How we count
Every figure on this page is a direct count of entries in CISA’s Known Exploited Vulnerabilities catalog attributed by CISA to Samsung (KEV field vendorProject), refreshed daily. “Ransomware-linked” counts entries CISA marks as known to be used in ransomware campaigns; the remainder are “unknown” to CISA, not confirmed ransomware-free. A KEV listing means the vulnerability has been observed exploited in the wild. Snapshot as of 2026-08-31.
Exploited Samsung vulnerabilities (CISA KEV)
| CVE | Product | Vulnerability | Added | |
|---|---|---|---|---|
| CVE-2024-7399 | MagicINFO 9 Server | Samsung MagicINFO 9 Server Path Traversal Vulnerability | 2026-04-24 | |
| CVE-2025-21042 | Mobile Devices | Samsung Mobile Devices Out-of-Bounds Write Vulnerability | 2025-11-10 | |
| CVE-2025-21043 | Mobile Devices | Samsung Mobile Devices Out-of-Bounds Write Vulnerability | 2025-10-02 | |
| CVE-2025-4632 | MagicINFO 9 Server | Samsung MagicINFO 9 Server Path Traversal Vulnerability | 2025-05-22 | |
| CVE-2022-22265 | Mobile Devices | Samsung Mobile Devices Use-After-Free Vulnerability | 2023-09-18 | |
| CVE-2021-25487 | Mobile Devices | Samsung Mobile Devices Out-of-Bounds Read Vulnerability | 2023-06-29 | |
| CVE-2021-25489 | Mobile Devices | Samsung Mobile Devices Improper Input Validation Vulnerability | 2023-06-29 | |
| CVE-2021-25394 | Mobile Devices | Samsung Mobile Devices Race Condition Vulnerability | 2023-06-29 | |
| CVE-2021-25395 | Mobile Devices | Samsung Mobile Devices Race Condition Vulnerability | 2023-06-29 | |
| CVE-2021-25371 | Mobile Devices | Samsung Mobile Devices Unspecified Vulnerability | 2023-06-29 | |
| CVE-2021-25372 | Mobile Devices | Samsung Mobile Devices Improper Boundary Check Vulnerability | 2023-06-29 | |
| CVE-2023-21492 | Mobile Devices | Samsung Mobile Devices Insertion of Sensitive Information Into Log File Vulnerability | 2023-05-19 | |
| CVE-2021-25337 | Mobile Devices | Samsung Mobile Devices Improper Access Control Vulnerability | 2022-11-08 | |
| CVE-2021-25369 | Mobile Devices | Samsung Mobile Devices Improper Access Control Vulnerability | 2022-11-08 | |
| CVE-2021-25370 | Mobile Devices | Samsung Mobile Devices Memory Corruption Vulnerability | 2022-11-08 |
← All vendors by exploited-vulnerability count
🤖 Generated by defend.network from the CISA KEV catalog. Counts are deterministic aggregates of official CISA data; verify individual advisories at the linked sources.