Skip to main content
Griffin Technology PartnersGTP

Public security advisories

GTP Security Intelligence

Current vulnerabilities, known exploitation, Microsoft security updates, and practical guidance from Griffin Technology Partners.

Primary sources

Microsoft Security Response Center
CISA Known Exploited Vulnerabilities

Subscribe via RSS

Vulnerability intelligence

Security bulletins

Last collection: October 9, 2026
Six-hour refresh · Public-source information only

494 bulletins · Page 5 of 21

JSON feed
Severity not suppliedKnown exploited
CVE-2026-46817Oracle

Oracle E-Business Suite Improper Privilege Management Vulnerability

Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments.

CVSS
Not supplied
Update availability
Patch status unknown

Affected: E-Business Suite

Added to CISA KEV

HighKnown exploited
CVE-2026-56155Microsoft

Active Directory Federation Services Elevation of Privilege Vulnerability

Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.

CVSS
7.8
Update availability
Security update available

Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +13 more

Updated

Severity not suppliedKnown exploited
CVE-2008-4128Cisco

Cisco IOS Cross-Site Request Forgery Vulnerability

Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI.

CVSS
Not supplied
Update availability
Patch status unknown

Affected: IOS

Added to CISA KEV

Severity not suppliedKnown exploited
CVE-2026-48908JoomShaper

JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability

JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.

CVSS
Not supplied
Update availability
Patch status unknown

Affected: SP Page Builder

Added to CISA KEV

Severity not suppliedKnown exploited
CVE-2026-48558SimpleHelp

SimpleHelp Authentication Bypass Vulnerability

SimpleHelp contains an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication.

CVSS
Not supplied
Update availability
Patch status unknown

Affected: SimpleHelp

Added to CISA KEV

Severity not suppliedKnown exploited
CVE-2026-20230Cisco

Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability

Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) contain a server-side request forgery (SSRF) Vulnerability that could allow an unauthenticated, remote attacker to write files to the underlying operating system that could be used later to elevate to root.

CVSS
Not supplied
Update availability
Patch status unknown

Affected: Unified Communications Manager

Added to CISA KEV

Severity not suppliedKnown exploited
CVE-2025-67038Lantronix

Lantronix EDS5000 Code Injection Vulnerability

Lantronix EDS5000 contains a code injection vulnerability that could allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.

CVSS
Not supplied
Update availability
Patch status unknown

Affected: EDS5000

Added to CISA KEV

Severity not suppliedKnown exploited
CVE-2026-34909Ubiquiti

Ubiquiti UniFi OS Path Traversal Vulnerability

Ubiquiti UniFi OS contains a path traversal vulnerability which could allow a malicious actor with access to the network to access files on the underlying system that could be manipulated to access an underlying account.

CVSS
Not supplied
Update availability
Patch status unknown

Affected: UniFi OS

Added to CISA KEV

Severity not suppliedKnown exploited
CVE-2008-4250Microsoft

Microsoft Windows Buffer Overflow Vulnerability

Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization.

CVSS
Not supplied
Update availability
Patch status unknown

Affected: Windows

Added to CISA KEV

Severity not suppliedKnown exploited
CVE-2009-1537Microsoft

Microsoft DirectX NULL Byte Overwrite Vulnerability

Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitrary code via a crafted QuickTime media file.

CVSS
Not supplied
Update availability
Patch status unknown

Affected: DirectX

Added to CISA KEV

Severity not suppliedKnown exploited
CVE-2010-0249Microsoft

Microsoft Internet Explorer Use-After-Free Vulnerability

Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

CVSS
Not supplied
Update availability
Patch status unknown

Affected: Internet Explorer

Added to CISA KEV

Sources & coverage

The collection starts with 90 days of Microsoft updates and CISA additions, plus older Microsoft vulnerabilities still listed by CISA. Older entries do not imply that a product remains supported. Counts describe this collection, not every vulnerability or any customer environment.

Microsoft Security Response Center (opens in a new tab)

Last successful check: October 9, 2026

CISA Known Exploited Vulnerabilities (opens in a new tab)

Last successful check: October 9, 2026

Managed by GTP?

Griffin Technology Partners managed customers may receive additional environment-specific security guidance and remediation assistance through their managed services relationship.

Security bulletins are provided for informational purposes and compiled from authoritative public sources. Vulnerability applicability varies by environment. Validate affected products, configuration, compatibility requirements, and vendor guidance before making production changes.