Brand
Kaseya: actively exploited vulnerabilities
3 vulnerabilities in Kaseya products (VSA) are in CISA’s catalog of exploited vulnerabilities. Last added: May 24, 2022.
-
0 vulnerabilities added in the last 12 months
-
3 exploited vulnerabilities in the catalog, in total
-
0 added in the last 30 days
By category
Add just one Kaseya category to your radar, or open its page.
- Remote monitoring and management (RMM) 3 vulnerabilities
A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.
Affected products
- VSA 3 vulnerabilities · Remote management (RMM)
Name used by CISA: Kaseya. Product families: indicative classification by this site.
Patch first
In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this Kaseya list.
Rank 1Kaseya VSA
CVE-2018-20753RansomwareCVE from 2018, added in 2022
Kaseya VSA Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Apr 13, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 2Kaseya VSA
CVE-2021-30116Ransomware
Kaseya Virtual System/Server Administrator (VSA) Information Disclosure Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 14 days
- CVSS severity
- 9.8 (critical)
End of life: remove
These products are no longer supported: no patch is coming. Remove them or isolate them from the network.
Kaseya VSA
CVE-2017-18362RansomwareEnd of lifeCVE from 2017, added in 2022
Kaseya VSA SQL Injection Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- May 24, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Follow and verify
Indicative classification, based on the vendor and product names given by CISA. How products are classified.