| CVE | 제조사 | 취약점 | 내용 | 조치사항 |
|---|
| CVE-2026-34621 | Adobe | Adobe Acrobat and Reader Prototype Pollution Vulnerability | Adobe Acrobat and Reader contain a prototype pollution vulnerability that allows for arbitrary code execution. | Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. |
| CVE-2026-21643 | Fortinet | Fortinet SQL Injection Vulnerability | Fortinet FortiClient EMS contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests. | Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. |
| CVE-2020-9715 | Adobe | Adobe Acrobat Use-After-Free Vulnerability | Adobe Acrobat contains a use-after-free vulnerability that allows for code execution | Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. |
| CVE-2023-36424 | Microsoft | Microsoft Windows Out-of-Bounds Read Vulnerability | Microsoft Windows Common Log File System Driver contains an out-of-bounds read vulnerability that could allow a threat actor for privileges escalation | Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. |
| CVE-2023-21529 | Microsoft | Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability | Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution. | Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. |
| CVE-2025-60710 | Microsoft | Microsoft Windows Link Following Vulnerability | Microsoft Windows contains a link following vulnerability that allows for privilege escalation | Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. |
| CVE-2012-1854 | Microsoft | Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability | Microsoft Visual Basic for Applications (VBA) contains an insecure library loading vulnerability that could allow for remote code execution. | Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. |