Vulnerabilities exploited by ransomware groups
Every vulnerability we can tie to a ransomware group we track, ranked by how urgently a defender should care: catalogued exploitation first, then predicted exploitation, then severity. 25 of 28 are in the CISA Known Exploited Vulnerabilities catalog.
| CVE | Affected | Severity | EPSS | Groups |
|---|---|---|---|---|
| CVE-2023-0669 KEV | Fortra GoAnywhere Managed File Transfer | HIGH 7.2 | 100% | Clop |
| CVE-2022-40684 KEV | Fortinet FortiOS | CRITICAL 9.8 | 100% | Akira |
| CVE-2023-34362 KEV | Progress Software MOVEit | CRITICAL 9.8 | 99.9% | Clop |
| CVE-2025-61882 KEV | Oracle E-Business | CRITICAL 9.8 | 99.7% | Clop, Sinobi, Shinyhunters |
| CVE-2023-3519 KEV | Citrix NetScaler ADC & Gateway | CRITICAL 9.8 | 99.7% | Ransomhub |
| CVE-2023-46604 KEV | Apache ActiveMQ | CRITICAL 10 | 99.7% | Ransomhub |
| CVE-2021-21972 KEV | VMware vSphere Client | CRITICAL 9.8 | 99.5% | Akira |
| CVE-2023-22515 KEV | Atlassian Confluence Data Center & Server | CRITICAL 9.8 | 99.2% | Ransomhub |
| CVE-2023-48788 KEV | Fortinet FortiClient | CRITICAL 9.8 | 97.6% | Akira, Ransomhub |
| CVE-2023-46747 KEV | F5 BIG-IP | CRITICAL 9.8 | 96.5% | Ransomhub |
| CVE-2024-57727 KEV | SimpleHelp RMM | HIGH 7.5 | 95.2% | Medusa |
| CVE-2024-53704 KEV | SonicWall SSL VPN | CRITICAL 9.8 | 95.1% | Sinobi |
| CVE-2024-55956 KEV | Cleo VLTrader, Harmony, LexiCom | CRITICAL 9.8 | 93.8% | Clop |
| CVE-2021-35211 KEV | SolarWinds Serv-U FTP | CRITICAL 9 | 91.2% | Clop |
| CVE-2024-40711 KEV | Veeam Backup & Replication | CRITICAL 9.8 | 90.4% | Akira |
| CVE-2023-27997 KEV | Fortinet FortiOS SSL-VPN & FortiProxy | CRITICAL 9.8 | 85.7% | Ransomhub |
| CVE-2023-27532 KEV | Veeam Backup & Replication | HIGH 7.5 | 77.6% | Akira |
| CVE-2020-3259 KEV | Cisco ASA & FTD | HIGH 7.5 | 69.3% | Akira |
| CVE-2020-0787 KEV | Windows BITS | HIGH 7.8 | 42.5% | Ransomhub |
| CVE-2024-38178 KEV | Microsoft Windows Scripting Engine | HIGH 7.5 | 41.4% | Tengu |
| CVE-2023-20269 KEV | Cisco ASA & FTD | MEDIUM 5 | 21.6% | Akira |
| CVE-2024-40766 KEV | SonicWall SonicOS SSL-VPN | CRITICAL 9.8 | 18.2% | Akira, Sinobi |
| CVE-2019-6693 KEV | Fortinet FortiOS | MEDIUM 6.5 | 5.7% | Akira |
| CVE-2026-20045 KEV | Cisco Unified Communications | HIGH 8.2 | 4.3% | Shinyhunters |
| CVE-2024-26169 KEV | Windows Error Reporting Service | HIGH 7.8 | 4% | Blackbasta |
| CVE-2025-55754 | Other Console (ANSI Injection) | CRITICAL 9.6 | 10.1% | Tengu |
| CVE-2025-43995 | DSM Data Collector | CRITICAL 9.8 | 0.8% | Tengu |
| CVE-2023-20263 | Cisco ASA & FTD | MEDIUM 4.7 | 0.5% | Akira |
Exploitation is attributed to a group across its recorded activity, not to any individual victim. Severity and description come from NVD, exploitation probability from FIRST EPSS, and catalogue status from CISA. Group attribution comes from ransomware.live.