Cross-Vendor Patch Advisories
Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.
Browse Advisories
1,308 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.
| CVE | Vendor | Product | Vulnerability | EVRS | EPSS | Ransomware | CISA due |
|---|---|---|---|---|---|---|---|
| CVE-2019-3010 | Oracle | Solaris | Oracle Solaris Privilege Escalation Vulnerability | 75 Urgent | 0.134 (96.2nd pctl) | Unknown/None | 2022-06-15 |
| CVE-2015-4902 | Oracle | Java SE | Oracle Java SE Integrity Check Vulnerability | 75 Urgent | 0.134 (96.1st pctl) | Unknown/None | 2022-03-24 |
| CVE-2022-22948 | VMware | vCenter Server | VMware vCenter Server Incorrect Default File Permissions Vulnerability | 75 Urgent | 0.133 (96.1st pctl) | Unknown/None | 2024-08-07 |
| CVE-2026-22769 | Dell | RecoverPoint for Virtual Machines (RP4VMs) | Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability | 75 Urgent | 0.131 (96.1st pctl) | Unknown/None | 2026-02-21 |
| CVE-2026-46817 | Oracle | E-Business Suite | Oracle E-Business Suite Improper Privilege Management Vulnerability | 75 Urgent | 0.130 (96.1st pctl) | Unknown/None | 2026-07-18 |
| CVE-2025-6554 | Chromium V8 | Google Chromium V8 Type Confusion Vulnerability | 75 Urgent | 0.127 (96th pctl) | Unknown/None | 2025-07-23 | |
| CVE-2022-23176 | WatchGuard | Firebox and XTM | WatchGuard Firebox and XTM Privilege Escalation Vulnerability | 75 Urgent | 0.127 (96th pctl) | Unknown/None | 2022-05-02 |
| CVE-2026-34926 | Trend Micro | Apex One | Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability | 75 Urgent | 0.127 (96th pctl) | Unknown/None | 2026-06-04 |
| CVE-2022-22675 | Apple | macOS | Apple macOS Out-of-Bounds Write Vulnerability | 75 Urgent | 0.125 (95.9th pctl) | Unknown/None | 2022-04-25 |
| CVE-2022-20775 | Cisco | SD-WAN | Cisco SD-WAN Path Traversal Vulnerability | 75 Urgent | 0.125 (95.9th pctl) | Unknown/None | 2026-02-27 |
| CVE-2022-41328 | Fortinet | FortiOS | Fortinet FortiOS Path Traversal Vulnerability | 75 Urgent | 0.123 (95.9th pctl) | Unknown/None | 2023-04-04 |
| CVE-2023-32373 | Apple | Multiple Products | Apple Multiple Products WebKit Use-After-Free Vulnerability | 75 Urgent | 0.122 (95.9th pctl) | Unknown/None | 2023-06-12 |
| CVE-2022-20821 | Cisco | IOS XR | Cisco IOS XR Open Port Vulnerability | 75 Urgent | 0.121 (95.9th pctl) | Unknown/None | 2022-06-13 |
| CVE-2021-28663 | Arm | Mali Graphics Processing Unit (GPU) | Arm Mali Graphics Processing Unit (GPU) Use-After-Free Vulnerability | 75 Urgent | 0.121 (95.9th pctl) | Unknown/None | 2021-11-17 |
| CVE-2017-11292 | Adobe | Flash Player | Adobe Flash Player Type Confusion Vulnerability | 75 Urgent | 0.119 (95.8th pctl) | Unknown/None | 2022-03-24 |
| CVE-2020-8599 | Trend Micro | Apex One and OfficeScan | Trend Micro Apex One and OfficeScan Authentication Bypass Vulnerability | 75 Urgent | 0.119 (95.8th pctl) | Unknown/None | 2022-05-03 |
| CVE-2026-15410 | SonicWall | SMA1000 Appliances | SonicWall SMA1000 Appliances Code Injection Vulnerability | 75 Urgent | 0.118 (95.8th pctl) | Known | 2026-07-17 |
| CVE-2020-3118 | Cisco | IOS XR | Cisco IOS XR Software Discovery Protocol Format String Vulnerability | 75 Urgent | 0.117 (95.8th pctl) | Unknown/None | 2022-05-03 |
| CVE-2021-37973 | Chromium Portals | Google Chromium Portals Use-After-Free Vulnerability | 75 Urgent | 0.116 (95.8th pctl) | Unknown/None | 2021-11-17 | |
| CVE-2022-22587 | Apple | iOS and macOS | Apple Memory Corruption Vulnerability | 75 Urgent | 0.116 (95.8th pctl) | Unknown/None | 2022-02-11 |
| CVE-2025-48927 | TeleMessage | TM SGNL | TeleMessage TM SGNL Initialization of a Resource with an Insecure Default Vulnerability | 75 Urgent | 0.111 (95.6th pctl) | Unknown/None | 2025-07-22 |
| CVE-2013-0648 | Adobe | Flash Player | Adobe Flash Player Code Execution Vulnerability | 75 Urgent | 0.111 (95.6th pctl) | Unknown/None | 2024-10-08 |
| CVE-2026-48710 | Kludex | Starlette | Kludex Starlette HTTP Request/Response Smuggling Vulnerability | 75 Urgent | 0.110 (95.6th pctl) | Unknown/None | 2026-09-16 |
| CVE-2024-4761 | Chromium V8 | Google Chromium V8 Out-of-Bounds Memory Write Vulnerability | 75 Urgent | 0.110 (95.6th pctl) | Unknown/None | 2024-06-06 | |
| CVE-2021-30762 | Apple | iOS | Apple iOS WebKit Use-After-Free Vulnerability | 75 Urgent | 0.110 (95.6th pctl) | Unknown/None | 2021-11-17 |
Exactly the 1,308 advisory(ies) matching the filters above.
Advisory detail
Expand any advisory for its description, CISA's own required action, and research links.
CVE-2019-3010 — Oracle Solaris: Oracle Solaris Privilege Escalation Vulnerability
Oracle Solaris component: XScreenSaver contains an unspecified vulnerability that allows for privilege escalation.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.134 (96.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-05-25
CISA remediation due: 2022-06-15
Known ransomware campaign use: Unknown/None
CVE-2015-4902 — Oracle Java SE: Oracle Java SE Integrity Check Vulnerability
Unspecified vulnerability in Oracle Java SE allows remote attackers to affect integrity via Unknown vectors related to deployment.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 5.3 (NVD)
FIRST EPSS: 0.134 (96.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-03
CISA remediation due: 2022-03-24
Known ransomware campaign use: Unknown/None
CVE-2022-22948 — VMware vCenter Server: VMware vCenter Server Incorrect Default File Permissions Vulnerability
VMware vCenter Server contains an incorrect default file permissions vulnerability that allows a remote, privileged attacker to gain access to sensitive information.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 6.5 (NVD)
FIRST EPSS: 0.133 (96.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-07-17
CISA remediation due: 2024-08-07
Known ransomware campaign use: Unknown/None
CVE-2026-22769 — Dell RecoverPoint for Virtual Machines (RP4VMs): Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability
Dell RecoverPoint for Virtual Machines (RP4VMs) contains an use of hard-coded credentials vulnerability that could allow an unauthenticated remote attacker to gain unauthorized access to the underlying operating system and root-level persistence.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 10.0 (NVD)
FIRST EPSS: 0.131 (96.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-02-18
CISA remediation due: 2026-02-21
Known ransomware campaign use: Unknown/None
CVE-2026-46817 — Oracle E-Business Suite: Oracle E-Business Suite Improper Privilege Management Vulnerability
Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.130 (96.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-07-15
CISA remediation due: 2026-07-18
Known ransomware campaign use: Unknown/None
CVE-2025-6554 — Google Chromium V8: Google Chromium V8 Type Confusion Vulnerability
Google Chromium V8 contains a type confusion vulnerability that could allow a remote attacker to perform arbitrary read/write via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 8.1 (NVD)
FIRST EPSS: 0.127 (96th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-07-02
CISA remediation due: 2025-07-23
Known ransomware campaign use: Unknown/None
CVE-2022-23176 — WatchGuard Firebox and XTM: WatchGuard Firebox and XTM Privilege Escalation Vulnerability
WatchGuard Firebox and XTM appliances allow a remote attacker with unprivileged credentials to access the system with a privileged management session via exposed management access.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.127 (96th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-04-11
CISA remediation due: 2022-05-02
Known ransomware campaign use: Unknown/None
CVE-2026-34926 — Trend Micro Apex One: Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability
Trend Micro Apex One (on-premise) contains a directory traversal vulnerability that could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 6.7 (NVD)
FIRST EPSS: 0.127 (96th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-05-21
CISA remediation due: 2026-06-04
Known ransomware campaign use: Unknown/None
CVE-2022-22675 — Apple macOS: Apple macOS Out-of-Bounds Write Vulnerability
macOS Monterey contains an out-of-bounds write vulnerability that could allow an application to execute arbitrary code with kernel privileges.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.125 (95.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-04-04
CISA remediation due: 2022-04-25
Known ransomware campaign use: Unknown/None
CVE-2022-20775 — Cisco SD-WAN: Cisco SD-WAN Path Traversal Vulnerability
Cisco SD-WAN CLI contains a path traversal vulnerability that could allow an authenticated local attacker to gain elevated privileges via improper access controls on commands within the application CLI. A successful exploit could allow the attacker to execute arbitrary commands as the root user.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.125 (95.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-02-25
CISA remediation due: 2026-02-27
Known ransomware campaign use: Unknown/None
CVE-2022-41328 — Fortinet FortiOS: Fortinet FortiOS Path Traversal Vulnerability
Fortinet FortiOS contains a path traversal vulnerability that may allow a local privileged attacker to read and write files via crafted CLI commands.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.1 (NVD)
FIRST EPSS: 0.123 (95.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-03-14
CISA remediation due: 2023-04-04
Known ransomware campaign use: Unknown/None
CVE-2023-32373 — Apple Multiple Products: Apple Multiple Products WebKit Use-After-Free Vulnerability
Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.122 (95.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-05-22
CISA remediation due: 2023-06-12
Known ransomware campaign use: Unknown/None
CVE-2022-20821 — Cisco IOS XR: Cisco IOS XR Open Port Vulnerability
Cisco IOS XR software health check opens TCP port 6379 by default on activation. An attacker can connect to the Redis instance on the open port and allow access to the Redis instance that is running within the NOSi container.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 6.5 (NVD)
FIRST EPSS: 0.121 (95.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-05-23
CISA remediation due: 2022-06-13
Known ransomware campaign use: Unknown/None
CVE-2021-28663 — Arm Mali Graphics Processing Unit (GPU): Arm Mali Graphics Processing Unit (GPU) Use-After-Free Vulnerability
Arm Mali Graphics Processing Unit (GPU) kernel driver contains a use-after-free vulnerability that may allow a non-privileged user to make improper operations on GPU memory to gain root privilege, and/or disclose information.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.121 (95.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2021-11-17
Known ransomware campaign use: Unknown/None
CVE-2017-11292 — Adobe Flash Player: Adobe Flash Player Type Confusion Vulnerability
Adobe Flash Player contains a type confusion vulnerability which can allow for remote code execution.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: The impacted product is end-of-life and should be disconnected if still in use.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.119 (95.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-03
CISA remediation due: 2022-03-24
Known ransomware campaign use: Unknown/None
CVE-2020-8599 — Trend Micro Apex One and OfficeScan: Trend Micro Apex One and OfficeScan Authentication Bypass Vulnerability
Trend Micro Apex One and OfficeScan server contain a vulnerable EXE file that could allow a remote attacker to write data to a path on affected installations and bypass root login.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.119 (95.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2026-15410 — SonicWall SMA1000 Appliances: SonicWall SMA1000 Appliances Code Injection Vulnerability
SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVSS: 7.2 (NVD)
FIRST EPSS: 0.118 (95.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-07-14
CISA remediation due: 2026-07-17
Known ransomware campaign use: Known
CVE-2020-3118 — Cisco IOS XR: Cisco IOS XR Software Discovery Protocol Format String Vulnerability
Cisco IOS XR improperly validates string input from certain fields in Cisco Discovery Protocol messages. Exploitation could allow an unauthenticated, adjacent attacker to execute code with administrative privileges or cause a reload on an affected device.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.117 (95.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2021-37973 — Google Chromium Portals: Google Chromium Portals Use-After-Free Vulnerability
Google Chromium Portals contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability affects web browsers that utilize Chromium, including Google Chrome and Microsoft Edge.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.6 (NVD)
FIRST EPSS: 0.116 (95.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2021-11-17
Known ransomware campaign use: Unknown/None
CVE-2022-22587 — Apple iOS and macOS: Apple Memory Corruption Vulnerability
Apple IOMobileFrameBuffer contains a memory corruption vulnerability which can allow a malicious application to execute arbitrary code with kernel privileges.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.116 (95.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-01-28
CISA remediation due: 2022-02-11
Known ransomware campaign use: Unknown/None
CVE-2025-48927 — TeleMessage TM SGNL: TeleMessage TM SGNL Initialization of a Resource with an Insecure Default Vulnerability
TeleMessage TM SGNL contains an initialization of a resource with an insecure default vulnerability. This vulnerability relies on how the Spring Boot Actuator is configured with an exposed heap dump endpoint at a /heapdump URI.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 5.3 (NVD)
FIRST EPSS: 0.111 (95.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-07-01
CISA remediation due: 2025-07-22
Known ransomware campaign use: Unknown/None
CVE-2013-0648 — Adobe Flash Player: Adobe Flash Player Code Execution Vulnerability
Adobe Flash Player contains an unspecified vulnerability in the ExternalInterface ActionScript functionality that allows a remote attacker to execute arbitrary code via crafted SWF content.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.111 (95.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-09-17
CISA remediation due: 2024-10-08
Known ransomware campaign use: Unknown/None
CVE-2026-48710 — Kludex Starlette: Kludex Starlette HTTP Request/Response Smuggling Vulnerability
Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentication bypass when the authentication depends on the reconstructed URL’s path. This vulnerability could be chaned with CVE-2026-42271.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVSS: 6.5 (NVD)
FIRST EPSS: 0.110 (95.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-09-02
CISA remediation due: 2026-09-16
Known ransomware campaign use: Unknown/None
CVE-2024-4761 — Google Chromium V8: Google Chromium V8 Out-of-Bounds Memory Write Vulnerability
Google Chromium V8 Engine contains an unspecified out-of-bounds memory write vulnerability via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.110 (95.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-05-16
CISA remediation due: 2024-06-06
Known ransomware campaign use: Unknown/None
CVE-2021-30762 — Apple iOS: Apple iOS WebKit Use-After-Free Vulnerability
Apple iOS WebKit contains a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.110 (95.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2021-11-17
Known ransomware campaign use: Unknown/None