Cross-Vendor Patch Advisories

Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.

Browse Advisories

Association
Vendor — all

Leave every box clear to show all 282 vendors.

1,308 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.

CISA KEV advisories matching the current filters, ranked by EVULNABLE Risk Score
CVE Vendor Product Vulnerability EVRS EPSS Ransomware CISA due
CVE-2019-3010 Oracle Solaris Oracle Solaris Privilege Escalation Vulnerability 75 Urgent 0.134 (96.2nd pctl) Unknown/None 2022-06-15
CVE-2015-4902 Oracle Java SE Oracle Java SE Integrity Check Vulnerability 75 Urgent 0.134 (96.1st pctl) Unknown/None 2022-03-24
CVE-2022-22948 VMware vCenter Server VMware vCenter Server Incorrect Default File Permissions Vulnerability 75 Urgent 0.133 (96.1st pctl) Unknown/None 2024-08-07
CVE-2026-22769 Dell RecoverPoint for Virtual Machines (RP4VMs) Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability 75 Urgent 0.131 (96.1st pctl) Unknown/None 2026-02-21
CVE-2026-46817 Oracle E-Business Suite Oracle E-Business Suite Improper Privilege Management Vulnerability 75 Urgent 0.130 (96.1st pctl) Unknown/None 2026-07-18
CVE-2025-6554 Google Chromium V8 Google Chromium V8 Type Confusion Vulnerability 75 Urgent 0.127 (96th pctl) Unknown/None 2025-07-23
CVE-2022-23176 WatchGuard Firebox and XTM WatchGuard Firebox and XTM Privilege Escalation Vulnerability 75 Urgent 0.127 (96th pctl) Unknown/None 2022-05-02
CVE-2026-34926 Trend Micro Apex One Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability 75 Urgent 0.127 (96th pctl) Unknown/None 2026-06-04
CVE-2022-22675 Apple macOS Apple macOS Out-of-Bounds Write Vulnerability 75 Urgent 0.125 (95.9th pctl) Unknown/None 2022-04-25
CVE-2022-20775 Cisco SD-WAN Cisco SD-WAN Path Traversal Vulnerability 75 Urgent 0.125 (95.9th pctl) Unknown/None 2026-02-27
CVE-2022-41328 Fortinet FortiOS Fortinet FortiOS Path Traversal Vulnerability 75 Urgent 0.123 (95.9th pctl) Unknown/None 2023-04-04
CVE-2023-32373 Apple Multiple Products Apple Multiple Products WebKit Use-After-Free Vulnerability 75 Urgent 0.122 (95.9th pctl) Unknown/None 2023-06-12
CVE-2022-20821 Cisco IOS XR Cisco IOS XR Open Port Vulnerability 75 Urgent 0.121 (95.9th pctl) Unknown/None 2022-06-13
CVE-2021-28663 Arm Mali Graphics Processing Unit (GPU) Arm Mali Graphics Processing Unit (GPU) Use-After-Free Vulnerability 75 Urgent 0.121 (95.9th pctl) Unknown/None 2021-11-17
CVE-2017-11292 Adobe Flash Player Adobe Flash Player Type Confusion Vulnerability 75 Urgent 0.119 (95.8th pctl) Unknown/None 2022-03-24
CVE-2020-8599 Trend Micro Apex One and OfficeScan Trend Micro Apex One and OfficeScan Authentication Bypass Vulnerability 75 Urgent 0.119 (95.8th pctl) Unknown/None 2022-05-03
CVE-2026-15410 SonicWall SMA1000 Appliances SonicWall SMA1000 Appliances Code Injection Vulnerability 75 Urgent 0.118 (95.8th pctl) Known 2026-07-17
CVE-2020-3118 Cisco IOS XR Cisco IOS XR Software Discovery Protocol Format String Vulnerability 75 Urgent 0.117 (95.8th pctl) Unknown/None 2022-05-03
CVE-2021-37973 Google Chromium Portals Google Chromium Portals Use-After-Free Vulnerability 75 Urgent 0.116 (95.8th pctl) Unknown/None 2021-11-17
CVE-2022-22587 Apple iOS and macOS Apple Memory Corruption Vulnerability 75 Urgent 0.116 (95.8th pctl) Unknown/None 2022-02-11
CVE-2025-48927 TeleMessage TM SGNL TeleMessage TM SGNL Initialization of a Resource with an Insecure Default Vulnerability 75 Urgent 0.111 (95.6th pctl) Unknown/None 2025-07-22
CVE-2013-0648 Adobe Flash Player Adobe Flash Player Code Execution Vulnerability 75 Urgent 0.111 (95.6th pctl) Unknown/None 2024-10-08
CVE-2026-48710 Kludex Starlette Kludex Starlette HTTP Request/Response Smuggling Vulnerability 75 Urgent 0.110 (95.6th pctl) Unknown/None 2026-09-16
CVE-2024-4761 Google Chromium V8 Google Chromium V8 Out-of-Bounds Memory Write Vulnerability 75 Urgent 0.110 (95.6th pctl) Unknown/None 2024-06-06
CVE-2021-30762 Apple iOS Apple iOS WebKit Use-After-Free Vulnerability 75 Urgent 0.110 (95.6th pctl) Unknown/None 2021-11-17
Download filtered advisories (CSV)

Exactly the 1,308 advisory(ies) matching the filters above.

Advisory detail

Expand any advisory for its description, CISA's own required action, and research links.

CVE-2019-3010 — Oracle Solaris: Oracle Solaris Privilege Escalation Vulnerability

Oracle Solaris component: XScreenSaver contains an unspecified vulnerability that allows for privilege escalation.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.134 (96.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-05-25

CISA remediation due: 2022-06-15

Known ransomware campaign use: Unknown/None

CVE-2015-4902 — Oracle Java SE: Oracle Java SE Integrity Check Vulnerability

Unspecified vulnerability in Oracle Java SE allows remote attackers to affect integrity via Unknown vectors related to deployment.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 5.3 (NVD)

FIRST EPSS: 0.134 (96.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-03

CISA remediation due: 2022-03-24

Known ransomware campaign use: Unknown/None

CVE-2022-22948 — VMware vCenter Server: VMware vCenter Server Incorrect Default File Permissions Vulnerability

VMware vCenter Server contains an incorrect default file permissions vulnerability that allows a remote, privileged attacker to gain access to sensitive information.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 6.5 (NVD)

FIRST EPSS: 0.133 (96.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-07-17

CISA remediation due: 2024-08-07

Known ransomware campaign use: Unknown/None

CVE-2026-22769 — Dell RecoverPoint for Virtual Machines (RP4VMs): Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability

Dell RecoverPoint for Virtual Machines (RP4VMs) contains an use of hard-coded credentials vulnerability that could allow an unauthenticated remote attacker to gain unauthorized access to the underlying operating system and root-level persistence.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 10.0 (NVD)

FIRST EPSS: 0.131 (96.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-02-18

CISA remediation due: 2026-02-21

Known ransomware campaign use: Unknown/None

CVE-2026-46817 — Oracle E-Business Suite: Oracle E-Business Suite Improper Privilege Management Vulnerability

Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.130 (96.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-07-15

CISA remediation due: 2026-07-18

Known ransomware campaign use: Unknown/None

CVE-2025-6554 — Google Chromium V8: Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 contains a type confusion vulnerability that could allow a remote attacker to perform arbitrary read/write via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 8.1 (NVD)

FIRST EPSS: 0.127 (96th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-07-02

CISA remediation due: 2025-07-23

Known ransomware campaign use: Unknown/None

CVE-2022-23176 — WatchGuard Firebox and XTM: WatchGuard Firebox and XTM Privilege Escalation Vulnerability

WatchGuard Firebox and XTM appliances allow a remote attacker with unprivileged credentials to access the system with a privileged management session via exposed management access.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.127 (96th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-04-11

CISA remediation due: 2022-05-02

Known ransomware campaign use: Unknown/None

CVE-2026-34926 — Trend Micro Apex One: Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability

Trend Micro Apex One (on-premise) contains a directory traversal vulnerability that could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 6.7 (NVD)

FIRST EPSS: 0.127 (96th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-05-21

CISA remediation due: 2026-06-04

Known ransomware campaign use: Unknown/None

CVE-2022-22675 — Apple macOS: Apple macOS Out-of-Bounds Write Vulnerability

macOS Monterey contains an out-of-bounds write vulnerability that could allow an application to execute arbitrary code with kernel privileges.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.125 (95.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-04-04

CISA remediation due: 2022-04-25

Known ransomware campaign use: Unknown/None

CVE-2022-20775 — Cisco SD-WAN: Cisco SD-WAN Path Traversal Vulnerability

Cisco SD-WAN CLI contains a path traversal vulnerability that could allow an authenticated local attacker to gain elevated privileges via improper access controls on commands within the application CLI. A successful exploit could allow the attacker to execute arbitrary commands as the root user.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.125 (95.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-02-25

CISA remediation due: 2026-02-27

Known ransomware campaign use: Unknown/None

CVE-2022-41328 — Fortinet FortiOS: Fortinet FortiOS Path Traversal Vulnerability

Fortinet FortiOS contains a path traversal vulnerability that may allow a local privileged attacker to read and write files via crafted CLI commands.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.1 (NVD)

FIRST EPSS: 0.123 (95.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-03-14

CISA remediation due: 2023-04-04

Known ransomware campaign use: Unknown/None

CVE-2023-32373 — Apple Multiple Products: Apple Multiple Products WebKit Use-After-Free Vulnerability

Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.122 (95.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-05-22

CISA remediation due: 2023-06-12

Known ransomware campaign use: Unknown/None

CVE-2022-20821 — Cisco IOS XR: Cisco IOS XR Open Port Vulnerability

Cisco IOS XR software health check opens TCP port 6379 by default on activation. An attacker can connect to the Redis instance on the open port and allow access to the Redis instance that is running within the NOSi container.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 6.5 (NVD)

FIRST EPSS: 0.121 (95.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-05-23

CISA remediation due: 2022-06-13

Known ransomware campaign use: Unknown/None

CVE-2021-28663 — Arm Mali Graphics Processing Unit (GPU): Arm Mali Graphics Processing Unit (GPU) Use-After-Free Vulnerability

Arm Mali Graphics Processing Unit (GPU) kernel driver contains a use-after-free vulnerability that may allow a non-privileged user to make improper operations on GPU memory to gain root privilege, and/or disclose information.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.121 (95.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2021-11-17

Known ransomware campaign use: Unknown/None

CVE-2017-11292 — Adobe Flash Player: Adobe Flash Player Type Confusion Vulnerability

Adobe Flash Player contains a type confusion vulnerability which can allow for remote code execution.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: The impacted product is end-of-life and should be disconnected if still in use.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.119 (95.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-03

CISA remediation due: 2022-03-24

Known ransomware campaign use: Unknown/None

CVE-2020-8599 — Trend Micro Apex One and OfficeScan: Trend Micro Apex One and OfficeScan Authentication Bypass Vulnerability

Trend Micro Apex One and OfficeScan server contain a vulnerable EXE file that could allow a remote attacker to write data to a path on affected installations and bypass root login.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.119 (95.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2026-15410 — SonicWall SMA1000 Appliances: SonicWall SMA1000 Appliances Code Injection Vulnerability

SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVSS: 7.2 (NVD)

FIRST EPSS: 0.118 (95.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-07-14

CISA remediation due: 2026-07-17

Known ransomware campaign use: Known

CVE-2020-3118 — Cisco IOS XR: Cisco IOS XR Software Discovery Protocol Format String Vulnerability

Cisco IOS XR improperly validates string input from certain fields in Cisco Discovery Protocol messages. Exploitation could allow an unauthenticated, adjacent attacker to execute code with administrative privileges or cause a reload on an affected device.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.117 (95.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2021-37973 — Google Chromium Portals: Google Chromium Portals Use-After-Free Vulnerability

Google Chromium Portals contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability affects web browsers that utilize Chromium, including Google Chrome and Microsoft Edge.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.6 (NVD)

FIRST EPSS: 0.116 (95.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2021-11-17

Known ransomware campaign use: Unknown/None

CVE-2022-22587 — Apple iOS and macOS: Apple Memory Corruption Vulnerability

Apple IOMobileFrameBuffer contains a memory corruption vulnerability which can allow a malicious application to execute arbitrary code with kernel privileges.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.116 (95.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-01-28

CISA remediation due: 2022-02-11

Known ransomware campaign use: Unknown/None

CVE-2025-48927 — TeleMessage TM SGNL: TeleMessage TM SGNL Initialization of a Resource with an Insecure Default Vulnerability

TeleMessage TM SGNL contains an initialization of a resource with an insecure default vulnerability. This vulnerability relies on how the Spring Boot Actuator is configured with an exposed heap dump endpoint at a /heapdump URI.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 5.3 (NVD)

FIRST EPSS: 0.111 (95.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-07-01

CISA remediation due: 2025-07-22

Known ransomware campaign use: Unknown/None

CVE-2013-0648 — Adobe Flash Player: Adobe Flash Player Code Execution Vulnerability

Adobe Flash Player contains an unspecified vulnerability in the ExternalInterface ActionScript functionality that allows a remote attacker to execute arbitrary code via crafted SWF content.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.111 (95.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-09-17

CISA remediation due: 2024-10-08

Known ransomware campaign use: Unknown/None

CVE-2026-48710 — Kludex Starlette: Kludex Starlette HTTP Request/Response Smuggling Vulnerability

Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentication bypass when the authentication depends on the reconstructed URL’s path. This vulnerability could be chaned with CVE-2026-42271.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVSS: 6.5 (NVD)

FIRST EPSS: 0.110 (95.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-09-02

CISA remediation due: 2026-09-16

Known ransomware campaign use: Unknown/None

CVE-2024-4761 — Google Chromium V8: Google Chromium V8 Out-of-Bounds Memory Write Vulnerability

Google Chromium V8 Engine contains an unspecified out-of-bounds memory write vulnerability via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.110 (95.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-05-16

CISA remediation due: 2024-06-06

Known ransomware campaign use: Unknown/None

CVE-2021-30762 — Apple iOS: Apple iOS WebKit Use-After-Free Vulnerability

Apple iOS WebKit contains a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.110 (95.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2021-11-17

Known ransomware campaign use: Unknown/None

Data sources & attribution

Known-exploitation status, required actions, ransomware association and remediation deadlines come from the CISA Known Exploited Vulnerabilities Catalog. Exploitation probability and percentile are provided by FIRST.org's EPSS, used under FIRST's open data terms.

Microsoft Patch Tuesday data is sourced from the Microsoft Security Update Guide; lifecycle milestones from endoflife.date. Linux distribution advisories come from Red Hat, Ubuntu and Debian; vendor bulletins from Adobe, Apple, Chrome, Cisco, Ivanti and Oracle, each linked to its own advisory.