CISA Known Exploited Vulnerabilities

Exploited CVEs

52 CVEs in the products we track are exploited in the wild, 22 of them in ransomware attacks. Newest first. Full analysis marks the CVEs we've written up in depth; the rest link to an automatic summary.

Added to KEVCVEVendor / productIssueSeverityEPSS
CVE-2026-104286Full analysisFortinet · FortiMailFortiMail Path TraversalCRITICAL2.2%
CVE-2026-93616Full analysisCheck Point · Security Management and SmartConsoleDirectory Traversal and File upload allows execution of arbitrary script on the Management ServerCRITICAL20%
CVE-2026-85102Full analysisCheck Point · Quantum Security GatewayImproper Certificate Validation in Quantum Security GatewayCRITICAL7.5%
CVE-2025-25249Full analysisFortinet · FortiOSHeap-based buffer overflow in FortiOS, FortiSwitchManagerHIGH3.8%
CVE-2025-68686Fortinet · FortiOSFortiOS Exposure of Sensitive Information to an Unauthorized ActorMEDIUM29%
CVE-2026-16232Check Point · Security Management and SmartConsoleAuthentication Bypass in the SmartConsole Login Process Using an Application TokenCRITICAL78%
CVE-2026-25089Fortinet · FortiSandboxFortiSandbox OS Command InjectionCRITICAL76%
CVE-2026-39808Fortinet · FortiSandboxFortiSandbox OS Command InjectionCRITICAL47%
CVE-2026-50751Full analysisCheck Point · Quantum Security GatewayUser Authentication Bypass in VPN Remote Access and Mobile AccessRansomwareCRITICAL85%
CVE-2026-0257Full analysisPalo Alto Networks · PAN-OSGlobalProtect Authentication Bypass VulnerabilitiesRansomwareHIGH97%
CVE-2026-0300Full analysisPalo Alto Networks · PAN-OSUnauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication PortalCRITICAL32%
CVE-2026-21643Fortinet · FortiClient and EMSFortiClient EMS SQL InjectionCRITICAL94%
CVE-2026-35616Fortinet · FortiClient and EMSFortiClient EMS Improper Access ControlCRITICAL9.1%
CVE-2026-24858Full analysisFortinet · FortiOSAuthentication Bypass Using an Alternate Path or Channel in FortiOS, FortiProxy and othersCRITICAL86%
CVE-2025-59718Fortinet · FortiOSImproper verification of cryptographic signature in FortiOS, FortiProxy and othersCRITICAL68%
CVE-2025-58034Fortinet · FortiWebFortiWeb OS Command InjectionMEDIUM56%
CVE-2025-64446Full analysisFortinet · FortiWebFortiWeb Path TraversalCRITICAL92%
CVE-2025-25257Fortinet · FortiWebFortiWeb SQL InjectionCRITICAL100%
CVE-2019-6693Fortinet · FortiOSFortiOS Use of Hard-Coded CredentialsRansomwareMEDIUM5.8%
CVE-2025-32756Fortinet · FortiMailStack-based buffer overflow in FortiMail, FortiVoice and othersCRITICAL31%
CVE-2025-24472Fortinet · FortiOSFortiOS and FortiProxy Authentication BypassRansomwareHIGH7.2%
CVE-2025-0111Palo Alto Networks · PAN-OSAuthenticated File Read Vulnerability in the Management Web InterfaceHIGH2.0%
CVE-2025-0108Full analysisPalo Alto Networks · PAN-OSAuthentication Bypass in the Management Web InterfaceHIGH98%
CVE-2024-55591Fortinet · FortiOSFortiOS and FortiProxy Authentication BypassRansomwareCRITICAL94%
CVE-2024-3393Palo Alto Networks · PAN-OSFirewall Denial of Service (DoS) in DNS Security Using a Specially Crafted PacketHIGH29%
CVE-2024-9474Full analysisPalo Alto Networks · PAN-OSPrivilege Escalation (PE) Vulnerability in the Web Management InterfaceRansomwareMEDIUM95%
CVE-2024-0012Full analysisPalo Alto Networks · PAN-OSAuthentication Bypass in the Management Web InterfaceRansomwareCRITICAL100%
CVE-2024-9465Palo Alto Networks · ExpeditionMultiple Vulnerabilities in Expedition Lead to Exposure of Firewall CredentialsCRITICAL100%
CVE-2024-9463Palo Alto Networks · ExpeditionMultiple Vulnerabilities in Expedition Lead to Exposure of Firewall CredentialsCRITICAL99%
CVE-2024-5910Palo Alto Networks · ExpeditionMissing Authentication Leads to Admin Account TakeoverCRITICAL92%
CVE-2024-47575Fortinet · FortiManager and FortiAnalyzerFortiManager Missing AuthenticationCRITICAL95%
CVE-2024-23113Fortinet · FortiOSUse of externally-controlled format string in FortiOS, FortiProxy and othersCRITICAL62%
CVE-2024-24919Check Point · Quantum Security GatewayQuantum Security Gateways Information DisclosureRansomwareHIGH100%
CVE-2024-3400Full analysisPalo Alto Networks · PAN-OSArbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtectRansomwareCRITICAL100%
CVE-2023-48788Fortinet · FortiClient and EMSFortiClient EMS SQL InjectionRansomwareCRITICAL98%
CVE-2024-21762Fortinet · FortiOSFortiOS Out-of-Bound WriteRansomwareCRITICAL83%
CVE-2023-27997Fortinet · FortiOSFortiOS and FortiProxy SSL-VPN Heap-Based Buffer OverflowRansomwareCRITICAL86%
CVE-2022-41328Fortinet · FortiOSFortiOS Path TraversalMEDIUM11%
CVE-2022-42475Fortinet · FortiOSFortiOS Heap-Based Buffer OverflowRansomwareCRITICAL99%
CVE-2022-40684Fortinet · FortiOSAuthentication bypass using an alternate path or channel in Fortinet FortiOS, FortiProxy, FortiSwitchManagerRansomwareCRITICAL100%
CVE-2018-13374Fortinet · FortiOSFortiOS and FortiADC Improper Access ControlRansomwareMEDIUM38%
CVE-2022-0028Palo Alto Networks · PAN-OSReflected Amplification Denial-of-Service (DoS) Vulnerability in URL FilteringHIGH2.5%
CVE-2017-15944Palo Alto Networks · PAN-OSVulnerability in PAN-OS and Panorama on Management InterfaceCRITICAL98%
CVE-2020-2021Palo Alto Networks · PAN-OSAuthentication Bypass in SAML AuthenticationRansomwareCRITICAL4.4%
CVE-2019-1579Palo Alto Networks · PAN-OSRemote Code Execution in GlobalProtect Portal/Gateway InterfaceRansomwareHIGH46%
CVE-2018-13382Fortinet · FortiOSFortiOS and FortiProxy Improper AuthorizationRansomwareCRITICAL82%
CVE-2018-13383Fortinet · FortiOSFortiOS and FortiProxy Out-of-bounds WriteRansomwareMEDIUM34%
CVE-2021-44168Fortinet · FortiOSFortiOS Arbitrary File DownloadLOW0.86%
CVE-2019-5591Fortinet · FortiOSFortiOS Default ConfigurationRansomwareMEDIUM19%
CVE-2020-12812Fortinet · FortiOSFortiOS SSL VPN Improper AuthenticationRansomwareHIGH45%
CVE-2018-13379Fortinet · FortiOSFortiOS SSL VPN Path TraversalRansomwareCRITICAL100%
CVE-2017-6327Symantec · Messaging GatewayMessaging Gateway Remote Code ExecutionHIGH36%

Source: CISA KEV catalog, refreshed daily.

Get alerts

A notification when we publish a new analysis or a covered vendor gets a new actively exploited CVE. No account, no email.