CISA's list that day

26 January 2026

On CISA added 5 vulnerabilities to its list of exploited vulnerabilities, in Linux Kernel, SmarterTools SmarterMail, Microsoft Office and 1 other product. US federal agencies must fix them by .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2025-52691Unrestricted Upload of File with Dangerous TypeSmarterTools SmarterMailPatch nowRansomware use, listed within a year; Metasploit module0.86
CVE-2026-23760Authentication Bypass Using an Alternate Path or ChannelSmarterTools SmarterMailPatch nowRansomware use, listed within a year0.97
CVE-2026-24061Argument InjectionGNU InetUtilsPatch this weekMetasploit module; EPSS 0.990.99
CVE-2026-21509Security Feature BypassMicrosoft OfficePatch this weekEPSS 0.710.71
CVE-2018-14634Integer OverflowLinux KernelPatch soon0.15