Vendor

Apache

As of , 40 Apache vulnerabilities are on CISA's list of exploited vulnerabilities, 8 of them used in ransomware campaigns; 2 were added in 2026. Patch first: CVE-2020-17519.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2020-17519Improper Access ControlApache FlinkPatch this weekMetasploit module; EPSS 0.98; verified Exploit-DB entry0.98
2CVE-2013-2251Improper Input ValidationApache StrutsPatch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry0.99
3CVE-2017-12617Remote Code ExecutionApache TomcatPatch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry0.99
4CVE-2020-1938Improper Privilege ManagementApache TomcatPatch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry0.99
5CVE-2016-3088Improper Input ValidationApache ActiveMQPatch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry0.99
6CVE-2017-9791Improper Input ValidationApache Struts 1Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry0.99
7CVE-2012-0391Improper Input ValidationApache Struts 2Patch this weekMetasploit module; EPSS 0.76; verified Exploit-DB entry0.76
8CVE-2016-4437Code ExecutionApache ShiroPatch this weekMetasploit module; EPSS 0.93; verified Exploit-DB entry0.93
9CVE-2017-5638Remote Code ExecutionApache StrutsPatch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry0.99
10CVE-2018-11776Remote Code ExecutionApache StrutsPatch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry0.99
11CVE-2019-17558VelocityResponseWriter Plug-In Remote Code ExecutionApache SolrPatch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry0.99
12CVE-2021-41773Path TraversalApache HTTP ServerPatch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry0.99
13CVE-2021-42013Path TraversalApache HTTP ServerPatch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry0.99
14CVE-2025-24813Path EquivalenceApache TomcatPatch this weekMetasploit module; EPSS 0.990.99
15CVE-2024-27348Improper Access ControlApache HugeGraph-ServerPatch this weekMetasploit module; EPSS 0.990.99
16CVE-2024-38856Incorrect AuthorizationApache OFBizPatch this weekMetasploit module; EPSS 0.990.99
17CVE-2024-32113Path TraversalApache OFBizPatch this weekMetasploit module; EPSS 0.990.99
18CVE-2023-27524Insecure Default Initialization of ResourceApache SupersetPatch this weekMetasploit module; EPSS 0.970.97
19CVE-2023-46604Deserialization of Untrusted DataApache ActiveMQPatch this weekRansomware use; Metasploit module; EPSS 0.990.99
20CVE-2023-33246Command ExecutionApache RocketMQPatch this weekMetasploit module; EPSS 0.970.97
21CVE-2021-45046Deserialization of Untrusted DataApache Log4j2Patch this weekRansomware use; Metasploit module; EPSS 0.990.99
22CVE-2022-33891Command InjectionApache SparkPatch this weekMetasploit module; EPSS 0.930.93
23CVE-2022-24112Authentication BypassApache APISIXPatch this weekMetasploit module; EPSS 0.960.96
24CVE-2022-24706Insecure Default Initialization of ResourceApache CouchDBPatch this weekMetasploit module; EPSS 0.930.93
25CVE-2020-11978Command InjectionApache AirflowPatch this weekMetasploit module; EPSS 0.990.99

The next 15, from number 26

Products

  • Tomcat6 entries
  • Struts5 entries
  • HTTP Server4 entries
  • ActiveMQ3 entries
  • OFBiz3 entries
  • Log4j22 entries
  • Solr2 entries
  • Struts 12 entries
  • Airflow1 entry
  • Airflow's Experimental API1 entry
  • Apache1 entry
  • APISIX1 entry
  • CouchDB1 entry
  • Flink1 entry
  • HugeGraph-Server1 entry
  • Kylin1 entry
  • RocketMQ1 entry
  • Shiro1 entry
  • Spark1 entry
  • Struts 21 entry
  • Superset1 entry

Added each year

510152021: 121220212022: 131320222023: 5520232024: 5520242025: 3320252026: 222026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
202112
202213
20235
20245
20253
20262

Used in ransomware

Changes CISA made to these entries

  1. CVE-2026-34486 Apache TomcatEdited: description.
  2. CVE-2025-24813 Apache TomcatEdited: description.
  3. CVE-2021-40438 ApacheRansomware use: Unknown to Known.
  4. CVE-2025-24813 Apache TomcatEdited: notes.
  5. CVE-2024-45195 Apache OFBizEdited: notes.
  6. CVE-2024-27348 Apache HugeGraph-ServerEdited: notes.
  7. CVE-2024-45195 Apache OFBizEdited: notes.

Every change we recorded