Patch first, page 7

As of , all 1,734 vulnerabilities on CISA's list of exploited vulnerabilities, in our patch-first order: 101 to patch now.

#VulnerabilityProductOur groupListedDeadlineEPSS
601CVE-2023-0386Improper Ownership ManagementLinux KernelPatch this weekMetasploit module0.08
602CVE-2026-60137SQL InjectionWordPress CorePatch this weekMetasploit module0.06
603CVE-2026-48558Authentication BypassSimpleHelp SimpleHelpPatch this weekMetasploit module0.06
604CVE-2022-0492Improper AuthenticationLinux KernelPatch this weekMetasploit module0.06
605CVE-2026-42208SQL InjectionBerriAI LiteLLMPatch this weekMetasploit module0.06
606CVE-2019-18988Bypass Remote LoginTeamViewer DesktopPatch this weekMetasploit module0.05
607CVE-2026-3055Out-of-Bounds ReadCitrix NetScalerPatch this weekMetasploit module0.04
608CVE-2026-31431Incorrect Resource Transfer Between SpheresLinux KernelPatch this weekMetasploit module0.03
609CVE-2020-9934Input ValidationApple iOS, iPadOS, and macOSPatch this weekMetasploit module0.03
610CVE-2018-6065Integer OverflowGoogle Chromium V8Patch this weekEPSS 0.60; verified Exploit-DB entry0.60
611CVE-2018-7602Remote Code ExecutionDrupal CorePatch this weekRansomware use; EPSS 0.99; verified Exploit-DB entry0.99
612CVE-2016-0151Windows CSRSS Security Feature BypassMicrosoft Client-Server Run-time Subsystem (CSRSS)Patch this weekRansomware use; EPSS 0.63; verified Exploit-DB entry0.63
613CVE-2016-7200Memory CorruptionMicrosoft EdgePatch this weekEPSS 0.83; verified Exploit-DB entry0.83
614CVE-2016-7201Memory CorruptionMicrosoft EdgePatch this weekEPSS 0.80; verified Exploit-DB entry0.80
615CVE-2017-0037Type ConfusionMicrosoft Edge and Internet ExplorerPatch this weekEPSS 0.80; verified Exploit-DB entry0.80
616CVE-2017-0059Information DisclosureMicrosoft Internet ExplorerPatch this weekEPSS 0.62; verified Exploit-DB entry0.62
617CVE-2017-0213Privilege EscalationMicrosoft WindowsPatch this weekRansomware use; EPSS 0.84; verified Exploit-DB entry0.84
618CVE-2013-4810HP Multiple Products Remote Code ExecutionHewlett Packard (HP) ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle ManagementPatch this weekEPSS 0.79; verified Exploit-DB entry0.79
619CVE-2018-6961by VeloCloud Command InjectionVMware SD-WAN EdgePatch this weekEPSS 0.86; verified Exploit-DB entry0.86
620CVE-2019-2616BI Publisher Unauthorized AccessOracle BI Publisher (Formerly XML Publisher)Patch this weekEPSS 0.92; verified Exploit-DB entry0.92
621CVE-2019-12989SQL InjectionCitrix SD-WAN and NetScalerPatch this weekEPSS 0.95; verified Exploit-DB entry0.95
622CVE-2019-12991Command InjectionCitrix SD-WAN and NetScalerPatch this weekEPSS 0.74; verified Exploit-DB entry0.74
623CVE-2013-0625Authentication BypassAdobe ColdFusionPatch this weekEPSS 0.94; verified Exploit-DB entry0.94
624CVE-2013-0629Directory TraversalAdobe ColdFusionPatch this weekEPSS 0.66; verified Exploit-DB entry0.66
625CVE-2013-0640Memory CorruptionAdobe Reader and AcrobatPatch this weekEPSS 0.87; verified Exploit-DB entry0.87
626CVE-2015-7645Arbitrary Code ExecutionAdobe Flash PlayerPatch this weekRansomware use; EPSS 0.65; verified Exploit-DB entry0.65
627CVE-2016-5195Race ConditionLinux KernelPatch this weekEPSS 0.84; verified Exploit-DB entry0.84
628CVE-2017-8540Improper Restriction of OperationsMicrosoft Malware Protection EnginePatch this weekEPSS 0.72; verified Exploit-DB entry0.72
629CVE-2018-8298Type ConfusionChakraCore ChakraCore scripting enginePatch this weekEPSS 0.75; verified Exploit-DB entry0.75
630CVE-2014-7169Arbitrary Code ExecutionGNU Bourne-Again Shell (Bash)Patch this weekEPSS 0.99; verified Exploit-DB entry0.99
631CVE-2016-0185Media Center Remote Code ExecutionMicrosoft WindowsPatch this weekEPSS 0.70; verified Exploit-DB entry0.70
632CVE-2019-1429Scripting Engine Memory CorruptionMicrosoft Internet ExplorerPatch this weekEPSS 0.77; verified Exploit-DB entry0.77
633CVE-2018-13374Improper Access ControlFortinet FortiOS and FortiADCPatch this weekRansomware use; verified Exploit-DB entry0.38
634CVE-2016-0984Use-After-FreeAdobe Flash Player and AIRPatch this weekEPSS 0.55; verified Exploit-DB entry0.55
635CVE-2019-0543Privilege EscalationMicrosoft WindowsPatch this weekRansomware use; verified Exploit-DB entry0.05
636CVE-2026-20230Server-Side Request Forgery (SSRF)Cisco Unified Communications ManagerPatch this weekEPSS 0.880.88
637CVE-2026-20253Missing Authentication for Critical FunctionSplunk EnterprisePatch this weekEPSS 0.970.97
638CVE-2026-10520OS Command InjectionIvanti SentryPatch this weekEPSS 0.990.99
639CVE-2024-21182UnspecifiedOracle WebLogic ServerPatch this weekEPSS 0.740.74
640CVE-2025-34291Origin Validation ErrorLangflow LangflowPatch this weekEPSS 0.930.93
641CVE-2025-29635Command InjectionD-Link DIR-823XPatch this weekEPSS 0.880.88
642CVE-2026-21643SQL InjectionFortinet FortiClient EMSPatch this weekEPSS 0.940.94
643CVE-2025-54068Code InjectionLaravel LivewirePatch this weekEPSS 0.970.97
644CVE-2025-47813Information DisclosureWing FTP Server Wing FTP ServerPatch this weekEPSS 0.630.63
645CVE-2021-22054Workspace ONE Server-Side Request ForgeryOmnissa Workspace One UEMPatch this weekEPSS 0.990.99
646CVE-2026-1603Authentication BypassIvanti Endpoint Manager (EPM)Patch this weekEPSS 0.880.88
647CVE-2021-22681Insufficient Protected CredentialsRockwell Multiple ProductsPatch this weekEPSS 0.640.64
648CVE-2020-7796(ZCS) Server-Side Request ForgerySynacor Zimbra Collaboration SuitePatch this weekEPSS 0.840.84
649CVE-2026-2441CSS Use-After-FreeGoogle ChromiumPatch this weekEPSS 0.550.55
650CVE-2024-43468SQL InjectionMicrosoft Configuration ManagerPatch this weekEPSS 0.810.81
651CVE-2025-11953OS Command InjectionReact Native Community CLIPatch this weekEPSS 0.940.94
652CVE-2019-19006Improper AuthenticationSangoma FreePBXPatch this weekEPSS 0.560.56
653CVE-2026-24858Authentication Bypass Using an Alternate Path or ChannelFortinet Multiple ProductsPatch this weekEPSS 0.860.86
654CVE-2026-21509Security Feature BypassMicrosoft OfficePatch this weekEPSS 0.710.71
655CVE-2025-31125Improper Access ControlVite VitejsPatch this weekEPSS 0.650.65
656CVE-2025-34026Improper AuthenticationVersa ConcertoPatch this weekEPSS 0.820.82
657CVE-2025-8110Path TraversalGogs GogsPatch this weekEPSS 0.850.85
658CVE-2009-0556PowerPoint Code InjectionMicrosoft OfficePatch this weekEPSS 0.670.67
659CVE-2023-52163Missing AuthorizationDigiever DS-2105 ProPatch this weekEPSS 0.970.97
660CVE-2025-59718Improper Verification of Cryptographic SignatureFortinet Multiple ProductsPatch this weekEPSS 0.680.68
661CVE-2025-6218Path TraversalRARLAB WinRARPatch this weekEPSS 0.900.90
662CVE-2022-37055Buffer OverflowD-Link RoutersPatch this weekEPSS 0.560.56
663CVE-2025-61757Missing Authentication for Critical FunctionOracle Fusion MiddlewarePatch this weekEPSS 0.890.89
664CVE-2025-9242Out-of-Bounds WriteWatchGuard FireboxPatch this weekEPSS 0.910.91
665CVE-2025-12480Improper Access ControlGladinet TriofoxPatch this weekEPSS 0.950.95
666CVE-2025-48703OS Command InjectionCWP Control Web PanelPatch this weekEPSS 0.990.99
667CVE-2025-6204Code InjectionDassault Systèmes DELMIA AprisoPatch this weekEPSS 0.790.79
668CVE-2025-6205Missing AuthorizationDassault Systèmes DELMIA AprisoPatch this weekEPSS 0.740.74
669CVE-2025-2746Authentication Bypass Using an Alternate Path or ChannelKentico Xperience CMSPatch this weekEPSS 0.730.73
670CVE-2025-2747Authentication Bypass Using an Alternate Path or ChannelKentico Xperience CMSPatch this weekEPSS 0.970.97
671CVE-2025-33073SMB Client Improper Access ControlMicrosoft WindowsPatch this weekEPSS 0.830.83
672CVE-2025-54253Experience Manager Forms Code ExecutionAdobe Experience Manager (AEM) FormsPatch this weekEPSS 0.880.88
673CVE-2025-4008Command InjectionSmartbedded MeteobridgePatch this weekEPSS 0.940.94
674CVE-2021-21311Server-Side Request ForgeryAdminer AdminerPatch this weekEPSS 0.980.98
675CVE-2025-10035Deserialization of Untrusted DataFortra GoAnywhere MFTPatch this weekRansomware use; EPSS 0.990.99
676CVE-2025-20333Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Buffer OverflowCisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat DefensePatch this weekEPSS 0.710.71
677CVE-2025-20362Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Missing AuthorizationCisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat DefensePatch this weekEPSS 0.870.87
678CVE-2025-5086Deserialization of Untrusted DataDassault Systèmes DELMIA AprisoPatch this weekEPSS 0.970.97
679CVE-2025-8088Path TraversalRARLAB WinRARPatch this weekRansomware use; EPSS 0.940.94
680CVE-2020-25078UnspecifiedD-Link DCS-2530L and DCS-2670L DevicesPatch this weekEPSS 0.980.98
681CVE-2025-20281InjectionCisco Identity Services EnginePatch this weekEPSS 0.980.98
682CVE-2025-20337InjectionCisco Identity Services EnginePatch this weekEPSS 0.680.68
683CVE-2025-2776Improper Restriction of XML External Entity ReferenceSysAid SysAid On-PremPatch this weekEPSS 0.650.65
684CVE-2025-54309Unprotected Alternate ChannelCrushFTP CrushFTPPatch this weekEPSS 0.950.95
685CVE-2025-25257SQL InjectionFortinet FortiWebPatch this weekEPSS 0.990.99
686CVE-2025-5777Out-of-Bounds ReadCitrix NetScaler ADC and GatewayPatch this weekRansomware use; EPSS 0.990.99
687CVE-2024-0769Path TraversalD-Link DIR-859 RouterPatch this weekEPSS 0.830.83
688CVE-2024-54085Authentication Bypass by SpoofingAMI MegaRAC SPxPatch this weekEPSS 0.610.61
689CVE-2024-42009Cross-Site ScriptingRoundcube WebmailPatch this weekEPSS 0.830.83
690CVE-2021-32030Improper AuthenticationASUS RoutersPatch this weekEPSS 0.990.99
691CVE-2023-38950Path TraversalZKTeco BioTimePatch this weekEPSS 0.920.92
692CVE-2024-12987OS Command InjectionDrayTek Vigor RoutersPatch this weekEPSS 0.980.98
693CVE-2024-58136Improper Protection of Alternate PathYiiframework YiiPatch this weekEPSS 0.880.88
694CVE-2025-34028Path TraversalCommvault Command CenterPatch this weekEPSS 0.980.98
695CVE-2023-44221OS Command InjectionSonicWall SMA100 AppliancesPatch this weekEPSS 0.760.76
696CVE-2024-38475Improper Escaping of OutputApache HTTP ServerPatch this weekEPSS 0.990.99
697CVE-2025-31324Unrestricted File UploadSAP NetWeaverPatch this weekRansomware use; EPSS 0.990.99
698CVE-2025-24054NTLM Hash Disclosure SpoofingMicrosoft WindowsPatch this weekEPSS 0.590.59
699CVE-2025-31161Authentication BypassCrushFTP CrushFTPPatch this weekRansomware use; EPSS 0.990.99
700CVE-2024-20439Static CredentialCisco Smart Licensing UtilityPatch this weekEPSS 0.970.97