Patch first, page 4
As of , all 1,734 vulnerabilities on CISA's list of exploited vulnerabilities, in our patch-first order: 101 to patch now.
| # | Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|---|
| 301 | CVE-2026-42271Command Injection | BerriAI LiteLLM | Patch this weekMetasploit module; EPSS 0.93 | 0.93 | ||
| 302 | CVE-2026-20182Controller Authentication Bypass | Cisco Catalyst SD-WAN | Patch this weekMetasploit module; EPSS 0.92 | 0.92 | ||
| 303 | CVE-2024-7399Path Traversal | Samsung MagicINFO 9 Server | Patch this weekMetasploit module; EPSS 0.92 | 0.92 | ||
| 304 | CVE-2026-1340Code Injection | Ivanti Endpoint Manager Mobile (EPMM) | Patch this weekMetasploit module; EPSS 0.99 | 0.99 | ||
| 305 | CVE-2025-32432Code Injection | Craft CMS Craft CMS | Patch this weekMetasploit module; EPSS 0.99 | 0.99 | ||
| 306 | CVE-2025-68613Improper Control of Dynamically-Managed Code Resources | n8n n8n | Patch this weekMetasploit module; EPSS 0.99 | 0.99 | ||
| 307 | CVE-2017-7921Improper Authentication | Hikvision Multiple Products | Patch this weekMetasploit module; EPSS 0.99 | 0.99 | ||
| 308 | CVE-2026-20127Authentication Bypass | Cisco Catalyst SD-WAN Controller and Manager | Patch this weekMetasploit module; EPSS 0.88 | 0.88 | ||
| 309 | CVE-2025-49113Deserialization of Untrusted Data | Roundcube Webmail | Patch this weekMetasploit module; EPSS 0.99 | 0.99 | ||
| 310 | CVE-2025-40536Security Control Bypass | SolarWinds Web Help Desk | Patch this weekMetasploit module; EPSS 0.74 | 0.74 | ||
| 311 | CVE-2025-40551Deserialization of Untrusted Data | SolarWinds Web Help Desk | Patch this weekMetasploit module; EPSS 0.84 | 0.84 | ||
| 312 | CVE-2025-64328OS Command Injection | Sangoma FreePBX | Patch this weekMetasploit module; EPSS 0.85 | 0.85 | ||
| 313 | CVE-2026-1281Code Injection | Ivanti Endpoint Manager Mobile (EPMM) | Patch this weekMetasploit module; EPSS 0.99 | 0.99 | ||
| 314 | CVE-2026-24061Argument Injection | GNU InetUtils | Patch this weekMetasploit module; EPSS 0.99 | 0.99 | ||
| 315 | CVE-2025-37164Code Injection | Hewlett Packard Enterprise (HPE) OneView | Patch this weekMetasploit module; EPSS 0.90 | 0.90 | ||
| 316 | CVE-2025-14847Improper Handling of Length Parameter Inconsistency | MongoDB MongoDB and MongoDB Server | Patch this weekMetasploit module; EPSS 0.83 | 0.83 | ||
| 317 | CVE-2025-58360Improper Restriction of XML External Entity Reference | OSGeo GeoServer | Patch this weekMetasploit module; EPSS 0.61 | 0.61 | ||
| 318 | CVE-2025-58034OS Command Injection | Fortinet FortiWeb | Patch this weekMetasploit module; EPSS 0.56 | 0.56 | ||
| 319 | CVE-2025-64446Path Traversal | Fortinet FortiWeb | Patch this weekMetasploit module; EPSS 0.92 | 0.92 | ||
| 320 | CVE-2025-11371Files or Directories Accessible to External Parties | Gladinet CentreStack and Triofox | Patch this weekMetasploit module; EPSS 0.92 | 0.92 | ||
| 321 | CVE-2025-24893Eval Injection | XWiki Platform | Patch this weekMetasploit module; EPSS 0.99 | 0.99 | ||
| 322 | CVE-2025-54236Improper Input Validation | Adobe Commerce and Magento | Patch this weekMetasploit module; EPSS 0.95 | 0.95 | ||
| 323 | CVE-2025-59287Server Update Service (WSUS) Deserialization of Untrusted Data | Microsoft Windows | Patch this weekMetasploit module; EPSS 0.99 | 0.99 | ||
| 324 | CVE-2021-43798Path Traversal | Grafana Labs Grafana | Patch this weekMetasploit module; EPSS 0.89 | 0.89 | ||
| 325 | CVE-2011-3402Remote Code Execution | Microsoft Windows | Patch this weekMetasploit module; EPSS 0.78 | 0.78 | ||
| 326 | CVE-2025-61882Unspecified | Oracle E-Business Suite | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 327 | CVE-2015-7755Improper Authentication | Juniper ScreenOS | Patch this weekMetasploit module; EPSS 0.61 | 0.61 | ||
| 328 | CVE-2017-1000353Remote Code Execution | Jenkins Jenkins | Patch this weekMetasploit module; EPSS 0.99 | 0.99 | ||
| 329 | CVE-2025-32463Inclusion of Functionality from Untrusted Control Sphere | Sudo Sudo | Patch this weekMetasploit module; EPSS 0.55 | 0.55 | ||
| 330 | CVE-2025-57819Authentication Bypass | Sangoma FreePBX | Patch this weekMetasploit module; EPSS 0.85 | 0.85 | ||
| 331 | CVE-2025-49704Code Injection | Microsoft SharePoint | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 332 | CVE-2025-49706Improper Authentication | Microsoft SharePoint | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 333 | CVE-2025-53770Deserialization of Untrusted Data | Microsoft SharePoint | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 334 | CVE-2025-47812Improper Neutralization of Null Byte or NUL Character | Wing FTP Server Wing FTP Server | Patch this weekMetasploit module; EPSS 0.93 | 0.93 | ||
| 335 | CVE-2019-5418Path Traversal | Rails Ruby on Rails | Patch this weekMetasploit module; EPSS 0.99 | 0.99 | ||
| 336 | CVE-2025-24016Deserialization of Untrusted Data | Wazuh Wazuh Server | Patch this weekMetasploit module; EPSS 0.94 | 0.94 | ||
| 337 | CVE-2025-33053External Control of File Name or Path | Microsoft Windows | Patch this weekMetasploit module; EPSS 0.87 | 0.87 | ||
| 338 | CVE-2025-32433SSH Server Missing Authentication for Critical Function | Erlang Erlang/OTP | Patch this weekMetasploit module; EPSS 0.99 | 0.99 | ||
| 339 | CVE-2024-56145Code Injection | Craft CMS Craft CMS | Patch this weekMetasploit module; EPSS 0.97 | 0.97 | ||
| 340 | CVE-2025-4427Authentication Bypass | Ivanti Endpoint Manager Mobile (EPMM) | Patch this weekMetasploit module; EPSS 0.99 | 0.99 | ||
| 341 | CVE-2025-4428Code Injection | Ivanti Endpoint Manager Mobile (EPMM) | Patch this weekMetasploit module; EPSS 0.87 | 0.87 | ||
| 342 | CVE-2025-3248Missing Authentication | Langflow Langflow | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 343 | CVE-2025-30406and Triofox Use of Hard-coded Cryptographic Key | Gladinet CentreStack | Patch this weekMetasploit module; EPSS 0.94 | 0.94 | ||
| 344 | CVE-2025-22457Stack-Based Buffer Overflow | Ivanti Connect Secure, Policy Secure, and ZTA Gateways | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 345 | CVE-2025-24813Path Equivalence | Apache Tomcat | Patch this weekMetasploit module; EPSS 0.99 | 0.99 | ||
| 346 | CVE-2022-43769Pentaho BA Server Special Element Injection | Hitachi Vantara Pentaho Business Analytics (BA) Server | Patch this weekMetasploit module; EPSS 0.98 | 0.98 | ||
| 347 | CVE-2022-43939Pentaho BA Server Authorization Bypass | Hitachi Vantara Pentaho Business Analytics (BA) Server | Patch this weekMetasploit module; EPSS 0.92 | 0.92 | ||
| 348 | CVE-2024-57727Path Traversal | SimpleHelp SimpleHelp | Patch this weekRansomware use; Metasploit module; EPSS 0.97 | 0.97 | ||
| 349 | CVE-2018-9276OS Command Injection | Paessler PRTG Network Monitor | Patch this weekMetasploit module; EPSS 0.87 | 0.87 | ||
| 350 | CVE-2020-2883Unspecified | Oracle WebLogic Server | Patch this weekMetasploit module; EPSS 0.95 | 0.95 | ||
| 351 | CVE-2024-12356Command Injection | BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) | Patch this weekMetasploit module; EPSS 0.87 | 0.87 | ||
| 352 | CVE-2024-55956Unauthenticated File Upload | Cleo Multiple Products | Patch this weekRansomware use; Metasploit module; EPSS 0.94 | 0.94 | ||
| 353 | CVE-2024-20767Improper Access Control | Adobe ColdFusion | Patch this weekMetasploit module; EPSS 0.99 | 0.99 | ||
| 354 | CVE-2024-51378Incorrect Default Permissions | CyberPersons CyberPanel | Patch this weekRansomware use; Metasploit module; EPSS 0.95 | 0.95 | ||
| 355 | CVE-2024-11680Improper Authentication | ProjectSend ProjectSend | Patch this weekMetasploit module; EPSS 0.92 | 0.92 | ||
| 356 | CVE-2024-0012Management Interface Authentication Bypass | Palo Alto Networks PAN-OS | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 357 | CVE-2024-1212OS Command Injection | Progress Kemp LoadMaster | Patch this weekMetasploit module; EPSS 0.95 | 0.95 | ||
| 358 | CVE-2024-9474Management Interface OS Command Injection | Palo Alto Networks PAN-OS | Patch this weekRansomware use; Metasploit module; EPSS 0.95 | 0.95 | ||
| 359 | CVE-2024-5910Missing Authentication | Palo Alto Networks Expedition | Patch this weekMetasploit module; EPSS 0.92 | 0.92 | ||
| 360 | CVE-2024-51567Incorrect Default Permissions | CyberPersons CyberPanel | Patch this weekRansomware use; Metasploit module; EPSS 0.87 | 0.87 | ||
| 361 | CVE-2024-47575Missing Authentication | Fortinet FortiManager | Patch this weekMetasploit module; EPSS 0.95 | 0.95 | ||
| 362 | CVE-2024-28987Hardcoded Credential | SolarWinds Web Help Desk | Patch this weekMetasploit module; EPSS 0.93 | 0.93 | ||
| 363 | CVE-2024-29824SQL Injection | Ivanti Endpoint Manager (EPM) | Patch this weekMetasploit module; EPSS 0.99 | 0.99 | ||
| 364 | CVE-2024-7593Authentication Bypass | Ivanti Virtual Traffic Manager | Patch this weekMetasploit module; EPSS 0.99 | 0.99 | ||
| 365 | CVE-2020-0618Reporting Services Remote Code Execution | Microsoft SQL Server | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 366 | CVE-2024-27348Improper Access Control | Apache HugeGraph-Server | Patch this weekMetasploit module; EPSS 0.99 | 0.99 | ||
| 367 | CVE-2024-6670SQL Injection | Progress WhatsUp Gold | Patch this weekRansomware use; Metasploit module; EPSS 0.93 | 0.93 | ||
| 368 | CVE-2024-38856Incorrect Authorization | Apache OFBiz | Patch this weekMetasploit module; EPSS 0.99 | 0.99 | ||
| 369 | CVE-2024-23897Path Traversal | Jenkins Jenkins Command Line Interface (CLI) | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 370 | CVE-2024-32113Path Traversal | Apache OFBiz | Patch this weekMetasploit module; EPSS 0.99 | 0.99 | ||
| 371 | CVE-2018-0824COM for Windows Deserialization of Untrusted Data | Microsoft Windows | Patch this weekMetasploit module; EPSS 0.73 | 0.73 | ||
| 372 | CVE-2024-28995Path Traversal | SolarWinds Serv-U | Patch this weekMetasploit module; EPSS 0.99 | 0.99 | ||
| 373 | CVE-2024-34102Improper Restriction of XML External Entity Reference (XXE) | Adobe Commerce and Magento Open Source | Patch this weekMetasploit module; EPSS 0.99 | 0.99 | ||
| 374 | CVE-2024-36401GeoTools Eval Injection | OSGeo GeoServer | Patch this weekMetasploit module; EPSS 0.99 | 0.99 | ||
| 375 | CVE-2024-23692Improper Neutralization of Special Elements Used in a Template Engine | Rejetto HTTP File Server | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 376 | CVE-2024-4358Authentication Bypass by Spoofing | Progress Telerik Report Server | Patch this weekMetasploit module; EPSS 0.97 | 0.97 | ||
| 377 | CVE-2024-4577PHP-CGI OS Command Injection | PHP Group PHP | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 378 | CVE-2024-24919Information Disclosure | Check Point Quantum Security Gateways | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 379 | CVE-2023-43208Deserialization of Untrusted Data | NextGen Healthcare Mirth Connect | Patch this weekRansomware use; Metasploit module; EPSS 0.83 | 0.83 | ||
| 380 | CVE-2023-7028Community and Enterprise Editions Improper Access Control | GitLab GitLab CE/EE | Patch this weekMetasploit module; EPSS 0.95 | 0.95 | ||
| 381 | CVE-2024-4040VFS Sandbox Escape | CrushFTP CrushFTP | Patch this weekMetasploit module; EPSS 0.99 | 0.99 | ||
| 382 | CVE-2024-3400Command Injection | Palo Alto Networks PAN-OS | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 383 | CVE-2023-24955Code Injection | Microsoft SharePoint Server | Patch this weekRansomware use; Metasploit module; EPSS 0.85 | 0.85 | ||
| 384 | CVE-2019-7256OS Command Injection | Nice Linear eMerge E3-Series | Patch this weekMetasploit module; EPSS 0.97 | 0.97 | ||
| 385 | CVE-2021-44529Code Injection | Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 386 | CVE-2023-48788SQL Injection | Fortinet FortiClient EMS | Patch this weekRansomware use; Metasploit module; EPSS 0.98 | 0.98 | ||
| 387 | CVE-2024-27198Authentication Bypass | JetBrains TeamCity | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 388 | CVE-2024-1709Authentication Bypass | ConnectWise ScreenConnect | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 389 | CVE-2024-21893Server-Side Request Forgery (SSRF) | Ivanti Connect Secure, Policy Secure, and Neurons | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 390 | CVE-2023-22527Template Injection | Atlassian Confluence Data Center and Server | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 391 | CVE-2023-29357Privilege Escalation | Microsoft SharePoint Server | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 392 | CVE-2023-46805Authentication Bypass | Ivanti Connect Secure and Policy Secure | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 393 | CVE-2024-21887Command Injection | Ivanti Connect Secure and Policy Secure | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 394 | CVE-2016-20017Command Injection | D-Link DSL-2750B Devices | Patch this weekMetasploit module; EPSS 0.64 | 0.64 | ||
| 395 | CVE-2023-27524Insecure Default Initialization of Resource | Apache Superset | Patch this weekMetasploit module; EPSS 0.97 | 0.97 | ||
| 396 | CVE-2023-49103Information Disclosure | ownCloud ownCloud graphapi | Patch this weekMetasploit module; EPSS 0.78 | 0.78 | ||
| 397 | CVE-2023-4911Buffer Overflow | GNU GNU C Library | Patch this weekMetasploit module; EPSS 0.64 | 0.64 | ||
| 398 | CVE-2023-36845EX Series and SRX Series PHP External Variable Modification | Juniper Junos OS | Patch this weekMetasploit module; EPSS 0.95 | 0.95 | ||
| 399 | CVE-2023-22518Improper Authorization | Atlassian Confluence Data Center and Server | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 400 | CVE-2023-46604Deserialization of Untrusted Data | Apache ActiveMQ | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 |