CISA · government feed

Known Exploited Vulnerabilities

Vulnerabilities under active exploitation, mandated by CISA for federal patching.

1,653 total matches · showing 200

CVEVendor / ProductStatus
CVE-2026-50522
Microsoft
SharePoint
Active
CVE-2026-16232
Check Point
SmartConsole
Active
CVE-2021-27137
DD-WRT
DD-WRT
Active
CVE-2026-0770
Langflow
Langflow
Active
CVE-2026-63030
WordPress
Core
Active
CVE-2026-60137
WordPress
Core
Active
CVE-2026-39808
Fortinet
FortiSandbox
Active
CVE-2026-25089
Fortinet
FortiSandbox
Active
CVE-2026-58644
Microsoft
SharePoint
Active
CVE-2023-4346
KNX Association
KNX Protocol Connection Authorization Option 1
Active
CVE-2026-46817
Oracle
E-Business Suite
Active
CVE-2026-15410
SonicWall
SMA1000 Appliances
Active
CVE-2026-15409
SonicWall
SMA1000 Appliances
Active
CVE-2026-56164
Microsoft
SharePoint Server
Active
CVE-2026-56155
Microsoft
Active Directory Federation Services
Active
CVE-2008-4128
Cisco
IOS
Active
CVE-2026-48939
iCagenda
iCagenda
Active
CVE-2026-56291
Balbooa
Forms
Active
CVE-2026-48282
Adobe
ColdFusion
Active
CVE-2026-56290
Joomlack
Page Builder
Active
CVE-2026-55255
Langflow
Langflow
Active
CVE-2026-48908
JoomShaper
SP Page Builder
Active
CVE-2026-45659
Microsoft
SharePoint Server
Active
CVE-2026-48558
SimpleHelp
SimpleHelp
Active
CVE-2026-20230
Cisco
Unified Communications Manager
Active
CVE-2026-12569
PTC
Windchill and FlexPLM
Ransomware
CVE-2026-34908
Ubiquiti
UniFi OS
Active
CVE-2026-34909
Ubiquiti
UniFi OS
Active
CVE-2026-34910
Ubiquiti
UniFi OS
Active
CVE-2025-67038
Lantronix
EDS5000
Active
CVE-2026-20253
Splunk
Enterprise
Active
CVE-2026-48907
Widget Factory
Joomla Content Editor
Active
CVE-2026-20262
Cisco
Catalyst SD-WAN Manager
Active
CVE-2026-54420
LiteSpeed
cPanel Plugin
Active
CVE-2026-35273
Oracle
PeopleSoft Enterprise PeopleTools
Ransomware
CVE-2026-10520
Ivanti
Sentry
Active
CVE-2026-20245
Cisco
Catalyst SD-WAN Manager
Active
CVE-2026-7473
Arista
Extensible Operating System
Active
CVE-2026-11645
Google
Chromium V8
Active
CVE-2026-50751
Check Point
Security Gateway
Ransomware
CVE-2026-42271
BerriAI
LiteLLM
Active
CVE-2026-28318
SolarWinds
Serv-U
Active
CVE-2026-45247
Mirasvit
Mirasvit Full Page Cache Warmer
Active
CVE-2025-48595
Android
Framework
Active
CVE-2022-0492
Linux
Kernel
Active
CVE-2024-21182
Oracle
WebLogic Server
Active
CVE-2026-0257
Palo Alto Networks
PAN-OS
Ransomware
CVE-2026-8398
Daemon
Daemon Tools Lite
Active
CVE-2026-45321
TanStack
TanStack
Ransomware
CVE-2026-48027
Nx
Nx Console
Ransomware
CVE-2026-48172
LiteSpeed
cPanel Plugin
Active
CVE-2026-9082
Drupal
Core
Active
CVE-2026-34926
Trend Micro
Apex One
Active
CVE-2025-34291
Langflow
Langflow
Active
CVE-2026-45498
Microsoft
Defender
Active
CVE-2026-41091
Microsoft
Defender
Active
CVE-2010-0806
Microsoft
Internet Explorer
Active
CVE-2010-0249
Microsoft
Internet Explorer
Active
CVE-2009-3459
Adobe
Acrobat and Reader
Active
CVE-2009-1537
Microsoft
DirectX
Active
CVE-2008-4250
Microsoft
Windows
Active
CVE-2026-42897
Microsoft
Microsoft
Active
CVE-2026-20182
Cisco
Catalyst SD-WAN
Active
CVE-2026-42208
BerriAI
LiteLLM
Active
CVE-2026-6973
Ivanti
Endpoint Manager Mobile (EPMM)
Active
CVE-2026-0300
Palo Alto Networks
PAN-OS
Active
CVE-2026-31431
Linux
Kernel
Active
CVE-2026-41940
WebPros
cPanel & WHM and WP2 (WordPress Squared)
Ransomware
CVE-2026-32202
Microsoft
Windows
Active
CVE-2024-1708
ConnectWise
ScreenConnect
Ransomware
CVE-2024-57726
SimpleHelp
SimpleHelp
Ransomware
CVE-2024-57728
SimpleHelp
SimpleHelp
Ransomware
CVE-2024-7399
Samsung
MagicINFO 9 Server
Active
CVE-2025-29635
D-Link
DIR-823X
Active
CVE-2026-39987
Marimo
Marimo
Active
CVE-2026-33825
Microsoft
Defender
Ransomware
CVE-2024-27199
JetBrains
TeamCity
Ransomware
CVE-2025-32975
Quest
KACE Systems Management Appliance (SMA)
Active
CVE-2026-20128
Cisco
Catalyst SD-WAN Manager
Active
CVE-2025-48700
Synacor
Zimbra Collaboration Suite (ZCS)
Active
CVE-2023-27351
PaperCut
NG/MF
Ransomware
CVE-2025-2749
Kentico
Kentico Xperience
Active
CVE-2026-20133
Cisco
Catalyst SD-WAN Manager
Active
CVE-2026-20122
Cisco
Catalyst SD-WAN Manger
Active
CVE-2026-34197
Apache
ActiveMQ
Active
CVE-2026-32201
Microsoft
SharePoint Server
Active
CVE-2009-0238
Microsoft
Office
Active
CVE-2026-34621
Adobe
Acrobat and Reader
Active
CVE-2026-21643
Fortinet
FortiClient EMS
Active
CVE-2020-9715
Adobe
Acrobat
Active
CVE-2023-36424
Microsoft
Windows
Active
CVE-2023-21529
Microsoft
Exchange Server
Ransomware
CVE-2025-60710
Microsoft
Windows
Active
CVE-2012-1854
Microsoft
Visual Basic for Applications (VBA)
Active
CVE-2026-1340
Ivanti
Endpoint Manager Mobile (EPMM)
Active
CVE-2026-35616
Fortinet
FortiClient EMS
Active
CVE-2026-3502
TrueConf
Client
Active
CVE-2026-5281
Google
Dawn
Active
CVE-2026-3055
Citrix
NetScaler
Active
CVE-2025-53521
F5
BIG-IP
Active
CVE-2026-33634
Aquasecurity
Trivy
Active
CVE-2026-33017
Langflow
Langflow
Active
CVE-2025-31277
Apple
Multiple Products
Active
CVE-2025-43520
Apple
Multiple Products
Active
CVE-2025-43510
Apple
Multiple Products
Active
CVE-2025-54068
Laravel
Livewire
Active
CVE-2025-32432
Craft CMS
Craft CMS
Active
CVE-2026-20131
Cisco
Secure Firewall Management Center (FMC)
Ransomware
CVE-2026-20963
Microsoft
SharePoint
Active
CVE-2025-66376
Synacor
Zimbra Collaboration Suite (ZCS)
Active
CVE-2025-47813
Wing FTP Server
Wing FTP Server
Active
CVE-2026-3909
Google
Skia
Active
CVE-2026-3910
Google
Chromium V8
Active
CVE-2025-68613
n8n
n8n
Active
CVE-2026-1603
Ivanti
Endpoint Manager (EPM)
Active
CVE-2025-26399
SolarWinds
Web Help Desk
Active
CVE-2021-22054
Omnissa
Workspace One UEM
Active
CVE-2023-41974
Apple
iOS and iPadOS
Active
CVE-2021-30952
Apple
Multiple Products
Active
CVE-2023-43000
Apple
Multiple Products
Active
CVE-2021-22681
Rockwell
Multiple Products
Active
CVE-2017-7921
Hikvision
Multiple Products
Active
CVE-2026-21385
Qualcomm
Multiple Chipsets
Active
CVE-2026-22719
Broadcom
VMware Aria Operations
Active
CVE-2026-20127
Cisco
Catalyst SD-WAN Controller and Manager
Active
CVE-2022-20775
Cisco
SD-WAN
Active
CVE-2026-25108
Soliton Systems K.K
FileZen
Active
CVE-2025-68461
Roundcube
Webmail
Active
CVE-2025-49113
Roundcube
Webmail
Active
CVE-2026-22769
Dell
RecoverPoint for Virtual Machines (RP4VMs)
Active
CVE-2021-22175
GitLab
GitLab
Active
CVE-2026-2441
Google
Chromium
Active
CVE-2008-0015
Microsoft
Windows
Active
CVE-2024-7694
TeamT5
ThreatSonar Anti-Ransomware
Active
CVE-2020-7796
Synacor
Zimbra Collaboration Suite
Active
CVE-2026-1731
BeyondTrust
Remote Support (RS) and Privileged Remote Access (PRA)
Ransomware
CVE-2025-40536
SolarWinds
Web Help Desk
Active
CVE-2025-15556
Notepad++
Notepad++
Active
CVE-2024-43468
Microsoft
Configuration Manager
Active
CVE-2026-20700
Apple
Multiple Products
Active
CVE-2026-21514
Microsoft
Office
Active
CVE-2026-21519
Microsoft
Windows
Active
CVE-2026-21533
Microsoft
Windows
Active
CVE-2026-21510
Microsoft
Windows
Active
CVE-2026-21525
Microsoft
Windows
Active
CVE-2026-21513
Microsoft
Windows
Active
CVE-2026-24423
SmarterTools
SmarterMail
Ransomware
CVE-2025-11953
React Native Community
CLI
Active
CVE-2025-40551
SolarWinds
Web Help Desk
Active
CVE-2019-19006
Sangoma
FreePBX
Active
CVE-2025-64328
Sangoma
FreePBX
Active
CVE-2021-39935
GitLab
Community and Enterprise Editions
Active
CVE-2026-1281
Ivanti
Endpoint Manager Mobile (EPMM)
Active
CVE-2026-24858
Fortinet
Multiple Products
Active
CVE-2026-21509
Microsoft
Office
Active
CVE-2026-24061
GNU
InetUtils
Active
CVE-2026-23760
SmarterTools
SmarterMail
Ransomware
CVE-2025-52691
SmarterTools
SmarterMail
Ransomware
CVE-2018-14634
Linux
Kernel
Active
CVE-2024-37079
Broadcom
VMware vCenter Server
Active
CVE-2025-54313
Prettier
eslint-config-prettier
Active
CVE-2025-31125
Vite
Vitejs
Active
CVE-2025-34026
Versa
Concerto
Active
CVE-2025-68645
Synacor
Zimbra Collaboration Suite (ZCS)
Active
CVE-2026-20045
Cisco
Unified Communications Manager
Active
CVE-2026-20805
Microsoft
Windows
Active
CVE-2025-8110
Gogs
Gogs
Active
CVE-2025-37164
Hewlett Packard Enterprise (HPE)
OneView
Active
CVE-2009-0556
Microsoft
Office
Active
CVE-2025-14847
MongoDB
MongoDB and MongoDB Server
Active
CVE-2023-52163
Digiever
DS-2105 Pro
Active
CVE-2025-14733
WatchGuard
Firebox
Active
CVE-2025-20393
Cisco
Multiple Products
Active
CVE-2025-40602
SonicWall
SMA1000 appliance
Active
CVE-2025-59374
ASUS
Live Update
Active
CVE-2025-59718
Fortinet
Multiple Products
Active
CVE-2025-43529
Apple
Multiple Products
Active
CVE-2025-14611
Gladinet
CentreStack and Triofox
Active
CVE-2025-14174
Google
Chromium
Active
CVE-2018-4063
Sierra Wireless
AirLink ALEOS
Active
CVE-2025-58360
OSGeo
GeoServer
Active
CVE-2025-62221
Microsoft
Windows
Active
CVE-2025-6218
RARLAB
WinRAR
Active
CVE-2025-66644
Array Networks
ArrayOS AG
Active
CVE-2022-37055
D-Link
Routers
Active
CVE-2025-55182
Meta
React Server Components
Ransomware
CVE-2021-26828
OpenPLC
ScadaBR
Active
CVE-2025-48572
Android
Framework
Active
CVE-2025-48633
Android
Framework
Active
CVE-2021-26829
OpenPLC
ScadaBR
Active
CVE-2025-61757
Oracle
Fusion Middleware
Active
CVE-2025-13223
Google
Chromium V8
Active
CVE-2025-58034
Fortinet
FortiWeb
Active
CVE-2025-64446
Fortinet
FortiWeb
Active
CVE-2025-9242
WatchGuard
Firebox
Active
CVE-2025-62215
Microsoft
Windows
Active
CVE-2025-12480
Gladinet
Triofox
Active
CVE-2025-21042
Samsung
Mobile Devices
Active
CVE-2025-11371
Gladinet
CentreStack and Triofox
Active
CVE-2025-48703
CWP
Control Web Panel
Active
Feedback

How was this page?

Spotted something off, or have an idea? Let us know.

0/1000