Monthly Vuln Summary 2026-04 (31)
In-the-Wild CVE Review · 2026-04
31 CVEs were added to the CISA KEV catalog this month (actively exploited; [RANSOMWARE] = tied to ransomware).
本月收录
- CVE-2026-41940 —
0.0— WebPros cPanel & WHM and WP2 (WordPress Squared) — WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to … [KEV] [RANSOMWARE] - CVE-2024-1708 —
0.0— ConnectWise ScreenConnect — ConnectWise ScreenConnect contains a path traversal vulnerability which could allow an attacker to execute remote code or directly impact confidential data and critical systems. [KEV] [RANSOMWARE] - CVE-2026-32202 —
0.0— Microsoft Windows — Microsoft Windows Shell contains a protection mechanism failure vulnerability that allows an unauthorized attacker to perform spoofing over a network. [KEV] - CVE-2025-29635 —
0.0— D-Link DIR-823X — D-Link DIR-823X contains a command injection vulnerability that allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/s… [KEV] - CVE-2024-7399 —
0.0— Samsung MagicINFO 9 Server — Samsung MagicINFO 9 Server contains a path traversal vulnerability that could allow an attacker to write arbitrary files as system authority. [KEV] - CVE-2024-57728 —
0.0— SimpleHelp SimpleHelp — SimpleHelp contains a path traversal vulnerability that allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). Th… [KEV] [RANSOMWARE] - CVE-2024-57726 —
0.0— SimpleHelp SimpleHelp — SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to e… [KEV] [RANSOMWARE] - CVE-2026-39987 —
0.0— Marimo Marimo — Marimo contains an pre-authorization remote code execution vulnerability, allowing an unauthenticated attacked to shell access and execute arbitrary system commands. [KEV] - CVE-2026-33825 —
0.0— Microsoft Defender — Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally. [KEV] [RANSOMWARE] - CVE-2026-20122 —
0.0— Cisco Catalyst SD-WAN Manger — Cisco Catalyst SD-WAN Manager contains an incorrect use of privileged APIs vulnerability due to improper file handling on the API interface of an affected system. An attacker could… [KEV] - CVE-2026-20133 —
0.0— Cisco Catalyst SD-WAN Manager — Cisco Catalyst SD-WAN Manager contains an exposure of sensitive information to an unauthorized actor vulnerability that could allow remote attackers to view sensitive information o… [KEV] - CVE-2025-2749 —
0.0— Kentico Kentico Xperience — Kentico Xperience contains a path traversal vulnerability that could allow an authenticated user's Staging Sync Server to upload arbitrary data to path relative locations. [KEV] - CVE-2023-27351 —
0.0— PaperCut NG/MF — PaperCut NG/MF contains an improper authentication vulnerability that could allow remote attackers to bypass authentication on affected installations via the SecurityRequestFilter … [KEV] [RANSOMWARE] - CVE-2025-48700 —
0.0— Synacor Zimbra Collaboration Suite (ZCS) — Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that could allow attackers to execute arbitrary JavaScript within the user's session, potenti… [KEV] - CVE-2026-20128 —
0.0— Cisco Catalyst SD-WAN Manager — Cisco Catalyst SD-WAN Manager contains a storing passwords in a recoverable format vulnerability that allows an authenticated, local attacker to gain DCA user privileges by accessi… [KEV] - CVE-2025-32975 —
0.0— Quest KACE Systems Management Appliance (SMA) — Quest KACE Systems Management Appliance (SMA) contains an improper authentication vulnerability that could allow attackers to impersonate legitimate users without valid credentials… [KEV] - CVE-2024-27199 —
0.0— JetBrains TeamCity — JetBrains TeamCity contains a relative path traversal vulnerability that could allow limited admin actions to be performed. [KEV] [RANSOMWARE] - CVE-2026-34197 —
0.0— Apache ActiveMQ — Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection. [KEV] - CVE-2009-0238 —
0.0— Microsoft Office — Microsoft Office Excel contains a remote code execution vulnerability that could allow an attacker to take complete control of an affected system if a user opens a specially crafte… [KEV] - CVE-2026-32201 —
0.0— Microsoft SharePoint Server — Microsoft SharePoint Server contains an improper input validation vulnerability that allows an unauthorized attacker to perform spoofing over a network. [KEV] - CVE-2012-1854 —
0.0— Microsoft Visual Basic for Applications (VBA) — Microsoft Visual Basic for Applications (VBA) contains an insecure library loading vulnerability that could allow for remote code execution. [KEV] - CVE-2025-60710 —
0.0— Microsoft Windows — Microsoft Windows contains a link following vulnerability that allows for privilege escalation [KEV] [RANSOMWARE] - CVE-2023-21529 —
0.0— Microsoft Exchange Server — Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution. [KEV] [RANSOMWARE] - CVE-2023-36424 —
0.0— Microsoft Windows — Microsoft Windows Common Log File System Driver contains an out-of-bounds read vulnerability that could allow a threat actor for privileges escalation [KEV] - CVE-2020-9715 —
0.0— Adobe Acrobat — Adobe Acrobat contains a use-after-free vulnerability that allows for code execution [KEV] - CVE-2026-21643 —
0.0— Fortinet FortiClient EMS — Fortinet FortiClient EMS contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP re… [KEV] - CVE-2026-34621 —
0.0— Adobe Acrobat and Reader — Adobe Acrobat and Reader contain a prototype pollution vulnerability that allows for arbitrary code execution. [KEV] - CVE-2026-1340 —
0.0— Ivanti Endpoint Manager Mobile (EPMM) — Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution. [KEV] - CVE-2026-35616 —
0.0— Fortinet FortiClient EMS — Fortinet FortiClient EMS contains an improper access control vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests. [KEV] - CVE-2026-3502 —
0.0— TrueConf Client — TrueConf Client contains a download of code without integrity check vulnerability. An attacker who is able to influence the update delivery path can substitute a tampered update pa… [KEV] - CVE-2026-5281 —
0.0— Google Dawn — Google Dawn contains an use-after-free vulnerability that could allow a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. … [KEV]
Source: CISA KEV. Auto-compiled by CaptainAI Labs AI agents.