Cross-Vendor Patch Advisories

Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.

Browse Advisories

Association
Vendor — all

Leave every box clear to show all 282 vendors.

1,308 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.

CISA KEV advisories matching the current filters, ranked by EVULNABLE Risk Score
CVE Vendor Product Vulnerability EVRS EPSS Ransomware CISA due
CVE-2021-22986 F5 BIG-IP and BIG-IQ Centralized Management F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution Vulnerability 94 Immediate 0.999 (99.96th pctl) Known 2021-11-17
CVE-2021-21972 VMware vCenter Server VMware vCenter Server Remote Code Execution Vulnerability 94 Immediate 0.999 (99.96th pctl) Known 2021-11-17
CVE-2019-11043 PHP FastCGI Process Manager (FPM) PHP FastCGI Process Manager (FPM) Buffer Overflow Vulnerability 94 Immediate 0.998 (99.95th pctl) Known 2022-04-15
CVE-2019-15107 Webmin Webmin Webmin Command Injection Vulnerability 94 Immediate 0.998 (99.95th pctl) Known 2022-04-15
CVE-2022-47966 Zoho ManageEngine Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability 94 Immediate 0.998 (99.95th pctl) Known 2023-02-13
CVE-2023-3519 Citrix NetScaler ADC and NetScaler Gateway Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability 94 Immediate 0.997 (99.95th pctl) Known 2023-08-09
CVE-2019-18935 Progress Telerik UI for ASP.NET AJAX Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability 94 Immediate 0.997 (99.95th pctl) Known 2022-05-03
CVE-2021-22205 GitLab Community and Enterprise Editions GitLab Community and Enterprise Editions Remote Code Execution Vulnerability 94 Immediate 0.997 (99.95th pctl) Known 2021-11-17
CVE-2023-46604 Apache ActiveMQ Apache ActiveMQ Deserialization of Untrusted Data Vulnerability 94 Immediate 0.997 (99.95th pctl) Known 2023-11-23
CVE-2010-2861 Adobe ColdFusion Adobe ColdFusion Directory Traversal Vulnerability 94 Immediate 0.997 (99.95th pctl) Known 2022-04-15
CVE-2024-0012 Palo Alto Networks PAN-OS Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability 94 Immediate 0.997 (99.95th pctl) Known 2024-12-09
CVE-2022-42475 Fortinet FortiOS Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability 94 Immediate 0.995 (99.94th pctl) Known 2023-01-03
CVE-2024-23692 Rejetto HTTP File Server Rejetto HTTP File Server Improper Neutralization of Special Elements Used in a Template Engine Vulnerability 94 Immediate 0.995 (99.94th pctl) Known 2024-07-30
CVE-2017-7494 Samba Samba Samba Remote Code Execution Vulnerability 94 Immediate 0.994 (99.94th pctl) Known 2023-04-20
CVE-2018-7602 Drupal Core Drupal Core Remote Code Execution Vulnerability 94 Immediate 0.992 (99.93rd pctl) Known 2022-05-04
CVE-2023-22515 Atlassian Confluence Data Center and Server Atlassian Confluence Data Center and Server Broken Access Control Vulnerability 94 Immediate 0.992 (99.93rd pctl) Known 2023-10-13
CVE-2024-50623 Cleo Multiple Products Cleo Multiple Products Unrestricted File Upload Vulnerability 94 Immediate 0.986 (99.92nd pctl) Known 2025-01-03
CVE-2024-55591 Fortinet FortiOS and FortiProxy Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability 94 Immediate 0.983 (99.91st pctl) Known 2025-01-21
CVE-2025-26399 SolarWinds Web Help Desk SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability 94 Immediate 0.895 (99.78th pctl) Known 2026-03-12
CVE-2026-1731 BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability 94 Immediate 0.894 (99.77th pctl) Known 2026-02-16
CVE-2026-15409 SonicWall SMA1000 Appliances SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability 94 Immediate 0.837 (99.67th pctl) Known 2026-07-17
CVE-2021-40438 Apache Apache Apache HTTP Server-Side Request Forgery (SSRF) 93 Immediate 0.999 (99.99th pctl) Known 2021-12-15
CVE-2024-21887 Ivanti Connect Secure and Policy Secure Ivanti Connect Secure and Policy Secure Command Injection Vulnerability 93 Immediate 0.999 (99.99th pctl) Known 2024-01-22
CVE-2024-27199 JetBrains TeamCity JetBrains TeamCity Relative Path Traversal Vulnerability 93 Immediate 0.999 (99.98th pctl) Known 2026-05-04
CVE-2021-45046 Apache Log4j2 Apache Log4j2 Deserialization of Untrusted Data Vulnerability 93 Immediate 0.999 (99.98th pctl) Known 2023-05-22
Download filtered advisories (CSV)

Exactly the 1,308 advisory(ies) matching the filters above.

Advisory detail

Expand any advisory for its description, CISA's own required action, and research links.

CVE-2021-22986 — F5 BIG-IP and BIG-IQ Centralized Management: F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution Vulnerability

F5 BIG-IP and BIG-IQ Centralized Management contain a remote code execution vulnerability in the iControl REST interface that allows unauthenticated attackers with network access to execute system commands, create or delete files, and disable services.

EVULNABLE Risk · priority 94/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.999 (99.96th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2021-11-17

Known ransomware campaign use: Known

CVE-2021-21972 — VMware vCenter Server: VMware vCenter Server Remote Code Execution Vulnerability

VMware vCenter Server vSphere Client contains a remote code execution vulnerability in a vCenter Server plugin which allows an attacker with network access to port 443 to execute commands with unrestricted privileges on the underlying operating system.

EVULNABLE Risk · priority 94/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.999 (99.96th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2021-11-17

Known ransomware campaign use: Known

CVE-2019-11043 — PHP FastCGI Process Manager (FPM): PHP FastCGI Process Manager (FPM) Buffer Overflow Vulnerability

In some versions of PHP in certain configurations of FPM setup, it is possible to cause FPM module to write past allocated buffers allowing the possibility of remote code execution.

EVULNABLE Risk · priority 94/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.998.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.998 (99.95th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-25

CISA remediation due: 2022-04-15

Known ransomware campaign use: Known

CVE-2019-15107 — Webmin Webmin: Webmin Command Injection Vulnerability

An issue was discovered in Webmin. The parameter old in password_change.cgi contains a command injection vulnerability.

EVULNABLE Risk · priority 94/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.998.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.998 (99.95th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-25

CISA remediation due: 2022-04-15

Known ransomware campaign use: Known

CVE-2022-47966 — Zoho ManageEngine: Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability

Multiple Zoho ManageEngine products contain an unauthenticated remote code execution vulnerability due to the usage of an outdated third-party dependency, Apache Santuario.

EVULNABLE Risk · priority 94/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.998.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.998 (99.95th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-01-23

CISA remediation due: 2023-02-13

Known ransomware campaign use: Known

CVE-2023-3519 — Citrix NetScaler ADC and NetScaler Gateway: Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability

Citrix NetScaler ADC and NetScaler Gateway contains a code injection vulnerability that allows for unauthenticated remote code execution.

EVULNABLE Risk · priority 94/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.997.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.997 (99.95th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-07-19

CISA remediation due: 2023-08-09

Known ransomware campaign use: Known

CVE-2019-18935 — Progress Telerik UI for ASP.NET AJAX: Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability

Progress Telerik UI for ASP.NET AJAX contains a deserialization of untrusted data vulnerability through RadAsyncUpload which leads to code execution on the server in the context of the w3wp.exe process.

EVULNABLE Risk · priority 94/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.997.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.997 (99.95th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Known

CVE-2021-22205 — GitLab Community and Enterprise Editions: GitLab Community and Enterprise Editions Remote Code Execution Vulnerability

GitHub Community and Enterprise Editions that utilize the ability to upload images through GitLab Workhorse are vulnerable to remote code execution. Workhorse passes image file extensions through ExifTool, which improperly validates the image files.

EVULNABLE Risk · priority 94/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.997.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 10.0 (NVD)

FIRST EPSS: 0.997 (99.95th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2021-11-17

Known ransomware campaign use: Known

CVE-2023-46604 — Apache ActiveMQ: Apache ActiveMQ Deserialization of Untrusted Data Vulnerability

Apache ActiveMQ contains a deserialization of untrusted data vulnerability that may allow a remote attacker with network access to a broker to run shell commands by manipulating serialized class types in the OpenWire protocol to cause the broker to instantiate any class on the classpath.

EVULNABLE Risk · priority 94/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.997.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.997 (99.95th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-11-02

CISA remediation due: 2023-11-23

Known ransomware campaign use: Known

CVE-2010-2861 — Adobe ColdFusion: Adobe ColdFusion Directory Traversal Vulnerability

A directory traversal vulnerability exists in the administrator console in Adobe ColdFusion which allows remote attackers to read arbitrary files.

EVULNABLE Risk · priority 94/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.997.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.997 (99.95th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-25

CISA remediation due: 2022-04-15

Known ransomware campaign use: Known

CVE-2024-0012 — Palo Alto Networks PAN-OS: Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability

Palo Alto Networks PAN-OS contains an authentication bypass vulnerability in the web-based management interface for several PAN-OS products, including firewalls and VPN concentrators.

EVULNABLE Risk · priority 94/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.997.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Additionally, management interface for affected devices should not be exposed to untrusted networks, including the internet.

CVSS: 9.3 (NVD)

FIRST EPSS: 0.997 (99.95th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-11-18

CISA remediation due: 2024-12-09

Known ransomware campaign use: Known

CVE-2022-42475 — Fortinet FortiOS: Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability

Multiple versions of Fortinet FortiOS SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker to execute arbitrary code or commands via specifically crafted requests.

EVULNABLE Risk · priority 94/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.995.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.995 (99.94th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-12-13

CISA remediation due: 2023-01-03

Known ransomware campaign use: Known

CVE-2024-23692 — Rejetto HTTP File Server: Rejetto HTTP File Server Improper Neutralization of Special Elements Used in a Template Engine Vulnerability

Rejetto HTTP File Server contains an improper neutralization of special elements used in a template engine vulnerability. This allows a remote, unauthenticated attacker to execute commands on the affected system by sending a specially crafted HTTP request.

EVULNABLE Risk · priority 94/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.995.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.995 (99.94th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-07-09

CISA remediation due: 2024-07-30

Known ransomware campaign use: Known

CVE-2017-7494 — Samba Samba: Samba Remote Code Execution Vulnerability

Samba contains a remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share and then cause the server to load and execute it.

EVULNABLE Risk · priority 94/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.994.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.994 (99.94th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-03-30

CISA remediation due: 2023-04-20

Known ransomware campaign use: Known

CVE-2018-7602 — Drupal Core: Drupal Core Remote Code Execution Vulnerability

A remote code execution vulnerability exists within multiple subsystems of Drupal that can allow attackers to exploit multiple attack vectors on a Drupal site.

EVULNABLE Risk · priority 94/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.992.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.992 (99.93rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-04-13

CISA remediation due: 2022-05-04

Known ransomware campaign use: Known

CVE-2023-22515 — Atlassian Confluence Data Center and Server: Atlassian Confluence Data Center and Server Broken Access Control Vulnerability

Atlassian Confluence Data Center and Server contains a broken access control vulnerability that allows an attacker to create unauthorized Confluence administrator accounts and access Confluence.

EVULNABLE Risk · priority 94/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.992.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Check all affected Confluence instances for evidence of compromise per vendor instructions and report any positive findings to CISA.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.992 (99.93rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-10-05

CISA remediation due: 2023-10-13

Known ransomware campaign use: Known

CVE-2024-50623 — Cleo Multiple Products: Cleo Multiple Products Unrestricted File Upload Vulnerability

Cleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload and download vulnerability that can lead to remote code execution with elevated privileges.

EVULNABLE Risk · priority 94/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.986.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.986 (99.92nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-12-13

CISA remediation due: 2025-01-03

Known ransomware campaign use: Known

CVE-2024-55591 — Fortinet FortiOS and FortiProxy: Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability

Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that may allow an unauthenticated, remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.

EVULNABLE Risk · priority 94/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.983.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.983 (99.91st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-01-14

CISA remediation due: 2025-01-21

Known ransomware campaign use: Known

CVE-2025-26399 — SolarWinds Web Help Desk: SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability

SolarWinds Web Help Desk contain a deserialization of untrusted data vulnerability in AjaxProxy that could allow an attacker to run commands on the host machine.

EVULNABLE Risk · priority 94/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.895.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.895 (99.78th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-03-09

CISA remediation due: 2026-03-12

Known ransomware campaign use: Known

CVE-2026-1731 — BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA): BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability

BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)contain an OS command injection vulnerability. Successful exploitation could allow an unauthenticated remote attacker to execute operating system commands in the context of the site user. Successful exploitation requires no authentication or user interaction and may lead to system compromise, including unauthorized access, data exfiltration, and service disruption.

EVULNABLE Risk · priority 94/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.894.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 9.9 (NVD)

FIRST EPSS: 0.894 (99.77th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-02-13

CISA remediation due: 2026-02-16

Known ransomware campaign use: Known

CVE-2026-15409 — SonicWall SMA1000 Appliances: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability

SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.

EVULNABLE Risk · priority 94/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.837.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVSS: 10.0 (NVD)

FIRST EPSS: 0.837 (99.67th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-07-14

CISA remediation due: 2026-07-17

Known ransomware campaign use: Known

CVE-2021-40438 — Apache Apache: Apache HTTP Server-Side Request Forgery (SSRF)

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.

EVULNABLE Risk · priority 93/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.0 (NVD)

FIRST EPSS: 0.999 (99.99th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-12-01

CISA remediation due: 2021-12-15

Known ransomware campaign use: Known

CVE-2024-21887 — Ivanti Connect Secure and Policy Secure: Ivanti Connect Secure and Policy Secure Command Injection Vulnerability

Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure contain a command injection vulnerability in the web components of these products, which can allow an authenticated administrator to send crafted requests to execute code on affected appliances. This vulnerability can be leveraged in conjunction with CVE-2023-46805, an authenticated bypass issue.

EVULNABLE Risk · priority 93/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 9.1 (NVD)

FIRST EPSS: 0.999 (99.99th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-01-10

CISA remediation due: 2024-01-22

Known ransomware campaign use: Known

CVE-2024-27199 — JetBrains TeamCity: JetBrains TeamCity Relative Path Traversal Vulnerability

JetBrains TeamCity contains a relative path traversal vulnerability that could allow limited admin actions to be performed.

EVULNABLE Risk · priority 93/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch Immediately

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 7.3 (NVD)

FIRST EPSS: 0.999 (99.98th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-04-20

CISA remediation due: 2026-05-04

Known ransomware campaign use: Known

CVE-2021-45046 — Apache Log4j2: Apache Log4j2 Deserialization of Untrusted Data Vulnerability

Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations.

EVULNABLE Risk · priority 93/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.0 (NVD)

FIRST EPSS: 0.999 (99.98th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-05-01

CISA remediation due: 2023-05-22

Known ransomware campaign use: Known

Data sources & attribution

Known-exploitation status, required actions, ransomware association and remediation deadlines come from the CISA Known Exploited Vulnerabilities Catalog. Exploitation probability and percentile are provided by FIRST.org's EPSS, used under FIRST's open data terms.

Microsoft Patch Tuesday data is sourced from the Microsoft Security Update Guide; lifecycle milestones from endoflife.date. Linux distribution advisories come from Red Hat, Ubuntu and Debian; vendor bulletins from Adobe, Apple, Chrome, Cisco, Ivanti and Oracle, each linked to its own advisory.