CISA Known Exploited Vulnerabilities
The KEV catalog lists vulnerabilities that are known to be actively exploited in the wild. Federal agencies are required to remediate these on defined deadlines.
The KEV catalog lists vulnerabilities that are known to be actively exploited in the wild. Federal agencies are required to remediate these on defined deadlines.
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-86218 | CRITICAL | 9.8 | N-able N-central contains a static code injection vulnerability that could allow for pre-authentication remote code execution. | Sep 6, 2026 |
| CVE-2025-14733 | CRITICAL | 9.8 | WatchGuard Fireware OS iked process contains an out of bounds write vulnerability in the OS iked process. This vulnerability may allow a remote unauthenticated attacker to execute arbitrary code and affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer. | Dec 19, 2025 |
| CVE-2026-87491 | UNKNOWN | — | Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Sep 9, 2026 |
| CVE-2025-25249 | UNKNOWN | — | Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets. | Sep 9, 2026 |
| CVE-2025-67038 | CRITICAL | 9.8 | Lantronix EDS5000 contains a code injection vulnerability that could allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges. | Mar 11, 2026 |
| CVE-2025-38352 | HIGH | 7.8 | Linux kernel contains a time-of-check time-of-use (TOCTOU) race condition vulnerability that has a high impact on confidentiality, integrity, and availability. | Jul 22, 2025 |
| CVE-2026-31431 | HIGH | 7.8 | Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation. | Apr 22, 2026 |
| CVE-2026-85046 | HIGH | 8.8 | Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Sep 3, 2026 |
| CVE-2026-81963 | UNKNOWN | — | Microsoft Windows Update Stack contains a link following vulnerability that allows a local attacker to escalate privileges locally up to SYSTEM. | Sep 8, 2026 |
| CVE-2026-85880 | UNKNOWN | — | Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally. | Sep 8, 2026 |
| CVE-2026-75650 | CRITICAL | 10.0 | Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allow an attacker to execute arbitrary code. | Sep 7, 2026 |
| CVE-2026-48710 | MEDIUM | 6.5 | Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentication bypass when the authentication depends on the reconstructed URL’s path. This vulnerability could be chaned with CVE-2026-42271. | May 26, 2026 |
| CVE-2023-50224 | MEDIUM | 6.5 | TP-Link TL-WR841N contains an authentication bypass by spoofing vulnerability within the httpd service, which listens on TCP port 80 by default, leading to the disclose of stored credentials. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. | May 3, 2024 |
| CVE-2026-9586 | CRITICAL | 9.8 | Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution. | Jul 17, 2026 |
| CVE-2026-83549 | HIGH | 7.8 | SonicWall SMA1000 Appliances contains an OS command injection vulnerability that could enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution. | Sep 1, 2026 |
| CVE-2026-83548 | CRITICAL | 10.0 | SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations. | Sep 1, 2026 |
| CVE-2026-82329 | CRITICAL | 9.8 | JFrog Artifactory contains an improper authentication vulnerability that under default configuration can allow an unauthenticated attacker with network access to obtain administrative privileges. | Aug 28, 2026 |
| CVE-2026-59822 | HIGH | 8.2 | BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token. | Jul 8, 2026 |
| CVE-2026-49869 | CRITICAL | 10.0 | Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials. | Jun 26, 2026 |
| CVE-2026-82078 | CRITICAL | 9.1 | PaperCut NG/MF contains an unsafe reflection vulnerability that allows an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process. This vulnerability can be chained with CVE-2026-81578. | Aug 28, 2026 |
| CVE-2026-81578 | CRITICAL | 9.8 | PaperCut NG/MF contains a missing authentication for critical function vulnerability which allows an unauthenticated remote attacker to modify certain system configurations. This vulnerability can be chained with CVE-2026-82078. | Aug 28, 2026 |
| CVE-2026-66384 | MEDIUM | 5.3 | JFrog Artifactory contains an improper limitation of a pathname to a restricted directory vulnerability. This can allow an authenticated user to write data outside the intended Docker cache path under specific remote-repository conditions. | Aug 12, 2026 |
| CVE-2026-53362 | HIGH | 7.8 | Linux Kernel contains an unspecified vulnerability that can allow for privilege escalation via IPv6 networking subsystem. This vulnerability can impact multiple products, including but not limited to Suse, Red Hat, and other products using Linux. | Jul 4, 2026 |
| CVE-2023-49105 | CRITICAL | 9.8 | ownCloud contains an improper authentication vulnerability that allows an attacker to access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. | Nov 21, 2023 |
| CVE-2026-48282 | CRITICAL | 10.0 | Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user. | Jun 30, 2026 |
Page 1 of 69