CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2025-59287

Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2025-10-24

Due Date: 2025-11-14

Description:

Microsoft Windows Server Update Service (WSUS) contains a deserialization of untrusted data vulnerability that allows for remote code execution.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-502

CVE-2025-61932

Motex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel Vulnerability

Vendor: Motex

Product: LANSCOPE Endpoint Manager

Added: 2025-10-22

Due Date: 2025-11-12

Description:

Motex LANSCOPE Endpoint Manager contains an improper verification of source of a communication channel vulnerability allowing an attacker to execute arbitrary code by sending specially crafted packets.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-940

CVE-2022-48503

Apple Multiple Products Unspecified Vulnerability

Vendor: Apple

Product: Multiple Products

Added: 2025-10-20

Due Date: 2025-11-10

Description:

Apple macOS, iOS, tvOS, Safari, and watchOS contain an unspecified vulnerability in JavaScriptCore that when processing web content may lead to arbitrary code execution. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-2746

Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability

Vendor: Kentico

Product: Xperience CMS

Added: 2025-10-20

Due Date: 2025-11-10

Description:

Kentico Xperience CMS contains an authentication bypass using an alternate path or channel vulnerability that could allow an attacker to control administrative objects.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-288

CVE-2025-2747

Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability

Vendor: Kentico

Product: Xperience CMS

Added: 2025-10-20

Due Date: 2025-11-10

Description:

Kentico Xperience CMS contains an authentication bypass using an alternate path or channel vulnerability that could allow an attacker to control administrative objects.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-288

CVE-2025-33073

Microsoft Windows SMB Client Improper Access Control Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2025-10-20

Due Date: 2025-11-10

Description:

Microsoft Windows SMB Client contains an improper access control vulnerability that could allow for privilege escalation. An attacker could execute a specially crafted malicious script to coerce the victim machine to connect back to the attack system using SMB and authenticate.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-284

CVE-2025-61884

Ransomware

Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability

Vendor: Oracle

Product: E-Business Suite

Added: 2025-10-20

Due Date: 2025-11-10

Description:

Oracle E-Business Suite contains a server-side request forgery (SSRF) vulnerability in the Runtime component of Oracle Configurator. This vulnerability is remotely exploitable without authentication.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-918

CVE-2025-54253

Adobe Experience Manager Forms Code Execution Vulnerability

Vendor: Adobe

Product: Experience Manager (AEM) Forms

Added: 2025-10-15

Due Date: 2025-11-05

Description:

Adobe Experience Manager Forms in JEE contains an unspecified vulnerability that allows for arbitrary code execution.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-47827

IGEL OS Use of a Key Past its Expiration Date Vulnerability

Vendor: IGEL

Product: IGEL OS

Added: 2025-10-14

Due Date: 2025-11-04

Description:

IGEL OS contains a use of a key past its expiration date vulnerability that allows for Secure Boot bypass. The igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a crafted root filesystem can be mounted from an unverified SquashFS image.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-324

CVE-2025-24990

Microsoft Windows Untrusted Pointer Dereference Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2025-10-14

Due Date: 2025-11-04

Description:

Microsoft Windows Agere Modem Driver contains an untrusted pointer dereference vulnerability that allows for privilege escalation. An attacker who successfully exploited this vulnerability could gain administrator privileges.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-822

CVE-2025-59230

Microsoft Windows Improper Access Control Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2025-10-14

Due Date: 2025-11-04

Description:

Microsoft Windows contains an improper access control vulnerability in Windows Remote Access Connection Manager which could allow an authorized attacker to elevate privileges locally.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-284

CVE-2016-7836

SKYSEA Client View Improper Authentication Vulnerability

Vendor: SKYSEA

Product: Client View

Added: 2025-10-14

Due Date: 2025-11-04

Description:

SKYSEA Client View contains an improper authentication vulnerability that allows remote code execution via a flaw in processing authentication on the TCP connection with the management console program.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-287

CVE-2021-43798

Grafana Path Traversal Vulnerability

Vendor: Grafana Labs

Product: Grafana

Added: 2025-10-09

Due Date: 2025-10-30

Description:

Grafana contains a path traversal vulnerability that could allow access to local files.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-22

CVE-2025-27915

Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability

Vendor: Synacor

Product: Zimbra Collaboration Suite (ZCS)

Added: 2025-10-07

Due Date: 2025-10-28

Description:

Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that exists in the Classic Web Client due to insufficient sanitization of HTML content in ICS files. When a user views an e-mail message containing a malicious ICS entry, its embedded JavaScript executes via an ontoggle event inside a tag. This allows an attacker to run arbitrary JavaScript within the victim's session, potentially leading to unauthorized actions such as setting e-mail filters to redirect messages to an attacker-controlled address. As a result, an attacker can perform unauthorized actions on the victim's account, including e-mail redirection and data exfiltration.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-79

CVE-2021-22555

Linux Kernel Heap Out-of-Bounds Write Vulnerability

Vendor: Linux

Product: Kernel

Added: 2025-10-06

Due Date: 2025-10-27

Description:

Linux Kernel contains a heap out-of-bounds write vulnerability that could allow an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-787