Cyber Resilience

Your toolchain

The tools you run to manage clients are themselves a target. Recent CVE activity in the RMM, PSA, and security vendors on your own stack, ranked by how many of their bugs reached CISA's exploited list.

Last updated: 11 August 2026 21:18 UTC

VendorCVEs (30d)KEV (1yr)avg CVSS
cisco39166.6
fortinet1296.4
ivanti257.3
solarwinds1548.4
n-able248.7
sonicwall236.1
vmware026.6
anydesk207.6
connectwise008.0
barracuda009.7
teamviewer006.6
zohocorp006.7

Sorted by KEV listings in the last year, then by CVE volume in the last 30 days. A vendor on this list is not a reason to switch; it is a reason to confirm you are current on their patches before you patch anyone else.

Exploited bugs in your stack — confirm you are patched

Each vendor expands to the specific CISA-KEV bugs in its products. Patch your own management stack first: a compromised RMM or PSA is a path to every client at once. Confirm every client is on the fixed version of the affected products before you patch anyone downstream — these are on CISA’s Known Exploited list, so they are proven in the wild, not theoretical.

Cisco — 16 exploited bugs to confirm patched · 1 used in ransomware
Fortinet — 9 exploited bugs to confirm patched
Ivanti — 5 exploited bugs to confirm patched
Solarwinds — 4 exploited bugs to confirm patched · 1 used in ransomware
N-Able — 4 exploited bugs to confirm patched
Sonicwall — 3 exploited bugs to confirm patched · 2 used in ransomware
Connectwise — 1 exploited bug to confirm patched · 1 used in ransomware

← MSP Weekly