A maximum-severity flaw in Microsoft Entra ID lets an attacker execute code over the network with no credentials or user interaction, and it is already being exploited.
Every CISA KEV addition, plus critical-severity flaws in the kit that sits at the edge of a network: firewalls, VPN gateways, load balancers, routers, switches and management consoles.
Colour on the left of each entry is the CVSS severity. A pink CISA KEV badge means the flaw is being exploited right now — treat those first, whatever the score says. How each post is sourced and checked is set out in the methodology.
Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability
An unauthenticated attacker can send crafted SMTP requests to Zimbra servers running the optional zimbra-snmp package with notifications enabled, triggering OS command execution as the Zimbra user.
TrueConf Server Code Injection Vulnerability
An unauthenticated attacker reaching port 4307/TCP on TrueConf Server can escape a sandboxed script environment and run arbitrary code on the underlying host, and the flaw is already being exploited.
TrueConf Server Missing Authentication for Critical Function Vulnerability
An unauthenticated attacker who can reach port 4307/TCP on a TrueConf Server can trigger an undocumented function to run arbitrary scripts, with no login or user action required.
MLflow Server-Side Request Forgery Vulnerability
An unauthenticated endpoint in MLflow’s webhook tester can be redirected to internal addresses or cloud metadata services, and the response body is handed straight back to the attacker.
Apple macOS Improper Authentication Vulnerability
Screen Sharing on unpatched Macs can be accessed by anyone on the network without a password, giving full remote control, and Apple confirms it’s already being exploited.
Broadcom VMware vCenter Path Traversal Vulnerability
A network-reachable flaw in vCenter’s Syslog service lets an attacker write files outside its intended directory, leading to arbitrary code execution on the server that controls your virtual infrastructure.
Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability
A double-free bug in Windows’ IKE Extension lets an unauthenticated attacker execute code over the network on any host with IPsec listening, and it’s already being exploited.
Microsoft SharePoint Weak Authentication Vulnerability
An unauthenticated attacker with network access to Microsoft Office SharePoint can bypass authentication controls and read data that should be protected, no login or user action needed.
Ray-Project Ray Code Injection Vulnerability
Ray’s local developer interface trusts a spoofable browser header as its only defence, letting a malicious webpage combine DNS rebinding with Firefox or Safari to run code on a developer’s machine.