An official Admiresty Corporation service
How to verify
Official Admiresty services use admiresty.co

Admiresty Corporation operates ThreatGrid and its full service ecosystem from admiresty.co. All official platforms run from this domain or a verified subdomain. If you’re unsure, visit admiresty.co directly to confirm.

Secure Admiresty services always use HTTPS

A padlock and https:// in your address bar confirm a safe, encrypted connection. Never enter credentials or share sensitive data on any page without a valid HTTPS connection to an Admiresty domain.

Security Bulletins

Active threat advisories and known exploited vulnerabilities.

Pulled daily from the CISA Known Exploited Vulnerabilities catalog. Every entry has confirmed active exploitation in the wild. Last synced Sep 11, 2026.

1,709 total bulletins 1,709 critical or high severity Source: CISA KEV + NVD
Critical CVE-2026-32202 Microsoft · Windows Added Apr 28, 2026

Microsoft Windows Protection Mechanism Failure Vulnerability

Microsoft Windows Shell contains a protection mechanism failure vulnerability that allows an unauthorized attacker to perform spoofing over a network.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-29635 D-Link · DIR-823X Added Apr 24, 2026

D-Link DIR-823X Command Injection Vulnerability

D-Link DIR-823X contains a command injection vulnerability that allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2024-7399 Samsung · MagicINFO 9 Server Added Apr 24, 2026

Samsung MagicINFO 9 Server Path Traversal Vulnerability

Samsung MagicINFO 9 Server contains a path traversal vulnerability that could allow an attacker to write arbitrary files as system authority.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2024-57728 SimpleHelp · SimpleHelp Added Apr 24, 2026

SimpleHelp Path Traversal Vulnerability

SimpleHelp contains a path traversal vulnerability that allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2024-57726 SimpleHelp · SimpleHelp Added Apr 24, 2026

SimpleHelp Missing Authorization Vulnerability

SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-39987 Marimo · Marimo Added Apr 23, 2026

Marimo Remote Code Execution Vulnerability

Marimo contains an pre-authorization remote code execution vulnerability, allowing an unauthenticated attacked to shell access and execute arbitrary system commands.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-33825 Microsoft · Defender Added Apr 22, 2026

Microsoft Defender Insufficient Granularity of Access Control Vulnerability

Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-20122 Cisco · Catalyst SD-WAN Manger Added Apr 20, 2026

Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability

Cisco Catalyst SD-WAN Manager contains an incorrect use of privileged APIs vulnerability due to improper file handling on the API interface of an affected system. An attacker could exploit this vulnerability by uploading a malicious file on the local file system. A successful exploit could allow the attacker to overwrite arbitrary files on the affected system and gain vmanage user privileges.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-20133 Cisco · Catalyst SD-WAN Manager Added Apr 20, 2026

Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability

Cisco Catalyst SD-WAN Manager contains an exposure of sensitive information to an unauthorized actor vulnerability that could allow remote attackers to view sensitive information on affected systems.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-2749 Kentico · Kentico Xperience Added Apr 20, 2026

Kentico Xperience Path Traversal Vulnerability

Kentico Xperience contains a path traversal vulnerability that could allow an authenticated user's Staging Sync Server to upload arbitrary data to path relative locations.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-27351 PaperCut · NG/MF Added Apr 20, 2026

PaperCut NG/MF Improper Authentication Vulnerability

PaperCut NG/MF contains an improper authentication vulnerability that could allow remote attackers to bypass authentication on affected installations via the SecurityRequestFilter class.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-48700 Synacor · Zimbra Collaboration Suite (ZCS) Added Apr 20, 2026

Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability

Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that could allow attackers to execute arbitrary JavaScript within the user's session, potentially leading to unauthorized access to sensitive information.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-20128 Cisco · Catalyst SD-WAN Manager Added Apr 20, 2026

Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability

Cisco Catalyst SD-WAN Manager contains a storing passwords in a recoverable format vulnerability that allows an authenticated, local attacker to gain DCA user privileges by accessing a credential file for the DCA user on the filesystem as a low-privileged user.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-32975 Quest · KACE Systems Management Appliance (SMA) Added Apr 20, 2026

Quest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability

Quest KACE Systems Management Appliance (SMA) contains an improper authentication vulnerability that could allow attackers to impersonate legitimate users without valid credentials.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2024-27199 JetBrains · TeamCity Added Apr 20, 2026

JetBrains TeamCity Relative Path Traversal Vulnerability

JetBrains TeamCity contains a relative path traversal vulnerability that could allow limited admin actions to be performed.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-34197 Apache · ActiveMQ Added Apr 16, 2026

Apache ActiveMQ Improper Input Validation Vulnerability

Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2009-0238 Microsoft · Office Added Apr 14, 2026

Microsoft Office Remote Code Execution

Microsoft Office Excel contains a remote code execution vulnerability that could allow an attacker to take complete control of an affected system if a user opens a specially crafted Excel file that includes a malformed object.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-32201 Microsoft · SharePoint Server Added Apr 14, 2026

Microsoft SharePoint Server Improper Input Validation Vulnerability

Microsoft SharePoint Server contains an improper input validation vulnerability that allows an unauthorized attacker to perform spoofing over a network.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2012-1854 Microsoft · Visual Basic for Applications (VBA) Added Apr 13, 2026

Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability

Microsoft Visual Basic for Applications (VBA) contains an insecure library loading vulnerability that could allow for remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-60710 Microsoft · Windows Added Apr 13, 2026

Microsoft Windows Link Following Vulnerability

Microsoft Windows contains a link following vulnerability that allows for privilege escalation

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-21529 Microsoft · Exchange Server Added Apr 13, 2026

Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability

Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-36424 Microsoft · Windows Added Apr 13, 2026

Microsoft Windows Out-of-Bounds Read Vulnerability

Microsoft Windows Common Log File System Driver contains an out-of-bounds read vulnerability that could allow a threat actor for privileges escalation

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-9715 Adobe · Acrobat Added Apr 13, 2026

Adobe Acrobat Use-After-Free Vulnerability

Adobe Acrobat contains a use-after-free vulnerability that allows for code execution

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-21643 Fortinet · FortiClient EMS Added Apr 13, 2026

Fortinet FortiClient EMS SQL Injection Vulnerability

Fortinet FortiClient EMS contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2026-34621 Adobe · Acrobat and Reader Added Apr 13, 2026

Adobe Acrobat and Reader Prototype Pollution Vulnerability

Adobe Acrobat and Reader contain a prototype pollution vulnerability that allows for arbitrary code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed

Need help prioritizing these vulnerabilities?

ThreatGrid can assess your environment and map active CVEs to your monitored assets.