Vulnerabilities CISA has confirmed as actively exploited. Prioritize these for remediation.
Vulnerabilities newly added to CISA KEV in the last 7 days.
| CVE ID | Title | Severity | Added |
|---|---|---|---|
| Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | CRITICAL | 2026. 07. 16. | |
| A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests | CRITICAL |
| CVE ID | Title | Severity | References | Ransom | |||||
|---|---|---|---|---|---|---|---|---|---|
| — | — | — | 82.50 | 98.3% | KEV |
| 2026. 07. 16. |
| CVE-2026-39808 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here> | CRITICAL | 2026. 07. 16. |
| CVE-2026-46817 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C | CRITICAL | 2026. 07. 15. |
| CVE-2023-4346 | KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device. The BCU key feature on the devices can be used to create a password for the device, but this password can often not be reset without entering the current password. If the device is configured to interface with a network, an attacker with access to that network could interface with the KNX instal | HIGH | 2026. 07. 15. |
| — |
| 2023. 06. 22. |
| — |
| CVE-2016-9079 | — | — | — | 82.50 | 87.6% | KEV | — | 2023. 06. 22. | — |
| CVE-2020-12641 | — | — | — | 82.50 | 84.5% | KEV | — | 2023. 06. 22. | — |
| CVE-2023-27997 | — | — | — | 87.50 | 85.7% | KEV KISA | — | 2023. 06. 13. | ⚠️ |
| CVE-2023-3079 | — | — | — | 82.50 | 32.7% | KEV KISA | — | 2023. 06. 07. | — |
| CVE-2023-33009 | — | — | — | 82.50 | 28.1% | KEV KISA | — | 2023. 06. 05. | — |
| CVE-2023-33010 | — | — | — | 82.50 | 28.8% | KEV KISA | — | 2023. 06. 05. | — |
| CVE-2023-34362 | — | — | — | 87.50 | 99.9% | KEV KISA | — | 2023. 06. 02. | ⚠️ |
| CVE-2023-28771 | — | — | — | 82.50 | 99.3% | KEV KISA | — | 2023. 05. 31. | — |
| CVE-2023-2868 | — | — | — | 82.50 | 87.0% | KEV KISA | — | 2023. 05. 26. | — |
| CVE-2023-28204 | — | — | — | 82.50 | 14.3% | KEV | — | 2023. 05. 22. | — |
| CVE-2023-32373 | — | — | — | 82.50 | 12.2% | KEV | — | 2023. 05. 22. | — |
| CVE-2023-32409 | — | — | — | 82.50 | 16.5% | KEV | — | 2023. 05. 22. | — |
| CVE-2016-6415 | The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x and 5.0.x through 5.2.x, and PIX before 7.0 allows remote attackers to obtain sensitive information from device memory via a Security Association (SA) negotiation request, aka Bug IDs CSCvb29204 and CSCvb36055 or BENIGNCERTAIN. | HIGH | 7.5v3.1 | 100 | 87.3% | KEV KISA | 2016. 09. 19. | 2023. 05. 19. | — |
| CVE-2004-1464 | Cisco IOS 12.2(15) and earlier allows remote attackers to cause a denial of service (refused VTY (virtual terminal) connections), via a crafted TCP connection to the Telnet or reverse Telnet port. | MEDIUM | 5.9v3.1 | 88.50 | 5.1% | KEV | 2004. 12. 31. | 2023. 05. 19. | — |
| CVE-2023-21492 | — | — | — | 82.50 | 2.6% | KEV | — | 2023. 05. 19. | — |
| CVE-2023-25717 | Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated by a /forms/doLogin?login_username=admin&password=password$(curl substring. | CRITICAL | 9.8v3.1 | 100 | 98.1% | KEV KISA | 2023. 02. 13. | 2023. 05. 12. | — |
| CVE-2021-3560 | It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user. This flaw could be used by an unprivileged local attacker to, for example, create a new local administrator. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. | HIGH | 7.8v3.1 | 100 | 22.2% | KEV | 2022. 02. 16. | 2023. 05. 12. | — |
| CVE-2016-8735 | Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types. | CRITICAL | 9.8v3.1 | 100 | 90.3% | KEV | 2017. 04. 06. | 2023. 05. 12. | — |
| CVE-2016-3427 | Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX. | CRITICAL | 9.8v3.1 | 100 | 92.3% | KEV | 2016. 04. 21. | 2023. 05. 12. | — |