Exploited, but EPSS says unlikely
As of , 444 of the 1,734 vulnerabilities on CISA's list of exploited vulnerabilities, 26%, have an EPSS score under 0.10.
EPSS estimates the chance of exploitation activity in the next 30 days from signals across all published CVEs. CISA lists a vulnerability once it has evidence of exploitation. Where the two disagree, the evidence wins: these entries are exploited whatever their score.
| # | Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|---|
| 1 | CVE-2026-83548Server-Side Request Forgery | SonicWall SMA1000 Appliances | Patch nowForensic triage required by CISA; Metasploit module | 0.09 | ||
| 2 | CVE-2026-15409Server-Side Request Forgery | SonicWall SMA1000 Appliances | Patch nowForensic triage required by CISA; ransomware use, listed within a year; Metasploit module | 0.07 | ||
| 3 | CVE-2026-35273Missing Authentication for Critical Function | Oracle PeopleSoft Enterprise PeopleTools | Patch nowRansomware use, listed within a year | 0.09 | ||
| 4 | CVE-2026-85102Improper Certificate Validation | Check Point Multiple Products | Patch nowForensic triage required by CISA | 0.08 | ||
| 5 | CVE-2026-18556Authentication Bypass Using an Alternate Path or Channel | N-able N-central | Patch nowForensic triage required by CISA | 0.08 | ||
| 6 | CVE-2026-86060Improper Neutralization of Argument Delimiters in a Command | MikroTik RouterOS | Patch nowForensic triage required by CISA | 0.06 | ||
| 7 | CVE-2026-50751Improper Authentication | Check Point Security Gateway | Patch nowRansomware use, listed within a year | 0.06 | ||
| 8 | CVE-2025-60710Link Following | Microsoft Windows | Patch nowRansomware use, listed within a year | 0.05 | ||
| 9 | CVE-2026-75650Improper Neutralization of Special Elements Used in a Template Engine | Adobe Commerce and Magento | Patch nowForensic triage required by CISA | 0.04 | ||
| 10 | CVE-2021-27137Stack-Based Buffer Overflow | DD-WRT DD-WRT | Patch nowForensic triage required by CISA | 0.04 | ||
| 11 | CVE-2025-25249Heap-based Buffer Overflow | Fortinet Multiple Products | Patch nowForensic triage required by CISA | 0.04 | ||
| 12 | CVE-2026-50522Deserialization of Untrusted Data | Microsoft SharePoint | Patch nowForensic triage required by CISA | 0.03 | ||
| 13 | CVE-2025-39682Improper Check for Unusual or Exceptional Conditions | Linux Kernel | Patch nowForensic triage required by CISA | 0.03 | ||
| 14 | CVE-2026-45659Deserialization of Untrusted Data | Microsoft SharePoint Server | Patch nowForensic triage required by CISA; ransomware use, listed within a year | 0.03 | ||
| 15 | CVE-2026-7273Stack-Based Buffer Overflow | Zyxel GS1900 Series Switches | Patch nowForensic triage required by CISA | 0.03 | ||
| 16 | CVE-2026-59310Path Traversal | Broadcom VMware vCenter | Patch nowForensic triage required by CISA; ransomware use, listed within a year | 0.03 | ||
| 17 | CVE-2026-94127Heap-based Buffer Overflow | F5 BIG-IP APM | Patch nowForensic triage required by CISA | 0.02 | ||
| 18 | CVE-2026-104286Path Traversal | Fortinet FortiMail | Patch nowForensic triage required by CISA; listed in the last 14 days | 0.02 | ||
| 19 | CVE-2026-65660Code Injection | Microsoft SharePoint | Patch nowForensic triage required by CISA; listed in the last 14 days | 0.02 | ||
| 20 | CVE-2026-49869OS Command Injection | Kestra Kestra OSS | Patch nowForensic triage required by CISA | 0.02 | ||
| 21 | CVE-2026-76504Hex Encoding | Cisco Catalyst SD-WAN Manager | Patch nowForensic triage required by CISA; listed in the last 14 days | 0.02 | ||
| 22 | CVE-2026-65400Improper Authentication | Apple macOS | Patch nowForensic triage required by CISA | 0.02 | ||
| 23 | CVE-2026-72529Missing Authentication for Critical Function | TrueConf Server | Patch nowForensic triage required by CISA | 0.01 | ||
| 24 | CVE-2026-102489Session Fixation | Zammad GmbH Zammad | Patch nowForensic triage required by CISA; listed in the last 14 days | 0.01 | ||
| 25 | CVE-2026-48027Embedded Malicious Code | Nx Nx Console | Patch nowRansomware use, listed within a year | 0.01 | ||
| 26 | CVE-2026-88772Improper Restriction of Operations within the Bounds of a Memory Buffer | Citrix NetScaler | Patch nowForensic triage required by CISA; listed in the last 14 days | 0.01 | ||
| 27 | CVE-2026-86950Out-of-Bounds Write | Apple Multiple Products | Patch nowForensic triage required by CISA; listed in the last 14 days | 0.01 | ||
| 28 | CVE-2025-39964Race Condition | Linux Kernel | Patch nowForensic triage required by CISA | 0.01 | ||
| 29 | CVE-2026-88771Improper Input Validation | Citrix NetScaler | Patch nowForensic triage required by CISA; listed in the last 14 days | 0.01 | ||
| 30 | CVE-2026-93952Improper Input Validation | Arista VeloCloud Orchestrator | Patch nowForensic triage required by CISA | 0.01 | ||
| 31 | CVE-2026-45321Unspecified | TanStack TanStack | Patch nowRansomware use, listed within a year | 0.01 | ||
| 32 | CVE-2026-67279Improper Enforcement of Behavioral Workflow | MikroTik RouterOS | Patch nowListed in the last 14 days | 0.01 | ||
| 33 | CVE-2026-16812On-Prem OS Command Injection | Arista VeloCloud Orchestrator | Patch nowForensic triage required by CISA | 0.01 | ||
| 34 | CVE-2026-56164Missing Authentication for Critical Function | Microsoft SharePoint Server | Patch nowForensic triage required by CISA | 0.01 | ||
| 35 | CVE-2026-84869Improper Privilege Management and Missing Authorization | ConnectWise ScreenConnect | Patch nowForensic triage required by CISA | 0.01 | ||
| 36 | CVE-2026-55255Authorization Bypass Through User-Controlled Key | Langflow Langflow | Patch nowForensic triage required by CISA | 0.01 | ||
| 37 | CVE-2026-53266Out-of-Bounds Write | Linux Kernel | Patch nowForensic triage required by CISA | 0.01 | ||
| 38 | CVE-2026-46817Improper Privilege Management | Oracle E-Business Suite | Patch nowForensic triage required by CISA | 0.01 | ||
| 39 | CVE-2026-53362Unspecified | Linux Kernel | Patch nowForensic triage required by CISA | 0.01 | ||
| 40 | CVE-2026-102490Improper Privilege Management | Zammad GmbH Zammad | Patch nowForensic triage required by CISA; listed in the last 14 days | 0.01 | ||
| 41 | CVE-2026-88779Improper Restriction of Operations within the Bounds of a Memory Buffer | Citrix NetScaler | Patch nowForensic triage required by CISA; listed in the last 14 days | 0.01 | ||
| 42 | CVE-2026-5430Path Traversal | WSO2 Multiple Products | Patch nowForensic triage required by CISA; listed in the last 14 days | 0.01 | ||
| 43 | CVE-2026-58704Improper Authorization | Google Pixel | Patch nowForensic triage required by CISA | 0.01 | ||
| 44 | CVE-2026-33825Insufficient Granularity of Access Control | Microsoft Defender | Patch nowRansomware use, listed within a year | 0.00 | ||
| 45 | CVE-2026-87886Incorrect Default Permissions | Acronis Backup | Patch nowForensic triage required by CISA | 0.00 | ||
| 46 | CVE-2015-3246Race Condition | Red Hat Libuser | Patch this weekMetasploit module; verified Exploit-DB entry | 0.08 | ||
| 47 | CVE-2020-3950Privilege Escalation | VMware Multiple Products | Patch this weekMetasploit module; verified Exploit-DB entry | 0.07 | ||
| 48 | CVE-2015-5287Privilege Escalation | Red Hat Automatic Bug Reporting Tool | Patch this weekMetasploit module; verified Exploit-DB entry | 0.05 | ||
| 49 | CVE-2022-0995Out-of-Bounds Write | Linux Kernel | Patch this weekMetasploit module | 0.09 | ||
| 50 | CVE-2023-0386Improper Ownership Management | Linux Kernel | Patch this weekMetasploit module | 0.08 | ||
| 51 | CVE-2026-60137SQL Injection | WordPress Core | Patch this weekMetasploit module | 0.06 | ||
| 52 | CVE-2026-48558Authentication Bypass | SimpleHelp SimpleHelp | Patch this weekMetasploit module | 0.06 | ||
| 53 | CVE-2022-0492Improper Authentication | Linux Kernel | Patch this weekMetasploit module | 0.06 | ||
| 54 | CVE-2026-42208SQL Injection | BerriAI LiteLLM | Patch this weekMetasploit module | 0.06 | ||
| 55 | CVE-2019-18988Bypass Remote Login | TeamViewer Desktop | Patch this weekMetasploit module | 0.05 | ||
| 56 | CVE-2026-3055Out-of-Bounds Read | Citrix NetScaler | Patch this weekMetasploit module | 0.04 | ||
| 57 | CVE-2026-31431Incorrect Resource Transfer Between Spheres | Linux Kernel | Patch this weekMetasploit module | 0.03 | ||
| 58 | CVE-2020-9934Input Validation | Apple iOS, iPadOS, and macOS | Patch this weekMetasploit module | 0.03 | ||
| 59 | CVE-2019-0543Privilege Escalation | Microsoft Windows | Patch this weekRansomware use; verified Exploit-DB entry | 0.05 | ||
| 60 | CVE-2015-2291Denial-of-Service | Intel Ethernet Diagnostics Driver for Windows | Patch this weekRansomware use | 0.09 | ||
| 61 | CVE-2025-24472Authentication Bypass | Fortinet FortiOS and FortiProxy | Patch this weekRansomware use | 0.07 | ||
| 62 | CVE-2019-1388Certificate Dialog Privilege Escalation | Microsoft Windows | Patch this weekRansomware use | 0.09 | ||
| 63 | CVE-2018-19323Privilege Escalation | GIGABYTE Multiple Products | Patch this weekRansomware use | 0.08 | ||
| 64 | CVE-2012-1710Unspecified | Oracle Fusion Middleware | Patch this weekRansomware use | 0.08 | ||
| 65 | CVE-2022-24521CLFS Driver Privilege Escalation | Microsoft Windows | Patch this weekRansomware use | 0.07 | ||
| 66 | CVE-2021-38646Access Connectivity Engine Remote Code Execution | Microsoft Office | Patch this weekRansomware use | 0.08 | ||
| 67 | CVE-2019-11634Remote Code Execution | Citrix Workspace Application and Receiver for Windows | Patch this weekRansomware use | 0.08 | ||
| 68 | CVE-2019-1064AppX Deployment Service (AppXSVC) Privilege Escalation | Microsoft Windows | Patch this weekRansomware use | 0.07 | ||
| 69 | CVE-2019-1069Privilege Escalation | Microsoft Task Scheduler | Patch this weekRansomware use | 0.06 | ||
| 70 | CVE-2021-27101SQL Injection | Accellion FTA | Patch this weekRansomware use | 0.06 | ||
| 71 | CVE-2019-6693Use of Hard-Coded Credentials | Fortinet FortiOS | Patch this weekRansomware use | 0.06 | ||
| 72 | CVE-2024-30051Privilege Escalation | Microsoft DWM Core Library | Patch this weekRansomware use | 0.06 | ||
| 73 | CVE-2022-26500Remote Code Execution | Veeam Backup & Replication | Patch this weekRansomware use | 0.06 | ||
| 74 | CVE-2016-0167Privilege Escalation | Microsoft Win32k | Patch this weekRansomware use | 0.06 | ||
| 75 | CVE-2020-29574(CROS) SQL Injection | Sophos CyberoamOS | Patch this weekRansomware use | 0.05 | ||
| 76 | CVE-2013-3993Invalid Input | IBM InfoSphere BigInsights | Patch this weekRansomware use | 0.05 | ||
| 77 | CVE-2024-26169Error Reporting Service Improper Privilege Management | Microsoft Windows | Patch this weekRansomware use | 0.04 | ||
| 78 | CVE-2022-26501Remote Code Execution | Veeam Backup & Replication | Patch this weekRansomware use | 0.04 | ||
| 79 | CVE-2020-2021Authentication Bypass | Palo Alto Networks PAN-OS | Patch this weekRansomware use | 0.04 | ||
| 80 | CVE-2019-0859Privilege Escalation | Microsoft Win32k | Patch this weekRansomware use | 0.04 | ||
| 81 | CVE-2021-36955Common Log File System (CLFS) Driver Privilege Escalation | Microsoft Windows | Patch this weekRansomware use | 0.04 | ||
| 82 | CVE-2018-19320Unspecified | GIGABYTE Multiple Products | Patch this weekRansomware use | 0.04 | ||
| 83 | CVE-2018-19321Privilege Escalation | GIGABYTE Multiple Products | Patch this weekRansomware use | 0.04 | ||
| 84 | CVE-2019-1385AppX Deployment Extensions Privilege Escalation | Microsoft Windows | Patch this weekRansomware use | 0.04 | ||
| 85 | CVE-2021-27102OS Command Injection | Accellion FTA | Patch this weekRansomware use | 0.04 | ||
| 86 | CVE-2018-8405DirectX Graphics Kernel Privilege Escalation | Microsoft DirectX Graphics Kernel (DXGKRNL) | Patch this weekRansomware use | 0.03 | ||
| 87 | CVE-2018-8406DirectX Graphics Kernel Privilege Escalation | Microsoft DirectX Graphics Kernel (DXGKRNL) | Patch this weekRansomware use | 0.03 | ||
| 88 | CVE-2019-1315Error Reporting Manager Privilege Escalation | Microsoft Windows | Patch this weekRansomware use | 0.03 | ||
| 89 | CVE-2021-43226Privilege Escalation | Microsoft Windows | Patch this weekRansomware use | 0.03 | ||
| 90 | CVE-2024-11667Path Traversal | Zyxel Multiple Firewalls | Patch this weekRansomware use | 0.03 | ||
| 91 | CVE-2020-0878Memory Corruption | Microsoft Edge and Internet Explorer | Patch this weekRansomware use | 0.03 | ||
| 92 | CVE-2020-0638Privilege Escalation | Microsoft Update Notification Manager | Patch this weekRansomware use | 0.02 | ||
| 93 | CVE-2022-41073Print Spooler Privilege Escalation | Microsoft Windows | Patch this weekRansomware use | 0.02 | ||
| 94 | CVE-2022-41091Mark of the Web (MOTW) Security Feature Bypass | Microsoft Windows | Patch this weekRansomware use | 0.02 | ||
| 95 | CVE-2018-19322Code Execution | GIGABYTE Multiple Products | Patch this weekRansomware use | 0.02 | ||
| 96 | CVE-2019-1129AppX Deployment Service (AppXSVC) Privilege Escalation | Microsoft Windows | Patch this weekRansomware use | 0.02 | ||
| 97 | CVE-2019-1130AppX Deployment Service Privilege Escalation | Microsoft Windows | Patch this weekRansomware use | 0.02 | ||
| 98 | CVE-2025-22225Arbitrary Write | VMware ESXi | Patch this weekRansomware use | 0.01 | ||
| 99 | CVE-2010-4398Kernel Stack-Based Buffer Overflow | Microsoft Windows | Patch soonVerified Exploit-DB entry | 0.09 | ||
| 100 | CVE-2004-0210Privilege Escalation | Microsoft Windows | Patch soonVerified Exploit-DB entry | 0.07 |