Vulnerabilities CISA has confirmed as actively exploited. Prioritize these for remediation.
Vulnerabilities newly added to CISA KEV in the last 7 days.
| CVE ID | Title | Severity | Added |
|---|---|---|---|
| Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | CRITICAL | 2026. 07. 16. | |
| A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests | CRITICAL |
| CVE ID | Title | Severity | References | Ransom | |||||
|---|---|---|---|---|---|---|---|---|---|
| Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | HIGH | 8.8v3.1 | 100 |
| 2026. 07. 16. |
| CVE-2026-39808 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here> | CRITICAL | 2026. 07. 16. |
| CVE-2026-46817 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C | CRITICAL | 2026. 07. 15. |
| CVE-2023-4346 | KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device. The BCU key feature on the devices can be used to create a password for the device, but this password can often not be reset without entering the current password. If the device is configured to interface with a network, an attacker with access to that network could interface with the KNX instal | HIGH | 2026. 07. 15. |
49.0% |
KEV KISA |
| 2023. 09. 28. |
| 2023. 10. 02. |
| — |
| CVE-2018-14667 | The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticated attacker could exploit this to execute arbitrary code using a chain of java serialized objects via org.ajax4jsf.resource.UserResource$UriData. | CRITICAL | 9.8v3.1 | 100 | 74.2% | KEV | 2018. 11. 06. | 2023. 09. 28. | — |
| CVE-2023-41993 | The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7. | HIGH | 8.8v3.1 | 100 | 29.2% | KEV KISA | 2023. 09. 21. | 2023. 09. 25. | — |
| CVE-2023-41992 | The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7, iOS 16.7 and iPadOS 16.7, macOS Ventura 13.6. A local attacker may be able to elevate their privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7. | HIGH | 7.8v3.1 | 100 | 2.9% | KEV KISA | 2023. 09. 21. | 2023. 09. 25. | — |
| CVE-2023-41991 | A certificate validation issue was addressed. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7. A malicious app may be able to bypass signature validation. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7. | MEDIUM | 5.5v3.1 | 82.50 | 4.5% | KEV KISA | 2023. 09. 21. | 2023. 09. 25. | — |
| CVE-2023-41179 | A vulnerability in the 3rd party AV uninstaller module contained in Trend Micro Apex One (on-prem and SaaS), Worry-Free Business Security and Worry-Free Business Security Services could allow an attacker to manipulate the module to execute arbitrary commands on an affected installation. Note that an attacker must first obtain administrative console access on the target system in order to exploit this vulnerability. | HIGH | 7.2v3.1 | 100 | 4.7% | KEV | 2023. 09. 19. | 2023. 09. 21. | — |
| CVE-2023-28434 | Minio is a Multi-Cloud Object Storage framework. Prior to RELEASE.2023-03-20T20-16-18Z, an attacker can use crafted requests to bypass metadata bucket name checking and put an object into any bucket while processing `PostPolicyBucket`. To carry out this attack, the attacker requires credentials with `arn:aws:s3:::*` permission, as well as enabled Console API access. This issue has been patched in RELEASE.2023-03-20T20-16-18Z. As a workaround, enable browser API access and turn off `MINIO_BROWSER | HIGH | 8.8v3.1 | 100 | 6.7% | KEV KISA | 2023. 03. 22. | 2023. 09. 19. | — |
| CVE-2021-3129 | Unauthenticated remote code execution in Ignition | CRITICAL | 9.8v3.1 | 100 | 99.9% | KEV | 2021. 03. 29. | 2023. 09. 18. | ⚠️ |
| CVE-2017-6884 | A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8. The vulnerability is located in the diagnostic tools, specifically the nslookup function. A malicious user may exploit numerous vectors to execute arbitrary commands on the router, such as the ping_ip parameter to the expert/maintenance/diagnostic/nslookup URI. | HIGH | 8.8v3.1 | 100 | 37.6% | KEV | 2017. 04. 06. | 2023. 09. 18. | ⚠️ |
| CVE-2014-8361 | The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023. | CRITICAL | 9.8v3.1 | 100 | 100.0% | KEV | 2015. 05. 01. | 2023. 09. 18. | — |
| CVE-2022-22265 | — | — | — | 82.50 | 0.4% | KEV | — | 2023. 09. 18. | — |
| CVE-2023-26369 | Acrobat Reader versions 23.003.20284 (and earlier), 20.005.30516 (and earlier) and 20.005.30514 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | HIGH | 7.8v3.1 | 100 | 7.0% | KEV | 2023. 09. 13. | 2023. 09. 14. | — |
| CVE-2023-4863 | Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical) | HIGH | 8.8v3.1 | 100 | 99.7% | KEV KISA | 2023. 09. 12. | 2023. 09. 13. | — |
| CVE-2023-35674 | In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | HIGH | 7.8v3.1 | 100 | 2.2% | KEV | 2023. 09. 11. | 2023. 09. 13. | — |
| CVE-2023-20269 | A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a brute force attack in an attempt to identify valid username and password combinations or an authenticated, remote attacker to establish a clientless SSL VPN session with an unauthorized user. This vulnerability is due to improper separation of authentication, authorization, and accoun | MEDIUM | 5.0v3.1 | 80 | 21.6% | KEV | 2023. 09. 06. | 2023. 09. 13. | ⚠️ |
| CVE-2023-36802 | Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability | HIGH | 7.8v3.1 | 100 | 26.1% | KEV KISA | 2023. 09. 12. | 2023. 09. 12. | — |
| CVE-2023-36761 | Microsoft Word Information Disclosure Vulnerability | MEDIUM | 6.5v3.1 | 97.50 | 19.0% | KEV KISA | 2023. 09. 12. | 2023. 09. 12. | — |
| CVE-2023-41064 | A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 16.6.1 and iPadOS 16.6.1, macOS Monterey 12.6.9, macOS Ventura 13.5.2, iOS 15.7.9 and iPadOS 15.7.9, macOS Big Sur 11.7.10. Processing a maliciously crafted image may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited. | HIGH | 7.8v3.1 | 100 | 15.3% | KEV | 2023. 09. 07. | 2023. 09. 11. | — |
| CVE-2023-41061 | A validation issue was addressed with improved logic. This issue is fixed in watchOS 9.6.2, iOS 16.6.1 and iPadOS 16.6.1. A maliciously crafted attachment may result in arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited. | HIGH | 7.8v3.1 | 100 | 3.2% | KEV | 2023. 09. 07. | 2023. 09. 11. | — |
| CVE-2023-33246 | Apache RocketMQ may have remote code execution vulnerability when using update configuration function | CRITICAL | 9.8v3.1 | 100 | 96.6% | KEV | 2023. 07. 06. | 2023. 09. 06. | — |