CISA KEV
CVE-2022-20775: Cisco SD-WAN authenticated local path traversal to root
Cisco SD-WAN's CLI path-traversal flaw requires authenticated local access and can grant root privileges. Inventory affected control and edge components, excluding IOS XE SD-WAN; historical fix thresholds do not establish protection from newer fabric vulnerabilities.
CVE-2008-0015: Legacy Windows Video ActiveX Control RCE
A crafted page using the Windows Video ActiveX control can execute code with the logged-on user's rights in legacy Internet Explorer. Verify the control's kill-bit protection on affected hosts, while retiring unsupported Windows systems.
CVE-2026-20700: Apple dyld arbitrary code execution in a targeted exploit chain
Apple's dyld flaw can enable code execution when an attacker already has memory-write capability. Install the supported OS update; suspected targets of the reported exploit chain need investigation beyond checking that installation succeeded.
CVE-2024-43468: Configuration Manager unauthenticated SQL injection
Unauthenticated requests can trigger commands on Configuration Manager servers or their databases. Remediation requires the revised in-console package and applicable site procedures, not merely a Windows update or the original package carrying the same KB number.
CVE-2025-43510: Apple shared-memory kernel corruption
Improper locking in the Apple kernel can let a malicious application alter memory shared between processes. Inventory each device's operating-system branch and install the matching update; this is not a separate application-package fix.
CVE-2025-31277: Apple WebKit memory corruption
Malicious web content can corrupt memory through this Apple WebKit flaw. Update the applicable operating system and Safari, checking Safari separately on the cited Mac branches; the reviewed description does not establish arbitrary code execution.
CVE-2026-20131: Cisco FMC unauthenticated Java deserialization RCE as root
Unauthenticated Java deserialization in Cisco FMC's web management interface can execute code as root. Cisco's SCC SaaS fix does not update independently managed FMC; use the Software Checker and preserve evidence before remediation.
CVE-2026-20963: SharePoint unauthenticated deserialization RCE
Microsoft's corrected SharePoint FAQ describes unauthenticated network code execution. Its March revision clarified prerequisites and scoring without changing the January update requirement; apply the applicable farm-wide fix and preserve evidence of possible earlier access.
CVE-2026-3909: Skia out-of-bounds write exploited through crafted web content
Crafted web content can trigger an out-of-bounds write in Skia. Update Chrome and check other Skia consumers through their own vendors; a fixed desktop browser does not certify Android, Flutter or embedded products as fixed.
CVE-2026-35616: FortiClient EMS unauthenticated access-control bypass to code execution
Unauthenticated crafted requests can execute code on affected FortiClient EMS servers. Check the server release and hotfix, not endpoint client versions, then follow the applicable Fortinet hotfix or supported upgrade path.
