Cross-Vendor Patch Advisories
Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.
Browse Advisories
1,308 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.
| CVE | Vendor | Product | Vulnerability | EVRS | EPSS | Ransomware | CISA due |
|---|---|---|---|---|---|---|---|
| CVE-2023-35674 | Android | Framework | Android Framework Privilege Escalation Vulnerability | 75 Urgent | 0.022 (81.3rd pctl) | Unknown/None | 2023-10-04 |
| CVE-2026-11645 | Chromium V8 | Google Chromium V8 Out-of-Bounds Read and Write Vulnerability | 75 Urgent | 0.022 (81.2nd pctl) | Unknown/None | 2026-06-23 | |
| CVE-2020-9819 | Apple | iOS, iPadOS, and watchOS | Apple iOS, iPadOS, and watchOS Memory Corruption Vulnerability | 75 Urgent | 0.022 (81.1st pctl) | Unknown/None | 2022-05-03 |
| CVE-2017-12232 | Cisco | IOS software | Cisco IOS Software for Cisco Integrated Services Routers Denial-of-Service Vulnerability | 75 Urgent | 0.022 (81.1st pctl) | Unknown/None | 2022-03-24 |
| CVE-2025-3928 | Commvault | Web Server | Commvault Web Server Unspecified Vulnerability | 75 Urgent | 0.021 (80.8th pctl) | Unknown/None | 2025-05-19 |
| CVE-2017-6663 | Cisco | IOS and IOS XE Software | Cisco IOS Software and Cisco IOS XE Software Denial-of-Service Vulnerability | 75 Urgent | 0.021 (80.8th pctl) | Unknown/None | 2022-03-24 |
| CVE-2025-40602 | SonicWall | SMA1000 appliance | SonicWall SMA1000 Missing Authorization Vulnerability | 75 Urgent | 0.021 (80.6th pctl) | Unknown/None | 2025-12-24 |
| CVE-2023-6448 | Unitronics | Vision PLC and HMI | Unitronics Vision PLC and HMI Insecure Default Password Vulnerability | 75 Urgent | 0.021 (80.1st pctl) | Unknown/None | 2023-12-18 |
| CVE-2017-12238 | Cisco | Catalyst 6800 Series Switches | Cisco Catalyst 6800 Series Switches VPLS Denial-of-Service Vulnerability | 75 Urgent | 0.020 (79.7th pctl) | Unknown/None | 2022-03-24 |
| CVE-2026-3910 | Chromium V8 | Google Chromium V8 Improper Restriction of Operations Within the Bounds of a Memory Buffer Vulnerability | 75 Urgent | 0.020 (79.4th pctl) | Unknown/None | 2026-03-27 | |
| CVE-2020-2506 | QNAP Systems | Helpdesk | QNAP Helpdesk Improper Access Control Vulnerability | 75 Urgent | 0.020 (79.2nd pctl) | Unknown/None | 2022-04-15 |
| CVE-2025-0111 | Palo Alto Networks | PAN-OS | Palo Alto Networks PAN-OS File Read Vulnerability | 75 Urgent | 0.020 (79th pctl) | Unknown/None | 2025-03-13 |
| CVE-2025-21043 | Samsung | Mobile Devices | Samsung Mobile Devices Out-of-Bounds Write Vulnerability | 75 Urgent | 0.019 (78.2nd pctl) | Unknown/None | 2025-10-23 |
| CVE-2025-59689 | Libraesva | Email Security Gateway | Libraesva Email Security Gateway Command Injection Vulnerability | 75 Urgent | 0.019 (77.8th pctl) | Unknown/None | 2025-10-20 |
| CVE-2024-7694 | TeamT5 | ThreatSonar Anti-Ransomware | TeamT5 ThreatSonar Anti-Ransomware Unrestricted Upload of File with Dangerous Type Vulnerability | 75 Urgent | 0.018 (77.1st pctl) | Unknown/None | 2026-03-10 |
| CVE-2018-19322 | GIGABYTE | Multiple Products | GIGABYTE Multiple Products Code Execution Vulnerability | 75 Urgent | 0.018 (77th pctl) | Known | 2022-11-14 |
| CVE-2025-27920 | Srimax | Output Messenger | Srimax Output Messenger Directory Traversal Vulnerability | 75 Urgent | 0.018 (76.9th pctl) | Unknown/None | 2025-06-09 |
| CVE-2020-11261 | Qualcomm | Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables | Qualcomm Multiple Chipsets Improper Input Validation Vulnerability | 75 Urgent | 0.018 (76.6th pctl) | Unknown/None | 2022-06-01 |
| CVE-2025-22226 | VMware | ESXi, Workstation, and Fusion | VMware ESXi, Workstation, and Fusion Information Disclosure Vulnerability | 75 Urgent | 0.017 (76.1st pctl) | Unknown/None | 2025-03-25 |
| CVE-2025-8875 | N-able | N-Central | N-able N-Central Insecure Deserialization Vulnerability | 75 Urgent | 0.017 (75.9th pctl) | Unknown/None | 2025-08-20 |
| CVE-2025-21590 | Juniper | Junos OS | Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability | 75 Urgent | 0.017 (75.8th pctl) | Unknown/None | 2025-04-03 |
| CVE-2025-48595 | Android | Framework | Android Framework Integer Overflow Vulnerability | 75 Urgent | 0.017 (75.8th pctl) | Unknown/None | 2026-06-05 |
| CVE-2025-15556 | Notepad++ | Notepad++ | Notepad++ Download of Code Without Integrity Check Vulnerability | 75 Urgent | 0.017 (75.8th pctl) | Unknown/None | 2026-03-05 |
| CVE-2025-48700 | Synacor | Zimbra Collaboration Suite (ZCS) | Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability | 75 Urgent | 0.017 (75.4th pctl) | Unknown/None | 2026-04-23 |
| CVE-2024-39891 | Twilio | Authy | Twilio Authy Information Disclosure Vulnerability | 75 Urgent | 0.017 (75.2nd pctl) | Unknown/None | 2024-08-13 |
Exactly the 1,308 advisory(ies) matching the filters above.
Advisory detail
Expand any advisory for its description, CISA's own required action, and research links.
CVE-2023-35674 — Android Framework: Android Framework Privilege Escalation Vulnerability
Android Framework contains an unspecified vulnerability that allows for privilege escalation.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.022 (81.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-09-13
CISA remediation due: 2023-10-04
Known ransomware campaign use: Unknown/None
CVE-2026-11645 — Google Chromium V8: Google Chromium V8 Out-of-Bounds Read and Write Vulnerability
Google Chromium V8 out-of-bounds read and write vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.022 (81.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-06-09
CISA remediation due: 2026-06-23
Known ransomware campaign use: Unknown/None
CVE-2020-9819 — Apple iOS, iPadOS, and watchOS: Apple iOS, iPadOS, and watchOS Memory Corruption Vulnerability
Apple iOS, iPadOS, and watchOS Mail contains a memory corruption vulnerability that may allow heap corruption when processing a maliciously crafted mail message.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 4.3 (NVD)
FIRST EPSS: 0.022 (81.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2017-12232 — Cisco IOS software: Cisco IOS Software for Cisco Integrated Services Routers Denial-of-Service Vulnerability
A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers running Cisco IOS could allow an unauthenticated, adjacent attacker to cause an affected device to reload, resulting in a denial of service.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 6.5 (NVD)
FIRST EPSS: 0.022 (81.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-03
CISA remediation due: 2022-03-24
Known ransomware campaign use: Unknown/None
CVE-2025-3928 — Commvault Web Server: Commvault Web Server Unspecified Vulnerability
Commvault Web Server contains an unspecified vulnerability that allows a remote, authenticated attacker to create and execute webshells.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 8.7 (NVD)
FIRST EPSS: 0.021 (80.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-04-28
CISA remediation due: 2025-05-19
Known ransomware campaign use: Unknown/None
CVE-2017-6663 — Cisco IOS and IOS XE Software: Cisco IOS Software and Cisco IOS XE Software Denial-of-Service Vulnerability
A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause autonomic nodes of an affected system to reload, resulting in denial-of-service (DoS).
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 6.5 (NVD)
FIRST EPSS: 0.021 (80.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-03
CISA remediation due: 2022-03-24
Known ransomware campaign use: Unknown/None
CVE-2025-40602 — SonicWall SMA1000 appliance: SonicWall SMA1000 Missing Authorization Vulnerability
SonicWall SMA1000 contains a missing authorization vulnerability that could allow for privilege escalation appliance management console (AMC) of affected devices.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable
CVSS: 6.6 (NVD)
FIRST EPSS: 0.021 (80.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-12-17
CISA remediation due: 2025-12-24
Known ransomware campaign use: Unknown/None
CVE-2023-6448 — Unitronics Vision PLC and HMI: Unitronics Vision PLC and HMI Insecure Default Password Vulnerability
Unitronics Vision Series PLCs and HMIs ship with an insecure default password, which if left unchanged, can allow attackers to execute remote commands.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.021 (80.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-12-11
CISA remediation due: 2023-12-18
Known ransomware campaign use: Unknown/None
CVE-2017-12238 — Cisco Catalyst 6800 Series Switches: Cisco Catalyst 6800 Series Switches VPLS Denial-of-Service Vulnerability
A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS for Cisco Catalyst 6800 Series Switches could allow an unauthenticated, adjacent attacker to cause a denial of service.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 6.5 (NVD)
FIRST EPSS: 0.020 (79.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-03
CISA remediation due: 2022-03-24
Known ransomware campaign use: Unknown/None
CVE-2026-3910 — Google Chromium V8: Google Chromium V8 Improper Restriction of Operations Within the Bounds of a Memory Buffer Vulnerability
Google Chromium V8 contains an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.020 (79.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-03-13
CISA remediation due: 2026-03-27
Known ransomware campaign use: Unknown/None
CVE-2020-2506 — QNAP Systems Helpdesk: QNAP Helpdesk Improper Access Control Vulnerability
QNAP Helpdesk contains an improper access control vulnerability which could allow an attacker to gain privileges or to read sensitive information.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.020 (79.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-25
CISA remediation due: 2022-04-15
Known ransomware campaign use: Unknown/None
CVE-2025-0111 — Palo Alto Networks PAN-OS: Palo Alto Networks PAN-OS File Read Vulnerability
Palo Alto Networks PAN-OS contains an external control of file name or path vulnerability. Successful exploitation enables an authenticated attacker with network access to the management web interface to read files on the PAN-OS filesystem that are readable by the “nobody” user.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 7.1 (NVD)
FIRST EPSS: 0.020 (79th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-02-20
CISA remediation due: 2025-03-13
Known ransomware campaign use: Unknown/None
CVE-2025-21043 — Samsung Mobile Devices: Samsung Mobile Devices Out-of-Bounds Write Vulnerability
Samsung mobile devices contain an out-of-bounds write vulnerability in libimagecodec.quram.so which allows remote attackers to execute arbitrary code.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.019 (78.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-10-02
CISA remediation due: 2025-10-23
Known ransomware campaign use: Unknown/None
CVE-2025-59689 — Libraesva Email Security Gateway: Libraesva Email Security Gateway Command Injection Vulnerability
Libraesva Email Security Gateway (ESG) contains a command injection vulnerability which allows command injection via a compressed e-mail attachment.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 6.1 (NVD)
FIRST EPSS: 0.019 (77.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-09-29
CISA remediation due: 2025-10-20
Known ransomware campaign use: Unknown/None
CVE-2024-7694 — TeamT5 ThreatSonar Anti-Ransomware: TeamT5 ThreatSonar Anti-Ransomware Unrestricted Upload of File with Dangerous Type Vulnerability
TeamT5 ThreatSonar Anti-Ransomware contains an unrestricted upload of file with dangerous type vulnerability. ThreatSonar Anti-Ransomware does not properly validate the content of uploaded files. Remote attackers with administrator privileges on the product platform can upload malicious files, which can be used to execute arbitrary system commands on the server.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 7.2 (NVD)
FIRST EPSS: 0.018 (77.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-02-17
CISA remediation due: 2026-03-10
Known ransomware campaign use: Unknown/None
CVE-2018-19322 — GIGABYTE Multiple Products: GIGABYTE Multiple Products Code Execution Vulnerability
The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read/write data from/to IO ports. This could be leveraged in a number of ways to ultimately run code with elevated privileges.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.018 (77th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-10-24
CISA remediation due: 2022-11-14
Known ransomware campaign use: Known
CVE-2025-27920 — Srimax Output Messenger: Srimax Output Messenger Directory Traversal Vulnerability
Srimax Output Messenger contains a directory traversal vulnerability that allows an attacker to access sensitive files outside the intended directory, potentially leading to configuration leakage or arbitrary file access.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.018 (76.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-05-19
CISA remediation due: 2025-06-09
Known ransomware campaign use: Unknown/None
CVE-2020-11261 — Qualcomm Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables: Qualcomm Multiple Chipsets Improper Input Validation Vulnerability
Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.018 (76.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-12-01
CISA remediation due: 2022-06-01
Known ransomware campaign use: Unknown/None
CVE-2025-22226 — VMware ESXi, Workstation, and Fusion: VMware ESXi, Workstation, and Fusion Information Disclosure Vulnerability
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. Successful exploitation allows an attacker with administrative privileges to a virtual machine to leak memory from the vmx process.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 6.0 (NVD)
FIRST EPSS: 0.017 (76.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-03-04
CISA remediation due: 2025-03-25
Known ransomware campaign use: Unknown/None
CVE-2025-8875 — N-able N-Central: N-able N-Central Insecure Deserialization Vulnerability
N-able N-Central contains an insecure deserialization vulnerability that could lead to command execution.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.4 (NVD)
FIRST EPSS: 0.017 (75.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-08-13
CISA remediation due: 2025-08-20
Known ransomware campaign use: Unknown/None
CVE-2025-21590 — Juniper Junos OS: Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability
Juniper Junos OS contains an improper isolation or compartmentalization vulnerability. This vulnerability could allows a local attacker with high privileges to inject arbitrary code.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 6.7 (NVD)
FIRST EPSS: 0.017 (75.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-03-13
CISA remediation due: 2025-04-03
Known ransomware campaign use: Unknown/None
CVE-2025-48595 — Android Framework: Android Framework Integer Overflow Vulnerability
Android Framework contains an integer overflow vulnerability that allows for code execution that could allow for local privilege escalation.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 8.4 (NVD)
FIRST EPSS: 0.017 (75.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-06-02
CISA remediation due: 2026-06-05
Known ransomware campaign use: Unknown/None
CVE-2025-15556 — Notepad++ Notepad++: Notepad++ Download of Code Without Integrity Check Vulnerability
Notepad++ when using the WinGUp updater, contains a download of code without integrity check vulnerability that could allow an attacker to intercept or redirect update traffic to download and execute an attacker-controlled installer. This could lead to arbitrary code execution with the privileges of the user.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 7.7 (NVD)
FIRST EPSS: 0.017 (75.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-02-12
CISA remediation due: 2026-03-05
Known ransomware campaign use: Unknown/None
CVE-2025-48700 — Synacor Zimbra Collaboration Suite (ZCS): Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability
Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that could allow attackers to execute arbitrary JavaScript within the user's session, potentially leading to unauthorized access to sensitive information.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 6.1 (NVD)
FIRST EPSS: 0.017 (75.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-04-20
CISA remediation due: 2026-04-23
Known ransomware campaign use: Unknown/None
CVE-2024-39891 — Twilio Authy: Twilio Authy Information Disclosure Vulnerability
Twilio Authy contains an information disclosure vulnerability in its API that allows an unauthenticated endpoint to accept a request containing a phone number and respond with information about whether the phone number was registered with Authy.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 5.3 (NVD)
FIRST EPSS: 0.017 (75.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-07-23
CISA remediation due: 2024-08-13
Known ransomware campaign use: Unknown/None