Research · Sector

Exploited Vulnerabilities in Healthcare

16 confirmed exploited · 2 ransomware-linked · as of 2026-09-04

16 vulnerabilities we’ve flagged as relevant to Healthcare are confirmed exploited in the wild (CISA KEV), and 2 (13%) are tied to ransomware.

Ransomware in Healthcare, exploitation trends, and the full list — below.

Exploited Healthcare-relevant vulnerabilities

CVEProductKEV added
CVE-2026-49869Kestra OSS2026-09-02
CVE-2026-82329JFrog Artifactory2026-09-02
CVE-2026-81578PaperCut NG/MF2026-08-31
CVE-2026-82078PaperCut NG/MF2026-08-31
CVE-2026-59310Broadcom VMware VCenter2026-08-18
CVE-2026-65400Apple MacOS2026-08-18
CVE-2026-55040Microsoft SharePoint2026-08-18
CVE-2026-42897Microsoft Exchange Server2026-05-15
CVE-2026-6973Ivanti Endpoint Manager Mobile (EPMM)2026-05-07
CVE-2026-31431Linux Kernel2026-05-01
CVE-2026-41940WebPros CPanel & WHM And WP2 (WordPress Squared)2026-04-30ransomware
CVE-2026-34621Adobe Acrobat And Reader2026-04-13
CVE-2026-35616Fortinet FortiClient EMS2026-04-06
CVE-2026-3055Citrix NetScaler2026-03-30
CVE-2025-53521F5 BIG-IP2026-03-27
CVE-2025-55182Meta React Server Components2025-12-05ransomware

How we count

This counts vulnerabilities that (a) defend.network has editorially tagged as relevant to the Healthcare sector in our vulnerability reports, and (b) CISA has confirmed exploited in the wild (in the KEV catalog). The sector tag reflects our editorial judgment about relevance, not a claim of exclusive impact — most vulnerabilities affect multiple sectors. Product names come from NVD/CISA (authoritative). Rows our reconciliation gate flags as mis-attributed are excluded. “Ransomware” uses CISA’s knownRansomwareUse flag. As of 2026-09-04.

Other sectors: Finance · Government · Technology  ·  State of Exploited Vulnerabilities

🤖 Generated deterministically from our editorial sector tags reconciled against the CISA KEV catalog. Free to cite with attribution to defend.network.