Atlas · circumvention-stack threats
Threats to circumvention
When the gear you rely on to evade censorship gets exploited
Censorship circumvention runs on a stack of network gear and client software — VPN concentrators, firewalls, routers, browsers, and messengers. When CISA confirms one of these is being actively exploited in the wild, the activists, journalists, and at-risk users who depend on Voidly and Veil are exactly who a state adversary would target with it. This feed surfaces those exploits.
680
circumvention-stack CVEs
actively exploited, per CISA
125
ransomware-linked
known to be used in ransomware
100
shown below
newest first
How to read this. This is the U.S. CISA Known Exploited Vulnerabilities catalog, re-surfaced and filtered to the gear that matters for safe circumvention. Voidly adds the relevance filter only — it makes no independent vulnerability claim. Always verify against the linked NVD/CISA record before acting.
| CVE | Vendor / product | Vulnerability | Added |
|---|---|---|---|
| CVE-2026-104286 | FortinetFortiMail | Fortinet FortiMail Path Traversal VulnerabilityFortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests. | 2026-10-01 |
| CVE-2026-76504 | CiscoCatalyst SD-WAN Manager | Cisco Catalyst SD-WAN Manager Hex Encoding VulnerabilityCisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP request. | 2026-09-30 |
| CVE-2026-86950 | AppleMultiple Products | Apple Multiple Products Out-of-Bounds Write VulnerabilityApple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution. | 2026-09-29 |
| CVE-2026-88772 | CitrixNetScaler | Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer VulnerabilityCitrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial of service | 2026-09-27 |
| CVE-2026-88771 | CitrixNetScaler | Citrix NetScaler Improper Input Validation VulnerabilityCitrix NetScaler ADC and NetScaler Gateway contain an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands. | 2026-09-27 |
| CVE-2026-67279 | MikroTikRouterOS | Mikrotik RouterOS Improper Enforcement of Behavioral Workflow VulnerabilityMikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060. | 2026-09-25 |
| CVE-2026-65660 | MicrosoftSharePoint | Microsoft SharePoint Code Injection VulnerabilityMicrosoft SharePoint contains a code injection vulnerability which could allow an authorized attacker to execute code over a network. | 2026-09-25 |
| CVE-2026-94127 | F5BIG-IP APM | F5 BIG-IP APM Heap-based Buffer Overflow VulnerabilityF5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unauthenticated attacker to perform remote code execution. | 2026-09-22 |
| CVE-2026-93616 | Check PointMultiple Products | Check Point Multiple Products Path Traversal VulnerabilityCheck Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent contain a path traversal vulnerability that allows an unauthenticated attacker to upload and execute arbitrary scripts. | 2026-09-22 |
| CVE-2026-85102 | Check PointMultiple Products | Check Point Multiple Products Improper Certificate Validation VulnerabilityCheck Point Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN contain an improper certificate validation vulnerability which could allow an unauthenticated remote attacker to execute arbitrary code on the Gateway. | 2026-09-22 |
| CVE-2026-7273 | ZyxelGS1900 Series Switches | Zyxel GS1900 Series Switches Stack-Based Buffer Overflow VulnerabilityZyxel GS1900 series switches contain a stack-based buffer overflow vulnerability in the CGI program which could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request. | 2026-09-21 |
| CVE-2026-76460 | CiscoIdentity Services Engine | Cisco Identity Services Engine Incorrect Use of Privileged APIs VulnerabilityCisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface. | 2026-09-16 |
| CVE-2026-58704 | GooglePixel | Google Pixel Improper Authorization VulnerabilityGoogle Pixel devices contain an improper authorization vulnerability in the cellular modem. A logic error may allow an attacker to bypass permission checks and escalate privileges. | 2026-09-16 |
| CVE-2026-76461 | CiscoSecure Email Gateway | Cisco Secure Email Gateway SQL Injection VulnerabilityCisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. | 2026-09-14 |
| CVE-2026-86060 | MikroTikRouterOS | MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command VulnerabilityMikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacked to change the trusted RouterOS policy mask, leading to privilege escalation. | 2026-09-10 |
| CVE-2026-67277 | MikroTikRouterOS | MikroTik RouterOS Missing Authentication for Critical Function VulnerabilityMikroTik RouterOS contains a missing authenticaion for critical function vulnerability which allows kernel memory disclosure and denial of service in the btest service. | 2026-09-10 |
| CVE-2026-87491 | GoogleChromium V8 | Google Chromium V8 Out of Bounds Write VulnerabilityGoogle Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | 2026-09-09 |
| CVE-2026-20079 | CiscoSecure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementCRITICAL 10 | Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel VulnerabilityCisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication Bypass using an alternate path or channel vulnerability that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. | 2026-09-09 |
| CVE-2026-19490 | CitrixNetScaler | Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel VulnerabilityCitrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy), an unauthenticated remote threat actor may be able to bypass authentication. | 2026-09-09 |
| CVE-2025-25249 | FortinetMultiple ProductsHIGH 8.1 | Fortinet Multiple Products Heap-based Buffer Overflow VulnerabilityFortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets. | 2026-09-09 |
| CVE-2026-85880 | MicrosoftWindows | Microsoft Windows Heap-Based Buffer Overflow VulnerabilityMicrosoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally. | 2026-09-08 |
| CVE-2026-81963 | MicrosoftWindows | Microsoft Windows Link Following VulnerabilityMicrosoft Windows Update Stack contains a link following vulnerability that allows a local attacker to escalate privileges locally up to SYSTEM. | 2026-09-08 |
| CVE-2026-85046 | GoogleChromium V8 | Google Chromium V8 Type Confusion VulnerabilityGoogle Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | 2026-09-04 |
| CVE-2026-83549 | SonicWallSMA1000 Appliances | SonicWall SMA1000 Appliances OS Command Injection VulnerabilitySonicWall SMA1000 Appliances contains an OS command injection vulnerability that could enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution. | 2026-09-02 |
| CVE-2026-83548 | SonicWallSMA1000 Appliances | SonicWall SMA1000 Appliances Server-Side Request Forgery VulnerabilitySonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations. | 2026-09-02 |
| CVE-2026-8452 | CitrixNetScaler ADC and NetScaler Gateway | Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer VulnerabilityCitrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability which could lead to denial of service. | 2026-08-26 |
| CVE-2019-1068 | MicrosoftSQL Server | Microsoft SQL Server Remote Code Execution VulnerabilityMicrosoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine service account. | 2026-08-26 |
| CVE-2026-21962 | OracleHTTP Server and Oracle Weblogic Server Proxy Plug-inCRITICAL 10 | Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control VulnerabilityOracle HTTP Server and Oracle Weblogic Server Proxy Plug-in contain an improper access control vulnerability that can result in unauthorized creation, deletion or modification access to critical data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in accessible data. | 2026-08-24 |
| CVE-2026-65400 | ApplemacOS | Apple macOS Improper Authentication VulnerabilityApple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials. | 2026-08-18 |
| CVE-2026-55040 | MicrosoftSharePoint | Microsoft SharePoint Weak Authentication VulnerabilityMicrosoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network. | 2026-08-18 |
| CVE-2026-33824 | MicrosoftInternet Key Exchange (IKE) Service ExtensionsCRITICAL 9.8 | Microsoft Internet Key Exchange (IKE) Service Extensions Double Free VulnerabilityMicrosoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution. | 2026-08-18 |
| CVE-2026-68820 | MicrosoftWindows Ancillary Function Driver for WinSock | Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free VulnerabilityMicrosoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally. | 2026-08-11 |
| CVE-2026-20349 | CiscoSecure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) | Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection VulnerabilityCisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. | 2026-08-11 |
| CVE-2026-20316ransomware | CiscoSecure Firewall Management Center (FMC) | Cisco Secure Firewall Management Center Use of Hard-coded Password VulnerabilityCisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. | 2026-07-29 |
| CVE-2025-68686 | FortinetFortiOSMEDIUM 5.9 | Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor VulnerabilityFortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level. | 2026-07-27 |
| CVE-2026-50522 | MicrosoftSharePoint | Microsoft SharePoint Deserialization of Untrusted Data Vulnerability Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network. | 2026-07-22 |
| CVE-2026-16232 | Check PointSmartConsole | Check Point SmartConsole Improper Authentication VulnerabilityCheck Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. | 2026-07-22 |
| CVE-2026-58644 | MicrosoftSharePoint | Microsoft SharePoint Deserialization of Untrusted Data VulnerabilityMicrosoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network. | 2026-07-16 |
| CVE-2026-39808 | FortinetFortiSandboxCRITICAL 9.8 | Fortinet FortiSandbox OS Command Injection VulnerabilityFortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests. | 2026-07-16 |
| CVE-2026-25089 | FortinetFortiSandbox | Fortinet FortiSandbox OS Command Injection VulnerabilityFortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests. | 2026-07-16 |
| CVE-2026-56164 | MicrosoftSharePoint Server | Microsoft SharePoint Server Missing Authentication for Critical Function VulnerabilityMicrosoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network. | 2026-07-14 |
| CVE-2026-56155 | MicrosoftActive Directory Federation Services | Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally. | 2026-07-14 |
| CVE-2026-15410ransomware | SonicWallSMA1000 Appliances | SonicWall SMA1000 Appliances Code Injection VulnerabilitySonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands. | 2026-07-14 |
| CVE-2026-15409ransomware | SonicWallSMA1000 Appliances | SonicWall SMA1000 Appliances Server-Side Request Forgery VulnerabilitySonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location. | 2026-07-14 |
| CVE-2008-4128 | CiscoIOS | Cisco IOS Cross-Site Request Forgery VulnerabilityCisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI. | 2026-07-13 |
| CVE-2026-45659ransomware | MicrosoftSharePoint Server | Microsoft SharePoint Server Deserialization of Untrusted Data VulnerabilityMicrosoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network. | 2026-07-01 |
| CVE-2026-20230 | CiscoUnified Communications Manager | Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) VulnerabilityCisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) contain a server-side request forgery (SSRF) Vulnerability that could allow an unauthenticated, remote attacker to write files to the underlying operating system that could be used later to elevate to root. | 2026-06-25 |
| CVE-2026-20262 | CiscoCatalyst SD-WAN Manager | Cisco Catalyst SD-WAN Manager Directory or Path Traversal VulnerabilityCisco Catalyst SD-WAN Manager contains a directory or path traversal vulnerability that could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system. | 2026-06-15 |
| CVE-2026-10520 | IvantiSentry | Ivanti Sentry OS Command Injection VulnerabilityIvanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve root-level remote code execution. This vulnerability can be successfully exploited in cases where the Sentry appliance is in an unmanaged state with its endpoints externally reachable. The use of mTLS with EPMM or restricted HTTPS access through Neurons for MDM makes interfaces inaccessible to external actors. | 2026-06-11 |
| CVE-2026-20245 | CiscoCatalyst SD-WAN Manager | Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output VulnerabilityCisco Catalyst SD-WAN Manager formerly SD-WAN vManage contains an improper encoding or escaping of output vulnerability. This vulnerability could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system. | 2026-06-09 |
| CVE-2026-11645 | GoogleChromium V8 | Google Chromium V8 Out-of-Bounds Read and Write VulnerabilityGoogle Chromium V8 out-of-bounds read and write vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | 2026-06-09 |
| CVE-2026-50751ransomware | Check PointSecurity Gateway | Check Point Security Gateway Improper Authentication VulnerabilityCheck Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password. | 2026-06-08 |
| CVE-2026-0257ransomware | Palo Alto NetworksPAN-OS | Palo Alto Networks PAN-OS Authentication Bypass VulnerabilityPalo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection. | 2026-05-29 |
| CVE-2026-45498 | MicrosoftDefender | Microsoft Defender Denial of Service VulnerabilityMicrosoft Defender contains an unspecified vulnerability that allows for denial of service. | 2026-05-20 |
| CVE-2026-41091 | MicrosoftDefender | Microsoft Defender Link Following VulnerabilityMicrosoft Defender contains a link following vulnerability that allows an authorized attacker to elevate privileges locally. | 2026-05-20 |
| CVE-2010-0806 | MicrosoftInternet Explorer | Microsoft Internet Explorer Use-After-Free VulnerabilityMicrosoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. | 2026-05-20 |
| CVE-2010-0249 | MicrosoftInternet Explorer | Microsoft Internet Explorer Use-After-Free VulnerabilityMicrosoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. | 2026-05-20 |
| CVE-2009-1537 | MicrosoftDirectX | Microsoft DirectX NULL Byte Overwrite VulnerabilityMicrosoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitrary code via a crafted QuickTime media file. | 2026-05-20 |
| CVE-2008-4250 | MicrosoftWindows | Microsoft Windows Buffer Overflow VulnerabilityMicrosoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization. | 2026-05-20 |
| CVE-2026-42897 | MicrosoftMicrosoftHIGH 8.1 | Microsoft Exchange Server Cross-Site Scripting VulnerabilityMicrosoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context. | 2026-05-15 |
| CVE-2026-20182 | CiscoCatalyst SD-WANCRITICAL 10 | Cisco Catalyst SD-WAN Controller Authentication Bypass VulnerabilityCisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. | 2026-05-14 |
| CVE-2026-6973 | IvantiEndpoint Manager Mobile (EPMM)HIGH 7.2 | Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation VulnerabilityIvanti Endpoint Manager Mobile (EPMM) contains an improper input validation vulnerability that allows a remotely authenticated user with administrative access to achieve remote code execution. | 2026-05-07 |
| CVE-2026-0300 | Palo Alto NetworksPAN-OSCRITICAL 9.8 | Palo Alto Networks PAN-OS Out-of-bounds Write VulnerabilityPalo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. | 2026-05-06 |
| CVE-2026-32202 | MicrosoftWindowsMEDIUM 4.3 | Microsoft Windows Protection Mechanism Failure VulnerabilityMicrosoft Windows Shell contains a protection mechanism failure vulnerability that allows an unauthorized attacker to perform spoofing over a network. | 2026-04-28 |
| CVE-2025-29635 | D-LinkDIR-823XHIGH 7.2 | D-Link DIR-823X Command Injection VulnerabilityD-Link DIR-823X contains a command injection vulnerability that allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. | 2026-04-24 |
| CVE-2026-33825ransomware | MicrosoftDefenderHIGH 7.8 | Microsoft Defender Insufficient Granularity of Access Control VulnerabilityMicrosoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally. | 2026-04-22 |
| CVE-2026-20133 | CiscoCatalyst SD-WAN Manager | Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor VulnerabilityCisco Catalyst SD-WAN Manager contains an exposure of sensitive information to an unauthorized actor vulnerability that could allow remote attackers to view sensitive information on affected systems. | 2026-04-20 |
| CVE-2026-20128 | CiscoCatalyst SD-WAN Manager | Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format VulnerabilityCisco Catalyst SD-WAN Manager contains a storing passwords in a recoverable format vulnerability that allows an authenticated, local attacker to gain DCA user privileges by accessing a credential file for the DCA user on the filesystem as a low-privileged user. | 2026-04-20 |
| CVE-2026-20122 | CiscoCatalyst SD-WAN Manger | Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs VulnerabilityCisco Catalyst SD-WAN Manager contains an incorrect use of privileged APIs vulnerability due to improper file handling on the API interface of an affected system. An attacker could exploit this vulnerability by uploading a malicious file on the local file system. A successful exploit could allow the attacker to overwrite arbitrary files on the affected system and gain vmanage user privileges. | 2026-04-20 |
| CVE-2026-32201 | MicrosoftSharePoint ServerMEDIUM 6.5 | Microsoft SharePoint Server Improper Input Validation VulnerabilityMicrosoft SharePoint Server contains an improper input validation vulnerability that allows an unauthorized attacker to perform spoofing over a network. | 2026-04-14 |
| CVE-2009-0238 | MicrosoftOffice | Microsoft Office Remote Code ExecutionMicrosoft Office Excel contains a remote code execution vulnerability that could allow an attacker to take complete control of an affected system if a user opens a specially crafted Excel file that includes a malformed object. | 2026-04-14 |
| CVE-2026-21643 | FortinetFortiClient EMSCRITICAL 9.8 | Fortinet FortiClient EMS SQL Injection VulnerabilityFortinet FortiClient EMS contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests. | 2026-04-13 |
| CVE-2025-60710ransomware | MicrosoftWindowsHIGH 7.8 | Microsoft Windows Link Following VulnerabilityMicrosoft Windows contains a link following vulnerability that allows for privilege escalation | 2026-04-13 |
| CVE-2023-36424 | MicrosoftWindows | Microsoft Windows Out-of-Bounds Read VulnerabilityMicrosoft Windows Common Log File System Driver contains an out-of-bounds read vulnerability that could allow a threat actor for privileges escalation | 2026-04-13 |
| CVE-2023-21529ransomware | MicrosoftExchange Server | Microsoft Exchange Server Deserialization of Untrusted Data VulnerabilityMicrosoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution. | 2026-04-13 |
| CVE-2012-1854 | MicrosoftVisual Basic for Applications (VBA) | Microsoft Visual Basic for Applications Insecure Library Loading VulnerabilityMicrosoft Visual Basic for Applications (VBA) contains an insecure library loading vulnerability that could allow for remote code execution. | 2026-04-13 |
| CVE-2026-1340 | IvantiEndpoint Manager Mobile (EPMM)CRITICAL 9.8 | Ivanti Endpoint Manager Mobile (EPMM) Code Injection VulnerabilityIvanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution. | 2026-04-08 |
| CVE-2026-35616 | FortinetFortiClient EMSCRITICAL 9.8 | Fortinet FortiClient EMS Improper Access Control VulnerabilityFortinet FortiClient EMS contains an improper access control vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests. | 2026-04-06 |
| CVE-2026-5281 | GoogleDawnHIGH 8.8 | Google Dawn Use-After-Free VulnerabilityGoogle Dawn contains an use-after-free vulnerability that could allow a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. This vulnerability could affect multiple Chromium-based products including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | 2026-04-01 |
| CVE-2026-3055 | CitrixNetScalerCRITICAL 9.8 | Citrix NetScaler Out-of-Bounds Read VulnerabilityCitrix NetScaler ADC (formerly Citrix ADC), NetScaler Gateway (formerly Citrix Gateway) and NetScaler ADC FIPS and NDcPP contain an out-of-bounds reads vulnerability when configured as a SAML IDP leading to memory overread. | 2026-03-30 |
| CVE-2025-53521 | F5BIG-IPCRITICAL 9.8 | F5 BIG-IP Stack-Based Buffer Overflow VulnerabilityF5 BIG-IP APM contains a stack-based buffer overflow vulnerability that could allow a threat actor to achieve remote code execution. | 2026-03-27 |
| CVE-2025-43520 | AppleMultiple ProductsMEDIUM 5.5 | Apple Multiple Products Classic Buffer Overflow VulnerabilityApple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain a classic buffer overflow vulnerability which could allow a malicious application to cause unexpected system termination or write kernel memory. | 2026-03-20 |
| CVE-2025-43510 | AppleMultiple ProductsHIGH 7.8 | Apple Multiple Products Improper Locking VulnerabilityApple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain an improper locking vulnerability that could allow a malicious application to cause unexpected changes in memory shared between processes. | 2026-03-20 |
| CVE-2025-31277 | AppleMultiple ProductsHIGH 8.8 | Apple Multiple Products Buffer Overflow VulnerabilityApple Safari, iOS, watchOS, visionOS, iPadOS, macOS, and tvOS contain a buffer overflow vulnerability that could allow the processing of maliciously crafted web content which may lead to memory corruption. | 2026-03-20 |
| CVE-2026-20131ransomware | CiscoSecure Firewall Management Center (FMC)CRITICAL 10 | Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data VulnerabilityCisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain a deserialization of untrusted data vulnerability in the web-based management interface that could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device. | 2026-03-19 |
| CVE-2026-20963 | MicrosoftSharePointCRITICAL 9.8 | Microsoft SharePoint Deserialization of Untrusted Data VulnerabilityMicrosoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network. | 2026-03-18 |
| CVE-2026-3910 | GoogleChromium V8HIGH 8.8 | Google Chromium V8 Improper Restriction of Operations Within the Bounds of a Memory Buffer VulnerabilityGoogle Chromium V8 contains an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | 2026-03-13 |
| CVE-2026-3909 | GoogleSkiaHIGH 8.8 | Google Skia Out-of-Bounds Write VulnerabilityGoogle Skia contains an out-of-bounds write vulnerability that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability affects Google Chrome and ChromeOS, Android, Flutter, and possibly other products. | 2026-03-13 |
| CVE-2026-1603 | Ivanti Endpoint Manager (EPM)HIGH 8.6 | Ivanti Endpoint Manager (EPM) Authentication Bypass VulnerabilityIvanti Endpoint Manager (EPM) contains an authentication bypass using an alternate path or channel vulnerability that could allow a remote unauthenticated attacker to leak specific stored credential data. | 2026-03-09 |
| CVE-2023-43000 | AppleMultiple ProductsHIGH 8.8 | Apple Multiple products Use-After-Free VulnerabilityApple macOS, iOS, iPadOS, and Safari 16.6 contain a use-after-free vulnerability due to the processing of maliciously crafted web content that may lead to memory corruption. | 2026-03-05 |
| CVE-2023-41974 | AppleiOS and iPadOS | Apple iOS and iPadOS Use-After-Free VulnerabilityApple iOS and iPadOS contain a use-after-free vulnerability. An app may be able to execute arbitrary code with kernel privileges. | 2026-03-05 |
| CVE-2021-30952 | AppleMultiple Products | Apple Multiple Products Integer Overflow or Wraparound VulnerabilityApple tvOS, macOS, Safari, iPadOS and watchOS contain an integer overflow or wraparound vulnerability due to the processing of maliciously crafted web content that may lead to arbitrary code execution. | 2026-03-05 |
| CVE-2026-20127 | CiscoCatalyst SD-WAN Controller and Manager | Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass VulnerabilityCisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, contain an authentication bypass vulnerability could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to an affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric. | 2026-02-25 |
| CVE-2022-20775 | CiscoSD-WAN | Cisco SD-WAN Path Traversal VulnerabilityCisco SD-WAN CLI contains a path traversal vulnerability that could allow an authenticated local attacker to gain elevated privileges via improper access controls on commands within the application CLI. A successful exploit could allow the attacker to execute arbitrary commands as the root user. | 2026-02-25 |
| CVE-2026-2441 | GoogleChromiumHIGH 8.8 | Google Chromium CSS Use-After-Free VulnerabilityGoogle Chromium CSS contains a use-after-free vulnerability that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | 2026-02-17 |
| CVE-2008-0015 | MicrosoftWindows | Microsoft Windows Video ActiveX Control Remote Code Execution VulnerabilityMicrosoft Windows Video ActiveX Control contains a remote code execution vulnerability. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. | 2026-02-17 |
| CVE-2026-1731ransomware | BeyondTrustRemote Support (RS) and Privileged Remote Access (PRA)CRITICAL 9.8 | BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection VulnerabilityBeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)contain an OS command injection vulnerability. Successful exploitation could allow an unauthenticated remote attacker to execute operating system commands in the context of the site user. Successful exploitation requires no authentication or user interaction and may lead to system compromise, including unauthorized access, data exfiltration, and service disruption. | 2026-02-13 |
| CVE-2026-20700 | AppleMultiple ProductsHIGH 7.8 | Apple Multiple Buffer Overflow VulnerabilityApple iOS, macOS, tvOS, watchOS, and visionOS contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow an attacker with memory write the capability to execute arbitrary code. | 2026-02-12 |
| CVE-2024-43468 | MicrosoftConfiguration ManagerCRITICAL 9.8 | Microsoft Configuration Manager SQL Injection VulnerabilityMicrosoft Configuration Manager contains an SQL injection vulnerability. An unauthenticated attacker could exploit this vulnerability by sending specially crafted requests to the target environment which are processed in an unsafe manner enabling the attacker to execute commands on the server and/or underlying database. | 2026-02-12 |
| CVE-2026-21533 | MicrosoftWindows | Microsoft Windows Improper Privilege Management VulnerabilityMicrosoft Windows Remote Desktop Services contains an improper privilege management vulnerability that could allow an authorized attacker to elevate privileges locally. | 2026-02-10 |
Scroll to see every column.
Source & method
- Data: CISA Known Exploited Vulnerabilities catalog, refreshed continuously into the Voidly federal-data hub.
- Filter: entries whose vendor or product is part of the censorship-circumvention stack (VPN, firewall, router, gateway, browser, messaging). Pass
?all=1to the API for the unfiltered catalog. - Voidly adds the relevance filter and the RSS surface; the underlying vulnerability data and severity are CISA's. Verify each item at its NVD link before acting.