Patch first, page 18
As of , all 1,734 vulnerabilities on CISA's list of exploited vulnerabilities, in our patch-first order: 101 to patch now.
| # | Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|---|
| 1701 | CVE-2025-1976Code Injection | Broadcom Brocade Fabric OS | Patch soon | 0.01 | ||
| 1702 | CVE-2024-43093Privilege Escalation | Android Framework | Patch soon | 0.01 | ||
| 1703 | CVE-2019-8526Use-After-Free | Apple macOS | Patch soon | 0.01 | ||
| 1704 | CVE-2021-39793Out-of-Bounds Write | Google Pixel | Patch soon | 0.01 | ||
| 1705 | CVE-2026-66384Improper Limitation of a Pathname to a Restricted Directory | JFrog Artifactory | Patch soon | 0.01 | ||
| 1706 | CVE-2024-43047Use-After-Free | Qualcomm Multiple Chipsets | Patch soon | 0.01 | ||
| 1707 | CVE-2024-29748Privilege Escalation | Android Pixel | Patch soon | 0.01 | ||
| 1708 | CVE-2023-33063Use-After-Free | Qualcomm Multiple Chipsets | Patch soon | 0.01 | ||
| 1709 | CVE-2026-7473Incomplete Comparison with Missing Factors | Arista Extensible Operating System | Patch soon | 0.01 | ||
| 1710 | CVE-2021-25487Out-of-Bounds Read | Samsung Mobile Devices | Patch soon | 0.01 | ||
| 1711 | CVE-2025-48928Exposure of Core Dump File to an Unauthorized Control Sphere | TeleMessage TM SGNL | Patch soon | 0.01 | ||
| 1712 | CVE-2026-34926(On-Premise) Directory Traversal | Trend Micro Apex One | Patch soon | 0.01 | ||
| 1713 | CVE-2025-48543Use-After-Free | Android Runtime | Patch soon | 0.01 | ||
| 1714 | CVE-2026-42897Exchange Server Cross-Site Scripting | Microsoft Microsoft | Patch soon | 0.01 | ||
| 1715 | CVE-2021-25489Improper Input Validation | Samsung Mobile Devices | Patch soon | 0.01 | ||
| 1716 | CVE-2021-1906Detection of Error Condition Without Action | Qualcomm Multiple Chipsets | Patch soon | 0.01 | ||
| 1717 | CVE-2024-29745Information Disclosure | Android Pixel | Patch soon | 0.00 | ||
| 1718 | CVE-2022-48618Memory Corruption | Apple Multiple Products | Patch soon | 0.00 | ||
| 1719 | CVE-2025-21480Incorrect Authorization | Qualcomm Multiple Chipsets | Patch soon | 0.00 | ||
| 1720 | CVE-2026-41091Link Following | Microsoft Defender | Patch soon | 0.00 | ||
| 1721 | CVE-2025-47729Hidden Functionality | TeleMessage TM SGNL | Patch soon | 0.00 | ||
| 1722 | CVE-2025-43520Classic Buffer Overflow | Apple Multiple Products | Patch soon | 0.00 | ||
| 1723 | CVE-2022-22071Use-After-Free | Qualcomm Multiple Chipsets | Patch soon | 0.00 | ||
| 1724 | CVE-2021-25394Race Condition | Samsung Mobile Devices | Patch soon | 0.00 | ||
| 1725 | CVE-2026-81963Link Following | Microsoft Windows | Patch soon | 0.00 | ||
| 1726 | CVE-2022-22265Use-After-Free | Samsung Mobile Devices | Patch soon | 0.00 | ||
| 1727 | CVE-2021-25395Race Condition | Samsung Mobile Devices | Patch soon | 0.00 | ||
| 1728 | CVE-2025-43510Improper Locking | Apple Multiple Products | Patch soon | 0.00 | ||
| 1729 | CVE-2026-56155Insufficient Granularity of Access Control | Microsoft Active Directory Federation Services | Patch soon | 0.00 | ||
| 1730 | CVE-2026-68820Use-After-Free | Microsoft Windows Ancillary Function Driver for WinSock | Patch soon | 0.00 | ||
| 1731 | CVE-2026-3502Download of Code Without Integrity Check | TrueConf Client | Patch soon | 0.00 | ||
| 1732 | CVE-2025-48572Privilege Escalation | Android Framework | Patch soon | 0.00 | ||
| 1733 | CVE-2025-48633Information Disclosure | Android Framework | Patch soon | 0.00 | ||
| 1734 | CVE-2023-21237Information Disclosure | Android Pixel | Patch soon | 0.00 |