CISA Known Exploited Vulnerabilities
Vulnerabilities CISA has confirmed are being actively exploited. These are the top priority — federal agencies have a mandated patch-by date, and so should you. 1,716 entries.
| CVE | Added | Patch by | EPSS | CVSS | Ransomware | What |
|---|---|---|---|---|---|---|
| CVE-2026-20245 | 2026-06-09 | 2026-06-23 | 25.3% | 7.8 | A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, former… | |
| CVE-2026-7473 | 2026-06-09 | 2026-06-23 | 1.1% | — | Arista Extensible Operating System (EOS) contains an incomplete compar… | |
| CVE-2026-42271 | 2026-06-08 | 2026-06-22 | 83.6% | — | BerriAI LiteLLM contains a command injection vulnerability that could … | |
| CVE-2026-50751 | 2026-06-08 | 2026-06-11 | 83.8% | 9.3 | yes | A logic flow weakness in Remote Access and Mobile Access certificate v… |
| CVE-2026-28318 | 2026-06-05 | 2026-06-19 | 40.0% | 7.5 | SolarWinds Serv-U is susceptible to specially crafted POST requests th… | |
| CVE-2026-45247 | 2026-06-03 | 2026-06-06 | 27.5% | 9.8 | Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 c… | |
| CVE-2025-48595 | 2026-06-02 | 2026-06-05 | 1.7% | 8.4 | In multiple locations, there is a possible way to achieve code executi… | |
| CVE-2022-0492 | 2026-06-02 | 2026-06-05 | 5.5% | — | Linux Kernel contains an improper authentication vulnerability which c… | |
| CVE-2024-21182 | 2026-06-01 | 2026-06-04 | 74.2% | — | Oracle WebLogic contains an unspecified vulnerability that could allow… | |
| CVE-2026-0257 | 2026-05-29 | 2026-06-01 | 95.2% | — | yes | Palo Alto Networks PAN-OS contains an authentication bypass vulnerabil… |
| CVE-2026-45321 | 2026-05-27 | 2026-06-10 | 2.3% | — | yes | TanStack contains an unspecified vulnerability that allowed malicious … |
| CVE-2026-48027 | 2026-05-27 | 2026-06-10 | 1.9% | — | yes | Nx Console contains an embedded malicious code vulnerability that allo… |
| CVE-2026-8398 | 2026-05-27 | 2026-05-30 | 1.5% | — | Daemon Tools contains an unspecified vulnerability that has a high imp… | |
| CVE-2026-48172 | 2026-05-26 | 2026-05-29 | 18.9% | 9.8 | LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalat… | |
| CVE-2026-9082 | 2026-05-22 | 2026-05-27 | 90.0% | 9.8 | Improper Neutralization of Special Elements used in an SQL Command ('S… | |
| CVE-2026-34926 | 2026-05-21 | 2026-06-04 | 12.7% | 6.7 | A directory traversal vulnerability in the Apex One (on-premise) serve… | |
| CVE-2025-34291 | 2026-05-21 | 2026-06-04 | 83.6% | — | Langflow contains an origin validation error vulnerability in which an… | |
| CVE-2026-41091 | 2026-05-20 | 2026-06-03 | 8.2% | 7.8 | Improper link resolution before file access ('link following') in Micr… | |
| CVE-2026-45498 | 2026-05-20 | 2026-06-03 | 63.1% | 4.0 | Microsoft Defender Denial of Service Vulnerability | |
| CVE-2008-4250 | 2026-05-20 | 2026-06-03 | 98.8% | — | Microsoft Windows contains a buffer overflow vulnerability in the Wind… | |
| CVE-2009-1537 | 2026-05-20 | 2026-06-03 | 51.2% | — | Microsoft DirectX contains a NULL byte overwrite vulnerability in the … | |
| CVE-2009-3459 | 2026-05-20 | 2026-06-03 | 86.6% | — | Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerab… | |
| CVE-2010-0249 | 2026-05-20 | 2026-06-03 | 91.9% | — | Microsoft Internet Explorer contains an use-after-free vulnerability t… | |
| CVE-2010-0806 | 2026-05-20 | 2026-06-03 | 82.2% | — | Microsoft Internet Explorer contains an use-after-free vulnerability t… | |
| CVE-2026-42897 | 2026-05-15 | 2026-05-29 | 71.8% | — | Microsoft Exchange Server contains a cross-site scripting vulnerabilit… | |
| CVE-2026-20182 | 2026-05-14 | 2026-05-17 | 91.5% | — | Cisco Catalyst SD-WAN Controller & Manager contain an authentication b… | |
| CVE-2026-42208 | 2026-05-08 | 2026-05-11 | 89.4% | — | BerriAI LiteLLM contains a SQL injection vulnerability that allows an … | |
| CVE-2026-6973 | 2026-05-07 | 2026-05-10 | 34.5% | — | Ivanti Endpoint Manager Mobile (EPMM) contains an improper input valid… | |
| CVE-2026-0300 | 2026-05-06 | 2026-05-09 | 31.7% | — | Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerabilit… | |
| CVE-2026-31431 | 2026-05-01 | 2026-05-15 | 99.9% | 7.8 | In the Linux kernel, the following vulnerability has been resolved: c… | |
| CVE-2026-41940 | 2026-04-30 | 2026-05-03 | 98.5% | — | yes | WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) con… |
| CVE-2026-32202 | 2026-04-28 | 2026-05-12 | 63.7% | 4.3 | Protection mechanism failure in Windows Shell allows an unauthorized a… | |
| CVE-2024-1708 | 2026-04-28 | 2026-05-12 | 95.5% | — | yes | ConnectWise ScreenConnect contains a path traversal vulnerability whic… |
| CVE-2025-29635 | 2026-04-24 | 2026-05-08 | 87.9% | — | D-Link DIR-823X contains a command injection vulnerability that allows… | |
| CVE-2024-57726 | 2026-04-24 | 2026-05-08 | 66.6% | — | yes | SimpleHelp contains a missing authorization vulnerability that could a… |
| CVE-2024-57728 | 2026-04-24 | 2026-05-08 | 7.0% | — | yes | SimpleHelp contains a path traversal vulnerability that allows admin u… |
| CVE-2024-7399 | 2026-04-24 | 2026-05-08 | 91.9% | — | Samsung MagicINFO 9 Server contains a path traversal vulnerability tha… | |
| CVE-2026-39987 | 2026-04-23 | 2026-05-07 | 98.9% | — | Marimo contains an pre-authorization remote code execution vulnerabili… | |
| CVE-2026-33825 | 2026-04-22 | 2026-05-06 | 6.7% | 7.8 | yes | Insufficient granularity of access control in Microsoft Defender allow… |
| CVE-2026-20133 | 2026-04-20 | 2026-04-23 | 31.4% | — | Cisco Catalyst SD-WAN Manager contains an exposure of sensitive inform… | |
| CVE-2026-20128 | 2026-04-20 | 2026-04-23 | 6.9% | — | Cisco Catalyst SD-WAN Manager contains a storing passwords in a recove… | |
| CVE-2026-20122 | 2026-04-20 | 2026-04-23 | 24.6% | — | Cisco Catalyst SD-WAN Manager contains an incorrect use of privileged … | |
| CVE-2025-32975 | 2026-04-20 | 2026-05-04 | 2.5% | — | Quest KACE Systems Management Appliance (SMA) contains an improper aut… | |
| CVE-2025-48700 | 2026-04-20 | 2026-04-23 | 1.7% | — | Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripti… | |
| CVE-2025-2749 | 2026-04-20 | 2026-05-04 | 4.0% | — | Kentico Xperience contains a path traversal vulnerability that could a… | |
| CVE-2024-27199 | 2026-04-20 | 2026-05-04 | 100.0% | — | yes | JetBrains TeamCity contains a relative path traversal vulnerability th… |
| CVE-2023-27351 | 2026-04-20 | 2026-05-04 | 78.1% | — | yes | PaperCut NG/MF contains an improper authentication vulnerability that … |
| CVE-2026-34197 | 2026-04-16 | 2026-04-30 | 98.3% | 8.8 | Improper Input Validation, Improper Control of Generation of Code ('Co… | |
| CVE-2026-32201 | 2026-04-14 | 2026-04-28 | 43.4% | — | Microsoft SharePoint Server contains an improper input validation vuln… | |
| CVE-2009-0238 | 2026-04-14 | 2026-04-28 | 43.2% | — | Microsoft Office Excel contains a remote code execution vulnerability … | |
| CVE-2012-1854 | 2026-04-13 | 2026-04-27 | 21.0% | — | Microsoft Visual Basic for Applications (VBA) contains an insecure lib… | |
| CVE-2023-21529 | 2026-04-13 | 2026-04-27 | 62.1% | 8.8 | yes | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2023-36424 | 2026-04-13 | 2026-04-27 | 12.2% | — | Microsoft Windows Common Log File System Driver contains an out-of-bou… | |
| CVE-2020-9715 | 2026-04-13 | 2026-04-27 | 48.6% | — | Adobe Acrobat contains a use-after-free vulnerability that allows for … | |
| CVE-2026-34621 | 2026-04-13 | 2026-04-27 | 7.1% | 8.6 | Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are aff… | |
| CVE-2026-21643 | 2026-04-13 | 2026-04-16 | 94.1% | — | Fortinet FortiClient EMS contains a SQL injection vulnerability that m… | |
| CVE-2025-60710 | 2026-04-13 | 2026-04-27 | 4.6% | — | yes | Microsoft Windows contains a link following vulnerability that allows … |
| CVE-2026-1340 | 2026-04-08 | 2026-04-11 | 98.7% | — | Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulner… | |
| CVE-2026-35616 | 2026-04-06 | 2026-04-09 | 90.7% | 9.8 | A improper access control vulnerability in Fortinet FortiClientEMS 7.4… | |
| CVE-2026-3502 | 2026-04-02 | 2026-04-16 | 5.7% | — | TrueConf Client contains a download of code without integrity check vu… | |
| CVE-2026-5281 | 2026-04-01 | 2026-04-15 | 4.9% | 8.8 | Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowe… | |
| CVE-2026-3055 | 2026-03-30 | 2026-04-02 | 87.2% | — | Citrix NetScaler ADC (formerly Citrix ADC), NetScaler Gateway (formerl… | |
| CVE-2025-53521 | 2026-03-27 | 2026-03-30 | 2.3% | — | F5 BIG-IP APM contains a stack-based buffer overflow vulnerability tha… | |
| CVE-2026-33634 | 2026-03-26 | 2026-04-09 | 59.2% | — | Aquasecurity Trivy contains an embedded malicious code vulnerability t… | |
| CVE-2026-33017 | 2026-03-25 | 2026-04-08 | 96.2% | — | Langflow contains a code injection vulnerability that could allow buil… | |
| CVE-2025-54068 | 2026-03-20 | 2026-04-03 | 97.1% | — | Laravel Livewire contain a code injection vulnerability that could all… | |
| CVE-2025-43510 | 2026-03-20 | 2026-04-03 | 0.4% | — | Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain an impro… | |
| CVE-2025-43520 | 2026-03-20 | 2026-04-03 | 0.4% | — | Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain a classi… | |
| CVE-2025-31277 | 2026-03-20 | 2026-04-03 | 1.5% | — | Apple Safari, iOS, watchOS, visionOS, iPadOS, macOS, and tvOS contain … | |
| CVE-2025-32432 | 2026-03-20 | 2026-04-03 | 99.8% | — | Craft CMS contains a code injection vulnerability that allows a remote… | |
| CVE-2026-20131 | 2026-03-19 | 2026-03-22 | 33.4% | — | yes | Cisco Secure Firewall Management Center (FMC) Software and Cisco Secur… |
| CVE-2026-20963 | 2026-03-18 | 2026-03-21 | 32.6% | — | Microsoft SharePoint contains a deserialization of untrusted data vuln… | |
| CVE-2025-66376 | 2026-03-18 | 2026-04-01 | 19.6% | — | Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripti… | |
| CVE-2025-47813 | 2026-03-16 | 2026-03-30 | 63.0% | — | Wing FTP Server contains a generation of error message containing sens… | |
| CVE-2026-3909 | 2026-03-13 | 2026-03-27 | 1.6% | — | Google Skia contains an out-of-bounds write vulnerability that could a… | |
| CVE-2026-3910 | 2026-03-13 | 2026-03-27 | 2.0% | — | Google Chromium V8 contains an improper restriction of operations with… | |
| CVE-2025-68613 | 2026-03-11 | 2026-03-25 | 99.1% | — | n8n contains an improper control of dynamically managed code resources… | |
| CVE-2026-1603 | 2026-03-09 | 2026-03-23 | 80.6% | — | Ivanti Endpoint Manager (EPM) contains an authentication bypass using … | |
| CVE-2025-26399 | 2026-03-09 | 2026-03-12 | 89.5% | — | yes | SolarWinds Web Help Desk contain a deserialization of untrusted data v… |
| CVE-2021-22054 | 2026-03-09 | 2026-03-23 | 97.4% | — | Omnissa Workspace One UEM formerly known as VMware Workspace One UEM c… | |
| CVE-2021-22681 | 2026-03-05 | 2026-03-26 | 63.6% | — | Multiple Rockwell products contain an insufficient protected credentia… | |
| CVE-2021-30952 | 2026-03-05 | 2026-03-26 | 7.0% | — | Apple tvOS, macOS, Safari, iPadOS and watchOS contain an integer overf… | |
| CVE-2023-41974 | 2026-03-05 | 2026-03-26 | 1.4% | — | Apple iOS and iPadOS contain a use-after-free vulnerability. An app ma… | |
| CVE-2017-7921 | 2026-03-05 | 2026-03-26 | 100.0% | — | Multiple Hikvision products contain an improper authentication vulnera… | |
| CVE-2023-43000 | 2026-03-05 | 2026-03-26 | 3.9% | — | Apple macOS, iOS, iPadOS, and Safari 16.6 contain a use-after-free vul… | |
| CVE-2026-21385 | 2026-03-03 | 2026-03-24 | 1.3% | — | Multiple Qualcomm chipsets contain a memory corruption vulnerability w… | |
| CVE-2026-22719 | 2026-03-03 | 2026-03-24 | 17.4% | — | Broadcom VMware Aria Operations formerly known as vRealize Operations … | |
| CVE-2026-20127 | 2026-02-25 | 2026-02-27 | 88.2% | — | Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Ca… | |
| CVE-2022-20775 | 2026-02-25 | 2026-02-27 | 12.5% | — | Cisco SD-WAN CLI contains a path traversal vulnerability that could al… | |
| CVE-2026-25108 | 2026-02-24 | 2026-03-17 | 5.1% | — | Soliton Systems K.K FileZen contains an OS command injection vulnerabi… | |
| CVE-2025-68461 | 2026-02-20 | 2026-03-13 | 26.8% | — | RoundCube Webmail contains a cross-site scripting vulnerability via th… | |
| CVE-2025-49113 | 2026-02-20 | 2026-03-13 | 98.9% | — | RoundCube Webmail contains a deserialization of untrusted data vulnera… | |
| CVE-2026-22769 | 2026-02-18 | 2026-02-21 | 13.3% | — | Dell RecoverPoint for Virtual Machines (RP4VMs) contains an use of har… | |
| CVE-2021-22175 | 2026-02-18 | 2026-03-11 | 53.4% | — | GitLab contains a server-side request forgery (SSRF) vulnerability whe… | |
| CVE-2020-7796 | 2026-02-17 | 2026-03-10 | 84.4% | — | Synacor Zimbra Collaboration Suite (ZCS) contains a server-side reques… | |
| CVE-2008-0015 | 2026-02-17 | 2026-03-10 | 76.7% | — | Microsoft Windows Video ActiveX Control contains a remote code executi… | |
| CVE-2026-2441 | 2026-02-17 | 2026-03-10 | 22.4% | — | Google Chromium CSS contains a use-after-free vulnerability that could… | |
| CVE-2024-7694 | 2026-02-17 | 2026-03-10 | 1.8% | — | TeamT5 ThreatSonar Anti-Ransomware contains an unrestricted upload of … | |
| CVE-2026-1731 | 2026-02-13 | 2026-02-16 | 89.5% | — | yes | BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)cont… |
| CVE-2026-20700 | 2026-02-12 | 2026-03-05 | 1.3% | — | Apple iOS, macOS, tvOS, watchOS, and visionOS contain an improper rest… |