CISA KEV

Security Notices
CVE-2023-21529: Exchange Server authenticated deserialization RCE

Authenticated Exchange network calls can trigger deserialization code execution in the server-account context without requiring a user to open mail. CISA records ransomware use; match each server's cumulative-update branch and investigate separately from patch installation.

Read this guide
Security Notices
CVE-2012-1854: Legacy VBA insecure library loading RCE

Opening a legitimate Office document beside an attacker's DLL can trigger legacy VBA code execution with the user's rights. Inventory private VBE6.dll copies in third-party applications; an Office update may leave those runtimes unchanged.

Read this guide
Security Notices
CVE-2026-1340: Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability

CISA reports unauthenticated code execution in Ivanti EPMM through CVE-2026-1340. Preserve appliance and off-device evidence while obtaining its release-specific fix; this notice verifies neither a fixed build nor a particular execution account.

Read this guide
Security Notices
CVE-2025-29635: D-Link DIR-823X authenticated command injection on an end-of-life router

Authenticated command injection affects the end-of-life D-Link DIR-823X. D-Link directs retirement and replacement across hardware revisions; its support page's Resolved label is not a firmware fix or evidence that an exposed router was uncompromised.

Read this guide
Security Notices
CVE-2026-33825: Microsoft Defender local privilege escalation

Defender access-control weaknesses can let an authorized local attacker gain SYSTEM privileges. Verify the Antimalware Platform update and investigate suspicious endpoint activity; CISA's later exploitation listing supersedes the original no-exploitation assessment.

Read this guide
Security Notices
CVE-2026-20133: Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability

Unauthenticated SD-WAN Manager API requests can expose sensitive operating-system information. This CVE does not inherit neighboring flaws' root or overwrite impacts, nor their release exclusions; preserve API evidence and use the disclosure-specific fix guidance.

Read this guide
Security Notices
CVE-2026-42897: Exchange Outlook Web Access cross-site scripting

Crafted email can trigger JavaScript in an Exchange OWA user's browser under the stated interaction conditions, not code execution on the server. Verify applicable July security updates before removing mitigation; IE-mode clients lack the required protection.

Read this guide
Security Notices
CVE-2026-20182: Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability

Crafted SD-WAN peering requests can grant high-privilege, non-root NETCONF access across vulnerable Controller, Manager and Validator deployments. Collect admin-tech evidence from every control component before upgrading; an earlier authentication-bypass update is not sufficient evidence of remediation.

Read this guide
Security Notices
CVE-2026-6973: Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability

Ivanti EPMM's input-validation flaw allows code execution by a remotely authenticated administrator. CISA reports exploitation, but this notice has no verified fixed build; review administrative activity and obtain the update for this CVE and branch.

Read this guide
Security Notices
CVE-2026-0300: PAN-OS User-ID Authentication Portal unauthenticated root RCE

PAN-OS User-ID Authentication Portal exposure can allow unauthenticated root code execution on affected PA-Series and VM-Series firewalls. Check portal and ingress-interface Response Pages settings; Prisma Access, Cloud NGFW and Panorama are outside this issue's scope.

Read this guide