Skip to content

Products › End-user applications

End-user applications

Collaboration, telephony and video conferencing

Intranets, wikis, teamwork tools, IP telephony and video conferencing.

For example: SharePoint, Confluence, Mitel, FreePBX.

Category RSS feed

Pace of additions

Number of “Collaboration and video” vulnerabilities added to CISA’s KEV catalog, per 30-day period (the last one, still in progress, ends on October 3, 2026). Source: CISA KEV catalog.
Catalog additions per 30-day period
PeriodVulnerabilities added
Sep 9, 2025 to Oct 8, 20250
Oct 9, 2025 to Nov 7, 20251
Nov 8, 2025 to Dec 7, 20250
Dec 8, 2025 to Jan 6, 20260
Jan 7, 2026 to Feb 5, 20263
Feb 6, 2026 to Mar 7, 20260
Mar 8, 2026 to Apr 6, 20262
Apr 7, 2026 to May 6, 20261
May 7, 2026 to Jun 5, 20260
Jun 6, 2026 to Jul 5, 20262
Jul 6, 2026 to Aug 4, 20263
Aug 5, 2026 to Sep 3, 20264
Sep 4, 2026 to Oct 3, 2026 (in progress)1

Affected brands

In alphabetical order, with their number of vulnerabilities in this category.

A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.

See also

  • Email 71 vulnerabilities

Patch first

In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this category.

  1. Rank 1

    Microsoft SharePoint ServerCVE-2026-65660

    Microsoft SharePoint Code Injection Vulnerability

    Recently addedHunt for compromise (CISA)

    CVSS severity 8.8high

    Added Sep 25, 2026

  2. Rank 2

    Sangoma SwitchvoxCVE-2026-9586

    Sangoma Switchvox SQL Injection Vulnerability

    Hunt for compromise (CISA)

    CVSS severity 9.8critical

    Added Sep 2, 2026

  3. Rank 3

    TrueConf ServerCVE-2026-72529

    TrueConf Server Missing Authentication for Critical Function Vulnerability

    Hunt for compromise (CISA)

    CVSS severity 9.8critical

    Added Aug 20, 2026

  4. Rank 4

    Microsoft SharePoint ServerCVE-2026-50522

    Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

    Hunt for compromise (CISA)

    CVSS severity 9.8critical

    Added Jul 22, 2026

  5. Rank 5

    Microsoft SharePoint ServerCVE-2026-58644

    Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

    Hunt for compromise (CISA)

    CVSS severity 9.8critical

    Added Jul 16, 2026

  6. Rank 6

    Microsoft SharePoint ServerCVE-2026-56164

    Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability

    Hunt for compromise (CISA)

    CVSS severity 9.8critical

    Added Jul 14, 2026

  7. Rank 7

    Microsoft SharePoint ServerCVE-2026-20963

    Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

    CVSS severity 9.8critical

    Added Mar 18, 2026

  8. Rank 8

    Sangoma FreePBXCVE-2019-19006

    Sangoma FreePBX Improper Authentication Vulnerability

    CVE from 2019, added in 2026

    CVSS severity 9.8critical

    Added Feb 3, 2026

  9. Rank 9

    Cisco Unified Communications ManagerCVE-2026-20045

    Cisco Unified Communications Products Code Injection Vulnerability

    CVSS severity 9.8critical

    Added Jan 21, 2026

  10. Rank 10

    XWiki PlatformCVE-2025-24893

    XWiki Platform Eval Injection Vulnerability

    CVSS severity 9.8critical

    Added Oct 30, 2025

Show 43 more vulnerabilities
  1. Rank 11

    Microsoft SharePoint ServerCVE-2026-55040

    Microsoft SharePoint Weak Authentication Vulnerability

    Hunt for compromise (CISA)

    CVSS severity 9.1critical

    Added Aug 18, 2026

  2. Rank 12

    TrueConf ServerCVE-2026-72530

    TrueConf Server Code Injection Vulnerability

    CVSS severity 9.0critical

    Added Aug 20, 2026

  3. Rank 13

    Microsoft SharePoint ServerCVE-2026-45659

    Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability

    Hunt for compromise (CISA)Ransomware

    CVSS severity 8.8high

    Added Jul 1, 2026

  4. Rank 14

    Cisco Unified Communications ManagerCVE-2026-20230

    Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability

    CVSS severity 8.6high

    Added Jun 25, 2026

  5. Rank 15

    TrueConf ClientCVE-2026-3502

    TrueConf Client Download of Code Without Integrity Check Vulnerability

    CVSS severity 7.8high

    Added Apr 2, 2026

  6. Rank 16

    Sangoma FreePBXCVE-2025-64328

    Sangoma FreePBX OS Command Injection Vulnerability

    CVSS severity 7.2high

    Added Feb 3, 2026

  7. Rank 17

    Microsoft SharePoint ServerCVE-2026-32201

    Microsoft SharePoint Server Improper Input Validation Vulnerability

    CVSS severity 6.5medium

    Added Apr 14, 2026

  8. Rank 18

    Sangoma FreePBXCVE-2025-57819

    Sangoma FreePBX Authentication Bypass Vulnerability

    CVSS severity 9.8critical

    Added Aug 29, 2025

  9. Rank 19

    Microsoft SharePoint ServerCVE-2025-53770

    Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added Jul 20, 2025

  10. Rank 20

    Fortinet FortiVoice / FortiFoneCVE-2025-32756

    Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability

    CVSS severity 9.8critical

    Added May 14, 2025

  11. Rank 21

    Atlassian Confluence Server / Data CenterCVE-2023-22527

    Atlassian Confluence Data Center and Server Template Injection Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added Jan 24, 2024

  12. Rank 22

    Microsoft SharePoint ServerCVE-2023-29357

    Microsoft SharePoint Server Privilege Escalation Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added Jan 10, 2024

  13. Rank 23

    Atlassian Confluence Server / Data CenterCVE-2023-22518

    Atlassian Confluence Data Center and Server Improper Authorization Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added Nov 7, 2023

  14. Rank 24

    Atlassian Confluence Server / Data CenterCVE-2023-22515

    Atlassian Confluence Data Center and Server Broken Access Control Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added Oct 5, 2023

  15. Rank 25

    Atlassian Confluence Server / Data CenterCVE-2022-26138

    Atlassian Questions For Confluence App Hard-coded Credentials Vulnerability

    CVSS severity 9.8critical

    Added Jul 29, 2022

  16. Rank 26

    Mitel MiVoice ConnectCVE-2022-29499

    Mitel MiVoice Connect Data Validation Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added Jun 27, 2022

  17. Rank 27

    Atlassian Confluence Server / Data CenterCVE-2022-26134

    Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added Jun 2, 2022

  18. Rank 28

    Alcatel-Lucent Enterprise OmniPCX EnterpriseCVE-2007-3010

    Alcatel OmniPCX Enterprise Remote Code Execution Vulnerability

    CVE from 2007, added in 2022

    CVSS severity 9.8critical

    Added Apr 15, 2022

  19. Rank 29

    Mitel MiCollabCVE-2022-26143

    MiCollab, MiVoice Business Express Access Control Vulnerability

    CVSS severity 9.8critical

    Added Mar 25, 2022

  20. Rank 30

    Atlassian Jira Server / Data CenterCVE-2019-11581

    Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability

    CVE from 2019, added in 2022

    CVSS severity 9.8critical

    Added Mar 7, 2022

  21. Rank 31

    Grandstream UCM6200CVE-2020-5722

    Grandstream Networks UCM6200 Series SQL Injection Vulnerability

    CVE from 2020, added in 2022

    CVSS severity 9.8critical

    Added Jan 28, 2022

  22. Rank 32

    Microsoft SharePoint ServerCVE-2019-0604

    Microsoft SharePoint Remote Code Execution Vulnerability

    RansomwareCVE from 2019, added in 2021

    CVSS severity 9.8critical

    Added Nov 3, 2021

  23. Rank 33

    Atlassian Confluence Server / Data CenterCVE-2019-3396

    Atlassian Confluence Server and Data Center Server-Side Template Injection Vulnerability

    RansomwareCVE from 2019, added in 2021

    CVSS severity 9.8critical

    Added Nov 3, 2021

  24. Rank 34

    Cisco IP PhonesCVE-2020-3161

    Cisco IP Phones Web Server Remote Code Execution and Denial-of-Service Vulnerability

    CVSS severity 9.8critical

    Added Nov 3, 2021

  25. Rank 35

    PlaySMSCVE-2020-8644

    PlaySMS Server-Side Template Injection Vulnerability

    CVSS severity 9.8critical

    Added Nov 3, 2021

  26. Rank 36

    Atlassian Confluence Server / Data CenterCVE-2021-26084

    Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added Nov 3, 2021

  27. Rank 37

    Yealink Device ManagementCVE-2021-27561

    Yealink Device Management Server-Side Request Forgery (SSRF) Vulnerability

    CVSS severity 9.8critical

    Added Nov 3, 2021

  28. Rank 38

    Mitel MiCollabCVE-2024-41713

    Mitel MiCollab Path Traversal Vulnerability

    Ransomware

    CVSS severity 9.1critical

    Added Jan 7, 2025

  29. Rank 39

    Microsoft SharePoint ServerCVE-2025-49704

    Microsoft SharePoint Code Injection Vulnerability

    Ransomware

    CVSS severity 8.8high

    Added Jul 22, 2025

  30. Rank 40

    Srimax Output MessengerCVE-2025-27920

    Srimax Output Messenger Directory Traversal Vulnerability

    CVSS severity 8.8high

    Added May 19, 2025

  31. Rank 41

    Atlassian Confluence Server / Data CenterCVE-2019-3398

    Atlassian Confluence Server and Data Center Path Traversal Vulnerability

    CVE from 2019, added in 2021

    CVSS severity 8.8high

    Added Nov 3, 2021

  32. Rank 42

    Microsoft SharePoint ServerCVE-2020-1147

    Microsoft .NET Framework, SharePoint, and Visual Studio Remote Code Execution Vulnerability

    CVSS severity 7.8high

    Added Nov 3, 2021

  33. Rank 43

    Ignite Realtime OpenfireCVE-2023-32315

    Ignite Realtime Openfire Path Traversal Vulnerability

    CVSS severity 7.5high

    Added Aug 24, 2023

  34. Rank 44

    Mitel SIP Phones (6800 / 6900)CVE-2024-41710

    Mitel SIP Phones Argument Injection Vulnerability

    CVSS severity 7.2high

    Added Feb 12, 2025

  35. Rank 45

    Microsoft SharePoint ServerCVE-2024-38094

    Microsoft SharePoint Deserialization Vulnerability

    Ransomware

    CVSS severity 7.2high

    Added Oct 22, 2024

  36. Rank 46

    Microsoft SharePoint ServerCVE-2023-24955

    Microsoft SharePoint Server Code Injection Vulnerability

    Ransomware

    CVSS severity 7.2high

    Added Mar 26, 2024

  37. Rank 47

    Mitel MiVoice ConnectCVE-2022-40765

    Mitel MiVoice Connect Command Injection Vulnerability

    Ransomware

    CVSS severity 6.8medium

    Added Feb 21, 2023

  38. Rank 48

    Mitel MiVoice ConnectCVE-2022-41223

    Mitel MiVoice Connect Code Injection Vulnerability

    Ransomware

    CVSS severity 6.8medium

    Added Feb 21, 2023

  39. Rank 49

    Microsoft SharePoint ServerCVE-2025-49706

    Microsoft SharePoint Improper Authentication Vulnerability

    Ransomware

    CVSS severity 6.5medium

    Added Jul 22, 2025

  40. Rank 50

    Atlassian Jira Server / Data CenterCVE-2021-26086

    Atlassian Jira Server and Data Center Path Traversal Vulnerability

    CVE from 2021, added in 2024

    CVSS severity 5.3medium

    Added Nov 12, 2024

  41. Rank 51

    Microsoft Skype for Business / LyncCVE-2023-41763

    Microsoft Skype for Business Privilege Escalation Vulnerability

    CVSS severity 5.3medium

    Added Oct 10, 2023

  42. Rank 52

    Atlassian Confluence Server / Data CenterCVE-2021-26085

    Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability

    Ransomware

    CVSS severity 5.3medium

    Added Mar 28, 2022

  43. Rank 53

    Mitel MiCollabCVE-2024-55550

    Mitel MiCollab Path Traversal Vulnerability

    Ransomware

    CVSS severity 2.7low

    Added Jan 7, 2025

Follow and verify

Get new vulnerabilities in this category: RSS feed (add it to Outlook, Teams, Slack or your feed reader).

Indicative classification, based on the vendor and product names given by CISA. How products are classified.