CISA KEV

Security Notices
CVE-2026-3055: Citrix NetScaler Out-of-Bounds Read Vulnerability

NetScaler memory overread requires SAML identity-provider configuration, not the gateway prerequisite of the neighboring CVE. Match standard or FIPS/NDcPP update branches and investigate suspected disclosure separately; CISA's exploitation listing does not establish appliance compromise.

Read this guide
Security Notices
CVE-2025-53521: F5 BIG-IP APM unauthenticated remote code execution

A stack-based buffer overflow in BIG-IP APM can permit remote code execution. Match the APM configuration and release branch, install the supported fix, and follow F5's additional mitigation and compromise-review guidance.

Read this guide
Security Notices
CVE-2025-43520: Apple kernel memory write or system crash

A malicious application can exploit this Apple kernel buffer overflow to terminate the system or write kernel memory. Match the device's operating-system branch and install its supported security update.

Read this guide
Security Notices
CVE-2026-20128: Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability

Cisco now describes unauthenticated remote disclosure of an SD-WAN Manager DCA credential, while CISA retains authenticated-local prerequisites. Follow the revised vendor exposure guidance; this CVE's 20.18-and-later exclusion does not extend to neighboring flaws.

Read this guide
Security Notices
CVE-2026-20122: Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability

Read-only API credentials can let an attacker overwrite files on SD-WAN Manager and gain vmanage-user privileges. Preserve API and licensing-upload evidence while updating; a read-only role alone does not block this exploited flaw.

Read this guide
Security Notices
CVE-2026-32201: SharePoint unauthenticated spoofing vulnerability

SharePoint's exploited spoofing flaw permits unauthenticated access to some sensitive information and changes to that information. It does not establish arbitrary account takeover or code execution; match updates to each on-premises farm server.

Read this guide
Security Notices
CVE-2009-0238: Legacy Microsoft Excel file remote code execution

Opening a crafted legacy Excel file can run code with the logged-on user's rights; receiving an email alone is insufficient. Match historical Excel, Viewer and Mac updates, including paired packages where required, and replace unsupported installations.

Read this guide
Security Notices
CVE-2026-21643: Fortinet FortiClient EMS SQL Injection Vulnerability

Unauthenticated HTTP requests can exploit SQL injection on FortiClient EMS to execute code or commands. Scope the management server, not endpoint agents; this notice does not verify the fixed release for the installed branch.

Read this guide
Security Notices
CVE-2025-60710: Windows link-following privilege escalation

Improper link resolution in Host Process for Windows Tasks can elevate a local authorized attacker to SYSTEM. Microsoft's December 2025 re-release requires revised updates; November-only patch records do not establish protection against this ransomware-associated flaw.

Read this guide
Security Notices
CVE-2023-36424: Windows Common Log File System privilege escalation

Windows CLFS exploitation can elevate a local attacker from Medium to High Integrity Level; the source does not establish SYSTEM access. Use a supported superseding update, not an expired historical package, and investigate suspicious privilege transitions.

Read this guide