Monthly Vuln Summary 2026-01 (17)

In-the-Wild CVE Review · 2026-01

17 CVEs were added to the CISA KEV catalog this month (actively exploited; [RANSOMWARE] = tied to ransomware).

本月收录

  • CVE-2026-1281 — 0.0 — Ivanti Endpoint Manager Mobile (EPMM) — Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution. [KEV]
  • CVE-2026-24858 — 0.0 — Fortinet Multiple Products — Fortinet FortiAnalyzer, FortiManager, FortiOS, and FortiProxy contain an authentication bypass using an alternate path or channel that could allow an attacker with a FortiCloud acc… [KEV]
  • CVE-2018-14634 — 0.0 — Linux Kernel — Linux Kernel contains an integer overflow vulnerability in the create_elf_tables() function which could allow an unprivileged local user with access to SUID (or otherwise privilege… [KEV]
  • CVE-2025-52691 — 0.0 — SmarterTools SmarterMail — SmarterTools SmarterMail contains an unrestricted upload of file with dangerous type vulnerability that could allow an unauthenticated attacker to upload arbitrary files to any loc… [KEV] [RANSOMWARE]
  • CVE-2026-23760 — 0.0 — SmarterTools SmarterMail — SmarterTools SmarterMail contains an authentication bypass using an alternate path or channel vulnerability in the password reset API. The force-reset-password endpoint permits ano… [KEV] [RANSOMWARE]
  • CVE-2026-24061 — 0.0 — GNU InetUtils — GNU InetUtils contains an argument injection vulnerability in telnetd that could allow for remote authentication bypass via a "-f root" value for the USER environment variable. [KEV]
  • CVE-2026-21509 — 0.0 — Microsoft Office — Microsoft Office contains a security feature bypass vulnerability in which reliance on untrusted inputs in a security decision in Microsoft Office could allow an unauthorized attac… [KEV]
  • CVE-2024-37079 — 0.0 — Broadcom VMware vCenter Server — Broadcom VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. This could allow a malicious actor with network access to… [KEV]
  • CVE-2025-68645 — 0.0 — Synacor Zimbra Collaboration Suite (ZCS) — Synacor Zimbra Collaboration Suite (ZCS) contains a PHP remote file inclusion vulnerability that could allow for remote attackers to craft requests to the /h/rest endpoint to influ… [KEV]
  • CVE-2025-34026 — 0.0 — Versa Concerto — Versa Concerto SD-WAN orchestration platform contains an improper authentication vulnerability in the Traefik reverse proxy configuration, allowing at attacker to access administra… [KEV]
  • CVE-2025-31125 — 0.0 — Vite Vitejs — Vite Vitejs contains an improper access control vulnerability that exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicitly exposing the Vite … [KEV]
  • CVE-2025-54313 — 0.0 — Prettier eslint-config-prettier — Prettier eslint-config-prettier contains an embedded malicious code vulnerability. Installing an affected package executes an install.js file that launches the node-gyp.dll malware… [KEV]
  • CVE-2026-20045 — 0.0 — Cisco Unified Communications Manager — Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Prese… [KEV]
  • CVE-2026-20805 — 0.0 — Microsoft Windows — Microsoft Windows Desktop Windows Manager contains an information disclosure vulnerability that allows an authorized attacker to disclose information locally. [KEV]
  • CVE-2025-8110 — 0.0 — Gogs Gogs — Gogs contains a path traversal vulnerability affecting improper Symbolic link handling in the PutContents API that could allow for code execution. [KEV]
  • CVE-2009-0556 — 0.0 — Microsoft Office — Microsoft Office PowerPoint contains a code injection vulnerability that allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containi… [KEV]
  • CVE-2025-37164 — 0.0 — Hewlett Packard Enterprise (HPE) OneView — Hewlett Packard Enterprise (HPE) OneView contains a code injection vulnerability that allows a remote unauthenticated user to perform remote code execution. [KEV]

Source: CISA KEV. Auto-compiled by CaptainAI Labs AI agents.