Exploited, but EPSS says unlikely

As of , 444 of the 1,734 vulnerabilities on CISA's list of exploited vulnerabilities, 26%, have an EPSS score under 0.10.

EPSS estimates the chance of exploitation activity in the next 30 days from signals across all published CVEs. CISA lists a vulnerability once it has evidence of exploitation. Where the two disagree, the evidence wins: these entries are exploited whatever their score.

#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2026-83548Server-Side Request ForgerySonicWall SMA1000 AppliancesPatch nowForensic triage required by CISA; Metasploit module0.09
2CVE-2026-15409Server-Side Request ForgerySonicWall SMA1000 AppliancesPatch nowForensic triage required by CISA; ransomware use, listed within a year; Metasploit module0.07
3CVE-2026-35273Missing Authentication for Critical FunctionOracle PeopleSoft Enterprise PeopleToolsPatch nowRansomware use, listed within a year0.09
4CVE-2026-85102Improper Certificate ValidationCheck Point Multiple ProductsPatch nowForensic triage required by CISA0.08
5CVE-2026-18556Authentication Bypass Using an Alternate Path or ChannelN-able N-centralPatch nowForensic triage required by CISA0.08
6CVE-2026-86060Improper Neutralization of Argument Delimiters in a CommandMikroTik RouterOSPatch nowForensic triage required by CISA0.06
7CVE-2026-50751Improper AuthenticationCheck Point Security GatewayPatch nowRansomware use, listed within a year0.06
8CVE-2025-60710Link FollowingMicrosoft WindowsPatch nowRansomware use, listed within a year0.05
9CVE-2026-75650Improper Neutralization of Special Elements Used in a Template EngineAdobe Commerce and MagentoPatch nowForensic triage required by CISA0.04
10CVE-2021-27137Stack-Based Buffer OverflowDD-WRT DD-WRTPatch nowForensic triage required by CISA0.04
11CVE-2025-25249Heap-based Buffer OverflowFortinet Multiple ProductsPatch nowForensic triage required by CISA0.04
12CVE-2026-50522Deserialization of Untrusted DataMicrosoft SharePointPatch nowForensic triage required by CISA0.03
13CVE-2025-39682Improper Check for Unusual or Exceptional ConditionsLinux KernelPatch nowForensic triage required by CISA0.03
14CVE-2026-45659Deserialization of Untrusted DataMicrosoft SharePoint ServerPatch nowForensic triage required by CISA; ransomware use, listed within a year0.03
15CVE-2026-7273Stack-Based Buffer OverflowZyxel GS1900 Series SwitchesPatch nowForensic triage required by CISA0.03
16CVE-2026-59310Path TraversalBroadcom VMware vCenterPatch nowForensic triage required by CISA; ransomware use, listed within a year0.03
17CVE-2026-94127Heap-based Buffer OverflowF5 BIG-IP APMPatch nowForensic triage required by CISA0.02
18CVE-2026-104286Path TraversalFortinet FortiMailPatch nowForensic triage required by CISA; listed in the last 14 days0.02
19CVE-2026-65660Code InjectionMicrosoft SharePointPatch nowForensic triage required by CISA; listed in the last 14 days0.02
20CVE-2026-49869OS Command InjectionKestra Kestra OSSPatch nowForensic triage required by CISA0.02
21CVE-2026-76504Hex EncodingCisco Catalyst SD-WAN ManagerPatch nowForensic triage required by CISA; listed in the last 14 days0.02
22CVE-2026-65400Improper AuthenticationApple macOSPatch nowForensic triage required by CISA0.02
23CVE-2026-72529Missing Authentication for Critical FunctionTrueConf ServerPatch nowForensic triage required by CISA0.01
24CVE-2026-102489Session FixationZammad GmbH ZammadPatch nowForensic triage required by CISA; listed in the last 14 days0.01
25CVE-2026-48027Embedded Malicious CodeNx Nx ConsolePatch nowRansomware use, listed within a year0.01
26CVE-2026-88772Improper Restriction of Operations within the Bounds of a Memory BufferCitrix NetScalerPatch nowForensic triage required by CISA; listed in the last 14 days0.01
27CVE-2026-86950Out-of-Bounds WriteApple Multiple ProductsPatch nowForensic triage required by CISA; listed in the last 14 days0.01
28CVE-2025-39964Race ConditionLinux KernelPatch nowForensic triage required by CISA0.01
29CVE-2026-88771Improper Input ValidationCitrix NetScalerPatch nowForensic triage required by CISA; listed in the last 14 days0.01
30CVE-2026-93952Improper Input ValidationArista VeloCloud OrchestratorPatch nowForensic triage required by CISA0.01
31CVE-2026-45321UnspecifiedTanStack TanStackPatch nowRansomware use, listed within a year0.01
32CVE-2026-67279Improper Enforcement of Behavioral WorkflowMikroTik RouterOSPatch nowListed in the last 14 days0.01
33CVE-2026-16812On-Prem OS Command InjectionArista VeloCloud OrchestratorPatch nowForensic triage required by CISA0.01
34CVE-2026-56164Missing Authentication for Critical FunctionMicrosoft SharePoint ServerPatch nowForensic triage required by CISA0.01
35CVE-2026-84869Improper Privilege Management and Missing AuthorizationConnectWise ScreenConnectPatch nowForensic triage required by CISA0.01
36CVE-2026-55255Authorization Bypass Through User-Controlled KeyLangflow LangflowPatch nowForensic triage required by CISA0.01
37CVE-2026-53266Out-of-Bounds WriteLinux KernelPatch nowForensic triage required by CISA0.01
38CVE-2026-46817Improper Privilege ManagementOracle E-Business SuitePatch nowForensic triage required by CISA0.01
39CVE-2026-53362UnspecifiedLinux KernelPatch nowForensic triage required by CISA0.01
40CVE-2026-102490Improper Privilege ManagementZammad GmbH ZammadPatch nowForensic triage required by CISA; listed in the last 14 days0.01
41CVE-2026-88779Improper Restriction of Operations within the Bounds of a Memory BufferCitrix NetScalerPatch nowForensic triage required by CISA; listed in the last 14 days0.01
42CVE-2026-5430Path TraversalWSO2 Multiple ProductsPatch nowForensic triage required by CISA; listed in the last 14 days0.01
43CVE-2026-58704Improper AuthorizationGoogle PixelPatch nowForensic triage required by CISA0.01
44CVE-2026-33825Insufficient Granularity of Access ControlMicrosoft DefenderPatch nowRansomware use, listed within a year0.00
45CVE-2026-87886Incorrect Default PermissionsAcronis BackupPatch nowForensic triage required by CISA0.00
46CVE-2015-3246Race ConditionRed Hat LibuserPatch this weekMetasploit module; verified Exploit-DB entry0.08
47CVE-2020-3950Privilege EscalationVMware Multiple ProductsPatch this weekMetasploit module; verified Exploit-DB entry0.07
48CVE-2015-5287Privilege EscalationRed Hat Automatic Bug Reporting ToolPatch this weekMetasploit module; verified Exploit-DB entry0.05
49CVE-2022-0995Out-of-Bounds WriteLinux KernelPatch this weekMetasploit module0.09
50CVE-2023-0386Improper Ownership ManagementLinux KernelPatch this weekMetasploit module0.08
51CVE-2026-60137SQL InjectionWordPress CorePatch this weekMetasploit module0.06
52CVE-2026-48558Authentication BypassSimpleHelp SimpleHelpPatch this weekMetasploit module0.06
53CVE-2022-0492Improper AuthenticationLinux KernelPatch this weekMetasploit module0.06
54CVE-2026-42208SQL InjectionBerriAI LiteLLMPatch this weekMetasploit module0.06
55CVE-2019-18988Bypass Remote LoginTeamViewer DesktopPatch this weekMetasploit module0.05
56CVE-2026-3055Out-of-Bounds ReadCitrix NetScalerPatch this weekMetasploit module0.04
57CVE-2026-31431Incorrect Resource Transfer Between SpheresLinux KernelPatch this weekMetasploit module0.03
58CVE-2020-9934Input ValidationApple iOS, iPadOS, and macOSPatch this weekMetasploit module0.03
59CVE-2019-0543Privilege EscalationMicrosoft WindowsPatch this weekRansomware use; verified Exploit-DB entry0.05
60CVE-2015-2291Denial-of-ServiceIntel Ethernet Diagnostics Driver for WindowsPatch this weekRansomware use0.09
61CVE-2025-24472Authentication BypassFortinet FortiOS and FortiProxyPatch this weekRansomware use0.07
62CVE-2019-1388Certificate Dialog Privilege EscalationMicrosoft WindowsPatch this weekRansomware use0.09
63CVE-2018-19323Privilege EscalationGIGABYTE Multiple ProductsPatch this weekRansomware use0.08
64CVE-2012-1710UnspecifiedOracle Fusion MiddlewarePatch this weekRansomware use0.08
65CVE-2022-24521CLFS Driver Privilege EscalationMicrosoft WindowsPatch this weekRansomware use0.07
66CVE-2021-38646Access Connectivity Engine Remote Code ExecutionMicrosoft OfficePatch this weekRansomware use0.08
67CVE-2019-11634Remote Code ExecutionCitrix Workspace Application and Receiver for WindowsPatch this weekRansomware use0.08
68CVE-2019-1064AppX Deployment Service (AppXSVC) Privilege EscalationMicrosoft WindowsPatch this weekRansomware use0.07
69CVE-2019-1069Privilege EscalationMicrosoft Task SchedulerPatch this weekRansomware use0.06
70CVE-2021-27101SQL InjectionAccellion FTAPatch this weekRansomware use0.06
71CVE-2019-6693Use of Hard-Coded CredentialsFortinet FortiOSPatch this weekRansomware use0.06
72CVE-2024-30051Privilege EscalationMicrosoft DWM Core LibraryPatch this weekRansomware use0.06
73CVE-2022-26500Remote Code ExecutionVeeam Backup & ReplicationPatch this weekRansomware use0.06
74CVE-2016-0167Privilege EscalationMicrosoft Win32kPatch this weekRansomware use0.06
75CVE-2020-29574(CROS) SQL InjectionSophos CyberoamOSPatch this weekRansomware use0.05
76CVE-2013-3993Invalid InputIBM InfoSphere BigInsightsPatch this weekRansomware use0.05
77CVE-2024-26169Error Reporting Service Improper Privilege ManagementMicrosoft WindowsPatch this weekRansomware use0.04
78CVE-2022-26501Remote Code ExecutionVeeam Backup & ReplicationPatch this weekRansomware use0.04
79CVE-2020-2021Authentication BypassPalo Alto Networks PAN-OSPatch this weekRansomware use0.04
80CVE-2019-0859Privilege EscalationMicrosoft Win32kPatch this weekRansomware use0.04
81CVE-2021-36955Common Log File System (CLFS) Driver Privilege EscalationMicrosoft WindowsPatch this weekRansomware use0.04
82CVE-2018-19320UnspecifiedGIGABYTE Multiple ProductsPatch this weekRansomware use0.04
83CVE-2018-19321Privilege EscalationGIGABYTE Multiple ProductsPatch this weekRansomware use0.04
84CVE-2019-1385AppX Deployment Extensions Privilege EscalationMicrosoft WindowsPatch this weekRansomware use0.04
85CVE-2021-27102OS Command InjectionAccellion FTAPatch this weekRansomware use0.04
86CVE-2018-8405DirectX Graphics Kernel Privilege EscalationMicrosoft DirectX Graphics Kernel (DXGKRNL)Patch this weekRansomware use0.03
87CVE-2018-8406DirectX Graphics Kernel Privilege EscalationMicrosoft DirectX Graphics Kernel (DXGKRNL)Patch this weekRansomware use0.03
88CVE-2019-1315Error Reporting Manager Privilege EscalationMicrosoft WindowsPatch this weekRansomware use0.03
89CVE-2021-43226Privilege EscalationMicrosoft WindowsPatch this weekRansomware use0.03
90CVE-2024-11667Path TraversalZyxel Multiple FirewallsPatch this weekRansomware use0.03
91CVE-2020-0878Memory CorruptionMicrosoft Edge and Internet ExplorerPatch this weekRansomware use0.03
92CVE-2020-0638Privilege EscalationMicrosoft Update Notification ManagerPatch this weekRansomware use0.02
93CVE-2022-41073Print Spooler Privilege EscalationMicrosoft WindowsPatch this weekRansomware use0.02
94CVE-2022-41091Mark of the Web (MOTW) Security Feature BypassMicrosoft WindowsPatch this weekRansomware use0.02
95CVE-2018-19322Code ExecutionGIGABYTE Multiple ProductsPatch this weekRansomware use0.02
96CVE-2019-1129AppX Deployment Service (AppXSVC) Privilege EscalationMicrosoft WindowsPatch this weekRansomware use0.02
97CVE-2019-1130AppX Deployment Service Privilege EscalationMicrosoft WindowsPatch this weekRansomware use0.02
98CVE-2025-22225Arbitrary WriteVMware ESXiPatch this weekRansomware use0.01
99CVE-2010-4398Kernel Stack-Based Buffer OverflowMicrosoft WindowsPatch soonVerified Exploit-DB entry0.09
100CVE-2004-0210Privilege EscalationMicrosoft WindowsPatch soonVerified Exploit-DB entry0.07