Threat Intelligence
Vulnerability Advisories
9 Realms tracks the CISA Known Exploited Vulnerabilities catalog and surfaces the threats most relevant to your environment. Click any entry for our full advisory.
1,559 entries in CISA KEV
CVE-2026-1340Ivanti · Endpoint Manager Mobile (EPMM)
Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
CVE-2026-35616Fortinet · FortiClient EMS
Fortinet FortiClient EMS Improper Access Control Vulnerability
CVE-2026-3502TrueConf · Client
TrueConf Client Download of Code Without Integrity Check Vulnerability
CVE-2026-5281Google · Dawn
Google Dawn Use-After-Free Vulnerability
CVE-2026-3055Citrix · NetScaler
Citrix NetScaler Out-of-Bounds Read Vulnerability
CVE-2025-53521F5 · BIG-IP
F5 BIG-IP Stack-Based Buffer Overflow Vulnerability
CVE-2026-33634Aquasecurity · Trivy
Aquasecurity Trivy Embedded Malicious Code Vulnerability
CVE-2026-33017Langflow · Langflow
Langflow Code Injection Vulnerability
CVE-2025-32432Craft CMS · Craft CMS
Craft CMS Code Injection Vulnerability
CVE-2025-54068Laravel · Livewire
Laravel Livewire Code Injection Vulnerability
CVE-2025-43510Apple · Multiple Products
Apple Multiple Products Improper Locking Vulnerability
CVE-2025-43520Apple · Multiple Products
Apple Multiple Products Classic Buffer Overflow Vulnerability
CVE-2025-31277Apple · Multiple Products
Apple Multiple Products Buffer Overflow Vulnerability
CVE-2026-20131Cisco · Secure Firewall Management Center (FMC)
Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability
CVE-2025-66376Synacor · Zimbra Collaboration Suite (ZCS)
Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability
CVE-2026-20963Microsoft · SharePoint
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
CVE-2025-47813Wing FTP Server · Wing FTP Server
Wing FTP Server Information Disclosure Vulnerability
CVE-2026-3910Google · Chromium V8
Google Chromium V8 Improper Restriction of Operations Within the Bounds of a Memory Buffer Vulnerability
CVE-2026-3909Google · Skia
Google Skia Out-of-Bounds Write Vulnerability
CVE-2025-68613n8n · n8n
n8n Improper Control of Dynamically-Managed Code Resources Vulnerability
CVE-2021-22054Omnissa · Workspace One UEM
Omnissa Workspace ONE Server-Side Request Forgery
CVE-2025-26399SolarWinds · Web Help Desk
SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability
CVE-2026-1603Ivanti · Endpoint Manager (EPM)
Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability
CVE-2017-7921Hikvision · Multiple Products
Hikvision Multiple Products Improper Authentication Vulnerability
Vulnerability data sourced from the CISA Known Exploited Vulnerabilities catalog. Threat level data from the SANS Internet Storm Center. Catalog contains 1,559 entries (version 2026.04.08).