CVE-2026-45659
Microsoft SharePoint Server allows remote code execution via deserialization of untrusted data.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Actively-exploited / critical CVEs correlated to FedRAMP-authorized products, read by dex — the gist, which products are hit, and what to do. Sorted with those under active attack (CISA KEV) first. Click a CVE for full detail.
Microsoft SharePoint Server allows remote code execution via deserialization of untrusted data.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco Unified CM SSRF vulnerability allows unauthenticated remote attackers to write files to the OS and escalate to root.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Splunk Enterprise allows unauthenticated users to create or truncate arbitrary files via a PostgreSQL sidecar service endpoint.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco Catalyst SD-WAN Manager allows authenticated attackers to overwrite arbitrary files via path traversal.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Ivanti Sentry allows remote unauthenticated root access via command injection when appliances are unmanaged and externally reachable.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Google Chromium V8 allows remote code execution via crafted HTML pages, enabling sandbox escape and arbitrary code execution.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco SD-WAN Manager allows authenticated local attackers to execute arbitrary root commands via crafted file uploads.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Oracle WebLogic Server vulnerability CVE-2024-21182 allows unauthenticated remote access to critical data via T3/IIOP protocols.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Palo Alto Networks PAN-OS allows attackers to bypass authentication and establish unauthorized VPN connections.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Trend Micro Apex One on-premise software allows local attackers to inject malicious code into agents via a directory traversal flaw.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Internet Explorer use-after-free vulnerability enables remote code execution on EoL browsers.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Internet Explorer use-after-free vulnerability (CVE-2010-0249) allows remote code execution on EoL browsers.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Defender allows denial of service via unspecified vulnerability, impacting DIB systems reliant on endpoint protection.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows Server Service buffer overflow vulnerability (CVE-2008-4250) enabled remote code execution via crafted RPC requests.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe Acrobat and Reader exploited a heap-based buffer overflow vulnerability allowing remote code execution via crafted PDF files.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft DirectX contained a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter allowing remote code execution via crafted media files.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Defender allows local privilege escalation via link following, enabling unauthorized access to sensitive systems.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Exchange Server XSS vulnerability allows arbitrary JavaScript execution in Outlook Web Access browser context.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco Catalyst SD-WAN Controller allows unauthenticated remote attackers to bypass authentication and gain administrative privileges.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Ivanti EPMM allows remote code execution for authenticated admins via improper input validation.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Palo Alto Networks PAN-OS allows unauthenticated attackers to execute arbitrary root code via an out-of-bounds write in the User-ID Authentication Portal.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows Shell allows network spoofing via a protection mechanism failure, enabling attackers to bypass authentication and execute commands.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco Catalyst SD-WAN Manager stores passwords in a recoverable format, allowing local attackers to escalate privileges by reading credential files.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco Catalyst SD-WAN Manager allows remote attackers to view sensitive information due to an exposure vulnerability actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco Catalyst SD-WAN Manager allows attackers to overwrite arbitrary files and gain vmanage privileges via local file upload.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Office Excel contains a remote code execution vulnerability that allows attackers to take complete control of a system by opening a specially crafted file.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft SharePoint Server is actively exploited via CVE-2026-32201, enabling network spoofing that threatens DIB data integrity and trust.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows is actively exploited for privilege escalation via CVE-2025-60710, a link-following flaw enabling unauthorized admin access.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft VBA allows remote code execution via insecure library loading, actively exploited and linked to ransomware.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe Acrobat and Reader are actively exploited for arbitrary code execution via prototype pollution.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe Acrobat use-after-free vulnerability (CVE-2020-9715) enables remote code execution and was actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows Common Log File System Driver contains an out-of-bounds read vulnerability enabling privilege escalation.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Ivanti EPMM allows unauthenticated remote code execution via code injection, enabling attackers to compromise endpoint management systems without credentials.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Google Dawn (Chrome/Edge/Opera) use-after-free vulnerability enables remote code execution via crafted HTML.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Citrix NetScaler SAML IDP configuration allows out-of-bounds memory reads, enabling attackers to read sensitive data without code execution.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft SharePoint allows remote code execution via deserialization of untrusted data, confirmed as actively exploited.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Google Chromium V8 allows remote code execution via crafted HTML pages, enabling attackers to bypass sandbox protections.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Google Skia contains an actively exploited out-of-bounds write vulnerability enabling remote memory access via crafted HTML.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Ivanti Endpoint Manager allows remote unauthenticated attackers to bypass authentication and leak stored credentials via an alternate path.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Broadcom's VMware Aria Operations had an unpatched command injection flaw exploited in the wild, allowing remote code execution during product migrations.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.