CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2025-54948

Trend Micro Apex One OS Command Injection Vulnerability

Vendor: Trend Micro

Product: Apex One

Added: 2025-08-18

Due Date: 2025-09-08

Description:

Trend Micro Apex One Management Console (on-premise) contains an OS command injection vulnerability that could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-78

CVE-2025-8876

N-able N-Central Command Injection Vulnerability

Vendor: N-able

Product: N-Central

Added: 2025-08-13

Due Date: 2025-08-20

Description:

N-able N-Central contains a command injection vulnerability via improper sanitization of user input.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-8875

N-able N-Central Insecure Deserialization Vulnerability

Vendor: N-able

Product: N-Central

Added: 2025-08-13

Due Date: 2025-08-20

Description:

N-able N-Central contains an insecure deserialization vulnerability that could lead to command execution.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-8088

RARLAB WinRAR Path Traversal Vulnerability

Vendor: RARLAB

Product: WinRAR

Added: 2025-08-12

Due Date: 2025-09-02

Description:

RARLAB WinRAR contains a path traversal vulnerability affecting the Windows version of WinRAR. This vulnerability could allow an attacker to execute arbitrary code by crafting malicious archive files.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-35

CVE-2007-0671

Microsoft Office Excel Remote Code Execution Vulnerability

Vendor: Microsoft

Product: Office

Added: 2025-08-12

Due Date: 2025-09-02

Description:

Microsoft Office Excel contains a remote code execution vulnerability that can be exploited when a specially crafted Excel file is opened. This malicious file could be delivered as an email attachment or hosted on a malicious website. An attacker could leverage this vulnerability by creating a specially crafted Excel file, which, when opened, allowing an attacker to execute remote code on the affected system.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2013-3893

Microsoft Internet Explorer Resource Management Errors Vulnerability

Vendor: Microsoft

Product: Internet Explorer

Added: 2025-08-12

Due Date: 2025-09-02

Description:

Microsoft Internet Explorer contains a memory corruption vulnerability that allows for remote code execution. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-399

CVE-2020-25078

D-Link DCS-2530L and DCS-2670L Devices Unspecified Vulnerability

Vendor: D-Link

Product: DCS-2530L and DCS-2670L Devices

Added: 2025-08-05

Due Date: 2025-08-26

Description:

D-Link DCS-2530L and DCS-2670L devices contains an unspecified vulnerability that could allow for remote administrator password disclosure. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2020-25079

D-Link DCS-2530L and DCS-2670L Command Injection Vulnerability

Vendor: D-Link

Product: DCS-2530L and DCS-2670L Devices

Added: 2025-08-05

Due Date: 2025-08-26

Description:

D-Link DCS-2530L and DCS-2670L devices contains a command injection vulnerability in the cgi-bin/ddns_enc.cgi. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-77

CVE-2022-40799

D-Link DNR-322L Download of Code Without Integrity Check Vulnerability

Vendor: D-Link

Product: DNR-322L

Added: 2025-08-05

Due Date: 2025-08-26

Description:

D-Link DNR-322L contains a download of code without integrity check vulnerability that could allow an authenticated attacker to execute OS level commands on the device. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-494

CVE-2023-2533

PaperCut NG/MF Cross-Site Request Forgery (CSRF) Vulnerability

Vendor: PaperCut

Product: NG/MF

Added: 2025-07-28

Due Date: 2025-08-18

Description:

PaperCut NG/MF contains a cross-site request forgery (CSRF) vulnerability, which, under specific conditions, could potentially enable an attacker to alter security settings or execute arbitrary code.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-352

CVE-2025-20337

Cisco Identity Services Engine Injection Vulnerability

Vendor: Cisco

Product: Identity Services Engine

Added: 2025-07-28

Due Date: 2025-08-18

Description:

Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing an attacker to exploit this vulnerability by submitting a crafted API request. Successful exploitation could allow an attacker to perform remote code execution and obtaining root privileges on an affected device.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-74

CVE-2025-20281

Cisco Identity Services Engine Injection Vulnerability

Vendor: Cisco

Product: Identity Services Engine

Added: 2025-07-28

Due Date: 2025-08-18

Description:

Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing an attacker to exploit this vulnerability by submitting a crafted API request. Successful exploitation could allow an attacker to perform remote code execution and obtaining root privileges on an affected device.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-74

CVE-2025-2775

SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability

Vendor: SysAid

Product: SysAid On-Prem

Added: 2025-07-22

Due Date: 2025-08-12

Description:

SysAid On-Prem contains an improper restriction of XML external entity reference vulnerability in the Checkin processing functionality, allowing for administrator account takeover and file read primitives.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-611

CVE-2025-2776

SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability

Vendor: SysAid

Product: SysAid On-Prem

Added: 2025-07-22

Due Date: 2025-08-12

Description:

SysAid On-Prem contains an improper restriction of XML external entity reference vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read primitives.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-611

CVE-2025-6558

Google Chromium ANGLE and GPU Improper Input Validation Vulnerability

Vendor: Google

Product: Chromium

Added: 2025-07-22

Due Date: 2025-08-12

Description:

Google Chromium contains an improper input validation vulnerability in ANGLE and GPU. This vulnerability could allow a remote attacker to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-20