Vulnerabilities CISA has confirmed as actively exploited. Prioritize these for remediation.
Vulnerabilities newly added to CISA KEV in the last 7 days.
| CVE ID | Title | Severity | Added |
|---|---|---|---|
| Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | CRITICAL | 2026. 07. 16. | |
| A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests | CRITICAL |
| CVE ID | Title | Severity | References | Ransom | |||||
|---|---|---|---|---|---|---|---|---|---|
| Certificate validation bypass on Windows in crypto/x509 | — | — | 82.50 | 89.4% | KEV |
| 2026. 07. 16. |
| CVE-2026-39808 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here> | CRITICAL | 2026. 07. 16. |
| CVE-2026-46817 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C | CRITICAL | 2026. 07. 15. |
| CVE-2023-4346 | KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device. The BCU key feature on the devices can be used to create a password for the device, but this password can often not be reset without entering the current password. If the device is configured to interface with a network, an attacker with access to that network could interface with the KNX instal | HIGH | 2026. 07. 15. |
| 2022. 08. 01. |
| 2021. 11. 03. |
| — |
| CVE-2020-11651 | SaltStack Salt Unauthenticated Remote Code Execution | CRITICAL | 9.8v3.1 | 100 | 96.4% | KEV | 2022. 05. 24. | 2021. 11. 03. | — |
| CVE-2020-11652 | SaltStack Salt is vulnerable Arbitrary Directory Access | HIGH | 6.5v3.1 | 97.50 | 86.1% | KEV | 2022. 05. 24. | 2021. 11. 03. | — |
| CVE-2020-7961 | Deserialization of Untrusted Data in Liferay Portal | CRITICAL | 9.8v3.1 | 100 | 99.8% | KEV | 2022. 05. 24. | 2021. 11. 03. | — |
| CVE-2021-26084 | In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are before version 6.13.23, from version 6.14.0 before 7.4.11, from version 7.5.0 before 7.11.6, and from version 7.12.0 before 7.12.5. | CRITICAL | 9.8v3.1 | 100 | 100.0% | KEV | 2021. 08. 30. | 2021. 11. 03. | ⚠️ |
| CVE-2021-30869 | A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 12.5.5, iOS 14.4 and iPadOS 14.4, macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, Security Update 2021-006 Catalina. A malicious application may be able to execute arbitrary code with kernel privileges. Apple is aware of reports that an exploit for this issue exists in the wild. | HIGH | 7.8v3.1 | 100 | 4.2% | KEV | 2021. 08. 24. | 2021. 11. 03. | — |
| CVE-2021-30860 | An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. Processing a maliciously crafted PDF may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited. | HIGH | 7.8v3.1 | 100 | 76.0% | KEV | 2021. 08. 24. | 2021. 11. 03. | — |
| CVE-2021-30858 | A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited. | HIGH | 8.8v3.1 | 100 | 13.5% | KEV | 2021. 08. 24. | 2021. 11. 03. | — |
| CVE-2021-35395 | Realtek Jungle SDK version v2.x up to v3.4.14B provides an HTTP web server exposing a management interface that can be used to configure the access point. Two versions of this management interface exists: one based on Go-Ahead named webs and another based on Boa named boa. Both of them are affected by these vulnerabilities. Specifically, these binaries are vulnerable to the following issues: - stack buffer overflow in formRebootCheck due to unsafe copy of submit-url parameter - stack buffer over | CRITICAL | 9.8v3.1 | 100 | 98.0% | KEV | 2021. 08. 16. | 2021. 11. 03. | — |
| CVE-2021-36948 | Windows Update Medic Service Elevation of Privilege Vulnerability | HIGH | 7.8v3.1 | 100 | 19.9% | KEV | 2021. 08. 12. | 2021. 11. 03. | — |
| CVE-2021-36942 | Windows LSA Spoofing Vulnerability | HIGH | 7.5v3.1 | 100 | 66.0% | KEV | 2021. 08. 12. | 2021. 11. 03. | ⚠️ |
| CVE-2021-30563 | Type Confusion in V8 in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | HIGH | 8.8v3.1 | 100 | 8.9% | KEV | 2021. 08. 03. | 2021. 11. 03. | — |
| CVE-2021-22900 | A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an authenticated administrator to perform a file write via a maliciously crafted archive upload in the administrator web interface. | HIGH | 7.2v3.1 | 100 | 14.1% | KEV | 2021. 05. 27. | 2021. 11. 03. | — |
| CVE-2021-22899 | A command injection vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to perform remote code execution via Windows Resource Profiles Feature | HIGH | 8.8v3.1 | 100 | 22.3% | KEV | 2021. 05. 27. | 2021. 11. 03. | — |
| CVE-2021-22894 | A buffer overflow vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to execute arbitrary code as the root user via maliciously crafted meeting room. | HIGH | 8.8v3.1 | 100 | 41.3% | KEV | 2021. 05. 27. | 2021. 11. 03. | — |
| CVE-2021-21985 | The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server. | CRITICAL | 9.8v3.1 | 100 | 100.0% | KEV | 2021. 05. 26. | 2021. 11. 03. | ⚠️ |
| CVE-2021-27562 | In Arm Trusted Firmware M through 1.2, the NS world may trigger a system halt, an overwrite of secure data, or the printing out of secure data when calling secure functions under the NSPE handler mode. | MEDIUM | 5.5v3.1 | 82.50 | 3.1% | KEV | 2021. 05. 25. | 2021. 11. 03. | — |
| CVE-2021-31207 | Microsoft Exchange Server Security Feature Bypass Vulnerability | MEDIUM | 6.6v3.1 | 100 | 99.8% | KEV KISA | 2021. 05. 11. | 2021. 11. 03. | ⚠️ |
| CVE-2021-28664 | The Arm Mali GPU kernel driver allows privilege escalation or a denial of service (memory corruption) because an unprivileged user can achieve read/write access to read-only pages. This affects Bifrost r0p0 through r29p0 before r30p0, Valhall r19p0 through r29p0 before r30p0, and Midgard r8p0 through r30p0 before r31p0. | HIGH | 8.8v3.1 | 100 | 5.5% | KEV | 2021. 05. 10. | 2021. 11. 03. | — |
| CVE-2021-28663 | The Arm Mali GPU kernel driver allows privilege escalation or information disclosure because GPU memory operations are mishandled, leading to a use-after-free. This affects Bifrost r0p0 through r28p0 before r29p0, Valhall r19p0 through r28p0 before r29p0, and Midgard r4p0 through r30p0. | HIGH | 8.8v3.1 | 100 | 12.1% | KEV | 2021. 05. 10. | 2021. 11. 03. | — |