Skip to content

Threat Radar

The vulnerabilities being exploited right now — filtered to what you run.

CISA publishes a catalog of security flaws confirmed to be under active attack. We rank it for the small-business stack — Microsoft, Google, Apple, your firewall/VPN, and everyday apps — and flag the ones tied to ransomware or past their federal remediation deadline.

SourceFetched live from CISA just now.
1 entry

Microsoft

Windows, Exchange, Office, and the rest of the Microsoft stack.

Microsoft SharePoint Server

RansomwarePast due 74d

Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability

Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Added Jul 1, 2026 · due Jul 4, 2026CVE-2026-45659
58 entries

Networking & VPN

Firewalls, routers, and remote-access gear at the network edge.

Cisco Secure Firewall Management Center (FMC)

RansomwarePast due 46d

Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability

Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Added Jul 29, 2026 · due Aug 1, 2026CVE-2026-20316

SonicWall SMA1000 Appliances

RansomwarePast due 61d

SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability

SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Added Jul 14, 2026 · due Jul 17, 2026CVE-2026-15409

SonicWall SMA1000 Appliances

RansomwarePast due 61d

SonicWall SMA1000 Appliances Code Injection Vulnerability

SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Added Jul 14, 2026 · due Jul 17, 2026CVE-2026-15410

Palo Alto Networks PAN-OS

RansomwarePast due 107d

Palo Alto Networks PAN-OS Authentication Bypass Vulnerability

Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection.

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Added May 29, 2026 · due Jun 1, 2026CVE-2026-0257

Cisco Secure Firewall Management Center (FMC)

RansomwarePast due 178d

Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability

Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain a deserialization of untrusted data vulnerability in the web-based management interface that could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device.

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Added Mar 19, 2026 · due Mar 22, 2026CVE-2026-20131

WatchGuard Firebox

RansomwarePast due 264d

WatchGuard Firebox Out of Bounds Write Vulnerability

WatchGuard Fireware OS iked process contains an out of bounds write vulnerability in the OS iked process. This vulnerability may allow a remote unauthenticated attacker to execute arbitrary code and affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer.

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Added Dec 19, 2025 · due Dec 26, 2025CVE-2025-14733

Citrix NetScaler ADC and Gateway

RansomwarePast due 432d

Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability

Citrix NetScaler ADC and Gateway contain an out-of-bounds read vulnerability due to insufficient input validation. This vulnerability can lead to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server.

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Added Jul 10, 2025 · due Jul 11, 2025CVE-2025-5777

Fortinet FortiOS

RansomwarePast due 427d

Fortinet FortiOS Use of Hard-Coded Credentials Vulnerability

Fortinet FortiOS contains a use of hard-coded credentials vulnerability that could allow an attacker to cipher sensitive data in FortiOS configuration backup file via knowledge of the hard-coded key.

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Added Jun 25, 2025 · due Jul 16, 2025CVE-2019-6693

Ivanti Connect Secure, Policy Secure, and ZTA Gateways

RansomwarePast due 523d

Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability

Ivanti Connect Secure, Policy Secure, and ZTA Gateways contains a stack-based buffer overflow vulnerability that allows a remote unauthenticated attacker to achieve remote code execution.

Required action: Apply mitigations as set forth in the CISA instructions linked below.

Added Apr 4, 2025 · due Apr 11, 2025CVE-2025-22457

Fortinet FortiOS and FortiProxy

RansomwarePast due 526d

Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability

Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that allows a remote attacker to gain super-admin privileges via crafted CSF proxy requests.

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Added Mar 18, 2025 · due Apr 8, 2025CVE-2025-24472

SonicWall SonicOS

RansomwarePast due 554d

SonicWall SonicOS SSLVPN Improper Authentication Vulnerability

SonicWall SonicOS contains an improper authentication vulnerability in the SSLVPN authentication mechanism that allows a remote attacker to bypass authentication.

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added Feb 18, 2025 · due Mar 11, 2025CVE-2024-53704

Sophos CyberoamOS

RansomwarePast due 566d

CyberoamOS (CROS) SQL Injection Vulnerability

CyberoamOS (CROS) contains a SQL injection vulnerability in the WebAdmin that allows an unauthenticated attacker to execute arbitrary SQL statements remotely.

Required action: The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.

Added Feb 6, 2025 · due Feb 27, 2025CVE-2020-29574

SonicWall SMA1000 Appliances

RansomwarePast due 579d

SonicWall SMA1000 Appliances Deserialization Vulnerability

SonicWall SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC) contain a deserialization of untrusted data vulnerability, which can enable a remote, unauthenticated attacker to execute arbitrary OS commands.

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added Jan 24, 2025 · due Feb 14, 2025CVE-2025-23006

Fortinet FortiOS and FortiProxy

RansomwarePast due 603d

Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability

Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that may allow an unauthenticated, remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added Jan 14, 2025 · due Jan 21, 2025CVE-2024-55591

Ivanti Connect Secure, Policy Secure, and ZTA Gateways

RansomwarePast due 609d

Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability

Ivanti Connect Secure, Policy Secure, and ZTA Gateways contain a stack-based buffer overflow which can lead to unauthenticated remote code execution.

Required action: Apply mitigations as set forth in the CISA instructions linked below to include conducting hunt activities, taking remediation actions if applicable, and applying updates prior to returning a device to service.

Added Jan 8, 2025 · due Jan 15, 2025CVE-2025-0282

Zyxel Multiple Firewalls

RansomwarePast due 631d

Zyxel Multiple Firewalls Path Traversal Vulnerability

Multiple Zyxel firewalls contain a path traversal vulnerability in the web management interface that could allow an attacker to download or upload files via a crafted URL.

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added Dec 3, 2024 · due Dec 24, 2024CVE-2024-11667

Palo Alto Networks PAN-OS

RansomwarePast due 646d

Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability

Palo Alto Networks PAN-OS contains an authentication bypass vulnerability in the web-based management interface for several PAN-OS products, including firewalls and VPN concentrators.

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Additionally, management interface for affected devices should not be exposed to untrusted networks, including the internet.

Added Nov 18, 2024 · due Dec 9, 2024CVE-2024-0012

Palo Alto Networks PAN-OS

RansomwarePast due 646d

Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability

Palo Alto Networks PAN-OS contains an OS command injection vulnerability that allows for privilege escalation through the web-based management interface for several PAN products, including firewalls and VPN concentrators.

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Additionally, the management interfaces for affected devices should not be exposed to untrusted networks, including the internet.

Added Nov 18, 2024 · due Dec 9, 2024CVE-2024-9474

SonicWall SonicOS

RansomwarePast due 716d

SonicWall SonicOS Improper Access Control Vulnerability

SonicWall SonicOS contains an improper access control vulnerability that could lead to unauthorized resource access and, under certain conditions, may cause the firewall to crash.

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added Sep 9, 2024 · due Sep 30, 2024CVE-2024-40766

Palo Alto Networks PAN-OS

RansomwarePast due 880d

Palo Alto Networks PAN-OS Command Injection Vulnerability

Palo Alto Networks PAN-OS GlobalProtect feature contains a command injection vulnerability that allows an unauthenticated attacker to execute commands with root privileges on the firewall.

Required action: Apply mitigations per vendor instructions as they become available. Otherwise, users with vulnerable versions of affected devices should enable Threat Prevention IDs available from the vendor. See the vendor bulletin for more details and a patch release schedule.

Added Apr 12, 2024 · due Apr 19, 2024CVE-2024-3400

Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA)

RansomwarePast due 884d

Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) Code Injection Vulnerability

Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) contains a code injection vulnerability that allows an unauthenticated user to execute malicious code with limited permissions (nobody).

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added Mar 25, 2024 · due Apr 15, 2024CVE-2021-44529

Fortinet FortiClient EMS

RansomwarePast due 884d

Fortinet FortiClient EMS SQL Injection Vulnerability

Fortinet FortiClient EMS contains a SQL injection vulnerability that allows an unauthenticated attacker to execute commands as SYSTEM via specifically crafted requests.

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added Mar 25, 2024 · due Apr 15, 2024CVE-2023-48788

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)

RansomwarePast due 923d

Cisco ASA and FTD Information Disclosure Vulnerability

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an information disclosure vulnerability. An attacker could retrieve memory contents on an affected device, which could lead to the disclosure of confidential information due to a buffer tracking issue when the software parses invalid URLs that are requested from the web services interface. This vulnerability affects only specific AnyConnect and WebVPN configurations.

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added Feb 15, 2024 · due Mar 7, 2024CVE-2020-3259

Fortinet FortiOS

RansomwarePast due 943d

Fortinet FortiOS Out-of-Bound Write Vulnerability

Fortinet FortiOS contains an out-of-bound write vulnerability that allows a remote unauthenticated attacker to execute code or commands via specially crafted HTTP requests.

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added Feb 9, 2024 · due Feb 16, 2024CVE-2024-21762

Ivanti Connect Secure, Policy Secure, and Neurons

RansomwarePast due 957d

Ivanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) Vulnerability

Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure), Ivanti Policy Secure, and Ivanti Neurons contain a server-side request forgery (SSRF) vulnerability in the SAML component that allows an attacker to access certain restricted resources without authentication.

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added Jan 31, 2024 · due Feb 2, 2024CVE-2024-21893

Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core

RansomwarePast due 951d

Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass Vulnerability

Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core contain an authentication bypass vulnerability that allows unauthorized users to access restricted functionality or resources of the application.

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added Jan 18, 2024 · due Feb 8, 2024CVE-2023-35082

Ivanti Connect Secure and Policy Secure

RansomwarePast due 968d

Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability

Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure gateways contain an authentication bypass vulnerability in the web component that allows an attacker to access restricted resources by bypassing control checks. This vulnerability can be leveraged in conjunction with CVE-2024-21887, a command injection vulnerability.

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added Jan 10, 2024 · due Jan 22, 2024CVE-2023-46805

Ivanti Connect Secure and Policy Secure

RansomwarePast due 968d

Ivanti Connect Secure and Policy Secure Command Injection Vulnerability

Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure contain a command injection vulnerability in the web components of these products, which can allow an authenticated administrator to send crafted requests to execute code on affected appliances. This vulnerability can be leveraged in conjunction with CVE-2023-46805, an authenticated bypass issue.

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added Jan 10, 2024 · due Jan 22, 2024CVE-2024-21887

F5 BIG-IP Configuration Utility

RansomwarePast due 1030d

F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability

F5 BIG-IP Configuration utility contains an authentication bypass using an alternate path or channel vulnerability due to undisclosed requests that may allow an unauthenticated attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute system commands. This vulnerability can be used in conjunction with CVE-2023-46748.

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added Oct 31, 2023 · due Nov 21, 2023CVE-2023-46747

Citrix NetScaler ADC and NetScaler Gateway

RansomwarePast due 1043d

Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability

Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for sensitive information disclosure when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.

Required action: Apply mitigations and kill all active and persistent sessions per vendor instructions [https://www.netscaler.com/blog/news/cve-2023-4966-critical-security-update-now-available-for-netscaler-adc-and-netscaler-gateway/] OR discontinue use of the product if mitigations are unavailable.

Added Oct 18, 2023 · due Nov 8, 2023CVE-2023-4966

Zyxel EMG2926 Routers

RansomwarePast due 1073d

Zyxel EMG2926 Routers Command Injection Vulnerability

Zyxel EMG2926 routers contain a command injection vulnerability located in the diagnostic tools, specifically the nslookup function. A malicious user may exploit numerous vectors to execute malicious commands on the router, such as the ping_ip parameter to the expert/maintenance/diagnostic/nslookup URI.

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added Sep 18, 2023 · due Oct 9, 2023CVE-2017-6884

Cisco Adaptive Security Appliance and Firepower Threat Defense

RansomwarePast due 1078d

Cisco Adaptive Security Appliance and Firepower Threat Defense Unauthorized Access Vulnerability

Cisco Adaptive Security Appliance and Firepower Threat Defense contain an unauthorized access vulnerability that could allow an unauthenticated, remote attacker to conduct a brute force attack in an attempt to identify valid username and password combinations or establish a clientless SSL VPN session with an unauthorized user.

Required action: Apply mitigations per vendor instructions for group-lock and vpn-simultaneous-logins or discontinue use of the product for unsupported devices.

Added Sep 13, 2023 · due Oct 4, 2023CVE-2023-20269

Ivanti Sentry

RansomwarePast due 1100d

Ivanti Sentry Authentication Bypass Vulnerability

Ivanti Sentry, formerly known as MobileIron Sentry, contains an authentication bypass vulnerability that may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTTPD configuration.

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added Aug 22, 2023 · due Sep 12, 2023CVE-2023-38035

Ivanti Endpoint Manager Mobile (EPMM)

RansomwarePast due 1128d

Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability

Ivanti Endpoint Manager Mobile (EPMM, previously branded MobileIron Core) contains an authentication bypass vulnerability that allows unauthenticated access to specific API paths. An attacker with access to these API paths can access personally identifiable information (PII) such as names, phone numbers, and other mobile device details for users on a vulnerable system. An attacker can also make other configuration changes including installing software and modifying security profiles on registered devices.

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added Jul 25, 2023 · due Aug 15, 2023CVE-2023-35078

Citrix NetScaler ADC and NetScaler Gateway

RansomwarePast due 1134d

Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability

Citrix NetScaler ADC and NetScaler Gateway contains a code injection vulnerability that allows for unauthenticated remote code execution.

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added Jul 19, 2023 · due Aug 9, 2023CVE-2023-3519

Fortinet FortiOS and FortiProxy SSL-VPN

RansomwarePast due 1170d

Fortinet FortiOS and FortiProxy SSL-VPN Heap-Based Buffer Overflow Vulnerability

Fortinet FortiOS and FortiProxy SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker to execute code or commands via specifically crafted requests.

Required action: Apply updates per vendor instructions.

Added Jun 13, 2023 · due Jul 4, 2023CVE-2023-27997

Fortinet FortiOS

RansomwarePast due 1352d

Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability

Multiple versions of Fortinet FortiOS SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker to execute arbitrary code or commands via specifically crafted requests.

Required action: Apply updates per vendor instructions.

Added Dec 13, 2022 · due Jan 3, 2023CVE-2022-42475

Cisco AnyConnect Secure

RansomwarePast due 1402d

Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability

Cisco AnyConnect Secure Mobility Client for Windows allows for incorrect handling of directory paths. An attacker with valid credentials on Windows would be able to copy malicious files to arbitrary locations with system level privileges. This could include DLL pre-loading, DLL hijacking, and other related attacks.

Required action: Apply updates per vendor instructions.

Added Oct 24, 2022 · due Nov 14, 2022CVE-2020-3153

Cisco AnyConnect Secure

RansomwarePast due 1402d

Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability

Cisco AnyConnect Secure Mobility Client for Windows interprocess communication (IPC) channel allows for insufficient validation of resources that are loaded by the application at run time. An attacker with valid credentials on Windows could execute code on the affected machine with SYSTEM privileges.

Required action: Apply updates per vendor instructions.

Added Oct 24, 2022 · due Nov 14, 2022CVE-2020-3433

Fortinet Multiple Products

RansomwarePast due 1415d

Fortinet Multiple Products Authentication Bypass Vulnerability

Fortinet FortiOS, FortiProxy, and FortiSwitchManager contain an authentication bypass vulnerability that could allow an unauthenticated attacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.

Required action: Apply updates per vendor instructions.

Added Oct 11, 2022 · due Nov 1, 2022CVE-2022-40684

Fortinet FortiOS and FortiADC

RansomwarePast due 1448d

Fortinet FortiOS and FortiADC Improper Access Control Vulnerability

Fortinet FortiOS and FortiADC contain an improper access control vulnerability that allows attackers to obtain the LDAP server login credentials configured in FortiGate by pointing a LDAP server connectivity test request to a rogue LDAP server.

Required action: Apply updates per vendor instructions.

Added Sep 8, 2022 · due Sep 29, 2022CVE-2018-13374

D-Link Multiple Routers

RansomwarePast due 1448d

D-Link Multiple Routers OS Command Injection Vulnerability

Multiple D-Link routers contain an unspecified vulnerability that allows for execution of OS commands.

Required action: The vendor D-Link published an advisory stating the fix under CVE-2018-20114 properly patches KEV entry CVE-2018-6530. If the device is still supported, apply updates per vendor instructions. If the affected device has since entered its end-of-life, it should be disconnected if still in use.

Added Sep 8, 2022 · due Sep 29, 2022CVE-2018-6530

F5 BIG-IP

RansomwarePast due 1569d

F5 BIG-IP Missing Authentication Vulnerability

F5 BIG-IP contains a missing authentication in critical function vulnerability which can allow for remote code execution, creation or deletion of files, or disabling services.

Required action: Apply updates per vendor instructions.

Added May 10, 2022 · due May 31, 2022CVE-2022-1388

Dasan Gigabit Passive Optical Network (GPON) Routers

RansomwarePast due 1609d

Dasan GPON Routers Command Injection Vulnerability

Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10561, exploitation can allow an attacker to perform remote code execution.

Required action: The impacted product is end-of-life and should be disconnected if still in use.

Added Mar 31, 2022 · due Apr 21, 2022CVE-2018-10562

SonicWall Secure Remote Access (SRA)

RansomwarePast due 1612d

SonicWall Secure Remote Access (SRA) SQL Injection Vulnerability

SonicWall Secure Remote Access (SRA) products contain an improper neutralization of a SQL Command leading to SQL injection.

Required action: The impacted product is end-of-life and should be disconnected if still in use.

Added Mar 28, 2022 · due Apr 18, 2022CVE-2021-20028

Palo Alto Networks PAN-OS

RansomwarePast due 1615d

Palo Alto Networks PAN-OS Authentication Bypass Vulnerability

Palo Alto Networks PAN-OS contains a vulnerability in SAML which allows an attacker to bypass authentication.

Required action: Apply updates per vendor instructions.

Added Mar 25, 2022 · due Apr 15, 2022CVE-2020-2021

Citrix ShareFile

RansomwarePast due 1615d

Citrix ShareFile Improper Access Control Vulnerability

Improper Access Control in Citrix ShareFile storage zones controller may allow an unauthenticated attacker to remotely compromise the storage zones controller.

Required action: Apply updates per vendor instructions.

Added Mar 25, 2022 · due Apr 15, 2022CVE-2021-22941

SonicWall SonicOS

RansomwarePast due 1625d

SonicWall SonicOS Buffer Overflow Vulnerability

A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a malicious request to the firewall.

Required action: Apply updates per vendor instructions.

Added Mar 15, 2022 · due Apr 5, 2022CVE-2020-5135

SonicWall SMA 100 Appliances

RansomwarePast due 1678d

SonicWall SMA 100 Appliances Stack-Based Buffer Overflow Vulnerability

SonicWall SMA 100 devies are vulnerable to an unauthenticated stack-based buffer overflow vulnerability where exploitation can result in code execution.

Required action: Apply updates per vendor instructions.

Added Jan 28, 2022 · due Feb 11, 2022CVE-2021-20038

Fortinet FortiOS and FortiProxy

RansomwarePast due 1529d

Fortinet FortiOS and FortiProxy Improper Authorization

An Improper Authorization vulnerability in Fortinet FortiOS and FortiProxy under SSL VPN web portal allows an unauthenticated attacker to modify the password.

Required action: Apply updates per vendor instructions.

Added Jan 10, 2022 · due Jul 10, 2022CVE-2018-13382

Fortinet FortiOS and FortiProxy

RansomwarePast due 1529d

Fortinet FortiOS and FortiProxy Out-of-bounds Write

A heap buffer overflow in Fortinet FortiOS and FortiProxy may cause the SSL VPN web service termination for logged in users.

Required action: Apply updates per vendor instructions.

Added Jan 10, 2022 · due Jul 10, 2022CVE-2018-13383

Palo Alto Networks PAN-OS

RansomwarePast due 1529d

Palo Alto Networks PAN-OS Remote Code Execution Vulnerability

Remote Code Execution in PAN-OS with GlobalProtect Portal or GlobalProtect Gateway Interface enabled.

Required action: Apply updates per vendor instructions.

Added Jan 10, 2022 · due Jul 10, 2022CVE-2019-1579

Fortinet FortiOS

RansomwarePast due 1597d

Fortinet FortiOS SSL VPN Path Traversal Vulnerability

Fortinet FortiOS SSL VPN web portal contains a path traversal vulnerability that may allow an unauthenticated attacker to download FortiOS system files through specially crafted HTTP resource requests.

Required action: Apply updates per vendor instructions.

Added Nov 3, 2021 · due May 3, 2022CVE-2018-13379

Ivanti Pulse Connect Secure

RansomwarePast due 1597d

Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability

Ivanti Pulse Connect Secure contains an arbitrary file read vulnerability that allows an unauthenticated remote attacker with network access via HTTPS to send a specially crafted URI.

Required action: Apply updates per vendor instructions.

Added Nov 3, 2021 · due May 3, 2022CVE-2019-11510

Ivanti Pulse Connect Secure and Pulse Policy Secure

RansomwarePast due 1597d

Ivanti Pulse Connect Secure and Policy Secure Command Injection Vulnerability

Ivanti Pulse Connect Secure and Policy Secure allows an authenticated attacker from the admin web interface to inject and execute commands.

Required action: Apply updates per vendor instructions.

Added Nov 3, 2021 · due May 3, 2022CVE-2019-11539

Citrix Workspace Application and Receiver for Windows

RansomwarePast due 1597d

Citrix Workspace Application and Receiver for Windows Remote Code Execution Vulnerability

Citrix Workspace Application and Receiver for Windows contains remote code execution vulnerability resulting from local drive access preferences not being enforced into the clients' local drives.

Required action: Apply updates per vendor instructions.

Added Nov 3, 2021 · due May 3, 2022CVE-2019-11634

Citrix StoreFront Server

RansomwarePast due 1597d

Citrix StoreFront Server XML External Entity (XXE) Processing Vulnerability

Citrix StoreFront Server contains an XML External Entity (XXE) processing vulnerability that may allow an unauthenticated attacker to retrieve potentially sensitive information.

Required action: Apply updates per vendor instructions.

Added Nov 3, 2021 · due May 3, 2022CVE-2019-13608

Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance

RansomwarePast due 1597d

Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution Vulnerability

Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an unspecified vulnerability that could allow an unauthenticated attacker to perform code execution.

Required action: Apply updates per vendor instructions.

Added Nov 3, 2021 · due May 3, 2022CVE-2019-19781
1 entry

Productivity & business apps

Adobe, Zoom, web platforms, and the apps that run the office.

Broadcom VMware vCenter

RansomwarePast due 26d

Broadcom VMware vCenter Path Traversal Vulnerability

Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code.

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Added Aug 18, 2026 · due Aug 21, 2026CVE-2026-59310
Keep going

Close the gaps these flaws exploit

Threat Radar tells you what's being attacked. These tools help you check whether you're exposed.

Web & DNS posture

Many KEV entries hit internet-facing services. Scan your TLS, security headers, and DNS hardening.

Open Web Security →

Email authentication

Phishing is the usual delivery vehicle for these exploits. Verify your SPF, DKIM, and DMARC are enforcing.

Open Email Security →

Data source: CISA Known Exploited Vulnerabilities Catalog (JSON feed), released into the public domain under CC0. “SMB relevance” bucketing and ranking are ours — they're a heuristic to help you triage, not a statement of CISA endorsement. The federal remediation due-dates apply to U.S. government agencies; we surface them as a useful urgency signal for everyone. Need the raw ranked data? /threat-radar.json.

Get alerts when your domain is exposed

Threat Radar shows what's being exploited in the wild. Run a free scan of your own site to see whether you're exposed — then let Resolute watch it for you and flag new risks as they land.