Weekly Enterprise Exploitation Trend Report

23-07-2025 to 29-07-2025
The report focuses solely on the exploitation statistics specific to enterprise vendors and their products over the past week, providing valuable insights to prioritize security measures and address emerging threats effectively.
244
244
Actively Exploited Vulnerabilities
110
110
Vendors Actively Exploited
Apache
Apache
Most Exploited Vendor
Atassian Confluence
Atassian Confluence
Most Exploited Product
Top 10 Actively Exploited Vendors
1
Apache
2
Ivanti
3
Atlassian
4
Cisco
5
Oracle
6
Microsoft
7
Palo Alto Networks
8
VMware
9
Citrix
10
Adobe
Top 10 CVEs of 2025 with the Highest EPSS Scores -30-07-2025
1
CVE-2023-42793
  • JetBrains TeamCity
  • Remote Code Execution
  • EPSS: 0.94584
  • Percentile: 1
2
CVE-2024-27198
  • JetBrains TeamCity
  • Authentication Bypass
  • EPSS: 0.94577
  • Percentile: 1
3
CVE-2023-23752
  • Joomla
  • Improper Access Control
  • EPSS: 0.94532
  • Percentile: 1
4
CVE-2024-27199
  • JetBrains TeamCity
  • Path Traversal
  • EPSS: 0.94489
  • Percentile: 0.99999
5
CVE-2023-35078
  • Ivanti EPMM
  • Authentication Bypass
  • EPSS: 0.94485
  • Percentile:0.99998
6
CVE-2023-35082
  • Ivanti EPMM
  • Authentication Bypass
  • EPSS: 0.94468
  • Percentile:0.99995
7
CVE-2024-6670
  • WhatUp Gold
  • SQL Injection
  • EPSS:0.94467
  • Percentile: 0.99995
8
CVE-2024-23897
  • Jenkins
  • Path Traversal
  • EPSS: 0.94466
  • Percentile: 0.99994
9
CVE-2023-46747
  • F5 BIG-IP Configuration Utility
  • Authentication Bypass
  • EPSS:0.94439
  • Percentile: 0.99987
10
CVE-2023-32315
  • Openfire
  • Path Traversal
  • EPSS: 0.94439
  • Percentile: 0.99986
Top Exploited CVEs Against Enterprise Applications
CVE-2023-22515
Critical
Critical
Critical
Critical
Atlassian
  • Broken Access Control
  • Confluence
  • Used by Ransomware
    -
    United States
CVE-2023-20198
Critical
Critical
Critical
Critical
Cisco
  • Code/command Injection and Execution
  • Cisco IOS XE
  • -
    United States
CVE-2022-41082
High
High
High
High
Microsoft
  • Code/command Injection and Execution
  • Exchange
  • Used by Ransomware
    -
    United States
CVE-2017-9841
Critical
Critical
Critical
Critical
PHPUnit - Sebastian Bergmann
  • Code/command Injection and Execution
  • PHPUnit
  • -
    United States
CVE-2023-42793
Critical
Critical
Critical
Critical
JetBrains
  • Code/command Injection and Execution
  • TeamCity
  • Used by Ransomware
    -
    United States
CVE-2021-42013
Critical
Critical
Critical
Critical
Apache
  • Path Traversal
  • Apache HTTP Server
  • Used by Ransomware
    -
    China
CVE-2019-1653
High
High
High
High
Cisco
  • Sensitive Information Disclosure
  • Cisco RV320/RV325
  • -
    Netherlands
CVE-2022-26134
Critical
Critical
Critical
Critical
Atlassian
  • Code/command Injection and Execution
  • Confluence
  • Used by Ransomware
    -
    United States
CVE-2023-22527
Critical
Critical
Critical
Critical
Atlassian
  • Code/command Injection and Execution
  • Confluence
  • Used by Ransomware
    -
    Netherlands
CVE-2023-23752
Medium
Medium
Medium
Medium
Open Source Matters, Inc/Joomla community
  • Improper Access Control
  • Joomla
  • -
    United States
Top 10 Targeted Countries
Top 10 Targeted Countries
China
:
44428
United States
:
34559
Singapore
:
17999
India
:
10579
Turkey
:
8086
Russia
:
6164
Brazil
:
5807
South Korea
:
4792
UK
:
4368
Germany
:
3457
Actively Exploited Enterprise Vendors
Apache | Ivanti | Atlassian | D-Link | Cisco | Oracle | Microsoft | Palo Alto Networks | VMware | Citrix | Adobe | Draytek | Progress | Netgear | F5 | Spring | Fortinet | Wordpress | ZyXEL | SysAid | Zoho | SAP | Realtek | JetBrains | Synacor | Geoserver | SolarWinds | Juniper | Drupal | QNAP | Sonatype | Elastic | Aviatrix | SonicWall | Tenda | Jenkins | TopThink | Dasan | PHPUnit - Sebastian Bergmann | Open Source Matters, Inc/Joomla community | ownCloud | Fortra | Zyxel/Billion | Pulse Secure | Sophos | Check Point | Laravel | SaltStack | TP-Link | PaperCut | ASUS | vBulletin | Webmin | GLPI (teclib) | Terramaster | PrimeFaces | WSO2 | Mitel | Metabase | Telerik | Rejetto | wftpserver.com | PHP Foundation | MinIO | NAKIVO | ConnectWise | IBM | ForgeRock | Commvault | Hikvision | GNU | Langflow | Yealink | Barco/AWIND | Linear | LG | nostromo | MobileIron | mongo-express | CONTEC | Roundcube | Grafana | Wazuh | Node.js | GeoVision | Kentico | Dahua | dotCMS | Qlik | Sunhillo | Micro Focus | Cacti | Sitecore | NextGen Healthcare | Hitachi Vantara | Lime Technology | CrushFTP | Ignite Realtime | CyberPanel | ServiceNow | D-Link/TRENDnet | RedHat | netis | Grandstream | Arcadyan | SugarCRM | Ruckus | Array Networks | Cleo | PTZOptics
Most Active Ransomware Groups
#
Industry
Country
Ransomware
1
1
Business
Industry
United States
Country
rhysida
2
2
Business
Industry
United States
Country
lynx
3
3
Business
Industry
United States
Country
brain cipher
4
4
Media
Industry
United States
Country
global
5
5
Business
Industry
UAE
Country
dragonforce
6
6
Business
Industry
United States
Country
kairos
7
7
Food
Industry
United States
Country
direwolf
8
8
Healthcare
Industry
Germany
Country
worldleaks
9
9
Business
Industry
Turkey
Country
qilin
10
10
Business
Industry
United States
Country
warlock
Ransomware Posting Frequency by Group - Last 7 Days
Remotely Exploited CISA KEV CVEs Added
These vulnerabilities have been newly added to the Known Exploited Vulnerabilities (KEV) Catalog. Organizations should prioritize addressing them  to mitigate risks.
CVE-2023-2533
CVE-2025-20337
CVE-2025-20281
CVE-2025-2775
CVE-2025-2776
CVE-2025-6558
CVE-2025-54309
CVE-2025-49704
CVE-2025-49706
CVE-2025-53770