// Operations

Vulnerabilities

Known weaknesses on inventoried assets. Ranked by CVSS, but triaged by what an attacker can actually reach: a medium with a public exploit on a tier-0 host outranks a critical on a kiosk.

8outstanding2with known exploits2on critical assets
8
Open
No remediation started
0
In progress
Remediation under way
0
Remediated
Fix applied and confirmed
0
Risk accepted
Documented decision not to fix

Findings

8 findings

CVEFindingCVSSSeverityAssetStatusFoundRemediation
CVE-2026-21847Exploit known
Remote code execution in the HTTP/2 request parser
nginx 1.14.0 → fixed in 1.25.4
9.8Criticalubuntu-web-01HIGHOPEN
CVE-2026-19022
Authentication bypass in the directory LDAP handler
Directory Services → fixed in KB5041823
9.1CriticalWIN-DC01CRITICALOPEN
CVE-2026-11740
Deserialisation of untrusted data in the reporting module
Finance Reporting 11.2 → fixed in 11.4.2
8.1HighWS-FIN-004HIGHOPEN
CVE-2026-13309Exploit known
Privilege escalation via unquoted service path
Backup Agent 4.2.1 → fixed in 4.3.0
7.8HighWIN-DC01CRITICALOPEN
CVE-2026-18334
Out-of-bounds read in the font rasteriser
Document Suite 24.1 → fixed in 24.3
7.5HighWS-ENG-118MEDIUMOPEN
CVE-2026-17781
Stored cross-site scripting in the device console
Kiosk Manager 2.8 → fixed in 2.9.1
6.4Mediumkiosk-lobby-02LOWOPEN
CVE-2026-20515
TLS downgrade permitted by legacy cipher configuration
OpenSSL 1.1.1f → fixed in 3.0.13
5.9Mediumubuntu-web-01HIGHOPEN
CVE-2026-14206
Information disclosure through verbose error responses
Platform API 6.1 → fixed in 6.1.9
3.7Lowubuntu-web-01HIGHOPEN