CISA's list that day
20 April 2026
On CISA added 8 vulnerabilities to its list of exploited vulnerabilities, in PaperCut NG/MF, JetBrains TeamCity, Kentico Xperience and 4 other products. The US federal deadlines run from to .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2023-27351Improper Authentication | PaperCut NG/MF | Patch nowRansomware use, listed within a year | 0.78 | ||
| CVE-2024-27199Relative Path Traversal | JetBrains TeamCity | Patch nowRansomware use, listed within a year | 0.99 | ||
| CVE-2026-20133Exposure of Sensitive Information to an Unauthorized Actor | Cisco Catalyst SD-WAN Manager | Patch soon | 0.32 | ||
| CVE-2026-20122Catalyst SD-WAN Manager Incorrect Use of Privileged APIs | Cisco Catalyst SD-WAN Manger | Patch soon | 0.25 | ||
| CVE-2026-20128Storing Passwords in a Recoverable Format | Cisco Catalyst SD-WAN Manager | Patch soon | 0.07 | ||
| CVE-2025-2749Path Traversal | Kentico Kentico Xperience | Patch soon | 0.04 | ||
| CVE-2025-32975Improper Authentication | Quest KACE Systems Management Appliance (SMA) | Patch soon | 0.02 | ||
| CVE-2025-48700Cross-site Scripting | Synacor Zimbra Collaboration Suite (ZCS) | Patch soon | 0.02 |