Threats and Vulnerabilities
The Vulnerabilities Ransomware Crews Are Actually Exploiting
The CISA Known Exploited Vulnerabilities Catalog offers a clear list of ransomware vulnerabilities that have been actively used in attacks. As of August 14, 2026, this document tracks 1,665 vulnerabilities, with 349 identified in known ransomware campaigns. Reviewing this catalog helps you direct your efforts toward the threats that attackers are actually using.
Which ransomware vulnerabilities are attackers using right now?
Ransomware groups do not bother with obscure or theoretical flaws. They use vulnerabilities that are widely deployed and often slow to patch. According to the CISA catalog, the following vulnerabilities have been added in 2026 and are confirmed as being used in ransomware campaigns:
- CVE-2026-15409 and CVE-2026-15410 (SonicWall SMA1000 Appliances)
Added July 14, 2026. The first is a server-side request forgery vulnerability, the second is a code injection vulnerability. Both are actively targeted in ransomware attacks.
- CVE-2026-45659 (Microsoft SharePoint Server)
Added July 1, 2026. This deserialization of untrusted data vulnerability in SharePoint Server is known to be exploited by ransomware actors.
- CVE-2026-12569 (PTC Windchill and FlexPLM)
Added June 25, 2026. An improper input validation vulnerability affecting these PTC products.
- CVE-2026-35273 (Oracle PeopleSoft Enterprise PeopleTools)
Added June 12, 2026. This is a missing authentication for critical function vulnerability.
- CVE-2026-50751 (Check Point Security Gateway)
Added June 8, 2026. Ransomware groups are exploiting this improper authentication vulnerability.
- CVE-2026-0257 (Palo Alto Networks PAN-OS)
Added May 29, 2026. An authentication bypass vulnerability in PAN-OS.
- CVE-2026-48027 (Nx Nx Console)
Added May 27, 2026. This vulnerability concerns embedded malicious code.
- CVE-2026-45321 (TanStack TanStack)
Added May 27, 2026. An unspecified vulnerability in TanStack, but flagged for ransomware campaign use.
- CVE-2026-41940 (WebPros cPanel & WHM and WP2)
Added April 30, 2026. Missing authentication for critical function vulnerability.
- CVE-2024-1708 (ConnectWise ScreenConnect)
Added April 28, 2026. A path traversal vulnerability.
- CVE-2024-57728 and CVE-2024-57726 (SimpleHelp SimpleHelp)
Added April 24, 2026. One is a path traversal vulnerability, the other is missing authorization.
- CVE-2026-33825 (Microsoft Defender)
Added April 22, 2026. Insufficient granularity of access control vulnerability.
- CVE-2023-27351 (PaperCut NG/MF)
Added April 20, 2026. An improper authentication vulnerability.
- CVE-2024-27199 (JetBrains TeamCity)
Added April 20, 2026. Relative path traversal vulnerability.
- CVE-2025-60710 (Microsoft Windows)
Added April 13, 2026. Link following vulnerability.
- CVE-2023-21529 (Microsoft Exchange Server)
Added April 13, 2026. Deserialization of untrusted data vulnerability.
- CVE-2026-20131 (Cisco Secure Firewall Management Center (FMC))
Added March 19, 2026. Deserialization of untrusted data vulnerability.
- CVE-2025-26399 (SolarWinds Web Help Desk)
Added March 9, 2026. Deserialization of untrusted data vulnerability.
These entries are not theoretical or speculative. Each is flagged by CISA as being used in ransomware campaigns.
How does CISA decide which vulnerabilities to flag for ransomware campaign use?
CISA flags vulnerabilities in its Known Exploited Vulnerabilities Catalog when there is evidence that they are being used in active ransomware campaigns. As of August 2026, the catalog contains 349 entries with this tag. This is based on observed exploitation in the wild and reporting from trusted partners. If a vulnerability is in this subset, it means attackers are using it to gain initial access or escalate privileges, often leading directly to ransomware deployment.
Should I worry about vulnerabilities not flagged for ransomware use?
You should prioritize patching vulnerabilities flagged for ransomware campaign use, especially if they affect systems you run. Other vulnerabilities may still be serious, but CISA does not list them as being used in ransomware campaigns at this time. For example, recent vulnerabilities in Cisco Secure Firewall ASA, Microsoft Windows Ancillary Function Driver for WinSock, and WordPress Core have been added to the catalog, but their use in ransomware attacks is not confirmed.
What kinds of products are targeted by ransomware vulnerabilities?
The CISA catalog shows that ransomware actors target a wide range of products, including:
- Network security appliances (SonicWall, Check Point, Palo Alto Networks, Cisco)
- Enterprise software (Microsoft SharePoint, Exchange Server, Defender, Oracle PeopleSoft, PTC Windchill, SolarWinds Web Help Desk)
- IT management tools (ConnectWise ScreenConnect, SimpleHelp, JetBrains TeamCity, PaperCut NG/MF, WebPros cPanel & WHM)
- General-purpose operating systems (Microsoft Windows)
This diversity means you should not assume ransomware only threatens Windows desktops or email servers. Attackers go after any system with a vulnerability that gives them a foothold.
How do I know if I am exposed to these ransomware vulnerabilities?
Start by checking your environment for the affected products and versions. For each product listed above, review your asset inventory and patch management records. If you use any of these products, verify you have applied the latest security updates or mitigations recommended by the vendor.
If you use a managed service provider, ask them which of these CVEs they are tracking and how they are addressing them. If you manage your own infrastructure, prioritize patching these vulnerabilities above others, since they are proven attack vectors for ransomware.
Common questions
What is the CISA Known Exploited Vulnerabilities Catalog? It is a list maintained by the Cybersecurity and Infrastructure Security Agency (CISA) tracking vulnerabilities known to be exploited in the wild, including those used in ransomware campaigns.
How many ransomware vulnerabilities are in the CISA catalog? As of August 14, 2026, there are 349 entries flagged as having known ransomware campaign use.
Should I patch vulnerabilities not flagged for ransomware campaigns? Yes, but prioritize those flagged for ransomware use if they affect your systems, as they are proven to be exploited.
What should I do next?
If you are a defense contractor or support organizations handling sensitive data, understanding where ransomware attackers are actually getting in is critical for compliance and business continuity. Review the CISA Known Exploited Vulnerabilities Catalog, focus on the vulnerabilities confirmed as being used in ransomware campaigns, and make sure your patching program covers these high-risk areas.
For organizations preparing for CMMC or NIST 800-171, you may qualify for the Cyber Grants Alliance CMMC Gap Assessment Grant. This in kind grant is delivered as services, covering all 110 controls for qualifying defense contractors. Learn more at https://cybergrantsalliance.org/cmmc-gap-assessment-grant/.
Stay focused on what ransomware crews are actually exploiting, and make your Monday patching decisions count.