Monthly Vuln Summary 2026-05 (21)

In-the-Wild CVE Review · 2026-05

21 CVEs were added to the CISA KEV catalog this month (actively exploited; [RANSOMWARE] = tied to ransomware).

本月收录

  • CVE-2026-0257 — 0.0 — Palo Alto Networks PAN-OS — Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection. [KEV] [RANSOMWARE]
  • CVE-2026-48027 — 0.0 — Nx Nx Console — Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload… [KEV] [RANSOMWARE]
  • CVE-2026-45321 — 0.0 — TanStack TanStack — TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a tru… [KEV] [RANSOMWARE]
  • CVE-2026-8398 — 0.0 — Daemon Daemon Tools Lite — Daemon Tools contains an unspecified vulnerability that has a high impact on confidentiality, integrity, and availability. [KEV]
  • CVE-2026-48172 — 0.0 — LiteSpeed cPanel Plugin — LiteSpeed cPanel Plugin contains privilege escalation vulnerability that is exposed via the user-end cPanel plugin, which can be abused by any cPanel user account to execute arbitr… [KEV]
  • CVE-2026-9082 — 0.0 — Drupal Core — Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstrac… [KEV]
  • CVE-2025-34291 — 0.0 — Langflow Langflow — Langflow contains an origin validation error vulnerability in which an overly permissive CORS configuration combined with a refresh token cookie configured as SameSite=None allows … [KEV]
  • CVE-2026-34926 — 0.0 — Trend Micro Apex One — Trend Micro Apex One (on-premise) contains a directory traversal vulnerability that could allow a pre-authenticated local attacker to modify a key table on the server to inject mal… [KEV]
  • CVE-2008-4250 — 0.0 — Microsoft Windows — Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that trigg… [KEV]
  • CVE-2009-1537 — 0.0 — Microsoft DirectX — Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitr… [KEV]
  • CVE-2009-3459 — 0.0 — Adobe Acrobat and Reader — Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability which could allow remote attackers to execute arbitrary code via a crafted PDF file that triggers memory… [KEV]
  • CVE-2010-0249 — 0.0 — Microsoft Internet Explorer — Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted ob… [KEV]
  • CVE-2010-0806 — 0.0 — Microsoft Internet Explorer — Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer … [KEV]
  • CVE-2026-41091 — 0.0 — Microsoft Defender — Microsoft Defender contains a link following vulnerability that allows an authorized attacker to elevate privileges locally. [KEV]
  • CVE-2026-45498 — 0.0 — Microsoft Defender — Microsoft Defender contains an unspecified vulnerability that allows for denial of service. [KEV]
  • CVE-2026-42897 — 0.0 — Microsoft Microsoft — Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditions are met, arbitrary … [KEV]
  • CVE-2026-20182 — 0.0 — Cisco Catalyst SD-WAN — Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authentication and obtain admini… [KEV]
  • CVE-2026-42208 — 0.0 — BerriAI LiteLLM — BerriAI LiteLLM contains a SQL injection vulnerability that allows an attacker to read data from the proxy's database and potentially modify it, leading to unauthorized access to t… [KEV]
  • CVE-2026-6973 — 0.0 — Ivanti Endpoint Manager Mobile (EPMM) — Ivanti Endpoint Manager Mobile (EPMM) contains an improper input validation vulnerability that allows a remotely authenticated user with administrative access to achieve remote cod… [KEV]
  • CVE-2026-0300 — 0.0 — Palo Alto Networks PAN-OS — Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an unauthenticated attacker… [KEV]
  • CVE-2026-31431 — 0.0 — Linux Kernel — Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation. [KEV]

Source: CISA KEV. Auto-compiled by CaptainAI Labs AI agents.