The most dangerous VPN vulnerabilities of the past seven years affect corporate VPN gateways rather than consumer VPN apps. These are the gateways companies and governments expose to the internet: Pulse Secure/Ivanti Connect Secure, Fortinet FortiOS SSL-VPN, Citrix NetScaler Gateway, Palo Alto GlobalProtect, Cisco ASA, SonicWall and Check Point. Dozens of their flaws have been exploited in the wild, many by ransomware gangs and state-backed espionage groups, often before a patch existed.
The tracker covers the most significant critical and exploited flaws from 2019 to 2026, with scores from the US National Vulnerability Database (NVD) and exploitation status from CISA’s Known Exploited Vulnerabilities (KEV) catalog.
Exploited VPN gateway flaws by product line
Of the 1,730 entries in CISA’s KEV catalog as of September 30, 2026, 103 belong to the seven vendors’ product lines that include remote-access VPN gateways. Not every entry affects the VPN component itself; some hit the management interface of the same appliance, which attackers reach the same way.
| Product line | KEV entries | Flagged “known ransomware use” | Source |
|---|---|---|---|
| Fortinet FortiOS / FortiProxy (incl. multi-product advisories) | 21 | 13 | CISA KEV, 2026 |
| Citrix NetScaler ADC / Gateway | 20 | 4 | CISA KEV, 2026 |
| Pulse Secure / Ivanti Connect Secure and Policy Secure | 16 | 10 | CISA KEV, 2026 |
| SonicWall SMA, SonicOS, SRA | 16 | 10 | CISA KEV, 2026 |
| Cisco ASA / Firepower Threat Defense | 14 | 3 | CISA KEV, 2026 |
| Palo Alto Networks PAN-OS | 12 | 6 | CISA KEV, 2026 |
| Check Point security gateways | 4 | 2 | CISA KEV, 2026 |
| Total | 103 | 48 |
By the year CISA added them, these entries break down as 21 in 2021 (the catalog launched that November with a backlog), 22 in 2022, 5 in 2023, 18 in 2024, 19 in 2025 and 18 in the first nine months of 2026, so the pace has not slowed.
Critical exploited VPN vulnerabilities, 2019 to 2026
These are the flaws with the greatest impact on VPN gateways. “CVSS” is NVD’s own CVSS v3.1 base score unless noted; where NVD has not scored a CVE, the vendor’s or CISA’s score is given and labeled. “Ransomware” reflects CISA’s flag on the KEV entry.
| CVE | Product | What it allows | CVSS | Year | In CISA KEV | Ransomware | Source |
|---|---|---|---|---|---|---|---|
| CVE-2019-11510 | Pulse Connect Secure | Unauthenticated arbitrary file read | 10.0 | 2019 | Yes | Known | NVD |
| CVE-2018-13379 | Fortinet FortiOS SSL VPN | Unauthenticated download of system files | 9.8 | 2019 | Yes | Known | NVD |
| CVE-2019-1579 | Palo Alto GlobalProtect | Remote code execution | 8.1 | 2019 | Yes | Known | NVD |
| CVE-2019-19781 | Citrix ADC / Gateway | Directory traversal leading to code execution | 9.8 | 2019 | Yes | Known | NVD |
| CVE-2020-12812 | Fortinet FortiOS SSL VPN | Login without second factor (username case change) | 9.8 | 2020 | Yes | Known | NVD |
| CVE-2020-5135 | SonicWall SonicOS | Buffer overflow, possible code execution | 9.8 | 2020 | Yes | Known | NVD |
| CVE-2021-22893 | Pulse Connect Secure | Authentication bypass | 10.0 | 2021 | Yes | Known | NVD |
| CVE-2021-20016 | SonicWall SSLVPN SMA100 | SQL injection exposing credentials | 9.8 | 2021 | Yes | Known | NVD |
| CVE-2021-20038 | SonicWall SMA100 | Unauthenticated stack overflow | 9.8 | 2021 | Yes | Known | NVD |
| CVE-2022-42475 | Fortinet FortiOS SSL-VPN | Heap overflow, code execution | 9.8 | 2023 | Yes | Known | NVD |
| CVE-2022-27518 | Citrix ADC / Gateway | Unauthenticated code execution | 9.8 | 2022 | Yes | Not known | NVD |
| CVE-2023-27997 | Fortinet FortiOS SSL-VPN | Heap overflow, code execution | 9.8 | 2023 | Yes | Known | NVD |
| CVE-2023-3519 | Citrix NetScaler ADC / Gateway | Unauthenticated code execution | 9.8 | 2023 | Yes | Known | NVD |
| CVE-2023-4966 (“Citrix Bleed”) | Citrix NetScaler Gateway | Sensitive information disclosure | 7.5 (Citrix: 9.4) | 2023 | Yes | Known | NVD |
| CVE-2023-20269 | Cisco ASA / FTD remote access VPN | Password brute-forcing; unauthorized clientless VPN session | 9.1 (Cisco: 5.0) | 2023 | Yes | Known | NVD |
| CVE-2023-46805 | Ivanti Connect Secure | Authentication bypass | 8.2 | 2024 | Yes | Known | NVD |
| CVE-2024-21887 | Ivanti Connect Secure | Command injection (chained with above) | 9.1 | 2024 | Yes | Known | NVD |
| CVE-2024-21762 | Fortinet FortiOS SSL VPN | Out-of-bounds write, code execution | 9.8 | 2024 | Yes | Known | NVD |
| CVE-2024-3400 | Palo Alto GlobalProtect | Command injection | 10.0 | 2024 | Yes | Known | NVD |
| CVE-2024-24919 | Check Point gateways with VPN enabled | Information disclosure | 8.6 | 2024 | Yes | Known | NVD |
| CVE-2024-40766 | SonicWall SonicOS | Improper access control in management access | 9.8 | 2024 | Yes | Known | NVD |
| CVE-2024-53704 | SonicWall SonicOS SSLVPN | Authentication bypass | 9.8 | 2025 | Yes | Known | NVD |
| CVE-2025-0282 | Ivanti Connect Secure | Stack overflow, code execution | 9.0 | 2025 | Yes | Known | NVD |
| CVE-2025-23006 | SonicWall SMA1000 | Pre-auth deserialization | 9.8 | 2025 | Yes | Known | NVD |
| CVE-2025-22457 | Ivanti Connect Secure | Stack overflow, code execution | 9.8 (Ivanti: 9.0) | 2025 | Yes | Known | NVD |
| CVE-2025-5777 (“CitrixBleed 2”) | Citrix NetScaler Gateway | Memory overread | 7.5 (Citrix CVSS 4.0: 9.3) | 2025 | Yes | Known | NVD |
| CVE-2025-20333 | Cisco ASA / FTD VPN web server | Remote code execution | 9.9 (Cisco; no NVD score) | 2025 | Yes | Not known | NVD |
| CVE-2025-20362 | Cisco ASA / FTD VPN web server | Missing authorization (chained with above) | 8.6 | 2025 | Yes | Not known | NVD |
| CVE-2026-0257 | Palo Alto GlobalProtect | Authentication bypass, unauthorized VPN connection | 9.1 | 2026 | Yes | Known | NVD |
| CVE-2026-50751 | Check Point Remote Access (IKEv1) | VPN login without valid password | 9.3 (CISA-ADP; no NVD score) | 2026 | Yes | Known | NVD |
“Year” is the year NVD published the CVE. NVD and vendors sometimes disagree sharply: Citrix rated Citrix Bleed 9.4 while NVD rated it 7.5, and Cisco rated CVE-2023-20269 at 5.0 while NVD gave 9.1. Severity scores also say nothing about how widely a flaw is exploited: Citrix Bleed’s NVD score of 7.5 sits below many unexploited bugs, yet CISA lists it as exploited and used by ransomware groups.
Why VPN gateways are top targets
Attackers value three properties of VPN gateways. A remote-access gateway faces the internet by design: it has to accept connections from anywhere, so it cannot simply be hidden behind a firewall. It also sits at the network edge with high privileges, so a compromised gateway can reveal credentials and session tokens and give a foothold inside the network. And the appliances are hard to monitor, because they run closed firmware where endpoint security tools usually cannot be installed.
In Verizon’s 2025 Data Breach Investigations Report, exploitation of vulnerabilities was the initial access route in 20% of breaches, a 34% increase on the previous report. Edge devices and VPNs were the target in 22% of vulnerability-exploitation cases, almost eight times the 3% seen a year earlier (Verizon DBIR, 2025).
Verizon found that 54% of the edge-device vulnerabilities in its sample were fully remediated during the year, compared with 38% for the KEV catalog overall, with a median of 32 days to fix. But for a sample of 17 edge-device CVEs, the median time between CVE publication and CISA listing the flaw as exploited was zero days. Nine of the 17 were listed as exploited on or before their publication date (Verizon DBIR, 2025), so many organizations were being attacked before they could possibly have patched.
Emergency directives: Ivanti and Cisco
Two VPN product lines have triggered CISA emergency directives, which order US federal civilian agencies to act within days.
- ED 24-01, Ivanti (January 19, 2024): after “widespread and active exploitation” of CVE-2023-46805 and CVE-2024-21887, CISA ordered agencies to apply mitigations and run integrity checks. Supplemental direction later required agencies to disconnect affected Ivanti products by February 2, 2024, and to rebuild them before reconnecting, because attackers had found ways around earlier mitigations (CISA, 2024).
- ED 25-03, Cisco (September 25, 2025): CISA cited an ongoing campaign, linked to the “ArcaneDoor” activity, that exploited CVE-2025-20333 and CVE-2025-20362. The attackers could modify device ROM to persist through reboots and upgrades, so agencies had to collect forensic data and disconnect end-of-support devices (CISA, 2025).
Vendor patterns
- Fortinet’s SSL-VPN has produced a run of heap-overflow and out-of-bounds bugs (2022, 2023, 2024), each rated 9.8 and each exploited.
- Ivanti Connect Secure (formerly Pulse Secure) appears at both ends of the period, from CVE-2019-11510 to the 2025 stack overflows, with 10 of its 16 KEV entries flagged for ransomware use.
- Citrix NetScaler Gateway suffered two “Bleed” memory-disclosure bugs two years apart (2023 and 2025), both exploited and both flagged for ransomware use.
- Palo Alto GlobalProtect had maximum-severity CVE-2024-3400 and a further exploited authentication bypass in 2026.
Consumer VPN apps
Consumer VPN clients rarely appear in KEV, which focuses on flaws exploited against organizations. One client entry is Cisco’s AnyConnect Secure Mobility Client for Windows (CVE-2020-3433, CVSS 7.8), a local privilege escalation flagged for ransomware use.
The best-known recent consumer-side issue is an attack technique that works across products. TunnelVision (CVE-2024-3661, CVSS 7.6) lets an attacker on the same local network use DHCP option 121 to route a victim’s traffic outside the VPN tunnel without tripping the kill switch. It affects routing-based VPNs on Windows, Linux, macOS and iOS; Android is not affected because it ignores option 121 (Leviathan Security, 2024). It is not listed in KEV.
What this means for you
If you run a VPN gateway:
- Subscribe to your vendor’s security advisories and to CISA KEV updates; treat KEV listings as patch-now events.
- Assume compromise when a critical gateway flaw is exploited before disclosure: patch, but also check integrity, reset credentials and revoke sessions.
- Do not expose management interfaces to the internet, and require phishing-resistant MFA for VPN logins.
- Plan to retire end-of-support appliances; ED 25-03 required disconnecting them.
If you are an individual:
- These gateway bugs mostly affect employers rather than personal VPN subscriptions, but a breach at your company’s VPN can expose your work credentials, so use unique passwords and MFA.
- Keep your personal VPN app and operating system updated, and avoid untrusted Wi-Fi for sensitive work given attacks like TunnelVision.
Methodology
KEV counts come from CISA’s KEV JSON feed (catalog version 2026.09.30, 1,730 entries), filtered by vendor and product for lines that include remote-access VPN gateways. Scores in the main table come from the NVD CVE API 2.0, queried on October 1, 2026: the NVD primary CVSS v3.1 base score, or the vendor or CISA-ADP score where NVD had not scored the CVE. Ransomware status is CISA’s “knownRansomwareCampaignUse” field. Context comes from Verizon’s 2025 DBIR, CISA emergency directives and the TunnelVision disclosure.
KEV lists only vulnerabilities CISA has confirmed as exploited; absence from KEV does not mean a flaw is safe. Our product filter is broad and includes some non-VPN components of the same appliances. CVSS scores change as NVD re-analyzes CVEs. The main table is a curated selection of VPN-related CVEs and leaves out consumer VPN client bugs that lack an independent public record.