Cross-Vendor Patch Advisories
Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.
Browse Advisories
1,308 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.
| CVE | Vendor | Product | Vulnerability | EVRS | EPSS | Ransomware | CISA due |
|---|---|---|---|---|---|---|---|
| CVE-2024-32113 | Apache | OFBiz | Apache OFBiz Path Traversal Vulnerability | 87 Immediate | 0.994 (99.94th pctl) | Unknown/None | 2024-08-28 |
| CVE-2023-34048 | VMware | vCenter Server | VMware vCenter Server Out-of-Bounds Write Vulnerability | 87 Immediate | 0.994 (99.94th pctl) | Unknown/None | 2024-02-12 |
| CVE-2024-38856 | Apache | OFBiz | Apache OFBiz Incorrect Authorization Vulnerability | 87 Immediate | 0.994 (99.94th pctl) | Unknown/None | 2024-09-17 |
| CVE-2022-0543 | Redis | Debian-specific Redis Servers | Debian-specific Redis Server Lua Sandbox Escape Vulnerability | 87 Immediate | 0.994 (99.94th pctl) | Unknown/None | 2022-04-18 |
| CVE-2015-5119 | Adobe | Flash Player | Adobe Flash Player Use-After-Free Vulnerability | 87 Immediate | 0.993 (99.94th pctl) | Unknown/None | 2022-03-24 |
| CVE-2014-6287 | Rejetto | HTTP File Server (HFS) | Rejetto HTTP File Server (HFS) Remote Code Execution Vulnerability | 87 Immediate | 0.993 (99.94th pctl) | Unknown/None | 2022-04-15 |
| CVE-2023-28771 | Zyxel | Multiple Firewalls | Zyxel Multiple Firewalls OS Command Injection Vulnerability | 87 Immediate | 0.993 (99.94th pctl) | Unknown/None | 2023-06-21 |
| CVE-2020-14750 | Oracle | WebLogic Server | Oracle WebLogic Server Remote Code Execution Vulnerability | 87 Immediate | 0.993 (99.93rd pctl) | Unknown/None | 2022-05-03 |
| CVE-2020-1938 | Apache | Tomcat | Apache Tomcat Improper Privilege Management Vulnerability | 87 Immediate | 0.993 (99.94th pctl) | Unknown/None | 2022-03-17 |
| CVE-2022-24086 | Adobe | Commerce and Magento Open Source | Adobe Commerce and Magento Open Source Improper Input Validation Vulnerability | 87 Immediate | 0.992 (99.93rd pctl) | Unknown/None | 2022-03-01 |
| CVE-2017-3881 | Cisco | IOS and IOS XE | Cisco IOS and IOS XE Remote Code Execution Vulnerability | 87 Immediate | 0.990 (99.93rd pctl) | Unknown/None | 2022-04-15 |
| CVE-2020-7247 | OpenBSD | OpenSMTPD | OpenSMTPD Remote Code Execution Vulnerability | 87 Immediate | 0.990 (99.93rd pctl) | Unknown/None | 2022-04-15 |
| CVE-2019-3929 | Crestron | Multiple Products | Crestron Multiple Products Command Injection Vulnerability | 87 Immediate | 0.990 (99.93rd pctl) | Unknown/None | 2022-05-06 |
| CVE-2017-9791 | Apache | Struts 1 | Apache Struts 1 Improper Input Validation Vulnerability | 87 Immediate | 0.989 (99.92nd pctl) | Unknown/None | 2022-08-10 |
| CVE-2022-3236 | Sophos | Firewall | Sophos Firewall Code Injection Vulnerability | 87 Immediate | 0.989 (99.92nd pctl) | Unknown/None | 2022-10-14 |
| CVE-2024-8963 | Ivanti | Cloud Services Appliance (CSA) | Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability | 87 Immediate | 0.986 (99.92nd pctl) | Unknown/None | 2024-10-10 |
| CVE-2016-3088 | Apache | ActiveMQ | Apache ActiveMQ Improper Input Validation Vulnerability | 87 Immediate | 0.985 (99.92nd pctl) | Unknown/None | 2022-08-10 |
| CVE-2022-24816 | OSGeo | JAI-EXT | OSGeo GeoServer JAI-EXT Code Injection Vulnerability | 87 Immediate | 0.985 (99.92nd pctl) | Unknown/None | 2024-07-17 |
| CVE-2018-1000861 | Jenkins | Jenkins Stapler Web Framework | Jenkins Stapler Web Framework Deserialization of Untrusted Data Vulnerability | 87 Immediate | 0.983 (99.91st pctl) | Unknown/None | 2022-08-10 |
| CVE-2016-1555 | NETGEAR | Wireless Access Point (WAP) Devices | NETGEAR Multiple WAP Devices Command Injection Vulnerability | 87 Immediate | 0.983 (99.91st pctl) | Unknown/None | 2022-04-15 |
| CVE-2017-15944 | Palo Alto Networks | PAN-OS | Palo Alto Networks PAN-OS Remote Code Execution Vulnerability | 87 Immediate | 0.983 (99.91st pctl) | Unknown/None | 2022-09-08 |
| CVE-2023-20887 | VMware | Aria Operations for Networks | Vmware Aria Operations for Networks Command Injection Vulnerability | 87 Immediate | 0.983 (99.91st pctl) | Unknown/None | 2023-07-13 |
| CVE-2020-6207 | SAP | Solution Manager | SAP Solution Manager Missing Authentication for Critical Function Vulnerability | 87 Immediate | 0.983 (99.91st pctl) | Unknown/None | 2022-05-03 |
| CVE-2022-22947 | VMware | Spring Cloud Gateway | VMware Spring Cloud Gateway Code Injection Vulnerability | 87 Immediate | 0.983 (99.91st pctl) | Unknown/None | 2022-06-06 |
| CVE-2022-26138 | Atlassian | Confluence | Atlassian Questions For Confluence App Hard-coded Credentials Vulnerability | 87 Immediate | 0.982 (99.91st pctl) | Unknown/None | 2022-08-19 |
Exactly the 1,308 advisory(ies) matching the filters above.
Advisory detail
Expand any advisory for its description, CISA's own required action, and research links.
CVE-2024-32113 — Apache OFBiz: Apache OFBiz Path Traversal Vulnerability
Apache OFBiz contains a path traversal vulnerability that could allow for remote code execution.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.994.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.994 (99.94th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-08-07
CISA remediation due: 2024-08-28
Known ransomware campaign use: Unknown/None
CVE-2023-34048 — VMware vCenter Server: VMware vCenter Server Out-of-Bounds Write Vulnerability
VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol that allows an attacker to conduct remote code execution.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.994.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.994 (99.94th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-01-22
CISA remediation due: 2024-02-12
Known ransomware campaign use: Unknown/None
CVE-2024-38856 — Apache OFBiz: Apache OFBiz Incorrect Authorization Vulnerability
Apache OFBiz contains an incorrect authorization vulnerability that could allow remote code execution via a Groovy payload in the context of the OFBiz user process by an unauthenticated attacker.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.994.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.994 (99.94th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-08-27
CISA remediation due: 2024-09-17
Known ransomware campaign use: Unknown/None
CVE-2022-0543 — Redis Debian-specific Redis Servers: Debian-specific Redis Server Lua Sandbox Escape Vulnerability
Redis is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.994.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 10.0 (NVD)
FIRST EPSS: 0.994 (99.94th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-28
CISA remediation due: 2022-04-18
Known ransomware campaign use: Unknown/None
CVE-2015-5119 — Adobe Flash Player: Adobe Flash Player Use-After-Free Vulnerability
A use-after-free vulnerability exists within the ActionScript 3 ByteArray class in Adobe Flash Player that allows an attacker to perform remote code execution.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.993.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: The impacted product is end-of-life and should be disconnected if still in use.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.993 (99.94th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-03
CISA remediation due: 2022-03-24
Known ransomware campaign use: Unknown/None
CVE-2014-6287 — Rejetto HTTP File Server (HFS): Rejetto HTTP File Server (HFS) Remote Code Execution Vulnerability
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (HFS or HttpFileServer) allows remote attackers to execute arbitrary programs.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.993.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.993 (99.94th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-25
CISA remediation due: 2022-04-15
Known ransomware campaign use: Unknown/None
CVE-2023-28771 — Zyxel Multiple Firewalls: Zyxel Multiple Firewalls OS Command Injection Vulnerability
Zyxel ATP, USG FLEX, VPN, and ZyWALL/USG firewalls allow for improper error message handling which could allow an unauthenticated attacker to execute OS commands remotely by sending crafted packets to an affected device.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.993.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.993 (99.94th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-05-31
CISA remediation due: 2023-06-21
Known ransomware campaign use: Unknown/None
CVE-2020-14750 — Oracle WebLogic Server: Oracle WebLogic Server Remote Code Execution Vulnerability
Oracle WebLogic Server contains an unspecified vulnerability allowing an unauthenticated attacker to perform remote code execution. This vulnerability is related to CVE-2020-14882.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.993.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.993 (99.93rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2020-1938 — Apache Tomcat: Apache Tomcat Improper Privilege Management Vulnerability
Apache Tomcat treats Apache JServ Protocol (AJP) connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.993.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.993 (99.94th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-03
CISA remediation due: 2022-03-17
Known ransomware campaign use: Unknown/None
CVE-2022-24086 — Adobe Commerce and Magento Open Source: Adobe Commerce and Magento Open Source Improper Input Validation Vulnerability
Adobe Commerce and Magento Open Source contain an improper input validation vulnerability which can allow for arbitrary code execution.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.992.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.992 (99.93rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-02-15
CISA remediation due: 2022-03-01
Known ransomware campaign use: Unknown/None
CVE-2017-3881 — Cisco IOS and IOS XE: Cisco IOS and IOS XE Remote Code Execution Vulnerability
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device or remotely execute code with elevated privileges.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.990.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.990 (99.93rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-25
CISA remediation due: 2022-04-15
Known ransomware campaign use: Unknown/None
CVE-2020-7247 — OpenBSD OpenSMTPD: OpenSMTPD Remote Code Execution Vulnerability
smtp_mailaddr in smtp_session.c in OpenSMTPD, as used in OpenBSD and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP session.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.990.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.990 (99.93rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-25
CISA remediation due: 2022-04-15
Known ransomware campaign use: Unknown/None
CVE-2019-3929 — Crestron Multiple Products: Crestron Multiple Products Command Injection Vulnerability
Multiple Crestron products are vulnerable to command injection via the file_transfer.cgi HTTP endpoint. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.990.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.990 (99.93rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-04-15
CISA remediation due: 2022-05-06
Known ransomware campaign use: Unknown/None
CVE-2017-9791 — Apache Struts 1: Apache Struts 1 Improper Input Validation Vulnerability
The Struts 1 plugin in Apache Struts might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.989.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.989 (99.92nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-02-10
CISA remediation due: 2022-08-10
Known ransomware campaign use: Unknown/None
CVE-2022-3236 — Sophos Firewall: Sophos Firewall Code Injection Vulnerability
A code injection vulnerability in the User Portal and Webadmin of Sophos Firewall allows for remote code execution.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.989.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.989 (99.92nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-09-23
CISA remediation due: 2022-10-14
Known ransomware campaign use: Unknown/None
CVE-2024-8963 — Ivanti Cloud Services Appliance (CSA): Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability
Ivanti Cloud Services Appliance (CSA) contains a path traversal vulnerability that could allow a remote, unauthenticated attacker to access restricted functionality. If CVE-2024-8963 is used in conjunction with CVE-2024-8190, an attacker could bypass admin authentication and execute arbitrary commands on the appliance.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.986.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: As Ivanti CSA has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line of supported solutions, as future vulnerabilities on the 4.6.x version of CSA are unlikely to receive security updates.
CVSS: 9.1 (NVD)
FIRST EPSS: 0.986 (99.92nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-09-19
CISA remediation due: 2024-10-10
Known ransomware campaign use: Unknown/None
CVE-2016-3088 — Apache ActiveMQ: Apache ActiveMQ Improper Input Validation Vulnerability
The Fileserver web application in Apache ActiveMQ allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.985.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.985 (99.92nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-02-10
CISA remediation due: 2022-08-10
Known ransomware campaign use: Unknown/None
CVE-2022-24816 — OSGeo JAI-EXT: OSGeo GeoServer JAI-EXT Code Injection Vulnerability
OSGeo GeoServer JAI-EXT contains a code injection vulnerability that, when programs use jt-jiffle and allow Jiffle script to be provided via network request, could allow remote code execution.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.985.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 10.0 (NVD)
FIRST EPSS: 0.985 (99.92nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-06-26
CISA remediation due: 2024-07-17
Known ransomware campaign use: Unknown/None
CVE-2018-1000861 — Jenkins Jenkins Stapler Web Framework: Jenkins Stapler Web Framework Deserialization of Untrusted Data Vulnerability
A code execution vulnerability exists in the Stapler web framework used by Jenkins
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.983.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.983 (99.91st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-02-10
CISA remediation due: 2022-08-10
Known ransomware campaign use: Unknown/None
CVE-2016-1555 — NETGEAR Wireless Access Point (WAP) Devices: NETGEAR Multiple WAP Devices Command Injection Vulnerability
Multiple NETGEAR Wireless Access Point devices allows unauthenticated web pages to pass form input directly to the command-line interface. Exploitation allows for arbitrary code execution.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.983.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.983 (99.91st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-25
CISA remediation due: 2022-04-15
Known ransomware campaign use: Unknown/None
CVE-2017-15944 — Palo Alto Networks PAN-OS: Palo Alto Networks PAN-OS Remote Code Execution Vulnerability
Palo Alto Networks PAN-OS contains multiple, unspecified vulnerabilities which can allow for remote code execution when chained.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.983.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.983 (99.91st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-08-18
CISA remediation due: 2022-09-08
Known ransomware campaign use: Unknown/None
CVE-2023-20887 — VMware Aria Operations for Networks: Vmware Aria Operations for Networks Command Injection Vulnerability
VMware Aria Operations for Networks (formerly vRealize Network Insight) contains a command injection vulnerability that allows a malicious actor with network access to perform an attack resulting in remote code execution.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.983.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.983 (99.91st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-06-22
CISA remediation due: 2023-07-13
Known ransomware campaign use: Unknown/None
CVE-2020-6207 — SAP Solution Manager: SAP Solution Manager Missing Authentication for Critical Function Vulnerability
SAP Solution Manager User Experience Monitoring contains a missing authentication for critical function vulnerability which results in complete compromise of all SMDAgents connected to the Solution Manager.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.983.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.983 (99.91st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2022-22947 — VMware Spring Cloud Gateway: VMware Spring Cloud Gateway Code Injection Vulnerability
Spring Cloud Gateway applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.983.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 10.0 (NVD)
FIRST EPSS: 0.983 (99.91st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-05-16
CISA remediation due: 2022-06-06
Known ransomware campaign use: Unknown/None
CVE-2022-26138 — Atlassian Confluence: Atlassian Questions For Confluence App Hard-coded Credentials Vulnerability
Atlassian Questions For Confluence App has hard-coded credentials, exposing the username and password in plaintext. A remote unauthenticated attacker can use these credentials to log into Confluence and access all content accessible to users in the confluence-users group.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.982.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.982 (99.91st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-07-29
CISA remediation due: 2022-08-19
Known ransomware campaign use: Unknown/None