{
  "query": {
    "exploited": "1",
    "page": "9"
  },
  "count": 20,
  "total": 1734,
  "page": 9,
  "limit": 20,
  "updated": {
    "cves": "2026-10-06T06:45:27.610Z",
    "kev": "2026-10-06T06:44:27.275Z",
    "epss": "2026-10-06T00:57:13.818Z",
    "breaches": "2026-10-06T06:45:27.314Z",
    "posts": "2026-10-06T06:45:27.610Z"
  },
  "links": {
    "web": "https://spydr.io/threats?exploited=1&page=9",
    "next": "https://spydr.io/threats.json?exploited=1&page=10"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2026-21643",
      "url": "https://spydr.io/cve/CVE-2026-21643",
      "published": "2026-02-06T09:15:49.330Z",
      "modified": "2026-06-17T10:18:51.890Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "fortinet.com",
      "epss": 0.93871,
      "epss_percentile": 0.99843,
      "exploited": true,
      "kev": {
        "added": "2026-04-13",
        "due": "2026-04-16",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Fortinet"
      ],
      "products": [
        "Fortinet FortiClientEMS"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests."
    },
    {
      "id": "CVE-2025-15556",
      "url": "https://spydr.io/cve/CVE-2025-15556",
      "published": "2026-02-03T01:15:57.757Z",
      "modified": "2026-06-17T08:38:01.047Z",
      "score": 7.7,
      "severity": "high",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "vulncheck.com",
      "epss": 0.01772,
      "epss_percentile": 0.77395,
      "exploited": true,
      "kev": {
        "added": "2026-02-12",
        "due": "2026-03-05",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "notepad-plus-plus"
      ],
      "products": [
        "notepad-plus-plus"
      ],
      "cwes": [
        "CWE-494"
      ],
      "description": "Notepad++ versions prior to 8.8.9, when using the WinGUp updater, contain an update integrity verification vulnerability where downloaded update metadata and installers are not cryptographically verified. An attacker able to intercept or redirect update traffic can cause the updater to download and execute an attacker-controlled installer, resulting in arbitrary code execution with the privileges of the user."
    },
    {
      "id": "CVE-2026-1340",
      "url": "https://spydr.io/cve/CVE-2026-1340",
      "published": "2026-01-29T22:15:53.313Z",
      "modified": "2026-06-17T10:15:37.873Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "CNA",
      "epss": 0.98639,
      "epss_percentile": 0.99923,
      "exploited": true,
      "kev": {
        "added": "2026-04-08",
        "due": "2026-04-11",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Ivanti"
      ],
      "products": [
        "Ivanti Endpoint Manager Mobile"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution."
    },
    {
      "id": "CVE-2026-1281",
      "url": "https://spydr.io/cve/CVE-2026-1281",
      "published": "2026-01-29T22:15:53.140Z",
      "modified": "2026-06-17T10:15:26.787Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "CNA",
      "epss": 0.98688,
      "epss_percentile": 0.99924,
      "exploited": true,
      "kev": {
        "added": "2026-01-29",
        "due": "2026-02-01",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Ivanti"
      ],
      "products": [
        "Ivanti Endpoint Manager Mobile"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution."
    },
    {
      "id": "CVE-2025-40551",
      "url": "https://spydr.io/cve/CVE-2025-40551",
      "published": "2026-01-28T08:16:02.273Z",
      "modified": "2026-06-17T09:21:44.487Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "solarwinds.com",
      "epss": 0.84181,
      "epss_percentile": 0.99691,
      "exploited": true,
      "kev": {
        "added": "2026-02-03",
        "due": "2026-02-06",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "SolarWinds"
      ],
      "products": [
        "SolarWinds Web Help Desk"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication."
    },
    {
      "id": "CVE-2025-40536",
      "url": "https://spydr.io/cve/CVE-2025-40536",
      "published": "2026-01-28T08:16:01.893Z",
      "modified": "2026-06-17T09:21:43.410Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.73562,
      "epss_percentile": 0.99457,
      "exploited": true,
      "kev": {
        "added": "2026-02-12",
        "due": "2026-02-15",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "SolarWinds"
      ],
      "products": [
        "SolarWinds Web Help Desk"
      ],
      "cwes": [
        "CWE-693"
      ],
      "description": "SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated attacker to gain access to certain restricted functionality."
    },
    {
      "id": "CVE-2026-24858",
      "url": "https://spydr.io/cve/CVE-2026-24858",
      "published": "2026-01-27T20:16:24.477Z",
      "modified": "2026-06-17T10:23:43.040Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "fortinet.com",
      "epss": 0.85796,
      "epss_percentile": 0.99723,
      "exploited": true,
      "kev": {
        "added": "2026-01-27",
        "due": "2026-01-30",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Fortinet",
        "Siemens"
      ],
      "products": [
        "Fortinet FortiWeb",
        "Fortinet FortiNAC-F",
        "Fortinet FortiOS",
        "Fortinet FortiAnalyzer",
        "Fortinet FortiProxy",
        "Fortinet FortiManager",
        "Siemens RUGGEDCOM APE1808"
      ],
      "cwes": [
        "CWE-288"
      ],
      "description": "An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiManager 7.6.0 through 7.6.5, FortiManager 7.4.0 through 7.4.9, FortiManager 7.2.0 through 7.2.11, FortiManager 7.0.0 through 7.0.15, FortiNAC-F 7.6.3 through 7.6.5, FortiOS 7.6.0 through 7.6.5, FortiOS 7.4.0 through 7.4.10, FortiOS 7.2.0 through 7.2.12, FortiOS 7.0.0 through 7.0.18, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4.0 through 7.4.12, FortiProxy 7.2.0 through 7.2.15, FortiProxy 7.0.0 through 7.0.22, FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11 may allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices."
    },
    {
      "id": "CVE-2026-21509",
      "url": "https://spydr.io/cve/CVE-2026-21509",
      "published": "2026-01-26T18:16:38.540Z",
      "modified": "2026-06-25T05:16:53.167Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.70795,
      "epss_percentile": 0.99385,
      "exploited": true,
      "kev": {
        "added": "2026-01-26",
        "due": "2026-02-16",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft 365 Apps for Enterprise",
        "Microsoft Office 2016",
        "Microsoft Office 2019",
        "Microsoft Office LTSC 2021",
        "Microsoft Office LTSC 2024"
      ],
      "cwes": [
        "CWE-807"
      ],
      "description": "Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally."
    },
    {
      "id": "CVE-2026-24423",
      "url": "https://spydr.io/cve/CVE-2026-24423",
      "published": "2026-01-23T17:16:13.483Z",
      "modified": "2026-08-04T05:16:38.320Z",
      "score": 9.3,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "vulncheck.com",
      "epss": 0.88177,
      "epss_percentile": 0.99765,
      "exploited": true,
      "kev": {
        "added": "2026-02-05",
        "due": "2026-02-26",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "SmarterTools"
      ],
      "products": [
        "SmarterTools SmarterMail"
      ],
      "cwes": [
        "CWE-306"
      ],
      "description": "SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. The attacker could point the SmarterMail to the malicious HTTP server, which serves the malicious OS command. This command will be executed by the vulnerable application."
    },
    {
      "id": "CVE-2026-0770",
      "url": "https://spydr.io/cve/CVE-2026-0770",
      "published": "2026-01-23T04:16:04.063Z",
      "modified": "2026-07-22T05:17:08.693Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.0",
      "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "trendmicro.com",
      "epss": 0.63013,
      "epss_percentile": 0.9918,
      "exploited": true,
      "kev": {
        "added": "2026-07-21",
        "due": "2026-07-24",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Langflow"
      ],
      "products": [
        "Langflow"
      ],
      "cwes": [
        "CWE-829"
      ],
      "description": "Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the exec_globals parameter provided to the validate endpoint. The issue results from the inclusion of a resource from an untrusted control sphere. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-27325."
    },
    {
      "id": "CVE-2026-23760",
      "url": "https://spydr.io/cve/CVE-2026-23760",
      "published": "2026-01-22T15:16:55.120Z",
      "modified": "2026-08-04T05:16:38.160Z",
      "score": 9.3,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "vulncheck.com",
      "epss": 0.96544,
      "epss_percentile": 0.99881,
      "exploited": true,
      "kev": {
        "added": "2026-01-26",
        "due": "2026-02-16",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "SmarterTools"
      ],
      "products": [
        "SmarterTools SmarterMail"
      ],
      "cwes": [
        "CWE-288"
      ],
      "description": "SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a reset token when resetting system administrator accounts. An unauthenticated attacker can supply a target administrator username and a new password to reset the account, resulting in full administrative compromise of the SmarterMail instance. NOTE: SmarterMail system administrator privileges grant the ability to execute operating system commands via built-in management functionality, effectively providing administrative (SYSTEM or root) access on the underlying host."
    },
    {
      "id": "CVE-2026-20045",
      "url": "https://spydr.io/cve/CVE-2026-20045",
      "published": "2026-01-21T17:16:08.077Z",
      "modified": "2026-06-17T10:16:58.097Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.04541,
      "epss_percentile": 0.9128,
      "exploited": true,
      "kev": {
        "added": "2026-01-21",
        "due": "2026-02-11",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco Unified Communications Manager",
        "Cisco Unified Communications Manager IM and Presence Service",
        "Cisco Unity Connection"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM &amp; Presence Service (Unified CM IM&amp;P), Cisco Unity Connection, and Cisco Webex Calling Dedicated Instance could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device.&nbsp; This vulnerability is due to improper validation of user-supplied input in HTTP requests. An attacker could exploit this vulnerability by sending a sequence of crafted HTTP requests to the web-based management interface of an affected device. A successful exploit could allow the attacker to obtain user-level access to the underlying operating system and then elevate privileges to root.&nbsp; Note: Cisco has assigned this security advisory a Security Impact Rating (SIR) of Critical rather than High as the score indicates. The reason is that exploitation of this vulnerability could result in an attacker elevating privileges to root."
    },
    {
      "id": "CVE-2026-24061",
      "url": "https://spydr.io/cve/CVE-2026-24061",
      "published": "2026-01-21T07:16:01.597Z",
      "modified": "2026-09-30T11:47:02.427Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "mitre.org",
      "epss": 0.98984,
      "epss_percentile": 0.9993,
      "exploited": true,
      "kev": {
        "added": "2026-01-26",
        "due": "2026-02-16",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "GNU"
      ],
      "products": [
        "GNU Inetutils"
      ],
      "cwes": [
        "CWE-88"
      ],
      "description": "telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a \"-f root\" value for the USER environment variable."
    },
    {
      "id": "CVE-2026-21962",
      "url": "https://spydr.io/cve/CVE-2026-21962",
      "published": "2026-01-20T22:15:59.110Z",
      "modified": "2026-08-25T04:18:11.067Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N",
      "score_source": "oracle.com",
      "epss": 0.73192,
      "epss_percentile": 0.99447,
      "exploited": true,
      "kev": {
        "added": "2026-08-24",
        "due": "2026-08-27",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Oracle Corporation"
      ],
      "products": [
        "Oracle Corporation Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in"
      ],
      "cwes": [
        "CWE-284"
      ],
      "description": "Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in. While the vulnerability is in Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data. Note: Affected version for Weblogic Server Proxy Plug-in for IIS is 12.2.1.4.0 only. CVSS 3.1 Base Score 10.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N)."
    },
    {
      "id": "CVE-2026-20963",
      "url": "https://spydr.io/cve/CVE-2026-20963",
      "published": "2026-01-13T18:16:24.260Z",
      "modified": "2026-06-17T10:18:07.473Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.29582,
      "epss_percentile": 0.98144,
      "exploited": true,
      "kev": {
        "added": "2026-03-18",
        "due": "2026-03-21",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft SharePoint Enterprise Server 2016",
        "Microsoft SharePoint Server 2019",
        "Microsoft SharePoint Server Subscription Edition"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network."
    },
    {
      "id": "CVE-2026-20805",
      "url": "https://spydr.io/cve/CVE-2026-20805",
      "published": "2026-01-13T18:16:07.023Z",
      "modified": "2026-07-30T21:16:56.810Z",
      "score": 5.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "microsoft.com",
      "epss": 0.07203,
      "epss_percentile": 0.94132,
      "exploited": true,
      "kev": {
        "added": "2026-01-13",
        "due": "2026-02-03",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 23H2",
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows 11 Version 25H2",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)",
        "Microsoft Windows Server 2025",
        "Microsoft Windows Server 2025 (Server Core installation)"
      ],
      "cwes": [
        "CWE-200"
      ],
      "description": "Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally."
    },
    {
      "id": "CVE-2025-25249",
      "url": "https://spydr.io/cve/CVE-2025-25249",
      "published": "2026-01-13T17:15:56.910Z",
      "modified": "2026-09-10T12:47:59.933Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.03859,
      "epss_percentile": 0.89856,
      "exploited": true,
      "kev": {
        "added": "2026-09-09",
        "due": "2026-09-12",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Fortinet",
        "Siemens"
      ],
      "products": [
        "Fortinet FortiSwitchManager",
        "Fortinet FortiOS",
        "Siemens RUGGEDCOM APE1808"
      ],
      "cwes": [
        "CWE-122",
        "CWE-787"
      ],
      "description": "A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets"
    },
    {
      "id": "CVE-2025-66376",
      "url": "https://spydr.io/cve/CVE-2025-66376",
      "published": "2026-01-05T15:15:44.903Z",
      "modified": "2026-09-30T23:10:00.237Z",
      "score": 6.1,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.20227,
      "epss_percentile": 0.97401,
      "exploited": true,
      "kev": {
        "added": "2026-03-18",
        "due": "2026-04-01",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Zimbra"
      ],
      "products": [
        "Zimbra Collaboration"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message."
    },
    {
      "id": "CVE-2025-52691",
      "url": "https://spydr.io/cve/CVE-2025-52691",
      "published": "2025-12-29T03:15:42.837Z",
      "modified": "2026-06-17T09:36:54.733Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "CNA",
      "epss": 0.85655,
      "epss_percentile": 0.9972,
      "exploited": true,
      "kev": {
        "added": "2026-01-26",
        "due": "2026-02-16",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "SmarterTools"
      ],
      "products": [
        "SmarterTools SmarterMail"
      ],
      "cwes": [
        "CWE-434"
      ],
      "description": "Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution."
    },
    {
      "id": "CVE-2025-68645",
      "url": "https://spydr.io/cve/CVE-2025-68645",
      "published": "2025-12-22T18:16:17.070Z",
      "modified": "2026-06-17T09:59:22.500Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.48873,
      "epss_percentile": 0.98846,
      "exploited": true,
      "kev": {
        "added": "2026-01-22",
        "due": "2026-02-12",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "synacor"
      ],
      "products": [
        "synacor zimbra collaboration suite"
      ],
      "cwes": [
        "CWE-98"
      ],
      "description": "A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper handling of user-supplied request parameters in the RestFilter servlet. An unauthenticated remote attacker can craft requests to the /h/rest endpoint to influence internal request dispatching, allowing inclusion of arbitrary files from the WebRoot directory."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
