{
  "query": {
    "kev": "1",
    "page": "12"
  },
  "count": 20,
  "total": 1734,
  "page": 12,
  "limit": 20,
  "updated": {
    "cves": "2026-10-06T08:45:32.201Z",
    "kev": "2026-10-06T08:44:32.120Z",
    "epss": "2026-10-06T06:57:27.860Z",
    "breaches": "2026-10-06T06:45:27.314Z",
    "posts": "2026-10-06T08:45:32.201Z"
  },
  "links": {
    "web": "https://spydr.io/threats?kev=1&page=12",
    "next": "https://spydr.io/threats.json?kev=1&page=13"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2024-43468",
      "url": "https://spydr.io/cve/CVE-2024-43468",
      "published": "2024-10-08T18:15:09.537Z",
      "modified": "2026-06-17T07:51:06.577Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.80912,
      "epss_percentile": 0.99622,
      "exploited": true,
      "kev": {
        "added": "2026-02-12",
        "due": "2026-03-05",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Configuration Manager"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "Microsoft Configuration Manager Remote Code Execution Vulnerability"
    },
    {
      "id": "CVE-2026-21533",
      "url": "https://spydr.io/cve/CVE-2026-21533",
      "published": "2026-02-10T18:16:35.790Z",
      "modified": "2026-06-17T10:18:47.933Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.04125,
      "epss_percentile": 0.90503,
      "exploited": true,
      "kev": {
        "added": "2026-02-10",
        "due": "2026-03-03",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows 11 Version 25H2",
        "Microsoft Windows 11 version 26H1",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)",
        "Microsoft Windows Server 2025"
      ],
      "cwes": [
        "CWE-269"
      ],
      "description": "Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally."
    },
    {
      "id": "CVE-2026-21525",
      "url": "https://spydr.io/cve/CVE-2026-21525",
      "published": "2026-02-10T18:16:34.930Z",
      "modified": "2026-06-17T10:18:46.993Z",
      "score": 6.2,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "score_source": "microsoft.com",
      "epss": 0.04797,
      "epss_percentile": 0.91682,
      "exploited": true,
      "kev": {
        "added": "2026-02-10",
        "due": "2026-03-03",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows 11 Version 25H2",
        "Microsoft Windows 11 version 26H1",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)",
        "Microsoft Windows Server 2025"
      ],
      "cwes": [
        "CWE-476"
      ],
      "description": "Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally."
    },
    {
      "id": "CVE-2026-21519",
      "url": "https://spydr.io/cve/CVE-2026-21519",
      "published": "2026-02-10T18:16:34.417Z",
      "modified": "2026-06-17T10:18:46.287Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.02462,
      "epss_percentile": 0.83912,
      "exploited": true,
      "kev": {
        "added": "2026-02-10",
        "due": "2026-03-03",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows 11 Version 25H2",
        "Microsoft Windows 11 version 26H1",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)",
        "Microsoft Windows Server 2025",
        "Microsoft Windows Server 2025 (Server Core installation)"
      ],
      "cwes": [
        "CWE-843"
      ],
      "description": "Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to elevate privileges locally."
    },
    {
      "id": "CVE-2026-21514",
      "url": "https://spydr.io/cve/CVE-2026-21514",
      "published": "2026-02-10T18:16:33.803Z",
      "modified": "2026-06-17T10:18:45.733Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.01578,
      "epss_percentile": 0.74639,
      "exploited": true,
      "kev": {
        "added": "2026-02-10",
        "due": "2026-03-03",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft 365 Apps for Enterprise",
        "Microsoft Office LTSC 2021",
        "Microsoft Office LTSC 2024",
        "Microsoft Office LTSC for Mac 2021",
        "Microsoft Office LTSC for Mac 2024"
      ],
      "cwes": [
        "CWE-807"
      ],
      "description": "Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally."
    },
    {
      "id": "CVE-2026-21513",
      "url": "https://spydr.io/cve/CVE-2026-21513",
      "published": "2026-02-10T18:16:33.643Z",
      "modified": "2026-06-17T10:18:45.540Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.15642,
      "epss_percentile": 0.96754,
      "exploited": true,
      "kev": {
        "added": "2026-02-10",
        "due": "2026-03-03",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows 11 Version 25H2",
        "Microsoft Windows 11 version 26H1",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)",
        "Microsoft Windows Server 2025"
      ],
      "cwes": [
        "CWE-693"
      ],
      "description": "Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network."
    },
    {
      "id": "CVE-2026-21510",
      "url": "https://spydr.io/cve/CVE-2026-21510",
      "published": "2026-02-10T18:16:33.170Z",
      "modified": "2026-06-17T10:18:45.110Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.24226,
      "epss_percentile": 0.97797,
      "exploited": true,
      "kev": {
        "added": "2026-02-10",
        "due": "2026-03-03",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows 11 Version 25H2",
        "Microsoft Windows 11 version 26H1",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)",
        "Microsoft Windows Server 2025"
      ],
      "cwes": [
        "CWE-693"
      ],
      "description": "Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network."
    },
    {
      "id": "CVE-2026-24423",
      "url": "https://spydr.io/cve/CVE-2026-24423",
      "published": "2026-01-23T17:16:13.483Z",
      "modified": "2026-08-04T05:16:38.320Z",
      "score": 9.3,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "vulncheck.com",
      "epss": 0.88177,
      "epss_percentile": 0.99765,
      "exploited": true,
      "kev": {
        "added": "2026-02-05",
        "due": "2026-02-26",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "SmarterTools"
      ],
      "products": [
        "SmarterTools SmarterMail"
      ],
      "cwes": [
        "CWE-306"
      ],
      "description": "SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. The attacker could point the SmarterMail to the malicious HTTP server, which serves the malicious OS command. This command will be executed by the vulnerable application."
    },
    {
      "id": "CVE-2025-11953",
      "url": "https://spydr.io/cve/CVE-2025-11953",
      "published": "2025-11-03T17:15:32.677Z",
      "modified": "2026-06-17T08:31:28.530Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "jfrog.com",
      "epss": 0.9398,
      "epss_percentile": 0.99845,
      "exploited": true,
      "kev": {
        "added": "2026-02-05",
        "due": "2026-02-26",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "react-native-community"
      ],
      "products": [
        "react-native-community react native community cli"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpoint that is vulnerable to OS command injection. This allows unauthenticated network attackers to send a POST request to the server and run arbitrary executables. On Windows, the attackers can also execute arbitrary shell commands with fully controlled arguments."
    },
    {
      "id": "CVE-2025-40551",
      "url": "https://spydr.io/cve/CVE-2025-40551",
      "published": "2026-01-28T08:16:02.273Z",
      "modified": "2026-06-17T09:21:44.487Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "solarwinds.com",
      "epss": 0.84181,
      "epss_percentile": 0.99691,
      "exploited": true,
      "kev": {
        "added": "2026-02-03",
        "due": "2026-02-06",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "SolarWinds"
      ],
      "products": [
        "SolarWinds Web Help Desk"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication."
    },
    {
      "id": "CVE-2025-64328",
      "url": "https://spydr.io/cve/CVE-2025-64328",
      "published": "2025-11-07T04:15:47.397Z",
      "modified": "2026-06-17T15:45:21.527Z",
      "score": 8.6,
      "severity": "high",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "github.com",
      "epss": 0.84618,
      "epss_percentile": 0.99699,
      "exploited": true,
      "kev": {
        "added": "2026-02-03",
        "due": "2026-02-24",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "FreePBX"
      ],
      "products": [
        "FreePBX filestore"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions 17.0.2.36 and above before 17.0.3, the filestore module within the Administrative interface is vulnerable to a post-authentication command injection by an authenticated known user via the testconnection -> check_ssh_connect() function. An attacker can leverage this vulnerability to obtain remote access to the system as an asterisk user. This issue is fixed in version 17.0.3."
    },
    {
      "id": "CVE-2021-39935",
      "url": "https://spydr.io/cve/CVE-2021-39935",
      "published": "2021-12-13T16:15:09.367Z",
      "modified": "2026-06-17T04:04:27.387Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.35649,
      "epss_percentile": 0.98421,
      "exploited": true,
      "kev": {
        "added": "2026-02-03",
        "due": "2026-02-24",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "GitLab"
      ],
      "products": [
        "GitLab"
      ],
      "cwes": [
        "CWE-918"
      ],
      "description": "An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Unauthorized external users could perform Server Side Requests via the CI Lint API"
    },
    {
      "id": "CVE-2019-19006",
      "url": "https://spydr.io/cve/CVE-2019-19006",
      "published": "2019-11-21T18:15:11.993Z",
      "modified": "2026-06-17T15:45:04.213Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.55946,
      "epss_percentile": 0.99022,
      "exploited": true,
      "kev": {
        "added": "2026-02-03",
        "due": "2026-02-24",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "sangoma"
      ],
      "products": [
        "sangoma freepbx"
      ],
      "cwes": [
        "CWE-287"
      ],
      "description": "Sangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below have Incorrect Access Control."
    },
    {
      "id": "CVE-2026-1281",
      "url": "https://spydr.io/cve/CVE-2026-1281",
      "published": "2026-01-29T22:15:53.140Z",
      "modified": "2026-06-17T10:15:26.787Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "CNA",
      "epss": 0.98688,
      "epss_percentile": 0.99924,
      "exploited": true,
      "kev": {
        "added": "2026-01-29",
        "due": "2026-02-01",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Ivanti"
      ],
      "products": [
        "Ivanti Endpoint Manager Mobile"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution."
    },
    {
      "id": "CVE-2026-24858",
      "url": "https://spydr.io/cve/CVE-2026-24858",
      "published": "2026-01-27T20:16:24.477Z",
      "modified": "2026-06-17T10:23:43.040Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "fortinet.com",
      "epss": 0.85796,
      "epss_percentile": 0.99723,
      "exploited": true,
      "kev": {
        "added": "2026-01-27",
        "due": "2026-01-30",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Fortinet",
        "Siemens"
      ],
      "products": [
        "Fortinet FortiWeb",
        "Fortinet FortiNAC-F",
        "Fortinet FortiOS",
        "Fortinet FortiAnalyzer",
        "Fortinet FortiProxy",
        "Fortinet FortiManager",
        "Siemens RUGGEDCOM APE1808"
      ],
      "cwes": [
        "CWE-288"
      ],
      "description": "An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiManager 7.6.0 through 7.6.5, FortiManager 7.4.0 through 7.4.9, FortiManager 7.2.0 through 7.2.11, FortiManager 7.0.0 through 7.0.15, FortiNAC-F 7.6.3 through 7.6.5, FortiOS 7.6.0 through 7.6.5, FortiOS 7.4.0 through 7.4.10, FortiOS 7.2.0 through 7.2.12, FortiOS 7.0.0 through 7.0.18, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4.0 through 7.4.12, FortiProxy 7.2.0 through 7.2.15, FortiProxy 7.0.0 through 7.0.22, FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11 may allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices."
    },
    {
      "id": "CVE-2026-21509",
      "url": "https://spydr.io/cve/CVE-2026-21509",
      "published": "2026-01-26T18:16:38.540Z",
      "modified": "2026-06-25T05:16:53.167Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.70795,
      "epss_percentile": 0.99385,
      "exploited": true,
      "kev": {
        "added": "2026-01-26",
        "due": "2026-02-16",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft 365 Apps for Enterprise",
        "Microsoft Office 2016",
        "Microsoft Office 2019",
        "Microsoft Office LTSC 2021",
        "Microsoft Office LTSC 2024"
      ],
      "cwes": [
        "CWE-807"
      ],
      "description": "Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally."
    },
    {
      "id": "CVE-2026-23760",
      "url": "https://spydr.io/cve/CVE-2026-23760",
      "published": "2026-01-22T15:16:55.120Z",
      "modified": "2026-08-04T05:16:38.160Z",
      "score": 9.3,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "vulncheck.com",
      "epss": 0.96544,
      "epss_percentile": 0.99881,
      "exploited": true,
      "kev": {
        "added": "2026-01-26",
        "due": "2026-02-16",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "SmarterTools"
      ],
      "products": [
        "SmarterTools SmarterMail"
      ],
      "cwes": [
        "CWE-288"
      ],
      "description": "SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a reset token when resetting system administrator accounts. An unauthenticated attacker can supply a target administrator username and a new password to reset the account, resulting in full administrative compromise of the SmarterMail instance. NOTE: SmarterMail system administrator privileges grant the ability to execute operating system commands via built-in management functionality, effectively providing administrative (SYSTEM or root) access on the underlying host."
    },
    {
      "id": "CVE-2026-24061",
      "url": "https://spydr.io/cve/CVE-2026-24061",
      "published": "2026-01-21T07:16:01.597Z",
      "modified": "2026-09-30T11:47:02.427Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "mitre.org",
      "epss": 0.98984,
      "epss_percentile": 0.9993,
      "exploited": true,
      "kev": {
        "added": "2026-01-26",
        "due": "2026-02-16",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "GNU"
      ],
      "products": [
        "GNU Inetutils"
      ],
      "cwes": [
        "CWE-88"
      ],
      "description": "telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a \"-f root\" value for the USER environment variable."
    },
    {
      "id": "CVE-2025-52691",
      "url": "https://spydr.io/cve/CVE-2025-52691",
      "published": "2025-12-29T03:15:42.837Z",
      "modified": "2026-06-17T09:36:54.733Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "CNA",
      "epss": 0.85655,
      "epss_percentile": 0.9972,
      "exploited": true,
      "kev": {
        "added": "2026-01-26",
        "due": "2026-02-16",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "SmarterTools"
      ],
      "products": [
        "SmarterTools SmarterMail"
      ],
      "cwes": [
        "CWE-434"
      ],
      "description": "Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution."
    },
    {
      "id": "CVE-2018-14634",
      "url": "https://spydr.io/cve/CVE-2018-14634",
      "published": "2018-09-25T21:29:00.390Z",
      "modified": "2026-06-17T01:41:20.410Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.0",
      "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.14689,
      "epss_percentile": 0.96576,
      "exploited": true,
      "kev": {
        "added": "2026-01-26",
        "due": "2026-02-16",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "The Linux Foundation"
      ],
      "products": [
        "The Linux Foundation kernel"
      ],
      "cwes": [
        "CWE-190"
      ],
      "description": "An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise privileged) binary could use this flaw to escalate their privileges on the system. Kernel versions 2.6.x, 3.10.x and 4.14.x are believed to be vulnerable."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
