CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2020-9715

Adobe Acrobat Use-After-Free Vulnerability

Vendor: Adobe

Product: Acrobat

Added: 2026-04-13

Due Date: 2026-04-27

Description:

Adobe Acrobat contains a use-after-free vulnerability that allows for code execution

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-416

CVE-2026-21643

Fortinet FortiClient EMS SQL Injection Vulnerability

Vendor: Fortinet

Product: FortiClient EMS

Added: 2026-04-13

Due Date: 2026-04-16

Description:

Fortinet FortiClient EMS contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-89

CVE-2026-34621

Adobe Acrobat and Reader Prototype Pollution Vulnerability

Vendor: Adobe

Product: Acrobat and Reader

Added: 2026-04-13

Due Date: 2026-04-27

Description:

Adobe Acrobat and Reader contain a prototype pollution vulnerability that allows for arbitrary code execution.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-1321

CVE-2026-1340

Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability

Vendor: Ivanti

Product: Endpoint Manager Mobile (EPMM)

Added: 2026-04-08

Due Date: 2026-04-11

Description:

Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-94

CVE-2026-35616

Fortinet FortiClient EMS Improper Access Control Vulnerability

Vendor: Fortinet

Product: FortiClient EMS

Added: 2026-04-06

Due Date: 2026-04-09

Description:

Fortinet FortiClient EMS contains an improper access control vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-284

CVE-2026-3502

TrueConf Client Download of Code Without Integrity Check Vulnerability

Vendor: TrueConf

Product: Client

Added: 2026-04-02

Due Date: 2026-04-16

Description:

TrueConf Client contains a download of code without integrity check vulnerability. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the payload is executed or installed by the updater, this may result in arbitrary code execution in the context of the updating process or user.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-494

CVE-2026-5281

Google Dawn Use-After-Free Vulnerability

Vendor: Google

Product: Dawn

Added: 2026-04-01

Due Date: 2026-04-15

Description:

Google Dawn contains an use-after-free vulnerability that could allow a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. This vulnerability could affect multiple Chromium-based products including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-416

CVE-2026-3055

Citrix NetScaler Out-of-Bounds Read Vulnerability

Vendor: Citrix

Product: NetScaler

Added: 2026-03-30

Due Date: 2026-04-02

Description:

Citrix NetScaler ADC (formerly Citrix ADC), NetScaler Gateway (formerly Citrix Gateway) and NetScaler ADC FIPS and NDcPP contain an out-of-bounds reads vulnerability when configured as a SAML IDP leading to memory overread.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-125

CVE-2025-53521

F5 BIG-IP Stack-Based Buffer Overflow Vulnerability

Vendor: F5

Product: BIG-IP

Added: 2026-03-27

Due Date: 2026-03-30

Description:

F5 BIG-IP APM contains a stack-based buffer overflow vulnerability that could allow a threat actor to achieve remote code execution.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-121

CVE-2026-33634

Aquasecurity Trivy Embedded Malicious Code Vulnerability

Vendor: Aquasecurity

Product: Trivy

Added: 2026-03-26

Due Date: 2026-04-09

Description:

Aquasecurity Trivy contains an embedded malicious code vulnerability that could allow an attacker to gain access to everything in the CI/CD environment, including all tokens, SSH keys, cloud credentials, database passwords, and any sensitive configuration in memory.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-506

CVE-2026-33017

Langflow Code Injection Vulnerability

Vendor: Langflow

Product: Langflow

Added: 2026-03-25

Due Date: 2026-04-08

Description:

Langflow contains a code injection vulnerability that could allow building public flows without requiring authentication.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-94 CWE-95 CWE-306

CVE-2025-32432

Craft CMS Code Injection Vulnerability

Vendor: Craft CMS

Product: Craft CMS

Added: 2026-03-20

Due Date: 2026-04-03

Description:

Craft CMS contains a code injection vulnerability that allows a remote attacker to execute arbitrary code.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-94

CVE-2025-54068

Laravel Livewire Code Injection Vulnerability

Vendor: Laravel

Product: Livewire

Added: 2026-03-20

Due Date: 2026-04-03

Description:

Laravel Livewire contain a code injection vulnerability that could allow unauthenticated attackers to achieve remote command execution in specific scenarios.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-94

CVE-2025-43510

Apple Multiple Products Improper Locking Vulnerability

Vendor: Apple

Product: Multiple Products

Added: 2026-03-20

Due Date: 2026-04-03

Description:

Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain an improper locking vulnerability that could allow a malicious application to cause unexpected changes in memory shared between processes.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-667

CVE-2025-43520

Apple Multiple Products Classic Buffer Overflow Vulnerability

Vendor: Apple

Product: Multiple Products

Added: 2026-03-20

Due Date: 2026-04-03

Description:

Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain a classic buffer overflow vulnerability which could allow a malicious application to cause unexpected system termination or write kernel memory.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-120