Vendor Exploitation Record

Samsung — Known Exploited Vulnerabilities

15 in CISA KEV · 0 ransomware-linked · as of 2026-08-31
In CISA KEV15 confirmed exploited
Ransomware-linked0 (0% of KEV, per CISA)
First KEV addition2022-11-08
Most recent2026-04-24

How we count

Every figure on this page is a direct count of entries in CISA’s Known Exploited Vulnerabilities catalog attributed by CISA to Samsung (KEV field vendorProject), refreshed daily. “Ransomware-linked” counts entries CISA marks as known to be used in ransomware campaigns; the remainder are “unknown” to CISA, not confirmed ransomware-free. A KEV listing means the vulnerability has been observed exploited in the wild. Snapshot as of 2026-08-31.

Exploited Samsung vulnerabilities (CISA KEV)

CVEProductVulnerabilityAdded
CVE-2024-7399MagicINFO 9 ServerSamsung MagicINFO 9 Server Path Traversal Vulnerability2026-04-24
CVE-2025-21042Mobile DevicesSamsung Mobile Devices Out-of-Bounds Write Vulnerability2025-11-10
CVE-2025-21043Mobile DevicesSamsung Mobile Devices Out-of-Bounds Write Vulnerability2025-10-02
CVE-2025-4632MagicINFO 9 ServerSamsung MagicINFO 9 Server Path Traversal Vulnerability2025-05-22
CVE-2022-22265Mobile DevicesSamsung Mobile Devices Use-After-Free Vulnerability2023-09-18
CVE-2021-25487Mobile DevicesSamsung Mobile Devices Out-of-Bounds Read Vulnerability2023-06-29
CVE-2021-25489Mobile DevicesSamsung Mobile Devices Improper Input Validation Vulnerability2023-06-29
CVE-2021-25394Mobile DevicesSamsung Mobile Devices Race Condition Vulnerability2023-06-29
CVE-2021-25395Mobile DevicesSamsung Mobile Devices Race Condition Vulnerability2023-06-29
CVE-2021-25371Mobile DevicesSamsung Mobile Devices Unspecified Vulnerability2023-06-29
CVE-2021-25372Mobile DevicesSamsung Mobile Devices Improper Boundary Check Vulnerability2023-06-29
CVE-2023-21492Mobile DevicesSamsung Mobile Devices Insertion of Sensitive Information Into Log File Vulnerability2023-05-19
CVE-2021-25337Mobile DevicesSamsung Mobile Devices Improper Access Control Vulnerability2022-11-08
CVE-2021-25369Mobile DevicesSamsung Mobile Devices Improper Access Control Vulnerability2022-11-08
CVE-2021-25370Mobile DevicesSamsung Mobile Devices Memory Corruption Vulnerability2022-11-08

← All vendors by exploited-vulnerability count

🤖 Generated by defend.network from the CISA KEV catalog. Counts are deterministic aggregates of official CISA data; verify individual advisories at the linked sources.

Track newly exploited vulnerabilities

Free daily briefing on CVEs added to CISA KEV and exploited in the wild.