CISA KEV
CVE-2023-21529: Exchange Server authenticated deserialization RCE
Authenticated Exchange network calls can trigger deserialization code execution in the server-account context without requiring a user to open mail. CISA records ransomware use; match each server's cumulative-update branch and investigate separately from patch installation.
CVE-2012-1854: Legacy VBA insecure library loading RCE
Opening a legitimate Office document beside an attacker's DLL can trigger legacy VBA code execution with the user's rights. Inventory private VBE6.dll copies in third-party applications; an Office update may leave those runtimes unchanged.
CVE-2026-1340: Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
CISA reports unauthenticated code execution in Ivanti EPMM through CVE-2026-1340. Preserve appliance and off-device evidence while obtaining its release-specific fix; this notice verifies neither a fixed build nor a particular execution account.
CVE-2025-29635: D-Link DIR-823X authenticated command injection on an end-of-life router
Authenticated command injection affects the end-of-life D-Link DIR-823X. D-Link directs retirement and replacement across hardware revisions; its support page's Resolved label is not a firmware fix or evidence that an exposed router was uncompromised.
CVE-2026-33825: Microsoft Defender local privilege escalation
Defender access-control weaknesses can let an authorized local attacker gain SYSTEM privileges. Verify the Antimalware Platform update and investigate suspicious endpoint activity; CISA's later exploitation listing supersedes the original no-exploitation assessment.
CVE-2026-20133: Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
Unauthenticated SD-WAN Manager API requests can expose sensitive operating-system information. This CVE does not inherit neighboring flaws' root or overwrite impacts, nor their release exclusions; preserve API evidence and use the disclosure-specific fix guidance.
CVE-2026-42897: Exchange Outlook Web Access cross-site scripting
Crafted email can trigger JavaScript in an Exchange OWA user's browser under the stated interaction conditions, not code execution on the server. Verify applicable July security updates before removing mitigation; IE-mode clients lack the required protection.
CVE-2026-20182: Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
Crafted SD-WAN peering requests can grant high-privilege, non-root NETCONF access across vulnerable Controller, Manager and Validator deployments. Collect admin-tech evidence from every control component before upgrading; an earlier authentication-bypass update is not sufficient evidence of remediation.
CVE-2026-6973: Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability
Ivanti EPMM's input-validation flaw allows code execution by a remotely authenticated administrator. CISA reports exploitation, but this notice has no verified fixed build; review administrative activity and obtain the update for this CVE and branch.
CVE-2026-0300: PAN-OS User-ID Authentication Portal unauthenticated root RCE
PAN-OS User-ID Authentication Portal exposure can allow unauthenticated root code execution on affected PA-Series and VM-Series firewalls. Check portal and ingress-interface Response Pages settings; Prisma Access, Cloud NGFW and Panorama are outside this issue's scope.
