CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2020-25078 Recently Added

D-Link DCS-2530L and DCS-2670L Devices Unspecified Vulnerability

Vendor: D-Link

Product: DCS-2530L and DCS-2670L Devices

Added: 2025-08-05

Due Date: 2025-08-26

Description:

D-Link DCS-2530L and DCS-2670L devices contains an unspecified vulnerability that could allow for remote administrator password disclosure. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2020-25079 Recently Added

D-Link DCS-2530L and DCS-2670L Command Injection Vulnerability

Vendor: D-Link

Product: DCS-2530L and DCS-2670L Devices

Added: 2025-08-05

Due Date: 2025-08-26

Description:

D-Link DCS-2530L and DCS-2670L devices contains a command injection vulnerability in the cgi-bin/ddns_enc.cgi. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-77

CVE-2022-40799 Recently Added

D-Link DNR-322L Download of Code Without Integrity Check Vulnerability

Vendor: D-Link

Product: DNR-322L

Added: 2025-08-05

Due Date: 2025-08-26

Description:

D-Link DNR-322L contains a download of code without integrity check vulnerability that could allow an authenticated attacker to execute OS level commands on the device. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-494

CVE-2023-2533

PaperCut NG/MF Cross-Site Request Forgery (CSRF) Vulnerability

Vendor: PaperCut

Product: NG/MF

Added: 2025-07-28

Due Date: 2025-08-18

Description:

PaperCut NG/MF contains a cross-site request forgery (CSRF) vulnerability, which, under specific conditions, could potentially enable an attacker to alter security settings or execute arbitrary code.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-352

CVE-2025-20337

Cisco Identity Services Engine Injection Vulnerability

Vendor: Cisco

Product: Identity Services Engine

Added: 2025-07-28

Due Date: 2025-08-18

Description:

Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing an attacker to exploit this vulnerability by submitting a crafted API request. Successful exploitation could allow an attacker to perform remote code execution and obtaining root privileges on an affected device.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-74

CVE-2025-20281

Cisco Identity Services Engine Injection Vulnerability

Vendor: Cisco

Product: Identity Services Engine

Added: 2025-07-28

Due Date: 2025-08-18

Description:

Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing an attacker to exploit this vulnerability by submitting a crafted API request. Successful exploitation could allow an attacker to perform remote code execution and obtaining root privileges on an affected device.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-74

CVE-2025-2775

SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability

Vendor: SysAid

Product: SysAid On-Prem

Added: 2025-07-22

Due Date: 2025-08-12

Description:

SysAid On-Prem contains an improper restriction of XML external entity reference vulnerability in the Checkin processing functionality, allowing for administrator account takeover and file read primitives.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-611

CVE-2025-2776

SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability

Vendor: SysAid

Product: SysAid On-Prem

Added: 2025-07-22

Due Date: 2025-08-12

Description:

SysAid On-Prem contains an improper restriction of XML external entity reference vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read primitives.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-611

CVE-2025-6558

Google Chromium ANGLE and GPU Improper Input Validation Vulnerability

Vendor: Google

Product: Chromium

Added: 2025-07-22

Due Date: 2025-08-12

Description:

Google Chromium contains an improper input validation vulnerability in ANGLE and GPU. This vulnerability could allow a remote attacker to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-20

CVE-2025-54309

CrushFTP Unprotected Alternate Channel Vulnerability

Vendor: CrushFTP

Product: CrushFTP

Added: 2025-07-22

Due Date: 2025-08-12

Description:

CrushFTP contains an unprotected alternate channel vulnerability. When the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via HTTPS.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-420

CVE-2025-49704

Ransomware

Microsoft SharePoint Code Injection Vulnerability

Vendor: Microsoft

Product: SharePoint

Added: 2025-07-22

Due Date: 2025-07-23

Description:

Microsoft SharePoint contains a code injection vulnerability that could allow an authorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-49706. CVE-2025-53770 is a patch bypass for CVE-2025-49704, and the updates for CVE-2025-53770 include more robust protection than those for CVE-2025-49704.

Required Action:

Disconnect public-facing versions of SharePoint Server that have reached their end-of-life (EOL) or end-of-service (EOS) to include SharePoint Server 2013 and earlier versions. For supported versions, please follow the mitigations according to CISA (URL listed below in Notes) and vendor instructions (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.

CWEs:

CWE-94

CVE-2025-49706

Ransomware

Microsoft SharePoint Improper Authentication Vulnerability

Vendor: Microsoft

Product: SharePoint

Added: 2025-07-22

Due Date: 2025-07-23

Description:

Microsoft SharePoint contains an improper authentication vulnerability that allows an authorized attacker to perform spoofing over a network. Successfully exploitation could allow an attacker to view sensitive information and make some changes to disclosed information. This vulnerability could be chained with CVE-2025-49704. CVE-2025-53771 is a patch bypass for CVE-2025-49706, and the updates for CVE-2025-53771 include more robust protection than those for CVE-2025-49706.

Required Action:

Disconnect public-facing versions of SharePoint Server that have reached their end-of-life (EOL) or end-of-service (EOS) to include SharePoint Server 2013 and earlier versions. For supported versions, please follow the mitigations according to CISA (URL listed below in Notes) and vendor instructions (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.

CWEs:

CWE-287

CVE-2025-53770

Ransomware

Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

Vendor: Microsoft

Product: SharePoint

Added: 2025-07-20

Due Date: 2025-07-21

Description:

Microsoft SharePoint Server on-premises contains a deserialization of untrusted data vulnerability that could allow an unauthorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-53771. CVE-2025-53770 is a patch bypass for CVE-2025-49704, and the updates for CVE-2025-53770 include more robust protection than those for CVE-2025-49704.

Required Action:

Disconnect public-facing versions of SharePoint Server that have reached their end-of-life (EOL) or end-of-service (EOS) to include SharePoint Server 2013 and earlier versions. For supported versions, please follow the mitigations according to CISA (URL listed below in Notes) and vendor instructions (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.

CWEs:

CWE-502

CVE-2025-25257

Fortinet FortiWeb SQL Injection Vulnerability

Vendor: Fortinet

Product: FortiWeb

Added: 2025-07-18

Due Date: 2025-08-08

Description:

Fortinet FortiWeb contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-89

CVE-2025-47812

Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerability

Vendor: Wing FTP Server

Product: Wing FTP Server

Added: 2025-07-14

Due Date: 2025-08-04

Description:

Wing FTP Server contains an improper neutralization of null byte or NUL character vulnerability that can allow injection of arbitrary Lua code into user session files. This can be used to execute arbitrary system commands with the privileges of the FTP service (root or SYSTEM by default).

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-158