Skip to main content

CISA known exploited vulnerabilities

Under attack. Patch these first.

Page 9 of 21

Alerts tracked

2625

Security flaws we track for Upstate SC businesses.

Known exploited

503

On CISA’s list of vulnerabilities attackers are actively using. Patch these first.

New exploited this month

43

Fresh additions to that CISA list since the first of the month.Feeds last synced Aug 19, 2026, 6:00 AM UTC.

Showing page 9 (24 alerts) of 503 known-exploited alerts.

Actively exploited (KEV)Ransomware

CVE-2025-31161

CrushFTP Authentication Bypass Vulnerability

CrushFTP CrushFTP is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-31161). CrushFTP contains an authentication bypass vulnerability in the HTTP authorization header that allows a remote unauthenticated attacker to authenticate to any known or guessable user account (e.g., crushadmin), potentially leading to a full compromise. CISA remediation due date: 2025-04-28. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2025-22457

Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability

Ivanti Connect Secure, Policy Secure, and ZTA Gateways is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-22457). Ivanti Connect Secure, Policy Secure, and ZTA Gateways contains a stack-based buffer overflow vulnerability that allows a remote unauthenticated attacker to achieve remote code execution. CISA remediation due date: 2025-04-11. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2025-24472

Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability

Fortinet FortiOS and FortiProxy is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-24472). Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that allows a remote attacker to gain super-admin privileges via crafted CSF proxy requests. CISA remediation due date: 2025-04-08. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2025-26633

Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-26633). Microsoft Windows Management Console (MMC) contains an improper neutralization vulnerability that allows an unauthorized attacker to bypass a security feature locally. CISA remediation due date: 2025-04-01. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2025-22225

VMware ESXi Arbitrary Write Vulnerability

VMware ESXi is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-22225). VMware ESXi contains an arbitrary write vulnerability. Successful exploitation allows an attacker with privileges within the VMX process to trigger an arbitrary kernel write leading to an escape of the sandbox. CISA remediation due date: 2025-03-25. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2018-8639

Microsoft Windows Win32k Improper Resource Shutdown or Release Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-8639). Microsoft Windows Win32k contains an improper resource shutdown or release vulnerability that allows for local, authenticated privilege escalation. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. CISA remediation due date: 2025-03-24. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-53704

SonicWall SonicOS SSLVPN Improper Authentication Vulnerability

SonicWall SonicOS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-53704). SonicWall SonicOS contains an improper authentication vulnerability in the SSLVPN authentication mechanism that allows a remote attacker to bypass authentication. CISA remediation due date: 2025-03-11. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-57727

SimpleHelp Path Traversal Vulnerability

SimpleHelp SimpleHelp is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-57727). SimpleHelp remote support software contains multiple path traversal vulnerabilities that allow unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files may include server configuration files and hashed user passwords. CISA remediation due date: 2025-03-06. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2020-29574

CyberoamOS (CROS) SQL Injection Vulnerability

Sophos CyberoamOS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2020-29574). CyberoamOS (CROS) contains a SQL injection vulnerability in the WebAdmin that allows an unauthenticated attacker to execute arbitrary SQL statements remotely. CISA remediation due date: 2025-02-27. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2025-23006

SonicWall SMA1000 Appliances Deserialization Vulnerability

SonicWall SMA1000 Appliances is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-23006). SonicWall SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC) contain a deserialization of untrusted data vulnerability, which can enable a remote, unauthenticated attacker to execute arbitrary OS commands. CISA remediation due date: 2025-02-14. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-55591

Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability

Fortinet FortiOS and FortiProxy is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-55591). Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that may allow an unauthenticated, remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module. CISA remediation due date: 2025-01-21. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-48365

Qlik Sense HTTP Tunneling Vulnerability

Qlik Sense is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-48365). Qlik Sense contains an HTTP tunneling vulnerability that allows an attacker to escalate privileges and execute HTTP requests on the backend server hosting the software. CISA remediation due date: 2025-02-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2025-0282

Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability

Ivanti Connect Secure, Policy Secure, and ZTA Gateways is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-0282). Ivanti Connect Secure, Policy Secure, and ZTA Gateways contain a stack-based buffer overflow which can lead to unauthenticated remote code execution. CISA remediation due date: 2025-01-15. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-55550

Mitel MiCollab Path Traversal Vulnerability

Mitel MiCollab is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-55550). Mitel MiCollab contains a path traversal vulnerability that could allow an authenticated attacker with administrative privileges to read local files within the system due to insufficient input sanitization. This vulnerability can be chained with CVE-2024-41713, which allows an unauthenticated, remote attacker to read arbitrary files on the server. CISA remediation due date: 2025-01-28. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-41713

Mitel MiCollab Path Traversal Vulnerability

Mitel MiCollab is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-41713). Mitel MiCollab contains a path traversal vulnerability that could allow an attacker to gain unauthorized and unauthenticated access. This vulnerability can be chained with CVE-2024-55550, which allows an unauthenticated, remote attacker to read arbitrary files on the server. CISA remediation due date: 2025-01-28. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-55956

Cleo Multiple Products Unauthenticated File Upload Vulnerability

Cleo Multiple Products is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-55956). Cleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload vulnerability that could allow an unauthenticated user to import and execute arbitrary bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory. CISA remediation due date: 2025-01-07. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-50623

Cleo Multiple Products Unrestricted File Upload Vulnerability

Cleo Multiple Products is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-50623). Cleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload and download vulnerability that can lead to remote code execution with elevated privileges. CISA remediation due date: 2025-01-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-51378

CyberPanel Incorrect Default Permissions Vulnerability

CyberPersons CyberPanel is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-51378). CyberPanel contains an incorrect default permissions vulnerability that allows for authentication bypass and the execution of arbitrary commands using shell metacharacters in the statusfile property. CISA remediation due date: 2024-12-25. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-11667

Zyxel Multiple Firewalls Path Traversal Vulnerability

Zyxel Multiple Firewalls is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-11667). Multiple Zyxel firewalls contain a path traversal vulnerability in the web management interface that could allow an attacker to download or upload files via a crafted URL. CISA remediation due date: 2024-12-24. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-28461

Array Networks AG and vxAG ArrayOS Missing Authentication for Critical Function Vulnerability

Array Networks AG/vxAG ArrayOS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-28461). Array Networks AG and vxAG ArrayOS contain a missing authentication for critical function vulnerability that allows an attacker to read local files and execute code on the SSL VPN gateway. CISA remediation due date: 2024-12-16. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-9474

Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability

Palo Alto Networks PAN-OS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-9474). Palo Alto Networks PAN-OS contains an OS command injection vulnerability that allows for privilege escalation through the web-based management interface for several PAN products, including firewalls and VPN concentrators. CISA remediation due date: 2024-12-09. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-0012

Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability

Palo Alto Networks PAN-OS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-0012). Palo Alto Networks PAN-OS contains an authentication bypass vulnerability in the web-based management interface for several PAN-OS products, including firewalls and VPN concentrators. CISA remediation due date: 2024-12-09. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-49039

Microsoft Windows Task Scheduler Privilege Escalation Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-49039). Microsoft Windows Task Scheduler contains a privilege escalation vulnerability that can allow an attacker-provided, local application to escalate privileges outside of its AppContainer, and access privileged RPC functions. CISA remediation due date: 2024-12-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-51567

CyberPanel Incorrect Default Permissions Vulnerability

CyberPersons CyberPanel is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-51567). CyberPanel contains an incorrect default permissions vulnerability that allows a remote, unauthenticated attacker to execute commands as root. CISA remediation due date: 2024-11-28. If you need help checking exposure, call (864) 335-9223.