Cross-Vendor Patch Advisories
Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.
Browse Advisories
1,308 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.
| CVE | Vendor | Product | Vulnerability | EVRS | EPSS | Ransomware | CISA due |
|---|---|---|---|---|---|---|---|
| CVE-2016-4656 | Apple | iOS | Apple iOS Memory Corruption Vulnerability | 75 Urgent | 0.236 (97.6th pctl) | Unknown/None | 2022-06-14 |
| CVE-2021-22899 | Ivanti | Pulse Connect Secure | Ivanti Pulse Connect Secure Command Injection Vulnerability | 75 Urgent | 0.229 (97.6th pctl) | Unknown/None | 2022-05-03 |
| CVE-2023-32435 | Apple | Multiple Products | Apple Multiple Products WebKit Memory Corruption Vulnerability | 75 Urgent | 0.228 (97.6th pctl) | Unknown/None | 2023-07-14 |
| CVE-2025-14174 | Chromium | Google Chromium Out of Bounds Memory Access Vulnerability | 75 Urgent | 0.226 (97.6th pctl) | Unknown/None | 2026-01-02 | |
| CVE-2024-44309 | Apple | Multiple Products | Apple Multiple Products Cross-Site Scripting (XSS) Vulnerability | 75 Urgent | 0.226 (97.6th pctl) | Unknown/None | 2024-12-12 |
| CVE-2016-6367 | Cisco | Adaptive Security Appliance (ASA) | Cisco Adaptive Security Appliance (ASA) CLI Remote Code Execution Vulnerability | 75 Urgent | 0.226 (97.6th pctl) | Unknown/None | 2022-06-14 |
| CVE-2014-0196 | Linux | Kernel | Linux Kernel Race Condition Vulnerability | 75 Urgent | 0.225 (97.5th pctl) | Unknown/None | 2023-06-02 |
| CVE-2015-5317 | Jenkins | Jenkins User Interface (UI) | Jenkins User Interface (UI) Information Disclosure Vulnerability | 75 Urgent | 0.224 (97.5th pctl) | Unknown/None | 2023-06-02 |
| CVE-2024-37079 | Broadcom | VMware vCenter Server | Broadcom VMware vCenter Server Out-of-bounds Write Vulnerability | 75 Urgent | 0.224 (97.5th pctl) | Unknown/None | 2026-02-13 |
| CVE-2014-0546 | Adobe | Reader and Acrobat | Adobe Reader and Acrobat Sandbox Bypass Vulnerability | 75 Urgent | 0.223 (97.5th pctl) | Unknown/None | 2022-06-15 |
| CVE-2022-0609 | Chromium Animation | Google Chromium Animation Use-After-Free Vulnerability | 75 Urgent | 0.223 (97.5th pctl) | Unknown/None | 2022-03-01 | |
| CVE-2024-40890 | Zyxel | DSL CPE Devices | Zyxel DSL CPE OS Command Injection Vulnerability | 75 Urgent | 0.223 (97.5th pctl) | Unknown/None | 2025-03-04 |
| CVE-2021-3560 | Red Hat | Polkit | Red Hat Polkit Incorrect Authorization Vulnerability | 75 Urgent | 0.222 (97.5th pctl) | Unknown/None | 2023-06-02 |
| CVE-2026-2441 | Chromium | Google Chromium CSS Use-After-Free Vulnerability | 75 Urgent | 0.220 (97.5th pctl) | Unknown/None | 2026-03-10 | |
| CVE-2020-27930 | Apple | Multiple Products | Apple Multiple Products Memory Corruption Vulnerability | 75 Urgent | 0.220 (97.5th pctl) | Unknown/None | 2022-05-03 |
| CVE-2025-43300 | Apple | iOS, iPadOS, and macOS | Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability | 75 Urgent | 0.220 (97.5th pctl) | Unknown/None | 2025-09-11 |
| CVE-2025-23209 | Craft CMS | Craft CMS | Craft CMS Code Injection Vulnerability | 75 Urgent | 0.218 (97.5th pctl) | Unknown/None | 2025-03-13 |
| CVE-2024-40891 | Zyxel | DSL CPE Devices | Zyxel DSL CPE OS Command Injection Vulnerability | 75 Urgent | 0.215 (97.5th pctl) | Unknown/None | 2025-03-04 |
| CVE-2017-6742 | Cisco | IOS and IOS XE Software | Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability | 75 Urgent | 0.214 (97.4th pctl) | Unknown/None | 2023-05-10 |
| CVE-2020-9377 | D-Link | DIR-610 Devices | D-Link DIR-610 Devices Remote Command Execution | 75 Urgent | 0.213 (97.4th pctl) | Unknown/None | 2022-04-15 |
| CVE-2012-5054 | Adobe | Flash Player | Adobe Flash Player Integer Overflow Vulnerability | 75 Urgent | 0.212 (97.4th pctl) | Unknown/None | 2022-06-22 |
| CVE-2025-54948 | Trend Micro | Apex One | Trend Micro Apex One OS Command Injection Vulnerability | 75 Urgent | 0.208 (97.4th pctl) | Unknown/None | 2025-09-08 |
| CVE-2024-7971 | Chromium V8 | Google Chromium V8 Type Confusion Vulnerability | 75 Urgent | 0.207 (97.4th pctl) | Unknown/None | 2024-09-16 | |
| CVE-2020-24363 | TP-Link | TL-WA855RE | TP-link TL-WA855RE Missing Authentication for Critical Function Vulnerability | 75 Urgent | 0.207 (97.4th pctl) | Unknown/None | 2025-09-23 |
| CVE-2014-9163 | Adobe | Flash Player | Adobe Flash Player Stack-Based Buffer Overflow Vulnerability | 75 Urgent | 0.204 (97.3rd pctl) | Unknown/None | 2022-05-04 |
Exactly the 1,308 advisory(ies) matching the filters above.
Advisory detail
Expand any advisory for its description, CISA's own required action, and research links.
CVE-2016-4656 — Apple iOS: Apple iOS Memory Corruption Vulnerability
A memory corruption vulnerability in Apple iOS kernel allows attackers to execute code in a privileged context or cause a denial-of-service (DoS) via a crafted application.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.236 (97.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-05-24
CISA remediation due: 2022-06-14
Known ransomware campaign use: Unknown/None
CVE-2021-22899 — Ivanti Pulse Connect Secure: Ivanti Pulse Connect Secure Command Injection Vulnerability
Ivanti Pulse Connect Secure contains a command injection vulnerability that allows remote authenticated users to perform remote code execution via Windows File Resource Profiles.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.229 (97.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2023-32435 — Apple Multiple Products: Apple Multiple Products WebKit Memory Corruption Vulnerability
Apple iOS, iPadOS, macOS, and Safari WebKit contain a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.228 (97.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-06-23
CISA remediation due: 2023-07-14
Known ransomware campaign use: Unknown/None
CVE-2025-14174 — Google Chromium: Google Chromium Out of Bounds Memory Access Vulnerability
Google Chromium contains an out of bounds memory access vulnerability in ANGLE that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.226 (97.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-12-12
CISA remediation due: 2026-01-02
Known ransomware campaign use: Unknown/None
CVE-2024-44309 — Apple Multiple Products: Apple Multiple Products Cross-Site Scripting (XSS) Vulnerability
Apple iOS, macOS, and other Apple products contain an unspecified vulnerability when processing maliciously crafted web content that may lead to a cross-site scripting (XSS) attack.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 6.3 (NVD)
FIRST EPSS: 0.226 (97.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-11-21
CISA remediation due: 2024-12-12
Known ransomware campaign use: Unknown/None
CVE-2016-6367 — Cisco Adaptive Security Appliance (ASA): Cisco Adaptive Security Appliance (ASA) CLI Remote Code Execution Vulnerability
A vulnerability in the command-line interface (CLI) parser of Cisco ASA software could allow an authenticated, local attacker to create a denial-of-service (DoS) condition or potentially execute code.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.226 (97.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-05-24
CISA remediation due: 2022-06-14
Known ransomware campaign use: Unknown/None
CVE-2014-0196 — Linux Kernel: Linux Kernel Race Condition Vulnerability
Linux Kernel contains a race condition vulnerability within the n_tty_write function that allows local users to cause a denial-of-service (DoS) or gain privileges via read and write operations with long strings.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: The impacted product is end-of-life and should be disconnected if still in use.
CVSS: 5.5 (NVD)
FIRST EPSS: 0.225 (97.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-05-12
CISA remediation due: 2023-06-02
Known ransomware campaign use: Unknown/None
CVE-2015-5317 — Jenkins Jenkins User Interface (UI): Jenkins User Interface (UI) Information Disclosure Vulnerability
Jenkins User Interface (UI) contains an information disclosure vulnerability that allows users to see the names of jobs and builds otherwise inaccessible to them on the "Fingerprints" pages.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.5 (NVD)
FIRST EPSS: 0.224 (97.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-05-12
CISA remediation due: 2023-06-02
Known ransomware campaign use: Unknown/None
CVE-2024-37079 — Broadcom VMware vCenter Server: Broadcom VMware vCenter Server Out-of-bounds Write Vulnerability
Broadcom VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. This could allow a malicious actor with network access to vCenter Server to send specially crafted network packets, potentially leading to remote code execution.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.224 (97.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-01-23
CISA remediation due: 2026-02-13
Known ransomware campaign use: Unknown/None
CVE-2014-0546 — Adobe Reader and Acrobat: Adobe Reader and Acrobat Sandbox Bypass Vulnerability
Adobe Reader and Acrobat on Windows allow attackers to bypass a sandbox protection mechanism, and consequently execute native code in a privileged context.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.223 (97.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-05-25
CISA remediation due: 2022-06-15
Known ransomware campaign use: Unknown/None
CVE-2022-0609 — Google Chromium Animation: Google Chromium Animation Use-After-Free Vulnerability
Google Chromium Animation contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.223 (97.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-02-15
CISA remediation due: 2022-03-01
Known ransomware campaign use: Unknown/None
CVE-2024-40890 — Zyxel DSL CPE Devices: Zyxel DSL CPE OS Command Injection Vulnerability
Multiple Zyxel DSL CPE devices contain a post-authentication command injection vulnerability in the CGI program that could allow an authenticated attacker to execute OS commands via a crafted HTTP request.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.223 (97.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-02-11
CISA remediation due: 2025-03-04
Known ransomware campaign use: Unknown/None
CVE-2021-3560 — Red Hat Polkit: Red Hat Polkit Incorrect Authorization Vulnerability
Red Hat Polkit contains an incorrect authorization vulnerability through the bypassing of credential checks for D-Bus requests, allowing for privilege escalation.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.222 (97.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-05-12
CISA remediation due: 2023-06-02
Known ransomware campaign use: Unknown/None
CVE-2026-2441 — Google Chromium: Google Chromium CSS Use-After-Free Vulnerability
Google Chromium CSS contains a use-after-free vulnerability that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.220 (97.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-02-17
CISA remediation due: 2026-03-10
Known ransomware campaign use: Unknown/None
CVE-2020-27930 — Apple Multiple Products: Apple Multiple Products Memory Corruption Vulnerability
Apple iOS, iPadOS, macOS, and watchOS FontParser contain a memory corruption vulnerability which may allow for code execution when processing maliciously crafted front.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.220 (97.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2025-43300 — Apple iOS, iPadOS, and macOS: Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability
Apple iOS, iPadOS, and macOS contain an out-of-bounds write vulnerability in the Image I/O framework.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 10.0 (NVD)
FIRST EPSS: 0.220 (97.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-08-21
CISA remediation due: 2025-09-11
Known ransomware campaign use: Unknown/None
CVE-2025-23209 — Craft CMS Craft CMS: Craft CMS Code Injection Vulnerability
Craft CMS contains a code injection vulnerability caused by improper validation of the database backup path, ultimately enabling remote code execution.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 8.1 (NVD)
FIRST EPSS: 0.218 (97.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-02-20
CISA remediation due: 2025-03-13
Known ransomware campaign use: Unknown/None
CVE-2024-40891 — Zyxel DSL CPE Devices: Zyxel DSL CPE OS Command Injection Vulnerability
Multiple Zyxel DSL CPE devices contain a post-authentication command injection vulnerability in the management commands that could allow an authenticated attacker to execute OS commands via Telnet.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.215 (97.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-02-11
CISA remediation due: 2025-03-04
Known ransomware campaign use: Unknown/None
CVE-2017-6742 — Cisco IOS and IOS XE Software: Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.214 (97.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-04-19
CISA remediation due: 2023-05-10
Known ransomware campaign use: Unknown/None
CVE-2020-9377 — D-Link DIR-610 Devices: D-Link DIR-610 Devices Remote Command Execution
D-Link DIR-610 devices allow remote code execution via the cmd parameter to command.php.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: The impacted product is end-of-life and should be disconnected if still in use.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.213 (97.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-25
CISA remediation due: 2022-04-15
Known ransomware campaign use: Unknown/None
CVE-2012-5054 — Adobe Flash Player: Adobe Flash Player Integer Overflow Vulnerability
Adobe Flash Player contains an integer overflow vulnerability that allows remote attackers to execute code via malformed arguments.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: The impacted product is end-of-life and should be disconnected if still in use.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.212 (97.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-06-08
CISA remediation due: 2022-06-22
Known ransomware campaign use: Unknown/None
CVE-2025-54948 — Trend Micro Apex One: Trend Micro Apex One OS Command Injection Vulnerability
Trend Micro Apex One Management Console (on-premise) contains an OS command injection vulnerability that could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.208 (97.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-08-18
CISA remediation due: 2025-09-08
Known ransomware campaign use: Unknown/None
CVE-2024-7971 — Google Chromium V8: Google Chromium V8 Type Confusion Vulnerability
Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 9.6 (NVD)
FIRST EPSS: 0.207 (97.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-08-26
CISA remediation due: 2024-09-16
Known ransomware campaign use: Unknown/None
CVE-2020-24363 — TP-Link TL-WA855RE: TP-link TL-WA855RE Missing Authentication for Critical Function Vulnerability
TP-link TL-WA855RE contains a missing authentication for critical function vulnerability. This vulnerability could allow an unauthenticated attacker (on the same network) to submit a TDDP_RESET POST request for a factory reset and reboot. The attacker can then obtain incorrect access control by setting a new administrative password. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.207 (97.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-09-02
CISA remediation due: 2025-09-23
Known ransomware campaign use: Unknown/None
CVE-2014-9163 — Adobe Flash Player: Adobe Flash Player Stack-Based Buffer Overflow Vulnerability
Stack-based buffer overflow in Adobe Flash Player allows attackers to execute code remotely.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: The impacted product is end-of-life and should be disconnected if still in use.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.204 (97.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-04-13
CISA remediation due: 2022-05-04
Known ransomware campaign use: Unknown/None