Cross-Vendor Patch Advisories

Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.

Browse Advisories

Association
Vendor — all

Leave every box clear to show all 282 vendors.

1,308 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.

CISA KEV advisories matching the current filters, ranked by EVULNABLE Risk Score
CVE Vendor Product Vulnerability EVRS EPSS Ransomware CISA due
CVE-2025-13223 Google Chromium V8 Google Chromium V8 Type Confusion Vulnerability 75 Urgent 0.050 (91.7th pctl) Unknown/None 2025-12-10
CVE-2026-25108 Soliton Systems K.K FileZen Soliton Systems K.K FileZen OS Command Injection Vulnerability 75 Urgent 0.050 (91.6th pctl) Unknown/None 2026-03-17
CVE-2018-0179 Cisco IOS Software Cisco IOS Software Denial-of-Service Vulnerability 75 Urgent 0.050 (91.6th pctl) Unknown/None 2022-03-17
CVE-2018-0180 Cisco IOS Software Cisco IOS Software Denial-of-Service Vulnerability 75 Urgent 0.050 (91.6th pctl) Unknown/None 2022-03-17
CVE-2015-5287 Red Hat Automatic Bug Reporting Tool Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability 75 Urgent 0.050 (91.6th pctl) Unknown/None 2026-09-09
CVE-2021-36741 Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security Trend Micro Multiple Products Improper Input Validation Vulnerability 75 Urgent 0.050 (91.6th pctl) Unknown/None 2021-11-17
CVE-2019-16256 SIMalliance Toolbox Browser SIMalliance Toolbox Browser Command Injection Vulnerability 75 Urgent 0.049 (91.6th pctl) Unknown/None 2022-05-03
CVE-2026-5281 Google Dawn Google Dawn Use-After-Free Vulnerability 75 Urgent 0.049 (91.6th pctl) Unknown/None 2026-04-15
CVE-2023-41179 Trend Micro Apex One and Worry-Free Business Security Trend Micro Apex One and Worry-Free Business Security Remote Code Execution Vulnerability 75 Urgent 0.047 (91.2nd pctl) Unknown/None 2023-10-12
CVE-2020-1631 Juniper Junos OS Juniper Junos OS Path Traversal Vulnerability 75 Urgent 0.047 (91.2nd pctl) Unknown/None 2022-04-15
CVE-2004-1464 Cisco IOS Cisco IOS Denial-of-Service Vulnerability 75 Urgent 0.047 (91.2nd pctl) Unknown/None 2023-06-09
CVE-2019-18988 TeamViewer Desktop TeamViewer Desktop Bypass Remote Login Vulnerability 75 Urgent 0.047 (91.2nd pctl) Unknown/None 2022-05-03
CVE-2012-0518 Oracle Fusion Middleware Oracle Fusion Middleware Unspecified Vulnerability 75 Urgent 0.047 (91.2nd pctl) Unknown/None 2022-04-18
CVE-2021-38000 Google Chromium Intents Google Chromium Intents Improper Input Validation Vulnerability 75 Urgent 0.047 (91.1st pctl) Unknown/None 2021-11-17
CVE-2019-7287 Apple iOS Apple iOS Memory Corruption Vulnerability 75 Urgent 0.046 (90.9th pctl) Unknown/None 2022-06-13
CVE-2023-41991 Apple Multiple Products Apple Multiple Products Improper Certificate Validation Vulnerability 75 Urgent 0.045 (90.9th pctl) Unknown/None 2023-10-16
CVE-2022-2856 Google Chromium Intents Google Chromium Intents Insufficient Input Validation Vulnerability 75 Urgent 0.045 (90.9th pctl) Unknown/None 2022-09-08
CVE-2021-30661 Apple Multiple Products Apple Multiple Products WebKit Storage Use-After-Free Vulnerability 75 Urgent 0.045 (90.8th pctl) Unknown/None 2021-11-17
CVE-2023-46748 F5 BIG-IP Configuration Utility F5 BIG-IP Configuration Utility SQL Injection Vulnerability 75 Urgent 0.045 (90.8th pctl) Unknown/None 2023-11-21
CVE-2026-20045 Cisco Unified Communications Manager Cisco Unified Communications Products Code Injection Vulnerability 75 Urgent 0.044 (90.6th pctl) Unknown/None 2026-02-11
CVE-2025-24200 Apple iOS and iPadOS Apple iOS and iPadOS Incorrect Authorization Vulnerability 75 Urgent 0.044 (90.6th pctl) Unknown/None 2025-03-05
CVE-2025-54313 Prettier eslint-config-prettier Prettier eslint-config-prettier Embedded Malicious Code Vulnerability 75 Urgent 0.043 (90.6th pctl) Unknown/None 2026-02-12
CVE-2024-20399 Cisco NX-OS Cisco NX-OS Command Injection Vulnerability 75 Urgent 0.043 (90.5th pctl) Unknown/None 2024-07-23
CVE-2025-55177 Meta Platforms WhatsApp Meta Platforms WhatsApp Incorrect Authorization Vulnerability 75 Urgent 0.042 (90.3rd pctl) Unknown/None 2025-09-23
CVE-2021-30869 Apple iOS, iPadOS, and macOS Apple iOS, iPadOS, and macOS Type Confusion Vulnerability 75 Urgent 0.042 (90.2nd pctl) Unknown/None 2021-11-17
Download filtered advisories (CSV)

Exactly the 1,308 advisory(ies) matching the filters above.

Advisory detail

Expand any advisory for its description, CISA's own required action, and research links.

CVE-2025-13223 — Google Chromium V8: Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 contains a type confusion vulnerability that allows for heap corruption.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.050 (91.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-11-19

CISA remediation due: 2025-12-10

Known ransomware campaign use: Unknown/None

CVE-2026-25108 — Soliton Systems K.K FileZen: Soliton Systems K.K FileZen OS Command Injection Vulnerability

Soliton Systems K.K FileZen contains an OS command injection vulnerability when an user logs-in to the affected product and sends a specially crafted HTTP request.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 8.7 (NVD)

FIRST EPSS: 0.050 (91.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-02-24

CISA remediation due: 2026-03-17

Known ransomware campaign use: Unknown/None

CVE-2018-0179 — Cisco IOS Software: Cisco IOS Software Denial-of-Service Vulnerability

A vulnerability in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 5.9 (NVD)

FIRST EPSS: 0.050 (91.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-03

CISA remediation due: 2022-03-17

Known ransomware campaign use: Unknown/None

CVE-2018-0180 — Cisco IOS Software: Cisco IOS Software Denial-of-Service Vulnerability

A vulnerability in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 5.9 (NVD)

FIRST EPSS: 0.050 (91.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-03

CISA remediation due: 2022-03-17

Known ransomware campaign use: Unknown/None

CVE-2015-5287 — Red Hat Automatic Bug Reporting Tool: Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability

Red Hat Automatic Bug Reporting Tool (ABRT) contains a privilege escalation vulnerability that could allow local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.050 (91.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-08-26

CISA remediation due: 2026-09-09

Known ransomware campaign use: Unknown/None

CVE-2021-36741 — Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security: Trend Micro Multiple Products Improper Input Validation Vulnerability

Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security contain an improper input validation vulnerability that allows a remote attacker to upload files.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.050 (91.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2021-11-17

Known ransomware campaign use: Unknown/None

CVE-2019-16256 — SIMalliance Toolbox Browser: SIMalliance Toolbox Browser Command Injection Vulnerability

SIMalliance Toolbox Browser contains an command injection vulnerability that could allow remote attackers to retrieve location and IMEI information or execute a range of other attacks by modifying the attack message.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.049 (91.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2026-5281 — Google Dawn: Google Dawn Use-After-Free Vulnerability

Google Dawn contains an use-after-free vulnerability that could allow a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. This vulnerability could affect multiple Chromium-based products including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.049 (91.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-04-01

CISA remediation due: 2026-04-15

Known ransomware campaign use: Unknown/None

CVE-2023-41179 — Trend Micro Apex One and Worry-Free Business Security: Trend Micro Apex One and Worry-Free Business Security Remote Code Execution Vulnerability

Trend Micro Apex One and Worry-Free Business Security contain an unspecified vulnerability in the third-party anti-virus uninstaller that could allow an attacker to manipulate the module to conduct remote code execution. An attacker must first obtain administrative console access on the target system in order to exploit this vulnerability.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 7.2 (NVD)

FIRST EPSS: 0.047 (91.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-09-21

CISA remediation due: 2023-10-12

Known ransomware campaign use: Unknown/None

CVE-2020-1631 — Juniper Junos OS: Juniper Junos OS Path Traversal Vulnerability

A path traversal vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication Pass-Through with Web-Redirect, and Zero Touch Provisioning (ZTP) allows an unauthenticated attacker to perform remote code execution.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.047 (91.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-25

CISA remediation due: 2022-04-15

Known ransomware campaign use: Unknown/None

CVE-2004-1464 — Cisco IOS: Cisco IOS Denial-of-Service Vulnerability

Cisco IOS contains an unspecified vulnerability that may block further telnet, reverse telnet, Remote Shell (RSH), Secure Shell (SSH), and in some cases, Hypertext Transport Protocol (HTTP) access to the Cisco device.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 5.9 (NVD)

FIRST EPSS: 0.047 (91.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-05-19

CISA remediation due: 2023-06-09

Known ransomware campaign use: Unknown/None

CVE-2019-18988 — TeamViewer Desktop: TeamViewer Desktop Bypass Remote Login Vulnerability

TeamViewer Desktop allows for bypass of remote-login access control because the same AES key is used for different customers' installations. If an attacker were to know this key, they could decrypt protected information stored in registry or configuration files or decryption of the Unattended Access password to the system (which allows for remote login to the system).

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.0 (NVD)

FIRST EPSS: 0.047 (91.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2012-0518 — Oracle Fusion Middleware: Oracle Fusion Middleware Unspecified Vulnerability

Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware allows remote attackers to affect integrity via Unknown vectors

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 4.7 (NVD)

FIRST EPSS: 0.047 (91.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-28

CISA remediation due: 2022-04-18

Known ransomware campaign use: Unknown/None

CVE-2021-38000 — Google Chromium Intents: Google Chromium Intents Improper Input Validation Vulnerability

Google Chromium Intents contains an improper input validation vulnerability that allows a remote attacker to arbitrarily browser to a malicious URL via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 6.1 (NVD)

FIRST EPSS: 0.047 (91.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2021-11-17

Known ransomware campaign use: Unknown/None

CVE-2019-7287 — Apple iOS: Apple iOS Memory Corruption Vulnerability

Apple iOS contains a memory corruption vulnerability which could allow an attacker to perform remote code execution.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.046 (90.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-05-23

CISA remediation due: 2022-06-13

Known ransomware campaign use: Unknown/None

CVE-2023-41991 — Apple Multiple Products: Apple Multiple Products Improper Certificate Validation Vulnerability

Apple iOS, iPadOS, macOS, and watchOS contain an improper certificate validation vulnerability that can allow a malicious app to bypass signature validation.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 5.5 (NVD)

FIRST EPSS: 0.045 (90.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-09-25

CISA remediation due: 2023-10-16

Known ransomware campaign use: Unknown/None

CVE-2022-2856 — Google Chromium Intents: Google Chromium Intents Insufficient Input Validation Vulnerability

Google Chromium Intents contains an insufficient validation of untrusted input vulnerability that allows a remote attacker to browse to a malicious website via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 6.5 (NVD)

FIRST EPSS: 0.045 (90.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-08-18

CISA remediation due: 2022-09-08

Known ransomware campaign use: Unknown/None

CVE-2021-30661 — Apple Multiple Products: Apple Multiple Products WebKit Storage Use-After-Free Vulnerability

Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit Storage contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.045 (90.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2021-11-17

Known ransomware campaign use: Unknown/None

CVE-2023-46748 — F5 BIG-IP Configuration Utility: F5 BIG-IP Configuration Utility SQL Injection Vulnerability

F5 BIG-IP Configuration utility contains an SQL injection vulnerability that may allow an authenticated attacker with network access through the BIG-IP management port and/or self IP addresses to execute system commands. This vulnerability can be used in conjunction with CVE-2023-46747.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.045 (90.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-10-31

CISA remediation due: 2023-11-21

Known ransomware campaign use: Unknown/None

CVE-2026-20045 — Cisco Unified Communications Manager: Cisco Unified Communications Products Code Injection Vulnerability

Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unity Connection, and Cisco Webex Calling Dedicated Instance contain a code injection vulnerability that could allow the attacker to obtain user-level access to the underlying operating system and then elevate privileges to root.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.044 (90.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-01-21

CISA remediation due: 2026-02-11

Known ransomware campaign use: Unknown/None

CVE-2025-24200 — Apple iOS and iPadOS: Apple iOS and iPadOS Incorrect Authorization Vulnerability

Apple iOS and iPadOS contains an incorrect authorization vulnerability that allows a physical attacker to disable USB Restricted Mode on a locked device.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 6.1 (NVD)

FIRST EPSS: 0.044 (90.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-02-12

CISA remediation due: 2025-03-05

Known ransomware campaign use: Unknown/None

CVE-2025-54313 — Prettier eslint-config-prettier: Prettier eslint-config-prettier Embedded Malicious Code Vulnerability

Prettier eslint-config-prettier contains an embedded malicious code vulnerability. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.043 (90.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-01-22

CISA remediation due: 2026-02-12

Known ransomware campaign use: Unknown/None

CVE-2024-20399 — Cisco NX-OS: Cisco NX-OS Command Injection Vulnerability

Cisco NX-OS contains a command injection vulnerability in the command line interface (CLI) that could allow an authenticated, local attacker to execute commands as root on the underlying operating system of an affected device.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 6.7 (NVD)

FIRST EPSS: 0.043 (90.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-07-02

CISA remediation due: 2024-07-23

Known ransomware campaign use: Unknown/None

CVE-2025-55177 — Meta Platforms WhatsApp: Meta Platforms WhatsApp Incorrect Authorization Vulnerability

Meta Platforms WhatsApp contains an incorrect authorization vulnerability due to an incomplete authorization of linked device synchronization messages. This vulnerability could allow an unrelated user to trigger processing of content from an arbitrary URL on a target’s device.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 5.4 (NVD)

FIRST EPSS: 0.042 (90.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-09-02

CISA remediation due: 2025-09-23

Known ransomware campaign use: Unknown/None

CVE-2021-30869 — Apple iOS, iPadOS, and macOS: Apple iOS, iPadOS, and macOS Type Confusion Vulnerability

Apple iOS, iPadOS, and macOS contain a type confusion vulnerability in the XNU which may allow a malicious application to execute code with kernel privileges.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.042 (90.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2021-11-17

Known ransomware campaign use: Unknown/None

Data sources & attribution

Known-exploitation status, required actions, ransomware association and remediation deadlines come from the CISA Known Exploited Vulnerabilities Catalog. Exploitation probability and percentile are provided by FIRST.org's EPSS, used under FIRST's open data terms.

Microsoft Patch Tuesday data is sourced from the Microsoft Security Update Guide; lifecycle milestones from endoflife.date. Linux distribution advisories come from Red Hat, Ubuntu and Debian; vendor bulletins from Adobe, Apple, Chrome, Cisco, Ivanti and Oracle, each linked to its own advisory.