Latest vulnerabilities

Last 90 days. Sources: NVD (product search), CVE.org (reference data), CISA Known Exploited Vulnerabilities. Latest entry from Oct 4, 2026.

278 entries

  • Citrix NetScaler 8.7 KEV CVE-2026-88779 Memory overflow vulnerability leading to Denial of Service Oct 4, 2026

    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28.

    Vendor
    NetScaler · ADC
    Weakness type
    CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
    CVSS 4.0
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
    Published
    Oct 4, 2026
    In KEV catalog since
    Oct 4, 2026
  • Zammad 8.5 KEV CVE-2026-102490 Undisclosed LPE in Zammad v1.5.0 to v7.1.0-alpha Oct 2, 2026

    All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.

    Vendor
    Zammad GmbH · Zammad
    Weakness type
    CWE-269: Improper Privilege Management
    CVSS 4.0
    CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A/AU:Y/V:D
    Published
    Sep 30, 2026
    In KEV catalog since
    Oct 2, 2026
  • Zammad 8.7 KEV CVE-2026-102489 Undisclosed RCE in Zammad v6.3 and higher Oct 2, 2026

    Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.

    Vendor
    Zammad GmbH · Zammad
    Weakness type
    CWE-384: Session Fixation
    CVSS 4.0
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:A/AU:Y/V:C
    Published
    Sep 30, 2026
    In KEV catalog since
    Oct 2, 2026
  • Microsoft Exchange Server 8.8 CVE-2026-96940 Microsoft Exchange Server Elevation of Privilege Vulnerability Oct 2, 2026

    Critical or actively exploited: triggers an email alert

    Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.

    Vendor
    Microsoft · Microsoft Exchange Server
    Product scope
    Exchange Server
    Weakness type
    CWE-1390: Weak Authentication
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Published
    Oct 2, 2026
  • Fortinet FortiMail 9.8 KEV CVE-2026-104286 Fortinet FortiMail: Path Traversal Oct 1, 2026

    Critical or actively exploited: triggers an email alert

    An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.

    Vendor
    Fortinet · FortiMail
    Product scope
    FortiMail
    Weakness type
    CWE-22: Path Traversal
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
    Published
    Oct 1, 2026
    In KEV catalog since
    Oct 1, 2026
  • Kiteworks Email Protection Gateway 9.4 CVE-2026-102149 Kiteworks Email Protection Gateway Improper Access Control Sep 30, 2026

    Critical or actively exploited: triggers an email alert

    Kiteworks Email Protection Gateway did not sufficiently restrict which account a certificate could be assigned to. This could allow an attacker to associate a certificate with another user's account, affecting the confidentiality and integrity of that account's encrypted mail and, where certificate-based login is enabled, potentially permitting unauthorized access to the account.

    Vendor
    Kiteworks · Email Protection Gateway
    Product scope
    totemomail / Kiteworks
    Weakness type
    CWE-306: Missing Authentication
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
    Published
    Sep 30, 2026
  • Kiteworks Email Protection Gateway 5.3 CVE-2026-102144 Kiteworks Email Protection Gateway Uncontrolled Resource Consumption Sep 30, 2026

    A resource exhaustion vulnerability in Kiteworks Email Protection Gateway allowed an unauthenticated remote attacker to repeatedly trigger a comparatively expensive server-side operation, causing a partial denial of service.

    Vendor
    Kiteworks · Email Protection Gateway
    Product scope
    totemomail / Kiteworks
    Weakness type
    CWE-306: Missing Authentication
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
    Published
    Sep 30, 2026
  • Kiteworks Email Protection Gateway 6.5 CVE-2026-102139 Kiteworks Email Protection Gateway Incorrect Authorization Sep 30, 2026

    An authorization check in the large file exchange feature of Kiteworks Email Protection Gateway did not correctly establish that the requesting user was a party to the package being requested. An authenticated user of that optional feature could read the subject, message body, and attachments of packages they neither sent nor received.

    Vendor
    Kiteworks · Email Protection Gateway
    Product scope
    totemomail / Kiteworks
    Weakness type
    CWE-639: Authorization Bypass Through User-Controlled Key
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
    Published
    Sep 30, 2026
  • Kiteworks Email Protection Gateway 6.6 CVE-2026-102135 Kiteworks Email Protection Gateway Deserialization of Untrusted Data Sep 30, 2026

    On a Kiteworks Email Protection Gateway cluster with database replication enabled, a party trusted by the cluster could submit a crafted serialized object that was deserialized without sufficient validation, potentially allowing code execution as the gateway service account. Replication is disabled by default, and exploitation requires control of a trusted cluster peer or administrative access to the appliance.

    Vendor
    Kiteworks · Email Protection Gateway
    Product scope
    totemomail / Kiteworks
    Weakness type
    CWE-502: Deserialization of Untrusted Data
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
    Published
    Sep 30, 2026
  • Kiteworks Email Protection Gateway 7.2 CVE-2026-102131 Kiteworks Email Protection Gateway Improper Handling of Case Sensitivity Sep 30, 2026

    Kiteworks Email Protection Gateway rejected certain configuration settings, but its validation did not recognize every form in which they could be supplied. An authenticated administrator could potentially use an unrecognized form to have a file of their choosing written to the gateway and executed, resulting in code execution as the gateway service account.

    Vendor
    Kiteworks · Email Protection Gateway
    Product scope
    totemomail / Kiteworks
    Weakness type
    CWE-94: Code Injection
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
    Published
    Sep 30, 2026
  • Kiteworks Email Protection Gateway 7.2 CVE-2026-102130 Kiteworks Email Protection Gateway Remote Code Execution Sep 30, 2026

    Kiteworks Email Protection Gateway did not sufficiently validate the content of an uploaded backup, and allowed an administrator to influence how the application loaded it. An authenticated administrator could potentially use this to execute arbitrary code on the gateway as the underlying service account.

    Vendor
    Kiteworks · Email Protection Gateway
    Product scope
    totemomail / Kiteworks
    Weakness type
    CWE-94: Code Injection
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
    Published
    Sep 30, 2026
  • Kiteworks Email Protection Gateway 7.5 CVE-2026-102128 Kiteworks Email Protection Gateway Improper Authentication Sep 30, 2026

    An identity-verification weakness in Kiteworks Email Protection Gateway allowed the gateway to act on the Kiteworks platform on behalf of a user it had not authenticated, and to provision a platform account for an identity it did not already know. A remote, unauthenticated sender could potentially exploit this to obtain control of a platform account.

    Vendor
    Kiteworks · Email Protection Gateway
    Product scope
    totemomail / Kiteworks
    Weakness type
    CWE-287: Improper Authentication
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
    Published
    Sep 30, 2026
  • Kiteworks Email Protection Gateway 7.0 CVE-2026-102127 Kiteworks Email Protection Gateway Improper Restriction of XML External Entity Reference Sep 30, 2026

    An XML parser used by Kiteworks Email Protection Gateway did not restrict external entity references. Where an optional, non-default message-processing feature is enabled, a remote and unauthenticated sender could potentially use a crafted message to read files accessible to the gateway service account, including cryptographic key material and credentials, and have them sent to a destination they control.

    Vendor
    Kiteworks · Email Protection Gateway
    Product scope
    totemomail / Kiteworks
    Weakness type
    CWE-611: XML External Entity
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L
    Published
    Sep 30, 2026
  • Kiteworks Email Protection Gateway 7.2 CVE-2026-102116 Kiteworks Email Protection Gateway Path Traversal Sep 30, 2026

    -A weakness could have allowed an authenticated Kiteworks Email Protection Gateway administrator to write a file outside its intended location and cause the application to execute it, potentially resulting in remote code execution as the underlying service account.

    Vendor
    Kiteworks · Email Protection Gateway
    Product scope
    totemomail / Kiteworks
    Weakness type
    CWE-22: Path Traversal
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
    Published
    Sep 30, 2026
  • Kiteworks Email Protection Gateway 7.2 CVE-2026-102108 Kiteworks Email Protection Gateway deserialization of untrusted data Sep 30, 2026

    An authenticated administrator of Kiteworks Email Protection Gateway could submit a crafted serialized object to a cluster management interface that was deserialized without sufficient validation, potentially allowing arbitrary code execution in the context of the gateway service account. Exploitation requires an administrator account holding a specific queue-management privilege.

    Vendor
    Kiteworks · Email Protection Gateway
    Product scope
    totemomail / Kiteworks
    Weakness type
    CWE-502: Deserialization of Untrusted Data
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
    Published
    Sep 30, 2026
  • Kiteworks Email Protection Gateway 9.1 CVE-2026-102106 Kiteworks Email Protection Gateway improper authentication Sep 30, 2026

    Critical or actively exploited: triggers an email alert

    Improper authentication in a Kiteworks Email Protection Gateway administrative service. An administrative service in Kiteworks Email Protection Gateway did not consistently enforce administrator authentication, so the required password check could be bypassed. An attacker who referenced a valid administrator account could potentially create, modify, or delete internal users and managed domains and change their security-feature configuration without authenticating; deleting a managed domain also removes its user accounts and could lock administrators out of the gateway.

    Vendor
    Kiteworks · Email Protection Gateway
    Product scope
    totemomail / Kiteworks
    Weakness type
    CWE-287: Improper Authentication
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
    Published
    Sep 30, 2026
  • Kiteworks Email Protection Gateway 9.1 CVE-2026-102105 Kiteworks Email Protection Gateway server-side request forgery Sep 30, 2026

    Critical or actively exploited: triggers an email alert

    Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted requests to internal or otherwise unintended network destinations. The requests are triggered while the gateway renders message content that references external resources. Depending on the services reachable from the gateway, this could disclose sensitive internal information or trigger unintended actions on internal systems.

    Vendor
    Kiteworks · Email Protection Gateway
    Product scope
    totemomail / Kiteworks
    Weakness type
    CWE-918: Server-Side Request Forgery
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
    Published
    Sep 30, 2026
  • Kiteworks Email Protection Gateway 9.1 CVE-2026-102104 Kiteworks Email Protection Gateway server-side request forgery Sep 30, 2026

    Critical or actively exploited: triggers an email alert

    Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted requests to internal or otherwise unintended network destinations. The requests are triggered while the gateway performs an online certificate status check for an inbound message. Depending on the services reachable from the gateway, this could disclose sensitive internal information or disrupt gateway operation.

    Vendor
    Kiteworks · Email Protection Gateway
    Product scope
    totemomail / Kiteworks
    Weakness type
    CWE-918: Server-Side Request Forgery
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
    Published
    Sep 30, 2026
  • Kiteworks Email Protection Gateway 9.1 CVE-2026-102103 Kiteworks Email Protection Gateway server-side request forgery Sep 30, 2026

    Critical or actively exploited: triggers an email alert

    Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted requests to internal or otherwise unintended network destinations. The requests are triggered while the gateway retrieves a certificate revocation list in an inbound message. Depending on the services reachable from the gateway, this could disclose sensitive internal information or disrupt gateway operation.

    Vendor
    Kiteworks · Email Protection Gateway
    Product scope
    totemomail / Kiteworks
    Weakness type
    CWE-918: Server-Side Request Forgery
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
    Published
    Sep 30, 2026
  • Kiteworks Email Protection Gateway 9.1 CVE-2026-102102 Kiteworks Email Protection Gateway server-side request forgery Sep 30, 2026

    Critical or actively exploited: triggers an email alert

    Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted requests to internal or otherwise unintended network destinations. The requests are triggered while the gateway retrieves an issuer certificate in an inbound message. Depending on the services reachable from the gateway, this could disclose sensitive internal information or disrupt gateway operation.

    Vendor
    Kiteworks · Email Protection Gateway
    Product scope
    totemomail / Kiteworks
    Weakness type
    CWE-918: Server-Side Request Forgery
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
    Published
    Sep 30, 2026
  • Kiteworks Email Protection Gateway 7.2 CVE-2026-102097 Kiteworks Email Protection Gateway remote code execution Sep 30, 2026

    Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Remote Code Execution. Kiteworks Email Protection Gateway allowed an authenticated administrator to import configuration whose contents were not sufficiently validated before being processed. A crafted submission could potentially allow arbitrary commands to be executed on the affected gateway.

    Vendor
    Kiteworks · Email Protection Gateway
    Product scope
    totemomail / Kiteworks
    Weakness type
    CWE-22: Path Traversal
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
    Published
    Sep 30, 2026
  • Kiteworks Email Protection Gateway 9.1 CVE-2026-102095 Kiteworks Email Protection Gateway server-side request forgery Sep 30, 2026

    Critical or actively exploited: triggers an email alert

    Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery. Kiteworks Email Protection Gateway performed server-side fetches of URLs contained in the message content it processed, without adequately restricting the fetch destination. A remote, unauthenticated sender could craft a message that caused the gateway to issue requests to internal services and cloud instance metadata endpoints and return the responses, potentially disclosing sensitive internal data and, depending on the internal service reached, affecting its state.

    Vendor
    Kiteworks · Email Protection Gateway
    Product scope
    totemomail / Kiteworks
    Weakness type
    CWE-918: Server-Side Request Forgery
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
    Published
    Sep 30, 2026
  • Kiteworks Email Protection Gateway 7.2 CVE-2026-102094 Kiteworks Email Protection Gateway unsafe reflection Sep 30, 2026

    Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Unsafe Reflection and does not sufficiently restrict the code that the mail-processing pipeline could load from an imported rule configuration. An authenticated administrator with mail-rule configuration privileges could cause the gateway to load and execute code beyond the approved set of mail-processing components, potentially in the context of the mail-gateway service account.

    Vendor
    Kiteworks · Email Protection Gateway
    Product scope
    totemomail / Kiteworks
    Weakness type
    CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
    Published
    Sep 30, 2026
  • Kiteworks Email Protection Gateway 7.2 CVE-2026-102089 Kiteworks Email Protection Gateway path traversal Sep 30, 2026

    Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to a path traversal weakness in an administrative import function allowed an authenticated administrator to write files to arbitrary locations on the server. This could potentially be leveraged to execute arbitrary code on the underlying system.

    Vendor
    Kiteworks · Email Protection Gateway
    Product scope
    totemomail / Kiteworks
    Weakness type
    CWE-22: Path Traversal
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
    Published
    Sep 30, 2026
  • Cisco Catalyst SD-WAN Manager 9.8 KEV CVE-2026-76504 Cisco Catalyst SD-WAN Manager System Account Authorization Bypass Vulnerability Sep 30, 2026

    A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system. A successful exploit could allow the attacker to bypass authentication and gain access to the API as the admin user.

    Vendor
    Cisco · Cisco Catalyst SD-WAN Manager
    Weakness type
    CWE-177
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Published
    Sep 30, 2026
    In KEV catalog since
    Sep 30, 2026
  • Apple Multiple Products 8.8 KEV CVE-2026-86950 Apple iOS and iPadOS: Out-of-bounds Write Sep 29, 2026

    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.

    Vendor
    Apple · iOS and iPadOS
    Weakness type
    CWE-787: Out-of-bounds Write
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
    Published
    Sep 28, 2026
    In KEV catalog since
    Sep 29, 2026
  • OpenSSL 7.5 CVE-2026-84784 QUIC: Unbounded RETIRE_CONNECTION_ID Backlog Sep 29, 2026

    Issue summary: A malicious remote peer may flood the local QUIC stack with NEW_CONNECTION_ID frames by avoiding a limit check on how many connection IDs the remote QUIC stack can use. Impact summary: The local QUIC stack sends a RETIRE_CONN_ID frame for every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID frame is dispatched via the Control Frame Queue (CFQ). If the remote peer also withholds ACKs, then it can force the local stack to allocate ~400MB (depending on ACK delay). CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: RFC 9000 sections 5.1.1 and 5.1.2 [1] describe the mechanism by which a remote peer can notify the local QUIC stack to change the destination connection ID (a.k.a. CID) the local stack uses to identify the connection at the remote peer. Each CID is associated with a sequence number. The sequence number is transmitted in NEW_CONNECTION_ID and RETIRE_CONNECTION_ID frames to identify the CID which is being either associated with a connection or retired. The remote peer sends a NEW_CONNECTION_ID frame to let the local stack know a new CID is being associated with an existing connection. The NEW_CONNECTION_ID frame carries the new CID, its sequence number, and the retire-prior-to number. The retire-prior-to identifies existing CIDs that are to be retired. The local QUIC stack must send a RETIRE_CONNECTION_ID for every destination CID whose sequence number is less than retire-prior-to. The CID becomes retired after the local stack receives an ACK for its RETIRE_CONNECTION_ID frame. Although the OpenSSL QUIC stack supports at most one destination CID for every connection, it can be tricked into processing more than one RETIRE_CONNECTION_ID frame per connection. The OpenSSL QUIC stack currently retires the destination CID as soon as it receives the NEW_CONNECTION_ID, while in fact the destination CID must be retired after an ACK for the RETIRE_CONNECTION_ID frame is received. Correcting the flawed logic also fixes the backlog growth. [1] https://datatracker.ietf.org/doc/html/rfc9000#name-issuing-connection-ids FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary.

    Vendor
    OpenSSL · OpenSSL
    Product scope
    OpenSSL / OpenSSH
    Weakness type
    CWE-770: Allocation of Resources Without Limits or Throttling
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
    Published
    Sep 29, 2026
  • OpenSSL 7.5 CVE-2026-84783 Use-After-Free in X.509 Extension Cache Under Concurrent Use Sep 29, 2026

    Issue summary: The first concurrent use of the same X.509 certificate by several threads may cause its cached extension data to be freed while another thread is still using it. Impact summary: A remote, unauthenticated peer could crash a multi-threaded TLS client, or a multi-threaded TLS server that requests client certificates, if the first certificate chains built to the same trusted CA certificate are built by several connections at the same time. This is a use-after-free read, which is likely to crash the process, resulting in a Denial of Service. CWE: CWE-416: Use After Free Description: OpenSSL caches the decoded values of a certificate's X.509v3 extensions inside the X509 object the first time they are needed. In OpenSSL 4.0 this cache is built in two phases: the extension values are computed while holding a read lock on the certificate, and the results are then installed into the certificate under a write lock. Because a read lock does not exclude other readers, several threads can compute the cache for the same certificate at the same time. Each thread that subsequently acquires the write lock installs its own results and frees the values installed by the thread before it, even though that earlier thread has already marked the cache as complete and may have returned pointers into it to its caller. A caller still using those pointers then reads freed memory. Any certificate shared between threads is exposed the first time its extensions are decoded. In TLS the certificates at risk are the trusted CA certificates supplied for chain verification, by whatever means, since these are shared by every connection and their extensions are decoded and cached the first time a chain is built to them. Certificates sent by the peer are decoded separately for each connection and are not shared, so they are not affected. In a TLS client verifying server certificates, or a TLS server that requests and verifies client certificates, the use-after-free could only occur if the first chains built to the same trusted CA are built by several connections at the same time. FIPS impact: no The FIPS module is not affected as X.509 certificate handling is outside of the OpenSSL FIPS module boundary. OpenSSL 4.0 is vulnerable to this issue. OpenSSL 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are not affected by this issue. OpenSSL 4.0 users should upgrade to OpenSSL 4.0.3. This issue was reported on 27 August 2026 by Tim Becker (Xint.io) and independently in a public report on 31 August 2026 by aydinmercan. The fix has been developed by Bob Beck. -- cut (non-publishing metadata for internal use) -- Reported by: Tim Becker (Xint.io), aydinmercan Fixed by: Bob Beck

    Vendor
    OpenSSL · OpenSSL
    Product scope
    OpenSSL / OpenSSH
    Weakness type
    CWE-416: Use After Free
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
    Published
    Sep 29, 2026
  • OpenSSL 5.3 CVE-2026-75805 NULL Pointer Dereference in CMP Client Revocation Response Handling Sep 29, 2026

    Issue summary: A CMP client that requests certificate revocation on the basis of a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when processing a crafted revocation response. Impact summary: The NULL pointer dereference happens on a read which leads to a crash and a Denial of Service for the affected client application. CWE: CWE-476: NULL-pointer dereference Description: A CMP client revoking a certificate has to tell the server which certificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the certificate itself or its issuer name and serial number. This is 'openssl cmp -cmd rr -csr <file>' on the command line, or OSSL_CMP_exec_RR_ses() with the certificate supplied via OSSL_CMP_CTX_set1_p10CSR() through the API. A CSR does not contain the issuer name and serial number of the certificate, so the client does not send them. A server may optionally name the certificate it revoked in its response, and the client then compares that name against what it sent. Having sent neither an issuer name nor a serial number, it has nothing to compare against, and a server returning a specially crafted name causes the client to read from a NULL pointer and crash. The revocation response is checked for valid message protection before the affected code is reached, so an attacker must be a malicious or compromised CMP server, or a man-in-the-middle in possession of the secret used for message protection. Clients that identify the certificate to be revoked by a certificate or by issuer and serial number rather than by a PKCS#10 CSR are not affected. FIPS impact: no No FIPS modules are affected by this issue, as the CMP protocol implementation is outside the OpenSSL FIPS module boundary.

    Vendor
    OpenSSL · OpenSSL
    Product scope
    OpenSSL / OpenSSH
    Weakness type
    CWE-476: NULL-pointer dereference
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
    Published
    Sep 29, 2026
  • OpenSSL 5.3 CVE-2026-75804 QUIC Connection-Level Flow Control is Not Enforced for Streams Sep 29, 2026

    Issue summary: OpenSSL QUIC stack does not enforce connection level flow control for streams. Remote peers may send more bytes as long as they fit within the stream flow control limits. Impact summary: A malicious remote peer may exploit the lack of connection flow control for streams to make the QUIC stack receive ~100MB of memory instead of 768 KiB (default flow control window size). CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: The local QUIC stack advertises two flow control limits to its remote peer: stream flow control limit and connection flow control limit. The remote peer must follow both limits when transmitting stream data. Whenever the local QUIC stack receives a stream frame, it validates that the size of the received stream frame stays within flow control limits. If either limit is exceeded (stream level or connection level), then the QUIC stack must close the connection with a flow control error. The vulnerable OpenSSL QUIC stack enforces the stream-level but not the connection-level limit. To exploit the issue, three conditions must be met: - the remote peer opens several streams - each stream must stay within the stream-level flow control limit - there must be no zero-offset byte sent on any of the streams (to prevent the vulnerable QUIC stack from consuming data). By meeting the conditions above, the remote peer may make the local stack allocate 2 x MAX_STREAMS x (stream flow control limit) bytes of memory. MAX_STREAMS defaults to 100, and the limit applies to both bidirectional and unidirectional streams, making it 200 in total. The default flow control window for a stream is 512kB. The remote peer may force the vulnerable QUIC stack to allocate 100MB of heap per connection. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary.

    Vendor
    OpenSSL · OpenSSL
    Product scope
    OpenSSL / OpenSSH
    Weakness type
    CWE-770: Allocation of Resources Without Limits or Throttling
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
    Published
    Sep 29, 2026
  • OpenSSL 7.5 CVE-2026-72897 Out-of-Bounds Access After SSL_set_SSL_CTX() During a Handshake Sep 29, 2026

    Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a connection to a different SSL_CTX part way through a handshake may access memory beyond the end of an internal array if the replacement context knows about more provider signature algorithms than the context the connection was created from. Applications which never call SSL_set_SSL_CTX() are not affected. Impact summary: A remote peer may be able to cause a small out-of-bounds read, and in some circumstances a fixed-value out-of-bounds write, on the server heap. This may lead to a Denial of Service. CWE: CWE-787: Out-of-bounds Write Description: A TLS connection records how many certificate slots it has when it is created, taken from the SSL_CTX that created it: the built-in certificate types plus one slot for each provider TLS-SIGALG entry that context was aware of. That count sizes an internal array of per-slot certificate validity flags. An application may replace a connection's SSL_CTX part way through the handshake by calling SSL_set_SSL_CTX(), most commonly from a servername callback in order to serve a different virtual host. Doing so did not refresh the recorded count. A provider signature algorithm's slot index is its position in the list of whichever context resolves it, so if the replacement context is aware of more of them than the original, an algorithm offered by the peer can resolve to an index beyond the end of the array. Processing the peer's signature algorithms then reads one four byte word past the end for each such algorithm and, where the word read is zero, writes a fixed value over it. A peer offering many of them can corrupt heap metadata and abort the process. Only provider signature algorithms which occupy one of the excess slots, and which the server also has configured, have this effect. Codepoints the replacement context does not recognise are discarded without being resolved to a slot, and provider signature algorithms are usable only from TLS 1.3. The two contexts must therefore be aware of different numbers of provider signature algorithms, which requires separate library contexts, a provider loaded between the two being created, or providers which differ in what they advertise - in 4.0, for example, the default provider advertises SM2 where the FIPS provider does not. A deployment meeting the condition is also unable to negotiate the affected algorithms with legitimate clients, since the same stale count hides the corresponding certificates, so the misconfiguration is likely to be noticed. For that reason, and because the configuration is not the default, this issue has been assessed as Low severity. FIPS impact: no No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary.

    Vendor
    OpenSSL · OpenSSL
    Product scope
    OpenSSL / OpenSSH
    Weakness type
    CWE-787: Out-of-bounds Write
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
    Published
    Sep 29, 2026
  • OpenSSL 3.7 CVE-2026-54875 Non-Constant-Time SM2 Scalar Multiplication on ARM64 and RISC-V Sep 29, 2026

    Issue summary: A non-constant-time optimized implementation of scalar point multiplication is used for SM2 private key operations on ARM64 and RISC-V platforms. Impact summary: An attacker able to measure the time taken by, or to observe the cache-line access pattern of SM2 signing or decryption on an affected platform can learn information about the secret scalar. CWE: CWE-208: Observable Timing Discrepancy Description: On ARM64 and RISC-V processors, the SM2 curve uses an optimized scalar multiplication implementation whose conditional branches and table look ups are chosen according to the bits of the secret scalar. The execution time and the cache-access pattern therefore depend on the long-term private key (during SM2 decryption) or the per-signature nonce (during SM2 signature generation), forming a timing and cache side-channel. FIPS Impact: no SM2 is not a FIPS algorithm and the optimized SM2 implementation is not part of the FIPS module. OpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and RISC-V. OpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue. OpenSSL 4.0 users should upgrade to OpenSSL 4.0.3. OpenSSL 3.6 users should upgrade to OpenSSL 3.6.5. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.9. OpenSSL 3.4 users should upgrade to OpenSSL 3.4.8. This issue was reported on 2 May 2026 by Abhinav Agarwal. It was independently reported on 6 June 2026 by Feng Xue. The fix was developed by Igor Ustinov. -- cut (non-publishing metadata for internal use) -- Reported by: Abhinav Agarwal, Feng Xue Fixed by: Igor Ustinov

    Vendor
    OpenSSL · OpenSSL
    Product scope
    OpenSSL / OpenSSH
    Weakness type
    CWE-208: Observable Timing Discrepancy
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
    Published
    Sep 29, 2026
  • OpenSSL 7.5 CVE-2026-54873 QUIC STREAM Fragment Metadata DoS Sep 29, 2026

    Issue summary: QUIC process may keep memory for QUIC packet buffer for much longer period than necessary. Impact summary: Remote peer can exploit this vulnerability by sending maliciously crafted packets, making the local QUIC stack to keep the memory for packet buffers allocated. The time for which the memory remains allocated is entirely under the control of the potentially malicious remote peer. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: To save copy operation from the packet buffer to the stream reassemble buffer the QUIC stack leaves the stream data on the packet buffer waiting to be copied to a buffer provided by the local receiving application. The QUIC stack releases a reference to the packet buffer only after the data are copied to the application buffer. This design is more efficient for legitimate data transfers but enables an attacker to allocate a lot more memory than actually required by the data kept in the receiving stream buffer. To mitigate the vulnerability, the QUIC stack now calculates and monitors memory overhead for every stream. The memory overhead for a single stream frame is calculated as a difference between the size of the whole packet that carries the stream frame and the size of the stream frame itself. The memory overhead for a single stream frame is added to the total (cumulative) memory overhead QUIC stack keeps for each stream. Once the cumulative memory overhead exceeds 64kB, the QUIC stack moves the stream frame data from the packet buffer to the stream buffer, starting with the next packet received. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary.

    Vendor
    OpenSSL · OpenSSL
    Product scope
    OpenSSL / OpenSSH
    Weakness type
    CWE-770: Allocation of Resources Without Limits or Throttling
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
    Published
    Sep 29, 2026
  • OpenSSL 5.3 CVE-2026-42772 Potential CPU DoS via O(n^2) Fragment Reassembly in QUIC Sep 29, 2026

    Issue summary: The QUIC stream reassembly algorithm performance deteriorates progressively as packets are arriving out of order. The worst case has a quadratic complexity proportional to the number of stream frames kept in the buffer for the received stream data. Impact summary: A remote QUIC peer that completes the handshake can create a connection-scoped CPU pressure and potentially a Denial of Service using compliant STREAM frames inside the advertised receive window, with low attacker bandwidth. CWE: CWE-407: Inefficient Algorithmic Complexity Description: OpenSSL manages received QUIC stream fragments using a doubly-linked list. While it optimizes for append operations (at the end of the list), it falls back to a head-to-tail linear search for any fragment that does not immediately follow the current `tail`. By manipulating the sequence of offsets, an attacker can force the server to perform O(n^2) operations, consuming excessive CPU time for the QUIC process. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary.

    Vendor
    OpenSSL · OpenSSL
    Product scope
    OpenSSL / OpenSSH
    Weakness type
    CWE-407: Inefficient Algorithmic Complexity
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
    Published
    Sep 29, 2026
  • OpenSSL 3.7 CVE-2026-35191 QUIC Unvalidated Amplification Credit may be Over Accounted Sep 29, 2026

    Issue summary: The OpenSSL QUIC server, when configured to not preform address validation, can be forced to count incoming packets multiple times in its unvalidated credit computation, leading to a violation of the RFC 9000 unvalidated connection amplification limit of 3 times the amount of data received. Impact summary: A remote attacker able to spoof packets to a server using the OpenSSL QUIC implementation might use the server for an amplification of a DDoS attack. CWE: CWE-440: Expected Behavior Violation Description: OpenSSL's QUIC stack, when operating as a server, enforces client address validation (RFC 9000, Section 8), to confirm the peer address is not used for a traffic amplification attack. If this feature is disabled on the server, the QUIC stack limits the amount of server data that can be sent to 3 times the amount of data received from the peer address, until such time as the TLS handshake is completed. The OpenSSL QUIC server, when operating in non-validation mode, adds the length of the whole datagram received to the unvalidated credit limit when processing each QUIC packet in the datagram. A remote peer may, after establishing a connection with an initial client hello frame, send a subsequent datagram containing multiple QUIC packets, leading the server to account the entire datagram length for each packet in the datagram, resulting in the server believing that the peer has sent more data than it actually has, thereby violating the 3x amplification limit mandated by the RFC. FIPS impact: no As the QUIC stack lives outside the FIPS module boundary, no FIPS modules are affected by this CVE.

    Vendor
    OpenSSL · OpenSSL
    Product scope
    OpenSSL / OpenSSH
    Weakness type
    CWE-440: Expected Behavior Violation
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
    Published
    Sep 29, 2026
  • OpenSSL 5.3 CVE-2026-35189 Excessive Memory Allocation in Relative CRLDP Processing Sep 29, 2026

    Issue summary: A certificate with many nameRelativeToCRLIssuer CRL distribution points causes disproportionate heap growth when OpenSSL caches X.509 extensions. Impact summary: Receiving a crafted certificate from a malicious peer can lead to significant memory pressure and possible Denial of Service in clients or in servers that solicit client certificates. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: A certificate or a set of certificates that fits under the limit for size of certificates accepted from the peer (~100 KiB) can result in allocation of several hundred MiB of resident memory on the receiving side during a normal TLS handshake. This may be enough to crash the client or server, if multiple concurrent connections lead to similarly large memory allocations. The fix postpones processing of the CRL distribution points extensions in certificates to the time when the processed value is required for CRL processing. This avoids keeping large memory allocations for a long time when such certificates are received. FIPS impact: no The affected code is outside the FIPS module boundary.

    Vendor
    OpenSSL · OpenSSL
    Product scope
    OpenSSL / OpenSSH
    Weakness type
    CWE-770: Allocation of Resources Without Limits or Throttling
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
    Published
    Sep 29, 2026
  • Citrix NetScaler 9.5 KEV CVE-2026-88772 Memory overflow vulnerability leading to Remote Code Execution or Denial of Service Sep 27, 2026

    Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service

    Vendor
    Citrix NetScaler · ADC
    Weakness type
    CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
    CVSS 4.0
    CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
    Published
    Sep 27, 2026
    In KEV catalog since
    Sep 27, 2026
  • Citrix NetScaler 9.5 KEV CVE-2026-88771 A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands Sep 27, 2026

    Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.

    Vendor
    Citrix NetScaler · ADC
    Weakness type
    CWE-20: Improper Input Validation
    CVSS 4.0
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
    Published
    Sep 27, 2026
    In KEV catalog since
    Sep 27, 2026
  • Zimbra Collaboration Suite 9.3 CVE-2026-93647 Zimbra Collaboration Suite Classic Web Client Stored Cross-Site Scripting via Crafted Calendar COUNTER Message From Address Sep 25, 2026

    Critical or actively exploited: triggers an email alert

    An unauthenticated calendar sender can place active markup in a COUNTER message's RFC From address. Selecting the message in Zimbra Classic triggers stored XSS, allowing the attacker to access mailbox data and act as the victim.

    Vendor
    Zimbra · Zimbra Collaboration Suite (ZCS)
    Product scope
    Webmail
    Weakness type
    CWE-79: Cross-Site Scripting
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
    Published
    Sep 25, 2026
  • Zimbra Collaboration Suite 9.3 CVE-2026-93642 Zimbra Collaboration Suite Modern Web Client Stored Cross-Site Scripting via Forged Share Invitation Sep 25, 2026

    Critical or actively exploited: triggers an email alert

    An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Modern recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim.

    Vendor
    Zimbra · Zimbra Collaboration Suite (ZCS)
    Product scope
    Webmail
    Weakness type
    CWE-79: Cross-Site Scripting
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
    Published
    Sep 25, 2026
  • Zimbra Collaboration Suite 9.3 CVE-2026-93641 Zimbra Collaboration Suite Classic Web Client Stored Cross-Site Scripting via Forged Share Invitation Sep 25, 2026

    Critical or actively exploited: triggers an email alert

    An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Classic recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim.

    Vendor
    Zimbra · Zimbra Collaboration Suite (ZCS)
    Product scope
    Webmail
    Weakness type
    CWE-79: Cross-Site Scripting
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
    Published
    Sep 25, 2026
  • WordPress Core 8.1 KEV CVE-2026-87902 WordPress: Remote File Inclusion Sep 25, 2026

    An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.

    Vendor
    WordPress · WordPress
    Weakness type
    CWE-98: Remote File Inclusion
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
    Published
    Sep 22, 2026
    In KEV catalog since
    Sep 25, 2026
  • MikroTik RouterOS 6.9 KEV CVE-2026-67279 SSH Pre-Authentication Rekey State Bypass in MikroTik RouterOS Sep 25, 2026

    RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request. On affected builds the server dispatches the command, enabling unauthenticated creation, overwrite, and reconstruction of files in the RouterOS managed file namespace, including support files containing configuration and diagnostic data.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)

    Vendor
    Mikrotik · RouterOS
    Weakness type
    CWE-841: Improper enforcement of behavioral workflow
    CVSS 4.0
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
    Published
    Sep 5, 2026
    In KEV catalog since
    Sep 25, 2026
  • Microsoft SharePoint 8.8 KEV CVE-2026-65660 Microsoft SharePoint Server Remote Code Execution Vulnerability Sep 25, 2026

    Critical or actively exploited: triggers an email alert

    Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

    Vendor
    Microsoft · Microsoft SharePoint
    Product scope
    SharePoint
    Weakness type
    CWE-94: Code Injection
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Published
    Aug 11, 2026
    In KEV catalog since
    Sep 25, 2026
  • Adobe Commerce and Magento 9.1 KEV CVE-2026-71362 Adobe Commerce | Incorrect Authorization (CWE-863) Sep 24, 2026

    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue does not require user interaction.

    Vendor
    Adobe · Adobe Commerce
    Weakness type
    CWE-863: Incorrect Authorization
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
    Published
    Aug 11, 2026
    In KEV catalog since
    Sep 24, 2026
  • WSO2 Multiple Products 10.0 KEV CVE-2026-5430 Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Account Takeover Sep 24, 2026

    The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access. Successful exploitation of this vulnerability may result in unauthorized access to the system, including the potential compromise of administrative accounts and full account takeover. The CVSS score is adjusted to 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) in single-tenant deployments, reflecting that the impact is contained within a single security authority boundary.

    Vendor
    WSO2 · WSO2 Universal Gateway
    Weakness type
    CWE-347: Improper Validation of Certificate With Host Mismatch
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
    Published
    Aug 6, 2026
    In KEV catalog since
    Sep 24, 2026
  • F5 BIG-IP APM 9.3 KEV CVE-2026-94127 BIG-IP APM OAuth vulnerability Sep 22, 2026

    When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected by this vulnerability. Impact: This vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

    Vendor
    F5 · BIG-IP
    Weakness type
    CWE-122: Heap-based Buffer Overflow
    CVSS 4.0
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
    Published
    Sep 22, 2026
    In KEV catalog since
    Sep 22, 2026
  • Arista VeloCloud Orchestrator 9.5 KEV CVE-2026-93952 Security Advisory 0183 Sep 22, 2026

    VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. Hosted, including Dedicated, versions of VCO were impacted and have already been patched.

    Vendor
    Arista Networks · VeloCloud Orchestrator (VCO) On-Prem
    Weakness type
    CWE-20: Improper Input Validation
    CVSS 4.0
    CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
    Published
    Sep 22, 2026
    In KEV catalog since
    Sep 22, 2026
  • Check Point Multiple Products 9.8 KEV CVE-2026-93616 Directory Traversal and File upload allows execution of arbitrary script on the Management Server Sep 22, 2026

    A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.

    Vendor
    checkpoint · Quantum Security Management
    Weakness type
    CWE-22: Path Traversal
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Published
    Sep 22, 2026
    In KEV catalog since
    Sep 22, 2026
  • Check Point Multiple Products 9.8 KEV CVE-2026-85102 Improper Certificate Validation in Quantum Security Gateway Sep 22, 2026

    Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.

    Vendor
    checkpoint · Quantum Security Gateway
    Weakness type
    CWE-295: Improper Certificate Validation.
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Published
    Sep 9, 2026
    In KEV catalog since
    Sep 22, 2026
  • Zyxel GS1900 Series Switches 8.8 KEV CVE-2026-7273 Zyxel GS1900-48HPv2 firmware: Stack-based Buffer Overflow Sep 21, 2026

    A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.

    Vendor
    Zyxel · GS1900-48HPv2 firmware
    Weakness type
    CWE-121: Stack-based Buffer Overflow
    CVSS 3.1
    CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Published
    Jun 16, 2026
    In KEV catalog since
    Sep 21, 2026
  • Exim 4.0 CVE-2026-94057 Exim: Improper Neutralization of CRLF Sequences ('CRLF Injection') Sep 19, 2026

    Exim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent message, and instead depends on crafted data sent after a rejection during DATA processing.

    Vendor
    Exim · Exim
    Product scope
    Postfix / Exim / Dovecot
    Weakness type
    CWE-93: Improper Neutralization of CRLF Sequences ('CRLF Injection')
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N
    Published
    Sep 19, 2026
  • Exim 7.5 CVE-2026-94056 Exim: Use of Uninitialized Resource Sep 19, 2026

    Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack memory.

    Vendor
    Exim · Exim
    Product scope
    Postfix / Exim / Dovecot
    Weakness type
    CWE-908: Use of Uninitialized Resource
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:L
    Published
    Sep 19, 2026
  • Exim 3.7 CVE-2026-94055 Exim: Use After Free Sep 19, 2026

    Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free.

    Vendor
    Exim · Exim
    Product scope
    Postfix / Exim / Dovecot
    Weakness type
    CWE-416: Use After Free
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
    Published
    Sep 19, 2026
  • Exim 7.0 CVE-2026-94054 Exim: Out-of-bounds Write Sep 19, 2026

    Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write.

    Vendor
    Exim · Exim
    Product scope
    Postfix / Exim / Dovecot
    Weakness type
    CWE-787: Out-of-bounds Write
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L
    Published
    Sep 19, 2026
  • Linux Kernel 8.8 KEV CVE-2026-53266 netfilter: bridge: make ebt_snat ARP rewrite writable Sep 18, 2026

    In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target keeps the Ethernet source address rewrite behind skb_ensure_writable(skb, 0). This is intentional: at the bridge ebtables hooks the Ethernet header is addressed through skb_mac_header()/eth_hdr(), while skb->data points at the Ethernet payload. Asking skb_ensure_writable() for ETH_HLEN bytes would check the payload, not the Ethernet header, and would reintroduce the small packet regression fixed by commit 63137bc5882a. However, the optional ARP sender hardware address rewrite is different. It writes through skb_store_bits() at an offset relative to skb->data: skb_store_bits(skb, sizeof(struct arphdr), info->mac, ETH_ALEN) skb_header_pointer() only safely reads the ARP header; it does not make the later sender hardware address range writable. If that range is still held in a nonlinear skb fragment backed by a splice-imported file page, skb_store_bits() maps the frag page and copies the new MAC address directly into it. Ensure the ARP SHA range is writable before reading the ARP header and before calling skb_store_bits().

    Vendor
    Linux · Linux
    Weakness type
    CWE-787: Out-of-bounds Write
    CVSS 3.1
    CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
    Published
    Jun 25, 2026
    In KEV catalog since
    Sep 18, 2026
  • Linux Kernel 7.8 KEV CVE-2025-39964 crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Sep 18, 2026

    In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable fashion. Furthermore, concurrent writes may create inconsistencies in the internal socket state. Disallow this by adding a new ctx->write field that indiciates exclusive ownership for writing.

    Vendor
    Linux · Linux
    Weakness type
    CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
    CVSS 3.1
    CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
    Published
    Oct 13, 2025
    In KEV catalog since
    Sep 18, 2026
  • Linux Kernel 9.8 KEV CVE-2025-39682 tls: fix handling of zero-length records on the rx_list Sep 18, 2026

    In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call must process either - only contiguous DATA records (any number of them) - one non-DATA record If the next record has different type than what has already been processed we break out of the main processing loop. If the record has already been decrypted (which may be the case for TLS 1.3 where we don't know type until decryption) we queue the pending record to the rx_list. Next recvmsg() will pick it up from there. Queuing the skb to rx_list after zero-copy decrypt is not possible, since in that case we decrypted directly to the user space buffer, and we don't have an skb to queue (darg.skb points to the ciphertext skb for access to metadata like length). Only data records are allowed zero-copy, and we break the processing loop after each non-data record. So we should never zero-copy and then find out that the record type has changed. The corner case we missed is when the initial record comes from rx_list, and it's zero length.

    Vendor
    Linux · Linux
    Weakness type
    CWE-754: Improper Check for Unusual or Exceptional Conditions
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Published
    Sep 5, 2025
    In KEV catalog since
    Sep 18, 2026
  • Acronis Backup 7.8 KEV CVE-2026-87886 Acronis Backup Sep 17, 2026

    Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux) before build 1.8.11.638, Acronis Backup plugin for DirectAdmin (Linux) before build 1.2.3.238.

    Vendor
    Acronis · Acronis Backup
    Weakness type
    CWE-276
    CVSS 3.0
    CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
    Published
    Sep 17, 2026
    In KEV catalog since
    Sep 16, 2026
  • Cisco Identity Services Engine 10.0 KEV CVE-2026-76460 Cisco Identity Services Engine Authentication Bypass Vulnerability Sep 16, 2026

    A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.

    Vendor
    Cisco · Cisco Identity Services Engine Software
    Weakness type
    CWE-648
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
    Published
    Sep 16, 2026
    In KEV catalog since
    Sep 16, 2026
  • Google Pixel 8.8 KEV CVE-2026-58704 Google Android: Protection Mechanism Failure Sep 16, 2026

    In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Vendor
    Google · Android
    Weakness type
    CWE-693: Protection Mechanism Failure
    CVSS 3.1
    CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Published
    Sep 15, 2026
    In KEV catalog since
    Sep 16, 2026
  • Cisco Secure Email Gateway 9.8 KEV CVE-2026-76461 Cisco Secure Email Gateway SQL Injection Vulnerability Sep 14, 2026

    Critical or actively exploited: triggers an email alert

    A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.

    Vendor
    Cisco · Cisco Secure Email
    Product scope
    Mail-Gateways
    Weakness type
    CWE-89: SQL Injection
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Published
    Sep 14, 2026
    In KEV catalog since
    Sep 14, 2026
  • Cisco Secure Email 9.8 CVE-2026-76443 Cisco Secure Email Gateway Security Hardening Release Sep 14, 2026

    Critical or actively exploited: triggers an email alert

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76443 are related to issues with improper neutralization that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-707.

    Vendor
    Cisco · Cisco Secure Email
    Product scope
    Mail-Gateways
    Weakness type
    CWE-707
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Published
    Sep 14, 2026
  • Cisco Secure Email 7.5 CVE-2026-76442 Cisco Secure Email Gateway Security Hardening Release Sep 14, 2026

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76442 are related to issues with improper validation of specified quantity in input that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-1284.

    Vendor
    Cisco · Cisco Secure Email
    Product scope
    Mail-Gateways
    Weakness type
    CWE-1284
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
    Published
    Sep 14, 2026
  • Cisco Secure Email and Web Manager 9.8 CVE-2026-76441 Cisco Secure Email Gateway Security Hardening Release Sep 14, 2026

    Critical or actively exploited: triggers an email alert

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76441 are related to issues with improper access control that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-284.

    Vendor
    Cisco · Cisco Secure Email and Web Manager
    Product scope
    Mail-Gateways
    Weakness type
    CWE-284
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Published
    Sep 14, 2026
  • Cisco Secure Email 9.8 CVE-2026-76440 Cisco Secure Email Gateway Security Hardening Release Sep 14, 2026

    Critical or actively exploited: triggers an email alert

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76440 are related to path traversal issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-23.

    Vendor
    Cisco · Cisco Secure Email
    Product scope
    Mail-Gateways
    Weakness type
    CWE-23
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Published
    Sep 14, 2026
  • Cisco Secure Email 9.8 CVE-2026-20353 Cisco Secure Email Gateway Security Hardening Release Sep 14, 2026

    Critical or actively exploited: triggers an email alert

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20353 are related to issues with improper control of a resource through its lifetime that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-664.

    Vendor
    Cisco · Cisco Secure Email
    Product scope
    Mail-Gateways
    Weakness type
    CWE-664
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Published
    Sep 14, 2026
  • GitLab Community Edition and Enterprise Edition 10.0 KEV CVE-2026-85706 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab Sep 12, 2026

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.11.12, 19.0 before 19.0.9, 19.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.

    Vendor
    GitLab · GitLab
    Weakness type
    CWE-22: Path Traversal
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
    Published
    Sep 12, 2026
    In KEV catalog since
    Sep 11, 2026
  • ConnectWise ScreenConnect 9.9 KEV CVE-2026-84869 ScreenConnect Client: Guest-to-Host File Execution via File-Transfer Actions Sep 11, 2026

    A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.

    Vendor
    ConnectWise · ScreenConnect
    Weakness type
    CWE-862: Missing Authorization
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
    Published
    Sep 8, 2026
    In KEV catalog since
    Sep 11, 2026
  • JFrog Artifactory 7.5 KEV CVE-2026-42018 Anonymous user token generation exposure in JFrog Artifactory Sep 11, 2026

    JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.

    Vendor
    jfrog · artifactory
    Weakness type
    CWE-287: Improper Authentication
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
    Published
    Aug 12, 2026
    In KEV catalog since
    Sep 11, 2026
  • JFrog Artifactory 8.1 KEV CVE-2026-42016 Incorrect authorization validation of user token in JFrog Artifactory allows Privilege Escalation Sep 11, 2026

    JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.

    Vendor
    jfrog · artifactory
    Weakness type
    CWE-863: Incorrect Authorization
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
    Published
    Jul 27, 2026
    In KEV catalog since
    Sep 11, 2026
  • MikroTik RouterOS 9.2 KEV CVE-2026-86060 SSH session privilege manipulation via a crafted username in Mikrotik RouterOS Sep 10, 2026

    RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)

    Vendor
    Mikrotik · RouterOS
    Weakness type
    CWE-88: Improper neutralization of argument delimiters in a command ('argument injection')
    CVSS 4.0
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
    Published
    Sep 5, 2026
    In KEV catalog since
    Sep 10, 2026
  • MikroTik RouterOS 8.8 KEV CVE-2026-67277 Kernel memory disclosure and denial of service in MikroTik RouterOS btest service Sep 10, 2026

    RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits an uninitialized tail from a kernel packet buffer. A separate unchecked, inverted packet-size interval causes unsigned integer underflow, anomalously large fragmented output, and can restart the RouterOS kernel. This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)

    Vendor
    Mikrotik · RouterOS
    Weakness type
    CWE-306: Missing Authentication
    CVSS 4.0
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
    Published
    Sep 5, 2026
    In KEV catalog since
    Sep 10, 2026
  • Google Chromium V8 8.8 KEV CVE-2026-87491 Google Chrome: Out-of-bounds Write Sep 9, 2026

    Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Vendor
    Google · Chrome
    Weakness type
    CWE-787: Out-of-bounds Write
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
    Published
    Sep 9, 2026
    In KEV catalog since
    Sep 9, 2026
  • Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management 10.0 KEV CVE-2026-20079 Cisco Secure Firewall Management Center Authentication Bypass Remote Code Execution Vulnerability Sep 9, 2026

    A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.&nbsp; This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow&nbsp;root access to the device.&nbsp;

    Vendor
    Cisco · Cisco Secure Firewall Management Center (FMC)
    Weakness type
    CWE-288
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
    Published
    Mar 4, 2026
    In KEV catalog since
    Sep 9, 2026
  • Citrix NetScaler 9.3 KEV CVE-2026-19490 NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490 Sep 9, 2026

    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.

    Vendor
    NetScaler · ADC
    Weakness type
    CWE-288: Authentication Bypass Using an Alternate Path or Channel
    CVSS 4.0
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L
    Published
    Aug 19, 2026
    In KEV catalog since
    Sep 9, 2026
  • Fortinet Multiple Products 7.4 KEV CVE-2025-25249 Fortinet FortiSwitchManager: Heap-based Buffer Overflow Sep 9, 2026

    A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets

    Vendor
    Fortinet · FortiSwitchManager
    Weakness type
    CWE-122: Heap-based Buffer Overflow
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:W/RC:C
    Published
    Jan 13, 2026
    In KEV catalog since
    Sep 9, 2026
  • N-able N-central 10.0 KEV CVE-2026-86218 pre-authentication remote code execution Sep 8, 2026

    N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.

    Vendor
    N-able · N-central
    Weakness type
    CWE-96: Improper neutralization of directives in statically saved code ('static code injection')
    CVSS 4.0
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
    Published
    Sep 6, 2026
    In KEV catalog since
    Sep 8, 2026
  • Microsoft Windows 7.8 KEV CVE-2026-85880 Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability Sep 8, 2026

    Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.

    Vendor
    Microsoft · Windows 10 Version 1607
    Weakness type
    CWE-122: Heap-based Buffer Overflow
    CVSS 3.1
    CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
    Published
    Sep 8, 2026
    In KEV catalog since
    Sep 8, 2026
  • Microsoft Windows 7.8 KEV CVE-2026-81963 Windows Update Stack Elevation of Privilege Vulnerability Sep 8, 2026

    Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.

    Vendor
    Microsoft · Windows 11 version 23H2
    Weakness type
    CWE-59: Improper Link Resolution Before File Access ('Link Following')
    CVSS 3.1
    CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
    Published
    Sep 8, 2026
    In KEV catalog since
    Sep 8, 2026
  • Adobe Commerce and Magento 10.0 KEV CVE-2026-75650 Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) Sep 8, 2026

    Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

    Vendor
    Adobe · Adobe Commerce
    Weakness type
    CWE-1336
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
    Published
    Sep 7, 2026
    In KEV catalog since
    Sep 8, 2026
  • Microsoft Active Directory / Entra 5.9 CVE-2026-72978 Active Directory Federation Services (AD FS) Denial of Service Vulnerability Sep 8, 2026

    Allocation of resources without limits or throttling in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.

    Vendor
    Microsoft · Windows 10 Version 1607
    Product scope
    Active Directory / Entra
    Weakness type
    CWE-770: Allocation of Resources Without Limits or Throttling
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
    Published
    Sep 8, 2026
  • Microsoft Active Directory / Entra 7.8 CVE-2026-69822 Windows Kerberos Elevation of Privilege Vulnerability Sep 8, 2026

    Numeric truncation error in Windows Kerberos allows an authorized attacker to elevate privileges locally.

    Vendor
    Microsoft · Windows 10 Version 1809
    Product scope
    Active Directory / Entra
    Weakness type
    CWE-197: Numeric Truncation Error
    CVSS 3.1
    CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Published
    Sep 8, 2026
  • Microsoft Active Directory / Entra 7.8 CVE-2026-69821 Active Directory Certificate Services (AD CS) Elevation of Privilege Vulnerability Sep 8, 2026

    Improper encoding or escaping of output in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges locally.

    Vendor
    Microsoft · Windows 10 Version 1607
    Product scope
    Active Directory / Entra
    Weakness type
    CWE-116: Improper Encoding or Escaping of Output
    CVSS 3.1
    CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Published
    Sep 8, 2026
  • Microsoft Active Directory / Entra 7.5 CVE-2026-69809 Windows Active Directory Domain Services Denial of Service Vulnerability Sep 8, 2026

    Missing release of memory after effective lifetime in Active Directory Domain Services allows an unauthorized attacker to deny service over a network.

    Vendor
    Microsoft · Windows 11 version 23H2
    Product scope
    Active Directory / Entra
    Weakness type
    CWE-401: Missing Release of Memory after Effective Lifetime
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
    Published
    Sep 8, 2026
  • Microsoft Active Directory / Entra 7.5 CVE-2026-69760 Windows Kerberos Denial of Service Vulnerability Sep 8, 2026

    Out-of-bounds read in Windows Kerberos allows an unauthorized attacker to deny service over a network.

    Vendor
    Microsoft · Windows 10 Version 1607
    Product scope
    Active Directory / Entra
    Weakness type
    CWE-125: Out-of-bounds Read
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
    Published
    Sep 8, 2026
  • Microsoft Active Directory / Entra 7.5 CVE-2026-69744 Windows Kerberos Denial of Service Vulnerability Sep 8, 2026

    Null pointer dereference in Windows Kerberos allows an unauthorized attacker to deny service over a network.

    Vendor
    Microsoft · Windows 11 Version 24H2
    Product scope
    Active Directory / Entra
    Weakness type
    CWE-476: NULL Pointer Dereference
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
    Published
    Sep 8, 2026
  • Microsoft Active Directory / Entra 7.8 CVE-2026-69685 Windows Kerberos Elevation of Privilege Vulnerability Sep 8, 2026

    Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.

    Vendor
    Microsoft · Windows 10 Version 1607
    Product scope
    Active Directory / Entra
    Weakness type
    CWE-122: Heap-based Buffer Overflow
    CVSS 3.1
    CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Published
    Sep 8, 2026
  • Microsoft Active Directory / Entra 8.8 CVE-2026-69676 Windows Kerberos Remote Code Execution Vulnerability Sep 8, 2026

    Critical or actively exploited: triggers an email alert

    Authentication bypass by capture-replay in Windows Kerberos allows an authorized attacker to execute code over a network.

    Vendor
    Microsoft · Windows 10 Version 1607
    Product scope
    Active Directory / Entra
    Weakness type
    CWE-294: Authentication Bypass by Capture-replay
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Published
    Sep 8, 2026
  • Microsoft Exchange Server 9.1 CVE-2026-69641 Microsoft Exchange Server Elevation of Privilege Vulnerability Sep 8, 2026

    Critical or actively exploited: triggers an email alert

    Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

    Vendor
    Microsoft · Microsoft Exchange Server
    Product scope
    Exchange Server
    Weakness type
    CWE-862: Missing Authorization
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C
    Published
    Sep 8, 2026
  • Microsoft Active Directory / Entra 6.5 CVE-2026-69624 Active Directory Certificate Services (AD CS) Tampering Vulnerability Sep 8, 2026

    Incomplete list of disallowed inputs in Active Directory Certificate Services (AD CS) allows an authorized attacker to perform tampering over a network.

    Vendor
    Microsoft · Windows 10 Version 1607
    Product scope
    Active Directory / Entra
    Weakness type
    CWE-184: Incomplete List of Disallowed Inputs
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C
    Published
    Sep 8, 2026
  • Microsoft Teams 5.8 CVE-2026-69559 Microsoft Teams for Android Information Disclosure Vulnerability Sep 8, 2026

    Origin validation error in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.

    Vendor
    Microsoft · Microsoft Teams for Android
    Product scope
    Teams
    Weakness type
    CWE-346: Origin Validation Error
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C
    Published
    Sep 8, 2026
  • Microsoft Active Directory / Entra 8.1 CVE-2026-69546 Windows Active Directory Domain Services Remote Code Execution Vulnerability Sep 8, 2026

    Critical or actively exploited: triggers an email alert

    Use after free in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.

    Vendor
    Microsoft · Windows 10 Version 1607
    Product scope
    Active Directory / Entra
    Weakness type
    CWE-416: Use After Free
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Published
    Sep 8, 2026
  • Microsoft Active Directory / Entra 8.1 CVE-2026-69524 Windows Active Directory Domain Services Remote Code Execution Vulnerability Sep 8, 2026

    Critical or actively exploited: triggers an email alert

    Use after free in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.

    Vendor
    Microsoft · Windows 10 Version 1607
    Product scope
    Active Directory / Entra
    Weakness type
    CWE-416: Use After Free
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Published
    Sep 8, 2026
  • Microsoft Active Directory / Entra 6.5 CVE-2026-69395 Active Directory Certificate Services (AD CS) Information Disclosure Vulnerability Sep 8, 2026

    Use of externally-controlled format string in Active Directory Certificate Services (AD CS) allows an authorized attacker to disclose information over a network.

    Vendor
    Microsoft · Windows 10 Version 1607
    Product scope
    Active Directory / Entra
    Weakness type
    CWE-134: Use of Externally-Controlled Format String
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
    Published
    Sep 8, 2026
  • Microsoft Exchange Server 5.9 CVE-2026-69382 Microsoft Exchange Server Information Disclosure Vulnerability Sep 8, 2026

    Use of a broken or risky cryptographic algorithm in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network.

    Vendor
    Microsoft · Microsoft Exchange Server
    Product scope
    Exchange Server
    Weakness type
    CWE-327: Use of a Broken or Risky Cryptographic Algorithm
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
    Published
    Sep 8, 2026
  • Microsoft Exchange Server 8.1 CVE-2026-69380 Microsoft Exchange Server Elevation of Privilege Vulnerability Sep 8, 2026

    Critical or actively exploited: triggers an email alert

    Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

    Vendor
    Microsoft · Microsoft Exchange Server
    Product scope
    Exchange Server
    Weakness type
    CWE-862: Missing Authorization
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C
    Published
    Sep 8, 2026
  • Microsoft Exchange Server 7.5 CVE-2026-69378 Microsoft Exchange Server Denial of Service Vulnerability Sep 8, 2026

    Uncontrolled recursion in Microsoft Exchange Server allows an unauthorized attacker to deny service over a network.

    Vendor
    Microsoft · Microsoft Exchange Server
    Product scope
    Exchange Server
    Weakness type
    CWE-674: Uncontrolled Recursion
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
    Published
    Sep 8, 2026
  • Microsoft Exchange Server 6.5 CVE-2026-69375 Microsoft Exchange Server Tampering Vulnerability Sep 8, 2026

    Authorization bypass through user-controlled key in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network.

    Vendor
    Microsoft · Microsoft Exchange Server
    Product scope
    Exchange Server
    Weakness type
    CWE-639: Authorization Bypass Through User-Controlled Key
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C
    Published
    Sep 8, 2026
  • Microsoft Exchange Server 6.5 CVE-2026-69361 Microsoft Exchange Server Spoofing Vulnerability Sep 8, 2026

    Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.

    Vendor
    Microsoft · Microsoft Exchange Server
    Product scope
    Exchange Server
    Weakness type
    CWE-918: Server-Side Request Forgery
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
    Published
    Sep 8, 2026
  • Microsoft Active Directory / Entra 7.8 CVE-2026-69359 Active Directory Domain Services Elevation of Privilege Vulnerability Sep 8, 2026

    Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to elevate privileges locally.

    Vendor
    Microsoft · Windows 10 Version 1607
    Product scope
    Active Directory / Entra
    Weakness type
    CWE-122: Heap-based Buffer Overflow
    CVSS 3.1
    CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Published
    Sep 8, 2026
  • Microsoft Exchange Server 9.3 CVE-2026-69356 Microsoft Exchange Server Spoofing Vulnerability Sep 8, 2026

    Critical or actively exploited: triggers an email alert

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

    Vendor
    Microsoft · Microsoft Exchange Server
    Product scope
    Exchange Server
    Weakness type
    CWE-79: Cross-Site Scripting
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C
    Published
    Sep 8, 2026
  • Microsoft Exchange Server 8.8 CVE-2026-69355 Microsoft Exchange Server Remote Code Execution Vulnerability Sep 8, 2026

    Critical or actively exploited: triggers an email alert

    External control of file name or path in Microsoft Exchange Server allows an authorized attacker to execute code over a network.

    Vendor
    Microsoft · Microsoft Exchange Server
    Product scope
    Exchange Server
    Weakness type
    CWE-73: External Control of File Name or Path
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Published
    Sep 8, 2026
  • Microsoft Teams 6.8 CVE-2026-65812 Microsoft Teams for Android Information Disclosure Vulnerability Sep 8, 2026

    Insertion of sensitive information into sent data in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.

    Vendor
    Microsoft · Microsoft Teams for Android
    Product scope
    Teams
    Weakness type
    CWE-201: Insertion of Sensitive Information Into Sent Data
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C
    Published
    Sep 8, 2026
  • Microsoft Active Directory / Entra 7.5 CVE-2026-62813 Windows Active Directory Domain Services Remote Code Execution Vulnerability Sep 8, 2026

    Use after free in Active Directory Domain Services allows an authorized attacker to execute code over a network.

    Vendor
    Microsoft · Windows 10 Version 1607
    Product scope
    Active Directory / Entra
    Weakness type
    CWE-416: Use After Free
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Published
    Sep 8, 2026
  • Microsoft Active Directory / Entra 7.8 CVE-2026-62810 Active Directory Certificate Services (AD CS) Elevation of Privilege Vulnerability Sep 8, 2026

    Heap-based buffer overflow in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges locally.

    Vendor
    Microsoft · Windows 10 Version 1607
    Product scope
    Active Directory / Entra
    Weakness type
    CWE-122: Heap-based Buffer Overflow
    CVSS 3.1
    CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Published
    Sep 8, 2026
  • Microsoft Active Directory / Entra 6.5 CVE-2026-62762 Windows Active Directory Domain Services Denial of Service Vulnerability Sep 8, 2026

    Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.

    Vendor
    Microsoft · Windows 10 Version 1607
    Product scope
    Active Directory / Entra
    Weakness type
    CWE-476: NULL Pointer Dereference
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
    Published
    Sep 8, 2026
  • Microsoft Exchange Server 8.1 CVE-2026-55007 Microsoft Exchange Server Remote Code Execution Vulnerability Sep 8, 2026

    Critical or actively exploited: triggers an email alert

    Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.

    Vendor
    Microsoft · Microsoft Exchange Server
    Product scope
    Exchange Server
    Weakness type
    CWE-415: Double Free
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Published
    Sep 8, 2026
  • Google Chromium V8 8.8 KEV CVE-2026-85046 Google Chrome Sep 4, 2026

    Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Vendor
    Google · Chrome
    Weakness type
    CWE-843
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
    Published
    Sep 3, 2026
    In KEV catalog since
    Sep 4, 2026
  • SEPPmail 8.6 CVE-2026-84832 Unsafe deserialization in the REST interface Sep 3, 2026

    Critical or actively exploited: triggers an email alert

    SEPPmail Secure Email Gateway before 15.0.6 deserializes attacker-controlled data in a privileged REST import workflow without adequate validation. An attacker with a privileged API token can execute arbitrary commands with "nobody" privileges.

    Vendor
    SEPPmail AG · SEPPmail Secure Email Gateway (SEG)
    Product scope
    SEPPmail
    Weakness type
    CWE-502: Deserialization of Untrusted Data
    CVSS 4.0
    CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
    Published
    Sep 3, 2026
  • SEPPmail 7.7 CVE-2026-84831 Mandatory MFA bypass before enrollment Sep 3, 2026

    SEPPmail Secure Email Gateway before 15.0.7 creates a fully privileged session before required multi-factor authentication enrollment is completed. An attacker with the password for an MFA-required but unenrolled account can access protected functionality without providing a second factor.

    Vendor
    SEPPmail AG · SEPPmail Secure Email Gateway (SEG)
    Product scope
    SEPPmail
    Weakness type
    CWE-287: Improper Authentication
    CVSS 4.0
    CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
    Published
    Sep 3, 2026
  • Microsoft Active Directory / Entra 10.0 CVE-2026-83711 Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability Sep 3, 2026

    Critical or actively exploited: triggers an email alert

    Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.

    Vendor
    Microsoft · Entra
    Product scope
    Active Directory / Entra
    Weakness type
    CWE-639: Authorization Bypass Through User-Controlled Key
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C
    Published
    Sep 3, 2026
  • Microsoft Active Directory / Entra 9.1 CVE-2026-62916 Microsoft Entra ID Elevation of Privilege Vulnerability Sep 3, 2026

    Critical or actively exploited: triggers an email alert

    Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.

    Vendor
    Microsoft · Microsoft Entra
    Product scope
    Active Directory / Entra
    Weakness type
    CWE-288: Authentication Bypass Using an Alternate Path or Channel
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C
    Published
    Sep 3, 2026
  • SonicWall SMA1000 Appliances 7.8 KEV CVE-2026-83549 SonicWall SMA1000: OS Command Injection Sep 2, 2026

    Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.

    Vendor
    SonicWall · SMA1000
    Weakness type
    CWE-78: OS Command Injection
    CVSS 3.1
    CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
    Published
    Sep 1, 2026
    In KEV catalog since
    Sep 2, 2026
  • SonicWall SMA1000 Appliances 10.0 KEV CVE-2026-83548 SonicWall SMA1000: Server-Side Request Forgery Sep 2, 2026

    A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.

    Vendor
    SonicWall · SMA1000
    Weakness type
    CWE-918: Server-Side Request Forgery
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
    Published
    Sep 1, 2026
    In KEV catalog since
    Sep 2, 2026
  • JFrog Artifactory 9.8 KEV CVE-2026-82329 Potential authentication bypass leading to administrative access in Artifactory Sep 2, 2026

    JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.

    Vendor
    jfrog · artifactory
    Weakness type
    CWE-287: Improper Authentication
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Published
    Aug 28, 2026
    In KEV catalog since
    Sep 2, 2026
  • BerriAI LiteLLM 8.8 KEV CVE-2026-59822 LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback Sep 2, 2026

    LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to use a fabricated Authorization header to trigger an OAuth2 passthrough fallback path that replaced failed LiteLLM key validation with an empty UserAPIKeyAuth() object, allowing requests to reach MCP tooling without a valid LiteLLM key. This issue is fixed in version 1.84.0.

    Vendor
    BerriAI · litellm
    Weakness type
    CWE-287: Improper Authentication
    CVSS 4.0
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
    Published
    Jul 8, 2026
    In KEV catalog since
    Sep 2, 2026
  • Kestra OSS 10.0 KEV CVE-2026-49869 Kestra: Unauthenticated Remote Code Execution via Authentication Bypass in `AuthenticationFilter` Sep 2, 2026

    Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().endsWith("/configs") to whitelist the public configuration endpoint from Basic Auth. Because the check is a suffix match rather than an exact path match, any API path whose last segment is configs bypasses authentication entirely. An unauthenticated remote attacker can exploit this to create and execute arbitrary workflows without credentials. Because Kestra ships with script execution plugins (plugin-script-shell, plugin-script-python, etc.) enabled by default, this directly results in unauthenticated Remote Code Execution as root inside the Kestra worker container. This vulnerability is fixed in 1.0.45 and 1.3.21.

    Vendor
    kestra-io · kestra
    Weakness type
    CWE-78: OS Command Injection
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
    Published
    Jun 26, 2026
    In KEV catalog since
    Sep 2, 2026
  • Kludex Starlette 6.5 KEV CVE-2026-48710 Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks Sep 2, 2026

    Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `request.url` is rebuilt from the `Host` header, a malformed header could make `request.url.path` differ from the path that was actually requested. Middleware and endpoints that apply security restrictions based on `request.url` (rather than the raw `scope` path) could therefore be bypassed. Users should upgrade to a version greater than or equal to version 1.0.1, which validates the `Host` header against the grammar of RFC 9112 §3.2 / RFC 3986 §3.2.2 when constructing `request.url` and falls back to `scope["server"]` for malformed values.

    Vendor
    Kludex · starlette
    Weakness type
    CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
    Published
    May 26, 2026
    In KEV catalog since
    Sep 2, 2026
  • Cisco Secure Email 5.9 CVE-2026-20355 Cisco Secure Email S/MIME Ciphertext Decryption Vulnerabilty Sep 2, 2026

    Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages. These vulnerabilities are due to insufficient validation of message integrity. An attacker could exploit these vulnerabilities by using a machine-in-the-middle technique to intercept and modify traffic between email gateways. A successful exploit could allow the attacker to obtain plaintext content from the encrypted communication.

    Vendor
    Cisco · Cisco Secure Email
    Product scope
    Mail-Gateways
    Weakness type
    CWE-345
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
    Published
    Sep 2, 2026
  • Cisco Secure Email 5.9 CVE-2026-20354 Cisco Secure Email S/MIME Ciphertext Decryption Vulnerabilty Sep 2, 2026

    Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages. These vulnerabilities are due to insufficient validation of message integrity. An attacker could exploit these vulnerabilities by using a machine-in-the-middle technique to intercept and modify traffic between email gateways. A successful exploit could allow the attacker to obtain plaintext content from the encrypted communication.

    Vendor
    Cisco · Cisco Secure Email
    Product scope
    Mail-Gateways
    Weakness type
    CWE-354
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
    Published
    Sep 2, 2026
  • Sangoma Switchvox 9.3 KEV CVE-2026-9586 Unauthenticated SQL Injection Leading to Remote Code Execution in Switchvox SMB Sep 2, 2026

    An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization or parameterization. An unauthenticated remote attacker can execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.

    Vendor
    Sangoma · Switchvox SMB Edition
    Weakness type
    CWE-89: SQL Injection
    CVSS 4.0
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
    Published
    Jul 17, 2026
    In KEV catalog since
    Sep 2, 2026
  • PaperCut NG/MF 9.4 KEV CVE-2026-82078 PaperCut MF/NG: Unsafe Dynamic Class Loading in Database Connector Aug 31, 2026

    An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process.

    Vendor
    PaperCut · PaperCut MF/NG
    Weakness type
    CWE-470: Use of Externally-Controlled input to select classes or code ('unsafe reflection')
    CVSS 4.0
    CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
    Published
    Aug 28, 2026
    In KEV catalog since
    Aug 31, 2026
  • PaperCut NG/MF 8.8 KEV CVE-2026-81578 PaperCut MF/NG: Authentication Bypass Aug 31, 2026

    An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations.

    Vendor
    PaperCut · PaperCut MF/NG
    Weakness type
    CWE-305: Authentication bypass by primary weakness
    CVSS 4.0
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N
    Published
    Aug 28, 2026
    In KEV catalog since
    Aug 31, 2026
  • Open-Xchange OX Dovecot 7.4 CVE-2026-73208 Open-Xchange GmbH OX Dovecot: Improper Authentication Aug 28, 2026

    An attacker that holds a token intended for a different purpose can authenticate, because when an OAuth2 token response does not contain a scope claim, the audience claim is used in its place and checked against the configured required scopes. These are different concepts, and the audience claim does not describe what a token is allowed to do. A token that grants no relevant permissions can be accepted because its intended recipient value happens to match a configured scope name, granting access that should have been denied. It also hides an identity provider misconfiguration where scopes are not being issued at all. Ensure the identity provider issues a scope claim for all tokens used with Dovecot, and that configured scope names do not match audience values. Update to non-vulnerable version. No publicly available exploits are known.

    Vendor
    Open-Xchange GmbH · OX Dovecot
    Product scope
    Postfix / Exim / Dovecot
    Weakness type
    CWE-287: Improper Authentication
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
    Published
    Aug 28, 2026
  • Open-Xchange OX Dovecot 4.3 CVE-2026-42008 Open-Xchange GmbH OX Dovecot: Improper Authentication Aug 28, 2026

    Forwarding information received from a host listed as a trusted proxy is not kept separate from Dovecot's own authentication fields, so a value sent by that host can be injected as an internal authentication field. Any host permitted to act as a trusted proxy can authenticate as any user without knowing that user's password. This affects deployments whose password database honours a field that permits authentication without a password. Deployments that do not configure trusted proxies are not affected. Restrict the list of trusted proxy networks to hosts that are fully under your control. Update to non-vulnerable version. No publicly available exploits are known.

    Vendor
    Open-Xchange GmbH · OX Dovecot
    Product scope
    Postfix / Exim / Dovecot
    Weakness type
    CWE-287: Improper Authentication
    CVSS 3.1
    CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
    Published
    Aug 28, 2026
  • Open-Xchange OX Dovecot 5.9 CVE-2026-33604 Open-Xchange GmbH OX Dovecot Aug 28, 2026

    An attacker that can get Dovecot to relay a message, for example through Sieve redirect or submission relay, can use a crafted line ending in the message body to bypass the outbound protection that prevents message content from being interpreted as SMTP commands. A downstream mail server that hasn't yet fixed the SMTP smuggling vulnerability can be tricked into treating part of the message body as new SMTP commands, allowing injection of spoofed email. This is the same vulnerability class as CVE-2023-51764 and CVE-2023-51766. Where you control the receiving mail servers, ensure they reject bare carriage returns in message data. Update to non-vulnerable version. No publicly available exploits are known.

    Vendor
    Open-Xchange GmbH · OX Dovecot
    Product scope
    Postfix / Exim / Dovecot
    Weakness type
    CWE-655
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
    Published
    Aug 28, 2026
  • JFrog Artifactory 5.3 KEV CVE-2026-66384 Authenticated users may write data outside the intended Docker cache path Aug 27, 2026

    An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.

    Vendor
    jfrog · artifactory
    Weakness type
    CWE-22: Path Traversal
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
    Published
    Aug 12, 2026
    In KEV catalog since
    Aug 27, 2026
  • Linux Kernel 7.8 KEV CVE-2026-53362 ipv6: account for fraggap on the paged allocation path Aug 27, 2026

    In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocation path In __ip6_append_data(), when the paged-allocation branch is taken (MSG_MORE / NETIF_F_SG / large fraglen), alloclen and pagedlen are computed as alloclen = fragheaderlen + transhdrlen; pagedlen = datalen - transhdrlen; datalen already includes fraggap (datalen = length + fraggap). When fraggap is non-zero, this is not the first skb and transhdrlen is zero. The fraggap bytes carried over from the previous skb are copied just past the fragment headers in the new skb's linear area. The linear area is therefore undersized by fraggap bytes while pagedlen is overstated by the same amount, and the copy writes past skb->end into the trailing skb_shared_info. An unprivileged user can trigger this via a UDPv6 socket using MSG_MORE together with MSG_SPLICE_PAGES. The bad accounting was introduced by commit 773ba4fe9104 ("ipv6: avoid partial copy for zc"). Before commit ce650a166335 ("udp6: Fix __ip6_append_data()'s handling of MSG_SPLICE_PAGES"), the negative copy value caused -EINVAL to be returned. That later commit allowed MSG_SPLICE_PAGES to proceed in this case, making the corruption triggerable. The non-paged branch sets alloclen to fraglen, which already accounts for fraggap because datalen does. Bring the paged branch in line by adding fraggap to alloclen and subtracting it from pagedlen. After this adjustment, copy no longer collapses to -fraggap on the paged path, so remove the stale comment describing that old arithmetic. Since a negative copy is no longer expected for a valid MSG_SPLICE_PAGES case, remove the MSG_SPLICE_PAGES exception from the negative copy check.

    Vendor
    Linux · Linux
    Weakness type
    CWE-122: Heap-based Buffer Overflow
    CVSS 3.1
    CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
    Published
    Jul 4, 2026
    In KEV catalog since
    Aug 27, 2026
  • ownCloud 9.8 KEV CVE-2023-49105 Improper Authentication Aug 27, 2026

    An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs because pre-signed URLs can be accepted even when no signing-key is configured for the owner of the files. The earliest affected version is 10.6.0.

    Weakness type
    CWE-287: Improper Authentication
    CVSS 3.1
    CVSS:3.1/AC:L/AV:N/A:H/C:H/I:H/PR:N/S:U/UI:N
    Published
    Nov 21, 2023
    In KEV catalog since
    Aug 27, 2026
  • Gitea 9.8 KEV CVE-2026-60004 Gitea: Code Injection Aug 26, 2026

    Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

    Vendor
    Gitea · Gitea
    Weakness type
    CWE-94: Code Injection
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Published
    Aug 26, 2026
    In KEV catalog since
    Aug 25, 2026
  • Citrix NetScaler ADC and NetScaler Gateway 8.8 KEV CVE-2026-8452 Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service Aug 26, 2026

    Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server

    Vendor
    NetScaler · ADC
    Weakness type
    CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
    CVSS 4.0
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:H/SC:L/SI:L/SA:L
    Published
    Jun 30, 2026
    In KEV catalog since
    Aug 26, 2026
  • Linux Kernel 7.8 KEV CVE-2022-0995 n/a kernel: Out-of-bounds Write Aug 26, 2026

    An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged access or cause a denial of service on the system.

    Vendor
    n/a · kernel
    Weakness type
    CWE-787: Out-of-bounds Write
    CVSS 3.1
    CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
    Published
    Mar 25, 2022
    In KEV catalog since
    Aug 26, 2026
  • Ajax.NET Professional 8.1 KEV CVE-2021-23758 Deserialization of Untrusted Data Aug 26, 2026

    All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.

    Vendor
    n/a · AjaxPro.2
    Weakness type
    CWE-502: Deserialization of Untrusted Data
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
    Published
    Dec 3, 2021
    In KEV catalog since
    Aug 26, 2026
  • Microsoft SQL Server 8.8 KEV CVE-2019-1068 Microsoft SQL Server: Improper Input Validation Aug 26, 2026

    A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'.

    Vendor
    Microsoft · Microsoft SQL Server
    Weakness type
    CWE-20: Improper Input Validation
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
    Published
    Jul 15, 2019
    In KEV catalog since
    Aug 26, 2026
  • Red Hat Automatic Bug Reporting Tool 7.8 KEV CVE-2015-5287 Improper Link Resolution Before File Access ('Link Following') Aug 26, 2026

    The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name, as demonstrated by /var/tmp/abrt/abrt-hax-coredump or /var/spool/abrt/abrt-hax-coredump.

    Weakness type
    CWE-59: Improper Link Resolution Before File Access ('Link Following')
    CVSS 3.1
    CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
    Published
    Dec 7, 2015
    In KEV catalog since
    Aug 26, 2026
  • Red Hat Libuser 7.4 KEV CVE-2015-3246 Time-of-check Time-of-use (TOCTOU) Race Condition Aug 26, 2026

    libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error during the modification. NOTE: this issue can be combined with CVE-2015-3245 to gain privileges.

    Weakness type
    CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition
    CVSS 3.1
    CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
    Published
    Aug 11, 2015
    In KEV catalog since
    Aug 26, 2026
  • OpenSSL 7.5 CVE-2026-63076 Invalid Pointer Dereference in CMP Server via Crafted protectionAlg Aug 25, 2026

    Issue summary: OpenSSL CMP password based protection verification only checks whether the protectionAlg parameter was not NULL and not its ASN.1 type, before treating it as a PBMParameter. A crafted message can contain a parameter of a different type, which is then dereferenced as an invalid pointer. Impact summary: A remote, unauthenticated attacker can crash an application acting as a CMP server that accepts PBM-protected messages, or a CMP client talking to a malicious or intercepted CMP server, resulting in a Denial of Service. CWE: CWE-476: NULL Pointer Dereference Description: When verifying the password-based MAC protection of a CMP message, OpenSSL library reads the protectionAlg algorithm parameter with X509_ALGOR_get0(), which returns both the parameter type and its value pointer. The value is then cast to an ASN1_STRING and treated as the expected PBMParameter after only checking that pointer is not NULL. The parameter type returned by X509_ALGOR_get0() was never consulted. This happens during protection verification, before any MAC is computed, so no knowledge of the PBM shared secret is required; the only precondition is that PBM verification is reachable. On the server side this is reached from OSSL_CMP_SRV_process_request() for any application that stands up a CMP server accepting PBM-protected messages, and on the client side from CMP response validation against a malicious or on-path (MITM) server. The reliable consequence is a denial of service; there is no memory disclosure, no controlled memory write, and no path to code execution. CMP is a specialized feature that an application must explicitly enable. FIPS impact: no As the CMP code lives outside the FIPS module boundary, no FIPS modules are affected by this CVE.

    Vendor
    OpenSSL · OpenSSL
    Product scope
    OpenSSL / OpenSSH
    Weakness type
    CWE-476: NULL Pointer Dereference
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
    Published
    Aug 25, 2026
  • OpenSSL 7.5 CVE-2026-63075 QUIC ACK-only Packet Retention Can Cause Memory Exhaustion Aug 25, 2026

    Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly sends ack-eliciting packets while not acknowledging ACK-only responses, the QUIC stack can retain ACK-only packet metadata for the lifetime of the connection. Impact summary: A remote peer that can complete a QUIC handshake can cause connection-scoped memory growth which may lead to Denial of Service through memory exhaustion, especially with sustained traffic or many concurrent QUIC connections. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: When the OpenSSL QUIC stack sends an ACK-only packet, there is no requirement by the QUIC protocol that the peer will acknowledge that ACK-only packet (i.e. it is itself not ack-eliciting). However, the OpenSSL implementation stores the metadata about the ACK frames regardless. In and of itself that's ok, but if a malicious peer establishes a connection, and then drives the connection such that ACK-only packets are forced from the OpenSSL implementation peer (i.e., by sending numerous PING frames), and then withholding any subsequent acks for ack-eliciting data, like legitimate data, said malicious peer can force inappropriate memory growth on the OpenSSL peer, potentially leading to a Denial of Service. The fix is to ensure that we account for the transmission of the ACK-only packet in the packet histories high and low watermark without actually storing the ACK-only packet metadata itself. FIPS impact: no The OpenSSL FIPS module is not affected as the QUIC code is outside the FIPS module boundary.

    Vendor
    OpenSSL · OpenSSL
    Product scope
    OpenSSL / OpenSSH
    Weakness type
    CWE-770: Allocation of Resources Without Limits or Throttling
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
    Published
    Aug 25, 2026
  • OpenSSL 5.9 CVE-2026-63074 CMP Indefinite Cache Growth of ExtraCerts Aug 25, 2026

    Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches additional certificates (extraCerts) sent in a CMP message, but never expunges them (for instance if they are invalid). If a server reuses an OSSL_CMP_CTX frequently, this cache of extraCerts may grow unboundedly, and a malicious client may flood a CMP server with requests driving this growth. Impact summary: Users utilizing a CMP server that reuses a single OSSL_CMP_CTX for the lifetime of a server process may observe unbounded memory growth in the event a malicious client repeatedly sends requests containing unique extra certificates, which may lead to OOM conditions. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: If a remote user sends CMP messages to a server with a list of extraCerts and the message is rejected, the extraCerts from the message remains in the server contexts untrusted certificate stack. This exposes servers with long lived ctx objects to Denial of Service attacks in which an attacker sends messages intending to be rejected with a large list of additional certificates repeatedly, forcing the server to store them indefinitely. The issue was fixed by removing the added extra certs if the message is rejected, using the same method as when the context is configured to not do caching at all. FIPS impact: no As the CMP code lives outside the FIPS module boundary, no FIPS modules are affected by this CVE.

    Vendor
    OpenSSL · OpenSSL
    Product scope
    OpenSSL / OpenSSH
    Weakness type
    CWE-770: Allocation of Resources Without Limits or Throttling
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
    Published
    Aug 25, 2026
  • OpenSSL 9.8 CVE-2026-63073 Untrusted Sender DN Used as Format String in CMP Response Validation Aug 25, 2026

    Critical or actively exploited: triggers an email alert

    Issue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished name directly as the format string to `ERR_raise_data()`. Impact summary: A malicious or intercepted CMP endpoint can crash a CMP client that enforces an expected sender or uses a pinned server certificate whose subject becomes the default expected sender. CWE: CWE-134 (Use of Externally-Controlled Format String) Description: When validating a received CMP message, ossl_cmp_msg_check_update() converts the peer-supplied sender distinguished name with X509_NAME_oneline() and passes it directly as the format argument to ERR_raise_data(). Percent characters survive the conversion, so a sender DN such as "CN=%s%n" reaches BIO_vsnprintf() as an attacker-controlled format string with no matching variadic arguments. This path is only reached when the caller configures an expected sender or pins a server certificate, which is the normal configuration for a CMP client validating server responses. Since the attacker controls the format string but none of the variadic arguments, such specifiers as %s and %n dereference or write through unrelated stack contents and crash the client. The reliable consequence is a denial of service, when the response comes from a malicious or intercepted CMP endpoint. There is no controlled memory write, arbitrary-address read, or reliable path to remote code execution. FIPS impact: no No FIPS modules are affected by this issue, as the CMP protocol implementation is outside the OpenSSL FIPS module boundary.

    Vendor
    OpenSSL · OpenSSL
    Product scope
    OpenSSL / OpenSSH
    Weakness type
    CWE-134
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Published
    Aug 25, 2026
  • OpenSSL 7.5 CVE-2026-63072 Heap Buffer Overflow in CMS Key Unwrapping Aug 25, 2026

    Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive can write and cleanse more bytes than that query reports, causing an 8-byte out-of-bounds heap write. Impact summary: An attacker who supplies a crafted CMS message can trigger a deterministic 8-byte out-of-bounds heap write when the victim decrypts it with CMS_decrypt(), corrupting the heap and typically resulting in a Denial of Service. CWE: CWE-787: Out-of-bounds Write Description: The key-wrap OID is potentially attacker-controlled on the wire. CMS unwrapping allows both id-aesNNN-wrap-pad and id-aesNNN-wrap ciphers. An attacker can take a legitimate message and change a single OID byte to select the padded variant while leaving the message otherwise valid. Since the unwrap key is derived from the recipient's private operation (ECDH key agreement or ML-KEM decapsulation), the RFC 5649 integrity check cannot pass, and the decryption fails with integrity failure. The write is a fixed-size (8-byte), fixed-value (zero) heap overflow immediately past the allocation, requires no special configuration, and is reachable from the public CMS_decrypt() function. The consequence is a heap corruption leading to a Denial of Service. The fix in the CMS code sizes the unwrap output buffer for the worst case so a failed unwrap cannot write past the allocation. FIPS impact: no As the CMS code lives outside the FIPS module boundary, no FIPS modules are affected by this CVE.

    Vendor
    OpenSSL · OpenSSL
    Product scope
    OpenSSL / OpenSSH
    Weakness type
    CWE-787: Out-of-bounds Write
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
    Published
    Aug 25, 2026
  • OpenSSL 7.5 CVE-2026-54874 Excessive Memory Use Buffering DTLS Records for a Future Epoch Aug 25, 2026

    Issue summary: Receiving a DTLS record for a future epoch while a handshake is in progress causes OpenSSL to buffer far more memory than the record itself requires. Impact summary: A peer can use a small amount of network traffic to make an OpenSSL DTLS endpoint retain a disproportionately large amount of memory, which may lead to a Denial of Service. CWE: CWE-405: Asymmetric Resource Consumption (Amplification) Description: While a DTLS handshake is in progress, a peer may legitimately have already moved on to the next epoch (for example, having sent its ChangeCipherSpec and Finished messages) before the local endpoint has processed the same transition, typically because of reordering on the underlying UDP transport. OpenSSL buffers such early records so that they can be processed once the local endpoint catches up. Buffering a record currently retains the entire read buffer it arrived in, which is sized to hold the largest possible DTLS record (around 16 kilobytes), rather than just the bytes that make up the record itself. Up to 100 such records may be buffered per connection. As a result, a peer that sends a stream of small forged records claiming to belong to the next epoch can cause an OpenSSL DTLS endpoint to retain around 1.7 megabytes of memory, despite sending only a small fraction of that amount of data over the network. An attacker therefore gains a memory amplification factor of around 1200, and can multiply the effect across as many associations as it is able to open, making this a remote memory exhaustion Denial of Service risk for DTLS servers. Since the memory retained per connection remains bounded, and any limit an application already places on the number of concurrent associations also bounds the total exposure, this issue has been assessed as Low severity. FIPS impact: no No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary. OpenSSL 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue. OpenSSL 4.0 users should upgrade to OpenSSL 4.0.2. OpenSSL 3.6 users should upgrade to OpenSSL 3.6.4. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.8. OpenSSL 3.4 users should upgrade to OpenSSL 3.4.7. OpenSSL 3.0 users should upgrade to OpenSSL 3.0.22. Premium support customers only: OpenSSL 1.1.1 users should upgrade to OpenSSL 1.1.1zi OpenSSL 1.0.2 users should upgrade to OpenSSL 1.0.2zr This issue was reported on 18 May 2026 by Amazon Web Services. The fix has been developed by Matt Caswell. -- cut (non-publishing metadata for internal use) -- Reported by: Amazon Web Services Fixed by: Matt Caswell

    Vendor
    OpenSSL · OpenSSL
    Product scope
    OpenSSL / OpenSSH
    Weakness type
    CWE-405: Asymmetric Resource Consumption (Amplification)
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
    Published
    Aug 25, 2026
  • OpenSSL 7.5 CVE-2026-18798 QUIC Server May Trigger Double Free When Processing INITIAL Packet Aug 25, 2026

    Issue summary: QUIC server may double free QRX (QUIC record layer RX) object when channel creation fails for initial packet. Impact summary: Double free leads to heap corruption, which typically results in termination of QUIC server process, leading to Denial of Service. There is so far no evidence that this double free is exploitable for remote code execution, thus it is considered highly improbable. CWE: CWE-415: Double Free Description: In order to validate initial packet, OpenSSL QUIC stack default packet handler (port_default_packet_handler()) creates a so-called QRX object. If the initial packet validates successfully with QRX object, the default packet handler proceeds to channel (connection object) creation. The QRX object used for packet validation is passed to port_bind_channel(), so it becomes part of the newly created connection. If port_bind_channel() fails, then it also frees the QRX object. Once port_bind_channel() returns, the port_default_packet_handler() detects the failure and proceeds to the error branch, where the same QRX object is freed for the second time. The failure in port_bind_channel() function can be induced with a relatively low effort by a malformed (non RFC 9000 compliant) INITIAL packet. If the packet carries DCID (destination connection ID) which is shorter than 8 bytes, then port_bind_channel() jumps to the error path after ossl_quic_lcidm_enrol_odcid() detects that the DCID has invalid length. FIPS impact: no The FIPS module is not affected, as the QUIC implementation is outside of the OpenSSL FIPS module boundary.

    Vendor
    OpenSSL · OpenSSL
    Product scope
    OpenSSL / OpenSSH
    Weakness type
    CWE-415: Double Free
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
    Published
    Aug 25, 2026
  • OpenSSL 7.5 CVE-2026-14457 RPK Server Signature Algorithm Selection Can Dereference a Missing Certificate Aug 25, 2026

    Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs) enabled, and only the private key (with no associated certificate) configured locally, a NULL pointer dereference may occur when the remote peer solicits raw public keys and also sends the typically omitted "signature_algorithms_cert" TLS extension. Impact summary: The impact is limited to a possible Denial of Service as a result of an application abort, no data disclosure or remote command execution are possible. CWE: CWE-476: NULL Pointer Dereference Description: While a passing comment in sample code in the documentation suggests that key-only RPK configurations are supported, the best-practice RPK configuration is to always configure a corresponding certificate (possibly self-signed or signed by any convenient CA). When the private key is configured along with a matching certificate, the "signature_algorithms_cert" extension is handled reliably even without the fix, and peer clients or servers that don't support raw public keys may be able to complete a TLS connection by pinning or verifying the corresponding certificate or its public key. Deployments that prefer to configure just a private key with no certificate need to upgrade to an updated release as noted below. FIPS impact: no No FIPS modules are affected by this issue, as the SSL protocol implementation is outside the OpenSSL FIPS module boundary.

    Vendor
    OpenSSL · OpenSSL
    Product scope
    OpenSSL / OpenSSH
    Weakness type
    CWE-476: NULL Pointer Dereference
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
    Published
    Aug 25, 2026
  • Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in 10.0 KEV CVE-2026-21962 Oracle Corporation Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in: Improper Access Control Aug 24, 2026

    Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in. While the vulnerability is in Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data. Note: Affected version for Weblogic Server Proxy Plug-in for IIS is 12.2.1.4.0 only. CVSS 3.1 Base Score 10.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).

    Vendor
    Oracle Corporation · Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in
    Weakness type
    CWE-284: Improper Access Control
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
    Published
    Jan 20, 2026
    In KEV catalog since
    Aug 24, 2026
  • Synacor Zimbra Collaboration Suite (ZCS) 8.9 KEV CVE-2026-73570 Zimbra Collaboration: OS Command Injection Aug 21, 2026

    Critical or actively exploited: triggers an email alert

    A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.

    Vendor
    Zimbra · Collaboration
    Product scope
    Webmail
    Weakness type
    CWE-78: OS Command Injection
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L
    Published
    Aug 13, 2026
    In KEV catalog since
    Aug 21, 2026
  • TrueConf Server 9.5 KEV CVE-2026-72530 TrueConf Server: Code Injection Aug 20, 2026

    A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.

    Vendor
    TrueConf · TrueConf Server
    Weakness type
    CWE-94: Code Injection
    CVSS 4.0
    CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
    Published
    Aug 19, 2026
    In KEV catalog since
    Aug 20, 2026
  • TrueConf Server 9.3 KEV CVE-2026-72529 TrueConf Server: Missing Authentication Aug 20, 2026

    A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.

    Vendor
    TrueConf · TrueConf Server
    Weakness type
    CWE-306: Missing Authentication
    CVSS 4.0
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
    Published
    Aug 19, 2026
    In KEV catalog since
    Aug 20, 2026
  • Microsoft Active Directory / Entra 9.9 CVE-2026-69851 Microsoft Entra ID Elevation of Privilege Vulnerability Aug 20, 2026

    Critical or actively exploited: triggers an email alert

    Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.

    Vendor
    Microsoft · Microsoft Entra
    Product scope
    Active Directory / Entra
    Weakness type
    CWE-918: Server-Side Request Forgery
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C
    Published
    Aug 20, 2026
  • Microsoft Active Directory / Entra 10.0 CVE-2026-69836 Microsoft Entra ID Remote Code Execution Vulnerability Aug 20, 2026

    Critical or actively exploited: triggers an email alert

    Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.

    Vendor
    Microsoft · Microsoft Entra
    Product scope
    Active Directory / Entra
    Weakness type
    CWE-502: Deserialization of Untrusted Data
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C
    Published
    Aug 20, 2026
  • MLflow 9.3 KEV CVE-2026-64849 MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding) Aug 19, 2026

    MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Starting in 3.3.0 and prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in mlflow/utils/validation.py only for the original URL while mlflow/webhooks/delivery.py follows redirects and re-resolves the hostname without pinning the validated address, allowing attackers to reach internal or cloud metadata services and receive response_status and response_body. This issue is fixed in version 3.15.0.

    Vendor
    mlflow · mlflow
    Weakness type
    CWE-918: Server-Side Request Forgery
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
    Published
    Aug 17, 2026
    In KEV catalog since
    Aug 19, 2026
  • Apple macOS 9.8 KEV CVE-2026-65400 Apple macOS: Improper Authentication Aug 18, 2026

    An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1, macOS Tahoe 26.7. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.

    Vendor
    Apple · macOS
    Weakness type
    CWE-287: Improper Authentication
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Published
    Aug 6, 2026
    In KEV catalog since
    Aug 18, 2026
  • Broadcom VMware vCenter 9.8 KEV CVE-2026-59310 vCenter directory-traversal vulnerability Aug 18, 2026

    VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

    Vendor
    VMware · Cloud Foundation
    Weakness type
    CWE-22: Path Traversal
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Published
    Jul 30, 2026
    In KEV catalog since
    Aug 18, 2026 · Used in ransomware campaigns
  • Microsoft SharePoint 9.1 KEV CVE-2026-55040 Microsoft SharePoint Server Security Feature Bypass Vulnerability Aug 18, 2026

    Critical or actively exploited: triggers an email alert

    Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.

    Vendor
    Microsoft · Microsoft SharePoint
    Product scope
    SharePoint
    Weakness type
    CWE-1390: Weak Authentication
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C
    Published
    Jul 14, 2026
    In KEV catalog since
    Aug 18, 2026
  • Microsoft Internet Key Exchange (IKE) Service Extensions 9.8 KEV CVE-2026-33824 Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability Aug 18, 2026

    Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.

    Vendor
    Microsoft · Windows 10 Version 1607
    Weakness type
    CWE-415: Double Free
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Published
    Apr 14, 2026
    In KEV catalog since
    Aug 18, 2026
  • Roundcube Webmail 6.4 CVE-2026-75010 Roundcube Webmail: Incorrect Resource Transfer Between Spheres Aug 17, 2026

    In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modoboa API authentication token to a user-controlled host via crafted session data. This issue only affects Roundcube instances using the password plugin with its modoboa driver.

    Vendor
    Roundcube · Webmail
    Product scope
    Webmail
    Weakness type
    CWE-669: Incorrect Resource Transfer Between Spheres
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
    Published
    Aug 17, 2026
  • Roundcube Webmail 5.4 CVE-2026-75007 Roundcube Webmail: Command Injection Aug 17, 2026

    In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the LDAP search filter was subject to injection via unescaped %u/%fu/%d substitution, which may lead to information disclosure or privilege escalation.

    Vendor
    Roundcube · Webmail
    Product scope
    Webmail
    Weakness type
    CWE-77: Command Injection
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
    Published
    Aug 17, 2026
  • Roundcube Webmail 5.8 CVE-2026-75006 Roundcube Webmail: Server-Side Request Forgery Aug 17, 2026

    In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. This issue exists because of insufficient fixes for CVE-2026-35540, CVE-2026-48843 and CVE-2026-62643.

    Vendor
    Roundcube · Webmail
    Product scope
    Webmail
    Weakness type
    CWE-918: Server-Side Request Forgery
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
    Published
    Aug 17, 2026
  • Roundcube Webmail 4.3 CVE-2026-75004 Roundcube Webmail: Command Injection Aug 17, 2026

    In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper rule name quoting could lead to managesieve_disabled_actions setting bypass via a crafted rule name in a Sieve script. This issue only affects Roundcube instances using the managesieve plugin.

    Vendor
    Roundcube · Webmail
    Product scope
    Webmail
    Weakness type
    CWE-77: Command Injection
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
    Published
    Aug 17, 2026
  • Roundcube Webmail 5.8 CVE-2026-75003 Roundcube Webmail: Incorrect Resource Transfer Between Spheres Aug 17, 2026

    In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote image blocking, which may lead to information disclosure or privilege escalation.

    Vendor
    Roundcube · Webmail
    Product scope
    Webmail
    Weakness type
    CWE-669: Incorrect Resource Transfer Between Spheres
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
    Published
    Aug 17, 2026
  • Roundcube Webmail 7.1 CVE-2026-75002 Roundcube Webmail: Command Injection Aug 17, 2026

    In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-count desynchronization could lead to information disclosure or privilege escalation via IMAP command injection.

    Vendor
    Roundcube · Webmail
    Product scope
    Webmail
    Weakness type
    CWE-77: Command Injection
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L
    Published
    Aug 17, 2026
  • Roundcube Webmail 5.8 CVE-2026-75000 Roundcube Webmail: Incorrect Resource Transfer Between Spheres Aug 17, 2026

    In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG animate "by" attribute may lead to remote image blocking bypass, which in turn may lead to information disclosure or privilege escalation.

    Vendor
    Roundcube · Webmail
    Product scope
    Webmail
    Weakness type
    CWE-669: Incorrect Resource Transfer Between Spheres
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
    Published
    Aug 17, 2026
  • Roundcube Webmail 5.4 CVE-2026-74999 Roundcube Webmail: Cross-Site Scripting Aug 17, 2026

    In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subject to stored XSS.

    Vendor
    Roundcube · Webmail
    Product scope
    Webmail
    Weakness type
    CWE-79: Cross-Site Scripting
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
    Published
    Aug 17, 2026
  • Roundcube Webmail 7.2 CVE-2026-74998 Roundcube Webmail: Cross-Site Scripting Aug 17, 2026

    In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were not validated, which may result in information disclosure or XSS (cross-site scripting) via MIME sniffing.

    Vendor
    Roundcube · Webmail
    Product scope
    Webmail
    Weakness type
    CWE-79: Cross-Site Scripting
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
    Published
    Aug 17, 2026
  • Roundcube Webmail 8.8 CVE-2026-74997 Roundcube Webmail: OS Command Injection Aug 17, 2026

    Critical or actively exploited: triggers an email alert

    In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to remote code execution via crafted placeholder replacement values. This issue only affects Roundcube instances using the markasjunk plugin with its cmd_learn driver.

    Vendor
    Roundcube · Webmail
    Product scope
    Webmail
    Weakness type
    CWE-78: OS Command Injection
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
    Published
    Aug 17, 2026
  • Ray-Project Ray 9.4 KEV CVE-2025-62593 Ray is vulnerable to RCE via Safari & Firefox Browsers through DNS Rebinding Attack Aug 17, 2026

    Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerability exploitable via Firefox and Safari. This vulnerability is due to an insufficient guard against browser-based attacks, as the current defense uses the User-Agent header starting with the string "Mozilla" as a defense mechanism. This defense is insufficient as the fetch specification allows the User-Agent header to be modified. Combined with a DNS rebinding attack against the browser, and this vulnerability is exploitable against a developer running Ray who inadvertently visits a malicious website, or is served a malicious advertisement (malvertising). This issue has been patched in version 2.52.0.

    Vendor
    ray-project · ray
    Weakness type
    CWE-94: Code Injection
    CVSS 4.0
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
    Published
    Nov 26, 2025
    In KEV catalog since
    Aug 17, 2026
  • Zimbra Collaboration 6.3 CVE-2026-73576 Zimbra Collaboration: Use of Predictable Algorithm in Random Number Generator Aug 13, 2026

    In Zimbra Collaboration (ZCS) before 10.1.17, weak cryptographic key generation vulnerability exists in the OnlyOffice integration. The zimbraDocumentEditingJwtSecret is generated using an insecure random number generator, resulting in insufficient entropy. An attacker who obtains a JWT signed with the generated secret may be able to recover the JWT signing secret through offline brute-force, potentially enabling JWT forgery.

    Vendor
    Zimbra · Collaboration
    Product scope
    Webmail
    Weakness type
    CWE-1241: Use of Predictable Algorithm in Random Number Generator
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:N
    Published
    Aug 13, 2026
  • Zimbra Collaboration 3.1 CVE-2026-73575 Zimbra Collaboration: Cross-Site Request Forgery Aug 13, 2026

    In Zimbra Collaboration (ZCS) before 10.1.17, a Cross-Site Request Forgery (CSRF) vulnerability exists in the Exchange Web Services (EWS) endpoint of Zimbra Collaboration (ZCS) due to insufficient validation of request content types. An attacker can exploit this vulnerability by causing an authenticated user to submit a crafted request, potentially allowing unauthorized actions to be performed on behalf of the victim.

    Vendor
    Zimbra · Collaboration
    Product scope
    Webmail
    Weakness type
    CWE-352: Cross-Site Request Forgery
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
    Published
    Aug 13, 2026
  • Zimbra Collaboration 3.1 CVE-2026-73574 Zimbra Collaboration: Incorrect Resource Transfer Between Spheres Aug 13, 2026

    In Zimbra Collaboration before 10.1.17, a local file inclusion (LFI) vulnerability exists in the Zimbra Classic Web Client due to improper validation of the fu request parameter. An unauthenticated attacker can exploit this vulnerability by supplying a crafted path, potentially allowing unauthorized disclosure of protected files, such as WEB-INF/web.xml, within the web application directory. This occurs in the Forward servlet.

    Vendor
    Zimbra · Collaboration
    Product scope
    Webmail
    Weakness type
    CWE-669: Incorrect Resource Transfer Between Spheres
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
    Published
    Aug 13, 2026
  • Zimbra Collaboration 3.1 CVE-2026-73573 Zimbra Collaboration: Path Traversal: '../filedir' Aug 13, 2026

    In Zimbra Collaboration (ZCS) before 10.1.17, a path traversal vulnerability exists in the Zimbra Briefcase document editing functionality due to improper validation of the packages parameter. An authenticated attacker can exploit this vulnerability by supplying a crafted path traversal sequence, potentially allowing unauthorized disclosure of sensitive files within the web application directory.

    Vendor
    Zimbra · Collaboration
    Product scope
    Webmail
    Weakness type
    CWE-24: Path Traversal: '../filedir'
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
    Published
    Aug 13, 2026
  • Zimbra Collaboration 6.1 CVE-2026-73572 Zimbra Collaboration: Cross-Site Scripting Aug 13, 2026

    In Zimbra Collaboration (ZCS) before 10.1.17, a stored cross-site scripting (XSS) vulnerability exists in the Zimbra Classic Web Client due to insufficient sanitization of specific attachment content during inline preview. An attacker can send a crafted email containing a malicious attachment that, when previewed by a user, executes arbitrary JavaScript within the victim's browser session. Successful exploitation may allow an attacker to perform unauthorized actions on behalf of the victim user, potentially leading to data exfiltration or unauthorized access to sensitive information.

    Vendor
    Zimbra · Collaboration
    Product scope
    Webmail
    Weakness type
    CWE-79: Cross-Site Scripting
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
    Published
    Aug 13, 2026
  • Zimbra Collaboration 3.1 CVE-2026-73571 Zimbra Collaboration: Incorrect Authorization Aug 13, 2026

    An authorization bypass vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.17 due to improper authorization validation in delegated email sending functionality. An authenticated attacker can send specially crafted SOAP requests to impersonate another user and send emails without possessing the required delegation or send-as permissions. This occurs in the SaveDraftRequest SOAP handler.

    Vendor
    Zimbra · Collaboration
    Product scope
    Webmail
    Weakness type
    CWE-863: Incorrect Authorization
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
    Published
    Aug 13, 2026
  • OpenSSL 7.5 CVE-2026-14456 Unbounded Memory Growth in QUIC Server Incoming Channel Queue Aug 13, 2026

    Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit. Impact summary: A remote peer that can make many Initial packets reach the server listener faster than the application accepts connections, can cause the memory allocated to store the per-channel state to grow without any limits, potentially making the QUIC listener unavailable and causing Denial of Service. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: The function that handles inbound QUIC packets uses Connection-Id from the packet header to find an existing connection (QUIC channel). If no existing connection is found and the packet type is INITIAL, the function treats the packet as a new connection. It allocates a new channel object and inserts it into a queue where it waits to be accepted by the local application with SSL_accept(3ossl). The memory occupied by these initial channel objects may grow without bounds if the application is not able to call SSL_accept() frequently enough to serve these inbound connection requests. The issue is present since OpenSSL 3.5 when the QUIC server implementation was added. The fix introduces a limit for pending connections. The default limit is set to 256 pending connections (waiting to be accepted by the local application). Applications may change the default by calling SSL_set_value_uint(3ossl). FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary.

    Vendor
    OpenSSL · OpenSSL
    Product scope
    OpenSSL / OpenSSH
    Weakness type
    CWE-770: Allocation of Resources Without Limits or Throttling
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
    Published
    Aug 13, 2026
  • OpenBSD OpenSSH 2.5 CVE-2026-73283 OpenBSD OpenSSH: Always-Incorrect Control Flow Implementation Aug 11, 2026

    In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.

    Vendor
    OpenBSD · OpenSSH
    Product scope
    OpenSSL / OpenSSH
    Weakness type
    CWE-670: Always-Incorrect Control Flow Implementation
    CVSS 3.1
    CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
    Published
    Aug 11, 2026
  • OpenBSD OpenSSH 4.8 CVE-2026-73282 OpenBSD OpenSSH: Use After Free Aug 11, 2026

    In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.

    Vendor
    OpenBSD · OpenSSH
    Product scope
    OpenSSL / OpenSSH
    Weakness type
    CWE-416: Use After Free
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
    Published
    Aug 11, 2026
  • OpenBSD OpenSSH 3.5 CVE-2026-73281 OpenBSD OpenSSH: Incorrect Resource Transfer Between Spheres Aug 11, 2026

    In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.

    Vendor
    OpenBSD · OpenSSH
    Product scope
    OpenSSL / OpenSSH
    Weakness type
    CWE-669: Incorrect Resource Transfer Between Spheres
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N
    Published
    Aug 11, 2026
  • Metabase 10.0 KEV CVE-2026-72898 Metabase SQL injection via password reset endpoint Aug 11, 2026

    Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.

    Vendor
    Metabase · Metabase
    Weakness type
    CWE-89: SQL Injection
    CVSS 4.0
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
    Published
    Aug 10, 2026
    In KEV catalog since
    Aug 11, 2026
  • Microsoft Windows Ancillary Function Driver for WinSock 7.0 KEV CVE-2026-68820 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability Aug 11, 2026

    Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

    Vendor
    Microsoft · Windows 10 Version 1607
    Weakness type
    CWE-416: Use After Free
    CVSS 3.1
    CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Published
    Aug 11, 2026
    In KEV catalog since
    Aug 11, 2026
  • Microsoft Exchange Server 6.5 CVE-2026-65813 Microsoft Exchange Server Elevation of Privilege Vulnerability Aug 11, 2026

    Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

    Vendor
    Microsoft · Microsoft Exchange Server
    Product scope
    Exchange Server
    Weakness type
    CWE-918: Server-Side Request Forgery
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
    Published
    Aug 11, 2026
  • Microsoft Active Directory / Entra 5.3 CVE-2026-65777 Active Directory Security Feature Bypass Vulnerability Aug 11, 2026

    Inadequate encryption strength in Windows Active Directory allows an authorized attacker to bypass a security feature over a network.

    Vendor
    Microsoft · Windows 11 version 23H2
    Product scope
    Active Directory / Entra
    Weakness type
    CWE-326: Inadequate Encryption Strength
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C
    Published
    Aug 11, 2026
  • Microsoft Teams 6.5 CVE-2026-65769 Microsoft Teams iOS Information Disclosure Vulnerability Aug 11, 2026

    Exposure of sensitive information to an unauthorized actor in Microsoft Teams Mobile allows an unauthorized attacker to disclose information over a network.

    Vendor
    Microsoft · Microsoft Teams for iOS
    Product scope
    Teams
    Weakness type
    CWE-200: Information Disclosure
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
    Published
    Aug 11, 2026
  • Microsoft Teams 8.8 CVE-2026-65768 Microsoft Teams Remote Code Execution Vulnerability Aug 11, 2026

    Critical or actively exploited: triggers an email alert

    Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network.

    Vendor
    Microsoft · Microsoft Teams for Android
    Product scope
    Teams
    Weakness type
    CWE-22: Path Traversal
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Published
    Aug 11, 2026
  • Microsoft Teams 8.8 CVE-2026-65767 Microsoft Teams for Android Spoofing Vulnerability Aug 11, 2026

    Critical or actively exploited: triggers an email alert

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized attacker to perform spoofing over a network.

    Vendor
    Microsoft · Microsoft Teams for Android
    Product scope
    Teams
    Weakness type
    CWE-79: Cross-Site Scripting
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Published
    Aug 11, 2026
  • Microsoft Active Directory / Entra 7.8 CVE-2026-65673 Microsoft Entra Connect Elevation of Privilege Vulnerability Aug 11, 2026

    Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Entra Connect Sync allows an authorized attacker to elevate privileges locally.

    Vendor
    Microsoft · Microsoft Entra Connect
    Product scope
    Active Directory / Entra
    Weakness type
    CWE-89: SQL Injection
    CVSS 3.1
    CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Published
    Aug 11, 2026
  • Microsoft Exchange Server 6.5 CVE-2026-62915 Microsoft Exchange Server Security Feature Bypass Vulnerability Aug 11, 2026

    Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network.

    Vendor
    Microsoft · Microsoft Exchange Server
    Product scope
    Exchange Server
    Weakness type
    CWE-862: Missing Authorization
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C
    Published
    Aug 11, 2026
  • Microsoft Exchange Server 7.3 CVE-2026-62914 Microsoft Exchange Server Spoofing Vulnerability Aug 11, 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.

    Vendor
    Microsoft · Microsoft Exchange Server
    Product scope
    Exchange Server
    Weakness type
    CWE-79: Cross-Site Scripting
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C
    Published
    Aug 11, 2026
  • Microsoft Exchange Server 8.8 CVE-2026-62913 Microsoft Exchange Server Remote Code Execution Vulnerability Aug 11, 2026

    Critical or actively exploited: triggers an email alert

    Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.

    Vendor
    Microsoft · Microsoft Exchange Server
    Product scope
    Exchange Server
    Weakness type
    CWE-122: Heap-based Buffer Overflow
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Published
    Aug 11, 2026
  • Microsoft Exchange Server 6.5 CVE-2026-62912 Microsoft Exchange Server Denial of Service Vulnerability Aug 11, 2026

    Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network.

    Vendor
    Microsoft · Microsoft Exchange Server
    Product scope
    Exchange Server
    Weakness type
    CWE-502: Deserialization of Untrusted Data
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
    Published
    Aug 11, 2026
  • Microsoft Exchange Server 8.0 CVE-2026-62911 Microsoft Exchange Server Elevation of Privilege Vulnerability Aug 11, 2026

    Critical or actively exploited: triggers an email alert

    Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

    Vendor
    Microsoft · Microsoft Exchange Server
    Product scope
    Exchange Server
    Weakness type
    CWE-294: Authentication Bypass by Capture-replay
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Published
    Aug 11, 2026
  • Microsoft Exchange Server 7.2 CVE-2026-62910 Microsoft Exchange Server Elevation of Privilege Vulnerability Aug 11, 2026

    Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

    Vendor
    Microsoft · Microsoft Exchange Server
    Product scope
    Exchange Server
    Weakness type
    CWE-99: Improper Control of Resource Identifiers ('Resource Injection')
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Published
    Aug 11, 2026
  • Microsoft Active Directory / Entra 8.8 CVE-2026-62818 Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability Aug 11, 2026

    Critical or actively exploited: triggers an email alert

    Use after free in Active Directory Certificate Services (AD CS) allows an authorized attacker to execute code over a network.

    Vendor
    Microsoft · Windows 10 Version 1607
    Product scope
    Active Directory / Entra
    Weakness type
    CWE-416: Use After Free
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Published
    Aug 11, 2026
  • Microsoft Active Directory / Entra 7.0 CVE-2026-62773 Windows Kerberos Elevation of Privilege Vulnerability Aug 11, 2026

    Use after free in Windows Kerberos allows an authorized attacker to elevate privileges locally.

    Vendor
    Microsoft · Windows 10 Version 1607
    Product scope
    Active Directory / Entra
    Weakness type
    CWE-416: Use After Free
    CVSS 3.1
    CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Published
    Aug 11, 2026
  • Microsoft Active Directory / Entra 7.0 CVE-2026-62766 Windows Kerberos Elevation of Privilege Vulnerability Aug 11, 2026

    Double free in Windows Kerberos allows an authorized attacker to elevate privileges locally.

    Vendor
    Microsoft · Windows 11 Version 24H2
    Product scope
    Active Directory / Entra
    Weakness type
    CWE-415: Double Free
    CVSS 3.1
    CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Published
    Aug 11, 2026
  • Microsoft Active Directory / Entra 7.8 CVE-2026-62754 Windows Kerberos Elevation of Privilege Vulnerability Aug 11, 2026

    Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.

    Vendor
    Microsoft · Windows 10 Version 1607
    Product scope
    Active Directory / Entra
    Weakness type
    CWE-122: Heap-based Buffer Overflow
    CVSS 3.1
    CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Published
    Aug 11, 2026
  • Microsoft Active Directory / Entra 7.8 CVE-2026-62752 Windows Kerberos Elevation of Privilege Vulnerability Aug 11, 2026

    Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.

    Vendor
    Microsoft · Windows 10 Version 1607
    Product scope
    Active Directory / Entra
    Weakness type
    CWE-122: Heap-based Buffer Overflow
    CVSS 3.1
    CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Published
    Aug 11, 2026
  • Microsoft Active Directory / Entra 8.8 CVE-2026-49179 Windows Active Directory Domain Services Remote Code Execution Vulnerability Aug 11, 2026

    Critical or actively exploited: triggers an email alert

    Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network.

    Vendor
    Microsoft · Windows 10 Version 1607
    Product scope
    Active Directory / Entra
    Weakness type
    CWE-77: Command Injection
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Published
    Aug 11, 2026
  • Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) 8.6 KEV CVE-2026-20349 Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability Aug 11, 2026

    A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.&nbsp; This vulnerability is due to insufficient error checking when processing HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.

    Vendor
    Cisco · Cisco Secure Firewall
    Weakness type
    CWE-244
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
    Published
    Aug 11, 2026
    In KEV catalog since
    Aug 11, 2026
  • Progress LoadMaster 9.6 KEV CVE-2026-8037 OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF Aug 7, 2026

    OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints

    Vendor
    Progress Software · LoadMaster
    Weakness type
    CWE-77: Command Injection
    CVSS 3.1
    CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
    Published
    Jun 4, 2026
    In KEV catalog since
    Aug 7, 2026
  • Microsoft Teams 10.0 CVE-2026-65667 Microsoft Teams Elevation of Privilege Vulnerability Aug 6, 2026

    Critical or actively exploited: triggers an email alert

    Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.

    Vendor
    Microsoft · Microsoft Teams
    Product scope
    Teams
    Weakness type
    CWE-862: Missing Authorization
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C
    Published
    Aug 6, 2026
  • Microsoft Teams 7.5 CVE-2026-62918 Microsoft Teams Spoofing Vulnerability Aug 6, 2026

    Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network.

    Vendor
    Microsoft · Microsoft Teams
    Product scope
    Teams
    Weakness type
    CWE-347: Improper Verification of Cryptographic Signature
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C
    Published
    Aug 6, 2026
  • Microsoft Teams 9.6 CVE-2026-62896 Microsoft Teams Elevation of Privilege Vulnerability Aug 6, 2026

    Critical or actively exploited: triggers an email alert

    Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.

    Vendor
    Microsoft · Microsoft Teams
    Product scope
    Teams
    Weakness type
    CWE-287: Improper Authentication
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C
    Published
    Aug 6, 2026
  • Microsoft Active Directory / Entra 9.9 CVE-2026-59115 Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability Aug 6, 2026

    Critical or actively exploited: triggers an email alert

    '.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.

    Vendor
    Microsoft · Microsoft Entra Provisioning Service
    Product scope
    Active Directory / Entra
    Weakness type
    CWE-35: Path Traversal: '.../...//'
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C
    Published
    Aug 6, 2026
  • Microsoft Active Directory / Entra 9.9 CVE-2026-50481 Azure Active Directory Elevation of Privilege Vulnerability Aug 6, 2026

    Critical or actively exploited: triggers an email alert

    Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.

    Vendor
    Microsoft · Azure Active Directory
    Product scope
    Active Directory / Entra
    Weakness type
    CWE-471: Modification of Assumed-Immutable Data (MAID)
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L/E:U/RL:O/RC:C
    Published
    Aug 6, 2026
  • JetBrains TeamCity 9.8 KEV CVE-2026-63077 JetBrains TeamCity: Deserialization of Untrusted Data Aug 5, 2026

    In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

    Vendor
    JetBrains · TeamCity
    Weakness type
    CWE-502: Deserialization of Untrusted Data
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Published
    Jul 27, 2026
    In KEV catalog since
    Aug 5, 2026 · Used in ransomware campaigns
  • OpenSSL 7.5 CVE-2026-54876 Client-Side Memory Leak in OCSP Response Checking Aug 5, 2026

    Issue summary: A malicious TLS server can cause a memory leak in a TLS client that has enabled OCSP response checking by sending an OCSP response that contains no single response entries. Impact summary: An attacker can leak an attacker-tunable amount of memory per TLS handshake in a victim client application. A long-running client that repeatedly connects to a malicious server can have its memory exhausted, resulting in a Denial of Service. CWE: CWE-401: Missing Release of Memory after Effective Lifetime Description: The affected function is called during X.509 certificate chain verification when OCSP response checking is enabled with the X509_V_FLAG_OCSP_RESP_CHECK or X509_V_FLAG_OCSP_RESP_CHECK_ALL verification flags, for example when a TLS client verifies an OCSP response stapled into the TLS handshake by the server. When the received BasicOCSPResponse contains an empty SEQUENCE OF SingleResponse, which is permitted on the wire and accepted by the OpenSSL decoder, the OCSP_BASICRESP structure allocated by OCSP_response_get1_basic() was not freed because an early return bypassed the cleanup code at the end of the function. The amount of memory leaked per handshake can be amplified by the attacker by padding the certs field of the BasicOCSPResponse with bogus certificates, which are parsed and stored in the leaked structure before the empty response check triggers the early return. A long-running TLS client that repeatedly connects to a malicious server can have its memory exhausted over time. OCSP response checking is not enabled by default. Only client applications that explicitly enable the OCSP response check verification flags are affected. FIPS impact: no The FIPS modules in 4.0 and 3.6 are not affected by this issue as the affected code is outside the OpenSSL FIPS module boundary.

    Vendor
    OpenSSL · OpenSSL
    Product scope
    OpenSSL / OpenSSH
    Weakness type
    CWE-401: Missing Release of Memory after Effective Lifetime
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
    Published
    Aug 5, 2026
  • Apache Tomcat 7.5 KEV CVE-2026-34486 Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor Aug 4, 2026

    Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.

    Vendor
    Apache Software Foundation · Apache Tomcat
    Weakness type
    CWE-311: Missing Encryption of Sensitive Data
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
    Published
    Apr 9, 2026
    In KEV catalog since
    Aug 4, 2026
  • N-able N-central 8.2 KEV CVE-2026-18556 Unauthenticated administrative account takeover Aug 4, 2026

    Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.

    Vendor
    N-able · N-central
    Weakness type
    CWE-288: Authentication bypass using an alternate path or channel
    CVSS 4.0
    CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
    Published
    Aug 1, 2026
    In KEV catalog since
    Aug 4, 2026
  • IBM Langflow 9.8 KEV CVE-2026-9198 Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation Aug 4, 2026

    IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments

    Vendor
    IBM · Langflow OSS
    Weakness type
    CWE-94: Code Injection
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Published
    Jul 17, 2026
    In KEV catalog since
    Aug 4, 2026
  • N-able N-central 8.2 KEV CVE-2026-18577 Incomplete patch leads to administrative account takeover Aug 3, 2026

    An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

    Vendor
    N-able · N-central
    Weakness type
    CWE-288: Authentication bypass using an alternate path or channel
    CVSS 4.0
    CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:L/E:A
    Published
    Aug 2, 2026
    In KEV catalog since
    Aug 3, 2026
  • Cisco Secure Firewall Management Center (FMC) 5.3 KEV CVE-2026-20316 Cisco Secure Firewall Management Center Software Static Credential Vulnerability Jul 29, 2026

    A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the presence of static user credentials for a low-privileged&nbsp;account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user.&nbsp; Note:&nbsp;If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.&nbsp;&nbsp; Cisco has assigned this security advisory a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that this vulnerability can be used with other Cisco Secure FMC Software vulnerabilities to elevate privileges.

    Vendor
    Cisco · Cisco Secure Firewall Management Center (FMC)
    Weakness type
    CWE-259
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
    Published
    Jul 29, 2026
    In KEV catalog since
    Jul 29, 2026 · Used in ransomware campaigns
  • Arista VeloCloud Orchestrator 10.0 KEV CVE-2026-16812 VeloCloud Orchestrator OS Command Injection Jul 27, 2026

    VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. This functionality was intended to be for internal use only and is not intended to be remotely accessible. Hosted and Dedicated versions of VCO have already been patched in advance of this notice going out. This issue was discovered externally and is known to be actively exploited.

    Vendor
    Arista Networks · VeloCloud Orchestrator On-Prem
    Weakness type
    CWE-78: OS Command Injection
    CVSS 4.0
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/S:P
    Published
    Jul 27, 2026
    In KEV catalog since
    Jul 27, 2026
  • Fortinet FortiOS 5.3 KEV CVE-2025-68686 Fortinet FortiOS: Information Disclosure Jul 27, 2026

    An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.

    Vendor
    Fortinet · FortiOS
    Weakness type
    CWE-200: Information Disclosure
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C
    Published
    Feb 10, 2026
    In KEV catalog since
    Jul 27, 2026
  • Exim 7.4 CVE-2026-66141 Exim: Inclusion of Functionality from Untrusted Control Sphere Jul 24, 2026

    Exim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled.

    Vendor
    Exim · Exim
    Product scope
    Postfix / Exim / Dovecot
    Weakness type
    CWE-829: Inclusion of Functionality from Untrusted Control Sphere
    CVSS 3.1
    CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
    Published
    Jul 24, 2026
  • Exim 8.4 CVE-2026-66140 Exim: Path Traversal: '../filedir' Jul 24, 2026

    Critical or actively exploited: triggers an email alert

    Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-name are mishandled.

    Vendor
    Exim · Exim
    Product scope
    Postfix / Exim / Dovecot
    Weakness type
    CWE-24: Path Traversal: '../filedir'
    CVSS 3.1
    CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Published
    Jul 24, 2026
  • Microsoft SharePoint 9.8 KEV CVE-2026-50522 Microsoft SharePoint Remote Code Execution Vulnerability Jul 22, 2026

    Critical or actively exploited: triggers an email alert

    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

    Vendor
    Microsoft · Microsoft SharePoint
    Product scope
    SharePoint
    Weakness type
    CWE-502: Deserialization of Untrusted Data
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Published
    Jul 14, 2026
    In KEV catalog since
    Jul 22, 2026
  • Check Point SmartConsole 9.3 KEV CVE-2026-16232 Authentication Bypass in the SmartConsole Login Process Using an Application Token Jul 22, 2026

    An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers.

    Vendor
    checkpoint · Quantum Security Management
    Weakness type
    CWE-287: Improper Authentication
    CVSS 4.0
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
    Published
    Jul 22, 2026
    In KEV catalog since
    Jul 22, 2026
  • WordPress Core 9.8 KEV CVE-2026-63030 WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution Jul 21, 2026

    WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.

    Vendor
    WordPress · WordPress
    Weakness type
    CWE-436: Interpretation Conflict
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Published
    Jul 17, 2026
    In KEV catalog since
    Jul 21, 2026
  • WordPress Core 5.9 KEV CVE-2026-60137 WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query Jul 21, 2026

    WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.

    Vendor
    WordPress · WordPress
    Weakness type
    CWE-89: SQL Injection
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
    Published
    Jul 17, 2026
    In KEV catalog since
    Jul 21, 2026
  • Langflow 9.8 KEV CVE-2026-0770 Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability Jul 21, 2026

    Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the exec_globals parameter provided to the validate endpoint. The issue results from the inclusion of a resource from an untrusted control sphere. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-27325.

    Vendor
    Langflow · Langflow
    Weakness type
    CWE-829: Inclusion of Functionality from Untrusted Control Sphere
    CVSS 3.0
    CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Published
    Jan 23, 2026
    In KEV catalog since
    Jul 21, 2026
  • DD-WRT 8.1 KEV CVE-2021-27137 DD-WRT: Stack-based Buffer Overflow Jul 21, 2026

    An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality allows an unauthenticated remote attacker to send a request that would overflow an internal fixed buffer. Exploitation requires the DD-WRT user to enable UPnP (which is off by default, and only listens on internal interfaces by default). This occurs in ssdp_msearch (reachable by an M-SEARCH request).

    Vendor
    DD-WRT · DD-WRT
    Weakness type
    CWE-121: Stack-based Buffer Overflow
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
    Published
    Jul 16, 2026
    In KEV catalog since
    Jul 21, 2026
  • rust-openssl 5.1 CVE-2026-45784 rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers Jul 17, 2026

    rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.50 until 0.10.80, CipherCtxRef::cipher_update_inplace in openssl/src/cipher_ctx.rs incorrectly sized output buffers when used with AES key-wrap-with-padding ciphers EVP_aes_{128,192,256}_wrap_pad. For a non-multiple-of-8 input, OpenSSL writes up to 7 bytes past the end of the caller's buffer or Vec, producing attacker-controllable heap corruption when the plaintext length is attacker-influenced. This issue is fixed in version 0.10.80.

    Vendor
    rust-openssl · rust-openssl
    Product scope
    OpenSSL / OpenSSH
    Weakness type
    CWE-131: Incorrect Calculation of Buffer Size
    CVSS 4.0
    CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
    Published
    Jul 17, 2026
  • SEPPmail 7.5 CVE-2026-9592 Sensitive Information Disclosure in HTTP header Jul 17, 2026

    SEPPmail Secure Email Gateway & SEPPmail Cloud before version 15.0.4.2 allows an attacker to replay & hijack a user session in the GINA web portal, as the session token is disclosed inside the URL and a HTTP header.

    Vendor
    SEPPmail · SEPPmail Secure Email Gateway & SEPPmail Cloud
    Product scope
    SEPPmail
    Weakness type
    CWE-598: Use of GET request method with sensitive query strings
    CVSS 4.0
    CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:U
    Published
    Jul 17, 2026
  • Microsoft SharePoint 9.8 KEV CVE-2026-58644 Microsoft SharePoint Remote Code Execution Vulnerability Jul 16, 2026

    Critical or actively exploited: triggers an email alert

    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

    Vendor
    Microsoft · Microsoft SharePoint
    Product scope
    SharePoint
    Weakness type
    CWE-502: Deserialization of Untrusted Data
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
    Published
    Jul 14, 2026
    In KEV catalog since
    Jul 16, 2026
  • Microsoft Teams 9.3 CVE-2026-54733 moodle-local_o365: Authentication bypass via unverified JWT signature in Teams SSO endpoint Jul 16, 2026

    Critical or actively exploited: triggers an email alert

    The Microsoft 365 and Microsoft Entra ID Plugins for Moodle provide Office 365 and Azure Active Directory integration for Moodle. Prior to 4.5.6, 5.0.5, and 5.1.1, the Microsoft Office 365 Integration plugin local_o365 Teams SSO endpoint sso_login.php base64-decodes a JWT payload and authenticates users from the upn claim without verifying the JWT signature, allowing an unauthenticated attacker to forge a token and obtain a Moodle session as an O365-authenticated user. This issue is fixed in versions 4.5.6, 5.0.5, and 5.1.1.

    Vendor
    microsoft · o365-moodle
    Product scope
    Teams
    Weakness type
    CWE-347: Improper Verification of Cryptographic Signature
    CVSS 4.0
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
    Published
    Jul 16, 2026
  • Fortinet FortiSandbox 9.1 KEV CVE-2026-39808 Fortinet FortiSandbox: OS Command Injection Jul 16, 2026

    A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here>

    Vendor
    Fortinet · FortiSandbox
    Weakness type
    CWE-78: OS Command Injection
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
    Published
    Apr 14, 2026
    In KEV catalog since
    Jul 16, 2026
  • Fortinet FortiSandbox 9.1 KEV CVE-2026-25089 Fortinet FortiSandbox: OS Command Injection Jul 16, 2026

    A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests

    Vendor
    Fortinet · FortiSandbox
    Weakness type
    CWE-78: OS Command Injection
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
    Published
    Jun 9, 2026
    In KEV catalog since
    Jul 16, 2026
  • Oracle E-Business Suite 9.8 KEV CVE-2026-46817 Oracle Corporation Oracle Payments: Missing Authentication Jul 15, 2026

    Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

    Vendor
    Oracle Corporation · Oracle Payments
    Weakness type
    CWE-306: Missing Authentication
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Published
    May 28, 2026
    In KEV catalog since
    Jul 15, 2026
  • KNX Association KNX Protocol Connection Authorization Option 1 7.5 KEV CVE-2023-4346 KNX Association KNX Protocol Connection Authorization Option 1: Overly Restrictive Account Lockout Mechanism Jul 15, 2026

    KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device. The BCU key feature on the devices can be used to create a password for the device, but this password can often not be reset without entering the current password. If the device is configured to interface with a network, an attacker with access to that network could interface with the KNX installation, purge all devices without additional security options enabled, and set a BCU key, locking the device. Even if a device is not connected to a network, an attacker with physical access to the device could also exploit this vulnerability in the same way.

    Vendor
    KNX Association · KNX Protocol Connection Authorization Option 1
    Weakness type
    CWE-645: Overly Restrictive Account Lockout Mechanism
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
    Published
    Aug 29, 2023
    In KEV catalog since
    Jul 15, 2026
  • Roundcube Webmail 6.4 CVE-2026-62644 Roundcube Webmail: Authentication Bypass by Spoofing Jul 14, 2026

    In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover.

    Vendor
    Roundcube · Webmail
    Product scope
    Webmail
    Weakness type
    CWE-290: Authentication Bypass by Spoofing
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N
    Published
    Jul 14, 2026
  • Roundcube Webmail 7.2 CVE-2026-62643 Roundcube Webmail: Server-Side Request Forgery Jul 14, 2026

    In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. NOTE: this issue exists because of insufficient fixes for CVE-2026-35540 and CVE-2026-48843.

    Vendor
    Roundcube · Webmail
    Product scope
    Webmail
    Weakness type
    CWE-918: Server-Side Request Forgery
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
    Published
    Jul 14, 2026
  • Roundcube Webmail 4.3 CVE-2026-62642 Roundcube Webmail: Loop with Unreachable Exit Condition ('Infinite Loop') Jul 14, 2026

    In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TNEF decoder, which may lead to denial of service upon opening an email with a TNEF attachment.

    Vendor
    Roundcube · Webmail
    Product scope
    Webmail
    Weakness type
    CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop')
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
    Published
    Jul 14, 2026
  • Roundcube Webmail 4.3 CVE-2026-62641 Roundcube Webmail: Allocation of Resources Without Limits or Throttling Jul 14, 2026

    In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder was subject to denial of service via a crafted compressed-RTF size.

    Vendor
    Roundcube · Webmail
    Product scope
    Webmail
    Weakness type
    CWE-770: Allocation of Resources Without Limits or Throttling
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
    Published
    Jul 14, 2026
  • Microsoft Active Directory / Entra 7.1 CVE-2026-58529 Windows Active Directory Federation Services (ADFS) Information Disclosure Vulnerability Jul 14, 2026

    Out-of-bounds read in Active Directory Federation Services (AD FS) allows an authorized attacker to disclose information over a network.

    Vendor
    Microsoft · Windows 11 version 26H1
    Product scope
    Active Directory / Entra
    Weakness type
    CWE-125: Out-of-bounds Read
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L/E:U/RL:O/RC:C
    Published
    Jul 14, 2026
  • Microsoft Active Directory / Entra 6.5 CVE-2026-57976 Windows Active Directory Domain Services Denial of Service Vulnerability Jul 14, 2026

    Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.

    Vendor
    Microsoft · Windows 10 Version 1607
    Product scope
    Active Directory / Entra
    Weakness type
    CWE-476: NULL Pointer Dereference
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
    Published
    Jul 14, 2026
  • Microsoft SharePoint 5.3 KEV CVE-2026-56164 Microsoft SharePoint Server Elevation of Privilege Vulnerability Jul 14, 2026

    Critical or actively exploited: triggers an email alert

    Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.

    Vendor
    Microsoft · Microsoft SharePoint
    Product scope
    SharePoint
    Weakness type
    CWE-306: Missing Authentication
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:F/RL:O/RC:C
    Published
    Jul 14, 2026
    In KEV catalog since
    Jul 14, 2026
  • Microsoft Active Directory / Entra 7.8 KEV CVE-2026-56155 Active Directory Federation Services Elevation of Privilege Vulnerability Jul 14, 2026

    Critical or actively exploited: triggers an email alert

    Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.

    Vendor
    Microsoft · Windows 10 Version 1607
    Product scope
    Active Directory / Entra
    Weakness type
    CWE-1220: Insufficient Granularity of Access Control
    CVSS 3.1
    CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
    Published
    Jul 14, 2026
    In KEV catalog since
    Jul 14, 2026
  • Microsoft Exchange Server 7.8 CVE-2026-55009 Microsoft Exchange Server Elevation of Privilege Vulnerability Jul 14, 2026

    Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.

    Vendor
    Microsoft · Microsoft Exchange Server
    Product scope
    Exchange Server
    Weakness type
    CWE-502: Deserialization of Untrusted Data
    CVSS 3.1
    CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Published
    Jul 14, 2026
  • Microsoft Exchange Server 9.6 CVE-2026-55008 Microsoft Exchange Server Spoofing Vulnerability Jul 14, 2026

    Critical or actively exploited: triggers an email alert

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

    Vendor
    Microsoft · Microsoft Exchange Server
    Product scope
    Exchange Server
    Weakness type
    CWE-79: Cross-Site Scripting
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C
    Published
    Jul 14, 2026
  • Microsoft Exchange Server 7.8 CVE-2026-55006 Microsoft Exchange Server Elevation of Privilege Vulnerability Jul 14, 2026

    Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.

    Vendor
    Microsoft · Microsoft Exchange Server
    Product scope
    Exchange Server
    Weakness type
    CWE-1220: Insufficient Granularity of Access Control
    CVSS 3.1
    CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Published
    Jul 14, 2026
  • Microsoft Exchange Server 8.8 CVE-2026-55005 Microsoft Exchange Server Remote Code Execution Vulnerability Jul 14, 2026

    Critical or actively exploited: triggers an email alert

    Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.

    Vendor
    Microsoft · Microsoft Exchange Server
    Product scope
    Exchange Server
    Weakness type
    CWE-122: Heap-based Buffer Overflow
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Published
    Jul 14, 2026
  • Microsoft Active Directory / Entra 7.8 CVE-2026-55001 Active Directory Domain Services Elevation of Privilege Vulnerability Jul 14, 2026

    Improper certificate validation in Windows Active Directory allows an authorized attacker to elevate privileges locally.

    Vendor
    Microsoft · Windows 10 Version 1607
    Product scope
    Active Directory / Entra
    Weakness type
    CWE-295: Improper Certificate Validation
    CVSS 3.1
    CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Published
    Jul 14, 2026
  • Microsoft Active Directory / Entra 7.5 CVE-2026-54983 Windows Active Directory Federation Services Denial of Service Vulnerability Jul 14, 2026

    Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.

    Vendor
    Microsoft · Windows 10 Version 1607
    Product scope
    Active Directory / Entra
    Weakness type
    CWE-121: Stack-based Buffer Overflow
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
    Published
    Jul 14, 2026
  • Roundcube Webmail 7.2 CVE-2026-54433 Roundcube Webmail: Cross-Site Scripting Jul 14, 2026

    In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message. The attacker-controlled JavaScript executes within the victim's authenticated session simply by opening or previewing the message (zero-click).

    Vendor
    Roundcube · Webmail
    Product scope
    Webmail
    Weakness type
    CWE-79: Cross-Site Scripting
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
    Published
    Jul 14, 2026
  • Roundcube Webmail 4.7 CVE-2026-54432 Roundcube Webmail: Cross-Site Scripting Jul 14, 2026

    Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2 allows Stored Cross-Site Scripting (XSS). The issue occurs because the attachment MIME type is not properly escaped on the attachment-validation warning page.

    Vendor
    Roundcube · Webmail
    Product scope
    Webmail
    Weakness type
    CWE-79: Cross-Site Scripting
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
    Published
    Jul 14, 2026
  • Microsoft Active Directory / Entra 8.8 CVE-2026-54121 Active Directory Certificate Services Elevation of Privilege Vulnerability Jul 14, 2026

    Critical or actively exploited: triggers an email alert

    Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.

    Vendor
    Microsoft · Windows 10 Version 1607
    Product scope
    Active Directory / Entra
    Weakness type
    CWE-285: Improper Authorization
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Published
    Jul 14, 2026
  • Microsoft Active Directory / Entra 7.5 CVE-2026-54119 Windows Active Directory Denial of Service Vulnerability Jul 14, 2026

    Loop with unreachable exit condition ('infinite loop') in Windows Active Directory allows an unauthorized attacker to deny service over a network.

    Vendor
    Microsoft · Windows 10 Version 1607
    Product scope
    Active Directory / Entra
    Weakness type
    CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop')
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
    Published
    Jul 14, 2026
  • Microsoft Active Directory / Entra 7.5 CVE-2026-50695 Windows Active Directory Federation Services Denial of Service Vulnerability Jul 14, 2026

    Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.

    Vendor
    Microsoft · Windows 10 Version 1607
    Product scope
    Active Directory / Entra
    Weakness type
    CWE-121: Stack-based Buffer Overflow
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
    Published
    Jul 14, 2026
  • Microsoft Active Directory / Entra 4.8 CVE-2026-50684 Active Directory Federation Server Spoofing Vulnerability Jul 14, 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Active Directory Federation Services (AD FS) allows an authorized attacker to perform spoofing over a network.

    Vendor
    Microsoft · Windows 10 Version 1607
    Product scope
    Active Directory / Entra
    Weakness type
    CWE-79: Cross-Site Scripting
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N/E:U/RL:O/RC:C
    Published
    Jul 14, 2026
  • Microsoft Active Directory / Entra 7.1 CVE-2026-50682 Active Directory Denial of Service Vulnerability Jul 14, 2026

    Out-of-bounds read in Windows Active Directory allows an authorized attacker to deny service over a network.

    Vendor
    Microsoft · Windows 10 Version 21H2
    Product scope
    Active Directory / Entra
    Weakness type
    CWE-125: Out-of-bounds Read
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H/E:U/RL:O/RC:C
    Published
    Jul 14, 2026
  • Microsoft Active Directory / Entra 7.5 CVE-2026-50653 Azure Active Directory Denial of Service Vulnerability Jul 14, 2026

    Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.

    Vendor
    Microsoft · Azure Active Directory
    Product scope
    Active Directory / Entra
    Weakness type
    CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop')
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
    Published
    Jul 14, 2026
  • Microsoft Active Directory / Entra 7.5 CVE-2026-50652 Azure Active Directory Denial of Service Vulnerability Jul 14, 2026

    Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.

    Vendor
    Microsoft · Azure Active Directory
    Product scope
    Active Directory / Entra
    Weakness type
    CWE-502: Deserialization of Untrusted Data
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
    Published
    Jul 14, 2026
  • Microsoft Active Directory / Entra 7.5 CVE-2026-50647 Active Directory Federation Server Denial of Service Vulnerability Jul 14, 2026

    Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.

    Vendor
    Microsoft · Microsoft .NET Framework 3.5 AND 4.7.2
    Product scope
    Active Directory / Entra
    Weakness type
    CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop')
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
    Published
    Jul 14, 2026
  • Microsoft Active Directory / Entra 7.5 CVE-2026-50411 Windows Active Directory Federation Services Denial of Service Vulnerability Jul 14, 2026

    Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.

    Vendor
    Microsoft · Microsoft .NET Framework 3.5 AND 4.7.2
    Product scope
    Active Directory / Entra
    Weakness type
    CWE-121: Stack-based Buffer Overflow
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
    Published
    Jul 14, 2026
  • Microsoft Active Directory / Entra 7.5 CVE-2026-50368 Windows Active Directory Federation Services Denial of Service Vulnerability Jul 14, 2026

    Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.

    Vendor
    Microsoft · Microsoft .NET Framework 3.5 AND 4.7.2
    Product scope
    Active Directory / Entra
    Weakness type
    CWE-121: Stack-based Buffer Overflow
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
    Published
    Jul 14, 2026
  • Microsoft Active Directory / Entra 6.5 CVE-2026-50366 Windows Active Directory Domain Services Denial of Service Vulnerability Jul 14, 2026

    Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.

    Vendor
    Microsoft · Windows 10 Version 1607
    Product scope
    Active Directory / Entra
    Weakness type
    CWE-476: NULL Pointer Dereference
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
    Published
    Jul 14, 2026
  • Microsoft Active Directory / Entra 7.5 CVE-2026-50355 Windows Active Directory Federation Services Denial of Service Vulnerability Jul 14, 2026

    Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.

    Vendor
    Microsoft · Microsoft .NET Framework 3.5 AND 4.7.2
    Product scope
    Active Directory / Entra
    Weakness type
    CWE-121: Stack-based Buffer Overflow
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
    Published
    Jul 14, 2026
  • Microsoft Active Directory / Entra 5.9 CVE-2026-50324 Windows Active Directory Federation Services Denial of Service Vulnerability Jul 14, 2026

    Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.

    Vendor
    Microsoft · Microsoft .NET Framework 3.5 AND 4.7.2
    Product scope
    Active Directory / Entra
    Weakness type
    CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop')
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
    Published
    Jul 14, 2026
  • Microsoft Active Directory / Entra 7.5 CVE-2026-50304 Windows Active Directory Federation Services Denial of Service Vulnerability Jul 14, 2026

    Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.

    Vendor
    Microsoft · Microsoft .NET Framework 3.5 AND 4.7.2
    Product scope
    Active Directory / Entra
    Weakness type
    CWE-121: Stack-based Buffer Overflow
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
    Published
    Jul 14, 2026
  • Microsoft Active Directory / Entra 8.8 CVE-2026-49178 Windows Active Directory Domain Services Remote Code Execution Vulnerability Jul 14, 2026

    Critical or actively exploited: triggers an email alert

    Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network.

    Vendor
    Microsoft · Windows 10 Version 1607
    Product scope
    Active Directory / Entra
    Weakness type
    CWE-122: Heap-based Buffer Overflow
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Published
    Jul 14, 2026
  • Microsoft Active Directory / Entra 8.1 CVE-2026-49164 Windows Active Directory Domain Services Remote Code Execution Vulnerability Jul 14, 2026

    Critical or actively exploited: triggers an email alert

    Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.

    Vendor
    Microsoft · Windows 10 Version 1607
    Product scope
    Active Directory / Entra
    Weakness type
    CWE-122: Heap-based Buffer Overflow
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Published
    Jul 14, 2026
  • SonicWall SMA1000 Appliances 7.2 KEV CVE-2026-15410 SonicWall SMA1000: Code Injection Jul 14, 2026

    Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.

    Vendor
    SonicWall · SMA1000
    Weakness type
    CWE-94: Code Injection
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
    Published
    Jul 14, 2026
    In KEV catalog since
    Jul 14, 2026 · Used in ransomware campaigns
  • SonicWall SMA1000 Appliances 10.0 KEV CVE-2026-15409 SonicWall SMA1000: Server-Side Request Forgery Jul 14, 2026

    A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.

    Vendor
    SonicWall · SMA1000
    Weakness type
    CWE-918: Server-Side Request Forgery
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
    Published
    Jul 14, 2026
    In KEV catalog since
    Jul 14, 2026 · Used in ransomware campaigns
  • Cisco IOS 8.1 KEV CVE-2008-4128 Cross-Site Request Forgery Jul 13, 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router allow remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI. NOTE: some of these details are obtained from third party information.

    Weakness type
    CWE-352: Cross-Site Request Forgery
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
    Published
    Sep 18, 2008
    In KEV catalog since
    Jul 13, 2026
  • Balbooa Forms 10.0 KEV CVE-2026-56291 Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 Jul 10, 2026

    Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

    Vendor
    balbooa.com · balbooa.com Balbooa Forms extension for Joomla
    Weakness type
    CWE-434: Unrestricted File Upload
    CVSS 4.0
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y/U:Red
    Published
    Jul 9, 2026
    In KEV catalog since
    Jul 10, 2026
  • iCagenda 10.0 KEV CVE-2026-48939 Joomla Extension - icagenda.com - Remote Code Execution in iCaganda extension for Joomla < 4.0.8/3.9.15 Jul 10, 2026

    A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

    Vendor
    icagenda.com · iCagenda extension for Joomla
    Weakness type
    CWE-434: Unrestricted File Upload
    CVSS 4.0
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y/U:Red
    Published
    Jun 20, 2026
    In KEV catalog since
    Jul 10, 2026
  • OpenBSD OpenSSH 7.7 CVE-2026-60002 OpenBSD OpenSSH: Use After Free Jul 8, 2026

    ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)

    Vendor
    OpenBSD · OpenSSH
    Product scope
    OpenSSL / OpenSSH
    Weakness type
    CWE-416: Use After Free
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
    Published
    Jul 8, 2026
  • OpenBSD OpenSSH 6.5 CVE-2026-60001 OpenBSD OpenSSH: Allocation of Resources Without Limits or Throttling Jul 8, 2026

    sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.

    Vendor
    OpenBSD · OpenSSH
    Product scope
    OpenSSL / OpenSSH
    Weakness type
    CWE-770: Allocation of Resources Without Limits or Throttling
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
    Published
    Jul 8, 2026
  • OpenBSD OpenSSH 3.7 CVE-2026-60000 OpenBSD OpenSSH: Allocation of Resources Without Limits or Throttling Jul 8, 2026

    sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication.

    Vendor
    OpenBSD · OpenSSH
    Product scope
    OpenSSL / OpenSSH
    Weakness type
    CWE-770: Allocation of Resources Without Limits or Throttling
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
    Published
    Jul 8, 2026
  • OpenBSD OpenSSH 5.9 CVE-2026-59999 OpenBSD OpenSSH: Use of Less Trusted Source Jul 8, 2026

    In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.

    Vendor
    OpenBSD · OpenSSH
    Product scope
    OpenSSL / OpenSSH
    Weakness type
    CWE-348: Use of Less Trusted Source
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
    Published
    Jul 8, 2026
  • OpenBSD OpenSSH 4.8 CVE-2026-59998 OpenBSD OpenSSH: Improper Following of Specification by Caller Jul 8, 2026

    sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.

    Vendor
    OpenBSD · OpenSSH
    Product scope
    OpenSSL / OpenSSH
    Weakness type
    CWE-573: Improper Following of Specification by Caller
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
    Published
    Jul 8, 2026
  • OpenBSD OpenSSH 4.2 CVE-2026-59997 OpenBSD OpenSSH: Improper Validation of Specified Quantity in Input Jul 8, 2026

    internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection.

    Vendor
    OpenBSD · OpenSSH
    Product scope
    OpenSSL / OpenSSH
    Weakness type
    CWE-1284: Improper Validation of Specified Quantity in Input
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
    Published
    Jul 8, 2026
  • OpenBSD OpenSSH 4.2 CVE-2026-59996 OpenBSD OpenSSH: Relative Path Traversal Jul 8, 2026

    scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.

    Vendor
    OpenBSD · OpenSSH
    Product scope
    OpenSSL / OpenSSH
    Weakness type
    CWE-23: Relative Path Traversal
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L
    Published
    Jul 8, 2026
  • OpenBSD OpenSSH 4.2 CVE-2026-59995 OpenBSD OpenSSH: Relative Path Traversal Jul 8, 2026

    sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.

    Vendor
    OpenBSD · OpenSSH
    Product scope
    OpenSSL / OpenSSH
    Weakness type
    CWE-23: Relative Path Traversal
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L
    Published
    Jul 8, 2026
  • Joomlack Page Builder 10.0 KEV CVE-2026-56290 Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 Jul 7, 2026

    Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

    Vendor
    joomlack.fr · JoomlaCK.fr Page Builder CK extension for Joomla
    Weakness type
    CWE-434: Unrestricted File Upload
    CVSS 4.0
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y/U:Red
    Published
    Jun 29, 2026
    In KEV catalog since
    Jul 7, 2026
  • Langflow 8.4 KEV CVE-2026-55255 Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow Jul 7, 2026

    Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object Reference (IDOR) vulnerability in /api/v1/responses endpoint allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request. This vulnerability is fixed in 1.9.1.

    Vendor
    langflow-ai · langflow
    Weakness type
    CWE-639: Authorization Bypass Through User-Controlled Key
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L
    Published
    Jun 23, 2026
    In KEV catalog since
    Jul 7, 2026
  • JoomShaper SP Page Builder 10.0 KEV CVE-2026-48908 Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2 Jul 7, 2026

    A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.

    Vendor
    joomshaper.net · SP Page Builder extension for Joomla
    Weakness type
    CWE-434: Unrestricted File Upload
    CVSS 4.0
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y/U:Red
    Published
    Jun 20, 2026
    In KEV catalog since
    Jul 7, 2026
  • Adobe ColdFusion 10.0 KEV CVE-2026-48282 ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) Jul 7, 2026

    ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

    Vendor
    Adobe · ColdFusion 2025
    Weakness type
    CWE-22: Path Traversal
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
    Published
    Jun 30, 2026
    In KEV catalog since
    Jul 7, 2026

Covered in articles

Vulnerabilities discussed in detail in the articles and the knowledge base. Each CVE leads to its analysis.

13 vulnerabilities · Reference data: CVE.org (CNA records) and CISA Known Exploited Vulnerabilities, as of the last build.

CVE Product CVSS Published Analysis
CVE-2026-104286 Fortinet FortiMail: Path Traversal FortiMail 9.8 KEV Oct 1, 2026
CVE-2026-65813 Microsoft Exchange Server Elevation of Privilege Vulnerability Microsoft Exchange Server 6.5 Aug 11, 2026
CVE-2026-62915 Microsoft Exchange Server Security Feature Bypass Vulnerability Microsoft Exchange Server 6.5 Aug 11, 2026
CVE-2026-62914 Microsoft Exchange Server Spoofing Vulnerability Microsoft Exchange Server 7.3 Aug 11, 2026
CVE-2026-62913 Microsoft Exchange Server Remote Code Execution Vulnerability Microsoft Exchange Server 8.8 Aug 11, 2026
CVE-2026-62912 Microsoft Exchange Server Denial of Service Vulnerability Microsoft Exchange Server 6.5 Aug 11, 2026
CVE-2026-62911 Microsoft Exchange Server Elevation of Privilege Vulnerability Microsoft Exchange Server 8.0 Aug 11, 2026
CVE-2026-62910 Microsoft Exchange Server Elevation of Privilege Vulnerability Microsoft Exchange Server 7.2 Aug 11, 2026
CVE-2026-42897 Microsoft Exchange Server Spoofing Vulnerability Microsoft Exchange Server 8.1 KEV May 14, 2026
CVE-2025-32756 Fortinet FortiNDR: Stack-based Buffer Overflow FortiNDR 9.6 KEV May 13, 2025
CVE-2024-28063 Kiteworks totemomail: Cross-Site Scripting totemomail 6.1 May 18, 2024
CVE-2020-7918 totemomail: Insecure Direct Object Reference totemomail – Mar 27, 2020
CVE-2018-6563 totemomail Encryption Gateway: Cross-Site Request Forgery totemomail Encryption Gateway – Jun 20, 2018