Technology Innovation Partners

CISA Known Exploited Vulnerabilities

Not theoretical risks — these are vulnerabilities CISA has confirmed are being exploited right now. Federal agencies are required to remediate every one of them, and if you hold a government contract, your auditors will ask whether you have.

Catalog size
1,729
Showing newest
48
Used in ransomware
0
CISA updated
September 29, 2026

Most Recently Added

Apple · Multiple Products

Apple Multiple Products Out-of-Bounds Write Vulnerability

Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution.

Added Sep 29, 2026Vendor advisory

Citrix · NetScaler

Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial of service

Added Sep 27, 2026Vendor advisory

Citrix · NetScaler

Citrix NetScaler Improper Input Validation Vulnerability

Citrix NetScaler ADC and NetScaler Gateway contain an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands.

Added Sep 27, 2026Vendor advisory

MikroTik · RouterOS

Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability

Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060.

Added Sep 25, 2026Vendor advisory

Microsoft · SharePoint

Microsoft SharePoint Code Injection Vulnerability

Microsoft SharePoint contains a code injection vulnerability which could allow an authorized attacker to execute code over a network.

Added Sep 25, 2026Vendor advisory

WordPress · Core

WordPress Core Remote File Inclusion Vulnerability

WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local `.php` file outside the active theme directories, leading to remote code execution.

Added Sep 25, 2026Vendor advisory

WSO2 · Multiple Products

WSO2 Multiple Products Path Traversal Vulnerability

WSO2 API Control Plane, API Manager, Traffic Manager & Universal Gateway contain a path traversal vulnerability that could allow for unrestricted file upload and lead to remote code execution.

Added Sep 24, 2026Vendor advisory

Adobe · Commerce and Magento

Adobe Commerce and Magento Incorrect Authorization Vulnerability

Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction.

Added Sep 24, 2026Vendor advisory

Arista · VeloCloud Orchestrator

Arista VeloCloud Orchestrator Improper Input Validation Vulnerability

Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.

Added Sep 22, 2026Vendor advisory

Also In The Catalog

CVE-2026-94127F5 · BIG-IP APM

F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability

CVE-2026-93616Check Point · Multiple Products

Check Point Multiple Products Path Traversal Vulnerability

CVE-2026-85102Check Point · Multiple Products

Check Point Multiple Products Improper Certificate Validation Vulnerability

CVE-2026-7273Zyxel · GS1900 Series Switches

Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability

CVE-2025-39964Linux · Kernel

Linux Kernel Race Condition Vulnerability

CVE-2026-53266Linux · Kernel

Linux Kernel Out-of-Bounds Write Vulnerability

CVE-2025-39682Linux · Kernel

Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability

CVE-2026-58704Google · Pixel

Google Pixel Improper Authorization Vulnerability

CVE-2026-76460Cisco · Identity Services Engine

Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability

CVE-2026-87886Acronis · Backup

Acronis Backup Incorrect Default Permissions Vulnerability

CVE-2026-76461Cisco · Secure Email Gateway

Cisco Secure Email Gateway SQL Injection Vulnerability

CVE-2026-84869ConnectWise · ScreenConnect

ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability

CVE-2026-42016JFrog · Artifactory

JFrog Artifactory Incorrect Authorization Vulnerability

CVE-2026-42018JFrog · Artifactory

JFrog Artifactory Improper Authentication Vulnerability

CVE-2026-85706GitLab · Community Edition and Enterprise Edition

GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability

CVE-2026-86060MikroTik · RouterOS

MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability

CVE-2026-67277MikroTik · RouterOS

MikroTik RouterOS Missing Authentication for Critical Function Vulnerability

CVE-2026-19490Citrix · NetScaler

Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability

CVE-2025-25249Fortinet · Multiple Products

Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability

CVE-2026-87491Google · Chromium V8

Google Chromium V8 Out of Bounds Write Vulnerability

CVE-2026-20079Cisco · Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management

Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability

CVE-2026-75650Adobe · Commerce and Magento

Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability

CVE-2026-81963Microsoft · Windows

Microsoft Windows Link Following Vulnerability

CVE-2026-86218N-able · N-central

N-able N-central Static Code Injection Vulnerability

CVE-2026-85880Microsoft · Windows

Microsoft Windows Heap-Based Buffer Overflow Vulnerability

CVE-2026-85046Google · Chromium V8

Google Chromium V8 Type Confusion Vulnerability

CVE-2026-59822BerriAI · LiteLLM

BerriAI LiteLLM Improper Authentication Vulnerability

CVE-2026-48710Kludex · Starlette

Kludex Starlette HTTP Request/Response Smuggling Vulnerability

CVE-2026-49869Kestra · Kestra OSS

Kestra OSS OS Command Injection Vulnerability

CVE-2026-82329JFrog · Artifactory

JFrog Artifactory Improper Authentication Vulnerability

CVE-2026-9586Sangoma · Switchvox

Sangoma Switchvox SQL Injection Vulnerability

CVE-2026-83548SonicWall · SMA1000 Appliances

SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability

CVE-2026-83549SonicWall · SMA1000 Appliances

SonicWall SMA1000 Appliances OS Command Injection Vulnerability

CVE-2026-82078PaperCut · NG/MF

PaperCut NG/MF Unsafe Reflection Vulnerability

CVE-2026-81578PaperCut · NG/MF

PaperCut NG/MF Missing Authentication for Critical Function Vulnerability

CVE-2023-49105ownCloud · ownCloud

ownCloud Improper Authentication Vulnerability

CVE-2026-53362Linux · Kernel

Linux Kernel Unspecified Vulnerability

CVE-2026-66384JFrog · Artifactory

JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability

CVE-2021-23758Ajax.NET Professional · Ajax.NET Professional

Ajax.NET Professional Deserialization of Untrusted Data Vulnerability

Source: CISA Known Exploited Vulnerabilities Catalog, published by the Cybersecurity and Infrastructure Security Agency as a public resource. Technology Innovation Partners is not affiliated with or endorsed by CISA.

Do You Know If You're Running Any of These?

Most organizations can't answer that quickly — which is exactly how these get exploited. We'll inventory your environment against the KEV catalog and tell you where you stand.