Monthly Vuln Summary 2026-04 (31)

In-the-Wild CVE Review · 2026-04

31 CVEs were added to the CISA KEV catalog this month (actively exploited; [RANSOMWARE] = tied to ransomware).

本月收录

  • CVE-2026-41940 — 0.0 — WebPros cPanel & WHM and WP2 (WordPress Squared) — WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to … [KEV] [RANSOMWARE]
  • CVE-2024-1708 — 0.0 — ConnectWise ScreenConnect — ConnectWise ScreenConnect contains a path traversal vulnerability which could allow an attacker to execute remote code or directly impact confidential data and critical systems. [KEV] [RANSOMWARE]
  • CVE-2026-32202 — 0.0 — Microsoft Windows — Microsoft Windows Shell contains a protection mechanism failure vulnerability that allows an unauthorized attacker to perform spoofing over a network. [KEV]
  • CVE-2025-29635 — 0.0 — D-Link DIR-823X — D-Link DIR-823X contains a command injection vulnerability that allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/s… [KEV]
  • CVE-2024-7399 — 0.0 — Samsung MagicINFO 9 Server — Samsung MagicINFO 9 Server contains a path traversal vulnerability that could allow an attacker to write arbitrary files as system authority. [KEV]
  • CVE-2024-57728 — 0.0 — SimpleHelp SimpleHelp — SimpleHelp contains a path traversal vulnerability that allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). Th… [KEV] [RANSOMWARE]
  • CVE-2024-57726 — 0.0 — SimpleHelp SimpleHelp — SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to e… [KEV] [RANSOMWARE]
  • CVE-2026-39987 — 0.0 — Marimo Marimo — Marimo contains an pre-authorization remote code execution vulnerability, allowing an unauthenticated attacked to shell access and execute arbitrary system commands. [KEV]
  • CVE-2026-33825 — 0.0 — Microsoft Defender — Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally. [KEV] [RANSOMWARE]
  • CVE-2026-20122 — 0.0 — Cisco Catalyst SD-WAN Manger — Cisco Catalyst SD-WAN Manager contains an incorrect use of privileged APIs vulnerability due to improper file handling on the API interface of an affected system. An attacker could… [KEV]
  • CVE-2026-20133 — 0.0 — Cisco Catalyst SD-WAN Manager — Cisco Catalyst SD-WAN Manager contains an exposure of sensitive information to an unauthorized actor vulnerability that could allow remote attackers to view sensitive information o… [KEV]
  • CVE-2025-2749 — 0.0 — Kentico Kentico Xperience — Kentico Xperience contains a path traversal vulnerability that could allow an authenticated user's Staging Sync Server to upload arbitrary data to path relative locations. [KEV]
  • CVE-2023-27351 — 0.0 — PaperCut NG/MF — PaperCut NG/MF contains an improper authentication vulnerability that could allow remote attackers to bypass authentication on affected installations via the SecurityRequestFilter … [KEV] [RANSOMWARE]
  • CVE-2025-48700 — 0.0 — Synacor Zimbra Collaboration Suite (ZCS) — Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that could allow attackers to execute arbitrary JavaScript within the user's session, potenti… [KEV]
  • CVE-2026-20128 — 0.0 — Cisco Catalyst SD-WAN Manager — Cisco Catalyst SD-WAN Manager contains a storing passwords in a recoverable format vulnerability that allows an authenticated, local attacker to gain DCA user privileges by accessi… [KEV]
  • CVE-2025-32975 — 0.0 — Quest KACE Systems Management Appliance (SMA) — Quest KACE Systems Management Appliance (SMA) contains an improper authentication vulnerability that could allow attackers to impersonate legitimate users without valid credentials… [KEV]
  • CVE-2024-27199 — 0.0 — JetBrains TeamCity — JetBrains TeamCity contains a relative path traversal vulnerability that could allow limited admin actions to be performed. [KEV] [RANSOMWARE]
  • CVE-2026-34197 — 0.0 — Apache ActiveMQ — Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection. [KEV]
  • CVE-2009-0238 — 0.0 — Microsoft Office — Microsoft Office Excel contains a remote code execution vulnerability that could allow an attacker to take complete control of an affected system if a user opens a specially crafte… [KEV]
  • CVE-2026-32201 — 0.0 — Microsoft SharePoint Server — Microsoft SharePoint Server contains an improper input validation vulnerability that allows an unauthorized attacker to perform spoofing over a network. [KEV]
  • CVE-2012-1854 — 0.0 — Microsoft Visual Basic for Applications (VBA) — Microsoft Visual Basic for Applications (VBA) contains an insecure library loading vulnerability that could allow for remote code execution. [KEV]
  • CVE-2025-60710 — 0.0 — Microsoft Windows — Microsoft Windows contains a link following vulnerability that allows for privilege escalation [KEV] [RANSOMWARE]
  • CVE-2023-21529 — 0.0 — Microsoft Exchange Server — Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution. [KEV] [RANSOMWARE]
  • CVE-2023-36424 — 0.0 — Microsoft Windows — Microsoft Windows Common Log File System Driver contains an out-of-bounds read vulnerability that could allow a threat actor for privileges escalation [KEV]
  • CVE-2020-9715 — 0.0 — Adobe Acrobat — Adobe Acrobat contains a use-after-free vulnerability that allows for code execution [KEV]
  • CVE-2026-21643 — 0.0 — Fortinet FortiClient EMS — Fortinet FortiClient EMS contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP re… [KEV]
  • CVE-2026-34621 — 0.0 — Adobe Acrobat and Reader — Adobe Acrobat and Reader contain a prototype pollution vulnerability that allows for arbitrary code execution. [KEV]
  • CVE-2026-1340 — 0.0 — Ivanti Endpoint Manager Mobile (EPMM) — Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution. [KEV]
  • CVE-2026-35616 — 0.0 — Fortinet FortiClient EMS — Fortinet FortiClient EMS contains an improper access control vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests. [KEV]
  • CVE-2026-3502 — 0.0 — TrueConf Client — TrueConf Client contains a download of code without integrity check vulnerability. An attacker who is able to influence the update delivery path can substitute a tampered update pa… [KEV]
  • CVE-2026-5281 — 0.0 — Google Dawn — Google Dawn contains an use-after-free vulnerability that could allow a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. … [KEV]

Source: CISA KEV. Auto-compiled by CaptainAI Labs AI agents.