{
  "source": "https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json",
  "lastVerified": "2026-07-30T16:34:18.891Z",
  "total": 1656,
  "shown": 19,
  "note": "Representative subset. Full catalog at the source URL.",
  "entries": [
    {
      "cve": "CVE-2026-20316",
      "vendor": "Cisco",
      "product": "Secure Firewall Management Center (FMC)",
      "detail": "Use of Hard-coded Password",
      "affectedVersions": "—",
      "dateAdded": "2026-07-29",
      "dueDate": "2026-08-01",
      "status": "Active",
      "group": "Added in the last 7 days"
    },
    {
      "cve": "CVE-2025-68686",
      "vendor": "Fortinet",
      "product": "FortiOS",
      "detail": "Exposure of Sensitive Information to an Unauthorized Actor",
      "affectedVersions": "—",
      "dateAdded": "2026-07-27",
      "dueDate": "2026-08-10",
      "status": "Active",
      "group": "Added in the last 7 days"
    },
    {
      "cve": "CVE-2026-16812",
      "vendor": "Arista",
      "product": "VeloCloud Orchestrator",
      "detail": "On-Prem OS Command Injection",
      "affectedVersions": "—",
      "dateAdded": "2026-07-27",
      "dueDate": "2026-07-30",
      "status": "Past due",
      "group": "Added in the last 7 days"
    },
    {
      "cve": "CVE-2026-20316",
      "vendor": "Cisco",
      "product": "Secure Firewall Management Center (FMC)",
      "detail": "Use of Hard-coded Password",
      "affectedVersions": "—",
      "dateAdded": "2026-07-29",
      "dueDate": "2026-08-01",
      "status": "Active",
      "group": "Edge & VPN appliances"
    },
    {
      "cve": "CVE-2025-68686",
      "vendor": "Fortinet",
      "product": "FortiOS",
      "detail": "Exposure of Sensitive Information to an Unauthorized Actor",
      "affectedVersions": "—",
      "dateAdded": "2026-07-27",
      "dueDate": "2026-08-10",
      "status": "Active",
      "group": "Edge & VPN appliances"
    },
    {
      "cve": "CVE-2026-25089",
      "vendor": "Fortinet",
      "product": "FortiSandbox",
      "detail": "OS Command Injection",
      "affectedVersions": "—",
      "dateAdded": "2026-07-16",
      "dueDate": "2026-07-19",
      "status": "Past due",
      "group": "Edge & VPN appliances"
    },
    {
      "cve": "CVE-2026-39808",
      "vendor": "Fortinet",
      "product": "FortiSandbox",
      "detail": "OS Command Injection",
      "affectedVersions": "—",
      "dateAdded": "2026-07-16",
      "dueDate": "2026-07-19",
      "status": "Past due",
      "group": "Edge & VPN appliances"
    },
    {
      "cve": "CVE-2026-15409",
      "vendor": "SonicWall",
      "product": "SMA1000 Appliances",
      "detail": "Server-Side Request Forgery",
      "affectedVersions": "—",
      "dateAdded": "2026-07-14",
      "dueDate": "2026-07-17",
      "status": "Past due",
      "group": "Edge & VPN appliances"
    },
    {
      "cve": "CVE-2026-15410",
      "vendor": "SonicWall",
      "product": "SMA1000 Appliances",
      "detail": "Code Injection",
      "affectedVersions": "—",
      "dateAdded": "2026-07-14",
      "dueDate": "2026-07-17",
      "status": "Past due",
      "group": "Edge & VPN appliances"
    },
    {
      "cve": "CVE-2008-4128",
      "vendor": "Cisco",
      "product": "IOS",
      "detail": "Cross-Site Request Forgery",
      "affectedVersions": "—",
      "dateAdded": "2026-07-13",
      "dueDate": "2026-07-16",
      "status": "Past due",
      "group": "Edge & VPN appliances"
    },
    {
      "cve": "CVE-2026-20230",
      "vendor": "Cisco",
      "product": "Unified Communications Manager",
      "detail": "Server-Side Request Forgery (SSRF)",
      "affectedVersions": "—",
      "dateAdded": "2026-06-25",
      "dueDate": "2026-06-28",
      "status": "Past due",
      "group": "Edge & VPN appliances"
    },
    {
      "cve": "CVE-2026-12569",
      "vendor": "PTC",
      "product": "Windchill and FlexPLM",
      "detail": "Improper Input Validation",
      "affectedVersions": "—",
      "dateAdded": "2026-06-25",
      "dueDate": "2026-06-28",
      "status": "Ransomware",
      "group": "Ransomware-linked"
    },
    {
      "cve": "CVE-2026-35273",
      "vendor": "Oracle",
      "product": " PeopleSoft Enterprise PeopleTools",
      "detail": "Missing Authentication for Critical Function",
      "affectedVersions": "—",
      "dateAdded": "2026-06-12",
      "dueDate": "2026-06-15",
      "status": "Ransomware",
      "group": "Ransomware-linked"
    },
    {
      "cve": "CVE-2026-50751",
      "vendor": "Check Point",
      "product": "Security Gateway",
      "detail": "Improper Authentication",
      "affectedVersions": "—",
      "dateAdded": "2026-06-08",
      "dueDate": "2026-06-11",
      "status": "Ransomware",
      "group": "Ransomware-linked"
    },
    {
      "cve": "CVE-2026-0257",
      "vendor": "Palo Alto Networks",
      "product": "PAN-OS",
      "detail": "Authentication Bypass",
      "affectedVersions": "—",
      "dateAdded": "2026-05-29",
      "dueDate": "2026-06-01",
      "status": "Ransomware",
      "group": "Ransomware-linked"
    },
    {
      "cve": "CVE-2026-48027",
      "vendor": "Nx",
      "product": "Nx Console",
      "detail": "Embedded Malicious Code",
      "affectedVersions": "—",
      "dateAdded": "2026-05-27",
      "dueDate": "2026-06-10",
      "status": "Ransomware",
      "group": "Ransomware-linked"
    },
    {
      "cve": "CVE-2026-45321",
      "vendor": "TanStack",
      "product": "TanStack",
      "detail": "Unspecified",
      "affectedVersions": "—",
      "dateAdded": "2026-05-27",
      "dueDate": "2026-06-10",
      "status": "Ransomware",
      "group": "Ransomware-linked"
    },
    {
      "cve": "CVE-2026-41940",
      "vendor": "WebPros",
      "product": "cPanel & WHM and WP2 (WordPress Squared)",
      "detail": "Missing Authentication for Critical Function",
      "affectedVersions": "—",
      "dateAdded": "2026-04-30",
      "dueDate": "2026-05-03",
      "status": "Ransomware",
      "group": "Ransomware-linked"
    },
    {
      "cve": "CVE-2024-1708",
      "vendor": "ConnectWise",
      "product": "ScreenConnect",
      "detail": "Path Traversal",
      "affectedVersions": "—",
      "dateAdded": "2026-04-28",
      "dueDate": "2026-05-12",
      "status": "Ransomware",
      "group": "Ransomware-linked"
    }
  ]
}