CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2025-8875

N-able N-Central Insecure Deserialization Vulnerability

Vendor: N-able

Product: N-Central

Added: 2025-08-13

Due Date: 2025-08-20

Description:

N-able N-Central contains an insecure deserialization vulnerability that could lead to command execution.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-8088

RARLAB WinRAR Path Traversal Vulnerability

Vendor: RARLAB

Product: WinRAR

Added: 2025-08-12

Due Date: 2025-09-02

Description:

RARLAB WinRAR contains a path traversal vulnerability affecting the Windows version of WinRAR. This vulnerability could allow an attacker to execute arbitrary code by crafting malicious archive files.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-35

CVE-2007-0671

Microsoft Office Excel Remote Code Execution Vulnerability

Vendor: Microsoft

Product: Office

Added: 2025-08-12

Due Date: 2025-09-02

Description:

Microsoft Office Excel contains a remote code execution vulnerability that can be exploited when a specially crafted Excel file is opened. This malicious file could be delivered as an email attachment or hosted on a malicious website. An attacker could leverage this vulnerability by creating a specially crafted Excel file, which, when opened, allowing an attacker to execute remote code on the affected system.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2013-3893

Microsoft Internet Explorer Resource Management Errors Vulnerability

Vendor: Microsoft

Product: Internet Explorer

Added: 2025-08-12

Due Date: 2025-09-02

Description:

Microsoft Internet Explorer contains a memory corruption vulnerability that allows for remote code execution. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-399

CVE-2020-25078

D-Link DCS-2530L and DCS-2670L Devices Unspecified Vulnerability

Vendor: D-Link

Product: DCS-2530L and DCS-2670L Devices

Added: 2025-08-05

Due Date: 2025-08-26

Description:

D-Link DCS-2530L and DCS-2670L devices contains an unspecified vulnerability that could allow for remote administrator password disclosure. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2020-25079

D-Link DCS-2530L and DCS-2670L Command Injection Vulnerability

Vendor: D-Link

Product: DCS-2530L and DCS-2670L Devices

Added: 2025-08-05

Due Date: 2025-08-26

Description:

D-Link DCS-2530L and DCS-2670L devices contains a command injection vulnerability in the cgi-bin/ddns_enc.cgi. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-77

CVE-2022-40799

D-Link DNR-322L Download of Code Without Integrity Check Vulnerability

Vendor: D-Link

Product: DNR-322L

Added: 2025-08-05

Due Date: 2025-08-26

Description:

D-Link DNR-322L contains a download of code without integrity check vulnerability that could allow an authenticated attacker to execute OS level commands on the device. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-494

CVE-2023-2533

PaperCut NG/MF Cross-Site Request Forgery (CSRF) Vulnerability

Vendor: PaperCut

Product: NG/MF

Added: 2025-07-28

Due Date: 2025-08-18

Description:

PaperCut NG/MF contains a cross-site request forgery (CSRF) vulnerability, which, under specific conditions, could potentially enable an attacker to alter security settings or execute arbitrary code.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-352

CVE-2025-20337

Cisco Identity Services Engine Injection Vulnerability

Vendor: Cisco

Product: Identity Services Engine

Added: 2025-07-28

Due Date: 2025-08-18

Description:

Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing an attacker to exploit this vulnerability by submitting a crafted API request. Successful exploitation could allow an attacker to perform remote code execution and obtaining root privileges on an affected device.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-74

CVE-2025-20281

Cisco Identity Services Engine Injection Vulnerability

Vendor: Cisco

Product: Identity Services Engine

Added: 2025-07-28

Due Date: 2025-08-18

Description:

Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing an attacker to exploit this vulnerability by submitting a crafted API request. Successful exploitation could allow an attacker to perform remote code execution and obtaining root privileges on an affected device.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-74

CVE-2025-2775

SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability

Vendor: SysAid

Product: SysAid On-Prem

Added: 2025-07-22

Due Date: 2025-08-12

Description:

SysAid On-Prem contains an improper restriction of XML external entity reference vulnerability in the Checkin processing functionality, allowing for administrator account takeover and file read primitives.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-611

CVE-2025-2776

SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability

Vendor: SysAid

Product: SysAid On-Prem

Added: 2025-07-22

Due Date: 2025-08-12

Description:

SysAid On-Prem contains an improper restriction of XML external entity reference vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read primitives.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-611

CVE-2025-6558

Google Chromium ANGLE and GPU Improper Input Validation Vulnerability

Vendor: Google

Product: Chromium

Added: 2025-07-22

Due Date: 2025-08-12

Description:

Google Chromium contains an improper input validation vulnerability in ANGLE and GPU. This vulnerability could allow a remote attacker to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-20

CVE-2025-54309

CrushFTP Unprotected Alternate Channel Vulnerability

Vendor: CrushFTP

Product: CrushFTP

Added: 2025-07-22

Due Date: 2025-08-12

Description:

CrushFTP contains an unprotected alternate channel vulnerability. When the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via HTTPS.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-420

CVE-2025-49704

Ransomware

Microsoft SharePoint Code Injection Vulnerability

Vendor: Microsoft

Product: SharePoint

Added: 2025-07-22

Due Date: 2025-07-23

Description:

Microsoft SharePoint contains a code injection vulnerability that could allow an authorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-49706. CVE-2025-53770 is a patch bypass for CVE-2025-49704, and the updates for CVE-2025-53770 include more robust protection than those for CVE-2025-49704.

Required Action:

Disconnect public-facing versions of SharePoint Server that have reached their end-of-life (EOL) or end-of-service (EOS) to include SharePoint Server 2013 and earlier versions. For supported versions, please follow the mitigations according to CISA (URL listed below in Notes) and vendor instructions (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.

CWEs:

CWE-94