CISA KEV
CVE-2026-34909: UniFi OS path traversal
UniFi OS path traversal can expose underlying files to an attacker with network access. Apply the product-specific update and preserve access logs; the reviewed scope does not establish arbitrary file upload or placement.
CVE-2025-68686: Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
This FortiOS information-exposure flaw requires prior filesystem compromise through another vulnerability. Its symbolic-link persistence mechanism makes recovery distinct from updating; the reviewed notice does not establish a verified fixed-release mapping.
CVE-2026-50522: SharePoint unauthenticated remote code execution
Microsoft's SharePoint deserialization advisory conflicts on authentication prerequisites: its description says unauthenticated, while its FAQ requires Site Owner access. CISA lists exploitation; update affected farms and preserve evidence without resolving that conflict by assumption.
CVE-2026-16232: Check Point SmartConsole token bypass to full administrator
The SmartConsole flaw can give an unauthenticated attacker a full-administrator login token. Restrict management exposure and Trusted Clients, preserve evidence, and install the Jumbo Hotfix Accumulator take for the deployed Check Point branch.
CVE-2021-27137: DD-WRT Stack-Based Buffer Overflow Vulnerability
DD-WRT's exploited UPnP buffer overflow can allow unauthenticated code execution. The linked source correction does not identify a compatible router firmware image; match the hardware and build, and preserve evidence before remediation.
CVE-2026-58644: SharePoint unauthenticated deserialization RCE
Microsoft reports exploitation of this SharePoint deserialization flaw but gives conflicting authentication prerequisites. Use its CVE-specific edition mapping across the farm; neither another SharePoint fix nor the narrower FAQ establishes this exposure is resolved.
CVE-2026-39808: FortiSandbox unauthenticated command injection
Crafted HTTP requests can trigger unauthorized commands on affected FortiSandbox systems without authentication. Restrict the management path while arranging the supported update, and match the fix to the installed release branch.
CVE-2026-25089: FortiSandbox second-order command injection
CISA reports unauthenticated HTTP command injection in FortiSandbox appliances, Cloud and PaaS. Confirm who controls remediation for each deployment; this notice establishes neither a fixed appliance build nor a completed managed-service rollout.
CVE-2026-56164: SharePoint missing-authentication privilege escalation
Missing authentication in SharePoint can let an unauthorized network attacker elevate privileges. Microsoft's Moderate severity does not negate reported exploitation; update every applicable farm server and review authentication, IIS and role-change evidence.
CVE-2026-56155: AD FS local privilege escalation
An authorized local attacker can exploit AD FS access controls to gain administrator privileges. Match each federation node to its Windows update; patch completion alone cannot establish that identity-service credentials and trusts remain safe.
