Vulnerabilities CISA has confirmed as actively exploited. Prioritize these for remediation.
Vulnerabilities newly added to CISA KEV in the last 7 days.
| CVE ID | Title | Severity | Added |
|---|---|---|---|
| Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | CRITICAL | 2026. 07. 16. | |
| A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests | CRITICAL |
| CVE ID | Title | Severity | References | Ransom | |||||
|---|---|---|---|---|---|---|---|---|---|
| RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because a ZIP archive may include a benign file (such as an ordinary .JPG file) and also a folder that has the same name as the benign file, and the contents of the folder (which may include executable content) are processed during an attempt to access only the benign file. This was exploited in the wild in April through October 2023. | HIGH | 7.8 |
| 2026. 07. 16. |
| CVE-2026-39808 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here> | CRITICAL | 2026. 07. 16. |
| CVE-2026-46817 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C | CRITICAL | 2026. 07. 15. |
| CVE-2023-4346 | KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device. The BCU key feature on the devices can be used to create a password for the device, but this password can often not be reset without entering the current password. If the device is configured to interface with a network, an attacker with access to that network could interface with the KNX instal | HIGH | 2026. 07. 15. |
100 |
97.8% |
KEV KISA |
| 2023. 08. 23. |
| 2023. 08. 24. |
| ⚠️ |
| CVE-2023-32315 | Administration Console authentication bypass in openfire xmppserver | HIGH | 8.6v3.1 | 100 | 100.0% | KEV | 2023. 05. 23. | 2023. 08. 24. | — |
| CVE-2023-38035 | A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTTPD configuration. | CRITICAL | 9.8v3.1 | 100 | 99.9% | KEV | 2023. 08. 21. | 2023. 08. 22. | ⚠️ |
| CVE-2023-27532 | Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained. This may lead to gaining access to the backup infrastructure hosts. | HIGH | 7.5v3.1 | 100 | 77.6% | KEV | 2023. 03. 10. | 2023. 08. 22. | ⚠️ |
| CVE-2023-26359 | Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. | CRITICAL | 9.8v3.1 | 100 | 17.9% | KEV KISA | 2023. 03. 23. | 2023. 08. 21. | — |
| CVE-2023-24489 | A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated attacker to remotely compromise the customer-managed ShareFile storage zones controller. | CRITICAL | 9.8v3.1 | 100 | 95.1% | KEV | 2023. 07. 10. | 2023. 08. 16. | — |
| CVE-2023-38180 | .NET and Visual Studio Denial of Service Vulnerability | HIGH | 7.5v3.1 | 100 | 14.7% | KEV KISA | 2023. 08. 08. | 2023. 08. 09. | — |
| CVE-2017-18368 | — | — | — | 82.50 | 94.5% | KEV | — | 2023. 08. 07. | — |
| CVE-2023-35081 | A path traversal vulnerability in Ivanti EPMM versions (11.10.x < 11.10.0.3, 11.9.x < 11.9.1.2 and 11.8.x < 11.8.1.2) allows an authenticated administrator to write arbitrary files onto the appliance. | HIGH | 7.2v3.1 | 100 | 63.3% | KEV | 2023. 08. 03. | 2023. 07. 31. | — |
| CVE-2023-37580 | Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client. | MEDIUM | 6.1v3.1 | 91.50 | 60.0% | KEV | 2023. 07. 31. | 2023. 07. 27. | — |
| CVE-2023-38606 | This issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.6.8, iOS 15.7.8 and iPadOS 15.7.8, iOS 16.6 and iPadOS 16.6, tvOS 16.6, macOS Big Sur 11.7.9, macOS Ventura 13.5, watchOS 9.6. An app may be able to modify sensitive kernel state. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7.1. | MEDIUM | 5.5v3.1 | 82.50 | 1.0% | KEV | 2023. 07. 27. | 2023. 07. 26. | — |
| CVE-2023-35078 | An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication. | CRITICAL | 9.8v3.1 | 100 | 100.0% | KEV | 2023. 07. 25. | 2023. 07. 25. | ⚠️ |
| CVE-2023-38205 | Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access the administration CFM and CFC endpoints. Exploitation of this issue does not require user interaction. | HIGH | 7.5v3.1 | 100 | 99.8% | KEV KISA | 2023. 09. 14. | 2023. 07. 20. | — |
| CVE-2023-29298 | Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access the administration CFM and CFC endpoints. Exploitation of this issue does not require user interaction. | HIGH | 7.5v3.1 | 100 | 99.8% | KEV KISA | 2023. 07. 12. | 2023. 07. 20. | — |
| CVE-2023-3519 | Unauthenticated remote code execution | CRITICAL | 9.8v3.1 | 100 | 99.7% | KEV KISA | 2023. 07. 19. | 2023. 07. 19. | ⚠️ |
| CVE-2023-36884 | Windows Search Remote Code Execution Vulnerability | HIGH | 7.5v3.1 | 100 | 99.0% | KEV KISA | 2023. 07. 11. | 2023. 07. 17. | ⚠️ |
| CVE-2023-37450 | The issue was addressed with improved checks. This issue is fixed in iOS 16.6 and iPadOS 16.6, Safari 16.5.2, tvOS 16.6, macOS Ventura 13.5, watchOS 9.6. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited. | HIGH | 8.8v3.1 | 100 | 18.9% | KEV KISA | 2023. 07. 27. | 2023. 07. 13. | — |
| CVE-2022-29303 | — | — | — | 82.50 | 98.0% | KEV | — | 2023. 07. 13. | — |
| CVE-2023-36874 | Windows Error Reporting Service Elevation of Privilege Vulnerability | HIGH | 7.8v3.1 | 100 | 42.6% | KEV KISA | 2023. 07. 11. | 2023. 07. 11. | — |
| CVE-2023-35311 | Microsoft Outlook Security Feature Bypass Vulnerability | HIGH | 8.8v3.1 | 100 | 15.5% | KEV KISA | 2023. 07. 11. | 2023. 07. 11. | — |