CISA Known Exploited Vulnerabilities
Vulnerabilities CISA has confirmed are being actively exploited. These are the top priority — federal agencies have a mandated patch-by date, and so should you. 1,716 entries.
| CVE | Added | Patch by | EPSS | CVSS | Ransomware | What |
|---|---|---|---|---|---|---|
| CVE-2025-40536 | 2026-02-12 | 2026-02-15 | 82.0% | — | SolarWinds Web Help Desk contains a security control bypass vulnerabil… | |
| CVE-2025-15556 | 2026-02-12 | 2026-03-05 | 1.7% | — | Notepad++ when using the WinGUp updater, contains a download of code w… | |
| CVE-2024-43468 | 2026-02-12 | 2026-03-05 | 82.0% | — | Microsoft Configuration Manager contains an SQL injection vulnerabilit… | |
| CVE-2026-21510 | 2026-02-10 | 2026-03-03 | 26.2% | — | Microsoft Windows Shell contains a protection mechanism failure vulner… | |
| CVE-2026-21513 | 2026-02-10 | 2026-03-03 | 15.6% | — | Microsoft MSHTML Framework contains a protection mechanism failure vul… | |
| CVE-2026-21514 | 2026-02-10 | 2026-03-03 | 1.5% | — | Microsoft Office Word contains a reliance on untrusted inputs in a sec… | |
| CVE-2026-21519 | 2026-02-10 | 2026-03-03 | 2.5% | — | Microsoft Desktop Windows Manager contains a type confusion vulnerabil… | |
| CVE-2026-21525 | 2026-02-10 | 2026-03-03 | 5.0% | — | Microsoft Windows Remote Access Connection Manager contains a NULL poi… | |
| CVE-2026-21533 | 2026-02-10 | 2026-03-03 | 3.9% | — | Microsoft Windows Remote Desktop Services contains an improper privile… | |
| CVE-2026-24423 | 2026-02-05 | 2026-02-26 | 88.0% | 9.8 | yes | SmarterTools SmarterMail versions prior to build 9511 contain an unaut… |
| CVE-2025-11953 | 2026-02-05 | 2026-02-26 | 94.0% | — | React Native Community CLI contains an OS command injection vulnerabil… | |
| CVE-2025-64328 | 2026-02-03 | 2026-02-24 | 84.6% | — | Sangoma FreePBX Endpoint Manager contains an OS command injection vuln… | |
| CVE-2025-40551 | 2026-02-03 | 2026-02-06 | 83.6% | — | SolarWinds Web Help Desk contains a deserialization of untrusted data … | |
| CVE-2019-19006 | 2026-02-03 | 2026-02-24 | 36.6% | — | Sangoma FreePBX contains an improper authentication vulnerability that… | |
| CVE-2021-39935 | 2026-02-03 | 2026-02-24 | 35.6% | — | GitLab Community and Enterprise Editions contain a server-side request… | |
| CVE-2026-1281 | 2026-01-29 | 2026-02-01 | 98.6% | — | Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulner… | |
| CVE-2026-24858 | 2026-01-27 | 2026-01-30 | 86.1% | — | Fortinet FortiAnalyzer, FortiManager, FortiOS, and FortiProxy contain … | |
| CVE-2026-23760 | 2026-01-26 | 2026-02-16 | 96.4% | 9.8 | yes | SmarterTools SmarterMail versions prior to build 9511 contain an authe… |
| CVE-2026-24061 | 2026-01-26 | 2026-02-16 | 98.1% | — | GNU InetUtils contains an argument injection vulnerability in telnetd … | |
| CVE-2026-21509 | 2026-01-26 | 2026-02-16 | 72.6% | — | Microsoft Office contains a security feature bypass vulnerability in w… | |
| CVE-2025-52691 | 2026-01-26 | 2026-02-16 | 85.7% | — | yes | SmarterTools SmarterMail contains an unrestricted upload of file with … |
| CVE-2018-14634 | 2026-01-26 | 2026-02-16 | 14.7% | — | Linux Kernel contains an integer overflow vulnerability in the create_… | |
| CVE-2024-37079 | 2026-01-23 | 2026-02-13 | 22.4% | — | Broadcom VMware vCenter Server contains an out-of-bounds write vulnera… | |
| CVE-2025-31125 | 2026-01-22 | 2026-02-12 | 58.5% | — | Vite Vitejs contains an improper access control vulnerability that exp… | |
| CVE-2025-54313 | 2026-01-22 | 2026-02-12 | 4.5% | — | Prettier eslint-config-prettier contains an embedded malicious code vu… | |
| CVE-2025-34026 | 2026-01-22 | 2026-02-12 | 81.9% | — | Versa Concerto SD-WAN orchestration platform contains an improper auth… | |
| CVE-2025-68645 | 2026-01-22 | 2026-02-12 | 48.9% | — | Synacor Zimbra Collaboration Suite (ZCS) contains a PHP remote file in… | |
| CVE-2026-20045 | 2026-01-21 | 2026-02-11 | 4.5% | — | Cisco Unified Communications Manager (Unified CM), Cisco Unified Commu… | |
| CVE-2026-20805 | 2026-01-13 | 2026-02-03 | 5.2% | 5.5 | Exposure of sensitive information to an unauthorized actor in Desktop … | |
| CVE-2025-8110 | 2026-01-12 | 2026-02-02 | 82.5% | — | Gogs contains a path traversal vulnerability affecting improper Symbol… | |
| CVE-2025-37164 | 2026-01-07 | 2026-01-28 | 90.2% | — | Hewlett Packard Enterprise (HPE) OneView contains a code injection vul… | |
| CVE-2009-0556 | 2026-01-07 | 2026-01-28 | 67.3% | — | Microsoft Office PowerPoint contains a code injection vulnerability th… | |
| CVE-2025-14847 | 2025-12-29 | 2026-01-19 | 83.2% | — | MongoDB Server contains an improper handling of length parameter incon… | |
| CVE-2023-52163 | 2025-12-22 | 2026-01-12 | 96.9% | — | Digiever DS-2105 Pro contains a missing authorization vulnerability wh… | |
| CVE-2025-14733 | 2025-12-19 | 2025-12-26 | 26.5% | 9.8 | yes | An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS ike… |
| CVE-2025-20393 | 2025-12-17 | 2025-12-24 | 29.9% | — | Cisco Secure Email Gateway, Secure Email, AsyncOS Software, and Web Ma… | |
| CVE-2025-40602 | 2025-12-17 | 2025-12-24 | 2.1% | — | SonicWall SMA1000 contains a missing authorization vulnerability that … | |
| CVE-2025-59374 | 2025-12-17 | 2026-01-07 | 1.2% | — | ASUS Live Update contains an embedded malicious code vulnerability cli… | |
| CVE-2025-59718 | 2025-12-16 | 2025-12-23 | 68.3% | — | Fortinet FortiOS, FortiSwitchMaster, FortiProxy, and FortiWeb contain … | |
| CVE-2025-43529 | 2025-12-15 | 2026-01-05 | 8.8% | — | Apple iOS, iPadOS, macOS, and other Apple products contain a use-after… | |
| CVE-2025-14611 | 2025-12-15 | 2026-01-05 | 53.3% | — | Gladinet CentreStack and TrioFox contain a hardcoded cryptographic key… | |
| CVE-2025-14174 | 2025-12-12 | 2026-01-02 | 22.3% | — | Google Chromium contains an out of bounds memory access vulnerability … | |
| CVE-2018-4063 | 2025-12-12 | 2026-01-02 | 27.1% | — | Sierra Wireless AirLink ALEOS contains an unrestricted upload of file … | |
| CVE-2025-58360 | 2025-12-11 | 2026-01-01 | 64.9% | — | OSGeo GeoServer contains an improper restriction of XML external entit… | |
| CVE-2025-6218 | 2025-12-09 | 2025-12-30 | 90.5% | — | RARLAB WinRAR contains a path traversal vulnerability allowing an atta… | |
| CVE-2025-62221 | 2025-12-09 | 2025-12-30 | 2.5% | — | Microsoft Windows Cloud Files Mini Filter Driver contains a use after … | |
| CVE-2025-66644 | 2025-12-08 | 2025-12-29 | 3.4% | — | Array Networks ArrayOS AG contains an OS command injection vulnerabili… | |
| CVE-2022-37055 | 2025-12-08 | 2025-12-29 | 55.5% | — | D-Link Routers contains a buffer overflow vulnerability that has a hig… | |
| CVE-2025-55182 | 2025-12-05 | 2025-12-12 | 99.8% | 10.0 | yes | A pre-authentication remote code execution vulnerability exists in Rea… |
| CVE-2021-26828 | 2025-12-03 | 2025-12-24 | 39.4% | — | OpenPLC ScadaBR contains an unrestricted upload of file with dangerous… | |
| CVE-2025-48633 | 2025-12-02 | 2025-12-23 | 0.3% | — | Android Framework contains an unspecified vulnerability that allows fo… | |
| CVE-2025-48572 | 2025-12-02 | 2025-12-23 | 0.3% | — | Android Framework contains an unspecified vulnerability that allows fo… | |
| CVE-2021-26829 | 2025-11-28 | 2025-12-19 | 48.1% | — | OpenPLC ScadaBR contains a cross-site scripting vulnerability via syst… | |
| CVE-2025-61757 | 2025-11-21 | 2025-12-12 | 88.3% | — | Oracle Fusion Middleware contains a missing authentication for critica… | |
| CVE-2025-13223 | 2025-11-19 | 2025-12-10 | 5.0% | — | Google Chromium V8 contains a type confusion vulnerability that allows… | |
| CVE-2025-58034 | 2025-11-18 | 2025-11-25 | 55.6% | — | Fortinet FortiWeb contains an OS command Injection vulnerability that … | |
| CVE-2025-64446 | 2025-11-14 | 2025-11-21 | 91.8% | — | Fortinet FortiWeb contains a relative path traversal vulnerability tha… | |
| CVE-2025-62215 | 2025-11-12 | 2025-12-03 | 6.0% | — | Microsoft Windows Kernel contains a race condition vulnerability that … | |
| CVE-2025-9242 | 2025-11-12 | 2025-12-03 | 91.3% | 9.8 | An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS ike… | |
| CVE-2025-12480 | 2025-11-12 | 2025-12-03 | 90.5% | — | Gladinet Triofox contains an improper access control vulnerability tha… | |
| CVE-2025-21042 | 2025-11-10 | 2025-12-01 | 33.2% | — | Samsung mobile devices contain an out-of-bounds write vulnerability in… | |
| CVE-2025-11371 | 2025-11-04 | 2025-11-25 | 92.1% | — | Gladinet CentreStack and Triofox contains a files or directories acces… | |
| CVE-2025-48703 | 2025-11-04 | 2025-11-25 | 99.7% | — | CWP Control Web Panel (formerly CentOS Web Panel) contains an OS comma… | |
| CVE-2025-41244 | 2025-10-30 | 2025-11-20 | 8.4% | — | Broadcom VMware Aria Operations and VMware Tools contain a privilege d… | |
| CVE-2025-24893 | 2025-10-30 | 2025-11-20 | 99.9% | — | XWiki Platform contains an eval injection vulnerability that could all… | |
| CVE-2025-6204 | 2025-10-28 | 2025-11-18 | 77.3% | — | Dassault Systèmes DELMIA Apriso contains a code injection vulnerabilit… | |
| CVE-2025-6205 | 2025-10-28 | 2025-11-18 | 73.3% | — | Dassault Systèmes DELMIA Apriso contains a missing authorization vulne… | |
| CVE-2025-59287 | 2025-10-24 | 2025-11-14 | 100.0% | — | Microsoft Windows Server Update Service (WSUS) contains a deserializat… | |
| CVE-2025-54236 | 2025-10-24 | 2025-11-14 | 94.5% | — | Adobe Commerce and Magento Open Source contain an improper input valid… | |
| CVE-2025-61932 | 2025-10-22 | 2025-11-12 | 2.6% | — | Motex LANSCOPE Endpoint Manager contains an improper verification of s… | |
| CVE-2025-61884 | 2025-10-20 | 2025-11-10 | 95.9% | 7.5 | yes | Vulnerability in the Oracle Configurator product of Oracle E-Business … |
| CVE-2025-33073 | 2025-10-20 | 2025-11-10 | 82.7% | — | Microsoft Windows SMB Client contains an improper access control vulne… | |
| CVE-2025-2746 | 2025-10-20 | 2025-11-10 | 59.1% | — | Kentico Xperience CMS contains an authentication bypass using an alter… | |
| CVE-2025-2747 | 2025-10-20 | 2025-11-10 | 92.5% | — | Kentico Xperience CMS contains an authentication bypass using an alter… | |
| CVE-2022-48503 | 2025-10-20 | 2025-11-10 | 3.2% | — | Apple macOS, iOS, tvOS, Safari, and watchOS contain an unspecified vul… | |
| CVE-2025-54253 | 2025-10-15 | 2025-11-05 | 88.0% | — | Adobe Experience Manager Forms in JEE contains an unspecified vulnerab… | |
| CVE-2025-59230 | 2025-10-14 | 2025-11-04 | 2.7% | — | Microsoft Windows contains an improper access control vulnerability in… | |
| CVE-2025-47827 | 2025-10-14 | 2025-11-04 | 4.9% | — | IGEL OS contains a use of a key past its expiration date vulnerability… | |
| CVE-2025-24990 | 2025-10-14 | 2025-11-04 | 6.4% | — | Microsoft Windows Agere Modem Driver contains an untrusted pointer der… | |
| CVE-2016-7836 | 2025-10-14 | 2025-11-04 | 19.2% | — | SKYSEA Client View contains an improper authentication vulnerability t… | |
| CVE-2021-43798 | 2025-10-09 | 2025-10-30 | 88.5% | — | Grafana contains a path traversal vulnerability that could allow acces… | |
| CVE-2025-27915 | 2025-10-07 | 2025-10-28 | 4.0% | — | Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripti… | |
| CVE-2025-61882 | 2025-10-06 | 2025-10-27 | 99.7% | 9.8 | yes | Vulnerability in the Oracle Concurrent Processing product of Oracle E-… |
| CVE-2021-43226 | 2025-10-06 | 2025-10-27 | 3.1% | 7.8 | yes | Windows Common Log File System Driver Elevation of Privilege Vulnerabi… |
| CVE-2021-22555 | 2025-10-06 | 2025-10-27 | 78.7% | — | Linux Kernel contains a heap out-of-bounds write vulnerability that co… | |
| CVE-2010-3765 | 2025-10-06 | 2025-10-27 | 83.2% | — | Mozilla Firefox, SeaMonkey, and Thunderbird contain an unspecified vul… | |
| CVE-2010-3962 | 2025-10-06 | 2025-10-27 | 96.8% | — | Microsoft Internet Explorer contains an uninitialized memory corruptio… | |
| CVE-2011-3402 | 2025-10-06 | 2025-10-27 | 78.1% | — | Microsoft Windows Kernel contains an unspecified vulnerability in the … | |
| CVE-2013-3918 | 2025-10-06 | 2025-10-27 | 73.7% | — | Microsoft Windows contains an out-of-bounds write vulnerability in the… | |
| CVE-2017-1000353 | 2025-10-02 | 2025-10-23 | 99.7% | — | Jenkins contains a remote code execution vulnerability. This vulnerabi… | |
| CVE-2015-7755 | 2025-10-02 | 2025-10-23 | 61.1% | — | Juniper ScreenOS contains an improper authentication vulnerability tha… | |
| CVE-2014-6278 | 2025-10-02 | 2025-10-23 | 99.5% | — | GNU Bash contains an OS command injection vulnerability which allows r… | |
| CVE-2025-4008 | 2025-10-02 | 2025-10-23 | 93.7% | — | Smartbedded Meteobridge contains a command injection vulnerability tha… | |
| CVE-2025-21043 | 2025-10-02 | 2025-10-23 | 1.9% | — | Samsung mobile devices contain an out-of-bounds write vulnerability in… | |
| CVE-2025-20352 | 2025-09-29 | 2025-10-20 | 39.4% | — | Cisco IOS and IOS XE contains a stack-based buffer overflow vulnerabil… | |
| CVE-2025-32463 | 2025-09-29 | 2025-10-20 | 59.4% | — | Sudo contains an inclusion of functionality from untrusted control sph… | |
| CVE-2025-10035 | 2025-09-29 | 2025-10-20 | 99.8% | 10.0 | yes | A deserialization vulnerability in the License Servlet of Fortra's GoA… |
| CVE-2025-59689 | 2025-09-29 | 2025-10-20 | 1.9% | — | Libraesva Email Security Gateway (ESG) contains a command injection vu… | |
| CVE-2021-21311 | 2025-09-29 | 2025-10-20 | 90.5% | — | Adminer contains a server-side request forgery vulnerability that, whe… | |
| CVE-2025-20362 | 2025-09-25 | 2025-09-26 | 87.1% | 6.5 | Update: On November 5, 2025, Cisco became aware of a new attack varian… |