Cross-Vendor Patch Advisories
Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.
Browse Advisories
1,308 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.
| CVE | Vendor | Product | Vulnerability | EVRS | EPSS | Ransomware | CISA due |
|---|---|---|---|---|---|---|---|
| CVE-2020-8467 | Trend Micro | Apex One and OfficeScan | Trend Micro Apex One and OfficeScan Remote Code Execution Vulnerability | 75 Urgent | 0.108 (95.5th pctl) | Unknown/None | 2022-05-03 |
| CVE-2017-6740 | Cisco | IOS and IOS XE Software | Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability | 75 Urgent | 0.108 (95.5th pctl) | Unknown/None | 2022-03-24 |
| CVE-2017-1000253 | Linux | Kernel | Linux Kernel PIE Stack Buffer Corruption Vulnerability | 75 Urgent | 0.107 (95.5th pctl) | Known | 2024-09-30 |
| CVE-2020-15069 | Sophos | XG Firewall | Sophos XG Firewall Buffer Overflow Vulnerability | 75 Urgent | 0.107 (95.5th pctl) | Unknown/None | 2025-02-27 |
| CVE-2024-23222 | Apple | Multiple Products | Apple Multiple Products WebKit Type Confusion Vulnerability | 75 Urgent | 0.106 (95.5th pctl) | Unknown/None | 2024-02-13 |
| CVE-2020-6572 | Chrome Media | Google Chrome Media Use-After-Free Vulnerability | 75 Urgent | 0.106 (95.5th pctl) | Unknown/None | 2022-07-10 | |
| CVE-2022-41223 | Mitel | MiVoice Connect | Mitel MiVoice Connect Code Injection Vulnerability | 75 Urgent | 0.106 (95.5th pctl) | Known | 2023-03-14 |
| CVE-2017-6738 | Cisco | IOS and IOS XE Software | Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability | 75 Urgent | 0.105 (95.5th pctl) | Unknown/None | 2022-03-24 |
| CVE-2017-6739 | Cisco | IOS and IOS XE Software | Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability | 75 Urgent | 0.105 (95.5th pctl) | Unknown/None | 2022-03-24 |
| CVE-2017-6743 | Cisco | IOS and IOS XE Software | Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability | 75 Urgent | 0.105 (95.5th pctl) | Unknown/None | 2022-03-24 |
| CVE-2021-30761 | Apple | iOS | Apple iOS WebKit Memory Corruption Vulnerability | 75 Urgent | 0.105 (95.5th pctl) | Unknown/None | 2021-11-17 |
| CVE-2013-0643 | Adobe | Flash Player | Adobe Flash Player Incorrect Default Permissions Vulnerability | 75 Urgent | 0.105 (95.4th pctl) | Unknown/None | 2024-10-08 |
| CVE-2022-40765 | Mitel | MiVoice Connect | Mitel MiVoice Connect Command Injection Vulnerability | 75 Urgent | 0.105 (95.4th pctl) | Known | 2023-03-14 |
| CVE-2022-2586 | Linux | Kernel | Linux Kernel Use-After-Free Vulnerability | 75 Urgent | 0.105 (95.4th pctl) | Unknown/None | 2024-07-17 |
| CVE-2020-27932 | Apple | Multiple Products | Apple Multiple Products Type Confusion Vulnerability | 75 Urgent | 0.103 (95.4th pctl) | Unknown/None | 2022-05-03 |
| CVE-2025-6543 | Citrix | NetScaler ADC and Gateway | Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerability | 75 Urgent | 0.101 (95.3rd pctl) | Unknown/None | 2025-07-21 |
| CVE-2024-6047 | GeoVision | Multiple Devices | GeoVision Devices OS Command Injection Vulnerability | 75 Urgent | 0.101 (95.3rd pctl) | Unknown/None | 2025-05-28 |
| CVE-2020-3433 | Cisco | AnyConnect Secure | Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability | 75 Urgent | 0.100 (95.3rd pctl) | Known | 2022-11-14 |
| CVE-2026-65400 | Apple | macOS | Apple macOS Improper Authentication Vulnerability | 75 Urgent | 0.099 (95.2nd pctl) | Unknown/None | 2026-08-21 |
| CVE-2015-1130 | Apple | OS X | Apple OS X Authentication Bypass Vulnerability | 75 Urgent | 0.099 (95.2nd pctl) | Unknown/None | 2022-08-10 |
| CVE-2021-21193 | Chromium Blink | Google Chromium Blink Use-After-Free Vulnerability | 75 Urgent | 0.099 (95.2nd pctl) | Unknown/None | 2021-11-17 | |
| CVE-2022-32893 | Apple | iOS and macOS | Apple iOS and macOS Out-of-Bounds Write Vulnerability | 75 Urgent | 0.099 (95.2nd pctl) | Unknown/None | 2022-09-08 |
| CVE-2026-20316 | Cisco | Secure Firewall Management Center (FMC) | Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability | 75 Urgent | 0.098 (95.2nd pctl) | Unknown/None | 2026-08-01 |
| CVE-2022-20701 | Cisco | Small Business RV160, RV260, RV340, and RV345 Series Routers | Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability | 75 Urgent | 0.097 (95.2nd pctl) | Unknown/None | 2022-03-17 |
| CVE-2025-6558 | Chromium | Google Chromium ANGLE and GPU Improper Input Validation Vulnerability | 75 Urgent | 0.096 (95.1st pctl) | Unknown/None | 2025-08-12 |
Exactly the 1,308 advisory(ies) matching the filters above.
Advisory detail
Expand any advisory for its description, CISA's own required action, and research links.
CVE-2020-8467 — Trend Micro Apex One and OfficeScan: Trend Micro Apex One and OfficeScan Remote Code Execution Vulnerability
Trend Micro Apex One and OfficeScan contain an unspecified vulnerability within a migration tool component that allows for remote code execution.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.108 (95.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2017-6740 — Cisco IOS and IOS XE Software: Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.108 (95.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-03
CISA remediation due: 2022-03-24
Known ransomware campaign use: Unknown/None
CVE-2017-1000253 — Linux Kernel: Linux Kernel PIE Stack Buffer Corruption Vulnerability
Linux kernel contains a position-independent executable (PIE) stack buffer corruption vulnerability in load_elf_ binary() that allows a local attacker to escalate privileges.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.107 (95.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-09-09
CISA remediation due: 2024-09-30
Known ransomware campaign use: Known
CVE-2020-15069 — Sophos XG Firewall: Sophos XG Firewall Buffer Overflow Vulnerability
Sophos XG Firewall contains a buffer overflow vulnerability that allows for remote code execution via the "HTTP/S bookmark" feature.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.107 (95.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-02-06
CISA remediation due: 2025-02-27
Known ransomware campaign use: Unknown/None
CVE-2024-23222 — Apple Multiple Products: Apple Multiple Products WebKit Type Confusion Vulnerability
Apple iOS, iPadOS, macOS, tvOS, and Safari WebKit contain a type confusion vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.106 (95.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-01-23
CISA remediation due: 2024-02-13
Known ransomware campaign use: Unknown/None
CVE-2020-6572 — Google Chrome Media: Google Chrome Media Use-After-Free Vulnerability
Google Chrome Media contains a use-after-free vulnerability that allows a remote attacker to execute code via a crafted HTML page.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.106 (95.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-01-10
CISA remediation due: 2022-07-10
Known ransomware campaign use: Unknown/None
CVE-2022-41223 — Mitel MiVoice Connect: Mitel MiVoice Connect Code Injection Vulnerability
The Director component in Mitel MiVoice Connect allows an authenticated attacker with internal network access to execute code within the context of the application.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 6.8 (NVD)
FIRST EPSS: 0.106 (95.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-02-21
CISA remediation due: 2023-03-14
Known ransomware campaign use: Known
CVE-2017-6738 — Cisco IOS and IOS XE Software: Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.105 (95.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-03
CISA remediation due: 2022-03-24
Known ransomware campaign use: Unknown/None
CVE-2017-6739 — Cisco IOS and IOS XE Software: Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.105 (95.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-03
CISA remediation due: 2022-03-24
Known ransomware campaign use: Unknown/None
CVE-2017-6743 — Cisco IOS and IOS XE Software: Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.105 (95.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-03
CISA remediation due: 2022-03-24
Known ransomware campaign use: Unknown/None
CVE-2021-30761 — Apple iOS: Apple iOS WebKit Memory Corruption Vulnerability
Apple iOS WebKit contains a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.105 (95.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2021-11-17
Known ransomware campaign use: Unknown/None
CVE-2013-0643 — Adobe Flash Player: Adobe Flash Player Incorrect Default Permissions Vulnerability
Adobe Flash Player contains an incorrect default permissions vulnerability in the Firefox sandbox that allows a remote attacker to execute arbitrary code via crafted SWF content.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.105 (95.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-09-17
CISA remediation due: 2024-10-08
Known ransomware campaign use: Unknown/None
CVE-2022-40765 — Mitel MiVoice Connect: Mitel MiVoice Connect Command Injection Vulnerability
The Mitel Edge Gateway component of MiVoice Connect allows an authenticated attacker with internal network access to execute commands within the context of the system.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 6.8 (NVD)
FIRST EPSS: 0.105 (95.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-02-21
CISA remediation due: 2023-03-14
Known ransomware campaign use: Known
CVE-2022-2586 — Linux Kernel: Linux Kernel Use-After-Free Vulnerability
Linux Kernel contains a use-after-free vulnerability in the nft_object, allowing local attackers to escalate privileges.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.105 (95.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-06-26
CISA remediation due: 2024-07-17
Known ransomware campaign use: Unknown/None
CVE-2020-27932 — Apple Multiple Products: Apple Multiple Products Type Confusion Vulnerability
Apple iOS, iPadOS, macOS, and watchOS contain a type confusion vulnerability that may allow a malicious application to execute code with kernel privileges.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.103 (95.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2025-6543 — Citrix NetScaler ADC and Gateway: Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerability
Citrix NetScaler ADC and Gateway contain a buffer overflow vulnerability leading to unintended control flow and Denial of Service. NetScaler must be configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.2 (NVD)
FIRST EPSS: 0.101 (95.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-06-30
CISA remediation due: 2025-07-21
Known ransomware campaign use: Unknown/None
CVE-2024-6047 — GeoVision Multiple Devices: GeoVision Devices OS Command Injection Vulnerability
Multiple GeoVision devices contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to inject and execute arbitrary system commands. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.101 (95.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-05-07
CISA remediation due: 2025-05-28
Known ransomware campaign use: Unknown/None
CVE-2020-3433 — Cisco AnyConnect Secure: Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability
Cisco AnyConnect Secure Mobility Client for Windows interprocess communication (IPC) channel allows for insufficient validation of resources that are loaded by the application at run time. An attacker with valid credentials on Windows could execute code on the affected machine with SYSTEM privileges.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.100 (95.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-10-24
CISA remediation due: 2022-11-14
Known ransomware campaign use: Known
CVE-2026-65400 — Apple macOS: Apple macOS Improper Authentication Vulnerability
Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.099 (95.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-08-18
CISA remediation due: 2026-08-21
Known ransomware campaign use: Unknown/None
CVE-2015-1130 — Apple OS X: Apple OS X Authentication Bypass Vulnerability
The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.099 (95.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-02-10
CISA remediation due: 2022-08-10
Known ransomware campaign use: Unknown/None
CVE-2021-21193 — Google Chromium Blink: Google Chromium Blink Use-After-Free Vulnerability
Google Chromium Blink contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.099 (95.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2021-11-17
Known ransomware campaign use: Unknown/None
CVE-2022-32893 — Apple iOS and macOS: Apple iOS and macOS Out-of-Bounds Write Vulnerability
Apple iOS and macOS contain an out-of-bounds write vulnerability that could allow for remote code execution when processing malicious crafted web content.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.099 (95.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-08-18
CISA remediation due: 2022-09-08
Known ransomware campaign use: Unknown/None
CVE-2026-20316 — Cisco Secure Firewall Management Center (FMC): Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability
Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVSS: 5.3 (Cisco (estimated))
FIRST EPSS: 0.098 (95.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-07-29
CISA remediation due: 2026-08-01
Known ransomware campaign use: Unknown/None
CVE-2022-20701 — Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers: Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability
A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.097 (95.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-03
CISA remediation due: 2022-03-17
Known ransomware campaign use: Unknown/None
CVE-2025-6558 — Google Chromium: Google Chromium ANGLE and GPU Improper Input Validation Vulnerability
Google Chromium contains an improper input validation vulnerability in ANGLE and GPU. This vulnerability could allow a remote attacker to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.096 (95.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-07-22
CISA remediation due: 2025-08-12
Known ransomware campaign use: Unknown/None