CISA Known Exploited Vulnerabilities
Exploited CVEs
52 CVEs in the products we track are exploited in the wild, 22 of them in ransomware attacks. Newest first. Full analysis marks the CVEs we've written up in depth; the rest link to an automatic summary.
| Added to KEV | CVE | Vendor / product | Issue | Severity | EPSS |
|---|---|---|---|---|---|
| CVE-2026-104286Full analysis | Fortinet · FortiMail | FortiMail Path Traversal | CRITICAL | 2.2% | |
| CVE-2026-93616Full analysis | Check Point · Security Management and SmartConsole | Directory Traversal and File upload allows execution of arbitrary script on the Management Server | CRITICAL | 20% | |
| CVE-2026-85102Full analysis | Check Point · Quantum Security Gateway | Improper Certificate Validation in Quantum Security Gateway | CRITICAL | 7.5% | |
| CVE-2025-25249Full analysis | Fortinet · FortiOS | Heap-based buffer overflow in FortiOS, FortiSwitchManager | HIGH | 3.8% | |
| CVE-2025-68686 | Fortinet · FortiOS | FortiOS Exposure of Sensitive Information to an Unauthorized Actor | MEDIUM | 29% | |
| CVE-2026-16232 | Check Point · Security Management and SmartConsole | Authentication Bypass in the SmartConsole Login Process Using an Application Token | CRITICAL | 78% | |
| CVE-2026-25089 | Fortinet · FortiSandbox | FortiSandbox OS Command Injection | CRITICAL | 76% | |
| CVE-2026-39808 | Fortinet · FortiSandbox | FortiSandbox OS Command Injection | CRITICAL | 47% | |
| CVE-2026-50751Full analysis | Check Point · Quantum Security Gateway | User Authentication Bypass in VPN Remote Access and Mobile AccessRansomware | CRITICAL | 85% | |
| CVE-2026-0257Full analysis | Palo Alto Networks · PAN-OS | GlobalProtect Authentication Bypass VulnerabilitiesRansomware | HIGH | 97% | |
| CVE-2026-0300Full analysis | Palo Alto Networks · PAN-OS | Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal | CRITICAL | 32% | |
| CVE-2026-21643 | Fortinet · FortiClient and EMS | FortiClient EMS SQL Injection | CRITICAL | 94% | |
| CVE-2026-35616 | Fortinet · FortiClient and EMS | FortiClient EMS Improper Access Control | CRITICAL | 9.1% | |
| CVE-2026-24858Full analysis | Fortinet · FortiOS | Authentication Bypass Using an Alternate Path or Channel in FortiOS, FortiProxy and others | CRITICAL | 86% | |
| CVE-2025-59718 | Fortinet · FortiOS | Improper verification of cryptographic signature in FortiOS, FortiProxy and others | CRITICAL | 68% | |
| CVE-2025-58034 | Fortinet · FortiWeb | FortiWeb OS Command Injection | MEDIUM | 56% | |
| CVE-2025-64446Full analysis | Fortinet · FortiWeb | FortiWeb Path Traversal | CRITICAL | 92% | |
| CVE-2025-25257 | Fortinet · FortiWeb | FortiWeb SQL Injection | CRITICAL | 100% | |
| CVE-2019-6693 | Fortinet · FortiOS | FortiOS Use of Hard-Coded CredentialsRansomware | MEDIUM | 5.8% | |
| CVE-2025-32756 | Fortinet · FortiMail | Stack-based buffer overflow in FortiMail, FortiVoice and others | CRITICAL | 31% | |
| CVE-2025-24472 | Fortinet · FortiOS | FortiOS and FortiProxy Authentication BypassRansomware | HIGH | 7.2% | |
| CVE-2025-0111 | Palo Alto Networks · PAN-OS | Authenticated File Read Vulnerability in the Management Web Interface | HIGH | 2.0% | |
| CVE-2025-0108Full analysis | Palo Alto Networks · PAN-OS | Authentication Bypass in the Management Web Interface | HIGH | 98% | |
| CVE-2024-55591 | Fortinet · FortiOS | FortiOS and FortiProxy Authentication BypassRansomware | CRITICAL | 94% | |
| CVE-2024-3393 | Palo Alto Networks · PAN-OS | Firewall Denial of Service (DoS) in DNS Security Using a Specially Crafted Packet | HIGH | 29% | |
| CVE-2024-9474Full analysis | Palo Alto Networks · PAN-OS | Privilege Escalation (PE) Vulnerability in the Web Management InterfaceRansomware | MEDIUM | 95% | |
| CVE-2024-0012Full analysis | Palo Alto Networks · PAN-OS | Authentication Bypass in the Management Web InterfaceRansomware | CRITICAL | 100% | |
| CVE-2024-9465 | Palo Alto Networks · Expedition | Multiple Vulnerabilities in Expedition Lead to Exposure of Firewall Credentials | CRITICAL | 100% | |
| CVE-2024-9463 | Palo Alto Networks · Expedition | Multiple Vulnerabilities in Expedition Lead to Exposure of Firewall Credentials | CRITICAL | 99% | |
| CVE-2024-5910 | Palo Alto Networks · Expedition | Missing Authentication Leads to Admin Account Takeover | CRITICAL | 92% | |
| CVE-2024-47575 | Fortinet · FortiManager and FortiAnalyzer | FortiManager Missing Authentication | CRITICAL | 95% | |
| CVE-2024-23113 | Fortinet · FortiOS | Use of externally-controlled format string in FortiOS, FortiProxy and others | CRITICAL | 62% | |
| CVE-2024-24919 | Check Point · Quantum Security Gateway | Quantum Security Gateways Information DisclosureRansomware | HIGH | 100% | |
| CVE-2024-3400Full analysis | Palo Alto Networks · PAN-OS | Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtectRansomware | CRITICAL | 100% | |
| CVE-2023-48788 | Fortinet · FortiClient and EMS | FortiClient EMS SQL InjectionRansomware | CRITICAL | 98% | |
| CVE-2024-21762 | Fortinet · FortiOS | FortiOS Out-of-Bound WriteRansomware | CRITICAL | 83% | |
| CVE-2023-27997 | Fortinet · FortiOS | FortiOS and FortiProxy SSL-VPN Heap-Based Buffer OverflowRansomware | CRITICAL | 86% | |
| CVE-2022-41328 | Fortinet · FortiOS | FortiOS Path Traversal | MEDIUM | 11% | |
| CVE-2022-42475 | Fortinet · FortiOS | FortiOS Heap-Based Buffer OverflowRansomware | CRITICAL | 99% | |
| CVE-2022-40684 | Fortinet · FortiOS | Authentication bypass using an alternate path or channel in Fortinet FortiOS, FortiProxy, FortiSwitchManagerRansomware | CRITICAL | 100% | |
| CVE-2018-13374 | Fortinet · FortiOS | FortiOS and FortiADC Improper Access ControlRansomware | MEDIUM | 38% | |
| CVE-2022-0028 | Palo Alto Networks · PAN-OS | Reflected Amplification Denial-of-Service (DoS) Vulnerability in URL Filtering | HIGH | 2.5% | |
| CVE-2017-15944 | Palo Alto Networks · PAN-OS | Vulnerability in PAN-OS and Panorama on Management Interface | CRITICAL | 98% | |
| CVE-2020-2021 | Palo Alto Networks · PAN-OS | Authentication Bypass in SAML AuthenticationRansomware | CRITICAL | 4.4% | |
| CVE-2019-1579 | Palo Alto Networks · PAN-OS | Remote Code Execution in GlobalProtect Portal/Gateway InterfaceRansomware | HIGH | 46% | |
| CVE-2018-13382 | Fortinet · FortiOS | FortiOS and FortiProxy Improper AuthorizationRansomware | CRITICAL | 82% | |
| CVE-2018-13383 | Fortinet · FortiOS | FortiOS and FortiProxy Out-of-bounds WriteRansomware | MEDIUM | 34% | |
| CVE-2021-44168 | Fortinet · FortiOS | FortiOS Arbitrary File Download | LOW | 0.86% | |
| CVE-2019-5591 | Fortinet · FortiOS | FortiOS Default ConfigurationRansomware | MEDIUM | 19% | |
| CVE-2020-12812 | Fortinet · FortiOS | FortiOS SSL VPN Improper AuthenticationRansomware | HIGH | 45% | |
| CVE-2018-13379 | Fortinet · FortiOS | FortiOS SSL VPN Path TraversalRansomware | CRITICAL | 100% | |
| CVE-2017-6327 | Symantec · Messaging Gateway | Messaging Gateway Remote Code Execution | HIGH | 36% |
Source: CISA KEV catalog, refreshed daily.