Skip to content

Threat Radar

The vulnerabilities being exploited right now — filtered to what you run.

CISA publishes a catalog of security flaws confirmed to be under active attack. We rank it for the small-business stack — Microsoft, Google, Apple, your firewall/VPN, and everyday apps — and flag the ones tied to ransomware or past their federal remediation deadline.

In the catalog

1,611

Actively exploited CVEs (all vendors)

Relevant to SMBs

1,122

Matched to common business products

Ransomware-linked

325

Used in known ransomware campaigns

Added this week

5

New entries in the last 7 days

SourceFetched live from CISA just now.
1 entry

Microsoft

Windows, Exchange, Office, and the rest of the Microsoft stack.

Microsoft Exchange Server

RansomwarePast due 38d

Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability

Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution.

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Added Apr 13, 2026 · due Apr 27, 2026CVE-2023-21529
57 entries

Networking & VPN

Firewalls, routers, and remote-access gear at the network edge.

Cisco Secure Firewall Management Center (FMC)

RansomwarePast due 74d

Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability

Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain a deserialization of untrusted data vulnerability in the web-based management interface that could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device.

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Added Mar 19, 2026 · due Mar 22, 2026CVE-2026-20131

Citrix NetScaler ADC and Gateway

RansomwarePast due 328d

Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability

Citrix NetScaler ADC and Gateway contain an out-of-bounds read vulnerability due to insufficient input validation. This vulnerability can lead to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server.

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Added Jul 10, 2025 · due Jul 11, 2025CVE-2025-5777

Fortinet FortiOS

RansomwarePast due 323d

Fortinet FortiOS Use of Hard-Coded Credentials Vulnerability

Fortinet FortiOS contains a use of hard-coded credentials vulnerability that could allow an attacker to cipher sensitive data in FortiOS configuration backup file via knowledge of the hard-coded key.

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Added Jun 25, 2025 · due Jul 16, 2025CVE-2019-6693

Ivanti Connect Secure, Policy Secure, and ZTA Gateways

RansomwarePast due 419d

Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability

Ivanti Connect Secure, Policy Secure, and ZTA Gateways contains a stack-based buffer overflow vulnerability that allows a remote unauthenticated attacker to achieve remote code execution.

Required action: Apply mitigations as set forth in the CISA instructions linked below.

Added Apr 4, 2025 · due Apr 11, 2025CVE-2025-22457

Fortinet FortiOS and FortiProxy

RansomwarePast due 422d

Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability

Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that allows a remote attacker to gain super-admin privileges via crafted CSF proxy requests.

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Added Mar 18, 2025 · due Apr 8, 2025CVE-2025-24472

SonicWall SonicOS

RansomwarePast due 450d

SonicWall SonicOS SSLVPN Improper Authentication Vulnerability

SonicWall SonicOS contains an improper authentication vulnerability in the SSLVPN authentication mechanism that allows a remote attacker to bypass authentication.

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added Feb 18, 2025 · due Mar 11, 2025CVE-2024-53704

SonicWall SMA1000 Appliances

RansomwarePast due 475d

SonicWall SMA1000 Appliances Deserialization Vulnerability

SonicWall SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC) contain a deserialization of untrusted data vulnerability, which can enable a remote, unauthenticated attacker to execute arbitrary OS commands.

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added Jan 24, 2025 · due Feb 14, 2025CVE-2025-23006

Fortinet FortiOS and FortiProxy

RansomwarePast due 499d

Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability

Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that may allow an unauthenticated, remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added Jan 14, 2025 · due Jan 21, 2025CVE-2024-55591

Ivanti Connect Secure, Policy Secure, and ZTA Gateways

RansomwarePast due 505d

Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability

Ivanti Connect Secure, Policy Secure, and ZTA Gateways contain a stack-based buffer overflow which can lead to unauthenticated remote code execution.

Required action: Apply mitigations as set forth in the CISA instructions linked below to include conducting hunt activities, taking remediation actions if applicable, and applying updates prior to returning a device to service.

Added Jan 8, 2025 · due Jan 15, 2025CVE-2025-0282

Zyxel Multiple Firewalls

RansomwarePast due 527d

Zyxel Multiple Firewalls Path Traversal Vulnerability

Multiple Zyxel firewalls contain a path traversal vulnerability in the web management interface that could allow an attacker to download or upload files via a crafted URL.

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added Dec 3, 2024 · due Dec 24, 2024CVE-2024-11667

Palo Alto Networks PAN-OS

RansomwarePast due 542d

Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability

Palo Alto Networks PAN-OS contains an authentication bypass vulnerability in the web-based management interface for several PAN-OS products, including firewalls and VPN concentrators.

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Additionally, management interface for affected devices should not be exposed to untrusted networks, including the internet.

Added Nov 18, 2024 · due Dec 9, 2024CVE-2024-0012

Palo Alto Networks PAN-OS

RansomwarePast due 542d

Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability

Palo Alto Networks PAN-OS contains an OS command injection vulnerability that allows for privilege escalation through the web-based management interface for several PAN products, including firewalls and VPN concentrators.

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Additionally, the management interfaces for affected devices should not be exposed to untrusted networks, including the internet.

Added Nov 18, 2024 · due Dec 9, 2024CVE-2024-9474

SonicWall SonicOS

RansomwarePast due 612d

SonicWall SonicOS Improper Access Control Vulnerability

SonicWall SonicOS contains an improper access control vulnerability that could lead to unauthorized resource access and, under certain conditions, may cause the firewall to crash.

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added Sep 9, 2024 · due Sep 30, 2024CVE-2024-40766

Palo Alto Networks PAN-OS

RansomwarePast due 776d

Palo Alto Networks PAN-OS Command Injection Vulnerability

Palo Alto Networks PAN-OS GlobalProtect feature contains a command injection vulnerability that allows an unauthenticated attacker to execute commands with root privileges on the firewall.

Required action: Apply mitigations per vendor instructions as they become available. Otherwise, users with vulnerable versions of affected devices should enable Threat Prevention IDs available from the vendor. See the vendor bulletin for more details and a patch release schedule.

Added Apr 12, 2024 · due Apr 19, 2024CVE-2024-3400

Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA)

RansomwarePast due 780d

Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) Code Injection Vulnerability

Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) contains a code injection vulnerability that allows an unauthenticated user to execute malicious code with limited permissions (nobody).

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added Mar 25, 2024 · due Apr 15, 2024CVE-2021-44529

Fortinet FortiClient EMS

RansomwarePast due 780d

Fortinet FortiClient EMS SQL Injection Vulnerability

Fortinet FortiClient EMS contains a SQL injection vulnerability that allows an unauthenticated attacker to execute commands as SYSTEM via specifically crafted requests.

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added Mar 25, 2024 · due Apr 15, 2024CVE-2023-48788

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)

RansomwarePast due 819d

Cisco ASA and FTD Information Disclosure Vulnerability

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an information disclosure vulnerability. An attacker could retrieve memory contents on an affected device, which could lead to the disclosure of confidential information due to a buffer tracking issue when the software parses invalid URLs that are requested from the web services interface. This vulnerability affects only specific AnyConnect and WebVPN configurations.

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added Feb 15, 2024 · due Mar 7, 2024CVE-2020-3259

Fortinet FortiOS

RansomwarePast due 839d

Fortinet FortiOS Out-of-Bound Write Vulnerability

Fortinet FortiOS contains an out-of-bound write vulnerability that allows a remote unauthenticated attacker to execute code or commands via specially crafted HTTP requests.

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added Feb 9, 2024 · due Feb 16, 2024CVE-2024-21762

Ivanti Connect Secure, Policy Secure, and Neurons

RansomwarePast due 853d

Ivanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) Vulnerability

Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure), Ivanti Policy Secure, and Ivanti Neurons contain a server-side request forgery (SSRF) vulnerability in the SAML component that allows an attacker to access certain restricted resources without authentication.

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added Jan 31, 2024 · due Feb 2, 2024CVE-2024-21893

Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core

RansomwarePast due 847d

Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass Vulnerability

Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core contain an authentication bypass vulnerability that allows unauthorized users to access restricted functionality or resources of the application.

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added Jan 18, 2024 · due Feb 8, 2024CVE-2023-35082

Ivanti Connect Secure and Policy Secure

RansomwarePast due 864d

Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability

Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure gateways contain an authentication bypass vulnerability in the web component that allows an attacker to access restricted resources by bypassing control checks. This vulnerability can be leveraged in conjunction with CVE-2024-21887, a command injection vulnerability.

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added Jan 10, 2024 · due Jan 22, 2024CVE-2023-46805

Ivanti Connect Secure and Policy Secure

RansomwarePast due 864d

Ivanti Connect Secure and Policy Secure Command Injection Vulnerability

Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure contain a command injection vulnerability in the web components of these products, which can allow an authenticated administrator to send crafted requests to execute code on affected appliances. This vulnerability can be leveraged in conjunction with CVE-2023-46805, an authenticated bypass issue.

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added Jan 10, 2024 · due Jan 22, 2024CVE-2024-21887

F5 BIG-IP Configuration Utility

RansomwarePast due 926d

F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability

F5 BIG-IP Configuration utility contains an authentication bypass using an alternate path or channel vulnerability due to undisclosed requests that may allow an unauthenticated attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute system commands. This vulnerability can be used in conjunction with CVE-2023-46748.

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added Oct 31, 2023 · due Nov 21, 2023CVE-2023-46747

Citrix NetScaler ADC and NetScaler Gateway

RansomwarePast due 939d

Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability

Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for sensitive information disclosure when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.

Required action: Apply mitigations and kill all active and persistent sessions per vendor instructions [https://www.netscaler.com/blog/news/cve-2023-4966-critical-security-update-now-available-for-netscaler-adc-and-netscaler-gateway/] OR discontinue use of the product if mitigations are unavailable.

Added Oct 18, 2023 · due Nov 8, 2023CVE-2023-4966

Zyxel EMG2926 Routers

RansomwarePast due 969d

Zyxel EMG2926 Routers Command Injection Vulnerability

Zyxel EMG2926 routers contain a command injection vulnerability located in the diagnostic tools, specifically the nslookup function. A malicious user may exploit numerous vectors to execute malicious commands on the router, such as the ping_ip parameter to the expert/maintenance/diagnostic/nslookup URI.

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added Sep 18, 2023 · due Oct 9, 2023CVE-2017-6884

Cisco Adaptive Security Appliance and Firepower Threat Defense

RansomwarePast due 974d

Cisco Adaptive Security Appliance and Firepower Threat Defense Unauthorized Access Vulnerability

Cisco Adaptive Security Appliance and Firepower Threat Defense contain an unauthorized access vulnerability that could allow an unauthenticated, remote attacker to conduct a brute force attack in an attempt to identify valid username and password combinations or establish a clientless SSL VPN session with an unauthorized user.

Required action: Apply mitigations per vendor instructions for group-lock and vpn-simultaneous-logins or discontinue use of the product for unsupported devices.

Added Sep 13, 2023 · due Oct 4, 2023CVE-2023-20269

Ivanti Sentry

RansomwarePast due 996d

Ivanti Sentry Authentication Bypass Vulnerability

Ivanti Sentry, formerly known as MobileIron Sentry, contains an authentication bypass vulnerability that may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTTPD configuration.

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added Aug 22, 2023 · due Sep 12, 2023CVE-2023-38035

Ivanti Endpoint Manager Mobile (EPMM)

RansomwarePast due 1024d

Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability

Ivanti Endpoint Manager Mobile (EPMM, previously branded MobileIron Core) contains an authentication bypass vulnerability that allows unauthenticated access to specific API paths. An attacker with access to these API paths can access personally identifiable information (PII) such as names, phone numbers, and other mobile device details for users on a vulnerable system. An attacker can also make other configuration changes including installing software and modifying security profiles on registered devices.

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added Jul 25, 2023 · due Aug 15, 2023CVE-2023-35078

Citrix NetScaler ADC and NetScaler Gateway

RansomwarePast due 1030d

Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability

Citrix NetScaler ADC and NetScaler Gateway contains a code injection vulnerability that allows for unauthenticated remote code execution.

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added Jul 19, 2023 · due Aug 9, 2023CVE-2023-3519

Fortinet FortiOS and FortiProxy SSL-VPN

RansomwarePast due 1066d

Fortinet FortiOS and FortiProxy SSL-VPN Heap-Based Buffer Overflow Vulnerability

Fortinet FortiOS and FortiProxy SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker to execute code or commands via specifically crafted requests.

Required action: Apply updates per vendor instructions.

Added Jun 13, 2023 · due Jul 4, 2023CVE-2023-27997

Fortinet FortiOS

RansomwarePast due 1248d

Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability

Multiple versions of Fortinet FortiOS SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker to execute arbitrary code or commands via specifically crafted requests.

Required action: Apply updates per vendor instructions.

Added Dec 13, 2022 · due Jan 3, 2023CVE-2022-42475

Cisco AnyConnect Secure

RansomwarePast due 1298d

Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability

Cisco AnyConnect Secure Mobility Client for Windows allows for incorrect handling of directory paths. An attacker with valid credentials on Windows would be able to copy malicious files to arbitrary locations with system level privileges. This could include DLL pre-loading, DLL hijacking, and other related attacks.

Required action: Apply updates per vendor instructions.

Added Oct 24, 2022 · due Nov 14, 2022CVE-2020-3153

Cisco AnyConnect Secure

RansomwarePast due 1298d

Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability

Cisco AnyConnect Secure Mobility Client for Windows interprocess communication (IPC) channel allows for insufficient validation of resources that are loaded by the application at run time. An attacker with valid credentials on Windows could execute code on the affected machine with SYSTEM privileges.

Required action: Apply updates per vendor instructions.

Added Oct 24, 2022 · due Nov 14, 2022CVE-2020-3433

Fortinet Multiple Products

RansomwarePast due 1311d

Fortinet Multiple Products Authentication Bypass Vulnerability

Fortinet FortiOS, FortiProxy, and FortiSwitchManager contain an authentication bypass vulnerability that could allow an unauthenticated attacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.

Required action: Apply updates per vendor instructions.

Added Oct 11, 2022 · due Nov 1, 2022CVE-2022-40684

Fortinet FortiOS and FortiADC

RansomwarePast due 1344d

Fortinet FortiOS and FortiADC Improper Access Control Vulnerability

Fortinet FortiOS and FortiADC contain an improper access control vulnerability that allows attackers to obtain the LDAP server login credentials configured in FortiGate by pointing a LDAP server connectivity test request to a rogue LDAP server.

Required action: Apply updates per vendor instructions.

Added Sep 8, 2022 · due Sep 29, 2022CVE-2018-13374

D-Link Multiple Routers

RansomwarePast due 1344d

D-Link Multiple Routers OS Command Injection Vulnerability

Multiple D-Link routers contain an unspecified vulnerability that allows for execution of OS commands.

Required action: The vendor D-Link published an advisory stating the fix under CVE-2018-20114 properly patches KEV entry CVE-2018-6530. If the device is still supported, apply updates per vendor instructions. If the affected device has since entered its end-of-life, it should be disconnected if still in use.

Added Sep 8, 2022 · due Sep 29, 2022CVE-2018-6530

F5 BIG-IP

RansomwarePast due 1465d

F5 BIG-IP Missing Authentication Vulnerability

F5 BIG-IP contains a missing authentication in critical function vulnerability which can allow for remote code execution, creation or deletion of files, or disabling services.

Required action: Apply updates per vendor instructions.

Added May 10, 2022 · due May 31, 2022CVE-2022-1388

Dasan Gigabit Passive Optical Network (GPON) Routers

RansomwarePast due 1505d

Dasan GPON Routers Command Injection Vulnerability

Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10561, exploitation can allow an attacker to perform remote code execution.

Required action: The impacted product is end-of-life and should be disconnected if still in use.

Added Mar 31, 2022 · due Apr 21, 2022CVE-2018-10562

SonicWall Secure Remote Access (SRA)

RansomwarePast due 1508d

SonicWall Secure Remote Access (SRA) SQL Injection Vulnerability

SonicWall Secure Remote Access (SRA) products contain an improper neutralization of a SQL Command leading to SQL injection.

Required action: The impacted product is end-of-life and should be disconnected if still in use.

Added Mar 28, 2022 · due Apr 18, 2022CVE-2021-20028

Palo Alto Networks PAN-OS

RansomwarePast due 1511d

Palo Alto Networks PAN-OS Authentication Bypass Vulnerability

Palo Alto Networks PAN-OS contains a vulnerability in SAML which allows an attacker to bypass authentication.

Required action: Apply updates per vendor instructions.

Added Mar 25, 2022 · due Apr 15, 2022CVE-2020-2021

Citrix ShareFile

RansomwarePast due 1511d

Citrix ShareFile Improper Access Control Vulnerability

Improper Access Control in Citrix ShareFile storage zones controller may allow an unauthenticated attacker to remotely compromise the storage zones controller.

Required action: Apply updates per vendor instructions.

Added Mar 25, 2022 · due Apr 15, 2022CVE-2021-22941

SonicWall SMA 100 Appliances

RansomwarePast due 1574d

SonicWall SMA 100 Appliances Stack-Based Buffer Overflow Vulnerability

SonicWall SMA 100 devies are vulnerable to an unauthenticated stack-based buffer overflow vulnerability where exploitation can result in code execution.

Required action: Apply updates per vendor instructions.

Added Jan 28, 2022 · due Feb 11, 2022CVE-2021-20038

Fortinet FortiOS and FortiProxy

RansomwarePast due 1425d

Fortinet FortiOS and FortiProxy Improper Authorization

An Improper Authorization vulnerability in Fortinet FortiOS and FortiProxy under SSL VPN web portal allows an unauthenticated attacker to modify the password.

Required action: Apply updates per vendor instructions.

Added Jan 10, 2022 · due Jul 10, 2022CVE-2018-13382

Fortinet FortiOS and FortiProxy

RansomwarePast due 1425d

Fortinet FortiOS and FortiProxy Out-of-bounds Write

A heap buffer overflow in Fortinet FortiOS and FortiProxy may cause the SSL VPN web service termination for logged in users.

Required action: Apply updates per vendor instructions.

Added Jan 10, 2022 · due Jul 10, 2022CVE-2018-13383

Palo Alto Networks PAN-OS

RansomwarePast due 1425d

Palo Alto Networks PAN-OS Remote Code Execution Vulnerability

Remote Code Execution in PAN-OS with GlobalProtect Portal or GlobalProtect Gateway Interface enabled.

Required action: Apply updates per vendor instructions.

Added Jan 10, 2022 · due Jul 10, 2022CVE-2019-1579

Fortinet FortiOS

RansomwarePast due 1493d

Fortinet FortiOS SSL VPN Path Traversal Vulnerability

Fortinet FortiOS SSL VPN web portal contains a path traversal vulnerability that may allow an unauthenticated attacker to download FortiOS system files through specially crafted HTTP resource requests.

Required action: Apply updates per vendor instructions.

Added Nov 3, 2021 · due May 3, 2022CVE-2018-13379

Ivanti Pulse Connect Secure

RansomwarePast due 1493d

Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability

Ivanti Pulse Connect Secure contains an arbitrary file read vulnerability that allows an unauthenticated remote attacker with network access via HTTPS to send a specially crafted URI.

Required action: Apply updates per vendor instructions.

Added Nov 3, 2021 · due May 3, 2022CVE-2019-11510

Ivanti Pulse Connect Secure and Pulse Policy Secure

RansomwarePast due 1493d

Ivanti Pulse Connect Secure and Policy Secure Command Injection Vulnerability

Ivanti Pulse Connect Secure and Policy Secure allows an authenticated attacker from the admin web interface to inject and execute commands.

Required action: Apply updates per vendor instructions.

Added Nov 3, 2021 · due May 3, 2022CVE-2019-11539

Citrix Workspace Application and Receiver for Windows

RansomwarePast due 1493d

Citrix Workspace Application and Receiver for Windows Remote Code Execution Vulnerability

Citrix Workspace Application and Receiver for Windows contains remote code execution vulnerability resulting from local drive access preferences not being enforced into the clients' local drives.

Required action: Apply updates per vendor instructions.

Added Nov 3, 2021 · due May 3, 2022CVE-2019-11634

Citrix StoreFront Server

RansomwarePast due 1493d

Citrix StoreFront Server XML External Entity (XXE) Processing Vulnerability

Citrix StoreFront Server contains an XML External Entity (XXE) processing vulnerability that may allow an unauthenticated attacker to retrieve potentially sensitive information.

Required action: Apply updates per vendor instructions.

Added Nov 3, 2021 · due May 3, 2022CVE-2019-13608

Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance

RansomwarePast due 1493d

Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution Vulnerability

Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an unspecified vulnerability that could allow an unauthenticated attacker to perform code execution.

Required action: Apply updates per vendor instructions.

Added Nov 3, 2021 · due May 3, 2022CVE-2019-19781

SonicWall SMA100

RansomwarePast due 1493d

SonicWall SMA100 SQL Injection Vulnerability

SonicWall SMA100 contains a SQL injection vulnerability allowing an unauthenticated user to gain read-only access to unauthorized resources.

Required action: Apply updates per vendor instructions.

Added Nov 3, 2021 · due May 3, 2022CVE-2019-7481

Sophos SFOS

RansomwarePast due 1493d

Sophos SFOS SQL Injection Vulnerability

Sophos Firewall operating system (SFOS) firmware contains a SQL injection vulnerability when configured with either the administration (HTTPS) service or the User Portal is exposed on the WAN zone. Successful exploitation may cause remote code execution to exfiltrate usernames and hashed passwords for the local device admin(s), portal admins, and user accounts used for remote access (but not external Active Directory or LDAP passwords).

Required action: Apply updates per vendor instructions.

Added Nov 3, 2021 · due May 3, 2022CVE-2020-12271

Fortinet FortiOS

RansomwarePast due 1493d

Fortinet FortiOS SSL VPN Improper Authentication Vulnerability

Fortinet FortiOS SSL VPN contains an improper authentication vulnerability that may allow a user to login successfully without being prompted for the second factor of authentication (FortiToken) if they change the case in their username.

Required action: Apply updates per vendor instructions.

Added Nov 3, 2021 · due May 3, 2022CVE-2020-12812

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)

RansomwarePast due 1493d

Cisco ASA and FTD Cross-Site Scripting (XSS) Vulnerability

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an insufficient input validation vulnerability for user-supplied input by the web services interface. Successful exploitation could allow an attacker to perform cross-site scripting (XSS) in the context of the interface or access sensitive browser-based information.

Required action: Apply updates per vendor instructions.

Added Nov 3, 2021 · due May 3, 2022CVE-2020-3580

F5 BIG-IP

RansomwarePast due 1493d

F5 BIG-IP Traffic Management User Interface (TMUI) Remote Code Execution Vulnerability

F5 BIG-IP Traffic Management User Interface (TMUI) contains a remote code execution vulnerability in undisclosed pages.

Required action: Apply updates per vendor instructions.

Added Nov 3, 2021 · due May 3, 2022CVE-2020-5902

SonicWall SSLVPN SMA100

RansomwarePast due 1660d

SonicWall SSLVPN SMA100 SQL Injection Vulnerability

SonicWall SSLVPN SMA100 contains a SQL injection vulnerability that allows remote exploitation for credential access by an unauthenticated attacker.

Required action: Apply updates per vendor instructions.

Added Nov 3, 2021 · due Nov 17, 2021CVE-2021-20016
2 entries

Productivity & business apps

Adobe, Zoom, web platforms, and the apps that run the office.

WebPros cPanel & WHM and WP2 (WordPress Squared)

RansomwarePast due 32d

WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability

WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Added Apr 30, 2026 · due May 3, 2026CVE-2026-41940

PaperCut NG/MF

RansomwarePast due 31d

PaperCut NG/MF Improper Authentication Vulnerability

PaperCut NG/MF contains an improper authentication vulnerability that could allow remote attackers to bypass authentication on affected installations via the SecurityRequestFilter class.

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Added Apr 20, 2026 · due May 4, 2026CVE-2023-27351
Keep going

Close the gaps these flaws exploit

Threat Radar tells you what's being attacked. These tools help you check whether you're exposed.

Web & DNS posture

Many KEV entries hit internet-facing services. Scan your TLS, security headers, and DNS hardening.

Open Web Security →

Email authentication

Phishing is the usual delivery vehicle for these exploits. Verify your SPF, DKIM, and DMARC are enforcing.

Open Email Security →

Data source: CISA Known Exploited Vulnerabilities Catalog (JSON feed), released into the public domain under CC0. “SMB relevance” bucketing and ranking are ours — they're a heuristic to help you triage, not a statement of CISA endorsement. The federal remediation due-dates apply to U.S. government agencies; we surface them as a useful urgency signal for everyone. Need the raw ranked data? /threat-radar.json.