CISA's list that day

9 March 2026

On CISA added 3 vulnerabilities to its list of exploited vulnerabilities, in Omnissa Workspace One UEM, SolarWinds Web Help Desk and Ivanti Endpoint Manager (EPM). The US federal deadlines run from to .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2025-26399Deserialization of Untrusted DataSolarWinds Web Help DeskPatch nowRansomware use, listed within a year0.90
CVE-2021-22054Workspace ONE Server-Side Request ForgeryOmnissa Workspace One UEMPatch this weekEPSS 0.990.99
CVE-2026-1603Authentication BypassIvanti Endpoint Manager (EPM)Patch this weekEPSS 0.880.88