CISA KEV
CVE-2026-21513: Windows MSHTML security-feature bypass
Opening a malicious HTML file or shortcut can bypass MSHTML security prompts and permit attacker-controlled execution. The network attack vector does not mean zero-click; preserve file-origin evidence and apply the matching Windows update.
CVE-2026-21510: Windows Shell and SmartScreen warning bypass
A malicious link or shortcut can bypass SmartScreen and Windows Shell warnings after a user opens it. Execution may proceed without the expected prompt; update the affected Windows branch and investigate downloaded shortcuts and follow-on activity.
CVE-2026-1281: Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
Ivanti EPMM code injection can permit unauthenticated remote execution. The linked security RPM filenames do not establish package applicability; obtain the CVE-specific release instructions and investigate potential mobile-management compromise separately from installing a patch.
CVE-2026-24858: FortiCloud SSO cross-account authentication bypass
An attacker with a FortiCloud account and registered device can cross account boundaries when a vulnerable target enables FortiCloud SSO. Verify product-specific fixes and administrator activity; Fortinet's cloud-side block is not an appliance patch.
CVE-2026-1603: Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability
An alternate authentication path in Ivanti Endpoint Manager can expose specific stored credentials without authentication. This is EPM, not EPMM; the fixed build remains unverified, and updating cannot invalidate credentials already disclosed.
CVE-2023-43000: Apple WebKit use-after-free memory corruption
Malicious web content can trigger WebKit use-after-free memory corruption. Update the supported Apple OS and Safari branch, and explicitly check legacy devices for the backported fix rather than mistaking historical fixed releases for affected ranges.
CVE-2023-41974: iPhone and iPad kernel privilege escalation
An application can exploit this iPhone and iPad kernel use-after-free to execute code with kernel privileges. Install the newest supported OS update, checking the separate backport for devices unable to take a current major release.
CVE-2021-30952: Apple WebKit arbitrary code execution
Malicious web content can trigger a WebKit integer overflow and arbitrary code execution. Install supported Apple OS and Safari updates; the historical 2021 fix releases are minimums for this flaw, not current update targets.
CVE-2026-21385: Qualcomm graphics memory corruption
Qualcomm Graphics memory corruption affects devices with the specified component, not every Android phone. Match chipset and OEM firmware, obtain the manufacturer's update, and verify the patch level alongside actual component applicability.
CVE-2026-20127: Cisco Catalyst SD-WAN controller authentication bypass to fabric administration
Cisco's SD-WAN peering bypass can grant a high-privilege non-root account with NETCONF access to alter fabric configuration. Include Controller, Manager and Validator in evidence collection and updates; successful upgrading alone does not establish fabric recovery.
