CISA KEV

Security Notices
CVE-2022-20775: Cisco SD-WAN authenticated local path traversal to root

Cisco SD-WAN's CLI path-traversal flaw requires authenticated local access and can grant root privileges. Inventory affected control and edge components, excluding IOS XE SD-WAN; historical fix thresholds do not establish protection from newer fabric vulnerabilities.

Read this guide
Security Notices
CVE-2008-0015: Legacy Windows Video ActiveX Control RCE

A crafted page using the Windows Video ActiveX control can execute code with the logged-on user's rights in legacy Internet Explorer. Verify the control's kill-bit protection on affected hosts, while retiring unsupported Windows systems.

Read this guide
Security Notices
CVE-2026-20700: Apple dyld arbitrary code execution in a targeted exploit chain

Apple's dyld flaw can enable code execution when an attacker already has memory-write capability. Install the supported OS update; suspected targets of the reported exploit chain need investigation beyond checking that installation succeeded.

Read this guide
Security Notices
CVE-2024-43468: Configuration Manager unauthenticated SQL injection

Unauthenticated requests can trigger commands on Configuration Manager servers or their databases. Remediation requires the revised in-console package and applicable site procedures, not merely a Windows update or the original package carrying the same KB number.

Read this guide
Security Notices
CVE-2025-43510: Apple shared-memory kernel corruption

Improper locking in the Apple kernel can let a malicious application alter memory shared between processes. Inventory each device's operating-system branch and install the matching update; this is not a separate application-package fix.

Read this guide
Security Notices
CVE-2025-31277: Apple WebKit memory corruption

Malicious web content can corrupt memory through this Apple WebKit flaw. Update the applicable operating system and Safari, checking Safari separately on the cited Mac branches; the reviewed description does not establish arbitrary code execution.

Read this guide
Security Notices
CVE-2026-20131: Cisco FMC unauthenticated Java deserialization RCE as root

Unauthenticated Java deserialization in Cisco FMC's web management interface can execute code as root. Cisco's SCC SaaS fix does not update independently managed FMC; use the Software Checker and preserve evidence before remediation.

Read this guide
Security Notices
CVE-2026-20963: SharePoint unauthenticated deserialization RCE

Microsoft's corrected SharePoint FAQ describes unauthenticated network code execution. Its March revision clarified prerequisites and scoring without changing the January update requirement; apply the applicable farm-wide fix and preserve evidence of possible earlier access.

Read this guide
Security Notices
CVE-2026-3909: Skia out-of-bounds write exploited through crafted web content

Crafted web content can trigger an out-of-bounds write in Skia. Update Chrome and check other Skia consumers through their own vendors; a fixed desktop browser does not certify Android, Flutter or embedded products as fixed.

Read this guide
Security Notices
CVE-2026-35616: FortiClient EMS unauthenticated access-control bypass to code execution

Unauthenticated crafted requests can execute code on affected FortiClient EMS servers. Check the server release and hotfix, not endpoint client versions, then follow the applicable Fortinet hotfix or supported upgrade path.

Read this guide