An official Admiresty Corporation service
How to verify
Official Admiresty services use admiresty.co

Admiresty Corporation operates ThreatGrid and its full service ecosystem from admiresty.co. All official platforms run from this domain or a verified subdomain. If you’re unsure, visit admiresty.co directly to confirm.

Secure Admiresty services always use HTTPS

A padlock and https:// in your address bar confirm a safe, encrypted connection. Never enter credentials or share sensitive data on any page without a valid HTTPS connection to an Admiresty domain.

Security Bulletins

Active threat advisories and known exploited vulnerabilities.

Pulled daily from the CISA Known Exploited Vulnerabilities catalog. Every entry has confirmed active exploitation in the wild. Last synced Jul 27, 2026.

1,655 total bulletins 1,655 critical or high severity Source: CISA KEV + NVD
Critical CVE-2024-57726 SimpleHelp · SimpleHelp Added Apr 24, 2026

SimpleHelp Missing Authorization Vulnerability

SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-39987 Marimo · Marimo Added Apr 23, 2026

Marimo Remote Code Execution Vulnerability

Marimo contains an pre-authorization remote code execution vulnerability, allowing an unauthenticated attacked to shell access and execute arbitrary system commands.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-33825 Microsoft · Defender Added Apr 22, 2026

Microsoft Defender Insufficient Granularity of Access Control Vulnerability

Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-20122 Cisco · Catalyst SD-WAN Manger Added Apr 20, 2026

Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability

Cisco Catalyst SD-WAN Manager contains an incorrect use of privileged APIs vulnerability due to improper file handling on the API interface of an affected system. An attacker could exploit this vulnerability by uploading a malicious file on the local file system. A successful exploit could allow the attacker to overwrite arbitrary files on the affected system and gain vmanage user privileges.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-20133 Cisco · Catalyst SD-WAN Manager Added Apr 20, 2026

Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability

Cisco Catalyst SD-WAN Manager contains an exposure of sensitive information to an unauthorized actor vulnerability that could allow remote attackers to view sensitive information on affected systems.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-2749 Kentico · Kentico Xperience Added Apr 20, 2026

Kentico Xperience Path Traversal Vulnerability

Kentico Xperience contains a path traversal vulnerability that could allow an authenticated user's Staging Sync Server to upload arbitrary data to path relative locations.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-27351 PaperCut · NG/MF Added Apr 20, 2026

PaperCut NG/MF Improper Authentication Vulnerability

PaperCut NG/MF contains an improper authentication vulnerability that could allow remote attackers to bypass authentication on affected installations via the SecurityRequestFilter class.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-48700 Synacor · Zimbra Collaboration Suite (ZCS) Added Apr 20, 2026

Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability

Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that could allow attackers to execute arbitrary JavaScript within the user's session, potentially leading to unauthorized access to sensitive information.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-20128 Cisco · Catalyst SD-WAN Manager Added Apr 20, 2026

Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability

Cisco Catalyst SD-WAN Manager contains a storing passwords in a recoverable format vulnerability that allows an authenticated, local attacker to gain DCA user privileges by accessing a credential file for the DCA user on the filesystem as a low-privileged user.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-32975 Quest · KACE Systems Management Appliance (SMA) Added Apr 20, 2026

Quest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability

Quest KACE Systems Management Appliance (SMA) contains an improper authentication vulnerability that could allow attackers to impersonate legitimate users without valid credentials.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2024-27199 JetBrains · TeamCity Added Apr 20, 2026

JetBrains TeamCity Relative Path Traversal Vulnerability

JetBrains TeamCity contains a relative path traversal vulnerability that could allow limited admin actions to be performed.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-34197 Apache · ActiveMQ Added Apr 16, 2026

Apache ActiveMQ Improper Input Validation Vulnerability

Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2009-0238 Microsoft · Office Added Apr 14, 2026

Microsoft Office Remote Code Execution

Microsoft Office Excel contains a remote code execution vulnerability that could allow an attacker to take complete control of an affected system if a user opens a specially crafted Excel file that includes a malformed object.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-32201 Microsoft · SharePoint Server Added Apr 14, 2026

Microsoft SharePoint Server Improper Input Validation Vulnerability

Microsoft SharePoint Server contains an improper input validation vulnerability that allows an unauthorized attacker to perform spoofing over a network.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2012-1854 Microsoft · Visual Basic for Applications (VBA) Added Apr 13, 2026

Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability

Microsoft Visual Basic for Applications (VBA) contains an insecure library loading vulnerability that could allow for remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-60710 Microsoft · Windows Added Apr 13, 2026

Microsoft Windows Link Following Vulnerability

Microsoft Windows contains a link following vulnerability that allows for privilege escalation

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-21529 Microsoft · Exchange Server Added Apr 13, 2026

Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability

Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-36424 Microsoft · Windows Added Apr 13, 2026

Microsoft Windows Out-of-Bounds Read Vulnerability

Microsoft Windows Common Log File System Driver contains an out-of-bounds read vulnerability that could allow a threat actor for privileges escalation

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-9715 Adobe · Acrobat Added Apr 13, 2026

Adobe Acrobat Use-After-Free Vulnerability

Adobe Acrobat contains a use-after-free vulnerability that allows for code execution

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-21643 Fortinet · FortiClient EMS Added Apr 13, 2026

Fortinet FortiClient EMS SQL Injection Vulnerability

Fortinet FortiClient EMS contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-34621 Adobe · Acrobat and Reader Added Apr 13, 2026

Adobe Acrobat and Reader Prototype Pollution Vulnerability

Adobe Acrobat and Reader contain a prototype pollution vulnerability that allows for arbitrary code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-1340 Ivanti · Endpoint Manager Mobile (EPMM) Added Apr 8, 2026

Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability

Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-35616 Fortinet · FortiClient EMS Added Apr 6, 2026

Fortinet FortiClient EMS Improper Access Control Vulnerability

Fortinet FortiClient EMS contains an improper access control vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-3502 TrueConf · Client Added Apr 2, 2026

TrueConf Client Download of Code Without Integrity Check Vulnerability

TrueConf Client contains a download of code without integrity check vulnerability. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the payload is executed or installed by the updater, this may result in arbitrary code execution in the context of the updating process or user.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-5281 Google · Dawn Added Apr 1, 2026

Google Dawn Use-After-Free Vulnerability

Google Dawn contains an use-after-free vulnerability that could allow a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. This vulnerability could affect multiple Chromium-based products including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed

Need help prioritizing these vulnerabilities?

ThreatGrid can assess your environment and map active CVEs to your monitored assets.