Cross-Vendor Patch Advisories
Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.
Browse Advisories
1,308 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.
| CVE | Vendor | Product | Vulnerability | EVRS | EPSS | Ransomware | CISA due |
|---|---|---|---|---|---|---|---|
| CVE-2025-68461 | Roundcube | Webmail | RoundCube Webmail Cross-site Scripting Vulnerability | 75 Urgent | 0.268 (97.9th pctl) | Unknown/None | 2026-03-13 |
| CVE-2024-37085 | VMware | ESXi | VMware ESXi Authentication Bypass Vulnerability | 75 Urgent | 0.268 (97.9th pctl) | Known | 2024-08-20 |
| CVE-2021-21166 | Chromium | Google Chromium Race Condition Vulnerability | 75 Urgent | 0.265 (97.9th pctl) | Unknown/None | 2021-11-17 | |
| CVE-2025-14733 | WatchGuard | Firebox | WatchGuard Firebox Out of Bounds Write Vulnerability | 75 Urgent | 0.265 (97.9th pctl) | Unknown/None | 2025-12-26 |
| CVE-2020-8196 | Citrix | Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability | 75 Urgent | 0.263 (97.9th pctl) | Unknown/None | 2022-05-03 |
| CVE-2021-22506 | Micro Focus | Micro Focus Access Manager | Micro Focus Access Manager Information Leakage Vulnerability | 75 Urgent | 0.257 (97.8th pctl) | Unknown/None | 2021-11-17 |
| CVE-2015-2590 | Oracle | Java SE | Oracle Java SE and Java SE Embedded Remote Code Execution Vulnerability | 75 Urgent | 0.255 (97.8th pctl) | Unknown/None | 2022-03-24 |
| CVE-2018-6882 | Synacor | Zimbra Collaboration Suite (ZCS) | Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability | 75 Urgent | 0.254 (97.8th pctl) | Known | 2022-05-10 |
| CVE-2018-5002 | Adobe | Flash Player | Adobe Flash Player Stack-based Buffer Overflow Vulnerability | 75 Urgent | 0.254 (97.8th pctl) | Unknown/None | 2022-06-13 |
| CVE-2026-20245 | Cisco | Catalyst SD-WAN Manager | Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability | 75 Urgent | 0.253 (97.8th pctl) | Unknown/None | 2026-06-23 |
| CVE-2016-7855 | Adobe | Flash Player | Adobe Flash Player Use-After-Free Vulnerability | 75 Urgent | 0.252 (97.8th pctl) | Unknown/None | 2022-03-24 |
| CVE-2022-0185 | Linux | Kernel | Linux Kernel Heap-Based Buffer Overflow Vulnerability | 75 Urgent | 0.252 (97.8th pctl) | Unknown/None | 2024-09-11 |
| CVE-2019-18187 | Trend Micro | OfficeScan | Trend Micro OfficeScan Directory Traversal Vulnerability | 75 Urgent | 0.251 (97.8th pctl) | Unknown/None | 2022-05-03 |
| CVE-2009-1862 | Adobe | Acrobat and Reader, Flash Player | Adobe Acrobat and Reader, Flash Player Unspecified Vulnerability | 75 Urgent | 0.250 (97.8th pctl) | Unknown/None | 2022-06-22 |
| CVE-2022-3038 | Chromium Network Service | Google Chromium Network Service Use-After-Free Vulnerability | 75 Urgent | 0.247 (97.7th pctl) | Unknown/None | 2023-04-20 | |
| CVE-2026-20122 | Cisco | Catalyst SD-WAN Manger | Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability | 75 Urgent | 0.246 (97.7th pctl) | Unknown/None | 2026-04-23 |
| CVE-2023-28206 | Apple | iOS, iPadOS, and macOS | Apple iOS, iPadOS, and macOS IOSurfaceAccelerator Out-of-Bounds Write Vulnerability | 75 Urgent | 0.245 (97.7th pctl) | Unknown/None | 2023-05-01 |
| CVE-2022-1096 | Chromium V8 | Google Chromium V8 Type Confusion Vulnerability | 75 Urgent | 0.244 (97.7th pctl) | Unknown/None | 2022-04-18 | |
| CVE-2025-4632 | Samsung | MagicINFO 9 Server | Samsung MagicINFO 9 Server Path Traversal Vulnerability | 75 Urgent | 0.243 (97.7th pctl) | Unknown/None | 2025-06-12 |
| CVE-2014-0502 | Adobe | Flash Player | Adobe Flash Player Double Free Vulnerablity | 75 Urgent | 0.242 (97.7th pctl) | Unknown/None | 2024-10-08 |
| CVE-2021-27878 | Veritas | Backup Exec Agent | Veritas Backup Exec Agent Command Execution Vulnerability | 75 Urgent | 0.240 (97.7th pctl) | Known | 2023-04-28 |
| CVE-2018-19953 | QNAP | Network Attached Storage (NAS) | QNAP NAS File Station Cross-Site Scripting Vulnerability | 75 Urgent | 0.239 (97.7th pctl) | Known | 2022-06-14 |
| CVE-2016-9563 | SAP | NetWeaver | SAP NetWeaver XML External Entity (XXE) Vulnerability | 75 Urgent | 0.238 (97.7th pctl) | Unknown/None | 2022-05-03 |
| CVE-2023-32439 | Apple | Multiple Products | Apple Multiple Products WebKit Type Confusion Vulnerability | 75 Urgent | 0.238 (97.7th pctl) | Unknown/None | 2023-07-14 |
| CVE-2024-27443 | Synacor | Zimbra Collaboration Suite (ZCS) | Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability | 75 Urgent | 0.236 (97.6th pctl) | Unknown/None | 2025-06-09 |
Exactly the 1,308 advisory(ies) matching the filters above.
Advisory detail
Expand any advisory for its description, CISA's own required action, and research links.
CVE-2025-68461 — Roundcube Webmail: RoundCube Webmail Cross-site Scripting Vulnerability
RoundCube Webmail contains a cross-site scripting vulnerability via the animate tag in an SVG document.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 6.1 (NVD)
FIRST EPSS: 0.268 (97.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-02-20
CISA remediation due: 2026-03-13
Known ransomware campaign use: Unknown/None
CVE-2024-37085 — VMware ESXi: VMware ESXi Authentication Bypass Vulnerability
VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management by re-creating the configured AD group ('ESXi Admins' by default) after it was deleted from AD.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 7.2 (NVD)
FIRST EPSS: 0.268 (97.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-07-30
CISA remediation due: 2024-08-20
Known ransomware campaign use: Known
CVE-2021-21166 — Google Chromium: Google Chromium Race Condition Vulnerability
Google Chromium contains a race condition vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.265 (97.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2021-11-17
Known ransomware campaign use: Unknown/None
CVE-2025-14733 — WatchGuard Firebox: WatchGuard Firebox Out of Bounds Write Vulnerability
WatchGuard Fireware OS iked process contains an out of bounds write vulnerability in the OS iked process. This vulnerability may allow a remote unauthenticated attacker to execute arbitrary code and affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.3 (NVD)
FIRST EPSS: 0.265 (97.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-12-19
CISA remediation due: 2025-12-26
Known ransomware campaign use: Unknown/None
CVE-2020-8196 — Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance: Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability
Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an information disclosure vulnerability.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 4.3 (NVD)
FIRST EPSS: 0.263 (97.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2021-22506 — Micro Focus Micro Focus Access Manager: Micro Focus Access Manager Information Leakage Vulnerability
Micro Focus Access Manager contains an information leakage vulnerability resulting from a SAML service provider redirection issue when the Assertion Consumer Service URL is used.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.5 (NVD)
FIRST EPSS: 0.257 (97.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2021-11-17
Known ransomware campaign use: Unknown/None
CVE-2015-2590 — Oracle Java SE: Oracle Java SE and Java SE Embedded Remote Code Execution Vulnerability
An unspecified vulnerability exists within Oracle Java Runtime Environment that allows an attacker to perform remote code execution.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.255 (97.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-03
CISA remediation due: 2022-03-24
Known ransomware campaign use: Unknown/None
CVE-2018-6882 — Synacor Zimbra Collaboration Suite (ZCS): Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability
Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that might allow remote attackers to inject arbitrary web script or HTML.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 6.1 (NVD)
FIRST EPSS: 0.254 (97.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-04-19
CISA remediation due: 2022-05-10
Known ransomware campaign use: Known
CVE-2018-5002 — Adobe Flash Player: Adobe Flash Player Stack-based Buffer Overflow Vulnerability
Adobe Flash Player have a stack-based buffer overflow vulnerability that could lead to remote code execution.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: The impacted product is end-of-life and should be disconnected if still in use.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.254 (97.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-05-23
CISA remediation due: 2022-06-13
Known ransomware campaign use: Unknown/None
CVE-2026-20245 — Cisco Catalyst SD-WAN Manager: Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability
Cisco Catalyst SD-WAN Manager formerly SD-WAN vManage contains an improper encoding or escaping of output vulnerability. This vulnerability could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.253 (97.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-06-09
CISA remediation due: 2026-06-23
Known ransomware campaign use: Unknown/None
CVE-2016-7855 — Adobe Flash Player: Adobe Flash Player Use-After-Free Vulnerability
Use-after-free vulnerability in Adobe Flash Player Windows and OS and Linux allows remote attackers to execute arbitrary code.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: The impacted product is end-of-life and should be disconnected if still in use.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.252 (97.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-03
CISA remediation due: 2022-03-24
Known ransomware campaign use: Unknown/None
CVE-2022-0185 — Linux Kernel: Linux Kernel Heap-Based Buffer Overflow Vulnerability
Linux kernel contains a heap-based buffer overflow vulnerability in the legacy_parse_param function in the Filesystem Context functionality. This allows an attacker to open a filesystem that does not support the Filesystem Context API and ultimately escalate privileges.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.
CVSS: 8.4 (NVD)
FIRST EPSS: 0.252 (97.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-08-21
CISA remediation due: 2024-09-11
Known ransomware campaign use: Unknown/None
CVE-2019-18187 — Trend Micro OfficeScan: Trend Micro OfficeScan Directory Traversal Vulnerability
Trend Micro OfficeScan contains a directory traversal vulnerability by extracting files from a zip file to a specific folder on the OfficeScan server, leading to remote code execution.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.5 (NVD)
FIRST EPSS: 0.251 (97.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2009-1862 — Adobe Acrobat and Reader, Flash Player: Adobe Acrobat and Reader, Flash Player Unspecified Vulnerability
Adobe Acrobat and Reader and Adobe Flash Player allows remote attackers to execute code or cause denial-of-service (DoS).
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: For Adobe Acrobat and Reader, apply updates per vendor instructions. For Adobe Flash Player, the impacted product is end-of-life and should be disconnected if still in use.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.250 (97.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-06-08
CISA remediation due: 2022-06-22
Known ransomware campaign use: Unknown/None
CVE-2022-3038 — Google Chromium Network Service: Google Chromium Network Service Use-After-Free Vulnerability
Google Chromium Network Service contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.247 (97.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-03-30
CISA remediation due: 2023-04-20
Known ransomware campaign use: Unknown/None
CVE-2026-20122 — Cisco Catalyst SD-WAN Manger: Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability
Cisco Catalyst SD-WAN Manager contains an incorrect use of privileged APIs vulnerability due to improper file handling on the API interface of an affected system. An attacker could exploit this vulnerability by uploading a malicious file on the local file system. A successful exploit could allow the attacker to overwrite arbitrary files on the affected system and gain vmanage user privileges.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.
CVSS: 5.4 (NVD)
FIRST EPSS: 0.246 (97.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-04-20
CISA remediation due: 2026-04-23
Known ransomware campaign use: Unknown/None
CVE-2023-28206 — Apple iOS, iPadOS, and macOS: Apple iOS, iPadOS, and macOS IOSurfaceAccelerator Out-of-Bounds Write Vulnerability
Apple iOS, iPadOS, and macOS IOSurfaceAccelerator contain an out-of-bounds write vulnerability that allows an app to execute code with kernel privileges.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.6 (NVD)
FIRST EPSS: 0.245 (97.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-04-10
CISA remediation due: 2023-05-01
Known ransomware campaign use: Unknown/None
CVE-2022-1096 — Google Chromium V8: Google Chromium V8 Type Confusion Vulnerability
Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.244 (97.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-28
CISA remediation due: 2022-04-18
Known ransomware campaign use: Unknown/None
CVE-2025-4632 — Samsung MagicINFO 9 Server: Samsung MagicINFO 9 Server Path Traversal Vulnerability
Samsung MagicINFO 9 Server contains a path traversal vulnerability that allows an attacker to write arbitrary file as system authority.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.243 (97.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-05-22
CISA remediation due: 2025-06-12
Known ransomware campaign use: Unknown/None
CVE-2014-0502 — Adobe Flash Player: Adobe Flash Player Double Free Vulnerablity
Adobe Flash Player contains a double free vulnerability that allows a remote attacker to execute arbitrary code.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.242 (97.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-09-17
CISA remediation due: 2024-10-08
Known ransomware campaign use: Unknown/None
CVE-2021-27878 — Veritas Backup Exec Agent: Veritas Backup Exec Agent Command Execution Vulnerability
Veritas Backup Exec (BE) Agent contains a command execution vulnerability that could allow an attacker to use a data management protocol command to execute a command on the BE Agent machine.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.240 (97.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-04-07
CISA remediation due: 2023-04-28
Known ransomware campaign use: Known
CVE-2018-19953 — QNAP Network Attached Storage (NAS): QNAP NAS File Station Cross-Site Scripting Vulnerability
A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 6.1 (NVD)
FIRST EPSS: 0.239 (97.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-05-24
CISA remediation due: 2022-06-14
Known ransomware campaign use: Known
CVE-2016-9563 — SAP NetWeaver: SAP NetWeaver XML External Entity (XXE) Vulnerability
SAP NetWeaver Application Server Java Platforms contains an unspecified vulnerability in BC-BMT-BPM-DSK which allows remote, authenticated users to conduct XML External Entity (XXE) attacks.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 6.5 (NVD)
FIRST EPSS: 0.238 (97.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2023-32439 — Apple Multiple Products: Apple Multiple Products WebKit Type Confusion Vulnerability
Apple iOS, iPadOS, macOS, and Safari WebKit contain a type confusion vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.238 (97.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-06-23
CISA remediation due: 2023-07-14
Known ransomware campaign use: Unknown/None
CVE-2024-27443 — Synacor Zimbra Collaboration Suite (ZCS): Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability
Zimbra Collaboration contains a cross-site scripting (XSS) vulnerability in the CalendarInvite feature of the Zimbra webmail classic user interface. An attacker can exploit this vulnerability via an email message containing a crafted calendar header, leading to the execution of arbitrary JavaScript code.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 6.1 (NVD)
FIRST EPSS: 0.236 (97.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-05-19
CISA remediation due: 2025-06-09
Known ransomware campaign use: Unknown/None