Cross-Vendor Patch Advisories
Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.
Browse Advisories
1,308 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.
| CVE | Vendor | Product | Vulnerability | EVRS | EPSS | Ransomware | CISA due |
|---|---|---|---|---|---|---|---|
| CVE-2025-13223 | Chromium V8 | Google Chromium V8 Type Confusion Vulnerability | 75 Urgent | 0.050 (91.7th pctl) | Unknown/None | 2025-12-10 | |
| CVE-2026-25108 | Soliton Systems K.K | FileZen | Soliton Systems K.K FileZen OS Command Injection Vulnerability | 75 Urgent | 0.050 (91.6th pctl) | Unknown/None | 2026-03-17 |
| CVE-2018-0179 | Cisco | IOS Software | Cisco IOS Software Denial-of-Service Vulnerability | 75 Urgent | 0.050 (91.6th pctl) | Unknown/None | 2022-03-17 |
| CVE-2018-0180 | Cisco | IOS Software | Cisco IOS Software Denial-of-Service Vulnerability | 75 Urgent | 0.050 (91.6th pctl) | Unknown/None | 2022-03-17 |
| CVE-2015-5287 | Red Hat | Automatic Bug Reporting Tool | Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability | 75 Urgent | 0.050 (91.6th pctl) | Unknown/None | 2026-09-09 |
| CVE-2021-36741 | Trend Micro | Apex One, Apex One as a Service, and Worry-Free Business Security | Trend Micro Multiple Products Improper Input Validation Vulnerability | 75 Urgent | 0.050 (91.6th pctl) | Unknown/None | 2021-11-17 |
| CVE-2019-16256 | SIMalliance | Toolbox Browser | SIMalliance Toolbox Browser Command Injection Vulnerability | 75 Urgent | 0.049 (91.6th pctl) | Unknown/None | 2022-05-03 |
| CVE-2026-5281 | Dawn | Google Dawn Use-After-Free Vulnerability | 75 Urgent | 0.049 (91.6th pctl) | Unknown/None | 2026-04-15 | |
| CVE-2023-41179 | Trend Micro | Apex One and Worry-Free Business Security | Trend Micro Apex One and Worry-Free Business Security Remote Code Execution Vulnerability | 75 Urgent | 0.047 (91.2nd pctl) | Unknown/None | 2023-10-12 |
| CVE-2020-1631 | Juniper | Junos OS | Juniper Junos OS Path Traversal Vulnerability | 75 Urgent | 0.047 (91.2nd pctl) | Unknown/None | 2022-04-15 |
| CVE-2004-1464 | Cisco | IOS | Cisco IOS Denial-of-Service Vulnerability | 75 Urgent | 0.047 (91.2nd pctl) | Unknown/None | 2023-06-09 |
| CVE-2019-18988 | TeamViewer | Desktop | TeamViewer Desktop Bypass Remote Login Vulnerability | 75 Urgent | 0.047 (91.2nd pctl) | Unknown/None | 2022-05-03 |
| CVE-2012-0518 | Oracle | Fusion Middleware | Oracle Fusion Middleware Unspecified Vulnerability | 75 Urgent | 0.047 (91.2nd pctl) | Unknown/None | 2022-04-18 |
| CVE-2021-38000 | Chromium Intents | Google Chromium Intents Improper Input Validation Vulnerability | 75 Urgent | 0.047 (91.1st pctl) | Unknown/None | 2021-11-17 | |
| CVE-2019-7287 | Apple | iOS | Apple iOS Memory Corruption Vulnerability | 75 Urgent | 0.046 (90.9th pctl) | Unknown/None | 2022-06-13 |
| CVE-2023-41991 | Apple | Multiple Products | Apple Multiple Products Improper Certificate Validation Vulnerability | 75 Urgent | 0.045 (90.9th pctl) | Unknown/None | 2023-10-16 |
| CVE-2022-2856 | Chromium Intents | Google Chromium Intents Insufficient Input Validation Vulnerability | 75 Urgent | 0.045 (90.9th pctl) | Unknown/None | 2022-09-08 | |
| CVE-2021-30661 | Apple | Multiple Products | Apple Multiple Products WebKit Storage Use-After-Free Vulnerability | 75 Urgent | 0.045 (90.8th pctl) | Unknown/None | 2021-11-17 |
| CVE-2023-46748 | F5 | BIG-IP Configuration Utility | F5 BIG-IP Configuration Utility SQL Injection Vulnerability | 75 Urgent | 0.045 (90.8th pctl) | Unknown/None | 2023-11-21 |
| CVE-2026-20045 | Cisco | Unified Communications Manager | Cisco Unified Communications Products Code Injection Vulnerability | 75 Urgent | 0.044 (90.6th pctl) | Unknown/None | 2026-02-11 |
| CVE-2025-24200 | Apple | iOS and iPadOS | Apple iOS and iPadOS Incorrect Authorization Vulnerability | 75 Urgent | 0.044 (90.6th pctl) | Unknown/None | 2025-03-05 |
| CVE-2025-54313 | Prettier | eslint-config-prettier | Prettier eslint-config-prettier Embedded Malicious Code Vulnerability | 75 Urgent | 0.043 (90.6th pctl) | Unknown/None | 2026-02-12 |
| CVE-2024-20399 | Cisco | NX-OS | Cisco NX-OS Command Injection Vulnerability | 75 Urgent | 0.043 (90.5th pctl) | Unknown/None | 2024-07-23 |
| CVE-2025-55177 | Meta Platforms | Meta Platforms WhatsApp Incorrect Authorization Vulnerability | 75 Urgent | 0.042 (90.3rd pctl) | Unknown/None | 2025-09-23 | |
| CVE-2021-30869 | Apple | iOS, iPadOS, and macOS | Apple iOS, iPadOS, and macOS Type Confusion Vulnerability | 75 Urgent | 0.042 (90.2nd pctl) | Unknown/None | 2021-11-17 |
Exactly the 1,308 advisory(ies) matching the filters above.
Advisory detail
Expand any advisory for its description, CISA's own required action, and research links.
CVE-2025-13223 — Google Chromium V8: Google Chromium V8 Type Confusion Vulnerability
Google Chromium V8 contains a type confusion vulnerability that allows for heap corruption.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.050 (91.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-11-19
CISA remediation due: 2025-12-10
Known ransomware campaign use: Unknown/None
CVE-2026-25108 — Soliton Systems K.K FileZen: Soliton Systems K.K FileZen OS Command Injection Vulnerability
Soliton Systems K.K FileZen contains an OS command injection vulnerability when an user logs-in to the affected product and sends a specially crafted HTTP request.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 8.7 (NVD)
FIRST EPSS: 0.050 (91.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-02-24
CISA remediation due: 2026-03-17
Known ransomware campaign use: Unknown/None
CVE-2018-0179 — Cisco IOS Software: Cisco IOS Software Denial-of-Service Vulnerability
A vulnerability in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 5.9 (NVD)
FIRST EPSS: 0.050 (91.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-03
CISA remediation due: 2022-03-17
Known ransomware campaign use: Unknown/None
CVE-2018-0180 — Cisco IOS Software: Cisco IOS Software Denial-of-Service Vulnerability
A vulnerability in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 5.9 (NVD)
FIRST EPSS: 0.050 (91.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-03
CISA remediation due: 2022-03-17
Known ransomware campaign use: Unknown/None
CVE-2015-5287 — Red Hat Automatic Bug Reporting Tool: Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
Red Hat Automatic Bug Reporting Tool (ABRT) contains a privilege escalation vulnerability that could allow local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.050 (91.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-08-26
CISA remediation due: 2026-09-09
Known ransomware campaign use: Unknown/None
CVE-2021-36741 — Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security: Trend Micro Multiple Products Improper Input Validation Vulnerability
Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security contain an improper input validation vulnerability that allows a remote attacker to upload files.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.050 (91.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2021-11-17
Known ransomware campaign use: Unknown/None
CVE-2019-16256 — SIMalliance Toolbox Browser: SIMalliance Toolbox Browser Command Injection Vulnerability
SIMalliance Toolbox Browser contains an command injection vulnerability that could allow remote attackers to retrieve location and IMEI information or execute a range of other attacks by modifying the attack message.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.049 (91.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2026-5281 — Google Dawn: Google Dawn Use-After-Free Vulnerability
Google Dawn contains an use-after-free vulnerability that could allow a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. This vulnerability could affect multiple Chromium-based products including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.049 (91.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-04-01
CISA remediation due: 2026-04-15
Known ransomware campaign use: Unknown/None
CVE-2023-41179 — Trend Micro Apex One and Worry-Free Business Security: Trend Micro Apex One and Worry-Free Business Security Remote Code Execution Vulnerability
Trend Micro Apex One and Worry-Free Business Security contain an unspecified vulnerability in the third-party anti-virus uninstaller that could allow an attacker to manipulate the module to conduct remote code execution. An attacker must first obtain administrative console access on the target system in order to exploit this vulnerability.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 7.2 (NVD)
FIRST EPSS: 0.047 (91.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-09-21
CISA remediation due: 2023-10-12
Known ransomware campaign use: Unknown/None
CVE-2020-1631 — Juniper Junos OS: Juniper Junos OS Path Traversal Vulnerability
A path traversal vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication Pass-Through with Web-Redirect, and Zero Touch Provisioning (ZTP) allows an unauthenticated attacker to perform remote code execution.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.047 (91.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-25
CISA remediation due: 2022-04-15
Known ransomware campaign use: Unknown/None
CVE-2004-1464 — Cisco IOS: Cisco IOS Denial-of-Service Vulnerability
Cisco IOS contains an unspecified vulnerability that may block further telnet, reverse telnet, Remote Shell (RSH), Secure Shell (SSH), and in some cases, Hypertext Transport Protocol (HTTP) access to the Cisco device.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 5.9 (NVD)
FIRST EPSS: 0.047 (91.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-05-19
CISA remediation due: 2023-06-09
Known ransomware campaign use: Unknown/None
CVE-2019-18988 — TeamViewer Desktop: TeamViewer Desktop Bypass Remote Login Vulnerability
TeamViewer Desktop allows for bypass of remote-login access control because the same AES key is used for different customers' installations. If an attacker were to know this key, they could decrypt protected information stored in registry or configuration files or decryption of the Unattended Access password to the system (which allows for remote login to the system).
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.0 (NVD)
FIRST EPSS: 0.047 (91.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2012-0518 — Oracle Fusion Middleware: Oracle Fusion Middleware Unspecified Vulnerability
Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware allows remote attackers to affect integrity via Unknown vectors
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 4.7 (NVD)
FIRST EPSS: 0.047 (91.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-28
CISA remediation due: 2022-04-18
Known ransomware campaign use: Unknown/None
CVE-2021-38000 — Google Chromium Intents: Google Chromium Intents Improper Input Validation Vulnerability
Google Chromium Intents contains an improper input validation vulnerability that allows a remote attacker to arbitrarily browser to a malicious URL via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 6.1 (NVD)
FIRST EPSS: 0.047 (91.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2021-11-17
Known ransomware campaign use: Unknown/None
CVE-2019-7287 — Apple iOS: Apple iOS Memory Corruption Vulnerability
Apple iOS contains a memory corruption vulnerability which could allow an attacker to perform remote code execution.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.046 (90.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-05-23
CISA remediation due: 2022-06-13
Known ransomware campaign use: Unknown/None
CVE-2023-41991 — Apple Multiple Products: Apple Multiple Products Improper Certificate Validation Vulnerability
Apple iOS, iPadOS, macOS, and watchOS contain an improper certificate validation vulnerability that can allow a malicious app to bypass signature validation.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 5.5 (NVD)
FIRST EPSS: 0.045 (90.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-09-25
CISA remediation due: 2023-10-16
Known ransomware campaign use: Unknown/None
CVE-2022-2856 — Google Chromium Intents: Google Chromium Intents Insufficient Input Validation Vulnerability
Google Chromium Intents contains an insufficient validation of untrusted input vulnerability that allows a remote attacker to browse to a malicious website via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 6.5 (NVD)
FIRST EPSS: 0.045 (90.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-08-18
CISA remediation due: 2022-09-08
Known ransomware campaign use: Unknown/None
CVE-2021-30661 — Apple Multiple Products: Apple Multiple Products WebKit Storage Use-After-Free Vulnerability
Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit Storage contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.045 (90.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2021-11-17
Known ransomware campaign use: Unknown/None
CVE-2023-46748 — F5 BIG-IP Configuration Utility: F5 BIG-IP Configuration Utility SQL Injection Vulnerability
F5 BIG-IP Configuration utility contains an SQL injection vulnerability that may allow an authenticated attacker with network access through the BIG-IP management port and/or self IP addresses to execute system commands. This vulnerability can be used in conjunction with CVE-2023-46747.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.045 (90.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-10-31
CISA remediation due: 2023-11-21
Known ransomware campaign use: Unknown/None
CVE-2026-20045 — Cisco Unified Communications Manager: Cisco Unified Communications Products Code Injection Vulnerability
Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unity Connection, and Cisco Webex Calling Dedicated Instance contain a code injection vulnerability that could allow the attacker to obtain user-level access to the underlying operating system and then elevate privileges to root.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.044 (90.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-01-21
CISA remediation due: 2026-02-11
Known ransomware campaign use: Unknown/None
CVE-2025-24200 — Apple iOS and iPadOS: Apple iOS and iPadOS Incorrect Authorization Vulnerability
Apple iOS and iPadOS contains an incorrect authorization vulnerability that allows a physical attacker to disable USB Restricted Mode on a locked device.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 6.1 (NVD)
FIRST EPSS: 0.044 (90.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-02-12
CISA remediation due: 2025-03-05
Known ransomware campaign use: Unknown/None
CVE-2025-54313 — Prettier eslint-config-prettier: Prettier eslint-config-prettier Embedded Malicious Code Vulnerability
Prettier eslint-config-prettier contains an embedded malicious code vulnerability. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 7.5 (NVD)
FIRST EPSS: 0.043 (90.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-01-22
CISA remediation due: 2026-02-12
Known ransomware campaign use: Unknown/None
CVE-2024-20399 — Cisco NX-OS: Cisco NX-OS Command Injection Vulnerability
Cisco NX-OS contains a command injection vulnerability in the command line interface (CLI) that could allow an authenticated, local attacker to execute commands as root on the underlying operating system of an affected device.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 6.7 (NVD)
FIRST EPSS: 0.043 (90.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-07-02
CISA remediation due: 2024-07-23
Known ransomware campaign use: Unknown/None
CVE-2025-55177 — Meta Platforms WhatsApp: Meta Platforms WhatsApp Incorrect Authorization Vulnerability
Meta Platforms WhatsApp contains an incorrect authorization vulnerability due to an incomplete authorization of linked device synchronization messages. This vulnerability could allow an unrelated user to trigger processing of content from an arbitrary URL on a target’s device.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 5.4 (NVD)
FIRST EPSS: 0.042 (90.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-09-02
CISA remediation due: 2025-09-23
Known ransomware campaign use: Unknown/None
CVE-2021-30869 — Apple iOS, iPadOS, and macOS: Apple iOS, iPadOS, and macOS Type Confusion Vulnerability
Apple iOS, iPadOS, and macOS contain a type confusion vulnerability in the XNU which may allow a malicious application to execute code with kernel privileges.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.042 (90.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2021-11-17
Known ransomware campaign use: Unknown/None