Patch first, page 7
As of , all 1,734 vulnerabilities on CISA's list of exploited vulnerabilities, in our patch-first order: 101 to patch now.
| # | Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|---|
| 601 | CVE-2023-0386Improper Ownership Management | Linux Kernel | Patch this weekMetasploit module | 0.08 | ||
| 602 | CVE-2026-60137SQL Injection | WordPress Core | Patch this weekMetasploit module | 0.06 | ||
| 603 | CVE-2026-48558Authentication Bypass | SimpleHelp SimpleHelp | Patch this weekMetasploit module | 0.06 | ||
| 604 | CVE-2022-0492Improper Authentication | Linux Kernel | Patch this weekMetasploit module | 0.06 | ||
| 605 | CVE-2026-42208SQL Injection | BerriAI LiteLLM | Patch this weekMetasploit module | 0.06 | ||
| 606 | CVE-2019-18988Bypass Remote Login | TeamViewer Desktop | Patch this weekMetasploit module | 0.05 | ||
| 607 | CVE-2026-3055Out-of-Bounds Read | Citrix NetScaler | Patch this weekMetasploit module | 0.04 | ||
| 608 | CVE-2026-31431Incorrect Resource Transfer Between Spheres | Linux Kernel | Patch this weekMetasploit module | 0.03 | ||
| 609 | CVE-2020-9934Input Validation | Apple iOS, iPadOS, and macOS | Patch this weekMetasploit module | 0.03 | ||
| 610 | CVE-2018-6065Integer Overflow | Google Chromium V8 | Patch this weekEPSS 0.60; verified Exploit-DB entry | 0.60 | ||
| 611 | CVE-2018-7602Remote Code Execution | Drupal Core | Patch this weekRansomware use; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 612 | CVE-2016-0151Windows CSRSS Security Feature Bypass | Microsoft Client-Server Run-time Subsystem (CSRSS) | Patch this weekRansomware use; EPSS 0.63; verified Exploit-DB entry | 0.63 | ||
| 613 | CVE-2016-7200Memory Corruption | Microsoft Edge | Patch this weekEPSS 0.83; verified Exploit-DB entry | 0.83 | ||
| 614 | CVE-2016-7201Memory Corruption | Microsoft Edge | Patch this weekEPSS 0.80; verified Exploit-DB entry | 0.80 | ||
| 615 | CVE-2017-0037Type Confusion | Microsoft Edge and Internet Explorer | Patch this weekEPSS 0.80; verified Exploit-DB entry | 0.80 | ||
| 616 | CVE-2017-0059Information Disclosure | Microsoft Internet Explorer | Patch this weekEPSS 0.62; verified Exploit-DB entry | 0.62 | ||
| 617 | CVE-2017-0213Privilege Escalation | Microsoft Windows | Patch this weekRansomware use; EPSS 0.84; verified Exploit-DB entry | 0.84 | ||
| 618 | CVE-2013-4810HP Multiple Products Remote Code Execution | Hewlett Packard (HP) ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management | Patch this weekEPSS 0.79; verified Exploit-DB entry | 0.79 | ||
| 619 | CVE-2018-6961by VeloCloud Command Injection | VMware SD-WAN Edge | Patch this weekEPSS 0.86; verified Exploit-DB entry | 0.86 | ||
| 620 | CVE-2019-2616BI Publisher Unauthorized Access | Oracle BI Publisher (Formerly XML Publisher) | Patch this weekEPSS 0.92; verified Exploit-DB entry | 0.92 | ||
| 621 | CVE-2019-12989SQL Injection | Citrix SD-WAN and NetScaler | Patch this weekEPSS 0.95; verified Exploit-DB entry | 0.95 | ||
| 622 | CVE-2019-12991Command Injection | Citrix SD-WAN and NetScaler | Patch this weekEPSS 0.74; verified Exploit-DB entry | 0.74 | ||
| 623 | CVE-2013-0625Authentication Bypass | Adobe ColdFusion | Patch this weekEPSS 0.94; verified Exploit-DB entry | 0.94 | ||
| 624 | CVE-2013-0629Directory Traversal | Adobe ColdFusion | Patch this weekEPSS 0.66; verified Exploit-DB entry | 0.66 | ||
| 625 | CVE-2013-0640Memory Corruption | Adobe Reader and Acrobat | Patch this weekEPSS 0.87; verified Exploit-DB entry | 0.87 | ||
| 626 | CVE-2015-7645Arbitrary Code Execution | Adobe Flash Player | Patch this weekRansomware use; EPSS 0.65; verified Exploit-DB entry | 0.65 | ||
| 627 | CVE-2016-5195Race Condition | Linux Kernel | Patch this weekEPSS 0.84; verified Exploit-DB entry | 0.84 | ||
| 628 | CVE-2017-8540Improper Restriction of Operations | Microsoft Malware Protection Engine | Patch this weekEPSS 0.72; verified Exploit-DB entry | 0.72 | ||
| 629 | CVE-2018-8298Type Confusion | ChakraCore ChakraCore scripting engine | Patch this weekEPSS 0.75; verified Exploit-DB entry | 0.75 | ||
| 630 | CVE-2014-7169Arbitrary Code Execution | GNU Bourne-Again Shell (Bash) | Patch this weekEPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 631 | CVE-2016-0185Media Center Remote Code Execution | Microsoft Windows | Patch this weekEPSS 0.70; verified Exploit-DB entry | 0.70 | ||
| 632 | CVE-2019-1429Scripting Engine Memory Corruption | Microsoft Internet Explorer | Patch this weekEPSS 0.77; verified Exploit-DB entry | 0.77 | ||
| 633 | CVE-2018-13374Improper Access Control | Fortinet FortiOS and FortiADC | Patch this weekRansomware use; verified Exploit-DB entry | 0.38 | ||
| 634 | CVE-2016-0984Use-After-Free | Adobe Flash Player and AIR | Patch this weekEPSS 0.55; verified Exploit-DB entry | 0.55 | ||
| 635 | CVE-2019-0543Privilege Escalation | Microsoft Windows | Patch this weekRansomware use; verified Exploit-DB entry | 0.05 | ||
| 636 | CVE-2026-20230Server-Side Request Forgery (SSRF) | Cisco Unified Communications Manager | Patch this weekEPSS 0.88 | 0.88 | ||
| 637 | CVE-2026-20253Missing Authentication for Critical Function | Splunk Enterprise | Patch this weekEPSS 0.97 | 0.97 | ||
| 638 | CVE-2026-10520OS Command Injection | Ivanti Sentry | Patch this weekEPSS 0.99 | 0.99 | ||
| 639 | CVE-2024-21182Unspecified | Oracle WebLogic Server | Patch this weekEPSS 0.74 | 0.74 | ||
| 640 | CVE-2025-34291Origin Validation Error | Langflow Langflow | Patch this weekEPSS 0.93 | 0.93 | ||
| 641 | CVE-2025-29635Command Injection | D-Link DIR-823X | Patch this weekEPSS 0.88 | 0.88 | ||
| 642 | CVE-2026-21643SQL Injection | Fortinet FortiClient EMS | Patch this weekEPSS 0.94 | 0.94 | ||
| 643 | CVE-2025-54068Code Injection | Laravel Livewire | Patch this weekEPSS 0.97 | 0.97 | ||
| 644 | CVE-2025-47813Information Disclosure | Wing FTP Server Wing FTP Server | Patch this weekEPSS 0.63 | 0.63 | ||
| 645 | CVE-2021-22054Workspace ONE Server-Side Request Forgery | Omnissa Workspace One UEM | Patch this weekEPSS 0.99 | 0.99 | ||
| 646 | CVE-2026-1603Authentication Bypass | Ivanti Endpoint Manager (EPM) | Patch this weekEPSS 0.88 | 0.88 | ||
| 647 | CVE-2021-22681Insufficient Protected Credentials | Rockwell Multiple Products | Patch this weekEPSS 0.64 | 0.64 | ||
| 648 | CVE-2020-7796(ZCS) Server-Side Request Forgery | Synacor Zimbra Collaboration Suite | Patch this weekEPSS 0.84 | 0.84 | ||
| 649 | CVE-2026-2441CSS Use-After-Free | Google Chromium | Patch this weekEPSS 0.55 | 0.55 | ||
| 650 | CVE-2024-43468SQL Injection | Microsoft Configuration Manager | Patch this weekEPSS 0.81 | 0.81 | ||
| 651 | CVE-2025-11953OS Command Injection | React Native Community CLI | Patch this weekEPSS 0.94 | 0.94 | ||
| 652 | CVE-2019-19006Improper Authentication | Sangoma FreePBX | Patch this weekEPSS 0.56 | 0.56 | ||
| 653 | CVE-2026-24858Authentication Bypass Using an Alternate Path or Channel | Fortinet Multiple Products | Patch this weekEPSS 0.86 | 0.86 | ||
| 654 | CVE-2026-21509Security Feature Bypass | Microsoft Office | Patch this weekEPSS 0.71 | 0.71 | ||
| 655 | CVE-2025-31125Improper Access Control | Vite Vitejs | Patch this weekEPSS 0.65 | 0.65 | ||
| 656 | CVE-2025-34026Improper Authentication | Versa Concerto | Patch this weekEPSS 0.82 | 0.82 | ||
| 657 | CVE-2025-8110Path Traversal | Gogs Gogs | Patch this weekEPSS 0.85 | 0.85 | ||
| 658 | CVE-2009-0556PowerPoint Code Injection | Microsoft Office | Patch this weekEPSS 0.67 | 0.67 | ||
| 659 | CVE-2023-52163Missing Authorization | Digiever DS-2105 Pro | Patch this weekEPSS 0.97 | 0.97 | ||
| 660 | CVE-2025-59718Improper Verification of Cryptographic Signature | Fortinet Multiple Products | Patch this weekEPSS 0.68 | 0.68 | ||
| 661 | CVE-2025-6218Path Traversal | RARLAB WinRAR | Patch this weekEPSS 0.90 | 0.90 | ||
| 662 | CVE-2022-37055Buffer Overflow | D-Link Routers | Patch this weekEPSS 0.56 | 0.56 | ||
| 663 | CVE-2025-61757Missing Authentication for Critical Function | Oracle Fusion Middleware | Patch this weekEPSS 0.89 | 0.89 | ||
| 664 | CVE-2025-9242Out-of-Bounds Write | WatchGuard Firebox | Patch this weekEPSS 0.91 | 0.91 | ||
| 665 | CVE-2025-12480Improper Access Control | Gladinet Triofox | Patch this weekEPSS 0.95 | 0.95 | ||
| 666 | CVE-2025-48703OS Command Injection | CWP Control Web Panel | Patch this weekEPSS 0.99 | 0.99 | ||
| 667 | CVE-2025-6204Code Injection | Dassault Systèmes DELMIA Apriso | Patch this weekEPSS 0.79 | 0.79 | ||
| 668 | CVE-2025-6205Missing Authorization | Dassault Systèmes DELMIA Apriso | Patch this weekEPSS 0.74 | 0.74 | ||
| 669 | CVE-2025-2746Authentication Bypass Using an Alternate Path or Channel | Kentico Xperience CMS | Patch this weekEPSS 0.73 | 0.73 | ||
| 670 | CVE-2025-2747Authentication Bypass Using an Alternate Path or Channel | Kentico Xperience CMS | Patch this weekEPSS 0.97 | 0.97 | ||
| 671 | CVE-2025-33073SMB Client Improper Access Control | Microsoft Windows | Patch this weekEPSS 0.83 | 0.83 | ||
| 672 | CVE-2025-54253Experience Manager Forms Code Execution | Adobe Experience Manager (AEM) Forms | Patch this weekEPSS 0.88 | 0.88 | ||
| 673 | CVE-2025-4008Command Injection | Smartbedded Meteobridge | Patch this weekEPSS 0.94 | 0.94 | ||
| 674 | CVE-2021-21311Server-Side Request Forgery | Adminer Adminer | Patch this weekEPSS 0.98 | 0.98 | ||
| 675 | CVE-2025-10035Deserialization of Untrusted Data | Fortra GoAnywhere MFT | Patch this weekRansomware use; EPSS 0.99 | 0.99 | ||
| 676 | CVE-2025-20333Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Buffer Overflow | Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense | Patch this weekEPSS 0.71 | 0.71 | ||
| 677 | CVE-2025-20362Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Missing Authorization | Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense | Patch this weekEPSS 0.87 | 0.87 | ||
| 678 | CVE-2025-5086Deserialization of Untrusted Data | Dassault Systèmes DELMIA Apriso | Patch this weekEPSS 0.97 | 0.97 | ||
| 679 | CVE-2025-8088Path Traversal | RARLAB WinRAR | Patch this weekRansomware use; EPSS 0.94 | 0.94 | ||
| 680 | CVE-2020-25078Unspecified | D-Link DCS-2530L and DCS-2670L Devices | Patch this weekEPSS 0.98 | 0.98 | ||
| 681 | CVE-2025-20281Injection | Cisco Identity Services Engine | Patch this weekEPSS 0.98 | 0.98 | ||
| 682 | CVE-2025-20337Injection | Cisco Identity Services Engine | Patch this weekEPSS 0.68 | 0.68 | ||
| 683 | CVE-2025-2776Improper Restriction of XML External Entity Reference | SysAid SysAid On-Prem | Patch this weekEPSS 0.65 | 0.65 | ||
| 684 | CVE-2025-54309Unprotected Alternate Channel | CrushFTP CrushFTP | Patch this weekEPSS 0.95 | 0.95 | ||
| 685 | CVE-2025-25257SQL Injection | Fortinet FortiWeb | Patch this weekEPSS 0.99 | 0.99 | ||
| 686 | CVE-2025-5777Out-of-Bounds Read | Citrix NetScaler ADC and Gateway | Patch this weekRansomware use; EPSS 0.99 | 0.99 | ||
| 687 | CVE-2024-0769Path Traversal | D-Link DIR-859 Router | Patch this weekEPSS 0.83 | 0.83 | ||
| 688 | CVE-2024-54085Authentication Bypass by Spoofing | AMI MegaRAC SPx | Patch this weekEPSS 0.61 | 0.61 | ||
| 689 | CVE-2024-42009Cross-Site Scripting | Roundcube Webmail | Patch this weekEPSS 0.83 | 0.83 | ||
| 690 | CVE-2021-32030Improper Authentication | ASUS Routers | Patch this weekEPSS 0.99 | 0.99 | ||
| 691 | CVE-2023-38950Path Traversal | ZKTeco BioTime | Patch this weekEPSS 0.92 | 0.92 | ||
| 692 | CVE-2024-12987OS Command Injection | DrayTek Vigor Routers | Patch this weekEPSS 0.98 | 0.98 | ||
| 693 | CVE-2024-58136Improper Protection of Alternate Path | Yiiframework Yii | Patch this weekEPSS 0.88 | 0.88 | ||
| 694 | CVE-2025-34028Path Traversal | Commvault Command Center | Patch this weekEPSS 0.98 | 0.98 | ||
| 695 | CVE-2023-44221OS Command Injection | SonicWall SMA100 Appliances | Patch this weekEPSS 0.76 | 0.76 | ||
| 696 | CVE-2024-38475Improper Escaping of Output | Apache HTTP Server | Patch this weekEPSS 0.99 | 0.99 | ||
| 697 | CVE-2025-31324Unrestricted File Upload | SAP NetWeaver | Patch this weekRansomware use; EPSS 0.99 | 0.99 | ||
| 698 | CVE-2025-24054NTLM Hash Disclosure Spoofing | Microsoft Windows | Patch this weekEPSS 0.59 | 0.59 | ||
| 699 | CVE-2025-31161Authentication Bypass | CrushFTP CrushFTP | Patch this weekRansomware use; EPSS 0.99 | 0.99 | ||
| 700 | CVE-2024-20439Static Credential | Cisco Smart Licensing Utility | Patch this weekEPSS 0.97 | 0.97 |