Vulnerabilities CISA has confirmed as actively exploited. Prioritize these for remediation.
Vulnerabilities newly added to CISA KEV in the last 7 days.
| CVE ID | Title | Severity | Added |
|---|---|---|---|
| Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | CRITICAL | 2026. 07. 16. | |
| A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests | CRITICAL |
| CVE ID | Title | Severity | References | Ransom | |||||
|---|---|---|---|---|---|---|---|---|---|
| The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands via a crafted serialized Java object in T3 protocol traffic to TCP port 7001, related to oracle_common/modules/com.bea.core.apache.commons.collections.jar. NOTE: the scope of this CVE is limited to the WebLogic Server product. | CRITICAL | 9.8v3.1 |
| 2026. 07. 16. |
| CVE-2026-39808 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here> | CRITICAL | 2026. 07. 16. |
| CVE-2026-46817 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C | CRITICAL | 2026. 07. 15. |
| CVE-2023-4346 | KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device. The BCU key feature on the devices can be used to create a password for the device, but this password can often not be reset without entering the current password. If the device is configured to interface with a network, an attacker with access to that network could interface with the KNX instal | HIGH | 2026. 07. 15. |
96.0% |
KEV |
| 2015. 11. 18. |
| 2021. 11. 03. |
| — |
| CVE-2015-1641 | Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2 and 2013 SP1, and Office Web Apps Server 2010 SP2 and 2013 SP1 allow remote attackers to execute arbitrary code via a crafted RTF document, aka "Microsoft Office Memory Corruption Vulnerability." | HIGH | 7.8v3.1 | 100 | 96.8% | KEV | 2015. 04. 14. | 2021. 11. 03. | — |
| CVE-2014-1812 | The Group Policy implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 does not properly handle distribution of passwords, which allows remote authenticated users to obtain sensitive credential information and consequently gain privileges by leveraging access to the SYSVOL share, as exploited in the wild in May 2014, aka "Group Policy Preferences Password Elevation of Privilege Vulnerability." | HIGH | 8.8v3.1 | 100 | 65.1% | KEV KISA | 2014. 05. 14. | 2021. 11. 03. | ⚠️ |
| CVE-2012-3152 | Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and 11.1.2.0 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Report Server Component. NOTE: the previous information is from the October 2012 CPU. Oracle has not commented on claims from the original researcher that the URLPARAMETER functionality allows remote attackers to read and upload arbitrary files to reports/rwservlet, and that | CRITICAL | 9.1v3.1 | 100 | 98.7% | KEV | 2012. 10. 16. | 2021. 11. 03. | — |
| CVE-2012-0158 | The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2003 Web Components SP3; SQL Server 2000 SP4, 2005 SP4, and 2008 SP2, SP3, and R2; BizTalk Server 2002 SP1; Commerce Server 2002 SP4, 2007 SP2, and 2009 Gold and R2; Visual FoxPro 8.0 SP1 and 9.0 SP2; and Visual Basic 6.0 Runtime allow remote attackers to execute arbitrary code via a crafted (a) web | HIGH | 8.8v3.1 | 100 | 100.0% | KEV KISA | 2012. 04. 10. | 2021. 11. 03. | — |
| CVE-2021-20016 | — | — | — | 87.50 | 40.0% | KEV | — | 2021. 11. 03. | ⚠️ |
| CVE-2020-3569 | — | — | — | 82.50 | 3.3% | KEV | — | 2021. 11. 03. | — |
| CVE-2020-3118 | — | — | — | 82.50 | 11.7% | KEV | — | 2021. 11. 03. | — |
| CVE-2021-1879 | — | — | — | 82.50 | 7.1% | KEV | — | 2021. 11. 03. | — |
| CVE-2021-1871 | — | — | — | 82.50 | 7.1% | KEV | — | 2021. 11. 03. | — |
| CVE-2021-1870 | — | — | — | 82.50 | 7.9% | KEV | — | 2021. 11. 03. | — |
| CVE-2021-1732 | — | — | — | 87.50 | 78.4% | KEV | — | 2021. 11. 03. | ⚠️ |
| CVE-2019-3398 | — | — | — | 82.50 | 97.2% | KEV | — | 2021. 11. 03. | — |
| CVE-2021-1675 | — | — | — | 87.50 | 86.1% | KEV | — | 2021. 11. 03. | ⚠️ |
| CVE-2021-1647 | — | — | — | 82.50 | 39.7% | KEV | — | 2021. 11. 03. | — |
| CVE-2020-8655 | — | — | — | 82.50 | 58.1% | KEV | — | 2021. 11. 03. | — |
| CVE-2020-8468 | — | — | — | 82.50 | 5.8% | KEV | — | 2021. 11. 03. | — |
| CVE-2020-0968 | — | — | — | 82.50 | 30.0% | KEV KISA | — | 2021. 11. 03. | — |
| CVE-2020-0938 | — | — | — | 82.50 | 69.2% | KEV KISA | — | 2021. 11. 03. | — |
| CVE-2019-3396 | — | — | — | 87.50 | 99.9% | KEV | — | 2021. 11. 03. | ⚠️ |