CISA KEV

Security Notices
CVE-2026-21509: Microsoft Office OLE security-feature bypass

Opening a malicious Office file can bypass OLE protections; Preview Pane is excluded. Available edition-specific updates supersede old pending-patch wording, but conflicting registry instructions remain unresolved and service-side protection requires restarting Office applications.

Read this guide
Security Notices
CVE-2025-34026: Versa Concerto Improper Authentication Vulnerability

Versa Concerto's Traefik authentication bypass can expose administrative Actuator endpoints, heap dumps and trace logs. For 12.1.2, verify the dated hotfix rather than the version alone; patching cannot undo sensitive data already disclosed.

Read this guide
Security Notices
CVE-2026-20045: Cisco Unified Communications Products Code Injection Vulnerability

Unauthenticated HTTP requests to affected Cisco Unified Communications management interfaces can obtain operating-system user access and then root. Select the remedy for each listed product; a scheduled release date does not verify download availability.

Read this guide
Security Notices
CVE-2026-20805: Desktop Window Manager local information disclosure

An authorized local attacker can obtain a Desktop Window Manager user-mode memory section address. This disclosure does not itself establish SYSTEM access or code execution; match the January update and investigate suspected follow-on activity separately.

Read this guide
Security Notices
CVE-2025-37164: HPE OneView unauthenticated remote code execution

HPE OneView's unauthenticated code-execution flaw requires current, platform-specific remediation. Enhanced hotfix notes say earlier packages are insufficient; distinguish Synergy from standalone appliances and do not treat an old hotfix record as completed protection.

Read this guide
Security Notices
CVE-2009-0556: Legacy PowerPoint file code execution

A crafted file can corrupt memory and execute code when opened in affected legacy PowerPoint versions, using the logged-on user's rights. Match this CVE's specific products rather than the whole bulletin, and migrate unsupported Office.

Read this guide
Security Notices
CVE-2026-21525: Windows Remote Access Connection Manager denial of service

Windows RasMan's NULL-pointer flaw permits local denial of service, not remote code execution. Preserve service-crash context and apply the matching Windows update; restarting the service may restore availability without repairing the vulnerable code.

Read this guide
Security Notices
CVE-2026-21519: Desktop Window Manager local privilege escalation

Desktop Window Manager type confusion can elevate an authorized local attacker to SYSTEM. Use this CVE's Windows update mapping and review privilege transitions; the flaw is distinct from DWM's separate information-disclosure issue.

Read this guide
Security Notices
CVE-2026-21514: Microsoft Word OLE protection bypass

Microsoft describes Word's flaw as an OLE protection bypass requiring a malicious file to be opened; Preview Pane is excluded. CISA instead describes local privilege escalation, a source disagreement retained alongside platform-specific update guidance.

Read this guide
Security Notices
CVE-2026-21513: Windows MSHTML security-feature bypass

Opening a malicious HTML file or shortcut can bypass MSHTML security prompts and permit attacker-controlled execution. The network attack vector does not mean zero-click; preserve file-origin evidence and apply the matching Windows update.

Read this guide