Knox Security Intelligence

Knox CVE Database

Actively exploited vulnerabilities from the CISA KEV catalog, tracked through the FedRAMP remediation lens — severity, exploitation status, and federal deadlines, updated as CISA adds them.

Latest vulnerabilities added to the CISA KEV catalog

CVE ID
Severity
Score
Vendor
Product
Date added
Due date
Ransomware
CVE-2026-60004
Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account.
Critical
9.8
Gitea
Gitea
August 25, 2026
August 28, 2026
Unknown
CVE-2026-21962
Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in contain an improper access control vulnerability that can result in unauthorized creation, deletion or modification access to critical data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in accessible data.
Critical
10.0
Oracle
HTTP Server and Oracle Weblogic Server Proxy Plug-in
August 24, 2026
August 27, 2026
Unknown
CVE-2026-73570
Zimbra Collaboration Suite (ZCS) contains an OS command injection vulnerability which could allow an unauthenticated attacker to send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.
High
8.9
Synacor
Zimbra Collaboration Suite (ZCS)
August 21, 2026
August 24, 2026
Unknown
CVE-2026-72530
TrueConf Server contains a code injection vulnerability that could allow an unauthorized remote attacker with network access via port 4307/TCP to use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.
Critical
9.5
TrueConf
Server
August 20, 2026
September 3, 2026
Unknown
CVE-2026-72529
TrueConf Server contains a missing authentication for critical function vulnerability which could allow a remote unauthorized attacker with network access via port 4307/TCP to execute an arbitrary script.
Critical
9.3
TrueConf
Server
August 20, 2026
August 23, 2026
Unknown
CVE-2026-64849
MLflow contains a server-side request forgery vulnerability that can allow attackers to reach internal or cloud metadata services and receive response_status and response_body.
Critical
9.3
MLflow
MLflow
August 19, 2026
September 2, 2026
Unknown
CVE-2026-33824
Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.
Critical
9.8
Microsoft
Internet Key Exchange (IKE) Service Extensions
August 18, 2026
August 21, 2026
Unknown
CVE-2026-59310
Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code.
Critical
9.8
Broadcom
VMware vCenter
August 18, 2026
August 21, 2026
Unknown
CVE-2026-55040
Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network.
Critical
9.1
Microsoft
SharePoint
August 18, 2026
August 21, 2026
Unknown
CVE-2026-65400
Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials.
Critical
9.8
Apple
macOS
August 18, 2026
August 21, 2026
Unknown
CVE-2025-62593
Ray-Project Ray contains a code injection vulnerability that could allow remote code execution. Developers using Ray as a development tool may be exposed to this vulnerability exploitable through Firefox and Safari.
High
8.8
Ray-Project
Ray
August 17, 2026
August 20, 2026
Unknown
CVE-2026-20349
Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.
High
8.6
Cisco
Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)
August 11, 2026
August 14, 2026
Unknown
CVE-2026-68820
Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.
High
7.0
Microsoft
Windows Ancillary Function Driver for WinSock
August 11, 2026
August 25, 2026
Unknown
CVE-2026-72898
Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data.
Critical
10.0
Metabase
Metabase
August 11, 2026
August 14, 2026
Unknown
CVE-2026-8037
Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints.
Critical
9.8
Progress
LoadMaster
August 7, 2026
August 10, 2026
Unknown
CVE-2026-63077
JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol.
Critical
9.8
JetBrains
TeamCity
August 5, 2026
August 8, 2026
Unknown
CVE-2026-9198
Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.
Critical
9.8
IBM
Langflow
August 4, 2026
August 7, 2026
Unknown
CVE-2026-34486
Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813.
High
7.5
Apache
Tomcat
August 4, 2026
August 7, 2026
Unknown
CVE-2026-18556
N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.
High
7.4
N-able
N-central
August 4, 2026
August 7, 2026
Unknown
CVE-2026-18577
N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for CVE-2026-18556.
High
8.1
N-able
N-central
August 3, 2026
August 6, 2026
Unknown

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.