Your toolchain
The tools you run to manage clients are themselves a target. Recent CVE activity in the RMM, PSA, and security vendors on your own stack, ranked by how many of their bugs reached CISA's exploited list.
Last updated: 11 August 2026 21:18 UTC
| Vendor | CVEs (30d) | KEV (1yr) | avg CVSS |
|---|---|---|---|
| cisco | 39 | 16 | 6.6 |
| fortinet | 12 | 9 | 6.4 |
| ivanti | 2 | 5 | 7.3 |
| solarwinds | 15 | 4 | 8.4 |
| n-able | 2 | 4 | 8.7 |
| sonicwall | 2 | 3 | 6.1 |
| vmware | 0 | 2 | 6.6 |
| anydesk | 2 | 0 | 7.6 |
| connectwise | 0 | 0 | 8.0 |
| barracuda | 0 | 0 | 9.7 |
| teamviewer | 0 | 0 | 6.6 |
| zohocorp | 0 | 0 | 6.7 |
Sorted by KEV listings in the last year, then by CVE volume in the last 30 days. A vendor on this list is not a reason to switch; it is a reason to confirm you are current on their patches before you patch anyone else.
Exploited bugs in your stack — confirm you are patched
Each vendor expands to the specific CISA-KEV bugs in its products. Patch your own management stack first: a compromised RMM or PSA is a path to every client at once. Confirm every client is on the fixed version of the affected products before you patch anyone downstream — these are on CISA’s Known Exploited list, so they are proven in the wild, not theoretical.
Cisco — 16 exploited bugs to confirm patched · 1 used in ransomware
- CVE-2026-20131 — Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability · Secure Firewall Management Center (FMC) · added 2026-03-19 ransomware
- CVE-2026-20349 — Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability · Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) · added 2026-08-11
- CVE-2026-20316 — Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability · Secure Firewall Management Center (FMC) · added 2026-07-29
- CVE-2008-4128 — Cisco IOS Cross-Site Request Forgery Vulnerability · IOS · added 2026-07-13
- CVE-2026-20230 — Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability · Unified Communications Manager · added 2026-06-25
- CVE-2026-20262 — Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability · Catalyst SD-WAN Manager · added 2026-06-15
- +12 more on the Cisco page
Fortinet — 9 exploited bugs to confirm patched
- CVE-2025-68686 — Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability · FortiOS · added 2026-07-27
- CVE-2026-39808 — Fortinet FortiSandbox OS Command Injection Vulnerability · FortiSandbox · added 2026-07-16
- CVE-2026-25089 — Fortinet FortiSandbox OS Command Injection Vulnerability · FortiSandbox · added 2026-07-16
- CVE-2026-21643 — Fortinet FortiClient EMS SQL Injection Vulnerability · FortiClient EMS · added 2026-04-13
- CVE-2026-35616 — Fortinet FortiClient EMS Improper Access Control Vulnerability · FortiClient EMS · added 2026-04-06
- CVE-2026-24858 — Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability · Multiple Products · added 2026-01-27
- +3 more on the Fortinet page
Ivanti — 5 exploited bugs to confirm patched
- CVE-2026-10520 — Ivanti Sentry OS Command Injection Vulnerability · Sentry · added 2026-06-11
- CVE-2026-6973 — Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability · Endpoint Manager Mobile (EPMM) · added 2026-05-07
- CVE-2026-1340 — Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability · Endpoint Manager Mobile (EPMM) · added 2026-04-08
- CVE-2026-1603 — Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability · Endpoint Manager (EPM) · added 2026-03-09
- CVE-2026-1281 — Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability · Endpoint Manager Mobile (EPMM) · added 2026-01-29
Solarwinds — 4 exploited bugs to confirm patched · 1 used in ransomware
- CVE-2025-26399 — SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability · Web Help Desk · added 2026-03-09 ransomware
- CVE-2026-28318 — SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability · Serv-U · added 2026-06-05
- CVE-2025-40536 — SolarWinds Web Help Desk Security Control Bypass Vulnerability · Web Help Desk · added 2026-02-12
- CVE-2025-40551 — SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability · Web Help Desk · added 2026-02-03
N-Able — 4 exploited bugs to confirm patched
- CVE-2026-18556 — N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · N-central · added 2026-08-04
- CVE-2026-18577 — N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · N-central · added 2026-08-03
Sonicwall — 3 exploited bugs to confirm patched · 2 used in ransomware
- CVE-2026-15410 — SonicWall SMA1000 Appliances Code Injection Vulnerability · SMA1000 Appliances · added 2026-07-14 ransomware
- CVE-2026-15409 — SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability · SMA1000 Appliances · added 2026-07-14 ransomware
- CVE-2025-40602 — SonicWall SMA1000 Missing Authorization Vulnerability · SMA1000 appliance · added 2025-12-17
Connectwise — 1 exploited bug to confirm patched · 1 used in ransomware
- CVE-2024-1708 — ConnectWise ScreenConnect Path Traversal Vulnerability · ScreenConnect · added 2026-04-28 ransomware