Vulnerabilities CISA has confirmed as actively exploited. Prioritize these for remediation.
Vulnerabilities newly added to CISA KEV in the last 7 days.
| CVE ID | Title | Severity | Added |
|---|---|---|---|
| Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | CRITICAL | 2026. 07. 16. | |
| A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests | CRITICAL |
| CVE ID | Title | Severity | References | Ransom | |||||
|---|---|---|---|---|---|---|---|---|---|
| — | — | — | 82.50 | 41.8% | KEV |
| 2026. 07. 16. |
| CVE-2026-39808 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here> | CRITICAL | 2026. 07. 16. |
| CVE-2026-46817 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C | CRITICAL | 2026. 07. 15. |
| CVE-2023-4346 | KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device. The BCU key feature on the devices can be used to create a password for the device, but this password can often not be reset without entering the current password. If the device is configured to interface with a network, an attacker with access to that network could interface with the KNX instal | HIGH | 2026. 07. 15. |
| — |
| 2023. 01. 10. |
| — |
| CVE-2018-18809 | The default server implementation of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library Community Edition, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a directory-traversal vulnerability that may theoretically allow web server users to | MEDIUM | 6.5v3.1 | 97.50 | 79.1% | KEV | 2019. 03. 07. | 2022. 12. 29. | — |
| CVE-2018-5430 | The Spring web flows of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contain a vulnerability which may allow any authenticated user read-only access to the contents of the web application, including key configuration files. Affected releases include TIBCO Software Inc.'s TIBCO JasperReports Server: ve | HIGH | 8.8v3.1 | 100 | 48.8% | KEV | 2018. 04. 17. | 2022. 12. 29. | — |
| CVE-2022-42856 | — | — | — | 82.50 | 8.5% | KEV | — | 2022. 12. 14. | — |
| CVE-2022-44698 | Windows SmartScreen Security Feature Bypass Vulnerability | MEDIUM | 5.4v3.1 | 86 | 76.1% | KEV | 2022. 12. 13. | 2022. 12. 13. | ⚠️ |
| CVE-2022-27518 | Unauthenticated remote arbitrary code execution | CRITICAL | 9.8v3.1 | 100 | 6.9% | KEV | 2022. 12. 13. | 2022. 12. 13. | — |
| CVE-2022-26501 | Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2). | CRITICAL | 9.8v3.1 | 100 | 4.3% | KEV | 2022. 03. 17. | 2022. 12. 13. | ⚠️ |
| CVE-2022-26500 | Improper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote authenticated users access to internal API functions that allows attackers to upload and execute arbitrary code. | HIGH | 8.8v3.1 | 100 | 5.9% | KEV | 2022. 03. 17. | 2022. 12. 13. | ⚠️ |
| CVE-2022-42475 | — | — | — | 87.50 | 99.5% | KEV KISA | — | 2022. 12. 13. | ⚠️ |
| CVE-2022-4262 | Type confusion in V8 in Google Chrome prior to 108.0.5359.94 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | HIGH | 8.8v3.1 | 100 | 16.1% | KEV | 2022. 12. 02. | 2022. 12. 05. | — |
| CVE-2022-4135 | Heap buffer overflow in GPU | CRITICAL | 9.6v3.1 | 100 | 31.9% | KEV | 2022. 11. 25. | 2022. 11. 28. | — |
| CVE-2021-35587 | — | — | — | 82.50 | 96.3% | KEV KISA | — | 2022. 11. 28. | — |
| CVE-2022-41049 | — | — | — | 82.50 | 2.5% | KEV | — | 2022. 11. 14. | — |
| CVE-2022-41128 | — | — | — | 82.50 | 24.6% | KEV | — | 2022. 11. 08. | — |
| CVE-2021-25370 | — | — | — | 82.50 | 0.9% | KEV | — | 2022. 11. 08. | — |
| CVE-2022-41125 | — | — | — | 82.50 | 3.0% | KEV | — | 2022. 11. 08. | — |
| CVE-2022-41073 | — | — | — | 87.50 | 2.4% | KEV | — | 2022. 11. 08. | ⚠️ |
| CVE-2022-41091 | — | — | — | 87.50 | 2.0% | KEV | — | 2022. 11. 08. | ⚠️ |
| CVE-2021-25337 | — | — | — | 82.50 | 2.8% | KEV | — | 2022. 11. 08. | — |
| CVE-2021-25369 | — | — | — | 82.50 | 1.1% | KEV | — | 2022. 11. 08. | — |