Critical · CVSS 9.8 · CISA KEV
Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.
Published Oct 14, 2025 · Updated Feb 26, 2026
Critical · CVSS 10 · CISA KEV
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.
Published Dec 3, 2025 · Updated Feb 26, 2026
High · CVSS 7.2 · CISA KEV
Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025.
Published Dec 5, 2025 · Updated Feb 26, 2026
High · CVSS 7.8 · CISA KEV
In multiple locations, there is a possible way to launch activities from the background due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published Dec 8, 2025 · Updated Feb 26, 2026
Critical · CVSS 9.8 · CISA KEV
Lanscope Endpoint Manager (On-Premises) (Client program (MR) and Detection agent (DA)) improperly verifies the origin of incoming requests, allowing an attacker to execute arbitrary code by sending specially crafted packets.
Published Oct 20, 2025 · Updated Feb 26, 2026
Critical · CVSS 9.8 · CISA KEV
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Identity Manager. Successful attacks of this vulnerability can result in takeover of Identity Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published Oct 21, 2025 · Updated Feb 26, 2026
High · CVSS 7 · CISA KEV
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.
Published Nov 11, 2025 · Updated Feb 26, 2026
Medium · CVSS 5.5 · CISA KEV
In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published Dec 8, 2025 · Updated Feb 26, 2026
Critical · CVSS 9.4 · CISA KEV
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.
Published Nov 14, 2025 · Updated Feb 26, 2026
Medium · CVSS 6.7 · CISA KEV
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an authenticated attacker to execute unauthorized code on the underlying system via crafted HTTP requests or CLI commands.
Published Nov 18, 2025 · Updated Feb 26, 2026
High · CVSS 8.7 · CISA KEV
Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code.
Published Dec 10, 2025 · Updated Feb 26, 2026
High · CVSS 8.8 · CISA KEV
Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
Published Dec 12, 2025 · Updated Feb 26, 2026
High · CVSS 7.1 · CISA KEV
Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of the AES cryptoscheme. This degrades security for public exposed endpoints that may make use of it and may offer arbitrary local file inclusion when provided a specially crafted request without authentication. This opens the door for future exploitation and can be leveraged with previous vulnerabilities to gain a full system compromise.
Published Dec 12, 2025 · Updated Feb 26, 2026
Critical · CVSS 10 · CISA KEV
A remote code execution issue exists in HPE OneView.
Published Dec 16, 2025 · Updated Feb 26, 2026
Critical · CVSS 9.3 · CISA KEV
"UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause devices meeting specific targeting conditions to perform unintended actions. Only devices that met these conditions and installed the compromised versions were affected. The Live Update client has already reached End-of-Support (EOS) in October 2021, and no currently supported devices or products are affected by this issue.
Published Dec 17, 2025 · Updated Feb 26, 2026
Critical · CVSS 10 · CISA KEV
A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to execute arbitrary system commands on an affected device with root privileges.
This vulnerability is due to insufficient validation of HTTP requests by the Spam Quarantine feature. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with root privileges.
Published Dec 17, 2025 · Updated Feb 26, 2026
High · CVSS 7.2 · CISA KEV
Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.
Published Dec 18, 2025 · Updated Feb 26, 2026
High · CVSS 8.2 · CISA KEV
GeoServer is an open source server that allows users to share and edit geospatial data. From version 2.26.0 to before 2.26.2 and before 2.25.6, an XML External Entity (XXE) vulnerability was identified. The application accepts XML input through a specific endpoint /geoserver/wms operation GetMap. However, this input is not sufficiently sanitized or restricted, allowing an attacker to define external entities within the XML request. This issue has been patched in GeoServer 2.25.6, GeoServer 2.26.3, and GeoServer 2.27.0.
Published Nov 25, 2025 · Updated Feb 26, 2026
Critical · CVSS 9.3 · CISA KEV
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the Mobile User VPN with IKEv2 and the Branch Office VPN using IKEv2 when configured with a dynamic gateway peer.This vulnerability affects Fireware OS 11.10.2 up to and including 11.12.4_Update1, 12.0 up to and including 12.11.5 and 2025.1 up to and including 2025.1.3.
Published Dec 19, 2025 · Updated Feb 26, 2026
High · CVSS 8.7 · CISA KEV
Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, MongoDB Server v6.0 versions prior to 6.0.27, MongoDB Server v5.0 versions prior to 5.0.32, MongoDB Server v4.4 versions prior to 4.4.30, MongoDB Server v4.2 versions greater than or equal to 4.2.0, MongoDB Server v4.0 versions greater than or equal to 4.0.0, and MongoDB Server v3.6 versions greater than or equal to 3.6.0.
Published Dec 19, 2025 · Updated Feb 26, 2026
High · CVSS 8.8 · CISA KEV
A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper handling of user-supplied request parameters in the RestFilter servlet. An unauthenticated remote attacker can craft requests to the /h/rest endpoint to influence internal request dispatching, allowing inclusion of arbitrary files from the WebRoot directory.
Published Dec 22, 2025 · Updated Feb 26, 2026
Critical · CVSS 10 · CISA KEV
Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.
Published Dec 29, 2025 · Updated Feb 26, 2026
High · CVSS 8.1 · CISA KEV
SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated attacker to gain access to certain restricted functionality.
Published Jan 28, 2026 · Updated Feb 26, 2026
Critical · CVSS 9.8 · CISA KEV
SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication.
Published Jan 28, 2026 · Updated Feb 26, 2026
Critical · CVSS 9.8 · CISA KEV
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
Published Jan 29, 2026 · Updated Feb 26, 2026
Critical · CVSS 9.9 · CISA KEV
BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the context of the site user.
Published Feb 6, 2026 · Updated Feb 26, 2026
High · CVSS 8.2 · CISA KEV
A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unity Connection, and Cisco Webex Calling Dedicated Instance could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device.
This vulnerability is due to improper validation of user-supplied input in HTTP requests. An attacker could exploit this vulnerability by sending a sequence of crafted HTTP requests to the web-based management interface of an affected device. A successful exploit could allow the attacker to obtain user-level access to the underlying operating system and then elevate privileges to root.
Note: Cisco has assigned this security advisory a Security Impact Rating (SIR) of Critical rather than High as the score indicates. The reason is that exploitation of this vulnerability could result in an attacker elevating privileges to root.
Published Jan 21, 2026 · Updated Feb 26, 2026
High · CVSS 8.8 · CISA KEV
FileZen contains an OS command injection vulnerability. When FileZen Antivirus Check Option is enabled, a logged-in user may send a specially crafted HTTP request to execute an arbitrary OS command.
Published Feb 13, 2026 · Updated Feb 26, 2026
High · CVSS 8.8 · CISA KEV
Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published Feb 13, 2026 · Updated Feb 26, 2026
Critical · CVSS 10 · CISA KEV
Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability. This is considered critical as an unauthenticated remote attacker with knowledge of the hardcoded credential could potentially exploit this vulnerability leading to unauthorized access to the underlying operating system and root-level persistence. Dell recommends that customers upgrade or apply one of the remediations as soon as possible.
Published Feb 17, 2026 · Updated Feb 26, 2026
Medium · CVSS 5.3 · CISA KEV
An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.
Published Feb 16, 2023 · Updated Feb 26, 2026
Critical · CVSS 9.9 · CISA KEV
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.
Published Jun 2, 2025 · Updated Feb 21, 2026
Medium · CVSS 6.8 · CISA KEV
When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is disabled
Published Jun 11, 2021 · Updated Feb 19, 2026
High · CVSS 8.8 · CISA KEV
Stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL), as used in the MPEG2TuneRequest ActiveX control in msvidctl.dll in DirectShow, in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted web page, as exploited in the wild in July 2009, aka "Microsoft Video ActiveX Control Vulnerability."
Published Jul 7, 2009 · Updated Feb 18, 2026
Critical · CVSS 9.8 · CISA KEV
Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 allows SSRF when WebEx zimlet is installed and zimlet JSP is enabled.
Published Feb 18, 2020 · Updated Feb 18, 2026
High · CVSS 7.2 · CISA KEV
ThreatSonar Anti-Ransomware from TeamT5 does not properly validate the content of uploaded files. Remote attackers with administrator privileges on the product platform can upload malicious files, which can be used to execute arbitrary system command on the server.
Published Aug 12, 2024 · Updated Feb 18, 2026
High · CVSS 8.6 · CISA KEV
FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions 17.0.2.36 and above before 17.0.3, the filestore module within the Administrative interface is vulnerable to a post-authentication command injection by an authenticated known user via the testconnection -> check_ssh_connect() function. An attacker can leverage this vulnerability to obtain remote access to the system as an asterisk user. This issue is fixed in version 17.0.3.
Published Nov 7, 2025 · Updated Feb 13, 2026
High · CVSS 8.2 · CISA KEV
An improper access control vulnerability in Power Pages allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control.
This vulnerability has already been mitigated in the service and all affected customers have been notified. This update addressed the registration control bypass. Affected customers have been given instructions on reviewing their sites for potential exploitation and clean up methods. If you've not been notified this vulnerability does not affect you.
Published Feb 19, 2025 · Updated Feb 13, 2026
Medium · CVSS 6.5 · CISA KEV
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
Published Mar 11, 2025 · Updated Feb 13, 2026
High · CVSS 7.8 · CISA KEV
Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
Published Apr 8, 2025 · Updated Feb 13, 2026
High · CVSS 8.8 · CISA KEV
Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Published Jul 8, 2025 · Updated Feb 13, 2026
High · CVSS 7.2 · CISA KEV
Microsoft SharePoint Remote Code Execution Vulnerability
Published Jul 9, 2024 · Updated Feb 10, 2026
High · CVSS 7.5 · CISA KEV
Windows MSHTML Platform Spoofing Vulnerability
Published Jul 9, 2024 · Updated Feb 10, 2026
High · CVSS 7.8 · CISA KEV
Windows Hyper-V Elevation of Privilege Vulnerability
Published Jul 9, 2024 · Updated Feb 10, 2026
Critical · CVSS 10 · CISA KEV
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.1.1 sometimes allows unauthenticated users to execute commands.
Published Oct 2, 2024 · Updated Feb 3, 2026
Critical · CVSS 9.8 · CISA KEV
Sangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below have Incorrect Access Control.
Published Nov 21, 2019 · Updated Feb 3, 2026
Medium · CVSS 6.8 · CISA KEV
An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Unauthorized external users could perform Server Side Requests via the CI Lint API
Published Dec 13, 2021 · Updated Feb 3, 2026
High · CVSS 7.8 · CISA KEV
An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise privileged) binary could use this flaw to escalate their privileges on the system. Kernel versions 2.6.x, 3.10.x and 4.14.x are believed to be vulnerable.
Published Sep 25, 2018 · Updated Jan 27, 2026
Critical · CVSS 9.8 · CISA KEV
vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.
Published Jun 18, 2024 · Updated Jan 24, 2026
Medium · CVSS 5.3 · CISA KEV
Vite is a frontend tooling framework for javascript. Vite exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicitly exposing the Vite dev server to the network (using --host or server.host config option) are affected. This vulnerability is fixed in 6.2.4, 6.1.3, 6.0.13, 5.4.16, and 4.5.11.
Published Mar 31, 2025 · Updated Jan 23, 2026