Vendor

Elastic

As of , 3 Elastic vulnerabilities are on CISA's list of exploited vulnerabilities; 0 were added in 2026. Patch first: CVE-2014-3120.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2014-3120Remote Code ExecutionElastic ElasticsearchPatch this weekMetasploit module; EPSS 0.89; verified Exploit-DB entry0.89
2CVE-2015-1427Groovy Scripting Engine Remote Code ExecutionElastic ElasticsearchPatch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry0.99
3CVE-2019-7609Arbitrary Code ExecutionElastic KibanaPatch this weekMetasploit module; EPSS 0.950.95

Products

  • Elasticsearch2 entries
  • Kibana1 entry

Added each year

1232022: 3320222023: nonenone20232024: nonenone20242025: nonenone20252026: nonenone2026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20223
2023none
2024none
2025none
2026none

Used in ransomware