A local privilege escalation bug in the Windows Update Stack lets a logged-in low-privilege user redirect a file operation via a symbolic link to gain full SYSTEM control, and it’s already being exploited.
Every CISA KEV addition, plus critical-severity flaws in the kit that sits at the edge of a network: firewalls, VPN gateways, load balancers, routers, switches and management consoles.
Colour on the left of each entry is the CVSS severity. A pink CISA KEV badge means the flaw is being exploited right now — treat those first, whatever the score says. How each post is sourced and checked is set out in the methodology.
N-able N-central Static Code Injection Vulnerability
N-able N-central contains a static code injection vulnerability that could allow for pre-authentication remote code execution.
Microsoft Entra ID Deserialization of Untrusted Data Vulnerability
A maximum-severity flaw in Microsoft Entra ID lets an attacker execute code over the network with no credentials or user interaction, and it is already being exploited.
Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability
An unauthenticated attacker can send crafted SMTP requests to Zimbra servers running the optional zimbra-snmp package with notifications enabled, triggering OS command execution as the Zimbra user.
TrueConf Server Code Injection Vulnerability
An unauthenticated attacker reaching port 4307/TCP on TrueConf Server can escape a sandboxed script environment and run arbitrary code on the underlying host, and the flaw is already being exploited.
TrueConf Server Missing Authentication for Critical Function Vulnerability
An unauthenticated attacker who can reach port 4307/TCP on a TrueConf Server can trigger an undocumented function to run arbitrary scripts, with no login or user action required.
MLflow Server-Side Request Forgery Vulnerability
An unauthenticated endpoint in MLflow’s webhook tester can be redirected to internal addresses or cloud metadata services, and the response body is handed straight back to the attacker.
Apple macOS Improper Authentication Vulnerability
Screen Sharing on unpatched Macs can be accessed by anyone on the network without a password, giving full remote control, and Apple confirms it’s already being exploited.
Broadcom VMware vCenter Path Traversal Vulnerability
A network-reachable flaw in vCenter’s Syslog service lets an attacker write files outside its intended directory, leading to arbitrary code execution on the server that controls your virtual infrastructure.
Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability
A double-free bug in Windows’ IKE Extension lets an unauthenticated attacker execute code over the network on any host with IPsec listening, and it’s already being exploited.