CISA KEV

Security Notices
CVE-2009-1537: Legacy DirectShow QuickTime parsing RCE

Crafted media can exploit Microsoft's legacy DirectShow QuickTime parser and run code with the user's rights. This is not blanket exposure of Apple's QuickTime application; match the historical Windows component and replace unsupported systems.

Read this guide
Security Notices
CVE-2008-4250: Legacy Windows Server Service RPC remote code execution

The legacy Windows Server Service RPC flaw permits unauthenticated code execution on Windows 2000, XP and Server 2003; Vista and Server 2008 require authentication. Historical patching does not replace retirement or investigation of unsupported assets.

Read this guide
Security Notices
CVE-2026-20262: Cisco Catalyst SD-WAN Manager arbitrary file write

Authenticated attackers can create or overwrite files through Catalyst SD-WAN Manager path traversal. Preserve admin-tech and upload logs, install the branch-specific fix, and involve Cisco TAC when suspicious uploads or other indicators appear.

Read this guide
Security Notices
CVE-2026-10520: Ivanti Sentry OS Command Injection Vulnerability

Ivanti Sentry command injection can permit unauthenticated root access when the appliance is unmanaged and vulnerable endpoints are externally reachable. Managed access controls limit exposure but do not establish a software fix; the fixed-build mapping remains unverified.

Read this guide
Security Notices
CVE-2008-4128: Cisco IOS Cross-Site Request Forgery Vulnerability

Legacy Cisco IOS 12.4 request forgery can misuse a signed-in administrator's browser to issue commands. The linked retirement notice does not identify a fixed image; confirm a hardware-compatible supported migration and preserve management evidence.

Read this guide
Security Notices
CVE-2026-45659: SharePoint authenticated remote code execution

SharePoint code execution requires an authenticated attacker with at least Site Member permissions. CISA records ransomware-campaign use; apply edition-specific farm updates and preserve membership, IIS and endpoint evidence without assuming this farm was compromised.

Read this guide
Security Notices
CVE-2026-20230: Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability

Unified CM and Unified CM SME systems with WebDialer enabled face unauthenticated file writes that may later enable root escalation. Check actual service state, then select Cisco's update or assess temporary disablement's workflow impact.

Read this guide
Security Notices
CVE-2026-34910: UniFi OS input-validation flaw

UniFi OS input-validation failures can permit command injection from an attacker with network access. Match the exact console or server product to its fixed release, then review system and access logs for unexplained activity.

Read this guide
Security Notices
CVE-2026-34909: UniFi OS path traversal

UniFi OS path traversal can expose underlying files to an attacker with network access. Apply the product-specific update and preserve access logs; the reviewed scope does not establish arbitrary file upload or placement.

Read this guide
Security Notices
CVE-2026-34908: UniFi OS improper access control allows unauthorized system changes

UniFi OS access-control failures can allow unauthorized system changes from the network. Update the affected console or server and review its state and access logs; installing the fix does not reverse earlier changes.

Read this guide