Cross-Vendor Patch Advisories
Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.
Browse Advisories
238 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.
| CVE | Vendor | Product | Vulnerability | EVRS | EPSS | Ransomware | CISA due |
|---|---|---|---|---|---|---|---|
| CVE-2025-55182 | Meta | React Server Components | Meta React Server Components Remote Code Execution Vulnerability | 97 Immediate | 0.998 (99.96th pctl) | Known | 2025-12-12 |
| CVE-2026-35273 | Oracle | PeopleSoft Enterprise PeopleTools | Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability | 97 Immediate | 0.955 (99.86th pctl) | Known | 2026-06-15 |
| CVE-2025-10035 | Fortra | GoAnywhere MFT | Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability | 96 Immediate | 0.998 (99.96th pctl) | Known | 2025-10-20 |
| CVE-2025-61882 | Oracle | E-Business Suite | Oracle E-Business Suite Unspecified Vulnerability | 96 Immediate | 0.997 (99.95th pctl) | Known | 2025-10-27 |
| CVE-2025-3248 | Langflow | Langflow | Langflow Missing Authentication Vulnerability | 95 Immediate | 0.999 (99.99th pctl) | Known | 2025-05-26 |
| CVE-2025-22457 | Ivanti | Connect Secure, Policy Secure, and ZTA Gateways | Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability | 95 Immediate | 0.999 (99.98th pctl) | Known | 2025-04-11 |
| CVE-2025-31161 | CrushFTP | CrushFTP | CrushFTP Authentication Bypass Vulnerability | 95 Immediate | 0.999 (99.98th pctl) | Known | 2025-04-28 |
| CVE-2025-31324 | SAP | NetWeaver | SAP NetWeaver Unrestricted File Upload Vulnerability | 95 Immediate | 0.995 (99.94th pctl) | Known | 2025-05-20 |
| CVE-2026-41940 | WebPros | cPanel & WHM and WP2 (WordPress Squared) | WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability | 95 Immediate | 0.985 (99.92nd pctl) | Known | 2026-05-03 |
| CVE-2026-23760 | SmarterTools | SmarterMail | SmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel Vulnerability | 95 Immediate | 0.963 (99.87th pctl) | Known | 2026-02-16 |
| CVE-2017-5638 | Apache | Struts | Apache Struts Remote Code Execution Vulnerability | 94 Immediate | 0.999 (99.99th pctl) | Known | 2022-05-03 |
| CVE-2018-13379 | Fortinet | FortiOS | Fortinet FortiOS SSL VPN Path Traversal Vulnerability | 94 Immediate | 0.999 (99.99th pctl) | Known | 2022-05-03 |
| CVE-2019-11510 | Ivanti | Pulse Connect Secure | Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability | 94 Immediate | 0.999 (99.99th pctl) | Known | 2022-05-03 |
| CVE-2019-19781 | Citrix | Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution Vulnerability | 94 Immediate | 0.999 (99.99th pctl) | Known | 2022-05-03 |
| CVE-2020-5902 | F5 | BIG-IP | F5 BIG-IP Traffic Management User Interface (TMUI) Remote Code Execution Vulnerability | 94 Immediate | 0.999 (99.99th pctl) | Known | 2022-05-03 |
| CVE-2021-21985 | VMware | vCenter Server | VMware vCenter Server Improper Input Validation Vulnerability | 94 Immediate | 0.999 (99.99th pctl) | Known | 2021-11-17 |
| CVE-2021-22005 | VMware | vCenter Server | VMware vCenter Server File Upload Vulnerability | 94 Immediate | 0.999 (99.99th pctl) | Known | 2021-11-17 |
| CVE-2021-26084 | Atlassian | Confluence Server and Data Center | Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability | 94 Immediate | 0.999 (99.99th pctl) | Known | 2021-11-17 |
| CVE-2021-35464 | ForgeRock | Access Management (AM) | ForgeRock Access Management (AM) Core Server Remote Code Execution Vulnerability | 94 Immediate | 0.999 (99.99th pctl) | Known | 2021-11-17 |
| CVE-2021-44228 | Apache | Log4j2 | Apache Log4j2 Remote Code Execution Vulnerability | 94 Immediate | 0.999 (99.99th pctl) | Known | 2021-12-24 |
| CVE-2022-26134 | Atlassian | Confluence Server/Data Center | Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability | 94 Immediate | 0.999 (99.99th pctl) | Known | 2022-06-06 |
| CVE-2022-29464 | WSO2 | Multiple Products | WSO2 Multiple Products Unrestrictive Upload of File Vulnerability | 94 Immediate | 0.999 (99.99th pctl) | Known | 2022-05-16 |
| CVE-2023-22518 | Atlassian | Confluence Data Center and Server | Atlassian Confluence Data Center and Server Improper Authorization Vulnerability | 94 Immediate | 0.999 (99.99th pctl) | Known | 2023-11-28 |
| CVE-2023-27350 | PaperCut | MF/NG | PaperCut MF/NG Improper Access Control Vulnerability | 94 Immediate | 0.999 (99.99th pctl) | Known | 2023-05-12 |
| CVE-2023-35078 | Ivanti | Endpoint Manager Mobile (EPMM) | Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability | 94 Immediate | 0.999 (99.99th pctl) | Known | 2023-08-15 |
Exactly the 238 advisory(ies) matching the filters above.
Advisory detail
Expand any advisory for its description, CISA's own required action, and research links.
CVE-2025-55182 — Meta React Server Components: Meta React Server Components Remote Code Execution Vulnerability
Meta React Server Components contains a remote code execution vulnerability that could allow unauthenticated remote code execution by exploiting a flaw in how React decodes payloads sent to React Server Function endpoints. Please note CVE-2025-66478 has been rejected, but it is associated with CVE-2025- 55182.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.998.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 10.0 (NVD)
FIRST EPSS: 0.998 (99.96th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-12-05
CISA remediation due: 2025-12-12
Known ransomware campaign use: Known
CVE-2026-35273 — Oracle PeopleSoft Enterprise PeopleTools: Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability
Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise PeopleTools.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.955.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.955 (99.86th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-06-12
CISA remediation due: 2026-06-15
Known ransomware campaign use: Known
CVE-2025-10035 — Fortra GoAnywhere MFT: Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability
Fortra GoAnywhere MFT contains a deserialization of untrusted data vulnerability allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.998.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.998 (99.96th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-09-29
CISA remediation due: 2025-10-20
Known ransomware campaign use: Known
CVE-2025-61882 — Oracle E-Business Suite: Oracle E-Business Suite Unspecified Vulnerability
Oracle E-Business Suite contains an unspecified vulnerability in the BI Publisher Integration component. The vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Concurrent Processing. Successful attacks can result in takeover of Oracle Concurrent Processing.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.997.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.997 (99.95th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-10-06
CISA remediation due: 2025-10-27
Known ransomware campaign use: Known
CVE-2025-3248 — Langflow Langflow: Langflow Missing Authentication Vulnerability
Langflow contains a missing authentication vulnerability in the /api/v1/validate/code endpoint that allows a remote, unauthenticated attacker to execute arbitrary code via crafted HTTP requests.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.999 (99.99th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-05-05
CISA remediation due: 2025-05-26
Known ransomware campaign use: Known
CVE-2025-22457 — Ivanti Connect Secure, Policy Secure, and ZTA Gateways: Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability
Ivanti Connect Secure, Policy Secure, and ZTA Gateways contains a stack-based buffer overflow vulnerability that allows a remote unauthenticated attacker to achieve remote code execution.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations as set forth in the CISA instructions linked below.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.999 (99.98th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-04-04
CISA remediation due: 2025-04-11
Known ransomware campaign use: Known
CVE-2025-31161 — CrushFTP CrushFTP: CrushFTP Authentication Bypass Vulnerability
CrushFTP contains an authentication bypass vulnerability in the HTTP authorization header that allows a remote unauthenticated attacker to authenticate to any known or guessable user account (e.g., crushadmin), potentially leading to a full compromise.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.999 (99.98th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-04-07
CISA remediation due: 2025-04-28
Known ransomware campaign use: Known
CVE-2025-31324 — SAP NetWeaver: SAP NetWeaver Unrestricted File Upload Vulnerability
SAP NetWeaver Visual Composer Metadata Uploader contains an unrestricted file upload vulnerability that allows an unauthenticated agent to upload potentially malicious executable binaries.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.995.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.995 (99.94th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-04-29
CISA remediation due: 2025-05-20
Known ransomware campaign use: Known
CVE-2026-41940 — WebPros cPanel & WHM and WP2 (WordPress Squared): WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability
WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.985.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.3 (NVD)
FIRST EPSS: 0.985 (99.92nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-04-30
CISA remediation due: 2026-05-03
Known ransomware campaign use: Known
CVE-2026-23760 — SmarterTools SmarterMail: SmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel Vulnerability
SmarterTools SmarterMail contains an authentication bypass using an alternate path or channel vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a reset token when resetting system administrator accounts. This could allow an unauthenticated attacker to supply a target administrator username and a new password to reset the account, resulting in full administrative compromise of the SmarterMail instance.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.963.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.3 (NVD)
FIRST EPSS: 0.963 (99.87th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-01-26
CISA remediation due: 2026-02-16
Known ransomware campaign use: Known
CVE-2017-5638 — Apache Struts: Apache Struts Remote Code Execution Vulnerability
Apache Struts Jakarta Multipart parser allows for malicious file upload using the Content-Type value, leading to remote code execution.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.999 (99.99th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Known
CVE-2018-13379 — Fortinet FortiOS: Fortinet FortiOS SSL VPN Path Traversal Vulnerability
Fortinet FortiOS SSL VPN web portal contains a path traversal vulnerability that may allow an unauthenticated attacker to download FortiOS system files through specially crafted HTTP resource requests.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.999 (99.99th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Known
CVE-2019-11510 — Ivanti Pulse Connect Secure: Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability
Ivanti Pulse Connect Secure contains an arbitrary file read vulnerability that allows an unauthenticated remote attacker with network access via HTTPS to send a specially crafted URI.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 10.0 (NVD)
FIRST EPSS: 0.999 (99.99th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Known
CVE-2019-19781 — Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance: Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution Vulnerability
Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an unspecified vulnerability that could allow an unauthenticated attacker to perform code execution.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.999 (99.99th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Known
CVE-2020-5902 — F5 BIG-IP: F5 BIG-IP Traffic Management User Interface (TMUI) Remote Code Execution Vulnerability
F5 BIG-IP Traffic Management User Interface (TMUI) contains a remote code execution vulnerability in undisclosed pages.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.999 (99.99th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Known
CVE-2021-21985 — VMware vCenter Server: VMware vCenter Server Improper Input Validation Vulnerability
VMware vSphere Client contains an improper input validation vulnerability in the Virtual SAN Health Check plug-in, which is enabled by default in vCenter Server, which allows for remote code execution.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.999 (99.99th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2021-11-17
Known ransomware campaign use: Known
CVE-2021-22005 — VMware vCenter Server: VMware vCenter Server File Upload Vulnerability
VMware vCenter Server contains a file upload vulnerability in the Analytics service that allows a user with network access to port 443 to execute code.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.999 (99.99th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2021-11-17
Known ransomware campaign use: Known
CVE-2021-26084 — Atlassian Confluence Server and Data Center: Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability
Atlassian Confluence Server and Data Server contain an Object-Graph Navigation Language (OGNL) injection vulnerability that may allow an unauthenticated attacker to execute code.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.999 (99.99th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2021-11-17
Known ransomware campaign use: Known
CVE-2021-35464 — ForgeRock Access Management (AM): ForgeRock Access Management (AM) Core Server Remote Code Execution Vulnerability
ForgeRock Access Management (AM) Core Server allows an attacker who sends a specially crafted HTTP request to one of three endpoints (/ccversion/Version, /ccversion/Masthead, or /ccversion/ButtonFrame) to execute code in the context of the current user (unless ForgeRock AM is running as root user, which the vendor does not recommend).
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.999 (99.99th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2021-11-17
Known ransomware campaign use: Known
CVE-2021-44228 — Apache Log4j2: Apache Log4j2 Remote Code Execution Vulnerability
Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: For all affected software assets for which updates exist, the only acceptable remediation actions are: 1) Apply updates; OR 2) remove affected assets from agency networks. Temporary mitigations using one of the measures provided at https://www.cisa.gov/uscert/ed-22-02-apache-log4j-recommended-mitigation-measures are only acceptable until updates are available.
CVSS: 10.0 (NVD)
FIRST EPSS: 0.999 (99.99th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-12-10
CISA remediation due: 2021-12-24
Known ransomware campaign use: Known
CVE-2022-26134 — Atlassian Confluence Server/Data Center: Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability
Atlassian Confluence Server and Data Center contain a remote code execution vulnerability that allows for an unauthenticated attacker to perform remote code execution.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Immediately block all internet traffic to and from affected products AND apply the update per vendor instructions [https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html] OR remove the affected products by the due date on the right. Note: Once the update is successfully deployed, agencies can reassess the internet blocking rules.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.999 (99.99th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-06-02
CISA remediation due: 2022-06-06
Known ransomware campaign use: Known
CVE-2022-29464 — WSO2 Multiple Products: WSO2 Multiple Products Unrestrictive Upload of File Vulnerability
Multiple WSO2 products allow for unrestricted file upload, resulting in remote code execution.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.999 (99.99th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-04-25
CISA remediation due: 2022-05-16
Known ransomware campaign use: Known
CVE-2023-22518 — Atlassian Confluence Data Center and Server: Atlassian Confluence Data Center and Server Improper Authorization Vulnerability
Atlassian Confluence Data Center and Server contain an improper authorization vulnerability that can result in significant data loss when exploited by an unauthenticated attacker. There is no impact on confidentiality since the attacker cannot exfiltrate any data.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.999 (99.99th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-11-07
CISA remediation due: 2023-11-28
Known ransomware campaign use: Known
CVE-2023-27350 — PaperCut MF/NG: PaperCut MF/NG Improper Access Control Vulnerability
PaperCut MF/NG contains an improper access control vulnerability within the SetupCompleted class that allows authentication bypass and code execution in the context of system.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.999 (99.99th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-04-21
CISA remediation due: 2023-05-12
Known ransomware campaign use: Known
CVE-2023-35078 — Ivanti Endpoint Manager Mobile (EPMM): Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability
Ivanti Endpoint Manager Mobile (EPMM, previously branded MobileIron Core) contains an authentication bypass vulnerability that allows unauthenticated access to specific API paths. An attacker with access to these API paths can access personally identifiable information (PII) such as names, phone numbers, and other mobile device details for users on a vulnerable system. An attacker can also make other configuration changes including installing software and modifying security profiles on registered devices.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.999 (99.99th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-07-25
CISA remediation due: 2023-08-15
Known ransomware campaign use: Known