MikroTik’s bandwidth-test service accepts a related connection before login finishes, letting an unauthenticated network client leak kernel memory or crash the router’s kernel.
Every CISA KEV addition, plus critical-severity flaws in the kit that sits at the edge of a network: firewalls, VPN gateways, load balancers, routers, switches and management consoles.
Colour on the left of each entry is the CVSS severity. A pink CISA KEV badge means the flaw is being exploited right now — treat those first, whatever the score says. How each post is sourced and checked is set out in the methodology.
Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability
An unauthenticated attacker can send crafted HTTP requests to Cisco Firewall Management Center’s web interface and gain root on the underlying host, no login needed.
Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
An unauthenticated attacker reaching a NetScaler AAA virtual server or Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) can walk straight past the login step, and CISA confirms this is already being exploited.
Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
A network-reachable heap overflow in FortiOS, FortiSwitchManager and FortiSASE lets unauthenticated attackers send crafted packets to run unauthorised code, and it’s already known to be exploited.
Google Chromium V8 Out of Bounds Write Vulnerability
A V8 engine flaw lets a malicious web page run code inside Chrome’s sandbox with no login or download needed, and it’s already being exploited in the wild.
Improper Authentication of FortiPAM Server
A Chrome extension that mediates FortiPAM privileged access sessions can be tricked into routing a user’s browser traffic through an attacker’s servers just by visiting a malicious site.
Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
A server-side template injection in Adobe Commerce and Magento lets an unauthenticated attacker get crafted input evaluated by the template engine, leading to full code execution on the store.
Microsoft Windows Heap-Based Buffer Overflow Vulnerability
A heap overflow in Windows ALPC lets a local attacker with basic access escalate to SYSTEM privileges, and it’s already being exploited in the wild.
Microsoft Windows Link Following Vulnerability
A local privilege escalation bug in the Windows Update Stack lets a logged-in low-privilege user redirect a file operation via a symbolic link to gain full SYSTEM control, and it’s already being exploited.
N-able N-central Static Code Injection Vulnerability
N-able N-central contains a static code injection vulnerability that could allow for pre-authentication remote code execution.