Most Exploited Internet-Facing Products

MEIFP

Ranks internet-facing vendors & products by active exploitation risk. Data sourced from CISA Vulnrichment (cisagov/vulnrichment) · AV:Network CVEs with SSVC Exploitation: Active

Vendor score = sum of Active CVE scores  ·  Each CVE: 10 pts base, boosted by:
KEV×2.0AC: Low×1.2PR: None×1.3PR: Low×1.1Auto×1.3

Vendor Risk Ranking

Ranked by cumulative score from Active CVEs in the selected period · AV:Network only · Click vendor name for CVE details

114 vendors
#VendorScore(hover for detail)Active CVEsProducts
1Ivanti
843.4
2413
2Cisco
720.3
2120
3Microsoft
544.8
1520
4Fortinet
527.4
1418
5Palo Alto Networks
406.1
114
6Adobe
317.7
84
7Apache Software Foundation
294.7
816
8Oracle
269.8
78
9SolarWinds
269.4
72
10Citrix
245.4
73
11Apple
202.8
58
12Juniper Networks
202.8
52
13SonicWall
165.7
55
14Progress Software Corporation
152.9
43
15Atlassian
121.7
32
16JetBrains
121.7
31
17SmarterTools
121.7
31
18Ubiquiti Inc
121.7
320
19D-Link
112.3
320
20F5
107.5
31
21CrushFTP
107.1
31
22Kentico
105.1
31
23BeyondTrust
101.1
34
24Zyxel
93.4
39
25BerriAI
93.4
31
26Gladinet
92.6
33
27Dassault Systèmes
86.6
31
28craftcms
81.1
22
29geoserver
81.1
21
30GeoVision
81.1
220
31checkpoint
81.1
23
32ServiceNow
81.1
21
33WatchGuard
81.1
21
34SysAid
81.1
21
35langflow-ai
81.1
21
36Roundcube
67.0
22
37ASUS
67.0
22
38Advantive
67.0
21
39Samsung Electronics
67.0
21
40wftpserver
67.0
21
41Commvault
67.0
22
42ConnectWise
66.6
21
43Trend Micro, Inc.
64.6
23
44SAP_SE
64.6
23
45FreePBX
64.6
25
46PTZOptics
64.6
22
47LiteSpeed Technologies
62.6
23
48Versa
60.6
22
49VMware
57.2
26
50N-able
52.8
21
51GitLab
40.6
11
52Arista Networks
40.6
16
53Unitronics
40.6
12
54Mozilla
40.6
15
55xwiki
40.6
13
56Acronis
40.6
11
57North Grid Corporation
40.6
13
58Splunk
40.6
14
59GNU
40.6
15
60tj-actions
40.6
12
61projectSend
40.6
11
62Meta
40.6
14
63Cloud Software Group
40.6
11
64PHP Group
40.6
11
65DrayTek
40.6
13
66Progress Software
40.6
12
67Rejetto
40.6
11
68Jenkins Project
40.6
11
69Fortra
40.6
13
70Veeam
40.6
12
71NAKIVO
40.6
11
72Aviatrix
40.6
11
73Hewlett Packard Enterprise (HPE)
40.6
13
74erlang
40.6
11
75AMI
40.6
11
76ScienceLogic
40.6
11
77TrioFox
40.6
11
78Edimax
40.6
112
79MongoDB Inc.
40.6
11
80Srimax
40.6
11
81reviewdog
40.6
11
82Craft
40.6
11
83Dell
40.6
12
84QUALITIA CO., LTD.
40.6
11
85TeleMessage
40.6
11
86MOTEX Inc.
40.6
11
87Drupal
40.6
14
88PTC
40.6
12
89marimo-team
40.6
11
90WebPros
40.6
13
91Mirasvit
40.6
11
92nrwl
40.6
11
93joomlacontenteditor.net
40.6
11
94AVB Disc Soft
40.6
11
95Zimbra
31.2
12
96wazuh
26.4
17
97FXC Inc.
26.4
12
98gogs
26.4
11
99Facebook
26.4
13
100n8n-io
26.4
11
101Soliton Systems K.K.
26.4
11
102aquasecurity
26.4
13
103team-telnyx
26.4
11
104Google
26.0
18
105livewire
26.0
11
106yiiframework
26.0
11
107FreeType
26.0
11
108Sitecore
26.0
16
109centos-webpanel
26.0
11
110prettier
26.0
11
111TeamT5
24.0
11
112Trimble
24.0
13
113Array Networks
24.0
11
114TP-Link Systems Inc.
24.0
16

Recently Active CVEs

Newest 100 CVEs with confirmed active exploitation, sorted by published date  · NEW = directly Active  · POC→ACT = was POC in Vulnrichment SSVC, now confirmed Active

100 entries
StatusCVE IDVendorProductScore
NEWCVE-2026-12569PTCFlexPLM
40.6
NEWCVE-2026-20262CiscoCisco Catalyst SD-WAN Manager
26.4
NEWCVE-2026-54420LiteSpeed TechnologiescPanel Plugin
22.0
NEWCVE-2026-35273OraclePeopleSoft Enterprise PeopleTools
40.6
NEWCVE-2026-20253SplunkSplunk Enterprise
40.6
NEWCVE-2026-10520IvantiSentry
40.6
NEWCVE-2026-11645GoogleChrome
31.2
NEWCVE-2026-50751checkpointQuantum Security Gateway
40.6
NEWCVE-2026-7473Arista NetworksEOS
40.6
NEWCVE-2026-48907joomlacontenteditor.netJoomla Content Editor (JCE) extension for Joomla
40.6
NEWCVE-2026-28318SolarWindsServ-U
40.6
NEWCVE-2026-20230CiscoCisco Unified Communications Manager
31.2
NEWCVE-2026-48027nrwlnx-console
40.6
NEWCVE-2026-45247MirasvitFull Page Cache Warmer for Magento 2
40.6
NEWCVE-2026-34908Ubiquiti IncEFG
40.6
NEWCVE-2026-34909Ubiquiti IncEFG
40.6
NEWCVE-2026-34910Ubiquiti IncEFG
40.6
NEWCVE-2026-48172LiteSpeed TechnologiescPanel Plugin
40.6
NEWCVE-2026-9082DrupalDrupal core
40.6
NEWCVE-2026-8398AVB Disc SoftDAEMON Tools Lite
40.6
NEWCVE-2026-42897MicrosoftMicrosoft Exchange Server 2016 Cumulative Update 23
31.2
NEWCVE-2026-20182CiscoCisco Catalyst SD-WAN Controller
40.6
NEWCVE-2026-0257Palo Alto NetworksCloud NGFW
31.2
NEWCVE-2026-45321@tanstackarktype-adapter
31.2
NEWCVE-2026-42208BerriAIlitellm
40.6
NEWCVE-2026-42271BerriAIlitellm
26.4
NEWCVE-2026-6973IvantiEndpoint Manager Mobile
24.0
NEWCVE-2026-0300Palo Alto NetworksCloud NGFW
40.6
NEWCVE-2026-41940WebProscPanel
40.6
NEWCVE-2026-32201MicrosoftMicrosoft SharePoint Enterprise Server 2016
40.6
NEWCVE-2026-32202MicrosoftWindows 10 Version 1607
31.2
NEWCVE-2026-39987marimo-teammarimo
40.6
NEWCVE-2026-34197Apache Software FoundationApache ActiveMQ
26.4
NEWCVE-2026-35616FortinetFortiClientEMS
40.6
NEWCVE-2026-5281GoogleChrome
31.2
NEWCVE-2026-3055CitrixNetScaler ADC
40.6
NEWCVE-2026-33634BerriAIlitellm
26.4
NEWCVE-2026-33017langflow-ailangflow
40.6
NEWCVE-2026-3909GoogleChrome
31.2
NEWCVE-2026-3910GoogleChrome
31.2
NEWCVE-2026-20131CiscoCisco Secure Firewall Management Center (FMC)
40.6
NEWCVE-2026-20122CiscoCisco Catalyst SD-WAN Manager
26.4
NEWCVE-2026-20127CiscoCisco Catalyst SD-WAN Manager
40.6
NEWCVE-2026-20133CiscoCisco Catalyst SD-WAN Manager
26.4
NEWCVE-2026-22719VMwareTelco Cloud Infrastructure
26.0
NEWCVE-2026-22769DellRecoverPoint for Virtual Machines
40.6
NEWCVE-2026-2441GoogleChrome
31.2
NEWCVE-2026-25108Soliton Systems K.K.FileZen
26.4
NEWCVE-2026-21510MicrosoftWindows 10 Version 1607
31.2
NEWCVE-2026-21513MicrosoftWindows 10 Version 1607
31.2
NEWCVE-2026-1603IvantiEndpoint Manager
40.6
NEWCVE-2026-21643FortinetFortiClientEMS
40.6
NEWCVE-2026-1731BeyondTrustRemote Support(RS) & Privileged Remote Access(PRA)
40.6
NEWCVE-2025-15556notepad-plus-plusnotepad-plus-plus
26.0
NEWCVE-2026-1281IvantiEndpoint Manager Mobile
40.6
NEWCVE-2026-1340IvantiEndpoint Manager Mobile
40.6
NEWCVE-2025-40536SolarWindsWeb Help Desk
26.0
NEWCVE-2025-40551SolarWindsWeb Help Desk
40.6
NEWCVE-2026-24858FortinetFortiAnalyzer
40.6
NEWCVE-2026-24423SmarterToolsSmarterMail
40.6
NEWCVE-2026-23760SmarterToolsSmarterMail
40.6
NEWCVE-2026-20045CiscoCisco Unified Communications Manager
40.6
NEWCVE-2026-24061GNUinetutils
40.6
NEWCVE-2026-20963MicrosoftMicrosoft SharePoint Enterprise Server 2016
40.6
NEWCVE-2025-66376ZimbraCollaboration
31.2
NEWCVE-2025-52691SmarterToolsSmarterMail
40.6
NEWCVE-2025-14733WatchGuardFireware OS
40.6
NEWCVE-2025-14847MongoDB Inc.MongoDB Server
40.6
NEWCVE-2025-68613n8n-ion8n
26.4
NEWCVE-2025-40602SonicWallSMA1000
20.0
NEWCVE-2025-68461RoundcubeWebmail
40.6
NEWCVE-2025-20393CiscoCisco Secure Email
40.6
NEWCVE-2025-43529AppleiOS and iPadOS
31.2
NEWCVE-2025-59374ASUSlive update
40.6
NEWCVE-2025-37164Hewlett Packard Enterprise (HPE)HPE OneView
40.6
NEWCVE-2025-14174GoogleChrome
31.2
NEWCVE-2025-14611GladinetCentreStack and TrioFox
26.0
NEWCVE-2025-8110gogsgogs
26.4
NEWCVE-2025-59718FortinetFortiOS
40.6
NEWCVE-2025-34291LangflowLangflow
31.2
NEWCVE-2025-66644Array NetworksArrayOS AG
24.0
NEWCVE-2025-55182Metareact-server-dom-parcel
40.6
NEWCVE-2025-58360geoservergeoserver
40.6
NEWCVE-2025-58034FortinetFortiWeb
24.0
NEWCVE-2025-13223GoogleChrome
31.2
NEWCVE-2025-64446FortinetFortiWeb
40.6
NEWCVE-2025-12480TrioFoxTrioFox
40.6
NEWCVE-2025-64328FreePBXfilestore
24.0
NEWCVE-2023-43000AppleiOS and iPadOS
31.2
NEWCVE-2025-61757OracleIdentity Manager
40.6
NEWCVE-2025-61932MOTEX Inc.Lanscope Endpoint Manager (On-Premises) (Client program (MR) and Detection agent (DA))
40.6
NEWCVE-2025-53521F5BIG-IP
40.6
NEWCVE-2025-59287MicrosoftWindows Server 2012
40.6
NEWCVE-2025-61884OracleOracle Configurator
40.6
NEWCVE-2025-11371GladinetCentreStack and TrioFox
40.6
NEWCVE-2025-61882OracleOracle Concurrent Processing
40.6
NEWCVE-2025-20333CiscoCisco Secure Firewall Adaptive Security Appliance (ASA) Software
26.4
NEWCVE-2025-20362CiscoCisco Secure Firewall Adaptive Security Appliance (ASA) Software
40.6
NEWCVE-2025-10585GoogleChrome
31.2
NEWCVE-2025-20352CiscoCisco IOS XE Catalyst SD-WAN
26.4

Monthly Risk Score TrendJun 2023Jun 2026

Rolling 36-month cumulative score — CVEs older than 3 years expire · hover for breakdown

0211422633843Jun '23Sep '23Dec '23Mar '24Jun '24Sep '24Dec '24Mar '25Jun '25Sep '25Dec '25Mar '26Jun '26
Ivanti
Cisco
Microsoft
Fortinet
Palo Alto Networks
Adobe
Apache Software Foundation
Oracle
SolarWinds
Citrix
Apple
Juniper Networks
SonicWall
Progress Software Corporation
Atlassian