12 vulnerabilities we’ve flagged as relevant to Healthcare are confirmed exploited in the wild (CISA KEV), and 2 (17%) are tied to ransomware.
Ransomware in Healthcare, exploitation trends, and the full list — below.
Exploited Healthcare-relevant vulnerabilities
| CVE | Product | KEV added | |
|---|---|---|---|
| CVE-2026-59310 | Broadcom VMware VCenter | 2026-08-18 | |
| CVE-2026-65400 | Apple MacOS | 2026-08-18 | |
| CVE-2026-55040 | Microsoft SharePoint | 2026-08-18 | |
| CVE-2026-42897 | Microsoft Exchange Server | 2026-05-15 | |
| CVE-2026-6973 | Ivanti Endpoint Manager Mobile (EPMM) | 2026-05-07 | |
| CVE-2026-31431 | Linux Kernel | 2026-05-01 | |
| CVE-2026-41940 | WebPros CPanel & WHM And WP2 (WordPress Squared) | 2026-04-30 | ransomware |
| CVE-2026-34621 | Adobe Acrobat And Reader | 2026-04-13 | |
| CVE-2026-35616 | Fortinet FortiClient EMS | 2026-04-06 | |
| CVE-2026-3055 | Citrix NetScaler | 2026-03-30 | |
| CVE-2025-53521 | F5 BIG-IP | 2026-03-27 | |
| CVE-2025-55182 | Meta React Server Components | 2025-12-05 | ransomware |
How we count
This counts vulnerabilities that (a) defend.network has editorially tagged as relevant to the Healthcare sector in our vulnerability reports, and (b) CISA has confirmed exploited in the wild (in the KEV catalog). The sector tag reflects our editorial judgment about relevance, not a claim of exclusive impact — most vulnerabilities affect multiple sectors. Product names come from NVD/CISA (authoritative). Rows our reconciliation gate flags as mis-attributed are excluded. “Ransomware” uses CISA’s knownRansomwareUse flag. As of 2026-08-31.
Other sectors: Finance · Government · Technology · State of Exploited Vulnerabilities