Every vulnerability we have written a full remediation guide for
26 guides. Each one answers the same four questions for one CVE: what breaks, whether you are affected, how bad it really is, and exactly what to run to fix it. Affected-version tables are generated from the NVD record rather than written by hand, so no guide can send you to a release that is still vulnerable.
Of the vulnerabilities covered here, 16 are confirmed exploited in the wild by CISA and 16 are recorded as used in ransomware campaigns. This page is rebuilt automatically as guides are published.
See also: the KEV tracker for what CISA confirmed this month, and the exploit likelihood watchlist for what a model expects next.
| CVSS | CVE and guide | Product | Exploitation status |
|---|---|---|---|
| 10.0 | CVE-2026-20131 CVE-2026-20131 – Immediate Action Guide for Cisco FMC and SCC |
Secure Firewall Management Center (FMC) | Exploited CISA confirmed 2026-03-19 Ransomware |
| 10.0 | CVE-2025-34037 CVE-2025-34037 – Critical OS command injection in Linksys E‑Series routers |
— | Not confirmed exploited |
| 10.0 | CVE-2025-59528 CVE-2025-59528 – Immediate steps for Flowise remote code execution |
flowiseai | Not confirmed exploited |
| 9.9 | CVE-2025-49844 CVE-2025-49844 – Immediate actions for Redis administrators |
redis | Not confirmed exploited |
| 9.8 | CVE-2024-4577 CVE-2024-4577 – Critical PHP CGI Command Injection |
PHP | Exploited CISA confirmed 2024-06-12 Ransomware |
| 9.8 | CVE-2024-23897 CVE-2024-23897 – Jenkins CLI Path Traversal – What you need to know and fix now |
Jenkins Command Line Interface (CLI) | Exploited CISA confirmed 2024-08-19 Ransomware |
| 9.8 | CVE-2024-40766 CVE-2024-40766 – Immediate actions for SonicWall SonicOS firewalls |
SonicOS | Exploited CISA confirmed 2024-09-09 Ransomware |
| 9.8 | CVE-2024-6670 CVE-2024-6670 – WhatsUp Gold SQL injection – What you need to know and fix now |
WhatsUp Gold | Exploited CISA confirmed 2024-09-16 Ransomware |
| 9.8 | CVE-2024-9680 CVE-2024-9680 – Critical Use‑After‑Free in Firefox and Thunderbird |
Firefox | Exploited CISA confirmed 2024-10-15 Ransomware |
| 9.8 | CVE-2024-40711 CVE-2024-40711 – Immediate actions for Veeam Backup & Replication |
Backup & Replication | Exploited CISA confirmed 2024-10-17 Ransomware |
| 9.8 | CVE-2024-0012 CVE-2024-0012 – PAN‑OS authentication bypass – immediate actions |
PAN-OS | Exploited CISA confirmed 2024-11-18 Ransomware |
| 9.8 | CVE-2024-55591 CVE-2024-55591 – Immediate Action Guide for FortiOS and FortiProxy |
FortiOS and FortiProxy | Exploited CISA confirmed 2025-01-14 Ransomware |
| 9.8 | CVE-2025-23006 CVE-2025-23006: SonicWall SMA1000 Remote Code Execution – Immediate Action Required |
SMA1000 Appliances | Exploited CISA confirmed 2025-01-24 Ransomware |
| 9.8 | CVE-2024-53704 CVE-2024-53704 – SonicWall SSLVPN authentication bypass – what to do |
SonicOS | Exploited CISA confirmed 2025-02-18 Ransomware |
| 9.8 | CVE-2025-53770 CVE-2025-53770 SharePoint Server – Immediate Action Guide |
SharePoint | Exploited CISA confirmed 2025-07-20 Ransomware |
| 9.8 | CVE-2025-61882 CVE-2025-61882 – Immediate Action Guide for Oracle E‑Business Suite |
E-Business Suite | Exploited CISA confirmed 2025-10-06 Ransomware |
| 9.8 | CVE-2025-26399 CVE-2025-26399 – Immediate actions for SolarWinds Web Help Desk |
Web Help Desk | Exploited CISA confirmed 2026-03-09 Ransomware |
| 9.8 | CVE-2026-35273 CVE-2026-35273 – Critical PeopleSoft PeopleTools Authentication Bypass |
PeopleSoft Enterprise PeopleTools | Exploited CISA confirmed 2026-06-12 Ransomware |
| 9.8 | CVE-2025-1974 CVE-2025-1974 – Critical Kubernetes Ingress‑NGINX Remote Code Execution |
— | Not confirmed exploited |
| 9.8 | CVE-2026-61511 CVE-2026-61511 – Immediate guide for vBulletin admins |
— | Not confirmed exploited |
| 9.5 | CVE-2026-6875 CVE-2026-6875 – ServiceNow AI Platform Remote Code Execution – What You Need to Do |
— | Not confirmed exploited |
| 9.4 | CVE-2026-26980 CVE-2026-26980 – Immediate Action Guide for Ghost Administrators |
ghost | Not confirmed exploited |
| 9.1 | CVE-2025-29927 CVE-2025-29927 – Critical Next.js Authorization Bypass – Immediate Action Required |
vercel | Not confirmed exploited |
| 9.0 | CVE-2025-22457 CVE-2025-22457 – Critical Remote Code Execution in Ivanti Connect Secure, Policy Secure an |
Connect Secure, Policy Secure, and ZTA Gatew | Exploited CISA confirmed 2025-04-04 Ransomware |
| 8.8 | CVE-2026-43284 CVE-2026-43284 – Linux kernel ESP‑in‑UDP in‑place decryption flaw |
linux | Not confirmed exploited |
| 8.1 | CVE-2025-1094 CVE-2025-1094 – PostgreSQL libpq quoting injection – quick guide |
— | Not confirmed exploited |

