Remediation
Action plan
Prioritised from live KEV, EPSS, public-exploit and CVSS signals across your products.
1
Patch now — known exploited8
On the CISA KEV catalog. Actively exploited and, for federal systems, bound by a remediation deadline.
| CVE | Severity | EPSS | KEV due | Products |
|---|---|---|---|---|
| CVE-2018-0171 | Critical · 9.8 | 100% | 2022-05-03 | |
| CVE-2023-20198 | Critical · 10.0 | 100% | 2023-10-20 | |
| CVE-2023-20273 | High · 7.2 | 90% | 2023-10-27 | |
| CVE-2023-20109 | Medium · 6.6 | 2% | 2023-10-31 | |
| CVE-2024-39717 | High · 7.2 | 4% | 2024-09-13 | |
| CVE-2025-21590 | Medium · 4.4 | 2% | 2025-04-03 | |
| CVE-2025-20352 | High · 7.7 | 38% | 2025-10-20 | |
| CVE-2025-34026 | High · 7.5 | 83% | 2026-02-12 |
2
High exploitation risk2
A public exploit exists or EPSS puts near-term exploitation above 10%. Prioritise after KEV.
| CVE | Severity | EPSS | KEV due | Products |
|---|---|---|---|---|
| CVE-2025-34027 | Critical · 10.0 | 37% | — | |
| CVE-2025-20188 | Critical · 10.0 | 18% | — |
3
Critical severity1
CVSS 9.0+ with no exploit signal yet — schedule promptly.
| CVE | Severity | EPSS | KEV due | Products |
|---|---|---|---|---|
| CVE-2024-42450 | Critical · 10.0 | <1% | — |
4
High severity14
CVSS 7.0–8.9. Fold into the regular patch cycle.
| CVE | Severity | EPSS | KEV due | Products |
|---|---|---|---|---|
| CVE-2018-16495 | High · 8.8 | <1% | — | |
| CVE-2025-20154 | High · 8.6 | <1% | — | |
| CVE-2025-34025 | High · 8.6 | <1% | — | |
| CVE-2023-20035 | High · 7.8 | <1% | — | |
| CVE-2021-1529 | High · 7.8 | <1% | — | |
| CVE-2018-16497 | High · 7.8 | <1% | — | |
| CVE-2024-47497 | High · 7.5 | <1% | — | |
| CVE-2024-39549 | High · 7.5 | <1% | — | |
| CVE-2024-39516 | High · 7.5 | <1% | — | |
| CVE-2023-44191 | High · 7.5 | <1% | — | |
| CVE-2025-20311 | High · 7.4 | <1% | — | |
| CVE-2025-21591 | High · 7.4 | <1% | — | |
| CVE-2025-23171 | High · 7.2 | <1% | — | |
| CVE-2025-23172 | High · 7.2 | <1% | — |