Vulnerabilities exploited by ransomware groups

Every vulnerability we can tie to a ransomware group we track, ranked by how urgently a defender should care: catalogued exploitation first, then predicted exploitation, then severity. 25 of 28 are in the CISA Known Exploited Vulnerabilities catalog.

CVE Affected Severity EPSS Groups
CVE-2023-0669 KEV Fortra GoAnywhere Managed File Transfer HIGH 7.2 100% Clop
CVE-2022-40684 KEV Fortinet FortiOS CRITICAL 9.8 100% Akira
CVE-2023-34362 KEV Progress Software MOVEit CRITICAL 9.8 99.9% Clop
CVE-2025-61882 KEV Oracle E-Business CRITICAL 9.8 99.7% Clop, Sinobi, Shinyhunters
CVE-2023-3519 KEV Citrix NetScaler ADC & Gateway CRITICAL 9.8 99.7% Ransomhub
CVE-2023-46604 KEV Apache ActiveMQ CRITICAL 10 99.7% Ransomhub
CVE-2021-21972 KEV VMware vSphere Client CRITICAL 9.8 99.5% Akira
CVE-2023-22515 KEV Atlassian Confluence Data Center & Server CRITICAL 9.8 99.2% Ransomhub
CVE-2023-48788 KEV Fortinet FortiClient CRITICAL 9.8 97.6% Akira, Ransomhub
CVE-2023-46747 KEV F5 BIG-IP CRITICAL 9.8 96.5% Ransomhub
CVE-2024-57727 KEV SimpleHelp RMM HIGH 7.5 95.2% Medusa
CVE-2024-53704 KEV SonicWall SSL VPN CRITICAL 9.8 95.1% Sinobi
CVE-2024-55956 KEV Cleo VLTrader, Harmony, LexiCom CRITICAL 9.8 93.8% Clop
CVE-2021-35211 KEV SolarWinds Serv-U FTP CRITICAL 9 91.2% Clop
CVE-2024-40711 KEV Veeam Backup & Replication CRITICAL 9.8 90.4% Akira
CVE-2023-27997 KEV Fortinet FortiOS SSL-VPN & FortiProxy CRITICAL 9.8 85.7% Ransomhub
CVE-2023-27532 KEV Veeam Backup & Replication HIGH 7.5 77.6% Akira
CVE-2020-3259 KEV Cisco ASA & FTD HIGH 7.5 69.3% Akira
CVE-2020-0787 KEV Windows BITS HIGH 7.8 42.5% Ransomhub
CVE-2024-38178 KEV Microsoft Windows Scripting Engine HIGH 7.5 41.4% Tengu
CVE-2023-20269 KEV Cisco ASA & FTD MEDIUM 5 21.6% Akira
CVE-2024-40766 KEV SonicWall SonicOS SSL-VPN CRITICAL 9.8 18.2% Akira, Sinobi
CVE-2019-6693 KEV Fortinet FortiOS MEDIUM 6.5 5.7% Akira
CVE-2026-20045 KEV Cisco Unified Communications HIGH 8.2 4.3% Shinyhunters
CVE-2024-26169 KEV Windows Error Reporting Service HIGH 7.8 4% Blackbasta
CVE-2025-55754 Other Console (ANSI Injection) CRITICAL 9.6 10.1% Tengu
CVE-2025-43995 DSM Data Collector CRITICAL 9.8 0.8% Tengu
CVE-2023-20263 Cisco ASA & FTD MEDIUM 4.7 0.5% Akira

Exploitation is attributed to a group across its recorded activity, not to any individual victim. Severity and description come from NVD, exploitation probability from FIRST EPSS, and catalogue status from CISA. Group attribution comes from ransomware.live.