CISA KEV / NVD

Exploited vulnerabilities, at a glance

From CISA's Known Exploited Vulnerabilities (KEV) and high-severity CVEs in the NVD (NVD), major vulnerabilities organized with sources. This site is not an official U.S. government source.

Security: this page is a general organization of public information, not advice or a warranty. Judge applicability and priority against official vendor information and your own environment.

Browse all collected data (list, filter, search) →

Featured

Featured

High-severity, actively exploited vulnerabilities explained with key points, FAQs, and sources.

Exploited CVE-2026-85046 Sep 4, 2026

One component inside several browsers: type confusion in Chromium V8

A type confusion flaw added to the catalog on 4 September 2026. The record itself states that it could affect multiple Chromium-based browsers, naming Chrome, Edge and Opera.

  • A type confusion vulnerability in V8, the JavaScript engine in Chromium, reachable through a crafted HTML page.
  • The record itself states the flaw could affect several Chromium-based browsers, naming Chrome, Edge and Opera.
  • V8 appears 40 times in the catalog, and 20 of those are the same weakness, CWE-843.
Read more
Exploited Ransomware use CVE-2026-59310 Aug 18, 2026

A path traversal in VMware vCenter (CVE-2026-59310) — what it means to lose the management plane of a virtualized estate

VMware vCenter, the management server for a virtualized estate, contains a flaw in how it validates pathnames. An attacker with network access to vCenter can execute arbitrary code. CISA added it to the KEV catalog on 2026-08-18 with a due date of 2026-08-21 — three days after listing.

  • The affected product is Broadcom VMware vCenter; CWE-22, improper limitation of a pathname (path traversal).
  • The catalog records that a threat actor with network access to vCenter can execute arbitrary code.
  • vCenter is the management plane of a virtualized environment — the layer that creates, moves, clones, and deletes virtual machines.
Read more
Exploited Ransomware use CVE-2026-20316 Jul 29, 2026

A hard-coded password in a firewall management appliance - one of only two such entries in 1,687 (Cisco FMC, CVE-2026-20316)

A use of hard-coded password vulnerability in Cisco Secure Firewall Management Center has been added to CISA's Known Exploited Vulnerabilities catalog. An unauthenticated remote attacker can log in with a low-privileged account.

  • A hard-coded password (CWE-259) lets an unauthenticated remote attacker log in with a low-privileged account.
  • A credential embedded in a product does not differ between environments, so once known it reaches widely.
  • The subject is an appliance centrally managing firewalls - the defending machinery itself as the way in.
Read more
Exploited Ransomware use CVE-2026-15409 Jul 14, 2026

Server-side request forgery in SonicWall SMA1000 — remote-access appliances carry markedly higher ransomware association

SonicWall SMA1000 appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to cause the appliance to make requests to unintended locations. It was added to the CISA Known Exploited Vulnerabilities catalog on 2026-07-14 with a due date three days later, and use in ransomware campaigns is known.

  • SonicWall SMA1000 appliances contain a server-side request forgery (CWE-918) exploitable without authentication.
  • Added to KEV on 2026-07-14 with a due date of 2026-07-17, a three-day grace period. Use in ransomware campaigns is known.
  • Among the 1,687 records this site holds as of 2026-09-02, vendors with at least 8 records show ransomware shares of QNAP 81.8% (9/11), SonicWall 76.5% (13/17), Atlassian 61.5% (8/13), Fortinet 48.3% (14/29).
Read more
Exploited Ransomware use CVE-2026-15410 Jul 14, 2026

Code injection in SonicWall SMA1000 (CVE-2026-15410) — recorded as used in ransomware campaigns

SonicWall SMA1000, a remote access appliance, contains a code injection flaw allowing a remote attacker authenticated as administrator to execute arbitrary OS commands. CISA added it to the KEV catalog on 2026-07-14 with a due date of 2026-07-17 — three days. This entry is recorded as known to be used in ransomware campaigns.

  • The affected product is SonicWall SMA1000 Appliances; CWE-94, improper control of code generation.
  • Under specific conditions a remote attacker authenticated as administrator can execute arbitrary OS commands.
  • Use in ransomware campaigns is recorded as known — unlike most entries this site holds.
Read more
High Ransomware use CVE-2026-45659 Jul 1, 2026

Deserialization flaw in Microsoft SharePoint Server (CVE-2026-45659) — authenticated remote code execution, with a 3-day remediation deadline

Microsoft SharePoint Server, the widely used document-collaboration platform, contains a deserialization-of-untrusted-data vulnerability that lets an authorized attacker execute code over the network. CISA added it to the KEV (Known Exploited Vulnerabilities) catalog on July 1, 2026, setting the remediation deadline just three days later, on July 4.

  • Deserialization of untrusted data (CWE-502) in SharePoint Server — crafted data injected into the restore process can execute code remotely
  • Requires authorization (login) — the classic post-intrusion pattern: a stolen account or existing foothold becomes full server takeover
  • Microsoft's NVD-registered assessment: CVSS 8.8 (HIGH) — low privileges, no user interaction
Read more
Critical Ransomware use CVE-2026-12569 Jun 25, 2026

Unauthenticated RCE in PTC Windchill / FlexPLM (CVE-2026-12569) — the heart of manufacturing design under attack, CVSS 9.8

PTC Windchill / FlexPLM, product lifecycle management (PLM) platforms for manufacturing, contain an improper-input-validation flaw (CWE-20/CWE-502). An unauthenticated remote attacker can execute arbitrary code just by sending a crafted request. The official NVD score is CVSS 9.8 (CRITICAL). CISA added it to KEV on June 25, 2026, with remediation due three days later, June 28.

  • Improper input validation (CWE-20/CWE-502) in manufacturing PLM platforms PTC Windchill / FlexPLM
  • No authentication, no user interaction, remote code execution — the dangerous "pre-auth RCE"
  • Official NVD score: CVSS 9.8 (CRITICAL)
Read more
Critical Ransomware use CVE-2026-35273 Jun 12, 2026

Missing authentication in Oracle PeopleSoft (PeopleTools) (CVE-2026-35273) — unauthenticated takeover, used in ransomware

Oracle PeopleSoft Enterprise PeopleTools — the platform under the PeopleSoft ERP (HR, finance) — has a missing-authentication-for-critical-function flaw (CWE-306). A remote, unauthenticated attacker can take over PeopleTools. CISA listed it as known-exploited (KEV) and confirmed ransomware use (CVSS 9.8 Critical, per NVD).

  • Missing authentication for a critical function (CWE-306) in PeopleTools, the platform under PeopleSoft
  • A remote, unauthenticated attacker can take over PeopleTools
  • Listed in CISA KEV = exploitation confirmed; also confirmed used in ransomware
Read more
Critical Ransomware use CVE-2026-50751 Jun 8, 2026

Authentication bypass in Check Point Security Gateway (CVE-2026-50751) — VPN access without a password, CVSS 9.3

Check Point's Security Gateway products have an improper-authentication vulnerability in IKEv1 key exchange that lets an unauthenticated remote attacker bypass user authentication and establish a remote-access VPN connection without a valid user password. CISA listed it as known-exploited (KEV) (CVSS 9.3 Critical).

  • IKEv1 authentication bypass (CWE-287) in Check Point Security Gateway
  • An unauthenticated remote attacker establishes a remote-access VPN connection without a valid password
  • Compromise of a perimeter VPN/firewall = a foothold for internal intrusion. CVSS 9.3 (Critical)
Read more
Critical Ransomware use CVE-2026-0257 May 29, 2026

Authentication bypass in Palo Alto PAN-OS (CVE-2026-0257) — allows unauthorized VPN connections

An authentication-bypass vulnerability in Palo Alto Networks' firewall OS, PAN-OS, lets an attacker bypass security restrictions and establish an unauthorized VPN connection. CISA listed it as known-exploited (KEV) (CVSS 9.1 Critical).

  • Authentication-bypass vulnerability in PAN-OS (the OS for Palo Alto firewall products)
  • An attacker can bypass security restrictions and establish an unauthorized VPN connection
  • Compromise of a perimeter device = a foothold for internal intrusion. Listed in CISA KEV (CVSS 9.1 Critical)
Read more
Critical Ransomware use CVE-2026-48027 May 27, 2026

Malware in the Nx Console extension (CVE-2026-48027) — a supply-chain attack that steals developer credentials

A malicious version of "Nx Console," a popular IDE extension for the Nx build system, was published; it fetches an obfuscated payload and harvests credentials (tokens and keys) from disk and memory. CISA listed it as known-exploited (KEV) with confirmed ransomware use (CVSS 9.8 Critical).

  • A tampered build of Nx Console (an IDE extension for the Nx build system) fetched and ran an obfuscated payload
  • It stole credentials from disk and memory (GitHub/npm tokens, SSH keys, cloud credentials, etc.)
  • Listed in CISA KEV = exploitation confirmed; ransomware use also confirmed (CVSS 9.8 Critical)
Read more
Critical Ransomware use CVE-2026-45321 May 27, 2026

Malicious versions of TanStack npm packages (CVE-2026-45321) — credential-stealing malware shipped under a trusted name

Malicious versions of the widely used TanStack (a family of React libraries) were published to the npm registry, distributing credential-stealing malware under a trusted publisher identity. CISA listed it as known-exploited (KEV) with confirmed ransomware use (CVSS 9.6 Critical).

  • Malicious versions of TanStack (popular React libraries) were published to npm
  • A trusted publisher (maintainer identity) was abused to distribute credential-stealing malware
  • Listed in CISA KEV = exploitation confirmed; ransomware use also confirmed (CVSS 9.6 Critical)
Read more
Critical Ransomware use CVE-2026-41940 Apr 30, 2026

Missing authentication in cPanel & WHM (CVE-2026-41940) — control-panel takeover without authentication, ransomware use confirmed

cPanel & WHM and WP2, a widely used web-hosting control panel, have a missing-authentication flaw in the login flow that lets an unauthenticated remote attacker gain unauthorized access to the control panel. CISA listed it as known-exploited (KEV) with confirmed ransomware use (CVSS 9.8 Critical).

  • Missing authentication (CWE-306) in the login flow of cPanel & WHM / WP2
  • An unauthenticated remote attacker gains unauthorized access to the control panel
  • cPanel/WHM is the most widely used hosting control panel = one compromise ripples to many sites
Read more
High Ransomware use CVE-2024-1708 Apr 28, 2026

Path traversal in ConnectWise ScreenConnect (CVE-2024-1708) — remote code execution, ransomware use confirmed

ConnectWise ScreenConnect, a remote-management (RMM) / remote-support tool, has a path-traversal vulnerability that could let an attacker execute remote code or directly impact confidential data and critical systems. CISA listed it as known-exploited (KEV) with confirmed ransomware use (CVSS 8.4 High).

  • Path traversal (CWE-22) in ConnectWise ScreenConnect (an RMM tool that remotely manages many endpoints)
  • Can lead to remote code execution (RCE) or direct impact on confidential data and critical systems
  • RMM compromise = a "lever" to push malware to many managed endpoints at once
Read more
Critical Ransomware use CVE-2024-57726 Apr 24, 2026

Missing Authorization in SimpleHelp Could Allow Privilege Escalation to Server Admin (CVE-2024-57726)

The remote support/RMM tool SimpleHelp has a missing-authorization flaw that lets a low-privilege technician create an overly privileged API key and escalate to server administrator. It is listed in CISA's Known Exploited Vulnerabilities catalog and has been used in ransomware campaigns.

  • Affects SimpleHelp's remote support / RMM product SimpleHelp (CVE-2024-57726).
  • The weakness type is Missing Authorization.
  • A low-privilege technician can create an overly privileged API key and escalate to server administrator.
Read more
High Ransomware use CVE-2023-27351 Apr 20, 2026

Authentication Bypass in PaperCut NG/MF (CVE-2023-27351)

PaperCut NG/MF, a print management product, contains a flaw that may allow authentication (the identity-verification step) to be bypassed, potentially letting an attacker reach administrative functions without a valid login.

  • Affects PaperCut NG/MF print management software through an improper authentication flaw that may allow the identity check to be bypassed.
  • The KEV record states authentication may be bypassed via the SecurityRequestFilter class, potentially leading to unauthorized access to administrative functions.
  • Listed by CISA in its Known Exploited Vulnerabilities (KEV) catalog (added 2026-04-20, remediation due 2026-05-04).
Read more
High Ransomware use CVE-2024-27199 Apr 20, 2026

Relative Path Traversal in JetBrains TeamCity (CVE-2024-27199) — Known Exploited Flaw in a CI/CD Server, With Confirmed Ransomware Use

JetBrains TeamCity, a CI/CD server that automates building and distributing software, contains a relative path traversal flaw that can lead to limited admin actions, and CISA has added it to its Known Exploited Vulnerabilities (KEV) catalog.

  • Affected product is JetBrains TeamCity, a CI/CD server that automates building and distributing software.
  • The flaw is relative path traversal (reaching paths that were not meant to be accessible) and can lead to limited admin actions.
  • CISA added it to the KEV catalog on 2026-04-20, with a remediation due date of 2026-05-04.
Read more
Exploited Ransomware use CVE-2025-60710 Apr 13, 2026

One product listed 172 times: a Windows link following flaw and what repetition means

A privilege escalation flaw added to the CISA exploited-vulnerabilities catalog on 13 April 2026. Windows appears in that catalog 172 times, more than any other product in these records.

  • A privilege escalation flaw in Windows from link following (CWE-59), added to the catalog on 13 April 2026.
  • The remediation date was 27 April 2026, a fourteen-day window, and ransomware use is confirmed.
  • Of the 1,695 KEV records this site holds as of 2026-09-06, across 711 products, Windows accounts for 172.
Read more
High Ransomware use CVE-2023-21529 Apr 13, 2026

Deserialization of Untrusted Data in Microsoft Exchange Server (CVE-2023-21529) — Authenticated Remote Code Execution, Confirmed in Ransomware

Microsoft Exchange Server, an email backbone, contains a deserialization of untrusted data flaw (CWE-502) that lets an authenticated attacker run arbitrary code remotely. It has been confirmed used in ransomware attacks, and CISA added it to the KEV on 2026-04-13. The CVSS published on NVD is 8.8 (HIGH).

  • Deserialization (CWE-502) in Microsoft Exchange Server — reconstructing crafted data leads to remote arbitrary code execution.
  • The vector is PR:L (some privilege required), but stepping-stone attacks from stolen low-privilege accounts are standard, so "authenticated only" is no comfort.
  • Confirmed use in ransomware attacks (per CISA's record).
Read more
Exploited Ransomware use CVE-2026-20131 Mar 19, 2026

A product listed for the second time: arbitrary code as root on a security console

Added on 19 March 2026 with a remediation date of 22 March. The record states that an unauthenticated remote attacker could execute arbitrary Java code as root through the management interface.

  • A deserialization of untrusted data flaw in Cisco Secure Firewall Management Center and related management.
  • An unauthenticated remote attacker could execute arbitrary Java code as root through the management interface.
  • Added 19 March 2026 with a 22 March deadline, a three-day window, with ransomware use confirmed.
Read more
Exploited Ransomware use CVE-2025-26399 Mar 9, 2026

SolarWinds Web Help Desk deserialization (CVE-2025-26399) — what happens when data converted for storage is turned back

A deserialization vulnerability in SolarWinds Web Help Desk. Restoring untrusted data to its original form is described as allowing commands to be run on the host machine. The remediation deadline was set three days after listing.

  • The affected product is SolarWinds Web Help Desk, classified as CWE-502, deserialization of untrusted data.
  • A component of the product is described as allowing commands to be run on the host machine.
  • Deserialization restores data converted for storage or transmission, and what runs during that rebuilding depends on the content.
Read more
Exploited Ransomware use CVE-2026-1731 Feb 13, 2026

OS command injection in a remote support product (CVE-2026-1731) — no authentication, no user interaction, ransomware use known, and three days to remediate

BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) contain an OS command injection flaw. With neither authentication nor user interaction required, a remote attacker can execute operating system commands in the context of the site user. CISA added it to the KEV catalog on 2026-02-13 with a due date of 2026-02-16 — three days. Use in ransomware campaigns is recorded as known.

  • The affected products are BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA); CWE-78, OS command injection.
  • Exploitation requires neither authentication nor user interaction, allowing a remote attacker to execute OS commands in the context of the site user.
  • The catalog states it may lead to system compromise including unauthorized access, data exfiltration and service disruption.
Read more
Exploited Ransomware use CVE-2026-23760 Jan 26, 2026

Authentication bypass in SmarterMail (CVE-2026-23760) — an anonymous call to the password reset endpoint takes over an administrator account, and the product has reached KEV three times

SmarterTools SmarterMail contains an authentication bypass in its password reset API. The force-reset-password endpoint permits anonymous requests and does not verify an existing password or a reset token when resetting system administrator accounts, so an unauthenticated attacker supplying a target administrator username and a new password can take full administrative control of the instance.

  • The affected product is SmarterTools SmarterMail; CWE-288, authentication bypass using an alternate path or channel.
  • The force-reset-password endpoint permits anonymous requests and verifies neither the existing password nor a reset token for administrator accounts.
  • An unauthenticated attacker supplying a target administrator username and a new password can take full administrative control of the instance.
Read more
Exploited Ransomware use CVE-2025-55182 Dec 5, 2025

Remote code execution in React Server Components (CVE-2025-55182) — a flaw beneath the code you wrote, carrying no CWE assignment

Meta React Server Components contains a remote code execution flaw. Exploiting a defect in how React decodes payloads sent to React Server Function endpoints can yield unauthenticated remote code execution. CISA added it to the KEV catalog on 2025-12-05 with a due date of 2025-12-12 — seven days.

  • The affected product is Meta React Server Components, the framework beneath a great many web applications.
  • A defect in how React decodes payloads sent to Server Function endpoints can yield unauthenticated remote code execution.
  • The catalog notes that CVE-2025-66478 has been rejected but is associated with this record.
Read more
Exploited Ransomware use CVE-2025-61882 Oct 6, 2025

Oracle E-Business Suite unspecified vulnerability (CVE-2025-61882) — listed on the fact of exploitation while the class of flaw is undetermined

An unspecified vulnerability in the core business system Oracle E-Business Suite. Both the name and the description say unspecified, and the records this site holds carry no class of flaw. It appears in the catalog nonetheless because exploitation was confirmed.

  • The affected product is Oracle E-Business Suite, with the name given as an unspecified vulnerability and no class recorded.
  • The catalog collects what has been confirmed as actually exploited, so an entry can appear with the class undetermined.
  • It sits in a named component, and an unauthenticated party with network access via HTTP is described as able to compromise a processing component.
Read more
Exploited Ransomware use CVE-2025-10035 Sep 29, 2025

Deserialization in GoAnywhere MFT (CVE-2025-10035) — an actor with a validly forged license response signature can have arbitrary objects reconstructed

Fortra GoAnywhere MFT contains a deserialization of untrusted data flaw. An actor holding a validly forged license response signature can deserialize an arbitrary object under their control, possibly leading to command injection. CISA added it to the KEV catalog on 2025-09-29.

  • The affected product is Fortra GoAnywhere MFT; CWE-502 (deserialization of untrusted data) and CWE-77 (command injection).
  • An actor with a validly forged license response signature can deserialize an arbitrary object under their control.
  • The catalog states this may lead to command injection.
Read more
Exploited Ransomware use CVE-2025-8088 Aug 12, 2025

Path traversal in WinRAR (CVE-2025-8088) — code execution from a crafted archive, on software that runs on personal machines rather than enterprise systems

The Windows version of RARLAB WinRAR contains a path traversal flaw. An attacker can execute arbitrary code by crafting malicious archive files. CISA added it to the KEV catalog on 2025-08-12 with a due date of 2025-09-02. Use in ransomware campaigns is recorded as known.

  • The affected product is the Windows version of RARLAB WinRAR; CWE-35, path traversal.
  • A maliciously crafted archive file can let an attacker execute arbitrary code.
  • An archive carries information about where contents go; where that specification reaches outside the destination, files can be placed at will.
Read more
Exploited Ransomware use CVE-2025-49704 Jul 22, 2025

SharePoint code injection (CVE-2025-49704) — chainable with an authentication flaw, and due the day after it was listed

A code injection vulnerability in Microsoft SharePoint. The CISA Known Exploited Vulnerabilities catalog listed it on July 22, 2025 with a remediation due date of July 23. It is described as chainable with a separate authentication vulnerability, and use in ransomware campaigns is known.

  • The affected product is Microsoft SharePoint, classified as CWE-94, improper control of generation of code.
  • It is described as allowing an authorized attacker to execute code over a network.
  • The catalog records expressly that it could be chained with a separate authentication vulnerability.
Read more
Exploited Ransomware use CVE-2025-5777 Jul 10, 2025

A Citrix NetScaler out-of-bounds read given a next-day due date — one day against a median grace period of 21

Citrix NetScaler ADC and Gateway contain an out-of-bounds read vulnerability caused by insufficient input validation, which can lead to memory overread when configured as a Gateway or AAA virtual server. It was added to the CISA Known Exploited Vulnerabilities catalog on 2025-07-10 with a due date of 2025-07-11 — one day later. Use in ransomware campaigns is known.

  • Citrix NetScaler ADC and Gateway contain an out-of-bounds read (CWE-125) caused by insufficient input validation.
  • Memory overread can occur when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or as an AAA virtual server.
  • Added to KEV on 2025-07-10 with a due date of 2025-07-11 — a one-day grace period. Use in ransomware campaigns is known.
Read more
Exploited Ransomware use CVE-2025-31324 Apr 29, 2025

Unrestricted file upload in SAP NetWeaver (CVE-2025-31324) — executable binaries uploadable without authentication, on a product with eleven KEV entries

The SAP NetWeaver Visual Composer Metadata Uploader contains an unrestricted file upload flaw allowing an unauthenticated agent to upload potentially malicious executable binaries. CISA added it to the KEV catalog on 2025-04-29 with a due date of 2025-05-20.

  • The affected component is the SAP NetWeaver Visual Composer Metadata Uploader; CWE-434, unrestricted upload of file with dangerous type.
  • An unauthenticated agent can upload potentially malicious executable binaries.
  • Unrestricted signals that checks on extension and content and limits on the destination — the machinery keeping a placed file from executing — are not working.
Read more
New KEV (confirmed exploited)

Newly added exploited vulnerabilities

Vulnerabilities CISA has confirmed are exploited in the wild, newest first from the source feed.

This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.

High-severity CVEs (NVD)

High-severity CVEs from the NVD

Newly published high-severity (CVSS high to critical) CVEs from the U.S. NVD.

This product uses data from the NVD API but is not endorsed or certified by the NVD. KEV data is CC0 (public domain).

Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.