Vulnerabilities CISA has confirmed as actively exploited. Prioritize these for remediation.
Vulnerabilities newly added to CISA KEV in the last 7 days.
| CVE ID | Title | Severity | Added |
|---|---|---|---|
| Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | CRITICAL | 2026. 07. 16. | |
| A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests | CRITICAL |
| CVE ID | Title | Severity | References | Ransom | |||||
|---|---|---|---|---|---|---|---|---|---|
| — | — | — | 87.50 | 1.0% | KEV |
| 2026. 07. 16. |
| CVE-2026-39808 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here> | CRITICAL | 2026. 07. 16. |
| CVE-2026-46817 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C | CRITICAL | 2026. 07. 15. |
| CVE-2023-4346 | KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device. The BCU key feature on the devices can be used to create a password for the device, but this password can often not be reset without entering the current password. If the device is configured to interface with a network, an attacker with access to that network could interface with the KNX instal | HIGH | 2026. 07. 15. |
| — |
| 2025. 03. 04. |
| ⚠️ |
| CVE-2025-22226 | — | — | — | 82.50 | 1.7% | KEV KISA | — | 2025. 03. 04. | — |
| CVE-2023-20118 | A vulnerability in the web-based management interface of Cisco Small Business Routers RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary commands on an affected device. This vulnerability is due to improper validation of user input within incoming HTTP packets. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web-based management interface. A successful exploit could allow the attacker t | MEDIUM | 6.5v3.1 | 97.50 | 54.1% | KEV | 2023. 04. 13. | 2025. 03. 03. | — |
| CVE-2022-43939 | Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x contain security restrictions using non-canonical URLs which can be circumvented. | HIGH | 8.6v3.1 | 100 | 92.3% | KEV | 2023. 04. 03. | 2025. 03. 03. | — |
| CVE-2022-43769 | Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain web services to set property values which contain Spring templates that are interpreted downstream. | HIGH | 8.8v3.1 | 100 | 97.7% | KEV | 2023. 04. 03. | 2025. 03. 03. | — |
| CVE-2018-8639 | An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8641. | HIGH | 7.8v3.1 | 100 | 22.3% | KEV | 2018. 12. 12. | 2025. 03. 03. | ⚠️ |
| CVE-2024-4885 | — | — | — | 82.50 | 99.3% | KEV | — | 2025. 03. 03. | — |
| CVE-2024-49035 | An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privileges over a network. | HIGH | 8.7v3.1 | 100 | 1.3% | KEV KISA | 2024. 11. 26. | 2025. 02. 25. | — |
| CVE-2023-34192 | Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary code via a crafted script to the /h/autoSaveDraft function. | CRITICAL | 9.0v3.1 | 100 | 77.3% | KEV | 2023. 07. 06. | 2025. 02. 25. | — |
| CVE-2017-3066 | Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserialization vulnerability in the Apache BlazeDS library. Successful exploitation could lead to arbitrary code execution. | CRITICAL | 9.8v3.1 | 100 | 90.6% | KEV KISA | 2017. 04. 27. | 2025. 02. 24. | — |
| CVE-2024-20953 | — | — | — | 82.50 | 3.4% | KEV | — | 2025. 02. 24. | — |
| CVE-2025-24989 | — | — | — | 82.50 | 1.7% | KEV KISA | — | 2025. 02. 21. | — |
| CVE-2025-23209 | Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. This is an remote code execution (RCE) vulnerability that affects Craft 4 and 5 installs where your security key has already been compromised. Anyone running an unpatched version of Craft with a compromised security key is affected. This vulnerability has been patched in Craft 5.5.8 and 4.13.8. Users who cannot update to a patched version, should rotate their security keys and ensure their priva | HIGH | 8.0v3.1 | 100 | 4.7% | KEV | 2025. 01. 18. | 2025. 02. 20. | — |
| CVE-2025-0111 | — | — | — | 82.50 | 1.9% | KEV KISA | — | 2025. 02. 20. | — |
| CVE-2024-53704 | An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication. | CRITICAL | 9.8v3.1 | 100 | 95.1% | KEV | 2025. 01. 09. | 2025. 02. 18. | ⚠️ |
| CVE-2025-0108 | — | — | — | 82.50 | 98.4% | KEV KISA | — | 2025. 02. 18. | — |
| CVE-2024-57727 | SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files include server configuration files containing various secrets and hashed user passwords. | HIGH | 7.5v3.1 | 100 | 95.2% | KEV | 2025. 01. 15. | 2025. 02. 13. | ⚠️ |
| CVE-2025-24200 | — | — | — | 82.50 | 4.4% | KEV | — | 2025. 02. 12. | — |
| CVE-2024-41710 | — | — | — | 82.50 | 41.6% | KEV | — | 2025. 02. 12. | — |
| CVE-2025-21418 | — | — | — | 82.50 | 1.5% | KEV KISA | — | 2025. 02. 11. | — |