A maximum-severity flaw in Microsoft Entra ID lets an attacker execute code over the network with no credentials or user interaction, and it is already being exploited.
Every CISA KEV addition, plus critical-severity flaws in the kit that sits at the edge of a network: firewalls, VPN gateways, load balancers, routers, switches and management consoles.
Colour on the left of each entry is the CVSS severity. A pink CISA KEV badge means the flaw is being exploited right now — treat those first, whatever the score says. How each post is sourced and checked is set out in the methodology.
Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability
An unauthenticated attacker can send a crafted SMTP request to Zimbra Collaboration Suite and run operating system commands as the Zimbra user, with active exploitation already confirmed.
TrueConf Server Code Injection Vulnerability
An unauthenticated attacker reaching TrueConf Server’s port 4307/TCP can send a crafted script that escapes the server’s sandboxed execution and runs arbitrary code on the host, and it’s already being exploited.
TrueConf Server Missing Authentication for Critical Function Vulnerability
TrueConf Server exposes a critical function on port 4307/TCP with no authentication check, letting a remote attacker run arbitrary scripts without credentials or user interaction.
MLflow Server-Side Request Forgery Vulnerability
An unauthenticated attacker can make MLflow fetch internal URLs or cloud metadata endpoints and hand back the response, exposing credentials or config from systems behind it.
Apple macOS Improper Authentication Vulnerability
A flaw in macOS Screen Sharing lets a network attacker log in without a password, and CISA confirms it’s already being used in attacks against unpatched Macs.
Broadcom VMware vCenter Path Traversal Vulnerability
An unauthenticated path traversal flaw in VMware vCenter lets anyone with network reach to the server run arbitrary code, and it’s already being exploited, with no fix yet listed.
Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability
A double-free in Windows’ IKE/AuthIP IPsec keying service allows unauthenticated remote code execution over the network, no login or user click needed, and it’s already being exploited.
Microsoft SharePoint Weak Authentication Vulnerability
A weak authentication flaw in SharePoint lets an attacker bypass a security check over the network without credentials, exposing confidential content, and it’s already being actively exploited.
Ray-Project Ray Code Injection Vulnerability
A code injection flaw in Ray lets remote code run on developer machines when they visit a malicious page in Firefox or Safari, and it’s already being exploited.