Vendor

Mitel

As of , 7 Mitel vulnerabilities are on CISA's list of exploited vulnerabilities, 5 of them used in ransomware campaigns; 0 were added in 2026. Patch first: CVE-2024-41713.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2024-41713Path TraversalMitel MiCollabPatch this weekRansomware use; EPSS 0.980.98
2CVE-2022-29499Data ValidationMitel MiVoice ConnectPatch this weekRansomware use; EPSS 0.550.55
3CVE-2022-26143Access ControlMitel MiCollab, MiVoice Business ExpressPatch this weekEPSS 0.870.87
4CVE-2024-55550Path TraversalMitel MiCollabPatch this weekRansomware use0.38
5CVE-2022-40765Command InjectionMitel MiVoice ConnectPatch this weekRansomware use0.11
6CVE-2022-41223Code InjectionMitel MiVoice ConnectPatch this weekRansomware use0.11
7CVE-2024-41710Argument InjectionMitel SIP PhonesPatch soon0.42

Products

  • MiVoice Connect3 entries
  • MiCollab2 entries
  • MiCollab, MiVoice Business Express1 entry
  • SIP Phones1 entry

Added each year

1232022: 2220222023: 2220232024: nonenone20242025: 3320252026: nonenone2026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20222
20232
2024none
20253
2026none

Used in ransomware

Changes CISA made to these entries

  1. CVE-2024-55550 Mitel MiCollabRansomware use: Unknown to Known.
  2. CVE-2024-41713 Mitel MiCollabRansomware use: Unknown to Known.

Every change we recorded