Cross-Vendor Patch Advisories
Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.
Browse Advisories
1,308 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.
| CVE | Vendor | Product | Vulnerability | EVRS | EPSS | Ransomware | CISA due |
|---|---|---|---|---|---|---|---|
| CVE-2025-49113 | Roundcube | Webmail | RoundCube Webmail Deserialization of Untrusted Data Vulnerability | 88 Immediate | 0.989 (99.92nd pctl) | Unknown/None | 2026-03-13 |
| CVE-2025-32433 | Erlang | Erlang/OTP | Erlang Erlang/OTP SSH Server Missing Authentication for Critical Function Vulnerability | 88 Immediate | 0.986 (99.92nd pctl) | Unknown/None | 2025-06-30 |
| CVE-2024-9463 | Palo Alto Networks | Expedition | Palo Alto Networks Expedition OS Command Injection Vulnerability | 88 Immediate | 0.985 (99.92nd pctl) | Unknown/None | 2024-12-05 |
| CVE-2024-50603 | Aviatrix | Controllers | Aviatrix Controllers OS Command Injection Vulnerability | 88 Immediate | 0.985 (99.92nd pctl) | Unknown/None | 2025-02-06 |
| CVE-2018-19410 | Paessler | PRTG Network Monitor | Paessler PRTG Network Monitor Local File Inclusion Vulnerability | 88 Immediate | 0.979 (99.91st pctl) | Unknown/None | 2025-02-25 |
| CVE-2026-34197 | Apache | ActiveMQ | Apache ActiveMQ Improper Input Validation Vulnerability | 88 Immediate | 0.972 (99.89th pctl) | Unknown/None | 2026-04-30 |
| CVE-2025-20281 | Cisco | Identity Services Engine | Cisco Identity Services Engine Injection Vulnerability | 88 Immediate | 0.971 (99.89th pctl) | Unknown/None | 2025-08-18 |
| CVE-2023-52163 | Digiever | DS-2105 Pro | Digiever DS-2105 Pro Missing Authorization Vulnerability | 88 Immediate | 0.969 (99.89th pctl) | Unknown/None | 2026-01-12 |
| CVE-2025-54068 | Laravel | Livewire | Laravel Livewire Code Injection Vulnerability | 88 Immediate | 0.965 (99.88th pctl) | Unknown/None | 2026-04-03 |
| CVE-2026-33017 | Langflow | Langflow | Langflow Code Injection Vulnerability | 88 Immediate | 0.962 (99.87th pctl) | Unknown/None | 2026-04-08 |
| CVE-2026-21643 | Fortinet | FortiClient EMS | Fortinet FortiClient EMS SQL Injection Vulnerability | 88 Immediate | 0.941 (99.84th pctl) | Unknown/None | 2026-04-16 |
| CVE-2025-11953 | React Native Community | CLI | React Native Community CLI OS Command Injection Vulnerability | 88 Immediate | 0.940 (99.84th pctl) | Unknown/None | 2026-02-26 |
| CVE-2025-2747 | Kentico | Xperience CMS | Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability | 88 Immediate | 0.925 (99.82nd pctl) | Unknown/None | 2025-11-10 |
| CVE-2024-7399 | Samsung | MagicINFO 9 Server | Samsung MagicINFO 9 Server Path Traversal Vulnerability | 88 Immediate | 0.919 (99.81st pctl) | Unknown/None | 2026-05-08 |
| CVE-2025-64446 | Fortinet | FortiWeb | Fortinet FortiWeb Path Traversal Vulnerability | 88 Immediate | 0.918 (99.81st pctl) | Unknown/None | 2025-11-21 |
| CVE-2026-20182 | Cisco | Catalyst SD-WAN | Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability | 88 Immediate | 0.915 (99.8th pctl) | Unknown/None | 2026-05-17 |
| CVE-2018-4878 | Adobe | Flash Player | Adobe Flash Player Use-After-Free Vulnerability | 88 Immediate | 0.895 (99.78th pctl) | Known | 2022-05-03 |
| CVE-2010-0188 | Adobe | Reader and Acrobat | Adobe Reader and Acrobat Arbitrary Code Execution Vulnerability | 88 Immediate | 0.882 (99.76th pctl) | Known | 2022-03-24 |
| CVE-2026-34910 | Ubiquiti | UniFi OS | Ubiquiti UniFi OS Improper Input Validation Vulnerability | 88 Immediate | 0.875 (99.74th pctl) | Unknown/None | 2026-06-26 |
| CVE-2026-34908 | Ubiquiti | UniFi OS | Ubiquiti UniFi OS Improper Access Control Vulnerability | 88 Immediate | 0.852 (99.7th pctl) | Unknown/None | 2026-06-26 |
| CVE-2021-28799 | QNAP | Network Attached Storage (NAS) | QNAP NAS Improper Authorization Vulnerability | 88 Immediate | 0.782 (99.55th pctl) | Known | 2022-04-21 |
| CVE-2017-11357 | Telerik | User Interface (UI) for ASP.NET AJAX | Telerik UI for ASP.NET AJAX Insecure Direct Object Reference Vulnerability | 88 Immediate | 0.777 (99.53rd pctl) | Known | 2023-02-16 |
| CVE-2024-57726 | SimpleHelp | SimpleHelp | SimpleHelp Missing Authorization Vulnerability | 88 Immediate | 0.666 (99.23rd pctl) | Known | 2026-05-08 |
| CVE-2014-6271 | GNU | Bourne-Again Shell (Bash) | GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability | 87 Immediate | 0.999 (99.99th pctl) | Unknown/None | 2022-07-28 |
| CVE-2017-9841 | PHPUnit | PHPUnit | PHPUnit Command Injection Vulnerability | 87 Immediate | 0.999 (99.99th pctl) | Unknown/None | 2022-08-15 |
Exactly the 1,308 advisory(ies) matching the filters above.
Advisory detail
Expand any advisory for its description, CISA's own required action, and research links.
CVE-2025-49113 — Roundcube Webmail: RoundCube Webmail Deserialization of Untrusted Data Vulnerability
RoundCube Webmail contains a deserialization of untrusted data vulnerability that allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php.
Recommended priority: Patch Immediately
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.989.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.989 (99.92nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-02-20
CISA remediation due: 2026-03-13
Known ransomware campaign use: Unknown/None
CVE-2025-32433 — Erlang Erlang/OTP: Erlang Erlang/OTP SSH Server Missing Authentication for Critical Function Vulnerability
Erlang Erlang/OTP SSH server contains a missing authentication for critical function vulnerability. This could allow an attacker to execute arbitrary commands without valid credentials, potentially leading to unauthenticated remote code execution (RCE). By exploiting a flaw in how SSH protocol messages are handled, a malicious actor could gain unauthorized access to affected systems. This vulnerability could affect various products that implement Erlang/OTP SSH server, including—but not limited to—Cisco, NetApp, and SUSE.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.986.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 10.0 (NVD)
FIRST EPSS: 0.986 (99.92nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-06-09
CISA remediation due: 2025-06-30
Known ransomware campaign use: Unknown/None
CVE-2024-9463 — Palo Alto Networks Expedition: Palo Alto Networks Expedition OS Command Injection Vulnerability
Palo Alto Networks Expedition contains an OS command injection vulnerability that allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.985.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 9.9 (NVD)
FIRST EPSS: 0.985 (99.92nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-11-14
CISA remediation due: 2024-12-05
Known ransomware campaign use: Unknown/None
CVE-2024-50603 — Aviatrix Controllers: Aviatrix Controllers OS Command Injection Vulnerability
Aviatrix Controllers contain an OS command injection vulnerability that could allow an unauthenticated attacker to execute arbitrary code. Shell metacharacters can be sent to /v1/api in cloud_type for list_flightpath_destination_instances, or src_cloud_type for flightpath_connection_test.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.985.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.985 (99.92nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-01-16
CISA remediation due: 2025-02-06
Known ransomware campaign use: Unknown/None
CVE-2018-19410 — Paessler PRTG Network Monitor: Paessler PRTG Network Monitor Local File Inclusion Vulnerability
Paessler PRTG Network Monitor contains a local file inclusion vulnerability that allows a remote, unauthenticated attacker to create users with read-write privileges (including administrator).
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.979.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.979 (99.91st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-02-04
CISA remediation due: 2025-02-25
Known ransomware campaign use: Unknown/None
CVE-2026-34197 — Apache ActiveMQ: Apache ActiveMQ Improper Input Validation Vulnerability
Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection.
Recommended priority: Patch Immediately
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.972.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.972 (99.89th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-04-16
CISA remediation due: 2026-04-30
Known ransomware campaign use: Unknown/None
CVE-2025-20281 — Cisco Identity Services Engine: Cisco Identity Services Engine Injection Vulnerability
Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing an attacker to exploit this vulnerability by submitting a crafted API request. Successful exploitation could allow an attacker to perform remote code execution and obtaining root privileges on an affected device.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.971.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 10.0 (NVD)
FIRST EPSS: 0.971 (99.89th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-07-28
CISA remediation due: 2025-08-18
Known ransomware campaign use: Unknown/None
CVE-2023-52163 — Digiever DS-2105 Pro: Digiever DS-2105 Pro Missing Authorization Vulnerability
Digiever DS-2105 Pro contains a missing authorization vulnerability which could allow for command injection via time_tzsetup.cgi.
Recommended priority: Patch Immediately
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.969.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.969 (99.89th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-12-22
CISA remediation due: 2026-01-12
Known ransomware campaign use: Unknown/None
CVE-2025-54068 — Laravel Livewire: Laravel Livewire Code Injection Vulnerability
Laravel Livewire contain a code injection vulnerability that could allow unauthenticated attackers to achieve remote command execution in specific scenarios.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.965.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.2 (NVD)
FIRST EPSS: 0.965 (99.88th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-03-20
CISA remediation due: 2026-04-03
Known ransomware campaign use: Unknown/None
CVE-2026-33017 — Langflow Langflow: Langflow Code Injection Vulnerability
Langflow contains a code injection vulnerability that could allow building public flows without requiring authentication.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.962.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.3 (NVD)
FIRST EPSS: 0.962 (99.87th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-03-25
CISA remediation due: 2026-04-08
Known ransomware campaign use: Unknown/None
CVE-2026-21643 — Fortinet FortiClient EMS: Fortinet FortiClient EMS SQL Injection Vulnerability
Fortinet FortiClient EMS contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.941.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.941 (99.84th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-04-13
CISA remediation due: 2026-04-16
Known ransomware campaign use: Unknown/None
CVE-2025-11953 — React Native Community CLI: React Native Community CLI OS Command Injection Vulnerability
React Native Community CLI contains an OS command injection vulnerability which could allow unauthenticated network attackers to send POST requests to the Metro Development Server and run arbitrary executables via a vulnerable endpoint exposed by the server. On Windows, attackers can also execute arbitrary shell commands with fully controlled arguments.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.940.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.940 (99.84th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-02-05
CISA remediation due: 2026-02-26
Known ransomware campaign use: Unknown/None
CVE-2025-2747 — Kentico Xperience CMS: Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability
Kentico Xperience CMS contains an authentication bypass using an alternate path or channel vulnerability that could allow an attacker to control administrative objects.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.925.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.925 (99.82nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-10-20
CISA remediation due: 2025-11-10
Known ransomware campaign use: Unknown/None
CVE-2024-7399 — Samsung MagicINFO 9 Server: Samsung MagicINFO 9 Server Path Traversal Vulnerability
Samsung MagicINFO 9 Server contains a path traversal vulnerability that could allow an attacker to write arbitrary files as system authority.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.919.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.919 (99.81st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-04-24
CISA remediation due: 2026-05-08
Known ransomware campaign use: Unknown/None
CVE-2025-64446 — Fortinet FortiWeb: Fortinet FortiWeb Path Traversal Vulnerability
Fortinet FortiWeb contains a relative path traversal vulnerability that may allow an unauthenticated attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.918.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.918 (99.81st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-11-14
CISA remediation due: 2025-11-21
Known ransomware campaign use: Unknown/None
CVE-2026-20182 — Cisco Catalyst SD-WAN: Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.915.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlined in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.
CVSS: 10.0 (NVD)
FIRST EPSS: 0.915 (99.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-05-14
CISA remediation due: 2026-05-17
Known ransomware campaign use: Unknown/None
CVE-2018-4878 — Adobe Flash Player: Adobe Flash Player Use-After-Free Vulnerability
Adobe Flash Player contains a use-after-free vulnerability that could allow for code execution.
Recommended priority: Patch Immediately
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.895.
CISA required action: The impacted product is end-of-life and should be disconnected if still in use.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.895 (99.78th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Known
CVE-2010-0188 — Adobe Reader and Acrobat: Adobe Reader and Acrobat Arbitrary Code Execution Vulnerability
Unspecified vulnerability in Adobe Reader and Acrobat allows attackers to cause a denial of service or possibly execute arbitrary code.
Recommended priority: Patch Immediately
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.882.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.882 (99.76th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-03
CISA remediation due: 2022-03-24
Known ransomware campaign use: Known
CVE-2026-34910 — Ubiquiti UniFi OS: Ubiquiti UniFi OS Improper Input Validation Vulnerability
Ubiquiti UniFi OS contains an improper input validation vulnerability which could allow a malicious actor with access to the network to conduct command injection.
Recommended priority: Patch Immediately
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.875.
CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVSS: 10.0 (NVD)
FIRST EPSS: 0.875 (99.74th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-06-23
CISA remediation due: 2026-06-26
Known ransomware campaign use: Unknown/None
CVE-2026-34908 — Ubiquiti UniFi OS: Ubiquiti UniFi OS Improper Access Control Vulnerability
Ubiquiti UniFi OS contains an improper access control vulnerability which could allow a malicious actor with access to the network to make unauthorized changes to the system.
Recommended priority: Patch Immediately
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.852.
CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVSS: 10.0 (NVD)
FIRST EPSS: 0.852 (99.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-06-23
CISA remediation due: 2026-06-26
Known ransomware campaign use: Unknown/None
CVE-2021-28799 — QNAP Network Attached Storage (NAS): QNAP NAS Improper Authorization Vulnerability
QNAP NAS running HBS 3 contains an improper authorization vulnerability which can allow remote attackers to log in to a device.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.782.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.782 (99.55th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-31
CISA remediation due: 2022-04-21
Known ransomware campaign use: Known
CVE-2017-11357 — Telerik User Interface (UI) for ASP.NET AJAX: Telerik UI for ASP.NET AJAX Insecure Direct Object Reference Vulnerability
Telerik UI for ASP.NET AJAX contains an insecure direct object reference vulnerability in RadAsyncUpload that can result in file uploads in a limited location and/or remote code execution.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.777.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.777 (99.53rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-01-26
CISA remediation due: 2023-02-16
Known ransomware campaign use: Known
CVE-2024-57726 — SimpleHelp SimpleHelp: SimpleHelp Missing Authorization Vulnerability
SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.9 (NVD)
FIRST EPSS: 0.666 (99.23rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-04-24
CISA remediation due: 2026-05-08
Known ransomware campaign use: Known
CVE-2014-6271 — GNU Bourne-Again Shell (Bash): GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute code.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.999 (99.99th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-01-28
CISA remediation due: 2022-07-28
Known ransomware campaign use: Unknown/None
CVE-2017-9841 — PHPUnit PHPUnit: PHPUnit Command Injection Vulnerability
PHPUnit allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring, as demonstrated by an attack on a site with an exposed /vendor folder, i.e., external access to the /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php URI.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.999 (99.99th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-02-15
CISA remediation due: 2022-08-15
Known ransomware campaign use: Unknown/None