86 lines
7.1 KiB
JSON
86 lines
7.1 KiB
JSON
{
|
|
"title": "CISA Catalog of Known Exploited Vulnerabilities",
|
|
"catalogVersion": "2026.07.01",
|
|
"dateReleased": "2026-07-01T19:00:06.9016Z",
|
|
"count": 5,
|
|
"vulnerabilities": [
|
|
{
|
|
"cveID": "CVE-2021-44228",
|
|
"vendorProject": "Apache",
|
|
"product": "Log4j2",
|
|
"vulnerabilityName": "Apache Log4j2 Remote Code Execution Vulnerability",
|
|
"dateAdded": "2021-12-10",
|
|
"shortDescription": "Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution.",
|
|
"requiredAction": "For all affected software assets for which updates exist, the only acceptable remediation actions are: 1) Apply updates; OR 2) remove affected assets from agency networks. Temporary mitigations using one of the measures provided at https://www.cisa.gov/uscert/ed-22-02-apache-log4j-recommended-mitigation-measures are only acceptable until updates are available.",
|
|
"dueDate": "2021-12-24",
|
|
"knownRansomwareCampaignUse": "Known",
|
|
"notes": "https://nvd.nist.gov/vuln/detail/CVE-2021-44228",
|
|
"cwes": [
|
|
"CWE-20",
|
|
"CWE-400",
|
|
"CWE-502"
|
|
]
|
|
},
|
|
{
|
|
"cveID": "CVE-2026-45659",
|
|
"vendorProject": "Microsoft",
|
|
"product": "SharePoint Server",
|
|
"vulnerabilityName": "Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability",
|
|
"dateAdded": "2026-07-01",
|
|
"shortDescription": "Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.",
|
|
"requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA\u2019s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA\u2019s \u201cForensics Triage Requirements\u201d (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
|
|
"dueDate": "2026-07-04",
|
|
"knownRansomwareCampaignUse": "Unknown",
|
|
"notes": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-45659",
|
|
"cwes": [
|
|
"CWE-502"
|
|
]
|
|
},
|
|
{
|
|
"cveID": "CVE-2026-48558",
|
|
"vendorProject": "SimpleHelp ",
|
|
"product": "SimpleHelp",
|
|
"vulnerabilityName": "SimpleHelp Authentication Bypass Vulnerability",
|
|
"dateAdded": "2026-06-29",
|
|
"shortDescription": "SimpleHelp contains an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication.",
|
|
"requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA\u2019s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA\u2019s \u201cForensics Triage Requirements\u201d (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
|
|
"dueDate": "2026-07-02",
|
|
"knownRansomwareCampaignUse": "Unknown",
|
|
"notes": "https://simple-help.com/security/simplehelp-security-update-2026-05 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-48558",
|
|
"cwes": [
|
|
"CWE-347"
|
|
]
|
|
},
|
|
{
|
|
"cveID": "CVE-2026-35273",
|
|
"vendorProject": "Oracle",
|
|
"product": " PeopleSoft Enterprise PeopleTools",
|
|
"vulnerabilityName": "Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability",
|
|
"dateAdded": "2026-06-12",
|
|
"shortDescription": "Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise PeopleTools.",
|
|
"requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA\u2019s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA\u2019s \u201cForensics Triage Requirements\u201d (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
|
|
"dueDate": "2026-06-15",
|
|
"knownRansomwareCampaignUse": "Known",
|
|
"notes": "https://www.oracle.com/security-alerts/alert-cve-2026-35273.html ; https://support.oracle.com/signin/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-35273",
|
|
"cwes": [
|
|
"CWE-306"
|
|
]
|
|
},
|
|
{
|
|
"cveID": "CVE-2026-50751",
|
|
"vendorProject": "Check Point",
|
|
"product": "Security Gateway",
|
|
"vulnerabilityName": "Check Point Security Gateway Improper Authentication Vulnerability",
|
|
"dateAdded": "2026-06-08",
|
|
"shortDescription": "Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.",
|
|
"requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
|
|
"dueDate": "2026-06-11",
|
|
"knownRansomwareCampaignUse": "Known",
|
|
"notes": "https://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/ ; https://support.checkpoint.com/results/sk/sk185033?_gl=1*1wqeqhc*_gcl_au*MTI1MzE5MjI2LjE3ODA5MzQ1NTM. ; https://nvd.nist.gov/vuln/detail/CVE-2026-50751",
|
|
"cwes": [
|
|
"CWE-287"
|
|
]
|
|
}
|
|
]
|
|
}
|