39 vulnerabilities we’ve flagged as relevant to Government are confirmed exploited in the wild (CISA KEV), and 6 (15%) are tied to ransomware.
Ransomware in Government, exploitation trends, and the full list — below.
Exploited Government-relevant vulnerabilities
| CVE | Product | KEV added | |
|---|---|---|---|
| CVE-2026-53362 | Linux Kernel | 2026-08-27 | |
| CVE-2026-66384 | JFrog Artifactory | 2026-08-27 | |
| CVE-2026-21962 | Oracle HTTP Server And Oracle Weblogic Server Proxy Plug-In | 2026-08-24 | |
| CVE-2026-59310 | Broadcom VMware VCenter | 2026-08-18 | |
| CVE-2026-65400 | Apple MacOS | 2026-08-18 | |
| CVE-2026-55040 | Microsoft SharePoint | 2026-08-18 | |
| CVE-2026-20349 | Cisco Secure Firewall Adaptive Security Appliance (ASA) And Secure Firewall Threat Defense (FTD) | 2026-08-11 | |
| CVE-2026-68820 | Microsoft Windows Ancillary Function Driver For WinSock | 2026-08-11 | |
| CVE-2026-34486 | Apache Tomcat | 2026-08-04 | |
| CVE-2026-18556 | N-Able N-Central | 2026-08-04 | |
| CVE-2026-18577 | N-Able N-Central | 2026-08-03 | |
| CVE-2026-0770 | Langflow | 2026-07-21 | |
| CVE-2026-63030 | WordPress Core | 2026-07-21 | |
| CVE-2026-60137 | WordPress Core | 2026-07-21 | |
| CVE-2026-46817 | Oracle E-Business Suite | 2026-07-15 | |
| CVE-2026-56164 | Microsoft SharePoint Server | 2026-07-14 | |
| CVE-2026-56155 | Microsoft Active Directory Federation Services | 2026-07-14 | |
| CVE-2008-4128 | Cisco IOS | 2026-07-13 | |
| CVE-2026-45659 | Microsoft SharePoint Server | 2026-07-01 | ransomware |
| CVE-2026-20245 | Cisco Catalyst SD-WAN Manager | 2026-06-09 | |
| CVE-2026-50751 | Check Point Security Gateway | 2026-06-08 | ransomware |
| CVE-2025-48595 | Android Framework | 2026-06-02 | |
| CVE-2022-0492 | Linux Kernel | 2026-06-02 | |
| CVE-2024-21182 | Oracle WebLogic Server | 2026-06-01 | |
| CVE-2026-0257 | Palo Alto Networks PAN-OS | 2026-05-29 | ransomware |
| CVE-2026-42897 | Microsoft Exchange Server | 2026-05-15 | |
| CVE-2026-42208 | BerriAI LiteLLM | 2026-05-08 | |
| CVE-2026-6973 | Ivanti Endpoint Manager Mobile (EPMM) | 2026-05-07 | |
| CVE-2026-0300 | Palo Alto Networks PAN-OS | 2026-05-06 | |
| CVE-2026-31431 | Linux Kernel | 2026-05-01 | |
| CVE-2026-41940 | WebPros CPanel & WHM And WP2 (WordPress Squared) | 2026-04-30 | ransomware |
| CVE-2024-7399 | Samsung MagicINFO 9 Server | 2026-04-24 | |
| CVE-2026-32201 | Microsoft SharePoint Server | 2026-04-14 | |
| CVE-2026-34621 | Adobe Acrobat And Reader | 2026-04-13 | |
| CVE-2026-35616 | Fortinet FortiClient EMS | 2026-04-06 | |
| CVE-2026-3055 | Citrix NetScaler | 2026-03-30 | |
| CVE-2025-53521 | F5 BIG-IP | 2026-03-27 | |
| CVE-2025-55182 | Meta React Server Components | 2025-12-05 | ransomware |
| CVE-2025-8088 | RARLAB WinRAR | 2025-08-12 | ransomware |
How we count
This counts vulnerabilities that (a) defend.network has editorially tagged as relevant to the Government sector in our vulnerability reports, and (b) CISA has confirmed exploited in the wild (in the KEV catalog). The sector tag reflects our editorial judgment about relevance, not a claim of exclusive impact — most vulnerabilities affect multiple sectors. Product names come from NVD/CISA (authoritative). Rows our reconciliation gate flags as mis-attributed are excluded. “Ransomware” uses CISA’s knownRansomwareUse flag. As of 2026-08-31.
Other sectors: Finance · Healthcare · Technology · State of Exploited Vulnerabilities