Historical snapshot · Cybersecurity

CISA Exploited Vulnerabilities

Vulnerabilities with evidence of exploitation, including affected products and required actions.

This page is an archived snapshot of the CISA Exploited Vulnerabilities feed collected on Oct 1, 2026, preserved by BioThreat Corporation. Publication dates belong to the original source; this snapshot is not a current advisory.
1731 recordsOfficial source · JSON
CVE-2025-32975 · CISA Known Exploited Vulnerabilities

Quest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability

Vendor: Quest | Product: KACE Systems Management Appliance (SMA) | Quest KACE Systems Management Appliance (SMA) contains an improper authentication vulnerability that could allow attackers to impersonate legitimate users without valid credentials. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations…
Read full source summary
Vendor: Quest | Product: KACE Systems Management Appliance (SMA) | Quest KACE Systems Management Appliance (SMA) contains an improper authentication vulnerability that could allow attackers to impersonate legitimate users without valid credentials. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2026-05-04
CVE-2024-27199 · CISA Known Exploited Vulnerabilities

JetBrains TeamCity Relative Path Traversal Vulnerability

Vendor: JetBrains | Product: TeamCity | JetBrains TeamCity contains a relative path traversal vulnerability that could allow limited admin actions to be performed. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2026-05-04
CVE-2026-34197 · CISA Known Exploited Vulnerabilities

Apache ActiveMQ Improper Input Validation Vulnerability

Vendor: Apache | Product: ActiveMQ | Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2026-04-30
CVE-2009-0238 · CISA Known Exploited Vulnerabilities

Microsoft Office Remote Code Execution

Vendor: Microsoft | Product: Office | Microsoft Office Excel contains a remote code execution vulnerability that could allow an attacker to take complete control of an affected system if a user opens a specially crafted Excel file that includes a malformed object. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product…
Read full source summary
Vendor: Microsoft | Product: Office | Microsoft Office Excel contains a remote code execution vulnerability that could allow an attacker to take complete control of an affected system if a user opens a specially crafted Excel file that includes a malformed object. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2026-04-28
CVE-2026-32201 · CISA Known Exploited Vulnerabilities

Microsoft SharePoint Server Improper Input Validation Vulnerability

Vendor: Microsoft | Product: SharePoint Server | Microsoft SharePoint Server contains an improper input validation vulnerability that allows an unauthorized attacker to perform spoofing over a network. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due:…
Read full source summary
Vendor: Microsoft | Product: SharePoint Server | Microsoft SharePoint Server contains an improper input validation vulnerability that allows an unauthorized attacker to perform spoofing over a network. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2026-04-28
CVE-2012-1854 · CISA Known Exploited Vulnerabilities

Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability

Vendor: Microsoft | Product: Visual Basic for Applications (VBA) | Microsoft Visual Basic for Applications (VBA) contains an insecure library loading vulnerability that could allow for remote code execution. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due:…
Read full source summary
Vendor: Microsoft | Product: Visual Basic for Applications (VBA) | Microsoft Visual Basic for Applications (VBA) contains an insecure library loading vulnerability that could allow for remote code execution. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2026-04-27
CVE-2025-60710 · CISA Known Exploited Vulnerabilities

Microsoft Windows Link Following Vulnerability

Vendor: Microsoft | Product: Windows | Microsoft Windows contains a link following vulnerability that allows for privilege escalation | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2026-04-27
CVE-2023-21529 · CISA Known Exploited Vulnerabilities

Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability

Vendor: Microsoft | Product: Exchange Server | Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2026-04-27
CVE-2023-36424 · CISA Known Exploited Vulnerabilities

Microsoft Windows Out-of-Bounds Read Vulnerability

Vendor: Microsoft | Product: Windows | Microsoft Windows Common Log File System Driver contains an out-of-bounds read vulnerability that could allow a threat actor for privileges escalation | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2026-04-27
CVE-2020-9715 · CISA Known Exploited Vulnerabilities

Adobe Acrobat Use-After-Free Vulnerability

Vendor: Adobe | Product: Acrobat | Adobe Acrobat contains a use-after-free vulnerability that allows for code execution | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2026-04-27
CVE-2026-21643 · CISA Known Exploited Vulnerabilities

Fortinet FortiClient EMS SQL Injection Vulnerability

Vendor: Fortinet | Product: FortiClient EMS | Fortinet FortiClient EMS contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.…
Read full source summary
Vendor: Fortinet | Product: FortiClient EMS | Fortinet FortiClient EMS contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2026-04-16
CVE-2026-34621 · CISA Known Exploited Vulnerabilities

Adobe Acrobat and Reader Prototype Pollution Vulnerability

Vendor: Adobe | Product: Acrobat and Reader | Adobe Acrobat and Reader contain a prototype pollution vulnerability that allows for arbitrary code execution. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2026-04-27
CVE-2026-1340 · CISA Known Exploited Vulnerabilities

Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability

Vendor: Ivanti | Product: Endpoint Manager Mobile (EPMM) | Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal…
Read full source summary
Vendor: Ivanti | Product: Endpoint Manager Mobile (EPMM) | Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2026-04-11
CVE-2026-35616 · CISA Known Exploited Vulnerabilities

Fortinet FortiClient EMS Improper Access Control Vulnerability

Vendor: Fortinet | Product: FortiClient EMS | Fortinet FortiClient EMS contains an improper access control vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. |…
Read full source summary
Vendor: Fortinet | Product: FortiClient EMS | Fortinet FortiClient EMS contains an improper access control vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2026-04-09
CVE-2026-3502 · CISA Known Exploited Vulnerabilities

TrueConf Client Download of Code Without Integrity Check Vulnerability

Vendor: TrueConf | Product: Client | TrueConf Client contains a download of code without integrity check vulnerability. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the payload is executed or installed by the updater, this may result in arbitrary code execution in the context of the updating process or user. | Required action: Apply mitigations per vendor…
Read full source summary
Vendor: TrueConf | Product: Client | TrueConf Client contains a download of code without integrity check vulnerability. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the payload is executed or installed by the updater, this may result in arbitrary code execution in the context of the updating process or user. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2026-04-16
CVE-2026-5281 · CISA Known Exploited Vulnerabilities

Google Dawn Use-After-Free Vulnerability

Vendor: Google | Product: Dawn | Google Dawn contains an use-after-free vulnerability that could allow a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. This vulnerability could affect multiple Chromium-based products including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required action: Apply mitigations per vendor instructions, follow…
Read full source summary
Vendor: Google | Product: Dawn | Google Dawn contains an use-after-free vulnerability that could allow a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. This vulnerability could affect multiple Chromium-based products including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2026-04-15
CVE-2026-3055 · CISA Known Exploited Vulnerabilities

Citrix NetScaler Out-of-Bounds Read Vulnerability

Vendor: Citrix | Product: NetScaler | Citrix NetScaler ADC (formerly Citrix ADC), NetScaler Gateway (formerly Citrix Gateway) and NetScaler ADC FIPS and NDcPP contain an out-of-bounds reads vulnerability when configured as a SAML IDP leading to memory overread. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if…
Read full source summary
Vendor: Citrix | Product: NetScaler | Citrix NetScaler ADC (formerly Citrix ADC), NetScaler Gateway (formerly Citrix Gateway) and NetScaler ADC FIPS and NDcPP contain an out-of-bounds reads vulnerability when configured as a SAML IDP leading to memory overread. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2026-04-02
CVE-2025-53521 · CISA Known Exploited Vulnerabilities

F5 BIG-IP Stack-Based Buffer Overflow Vulnerability

Vendor: F5 | Product: BIG-IP | F5 BIG-IP APM contains a stack-based buffer overflow vulnerability that could allow a threat actor to achieve remote code execution. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2026-03-30
CVE-2026-33634 · CISA Known Exploited Vulnerabilities

Aquasecurity Trivy Embedded Malicious Code Vulnerability

Vendor: Aquasecurity | Product: Trivy | Aquasecurity Trivy contains an embedded malicious code vulnerability that could allow an attacker to gain access to everything in the CI/CD environment, including all tokens, SSH keys, cloud credentials, database passwords, and any sensitive configuration in memory. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud…
Read full source summary
Vendor: Aquasecurity | Product: Trivy | Aquasecurity Trivy contains an embedded malicious code vulnerability that could allow an attacker to gain access to everything in the CI/CD environment, including all tokens, SSH keys, cloud credentials, database passwords, and any sensitive configuration in memory. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2026-04-09
CVE-2026-33017 · CISA Known Exploited Vulnerabilities

Langflow Code Injection Vulnerability

Vendor: Langflow | Product: Langflow | Langflow contains a code injection vulnerability that could allow building public flows without requiring authentication. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2026-04-08
Browse saved snapshots