CISA Known Exploited Vulnerabilities

Vulnerabilities CISA has confirmed are being actively exploited. These are the top priority — federal agencies have a mandated patch-by date, and so should you. 1,716 entries.

CVEAddedPatch byEPSSCVSSRansomwareWhat
CVE-2026-20245 2026-06-09 2026-06-23 25.3% 7.8 A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, former…
CVE-2026-7473 2026-06-09 2026-06-23 1.1% Arista Extensible Operating System (EOS) contains an incomplete compar…
CVE-2026-42271 2026-06-08 2026-06-22 83.6% BerriAI LiteLLM contains a command injection vulnerability that could …
CVE-2026-50751 2026-06-08 2026-06-11 83.8% 9.3 yes A logic flow weakness in Remote Access and Mobile Access certificate v…
CVE-2026-28318 2026-06-05 2026-06-19 40.0% 7.5 SolarWinds Serv-U is susceptible to specially crafted POST requests th…
CVE-2026-45247 2026-06-03 2026-06-06 27.5% 9.8 Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 c…
CVE-2025-48595 2026-06-02 2026-06-05 1.7% 8.4 In multiple locations, there is a possible way to achieve code executi…
CVE-2022-0492 2026-06-02 2026-06-05 5.5% Linux Kernel contains an improper authentication vulnerability which c…
CVE-2024-21182 2026-06-01 2026-06-04 74.2% Oracle WebLogic contains an unspecified vulnerability that could allow…
CVE-2026-0257 2026-05-29 2026-06-01 95.2% yes Palo Alto Networks PAN-OS contains an authentication bypass vulnerabil…
CVE-2026-45321 2026-05-27 2026-06-10 2.3% yes TanStack contains an unspecified vulnerability that allowed malicious …
CVE-2026-48027 2026-05-27 2026-06-10 1.9% yes Nx Console contains an embedded malicious code vulnerability that allo…
CVE-2026-8398 2026-05-27 2026-05-30 1.5% Daemon Tools contains an unspecified vulnerability that has a high imp…
CVE-2026-48172 2026-05-26 2026-05-29 18.9% 9.8 LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalat…
CVE-2026-9082 2026-05-22 2026-05-27 90.0% 9.8 Improper Neutralization of Special Elements used in an SQL Command ('S…
CVE-2026-34926 2026-05-21 2026-06-04 12.7% 6.7 A directory traversal vulnerability in the Apex One (on-premise) serve…
CVE-2025-34291 2026-05-21 2026-06-04 83.6% Langflow contains an origin validation error vulnerability in which an…
CVE-2026-41091 2026-05-20 2026-06-03 8.2% 7.8 Improper link resolution before file access ('link following') in Micr…
CVE-2026-45498 2026-05-20 2026-06-03 63.1% 4.0 Microsoft Defender Denial of Service Vulnerability
CVE-2008-4250 2026-05-20 2026-06-03 98.8% Microsoft Windows contains a buffer overflow vulnerability in the Wind…
CVE-2009-1537 2026-05-20 2026-06-03 51.2% Microsoft DirectX contains a NULL byte overwrite vulnerability in the …
CVE-2009-3459 2026-05-20 2026-06-03 86.6% Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerab…
CVE-2010-0249 2026-05-20 2026-06-03 91.9% Microsoft Internet Explorer contains an use-after-free vulnerability t…
CVE-2010-0806 2026-05-20 2026-06-03 82.2% Microsoft Internet Explorer contains an use-after-free vulnerability t…
CVE-2026-42897 2026-05-15 2026-05-29 71.8% Microsoft Exchange Server contains a cross-site scripting vulnerabilit…
CVE-2026-20182 2026-05-14 2026-05-17 91.5% Cisco Catalyst SD-WAN Controller & Manager contain an authentication b…
CVE-2026-42208 2026-05-08 2026-05-11 89.4% BerriAI LiteLLM contains a SQL injection vulnerability that allows an …
CVE-2026-6973 2026-05-07 2026-05-10 34.5% Ivanti Endpoint Manager Mobile (EPMM) contains an improper input valid…
CVE-2026-0300 2026-05-06 2026-05-09 31.7% Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerabilit…
CVE-2026-31431 2026-05-01 2026-05-15 99.9% 7.8 In the Linux kernel, the following vulnerability has been resolved: c…
CVE-2026-41940 2026-04-30 2026-05-03 98.5% yes WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) con…
CVE-2026-32202 2026-04-28 2026-05-12 63.7% 4.3 Protection mechanism failure in Windows Shell allows an unauthorized a…
CVE-2024-1708 2026-04-28 2026-05-12 95.5% yes ConnectWise ScreenConnect contains a path traversal vulnerability whic…
CVE-2025-29635 2026-04-24 2026-05-08 87.9% D-Link DIR-823X contains a command injection vulnerability that allows…
CVE-2024-57726 2026-04-24 2026-05-08 66.6% yes SimpleHelp contains a missing authorization vulnerability that could a…
CVE-2024-57728 2026-04-24 2026-05-08 7.0% yes SimpleHelp contains a path traversal vulnerability that allows admin u…
CVE-2024-7399 2026-04-24 2026-05-08 91.9% Samsung MagicINFO 9 Server contains a path traversal vulnerability tha…
CVE-2026-39987 2026-04-23 2026-05-07 98.9% Marimo contains an pre-authorization remote code execution vulnerabili…
CVE-2026-33825 2026-04-22 2026-05-06 6.7% 7.8 yes Insufficient granularity of access control in Microsoft Defender allow…
CVE-2026-20133 2026-04-20 2026-04-23 31.4% Cisco Catalyst SD-WAN Manager contains an exposure of sensitive inform…
CVE-2026-20128 2026-04-20 2026-04-23 6.9% Cisco Catalyst SD-WAN Manager contains a storing passwords in a recove…
CVE-2026-20122 2026-04-20 2026-04-23 24.6% Cisco Catalyst SD-WAN Manager contains an incorrect use of privileged …
CVE-2025-32975 2026-04-20 2026-05-04 2.5% Quest KACE Systems Management Appliance (SMA) contains an improper aut…
CVE-2025-48700 2026-04-20 2026-04-23 1.7% Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripti…
CVE-2025-2749 2026-04-20 2026-05-04 4.0% Kentico Xperience contains a path traversal vulnerability that could a…
CVE-2024-27199 2026-04-20 2026-05-04 100.0% yes JetBrains TeamCity contains a relative path traversal vulnerability th…
CVE-2023-27351 2026-04-20 2026-05-04 78.1% yes PaperCut NG/MF contains an improper authentication vulnerability that …
CVE-2026-34197 2026-04-16 2026-04-30 98.3% 8.8 Improper Input Validation, Improper Control of Generation of Code ('Co…
CVE-2026-32201 2026-04-14 2026-04-28 43.4% Microsoft SharePoint Server contains an improper input validation vuln…
CVE-2009-0238 2026-04-14 2026-04-28 43.2% Microsoft Office Excel contains a remote code execution vulnerability …
CVE-2012-1854 2026-04-13 2026-04-27 21.0% Microsoft Visual Basic for Applications (VBA) contains an insecure lib…
CVE-2023-21529 2026-04-13 2026-04-27 62.1% 8.8 yes Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2023-36424 2026-04-13 2026-04-27 12.2% Microsoft Windows Common Log File System Driver contains an out-of-bou…
CVE-2020-9715 2026-04-13 2026-04-27 48.6% Adobe Acrobat contains a use-after-free vulnerability that allows for …
CVE-2026-34621 2026-04-13 2026-04-27 7.1% 8.6 Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are aff…
CVE-2026-21643 2026-04-13 2026-04-16 94.1% Fortinet FortiClient EMS contains a SQL injection vulnerability that m…
CVE-2025-60710 2026-04-13 2026-04-27 4.6% yes Microsoft Windows contains a link following vulnerability that allows …
CVE-2026-1340 2026-04-08 2026-04-11 98.7% Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulner…
CVE-2026-35616 2026-04-06 2026-04-09 90.7% 9.8 A improper access control vulnerability in Fortinet FortiClientEMS 7.4…
CVE-2026-3502 2026-04-02 2026-04-16 5.7% TrueConf Client contains a download of code without integrity check vu…
CVE-2026-5281 2026-04-01 2026-04-15 4.9% 8.8 Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowe…
CVE-2026-3055 2026-03-30 2026-04-02 87.2% Citrix NetScaler ADC (formerly Citrix ADC), NetScaler Gateway (formerl…
CVE-2025-53521 2026-03-27 2026-03-30 2.3% F5 BIG-IP APM contains a stack-based buffer overflow vulnerability tha…
CVE-2026-33634 2026-03-26 2026-04-09 59.2% Aquasecurity Trivy contains an embedded malicious code vulnerability t…
CVE-2026-33017 2026-03-25 2026-04-08 96.2% Langflow contains a code injection vulnerability that could allow buil…
CVE-2025-54068 2026-03-20 2026-04-03 97.1% Laravel Livewire contain a code injection vulnerability that could all…
CVE-2025-43510 2026-03-20 2026-04-03 0.4% Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain an impro…
CVE-2025-43520 2026-03-20 2026-04-03 0.4% Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain a classi…
CVE-2025-31277 2026-03-20 2026-04-03 1.5% Apple Safari, iOS, watchOS, visionOS, iPadOS, macOS, and tvOS contain …
CVE-2025-32432 2026-03-20 2026-04-03 99.8% Craft CMS contains a code injection vulnerability that allows a remote…
CVE-2026-20131 2026-03-19 2026-03-22 33.4% yes Cisco Secure Firewall Management Center (FMC) Software and Cisco Secur…
CVE-2026-20963 2026-03-18 2026-03-21 32.6% Microsoft SharePoint contains a deserialization of untrusted data vuln…
CVE-2025-66376 2026-03-18 2026-04-01 19.6% Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripti…
CVE-2025-47813 2026-03-16 2026-03-30 63.0% Wing FTP Server contains a generation of error message containing sens…
CVE-2026-3909 2026-03-13 2026-03-27 1.6% Google Skia contains an out-of-bounds write vulnerability that could a…
CVE-2026-3910 2026-03-13 2026-03-27 2.0% Google Chromium V8 contains an improper restriction of operations with…
CVE-2025-68613 2026-03-11 2026-03-25 99.1% n8n contains an improper control of dynamically managed code resources…
CVE-2026-1603 2026-03-09 2026-03-23 80.6% Ivanti Endpoint Manager (EPM) contains an authentication bypass using …
CVE-2025-26399 2026-03-09 2026-03-12 89.5% yes SolarWinds Web Help Desk contain a deserialization of untrusted data v…
CVE-2021-22054 2026-03-09 2026-03-23 97.4% Omnissa Workspace One UEM formerly known as VMware Workspace One UEM c…
CVE-2021-22681 2026-03-05 2026-03-26 63.6% Multiple Rockwell products contain an insufficient protected credentia…
CVE-2021-30952 2026-03-05 2026-03-26 7.0% Apple tvOS, macOS, Safari, iPadOS and watchOS contain an integer overf…
CVE-2023-41974 2026-03-05 2026-03-26 1.4% Apple iOS and iPadOS contain a use-after-free vulnerability. An app ma…
CVE-2017-7921 2026-03-05 2026-03-26 100.0% Multiple Hikvision products contain an improper authentication vulnera…
CVE-2023-43000 2026-03-05 2026-03-26 3.9% Apple macOS, iOS, iPadOS, and Safari 16.6 contain a use-after-free vul…
CVE-2026-21385 2026-03-03 2026-03-24 1.3% Multiple Qualcomm chipsets contain a memory corruption vulnerability w…
CVE-2026-22719 2026-03-03 2026-03-24 17.4% Broadcom VMware Aria Operations formerly known as vRealize Operations …
CVE-2026-20127 2026-02-25 2026-02-27 88.2% Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Ca…
CVE-2022-20775 2026-02-25 2026-02-27 12.5% Cisco SD-WAN CLI contains a path traversal vulnerability that could al…
CVE-2026-25108 2026-02-24 2026-03-17 5.1% Soliton Systems K.K FileZen contains an OS command injection vulnerabi…
CVE-2025-68461 2026-02-20 2026-03-13 26.8% RoundCube Webmail contains a cross-site scripting vulnerability via th…
CVE-2025-49113 2026-02-20 2026-03-13 98.9% RoundCube Webmail contains a deserialization of untrusted data vulnera…
CVE-2026-22769 2026-02-18 2026-02-21 13.3% Dell RecoverPoint for Virtual Machines (RP4VMs) contains an use of har…
CVE-2021-22175 2026-02-18 2026-03-11 53.4% GitLab contains a server-side request forgery (SSRF) vulnerability whe…
CVE-2020-7796 2026-02-17 2026-03-10 84.4% Synacor Zimbra Collaboration Suite (ZCS) contains a server-side reques…
CVE-2008-0015 2026-02-17 2026-03-10 76.7% Microsoft Windows Video ActiveX Control contains a remote code executi…
CVE-2026-2441 2026-02-17 2026-03-10 22.4% Google Chromium CSS contains a use-after-free vulnerability that could…
CVE-2024-7694 2026-02-17 2026-03-10 1.8% TeamT5 ThreatSonar Anti-Ransomware contains an unrestricted upload of …
CVE-2026-1731 2026-02-13 2026-02-16 89.5% yes BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)cont…
CVE-2026-20700 2026-02-12 2026-03-05 1.3% Apple iOS, macOS, tvOS, watchOS, and visionOS contain an improper rest…
← Prev Page 2 of 18 Next →