Vulnerabilities CISA has confirmed as actively exploited. Prioritize these for remediation.
Vulnerabilities newly added to CISA KEV in the last 7 days.
| CVE ID | Title | Severity | Added |
|---|---|---|---|
| Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | CRITICAL | 2026. 07. 16. | |
| A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests | CRITICAL |
| CVE ID | Title | Severity | References | Ransom | |||||
|---|---|---|---|---|---|---|---|---|---|
| — | — | — | 82.50 | 4.1% | KEV |
| 2026. 07. 16. |
| CVE-2026-39808 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here> | CRITICAL | 2026. 07. 16. |
| CVE-2026-46817 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C | CRITICAL | 2026. 07. 15. |
| CVE-2023-4346 | KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device. The BCU key feature on the devices can be used to create a password for the device, but this password can often not be reset without entering the current password. If the device is configured to interface with a network, an attacker with access to that network could interface with the KNX instal | HIGH | 2026. 07. 15. |
| — |
| 2025. 09. 02. |
| — |
| CVE-2025-57819 | FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-supplied data allowing unauthenticated access to FreePBX Administrator leading to arbitrary database manipulation and remote code execution. This issue has been patched in endpoint versions 15.0.66, 16.0.89, and 17.0.3. | CRITICAL | 10.0v4.0 | 100 | 93.3% | KEV | 2025. 08. 28. | 2025. 08. 29. | — |
| CVE-2025-7775 | — | — | — | 82.50 | 19.0% | KEV KISA | — | 2025. 08. 26. | — |
| CVE-2024-8069 | Limited remote code execution with privilege of a NetworkService Account access in Citrix Session Recording if the attacker is an authenticated user on the same intranet as the session recording server | MEDIUM | 5.1v4.0 | 76.50 | 14.7% | KEV | 2024. 11. 12. | 2025. 08. 25. | — |
| CVE-2024-8068 | Privilege escalation to NetworkService Account access in Citrix Session Recording when an attacker is an authenticated user in the same Windows Active Directory domain as the session recording server domain | MEDIUM | 5.1v4.0 | 76.50 | 1.4% | KEV | 2024. 11. 12. | 2025. 08. 25. | — |
| CVE-2025-48384 | — | — | — | 82.50 | 2.8% | KEV KISA | — | 2025. 08. 25. | — |
| CVE-2025-43300 | — | — | — | 82.50 | 20.0% | KEV KISA | — | 2025. 08. 21. | — |
| CVE-2025-54948 | A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations. | CRITICAL | 9.4v3.1 | 100 | 20.8% | KEV | 2025. 08. 05. | 2025. 08. 18. | — |
| CVE-2025-8876 | — | — | — | 82.50 | 3.1% | KEV | — | 2025. 08. 13. | — |
| CVE-2025-8875 | — | — | — | 82.50 | 1.6% | KEV | — | 2025. 08. 13. | — |
| CVE-2025-8088 | A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček from ESET. | HIGH | 8.4v4.0 | 100 | 80.9% | KEV KISA | 2025. 08. 08. | 2025. 08. 12. | — |
| CVE-2013-3893 | Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code via crafted JavaScript strings, as demonstrated by use of an ms-help: URL that triggers loading of hxds.dll. | HIGH | 8.8v3.1 | 100 | 85.9% | KEV KISA | 2013. 09. 18. | 2025. 08. 12. | — |
| CVE-2007-0671 | Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as demonstrated by Exploit-MSExcel.h in targeted zero-day attacks. | HIGH | 8.8v3.1 | 100 | 42.1% | KEV | 2007. 02. 03. | 2025. 08. 12. | — |
| CVE-2022-40799 | Data Integrity Failure in 'Backup Config' in D-Link DNR-322L <= 2.60B15 allows an authenticated attacker to execute OS level commands on the device. | HIGH | 8.8v3.1 | 100 | 31.3% | KEV | 2022. 11. 29. | 2025. 08. 05. | — |
| CVE-2020-25079 | An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. cgi-bin/ddns_enc.cgi allows authenticated command injection. | HIGH | 8.8v3.1 | 100 | 52.7% | KEV | 2020. 09. 02. | 2025. 08. 05. | — |
| CVE-2020-25078 | An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticated /config/getuser endpoint allows for remote administrator password disclosure. | HIGH | 7.5v3.1 | 100 | 97.9% | KEV | 2020. 09. 02. | 2025. 08. 05. | — |
| CVE-2025-20337 | A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerability. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a crafted API request. A successful exploit could allow the attacker to obtain root privileges | CRITICAL | 10.0v3.1 | 100 | 65.1% | KEV KISA | 2025. 07. 16. | 2025. 07. 28. | — |
| CVE-2025-20281 | A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerability. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a crafted API request. A successful exploit could allow the attacker to obtain root privileges | CRITICAL | 10.0v3.1 | 100 | 96.7% | KEV KISA | 2025. 06. 25. | 2025. 07. 28. | — |
| CVE-2023-2533 | — | — | — | 82.50 | 29.2% | KEV | — | 2025. 07. 28. | — |
| CVE-2025-54309 | CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via HTTPS, as exploited in the wild in July 2025. | CRITICAL | 9.0v3.1 | 100 | 92.0% | KEV KISA | 2025. 07. 18. | 2025. 07. 22. | — |