Patch first
As of , all 1,734 vulnerabilities on CISA's list of exploited vulnerabilities, in our patch-first order: 101 to patch now.
| # | Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|---|
| 1 | CVE-2026-85706Path Traversal | GitLab Community Edition and Enterprise Edition | Patch nowForensic triage required by CISA; Metasploit module | 0.93 | ||
| 2 | CVE-2026-20079Firewall Management Center Authentication Bypass Using an Alternate Path or Channel | Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management | Patch nowForensic triage required by CISA; Metasploit module | 0.88 | ||
| 3 | CVE-2026-63077Deserialization of Untrusted Data | JetBrains TeamCity | Patch nowForensic triage required by CISA; ransomware use, listed within a year; Metasploit module | 0.90 | ||
| 4 | CVE-2026-16232Improper Authentication | Check Point SmartConsole | Patch nowForensic triage required by CISA; Metasploit module | 0.78 | ||
| 5 | CVE-2026-0770Inclusion of Functionality from Untrusted Control Sphere | Langflow Langflow | Patch nowForensic triage required by CISA; Metasploit module | 0.63 | ||
| 6 | CVE-2026-41940Missing Authentication for Critical Function | WebPros cPanel & WHM and WP2 (WordPress Squared) | Patch nowRansomware use, listed within a year; Metasploit module | 0.99 | ||
| 7 | CVE-2024-1708Path Traversal | ConnectWise ScreenConnect | Patch nowRansomware use, listed within a year; Metasploit module | 0.95 | ||
| 8 | CVE-2026-1731OS Command Injection | BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) | Patch nowRansomware use, listed within a year; Metasploit module | 0.91 | ||
| 9 | CVE-2025-52691Unrestricted Upload of File with Dangerous Type | SmarterTools SmarterMail | Patch nowRansomware use, listed within a year; Metasploit module | 0.86 | ||
| 10 | CVE-2025-55182Remote Code Execution | Meta React Server Components | Patch nowRansomware use, listed within a year; Metasploit module | 0.99 | ||
| 11 | CVE-2026-9198Code Injection | IBM Langflow | Patch nowForensic triage required by CISA; Metasploit module | 0.29 | ||
| 12 | CVE-2026-83548Server-Side Request Forgery | SonicWall SMA1000 Appliances | Patch nowForensic triage required by CISA; Metasploit module | 0.09 | ||
| 13 | CVE-2026-83549OS Command Injection | SonicWall SMA1000 Appliances | Patch nowForensic triage required by CISA; Metasploit module | 0.11 | ||
| 14 | CVE-2026-63030Interpretation Conflict | WordPress Core | Patch nowForensic triage required by CISA; Metasploit module | 0.10 | ||
| 15 | CVE-2026-15409Server-Side Request Forgery | SonicWall SMA1000 Appliances | Patch nowForensic triage required by CISA; ransomware use, listed within a year; Metasploit module | 0.07 | ||
| 16 | CVE-2008-4128Cross-Site Request Forgery | Cisco IOS | Patch nowForensic triage required by CISA; verified Exploit-DB entry | 0.34 | ||
| 17 | CVE-2026-71362Incorrect Authorization | Adobe Commerce and Magento | Patch nowForensic triage required by CISA; listed in the last 14 days | 0.88 | ||
| 18 | CVE-2019-1068Remote Code Execution | Microsoft SQL Server | Patch nowForensic triage required by CISA | 0.57 | ||
| 19 | CVE-2026-21962Improper Access Control | Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in | Patch nowForensic triage required by CISA | 0.73 | ||
| 20 | CVE-2026-73570OS Command Injection | Synacor Zimbra Collaboration Suite (ZCS) | Patch nowForensic triage required by CISA | 0.72 | ||
| 21 | CVE-2026-55040Weak Authentication | Microsoft SharePoint | Patch nowForensic triage required by CISA | 0.70 | ||
| 22 | CVE-2025-62593Code Injection | Ray-Project Ray | Patch nowForensic triage required by CISA | 0.62 | ||
| 23 | CVE-2026-8037Command Injection | Progress LoadMaster | Patch nowForensic triage required by CISA | 0.77 | ||
| 24 | CVE-2026-25089OS Command Injection | Fortinet FortiSandbox | Patch nowForensic triage required by CISA | 0.76 | ||
| 25 | CVE-2026-48908Unrestricted Upload of File with Dangerous Type | JoomShaper SP Page Builder | Patch nowForensic triage required by CISA | 0.89 | ||
| 26 | CVE-2026-0257Authentication Bypass | Palo Alto Networks PAN-OS | Patch nowRansomware use, listed within a year | 0.97 | ||
| 27 | CVE-2024-57726Missing Authorization | SimpleHelp SimpleHelp | Patch nowRansomware use, listed within a year | 0.67 | ||
| 28 | CVE-2024-57728Path Traversal | SimpleHelp SimpleHelp | Patch nowRansomware use, listed within a year | 0.65 | ||
| 29 | CVE-2023-27351Improper Authentication | PaperCut NG/MF | Patch nowRansomware use, listed within a year | 0.78 | ||
| 30 | CVE-2024-27199Relative Path Traversal | JetBrains TeamCity | Patch nowRansomware use, listed within a year | 0.99 | ||
| 31 | CVE-2023-21529Deserialization of Untrusted Data | Microsoft Exchange Server | Patch nowRansomware use, listed within a year | 0.59 | ||
| 32 | CVE-2025-26399Deserialization of Untrusted Data | SolarWinds Web Help Desk | Patch nowRansomware use, listed within a year | 0.90 | ||
| 33 | CVE-2026-24423Missing Authentication for Critical Function | SmarterTools SmarterMail | Patch nowRansomware use, listed within a year | 0.88 | ||
| 34 | CVE-2026-23760Authentication Bypass Using an Alternate Path or Channel | SmarterTools SmarterMail | Patch nowRansomware use, listed within a year | 0.97 | ||
| 35 | CVE-2025-61884Server-Side Request Forgery (SSRF) | Oracle E-Business Suite | Patch nowRansomware use, listed within a year | 0.96 | ||
| 36 | CVE-2026-87902Remote File Inclusion | WordPress Core | Patch nowForensic triage required by CISA; listed in the last 14 days | 0.46 | ||
| 37 | CVE-2026-76461SQL Injection | Cisco Secure Email Gateway | Patch nowForensic triage required by CISA | 0.28 | ||
| 38 | CVE-2023-49105Improper Authentication | ownCloud ownCloud | Patch nowForensic triage required by CISA | 0.43 | ||
| 39 | CVE-2026-20316Secure Firewall Management Center Use of Hard-coded Password | Cisco Secure Firewall Management Center (FMC) | Patch nowRansomware use, listed within a year | 0.35 | ||
| 40 | CVE-2026-39808OS Command Injection | Fortinet FortiSandbox | Patch nowForensic triage required by CISA | 0.47 | ||
| 41 | CVE-2026-48282Path Traversal | Adobe ColdFusion | Patch nowForensic triage required by CISA | 0.42 | ||
| 42 | CVE-2026-56290Improper Access Control | Joomlack Page Builder | Patch nowForensic triage required by CISA | 0.31 | ||
| 43 | CVE-2026-12569Improper Input Validation | PTC Windchill and FlexPLM | Patch nowRansomware use, listed within a year | 0.46 | ||
| 44 | CVE-2026-20131Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data | Cisco Secure Firewall Management Center (FMC) | Patch nowRansomware use, listed within a year | 0.43 | ||
| 45 | CVE-2026-93616Path Traversal | Check Point Multiple Products | Patch nowForensic triage required by CISA | 0.20 | ||
| 46 | CVE-2026-19490Authentication Bypass Using an Alternate Path or Channel | Citrix NetScaler | Patch nowForensic triage required by CISA | 0.23 | ||
| 47 | CVE-2026-9586SQL Injection | Sangoma Switchvox | Patch nowForensic triage required by CISA | 0.19 | ||
| 48 | CVE-2026-60004Code Injection | Gitea Gitea | Patch nowForensic triage required by CISA | 0.24 | ||
| 49 | CVE-2026-72898SQL Injection | Metabase Metabase | Patch nowForensic triage required by CISA | 0.19 | ||
| 50 | CVE-2026-48939Unrestricted Upload of File with Dangerous Type | iCagenda iCagenda | Patch nowForensic triage required by CISA | 0.20 | ||
| 51 | CVE-2025-14733Out of Bounds Write | WatchGuard Firebox | Patch nowRansomware use, listed within a year | 0.27 | ||
| 52 | CVE-2026-76460Incorrect Use of Privileged APIs | Cisco Identity Services Engine | Patch nowForensic triage required by CISA | 0.14 | ||
| 53 | CVE-2026-86218Static Code Injection | N-able N-central | Patch nowForensic triage required by CISA | 0.13 | ||
| 54 | CVE-2026-82329Improper Authentication | JFrog Artifactory | Patch nowForensic triage required by CISA | 0.14 | ||
| 55 | CVE-2026-18577Authentication Bypass Using an Alternate Path or Channel | N-able N-central | Patch nowForensic triage required by CISA | 0.15 | ||
| 56 | CVE-2026-58644Deserialization of Untrusted Data | Microsoft SharePoint | Patch nowForensic triage required by CISA | 0.16 | ||
| 57 | CVE-2026-56291Unrestricted Upload of File with Dangerous Type | Balbooa Forms | Patch nowForensic triage required by CISA | 0.15 | ||
| 58 | CVE-2026-15410Code Injection | SonicWall SMA1000 Appliances | Patch nowForensic triage required by CISA; ransomware use, listed within a year | 0.12 | ||
| 59 | CVE-2026-35273Missing Authentication for Critical Function | Oracle PeopleSoft Enterprise PeopleTools | Patch nowRansomware use, listed within a year | 0.09 | ||
| 60 | CVE-2026-85102Improper Certificate Validation | Check Point Multiple Products | Patch nowForensic triage required by CISA | 0.08 | ||
| 61 | CVE-2026-18556Authentication Bypass Using an Alternate Path or Channel | N-able N-central | Patch nowForensic triage required by CISA | 0.08 | ||
| 62 | CVE-2026-86060Improper Neutralization of Argument Delimiters in a Command | MikroTik RouterOS | Patch nowForensic triage required by CISA | 0.06 | ||
| 63 | CVE-2026-50751Improper Authentication | Check Point Security Gateway | Patch nowRansomware use, listed within a year | 0.06 | ||
| 64 | CVE-2025-60710Link Following | Microsoft Windows | Patch nowRansomware use, listed within a year | 0.05 | ||
| 65 | CVE-2026-75650Improper Neutralization of Special Elements Used in a Template Engine | Adobe Commerce and Magento | Patch nowForensic triage required by CISA | 0.04 | ||
| 66 | CVE-2021-27137Stack-Based Buffer Overflow | DD-WRT DD-WRT | Patch nowForensic triage required by CISA | 0.04 | ||
| 67 | CVE-2025-25249Heap-based Buffer Overflow | Fortinet Multiple Products | Patch nowForensic triage required by CISA | 0.04 | ||
| 68 | CVE-2026-50522Deserialization of Untrusted Data | Microsoft SharePoint | Patch nowForensic triage required by CISA | 0.03 | ||
| 69 | CVE-2025-39682Improper Check for Unusual or Exceptional Conditions | Linux Kernel | Patch nowForensic triage required by CISA | 0.03 | ||
| 70 | CVE-2026-45659Deserialization of Untrusted Data | Microsoft SharePoint Server | Patch nowForensic triage required by CISA; ransomware use, listed within a year | 0.03 | ||
| 71 | CVE-2026-7273Stack-Based Buffer Overflow | Zyxel GS1900 Series Switches | Patch nowForensic triage required by CISA | 0.03 | ||
| 72 | CVE-2026-59310Path Traversal | Broadcom VMware vCenter | Patch nowForensic triage required by CISA; ransomware use, listed within a year | 0.03 | ||
| 73 | CVE-2026-94127Heap-based Buffer Overflow | F5 BIG-IP APM | Patch nowForensic triage required by CISA | 0.02 | ||
| 74 | CVE-2026-104286Path Traversal | Fortinet FortiMail | Patch nowForensic triage required by CISA; listed in the last 14 days | 0.02 | ||
| 75 | CVE-2026-65660Code Injection | Microsoft SharePoint | Patch nowForensic triage required by CISA; listed in the last 14 days | 0.02 | ||
| 76 | CVE-2026-49869OS Command Injection | Kestra Kestra OSS | Patch nowForensic triage required by CISA | 0.02 | ||
| 77 | CVE-2026-76504Hex Encoding | Cisco Catalyst SD-WAN Manager | Patch nowForensic triage required by CISA; listed in the last 14 days | 0.02 | ||
| 78 | CVE-2026-65400Improper Authentication | Apple macOS | Patch nowForensic triage required by CISA | 0.02 | ||
| 79 | CVE-2026-72529Missing Authentication for Critical Function | TrueConf Server | Patch nowForensic triage required by CISA | 0.01 | ||
| 80 | CVE-2026-102489Session Fixation | Zammad GmbH Zammad | Patch nowForensic triage required by CISA; listed in the last 14 days | 0.01 | ||
| 81 | CVE-2026-48027Embedded Malicious Code | Nx Nx Console | Patch nowRansomware use, listed within a year | 0.01 | ||
| 82 | CVE-2026-88772Improper Restriction of Operations within the Bounds of a Memory Buffer | Citrix NetScaler | Patch nowForensic triage required by CISA; listed in the last 14 days | 0.01 | ||
| 83 | CVE-2026-86950Out-of-Bounds Write | Apple Multiple Products | Patch nowForensic triage required by CISA; listed in the last 14 days | 0.01 | ||
| 84 | CVE-2025-39964Race Condition | Linux Kernel | Patch nowForensic triage required by CISA | 0.01 | ||
| 85 | CVE-2026-88771Improper Input Validation | Citrix NetScaler | Patch nowForensic triage required by CISA; listed in the last 14 days | 0.01 | ||
| 86 | CVE-2026-93952Improper Input Validation | Arista VeloCloud Orchestrator | Patch nowForensic triage required by CISA | 0.01 | ||
| 87 | CVE-2026-45321Unspecified | TanStack TanStack | Patch nowRansomware use, listed within a year | 0.01 | ||
| 88 | CVE-2026-67279Improper Enforcement of Behavioral Workflow | MikroTik RouterOS | Patch nowListed in the last 14 days | 0.01 | ||
| 89 | CVE-2026-16812On-Prem OS Command Injection | Arista VeloCloud Orchestrator | Patch nowForensic triage required by CISA | 0.01 | ||
| 90 | CVE-2026-56164Missing Authentication for Critical Function | Microsoft SharePoint Server | Patch nowForensic triage required by CISA | 0.01 | ||
| 91 | CVE-2026-84869Improper Privilege Management and Missing Authorization | ConnectWise ScreenConnect | Patch nowForensic triage required by CISA | 0.01 | ||
| 92 | CVE-2026-55255Authorization Bypass Through User-Controlled Key | Langflow Langflow | Patch nowForensic triage required by CISA | 0.01 | ||
| 93 | CVE-2026-53266Out-of-Bounds Write | Linux Kernel | Patch nowForensic triage required by CISA | 0.01 | ||
| 94 | CVE-2026-46817Improper Privilege Management | Oracle E-Business Suite | Patch nowForensic triage required by CISA | 0.01 | ||
| 95 | CVE-2026-53362Unspecified | Linux Kernel | Patch nowForensic triage required by CISA | 0.01 | ||
| 96 | CVE-2026-102490Improper Privilege Management | Zammad GmbH Zammad | Patch nowForensic triage required by CISA; listed in the last 14 days | 0.01 | ||
| 97 | CVE-2026-88779Improper Restriction of Operations within the Bounds of a Memory Buffer | Citrix NetScaler | Patch nowForensic triage required by CISA; listed in the last 14 days | 0.01 | ||
| 98 | CVE-2026-5430Path Traversal | WSO2 Multiple Products | Patch nowForensic triage required by CISA; listed in the last 14 days | 0.01 | ||
| 99 | CVE-2026-58704Improper Authorization | Google Pixel | Patch nowForensic triage required by CISA | 0.01 | ||
| 100 | CVE-2026-33825Insufficient Granularity of Access Control | Microsoft Defender | Patch nowRansomware use, listed within a year | 0.00 |