Vendor

Kaseya

As of , 3 Kaseya vulnerabilities are on CISA's list of exploited vulnerabilities, 3 of them used in ransomware campaigns; 0 were added in 2026. Patch first: CVE-2017-18362.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2017-18362VSA SQL InjectionKaseya Virtual System/Server Administrator (VSA)Patch this weekRansomware use; EPSS 0.870.87
2CVE-2021-30116Information DisclosureKaseya Virtual System/Server Administrator (VSA)Patch this weekRansomware use; EPSS 0.860.86
3CVE-2018-20753VSA Remote Code ExecutionKaseya Virtual System/Server Administrator (VSA)Patch this weekRansomware use0.29

Added each year

0.511.522021: 1120212022: 2220222023: nonenone20232024: nonenone20242025: nonenone20252026: nonenone2026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20211
20222
2023none
2024none
2025none
2026none

Used in ransomware