Cross-Vendor Patch Advisories

Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.

Browse Advisories

Association
Vendor — all

Leave every box clear to show all 282 vendors.

1,308 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.

CISA KEV advisories matching the current filters, ranked by EVULNABLE Risk Score
CVE Vendor Product Vulnerability EVRS EPSS Ransomware CISA due
CVE-2025-21479 Qualcomm Multiple Chipsets Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability 75 Urgent 0.008 (54.4th pctl) Unknown/None 2025-06-24
CVE-2021-25372 Samsung Mobile Devices Samsung Mobile Devices Improper Boundary Check Vulnerability 75 Urgent 0.008 (54.3rd pctl) Unknown/None 2023-07-20
CVE-2021-25371 Samsung Mobile Devices Samsung Mobile Devices Unspecified Vulnerability 75 Urgent 0.008 (54.2nd pctl) Unknown/None 2023-07-20
CVE-2026-81578 PaperCut NG/MF PaperCut NG/MF Missing Authentication for Critical Function Vulnerability 75 Urgent 0.008 (53.2nd pctl) Unknown/None 2026-09-14
CVE-2024-4610 Arm Mali GPU Kernel Driver Arm Mali GPU Kernel Driver Use-After-Free Vulnerability 75 Urgent 0.008 (52.7th pctl) Unknown/None 2024-07-03
CVE-2021-39793 Google Pixel Google Pixel Out-of-Bounds Write Vulnerability 75 Urgent 0.007 (52.1st pctl) Unknown/None 2022-05-02
CVE-2024-43093 Android Framework Android Framework Privilege Escalation Vulnerability 75 Urgent 0.007 (51.3rd pctl) Unknown/None 2024-11-28
CVE-2019-8526 Apple macOS Apple macOS Use-After-Free Vulnerability 75 Urgent 0.007 (50.8th pctl) Unknown/None 2023-05-08
CVE-2023-33063 Qualcomm Multiple Chipsets Qualcomm Multiple Chipsets Use-After-Free Vulnerability 75 Urgent 0.007 (50.7th pctl) Unknown/None 2023-12-26
CVE-2025-1976 Broadcom Brocade Fabric OS Broadcom Brocade Fabric OS Code Injection Vulnerability 75 Urgent 0.007 (50.5th pctl) Unknown/None 2025-05-19
CVE-2024-29748 Android Pixel Android Pixel Privilege Escalation Vulnerability 75 Urgent 0.007 (50th pctl) Unknown/None 2024-04-25
CVE-2024-43047 Qualcomm Multiple Chipsets Qualcomm Multiple Chipsets Use-After-Free Vulnerability 75 Urgent 0.007 (49.7th pctl) Unknown/None 2024-10-29
CVE-2021-25487 Samsung Mobile Devices Samsung Mobile Devices Out-of-Bounds Read Vulnerability 75 Urgent 0.006 (48.1st pctl) Unknown/None 2023-07-20
CVE-2026-66384 JFrog Artifactory JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability 75 Urgent 0.006 (45.4th pctl) Unknown/None 2026-09-10
CVE-2025-48928 TeleMessage TM SGNL TeleMessage TM SGNL Exposure of Core Dump File to an Unauthorized Control Sphere Vulnerability 75 Urgent 0.006 (44.1st pctl) Unknown/None 2025-07-22
CVE-2021-25489 Samsung Mobile Devices Samsung Mobile Devices Improper Input Validation Vulnerability 75 Urgent 0.005 (42.8th pctl) Unknown/None 2023-07-20
CVE-2025-48543 Android Runtime Android Runtime Use-After-Free Vulnerability 75 Urgent 0.005 (42.9th pctl) Unknown/None 2025-09-25
CVE-2021-1906 Qualcomm Multiple Chipsets Qualcomm Multiple Chipsets Detection of Error Condition Without Action Vulnerability 75 Urgent 0.005 (42.2nd pctl) Unknown/None 2021-11-17
CVE-2026-59822 BerriAI LiteLLM BerriAI LiteLLM Improper Authentication Vulnerability 75 Urgent 0.005 (41.9th pctl) Unknown/None 2026-09-16
CVE-2026-53362 Linux Kernel Linux Kernel Unspecified Vulnerability 75 Urgent 0.005 (41.6th pctl) Unknown/None 2026-08-30
CVE-2022-48618 Apple Multiple Products Apple Multiple Products Memory Corruption Vulnerability 75 Urgent 0.005 (40.1st pctl) Unknown/None 2024-02-21
CVE-2024-29745 Android Pixel Android Pixel Information Disclosure Vulnerability 75 Urgent 0.005 (39.7th pctl) Unknown/None 2024-04-25
CVE-2022-22071 Qualcomm Multiple Chipsets Qualcomm Multiple Chipsets Use-After-Free Vulnerability 75 Urgent 0.005 (37.9th pctl) Unknown/None 2023-12-26
CVE-2025-21480 Qualcomm Multiple Chipsets Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability 75 Urgent 0.004 (36.9th pctl) Unknown/None 2025-06-24
CVE-2025-43520 Apple Multiple Products Apple Multiple Products Classic Buffer Overflow Vulnerability 75 Urgent 0.004 (36.1st pctl) Unknown/None 2026-04-03
Download filtered advisories (CSV)

Exactly the 1,308 advisory(ies) matching the filters above.

Advisory detail

Expand any advisory for its description, CISA's own required action, and research links.

CVE-2025-21479 — Qualcomm Multiple Chipsets: Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability

Multiple Qualcomm chipsets contain an incorrect authorization vulnerability. This vulnerability allows for memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 8.6 (NVD)

FIRST EPSS: 0.008 (54.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-06-03

CISA remediation due: 2025-06-24

Known ransomware campaign use: Unknown/None

CVE-2021-25372 — Samsung Mobile Devices: Samsung Mobile Devices Improper Boundary Check Vulnerability

Samsung mobile devices contain an improper boundary check vulnerability within DSP driver that allows for out-of-bounds memory access.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable

CVSS: 6.7 (NVD)

FIRST EPSS: 0.008 (54.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-06-29

CISA remediation due: 2023-07-20

Known ransomware campaign use: Unknown/None

CVE-2021-25371 — Samsung Mobile Devices: Samsung Mobile Devices Unspecified Vulnerability

Samsung mobile devices contain an unspecified vulnerability within DSP driver that allows attackers to load ELF libraries inside DSP.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable

CVSS: 6.7 (NVD)

FIRST EPSS: 0.008 (54.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-06-29

CISA remediation due: 2023-07-20

Known ransomware campaign use: Unknown/None

CVE-2026-81578 — PaperCut NG/MF: PaperCut NG/MF Missing Authentication for Critical Function Vulnerability

PaperCut NG/MF contains a missing authentication for critical function vulnerability which allows an unauthenticated remote attacker to modify certain system configurations. This vulnerability can be chained with CVE-2026-82078.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.008 (53.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-08-31

CISA remediation due: 2026-09-14

Known ransomware campaign use: Unknown/None

CVE-2024-4610 — Arm Mali GPU Kernel Driver: Arm Mali GPU Kernel Driver Use-After-Free Vulnerability

Arm Bifrost and Valhall GPU kernel drivers contain a use-after-free vulnerability that allows a local, non-privileged user to make improper GPU memory processing operations to gain access to already freed memory.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.008 (52.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-06-12

CISA remediation due: 2024-07-03

Known ransomware campaign use: Unknown/None

CVE-2021-39793 — Google Pixel: Google Pixel Out-of-Bounds Write Vulnerability

Google Pixel contains a possible out-of-bounds write due to a logic error in the code that could lead to local escalation of privilege.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.007 (52.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-04-11

CISA remediation due: 2022-05-02

Known ransomware campaign use: Unknown/None

CVE-2024-43093 — Android Framework: Android Framework Privilege Escalation Vulnerability

Android Framework contains an unspecified vulnerability that allows for privilege escalation.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 7.3 (NVD)

FIRST EPSS: 0.007 (51.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-11-07

CISA remediation due: 2024-11-28

Known ransomware campaign use: Unknown/None

CVE-2019-8526 — Apple macOS: Apple macOS Use-After-Free Vulnerability

Apple macOS contains a use-after-free vulnerability that could allow for privilege escalation.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.007 (50.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-04-17

CISA remediation due: 2023-05-08

Known ransomware campaign use: Unknown/None

CVE-2023-33063 — Qualcomm Multiple Chipsets: Qualcomm Multiple Chipsets Use-After-Free Vulnerability

Multiple Qualcomm chipsets contain a use-after-free vulnerability due to memory corruption in DSP Services during a remote call from HLOS to DSP.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.007 (50.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-12-05

CISA remediation due: 2023-12-26

Known ransomware campaign use: Unknown/None

CVE-2025-1976 — Broadcom Brocade Fabric OS: Broadcom Brocade Fabric OS Code Injection Vulnerability

Broadcom Brocade Fabric OS contains a code injection vulnerability that allows a local user with administrative privileges to execute arbitrary code with full root privileges.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 8.6 (NVD)

FIRST EPSS: 0.007 (50.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-04-28

CISA remediation due: 2025-05-19

Known ransomware campaign use: Unknown/None

CVE-2024-29748 — Android Pixel: Android Pixel Privilege Escalation Vulnerability

Android Pixel contains a privilege escalation vulnerability that allows an attacker to interrupt a factory reset triggered by a device admin app.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.007 (50th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-04-04

CISA remediation due: 2024-04-25

Known ransomware campaign use: Unknown/None

CVE-2024-43047 — Qualcomm Multiple Chipsets: Qualcomm Multiple Chipsets Use-After-Free Vulnerability

Multiple Qualcomm chipsets contain a use-after-free vulnerability due to memory corruption in DSP Services while maintaining memory maps of HLOS memory.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.007 (49.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-10-08

CISA remediation due: 2024-10-29

Known ransomware campaign use: Unknown/None

CVE-2021-25487 — Samsung Mobile Devices: Samsung Mobile Devices Out-of-Bounds Read Vulnerability

Samsung mobile devices contain an out-of-bounds read vulnerability within the modem interface driver due to a lack of boundary checking of a buffer in set_skb_priv(), leading to remote code execution by dereference of an invalid function pointer.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable

CVSS: 7.8 (NVD)

FIRST EPSS: 0.006 (48.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-06-29

CISA remediation due: 2023-07-20

Known ransomware campaign use: Unknown/None

CVE-2026-66384 — JFrog Artifactory: JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability

JFrog Artifactory contains an improper limitation of a pathname to a restricted directory vulnerability. This can allow an authenticated user to write data outside the intended Docker cache path under specific remote-repository conditions.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVSS: 5.3 (NVD)

FIRST EPSS: 0.006 (45.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-08-27

CISA remediation due: 2026-09-10

Known ransomware campaign use: Unknown/None

CVE-2025-48928 — TeleMessage TM SGNL: TeleMessage TM SGNL Exposure of Core Dump File to an Unauthorized Control Sphere Vulnerability

TeleMessage TM SGNL contains an exposure of core dump file to an unauthorized control sphere Vulnerability. This vulnerability is based on a JSP application in which the heap content is roughly equivalent to a "core dump" in which a password previously sent over HTTP would be included in this dump.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 4.0 (NVD)

FIRST EPSS: 0.006 (44.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-07-01

CISA remediation due: 2025-07-22

Known ransomware campaign use: Unknown/None

CVE-2021-25489 — Samsung Mobile Devices: Samsung Mobile Devices Improper Input Validation Vulnerability

Samsung mobile devices contain an improper input validation vulnerability within the modem interface driver that results in a format string bug leading to kernel panic.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable

CVSS: 5.5 (NVD)

FIRST EPSS: 0.005 (42.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-06-29

CISA remediation due: 2023-07-20

Known ransomware campaign use: Unknown/None

CVE-2025-48543 — Android Runtime: Android Runtime Use-After-Free Vulnerability

Android Runtime contains a use-after-free vulnerability potentially allowing a chrome sandbox escape leading to local privilege escalation.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.005 (42.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-09-04

CISA remediation due: 2025-09-25

Known ransomware campaign use: Unknown/None

CVE-2021-1906 — Qualcomm Multiple Chipsets: Qualcomm Multiple Chipsets Detection of Error Condition Without Action Vulnerability

Multiple Qualcomm chipsets contain a detection of error condition without action vulnerability when improper handling of address deregistration on failure can lead to new GPU address allocation failure.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply updates per vendor instructions.

CVSS: 5.5 (NVD)

FIRST EPSS: 0.005 (42.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2021-11-17

Known ransomware campaign use: Unknown/None

CVE-2026-59822 — BerriAI LiteLLM: BerriAI LiteLLM Improper Authentication Vulnerability

BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.005 (41.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-09-02

CISA remediation due: 2026-09-16

Known ransomware campaign use: Unknown/None

CVE-2026-53362 — Linux Kernel: Linux Kernel Unspecified Vulnerability

Linux Kernel contains an unspecified vulnerability that can allow for privilege escalation via IPv6 networking subsystem. This vulnerability can impact multiple products, including but not limited to Suse, Red Hat, and other products using Linux.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.005 (41.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-08-27

CISA remediation due: 2026-08-30

Known ransomware campaign use: Unknown/None

CVE-2022-48618 — Apple Multiple Products: Apple Multiple Products Memory Corruption Vulnerability

Apple iOS, iPadOS, macOS, tvOS, and watchOS contain a time-of-check/time-of-use (TOCTOU) memory corruption vulnerability that allows an attacker with read and write capabilities to bypass Pointer Authentication.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 7.0 (NVD)

FIRST EPSS: 0.005 (40.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-01-31

CISA remediation due: 2024-02-21

Known ransomware campaign use: Unknown/None

CVE-2024-29745 — Android Pixel: Android Pixel Information Disclosure Vulnerability

Android Pixel contains an information disclosure vulnerability in the fastboot firmware used to support unlocking, flashing, and locking affected devices.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 5.5 (NVD)

FIRST EPSS: 0.005 (39.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-04-04

CISA remediation due: 2024-04-25

Known ransomware campaign use: Unknown/None

CVE-2022-22071 — Qualcomm Multiple Chipsets: Qualcomm Multiple Chipsets Use-After-Free Vulnerability

Multiple Qualcomm chipsets contain a use-after-free vulnerability when process shell memory is freed using IOCTL munmap call and process initialization is in progress.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.005 (37.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-12-05

CISA remediation due: 2023-12-26

Known ransomware campaign use: Unknown/None

CVE-2025-21480 — Qualcomm Multiple Chipsets: Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability

Multiple Qualcomm chipsets contain an incorrect authorization vulnerability. This vulnerability allows for memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 8.6 (NVD)

FIRST EPSS: 0.004 (36.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-06-03

CISA remediation due: 2025-06-24

Known ransomware campaign use: Unknown/None

CVE-2025-43520 — Apple Multiple Products: Apple Multiple Products Classic Buffer Overflow Vulnerability

Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain a classic buffer overflow vulnerability which could allow a malicious application to cause unexpected system termination or write kernel memory.

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 5.5 (NVD)

FIRST EPSS: 0.004 (36.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-03-20

CISA remediation due: 2026-04-03

Known ransomware campaign use: Unknown/None

Data sources & attribution

Known-exploitation status, required actions, ransomware association and remediation deadlines come from the CISA Known Exploited Vulnerabilities Catalog. Exploitation probability and percentile are provided by FIRST.org's EPSS, used under FIRST's open data terms.

Microsoft Patch Tuesday data is sourced from the Microsoft Security Update Guide; lifecycle milestones from endoflife.date. Linux distribution advisories come from Red Hat, Ubuntu and Debian; vendor bulletins from Adobe, Apple, Chrome, Cisco, Ivanti and Oracle, each linked to its own advisory.