CISA KEV
CVE-2026-21509: Microsoft Office OLE security-feature bypass
Opening a malicious Office file can bypass OLE protections; Preview Pane is excluded. Available edition-specific updates supersede old pending-patch wording, but conflicting registry instructions remain unresolved and service-side protection requires restarting Office applications.
CVE-2025-34026: Versa Concerto Improper Authentication Vulnerability
Versa Concerto's Traefik authentication bypass can expose administrative Actuator endpoints, heap dumps and trace logs. For 12.1.2, verify the dated hotfix rather than the version alone; patching cannot undo sensitive data already disclosed.
CVE-2026-20045: Cisco Unified Communications Products Code Injection Vulnerability
Unauthenticated HTTP requests to affected Cisco Unified Communications management interfaces can obtain operating-system user access and then root. Select the remedy for each listed product; a scheduled release date does not verify download availability.
CVE-2026-20805: Desktop Window Manager local information disclosure
An authorized local attacker can obtain a Desktop Window Manager user-mode memory section address. This disclosure does not itself establish SYSTEM access or code execution; match the January update and investigate suspected follow-on activity separately.
CVE-2025-37164: HPE OneView unauthenticated remote code execution
HPE OneView's unauthenticated code-execution flaw requires current, platform-specific remediation. Enhanced hotfix notes say earlier packages are insufficient; distinguish Synergy from standalone appliances and do not treat an old hotfix record as completed protection.
CVE-2009-0556: Legacy PowerPoint file code execution
A crafted file can corrupt memory and execute code when opened in affected legacy PowerPoint versions, using the logged-on user's rights. Match this CVE's specific products rather than the whole bulletin, and migrate unsupported Office.
CVE-2026-21525: Windows Remote Access Connection Manager denial of service
Windows RasMan's NULL-pointer flaw permits local denial of service, not remote code execution. Preserve service-crash context and apply the matching Windows update; restarting the service may restore availability without repairing the vulnerable code.
CVE-2026-21519: Desktop Window Manager local privilege escalation
Desktop Window Manager type confusion can elevate an authorized local attacker to SYSTEM. Use this CVE's Windows update mapping and review privilege transitions; the flaw is distinct from DWM's separate information-disclosure issue.
CVE-2026-21514: Microsoft Word OLE protection bypass
Microsoft describes Word's flaw as an OLE protection bypass requiring a malicious file to be opened; Preview Pane is excluded. CISA instead describes local privilege escalation, a source disagreement retained alongside platform-specific update guidance.
CVE-2026-21513: Windows MSHTML security-feature bypass
Opening a malicious HTML file or shortcut can bypass MSHTML security prompts and permit attacker-controlled execution. The network attack vector does not mean zero-click; preserve file-origin evidence and apply the matching Windows update.
