CISA Known Exploited Vulnerabilities
The KEV catalog lists vulnerabilities that are known to be actively exploited in the wild. Federal agencies are required to remediate these on defined deadlines.
The KEV catalog lists vulnerabilities that are known to be actively exploited in the wild. Federal agencies are required to remediate these on defined deadlines.
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-34621 | HIGH | 8.6 | Adobe Acrobat and Reader contain a prototype pollution vulnerability that allows for arbitrary code execution. | Apr 11, 2026 |
| CVE-2026-60004 | CRITICAL | 9.8 | Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account. | Aug 26, 2026 |
| CVE-2015-3246 | UNKNOWN | — | Red Hat libuser contains a race condition vulnerability that allows authenticated local users to corrupt the /etc/passwd file to cause a denial of service or privilege escalation. | Aug 26, 2026 |
| CVE-2022-0995 | UNKNOWN | — | Linux Kernel contains an out-of-bounds memory write vulnerability which could allow a local user to gain privileged access or cause a denial of service on the system. | Aug 26, 2026 |
| CVE-2026-8452 | UNKNOWN | — | Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability which could lead to denial of service. | Aug 26, 2026 |
| CVE-2019-1068 | UNKNOWN | — | Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine service account. | Aug 26, 2026 |
| CVE-2021-23758 | UNKNOWN | — | Ajax.NET Professional (AjaxPro) contains a deserialization of untrusted data vulnerability that could allow for remote code execution via arbitrary .NET classes. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. | Aug 26, 2026 |
| CVE-2015-5287 | UNKNOWN | — | Red Hat Automatic Bug Reporting Tool (ABRT) contains a privilege escalation vulnerability that could allow local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. | Aug 26, 2026 |
| CVE-2020-1938 | CRITICAL | 9.8 | Apache Tomcat treats Apache JServ Protocol (AJP) connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited. | Feb 24, 2020 |
| CVE-2017-12617 | HIGH | 8.1 | When running Apache Tomcat, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server. | Oct 4, 2017 |
| CVE-2019-2725 | CRITICAL | 9.8 | Injection vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). | Apr 26, 2019 |
| CVE-2016-8735 | CRITICAL | 9.8 | Apache Tomcat contains an unspecified vulnerability that allows for remote code execution if JmxRemoteLifecycleListener is used and an attacker can reach Java Management Extension (JMX) ports. This CVE exists because this listener wasn't updated for consistency with the Oracle patched issues for CVE-2016-3427 which affected credential types. | Apr 6, 2017 |
| CVE-2026-21962 | CRITICAL | 10.0 | Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in contain an improper access control vulnerability that can result in unauthorized creation, deletion or modification access to critical data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in accessible data. | Jan 20, 2026 |
| CVE-2026-73570 | HIGH | 8.9 | Zimbra Collaboration Suite (ZCS) contains an OS command injection vulnerability which could allow an unauthenticated attacker to send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user. | Aug 13, 2026 |
| CVE-2021-43226 | HIGH | 7.8 | Microsoft Windows Common Log File System Driver contains a privilege escalation vulnerability that could allow a local, privileged attacker to bypass certain security mechanisms. | Dec 15, 2021 |
| CVE-2026-64849 | CRITICAL | 9.3 | MLflow contains a server-side request forgery vulnerability that can allow attackers to reach internal or cloud metadata services and receive response_status and response_body. | Aug 17, 2026 |
| CVE-2026-19490 | UNKNOWN | — | Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy), an unauthenticated remote threat actor may be able to bypass authentication. | Aug 19, 2026 |
| CVE-2026-72529 | UNKNOWN | — | TrueConf Server contains a missing authentication for critical function vulnerability which could allow a remote unauthorized attacker with network access via port 4307/TCP to execute an arbitrary script. | Aug 20, 2026 |
| CVE-2026-72530 | UNKNOWN | — | TrueConf Server contains a code injection vulnerability that could allow an unauthorized remote attacker with network access via port 4307/TCP to use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system. | Aug 20, 2026 |
| CVE-2021-26858 | HIGH | 7.8 | Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain. | Mar 3, 2021 |
| CVE-2021-42321 | HIGH | 8.8 | An authenticated attacker could leverage improper validation in cmdlet arguments within Microsoft Exchange and perform remote code execution. | Nov 10, 2021 |
| CVE-2021-42292 | HIGH | 7.8 | A security feature bypass vulnerability in Microsoft Excel would allow a local user to perform arbitrary code execution. | Nov 10, 2021 |
| CVE-2021-42287 | HIGH | 7.5 | Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation. | Nov 10, 2021 |
| CVE-2021-42278 | HIGH | 7.5 | Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation. | Nov 10, 2021 |
| CVE-2021-41379 | MEDIUM | 5.5 | Microsoft Windows Installer contains an unspecified vulnerability that allows for privilege escalation. | Nov 10, 2021 |