Cross-Vendor Patch Advisories
Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.
Browse Advisories
1,308 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.
| CVE | Vendor | Product | Vulnerability | EVRS | EPSS | Ransomware | CISA due |
|---|---|---|---|---|---|---|---|
| CVE-2020-10148 | SolarWinds | Orion | SolarWinds Orion Authentication Bypass Vulnerability | 85 Immediate | 0.920 (99.81st pctl) | Unknown/None | 2022-05-03 |
| CVE-2020-8657 | EyesOfNetwork | EyesOfNetwork | EyesOfNetwork Use of Hard-Coded Credentials Vulnerability | 85 Immediate | 0.919 (99.81st pctl) | Unknown/None | 2022-05-03 |
| CVE-2024-5910 | Palo Alto Networks | Expedition | Palo Alto Networks Expedition Missing Authentication Vulnerability | 85 Immediate | 0.918 (99.81st pctl) | Unknown/None | 2024-11-28 |
| CVE-2012-5076 | Oracle | Java SE | Oracle Java SE Sandbox Bypass Vulnerability | 85 Immediate | 0.910 (99.8th pctl) | Unknown/None | 2022-04-18 |
| CVE-2025-6218 | RARLAB | WinRAR | RARLAB WinRAR Path Traversal Vulnerability | 85 Immediate | 0.905 (99.79th pctl) | Unknown/None | 2025-12-30 |
| CVE-2021-32648 | October CMS | October CMS | October CMS Improper Authentication | 85 Immediate | 0.904 (99.79th pctl) | Unknown/None | 2022-02-01 |
| CVE-2020-3952 | VMware | vCenter Server | VMware vCenter Server Information Disclosure Vulnerability | 85 Immediate | 0.904 (99.79th pctl) | Unknown/None | 2022-05-03 |
| CVE-2016-8735 | Apache | Tomcat | Apache Tomcat Remote Code Execution Vulnerability | 85 Immediate | 0.903 (99.79th pctl) | Unknown/None | 2023-06-02 |
| CVE-2020-29583 | Zyxel | Multiple Products | Zyxel Multiple Products Use of Hard-Coded Credentials Vulnerability | 85 Immediate | 0.902 (99.79th pctl) | Unknown/None | 2022-05-03 |
| CVE-2013-0431 | Oracle | Java Runtime Environment (JRE) | Oracle JRE Sandbox Bypass Vulnerability | 85 Immediate | 0.900 (99.78th pctl) | Known | 2022-06-15 |
| CVE-2025-57819 | Sangoma | FreePBX | Sangoma FreePBX Authentication Bypass Vulnerability | 85 Immediate | 0.883 (99.76th pctl) | Unknown/None | 2025-09-19 |
| CVE-2024-12356 | BeyondTrust | Privileged Remote Access (PRA) and Remote Support (RS) | BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) Command Injection Vulnerability | 85 Immediate | 0.880 (99.75th pctl) | Unknown/None | 2024-12-27 |
| CVE-2025-20362 | Cisco | Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense | Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Missing Authorization Vulnerability | 85 Immediate | 0.871 (99.74th pctl) | Unknown/None | 2025-09-26 |
| CVE-2009-3459 | Adobe | Acrobat and Reader | Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability | 85 Immediate | 0.866 (99.72nd pctl) | Unknown/None | 2026-06-03 |
| CVE-2020-3580 | Cisco | Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | Cisco ASA and FTD Cross-Site Scripting (XSS) Vulnerability | 85 Immediate | 0.856 (99.71st pctl) | Known | 2022-05-03 |
| CVE-2023-41266 | Qlik | Sense | Qlik Sense Path Traversal Vulnerability | 85 Immediate | 0.848 (99.69th pctl) | Known | 2023-12-28 |
| CVE-2025-34291 | Langflow | Langflow | Langflow Origin Validation Error Vulnerability | 85 Immediate | 0.836 (99.67th pctl) | Unknown/None | 2026-06-04 |
| CVE-2025-40551 | SolarWinds | Web Help Desk | SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability | 85 Immediate | 0.836 (99.67th pctl) | Unknown/None | 2026-02-06 |
| CVE-2010-3765 | Mozilla | Multiple Products | Mozilla Multiple Products Remote Code Execution Vulnerability | 85 Immediate | 0.833 (99.66th pctl) | Unknown/None | 2025-10-27 |
| CVE-2026-1281 | Ivanti | Endpoint Manager Mobile (EPMM) | Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability | 85 Immediate | 0.818 (99.62nd pctl) | Unknown/None | 2026-02-01 |
| CVE-2025-40536 | SolarWinds | Web Help Desk | SolarWinds Web Help Desk Security Control Bypass Vulnerability | 85 Immediate | 0.816 (99.62nd pctl) | Unknown/None | 2026-02-15 |
| CVE-2021-21975 | VMware | vRealize Operations Manager API | VMware Server Side Request Forgery in vRealize Operations Manager API | 85 Immediate | 0.783 (99.55th pctl) | Known | 2022-02-01 |
| CVE-2023-27532 | Veeam | Backup & Replication | Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function Vulnerability | 85 Immediate | 0.776 (99.53rd pctl) | Known | 2023-09-12 |
| CVE-2026-25089 | Fortinet | FortiSandbox | Fortinet FortiSandbox OS Command Injection Vulnerability | 85 Immediate | 0.761 (99.5th pctl) | Unknown/None | 2026-07-19 |
| CVE-2022-2294 | WebRTC | WebRTC | WebRTC Heap Buffer Overflow Vulnerability | 85 Immediate | 0.705 (99.34th pctl) | Known | 2022-09-15 |
Exactly the 1,308 advisory(ies) matching the filters above.
Advisory detail
Expand any advisory for its description, CISA's own required action, and research links.
CVE-2020-10148 — SolarWinds Orion: SolarWinds Orion Authentication Bypass Vulnerability
SolarWinds Orion API contains an authentication bypass vulnerability that could allow a remote attacker to execute API commands.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.920.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.920 (99.81st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2020-8657 — EyesOfNetwork EyesOfNetwork: EyesOfNetwork Use of Hard-Coded Credentials Vulnerability
EyesOfNetwork contains a use of hard-coded credentials vulnerability, as it uses the same API key by default. Exploitation allows an attacker to calculate or guess the admin access token.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.919.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.919 (99.81st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2024-5910 — Palo Alto Networks Expedition: Palo Alto Networks Expedition Missing Authentication Vulnerability
Palo Alto Networks Expedition contains a missing authentication vulnerability that allows an attacker with network access to takeover an Expedition admin account and potentially access configuration secrets, credentials, and other data.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.918.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 9.3 (NVD)
FIRST EPSS: 0.918 (99.81st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-11-07
CISA remediation due: 2024-11-28
Known ransomware campaign use: Unknown/None
CVE-2012-5076 — Oracle Java SE: Oracle Java SE Sandbox Bypass Vulnerability
The default Java security properties configuration did not restrict access to the com.sun.org.glassfish.external and com.sun.org.glassfish.gmbal packages. An untrusted Java application or applet could use these flaws to bypass Java sandbox restrictions.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.910.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.910 (99.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-28
CISA remediation due: 2022-04-18
Known ransomware campaign use: Unknown/None
CVE-2025-6218 — RARLAB WinRAR: RARLAB WinRAR Path Traversal Vulnerability
RARLAB WinRAR contains a path traversal vulnerability allowing an attacker to execute code in the context of the current user.
Recommended priority: Patch Immediately
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.905.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.905 (99.79th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-12-09
CISA remediation due: 2025-12-30
Known ransomware campaign use: Unknown/None
CVE-2021-32648 — October CMS October CMS: October CMS Improper Authentication
In affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially crafted request.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.904.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.1 (NVD)
FIRST EPSS: 0.904 (99.79th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-01-18
CISA remediation due: 2022-02-01
Known ransomware campaign use: Unknown/None
CVE-2020-3952 — VMware vCenter Server: VMware vCenter Server Information Disclosure Vulnerability
VMware vCenter Server contains an information disclosure vulnerability in the VMware Directory Service (vmdir) when the Platform Services Controller (PSC) does not correctly implement access controls. Successful exploitation allows an attacker with network access to port 389 to extract sensitive information.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.904.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.904 (99.79th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2016-8735 — Apache Tomcat: Apache Tomcat Remote Code Execution Vulnerability
Apache Tomcat contains an unspecified vulnerability that allows for remote code execution if JmxRemoteLifecycleListener is used and an attacker can reach Java Management Extension (JMX) ports. This CVE exists because this listener wasn't updated for consistency with the Oracle patched issues for CVE-2016-3427 which affected credential types.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.903.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.903 (99.79th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-05-12
CISA remediation due: 2023-06-02
Known ransomware campaign use: Unknown/None
CVE-2020-29583 — Zyxel Multiple Products: Zyxel Multiple Products Use of Hard-Coded Credentials Vulnerability
Zyxel firewalls (ATP, USG, VM) and AP Controllers (NXC2500 and NXC5500) contain a use of hard-coded credentials vulnerability in an undocumented account ("zyfwp") with an unchangeable password.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.902.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.902 (99.79th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2013-0431 — Oracle Java Runtime Environment (JRE): Oracle JRE Sandbox Bypass Vulnerability
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle allows remote attackers to bypass the Java security sandbox.
Recommended priority: Patch Immediately
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.900.
CISA required action: Apply updates per vendor instructions.
CVSS: 5.3 (NVD)
FIRST EPSS: 0.900 (99.78th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-05-25
CISA remediation due: 2022-06-15
Known ransomware campaign use: Known
CVE-2025-57819 — Sangoma FreePBX: Sangoma FreePBX Authentication Bypass Vulnerability
Sangoma FreePBX contains an authentication bypass vulnerability due to insufficiently sanitized user-supplied data allows unauthenticated access to FreePBX Administrator leading to arbitrary database manipulation and remote code execution.
Recommended priority: Patch Immediately
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.883.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 10.0 (NVD)
FIRST EPSS: 0.883 (99.76th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-08-29
CISA remediation due: 2025-09-19
Known ransomware campaign use: Unknown/None
CVE-2024-12356 — BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS): BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) Command Injection Vulnerability
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain a command injection vulnerability, which can allow an unauthenticated attacker to inject commands that are run as a site user.
Recommended priority: Patch Immediately
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.880.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.880 (99.75th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-12-19
CISA remediation due: 2024-12-27
Known ransomware campaign use: Unknown/None
CVE-2025-20362 — Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense: Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Missing Authorization Vulnerability
Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Software VPN Web Server contain a missing authorization vulnerability. This vulnerability could be chained with CVE-2025-20333.
Recommended priority: Patch Immediately
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.871.
CISA required action: The KEV due date refers to the deadline by which FCEB agencies are expected to review and begin implementing the guidance outlined in Emergency Directive (ED) 25-03 (URL listed below in Notes). Agencies must follow the mitigation steps provided by CISA (URL listed below in Notes) and vendor’s instructions (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.
CVSS: 8.6 (NVD)
FIRST EPSS: 0.871 (99.74th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-09-25
CISA remediation due: 2025-09-26
Known ransomware campaign use: Unknown/None
CVE-2009-3459 — Adobe Acrobat and Reader: Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability
Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability which could allow remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption.
Recommended priority: Patch Immediately
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.866.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.866 (99.72nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-05-20
CISA remediation due: 2026-06-03
Known ransomware campaign use: Unknown/None
CVE-2020-3580 — Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD): Cisco ASA and FTD Cross-Site Scripting (XSS) Vulnerability
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an insufficient input validation vulnerability for user-supplied input by the web services interface. Successful exploitation could allow an attacker to perform cross-site scripting (XSS) in the context of the interface or access sensitive browser-based information.
Recommended priority: Patch Immediately
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.856.
CISA required action: Apply updates per vendor instructions.
CVSS: 6.1 (NVD)
FIRST EPSS: 0.856 (99.71st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Known
CVE-2023-41266 — Qlik Sense: Qlik Sense Path Traversal Vulnerability
Qlik Sense contains a path traversal vulnerability that allows a remote, unauthenticated attacker to create an anonymous session by sending maliciously crafted HTTP requests. This anonymous session could allow the attacker to send further requests to unauthorized endpoints.
Recommended priority: Patch Immediately
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.848.
CISA required action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
CVSS: 6.5 (NVD)
FIRST EPSS: 0.848 (99.69th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-12-07
CISA remediation due: 2023-12-28
Known ransomware campaign use: Known
CVE-2025-34291 — Langflow Langflow: Langflow Origin Validation Error Vulnerability
Langflow contains an origin validation error vulnerability in which an overly permissive CORS configuration combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform cross-origin requests that include credentials and successfully call the refresh endpoint. This could allow the attacker to execute arbitrary code and achieve full system compromise via obtained tokens that permit access to authenticated endpoints.
Recommended priority: Patch Immediately
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.836.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.4 (NVD)
FIRST EPSS: 0.836 (99.67th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-05-21
CISA remediation due: 2026-06-04
Known ransomware campaign use: Unknown/None
CVE-2025-40551 — SolarWinds Web Help Desk: SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability
SolarWinds Web Help Desk contains a deserialization of untrusted data vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication.
Recommended priority: Patch Immediately
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.836.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.836 (99.67th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-02-03
CISA remediation due: 2026-02-06
Known ransomware campaign use: Unknown/None
CVE-2010-3765 — Mozilla Multiple Products: Mozilla Multiple Products Remote Code Execution Vulnerability
Mozilla Firefox, SeaMonkey, and Thunderbird contain an unspecified vulnerability when JavaScript is enabled. This allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the creation of multiple frames, which triggers memory corruption.
Recommended priority: Patch Immediately
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.833.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.833 (99.66th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-10-06
CISA remediation due: 2025-10-27
Known ransomware campaign use: Unknown/None
CVE-2026-1281 — Ivanti Endpoint Manager Mobile (EPMM): Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution.
Recommended priority: Patch Immediately
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.818.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.818 (99.62nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-01-29
CISA remediation due: 2026-02-01
Known ransomware campaign use: Unknown/None
CVE-2025-40536 — SolarWinds Web Help Desk: SolarWinds Web Help Desk Security Control Bypass Vulnerability
SolarWinds Web Help Desk contains a security control bypass vulnerability that could allow an unauthenticated attacker to gain access to certain restricted functionality.
Recommended priority: Patch Immediately
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.816.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.816 (99.62nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-02-12
CISA remediation due: 2026-02-15
Known ransomware campaign use: Unknown/None
CVE-2021-21975 — VMware vRealize Operations Manager API: VMware Server Side Request Forgery in vRealize Operations Manager API
Server Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API to perform a SSRF attack to steal administrative credentials.
Recommended priority: Patch Immediately
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.783.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.5 (NVD)
FIRST EPSS: 0.783 (99.55th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-01-18
CISA remediation due: 2022-02-01
Known ransomware campaign use: Known
CVE-2023-27532 — Veeam Backup & Replication: Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function Vulnerability
Veeam Backup & Replication Cloud Connect component contains a missing authentication for critical function vulnerability that allows an unauthenticated user operating within the backup infrastructure network perimeter to obtain encrypted credentials stored in the configuration database. This may lead to an attacker gaining access to the backup infrastructure hosts.
Recommended priority: Patch Immediately
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.776.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 7.5 (NVD)
FIRST EPSS: 0.776 (99.53rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-08-22
CISA remediation due: 2023-09-12
Known ransomware campaign use: Known
CVE-2026-25089 — Fortinet FortiSandbox: Fortinet FortiSandbox OS Command Injection Vulnerability
Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.
Recommended priority: Patch Immediately
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.761.
CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.761 (99.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-07-16
CISA remediation due: 2026-07-19
Known ransomware campaign use: Unknown/None
CVE-2022-2294 — WebRTC WebRTC: WebRTC Heap Buffer Overflow Vulnerability
WebRTC, an open-source project providing web browsers with real-time communication, contains a heap buffer overflow vulnerability that allows an attacker to perform shellcode execution. This vulnerability impacts web browsers using WebRTC including but not limited to Google Chrome.
Recommended priority: Patch Immediately
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.705 (99.34th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-08-25
CISA remediation due: 2022-09-15
Known ransomware campaign use: Known