Skip to main content

CISA known exploited vulnerabilities

Under attack. Patch these first.

Page 12 of 21

Alerts tracked

2625

Security flaws we track for Upstate SC businesses.

Known exploited

503

On CISA’s list of vulnerabilities attackers are actively using. Patch these first.

New exploited this month

43

Fresh additions to that CISA list since the first of the month.Feeds last synced Aug 19, 2026, 6:00 AM UTC.

Showing page 12 (24 alerts) of 503 known-exploited alerts.

Actively exploited (KEV)Ransomware

CVE-2023-38831

RARLAB WinRAR Code Execution Vulnerability

RARLAB WinRAR is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-38831). RARLAB WinRAR contains an unspecified vulnerability that allows an attacker to execute code when a user attempts to view a benign file within a ZIP archive. CISA remediation due date: 2023-09-14. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-38035

Ivanti Sentry Authentication Bypass Vulnerability

Ivanti Sentry is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-38035). Ivanti Sentry, formerly known as MobileIron Sentry, contains an authentication bypass vulnerability that may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTTPD configuration. CISA remediation due date: 2023-09-12. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-27532

Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function Vulnerability

Veeam Backup & Replication is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-27532). Veeam Backup & Replication Cloud Connect component contains a missing authentication for critical function vulnerability that allows an unauthenticated user operating within the backup infrastructure network perimeter to obtain encrypted credentials stored in the configuration database. This may lead to an attacker gaining access to the backup infrastructure hosts. CISA remediation due date: 2023-09-12. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-35078

Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability

Ivanti Endpoint Manager Mobile (EPMM) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-35078). Ivanti Endpoint Manager Mobile (EPMM, previously branded MobileIron Core) contains an authentication bypass vulnerability that allows unauthenticated access to specific API paths. An attacker with access to these API paths can access personally identifiable information (PII) such as names, phone numbers, and other mobile device details for users on a vulnerable system. An attacker can also make other configuration changes including installing software and modifying security profiles on registered devices. CISA remediation due date: 2023-08-15. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-3519

Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability

Citrix NetScaler ADC and NetScaler Gateway is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-3519). Citrix NetScaler ADC and NetScaler Gateway contains a code injection vulnerability that allows for unauthenticated remote code execution. CISA remediation due date: 2023-08-09. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-36884

Microsoft Windows Search Remote Code Execution Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-36884). Microsoft Windows Search contains an unspecified vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file, leading to remote code execution. CISA remediation due date: 2023-08-29. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2022-31199

Netwrix Auditor Insecure Object Deserialization Vulnerability

Netwrix Auditor is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-31199). Netwrix Auditor User Activity Video Recording component contains an insecure objection deserialization vulnerability that allows an unauthenticated, remote attacker to execute code as the NT AUTHORITY\SYSTEM user. Successful exploitation requires that the attacker is able to reach port 9004/TCP, which is commonly blocked by standard enterprise firewalling. CISA remediation due date: 2023-08-01. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-27997

Fortinet FortiOS and FortiProxy SSL-VPN Heap-Based Buffer Overflow Vulnerability

Fortinet FortiOS and FortiProxy SSL-VPN is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-27997). Fortinet FortiOS and FortiProxy SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker to execute code or commands via specifically crafted requests. CISA remediation due date: 2023-07-04. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-34362

Progress MOVEit Transfer SQL Injection Vulnerability

Progress MOVEit Transfer is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-34362). Progress MOVEit Transfer contains a SQL injection vulnerability that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database in addition to executing SQL statements that alter or delete database elements. CISA remediation due date: 2023-06-23. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-45046

Apache Log4j2 Deserialization of Untrusted Data Vulnerability

Apache Log4j2 is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-45046). Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations. CISA remediation due date: 2023-05-22. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-27350

PaperCut MF/NG Improper Access Control Vulnerability

PaperCut MF/NG is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-27350). PaperCut MF/NG contains an improper access control vulnerability within the SetupCompleted class that allows authentication bypass and code execution in the context of system. CISA remediation due date: 2023-05-12. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-28252

Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-28252). Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation. CISA remediation due date: 2023-05-02. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-27878

Veritas Backup Exec Agent Command Execution Vulnerability

Veritas Backup Exec Agent is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-27878). Veritas Backup Exec (BE) Agent contains a command execution vulnerability that could allow an attacker to use a data management protocol command to execute a command on the BE Agent machine. CISA remediation due date: 2023-04-28. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-27877

Veritas Backup Exec Agent Improper Authentication Vulnerability

Veritas Backup Exec Agent is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-27877). Veritas Backup Exec (BE) Agent contains an improper authentication vulnerability that could allow an attacker unauthorized access to the BE Agent via SHA authentication scheme. CISA remediation due date: 2023-04-28. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-27876

Veritas Backup Exec Agent File Access Vulnerability

Veritas Backup Exec Agent is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-27876). Veritas Backup Exec (BE) Agent contains a file access vulnerability that could allow an attacker to specially craft input parameters on a data management protocol command to access files on the BE Agent machine. CISA remediation due date: 2023-04-28. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2019-1388

Microsoft Windows Certificate Dialog Privilege Escalation Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-1388). Microsoft Windows Certificate Dialog contains a privilege escalation vulnerability, allowing attackers to run processes in an elevated context. CISA remediation due date: 2023-04-28. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2017-7494

Samba Remote Code Execution Vulnerability

Samba Samba is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-7494). Samba contains a remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share and then cause the server to load and execute it. CISA remediation due date: 2023-04-20. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-24880

Microsoft Windows SmartScreen Security Feature Bypass Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-24880). Microsoft Windows SmartScreen contains a security feature bypass vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file. CISA remediation due date: 2023-04-04. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2022-36537

ZK Framework AuUploader Unspecified Vulnerability

ZK Framework AuUploader is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-36537). ZK Framework AuUploader servlets contain an unspecified vulnerability that could allow an attacker to retrieve the content of a file located in the web context. The ZK Framework is an open-source Java framework. This vulnerability can impact multiple products, including but not limited to ConnectWise R1Soft Server Backup Manager. CISA remediation due date: 2023-03-20. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2022-47986

IBM Aspera Faspex Code Execution Vulnerability

IBM Aspera Faspex is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-47986). IBM Aspera Faspex could allow a remote attacker to execute code on the system, caused by a YAML deserialization flaw. CISA remediation due date: 2023-03-14. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2022-41223

Mitel MiVoice Connect Code Injection Vulnerability

Mitel MiVoice Connect is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-41223). The Director component in Mitel MiVoice Connect allows an authenticated attacker with internal network access to execute code within the context of the application. CISA remediation due date: 2023-03-14. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2022-40765

Mitel MiVoice Connect Command Injection Vulnerability

Mitel MiVoice Connect is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-40765). The Mitel Edge Gateway component of MiVoice Connect allows an authenticated attacker with internal network access to execute commands within the context of the system. CISA remediation due date: 2023-03-14. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-23376

Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-23376). Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation. CISA remediation due date: 2023-03-07. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-0669

Fortra GoAnywhere MFT Remote Code Execution Vulnerability

Fortra GoAnywhere MFT is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-0669). Fortra (formerly, HelpSystems) GoAnywhere MFT contains a pre-authentication remote code execution vulnerability in the License Response Servlet due to deserializing an attacker-controlled object. CISA remediation due date: 2023-03-03. If you need help checking exposure, call (864) 335-9223.