cisa-kev
CISA KEVKeeps: CVE id, vendor, due date
CVE: CVE-2026-21962 Vendor/project: Oracle Product: HTTP Server and Oracle Weblogic Server Proxy Plug-in Known ransomware campaign use: Unknown Due date: 2026-08-27 CWE: CWE-284 Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in contain an improper access control vulnera
CVE: CVE-2026-73570 Vendor/project: Synacor Product: Zimbra Collaboration Suite (ZCS) Known ransomware campaign use: Unknown Due date: 2026-08-24 CWE: CWE-78 Zimbra Collaboration Suite (ZCS) contains an OS command injection vulnerability which could allow an unauthenticated attac
CVE: CVE-2026-72529 Vendor/project: TrueConf Product: Server Known ransomware campaign use: Unknown Due date: 2026-08-23 CWE: CWE-306 TrueConf Server contains a missing authentication for critical function vulnerability which could allow a remote unauthorized attacker with networ
CVE: CVE-2026-72530 Vendor/project: TrueConf Product: Server Known ransomware campaign use: Unknown Due date: 2026-09-03 CWE: CWE-94 TrueConf Server contains a code injection vulnerability that could allow an unauthorized remote attacker with network access via port 4307/TCP to u
CVE: CVE-2026-64849 Vendor/project: MLflow Product: MLflow Known ransomware campaign use: Unknown Due date: 2026-09-02 CWE: CWE-918 MLflow contains a server-side request forgery vulnerability that can allow attackers to reach internal or cloud metadata services and receive respon
CVE: CVE-2026-65400 Vendor/project: Apple Product: macOS Known ransomware campaign use: Unknown Due date: 2026-08-21 CWE: CWE-287 Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without va
CVE: CVE-2026-55040 Vendor/project: Microsoft Product: SharePoint Known ransomware campaign use: Unknown Due date: 2026-08-21 CWE: CWE-1390 Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a
- 2026-08-18CISA KEV: Broadcom / VMware vCenter / Broadcom VMware vCenter Path Traversal Vulnerability
CVE: CVE-2026-59310 Vendor/project: Broadcom Product: VMware vCenter Known ransomware campaign use: Unknown Due date: 2026-08-21 CWE: CWE-22 Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute
CVE: CVE-2026-33824 Vendor/project: Microsoft Product: Internet Key Exchange (IKE) Service Extensions Known ransomware campaign use: Unknown Due date: 2026-08-21 CWE: CWE-415 Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could
CVE: CVE-2025-62593 Vendor/project: Ray-Project Product: Ray Known ransomware campaign use: Unknown Due date: 2026-08-20 CWE: CWE-94, CWE-352 Ray-Project Ray contains a code injection vulnerability that could allow remote code execution. Developers using Ray as a development tool
CVE: CVE-2026-72898 Vendor/project: Metabase Product: Metabase Known ransomware campaign use: Unknown Due date: 2026-08-14 CWE: CWE-89 Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase applicat
CVE: CVE-2026-68820 Vendor/project: Microsoft Product: Windows Ancillary Function Driver for WinSock Known ransomware campaign use: Unknown Due date: 2026-08-25 CWE: CWE-416 Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allow
CVE: CVE-2026-20349 Vendor/project: Cisco Product: Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Known ransomware campaign use: Unknown Due date: 2026-08-14 CWE: CWE-244 Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secur
CVE: CVE-2026-8037 Vendor/project: Progress Product: LoadMaster Known ransomware campaign use: Unknown Due date: 2026-08-10 CWE: CWE-77 Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the Loa
- 2026-08-05CISA KEV: JetBrains / TeamCity / JetBrains TeamCity Deserialization of Untrusted Data Vulnerability
CVE: CVE-2026-63077 Vendor/project: JetBrains Product: TeamCity Known ransomware campaign use: Unknown Due date: 2026-08-08 CWE: CWE-502 JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the ag
CVE: CVE-2026-9198 Vendor/project: IBM Product: Langflow Known ransomware campaign use: Unknown Due date: 2026-08-07 CWE: CWE-94 Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deploy
- 2026-08-04CISA KEV: Apache / Tomcat / Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
CVE: CVE-2026-34486 Vendor/project: Apache Product: Tomcat Known ransomware campaign use: Unknown Due date: 2026-08-07 CWE: CWE-311 Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. Required action: Apply
CVE: CVE-2026-18556 Vendor/project: N-able Product: N-central Known ransomware campaign use: Unknown Due date: 2026-08-07 CWE: CWE-288 N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass. Required action: App
CVE: CVE-2026-18577 Vendor/project: N-able Product: N-central Known ransomware campaign use: Unknown Due date: 2026-08-06 CWE: CWE-288 N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-
CVE: CVE-2026-20316 Vendor/project: Cisco Product: Secure Firewall Management Center (FMC) Known ransomware campaign use: Unknown Due date: 2026-08-01 CWE: CWE-259 Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-c
CVE: CVE-2026-16812 Vendor/project: Arista Product: VeloCloud Orchestrator Known ransomware campaign use: Unknown Due date: 2026-07-30 CWE: CWE-78 Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privi
CVE: CVE-2025-68686 Vendor/project: Fortinet Product: FortiOS Known ransomware campaign use: Unknown Due date: 2026-08-10 CWE: CWE-200 Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated at
CVE: CVE-2026-50522 Vendor/project: Microsoft Product: SharePoint Known ransomware campaign use: Unknown Due date: 2026-07-25 CWE: CWE-502 Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code ov
CVE: CVE-2026-16232 Vendor/project: Check Point Product: SmartConsole Known ransomware campaign use: Unknown Due date: 2026-07-25 CWE: CWE-287 Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain
CVE: CVE-2021-27137 Vendor/project: DD-WRT Product: DD-WRT Known ransomware campaign use: Unknown Due date: 2026-07-24 CWE: CWE-121 DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP
CVE: CVE-2026-0770 Vendor/project: Langflow Product: Langflow Known ransomware campaign use: Unknown Due date: 2026-07-24 CWE: CWE-829 Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary cod
CVE: CVE-2026-63030 Vendor/project: WordPress Product: Core Known ransomware campaign use: Unknown Due date: 2026-07-24 CWE: CWE-436 WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Exec
CVE: CVE-2026-60137 Vendor/project: WordPress Product: Core Known ransomware campaign use: Unknown Due date: 2026-08-04 CWE: CWE-89 WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chai
- 2026-07-16CISA KEV: Fortinet / FortiSandbox / Fortinet FortiSandbox OS Command Injection Vulnerability
CVE: CVE-2026-39808 Vendor/project: Fortinet Product: FortiSandbox Known ransomware campaign use: Unknown Due date: 2026-07-19 CWE: CWE-78 Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized cod
- 2026-07-16CISA KEV: Fortinet / FortiSandbox / Fortinet FortiSandbox OS Command Injection Vulnerability
CVE: CVE-2026-25089 Vendor/project: Fortinet Product: FortiSandbox Known ransomware campaign use: Unknown Due date: 2026-07-19 CWE: CWE-78 Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated
CVE: CVE-2026-58644 Vendor/project: Microsoft Product: SharePoint Known ransomware campaign use: Unknown Due date: 2026-07-19 CWE: CWE-502 Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a n
CVE: CVE-2023-4346 Vendor/project: KNX Association Product: KNX Protocol Connection Authorization Option 1 Known ransomware campaign use: Unknown Due date: 2026-07-29 CWE: CWE-645 KNX Association KNX Protocol Connection Authorization Option 1 contains an overly restrictive accoun
CVE: CVE-2026-46817 Vendor/project: Oracle Product: E-Business Suite Known ransomware campaign use: Unknown Due date: 2026-07-18 CWE: CWE-269, CWE-287, CWE-306 Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker
- 2026-07-14CISA KEV: SonicWall / SMA1000 Appliances / SonicWall SMA1000 Appliances Code Injection Vulnerability
CVE: CVE-2026-15410 Vendor/project: SonicWall Product: SMA1000 Appliances Known ransomware campaign use: Unknown Due date: 2026-07-17 CWE: CWE-94 SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote aut
CVE: CVE-2026-15409 Vendor/project: SonicWall Product: SMA1000 Appliances Known ransomware campaign use: Unknown Due date: 2026-07-17 CWE: CWE-918 SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker t
CVE: CVE-2026-56164 Vendor/project: Microsoft Product: SharePoint Server Known ransomware campaign use: Unknown Due date: 2026-07-17 CWE: CWE-306 Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to ele
CVE: CVE-2026-56155 Vendor/project: Microsoft Product: Active Directory Federation Services Known ransomware campaign use: Unknown Due date: 2026-07-28 CWE: CWE-1220 Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerabilit
CVE: CVE-2008-4128 Vendor/project: Cisco Product: IOS Known ransomware campaign use: Unknown Due date: 2026-07-16 CWE: CWE-352 Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain "show pr
CVE: CVE-2026-48939 Vendor/project: iCagenda Product: iCagenda Known ransomware campaign use: Unknown Due date: 2026-07-13 CWE: CWE-434 iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachm
CVE: CVE-2026-56291 Vendor/project: Balbooa Product: Forms Known ransomware campaign use: Unknown Due date: 2026-07-13 CWE: CWE-434 Balbooa Forms contains an unrestricted upload of file with dangerous type vulnerability that allows an unauthenticated arbitrary file upload which c
CVE: CVE-2026-48282 Vendor/project: Adobe Product: ColdFusion Known ransomware campaign use: Unknown Due date: 2026-07-10 CWE: CWE-22 Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user. Required
- 2026-07-07CISA KEV: Joomlack / Page Builder / Joomlack Page Builder Improper Access Control Vulnerability
CVE: CVE-2026-56290 Vendor/project: Joomlack Product: Page Builder Known ransomware campaign use: Unknown Due date: 2026-07-10 CWE: CWE-284 Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbit
CVE: CVE-2026-55255 Vendor/project: Langflow Product: Langflow Known ransomware campaign use: Unknown Due date: 2026-07-10 CWE: CWE-639 Langflow contains an authorization bypass through user-controlled key vulnerability which allows an authenticated attacker to execute any flow b
CVE: CVE-2026-48908 Vendor/project: JoomShaper Product: SP Page Builder Known ransomware campaign use: Unknown Due date: 2026-07-10 CWE: CWE-434 JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users
CVE: CVE-2026-45659 Vendor/project: Microsoft Product: SharePoint Server Known ransomware campaign use: Unknown Due date: 2026-07-04 CWE: CWE-502 Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute
CVE: CVE-2026-48558 Vendor/project: SimpleHelp Product: SimpleHelp Known ransomware campaign use: Unknown Due date: 2026-07-02 CWE: CWE-347 SimpleHelp contains an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity
CVE: CVE-2026-20230 Vendor/project: Cisco Product: Unified Communications Manager Known ransomware campaign use: Unknown Due date: 2026-06-28 CWE: CWE-918 Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unifie
CVE: CVE-2026-12569 Vendor/project: PTC Product: Windchill and FlexPLM Known ransomware campaign use: Unknown Due date: 2026-06-28 CWE: CWE-20, CWE-502 PTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attacker to ex
CVE: CVE-2026-34908 Vendor/project: Ubiquiti Product: UniFi OS Known ransomware campaign use: Unknown Due date: 2026-06-26 CWE: CWE-284 Ubiquiti UniFi OS contains an improper access control vulnerability which could allow a malicious actor with access to the network to make unaut
CVE: CVE-2026-34909 Vendor/project: Ubiquiti Product: UniFi OS Known ransomware campaign use: Unknown Due date: 2026-06-26 CWE: CWE-22 Ubiquiti UniFi OS contains a path traversal vulnerability which could allow a malicious actor with access to the network to access files on the u