Original Research 9 min read

VPN Vulnerabilities Tracker: Critical CVEs in VPN Products (2019–2026)

Tracker of critical, exploited VPN vulnerabilities 2019 to 2026 from NVD and CISA KEV data: Ivanti, Fortinet, Citrix, Palo Alto, Cisco, SonicWall, Check Point.

VPN Vulnerabilities Tracker: Critical CVEs in VPN Products (2019–2026)

Key Findings

  • As of September 30, 2026, CISA's Known Exploited Vulnerabilities catalog listed 103 entries for seven vendors' VPN-gateway product lines; 48 of them were flagged as used in ransomware campaigns.
  • Verizon's 2025 DBIR found edge devices and VPNs were the target in 22% of vulnerability-exploitation breaches, up from 3% a year earlier.
  • For a sample of 17 edge-device flaws, Verizon measured a median of zero days between CVE publication and CISA's confirmation of exploitation; 9 of 17 were listed as exploited on or before publication day.
  • Two VPN products triggered CISA emergency directives: Ivanti Connect Secure in January 2024 and Cisco ASA/FTD in September 2025.
  • 22 of the 30 gateway CVEs in our table carry an NVD base score of 9.0 or higher, and three (two Pulse Secure flaws and Palo Alto's CVE-2024-3400) scored the maximum 10.0.

The most dangerous VPN vulnerabilities of the past seven years affect corporate VPN gateways rather than consumer VPN apps. These are the gateways companies and governments expose to the internet: Pulse Secure/Ivanti Connect Secure, Fortinet FortiOS SSL-VPN, Citrix NetScaler Gateway, Palo Alto GlobalProtect, Cisco ASA, SonicWall and Check Point. Dozens of their flaws have been exploited in the wild, many by ransomware gangs and state-backed espionage groups, often before a patch existed.

The tracker covers the most significant critical and exploited flaws from 2019 to 2026, with scores from the US National Vulnerability Database (NVD) and exploitation status from CISA’s Known Exploited Vulnerabilities (KEV) catalog.

Exploited VPN gateway flaws by product line

Of the 1,730 entries in CISA’s KEV catalog as of September 30, 2026, 103 belong to the seven vendors’ product lines that include remote-access VPN gateways. Not every entry affects the VPN component itself; some hit the management interface of the same appliance, which attackers reach the same way.

Product lineKEV entriesFlagged “known ransomware use”Source
Fortinet FortiOS / FortiProxy (incl. multi-product advisories)2113CISA KEV, 2026
Citrix NetScaler ADC / Gateway204CISA KEV, 2026
Pulse Secure / Ivanti Connect Secure and Policy Secure1610CISA KEV, 2026
SonicWall SMA, SonicOS, SRA1610CISA KEV, 2026
Cisco ASA / Firepower Threat Defense143CISA KEV, 2026
Palo Alto Networks PAN-OS126CISA KEV, 2026
Check Point security gateways42CISA KEV, 2026
Total10348

By the year CISA added them, these entries break down as 21 in 2021 (the catalog launched that November with a backlog), 22 in 2022, 5 in 2023, 18 in 2024, 19 in 2025 and 18 in the first nine months of 2026, so the pace has not slowed.

Critical exploited VPN vulnerabilities, 2019 to 2026

These are the flaws with the greatest impact on VPN gateways. “CVSS” is NVD’s own CVSS v3.1 base score unless noted; where NVD has not scored a CVE, the vendor’s or CISA’s score is given and labeled. “Ransomware” reflects CISA’s flag on the KEV entry.

CVEProductWhat it allowsCVSSYearIn CISA KEVRansomwareSource
CVE-2019-11510Pulse Connect SecureUnauthenticated arbitrary file read10.02019YesKnownNVD
CVE-2018-13379Fortinet FortiOS SSL VPNUnauthenticated download of system files9.82019YesKnownNVD
CVE-2019-1579Palo Alto GlobalProtectRemote code execution8.12019YesKnownNVD
CVE-2019-19781Citrix ADC / GatewayDirectory traversal leading to code execution9.82019YesKnownNVD
CVE-2020-12812Fortinet FortiOS SSL VPNLogin without second factor (username case change)9.82020YesKnownNVD
CVE-2020-5135SonicWall SonicOSBuffer overflow, possible code execution9.82020YesKnownNVD
CVE-2021-22893Pulse Connect SecureAuthentication bypass10.02021YesKnownNVD
CVE-2021-20016SonicWall SSLVPN SMA100SQL injection exposing credentials9.82021YesKnownNVD
CVE-2021-20038SonicWall SMA100Unauthenticated stack overflow9.82021YesKnownNVD
CVE-2022-42475Fortinet FortiOS SSL-VPNHeap overflow, code execution9.82023YesKnownNVD
CVE-2022-27518Citrix ADC / GatewayUnauthenticated code execution9.82022YesNot knownNVD
CVE-2023-27997Fortinet FortiOS SSL-VPNHeap overflow, code execution9.82023YesKnownNVD
CVE-2023-3519Citrix NetScaler ADC / GatewayUnauthenticated code execution9.82023YesKnownNVD
CVE-2023-4966 (“Citrix Bleed”)Citrix NetScaler GatewaySensitive information disclosure7.5 (Citrix: 9.4)2023YesKnownNVD
CVE-2023-20269Cisco ASA / FTD remote access VPNPassword brute-forcing; unauthorized clientless VPN session9.1 (Cisco: 5.0)2023YesKnownNVD
CVE-2023-46805Ivanti Connect SecureAuthentication bypass8.22024YesKnownNVD
CVE-2024-21887Ivanti Connect SecureCommand injection (chained with above)9.12024YesKnownNVD
CVE-2024-21762Fortinet FortiOS SSL VPNOut-of-bounds write, code execution9.82024YesKnownNVD
CVE-2024-3400Palo Alto GlobalProtectCommand injection10.02024YesKnownNVD
CVE-2024-24919Check Point gateways with VPN enabledInformation disclosure8.62024YesKnownNVD
CVE-2024-40766SonicWall SonicOSImproper access control in management access9.82024YesKnownNVD
CVE-2024-53704SonicWall SonicOS SSLVPNAuthentication bypass9.82025YesKnownNVD
CVE-2025-0282Ivanti Connect SecureStack overflow, code execution9.02025YesKnownNVD
CVE-2025-23006SonicWall SMA1000Pre-auth deserialization9.82025YesKnownNVD
CVE-2025-22457Ivanti Connect SecureStack overflow, code execution9.8 (Ivanti: 9.0)2025YesKnownNVD
CVE-2025-5777 (“CitrixBleed 2”)Citrix NetScaler GatewayMemory overread7.5 (Citrix CVSS 4.0: 9.3)2025YesKnownNVD
CVE-2025-20333Cisco ASA / FTD VPN web serverRemote code execution9.9 (Cisco; no NVD score)2025YesNot knownNVD
CVE-2025-20362Cisco ASA / FTD VPN web serverMissing authorization (chained with above)8.62025YesNot knownNVD
CVE-2026-0257Palo Alto GlobalProtectAuthentication bypass, unauthorized VPN connection9.12026YesKnownNVD
CVE-2026-50751Check Point Remote Access (IKEv1)VPN login without valid password9.3 (CISA-ADP; no NVD score)2026YesKnownNVD

“Year” is the year NVD published the CVE. NVD and vendors sometimes disagree sharply: Citrix rated Citrix Bleed 9.4 while NVD rated it 7.5, and Cisco rated CVE-2023-20269 at 5.0 while NVD gave 9.1. Severity scores also say nothing about how widely a flaw is exploited: Citrix Bleed’s NVD score of 7.5 sits below many unexploited bugs, yet CISA lists it as exploited and used by ransomware groups.

Why VPN gateways are top targets

Attackers value three properties of VPN gateways. A remote-access gateway faces the internet by design: it has to accept connections from anywhere, so it cannot simply be hidden behind a firewall. It also sits at the network edge with high privileges, so a compromised gateway can reveal credentials and session tokens and give a foothold inside the network. And the appliances are hard to monitor, because they run closed firmware where endpoint security tools usually cannot be installed.

In Verizon’s 2025 Data Breach Investigations Report, exploitation of vulnerabilities was the initial access route in 20% of breaches, a 34% increase on the previous report. Edge devices and VPNs were the target in 22% of vulnerability-exploitation cases, almost eight times the 3% seen a year earlier (Verizon DBIR, 2025).

Verizon found that 54% of the edge-device vulnerabilities in its sample were fully remediated during the year, compared with 38% for the KEV catalog overall, with a median of 32 days to fix. But for a sample of 17 edge-device CVEs, the median time between CVE publication and CISA listing the flaw as exploited was zero days. Nine of the 17 were listed as exploited on or before their publication date (Verizon DBIR, 2025), so many organizations were being attacked before they could possibly have patched.

Emergency directives: Ivanti and Cisco

Two VPN product lines have triggered CISA emergency directives, which order US federal civilian agencies to act within days.

  • ED 24-01, Ivanti (January 19, 2024): after “widespread and active exploitation” of CVE-2023-46805 and CVE-2024-21887, CISA ordered agencies to apply mitigations and run integrity checks. Supplemental direction later required agencies to disconnect affected Ivanti products by February 2, 2024, and to rebuild them before reconnecting, because attackers had found ways around earlier mitigations (CISA, 2024).
  • ED 25-03, Cisco (September 25, 2025): CISA cited an ongoing campaign, linked to the “ArcaneDoor” activity, that exploited CVE-2025-20333 and CVE-2025-20362. The attackers could modify device ROM to persist through reboots and upgrades, so agencies had to collect forensic data and disconnect end-of-support devices (CISA, 2025).

Vendor patterns

  • Fortinet’s SSL-VPN has produced a run of heap-overflow and out-of-bounds bugs (2022, 2023, 2024), each rated 9.8 and each exploited.
  • Ivanti Connect Secure (formerly Pulse Secure) appears at both ends of the period, from CVE-2019-11510 to the 2025 stack overflows, with 10 of its 16 KEV entries flagged for ransomware use.
  • Citrix NetScaler Gateway suffered two “Bleed” memory-disclosure bugs two years apart (2023 and 2025), both exploited and both flagged for ransomware use.
  • Palo Alto GlobalProtect had maximum-severity CVE-2024-3400 and a further exploited authentication bypass in 2026.

Consumer VPN apps

Consumer VPN clients rarely appear in KEV, which focuses on flaws exploited against organizations. One client entry is Cisco’s AnyConnect Secure Mobility Client for Windows (CVE-2020-3433, CVSS 7.8), a local privilege escalation flagged for ransomware use.

The best-known recent consumer-side issue is an attack technique that works across products. TunnelVision (CVE-2024-3661, CVSS 7.6) lets an attacker on the same local network use DHCP option 121 to route a victim’s traffic outside the VPN tunnel without tripping the kill switch. It affects routing-based VPNs on Windows, Linux, macOS and iOS; Android is not affected because it ignores option 121 (Leviathan Security, 2024). It is not listed in KEV.

What this means for you

If you run a VPN gateway:

  • Subscribe to your vendor’s security advisories and to CISA KEV updates; treat KEV listings as patch-now events.
  • Assume compromise when a critical gateway flaw is exploited before disclosure: patch, but also check integrity, reset credentials and revoke sessions.
  • Do not expose management interfaces to the internet, and require phishing-resistant MFA for VPN logins.
  • Plan to retire end-of-support appliances; ED 25-03 required disconnecting them.

If you are an individual:

  • These gateway bugs mostly affect employers rather than personal VPN subscriptions, but a breach at your company’s VPN can expose your work credentials, so use unique passwords and MFA.
  • Keep your personal VPN app and operating system updated, and avoid untrusted Wi-Fi for sensitive work given attacks like TunnelVision.

Methodology

KEV counts come from CISA’s KEV JSON feed (catalog version 2026.09.30, 1,730 entries), filtered by vendor and product for lines that include remote-access VPN gateways. Scores in the main table come from the NVD CVE API 2.0, queried on October 1, 2026: the NVD primary CVSS v3.1 base score, or the vendor or CISA-ADP score where NVD had not scored the CVE. Ransomware status is CISA’s “knownRansomwareCampaignUse” field. Context comes from Verizon’s 2025 DBIR, CISA emergency directives and the TunnelVision disclosure.

KEV lists only vulnerabilities CISA has confirmed as exploited; absence from KEV does not mean a flaw is safe. Our product filter is broad and includes some non-VPN components of the same appliances. CVSS scores change as NVD re-analyzes CVEs. The main table is a curated selection of VPN-related CVEs and leaves out consumer VPN client bugs that lack an independent public record.

Sources

  1. Known Exploited Vulnerabilities Catalog (JSON feed, version 2026.09.30) — Cybersecurity and Infrastructure Security Agency (CISA), 2026-09-30
  2. National Vulnerability Database CVE API 2.0 — NIST, 2026-10-01
  3. 2025 Data Breach Investigations Report — Verizon Business, 2025
  4. ED 24-01: Mitigate Ivanti Connect Secure and Ivanti Policy Secure Vulnerabilities — CISA, 2024-01-19
  5. ED 25-03: Identify and Mitigate Potential Compromise of Cisco Devices — CISA, 2025-09-25
  6. TunnelVision (CVE-2024-3661): How Attackers Can Decloak Routing-Based VPNs — Leviathan Security Group, 2024-05-06
Cite this research: PhantomGuide Research Team, “VPN Vulnerabilities Tracker: Critical CVEs in VPN Products (2019–2026)”, PhantomGuide, 2026-10-01, https://phantomguide.com/research/vpn-vulnerabilities-tracker/

More Research