Cross-Vendor Patch Advisories

Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.

Browse Advisories

Association
Vendor — all

Leave every box clear to show all 282 vendors.

1,308 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.

CISA KEV advisories matching the current filters, ranked by EVULNABLE Risk Score
CVE Vendor Product Vulnerability EVRS EPSS Ransomware CISA due
CVE-2023-35674 Android Framework Android Framework Privilege Escalation Vulnerability 75 Urgent 0.022 (81.3rd pctl) Unknown/None 2023-10-04
CVE-2026-11645 Google Chromium V8 Google Chromium V8 Out-of-Bounds Read and Write Vulnerability 75 Urgent 0.022 (81.2nd pctl) Unknown/None 2026-06-23
CVE-2020-9819 Apple iOS, iPadOS, and watchOS Apple iOS, iPadOS, and watchOS Memory Corruption Vulnerability 75 Urgent 0.022 (81.1st pctl) Unknown/None 2022-05-03
CVE-2017-12232 Cisco IOS software Cisco IOS Software for Cisco Integrated Services Routers Denial-of-Service Vulnerability 75 Urgent 0.022 (81.1st pctl) Unknown/None 2022-03-24
CVE-2025-3928 Commvault Web Server Commvault Web Server Unspecified Vulnerability 75 Urgent 0.021 (80.8th pctl) Unknown/None 2025-05-19
CVE-2017-6663 Cisco IOS and IOS XE Software Cisco IOS Software and Cisco IOS XE Software Denial-of-Service Vulnerability 75 Urgent 0.021 (80.8th pctl) Unknown/None 2022-03-24
CVE-2025-40602 SonicWall SMA1000 appliance SonicWall SMA1000 Missing Authorization Vulnerability 75 Urgent 0.021 (80.6th pctl) Unknown/None 2025-12-24
CVE-2023-6448 Unitronics Vision PLC and HMI Unitronics Vision PLC and HMI Insecure Default Password Vulnerability 75 Urgent 0.021 (80.1st pctl) Unknown/None 2023-12-18
CVE-2017-12238 Cisco Catalyst 6800 Series Switches Cisco Catalyst 6800 Series Switches VPLS Denial-of-Service Vulnerability 75 Urgent 0.020 (79.7th pctl) Unknown/None 2022-03-24
CVE-2026-3910 Google Chromium V8 Google Chromium V8 Improper Restriction of Operations Within the Bounds of a Memory Buffer Vulnerability 75 Urgent 0.020 (79.4th pctl) Unknown/None 2026-03-27
CVE-2020-2506 QNAP Systems Helpdesk QNAP Helpdesk Improper Access Control Vulnerability 75 Urgent 0.020 (79.2nd pctl) Unknown/None 2022-04-15
CVE-2025-0111 Palo Alto Networks PAN-OS Palo Alto Networks PAN-OS File Read Vulnerability 75 Urgent 0.020 (79th pctl) Unknown/None 2025-03-13
CVE-2025-21043 Samsung Mobile Devices Samsung Mobile Devices Out-of-Bounds Write Vulnerability 75 Urgent 0.019 (78.2nd pctl) Unknown/None 2025-10-23
CVE-2025-59689 Libraesva Email Security Gateway Libraesva Email Security Gateway Command Injection Vulnerability 75 Urgent 0.019 (77.8th pctl) Unknown/None 2025-10-20
CVE-2024-7694 TeamT5 ThreatSonar Anti-Ransomware TeamT5 ThreatSonar Anti-Ransomware Unrestricted Upload of File with Dangerous Type Vulnerability 75 Urgent 0.018 (77.1st pctl) Unknown/None 2026-03-10
CVE-2018-19322 GIGABYTE Multiple Products GIGABYTE Multiple Products Code Execution Vulnerability 75 Urgent 0.018 (77th pctl) Known 2022-11-14
CVE-2025-27920 Srimax Output Messenger Srimax Output Messenger Directory Traversal Vulnerability 75 Urgent 0.018 (76.9th pctl) Unknown/None 2025-06-09
CVE-2020-11261 Qualcomm Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables Qualcomm Multiple Chipsets Improper Input Validation Vulnerability 75 Urgent 0.018 (76.6th pctl) Unknown/None 2022-06-01
CVE-2025-22226 VMware ESXi, Workstation, and Fusion VMware ESXi, Workstation, and Fusion Information Disclosure Vulnerability 75 Urgent 0.017 (76.1st pctl) Unknown/None 2025-03-25
CVE-2025-8875 N-able N-Central N-able N-Central Insecure Deserialization Vulnerability 75 Urgent 0.017 (75.9th pctl) Unknown/None 2025-08-20
CVE-2025-21590 Juniper Junos OS Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability 75 Urgent 0.017 (75.8th pctl) Unknown/None 2025-04-03
CVE-2025-48595 Android Framework Android Framework Integer Overflow Vulnerability 75 Urgent 0.017 (75.8th pctl) Unknown/None 2026-06-05
CVE-2025-15556 Notepad++ Notepad++ Notepad++ Download of Code Without Integrity Check Vulnerability 75 Urgent 0.017 (75.8th pctl) Unknown/None 2026-03-05
CVE-2025-48700 Synacor Zimbra Collaboration Suite (ZCS) Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability 75 Urgent 0.017 (75.4th pctl) Unknown/None 2026-04-23
CVE-2024-39891 Twilio Authy Twilio Authy Information Disclosure Vulnerability 75 Urgent 0.017 (75.2nd pctl) Unknown/None 2024-08-13
Download filtered advisories (CSV)

Exactly the 1,308 advisory(ies) matching the filters above.

Advisory detail

Expand any advisory for its description, CISA's own required action, and research links.

CVE-2023-35674 — Android Framework: Android Framework Privilege Escalation Vulnerability

Android Framework contains an unspecified vulnerability that allows for privilege escalation.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.022 (81.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-09-13

CISA remediation due: 2023-10-04

Known ransomware campaign use: Unknown/None

CVE-2026-11645 — Google Chromium V8: Google Chromium V8 Out-of-Bounds Read and Write Vulnerability

Google Chromium V8 out-of-bounds read and write vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.022 (81.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-06-09

CISA remediation due: 2026-06-23

Known ransomware campaign use: Unknown/None

CVE-2020-9819 — Apple iOS, iPadOS, and watchOS: Apple iOS, iPadOS, and watchOS Memory Corruption Vulnerability

Apple iOS, iPadOS, and watchOS Mail contains a memory corruption vulnerability that may allow heap corruption when processing a maliciously crafted mail message.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 4.3 (NVD)

FIRST EPSS: 0.022 (81.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2017-12232 — Cisco IOS software: Cisco IOS Software for Cisco Integrated Services Routers Denial-of-Service Vulnerability

A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers running Cisco IOS could allow an unauthenticated, adjacent attacker to cause an affected device to reload, resulting in a denial of service.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 6.5 (NVD)

FIRST EPSS: 0.022 (81.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-03

CISA remediation due: 2022-03-24

Known ransomware campaign use: Unknown/None

CVE-2025-3928 — Commvault Web Server: Commvault Web Server Unspecified Vulnerability

Commvault Web Server contains an unspecified vulnerability that allows a remote, authenticated attacker to create and execute webshells.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 8.7 (NVD)

FIRST EPSS: 0.021 (80.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-04-28

CISA remediation due: 2025-05-19

Known ransomware campaign use: Unknown/None

CVE-2017-6663 — Cisco IOS and IOS XE Software: Cisco IOS Software and Cisco IOS XE Software Denial-of-Service Vulnerability

A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause autonomic nodes of an affected system to reload, resulting in denial-of-service (DoS).

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 6.5 (NVD)

FIRST EPSS: 0.021 (80.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-03

CISA remediation due: 2022-03-24

Known ransomware campaign use: Unknown/None

CVE-2025-40602 — SonicWall SMA1000 appliance: SonicWall SMA1000 Missing Authorization Vulnerability

SonicWall SMA1000 contains a missing authorization vulnerability that could allow for privilege escalation appliance management console (AMC) of affected devices.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable

CVSS: 6.6 (NVD)

FIRST EPSS: 0.021 (80.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-12-17

CISA remediation due: 2025-12-24

Known ransomware campaign use: Unknown/None

CVE-2023-6448 — Unitronics Vision PLC and HMI: Unitronics Vision PLC and HMI Insecure Default Password Vulnerability

Unitronics Vision Series PLCs and HMIs ship with an insecure default password, which if left unchanged, can allow attackers to execute remote commands.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.021 (80.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-12-11

CISA remediation due: 2023-12-18

Known ransomware campaign use: Unknown/None

CVE-2017-12238 — Cisco Catalyst 6800 Series Switches: Cisco Catalyst 6800 Series Switches VPLS Denial-of-Service Vulnerability

A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS for Cisco Catalyst 6800 Series Switches could allow an unauthenticated, adjacent attacker to cause a denial of service.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 6.5 (NVD)

FIRST EPSS: 0.020 (79.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-03

CISA remediation due: 2022-03-24

Known ransomware campaign use: Unknown/None

CVE-2026-3910 — Google Chromium V8: Google Chromium V8 Improper Restriction of Operations Within the Bounds of a Memory Buffer Vulnerability

Google Chromium V8 contains an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.020 (79.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-03-13

CISA remediation due: 2026-03-27

Known ransomware campaign use: Unknown/None

CVE-2020-2506 — QNAP Systems Helpdesk: QNAP Helpdesk Improper Access Control Vulnerability

QNAP Helpdesk contains an improper access control vulnerability which could allow an attacker to gain privileges or to read sensitive information.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.020 (79.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-25

CISA remediation due: 2022-04-15

Known ransomware campaign use: Unknown/None

CVE-2025-0111 — Palo Alto Networks PAN-OS: Palo Alto Networks PAN-OS File Read Vulnerability

Palo Alto Networks PAN-OS contains an external control of file name or path vulnerability. Successful exploitation enables an authenticated attacker with network access to the management web interface to read files on the PAN-OS filesystem that are readable by the “nobody” user.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 7.1 (NVD)

FIRST EPSS: 0.020 (79th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-02-20

CISA remediation due: 2025-03-13

Known ransomware campaign use: Unknown/None

CVE-2025-21043 — Samsung Mobile Devices: Samsung Mobile Devices Out-of-Bounds Write Vulnerability

Samsung mobile devices contain an out-of-bounds write vulnerability in libimagecodec.quram.so which allows remote attackers to execute arbitrary code.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.019 (78.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-10-02

CISA remediation due: 2025-10-23

Known ransomware campaign use: Unknown/None

CVE-2025-59689 — Libraesva Email Security Gateway: Libraesva Email Security Gateway Command Injection Vulnerability

Libraesva Email Security Gateway (ESG) contains a command injection vulnerability which allows command injection via a compressed e-mail attachment.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 6.1 (NVD)

FIRST EPSS: 0.019 (77.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-09-29

CISA remediation due: 2025-10-20

Known ransomware campaign use: Unknown/None

CVE-2024-7694 — TeamT5 ThreatSonar Anti-Ransomware: TeamT5 ThreatSonar Anti-Ransomware Unrestricted Upload of File with Dangerous Type Vulnerability

TeamT5 ThreatSonar Anti-Ransomware contains an unrestricted upload of file with dangerous type vulnerability. ThreatSonar Anti-Ransomware does not properly validate the content of uploaded files. Remote attackers with administrator privileges on the product platform can upload malicious files, which can be used to execute arbitrary system commands on the server.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 7.2 (NVD)

FIRST EPSS: 0.018 (77.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-02-17

CISA remediation due: 2026-03-10

Known ransomware campaign use: Unknown/None

CVE-2018-19322 — GIGABYTE Multiple Products: GIGABYTE Multiple Products Code Execution Vulnerability

The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read/write data from/to IO ports. This could be leveraged in a number of ways to ultimately run code with elevated privileges.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.018 (77th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-10-24

CISA remediation due: 2022-11-14

Known ransomware campaign use: Known

CVE-2025-27920 — Srimax Output Messenger: Srimax Output Messenger Directory Traversal Vulnerability

Srimax Output Messenger contains a directory traversal vulnerability that allows an attacker to access sensitive files outside the intended directory, potentially leading to configuration leakage or arbitrary file access.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.018 (76.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-05-19

CISA remediation due: 2025-06-09

Known ransomware campaign use: Unknown/None

CVE-2020-11261 — Qualcomm Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables: Qualcomm Multiple Chipsets Improper Input Validation Vulnerability

Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.018 (76.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-12-01

CISA remediation due: 2022-06-01

Known ransomware campaign use: Unknown/None

CVE-2025-22226 — VMware ESXi, Workstation, and Fusion: VMware ESXi, Workstation, and Fusion Information Disclosure Vulnerability

VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. Successful exploitation allows an attacker with administrative privileges to a virtual machine to leak memory from the vmx process.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 6.0 (NVD)

FIRST EPSS: 0.017 (76.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-03-04

CISA remediation due: 2025-03-25

Known ransomware campaign use: Unknown/None

CVE-2025-8875 — N-able N-Central: N-able N-Central Insecure Deserialization Vulnerability

N-able N-Central contains an insecure deserialization vulnerability that could lead to command execution.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 9.4 (NVD)

FIRST EPSS: 0.017 (75.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-08-13

CISA remediation due: 2025-08-20

Known ransomware campaign use: Unknown/None

CVE-2025-21590 — Juniper Junos OS: Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability

Juniper Junos OS contains an improper isolation or compartmentalization vulnerability. This vulnerability could allows a local attacker with high privileges to inject arbitrary code.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 6.7 (NVD)

FIRST EPSS: 0.017 (75.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-03-13

CISA remediation due: 2025-04-03

Known ransomware campaign use: Unknown/None

CVE-2025-48595 — Android Framework: Android Framework Integer Overflow Vulnerability

Android Framework contains an integer overflow vulnerability that allows for code execution that could allow for local privilege escalation.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 8.4 (NVD)

FIRST EPSS: 0.017 (75.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-06-02

CISA remediation due: 2026-06-05

Known ransomware campaign use: Unknown/None

CVE-2025-15556 — Notepad++ Notepad++: Notepad++ Download of Code Without Integrity Check Vulnerability

Notepad++ when using the WinGUp updater, contains a download of code without integrity check vulnerability that could allow an attacker to intercept or redirect update traffic to download and execute an attacker-controlled installer. This could lead to arbitrary code execution with the privileges of the user.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 7.7 (NVD)

FIRST EPSS: 0.017 (75.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-02-12

CISA remediation due: 2026-03-05

Known ransomware campaign use: Unknown/None

CVE-2025-48700 — Synacor Zimbra Collaboration Suite (ZCS): Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability

Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that could allow attackers to execute arbitrary JavaScript within the user's session, potentially leading to unauthorized access to sensitive information.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 6.1 (NVD)

FIRST EPSS: 0.017 (75.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-04-20

CISA remediation due: 2026-04-23

Known ransomware campaign use: Unknown/None

CVE-2024-39891 — Twilio Authy: Twilio Authy Information Disclosure Vulnerability

Twilio Authy contains an information disclosure vulnerability in its API that allows an unauthenticated endpoint to accept a request containing a phone number and respond with information about whether the phone number was registered with Authy.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 5.3 (NVD)

FIRST EPSS: 0.017 (75.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-07-23

CISA remediation due: 2024-08-13

Known ransomware campaign use: Unknown/None

Data sources & attribution

Known-exploitation status, required actions, ransomware association and remediation deadlines come from the CISA Known Exploited Vulnerabilities Catalog. Exploitation probability and percentile are provided by FIRST.org's EPSS, used under FIRST's open data terms.

Microsoft Patch Tuesday data is sourced from the Microsoft Security Update Guide; lifecycle milestones from endoflife.date. Linux distribution advisories come from Red Hat, Ubuntu and Debian; vendor bulletins from Adobe, Apple, Chrome, Cisco, Ivanti and Oracle, each linked to its own advisory.