Firewall CVE Tracker
Every firewall, VPN and perimeter-device vulnerability in CISA's Known Exploited Vulnerabilities catalog — the ones with confirmed exploitation in the wild, not a severity score someone assigned. Filtered to products that actually sit at a network edge, so a sandbox appliance or a phone system from the same vendor doesn't bury the entries that matter.
Source: CISA KEV catalog 2026.07.27 (live). Last 24 months. Refreshed every 6 hours.
| Added | CVE | Product | CISA due | Flags |
|---|---|---|---|---|
| Jul 27, 2026 | CVE-2025-68686 | Fortinet FortiOS Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability → our analysis and mitigation | Aug 10, 2026 | we audit this vendor |
| Jul 22, 2026 | CVE-2026-16232 | Check Point SmartConsole Check Point SmartConsole Improper Authentication Vulnerability → our analysis and mitigation | Jul 25, 2026 | we audit this vendor |
| Jul 14, 2026 | CVE-2026-15409 | SonicWall SMA1000 Appliances SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability | Jul 17, 2026 | |
| Jul 14, 2026 | CVE-2026-15410 | SonicWall SMA1000 Appliances SonicWall SMA1000 Appliances Code Injection Vulnerability | Jul 17, 2026 | |
| Jun 15, 2026 | CVE-2026-20262 | Cisco Catalyst SD-WAN Manager Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability | Jun 29, 2026 | we audit this vendor |
| Jun 9, 2026 | CVE-2026-20245 | Cisco Catalyst SD-WAN Manager Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability | Jun 23, 2026 | we audit this vendor |
| Jun 8, 2026 | CVE-2026-50751 | Check Point Security Gateway Check Point Security Gateway Improper Authentication Vulnerability → our analysis and mitigation | Jun 11, 2026 | we audit this vendorransomware |
| May 29, 2026 | CVE-2026-0257 | Palo Alto Networks PAN-OS Palo Alto Networks PAN-OS Authentication Bypass Vulnerability → our analysis and mitigation | Jun 1, 2026 | we audit this vendorransomware |
| May 14, 2026 | CVE-2026-20182 | Cisco Catalyst SD-WAN Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability | May 17, 2026 | we audit this vendor |
| May 6, 2026 | CVE-2026-0300 | Palo Alto Networks PAN-OS Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability → our analysis and mitigation | May 9, 2026 | we audit this vendor |
| Apr 20, 2026 | CVE-2026-20122 | Cisco Catalyst SD-WAN Manger Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability | Apr 23, 2026 | we audit this vendor |
| Apr 20, 2026 | CVE-2026-20133 | Cisco Catalyst SD-WAN Manager Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability | Apr 23, 2026 | we audit this vendor |
| Apr 20, 2026 | CVE-2026-20128 | Cisco Catalyst SD-WAN Manager Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability | Apr 23, 2026 | we audit this vendor |
| Apr 13, 2026 | CVE-2026-21643 | Fortinet FortiClient EMS Fortinet FortiClient EMS SQL Injection Vulnerability | Apr 16, 2026 | we audit this vendor |
| Apr 6, 2026 | CVE-2026-35616 | Fortinet FortiClient EMS Fortinet FortiClient EMS Improper Access Control Vulnerability | Apr 9, 2026 | we audit this vendor |
| Mar 19, 2026 | CVE-2026-20131 | Cisco Secure Firewall Management Center (FMC) Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability | Mar 22, 2026 | we audit this vendorransomware |
| Feb 25, 2026 | CVE-2022-20775 | Cisco SD-WAN Cisco SD-WAN Path Traversal Vulnerability | Feb 27, 2026 | we audit this vendor |
| Feb 25, 2026 | CVE-2026-20127 | Cisco Catalyst SD-WAN Controller and Manager Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability | Feb 27, 2026 | we audit this vendor |
| Dec 17, 2025 | CVE-2025-40602 | SonicWall SMA1000 appliance SonicWall SMA1000 Missing Authorization Vulnerability | Dec 24, 2025 | |
| Dec 8, 2025 | CVE-2022-37055 | D-Link Routers D-Link Routers Buffer Overflow Vulnerability | Dec 29, 2025 | |
| Sep 25, 2025 | CVE-2025-20362 | Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Missing Authorization Vulnerability | Sep 26, 2025 | we audit this vendor |
| Sep 25, 2025 | CVE-2025-20333 | Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Buffer Overflow Vulnerability | Sep 26, 2025 | we audit this vendor |
| Sep 3, 2025 | CVE-2025-9377 | TP-Link Multiple Routers TP-Link Archer C7(EU) and TL-WR841N/ND(MS) OS Command Injection Vulnerability | Sep 24, 2025 | |
| Jul 10, 2025 | CVE-2025-5777 | Citrix NetScaler ADC and Gateway Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability | Jul 11, 2025 | ransomware |
| Jun 30, 2025 | CVE-2025-6543 | Citrix NetScaler ADC and Gateway Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerability | Jul 21, 2025 | |
| Jun 25, 2025 | CVE-2019-6693 | Fortinet FortiOS Fortinet FortiOS Use of Hard-Coded Credentials Vulnerability | Jul 16, 2025 | we audit this vendorransomware |
| Jun 25, 2025 | CVE-2024-0769 | D-Link DIR-859 Router D-Link DIR-859 Router Path Traversal Vulnerability | Jul 16, 2025 | |
| Jun 16, 2025 | CVE-2023-33538 | TP-Link Multiple Routers TP-Link Multiple Routers Command Injection Vulnerability | Jul 7, 2025 | |
| May 15, 2025 | CVE-2024-12987 | DrayTek Vigor Routers DrayTek Vigor Routers OS Command Injection Vulnerability | Jun 5, 2025 | |
| May 1, 2025 | CVE-2023-44221 | SonicWall SMA100 Appliances SonicWall SMA100 Appliances OS Command Injection Vulnerability | May 22, 2025 | |
| Apr 16, 2025 | CVE-2021-20035 | SonicWall SMA100 Appliances SonicWall SMA100 Appliances OS Command Injection Vulnerability | May 7, 2025 | |
| Apr 4, 2025 | CVE-2025-22457 | Ivanti Connect Secure, Policy Secure, and ZTA Gateways Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability | Apr 11, 2025 | ransomware |
| Mar 18, 2025 | CVE-2025-24472 | Fortinet FortiOS and FortiProxy Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability | Apr 8, 2025 | we audit this vendorransomware |
| Mar 3, 2025 | CVE-2023-20118 | Cisco Small Business RV Series Routers Cisco Small Business RV Series Routers Command Injection Vulnerability | Mar 24, 2025 | we audit this vendor |
| Feb 20, 2025 | CVE-2025-0111 | Palo Alto Networks PAN-OS Palo Alto Networks PAN-OS File Read Vulnerability | Mar 13, 2025 | we audit this vendor |
| Feb 18, 2025 | CVE-2025-0108 | Palo Alto Networks PAN-OS Palo Alto Networks PAN-OS Authentication Bypass Vulnerability | Mar 11, 2025 | we audit this vendor |
| Feb 18, 2025 | CVE-2024-53704 | SonicWall SonicOS SonicWall SonicOS SSLVPN Improper Authentication Vulnerability | Mar 11, 2025 | ransomware |
| Feb 6, 2025 | CVE-2020-15069 | Sophos XG Firewall Sophos XG Firewall Buffer Overflow Vulnerability | Feb 27, 2025 | we audit this vendor |
| Jan 24, 2025 | CVE-2025-23006 | SonicWall SMA1000 Appliances SonicWall SMA1000 Appliances Deserialization Vulnerability | Feb 14, 2025 | ransomware |
| Jan 14, 2025 | CVE-2024-55591 | Fortinet FortiOS and FortiProxy Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability | Jan 21, 2025 | we audit this vendorransomware |
| Jan 8, 2025 | CVE-2025-0282 | Ivanti Connect Secure, Policy Secure, and ZTA Gateways Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability | Jan 15, 2025 | ransomware |
| Dec 30, 2024 | CVE-2024-3393 | Palo Alto Networks PAN-OS Palo Alto Networks PAN-OS Malicious DNS Packet Vulnerability | Jan 20, 2025 | we audit this vendor |
| Dec 3, 2024 | CVE-2024-11667 | Zyxel Multiple Firewalls Zyxel Multiple Firewalls Path Traversal Vulnerability | Dec 24, 2024 | ransomware |
| Nov 18, 2024 | CVE-2024-9474 | Palo Alto Networks PAN-OS Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability | Dec 9, 2024 | we audit this vendorransomware |
| Nov 18, 2024 | CVE-2024-0012 | Palo Alto Networks PAN-OS Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability | Dec 9, 2024 | we audit this vendorransomware |
| Nov 12, 2024 | CVE-2014-2120 | Cisco Adaptive Security Appliance (ASA) Cisco Adaptive Security Appliance (ASA) Cross-Site Scripting (XSS) Vulnerability | Dec 3, 2024 | we audit this vendor |
| Oct 24, 2024 | CVE-2024-20481 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) Cisco ASA and FTD Denial-of-Service Vulnerability | Nov 14, 2024 | we audit this vendor |
| Sep 30, 2024 | CVE-2020-15415 | DrayTek Multiple Vigor Routers DrayTek Multiple Vigor Routers OS Command Injection Vulnerability | Oct 21, 2024 | |
| Sep 30, 2024 | CVE-2023-25280 | D-Link DIR-820 Router D-Link DIR-820 Router OS Command Injection Vulnerability | Oct 21, 2024 |
Which of these affects your firewalls?
Answering that needs two facts per device: the exact firmware version, and whether the vulnerable feature is even enabled. Both live in the config you already have. Upload a FortiGate, Palo Alto, Check Point, Sophos or Cisco ASA config and CRWLR cross-references the running version against CISA KEV, NVD and vendor PSIRT feeds — and skips CVEs for features your config shows are off.
Check my firewalls →60 seconds. No credit card. Raw configs never stored.
How this list is built
- → Source is the CISA Known Exploited Vulnerabilities catalog — inclusion requires reliable evidence of active exploitation, so a medium-scored entry here outranks a critical nobody has ever used.
- → We filter to perimeter products — firewalls, VPN gateways, SD-WAN and secure-access appliances. Entries from the same vendors for non-edge products (sandboxes, phone systems) are excluded from this table on purpose.
- → "We audit this vendor" means CRWLR parses that vendor's configuration. It does not mean we detect that specific vulnerability — many edge flaws live in binaries or filesystems a config export doesn't contain.
- → The CISA due date is the federal remediation deadline under BOD 22-01 / 26-04. It is not a legal obligation for private companies — it is a useful signal of how fast the agency thinks you should move.