Sponsored by Hudson Rock – Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks
| Product | CVE(s) | Ransomware Group(s) | Source |
|---|---|---|---|
| Accellion File Transfer Appliance | CVE-2021-27101 | Clop | mandiant.com |
| Accellion File Transfer Appliance | CVE-2021-27102 | Clop | mandiant.com |
| Accellion File Transfer Appliance | CVE-2021-27103 | Clop | mandiant.com |
| Accellion File Transfer Appliance | CVE-2021-27104 | Clop | mandiant.com |
| Product | CVE(s) | Ransomware Group(s) | Source |
|---|---|---|---|
| ActiveMQ | CVE-2023-46604 | RansomHub | cisa.gov |
| Log4j | CVE-2021-44228 | DragonForce, LockBit, ProphetSpider | trendmicro.com |
| Apache bRPC | CVE-2025-60021 | qilin | ctrlaltintel.com |
| Struts | CVE-2017-5638 | ProphetSpider | secureworks.com |
| Log4j | CVE-2021-4104 | ProphetSpider | secureworks.com |
| Product | CVE(s) | Ransomware Group(s) | Source |
|---|---|---|---|
| Apache Tomcat | CVE-2025-55754 | Tengu | — |
| Product | CVE(s) | Ransomware Group(s) | Source |
|---|---|---|---|
| Confluence Data Center & Server | CVE-2023-22515 | RansomHub | cisa.gov |
| Product | CVE(s) | Ransomware Group(s) | Source |
|---|---|---|---|
| Remote Support / Privileged Remote Access | CVE-2026-1731 | Medusa | cisa.gov |
| Product | CVE(s) | Ransomware Group(s) | Source |
|---|---|---|---|
| Gladinet CentreStack | CVE-2025-11371 | Clop | securityaffairs.com |
| Gladinet CentreStack | CVE-2025-14611 | WarLock | linkedin.com |
| Product | CVE(s) | Ransomware Group(s) | Source |
|---|---|---|---|
| Security Gateway | CVE-2026-50751 | rhysida | — |
| Security Gateway (IKEv1 VPN) | CVE-2026-50751 | direwolf, spacebears | checkpoint.com |
| Security Gateway (Remote Access VPN / IKEv1) | CVE-2026-50751 | Panzer | checkpoint.com |
| VPN Remote Access and Mobile Access | CVE-2026-50751 | qilin | blog.checkpoint.com |
| Security Gateway | CVE-2024-24919 | PioneerKitten | cisa.gov |
| Security Gateway (IKEv1 improper auth) | CVE-2026-50751 | Emperador | — |
| Product | CVE(s) | Ransomware Group(s) | Source |
|---|---|---|---|
| Secure Firewall Management Center (FMC) | CVE-2026-20131 | interlock, Panzer | cisco.com |
| Cisco Unified Communications | CVE-2026-20045 | ShinyHunters | — |
| ASA & FTD | CVE-2020-3259 | Akira | cisa.gov |
| Secure Firewall Management Center (FMC) | CVE-2026-20316 | qilin | thehackernews.com |
| ASA & FTD | CVE-2023-20269 | Akira | cisco.com |
| ASA & FTD | CVE-2023-20263 | Akira | blog.talosintelligence.com |
| Product | CVE(s) | Ransomware Group(s) | Source |
|---|---|---|---|
| NetScaler ADC & Gateway | CVE-2023-3519 | PioneerKitten, RansomHub | cisa.gov |
| NetScaler ADC & Gateway & SD-WAN | CVE-2019-19781 | PioneerKitten | cisa.gov |
| ShareFile Storage Zones Controller | CVE-2021-22941 | ProphetSpider | crowdstrike.com |
| NetScaler ADC & Gateway | CVE-2023-4966 | BlackCat, LockBit | therecord.media |
| Product | CVE(s) | Ransomware Group(s) | Source |
|---|---|---|---|
| Cleo VLTrader, Harmony, LexiCom | CVE-2024-55956 | Clop | huntress.com |
| Product | CVE(s) | Ransomware Group(s) | Source |
|---|---|---|---|
| ScreenConnect | CVE-2024-1709 | BlackBasta, BlackCat | cisa.gov |
| ScreenConnect | CVE-2024-1708 | BlackCat, direwolf, Panzer, rhysida, spacebears | bleepingcomputer.com |
| ScreenConnect (path traversal -> RCE) | CVE-2024-1708 | Emperador | — |
| Product | CVE(s) | Ransomware Group(s) | Source |
|---|---|---|---|
| DSM Data Collector | CVE-2025-43995 | Tengu | — |
| Product | CVE(s) | Ransomware Group(s) | Source |
|---|---|---|---|
| otp | CVE-2025-32433 | thegentlemen | Unit42 |
| Product | CVE(s) | Ransomware Group(s) | Source |
|---|---|---|---|
| BIG-IP | CVE-2022-1388 | PioneerKitten | cisa.gov |
| BIG-IP | CVE-2023-46747 | RansomHub | cisa.gov |
| iControl REST | CVE-2021-22986 | LockBit | cisa.gov |
| Product | CVE(s) | Ransomware Group(s) | Source |
|---|---|---|---|
| FortiClient | CVE-2023-48788 | Akira | blog.talosintelligence.com |
| FortiClientEMS | CVE-2023-48788 | RansomHub | cisa.gov |
| FortiOS | CVE-2022-40684 | Akira | stairwell.com |
| FortiOS | CVE-2025-59718 | qilin | ctrlaltintel.com |
| FortiOS | CVE-2024-55591 | thegentlemen | Unit42 |
| FortiOS & FortiProxy | CVE-2024-21762 | DragonForce, qilin | ccb.belgium.be |
| FortiOS & FortiProxy | CVE-2024-55591 | DragonForce, qilin | ccb.belgium.be |
| FortiOS SSL-VPN & FortiProxy | CVE-2023-27997 | RansomHub | cisa.gov |
| FortiOS | CVE-2018-13379 | LockBit | cisa.gov |
| FortiOS | CVE-2019-6693 | Akira | stairwell.com |
| Product | CVE(s) | Ransomware Group(s) | Source |
|---|---|---|---|
| GoAnywhere Managed File Transfer | CVE-2023-0669 | Clop, LockBit | censys.io |
| Product | CVE(s) | Ransomware Group(s) | Source |
|---|---|---|---|
| ICS | CVE-2024-21887 | DragonForce | trendmicro.com |
| VPN Appliance | CVE-2024-21887 | 0apt | — |
| Ivanti ICS | CVE-2025-22457 | 0apt | — |
| Product | CVE(s) | Ransomware Group(s) | Source |
|---|---|---|---|
| Jboss Application Server | CVE-2017-7504 | ProphetSpider | secureworks.com |
| Product | CVE(s) | Ransomware Group(s) | Source |
|---|---|---|---|
| Polkit pkexec | CVE-2021-4034 | BlackCat | crowdstrike.com |
| Product | CVE(s) | Ransomware Group(s) | Source |
|---|---|---|---|
| react-server-dom-webpack | CVE-2025-55182 | thegentlemen | Unit42 |
| Product | CVE(s) | Ransomware Group(s) | Source |
|---|---|---|---|
| Exchange Server | CVE-2023-21529 | direwolf, Panzer, rhysida, spacebears | msrc.microsoft.com |
| Windows 10 Version 1507 | CVE-2025-33073 | thegentlemen | Unit42 |
| Windows | CVE-2025-60710 | rhysida | — |
| Windows (Host Process for Tasks) | CVE-2025-60710 | direwolf, spacebears | sentinelone.com |
| Windows Scripting Engine | CVE-2024-38178 | Tengu | — |
| Windows Server 2019 | CVE-2021-42278 | BlackBasta | cisa.gov |
| Exchange (deserialization) | CVE-2023-21529 | Emperador | — |
| Windows (link following) | CVE-2025-60710 | Emperador | — |
| Product | CVE(s) | Ransomware Group(s) | Source |
|---|---|---|---|
| SharePoint Server | CVE-2025-49704 | WarLock | microsoft.com |
| SMBv1 | CVE-2017-0144 | thegentlemen | kelacyber.com |
| SharePoint Server | CVE-2025-49706 | WarLock | microsoft.com |
| Product | CVE(s) | Ransomware Group(s) | Source |
|---|---|---|---|
| Nx Console (VS Code extension) | CVE-2026-48027 | direwolf, spacebears | cisa.gov |
| Nx Console | CVE-2026-48027 | rhysida | — |
| Nx Console (embedded malicious code) | CVE-2026-48027 | Emperador | — |
| Product | CVE(s) | Ransomware Group(s) | Source |
|---|---|---|---|
| Oracle E-Business Suite (EBS) | CVE-2025-61882 | ShinyHunters, Sinobi | — |
| WebLogic | CVE-2020-14882 | ProphetSpider | secureworks.com |
| WebLogic | CVE-2020-14750 | ProphetSpider | secureworks.com |
| E-Business | CVE-2016-0545 | ProphetSpider | secureworks.com |
| Product | CVE(s) | Ransomware Group(s) | Source |
|---|---|---|---|
| Oracle Concurrent Processing | CVE-2025-61882 | 0apt, Clop | crowdstrike.com |
| Product | CVE(s) | Ransomware Group(s) | Source |
|---|---|---|---|
| PAN-OS (Edge Firewalls) | CVE-2024-3400 | 0apt | — |
| PAN-OS Firewall | CVE-2024-3400 | PioneerKitten | cisa.gov |
| Cloud NGFW | CVE-2026-0257 | qilin | Articwolf |
| Product | CVE(s) | Ransomware Group(s) | Source |
|---|---|---|---|
| PaperCut Application Server | CVE-2023-27350 | Clop | twitter.com/MsftSecIntel |
| PaperCut Application Server | CVE-2023-27351 | Clop | twitter.com/MsftSecIntel |
| PaperCut Application Server | CVE-2023-27350, CVE-2023-27351 | LockBit | twitter.com/MsftSecIntel |
| Product | CVE(s) | Ransomware Group(s) | Source |
|---|---|---|---|
| MOVEit | CVE-2023-34362 | Clop | cisa.gov |
| Product | CVE(s) | Ransomware Group(s) | Source |
|---|---|---|---|
| Windchill PDMLink / FlexPLM | CVE-2026-12569 | Clop | bleepingcomputer.com |
| Windchill PDMLink | CVE-2026-4681 | Clop | — |
| Product | CVE(s) | Ransomware Group(s) | Source |
|---|---|---|---|
| Pulse Connect Secure | CVE-2019-11510 | PioneerKitten | cisa.gov |
| Ivanti EPM Cloud Services Appliance (CSA) | CVE-2021-44529 | BlackCat | crowdstrike.com |
| Pulse Connect Secure | CVE-2024-21887 | PioneerKitten | cisa.gov |
| Ivanti Connect Secure | CVE-2024-21893 | DragonForce | trendmicro.com |
| Ivanti Connect Secure | CVE-2023-46805 | DragonForce | trendmicro.com |
| Pulse Connect Secure & Pulse Policy Secure | CVE-2019-11539 | PioneerKitten | cisa.gov |
| Product | CVE(s) | Ransomware Group(s) | Source |
|---|---|---|---|
| SimpleHelp RMM | CVE-2024-57727 | DragonForce, Medusa | sophos.com |
| SimpleHelp RMM | CVE-2024-57728 | DragonForce | sophos.com |
| Product | CVE(s) | Ransomware Group(s) | Source |
|---|---|---|---|
| Sitecore XP | CVE-2021-42237 | ProphetSpider | secureworks.com |
| Product | CVE(s) | Ransomware Group(s) | Source |
|---|---|---|---|
| SmarterMail | CVE-2026-23760 | WarLock | reliaquest.com |
| SmarterMail | CVE-2026-24423 | qilin | ctrlaltintel.com |
| Product | CVE(s) | Ransomware Group(s) | Source |
|---|---|---|---|
| Snowflake (credential stuffing / no MFA) | OAuth Abuse | ShinyHunters | — |
| Product | CVE(s) | Ransomware Group(s) | Source |
|---|---|---|---|
| SolarWinds Web Help Desk | CVE-2025-40551 | WarLock | linkedin.com |
| SolarWinds Serv-U FTP | CVE-2021-35211 | Clop | research.nccgroup.com |
| SolarWinds Web Help Desk | CVE-2025-40554 | qilin | ctrlaltintel.com |
| Product | CVE(s) | Ransomware Group(s) | Source |
|---|---|---|---|
| SMA1000 | CVE-2026-15409 | incransom | — |
| SonicOS SSL-VPN | CVE-2024-40766 | Akira, DragonForce | arcticwolf.com |
| SonicWall SonicOS | CVE-2024-40766 | Sinobi | — |
| SonicWall SSL VPN | CVE-2024-53704 | Sinobi | — |
| SMA 100 | CVE-2019-7481 | BlackCat | blackberry.com |
| SMA1000 | CVE-2026-15410 | incransom | — |
| Product | CVE(s) | Ransomware Group(s) | Source |
|---|---|---|---|
| Telnetd in GNU Inetutils | CVE-2026-24061 | qilin | ctrlaltintel.com |
| Product | CVE(s) | Ransomware Group(s) | Source |
|---|---|---|---|
| Backup & Replication | CVE-2024-40711 | Akira | @SophosXOps |
| Backup & Replication | CVE-2023-27532 | Akira, qilin | sophos.com |
| Product | CVE(s) | Ransomware Group(s) | Source |
|---|---|---|---|
| vSphere Client | CVE-2021-21972 | Akira, BlackCat | qualys.com |
| ESXi | CVE-2024-37085 | Akira, BlackBasta | microsoft.com |
| Product | CVE(s) | Ransomware Group(s) | Source |
|---|---|---|---|
| WatchGuard Fireware OS | CVE-2025-9242 | qilin | ctrlaltintel.com |
| WatchGuard Fireware OS | CVE-2025-14733 | qilin | ctrlaltintel.com |
| Product | CVE(s) | Ransomware Group(s) | Source |
|---|---|---|---|
| Remote Desktop Services | CVE-2019-0708 | LockBit | cisa.gov |
| Print Spooler | CVE-2021-1675 | BlackBasta | cisa.gov |
| Print Spooler | CVE-2021-34527 | BlackBasta | cisa.gov |
| SMBv1 | CVE-2017-0144 | RansomHub | cisa.gov |
| SmartScreen | CVE-2024-21412 | DragonForce, thegentlemen | trendmicro.com |
| BITS | CVE-2020-0787 | RansomHub | cisa.gov |
| MSDT | CVE-2022-30190 | BlackBasta | sentinelone.com |
| Windows Error Reporting Service | CVE-2024-26169 | BlackBasta | www.security.com |
| Active Directory | CVE-2021-42287 | BlackBasta | cisa.gov |
| NetLogon | CVE-2020-1472 | BlackBasta, LockBit, RansomHub, thegentlemen | cisa.gov |
| Local Security Authority (LSA) | CVE-2021-36942 | thegentlemen | kelacyber.com |
| Product | CVE(s) | Ransomware Group(s) | Source |
|---|---|---|---|
| Exchange On-Prem | CVE-2021-34523 | BlackCat | trendmicro.com |
| Exchange On-Prem | CVE-2021-34473 | BlackCat | trendmicro.com |
| Exchange On-Prem | CVE-2021-31207 | BlackCat | trendmicro.com |
| Secondary Logon Service | CVE-2016-0099 | BlackCat | kaspersky.com |
| Product | CVE(s) | Ransomware Group(s) | Source |
|---|---|---|---|
| Zemana AntiLogger | CVE-2024-1853 | qilin | binarydefense.com |
| Vendor | Product | CVE(s) | Source |
|---|---|---|---|
| Palo Alto Networks | PAN-OS (Edge Firewalls) | CVE-2024-3400 | — |
| Oracle Corporation | Oracle Concurrent Processing | CVE-2025-61882 | — |
| Ivanti | VPN Appliance | CVE-2024-21887 | — |
| Ivanti | Ivanti ICS | CVE-2025-22457 | — |
| Vendor | Product | CVE(s) | Source |
|---|---|---|---|
| Fortinet | FortiOS | CVE-2022-40684 | stairwell.com |
| Fortinet | FortiClient | CVE-2023-48788 | blog.talosintelligence.com |
| SonicWall | SonicOS SSL-VPN | CVE-2024-40766 | arcticwolf.com |
| Veeam | Backup & Replication | CVE-2024-40711 | @SophosXOps |
| VMware | vSphere Client | CVE-2021-21972 | qualys.com |
| Cisco | ASA & FTD | CVE-2020-3259 | cisa.gov |
| Veeam | Backup & Replication | CVE-2023-27532 | sophos.com |
| VMware | ESXi | CVE-2024-37085 | microsoft.com |
| Fortinet | FortiOS | CVE-2019-6693 | stairwell.com |
| Cisco | ASA & FTD | CVE-2023-20269 | cisco.com |
| Cisco | ASA & FTD | CVE-2023-20263 | blog.talosintelligence.com |
| Vendor | Product | CVE(s) | Source |
|---|---|---|---|
| ConnectWise | ScreenConnect | CVE-2024-1709 | cisa.gov |
| Windows | Print Spooler | CVE-2021-1675 | cisa.gov |
| Windows | Print Spooler | CVE-2021-34527 | cisa.gov |
| Windows | Windows Error Reporting Service | CVE-2024-26169 | www.security.com |
| Windows | MSDT | CVE-2022-30190 | sentinelone.com |
| Microsoft | Windows Server 2019 | CVE-2021-42278 | cisa.gov |
| Windows | Active Directory | CVE-2021-42287 | cisa.gov |
| VMware | ESXi | CVE-2024-37085 | microsoft.com |
| Windows | NetLogon | CVE-2020-1472 | cisa.gov |
| Vendor | Product | CVE(s) | Source |
|---|---|---|---|
| ConnectWise | ScreenConnect | CVE-2024-1708 | bleepingcomputer.com |
| ConnectWise | ScreenConnect | CVE-2024-1709 | bleepingcomputer.com |
| Pulse Secure / Ivanti | Ivanti EPM Cloud Services Appliance (CSA) | CVE-2021-44529 | crowdstrike.com |
| VMware | vSphere Client | CVE-2021-21972 | crowdstrike.com |
| Citrix | NetScaler ADC & Gateway | CVE-2023-4966 | therecord.media |
| Windows & MS Server Products | Exchange On-Prem | CVE-2021-34523 | trendmicro.com |
| Windows & MS Server Products | Exchange On-Prem | CVE-2021-34473 | trendmicro.com |
| Windows & MS Server Products | Exchange On-Prem | CVE-2021-31207 | trendmicro.com |
| Linux System Utilities | Polkit pkexec | CVE-2021-4034 | crowdstrike.com |
| Windows & MS Server Products | Secondary Logon Service | CVE-2016-0099 | kaspersky.com |
| SonicWall | SMA 100 | CVE-2019-7481 | blackberry.com |
| Vendor | Product | CVE(s) | Source |
|---|---|---|---|
| Accellion | Accellion File Transfer Appliance | CVE-2021-27101 | mandiant.com |
| Accellion | Accellion File Transfer Appliance | CVE-2021-27102 | mandiant.com |
| Accellion | Accellion File Transfer Appliance | CVE-2021-27103 | mandiant.com |
| Accellion | Accellion File Transfer Appliance | CVE-2021-27104 | mandiant.com |
| Cleo | Cleo VLTrader, Harmony, LexiCom | CVE-2024-55956 | huntress.com |
| Oracle Corporation | Oracle Concurrent Processing | CVE-2025-61882 | crowdstrike.com |
| PaperCut | PaperCut Application Server | CVE-2023-27350 | twitter.com/MsftSecIntel |
| PaperCut | PaperCut Application Server | CVE-2023-27351 | twitter.com/MsftSecIntel |
| Progress Software | MOVEit | CVE-2023-34362 | cisa.gov |
| PTC | Windchill PDMLink / FlexPLM | CVE-2026-12569 | bleepingcomputer.com |
| PTC | Windchill PDMLink | CVE-2026-4681 | — |
| SolarWinds | SolarWinds Serv-U FTP | CVE-2021-35211 | research.nccgroup.com |
| CentreStack | Gladinet CentreStack | CVE-2025-11371 | securityaffairs.com |
| Fortra | GoAnywhere Managed File Transfer | CVE-2023-0669 | censys.io |
| Vendor | Product | CVE(s) | Source |
|---|---|---|---|
| Nx | Nx Console (VS Code extension) | CVE-2026-48027 | cisa.gov |
| Check Point | Security Gateway (IKEv1 VPN) | CVE-2026-50751 | checkpoint.com |
| Microsoft | Exchange Server | CVE-2023-21529 | nvd.nist.gov |
| ConnectWise | ScreenConnect | CVE-2024-1708 | cisa.gov |
| Microsoft | Windows (Host Process for Tasks) | CVE-2025-60710 | sentinelone.com |
| Vendor | Product | CVE(s) | Source |
|---|---|---|---|
| Apache | Log4j | CVE-2021-44228 | trendmicro.com |
| Fortinet | FortiOS & FortiProxy | CVE-2024-21762 | ccb.belgium.be |
| Fortinet | FortiOS & FortiProxy | CVE-2024-55591 | ccb.belgium.be |
| SonicWall | SonicOS SSL-VPN | CVE-2024-40766 | ccb.belgium.be |
| Ivanti | ICS | CVE-2024-21887 | trendmicro.com |
| Pulse Secure / Ivanti | Ivanti Connect Secure | CVE-2024-21893 | trendmicro.com |
| Pulse Secure / Ivanti | Ivanti Connect Secure | CVE-2023-46805 | trendmicro.com |
| Windows | SmartScreen | CVE-2024-21412 | trendmicro.com |
| SimpleHelp | SimpleHelp RMM | CVE-2024-57727 | sophos.com |
| SimpleHelp | SimpleHelp RMM | CVE-2024-57728 | sophos.com |
| Vendor | Product | CVE(s) | Source |
|---|---|---|---|
| Check Point | Security Gateway (IKEv1 improper auth) | CVE-2026-50751 | — |
| ConnectWise | ScreenConnect (path traversal -> RCE) | CVE-2024-1708 | — |
| Microsoft | Exchange (deserialization) | CVE-2023-21529 | — |
| Microsoft | Windows (link following) | CVE-2025-60710 | — |
| Nx | Nx Console (embedded malicious code) | CVE-2026-48027 | — |
| Vendor | Product | CVE(s) | Source |
|---|---|---|---|
| SonicWall | SMA1000 | CVE-2026-15409 | — |
| SonicWall | SMA1000 | CVE-2026-15410 | — |
| Vendor | Product | CVE(s) | Source |
|---|---|---|---|
| Cisco | Secure Firewall Management Center (FMC) | CVE-2026-20131 | thehackernews.com |
| Vendor | Product | CVE(s) | Source |
|---|---|---|---|
| Apache | Log4j | CVE-2021-44228 | cisa.gov |
| F5 | iControl REST | CVE-2021-22986 | cisa.gov |
| Windows | Remote Desktop Services | CVE-2019-0708 | cisa.gov |
| Citrix | NetScaler ADC & Gateway | CVE-2023-4966 | doublepulsar.com |
| Fortinet | FortiOS | CVE-2018-13379 | cisa.gov |
| Fortra | GoAnywhere Managed File Transfer | CVE-2023-0669 | cisa.gov |
| Windows | NetLogon | CVE-2020-1472 | cisa.gov |
| PaperCut | PaperCut Application Server | CVE-2023-27350, CVE-2023-27351 | twitter.com/MsftSecIntel |
| Vendor | Product | CVE(s) | Source |
|---|---|---|---|
| BeyondTrust | Remote Support / Privileged Remote Access | CVE-2026-1731 | cisa.gov |
| SimpleHelp | SimpleHelp RMM | CVE-2024-57727 | arcticwolf.com |
| Vendor | Product | CVE(s) | Source |
|---|---|---|---|
| Cisco | Secure Firewall Management Center (FMC) | CVE-2026-20131 | cisco.com |
| Check Point | Security Gateway (Remote Access VPN / IKEv1) | CVE-2026-50751 | checkpoint.com |
| Microsoft | Exchange Server | CVE-2023-21529 | msrc.microsoft.com |
| ConnectWise | ScreenConnect | CVE-2024-1708 | huntress.com |
| Vendor | Product | CVE(s) | Source |
|---|---|---|---|
| Palo Alto Networks | PAN-OS Firewall | CVE-2024-3400 | cisa.gov |
| Pulse Secure / Ivanti | Pulse Connect Secure | CVE-2019-11510 | cisa.gov |
| Citrix | NetScaler ADC & Gateway | CVE-2023-3519 | cisa.gov |
| Citrix | NetScaler ADC & Gateway & SD-WAN | CVE-2019-19781 | cisa.gov |
| F5 | BIG-IP | CVE-2022-1388 | cisa.gov |
| Pulse Secure / Ivanti | Pulse Connect Secure | CVE-2024-21887 | cisa.gov |
| Check Point | Security Gateway | CVE-2024-24919 | cisa.gov |
| Pulse Secure / Ivanti | Pulse Connect Secure & Pulse Policy Secure | CVE-2019-11539 | cisa.gov |
| Vendor | Product | CVE(s) | Source |
|---|---|---|---|
| Apache | Log4j | CVE-2021-44228 | secureworks.com |
| Apache | Struts | CVE-2017-5638 | secureworks.com |
| Citrix | ShareFile Storage Zones Controller | CVE-2021-22941 | crowdstrike.com |
| Oracle | WebLogic | CVE-2020-14882 | secureworks.com |
| Oracle | WebLogic | CVE-2020-14750 | secureworks.com |
| Sitecore | Sitecore XP | CVE-2021-42237 | secureworks.com |
| Apache | Log4j | CVE-2021-4104 | secureworks.com |
| Java Applications | Jboss Application Server | CVE-2017-7504 | secureworks.com |
| Oracle | E-Business | CVE-2016-0545 | secureworks.com |
| Vendor | Product | CVE(s) | Source |
|---|---|---|---|
| Apache | Apache bRPC | CVE-2025-60021 | ctrlaltintel.com |
| Fortinet | FortiOS | CVE-2025-59718 | ctrlaltintel.com |
| Fortinet | FortiOS & FortiProxy | CVE-2024-21762 | checkpoint.com |
| Fortinet | FortiOS & FortiProxy | CVE-2024-55591 | checkpoint.com |
| SmarterTools | SmarterMail | CVE-2026-24423 | ctrlaltintel.com |
| Telnet | Telnetd in GNU Inetutils | CVE-2026-24061 | ctrlaltintel.com |
| WatchGuard | WatchGuard Fireware OS | CVE-2025-9242 | ctrlaltintel.com |
| WatchGuard | WatchGuard Fireware OS | CVE-2025-14733 | ctrlaltintel.com |
| Check Point | VPN Remote Access and Mobile Access | CVE-2026-50751 | blog.checkpoint.com |
| Palo Alto Networks | Cloud NGFW | CVE-2026-0257 | Articwolf |
| Veeam | Backup & Replication | CVE-2023-27532 | group-ib.com |
| Cisco | Secure Firewall Management Center (FMC) | CVE-2026-20316 | thehackernews.com |
| SolarWinds | SolarWinds Web Help Desk | CVE-2025-40554 | ctrlaltintel.com |
| Zemana | Zemana AntiLogger | CVE-2024-1853 | binarydefense.com |
| Vendor | Product | CVE(s) | Source |
|---|---|---|---|
| Apache | ActiveMQ | CVE-2023-46604 | cisa.gov |
| Atlassian | Confluence Data Center & Server | CVE-2023-22515 | cisa.gov |
| Citrix | NetScaler ADC & Gateway | CVE-2023-3519 | cisa.gov |
| F5 | BIG-IP | CVE-2023-46747 | cisa.gov |
| Fortinet | FortiOS SSL-VPN & FortiProxy | CVE-2023-27997 | cisa.gov |
| Fortinet | FortiClientEMS | CVE-2023-48788 | cisa.gov |
| Windows | SMBv1 | CVE-2017-0144 | cisa.gov |
| Windows | BITS | CVE-2020-0787 | cisa.gov |
| Windows | NetLogon | CVE-2020-1472 | cisa.gov |
| Vendor | Product | CVE(s) | Source |
|---|---|---|---|
| Check Point | Security Gateway | CVE-2026-50751 | — |
| Nx | Nx Console | CVE-2026-48027 | — |
| Microsoft | Exchange Server | CVE-2023-21529 | — |
| ConnectWise | ScreenConnect | CVE-2024-1708 | — |
| Microsoft | Windows | CVE-2025-60710 | — |
| Vendor | Product | CVE(s) | Source |
|---|---|---|---|
| Oracle | Oracle E-Business Suite (EBS) | CVE-2025-61882 | — |
| Cisco | Cisco Unified Communications | CVE-2026-20045 | — |
| Snowflake | Snowflake (credential stuffing / no MFA) | OAuth Abuse | — |
| Vendor | Product | CVE(s) | Source |
|---|---|---|---|
| Oracle | Oracle E-Business Suite (EBS) | CVE-2025-61882 | — |
| SonicWall | SonicWall SSL VPN | CVE-2024-53704 | — |
| SonicWall | SonicWall SonicOS | CVE-2024-40766 | — |
| Vendor | Product | CVE(s) | Source |
|---|---|---|---|
| Nx | Nx Console (VS Code extension) | CVE-2026-48027 | cisa.gov |
| Check Point | Security Gateway (IKEv1 VPN) | CVE-2026-50751 | checkpoint.com |
| Microsoft | Exchange Server | CVE-2023-21529 | nvd.nist.gov |
| ConnectWise | ScreenConnect | CVE-2024-1708 | cisa.gov |
| Microsoft | Windows (Host Process for Tasks) | CVE-2025-60710 | sentinelone.com |
| Vendor | Product | CVE(s) | Source |
|---|---|---|---|
| DSM | DSM Data Collector | CVE-2025-43995 | — |
| Apache Software Foundation | Apache Tomcat | CVE-2025-55754 | — |
| Microsoft | Windows Scripting Engine | CVE-2024-38178 | — |
| Vendor | Product | CVE(s) | Source |
|---|---|---|---|
| erlang | otp | CVE-2025-32433 | Unit42 |
| Meta | react-server-dom-webpack | CVE-2025-55182 | Unit42 |
| Fortinet | FortiOS | CVE-2024-55591 | Unit42 |
| Microsoft | Windows 10 Version 1507 | CVE-2025-33073 | Unit42 |
| MS Server Products | SMBv1 | CVE-2017-0144 | kelacyber.com |
| Windows | SmartScreen | CVE-2024-21412 | ransom-isac.com |
| Windows | NetLogon | CVE-2020-1472 | checkpoint.com |
| Windows | Local Security Authority (LSA) | CVE-2021-36942 | kelacyber.com |
| Vendor | Product | CVE(s) | Source |
|---|---|---|---|
| SmarterTools | SmarterMail | CVE-2026-23760 | reliaquest.com |
| SolarWinds | SolarWinds Web Help Desk | CVE-2025-40551 | linkedin.com |
| MS Server Products | SharePoint Server | CVE-2025-49704 | microsoft.com |
| MS Server Products | SharePoint Server | CVE-2025-49706 | microsoft.com |
| CentreStack | Gladinet CentreStack | CVE-2025-14611 | linkedin.com |