Known exploited vulnerabilities classified as CWE-88
Entries5
Ransomware-linked0
Vendors5
By vendor
1
1
1
1
1
| CVE | Vendor / product | Added | EPSS | Ransomware |
|---|---|---|---|---|
| CVE-2026-86060 | MikroTik RouterOS | 2026-09-10 | 6.3% | Unknown |
| CVE-2026-24061 | GNU InetUtils | 2026-01-26 | 98.9% | Unknown |
| CVE-2016-10033 | PHP PHPMailer | 2025-07-07 | 99.7% | Unknown |
| CVE-2024-41710 | Mitel SIP Phones | 2025-02-12 | 41.6% | Unknown |
| CVE-2022-36804 | Atlassian Bitbucket Server and Data Center | 2022-09-30 | 99.1% | Unknown |
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
5 KEV entries are classified as CWE-88. CWE definition (MITRE)