Knox Security Intelligence

Knox CVE Database

Actively exploited vulnerabilities from the CISA KEV catalog, tracked through the FedRAMP remediation lens — severity, exploitation status, and federal deadlines, updated as CISA adds them.

Latest vulnerabilities added to the CISA KEV catalog

CVE ID
Severity
Score
Vendor
Product
Date added
Due date
Ransomware
CVE-2026-56291
Balbooa Forms contains an unrestricted upload of file with dangerous type vulnerability that allows an unauthenticated arbitrary file upload which could allow uploading of executable files leading to full RCE.
Critical
9.8
Balbooa
Forms
July 10, 2026
July 13, 2026
Unknown
CVE-2026-55255
Langflow contains an authorization bypass through user-controlled key vulnerability which allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request.
High
8.4
Langflow
Langflow
July 7, 2026
July 10, 2026
Unknown
CVE-2026-48908
JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.
Critical
9.8
JoomShaper
SP Page Builder
July 7, 2026
July 10, 2026
Unknown
CVE-2026-48282
Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user.
Critical
10.0
Adobe
ColdFusion
July 7, 2026
July 10, 2026
Unknown
CVE-2026-56290
Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload.
Critical
9.8
Joomlack
Page Builder
July 7, 2026
July 10, 2026
Unknown
CVE-2026-45659
Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.
High
8.8
Microsoft
SharePoint Server
July 1, 2026
July 4, 2026
Known
CVE-2026-48558
SimpleHelp contains an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication.
Critical
9.5
SimpleHelp
SimpleHelp
June 29, 2026
July 2, 2026
Unknown
CVE-2026-12569
PTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attacker to execute arbitrary code by sending a malicious request to the network.
Critical
9.8
PTC
Windchill and FlexPLM
June 25, 2026
June 28, 2026
Known
CVE-2026-20230
Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) contain a server-side request forgery (SSRF) Vulnerability that could allow an unauthenticated, remote attacker to write files to the underlying operating system that could be used later to elevate to root.
High
8.6
Cisco
Unified Communications Manager
June 25, 2026
June 28, 2026
Unknown
CVE-2026-34909
Ubiquiti UniFi OS contains a path traversal vulnerability which could allow a malicious actor with access to the network to access files on the underlying system that could be manipulated to access an underlying account.
Critical
10.0
Ubiquiti
UniFi OS
June 23, 2026
June 26, 2026
Unknown
CVE-2026-34908
Ubiquiti UniFi OS contains an improper access control vulnerability which could allow a malicious actor with access to the network to make unauthorized changes to the system.
Critical
10.0
Ubiquiti
UniFi OS
June 23, 2026
June 26, 2026
Unknown
CVE-2026-34910
Ubiquiti UniFi OS contains an improper input validation vulnerability which could allow a malicious actor with access to the network to conduct command injection.
Critical
10.0
Ubiquiti
UniFi OS
June 23, 2026
June 26, 2026
Unknown
CVE-2025-67038
Lantronix EDS5000 contains a code injection vulnerability that could allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.
Critical
9.8
Lantronix
EDS5000
June 23, 2026
June 26, 2026
Unknown
CVE-2026-20253
Splunk Enterprise contains a missing authentication for critical function vulnerability which could allow an unauthenticated user to create or truncate arbitrary files through a PostgreSQL sidecar service endpoint.
Critical
9.8
Splunk
Enterprise
June 18, 2026
June 21, 2026
Unknown
CVE-2026-48907
Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticated users.
Critical
9.8
Widget Factory
Joomla Content Editor
June 16, 2026
June 19, 2026
Unknown
CVE-2026-54420
LiteSpeed cPanel plugin contains a UNIX symbolic link (Symlink) following vulnerability that could allow a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS.
High
8.5
LiteSpeed
cPanel Plugin
June 15, 2026
June 18, 2026
Unknown
CVE-2026-20262
Cisco Catalyst SD-WAN Manager contains a directory or path traversal vulnerability that could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system.
Medium
6.5
Cisco
Catalyst SD-WAN Manager
June 15, 2026
June 29, 2026
Unknown
CVE-2026-35273
Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise PeopleTools.
Critical
9.8
Oracle
PeopleSoft Enterprise PeopleTools
June 12, 2026
June 15, 2026
Known
CVE-2026-10520
Ivanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve root-level remote code execution. This vulnerability can be successfully exploited in cases where the Sentry appliance is in an unmanaged state with its endpoints externally reachable. The use of mTLS with EPMM or restricted HTTPS access through Neurons for MDM makes interfaces inaccessible to external actors.
Critical
10.0
Ivanti
Sentry
June 11, 2026
June 14, 2026
Unknown
CVE-2026-20245
Cisco Catalyst SD-WAN Manager formerly SD-WAN vManage contains an improper encoding or escaping of output vulnerability. This vulnerability could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system.
High
7.8
Cisco
Catalyst SD-WAN Manager
June 9, 2026
June 23, 2026
Unknown

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.