Cross-Vendor Patch Advisories

Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.

Browse Advisories

Association
Vendor — all

Leave every box clear to show all 282 vendors.

1,308 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.

CISA KEV advisories matching the current filters, ranked by EVULNABLE Risk Score
CVE Vendor Product Vulnerability EVRS EPSS Ransomware CISA due
CVE-2025-49113 Roundcube Webmail RoundCube Webmail Deserialization of Untrusted Data Vulnerability 88 Immediate 0.989 (99.92nd pctl) Unknown/None 2026-03-13
CVE-2025-32433 Erlang Erlang/OTP Erlang Erlang/OTP SSH Server Missing Authentication for Critical Function Vulnerability 88 Immediate 0.986 (99.92nd pctl) Unknown/None 2025-06-30
CVE-2024-9463 Palo Alto Networks Expedition Palo Alto Networks Expedition OS Command Injection Vulnerability 88 Immediate 0.985 (99.92nd pctl) Unknown/None 2024-12-05
CVE-2024-50603 Aviatrix Controllers Aviatrix Controllers OS Command Injection Vulnerability 88 Immediate 0.985 (99.92nd pctl) Unknown/None 2025-02-06
CVE-2018-19410 Paessler PRTG Network Monitor Paessler PRTG Network Monitor Local File Inclusion Vulnerability 88 Immediate 0.979 (99.91st pctl) Unknown/None 2025-02-25
CVE-2026-34197 Apache ActiveMQ Apache ActiveMQ Improper Input Validation Vulnerability 88 Immediate 0.972 (99.89th pctl) Unknown/None 2026-04-30
CVE-2025-20281 Cisco Identity Services Engine Cisco Identity Services Engine Injection Vulnerability 88 Immediate 0.971 (99.89th pctl) Unknown/None 2025-08-18
CVE-2023-52163 Digiever DS-2105 Pro Digiever DS-2105 Pro Missing Authorization Vulnerability 88 Immediate 0.969 (99.89th pctl) Unknown/None 2026-01-12
CVE-2025-54068 Laravel Livewire Laravel Livewire Code Injection Vulnerability 88 Immediate 0.965 (99.88th pctl) Unknown/None 2026-04-03
CVE-2026-33017 Langflow Langflow Langflow Code Injection Vulnerability 88 Immediate 0.962 (99.87th pctl) Unknown/None 2026-04-08
CVE-2026-21643 Fortinet FortiClient EMS Fortinet FortiClient EMS SQL Injection Vulnerability 88 Immediate 0.941 (99.84th pctl) Unknown/None 2026-04-16
CVE-2025-11953 React Native Community CLI React Native Community CLI OS Command Injection Vulnerability 88 Immediate 0.940 (99.84th pctl) Unknown/None 2026-02-26
CVE-2025-2747 Kentico Xperience CMS Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability 88 Immediate 0.925 (99.82nd pctl) Unknown/None 2025-11-10
CVE-2024-7399 Samsung MagicINFO 9 Server Samsung MagicINFO 9 Server Path Traversal Vulnerability 88 Immediate 0.919 (99.81st pctl) Unknown/None 2026-05-08
CVE-2025-64446 Fortinet FortiWeb Fortinet FortiWeb Path Traversal Vulnerability 88 Immediate 0.918 (99.81st pctl) Unknown/None 2025-11-21
CVE-2026-20182 Cisco Catalyst SD-WAN Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability 88 Immediate 0.915 (99.8th pctl) Unknown/None 2026-05-17
CVE-2018-4878 Adobe Flash Player Adobe Flash Player Use-After-Free Vulnerability 88 Immediate 0.895 (99.78th pctl) Known 2022-05-03
CVE-2010-0188 Adobe Reader and Acrobat Adobe Reader and Acrobat Arbitrary Code Execution Vulnerability 88 Immediate 0.882 (99.76th pctl) Known 2022-03-24
CVE-2026-34910 Ubiquiti UniFi OS Ubiquiti UniFi OS Improper Input Validation Vulnerability 88 Immediate 0.875 (99.74th pctl) Unknown/None 2026-06-26
CVE-2026-34908 Ubiquiti UniFi OS Ubiquiti UniFi OS Improper Access Control Vulnerability 88 Immediate 0.852 (99.7th pctl) Unknown/None 2026-06-26
CVE-2021-28799 QNAP Network Attached Storage (NAS) QNAP NAS Improper Authorization Vulnerability 88 Immediate 0.782 (99.55th pctl) Known 2022-04-21
CVE-2017-11357 Telerik User Interface (UI) for ASP.NET AJAX Telerik UI for ASP.NET AJAX Insecure Direct Object Reference Vulnerability 88 Immediate 0.777 (99.53rd pctl) Known 2023-02-16
CVE-2024-57726 SimpleHelp SimpleHelp SimpleHelp Missing Authorization Vulnerability 88 Immediate 0.666 (99.23rd pctl) Known 2026-05-08
CVE-2014-6271 GNU Bourne-Again Shell (Bash) GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability 87 Immediate 0.999 (99.99th pctl) Unknown/None 2022-07-28
CVE-2017-9841 PHPUnit PHPUnit PHPUnit Command Injection Vulnerability 87 Immediate 0.999 (99.99th pctl) Unknown/None 2022-08-15
Download filtered advisories (CSV)

Exactly the 1,308 advisory(ies) matching the filters above.

Advisory detail

Expand any advisory for its description, CISA's own required action, and research links.

CVE-2025-49113 — Roundcube Webmail: RoundCube Webmail Deserialization of Untrusted Data Vulnerability

RoundCube Webmail contains a deserialization of untrusted data vulnerability that allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php.

EVULNABLE Risk · priority 88/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch Immediately

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.989.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.989 (99.92nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-02-20

CISA remediation due: 2026-03-13

Known ransomware campaign use: Unknown/None

CVE-2025-32433 — Erlang Erlang/OTP: Erlang Erlang/OTP SSH Server Missing Authentication for Critical Function Vulnerability

Erlang Erlang/OTP SSH server contains a missing authentication for critical function vulnerability. This could allow an attacker to execute arbitrary commands without valid credentials, potentially leading to unauthenticated remote code execution (RCE). By exploiting a flaw in how SSH protocol messages are handled, a malicious actor could gain unauthorized access to affected systems. This vulnerability could affect various products that implement Erlang/OTP SSH server, including—but not limited to—Cisco, NetApp, and SUSE.

EVULNABLE Risk · priority 88/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.986.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 10.0 (NVD)

FIRST EPSS: 0.986 (99.92nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-06-09

CISA remediation due: 2025-06-30

Known ransomware campaign use: Unknown/None

CVE-2024-9463 — Palo Alto Networks Expedition: Palo Alto Networks Expedition OS Command Injection Vulnerability

Palo Alto Networks Expedition contains an OS command injection vulnerability that allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.

EVULNABLE Risk · priority 88/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.985.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 9.9 (NVD)

FIRST EPSS: 0.985 (99.92nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-11-14

CISA remediation due: 2024-12-05

Known ransomware campaign use: Unknown/None

CVE-2024-50603 — Aviatrix Controllers: Aviatrix Controllers OS Command Injection Vulnerability

Aviatrix Controllers contain an OS command injection vulnerability that could allow an unauthenticated attacker to execute arbitrary code. Shell metacharacters can be sent to /v1/api in cloud_type for list_flightpath_destination_instances, or src_cloud_type for flightpath_connection_test.

EVULNABLE Risk · priority 88/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.985.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.985 (99.92nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-01-16

CISA remediation due: 2025-02-06

Known ransomware campaign use: Unknown/None

CVE-2018-19410 — Paessler PRTG Network Monitor: Paessler PRTG Network Monitor Local File Inclusion Vulnerability

Paessler PRTG Network Monitor contains a local file inclusion vulnerability that allows a remote, unauthenticated attacker to create users with read-write privileges (including administrator).

EVULNABLE Risk · priority 88/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.979.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.979 (99.91st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-02-04

CISA remediation due: 2025-02-25

Known ransomware campaign use: Unknown/None

CVE-2026-34197 — Apache ActiveMQ: Apache ActiveMQ Improper Input Validation Vulnerability

Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection.

EVULNABLE Risk · priority 88/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch Immediately

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.972.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.972 (99.89th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-04-16

CISA remediation due: 2026-04-30

Known ransomware campaign use: Unknown/None

CVE-2025-20281 — Cisco Identity Services Engine: Cisco Identity Services Engine Injection Vulnerability

Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing an attacker to exploit this vulnerability by submitting a crafted API request. Successful exploitation could allow an attacker to perform remote code execution and obtaining root privileges on an affected device.

EVULNABLE Risk · priority 88/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.971.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 10.0 (NVD)

FIRST EPSS: 0.971 (99.89th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-07-28

CISA remediation due: 2025-08-18

Known ransomware campaign use: Unknown/None

CVE-2023-52163 — Digiever DS-2105 Pro: Digiever DS-2105 Pro Missing Authorization Vulnerability

Digiever DS-2105 Pro contains a missing authorization vulnerability which could allow for command injection via time_tzsetup.cgi.

EVULNABLE Risk · priority 88/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch Immediately

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.969.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.969 (99.89th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-12-22

CISA remediation due: 2026-01-12

Known ransomware campaign use: Unknown/None

CVE-2025-54068 — Laravel Livewire: Laravel Livewire Code Injection Vulnerability

Laravel Livewire contain a code injection vulnerability that could allow unauthenticated attackers to achieve remote command execution in specific scenarios.

EVULNABLE Risk · priority 88/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.965.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 9.2 (NVD)

FIRST EPSS: 0.965 (99.88th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-03-20

CISA remediation due: 2026-04-03

Known ransomware campaign use: Unknown/None

CVE-2026-33017 — Langflow Langflow: Langflow Code Injection Vulnerability

Langflow contains a code injection vulnerability that could allow building public flows without requiring authentication.

EVULNABLE Risk · priority 88/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.962.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 9.3 (NVD)

FIRST EPSS: 0.962 (99.87th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-03-25

CISA remediation due: 2026-04-08

Known ransomware campaign use: Unknown/None

CVE-2026-21643 — Fortinet FortiClient EMS: Fortinet FortiClient EMS SQL Injection Vulnerability

Fortinet FortiClient EMS contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.

EVULNABLE Risk · priority 88/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.941.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.941 (99.84th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-04-13

CISA remediation due: 2026-04-16

Known ransomware campaign use: Unknown/None

CVE-2025-11953 — React Native Community CLI: React Native Community CLI OS Command Injection Vulnerability

React Native Community CLI contains an OS command injection vulnerability which could allow unauthenticated network attackers to send POST requests to the Metro Development Server and run arbitrary executables via a vulnerable endpoint exposed by the server. On Windows, attackers can also execute arbitrary shell commands with fully controlled arguments.

EVULNABLE Risk · priority 88/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.940.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.940 (99.84th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-02-05

CISA remediation due: 2026-02-26

Known ransomware campaign use: Unknown/None

CVE-2025-2747 — Kentico Xperience CMS: Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability

Kentico Xperience CMS contains an authentication bypass using an alternate path or channel vulnerability that could allow an attacker to control administrative objects.

EVULNABLE Risk · priority 88/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.925.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.925 (99.82nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-10-20

CISA remediation due: 2025-11-10

Known ransomware campaign use: Unknown/None

CVE-2024-7399 — Samsung MagicINFO 9 Server: Samsung MagicINFO 9 Server Path Traversal Vulnerability

Samsung MagicINFO 9 Server contains a path traversal vulnerability that could allow an attacker to write arbitrary files as system authority.

EVULNABLE Risk · priority 88/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.919.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.919 (99.81st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-04-24

CISA remediation due: 2026-05-08

Known ransomware campaign use: Unknown/None

CVE-2025-64446 — Fortinet FortiWeb: Fortinet FortiWeb Path Traversal Vulnerability

Fortinet FortiWeb contains a relative path traversal vulnerability that may allow an unauthenticated attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.

EVULNABLE Risk · priority 88/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.918.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.918 (99.81st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-11-14

CISA remediation due: 2025-11-21

Known ransomware campaign use: Unknown/None

CVE-2026-20182 — Cisco Catalyst SD-WAN: Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability

Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.

EVULNABLE Risk · priority 88/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.915.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlined in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.

CVSS: 10.0 (NVD)

FIRST EPSS: 0.915 (99.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-05-14

CISA remediation due: 2026-05-17

Known ransomware campaign use: Unknown/None

CVE-2018-4878 — Adobe Flash Player: Adobe Flash Player Use-After-Free Vulnerability

Adobe Flash Player contains a use-after-free vulnerability that could allow for code execution.

EVULNABLE Risk · priority 88/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch Immediately

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.895.

CISA required action: The impacted product is end-of-life and should be disconnected if still in use.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.895 (99.78th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Known

CVE-2010-0188 — Adobe Reader and Acrobat: Adobe Reader and Acrobat Arbitrary Code Execution Vulnerability

Unspecified vulnerability in Adobe Reader and Acrobat allows attackers to cause a denial of service or possibly execute arbitrary code.

EVULNABLE Risk · priority 88/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch Immediately

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.882.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.8 (NVD)

FIRST EPSS: 0.882 (99.76th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-03

CISA remediation due: 2022-03-24

Known ransomware campaign use: Known

CVE-2026-34910 — Ubiquiti UniFi OS: Ubiquiti UniFi OS Improper Input Validation Vulnerability

Ubiquiti UniFi OS contains an improper input validation vulnerability which could allow a malicious actor with access to the network to conduct command injection.

EVULNABLE Risk · priority 88/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch Immediately

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.875.

CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVSS: 10.0 (NVD)

FIRST EPSS: 0.875 (99.74th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-06-23

CISA remediation due: 2026-06-26

Known ransomware campaign use: Unknown/None

CVE-2026-34908 — Ubiquiti UniFi OS: Ubiquiti UniFi OS Improper Access Control Vulnerability

Ubiquiti UniFi OS contains an improper access control vulnerability which could allow a malicious actor with access to the network to make unauthorized changes to the system.

EVULNABLE Risk · priority 88/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch Immediately

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.852.

CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVSS: 10.0 (NVD)

FIRST EPSS: 0.852 (99.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-06-23

CISA remediation due: 2026-06-26

Known ransomware campaign use: Unknown/None

CVE-2021-28799 — QNAP Network Attached Storage (NAS): QNAP NAS Improper Authorization Vulnerability

QNAP NAS running HBS 3 contains an improper authorization vulnerability which can allow remote attackers to log in to a device.

EVULNABLE Risk · priority 88/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.782.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.782 (99.55th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-31

CISA remediation due: 2022-04-21

Known ransomware campaign use: Known

CVE-2017-11357 — Telerik User Interface (UI) for ASP.NET AJAX: Telerik UI for ASP.NET AJAX Insecure Direct Object Reference Vulnerability

Telerik UI for ASP.NET AJAX contains an insecure direct object reference vulnerability in RadAsyncUpload that can result in file uploads in a limited location and/or remote code execution.

EVULNABLE Risk · priority 88/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.777.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.777 (99.53rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-01-26

CISA remediation due: 2023-02-16

Known ransomware campaign use: Known

CVE-2024-57726 — SimpleHelp SimpleHelp: SimpleHelp Missing Authorization Vulnerability

SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.

EVULNABLE Risk · priority 88/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 9.9 (NVD)

FIRST EPSS: 0.666 (99.23rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-04-24

CISA remediation due: 2026-05-08

Known ransomware campaign use: Known

CVE-2014-6271 — GNU Bourne-Again Shell (Bash): GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability

GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute code.

EVULNABLE Risk · priority 87/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.999 (99.99th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-01-28

CISA remediation due: 2022-07-28

Known ransomware campaign use: Unknown/None

CVE-2017-9841 — PHPUnit PHPUnit: PHPUnit Command Injection Vulnerability

PHPUnit allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring, as demonstrated by an attack on a site with an exposed /vendor folder, i.e., external access to the /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php URI.

EVULNABLE Risk · priority 87/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.999 (99.99th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-02-15

CISA remediation due: 2022-08-15

Known ransomware campaign use: Unknown/None

Data sources & attribution

Known-exploitation status, required actions, ransomware association and remediation deadlines come from the CISA Known Exploited Vulnerabilities Catalog. Exploitation probability and percentile are provided by FIRST.org's EPSS, used under FIRST's open data terms.

Microsoft Patch Tuesday data is sourced from the Microsoft Security Update Guide; lifecycle milestones from endoflife.date. Linux distribution advisories come from Red Hat, Ubuntu and Debian; vendor bulletins from Adobe, Apple, Chrome, Cisco, Ivanti and Oracle, each linked to its own advisory.