Activity

Latest CVE events and analysis as they emerge

  1. CVE-2026-58644

    16 Jul 2026, 00:00

    SharePointMicrosoft Office

    Added to CISA KEV catalog

    Vulnerability name
    Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
    Product
    Microsoft SharePoint

    CVE-2026-58644 is a vulnerability found in Microsoft Office SharePoint, categorized as a deserialization of untrusted data flaw. This vulnerability enables an unauthorized attacker to execute code over a network. The flaw affects multiple versions of Microsoft SharePoint Server, including Subscription Edition, 2019, and 2016. The Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-58644 to its Known Exploited Vulnerabilities Catalog, indicating that it is being actively exploited.

  2. CVE-2026-39808

    16 Jul 2026, 00:00

    Fortinet FortiSandbox

    Added to CISA KEV catalog

    Vulnerability name
    Fortinet FortiSandbox OS Command Injection Vulnerability
    Product
    Fortinet FortiSandbox

    CVE-2026-39808 is an operating system (OS) command injection vulnerability affecting Fortinet FortiSandbox versions 4.4.0 through 4.4.8. This flaw stems from the improper neutralization of special elements used in OS commands, which allows attackers to inject malicious commands into system operations. Successful exploitation of CVE-2026-39808 enables remote attackers to execute unauthorized code or commands on the target system. This can be achieved without requiring any authentication or user interaction, typically through specially crafted HTTP requests to an API endpoint.

  3. CVE-2026-25089

    16 Jul 2026, 00:00

    FortiSandbox PaaSFortinet FortiSandboxFortiSandbox Cloud

    Added to CISA KEV catalog

    Vulnerability name
    Fortinet FortiSandbox OS Command Injection Vulnerability
    Product
    Fortinet FortiSandbox

    CVE-2026-25089 is an operating system (OS) command injection vulnerability affecting Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS. This flaw, categorized as CWE-78 (Improper Neutralization of Special Elements used in an OS Command), allows an unauthenticated, remote attacker to execute unauthorized commands on the appliance. The vulnerability is triggered by sending specially crafted HTTP requests, specifically exploiting a second-order command injection within the JSON input of the "start VNC" feature in the web-based management interface. Successful exploitation of CVE-2026-25089 can lead to the execution of arbitrary OS commands on the underlying system. Affected versions include FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, all FortiSandbox 4.2 versions, FortiSandbox Cloud 5.0.4 through 5.0.5, and FortiSandbox PaaS 5.0.4 through 5.0.5.

  4. CVE-2026-46817

    15 Jul 2026, 00:00

    Oracle PaymentsOracle E-Business Suite

    Added to CISA KEV catalog

    Vulnerability name
    Oracle E-Business Suite Improper Privilege Management Vulnerability
    Product
    Oracle E-Business Suite

    CVE-2026-46817 is a vulnerability found in the File Transmission component of Oracle Payments, part of Oracle E-Business Suite, affecting versions 12.2.3 through 12.2.15. This flaw stems from improper privilege management, improper authentication, and a lack of authentication for a critical function. It can be exploited remotely over HTTP without requiring authentication or user interaction, specifically targeting the `/OA_HTML/ibytransmit` endpoint with XML payloads. Successful exploitation of CVE-2026-46817 can lead to a complete compromise of the Oracle Payments module. Observed exploitation attempts have included unauthenticated file-read operations, potentially exposing sensitive system files like `/etc/passwd` and configuration files containing database credentials, encryption keys, and payment-processor API keys. The vulnerability has been added to CISA's Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild, and Oracle released patches for it in May 2026.

  5. CVE-2023-4346

    15 Jul 2026, 00:00

    KNXBCU

    Added to CISA KEV catalog

    Vulnerability name
    KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability
    Product
    KNX Association KNX Protocol Connection Authorization Option 1

    CVE-2023-4346 describes a vulnerability affecting KNX devices that utilize KNX Connection Authorization and support Option 1. The core issue stems from the implementation of the BCU key feature, which allows for the creation of a device password that, in many cases, cannot be reset without knowledge of the existing password. This design flaw can lead to legitimate users being locked out of their devices. An attacker can exploit this vulnerability through either network access, if the device is configured to interface with a network, or physical access to the device. By purging devices that lack additional security options, an attacker can then set their own BCU key, effectively locking out the rightful owners and preventing them from accessing the device. This vulnerability has been added to the CISA's Known Exploited Vulnerabilities Catalog, indicating that it is actively being exploited.