Catalogue CISA KEV
Ajouts KEV — août 2026
26 CVE sont entrées au catalogue KEV en août 2026.
Ajoutées le 31 août 20262
| CVE | Vulnérabilité | CVSS | EPSS | Échéance |
|---|---|---|---|---|
| CVE-2026-81578 | PaperCut NG/MF Missing Authentication for Critical Function Vulnerability | — | 0.4 % | 14 septembre 2026 |
| CVE-2026-82078 | PaperCut NG/MF Unsafe Reflection Vulnerability | — | 0.5 % | 14 septembre 2026 |
Ajoutées le 27 août 20262
| CVE | Vulnérabilité | CVSS | EPSS | Échéance |
|---|---|---|---|---|
| CVE-2026-53362 | Linux Kernel Unspecified Vulnerability | — | 0.2 % | 30 août 2026 |
| CVE-2026-66384 | JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability | 5.3 | 0.3 % | 10 septembre 2026 |
Ajoutées le 26 août 20264
| CVE | Vulnérabilité | CVSS | EPSS | Échéance |
|---|---|---|---|---|
| CVE-2019-1068 | Microsoft SQL Server Remote Code Execution Vulnerability | 8.8 | 41.6 % | 29 août 2026 |
| CVE-2021-23758 | Ajax.NET Professional Deserialization of Untrusted Data Vulnerability | 9.8 | 87.8 % | 9 septembre 2026 |
| CVE-2022-0995 | Linux Kernel Out-of-Bounds Write Vulnerability | 7.8 | 20.5 % | 9 septembre 2026 |
| CVE-2026-8452 | Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability | 9.8 | 0.4 % | 29 août 2026 |
Ajoutées le 25 août 20261
| CVE | Vulnérabilité | CVSS | EPSS | Échéance |
|---|---|---|---|---|
| CVE-2026-60004 | Gitea Code Injection Vulnerability | 9.8 | 82.4 % | 28 août 2026 |
Ajoutées le 24 août 20261
| CVE | Vulnérabilité | CVSS | EPSS | Échéance |
|---|---|---|---|---|
| CVE-2026-21962 | Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability | 10 | 0.0 % | 27 août 2026 |
Ajoutées le 21 août 20262
| CVE | Vulnérabilité | CVSS | EPSS | Échéance |
|---|---|---|---|---|
| CVE-2026-69836 | Microsoft Entra ID Deserialization of Untrusted Data Vulnerability | 10 | 1.4 % | 24 août 2026 |
| CVE-2026-73570 | Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability | 8.9 | 0.5 % | 24 août 2026 |
Ajoutées le 20 août 20262
| CVE | Vulnérabilité | CVSS | EPSS | Échéance |
|---|---|---|---|---|
| CVE-2026-72529 | TrueConf Server Missing Authentication for Critical Function Vulnerability | 9.8 | 0.8 % | 23 août 2026 |
| CVE-2026-72530 | TrueConf Server Code Injection Vulnerability | 9 | 1.0 % | 3 septembre 2026 |
Ajoutées le 19 août 20261
| CVE | Vulnérabilité | CVSS | EPSS | Échéance |
|---|---|---|---|---|
| CVE-2026-64849 | MLflow Server-Side Request Forgery Vulnerability | 9.3 | 1.1 % | 2 septembre 2026 |
Ajoutées le 18 août 20264
| CVE | Vulnérabilité | CVSS | EPSS | Échéance |
|---|---|---|---|---|
| CVE-2026-33824 | Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability | 9.8 | 0.1 % | 21 août 2026 |
| CVE-2026-55040 | Microsoft SharePoint Weak Authentication Vulnerability | 9.1 | 0.7 % | 21 août 2026 |
| CVE-2026-59310 | vCenter directory-traversal vulnerability | 9.8 | 1.1 % | 21 août 2026 |
| CVE-2026-65400 | Apple macOS Improper Authentication Vulnerability | 7.1 | 0.3 % | 21 août 2026 |
Ajoutées le 11 août 20263
| CVE | Vulnérabilité | CVSS | EPSS | Échéance |
|---|---|---|---|---|
| CVE-2026-20349 | Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability | 8.6 | 1.0 % | 14 août 2026 |
| CVE-2026-68820 | Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability | 7 | 0.4 % | 25 août 2026 |
| CVE-2026-72898 | Metabase SQL Injection Vulnerability | 10 | 0.7 % | 14 août 2026 |
Ajoutées le 5 août 20261
| CVE | Vulnérabilité | CVSS | EPSS | Échéance |
|---|---|---|---|---|
| CVE-2026-63077 | JetBrains TeamCity Deserialization of Untrusted Data Vulnerability | 9.8 | 0.6 % | 8 août 2026 |
Ajoutées le 4 août 20262
| CVE | Vulnérabilité | CVSS | EPSS | Échéance |
|---|---|---|---|---|
| CVE-2026-18556 | N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability | — | 0.3 % | 7 août 2026 |
| CVE-2026-9198 | Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation | 9.8 | 0.4 % | 7 août 2026 |
Ajoutées le 3 août 20261
| CVE | Vulnérabilité | CVSS | EPSS | Échéance |
|---|---|---|---|---|
| CVE-2026-18577 | N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability | 8.1 | 2.5 % | 6 août 2026 |