Patch priority
Tracked CVEs sorted into three tiers by evidence of exploitation, each with the reasons it is here and the vendor's fix. This ranks what attackers are doing, not what you run. Whether a CVE affects you depends on your product and version: check your version.
Tier 1: Exploited now (60)
Listed in the CISA Known Exploited Vulnerabilities catalog. Those linked to ransomware campaigns sort first.
| CVE | Severity | Vendor | Why it is here | Fix | EPSS |
|---|---|---|---|---|---|
| CVE-2024-3400 Apr 12, 2024 | Critical 10 | Palo Alto Networks | In CISA KEVKnown ransomware use | We strongly advise customers to immediately upgrade to a fixed version of PAN-OS to protect their devices even when workarounds and mitigations have been applied. This issue is… | 1.000 |
| CVE-2024-24919 May 28, 2024 | High 8.6 | Check Point | In CISA KEVKnown ransomware use | See the vendor advisory | 1.000 |
| CVE-2024-0012 Nov 18, 2024 | Critical 9.3 | Palo Alto Networks | In CISA KEVKnown ransomware use | We strongly recommend that you secure access to your management interface following the instructions in the workarounds section below. This issue is fixed in PAN-OS 10.2.12-h2,… | 0.998 |
| CVE-2026-0257 May 13, 2026 | High 7.8 | Palo Alto Networks | In CISA KEVKnown ransomware use | Version Minor Version Suggested Solution Cloud NGFW All No action needed. PAN-OS 12.1 12.1.5 through 12.1.6 Upgrade to 12.1.7 or later. 12.1.2 through 12.1.4-h* Upgrade to 12.1.… | 0.964 |
| CVE-2024-9474 Nov 18, 2024 | Medium 6.9 | Palo Alto Networks | In CISA KEVKnown ransomware use | This issue is fixed in PAN-OS 10.1.14-h6, PAN-OS 10.2.12-h2, PAN-OS 11.0.6-h1, PAN-OS 11.1.5-h1, PAN-OS 11.2.4-h1, and all later PAN-OS versions. In addition, in an attempt to p… | 0.947 |
| CVE-2024-55591 Jan 14, 2025 | Critical 9.6 | Fortinet | In CISA KEVKnown ransomware use | Upgrade to FortiOS version 7.0.17 or above Upgrade to FortiProxy version 7.2.13 or above Upgrade to FortiProxy version 7.0.20 or above | 0.941 |
| CVE-2024-21762 Feb 9, 2024 | Critical 9.6 | Fortinet | In CISA KEVKnown ransomware use | Please upgrade to FortiProxy version 7.4.3 or above Please upgrade to FortiProxy version 7.2.9 or above Please upgrade to FortiProxy version 7.0.15 or above Please upgrade to Fo… | 0.834 |
| CVE-2026-20131 Mar 4, 2026 | Critical 10 | Cisco | In CISA KEVKnown ransomware use | See the vendor advisory | 0.427 |
| CVE-2026-20316 Jul 29, 2026 | Medium 5.3 | Cisco | In CISA KEVKnown ransomware use | See the vendor advisory | 0.351 |
| CVE-2025-24472 Feb 11, 2025 | High 8.1 | Fortinet | In CISA KEVKnown ransomware use | Upgrade to FortiOS version 7.0.17 or above Upgrade to FortiProxy version 7.2.13 or above Upgrade to FortiProxy version 7.0.20 or above | 0.072 |
| CVE-2026-50751 Jun 8, 2026 | Critical 9.3 | Check Point | In CISA KEVKnown ransomware use | See the vendor advisory | 0.063 |
| CVE-2025-25257 Jul 17, 2025 | Critical 9.6 | Fortinet | In CISA KEV | Upgrade to FortiWeb version 7.6.4 or above Upgrade to FortiWeb version 7.4.8 or above Upgrade to FortiWeb version 7.2.11 or above Upgrade to FortiWeb version 7.0.11 or above | 0.998 |
| CVE-2024-9465 Oct 9, 2024 | Critical 9.2 | Palo Alto Networks | In CISA KEV | The fixes for all listed issues are available in Expedition 1.2.96, and all later Expedition versions. All Expedition usernames, passwords, and API keys should be rotated after… | 0.996 |
| CVE-2024-9463 Oct 9, 2024 | Critical 9.9 | Palo Alto Networks | In CISA KEV | The fixes for all listed issues are available in Expedition 1.2.96, and all later Expedition versions. All Expedition usernames, passwords, and API keys should be rotated after… | 0.985 |
| CVE-2025-0108 Feb 12, 2025 | High 8.8 | Palo Alto Networks | In CISA KEV | Version Minor Version Suggested Solution PAN-OS 10.1 10.1.0 through 10.1.14 Upgrade to 10.1.14-h9 or later PAN-OS 10.2 10.2.0 through 10.2.13 Upgrade to 10.2.13-h3 or later 10.2… | 0.985 |
| CVE-2025-20281 Jun 25, 2025 | Critical 10 | Cisco | In CISA KEV | See the vendor advisory | 0.976 |
| CVE-2024-20439 Sep 4, 2024 | Critical 9.8 | Cisco | In CISA KEV | See the vendor advisory | 0.971 |
| CVE-2026-20253 Jun 10, 2026 | Critical 9.8 | Cisco | In CISA KEV | See the vendor advisory | 0.969 |
| CVE-2024-47575 Oct 23, 2024 | Critical 9.8 | Fortinet | In CISA KEV | Please upgrade to FortiManager Cloud version 7.6.2 or above Please upgrade to FortiManager Cloud version 7.4.5 or above Please upgrade to FortiManager Cloud version 7.2.8 or abo… | 0.948 |
| CVE-2026-21643 Feb 6, 2026 | Critical 9.1 | Fortinet | In CISA KEV | Upgrade to upcoming FortiClientEMS version 8.0.0 or above Upgrade to FortiClientEMS version 7.4.5 or above | 0.937 |
| CVE-2025-64446 Nov 14, 2025 | Critical 9.4 | Fortinet | In CISA KEV | Upgrade to FortiWeb version 8.0.2 or above Upgrade to FortiWeb version 7.6.5 or above Upgrade to FortiWeb version 7.4.10 or above Upgrade to FortiWeb version 7.2.12 or above Upg… | 0.918 |
| CVE-2024-5910 Jul 10, 2024 | Critical 9.3 | Palo Alto Networks | In CISA KEV | This issue is fixed in Expedition 1.2.92 and all later versions. | 0.918 |
| CVE-2026-20182 May 14, 2026 | Critical 10 | Cisco | In CISA KEV | See the vendor advisory | 0.915 |
| CVE-2026-20127 Feb 25, 2026 | Critical 10 | Cisco | In CISA KEV | See the vendor advisory | 0.885 |
| CVE-2026-20230 Jun 3, 2026 | High 8.6 | Cisco | In CISA KEV | See the vendor advisory | 0.882 |
| CVE-2026-20079 Mar 4, 2026 | Critical 10 | Cisco | In CISA KEV | See the vendor advisory | 0.882 |
| CVE-2025-20362 Sep 25, 2025 | Medium 6.5 | Cisco | In CISA KEV | See the vendor advisory | 0.871 |
| CVE-2026-24858 Jan 27, 2026 | Critical 9.4 | Fortinet | In CISA KEV | Upgrade to upcoming FortiOS version 8.0.0 or above Upgrade to FortiOS version 7.6.6 or above Upgrade to FortiOS version 7.4.11 or above Upgrade to FortiOS version 7.2.13 or abov… | 0.858 |
| CVE-2026-16232 Jul 22, 2026 | Critical 9.3 | Check Point | In CISA KEV | See the vendor advisory | 0.780 |
| CVE-2026-25089 Jun 9, 2026 | Critical 9.1 | Fortinet | In CISA KEV | Upgrade to upcoming FortiSandbox version 5.2.0 or above Upgrade to FortiSandbox version 5.0.6 or above Upgrade to FortiSandbox version 4.4.9 or above Upgrade to upcoming FortiSa… | 0.761 |
| CVE-2024-20353 Apr 24, 2024 | High 8.6 | Cisco | In CISA KEV | See the vendor advisory | 0.707 |
| CVE-2025-20333 Sep 25, 2025 | Critical 9.9 | Cisco | In CISA KEV | See the vendor advisory | 0.707 |
| CVE-2025-59718 Dec 9, 2025 | Critical 9.1 | Fortinet | In CISA KEV | Upgrade to FortiSwitchManager version 7.2.7 or above Upgrade to FortiSwitchManager version 7.0.6 or above Upgrade to FortiProxy version 7.6.4 or above Upgrade to FortiProxy vers… | 0.683 |
| CVE-2025-20337 Jul 16, 2025 | Critical 10 | Cisco | In CISA KEV | See the vendor advisory | 0.678 |
| CVE-2024-23113 Feb 15, 2024 | Critical 9.8 | Fortinet | In CISA KEV | Please upgrade to FortiWeb version 7.4.3 or above Please upgrade to FortiVoice version 7.0.2 or above Please upgrade to FortiVoice version 6.4.9 or above Please upgrade to Forti… | 0.617 |
| CVE-2025-58034 Nov 18, 2025 | Medium 6.7 | Fortinet | In CISA KEV | Upgrade to FortiWeb version 8.0.2 or above Upgrade to FortiWeb version 7.6.6 or above Upgrade to FortiWeb version 7.4.11 or above Upgrade to FortiWeb version 7.2.12 or above Upg… | 0.556 |
| CVE-2026-39808 Apr 14, 2026 | Critical 9.1 | Fortinet | In CISA KEV | Upgrade to FortiSandbox version 4.4.9 or above Upgrade to FortiSandbox PaaS version 5.0.2 or above | 0.474 |
| CVE-2025-20352 Sep 24, 2025 | High 7.7 | Cisco | In CISA KEV | See the vendor advisory | 0.394 |
| CVE-2025-20393 Dec 17, 2025 | Critical 10 | Cisco | In CISA KEV | See the vendor advisory | 0.324 |
| CVE-2026-20133 Feb 25, 2026 | Medium 6.5 | Cisco | In CISA KEV | See the vendor advisory | 0.318 |
| CVE-2026-0300 May 6, 2026 | Critical 9.3 | Palo Alto Networks | In CISA KEV | This issue will be fixed in upcoming releases of PAN-OS as captured in the table above. We strongly recommend that you secure access to your User-ID™ Authentication Portal follo… | 0.317 |
| CVE-2025-32756 May 13, 2025 | Critical 9.6 | Fortinet | In CISA KEV | Upgrade to FortiNDR version 7.6.1 or above Upgrade to FortiNDR version 7.4.8 or above Upgrade to FortiNDR version 7.2.5 or above Upgrade to FortiNDR version 7.0.7 or above Upgra… | 0.298 |
| CVE-2025-68686 Feb 10, 2026 | Medium 5.3 | Fortinet | In CISA KEV | Upgrade to FortiOS version 7.6.2 or above Upgrade to FortiOS version 7.4.7 or above | 0.296 |
| CVE-2024-3393 Dec 27, 2024 | High 8.7 | Palo Alto Networks | In CISA KEV | This issue is fixed in PAN-OS 10.1.14-h8, PAN-OS 10.2.10-h12, PAN-OS 11.1.5, PAN-OS 11.2.3, and all later PAN-OS versions. Note: PAN-OS 11.0 reached the end of life (EOL) on Nov… | 0.284 |
| CVE-2026-76461 Sep 14, 2026 | Critical 9.8 | Cisco | In CISA KEV | See the vendor advisory | 0.283 |
| CVE-2026-20262 Jun 15, 2026 | Medium 6.5 | Cisco | In CISA KEV | See the vendor advisory | 0.282 |
| CVE-2026-20245 Jun 4, 2026 | High 7.8 | Cisco | In CISA KEV | See the vendor advisory | 0.253 |
| CVE-2026-20122 Feb 25, 2026 | Medium 5.4 | Cisco | In CISA KEV | See the vendor advisory | 0.250 |
| CVE-2026-93616 Sep 22, 2026 | Critical 9.8 | Check Point | In CISA KEV | See the vendor advisory | 0.197 |
| CVE-2024-20359 Apr 24, 2024 | Medium 6 | Cisco | In CISA KEV | See the vendor advisory | 0.194 |
| CVE-2024-20481 Oct 23, 2024 | Medium 5.8 | Cisco | In CISA KEV | See the vendor advisory | 0.158 |
| CVE-2026-76460 Sep 16, 2026 | Critical 10 | Cisco | In CISA KEV | See the vendor advisory | 0.140 |
| CVE-2026-35616 Apr 4, 2026 | Critical 9.1 | Fortinet | In CISA KEV | Upgrade to upcoming FortiClientEMS version 8.0.0 or above Upgrade to FortiClientEMS version 7.4.7 or above | 0.091 |
| CVE-2026-85102 Sep 9, 2026 | Critical 9.8 | Check Point | In CISA KEV | See the vendor advisory | 0.075 |
| CVE-2026-20128 Feb 25, 2026 | High 7.5 | Cisco | In CISA KEV | See the vendor advisory | 0.071 |
| CVE-2026-20045 Jan 21, 2026 | High 8.2 | Cisco | In CISA KEV | See the vendor advisory | 0.045 |
| CVE-2024-20399 Jul 1, 2024 | Medium 6 | Cisco | In CISA KEV | See the vendor advisory | 0.043 |
| CVE-2025-25249 Jan 13, 2026 | High 7.4 | Fortinet | In CISA KEV | Upgrade to FortiSwitchManager version 7.2.7 or above Upgrade to FortiSwitchManager version 7.0.6 or above Fortinet remediated this issue in FortiSASE version 25.2.c and hence cu… | 0.039 |
| CVE-2025-0111 Feb 12, 2025 | High 7.1 | Palo Alto Networks | In CISA KEV | Version Minor Version Suggested Solution PAN-OS 10.1 10.1.0 through 10.1.14 Upgrade to 10.1.14-h9 or later PAN-OS 10.2 10.2.0 through 10.2.13 Upgrade to 10.2.13-h3 or later 10.2… | 0.020 |
| CVE-2026-20349 Aug 11, 2026 | High 8.6 | Cisco | In CISA KEV | See the vendor advisory | 0.010 |
Tier 2: Likely next (36)
Not yet in KEV, but EPSS is at least 0.1 or has risen by at least 0.05 over the last 30 days.
| CVE | Severity | Vendor | Why it is here | Fix | EPSS |
|---|---|---|---|---|---|
| CVE-2024-20328 Mar 1, 2024 | Medium 5.3 | Cisco | EPSS 0.85 | See the vendor advisory | 0.848 |
| CVE-2024-9464 Oct 9, 2024 | Critical 9.3 | Palo Alto Networks | EPSS 0.83 | The fixes for all listed issues are available in Expedition 1.2.96, and all later Expedition versions. All Expedition usernames, passwords, and API keys should be rotated after… | 0.826 |
| CVE-2024-20419 Jul 17, 2024 | Critical 10 | Cisco | EPSS 0.81 | See the vendor advisory | 0.806 |
| CVE-2025-0107 Jan 11, 2025 | High 7.7 | Palo Alto Networks | EPSS 0.79 | This issue is fixed in Expedition 1.2.100 and all later versions* of Expedition. * Expedition reached its End of Life (EoL) date https://live.paloaltonetworks.com/t5/expedition-… | 0.785 |
| CVE-2024-23108 Feb 5, 2024 | Critical 9.7 | Fortinet | EPSS 0.78 | Please upgrade to FortiSIEM version 7.1.2 or above Please upgrade to FortiSIEM version 7.0.3 or above Please upgrade to FortiSIEM version 6.7.9 or above Please upgrade to FortiS… | 0.784 |
| CVE-2025-25256 Aug 12, 2025 | Critical 9.8 | Fortinet | EPSS 0.65 | Upgrade to FortiSIEM version 7.4.0 or above Upgrade to FortiSIEM version 7.3.2 or above Upgrade to FortiSIEM version 7.2.6 or above Upgrade to FortiSIEM version 7.1.8 or above U… | 0.647 |
| CVE-2024-20440 Sep 4, 2024 | High 7.5 | Cisco | EPSS 0.52 | See the vendor advisory | 0.519 |
| CVE-2025-0133 May 14, 2025 | Low 1.2 | Palo Alto Networks | EPSS 0.46 | VERSION MINOR VERSION SUGGESTED SOLUTION PAN-OS 11.2 11.2.0 through 11.2.4 Upgrade to 11.2.4-h9 or later 11.2.5 through 11.2.6 Upgrade to 11.2.7 or later PAN-OS 11.1 11.1.0 thro… | 0.464 |
| CVE-2025-64155 Jan 13, 2026 | Critical 9.4 | Fortinet | EPSS 0.43 | Upgrade to FortiSIEM version 7.5.0 or above Upgrade to FortiSIEM version 7.4.1 or above Upgrade to FortiSIEM version 7.3.5 or above Upgrade to FortiSIEM version 7.2.7 or above U… | 0.428 |
| CVE-2025-20282 Jun 25, 2025 | Critical 10 | Cisco | EPSS 0.39EPSS up 0.12 in 30 days | See the vendor advisory | 0.387 |
| CVE-2024-20290 Feb 7, 2024 | High 7.5 | Cisco | EPSS 0.34 | See the vendor advisory | 0.336 |
| CVE-2024-20356 Apr 24, 2024 | High 8.7 | Cisco | EPSS 0.33 | See the vendor advisory | 0.327 |
| CVE-2026-20251 Jun 10, 2026 | High 8.8 | Cisco | EPSS 0.32 | See the vendor advisory | 0.322 |
| CVE-2024-20337 Mar 6, 2024 | High 8.2 | Cisco | EPSS 0.30 | See the vendor advisory | 0.299 |
| CVE-2025-59719 Dec 9, 2025 | Critical 9.1 | Fortinet | EPSS 0.29 | Upgrade to FortiSwitchManager version 7.2.7 or above Upgrade to FortiSwitchManager version 7.0.6 or above Upgrade to FortiProxy version 7.6.4 or above Upgrade to FortiProxy vers… | 0.292 |
| CVE-2025-20297 Jun 2, 2025 | Medium 4.3 | Cisco | EPSS 0.29EPSS up 0.09 in 30 days | See the vendor advisory | 0.287 |
| CVE-2024-27781 Feb 11, 2025 | Medium 6.9 | Fortinet | EPSS 0.28 | Upgrade to FortiSandbox version 4.4.5 or above Upgrade to FortiSandbox version 4.2.7 or above Upgrade to FortiSandbox version 4.0.5 or above Fortinet remediated this issue in Fo… | 0.282 |
| CVE-2025-20188 May 7, 2025 | Critical 10 | Cisco | EPSS 0.27 | See the vendor advisory | 0.271 |
| CVE-2024-20404 Jun 5, 2024 | High 7.2 | Cisco | EPSS 0.23 | See the vendor advisory | 0.226 |
| CVE-2025-20124 Feb 5, 2025 | Critical 9.9 | Cisco | EPSS 0.18 | See the vendor advisory | 0.185 |
| CVE-2025-20284 Jul 16, 2025 | Medium 6.5 | Cisco | EPSS 0.17 | See the vendor advisory | 0.174 |
| CVE-2025-53949 Dec 9, 2025 | High 7 | Fortinet | EPSS 0.17 | Upgrade to FortiSandbox version 5.0.3 or above Upgrade to FortiSandbox version 4.4.8 or above | 0.172 |
| CVE-2025-25254 Apr 8, 2025 | Medium 6.8 | Fortinet | EPSS 0.17 | Please upgrade to FortiWeb version 7.6.3 or above Please upgrade to FortiWeb version 7.4.7 or above | 0.171 |
| CVE-2025-20125 Feb 5, 2025 | Critical 9.1 | Cisco | EPSS 0.16 | See the vendor advisory | 0.164 |
| CVE-2025-20229 Mar 26, 2025 | High 8 | Cisco | EPSS 0.16 | See the vendor advisory | 0.160 |
| CVE-2025-20265 Aug 14, 2025 | Critical 10 | Cisco | EPSS 0.16 | See the vendor advisory | 0.158 |
| CVE-2024-48887 Apr 8, 2025 | Critical 9.3 | Fortinet | EPSS 0.16 | Please upgrade to FortiSwitch version 7.6.1 or above Please upgrade to FortiSwitch version 7.4.5 or above Please upgrade to FortiSwitch version 7.2.9 or above Please upgrade to… | 0.157 |
| CVE-2024-48884 Jan 14, 2025 | High 7.1 | Fortinet | EPSS 0.15 | Upgrade to upcoming FortiAuthenticator version 7.0.0 or above Upgrade to FortiOS version 7.6.1 or above Upgrade to FortiOS version 7.4.5 or above Upgrade to FortiOS version 7.2.… | 0.153 |
| CVE-2024-45741 Oct 14, 2024 | Medium 5.4 | Cisco | EPSS 0.15 | See the vendor advisory | 0.148 |
| CVE-2024-9466 Oct 9, 2024 | High 8.2 | Palo Alto Networks | EPSS 0.14 | The fixes for all listed issues are available in Expedition 1.2.96, and all later Expedition versions. The affected cleartext file will be removed automatically during the upgra… | 0.136 |
| CVE-2025-0105 Jan 11, 2025 | Medium 6.9 | Palo Alto Networks | EPSS 0.13 | This issue is fixed in Expedition 1.2.101 and all later versions* of Expedition. * Expedition reached its End of Life (EoL) date https://live.paloaltonetworks.com/t5/expedition-… | 0.133 |
| CVE-2024-36991 Jul 1, 2024 | High 7.5 | Cisco | EPSS 0.13 | See the vendor advisory | 0.130 |
| CVE-2025-53679 Dec 9, 2025 | Medium 6.9 | Fortinet | EPSS 0.12 | Upgrade to FortiSandbox version 5.0.3 or above Upgrade to FortiSandbox version 4.4.8 or above Fortinet remediated this issue in FortiSandbox Cloud version 24.2 (not released) an… | 0.123 |
| CVE-2026-20147 Apr 15, 2026 | Critical 9.9 | Cisco | EPSS 0.10 | See the vendor advisory | 0.104 |
| CVE-2025-52970 Aug 12, 2025 | High 7.7 | Fortinet | EPSS 0.10 | Upgrade to FortiWeb version 8.0.0 or above Upgrade to FortiWeb version 7.6.4 or above Upgrade to FortiWeb version 7.4.8 or above Upgrade to FortiWeb version 7.2.11 or above Upgr… | 0.101 |
| CVE-2024-54018 Mar 11, 2025 | Medium 6.5 | Fortinet | EPSS 0.10 | Upgrade to FortiSandbox version 5.0.0 or above Upgrade to FortiSandbox version 4.4.6 or above | 0.100 |
Tier 3: Open to the network (86)
Critical or High, reachable remotely with no authentication and no user interaction, and published in the last 90 days.
| CVE | Severity | Vendor | Why it is here | Fix | EPSS |
|---|---|---|---|---|---|
| CVE-2026-85103 Sep 9, 2026 | Critical 9.8 | Check Point | Remote, no authCritical, 20 days old | See the vendor advisory | 0.037 |
| CVE-2026-62144 Jul 22, 2026 | Critical 9.1 | Check Point | Remote, no authCritical, 69 days old | See the vendor advisory | 0.010 |
| CVE-2026-18574 Aug 3, 2026 | Critical 9.3 | Check Point | Remote, no authCritical, 57 days old | See the vendor advisory | 0.009 |
| CVE-2026-0288 Jul 8, 2026 | High 7.2 | Palo Alto Networks | Remote, no authHigh, 82 days old | Version Minor Version Suggested Solution Cloud NGFWNo action needed. PAN-OS 12.1 12.1.5 through 12.1.7-h* Upgrade to 12.1.7-h2 or 12.1.8 or later. 12.1.2 through 12.1.4-h* Upgra… | 0.008 |
| CVE-2026-26035 Aug 12, 2026 | High 8.8 | Fortinet | Remote, no authHigh, 48 days old | Upgrade to FortiWeb version 8.0.3 or above Upgrade to FortiWeb version 7.6.7 or above Upgrade to FortiWeb version 7.4.12 or above Upgrade to upcoming FortiWeb version 7.2.13 or… | 0.007 |
| CVE-2026-20274 Sep 2, 2026 | Critical 9.8 | Cisco | Remote, no authCritical, 26 days old | See the vendor advisory | 0.007 |
| CVE-2026-20212 Sep 2, 2026 | Critical 9.8 | Cisco | Remote, no authCritical, 26 days old | See the vendor advisory | 0.007 |
| CVE-2026-20191 Jul 1, 2026 | High 7.5 | Cisco | Remote, no authHigh, 89 days old | See the vendor advisory | 0.006 |
| CVE-2026-20242 Sep 16, 2026 | Critical 9.8 | Cisco | Remote, no authCritical, 12 days old | See the vendor advisory | 0.006 |
| CVE-2026-76440 Sep 14, 2026 | Critical 9.8 | Cisco | Remote, no authCritical, 14 days old | See the vendor advisory | 0.006 |
| CVE-2026-20357 Aug 19, 2026 | Critical 10 | Cisco | Remote, no authCritical, 40 days old | See the vendor advisory | 0.006 |
| CVE-2026-76356 Aug 19, 2026 | High 8.1 | Cisco | Remote, no authHigh, 40 days old | Upgrade Splunk SOAR to 8.6.0 or higher. | 0.006 |
| CVE-2026-76423 Sep 16, 2026 | Critical 10 | Cisco | Remote, no authCritical, 12 days old | See the vendor advisory | 0.006 |
| CVE-2026-20301 Aug 5, 2026 | High 8.6 | Cisco | Remote, no authHigh, 54 days old | See the vendor advisory | 0.006 |
| CVE-2026-20272 Aug 5, 2026 | Critical 9.8 | Cisco | Remote, no authCritical, 54 days old | See the vendor advisory | 0.006 |
| CVE-2026-20263 Aug 5, 2026 | High 8.6 | Cisco | Remote, no authHigh, 54 days old | See the vendor advisory | 0.006 |
| CVE-2026-20243 Jul 1, 2026 | High 7.5 | Cisco | Remote, no authHigh, 89 days old | See the vendor advisory | 0.006 |
| CVE-2026-20244 Jul 1, 2026 | High 7.5 | Cisco | Remote, no authHigh, 89 days old | See the vendor advisory | 0.006 |
| CVE-2026-20215 Jul 1, 2026 | High 7.5 | Cisco | Remote, no authHigh, 89 days old | See the vendor advisory | 0.006 |
| CVE-2026-20217 Jul 1, 2026 | High 7.5 | Cisco | Remote, no authHigh, 89 days old | See the vendor advisory | 0.006 |
| CVE-2026-20216 Jul 1, 2026 | High 7.5 | Cisco | Remote, no authHigh, 89 days old | See the vendor advisory | 0.006 |
| CVE-2026-20213 Jul 1, 2026 | High 7.5 | Cisco | Remote, no authHigh, 89 days old | See the vendor advisory | 0.006 |
| CVE-2026-20214 Jul 1, 2026 | High 7.5 | Cisco | Remote, no authHigh, 89 days old | See the vendor advisory | 0.006 |
| CVE-2026-20317 Aug 19, 2026 | Critical 10 | Cisco | Remote, no authCritical, 40 days old | See the vendor advisory | 0.006 |
| CVE-2026-20295 Sep 16, 2026 | High 8.6 | Cisco | Remote, no authHigh, 12 days old | See the vendor advisory | 0.005 |
| CVE-2026-20250 Sep 16, 2026 | High 8.6 | Cisco | Remote, no authHigh, 12 days old | See the vendor advisory | 0.005 |
| CVE-2026-20030 Aug 19, 2026 | Critical 10 | Cisco | Remote, no authCritical, 40 days old | See the vendor advisory | 0.005 |
| CVE-2026-76441 Sep 14, 2026 | Critical 9.8 | Cisco | Remote, no authCritical, 14 days old | See the vendor advisory | 0.005 |
| CVE-2026-76443 Sep 14, 2026 | Critical 9.8 | Cisco | Remote, no authCritical, 14 days old | See the vendor advisory | 0.005 |
| CVE-2025-53379 Jul 14, 2026 | High 7 | Fortinet | Remote, no authHigh, 76 days old | Upgrade to FortiAuthenticator version 6.6.3 or above | 0.005 |
| CVE-2026-91843 Sep 16, 2026 | Critical 9.8 | Check Point | Remote, no authCritical, 13 days old | See the vendor advisory | 0.005 |
| CVE-2026-70465 Aug 12, 2026 | High 7.3 | Fortinet | Remote, no authHigh, 48 days old | Upgrade to FortiClientWindows version 7.4.4 or above Upgrade to FortiClientWindows version 7.2.12 or above | 0.005 |
| CVE-2026-20337 Aug 7, 2026 | High 7.5 | Cisco | Remote, no authHigh, 52 days old | See the vendor advisory | 0.005 |
| CVE-2026-76262 Aug 19, 2026 | High 7.5 | Cisco | Remote, no authHigh, 40 days old | Upgrade Splunk Enterprise to versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14, or higher. | 0.005 |
| CVE-2026-76355 Aug 19, 2026 | High 7.5 | Cisco | Remote, no authHigh, 40 days old | Upgrade Splunk Enterprise to versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14, or higher. | 0.005 |
| CVE-2026-20320 Aug 19, 2026 | High 7.5 | Cisco | Remote, no authHigh, 40 days old | See the vendor advisory | 0.005 |
| CVE-2026-20315 Aug 19, 2026 | Critical 10 | Cisco | Remote, no authCritical, 40 days old | See the vendor advisory | 0.005 |
| CVE-2026-20358 Aug 19, 2026 | Critical 10 | Cisco | Remote, no authCritical, 40 days old | See the vendor advisory | 0.005 |
| CVE-2026-20338 Aug 7, 2026 | High 7.5 | Cisco | Remote, no authHigh, 52 days old | See the vendor advisory | 0.005 |
| CVE-2026-76338 Aug 19, 2026 | High 8.1 | Cisco | Remote, no authHigh, 40 days old | Upgrade Splunk Enterprise to versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14, or higher. Set `strictPeerNameValidation = true` in `authentication.conf` on every distributed node, th… | 0.005 |
| CVE-2026-76442 Sep 14, 2026 | High 7.5 | Cisco | Remote, no authHigh, 14 days old | See the vendor advisory | 0.005 |
| CVE-2026-20319 Aug 19, 2026 | High 7.5 | Cisco | Remote, no authHigh, 40 days old | See the vendor advisory | 0.005 |
| CVE-2026-20273 Aug 5, 2026 | High 8.6 | Cisco | Remote, no authHigh, 54 days old | See the vendor advisory | 0.005 |
| CVE-2026-20271 Aug 5, 2026 | High 8.6 | Cisco | Remote, no authHigh, 54 days old | See the vendor advisory | 0.005 |
| CVE-2026-20270 Aug 5, 2026 | High 8.6 | Cisco | Remote, no authHigh, 54 days old | See the vendor advisory | 0.005 |
| CVE-2026-20269 Aug 5, 2026 | High 8.6 | Cisco | Remote, no authHigh, 54 days old | See the vendor advisory | 0.005 |
| CVE-2026-20268 Aug 5, 2026 | High 8.6 | Cisco | Remote, no authHigh, 54 days old | See the vendor advisory | 0.005 |
| CVE-2026-20187 Jul 15, 2026 | High 7.5 | Cisco | Remote, no authHigh, 75 days old | See the vendor advisory | 0.005 |
| CVE-2026-20158 Jul 15, 2026 | High 7.5 | Cisco | Remote, no authHigh, 75 days old | See the vendor advisory | 0.005 |
| CVE-2026-20153 Jul 15, 2026 | High 7.5 | Cisco | Remote, no authHigh, 75 days old | See the vendor advisory | 0.005 |
| CVE-2026-20348 Aug 7, 2026 | High 7.5 | Cisco | Remote, no authHigh, 52 days old | See the vendor advisory | 0.005 |
| CVE-2026-20345 Aug 7, 2026 | High 7.5 | Cisco | Remote, no authHigh, 52 days old | See the vendor advisory | 0.005 |
| CVE-2026-20339 Aug 7, 2026 | High 7.5 | Cisco | Remote, no authHigh, 52 days old | See the vendor advisory | 0.005 |
| CVE-2026-20347 Aug 7, 2026 | High 7.5 | Cisco | Remote, no authHigh, 52 days old | See the vendor advisory | 0.005 |
| CVE-2026-70468 Aug 12, 2026 | High 7.3 | Fortinet | Remote, no authHigh, 48 days old | Upgrade to FortiManager Cloud version 7.6.2 or above Upgrade to FortiManager Cloud version 7.4.6 or above Upgrade to FortiManager Cloud version 7.2.10 or above Upgrade to FortiM… | 0.005 |
| CVE-2026-20156 Jul 15, 2026 | High 8.1 | Cisco | Remote, no authHigh, 75 days old | See the vendor advisory | 0.005 |
| CVE-2026-20192 Sep 16, 2026 | Critical 10 | Cisco | Remote, no authCritical, 12 days old | See the vendor advisory | 0.005 |
| CVE-2026-20135 Sep 16, 2026 | High 8.6 | Cisco | Remote, no authHigh, 12 days old | See the vendor advisory | 0.005 |
| CVE-2026-76413 Sep 16, 2026 | High 8.2 | Cisco | Remote, no authHigh, 12 days old | See the vendor advisory | 0.005 |
| CVE-2026-20343 Sep 16, 2026 | High 7.5 | Cisco | Remote, no authHigh, 12 days old | See the vendor advisory | 0.004 |
| CVE-2026-76312 Aug 19, 2026 | Critical 9.4 | Cisco | Remote, no authCritical, 40 days old | Upgrade Splunk Enterprise to versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14, or higher. | 0.004 |
| CVE-2026-76311 Aug 19, 2026 | Critical 9.4 | Cisco | Remote, no authCritical, 40 days old | Upgrade Splunk Enterprise to versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14, or higher. | 0.004 |
| CVE-2026-76310 Aug 19, 2026 | Critical 9.4 | Cisco | Remote, no authCritical, 40 days old | Upgrade Splunk Enterprise to versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14, or higher. | 0.004 |
| CVE-2026-20346 Aug 7, 2026 | High 7.5 | Cisco | Remote, no authHigh, 52 days old | See the vendor advisory | 0.004 |
| CVE-2026-76321 Aug 19, 2026 | High 7.3 | Cisco | Remote, no authHigh, 40 days old | Upgrade Splunk Enterprise to versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14, or higher. | 0.004 |
| CVE-2026-76402 Aug 19, 2026 | High 8.2 | Cisco | Remote, no authHigh, 40 days old | Upgrade each affected Splunk app or add-on to the applicable fixed version listed in Product Status. | 0.004 |
| CVE-2026-20154 Sep 16, 2026 | High 8.6 | Cisco | Remote, no authHigh, 12 days old | See the vendor advisory | 0.004 |
| CVE-2026-20352 Sep 16, 2026 | High 8.6 | Cisco | Remote, no authHigh, 12 days old | See the vendor advisory | 0.004 |
| CVE-2026-20249 Sep 16, 2026 | High 8.6 | Cisco | Remote, no authHigh, 12 days old | See the vendor advisory | 0.004 |
| CVE-2026-20353 Sep 14, 2026 | Critical 9.8 | Cisco | Remote, no authCritical, 14 days old | See the vendor advisory | 0.004 |
| CVE-2026-20130 Sep 16, 2026 | Critical 10 | Cisco | Remote, no authCritical, 12 days old | See the vendor advisory | 0.004 |
| CVE-2026-59835 Jul 14, 2026 | High 7.7 | Fortinet | Remote, no authHigh, 76 days old | Upgrade to FortiSandbox version 5.0.3 or above Upgrade to FortiSandbox version 4.4.9 or above | 0.004 |
| CVE-2026-26084 Sep 8, 2026 | High 8.9 | Fortinet | Remote, no authHigh, 20 days old | Upgrade to FortiSandbox version 5.2.0 or above Upgrade to FortiSandbox version 5.0.6 or above Upgrade to FortiSandbox version 4.4.9 or above Upgrade to FortiSandbox Cloud versio… | 0.004 |
| CVE-2026-20326 Sep 16, 2026 | Critical 9.8 | Cisco | Remote, no authCritical, 12 days old | See the vendor advisory | 0.004 |
| CVE-2026-20267 Aug 5, 2026 | Critical 9 | Cisco | Remote, no authCritical, 54 days old | See the vendor advisory | 0.004 |
| CVE-2026-76420 Sep 16, 2026 | Critical 9 | Cisco | Remote, no authCritical, 12 days old | See the vendor advisory | 0.004 |
| CVE-2026-0310 Sep 10, 2026 | High 7.2 | Palo Alto Networks | Remote, no authHigh, 19 days old | VERSION MINOR VERSION SUGGESTED SOLUTION Cloud NGFW Customers who prefer to upgrade can work with Palo Alto Networks support to schedule an on-demand software upgrade. PAN-OS 12… | 0.004 |
| CVE-2026-20281 Sep 2, 2026 | High 7.5 | Cisco | Remote, no authHigh, 26 days old | See the vendor advisory | 0.004 |
| CVE-2026-20247 Sep 16, 2026 | High 7.5 | Cisco | Remote, no authHigh, 12 days old | See the vendor advisory | 0.003 |
| CVE-2026-20279 Sep 2, 2026 | Critical 9.8 | Cisco | Remote, no authCritical, 26 days old | See the vendor advisory | 0.003 |
| CVE-2026-20335 Sep 16, 2026 | High 8.1 | Cisco | Remote, no authHigh, 12 days old | See the vendor advisory | 0.003 |
| CVE-2026-20276 Sep 2, 2026 | High 8.6 | Cisco | Remote, no authHigh, 26 days old | See the vendor advisory | 0.003 |
| CVE-2026-84393 Sep 8, 2026 | High 7.3 | Fortinet | Remote, no authHigh, 20 days old | Upgrade to FortiOS version 8.0.0 or above Upgrade to FortiOS version 7.6.7 or above Upgrade to upcoming FortiProxy version 8.0.0 or above Upgrade to upcoming FortiProxy version… | 0.002 |
| CVE-2026-76403 Aug 19, 2026 | High 7.4 | Cisco | Remote, no authHigh, 40 days old | Upgrade each affected Splunk app or add-on to the applicable fixed version listed in Product Status. | 0.002 |
| CVE-2026-20277 Sep 2, 2026 | High 8.2 | Cisco | Remote, no authHigh, 26 days old | See the vendor advisory | 0.002 |
| CVE-2026-76362 Aug 19, 2026 | High 7.4 | Cisco | Remote, no authHigh, 40 days old | Upgrade Splunk SOAR to 8.6.0 or higher. For existing CyberArk REST credential-manager configurations, turn on Verify server certificate after upgrading. | 0.002 |
Biggest EPSS rises
EPSS estimates the probability of exploitation in the next 30 days. A sharp rise is often the first public sign that attackers have taken an interest, ahead of any KEV listing. Current scores as of Sep 29, 2026.
Last 7 days
| CVE | Was | Now | Rise |
|---|---|---|---|
| CVE-2026-76461 KEV | 0.020 | 0.283 | +0.263 |
| CVE-2026-20316 KEV | 0.112 | 0.351 | +0.239 |
| CVE-2026-76460 KEV | 0.008 | 0.140 | +0.132 |
| CVE-2026-20079 KEV | 0.758 | 0.882 | +0.124 |
| CVE-2025-20282 | 0.275 | 0.387 | +0.112 |
| CVE-2026-20131 KEV | 0.334 | 0.427 | +0.093 |
| CVE-2026-85102 KEV | 0.003 | 0.075 | +0.072 |
| CVE-2026-16232 KEV | 0.721 | 0.780 | +0.059 |
| CVE-2024-20439 KEV | 0.921 | 0.971 | +0.050 |
| CVE-2026-85103 | 0.004 | 0.037 | +0.033 |
Last 30 days
| CVE | Was | Now | Rise |
|---|---|---|---|
| CVE-2026-20079 KEV | 0.359 | 0.882 | +0.522 |
| CVE-2026-20316 KEV | 0.098 | 0.351 | +0.253 |
| CVE-2025-20282 | 0.270 | 0.387 | +0.117 |
| CVE-2026-20131 KEV | 0.312 | 0.427 | +0.114 |
| CVE-2025-20297 | 0.197 | 0.287 | +0.090 |
| CVE-2026-16232 KEV | 0.721 | 0.780 | +0.059 |
| CVE-2024-20439 KEV | 0.921 | 0.971 | +0.050 |
| CVE-2025-25256 | 0.603 | 0.647 | +0.044 |
| CVE-2025-25249 KEV | 0.008 | 0.039 | +0.031 |
| CVE-2025-20393 KEV | 0.299 | 0.324 | +0.025 |
Tier rules are on the methodology page. Thresholds: EPSS ≥ 0.1, a rise of ≥ 0.05 over 30 days, and a 90-day window for new remote no-auth bugs. EPSS data courtesy of FIRST. Known-exploited status from CISA KEV.