CISA's list that day

20 April 2026

On CISA added 8 vulnerabilities to its list of exploited vulnerabilities, in PaperCut NG/MF, JetBrains TeamCity, Kentico Xperience and 4 other products. The US federal deadlines run from to .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2023-27351Improper AuthenticationPaperCut NG/MFPatch nowRansomware use, listed within a year0.78
CVE-2024-27199Relative Path TraversalJetBrains TeamCityPatch nowRansomware use, listed within a year0.99
CVE-2026-20133Exposure of Sensitive Information to an Unauthorized ActorCisco Catalyst SD-WAN ManagerPatch soon0.32
CVE-2026-20122Catalyst SD-WAN Manager Incorrect Use of Privileged APIsCisco Catalyst SD-WAN MangerPatch soon0.25
CVE-2026-20128Storing Passwords in a Recoverable FormatCisco Catalyst SD-WAN ManagerPatch soon0.07
CVE-2025-2749Path TraversalKentico Kentico XperiencePatch soon0.04
CVE-2025-32975Improper AuthenticationQuest KACE Systems Management Appliance (SMA)Patch soon0.02
CVE-2025-48700Cross-site ScriptingSynacor Zimbra Collaboration Suite (ZCS)Patch soon0.02