| 2026-10-04 | CVE-2026-86060 | MikroTik RouterOS's Argument Injection in a Command-Processing Component Allows Unauthenticated Attackers to Execute Arbitrary Commands on the Router; CISA's September 13th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-10-04 | CVE-2026-85102 | Check Point Firewall Certificate Validation Bypass Across Site-to-Site and Remote Access VPN Carries a Lapsed September 25th CISA KEV Requirement for Covered Entities | 9.8 Critical | KEV |
| 2026-10-04 | CVE-2026-82078 | PaperCut NG/MF's Unsafe Reflection Allows Remote Attackers to Manipulate Class Loading and Execute Arbitrary Code on the Print Management Server; CISA's September 14th KEV Deadline Has Passed | 9.1 Critical | KEV |
| 2026-10-04 | CVE-2026-67276 | MikroTik RouterOS SSH Key Comparison Omits RSA Exponent, Letting an Attacker with a Known Modulus Authenticate as Another User | 8.1 High | EPSS-Imminent |
| 2026-10-04 | CVE-2026-20181 | Cisco Identity Services Engine Authenticated Admin Command Injection Enables Arbitrary OS Command Execution on the Underlying System | 9.1 Critical | EPSS-Imminent |
| 2026-10-03 | CVE-2026-98154 | Linux Kernel nvme-rdma: Failure to Fix -EIO cleanup order in queue_rq | 7.0 High | Updated |
| 2026-10-03 | CVE-2026-98130 | Linux Kernel sctp: Failure to Fix a TOCTOU race in SCTP_CMD_TIMER_START, Reachable from the Network Without Credentials (CVSS 8.1) | 8.1 High | Updated |
| 2026-10-03 | CVE-2026-98122 | Linux Kernel vxlan: mdb: Fix use-after-free in vxlan_mdb_remote_src_del() | 7.8 High | Updated |
| 2026-10-03 | CVE-2026-98116 | Linux Kernel ALSA: pcm: Serialize PCM mmap with buffer reallocation to fix page UAF | 7.8 High | Updated |
| 2026-10-03 | CVE-2026-98108 | Linux Kernel Bluetooth: L2CAP: fix chan mode for LE_CONN_REQ + EXT_FLOWCTL pchan | 7.5 High | Updated |
| 2026-10-03 | CVE-2026-98096 | Linux Kernel ipv6: sr: restore network header before routing and forwarding, Reachable from the Network Without Credentials (CVSS 7.4) | 7.4 High | Updated |
| 2026-10-03 | CVE-2026-98083 | Linux Kernel btrfs: Failure to Fix transaction use-after-free in raid stripe insertion | 7.0 High | Updated |
| 2026-10-03 | CVE-2026-98070 | Linux Kernel net/rds: acquire RDS_IN_XMIT in rds_tcp_reset_callbacks(), Reachable from the Network Without Credentials (CVSS 8.1) | 8.1 High | Updated |
| 2026-10-03 | CVE-2026-98069 | Linux Kernel net/rds: acquire the fastpath locks in rds_conn_shutdown(), Reachable from the Network Without Credentials (CVSS 8.1) | 8.1 High | Updated |
| 2026-10-03 | CVE-2026-98052 | Linux Kernel net: bcmasp: clear txcb->last before writing each descriptor | 7.8 High | Updated |
| 2026-10-03 | CVE-2026-98030 | Linux Kernel net: dsa: bcm_sf2: bound the CFP rule dump by the caller's buffer size | 7.0 High | Updated |
| 2026-10-03 | CVE-2026-98027 | Linux Kernel net: dsa: mv88e6xxx: bound the policy rule dump by the caller's buffer size | 7.0 High | Updated |
| 2026-10-03 | CVE-2026-98023 | Linux Kernel vxlan: reject dynamic fdb entries that reference a nexthop id | 7.8 High | Updated |
| 2026-10-03 | CVE-2026-98017 | Linux Kernel net/sched: defer qdisc freeing after failed creation | 7.8 High | Updated |
| 2026-10-03 | CVE-2026-97991 | Linux Kernel vdpa_sim_blk: reject out-of-range sector starts | 7.8 High | Updated |
| 2026-10-03 | CVE-2026-97990 | Linux Kernel vdpa_sim_net: Failure to Check TX pull result before RX copy | 7.5 High | Updated |
| 2026-10-03 | CVE-2026-97957 | Linux Kernel net: hinic: fix mailbox segment buffer overflow | 8.8 High | Updated |
| 2026-10-03 | CVE-2026-97509 | Linux Kernel thunderbolt: Keep XDomain reference during the lifetime of a service | 8.8 High | Updated |
| 2026-10-03 | CVE-2026-97508 | Linux Kernel thunderbolt: Set tb->root_switch to NULL when domain is stopped | 7.5 High | Updated |
| 2026-10-03 | CVE-2026-97497 | Linux Kernel drm/amdkfd: Failure to Check bounds for allocate_sdma_queue restore_sdma_id | 7.8 High | Updated |
| 2026-10-03 | CVE-2026-97496 | Linux Kernel drm/amdkfd: Failure to Fix OOB memory exposure in get_wave_state() | 7.1 High | Updated |
| 2026-10-03 | CVE-2026-97455 | Linux Kernel ACPICA: Failure to Fix use-after-free in acpi_ds_terminate_control_method() | 8.4 High | Updated |
| 2026-10-03 | CVE-2026-97454 | Linux Kernel ACPICA: Failure to Add boundary checks in acpi_ps_get_next_field() | 7.7 High | Updated |
| 2026-10-03 | CVE-2026-97452 | Linux Kernel ACPICA: Failure to Prevent adding invalid references | 8.4 High | Updated |
| 2026-10-03 | CVE-2026-97451 | Linux Kernel ACPICA: Failure to Fix integer overflow in acpi_ex_opcode_3A_1T_1R() (mid_op) | 8.4 High | Updated |
| 2026-10-03 | CVE-2026-97450 | Linux Kernel ACPICA: Failure to Validate handler object type in two places | 8.4 High | Updated |
| 2026-10-03 | CVE-2026-97448 | Linux Kernel ACPICA: Failure to Add validation for node in acpi_ns_build_normalized_path() | 7.7 High | Updated |
| 2026-10-03 | CVE-2026-93196 | Linux Kernel nvdimm: virtio_pmem: refcount requests for token lifetime | 8.4 High | Updated |
| 2026-10-03 | CVE-2026-90030 | Linux Kernel usb: dwc3: clear forceRM when issuing EndTransfer | 7.8 High | Updated |
| 2026-10-03 | CVE-2026-90016 | Linux Kernel staging: rtl8723bs: fix OOB read in rtw_restruct_wmm_ie() | 7.1 High | Updated |
| 2026-10-03 | CVE-2026-90013 | Linux Kernel tracing: Take trace_array reference when opening options file | 7.8 High | Updated |
| 2026-10-03 | CVE-2026-90002 | Linux Kernel ftrace: Take trace_array reference before accessing its ftrace_ops | 7.8 High | Updated |
| 2026-10-03 | CVE-2026-89972 | Linux Kernel nvme: Failure to Add missing SRCU grace period in error path, Reachable Without Authentication (CVSS 9.8) | 9.8 Critical | Updated |
| 2026-10-03 | CVE-2026-89971 | Linux Kernel nvme: skip the zoned limits update if the zone info query failed, Reachable from the Network Without Credentials (CVSS 7.5) | 7.5 High | Updated |
| 2026-10-03 | CVE-2026-89840 | Linux Kernel f2fs: Failure to Validate MOVE_RANGE destination size | 7.1 High | Updated |
| 2026-10-03 | CVE-2026-89838 | Linux Kernel f2fs: limit recovery filename logging to stored length | 7.1 High | Updated |
| 2026-10-03 | CVE-2026-89832 | Linux Kernel f2fs: Failure to Fix to clear dirty flag on folio in error path | 7.8 High | Updated |
| 2026-10-03 | CVE-2026-89806 | Linux Kernel drm/sysfb: ofdrm: Fix integer overflow in fb_size calculation | 8.4 High | Updated |
| 2026-10-03 | CVE-2026-89795 | Linux Kernel PCI: Allow per function PCI slots to fix slot reset on s390 | 8.4 High | Updated |
| 2026-10-03 | CVE-2026-89792 | Linux Kernel ksmbd: Failure to Prevent out-of-bounds reads in share config responses | 7.1 High | Updated |
| 2026-10-03 | CVE-2026-89560 | Linux Kernel landlock: Require LANDLOCK_ACCESS_FS_MAKE_REG for whiteout creation | 8.4 High | Updated |
| 2026-10-03 | CVE-2026-89520 | Linux Kernel sched/core: Make core-sched flips wait for in-flight selections | 7.8 High | Updated |
| 2026-10-03 | CVE-2026-89503 | Linux Kernel ring-buffer: Failure to Fix subbuf resize race with ring_buffer_alloc_read_page() | 7.8 High | Updated |
| 2026-10-03 | CVE-2026-89500 | Linux Kernel ring-buffer: Make cpu_buffer::free_page a buffer_data_read_page | 7.8 High | Updated |
| 2026-10-03 | CVE-2026-89452 | Linux Kernel iommu/msm: Unwind probe state on registration failure | 8.4 High | Updated |
| 2026-10-03 | CVE-2026-89445 | Linux Kernel iommufd: Failure to Fix UAF in selftest IOPF reporting | 8.8 High | Updated |
| 2026-10-03 | CVE-2026-89441 | Linux Kernel mmc: via-sdmmc: cancel card-detect work on remove | 7.8 High | Updated |
| 2026-10-03 | CVE-2026-81016 | Linux Kernel platform/x86/amd/pmc: Propagate SMU errors and validate S2D address | 7.7 High | Updated |
| 2026-10-03 | CVE-2026-81015 | Linux Kernel platform/x86/amd/pmc: Failure to Fix LPS0 and debugfs leaks when STB init fails | 7.8 High | Updated |
| 2026-10-03 | CVE-2026-80980 | Linux Kernel net/smc: stop killed, freed and out_of_sync sharing a byte, Reachable Without Authentication (CVSS 9.8) | 9.8 Critical | Updated |
| 2026-10-03 | CVE-2026-80937 | Linux Kernel wifi: mt76: mt7915: bound the device EEPROM address before the EFUSE copy | 8.8 High | Updated |
| 2026-10-03 | CVE-2026-80935 | Linux Kernel wifi: mt76: mt7996: bound the device EEPROM address before the EFUSE copy | 8.8 High | Updated |
| 2026-10-03 | CVE-2026-80926 | Linux Kernel ksmbd: Failure to Fix use-after-free in oplock break notification, Reachable Without Authentication (CVSS 9.8) | 9.8 Critical | Updated |
| 2026-10-03 | CVE-2026-80726 | Linux Kernel KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page (CVSS 9.3) | 9.3 Critical | Updated |
| 2026-10-03 | CVE-2026-80521 | Linux Kernel af_unix: Unlink scc_entry in unix_del_edge() | 7.8 High | Updated |
| 2026-10-03 | CVE-2026-76504 | CISA's October 3rd KEV Remediation Deadline for Cisco Catalyst SD-WAN Manager URI Encoding Bypass Has Passed; Covered Entities Still Exposed Are Out of Compliance | 9.8 Critical | KEV |
| 2026-10-03 | CVE-2026-74743 | Linux Kernel macvlan: inherit needed_headroom and needed_tailroom from lowerdev, Reachable Without Authentication (CVSS 9.8) | 9.8 Critical | Updated |
| 2026-10-03 | CVE-2026-74521 | Linux Kernel ksmbd: Failure to Use memcmp() to compare ClientGUIDs, Reachable Without Authentication (CVSS 9.1) | 9.1 Critical | Updated |
| 2026-10-03 | CVE-2026-74496 | Linux Kernel fou: Failure to Fix use-after-free in fou_create() | 7.8 High | Updated |
| 2026-10-03 | CVE-2026-74347 | Linux Kernel netfilter: cttimeout: detach dataplane timeout policy and repurpose refcount | 7.8 High | Updated |
| 2026-10-03 | CVE-2026-74294 | Linux Kernel ASoC: meson: aiu: Validate written enum values | 7.3 High | Updated |
| 2026-10-03 | CVE-2026-74289 | Linux Kernel ipv4: fib: Don't dump dying fib_info in fib_leaf_notify() | 7.8 High | Updated |
| 2026-10-03 | CVE-2026-74258 | Linux Kernel bpf: Guard __get_user acesss with access_ok for uprobe_multi data | 7.8 High | Updated |
| 2026-10-03 | CVE-2026-72496 | Linux Kernel RDMA/bnxt_re: Proper rollback if the ioremap fails (CVSS 9.2) | 9.2 Critical | Updated |
| 2026-10-03 | CVE-2026-72485 | Linux Kernel coresight: platform: defer connection counter increment until alloc succeeds | 7.8 High | Updated |
| 2026-10-03 | CVE-2026-72334 | Linux Kernel Bluetooth: ISO: fix malformed ISO_END/CONT handling | 8.8 High | Updated |
| 2026-10-03 | CVE-2026-68391 | Linux Kernel Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds | 7.8 High | Updated |
| 2026-10-03 | CVE-2026-68287 | Linux Kernel drop_monitor: Failure to Fix size calculations for 64-bit attributes, Reachable from the Network Without Credentials (CVSS 7.5) | 7.5 High | Updated |
| 2026-10-03 | CVE-2026-68236 | Linux Kernel drm/amd/display: set new_stream to NULL after release | 7.8 High | Updated |
| 2026-10-03 | CVE-2026-68161 | Linux Kernel sctp: close UDP tunnel sockets during netns teardown, Reachable Without Authentication (CVSS 9.8) | 9.8 Critical | Updated |
| 2026-10-03 | CVE-2026-68155 | Linux Kernel libceph: Reject monmaps advertising zero monitors, Reachable from the Network Without Credentials (CVSS 7.5) | 7.5 High | Updated |
| 2026-10-03 | CVE-2026-68097 | Linux Kernel ksmbd: Failure to Validate ACE size against SID sub-authorities | 8.8 High | Updated |
| 2026-10-03 | CVE-2026-53359 | Linux Kernel KVM: x86: Fix shadow paging use-after-free due to unexpected role | 8.8 High | Updated |
| 2026-10-03 | CVE-2026-53005 | Linux Kernel AF_UNIX SOCKMAP Redirect Hides Inflight File Descriptors from the Garbage Collector, Leaking Inflight Sockets Indefinitely | 7.8 High | Updated |
| 2026-10-03 | CVE-2026-52988 | Linux Kernel netfilter: nf_tables: join hook list via splice_list_rcu() in commit phase | 7.1 High | Updated |
| 2026-10-03 | CVE-2026-46242 | Linux Kernel eventpoll: Failure to Fix ep_remove struct eventpoll / struct file UAF | 7.8 High | Updated |
| 2026-10-03 | CVE-2026-46113 | Linux Kernel KVM: x86: Fix shadow paging use-after-free due to unexpected GFN | 8.8 High | Updated |
| 2026-10-03 | CVE-2026-20273 | Cisco IOS XE's Improper Input Validation Allows a Remote Attacker to Trigger a Device Crash or Disruption via a Specially Crafted Input | 8.6 High | Updated |
| 2026-10-03 | CVE-2026-20272 | Cisco IOS XE's Injection Flaw Allows Remote Attackers to Execute Arbitrary Commands via a Specially Crafted Input Reaching a Downstream Component | 9.8 Critical | Updated |
| 2026-10-03 | CVE-2026-20271 | Cisco IOS XE's Insufficient Control Flow Management Allows a Remote Attacker to Disrupt Device Operation via a Crafted Packet | 8.6 High | Updated |
| 2026-10-03 | CVE-2026-20270 | Cisco IOS XE's Incorrect Calculation Vulnerability Allows a Remote Attacker to Cause an Unrecoverable Device Condition via a Specially Crafted Input | 8.6 High | Updated |
| 2026-10-03 | CVE-2026-20269 | Cisco IOS XE's Improper Resource Lifetime Management Allows Remote Attackers to Exhaust Device Resources and Cause a Denial of Service | 8.6 High | Updated |
| 2026-10-03 | CVE-2026-20268 | Cisco IOS XE's Improper Restriction of Memory Buffer Operations Allows Remote Attackers to Potentially Execute Code or Crash the Device via a Malformed Packet | 8.6 High | Updated |
| 2026-10-03 | CVE-2026-20267 | Cisco IOS XE's Improper Access Control Allows Network-Based Attackers to Access Protected Functions or Data Without Proper Authorization | 9.0 Critical | Updated |
| 2026-10-02 | CVE-2026-98163 | Linux Kernel cgroup: Failure to Avoid iteration of dying tasks with zero refcount | 7.0 High | Updated |
| 2026-10-02 | CVE-2026-98115 | Linux Kernel ksmbd: Failure to Safely drain sessions during logoff | 8.8 High | Updated |
| 2026-10-02 | CVE-2026-97415 | Linux Kernel btrfs: tree-checker: validate names in ROOT_REF and ROOT_BACKREF | 7.8 High | Updated |
| 2026-10-02 | CVE-2026-86326 | Moxa MGate MB3170 Series Security Vulnerability Exploitable by Authenticated Admin Network Attackers (CVSS 8.6) | 8.6 High | Updated |
| 2026-10-02 | CVE-2026-86325 | Moxa MGate MB3170 Series Buffer Overflow Exploitable by Low-Privilege Network Attackers (CVSS 9.4) | 9.4 Critical | Updated |
| 2026-10-02 | CVE-2026-84411 | MikroTik RouterOS Remote Code Execution Reachable Without Authentication at CVSS 9.8 | 9.8 Critical | Updated |
| 2026-10-02 | CVE-2026-75937 | Digi International IX Family Security Vulnerability Reachable by Adjacent Unauthenticated Attackers (CVSS 9.4) | 9.4 Critical | Updated |
| 2026-10-02 | CVE-2026-71452 | Johnson Controls EasyIO FS32 Command Injection Exploitable by Authenticated Admin Adjacent-Network Attackers (CVSS 7.2) | 7.2 High | Updated |
| 2026-10-02 | CVE-2026-71449 | Johnson Controls EasyIO FS32 Security Vulnerability Reachable Without Authentication at CVSS 9.3 | 9.3 Critical | Updated |
| 2026-10-02 | CVE-2026-64893 | Johnson Controls EasyIO NEO Security Vulnerability Exploitable by Low-Privilege Network (High-Complexity Exploit) Attackers (CVSS 7.3) | 7.3 High | Updated |
| 2026-10-02 | CVE-2026-64008 | Linux Kernel accel/rocket: Failure to Fix UAF via dangling GEM handle in create_bo | 7.8 High | Updated |
| 2026-10-02 | CVE-2026-64001 | Linux Kernel ALSA: pcm: oss: Fix setup list UAF on proc write error | 7.8 High | Updated |
| 2026-10-02 | CVE-2026-63996 | Linux Kernel ethtool: cmis: require exact CDB reply length | 7.8 High | Updated |
| 2026-10-02 | CVE-2026-63993 | Linux Kernel vxlan: Missing Guard: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu(), Reachable Without Authentication (CVSS 9.8) | 9.8 Critical | Updated |
| 2026-10-02 | CVE-2026-63975 | Linux Kernel Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp | 8.8 High | Updated |
| 2026-10-02 | CVE-2026-63972 | Linux Kernel net: mana: Skip redundant detach on already-detached port, Reachable from the Network Without Credentials (CVSS 7.5) | 7.5 High | Updated |
| 2026-10-02 | CVE-2026-63971 | Linux Kernel sctp: Failure to Fix race between sctp_wait_for_connect and peeloff | 7.8 High | Updated |
| 2026-10-02 | CVE-2026-63970 | Linux Kernel vsock/virtio: bind uarg before filling zerocopy skb | 7.8 High | Updated |
| 2026-10-02 | CVE-2026-58016 | Enterprise Linux GLib Out-of-Bounds Read Reachable by Unauthenticated Remote Attackers (CVSS 7.5) | 7.5 High | Updated |
| 2026-10-02 | CVE-2026-58014 | Enterprise Linux GLib Denial of Service Reachable by Unauthenticated Remote Attackers (CVSS 7.3) | 7.3 High | Updated |
| 2026-10-02 | CVE-2026-55396 | Teledyne FLIR Aware2 Security Vulnerability Reachable by Adjacent Unauthenticated Attackers (CVSS 8.5) | 8.5 High | Updated |
| 2026-10-02 | CVE-2026-55395 | Teledyne FLIR Aware2 Security Vulnerability Reachable by Adjacent Unauthenticated Attackers (CVSS 9.4) | 9.4 Critical | Updated |
| 2026-10-02 | CVE-2026-55393 | Teledyne FLIR Aware2 Path Traversal Reachable Without Authentication at CVSS 10.0 | 10.0 Critical | Updated |
| 2026-10-02 | CVE-2026-48864 | Enterprise Linux libsolv Buffer Overflow Reachable by Unauthenticated Local Attackers (CVSS 7.8) | 7.8 High | Updated |
| 2026-10-02 | CVE-2026-42010 | Enterprise Linux gnutls Authorization Bypass Reachable by Low-Privilege Remote Attackers (CVSS 7.1) | 7.1 High | Updated |
| 2026-10-02 | CVE-2026-42009 | Enterprise Linux gnutls Denial of Service Reachable by Unauthenticated Remote Attackers (CVSS 7.5) | 7.5 High | Updated |
| 2026-10-02 | CVE-2026-34494 | Johnson Controls Neo Series MVP2 Unauthenticated Security Vulnerability over Network (CVSS 7.2) | 7.2 High | Updated |
| 2026-10-02 | CVE-2026-34493 | Johnson Controls EasyIO FS32 Unauthenticated Security Vulnerability over Network (CVSS 7.2) | 7.2 High | Updated |
| 2026-10-02 | CVE-2026-33845 | Enterprise Linux Out-of-Bounds Read Reachable by Unauthenticated Remote Attackers (CVSS 7.5) | 7.5 High | Updated |
| 2026-10-02 | CVE-2026-17523 | Linux Kernel can: bcm: switch timer to HRTIMER_MODE_SOFT and remove hrtimer_tasklet | 7.8 High | Updated |
| 2026-10-02 | CVE-2026-14984 | Teledyne FLIR Aware2 Security Vulnerability Reachable by Adjacent Unauthenticated Attackers (CVSS 9.4) | 9.4 Critical | Updated |
| 2026-10-02 | CVE-2026-14983 | Teledyne FLIR Aware2 Denial of Service Reachable by Adjacent Unauthenticated Attackers (CVSS 7.1) | 7.1 High | Updated |
| 2026-10-02 | CVE-2026-104286 | Fortinet FortiMail Unauthenticated Arbitrary File Write via Path Traversal Carries an October 4th CISA KEV Federal Remediation Requirement for Covered Entities | 9.8 Critical | KEV |
| 2026-10-02 | CVE-2026-102490 | Zammad Local Privilege Escalation to Root via Improper Privilege Management Carries an October 5th CISA KEV Federal Deadline for Covered Organizations | 9.8 Critical | KEV |
| 2026-10-02 | CVE-2026-102489 | Zammad Session Fixation Enabling Remote Code Execution as the Zammad User Carries an October 5th CISA KEV Federal Deadline for Covered Organizations | 9.8 Critical | KEV |
| 2026-10-02 | CVE-2026-100075 | Linux Kernel RDMA/srpt: Failure to Fix srpt_alloc_rw_ctxs() unwind counters, Reachable Without Authentication (CVSS 9.8) | 9.8 Critical | Updated |
| 2026-10-01 | CVE-2026-8037 | Progress LoadMaster's Command Injection Flaw Allows Unauthenticated Remote Attackers to Execute Arbitrary OS Commands on the Load Balancer Appliance; CISA's August 10th KEV Deadline Has Passed | 9.6 Critical | KEV |
| 2026-10-01 | CVE-2026-69594 | Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally | 7.8 High | Updated |
| 2026-10-01 | CVE-2026-69576 | Use after free in Graphic Fonts allows an authorized attacker to elevate privileges locally | 7.8 High | Updated |
| 2026-10-01 | CVE-2026-69549 | Out-of-bounds read in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally | 7.0 High | Updated |
| 2026-10-01 | CVE-2026-69546 | Use after free in Active Directory Domain Services allows an unauthorized attacker to execute code over a network | 8.1 High | Updated |
| 2026-10-01 | CVE-2026-69541 | Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally | 7.8 High | Updated |
| 2026-10-01 | CVE-2026-69524 | Use after free in Active Directory Domain Services allows an unauthorized attacker to execute code over a network | 8.1 High | Updated |
| 2026-10-01 | CVE-2026-48710 | Kludex Starlette's HTTP Request Smuggling Vulnerability Allows Network-Adjacent Attackers to Bypass Security Controls and Poison Shared HTTP Connections | 6.5 Medium | KEV |
| 2026-10-01 | CVE-2026-42965 | OpenShift Container Platform Security Flaw Reachable by Low-Privilege Remote Attackers (CVSS 7.7) | 7.7 High | Updated |
| 2026-10-01 | CVE-2026-3012 | Enterprise Linux Samba’s Security Flaw Reachable by Unauthenticated Adjacent-Network Attackers (CVSS 8.0) | 8.0 High | Updated |
| 2026-10-01 | CVE-2026-1784 | OpenShift Container Platform Injection Reachable by Low-Privilege Local Attackers (CVSS 8.8) | 8.8 High | Updated |
| 2026-10-01 | CVE-2025-41753 | WAGO 0751-9x01 Security Vulnerability Reachable Without Authentication at CVSS 9.8 | 9.8 Critical | Updated |
| 2026-09-30 | CVE-2026-41940 | WebPros cPanel and WHM's Login Flow Authentication Bypass Gives Unauthenticated Attackers Unauthorized Access to the Control Panel; CISA's May 3rd KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-28 | CVE-2026-20263 | Cisco IOS XE BEEP Feature Crashes on a Specific Malformed SOAP Request, Enabling Unauthenticated Remote Denial of Service | 8.6 High | Updated |
| 2026-09-26 | CVE-2026-80152 | Lantronix SLC/EMG/SLB Web Management Services Endpoint Lets Authenticated Users Inject OS Commands as Root | 9.1 Critical | Updated |
| 2026-09-26 | CVE-2026-80151 | Lantronix SLC/EMG/SLB Web Management Services Endpoint Contains a Second Command Injection Path Allowing Root Execution by Authenticated Users | 9.1 Critical | Updated |
| 2026-09-26 | CVE-2026-80150 | Lantronix SLC8000/SLC9000/EMG/SLB882 WebSSH Listener Accepts Unauthenticated Server-Side Request Forgery Targets | 7.5 High | Updated |
| 2026-09-26 | CVE-2026-80149 | Lantronix WebSSH and WebTelnet Server-Side Request Forgery Lets Unauthenticated Attackers Redirect Device Requests to Internal Hosts | 8.6 High | Updated |
| 2026-09-26 | CVE-2026-80148 | Lantronix SLC/EMG/SLB882 WebSSH Listener Processes SSRF Probes From Unauthenticated Callers, Enabling Internal Network Mapping | 8.6 High | Updated |
| 2026-09-26 | CVE-2026-80146 | A Second Lantronix SLC/EMG/SLB Stack Buffer Overflow via Undocumented Interface Allows Authenticated Attackers to Execute Arbitrary Code | 9.9 Critical | Updated |
| 2026-09-26 | CVE-2026-67279 | MikroTik RouterOS Unauthenticated Session Bypass Carries Federal Remediation Deadline of September 28 | 6.5 Medium | KEV |
| 2026-09-25 | CVE-2026-93616 | Path Traversal Across Check Point Management and Log Server Infrastructure Missed the September 25th CISA KEV Window; Covered Organizations Are Now Out of Compliance | 9.8 Critical | KEV |
| 2026-09-25 | CVE-2026-85046 | Google Chromium V8's Type Confusion Allows Remote Attackers to Execute Arbitrary Code or Escape the Browser Sandbox via a Crafted Web Page | 8.8 High | KEV |
| 2026-09-25 | CVE-2026-81578 | PaperCut NG/MF's Missing Authentication on a Critical Function Allows Unauthenticated Attackers to Perform Administrative Actions Without Logging In; CISA's September 14th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-25 | CVE-2026-76461 | Cisco Secure Email Gateway's SQL Injection Flaw Allows Unauthenticated Attackers to Execute Arbitrary Database Queries and Compromise the Email Security Platform | 9.8 Critical | KEV |
| 2026-09-25 | CVE-2026-76460 | Cisco Identity Services Engine's Incorrect Use of Privileged APIs Allows Unauthenticated Remote Attackers to Gain Full Administrative Control; CISA's September 19th KEV Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-25 | CVE-2026-75650 | Adobe Commerce and Magento's Template Engine Injection Flaw Allows Unauthenticated Remote Attackers to Execute Arbitrary Server-Side Code on the E-Commerce Platform | 10.0 Critical | KEV |
| 2026-09-25 | CVE-2026-97941 | Linux Kernel SLAB Allocator Optimistic Freelist Return Races Against Concurrent Object Free, Enabling Local Privilege Escalation | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-97940 | Linux Kernel IPv6 fib6 Route Walker Use-After-Free on seq Stop Allows Local Privilege Escalation | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-97937 | Linux Kernel ftrace Function Graph State Initialized After Task Structure Copy, Enabling Local Privilege Escalation on Fork | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-97931 | Linux Kernel ALSA us122l mmap Leaves VM_MAYWRITE on Read-Only Mappings, Enabling Privilege Escalation | 7.0 High | Updated |
| 2026-09-25 | CVE-2026-97926 | Linux Kernel UFS Filesystem Caches On-Disk Cylinder Group Metadata Without Validation, Enabling Local Memory Corruption | 7.0 High | Updated |
| 2026-09-25 | CVE-2026-97911 | Linux Kernel Arm Ethos-U NPU Driver Allows Zero-Size SRAM Job Configuration While Command Stream Still Accesses SRAM | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-97910 | Linux Kernel Spreadtrum ASoC Compress Driver Does Not Validate Buffer Sizes Against Fixed Allocations, Enabling Local Privilege Escalation | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-97903 | Linux Kernel Process Exit Releases thread_pid Reference Before proc_flush_pid Completes, Enabling Use-After-Free | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-97612 | Linux Kernel MPLS Stack Pop Leaves Stale Inner Protocol Record Set by Prior Push, Enabling Local Memory Corruption | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-97611 | Linux Kernel Open vSwitch Flow Table Mask Array Retired to RCU Before Last Dereference Completes, Enabling Use-After-Free | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-97609 | Linux Kernel Netfilter Connection Timeout Module Unload Unregisters Per-Net Operations Before Clearing Global Hook, Enabling Use-After-Free | 7.0 High | Updated |
| 2026-09-25 | CVE-2026-97608 | Linux Kernel Netfilter Logger Teardown Leaves sysctl Exposed After Logger Unregistered but Before Backend Removed | 7.0 High | Updated |
| 2026-09-25 | CVE-2026-97602 | Linux Kernel IP Fragment Queue Flushed While Completion State Unchanged Allows Concurrent Fragment to Acquire Lock | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-97595 | Linux Kernel 802.15.4 Receiver Queues Beacon Frames Against Interface Being Torn Down, Enabling Use-After-Free | 7.5 High | Updated |
| 2026-09-25 | CVE-2026-97594 | Linux Kernel Landlock Security Module Reads Parent Directory Without Reference or Lock, Enabling Use-After-Free | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-97589 | Linux Kernel s390 Crypto Engine Wrong Async Callback Return Code Causes Request Re-queue Loop, Enabling Denial of Service | 7.0 High | Updated |
| 2026-09-25 | CVE-2026-97584 | Linux Kernel AFS Server Lookup Frees Existing Endpoint State When Cleaning Up Candidate, Enabling Use-After-Free | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-97583 | Linux Kernel AFS File Server Leaves Stale Peer App Data After Address List Change, Causing Crash on Reconnect | 7.5 High | Updated |
| 2026-09-25 | CVE-2026-97580 | Linux Kernel Rockchip HEVC Decoder Unbounded Tile Loop and Unvalidated PPS ID Enable Local Privilege Escalation | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-97579 | Linux Kernel MediaTek AV1 Video Decoder Tile Start Array Copy Exceeds Array Capacity, Enabling Local Privilege Escalation | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-97578 | Linux Kernel Rockchip VPU981 AV1 Decoder Missing Divisor Guard Allows Local Privilege Escalation | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-97577 | Linux Kernel Rockchip VPU981 AV1 Decoder Tile Group Entry Indexing Past Array Capacity Enables Local Privilege Escalation | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-97576 | Linux Kernel V4L2 Stateless HEVC Decoder Uses Unvalidated Tile Counts as Loop Bounds, Enabling Local Privilege Escalation | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-97575 | Linux Kernel V4L2 Stateless AV1 Decoder Uses Unvalidated Tile Counts as Array Indices and Loop Bounds, Enabling Local Privilege Escalation | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-97573 | Linux Kernel Broadcom bnxt_en Ignores Ring Buffer Allocation Failure During RX Ring Reset, Enabling Local Memory Corruption | 8.1 High | Updated |
| 2026-09-25 | CVE-2026-97570 | Linux Kernel Broadcom bnxt_en TPA ID Indexing Without Software Bound Allows Memory Corruption on High-ID Aggregations | 8.1 High | Updated |
| 2026-09-25 | CVE-2026-97562 | Linux Kernel CIFS DFS Superblock Iterator Stores Raw Pointer Before Reference Acquired, Enabling Race-Condition Use-After-Free | 7.5 High | Updated |
| 2026-09-25 | CVE-2026-97557 | Linux Kernel CIFS Oplock Break Queue Takes File Reference Unconditionally, Leaking It on Failure Paths | 7.5 High | Updated |
| 2026-09-25 | CVE-2026-97555 | Linux Kernel CIFS DACL Rewrite Allocates Buffer From On-Disk Length Then Writes Beyond It, Enabling Cross-Scope Heap Overflow | 8.8 High | Updated |
| 2026-09-25 | CVE-2026-97548 | Linux Kernel XFS Realtime Block Map and Refcount Cursor Size Miscalculation Enables Local Memory Corruption | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-97536 | Linux Kernel Qla2xxx FC Adapter Schedules Work Against Queue Pair Freed During Teardown, Enabling Use-After-Free | 7.5 High | Updated |
| 2026-09-25 | CVE-2026-97531 | Linux Kernel Qla2xxx FC Driver Takes Reference on Vport Under Active Deletion, Enabling Use-After-Free | 7.5 High | Updated |
| 2026-09-25 | CVE-2026-97528 | Linux Kernel Qla2xxx NVMe Unsolicited Context Freed While Still Linked in fcport List, Enabling Cross-Scope Use-After-Free | 8.8 High | Updated |
| 2026-09-25 | CVE-2026-97527 | Linux Kernel Qla2xxx NVMe Unsolicited Context List Modified From Multiple Contexts Without Locking, Enabling Cross-Scope Use-After-Free | 8.8 High | Updated |
| 2026-09-25 | CVE-2026-97525 | Linux Kernel x86 PAT Large-Page Split Allocates Page Tables Outside Standard Path, Enabling Cross-Scope Memory Corruption | 8.2 High | Updated |
| 2026-09-25 | CVE-2026-97524 | Linux Kernel MPTCP Subflow Reset Triggers Recursive Data-Ready Call, Causing Double Lock and Denial of Service | 7.5 High | Updated |
| 2026-09-25 | CVE-2026-97523 | Linux Kernel MPTCP Scheduler Uses Zero MSS When Subflow State Changes Race Data Transmission | 7.5 High | Updated |
| 2026-09-25 | CVE-2026-97445 | Linux Kernel ACPICA AML Resource Walker Insufficient Buffer Validation Allows Cross-Scope Overflow | 7.7 High | Updated |
| 2026-09-25 | CVE-2026-97444 | Linux Kernel ACPICA Parser Missing Boundary Checks in Two Namestring and Opcode Functions Allow Out-of-Scope Memory Access | 7.7 High | Updated |
| 2026-09-25 | CVE-2026-97442 | Linux Kernel ath11k Wi-Fi Driver Out-of-Bounds Write on Oversized Native Wi-Fi Headers Enables Cross-Scope Memory Corruption | 8.8 High | Updated |
| 2026-09-25 | CVE-2026-97438 | Linux Kernel NTFS3 Directory Index Entry Accepts Advertised key_size Exceeding Actual Payload, Enabling Out-of-Bounds Read | 7.1 High | Updated |
| 2026-09-25 | CVE-2026-97437 | Linux Kernel NTFS3 Directory Entry Bounds Check Confuses Character Count with Byte Count, Enabling Out-of-Bounds Read | 7.1 High | Updated |
| 2026-09-25 | CVE-2026-97433 | Linux Kernel NVMe FDP Configuration Log Parser Accepts Zero Descriptor Size, Enabling Unbounded Iteration and Cross-Scope Memory Access | 8.2 High | Updated |
| 2026-09-25 | CVE-2026-97429 | Linux Kernel AMD KFD Queue Destruction Drops Locks While Waiting for Resume, Enabling Concurrent Use-After-Free | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-97428 | Linux Kernel AMD GPU FRU PIA TLV Parser Reads EEPROM Data Without Bounds, Allowing Cross-Scope Out-of-Bounds Access | 7.7 High | Updated |
| 2026-09-25 | CVE-2026-97421 | Linux Kernel RDMA umem iova Truncated to 32-Bit on Page-Size Selection, Enabling Local Memory Corruption | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-97417 | Linux Kernel Netfilter Connection Tracker TCP SACK Parser Dereferences Unaligned Pointer, Enabling Remote Memory Corruption | 7.5 High | Updated |
| 2026-09-25 | CVE-2026-97413 | Linux Kernel RDMA/RTRS Server Integer Underflow in Network-Supplied Length Field Enables Unauthenticated Remote Code Execution | 9.8 Critical | Updated |
| 2026-09-25 | CVE-2026-97409 | Linux Kernel NVMe-FC Aborts Inflight Admin Requests Before Controller Initialization Completes, Enabling Out-of-Scope Memory Corruption | 8.8 High | Updated |
| 2026-09-25 | CVE-2026-93830 | Linux Kernel stmmac XGMAC2 Default Interrupt Mask Triggers a MAC Interrupt Storm Reaching 695 Times the Actual RX Completion Rate | 7.5 High | Updated |
| 2026-09-25 | CVE-2026-93827 | Linux Kernel virtio-fs Double-Free on Failed Queue Setup Leads to Cross-Component Memory Corruption | 8.4 High | Updated |
| 2026-09-25 | CVE-2026-93826 | Linux Kernel HID++ Driver Keeps Stale Input Device Pointer After Failed Registration, Enabling Use-After-Free | 7.5 High | Updated |
| 2026-09-25 | CVE-2026-93817 | Linux Kernel perf Subsystem addr_filter_ranges RCU Use-After-Free Exposes Local Privilege Escalation | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-93816 | Linux Kernel F2FS Inline Dentry Conversion Copies Names Before Validating Length Against Available Slots, Enabling Out-of-Bounds Write | 7.1 High | Updated |
| 2026-09-25 | CVE-2026-93813 | Linux Kernel btrfs Tree Checker Accepts Malformed INODE_REF namelen, Enabling Local Privilege Escalation via Crafted Image | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-93810 | Linux Kernel cachefiles Double File Reference Release in tmpfile Error Path Allows Local Privilege Escalation | 7.0 High | Updated |
| 2026-09-25 | CVE-2026-93806 | Linux Kernel cfg80211 Wi-Fi Association Response Parser Accesses Status Fields Before Length Validation, Enabling Cross-Scope Memory Corruption | 8.8 High | Updated |
| 2026-09-25 | CVE-2026-93801 | Linux Kernel CIFS Client Stack-Allocated cifs_open_info_data May Expose Uninitialized Kernel Memory | 7.0 High | Updated |
| 2026-09-25 | CVE-2026-93799 | Linux Kernel iwlwifi BA Window Status Handler Indexes Station Data Using Unvalidated Firmware-Supplied ID, Enabling Out-of-Scope Write | 8.8 High | Updated |
| 2026-09-25 | CVE-2026-93798 | Linux Kernel btrfs Relocation Root Reset Without Memory Barrier Exposes Race Condition Leading to Local Privilege Escalation | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-93796 | Linux Kernel iwlwifi PCIe Transport Keeps Non-Null RX Pointers After Free, Enabling Use-After-Free on Reinitialize | 7.0 High | Updated |
| 2026-09-25 | CVE-2026-93793 | Linux Kernel iwlwifi TX_CMD Response Parser Uses Firmware-Supplied frame_count Without Validation, Allowing Out-of-Scope Memory Access | 8.8 High | Updated |
| 2026-09-25 | CVE-2026-93790 | Linux Kernel iwlwifi BA Handler Indexes tid_data by Loop Counter Instead of Actual TID, Enabling Cross-Scope Out-of-Bounds Write | 8.8 High | Updated |
| 2026-09-25 | CVE-2026-93787 | Linux Kernel CIFS filldir Copies Directory Entry Name Using Server-Supplied Length Without Bounding to Response, Enabling Heap Overflow | 8.1 High | Updated |
| 2026-09-25 | CVE-2026-93786 | Linux Kernel ksmbd SMB Server Mutates Parent POSIX ACL Instead of Inheriting It, Corrupting Child Access Permissions | 8.1 High | Updated |
| 2026-09-25 | CVE-2026-93782 | Linux Kernel vhost-scsi Races VHOST_SET_MEM_TABLE Against Async Command Completion, Enabling Local Privilege Escalation | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-93345 | MikroTik RouterOS Labelled-VPN NLRI Iterator Accepts Below-Minimum Prefix Length in BGP UPDATE, Enabling On-Path Service Crash | 7.5 High | Updated |
| 2026-09-25 | CVE-2026-93288 | Linux Kernel Netfilter Logging Namespace Teardown Clears Logger Pointer Without RCU Grace Period, Enabling Use-After-Free | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-93287 | Linux Kernel I2C SMBus Block Transfer Length Validated After Tracepoint Use, Enabling Local Memory Corruption | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-93284 | Linux Kernel DRM Pagemap Migration Clears Page Array Before DMA Unmap Walk, Enabling Out-of-Scope Memory Corruption on Failure | 8.8 High | Updated |
| 2026-09-25 | CVE-2026-93282 | Linux ksmbd Accumulates ACEs from Every Principal Rather Than the Requesting User, Granting Authenticated Network Clients File Rights They Were Not Assigned | 8.1 High | Updated |
| 2026-09-25 | CVE-2026-93280 | Linux Kernel Greybus Audio Driver Walks Module-Supplied Topology Sections Without Bounding Sub-Section Sizes, Enabling Local Code Execution | 8.8 High | Updated |
| 2026-09-25 | CVE-2026-93277 | Linux Kernel bnxt_re RDMA Destroy Callback Writes Output Before Validating Userspace Access, Enabling Double-Destroy Privilege Escalation | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-93265 | Linux Kernel tc9563 PCI Power Controller Misparses Integrated Ethernet MAC Endpoint, Enabling Cross-Component Impact | 7.7 High | Updated |
| 2026-09-25 | CVE-2026-93262 | Linux Kernel RAID5 PPL Log Flush Iterator Continues After Entry Freed, Enabling Use-After-Free | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-93260 | Linux Kernel PowerPC XIVE IPI Init Error Ignored in SMP Probe, Enabling Use-After-Free on Freed xive_ipis Array | 7.4 High | Updated |
| 2026-09-25 | CVE-2026-93250 | Linux Kernel VXLAN MDB Flush Continues Iterating Past Removed Entry, Enabling Use-After-Free | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-93237 | Linux Kernel LoongArch's Compile-Time DIRECT_MAP_PHYSMEM_END Ignores cpu_pabits, Letting vmemmap_populate() Wrap Into Low Memory and Corrupt Page Tables on Loongson-2K CPUs | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-93229 | Linux Kernel NFS Server RPC Status Dump Missing Read Memory Barrier Before Seqcount Retry Enables Information Disclosure Race | 7.1 High | Updated |
| 2026-09-25 | CVE-2026-93228 | Linux Kernel RDMA svcrdma Accepts Zero-Segment Write/Reply Chunks From Unauthenticated Peers, Enabling Remote Memory Corruption | 9.1 Critical | Updated |
| 2026-09-25 | CVE-2026-93225 | Linux Kernel fsl-imx8mq USB PHY Driver Leaks typec Switch Reference on Probe Failure | 7.4 High | Updated |
| 2026-09-25 | CVE-2026-93224 | Linux Kernel svcrdma Accept Error Path Calls Unregister Notification Before Register Succeeds, Enabling Double-Unregister Corruption | 8.1 High | Updated |
| 2026-09-25 | CVE-2026-93221 | Linux Kernel NFS Server Boolean Flags Accessed Without Serialization Enable Data Race Leading to Memory Corruption | 8.1 High | Updated |
| 2026-09-25 | CVE-2026-93207 | Linux Kernel SUNRPC GSS Credential Decoder Uses Uninitialized Stack Memory, Enabling Unauthenticated Remote Code Execution | 9.8 Critical | Updated |
| 2026-09-25 | CVE-2026-72463 | Linux Kernel xfrm IPsec Async Resumption Modifies Device Pointer Without Reference, Enabling Unauthenticated Remote Code Execution | 9.8 Critical | Updated |
| 2026-09-25 | CVE-2026-72315 | Linux Kernel CIFS Client Deferred Close Holds Dentry Reference, Causing Use-After-Free on Unmount After Direct I/O | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-69458 | Windows BitLocker Out-of-Bounds Read Lets Authorized Attackers Escalate Privileges Over a Network Connection | 8.0 High | Updated |
| 2026-09-25 | CVE-2026-69456 | Windows Speech Heap Buffer Overflow Spans Windows Server 2012 Through Server 2025, Letting Authorized Local Attackers Elevate Privileges | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-69455 | Windows Remote Access Connection Manager Heap Buffer Overflow Lets Authorized Local Attackers Escalate Privileges | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-69451 | Windows Management Instrumentation Use-After-Free Lets Authorized Attackers Escalate Privileges Over a Network Connection | 7.1 High | Updated |
| 2026-09-25 | CVE-2026-69448 | Windows Bluetooth Service Race Condition Lets a Local Low-Privilege User Gain Elevated Privileges on Windows 10, 11, and Server | 7.0 High | Updated |
| 2026-09-25 | CVE-2026-69447 | Windows Audio Service Heap Buffer Overflow Lets Authorized Local Attackers Elevate Privileges | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-69445 | Windows Compressed Folder Path Traversal Lets Authorized Local Attackers Elevate Privileges Across All Supported Windows Versions | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-69444 | Windows Speech Heap Buffer Overflow from Windows Server 2016 Upward Lets Authorized Local Attackers Elevate Privileges | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-69441 | Windows Installer Race Condition Lets Authorized Local Attackers Escalate Privileges Across All Supported Windows Versions | 7.0 High | Updated |
| 2026-09-25 | CVE-2026-69440 | Windows MIDI Service TOCTOU Race Condition Enables Local Privilege Escalation on Windows 11 | 7.0 High | Updated |
| 2026-09-25 | CVE-2026-69436 | Windows Error Reporting Heap Buffer Overflow from Windows 10 Version 1809 Upward Lets Authorized Local Attackers Escalate Privileges | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-69434 | Windows URL Moniker Heap Buffer Overflow Lets Unauthenticated Network Attackers Execute Code Across All Supported Windows Versions | 8.8 High | Updated |
| 2026-09-25 | CVE-2026-69433 | Windows Error Reporting Heap Buffer Overflow, Including Windows Server 2012, Lets Authorized Local Attackers Escalate Privileges | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-69396 | Windows NDIS Use-After-Free Lets Authorized Attackers Escalate Privileges Over a Network Connection | 7.1 High | Updated |
| 2026-09-25 | CVE-2026-69394 | Windows Audio Service Heap Buffer Overflow Lets a Low-Privilege Local User Elevate Privileges Across Windows 10 Through Server 2025 | 7.0 High | Updated |
| 2026-09-25 | CVE-2026-69392 | Windows Shell Use-After-Free Lets Authorized Local Attackers Escalate Privileges on Windows 11 and Server 2025 | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-69391 | Windows Broker Infrastructure Service Stack Buffer Overflow Lets Authorized Local Attackers Elevate Privileges | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-69389 | Windows Storage Management Provider Heap Buffer Overflow Lets Authorized Local Attackers Escalate Privileges | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-67281 | MikroTik RouterOS WebFig Stale Session Pointer Lets Unauthenticated Attackers Read Arbitrary Files | 7.5 High | Updated |
| 2026-09-25 | CVE-2026-67278 | MikroTik RouterOS Accepts Malformed RSA/PKCS#1 v1.5 Signatures Across TLS and SSH, and Its Trust Store Includes an e=3 Root CA, Letting a Network Attacker Forge Valid Signatures Without the Private Key | 9.1 Critical | Updated |
| 2026-09-25 | CVE-2026-5430 | WSO2 API Gateway Path Traversal Reaches Federal Remediation Deadline of September 27 | 10.0 Critical | KEV |
| 2026-09-25 | CVE-2026-33824 | Microsoft Windows IKE Service Extensions' Double Free Enables Unauthenticated Remote Attackers to Execute Arbitrary Code; CISA's August 21st KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-25 | CVE-2026-32157 | Windows Remote Desktop Client Use-After-Free Lets Unauthenticated Network Attackers Execute Code | 8.8 High | Updated |
| 2026-09-25 | CVE-2026-26174 | Windows Server Update Service Race Condition Lets Authorized Local Attackers Escalate Privileges Across All Supported Windows Versions | 7.0 High | Updated |
| 2026-09-25 | CVE-2026-20190 | Cisco Identity Services Engine Improper Authorization Exposes Sensitive Information to Unauthenticated Remote Attackers | 7.5 High | Updated |
| 2026-09-25 | CVE-2026-20147 | Critical Cisco ISE and ISE-PIC Command Injection Scores 9.9 | 9.9 Critical | EPSS-Imminent |
| 2026-09-24 | CVE-2026-71474 | Red Hat insights-client logs a long-lived OpenShift pull-secret token that local pod-log access can expose | 7.1 High | Updated |
| 2026-09-24 | CVE-2026-54100 | Red Hat's Windows Machine Config Operator skips SSH host-key checks, letting adjacent attackers capture node bootstrap credentials | 8.3 High | Updated |
| 2026-09-24 | CVE-2026-54099 | A compromised Windows node can forge a cluster-administrator certificate through WMCO's CSR auto-approver, CVSS 8.8 | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-4740 | Red Hat Advanced Cluster Management lets a managed-cluster admin forge certificates for cross-cluster privilege escalation | 8.2 High | Updated |
| 2026-09-24 | CVE-2026-40141 | A critical query-injection flaw in BeyondTrust Remote Support lets low-privileged users reach unauthorized resources, CVSS 9.9 | 9.9 Critical | Updated |
| 2026-09-24 | CVE-2026-40140 | Unauthenticated attackers can crash BeyondTrust Remote Support appliances via a network-communication flaw | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-40139 | Critical Pre-Authentication Bypass in BeyondTrust Remote Support Allows Unauthorized Access | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-40138 | BeyondTrust Privileged Remote Access Shares Pre-Authentication Bypass Flaw with Remote Support | 8.1 High | Updated |
| 2026-09-24 | CVE-2026-33105 | Critical Authorization Bypass in Microsoft Azure Kubernetes Service Allows Network Privilege Escalation | 10.0 Critical | Updated |
| 2026-09-24 | CVE-2026-32590 | Unsafe Deserialization in Red Hat Quay Resumable Upload Handling | 7.1 High | Updated |
| 2026-09-24 | CVE-2026-32153 | Use-After-Free in Windows Speech Component Allows Local Privilege Escalation | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-32091 | Race Condition in Microsoft Brokering File System Allows Unauthorized Privilege Escalation | 8.4 High | Updated |
| 2026-09-24 | CVE-2026-27914 | Improper Access Control in Microsoft Management Console Allows Local Privilege Escalation | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-27909 | Use-After-Free in Windows Search Component Allows Authorized Attacker to Escalate Privileges | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-26181 | Use-After-Free in Microsoft Brokering File System Lets Authorized User Escalate Privileges | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-26170 | Input Validation Flaw in Microsoft PowerShell Allows Local Privilege Escalation | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-23429 | Linux Kernel IOMMU SVA Use-After-Free in Unbind Path Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-23428 | Critical Linux Kernel ksmbd Use-After-Free in Compound Request Handling Scores 9.8 | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-23427 | Critical Linux Kernel ksmbd Use-After-Free in Durable Handle Replay Scores 9.8 | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-23425 | Linux Kernel KVM arm64 ID Register Initialization Flaw Scores 8.8 | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-23424 | Linux Kernel amdxdna Missing Command Buffer Validation Scores 7.1 | 7.1 High | Updated |
| 2026-09-24 | CVE-2026-23422 | Linux Kernel dpaa2-switch Out-of-Bounds Write from Malformed Interrupt Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-23415 | Linux Kernel Futex Use-After-Free between Key Lookup and VMA Policy Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-23414 | Linux Kernel TLS Memory Leak in Async Decrypt Wait Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-23413 | Linux Kernel clsact Use-After-Free in Init/Destroy Rollback Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-23412 | Linux Kernel Netfilter BPF Use-After-Free in Hook Memory Release Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-23411 | Linux Kernel AppArmor Race Condition Frees i_private Data Early Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-23410 | Linux Kernel AppArmor Race on Rawdata Dereference Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-23408 | Linux Kernel AppArmor Double Free of Namespace Name Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-23407 | Linux Kernel AppArmor Out-of-Bounds Read in DFA Verification Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-22619 | Eaton Intelligent Power Protector Uncontrolled Search Path Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-21662 | Critical Johnson Controls FMS Employee Unrestricted File Upload Scores 9.8 | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-20160 | Critical Cisco Smart Software Manager On-Prem Resource Exposure Scores 9.8 | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-20155 | Cisco Evolved Programmable Network Manager Missing Authorization Scores 8.0 | 8.0 High | Updated |
| 2026-09-24 | CVE-2026-20151 | Cisco Smart Software Manager On-Prem Leaks Sensitive Data in Transmitted Requests | 7.3 High | Updated |
| 2026-09-24 | CVE-2026-20094 | Cisco UCS Command Injection Scores 8.8 | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-16443 | Red Hat Build of Keycloak Cryptographic Signature Verification Flaw Scores 7.4 | 7.4 High | Updated |
| 2026-09-24 | CVE-2026-0265 | Palo Alto Networks PAN-OS Authentication Bypass Affects Siemens RUGGEDCOM APE1808, Scores 8.1 | 8.1 High | Updated |
| 2026-09-24 | CVE-2026-0264 | Critical Palo Alto Networks PAN-OS DNS Heap Overflow Affects Siemens RUGGEDCOM APE1808, Scores 9.8 | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-0262 | Palo Alto Networks PAN-OS Multiple Denial-of-Service Flaws Affect Siemens RUGGEDCOM APE1808 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-0261 | Palo Alto Networks PAN-OS Command Injection Affects Siemens RUGGEDCOM APE1808, Scores 7.2 | 7.2 High | Updated |
| 2026-09-24 | CVE-2026-0258 | Palo Alto Networks PAN-OS IKEv2 SSRF Affects Siemens RUGGEDCOM APE1808, Scores 9.1 | 9.1 Critical | Updated |
| 2026-09-24 | CVE-2026-89028 | MikroTik RouterOS SMB1 Session Setup Handler Accepts Crafted uniPwdLen That Corrupts Adjacent Heap Memory | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-85880 | Microsoft Windows' Heap-Based Buffer Overflow Allows Local Attackers to Escalate Privileges by Corrupting Heap Memory; CISA's September 22nd KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-24 | CVE-2026-80156 | Lantronix SLC8000/SLC9000/EMG Series Web Upload Path Traversal Lets Authenticated Attackers Write Arbitrary Files | 9.1 Critical | Updated |
| 2026-09-24 | CVE-2026-80155 | Lantronix SLC8000/SLC9000/EMG Series Web Upload Authentication Bypass Lets Unauthenticated Attackers Write Arbitrary Files | 10.0 Critical | Updated |
| 2026-09-24 | CVE-2026-80154 | All Lantronix SLC/EMG/SLB Firmware Versions Use Predictable Session Tokens, Letting Unauthenticated Attackers Hijack Active Sessions | 9.6 Critical | Updated |
| 2026-09-24 | CVE-2026-80147 | Lantronix SLC8000/SLC9000/EMG/SLB Stack Buffer Overflow via Undocumented Interface Allows Authenticated Attackers to Execute Arbitrary Code | 9.9 Critical | Updated |
| 2026-09-24 | CVE-2026-80145 | Lantronix SLC8000/SLC9000/EMG Series Services Permission Allows Authenticated Command Injection as Root via a Distinct Injection Path | 9.1 Critical | Updated |
| 2026-09-24 | CVE-2026-80144 | Lantronix SLC/EMG/SLB Undocumented Management Feature Lets Authenticated Attackers Execute Arbitrary Root Shell Commands | 9.9 Critical | Updated |
| 2026-09-24 | CVE-2026-80143 | A Second Undocumented Lantronix SLC/EMG/SLB Command Path Lets Authenticated Attackers Execute Arbitrary Root Shell Commands | 9.9 Critical | Updated |
| 2026-09-24 | CVE-2026-69571 | Windows USB Audio Class driver (usbaudio.sys) Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-69567 | Windows NTFS Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69564 | Windows Online Certificate Status Protocol (OCSP) Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69563 | Windows Program Compatibility Assistant Service Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69561 | Windows CD-ROM Driver Out-of-bounds read Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-69560 | Windows Work Folder Service Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69553 | Windows Hyper-V Missing authorization Lets Authorized Attackers Escalate Privileges over the Network (CVSS 7.1) | 7.1 High | Updated |
| 2026-09-24 | CVE-2026-69551 | Windows DNS Use after free Lets Authorized Attackers Execute Code over the Network (CVSS 8.8) | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-69547 | Windows DHCP Server Heap-based buffer overflow Lets Authorized Attackers Execute Code over the Network (CVSS 8.8) | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-69544 | Windows SMB Client Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-69542 | Windows Camera Frame Server Monitor Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-69540 | Windows Audio Service Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69539 | Windows Remote Desktop Services Use after free Lets Authorized Attackers Execute Code over the Network (CVSS 7.5) | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-69538 | Windows Spaceport.sys Out-of-bounds read Lets Authorized Attackers Execute Code Locally (CVSS 7.8) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-69535 | Windows Spaceport.sys Numeric Truncation Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-69534 | Windows Program Compatibility Assistant Service Command Injection Lets Authorized Attackers Escalate Privileges Locally | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-69532 | Windows NTFS Out-of-bounds read Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-69525 | Windows Remote Desktop Services Use after free Lets Unauthenticated Attackers Execute Code over the Network (CVSS 9.8) | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-69518 | Windows Remote Desktop Heap-based buffer overflow Lets Unauthenticated Attackers Execute Code over the Network (CVSS 8.8) | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-69514 | Windows Remote Desktop Services Heap-based buffer overflow Lets Authorized Attackers Execute Code over the Network (CVSS 7.5) | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-69511 | Microsoft Windows Media Foundation Heap-based buffer overflow Lets Unauthenticated Attackers Execute Code over the Network (CVSS 8.8) | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-69510 | Windows DHCP Server Stack-based buffer overflow Lets Unauthenticated Attackers Execute Code over the Network (CVSS 8.1) | 8.1 High | Updated |
| 2026-09-24 | CVE-2026-69509 | Windows Fax Service Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-69505 | Windows NTFS Out-of-Bounds Read Lets Authorized Attackers Escalate Privileges over the Network (CVSS 8.0) | 8.0 High | Updated |
| 2026-09-24 | CVE-2026-69500 | Windows Image Acquisition Use after free Lets Authorized Attackers Escalate Privileges Locally (CVE-2026-69500) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69496 | Windows Compressed Folder Heap-based buffer overflow Lets Unauthenticated Attackers Execute Code over the Network (CVSS 9.8) | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-69491 | Windows Microsoft DirectMusic Heap-based buffer overflow Lets Unauthenticated Attackers Execute Code over the Network (CVSS 9.8) | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-69479 | Windows NTFS Heap-based buffer overflow Lets Unauthenticated Attackers Execute Code Locally (CVSS 8.4) | 8.4 High | Updated |
| 2026-09-24 | CVE-2026-69475 | Windows Remote Desktop Services Untrusted Pointer Dereference Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-69473 | Windows Kernel Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69466 | Windows Kernel TOCTOU Race Condition Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69463 | Windows NTFS Heap-based buffer overflow Lets Unauthenticated Attackers Execute Code over the Network (CVSS 9.8) | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-69461 | Windows NTFS Stack-based buffer overflow Lets Unauthenticated Attackers Execute Code over the Network (CVSS 8.8) | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-69450 | Windows Error Reporting Out-of-bounds read Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-69430 | Windows Embedded Mode Service Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69429 | Windows IKE Extension Heap-based buffer overflow Lets Authorized Attackers Execute Code over the Network (CVSS 7.5) | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-69428 | Windows LDAP - Lightweight Directory Access Protocol Out-of-bounds read Lets Unauthenticated Attackers Disclose Sensitive Information over the Network (CVSS 7.5) | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-69427 | Windows VOLSNAP.SYS Out-of-bounds read Lets Authorized Attackers Escalate Privileges over the Network (CVSS 8.0) | 8.0 High | Updated |
| 2026-09-24 | CVE-2026-69426 | Windows VOLSNAP.SYS Heap-based buffer overflow Lets Authorized Attackers Execute Code Locally (CVSS 7.8) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-69424 | Windows Distributed File System (DFS) Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-69423 | Windows USB Video Driver Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges over the Network (CVSS 8.0) | 8.0 High | Updated |
| 2026-09-24 | CVE-2026-69421 | Windows Kernel Mode Driver Integer Underflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-69420 | Windows VOLSNAP.SYS Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-69413 | Windows USB Audio Class driver (usbaudio.sys) Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69412 | Windows DHCP Server Stack-based buffer overflow Lets Authorized Attackers Execute Code (CVSS 8.0) | 8.0 High | Updated |
| 2026-09-24 | CVE-2026-69410 | Windows Win32K Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69408 | Microsoft Windows Media Foundation Integer overflow or wraparound Lets Unauthenticated Attackers Execute Code over the Network (CVSS 9.8) | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-69404 | Windows TCP/IP Race Condition Lets Authorized Attackers Execute Code over the Network (CVSS 8.1) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69398 | Windows Bluetooth Service Race Condition Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69397 | OpenSSH for Windows Use after free Lets Unauthenticated Attackers Execute Code over the Network (CVSS 7.5) | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-69388 | Windows Bluetooth Service Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69386 | Microsoft Windows Media Foundation Heap-based buffer overflow Lets Unauthenticated Attackers Execute Code over the Network (CVSS 8.8) | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-69385 | Windows TCP/IP Race Condition Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69383 | Windows Shell Arbitrary File Path Control Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69377 | Windows Modern Device Management (MDM) Missing authorization Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-69371 | Windows Overlay Filter Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges over the Network (CVSS 8.0) | 8.0 High | Updated |
| 2026-09-24 | CVE-2026-69368 | Windows Overlay Filter Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-69366 | Windows Kernel Use after free Lets Authorized Attackers Escalate Privileges over the Network (CVSS 7.1) | 7.1 High | Updated |
| 2026-09-24 | CVE-2026-69364 | Windows Print Spooler Components Race Condition Lets Authorized Attackers Escalate Privileges over the Network (CVSS 7.1) | 7.1 High | Updated |
| 2026-09-24 | CVE-2026-69362 | Windows Error Reporting Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69357 | Windows NDIS Use after free Lets Authorized Attackers Escalate Privileges over the Network (CVSS 7.1) | 7.1 High | Updated |
| 2026-09-24 | CVE-2026-69347 | Windows Fast FAT Driver Heap-based buffer overflow Lets Unauthenticated Attackers Execute Code Locally (CVSS 7.4) | 7.4 High | Updated |
| 2026-09-24 | CVE-2026-69346 | Windows Print Spooler Components Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges over the Network (CVSS 8.0) | 8.0 High | Updated |
| 2026-09-24 | CVE-2026-69342 | Windows DHCP Server Out-of-bounds read Lets Unauthenticated Attackers Disclose Sensitive Information over the Network (CVSS 7.5) | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-69341 | Windows Image Acquisition Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69340 | Windows NTFS Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges over the Network (CVSS 7.1) | 7.1 High | Updated |
| 2026-09-24 | CVE-2026-69337 | Windows Registry Double free Lets Authorized Attackers Escalate Privileges over the Network (CVSS 7.1) | 7.1 High | Updated |
| 2026-09-24 | CVE-2026-69335 | Windows Win32K Use after free Lets Authorized Attackers Escalate Privileges Locally (CVE-2026-69335) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69334 | Windows Volume Manager Extension Driver Heap-based buffer overflow Lets Unauthenticated Attackers Execute Code over the Network (CVSS 8.8) | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-69332 | Windows NTFS Out-of-bounds read Lets Authorized Attackers Escalate Privileges over the Network (CVSS 8.0) | 8.0 High | Updated |
| 2026-09-24 | CVE-2026-69331 | Windows Remote Access Connection Manager Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69328 | Windows Storage Untrusted search path Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-69324 | Windows Performance Monitor Type Confusion Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-69322 | Microsoft Windows Search Component Double free Lets Authorized Attackers Escalate Privileges over the Network (CVSS 8.0) | 8.0 High | Updated |
| 2026-09-24 | CVE-2026-69319 | Windows USB Video Driver Race Condition Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69312 | Windows NTFS Out-of-Bounds Read Lets Authorized Attackers Escalate Privileges Locally (CVE-2026-69312) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-69311 | Windows Audio Service Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69310 | Windows DNS Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69309 | Windows Print Spooler Components Double free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69307 | Windows USB Audio Class driver (usbaudio.sys) Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-69305 | Microsoft Windows Search Component Use after free Lets Authorized Attackers Escalate Privileges over the Network (CVSS 7.1) | 7.1 High | Updated |
| 2026-09-24 | CVE-2026-69301 | Windows Win32K Stack-based buffer overflow Lets Authorized Attackers Escalate Privileges over the Network (CVSS 8.0) | 8.0 High | Updated |
| 2026-09-24 | CVE-2026-69300 | Windows Push Notifications Use after free Lets Authorized Attackers Escalate Privileges Locally (CVE-2026-69300) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69299 | Microsoft COM for Windows Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69296 | Windows Device Association Service Use after free Lets Authorized Attackers Escalate Privileges over the Network (CVSS 7.1) | 7.1 High | Updated |
| 2026-09-24 | CVE-2026-69295 | Windows USB Driver Out-of-bounds read Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-69291 | Windows Volume Manager Extension Driver Heap-based buffer overflow Lets Unauthenticated Attackers Execute Code over the Network (CVSS 8.8) | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-69290 | Windows Storage Spaces Controller Stack-based buffer overflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-69289 | Windows Setup Files Cleanup Symbolic Link Following Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-69287 | Windows Remote Desktop Services Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69284 | Windows DCOM Server Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-69283 | Windows CD-ROM Driver Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-69281 | Windows License Manager Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69280 | Windows Push Notifications Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69279 | Windows Cloud Files Mini Filter Driver Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-69274 | Windows Win32K Use after free Lets Authorized Attackers Escalate Privileges over the Network (CVSS 7.1) | 7.1 High | Updated |
| 2026-09-24 | CVE-2026-69270 | Windows USB Audio Class driver (usbaudio.sys) Heap-based buffer overflow Lets Authorized Attackers Execute Code Locally (CVSS 7.8) (CVE-2026-69270) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-69266 | Windows DHCP Server Integer Overflow or Wraparound Lets Unauthenticated Attackers Execute Code over the Network | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-69265 | Windows NTFS Out-of-Bounds Read Lets Authorized Attackers Escalate Privileges Locally (CVE-2026-69265) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-68896 | Microsoft Windows Search Component Absolute path traversal Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-68894 | Windows Error Reporting Heap-Based Buffer Overflow Lets Authorized Attackers Escalate Privileges over the Network | 8.0 High | Updated |
| 2026-09-24 | CVE-2026-68893 | Windows Remote Desktop Licensing Service Use after free Lets Authorized Attackers Escalate Privileges over the Network (CVSS 7.1) | 7.1 High | Updated |
| 2026-09-24 | CVE-2026-68887 | Windows Message Queuing Queue Manager Out-of-Bounds Read Lets Unauthenticated Attackers Access Sensitive Data over the Network | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-68880 | Windows Win32K Heap-Based Buffer Overflow Lets Authorized Attackers Escalate Privileges over the Network | 8.0 High | Updated |
| 2026-09-24 | CVE-2026-68878 | Windows Fast FAT Driver Stack-Based Buffer Overflow Lets Authorized Attackers Escalate Privileges over the Network | 8.0 High | Updated |
| 2026-09-24 | CVE-2026-68877 | Windows Storage Spaces Controller Heap-Based Buffer Overflow Lets Authorized Attackers Execute Code Locally (CVE-2026-68877) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-68876 | Windows Program Compatibility Assistant Service Heap-Based Buffer Overflow Lets Authorized Attackers Escalate Privileges over the Network | 8.0 High | Updated |
| 2026-09-24 | CVE-2026-68875 | Windows NTFS Buffer Over-read Lets Authorized Attackers Execute Code Locally | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-68848 | Windows Print Spooler Components Heap-Based Buffer Overflow Lets Authorized Attackers Escalate Privileges Locally | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-68846 | Windows Kernel Use after free Lets Authorized Attackers Escalate Privileges over the Network (CVSS 7.1) | 7.1 High | Updated |
| 2026-09-24 | CVE-2026-68845 | Windows Program Compatibility Assistant Service Heap-Based Buffer Overflow Lets Authorized Attackers Escalate Privileges Locally | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-68844 | Windows Storage Spaces Controller Heap-Based Buffer Overflow Lets Authorized Attackers Execute Code Locally | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-68841 | Windows NTFS Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8) | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-68840 | Windows USB Driver Concurrent execution using shared resource with improper synchronization ('race condition') Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-68839 | Windows USB Mass Storage Class Driver Heap-based buffer overflow Lets Unauthenticated Attackers Execute Code over the Network (CVSS 9.8) | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-68838 | Windows NTFS Stack-based buffer overflow Lets Authorized Attackers Escalate Privileges over the Network (CVSS 8.0) | 8.0 High | Updated |
| 2026-09-24 | CVE-2026-68835 | Windows Print Spooler Components Use-After-Free Lets Authorized Attackers Escalate Privileges over the Network | 7.1 High | Updated |
| 2026-09-24 | CVE-2026-68834 | Windows NTFS Stack-Based Buffer Overflow Lets Authorized Attackers Escalate Privileges over the Network (CVE-2026-68834) | 8.0 High | Updated |
| 2026-09-24 | CVE-2026-68832 | Windows NTFS Integer Overflow Lets Authorized Attackers Escalate Privileges Locally | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-68827 | Windows GDI+ Integer Underflow Lets Authorized Attackers Escalate Privileges over the Network | 8.0 High | Updated |
| 2026-09-24 | CVE-2026-62759 | Windows Netlogon Authentication Bypass Lets Unauthenticated Attackers Compromise the System Locally | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-62706 | Microsoft Windows Media Foundation Out-of-Bounds Read Lets Unauthenticated Attackers Execute Code over the Network | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-62694 | Windows Installer Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0) | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-5857 | Contiki-NG MQTT Client Over-Length Topic Sets Received Flag Before Rejection, Enabling Out-of-Bounds Write on Subsequent TCP Segment | 8.1 High | Updated |
| 2026-09-24 | CVE-2026-50349 | Windows Ancillary Function Driver for WinSock Race Condition Lets Authorized Attackers Escalate Privileges Locally | 7.0 High | Updated |
| 2026-09-24 | CVE-2026-19654 | Privilege Escalation in Enterprise Linux 9, Allowing Privilege Escalation | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-13249 | Honeywell PD45 Industrial Printer Web Management Interface Accepts Unauthenticated File Uploads That Enable Remote Code Execution | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-13248 | Honeywell PD45 Industrial Printer Intermec Fingerprint Interface Lets Authenticated Admin Accounts Write Arbitrary Files, Enabling Remote Code Execution | 8.8 High | Updated |
| 2026-09-23 | CVE-2026-20180 | Critical Cisco ISE Path Traversal Enables Remote Code Execution, Scores 9.9 | 9.9 Critical | EPSS-Imminent |
| 2026-09-23 | CVE-2026-94127 | CISA's September 25th Remediation Deadline for F5 BIG-IP APM's OAuth Profile Heap Overflow Has Passed; Covered Entities Running Affected Virtual Servers Are Out of Compliance | 9.8 Critical | KEV |
| 2026-09-23 | CVE-2026-93952 | Arista VeloCloud Orchestrator Input Validation Gap Lets Remote Attackers Reach Privileged APIs; CISA's September 25th KEV Deadline for Covered Entities Has Now Passed | 10.0 Critical | KEV |
| 2026-09-23 | CVE-2026-83998 | Remote Desktop Client Heap-Based Buffer Overflow Lets Unauthenticated Attackers Execute Code over the Network | 8.8 High | Updated |
| 2026-09-23 | CVE-2026-82028 | absmach magistrala SQL Injection Reachable by Authenticated Remote Attackers with High Severity (CVSS 8.8) | 8.8 High | Updated |
| 2026-09-23 | CVE-2026-73176 | Advantech EKI-1242IEIMS Firmware V1.06.01 Web Management Interface Command Injection Lets Authenticated Remote Attackers Execute OS Commands | 8.6 High | Updated |
| 2026-09-23 | CVE-2026-73175 | Advantech EKI-1242EIMS OPC UA Gateway Session Pool Exhaustion Lets Adjacent Unauthenticated Attackers Cause Complete Denial of Service | 7.1 High | Updated |
| 2026-09-23 | CVE-2026-73174 | Advantech EKI-1242EIMS edgserver Management Protocol Transmits Credentials in Cleartext, Exposing Them to Network-Adjacent Observers | 8.7 High | Updated |
| 2026-09-23 | CVE-2026-73173 | Advantech EKI-1242EIMS edgserver Management Protocol Exposes Critical Device Management Functions Without Authentication | 8.8 High | Updated |
| 2026-09-23 | CVE-2026-73172 | Advantech EKI-1242EIMS edgserver Management Service Unauthenticated OS Command Injection Allows Remote Root Execution | 9.3 Critical | Updated |
| 2026-09-23 | CVE-2026-73171 | Advantech EKI-1242EIMS Backup-Restore Upload Lets Authenticated Remote Attackers Overwrite Arbitrary Device Filesystem Files | 8.6 High | Updated |
| 2026-09-23 | CVE-2026-73170 | Advantech EKI-1242EIMS Modbus CSV Import Executes Attacker-Controlled Lua Code via Crafted Upload | 8.6 High | Updated |
| 2026-09-23 | CVE-2026-73167 | Advantech EKI-1242IEIMS Web Management Interface Contains a Second OS Command Injection Path Exploitable by Authenticated Remote Attackers | 8.6 High | Updated |
| 2026-09-23 | CVE-2026-73166 | Advantech EKI-1242IEIMS Web Management Interface Code Injection Lets Authenticated Remote Attackers Execute Arbitrary OS Commands | 8.6 High | Updated |
| 2026-09-23 | CVE-2026-73165 | Advantech EKI-1242IEIMS Web Management Interface Has a Third Command Injection Path Exploitable by Authenticated Remote Attackers | 8.6 High | Updated |
| 2026-09-23 | CVE-2026-73164 | Advantech EKI-1242IEIMS Web Management Interface Contains a Fourth OS Command Injection Path Exploitable by Authenticated Remote Attackers | 8.6 High | Updated |
| 2026-09-23 | CVE-2026-73163 | Advantech EKI-1242IEIMS Web Management Interface Authenticated Command Injection Allows Remote OS Command Execution via Web Interface | 8.6 High | Updated |
| 2026-09-23 | CVE-2026-73014 | Data Sharing Service Client Missing authorization Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8) | 7.8 High | Updated |
| 2026-09-23 | CVE-2026-70584 | Windows Core Messaging Type Confusion Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8) | 7.8 High | Updated |
| 2026-09-23 | CVE-2026-69528 | Windows Shell Missing Authentication Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8) | 7.8 High | Updated |
| 2026-09-23 | CVE-2026-69517 | Windows Wireless Networking Use-After-Free Lets Authorized Attackers Escalate Privileges Locally | 7.0 High | Updated |
| 2026-09-23 | CVE-2026-69512 | Windows Spaceport.sys Heap-Based Buffer Overflow Lets Authorized Attackers Escalate Privileges over the Network | 8.0 High | Updated |
| 2026-09-23 | CVE-2026-69508 | Windows MIDI Service Module Stack-Based Buffer Overflow Lets Authorized Attackers Escalate Privileges Locally | 7.8 High | Updated |
| 2026-09-23 | CVE-2026-69443 | Microsoft Azure Attestation service and Device Health Attestation Service Out-of-Bounds Read Lets Unauthenticated Attackers Access Sensitive Data over the Network | 7.5 High | Updated |
| 2026-09-23 | CVE-2026-53983 | Ground Station Orbital-Source Configuration Path Accepts Unauthenticated Socket.IO SSRF Requests, Causing Outbound HTTP Requests to Attacker-Chosen Destinations | 8.6 High | Updated |
| 2026-09-23 | CVE-2026-19535 | Advantech EKI-1242IEIMS LuCI Administrative Interface CSRF Lets Unauthenticated Attackers Perform Unauthorized State Changes via Logged-In Users | 8.6 High | Updated |
| 2026-09-23 | CVE-2026-19438 | ABB Mint Workbench I Path Traversal Lets Unauthenticated Remote Attackers Access Sensitive Files (CVSS 7.5) | 7.5 High | Updated |
| 2026-09-23 | CVE-2026-12974 | Forcepoint NGFW Security Policy Bypass via Overly Permissive Input Validation Affects Versions 7.1 Through 7.5 | 7.9 High | Updated |
| 2026-09-22 | CVE-2026-9586 | Sangoma Switchvox's SQL Injection Vulnerability Allows Unauthenticated Remote Attackers to Execute Arbitrary Database Queries and Compromise the Telephony Platform | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-9198 | IBM Langflow's Code Injection Flaw Allows Unauthenticated Remote Attackers to Execute Arbitrary Code on the AI Workflow Platform; CISA's August 7th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-9082 | Drupal Core's SQL Injection via Specially Crafted Database Abstraction API Requests Enables Privilege Escalation and Remote Code Execution; CISA's May 27th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-86218 | N-able N-central's Static Code Injection Flaw Allows Remote Attackers to Inject and Execute Arbitrary Code on the RMM Platform Without Prior Authentication | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-85706 | GitLab Community and Enterprise Edition's Path Traversal Flaw Allows Unauthenticated Remote Attackers to Read Arbitrary Files on the Server and Fully Compromise the GitLab Instance | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-83549 | SonicWall SMA1000 Appliances' OS Command Injection Allows Authenticated Local Attackers to Execute Arbitrary Commands with Root Privileges; CISA's September 5th KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-22 | CVE-2026-83548 | SonicWall SMA1000 Appliances' Server-Side Request Forgery Allows Unauthenticated Remote Attackers to Reach Internal Services and Compromise the Secure Mobile Access Gateway; CISA's September 5th KEV Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-82329 | JFrog Artifactory Carries a 9.8 Critical Improper Authentication Flaw That Lets Unauthenticated Attackers Bypass Login Controls on the Artifact Repository | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-73570 | Zimbra Collaboration Suite's OS Command Injection Allows Authenticated Attackers to Execute Arbitrary Commands on the Email Server with Elevated Privileges; CISA's August 24th KEV Deadline Has Passed | 8.9 High | KEV |
| 2026-09-22 | CVE-2026-72898 | Metabase's SQL Injection Flaw Allows Unauthenticated Attackers to Execute Arbitrary Database Queries and Achieve Full Platform Compromise; CISA's August 14th KEV Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-6973 | Ivanti Endpoint Manager Mobile's Improper Input Validation Allows a Remotely Authenticated Administrator to Execute Code Remotely; CISA's May 10th KEV Deadline Has Passed | 7.2 High | KEV |
| 2026-09-22 | CVE-2026-68820 | Microsoft Windows Ancillary Function Driver for WinSock's Use-After-Free Allows a Local Attacker to Gain Elevated Privileges via a Freed Memory Reference; CISA's August 25th KEV Deadline Has Passed | 7.0 High | KEV |
| 2026-09-22 | CVE-2026-65400 | Apple macOS's Improper Authentication Flaw Allows a Network Attacker to Bypass Login Controls and Gain Unauthorized Access to the Operating System; CISA's August 21st KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-64849 | MLflow's Server-Side Request Forgery Flaw Allows Remote Attackers to Use the ML Platform Server as a Proxy to Access Internal Services and Steal Credentials; CISA's September 2nd KEV Deadline Has Passed | 9.3 Critical | KEV |
| 2026-09-22 | CVE-2026-63077 | JetBrains TeamCity's Deserialization of Untrusted Data Allows Unauthenticated Remote Attackers to Execute Arbitrary Code on the CI/CD Server; CISA's August 8th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-63030 | WordPress Core Input Interpretation Conflict Exploited in the Wild Carries a Lapsed July 24th CISA KEV Mandate for Covered Entities | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-60137 | WordPress Core SQL Injection Enabling Database Access Joins CISA's Known Exploited Vulnerabilities Catalog; Covered Entities Past the August 4th Remediation Deadline | 5.9 Medium | KEV |
| 2026-09-22 | CVE-2026-60004 | Gitea's Code Injection Vulnerability Allows Unauthenticated Remote Attackers to Execute Arbitrary Code on the Repository Platform; CISA's August 28th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-59310 | Broadcom VMware vCenter's Path Traversal Flaw Allows Unauthenticated Remote Attackers to Access Files Outside the Web Root and Potentially Compromise the Virtualization Platform; CISA's August 21st KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-56291 | Balbooa Forms Unrestricted File Upload Requiring No Authentication Has Missed CISA's July 13th KEV Remediation Deadline; Covered Entities Are Now Out of Compliance | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-56290 | Joomlack Page Builder Lets Unauthenticated Users Upload Arbitrary Files, Enabling Remote Code Execution; CISA's July 10th KEV Mandate Has Lapsed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-55040 | Microsoft SharePoint's Weak Authentication Allows Attackers to Bypass Login Controls and Gain Unauthorized Access to SharePoint Sites and Data; CISA's August 21st KEV Deadline Has Passed | 9.1 Critical | KEV |
| 2026-09-22 | CVE-2026-50751 | Check Point Security Gateway's IKEv1 Key Exchange Flaw Lets Unauthenticated Attackers Establish Remote Access VPN Tunnels Without a Valid Password; CISA's June 11th KEV Deadline Has Passed | 9.3 Critical | KEV |
| 2026-09-22 | CVE-2026-48939 | iCagenda Joomla Event Calendar Extension Accepts Unrestricted File Uploads Without Authentication, Enabling Remote Code Execution; CISA's July 13th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-48908 | JoomShaper SP Page Builder Accepts Arbitrary File Uploads from Unauthenticated Users; CISA's July 10th KEV Deadline for Covered Entities Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-48907 | Joomla Content Editor Plugin Exposes Privileged Functions Without Proper Authorization; CISA's June 19th KEV Deadline for Covered Entities Has Lapsed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-48558 | SimpleHelp Accepts Unverified Cryptographic Signatures, Letting Remote Attackers Bypass Authentication; CISA's July 2nd KEV Deadline for Covered Entities Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-48172 | Any cPanel User Can Escalate Privileges Through LiteSpeed's Plugin; CISA's May 29th KEV Remediation Requirement for Covered Entities Has Expired | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-46817 | Oracle E-Business Suite's Improper Privilege Management in Oracle Payments Allows an Unauthenticated Network Attacker to Take Over the Payments Module via HTTP; CISA's July 18th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-45498 | Microsoft Defender's Unspecified Vulnerability Allows for Denial of Service; CISA's June 3rd KEV Deadline Has Passed | 4.0 Medium | KEV |
| 2026-09-22 | CVE-2026-45247 | Mirasvit Full Page Cache Warmer's Deserialization Flaw Lets Unauthenticated Attackers Reach Remote Code Execution via a Crafted PHP Object in the CacheWarmer Cookie; CISA's June 6th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-42897 | Microsoft Exchange Server's Outlook Web Access Cross-Site Scripting Flaw Executes Arbitrary JavaScript When Interaction Conditions Are Met; CISA's May 29th KEV Deadline Has Passed | 8.1 High | KEV |
| 2026-09-22 | CVE-2026-42018 | JFrog Artifactory's Improper Authentication Allows Network-Based Attackers to Bypass Login Controls and Gain Unauthorized Access to the Artifact Repository | 7.5 High | KEV |
| 2026-09-22 | CVE-2026-42016 | JFrog Artifactory's Incorrect Authorization Allows Authenticated Users to Access Artifacts and Repositories Outside Their Permitted Scope | 8.1 High | KEV |
| 2026-09-22 | CVE-2026-41091 | Microsoft Defender's Link Following Flaw Enables an Authorized Attacker to Elevate Privileges Locally; CISA's June 3rd KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-22 | CVE-2026-39987 | Marimo's Pre-Authentication Flaw Gives Unauthenticated Attackers Shell Access and Arbitrary Command Execution; CISA's May 7th KEV Remediation Requirement for Covered Entities Has Long Lapsed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-39808 | Fortinet FortiSandbox's OS Command Injection Gives Unauthenticated Attackers Remote Code Execution via Crafted HTTP Requests; CISA's July 19th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-35616 | Fortinet FortiClient EMS Access Control Bypass Entered CISA's Known Exploited Vulnerabilities Catalog with an April 9th Federal Deadline That Has Long Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-35273 | Oracle PeopleSoft Enterprise PeopleTools' Missing Authentication for a Critical Function Allows Unauthenticated Attackers to Take Over the Platform; CISA's June 15th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-34926 | Pre-Authenticated Local Attackers Can Use Relative Path Traversal in Trend Micro Apex One to Modify Key Configuration Data; CISA's June 4th KEV Mandate for Covered Entities Has Lapsed | 6.7 Medium | KEV |
| 2026-09-22 | CVE-2026-34910 | Network-Adjacent Attackers Can Inject Commands into Ubiquiti UniFi OS Through an Input Validation Flaw; CISA's June 26th KEV Remediation Window Has Closed for Covered Entities | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-34909 | Ubiquiti UniFi OS's Path Traversal Lets a Network-Adjacent Attacker Access Files on the Underlying System and Manipulate an Underlying Account; CISA's June 26th KEV Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-34908 | Ubiquiti UniFi OS's Improper Access Control Lets a Network-Adjacent Attacker Make Unauthorized Changes to the System; CISA's June 26th KEV Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-34486 | Apache Tomcat's Missing Encryption of Sensitive Session Data Exposes Credentials and Tokens to Network Interception; CISA's August 7th KEV Deadline Has Passed | 7.5 High | KEV |
| 2026-09-22 | CVE-2026-34197 | Apache ActiveMQ's Improper Input Validation Enables Code Injection Affecting Both ActiveMQ and Broker Deployments; CISA's April 30th KEV Deadline Has Passed | 8.8 High | KEV |
| 2026-09-22 | CVE-2026-33825 | Microsoft Defender's Insufficient Access Control Allows an Authorized Attacker to Escalate Privileges Locally; CISA's May 6th KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-22 | CVE-2026-32202 | Microsoft Windows Shell's Protection Mechanism Failure Allows an Unauthorized Attacker to Perform Spoofing Over the Network; CISA's May 12th KEV Deadline Has Passed | 4.3 Medium | KEV |
| 2026-09-22 | CVE-2026-31431 | Linux Kernel Resource Mishandling That Allows Privilege Escalation Carries a Lapsed May 15th CISA KEV Mandate; Covered Entities on Unpatched Kernels Remain Out of Compliance | 7.8 High | KEV |
| 2026-09-22 | CVE-2026-28318 | SolarWinds Serv-U File Transfer Server Resource Exhaustion Exploited in the Wild Carries a Lapsed June 19th CISA KEV Federal Deadline | 7.5 High | KEV |
| 2026-09-22 | CVE-2026-25089 | Fortinet FortiSandbox's Unauthenticated OS Command Injection via Crafted HTTP Requests Covers Cloud and PaaS Deployments; CISA's July 19th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-21962 | Oracle HTTP Server and WebLogic Server Proxy Plug-in's Improper Access Control Allows Unauthenticated Network Attackers to Fully Compromise the Middleware Platform; CISA's August 27th KEV Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-21643 | Fortinet FortiClient EMS's SQL Injection Allows Unauthenticated Attackers to Execute Unauthorized Code via Crafted HTTP Requests; CISA's April 16th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-20316 | Cisco Secure Firewall Management Center Hard-Coded Password Lets Attackers Bypass Authentication; CISA's August 1st KEV Deadline for Covered Entities Has Passed | 5.3 Medium | KEV |
| 2026-09-22 | CVE-2026-20262 | Authenticated Path Traversal in Cisco Catalyst SD-WAN Manager Lets Remote Attackers Write Files Outside Allowed Directories; CISA's June 29th KEV Deadline Has Passed | 6.5 Medium | KEV |
| 2026-09-22 | CVE-2026-20253 | Splunk Enterprise's Missing Authentication on a PostgreSQL Sidecar Service Endpoint Lets Unauthenticated Users Create or Truncate Arbitrary Files; CISA's June 21st KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-20245 | Cisco Catalyst SD-WAN Manager's Improper Encoding Allows an Authenticated Local Attacker to Execute Arbitrary Commands as Root via a Crafted File; CISA's June 23rd KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-22 | CVE-2026-20230 | Cisco Unified Communications Manager SSRF Flaw Routes Attacker Requests to Internal Resources; CISA's June 28th KEV Deadline for Covered Entities Has Lapsed | 8.6 High | KEV |
| 2026-09-22 | CVE-2026-20200 | Cisco Unified Computing System's Argument Delimiter Injection Allows an Authenticated Attacker to Execute Arbitrary Commands on the Management Controller | 8.8 High | Exploited |
| 2026-09-22 | CVE-2026-20182 | Cisco Catalyst SD-WAN Controller and Manager's Authentication Bypass Gives Unauthenticated Remote Attackers Administrative Privileges; CISA's May 17th KEV Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-20133 | Cisco Catalyst SD-WAN Manager Leaks Sensitive Configuration Data to Unauthorized Users; CISA's April 23rd KEV Remediation Requirement Has Expired for Covered Entities | 6.5 Medium | KEV |
| 2026-09-22 | CVE-2026-20128 | Cisco Catalyst SD-WAN Manager Stores Credentials in a Recoverable Format, Enabling Credential Theft; CISA's April 23rd KEV Mandate for Covered Entities Has Lapsed | 7.5 High | KEV |
| 2026-09-22 | CVE-2026-20122 | Cisco Catalyst SD-WAN Manager Exposes Privileged API Functions to Unauthorized Callers; CISA's April 23rd KEV Remediation Deadline for Covered Entities Has Long Passed | 5.4 Medium | KEV |
| 2026-09-22 | CVE-2026-20079 | Cisco Firewall Management Center's Authentication Bypass via an Alternate Path Grants Unauthenticated Remote Attackers Full Administrative Control; CISA's September 12th KEV Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-19490 | Citrix NetScaler's Authentication Bypass via an Alternate Path Allows Unauthenticated Remote Attackers to Access Protected Resources Without Valid Credentials | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-16232 | Check Point SmartConsole's Improper Authentication Allows Unauthenticated Remote Attackers to Obtain a Login Token and Authenticate with Full Administrative Privileges; CISA's July 25th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-15410 | SonicWall SMA1000's Code Injection Allows a Remote Authenticated Administrator to Execute Arbitrary OS Commands Under Specific Conditions; CISA's July 17th KEV Deadline Has Passed | 7.2 High | KEV |
| 2026-09-22 | CVE-2026-15409 | SonicWall SMA1000 Secure Access Appliances Accept Forged Server-Side Requests, Enabling Internal Network Pivoting; CISA's July 17th KEV Remediation Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-1340 | Ivanti Endpoint Manager Mobile's Code Injection Vulnerability Allows Attackers to Achieve Unauthenticated Remote Code Execution; CISA's April 11th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-12569 | PTC Windchill and FlexPLM's Improper Input Validation Allows Unauthenticated Remote Attackers to Execute Arbitrary Code via Malicious Network Requests; CISA's June 28th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-10520 | Ivanti Sentry's OS Command Injection Gives Remote Unauthenticated Attackers Root-Level Remote Code Execution; CISA's June 14th KEV Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-0300 | PAN-OS Out-of-Bounds Write Enabling Code Execution Affects Both Palo Alto Networks Firewalls and Siemens RUGGEDCOM APE1808 Industrial Appliances; CISA's May 9th KEV Window Has Closed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-0257 | PAN-OS Authentication Bypass Enabling Unauthorized VPN Tunnels Affects Palo Alto Networks Prisma Access and Siemens RUGGEDCOM APE1808; Now Listed in CISA's Known Exploited Vulnerabilities Catalog | 9.1 Critical | KEV |
| 2026-09-22 | CVE-2026-95862 | Ubiquiti Inc Dream Wall Out-of-Bounds Write Reachable by Unauthenticated Remote Attackers | 7.5 High | Updated |
| 2026-09-22 | CVE-2026-95861 | Ubiquiti Inc Dream Wall Denial of Service Reachable by Unauthenticated Remote Attackers in Ubiquiti Inc Dream Wall | 7.5 High | Updated |
| 2026-09-22 | CVE-2026-95675 | D-Link DAP-1360 Remote Code Execution Reachable by Unauthenticated Remote Attackers at Critical Severity (CVSS 9.8) | 9.8 Critical | Updated |
| 2026-09-22 | CVE-2026-94089 | D-Link DIR-868L Buffer Overflow Reachable by Unauthenticated Remote Attackers at Critical Severity (CVSS 10.0) | 10.0 Critical | Updated |
| 2026-09-22 | CVE-2026-77558 | Ubiquiti UniFi Dream Wall Out-of-Bounds Read Lets Unauthenticated Network Attackers Cause Denial of Service (CVSS 7.5) | 7.5 High | Updated |
| 2026-09-22 | CVE-2026-77556 | Ubiquiti UniFi Dream Wall Out-of-Bounds Read Lets Network-Adjacent Attackers Read Sensitive Data (CVSS 7.5) | 7.5 High | Updated |
| 2026-09-22 | CVE-2026-77555 | Ubiquiti Inc Dream Wall Out-of-Bounds Write Reachable by Unauthenticated Remote Attackers (CVE-2026-77555) | 7.5 High | Updated |
| 2026-09-22 | CVE-2026-77544 | Ubiquiti Inc Dream Wall Out-of-Bounds Write Reachable by Unauthenticated Remote Attackers in Ubiquiti Inc Dream Wall | 7.5 High | Updated |
| 2026-09-22 | CVE-2026-72946 | Heap-based buffer overflow in Storage Port Driver allows an authorized attacker to elevate privileges locally | 7.8 High | Updated |
| 2026-09-22 | CVE-2026-72940 | Heap-based buffer overflow in Windows Schannel allows an unauthorized attacker to execute code over a network | 8.8 High | Updated |
| 2026-09-22 | CVE-2026-72936 | Use after free in Windows SMB Client allows an unauthorized attacker to execute code over a network | 8.1 High | Updated |
| 2026-09-22 | CVE-2026-72929 | Improper validation of integrity check value in Windows Installer allows an authorized attacker to elevate privileges locally | 7.8 High | Updated |
| 2026-09-22 | CVE-2026-72926 | Use after free in Windows Internet Connection Sharing (ICS) allows an authorized attacker to elevate privileges locally | 7.0 High | Updated |
| 2026-09-22 | CVE-2026-7273 | Zyxel GS1900 Series Switches' CGI Program Stack-Based Buffer Overflow Allows a LAN-Side Unauthenticated Attacker to Execute OS Commands via Crafted HTTP Requests; CISA's September 24th KEV Deadline Has Passed | 8.8 High | KEV |
| 2026-09-22 | CVE-2026-71221 | Enterprise Linux gfs2-utils Code Execution Reachable by Unauthenticated Local Attackers (CVSS 7.0) | 7.0 High | Updated |
| 2026-09-22 | CVE-2026-71220 | Enterprise Linux gfs2-utils Buffer Overflow Reachable by Unauthenticated Local Attackers (CVSS 7.0) | 7.0 High | Updated |
| 2026-09-22 | CVE-2026-69791 | Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally | 7.0 High | Updated |
| 2026-09-22 | CVE-2026-69790 | Heap-based buffer overflow in Windows Credential Providers allows an authorized attacker to elevate privileges locally | 7.8 High | Updated |
| 2026-09-22 | CVE-2026-69784 | Windows Hello Use-After-Free Lets Authorized Attackers Escalate Privileges Locally | 8.8 High | Updated |
| 2026-09-22 | CVE-2026-69775 | Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges over a network | 7.1 High | Updated |
| 2026-09-22 | CVE-2026-69762 | Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges over a network | 8.0 High | Updated |
| 2026-09-22 | CVE-2026-69760 | Out-of-bounds read in Windows Kerberos allows an unauthorized attacker to deny service over a network | 7.5 High | Updated |
| 2026-09-22 | CVE-2026-69757 | Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges over a network | 7.1 High | Updated |
| 2026-09-22 | CVE-2026-69744 | Null pointer dereference in Windows Kerberos allows an unauthorized attacker to deny service over a network | 7.5 High | Updated |
| 2026-09-22 | CVE-2026-69740 | Use after free in Windows Hello allows an authorized attacker to elevate privileges locally | 8.8 High | Updated |
| 2026-09-22 | CVE-2026-69735 | Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally | 7.0 High | Updated |
| 2026-09-22 | CVE-2026-69729 | Heap-based buffer overflow in Windows Credential Providers allows an authorized attacker to execute code over a network | 8.8 High | Updated |
| 2026-09-22 | CVE-2026-69725 | Double free in Windows Hello allows an authorized attacker to elevate privileges locally | 7.8 High | Updated |
| 2026-09-22 | CVE-2026-69720 | Heap-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally | 7.8 High | Updated |
| 2026-09-22 | CVE-2026-69711 | Windows Device Association Service Use-After-Free Lets Authorized Attackers Escalate Privileges Locally | 7.0 High | Updated |
| 2026-09-22 | CVE-2026-69710 | Windows Hello Race Condition Lets Authorized Attackers Escalate Privileges Locally | 7.5 High | Updated |
| 2026-09-22 | CVE-2026-69708 | Use after free in Windows Web Platform Storage allows an authorized attacker to elevate privileges locally | 7.0 High | Updated |
| 2026-09-22 | CVE-2026-69694 | Deserialization of untrusted data in Windows IP Address Management (IPAM) Service allows an authorized attacker to elevate privileges locally | 7.0 High | Updated |
| 2026-09-22 | CVE-2026-69693 | Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally | 7.0 High | Updated |
| 2026-09-22 | CVE-2026-69689 | Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges over a network | 8.0 High | Updated |
| 2026-09-22 | CVE-2026-69682 | Use after free in Windows Host Guardian Service allows an authorized attacker to elevate privileges locally | 7.0 High | Updated |
| 2026-09-22 | CVE-2026-69654 | Use after free in Windows Accounts Control allows an authorized attacker to elevate privileges locally | 7.0 High | Updated |
| 2026-09-22 | CVE-2026-69652 | Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally | 7.0 High | Updated |
| 2026-09-22 | CVE-2026-31278 | Suprema BioStar 2 Active Directory Settings Endpoint Exposes Service Account Credentials in Cleartext to Crafted GET Requests | 7.7 High | Updated |
| 2026-09-21 | CVE-2026-94036 | D-Link DIR-X1860Z Improper Access Control Reachable by Adjacent-Network Attackers | 8.8 High | Updated |
| 2026-09-21 | CVE-2026-93958 | D-Link R95 Command Injection Exploitable by Authenticated Admin Network Attackers (CVSS 9.1) | 9.1 Critical | Updated |
| 2026-09-21 | CVE-2026-90042 | Linux Kernel ceph properly decrypt filenames in vmalloc() buffers, Reachable Without Authentication at CVSS 9.8 | 9.8 Critical | Updated |
| 2026-09-21 | CVE-2026-90041 | Linux Kernel HID: sony: clean up device list on probe failure | 8.8 High | Updated |
| 2026-09-21 | CVE-2026-90037 | Linux Kernel NFSD: Failure to Prevent client use-after-free during close_lru reaping, Reachable Without Authentication (CVSS 9.8) | 9.8 Critical | Updated |
| 2026-09-21 | CVE-2026-90036 | Linux Kernel NFSD Prevent client use-after-free during blocked-lock reaping, Reachable Without Authentication at CVSS 9.8 | 9.8 Critical | Updated |
| 2026-09-21 | CVE-2026-89815 | Linux Kernel drm/ttm: Memory Safety Issue Allows Local Privilege Escalation | 7.8 High | Updated |
| 2026-09-21 | CVE-2026-89799 | Linux Kernel bpf: Disable preemption in bpf_get_stackid | 7.8 High | Updated |
| 2026-09-21 | CVE-2026-89763 | Linux Kernel KEYS trusted: Fix TPM teardown ordering | 7.8 High | Updated |
| 2026-09-21 | CVE-2026-89755 | Linux Kernel mm/migrate_device: Failure to Clear stale mapping after freeing swapcache | 7.8 High | Updated |
| 2026-09-21 | CVE-2026-89731 | Linux Kernel cxl/ras: Out-of-Bounds Read Allows Local Privilege Escalation | 7.1 High | Updated |
| 2026-09-21 | CVE-2026-89708 | Linux Kernel nfsd: RCU-protect cl_cb_session to fix use-after-free on session teardown, Reachable Without Authentication (CVSS 9.8) | 9.8 Critical | Updated |
| 2026-09-21 | CVE-2026-89685 | Linux Kernel nfsd fix clock domain mismatch in clients_still_reclaiming(), Reachable from the Network Without Credentials (CVSS 7.5) | 7.5 High | Updated |
| 2026-09-21 | CVE-2026-89676 | Linux Kernel nfsd: Reference Count Error Enables Remote Code Execution (CVSS 9.8) | 9.8 Critical | Updated |
| 2026-09-21 | CVE-2026-89667 | Linux Kernel nfsd: close shrinker/GC/fsnotify vs per-net shutdown race in filecache, Reachable from the Network Without Credentials (CVSS 8.1) | 8.1 High | Updated |
| 2026-09-21 | CVE-2026-89660 | Linux Kernel NFSD Prevent client use-after-free during admin state revocation, Reachable Without Authentication at CVSS 9.8 | 9.8 Critical | Updated |
| 2026-09-21 | CVE-2026-89659 | Linux Kernel NFSD Prevent client use-after-free during delegation revoke, Reachable Without Authentication at CVSS 9.8 | 9.8 Critical | Updated |
| 2026-09-21 | CVE-2026-89624 | Linux Kernel HID: universal-pidff: stop the device when force-feedback init fails | 7.8 High | Updated |
| 2026-09-21 | CVE-2026-89622 | Linux Kernel HID mcp2221: clear rxbuf after I2C/SMBus transfer completes | 7.8 High | Updated |
| 2026-09-21 | CVE-2026-89602 | Linux Kernel erofs: skip sufficiently large global buffers when resizing | 7.8 High | Updated |
| 2026-09-21 | CVE-2026-89564 | Linux Kernel ip orphan prefetched skbs before multicast forwarding | 7.8 High | Updated |
| 2026-09-21 | CVE-2026-89561 | Linux Kernel ipv6: rpl: fix NULL dereference of idev in ipv6_rpl_srh_rcv(), Reachable from the Network Without Credentials (CVSS 7.5) | 7.5 High | Updated |
| 2026-09-21 | CVE-2026-89545 | Linux Kernel sunrpc: defer rq_argp and rq_resp free until after RCU grace period | 7.8 High | Updated |
| 2026-09-21 | CVE-2026-89544 | Linux Kernel SUNRPC: Failure to Fix gssx_dec_option_array error path bugs, Reachable from the Network Without Credentials (CVSS 7.5) | 7.5 High | Updated |
| 2026-09-21 | CVE-2026-89535 | Linux Kernel svcrdma: Reorder rpcrdma_rn_unregister before rdma_destroy_id, Reachable from the Network Without Credentials (CVSS 8.1) | 8.1 High | Updated |
| 2026-09-21 | CVE-2026-89492 | Linux Kernel ocfs2: Failure to Validate directory-index entry counts when reading metadata, Reachable Without Authentication (CVSS 9.8) | 9.8 Critical | Updated |
| 2026-09-21 | CVE-2026-80945 | Linux Kernel crypto: iaa - unmap dst before software fallback on decompress, Reachable Without Authentication (CVSS 9.1) | 9.1 Critical | Updated |
| 2026-09-21 | CVE-2026-80734 | Linux Kernel btrfs: Failure to Initialize inode mapping flags for cached inodes | 8.8 High | Updated |
| 2026-09-21 | CVE-2026-80685 | Linux Kernel mm/util: Missing Guard: don't read __page_2 for order-1 folios in snapshot_page() | 7.1 High | Updated |
| 2026-09-21 | CVE-2026-74407 | Linux Kernel wifi ath11k: cancel SSR work items during PCI shutdown | 8.8 High | Updated |
| 2026-09-21 | CVE-2026-74269 | Linux Kernel bnxt: Failure to Fix head underflow on XDP head-grow, Reachable Without Authentication (CVSS 9.8) | 9.8 Critical | Updated |
| 2026-09-21 | CVE-2026-72989 | Use of uninitialized resource in Windows Failover Cluster allows an unauthorized attacker to disclose information over a network | 7.5 High | Updated |
| 2026-09-21 | CVE-2026-72962 | Heap-based buffer overflow in Windows USB Video Driver allows an authorized attacker to elevate privileges locally | 8.2 High | Updated |
| 2026-09-21 | CVE-2026-72961 | Out-of-bounds read in Windows Hyper-V allows an authorized attacker to elevate privileges locally | 8.2 High | Updated |
| 2026-09-21 | CVE-2026-72960 | Heap-based buffer overflow in Windows Media Player allows an unauthorized attacker to execute code over a network | 8.8 High | Updated |
| 2026-09-21 | CVE-2026-72958 | Double free in Windows Credential Guard allows an authorized attacker to elevate privileges locally | 8.2 High | Updated |
| 2026-09-21 | CVE-2026-72953 | Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally | 7.8 High | Updated |
| 2026-09-21 | CVE-2026-72952 | Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to execute code locally | 7.0 High | Updated |
| 2026-09-21 | CVE-2026-72949 | Null pointer dereference in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to deny service over a network | 7.5 High | Updated |
| 2026-09-21 | CVE-2026-72494 | Linux Kernel RDMA/irdma Replace waitqueue and flag with completion, Reachable Without Authentication at CVSS 9.8 | 9.8 Critical | Updated |
| 2026-09-21 | CVE-2026-72438 | Linux Kernel md/raid10: Failure to Fix writes_pending and barrier reference leaks on discard failures, Reachable from the Network Without Credentials (CVSS 7.5) | 7.5 High | Updated |
| 2026-09-21 | CVE-2026-72355 | Linux Kernel netfs: Failure to Fix barriering when walking subrequest list, Reachable Without Authentication (CVSS 9.8) | 9.8 Critical | Updated |
| 2026-09-21 | CVE-2026-71226 | Enterprise Linux Memory Corruption Reachable by Unauthenticated Local Attackers (CVSS 7.3) | 7.3 High | Updated |
| 2026-09-21 | CVE-2026-69648 | Use after free in Windows Notification allows an authorized attacker to elevate privileges locally | 7.0 High | Updated |
| 2026-09-21 | CVE-2026-69625 | Heap-based buffer overflow in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges over a network | 8.0 High | Updated |
| 2026-09-21 | CVE-2026-69617 | Out-of-bounds read in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally | 7.0 High | Updated |
| 2026-09-21 | CVE-2026-69606 | Use after free in Windows Shell allows an authorized attacker to elevate privileges locally | 7.0 High | Updated |
| 2026-09-21 | CVE-2026-69602 | Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges over a network | 7.1 High | Updated |
| 2026-09-21 | CVE-2026-69597 | Use after free in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network | 7.1 High | Updated |
| 2026-09-21 | CVE-2026-69586 | Integer overflow or wraparound in Microsoft Windows PDF allows an unauthorized attacker to execute code over a network | 9.8 Critical | Updated |
| 2026-09-21 | CVE-2026-69575 | Use after free in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally | 7.0 High | Updated |
| 2026-09-21 | CVE-2026-54230 | Enterprise Linux Arbitrary Filesystem Write Reachable by Low-Privilege Local Attackers (CVSS 7.0) | 7.0 High | Updated |
| 2026-09-20 | CVE-2026-87886 | Acronis Backup's Incorrect Default Permissions Allow a Local Attacker to Access Backup Files and Configurations Not Intended for Their Account; CISA's September 19th KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-20 | CVE-2026-84869 | ConnectWise ScreenConnect's Improper Privilege Management and Missing Authorization Allow Unauthenticated Attackers to Gain Administrative Control of the Remote Support Platform; CISA's September 14th KEV Deadline Has Passed | 9.9 Critical | KEV |
| 2026-09-20 | CVE-2026-81963 | Windows Update Stack Symbolic Link Following Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8) | 7.8 High | KEV |
| 2026-09-20 | CVE-2026-67277 | MikroTik RouterOS's Missing Authentication for a Critical Function Allows Unauthenticated Attackers to Access and Modify Router Configuration; CISA's September 13th KEV Deadline Has Passed | 8.2 High | KEV |
| 2026-09-20 | CVE-2026-53362 | Linux Kernel's Unspecified Flaw Allows Local Attackers to Gain Elevated Privileges on Affected Systems; CISA's August 30th KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-20 | CVE-2026-53266 | Linux Kernel's Out-of-Bounds Write Vulnerability Allows Local Attackers to Escalate Privileges or Cause a Kernel Crash; CISA's September 21st KEV Deadline Has Passed | 8.8 High | KEV |
| 2026-09-20 | CVE-2026-50516 | Microsoft Azure Kubernetes Service's Missing Authentication on a Critical Function Allows Unauthenticated Attackers to Interact with Privileged Cluster Management Endpoints | 9.4 Critical | Updated |
| 2026-09-20 | CVE-2026-20349 | Cisco Secure Firewall ASA and FTD's Heap Inspection Vulnerability Allows Remote Attackers to Extract Sensitive Memory Contents from the Firewall Device; CISA's August 14th KEV Deadline Has Passed | 8.6 High | KEV |
| 2026-09-20 | CVE-2026-20301 | Cisco IOS XE's Unchecked Loop Condition Input Allows Network-Accessible Devices to Be Crashed via a Specially Crafted Packet | 8.6 High | Exploited |
| 2026-09-20 | CVE-2026-20124 | Cisco IOS XE's Memory Resource Leak Allows Remote Attackers to Exhaust Device Memory and Cause a Denial of Service via Repeated Packet Transmission | 7.7 High | Exploited |
| 2026-09-20 | CVE-2026-72530 | TrueConf Server's Code Injection Vulnerability Allows Remote Attackers to Execute Arbitrary Code on the Video Conferencing Platform; CISA's September 3rd KEV Deadline Has Passed | 9.0 Critical | KEV |
| 2026-09-20 | CVE-2026-72529 | TrueConf Server's Missing Authentication on a Critical Function Allows Unauthenticated Remote Attackers to Access Administrative Capabilities; CISA's August 23rd KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-18 | CVE-2026-87491 | Google Chromium V8's Out-of-Bounds Write Allows Remote Attackers to Corrupt the JavaScript Engine's Heap and Execute Arbitrary Code via a Crafted Web Page | 8.8 High | KEV |
| 2026-09-18 | CVE-2026-59822 | BerriAI LiteLLM's Improper Authentication Allows Unauthenticated Attackers to Access the AI Model Gateway and Interact with Configured LLM Endpoints Without Credentials | 8.2 High | KEV |
| 2026-09-18 | CVE-2026-58704 | Google Pixel's Improper Authorization Flaw Allows an Attacker with Physical or Local Access to Bypass Permission Controls and Access Protected Device Functions | 8.8 High | KEV |
| 2026-09-18 | CVE-2026-49869 | Kestra OSS's OS Command Injection Flaw Lets Unauthenticated Remote Attackers Execute Arbitrary Commands on the Workflow Orchestration Server with Full System Privileges | 10.0 Critical | KEV |
| 2026-09-18 | CVE-2026-27563 | Crafted GET Request to the Datastorage API Lets Admin Credentials Trigger Root Command Execution on Pepperl+Fuchs ICE-Series IO-Link Masters | 7.2 High | Updated |
| 2026-09-18 | CVE-2026-27558 | Operator Access to the IODD File Removal Endpoint on Pepperl+Fuchs ICE-Series IO-Link Masters Allows Root Command Injection | 8.8 High | Updated |
| 2026-09-18 | CVE-2026-27548 | Command Injection in the IODD Port Info Endpoint Grants Root Access on Pepperl+Fuchs ICE-Series IO-Link Masters to Any User or Operator Account | 8.8 High | Updated |
| 2026-09-16 | CVE-2026-27565 | Unauthenticated IODD File Upload on Pepperl+Fuchs ICE-Series IO-Link Masters Executes a Root Shell Script That Persists Across Reboots | 9.8 Critical | Updated |
| 2026-09-16 | CVE-2026-27564 | Pepperl+Fuchs ICE-Series IO-Link Masters Run Injected Root Commands When Admin Credentials Submit a Crafted PUT Request to the Datastorage API | 7.2 High | Updated |
| 2026-09-16 | CVE-2026-27562 | Admin-Level PUT Requests to the IODD Configuration API Execute Injected Commands as Root on Pepperl+Fuchs ICE-Series IO-Link Masters | 7.2 High | Updated |
| 2026-09-16 | CVE-2026-27561 | Admin Credentials Enable Root Command Injection via the IODD Config GET API on Pepperl+Fuchs ICE-Series IO-Link Masters | 7.2 High | Updated |
| 2026-09-16 | CVE-2026-27560 | Admin-Credentialed DELETE Requests to Pepperl+Fuchs ICE-Series IO-Link Masters' Status API Carry Injected Commands Executed at Root | 7.2 High | Updated |
| 2026-09-16 | CVE-2026-27559 | User Credentials Are Enough to Inject Root-Level Commands via the Status Data API on Pepperl+Fuchs ICE-Series IO-Link Masters | 8.8 High | Updated |
| 2026-09-16 | CVE-2026-27557 | Unauthenticated Path Traversal in Pepperl+Fuchs ICE-Series IO-Link Masters Exposes the Device's SSH Server Private Keys | 7.5 High | Updated |
| 2026-09-16 | CVE-2026-27556 | Operator Cookie Enables Arbitrary PHP Code Execution on Pepperl+Fuchs ICE-Series IO-Link Masters via Local File Inclusion in the IODD Parameter Save Endpoint | 8.8 High | Updated |
| 2026-09-16 | CVE-2026-27555 | A Valid User Cookie Triggers Arbitrary PHP Code Execution on Pepperl+Fuchs ICE-Series IO-Link Masters via Local File Inclusion in the IODD Port Info Endpoint | 8.8 High | Updated |
| 2026-09-16 | CVE-2026-27554 | IODD Parameter Save Endpoint on Pepperl+Fuchs ICE-Series IO-Link Masters Accepts Injected Commands from Operator-Level Accounts, Yielding Root Access | 8.8 High | Updated |
| 2026-09-16 | CVE-2026-27552 | Pepperl+Fuchs ICE-Series IO-Link Masters Allow Low-Privileged Users to Upload Arbitrary IODD Files via a Missing Authorization Check, Enabling Device Manipulation or Crashes | 8.1 High | Updated |
| 2026-09-16 | CVE-2026-27551 | User-Level Credentials Give Root Shell on Pepperl+Fuchs ICE-Series IO-Link Masters via the Parameter Management Endpoint | 8.8 High | Updated |
| 2026-09-16 | CVE-2026-27550 | Operator Credentials Can Inject Root-Level OS Commands via the Field_Shadow_Password Handler on Pepperl+Fuchs ICE-Series IO-Link Masters | 8.8 High | Updated |
| 2026-09-16 | CVE-2026-27549 | Operator-Level Credentials Suffice to Run Root Commands on Pepperl+Fuchs ICE-Series IO-Link Masters via the IODD Upload Endpoint | 8.8 High | Updated |
| 2026-09-16 | CVE-2026-27547 | IODD Menu Info Request on Pepperl+Fuchs ICE-Series IO-Link Masters Passes Unvalidated Parameters to Root-Level Commands, Reachable with User-Level Credentials | 8.8 High | Updated |
| 2026-09-16 | CVE-2026-27546 | The _account_log Function in Pepperl+Fuchs ICE-Series IO-Link Masters Lets Unauthenticated Attackers Log In as Admin Regardless of Account Configuration | 9.8 Critical | Updated |
| 2026-09-11 | CVE-2026-63298 | LXD NVIDIA Instance Configuration Handler Accepts Newline Characters in nvidia.driver.capabilities and nvidia.require.* Values, Letting Authenticated Attackers Inject Arbitrary Directives into the GPU Configuration | 9.9 Critical | Updated |
| 2026-09-10 | CVE-2026-32589 | Red Hat Quay authenticated push access enables interference with other users' in-progress image uploads across repositories | 7.4 High | Updated |
| 2026-08-13 | CVE-2026-64125 | Linux Kernel bcmgenet Driver Enabling RBUF EEE and PM Bits Stops RX Traffic When MAC EEE Activates, Causing a Denial-of-Service Condition on Broadcom GENET Hardware | 9.8 Critical | Updated |
| 2026-07-28 | CVE-2026-16812 | Arista VeloCloud Orchestrator On-Prem Management Plane Executes Injected OS Commands; CISA's July 30th KEV Deadline Has Passed for Covered Entities | 10.0 Critical | KEV |
| 2026-07-24 | CVE-2026-31405 | Linux Kernel DVB-net ULE Extension Handler Uses a Network-Controlled Index into a 255-Entry Table Without Bounds Checking, Enabling Out-of-Bounds Reads and Writes | 9.8 Critical | Updated |
| 2026-07-24 | CVE-2026-23458 | Linux kernel ctnetlink multi-round dump dereferences freed conntrack pointer in second callback invocation | 7.8 High | Updated |
| 2026-07-24 | CVE-2026-23450 | Linux Kernel SMC-over-TCP SYN Receive Path Calls sock_hold Then Schedules a tcp_close Work Item Without Synchronizing Against Concurrent Stack Cleanup, Enabling Use-After-Free and Null Dereference | 9.8 Critical | Updated |
| 2026-07-24 | CVE-2026-23419 | Linux kernel rds_tcp_tune circular locking dependency causes deadlock via sk_net_refcnt_upgrade | 7.5 High | Updated |
| 2026-07-23 | CVE-2026-54420 | LiteSpeed's cPanel Plugin Follows Symlinks Across Security Boundaries to Escalate Privileges; CISA's June 18th KEV Remediation Window Has Closed for Covered Entities | 8.5 High | KEV |
| 2026-07-23 | CVE-2026-42542 | TDengine taosd Integer Underflow in RPC Handler Lets Unauthenticated Attackers Crash the Server With One Packet | 7.5 High | Updated |
| 2026-07-15 | CVE-2026-56155 | Microsoft Active Directory Federation Services Insufficient Access Control Allows an Authorized Attacker to Elevate Privileges Locally; CISA's July 28th KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-07-15 | CVE-2026-39304 | Apache ActiveMQ NIO SSL Transports Vulnerable to Denial-of-Service via Memory Exhaustion | 7.5 High | Updated |
| 2026-07-14 | CVE-2026-31446 | Linux kernel ext4 use-after-free in update_super_work races with unmount after sysfs unregistration | 7.8 High | Updated |
| 2026-07-08 | CVE-2026-46279 | Linux Kernel Page Extension Initialization Leaves Codetag Uninitialized for Pages Allocated Before page_ext Is Ready | 7.8 High | Updated |
| 2026-07-02 | CVE-2026-53225 | Linux Kernel SCTP ASCONF Lookup Reads Past the Validated Header Boundary, Exposing Uninitialized Memory to Downstream Address Parameter Processing | 9.1 Critical | Updated |
| 2026-06-17 | CVE-2026-8398 | Daemon Tools Lite Contains Embedded Malicious Code; CISA Added It to KEV with a May 30th Deadline That Has Since Passed for Covered Entities | 9.8 Critical | KEV |
| 2026-06-17 | CVE-2026-7473 | Arista Extensible Operating System Validation Bypass Added to CISA's Known Exploited Vulnerabilities List; Federal Remediation Window for Covered Entities Closed June 23rd | 5.8 Medium | KEV |
| 2026-06-17 | CVE-2026-48027 | Nx Console Developer Tooling Published Packages Contain Embedded Malicious Code; CISA's June 10th KEV Mandate for Covered Entities Has Passed | 9.8 Critical | KEV |
| 2026-06-17 | CVE-2026-45321 | TanStack JavaScript Library Suite Added to CISA's Known Exploited Vulnerabilities Catalog; Federal Remediation Deadline for Covered Entities Was June 10th | 9.6 Critical | KEV |
| 2026-06-17 | CVE-2026-43296 | Linux Kernel octeontx2-af NIC SQ Manager Sticky Mode Causes Stalls and Potential PSE Deadlock When Multiple Queues Share an SMQ | 7.5 High | Updated |
| 2026-06-17 | CVE-2026-4116 | SonicWall SMA1000 Mishandles Unicode Encoding in TOTP Validation, Allowing an Authenticated SSLVPN User to Bypass Two-Factor Authentication | 7.2 High | Updated |
| 2026-06-17 | CVE-2026-4113 | SonicWall SMA1000 Distinguishable Authentication Error Responses Allow a Remote Attacker to Enumerate SSL VPN User Accounts | 7.2 High | Updated |
| 2026-06-17 | CVE-2026-4112 | SonicWall SMA1000 SQL Injection in the SSLVPN Component Allows a Read-Only Administrator to Escalate to Primary Administrator | 7.2 High | Updated |
| 2026-06-17 | CVE-2026-31693 | Linux kernel CIFS replay path missing variable reinitializations causes undefined behavior on request retry | 7.8 High | Updated |
| 2026-06-17 | CVE-2026-31568 | Linux kernel s390/mm missing secure storage access fixups for donated pages causes kernel context exceptions | 7.1 High | Updated |
| 2026-06-17 | CVE-2026-31426 | Linux kernel ACPI EC address space handler persists after probe failure leaves dangling pointer | 7.0 High | Updated |
| 2026-06-17 | CVE-2026-23406 | Linux kernel AppArmor match_char macro evaluates pointer multiple times and skips input characters during DFA traversal | 7.8 High | Updated |
| 2026-06-17 | CVE-2026-1952 | Delta Electronics AS320T Denial of Service via Undocumented Subfunction Call, Exploitable Remotely Without Authentication | 9.8 Critical | Updated |
| 2026-06-17 | CVE-2026-1951 | Delta Electronics AS320T Stack-Based Buffer Overflow Due to Missing Directory Name Length Check, Enabling Unauthenticated Remote Code Execution | 9.8 Critical | Updated |
| 2026-06-17 | CVE-2026-1950 | Delta Electronics AS320T Stack-Based Buffer Overflow Due to Missing File Name Length Check, Enabling Unauthenticated Remote Code Execution | 9.8 Critical | Updated |
| 2026-06-17 | CVE-2026-1949 | Delta Electronics AS320T GET/PUT Request Handler Incorrectly Calculates Stack Buffer Size, Enabling Unauthenticated Remote Code Execution via the Web Service | 9.8 Critical | Updated |