Patch first, page 11
As of , all 1,734 vulnerabilities on CISA's list of exploited vulnerabilities, in our patch-first order: 101 to patch now.
| # | Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|---|
| 1001 | CVE-2006-1547ActionForm Denial-of-Service | Apache Struts 1 | Patch this weekEPSS 0.55 | 0.55 | ||
| 1002 | CVE-2018-13383Out-of-bounds Write | Fortinet FortiOS and FortiProxy | Patch this weekRansomware use | 0.34 | ||
| 1003 | CVE-2019-1579Remote Code Execution | Palo Alto Networks PAN-OS | Patch this weekRansomware use | 0.46 | ||
| 1004 | CVE-2018-2380Path Traversal | SAP Customer Relationship Management (CRM) | Patch this weekRansomware use | 0.29 | ||
| 1005 | CVE-2019-0541Remote Code Execution | Microsoft MSHTML | Patch this weekEPSS 0.53 | 0.53 | ||
| 1006 | CVE-2019-0803Privilege Escalation | Microsoft Win32k | Patch this weekRansomware use | 0.45 | ||
| 1007 | CVE-2019-1367Scripting Engine Memory Corruption | Microsoft Internet Explorer | Patch this weekRansomware use; EPSS 0.52 | 0.52 | ||
| 1008 | CVE-2019-13608XML External Entity (XXE) Processing | Citrix StoreFront Server | Patch this weekRansomware use | 0.30 | ||
| 1009 | CVE-2020-0968Scripting Engine Memory Corruption | Microsoft Internet Explorer | Patch this weekRansomware use | 0.31 | ||
| 1010 | CVE-2020-12271SQL Injection | Sophos SFOS | Patch this weekRansomware use | 0.42 | ||
| 1011 | CVE-2020-12812SSL VPN Improper Authentication | Fortinet FortiOS | Patch this weekRansomware use | 0.45 | ||
| 1012 | CVE-2020-29557Buffer Overflow | D-Link DIR-825 R1 Devices | Patch this weekEPSS 0.54 | 0.54 | ||
| 1013 | CVE-2021-20016SQL Injection | SonicWall SSLVPN SMA100 | Patch this weekRansomware use | 0.40 | ||
| 1014 | CVE-2021-20023Path Traversal | SonicWall SonicWall Email Security | Patch this weekRansomware use; EPSS 0.52 | 0.52 | ||
| 1015 | CVE-2021-22893Use-After-Free | Ivanti Pulse Connect Secure | Patch this weekRansomware use | 0.47 | ||
| 1016 | CVE-2021-28550Use-After-Free | Adobe Acrobat and Reader | Patch this weekEPSS 0.52 | 0.52 | ||
| 1017 | CVE-2018-8639Win32k Improper Resource Shutdown or Release | Microsoft Windows | Patch this weekRansomware use | 0.22 | ||
| 1018 | CVE-2025-23006Deserialization | SonicWall SMA1000 Appliances | Patch this weekRansomware use | 0.23 | ||
| 1019 | CVE-2024-9680Use-After-Free | Mozilla Firefox | Patch this weekRansomware use | 0.23 | ||
| 1020 | CVE-2024-40766Improper Access Control | SonicWall SonicOS | Patch this weekRansomware use | 0.18 | ||
| 1021 | CVE-2024-37085Authentication Bypass | VMware ESXi | Patch this weekRansomware use | 0.27 | ||
| 1022 | CVE-2023-20269Unauthorized Access | Cisco Adaptive Security Appliance and Firepower Threat Defense | Patch this weekRansomware use | 0.25 | ||
| 1023 | CVE-2016-3351Information Disclosure | Microsoft Internet Explorer and Edge | Patch this weekRansomware use | 0.26 | ||
| 1024 | CVE-2018-19943NAS File Station Cross-Site Scripting | QNAP Network Attached Storage (NAS) | Patch this weekRansomware use | 0.21 | ||
| 1025 | CVE-2016-3309Kernel Privilege Escalation | Microsoft Windows | Patch this weekRansomware use | 0.20 | ||
| 1026 | CVE-2020-5135Buffer Overflow | SonicWall SonicOS | Patch this weekRansomware use | 0.27 | ||
| 1027 | CVE-2016-1019Arbitrary Code Execution | Adobe Flash Player | Patch this weekRansomware use | 0.22 | ||
| 1028 | CVE-2021-41379Installer Privilege Escalation | Microsoft Windows | Patch this weekRansomware use | 0.19 | ||
| 1029 | CVE-2019-1215Privilege Escalation | Microsoft Windows | Patch this weekRansomware use | 0.19 | ||
| 1030 | CVE-2019-5591Default Configuration | Fortinet FortiOS | Patch this weekRansomware use | 0.18 | ||
| 1031 | CVE-2025-42999Deserialization | SAP NetWeaver | Patch this weekRansomware use | 0.14 | ||
| 1032 | CVE-2025-29824Common Log File System (CLFS) Driver Use-After-Free | Microsoft Windows | Patch this weekRansomware use | 0.14 | ||
| 1033 | CVE-2024-49039Task Scheduler Privilege Escalation | Microsoft Windows | Patch this weekRansomware use | 0.14 | ||
| 1034 | CVE-2019-7193Improper Input Validation | QNAP QTS | Patch this weekRansomware use | 0.14 | ||
| 1035 | CVE-2021-20022Unrestricted Upload of File | SonicWall SonicWall Email Security | Patch this weekRansomware use | 0.17 | ||
| 1036 | CVE-2017-1000253PIE Stack Buffer Corruption | Linux Kernel | Patch this weekRansomware use | 0.11 | ||
| 1037 | CVE-2022-40765Command Injection | Mitel MiVoice Connect | Patch this weekRansomware use | 0.11 | ||
| 1038 | CVE-2022-41223Code Injection | Mitel MiVoice Connect | Patch this weekRansomware use | 0.11 | ||
| 1039 | CVE-2023-23376Common Log File System (CLFS) Driver Privilege Escalation | Microsoft Windows | Patch this weekRansomware use | 0.11 | ||
| 1040 | CVE-2015-2291Denial-of-Service | Intel Ethernet Diagnostics Driver for Windows | Patch this weekRansomware use | 0.09 | ||
| 1041 | CVE-2015-2546Memory Corruption | Microsoft Win32k | Patch this weekRansomware use | 0.10 | ||
| 1042 | CVE-2019-1253AppX Deployment Server Privilege Escalation | Microsoft Windows | Patch this weekRansomware use | 0.12 | ||
| 1043 | CVE-2021-43890AppX Installer Spoofing | Microsoft Windows | Patch this weekRansomware use | 0.10 | ||
| 1044 | CVE-2021-27103Server-Side Request Forgery (SSRF) | Accellion FTA | Patch this weekRansomware use | 0.11 | ||
| 1045 | CVE-2025-24472Authentication Bypass | Fortinet FortiOS and FortiProxy | Patch this weekRansomware use | 0.07 | ||
| 1046 | CVE-2019-1388Certificate Dialog Privilege Escalation | Microsoft Windows | Patch this weekRansomware use | 0.09 | ||
| 1047 | CVE-2018-19323Privilege Escalation | GIGABYTE Multiple Products | Patch this weekRansomware use | 0.08 | ||
| 1048 | CVE-2012-1710Unspecified | Oracle Fusion Middleware | Patch this weekRansomware use | 0.08 | ||
| 1049 | CVE-2022-24521CLFS Driver Privilege Escalation | Microsoft Windows | Patch this weekRansomware use | 0.07 | ||
| 1050 | CVE-2021-38646Access Connectivity Engine Remote Code Execution | Microsoft Office | Patch this weekRansomware use | 0.08 | ||
| 1051 | CVE-2019-11634Remote Code Execution | Citrix Workspace Application and Receiver for Windows | Patch this weekRansomware use | 0.08 | ||
| 1052 | CVE-2019-1064AppX Deployment Service (AppXSVC) Privilege Escalation | Microsoft Windows | Patch this weekRansomware use | 0.07 | ||
| 1053 | CVE-2019-1069Privilege Escalation | Microsoft Task Scheduler | Patch this weekRansomware use | 0.06 | ||
| 1054 | CVE-2021-27101SQL Injection | Accellion FTA | Patch this weekRansomware use | 0.06 | ||
| 1055 | CVE-2019-6693Use of Hard-Coded Credentials | Fortinet FortiOS | Patch this weekRansomware use | 0.06 | ||
| 1056 | CVE-2024-30051Privilege Escalation | Microsoft DWM Core Library | Patch this weekRansomware use | 0.06 | ||
| 1057 | CVE-2022-26500Remote Code Execution | Veeam Backup & Replication | Patch this weekRansomware use | 0.06 | ||
| 1058 | CVE-2016-0167Privilege Escalation | Microsoft Win32k | Patch this weekRansomware use | 0.06 | ||
| 1059 | CVE-2020-29574(CROS) SQL Injection | Sophos CyberoamOS | Patch this weekRansomware use | 0.05 | ||
| 1060 | CVE-2013-3993Invalid Input | IBM InfoSphere BigInsights | Patch this weekRansomware use | 0.05 | ||
| 1061 | CVE-2024-26169Error Reporting Service Improper Privilege Management | Microsoft Windows | Patch this weekRansomware use | 0.04 | ||
| 1062 | CVE-2022-26501Remote Code Execution | Veeam Backup & Replication | Patch this weekRansomware use | 0.04 | ||
| 1063 | CVE-2020-2021Authentication Bypass | Palo Alto Networks PAN-OS | Patch this weekRansomware use | 0.04 | ||
| 1064 | CVE-2019-0859Privilege Escalation | Microsoft Win32k | Patch this weekRansomware use | 0.04 | ||
| 1065 | CVE-2021-36955Common Log File System (CLFS) Driver Privilege Escalation | Microsoft Windows | Patch this weekRansomware use | 0.04 | ||
| 1066 | CVE-2018-19320Unspecified | GIGABYTE Multiple Products | Patch this weekRansomware use | 0.04 | ||
| 1067 | CVE-2018-19321Privilege Escalation | GIGABYTE Multiple Products | Patch this weekRansomware use | 0.04 | ||
| 1068 | CVE-2019-1385AppX Deployment Extensions Privilege Escalation | Microsoft Windows | Patch this weekRansomware use | 0.04 | ||
| 1069 | CVE-2021-27102OS Command Injection | Accellion FTA | Patch this weekRansomware use | 0.04 | ||
| 1070 | CVE-2018-8405DirectX Graphics Kernel Privilege Escalation | Microsoft DirectX Graphics Kernel (DXGKRNL) | Patch this weekRansomware use | 0.03 | ||
| 1071 | CVE-2018-8406DirectX Graphics Kernel Privilege Escalation | Microsoft DirectX Graphics Kernel (DXGKRNL) | Patch this weekRansomware use | 0.03 | ||
| 1072 | CVE-2019-1315Error Reporting Manager Privilege Escalation | Microsoft Windows | Patch this weekRansomware use | 0.03 | ||
| 1073 | CVE-2021-43226Privilege Escalation | Microsoft Windows | Patch this weekRansomware use | 0.03 | ||
| 1074 | CVE-2024-11667Path Traversal | Zyxel Multiple Firewalls | Patch this weekRansomware use | 0.03 | ||
| 1075 | CVE-2020-0878Memory Corruption | Microsoft Edge and Internet Explorer | Patch this weekRansomware use | 0.03 | ||
| 1076 | CVE-2020-0638Privilege Escalation | Microsoft Update Notification Manager | Patch this weekRansomware use | 0.02 | ||
| 1077 | CVE-2022-41073Print Spooler Privilege Escalation | Microsoft Windows | Patch this weekRansomware use | 0.02 | ||
| 1078 | CVE-2022-41091Mark of the Web (MOTW) Security Feature Bypass | Microsoft Windows | Patch this weekRansomware use | 0.02 | ||
| 1079 | CVE-2018-19322Code Execution | GIGABYTE Multiple Products | Patch this weekRansomware use | 0.02 | ||
| 1080 | CVE-2019-1129AppX Deployment Service (AppXSVC) Privilege Escalation | Microsoft Windows | Patch this weekRansomware use | 0.02 | ||
| 1081 | CVE-2019-1130AppX Deployment Service Privilege Escalation | Microsoft Windows | Patch this weekRansomware use | 0.02 | ||
| 1082 | CVE-2025-22225Arbitrary Write | VMware ESXi | Patch this weekRansomware use | 0.01 | ||
| 1083 | CVE-2013-2094Privilege Escalation | Linux Kernel | Patch soonVerified Exploit-DB entry | 0.48 | ||
| 1084 | CVE-2019-11707Type Confusion | Mozilla Firefox and Thunderbird | Patch soonVerified Exploit-DB entry | 0.38 | ||
| 1085 | CVE-2017-6327Remote Code Execution | Symantec Symantec Messaging Gateway | Patch soonVerified Exploit-DB entry | 0.36 | ||
| 1086 | CVE-2019-8605Use-After-Free | Apple Multiple Products | Patch soonVerified Exploit-DB entry | 0.18 | ||
| 1087 | CVE-2020-3837Memory Corruption | Apple Multiple Products | Patch soonVerified Exploit-DB entry | 0.15 | ||
| 1088 | CVE-2019-8506Type Confusion | Apple Multiple Products | Patch soonVerified Exploit-DB entry | 0.16 | ||
| 1089 | CVE-2010-4398Kernel Stack-Based Buffer Overflow | Microsoft Windows | Patch soonVerified Exploit-DB entry | 0.09 | ||
| 1090 | CVE-2004-0210Privilege Escalation | Microsoft Windows | Patch soonVerified Exploit-DB entry | 0.07 | ||
| 1091 | CVE-2008-3431Insufficient Input Validation | Oracle VirtualBox | Patch soonVerified Exploit-DB entry | 0.07 | ||
| 1092 | CVE-2002-0367Privilege Escalation | Microsoft Windows | Patch soonVerified Exploit-DB entry | 0.05 | ||
| 1093 | CVE-2026-85046Type Confusion | Google Chromium V8 | Patch soon | 0.49 | ||
| 1094 | CVE-2025-68686Exposure of Sensitive Information to an Unauthorized Actor | Fortinet FortiOS | Patch soon | 0.30 | ||
| 1095 | CVE-2026-34910Improper Input Validation | Ubiquiti UniFi OS | Patch soon | 0.46 | ||
| 1096 | CVE-2026-20262Directory or Path Traversal | Cisco Catalyst SD-WAN Manager | Patch soon | 0.28 | ||
| 1097 | CVE-2026-0300Out-of-bounds Write | Palo Alto Networks PAN-OS | Patch soon | 0.32 | ||
| 1098 | CVE-2026-39987Remote Code Execution | Marimo Marimo | Patch soon | 0.38 | ||
| 1099 | CVE-2026-20133Exposure of Sensitive Information to an Unauthorized Actor | Cisco Catalyst SD-WAN Manager | Patch soon | 0.32 | ||
| 1100 | CVE-2009-0238Remote Code Execution | Microsoft Office | Patch soon | 0.43 |