Cross-Vendor Patch Advisories

Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.

Scope

Microsoft only, non-Microsoft, or both. Everything below follows the choice.

Why the two halves are ranked separately

Every vendor except Microsoft: the CISA KEV catalog, Linux distribution advisories, and vendor security bulletins.

At a glance

  • 1,308 Advisories CISA KEV entries, every vendor except Microsoft
  • 282 Vendors Distinct vendors named across them
  • 238 Ransomware-associated CISA records a known ransomware campaign using these
  • 1,308 / 1,308 CVSS resolved CISA's schema carries no CVSS. It is filled in by cross-referencing Cisco, Red Hat and Chrome first, then a rate-limited NVD lookup for what is left. Chrome's severity is categorical, so scores derived from it are marked estimated and cannot trigger Exigent.

1,293 advisory(ies) are past CISA's federal remediation due date and 11 fall due within 7 days. Past-deadline is the catalog's normal condition — it reaches back to 2021 — so the small due-within-7-days figure is the one that means act this week.

Source: CISA Known Exploited Vulnerabilities Catalog ↗

Priority Advisories

The highest EVULNABLE Risk advisories in the current scope. Every row here is KEV-listed and confirmed exploited by construction, so the card says that once as its source rather than repeating it as a second pill.

Rank 1 CVE-2025-55182
ExigentRansomwareCISA KEV

Meta — Meta React Server Components Remote Code Execution Vulnerability

EVULNABLE Risk · priority 97/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data
CVSS 10.0 (NVD)EPSS 0.998 (99.96th pctl)KEV since 2025-12-05CISA due 2025-12-12

Why it matters: Listed in the CISA KEV catalog, and an EPSS probability of 0.998.

Out-of-Band / Urgent Remediation
Rank 2 CVE-2026-35273
ExigentRansomwareCISA KEV

Oracle — Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability

EVULNABLE Risk · priority 97/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data
CVSS 9.8 (NVD)EPSS 0.955 (99.86th pctl)KEV since 2026-06-12CISA due 2026-06-15

Why it matters: Listed in the CISA KEV catalog, and an EPSS probability of 0.955.

Out-of-Band / Urgent Remediation
Rank 3 CVE-2025-10035
ExigentRansomwareCISA KEV

Fortra — Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability

EVULNABLE Risk · priority 96/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data
CVSS 9.8 (NVD)EPSS 0.998 (99.96th pctl)KEV since 2025-09-29CISA due 2025-10-20

Why it matters: Listed in the CISA KEV catalog, and an EPSS probability of 0.998.

Out-of-Band / Urgent Remediation
Rank 4 CVE-2025-61882
ExigentRansomwareCISA KEV

Oracle — Oracle E-Business Suite Unspecified Vulnerability

EVULNABLE Risk · priority 96/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data
CVSS 9.8 (NVD)EPSS 0.997 (99.95th pctl)KEV since 2025-10-06CISA due 2025-10-27

Why it matters: Listed in the CISA KEV catalog, and an EPSS probability of 0.997.

Out-of-Band / Urgent Remediation
Rank 5 CVE-2025-3248
ExigentRansomwareCISA KEV

Langflow — Langflow Missing Authentication Vulnerability

EVULNABLE Risk · priority 95/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data
CVSS 9.8 (NVD)EPSS 0.999 (99.99th pctl)KEV since 2025-05-05CISA due 2025-05-26

Why it matters: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.

Out-of-Band / Urgent Remediation
Rank 6 CVE-2025-22457
ExigentRansomwareCISA KEV

Ivanti — Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability

EVULNABLE Risk · priority 95/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data
CVSS 9.8 (NVD)EPSS 0.999 (99.98th pctl)KEV since 2025-04-04CISA due 2025-04-11

Why it matters: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.

Out-of-Band / Urgent Remediation
Rank 7 CVE-2025-31161
ExigentRansomwareCISA KEV

CrushFTP — CrushFTP Authentication Bypass Vulnerability

EVULNABLE Risk · priority 95/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data
CVSS 9.8 (NVD)EPSS 0.999 (99.98th pctl)KEV since 2025-04-07CISA due 2025-04-28

Why it matters: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.

Out-of-Band / Urgent Remediation
Rank 8 CVE-2025-31324
ExigentRansomwareCISA KEV

SAP — SAP NetWeaver Unrestricted File Upload Vulnerability

EVULNABLE Risk · priority 95/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data
CVSS 9.8 (NVD)EPSS 0.995 (99.94th pctl)KEV since 2025-04-29CISA due 2025-05-20

Why it matters: Listed in the CISA KEV catalog, and an EPSS probability of 0.995.

Out-of-Band / Urgent Remediation

Advisory Dashboard

Advisories by EVULNABLE Risk band

  1. Immediate 465
  2. Urgent 843

Band · Advisories

Select a bar to filter the advisory browser below.

Top Vendors

  1. Cisco 96
  2. Apple 94
  3. Adobe 80
  4. Google 72
  5. Oracle 46
  6. Apache 40
  7. Ivanti 35
  8. Fortinet 29
  9. Linux 28
  10. D-Link 26

Vendor · Advisories

Select a bar to filter the advisory browser below to that vendor.

Data sources & attribution

Known-exploitation status, required actions, ransomware association and remediation deadlines come from the CISA Known Exploited Vulnerabilities Catalog. Exploitation probability and percentile are provided by FIRST.org's EPSS, used under FIRST's open data terms.

Microsoft Patch Tuesday data is sourced from the Microsoft Security Update Guide; lifecycle milestones from endoflife.date. Linux distribution advisories come from Red Hat, Ubuntu and Debian; vendor bulletins from Adobe, Apple, Chrome, Cisco, Ivanti and Oracle, each linked to its own advisory.