Used in ransomware
As of , 361 vulnerabilities on CISA's list are known to be used in ransomware campaigns.
| # | Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|---|
| 1 | CVE-2026-63077Deserialization of Untrusted Data | JetBrains TeamCity | Patch nowForensic triage required by CISA; ransomware use, listed within a year; Metasploit module | 0.90 | ||
| 2 | CVE-2026-41940Missing Authentication for Critical Function | WebPros cPanel & WHM and WP2 (WordPress Squared) | Patch nowRansomware use, listed within a year; Metasploit module | 0.99 | ||
| 3 | CVE-2024-1708Path Traversal | ConnectWise ScreenConnect | Patch nowRansomware use, listed within a year; Metasploit module | 0.95 | ||
| 4 | CVE-2026-1731OS Command Injection | BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) | Patch nowRansomware use, listed within a year; Metasploit module | 0.91 | ||
| 5 | CVE-2025-52691Unrestricted Upload of File with Dangerous Type | SmarterTools SmarterMail | Patch nowRansomware use, listed within a year; Metasploit module | 0.86 | ||
| 6 | CVE-2025-55182Remote Code Execution | Meta React Server Components | Patch nowRansomware use, listed within a year; Metasploit module | 0.99 | ||
| 7 | CVE-2026-15409Server-Side Request Forgery | SonicWall SMA1000 Appliances | Patch nowForensic triage required by CISA; ransomware use, listed within a year; Metasploit module | 0.07 | ||
| 8 | CVE-2026-0257Authentication Bypass | Palo Alto Networks PAN-OS | Patch nowRansomware use, listed within a year | 0.97 | ||
| 9 | CVE-2024-57726Missing Authorization | SimpleHelp SimpleHelp | Patch nowRansomware use, listed within a year | 0.67 | ||
| 10 | CVE-2024-57728Path Traversal | SimpleHelp SimpleHelp | Patch nowRansomware use, listed within a year | 0.65 | ||
| 11 | CVE-2023-27351Improper Authentication | PaperCut NG/MF | Patch nowRansomware use, listed within a year | 0.78 | ||
| 12 | CVE-2024-27199Relative Path Traversal | JetBrains TeamCity | Patch nowRansomware use, listed within a year | 0.99 | ||
| 13 | CVE-2023-21529Deserialization of Untrusted Data | Microsoft Exchange Server | Patch nowRansomware use, listed within a year | 0.59 | ||
| 14 | CVE-2025-26399Deserialization of Untrusted Data | SolarWinds Web Help Desk | Patch nowRansomware use, listed within a year | 0.90 | ||
| 15 | CVE-2026-24423Missing Authentication for Critical Function | SmarterTools SmarterMail | Patch nowRansomware use, listed within a year | 0.88 | ||
| 16 | CVE-2026-23760Authentication Bypass Using an Alternate Path or Channel | SmarterTools SmarterMail | Patch nowRansomware use, listed within a year | 0.97 | ||
| 17 | CVE-2025-61884Server-Side Request Forgery (SSRF) | Oracle E-Business Suite | Patch nowRansomware use, listed within a year | 0.96 | ||
| 18 | CVE-2026-20316Secure Firewall Management Center Use of Hard-coded Password | Cisco Secure Firewall Management Center (FMC) | Patch nowRansomware use, listed within a year | 0.35 | ||
| 19 | CVE-2026-12569Improper Input Validation | PTC Windchill and FlexPLM | Patch nowRansomware use, listed within a year | 0.46 | ||
| 20 | CVE-2026-20131Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data | Cisco Secure Firewall Management Center (FMC) | Patch nowRansomware use, listed within a year | 0.43 | ||
| 21 | CVE-2025-14733Out of Bounds Write | WatchGuard Firebox | Patch nowRansomware use, listed within a year | 0.27 | ||
| 22 | CVE-2026-15410Code Injection | SonicWall SMA1000 Appliances | Patch nowForensic triage required by CISA; ransomware use, listed within a year | 0.12 | ||
| 23 | CVE-2026-35273Missing Authentication for Critical Function | Oracle PeopleSoft Enterprise PeopleTools | Patch nowRansomware use, listed within a year | 0.09 | ||
| 24 | CVE-2026-50751Improper Authentication | Check Point Security Gateway | Patch nowRansomware use, listed within a year | 0.06 | ||
| 25 | CVE-2025-60710Link Following | Microsoft Windows | Patch nowRansomware use, listed within a year | 0.05 | ||
| 26 | CVE-2026-45659Deserialization of Untrusted Data | Microsoft SharePoint Server | Patch nowForensic triage required by CISA; ransomware use, listed within a year | 0.03 | ||
| 27 | CVE-2026-59310Path Traversal | Broadcom VMware vCenter | Patch nowForensic triage required by CISA; ransomware use, listed within a year | 0.03 | ||
| 28 | CVE-2026-48027Embedded Malicious Code | Nx Nx Console | Patch nowRansomware use, listed within a year | 0.01 | ||
| 29 | CVE-2026-45321Unspecified | TanStack TanStack | Patch nowRansomware use, listed within a year | 0.01 | ||
| 30 | CVE-2026-33825Insufficient Granularity of Access Control | Microsoft Defender | Patch nowRansomware use, listed within a year | 0.00 | ||
| 31 | CVE-2017-7494Remote Code Execution | Samba Samba | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 32 | CVE-2010-0738Authentication Bypass | Red Hat JBoss | Patch this weekRansomware use; Metasploit module; EPSS 0.80; verified Exploit-DB entry | 0.80 | ||
| 33 | CVE-2013-0074Double Dereference | Microsoft Silverlight | Patch this weekRansomware use; Metasploit module; EPSS 0.79; verified Exploit-DB entry | 0.79 | ||
| 34 | CVE-2013-0422JRE Remote Code Execution | Oracle Java Runtime Environment (JRE) | Patch this weekRansomware use; Metasploit module; EPSS 0.97; verified Exploit-DB entry | 0.97 | ||
| 35 | CVE-2013-0431JRE Sandbox Bypass | Oracle Java Runtime Environment (JRE) | Patch this weekRansomware use; Metasploit module; EPSS 0.90; verified Exploit-DB entry | 0.90 | ||
| 36 | CVE-2017-0147Windows SMBv1 Information Disclosure | Microsoft SMBv1 server | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 37 | CVE-2017-0148Remote Code Execution | Microsoft SMBv1 server | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 38 | CVE-2013-2465Unspecified | Oracle Java SE | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 39 | CVE-2013-2551Use-After-Free | Microsoft Internet Explorer | Patch this weekRansomware use; Metasploit module; EPSS 0.74; verified Exploit-DB entry | 0.74 | ||
| 40 | CVE-2010-2861Directory Traversal | Adobe ColdFusion | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 41 | CVE-2017-0146SMB Remote Code Execution | Microsoft Windows | Patch this weekRansomware use; Metasploit module; EPSS 0.90; verified Exploit-DB entry | 0.90 | ||
| 42 | CVE-2018-11138Remote Command Execution | Quest KACE System Management Appliance | Patch this weekRansomware use; Metasploit module; EPSS 0.92; verified Exploit-DB entry | 0.92 | ||
| 43 | CVE-2019-11043Buffer Overflow | PHP FastCGI Process Manager (FPM) | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 44 | CVE-2019-15107Command Injection | Webmin Webmin | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 45 | CVE-2018-8120Privilege Escalation | Microsoft Win32k | Patch this weekRansomware use; Metasploit module; EPSS 0.73; verified Exploit-DB entry | 0.73 | ||
| 46 | CVE-2009-3960Information Disclosure | Adobe BlazeDS | Patch this weekRansomware use; Metasploit module; EPSS 0.90; verified Exploit-DB entry | 0.90 | ||
| 47 | CVE-2008-2992Reader and Acrobat Input Validation | Adobe Acrobat and Reader | Patch this weekRansomware use; Metasploit module; EPSS 0.98; verified Exploit-DB entry | 0.98 | ||
| 48 | CVE-2010-0188Arbitrary Code Execution | Adobe Reader and Acrobat | Patch this weekRansomware use; Metasploit module; EPSS 0.88; verified Exploit-DB entry | 0.88 | ||
| 49 | CVE-2012-0507Runtime Environment (JRE) Arbitrary Code Execution | Oracle Java SE | Patch this weekRansomware use; Metasploit module; EPSS 0.98; verified Exploit-DB entry | 0.98 | ||
| 50 | CVE-2012-1723Runtime Environment (JRE) Arbitrary Code Execution | Oracle Java SE | Patch this weekRansomware use; Metasploit module; EPSS 0.94; verified Exploit-DB entry | 0.94 | ||
| 51 | CVE-2012-4681Runtime Environment (JRE) Arbitrary Code Execution | Oracle Java SE | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 52 | CVE-2015-1701Privilege Escalation | Microsoft Win32k | Patch this weekRansomware use; Metasploit module; EPSS 0.56; verified Exploit-DB entry | 0.56 | ||
| 53 | CVE-2016-4117Arbitrary Code Execution | Adobe Flash Player | Patch this weekRansomware use; Metasploit module; EPSS 0.94; verified Exploit-DB entry | 0.94 | ||
| 54 | CVE-2018-20250Absolute Path Traversal | RARLAB WinRAR | Patch this weekRansomware use; Metasploit module; EPSS 0.96; verified Exploit-DB entry | 0.96 | ||
| 55 | CVE-2017-0144Remote Code Execution | Microsoft SMBv1 | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 56 | CVE-2017-0145Remote Code Execution | Microsoft SMBv1 | Patch this weekRansomware use; Metasploit module; EPSS 0.90; verified Exploit-DB entry | 0.90 | ||
| 57 | CVE-2017-10271Corporation WebLogic Server Remote Code Execution | Oracle WebLogic Server | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 58 | CVE-2018-8453Privilege Escalation | Microsoft Win32k | Patch this weekRansomware use; Metasploit module; EPSS 0.70; verified Exploit-DB entry | 0.70 | ||
| 59 | CVE-2019-2725WebLogic Server, Injection | Oracle WebLogic Server | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 60 | CVE-2012-0158Remote Code Execution | Microsoft MSCOMCTL.OCX | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 61 | CVE-2017-0143Server Message Block (SMBv1) Remote Code Execution | Microsoft Windows | Patch this weekRansomware use; Metasploit module; EPSS 0.93; verified Exploit-DB entry | 0.93 | ||
| 62 | CVE-2017-0199Remote Code Execution | Microsoft Office and WordPad | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 63 | CVE-2017-5638Remote Code Execution | Apache Struts | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 64 | CVE-2017-9822Remote Code Execution | DotNetNuke (DNN) DotNetNuke (DNN) | Patch this weekRansomware use; Metasploit module; EPSS 0.95; verified Exploit-DB entry | 0.95 | ||
| 65 | CVE-2018-7600Remote Code Execution | Drupal Drupal Core | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 66 | CVE-2019-0708Remote Code Execution | Microsoft Remote Desktop Services | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 67 | CVE-2019-3396Confluence Server and Data Center Server-Side Template Injection | Atlassian Confluence Server and Data Server | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 68 | CVE-2019-11539Pulse Connect Secure and Policy Secure Command Injection | Ivanti Pulse Connect Secure and Pulse Policy Secure | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 69 | CVE-2020-0688Validation Key Remote Code Execution | Microsoft Exchange Server | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 70 | CVE-2021-41773Path Traversal | Apache HTTP Server | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 71 | CVE-2021-42013Path Traversal | Apache HTTP Server | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 72 | CVE-2019-0841AppX Deployment Service (AppXSVC) Privilege Escalation | Microsoft Windows | Patch this weekRansomware use; Metasploit module; verified Exploit-DB entry | 0.41 | ||
| 73 | CVE-2019-1405Universal Plug and Play (UPnP) Service Privilege Escalation | Microsoft Windows | Patch this weekRansomware use; Metasploit module; verified Exploit-DB entry | 0.30 | ||
| 74 | CVE-2016-0099Secondary Logon Service Privilege Escalation | Microsoft Windows | Patch this weekRansomware use; Metasploit module; verified Exploit-DB entry | 0.37 | ||
| 75 | CVE-2019-1322Privilege Escalation | Microsoft Windows | Patch this weekRansomware use; Metasploit module; verified Exploit-DB entry | 0.19 | ||
| 76 | CVE-2025-61882Unspecified | Oracle E-Business Suite | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 77 | CVE-2025-49704Code Injection | Microsoft SharePoint | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 78 | CVE-2025-49706Improper Authentication | Microsoft SharePoint | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 79 | CVE-2025-53770Deserialization of Untrusted Data | Microsoft SharePoint | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 80 | CVE-2025-3248Missing Authentication | Langflow Langflow | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 81 | CVE-2025-22457Stack-Based Buffer Overflow | Ivanti Connect Secure, Policy Secure, and ZTA Gateways | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 82 | CVE-2024-57727Path Traversal | SimpleHelp SimpleHelp | Patch this weekRansomware use; Metasploit module; EPSS 0.97 | 0.97 | ||
| 83 | CVE-2024-55956Unauthenticated File Upload | Cleo Multiple Products | Patch this weekRansomware use; Metasploit module; EPSS 0.94 | 0.94 | ||
| 84 | CVE-2024-51378Incorrect Default Permissions | CyberPersons CyberPanel | Patch this weekRansomware use; Metasploit module; EPSS 0.95 | 0.95 | ||
| 85 | CVE-2024-0012Management Interface Authentication Bypass | Palo Alto Networks PAN-OS | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 86 | CVE-2024-9474Management Interface OS Command Injection | Palo Alto Networks PAN-OS | Patch this weekRansomware use; Metasploit module; EPSS 0.95 | 0.95 | ||
| 87 | CVE-2024-51567Incorrect Default Permissions | CyberPersons CyberPanel | Patch this weekRansomware use; Metasploit module; EPSS 0.87 | 0.87 | ||
| 88 | CVE-2020-0618Reporting Services Remote Code Execution | Microsoft SQL Server | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 89 | CVE-2024-6670SQL Injection | Progress WhatsUp Gold | Patch this weekRansomware use; Metasploit module; EPSS 0.93 | 0.93 | ||
| 90 | CVE-2024-23897Path Traversal | Jenkins Jenkins Command Line Interface (CLI) | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 91 | CVE-2024-23692Improper Neutralization of Special Elements Used in a Template Engine | Rejetto HTTP File Server | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 92 | CVE-2024-4577PHP-CGI OS Command Injection | PHP Group PHP | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 93 | CVE-2024-24919Information Disclosure | Check Point Quantum Security Gateways | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 94 | CVE-2023-43208Deserialization of Untrusted Data | NextGen Healthcare Mirth Connect | Patch this weekRansomware use; Metasploit module; EPSS 0.83 | 0.83 | ||
| 95 | CVE-2024-3400Command Injection | Palo Alto Networks PAN-OS | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 96 | CVE-2023-24955Code Injection | Microsoft SharePoint Server | Patch this weekRansomware use; Metasploit module; EPSS 0.85 | 0.85 | ||
| 97 | CVE-2021-44529Code Injection | Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 98 | CVE-2023-48788SQL Injection | Fortinet FortiClient EMS | Patch this weekRansomware use; Metasploit module; EPSS 0.98 | 0.98 | ||
| 99 | CVE-2024-27198Authentication Bypass | JetBrains TeamCity | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 100 | CVE-2024-1709Authentication Bypass | ConnectWise ScreenConnect | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 |
Ransomware use changed to Known
CISA changes this flag without saying so; these are the changes our record has seen, newest first.
- CVE-2026-1731 BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)Ransomware use: Unknown to Known.