Cross-Vendor Patch Advisories

Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.

Browse Advisories

Association
Vendor — all

Leave every box clear to show all 282 vendors.

1,308 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.

CISA KEV advisories matching the current filters, ranked by EVULNABLE Risk Score
CVE Vendor Product Vulnerability EVRS EPSS Ransomware CISA due
CVE-2025-4008 Smartbedded Meteobridge Smartbedded Meteobridge Command Injection Vulnerability 86 Immediate 0.933 (99.83rd pctl) Unknown/None 2025-10-23
CVE-2025-47812 Wing FTP Server Wing FTP Server Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerability 86 Immediate 0.928 (99.82nd pctl) Unknown/None 2025-08-04
CVE-2022-43939 Hitachi Vantara Pentaho Business Analytics (BA) Server Hitachi Vantara Pentaho BA Server Authorization Bypass Vulnerability 86 Immediate 0.923 (99.82nd pctl) Unknown/None 2025-03-24
CVE-2024-20439 Cisco Smart Licensing Utility Cisco Smart Licensing Utility Static Credential Vulnerability 86 Immediate 0.921 (99.81st pctl) Unknown/None 2025-04-21
CVE-2024-11680 ProjectSend ProjectSend ProjectSend Improper Authentication Vulnerability 86 Immediate 0.917 (99.81st pctl) Unknown/None 2024-12-24
CVE-2017-3066 Adobe ColdFusion Adobe ColdFusion Deserialization Vulnerability 86 Immediate 0.906 (99.79th pctl) Unknown/None 2025-03-17
CVE-2025-12480 Gladinet Triofox Gladinet Triofox Improper Access Control Vulnerability 86 Immediate 0.905 (99.79th pctl) Unknown/None 2025-12-03
CVE-2026-42208 BerriAI LiteLLM BerriAI LiteLLM SQL Injection Vulnerability 86 Immediate 0.894 (99.77th pctl) Unknown/None 2026-05-11
CVE-2026-3055 Citrix NetScaler Citrix NetScaler Out-of-Bounds Read Vulnerability 86 Immediate 0.872 (99.74th pctl) Unknown/None 2026-04-02
CVE-2026-1340 Ivanti Endpoint Manager Mobile (EPMM) Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability 86 Immediate 0.862 (99.72nd pctl) Unknown/None 2026-04-11
CVE-2026-24858 Fortinet Multiple Products Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability 86 Immediate 0.861 (99.72nd pctl) Unknown/None 2026-01-30
CVE-2020-7796 Synacor Zimbra Collaboration Suite Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability 86 Immediate 0.844 (99.68th pctl) Unknown/None 2026-03-10
CVE-2026-42271 BerriAI LiteLLM BerriAI LiteLLM Command Injection Vulnerability 86 Immediate 0.836 (99.67th pctl) Unknown/None 2026-06-22
CVE-2022-24990 TerraMaster TerraMaster OS TerraMaster OS Remote Command Execution Vulnerability 86 Immediate 0.836 (99.67th pctl) Known 2023-03-03
CVE-2018-15982 Adobe Flash Player Adobe Flash Player Use-After-Free Vulnerability 86 Immediate 0.825 (99.64th pctl) Known 2022-08-15
CVE-2018-13382 Fortinet FortiOS and FortiProxy Fortinet FortiOS and FortiProxy Improper Authorization 86 Immediate 0.817 (99.62nd pctl) Known 2022-07-10
CVE-2026-48907 Widget Factory Joomla Content Editor Widget Factory Joomla Content Editor Improper Access Control Vulnerability 86 Immediate 0.781 (99.54th pctl) Unknown/None 2026-06-19
CVE-2023-28461 Array Networks AG/vxAG ArrayOS Array Networks AG and vxAG ArrayOS Missing Authentication for Critical Function Vulnerability 86 Immediate 0.681 (99.27th pctl) Known 2024-12-16
CVE-2024-13159 Ivanti Endpoint Manager (EPM) Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability 85 Immediate 0.999 (99.99th pctl) Unknown/None 2025-03-31
CVE-2018-11776 Apache Struts Apache Struts Remote Code Execution Vulnerability 85 Immediate 0.999 (99.99th pctl) Unknown/None 2022-05-03
CVE-2017-12617 Apache Tomcat Apache Tomcat Remote Code Execution Vulnerability 85 Immediate 0.999 (99.98th pctl) Unknown/None 2022-04-15
CVE-2024-45195 Apache OFBiz Apache OFBiz Forced Browsing Vulnerability 85 Immediate 0.999 (99.98th pctl) Unknown/None 2025-02-25
CVE-2025-4427 Ivanti Endpoint Manager Mobile (EPMM) Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability 85 Immediate 0.999 (99.97th pctl) Unknown/None 2025-06-09
CVE-2017-9805 Apache Struts Apache Struts Deserialization of Untrusted Data Vulnerability 85 Immediate 0.994 (99.94th pctl) Unknown/None 2022-05-03
CVE-2022-36804 Atlassian Bitbucket Server and Data Center Atlassian Bitbucket Server and Data Center Command Injection Vulnerability 85 Immediate 0.991 (99.93rd pctl) Unknown/None 2022-10-21
Download filtered advisories (CSV)

Exactly the 1,308 advisory(ies) matching the filters above.

Advisory detail

Expand any advisory for its description, CISA's own required action, and research links.

CVE-2025-4008 — Smartbedded Meteobridge: Smartbedded Meteobridge Command Injection Vulnerability

Smartbedded Meteobridge contains a command injection vulnerability that could allow remote unauthenticated attackers to gain arbitrary command execution with elevated privileges (root) on affected devices.

EVULNABLE Risk · priority 86/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch Immediately

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.933.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 8.7 (NVD)

FIRST EPSS: 0.933 (99.83rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-10-02

CISA remediation due: 2025-10-23

Known ransomware campaign use: Unknown/None

CVE-2025-47812 — Wing FTP Server Wing FTP Server: Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerability

Wing FTP Server contains an improper neutralization of null byte or NUL character vulnerability that can allow injection of arbitrary Lua code into user session files. This can be used to execute arbitrary system commands with the privileges of the FTP service (root or SYSTEM by default).

EVULNABLE Risk · priority 86/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.928.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 10.0 (NVD)

FIRST EPSS: 0.928 (99.82nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-07-14

CISA remediation due: 2025-08-04

Known ransomware campaign use: Unknown/None

CVE-2022-43939 — Hitachi Vantara Pentaho Business Analytics (BA) Server: Hitachi Vantara Pentaho BA Server Authorization Bypass Vulnerability

Hitachi Vantara Pentaho BA Server contains a use of non-canonical URL paths for authorization decisions vulnerability that enables an attacker to bypass authorization.

EVULNABLE Risk · priority 86/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.923.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.923 (99.82nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-03-03

CISA remediation due: 2025-03-24

Known ransomware campaign use: Unknown/None

CVE-2024-20439 — Cisco Smart Licensing Utility: Cisco Smart Licensing Utility Static Credential Vulnerability

Cisco Smart Licensing Utility contains a static credential vulnerability that allows an unauthenticated, remote attacker to log in to an affected system and gain administrative credentials.

EVULNABLE Risk · priority 86/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.921.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.921 (99.81st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-03-31

CISA remediation due: 2025-04-21

Known ransomware campaign use: Unknown/None

CVE-2024-11680 — ProjectSend ProjectSend: ProjectSend Improper Authentication Vulnerability

ProjectSend contains an improper authentication vulnerability that allows a remote, unauthenticated attacker to enable unauthorized modification of the application's configuration via crafted HTTP requests to options.php. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript.

EVULNABLE Risk · priority 86/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.917.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.917 (99.81st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-12-03

CISA remediation due: 2024-12-24

Known ransomware campaign use: Unknown/None

CVE-2017-3066 — Adobe ColdFusion: Adobe ColdFusion Deserialization Vulnerability

Adobe ColdFusion contains a deserialization vulnerability in the Apache BlazeDS library that allows for arbitrary code execution.

EVULNABLE Risk · priority 86/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.906.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.906 (99.79th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-02-24

CISA remediation due: 2025-03-17

Known ransomware campaign use: Unknown/None

CVE-2025-12480 — Gladinet Triofox: Gladinet Triofox Improper Access Control Vulnerability

Gladinet Triofox contains an improper access control vulnerability that allows access to initial setup pages even after setup is complete.

EVULNABLE Risk · priority 86/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.905.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 9.1 (NVD)

FIRST EPSS: 0.905 (99.79th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-11-12

CISA remediation due: 2025-12-03

Known ransomware campaign use: Unknown/None

CVE-2026-42208 — BerriAI LiteLLM: BerriAI LiteLLM SQL Injection Vulnerability

BerriAI LiteLLM contains a SQL injection vulnerability that allows an attacker to read data from the proxy's database and potentially modify it, leading to unauthorized access to the proxy and the credentials it manages.

EVULNABLE Risk · priority 86/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch Immediately

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.894.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 9.3 (NVD)

FIRST EPSS: 0.894 (99.77th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-05-08

CISA remediation due: 2026-05-11

Known ransomware campaign use: Unknown/None

CVE-2026-3055 — Citrix NetScaler: Citrix NetScaler Out-of-Bounds Read Vulnerability

Citrix NetScaler ADC (formerly Citrix ADC), NetScaler Gateway (formerly Citrix Gateway) and NetScaler ADC FIPS and NDcPP contain an out-of-bounds reads vulnerability when configured as a SAML IDP leading to memory overread.

EVULNABLE Risk · priority 86/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch Immediately

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.872.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 9.3 (NVD)

FIRST EPSS: 0.872 (99.74th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-03-30

CISA remediation due: 2026-04-02

Known ransomware campaign use: Unknown/None

CVE-2026-1340 — Ivanti Endpoint Manager Mobile (EPMM): Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability

Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution.

EVULNABLE Risk · priority 86/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch Immediately

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.862.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.862 (99.72nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-04-08

CISA remediation due: 2026-04-11

Known ransomware campaign use: Unknown/None

CVE-2026-24858 — Fortinet Multiple Products: Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability

Fortinet FortiAnalyzer, FortiManager, FortiOS, and FortiProxy contain an authentication bypass using an alternate path or channel that could allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.

EVULNABLE Risk · priority 86/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch Immediately

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.861.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.861 (99.72nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-01-27

CISA remediation due: 2026-01-30

Known ransomware campaign use: Unknown/None

CVE-2020-7796 — Synacor Zimbra Collaboration Suite: Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability

Synacor Zimbra Collaboration Suite (ZCS) contains a server-side request forgery vulnerability if WebEx zimlet installed and zimlet JSP is enabled.

EVULNABLE Risk · priority 86/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch Immediately

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.844.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.844 (99.68th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-02-17

CISA remediation due: 2026-03-10

Known ransomware campaign use: Unknown/None

CVE-2026-42271 — BerriAI LiteLLM: BerriAI LiteLLM Command Injection Vulnerability

BerriAI LiteLLM contains a command injection vulnerability that could allow any authenticated user, including holders of low-privilege internal-user keys, to run arbitrary commands on the host.

EVULNABLE Risk · priority 86/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch Immediately

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.836.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 8.7 (NVD)

FIRST EPSS: 0.836 (99.67th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-06-08

CISA remediation due: 2026-06-22

Known ransomware campaign use: Unknown/None

CVE-2022-24990 — TerraMaster TerraMaster OS: TerraMaster OS Remote Command Execution Vulnerability

TerraMaster OS contains a remote command execution vulnerability that allows an unauthenticated user to execute commands on the target endpoint.

EVULNABLE Risk · priority 86/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch Immediately

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.836.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.836 (99.67th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-02-10

CISA remediation due: 2023-03-03

Known ransomware campaign use: Known

CVE-2018-15982 — Adobe Flash Player: Adobe Flash Player Use-After-Free Vulnerability

Adobe Flash Player com.adobe.tvsdk.mediacore.metadata Use After Free Vulnerability

EVULNABLE Risk · priority 86/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch Immediately

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.825.

CISA required action: The impacted product is end-of-life and should be disconnected if still in use.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.825 (99.64th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-02-15

CISA remediation due: 2022-08-15

Known ransomware campaign use: Known

CVE-2018-13382 — Fortinet FortiOS and FortiProxy: Fortinet FortiOS and FortiProxy Improper Authorization

An Improper Authorization vulnerability in Fortinet FortiOS and FortiProxy under SSL VPN web portal allows an unauthenticated attacker to modify the password.

EVULNABLE Risk · priority 86/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch Immediately

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.817.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.817 (99.62nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-01-10

CISA remediation due: 2022-07-10

Known ransomware campaign use: Known

CVE-2026-48907 — Widget Factory Joomla Content Editor: Widget Factory Joomla Content Editor Improper Access Control Vulnerability

Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticated users.

EVULNABLE Risk · priority 86/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch Immediately

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.781.

CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVSS: 10.0 (NVD)

FIRST EPSS: 0.781 (99.54th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-06-16

CISA remediation due: 2026-06-19

Known ransomware campaign use: Unknown/None

CVE-2023-28461 — Array Networks AG/vxAG ArrayOS: Array Networks AG and vxAG ArrayOS Missing Authentication for Critical Function Vulnerability

Array Networks AG and vxAG ArrayOS contain a missing authentication for critical function vulnerability that allows an attacker to read local files and execute code on the SSL VPN gateway.

EVULNABLE Risk · priority 86/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.681 (99.27th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-11-25

CISA remediation due: 2024-12-16

Known ransomware campaign use: Known

CVE-2024-13159 — Ivanti Endpoint Manager (EPM): Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability

Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information.

EVULNABLE Risk · priority 85/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch Immediately

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.999 (99.99th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-03-10

CISA remediation due: 2025-03-31

Known ransomware campaign use: Unknown/None

CVE-2018-11776 — Apache Struts: Apache Struts Remote Code Execution Vulnerability

Apache Struts contains a vulnerability that allows for remote code execution under two circumstances. One, where the alwaysSelectFullNamespace option is true and the value isn't set for a result defined in underlying configurations and in same time, its upper package configuration have no or wildcard namespace. Or, using URL tag which doesn't have value and action set and in same time, its upper package configuration have no or wildcard namespace.

EVULNABLE Risk · priority 85/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch Immediately

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.1 (NVD)

FIRST EPSS: 0.999 (99.99th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2017-12617 — Apache Tomcat: Apache Tomcat Remote Code Execution Vulnerability

When running Apache Tomcat, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

EVULNABLE Risk · priority 85/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch Immediately

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.1 (NVD)

FIRST EPSS: 0.999 (99.98th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-25

CISA remediation due: 2022-04-15

Known ransomware campaign use: Unknown/None

CVE-2024-45195 — Apache OFBiz: Apache OFBiz Forced Browsing Vulnerability

Apache OFBiz contains a forced browsing vulnerability that allows a remote attacker to obtain unauthorized access.

EVULNABLE Risk · priority 85/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch Immediately

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.999 (99.98th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-02-04

CISA remediation due: 2025-02-25

Known ransomware campaign use: Unknown/None

CVE-2025-4427 — Ivanti Endpoint Manager Mobile (EPMM): Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability

Ivanti Endpoint Manager Mobile (EPMM) contains an authentication bypass vulnerability in the API component that allows an attacker to access protected resources without proper credentials via crafted API requests. This vulnerability results from an insecure implementation of the Spring Framework open-source library.

EVULNABLE Risk · priority 85/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch Immediately

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.999 (99.97th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-05-19

CISA remediation due: 2025-06-09

Known ransomware campaign use: Unknown/None

CVE-2017-9805 — Apache Struts: Apache Struts Deserialization of Untrusted Data Vulnerability

Apache Struts REST Plugin uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to remote code execution when deserializing XML payloads.

EVULNABLE Risk · priority 85/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch Immediately

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.994.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.1 (NVD)

FIRST EPSS: 0.994 (99.94th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2022-36804 — Atlassian Bitbucket Server and Data Center: Atlassian Bitbucket Server and Data Center Command Injection Vulnerability

Multiple API endpoints of Atlassian Bitbucket Server and Data Center contain a command injection vulnerability where an attacker with access to a public Bitbucket repository, or with read permissions to a private one, can execute code by sending a malicious HTTP request.

EVULNABLE Risk · priority 85/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch Immediately

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.991.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.991 (99.93rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-09-30

CISA remediation due: 2022-10-21

Known ransomware campaign use: Unknown/None

Data sources & attribution

Known-exploitation status, required actions, ransomware association and remediation deadlines come from the CISA Known Exploited Vulnerabilities Catalog. Exploitation probability and percentile are provided by FIRST.org's EPSS, used under FIRST's open data terms.

Microsoft Patch Tuesday data is sourced from the Microsoft Security Update Guide; lifecycle milestones from endoflife.date. Linux distribution advisories come from Red Hat, Ubuntu and Debian; vendor bulletins from Adobe, Apple, Chrome, Cisco, Ivanti and Oracle, each linked to its own advisory.