Apple · Multiple Products
Apple Multiple Products Out-of-Bounds Write Vulnerability
Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution.

Not theoretical risks — these are vulnerabilities CISA has confirmed are being exploited right now. Federal agencies are required to remediate every one of them, and if you hold a government contract, your auditors will ask whether you have.
Apple · Multiple Products
Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution.
Citrix · NetScaler
Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial of service
Citrix · NetScaler
Citrix NetScaler ADC and NetScaler Gateway contain an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands.
MikroTik · RouterOS
Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060.
Microsoft · SharePoint
Microsoft SharePoint contains a code injection vulnerability which could allow an authorized attacker to execute code over a network.
WordPress · Core
WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local `.php` file outside the active theme directories, leading to remote code execution.
WSO2 · Multiple Products
WSO2 API Control Plane, API Manager, Traffic Manager & Universal Gateway contain a path traversal vulnerability that could allow for unrestricted file upload and lead to remote code execution.
Adobe · Commerce and Magento
Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction.
Arista · VeloCloud Orchestrator
Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.
Check Point Multiple Products Path Traversal Vulnerability
Check Point Multiple Products Improper Certificate Validation Vulnerability
Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability
Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability
Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability
ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability
MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability
Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
SonicWall SMA1000 Appliances OS Command Injection Vulnerability
PaperCut NG/MF Missing Authentication for Critical Function Vulnerability
JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability
Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
Source: CISA Known Exploited Vulnerabilities Catalog, published by the Cybersecurity and Infrastructure Security Agency as a public resource. Technology Innovation Partners is not affiliated with or endorsed by CISA.

Most organizations can't answer that quickly — which is exactly how these get exploited. We'll inventory your environment against the KEV catalog and tell you where you stand.