CISA's list that day

13 December 2022

On CISA added 5 vulnerabilities to its list of exploited vulnerabilities, in Veeam Backup & Replication, Citrix Application Delivery Controller (ADC) and Gateway, Fortinet FortiOS and 1 other product. US federal agencies must fix them by .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2022-42475Heap-Based Buffer OverflowFortinet FortiOSPatch this weekRansomware use; EPSS 0.990.99
CVE-2022-44698SmartScreen Security Feature BypassMicrosoft DefenderPatch this weekRansomware use; EPSS 0.760.76
CVE-2022-26500Remote Code ExecutionVeeam Backup & ReplicationPatch this weekRansomware use0.06
CVE-2022-26501Remote Code ExecutionVeeam Backup & ReplicationPatch this weekRansomware use0.04
CVE-2022-27518Authentication BypassCitrix Application Delivery Controller (ADC) and GatewayPatch soon0.07

Our record of CISA's changes begins on 24 January 2025. For earlier days this page lists the entries CISA dates to this day; changes CISA made that day are not known to us.