Vulnerabilities with evidence of exploitation, including affected products and required actions.
This page is an archived snapshot of the CISA Exploited Vulnerabilities feed collected on Oct 2, 2026, preserved by BioThreat Corporation. Publication dates belong to the original source; this snapshot is not a current advisory.
Vendor: Quest | Product: KACE Systems Management Appliance (SMA) | Quest KACE Systems Management Appliance (SMA) contains an improper authentication vulnerability that could allow attackers to impersonate legitimate users without valid credentials. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations…
Read full source summary
Vendor: Quest | Product: KACE Systems Management Appliance (SMA) | Quest KACE Systems Management Appliance (SMA) contains an improper authentication vulnerability that could allow attackers to impersonate legitimate users without valid credentials. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2026-05-04
CVE-2024-27199 · CISA Known Exploited Vulnerabilities
Vendor: JetBrains | Product: TeamCity | JetBrains TeamCity contains a relative path traversal vulnerability that could allow limited admin actions to be performed. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2026-05-04
CVE-2026-34197 · CISA Known Exploited Vulnerabilities
Vendor: Apache | Product: ActiveMQ | Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2026-04-30
CVE-2009-0238 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Office | Microsoft Office Excel contains a remote code execution vulnerability that could allow an attacker to take complete control of an affected system if a user opens a specially crafted Excel file that includes a malformed object. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product…
Read full source summary
Vendor: Microsoft | Product: Office | Microsoft Office Excel contains a remote code execution vulnerability that could allow an attacker to take complete control of an affected system if a user opens a specially crafted Excel file that includes a malformed object. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2026-04-28
CVE-2026-32201 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: SharePoint Server | Microsoft SharePoint Server contains an improper input validation vulnerability that allows an unauthorized attacker to perform spoofing over a network. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due:…
Read full source summary
Vendor: Microsoft | Product: SharePoint Server | Microsoft SharePoint Server contains an improper input validation vulnerability that allows an unauthorized attacker to perform spoofing over a network. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2026-04-28
CVE-2012-1854 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Visual Basic for Applications (VBA) | Microsoft Visual Basic for Applications (VBA) contains an insecure library loading vulnerability that could allow for remote code execution. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due:…
Read full source summary
Vendor: Microsoft | Product: Visual Basic for Applications (VBA) | Microsoft Visual Basic for Applications (VBA) contains an insecure library loading vulnerability that could allow for remote code execution. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2026-04-27
CVE-2025-60710 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | Microsoft Windows contains a link following vulnerability that allows for privilege escalation | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2026-04-27
CVE-2023-21529 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Exchange Server | Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2026-04-27
CVE-2023-36424 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | Microsoft Windows Common Log File System Driver contains an out-of-bounds read vulnerability that could allow a threat actor for privileges escalation | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2026-04-27
CVE-2020-9715 · CISA Known Exploited Vulnerabilities
Vendor: Adobe | Product: Acrobat | Adobe Acrobat contains a use-after-free vulnerability that allows for code execution | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2026-04-27
CVE-2026-21643 · CISA Known Exploited Vulnerabilities
Vendor: Fortinet | Product: FortiClient EMS | Fortinet FortiClient EMS contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.…
Read full source summary
Vendor: Fortinet | Product: FortiClient EMS | Fortinet FortiClient EMS contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2026-04-16
CVE-2026-34621 · CISA Known Exploited Vulnerabilities
Vendor: Adobe | Product: Acrobat and Reader | Adobe Acrobat and Reader contain a prototype pollution vulnerability that allows for arbitrary code execution. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2026-04-27
CVE-2026-1340 · CISA Known Exploited Vulnerabilities
Vendor: Ivanti | Product: Endpoint Manager Mobile (EPMM) | Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal…
Read full source summary
Vendor: Ivanti | Product: Endpoint Manager Mobile (EPMM) | Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2026-04-11
CVE-2026-35616 · CISA Known Exploited Vulnerabilities
Vendor: Fortinet | Product: FortiClient EMS | Fortinet FortiClient EMS contains an improper access control vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. |…
Read full source summary
Vendor: Fortinet | Product: FortiClient EMS | Fortinet FortiClient EMS contains an improper access control vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2026-04-09
CVE-2026-3502 · CISA Known Exploited Vulnerabilities
Vendor: TrueConf | Product: Client | TrueConf Client contains a download of code without integrity check vulnerability. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the payload is executed or installed by the updater, this may result in arbitrary code execution in the context of the updating process or user. | Required action: Apply mitigations per vendor…
Read full source summary
Vendor: TrueConf | Product: Client | TrueConf Client contains a download of code without integrity check vulnerability. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the payload is executed or installed by the updater, this may result in arbitrary code execution in the context of the updating process or user. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2026-04-16
CVE-2026-5281 · CISA Known Exploited Vulnerabilities
Vendor: Google | Product: Dawn | Google Dawn contains an use-after-free vulnerability that could allow a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. This vulnerability could affect multiple Chromium-based products including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required action: Apply mitigations per vendor instructions, follow…
Read full source summary
Vendor: Google | Product: Dawn | Google Dawn contains an use-after-free vulnerability that could allow a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. This vulnerability could affect multiple Chromium-based products including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2026-04-15
CVE-2026-3055 · CISA Known Exploited Vulnerabilities
Vendor: Citrix | Product: NetScaler | Citrix NetScaler ADC (formerly Citrix ADC), NetScaler Gateway (formerly Citrix Gateway) and NetScaler ADC FIPS and NDcPP contain an out-of-bounds reads vulnerability when configured as a SAML IDP leading to memory overread. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if…
Read full source summary
Vendor: Citrix | Product: NetScaler | Citrix NetScaler ADC (formerly Citrix ADC), NetScaler Gateway (formerly Citrix Gateway) and NetScaler ADC FIPS and NDcPP contain an out-of-bounds reads vulnerability when configured as a SAML IDP leading to memory overread. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2026-04-02
CVE-2025-53521 · CISA Known Exploited Vulnerabilities
Vendor: F5 | Product: BIG-IP | F5 BIG-IP APM contains a stack-based buffer overflow vulnerability that could allow a threat actor to achieve remote code execution. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2026-03-30
CVE-2026-33634 · CISA Known Exploited Vulnerabilities
Vendor: Aquasecurity | Product: Trivy | Aquasecurity Trivy contains an embedded malicious code vulnerability that could allow an attacker to gain access to everything in the CI/CD environment, including all tokens, SSH keys, cloud credentials, database passwords, and any sensitive configuration in memory. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud…
Read full source summary
Vendor: Aquasecurity | Product: Trivy | Aquasecurity Trivy contains an embedded malicious code vulnerability that could allow an attacker to gain access to everything in the CI/CD environment, including all tokens, SSH keys, cloud credentials, database passwords, and any sensitive configuration in memory. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2026-04-09
CVE-2026-33017 · CISA Known Exploited Vulnerabilities
Vendor: Langflow | Product: Langflow | Langflow contains a code injection vulnerability that could allow building public flows without requiring authentication. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2026-04-08