# Added to CISA KEV Since 1 September 2026

CVEs added to the CISA KEV catalog on or after 1 September 2026.

Source: https://docs.deepinfo.com/reference/vulnerability/search/examples/cisa-exploit-add/

Last updated: 2026-09-26

---
`POST https://api.deepinfo.com/v1/discovery/vulnerability-search?page_size=25`

CVEs added to the CISA KEV catalog on or after 1 September 2026.

Example 1 of 4 in **Filters › NVD KEV Fields** · [Vulnerability Search Examples](/reference/vulnerability/search/examples/) · endpoint: [Search](/reference/vulnerability/search/)

Tags: `field` `cisa_exploit_add` · `operator` `gte`

`cisa_exploit_add` is the day the CVE was added to the CISA Known Exploited Vulnerabilities (KEV) catalog, as the NVD record carries it.

`gte` matches `2026-09-01` and above.

In the response, look at `results[].cisa_exploit_add`.

## Request

| Parameter | In | Value |
|---|---|---|
| `page_size` | query | `25` |
| `filters.must[0].name` | body | `cisa_exploit_add` |
| `filters.must[0].type` | body | `gte` |
| `filters.must[0].value` | body | `2026-09-01` |

```bash
curl -X POST 'https://api.deepinfo.com/v1/discovery/vulnerability-search?page_size=25' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{
  "filters": {
    "must": [
      {
        "name": "cisa_exploit_add",
        "type": "gte",
        "value": "2026-09-01"
      }
    ]
  }
}'
```

## Response

### 200 · OK

> Shortened for this page: results: 3 of 25 shown

`Content-Type: application/json` · `ratelimit-limit: 1` · `ratelimit-remaining: 0` · `ratelimit-reset: 1` · `x-ratelimit-limit-second: 1` · `x-ratelimit-remaining-second: 0` · `deepinfo-request-id: 5f0c6a8e-1b2d-4c3e-9f4a-7b8c9d0e1f2a`

```json
{
  "page": 1,
  "page_size": 25,
  "result_count": 34,
  "results": [
    {
      "id": "CVE-2026-86218",
      "source_identifier": "a5532a13-c4dd-4202-bef1-e0b8f2f8d12b",
      "published": "2026-09-06T03:17:17Z",
      "last_modified": "2026-09-09T05:18:19Z",
      "status": "Analyzed",
      "evaluator_comment": null,
      "evaluator_solution": null,
      "evaluator_impact": null,
      "cisa_exploit_add": "2026-09-08",
      "cisa_action_due": "2026-09-11",
      "cisa_required_action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
      "cisa_vulnerability_name": "N-able N-central Static Code Injection Vulnerability",
      "descriptions": [
        {
          "lang": "en",
          "value": "N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14."
        }
      ],
      "references": [
        {
          "url": "https://me.n-able.com/s/security-advisory/aArVy0000002Ld3KAE/cve202686218-preauthentication-remote-code-execution",
          "source": "a5532a13-c4dd-4202-bef1-e0b8f2f8d12b",
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-86218",
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "tags": [
            "US Government Resource"
          ]
        }
      ],
      "metrics": {
        "cvss_metric_v40": [
          {
            "source": "a5532a13-c4dd-4202-bef1-e0b8f2f8d12b",
            "type": "Secondary",
            "cvss_data": {
              "version": "4.0",
              "vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
              "attack_vector": "NETWORK",
              "attack_complexity": "LOW",
              "attack_requirements": "NONE",
              "privileges_required": "NONE",
              "user_interaction": "NONE",
              "vulnerable_system_confidentiality": null,
              "vulnerable_system_integrity": null,
              "vulnerable_system_availability": null,
              "subsequent_system_confidentiality": null,
              "subsequent_system_integrity": null,
              "subsequent_system_availability": null,
              "exploit_maturity": "NOT_DEFINED",
              "confidentiality_requirements": null,
              "integrity_requirements": null,
              "availability_requirements": null,
              "modified_attack_vector": "NOT_DEFINED",
              "modified_attack_complexity": "NOT_DEFINED",
              "modified_attack_requirements": "NOT_DEFINED",
              "modified_privileges_required": "NOT_DEFINED",
              "modified_user_interaction": "NOT_DEFINED",
              "modified_vulnerable_system_confidentiality": null,
              "modified_vulnerable_system_integrity": null,
              "modified_vulnerable_system_availability": null,
              "modified_subsequent_system_confidentiality": null,
              "modified_subsequent_system_integrity": null,
              "modified_subsequent_system_availability": null,
              "safety": null,
              "automatable": null,
              "recovery": null,
              "value_density": "NOT_DEFINED",
              "vulnerability_response_effort": "NOT_DEFINED",
              "provider_urgency": "NOT_DEFINED",
              "base_score": 10.0,
              "base_severity": "CRITICAL"
            }
          }
        ],
        "cvss_metric_v31": [
          {
            "source": "user@nist.gov",
            "type": "Primary",
            "cvss_data": {
              "version": "3.1",
              "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
              "attack_vector": "NETWORK",
              "attack_complexity": "LOW",
              "privileges_required": "NONE",
              "user_interaction": "NONE",
              "scope": "UNCHANGED",
              "confidentiality_impact": "HIGH",
              "integrity_impact": "HIGH",
              "availability_impact": "HIGH",
              "base_score": 9.8,
              "base_severity": "CRITICAL",
              "exploit_code_maturity": null,
              "remediation_level": null,
              "report_confidence": null,
              "temporal_score": null,
              "temporal_severity": null,
              "confidentiality_requirement": null,
              "integrity_requirement": null,
              "availability_requirement": null,
              "modified_attack_vector": null,
              "modified_attack_complexity": null,
              "modified_privileges_required": null,
              "modified_user_interaction": null,
              "modified_scope": null,
              "modified_confidentiality_impact": null,
              "modified_integrity_impact": null,
              "modified_availability_impact": null,
              "environmental_score": null,
              "environmental_severity": null
            },
            "exploitability_score": 3.9,
            "impact_score": 5.9
          }
        ],
        "cvss_metric_v30": null,
        "cvss_metric_v2": null
      },
      "weaknesses": [
        {
          "source": "a5532a13-c4dd-4202-bef1-e0b8f2f8d12b",
          "type": "Secondary",
          "description": [
            {
              "lang": "en",
              "value": "CWE-96"
            }
          ]
        }
      ],
      "configurations": [
        {
          "operator": null,
          "negate": null,
          "nodes": [
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:n-able:n-central:*:*:*:*:*:*:*:*",
                  "match_criteria_id": "6CEC2750-AFFB-40A4-97E0-88BDAC106F5E",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": "2026.3"
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:n-able:n-central:2026.3:-:*:*:*:*:*:*",
                  "match_criteria_id": "EB21160B-DDC4-4F70-A703-E313DED8CAF2",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:n-able:n-central:2026.3:hotfix1:*:*:*:*:*:*",
                  "match_criteria_id": "B28786B6-1DFC-4088-B3CC-C099719EDA17",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:n-able:n-central:2026.3:hotfix2:*:*:*:*:*:*",
                  "match_criteria_id": "24B69FFD-40FD-4DE2-AC51-A2101AD28EB3",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:n-able:n-central:2026.3:hotfix3:*:*:*:*:*:*",
                  "match_criteria_id": "BFA703C2-2F80-4FAC-9DA8-EE33A0F0646F",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                }
              ]
            }
          ]
        }
      ],
      "vendor_comments": null,
      "enrichment": {
        "cpe": [
          {
            "criteria": "cpe:2.3:a:n-able:n-central:*:*:*:*:*:*:*:*",
            "vendor": "n-able",
            "product": "n-central",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": "2026.3",
            "affected_versions_first": "2023.4",
            "affected_versions_last": "2026.2"
          },
          {
            "criteria": "cpe:2.3:a:n-able:n-central:2026.3:-:*:*:*:*:*:*",
            "vendor": "n-able",
            "product": "n-central",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": "2026.3",
            "affected_versions_last": "2026.3"
          },
          {
            "criteria": "cpe:2.3:a:n-able:n-central:2026.3:hotfix1:*:*:*:*:*:*",
            "vendor": "n-able",
            "product": "n-central",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": "2026.3",
            "affected_versions_last": "2026.3"
          },
          {
            "criteria": "cpe:2.3:a:n-able:n-central:2026.3:hotfix2:*:*:*:*:*:*",
            "vendor": "n-able",
            "product": "n-central",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": "2026.3",
            "affected_versions_last": "2026.3"
          },
          {
            "criteria": "cpe:2.3:a:n-able:n-central:2026.3:hotfix3:*:*:*:*:*:*",
            "vendor": "n-able",
            "product": "n-central",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": "2026.3",
            "affected_versions_last": "2026.3"
          }
        ],
        "cwe": [
          {
            "id": 96,
            "owasptop10_2021": "A03 Injection",
            "name": "Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')",
            "description": "The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes code syntax before inserting the input into an executable resource, such as a library, configuration file, or template.",
            "capec_id": [
              35,
              73,
              77,
              81,
              85
            ],
            "scope": [
              "Access Control",
              "Availability",
              "Confidentiality",
              "Integrity",
              "Non-Repudiation",
              "Other"
            ],
            "impact": [
              "Bypass Protection Mechanism",
              "Execute Unauthorized Code or Commands",
              "Gain Privileges or Assume Identity",
              "Hide Activities",
              "Read Application Data",
              "Read Files or Directories"
            ],
            "detection_method": [
              "Automated Static Analysis"
            ]
          }
        ],
        "epss_score": {
          "epss": 0.07494,
          "percentile": 0.94295,
          "date": "2026-09-21"
        },
        "cisa_kev": {
          "vendor_project": "N-able",
          "product": "N-central",
          "vulnerability_name": "N-able N-central Static Code Injection Vulnerability",
          "date_added": "2026-09-08",
          "short_description": "N-able N-central contains a static code injection vulnerability that could allow for pre-authentication remote code execution.",
          "required_action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
          "due_date": "2026-09-11",
          "known_ransomware_campaign_use": "Unknown",
          "notes": "https://status.n-able.com/2026/09/06/n-central-2026-3-hotfix-4-cve-2026-86218/ ; https://me.n-able.com/s/security-advisory/aArVy0000002Ld3KAE/cve202686218-preauthentication-remote-code-execution ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-86218"
        },
        "vdeep_metric": {
          "available_versions": [
            "4.0",
            "3.1"
          ],
          "source": "a5532a13-c4dd-4202-bef1-e0b8f2f8d12b",
          "type": "Secondary",
          "cvss_data": {
            "version": "4.0",
            "vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "attack_vector": "NETWORK",
            "attack_complexity": "LOW",
            "attack_requirements": "NONE",
            "privileges_required": "NONE",
            "user_interaction": "NONE",
            "vulnerable_system_confidentiality": null,
            "vulnerable_system_integrity": null,
            "vulnerable_system_availability": null,
            "subsequent_system_confidentiality": null,
            "subsequent_system_integrity": null,
            "subsequent_system_availability": null,
            "exploit_maturity": "NOT_DEFINED",
            "confidentiality_requirements": null,
            "integrity_requirements": null,
            "availability_requirements": null,
            "modified_attack_vector": "NOT_DEFINED",
            "modified_attack_complexity": "NOT_DEFINED",
            "modified_attack_requirements": "NOT_DEFINED",
            "modified_privileges_required": "NOT_DEFINED",
            "modified_user_interaction": "NOT_DEFINED",
            "modified_vulnerable_system_confidentiality": null,
            "modified_vulnerable_system_integrity": null,
            "modified_vulnerable_system_availability": null,
            "modified_subsequent_system_confidentiality": null,
            "modified_subsequent_system_integrity": null,
            "modified_subsequent_system_availability": null,
            "safety": null,
            "automatable": null,
            "recovery": null,
            "value_density": "NOT_DEFINED",
            "vulnerability_response_effort": "NOT_DEFINED",
            "provider_urgency": "NOT_DEFINED",
            "base_score": 10.0,
            "base_severity": "CRITICAL"
          }
        }
      }
    },
    {
      "id": "CVE-2026-85706",
      "source_identifier": "user@gitlab.com",
      "published": "2026-09-12T03:16:30Z",
      "last_modified": "2026-09-23T22:16:59Z",
      "status": "Modified",
      "evaluator_comment": null,
      "evaluator_solution": null,
      "evaluator_impact": null,
      "cisa_exploit_add": "2026-09-11",
      "cisa_action_due": "2026-09-14",
      "cisa_required_action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
      "cisa_vulnerability_name": "GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability",
      "descriptions": [
        {
          "lang": "en",
          "value": "GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.11.12, 19.0 before 19.0.9, 19.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API."
        }
      ],
      "references": [
        {
          "url": "https://gitlab.com/gitlab-org/gitlab/-/work_items/627748",
          "source": "user@gitlab.com",
          "tags": [
            "Broken Link"
          ]
        },
        {
          "url": "https://hackerone.com/reports/3909881",
          "source": "user@gitlab.com",
          "tags": [
            "Permissions Required"
          ]
        },
        {
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-85706",
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "tags": [
            "Third Party Advisory",
            "US Government Resource"
          ]
        }
      ],
      "metrics": {
        "cvss_metric_v40": null,
        "cvss_metric_v31": [
          {
            "source": "user@gitlab.com",
            "type": "Secondary",
            "cvss_data": {
              "version": "3.1",
              "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N",
              "attack_vector": "NETWORK",
              "attack_complexity": "LOW",
              "privileges_required": "NONE",
              "user_interaction": "NONE",
              "scope": "CHANGED",
              "confidentiality_impact": "HIGH",
              "integrity_impact": "HIGH",
              "availability_impact": "NONE",
              "base_score": 10.0,
              "base_severity": "CRITICAL",
              "exploit_code_maturity": null,
              "remediation_level": null,
              "report_confidence": null,
              "temporal_score": null,
              "temporal_severity": null,
              "confidentiality_requirement": null,
              "integrity_requirement": null,
              "availability_requirement": null,
              "modified_attack_vector": null,
              "modified_attack_complexity": null,
              "modified_privileges_required": null,
              "modified_user_interaction": null,
              "modified_scope": null,
              "modified_confidentiality_impact": null,
              "modified_integrity_impact": null,
              "modified_availability_impact": null,
              "environmental_score": null,
              "environmental_severity": null
            },
            "exploitability_score": 3.9,
            "impact_score": 5.8
          }
        ],
        "cvss_metric_v30": null,
        "cvss_metric_v2": null
      },
      "weaknesses": [
        {
          "source": "user@gitlab.com",
          "type": "Secondary",
          "description": [
            {
              "lang": "en",
              "value": "CWE-22"
            }
          ]
        }
      ],
      "configurations": [
        {
          "operator": null,
          "negate": null,
          "nodes": [
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*",
                  "match_criteria_id": "8308AEE0-FFC1-48F0-8E66-E3D6E3EF301E",
                  "version_start_including": "18.7.0",
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": "19.1.8"
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*",
                  "match_criteria_id": "D19F6592-4940-46BE-A140-BCD284B0EC37",
                  "version_start_including": "18.7.0",
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": "19.1.8"
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*",
                  "match_criteria_id": "4A6AAECA-E557-43EF-B109-B92D1281E48B",
                  "version_start_including": "19.2.0",
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": "19.2.6"
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*",
                  "match_criteria_id": "8598AF82-D212-4B5D-ABC3-C12C9B217BF3",
                  "version_start_including": "19.2.0",
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": "19.2.6"
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*",
                  "match_criteria_id": "198FF0EF-1A45-484F-9268-F7821E006BA8",
                  "version_start_including": "19.3.0",
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": "19.3.2"
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*",
                  "match_criteria_id": "03B1901F-AAF4-421E-B704-5345CB840DEF",
                  "version_start_including": "19.3.0",
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": "19.3.2"
                }
              ]
            }
          ]
        }
      ],
      "vendor_comments": null,
      "enrichment": {
        "cpe": [
          {
            "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*",
            "vendor": "gitlab",
            "product": "gitlab",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": "18.7.0",
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": "19.1.8",
            "affected_versions_first": "18.7.0",
            "affected_versions_last": "19.1.7"
          },
          {
            "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*",
            "vendor": "gitlab",
            "product": "gitlab",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": "18.7.0",
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": "19.1.8",
            "affected_versions_first": "18.7.0",
            "affected_versions_last": "19.1.7"
          },
          {
            "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*",
            "vendor": "gitlab",
            "product": "gitlab",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": "19.2.0",
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": "19.2.6",
            "affected_versions_first": "19.2.0",
            "affected_versions_last": "19.2.5"
          },
          {
            "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*",
            "vendor": "gitlab",
            "product": "gitlab",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": "19.2.0",
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": "19.2.6",
            "affected_versions_first": "19.2.0",
            "affected_versions_last": "19.2.5"
          },
          {
            "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*",
            "vendor": "gitlab",
            "product": "gitlab",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": "19.3.0",
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": "19.3.2",
            "affected_versions_first": "19.3.0",
            "affected_versions_last": "19.3.1"
          },
          {
            "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*",
            "vendor": "gitlab",
            "product": "gitlab",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": "19.3.0",
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": "19.3.2",
            "affected_versions_first": "19.3.0",
            "affected_versions_last": "19.3.1"
          }
        ],
        "cwe": [
          {
            "id": 22,
            "owasptop10_2021": "A01 Broken Access Control",
            "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
            "description": "The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.",
            "capec_id": [
              64,
              76,
              78,
              79,
              126
            ],
            "scope": [
              "Availability",
              "Confidentiality",
              "Integrity"
            ],
            "impact": [
              "DoS: Crash, Exit, or Restart",
              "Execute Unauthorized Code or Commands",
              "Modify Files or Directories",
              "Read Files or Directories"
            ],
            "detection_method": [
              "Architecture or Design Review",
              "Automated Static Analysis",
              "Automated Static Analysis - Binary or Bytecode",
              "Automated Static Analysis - Source Code",
              "Dynamic Analysis with Automated Results Interpretation",
              "Dynamic Analysis with Manual Results Interpretation",
              "Manual Static Analysis",
              "Manual Static Analysis - Binary or Bytecode",
              "Manual Static Analysis - Source Code"
            ]
          }
        ],
        "epss_score": {
          "epss": 0.09287,
          "percentile": 0.95144,
          "date": "2026-09-23"
        },
        "cisa_kev": {
          "vendor_project": "GitLab",
          "product": "Community Edition and Enterprise Edition",
          "vulnerability_name": "GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability",
          "date_added": "2026-09-11",
          "short_description": "GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability that allows an unauthenticated user to read arbitrary files due to an improper path confinement and missing authentication enforcement in the repository commits API.",
          "required_action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
          "due_date": "2026-09-14",
          "known_ransomware_campaign_use": "Unknown",
          "notes": "https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-85706"
        },
        "vdeep_metric": {
          "available_versions": [
            "3.1"
          ],
          "source": "user@gitlab.com",
          "type": "Secondary",
          "cvss_data": {
            "version": "3.1",
            "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N",
            "attack_vector": "NETWORK",
            "attack_complexity": "LOW",
            "attack_requirements": null,
            "privileges_required": "NONE",
            "user_interaction": "NONE",
            "vulnerable_system_confidentiality": "HIGH",
            "vulnerable_system_integrity": "HIGH",
            "vulnerable_system_availability": "NONE",
            "subsequent_system_confidentiality": null,
            "subsequent_system_integrity": null,
            "subsequent_system_availability": null,
            "exploit_maturity": null,
            "confidentiality_requirements": null,
            "integrity_requirements": null,
            "availability_requirements": null,
            "modified_attack_vector": null,
            "modified_attack_complexity": null,
            "modified_attack_requirements": null,
            "modified_privileges_required": null,
            "modified_user_interaction": null,
            "modified_vulnerable_system_confidentiality": null,
            "modified_vulnerable_system_integrity": null,
            "modified_vulnerable_system_availability": null,
            "modified_subsequent_system_confidentiality": null,
            "modified_subsequent_system_integrity": null,
            "modified_subsequent_system_availability": null,
            "safety": null,
            "automatable": null,
            "recovery": null,
            "value_density": null,
            "vulnerability_response_effort": null,
            "provider_urgency": null,
            "base_score": 10.0,
            "base_severity": "CRITICAL"
          }
        }
      }
    },
    {
      "id": "CVE-2026-83548",
      "source_identifier": "user@sonicwall.com",
      "published": "2026-09-01T22:17:13Z",
      "last_modified": "2026-09-03T13:06:16Z",
      "status": "Analyzed",
      "evaluator_comment": null,
      "evaluator_solution": null,
      "evaluator_impact": null,
      "cisa_exploit_add": "2026-09-02",
      "cisa_action_due": "2026-09-05",
      "cisa_required_action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
      "cisa_vulnerability_name": "SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability",
      "descriptions": [
        {
          "lang": "en",
          "value": "A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations."
        }
      ],
      "references": [
        {
          "url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016",
          "source": "user@sonicwall.com",
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-83548",
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "tags": [
            "US Government Resource"
          ]
        }
      ],
      "metrics": {
        "cvss_metric_v40": null,
        "cvss_metric_v31": [
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary",
            "cvss_data": {
              "version": "3.1",
              "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
              "attack_vector": "NETWORK",
              "attack_complexity": "LOW",
              "privileges_required": "NONE",
              "user_interaction": "NONE",
              "scope": "CHANGED",
              "confidentiality_impact": "HIGH",
              "integrity_impact": "HIGH",
              "availability_impact": "HIGH",
              "base_score": 10.0,
              "base_severity": "CRITICAL",
              "exploit_code_maturity": null,
              "remediation_level": null,
              "report_confidence": null,
              "temporal_score": null,
              "temporal_severity": null,
              "confidentiality_requirement": null,
              "integrity_requirement": null,
              "availability_requirement": null,
              "modified_attack_vector": null,
              "modified_attack_complexity": null,
              "modified_privileges_required": null,
              "modified_user_interaction": null,
              "modified_scope": null,
              "modified_confidentiality_impact": null,
              "modified_integrity_impact": null,
              "modified_availability_impact": null,
              "environmental_score": null,
              "environmental_severity": null
            },
            "exploitability_score": 3.9,
            "impact_score": 6.0
          }
        ],
        "cvss_metric_v30": null,
        "cvss_metric_v2": null
      },
      "weaknesses": [
        {
          "source": "user@sonicwall.com",
          "type": "Secondary",
          "description": [
            {
              "lang": "en",
              "value": "CWE-441"
            },
            {
              "lang": "en",
              "value": "CWE-918"
            }
          ]
        }
      ],
      "configurations": [
        {
          "operator": "AND",
          "negate": null,
          "nodes": [
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:sonicwall:sma8200v:*:*:*:*:*:*:*:*",
                  "match_criteria_id": "F160BF49-63F6-4458-AA1B-9D46AF320741",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": "12.4.3-03526"
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:sonicwall:sma8200v:*:*:*:*:*:*:*:*",
                  "match_criteria_id": "51E4FB42-435D-41F7-AF37-8235E3478CB5",
                  "version_start_including": "12.5.0",
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": "12.5.0-02952"
                }
              ]
            },
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": false,
                  "criteria": "cpe:2.3:a:sonicwall:sma8200v:-:*:*:*:*:*:*:*",
                  "match_criteria_id": "653B5F4D-7417-4A85-B385-46157A1540A6",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                }
              ]
            }
          ]
        },
        {
          "operator": "AND",
          "negate": null,
          "nodes": [
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:o:sonicwall:sma6210_firmware:*:*:*:*:*:*:*:*",
                  "match_criteria_id": "796684A5-0639-4D62-8C3B-7E330F200964",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": "12.4.3-03526"
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:o:sonicwall:sma6210_firmware:*:*:*:*:*:*:*:*",
                  "match_criteria_id": "22DA8C27-F1AF-4136-AB59-4E03350B68AD",
                  "version_start_including": "12.5.0",
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": "12.5.0-02952"
                }
              ]
            },
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": false,
                  "criteria": "cpe:2.3:h:sonicwall:sma6210:-:*:*:*:*:*:*:*",
                  "match_criteria_id": "7B24D300-1154-49A1-A1F3-FB0CC717166A",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                }
              ]
            }
          ]
        },
        {
          "operator": "AND",
          "negate": null,
          "nodes": [
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:o:sonicwall:sma7210_firmware:*:*:*:*:*:*:*:*",
                  "match_criteria_id": "70103B37-D895-4F07-B927-7CD4DE85DB9C",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": "12.4.3-03526"
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:o:sonicwall:sma7210_firmware:*:*:*:*:*:*:*:*",
                  "match_criteria_id": "ACADD37E-AEE1-4B8A-9D49-5AB22D53C393",
                  "version_start_including": "12.5.0",
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": "12.5.0-02952"
                }
              ]
            },
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": false,
                  "criteria": "cpe:2.3:h:sonicwall:sma7210:-:*:*:*:*:*:*:*",
                  "match_criteria_id": "E9B414C5-C376-4216-A267-ABC0930905CE",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                }
              ]
            }
          ]
        }
      ],
      "vendor_comments": null,
      "enrichment": {
        "cpe": [
          {
            "criteria": "cpe:2.3:a:sonicwall:sma8200v:*:*:*:*:*:*:*:*",
            "vendor": "sonicwall",
            "product": "sma8200v",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": "12.4.3-03526",
            "affected_versions_first": "12.4.3-02804",
            "affected_versions_last": "12.4.3-03453"
          },
          {
            "criteria": "cpe:2.3:a:sonicwall:sma8200v:*:*:*:*:*:*:*:*",
            "vendor": "sonicwall",
            "product": "sma8200v",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": "12.5.0",
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": "12.5.0-02952",
            "affected_versions_first": "12.5.0",
            "affected_versions_last": "12.5.0-02835"
          },
          {
            "criteria": "cpe:2.3:a:sonicwall:sma8200v:-:*:*:*:*:*:*:*",
            "vendor": "sonicwall",
            "product": "sma8200v",
            "product_type": "a",
            "vulnerable": false,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": null,
            "affected_versions_last": null
          },
          {
            "criteria": "cpe:2.3:o:sonicwall:sma6210_firmware:*:*:*:*:*:*:*:*",
            "vendor": "sonicwall",
            "product": "sma6210_firmware",
            "product_type": "o",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": "12.4.3-03526",
            "affected_versions_first": "12.4.3-02804",
            "affected_versions_last": "12.4.3-03453"
          },
          {
            "criteria": "cpe:2.3:o:sonicwall:sma6210_firmware:*:*:*:*:*:*:*:*",
            "vendor": "sonicwall",
            "product": "sma6210_firmware",
            "product_type": "o",
            "vulnerable": true,
            "version_start_including": "12.5.0",
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": "12.5.0-02952",
            "affected_versions_first": "12.5.0",
            "affected_versions_last": "12.5.0-02835"
          },
          {
            "criteria": "cpe:2.3:h:sonicwall:sma6210:-:*:*:*:*:*:*:*",
            "vendor": "sonicwall",
            "product": "sma6210",
            "product_type": "h",
            "vulnerable": false,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": null,
            "affected_versions_last": null
          },
          {
            "criteria": "cpe:2.3:o:sonicwall:sma7210_firmware:*:*:*:*:*:*:*:*",
            "vendor": "sonicwall",
            "product": "sma7210_firmware",
            "product_type": "o",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": "12.4.3-03526",
            "affected_versions_first": "12.4.3-02804",
            "affected_versions_last": "12.4.3-03453"
          },
          {
            "criteria": "cpe:2.3:o:sonicwall:sma7210_firmware:*:*:*:*:*:*:*:*",
            "vendor": "sonicwall",
            "product": "sma7210_firmware",
            "product_type": "o",
            "vulnerable": true,
            "version_start_including": "12.5.0",
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": "12.5.0-02952",
            "affected_versions_first": "12.5.0",
            "affected_versions_last": "12.5.0-02835"
          },
          {
            "criteria": "cpe:2.3:h:sonicwall:sma7210:-:*:*:*:*:*:*:*",
            "vendor": "sonicwall",
            "product": "sma7210",
            "product_type": "h",
            "vulnerable": false,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": null,
            "affected_versions_last": null
          }
        ],
        "cwe": [
          {
            "id": 441,
            "owasptop10_2021": "A01 Broken Access Control",
            "name": "Unintended Proxy or Intermediary ('Confused Deputy')",
            "description": "The product receives a request, message, or directive from an upstream component, but the product does not sufficiently preserve the original source of the request before forwarding the request to an external actor that is outside of the product's control sphere. This causes the product to appear to be the source of the request, leading it to act as a proxy or other intermediary between the upstream component and the external actor.",
            "capec_id": [
              219,
              465
            ],
            "scope": [
              "Access Control",
              "Non-Repudiation"
            ],
            "impact": [
              "Execute Unauthorized Code or Commands",
              "Gain Privileges or Assume Identity",
              "Hide Activities"
            ],
            "detection_method": [
              "Automated Static Analysis"
            ]
          },
          {
            "id": 918,
            "owasptop10_2021": "A10 Server-Side Request Forgery (SSRF)",
            "name": "Server-Side Request Forgery (SSRF)",
            "description": "The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.",
            "capec_id": [
              664
            ],
            "scope": [
              "Access Control",
              "Confidentiality",
              "Integrity"
            ],
            "impact": [
              "Bypass Protection Mechanism",
              "Execute Unauthorized Code or Commands",
              "Read Application Data"
            ],
            "detection_method": [
              "Automated Static Analysis"
            ]
          }
        ],
        "epss_score": {
          "epss": 0.04667,
          "percentile": 0.91357,
          "date": "2026-09-21"
        },
        "cisa_kev": {
          "vendor_project": "SonicWall",
          "product": "SMA1000 Appliances",
          "vulnerability_name": "SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability",
          "date_added": "2026-09-02",
          "short_description": "SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations.",
          "required_action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
          "due_date": "2026-09-05",
          "known_ransomware_campaign_use": "Unknown",
          "notes": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-83548"
        },
        "vdeep_metric": {
          "available_versions": [
            "3.1"
          ],
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "cvss_data": {
            "version": "3.1",
            "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
            "attack_vector": "NETWORK",
            "attack_complexity": "LOW",
            "attack_requirements": null,
            "privileges_required": "NONE",
            "user_interaction": "NONE",
            "vulnerable_system_confidentiality": "HIGH",
            "vulnerable_system_integrity": "HIGH",
            "vulnerable_system_availability": "HIGH",
            "subsequent_system_confidentiality": null,
            "subsequent_system_integrity": null,
            "subsequent_system_availability": null,
            "exploit_maturity": null,
            "confidentiality_requirements": null,
            "integrity_requirements": null,
            "availability_requirements": null,
            "modified_attack_vector": null,
            "modified_attack_complexity": null,
            "modified_attack_requirements": null,
            "modified_privileges_required": null,
            "modified_user_interaction": null,
            "modified_vulnerable_system_confidentiality": null,
            "modified_vulnerable_system_integrity": null,
            "modified_vulnerable_system_availability": null,
            "modified_subsequent_system_confidentiality": null,
            "modified_subsequent_system_integrity": null,
            "modified_subsequent_system_availability": null,
            "safety": null,
            "automatable": null,
            "recovery": null,
            "value_density": null,
            "vulnerability_response_effort": null,
            "provider_urgency": null,
            "base_score": 10.0,
            "base_severity": "CRITICAL"
          }
        }
      }
    }
  ]
}
```

## Related Examples

- [KEV Remediation Due in November 2021](/reference/vulnerability/search/examples/cisa-action-due/)
- [CVEs Modified Since 20 September 2026](/reference/vulnerability/search/examples/last-modified/)
- [CVEs Published in December 2021](/reference/vulnerability/search/examples/published/)
- [CVSS v3.0: Base Score 9 and Up](/reference/vulnerability/search/examples/metrics-cvss-metric-v30-cvss-data-base-score/)
- [CVSS v3.1: Base Score 9.8 and Up](/reference/vulnerability/search/examples/metrics-cvss-metric-v31-cvss-data-base-score/)
- [CVSS v3.1: Impact Score 5.9 and Up](/reference/vulnerability/search/examples/metrics-cvss-metric-v31-impact-score/)
