/
cyberknowledge
/
CVE
ОбзорДокументацияВойти
/
cyberknowledge
/
CVE
Код
Запросы
0
Задачи
Вики
Пакеты
0
Релизы
0
CI/CD
Аналитика
ДокументацияПоддержка
Политика конфиденциальностиПользовательское соглашениеПолитика использования «cookies»Согласие субъекта персональных данных
2026 ©
samples/cisa_kev.csv
101 строка184 KB

Zeros312

Rename sample/ to samples/; remove README from samples
30 июн 2026, 21:21
30 июн 2026, 21:2183c96cb
100 строк
CVE-2026-48027
Nx
Nx Console
Nx Console Embedded Malicious Code Vulnerability
2026-05-27
Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload that could harvested credentials from multiple sources on disk and in memory.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-06-10
Known
This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/nrwl/nx-console/security/advisories/GHSA-c9j4-9m59-847w ; https://nvd.nist.gov/vuln/detail/CVE-2026-48027
['CWE-506']
2026.05.28
2026-05-28 19:27:12.922700+03:00
1cb4323f204b161f4a0592428ed8f78ddb1f90e540220f8c82bece827f6804a1
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-506'], 'cveID': 'CVE-2026-48027', 'notes': 'This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/nrwl/nx-console/security/advisories/GHSA-c9j4-9m59-847w ; https://nvd.nist.gov/vuln/detail/CVE-2026-48027', 'dueDate': '2026-06-10', 'product': 'Nx Console', 'dateAdded': '2026-05-27', 'vendorProject': 'Nx', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload that could harvested credentials from multiple sources on disk and in memory.', 'vulnerabilityName': 'Nx Console Embedded Malicious Code Vulnerability', 'knownRansomwareCampaignUse': 'Known'}
CVE-2026-45321
TanStack
TanStack
TanStack Unspecified Vulnerability
2026-05-27
TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a trusted identity.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-06-10
Known
This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/TanStack/router/security/advisories/GHSA-g7cv-rxg3-hmpx ; https://nvd.nist.gov/vuln/detail/CVE-2026-45321
[]
2026.05.28
2026-05-28 19:27:12.922700+03:00
89b7e0a1da61e5821cc977fd7c49f51486feb66ffb10bda20e2680ce07aa670a
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': [], 'cveID': 'CVE-2026-45321', 'notes': 'This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/TanStack/router/security/advisories/GHSA-g7cv-rxg3-hmpx ; https://nvd.nist.gov/vuln/detail/CVE-2026-45321', 'dueDate': '2026-06-10', 'product': 'TanStack', 'dateAdded': '2026-05-27', 'vendorProject': 'TanStack', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a trusted identity.', 'vulnerabilityName': 'TanStack Unspecified Vulnerability', 'knownRansomwareCampaignUse': 'Known'}
CVE-2026-8398
Daemon
Daemon Tools Lite
Daemon Tools Lite Embedded Malicious Code Vulnerability
2026-05-27
Daemon Tools contains an unspecified vulnerability that has a high impact on confidentiality, integrity, and availability.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-05-30
Unknown
https://blog.daemon-tools.cc/post/security-incident ; https://nvd.nist.gov/vuln/detail/CVE-2026-8398
['CWE-506']
2026.05.28
2026-05-28 19:27:12.922700+03:00
03127f1f4160ad42ea2743b6ec74d225bef7ce511d49052acd32edb3a95bf1b0
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-506'], 'cveID': 'CVE-2026-8398', 'notes': 'https://blog.daemon-tools.cc/post/security-incident ; https://nvd.nist.gov/vuln/detail/CVE-2026-8398', 'dueDate': '2026-05-30', 'product': 'Daemon Tools Lite', 'dateAdded': '2026-05-27', 'vendorProject': 'Daemon', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Daemon Tools contains an unspecified vulnerability that has a high impact on confidentiality, integrity, and availability.', 'vulnerabilityName': 'Daemon Tools Lite Embedded Malicious Code Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2026-48172
LiteSpeed
cPanel Plugin
LiteSpeed cPanel Plugin Privilege Escalation Vulnerability
2026-05-26
LiteSpeed cPanel Plugin contains privilege escalation vulnerability that is exposed via the user-end cPanel plugin, which can be abused by any cPanel user account to execute arbitrary scripts with root privileges.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-05-29
Unknown
https://blog.litespeedtech.com/2026/05/21/security-update-for-litespeed-cpanel-plugin/ ; https://nvd.nist.gov/vuln/detail/CVE-2026-48172
['CWE-266']
2026.05.28
2026-05-28 19:27:12.922700+03:00
687a206e118ff326b62c7bd591249de824489afaf995a126d9105f02e6a70f60
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-266'], 'cveID': 'CVE-2026-48172', 'notes': 'https://blog.litespeedtech.com/2026/05/21/security-update-for-litespeed-cpanel-plugin/ ; https://nvd.nist.gov/vuln/detail/CVE-2026-48172', 'dueDate': '2026-05-29', 'product': 'cPanel Plugin', 'dateAdded': '2026-05-26', 'vendorProject': 'LiteSpeed', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'LiteSpeed cPanel Plugin contains privilege escalation vulnerability that is exposed via the user-end cPanel plugin, which can be abused by any cPanel user account to execute arbitrary scripts with root privileges.', 'vulnerabilityName': 'LiteSpeed cPanel Plugin Privilege Escalation Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2026-9082
Drupal
Core
Drupal Core SQL Injection Vulnerability
2026-05-22
Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-05-27
Unknown
https://www.drupal.org/sa-core-2026-004 ; https://nvd.nist.gov/vuln/detail/CVE-2026-9082
['CWE-89']
2026.05.28
2026-05-28 19:27:12.922700+03:00
a8c01942c2a1ebf672c9d736de8aa147a4e5fdd1290dd7dff6b3e06fa642788c
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-89'], 'cveID': 'CVE-2026-9082', 'notes': 'https://www.drupal.org/sa-core-2026-004 ; https://nvd.nist.gov/vuln/detail/CVE-2026-9082', 'dueDate': '2026-05-27', 'product': 'Core', 'dateAdded': '2026-05-22', 'vendorProject': 'Drupal', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.', 'vulnerabilityName': 'Drupal Core SQL Injection Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2025-34291
Langflow
Langflow
Langflow Origin Validation Error Vulnerability
2026-05-21
Langflow contains an origin validation error vulnerability in which an overly permissive CORS configuration combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform cross-origin requests that include credentials and successfully call the refresh endpoint. This could allow the attacker to execute arbitrary code and achieve full system compromise via obtained tokens that permit access to authenticated endpoints.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-06-04
Unknown
This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/langflow-ai/langflow ; https://github.com/langflow-ai/langflow/releases/tag/v1.9.3; https://github.com/langflow-ai/langflow/issues/11465#event-25774545848 ; https://nvd.nist.gov/vuln/detail/CVE-2025-34291
['CWE-346']
2026.05.28
2026-05-28 19:27:12.922700+03:00
bf29e2f9d490daf02a37918255eab0d220a2098578b15452b15d7429ce993119
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-346'], 'cveID': 'CVE-2025-34291', 'notes': 'This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/langflow-ai/langflow ; https://github.com/langflow-ai/langflow/releases/tag/v1.9.3; https://github.com/langflow-ai/langflow/issues/11465#event-25774545848 ; https://nvd.nist.gov/vuln/detail/CVE-2025-34291', 'dueDate': '2026-06-04', 'product': 'Langflow', 'dateAdded': '2026-05-21', 'vendorProject': 'Langflow', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Langflow contains an origin validation error vulnerability in which an overly permissive CORS configuration combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform cross-origin requests that include credentials and successfully call the refresh endpoint. This could allow the attacker to execute arbitrary code and achieve full system compromise via obtained tokens that permit access to authenticated endpoints.', 'vulnerabilityName': 'Langflow Origin Validation Error Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2026-34926
Trend Micro
Apex One
Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability
2026-05-21
Trend Micro Apex One (on-premise) contains a directory traversal vulnerability that could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-06-04
Unknown
https://success.trendmicro.com/en-US/solution/KA-0023430 ; https://nvd.nist.gov/vuln/detail/CVE-2026-34926
['CWE-23']
2026.05.28
2026-05-28 19:27:12.922700+03:00
6d241ec323099c047f4f60c55b6a6b9b7e0421637eb17c9e431303fbba89732a
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-23'], 'cveID': 'CVE-2026-34926', 'notes': 'https://success.trendmicro.com/en-US/solution/KA-0023430 ; https://nvd.nist.gov/vuln/detail/CVE-2026-34926', 'dueDate': '2026-06-04', 'product': 'Apex One', 'dateAdded': '2026-05-21', 'vendorProject': 'Trend Micro', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Trend Micro Apex One (on-premise) contains a directory traversal vulnerability that could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations.', 'vulnerabilityName': 'Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2008-4250
Microsoft
Windows
Microsoft Windows Buffer Overflow Vulnerability
2026-05-20
Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-06-03
Unknown
https://learn.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-067 ; https://nvd.nist.gov/vuln/detail/CVE-2008-4250
['CWE-94']
2026.05.28
2026-05-28 19:27:12.922700+03:00
736c8edc4a06a10ea3b1ed7a94b6daabcc630318ec504fb0065324f4a06f2955
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-94'], 'cveID': 'CVE-2008-4250', 'notes': 'https://learn.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-067 ; https://nvd.nist.gov/vuln/detail/CVE-2008-4250', 'dueDate': '2026-06-03', 'product': 'Windows', 'dateAdded': '2026-05-20', 'vendorProject': 'Microsoft', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization.', 'vulnerabilityName': 'Microsoft Windows Buffer Overflow Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2009-1537
Microsoft
DirectX
Microsoft DirectX NULL Byte Overwrite Vulnerability
2026-05-20
Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitrary code via a crafted QuickTime media file.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-06-03
Unknown
https://learn.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-028 ; https://nvd.nist.gov/vuln/detail/CVE-2009-1537
[]
2026.05.28
2026-05-28 19:27:12.922700+03:00
706b5983013ae8f7371f44973438e9b167d2536099eba034a7e261514b1a7c38
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': [], 'cveID': 'CVE-2009-1537', 'notes': 'https://learn.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-028 ; https://nvd.nist.gov/vuln/detail/CVE-2009-1537', 'dueDate': '2026-06-03', 'product': 'DirectX', 'dateAdded': '2026-05-20', 'vendorProject': 'Microsoft', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitrary code via a crafted QuickTime media file.', 'vulnerabilityName': 'Microsoft DirectX NULL Byte Overwrite Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2026-45498
Microsoft
Defender
Microsoft Defender Denial of Service Vulnerability
2026-05-20
Microsoft Defender contains an unspecified vulnerability that allows for denial of service.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-06-03
Unknown
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-45498 ; https://nvd.nist.gov/vuln/detail/CVE-2026-45498
[]
2026.05.28
2026-05-28 19:27:12.922700+03:00
f18135e66bb5740c8353436af5932fed629f4b03e08eb2bc8c7d0a39202c3a5d
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': [], 'cveID': 'CVE-2026-45498', 'notes': 'https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-45498 ; https://nvd.nist.gov/vuln/detail/CVE-2026-45498', 'dueDate': '2026-06-03', 'product': 'Defender', 'dateAdded': '2026-05-20', 'vendorProject': 'Microsoft', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Microsoft Defender contains an unspecified vulnerability that allows for denial of service.', 'vulnerabilityName': 'Microsoft Defender Denial of Service Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2009-3459
Adobe
Acrobat and Reader
Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability
2026-05-20
Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability which could allow remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-06-03
Unknown
https://www.cisa.gov/news-events/alerts/2009/10/13/adobe-reader-and-acrobat-vulnerabilities ; https://web.archive.org/web/20120324170253/http://www.adobe.com/support/security/bulletins/apsb09-15.html#:~:text=CVE%2D2009%2D3459).-,NOTE%3A,-There%20are%20reports ; https://nvd.nist.gov/vuln/detail/CVE-2009-3459
['CWE-119']
2026.05.28
2026-05-28 19:27:12.922700+03:00
cd52ee4161a83d064801fab703364c2046e1ab9b99d202285b99a6c232e861b4
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-119'], 'cveID': 'CVE-2009-3459', 'notes': 'https://www.cisa.gov/news-events/alerts/2009/10/13/adobe-reader-and-acrobat-vulnerabilities ; https://web.archive.org/web/20120324170253/http://www.adobe.com/support/security/bulletins/apsb09-15.html#:~:text=CVE%2D2009%2D3459).-,NOTE%3A,-There%20are%20reports ; https://nvd.nist.gov/vuln/detail/CVE-2009-3459', 'dueDate': '2026-06-03', 'product': 'Acrobat and Reader', 'dateAdded': '2026-05-20', 'vendorProject': 'Adobe', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability which could allow remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption.', 'vulnerabilityName': 'Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2010-0249
Microsoft
Internet Explorer
Microsoft Internet Explorer Use-After-Free Vulnerability
2026-05-20
Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-06-03
Unknown
https://learn.microsoft.com/en-us/security-updates/SecurityAdvisories/2010/979352 ; https://nvd.nist.gov/vuln/detail/CVE-2010-0249
['CWE-416']
2026.05.28
2026-05-28 19:27:12.922700+03:00
35b87c95829f534fd195a1e9b265a8b916ac56402f11ee40ac4ef5a2d179ba7f
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-416'], 'cveID': 'CVE-2010-0249', 'notes': 'https://learn.microsoft.com/en-us/security-updates/SecurityAdvisories/2010/979352 ; https://nvd.nist.gov/vuln/detail/CVE-2010-0249', 'dueDate': '2026-06-03', 'product': 'Internet Explorer', 'dateAdded': '2026-05-20', 'vendorProject': 'Microsoft', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.', 'vulnerabilityName': 'Microsoft Internet Explorer Use-After-Free Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2010-0806
Microsoft
Internet Explorer
Microsoft Internet Explorer Use-After-Free Vulnerability
2026-05-20
Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-06-03
Unknown
https://learn.microsoft.com/en-us/security-updates/securityadvisories/2010/981374 ; https://nvd.nist.gov/vuln/detail/CVE-2010-0806
['CWE-399']
2026.05.28
2026-05-28 19:27:12.922700+03:00
10df123103ce0a64756a756ab4bbeb7736e9d464997d6aca6635e43e08607cbf
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-399'], 'cveID': 'CVE-2010-0806', 'notes': 'https://learn.microsoft.com/en-us/security-updates/securityadvisories/2010/981374 ; https://nvd.nist.gov/vuln/detail/CVE-2010-0806', 'dueDate': '2026-06-03', 'product': 'Internet Explorer', 'dateAdded': '2026-05-20', 'vendorProject': 'Microsoft', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.', 'vulnerabilityName': 'Microsoft Internet Explorer Use-After-Free Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2026-41091
Microsoft
Defender
Microsoft Defender Link Following Vulnerability
2026-05-20
Microsoft Defender contains a link following vulnerability that allows an authorized attacker to elevate privileges locally.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-06-03
Unknown
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-41091 ; https://nvd.nist.gov/vuln/detail/CVE-2026-41091
['CWE-59']
2026.05.28
2026-05-28 19:27:12.922700+03:00
1d6bf911bddab27e01e3e50e533d0c57f493b659a656748b01fd52ba7d9812cc
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-59'], 'cveID': 'CVE-2026-41091', 'notes': 'https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-41091 ; https://nvd.nist.gov/vuln/detail/CVE-2026-41091', 'dueDate': '2026-06-03', 'product': 'Defender', 'dateAdded': '2026-05-20', 'vendorProject': 'Microsoft', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Microsoft Defender contains a link following vulnerability that allows an authorized attacker to elevate privileges locally.', 'vulnerabilityName': 'Microsoft Defender Link Following Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2016-4655
Apple
iOS
Apple iOS Information Disclosure Vulnerability
2022-05-24
The Apple iOS kernel allows attackers to obtain sensitive information from memory via a crafted application.
Apply updates per vendor instructions.
2022-06-14
Unknown
https://nvd.nist.gov/vuln/detail/CVE-2016-4655
['CWE-200']
2026.05.28
2026-05-28 19:27:12.922700+03:00
66658379a98316448ceb5f6c781cbe5e3ad443bd84c0b14bdc0fee03778ddc47
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-200'], 'cveID': 'CVE-2016-4655', 'notes': 'https://nvd.nist.gov/vuln/detail/CVE-2016-4655', 'dueDate': '2022-06-14', 'product': 'iOS', 'dateAdded': '2022-05-24', 'vendorProject': 'Apple', 'requiredAction': 'Apply updates per vendor instructions.', 'shortDescription': 'The Apple iOS kernel allows attackers to obtain sensitive information from memory via a crafted application.', 'vulnerabilityName': 'Apple iOS Information Disclosure Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2026-42897
Microsoft
Microsoft
Microsoft Exchange Server Cross-Site Scripting Vulnerability
2026-05-15
Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-05-29
Unknown
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-42897 ; https://learn.microsoft.com/en-us/exchange/plan-and-deploy/post-installation-tasks/security-best-practices/exchange-emergency-mitigation-service ; https://nvd.nist.gov/vuln/detail/CVE-2026-42897
['CWE-79']
2026.05.28
2026-05-28 19:27:12.922700+03:00
cae439f5fbfeb15672a815aef19c6abe11b76b4f4f650b0201d8c919ed08819b
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-79'], 'cveID': 'CVE-2026-42897', 'notes': 'https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-42897 ; https://learn.microsoft.com/en-us/exchange/plan-and-deploy/post-installation-tasks/security-best-practices/exchange-emergency-mitigation-service ; https://nvd.nist.gov/vuln/detail/CVE-2026-42897', 'dueDate': '2026-05-29', 'product': 'Microsoft', 'dateAdded': '2026-05-15', 'vendorProject': 'Microsoft', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context.', 'vulnerabilityName': 'Microsoft Exchange Server Cross-Site Scripting Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2026-20182
Cisco
Catalyst SD-WAN
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
2026-05-14
Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.
Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlined in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.
2026-05-17
Unknown
CISA Mitigation Instructions: https://www.cisa.gov/news-events/directives/ed-26-03-mitigate-vulnerabilities-cisco-sd-wan-systems ; https://www.cisa.gov/news-events/directives/supplemental-direction-ed-26-03-hunt-and-hardening-guidance-cisco-sd-wan-systems ; https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW ; https://nvd.nist.gov/vuln/detail/CVE-2026-20182
['CWE-287']
2026.05.28
2026-05-28 19:27:12.922700+03:00
0cb7a1e76504de089eef0e4abc159dcbaf0790d93ecf0862bea007b2180e6694
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-287'], 'cveID': 'CVE-2026-20182', 'notes': 'CISA Mitigation Instructions: https://www.cisa.gov/news-events/directives/ed-26-03-mitigate-vulnerabilities-cisco-sd-wan-systems ; https://www.cisa.gov/news-events/directives/supplemental-direction-ed-26-03-hunt-and-hardening-guidance-cisco-sd-wan-systems ; https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW ; https://nvd.nist.gov/vuln/detail/CVE-2026-20182', 'dueDate': '2026-05-17', 'product': 'Catalyst SD-WAN', 'dateAdded': '2026-05-14', 'vendorProject': 'Cisco', 'requiredAction': 'Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlined in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.', 'shortDescription': 'Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.', 'vulnerabilityName': 'Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2026-42208
BerriAI
LiteLLM
BerriAI LiteLLM SQL Injection Vulnerability
2026-05-08
BerriAI LiteLLM contains a SQL injection vulnerability that allows an attacker to read data from the proxy's database and potentially modify it, leading to unauthorized access to the proxy and the credentials it manages.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-05-11
Unknown
https://github.com/BerriAI/litellm/security/advisories/GHSA-r75f-5x8p-qvmc ; https://nvd.nist.gov/vuln/detail/CVE-2026-42208
['CWE-89']
2026.05.28
2026-05-28 19:27:12.922700+03:00
a2c1c1885b0e9f8213310871b5e4bc7bb09ff643549b24fc2bb125c63196621c
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-89'], 'cveID': 'CVE-2026-42208', 'notes': 'https://github.com/BerriAI/litellm/security/advisories/GHSA-r75f-5x8p-qvmc ; https://nvd.nist.gov/vuln/detail/CVE-2026-42208', 'dueDate': '2026-05-11', 'product': 'LiteLLM', 'dateAdded': '2026-05-08', 'vendorProject': 'BerriAI', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': "BerriAI LiteLLM contains a SQL injection vulnerability that allows an attacker to read data from the proxy's database and potentially modify it, leading to unauthorized access to the proxy and the credentials it manages.", 'vulnerabilityName': 'BerriAI LiteLLM SQL Injection Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2026-6973
Ivanti
Endpoint Manager Mobile (EPMM)
Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability
2026-05-07
Ivanti Endpoint Manager Mobile (EPMM) contains an improper input validation vulnerability that allows a remotely authenticated user with administrative access to achieve remote code execution.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-05-10
Unknown
https://hub.ivanti.com/s/article/May-2026-Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-Multiple-CVEs?language=en_US ; https://nvd.nist.gov/vuln/detail/CVE-2026-6973
['CWE-20']
2026.05.28
2026-05-28 19:27:12.922700+03:00
65bbee9866ecde1813699cb7834d3a56a423ca61905e20130c90bec6a6c35258
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-20'], 'cveID': 'CVE-2026-6973', 'notes': 'https://hub.ivanti.com/s/article/May-2026-Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-Multiple-CVEs?language=en_US ; https://nvd.nist.gov/vuln/detail/CVE-2026-6973', 'dueDate': '2026-05-10', 'product': 'Endpoint Manager Mobile (EPMM)', 'dateAdded': '2026-05-07', 'vendorProject': 'Ivanti', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Ivanti Endpoint Manager Mobile (EPMM) contains an improper input validation vulnerability that allows a remotely authenticated user with administrative access to achieve remote code execution.', 'vulnerabilityName': 'Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2026-0300
Palo Alto Networks
PAN-OS
Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability
2026-05-06
Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Until the vendor releases an official fix, the following workaround should be implemented: - Restrict User-ID Authentication Portal access to only trusted zones. - Disable User-ID Authentication Portal if not required. 5/13/2026: Palo Alto has released a variety of patches. If these are relevant to your environment, please apply the designated patch.
2026-05-09
Unknown
https://security.paloaltonetworks.com/CVE-2026-0300 ; https://nvd.nist.gov/vuln/detail/CVE-2026-0300
['CWE-787']
2026.05.28
2026-05-28 19:27:12.922700+03:00
9a8480a8e8a31e38d0658521152f44e6a4d8642672c1e83420bd95ae16dd5583
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-787'], 'cveID': 'CVE-2026-0300', 'notes': 'https://security.paloaltonetworks.com/CVE-2026-0300 ; https://nvd.nist.gov/vuln/detail/CVE-2026-0300', 'dueDate': '2026-05-09', 'product': 'PAN-OS', 'dateAdded': '2026-05-06', 'vendorProject': 'Palo Alto Networks', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Until the vendor releases an official fix, the following workaround should be implemented: - Restrict User-ID Authentication Portal access to only trusted zones. - Disable User-ID Authentication Portal if not required. 5/13/2026: Palo Alto has released a variety of patches. If these are relevant to your environment, please apply the designated patch.', 'shortDescription': 'Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets.', 'vulnerabilityName': 'Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2026-31431
Linux
Kernel
Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability
2026-05-01
Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation.
"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-05-15
Unknown
https://lore.kernel.org/linux-cve-announce/2026042214-CVE-2026-31431-3d65@gregkh/; https://xint.io/blog/copy-fail-linux-distributions#the-fix-6 ; https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/about/ ; https://nvd.nist.gov/vuln/detail/CVE-2026-31431
['CWE-669']
2026.05.28
2026-05-28 19:27:12.922700+03:00
96ed217fabcc3f12ac0537dade7b2caf16ce426529ae609f97b537335ef752f7
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-669'], 'cveID': 'CVE-2026-31431', 'notes': 'https://lore.kernel.org/linux-cve-announce/2026042214-CVE-2026-31431-3d65@gregkh/; https://xint.io/blog/copy-fail-linux-distributions#the-fix-6 ; https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/about/ ; https://nvd.nist.gov/vuln/detail/CVE-2026-31431', 'dueDate': '2026-05-15', 'product': 'Kernel', 'dateAdded': '2026-05-01', 'vendorProject': 'Linux', 'requiredAction': '"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation.', 'vulnerabilityName': 'Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2026-41940
WebPros
cPanel & WHM and WP2 (WordPress Squared)
WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability
2026-04-30
WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-05-03
Known
https://support.cpanel.net/hc/en-us/articles/40073787579671-cPanel-WHM-Security-Update-04-28-2026 ; https://docs.cpanel.net/release-notes/release-notes/ ; https://docs.wpsquared.com/changelogs/versions/changelog/#13617 ; https://nvd.nist.gov/vuln/detail/CVE-2026-41940"
['CWE-306']
2026.05.28
2026-05-28 19:27:12.922700+03:00
a28d3263f52b07b67c6f5afab001f5cb1e6bb9e4775eb6976aeeaa36b6390084
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-306'], 'cveID': 'CVE-2026-41940', 'notes': 'https://support.cpanel.net/hc/en-us/articles/40073787579671-cPanel-WHM-Security-Update-04-28-2026 ; https://docs.cpanel.net/release-notes/release-notes/ ; https://docs.wpsquared.com/changelogs/versions/changelog/#13617 ; https://nvd.nist.gov/vuln/detail/CVE-2026-41940"', 'dueDate': '2026-05-03', 'product': 'cPanel & WHM and WP2 (WordPress Squared)', 'dateAdded': '2026-04-30', 'vendorProject': 'WebPros', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.', 'vulnerabilityName': 'WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability', 'knownRansomwareCampaignUse': 'Known'}
CVE-2024-1708
ConnectWise
ScreenConnect
ConnectWise ScreenConnect Path Traversal Vulnerability
2026-04-28
ConnectWise ScreenConnect contains a path traversal vulnerability which could allow an attacker to execute remote code or directly impact confidential data and critical systems.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-05-12
Known
https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8 ; https://nvd.nist.gov/vuln/detail/CVE-2024-1708
['CWE-22']
2026.05.28
2026-05-28 19:27:12.922700+03:00
868a95c6ce0d13724e4821e0a6d8613844550558944e424b4665c55c9924a473
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-22'], 'cveID': 'CVE-2024-1708', 'notes': 'https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8 ; https://nvd.nist.gov/vuln/detail/CVE-2024-1708', 'dueDate': '2026-05-12', 'product': 'ScreenConnect', 'dateAdded': '2026-04-28', 'vendorProject': 'ConnectWise', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'ConnectWise ScreenConnect contains a path traversal vulnerability which could allow an attacker to execute remote code or directly impact confidential data and critical systems.', 'vulnerabilityName': 'ConnectWise ScreenConnect Path Traversal Vulnerability', 'knownRansomwareCampaignUse': 'Known'}
CVE-2026-32202
Microsoft
Windows
Microsoft Windows Protection Mechanism Failure Vulnerability
2026-04-28
Microsoft Windows Shell contains a protection mechanism failure vulnerability that allows an unauthorized attacker to perform spoofing over a network.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-05-12
Unknown
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-32202 ; https://nvd.nist.gov/vuln/detail/CVE-2026-32202
['CWE-693']
2026.05.28
2026-05-28 19:27:12.922700+03:00
5674190dac44cac50f00ae34017befbf990076f384564a47093409ff7ac71ac2
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-693'], 'cveID': 'CVE-2026-32202', 'notes': 'https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-32202 ; https://nvd.nist.gov/vuln/detail/CVE-2026-32202', 'dueDate': '2026-05-12', 'product': 'Windows', 'dateAdded': '2026-04-28', 'vendorProject': 'Microsoft', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Microsoft Windows Shell contains a protection mechanism failure vulnerability that allows an unauthorized attacker to perform spoofing over a network.', 'vulnerabilityName': 'Microsoft Windows Protection Mechanism Failure Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2025-29635
D-Link
DIR-823X
D-Link DIR-823X Command Injection Vulnerability
2026-04-24
D-Link DIR-823X contains a command injection vulnerability that allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-05-08
Unknown
https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10469 ; https://nvd.nist.gov/vuln/detail/CVE-2025-29635
['CWE-77']
2026.05.28
2026-05-28 19:27:12.922700+03:00
0963356a931db174564a3c90d9faba1551a99f4d45682a9c297f297546b60b82
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-77'], 'cveID': 'CVE-2025-29635', 'notes': 'https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10469 ; https://nvd.nist.gov/vuln/detail/CVE-2025-29635', 'dueDate': '2026-05-08', 'product': 'DIR-823X', 'dateAdded': '2026-04-24', 'vendorProject': 'D-Link', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'D-Link DIR-823X contains a command injection vulnerability that allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.', 'vulnerabilityName': 'D-Link DIR-823X Command Injection Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2024-7399
Samsung
MagicINFO 9 Server
Samsung MagicINFO 9 Server Path Traversal Vulnerability
2026-04-24
Samsung MagicINFO 9 Server contains a path traversal vulnerability that could allow an attacker to write arbitrary files as system authority.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-05-08
Unknown
https://security.samsungtv.com/securityUpdates ; https://nvd.nist.gov/vuln/detail/CVE-2024-7399
['CWE-22', 'CWE-434']
2026.05.28
2026-05-28 19:27:12.922700+03:00
cc9baaf3fae6d2d2205fd204a6216e4871ea375ed5c5265a87af3c0a1acec63c
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-22', 'CWE-434'], 'cveID': 'CVE-2024-7399', 'notes': 'https://security.samsungtv.com/securityUpdates ; https://nvd.nist.gov/vuln/detail/CVE-2024-7399', 'dueDate': '2026-05-08', 'product': 'MagicINFO 9 Server', 'dateAdded': '2026-04-24', 'vendorProject': 'Samsung', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Samsung MagicINFO 9 Server contains a path traversal vulnerability that could allow an attacker to write arbitrary files as system authority.', 'vulnerabilityName': 'Samsung MagicINFO 9 Server Path Traversal Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2024-57728
SimpleHelp
SimpleHelp
SimpleHelp Path Traversal Vulnerability
2026-04-24
SimpleHelp contains a path traversal vulnerability that allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-05-08
Known
https://simple-help.com/kb---security-vulnerabilities-01-2025#security-vulnerabilities-in-simplehelp-5-5-7-and-earlier ; https://nvd.nist.gov/vuln/detail/CVE-2024-57728
['CWE-22']
2026.05.28
2026-05-28 19:27:12.922700+03:00
f76928b83f496fcbc2c7f35358938e1dcb0c2d179a7f23476ba8d6208107fc1c
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-22'], 'cveID': 'CVE-2024-57728', 'notes': 'https://simple-help.com/kb---security-vulnerabilities-01-2025#security-vulnerabilities-in-simplehelp-5-5-7-and-earlier ; https://nvd.nist.gov/vuln/detail/CVE-2024-57728', 'dueDate': '2026-05-08', 'product': 'SimpleHelp', 'dateAdded': '2026-04-24', 'vendorProject': 'SimpleHelp ', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'SimpleHelp contains a path traversal vulnerability that allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user.', 'vulnerabilityName': 'SimpleHelp Path Traversal Vulnerability', 'knownRansomwareCampaignUse': 'Known'}
CVE-2024-57726
SimpleHelp
SimpleHelp
SimpleHelp Missing Authorization Vulnerability
2026-04-24
SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-05-08
Known
https://simple-help.com/kb---security-vulnerabilities-01-2025#security-vulnerabilities-in-simplehelp-5-5-7-and-earlier ; https://nvd.nist.gov/vuln/detail/CVE-2024-57726
['CWE-862']
2026.05.28
2026-05-28 19:27:12.922700+03:00
c2341561b172aed6b502162aa2558fdbc8e4d09e9b6b85fac2b9e564ad8f7fba
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-862'], 'cveID': 'CVE-2024-57726', 'notes': 'https://simple-help.com/kb---security-vulnerabilities-01-2025#security-vulnerabilities-in-simplehelp-5-5-7-and-earlier ; https://nvd.nist.gov/vuln/detail/CVE-2024-57726', 'dueDate': '2026-05-08', 'product': 'SimpleHelp', 'dateAdded': '2026-04-24', 'vendorProject': 'SimpleHelp ', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.', 'vulnerabilityName': 'SimpleHelp Missing Authorization Vulnerability', 'knownRansomwareCampaignUse': 'Known'}
CVE-2026-39987
Marimo
Marimo
Marimo Remote Code Execution Vulnerability
2026-04-23
Marimo contains an pre-authorization remote code execution vulnerability, allowing an unauthenticated attacked to shell access and execute arbitrary system commands.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-05-07
Unknown
https://github.com/marimo-team/marimo/security/advisories/GHSA-2679-6mx9-h9xc ; https://nvd.nist.gov/vuln/detail/CVE-2026-39987
['CWE-306']
2026.05.28
2026-05-28 19:27:12.922700+03:00
624c944e6b6186b01323c3d58349d603d07e20db21fbcc249e08f03dfd969ef7
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-306'], 'cveID': 'CVE-2026-39987', 'notes': 'https://github.com/marimo-team/marimo/security/advisories/GHSA-2679-6mx9-h9xc ; https://nvd.nist.gov/vuln/detail/CVE-2026-39987', 'dueDate': '2026-05-07', 'product': 'Marimo', 'dateAdded': '2026-04-23', 'vendorProject': 'Marimo', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Marimo contains an pre-authorization remote code execution vulnerability, allowing an unauthenticated attacked to shell access and execute arbitrary system commands.', 'vulnerabilityName': 'Marimo Remote Code Execution Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2026-20122
Cisco
Catalyst SD-WAN Manger
Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability
2026-04-20
Cisco Catalyst SD-WAN Manager contains an incorrect use of privileged APIs vulnerability due to improper file handling on the API interface of an affected system. An attacker could exploit this vulnerability by uploading a malicious file on the local file system. A successful exploit could allow the attacker to overwrite arbitrary files on the affected system and gain vmanage user privileges.
Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.
2026-04-23
Unknown
CISA Mitigation Instructions: https://www.cisa.gov/news-events/directives/ed-26-03-mitigate-vulnerabilities-cisco-sd-wan-systems ; https://www.cisa.gov/news-events/directives/supplemental-direction-ed-26-03-hunt-and-hardening-guidance-cisco-sd-wan-systems ; https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v ; https://nvd.nist.gov/vuln/detail/CVE-2026-20122
['CWE-648']
2026.05.28
2026-05-28 19:27:12.922700+03:00
7414d7c6a0b5669630b21e1a2830128c5a49eb5cd91c178a349fc0a7a143a4ce
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-648'], 'cveID': 'CVE-2026-20122', 'notes': 'CISA Mitigation Instructions: https://www.cisa.gov/news-events/directives/ed-26-03-mitigate-vulnerabilities-cisco-sd-wan-systems ; https://www.cisa.gov/news-events/directives/supplemental-direction-ed-26-03-hunt-and-hardening-guidance-cisco-sd-wan-systems ; https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v ; https://nvd.nist.gov/vuln/detail/CVE-2026-20122', 'dueDate': '2026-04-23', 'product': 'Catalyst SD-WAN Manger', 'dateAdded': '2026-04-20', 'vendorProject': 'Cisco', 'requiredAction': 'Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.', 'shortDescription': 'Cisco Catalyst SD-WAN Manager contains an incorrect use of privileged APIs vulnerability due to improper file handling on the API interface of an affected system. An attacker could exploit this vulnerability by uploading a malicious file on the local file system. A successful exploit could allow the attacker to overwrite arbitrary files on the affected system and gain vmanage user privileges.', 'vulnerabilityName': 'Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2026-20133
Cisco
Catalyst SD-WAN Manager
Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
2026-04-20
Cisco Catalyst SD-WAN Manager contains an exposure of sensitive information to an unauthorized actor vulnerability that could allow remote attackers to view sensitive information on affected systems.
Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.
2026-04-23
Unknown
CISA Mitigation Instructions: https://www.cisa.gov/news-events/directives/ed-26-03-mitigate-vulnerabilities-cisco-sd-wan-systems ; https://www.cisa.gov/news-events/directives/supplemental-direction-ed-26-03-hunt-and-hardening-guidance-cisco-sd-wan-systems ; https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v ; https://nvd.nist.gov/vuln/detail/CVE-2026-20133
['CWE-200']
2026.05.28
2026-05-28 19:27:12.922700+03:00
6e8f1f008372f9b9aeb049637c6254270076144d433ad6e9ffcad0922efd56a1
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-200'], 'cveID': 'CVE-2026-20133', 'notes': 'CISA Mitigation Instructions: https://www.cisa.gov/news-events/directives/ed-26-03-mitigate-vulnerabilities-cisco-sd-wan-systems ; https://www.cisa.gov/news-events/directives/supplemental-direction-ed-26-03-hunt-and-hardening-guidance-cisco-sd-wan-systems ; https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v ; https://nvd.nist.gov/vuln/detail/CVE-2026-20133', 'dueDate': '2026-04-23', 'product': 'Catalyst SD-WAN Manager', 'dateAdded': '2026-04-20', 'vendorProject': 'Cisco', 'requiredAction': 'Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.', 'shortDescription': 'Cisco Catalyst SD-WAN Manager contains an exposure of sensitive information to an unauthorized actor vulnerability that could allow remote attackers to view sensitive information on affected systems.', 'vulnerabilityName': 'Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2025-2749
Kentico
Kentico Xperience
Kentico Xperience Path Traversal Vulnerability
2026-04-20
Kentico Xperience contains a path traversal vulnerability that could allow an authenticated user's Staging Sync Server to upload arbitrary data to path relative locations.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-05-04
Unknown
https://devnet.kentico.com/download/hotfixes ; https://nvd.nist.gov/vuln/detail/CVE-2025-2749
['CWE-22', 'CWE-434']
2026.05.28
2026-05-28 19:27:12.922700+03:00
48076f3d6b0cfb4c8df57f5ac728244ad305517c78c5148a3c8dffebf0347431
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-22', 'CWE-434'], 'cveID': 'CVE-2025-2749', 'notes': 'https://devnet.kentico.com/download/hotfixes ; https://nvd.nist.gov/vuln/detail/CVE-2025-2749', 'dueDate': '2026-05-04', 'product': 'Kentico Xperience', 'dateAdded': '2026-04-20', 'vendorProject': 'Kentico', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': "Kentico Xperience contains a path traversal vulnerability that could allow an authenticated user's Staging Sync Server to upload arbitrary data to path relative locations.", 'vulnerabilityName': 'Kentico Xperience Path Traversal Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2023-27351
PaperCut
NG/MF
PaperCut NG/MF Improper Authentication Vulnerability
2026-04-20
PaperCut NG/MF contains an improper authentication vulnerability that could allow remote attackers to bypass authentication on affected installations via the SecurityRequestFilter class.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-05-04
Known
https://www.papercut.com/kb/Main/PO-1216-and-PO-1219 ; https://nvd.nist.gov/vuln/detail/CVE-2023-27351
['CWE-287']
2026.05.28
2026-05-28 19:27:12.922700+03:00
4cd697e2592f5b4eea57147924245fe6653942c85c6e7f609ee02da760120a3e
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-287'], 'cveID': 'CVE-2023-27351', 'notes': 'https://www.papercut.com/kb/Main/PO-1216-and-PO-1219 ; https://nvd.nist.gov/vuln/detail/CVE-2023-27351', 'dueDate': '2026-05-04', 'product': 'NG/MF', 'dateAdded': '2026-04-20', 'vendorProject': 'PaperCut', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'PaperCut NG/MF contains an improper authentication vulnerability that could allow remote attackers to bypass authentication on affected installations via the SecurityRequestFilter class.', 'vulnerabilityName': 'PaperCut NG/MF Improper Authentication Vulnerability', 'knownRansomwareCampaignUse': 'Known'}
CVE-2025-48700
Synacor
Zimbra Collaboration Suite (ZCS)
Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability
2026-04-20
Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that could allow attackers to execute arbitrary JavaScript within the user's session, potentially leading to unauthorized access to sensitive information.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-04-23
Unknown
https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories ; https://nvd.nist.gov/vuln/detail/CVE-2025-48700
['CWE-79']
2026.05.28
2026-05-28 19:27:12.922700+03:00
12692dd7ba893ff8409a6859176235e56d54191a74e9b21ba559910aea56f66f
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-79'], 'cveID': 'CVE-2025-48700', 'notes': 'https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories ; https://nvd.nist.gov/vuln/detail/CVE-2025-48700', 'dueDate': '2026-04-23', 'product': 'Zimbra Collaboration Suite (ZCS)', 'dateAdded': '2026-04-20', 'vendorProject': 'Synacor', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': "Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that could allow attackers to execute arbitrary JavaScript within the user's session, potentially leading to unauthorized access to sensitive information.", 'vulnerabilityName': 'Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2026-20128
Cisco
Catalyst SD-WAN Manager
Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability
2026-04-20
Cisco Catalyst SD-WAN Manager contains a storing passwords in a recoverable format vulnerability that allows an authenticated, local attacker to gain DCA user privileges by accessing a credential file for the DCA user on the filesystem as a low-privileged user.
Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.
2026-04-23
Unknown
CISA Mitigation Instructions: https://www.cisa.gov/news-events/directives/ed-26-03-mitigate-vulnerabilities-cisco-sd-wan-systems ; https://www.cisa.gov/news-events/directives/supplemental-direction-ed-26-03-hunt-and-hardening-guidance-cisco-sd-wan-systems ; https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v ; https://nvd.nist.gov/vuln/detail/CVE-2026-20128
['CWE-257']
2026.05.28
2026-05-28 19:27:12.922700+03:00
e0c1b6286e06f1e5d027ed00a80eaf72c4b161f475633974c20983fe9c806cee
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-257'], 'cveID': 'CVE-2026-20128', 'notes': 'CISA Mitigation Instructions: https://www.cisa.gov/news-events/directives/ed-26-03-mitigate-vulnerabilities-cisco-sd-wan-systems ; https://www.cisa.gov/news-events/directives/supplemental-direction-ed-26-03-hunt-and-hardening-guidance-cisco-sd-wan-systems ; https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v ; https://nvd.nist.gov/vuln/detail/CVE-2026-20128', 'dueDate': '2026-04-23', 'product': 'Catalyst SD-WAN Manager', 'dateAdded': '2026-04-20', 'vendorProject': 'Cisco', 'requiredAction': 'Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.', 'shortDescription': 'Cisco Catalyst SD-WAN Manager contains a storing passwords in a recoverable format vulnerability that allows an authenticated, local attacker to gain DCA user privileges by accessing a credential file for the DCA user on the filesystem as a low-privileged user.', 'vulnerabilityName': 'Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2025-32975
Quest
KACE Systems Management Appliance (SMA)
Quest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability
2026-04-20
Quest KACE Systems Management Appliance (SMA) contains an improper authentication vulnerability that could allow attackers to impersonate legitimate users without valid credentials.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-05-04
Unknown
https://support.quest.com/kb/4379499/quest-response-to-kace-sma-vulnerabilities-cve-2025-32975-cve-2025-32976-cve-2025-32977-cve-2025-32978 ; https://nvd.nist.gov/vuln/detail/CVE-2025-32975
['CWE-287']
2026.05.28
2026-05-28 19:27:12.922700+03:00
0a8a139476172a02c6c13a55423774fbe87c146991f1e442966c96c04af394c0
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-287'], 'cveID': 'CVE-2025-32975', 'notes': 'https://support.quest.com/kb/4379499/quest-response-to-kace-sma-vulnerabilities-cve-2025-32975-cve-2025-32976-cve-2025-32977-cve-2025-32978 ; https://nvd.nist.gov/vuln/detail/CVE-2025-32975', 'dueDate': '2026-05-04', 'product': 'KACE Systems Management Appliance (SMA)', 'dateAdded': '2026-04-20', 'vendorProject': 'Quest', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Quest KACE Systems Management Appliance (SMA) contains an improper authentication vulnerability that could allow attackers to impersonate legitimate users without valid credentials.', 'vulnerabilityName': 'Quest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2024-27199
JetBrains
TeamCity
JetBrains TeamCity Relative Path Traversal Vulnerability
2026-04-20
JetBrains TeamCity contains a relative path traversal vulnerability that could allow limited admin actions to be performed.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-05-04
Known
https://www.jetbrains.com/privacy-security/issues-fixed/ ; https://blog.jetbrains.com/teamcity/2024/03/additional-critical-security-issues-affecting-teamcity-on-premises-cve-2024-27198-and-cve-2024-27199-update-to-2023-11-4-now/ ; https://nvd.nist.gov/vuln/detail/CVE-2024-27199
['CWE-23']
2026.05.28
2026-05-28 19:27:12.922700+03:00
bd5e06ddec9738f6d43bfa8082b4024ffe265faa08574f962574b33f23461fc4
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-23'], 'cveID': 'CVE-2024-27199', 'notes': 'https://www.jetbrains.com/privacy-security/issues-fixed/ ; https://blog.jetbrains.com/teamcity/2024/03/additional-critical-security-issues-affecting-teamcity-on-premises-cve-2024-27198-and-cve-2024-27199-update-to-2023-11-4-now/ ; https://nvd.nist.gov/vuln/detail/CVE-2024-27199', 'dueDate': '2026-05-04', 'product': 'TeamCity', 'dateAdded': '2026-04-20', 'vendorProject': 'JetBrains', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'JetBrains TeamCity contains a relative path traversal vulnerability that could allow limited admin actions to be performed.', 'vulnerabilityName': 'JetBrains TeamCity Relative Path Traversal Vulnerability', 'knownRansomwareCampaignUse': 'Known'}
CVE-2026-34197
Apache
ActiveMQ
Apache ActiveMQ Improper Input Validation Vulnerability
2026-04-16
Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-04-30
Unknown
https://activemq.apache.org/security-advisories.data/CVE-2026-34197-announcement.txt ; https://nvd.nist.gov/vuln/detail/CVE-2026-34197
['CWE-20', 'CWE-94']
2026.05.28
2026-05-28 19:27:12.922700+03:00
16a1b378f2f7d5d3c210f3ef8ffa72d75fa521655e84a4472cbbc0bcaf6aabe7
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-20', 'CWE-94'], 'cveID': 'CVE-2026-34197', 'notes': 'https://activemq.apache.org/security-advisories.data/CVE-2026-34197-announcement.txt ; https://nvd.nist.gov/vuln/detail/CVE-2026-34197', 'dueDate': '2026-04-30', 'product': 'ActiveMQ', 'dateAdded': '2026-04-16', 'vendorProject': 'Apache', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection.', 'vulnerabilityName': 'Apache ActiveMQ Improper Input Validation Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2009-0238
Microsoft
Office
Microsoft Office Remote Code Execution
2026-04-14
Microsoft Office Excel contains a remote code execution vulnerability that could allow an attacker to take complete control of an affected system if a user opens a specially crafted Excel file that includes a malformed object.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-04-28
Unknown
https://learn.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-009 ; https://nvd.nist.gov/vuln/detail/CVE-2009-0238
['CWE-94']
2026.05.28
2026-05-28 19:27:12.922700+03:00
d37a38069ca62fb39e9b2c556e1397f6fdae2d986d7a10ef03158c757e73acfd
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-94'], 'cveID': 'CVE-2009-0238', 'notes': 'https://learn.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-009 ; https://nvd.nist.gov/vuln/detail/CVE-2009-0238', 'dueDate': '2026-04-28', 'product': 'Office', 'dateAdded': '2026-04-14', 'vendorProject': 'Microsoft', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Microsoft Office Excel contains a remote code execution vulnerability that could allow an attacker to take complete control of an affected system if a user opens a specially crafted Excel file that includes a malformed object.', 'vulnerabilityName': 'Microsoft Office Remote Code Execution', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2026-32201
Microsoft
SharePoint Server
Microsoft SharePoint Server Improper Input Validation Vulnerability
2026-04-14
Microsoft SharePoint Server contains an improper input validation vulnerability that allows an unauthorized attacker to perform spoofing over a network.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-04-28
Unknown
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-32201 ; https://nvd.nist.gov/vuln/detail/CVE-2026-32201
['CWE-20']
2026.05.28
2026-05-28 19:27:12.922700+03:00
2a4acf1bc527615decaa127246df9a6648d386e64faedb68e4fa5bdaa1cfb0f4
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-20'], 'cveID': 'CVE-2026-32201', 'notes': 'https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-32201 ; https://nvd.nist.gov/vuln/detail/CVE-2026-32201', 'dueDate': '2026-04-28', 'product': 'SharePoint Server', 'dateAdded': '2026-04-14', 'vendorProject': 'Microsoft', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Microsoft SharePoint Server contains an improper input validation vulnerability that allows an unauthorized attacker to perform spoofing over a network.', 'vulnerabilityName': 'Microsoft SharePoint Server Improper Input Validation Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2012-1854
Microsoft
Visual Basic for Applications (VBA)
Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability
2026-04-13
Microsoft Visual Basic for Applications (VBA) contains an insecure library loading vulnerability that could allow for remote code execution.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-04-27
Unknown
https://learn.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-046 ; https://nvd.nist.gov/vuln/detail/CVE-2012-1854
['CWE-426']
2026.05.28
2026-05-28 19:27:12.922700+03:00
1499cfb31789adae0540b832481ca1e657e42cd79e0582d725b4353e3d21db30
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-426'], 'cveID': 'CVE-2012-1854', 'notes': 'https://learn.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-046 ; https://nvd.nist.gov/vuln/detail/CVE-2012-1854', 'dueDate': '2026-04-27', 'product': 'Visual Basic for Applications (VBA)', 'dateAdded': '2026-04-13', 'vendorProject': 'Microsoft', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Microsoft Visual Basic for Applications (VBA) contains an insecure library loading vulnerability that could allow for remote code execution.', 'vulnerabilityName': 'Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2025-60710
Microsoft
Windows
Microsoft Windows Link Following Vulnerability
2026-04-13
Microsoft Windows contains a link following vulnerability that allows for privilege escalation
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-04-27
Unknown
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-60710 ; https://nvd.nist.gov/vuln/detail/CVE-2025-60710
['CWE-59']
2026.05.28
2026-05-28 19:27:12.922700+03:00
b0e5459e76dec74899342341b3054bec90626a946233a21dd977920704bdc3d6
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-59'], 'cveID': 'CVE-2025-60710', 'notes': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-60710 ; https://nvd.nist.gov/vuln/detail/CVE-2025-60710', 'dueDate': '2026-04-27', 'product': 'Windows', 'dateAdded': '2026-04-13', 'vendorProject': 'Microsoft', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Microsoft Windows contains a link following vulnerability that allows for privilege escalation', 'vulnerabilityName': 'Microsoft Windows Link Following Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2023-21529
Microsoft
Exchange Server
Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability
2026-04-13
Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-04-27
Known
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21529 ; https://nvd.nist.gov/vuln/detail/CVE-2023-21529
['CWE-502']
2026.05.28
2026-05-28 19:27:12.922700+03:00
05e8913d6533e8b23e981108f1db25e30571106465bdc97d24734024e0dfe24e
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-502'], 'cveID': 'CVE-2023-21529', 'notes': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21529 ; https://nvd.nist.gov/vuln/detail/CVE-2023-21529', 'dueDate': '2026-04-27', 'product': 'Exchange Server', 'dateAdded': '2026-04-13', 'vendorProject': 'Microsoft', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution.', 'vulnerabilityName': 'Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability', 'knownRansomwareCampaignUse': 'Known'}
CVE-2023-36424
Microsoft
Windows
Microsoft Windows Out-of-Bounds Read Vulnerability
2026-04-13
Microsoft Windows Common Log File System Driver contains an out-of-bounds read vulnerability that could allow a threat actor for privileges escalation
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-04-27
Unknown
https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2023-36424 ; https://nvd.nist.gov/vuln/detail/CVE-2023-36424
['CWE-125']
2026.05.28
2026-05-28 19:27:12.922700+03:00
e82b9aa710793eb1f380dc8b49f6f2aed45c103fdef43b270886575a934f8224
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-125'], 'cveID': 'CVE-2023-36424', 'notes': 'https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2023-36424 ; https://nvd.nist.gov/vuln/detail/CVE-2023-36424', 'dueDate': '2026-04-27', 'product': 'Windows', 'dateAdded': '2026-04-13', 'vendorProject': 'Microsoft', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Microsoft Windows Common Log File System Driver contains an out-of-bounds read vulnerability that could allow a threat actor for privileges escalation', 'vulnerabilityName': 'Microsoft Windows Out-of-Bounds Read Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2020-9715
Adobe
Acrobat
Adobe Acrobat Use-After-Free Vulnerability
2026-04-13
Adobe Acrobat contains a use-after-free vulnerability that allows for code execution
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-04-27
Unknown
https://helpx.adobe.com/security/products/acrobat/apsb20-48.html ; https://nvd.nist.gov/vuln/detail/CVE-2020-9715
['CWE-416']
2026.05.28
2026-05-28 19:27:12.922700+03:00
1f0f1fdabbefb0ac4194ae87444d7f652c824bc10dd3046eeb8fc81ad7daca4e
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-416'], 'cveID': 'CVE-2020-9715', 'notes': 'https://helpx.adobe.com/security/products/acrobat/apsb20-48.html ; https://nvd.nist.gov/vuln/detail/CVE-2020-9715', 'dueDate': '2026-04-27', 'product': 'Acrobat', 'dateAdded': '2026-04-13', 'vendorProject': 'Adobe', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Adobe Acrobat contains a use-after-free vulnerability that allows for code execution', 'vulnerabilityName': 'Adobe Acrobat Use-After-Free Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2026-21643
Fortinet
FortiClient EMS
Fortinet FortiClient EMS SQL Injection Vulnerability
2026-04-13
Fortinet FortiClient EMS contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-04-16
Unknown
https://fortiguard.fortinet.com/psirt/FG-IR-25-1142 ; https://nvd.nist.gov/vuln/detail/CVE-2026-21643
['CWE-89']
2026.05.28
2026-05-28 19:27:12.922700+03:00
a44ab2ec1e4eeee7c78924d1af7595e9c35724e088b8eee13b744cebf4bd6a9f
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-89'], 'cveID': 'CVE-2026-21643', 'notes': 'https://fortiguard.fortinet.com/psirt/FG-IR-25-1142 ; https://nvd.nist.gov/vuln/detail/CVE-2026-21643', 'dueDate': '2026-04-16', 'product': 'FortiClient EMS', 'dateAdded': '2026-04-13', 'vendorProject': 'Fortinet', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Fortinet FortiClient EMS contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.', 'vulnerabilityName': 'Fortinet FortiClient EMS SQL Injection Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2026-34621
Adobe
Acrobat and Reader
Adobe Acrobat and Reader Prototype Pollution Vulnerability
2026-04-13
Adobe Acrobat and Reader contain a prototype pollution vulnerability that allows for arbitrary code execution.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-04-27
Unknown
https://helpx.adobe.com/security/products/acrobat/apsb26-43.html ; https://nvd.nist.gov/vuln/detail/CVE-2026-34621
['CWE-1321']
2026.05.28
2026-05-28 19:27:12.922700+03:00
0621a5f70c8cc0f34f6844613f78f286fe924c86bc9e383e6df5752901902825
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-1321'], 'cveID': 'CVE-2026-34621', 'notes': 'https://helpx.adobe.com/security/products/acrobat/apsb26-43.html ; https://nvd.nist.gov/vuln/detail/CVE-2026-34621', 'dueDate': '2026-04-27', 'product': 'Acrobat and Reader', 'dateAdded': '2026-04-13', 'vendorProject': 'Adobe', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Adobe Acrobat and Reader contain a prototype pollution vulnerability that allows for arbitrary code execution.', 'vulnerabilityName': 'Adobe Acrobat and Reader Prototype Pollution Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2026-1340
Ivanti
Endpoint Manager Mobile (EPMM)
Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
2026-04-08
Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-04-11
Unknown
Please adhere to Ivanti's guidelines to assess exposure and mitigate risks. Check for signs of potential compromise on all internet accessible Ivanti products affected by this vulnerability. Apply any final mitigations provided by the vendor as soon as possible. For more information please see: https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2026-1281-CVE-2026-1340?language=en_US ; https://support.mobileiron.com/mi/vsp/AB1786671/ivanti-security-update-1761642-1.1.0S-5.noarch.rpm ; https://support.mobileiron.com/mi/vsp/AB1786671/ivanti-security-update-1761642-1.1.0L-5.noarch.rpm ; https://nvd.nist.gov/vuln/detail/CVE-2026-1340
['CWE-94']
2026.05.28
2026-05-28 19:27:12.922700+03:00
8c43f5ad410107d0395da49fe9e8a2c703ddc50b14d386eefa47136943402f78
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-94'], 'cveID': 'CVE-2026-1340', 'notes': "Please adhere to Ivanti's guidelines to assess exposure and mitigate risks. Check for signs of potential compromise on all internet accessible Ivanti products affected by this vulnerability. Apply any final mitigations provided by the vendor as soon as possible. For more information please see: https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2026-1281-CVE-2026-1340?language=en_US ; https://support.mobileiron.com/mi/vsp/AB1786671/ivanti-security-update-1761642-1.1.0S-5.noarch.rpm ; https://support.mobileiron.com/mi/vsp/AB1786671/ivanti-security-update-1761642-1.1.0L-5.noarch.rpm ; https://nvd.nist.gov/vuln/detail/CVE-2026-1340", 'dueDate': '2026-04-11', 'product': 'Endpoint Manager Mobile (EPMM)', 'dateAdded': '2026-04-08', 'vendorProject': 'Ivanti', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution.', 'vulnerabilityName': 'Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2026-35616
Fortinet
FortiClient EMS
Fortinet FortiClient EMS Improper Access Control Vulnerability
2026-04-06
Fortinet FortiClient EMS contains an improper access control vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-04-09
Unknown
Please adhere to Fortinet's guidelines to assess exposure and mitigate risks. Check for signs of potential compromise on all internet accessible Fortinet products affected by this vulnerability. Apply any final mitigations provided by the vendor as soon as they become available. For more information please see: https://fortiguard.fortinet.com/psirt/FG-IR-26-099 ; https://nvd.nist.gov/vuln/detail/CVE-2026-35616
['CWE-284']
2026.05.28
2026-05-28 19:27:12.922700+03:00
5d71d092c2a31c827adcb2659facf4fb41a09c6d3a3880d265d4fb3982d48aab
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-284'], 'cveID': 'CVE-2026-35616', 'notes': "Please adhere to Fortinet's guidelines to assess exposure and mitigate risks. Check for signs of potential compromise on all internet accessible Fortinet products affected by this vulnerability. Apply any final mitigations provided by the vendor as soon as they become available. For more information please see: https://fortiguard.fortinet.com/psirt/FG-IR-26-099 ; https://nvd.nist.gov/vuln/detail/CVE-2026-35616", 'dueDate': '2026-04-09', 'product': 'FortiClient EMS', 'dateAdded': '2026-04-06', 'vendorProject': 'Fortinet', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Fortinet FortiClient EMS contains an improper access control vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.', 'vulnerabilityName': 'Fortinet FortiClient EMS Improper Access Control Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2026-33017
Langflow
Langflow
Langflow Code Injection Vulnerability
2026-03-25
Langflow contains a code injection vulnerability that could allow building public flows without requiring authentication.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-04-08
Unknown
https://github.com/langflow-ai/langflow/security/advisories/GHSA-vwmf-pq79-vjvx ; https://nvd.nist.gov/vuln/detail/CVE-2026-33017
['CWE-94', 'CWE-95', 'CWE-306']
2026.05.28
2026-05-28 19:27:12.922700+03:00
c95b40ecd9301befe418c46ee4eb15a1b47862962148b1a4fa0bd7078ffcf88e
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-94', 'CWE-95', 'CWE-306'], 'cveID': 'CVE-2026-33017', 'notes': 'https://github.com/langflow-ai/langflow/security/advisories/GHSA-vwmf-pq79-vjvx ; https://nvd.nist.gov/vuln/detail/CVE-2026-33017', 'dueDate': '2026-04-08', 'product': 'Langflow', 'dateAdded': '2026-03-25', 'vendorProject': 'Langflow', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Langflow contains a code injection vulnerability that could allow building public flows without requiring authentication.', 'vulnerabilityName': 'Langflow Code Injection Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2026-3502
TrueConf
Client
TrueConf Client Download of Code Without Integrity Check Vulnerability
2026-04-02
TrueConf Client contains a download of code without integrity check vulnerability. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the payload is executed or installed by the updater, this may result in arbitrary code execution in the context of the updating process or user.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-04-16
Unknown
https://trueconf.com/blog/update/trueconf-8-5 ; https://trueconf.com/downloads/windows.html ; https://nvd.nist.gov/vuln/detail/CVE-2026-3502
['CWE-494']
2026.05.28
2026-05-28 19:27:12.922700+03:00
5de5ff590625ea1476c42dde68051b71ddd5031cabc97e79b8892fc2ae3b5dd0
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-494'], 'cveID': 'CVE-2026-3502', 'notes': 'https://trueconf.com/blog/update/trueconf-8-5 ; https://trueconf.com/downloads/windows.html ; https://nvd.nist.gov/vuln/detail/CVE-2026-3502', 'dueDate': '2026-04-16', 'product': 'Client', 'dateAdded': '2026-04-02', 'vendorProject': 'TrueConf', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'TrueConf Client contains a download of code without integrity check vulnerability. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the payload is executed or installed by the updater, this may result in arbitrary code execution in the context of the updating process or user.', 'vulnerabilityName': 'TrueConf Client Download of Code Without Integrity Check Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2026-5281
Google
Dawn
Google Dawn Use-After-Free Vulnerability
2026-04-01
Google Dawn contains an use-after-free vulnerability that could allow a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. This vulnerability could affect multiple Chromium-based products including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-04-15
Unknown
This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_31.html ; https://nvd.nist.gov/vuln/detail/CVE-2026-5281
['CWE-416']
2026.05.28
2026-05-28 19:27:12.922700+03:00
8b1802d067685ea19cacf914f990a4f9788994245b0dad26bc2a5ef672f24122
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-416'], 'cveID': 'CVE-2026-5281', 'notes': 'This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_31.html ; https://nvd.nist.gov/vuln/detail/CVE-2026-5281 ', 'dueDate': '2026-04-15', 'product': 'Dawn', 'dateAdded': '2026-04-01', 'vendorProject': 'Google', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Google Dawn contains an use-after-free vulnerability that could allow a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. This vulnerability could affect multiple Chromium-based products including, but not limited to, Google Chrome, Microsoft Edge, and Opera.', 'vulnerabilityName': 'Google Dawn Use-After-Free Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2026-3055
Citrix
NetScaler
Citrix NetScaler Out-of-Bounds Read Vulnerability
2026-03-30
Citrix NetScaler ADC (formerly Citrix ADC), NetScaler Gateway (formerly Citrix Gateway) and NetScaler ADC FIPS and NDcPP contain an out-of-bounds reads vulnerability when configured as a SAML IDP leading to memory overread.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-04-02
Unknown
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696300&articleURL=NetScaler_ADC_and_NetScaler_Gateway_Security_Bulletin_for_CVE_2026_3055_and_CVE_2026_4368 ; https://nvd.nist.gov/vuln/detail/CVE-2026-3055
['CWE-125']
2026.05.28
2026-05-28 19:27:12.922700+03:00
258951190c861a433345b5c547a1b221c38525cb27e8bac22e2ad5f17325ca60
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-125'], 'cveID': 'CVE-2026-3055', 'notes': 'https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696300&articleURL=NetScaler_ADC_and_NetScaler_Gateway_Security_Bulletin_for_CVE_2026_3055_and_CVE_2026_4368 ; https://nvd.nist.gov/vuln/detail/CVE-2026-3055', 'dueDate': '2026-04-02', 'product': 'NetScaler', 'dateAdded': '2026-03-30', 'vendorProject': 'Citrix', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Citrix NetScaler ADC (formerly Citrix ADC), NetScaler Gateway (formerly Citrix Gateway) and NetScaler ADC FIPS and NDcPP contain an out-of-bounds reads vulnerability when configured as a SAML IDP leading to memory overread.', 'vulnerabilityName': 'Citrix NetScaler Out-of-Bounds Read Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2025-53521
F5
BIG-IP
F5 BIG-IP Stack-Based Buffer Overflow Vulnerability
2026-03-27
F5 BIG-IP APM contains a stack-based buffer overflow vulnerability that could allow a threat actor to achieve remote code execution.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-03-30
Unknown
Please adhere to F5’s guidelines to assess exposure and mitigate risks. Check for signs of potential compromise on all internet accessible F5 products affected by this vulnerability. For more information please see: https://my.f5.com/manage/s/article/K000156741 ; https://my.f5.com/manage/s/article/K000160486 ; https://my.f5.com/manage/s/article/K11438344 ; https://nvd.nist.gov/vuln/detail/CVE-2025-53521
['CWE-121']
2026.05.28
2026-05-28 19:27:12.922700+03:00
6abbb201de4a0b7f41dcda009132a211a86b5dbc92716f3ca3e91447eb96854f
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-121'], 'cveID': 'CVE-2025-53521', 'notes': 'Please adhere to F5’s guidelines to assess exposure and mitigate risks. Check for signs of potential compromise on all internet accessible F5 products affected by this vulnerability. For more information please see: https://my.f5.com/manage/s/article/K000156741 ; https://my.f5.com/manage/s/article/K000160486 ; https://my.f5.com/manage/s/article/K11438344 ; https://nvd.nist.gov/vuln/detail/CVE-2025-53521', 'dueDate': '2026-03-30', 'product': 'BIG-IP', 'dateAdded': '2026-03-27', 'vendorProject': 'F5', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'F5 BIG-IP APM contains a stack-based buffer overflow vulnerability that could allow a threat actor to achieve remote code execution.', 'vulnerabilityName': 'F5 BIG-IP Stack-Based Buffer Overflow Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2026-33634
Aquasecurity
Trivy
Aquasecurity Trivy Embedded Malicious Code Vulnerability
2026-03-26
Aquasecurity Trivy contains an embedded malicious code vulnerability that could allow an attacker to gain access to everything in the CI/CD environment, including all tokens, SSH keys, cloud credentials, database passwords, and any sensitive configuration in memory.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-04-09
Unknown
This vulnerability involves a supply‑chain compromise in a product that may be used across multiple products and environments. Additional vendor‑provided guidance must be followed to ensure full remediation. For more information, please see: https://github.com/advisories/GHSA-69fq-xp46-6x23 ; https://nvd.nist.gov/vuln/detail/CVE-2026-33634
['CWE-506']
2026.05.28
2026-05-28 19:27:12.922700+03:00
2d770d5d738a6a33945345c4732a6e6f6d4f2469503758036b2bfdce5e5942ba
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-506'], 'cveID': 'CVE-2026-33634', 'notes': 'This vulnerability involves a supply‑chain compromise in a product that may be used across multiple products and environments. Additional vendor‑provided guidance must be followed to ensure full remediation. For more information, please see: https://github.com/advisories/GHSA-69fq-xp46-6x23 ; https://nvd.nist.gov/vuln/detail/CVE-2026-33634', 'dueDate': '2026-04-09', 'product': 'Trivy', 'dateAdded': '2026-03-26', 'vendorProject': 'Aquasecurity', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Aquasecurity Trivy contains an embedded malicious code vulnerability that could allow an attacker to gain access to everything in the CI/CD environment, including all tokens, SSH keys, cloud credentials, database passwords, and any sensitive configuration in memory.', 'vulnerabilityName': 'Aquasecurity Trivy Embedded Malicious Code Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2025-32432
Craft CMS
Craft CMS
Craft CMS Code Injection Vulnerability
2026-03-20
Craft CMS contains a code injection vulnerability that allows a remote attacker to execute arbitrary code.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-04-03
Unknown
https://craftcms.com/knowledge-base/craft-cms-cve-2025-32432 ; https://github.com/craftcms/cms/security/advisories/GHSA-f3gw-9ww9-jmc3 ; https://nvd.nist.gov/vuln/detail/CVE-2025-32432
['CWE-94']
2026.05.28
2026-05-28 19:27:12.922700+03:00
6327a28bb27b28d0160b52f76d4198f96d4ec7eeb531edb9c9d030631b58c5bc
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-94'], 'cveID': 'CVE-2025-32432', 'notes': 'https://craftcms.com/knowledge-base/craft-cms-cve-2025-32432 ; https://github.com/craftcms/cms/security/advisories/GHSA-f3gw-9ww9-jmc3 ; https://nvd.nist.gov/vuln/detail/CVE-2025-32432', 'dueDate': '2026-04-03', 'product': 'Craft CMS', 'dateAdded': '2026-03-20', 'vendorProject': 'Craft CMS', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Craft CMS contains a code injection vulnerability that allows a remote attacker to execute arbitrary code.', 'vulnerabilityName': 'Craft CMS Code Injection Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2025-54068
Laravel
Livewire
Laravel Livewire Code Injection Vulnerability
2026-03-20
Laravel Livewire contain a code injection vulnerability that could allow unauthenticated attackers to achieve remote command execution in specific scenarios.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-04-03
Unknown
https://github.com/livewire/livewire/security/advisories/GHSA-29cq-5w36-x7w3 ; https://github.com/livewire/livewire/commit/ef04be759da41b14d2d129e670533180a44987dc ; https://nvd.nist.gov/vuln/detail/CVE-2025-54068
['CWE-94']
2026.05.28
2026-05-28 19:27:12.922700+03:00
5ab4d067287ed87a0ee5bd44c245d878ad6b5ee36f7b05157950f762ee5abe2c
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-94'], 'cveID': 'CVE-2025-54068', 'notes': 'https://github.com/livewire/livewire/security/advisories/GHSA-29cq-5w36-x7w3 ; https://github.com/livewire/livewire/commit/ef04be759da41b14d2d129e670533180a44987dc ; https://nvd.nist.gov/vuln/detail/CVE-2025-54068', 'dueDate': '2026-04-03', 'product': 'Livewire', 'dateAdded': '2026-03-20', 'vendorProject': 'Laravel', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Laravel Livewire contain a code injection vulnerability that could allow unauthenticated attackers to achieve remote command execution in specific scenarios.', 'vulnerabilityName': 'Laravel Livewire Code Injection Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2025-43510
Apple
Multiple Products
Apple Multiple Products Improper Locking Vulnerability
2026-03-20
Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain an improper locking vulnerability that could allow a malicious application to cause unexpected changes in memory shared between processes.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-04-03
Unknown
https://support.apple.com/en-us/125632 ; https://support.apple.com/en-us/125633 ; https://support.apple.com/en-us/125634 ; https://support.apple.com/en-us/125635 ; https://support.apple.com/en-us/125636 ; https://support.apple.com/en-us/125637 ; https://support.apple.com/en-us/125638 ; https://support.apple.com/en-us/125639 ; https://nvd.nist.gov/vuln/detail/CVE-2025-43510
['CWE-667']
2026.05.28
2026-05-28 19:27:12.922700+03:00
0fcfda3e0283ba8d36cc688e7dfc1970ccbf90b25c4e034e1c2f47c9a4444ece
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-667'], 'cveID': 'CVE-2025-43510', 'notes': 'https://support.apple.com/en-us/125632 ; https://support.apple.com/en-us/125633 ; https://support.apple.com/en-us/125634 ; https://support.apple.com/en-us/125635 ; https://support.apple.com/en-us/125636 ; https://support.apple.com/en-us/125637 ; https://support.apple.com/en-us/125638 ; https://support.apple.com/en-us/125639 ; https://nvd.nist.gov/vuln/detail/CVE-2025-43510', 'dueDate': '2026-04-03', 'product': 'Multiple Products', 'dateAdded': '2026-03-20', 'vendorProject': 'Apple', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain an improper locking vulnerability that could allow a malicious application to cause unexpected changes in memory shared between processes.', 'vulnerabilityName': 'Apple Multiple Products Improper Locking Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2025-43520
Apple
Multiple Products
Apple Multiple Products Classic Buffer Overflow Vulnerability
2026-03-20
Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain a classic buffer overflow vulnerability which could allow a malicious application to cause unexpected system termination or write kernel memory.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-04-03
Unknown
https://support.apple.com/en-us/125632 ; https://support.apple.com/en-us/125633 ; https://support.apple.com/en-us/125634 ; https://support.apple.com/en-us/125635 ; https://support.apple.com/en-us/125636 ; https://support.apple.com/en-us/125637 ; https://support.apple.com/en-us/125638 ; https://support.apple.com/en-us/125639 ; https://nvd.nist.gov/vuln/detail/CVE-2025-43520
['CWE-120']
2026.05.28
2026-05-28 19:27:12.922700+03:00
017d1bd9c6875b25b51055f60bb93f53266fb7d84c3716b156452ad9f022d9f8
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-120'], 'cveID': 'CVE-2025-43520', 'notes': 'https://support.apple.com/en-us/125632 ; https://support.apple.com/en-us/125633 ; https://support.apple.com/en-us/125634 ; https://support.apple.com/en-us/125635 ; https://support.apple.com/en-us/125636 ; https://support.apple.com/en-us/125637 ; https://support.apple.com/en-us/125638 ; https://support.apple.com/en-us/125639 ; https://nvd.nist.gov/vuln/detail/CVE-2025-43520', 'dueDate': '2026-04-03', 'product': 'Multiple Products', 'dateAdded': '2026-03-20', 'vendorProject': 'Apple', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain a classic buffer overflow vulnerability which could allow a malicious application to cause unexpected system termination or write kernel memory.', 'vulnerabilityName': 'Apple Multiple Products Classic Buffer Overflow Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2024-7694
TeamT5
ThreatSonar Anti-Ransomware
TeamT5 ThreatSonar Anti-Ransomware Unrestricted Upload of File with Dangerous Type Vulnerability
2026-02-17
TeamT5 ThreatSonar Anti-Ransomware contains an unrestricted upload of file with dangerous type vulnerability. ThreatSonar Anti-Ransomware does not properly validate the content of uploaded files. Remote attackers with administrator privileges on the product platform can upload malicious files, which can be used to execute arbitrary system commands on the server.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-03-10
Unknown
https://teamt5.org/en/posts/vulnerability-notice-threat-sonar-anti-ransomware-20240715/ ; https://www.twcert.org.tw/en/cp-139-8000-e5a5c-2.html ; https://nvd.nist.gov/vuln/detail/CVE-2024-7694
['CWE-434']
2026.05.28
2026-05-28 19:27:12.922700+03:00
316009e3368bff8b24a55b1d02cac1099d228010089fce7236e2f914390bb11e
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-434'], 'cveID': 'CVE-2024-7694', 'notes': 'https://teamt5.org/en/posts/vulnerability-notice-threat-sonar-anti-ransomware-20240715/ ; https://www.twcert.org.tw/en/cp-139-8000-e5a5c-2.html ; https://nvd.nist.gov/vuln/detail/CVE-2024-7694', 'dueDate': '2026-03-10', 'product': 'ThreatSonar Anti-Ransomware', 'dateAdded': '2026-02-17', 'vendorProject': 'TeamT5', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'TeamT5 ThreatSonar Anti-Ransomware contains an unrestricted upload of file with dangerous type vulnerability. ThreatSonar Anti-Ransomware does not properly validate the content of uploaded files. Remote attackers with administrator privileges on the product platform can upload malicious files, which can be used to execute arbitrary system commands on the server.', 'vulnerabilityName': 'TeamT5 ThreatSonar Anti-Ransomware Unrestricted Upload of File with Dangerous Type Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2025-31277
Apple
Multiple Products
Apple Multiple Products Buffer Overflow Vulnerability
2026-03-20
Apple Safari, iOS, watchOS, visionOS, iPadOS, macOS, and tvOS contain a buffer overflow vulnerability that could allow the processing of maliciously crafted web content which may lead to memory corruption.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-04-03
Unknown
https://support.apple.com/en-us/124147 ; https://support.apple.com/en-us/124149 ; https://support.apple.com/en-us/124152 ; https://support.apple.com/en-us/124153 ; https://support.apple.com/en-us/124155 ; https://nvd.nist.gov/vuln/detail/CVE-2025-31277
['CWE-119']
2026.05.28
2026-05-28 19:27:12.922700+03:00
56096e07d69316f67bbf949f0373fb8ba9bd3e7db09923afa2d8e8bc8290dab1
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-119'], 'cveID': 'CVE-2025-31277', 'notes': 'https://support.apple.com/en-us/124147 ; https://support.apple.com/en-us/124149 ; https://support.apple.com/en-us/124152 ; https://support.apple.com/en-us/124153 ; https://support.apple.com/en-us/124155 ; https://nvd.nist.gov/vuln/detail/CVE-2025-31277', 'dueDate': '2026-04-03', 'product': 'Multiple Products', 'dateAdded': '2026-03-20', 'vendorProject': 'Apple', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Apple Safari, iOS, watchOS, visionOS, iPadOS, macOS, and tvOS contain a buffer overflow vulnerability that could allow the processing of maliciously crafted web content which may lead to memory corruption.', 'vulnerabilityName': 'Apple Multiple Products Buffer Overflow Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2026-20131
Cisco
Secure Firewall Management Center (FMC)
Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability
2026-03-19
Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain a deserialization of untrusted data vulnerability in the web-based management interface that could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-03-22
Known
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-rce-NKhnULJh ; https://nvd.nist.gov/vuln/detail/CVE-2026-20131
['CWE-502']
2026.05.28
2026-05-28 19:27:12.922700+03:00
fb709a7047045970a1132f9e09ba72808522e1efad3bd1a1af34af0d1ca45f91
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-502'], 'cveID': 'CVE-2026-20131', 'notes': 'https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-rce-NKhnULJh ; https://nvd.nist.gov/vuln/detail/CVE-2026-20131', 'dueDate': '2026-03-22', 'product': 'Secure Firewall Management Center (FMC)', 'dateAdded': '2026-03-19', 'vendorProject': 'Cisco', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain a deserialization of untrusted data vulnerability in the web-based management interface that could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device.', 'vulnerabilityName': 'Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability', 'knownRansomwareCampaignUse': 'Known'}
CVE-2025-66376
Synacor
Zimbra Collaboration Suite (ZCS)
Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability
2026-03-18
Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability in the Classic UI where attackers could abuse Cascading Style Sheets (CSS) @import directives in email HTML.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-04-01
Unknown
https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories ; https://nvd.nist.gov/vuln/detail/CVE-2025-66376
['CWE-79']
2026.05.28
2026-05-28 19:27:12.922700+03:00
bf325321b0adb5b6199043b50f219d1a4e39f4c6e6506dfda2e278525e7ee608
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-79'], 'cveID': 'CVE-2025-66376', 'notes': 'https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories ; https://nvd.nist.gov/vuln/detail/CVE-2025-66376', 'dueDate': '2026-04-01', 'product': 'Zimbra Collaboration Suite (ZCS)', 'dateAdded': '2026-03-18', 'vendorProject': 'Synacor', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability in the Classic UI where attackers could abuse Cascading Style Sheets (CSS) @import directives in email HTML.', 'vulnerabilityName': 'Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2026-20963
Microsoft
SharePoint
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
2026-03-18
Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-03-21
Unknown
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20963 ; https://nvd.nist.gov/vuln/detail/CVE-2026-20963
['CWE-502']
2026.05.28
2026-05-28 19:27:12.922700+03:00
fa53723abe351e6bed5d4e1606f6768ba063c9c4ccb085839a32768bf9f4747b
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-502'], 'cveID': 'CVE-2026-20963', 'notes': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20963 ; https://nvd.nist.gov/vuln/detail/CVE-2026-20963', 'dueDate': '2026-03-21', 'product': 'SharePoint', 'dateAdded': '2026-03-18', 'vendorProject': 'Microsoft', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.', 'vulnerabilityName': 'Microsoft SharePoint Deserialization of Untrusted Data Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2008-0015
Microsoft
Windows
Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability
2026-02-17
Microsoft Windows Video ActiveX Control contains a remote code execution vulnerability. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-03-10
Unknown
https://web.archive.org/web/20110305211119/https://www.microsoft.com/technet/security/bulletin/ms09-032.mspx ; https://nvd.nist.gov/vuln/detail/CVE-2008-0015
[]
2026.05.28
2026-05-28 19:27:12.922700+03:00
ee9c8aa8321964afee61525a9c516f830cdc5c038afd0882c24897267900dfc1
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': [], 'cveID': 'CVE-2008-0015', 'notes': 'https://web.archive.org/web/20110305211119/https://www.microsoft.com/technet/security/bulletin/ms09-032.mspx ; https://nvd.nist.gov/vuln/detail/CVE-2008-0015', 'dueDate': '2026-03-10', 'product': 'Windows', 'dateAdded': '2026-02-17', 'vendorProject': 'Microsoft', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Microsoft Windows Video ActiveX Control contains a remote code execution vulnerability. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user.', 'vulnerabilityName': ' Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2025-47813
Wing FTP Server
Wing FTP Server
Wing FTP Server Information Disclosure Vulnerability
2026-03-16
Wing FTP Server contains a generation of error message containing sensitive information vulnerability when using a long value in the UID cookie.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-03-30
Unknown
https://www.wftpserver.com/serverhistory.htm ; https://nvd.nist.gov/vuln/detail/CVE-2025-47813
['CWE-209']
2026.05.28
2026-05-28 19:27:12.922700+03:00
82a5cd3966daef688f5d981f5f8a4b3bca14ac16a9bf955d3058df1c29479a34
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-209'], 'cveID': 'CVE-2025-47813', 'notes': 'https://www.wftpserver.com/serverhistory.htm ; https://nvd.nist.gov/vuln/detail/CVE-2025-47813', 'dueDate': '2026-03-30', 'product': 'Wing FTP Server', 'dateAdded': '2026-03-16', 'vendorProject': 'Wing FTP Server', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Wing FTP Server contains a generation of error message containing sensitive information vulnerability when using a long value in the UID cookie.', 'vulnerabilityName': 'Wing FTP Server Information Disclosure Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2026-3910
Google
Chromium V8
Google Chromium V8 Improper Restriction of Operations Within the Bounds of a Memory Buffer Vulnerability
2026-03-13
Google Chromium V8 contains an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-03-27
Unknown
https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_12.html ; https://nvd.nist.gov/vuln/detail/CVE-2026-3910
['CWE-119']
2026.05.28
2026-05-28 19:27:12.922700+03:00
d944148aceaf014b6b4cc69ca2457438187fc0dc954df5c4d378fb1344337b58
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-119'], 'cveID': 'CVE-2026-3910', 'notes': 'https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_12.html ; https://nvd.nist.gov/vuln/detail/CVE-2026-3910', 'dueDate': '2026-03-27', 'product': 'Chromium V8', 'dateAdded': '2026-03-13', 'vendorProject': 'Google', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Google Chromium V8 contains an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.', 'vulnerabilityName': 'Google Chromium V8 Improper Restriction of Operations Within the Bounds of a Memory Buffer Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2026-3909
Google
Skia
Google Skia Out-of-Bounds Write Vulnerability
2026-03-13
Google Skia contains an out-of-bounds write vulnerability that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability affects Google Chrome and ChromeOS, Android, Flutter, and possibly other products.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-03-27
Unknown
This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_13.html ; https://nvd.nist.gov/vuln/detail/CVE-2026-3909
['CWE-787']
2026.05.28
2026-05-28 19:27:12.922700+03:00
8f2f6a9a2c22cfc98faf3f9cb5ff210fe56c8d51a62a75e4e57c31bba93645d7
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-787'], 'cveID': 'CVE-2026-3909', 'notes': 'This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_13.html ; https://nvd.nist.gov/vuln/detail/CVE-2026-3909', 'dueDate': '2026-03-27', 'product': 'Skia', 'dateAdded': '2026-03-13', 'vendorProject': 'Google', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Google Skia contains an out-of-bounds write vulnerability that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability affects Google Chrome and ChromeOS, Android, Flutter, and possibly other products.', 'vulnerabilityName': 'Google Skia Out-of-Bounds Write Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2025-68613
n8n
n8n
n8n Improper Control of Dynamically-Managed Code Resources Vulnerability
2026-03-11
n8n contains an improper control of dynamically managed code resources vulnerability in its workflow expression evaluation system that allows for remote code execution.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-03-25
Unknown
https://github.com/n8n-io/n8n/security/advisories/GHSA-v98v-ff95-f3cp ; https://nvd.nist.gov/vuln/detail/CVE-2025-68613
['CWE-913']
2026.05.28
2026-05-28 19:27:12.922700+03:00
469076f6b8b1f1beb53971f2e168e4a1b10e7a67d4007869ba651b4be2ef5c82
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-913'], 'cveID': 'CVE-2025-68613', 'notes': 'https://github.com/n8n-io/n8n/security/advisories/GHSA-v98v-ff95-f3cp ; https://nvd.nist.gov/vuln/detail/CVE-2025-68613', 'dueDate': '2026-03-25', 'product': 'n8n', 'dateAdded': '2026-03-11', 'vendorProject': 'n8n', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'n8n contains an improper control of dynamically managed code resources vulnerability in its workflow expression evaluation system that allows for remote code execution.', 'vulnerabilityName': 'n8n Improper Control of Dynamically-Managed Code Resources Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2021-22054
Omnissa
Workspace One UEM
Omnissa Workspace ONE Server-Side Request Forgery
2026-03-09
Omnissa Workspace One UEM formerly known as VMware Workspace One UEM contains a server-side request forgery (SSRF) vulnerability that could allow a malicious actor with network access to UEM to send their requests without authentication and to gain access to sensitive information.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-03-23
Unknown
https://web.archive.org/web/20211222154335/https://www.vmware.com/security/advisories/VMSA-2021-0029.html ; https://nvd.nist.gov/vuln/detail/CVE-2021-22054
['CWE-918']
2026.05.28
2026-05-28 19:27:12.922700+03:00
59c60f67c40fb96249c5ae6864c725ad7da667beb903258065121706d0b57442
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-918'], 'cveID': 'CVE-2021-22054', 'notes': 'https://web.archive.org/web/20211222154335/https://www.vmware.com/security/advisories/VMSA-2021-0029.html ; https://nvd.nist.gov/vuln/detail/CVE-2021-22054', 'dueDate': '2026-03-23', 'product': 'Workspace One UEM', 'dateAdded': '2026-03-09', 'vendorProject': 'Omnissa', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Omnissa Workspace One UEM formerly known as VMware Workspace One UEM contains a server-side request forgery (SSRF) vulnerability that could allow a malicious actor with network access to UEM to send their requests without authentication and to gain access to sensitive information.', 'vulnerabilityName': 'Omnissa Workspace ONE Server-Side Request Forgery', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2025-14733
WatchGuard
Firebox
WatchGuard Firebox Out of Bounds Write Vulnerability
2025-12-19
WatchGuard Fireware OS iked process contains an out of bounds write vulnerability in the OS iked process. This vulnerability may allow a remote unauthenticated attacker to execute arbitrary code and affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2025-12-26
Unknown
Check for signs of potential compromise on all internet accessible instances after applying mitigations. For more information please see: https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2025-00027 ; https://nvd.nist.gov/vuln/detail/CVE-2025-14733
['CWE-787']
2026.05.28
2026-05-28 19:27:12.922700+03:00
dd6cadb821a3f7b804acc72e2d7906ba3aa93a189a19c606fadaf921470750f0
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-787'], 'cveID': 'CVE-2025-14733', 'notes': 'Check for signs of potential compromise on all internet accessible instances after applying mitigations. For more information please see: https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2025-00027 ; https://nvd.nist.gov/vuln/detail/CVE-2025-14733', 'dueDate': '2025-12-26', 'product': 'Firebox', 'dateAdded': '2025-12-19', 'vendorProject': 'WatchGuard', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'WatchGuard Fireware OS iked process contains an out of bounds write vulnerability in the OS iked process. This vulnerability may allow a remote unauthenticated attacker to execute arbitrary code and affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer.', 'vulnerabilityName': 'WatchGuard Firebox Out of Bounds Write Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2025-26399
SolarWinds
Web Help Desk
SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability
2026-03-09
SolarWinds Web Help Desk contain a deserialization of untrusted data vulnerability in AjaxProxy that could allow an attacker to run commands on the host machine.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-03-12
Unknown
https://www.solarwinds.com/trust-center/security-advisories/cve-2025-26399 ; https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_12-8-7-hotfix-1_release_notes.htm ; https://nvd.nist.gov/vuln/detail/CVE-2025-26399
['CWE-502']
2026.05.28
2026-05-28 19:27:12.922700+03:00
0e8ea244c3d79961d63305c57ee5171a1efa5d320e8ac1feb1c3c4add13e7a5d
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-502'], 'cveID': 'CVE-2025-26399', 'notes': 'https://www.solarwinds.com/trust-center/security-advisories/cve-2025-26399 ; https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_12-8-7-hotfix-1_release_notes.htm ; https://nvd.nist.gov/vuln/detail/CVE-2025-26399', 'dueDate': '2026-03-12', 'product': 'Web Help Desk', 'dateAdded': '2026-03-09', 'vendorProject': 'SolarWinds', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'SolarWinds Web Help Desk contain a deserialization of untrusted data vulnerability in AjaxProxy that could allow an attacker to run commands on the host machine.', 'vulnerabilityName': 'SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2026-1603
Ivanti
Endpoint Manager (EPM)
Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability
2026-03-09
Ivanti Endpoint Manager (EPM) contains an authentication bypass using an alternate path or channel vulnerability that could allow a remote unauthenticated attacker to leak specific stored credential data.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-03-23
Unknown
https://hub.ivanti.com/s/article/Security-Advisory-EPM-February-2026-for-EPM-2024?language=en_US ; https://nvd.nist.gov/vuln/detail/CVE-2026-1603
['CWE-288']
2026.05.28
2026-05-28 19:27:12.922700+03:00
daf99a13371aa3294039335e8b3cf7d32c4576b5f989600da790ef6739244dd1
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-288'], 'cveID': 'CVE-2026-1603', 'notes': 'https://hub.ivanti.com/s/article/Security-Advisory-EPM-February-2026-for-EPM-2024?language=en_US ; https://nvd.nist.gov/vuln/detail/CVE-2026-1603', 'dueDate': '2026-03-23', 'product': ' Endpoint Manager (EPM)', 'dateAdded': '2026-03-09', 'vendorProject': 'Ivanti', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Ivanti Endpoint Manager (EPM) contains an authentication bypass using an alternate path or channel vulnerability that could allow a remote unauthenticated attacker to leak specific stored credential data.', 'vulnerabilityName': 'Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2017-7921
Hikvision
Multiple Products
Hikvision Multiple Products Improper Authentication Vulnerability
2026-03-05
Multiple Hikvision products contain an improper authentication vulnerability that could allow a malicious user to escalate privileges on the system and gain access to sensitive information.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-03-26
Unknown
https://www.hikvision.com/us-en/support/document-center/special-notices/privilege-escalating-vulnerability-in-certain-hikvision-ip-cameras/ ; https://nvd.nist.gov/vuln/detail/CVE-2017-7921
['CWE-287']
2026.05.28
2026-05-28 19:27:12.922700+03:00
dc20569560e5aca79dcf3c5d77eb42669f1153ed9a391b34f6024caa6389d770
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-287'], 'cveID': 'CVE-2017-7921', 'notes': 'https://www.hikvision.com/us-en/support/document-center/special-notices/privilege-escalating-vulnerability-in-certain-hikvision-ip-cameras/ ; https://nvd.nist.gov/vuln/detail/CVE-2017-7921', 'dueDate': '2026-03-26', 'product': 'Multiple Products', 'dateAdded': '2026-03-05', 'vendorProject': 'Hikvision', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Multiple Hikvision products contain an improper authentication vulnerability that could allow a malicious user to escalate privileges on the system and gain access to sensitive information.', 'vulnerabilityName': 'Hikvision Multiple Products Improper Authentication Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2021-22681
Rockwell
Multiple Products
Rockwell Multiple Products Insufficient Protected Credentials Vulnerability
2026-03-05
Multiple Rockwell products contain an insufficient protected credentials vulnerability. Studio 5000 Logix Designer software may allow a key to be discovered. This key is used to verify Logix controllers are communicating with Rockwell Automation design software. If successfully exploited, this vulnerability could allow an unauthorized application to connect with Logix controllers. To leverage this vulnerability, an unauthorized user would require network access to the controller.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-03-26
Unknown
https://support.rockwellautomation.com/app/answers/answer_view/a_id/1130301/~/cve-2021-22681%3A-authentication-bypass-vulnerability-found-in-logix-controllers- ; https://www.cisa.gov/news-events/ics-advisories/icsa-21-056-03 ; https://nvd.nist.gov/vuln/detail/CVE-2021-22681
['CWE-522']
2026.05.28
2026-05-28 19:27:12.922700+03:00
131855611e68b87fd4b455bb34e9ab8f851a0a8da30c8931138ffcad226e1e0d
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-522'], 'cveID': 'CVE-2021-22681', 'notes': 'https://support.rockwellautomation.com/app/answers/answer_view/a_id/1130301/~/cve-2021-22681%3A-authentication-bypass-vulnerability-found-in-logix-controllers- ; https://www.cisa.gov/news-events/ics-advisories/icsa-21-056-03 ; https://nvd.nist.gov/vuln/detail/CVE-2021-22681', 'dueDate': '2026-03-26', 'product': 'Multiple Products', 'dateAdded': '2026-03-05', 'vendorProject': 'Rockwell', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Multiple Rockwell products contain an insufficient protected credentials vulnerability. Studio 5000 Logix Designer software may allow a key to be discovered. This key is used to verify Logix controllers are communicating with Rockwell Automation design software. If successfully exploited, this vulnerability could allow an unauthorized application to connect with Logix controllers. To leverage this vulnerability, an unauthorized user would require network access to the controller.', 'vulnerabilityName': 'Rockwell Multiple Products Insufficient Protected Credentials Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2026-1731
BeyondTrust
Remote Support (RS) and Privileged Remote Access (PRA)
BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability
2026-02-13
BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)contain an OS command injection vulnerability. Successful exploitation could allow an unauthenticated remote attacker to execute operating system commands in the context of the site user. Successful exploitation requires no authentication or user interaction and may lead to system compromise, including unauthorized access, data exfiltration, and service disruption.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-02-16
Known
Please adhere to the vendor's guidelines to assess exposure and mitigate risks. Check for signs of potential compromise on all internet accessible BeyondTrust products affected by this vulnerability. For more information please: see: https://www.beyondtrust.com/trust-center/security-advisories/bt26-02 ; https://nvd.nist.gov/vuln/detail/CVE-2026-1731
['CWE-78']
2026.05.28
2026-05-28 19:27:12.922700+03:00
c04e54a2d999331029311d587d1cc2cfc5b95d1a120b9cc20fd8152238623720
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-78'], 'cveID': 'CVE-2026-1731', 'notes': "Please adhere to the vendor's guidelines to assess exposure and mitigate risks. Check for signs of potential compromise on all internet accessible BeyondTrust products affected by this vulnerability. For more information please: see: https://www.beyondtrust.com/trust-center/security-advisories/bt26-02 ; https://nvd.nist.gov/vuln/detail/CVE-2026-1731", 'dueDate': '2026-02-16', 'product': 'Remote Support (RS) and Privileged Remote Access (PRA)', 'dateAdded': '2026-02-13', 'vendorProject': 'BeyondTrust', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)contain an OS command injection vulnerability. Successful exploitation could allow an unauthenticated remote attacker to execute operating system commands in the context of the site user. Successful exploitation requires no authentication or user interaction and may lead to system compromise, including unauthorized access, data exfiltration, and service disruption.', 'vulnerabilityName': 'BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability', 'knownRansomwareCampaignUse': 'Known'}
CVE-2023-43000
Apple
Multiple Products
Apple Multiple products Use-After-Free Vulnerability
2026-03-05
Apple macOS, iOS, iPadOS, and Safari 16.6 contain a use-after-free vulnerability due to the processing of maliciously crafted web content that may lead to memory corruption.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-03-26
Unknown
https://support.apple.com/en-us/120324 ; https://support.apple.com/en-us/120331 ; https://support.apple.com/en-us/120338 ; https://nvd.nist.gov/vuln/detail/CVE-2023-43000
['CWE-416']
2026.05.28
2026-05-28 19:27:12.922700+03:00
a81fb58fe3023aeb9d625aee30236091efbcacda73358cb8418ad2b1fc1bfbfe
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-416'], 'cveID': 'CVE-2023-43000', 'notes': 'https://support.apple.com/en-us/120324 ; https://support.apple.com/en-us/120331 ; https://support.apple.com/en-us/120338 ; https://nvd.nist.gov/vuln/detail/CVE-2023-43000', 'dueDate': '2026-03-26', 'product': 'Multiple Products', 'dateAdded': '2026-03-05', 'vendorProject': 'Apple', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Apple macOS, iOS, iPadOS, and Safari 16.6 contain a use-after-free vulnerability due to the processing of maliciously crafted web content that may lead to memory corruption.', 'vulnerabilityName': 'Apple Multiple products Use-After-Free Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2021-30952
Apple
Multiple Products
Apple Multiple Products Integer Overflow or Wraparound Vulnerability
2026-03-05
Apple tvOS, macOS, Safari, iPadOS and watchOS contain an integer overflow or wraparound vulnerability due to the processing of maliciously crafted web content that may lead to arbitrary code execution.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-03-26
Unknown
https://support.apple.com/en-us/HT212975 ; https://support.apple.com/en-us/HT212976 ; https://support.apple.com/en-us/HT212978 ; https://support.apple.com/en-us/HT212980 ; https://support.apple.com/en-us/HT212982 ; https://nvd.nist.gov/vuln/detail/CVE-2021-30952
['CWE-190']
2026.05.28
2026-05-28 19:27:12.922700+03:00
0460f4d3f8a05dbf0f0c4a7c581f9c0abf7b4f2e606a3ddbc968a12e6c167834
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-190'], 'cveID': 'CVE-2021-30952', 'notes': 'https://support.apple.com/en-us/HT212975 ; https://support.apple.com/en-us/HT212976 ; https://support.apple.com/en-us/HT212978 ; https://support.apple.com/en-us/HT212980 ; https://support.apple.com/en-us/HT212982 ; https://nvd.nist.gov/vuln/detail/CVE-2021-30952', 'dueDate': '2026-03-26', 'product': 'Multiple Products', 'dateAdded': '2026-03-05', 'vendorProject': 'Apple', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Apple tvOS, macOS, Safari, iPadOS and watchOS contain an integer overflow or wraparound vulnerability due to the processing of maliciously crafted web content that may lead to arbitrary code execution.', 'vulnerabilityName': 'Apple Multiple Products Integer Overflow or Wraparound Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2023-41974
Apple
iOS and iPadOS
Apple iOS and iPadOS Use-After-Free Vulnerability
2026-03-05
Apple iOS and iPadOS contain a use-after-free vulnerability. An app may be able to execute arbitrary code with kernel privileges.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-03-26
Unknown
https://support.apple.com/en-us/HT213938 ; https://support.apple.com/kb/HT213938 ; https://nvd.nist.gov/vuln/detail/CVE-2023-41974
['CWE-416']
2026.05.28
2026-05-28 19:27:12.922700+03:00
2675bf67dd1a185b4b20c0360a437e7f42e7761f36ff024012727fac6657bb0c
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-416'], 'cveID': 'CVE-2023-41974', 'notes': 'https://support.apple.com/en-us/HT213938 ; https://support.apple.com/kb/HT213938 ; https://nvd.nist.gov/vuln/detail/CVE-2023-41974', 'dueDate': '2026-03-26', 'product': 'iOS and iPadOS', 'dateAdded': '2026-03-05', 'vendorProject': 'Apple', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Apple iOS and iPadOS contain a use-after-free vulnerability. An app may be able to execute arbitrary code with kernel privileges.', 'vulnerabilityName': 'Apple iOS and iPadOS Use-After-Free Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2026-22719
Broadcom
VMware Aria Operations
Broadcom VMware Aria Operations Command Injection Vulnerability
2026-03-03
Broadcom VMware Aria Operations formerly known as vRealize Operations (vROps) contains a command injection vulnerability that allows an unauthenticated attacker to execute arbitrary commands, potentially leading to remote code execution during support‑assisted product migration.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-03-24
Unknown
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ; https://knowledge.broadcom.com/external/article/430349 ; https://nvd.nist.gov/vuln/detail/CVE-2026-22719
['CWE-77']
2026.05.28
2026-05-28 19:27:12.922700+03:00
90ebb397cc53cf6fa60769462376c34707b3c5ef35a2e1b2f8c0e77eaf543840
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-77'], 'cveID': 'CVE-2026-22719', 'notes': 'https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ; https://knowledge.broadcom.com/external/article/430349 ; https://nvd.nist.gov/vuln/detail/CVE-2026-22719', 'dueDate': '2026-03-24', 'product': 'VMware Aria Operations', 'dateAdded': '2026-03-03', 'vendorProject': 'Broadcom', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Broadcom VMware Aria Operations formerly known as vRealize Operations (vROps) contains a command injection vulnerability that allows an unauthenticated attacker to execute arbitrary commands, potentially leading to remote code execution during support‑assisted product migration.', 'vulnerabilityName': 'Broadcom VMware Aria Operations Command Injection Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2024-54085
AMI
MegaRAC SPx
AMI MegaRAC SPx Authentication Bypass by Spoofing Vulnerability
2025-06-25
AMI MegaRAC SPx contains an authentication bypass by spoofing vulnerability in the Redfish Host Interface. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2025-07-16
Unknown
This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://go.ami.com/hubfs/Security%20Advisories/2025/AMI-SA-2025003.pdf ; https://security.netapp.com/advisory/ntap-20250328-0003/ ; https://nvd.nist.gov/vuln/detail/CVE-2024-54085
['CWE-290']
2026.05.28
2026-05-28 19:27:12.922700+03:00
83a6a05e226dccd7923cb46730eea0032dd9f0bb1d84e04d173452f26ebdf2e8
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-290'], 'cveID': 'CVE-2024-54085', 'notes': 'This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://go.ami.com/hubfs/Security%20Advisories/2025/AMI-SA-2025003.pdf ; https://security.netapp.com/advisory/ntap-20250328-0003/ ; https://nvd.nist.gov/vuln/detail/CVE-2024-54085', 'dueDate': '2025-07-16', 'product': 'MegaRAC SPx', 'dateAdded': '2025-06-25', 'vendorProject': 'AMI', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'AMI MegaRAC SPx contains an authentication bypass by spoofing vulnerability in the Redfish Host Interface. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.', 'vulnerabilityName': 'AMI MegaRAC SPx Authentication Bypass by Spoofing Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2026-21385
Qualcomm
Multiple Chipsets
Qualcomm Multiple Chipsets Memory Corruption Vulnerability
2026-03-03
Multiple Qualcomm chipsets contain a memory corruption vulnerability while using alignments for memory allocation.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-03-24
Unknown
Please check with specific vendors (OEMs,) for information on patching status. For more information, please see: https://source.android.com/docs/security/bulletin/2026/2026-03-01 ; https://nvd.nist.gov/vuln/detail/CVE-2026-21385
['CWE-190']
2026.05.28
2026-05-28 19:27:12.922700+03:00
31d9b32447d9faa0902991fc141b4f3208a346de2d92d32532a2665391a46f43
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-190'], 'cveID': 'CVE-2026-21385', 'notes': 'Please check with specific vendors (OEMs,) for information on patching status. For more information, please see: https://source.android.com/docs/security/bulletin/2026/2026-03-01 ; https://nvd.nist.gov/vuln/detail/CVE-2026-21385', 'dueDate': '2026-03-24', 'product': 'Multiple Chipsets', 'dateAdded': '2026-03-03', 'vendorProject': 'Qualcomm', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Multiple Qualcomm chipsets contain a memory corruption vulnerability while using alignments for memory allocation. ', 'vulnerabilityName': 'Qualcomm Multiple Chipsets Memory Corruption Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2022-20775
Cisco
SD-WAN
Cisco SD-WAN Path Traversal Vulnerability
2026-02-25
Cisco SD-WAN CLI contains a path traversal vulnerability that could allow an authenticated local attacker to gain elevated privileges via improper access controls on commands within the application CLI. A successful exploit could allow the attacker to execute arbitrary commands as the root user.
Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.
2026-02-27
Unknown
CISA Mitigation Instructions: https://www.cisa.gov/news-events/directives/ed-26-03-mitigate-vulnerabilities-cisco-sd-wan-systems ; https://www.cisa.gov/news-events/directives/supplemental-direction-ed-26-03-hunt-and-hardening-guidance-cisco-sd-wan-systems ; https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-sd-wan-priv-E6e8tEdF.html ; https://nvd.nist.gov/vuln/detail/CVE-2022-20775
['CWE-25', 'CWE-282']
2026.05.28
2026-05-28 19:27:12.922700+03:00
e5eb6063c4ebc51b9cd044cde25cf46d1f3e18516422e8920e4cc586ef019fb6
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-25', 'CWE-282'], 'cveID': 'CVE-2022-20775', 'notes': 'CISA Mitigation Instructions: https://www.cisa.gov/news-events/directives/ed-26-03-mitigate-vulnerabilities-cisco-sd-wan-systems ; https://www.cisa.gov/news-events/directives/supplemental-direction-ed-26-03-hunt-and-hardening-guidance-cisco-sd-wan-systems ; https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-sd-wan-priv-E6e8tEdF.html ; https://nvd.nist.gov/vuln/detail/CVE-2022-20775', 'dueDate': '2026-02-27', 'product': 'SD-WAN', 'dateAdded': '2026-02-25', 'vendorProject': 'Cisco', 'requiredAction': 'Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.', 'shortDescription': 'Cisco SD-WAN CLI contains a path traversal vulnerability that could allow an authenticated local attacker to gain elevated privileges via improper access controls on commands within the application CLI. A successful exploit could allow the attacker to execute arbitrary commands as the root user.', 'vulnerabilityName': 'Cisco SD-WAN Path Traversal Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2026-20127
Cisco
Catalyst SD-WAN Controller and Manager
Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability
2026-02-25
Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, contain an authentication bypass vulnerability could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to an affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric.
Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.
2026-02-27
Unknown
CISA Mitigation Instructions: https://www.cisa.gov/news-events/directives/ed-26-03-mitigate-vulnerabilities-cisco-sd-wan-systems ; https://www.cisa.gov/news-events/directives/supplemental-direction-ed-26-03-hunt-and-hardening-guidance-cisco-sd-wan-systems ; https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa-EHchtZk ; https://nvd.nist.gov/vuln/detail/CVE-2026-20127
['CWE-287']
2026.05.28
2026-05-28 19:27:12.922700+03:00
6b04295ab634af84293e8b3ee509f04629cf75ac1124e718f470683a2b816841
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-287'], 'cveID': 'CVE-2026-20127', 'notes': 'CISA Mitigation Instructions: https://www.cisa.gov/news-events/directives/ed-26-03-mitigate-vulnerabilities-cisco-sd-wan-systems ; https://www.cisa.gov/news-events/directives/supplemental-direction-ed-26-03-hunt-and-hardening-guidance-cisco-sd-wan-systems ; https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa-EHchtZk ; https://nvd.nist.gov/vuln/detail/CVE-2026-20127', 'dueDate': '2026-02-27', 'product': 'Catalyst SD-WAN Controller and Manager', 'dateAdded': '2026-02-25', 'vendorProject': 'Cisco', 'requiredAction': 'Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.', 'shortDescription': 'Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, contain an authentication bypass vulnerability could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to an affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric.', 'vulnerabilityName': 'Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2026-25108
Soliton Systems K.K
FileZen
Soliton Systems K.K FileZen OS Command Injection Vulnerability
2026-02-24
Soliton Systems K.K FileZen contains an OS command injection vulnerability when an user logs-in to the affected product and sends a specially crafted HTTP request.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-03-17
Unknown
https://jvn.jp/en/jp/JVN84622767/ ; https://nvd.nist.gov/vuln/detail/CVE-2026-25108
['CWE-78']
2026.05.28
2026-05-28 19:27:12.922700+03:00
ccc015e9c269fa6becbf0ad4abb28c4c23d6702b7f17377793c0af0d7c7ba573
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-78'], 'cveID': 'CVE-2026-25108', 'notes': 'https://jvn.jp/en/jp/JVN84622767/ ; https://nvd.nist.gov/vuln/detail/CVE-2026-25108', 'dueDate': '2026-03-17', 'product': 'FileZen', 'dateAdded': '2026-02-24', 'vendorProject': 'Soliton Systems K.K', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Soliton Systems K.K FileZen contains an OS command injection vulnerability when an user logs-in to the affected product and sends a specially crafted HTTP request.', 'vulnerabilityName': 'Soliton Systems K.K FileZen OS Command Injection Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2026-2441
Google
Chromium
Google Chromium CSS Use-After-Free Vulnerability
2026-02-17
Google Chromium CSS contains a use-after-free vulnerability that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-03-10
Unknown
https://chromereleases.googleblog.com/2026/02/stable-channel-update-for-desktop_13.html ; https://nvd.nist.gov/vuln/detail/CVE-2026-2441
['CWE-416']
2026.05.28
2026-05-28 19:27:12.922700+03:00
df8e657aee3265219d8b1d1a3cbd9556d931fc73ba0351eded1ef6e9f9f71f4b
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-416'], 'cveID': 'CVE-2026-2441', 'notes': 'https://chromereleases.googleblog.com/2026/02/stable-channel-update-for-desktop_13.html ; https://nvd.nist.gov/vuln/detail/CVE-2026-2441', 'dueDate': '2026-03-10', 'product': 'Chromium', 'dateAdded': '2026-02-17', 'vendorProject': 'Google', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Google Chromium CSS contains a use-after-free vulnerability that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.', 'vulnerabilityName': 'Google Chromium CSS Use-After-Free Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2025-49113
Roundcube
Webmail
RoundCube Webmail Deserialization of Untrusted Data Vulnerability
2026-02-20
RoundCube Webmail contains a deserialization of untrusted data vulnerability that allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-03-13
Unknown
https://roundcube.net/news/2025/06/01/security-updates-1.6.11-and-1.5.10 ; https://github.com/roundcube/roundcubemail/releases/tag/1.5.10 ; https://github.com/roundcube/roundcubemail/releases/tag/1.6.11 ; https://nvd.nist.gov/vuln/detail/CVE-2025-49113
['CWE-502']
2026.05.28
2026-05-28 19:27:12.922700+03:00
cae4fadf2c3ae924e8b8ccd895195e9c31bdd12bc5936a94aba0d9ad17b0ab22
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-502'], 'cveID': 'CVE-2025-49113', 'notes': 'https://roundcube.net/news/2025/06/01/security-updates-1.6.11-and-1.5.10 ; https://github.com/roundcube/roundcubemail/releases/tag/1.5.10 ; https://github.com/roundcube/roundcubemail/releases/tag/1.6.11 ; https://nvd.nist.gov/vuln/detail/CVE-2025-49113', 'dueDate': '2026-03-13', 'product': 'Webmail', 'dateAdded': '2026-02-20', 'vendorProject': 'Roundcube', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'RoundCube Webmail contains a deserialization of untrusted data vulnerability that allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php.', 'vulnerabilityName': 'RoundCube Webmail Deserialization of Untrusted Data Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2025-68461
Roundcube
Webmail
RoundCube Webmail Cross-site Scripting Vulnerability
2026-02-20
RoundCube Webmail contains a cross-site scripting vulnerability via the animate tag in an SVG document.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-03-13
Unknown
https://roundcube.net/news/2025/12/13/security-updates-1.6.12-and-1.5.12 ; https://github.com/roundcube/roundcubemail/commit/bfa032631c36b900e7444dfa278340b33cbf7cdb ; https://nvd.nist.gov/vuln/detail/CVE-2025-68461
['CWE-79']
2026.05.28
2026-05-28 19:27:12.922700+03:00
8dafec63cc7a0e1f3fc5815a7d6bdf5f544734bc2990acb440559e4b0dc97325
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-79'], 'cveID': 'CVE-2025-68461', 'notes': 'https://roundcube.net/news/2025/12/13/security-updates-1.6.12-and-1.5.12 ; https://github.com/roundcube/roundcubemail/commit/bfa032631c36b900e7444dfa278340b33cbf7cdb ; https://nvd.nist.gov/vuln/detail/CVE-2025-68461', 'dueDate': '2026-03-13', 'product': 'Webmail', 'dateAdded': '2026-02-20', 'vendorProject': 'Roundcube', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'RoundCube Webmail contains a cross-site scripting vulnerability via the animate tag in an SVG document.', 'vulnerabilityName': 'RoundCube Webmail Cross-site Scripting Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2021-22175
GitLab
GitLab
GitLab Server-Side Request Forgery (SSRF) Vulnerability
2026-02-18
GitLab contains a server-side request forgery (SSRF) vulnerability when requests to the internal network for webhooks are enabled.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-03-11
Unknown
https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22175.json ; https://nvd.nist.gov/vuln/detail/CVE-2021-22175
['CWE-918']
2026.05.28
2026-05-28 19:27:12.922700+03:00
528e60b765cb0f7a7fee7f24bf8defd1e8b5aa8737ec815be8b3b04e312ec5f1
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-918'], 'cveID': 'CVE-2021-22175', 'notes': 'https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22175.json ; https://nvd.nist.gov/vuln/detail/CVE-2021-22175', 'dueDate': '2026-03-11', 'product': 'GitLab', 'dateAdded': '2026-02-18', 'vendorProject': 'GitLab', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'GitLab contains a server-side request forgery (SSRF) vulnerability when requests to the internal network for webhooks are enabled.', 'vulnerabilityName': 'GitLab Server-Side Request Forgery (SSRF) Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2026-22769
Dell
RecoverPoint for Virtual Machines (RP4VMs)
Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability
2026-02-18
Dell RecoverPoint for Virtual Machines (RP4VMs) contains an use of hard-coded credentials vulnerability that could allow an unauthenticated remote attacker to gain unauthorized access to the underlying operating system and root-level persistence.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-02-21
Unknown
https://www.dell.com/support/kbdoc/en-us/000426773/dsa-2026-079 ; https://www.dell.com/support/kbdoc/en-us/000426742/recoverpoint-for-vms-apply-the-remediation-script-for-dsa ; https://cloud.google.com/blog/topics/threat-intelligence/unc6201-exploiting-dell-recoverpoint-zero-day ; https://nvd.nist.gov/vuln/detail/CVE-2026-22769
['CWE-798']
2026.05.28
2026-05-28 19:27:12.922700+03:00
3ff5e56e98cda5cc077055290a640bcdb58e2a5f36142b1deb3f0ca0aad7824f
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-798'], 'cveID': 'CVE-2026-22769', 'notes': 'https://www.dell.com/support/kbdoc/en-us/000426773/dsa-2026-079 ; https://www.dell.com/support/kbdoc/en-us/000426742/recoverpoint-for-vms-apply-the-remediation-script-for-dsa ; https://cloud.google.com/blog/topics/threat-intelligence/unc6201-exploiting-dell-recoverpoint-zero-day ; https://nvd.nist.gov/vuln/detail/CVE-2026-22769', 'dueDate': '2026-02-21', 'product': 'RecoverPoint for Virtual Machines (RP4VMs)', 'dateAdded': '2026-02-18', 'vendorProject': 'Dell', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Dell RecoverPoint for Virtual Machines (RP4VMs) contains an use of hard-coded credentials vulnerability that could allow an unauthenticated remote attacker to gain unauthorized access to the underlying operating system and root-level persistence.', 'vulnerabilityName': 'Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2020-7796
Synacor
Zimbra Collaboration Suite
Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability
2026-02-17
Synacor Zimbra Collaboration Suite (ZCS) contains a server-side request forgery vulnerability if WebEx zimlet installed and zimlet JSP is enabled.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-03-10
Unknown
https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.15/P7 ; https://nvd.nist.gov/vuln/detail/CVE-2020-7796
['CWE-918']
2026.05.28
2026-05-28 19:27:12.922700+03:00
1f3b6b6dc6bb1af40b74ae3d98ae1b04f00a41abb23e30ab6ce200197d6b5612
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-918'], 'cveID': 'CVE-2020-7796', 'notes': 'https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.15/P7 ; https://nvd.nist.gov/vuln/detail/CVE-2020-7796', 'dueDate': '2026-03-10', 'product': 'Zimbra Collaboration Suite', 'dateAdded': '2026-02-17', 'vendorProject': 'Synacor', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Synacor Zimbra Collaboration Suite (ZCS) contains a server-side request forgery vulnerability if WebEx zimlet installed and zimlet JSP is enabled.', 'vulnerabilityName': 'Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2026-20700
Apple
Multiple Products
Apple Multiple Buffer Overflow Vulnerability
2026-02-12
Apple iOS, macOS, tvOS, watchOS, and visionOS contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow an attacker with memory write the capability to execute arbitrary code.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-03-05
Unknown
https://support.apple.com/en-us/126346 ; https://support.apple.com/en-us/126348 ; https://support.apple.com/en-us/126351 ; https://support.apple.com/en-us/126352 ; https://support.apple.com/en-us/126353 ; https://nvd.nist.gov/vuln/detail/CVE-2026-20700
['CWE-119']
2026.05.28
2026-05-28 19:27:12.922700+03:00
2c90558661054ecaed6d7c04c169c27780781f7943ead10a30856f718e29fb4b
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-119'], 'cveID': 'CVE-2026-20700', 'notes': 'https://support.apple.com/en-us/126346 ; https://support.apple.com/en-us/126348 ; https://support.apple.com/en-us/126351 ; https://support.apple.com/en-us/126352 ; https://support.apple.com/en-us/126353 ; https://nvd.nist.gov/vuln/detail/CVE-2026-20700', 'dueDate': '2026-03-05', 'product': 'Multiple Products', 'dateAdded': '2026-02-12', 'vendorProject': 'Apple', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Apple iOS, macOS, tvOS, watchOS, and visionOS contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow an attacker with memory write the capability to execute arbitrary code.', 'vulnerabilityName': 'Apple Multiple Buffer Overflow Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2024-43468
Microsoft
Configuration Manager
Microsoft Configuration Manager SQL Injection Vulnerability
2026-02-12
Microsoft Configuration Manager contains an SQL injection vulnerability. An unauthenticated attacker could exploit this vulnerability by sending specially crafted requests to the target environment which are processed in an unsafe manner enabling the attacker to execute commands on the server and/or underlying database.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-03-05
Unknown
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43468 ; https://nvd.nist.gov/vuln/detail/CVE-2024-43468
['CWE-89']
2026.05.28
2026-05-28 19:27:12.922700+03:00
515b60a8529710902cde2652fa803216e35388bfec4af1d3b06a9437ee5cb51c
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-89'], 'cveID': 'CVE-2024-43468', 'notes': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43468 ; https://nvd.nist.gov/vuln/detail/CVE-2024-43468', 'dueDate': '2026-03-05', 'product': 'Configuration Manager', 'dateAdded': '2026-02-12', 'vendorProject': 'Microsoft', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Microsoft Configuration Manager contains an SQL injection vulnerability. An unauthenticated attacker could exploit this vulnerability by sending specially crafted requests to the target environment which are processed in an unsafe manner enabling the attacker to execute commands on the server and/or underlying database.', 'vulnerabilityName': 'Microsoft Configuration Manager SQL Injection Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2025-15556
Notepad++
Notepad++
Notepad++ Download of Code Without Integrity Check Vulnerability
2026-02-12
Notepad++ when using the WinGUp updater, contains a download of code without integrity check vulnerability that could allow an attacker to intercept or redirect update traffic to download and execute an attacker-controlled installer. This could lead to arbitrary code execution with the privileges of the user.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-03-05
Unknown
https://notepad-plus-plus.org/news/clarification-security-incident/ ; https://community.notepad-plus-plus.org/topic/27298/notepad-v8-8-9-vulnerability-fix ; https://nvd.nist.gov/vuln/detail/CVE-2025-15556
['CWE-494']
2026.05.28
2026-05-28 19:27:12.922700+03:00
bc5f8c8b96bf403c3ac29a436fdb53682b540e1ee48eddf9e3774c26551d4302
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-494'], 'cveID': 'CVE-2025-15556', 'notes': 'https://notepad-plus-plus.org/news/clarification-security-incident/ ; https://community.notepad-plus-plus.org/topic/27298/notepad-v8-8-9-vulnerability-fix ; https://nvd.nist.gov/vuln/detail/CVE-2025-15556', 'dueDate': '2026-03-05', 'product': 'Notepad++', 'dateAdded': '2026-02-12', 'vendorProject': 'Notepad++', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Notepad++ when using the WinGUp updater, contains a download of code without integrity check vulnerability that could allow an attacker to intercept or redirect update traffic to download and execute an attacker-controlled installer. This could lead to arbitrary code execution with the privileges of the user.', 'vulnerabilityName': 'Notepad++ Download of Code Without Integrity Check Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2025-40536
SolarWinds
Web Help Desk
SolarWinds Web Help Desk Security Control Bypass Vulnerability
2026-02-12
SolarWinds Web Help Desk contains a security control bypass vulnerability that could allow an unauthenticated attacker to gain access to certain restricted functionality.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-02-15
Unknown
https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_2026-1_release_notes.htm ; https://www.solarwinds.com/trust-center/security-advisories/CVE-2025-40536 ; https://nvd.nist.gov/vuln/detail/CVE-2025-40536
['CWE-693']
2026.05.28
2026-05-28 19:27:12.922700+03:00
d5e009cf5c041b0426997a0f44947b7ea0574f4f7ab7300561badbdd9a408a60
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-693'], 'cveID': 'CVE-2025-40536', 'notes': 'https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_2026-1_release_notes.htm ; https://www.solarwinds.com/trust-center/security-advisories/CVE-2025-40536 ; https://nvd.nist.gov/vuln/detail/CVE-2025-40536', 'dueDate': '2026-02-15', 'product': 'Web Help Desk', 'dateAdded': '2026-02-12', 'vendorProject': 'SolarWinds', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'SolarWinds Web Help Desk contains a security control bypass vulnerability that could allow an unauthenticated attacker to gain access to certain restricted functionality.', 'vulnerabilityName': 'SolarWinds Web Help Desk Security Control Bypass Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2026-21513
Microsoft
Windows
Microsoft MSHTML Framework Protection Mechanism Failure Vulnerability
2026-02-10
Microsoft MSHTML Framework contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-03-03
Unknown
https://msrc.microsoft.com/update-guide/advisory/CVE-2026-21513 ; https://nvd.nist.gov/vuln/detail/CVE-2026-21513
['CWE-693']
2026.05.28
2026-05-28 19:27:12.922700+03:00
9eb1c93e5796ed00b7bd2051810cc226633e1c3ef8163c5a874abd0baf768475
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-693'], 'cveID': 'CVE-2026-21513', 'notes': 'https://msrc.microsoft.com/update-guide/advisory/CVE-2026-21513 ; https://nvd.nist.gov/vuln/detail/CVE-2026-21513', 'dueDate': '2026-03-03', 'product': 'Windows', 'dateAdded': '2026-02-10', 'vendorProject': 'Microsoft', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Microsoft MSHTML Framework contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network.', 'vulnerabilityName': 'Microsoft MSHTML Framework Protection Mechanism Failure Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2026-21525
Microsoft
Windows
Microsoft Windows NULL Pointer Dereference Vulnerability
2026-02-10
Microsoft Windows Remote Access Connection Manager contains a NULL pointer dereference that could allow an unauthorized attacker to deny service locally.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-03-03
Unknown
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21525 ; https://nvd.nist.gov/vuln/detail/CVE-2026-21525
['CWE-476']
2026.05.28
2026-05-28 19:27:12.922700+03:00
6325f21d35840b964cb0deacb1dbb39f63de385a9abfffd2d7d537889a91d4d1
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-476'], 'cveID': 'CVE-2026-21525', 'notes': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21525 ; https://nvd.nist.gov/vuln/detail/CVE-2026-21525', 'dueDate': '2026-03-03', 'product': 'Windows', 'dateAdded': '2026-02-10', 'vendorProject': 'Microsoft', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Microsoft Windows Remote Access Connection Manager contains a NULL pointer dereference that could allow an unauthorized attacker to deny service locally.', 'vulnerabilityName': 'Microsoft Windows NULL Pointer Dereference Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2026-21510
Microsoft
Windows
Microsoft Windows Shell Protection Mechanism Failure Vulnerability
2026-02-10
Microsoft Windows Shell contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-03-03
Unknown
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21510 ; https://nvd.nist.gov/vuln/detail/CVE-2026-21510
['CWE-693']
2026.05.28
2026-05-28 19:27:12.922700+03:00
1021181ab6f94927a834700b893b9f287a41881af2242e5624a8125be6794fcb
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-693'], 'cveID': 'CVE-2026-21510', 'notes': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21510 ; https://nvd.nist.gov/vuln/detail/CVE-2026-21510 ', 'dueDate': '2026-03-03', 'product': 'Windows', 'dateAdded': '2026-02-10', 'vendorProject': 'Microsoft', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Microsoft Windows Shell contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network. ', 'vulnerabilityName': 'Microsoft Windows Shell Protection Mechanism Failure Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2026-21533
Microsoft
Windows
Microsoft Windows Improper Privilege Management Vulnerability
2026-02-10
Microsoft Windows Remote Desktop Services contains an improper privilege management vulnerability that could allow an authorized attacker to elevate privileges locally.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-03-03
Unknown
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21533 ; https://nvd.nist.gov/vuln/detail/CVE-2026-21533
['CWE-269']
2026.05.28
2026-05-28 19:27:12.922700+03:00
a9ebcaf6067d1aa03bec46e5c9ae0fec6421c9ef87e710accd1202f8b1901b48
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-269'], 'cveID': 'CVE-2026-21533', 'notes': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21533 ; https://nvd.nist.gov/vuln/detail/CVE-2026-21533', 'dueDate': '2026-03-03', 'product': 'Windows', 'dateAdded': '2026-02-10', 'vendorProject': 'Microsoft', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Microsoft Windows Remote Desktop Services contains an improper privilege management vulnerability that could allow an authorized attacker to elevate privileges locally.', 'vulnerabilityName': 'Microsoft Windows Improper Privilege Management Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}
CVE-2026-21519
Microsoft
Windows
Microsoft Windows Type Confusion Vulnerability
2026-02-10
Microsoft Desktop Windows Manager contains a type confusion vulnerability that could allow an authorized attacker to elevate privileges locally.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2026-03-03
Unknown
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21519 ; https://nvd.nist.gov/vuln/detail/CVE-2026-21519
['CWE-843']
2026.05.28
2026-05-28 19:27:12.922700+03:00
0fc1aa9774371adf52e9078f1588c078b9f7071e9642ae37f4f76e3e2ab6634c
2026-05-28 21:45:37.346124+03:00
2026-05-28 21:45:37.346124+03:00
{'cwes': ['CWE-843'], 'cveID': 'CVE-2026-21519', 'notes': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21519 ; https://nvd.nist.gov/vuln/detail/CVE-2026-21519', 'dueDate': '2026-03-03', 'product': 'Windows', 'dateAdded': '2026-02-10', 'vendorProject': 'Microsoft', 'requiredAction': 'Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.', 'shortDescription': 'Microsoft Desktop Windows Manager contains a type confusion vulnerability that could allow an authorized attacker to elevate privileges locally.', 'vulnerabilityName': 'Microsoft Windows Type Confusion Vulnerability', 'knownRansomwareCampaignUse': 'Unknown'}