Vulnerabilities exploited by ransomware groups

Every vulnerability we can tie to a ransomware group we track, ranked by how urgently a defender should care: catalogued exploitation first, then predicted exploitation, then severity. 71 of 77 are in the CISA Known Exploited Vulnerabilities catalog.

CVE Affected Severity EPSS Groups
CVE-2021-44228 KEV Apache Log4j CRITICAL 10 100% Dragonforce
CVE-2023-27350 KEV PaperCut Application Server CRITICAL 9.8 100% Clop
CVE-2024-21887 KEV Ivanti ICS CRITICAL 9.1 100% Dragonforce
CVE-2024-21893 KEV Pulse Secure / Ivanti Ivanti Connect Secure HIGH 8.2 100% Dragonforce
CVE-2025-49704 KEV MS Server Products SharePoint Server HIGH 8.8 100% Warlock
CVE-2023-46805 KEV Pulse Secure / Ivanti Ivanti Connect Secure HIGH 8.2 100% Dragonforce
CVE-2022-40684 KEV Fortinet FortiOS CRITICAL 9.8 100% Akira
CVE-2024-1709 KEV ConnectWise ScreenConnect CRITICAL 10 100% Blackbasta
CVE-2023-34362 KEV Progress Software MOVEit CRITICAL 9.8 99.9% Clop
CVE-2023-46604 KEV Apache ActiveMQ CRITICAL 10 99.9% Ransomhub
CVE-2021-21972 KEV VMware vSphere Client CRITICAL 9.8 99.9% Akira
CVE-2025-55182 KEV Meta react-server-dom-webpack CRITICAL 10 99.8% Thegentlemen
CVE-2021-34527 KEV Windows Print Spooler HIGH 8.8 99.8% Blackbasta
CVE-2023-3519 KEV Citrix NetScaler ADC & Gateway CRITICAL 9.8 99.7% Ransomhub
CVE-2025-61882 KEV Oracle Corporation Oracle Concurrent Processing CRITICAL 9.8 99.7% Clop, Sinobi, Shinyhunters
CVE-2024-21412 KEV Windows SmartScreen HIGH 8.1 99.4% Thegentlemen, Dragonforce
CVE-2020-1472 KEV Windows NetLogon MEDIUM 5.5 99.4% Ransomhub, Thegentlemen, Blackbasta
CVE-2022-30190 KEV Windows MSDT HIGH 7.8 99.2% Blackbasta
CVE-2017-0144 KEV Windows SMBv1 HIGH 8.8 99.2% Ransomhub, Thegentlemen
CVE-2023-22515 KEV Atlassian Confluence Data Center & Server CRITICAL 9.8 99.2% Ransomhub
CVE-2025-49706 KEV MS Server Products SharePoint Server MEDIUM 6.5 99.1% Warlock
CVE-2026-24061 KEV Telnet Telnetd in GNU Inetutils CRITICAL 9.8 99% Qilin
CVE-2025-32433 KEV erlang otp CRITICAL 10 98.8% Thegentlemen
CVE-2023-48788 KEV Fortinet FortiClient CRITICAL 9.8 98.4% Akira, Ransomhub
CVE-2024-57727 KEV SimpleHelp RMM HIGH 7.5 96.6% Dragonforce, Medusa
CVE-2026-23760 KEV SmarterTools SmarterMail CRITICAL 9.8 96.5% Warlock
CVE-2023-46747 KEV F5 BIG-IP CRITICAL 9.8 96.5% Ransomhub
CVE-2026-0257 KEV Palo Alto Networks Cloud NGFW CRITICAL 9.1 96.4% Qilin
CVE-2024-1708 KEV ConnectWise ScreenConnect HIGH 8.4 95.4% Rhysida, Spacebears, Direwolf, +2
CVE-2024-53704 KEV SonicWall SSL VPN CRITICAL 9.8 95.1% Sinobi
CVE-2024-55591 KEV Fortinet FortiOS & FortiProxy CRITICAL 9.8 94.1% Qilin, Thegentlemen, Dragonforce
CVE-2024-55956 KEV Cleo VLTrader, Harmony, LexiCom CRITICAL 9.8 94% Clop
CVE-2025-11371 KEV CentreStack Gladinet CentreStack HIGH 7.5 92.1% Clop
CVE-2025-9242 KEV WatchGuard Fireware OS CRITICAL 9.8 91.3% Qilin
CVE-2021-35211 KEV SolarWinds Serv-U FTP CRITICAL 9 91.2% Clop
CVE-2024-40711 KEV Veeam Backup & Replication CRITICAL 9.8 90.4% Akira
CVE-2026-24423 KEV SmarterTools SmarterMail CRITICAL 9.8 88.2% Qilin
CVE-2023-27997 KEV Fortinet FortiOS SSL-VPN & FortiProxy CRITICAL 9.8 85.7% Ransomhub
CVE-2021-1675 KEV Windows Print Spooler HIGH 7.8 85.3% Blackbasta
CVE-2025-40551 KEV SolarWinds Web Help Desk CRITICAL 9.8 84.2% Warlock
CVE-2024-21762 KEV Fortinet FortiOS & FortiProxy CRITICAL 9.8 83.4% Qilin, Dragonforce
CVE-2025-33073 KEV Microsoft Windows 10 Version 1507 HIGH 8.8 82.7% Thegentlemen
CVE-2023-27532 KEV Veeam Backup & Replication HIGH 7.5 81.3% Qilin, Akira
CVE-2023-27351 KEV PaperCut Application Server HIGH 7.5 78.1% Clop
CVE-2021-42287 KEV Windows Active Directory HIGH 7.5 77.2% Blackbasta
CVE-2021-42278 KEV Microsoft Windows Server 2019 HIGH 7.5 73.3% Blackbasta
CVE-2020-3259 KEV Cisco ASA & FTD HIGH 7.5 71.8% Akira
CVE-2025-59718 KEV Fortinet FortiOS CRITICAL 9.8 68.3% Qilin
CVE-2021-36942 KEV Windows Local Security Authority (LSA) HIGH 7.5 66% Thegentlemen
CVE-2024-57728 KEV SimpleHelp RMM HIGH 7.2 64.7% Dragonforce
CVE-2023-21529 KEV Microsoft Exchange Server HIGH 8.8 59.3% Rhysida, Spacebears, Direwolf, +2
CVE-2021-27104 KEV Accellion File Transfer Appliance CRITICAL 9.8 56.7% Clop
CVE-2025-14611 KEV CentreStack Gladinet CentreStack CRITICAL 9.8 53.3% Warlock
CVE-2026-20131 KEV Cisco Secure Firewall Management Center (FMC) CRITICAL 10 42.7% Panzer
CVE-2020-0787 KEV Windows BITS HIGH 7.8 42.5% Ransomhub
CVE-2024-38178 KEV Microsoft Windows Scripting Engine HIGH 7.5 41.4% Tengu
CVE-2024-37085 KEV VMware ESXi MEDIUM 6.8 26.8% Akira, Blackbasta
CVE-2025-14733 KEV WatchGuard Fireware OS CRITICAL 9.8 26.5% Qilin
CVE-2023-20269 KEV Cisco ASA & FTD MEDIUM 5 25.5% Akira
CVE-2024-40766 KEV SonicWall SonicOS SSL-VPN CRITICAL 9.8 18.4% Akira, Dragonforce, Sinobi
CVE-2026-15410 KEV SonicWall SMA1000 HIGH 7.2 11.8% Incransom
CVE-2021-27103 KEV Accellion File Transfer Appliance CRITICAL 9.8 11.4% Clop
CVE-2026-15409 KEV SonicWall SMA1000 CRITICAL 10 6.8% Incransom
CVE-2026-50751 KEV Check Point VPN Remote Access and Mobile Access CRITICAL 9.3 6.3% Qilin, Rhysida, Spacebears, +3
CVE-2021-27101 KEV Accellion File Transfer Appliance CRITICAL 9.8 6% Clop
CVE-2019-6693 KEV Fortinet FortiOS MEDIUM 6.5 5.8% Akira
CVE-2025-60710 KEV Microsoft Windows HIGH 7.8 4.6% Rhysida, Spacebears, Direwolf, +1
CVE-2026-20045 KEV Cisco Unified Communications HIGH 8.2 4.5% Shinyhunters
CVE-2024-26169 KEV Windows Error Reporting Service HIGH 7.8 4% Blackbasta
CVE-2021-27102 KEV Accellion File Transfer Appliance HIGH 7.8 3.7% Clop
CVE-2026-48027 KEV Nx Console CRITICAL 9.8 1.3% Rhysida, Spacebears, Direwolf, +1
CVE-2025-40554 SolarWinds Web Help Desk CRITICAL 9.8 60.6% Qilin
CVE-2025-60021 Apache bRPC CRITICAL 9.8 25.7% Qilin
CVE-2025-55754 Apache Software Foundation Apache Tomcat CRITICAL 9.6 10.1% Tengu
CVE-2025-43995 DSM Data Collector CRITICAL 9.8 0.8% Tengu
CVE-2026-4681 PTC Windchill PDMLink CRITICAL 9.3 0.8% Clop
CVE-2023-20263 Cisco ASA & FTD MEDIUM 4.7 0.6% Akira

Exploitation is attributed to a group across its recorded activity, not to any individual victim. Severity and description come from NVD, exploitation probability from FIRST EPSS, and catalogue status from CISA. Group attribution comes from ransomware.live.