Cross-Vendor Patch Advisories
Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.
Browse Advisories
1,308 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.
| CVE | Vendor | Product | Vulnerability | EVRS | EPSS | Ransomware | CISA due |
|---|---|---|---|---|---|---|---|
| CVE-2018-19943 | QNAP | Network Attached Storage (NAS) | QNAP NAS File Station Cross-Site Scripting Vulnerability | 75 Urgent | 0.177 (96.9th pctl) | Known | 2022-06-14 |
| CVE-2024-11182 | MDaemon | Email Server | MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability | 75 Urgent | 0.177 (96.9th pctl) | Unknown/None | 2025-06-09 |
| CVE-2025-24085 | Apple | Multiple Products | Apple Multiple Products Use-After-Free Vulnerability | 75 Urgent | 0.176 (96.9th pctl) | Unknown/None | 2025-02-19 |
| CVE-2022-27926 | Synacor | Zimbra Collaboration Suite (ZCS) | Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability | 75 Urgent | 0.176 (96.9th pctl) | Unknown/None | 2023-04-24 |
| CVE-2021-44207 | Acclaim Systems | USAHERDS | Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability | 75 Urgent | 0.176 (96.9th pctl) | Unknown/None | 2025-01-13 |
| CVE-2019-8605 | Apple | Multiple Products | Apple Multiple Products Use-After-Free Vulnerability | 75 Urgent | 0.175 (96.9th pctl) | Unknown/None | 2022-07-18 |
| CVE-2010-5326 | SAP | NetWeaver | SAP NetWeaver Remote Code Execution Vulnerability | 75 Urgent | 0.174 (96.9th pctl) | Unknown/None | 2022-05-03 |
| CVE-2026-22719 | Broadcom | VMware Aria Operations | Broadcom VMware Aria Operations Command Injection Vulnerability | 75 Urgent | 0.174 (96.9th pctl) | Unknown/None | 2026-03-24 |
| CVE-2023-50224 | TP-Link | TL-WR841N | TP-Link TL-WR841N Authentication Bypass by Spoofing Vulnerability | 75 Urgent | 0.174 (96.9th pctl) | Unknown/None | 2025-09-24 |
| CVE-2024-38813 | VMware | vCenter Server | VMware vCenter Server Privilege Escalation Vulnerability | 75 Urgent | 0.174 (96.9th pctl) | Unknown/None | 2024-12-11 |
| CVE-2020-4006 | VMware | Multiple Products | Multiple VMware Products Command Injection Vulnerability | 75 Urgent | 0.173 (96.9th pctl) | Unknown/None | 2022-05-03 |
| CVE-2023-26359 | Adobe | ColdFusion | Adobe ColdFusion Deserialization of Untrusted Data Vulnerability | 75 Urgent | 0.170 (96.9th pctl) | Unknown/None | 2023-09-11 |
| CVE-2025-62593 | Ray-Project | Ray | Ray-Project Ray Code Injection Vulnerability | 75 Urgent | 0.169 (96.8th pctl) | Unknown/None | 2026-08-20 |
| CVE-2021-30533 | Chromium PopupBlocker | Google Chromium PopupBlocker Security Bypass Vulnerability | 75 Urgent | 0.166 (96.8th pctl) | Unknown/None | 2022-07-18 | |
| CVE-2023-32409 | Apple | Multiple Products | Apple Multiple Products WebKit Sandbox Escape Vulnerability | 75 Urgent | 0.165 (96.8th pctl) | Unknown/None | 2023-06-12 |
| CVE-2020-27950 | Apple | Multiple Products | Apple Multiple Products Memory Initialization Vulnerability | 75 Urgent | 0.165 (96.8th pctl) | Unknown/None | 2022-05-03 |
| CVE-2021-20022 | SonicWall | SonicWall Email Security | SonicWall Email Security Unrestricted Upload of File Vulnerability | 75 Urgent | 0.165 (96.8th pctl) | Known | 2021-11-17 |
| CVE-2023-6345 | Chromium Skia | Google Skia Integer Overflow Vulnerability | 75 Urgent | 0.165 (96.8th pctl) | Unknown/None | 2023-12-21 | |
| CVE-2026-64849 | MLflow | MLflow | MLflow Server-Side Request Forgery Vulnerability | 75 Urgent | 0.164 (96.8th pctl) | Unknown/None | 2026-09-02 |
| CVE-2022-22620 | Apple | iOS, iPadOS, and macOS | Apple iOS, iPadOS, and macOS Webkit Use-After-Free Vulnerability | 75 Urgent | 0.162 (96.7th pctl) | Unknown/None | 2022-02-25 |
| CVE-2020-3837 | Apple | Multiple Products | Apple Multiple Products Memory Corruption Vulnerability | 75 Urgent | 0.161 (96.7th pctl) | Unknown/None | 2022-07-18 |
| CVE-2022-4262 | Chromium V8 | Google Chromium V8 Type Confusion Vulnerability | 75 Urgent | 0.160 (96.7th pctl) | Unknown/None | 2022-12-26 | |
| CVE-2024-20481 | Cisco | Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | Cisco ASA and FTD Denial-of-Service Vulnerability | 75 Urgent | 0.159 (96.6th pctl) | Unknown/None | 2024-11-14 |
| CVE-2025-67038 | Lantronix | EDS5000 | Lantronix EDS5000 Code Injection Vulnerability | 75 Urgent | 0.157 (96.6th pctl) | Unknown/None | 2026-06-26 |
| CVE-2019-7286 | Apple | Multiple Products | Apple Multiple Products Memory Corruption Vulnerability | 75 Urgent | 0.156 (96.6th pctl) | Unknown/None | 2022-06-13 |
Exactly the 1,308 advisory(ies) matching the filters above.
Advisory detail
Expand any advisory for its description, CISA's own required action, and research links.
CVE-2018-19943 — QNAP Network Attached Storage (NAS): QNAP NAS File Station Cross-Site Scripting Vulnerability
A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 5.4 (NVD)
FIRST EPSS: 0.177 (96.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-05-24
CISA remediation due: 2022-06-14
Known ransomware campaign use: Known
CVE-2024-11182 — MDaemon Email Server: MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability
MDaemon Email Server contains a cross-site scripting (XSS) vulnerability that allows a remote attacker to load arbitrary JavaScript code via an HTML e-mail message.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 5.3 (NVD)
FIRST EPSS: 0.177 (96.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-05-19
CISA remediation due: 2025-06-09
Known ransomware campaign use: Unknown/None
CVE-2025-24085 — Apple Multiple Products: Apple Multiple Products Use-After-Free Vulnerability
Apple iOS, macOS, and other Apple products contain a user-after-free vulnerability that could allow a malicious application to elevate privileges.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 10.0 (NVD)
FIRST EPSS: 0.176 (96.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-01-29
CISA remediation due: 2025-02-19
Known ransomware campaign use: Unknown/None
CVE-2022-27926 — Synacor Zimbra Collaboration Suite (ZCS): Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability
Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability by allowing an endpoint URL to accept parameters without sanitizing.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 6.1 (NVD)
FIRST EPSS: 0.176 (96.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-04-03
CISA remediation due: 2023-04-24
Known ransomware campaign use: Unknown/None
CVE-2021-44207 — Acclaim Systems USAHERDS: Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability
Acclaim Systems USAHERDS contains a hard-coded credentials vulnerability that could allow an attacker to achieve remote code execution on the system that runs the application. The MachineKey must be obtained via a separate vulnerability or other channel.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Please contact the product developer for support and vulnerability mitigation.
CVSS: 8.1 (NVD)
FIRST EPSS: 0.176 (96.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-12-23
CISA remediation due: 2025-01-13
Known ransomware campaign use: Unknown/None
CVE-2019-8605 — Apple Multiple Products: Apple Multiple Products Use-After-Free Vulnerability
A use-after-free vulnerability in Apple iOS, macOS, tvOS, and watchOS could allow a malicious application to execute code with system privileges.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.175 (96.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-06-27
CISA remediation due: 2022-07-18
Known ransomware campaign use: Unknown/None
CVE-2010-5326 — SAP NetWeaver: SAP NetWeaver Remote Code Execution Vulnerability
SAP NetWeaver Application Server Java Platforms Invoker Servlet does not require authentication, allowing for remote code execution via a HTTP or HTTPS request.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 10.0 (NVD)
FIRST EPSS: 0.174 (96.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2026-22719 — Broadcom VMware Aria Operations: Broadcom VMware Aria Operations Command Injection Vulnerability
Broadcom VMware Aria Operations formerly known as vRealize Operations (vROps) contains a command injection vulnerability that allows an unauthenticated attacker to execute arbitrary commands, potentially leading to remote code execution during support‑assisted product migration.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 8.1 (NVD)
FIRST EPSS: 0.174 (96.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-03-03
CISA remediation due: 2026-03-24
Known ransomware campaign use: Unknown/None
CVE-2023-50224 — TP-Link TL-WR841N: TP-Link TL-WR841N Authentication Bypass by Spoofing Vulnerability
TP-Link TL-WR841N contains an authentication bypass by spoofing vulnerability within the httpd service, which listens on TCP port 80 by default, leading to the disclose of stored credentials. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 6.5 (NVD)
FIRST EPSS: 0.174 (96.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-09-03
CISA remediation due: 2025-09-24
Known ransomware campaign use: Unknown/None
CVE-2024-38813 — VMware vCenter Server: VMware vCenter Server Privilege Escalation Vulnerability
VMware vCenter contains an improper check for dropped privileges vulnerability. This vulnerability could allow an attacker with network access to the vCenter Server to escalate privileges to root by sending a specially crafted packet.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.174 (96.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-11-20
CISA remediation due: 2024-12-11
Known ransomware campaign use: Unknown/None
CVE-2020-4006 — VMware Multiple Products: Multiple VMware Products Command Injection Vulnerability
VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector contain a command injection vulnerability. An attacker with network access to the administrative configurator on port 8443 and a valid password for the configurator administrator account can execute commands with unrestricted privileges on the underlying operating system.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.1 (NVD)
FIRST EPSS: 0.173 (96.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2023-26359 — Adobe ColdFusion: Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
Adobe ColdFusion contains a deserialization of untrusted data vulnerability that could result in code execution in the context of the current user.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.170 (96.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-08-21
CISA remediation due: 2023-09-11
Known ransomware campaign use: Unknown/None
CVE-2025-62593 — Ray-Project Ray: Ray-Project Ray Code Injection Vulnerability
Ray-Project Ray contains a code injection vulnerability that could allow remote code execution. Developers using Ray as a development tool may be exposed to this vulnerability exploitable through Firefox and Safari.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVSS: 9.4 (NVD)
FIRST EPSS: 0.169 (96.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-08-17
CISA remediation due: 2026-08-20
Known ransomware campaign use: Unknown/None
CVE-2021-30533 — Google Chromium PopupBlocker: Google Chromium PopupBlocker Security Bypass Vulnerability
Google Chromium PopupBlocker contains an insufficient policy enforcement vulnerability that allows a remote attacker to bypass navigation restrictions via a crafted iframe. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 6.5 (NVD)
FIRST EPSS: 0.166 (96.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-06-27
CISA remediation due: 2022-07-18
Known ransomware campaign use: Unknown/None
CVE-2023-32409 — Apple Multiple Products: Apple Multiple Products WebKit Sandbox Escape Vulnerability
Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit contain an unspecified vulnerability that can allow a remote attacker to break out of the Web Content sandbox. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.6 (NVD)
FIRST EPSS: 0.165 (96.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-05-22
CISA remediation due: 2023-06-12
Known ransomware campaign use: Unknown/None
CVE-2020-27950 — Apple Multiple Products: Apple Multiple Products Memory Initialization Vulnerability
Apple iOS, iPadOS, macOS, and watchOS contain a memory initialization vulnerability that may allow a malicious application to disclose kernel memory.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 5.5 (NVD)
FIRST EPSS: 0.165 (96.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2021-20022 — SonicWall SonicWall Email Security: SonicWall Email Security Unrestricted Upload of File Vulnerability
SonicWall Email Security contains an unrestricted upload of file with dangerous type vulnerability that allows a post-authenticated attacker to upload a file to the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20023 to achieve privilege escalation.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.2 (NVD)
FIRST EPSS: 0.165 (96.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2021-11-17
Known ransomware campaign use: Known
CVE-2023-6345 — Google Chromium Skia: Google Skia Integer Overflow Vulnerability
Google Chromium Skia contains an integer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a malicious file. This vulnerability affects Google Chrome and ChromeOS, Android, Flutter, and possibly other products.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 9.6 (NVD)
FIRST EPSS: 0.165 (96.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-11-30
CISA remediation due: 2023-12-21
Known ransomware campaign use: Unknown/None
CVE-2026-64849 — MLflow MLflow: MLflow Server-Side Request Forgery Vulnerability
MLflow contains a server-side request forgery vulnerability that can allow attackers to reach internal or cloud metadata services and receive response_status and response_body.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVSS: 8.5 (Red Hat (estimated))
FIRST EPSS: 0.164 (96.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-08-19
CISA remediation due: 2026-09-02
Known ransomware campaign use: Unknown/None
CVE-2022-22620 — Apple iOS, iPadOS, and macOS: Apple iOS, iPadOS, and macOS Webkit Use-After-Free Vulnerability
Apple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.162 (96.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-02-11
CISA remediation due: 2022-02-25
Known ransomware campaign use: Unknown/None
CVE-2020-3837 — Apple Multiple Products: Apple Multiple Products Memory Corruption Vulnerability
Apple iOS, iPadOS, macOS, tvOS, and watchOS contain a memory corruption vulnerability that could allow an application to execute code with kernel privileges.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.161 (96.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-06-27
CISA remediation due: 2022-07-18
Known ransomware campaign use: Unknown/None
CVE-2022-4262 — Google Chromium V8: Google Chromium V8 Type Confusion Vulnerability
Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.160 (96.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-12-05
CISA remediation due: 2022-12-26
Known ransomware campaign use: Unknown/None
CVE-2024-20481 — Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD): Cisco ASA and FTD Denial-of-Service Vulnerability
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain a missing release of resource after effective lifetime vulnerability that could allow an unauthenticated, remote attacker to cause a denial-of-service (DoS) of the RAVPN service.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 5.8 (NVD)
FIRST EPSS: 0.159 (96.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-10-24
CISA remediation due: 2024-11-14
Known ransomware campaign use: Unknown/None
CVE-2025-67038 — Lantronix EDS5000: Lantronix EDS5000 Code Injection Vulnerability
Lantronix EDS5000 contains a code injection vulnerability that could allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.157 (96.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-06-23
CISA remediation due: 2026-06-26
Known ransomware campaign use: Unknown/None
CVE-2019-7286 — Apple Multiple Products: Apple Multiple Products Memory Corruption Vulnerability
Apple iOS, macOS, watchOS, and tvOS contain a memory corruption vulnerability that could allow for privilege escalation.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.156 (96.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-05-23
CISA remediation due: 2022-06-13
Known ransomware campaign use: Unknown/None