Cross-Vendor Patch Advisories
Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.
Browse Advisories
1,308 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.
| CVE | Vendor | Product | Vulnerability | EVRS | EPSS | Ransomware | CISA due |
|---|---|---|---|---|---|---|---|
| CVE-2025-20352 | Cisco | IOS and IOS XE | Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability | 75 Urgent | 0.394 (98.5th pctl) | Unknown/None | 2025-10-20 |
| CVE-2021-26828 | OpenPLC | ScadaBR | OpenPLC ScadaBR Unrestricted Upload of File with Dangerous Type Vulnerability | 75 Urgent | 0.394 (98.5th pctl) | Unknown/None | 2025-12-24 |
| CVE-2019-3568 | Meta Platforms | WhatsApp VOIP Stack Buffer Overflow Vulnerability | 75 Urgent | 0.392 (98.5th pctl) | Unknown/None | 2022-05-10 | |
| CVE-2021-38003 | Chromium V8 | Google Chromium V8 Memory Corruption Vulnerability | 75 Urgent | 0.386 (98.5th pctl) | Unknown/None | 2021-11-17 | |
| CVE-2024-55550 | Mitel | MiCollab | Mitel MiCollab Path Traversal Vulnerability | 75 Urgent | 0.378 (98.4th pctl) | Known | 2025-01-28 |
| CVE-2018-13374 | Fortinet | FortiOS and FortiADC | Fortinet FortiOS and FortiADC Improper Access Control Vulnerability | 75 Urgent | 0.378 (98.4th pctl) | Known | 2022-09-29 |
| CVE-2019-11707 | Mozilla | Firefox and Thunderbird | Mozilla Firefox and Thunderbird Type Confusion Vulnerability | 75 Urgent | 0.377 (98.4th pctl) | Unknown/None | 2022-06-13 |
| CVE-2019-11001 | Reolink | Multiple IP Cameras | Reolink Multiple IP Cameras OS Command Injection Vulnerability | 75 Urgent | 0.375 (98.4th pctl) | Unknown/None | 2025-01-08 |
| CVE-2014-3153 | Linux | Kernel | Linux Kernel Privilege Escalation Vulnerability | 75 Urgent | 0.372 (98.4th pctl) | Unknown/None | 2022-06-15 |
| CVE-2017-16651 | Roundcube | Roundcube Webmail | Roundcube Webmail File Disclosure Vulnerability | 75 Urgent | 0.369 (98.4th pctl) | Unknown/None | 2022-05-03 |
| CVE-2008-0655 | Adobe | Acrobat and Reader | Adobe Acrobat and Reader Unspecified Vulnerability | 75 Urgent | 0.368 (98.4th pctl) | Unknown/None | 2022-06-22 |
| CVE-2019-19006 | Sangoma | FreePBX | Sangoma FreePBX Improper Authentication Vulnerability | 75 Urgent | 0.366 (98.4th pctl) | Unknown/None | 2026-02-24 |
| CVE-2018-4990 | Adobe | Acrobat and Reader | Adobe Acrobat and Reader Double Free Vulnerability | 75 Urgent | 0.366 (98.4th pctl) | Unknown/None | 2022-06-22 |
| CVE-2020-5735 | Amcrest | Cameras and Network Video Recorder (NVR) | Amcrest Cameras and NVR Stack-based Buffer Overflow Vulnerability | 75 Urgent | 0.362 (98.4th pctl) | Unknown/None | 2022-05-03 |
| CVE-2021-38163 | SAP | NetWeaver | SAP NetWeaver Unrestricted File Upload Vulnerability | 75 Urgent | 0.360 (98.4th pctl) | Unknown/None | 2022-06-30 |
| CVE-2022-22960 | VMware | Multiple Products | VMware Multiple Products Privilege Escalation Vulnerability | 75 Urgent | 0.358 (98.4th pctl) | Unknown/None | 2022-05-06 |
| CVE-2021-39935 | GitLab | Community and Enterprise Editions | GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability | 75 Urgent | 0.356 (98.3rd pctl) | Unknown/None | 2026-02-24 |
| CVE-2018-17480 | Chromium V8 | Google Chromium V8 Out-of-Bounds Write Vulnerability | 75 Urgent | 0.356 (98.3rd pctl) | Unknown/None | 2022-06-22 | |
| CVE-2020-13671 | Drupal | Drupal core | Drupal core Un-restricted Upload of File | 75 Urgent | 0.353 (98.3rd pctl) | Unknown/None | 2022-07-18 |
| CVE-2017-6327 | Symantec | Symantec Messaging Gateway | Symantec Messaging Gateway Remote Code Execution Vulnerability | 75 Urgent | 0.353 (98.3rd pctl) | Unknown/None | 2022-05-03 |
| CVE-2021-37975 | Chromium V8 | Google Chromium V8 Use-After-Free Vulnerability | 75 Urgent | 0.349 (98.3rd pctl) | Unknown/None | 2021-11-17 | |
| CVE-2016-5198 | Chromium V8 | Google Chromium V8 Out-of-Bounds Memory Vulnerability | 75 Urgent | 0.348 (98.3rd pctl) | Unknown/None | 2022-06-22 | |
| CVE-2010-5330 | Ubiquiti | AirOS | Ubiquiti AirOS Command Injection Vulnerability | 75 Urgent | 0.346 (98.3rd pctl) | Unknown/None | 2022-05-06 |
| CVE-2026-6973 | Ivanti | Endpoint Manager Mobile (EPMM) | Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability | 75 Urgent | 0.345 (98.3rd pctl) | Unknown/None | 2026-05-10 |
| CVE-2023-39780 | ASUS | RT-AX55 Routers | ASUS RT-AX55 Routers OS Command Injection Vulnerability | 75 Urgent | 0.339 (98.3rd pctl) | Unknown/None | 2025-06-23 |
Exactly the 1,308 advisory(ies) matching the filters above.
Advisory detail
Expand any advisory for its description, CISA's own required action, and research links.
CVE-2025-20352 — Cisco IOS and IOS XE: Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability
Cisco IOS and IOS XE contains a stack-based buffer overflow vulnerability in the Simple Network Management Protocol (SNMP) subsystem that could allow for denial of service or remote code execution. A successful exploit could allow a low-privileged attacker to cause the affected system to reload, resulting in a DoS condition, or allow a high-privileged attacker to execute arbitrary code as the root user and obtain full control of the affected system.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 7.7 (NVD)
FIRST EPSS: 0.394 (98.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-09-29
CISA remediation due: 2025-10-20
Known ransomware campaign use: Unknown/None
CVE-2021-26828 — OpenPLC ScadaBR: OpenPLC ScadaBR Unrestricted Upload of File with Dangerous Type Vulnerability
OpenPLC ScadaBR contains an unrestricted upload of file with dangerous type vulnerability that allows remote authenticated users to upload and execute arbitrary JSP files via view_edit.shtm.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.394 (98.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-12-03
CISA remediation due: 2025-12-24
Known ransomware campaign use: Unknown/None
CVE-2019-3568 — Meta Platforms WhatsApp: WhatsApp VOIP Stack Buffer Overflow Vulnerability
A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.392 (98.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-04-19
CISA remediation due: 2022-05-10
Known ransomware campaign use: Unknown/None
CVE-2021-38003 — Google Chromium V8: Google Chromium V8 Memory Corruption Vulnerability
Google Chromium V8 Engine has a bug in JSON.stringify, where the internal TheHole value can leak to script code, causing memory corruption. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.386 (98.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2021-11-17
Known ransomware campaign use: Unknown/None
CVE-2024-55550 — Mitel MiCollab: Mitel MiCollab Path Traversal Vulnerability
Mitel MiCollab contains a path traversal vulnerability that could allow an authenticated attacker with administrative privileges to read local files within the system due to insufficient input sanitization. This vulnerability can be chained with CVE-2024-41713, which allows an unauthenticated, remote attacker to read arbitrary files on the server.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 2.7 (NVD)
FIRST EPSS: 0.378 (98.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-01-07
CISA remediation due: 2025-01-28
Known ransomware campaign use: Known
CVE-2018-13374 — Fortinet FortiOS and FortiADC: Fortinet FortiOS and FortiADC Improper Access Control Vulnerability
Fortinet FortiOS and FortiADC contain an improper access control vulnerability that allows attackers to obtain the LDAP server login credentials configured in FortiGate by pointing a LDAP server connectivity test request to a rogue LDAP server.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 4.3 (NVD)
FIRST EPSS: 0.378 (98.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-09-08
CISA remediation due: 2022-09-29
Known ransomware campaign use: Known
CVE-2019-11707 — Mozilla Firefox and Thunderbird: Mozilla Firefox and Thunderbird Type Confusion Vulnerability
Mozilla Firefox and Thunderbird contain a type confusion vulnerability that can occur when manipulating JavaScript objects due to issues in Array.pop, allowing for an exploitable crash.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.377 (98.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-05-23
CISA remediation due: 2022-06-13
Known ransomware campaign use: Unknown/None
CVE-2019-11001 — Reolink Multiple IP Cameras: Reolink Multiple IP Cameras OS Command Injection Vulnerability
Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W IP cameras contain an authenticated OS command injection vulnerability. This vulnerability allows an authenticated admin to use the "TestEmail" functionality to inject and run OS commands as root.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.
CVSS: 7.2 (NVD)
FIRST EPSS: 0.375 (98.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-12-18
CISA remediation due: 2025-01-08
Known ransomware campaign use: Unknown/None
CVE-2014-3153 — Linux Kernel: Linux Kernel Privilege Escalation Vulnerability
The futex_requeue function in kernel/futex.c in Linux kernel does not ensure that calls have two different futex addresses, which allows local users to gain privileges.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.372 (98.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-05-25
CISA remediation due: 2022-06-15
Known ransomware campaign use: Unknown/None
CVE-2017-16651 — Roundcube Roundcube Webmail: Roundcube Webmail File Disclosure Vulnerability
Roundcube Webmail contains a file disclosure vulnerability caused by insufficient input validation in conjunction with file-based attachment plugins, which are used by default.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.369 (98.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2008-0655 — Adobe Acrobat and Reader: Adobe Acrobat and Reader Unspecified Vulnerability
Adobe Acrobat and Reader contains an unespecified vulnerability described as a design flaw which could allow a specially crafted file to be printed silently an arbitrary number of times.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.368 (98.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-06-08
CISA remediation due: 2022-06-22
Known ransomware campaign use: Unknown/None
CVE-2019-19006 — Sangoma FreePBX: Sangoma FreePBX Improper Authentication Vulnerability
Sangoma FreePBX contains an improper authentication vulnerability that potentially allows unauthorized users to bypass password authentication and access services provided by the FreePBX admin.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.366 (98.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-02-03
CISA remediation due: 2026-02-24
Known ransomware campaign use: Unknown/None
CVE-2018-4990 — Adobe Acrobat and Reader: Adobe Acrobat and Reader Double Free Vulnerability
Adobe Acrobat and Reader have a double free vulnerability that could lead to remote code execution.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.366 (98.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-06-08
CISA remediation due: 2022-06-22
Known ransomware campaign use: Unknown/None
CVE-2020-5735 — Amcrest Cameras and Network Video Recorder (NVR): Amcrest Cameras and NVR Stack-based Buffer Overflow Vulnerability
Amcrest cameras and NVR contain a stack-based buffer overflow vulnerability through port 37777 that allows an unauthenticated, remote attacker to crash the device and possibly execute code.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.362 (98.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2021-38163 — SAP NetWeaver: SAP NetWeaver Unrestricted File Upload Vulnerability
SAP NetWeaver contains a vulnerability that allows unrestricted file upload.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.360 (98.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-06-09
CISA remediation due: 2022-06-30
Known ransomware campaign use: Unknown/None
CVE-2022-22960 — VMware Multiple Products: VMware Multiple Products Privilege Escalation Vulnerability
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.358 (98.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-04-15
CISA remediation due: 2022-05-06
Known ransomware campaign use: Unknown/None
CVE-2021-39935 — GitLab Community and Enterprise Editions: GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability
GitLab Community and Enterprise Editions contain a server-side request forgery vulnerability which could allow unauthorized external users to perform Server Side Requests via the CI Lint API.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 7.5 (NVD)
FIRST EPSS: 0.356 (98.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-02-03
CISA remediation due: 2026-02-24
Known ransomware campaign use: Unknown/None
CVE-2018-17480 — Google Chromium V8: Google Chromium V8 Out-of-Bounds Write Vulnerability
Google Chromium V8 Engine contains out-of-bounds write vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.356 (98.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-06-08
CISA remediation due: 2022-06-22
Known ransomware campaign use: Unknown/None
CVE-2020-13671 — Drupal Drupal core: Drupal core Un-restricted Upload of File
Improper sanitization in the extension file names is present in Drupal core.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.353 (98.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-01-18
CISA remediation due: 2022-07-18
Known ransomware campaign use: Unknown/None
CVE-2017-6327 — Symantec Symantec Messaging Gateway: Symantec Messaging Gateway Remote Code Execution Vulnerability
Symantec Messaging Gateway contains an unspecified vulnerability which can allow for remote code execution. With the ability to perform remote code execution, an attacker may also desire to perform privilege escalating actions.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.353 (98.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2021-37975 — Google Chromium V8: Google Chromium V8 Use-After-Free Vulnerability
Google Chromium V8 Engine contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.349 (98.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2021-11-17
Known ransomware campaign use: Unknown/None
CVE-2016-5198 — Google Chromium V8: Google Chromium V8 Out-of-Bounds Memory Vulnerability
Google Chromium V8 Engine contains an out-of-bounds memory access vulnerability that allows a remote attacker to perform read/write operations, leading to code execution, via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.348 (98.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-06-08
CISA remediation due: 2022-06-22
Known ransomware campaign use: Unknown/None
CVE-2010-5330 — Ubiquiti AirOS: Ubiquiti AirOS Command Injection Vulnerability
Certain Ubiquiti devices contain a command injection vulnerability via a GET request to stainfo.cgi.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.346 (98.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-04-15
CISA remediation due: 2022-05-06
Known ransomware campaign use: Unknown/None
CVE-2026-6973 — Ivanti Endpoint Manager Mobile (EPMM): Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability
Ivanti Endpoint Manager Mobile (EPMM) contains an improper input validation vulnerability that allows a remotely authenticated user with administrative access to achieve remote code execution.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 7.2 (NVD)
FIRST EPSS: 0.345 (98.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-05-07
CISA remediation due: 2026-05-10
Known ransomware campaign use: Unknown/None
CVE-2023-39780 — ASUS RT-AX55 Routers: ASUS RT-AX55 Routers OS Command Injection Vulnerability
ASUS RT-AX55 devices contain an OS command injection vulnerability that could allow a remote, authenticated attacker to execute arbitrary commands. As represented by CVE-2023-41346.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.339 (98.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-06-02
CISA remediation due: 2025-06-23
Known ransomware campaign use: Unknown/None