Brand
Samsung: actively exploited vulnerabilities
15 vulnerabilities in Samsung products (Mobile Devices (Galaxy), MagicINFO Server) are in CISA’s catalog of exploited vulnerabilities. Last added: April 24, 2026.
The brand’s general security advisories page, not the advisory for a specific vulnerability (address checked September 28, 2026).
-
3 vulnerabilities added in the last 12 months
-
15 exploited vulnerabilities in the catalog, in total
-
0 added in the last 30 days
By category
Add just one Samsung category to your radar, or open its page.
- Phones, tablets and chipsets 13 vulnerabilities
- ERP, business applications and databases 2 vulnerabilities
A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.
Affected products
- Mobile Devices (Galaxy) 13 vulnerabilities · Phones and tablets
- MagicINFO Server 2 vulnerabilities · Business apps and data
Name used by CISA: Samsung. Product families: indicative classification by this site.
Patch first
In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this Samsung list.
Rank 1Samsung MagicINFO Server
CVE-2024-7399CVE from 2024, added in 2026
Samsung MagicINFO 9 Server Path Traversal Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Apr 24, 2026
- CISA deadline
- 14 days
- CVSS severity
- 9.8 (critical)
Rank 2Samsung Mobile Devices (Galaxy)
CVE-2025-21042Samsung Mobile Devices Out-of-Bounds Write Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Nov 10, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 3Samsung Mobile Devices (Galaxy)
CVE-2025-21043Samsung Mobile Devices Out-of-Bounds Write Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Oct 2, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 4Samsung MagicINFO Server
CVE-2025-4632Samsung MagicINFO 9 Server Path Traversal Vulnerability
Added more than a year ago: ranked by severity.
- Added
- May 22, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 5Samsung Mobile Devices (Galaxy)
CVE-2022-22265Samsung Mobile Devices Use-After-Free Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Sep 18, 2023
- CISA deadline
- 21 days
- CVSS severity
- 7.8 (high)
Rank 6Samsung Mobile Devices (Galaxy)
CVE-2021-25487CVE from 2021, added in 2023
Samsung Mobile Devices Out-of-Bounds Read Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jun 29, 2023
- CISA deadline
- 21 days
- CVSS severity
- 7.8 (high)
Rank 7Samsung Mobile Devices (Galaxy)
CVE-2021-25337Samsung Mobile Devices Improper Access Control Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 8, 2022
- CISA deadline
- 21 days
- CVSS severity
- 7.1 (high)
Rank 8Samsung Mobile Devices (Galaxy)
CVE-2021-25371CVE from 2021, added in 2023
Samsung Mobile Devices Unspecified Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jun 29, 2023
- CISA deadline
- 21 days
- CVSS severity
- 6.7 (medium)
Rank 9Samsung Mobile Devices (Galaxy)
CVE-2021-25372CVE from 2021, added in 2023
Samsung Mobile Devices Improper Boundary Check Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jun 29, 2023
- CISA deadline
- 21 days
- CVSS severity
- 6.7 (medium)
Rank 10Samsung Mobile Devices (Galaxy)
CVE-2021-25394CVE from 2021, added in 2023
Samsung Mobile Devices Race Condition Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jun 29, 2023
- CISA deadline
- 21 days
- CVSS severity
- 6.4 (medium)
Show 5 more vulnerabilities
Rank 11Samsung Mobile Devices (Galaxy)
CVE-2021-25395CVE from 2021, added in 2023
Samsung Mobile Devices Race Condition Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jun 29, 2023
- CISA deadline
- 21 days
- CVSS severity
- 6.4 (medium)
Rank 12Samsung Mobile Devices (Galaxy)
CVE-2021-25489CVE from 2021, added in 2023
Samsung Mobile Devices Improper Input Validation Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jun 29, 2023
- CISA deadline
- 21 days
- CVSS severity
- 5.5 (medium)
Rank 13Samsung Mobile Devices (Galaxy)
CVE-2021-25369Samsung Mobile Devices Improper Access Control Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 8, 2022
- CISA deadline
- 21 days
- CVSS severity
- 5.5 (medium)
Rank 14Samsung Mobile Devices (Galaxy)
CVE-2023-21492Samsung Mobile Devices Insertion of Sensitive Information Into Log File Vulnerability
Added more than a year ago: ranked by severity.
- Added
- May 19, 2023
- CISA deadline
- 21 days
- CVSS severity
- 4.4 (medium)
Rank 15Samsung Mobile Devices (Galaxy)
CVE-2021-25370Samsung Mobile Devices Memory Corruption Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 8, 2022
- CISA deadline
- 21 days
- CVSS severity
- 4.4 (medium)
Follow and verify
Get new Samsung vulnerabilities: RSS feed (add it to Outlook, Teams, Slack or your feed reader).
Indicative classification, based on the vendor and product names given by CISA. How products are classified.