CISA's list that day
26 January 2026
On CISA added 5 vulnerabilities to its list of exploited vulnerabilities, in Linux Kernel, SmarterTools SmarterMail, Microsoft Office and 1 other product. US federal agencies must fix them by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2025-52691Unrestricted Upload of File with Dangerous Type | SmarterTools SmarterMail | Patch nowRansomware use, listed within a year; Metasploit module | 0.86 | ||
| CVE-2026-23760Authentication Bypass Using an Alternate Path or Channel | SmarterTools SmarterMail | Patch nowRansomware use, listed within a year | 0.97 | ||
| CVE-2026-24061Argument Injection | GNU InetUtils | Patch this weekMetasploit module; EPSS 0.99 | 0.99 | ||
| CVE-2026-21509Security Feature Bypass | Microsoft Office | Patch this weekEPSS 0.71 | 0.71 | ||
| CVE-2018-14634Integer Overflow | Linux Kernel | Patch soon | 0.15 |