Cross-Vendor Patch Advisories
Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.
Browse Advisories
1,308 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.
| CVE | Vendor | Product | Vulnerability | EVRS | EPSS | Ransomware | CISA due |
|---|---|---|---|---|---|---|---|
| CVE-2023-39780 | ASUS | RT-AX55 Routers | ASUS RT-AX55 Routers OS Command Injection Vulnerability | 75 Urgent | 0.339 (98.3rd pctl) | Unknown/None | 2025-06-23 |
| CVE-2008-4128 | Cisco | IOS | Cisco IOS Cross-Site Request Forgery Vulnerability | 75 Urgent | 0.337 (98.3rd pctl) | Unknown/None | 2026-07-16 |
| CVE-2018-13383 | Fortinet | FortiOS and FortiProxy | Fortinet FortiOS and FortiProxy Out-of-bounds Write | 75 Urgent | 0.336 (98.3rd pctl) | Known | 2022-07-10 |
| CVE-2013-5223 | D-Link | DSL-2760U | D-Link DSL-2760U Gateway Cross-Site Scripting Vulnerability | 75 Urgent | 0.336 (98.3rd pctl) | Unknown/None | 2022-04-15 |
| CVE-2025-9377 | TP-Link | Multiple Routers | TP-Link Archer C7(EU) and TL-WR841N/ND(MS) OS Command Injection Vulnerability | 75 Urgent | 0.335 (98.3rd pctl) | Unknown/None | 2025-09-24 |
| CVE-2020-2509 | QNAP | QNAP Network-Attached Storage (NAS) | QNAP Network-Attached Storage (NAS) Command Injection Vulnerability | 75 Urgent | 0.334 (98.3rd pctl) | Unknown/None | 2022-05-02 |
| CVE-2016-4655 | Apple | iOS | Apple iOS Information Disclosure Vulnerability | 75 Urgent | 0.334 (98.3rd pctl) | Unknown/None | 2022-06-14 |
| CVE-2020-8195 | Citrix | Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability | 75 Urgent | 0.333 (98.3rd pctl) | Unknown/None | 2022-05-03 |
| CVE-2025-21042 | Samsung | Mobile Devices | Samsung Mobile Devices Out-of-Bounds Write Vulnerability | 75 Urgent | 0.332 (98.2nd pctl) | Unknown/None | 2025-12-01 |
| CVE-2020-8218 | Pulse Secure | Pulse Connect Secure | Pulse Connect Secure Code Injection Vulnerability | 75 Urgent | 0.327 (98.2nd pctl) | Unknown/None | 2022-09-07 |
| CVE-2020-35730 | Roundcube | Roundcube Webmail | Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability | 75 Urgent | 0.327 (98.2nd pctl) | Unknown/None | 2023-07-13 |
| CVE-2021-30633 | Chromium Indexed DB API | Google Chromium Indexed DB API Use-After-Free Vulnerability | 75 Urgent | 0.327 (98.2nd pctl) | Unknown/None | 2021-11-17 | |
| CVE-2013-0641 | Adobe | Reader | Adobe Reader Buffer Overflow Vulnerability | 75 Urgent | 0.324 (98.2nd pctl) | Unknown/None | 2022-03-24 |
| CVE-2026-73570 | Synacor | Zimbra Collaboration Suite (ZCS) | Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability | 75 Urgent | 0.324 (98.2nd pctl) | Unknown/None | 2026-08-24 |
| CVE-2024-57968 | Advantive | VeraCore | Advantive VeraCore Unrestricted File Upload Vulnerability | 75 Urgent | 0.323 (98.2nd pctl) | Unknown/None | 2025-03-31 |
| CVE-2023-3079 | Chromium V8 | Google Chromium V8 Type Confusion Vulnerability | 75 Urgent | 0.321 (98.2nd pctl) | Unknown/None | 2023-06-28 | |
| CVE-2021-27852 | Checkbox | Checkbox Survey | Checkbox Survey Deserialization of Untrusted Data Vulnerability | 75 Urgent | 0.319 (98.2nd pctl) | Unknown/None | 2022-05-02 |
| CVE-2019-15752 | Docker | Desktop Community Edition | Docker Desktop Community Edition Privilege Escalation Vulnerability | 75 Urgent | 0.319 (98.2nd pctl) | Unknown/None | 2022-05-03 |
| CVE-2022-4135 | Chromium GPU | Google Chromium GPU Heap Buffer Overflow Vulnerability | 75 Urgent | 0.319 (98.2nd pctl) | Unknown/None | 2022-12-19 | |
| CVE-2026-0300 | Palo Alto Networks | PAN-OS | Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability | 75 Urgent | 0.317 (98.2nd pctl) | Unknown/None | 2026-05-09 |
| CVE-2022-40799 | D-Link | DNR-322L | D-Link DNR-322L Download of Code Without Integrity Check Vulnerability | 75 Urgent | 0.317 (98.2nd pctl) | Unknown/None | 2025-08-26 |
| CVE-2016-4523 | Trihedral | VTScada (formerly VTS) | Trihedral VTScada (formerly VTS) Denial-of-Service Vulnerability | 75 Urgent | 0.314 (98.2nd pctl) | Unknown/None | 2022-05-06 |
| CVE-2026-20133 | Cisco | Catalyst SD-WAN Manager | Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability | 75 Urgent | 0.314 (98.2nd pctl) | Unknown/None | 2026-04-23 |
| CVE-2025-0994 | Trimble | Cityworks | Trimble Cityworks Deserialization Vulnerability | 75 Urgent | 0.313 (98.2nd pctl) | Unknown/None | 2025-02-28 |
| CVE-2017-5070 | Chromium V8 | Google Chromium V8 Type Confusion Vulnerability | 75 Urgent | 0.312 (98.1st pctl) | Unknown/None | 2022-06-22 |
Exactly the 1,308 advisory(ies) matching the filters above.
Advisory detail
Expand any advisory for its description, CISA's own required action, and research links.
CVE-2023-39780 — ASUS RT-AX55 Routers: ASUS RT-AX55 Routers OS Command Injection Vulnerability
ASUS RT-AX55 devices contain an OS command injection vulnerability that could allow a remote, authenticated attacker to execute arbitrary commands. As represented by CVE-2023-41346.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.339 (98.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-06-02
CISA remediation due: 2025-06-23
Known ransomware campaign use: Unknown/None
CVE-2008-4128 — Cisco IOS: Cisco IOS Cross-Site Request Forgery Vulnerability
Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVSS: 4.3 (NVD)
FIRST EPSS: 0.337 (98.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-07-13
CISA remediation due: 2026-07-16
Known ransomware campaign use: Unknown/None
CVE-2018-13383 — Fortinet FortiOS and FortiProxy: Fortinet FortiOS and FortiProxy Out-of-bounds Write
A heap buffer overflow in Fortinet FortiOS and FortiProxy may cause the SSL VPN web service termination for logged in users.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 6.5 (NVD)
FIRST EPSS: 0.336 (98.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-01-10
CISA remediation due: 2022-07-10
Known ransomware campaign use: Known
CVE-2013-5223 — D-Link DSL-2760U: D-Link DSL-2760U Gateway Cross-Site Scripting Vulnerability
A cross-site scripting (XSS) vulnerability exists in the D-Link DSL-2760U gateway, allowing remote authenticated users to inject arbitrary web script or HTML.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 5.4 (NVD)
FIRST EPSS: 0.336 (98.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-25
CISA remediation due: 2022-04-15
Known ransomware campaign use: Unknown/None
CVE-2025-9377 — TP-Link Multiple Routers: TP-Link Archer C7(EU) and TL-WR841N/ND(MS) OS Command Injection Vulnerability
TP-Link Archer C7(EU) and TL-WR841N/ND(MS) contain an OS command injection vulnerability that exists in the Parental Control page. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 8.6 (NVD)
FIRST EPSS: 0.335 (98.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-09-03
CISA remediation due: 2025-09-24
Known ransomware campaign use: Unknown/None
CVE-2020-2509 — QNAP QNAP Network-Attached Storage (NAS): QNAP Network-Attached Storage (NAS) Command Injection Vulnerability
QNAP NAS devices contain a command injection vulnerability which could allow attackers to perform remote code execution.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.334 (98.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-04-11
CISA remediation due: 2022-05-02
Known ransomware campaign use: Unknown/None
CVE-2016-4655 — Apple iOS: Apple iOS Information Disclosure Vulnerability
The Apple iOS kernel allows attackers to obtain sensitive information from memory via a crafted application.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 5.5 (NVD)
FIRST EPSS: 0.334 (98.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-05-24
CISA remediation due: 2022-06-14
Known ransomware campaign use: Unknown/None
CVE-2020-8195 — Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance: Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability
Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an information disclosure vulnerability.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 6.5 (NVD)
FIRST EPSS: 0.333 (98.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2025-21042 — Samsung Mobile Devices: Samsung Mobile Devices Out-of-Bounds Write Vulnerability
Samsung mobile devices contain an out-of-bounds write vulnerability in libimagecodec.quram.so. This vulnerability could allow remote attackers to execute arbitrary code.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.332 (98.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-11-10
CISA remediation due: 2025-12-01
Known ransomware campaign use: Unknown/None
CVE-2020-8218 — Pulse Secure Pulse Connect Secure: Pulse Connect Secure Code Injection Vulnerability
A code injection vulnerability exists in Pulse Connect Secure that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.2 (NVD)
FIRST EPSS: 0.327 (98.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-07
CISA remediation due: 2022-09-07
Known ransomware campaign use: Unknown/None
CVE-2020-35730 — Roundcube Roundcube Webmail: Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability
Roundcube Webmail contains a cross-site scripting (XSS) vulnerability that allows an attacker to send a plain text e-mail message with Javascript in a link reference element that is mishandled by linkref_addinindex in rcube_string_replacer.php.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 6.1 (NVD)
FIRST EPSS: 0.327 (98.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-06-22
CISA remediation due: 2023-07-13
Known ransomware campaign use: Unknown/None
CVE-2021-30633 — Google Chromium Indexed DB API: Google Chromium Indexed DB API Use-After-Free Vulnerability
Google Chromium Indexed DB API contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.6 (NVD)
FIRST EPSS: 0.327 (98.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2021-11-17
Known ransomware campaign use: Unknown/None
CVE-2013-0641 — Adobe Reader: Adobe Reader Buffer Overflow Vulnerability
A buffer overflow vulnerability exists in Adobe Reader which allows an attacker to perform remote code execution.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.324 (98.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-03
CISA remediation due: 2022-03-24
Known ransomware campaign use: Unknown/None
CVE-2026-73570 — Synacor Zimbra Collaboration Suite (ZCS): Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability
Zimbra Collaboration Suite (ZCS) contains an OS command injection vulnerability which could allow an unauthenticated attacker to send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVSS: 8.9 (NVD)
FIRST EPSS: 0.324 (98.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-08-21
CISA remediation due: 2026-08-24
Known ransomware campaign use: Unknown/None
CVE-2024-57968 — Advantive VeraCore: Advantive VeraCore Unrestricted File Upload Vulnerability
Advantive VeraCore contains an unrestricted file upload vulnerability that allows a remote unauthenticated attacker to upload files to unintended folders via upload.apsx.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.323 (98.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-03-10
CISA remediation due: 2025-03-31
Known ransomware campaign use: Unknown/None
CVE-2023-3079 — Google Chromium V8: Google Chromium V8 Type Confusion Vulnerability
Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.321 (98.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-06-07
CISA remediation due: 2023-06-28
Known ransomware campaign use: Unknown/None
CVE-2021-27852 — Checkbox Checkbox Survey: Checkbox Survey Deserialization of Untrusted Data Vulnerability
Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute arbitrary code.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Versions 6 and earlier for this product are end-of-life and must be removed from agency networks. Versions 7 and later are not considered vulnerable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.319 (98.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-04-11
CISA remediation due: 2022-05-02
Known ransomware campaign use: Unknown/None
CVE-2019-15752 — Docker Desktop Community Edition: Docker Desktop Community Edition Privilege Escalation Vulnerability
Docker Desktop Community Edition contains a vulnerability that may allow local users to escalate privileges by placing a trojan horse docker-credential-wincred.exe file in %PROGRAMDATA%\DockerDesktop\version-bin\.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.319 (98.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2022-4135 — Google Chromium GPU: Google Chromium GPU Heap Buffer Overflow Vulnerability
Google Chromium GPU contains a heap buffer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.6 (NVD)
FIRST EPSS: 0.319 (98.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-11-28
CISA remediation due: 2022-12-19
Known ransomware campaign use: Unknown/None
CVE-2026-0300 — Palo Alto Networks PAN-OS: Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability
Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Until the vendor releases an official fix, the following workaround should be implemented: - Restrict User-ID Authentication Portal access to only trusted zones. - Disable User-ID Authentication Portal if not required. 5/13/2026: Palo Alto has released a variety of patches. If these are relevant to your environment, please apply the designated patch.
CVSS: 9.3 (NVD)
FIRST EPSS: 0.317 (98.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-05-06
CISA remediation due: 2026-05-09
Known ransomware campaign use: Unknown/None
CVE-2022-40799 — D-Link DNR-322L: D-Link DNR-322L Download of Code Without Integrity Check Vulnerability
D-Link DNR-322L contains a download of code without integrity check vulnerability that could allow an authenticated attacker to execute OS level commands on the device. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.317 (98.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-08-05
CISA remediation due: 2025-08-26
Known ransomware campaign use: Unknown/None
CVE-2016-4523 — Trihedral VTScada (formerly VTS): Trihedral VTScada (formerly VTS) Denial-of-Service Vulnerability
The WAP interface in Trihedral VTScada (formerly VTS) allows remote attackers to cause a denial-of-service (DoS).
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.5 (NVD)
FIRST EPSS: 0.314 (98.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-04-15
CISA remediation due: 2022-05-06
Known ransomware campaign use: Unknown/None
CVE-2026-20133 — Cisco Catalyst SD-WAN Manager: Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
Cisco Catalyst SD-WAN Manager contains an exposure of sensitive information to an unauthorized actor vulnerability that could allow remote attackers to view sensitive information on affected systems.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.
CVSS: 7.5 (NVD)
FIRST EPSS: 0.314 (98.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-04-20
CISA remediation due: 2026-04-23
Known ransomware campaign use: Unknown/None
CVE-2025-0994 — Trimble Cityworks: Trimble Cityworks Deserialization Vulnerability
Trimble Cityworks contains a deserialization vulnerability. This could allow an authenticated user to perform a remote code execution attack against a customer's Microsoft Internet Information Services (IIS) web server.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 8.6 (NVD)
FIRST EPSS: 0.313 (98.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-02-07
CISA remediation due: 2025-02-28
Known ransomware campaign use: Unknown/None
CVE-2017-5070 — Google Chromium V8: Google Chromium V8 Type Confusion Vulnerability
Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.312 (98.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-06-08
CISA remediation due: 2022-06-22
Known ransomware campaign use: Unknown/None