[{"snapshot_month":"2026-09","fetched_at":"2026-09-01T00:00:00+00:00","cve_id":"CVE-2026-20316","vendor_canonical":"Cisco","vendor_raw":"Cisco","product":"Secure Firewall Management Center (FMC)","vulnerability_name":"Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability","short_description":"Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.","cwes":"CWE-259","date_added":"2026-07-29","due_date":"2026-08-01","days_since_added":34,"days_to_due":-31,"overdue_flag":1,"ransomware_flag":1,"forensic_triage":"No","required_action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","notes":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-20316","kev_catalog_version":"2026.09.24","kev_date_released":"2026-09-24T19:00:55.0481Z","kev_source_url":"https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json","epss":0.35096,"epss_percentile":0.98386,"epss_date":"2026-09-24T12:00:20Z","epss_tier":"low","epss_missing":0,"epss_source_url":"https://epss.empiricalsecurity.com/epss_scores-current.csv.gz","priority_score":97.58,"priority_tier":"p1","exploit_rank":1},{"snapshot_month":"2026-09","fetched_at":"2026-09-01T00:00:00+00:00","cve_id":"CVE-2026-63077","vendor_canonical":"JetBrains","vendor_raw":"JetBrains","product":"TeamCity","vulnerability_name":"JetBrains TeamCity Deserialization of Untrusted Data Vulnerability","short_description":"JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol.","cwes":"CWE-502","date_added":"2026-08-05","due_date":"2026-08-08","days_since_added":27,"days_to_due":-24,"overdue_flag":1,"ransomware_flag":1,"forensic_triage":"Yes","required_action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","notes":"https://blog.jetbrains.com/teamcity/2026/07/cve-2026-63077/; https://www.jetbrains.com/privacy-security/issues-fixed/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-63077","kev_catalog_version":"2026.09.24","kev_date_released":"2026-09-24T19:00:55.0481Z","kev_source_url":"https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json","epss":0.09763,"epss_percentile":0.95358,"epss_date":"2026-09-24T12:00:20Z","epss_tier":"low","epss_missing":0,"epss_source_url":"https://epss.empiricalsecurity.com/epss_scores-current.csv.gz","priority_score":96.72,"priority_tier":"p1","exploit_rank":2},{"snapshot_month":"2026-09","fetched_at":"2026-09-01T00:00:00+00:00","cve_id":"CVE-2026-12569","vendor_canonical":"PTC","vendor_raw":"PTC","product":"Windchill and FlexPLM","vulnerability_name":"PTC Windchill and FlexPLM Improper Input Validation Vulnerability","short_description":"PTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attacker to execute arbitrary code by sending a malicious request to the network.","cwes":"CWE-20,CWE-502","date_added":"2026-06-25","due_date":"2026-06-28","days_since_added":68,"days_to_due":-65,"overdue_flag":1,"ransomware_flag":1,"forensic_triage":"No","required_action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","notes":"https://www.ptc.com/en/support/article/CS473270 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-12569","kev_catalog_version":"2026.09.24","kev_date_released":"2026-09-24T19:00:55.0481Z","kev_source_url":"https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json","epss":0.46049,"epss_percentile":0.98767,"epss_date":"2026-09-24T12:00:20Z","epss_tier":"low","epss_missing":0,"epss_source_url":"https://epss.empiricalsecurity.com/epss_scores-current.csv.gz","priority_score":96.11,"priority_tier":"p1","exploit_rank":3},{"snapshot_month":"2026-09","fetched_at":"2026-09-01T00:00:00+00:00","cve_id":"CVE-2026-15410","vendor_canonical":"SonicWall","vendor_raw":"SonicWall","product":"SMA1000 Appliances","vulnerability_name":"SonicWall SMA1000 Appliances Code Injection Vulnerability","short_description":"SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.","cwes":"CWE-94","date_added":"2026-07-14","due_date":"2026-07-17","days_since_added":49,"days_to_due":-46,"overdue_flag":1,"ransomware_flag":1,"forensic_triage":"Yes","required_action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","notes":"https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-15410","kev_catalog_version":"2026.09.24","kev_date_released":"2026-09-24T19:00:55.0481Z","kev_source_url":"https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json","epss":0.11791,"epss_percentile":0.95933,"epss_date":"2026-09-24T12:00:20Z","epss_tier":"low","epss_missing":0,"epss_source_url":"https://epss.empiricalsecurity.com/epss_scores-current.csv.gz","priority_score":95.86,"priority_tier":"p1","exploit_rank":4},{"snapshot_month":"2026-09","fetched_at":"2026-09-01T00:00:00+00:00","cve_id":"CVE-2026-0257","vendor_canonical":"Palo Alto Networks","vendor_raw":"Palo Alto Networks","product":"PAN-OS","vulnerability_name":"Palo Alto Networks PAN-OS Authentication Bypass Vulnerability","short_description":"Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection.","cwes":"CWE-565","date_added":"2026-05-29","due_date":"2026-06-01","days_since_added":95,"days_to_due":-92,"overdue_flag":1,"ransomware_flag":1,"forensic_triage":"No","required_action":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","notes":"https://security.paloaltonetworks.com/CVE-2026-0257 ; https://nvd.nist.gov/vuln/detail/CVE-2026-0257","kev_catalog_version":"2026.09.24","kev_date_released":"2026-09-24T19:00:55.0481Z","kev_source_url":"https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json","epss":0.96895,"epss_percentile":0.99887,"epss_date":"2026-09-24T12:00:20Z","epss_tier":"critical","epss_missing":0,"epss_source_url":"https://epss.empiricalsecurity.com/epss_scores-current.csv.gz","priority_score":95.37,"priority_tier":"p1","exploit_rank":5},{"snapshot_month":"2026-09","fetched_at":"2026-09-01T00:00:00+00:00","cve_id":"CVE-2026-15409","vendor_canonical":"SonicWall","vendor_raw":"SonicWall","product":"SMA1000 Appliances","vulnerability_name":"SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability","short_description":"SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.","cwes":"CWE-918","date_added":"2026-07-14","due_date":"2026-07-17","days_since_added":49,"days_to_due":-46,"overdue_flag":1,"ransomware_flag":1,"forensic_triage":"Yes","required_action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","notes":"https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-15409","kev_catalog_version":"2026.09.24","kev_date_released":"2026-09-24T19:00:55.0481Z","kev_source_url":"https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json","epss":0.06795,"epss_percentile":0.93755,"epss_date":"2026-09-24T12:00:20Z","epss_tier":"low","epss_missing":0,"epss_source_url":"https://epss.empiricalsecurity.com/epss_scores-current.csv.gz","priority_score":94.99,"priority_tier":"p1","exploit_rank":6},{"snapshot_month":"2026-09","fetched_at":"2026-09-01T00:00:00+00:00","cve_id":"CVE-2026-41940","vendor_canonical":"WebPros","vendor_raw":"WebPros","product":"cPanel & WHM and WP2 (WordPress Squared)","vulnerability_name":"WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability","short_description":"WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.","cwes":"CWE-306","date_added":"2026-04-30","due_date":"2026-05-03","days_since_added":124,"days_to_due":-121,"overdue_flag":1,"ransomware_flag":1,"forensic_triage":"No","required_action":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","notes":"https://support.cpanel.net/hc/en-us/articles/40073787579671-cPanel-WHM-Security-Update-04-28-2026 ; https://docs.cpanel.net/release-notes/release-notes/ ; https://docs.wpsquared.com/changelogs/versions/changelog/#13617 ; https://nvd.nist.gov/vuln/detail/CVE-2026-41940\"","kev_catalog_version":"2026.09.24","kev_date_released":"2026-09-24T19:00:55.0481Z","kev_source_url":"https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json","epss":0.98527,"epss_percentile":0.9992,"epss_date":"2026-09-24T12:00:20Z","epss_tier":"critical","epss_missing":0,"epss_source_url":"https://epss.empiricalsecurity.com/epss_scores-current.csv.gz","priority_score":94.21,"priority_tier":"p1","exploit_rank":7},{"snapshot_month":"2026-09","fetched_at":"2026-09-01T00:00:00+00:00","cve_id":"CVE-2026-35273","vendor_canonical":"Oracle","vendor_raw":"Oracle","product":"PeopleSoft Enterprise PeopleTools","vulnerability_name":"Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability","short_description":"Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise PeopleTools.","cwes":"CWE-306","date_added":"2026-06-12","due_date":"2026-06-15","days_since_added":81,"days_to_due":-78,"overdue_flag":1,"ransomware_flag":1,"forensic_triage":"No","required_action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","notes":"https://www.oracle.com/security-alerts/alert-cve-2026-35273.html ; https://support.oracle.com/signin/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-35273","kev_catalog_version":"2026.09.24","kev_date_released":"2026-09-24T19:00:55.0481Z","kev_source_url":"https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json","epss":0.09444,"epss_percentile":0.95243,"epss_date":"2026-09-24T12:00:20Z","epss_tier":"low","epss_missing":0,"epss_source_url":"https://epss.empiricalsecurity.com/epss_scores-current.csv.gz","priority_score":94.12,"priority_tier":"p1","exploit_rank":8},{"snapshot_month":"2026-09","fetched_at":"2026-09-01T00:00:00+00:00","cve_id":"CVE-2024-1708","vendor_canonical":"ConnectWise","vendor_raw":"ConnectWise","product":"ScreenConnect","vulnerability_name":"ConnectWise ScreenConnect Path Traversal Vulnerability","short_description":"ConnectWise ScreenConnect contains a path traversal vulnerability which could allow an attacker to execute remote code or directly impact confidential data and critical systems.","cwes":"CWE-22","date_added":"2026-04-28","due_date":"2026-05-12","days_since_added":126,"days_to_due":-112,"overdue_flag":1,"ransomware_flag":1,"forensic_triage":"No","required_action":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","notes":"https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8 ; https://nvd.nist.gov/vuln/detail/CVE-2024-1708","kev_catalog_version":"2026.09.24","kev_date_released":"2026-09-24T19:00:55.0481Z","kev_source_url":"https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json","epss":0.95436,"epss_percentile":0.99868,"epss_date":"2026-09-24T12:00:20Z","epss_tier":"critical","epss_missing":0,"epss_source_url":"https://epss.empiricalsecurity.com/epss_scores-current.csv.gz","priority_score":94.11,"priority_tier":"p1","exploit_rank":9},{"snapshot_month":"2026-09","fetched_at":"2026-09-01T00:00:00+00:00","cve_id":"CVE-2024-27199","vendor_canonical":"JetBrains","vendor_raw":"JetBrains","product":"TeamCity","vulnerability_name":"JetBrains TeamCity Relative Path Traversal Vulnerability","short_description":"JetBrains TeamCity contains a relative path traversal vulnerability that could allow limited admin actions to be performed.","cwes":"CWE-23","date_added":"2026-04-20","due_date":"2026-05-04","days_since_added":134,"days_to_due":-120,"overdue_flag":1,"ransomware_flag":1,"forensic_triage":"No","required_action":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","notes":"https://www.jetbrains.com/privacy-security/issues-fixed/ ; https://blog.jetbrains.com/teamcity/2024/03/additional-critical-security-issues-affecting-teamcity-on-premises-cve-2024-27198-and-cve-2024-27199-update-to-2023-11-4-now/ ; https://nvd.nist.gov/vuln/detail/CVE-2024-27199","kev_catalog_version":"2026.09.24","kev_date_released":"2026-09-24T19:00:55.0481Z","kev_source_url":"https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json","epss":0.99991,"epss_percentile":0.99986,"epss_date":"2026-09-24T12:00:20Z","epss_tier":"critical","epss_missing":0,"epss_source_url":"https://epss.empiricalsecurity.com/epss_scores-current.csv.gz","priority_score":93.85,"priority_tier":"p1","exploit_rank":10},{"snapshot_month":"2026-09","fetched_at":"2026-09-01T00:00:00+00:00","cve_id":"CVE-2024-57726","vendor_canonical":"SimpleHelp","vendor_raw":"SimpleHelp","product":"SimpleHelp","vulnerability_name":"SimpleHelp Missing Authorization Vulnerability","short_description":"SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.","cwes":"CWE-862","date_added":"2026-04-24","due_date":"2026-05-08","days_since_added":130,"days_to_due":-116,"overdue_flag":1,"ransomware_flag":1,"forensic_triage":"No","required_action":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","notes":"https://simple-help.com/kb---security-vulnerabilities-01-2025#security-vulnerabilities-in-simplehelp-5-5-7-and-earlier ; https://nvd.nist.gov/vuln/detail/CVE-2024-57726","kev_catalog_version":"2026.09.24","kev_date_released":"2026-09-24T19:00:55.0481Z","kev_source_url":"https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json","epss":0.66601,"epss_percentile":0.99264,"epss_date":"2026-09-24T12:00:20Z","epss_tier":"medium","epss_missing":0,"epss_source_url":"https://epss.empiricalsecurity.com/epss_scores-current.csv.gz","priority_score":93.71,"priority_tier":"p1","exploit_rank":11},{"snapshot_month":"2026-09","fetched_at":"2026-09-01T00:00:00+00:00","cve_id":"CVE-2023-27351","vendor_canonical":"PaperCut","vendor_raw":"PaperCut","product":"NG/MF","vulnerability_name":"PaperCut NG/MF Improper Authentication Vulnerability","short_description":"PaperCut NG/MF contains an improper authentication vulnerability that could allow remote attackers to bypass authentication on affected installations via the SecurityRequestFilter class.","cwes":"CWE-287","date_added":"2026-04-20","due_date":"2026-05-04","days_since_added":134,"days_to_due":-120,"overdue_flag":1,"ransomware_flag":1,"forensic_triage":"No","required_action":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","notes":"https://www.papercut.com/kb/Main/PO-1216-and-PO-1219 ; https://nvd.nist.gov/vuln/detail/CVE-2023-27351","kev_catalog_version":"2026.09.24","kev_date_released":"2026-09-24T19:00:55.0481Z","kev_source_url":"https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json","epss":0.78052,"epss_percentile":0.99562,"epss_date":"2026-09-24T12:00:20Z","epss_tier":"high","epss_missing":0,"epss_source_url":"https://epss.empiricalsecurity.com/epss_scores-current.csv.gz","priority_score":93.68,"priority_tier":"p1","exploit_rank":12},{"snapshot_month":"2026-09","fetched_at":"2026-09-01T00:00:00+00:00","cve_id":"CVE-2023-21529","vendor_canonical":"Microsoft","vendor_raw":"Microsoft","product":"Exchange Server","vulnerability_name":"Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability","short_description":"Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution.","cwes":"CWE-502","date_added":"2026-04-13","due_date":"2026-04-27","days_since_added":141,"days_to_due":-127,"overdue_flag":1,"ransomware_flag":1,"forensic_triage":"No","required_action":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","notes":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21529 ; https://nvd.nist.gov/vuln/detail/CVE-2023-21529","kev_catalog_version":"2026.09.24","kev_date_released":"2026-09-24T19:00:55.0481Z","kev_source_url":"https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json","epss":0.59294,"epss_percentile":0.99088,"epss_date":"2026-09-24T12:00:20Z","epss_tier":"medium","epss_missing":0,"epss_source_url":"https://epss.empiricalsecurity.com/epss_scores-current.csv.gz","priority_score":93.23,"priority_tier":"p1","exploit_rank":13},{"snapshot_month":"2026-09","fetched_at":"2026-09-01T00:00:00+00:00","cve_id":"CVE-2026-50751","vendor_canonical":"Check Point","vendor_raw":"Check Point","product":"Security Gateway","vulnerability_name":"Check Point Security Gateway Improper Authentication Vulnerability","short_description":"Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.","cwes":"CWE-287","date_added":"2026-06-08","due_date":"2026-06-11","days_since_added":85,"days_to_due":-82,"overdue_flag":1,"ransomware_flag":1,"forensic_triage":"No","required_action":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","notes":"https://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/ ; https://support.checkpoint.com/results/sk/sk185033?_gl=1*1wqeqhc*_gcl_au*MTI1MzE5MjI2LjE3ODA5MzQ1NTM. ; https://nvd.nist.gov/vuln/detail/CVE-2026-50751","kev_catalog_version":"2026.09.24","kev_date_released":"2026-09-24T19:00:55.0481Z","kev_source_url":"https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json","epss":0.06301,"epss_percentile":0.93343,"epss_date":"2026-09-24T12:00:20Z","epss_tier":"low","epss_missing":0,"epss_source_url":"https://epss.empiricalsecurity.com/epss_scores-current.csv.gz","priority_score":93.18,"priority_tier":"p1","exploit_rank":14},{"snapshot_month":"2026-09","fetched_at":"2026-09-01T00:00:00+00:00","cve_id":"CVE-2026-59310","vendor_canonical":"Broadcom","vendor_raw":"Broadcom","product":"VMware vCenter","vulnerability_name":"Broadcom VMware vCenter Path Traversal Vulnerability","short_description":"Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code.","cwes":"CWE-22","date_added":"2026-08-18","due_date":"2026-08-21","days_since_added":14,"days_to_due":-11,"overdue_flag":1,"ransomware_flag":1,"forensic_triage":"Yes","required_action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","notes":"https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-59310","kev_catalog_version":"2026.09.24","kev_date_released":"2026-09-24T19:00:55.0481Z","kev_source_url":"https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json","epss":0.02565,"epss_percentile":0.84449,"epss_date":"2026-09-24T12:00:20Z","epss_tier":"low","epss_missing":0,"epss_source_url":"https://epss.empiricalsecurity.com/epss_scores-current.csv.gz","priority_score":93.03,"priority_tier":"p1","exploit_rank":15},{"snapshot_month":"2026-09","fetched_at":"2026-09-01T00:00:00+00:00","cve_id":"CVE-2025-26399","vendor_canonical":"SolarWinds","vendor_raw":"SolarWinds","product":"Web Help Desk","vulnerability_name":"SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability","short_description":"SolarWinds Web Help Desk contain a deserialization of untrusted data vulnerability in AjaxProxy that could allow an attacker to run commands on the host machine.","cwes":"CWE-502","date_added":"2026-03-09","due_date":"2026-03-12","days_since_added":176,"days_to_due":-173,"overdue_flag":1,"ransomware_flag":1,"forensic_triage":"No","required_action":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","notes":"https://www.solarwinds.com/trust-center/security-advisories/cve-2025-26399 ; https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_12-8-7-hotfix-1_release_notes.htm ; https://nvd.nist.gov/vuln/detail/CVE-2025-26399","kev_catalog_version":"2026.09.24","kev_date_released":"2026-09-24T19:00:55.0481Z","kev_source_url":"https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json","epss":0.895,"epss_percentile":0.99782,"epss_date":"2026-09-24T12:00:20Z","epss_tier":"high","epss_missing":0,"epss_source_url":"https://epss.empiricalsecurity.com/epss_scores-current.csv.gz","priority_score":92.26,"priority_tier":"p1","exploit_rank":16},{"snapshot_month":"2026-09","fetched_at":"2026-09-01T00:00:00+00:00","cve_id":"CVE-2026-20131","vendor_canonical":"Cisco","vendor_raw":"Cisco","product":"Secure Firewall Management Center (FMC)","vulnerability_name":"Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability","short_description":"Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain a deserialization of untrusted data vulnerability in the web-based management interface that could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device.","cwes":"CWE-502","date_added":"2026-03-19","due_date":"2026-03-22","days_since_added":166,"days_to_due":-163,"overdue_flag":1,"ransomware_flag":1,"forensic_triage":"No","required_action":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","notes":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-rce-NKhnULJh ; https://nvd.nist.gov/vuln/detail/CVE-2026-20131","kev_catalog_version":"2026.09.24","kev_date_released":"2026-09-24T19:00:55.0481Z","kev_source_url":"https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json","epss":0.42665,"epss_percentile":0.98664,"epss_date":"2026-09-24T12:00:20Z","epss_tier":"low","epss_missing":0,"epss_source_url":"https://epss.empiricalsecurity.com/epss_scores-current.csv.gz","priority_score":92.16,"priority_tier":"p1","exploit_rank":17},{"snapshot_month":"2026-09","fetched_at":"2026-09-01T00:00:00+00:00","cve_id":"CVE-2024-57728","vendor_canonical":"SimpleHelp","vendor_raw":"SimpleHelp","product":"SimpleHelp","vulnerability_name":"SimpleHelp Path Traversal Vulnerability","short_description":"SimpleHelp contains a path traversal vulnerability that allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user.","cwes":"CWE-22","date_added":"2026-04-24","due_date":"2026-05-08","days_since_added":130,"days_to_due":-116,"overdue_flag":1,"ransomware_flag":1,"forensic_triage":"No","required_action":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","notes":"https://simple-help.com/kb---security-vulnerabilities-01-2025#security-vulnerabilities-in-simplehelp-5-5-7-and-earlier ; https://nvd.nist.gov/vuln/detail/CVE-2024-57728","kev_catalog_version":"2026.09.24","kev_date_released":"2026-09-24T19:00:55.0481Z","kev_source_url":"https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json","epss":0.06982,"epss_percentile":0.93902,"epss_date":"2026-09-24T12:00:20Z","epss_tier":"low","epss_missing":0,"epss_source_url":"https://epss.empiricalsecurity.com/epss_scores-current.csv.gz","priority_score":91.57,"priority_tier":"p1","exploit_rank":18},{"snapshot_month":"2026-09","fetched_at":"2026-09-01T00:00:00+00:00","cve_id":"CVE-2026-1731","vendor_canonical":"BeyondTrust","vendor_raw":"BeyondTrust","product":"Remote Support (RS) and Privileged Remote Access (PRA)","vulnerability_name":"BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability","short_description":"BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)contain an OS command injection vulnerability. Successful exploitation could allow an unauthenticated remote attacker to execute operating system commands in the context of the site user. Successful exploitation requires no authentication or user interaction and may lead to system compromise, including unauthorized access, data exfiltration, and service disruption.","cwes":"CWE-78","date_added":"2026-02-13","due_date":"2026-02-16","days_since_added":200,"days_to_due":-197,"overdue_flag":1,"ransomware_flag":1,"forensic_triage":"No","required_action":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","notes":"Please adhere to the vendor's guidelines to assess exposure and mitigate risks. Check for signs of potential compromise on all internet accessible BeyondTrust products affected by this vulnerability. For more information please: see: https://www.beyondtrust.com/trust-center/security-advisories/bt26-02 ; https://nvd.nist.gov/vuln/detail/CVE-2026-1731","kev_catalog_version":"2026.09.24","kev_date_released":"2026-09-24T19:00:55.0481Z","kev_source_url":"https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json","epss":0.90691,"epss_percentile":0.99801,"epss_date":"2026-09-24T12:00:20Z","epss_tier":"critical","epss_missing":0,"epss_source_url":"https://epss.empiricalsecurity.com/epss_scores-current.csv.gz","priority_score":91.48,"priority_tier":"p1","exploit_rank":19},{"snapshot_month":"2026-09","fetched_at":"2026-09-01T00:00:00+00:00","cve_id":"CVE-2026-24423","vendor_canonical":"SmarterTools","vendor_raw":"SmarterTools","product":"SmarterMail","vulnerability_name":"SmarterTools SmarterMail Missing Authentication for Critical Function Vulnerability","short_description":"SmarterTools SmarterMail contains a missing authentication for critical function vulnerability in the ConnectToHub API method. This could allow the attacker to point the SmarterMail instance to a malicious HTTP server which serves the malicious OS command and could lead to command execution.","cwes":"CWE-306","date_added":"2026-02-05","due_date":"2026-02-26","days_since_added":208,"days_to_due":-187,"overdue_flag":1,"ransomware_flag":1,"forensic_triage":"No","required_action":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","notes":"https://www.smartertools.com/smartermail/release-notes/current ; https://www.cve.org/CVERecord?id=CVE-2026-24423 ; https://nvd.nist.gov/vuln/detail/CVE-2026-24423","kev_catalog_version":"2026.09.24","kev_date_released":"2026-09-24T19:00:55.0481Z","kev_source_url":"https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json","epss":0.88177,"epss_percentile":0.99764,"epss_date":"2026-09-24T12:00:20Z","epss_tier":"high","epss_missing":0,"epss_source_url":"https://epss.empiricalsecurity.com/epss_scores-current.csv.gz","priority_score":91.22,"priority_tier":"p1","exploit_rank":20}]