CISA's list that day

3 February 2026

On CISA added 4 vulnerabilities to its list of exploited vulnerabilities, in Sangoma FreePBX, GitLab Community and Enterprise Editions and SolarWinds Web Help Desk. The US federal deadlines run from to .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2025-40551Deserialization of Untrusted DataSolarWinds Web Help DeskPatch this weekMetasploit module; EPSS 0.840.84
CVE-2025-64328OS Command InjectionSangoma FreePBXPatch this weekMetasploit module; EPSS 0.850.85
CVE-2019-19006Improper AuthenticationSangoma FreePBXPatch this weekEPSS 0.560.56
CVE-2021-39935Server-Side Request Forgery (SSRF)GitLab Community and Enterprise EditionsPatch soon0.36