KEV CATALOG   H  ECV  KB  KEV  WINDOWS UPDATE  |  2026  2025  2024  2023 2022
KEV CATALOG 2026  H  January(21) February(29) March(26) April(22) May(28) June(15) July(26) August(32) September(22) October(0) November(0) December(0)


DATE

NAME

Info

CATEG.

WEB

12.9.26

CVE-2026-85706 GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability KEV KEV

12.9.26

CVE-2026-42016 JFrog Artifactory Incorrect Authorization Vulnerability KEV KEV

12.9.26

CVE-2026-42018 JFrog Artifactory Improper Authentication Vulnerability KEV KEV

12.9.26

CVE-2026-84869 ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability KEV KEV

11.9.26

CVE-2026-67277 MikroTik RouterOS Missing Authentication for Critical Function Vulnerability KEV KEV

11.9.26

CVE-2026-86060 MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability KEV KEV

10.9.26

CVE-2025-25249 Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability KEV KEV

10.9.26

CVE-2026-1949 Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability KEV KEV

10.9.26

CVE-2026-8749 Google Chromium V8 Out of Bounds Write Vulnerability KEV KEV

10.9.26

CVE-2026-20079 Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel KEV KEV

9.9.26

CVE-2026-75650 Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability KEV KEV

9.9.26

CVE-2026-81963 Microsoft Windows Link Following Vulnerability KEV KEV

9.9.26

CVE-2026-85880 Microsoft Windows Heap-Based Buffer Overflow Vulnerability KEV KEV

9.9.26

CVE-2026-86218 N-able N-central Static Code Injection Vulnerability KEV KEV

4.9.26

CVE-2026-85046 Google Chromium V8 Type Confusion Vulnerability KEV KEV

3.9.26

CVE-2026-83548 (CVSS score: 10.0) - A server-side request forgery vulnerability in SonicWall SMA 1000 Appliances that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations. KEV KEV

3.9.26

CVE-2026-83549 (CVSS score: 7.8) - A post-authentication operating system command injection vulnerability in SonicWall SMA 1000 Appliances that could enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution. KEV KEV

3.9.26

CVE-2026-9586 (CVSS score: 9.3) - An SQL injection vulnerability in Sangoma Switchvox that could allow an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution. KEV KEV

3.9.26

CVE-2026-82329 (CVSS score: 9.8) - An improper authentication vulnerability in JFrog Artifactory that under default configuration could allow an unauthenticated attacker with network access to obtain administrative privileges. KEV KEV

3.9.26

CVE-2026-48710 (CVSS score: 6.5) - An HTTP request/response smuggling vulnerability in Kludex Starlette that could allow attackers to inject paths into the host part, prepending the actual path, leading to issues such as authentication bypass when the authentication depends on the reconstructed URL's path. KEV KEV

3.9.26

CVE-2026-49869 (CVSS score: 10.0) - An operating system command injection vulnerability in Kestra OSS that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials. KEV KEV

3.9.26

CVE-2026-59822 (CVSS score: 8.8) - An improper authentication vulnerability in Berri LiteLLM's Model Context Protocol (MCP) Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token. KEV KEV

1.9.26

CVE-2026-81578 PaperCut NG/MF Missing Authentication for Critical Function Vulnerability  KEV KEV

1.9.26

CVE-2026-82078 PaperCut NG/MF Unsafe Reflection Vulnerability  KEV KEV