// Operations
Vulnerabilities
Known weaknesses on inventoried assets. Ranked by CVSS, but triaged by what an attacker can actually reach: a medium with a public exploit on a tier-0 host outranks a critical on a kiosk.
8outstanding2with known exploits2on critical assets
8
Open
No remediation started
0
In progress
Remediation under way
0
Remediated
Fix applied and confirmed
0
Risk accepted
Documented decision not to fix
Findings
8 findings
| CVE | Finding | CVSS | Severity | Asset | Status | Found | Remediation |
|---|---|---|---|---|---|---|---|
| CVE-2026-21847Exploit known | Remote code execution in the HTTP/2 request parser nginx 1.14.0 → fixed in 1.25.4 | 9.8 | Critical | ubuntu-web-01HIGH | OPEN | ||
| CVE-2026-19022 | Authentication bypass in the directory LDAP handler Directory Services → fixed in KB5041823 | 9.1 | Critical | WIN-DC01CRITICAL | OPEN | ||
| CVE-2026-11740 | Deserialisation of untrusted data in the reporting module Finance Reporting 11.2 → fixed in 11.4.2 | 8.1 | High | WS-FIN-004HIGH | OPEN | ||
| CVE-2026-13309Exploit known | Privilege escalation via unquoted service path Backup Agent 4.2.1 → fixed in 4.3.0 | 7.8 | High | WIN-DC01CRITICAL | OPEN | ||
| CVE-2026-18334 | Out-of-bounds read in the font rasteriser Document Suite 24.1 → fixed in 24.3 | 7.5 | High | WS-ENG-118MEDIUM | OPEN | ||
| CVE-2026-17781 | Stored cross-site scripting in the device console Kiosk Manager 2.8 → fixed in 2.9.1 | 6.4 | Medium | kiosk-lobby-02LOW | OPEN | ||
| CVE-2026-20515 | TLS downgrade permitted by legacy cipher configuration OpenSSL 1.1.1f → fixed in 3.0.13 | 5.9 | Medium | ubuntu-web-01HIGH | OPEN | ||
| CVE-2026-14206 | Information disclosure through verbose error responses Platform API 6.1 → fixed in 6.1.9 | 3.7 | Low | ubuntu-web-01HIGH | OPEN |