Cross-Vendor Patch Advisories
Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.
Browse Advisories
1,308 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.
| CVE | Vendor | Product | Vulnerability | EVRS | EPSS | Ransomware | CISA due |
|---|---|---|---|---|---|---|---|
| CVE-2021-27103 | Accellion | FTA | Accellion FTA Server-Side Request Forgery (SSRF) Vulnerability | 85 Immediate | 0.113 (95.7th pctl) | Known | 2021-11-17 |
| CVE-2019-11634 | Citrix | Workspace Application and Receiver for Windows | Citrix Workspace Application and Receiver for Windows Remote Code Execution Vulnerability | 85 Immediate | 0.080 (94.4th pctl) | Known | 2022-05-03 |
| CVE-2018-19323 | GIGABYTE | Multiple Products | GIGABYTE Multiple Products Privilege Escalation Vulnerability | 85 Immediate | 0.078 (94.3rd pctl) | Known | 2022-11-14 |
| CVE-2026-82329 | JFrog | Artifactory | JFrog Artifactory Improper Authentication Vulnerability | 85 Immediate | 0.077 (94.2nd pctl) | Unknown/None | 2026-09-05 |
| CVE-2021-27101 | Accellion | FTA | Accellion FTA SQL Injection Vulnerability | 85 Immediate | 0.059 (92.8th pctl) | Known | 2021-11-17 |
| CVE-2020-29574 | Sophos | CyberoamOS | CyberoamOS (CROS) SQL Injection Vulnerability | 85 Immediate | 0.046 (91st pctl) | Known | 2025-02-27 |
| CVE-2020-2021 | Palo Alto Networks | PAN-OS | Palo Alto Networks PAN-OS Authentication Bypass Vulnerability | 85 Immediate | 0.044 (90.6th pctl) | Known | 2022-04-15 |
| CVE-2022-26501 | Veeam | Backup & Replication | Veeam Backup & Replication Remote Code Execution Vulnerability | 85 Immediate | 0.041 (90.1st pctl) | Known | 2023-01-03 |
| CVE-2024-11667 | Zyxel | Multiple Firewalls | Zyxel Multiple Firewalls Path Traversal Vulnerability | 85 Immediate | 0.029 (86.1st pctl) | Known | 2024-12-24 |
| CVE-2026-45321 | TanStack | TanStack | TanStack Unspecified Vulnerability | 85 Immediate | 0.023 (82.5th pctl) | Known | 2026-06-10 |
| CVE-2026-49869 | Kestra | Kestra OSS | Kestra OSS OS Command Injection Vulnerability | 85 Immediate | 0.019 (78.5th pctl) | Unknown/None | 2026-09-05 |
| CVE-2026-48027 | Nx | Nx Console | Nx Console Embedded Malicious Code Vulnerability | 85 Immediate | 0.018 (77.7th pctl) | Known | 2026-06-10 |
| CVE-2026-72530 | TrueConf | Server | TrueConf Server Code Injection Vulnerability | 85 Immediate | 0.018 (77.4th pctl) | Unknown/None | 2026-09-03 |
| CVE-2026-82078 | PaperCut | NG/MF | PaperCut NG/MF Unsafe Reflection Vulnerability | 85 Immediate | 0.009 (58.1st pctl) | Unknown/None | 2026-09-14 |
| CVE-2026-83548 | SonicWall | SMA1000 Appliances | SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability | 85 Immediate | 0.007 (51.1st pctl) | Unknown/None | 2026-09-05 |
| CVE-2014-0160 | OpenSSL | OpenSSL | OpenSSL Information Disclosure Vulnerability | 84 Urgent | 0.999 (99.99th pctl) | Unknown/None | 2022-05-25 |
| CVE-2023-32315 | Ignite Realtime | Openfire | Ignite Realtime Openfire Path Traversal Vulnerability | 84 Urgent | 0.999 (99.99th pctl) | Unknown/None | 2023-09-14 |
| CVE-2023-44487 | IETF | HTTP/2 | HTTP/2 Rapid Reset Attack Vulnerability | 84 Urgent | 0.999 (99.99th pctl) | Unknown/None | 2023-10-31 |
| CVE-2020-3452 | Cisco | Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | Cisco ASA and FTD Read-Only Path Traversal Vulnerability | 84 Urgent | 0.999 (99.99th pctl) | Unknown/None | 2022-05-03 |
| CVE-2021-22204 | Perl | Exiftool | ExifTool Remote Code Execution Vulnerability | 84 Urgent | 0.999 (99.98th pctl) | Unknown/None | 2021-12-01 |
| CVE-2021-3156 | Sudo | Sudo | Sudo Heap-Based Buffer Overflow Vulnerability | 84 Urgent | 0.999 (99.98th pctl) | Unknown/None | 2022-04-27 |
| CVE-2021-39226 | Grafana Labs | Grafana | Grafana Authentication Bypass Vulnerability | 84 Urgent | 0.999 (99.97th pctl) | Unknown/None | 2022-09-15 |
| CVE-2018-0296 | Cisco | Adaptive Security Appliance (ASA) | Cisco Adaptive Security Appliance (ASA) Denial-of-Service Vulnerability | 84 Urgent | 0.999 (99.97th pctl) | Unknown/None | 2022-05-03 |
| CVE-2023-21839 | Oracle | WebLogic Server | Oracle WebLogic Server Unspecified Vulnerability | 84 Urgent | 0.999 (99.96th pctl) | Unknown/None | 2023-05-22 |
| CVE-2019-1653 | Cisco | Small Business RV320 and RV325 Routers | Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability | 84 Urgent | 0.999 (99.96th pctl) | Unknown/None | 2022-05-03 |
Exactly the 1,308 advisory(ies) matching the filters above.
Advisory detail
Expand any advisory for its description, CISA's own required action, and research links.
CVE-2021-27103 — Accellion FTA: Accellion FTA Server-Side Request Forgery (SSRF) Vulnerability
Accellion FTA contains a server-side request forgery (SSRF) vulnerability exploited via a crafted POST request to wmProgressstat.html.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.113 (95.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2021-11-17
Known ransomware campaign use: Known
CVE-2019-11634 — Citrix Workspace Application and Receiver for Windows: Citrix Workspace Application and Receiver for Windows Remote Code Execution Vulnerability
Citrix Workspace Application and Receiver for Windows contains remote code execution vulnerability resulting from local drive access preferences not being enforced into the clients' local drives.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.080 (94.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Known
CVE-2018-19323 — GIGABYTE Multiple Products: GIGABYTE Multiple Products Privilege Escalation Vulnerability
The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.078 (94.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-10-24
CISA remediation due: 2022-11-14
Known ransomware campaign use: Known
CVE-2026-82329 — JFrog Artifactory: JFrog Artifactory Improper Authentication Vulnerability
JFrog Artifactory contains an improper authentication vulnerability that under default configuration can allow an unauthenticated attacker with network access to obtain administrative privileges.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.077 (94.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-09-02
CISA remediation due: 2026-09-05
Known ransomware campaign use: Unknown/None
CVE-2021-27101 — Accellion FTA: Accellion FTA SQL Injection Vulnerability
Accellion FTA contains a SQL injection vulnerability exploited via a crafted host header in a request to document_root.html.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.059 (92.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2021-11-17
Known ransomware campaign use: Known
CVE-2020-29574 — Sophos CyberoamOS: CyberoamOS (CROS) SQL Injection Vulnerability
CyberoamOS (CROS) contains a SQL injection vulnerability in the WebAdmin that allows an unauthenticated attacker to execute arbitrary SQL statements remotely.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.046 (91st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-02-06
CISA remediation due: 2025-02-27
Known ransomware campaign use: Known
CVE-2020-2021 — Palo Alto Networks PAN-OS: Palo Alto Networks PAN-OS Authentication Bypass Vulnerability
Palo Alto Networks PAN-OS contains a vulnerability in SAML which allows an attacker to bypass authentication.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 10.0 (NVD)
FIRST EPSS: 0.044 (90.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-25
CISA remediation due: 2022-04-15
Known ransomware campaign use: Known
CVE-2022-26501 — Veeam Backup & Replication: Veeam Backup & Replication Remote Code Execution Vulnerability
The Veeam Distribution Service in the Backup & Replication application allows unauthenticated users to access internal API functions. A remote attacker can send input to the internal API which may lead to uploading and executing of malicious code.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.041 (90.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-12-13
CISA remediation due: 2023-01-03
Known ransomware campaign use: Known
CVE-2024-11667 — Zyxel Multiple Firewalls: Zyxel Multiple Firewalls Path Traversal Vulnerability
Multiple Zyxel firewalls contain a path traversal vulnerability in the web management interface that could allow an attacker to download or upload files via a crafted URL.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.029 (86.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-12-03
CISA remediation due: 2024-12-24
Known ransomware campaign use: Known
CVE-2026-45321 — TanStack TanStack: TanStack Unspecified Vulnerability
TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a trusted identity.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.6 (NVD)
FIRST EPSS: 0.023 (82.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-05-27
CISA remediation due: 2026-06-10
Known ransomware campaign use: Known
CVE-2026-49869 — Kestra Kestra OSS: Kestra OSS OS Command Injection Vulnerability
Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVSS: 10.0 (NVD)
FIRST EPSS: 0.019 (78.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-09-02
CISA remediation due: 2026-09-05
Known ransomware campaign use: Unknown/None
CVE-2026-48027 — Nx Nx Console: Nx Console Embedded Malicious Code Vulnerability
Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload that could harvested credentials from multiple sources on disk and in memory.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.3 (NVD)
FIRST EPSS: 0.018 (77.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-05-27
CISA remediation due: 2026-06-10
Known ransomware campaign use: Known
CVE-2026-72530 — TrueConf Server: TrueConf Server Code Injection Vulnerability
TrueConf Server contains a code injection vulnerability that could allow an unauthorized remote attacker with network access via port 4307/TCP to use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVSS: 9.5 (NVD)
FIRST EPSS: 0.018 (77.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-08-20
CISA remediation due: 2026-09-03
Known ransomware campaign use: Unknown/None
CVE-2026-82078 — PaperCut NG/MF: PaperCut NG/MF Unsafe Reflection Vulnerability
PaperCut NG/MF contains an unsafe reflection vulnerability that allows an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process. This vulnerability can be chained with CVE-2026-81578.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVSS: 9.4 (NVD)
FIRST EPSS: 0.009 (58.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-08-31
CISA remediation due: 2026-09-14
Known ransomware campaign use: Unknown/None
CVE-2026-83548 — SonicWall SMA1000 Appliances: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVSS: 10.0 (NVD)
FIRST EPSS: 0.007 (51.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-09-02
CISA remediation due: 2026-09-05
Known ransomware campaign use: Unknown/None
CVE-2014-0160 — OpenSSL OpenSSL: OpenSSL Information Disclosure Vulnerability
The TLS and DTLS implementations in OpenSSL do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.5 (NVD)
FIRST EPSS: 0.999 (99.99th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-05-04
CISA remediation due: 2022-05-25
Known ransomware campaign use: Unknown/None
CVE-2023-32315 — Ignite Realtime Openfire: Ignite Realtime Openfire Path Traversal Vulnerability
Ignite Realtime Openfire contains a path traversal vulnerability that allows an unauthenticated attacker to access restricted pages in the Openfire Admin Console reserved for administrative users.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 7.5 (NVD)
FIRST EPSS: 0.999 (99.99th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-08-24
CISA remediation due: 2023-09-14
Known ransomware campaign use: Unknown/None
CVE-2023-44487 — IETF HTTP/2: HTTP/2 Rapid Reset Attack Vulnerability
HTTP/2 contains a rapid reset vulnerability that allows for a distributed denial-of-service attack (DDoS).
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 7.5 (NVD)
FIRST EPSS: 0.999 (99.99th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-10-10
CISA remediation due: 2023-10-31
Known ransomware campaign use: Unknown/None
CVE-2020-3452 — Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD): Cisco ASA and FTD Read-Only Path Traversal Vulnerability
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an improper input validation vulnerability when HTTP requests process URLs. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences to an affected device. A successful exploit could allow the attacker to view arbitrary files within the web services file system on the targeted device.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.5 (NVD)
FIRST EPSS: 0.999 (99.99th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2021-22204 — Perl Exiftool: ExifTool Remote Code Execution Vulnerability
Improper neutralization of user data in the DjVu file format in Exiftool versions 7.44 and up allows arbitrary code execution when parsing the malicious image
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.999 (99.98th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-17
CISA remediation due: 2021-12-01
Known ransomware campaign use: Unknown/None
CVE-2021-3156 — Sudo Sudo: Sudo Heap-Based Buffer Overflow Vulnerability
Sudo contains an off-by-one error that can result in a heap-based buffer overflow, which allows for privilege escalation.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.999 (99.98th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-04-06
CISA remediation due: 2022-04-27
Known ransomware campaign use: Unknown/None
CVE-2021-39226 — Grafana Labs Grafana: Grafana Authentication Bypass Vulnerability
Grafana contains an authentication bypass vulnerability that allows authenticated and unauthenticated users to view and delete all snapshot data, potentially resulting in complete snapshot data loss.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.3 (NVD)
FIRST EPSS: 0.999 (99.97th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-08-25
CISA remediation due: 2022-09-15
Known ransomware campaign use: Unknown/None
CVE-2018-0296 — Cisco Adaptive Security Appliance (ASA): Cisco Adaptive Security Appliance (ASA) Denial-of-Service Vulnerability
Cisco Adaptive Security Appliance (ASA) contains an improper input validation vulnerability with HTTP URLs. Exploitation could allow an attacker to cause a denial-of-service (DoS) condition or information disclosure.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.5 (NVD)
FIRST EPSS: 0.999 (99.97th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2023-21839 — Oracle WebLogic Server: Oracle WebLogic Server Unspecified Vulnerability
Oracle WebLogic Server contains an unspecified vulnerability that allows an unauthenticated attacker with network access via T3, IIOP, to compromise Oracle WebLogic Server.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.5 (NVD)
FIRST EPSS: 0.999 (99.96th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-05-01
CISA remediation due: 2023-05-22
Known ransomware campaign use: Unknown/None
CVE-2019-1653 — Cisco Small Business RV320 and RV325 Routers: Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers contain improper access controls for URLs. Exploitation could allow an attacker to download the router configuration or detailed diagnostic information.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.5 (NVD)
FIRST EPSS: 0.999 (99.96th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None