CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2025-2746

Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability

Vendor: Kentico

Product: Xperience CMS

Added: 2025-10-20

Due Date: 2025-11-10

Description:

Kentico Xperience CMS contains an authentication bypass using an alternate path or channel vulnerability that could allow an attacker to control administrative objects.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-288

CVE-2025-2747

Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability

Vendor: Kentico

Product: Xperience CMS

Added: 2025-10-20

Due Date: 2025-11-10

Description:

Kentico Xperience CMS contains an authentication bypass using an alternate path or channel vulnerability that could allow an attacker to control administrative objects.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-288

CVE-2025-33073

Microsoft Windows SMB Client Improper Access Control Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2025-10-20

Due Date: 2025-11-10

Description:

Microsoft Windows SMB Client contains an improper access control vulnerability that could allow for privilege escalation. An attacker could execute a specially crafted malicious script to coerce the victim machine to connect back to the attack system using SMB and authenticate.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-284

CVE-2025-61884

Ransomware

Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability

Vendor: Oracle

Product: E-Business Suite

Added: 2025-10-20

Due Date: 2025-11-10

Description:

Oracle E-Business Suite contains a server-side request forgery (SSRF) vulnerability in the Runtime component of Oracle Configurator. This vulnerability is remotely exploitable without authentication.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-918

CVE-2025-54253

Adobe Experience Manager Forms Code Execution Vulnerability

Vendor: Adobe

Product: Experience Manager (AEM) Forms

Added: 2025-10-15

Due Date: 2025-11-05

Description:

Adobe Experience Manager Forms in JEE contains an unspecified vulnerability that allows for arbitrary code execution.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-47827

IGEL OS Use of a Key Past its Expiration Date Vulnerability

Vendor: IGEL

Product: IGEL OS

Added: 2025-10-14

Due Date: 2025-11-04

Description:

IGEL OS contains a use of a key past its expiration date vulnerability that allows for Secure Boot bypass. The igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a crafted root filesystem can be mounted from an unverified SquashFS image.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-324

CVE-2025-24990

Microsoft Windows Untrusted Pointer Dereference Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2025-10-14

Due Date: 2025-11-04

Description:

Microsoft Windows Agere Modem Driver contains an untrusted pointer dereference vulnerability that allows for privilege escalation. An attacker who successfully exploited this vulnerability could gain administrator privileges.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-822

CVE-2025-59230

Microsoft Windows Improper Access Control Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2025-10-14

Due Date: 2025-11-04

Description:

Microsoft Windows contains an improper access control vulnerability in Windows Remote Access Connection Manager which could allow an authorized attacker to elevate privileges locally.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-284

CVE-2016-7836

SKYSEA Client View Improper Authentication Vulnerability

Vendor: SKYSEA

Product: Client View

Added: 2025-10-14

Due Date: 2025-11-04

Description:

SKYSEA Client View contains an improper authentication vulnerability that allows remote code execution via a flaw in processing authentication on the TCP connection with the management console program.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-287

CVE-2021-43798

Grafana Path Traversal Vulnerability

Vendor: Grafana Labs

Product: Grafana

Added: 2025-10-09

Due Date: 2025-10-30

Description:

Grafana contains a path traversal vulnerability that could allow access to local files.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-22

CVE-2025-27915

Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability

Vendor: Synacor

Product: Zimbra Collaboration Suite (ZCS)

Added: 2025-10-07

Due Date: 2025-10-28

Description:

Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that exists in the Classic Web Client due to insufficient sanitization of HTML content in ICS files. When a user views an e-mail message containing a malicious ICS entry, its embedded JavaScript executes via an ontoggle event inside a tag. This allows an attacker to run arbitrary JavaScript within the victim's session, potentially leading to unauthorized actions such as setting e-mail filters to redirect messages to an attacker-controlled address. As a result, an attacker can perform unauthorized actions on the victim's account, including e-mail redirection and data exfiltration.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-79

CVE-2021-22555

Linux Kernel Heap Out-of-Bounds Write Vulnerability

Vendor: Linux

Product: Kernel

Added: 2025-10-06

Due Date: 2025-10-27

Description:

Linux Kernel contains a heap out-of-bounds write vulnerability that could allow an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-787

CVE-2010-3962

Microsoft Internet Explorer Uninitialized Memory Corruption Vulnerability

Vendor: Microsoft

Product: Internet Explorer

Added: 2025-10-06

Due Date: 2025-10-27

Description:

Microsoft Internet Explorer contains an uninitialized memory corruption vulnerability that could allow for remote code execution. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2021-43226

Microsoft Windows Privilege Escalation Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2025-10-06

Due Date: 2025-10-27

Description:

Microsoft Windows Common Log File System Driver contains a privilege escalation vulnerability that could allow a local, privileged attacker to bypass certain security mechanisms.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2013-3918

Microsoft Windows Out-of-Bounds Write Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2025-10-06

Due Date: 2025-10-27

Description:

Microsoft Windows contains an out-of-bounds write vulnerability in the InformationCardSigninHelper Class ActiveX control, icardie.dll. An attacker could exploit the vulnerability by constructing a specially crafted webpage. When a user views the webpage, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the current user. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.