Knox Security Intelligence

Knox CVE Database

Actively exploited vulnerabilities from the CISA KEV catalog, tracked through the FedRAMP remediation lens — severity, exploitation status, and federal deadlines, updated as CISA adds them.

Latest vulnerabilities added to the CISA KEV catalog

CVE ID
Severity
Score
Vendor
Product
Date added
Due date
Ransomware
CVE-2025-39964
Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state.
Medium
5.5
Linux
Kernel
September 18, 2026
September 21, 2026
Unknown
CVE-2025-39682
Linux Kernel contains an improper check for unusual or exceptional conditions vulnerability in the TLS receive path which allows a zero-length record retrieved from the rx_list to bypass the intended recvmsg() record-type handling, potentially causing subsequent TLS records to be processed using incorrect zero-copy and queuing assumptions. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.
Critical
9.8
Linux
Kernel
September 18, 2026
September 21, 2026
Unknown
CVE-2026-53266
Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.
High
8.8
Linux
Kernel
September 18, 2026
September 21, 2026
Unknown
CVE-2026-58704
Google Pixel devices contain an improper authorization vulnerability in the cellular modem. A logic error may allow an attacker to bypass permission checks and escalate privileges.
High
8.8
Google
Pixel
September 16, 2026
September 19, 2026
Unknown
CVE-2026-87886
Acronis Backup plugin for cPanel & WHM and extension for Plesk contains an incorrect default permissions vulnerability that could allow for privilege escalation.
High
7.8
Acronis
Backup
September 16, 2026
September 19, 2026
Unknown
CVE-2026-76460
Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.
Critical
10.0
Cisco
Identity Services Engine
September 16, 2026
September 19, 2026
Unknown
CVE-2026-76461
Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.
Critical
9.8
Cisco
Secure Email Gateway
September 14, 2026
September 17, 2026
Unknown
CVE-2026-85706
GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability that allows an unauthenticated user to read arbitrary files due to an improper path confinement and missing authentication enforcement in the repository commits API.
Critical
10.0
GitLab
Community Edition and Enterprise Edition
September 11, 2026
September 14, 2026
Unknown
CVE-2026-84869
ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to transfer and execute files through an active remote session without authorization or host confirmation.
Critical
9.9
ConnectWise
ScreenConnect
September 11, 2026
September 14, 2026
Unknown
CVE-2026-42016
JFrog Artifactory contains an incorrect authorization vulnerability that allows leads to privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.
High
8.8
JFrog
Artifactory
September 11, 2026
September 25, 2026
Unknown
CVE-2026-42018
JFrog Artifactory contains an improper authentication vulnerability that could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
High
7.5
JFrog
Artifactory
September 11, 2026
September 25, 2026
Unknown
CVE-2026-86060
MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacked to change the trusted RouterOS policy mask, leading to privilege escalation.
Critical
9.8
MikroTik
RouterOS
September 10, 2026
September 13, 2026
Unknown
CVE-2026-67277
MikroTik RouterOS contains a missing authenticaion for critical function vulnerability which allows kernel memory disclosure and denial of service in the btest service.
High
8.2
MikroTik
RouterOS
September 10, 2026
September 13, 2026
Unknown
CVE-2026-87491
Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
High
8.8
Google
Chromium V8
September 9, 2026
September 23, 2026
Unknown
CVE-2026-19490
Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy), an unauthenticated remote threat actor may be able to bypass authentication.
Critical
9.8
Citrix
NetScaler
September 9, 2026
September 12, 2026
Unknown
CVE-2025-25249
Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets.
Critical
9.8
Fortinet
Multiple Products
September 9, 2026
September 12, 2026
Unknown
CVE-2026-20079
Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication Bypass using an alternate path or channel vulnerability that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.
Critical
10.0
Cisco
Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management
September 9, 2026
September 12, 2026
Unknown
CVE-2026-85880
Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally.
High
7.8
Microsoft
Windows
September 8, 2026
September 22, 2026
Unknown
CVE-2026-86218
N-able N-central contains a static code injection vulnerability that could allow for pre-authentication remote code execution.
Critical
9.8
N-able
N-central
September 8, 2026
September 11, 2026
Unknown
CVE-2026-75650
Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allow an attacker to execute arbitrary code.
Critical
10.0
Adobe
Commerce and Magento
September 8, 2026
September 11, 2026
Unknown

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.