Known exploited vulnerabilities
Vulnerabilities CISA has confirmed are being exploited, newest additions first — with the remediation deadline federal agencies must meet.
| Score | CVE | Affected | EPSS | Added to KEV |
|---|---|---|---|---|
| 10.0 critical | CVE-2025-32975 KEV | quest kace systems management appliance Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) contains an authentication bypass vulnerability that allows attackers to impersonate legitimate users without valid credentials. The vulnerability exists in the SSO authentication handling mechanism and can lead to complete administrative takeover. | 2.5% | 20 Apr 2026 |
| 6.1 medium | CVE-2025-48700 KEV | synacor zimbra collaboration suite An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross-Site Scripting (XSS) vulnerability in the Zimbra Classic UI allows attackers to execute arbitrary JavaScript within the user's session, potentially leading to unauthorized access to sensitive information. This issue arises from insufficient sanitization of HTML content, specifically involving crafted tag structures and attribute values that include an @import directive and other script injection vectors. The vulnerability is triggered when a user views a crafted e-mail message in the Classic UI, requiring no additional user interaction. | 1.7% | 20 Apr 2026 |
| 7.2 high | CVE-2025-2749 KEV | Kentico Xperience An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arbitrary data to path relative locations. This results in path traversal and arbitrary file upload, including content that can be executed server side leading to remote code execution.This issue affects Kentico Xperience through 13.0.178. | 4.1% | 20 Apr 2026 |
| 7.3 high | CVE-2024-27199 KEV | JetBrains TeamCity In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible | >99% | 20 Apr 2026 |
| 7.5 high | CVE-2023-27351 KEV | PaperCut NG This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SecurityRequestFilter class. The issue results from improper implementation of the authentication algorithm. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-19226. | 78% | 20 Apr 2026 |
| 8.8 high | CVE-2026-34197 KEV | Apache Software Foundation Apache ActiveMQ Broker Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ MBeans (org.apache.activemq:*), including BrokerService.addNetworkConnector(String) and BrokerService.addConnector(String). An authenticated attacker can invoke these operations with a crafted discovery URI that triggers the VM transport's brokerConfig parameter to load a remote Spring XML application context using ResourceXmlApplicationContext. Because Spring's ResourceXmlApplicationContext instantiates all singleton beans before the BrokerService validates the configuration, arbitrary code execution occurs on the broker's JVM through bean factory methods such as Runtime.exec(). This issue affects Apache ActiveMQ Broker: before 5.19.4, from 6.0.0 before 6.2.3; Apache ActiveMQ All: before 5.19.4, from 6.0.0 before 6.2.3; Apache ActiveMQ: before 5.19.4, from 6.0.0 before 6.2.3. Users are recommended to upgrade to version 5.19.4 or 6.2.3, which fixes the issue | 15% | 16 Apr 2026 |
| 6.5 medium | CVE-2026-32201 KEV | Microsoft SharePoint Enterprise Server 2016 Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | 43% | 14 Apr 2026 |
| 8.8 high | CVE-2009-0238 KEV | microsoft excel Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer; Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1; and Excel in Microsoft Office 2004 and 2008 for Mac allow remote attackers to execute arbitrary code via a crafted Excel document that triggers an access attempt on an invalid object, as exploited in the wild in February 2009 by Trojan.Mdropper.AC. | 43% | 14 Apr 2026 |
| 8.6 high | CVE-2026-34621 KEV | Adobe Acrobat DC Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | 2.2% | 13 Apr 2026 |
| 9.8 critical | CVE-2026-21643 KEV | Fortinet FortiClientEMS An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests. | 94% | 13 Apr 2026 |
| 7.8 high | CVE-2025-60710 KEV | Microsoft Windows 11 Version 24H2 Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally. | 4.6% | 13 Apr 2026 |
| 7.8 high | CVE-2023-36424 KEV | Microsoft Windows 11 version 22H3 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 12% | 13 Apr 2026 |
| 8.8 high | CVE-2023-21529 KEV | Microsoft Exchange Server 2013 Cumulative Update 23 Microsoft Exchange Server Remote Code Execution Vulnerability | 59% | 13 Apr 2026 |
| 7.8 high | CVE-2020-9715 KEV | Adobe Acrobat and Reader Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution . | 49% | 13 Apr 2026 |
| 7.8 high | CVE-2012-1854 KEV | microsoft office Untrusted search path vulnerability in VBE6.dll in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Microsoft Visual Basic for Applications (VBA); and Summit Microsoft Visual Basic for Applications SDK allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .docx file, aka "Visual Basic for Applications Insecure Library Loading Vulnerability," as exploited in the wild in July 2012. | 21% | 13 Apr 2026 |
| 9.8 critical | CVE-2026-1340 KEV | Ivanti Endpoint Manager Mobile A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution. | 99% | 8 Apr 2026 |
| 9.8 critical | CVE-2026-35616 KEV | Fortinet FortiClientEMS A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests. | 9.1% | 6 Apr 2026 |
| 7.8 high | CVE-2026-3502 KEV | TrueConf Client TrueConf Client downloads application update code and applies it without performing verification. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the payload is executed or installed by the updater, this may result in arbitrary code execution in the context of the updating process or user. | 0.33% | 2 Apr 2026 |
| 8.8 high | CVE-2026-5281 KEV | Google Chrome Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) | 0.70% | 1 Apr 2026 |
| 9.3 critical | CVE-2026-3055 KEV | NetScaler ADC Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread | 4.0% | 30 Mar 2026 |