Vulnerabilities CISA has confirmed as actively exploited. Prioritize these for remediation.
Vulnerabilities newly added to CISA KEV in the last 7 days.
| CVE ID | Title | Severity | Added |
|---|---|---|---|
| Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | CRITICAL | 2026. 07. 16. | |
| A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests | CRITICAL |
| CVE ID | Title | Severity | References | Ransom | |||||
|---|---|---|---|---|---|---|---|---|---|
| An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX (with default API key) is vulnerable to remote code execution. When the admin key was changed or the port of Admin API was changed to a port different from the data panel, the impact is lower. But there is still a risk to bypass the IP restriction of Apache APISIX's data panel. There is a check in the batch-requests plugin which overrides the client | CRITICAL |
| 2026. 07. 16. |
| CVE-2026-39808 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here> | CRITICAL | 2026. 07. 16. |
| CVE-2026-46817 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C | CRITICAL | 2026. 07. 15. |
| CVE-2023-4346 | KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device. The BCU key feature on the devices can be used to create a password for the device, but this password can often not be reset without entering the current password. If the device is configured to interface with a network, an attacker with access to that network could interface with the KNX instal | HIGH | 2026. 07. 15. |
100 |
96.2% |
KEV |
| 2022. 02. 11. |
| 2022. 08. 25. |
| — |
| CVE-2021-39226 | Authentication bypass for viewing and deletions of snapshots | HIGH | 7.3v3.1 | 100 | 99.9% | KEV | 2021. 10. 05. | 2022. 08. 25. | — |
| CVE-2021-31010 | A deserialization issue was addressed through improved validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 12.5.5, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. A sandboxed process may be able to circumvent sandbox restrictions. Apple was aware of a report that this issue may have been actively exploited at the time of release.. | HIGH | 7.5v3.1 | 100 | 3.7% | KEV | 2021. 08. 24. | 2022. 08. 25. | — |
| CVE-2020-36193 | Directory Traversal in Archive_Tar | HIGH | 7.5v3.1 | 100 | 70.6% | KEV | 2021. 04. 22. | 2022. 08. 25. | — |
| CVE-2020-28949 | Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed. | HIGH | 7.8v3.1 | 100 | 84.6% | KEV | 2020. 11. 19. | 2022. 08. 25. | — |
| CVE-2021-38406 | — | — | — | 82.50 | 77.9% | KEV | — | 2022. 08. 25. | — |
| CVE-2022-0028 | A PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified TCP denial-of-service (RDoS) attacks. The DoS attack would appear to originate from a Palo Alto Networks PA-Series (hardware), VM-Series (virtual) and CN-Series (container) firewall against an attacker-specified target. To be misused by an external attacker, the firewall configuration must have a URL filtering profile with one or more blocked categories assigned to a source zone | HIGH | 8.6v3.1 | 100 | 2.1% | KEV | 2022. 08. 10. | 2022. 08. 22. | — |
| CVE-2022-32894 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey 12.5.1. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited. | HIGH | 7.8v3.1 | 100 | 3.3% | KEV | 2022. 08. 24. | 2022. 08. 18. | — |
| CVE-2022-32893 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey 12.5.1, Safari 15.6.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited. | HIGH | 8.8v3.1 | 100 | 9.8% | KEV | 2022. 08. 24. | 2022. 08. 18. | — |
| CVE-2022-22536 | SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable for request smuggling and request concatenation. An unauthenticated attacker can prepend a victim's request with arbitrary data. This way, the attacker can execute functions impersonating the victim or poison intermediary Web caches. A successful attack could result in complete compromise of Confidentiality, Integrity and Availability of the s | CRITICAL | 10.0v3.1 | 100 | 97.9% | KEV | 2022. 02. 09. | 2022. 08. 18. | — |
| CVE-2022-21971 | Windows Runtime Remote Code Execution Vulnerability | HIGH | 7.8v3.1 | 100 | 53.7% | KEV | 2022. 02. 09. | 2022. 08. 18. | — |
| CVE-2017-15944 | Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote attackers to execute arbitrary code via vectors involving the management interface. | CRITICAL | 9.8v3.1 | 100 | 98.3% | KEV | 2017. 12. 11. | 2022. 08. 18. | — |
| CVE-2022-26923 | — | — | — | 82.50 | 83.3% | KEV KISA | — | 2022. 08. 18. | — |
| CVE-2022-2856 | — | — | — | 82.50 | 4.5% | KEV | — | 2022. 08. 18. | — |
| CVE-2022-37042 | Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing authentication (i.e., not having an authtoken), an attacker can upload arbitrary files to the system, leading to directory traversal and remote code execution. NOTE: this issue exists because of an incomplete fix for CVE-2022-27925. | CRITICAL | 9.8v3.1 | 100 | 88.8% | KEV | 2022. 08. 12. | 2022. 08. 11. | ⚠️ |
| CVE-2022-27925 | Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, leading to directory traversal. | HIGH | 7.2v3.1 | 100 | 98.6% | KEV | 2022. 04. 21. | 2022. 08. 11. | ⚠️ |
| CVE-2022-34713 | Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability | HIGH | 7.8v3.1 | 100 | 68.0% | KEV | 2022. 08. 09. | 2022. 08. 09. | — |
| CVE-2022-30333 | — | — | — | 87.50 | 99.0% | KEV | — | 2022. 08. 09. | ⚠️ |
| CVE-2022-27924 | Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance. These memcache commands becomes unescaped, causing an overwrite of arbitrary cached entries. | HIGH | 7.5v3.1 | 100 | 85.4% | KEV | 2022. 04. 21. | 2022. 08. 04. | ⚠️ |
| CVE-2022-26138 | The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, unauthenticated attacker with knowledge of the hardcoded password could exploit this to log into Confluence and access all content accessible to users in the confluence-users group. This user account is created when installing versions 2.7.34, 2.7.35, and 3.0.2 of the app. | CRITICAL | 9.8v3.1 | 100 | 98.2% | KEV | 2022. 07. 20. | 2022. 07. 29. | — |