Blue Goat CyberBlue Goat CyberSMMedical Device Cybersecurity
    K
    Goat Feed · Topic

    KEV

    CISA KEV adds

    Back to the daily feed
    criticalKEVBGC-RS 6.9Infra · likely in-scope

    CISA KEV: Linux Kernel CVE-2026-53362 (CVSS 3.1 7.8 HIGH) - Kernel Unspecified Vulnerability

    In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocation path In __ip6_append_data(), when the paged-allocation branch is taken (MSG_MORE / NETIF_F_SG / large fraglen), alloclen and pagedlen are computed as alloclen = fragheaderlen + transhdrlen; pagedlen = datalen - transhdrlen; datalen already includes fraggap (datalen = length + fraggap). When fraggap is non-zero, this is not the first skb and transhdrlen is zero. The fraggap bytes carried over from the previous skb are copied just past the fragment headers in the new skb's linear area. The linear area is therefore undersized by fraggap bytes while pagedlen is overstated by the same amount, and the copy writes past skb->end into the trailing skb_shared_info. An unprivileged user can trigger this via a UDPv6 socket using MSG_MORE together with MSG_SPLICE_PAGES. The bad accounting was introduced by commit 773ba4fe9104 ("ipv6: avoid partial copy for zc"). Before commit ce650a166335 ("udp6: Fix __ip6_append_data()'s handling of MSG_SPLICE_PAGES"), the negative copy value caused -EINVAL to be returned. That later commit allowed MSG_SPLICE_PAGES to proceed in this case, making the corruption triggerable. The non-paged branch sets alloclen to fraglen, which already accounts for fraggap because datalen does. Bring the paged branch in line by adding fraggap to alloclen and subtracting it from pagedlen. After this adjustment, copy no longer collapses to -fraggap on the paged path, so remove the stale comment describing that old arithmetic. Since a negative copy is no longer expected for a valid MSG_SPLICE_PAGES case, remove the MSG_SPLICE_PAGES exception from the negative copy check.

    criticalKEVBGC-RS 6.9Infra · likely in-scope

    CISA KEV: Linux Kernel CVE-2022-0995 (CVSS 3.1 7.8 HIGH) - Kernel Out-of-Bounds Write Vulnerability

    An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged access or cause a denial of service on the system.

    criticalKEVBGC-RS 6.9Infra · likely in-scope

    CISA KEV: Microsoft Internet Key Exchange (IKE) Service Extensions CVE-2026-33824 (CVSS 3.1 9.8 CRITICAL) - Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability

    Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.

    criticalKEVBGC-RS 5.5Infra · likely in-scope

    CISA KEV: Microsoft Windows Ancillary Function Driver for WinSock CVE-2026-68820 (CVSS 3.1 7.0 HIGH) - Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability

    Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

    criticalKEVBGC-RS 8.8Infra · likely in-scope

    CISA KEV: N-able N-central CVE-2026-18556 (CVSS 4.0 8.2 HIGH) - N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

    Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.

    criticalKEVBGC-RS 8.5Infra · likely in-scope

    CISA KEV: Apache Tomcat CVE-2026-34486 (CVSS 3.1 7.5 HIGH) - Tomcat Missing Encryption of Sensitive Data Vulnerability

    Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.

    criticalKEVBGC-RS 8.8Infra · likely in-scope

    CISA KEV: N-able N-central CVE-2026-18577 (CVSS 4.0 8.2 HIGH) - N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

    An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

    criticalKEVBGC-RS 8.2Infra · likely in-scope

    CISA KEV: Fortinet FortiOS CVE-2025-68686 (CVSS 3.1 5.9 MEDIUM) - FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability

    An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.

    criticalKEVBGC-RS 4.7Infra · likely in-scope

    CISA KEV: Cisco IOS CVE-2008-4128 (CVSS 3.1 4.3 MEDIUM) - IOS Cross-Site Request Forgery Vulnerability

    Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router allow remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI. NOTE: some of these details are obtained from third party information.

    criticalKEVBGC-RS 4.2Infra · likely in-scope

    CISA KEV: Microsoft Windows CVE-2026-21519 - Windows Type Confusion Vulnerability

    Microsoft Desktop Windows Manager contains a type confusion vulnerability that could allow an authorized attacker to elevate privileges locally.

    criticalKEVBGC-RS 4.2Infra · likely in-scope

    CISA KEV: Cisco Catalyst SD-WAN Manager CVE-2026-20128 - Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability

    Cisco Catalyst SD-WAN Manager contains a storing passwords in a recoverable format vulnerability that allows an authenticated, local attacker to gain DCA user privileges by accessing a credential file for the DCA user on the filesystem as a low-privileged user.

    criticalKEVBGC-RS 4.2

    CISA KEV: Apache ActiveMQ CVE-2026-34197 - ActiveMQ Improper Input Validation Vulnerability

    Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection.

    criticalKEVBGC-RS 7.3Infra · likely in-scope

    CISA KEV: Microsoft Windows CVE-2026-21513 - MSHTML Framework Protection Mechanism Failure Vulnerability

    Microsoft MSHTML Framework contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network.

    criticalKEVBGC-RS 4.2Infra · likely in-scope

    CISA KEV: Microsoft Windows CVE-2025-60710 - Windows Link Following Vulnerability

    Microsoft Windows contains a link following vulnerability that allows for privilege escalation

    criticalKEVBGC-RS 4.2Infra · likely in-scope

    CISA KEV: Apple iOS and iPadOS CVE-2023-41974 - iOS and iPadOS Use-After-Free Vulnerability

    Apple iOS and iPadOS contain a use-after-free vulnerability. An app may be able to execute arbitrary code with kernel privileges.

    criticalKEVBGC-RS 4.5Infra · likely in-scope

    CISA KEV: Microsoft Windows CVE-2026-21525 - Windows NULL Pointer Dereference Vulnerability

    Microsoft Windows Remote Access Connection Manager contains a NULL pointer dereference that could allow an unauthorized attacker to deny service locally.

    criticalKEVBGC-RS 4.2Infra · likely in-scope

    CISA KEV: Linux Kernel CVE-2018-14634 - Kernel Integer Overflow Vulnerability

    Linux Kernel contains an integer overflow vulnerability in the create_elf_tables() function which could allow an unprivileged local user with access to SUID (or otherwise privileged) binary to escalate their privileges on the system.

    criticalKEVBGC-RS 4.2Infra · likely in-scope

    CISA KEV: Microsoft Windows CVE-2026-20805 - Windows Information Disclosure Vulnerability

    Microsoft Windows Desktop Windows Manager contains an information disclosure vulnerability that allows an authorized attacker to disclose information locally.

    criticalKEVBGC-RS 5.6Infra · likely in-scope

    CISA KEV: Microsoft Windows CVE-2008-0015 - Windows Video ActiveX Control Remote Code Execution Vulnerability

    Microsoft Windows Video ActiveX Control contains a remote code execution vulnerability. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user.

    criticalKEVBGC-RS 4.5Infra · likely in-scope

    CISA KEV: Microsoft Windows CVE-2026-32202 (CVSS 4.3 MEDIUM) - Windows Protection Mechanism Failure Vulnerability

    Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.

    criticalKEVBGC-RS 4.5Infra · likely in-scope

    CISA KEV: Microsoft Windows CVE-2026-21533 - Windows Improper Privilege Management Vulnerability

    Microsoft Windows Remote Desktop Services contains an improper privilege management vulnerability that could allow an authorized attacker to elevate privileges locally.

    criticalKEVBGC-RS 4.2Infra · likely in-scope

    CISA KEV: Microsoft Windows CVE-2023-36424 - Windows Out-of-Bounds Read Vulnerability

    Microsoft Windows Common Log File System Driver contains an out-of-bounds read vulnerability that could allow a threat actor for privileges escalation

    criticalKEVBGC-RS 7.3Infra · likely in-scope

    CISA KEV: Microsoft Windows CVE-2026-21510 - Windows Shell Protection Mechanism Failure Vulnerability

    Microsoft Windows Shell contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network.

    criticalKEVBGC-RS 4.6Infra · likely in-scope

    CISA KEV: Microsoft Windows CVE-2008-4250 - Windows Buffer Overflow Vulnerability

    Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization.

    criticalKEVBGC-RS 4.3Infra · likely in-scope

    CISA KEV: Linux Kernel CVE-2026-31431 - Kernel Incorrect Resource Transfer Between Spheres Vulnerability

    Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation.

    criticalKEVBGC-RS 6.5Infra · likely in-scope

    CISA KEV: Arista Extensible Operating System CVE-2026-7473 (CVSS 4.0 6.9 MEDIUM) - Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability

    On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly decapsulate and forward other unexpected tunneled packet with a destination IP matching its configured decapsulation IP. This occurs because the switch does not verify the tunnel protocol type, potentially leading to the unexpected processing of non-configured tunnel traffic. This issue has been reported as being exploited in the wild.

    criticalKEVBGC-RS 8.6Infra · likely in-scope

    CISA KEV: Linux Kernel CVE-2022-0492 (CVSS 3.1 7.8 HIGH) - Kernel Improper Authentication Vulnerability

    A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation unexpectedly.

    criticalKEVBGC-RS 4.3Infra · likely in-scope

    CISA KEV: Android Framework CVE-2025-48595 - Framework Integer Overflow Vulnerability

    Android Framework contains an integer overflow vulnerability that allows for code execution that could allow for local privilege escalation.