CISA Known Exploited Vulnerabilities
The KEV catalog lists vulnerabilities that are known to be actively exploited in the wild. Federal agencies are required to remediate these on defined deadlines.
The KEV catalog lists vulnerabilities that are known to be actively exploited in the wild. Federal agencies are required to remediate these on defined deadlines.
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2022-41128 | HIGH | 8.8 | Microsoft Windows contains an unspecified vulnerability in the JScript9 scripting language which allows for remote code execution. | Nov 9, 2022 |
| CVE-2022-41125 | HIGH | 7.8 | Microsoft Windows Cryptographic Next Generation (CNG) Key Isolation Service contains an unspecified vulnerability that allows an attacker to gain SYSTEM-level privileges. | Nov 9, 2022 |
| CVE-2022-41091 | MEDIUM | 5.4 | Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features. | Nov 9, 2022 |
| CVE-2022-41080 | HIGH | 8.8 | Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation. This vulnerability is chainable with CVE-2022-41082, which allows for remote code execution. | Nov 9, 2022 |
| CVE-2022-41073 | HIGH | 7.8 | Microsoft Windows Print Spooler contains an unspecified vulnerability that allows an attacker to gain SYSTEM-level privileges. | Nov 9, 2022 |
| CVE-2022-41049 | MEDIUM | 5.4 | Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features. | Nov 9, 2022 |
| CVE-2026-34486 | HIGH | 7.5 | Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813. | Apr 9, 2026 |
| CVE-2024-1086 | HIGH | 7.8 | Linux kernel contains a use-after-free vulnerability in the netfilter: nf_tables component that allows an attacker to achieve local privilege escalation. | Jan 31, 2024 |
| CVE-2022-24682 | MEDIUM | 6.1 | Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting (XSS) vulnerability in the Calendar feature that allows an attacker to execute arbitrary code. | Feb 9, 2022 |
| CVE-2026-18556 | HIGH | 7.4 | N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass. | Aug 1, 2026 |
| CVE-2025-26633 | HIGH | 7.0 | Microsoft Windows Management Console (MMC) contains an improper neutralization vulnerability that allows an unauthorized attacker to bypass a security feature locally. | Mar 11, 2025 |
| CVE-2025-24472 | HIGH | 8.1 | Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that allows a remote attacker to gain super-admin privileges via crafted CSF proxy requests. | Feb 11, 2025 |
| CVE-2024-55956 | CRITICAL | 9.8 | Cleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload vulnerability that could allow an unauthenticated user to import and execute arbitrary bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory. | Dec 13, 2024 |
| CVE-2024-55591 | CRITICAL | 9.8 | Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that may allow an unauthenticated, remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module. | Jan 14, 2025 |
| CVE-2024-51378 | CRITICAL | 10.0 | CyberPanel contains an incorrect default permissions vulnerability that allows for authentication bypass and the execution of arbitrary commands using shell metacharacters in the statusfile property. | Oct 29, 2024 |
| CVE-2024-24919 | HIGH | 8.6 | Check Point Quantum Security Gateways contain an unspecified information disclosure vulnerability. The vulnerability potentially allows an attacker to access information on Gateways connected to the internet, with IPSec VPN, Remote Access VPN or Mobile Access enabled. This issue affects several product lines from Check Point, including CloudGuard Network, Quantum Scalable Chassis, Quantum Security Gateways, and Quantum Spark Appliances. | May 28, 2024 |
| CVE-2024-11667 | HIGH | 7.5 | Multiple Zyxel firewalls contain a path traversal vulnerability in the web management interface that could allow an attacker to download or upload files via a crafted URL. | Nov 27, 2024 |
| CVE-2023-41266 | HIGH | 8.2 | Qlik Sense contains a path traversal vulnerability that allows a remote, unauthenticated attacker to create an anonymous session by sending maliciously crafted HTTP requests. This anonymous session could allow the attacker to send further requests to unauthorized endpoints. | Aug 29, 2023 |
| CVE-2023-41265 | CRITICAL | 9.6 | Qlik Sense contains an HTTP tunneling vulnerability that allows an attacker to escalate privileges and execute HTTP requests on the backend server hosting the software. | Aug 29, 2023 |
| CVE-2023-3519 | CRITICAL | 9.8 | Citrix NetScaler ADC and NetScaler Gateway contains a code injection vulnerability that allows for unauthenticated remote code execution. | Jul 19, 2023 |
| CVE-2023-38831 | HIGH | 7.8 | RARLAB WinRAR contains an unspecified vulnerability that allows an attacker to execute code when a user attempts to view a benign file within a ZIP archive. | Aug 23, 2023 |
| CVE-2023-35078 | CRITICAL | 9.8 | Ivanti Endpoint Manager Mobile (EPMM, previously branded MobileIron Core) contains an authentication bypass vulnerability that allows unauthenticated access to specific API paths. An attacker with access to these API paths can access personally identifiable information (PII) such as names, phone numbers, and other mobile device details for users on a vulnerable system. An attacker can also make other configuration changes including installing software and modifying security profiles on registered devices. | Jul 25, 2023 |
| CVE-2023-28461 | CRITICAL | 9.8 | Array Networks AG and vxAG ArrayOS contain a missing authentication for critical function vulnerability that allows an attacker to read local files and execute code on the SSL VPN gateway. | Mar 15, 2023 |
| CVE-2026-18577 | HIGH | 8.1 | N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for CVE-2026-18556. | Aug 2, 2026 |
| CVE-2026-34197 | HIGH | 8.8 | Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection. | Apr 7, 2026 |