Patch first

As of , all 1,734 vulnerabilities on CISA's list of exploited vulnerabilities, in our patch-first order: 101 to patch now.

#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2026-85706Path TraversalGitLab Community Edition and Enterprise EditionPatch nowForensic triage required by CISA; Metasploit module0.93
2CVE-2026-20079Firewall Management Center Authentication Bypass Using an Alternate Path or ChannelCisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementPatch nowForensic triage required by CISA; Metasploit module0.88
3CVE-2026-63077Deserialization of Untrusted DataJetBrains TeamCityPatch nowForensic triage required by CISA; ransomware use, listed within a year; Metasploit module0.90
4CVE-2026-16232Improper AuthenticationCheck Point SmartConsolePatch nowForensic triage required by CISA; Metasploit module0.78
5CVE-2026-0770Inclusion of Functionality from Untrusted Control SphereLangflow LangflowPatch nowForensic triage required by CISA; Metasploit module0.63
6CVE-2026-41940Missing Authentication for Critical FunctionWebPros cPanel & WHM and WP2 (WordPress Squared)Patch nowRansomware use, listed within a year; Metasploit module0.99
7CVE-2024-1708Path TraversalConnectWise ScreenConnectPatch nowRansomware use, listed within a year; Metasploit module0.95
8CVE-2026-1731OS Command InjectionBeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)Patch nowRansomware use, listed within a year; Metasploit module0.91
9CVE-2025-52691Unrestricted Upload of File with Dangerous TypeSmarterTools SmarterMailPatch nowRansomware use, listed within a year; Metasploit module0.86
10CVE-2025-55182Remote Code ExecutionMeta React Server ComponentsPatch nowRansomware use, listed within a year; Metasploit module0.99
11CVE-2026-9198Code InjectionIBM LangflowPatch nowForensic triage required by CISA; Metasploit module0.29
12CVE-2026-83548Server-Side Request ForgerySonicWall SMA1000 AppliancesPatch nowForensic triage required by CISA; Metasploit module0.09
13CVE-2026-83549OS Command InjectionSonicWall SMA1000 AppliancesPatch nowForensic triage required by CISA; Metasploit module0.11
14CVE-2026-63030Interpretation ConflictWordPress CorePatch nowForensic triage required by CISA; Metasploit module0.10
15CVE-2026-15409Server-Side Request ForgerySonicWall SMA1000 AppliancesPatch nowForensic triage required by CISA; ransomware use, listed within a year; Metasploit module0.07
16CVE-2008-4128Cross-Site Request ForgeryCisco IOSPatch nowForensic triage required by CISA; verified Exploit-DB entry0.34
17CVE-2026-71362Incorrect AuthorizationAdobe Commerce and MagentoPatch nowForensic triage required by CISA; listed in the last 14 days0.88
18CVE-2019-1068Remote Code ExecutionMicrosoft SQL ServerPatch nowForensic triage required by CISA0.57
19CVE-2026-21962Improper Access ControlOracle HTTP Server and Oracle Weblogic Server Proxy Plug-inPatch nowForensic triage required by CISA0.73
20CVE-2026-73570OS Command InjectionSynacor Zimbra Collaboration Suite (ZCS)Patch nowForensic triage required by CISA0.72
21CVE-2026-55040Weak AuthenticationMicrosoft SharePointPatch nowForensic triage required by CISA0.70
22CVE-2025-62593Code InjectionRay-Project RayPatch nowForensic triage required by CISA0.62
23CVE-2026-8037Command InjectionProgress LoadMasterPatch nowForensic triage required by CISA0.77
24CVE-2026-25089OS Command InjectionFortinet FortiSandboxPatch nowForensic triage required by CISA0.76
25CVE-2026-48908Unrestricted Upload of File with Dangerous TypeJoomShaper SP Page BuilderPatch nowForensic triage required by CISA0.89
26CVE-2026-0257Authentication BypassPalo Alto Networks PAN-OSPatch nowRansomware use, listed within a year0.97
27CVE-2024-57726Missing AuthorizationSimpleHelp SimpleHelpPatch nowRansomware use, listed within a year0.67
28CVE-2024-57728Path TraversalSimpleHelp SimpleHelpPatch nowRansomware use, listed within a year0.65
29CVE-2023-27351Improper AuthenticationPaperCut NG/MFPatch nowRansomware use, listed within a year0.78
30CVE-2024-27199Relative Path TraversalJetBrains TeamCityPatch nowRansomware use, listed within a year0.99
31CVE-2023-21529Deserialization of Untrusted DataMicrosoft Exchange ServerPatch nowRansomware use, listed within a year0.59
32CVE-2025-26399Deserialization of Untrusted DataSolarWinds Web Help DeskPatch nowRansomware use, listed within a year0.90
33CVE-2026-24423Missing Authentication for Critical FunctionSmarterTools SmarterMailPatch nowRansomware use, listed within a year0.88
34CVE-2026-23760Authentication Bypass Using an Alternate Path or ChannelSmarterTools SmarterMailPatch nowRansomware use, listed within a year0.97
35CVE-2025-61884Server-Side Request Forgery (SSRF)Oracle E-Business SuitePatch nowRansomware use, listed within a year0.96
36CVE-2026-87902Remote File InclusionWordPress CorePatch nowForensic triage required by CISA; listed in the last 14 days0.46
37CVE-2026-76461SQL InjectionCisco Secure Email GatewayPatch nowForensic triage required by CISA0.28
38CVE-2023-49105Improper AuthenticationownCloud ownCloudPatch nowForensic triage required by CISA0.43
39CVE-2026-20316Secure Firewall Management Center Use of Hard-coded PasswordCisco Secure Firewall Management Center (FMC)Patch nowRansomware use, listed within a year0.35
40CVE-2026-39808OS Command InjectionFortinet FortiSandboxPatch nowForensic triage required by CISA0.47
41CVE-2026-48282Path TraversalAdobe ColdFusionPatch nowForensic triage required by CISA0.42
42CVE-2026-56290Improper Access ControlJoomlack Page BuilderPatch nowForensic triage required by CISA0.31
43CVE-2026-12569Improper Input ValidationPTC Windchill and FlexPLMPatch nowRansomware use, listed within a year0.46
44CVE-2026-20131Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted DataCisco Secure Firewall Management Center (FMC)Patch nowRansomware use, listed within a year0.43
45CVE-2026-93616Path TraversalCheck Point Multiple ProductsPatch nowForensic triage required by CISA0.20
46CVE-2026-19490Authentication Bypass Using an Alternate Path or ChannelCitrix NetScalerPatch nowForensic triage required by CISA0.23
47CVE-2026-9586SQL InjectionSangoma SwitchvoxPatch nowForensic triage required by CISA0.19
48CVE-2026-60004Code InjectionGitea GiteaPatch nowForensic triage required by CISA0.24
49CVE-2026-72898SQL InjectionMetabase MetabasePatch nowForensic triage required by CISA0.19
50CVE-2026-48939Unrestricted Upload of File with Dangerous TypeiCagenda iCagendaPatch nowForensic triage required by CISA0.20
51CVE-2025-14733Out of Bounds WriteWatchGuard FireboxPatch nowRansomware use, listed within a year0.27
52CVE-2026-76460Incorrect Use of Privileged APIsCisco Identity Services EnginePatch nowForensic triage required by CISA0.14
53CVE-2026-86218Static Code InjectionN-able N-centralPatch nowForensic triage required by CISA0.13
54CVE-2026-82329Improper AuthenticationJFrog ArtifactoryPatch nowForensic triage required by CISA0.14
55CVE-2026-18577Authentication Bypass Using an Alternate Path or ChannelN-able N-centralPatch nowForensic triage required by CISA0.15
56CVE-2026-58644Deserialization of Untrusted DataMicrosoft SharePointPatch nowForensic triage required by CISA0.16
57CVE-2026-56291Unrestricted Upload of File with Dangerous TypeBalbooa FormsPatch nowForensic triage required by CISA0.15
58CVE-2026-15410Code InjectionSonicWall SMA1000 AppliancesPatch nowForensic triage required by CISA; ransomware use, listed within a year0.12
59CVE-2026-35273Missing Authentication for Critical FunctionOracle PeopleSoft Enterprise PeopleToolsPatch nowRansomware use, listed within a year0.09
60CVE-2026-85102Improper Certificate ValidationCheck Point Multiple ProductsPatch nowForensic triage required by CISA0.08
61CVE-2026-18556Authentication Bypass Using an Alternate Path or ChannelN-able N-centralPatch nowForensic triage required by CISA0.08
62CVE-2026-86060Improper Neutralization of Argument Delimiters in a CommandMikroTik RouterOSPatch nowForensic triage required by CISA0.06
63CVE-2026-50751Improper AuthenticationCheck Point Security GatewayPatch nowRansomware use, listed within a year0.06
64CVE-2025-60710Link FollowingMicrosoft WindowsPatch nowRansomware use, listed within a year0.05
65CVE-2026-75650Improper Neutralization of Special Elements Used in a Template EngineAdobe Commerce and MagentoPatch nowForensic triage required by CISA0.04
66CVE-2021-27137Stack-Based Buffer OverflowDD-WRT DD-WRTPatch nowForensic triage required by CISA0.04
67CVE-2025-25249Heap-based Buffer OverflowFortinet Multiple ProductsPatch nowForensic triage required by CISA0.04
68CVE-2026-50522Deserialization of Untrusted DataMicrosoft SharePointPatch nowForensic triage required by CISA0.03
69CVE-2025-39682Improper Check for Unusual or Exceptional ConditionsLinux KernelPatch nowForensic triage required by CISA0.03
70CVE-2026-45659Deserialization of Untrusted DataMicrosoft SharePoint ServerPatch nowForensic triage required by CISA; ransomware use, listed within a year0.03
71CVE-2026-7273Stack-Based Buffer OverflowZyxel GS1900 Series SwitchesPatch nowForensic triage required by CISA0.03
72CVE-2026-59310Path TraversalBroadcom VMware vCenterPatch nowForensic triage required by CISA; ransomware use, listed within a year0.03
73CVE-2026-94127Heap-based Buffer OverflowF5 BIG-IP APMPatch nowForensic triage required by CISA0.02
74CVE-2026-104286Path TraversalFortinet FortiMailPatch nowForensic triage required by CISA; listed in the last 14 days0.02
75CVE-2026-65660Code InjectionMicrosoft SharePointPatch nowForensic triage required by CISA; listed in the last 14 days0.02
76CVE-2026-49869OS Command InjectionKestra Kestra OSSPatch nowForensic triage required by CISA0.02
77CVE-2026-76504Hex EncodingCisco Catalyst SD-WAN ManagerPatch nowForensic triage required by CISA; listed in the last 14 days0.02
78CVE-2026-65400Improper AuthenticationApple macOSPatch nowForensic triage required by CISA0.02
79CVE-2026-72529Missing Authentication for Critical FunctionTrueConf ServerPatch nowForensic triage required by CISA0.01
80CVE-2026-102489Session FixationZammad GmbH ZammadPatch nowForensic triage required by CISA; listed in the last 14 days0.01
81CVE-2026-48027Embedded Malicious CodeNx Nx ConsolePatch nowRansomware use, listed within a year0.01
82CVE-2026-88772Improper Restriction of Operations within the Bounds of a Memory BufferCitrix NetScalerPatch nowForensic triage required by CISA; listed in the last 14 days0.01
83CVE-2026-86950Out-of-Bounds WriteApple Multiple ProductsPatch nowForensic triage required by CISA; listed in the last 14 days0.01
84CVE-2025-39964Race ConditionLinux KernelPatch nowForensic triage required by CISA0.01
85CVE-2026-88771Improper Input ValidationCitrix NetScalerPatch nowForensic triage required by CISA; listed in the last 14 days0.01
86CVE-2026-93952Improper Input ValidationArista VeloCloud OrchestratorPatch nowForensic triage required by CISA0.01
87CVE-2026-45321UnspecifiedTanStack TanStackPatch nowRansomware use, listed within a year0.01
88CVE-2026-67279Improper Enforcement of Behavioral WorkflowMikroTik RouterOSPatch nowListed in the last 14 days0.01
89CVE-2026-16812On-Prem OS Command InjectionArista VeloCloud OrchestratorPatch nowForensic triage required by CISA0.01
90CVE-2026-56164Missing Authentication for Critical FunctionMicrosoft SharePoint ServerPatch nowForensic triage required by CISA0.01
91CVE-2026-84869Improper Privilege Management and Missing AuthorizationConnectWise ScreenConnectPatch nowForensic triage required by CISA0.01
92CVE-2026-55255Authorization Bypass Through User-Controlled KeyLangflow LangflowPatch nowForensic triage required by CISA0.01
93CVE-2026-53266Out-of-Bounds WriteLinux KernelPatch nowForensic triage required by CISA0.01
94CVE-2026-46817Improper Privilege ManagementOracle E-Business SuitePatch nowForensic triage required by CISA0.01
95CVE-2026-53362UnspecifiedLinux KernelPatch nowForensic triage required by CISA0.01
96CVE-2026-102490Improper Privilege ManagementZammad GmbH ZammadPatch nowForensic triage required by CISA; listed in the last 14 days0.01
97CVE-2026-88779Improper Restriction of Operations within the Bounds of a Memory BufferCitrix NetScalerPatch nowForensic triage required by CISA; listed in the last 14 days0.01
98CVE-2026-5430Path TraversalWSO2 Multiple ProductsPatch nowForensic triage required by CISA; listed in the last 14 days0.01
99CVE-2026-58704Improper AuthorizationGoogle PixelPatch nowForensic triage required by CISA0.01
100CVE-2026-33825Insufficient Granularity of Access ControlMicrosoft DefenderPatch nowRansomware use, listed within a year0.00