CISA's list that day
7 March 2022
On CISA added 11 vulnerabilities to its list of exploited vulnerabilities, in Adobe BlazeDS, Adobe ColdFusion, NETGEAR Multiple Routers and 5 other products. The US federal deadlines run from to .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2009-3960Information Disclosure | Adobe BlazeDS | Patch this weekRansomware use; Metasploit module; EPSS 0.90; verified Exploit-DB entry | 0.90 | ||
| CVE-2016-6277Remote Code Execution | NETGEAR Multiple Routers | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| CVE-2013-0625Authentication Bypass | Adobe ColdFusion | Patch this weekEPSS 0.94; verified Exploit-DB entry | 0.94 | ||
| CVE-2013-0629Directory Traversal | Adobe ColdFusion | Patch this weekEPSS 0.66; verified Exploit-DB entry | 0.66 | ||
| CVE-2013-0631Information Disclosure | Adobe ColdFusion | Patch this weekEPSS 0.66 | 0.66 | ||
| CVE-2017-6077DGN2200 Remote Code Execution | NETGEAR Wireless Router DGN2200 | Patch this weekEPSS 0.69 | 0.69 | ||
| CVE-2019-11581Server-Side Template Injection | Atlassian Jira Server and Data Center | Patch this weekEPSS 0.85 | 0.85 | ||
| CVE-2021-21973Server Side Request Forgery (SSRF) | VMware vCenter Server and Cloud Foundation | Patch this weekEPSS 0.88 | 0.88 | ||
| CVE-2020-8218Code Injection | Pulse Secure Pulse Connect Secure | Patch soon | 0.32 | ||
| CVE-2022-26485Use-After-Free | Mozilla Firefox | Patch soon | 0.14 | ||
| CVE-2022-26486Use-After-Free | Mozilla Firefox | Patch soon | 0.02 |
Our record of CISA's changes begins on 24 January 2025. For earlier days this page lists the entries CISA dates to this day; changes CISA made that day are not known to us.