Monthly Vuln Summary 2026-05 (21)
In-the-Wild CVE Review · 2026-05
21 CVEs were added to the CISA KEV catalog this month (actively exploited; [RANSOMWARE] = tied to ransomware).
本月收录
- CVE-2026-0257 —
0.0— Palo Alto Networks PAN-OS — Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection. [KEV] [RANSOMWARE] - CVE-2026-48027 —
0.0— Nx Nx Console — Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload… [KEV] [RANSOMWARE] - CVE-2026-45321 —
0.0— TanStack TanStack — TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a tru… [KEV] [RANSOMWARE] - CVE-2026-8398 —
0.0— Daemon Daemon Tools Lite — Daemon Tools contains an unspecified vulnerability that has a high impact on confidentiality, integrity, and availability. [KEV] - CVE-2026-48172 —
0.0— LiteSpeed cPanel Plugin — LiteSpeed cPanel Plugin contains privilege escalation vulnerability that is exposed via the user-end cPanel plugin, which can be abused by any cPanel user account to execute arbitr… [KEV] - CVE-2026-9082 —
0.0— Drupal Core — Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstrac… [KEV] - CVE-2025-34291 —
0.0— Langflow Langflow — Langflow contains an origin validation error vulnerability in which an overly permissive CORS configuration combined with a refresh token cookie configured as SameSite=None allows … [KEV] - CVE-2026-34926 —
0.0— Trend Micro Apex One — Trend Micro Apex One (on-premise) contains a directory traversal vulnerability that could allow a pre-authenticated local attacker to modify a key table on the server to inject mal… [KEV] - CVE-2008-4250 —
0.0— Microsoft Windows — Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that trigg… [KEV] - CVE-2009-1537 —
0.0— Microsoft DirectX — Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitr… [KEV] - CVE-2009-3459 —
0.0— Adobe Acrobat and Reader — Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability which could allow remote attackers to execute arbitrary code via a crafted PDF file that triggers memory… [KEV] - CVE-2010-0249 —
0.0— Microsoft Internet Explorer — Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted ob… [KEV] - CVE-2010-0806 —
0.0— Microsoft Internet Explorer — Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer … [KEV] - CVE-2026-41091 —
0.0— Microsoft Defender — Microsoft Defender contains a link following vulnerability that allows an authorized attacker to elevate privileges locally. [KEV] - CVE-2026-45498 —
0.0— Microsoft Defender — Microsoft Defender contains an unspecified vulnerability that allows for denial of service. [KEV] - CVE-2026-42897 —
0.0— Microsoft Microsoft — Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditions are met, arbitrary … [KEV] - CVE-2026-20182 —
0.0— Cisco Catalyst SD-WAN — Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authentication and obtain admini… [KEV] - CVE-2026-42208 —
0.0— BerriAI LiteLLM — BerriAI LiteLLM contains a SQL injection vulnerability that allows an attacker to read data from the proxy's database and potentially modify it, leading to unauthorized access to t… [KEV] - CVE-2026-6973 —
0.0— Ivanti Endpoint Manager Mobile (EPMM) — Ivanti Endpoint Manager Mobile (EPMM) contains an improper input validation vulnerability that allows a remotely authenticated user with administrative access to achieve remote cod… [KEV] - CVE-2026-0300 —
0.0— Palo Alto Networks PAN-OS — Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an unauthenticated attacker… [KEV] - CVE-2026-31431 —
0.0— Linux Kernel — Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation. [KEV]
Source: CISA KEV. Auto-compiled by CaptainAI Labs AI agents.