Cross-Vendor Patch Advisories
Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.
Browse Advisories
1,308 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.
| CVE | Vendor | Product | Vulnerability | EVRS | EPSS | Ransomware | CISA due |
|---|---|---|---|---|---|---|---|
| CVE-2016-20017 | D-Link | DSL-2750B Devices | D-Link DSL-2750B Devices Command Injection Vulnerability | 78 Urgent | 0.652 (99.2nd pctl) | Unknown/None | 2024-01-29 |
| CVE-2022-21445 | Oracle | ADF Faces | Oracle ADF Faces Deserialization of Untrusted Data Vulnerability | 78 Urgent | 0.625 (99.13rd pctl) | Unknown/None | 2024-10-09 |
| CVE-2024-23113 | Fortinet | Multiple Products | Fortinet Multiple Products Format String Vulnerability | 78 Urgent | 0.617 (99.11st pctl) | Unknown/None | 2024-10-30 |
| CVE-2024-54085 | AMI | MegaRAC SPx | AMI MegaRAC SPx Authentication Bypass by Spoofing Vulnerability | 78 Urgent | 0.607 (99.09th pctl) | Unknown/None | 2025-07-16 |
| CVE-2026-33634 | Aquasecurity | Trivy | Aquasecurity Trivy Embedded Malicious Code Vulnerability | 78 Urgent | 0.592 (99.05th pctl) | Unknown/None | 2026-04-09 |
| CVE-2022-37055 | D-Link | Routers | D-Link Routers Buffer Overflow Vulnerability | 78 Urgent | 0.555 (99th pctl) | Unknown/None | 2025-12-29 |
| CVE-2023-49105 | ownCloud | ownCloud | ownCloud Improper Authentication Vulnerability | 78 Urgent | 0.432 (98.6th pctl) | Unknown/None | 2026-08-30 |
| CVE-2026-21962 | Oracle | HTTP Server and Oracle Weblogic Server Proxy Plug-in | Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability | 78 Urgent | 0.420 (98.6th pctl) | Unknown/None | 2026-08-27 |
| CVE-2023-36847 | Juniper | Junos OS | Juniper Junos OS EX Series Missing Authentication for Critical Function Vulnerability | 77 Urgent | 0.858 (99.71st pctl) | Unknown/None | 2023-11-17 |
| CVE-2022-23134 | Zabbix | Frontend | Zabbix Frontend Improper Access Control Vulnerability | 77 Urgent | 0.847 (99.69th pctl) | Unknown/None | 2022-03-08 |
| CVE-2018-18809 | TIBCO | JasperReports | TIBCO JasperReports Library Directory Traversal Vulnerability | 77 Urgent | 0.791 (99.57th pctl) | Unknown/None | 2023-01-19 |
| CVE-2018-8298 | ChakraCore | ChakraCore scripting engine | ChakraCore Scripting Engine Type Confusion Vulnerability | 77 Urgent | 0.748 (99.47th pctl) | Unknown/None | 2022-03-17 |
| CVE-2018-15811 | DotNetNuke (DNN) | DotNetNuke (DNN) | DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability | 77 Urgent | 0.740 (99.45th pctl) | Unknown/None | 2022-05-03 |
| CVE-2018-18325 | DotNetNuke (DNN) | DotNetNuke (DNN) | DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability | 77 Urgent | 0.740 (99.45th pctl) | Unknown/None | 2022-05-03 |
| CVE-2019-2215 | Android | Android Kernel | Android Kernel Use-After-Free Vulnerability | 77 Urgent | 0.721 (99.39th pctl) | Unknown/None | 2022-05-03 |
| CVE-2012-1535 | Adobe | Flash Player | Adobe Flash Player Arbitrary Code Execution Vulnerability | 77 Urgent | 0.704 (99.34th pctl) | Unknown/None | 2022-03-24 |
| CVE-2013-1690 | Mozilla | Firefox and Thunderbird | Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability | 77 Urgent | 0.690 (99.3rd pctl) | Unknown/None | 2022-04-18 |
| CVE-2015-8651 | Adobe | Flash Player | Adobe Flash Player Integer Overflow Vulnerability | 77 Urgent | 0.679 (99.27th pctl) | Unknown/None | 2022-06-15 |
| CVE-2016-4657 | Apple | iOS | Apple iOS Webkit Memory Corruption Vulnerability | 77 Urgent | 0.668 (99.24th pctl) | Unknown/None | 2022-06-14 |
| CVE-2018-4939 | Adobe | ColdFusion | Adobe ColdFusion Deserialization of Untrusted Data Vulnerability | 77 Urgent | 0.621 (99.12nd pctl) | Unknown/None | 2022-05-03 |
| CVE-2024-8956 | PTZOptics | PT30X-SDI/NDI Cameras | PTZOptics PT30X-SDI/NDI Cameras Authentication Bypass Vulnerability | 77 Urgent | 0.613 (99.1st pctl) | Unknown/None | 2024-11-25 |
| CVE-2021-22991 | F5 | BIG-IP Traffic Management Microkernel | F5 BIG-IP Traffic Management Microkernel Buffer Overflow | 77 Urgent | 0.611 (99.1st pctl) | Unknown/None | 2022-02-01 |
| CVE-2018-7445 | MikroTik | RouterOS | MikroTik RouterOS Stack-Based Buffer Overflow Vulnerability | 77 Urgent | 0.608 (99.09th pctl) | Unknown/None | 2022-09-29 |
| CVE-2026-18577 | N-able | N-central | N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability | 77 Urgent | 0.541 (98.9th pctl) | Unknown/None | 2026-08-06 |
| CVE-2021-22175 | GitLab | GitLab | GitLab Server-Side Request Forgery (SSRF) Vulnerability | 77 Urgent | 0.534 (98.9th pctl) | Unknown/None | 2026-03-11 |
Exactly the 1,308 advisory(ies) matching the filters above.
Advisory detail
Expand any advisory for its description, CISA's own required action, and research links.
CVE-2016-20017 — D-Link DSL-2750B Devices: D-Link DSL-2750B Devices Command Injection Vulnerability
D-Link DSL-2750B devices contain a command injection vulnerability that allows remote, unauthenticated command injection via the login.cgi cli parameter.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.652 (99.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-01-08
CISA remediation due: 2024-01-29
Known ransomware campaign use: Unknown/None
CVE-2022-21445 — Oracle ADF Faces: Oracle ADF Faces Deserialization of Untrusted Data Vulnerability
Oracle ADF Faces library, included with Oracle JDeveloper Distribution, contains a deserialization of untrusted data vulnerability leading to unauthenticated remote code execution.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.625 (99.13rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-09-18
CISA remediation due: 2024-10-09
Known ransomware campaign use: Unknown/None
CVE-2024-23113 — Fortinet Multiple Products: Fortinet Multiple Products Format String Vulnerability
Fortinet FortiOS, FortiPAM, FortiProxy, and FortiWeb contain a format string vulnerability that allows a remote, unauthenticated attacker to execute arbitrary code or commands via specially crafted requests.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.617 (99.11st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-10-09
CISA remediation due: 2024-10-30
Known ransomware campaign use: Unknown/None
CVE-2024-54085 — AMI MegaRAC SPx: AMI MegaRAC SPx Authentication Bypass by Spoofing Vulnerability
AMI MegaRAC SPx contains an authentication bypass by spoofing vulnerability in the Redfish Host Interface. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 10.0 (NVD)
FIRST EPSS: 0.607 (99.09th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-06-25
CISA remediation due: 2025-07-16
Known ransomware campaign use: Unknown/None
CVE-2026-33634 — Aquasecurity Trivy: Aquasecurity Trivy Embedded Malicious Code Vulnerability
Aquasecurity Trivy contains an embedded malicious code vulnerability that could allow an attacker to gain access to everything in the CI/CD environment, including all tokens, SSH keys, cloud credentials, database passwords, and any sensitive configuration in memory.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.4 (NVD)
FIRST EPSS: 0.592 (99.05th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-03-26
CISA remediation due: 2026-04-09
Known ransomware campaign use: Unknown/None
CVE-2022-37055 — D-Link Routers: D-Link Routers Buffer Overflow Vulnerability
D-Link Routers contains a buffer overflow vulnerability that has a high impact on confidentiality, integrity, and availability. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.555 (99th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-12-08
CISA remediation due: 2025-12-29
Known ransomware campaign use: Unknown/None
CVE-2023-49105 — ownCloud ownCloud: ownCloud Improper Authentication Vulnerability
ownCloud contains an improper authentication vulnerability that allows an attacker to access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.432 (98.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-08-27
CISA remediation due: 2026-08-30
Known ransomware campaign use: Unknown/None
CVE-2026-21962 — Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in: Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability
Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in contain an improper access control vulnerability that can result in unauthorized creation, deletion or modification access to critical data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in accessible data.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVSS: 10.0 (NVD)
FIRST EPSS: 0.420 (98.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-08-24
CISA remediation due: 2026-08-27
Known ransomware campaign use: Unknown/None
CVE-2023-36847 — Juniper Junos OS: Juniper Junos OS EX Series Missing Authentication for Critical Function Vulnerability
Juniper Junos OS on EX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to installAppPackage.php that doesn't require authentication, an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.858.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 5.3 (NVD)
FIRST EPSS: 0.858 (99.71st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-11-13
CISA remediation due: 2023-11-17
Known ransomware campaign use: Unknown/None
CVE-2022-23134 — Zabbix Frontend: Zabbix Frontend Improper Access Control Vulnerability
Malicious actors can pass step checks and potentially change the configuration of Zabbix Frontend.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.847.
CISA required action: Apply updates per vendor instructions.
CVSS: 5.3 (NVD)
FIRST EPSS: 0.847 (99.69th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-02-22
CISA remediation due: 2022-03-08
Known ransomware campaign use: Unknown/None
CVE-2018-18809 — TIBCO JasperReports: TIBCO JasperReports Library Directory Traversal Vulnerability
TIBCO JasperReports Library contains a directory-traversal vulnerability that may allow web server users to access contents of the host system.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.791.
CISA required action: Apply updates per vendor instructions.
CVSS: 6.5 (NVD)
FIRST EPSS: 0.791 (99.57th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-12-29
CISA remediation due: 2023-01-19
Known ransomware campaign use: Unknown/None
CVE-2018-8298 — ChakraCore ChakraCore scripting engine: ChakraCore Scripting Engine Type Confusion Vulnerability
The ChakraCore scripting engine contains a type confusion vulnerability which can allow for remote code execution.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.5 (NVD)
FIRST EPSS: 0.748 (99.47th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-03
CISA remediation due: 2022-03-17
Known ransomware campaign use: Unknown/None
CVE-2018-15811 — DotNetNuke (DNN) DotNetNuke (DNN): DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability
DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.5 (NVD)
FIRST EPSS: 0.740 (99.45th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2018-18325 — DotNetNuke (DNN) DotNetNuke (DNN): DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability
DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters. This CVE ID resolves an incomplete patch for CVE-2018-15811.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.5 (NVD)
FIRST EPSS: 0.740 (99.45th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2019-2215 — Android Android Kernel: Android Kernel Use-After-Free Vulnerability
Android Kernel contains a use-after-free vulnerability in binder.c that allows for privilege escalation from an application to the Linux Kernel. This vulnerability was observed chained with CVE-2020-0041 and CVE-2020-0069 under exploit chain "AbstractEmu."
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.721 (99.39th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2012-1535 — Adobe Flash Player: Adobe Flash Player Arbitrary Code Execution Vulnerability
Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute arbitrary code or cause a denial of service via crafted SWF content.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: The impacted product is end-of-life and should be disconnected if still in use.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.704 (99.34th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-03
CISA remediation due: 2022-03-24
Known ransomware campaign use: Unknown/None
CVE-2013-1690 — Mozilla Firefox and Thunderbird: Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability
Mozilla Firefox and Thunderbird do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial-of-service (DoS) or possibly execute malicious code via a crafted web site.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.690 (99.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-28
CISA remediation due: 2022-04-18
Known ransomware campaign use: Unknown/None
CVE-2015-8651 — Adobe Flash Player: Adobe Flash Player Integer Overflow Vulnerability
Integer overflow in Adobe Flash Player allows attackers to execute code.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: The impacted product is end-of-life and should be disconnected if still in use.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.679 (99.27th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-05-25
CISA remediation due: 2022-06-15
Known ransomware campaign use: Unknown/None
CVE-2016-4657 — Apple iOS: Apple iOS Webkit Memory Corruption Vulnerability
Apple iOS WebKit contains a memory corruption vulnerability that allows attackers to execute remote code or cause a denial-of-service (DoS) via a crafted web site. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.668 (99.24th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-05-24
CISA remediation due: 2022-06-14
Known ransomware campaign use: Unknown/None
CVE-2018-4939 — Adobe ColdFusion: Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
Adobe ColdFusion contains a deserialization of untrusted data vulnerability that could allow for code execution.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.621 (99.12nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2024-8956 — PTZOptics PT30X-SDI/NDI Cameras: PTZOptics PT30X-SDI/NDI Cameras Authentication Bypass Vulnerability
PTZOptics PT30X-SDI/NDI cameras contain an insecure direct object reference (IDOR) vulnerability that allows a remote, attacker to bypass authentication for the /cgi-bin/param.cgi CGI script. If combined with CVE-2024-8957, this can lead to remote code execution as root.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 9.1 (NVD)
FIRST EPSS: 0.613 (99.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-11-04
CISA remediation due: 2024-11-25
Known ransomware campaign use: Unknown/None
CVE-2021-22991 — F5 BIG-IP Traffic Management Microkernel: F5 BIG-IP Traffic Management Microkernel Buffer Overflow
The Traffic Management Microkernel of BIG-IP ASM Risk Engine has a buffer overflow vulnerability, leading to a bypassing of URL-based access controls.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.611 (99.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-01-18
CISA remediation due: 2022-02-01
Known ransomware campaign use: Unknown/None
CVE-2018-7445 — MikroTik RouterOS: MikroTik RouterOS Stack-Based Buffer Overflow Vulnerability
In MikroTik RouterOS, a stack-based buffer overflow occurs when processing NetBIOS session request messages. Remote attackers with access to the service can exploit this vulnerability and gain code execution on the system.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.608 (99.09th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-09-08
CISA remediation due: 2022-09-29
Known ransomware campaign use: Unknown/None
CVE-2026-18577 — N-able N-central: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for CVE-2026-18556.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVSS: 8.2 (NVD)
FIRST EPSS: 0.541 (98.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-08-03
CISA remediation due: 2026-08-06
Known ransomware campaign use: Unknown/None
CVE-2021-22175 — GitLab GitLab: GitLab Server-Side Request Forgery (SSRF) Vulnerability
GitLab contains a server-side request forgery (SSRF) vulnerability when requests to the internal network for webhooks are enabled.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.534 (98.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-02-18
CISA remediation due: 2026-03-11
Known ransomware campaign use: Unknown/None