SignalSec: Vulns & Hacks

Known Exploited Vulnerabilities and latest CVEs

Exploited in wild

CVE-2026-12569

CRITICAL (9.8)
6/18/2026

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.  * This advisory also applies to all CPS versions * The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030

CISA KEV Alert: Added on 6/25/2026. Action due: 6/28/2026.

Exploited in wild

CVE-2026-20262

MEDIUM (6.5)
Vendor: CiscoProduct: Catalyst SD-WAN Manager6/15/2026

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system. This vulnerability exists because the affected software does not properly validate user-supplied input during a file upload process. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected API endpoint of the affected system. A successful exploit could allow the attacker to create or overwrite any file on the underlying operating system. This file could later be used to elevate to root. To exploit this vulnerability, the attacker must have valid credentials with at least a lower-privileged, single-task user account.

CISA KEV Alert: Added on 6/15/2026. Action due: 6/29/2026.

Exploited in wild

CVE-2026-54420

HIGH (8.5)
Vendor: LiteSpeedProduct: cPanel Plugin6/15/2026

LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS, as exploited in the wild in May 2026.

CISA KEV Alert: Added on 6/15/2026. Action due: 6/18/2026.

Cloud SecurityLinux
View CISA Alert
Exploited in wild

CVE-2026-35273

CRITICAL (9.8)
Vendor: OracleProduct: PeopleSoft Enterprise PeopleTools6/12/2026

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CISA KEV Alert: Added on 6/12/2026. Action due: 6/15/2026.

Exploited in wild

CVE-2026-10520

CRITICAL (10)
Vendor: IvantiProduct: Sentry6/11/2026

An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution

CISA KEV Alert: Added on 6/11/2026. Action due: 6/14/2026.

Exploited in wild

CVE-2026-20253

CRITICAL (9.8)
6/10/2026

In Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.3 and 10.2.2510.14, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint.<br><br>The vulnerability exists because the PostgreSQL sidecar service endpoint lacks authentication controls, allowing any network-reachable user to invoke file operations without credentials.

CISA KEV Alert: Added on 6/18/2026. Action due: 6/21/2026.

Exploited in wild

CVE-2026-11645

HIGH (8.8)
Vendor: GoogleProduct: Chromium V86/9/2026

Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CISA KEV Alert: Added on 6/9/2026. Action due: 6/23/2026.

Exploited in wild

CVE-2026-20245

HIGH (7.8)
Vendor: CiscoProduct: Catalyst SD-WAN Manager6/9/2026

Cisco Catalyst SD-WAN Manager formerly SD-WAN vManage contains an improper encoding or escaping of output vulnerability. This vulnerability could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system.

CISA KEV Alert: Added on 6/9/2026. Action due: 6/23/2026.

Exploited in wild

CVE-2026-50751

CRITICAL (9.3)
Vendor: Check PointProduct: Security Gateway6/8/2026

A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.

CISA KEV Alert: Added on 6/8/2026. Action due: 6/11/2026.

Exploited in wild

CVE-2026-7473

MEDIUM (5.8)
6/5/2026

On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly decapsulate and forward other unexpected tunneled packet with a destination IP matching its configured decapsulation IP. This occurs because the switch does not verify the tunnel protocol type, potentially leading to the unexpected processing of non-configured tunnel traffic. This issue has been reported as being exploited in the wild.

CISA KEV Alert: Added on 6/9/2026. Action due: 6/23/2026.

Exploited in wild

CVE-2026-48907

CRITICAL (9.8)
6/5/2026

A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.

CISA KEV Alert: Added on 6/16/2026. Action due: 6/19/2026.

Exploited in wild

CVE-2026-28318

HIGH (7.5)
Vendor: SolarWindsProduct: Serv-U6/5/2026

SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate. Mitigation steps are provided to secure customer environments in the SolarWinds Trust Center if you are unable to deploy the update

CISA KEV Alert: Added on 6/5/2026. Action due: 6/19/2026.

Exploited in wild

CVE-2026-20230

HIGH (8.6)
6/3/2026

A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to write files to the underlying operating system that could be used later to elevate to root. Note: Cisco has assigned this security advisory a Security Impact Rating (SIR) of Critical rather than High as the score indicates. The reason is that exploitation of this vulnerability could result in an attacker elevating privileges to root. Note: To exploit this vulnerability, the WebDialer service must be enabled. WebDialer is disabled by default.

CISA KEV Alert: Added on 6/25/2026. Action due: 6/28/2026.

Exploited in wild

CVE-2025-48595

HIGH (8.4)
Vendor: AndroidProduct: Framework6/2/2026

In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CISA KEV Alert: Added on 6/2/2026. Action due: 6/5/2026.

Exploited in wild

CVE-2022-0492

HIGH (7.8)
Vendor: LinuxProduct: Kernel6/2/2026

Linux Kernel contains an improper authentication vulnerability which could allow for privilege escalation via the cgroups v1 release_agent feature.

CISA KEV Alert: Added on 6/2/2026. Action due: 6/5/2026.

Exploited in wild

CVE-2024-21182

HIGH (7.5)
Vendor: OracleProduct: WebLogic Server6/1/2026

Oracle WebLogic contains an unspecified vulnerability that could allow an unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data.

CISA KEV Alert: Added on 6/1/2026. Action due: 6/4/2026.

Exploited in wild

CVE-2026-48027

CRITICAL (9.8)
Vendor: NxProduct: Nx Console5/27/2026

Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload that could harvested credentials from multiple sources on disk and in memory.

CISA KEV Alert: Added on 5/27/2026. Action due: 6/10/2026.

AI/MLData Breach
View CISA Alert
Exploited in wild

CVE-2026-45247

CRITICAL (9.8)
5/26/2026

Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie. Attackers can exploit the unrestricted call to PHP's native unserialize() function combined with gadget chains available in Magento and its dependencies to execute arbitrary code on the server.

CISA KEV Alert: Added on 6/3/2026. Action due: 6/6/2026.

Exploited in wild

CVE-2026-34910

CRITICAL (10)
5/22/2026

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.

CISA KEV Alert: Added on 6/23/2026. Action due: 6/26/2026.

Exploited in wild

CVE-2026-34909

CRITICAL (10)
5/22/2026

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account.

CISA KEV Alert: Added on 6/23/2026. Action due: 6/26/2026.

Exploited in wild

CVE-2026-34908

CRITICAL (10)
5/22/2026

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.

CISA KEV Alert: Added on 6/23/2026. Action due: 6/26/2026.

Exploited in wild

CVE-2026-9082

MEDIUM (6.5)
Vendor: DrupalProduct: Core5/22/2026

Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.

CISA KEV Alert: Added on 5/22/2026. Action due: 5/27/2026.

Exploited in wild

CVE-2026-48172

CRITICAL (9.8)
5/21/2026

LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of grep -rE "cpanel_jsonapi_func=redisAble" /var/cpanel/logs /usr/local/cpanel/logs/ 2>/dev/null in Bash. If you get no output, you have not been hit with exploitation of the vulnerability. If there is output, we recommend you examine the IP addresses in the list, determine if they are valid IP addresses, and if not, block them. To determine damage done, examine the system logs for use by the detected IP addresses. The issue is related to mishandling of Redis enable/disable features. The recommended minimum version is 2.4.7.

CISA KEV Alert: Added on 5/26/2026. Action due: 5/29/2026.

Exploited in wild

CVE-2025-34291

HIGH (8.8)
Vendor: LangflowProduct: Langflow5/21/2026

Langflow contains an origin validation error vulnerability in which an overly permissive CORS configuration combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform cross-origin requests that include credentials and successfully call the refresh endpoint. This could allow the attacker to execute arbitrary code and achieve full system compromise via obtained tokens that permit access to authenticated endpoints.

CISA KEV Alert: Added on 5/21/2026. Action due: 6/4/2026.

Exploited in wild

CVE-2026-34926

MEDIUM (6.7)
Vendor: Trend MicroProduct: Apex One5/21/2026

A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations. This vulnerability is only exploitable on the on-premise version of Apex One and a potential attacker must have access to the Apex One Server and already obtained administrative credentials to the server via some other method to exploit this vulnerability.

CISA KEV Alert: Added on 5/21/2026. Action due: 6/4/2026.

Exploited in wild

CVE-2008-4250

CRITICAL (10)
Vendor: MicrosoftProduct: Windows5/20/2026

Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization.

CISA KEV Alert: Added on 5/20/2026. Action due: 6/3/2026.

AI/MLMicrosoft
View CISA Alert
Exploited in wild

CVE-2026-41091

HIGH (7.8)
Vendor: MicrosoftProduct: Defender5/20/2026

Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.

CISA KEV Alert: Added on 5/20/2026. Action due: 6/3/2026.

Exploited in wild

CVE-2010-0249

HIGH (8.8)
Vendor: MicrosoftProduct: Internet Explorer5/20/2026

Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

CISA KEV Alert: Added on 5/20/2026. Action due: 6/3/2026.

AI/MLRansomwareMicrosoft
View CISA Alert
Exploited in wild

CVE-2010-0806

CRITICAL (9.3)
Vendor: MicrosoftProduct: Internet Explorer5/20/2026

Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

CISA KEV Alert: Added on 5/20/2026. Action due: 6/3/2026.

AI/MLRansomwareMicrosoft
View CISA Alert
Exploited in wild

CVE-2026-45498

MEDIUM (4)
Vendor: MicrosoftProduct: Defender5/20/2026

Microsoft Defender Denial of Service Vulnerability

CISA KEV Alert: Added on 5/20/2026. Action due: 6/3/2026.

Exploited in wild

CVE-2009-3459

CRITICAL (9.3)
Vendor: AdobeProduct: Acrobat and Reader5/20/2026

Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability which could allow remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption.

CISA KEV Alert: Added on 5/20/2026. Action due: 6/3/2026.

Exploited in wild

CVE-2009-1537

CRITICAL (9.3)
Vendor: MicrosoftProduct: DirectX5/20/2026

Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitrary code via a crafted QuickTime media file.

CISA KEV Alert: Added on 5/20/2026. Action due: 6/3/2026.

AI/MLMicrosoft
View CISA Alert
Exploited in wild

CVE-2026-8398

CRITICAL (9.8)
5/15/2026

A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distributed from the legitimate website daemon-tools.cc between approximately April 8, 2026, and May 5, 2026. Attackers gained unauthorized access to the vendor's (AVB Disc Soft) build or distribution infrastructure and trojanized three binaries: DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe. These files were digitally signed with the legitimate AVB Disc Soft code-signing certificate, allowing the malicious installers to appear trustworthy and bypass signature-based detection.

CISA KEV Alert: Added on 5/27/2026. Action due: 5/30/2026.

Exploited in wild

CVE-2026-42897

HIGH (8.1)
Vendor: MicrosoftProduct: Microsoft5/15/2026

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

CISA KEV Alert: Added on 5/15/2026. Action due: 5/29/2026.

PhishingMicrosoft
View CISA Alert
Exploited in wild

CVE-2026-20182

CRITICAL (10)
Vendor: CiscoProduct: Catalyst SD-WAN5/14/2026

May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed in February 2026. This new advisory is for a new vulnerability in the control connection handshaking. The section of this advisory includes Show Control Connections guidance to help with system checks.&nbsp; A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to the affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric.

CISA KEV Alert: Added on 5/14/2026. Action due: 5/17/2026.

Exploited in wild

CVE-2026-0257

CRITICAL (9.1)
5/13/2026

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues.

CISA KEV Alert: Added on 5/29/2026. Action due: 6/1/2026.

Exploited in wild

CVE-2026-45321

CRITICAL (9.6)
5/12/2026

On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The attacker chained three known vulnerability classes — a pull_request_target "Pwn Request" misconfiguration, GitHub Actions cache poisoning across the fork↔base trust boundary, and runtime memory extraction of the OIDC token from the Actions runner process — to publish credential-stealing malware under a trusted identity. Each affected package received exactly two malicious versions, published a few minutes apart.

CISA KEV Alert: Added on 5/27/2026. Action due: 6/10/2026.

AI/MLMalware
View CISA Alert
Exploited in wild

CVE-2026-42271

HIGH (8.8)
5/8/2026

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints used to preview an MCP server before saving it — POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list — accepted a full server configuration in the request body, including the command, args, and env fields used by the stdio transport. When called with a stdio configuration, the endpoints attempted to connect, which spawned the supplied command as a subprocess on the proxy host with the privileges of the proxy process. The endpoints were gated only by a valid proxy API key, with no role check. Any authenticated user — including holders of low-privilege internal-user keys — could therefore run arbitrary commands on the host. This issue has been patched in version 1.83.7.

CISA KEV Alert: Added on 6/8/2026. Action due: 6/22/2026.

Exploited in wild

CVE-2026-42208

CRITICAL (9.8)
Vendor: BerriAIProduct: LiteLLM5/8/2026

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query used during proxy API key checks mixed the caller-supplied key value into the query text instead of passing it as a separate parameter. An unauthenticated attacker could send a specially crafted Authorization header to any LLM API route (for example POST /chat/completions) and reach this query through the proxy's error-handling path. An attacker could read data from the proxy's database and may be able to modify it, leading to unauthorised access to the proxy and the credentials it manages. This issue has been patched in version 1.83.7.

CISA KEV Alert: Added on 5/8/2026. Action due: 5/11/2026.

Exploited in wild

CVE-2026-6973

HIGH (7.2)
Vendor: IvantiProduct: Endpoint Manager Mobile (EPMM)5/7/2026

An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative access to achieve remote code execution.

CISA KEV Alert: Added on 5/7/2026. Action due: 5/10/2026.

Exploited in wild

CVE-2026-0300

CRITICAL (9.8)
Vendor: Palo Alto NetworksProduct: PAN-OS5/6/2026

A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. The risk of this issue is greatly reduced if you secure access to the User-ID™ Authentication Portal per the best practice guidelines https://knowledgebase.paloaltonetworks.com/KCSArticleDetail by restricting access to only trusted internal IP addresses. Prisma Access, Cloud NGFW and Panorama appliances are not impacted by this vulnerability.

CISA KEV Alert: Added on 5/6/2026. Action due: 5/9/2026.

AI/MLCloud Security
View CISA Alert
Exploited in wild

CVE-2026-41940

CRITICAL (9.8)
Vendor: WebProsProduct: cPanel & WHM and WP2 (WordPress Squared)4/30/2026

cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

CISA KEV Alert: Added on 4/30/2026. Action due: 5/3/2026.

Exploited in wild

CVE-2024-1708

HIGH (8.4)
Vendor: ConnectWiseProduct: ScreenConnect4/28/2026

ConnectWise ScreenConnect contains a path traversal vulnerability which could allow an attacker to execute remote code or directly impact confidential data and critical systems.

CISA KEV Alert: Added on 4/28/2026. Action due: 5/12/2026.

Exploited in wild

CVE-2026-32202

MEDIUM (4.3)
Vendor: MicrosoftProduct: Windows4/28/2026

Microsoft Windows Shell contains a protection mechanism failure vulnerability that allows an unauthorized attacker to perform spoofing over a network.

CISA KEV Alert: Added on 4/28/2026. Action due: 5/12/2026.

AI/MLPhishingMicrosoft
View CISA Alert
Exploited in wild

CVE-2024-57726

CRITICAL (9.9)
Vendor: SimpleHelp Product: SimpleHelp4/24/2026

SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.

CISA KEV Alert: Added on 4/24/2026. Action due: 5/8/2026.

Exploited in wild

CVE-2024-7399

HIGH (8.8)
Vendor: SamsungProduct: MagicINFO 9 Server4/24/2026

Samsung MagicINFO 9 Server contains a path traversal vulnerability that could allow an attacker to write arbitrary files as system authority.

CISA KEV Alert: Added on 4/24/2026. Action due: 5/8/2026.

Exploited in wild

CVE-2025-29635

HIGH (7.2)
Vendor: D-LinkProduct: DIR-823X4/24/2026

D-Link DIR-823X contains a command injection vulnerability that allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

CISA KEV Alert: Added on 4/24/2026. Action due: 5/8/2026.

AI/MLRansomware
View CISA Alert
Exploited in wild

CVE-2024-57728

HIGH (7.2)
Vendor: SimpleHelp Product: SimpleHelp4/24/2026

SimpleHelp contains a path traversal vulnerability that allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user.

CISA KEV Alert: Added on 4/24/2026. Action due: 5/8/2026.

Exploited in wild

CVE-2026-31431

HIGH (7.8)
4/22/2026

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.

CISA KEV Alert: Added on 5/1/2026. Action due: 5/15/2026.

Exploited in wild

CVE-2026-33825

HIGH (7.8)
Vendor: MicrosoftProduct: Defender4/22/2026

Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally.

CISA KEV Alert: Added on 4/22/2026. Action due: 5/6/2026.

AI/MLMicrosoft
View CISA Alert