Cross-Vendor Patch Advisories

Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.

Browse Advisories

Association
Vendor — all

Leave every box clear to show all 282 vendors.

1,308 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.

CISA KEV advisories matching the current filters, ranked by EVULNABLE Risk Score
CVE Vendor Product Vulnerability EVRS EPSS Ransomware CISA due
CVE-2023-41265 Qlik Sense Qlik Sense HTTP Tunneling Vulnerability 91 Immediate 0.882 (99.76th pctl) Known 2023-12-28
CVE-2019-7192 QNAP Photo Station QNAP Photo Station Improper Access Control Vulnerability 91 Immediate 0.882 (99.76th pctl) Known 2022-06-22
CVE-2024-51567 CyberPersons CyberPanel CyberPanel Incorrect Default Permissions Vulnerability 91 Immediate 0.865 (99.72nd pctl) Known 2024-11-28
CVE-2023-0669 Fortra GoAnywhere MFT Fortra GoAnywhere MFT Remote Code Execution Vulnerability 90 Immediate 0.999 (99.99th pctl) Known 2023-03-03
CVE-2017-7921 Hikvision Multiple Products Hikvision Multiple Products Improper Authentication Vulnerability 90 Immediate 0.999 (99.99th pctl) Unknown/None 2026-03-26
CVE-2025-24893 XWiki Platform XWiki Platform Eval Injection Vulnerability 90 Immediate 0.999 (99.96th pctl) Unknown/None 2025-11-20
CVE-2025-32432 Craft CMS Craft CMS Craft CMS Code Injection Vulnerability 90 Immediate 0.998 (99.96th pctl) Unknown/None 2026-04-03
CVE-2017-1000353 Jenkins Jenkins Jenkins Remote Code Execution Vulnerability 90 Immediate 0.997 (99.95th pctl) Unknown/None 2025-10-23
CVE-2022-30333 RARLAB UnRAR RARLAB UnRAR Directory Traversal Vulnerability 90 Immediate 0.991 (99.93rd pctl) Known 2022-08-30
CVE-2022-27925 Synacor Zimbra Collaboration Suite (ZCS) Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability 90 Immediate 0.987 (99.92nd pctl) Known 2022-09-01
CVE-2026-34486 Apache Tomcat Apache Tomcat Missing Encryption of Sensitive Data Vulnerability 90 Immediate 0.986 (99.92nd pctl) Unknown/None 2026-08-07
CVE-2019-11539 Ivanti Pulse Connect Secure and Pulse Policy Secure Ivanti Pulse Connect Secure and Policy Secure Command Injection Vulnerability 90 Immediate 0.985 (99.92nd pctl) Known 2022-05-03
CVE-2018-20250 RARLAB WinRAR WinRAR Absolute Path Traversal Vulnerability 90 Immediate 0.963 (99.88th pctl) Known 2022-08-15
CVE-2024-57727 SimpleHelp SimpleHelp SimpleHelp Path Traversal Vulnerability 90 Immediate 0.952 (99.86th pctl) Known 2025-03-06
CVE-2021-4034 Red Hat Polkit Red Hat Polkit Out-of-Bounds Read and Write Vulnerability 90 Immediate 0.949 (99.85th pctl) Known 2022-07-18
CVE-2023-40044 Progress WS_FTP Server Progress WS_FTP Server Deserialization of Untrusted Data Vulnerability 90 Immediate 0.901 (99.79th pctl) Known 2023-10-26
CVE-2022-27593 QNAP Photo Station QNAP Photo Station Externally Controlled Reference Vulnerability 90 Immediate 0.879 (99.75th pctl) Known 2022-09-29
CVE-2026-63077 JetBrains TeamCity JetBrains TeamCity Deserialization of Untrusted Data Vulnerability 90 Immediate 0.877 (99.75th pctl) Unknown/None 2026-08-08
CVE-2019-16057 D-Link DNS-320 Storage Device D-Link DNS-320 Remote Code Execution Vulnerability 90 Immediate 0.871 (99.73rd pctl) Known 2022-05-06
CVE-2017-18362 Kaseya Virtual System/Server Administrator (VSA) Kaseya VSA SQL Injection Vulnerability 90 Immediate 0.868 (99.73rd pctl) Known 2022-06-14
CVE-2026-60004 Gitea Gitea Gitea Code Injection Vulnerability 90 Immediate 0.868 (99.73rd pctl) Unknown/None 2026-08-28
CVE-2021-30116 Kaseya Virtual System/Server Administrator (VSA) Kaseya Virtual System/Server Administrator (VSA) Information Disclosure Vulnerability 90 Immediate 0.857 (99.71st pctl) Known 2021-11-17
CVE-2023-27997 Fortinet FortiOS and FortiProxy SSL-VPN Fortinet FortiOS and FortiProxy SSL-VPN Heap-Based Buffer Overflow Vulnerability 90 Immediate 0.857 (99.71st pctl) Known 2023-07-04
CVE-2024-21762 Fortinet FortiOS Fortinet FortiOS Out-of-Bound Write Vulnerability 90 Immediate 0.843 (99.68th pctl) Known 2024-02-16
CVE-2025-48703 CWP Control Web Panel CWP Control Web Panel OS Command Injection Vulnerability 89 Immediate 0.997 (99.95th pctl) Unknown/None 2025-11-25
Download filtered advisories (CSV)

Exactly the 1,308 advisory(ies) matching the filters above.

Advisory detail

Expand any advisory for its description, CISA's own required action, and research links.

CVE-2023-41265 — Qlik Sense: Qlik Sense HTTP Tunneling Vulnerability

Qlik Sense contains an HTTP tunneling vulnerability that allows an attacker to escalate privileges and execute HTTP requests on the backend server hosting the software.

EVULNABLE Risk · priority 91/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.882.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.

CVSS: 9.9 (NVD)

FIRST EPSS: 0.882 (99.76th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-12-07

CISA remediation due: 2023-12-28

Known ransomware campaign use: Known

CVE-2019-7192 — QNAP Photo Station: QNAP Photo Station Improper Access Control Vulnerability

QNAP NAS devices running Photo Station contain an improper access control vulnerability allowing remote attackers to gain unauthorized access to the system.

EVULNABLE Risk · priority 91/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.882.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.882 (99.76th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-06-08

CISA remediation due: 2022-06-22

Known ransomware campaign use: Known

CVE-2024-51567 — CyberPersons CyberPanel: CyberPanel Incorrect Default Permissions Vulnerability

CyberPanel contains an incorrect default permissions vulnerability that allows a remote, unauthenticated attacker to execute commands as root.

EVULNABLE Risk · priority 91/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.865.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.865 (99.72nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-11-07

CISA remediation due: 2024-11-28

Known ransomware campaign use: Known

CVE-2023-0669 — Fortra GoAnywhere MFT: Fortra GoAnywhere MFT Remote Code Execution Vulnerability

Fortra (formerly, HelpSystems) GoAnywhere MFT contains a pre-authentication remote code execution vulnerability in the License Response Servlet due to deserializing an attacker-controlled object.

EVULNABLE Risk · priority 90/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch Immediately

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.2 (NVD)

FIRST EPSS: 0.999 (99.99th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-02-10

CISA remediation due: 2023-03-03

Known ransomware campaign use: Known

CVE-2017-7921 — Hikvision Multiple Products: Hikvision Multiple Products Improper Authentication Vulnerability

Multiple Hikvision products contain an improper authentication vulnerability that could allow a malicious user to escalate privileges on the system and gain access to sensitive information.

EVULNABLE Risk · priority 90/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.999 (99.99th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-03-05

CISA remediation due: 2026-03-26

Known ransomware campaign use: Unknown/None

CVE-2025-24893 — XWiki Platform: XWiki Platform Eval Injection Vulnerability

XWiki Platform contains an eval injection vulnerability that could allow any guest to perform arbitrary remote code execution through a request to SolrSearch.

EVULNABLE Risk · priority 90/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.999 (99.96th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-10-30

CISA remediation due: 2025-11-20

Known ransomware campaign use: Unknown/None

CVE-2025-32432 — Craft CMS Craft CMS: Craft CMS Code Injection Vulnerability

Craft CMS contains a code injection vulnerability that allows a remote attacker to execute arbitrary code.

EVULNABLE Risk · priority 90/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.998.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 10.0 (NVD)

FIRST EPSS: 0.998 (99.96th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-03-20

CISA remediation due: 2026-04-03

Known ransomware campaign use: Unknown/None

CVE-2017-1000353 — Jenkins Jenkins: Jenkins Remote Code Execution Vulnerability

Jenkins contains a remote code execution vulnerability. This vulnerability that could allowed attackers to transfer a serialized Java SignedObject object to the remoting-based Jenkins CLI, that would be deserialized using a new ObjectInputStream, bypassing the existing blocklist-based protection mechanism.

EVULNABLE Risk · priority 90/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.997.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.997 (99.95th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-10-02

CISA remediation due: 2025-10-23

Known ransomware campaign use: Unknown/None

CVE-2022-30333 — RARLAB UnRAR: RARLAB UnRAR Directory Traversal Vulnerability

RARLAB UnRAR on Linux and UNIX contains a directory traversal vulnerability, allowing an attacker to write to files during an extract (unpack) operation.

EVULNABLE Risk · priority 90/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch Immediately

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.991.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.991 (99.93rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-08-09

CISA remediation due: 2022-08-30

Known ransomware campaign use: Known

CVE-2022-27925 — Synacor Zimbra Collaboration Suite (ZCS): Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability

Synacor Zimbra Collaboration Suite (ZCS) contains flaw in the mboximport functionality, allowing an authenticated attacker to upload arbitrary files to perform remote code execution. This vulnerability was chained with CVE-2022-37042 which allows for unauthenticated remote code execution.

EVULNABLE Risk · priority 90/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch Immediately

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.987.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.2 (NVD)

FIRST EPSS: 0.987 (99.92nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-08-11

CISA remediation due: 2022-09-01

Known ransomware campaign use: Known

CVE-2026-34486 — Apache Tomcat: Apache Tomcat Missing Encryption of Sensitive Data Vulnerability

Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813.

EVULNABLE Risk · priority 90/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch Immediately

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.986.

CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.986 (99.92nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-08-04

CISA remediation due: 2026-08-07

Known ransomware campaign use: Unknown/None

CVE-2019-11539 — Ivanti Pulse Connect Secure and Pulse Policy Secure: Ivanti Pulse Connect Secure and Policy Secure Command Injection Vulnerability

Ivanti Pulse Connect Secure and Policy Secure allows an authenticated attacker from the admin web interface to inject and execute commands.

EVULNABLE Risk · priority 90/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch Immediately

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.985.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.2 (NVD)

FIRST EPSS: 0.985 (99.92nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Known

CVE-2018-20250 — RARLAB WinRAR: WinRAR Absolute Path Traversal Vulnerability

WinRAR Absolute Path Traversal vulnerability leads to Remote Code Execution

EVULNABLE Risk · priority 90/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch Immediately

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.963.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.963 (99.88th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-02-15

CISA remediation due: 2022-08-15

Known ransomware campaign use: Known

CVE-2024-57727 — SimpleHelp SimpleHelp: SimpleHelp Path Traversal Vulnerability

SimpleHelp remote support software contains multiple path traversal vulnerabilities that allow unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files may include server configuration files and hashed user passwords.

EVULNABLE Risk · priority 90/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch Immediately

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.952.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.952 (99.86th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-02-13

CISA remediation due: 2025-03-06

Known ransomware campaign use: Known

CVE-2021-4034 — Red Hat Polkit: Red Hat Polkit Out-of-Bounds Read and Write Vulnerability

The Red Hat polkit pkexec utility contains an out-of-bounds read and write vulnerability that allows for privilege escalation with administrative rights.

EVULNABLE Risk · priority 90/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch Immediately

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.949.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.949 (99.85th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-06-27

CISA remediation due: 2022-07-18

Known ransomware campaign use: Known

CVE-2023-40044 — Progress WS_FTP Server: Progress WS_FTP Server Deserialization of Untrusted Data Vulnerability

Progress WS_FTP Server contains a deserialization of untrusted data vulnerability in the Ad Hoc Transfer module that allows an authenticated attacker to execute remote commands on the underlying operating system.

EVULNABLE Risk · priority 90/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch Immediately

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.901.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.901 (99.79th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-10-05

CISA remediation due: 2023-10-26

Known ransomware campaign use: Known

CVE-2022-27593 — QNAP Photo Station: QNAP Photo Station Externally Controlled Reference Vulnerability

Certain QNAP NAS running Photo Station with internet exposure contain an externally controlled reference to a resource vulnerability which can allow an attacker to modify system files. This vulnerability was observed being utilized in a Deadbolt ransomware campaign.

EVULNABLE Risk · priority 90/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.879.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.1 (NVD)

FIRST EPSS: 0.879 (99.75th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-09-08

CISA remediation due: 2022-09-29

Known ransomware campaign use: Known

CVE-2026-63077 — JetBrains TeamCity: JetBrains TeamCity Deserialization of Untrusted Data Vulnerability

JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol.

EVULNABLE Risk · priority 90/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch Immediately

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.877.

CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.877 (99.75th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-08-05

CISA remediation due: 2026-08-08

Known ransomware campaign use: Unknown/None

CVE-2019-16057 — D-Link DNS-320 Storage Device: D-Link DNS-320 Remote Code Execution Vulnerability

The login_mgr.cgi script in D-Link DNS-320 is vulnerable to remote code execution.

EVULNABLE Risk · priority 90/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.871.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: The impacted product is end-of-life and should be disconnected if still in use.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.871 (99.73rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-04-15

CISA remediation due: 2022-05-06

Known ransomware campaign use: Known

CVE-2017-18362 — Kaseya Virtual System/Server Administrator (VSA): Kaseya VSA SQL Injection Vulnerability

ConnectWise ManagedITSync integration for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database.

EVULNABLE Risk · priority 90/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.868.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: The impacted product is end-of-life and should be disconnected if still in use.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.868 (99.73rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-05-24

CISA remediation due: 2022-06-14

Known ransomware campaign use: Known

CVE-2026-60004 — Gitea Gitea: Gitea Code Injection Vulnerability

Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account.

EVULNABLE Risk · priority 90/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch Immediately

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.868.

CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.868 (99.73rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-08-25

CISA remediation due: 2026-08-28

Known ransomware campaign use: Unknown/None

CVE-2021-30116 — Kaseya Virtual System/Server Administrator (VSA): Kaseya Virtual System/Server Administrator (VSA) Information Disclosure Vulnerability

Kaseya Virtual System/Server Administrator (VSA) contains an information disclosure vulnerability allowing an attacker to obtain the sessionId that can be used to execute further attacks against the system.

EVULNABLE Risk · priority 90/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.857.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.857 (99.71st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2021-11-17

Known ransomware campaign use: Known

CVE-2023-27997 — Fortinet FortiOS and FortiProxy SSL-VPN: Fortinet FortiOS and FortiProxy SSL-VPN Heap-Based Buffer Overflow Vulnerability

Fortinet FortiOS and FortiProxy SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker to execute code or commands via specifically crafted requests.

EVULNABLE Risk · priority 90/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.857.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.857 (99.71st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-06-13

CISA remediation due: 2023-07-04

Known ransomware campaign use: Known

CVE-2024-21762 — Fortinet FortiOS: Fortinet FortiOS Out-of-Bound Write Vulnerability

Fortinet FortiOS contains an out-of-bound write vulnerability that allows a remote unauthenticated attacker to execute code or commands via specially crafted HTTP requests.

EVULNABLE Risk · priority 90/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.843.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.843 (99.68th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-02-09

CISA remediation due: 2024-02-16

Known ransomware campaign use: Known

CVE-2025-48703 — CWP Control Web Panel: CWP Control Web Panel OS Command Injection Vulnerability

CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command Injection vulnerability that allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager changePerm request. A valid non-root username must be known.

EVULNABLE Risk · priority 89/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.997.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 9.0 (NVD)

FIRST EPSS: 0.997 (99.95th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-11-04

CISA remediation due: 2025-11-25

Known ransomware campaign use: Unknown/None

Data sources & attribution

Known-exploitation status, required actions, ransomware association and remediation deadlines come from the CISA Known Exploited Vulnerabilities Catalog. Exploitation probability and percentile are provided by FIRST.org's EPSS, used under FIRST's open data terms.

Microsoft Patch Tuesday data is sourced from the Microsoft Security Update Guide; lifecycle milestones from endoflife.date. Linux distribution advisories come from Red Hat, Ubuntu and Debian; vendor bulletins from Adobe, Apple, Chrome, Cisco, Ivanti and Oracle, each linked to its own advisory.