CISA KEV
CVE-2026-3055: Citrix NetScaler Out-of-Bounds Read Vulnerability
NetScaler memory overread requires SAML identity-provider configuration, not the gateway prerequisite of the neighboring CVE. Match standard or FIPS/NDcPP update branches and investigate suspected disclosure separately; CISA's exploitation listing does not establish appliance compromise.
CVE-2025-53521: F5 BIG-IP APM unauthenticated remote code execution
A stack-based buffer overflow in BIG-IP APM can permit remote code execution. Match the APM configuration and release branch, install the supported fix, and follow F5's additional mitigation and compromise-review guidance.
CVE-2025-43520: Apple kernel memory write or system crash
A malicious application can exploit this Apple kernel buffer overflow to terminate the system or write kernel memory. Match the device's operating-system branch and install its supported security update.
CVE-2026-20128: Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability
Cisco now describes unauthenticated remote disclosure of an SD-WAN Manager DCA credential, while CISA retains authenticated-local prerequisites. Follow the revised vendor exposure guidance; this CVE's 20.18-and-later exclusion does not extend to neighboring flaws.
CVE-2026-20122: Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability
Read-only API credentials can let an attacker overwrite files on SD-WAN Manager and gain vmanage-user privileges. Preserve API and licensing-upload evidence while updating; a read-only role alone does not block this exploited flaw.
CVE-2026-32201: SharePoint unauthenticated spoofing vulnerability
SharePoint's exploited spoofing flaw permits unauthenticated access to some sensitive information and changes to that information. It does not establish arbitrary account takeover or code execution; match updates to each on-premises farm server.
CVE-2009-0238: Legacy Microsoft Excel file remote code execution
Opening a crafted legacy Excel file can run code with the logged-on user's rights; receiving an email alone is insufficient. Match historical Excel, Viewer and Mac updates, including paired packages where required, and replace unsupported installations.
CVE-2026-21643: Fortinet FortiClient EMS SQL Injection Vulnerability
Unauthenticated HTTP requests can exploit SQL injection on FortiClient EMS to execute code or commands. Scope the management server, not endpoint agents; this notice does not verify the fixed release for the installed branch.
CVE-2025-60710: Windows link-following privilege escalation
Improper link resolution in Host Process for Windows Tasks can elevate a local authorized attacker to SYSTEM. Microsoft's December 2025 re-release requires revised updates; November-only patch records do not establish protection against this ransomware-associated flaw.
CVE-2023-36424: Windows Common Log File System privilege escalation
Windows CLFS exploitation can elevate a local attacker from Medium to High Integrity Level; the source does not establish SYSTEM access. Use a supported superseding update, not an expired historical package, and investigate suspicious privilege transitions.
