KEV topic
Critical-severity KEV entries (CVSS 9.0+)
KEV entries with a CVSS v3 base score of 9.0 or higher — the CRITICAL band per the CVSS specification, meaning near-maximum impact and exploitation that typically requires little attacker effort. These are the patch-this-week items regardless of vendor or product category. Updated daily from the CISA KEV catalog.
CVE-2026-50522 · Microsoft SharePointDeserialization of Untrusted Data VulnerabilityPatch this weekAdded to KEV Jul 22, 2026
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
Affects anyone running Microsoft SharePoint. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.
CVE-2026-58644 · Microsoft SharePointDeserialization of Untrusted Data VulnerabilityPatch this weekAdded to KEV Jul 16, 2026
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
Affects anyone running Microsoft SharePoint. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.
Fortinet FortiSandbox: 2 CVEsPatch this weekadded Jul 16, 2026
Fortinet FortiSandbox OS Command Injection Vulnerability
Affects anyone whose internet connection goes through a Fortinet appliance — typically a FortiGate firewall or FortiClient VPN. The firewall sits between every device in the office and the internet; exploitation can mean an attacker gets inside the network perimeter without touching a workstation.
Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.
Fortinet FortiSandbox OS Command Injection Vulnerability
Affects anyone whose internet connection goes through a Fortinet appliance — typically a FortiGate firewall or FortiClient VPN. The firewall sits between every device in the office and the internet; exploitation can mean an attacker gets inside the network perimeter without touching a workstation.
Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.
CVE-2026-15409 · SonicWall SMA1000 AppliancesServer-Side Request Forgery VulnerabilityKnown ransomware usePatch nowAdded to KEV Jul 14, 2026
SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
Affects anyone whose network is fronted by a SonicWall firewall or SSL VPN. The device sits at the edge between your office and the internet and authenticates remote workers — exploitation typically means an attacker reaches inside without needing a user credential.
SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.
CVE-2026-48282 · Adobe ColdFusionPath Traversal VulnerabilityPatch this weekAdded to KEV Jul 7, 2026
Adobe ColdFusion Path Traversal Vulnerability
Affects anyone running Adobe ColdFusion. If it's part of your document workflow, exploitation can lead to code execution when a user opens an attacker-controlled file.
Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user.
Ubiquiti UniFi OS: 3 CVEsPatch this weekadded Jun 23, 2026
Ubiquiti UniFi OS Improper Input Validation Vulnerability
Affects anyone running Ubiquiti UniFi networking gear (access points, switches, security gateways, NVRs). The gear carries internal network traffic and often hosts video surveillance — exploitation can expose network traffic or grant management access to the network itself.
Ubiquiti UniFi OS contains an improper input validation vulnerability which could allow a malicious actor with access to the network to conduct command injection.
Ubiquiti UniFi OS Path Traversal Vulnerability
Affects anyone running Ubiquiti UniFi networking gear (access points, switches, security gateways, NVRs). The gear carries internal network traffic and often hosts video surveillance — exploitation can expose network traffic or grant management access to the network itself.
Ubiquiti UniFi OS contains a path traversal vulnerability which could allow a malicious actor with access to the network to access files on the underlying system that could be manipulated to access an underlying account.
Ubiquiti UniFi OS Improper Access Control Vulnerability
Affects anyone running Ubiquiti UniFi networking gear (access points, switches, security gateways, NVRs). The gear carries internal network traffic and often hosts video surveillance — exploitation can expose network traffic or grant management access to the network itself.
Ubiquiti UniFi OS contains an improper access control vulnerability which could allow a malicious actor with access to the network to make unauthorized changes to the system.
CVE-2026-10520 · Ivanti SentryOS Command Injection VulnerabilityPatch this weekAdded to KEV Jun 11, 2026
Ivanti Sentry OS Command Injection Vulnerability
Affects anyone using Ivanti VPN (Connect Secure or Pulse) or Ivanti endpoint management. The VPN is what remote workers use to reach internal systems; the endpoint management tool typically has admin reach into every laptop — exploitation in either is high-impact.
Ivanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve root-level remote code execution. This vulnerability can be successfully exploited in cases where the Sentry appliance is in an unmanaged state with its endpoints externally reachable. The use of mTLS with EPMM or restricted HTTPS access through Neurons for MDM makes interfaces inaccessible to external actors.
CVE-2026-0257 · Palo Alto Networks PAN-OSAuthentication Bypass VulnerabilityKnown ransomware usePatch nowAdded to KEV May 29, 2026
Palo Alto Networks PAN-OS Authentication Bypass Vulnerability
Affects anyone behind a Palo Alto firewall or using GlobalProtect VPN. The firewall is the network edge; the VPN is how remote workers reach inside the perimeter — exploitation puts an attacker on the internal network without touching a workstation.
Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection.
CVE-2008-4250 · Microsoft WindowsBuffer Overflow VulnerabilityPatch this weekAdded to KEV May 20, 2026
Microsoft Windows Buffer Overflow Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization.
CVE-2026-20182 · Cisco Catalyst SD-WANController Authentication Bypass VulnerabilityPatch this weekAdded to KEV May 14, 2026
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
Affects anyone with Cisco networking or security appliances on their network — typically a firewall, switch, or remote-access VPN. That device controls traffic to and from every workstation; exploitation can mean an attacker pivots inside the network without touching any user device.
Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.
CVE-2026-0300 · Palo Alto Networks PAN-OSOut-of-bounds Write VulnerabilityPatch this weekAdded to KEV May 6, 2026
Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability
Affects anyone behind a Palo Alto firewall or using GlobalProtect VPN. The firewall is the network edge; the VPN is how remote workers reach inside the perimeter — exploitation puts an attacker on the internal network without touching a workstation.
Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets.
CVE-2026-21643 · Fortinet FortiClient EMSSQL Injection VulnerabilityPatch this weekAdded to KEV Apr 13, 2026
Fortinet FortiClient EMS SQL Injection Vulnerability
Affects anyone whose internet connection goes through a Fortinet appliance — typically a FortiGate firewall or FortiClient VPN. The firewall sits between every device in the office and the internet; exploitation can mean an attacker gets inside the network perimeter without touching a workstation.
Fortinet FortiClient EMS contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
CVE-2026-1340 · Ivanti Endpoint Manager Mobile (EPMM)Code Injection VulnerabilityPatch this weekAdded to KEV Apr 8, 2026
Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
Affects anyone using Ivanti VPN (Connect Secure or Pulse) or Ivanti endpoint management. The VPN is what remote workers use to reach internal systems; the endpoint management tool typically has admin reach into every laptop — exploitation in either is high-impact.
Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution.
CVE-2026-35616 · Fortinet FortiClient EMSImproper Access Control VulnerabilityPatch this weekAdded to KEV Apr 6, 2026
Fortinet FortiClient EMS Improper Access Control Vulnerability
Affects anyone whose internet connection goes through a Fortinet appliance — typically a FortiGate firewall or FortiClient VPN. The firewall sits between every device in the office and the internet; exploitation can mean an attacker gets inside the network perimeter without touching a workstation.
Fortinet FortiClient EMS contains an improper access control vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.
CVE-2026-20131 · Cisco Secure Firewall Management Center (FMC)Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data VulnerabilityKnown ransomware usePatch nowAdded to KEV Mar 19, 2026
Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability
Affects anyone with Cisco networking or security appliances on their network — typically a firewall, switch, or remote-access VPN. That device controls traffic to and from every workstation; exploitation can mean an attacker pivots inside the network without touching any user device.
Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain a deserialization of untrusted data vulnerability in the web-based management interface that could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device.
CVE-2026-20963 · Microsoft SharePointDeserialization of Untrusted Data VulnerabilityPatch this weekAdded to KEV Mar 18, 2026
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
Affects anyone running Microsoft SharePoint. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.
CVE-2026-20127 · Cisco Catalyst SD-WAN Controller and ManagerAuthentication Bypass VulnerabilityPatch this weekAdded to KEV Feb 25, 2026
Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability
Affects anyone with Cisco networking or security appliances on their network — typically a firewall, switch, or remote-access VPN. That device controls traffic to and from every workstation; exploitation can mean an attacker pivots inside the network without touching any user device.
Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, contain an authentication bypass vulnerability could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to an affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric.
CVE-2024-43468 · Microsoft Configuration ManagerSQL Injection VulnerabilityPatch this weekAdded to KEV Feb 12, 2026
Microsoft Configuration Manager SQL Injection Vulnerability
Affects anyone running Microsoft Configuration Manager. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
Microsoft Configuration Manager contains an SQL injection vulnerability. An unauthenticated attacker could exploit this vulnerability by sending specially crafted requests to the target environment which are processed in an unsafe manner enabling the attacker to execute commands on the server and/or underlying database.
CVE-2026-1281 · Ivanti Endpoint Manager Mobile (EPMM)Code Injection VulnerabilityPatch this weekAdded to KEV Jan 29, 2026
Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
Affects anyone using Ivanti VPN (Connect Secure or Pulse) or Ivanti endpoint management. The VPN is what remote workers use to reach internal systems; the endpoint management tool typically has admin reach into every laptop — exploitation in either is high-impact.
Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution.
CVE-2026-24858 · Fortinet Multiple ProductsAuthentication Bypass Using an Alternate Path or Channel VulnerabilityPatch this weekAdded to KEV Jan 27, 2026
Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability
Affects anyone whose internet connection goes through a Fortinet appliance — typically a FortiGate firewall or FortiClient VPN. The firewall sits between every device in the office and the internet; exploitation can mean an attacker gets inside the network perimeter without touching a workstation.
Fortinet FortiAnalyzer, FortiManager, FortiOS, and FortiProxy contain an authentication bypass using an alternate path or channel that could allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.
CVE-2025-20393 · Cisco Multiple ProductsImproper Input Validation VulnerabilityPatch this weekAdded to KEV Dec 17, 2025
Cisco Multiple Products Improper Input Validation Vulnerability
Affects anyone with Cisco networking or security appliances on their network — typically a firewall, switch, or remote-access VPN. That device controls traffic to and from every workstation; exploitation can mean an attacker pivots inside the network without touching any user device.
Cisco Secure Email Gateway, Secure Email, AsyncOS Software, and Web Manager appliances contains an improper input validation vulnerability that allows threat actors to execute arbitrary commands with root privileges on the underlying operating system of an affected appliance.
CVE-2025-59718 · Fortinet Multiple ProductsImproper Verification of Cryptographic Signature VulnerabilityPatch this weekAdded to KEV Dec 16, 2025
Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability
Affects anyone whose internet connection goes through a Fortinet appliance — typically a FortiGate firewall or FortiClient VPN. The firewall sits between every device in the office and the internet; exploitation can mean an attacker gets inside the network perimeter without touching a workstation.
Fortinet FortiOS, FortiSwitchMaster, FortiProxy, and FortiWeb contain an improper verification of cryptographic signature vulnerability that may allow an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML message. Please be aware that CVE-2025-59719 pertains to the same problem and is mentioned in the same vendor advisory. Ensure to apply all patches mentioned in the advisory.
CVE-2025-64446 · Fortinet FortiWebPath Traversal VulnerabilityPatch this weekAdded to KEV Nov 14, 2025
Fortinet FortiWeb Path Traversal Vulnerability
Affects anyone whose internet connection goes through a Fortinet appliance — typically a FortiGate firewall or FortiClient VPN. The firewall sits between every device in the office and the internet; exploitation can mean an attacker gets inside the network perimeter without touching a workstation.
Fortinet FortiWeb contains a relative path traversal vulnerability that may allow an unauthenticated attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.
CVE-2025-59287 · Microsoft WindowsServer Update Service (WSUS) Deserialization of Untrusted Data VulnerabilityPatch this weekAdded to KEV Oct 24, 2025
Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Server Update Service (WSUS) contains a deserialization of untrusted data vulnerability that allows for remote code execution.
- KB5070883
- KB5070884
- KB5070892
- KB5070881
- +5 more
CVE-2025-54236 · Adobe Commerce and MagentoImproper Input Validation VulnerabilityPatch this weekAdded to KEV Oct 24, 2025
Adobe Commerce and Magento Improper Input Validation Vulnerability
Affects anyone running Adobe Commerce and Magento. If it's part of your document workflow, exploitation can lead to code execution when a user opens an attacker-controlled file.
Adobe Commerce and Magento Open Source contain an improper input validation vulnerability that could allow an attacker to take over customer accounts through the Commerce REST API.
CVE-2025-54253 · Adobe Experience Manager (AEM) FormsExperience Manager Forms Code Execution VulnerabilityPatch this weekAdded to KEV Oct 15, 2025
Adobe Experience Manager Forms Code Execution Vulnerability
Affects anyone running Adobe Experience Manager (AEM) Forms. If it's part of your document workflow, exploitation can lead to code execution when a user opens an attacker-controlled file.
Adobe Experience Manager Forms in JEE contains an unspecified vulnerability that allows for arbitrary code execution.
CVE-2025-20333 · Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat DefenseSecure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Buffer Overflow VulnerabilityPatch this weekAdded to KEV Sep 25, 2025
Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Buffer Overflow Vulnerability
Affects anyone with Cisco networking or security appliances on their network — typically a firewall, switch, or remote-access VPN. That device controls traffic to and from every workstation; exploitation can mean an attacker pivots inside the network without touching any user device.
Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Software VPN Web Server contain a buffer overflow vulnerability that allows for remote code execution. This vulnerability could be chained with CVE-2025-20362.
CVE-2025-10585 · Google Chromium V8Type Confusion VulnerabilityPatch this weekAdded to KEV Sep 23, 2025
Google Chromium V8 Type Confusion Vulnerability
Affects anyone using Chrome or Chromium as their browser. The browser is where staff log into cloud apps, banking, and client portals — exploitation can mean session theft or credential exposure for every site you're signed into.
Google Chromium contains a type confusion vulnerability in the V8 JavaScript and WebAssembly engine.
CVE-2025-43300 · Apple iOS, iPadOS, and macOSOut-of-Bounds Write VulnerabilityPatch this weekAdded to KEV Aug 21, 2025
Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability
Affects anyone running Macs, iPhones, or iPads in the office. For a small practice, Apple endpoints are typically how staff handle email, browse client portals, and store local case files — exploitation gives an attacker access to that data on the device.
Apple iOS, iPadOS, and macOS contain an out-of-bounds write vulnerability in the Image I/O framework.
Cisco Identity Services Engine: 2 CVEsPatch this weekadded Jul 28, 2025
Cisco Identity Services Engine Injection Vulnerability
Affects anyone with Cisco networking or security appliances on their network — typically a firewall, switch, or remote-access VPN. That device controls traffic to and from every workstation; exploitation can mean an attacker pivots inside the network without touching any user device.
Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing an attacker to exploit this vulnerability by submitting a crafted API request. Successful exploitation could allow an attacker to perform remote code execution and obtaining root privileges on an affected device.
Cisco Identity Services Engine Injection Vulnerability
Affects anyone with Cisco networking or security appliances on their network — typically a firewall, switch, or remote-access VPN. That device controls traffic to and from every workstation; exploitation can mean an attacker pivots inside the network without touching any user device.
Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing an attacker to exploit this vulnerability by submitting a crafted API request. Successful exploitation could allow an attacker to perform remote code execution and obtaining root privileges on an affected device.
CVE-2025-53770 · Microsoft SharePointDeserialization of Untrusted Data VulnerabilityKnown ransomware usePatch nowAdded to KEV Jul 20, 2025
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
Affects anyone running Microsoft SharePoint. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
Microsoft SharePoint Server on-premises contains a deserialization of untrusted data vulnerability that could allow an unauthorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-53771. CVE-2025-53770 is a patch bypass for CVE-2025-49704, and the updates for CVE-2025-53770 include more robust protection than those for CVE-2025-49704.
CVE-2025-25257 · Fortinet FortiWebSQL Injection VulnerabilityPatch this weekAdded to KEV Jul 18, 2025
Fortinet FortiWeb SQL Injection Vulnerability
Affects anyone whose internet connection goes through a Fortinet appliance — typically a FortiGate firewall or FortiClient VPN. The firewall sits between every device in the office and the internet; exploitation can mean an attacker gets inside the network perimeter without touching a workstation.
Fortinet FortiWeb contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests.
CVE-2025-32756 · Fortinet Multiple ProductsStack-Based Buffer Overflow VulnerabilityPatch this weekAdded to KEV May 14, 2025
Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability
Affects anyone whose internet connection goes through a Fortinet appliance — typically a FortiGate firewall or FortiClient VPN. The firewall sits between every device in the office and the internet; exploitation can mean an attacker gets inside the network perimeter without touching a workstation.
Fortinet FortiFone, FortiVoice, FortiNDR and FortiMail contain a stack-based overflow vulnerability that may allow a remote unauthenticated attacker to execute arbitrary code or commands via crafted HTTP requests.
Apple Multiple Products: 2 CVEsPatch this weekadded Apr 17, 2025
Apple Multiple Products Memory Corruption Vulnerability
Affects anyone running Macs, iPhones, or iPads in the office. For a small practice, Apple endpoints are typically how staff handle email, browse client portals, and store local case files — exploitation gives an attacker access to that data on the device.
Apple iOS, iPadOS, macOS, and other Apple products contain a memory corruption vulnerability that allows for code execution when processing an audio stream in a maliciously crafted media file.
Apple Multiple Products Arbitrary Read and Write Vulnerability
Affects anyone running Macs, iPhones, or iPads in the office. For a small practice, Apple endpoints are typically how staff handle email, browse client portals, and store local case files — exploitation gives an attacker access to that data on the device.
Apple iOS, iPadOS, macOS, and other Apple products contain an arbitrary read and write vulnerability that allows an attacker to bypass Pointer Authentication.
CVE-2025-22457 · Ivanti Connect Secure, Policy Secure, and ZTA GatewaysStack-Based Buffer Overflow VulnerabilityKnown ransomware usePatch nowAdded to KEV Apr 4, 2025
Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability
Affects anyone using Ivanti VPN (Connect Secure or Pulse) or Ivanti endpoint management. The VPN is what remote workers use to reach internal systems; the endpoint management tool typically has admin reach into every laptop — exploitation in either is high-impact.
Ivanti Connect Secure, Policy Secure, and ZTA Gateways contains a stack-based buffer overflow vulnerability that allows a remote unauthenticated attacker to achieve remote code execution.
CVE-2024-20439 · Cisco Smart Licensing UtilityStatic Credential VulnerabilityPatch this weekAdded to KEV Mar 31, 2025
Cisco Smart Licensing Utility Static Credential Vulnerability
Affects anyone with Cisco networking or security appliances on their network — typically a firewall, switch, or remote-access VPN. That device controls traffic to and from every workstation; exploitation can mean an attacker pivots inside the network without touching any user device.
Cisco Smart Licensing Utility contains a static credential vulnerability that allows an unauthenticated, remote attacker to log in to an affected system and gain administrative credentials.
CVE-2025-24201 · Apple Multiple ProductsWebKit Out-of-Bounds Write VulnerabilityPatch this weekAdded to KEV Mar 13, 2025
Apple Multiple Products WebKit Out-of-Bounds Write Vulnerability
Affects anyone running Macs, iPhones, or iPads in the office. For a small practice, Apple endpoints are typically how staff handle email, browse client portals, and store local case files — exploitation gives an attacker access to that data on the device.
Apple iOS, iPadOS, macOS, and other Apple products contain an out-of-bounds write vulnerability in WebKit that may allow maliciously crafted web content to break out of Web Content sandbox. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Ivanti Endpoint Manager (EPM): 3 CVEsPatch this weekadded Mar 10, 2025
Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability
Affects anyone using Ivanti VPN (Connect Secure or Pulse) or Ivanti endpoint management. The VPN is what remote workers use to reach internal systems; the endpoint management tool typically has admin reach into every laptop — exploitation in either is high-impact.
Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information.
Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability
Affects anyone using Ivanti VPN (Connect Secure or Pulse) or Ivanti endpoint management. The VPN is what remote workers use to reach internal systems; the endpoint management tool typically has admin reach into every laptop — exploitation in either is high-impact.
Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information.
Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability
Affects anyone using Ivanti VPN (Connect Secure or Pulse) or Ivanti endpoint management. The VPN is what remote workers use to reach internal systems; the endpoint management tool typically has admin reach into every laptop — exploitation in either is high-impact.
Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information.
CVE-2017-3066 · Adobe ColdFusionDeserialization VulnerabilityPatch this weekAdded to KEV Feb 24, 2025
Adobe ColdFusion Deserialization Vulnerability
Affects anyone running Adobe ColdFusion. If it's part of your document workflow, exploitation can lead to code execution when a user opens an attacker-controlled file.
Adobe ColdFusion contains a deserialization vulnerability in the Apache BlazeDS library that allows for arbitrary code execution.
CVE-2025-0108 · Palo Alto Networks PAN-OSAuthentication Bypass VulnerabilityPatch this weekAdded to KEV Feb 18, 2025
Palo Alto Networks PAN-OS Authentication Bypass Vulnerability
Affects anyone behind a Palo Alto firewall or using GlobalProtect VPN. The firewall is the network edge; the VPN is how remote workers reach inside the perimeter — exploitation puts an attacker on the internal network without touching a workstation.
Palo Alto Networks PAN-OS contains an authentication bypass vulnerability in its management web interface. This vulnerability allows an unauthenticated attacker with network access to the management web interface to bypass the authentication normally required and invoke certain PHP scripts.
CVE-2024-53704 · SonicWall SonicOSSSLVPN Improper Authentication VulnerabilityKnown ransomware usePatch nowAdded to KEV Feb 18, 2025
SonicWall SonicOS SSLVPN Improper Authentication Vulnerability
Affects anyone whose network is fronted by a SonicWall firewall or SSL VPN. The device sits at the edge between your office and the internet and authenticates remote workers — exploitation typically means an attacker reaches inside without needing a user credential.
SonicWall SonicOS contains an improper authentication vulnerability in the SSLVPN authentication mechanism that allows a remote attacker to bypass authentication.
CVE-2024-21413 · Microsoft Office OutlookOutlook Improper Input Validation VulnerabilityPatch this weekAdded to KEV Feb 6, 2025
Microsoft Outlook Improper Input Validation Vulnerability
Affects anyone using Microsoft 365 or Office to compose, store, or send email, documents, or spreadsheets. In a small practice, that's typically where client communications, engagement letters, and case notes live — credential compromise here means an attacker reads everything that platform stores.
Microsoft Outlook contains an improper input validation vulnerability that allows for remote code execution. Successful exploitation of this vulnerability would allow an attacker to bypass the Office Protected View and open in editing mode rather than protected mode.
CVE-2025-24085 · Apple Multiple ProductsUse-After-Free VulnerabilityPatch this weekAdded to KEV Jan 29, 2025
Apple Multiple Products Use-After-Free Vulnerability
Affects anyone running Macs, iPhones, or iPads in the office. For a small practice, Apple endpoints are typically how staff handle email, browse client portals, and store local case files — exploitation gives an attacker access to that data on the device.
Apple iOS, macOS, and other Apple products contain a user-after-free vulnerability that could allow a malicious application to elevate privileges.
CVE-2025-23006 · SonicWall SMA1000 AppliancesDeserialization VulnerabilityKnown ransomware usePatch nowAdded to KEV Jan 24, 2025
SonicWall SMA1000 Appliances Deserialization Vulnerability
Affects anyone whose network is fronted by a SonicWall firewall or SSL VPN. The device sits at the edge between your office and the internet and authenticates remote workers — exploitation typically means an attacker reaches inside without needing a user credential.
SonicWall SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC) contain a deserialization of untrusted data vulnerability, which can enable a remote, unauthenticated attacker to execute arbitrary OS commands.
CVE-2024-55591 · Fortinet FortiOS and FortiProxyAuthentication Bypass VulnerabilityKnown ransomware usePatch nowAdded to KEV Jan 14, 2025
Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability
Affects anyone whose internet connection goes through a Fortinet appliance — typically a FortiGate firewall or FortiClient VPN. The firewall sits between every device in the office and the internet; exploitation can mean an attacker gets inside the network perimeter without touching a workstation.
Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that may allow an unauthenticated, remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.
CVE-2025-0282 · Ivanti Connect Secure, Policy Secure, and ZTA GatewaysStack-Based Buffer Overflow VulnerabilityKnown ransomware usePatch nowAdded to KEV Jan 8, 2025
Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability
Affects anyone using Ivanti VPN (Connect Secure or Pulse) or Ivanti endpoint management. The VPN is what remote workers use to reach internal systems; the endpoint management tool typically has admin reach into every laptop — exploitation in either is high-impact.
Ivanti Connect Secure, Policy Secure, and ZTA Gateways contain a stack-based buffer overflow which can lead to unauthenticated remote code execution.
CVE-2024-0012 · Palo Alto Networks PAN-OSManagement Interface Authentication Bypass VulnerabilityKnown ransomware usePatch nowAdded to KEV Nov 18, 2024
Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability
Affects anyone behind a Palo Alto firewall or using GlobalProtect VPN. The firewall is the network edge; the VPN is how remote workers reach inside the perimeter — exploitation puts an attacker on the internal network without touching a workstation.
Palo Alto Networks PAN-OS contains an authentication bypass vulnerability in the web-based management interface for several PAN-OS products, including firewalls and VPN concentrators.
CVE-2024-9465 · Palo Alto Networks ExpeditionSQL Injection VulnerabilityPatch this weekAdded to KEV Nov 14, 2024
Palo Alto Networks Expedition SQL Injection Vulnerability
Affects anyone behind a Palo Alto firewall or using GlobalProtect VPN. The firewall is the network edge; the VPN is how remote workers reach inside the perimeter — exploitation puts an attacker on the internal network without touching a workstation.
Palo Alto Networks Expedition contains a SQL injection vulnerability that allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. With this, attackers can also create and read arbitrary files on the Expedition system.
CVE-2024-5910 · Palo Alto Networks ExpeditionMissing Authentication VulnerabilityPatch this weekAdded to KEV Nov 7, 2024
Palo Alto Networks Expedition Missing Authentication Vulnerability
Affects anyone behind a Palo Alto firewall or using GlobalProtect VPN. The firewall is the network edge; the VPN is how remote workers reach inside the perimeter — exploitation puts an attacker on the internal network without touching a workstation.
Palo Alto Networks Expedition contains a missing authentication vulnerability that allows an attacker with network access to takeover an Expedition admin account and potentially access configuration secrets, credentials, and other data.
CVE-2024-47575 · Fortinet FortiManagerMissing Authentication VulnerabilityPatch this weekAdded to KEV Oct 23, 2024
Fortinet FortiManager Missing Authentication Vulnerability
Affects anyone whose internet connection goes through a Fortinet appliance — typically a FortiGate firewall or FortiClient VPN. The firewall sits between every device in the office and the internet; exploitation can mean an attacker gets inside the network perimeter without touching a workstation.
Fortinet FortiManager contains a missing authentication vulnerability in the fgfmd daemon that allows a remote, unauthenticated attacker to execute arbitrary code or commands via specially crafted requests.
CVE-2024-23113 · Fortinet Multiple ProductsFormat String VulnerabilityPatch this weekAdded to KEV Oct 9, 2024
Fortinet Multiple Products Format String Vulnerability
Affects anyone whose internet connection goes through a Fortinet appliance — typically a FortiGate firewall or FortiClient VPN. The firewall sits between every device in the office and the internet; exploitation can mean an attacker gets inside the network perimeter without touching a workstation.
Fortinet FortiOS, FortiPAM, FortiProxy, and FortiWeb contain a format string vulnerability that allows a remote, unauthenticated attacker to execute arbitrary code or commands via specially crafted requests.
CVE-2024-7593 · Ivanti Virtual Traffic ManagerAuthentication Bypass VulnerabilityPatch this weekAdded to KEV Sep 24, 2024
Ivanti Virtual Traffic Manager Authentication Bypass Vulnerability
Affects anyone using Ivanti VPN (Connect Secure or Pulse) or Ivanti endpoint management. The VPN is what remote workers use to reach internal systems; the endpoint management tool typically has admin reach into every laptop — exploitation in either is high-impact.
Ivanti Virtual Traffic Manager contains an authentication bypass vulnerability that allows a remote, unauthenticated attacker to create a chosen administrator account.
CVE-2024-8963 · Ivanti Cloud Services Appliance (CSA)Path Traversal VulnerabilityPatch this weekAdded to KEV Sep 19, 2024
Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability
Affects anyone using Ivanti VPN (Connect Secure or Pulse) or Ivanti endpoint management. The VPN is what remote workers use to reach internal systems; the endpoint management tool typically has admin reach into every laptop — exploitation in either is high-impact.
Ivanti Cloud Services Appliance (CSA) contains a path traversal vulnerability that could allow a remote, unauthenticated attacker to access restricted functionality. If CVE-2024-8963 is used in conjunction with CVE-2024-8190, an attacker could bypass admin authentication and execute arbitrary commands on the appliance.
CVE-2014-0497 · Adobe Flash PlayerInteger Underflow VulnerablityPatch this weekAdded to KEV Sep 17, 2024
Adobe Flash Player Integer Underflow Vulnerablity
Affects anyone running Adobe Flash Player. If it's part of your document workflow, exploitation can lead to code execution when a user opens an attacker-controlled file.
Adobe Flash Player contains an integer underflow vulnerability that allows a remote attacker to execute arbitrary code.
CVE-2024-40766 · SonicWall SonicOSImproper Access Control VulnerabilityKnown ransomware usePatch nowAdded to KEV Sep 9, 2024
SonicWall SonicOS Improper Access Control Vulnerability
Affects anyone whose network is fronted by a SonicWall firewall or SSL VPN. The device sits at the edge between your office and the internet and authenticates remote workers — exploitation typically means an attacker reaches inside without needing a user credential.
SonicWall SonicOS contains an improper access control vulnerability that could lead to unauthorized resource access and, under certain conditions, may cause the firewall to crash.
CVE-2024-7971 · Google Chromium V8Type Confusion VulnerabilityPatch this weekAdded to KEV Aug 26, 2024
Google Chromium V8 Type Confusion Vulnerability
Affects anyone using Chrome or Chromium as their browser. The browser is where staff log into cloud apps, banking, and client portals — exploitation can mean session theft or credential exposure for every site you're signed into.
Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CVE-2024-34102 · Adobe Commerce and Magento Open SourceImproper Restriction of XML External Entity Reference (XXE) VulnerabilityPatch this weekAdded to KEV Jul 17, 2024
Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability
Affects anyone running Adobe Commerce and Magento Open Source. If it's part of your document workflow, exploitation can lead to code execution when a user opens an attacker-controlled file.
Adobe Commerce and Magento Open Source contain an improper restriction of XML external entity reference (XXE) vulnerability that allows for remote code execution.
CVE-2024-5274 · Google Chromium V8Type Confusion VulnerabilityPatch this weekAdded to KEV May 28, 2024
Google Chromium V8 Type Confusion Vulnerability
Affects anyone using Chrome or Chromium as their browser. The browser is where staff log into cloud apps, banking, and client portals — exploitation can mean session theft or credential exposure for every site you're signed into.
Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CVE-2024-4947 · Google Chromium V8Type Confusion VulnerabilityPatch this weekAdded to KEV May 20, 2024
Google Chromium V8 Type Confusion Vulnerability
Affects anyone using Chrome or Chromium as their browser. The browser is where staff log into cloud apps, banking, and client portals — exploitation can mean session theft or credential exposure for every site you're signed into.
Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page.
CVE-2024-4671 · Google ChromiumVisuals Use-After-Free VulnerabilityPatch this weekAdded to KEV May 13, 2024
Google Chromium Visuals Use-After-Free Vulnerability
Affects anyone using Chrome or Chromium as their browser. The browser is where staff log into cloud apps, banking, and client portals — exploitation can mean session theft or credential exposure for every site you're signed into.
Google Chromium Visuals contains a use-after-free vulnerability that allows a remote attacker to exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CVE-2024-3400 · Palo Alto Networks PAN-OSCommand Injection VulnerabilityKnown ransomware usePatch nowAdded to KEV Apr 12, 2024
Palo Alto Networks PAN-OS Command Injection Vulnerability
Affects anyone behind a Palo Alto firewall or using GlobalProtect VPN. The firewall is the network edge; the VPN is how remote workers reach inside the perimeter — exploitation puts an attacker on the internal network without touching a workstation.
Palo Alto Networks PAN-OS GlobalProtect feature contains a command injection vulnerability that allows an unauthenticated attacker to execute commands with root privileges on the firewall.
CVE-2021-44529 · Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA)Code Injection VulnerabilityKnown ransomware usePatch nowAdded to KEV Mar 25, 2024
Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) Code Injection Vulnerability
Affects anyone using Ivanti VPN (Connect Secure or Pulse) or Ivanti endpoint management. The VPN is what remote workers use to reach internal systems; the endpoint management tool typically has admin reach into every laptop — exploitation in either is high-impact.
Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) contains a code injection vulnerability that allows an unauthenticated user to execute malicious code with limited permissions (nobody).
CVE-2023-48788 · Fortinet FortiClient EMSSQL Injection VulnerabilityKnown ransomware usePatch nowAdded to KEV Mar 25, 2024
Fortinet FortiClient EMS SQL Injection Vulnerability
Affects anyone whose internet connection goes through a Fortinet appliance — typically a FortiGate firewall or FortiClient VPN. The firewall sits between every device in the office and the internet; exploitation can mean an attacker gets inside the network perimeter without touching a workstation.
Fortinet FortiClient EMS contains a SQL injection vulnerability that allows an unauthenticated attacker to execute commands as SYSTEM via specifically crafted requests.
CVE-2024-21410 · Microsoft Exchange ServerPrivilege Escalation VulnerabilityPatch this weekAdded to KEV Feb 15, 2024
Microsoft Exchange Server Privilege Escalation Vulnerability
Affects anyone running on-premises Microsoft Exchange Server. If you have Exchange in your office (as opposed to Microsoft 365 hosted email), it's the mail server holding all internal email — full compromise reads every conversation it stores.
Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation.
CVE-2024-21762 · Fortinet FortiOSOut-of-Bound Write VulnerabilityKnown ransomware usePatch nowAdded to KEV Feb 9, 2024
Fortinet FortiOS Out-of-Bound Write Vulnerability
Affects anyone whose internet connection goes through a Fortinet appliance — typically a FortiGate firewall or FortiClient VPN. The firewall sits between every device in the office and the internet; exploitation can mean an attacker gets inside the network perimeter without touching a workstation.
Fortinet FortiOS contains an out-of-bound write vulnerability that allows a remote unauthenticated attacker to execute code or commands via specially crafted HTTP requests.
CVE-2023-35082 · Ivanti Endpoint Manager Mobile (EPMM) and MobileIron CoreAuthentication Bypass VulnerabilityKnown ransomware usePatch nowAdded to KEV Jan 18, 2024
Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass Vulnerability
Affects anyone using Ivanti VPN (Connect Secure or Pulse) or Ivanti endpoint management. The VPN is what remote workers use to reach internal systems; the endpoint management tool typically has admin reach into every laptop — exploitation in either is high-impact.
Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core contain an authentication bypass vulnerability that allows unauthorized users to access restricted functionality or resources of the application.
CVE-2024-21887 · Ivanti Connect Secure and Policy SecureCommand Injection VulnerabilityKnown ransomware usePatch nowAdded to KEV Jan 10, 2024
Ivanti Connect Secure and Policy Secure Command Injection Vulnerability
Affects anyone using Ivanti VPN (Connect Secure or Pulse) or Ivanti endpoint management. The VPN is what remote workers use to reach internal systems; the endpoint management tool typically has admin reach into every laptop — exploitation in either is high-impact.
Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure contain a command injection vulnerability in the web components of these products, which can allow an authenticated administrator to send crafted requests to execute code on affected appliances. This vulnerability can be leveraged in conjunction with CVE-2023-46805, an authenticated bypass issue.
CVE-2023-29357 · Microsoft SharePoint ServerPrivilege Escalation VulnerabilityKnown ransomware usePatch nowAdded to KEV Jan 10, 2024
Microsoft SharePoint Server Privilege Escalation Vulnerability
Affects anyone running Microsoft SharePoint Server. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
Microsoft SharePoint Server contains an unspecified vulnerability that allows an unauthenticated attacker, who has gained access to spoofed JWT authentication tokens, to use them for executing a network attack. This attack bypasses authentication, enabling the attacker to gain administrator privileges.
Adobe ColdFusion: 2 CVEsPatch nowadded Jan 8, 2024
- CVE-2023-38203Known ransomware use
Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
Affects anyone running Adobe ColdFusion. If it's part of your document workflow, exploitation can lead to code execution when a user opens an attacker-controlled file.
Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for code execution.
- CVE-2023-29300Known ransomware use
Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
Affects anyone running Adobe ColdFusion. If it's part of your document workflow, exploitation can lead to code execution when a user opens an attacker-controlled file.
Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for code execution.
CVE-2023-6345 · Google Chromium SkiaSkia Integer Overflow VulnerabilityPatch this weekAdded to KEV Nov 30, 2023
Google Skia Integer Overflow Vulnerability
Affects anyone using Chrome or Chromium as their browser. The browser is where staff log into cloud apps, banking, and client portals — exploitation can mean session theft or credential exposure for every site you're signed into.
Google Chromium Skia contains an integer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a malicious file. This vulnerability affects Google Chrome and ChromeOS, Android, Flutter, and possibly other products.
CVE-2023-20198 · Cisco IOS XE Web UIPrivilege Escalation VulnerabilityPatch this weekAdded to KEV Oct 16, 2023
Cisco IOS XE Web UI Privilege Escalation Vulnerability
Affects anyone with Cisco networking or security appliances on their network — typically a firewall, switch, or remote-access VPN. That device controls traffic to and from every workstation; exploitation can mean an attacker pivots inside the network without touching any user device.
Cisco IOS XE Web UI contains a privilege escalation vulnerability in the web user interface that could allow a remote, unauthenticated attacker to create an account with privilege level 15 access. The attacker can then use that account to gain control of the affected device.
CVE-2023-38035 · Ivanti SentryAuthentication Bypass VulnerabilityKnown ransomware usePatch nowAdded to KEV Aug 22, 2023
Ivanti Sentry Authentication Bypass Vulnerability
Affects anyone using Ivanti VPN (Connect Secure or Pulse) or Ivanti endpoint management. The VPN is what remote workers use to reach internal systems; the endpoint management tool typically has admin reach into every laptop — exploitation in either is high-impact.
Ivanti Sentry, formerly known as MobileIron Sentry, contains an authentication bypass vulnerability that may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTTPD configuration.
CVE-2023-26359 · Adobe ColdFusionDeserialization of Untrusted Data VulnerabilityPatch this weekAdded to KEV Aug 21, 2023
Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
Affects anyone running Adobe ColdFusion. If it's part of your document workflow, exploitation can lead to code execution when a user opens an attacker-controlled file.
Adobe ColdFusion contains a deserialization of untrusted data vulnerability that could result in code execution in the context of the current user.
CVE-2023-35078 · Ivanti Endpoint Manager Mobile (EPMM)Endpoint Manager Mobile Authentication Bypass VulnerabilityKnown ransomware usePatch nowAdded to KEV Jul 25, 2023
Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability
Affects anyone using Ivanti VPN (Connect Secure or Pulse) or Ivanti endpoint management. The VPN is what remote workers use to reach internal systems; the endpoint management tool typically has admin reach into every laptop — exploitation in either is high-impact.
Ivanti Endpoint Manager Mobile (EPMM, previously branded MobileIron Core) contains an authentication bypass vulnerability that allows unauthenticated access to specific API paths. An attacker with access to these API paths can access personally identifiable information (PII) such as names, phone numbers, and other mobile device details for users on a vulnerable system. An attacker can also make other configuration changes including installing software and modifying security profiles on registered devices.
CVE-2023-27997 · Fortinet FortiOS and FortiProxy SSL-VPNHeap-Based Buffer Overflow VulnerabilityKnown ransomware usePatch nowAdded to KEV Jun 13, 2023
Fortinet FortiOS and FortiProxy SSL-VPN Heap-Based Buffer Overflow Vulnerability
Affects anyone whose internet connection goes through a Fortinet appliance — typically a FortiGate firewall or FortiClient VPN. The firewall sits between every device in the office and the internet; exploitation can mean an attacker gets inside the network perimeter without touching a workstation.
Fortinet FortiOS and FortiProxy SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker to execute code or commands via specifically crafted requests.
CVE-2023-2136 · Google Chromium SkiaChrome Skia Integer Overflow VulnerabilityPatch this weekAdded to KEV Apr 21, 2023
Google Chrome Skia Integer Overflow Vulnerability
Affects anyone using Chrome or Chromium as their browser. The browser is where staff log into cloud apps, banking, and client portals — exploitation can mean session theft or credential exposure for every site you're signed into.
Google Chromium Skia contains an integer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability affects Google Chrome and ChromeOS, Android, Flutter, and possibly other products.
CVE-2023-23397 · Microsoft OfficeOutlook Privilege Escalation VulnerabilityPatch this weekAdded to KEV Mar 14, 2023
Microsoft Office Outlook Privilege Escalation Vulnerability
Affects anyone using Microsoft 365 or Office to compose, store, or send email, documents, or spreadsheets. In a small practice, that's typically where client communications, engagement letters, and case notes live — credential compromise here means an attacker reads everything that platform stores.
Microsoft Office Outlook contains a privilege escalation vulnerability that allows for a NTLM Relay attack against another service to authenticate as the user.
CVE-2022-42475 · Fortinet FortiOSHeap-Based Buffer Overflow VulnerabilityKnown ransomware usePatch nowAdded to KEV Dec 13, 2022
Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability
Affects anyone whose internet connection goes through a Fortinet appliance — typically a FortiGate firewall or FortiClient VPN. The firewall sits between every device in the office and the internet; exploitation can mean an attacker gets inside the network perimeter without touching a workstation.
Multiple versions of Fortinet FortiOS SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker to execute arbitrary code or commands via specifically crafted requests.
CVE-2022-4135 · Google Chromium GPUHeap Buffer Overflow VulnerabilityPatch this weekAdded to KEV Nov 28, 2022
Google Chromium GPU Heap Buffer Overflow Vulnerability
Affects anyone using Chrome or Chromium as their browser. The browser is where staff log into cloud apps, banking, and client portals — exploitation can mean session theft or credential exposure for every site you're signed into.
Google Chromium GPU contains a heap buffer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CVE-2022-40684 · Fortinet Multiple ProductsAuthentication Bypass VulnerabilityKnown ransomware usePatch nowAdded to KEV Oct 11, 2022
Fortinet Multiple Products Authentication Bypass Vulnerability
Affects anyone whose internet connection goes through a Fortinet appliance — typically a FortiGate firewall or FortiClient VPN. The firewall sits between every device in the office and the internet; exploitation can mean an attacker gets inside the network perimeter without touching a workstation.
Fortinet FortiOS, FortiProxy, and FortiSwitchManager contain an authentication bypass vulnerability that could allow an unauthenticated attacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.
CVE-2022-3075 · Google Chromium MojoInsufficient Data Validation VulnerabilityPatch this weekAdded to KEV Sep 8, 2022
Google Chromium Mojo Insufficient Data Validation Vulnerability
Affects anyone using Chrome or Chromium as their browser. The browser is where staff log into cloud apps, banking, and client portals — exploitation can mean session theft or credential exposure for every site you're signed into.
Google Chromium Mojo contains an insufficient data validation vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CVE-2017-15944 · Palo Alto Networks PAN-OSRemote Code Execution VulnerabilityPatch this weekAdded to KEV Aug 18, 2022
Palo Alto Networks PAN-OS Remote Code Execution Vulnerability
Affects anyone behind a Palo Alto firewall or using GlobalProtect VPN. The firewall is the network edge; the VPN is how remote workers reach inside the perimeter — exploitation puts an attacker on the internal network without touching a workstation.
Palo Alto Networks PAN-OS contains multiple, unspecified vulnerabilities which can allow for remote code execution when chained.
CVE-2011-2462 · Adobe Reader and AcrobatUniversal 3D Memory Corruption VulnerabilityPatch this weekAdded to KEV Jun 8, 2022
Adobe Reader and Acrobat Universal 3D Memory Corruption Vulnerability
Affects anyone opening, editing, or signing PDFs in Adobe Acrobat or Reader. For a CPA or legal practice, PDFs are typically client tax returns, engagement letters, signed agreements, and discovery documents — opening a malicious PDF runs attacker code in the user's session, which can pivot to file shares or email.
The Universal 3D (U3D) component in Adobe Reader and Acrobat contains a memory corruption vulnerability which could allow remote attackers to execute code or cause denial-of-service (DoS).
CVE-2014-0546 · Adobe Reader and AcrobatSandbox Bypass VulnerabilityPatch this weekAdded to KEV May 25, 2022
Adobe Reader and Acrobat Sandbox Bypass Vulnerability
Affects anyone opening, editing, or signing PDFs in Adobe Acrobat or Reader. For a CPA or legal practice, PDFs are typically client tax returns, engagement letters, signed agreements, and discovery documents — opening a malicious PDF runs attacker code in the user's session, which can pivot to file shares or email.
Adobe Reader and Acrobat on Windows allow attackers to bypass a sandbox protection mechanism, and consequently execute native code in a privileged context.
CVE-2017-8543 · Microsoft WindowsSearch Remote Code Execution VulnerabilityPatch this weekAdded to KEV May 24, 2022
Microsoft Windows Search Remote Code Execution Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows allows an attacker to take control of the affected system when Windows Search fails to handle objects in memory.
- KB4022727
- KB4022714
- KB4025339
- KB4025342
- +7 more
CVE-2010-5330 · Ubiquiti AirOSCommand Injection VulnerabilityPatch this weekAdded to KEV Apr 15, 2022
Ubiquiti AirOS Command Injection Vulnerability
Affects anyone running Ubiquiti UniFi networking gear (access points, switches, security gateways, NVRs). The gear carries internal network traffic and often hosts video surveillance — exploitation can expose network traffic or grant management access to the network itself.
Certain Ubiquiti devices contain a command injection vulnerability via a GET request to stainfo.cgi.
Adobe Flash Player: 5 CVEsPatch this weekadded Apr 13, 2022
Adobe Flash Player Use-After-Free Vulnerability
Affects anyone running Adobe Flash Player. If it's part of your document workflow, exploitation can lead to code execution when a user opens an attacker-controlled file.
Use-after-free vulnerability in Adobe Flash Player allows remote attackers to execute code.
Adobe Flash Player Use-After-Free Vulnerability
Affects anyone running Adobe Flash Player. If it's part of your document workflow, exploitation can lead to code execution when a user opens an attacker-controlled file.
Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS).
Adobe Flash Player Use-After-Free Vulnerability
Affects anyone running Adobe Flash Player. If it's part of your document workflow, exploitation can lead to code execution when a user opens an attacker-controlled file.
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS).
Adobe Flash Player Heap-Based Buffer Overflow Vulnerability
Affects anyone running Adobe Flash Player. If it's part of your document workflow, exploitation can lead to code execution when a user opens an attacker-controlled file.
Heap-based buffer overflow vulnerability in Adobe Flash Player allows remote attackers to execute code.
Adobe Flash Player Remote Code Execution Vulnerability
Affects anyone running Adobe Flash Player. If it's part of your document workflow, exploitation can lead to code execution when a user opens an attacker-controlled file.
Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute code.
CVE-2021-31166 · Microsoft HTTP Protocol StackRemote Code Execution VulnerabilityPatch this weekAdded to KEV Apr 6, 2022
Microsoft HTTP Protocol Stack Remote Code Execution Vulnerability
Affects anyone running Microsoft HTTP Protocol Stack. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
Microsoft HTTP Protocol Stack contains a vulnerability in http.sys that allows for remote code execution.
- KB5003173
CVE-2021-20028 · SonicWall Secure Remote Access (SRA)SQL Injection VulnerabilityKnown ransomware usePatch nowAdded to KEV Mar 28, 2022
SonicWall Secure Remote Access (SRA) SQL Injection Vulnerability
Affects anyone whose network is fronted by a SonicWall firewall or SSL VPN. The device sits at the edge between your office and the internet and authenticates remote workers — exploitation typically means an attacker reaches inside without needing a user credential.
SonicWall Secure Remote Access (SRA) products contain an improper neutralization of a SQL Command leading to SQL injection.
CVE-2013-2729 · Adobe Reader and AcrobatArbitrary Integer Overflow VulnerabilityPatch this weekAdded to KEV Mar 28, 2022
Adobe Reader and Acrobat Arbitrary Integer Overflow Vulnerability
Affects anyone opening, editing, or signing PDFs in Adobe Acrobat or Reader. For a CPA or legal practice, PDFs are typically client tax returns, engagement letters, signed agreements, and discovery documents — opening a malicious PDF runs attacker code in the user's session, which can pivot to file shares or email.
Integer overflow vulnerability in Adobe Reader and Acrobat allows attackers to execute remote code.
CVE-2017-3881 · Cisco IOS and IOS XERemote Code Execution VulnerabilityPatch this weekAdded to KEV Mar 25, 2022
Cisco IOS and IOS XE Remote Code Execution Vulnerability
Affects anyone with Cisco networking or security appliances on their network — typically a firewall, switch, or remote-access VPN. That device controls traffic to and from every workstation; exploitation can mean an attacker pivots inside the network without touching any user device.
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device or remotely execute code with elevated privileges.
CVE-2016-4171 · Adobe Flash PlayerRemote Code Execution VulnerabilityPatch this weekAdded to KEV Mar 25, 2022
Adobe Flash Player Remote Code Execution Vulnerability
Affects anyone running Adobe Flash Player. If it's part of your document workflow, exploitation can lead to code execution when a user opens an attacker-controlled file.
Unspecified vulnerability in Adobe Flash Player allows for remote code execution.
CVE-2020-2021 · Palo Alto Networks PAN-OSAuthentication Bypass VulnerabilityKnown ransomware usePatch nowAdded to KEV Mar 25, 2022
Palo Alto Networks PAN-OS Authentication Bypass Vulnerability
Affects anyone behind a Palo Alto firewall or using GlobalProtect VPN. The firewall is the network edge; the VPN is how remote workers reach inside the perimeter — exploitation puts an attacker on the internal network without touching a workstation.
Palo Alto Networks PAN-OS contains a vulnerability in SAML which allows an attacker to bypass authentication.
CVE-2018-0147 · Cisco Secure Access Control System (ACS)Secure Access Control System Java Deserialization VulnerabilityPatch this weekAdded to KEV Mar 25, 2022
Cisco Secure Access Control System Java Deserialization Vulnerability
Affects anyone with Cisco networking or security appliances on their network — typically a firewall, switch, or remote-access VPN. That device controls traffic to and from every workstation; exploitation can mean an attacker pivots inside the network without touching any user device.
A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software.
CVE-2018-0125 · Cisco VPN RoutersRemote Code Execution VulnerabilityPatch this weekAdded to KEV Mar 25, 2022
Cisco VPN Routers Remote Code Execution Vulnerability
Affects anyone with Cisco networking or security appliances on their network — typically a firewall, switch, or remote-access VPN. That device controls traffic to and from every workstation; exploitation can mean an attacker pivots inside the network without touching any user device.
A vulnerability in the web interface of the Cisco VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as root and gain full control of an affected system.
CVE-2010-2861 · Adobe ColdFusionDirectory Traversal VulnerabilityKnown ransomware usePatch nowAdded to KEV Mar 25, 2022
Adobe ColdFusion Directory Traversal Vulnerability
Affects anyone running Adobe ColdFusion. If it's part of your document workflow, exploitation can lead to code execution when a user opens an attacker-controlled file.
A directory traversal vulnerability exists in the administrator console in Adobe ColdFusion which allows remote attackers to read arbitrary files.
CVE-2020-5135 · SonicWall SonicOSBuffer Overflow VulnerabilityPatch this weekAdded to KEV Mar 15, 2022
SonicWall SonicOS Buffer Overflow Vulnerability
Affects anyone whose network is fronted by a SonicWall firewall or SSL VPN. The device sits at the edge between your office and the internet and authenticates remote workers — exploitation typically means an attacker reaches inside without needing a user credential.
A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a malicious request to the firewall.
CVE-2013-0625 · Adobe ColdFusionAuthentication Bypass VulnerabilityPatch this weekAdded to KEV Mar 7, 2022
Adobe ColdFusion Authentication Bypass Vulnerability
Affects anyone running Adobe ColdFusion. If it's part of your document workflow, exploitation can lead to code execution when a user opens an attacker-controlled file.
Adobe Coldfusion contains an authentication bypass vulnerability, which could result in an unauthorized user gaining administrative access.
Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers: 5 CVEsPatch this weekadded Mar 3, 2022
Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability
Affects anyone with Cisco networking or security appliances on their network — typically a firewall, switch, or remote-access VPN. That device controls traffic to and from every workstation; exploitation can mean an attacker pivots inside the network without touching any user device.
A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).
Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability
Affects anyone with Cisco networking or security appliances on their network — typically a firewall, switch, or remote-access VPN. That device controls traffic to and from every workstation; exploitation can mean an attacker pivots inside the network without touching any user device.
A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).
Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability
Affects anyone with Cisco networking or security appliances on their network — typically a firewall, switch, or remote-access VPN. That device controls traffic to and from every workstation; exploitation can mean an attacker pivots inside the network without touching any user device.
A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).
Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability
Affects anyone with Cisco networking or security appliances on their network — typically a firewall, switch, or remote-access VPN. That device controls traffic to and from every workstation; exploitation can mean an attacker pivots inside the network without touching any user device.
A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).
Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability
Affects anyone with Cisco networking or security appliances on their network — typically a firewall, switch, or remote-access VPN. That device controls traffic to and from every workstation; exploitation can mean an attacker pivots inside the network without touching any user device.
A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).
Adobe Flash Player: 4 CVEsPatch nowadded Mar 3, 2022
Adobe Flash Player Arbitrary Code Execution Vulnerability
Affects anyone running Adobe Flash Player. If it's part of your document workflow, exploitation can lead to code execution when a user opens an attacker-controlled file.
An access of resource using incompatible type vulnerability exists within Adobe Flash Player that allows an attacker to perform remote code execution.
- CVE-2016-1019Known ransomware use
Adobe Flash Player Arbitrary Code Execution Vulnerability
Affects anyone running Adobe Flash Player. If it's part of your document workflow, exploitation can lead to code execution when a user opens an attacker-controlled file.
Adobe Flash Player allows remote attackers to cause a denial of service or possibly execute arbitrary code.
Adobe Flash Player Use-After-Free Vulnerability
Affects anyone running Adobe Flash Player. If it's part of your document workflow, exploitation can lead to code execution when a user opens an attacker-controlled file.
A use-after-free vulnerability exists within the ActionScript 3 ByteArray class in Adobe Flash Player that allows an attacker to perform remote code execution.
Adobe Flash Player Memory Corruption Vulnerability
Affects anyone running Adobe Flash Player. If it's part of your document workflow, exploitation can lead to code execution when a user opens an attacker-controlled file.
A memory corruption vulnerability exists in Adobe Flash Player that allows an attacker to perform remote code execution.
CVE-2013-3346 · Adobe Reader and AcrobatMemory Corruption VulnerabilityPatch this weekAdded to KEV Mar 3, 2022
Adobe Reader and Acrobat Memory Corruption Vulnerability
Affects anyone opening, editing, or signing PDFs in Adobe Acrobat or Reader. For a CPA or legal practice, PDFs are typically client tax returns, engagement letters, signed agreements, and discovery documents — opening a malicious PDF runs attacker code in the user's session, which can pivot to file shares or email.
Adobe Reader and Acrobat contain a memory corruption vulnerability which can allow attackers to execute arbitrary code or cause a denial of service.
Cisco IOS and IOS XE Software: 2 CVEsPatch this weekadded Mar 3, 2022
Cisco IOS Software and Cisco IOS XE Software Quality of Service Remote Code Execution Vulnerability
Affects anyone with Cisco networking or security appliances on their network — typically a firewall, switch, or remote-access VPN. That device controls traffic to and from every workstation; exploitation can mean an attacker pivots inside the network without touching any user device.
A vulnerability in the quality of service (QoS) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges.
Cisco IOS and IOS XE Software DHCP Remote Code Execution Vulnerability
Affects anyone with Cisco networking or security appliances on their network — typically a firewall, switch, or remote-access VPN. That device controls traffic to and from every workstation; exploitation can mean an attacker pivots inside the network without touching any user device.
The Dynamic Host Configuration Protocol (DHCP) relay subsystem of Cisco IOS and Cisco IOS XE Software contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code and gain full control of an affected system.
CVE-2013-0632 · Adobe ColdFusionAuthentication Bypass VulnerabilityPatch this weekAdded to KEV Mar 3, 2022
Adobe ColdFusion Authentication Bypass Vulnerability
Affects anyone running Adobe ColdFusion. If it's part of your document workflow, exploitation can lead to code execution when a user opens an attacker-controlled file.
An authentication bypass vulnerability exists in Adobe ColdFusion which could result in an unauthorized user gaining administrative access.
CVE-2011-1889 · Microsoft Forefront Threat Management Gateway (TMG)Forefront TMG Remote Code Execution VulnerabilityPatch this weekAdded to KEV Mar 3, 2022
Microsoft Forefront TMG Remote Code Execution Vulnerability
Affects anyone running Microsoft Forefront Threat Management Gateway (TMG). Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
A remote code execution vulnerability exists in the Forefront Threat Management Gateway (TMG) Firewall Client Winsock provider that could allow code execution in the security context of the client application.
CVE-2022-24086 · Adobe Commerce and Magento Open SourceImproper Input Validation VulnerabilityPatch this weekAdded to KEV Feb 15, 2022
Adobe Commerce and Magento Open Source Improper Input Validation Vulnerability
Affects anyone running Adobe Commerce and Magento Open Source. If it's part of your document workflow, exploitation can lead to code execution when a user opens an attacker-controlled file.
Adobe Commerce and Magento Open Source contain an improper input validation vulnerability which can allow for arbitrary code execution.
CVE-2015-1635 · Microsoft HTTP.sysRemote Code Execution VulnerabilityPatch this weekAdded to KEV Feb 10, 2022
Microsoft HTTP.sys Remote Code Execution Vulnerability
Affects anyone running Microsoft HTTP.sys. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
Microsoft HTTP protocol stack (HTTP.sys) contains a vulnerability that allows for remote code execution.
CVE-2020-0796 · Microsoft SMBv3Remote Code Execution VulnerabilityKnown ransomware usePatch nowAdded to KEV Feb 10, 2022
Microsoft SMBv3 Remote Code Execution Vulnerability
Affects anyone running Microsoft SMBv3. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests. An attacker who successfully exploited the vulnerability could gain the ability to execute code on the target server or client.
- KB4551762
CVE-2022-22587 · Apple iOS and macOSMemory Corruption VulnerabilityPatch this weekAdded to KEV Jan 28, 2022
Apple Memory Corruption Vulnerability
Affects anyone running Macs, iPhones, or iPads in the office. For a small practice, Apple endpoints are typically how staff handle email, browse client portals, and store local case files — exploitation gives an attacker access to that data on the device.
Apple IOMobileFrameBuffer contains a memory corruption vulnerability which can allow a malicious application to execute arbitrary code with kernel privileges.
CVE-2021-20038 · SonicWall SMA 100 AppliancesStack-Based Buffer Overflow VulnerabilityKnown ransomware usePatch nowAdded to KEV Jan 28, 2022
SonicWall SMA 100 Appliances Stack-Based Buffer Overflow Vulnerability
Affects anyone whose network is fronted by a SonicWall firewall or SSL VPN. The device sits at the edge between your office and the internet and authenticates remote workers — exploitation typically means an attacker reaches inside without needing a user credential.
SonicWall SMA 100 devies are vulnerable to an unauthenticated stack-based buffer overflow vulnerability where exploitation can result in code execution.
CVE-2014-1776 · Microsoft Internet ExplorerMemory Corruption VulnerabilityPatch this weekAdded to KEV Jan 28, 2022
Microsoft Internet Explorer Memory Corruption Vulnerability
Affects anyone running Microsoft Internet Explorer. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code in the context of the current user.
CVE-2018-13382 · Fortinet FortiOS and FortiProxyImproper AuthorizationKnown ransomware usePatch nowAdded to KEV Jan 10, 2022
Fortinet FortiOS and FortiProxy Improper Authorization
Affects anyone whose internet connection goes through a Fortinet appliance — typically a FortiGate firewall or FortiClient VPN. The firewall sits between every device in the office and the internet; exploitation can mean an attacker gets inside the network perimeter without touching a workstation.
An Improper Authorization vulnerability in Fortinet FortiOS and FortiProxy under SSL VPN web portal allows an unauthenticated attacker to modify the password.
Ivanti Pulse Connect Secure: 2 CVEsPatch nowadded Nov 3, 2021
- CVE-2021-22893Known ransomware use
Ivanti Pulse Connect Secure Use-After-Free Vulnerability
Affects anyone using Ivanti VPN (Connect Secure or Pulse) or Ivanti endpoint management. The VPN is what remote workers use to reach internal systems; the endpoint management tool typically has admin reach into every laptop — exploitation in either is high-impact.
Ivanti Pulse Connect Secure contains a use-after-free vulnerability that allow a remote, unauthenticated attacker to execute code via license services.
- CVE-2019-11510Known ransomware use
Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability
Affects anyone using Ivanti VPN (Connect Secure or Pulse) or Ivanti endpoint management. The VPN is what remote workers use to reach internal systems; the endpoint management tool typically has admin reach into every laptop — exploitation in either is high-impact.
Ivanti Pulse Connect Secure contains an arbitrary file read vulnerability that allows an unauthenticated remote attacker with network access via HTTPS to send a specially crafted URI.
CVE-2021-30633 · Google Chromium Indexed DB APIUse-After-Free VulnerabilityPatch this weekAdded to KEV Nov 3, 2021
Google Chromium Indexed DB API Use-After-Free Vulnerability
Affects anyone using Chrome or Chromium as their browser. The browser is where staff log into cloud apps, banking, and client portals — exploitation can mean session theft or credential exposure for every site you're signed into.
Google Chromium Indexed DB API contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CVE-2018-0171 · Cisco IOS and IOS XESoftware Smart Install Remote Code Execution VulnerabilityPatch this weekAdded to KEV Nov 3, 2021
Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability
Affects anyone with Cisco networking or security appliances on their network — typically a firewall, switch, or remote-access VPN. That device controls traffic to and from every workstation; exploitation can mean an attacker pivots inside the network without touching any user device.
Cisco IOS and IOS XE Software improperly validates packet data, allowing an unauthenticated, remote attacker to trigger a reload of an affected device, cause a denial-of-service (DoS) condition, or perform code execution on the affected device.
CVE-2020-1350 · Microsoft WindowsDNS Server Remote Code Execution VulnerabilityPatch this weekAdded to KEV Nov 3, 2021
Microsoft Windows DNS Server Remote Code Execution Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows DNS Servers fail to properly handle requests, allowing an attacker to perform remote code execution in the context of the Local System Account. The vulnerability is also known under the moniker of SIGRed.
- KB4558998
- KB4565483
- KB4565503
- KB4565511
- +8 more
CVE-2021-38647 · Microsoft Open Management Infrastructure (OMI)Remote Code Execution VulnerabilityKnown ransomware usePatch nowAdded to KEV Nov 3, 2021
Microsoft Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
Affects anyone running Microsoft Open Management Infrastructure (OMI). Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing remote code execution.
CVE-2020-1040 · Microsoft Hyper-V RemoteFXvGPU Remote Code Execution VulnerabilityPatch this weekAdded to KEV Nov 3, 2021
Microsoft Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability
Affects anyone running Microsoft Hyper-V RemoteFX. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
Microsoft Hyper-V RemoteFX vGPU contains an improper input validation vulnerability due to the host server failing to properly validate input from an authenticated user on a guest operating system. Successful exploitation allows for remote code execution on the host operating system.
Microsoft Exchange Server: 3 CVEsPatch nowadded Nov 3, 2021
- CVE-2021-26855Known ransomware use
Microsoft Exchange Server Remote Code Execution Vulnerability
Affects anyone running on-premises Microsoft Exchange Server. If you have Exchange in your office (as opposed to Microsoft 365 hosted email), it's the mail server holding all internal email — full compromise reads every conversation it stores.
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
- CVE-2021-34523Known ransomware use
Microsoft Exchange Server Privilege Escalation Vulnerability
Affects anyone running on-premises Microsoft Exchange Server. If you have Exchange in your office (as opposed to Microsoft 365 hosted email), it's the mail server holding all internal email — full compromise reads every conversation it stores.
Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation.
- CVE-2021-34473Known ransomware use
Microsoft Exchange Server Remote Code Execution Vulnerability
Affects anyone running on-premises Microsoft Exchange Server. If you have Exchange in your office (as opposed to Microsoft 365 hosted email), it's the mail server holding all internal email — full compromise reads every conversation it stores.
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution.
CVE-2017-7269 · Microsoft Internet Information Services (IIS)Windows Server Buffer Overflow VulnerabilityPatch this weekAdded to KEV Nov 3, 2021
Microsoft Windows Server Buffer Overflow Vulnerability
Affects anyone running Microsoft Internet Information Services (IIS). Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
Microsoft Windows Server 2003 R2 contains a buffer overflow vulnerability in Internet Information Services (IIS) 6.0 which allows remote attackers to execute code via a long header beginning with "If: <http://" in a PROPFIND request.
Adobe ColdFusion: 2 CVEsPatch this weekadded Nov 3, 2021
Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
Affects anyone running Adobe ColdFusion. If it's part of your document workflow, exploitation can lead to code execution when a user opens an attacker-controlled file.
Adobe ColdFusion contains a deserialization of untrusted data vulnerability that could allow for code execution.
Adobe ColdFusion Unrestricted File Upload Vulnerability
Affects anyone running Adobe ColdFusion. If it's part of your document workflow, exploitation can lead to code execution when a user opens an attacker-controlled file.
Adobe ColdFusion contains an unrestricted file upload vulnerability that could allow for code execution.
CVE-2019-0708 · Microsoft Remote Desktop ServicesRemote Code Execution VulnerabilityKnown ransomware usePatch nowAdded to KEV Nov 3, 2021
Microsoft Remote Desktop Services Remote Code Execution Vulnerability
Affects anyone running Microsoft Remote Desktop Services. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
Microsoft Remote Desktop Services, formerly known as Terminal Service, contains an unspecified vulnerability that allows an unauthenticated attacker to connect to the target system using RDP and send specially crafted requests. Successful exploitation allows for remote code execution. The vulnerability is also known under the moniker of BlueKeep.
- KB4499164
- KB4499175
- KB4499149
- KB4499180
Apple iOS, iPadOS, and macOS: 2 CVEsPatch this weekadded Nov 3, 2021
Apple iOS, iPadOS, and macOS WebKit Remote Code Execution Vulnerability
Affects anyone running Macs, iPhones, or iPads in the office. For a small practice, Apple endpoints are typically how staff handle email, browse client portals, and store local case files — exploitation gives an attacker access to that data on the device.
Apple iOS, iPadOS, and macOS WebKit contain an unspecified logic vulnerability that allows a remote attacker to execute code. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Apple iOS, iPadOS, and macOS WebKit Remote Code Execution Vulnerability
Affects anyone running Macs, iPhones, or iPads in the office. For a small practice, Apple endpoints are typically how staff handle email, browse client portals, and store local case files — exploitation gives an attacker access to that data on the device.
Apple iOS, iPadOS, and macOS WebKit contain an unspecified logic vulnerability that allows a remote attacker to execute code. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Fortinet FortiOS: 2 CVEsPatch nowadded Nov 3, 2021
- CVE-2020-12812Known ransomware use
Fortinet FortiOS SSL VPN Improper Authentication Vulnerability
Affects anyone whose internet connection goes through a Fortinet appliance — typically a FortiGate firewall or FortiClient VPN. The firewall sits between every device in the office and the internet; exploitation can mean an attacker gets inside the network perimeter without touching a workstation.
Fortinet FortiOS SSL VPN contains an improper authentication vulnerability that may allow a user to login successfully without being prompted for the second factor of authentication (FortiToken) if they change the case in their username.
- CVE-2018-13379Known ransomware use
Fortinet FortiOS SSL VPN Path Traversal Vulnerability
Affects anyone whose internet connection goes through a Fortinet appliance — typically a FortiGate firewall or FortiClient VPN. The firewall sits between every device in the office and the internet; exploitation can mean an attacker gets inside the network perimeter without touching a workstation.
Fortinet FortiOS SSL VPN web portal contains a path traversal vulnerability that may allow an unauthenticated attacker to download FortiOS system files through specially crafted HTTP resource requests.
CVE-2020-16010 · Google Chrome for Android UIHeap Buffer Overflow VulnerabilityPatch this weekAdded to KEV Nov 3, 2021
Google Chrome for Android UI Heap Buffer Overflow Vulnerability
Affects anyone using Chrome or Chromium as their browser. The browser is where staff log into cloud apps, banking, and client portals — exploitation can mean session theft or credential exposure for every site you're signed into.
Google Chrome for Android UI contains a heap buffer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page.
CVE-2020-15999 · Google Chrome FreeTypeHeap Buffer Overflow VulnerabilityPatch this weekAdded to KEV Nov 3, 2021
Google Chrome FreeType Heap Buffer Overflow Vulnerability
Affects anyone using Chrome or Chromium as their browser. The browser is where staff log into cloud apps, banking, and client portals — exploitation can mean session theft or credential exposure for every site you're signed into.
Google Chrome uses FreeType, an open-source software library to render fonts, which contains a heap buffer overflow vulnerability in the function Load_SBit_Png when processing PNG images embedded into fonts. This vulnerability is part of an exploit chain with CVE-2020-17087 on Windows and CVE-2020-16010 on Android.
CVE-2020-3161 · Cisco IP PhonesIP Phones Web Server Remote Code Execution and Denial-of-Service VulnerabilityPatch this weekAdded to KEV Nov 3, 2021
Cisco IP Phones Web Server Remote Code Execution and Denial-of-Service Vulnerability
Affects anyone with Cisco networking or security appliances on their network — typically a firewall, switch, or remote-access VPN. That device controls traffic to and from every workstation; exploitation can mean an attacker pivots inside the network without touching any user device.
Cisco IP Phones contain an improper input validation vulnerability for HTTP requests. Exploitation could allow an attacker to execute code remotely with root privileges or cause a denial-of-service (DoS) condition.
CVE-2021-37973 · Google Chromium PortalsUse-After-Free VulnerabilityPatch this weekAdded to KEV Nov 3, 2021
Google Chromium Portals Use-After-Free Vulnerability
Affects anyone using Chrome or Chromium as their browser. The browser is where staff log into cloud apps, banking, and client portals — exploitation can mean session theft or credential exposure for every site you're signed into.
Google Chromium Portals contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability affects web browsers that utilize Chromium, including Google Chrome and Microsoft Edge.
CVE-2020-15505 · Ivanti MobileIron Multiple ProductsRemote Code Execution VulnerabilityPatch this weekAdded to KEV Nov 3, 2021
Ivanti MobileIron Multiple Products Remote Code Execution Vulnerability
Affects anyone using Ivanti VPN (Connect Secure or Pulse) or Ivanti endpoint management. The VPN is what remote workers use to reach internal systems; the endpoint management tool typically has admin reach into every laptop — exploitation in either is high-impact.
Ivanti MobileIron's Core & Connector, Sentry, and Monitor and Reporting Database (RDB) products contain an unspecified vulnerability that allows for remote code execution.
CVE-2019-0604 · Microsoft SharePointRemote Code Execution VulnerabilityKnown ransomware usePatch nowAdded to KEV Nov 3, 2021
Microsoft SharePoint Remote Code Execution Vulnerability
Affects anyone running Microsoft SharePoint. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
Microsoft SharePoint fails to check the source markup of an application package. An attacker who successfully exploits the vulnerability could run remote code in the context of the SharePoint application pool and the SharePoint server farm account.
CVE-2020-0646 · Microsoft .NET FrameworkRemote Code Execution VulnerabilityPatch this weekAdded to KEV Nov 3, 2021
Microsoft .NET Framework Remote Code Execution Vulnerability
Affects anyone running Microsoft .NET Framework. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
Microsoft .NET Framework contains an improper input validation vulnerability that allows for remote code execution.
- KB4535102
- KB4534976
- KB4535104
- KB4534978
- +13 more
Cisco HyperFlex HX: 2 CVEsPatch this weekadded Nov 3, 2021
Cisco HyperFlex HX Installer Virtual Machine Command Injection Vulnerability
Affects anyone with Cisco networking or security appliances on their network — typically a firewall, switch, or remote-access VPN. That device controls traffic to and from every workstation; exploitation can mean an attacker pivots inside the network without touching any user device.
Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the root user.
Cisco HyperFlex HX Data Platform Command Injection Vulnerability
Affects anyone with Cisco networking or security appliances on their network — typically a firewall, switch, or remote-access VPN. That device controls traffic to and from every workstation; exploitation can mean an attacker pivots inside the network without touching any user device.
Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the tomcat8 user.
CVE-2020-16017 · Google ChromeUse-After-Free VulnerabilityPatch this weekAdded to KEV Nov 3, 2021
Google Chrome Use-After-Free Vulnerability
Affects anyone using Chrome or Chromium as their browser. The browser is where staff log into cloud apps, banking, and client portals — exploitation can mean session theft or credential exposure for every site you're signed into.
Google Chrome contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page.
CVE-2021-20021 · SonicWall Email SecurityEmail Security Improper Privilege Management VulnerabilityKnown ransomware usePatch nowAdded to KEV Nov 3, 2021
SonicWall Email Security Improper Privilege Management Vulnerability
Affects anyone whose network is fronted by a SonicWall firewall or SSL VPN. The device sits at the edge between your office and the internet and authenticates remote workers — exploitation typically means an attacker reaches inside without needing a user credential.
SonicWall Email Security contains an improper privilege management vulnerability that allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20022 and CVE-2021-20023 to achieve privilege escalation.
CVE-2021-20016 · SonicWall SSLVPN SMA100SQL Injection VulnerabilityKnown ransomware usePatch nowAdded to KEV Nov 3, 2021
SonicWall SSLVPN SMA100 SQL Injection Vulnerability
Affects anyone whose network is fronted by a SonicWall firewall or SSL VPN. The device sits at the edge between your office and the internet and authenticates remote workers — exploitation typically means an attacker reaches inside without needing a user credential.
SonicWall SSLVPN SMA100 contains a SQL injection vulnerability that allows remote exploitation for credential access by an unauthenticated attacker.
