CISA's list that day

7 March 2022

On CISA added 11 vulnerabilities to its list of exploited vulnerabilities, in Adobe BlazeDS, Adobe ColdFusion, NETGEAR Multiple Routers and 5 other products. The US federal deadlines run from to .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2009-3960Information DisclosureAdobe BlazeDSPatch this weekRansomware use; Metasploit module; EPSS 0.90; verified Exploit-DB entry0.90
CVE-2016-6277Remote Code ExecutionNETGEAR Multiple RoutersPatch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry0.99
CVE-2013-0625Authentication BypassAdobe ColdFusionPatch this weekEPSS 0.94; verified Exploit-DB entry0.94
CVE-2013-0629Directory TraversalAdobe ColdFusionPatch this weekEPSS 0.66; verified Exploit-DB entry0.66
CVE-2013-0631Information DisclosureAdobe ColdFusionPatch this weekEPSS 0.660.66
CVE-2017-6077DGN2200 Remote Code ExecutionNETGEAR Wireless Router DGN2200Patch this weekEPSS 0.690.69
CVE-2019-11581Server-Side Template InjectionAtlassian Jira Server and Data CenterPatch this weekEPSS 0.850.85
CVE-2021-21973Server Side Request Forgery (SSRF)VMware vCenter Server and Cloud FoundationPatch this weekEPSS 0.880.88
CVE-2020-8218Code InjectionPulse Secure Pulse Connect SecurePatch soon0.32
CVE-2022-26485Use-After-FreeMozilla FirefoxPatch soon0.14
CVE-2022-26486Use-After-FreeMozilla FirefoxPatch soon0.02

Our record of CISA's changes begins on 24 January 2025. For earlier days this page lists the entries CISA dates to this day; changes CISA made that day are not known to us.