KEV 2026

123 CISA Known Exploited Vulnerabilities from 2026

Critical 65

August 2026

CVE-2026-21962

Oracle HTTP Server / WebLogic Proxy Plug-in — Unauthenticated Access-Control Bypass

CVSS 10
CVE-2026-72898

Metabase — Pre-Auth SQL Injection in Password Reset via HoneySQL :raw Escape Hatch

CVSS 10
CVE-2026-8452

Citrix NetScaler ADC / Gateway — Pre-Auth SAML Memory Overflow (CTX696604)

CVSS 9.8
CVE-2026-60004

Gitea — diffpatch Git Hook Injection Enabling Remote Code Execution

CVSS 9.8
CVE-2026-72529

TrueConf Server — Unauthenticated Script Execution via TCP/4307

CVSS 9.8
CVE-2026-33824

Microsoft Windows IKEEXT — Pre-Auth Remote Code Execution as SYSTEM via IKEv2 Fragment Reassembly Double Free

CVSS 9.8
CVE-2026-59310

Broadcom VMware vCenter — Unauthenticated Path Traversal in the Syslog Service Leading to Remote Code Execution

CVSS 9.8
CVE-2026-65400

Apple macOS Screen Sharing — Pre-Authentication SRP Bypass in screensharingd Yielding Root Access

CVSS 9.8
CVE-2026-63077

JetBrains TeamCity — Pre-Auth XStream Deserialization RCE via the Agent Polling Protocol

CVSS 9.8
CVE-2026-9198

IBM Langflow — Unauthenticated RCE by Chaining auto_login to the Code Validation exec() Sink

CVSS 9.8
CVE-2026-8037

Progress Kemp LoadMaster — Pre-Auth Root RCE via Uninitialized Heap in escape_quotes()

CVSS 9.6
CVE-2026-64849

MLflow — Unauthenticated SSRF via Webhook Test Endpoint Redirect Bypass Exposing Cloud Metadata Credentials

CVSS 9.3
CVE-2026-55040

Microsoft SharePoint Server — Unauthenticated JWT Forgery Enabling Arbitrary User and Site Administrator Impersonation

CVSS 9.1
CVE-2026-72530

TrueConf Server — Sandbox Escape to SYSTEM via Code Injection

CVSS 9

July 2026

CVE-2026-16812

Arista VeloCloud Orchestrator — Pre-Auth OS Command Injection to Host Takeover of the SD-WAN Control Plane

CVSS 10
CVE-2026-15409

SonicWall SMA1000 — Unauthenticated Work Place SSRF Chained With Admin Code Injection in Zero-Day Attacks

CVSS 10
CVE-2026-48282

Adobe ColdFusion — RDS FILEIO Path Traversal to RCE, Exploited Within Hours of Disclosure

CVSS 10
CVE-2026-50522

Microsoft SharePoint — Deserialization RCE via SessionSecurityTokenHandler, Fourth in a Month-Long SharePoint Attack Wave

CVSS 9.8
CVE-2026-0770

Langflow — Unauthenticated Root RCE via Unsandboxed exec() in the Code Validation Endpoint

CVSS 9.8
CVE-2026-63030

WordPress Core — REST API Batch-Routing Confusion Chained with CVE-2026-60137 for Pre-Auth RCE ("wp2shell")

CVSS 9.8
CVE-2026-25089

Fortinet FortiSandbox — Unauthenticated Command Injection via Start VNC Feature

CVSS 9.8
CVE-2026-39808

Fortinet FortiSandbox — Unauthenticated Root Command Injection via tracer-behavior API

CVSS 9.8
CVE-2026-58644

Microsoft SharePoint Server — Unauthenticated Remote Code Execution via Deserialization of Untrusted Data

CVSS 9.8
CVE-2026-46817

Oracle E-Business Suite (Oracle Payments) — Unauthenticated Privilege Escalation and File Read via ibytransmit Endpoint

CVSS 9.8
CVE-2026-48939

iCagenda — Frontend Attachment Upload Zero-Day Exploited Hours Before Patch Release

CVSS 9.8
CVE-2026-56291

Balbooa Forms — Attachment Upload Extension Re-Attached Verbatim, Exploited as Zero-Day Before a Patch Existed

CVSS 9.8
CVE-2026-48908

JoomShaper SP Page Builder — Unauthenticated uploadCustomIcon Task Enables PHP Web Shell Upload

CVSS 9.8
CVE-2026-56290

Joomlack Page Builder CK — CSRF-Token-Only Upload Check Bypassed via Public Token Harvesting

CVSS 9.8
CVE-2026-16232

Check Point SmartConsole — Unauthenticated Login Token Theft Leads to Full Administrative Takeover

CVSS 9.1

June 2026

May 2026

April 2026

March 2026

February 2026

January 2026

High 43

August 2026

July 2026

June 2026

May 2026

April 2026

March 2026

February 2026

January 2026

Medium 15

August 2026

July 2026

June 2026

May 2026

April 2026

February 2026

January 2026