Microsoft Exchange, Cisco Flaws Hit KEV
Microsoft Exchange Server and Cisco Crosswork/Secure Workload vulnerabilities are actively exploited, with multiple critical flaws added to KEV and high CVSS scores.

Microsoft Exchange Server remains a high-priority target, with multiple critical RCE vulnerabilities added to the KEV catalog. CVE-2021-26855, a critical flaw with a CVSS score of 9.1, allows for remote code execution and has been linked to the StrikeShark campaign deploying Cobalt Strike. Other Exchange vulnerabilities, including CVE-2021-42321, CVE-2023-21529, CVE-2021-26858, CVE-2021-26857, and CVE-2021-27065, also carry critical risk scores and are actively exploited. These flaws, some dating back to 2021, highlight persistent threats to organizations running vulnerable Exchange environments, as detailed in reports by The Hacker News and Securelist. The Tenable Blog and The Register also noted the ongoing exploitation of these Exchange vulnerabilities in various threat actor campaigns.
Cisco has addressed a significant number of critical vulnerabilities across its Crosswork and Secure Workload product lines, with five flaws (CVE-2026-20358, CVE-2026-20357, CVE-2026-20030, CVE-2026-20317) receiving a CVSS score of 10.0. These vulnerabilities, described by The Register as having severity scores akin to Olympic gymnastics, enable various attacks including unauthorized code downloads and cleartext transmission of sensitive information. While the provided descriptions are somewhat vague, the critical nature and high CVSS scores indicate a severe risk to organizations utilizing these Cisco products. SecurityWeek and The Hacker News have reported on these patches, emphasizing the critical nature of the vulnerabilities.
Several other Microsoft products are impacted by newly disclosed vulnerabilities. Internet Explorer faces two RCE vulnerabilities, CVE-2021-26411 and CVE-2021-27085, with high severity ratings. Additionally, Active Directory Domain Services is affected by elevation of privilege vulnerabilities CVE-2021-42287 and CVE-2021-42278. The Windows Common Log File System Driver has an elevation of privilege vulnerability, CVE-2023-23376. Microsoft Word also has a critical RCE vulnerability, CVE-2023-21716, and the Protected Extensible Authentication Protocol (PEAP) has critical RCE flaws CVE-2023-21690 and CVE-2023-21689. These vulnerabilities, while not all on the KEV list, represent a broad attack surface across Microsoft's ecosystem.
A critical vulnerability in Joomla extensions from yootheme.com, CVE-2026-74803, allows unauthenticated arbitrary file uploads when the client-supplied Content-Type falls within the image MIME group. This flaw affects Zoo versions prior to 4.1.64. The vulnerability stems from the image element accepting arbitrary files under specific conditions, posing a significant risk for unauthorized file manipulation and potential system compromise.
Ozols Grupa OZOLS on Windows is affected by CVE-2026-22306, a critical vulnerability that involves the download of code without integrity checks, inclusion of functionality from untrusted control spheres, and cleartext transmission of sensitive information. This vulnerability is attributed to an abandoned auto-update domain, indicating a potential supply chain risk. The critical severity and CVSS score of 10.0 highlight the significant danger posed by this flaw.