Cross-Vendor Patch Advisories
Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.
Browse Advisories
1,308 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.
| CVE | Vendor | Product | Vulnerability | EVRS | EPSS | Ransomware | CISA due |
|---|---|---|---|---|---|---|---|
| CVE-2025-21479 | Qualcomm | Multiple Chipsets | Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability | 75 Urgent | 0.008 (54.4th pctl) | Unknown/None | 2025-06-24 |
| CVE-2021-25372 | Samsung | Mobile Devices | Samsung Mobile Devices Improper Boundary Check Vulnerability | 75 Urgent | 0.008 (54.3rd pctl) | Unknown/None | 2023-07-20 |
| CVE-2021-25371 | Samsung | Mobile Devices | Samsung Mobile Devices Unspecified Vulnerability | 75 Urgent | 0.008 (54.2nd pctl) | Unknown/None | 2023-07-20 |
| CVE-2026-81578 | PaperCut | NG/MF | PaperCut NG/MF Missing Authentication for Critical Function Vulnerability | 75 Urgent | 0.008 (53.2nd pctl) | Unknown/None | 2026-09-14 |
| CVE-2024-4610 | Arm | Mali GPU Kernel Driver | Arm Mali GPU Kernel Driver Use-After-Free Vulnerability | 75 Urgent | 0.008 (52.7th pctl) | Unknown/None | 2024-07-03 |
| CVE-2021-39793 | Pixel | Google Pixel Out-of-Bounds Write Vulnerability | 75 Urgent | 0.007 (52.1st pctl) | Unknown/None | 2022-05-02 | |
| CVE-2024-43093 | Android | Framework | Android Framework Privilege Escalation Vulnerability | 75 Urgent | 0.007 (51.3rd pctl) | Unknown/None | 2024-11-28 |
| CVE-2019-8526 | Apple | macOS | Apple macOS Use-After-Free Vulnerability | 75 Urgent | 0.007 (50.8th pctl) | Unknown/None | 2023-05-08 |
| CVE-2023-33063 | Qualcomm | Multiple Chipsets | Qualcomm Multiple Chipsets Use-After-Free Vulnerability | 75 Urgent | 0.007 (50.7th pctl) | Unknown/None | 2023-12-26 |
| CVE-2025-1976 | Broadcom | Brocade Fabric OS | Broadcom Brocade Fabric OS Code Injection Vulnerability | 75 Urgent | 0.007 (50.5th pctl) | Unknown/None | 2025-05-19 |
| CVE-2024-29748 | Android | Pixel | Android Pixel Privilege Escalation Vulnerability | 75 Urgent | 0.007 (50th pctl) | Unknown/None | 2024-04-25 |
| CVE-2024-43047 | Qualcomm | Multiple Chipsets | Qualcomm Multiple Chipsets Use-After-Free Vulnerability | 75 Urgent | 0.007 (49.7th pctl) | Unknown/None | 2024-10-29 |
| CVE-2021-25487 | Samsung | Mobile Devices | Samsung Mobile Devices Out-of-Bounds Read Vulnerability | 75 Urgent | 0.006 (48.1st pctl) | Unknown/None | 2023-07-20 |
| CVE-2026-66384 | JFrog | Artifactory | JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability | 75 Urgent | 0.006 (45.4th pctl) | Unknown/None | 2026-09-10 |
| CVE-2025-48928 | TeleMessage | TM SGNL | TeleMessage TM SGNL Exposure of Core Dump File to an Unauthorized Control Sphere Vulnerability | 75 Urgent | 0.006 (44.1st pctl) | Unknown/None | 2025-07-22 |
| CVE-2021-25489 | Samsung | Mobile Devices | Samsung Mobile Devices Improper Input Validation Vulnerability | 75 Urgent | 0.005 (42.8th pctl) | Unknown/None | 2023-07-20 |
| CVE-2025-48543 | Android | Runtime | Android Runtime Use-After-Free Vulnerability | 75 Urgent | 0.005 (42.9th pctl) | Unknown/None | 2025-09-25 |
| CVE-2021-1906 | Qualcomm | Multiple Chipsets | Qualcomm Multiple Chipsets Detection of Error Condition Without Action Vulnerability | 75 Urgent | 0.005 (42.2nd pctl) | Unknown/None | 2021-11-17 |
| CVE-2026-59822 | BerriAI | LiteLLM | BerriAI LiteLLM Improper Authentication Vulnerability | 75 Urgent | 0.005 (41.9th pctl) | Unknown/None | 2026-09-16 |
| CVE-2026-53362 | Linux | Kernel | Linux Kernel Unspecified Vulnerability | 75 Urgent | 0.005 (41.6th pctl) | Unknown/None | 2026-08-30 |
| CVE-2022-48618 | Apple | Multiple Products | Apple Multiple Products Memory Corruption Vulnerability | 75 Urgent | 0.005 (40.1st pctl) | Unknown/None | 2024-02-21 |
| CVE-2024-29745 | Android | Pixel | Android Pixel Information Disclosure Vulnerability | 75 Urgent | 0.005 (39.7th pctl) | Unknown/None | 2024-04-25 |
| CVE-2022-22071 | Qualcomm | Multiple Chipsets | Qualcomm Multiple Chipsets Use-After-Free Vulnerability | 75 Urgent | 0.005 (37.9th pctl) | Unknown/None | 2023-12-26 |
| CVE-2025-21480 | Qualcomm | Multiple Chipsets | Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability | 75 Urgent | 0.004 (36.9th pctl) | Unknown/None | 2025-06-24 |
| CVE-2025-43520 | Apple | Multiple Products | Apple Multiple Products Classic Buffer Overflow Vulnerability | 75 Urgent | 0.004 (36.1st pctl) | Unknown/None | 2026-04-03 |
Exactly the 1,308 advisory(ies) matching the filters above.
Advisory detail
Expand any advisory for its description, CISA's own required action, and research links.
CVE-2025-21479 — Qualcomm Multiple Chipsets: Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability
Multiple Qualcomm chipsets contain an incorrect authorization vulnerability. This vulnerability allows for memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 8.6 (NVD)
FIRST EPSS: 0.008 (54.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-06-03
CISA remediation due: 2025-06-24
Known ransomware campaign use: Unknown/None
CVE-2021-25372 — Samsung Mobile Devices: Samsung Mobile Devices Improper Boundary Check Vulnerability
Samsung mobile devices contain an improper boundary check vulnerability within DSP driver that allows for out-of-bounds memory access.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable
CVSS: 6.7 (NVD)
FIRST EPSS: 0.008 (54.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-06-29
CISA remediation due: 2023-07-20
Known ransomware campaign use: Unknown/None
CVE-2021-25371 — Samsung Mobile Devices: Samsung Mobile Devices Unspecified Vulnerability
Samsung mobile devices contain an unspecified vulnerability within DSP driver that allows attackers to load ELF libraries inside DSP.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable
CVSS: 6.7 (NVD)
FIRST EPSS: 0.008 (54.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-06-29
CISA remediation due: 2023-07-20
Known ransomware campaign use: Unknown/None
CVE-2026-81578 — PaperCut NG/MF: PaperCut NG/MF Missing Authentication for Critical Function Vulnerability
PaperCut NG/MF contains a missing authentication for critical function vulnerability which allows an unauthenticated remote attacker to modify certain system configurations. This vulnerability can be chained with CVE-2026-82078.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.008 (53.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-08-31
CISA remediation due: 2026-09-14
Known ransomware campaign use: Unknown/None
CVE-2024-4610 — Arm Mali GPU Kernel Driver: Arm Mali GPU Kernel Driver Use-After-Free Vulnerability
Arm Bifrost and Valhall GPU kernel drivers contain a use-after-free vulnerability that allows a local, non-privileged user to make improper GPU memory processing operations to gain access to already freed memory.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.008 (52.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-06-12
CISA remediation due: 2024-07-03
Known ransomware campaign use: Unknown/None
CVE-2021-39793 — Google Pixel: Google Pixel Out-of-Bounds Write Vulnerability
Google Pixel contains a possible out-of-bounds write due to a logic error in the code that could lead to local escalation of privilege.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.007 (52.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-04-11
CISA remediation due: 2022-05-02
Known ransomware campaign use: Unknown/None
CVE-2024-43093 — Android Framework: Android Framework Privilege Escalation Vulnerability
Android Framework contains an unspecified vulnerability that allows for privilege escalation.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 7.3 (NVD)
FIRST EPSS: 0.007 (51.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-11-07
CISA remediation due: 2024-11-28
Known ransomware campaign use: Unknown/None
CVE-2019-8526 — Apple macOS: Apple macOS Use-After-Free Vulnerability
Apple macOS contains a use-after-free vulnerability that could allow for privilege escalation.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.007 (50.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-04-17
CISA remediation due: 2023-05-08
Known ransomware campaign use: Unknown/None
CVE-2023-33063 — Qualcomm Multiple Chipsets: Qualcomm Multiple Chipsets Use-After-Free Vulnerability
Multiple Qualcomm chipsets contain a use-after-free vulnerability due to memory corruption in DSP Services during a remote call from HLOS to DSP.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.007 (50.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-12-05
CISA remediation due: 2023-12-26
Known ransomware campaign use: Unknown/None
CVE-2025-1976 — Broadcom Brocade Fabric OS: Broadcom Brocade Fabric OS Code Injection Vulnerability
Broadcom Brocade Fabric OS contains a code injection vulnerability that allows a local user with administrative privileges to execute arbitrary code with full root privileges.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 8.6 (NVD)
FIRST EPSS: 0.007 (50.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-04-28
CISA remediation due: 2025-05-19
Known ransomware campaign use: Unknown/None
CVE-2024-29748 — Android Pixel: Android Pixel Privilege Escalation Vulnerability
Android Pixel contains a privilege escalation vulnerability that allows an attacker to interrupt a factory reset triggered by a device admin app.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.007 (50th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-04-04
CISA remediation due: 2024-04-25
Known ransomware campaign use: Unknown/None
CVE-2024-43047 — Qualcomm Multiple Chipsets: Qualcomm Multiple Chipsets Use-After-Free Vulnerability
Multiple Qualcomm chipsets contain a use-after-free vulnerability due to memory corruption in DSP Services while maintaining memory maps of HLOS memory.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.007 (49.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-10-08
CISA remediation due: 2024-10-29
Known ransomware campaign use: Unknown/None
CVE-2021-25487 — Samsung Mobile Devices: Samsung Mobile Devices Out-of-Bounds Read Vulnerability
Samsung mobile devices contain an out-of-bounds read vulnerability within the modem interface driver due to a lack of boundary checking of a buffer in set_skb_priv(), leading to remote code execution by dereference of an invalid function pointer.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable
CVSS: 7.8 (NVD)
FIRST EPSS: 0.006 (48.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-06-29
CISA remediation due: 2023-07-20
Known ransomware campaign use: Unknown/None
CVE-2026-66384 — JFrog Artifactory: JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability
JFrog Artifactory contains an improper limitation of a pathname to a restricted directory vulnerability. This can allow an authenticated user to write data outside the intended Docker cache path under specific remote-repository conditions.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVSS: 5.3 (NVD)
FIRST EPSS: 0.006 (45.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-08-27
CISA remediation due: 2026-09-10
Known ransomware campaign use: Unknown/None
CVE-2025-48928 — TeleMessage TM SGNL: TeleMessage TM SGNL Exposure of Core Dump File to an Unauthorized Control Sphere Vulnerability
TeleMessage TM SGNL contains an exposure of core dump file to an unauthorized control sphere Vulnerability. This vulnerability is based on a JSP application in which the heap content is roughly equivalent to a "core dump" in which a password previously sent over HTTP would be included in this dump.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 4.0 (NVD)
FIRST EPSS: 0.006 (44.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-07-01
CISA remediation due: 2025-07-22
Known ransomware campaign use: Unknown/None
CVE-2021-25489 — Samsung Mobile Devices: Samsung Mobile Devices Improper Input Validation Vulnerability
Samsung mobile devices contain an improper input validation vulnerability within the modem interface driver that results in a format string bug leading to kernel panic.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable
CVSS: 5.5 (NVD)
FIRST EPSS: 0.005 (42.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-06-29
CISA remediation due: 2023-07-20
Known ransomware campaign use: Unknown/None
CVE-2025-48543 — Android Runtime: Android Runtime Use-After-Free Vulnerability
Android Runtime contains a use-after-free vulnerability potentially allowing a chrome sandbox escape leading to local privilege escalation.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.005 (42.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-09-04
CISA remediation due: 2025-09-25
Known ransomware campaign use: Unknown/None
CVE-2021-1906 — Qualcomm Multiple Chipsets: Qualcomm Multiple Chipsets Detection of Error Condition Without Action Vulnerability
Multiple Qualcomm chipsets contain a detection of error condition without action vulnerability when improper handling of address deregistration on failure can lead to new GPU address allocation failure.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply updates per vendor instructions.
CVSS: 5.5 (NVD)
FIRST EPSS: 0.005 (42.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2021-11-17
Known ransomware campaign use: Unknown/None
CVE-2026-59822 — BerriAI LiteLLM: BerriAI LiteLLM Improper Authentication Vulnerability
BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.005 (41.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-09-02
CISA remediation due: 2026-09-16
Known ransomware campaign use: Unknown/None
CVE-2026-53362 — Linux Kernel: Linux Kernel Unspecified Vulnerability
Linux Kernel contains an unspecified vulnerability that can allow for privilege escalation via IPv6 networking subsystem. This vulnerability can impact multiple products, including but not limited to Suse, Red Hat, and other products using Linux.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.005 (41.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-08-27
CISA remediation due: 2026-08-30
Known ransomware campaign use: Unknown/None
CVE-2022-48618 — Apple Multiple Products: Apple Multiple Products Memory Corruption Vulnerability
Apple iOS, iPadOS, macOS, tvOS, and watchOS contain a time-of-check/time-of-use (TOCTOU) memory corruption vulnerability that allows an attacker with read and write capabilities to bypass Pointer Authentication.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 7.0 (NVD)
FIRST EPSS: 0.005 (40.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-01-31
CISA remediation due: 2024-02-21
Known ransomware campaign use: Unknown/None
CVE-2024-29745 — Android Pixel: Android Pixel Information Disclosure Vulnerability
Android Pixel contains an information disclosure vulnerability in the fastboot firmware used to support unlocking, flashing, and locking affected devices.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 5.5 (NVD)
FIRST EPSS: 0.005 (39.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-04-04
CISA remediation due: 2024-04-25
Known ransomware campaign use: Unknown/None
CVE-2022-22071 — Qualcomm Multiple Chipsets: Qualcomm Multiple Chipsets Use-After-Free Vulnerability
Multiple Qualcomm chipsets contain a use-after-free vulnerability when process shell memory is freed using IOCTL munmap call and process initialization is in progress.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.005 (37.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-12-05
CISA remediation due: 2023-12-26
Known ransomware campaign use: Unknown/None
CVE-2025-21480 — Qualcomm Multiple Chipsets: Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability
Multiple Qualcomm chipsets contain an incorrect authorization vulnerability. This vulnerability allows for memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 8.6 (NVD)
FIRST EPSS: 0.004 (36.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-06-03
CISA remediation due: 2025-06-24
Known ransomware campaign use: Unknown/None
CVE-2025-43520 — Apple Multiple Products: Apple Multiple Products Classic Buffer Overflow Vulnerability
Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain a classic buffer overflow vulnerability which could allow a malicious application to cause unexpected system termination or write kernel memory.
Recommended priority: Patch This Cycle
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 5.5 (NVD)
FIRST EPSS: 0.004 (36.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-03-20
CISA remediation due: 2026-04-03
Known ransomware campaign use: Unknown/None