Research · Sector

Exploited Vulnerabilities in Healthcare

12 confirmed exploited · 2 ransomware-linked · as of 2026-08-31

12 vulnerabilities we’ve flagged as relevant to Healthcare are confirmed exploited in the wild (CISA KEV), and 2 (17%) are tied to ransomware.

Ransomware in Healthcare, exploitation trends, and the full list — below.

Exploited Healthcare-relevant vulnerabilities

CVEProductKEV added
CVE-2026-59310Broadcom VMware VCenter2026-08-18
CVE-2026-65400Apple MacOS2026-08-18
CVE-2026-55040Microsoft SharePoint2026-08-18
CVE-2026-42897Microsoft Exchange Server2026-05-15
CVE-2026-6973Ivanti Endpoint Manager Mobile (EPMM)2026-05-07
CVE-2026-31431Linux Kernel2026-05-01
CVE-2026-41940WebPros CPanel & WHM And WP2 (WordPress Squared)2026-04-30ransomware
CVE-2026-34621Adobe Acrobat And Reader2026-04-13
CVE-2026-35616Fortinet FortiClient EMS2026-04-06
CVE-2026-3055Citrix NetScaler2026-03-30
CVE-2025-53521F5 BIG-IP2026-03-27
CVE-2025-55182Meta React Server Components2025-12-05ransomware

How we count

This counts vulnerabilities that (a) defend.network has editorially tagged as relevant to the Healthcare sector in our vulnerability reports, and (b) CISA has confirmed exploited in the wild (in the KEV catalog). The sector tag reflects our editorial judgment about relevance, not a claim of exclusive impact — most vulnerabilities affect multiple sectors. Product names come from NVD/CISA (authoritative). Rows our reconciliation gate flags as mis-attributed are excluded. “Ransomware” uses CISA’s knownRansomwareUse flag. As of 2026-08-31.

Other sectors: Finance · Government · Technology  ·  State of Exploited Vulnerabilities

🤖 Generated deterministically from our editorial sector tags reconciled against the CISA KEV catalog. Free to cite with attribution to defend.network.

Track newly exploited vulnerabilities

Free daily briefing on CVEs added to CISA KEV and exploited in the wild.