Vulnerabilities CISA has confirmed as actively exploited. Prioritize these for remediation.
Vulnerabilities newly added to CISA KEV in the last 7 days.
| CVE ID | Title | Severity | Added |
|---|---|---|---|
| Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | CRITICAL | 2026. 07. 16. | |
| A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests | CRITICAL |
| CVE ID | Title | Severity | References | Ransom | |||||
|---|---|---|---|---|---|---|---|---|---|
| Windows SmartScreen Security Feature Bypass Vulnerability | HIGH | 8.8v3.1 | 100 | 4.4% |
| 2026. 07. 16. |
| CVE-2026-39808 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here> | CRITICAL | 2026. 07. 16. |
| CVE-2026-46817 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C | CRITICAL | 2026. 07. 15. |
| CVE-2023-4346 | KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device. The BCU key feature on the devices can be used to create a password for the device, but this password can often not be reset without entering the current password. If the device is configured to interface with a network, an attacker with access to that network could interface with the KNX instal | HIGH | 2026. 07. 15. |
KEV KISA |
| 2023. 07. 11. |
| 2023. 07. 11. |
| — |
| CVE-2023-32046 | Windows MSHTML Platform Elevation of Privilege Vulnerability | HIGH | 7.8v3.1 | 100 | 10.3% | KEV KISA | 2023. 07. 11. | 2023. 07. 11. | — |
| CVE-2022-31199 | — | — | — | 87.50 | 36.0% | KEV | — | 2023. 07. 11. | ⚠️ |
| CVE-2021-29256 | . The Arm Mali GPU kernel driver allows an unprivileged user to achieve access to freed memory, leading to information disclosure or root privilege escalation. This affects Bifrost r16p0 through r29p0 before r30p0, Valhall r19p0 through r29p0 before r30p0, and Midgard r28p0 through r30p0. | HIGH | 8.8v3.1 | 100 | 3.0% | KEV | 2021. 05. 24. | 2023. 07. 07. | — |
| CVE-2019-20500 | D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Save Configuration functionality in the Web interface, using shell metacharacters in the admin.cgi?action=config_save configBackup or downloadServerip parameter. | HIGH | 7.8v3.1 | 100 | 97.1% | KEV | 2020. 03. 05. | 2023. 06. 29. | — |
| CVE-2019-17621 | The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system commands as root, by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connecting to the local network. | CRITICAL | 9.8v3.1 | 100 | 89.6% | KEV | 2019. 12. 30. | 2023. 06. 29. | — |
| CVE-2021-25487 | — | — | — | 82.50 | 0.6% | KEV | — | 2023. 06. 29. | — |
| CVE-2021-25371 | — | — | — | 82.50 | 0.8% | KEV | — | 2023. 06. 29. | — |
| CVE-2021-25395 | — | — | — | 82.50 | 0.4% | KEV | — | 2023. 06. 29. | — |
| CVE-2021-25489 | — | — | — | 82.50 | 0.5% | KEV | — | 2023. 06. 29. | — |
| CVE-2021-25394 | — | — | — | 82.50 | 0.4% | KEV | — | 2023. 06. 29. | — |
| CVE-2021-25372 | — | — | — | 82.50 | 0.8% | KEV | — | 2023. 06. 29. | — |
| CVE-2023-32439 | — | — | — | 82.50 | 23.8% | KEV | — | 2023. 06. 23. | — |
| CVE-2023-20867 | — | — | — | 82.50 | 13.5% | KEV KISA | — | 2023. 06. 23. | — |
| CVE-2023-32434 | — | — | — | 82.50 | 51.5% | KEV KISA | — | 2023. 06. 23. | — |
| CVE-2023-27992 | — | — | — | 82.50 | 84.2% | KEV | — | 2023. 06. 23. | — |
| CVE-2023-32435 | — | — | — | 82.50 | 23.0% | KEV | — | 2023. 06. 23. | — |
| CVE-2020-35730 | An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mail message, with JavaScript in a link reference element that is mishandled by linkref_addindex in rcube_string_replacer.php. | MEDIUM | 6.1v3.1 | 91.50 | 32.8% | KEV | 2020. 12. 28. | 2023. 06. 22. | — |
| CVE-2016-0165 | The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0143 and CVE-2016-0167. | HIGH | 7.8v3.1 | 100 | 13.8% | KEV | 2016. 04. 12. | 2023. 06. 22. | — |
| CVE-2021-44026 | — | — | — | 82.50 | 42.8% | KEV | — | 2023. 06. 22. | — |