21 vulnerabilities we’ve flagged as relevant to Finance are confirmed exploited in the wild (CISA KEV), and 5 (24%) are tied to ransomware.
Ransomware in Finance, exploitation trends, and the full list — below.
Exploited Finance-relevant vulnerabilities
| CVE | Product | KEV added | |
|---|---|---|---|
| CVE-2026-53362 | Linux Kernel | 2026-08-27 | |
| CVE-2026-66384 | JFrog Artifactory | 2026-08-27 | |
| CVE-2026-21962 | Oracle HTTP Server And Oracle Weblogic Server Proxy Plug-In | 2026-08-24 | |
| CVE-2026-73570 | Synacor Zimbra Collaboration Suite (ZCS) | 2026-08-21 | |
| CVE-2026-72530 | TrueConf Server | 2026-08-20 | |
| CVE-2026-50522 | Microsoft SharePoint | 2026-07-22 | |
| CVE-2026-16232 | Check Point SmartConsole | 2026-07-22 | |
| CVE-2026-15409 | SonicWall SMA1000 Appliances | 2026-07-14 | ransomware |
| CVE-2026-15410 | SonicWall SMA1000 Appliances | 2026-07-14 | ransomware |
| CVE-2026-50751 | Check Point Security Gateway | 2026-06-08 | ransomware |
| CVE-2026-42897 | Microsoft Exchange Server | 2026-05-15 | |
| CVE-2026-42208 | BerriAI LiteLLM | 2026-05-08 | |
| CVE-2026-6973 | Ivanti Endpoint Manager Mobile (EPMM) | 2026-05-07 | |
| CVE-2026-0300 | Palo Alto Networks PAN-OS | 2026-05-06 | |
| CVE-2026-31431 | Linux Kernel | 2026-05-01 | |
| CVE-2026-41940 | WebPros CPanel & WHM And WP2 (WordPress Squared) | 2026-04-30 | ransomware |
| CVE-2026-34621 | Adobe Acrobat And Reader | 2026-04-13 | |
| CVE-2026-35616 | Fortinet FortiClient EMS | 2026-04-06 | |
| CVE-2026-3055 | Citrix NetScaler | 2026-03-30 | |
| CVE-2025-53521 | F5 BIG-IP | 2026-03-27 | |
| CVE-2025-55182 | Meta React Server Components | 2025-12-05 | ransomware |
How we count
This counts vulnerabilities that (a) defend.network has editorially tagged as relevant to the Finance sector in our vulnerability reports, and (b) CISA has confirmed exploited in the wild (in the KEV catalog). The sector tag reflects our editorial judgment about relevance, not a claim of exclusive impact — most vulnerabilities affect multiple sectors. Product names come from NVD/CISA (authoritative). Rows our reconciliation gate flags as mis-attributed are excluded. “Ransomware” uses CISA’s knownRansomwareUse flag. As of 2026-08-31.
Other sectors: Government · Healthcare · Technology · State of Exploited Vulnerabilities