Critical Infrastructure Vulnerability Intelligence

Advisories for Industrial Defenders

Compiled, structured vulnerability reports for operational technology and industrial control system security teams.

144
KEV Listed
154
Exploited
12
EPSS-Imminent
389
Total Advisories
Filter by Sector
ChemicalCommercialCommunicationsManufacturingDamsDefense IndustrialEmergency SvcsEnergyFinancial SvcsFood & AgGovernmentHealthcareInfo TechnologyNuclearTransportationWater
Filter by Status
UpdatedAdvisory IDTitleCVSSStatus
2026-09-26CVE-2017-20236ProSoft ICX35-HWC OS Command Injection via Web UI Scores 9.89.8 CriticalUpdated
2026-09-26CVE-2025-12694Forcepoint VPN Client Excessive-Privilege Execution Scores 7.87.8 HighUpdated
2026-09-26CVE-2025-14771ABB T-MAC Plus Exposes Files to External Parties, Scores 9.99.9 CriticalUpdated
2026-09-26CVE-2025-14772ABB T-MAC Plus Authorization Bypass via User-Controlled Key Scores 8.88.8 HighUpdated
2026-09-26CVE-2025-14773ABB T-MAC Plus Cross-Site Scripting Scores 8.08.0 HighUpdated
2026-09-26CVE-2025-14774ABB T-MAC Plus Incorrect Authorization Scores 7.47.4 HighUpdated
2026-09-26CVE-2025-33255NVIDIA TensorRT-LLM MPI Server Deserialization Flaw Scores 7.57.5 HighUpdated
2026-09-26CVE-2025-53681Fortinet FortiMail SQL Injection Scores 7.27.2 HighUpdated
2026-09-26CVE-2025-61848Fortinet FortiManager SQL Injection Scores 7.27.2 HighUpdated
2026-09-26CVE-2025-58136Apache Traffic Server Incorrect Control Flow Scores 7.57.5 HighUpdated
2026-09-26CVE-2025-62188Apache DolphinScheduler Sensitive Information Exposure Scores 7.57.5 HighUpdated
2026-09-26CVE-2025-65114Apache Traffic Server HTTP Request Smuggling Scores 7.57.5 HighUpdated
2026-09-26CVE-2025-24815Nokia MantaRay NM Unrestricted File Upload Scores 7.87.8 HighUpdated
2026-09-26CVE-2025-24817Nokia MantaRay NM OS Command Injection in Symptom Collector Scores 8.08.0 HighUpdated
2026-09-26CVE-2025-24818Nokia MantaRay NM OS Command Injection in Log Search Scores 8.08.0 HighUpdated
2026-09-26CVE-2025-7406Nokia MantaRay NM sudo Privilege Escalation Reaches Root, Scores 7.87.8 HighUpdated
2026-09-26CVE-2026-0233Palo Alto Networks ADEM Certificate Validation Flaw Scores 8.88.8 HighUpdated
2026-09-26CVE-2026-0236Palo Alto Networks Prisma Browser Code Injection Scores 7.87.8 HighUpdated
2026-09-26CVE-2026-0237Palo Alto Networks Prisma Browser Alternate Path Protection Flaw Scores 7.87.8 HighUpdated
2026-09-26CVE-2026-0244Palo Alto Networks Prisma SD-WAN Certificate Validation Flaw Scores 8.18.1 HighUpdated
2026-09-26CVE-2026-0246Palo Alto Networks Prisma Access Agent Missing Authorization Scores 7.87.8 HighNew
2026-09-26CVE-2026-0250Palo Alto Networks GlobalProtect Out-of-Bounds Write Scores 8.18.1 HighNew
2026-09-26CVE-2026-0251Palo Alto Networks GlobalProtect Untrusted Search Path Scores 7.87.8 HighNew
2026-09-26CVE-2026-0259Palo Alto Networks PAN-OS External File Path Control Scores 8.88.8 HighNew
2026-09-26CVE-2026-0263Critical Palo Alto Networks PAN-OS Out-of-Bounds Write Scores 9.89.8 CriticalNew
2026-09-26CVE-2026-0258Palo Alto Networks PAN-OS IKEv2 SSRF Affects Siemens RUGGEDCOM APE1808, Scores 9.19.1 CriticalUpdated
2026-09-26CVE-2026-0261Palo Alto Networks PAN-OS Command Injection Affects Siemens RUGGEDCOM APE1808, Scores 7.27.2 HighUpdated
2026-09-26CVE-2026-0262Palo Alto Networks PAN-OS Multiple Denial-of-Service Flaws Affect Siemens RUGGEDCOM APE18087.5 HighUpdated
2026-09-26CVE-2026-0264Critical Palo Alto Networks PAN-OS DNS Heap Overflow Affects Siemens RUGGEDCOM APE1808, Scores 9.89.8 CriticalUpdated
2026-09-26CVE-2026-0265Palo Alto Networks PAN-OS Authentication Bypass Affects Siemens RUGGEDCOM APE1808, Scores 8.18.1 HighUpdated
2026-09-26CVE-2026-0270Palo Alto Networks Cortex XSOAR Path Traversal Scores 7.57.5 HighUpdated
2026-09-26CVE-2026-0271Palo Alto Networks Prisma Access Agent Permission Misconfiguration Scores 7.87.8 HighNew
2026-09-26CVE-2026-0272Palo Alto Networks PAN-OS Missing Authorization Scores 7.27.2 HighNew
2026-09-26CVE-2026-0273Palo Alto Networks PAN-OS OS Command Injection Scores 7.27.2 HighNew
2026-09-26CVE-2026-0288Palo Alto Networks PAN-OS Out-of-Bounds Write Scores 7.57.5 HighNew
2026-09-26CVE-2026-16443Red Hat Build of Keycloak Cryptographic Signature Verification Flaw Scores 7.47.4 HighUpdated
2026-09-26CVE-2026-17744Google Chrome on Linux File Input Flaw Exposes Potential Sandbox Escape, Scores 7.17.1 HighNew
2026-09-26CVE-2026-17877Google Chrome on Linux Chromoting Flaw Enables Local Privilege Escalation, Scores 8.48.4 HighNew
2026-09-26CVE-2026-17894Google Chrome on Linux Use-After-Free in Views via Crafted HTML Scores 8.88.8 HighNew
2026-09-26CVE-2026-18378Red Hat Cost Management Metrics Operator SSRF via Arbitrary Upload URL Scores 7.67.6 HighUpdated
2026-09-26CVE-2026-18381Red Hat Cost Management Metrics Operator SSRF via Crafted Custom Resource Scores 7.67.6 HighUpdated
2026-09-26CVE-2026-20094Cisco UCS Command Injection Scores 8.88.8 HighUpdated
2026-09-26CVE-2026-20151Cisco Smart Software Manager On-Prem Leaks Sensitive Data in Transmitted Requests7.3 HighUpdated
2026-09-26CVE-2026-20155Cisco Evolved Programmable Network Manager Missing Authorization Scores 8.08.0 HighUpdated
2026-09-26CVE-2026-20160Critical Cisco Smart Software Manager On-Prem Resource Exposure Scores 9.89.8 CriticalUpdated
2026-09-26CVE-2026-21662Critical Johnson Controls FMS Employee Unrestricted File Upload Scores 9.89.8 CriticalUpdated
2026-09-26CVE-2026-21997Oracle Life Sciences Empirica Signal Access Control Weakness Scores 8.58.5 HighUpdated
2026-09-26CVE-2026-22010Oracle Financial Services Infrastructure Platform Access Control Flaw Scores 7.57.5 HighUpdated
2026-09-26CVE-2026-22011Oracle Applications DBA ADPatch Access Control Weakness Scores 7.67.6 HighUpdated
2026-09-26CVE-2026-22016Oracle Java SE JAXP Component Exposes Sensitive Information, Scores 7.57.5 HighUpdated
2026-09-26CVE-2026-22619Eaton Intelligent Power Protector Uncontrolled Search Path Scores 7.87.8 HighUpdated
2026-09-26CVE-2026-22828Fortinet FortiManager and FortiAnalyzer Cloud Heap Overflow Scores 8.18.1 HighUpdated
2026-09-26CVE-2026-23407Linux Kernel AppArmor Out-of-Bounds Read in DFA Verification Scores 7.87.8 HighUpdated
2026-09-26CVE-2026-23408Linux Kernel AppArmor Double Free of Namespace Name Scores 7.87.8 HighUpdated
2026-09-26CVE-2026-23410Linux Kernel AppArmor Race on Rawdata Dereference Scores 7.87.8 HighUpdated
2026-09-26CVE-2026-23411Linux Kernel AppArmor Race Condition Frees i_private Data Early Scores 7.87.8 HighUpdated
2026-09-26CVE-2026-23412Linux Kernel Netfilter BPF Use-After-Free in Hook Memory Release Scores 7.87.8 HighUpdated
2026-09-26CVE-2026-23413Linux Kernel clsact Use-After-Free in Init/Destroy Rollback Scores 7.87.8 HighUpdated
2026-09-26CVE-2026-23414Linux Kernel TLS Memory Leak in Async Decrypt Wait Scores 7.57.5 HighUpdated
2026-09-26CVE-2026-23415Linux Kernel Futex Use-After-Free between Key Lookup and VMA Policy Scores 7.87.8 HighUpdated
2026-09-26CVE-2026-23422Linux Kernel dpaa2-switch Out-of-Bounds Write from Malformed Interrupt Scores 7.87.8 HighUpdated
2026-09-26CVE-2026-23424Linux Kernel amdxdna Missing Command Buffer Validation Scores 7.17.1 HighUpdated
2026-09-26CVE-2026-23425Linux Kernel KVM arm64 ID Register Initialization Flaw Scores 8.88.8 HighUpdated
2026-09-26CVE-2026-23427Critical Linux Kernel ksmbd Use-After-Free in Durable Handle Replay Scores 9.89.8 CriticalUpdated
2026-09-26CVE-2026-23428Critical Linux Kernel ksmbd Use-After-Free in Compound Request Handling Scores 9.89.8 CriticalUpdated
2026-09-26CVE-2026-23429Linux Kernel IOMMU SVA Use-After-Free in Unbind Path Scores 7.87.8 HighUpdated
2026-09-26CVE-2026-23657Microsoft Office LTSC Use-After-Free Vulnerability Scores 7.87.8 HighUpdated
2026-09-26CVE-2026-23708Fortinet FortiSOAR Authentication Flaw Scores 7.57.5 HighUpdated
2026-09-26CVE-2026-24146NVIDIA Triton Inference Server Oversized Allocation Request Scores 7.57.5 HighUpdated
2026-09-26CVE-2026-24156NVIDIA Data Loading Library Deserialization Vulnerability Scores 7.37.3 HighUpdated
2026-09-26CVE-2026-24163NVIDIA TensorRT-LLM Deserialization Flaw Scores 7.57.5 HighUpdated
2026-09-26CVE-2026-24173NVIDIA Triton Inference Server Integer Overflow Scores 7.57.5 HighUpdated
2026-09-26CVE-2026-24174NVIDIA Triton Inference Server Numeric Type Conversion Error Scores 7.57.5 HighUpdated
2026-09-26CVE-2026-24175NVIDIA Triton Inference Server Uncaught Exception Scores 7.57.5 HighUpdated
2026-09-26CVE-2026-24178Critical NVIDIA NVFlare Authorization Bypass via User-Controlled Key Scores 9.89.8 CriticalUpdated
2026-09-26CVE-2026-24183NVIDIA Cumulus Linux Excessive-Privilege Execution Scores 7.87.8 HighUpdated
2026-09-26CVE-2026-24184NVIDIA Cumulus Linux Buffer Overflow Scores 7.57.5 HighUpdated
2026-09-26CVE-2026-24186NVIDIA NVFlare Deserialization of Untrusted Data Scores 8.88.8 HighUpdated
2026-09-26CVE-2026-24188NVIDIA TensorRT Out-of-Bounds Write Scores 8.28.2 HighUpdated
2026-09-26CVE-2026-24206NVIDIA Triton Inference Server Authentication Bypass via Alternate Path Scores 7.37.3 HighUpdated
2026-09-26CVE-2026-24207Critical Authentication Bypass in NVIDIA Triton Inference Server9.8 CriticalUpdated
2026-09-26CVE-2026-24209Path Traversal Vulnerability in NVIDIA Triton Inference Server7.5 HighUpdated
2026-09-26CVE-2026-24210Integer Overflow in NVIDIA Triton Inference Server Allows Code Execution or Denial of Service7.5 HighUpdated
2026-09-26CVE-2026-24213Out-of-Bounds Read in NVIDIA Triton Inference Server DALI Backend8.0 HighUpdated
2026-09-26CVE-2026-24214Integer Overflow in NVIDIA Triton Inference Server DALI Backend8.0 HighUpdated
2026-09-26CVE-2026-24216Deserialization of Untrusted Data in NVIDIA BioNeMo Enables Code Execution7.8 HighUpdated
2026-09-26CVE-2026-24217Path Traversal in NVIDIA BioNeMo Core Allows Malicious File to Escape Sandbox8.8 HighUpdated
2026-09-26CVE-2026-24222NVIDIA NeMoClaw Sandbox Initialization Exposes System Information to Remote Attackers8.6 HighUpdated
2026-09-26CVE-2026-24880Apache Tomcat Chunk Extension Parsing Allows HTTP Request Smuggling7.5 HighUpdated
2026-09-26CVE-2026-26143Improper Input Validation in Microsoft PowerShell Allows Unauthorized Security Feature Bypass7.8 HighNew
2026-09-26CVE-2026-26149Control Sequence Injection in Microsoft Power Apps Enables Network-Based Spoofing9.0 CriticalUpdated
2026-09-26CVE-2026-26170Input Validation Flaw in Microsoft PowerShell Allows Local Privilege Escalation7.8 HighUpdated
2026-09-26CVE-2026-26181Use-After-Free in Microsoft Brokering File System Lets Authorized User Escalate Privileges7.8 HighUpdated
2026-09-26CVE-2026-27314Apache Cassandra 5.0 CREATE Permission Allows Privilege Escalation in mTLS Environments8.8 HighUpdated
2026-09-26CVE-2026-27909Use-After-Free in Windows Search Component Allows Authorized Attacker to Escalate Privileges7.8 HighUpdated
2026-09-26CVE-2026-27914Improper Access Control in Microsoft Management Console Allows Local Privilege Escalation7.8 HighUpdated
2026-09-26CVE-2026-28811Apache JSPWiki Leaks Internal Information via Debug Messages7.5 HighUpdated
2026-09-26CVE-2026-28812Apache JSPWiki UserManager Spoofing Flaw Allows Attackers to Escalate Privileges9.8 CriticalUpdated
2026-09-26CVE-2026-28813JSON Hijacking in Apache JSPWiki Enables Cross-Site Request Forgery8.8 HighUpdated
2026-09-26CVE-2026-28814Apache JSPWiki Renders Wiki Markup Without Authentication, Exposing Sensitive Data7.5 HighUpdated
2026-09-26CVE-2026-29129Apache Tomcat Fails to Preserve Configured Cipher Preference Order7.5 HighUpdated
2026-09-26CVE-2026-29145Apache Tomcat CLIENT_CERT Authentication Bypass When Soft Fail Is Disabled9.1 CriticalUpdated
2026-09-26CVE-2026-32091Race Condition in Microsoft Brokering File System Allows Unauthorized Privilege Escalation8.4 HighUpdated
2026-09-26CVE-2026-32153Use-After-Free in Windows Speech Component Allows Local Privilege Escalation7.8 HighUpdated
2026-09-26CVE-2026-32184Deserialization Flaw in Microsoft HPC Pack Allows Authorized User to Escalate Privileges7.8 HighUpdated
2026-09-26CVE-2026-32186Critical SSRF in Microsoft Bing Enables Network-Based Privilege Escalation10.0 CriticalUpdated
2026-09-26CVE-2026-32188Out-of-Bounds Read in Microsoft Office Excel Discloses Information to Local Attackers7.1 HighUpdated
2026-09-26CVE-2026-32189Microsoft Office Excel Carries Additional Use-After-Free Code Execution Risk7.8 HighUpdated
2026-09-26CVE-2026-32190Use-After-Free in Microsoft Office Enables Local Code Execution8.4 HighUpdated
2026-09-26CVE-2026-32197Local Code Execution via Use-After-Free in Microsoft Office Excel7.8 HighUpdated
2026-09-26CVE-2026-32198Microsoft Office Excel Use-After-Free Lets Local Attacker Execute Code7.8 HighUpdated
2026-09-26CVE-2026-32199Use-After-Free in Microsoft Office Excel Enables Local Code Execution7.8 HighUpdated
2026-09-26CVE-2026-32200Use-After-Free in Microsoft PowerPoint Enables Local Code Execution7.8 HighUpdated
2026-09-26CVE-2026-32590Unsafe Deserialization in Red Hat Quay Resumable Upload Handling7.1 HighUpdated
2026-09-26CVE-2026-33105Critical Authorization Bypass in Microsoft Azure Kubernetes Service Allows Network Privilege Escalation10.0 CriticalUpdated
2026-09-26CVE-2026-33266Apache OpenMeetings Uses Default Hard-Coded Encryption Key for Remember-Me Cookies7.5 HighUpdated
2026-09-26CVE-2026-34020Apache OpenMeetings REST Login Exposes Credentials in URL Query String7.5 HighUpdated
2026-09-26CVE-2026-34478Apache Log4j RFC 5424 Layout Vulnerable to Log Injection in Versions 2.21 through 2.257.5 HighUpdated
2026-09-26CVE-2026-34483Improper Output Encoding in Apache Tomcat JsonAccessLogValve Enables Log Injection7.5 HighUpdated
2026-09-26CVE-2026-34487Apache Tomcat Cloud Clustering Component Logs Kubernetes Credentials in Plain Text7.5 HighUpdated
2026-09-26CVE-2026-3519Progress LoadMaster API Exposes Authenticated Command Injection for VS Administration Role8.4 HighEPSS-Imminent
2026-09-26CVE-2026-35554Race Condition in Apache Kafka Producer Can Silently Deliver Messages to Wrong Topics8.7 HighUpdated
2026-09-26CVE-2026-3692Low-Privilege OS Command Injection in Progress Flowmon Reporting Component8.8 HighUpdated
2026-09-26CVE-2026-39304Apache ActiveMQ NIO SSL Transports Vulnerable to Denial-of-Service via Memory Exhaustion7.5 HighUpdated
2026-09-26CVE-2026-39815SQL Injection in Fortinet FortiDDoS-F 7.2 May Allow Unauthorized Data Access8.8 HighUpdated
2026-09-26CVE-2026-40138BeyondTrust Privileged Remote Access Shares Pre-Authentication Bypass Flaw with Remote Support8.1 HighUpdated
2026-09-26CVE-2026-40139Critical Pre-Authentication Bypass in BeyondTrust Remote Support Allows Unauthorized Access9.8 CriticalUpdated
2026-09-26CVE-2026-4048Authenticated Command Injection in Progress LoadMaster UI Enables Remote Code Execution8.4 HighEPSS-Imminent
2026-09-26CVE-2026-5430WSO2 API Gateway Path Traversal Reaches Federal Remediation Deadline of September 27—KEV
2026-09-26CVE-2026-67279MikroTik RouterOS Unauthenticated Session Bypass Carries Federal Remediation Deadline of September 28—KEV
2026-09-26CVE-2026-0301CVE-2026-03017.5 HighUpdated
2026-09-26CVE-2026-0299CVE-2026-02997.8 HighUpdated
2026-09-26CVE-2026-0298CVE-2026-02988.1 HighUpdated
2026-09-26CVE-2026-0297CVE-2026-02978.1 HighUpdated
2026-09-26CVE-2026-0296CVE-2026-02967.4 HighUpdated
2026-09-26CVE-2026-20301CVE-2026-203018.6 HighUpdated
2026-09-26CVE-2026-0295CVE-2026-02957.0 HighUpdated
2026-09-26CVE-2026-0294CVE-2026-02947.8 HighUpdated
2026-09-26CVE-2026-76461CVE-2026-76461: Cisco Secure Email Gateway9.8 CriticalKEV
2026-09-26CVE-2026-75650CVE-2026-75650: Adobe Commerce and Magento10.0 CriticalKEV
2026-09-26CVE-2026-20200CVE-2026-202008.8 HighEPSS-Imminent
2026-09-26CVE-2026-20124CVE-2026-201247.7 HighUpdated
2026-09-26CVE-2026-9586CVE-2026-9586: Sangoma Switchvox SQL9.8 CriticalKEV
2026-09-26CVE-2026-76460CVE-2026-76460: Cisco Identity Services10.0 CriticalKEV
2026-09-26CVE-2026-20079CVE-2026-20079: Cisco Firewall Management10.0 CriticalKEV
2026-09-26CVE-2026-94127CVE-2026-94127: F5 BIG-IP APM Heap-based—KEV
2026-09-26CVE-2026-93952CVE-2026-93952: Arista VeloCloud Orchestrator—KEV
2026-09-26CVE-2026-93616CVE-2026-93616: Check Point Multiple Products—KEV
2026-09-26CVE-2026-9198CVE-2026-9198: IBM Langflow Code Injection9.8 CriticalKEV
2026-09-26CVE-2026-9082CVE-2026-9082: Drupal Core SQL Injection—KEV
2026-09-26CVE-2026-87886CVE-2026-87886: Acronis Backup Incorrect7.8 HighKEV
2026-09-26CVE-2026-87491CVE-2026-87491: Google Chromium V8 Out of8.8 HighKEV
2026-09-26CVE-2026-86218CVE-2026-86218: N-able N-central Static Code9.8 CriticalKEV
2026-09-26CVE-2026-86060CVE-2026-86060: MikroTik RouterOS Improper9.8 CriticalKEV
2026-09-26CVE-2026-85880CVE-2026-85880: Microsoft Windows Heap-Based7.8 HighKEV
2026-09-26CVE-2026-85706CVE-2026-85706: GitLab Community Edition and10.0 CriticalKEV
2026-09-26CVE-2026-85102CVE-2026-85102: Check Point Multiple Products—KEV
2026-09-26CVE-2026-85046CVE-2026-85046: Google Chromium V8 Type8.8 HighKEV
2026-09-26CVE-2026-84869ConnectWise ScreenConnect Missing Authorization and Privilege Management Vulnerabilities (CISA KEV)9.9 CriticalKEV
2026-09-26CVE-2026-8398CVE-2026-8398: Daemon Tools Lite Embedded—KEV
2026-09-26CVE-2026-83549CVE-2026-83549: SonicWall SMA1000 Appliances7.8 HighKEV
2026-09-26CVE-2026-83548CVE-2026-83548: SonicWall SMA1000 Appliances10.0 CriticalKEV
2026-09-26CVE-2026-82329CVE-2026-82329: JFrog Artifactory Improper9.8 CriticalKEV
2026-09-26CVE-2026-82078CVE-2026-82078: PaperCut NG/MF Unsafe9.1 CriticalKEV
2026-09-26CVE-2026-81963CVE-2026-81963: Microsoft Windows Link7.8 HighKEV
2026-09-26CVE-2026-81578CVE-2026-81578: PaperCut NG/MF Missing9.8 CriticalKEV
2026-09-26CVE-2026-8037CVE-2026-8037: Progress LoadMaster Command9.6 CriticalKEV
2026-09-26CVE-2026-7473CVE-2026-7473: Arista Extensible Operating—KEV
2026-09-26CVE-2026-73570CVE-2026-73570: Zimbra Collaboration Suite8.9 HighKEV
2026-09-26CVE-2026-72898CVE-2026-72898: Metabase SQL Injection10.0 CriticalKEV
2026-09-26CVE-2026-7273CVE-2026-7273: Zyxel GS1900 Series Switches—KEV
2026-09-26CVE-2026-72530CVE-2026-72530: TrueConf Server Code9.0 CriticalKEV
2026-09-26CVE-2026-72529CVE-2026-72529: TrueConf Server Missing9.8 CriticalKEV
2026-09-26CVE-2026-6973CVE-2026-6973: Ivanti Endpoint Manager—KEV
2026-09-26CVE-2026-68820CVE-2026-68820: Microsoft Windows Ancillary7.0 HighKEV
2026-09-26CVE-2026-67277CVE-2026-67277: MikroTik RouterOS Missing8.2 HighKEV
2026-09-26CVE-2026-65400CVE-2026-65400: Apple macOS Improper9.8 CriticalKEV
2026-09-26CVE-2026-64849CVE-2026-64849: MLflow Server-Side Request9.3 CriticalKEV
2026-09-26CVE-2026-63077CVE-2026-63077: JetBrains TeamCity9.8 CriticalKEV
2026-09-26CVE-2026-63030CVE-2026-63030: WordPress Core Interpretation—KEV
2026-09-26CVE-2026-60137CVE-2026-60137: WordPress Core SQL Injection—KEV
2026-09-26CVE-2026-60004CVE-2026-60004: Gitea Code Injection9.8 CriticalKEV
2026-09-26CVE-2026-59822CVE-2026-59822: BerriAI LiteLLM Improper8.2 HighKEV
2026-09-26CVE-2026-59310CVE-2026-59310: Broadcom VMware vCenter Path9.8 CriticalKEV
2026-09-26CVE-2026-58704CVE-2026-58704: Google Pixel Improper8.8 HighKEV
2026-09-26CVE-2026-56291CVE-2026-56291: Balbooa Forms Unrestricted—KEV
2026-09-26CVE-2026-56290CVE-2026-56290: Joomlack Page Builder—KEV
2026-09-26CVE-2026-56155CVE-2026-56155: Microsoft Active Directory—KEV
2026-09-26CVE-2026-55040CVE-2026-55040: Microsoft SharePoint Weak9.1 CriticalKEV
2026-09-26CVE-2026-54420CVE-2026-54420: LiteSpeed cPanel Plugin UNIX—KEV
2026-09-26CVE-2026-53362CVE-2026-53362: Linux Kernel Unspecified7.8 HighKEV
2026-09-26CVE-2026-53266CVE-2026-53266: Linux Kernel Out-of-Bounds8.8 HighKEV
2026-09-26CVE-2026-50751CVE-2026-50751: Check Point Security Gateway—KEV
2026-09-26CVE-2026-49869CVE-2026-49869: Kestra OSS OS Command10.0 CriticalKEV
2026-09-26CVE-2026-48939CVE-2026-48939: iCagenda Unrestricted Upload—KEV
2026-09-26CVE-2026-48908CVE-2026-48908: JoomShaper SP Page Builder—KEV
2026-09-26CVE-2026-48907CVE-2026-48907: Widget Factory Joomla Content—KEV
2026-09-26CVE-2026-48710CVE-2026-48710: Kludex Starlette HTTP6.5 MediumKEV
2026-09-26CVE-2026-48558CVE-2026-48558: SimpleHelp Authentication—KEV
2026-09-26CVE-2026-48172CVE-2026-48172: LiteSpeed cPanel Plugin—KEV
2026-09-26CVE-2026-48027CVE-2026-48027: Nx Console Embedded Malicious—KEV
2026-09-26CVE-2026-46817CVE-2026-46817: Oracle E-Business Suite—KEV
2026-09-26CVE-2026-45498CVE-2026-45498: Microsoft Defender Denial of—KEV
2026-09-26CVE-2026-45321CVE-2026-45321: TanStack Unspecified—KEV
2026-09-26CVE-2026-45247CVE-2026-45247: Mirasvit Full Page Cache—KEV
2026-09-26CVE-2026-42897CVE-2026-42897: Microsoft Exchange Server—KEV
2026-09-26CVE-2026-42018CVE-2026-42018: JFrog Artifactory Improper7.5 HighKEV
2026-09-26CVE-2026-42016CVE-2026-42016: JFrog Artifactory Incorrect8.1 HighKEV
2026-09-26CVE-2026-41940CVE-2026-41940: WebPros cPanel & WHM and WP2—KEV
2026-09-26CVE-2026-41091CVE-2026-41091: Microsoft Defender Link—KEV
2026-09-26CVE-2026-39987CVE-2026-39987: Marimo Remote Code Execution—KEV
2026-09-26CVE-2026-39808CVE-2026-39808: Fortinet FortiSandbox OS—KEV
2026-09-26CVE-2026-35616CVE-2026-35616: Fortinet FortiClient EMS—KEV
2026-09-26CVE-2026-35273CVE-2026-35273: Oracle PeopleSoft Enterprise—KEV
2026-09-26CVE-2026-34926CVE-2026-34926: Trend Micro Apex One—KEV
2026-09-26CVE-2026-34910CVE-2026-34910: Ubiquiti UniFi OS Improper—KEV
2026-09-26CVE-2026-34909CVE-2026-34909: Ubiquiti UniFi OS Path—KEV
2026-09-26CVE-2026-34908CVE-2026-34908: Ubiquiti UniFi OS Improper—KEV
2026-09-26CVE-2026-34486CVE-2026-34486: Apache Tomcat Missing7.5 HighKEV
2026-09-26CVE-2026-34197CVE-2026-34197: Apache ActiveMQ Improper—KEV
2026-09-26CVE-2026-33825CVE-2026-33825: Microsoft Defender—KEV
2026-09-26CVE-2026-33824CVE-2026-33824: Microsoft Internet Key9.8 CriticalKEV
2026-09-26CVE-2026-32202CVE-2026-32202: Microsoft Windows Protection—KEV
2026-09-26CVE-2026-31431CVE-2026-31431: Linux Kernel Incorrect—KEV
2026-09-26CVE-2026-28318CVE-2026-28318: SolarWinds Serv-U—KEV
2026-09-26CVE-2026-25089CVE-2026-25089: Fortinet FortiSandbox OS—KEV
2026-09-26CVE-2026-21962CVE-2026-21962: Oracle HTTP Server and Oracle10.0 CriticalKEV
2026-09-26CVE-2026-21643CVE-2026-21643: Fortinet FortiClient EMS SQL—KEV
2026-09-26CVE-2026-20349CVE-2026-20349: Cisco Secure Firewall8.6 HighKEV
2026-09-26CVE-2026-20316CVE-2026-20316: Cisco Secure Firewall—KEV
2026-09-26CVE-2026-20262CVE-2026-20262: Cisco Catalyst SD-WAN Manager—KEV
2026-09-26CVE-2026-20253CVE-2026-20253: Splunk Enterprise Missing—KEV
2026-09-26CVE-2026-20245CVE-2026-20245: Cisco Catalyst SD-WAN Manager—KEV
2026-09-26CVE-2026-20230CVE-2026-20230: Cisco Unified Communications—KEV
2026-09-26CVE-2026-20182CVE-2026-20182: Cisco Catalyst SD-WAN—KEV
2026-09-26CVE-2026-20133CVE-2026-20133: Cisco Catalyst SD-WAN Manager—KEV
2026-09-26CVE-2026-20128CVE-2026-20128: Cisco Catalyst SD-WAN Manager—KEV
2026-09-26CVE-2026-20122CVE-2026-20122: Cisco Catalyst SD-WAN Manager—KEV
2026-09-26CVE-2026-19490CVE-2026-19490: Citrix NetScaler9.8 CriticalKEV
2026-09-26CVE-2026-16812CVE-2026-16812: Arista VeloCloud Orchestrator—KEV
2026-09-26CVE-2026-16232CVE-2026-16232: Check Point SmartConsole—KEV
2026-09-26CVE-2026-15410CVE-2026-15410: SonicWall SMA1000 Appliances—KEV
2026-09-26CVE-2026-15409CVE-2026-15409: SonicWall SMA1000 Appliances—KEV
2026-09-26CVE-2026-1340CVE-2026-1340: Ivanti Endpoint Manager—KEV
2026-09-26CVE-2026-12569CVE-2026-12569: PTC Windchill and FlexPLM—KEV
2026-09-26CVE-2026-10520CVE-2026-10520: Ivanti Sentry OS Command—KEV
2026-09-26CVE-2026-0300CVE-2026-0300: Palo Alto Networks PAN-OS—KEV
2026-09-26CVE-2026-0257CVE-2026-0257: Palo Alto Networks PAN-OS—KEV
2026-09-26CVE-2025-68686CVE-2025-68686: Fortinet FortiOS Exposure of—KEV
2026-09-26CVE-2025-67038CVE-2025-67038: Lantronix EDS5000 Code—KEV
2026-09-26CVE-2025-62593CVE-2025-62593: Ray-Project Ray Code8.8 HighKEV
2026-09-26CVE-2025-60710CVE-2025-60710: Microsoft Windows Link—KEV
2026-09-26CVE-2025-48595CVE-2025-48595: Android Framework Integer—KEV
2026-09-26CVE-2025-39964CVE-2025-39964: Linux Kernel Race Condition7.8 HighKEV
2026-09-26CVE-2025-39682CVE-2025-39682: Linux Kernel Improper Check9.8 CriticalKEV
2026-09-26CVE-2025-32975CVE-2025-32975: Quest KACE Systems Management—KEV
2026-09-26CVE-2025-29635CVE-2025-29635: D-Link DIR-823X Command—KEV
2026-09-26CVE-2025-2749CVE-2025-2749: Kentico Xperience Path—KEV
2026-09-26CVE-2025-25249CVE-2025-25249: Fortinet Multiple Products8.1 HighKEV
2026-09-26CVE-2024-7399CVE-2024-7399: Samsung MagicINFO 9 Server—KEV
2026-09-26CVE-2024-57728CVE-2024-57728: SimpleHelp Path Traversal—KEV
2026-09-26CVE-2024-57726CVE-2024-57726: SimpleHelp Missing—KEV
2026-09-26CVE-2024-21182CVE-2024-21182: Oracle WebLogic Server—KEV
2026-09-26CVE-2024-1708CVE-2024-1708: ConnectWise ScreenConnect—KEV
2026-09-26CVE-2023-49105CVE-2023-49105: ownCloud Improper9.8 CriticalKEV
2026-09-26CVE-2023-4346CVE-2023-4346: KNX Association KNX Protocol—KEV
2026-09-26CVE-2023-36424CVE-2023-36424: Microsoft Windows—KEV
2026-09-26CVE-2023-21529CVE-2023-21529: Microsoft Exchange Server—KEV
2026-09-26CVE-2022-0995CVE-2022-0995: Linux Kernel Out-of-Bounds7.8 HighKEV
2026-09-26CVE-2022-0492CVE-2022-0492: Linux Kernel Improper—KEV
2026-09-26CVE-2021-27137CVE-2021-27137: DD-WRT Stack-Based Buffer—KEV
2026-09-26CVE-2021-23758CVE-2021-23758: Ajax.NET Professional8.1 HighKEV
2026-09-26CVE-2019-1068CVE-2019-1068: Microsoft SQL Server Remote8.8 HighKEV
2026-09-26CVE-2015-5287CVE-2015-5287: Red Hat Automatic Bug7.8 HighKEV
2026-09-26CVE-2015-3246CVE-2015-3246: Red Hat Libuser Race5.1 MediumKEV
2026-09-26CVE-2012-1854CVE-2012-1854: Microsoft Visual Basic for—KEV
2026-09-26CVE-2010-0806CVE-2010-0806: Microsoft Internet Explorer—KEV
2026-09-26CVE-2010-0249CVE-2010-0249: Microsoft Internet Explorer—KEV
2026-09-26CVE-2009-1537CVE-2009-1537: Microsoft DirectX NULL Byte—KEV
2026-09-26CVE-2009-0238CVE-2009-0238: Microsoft Office Remote Code—KEV
2026-09-26CVE-2008-4250CVE-2008-4250: Microsoft Windows Buffer—KEV
2026-09-26CVE-2008-4128CVE-2008-4128: Cisco IOS Cross-Site Request—KEV
2026-09-25CVE-2026-9203MarkLogic SSRF Flaw Exposes Cloud Instance Credentials to Low-Privilege Users8.5 HighUpdated
2026-09-25CVE-2026-9195Crafted Links Let Attackers Hijack MarkLogic Administrator Sessions Through Query Console XSS9.3 CriticalUpdated
2026-09-25CVE-2026-9193Low-Privilege Hadoop Role Escalates to Full Control of MarkLogic's Security Database9.9 CriticalUpdated
2026-09-25CVE-2026-9192Unauthenticated Attackers Can Impersonate Any MarkLogic User Through ODBC Authentication Bypass9.8 CriticalUpdated
2026-09-25CVE-2026-9190HTTP Request Smuggling Bypasses MarkLogic Authentication and Hijacks Sessions9.1 CriticalUpdated
2026-09-25CVE-2026-9089ConnectWise Automate agent trusts unverified plugin and update downloads, fixed in 2026.58.8 HighUpdated
2026-09-25CVE-2026-8709MarkLogic's REST document-patch API lets low-privileged users seize administrator control9.9 CriticalUpdated
2026-09-25CVE-2026-7557Unauthenticated attackers impersonate any MarkLogic administrator through a SAML signature flaw9.1 CriticalUpdated
2026-09-25CVE-2026-7329MarkLogic's SQL, SPARQL, and Optic query interfaces open a path from low-privileged access to full admin9.9 CriticalUpdated
2026-09-25CVE-2026-7327MarkLogic's document-processing pipeline lets an administrative REST role escalate further, exposing server-side data8.1 HighUpdated
2026-09-25CVE-2026-7326A CSRF flaw in MarkLogic's Admin UI lets attackers hijack lured administrators for configuration changes7.5 HighUpdated
2026-09-25CVE-2026-71474Red Hat insights-client logs a long-lived OpenShift pull-secret token that local pod-log access can expose7.1 HighUpdated
2026-09-25CVE-2026-68981Apache NiFi's gzip request handling bypasses size limits, opening a memory-exhaustion path, fixed in 2.11.07.5 HighUpdated
2026-09-25CVE-2026-68980Apache NiFi's asset-deletion API skips ownership checks across Parameter Contexts, fixed in 2.11.09.1 CriticalUpdated
2026-09-25CVE-2026-68979Missing authorization on Apache NiFi's Parameter Context updates can trigger code execution, fixed in 2.11.09.8 CriticalUpdated
2026-09-25CVE-2026-68060Pre-authentication attackers can exhaust memory in Apache Qpid Broker-J via oversized type handling, fixed in 10.1.07.5 HighUpdated
2026-09-25CVE-2026-67589Apache Qpid ProtonJ2 lets pre-authentication attackers trigger oversized memory allocations, fixed in 1.2.07.5 HighUpdated
2026-09-25CVE-2026-67588Unbounded symbol caching in Apache Qpid ProtonJ2 lets pre-authentication attackers exhaust memory, fixed in 1.2.07.5 HighUpdated
2026-09-25CVE-2026-67551Apache Qpid Proton-Dotnet lets pre-authentication attackers trigger oversized memory allocations, fixed in 1.1.07.5 HighUpdated
2026-09-25CVE-2026-67465Unbounded symbol caching in Apache Qpid Proton-Dotnet lets pre-authentication attackers exhaust memory, fixed in 1.1.07.5 HighUpdated
2026-09-25CVE-2026-66756A critical alternate-path flaw in Apache Tika precedes the 4.0.0-beta-1 fix, CVSS 9.89.8 CriticalUpdated
2026-09-25CVE-2026-66755Apache Tika's ISA-Tab parser lets crafted filenames leak arbitrary file contents into extracted text, fixed in 3.3.27.5 HighUpdated
2026-09-25CVE-2026-66273Apache Qpid Proton-J lets pre-authentication attackers trigger oversized memory allocations, fixed in 0.35.07.5 HighUpdated
2026-09-25CVE-2026-66257Unbounded symbol caching in Apache Qpid Proton-J lets pre-authentication attackers exhaust memory, fixed in 0.35.07.5 HighUpdated
2026-09-25CVE-2026-66015A JFrog Platform privilege-escalation flaw grants temporary admin access under admin-provisioned accounts7.2 HighNew
2026-09-25CVE-2026-66014An authentication weakness in JFrog Artifactory's internal request processing lets attackers escalate access8.8 HighNew
2026-09-25CVE-2026-65922Limited-access JFrog Artifactory users can write to restricted internal metadata under specific conditions7.1 HighNew
2026-09-25CVE-2026-65617A deserialization flaw in JFrog Artifactory package handling lets low-privileged users compromise confidentiality, integrity, and availability8.8 HighNew
2026-09-25CVE-2026-65616Flawed refresh-token signature validation lets non-admin JFrog users obtain a signed administrator token8.8 HighNew
2026-09-25CVE-2026-62391An incomplete fix for a prior Kyuubi flaw still lets clients bypass the local-directory allowlist via Spark config aliases, fixed in 1.12.08.1 HighUpdated
2026-09-25CVE-2026-61372A path traversal vulnerability in Apache Jena Fuseki is fixed in 6.2.07.5 HighUpdated
2026-09-25CVE-2026-6066ConnectWise Automate's Solution Center allowed unencrypted client-server traffic open to interception, fixed in 2026.47.1 HighUpdated
2026-09-25CVE-2026-60413An information-exposure flaw in Oracle Outside In Core lets a logged-in attacker take full control, CVSS 7.87.8 HighUpdated
2026-09-25CVE-2026-60412Insecure deserialization in Oracle Outside In Core lets a logged-in attacker take full control, CVSS 7.87.8 HighUpdated
2026-09-25CVE-2026-60393Unauthenticated network attackers can reach all Oracle Hyperion Infrastructure Technology data over HTTP, CVSS 7.57.5 HighUpdated
2026-09-25CVE-2026-60392Insecure deserialization in Oracle's Outside In PDF Export SDK lets a logged-in attacker take full control, CVSS 7.87.8 HighUpdated
2026-09-25CVE-2026-60391Unauthenticated network attackers can reach all Oracle Hyperion Financial Reporting data over HTTP, CVSS 7.57.5 HighUpdated
2026-09-25CVE-2026-6023Tampered RadFilter state in Telerik UI for ASP.NET AJAX enables server-side remote code execution8.1 HighUpdated
2026-09-25CVE-2026-6022Telerik UI for ASP.NET AJAX chunked upload flaw lets attackers bypass size limits and exhaust disk space7.5 HighUpdated
2026-09-25CVE-2026-5483Red Hat OpenShift AI's odh-dashboard leaks Kubernetes service account tokens through a NodeJS endpoint8.5 HighNew
2026-09-25CVE-2026-54100Red Hat's Windows Machine Config Operator skips SSH host-key checks, letting adjacent attackers capture node bootstrap credentials8.3 HighUpdated
2026-09-25CVE-2026-54099A compromised Windows node can forge a cluster-administrator certificate through WMCO's CSR auto-approver, CVSS 8.88.8 HighUpdated
2026-09-25CVE-2026-52680Path traversal in Apache Kyuubi's REST batch upload lets remote attackers write files outside the intended directory, fixed in 1.12.09.8 CriticalUpdated
2026-09-25CVE-2026-5174Improper input validation in Progress MOVEit Automation opens a path to privilege escalation7.7 HighUpdated
2026-09-25CVE-2026-47629Improper input validation in NVIDIA Triton Inference Server on Linux can trigger denial of service7.5 HighUpdated
2026-09-25CVE-2026-47628Unbounded resource allocation in NVIDIA Triton Inference Server on Linux opens a denial-of-service path7.5 HighUpdated
2026-09-25CVE-2026-47627A critical path-traversal flaw in NVIDIA Triton Inference Server on Linux enables denial of service, CVSS 9.89.8 CriticalUpdated
2026-09-25CVE-2026-4740Red Hat Advanced Cluster Management lets a managed-cluster admin forge certificates for cross-cluster privilege escalation8.2 HighUpdated
2026-09-25CVE-2026-42017An event-handling flaw in JFrog Artifactory exposes privileged authorization material to lower-privileged users8.8 HighNew
2026-09-25CVE-2026-41724Stored XSS in VMware Cloud Foundation Operations lets privileged users trigger admin actions via injected scripts8.0 HighUpdated
2026-09-25CVE-2026-41723A stored XSS spanning VMware Cloud Foundation Operations and vSphere lets privileged users trigger admin actions via injected scripts8.0 HighUpdated
2026-09-25CVE-2026-41722Another stored XSS across VMware Cloud Foundation Operations and vSphere lets privileged users trigger admin actions via injected scripts8.0 HighUpdated
2026-09-25CVE-2026-41702A TOCTOU flaw in a VMware Fusion SETUID binary lets local non-admin users escalate to root7.8 HighUpdated
2026-09-25CVE-2026-40141A critical query-injection flaw in BeyondTrust Remote Support lets low-privileged users reach unauthorized resources, CVSS 9.99.9 CriticalUpdated
2026-09-25CVE-2026-40140Unauthenticated attackers can crash BeyondTrust Remote Support appliances via a network-communication flaw7.5 HighUpdated
2026-09-24CVE-2017-20235CVE-2017-202359.1 CriticalUpdated
2026-09-23CVE-2026-3517CVE-2026-35178.4 HighEPSS-Imminent
2026-09-23CVE-2026-29146CVE-2026-291467.5 HighEPSS-Imminent
2026-09-23CVE-2026-20180CVE-2026-201809.9 CriticalEPSS-Imminent
2026-09-23CVE-2026-39813CVE-2026-398139.8 CriticalEPSS-Imminent
2026-09-23CVE-2026-40688CVE-2026-406887.2 HighEPSS-Imminent
2026-09-23CVE-2026-4670CVE-2026-46709.8 CriticalEPSS-Imminent
2026-09-23CVE-2026-59309CVE-2026-593099.8 CriticalEPSS-Imminent
2026-09-23CVE-2026-3518CVE-2026-35188.4 HighEPSS-Imminent
2026-09-23CVE-2026-20147CVE-2026-201479.9 CriticalEPSS-Imminent
2026-09-20CVE-2026-70468CVE-2026-704688.1 HighUpdated
2026-09-20CVE-2026-70465CVE-2026-704658.1 HighUpdated
2026-09-20CVE-2026-50516CVE-2026-505169.4 CriticalUpdated
2026-09-20CVE-2026-26035CVE-2026-260359.8 CriticalUpdated
2026-09-20CVE-2026-20273CVE-2026-202738.6 HighUpdated
2026-09-20CVE-2026-20272CVE-2026-202729.8 CriticalUpdated
2026-09-20CVE-2026-20271CVE-2026-202718.6 HighUpdated
2026-09-20CVE-2026-20270CVE-2026-202708.6 HighUpdated
2026-09-20CVE-2026-20269CVE-2026-202698.6 HighUpdated
2026-09-20CVE-2026-20268CVE-2026-202688.6 HighUpdated
2026-09-20CVE-2026-20267CVE-2026-202679.0 CriticalUpdated
2026-09-20CVE-2026-70332CVE-2026-703329.6 CriticalUpdated
2026-09-20CVE-2026-66322CVE-2026-663227.1 HighUpdated
2026-09-20CVE-2026-66321CVE-2026-663217.4 HighUpdated
2026-09-20CVE-2026-66318CVE-2026-663188.1 HighUpdated
2026-09-20CVE-2026-66315CVE-2026-663157.5 HighUpdated
2026-09-20CVE-2026-66310CVE-2026-663107.7 HighUpdated
2026-09-20CVE-2026-65802CVE-2026-658027.4 HighUpdated
2026-09-20CVE-2026-65668CVE-2026-656688.8 HighUpdated
2026-09-20CVE-2026-65667CVE-2026-6566710.0 CriticalUpdated
2026-09-20CVE-2026-63508CVE-2026-6350810.0 CriticalUpdated
2026-09-20CVE-2026-62918CVE-2026-629187.5 HighUpdated
2026-09-20CVE-2026-62896CVE-2026-628969.6 CriticalUpdated
2026-09-20CVE-2026-62873CVE-2026-628739.8 CriticalUpdated
2026-09-20CVE-2026-62870CVE-2026-628708.8 HighUpdated
2026-09-20CVE-2026-59115CVE-2026-591159.9 CriticalUpdated
2026-09-20CVE-2026-58612CVE-2026-586127.4 HighUpdated
2026-09-20CVE-2026-57105CVE-2026-571058.0 HighUpdated
2026-09-20CVE-2025-40582CVE-2025-405827.8 HighUpdated
2026-09-20CVE-2025-40581CVE-2025-405817.1 HighUpdated
2026-09-20CVE-2025-40574CVE-2025-405747.8 HighUpdated
2026-09-19CVE-2026-47623CVE-2026-476238.2 HighUpdated
2026-09-19CVE-2026-47618CVE-2026-476187.5 HighUpdated
2026-09-19CVE-2026-47617CVE-2026-476177.5 HighUpdated
2026-09-19CVE-2026-47616CVE-2026-476167.5 HighUpdated
2026-09-19CVE-2026-47615CVE-2026-476157.5 HighUpdated
2026-09-19CVE-2026-47614CVE-2026-476147.5 HighUpdated
2026-09-19CVE-2026-47613CVE-2026-476137.5 HighUpdated
2026-09-19CVE-2026-47612CVE-2026-476127.5 HighUpdated
2026-09-19CVE-2026-24255CVE-2026-242557.5 HighUpdated
2026-09-19CVE-2026-24254CVE-2026-242549.8 CriticalUpdated
2026-09-19CVE-2026-24253CVE-2026-242538.2 HighUpdated

No advisories match this filter.