Cross-Vendor Patch Advisories
Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.
Browse Advisories
80 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.
| CVE | Vendor | Product | Vulnerability | EVRS | EPSS | Ransomware | CISA due |
|---|---|---|---|---|---|---|---|
| CVE-2023-29300 | Adobe | ColdFusion | Adobe ColdFusion Deserialization of Untrusted Data Vulnerability | 94 Immediate | 0.999 (99.98th pctl) | Known | 2024-01-29 |
| CVE-2010-2861 | Adobe | ColdFusion | Adobe ColdFusion Directory Traversal Vulnerability | 94 Immediate | 0.997 (99.95th pctl) | Known | 2022-04-15 |
| CVE-2023-38203 | Adobe | ColdFusion | Adobe ColdFusion Deserialization of Untrusted Data Vulnerability | 93 Immediate | 0.967 (99.88th pctl) | Known | 2024-01-29 |
| CVE-2008-2992 | Adobe | Acrobat and Reader | Adobe Reader and Acrobat Input Validation Vulnerability | 91 Immediate | 0.985 (99.92nd pctl) | Known | 2022-03-24 |
| CVE-2014-0497 | Adobe | Flash Player | Adobe Flash Player Integer Underflow Vulnerablity | 88 Immediate | 0.999 (99.96th pctl) | Unknown/None | 2024-10-08 |
| CVE-2018-4878 | Adobe | Flash Player | Adobe Flash Player Use-After-Free Vulnerability | 88 Immediate | 0.895 (99.78th pctl) | Known | 2022-05-03 |
| CVE-2010-0188 | Adobe | Reader and Acrobat | Adobe Reader and Acrobat Arbitrary Code Execution Vulnerability | 88 Immediate | 0.882 (99.76th pctl) | Known | 2022-03-24 |
| CVE-2024-34102 | Adobe | Commerce and Magento Open Source | Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability | 87 Immediate | 0.999 (99.99th pctl) | Unknown/None | 2024-08-07 |
| CVE-2018-15961 | Adobe | ColdFusion | Adobe ColdFusion Unrestricted File Upload Vulnerability | 87 Immediate | 0.999 (99.97th pctl) | Unknown/None | 2022-05-03 |
| CVE-2015-3113 | Adobe | Flash Player | Adobe Flash Player Heap-Based Buffer Overflow Vulnerability | 87 Immediate | 0.999 (99.97th pctl) | Unknown/None | 2022-05-04 |
| CVE-2015-5119 | Adobe | Flash Player | Adobe Flash Player Use-After-Free Vulnerability | 87 Immediate | 0.993 (99.94th pctl) | Unknown/None | 2022-03-24 |
| CVE-2022-24086 | Adobe | Commerce and Magento Open Source | Adobe Commerce and Magento Open Source Improper Input Validation Vulnerability | 87 Immediate | 0.992 (99.93rd pctl) | Unknown/None | 2022-03-01 |
| CVE-2025-54236 | Adobe | Commerce and Magento | Adobe Commerce and Magento Improper Input Validation Vulnerability | 87 Immediate | 0.945 (99.85th pctl) | Unknown/None | 2025-11-14 |
| CVE-2009-3960 | Adobe | BlazeDS | Adobe BlazeDS Information Disclosure Vulnerability | 87 Immediate | 0.900 (99.78th pctl) | Known | 2022-09-07 |
| CVE-2025-54253 | Adobe | Experience Manager (AEM) Forms | Adobe Experience Manager Forms Code Execution Vulnerability | 87 Immediate | 0.875 (99.74th pctl) | Unknown/None | 2025-11-05 |
| CVE-2011-0611 | Adobe | Flash Player | Adobe Flash Player Remote Code Execution Vulnerability | 86 Immediate | 0.994 (99.94th pctl) | Unknown/None | 2022-03-24 |
| CVE-2015-0313 | Adobe | Flash Player | Adobe Flash Player Use-After-Free Vulnerability | 86 Immediate | 0.957 (99.87th pctl) | Unknown/None | 2022-05-04 |
| CVE-2016-4117 | Adobe | Flash Player | Adobe Flash Player Arbitrary Code Execution Vulnerability | 86 Immediate | 0.944 (99.84th pctl) | Unknown/None | 2022-03-24 |
| CVE-2017-3066 | Adobe | ColdFusion | Adobe ColdFusion Deserialization Vulnerability | 86 Immediate | 0.906 (99.79th pctl) | Unknown/None | 2025-03-17 |
| CVE-2018-15982 | Adobe | Flash Player | Adobe Flash Player Use-After-Free Vulnerability | 86 Immediate | 0.825 (99.64th pctl) | Known | 2022-08-15 |
| CVE-2023-26360 | Adobe | ColdFusion | Adobe ColdFusion Deserialization of Untrusted Data Vulnerability | 85 Immediate | 0.973 (99.89th pctl) | Unknown/None | 2023-04-05 |
| CVE-2009-0927 | Adobe | Reader and Acrobat | Adobe Reader and Adobe Acrobat Stack-Based Buffer Overflow Vulnerability | 85 Immediate | 0.966 (99.88th pctl) | Unknown/None | 2022-04-15 |
| CVE-2013-0625 | Adobe | ColdFusion | Adobe ColdFusion Authentication Bypass Vulnerability | 85 Immediate | 0.938 (99.84th pctl) | Unknown/None | 2022-09-07 |
| CVE-2013-0632 | Adobe | ColdFusion | Adobe ColdFusion Authentication Bypass Vulnerability | 85 Immediate | 0.937 (99.84th pctl) | Unknown/None | 2022-03-24 |
| CVE-2015-5122 | Adobe | Flash Player | Adobe Flash Player Use-After-Free Vulnerability | 85 Immediate | 0.937 (99.84th pctl) | Unknown/None | 2022-05-04 |
Exactly the 80 advisory(ies) matching the filters above.
Advisory detail
Expand any advisory for its description, CISA's own required action, and research links.
CVE-2023-29300 — Adobe ColdFusion: Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for code execution.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.999 (99.98th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-01-08
CISA remediation due: 2024-01-29
Known ransomware campaign use: Known
CVE-2010-2861 — Adobe ColdFusion: Adobe ColdFusion Directory Traversal Vulnerability
A directory traversal vulnerability exists in the administrator console in Adobe ColdFusion which allows remote attackers to read arbitrary files.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.997.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.997 (99.95th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-25
CISA remediation due: 2022-04-15
Known ransomware campaign use: Known
CVE-2023-38203 — Adobe ColdFusion: Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for code execution.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.967.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.967 (99.88th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-01-08
CISA remediation due: 2024-01-29
Known ransomware campaign use: Known
CVE-2008-2992 — Adobe Acrobat and Reader: Adobe Reader and Acrobat Input Validation Vulnerability
Adobe Acrobat and Reader contain an input validation issue in a JavaScript method that could potentially lead to remote code execution.
Recommended priority: Patch Immediately
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.985.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.985 (99.92nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-03
CISA remediation due: 2022-03-24
Known ransomware campaign use: Known
CVE-2014-0497 — Adobe Flash Player: Adobe Flash Player Integer Underflow Vulnerablity
Adobe Flash Player contains an integer underflow vulnerability that allows a remote attacker to execute arbitrary code.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.999 (99.96th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-09-17
CISA remediation due: 2024-10-08
Known ransomware campaign use: Unknown/None
CVE-2018-4878 — Adobe Flash Player: Adobe Flash Player Use-After-Free Vulnerability
Adobe Flash Player contains a use-after-free vulnerability that could allow for code execution.
Recommended priority: Patch Immediately
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.895.
CISA required action: The impacted product is end-of-life and should be disconnected if still in use.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.895 (99.78th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Known
CVE-2010-0188 — Adobe Reader and Acrobat: Adobe Reader and Acrobat Arbitrary Code Execution Vulnerability
Unspecified vulnerability in Adobe Reader and Acrobat allows attackers to cause a denial of service or possibly execute arbitrary code.
Recommended priority: Patch Immediately
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.882.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.882 (99.76th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-03
CISA remediation due: 2022-03-24
Known ransomware campaign use: Known
CVE-2024-34102 — Adobe Commerce and Magento Open Source: Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability
Adobe Commerce and Magento Open Source contain an improper restriction of XML external entity reference (XXE) vulnerability that allows for remote code execution.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.999 (99.99th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-07-17
CISA remediation due: 2024-08-07
Known ransomware campaign use: Unknown/None
CVE-2018-15961 — Adobe ColdFusion: Adobe ColdFusion Unrestricted File Upload Vulnerability
Adobe ColdFusion contains an unrestricted file upload vulnerability that could allow for code execution.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.999 (99.97th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2015-3113 — Adobe Flash Player: Adobe Flash Player Heap-Based Buffer Overflow Vulnerability
Heap-based buffer overflow vulnerability in Adobe Flash Player allows remote attackers to execute code.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: The impacted product is end-of-life and should be disconnected if still in use.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.999 (99.97th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-04-13
CISA remediation due: 2022-05-04
Known ransomware campaign use: Unknown/None
CVE-2015-5119 — Adobe Flash Player: Adobe Flash Player Use-After-Free Vulnerability
A use-after-free vulnerability exists within the ActionScript 3 ByteArray class in Adobe Flash Player that allows an attacker to perform remote code execution.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.993.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: The impacted product is end-of-life and should be disconnected if still in use.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.993 (99.94th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-03
CISA remediation due: 2022-03-24
Known ransomware campaign use: Unknown/None
CVE-2022-24086 — Adobe Commerce and Magento Open Source: Adobe Commerce and Magento Open Source Improper Input Validation Vulnerability
Adobe Commerce and Magento Open Source contain an improper input validation vulnerability which can allow for arbitrary code execution.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.992.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.992 (99.93rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-02-15
CISA remediation due: 2022-03-01
Known ransomware campaign use: Unknown/None
CVE-2025-54236 — Adobe Commerce and Magento: Adobe Commerce and Magento Improper Input Validation Vulnerability
Adobe Commerce and Magento Open Source contain an improper input validation vulnerability that could allow an attacker to take over customer accounts through the Commerce REST API.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.945.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.1 (NVD)
FIRST EPSS: 0.945 (99.85th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-10-24
CISA remediation due: 2025-11-14
Known ransomware campaign use: Unknown/None
CVE-2009-3960 — Adobe BlazeDS: Adobe BlazeDS Information Disclosure Vulnerability
Adobe BlazeDS, which is utilized in LifeCycle and Coldfusion, contains a vulnerability that allows for information disclosure.
Recommended priority: Patch Immediately
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.900.
CISA required action: Apply updates per vendor instructions.
CVSS: 6.5 (NVD)
FIRST EPSS: 0.900 (99.78th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-07
CISA remediation due: 2022-09-07
Known ransomware campaign use: Known
CVE-2025-54253 — Adobe Experience Manager (AEM) Forms: Adobe Experience Manager Forms Code Execution Vulnerability
Adobe Experience Manager Forms in JEE contains an unspecified vulnerability that allows for arbitrary code execution.
Recommended priority: Patch Immediately
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.875.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 10.0 (NVD)
FIRST EPSS: 0.875 (99.74th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-10-15
CISA remediation due: 2025-11-05
Known ransomware campaign use: Unknown/None
CVE-2011-0611 — Adobe Flash Player: Adobe Flash Player Remote Code Execution Vulnerability
Adobe Flash Player contains a vulnerability that allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content.
Recommended priority: Patch Immediately
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.994.
CISA required action: The impacted product is end-of-life and should be disconnected if still in use.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.994 (99.94th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-03
CISA remediation due: 2022-03-24
Known ransomware campaign use: Unknown/None
CVE-2015-0313 — Adobe Flash Player: Adobe Flash Player Use-After-Free Vulnerability
Use-after-free vulnerability in Adobe Flash Player allows remote attackers to execute code.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.957.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: The impacted product is end-of-life and should be disconnected if still in use.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.957 (99.87th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-04-13
CISA remediation due: 2022-05-04
Known ransomware campaign use: Unknown/None
CVE-2016-4117 — Adobe Flash Player: Adobe Flash Player Arbitrary Code Execution Vulnerability
An access of resource using incompatible type vulnerability exists within Adobe Flash Player that allows an attacker to perform remote code execution.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.944.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: The impacted product is end-of-life and should be disconnected if still in use.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.944 (99.84th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-03
CISA remediation due: 2022-03-24
Known ransomware campaign use: Unknown/None
CVE-2017-3066 — Adobe ColdFusion: Adobe ColdFusion Deserialization Vulnerability
Adobe ColdFusion contains a deserialization vulnerability in the Apache BlazeDS library that allows for arbitrary code execution.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.906.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.906 (99.79th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-02-24
CISA remediation due: 2025-03-17
Known ransomware campaign use: Unknown/None
CVE-2018-15982 — Adobe Flash Player: Adobe Flash Player Use-After-Free Vulnerability
Adobe Flash Player com.adobe.tvsdk.mediacore.metadata Use After Free Vulnerability
Recommended priority: Patch Immediately
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.825.
CISA required action: The impacted product is end-of-life and should be disconnected if still in use.
CVSS: 7.8 (NVD)
FIRST EPSS: 0.825 (99.64th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-02-15
CISA remediation due: 2022-08-15
Known ransomware campaign use: Known
CVE-2023-26360 — Adobe ColdFusion: Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for remote code execution.
Recommended priority: Patch Immediately
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.973.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.6 (NVD)
FIRST EPSS: 0.973 (99.89th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-03-15
CISA remediation due: 2023-04-05
Known ransomware campaign use: Unknown/None
CVE-2009-0927 — Adobe Reader and Acrobat: Adobe Reader and Adobe Acrobat Stack-Based Buffer Overflow Vulnerability
Stack-based buffer overflow in Adobe Reader and Adobe Acrobat allows remote attackers to execute arbitrary code.
Recommended priority: Patch Immediately
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.966.
CISA required action: Apply updates per vendor instructions.
CVSS: 8.8 (NVD)
FIRST EPSS: 0.966 (99.88th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-25
CISA remediation due: 2022-04-15
Known ransomware campaign use: Unknown/None
CVE-2013-0625 — Adobe ColdFusion: Adobe ColdFusion Authentication Bypass Vulnerability
Adobe Coldfusion contains an authentication bypass vulnerability, which could result in an unauthorized user gaining administrative access.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.938.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.938 (99.84th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-07
CISA remediation due: 2022-09-07
Known ransomware campaign use: Unknown/None
CVE-2013-0632 — Adobe ColdFusion: Adobe ColdFusion Authentication Bypass Vulnerability
An authentication bypass vulnerability exists in Adobe ColdFusion which could result in an unauthorized user gaining administrative access.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.937.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.937 (99.84th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-03
CISA remediation due: 2022-03-24
Known ransomware campaign use: Unknown/None
CVE-2015-5122 — Adobe Flash Player: Adobe Flash Player Use-After-Free Vulnerability
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS).
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.937.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: The impacted product is end-of-life and should be disconnected if still in use.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.937 (99.84th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-04-13
CISA remediation due: 2022-05-04
Known ransomware campaign use: Unknown/None