Vendor

SysAid

As of , 3 SysAid vulnerabilities are on CISA's list of exploited vulnerabilities, 1 of them used in ransomware campaigns; 0 were added in 2026. Patch first: CVE-2025-2776.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2025-2776Improper Restriction of XML External Entity ReferenceSysAid SysAid On-PremPatch this weekEPSS 0.650.65
2CVE-2023-47246Path TraversalSysAid SysAid ServerPatch this weekRansomware use; EPSS 0.990.99
3CVE-2025-2775Improper Restriction of XML External Entity ReferenceSysAid SysAid On-PremPatch soon0.43

Products

  • SysAid On-Prem2 entries
  • SysAid Server1 entry

Added each year

0.511.522023: 1120232024: nonenone20242025: 2220252026: nonenone2026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20231
2024none
20252
2026none

Used in ransomware