Cross-Vendor Patch Advisories
Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.
Browse Advisories
1,308 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.
| CVE | Vendor | Product | Vulnerability | EVRS | EPSS | Ransomware | CISA due |
|---|---|---|---|---|---|---|---|
| CVE-2023-41265 | Qlik | Sense | Qlik Sense HTTP Tunneling Vulnerability | 91 Immediate | 0.882 (99.76th pctl) | Known | 2023-12-28 |
| CVE-2019-7192 | QNAP | Photo Station | QNAP Photo Station Improper Access Control Vulnerability | 91 Immediate | 0.882 (99.76th pctl) | Known | 2022-06-22 |
| CVE-2024-51567 | CyberPersons | CyberPanel | CyberPanel Incorrect Default Permissions Vulnerability | 91 Immediate | 0.865 (99.72nd pctl) | Known | 2024-11-28 |
| CVE-2023-0669 | Fortra | GoAnywhere MFT | Fortra GoAnywhere MFT Remote Code Execution Vulnerability | 90 Immediate | 0.999 (99.99th pctl) | Known | 2023-03-03 |
| CVE-2017-7921 | Hikvision | Multiple Products | Hikvision Multiple Products Improper Authentication Vulnerability | 90 Immediate | 0.999 (99.99th pctl) | Unknown/None | 2026-03-26 |
| CVE-2025-24893 | XWiki | Platform | XWiki Platform Eval Injection Vulnerability | 90 Immediate | 0.999 (99.96th pctl) | Unknown/None | 2025-11-20 |
| CVE-2025-32432 | Craft CMS | Craft CMS | Craft CMS Code Injection Vulnerability | 90 Immediate | 0.998 (99.96th pctl) | Unknown/None | 2026-04-03 |
| CVE-2017-1000353 | Jenkins | Jenkins | Jenkins Remote Code Execution Vulnerability | 90 Immediate | 0.997 (99.95th pctl) | Unknown/None | 2025-10-23 |
| CVE-2022-30333 | RARLAB | UnRAR | RARLAB UnRAR Directory Traversal Vulnerability | 90 Immediate | 0.991 (99.93rd pctl) | Known | 2022-08-30 |
| CVE-2022-27925 | Synacor | Zimbra Collaboration Suite (ZCS) | Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability | 90 Immediate | 0.987 (99.92nd pctl) | Known | 2022-09-01 |
| CVE-2026-34486 | Apache | Tomcat | Apache Tomcat Missing Encryption of Sensitive Data Vulnerability | 90 Immediate | 0.986 (99.92nd pctl) | Unknown/None | 2026-08-07 |
| CVE-2019-11539 | Ivanti | Pulse Connect Secure and Pulse Policy Secure | Ivanti Pulse Connect Secure and Policy Secure Command Injection Vulnerability | 90 Immediate | 0.985 (99.92nd pctl) | Known | 2022-05-03 |
| CVE-2018-20250 | RARLAB | WinRAR | WinRAR Absolute Path Traversal Vulnerability | 90 Immediate | 0.963 (99.88th pctl) | Known | 2022-08-15 |
| CVE-2024-57727 | SimpleHelp | SimpleHelp | SimpleHelp Path Traversal Vulnerability | 90 Immediate | 0.952 (99.86th pctl) | Known | 2025-03-06 |
| CVE-2021-4034 | Red Hat | Polkit | Red Hat Polkit Out-of-Bounds Read and Write Vulnerability | 90 Immediate | 0.949 (99.85th pctl) | Known | 2022-07-18 |
| CVE-2023-40044 | Progress | WS_FTP Server | Progress WS_FTP Server Deserialization of Untrusted Data Vulnerability | 90 Immediate | 0.901 (99.79th pctl) | Known | 2023-10-26 |
| CVE-2022-27593 | QNAP | Photo Station | QNAP Photo Station Externally Controlled Reference Vulnerability | 90 Immediate | 0.879 (99.75th pctl) | Known | 2022-09-29 |
| CVE-2026-63077 | JetBrains | TeamCity | JetBrains TeamCity Deserialization of Untrusted Data Vulnerability | 90 Immediate | 0.877 (99.75th pctl) | Unknown/None | 2026-08-08 |
| CVE-2019-16057 | D-Link | DNS-320 Storage Device | D-Link DNS-320 Remote Code Execution Vulnerability | 90 Immediate | 0.871 (99.73rd pctl) | Known | 2022-05-06 |
| CVE-2017-18362 | Kaseya | Virtual System/Server Administrator (VSA) | Kaseya VSA SQL Injection Vulnerability | 90 Immediate | 0.868 (99.73rd pctl) | Known | 2022-06-14 |
| CVE-2026-60004 | Gitea | Gitea | Gitea Code Injection Vulnerability | 90 Immediate | 0.868 (99.73rd pctl) | Unknown/None | 2026-08-28 |
| CVE-2021-30116 | Kaseya | Virtual System/Server Administrator (VSA) | Kaseya Virtual System/Server Administrator (VSA) Information Disclosure Vulnerability | 90 Immediate | 0.857 (99.71st pctl) | Known | 2021-11-17 |
| CVE-2023-27997 | Fortinet | FortiOS and FortiProxy SSL-VPN | Fortinet FortiOS and FortiProxy SSL-VPN Heap-Based Buffer Overflow Vulnerability | 90 Immediate | 0.857 (99.71st pctl) | Known | 2023-07-04 |
| CVE-2024-21762 | Fortinet | FortiOS | Fortinet FortiOS Out-of-Bound Write Vulnerability | 90 Immediate | 0.843 (99.68th pctl) | Known | 2024-02-16 |
| CVE-2025-48703 | CWP | Control Web Panel | CWP Control Web Panel OS Command Injection Vulnerability | 89 Immediate | 0.997 (99.95th pctl) | Unknown/None | 2025-11-25 |
Exactly the 1,308 advisory(ies) matching the filters above.
Advisory detail
Expand any advisory for its description, CISA's own required action, and research links.
CVE-2023-41265 — Qlik Sense: Qlik Sense HTTP Tunneling Vulnerability
Qlik Sense contains an HTTP tunneling vulnerability that allows an attacker to escalate privileges and execute HTTP requests on the backend server hosting the software.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.882.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
CVSS: 9.9 (NVD)
FIRST EPSS: 0.882 (99.76th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-12-07
CISA remediation due: 2023-12-28
Known ransomware campaign use: Known
CVE-2019-7192 — QNAP Photo Station: QNAP Photo Station Improper Access Control Vulnerability
QNAP NAS devices running Photo Station contain an improper access control vulnerability allowing remote attackers to gain unauthorized access to the system.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.882.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.882 (99.76th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-06-08
CISA remediation due: 2022-06-22
Known ransomware campaign use: Known
CVE-2024-51567 — CyberPersons CyberPanel: CyberPanel Incorrect Default Permissions Vulnerability
CyberPanel contains an incorrect default permissions vulnerability that allows a remote, unauthenticated attacker to execute commands as root.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.865.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.865 (99.72nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-11-07
CISA remediation due: 2024-11-28
Known ransomware campaign use: Known
CVE-2023-0669 — Fortra GoAnywhere MFT: Fortra GoAnywhere MFT Remote Code Execution Vulnerability
Fortra (formerly, HelpSystems) GoAnywhere MFT contains a pre-authentication remote code execution vulnerability in the License Response Servlet due to deserializing an attacker-controlled object.
Recommended priority: Patch Immediately
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.2 (NVD)
FIRST EPSS: 0.999 (99.99th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-02-10
CISA remediation due: 2023-03-03
Known ransomware campaign use: Known
CVE-2017-7921 — Hikvision Multiple Products: Hikvision Multiple Products Improper Authentication Vulnerability
Multiple Hikvision products contain an improper authentication vulnerability that could allow a malicious user to escalate privileges on the system and gain access to sensitive information.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.999 (99.99th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-03-05
CISA remediation due: 2026-03-26
Known ransomware campaign use: Unknown/None
CVE-2025-24893 — XWiki Platform: XWiki Platform Eval Injection Vulnerability
XWiki Platform contains an eval injection vulnerability that could allow any guest to perform arbitrary remote code execution through a request to SolrSearch.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.999 (99.96th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-10-30
CISA remediation due: 2025-11-20
Known ransomware campaign use: Unknown/None
CVE-2025-32432 — Craft CMS Craft CMS: Craft CMS Code Injection Vulnerability
Craft CMS contains a code injection vulnerability that allows a remote attacker to execute arbitrary code.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.998.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 10.0 (NVD)
FIRST EPSS: 0.998 (99.96th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-03-20
CISA remediation due: 2026-04-03
Known ransomware campaign use: Unknown/None
CVE-2017-1000353 — Jenkins Jenkins: Jenkins Remote Code Execution Vulnerability
Jenkins contains a remote code execution vulnerability. This vulnerability that could allowed attackers to transfer a serialized Java SignedObject object to the remoting-based Jenkins CLI, that would be deserialized using a new ObjectInputStream, bypassing the existing blocklist-based protection mechanism.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.997.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.997 (99.95th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-10-02
CISA remediation due: 2025-10-23
Known ransomware campaign use: Unknown/None
CVE-2022-30333 — RARLAB UnRAR: RARLAB UnRAR Directory Traversal Vulnerability
RARLAB UnRAR on Linux and UNIX contains a directory traversal vulnerability, allowing an attacker to write to files during an extract (unpack) operation.
Recommended priority: Patch Immediately
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.991.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.5 (NVD)
FIRST EPSS: 0.991 (99.93rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-08-09
CISA remediation due: 2022-08-30
Known ransomware campaign use: Known
CVE-2022-27925 — Synacor Zimbra Collaboration Suite (ZCS): Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability
Synacor Zimbra Collaboration Suite (ZCS) contains flaw in the mboximport functionality, allowing an authenticated attacker to upload arbitrary files to perform remote code execution. This vulnerability was chained with CVE-2022-37042 which allows for unauthenticated remote code execution.
Recommended priority: Patch Immediately
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.987.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.2 (NVD)
FIRST EPSS: 0.987 (99.92nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-08-11
CISA remediation due: 2022-09-01
Known ransomware campaign use: Known
CVE-2026-34486 — Apache Tomcat: Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813.
Recommended priority: Patch Immediately
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.986.
CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVSS: 7.5 (NVD)
FIRST EPSS: 0.986 (99.92nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-08-04
CISA remediation due: 2026-08-07
Known ransomware campaign use: Unknown/None
CVE-2019-11539 — Ivanti Pulse Connect Secure and Pulse Policy Secure: Ivanti Pulse Connect Secure and Policy Secure Command Injection Vulnerability
Ivanti Pulse Connect Secure and Policy Secure allows an authenticated attacker from the admin web interface to inject and execute commands.
Recommended priority: Patch Immediately
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.985.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.2 (NVD)
FIRST EPSS: 0.985 (99.92nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Known
CVE-2018-20250 — RARLAB WinRAR: WinRAR Absolute Path Traversal Vulnerability
WinRAR Absolute Path Traversal vulnerability leads to Remote Code Execution
Recommended priority: Patch Immediately
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.963.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.963 (99.88th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-02-15
CISA remediation due: 2022-08-15
Known ransomware campaign use: Known
CVE-2024-57727 — SimpleHelp SimpleHelp: SimpleHelp Path Traversal Vulnerability
SimpleHelp remote support software contains multiple path traversal vulnerabilities that allow unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files may include server configuration files and hashed user passwords.
Recommended priority: Patch Immediately
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.952.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 7.5 (NVD)
FIRST EPSS: 0.952 (99.86th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-02-13
CISA remediation due: 2025-03-06
Known ransomware campaign use: Known
CVE-2021-4034 — Red Hat Polkit: Red Hat Polkit Out-of-Bounds Read and Write Vulnerability
The Red Hat polkit pkexec utility contains an out-of-bounds read and write vulnerability that allows for privilege escalation with administrative rights.
Recommended priority: Patch Immediately
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.949.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.949 (99.85th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-06-27
CISA remediation due: 2022-07-18
Known ransomware campaign use: Known
CVE-2023-40044 — Progress WS_FTP Server: Progress WS_FTP Server Deserialization of Untrusted Data Vulnerability
Progress WS_FTP Server contains a deserialization of untrusted data vulnerability in the Ad Hoc Transfer module that allows an authenticated attacker to execute remote commands on the underlying operating system.
Recommended priority: Patch Immediately
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.901.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.901 (99.79th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-10-05
CISA remediation due: 2023-10-26
Known ransomware campaign use: Known
CVE-2022-27593 — QNAP Photo Station: QNAP Photo Station Externally Controlled Reference Vulnerability
Certain QNAP NAS running Photo Station with internet exposure contain an externally controlled reference to a resource vulnerability which can allow an attacker to modify system files. This vulnerability was observed being utilized in a Deadbolt ransomware campaign.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.879.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.1 (NVD)
FIRST EPSS: 0.879 (99.75th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-09-08
CISA remediation due: 2022-09-29
Known ransomware campaign use: Known
CVE-2026-63077 — JetBrains TeamCity: JetBrains TeamCity Deserialization of Untrusted Data Vulnerability
JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol.
Recommended priority: Patch Immediately
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.877.
CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.877 (99.75th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-08-05
CISA remediation due: 2026-08-08
Known ransomware campaign use: Unknown/None
CVE-2019-16057 — D-Link DNS-320 Storage Device: D-Link DNS-320 Remote Code Execution Vulnerability
The login_mgr.cgi script in D-Link DNS-320 is vulnerable to remote code execution.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.871.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: The impacted product is end-of-life and should be disconnected if still in use.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.871 (99.73rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-04-15
CISA remediation due: 2022-05-06
Known ransomware campaign use: Known
CVE-2017-18362 — Kaseya Virtual System/Server Administrator (VSA): Kaseya VSA SQL Injection Vulnerability
ConnectWise ManagedITSync integration for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.868.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: The impacted product is end-of-life and should be disconnected if still in use.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.868 (99.73rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-05-24
CISA remediation due: 2022-06-14
Known ransomware campaign use: Known
CVE-2026-60004 — Gitea Gitea: Gitea Code Injection Vulnerability
Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account.
Recommended priority: Patch Immediately
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.868.
CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.868 (99.73rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-08-25
CISA remediation due: 2026-08-28
Known ransomware campaign use: Unknown/None
CVE-2021-30116 — Kaseya Virtual System/Server Administrator (VSA): Kaseya Virtual System/Server Administrator (VSA) Information Disclosure Vulnerability
Kaseya Virtual System/Server Administrator (VSA) contains an information disclosure vulnerability allowing an attacker to obtain the sessionId that can be used to execute further attacks against the system.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.857.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.857 (99.71st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2021-11-17
Known ransomware campaign use: Known
CVE-2023-27997 — Fortinet FortiOS and FortiProxy SSL-VPN: Fortinet FortiOS and FortiProxy SSL-VPN Heap-Based Buffer Overflow Vulnerability
Fortinet FortiOS and FortiProxy SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker to execute code or commands via specifically crafted requests.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.857.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.857 (99.71st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-06-13
CISA remediation due: 2023-07-04
Known ransomware campaign use: Known
CVE-2024-21762 — Fortinet FortiOS: Fortinet FortiOS Out-of-Bound Write Vulnerability
Fortinet FortiOS contains an out-of-bound write vulnerability that allows a remote unauthenticated attacker to execute code or commands via specially crafted HTTP requests.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.843.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.843 (99.68th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-02-09
CISA remediation due: 2024-02-16
Known ransomware campaign use: Known
CVE-2025-48703 — CWP Control Web Panel: CWP Control Web Panel OS Command Injection Vulnerability
CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command Injection vulnerability that allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager changePerm request. A valid non-root username must be known.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.997.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.0 (NVD)
FIRST EPSS: 0.997 (99.95th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-11-04
CISA remediation due: 2025-11-25
Known ransomware campaign use: Unknown/None