 | 2026-08-04 | 2026-08-07 | 98.6% | 7.5 | Missing Encryption of Sensitive Data vulnerability in Apache Tomcat du… | |
| CVE-2026-18556 | 2026-08-04 | 2026-08-07 | 40.2% | 7.4 | Authentication bypass using an alternate path or channel vulnerability… | |
| CVE-2026-18577 | 2026-08-03 | 2026-08-06 | 54.1% | 8.1 | An incomplete patch for CVE-2026-18556 allows for authentication bypas… | |
| CVE-2026-20316 | 2026-07-29 | 2026-08-01 | 11.2% | 5.3 | yes | A vulnerability in the web interface of Cisco Secure Firewall Manageme… |
| CVE-2026-16812 | 2026-07-27 | 2026-07-30 | 1.6% | 10.0 | VeloCloud Orchestrator (VCO) on-prem has a security issue where this i… | |
| CVE-2025-68686 | 2026-07-27 | 2026-08-10 | 29.6% | 5.9 | An Exposure of Sensitive Information to an Unauthorized Actor vulnerab… | |
| CVE-2026-16232 | 2026-07-22 | 2026-07-25 | 72.1% | 9.8 | An authentication bypass vulnerability in the Check Point SmartConsole… | |
| CVE-2026-50522 | 2026-07-22 | 2026-07-25 | 85.4% | 9.8 | Deserialization of untrusted data in Microsoft Office SharePoint allow… | |
| CVE-2026-60137 | 2026-07-21 | 2026-08-04 | 78.3% | 5.9 | WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0… | |
| CVE-2026-63030 | 2026-07-21 | 2026-07-24 | 97.3% | 9.8 | WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a R… | |
| CVE-2026-0770 | 2026-07-21 | 2026-07-24 | 63.4% | 9.8 | Langflow exec_globals Inclusion of Functionality from Untrusted Contro… | |
| CVE-2021-27137 | 2026-07-21 | 2026-07-24 | 4.0% | 8.1 | An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 457… | |
| CVE-2026-58644 | 2026-07-16 | 2026-07-19 | 15.9% | — | Microsoft SharePoint contains a deserialization of untrusted data vuln… | |
| CVE-2026-25089 | 2026-07-16 | 2026-07-19 | 76.1% | 9.8 | A improper neutralization of special elements used in an os command ('… | |
| CVE-2026-39808 | 2026-07-16 | 2026-07-19 | 92.8% | — | Fortinet FortiSandbox contains an OS command injection vulnerability t… | |
| CVE-2026-46817 | 2026-07-15 | 2026-07-18 | 13.0% | 9.8 | Vulnerability in the Oracle Payments product of Oracle E-Business Suit… | |
| CVE-2023-4346 | 2026-07-15 | 2026-07-29 | 1.3% | — | KNX Association KNX Protocol Connection Authorization Option 1 contain… | |
| CVE-2026-56155 | 2026-07-14 | 2026-07-28 | 0.3% | — | Microsoft Active Directory Federation Services contains an insufficien… | |
| CVE-2026-56164 | 2026-07-14 | 2026-07-17 | 26.6% | — | Microsoft SharePoint contains a missing authentication for critical fu… | |
| CVE-2026-15409 | 2026-07-14 | 2026-07-17 | 84.5% | — | yes | SonicWall SMA1000 Appliances contain a server-side request forgery vul… |
| CVE-2026-15410 | 2026-07-14 | 2026-07-17 | 11.8% | — | yes | SonicWall SMA1000 Appliances contain a code injection vulnerability wh… |
| CVE-2008-4128 | 2026-07-13 | 2026-07-16 | 33.9% | — | Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities th… | |
| CVE-2026-56291 | 2026-07-10 | 2026-07-13 | 14.9% | 9.8 | Joomla Extension - balbooa.com - Unauthenticated file upload in Balboo… | |
| CVE-2026-48939 | 2026-07-10 | 2026-07-13 | 20.1% | — | iCagenda contains an unrestricted upload of file with dangerous type v… | |
| CVE-2026-48908 | 2026-07-07 | 2026-07-10 | 15.1% | — | JoomShaper SP Page Builder contains an unrestricted upload of file wit… | |
| CVE-2026-48282 | 2026-07-07 | 2026-07-10 | 42.4% | 10.0 | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Imp… | |
| CVE-2026-56290 | 2026-07-07 | 2026-07-10 | 30.9% | 9.8 | Joomla Extension - joomlack.fr - Unauthenticated file upload in Page B… | |
| CVE-2026-55255 | 2026-07-07 | 2026-07-10 | 0.9% | — | Langflow contains an authorization bypass through user-controlled key … | |
| CVE-2026-45659 | 2026-07-01 | 2026-07-04 | 76.1% | 8.8 | yes | Deserialization of untrusted data in Microsoft Office SharePoint allow… |
| CVE-2026-48558 | 2026-06-29 | 2026-07-02 | 64.3% | — | SimpleHelp contains an authentication bypass vulnerability in the OIDC… | |
| CVE-2026-20230 | 2026-06-25 | 2026-06-28 | 88.2% | 8.6 | A vulnerability in Cisco Unified Communications Manager (Unified CM) a… | |
| CVE-2026-12569 | 2026-06-25 | 2026-06-28 | 40.6% | 9.8 | yes | A critical remote code execution (RCE) vulnerability has been reported… |
| CVE-2025-67038 | 2026-06-23 | 2026-06-26 | 19.3% | 9.8 | An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC m… | |
| CVE-2026-34908 | 2026-06-23 | 2026-06-26 | 85.2% | 10.0 | A malicious actor with access to the network could exploit an Improper… | |
| CVE-2026-34909 | 2026-06-23 | 2026-06-26 | 65.0% | 10.0 | A malicious actor with access to the network could exploit a Path Trav… | |
| CVE-2026-34910 | 2026-06-23 | 2026-06-26 | 87.5% | 10.0 | A malicious actor with access to the network could exploit an Improper… | |
| CVE-2026-20253 | 2026-06-18 | 2026-06-21 | 96.9% | 9.8 | In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below … | |
| CVE-2026-48907 | 2026-06-16 | 2026-06-19 | 78.1% | 9.8 | A vulnerability in the JCE editor extension for Joomla allows the crea… | |
| CVE-2026-54420 | 2026-06-15 | 2026-06-18 | 1.4% | 8.5 | LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM … | |
| CVE-2026-20262 | 2026-06-15 | 2026-06-29 | 28.2% | 6.5 | A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, former… | |
| CVE-2026-35273 | 2026-06-12 | 2026-06-15 | 95.5% | 9.8 | yes | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Orac… |
| CVE-2026-10520 | 2026-06-11 | 2026-06-14 | 99.9% | 10.0 | An OS Command Injection vulnerability in Ivanti Sentry before the R10.… | |
| CVE-2026-11645 | 2026-06-09 | 2026-06-23 | 2.2% | 8.8 | Out of bounds read and write in V8 in Google Chrome prior to 149.0.782… |
Page 1 of 18
Next →