Skip to content
English

Products › End-user applications

End-user applications

Collaboration, telephony and video conferencing

Intranets, wikis, teamwork tools, IP telephony and video conferencing.

For example: SharePoint, Confluence, Mitel, FreePBX.

Category RSS feed

Pace of additions

Number of “Collaboration and video” vulnerabilities added to CISA’s KEV catalog, per 30-day period (the last one, still in progress, ends on September 28, 2026). Source: CISA KEV catalog.
Catalog additions per 30-day period
PeriodVulnerabilities added
Sep 4, 2025 to Oct 3, 20250
Oct 4, 2025 to Nov 2, 20251
Nov 3, 2025 to Dec 2, 20250
Dec 3, 2025 to Jan 1, 20260
Jan 2, 2026 to Jan 31, 20261
Feb 1, 2026 to Mar 2, 20262
Mar 3, 2026 to Apr 1, 20261
Apr 2, 2026 to May 1, 20262
May 2, 2026 to May 31, 20260
Jun 1, 2026 to Jun 30, 20261
Jul 1, 2026 to Jul 30, 20264
Jul 31, 2026 to Aug 29, 20263
Aug 30, 2026 to Sep 28, 2026 (in progress)2

Affected brands

In alphabetical order, with their number of vulnerabilities in this category.

A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.

See also

  • Email 70 vulnerabilities

Patch first

In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this category.

  1. Rank 1Microsoft SharePoint Server

    CVE-2026-65660

    Recently addedHunt for compromise (CISA)

    Microsoft SharePoint Code Injection Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 25, 2026
    CISA deadline
    3 days
    CVSS severity
    8.8 (high)
  2. Rank 2Sangoma Switchvox

    CVE-2026-9586

    Recently addedHunt for compromise (CISA)

    Sangoma Switchvox SQL Injection Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 2, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  3. Rank 3TrueConf Server

    CVE-2026-72529

    Hunt for compromise (CISA)

    TrueConf Server Missing Authentication for Critical Function Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Aug 20, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  4. Rank 4Microsoft SharePoint Server

    CVE-2026-50522

    Hunt for compromise (CISA)

    Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 22, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  5. Rank 5Microsoft SharePoint Server

    CVE-2026-58644

    Hunt for compromise (CISA)

    Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 16, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  6. Rank 6Microsoft SharePoint Server

    CVE-2026-56164

    Hunt for compromise (CISA)

    Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 14, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  7. Rank 7Microsoft SharePoint Server

    CVE-2026-20963

    Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Mar 18, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  8. Rank 8Sangoma FreePBX

    CVE-2019-19006

    CVE from 2019, added in 2026

    Sangoma FreePBX Improper Authentication Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 3, 2026
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  9. Rank 9Cisco Unified Communications Manager

    CVE-2026-20045

    Cisco Unified Communications Products Code Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jan 21, 2026
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  10. Rank 10XWiki Platform

    CVE-2025-24893

    XWiki Platform Eval Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 30, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
Show 43 more vulnerabilities
  1. Rank 11Microsoft SharePoint Server

    CVE-2026-55040

    Hunt for compromise (CISA)

    Microsoft SharePoint Weak Authentication Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Aug 18, 2026
    CISA deadline
    3 days
    CVSS severity
    9.1 (critical)
  2. Rank 12TrueConf Server

    CVE-2026-72530

    TrueConf Server Code Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Aug 20, 2026
    CISA deadline
    14 days
    CVSS severity
    9.0 (critical)
  3. Rank 13Microsoft SharePoint Server

    CVE-2026-45659

    Hunt for compromise (CISA)Ransomware

    Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 1, 2026
    CISA deadline
    3 days
    CVSS severity
    8.8 (high)
  4. Rank 14Cisco Unified Communications Manager

    CVE-2026-20230

    Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jun 25, 2026
    CISA deadline
    3 days
    CVSS severity
    8.6 (high)
  5. Rank 15TrueConf Client

    CVE-2026-3502

    TrueConf Client Download of Code Without Integrity Check Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 2, 2026
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  6. Rank 16Sangoma FreePBX

    CVE-2025-64328

    Sangoma FreePBX OS Command Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 3, 2026
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  7. Rank 17Microsoft SharePoint Server

    CVE-2026-32201

    Microsoft SharePoint Server Improper Input Validation Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 14, 2026
    CISA deadline
    14 days
    CVSS severity
    6.5 (medium)
  8. Rank 18Sangoma FreePBX

    CVE-2025-57819

    Sangoma FreePBX Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 29, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  9. Rank 19Microsoft SharePoint Server

    CVE-2025-53770

    Ransomware

    Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 20, 2025
    CISA deadline
    1 day
    CVSS severity
    9.8 (critical)
  10. Rank 20Fortinet FortiVoice / FortiFone

    CVE-2025-32756

    Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 14, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  11. Rank 21Atlassian Confluence Server / Data Center

    CVE-2023-22527

    Ransomware

    Atlassian Confluence Data Center and Server Template Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 24, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  12. Rank 22Microsoft SharePoint Server

    CVE-2023-29357

    Ransomware

    Microsoft SharePoint Server Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 10, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  13. Rank 23Atlassian Confluence Server / Data Center

    CVE-2023-22518

    Ransomware

    Atlassian Confluence Data Center and Server Improper Authorization Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 7, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  14. Rank 24Atlassian Confluence Server / Data Center

    CVE-2023-22515

    Ransomware

    Atlassian Confluence Data Center and Server Broken Access Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 5, 2023
    CISA deadline
    8 days
    CVSS severity
    9.8 (critical)
  15. Rank 25Atlassian Confluence Server / Data Center

    CVE-2022-26138

    Atlassian Questions For Confluence App Hard-coded Credentials Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 29, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  16. Rank 26Mitel MiVoice Connect

    CVE-2022-29499

    Ransomware

    Mitel MiVoice Connect Data Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 27, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  17. Rank 27Atlassian Confluence Server / Data Center

    CVE-2022-26134

    Ransomware

    Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 2, 2022
    CISA deadline
    4 days
    CVSS severity
    9.8 (critical)
  18. Rank 28Alcatel-Lucent Enterprise OmniPCX Enterprise

    CVE-2007-3010

    CVE from 2007, added in 2022

    Alcatel OmniPCX Enterprise Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 15, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  19. Rank 29Mitel MiCollab

    CVE-2022-26143

    MiCollab, MiVoice Business Express Access Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  20. Rank 30Atlassian Jira Server / Data Center

    CVE-2019-11581

    CVE from 2019, added in 2022

    Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 7, 2022
    CISA deadline
    184 days
    CVSS severity
    9.8 (critical)
  21. Rank 31Grandstream UCM6200

    CVE-2020-5722

    CVE from 2020, added in 2022

    Grandstream Networks UCM6200 Series SQL Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 28, 2022
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  22. Rank 32Microsoft SharePoint Server

    CVE-2019-0604

    RansomwareCVE from 2019, added in 2021

    Microsoft SharePoint Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  23. Rank 33Atlassian Confluence Server / Data Center

    CVE-2019-3396

    RansomwareCVE from 2019, added in 2021

    Atlassian Confluence Server and Data Center Server-Side Template Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  24. Rank 34Cisco IP Phones

    CVE-2020-3161

    Cisco IP Phones Web Server Remote Code Execution and Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  25. Rank 35PlaySMS

    CVE-2020-8644

    PlaySMS Server-Side Template Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  26. Rank 36Atlassian Confluence Server / Data Center

    CVE-2021-26084

    Ransomware

    Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  27. Rank 37Yealink Device Management

    CVE-2021-27561

    Yealink Device Management Server-Side Request Forgery (SSRF) Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  28. Rank 38Mitel MiCollab

    CVE-2024-41713

    Ransomware

    Mitel MiCollab Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 7, 2025
    CISA deadline
    21 days
    CVSS severity
    9.1 (critical)
  29. Rank 39Microsoft SharePoint Server

    CVE-2025-49704

    Ransomware

    Microsoft SharePoint Code Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 22, 2025
    CISA deadline
    1 day
    CVSS severity
    8.8 (high)
  30. Rank 40Srimax Output Messenger

    CVE-2025-27920

    Srimax Output Messenger Directory Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 19, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  31. Rank 41Atlassian Confluence Server / Data Center

    CVE-2019-3398

    CVE from 2019, added in 2021

    Atlassian Confluence Server and Data Center Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  32. Rank 42Microsoft SharePoint Server

    CVE-2020-1147

    Microsoft .NET Framework, SharePoint, and Visual Studio Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  33. Rank 43Ignite Realtime Openfire

    CVE-2023-32315

    Ignite Realtime Openfire Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 24, 2023
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  34. Rank 44Mitel SIP Phones (6800 / 6900)

    CVE-2024-41710

    Mitel SIP Phones Argument Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 12, 2025
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  35. Rank 45Microsoft SharePoint Server

    CVE-2024-38094

    Ransomware

    Microsoft SharePoint Deserialization Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 22, 2024
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  36. Rank 46Microsoft SharePoint Server

    CVE-2023-24955

    Ransomware

    Microsoft SharePoint Server Code Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 26, 2024
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  37. Rank 47Mitel MiVoice Connect

    CVE-2022-40765

    Ransomware

    Mitel MiVoice Connect Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 21, 2023
    CISA deadline
    21 days
    CVSS severity
    6.8 (medium)
  38. Rank 48Mitel MiVoice Connect

    CVE-2022-41223

    Ransomware

    Mitel MiVoice Connect Code Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 21, 2023
    CISA deadline
    21 days
    CVSS severity
    6.8 (medium)
  39. Rank 49Microsoft SharePoint Server

    CVE-2025-49706

    Ransomware

    Microsoft SharePoint Improper Authentication Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 22, 2025
    CISA deadline
    1 day
    CVSS severity
    6.5 (medium)
  40. Rank 50Atlassian Jira Server / Data Center

    CVE-2021-26086

    CVE from 2021, added in 2024

    Atlassian Jira Server and Data Center Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 12, 2024
    CISA deadline
    21 days
    CVSS severity
    5.3 (medium)
  41. Rank 51Microsoft Skype for Business / Lync

    CVE-2023-41763

    Microsoft Skype for Business Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 10, 2023
    CISA deadline
    21 days
    CVSS severity
    5.3 (medium)
  42. Rank 52Atlassian Confluence Server / Data Center

    CVE-2021-26085

    Ransomware

    Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    5.3 (medium)
  43. Rank 53Mitel MiCollab

    CVE-2024-55550

    Ransomware

    Mitel MiCollab Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 7, 2025
    CISA deadline
    21 days
    CVSS severity
    2.7 (low)

Follow and verify

Get new vulnerabilities in this category: RSS feed (add it to Outlook, Teams, Slack or your feed reader).

Indicative classification, based on the vendor and product names given by CISA. How products are classified.