Vulnerabilities CISA has confirmed as actively exploited. Prioritize these for remediation.
Vulnerabilities newly added to CISA KEV in the last 7 days.
| CVE ID | Title | Severity | Added |
|---|---|---|---|
| Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | CRITICAL | 2026. 07. 16. | |
| A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests | CRITICAL |
| CVE ID | Title | Severity | References | Ransom | |||||
|---|---|---|---|---|---|---|---|---|---|
| — | — | — | 82.50 | 65.9% | KEV |
| 2026. 07. 16. |
| CVE-2026-39808 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here> | CRITICAL | 2026. 07. 16. |
| CVE-2026-46817 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C | CRITICAL | 2026. 07. 15. |
| CVE-2023-4346 | KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device. The BCU key feature on the devices can be used to create a password for the device, but this password can often not be reset without entering the current password. If the device is configured to interface with a network, an attacker with access to that network could interface with the KNX instal | HIGH | 2026. 07. 15. |
| — |
| 2023. 11. 08. |
| — |
| CVE-2023-22518 | All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an unauthenticated attacker to reset Confluence and create a Confluence instance administrator account. Using this account, an attacker can then perform all administrative actions that are available to Confluence instance administrator leading to - but not limited to - full loss of confidentiality, integrity and availability. Atlassian Cloud sites a | CRITICAL | 9.8v3.1 | 100 | 100.0% | KEV KISA | 2023. 10. 31. | 2023. 11. 07. | ⚠️ |
| CVE-2023-46604 | The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to either a Java-based OpenWire broker or client to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause either the client or the broker (respectively) to instantiate any class on the classpath. Users are recommended to upgrade both brokers and clients to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3 | CRITICAL | 10.0v3.1 | 100 | 99.7% | KEV KISA | 2023. 10. 27. | 2023. 11. 02. | ⚠️ |
| CVE-2023-46748 | An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which may allow an authenticated attacker with network access to the Configuration utility through the BIG-IP management port and/or self IP addresses to execute arbitrary system commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | HIGH | 8.8v3.1 | 100 | 4.5% | KEV | 2023. 10. 26. | 2023. 10. 31. | — |
| CVE-2023-46747 | Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | CRITICAL | 9.8v3.1 | 100 | 96.5% | KEV KISA | 2023. 10. 26. | 2023. 10. 31. | ⚠️ |
| CVE-2023-5631 | Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a remote attacker to load arbitrary JavaScript code. | MEDIUM | 6.1v3.1 | 91.50 | 75.9% | KEV | 2023. 10. 18. | 2023. 10. 26. | — |
| CVE-2023-20273 | A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges of root. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI. A successful exploit could allow the attacker to inject commands to the underlying operating system with root privileges. | HIGH | 7.2v3.1 | 100 | 89.6% | KEV | 2023. 10. 25. | 2023. 10. 23. | — |
| CVE-2023-4966 | Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. | CRITICAL | 9.4v3.1 | 100 | 100.0% | KEV KISA | 2023. 10. 10. | 2023. 10. 18. | ⚠️ |
| CVE-2023-20198 | Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are updating the list of fixed releases and adding the Software Checker. Our investigation has determined that the actors exploited two previously unknown issues. The attacker first exploited CVE-2023-20198 to gain initial access and issued a privilege 15 command to create a local user and password combination. This allowed the user to log in with normal user a | CRITICAL | 10.0v3.1 | 100 | 99.6% | KEV KISA | 2023. 10. 16. | 2023. 10. 16. | — |
| CVE-2023-41763 | Skype for Business Elevation of Privilege Vulnerability | MEDIUM | 5.3v3.1 | 79.50 | 90.4% | KEV KISA | 2023. 10. 10. | 2023. 10. 10. | — |
| CVE-2023-36563 | Microsoft WordPad Information Disclosure Vulnerability | MEDIUM | 6.5v3.1 | 97.50 | 20.7% | KEV KISA | 2023. 10. 10. | 2023. 10. 10. | — |
| CVE-2023-44487 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | HIGH | 7.5v3.1 | 100 | 100.0% | KEV KISA | 2023. 10. 10. | 2023. 10. 10. | — |
| CVE-2023-20109 | A vulnerability in the Cisco Group Encrypted Transport VPN (GET VPN) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker who has administrative control of either a group member or a key server to execute arbitrary code on an affected device or cause the device to crash. This vulnerability is due to insufficient validation of attributes in the Group Domain of Interpretation (GDOI) and G-IKEv2 protocols of the GET VPN feature. An attacker could | MEDIUM | 6.6v3.1 | 99 | 2.3% | KEV | 2023. 09. 27. | 2023. 10. 10. | — |
| CVE-2023-21608 | — | — | — | 82.50 | 61.5% | KEV | — | 2023. 10. 10. | — |
| CVE-2023-42824 | The issue was addressed with improved checks. This issue is fixed in iOS 16.7.1 and iPadOS 16.7.1. A local attacker may be able to elevate their privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.6. | HIGH | 7.8v3.1 | 100 | 0.9% | KEV KISA | 2023. 10. 04. | 2023. 10. 05. | — |
| CVE-2023-22515 | Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server instances to create unauthorized Confluence administrator accounts and access Confluence instances. Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this | CRITICAL | 9.8v3.1 | 100 | 99.2% | KEV | 2023. 10. 04. | 2023. 10. 05. | ⚠️ |
| CVE-2023-40044 | In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Transfer module to execute remote commands on the underlying WS_FTP Server operating system. | CRITICAL | 10.0v3.1 | 100 | 90.1% | KEV | 2023. 09. 27. | 2023. 10. 05. | ⚠️ |
| CVE-2023-42793 | In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible | CRITICAL | 9.8v3.1 | 100 | 100.0% | KEV | 2023. 09. 19. | 2023. 10. 04. | ⚠️ |
| CVE-2023-28229 | Windows CNG Key Isolation Service Elevation of Privilege Vulnerability | HIGH | 7.0v3.1 | 100 | 1.9% | KEV KISA | 2023. 04. 11. | 2023. 10. 04. | — |
| CVE-2023-4211 | A local non-privileged user can make improper GPU memory processing operations to gain access to already freed memory. | MEDIUM | 5.5v3.1 | 82.50 | 1.4% | KEV | 2023. 10. 01. | 2023. 10. 03. | — |