Knox Security Intelligence

Knox CVE Database

Actively exploited vulnerabilities from the CISA KEV catalog, tracked through the FedRAMP remediation lens — severity, exploitation status, and federal deadlines, updated as CISA adds them.

Latest vulnerabilities added to the CISA KEV catalog

CVE ID
Severity
Score
Vendor
Product
Date added
Due date
Ransomware
CVE-2026-7473
Arista Extensible Operating System (EOS) contains an incomplete comparison with missing factors vulnerability when the switch incorrectly decapsulate and forwards other unexpected tunneled packet with a destination IP matching its configured decapsulation IP.
Medium
6.9
Arista
Extensible Operating System
June 9, 2026
June 23, 2026
Unknown
CVE-2026-11645
Google Chromium V8 out-of-bounds read and write vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
High
8.8
Google
Chromium V8
June 9, 2026
June 23, 2026
Unknown
CVE-2026-50751
Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.
Critical
9.3
Check Point
Security Gateway
June 8, 2026
June 11, 2026
Known
CVE-2026-42271
BerriAI LiteLLM contains a command injection vulnerability that could allow any authenticated user, including holders of low-privilege internal-user keys, to run arbitrary commands on the host.
High
8.8
BerriAI
LiteLLM
June 8, 2026
June 22, 2026
Unknown
CVE-2026-28318
SolarWinds Serv-U contains an uncontrolled resource consumption vulnerability that allows specially crafted POST requests using the Content-Encoding: deflate header to crash the Serv-U service without authentication.
High
7.5
SolarWinds
Serv-U
June 5, 2026
June 19, 2026
Unknown
CVE-2026-45247
Mirasvit Full Page Cache Warmer contains a deserialization of untrusted data vulnerability that could allow unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie.
Critical
9.3
Mirasvit
Mirasvit Full Page Cache Warmer
June 3, 2026
June 6, 2026
Unknown
CVE-2025-48595
Android Framework contains an integer overflow vulnerability that allows for code execution that could allow for local privilege escalation.
High
8.4
Android
Framework
June 2, 2026
June 5, 2026
Unknown
CVE-2022-0492
Linux Kernel contains an improper authentication vulnerability which could allow for privilege escalation via the cgroups v1 release_agent feature.
High
7.8
Linux
Kernel
June 2, 2026
June 5, 2026
Unknown
CVE-2024-21182
Oracle WebLogic contains an unspecified vulnerability that could allow an unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data.
High
7.5
Oracle
WebLogic Server
June 1, 2026
June 4, 2026
Unknown
CVE-2026-0257
Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection.
Critical
9.1
Palo Alto Networks
PAN-OS
May 29, 2026
June 1, 2026
Known
CVE-2026-8398
Daemon Tools contains an unspecified vulnerability that has a high impact on confidentiality, integrity, and availability.
Critical
9.3
Daemon
Daemon Tools Lite
May 27, 2026
May 30, 2026
Unknown
CVE-2026-48027
Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload that could harvested credentials from multiple sources on disk and in memory.
Critical
9.8
Nx
Nx Console
May 27, 2026
June 10, 2026
Known
CVE-2026-48172
LiteSpeed cPanel Plugin contains privilege escalation vulnerability that is exposed via the user-end cPanel plugin, which can be abused by any cPanel user account to execute arbitrary scripts with root privileges.
Critical
9.8
LiteSpeed
cPanel Plugin
May 26, 2026
May 29, 2026
Unknown
CVE-2026-9082
Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.
Critical
9.8
Drupal
Core
May 22, 2026
May 27, 2026
Unknown
CVE-2025-34291
Langflow contains an origin validation error vulnerability in which an overly permissive CORS configuration combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform cross-origin requests that include credentials and successfully call the refresh endpoint. This could allow the attacker to execute arbitrary code and achieve full system compromise via obtained tokens that permit access to authenticated endpoints.
High
8.8
Langflow
Langflow
May 21, 2026
June 4, 2026
Unknown
CVE-2026-34926
Trend Micro Apex One (on-premise) contains a directory traversal vulnerability that could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations.
Medium
6.7
Trend Micro
Apex One
May 21, 2026
June 4, 2026
Unknown
CVE-2009-3459
Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability which could allow remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption.
Critical
9.3
Adobe
Acrobat and Reader
May 20, 2026
June 3, 2026
Unknown
CVE-2009-1537
Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitrary code via a crafted QuickTime media file.
Critical
9.3
Microsoft
DirectX
May 20, 2026
June 3, 2026
Unknown
CVE-2008-4250
Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization.
Critical
10.0
Microsoft
Windows
May 20, 2026
June 3, 2026
Unknown
CVE-2025-0282
Ivanti Connect Secure, Policy Secure, and ZTA Gateways contain a stack-based buffer overflow which can lead to unauthenticated remote code execution.
Critical
9.0
Ivanti
Connect Secure, Policy Secure, and ZTA Gateways
January 8, 2025
January 15, 2025
Known

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.