Cross-Vendor Patch Advisories
Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.
Browse Advisories
1,308 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.
| CVE | Vendor | Product | Vulnerability | EVRS | EPSS | Ransomware | CISA due |
|---|---|---|---|---|---|---|---|
| CVE-2024-7262 | Kingsoft | WPS Office | Kingsoft WPS Office Path Traversal Vulnerability | 75 Urgent | 0.029 (86.2nd pctl) | Unknown/None | 2024-09-24 |
| CVE-2021-30983 | Apple | iOS and iPadOS | Apple iOS and iPadOS Buffer Overflow Vulnerability | 75 Urgent | 0.029 (86.1st pctl) | Unknown/None | 2022-07-18 |
| CVE-2023-41992 | Apple | Multiple Products | Apple Multiple Products Kernel Privilege Escalation Vulnerability | 75 Urgent | 0.029 (86.1st pctl) | Unknown/None | 2023-10-16 |
| CVE-2018-4344 | Apple | Multiple Products | Apple Multiple Products Memory Corruption Vulnerability | 75 Urgent | 0.029 (86th pctl) | Unknown/None | 2022-07-18 |
| CVE-2023-38606 | Apple | Multiple Products | Apple Multiple Products Kernel Unspecified Vulnerability | 75 Urgent | 0.029 (85.9th pctl) | Unknown/None | 2023-08-16 |
| CVE-2022-40139 | Trend Micro | Apex One and Apex One as a Service | Trend Micro Apex One and Apex One as a Service Improper Validation Vulnerability | 75 Urgent | 0.029 (85.9th pctl) | Unknown/None | 2022-10-06 |
| CVE-2021-25337 | Samsung | Mobile Devices | Samsung Mobile Devices Improper Access Control Vulnerability | 75 Urgent | 0.028 (85.7th pctl) | Unknown/None | 2022-11-29 |
| CVE-2020-16013 | Chromium V8 | Google Chromium V8 Incorrect Implementation Vulnerabililty | 75 Urgent | 0.028 (85.2nd pctl) | Unknown/None | 2022-05-03 | |
| CVE-2020-16017 | Chrome | Google Chrome Use-After-Free Vulnerability | 75 Urgent | 0.027 (85.2nd pctl) | Unknown/None | 2022-05-03 | |
| CVE-2022-42948 | Fortra | Cobalt Strike | Fortra Cobalt Strike User Interface Remote Code Execution Vulnerability | 75 Urgent | 0.027 (84.9th pctl) | Unknown/None | 2023-04-20 |
| CVE-2024-36971 | Android | Kernel | Android Kernel Remote Code Execution Vulnerability | 75 Urgent | 0.027 (84.9th pctl) | Unknown/None | 2024-08-28 |
| CVE-2023-29492 | Novi Survey | Novi Survey | Novi Survey Insecure Deserialization Vulnerability | 75 Urgent | 0.027 (84.9th pctl) | Unknown/None | 2023-05-04 |
| CVE-2020-24557 | Trend Micro | Apex One, OfficeScan, and Worry-Free Business Security | Trend Micro Multiple Products Improper Access Control Vulnerability | 75 Urgent | 0.026 (84.5th pctl) | Unknown/None | 2022-05-03 |
| CVE-2019-6223 | Apple | iOS and macOS | Apple iOS and macOS Group Facetime Vulnerability | 75 Urgent | 0.026 (84.5th pctl) | Unknown/None | 2022-05-03 |
| CVE-2025-61932 | Motex | LANSCOPE Endpoint Manager | Motex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel Vulnerability | 75 Urgent | 0.026 (84.5th pctl) | Unknown/None | 2025-11-12 |
| CVE-2023-21492 | Samsung | Mobile Devices | Samsung Mobile Devices Insertion of Sensitive Information Into Log File Vulnerability | 75 Urgent | 0.026 (84th pctl) | Unknown/None | 2023-06-09 |
| CVE-2025-30154 | reviewdog | action-setup GitHub Action | reviewdog/action-setup GitHub Action Embedded Malicious Code Vulnerability | 75 Urgent | 0.024 (82.9th pctl) | Unknown/None | 2025-04-14 |
| CVE-2022-0028 | Palo Alto Networks | PAN-OS | Palo Alto Networks PAN-OS Reflected Amplification Denial-of-Service Vulnerability | 75 Urgent | 0.024 (82.8th pctl) | Unknown/None | 2022-09-12 |
| CVE-2025-32975 | Quest | KACE Systems Management Appliance (SMA) | Quest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability | 75 Urgent | 0.024 (82.7th pctl) | Unknown/None | 2026-05-04 |
| CVE-2022-26486 | Mozilla | Firefox | Mozilla Firefox Use-After-Free Vulnerability | 75 Urgent | 0.023 (82.5th pctl) | Unknown/None | 2022-03-21 |
| CVE-2023-20109 | Cisco | IOS and IOS XE | Cisco IOS and IOS XE Group Encrypted Transport VPN Out-of-Bounds Write Vulnerability | 75 Urgent | 0.023 (82.5th pctl) | Unknown/None | 2023-10-31 |
| CVE-2020-9818 | Apple | iOS, iPadOS, and watchOS | Apple iOS, iPadOS, and watchOS Out-of-Bounds Write Vulnerability | 75 Urgent | 0.023 (82nd pctl) | Unknown/None | 2022-05-03 |
| CVE-2021-1782 | Apple | Multiple Products | Apple Multiple Products Race Condition Vulnerability | 75 Urgent | 0.022 (81.5th pctl) | Unknown/None | 2021-11-17 |
| CVE-2025-53521 | F5 | BIG-IP | F5 BIG-IP Stack-Based Buffer Overflow Vulnerability | 75 Urgent | 0.022 (81.4th pctl) | Unknown/None | 2026-03-30 |
| CVE-2026-20349 | Cisco | Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) | Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability | 75 Urgent | 0.022 (81.4th pctl) | Unknown/None | 2026-08-14 |
Exactly the 1,308 advisory(ies) matching the filters above.
Advisory detail
Expand any advisory for its description, CISA's own required action, and research links.
CVE-2024-7262 — Kingsoft WPS Office: Kingsoft WPS Office Path Traversal Vulnerability
Kingsoft WPS Office contains a path traversal vulnerability in promecefpluginhost.exe on Windows that allows an attacker to load an arbitrary Windows library.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 9.3 (NVD)
FIRST EPSS: 0.029 (86.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-09-03
CISA remediation due: 2024-09-24
Known ransomware campaign use: Unknown/None
CVE-2021-30983 — Apple iOS and iPadOS: Apple iOS and iPadOS Buffer Overflow Vulnerability
Apple iOS and iPadOS contain a buffer overflow vulnerability that could allow an application to execute code with kernel privileges.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.029 (86.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-06-27
CISA remediation due: 2022-07-18
Known ransomware campaign use: Unknown/None
CVE-2023-41992 — Apple Multiple Products: Apple Multiple Products Kernel Privilege Escalation Vulnerability
Apple iOS, iPadOS, macOS, and watchOS contain an unspecified vulnerability that allows for local privilege escalation.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.029 (86.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-09-25
CISA remediation due: 2023-10-16
Known ransomware campaign use: Unknown/None
CVE-2018-4344 — Apple Multiple Products: Apple Multiple Products Memory Corruption Vulnerability
Apple iOS, macOS, tvOS, and watchOS contain a memory corruption vulnerability which can allow for code execution.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.029 (86th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-06-27
CISA remediation due: 2022-07-18
Known ransomware campaign use: Unknown/None
CVE-2023-38606 — Apple Multiple Products: Apple Multiple Products Kernel Unspecified Vulnerability
Apple iOS, iPadOS, macOS, tvOS, and watchOS contain an unspecified vulnerability allowing an app to modify a sensitive kernel state.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 5.5 (NVD)
FIRST EPSS: 0.029 (85.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-07-26
CISA remediation due: 2023-08-16
Known ransomware campaign use: Unknown/None
CVE-2022-40139 — Trend Micro Apex One and Apex One as a Service: Trend Micro Apex One and Apex One as a Service Improper Validation Vulnerability
Trend Micro Apex One and Apex One as a Service contain an improper validation of rollback mechanism components that could lead to remote code execution.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.2 (NVD)
FIRST EPSS: 0.029 (85.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-09-15
CISA remediation due: 2022-10-06
Known ransomware campaign use: Unknown/None
CVE-2021-25337 — Samsung Mobile Devices: Samsung Mobile Devices Improper Access Control Vulnerability
Samsung mobile devices contain an improper access control vulnerability in clipboard service which allows untrusted applications to read or write arbitrary files. This vulnerability was chained with CVE-2021-25369 and CVE-2021-25370.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.1 (NVD)
FIRST EPSS: 0.028 (85.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-11-08
CISA remediation due: 2022-11-29
Known ransomware campaign use: Unknown/None
CVE-2020-16013 — Google Chromium V8: Google Chromium V8 Incorrect Implementation Vulnerabililty
Google Chromium V8 Engine contains an inappropriate implementation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.028 (85.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2020-16017 — Google Chrome: Google Chrome Use-After-Free Vulnerability
Google Chrome contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.6 (NVD)
FIRST EPSS: 0.027 (85.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2022-42948 — Fortra Cobalt Strike: Fortra Cobalt Strike User Interface Remote Code Execution Vulnerability
Fortra Cobalt Strike User Interface contains an unspecified vulnerability rooted in Java Swing that may allow remote code execution.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.027 (84.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-03-30
CISA remediation due: 2023-04-20
Known ransomware campaign use: Unknown/None
CVE-2024-36971 — Android Kernel: Android Kernel Remote Code Execution Vulnerability
Android contains an unspecified vulnerability in the kernel that allows for remote code execution. This vulnerability resides in Linux Kernel and could impact other products, including but not limited to Android OS.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.027 (84.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-08-07
CISA remediation due: 2024-08-28
Known ransomware campaign use: Unknown/None
CVE-2023-29492 — Novi Survey Novi Survey: Novi Survey Insecure Deserialization Vulnerability
Novi Survey contains an insecure deserialization vulnerability that allows remote attackers to execute code on the server in the context of the service account.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.027 (84.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-04-13
CISA remediation due: 2023-05-04
Known ransomware campaign use: Unknown/None
CVE-2020-24557 — Trend Micro Apex One, OfficeScan, and Worry-Free Business Security: Trend Micro Multiple Products Improper Access Control Vulnerability
Trend Micro Apex One, OfficeScan, and Worry-Free Business Security on Microsoft Windows contain an improper access control vulnerability that may allow an attacker to manipulate a particular product folder to disable the security temporarily, abuse a specific Windows function, and attain privilege escalation.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.026 (84.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2019-6223 — Apple iOS and macOS: Apple iOS and macOS Group Facetime Vulnerability
Apple iOS and macOS Group FaceTime contains an unspecified vulnerability where the call initiator can cause the recipient's Apple device to answer unknowingly or without user interaction.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.5 (NVD)
FIRST EPSS: 0.026 (84.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2025-61932 — Motex LANSCOPE Endpoint Manager: Motex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel Vulnerability
Motex LANSCOPE Endpoint Manager contains an improper verification of source of a communication channel vulnerability allowing an attacker to execute arbitrary code by sending specially crafted packets.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.3 (NVD)
FIRST EPSS: 0.026 (84.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-10-22
CISA remediation due: 2025-11-12
Known ransomware campaign use: Unknown/None
CVE-2023-21492 — Samsung Mobile Devices: Samsung Mobile Devices Insertion of Sensitive Information Into Log File Vulnerability
Samsung mobile devices running Android 11, 12, and 13 contain an insertion of sensitive information into log file vulnerability that allows a privileged, local attacker to conduct an address space layout randomization (ASLR) bypass.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 4.4 (NVD)
FIRST EPSS: 0.026 (84th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-05-19
CISA remediation due: 2023-06-09
Known ransomware campaign use: Unknown/None
CVE-2025-30154 — reviewdog action-setup GitHub Action: reviewdog/action-setup GitHub Action Embedded Malicious Code Vulnerability
reviewdog action-setup GitHub Action contains an embedded malicious code vulnerability that dumps exposed secrets to Github Actions Workflow Logs.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations as set forth in the CISA instructions linked below. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 8.6 (NVD)
FIRST EPSS: 0.024 (82.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-03-24
CISA remediation due: 2025-04-14
Known ransomware campaign use: Unknown/None
CVE-2022-0028 — Palo Alto Networks PAN-OS: Palo Alto Networks PAN-OS Reflected Amplification Denial-of-Service Vulnerability
A Palo Alto Networks PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified TCP denial-of-service (RDoS) attacks.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.6 (NVD)
FIRST EPSS: 0.024 (82.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-08-22
CISA remediation due: 2022-09-12
Known ransomware campaign use: Unknown/None
CVE-2025-32975 — Quest KACE Systems Management Appliance (SMA): Quest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability
Quest KACE Systems Management Appliance (SMA) contains an improper authentication vulnerability that could allow attackers to impersonate legitimate users without valid credentials.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 10.0 (NVD)
FIRST EPSS: 0.024 (82.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-04-20
CISA remediation due: 2026-05-04
Known ransomware campaign use: Unknown/None
CVE-2022-26486 — Mozilla Firefox: Mozilla Firefox Use-After-Free Vulnerability
Mozilla Firefox contains a use-after-free vulnerability in WebGPU IPC Framework which can be exploited to perform arbitrary code execution.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.6 (NVD)
FIRST EPSS: 0.023 (82.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-07
CISA remediation due: 2022-03-21
Known ransomware campaign use: Unknown/None
CVE-2023-20109 — Cisco IOS and IOS XE: Cisco IOS and IOS XE Group Encrypted Transport VPN Out-of-Bounds Write Vulnerability
Cisco IOS and IOS XE contain an out-of-bounds write vulnerability in the Group Encrypted Transport VPN (GET VPN) feature that could allow an authenticated, remote attacker who has administrative control of either a group member or a key server to execute malicious code or cause a device to crash.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 6.6 (NVD)
FIRST EPSS: 0.023 (82.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-10-10
CISA remediation due: 2023-10-31
Known ransomware campaign use: Unknown/None
CVE-2020-9818 — Apple iOS, iPadOS, and watchOS: Apple iOS, iPadOS, and watchOS Out-of-Bounds Write Vulnerability
Apple iOS, iPadOS, and watchOS Mail contains an out-of-bounds write vulnerability which may allow memory modification or application termination when processing a maliciously crafted mail message.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.023 (82nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2021-1782 — Apple Multiple Products: Apple Multiple Products Race Condition Vulnerability
Apple iOS, iPadOs, macOS, watchOS, and tvOS contain a race condition vulnerability that may allow a malicious application to elevate privileges.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.0 (NVD)
FIRST EPSS: 0.022 (81.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2021-11-17
Known ransomware campaign use: Unknown/None
CVE-2025-53521 — F5 BIG-IP: F5 BIG-IP Stack-Based Buffer Overflow Vulnerability
F5 BIG-IP APM contains a stack-based buffer overflow vulnerability that could allow a threat actor to achieve remote code execution.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.3 (NVD)
FIRST EPSS: 0.022 (81.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-03-27
CISA remediation due: 2026-03-30
Known ransomware campaign use: Unknown/None
CVE-2026-20349 — Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD): Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability
Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVSS: 8.6 (Cisco (estimated))
FIRST EPSS: 0.022 (81.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-08-11
CISA remediation due: 2026-08-14
Known ransomware campaign use: Unknown/None