{
  "query": {
    "exploited": "1",
    "page": "8"
  },
  "count": 20,
  "total": 1734,
  "page": 8,
  "limit": 20,
  "updated": {
    "cves": "2026-10-06T04:45:22.933Z",
    "kev": "2026-10-06T05:44:24.841Z",
    "epss": "2026-10-06T00:57:13.818Z",
    "breaches": "2026-10-06T00:45:13.561Z",
    "posts": "2026-10-06T05:45:25.054Z"
  },
  "links": {
    "web": "https://spydr.io/threats?exploited=1&page=8",
    "next": "https://spydr.io/threats.json?exploited=1&page=9"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2026-20079",
      "url": "https://spydr.io/cve/CVE-2026-20079",
      "published": "2026-03-04T18:16:24.230Z",
      "modified": "2026-09-16T17:17:16.340Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "cisco.com",
      "epss": 0.8818,
      "epss_percentile": 0.99765,
      "exploited": true,
      "kev": {
        "added": "2026-09-09",
        "due": "2026-09-12",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco Secure Firewall Management Center (FMC)"
      ],
      "cwes": [
        "CWE-288"
      ],
      "description": "A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.&nbsp; This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow&nbsp;root access to the device.&nbsp;"
    },
    {
      "id": "CVE-2026-21385",
      "url": "https://spydr.io/cve/CVE-2026-21385",
      "published": "2026-03-02T17:16:29.207Z",
      "modified": "2026-06-17T10:18:36.360Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "qualcomm.com",
      "epss": 0.01265,
      "epss_percentile": 0.68717,
      "exploited": true,
      "kev": {
        "added": "2026-03-03",
        "due": "2026-03-24",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Qualcomm, Inc."
      ],
      "products": [
        "Qualcomm, Inc. Snapdragon"
      ],
      "cwes": [
        "CWE-190"
      ],
      "description": "Memory corruption while using alignments for memory allocation."
    },
    {
      "id": "CVE-2026-22719",
      "url": "https://spydr.io/cve/CVE-2026-22719",
      "published": "2026-02-25T20:23:46.840Z",
      "modified": "2026-06-17T10:20:17.637Z",
      "score": 8.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "vmware.com",
      "epss": 0.17713,
      "epss_percentile": 0.9708,
      "exploited": true,
      "kev": {
        "added": "2026-03-03",
        "due": "2026-03-24",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "VMware"
      ],
      "products": [
        "VMware Aria Operations",
        "VMware Cloud Foundation Operations",
        "VMware Telco Cloud Platform",
        "VMware Telco Cloud Infrastructure"
      ],
      "cwes": [
        "CWE-77"
      ],
      "description": "VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress. To remediate CVE-2026-22719, apply the patches listed in the 'Fixed Version' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001 Workarounds for CVE-2026-22719 are documented in the 'Workarounds' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001"
    },
    {
      "id": "CVE-2026-20133",
      "url": "https://spydr.io/cve/CVE-2026-20133",
      "published": "2026-02-25T17:25:30.983Z",
      "modified": "2026-06-17T10:17:11.190Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.31829,
      "epss_percentile": 0.98256,
      "exploited": true,
      "kev": {
        "added": "2026-04-20",
        "due": "2026-04-23",
        "action": "Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco Catalyst SD-WAN Manager"
      ],
      "cwes": [
        "CWE-200"
      ],
      "description": "A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system. This vulnerability is due to insufficient file system restrictions. An authenticated attacker with netadmin privileges could exploit this vulnerability by accessing the vshell of an affected system. A successful exploit could allow the attacker to read sensitive information on the underlying operating system."
    },
    {
      "id": "CVE-2026-20128",
      "url": "https://spydr.io/cve/CVE-2026-20128",
      "published": "2026-02-25T17:25:30.150Z",
      "modified": "2026-06-17T10:17:10.543Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "cisco.com",
      "epss": 0.07064,
      "epss_percentile": 0.94024,
      "exploited": true,
      "kev": {
        "added": "2026-04-20",
        "due": "2026-04-23",
        "action": "Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco Catalyst SD-WAN Manager"
      ],
      "cwes": [
        "CWE-257"
      ],
      "description": "A vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain DCA user privileges on an affected system. This vulnerability is due to the presence of a credential file for the DCA user on an affected system. An attacker could exploit this vulnerability by sending a crafted HTTP request and reading the file that contains the DCA password from that affected system. A successful exploit could allow the attacker to access another affected system and gain DCA user privileges. Note: Cisco Catalyst SD-WAN Manager releases 20.18 and later are not affected by this vulnerability."
    },
    {
      "id": "CVE-2026-20127",
      "url": "https://spydr.io/cve/CVE-2026-20127",
      "published": "2026-02-25T17:25:29.477Z",
      "modified": "2026-06-17T15:06:12.607Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.88476,
      "epss_percentile": 0.9977,
      "exploited": true,
      "kev": {
        "added": "2026-02-25",
        "due": "2026-02-27",
        "action": "Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco Catalyst SD-WAN Manager"
      ],
      "cwes": [
        "CWE-287"
      ],
      "description": "A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to an affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root&nbsp;user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric.&nbsp;"
    },
    {
      "id": "CVE-2026-20122",
      "url": "https://spydr.io/cve/CVE-2026-20122",
      "published": "2026-02-25T17:25:28.170Z",
      "modified": "2026-06-17T10:17:09.043Z",
      "score": 5.4,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.24978,
      "epss_percentile": 0.9786,
      "exploited": true,
      "kev": {
        "added": "2026-04-20",
        "due": "2026-04-23",
        "action": "Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco Catalyst SD-WAN Manager"
      ],
      "cwes": [
        "CWE-648"
      ],
      "description": "A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite arbitrary files on the local file system. To exploit this vulnerability, the attacker must have valid read-only credentials with API access on the affected system. This vulnerability is due to improper file handling on the API interface of an affected system. An attacker could exploit this vulnerability by uploading a malicious file on the local file system. A successful exploit could allow the attacker to overwrite arbitrary files on the affected system&nbsp;and gain vmanage user privileges."
    },
    {
      "id": "CVE-2026-22769",
      "url": "https://spydr.io/cve/CVE-2026-22769",
      "published": "2026-02-17T20:22:09.800Z",
      "modified": "2026-06-17T10:20:23.560Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.13345,
      "epss_percentile": 0.96308,
      "exploited": true,
      "kev": {
        "added": "2026-02-18",
        "due": "2026-02-21",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Dell"
      ],
      "products": [
        "Dell RecoverPoint for Virtual Machines"
      ],
      "cwes": [
        "CWE-798"
      ],
      "description": "Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability. This is considered critical as an unauthenticated remote attacker with knowledge of the hardcoded credential could potentially exploit this vulnerability leading to unauthorized access to the underlying operating system and root-level persistence. Dell recommends that customers upgrade or apply one of the remediations as soon as possible."
    },
    {
      "id": "CVE-2026-2441",
      "url": "https://spydr.io/cve/CVE-2026-2441",
      "published": "2026-02-13T19:17:31.310Z",
      "modified": "2026-06-17T10:30:57.667Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.55101,
      "epss_percentile": 0.99003,
      "exploited": true,
      "kev": {
        "added": "2026-02-17",
        "due": "2026-03-10",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)"
    },
    {
      "id": "CVE-2026-25108",
      "url": "https://spydr.io/cve/CVE-2026-25108",
      "published": "2026-02-13T04:15:53.410Z",
      "modified": "2026-06-17T10:24:07.187Z",
      "score": 8.7,
      "severity": "high",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "jpcert.or.jp",
      "epss": 0.05177,
      "epss_percentile": 0.92208,
      "exploited": true,
      "kev": {
        "added": "2026-02-24",
        "due": "2026-03-17",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Soliton Systems K.K."
      ],
      "products": [
        "Soliton Systems K.K. FileZen"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "FileZen contains an OS command injection vulnerability. When FileZen Antivirus Check Option is enabled, a logged-in user may send a specially crafted HTTP request to execute an arbitrary OS command."
    },
    {
      "id": "CVE-2026-20700",
      "url": "https://spydr.io/cve/CVE-2026-20700",
      "published": "2026-02-11T23:16:10.670Z",
      "modified": "2026-06-17T10:17:43.440Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.01372,
      "epss_percentile": 0.71016,
      "exploited": true,
      "kev": {
        "added": "2026-02-12",
        "due": "2026-03-05",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple iOS and iPadOS",
        "Apple macOS",
        "Apple tvOS",
        "Apple visionOS",
        "Apple watchOS"
      ],
      "cwes": [
        "CWE-119"
      ],
      "description": "A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An attacker with memory write capability may be able to execute arbitrary code. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 and CVE-2025-43529 were also issued in response to this report."
    },
    {
      "id": "CVE-2026-21533",
      "url": "https://spydr.io/cve/CVE-2026-21533",
      "published": "2026-02-10T18:16:35.790Z",
      "modified": "2026-06-17T10:18:47.933Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.04125,
      "epss_percentile": 0.90503,
      "exploited": true,
      "kev": {
        "added": "2026-02-10",
        "due": "2026-03-03",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows 11 Version 25H2",
        "Microsoft Windows 11 version 26H1",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)",
        "Microsoft Windows Server 2025"
      ],
      "cwes": [
        "CWE-269"
      ],
      "description": "Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally."
    },
    {
      "id": "CVE-2026-21525",
      "url": "https://spydr.io/cve/CVE-2026-21525",
      "published": "2026-02-10T18:16:34.930Z",
      "modified": "2026-06-17T10:18:46.993Z",
      "score": 6.2,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "score_source": "microsoft.com",
      "epss": 0.04797,
      "epss_percentile": 0.91682,
      "exploited": true,
      "kev": {
        "added": "2026-02-10",
        "due": "2026-03-03",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows 11 Version 25H2",
        "Microsoft Windows 11 version 26H1",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)",
        "Microsoft Windows Server 2025"
      ],
      "cwes": [
        "CWE-476"
      ],
      "description": "Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally."
    },
    {
      "id": "CVE-2026-21519",
      "url": "https://spydr.io/cve/CVE-2026-21519",
      "published": "2026-02-10T18:16:34.417Z",
      "modified": "2026-06-17T10:18:46.287Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.02462,
      "epss_percentile": 0.83912,
      "exploited": true,
      "kev": {
        "added": "2026-02-10",
        "due": "2026-03-03",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows 11 Version 25H2",
        "Microsoft Windows 11 version 26H1",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)",
        "Microsoft Windows Server 2025",
        "Microsoft Windows Server 2025 (Server Core installation)"
      ],
      "cwes": [
        "CWE-843"
      ],
      "description": "Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to elevate privileges locally."
    },
    {
      "id": "CVE-2026-21514",
      "url": "https://spydr.io/cve/CVE-2026-21514",
      "published": "2026-02-10T18:16:33.803Z",
      "modified": "2026-06-17T10:18:45.733Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.01578,
      "epss_percentile": 0.74639,
      "exploited": true,
      "kev": {
        "added": "2026-02-10",
        "due": "2026-03-03",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft 365 Apps for Enterprise",
        "Microsoft Office LTSC 2021",
        "Microsoft Office LTSC 2024",
        "Microsoft Office LTSC for Mac 2021",
        "Microsoft Office LTSC for Mac 2024"
      ],
      "cwes": [
        "CWE-807"
      ],
      "description": "Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally."
    },
    {
      "id": "CVE-2026-21513",
      "url": "https://spydr.io/cve/CVE-2026-21513",
      "published": "2026-02-10T18:16:33.643Z",
      "modified": "2026-06-17T10:18:45.540Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.15642,
      "epss_percentile": 0.96754,
      "exploited": true,
      "kev": {
        "added": "2026-02-10",
        "due": "2026-03-03",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows 11 Version 25H2",
        "Microsoft Windows 11 version 26H1",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)",
        "Microsoft Windows Server 2025"
      ],
      "cwes": [
        "CWE-693"
      ],
      "description": "Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network."
    },
    {
      "id": "CVE-2026-21510",
      "url": "https://spydr.io/cve/CVE-2026-21510",
      "published": "2026-02-10T18:16:33.170Z",
      "modified": "2026-06-17T10:18:45.110Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.24226,
      "epss_percentile": 0.97797,
      "exploited": true,
      "kev": {
        "added": "2026-02-10",
        "due": "2026-03-03",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows 11 Version 25H2",
        "Microsoft Windows 11 version 26H1",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)",
        "Microsoft Windows Server 2025"
      ],
      "cwes": [
        "CWE-693"
      ],
      "description": "Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network."
    },
    {
      "id": "CVE-2026-1603",
      "url": "https://spydr.io/cve/CVE-2026-1603",
      "published": "2026-02-10T16:16:10.540Z",
      "modified": "2026-06-17T10:16:09.150Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.8794,
      "epss_percentile": 0.99761,
      "exploited": true,
      "kev": {
        "added": "2026-03-09",
        "due": "2026-03-23",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Ivanti"
      ],
      "products": [
        "Ivanti Endpoint Manager"
      ],
      "cwes": [
        "CWE-288",
        "CWE-306"
      ],
      "description": "An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data."
    },
    {
      "id": "CVE-2025-68686",
      "url": "https://spydr.io/cve/CVE-2025-68686",
      "published": "2026-02-10T16:16:09.630Z",
      "modified": "2026-07-28T05:17:04.113Z",
      "score": 5.9,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "fortinet.com",
      "epss": 0.29601,
      "epss_percentile": 0.98144,
      "exploited": true,
      "kev": {
        "added": "2026-07-27",
        "due": "2026-08-10",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Fortinet"
      ],
      "products": [
        "Fortinet FortiOS"
      ],
      "cwes": [
        "CWE-200"
      ],
      "description": "An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level."
    },
    {
      "id": "CVE-2026-1731",
      "url": "https://spydr.io/cve/CVE-2026-1731",
      "published": "2026-02-06T22:16:11.020Z",
      "modified": "2026-06-17T10:16:24.797Z",
      "score": 9.9,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "CNA",
      "epss": 0.90891,
      "epss_percentile": 0.99804,
      "exploited": true,
      "kev": {
        "added": "2026-02-13",
        "due": "2026-02-16",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "BeyondTrust"
      ],
      "products": [
        "BeyondTrust Remote Support(RS) & Privileged Remote Access(PRA)"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the context of the site user."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
