Vulnerabilities CISA has confirmed as actively exploited. Prioritize these for remediation.
Vulnerabilities newly added to CISA KEV in the last 7 days.
| CVE ID | Title | Severity | Added |
|---|---|---|---|
| Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | CRITICAL | 2026. 07. 16. | |
| A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests | CRITICAL |
| CVE ID | Title | Severity | References | Ransom | |||||
|---|---|---|---|---|---|---|---|---|---|
| Lanscope Endpoint Manager (On-Premises) (Client program (MR) and Detection agent (DA)) improperly verifies the origin of incoming requests, allowing an attacker to execute arbitrary code by sending specially crafted packets. | CRITICAL | 9.3v4.0 | 100 |
| 2026. 07. 16. |
| CVE-2026-39808 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here> | CRITICAL | 2026. 07. 16. |
| CVE-2026-46817 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C | CRITICAL | 2026. 07. 15. |
| CVE-2023-4346 | KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device. The BCU key feature on the devices can be used to create a password for the device, but this password can often not be reset without entering the current password. If the device is configured to interface with a network, an attacker with access to that network could interface with the KNX instal | HIGH | 2026. 07. 15. |
2.6% |
KEV |
| 2025. 10. 20. |
| 2025. 10. 22. |
| — |
| CVE-2025-61884 | Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Configurator. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Configurator accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVS | HIGH | 7.5v3.1 | 100 | 97.8% | KEV KISA | 2025. 10. 12. | 2025. 10. 20. | ⚠️ |
| CVE-2025-33073 | Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network. | HIGH | 8.8v3.1 | 100 | 78.5% | KEV KISA | 2025. 06. 10. | 2025. 10. 20. | — |
| CVE-2025-2747 | An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server component password handling for the server defined None type. Authentication bypass allows an attacker to control administrative objects.This issue affects Xperience through 13.0.178. | CRITICAL | 9.8v3.1 | 100 | 92.2% | KEV | 2025. 03. 24. | 2025. 10. 20. | — |
| CVE-2025-2746 | An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server password handling of empty SHA1 usernames in digest authentication. Authentication bypass allows an attacker to control administrative objects.This issue affects Xperience through 13.0.172. | CRITICAL | 9.8v3.1 | 100 | 58.4% | KEV | 2025. 03. 24. | 2025. 10. 20. | — |
| CVE-2022-48503 | The issue was addressed with improved bounds checks. This issue is fixed in tvOS 15.6, watchOS 8.7, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5, Safari 15.6. Processing web content may lead to arbitrary code execution. | HIGH | 8.8v3.1 | 100 | 3.2% | KEV | 2023. 08. 14. | 2025. 10. 20. | — |
| CVE-2025-54253 | Adobe Experience Manager versions 6.5.23 and earlier are affected by a Misconfiguration vulnerability that could result in arbitrary code execution. An attacker could leverage this vulnerability to bypass security mechanisms and execute code. Exploitation of this issue does not require user interaction and scope is changed. | CRITICAL | 10.0v3.1 | 100 | 87.5% | KEV KISA | 2025. 08. 05. | 2025. 10. 15. | — |
| CVE-2025-59230 | Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. | HIGH | 7.8v3.1 | 100 | 2.7% | KEV KISA | 2025. 10. 14. | 2025. 10. 14. | — |
| CVE-2025-24990 | Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an announcement of the upcoming removal of ltmdm64.sys driver. The driver has been removed in the October cumulative update. Fax modem hardware dependent on this specific driver will no longer work on Windows. Microsoft recommends removing any existing dependencies on this hardware. | HIGH | 7.8v3.1 | 100 | 6.0% | KEV KISA | 2025. 10. 14. | 2025. 10. 14. | — |
| CVE-2025-47827 | In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a crafted root filesystem can be mounted from an unverified SquashFS image. | MEDIUM | 4.6v3.1 | 69 | 3.8% | KEV KISA | 2025. 06. 05. | 2025. 10. 14. | — |
| CVE-2016-7836 | SKYSEA Client View Ver.11.221.03 and earlier allows remote code execution via a flaw in processing authentication on the TCP connection with the management console program. | CRITICAL | 9.8v3.1 | 100 | 19.4% | KEV | 2017. 06. 09. | 2025. 10. 14. | — |
| CVE-2021-43798 | Grafana path traversal | HIGH | 7.5v3.1 | 100 | 88.8% | KEV | 2024. 02. 01. | 2025. 10. 09. | — |
| CVE-2025-27915 | — | — | — | 82.50 | 4.3% | KEV | — | 2025. 10. 07. | — |
| CVE-2025-61882 | Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Concurrent Processing. Successful attacks of this vulnerability can result in takeover of Oracle Concurrent Processing. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CV | CRITICAL | 9.8v3.1 | 100 | 99.7% | KEV KISA | 2025. 10. 05. | 2025. 10. 06. | ⚠️ |
| CVE-2013-3918 | The InformationCardSigninHelper Class ActiveX control in icardie.dll in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write) via a crafted web page that is accessed by Internet Explorer, as exploited in the wild in November 2013, aka "Inf | HIGH | 8.8v3.1 | 100 | 73.9% | KEV KISA | 2013. 11. 12. | 2025. 10. 06. | — |
| CVE-2011-3402 | Unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via crafted font data in a Word document or web page, as exploited in the wild in November 2011 by Duqu, aka "TrueType Font Parsing Vulnerability." | HIGH | 8.8v3.1 | 100 | 78.3% | KEV KISA | 2011. 11. 04. | 2025. 10. 06. | — |
| CVE-2010-3962 | Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code via vectors related to Cascading Style Sheets (CSS) token sequences and the clip attribute, aka an "invalid flag reference" issue or "Uninitialized Memory Corruption Vulnerability," as exploited in the wild in November 2010. | HIGH | 8.1v3.1 | 100 | 96.9% | KEV | 2010. 11. 05. | 2025. 10. 06. | — |
| CVE-2010-3765 | Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when JavaScript is enabled, allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the creation of multiple frames, which triggers memory corruption, as exploited in the wild in October 2010 by the Belmoo malware. | CRITICAL | 9.8v3.1 | 100 | 83.3% | KEV | 2010. 10. 28. | 2025. 10. 06. | — |
| CVE-2021-43226 | — | — | — | 82.50 | 3.1% | KEV | — | 2025. 10. 06. | — |
| CVE-2021-22555 | — | — | — | 82.50 | 78.7% | KEV | — | 2025. 10. 06. | — |