Skip to content
English

Products › Network and edge

Network and edge

Firewalls, VPNs and remote access

Devices that filter traffic and provide remote access to the network: attackers’ first target, because they are exposed to the internet.

For example: FortiGate, PAN-OS, Cisco ASA, SonicWall, Ivanti Connect Secure.

Category RSS feed

Pace of additions

Number of “Firewalls and VPNs” vulnerabilities added to CISA’s KEV catalog, per 30-day period (the last one, still in progress, ends on September 28, 2026). Source: CISA KEV catalog.
Catalog additions per 30-day period
PeriodVulnerabilities added
Sep 4, 2025 to Oct 3, 20253
Oct 4, 2025 to Nov 2, 20250
Nov 3, 2025 to Dec 2, 20251
Dec 3, 2025 to Jan 1, 20264
Jan 2, 2026 to Jan 31, 20261
Feb 1, 2026 to Mar 2, 20260
Mar 3, 2026 to Apr 1, 20261
Apr 2, 2026 to May 1, 20260
May 2, 2026 to May 31, 20262
Jun 1, 2026 to Jun 30, 20261
Jul 1, 2026 to Jul 30, 20265
Jul 31, 2026 to Aug 29, 20261
Aug 30, 2026 to Sep 28, 2026 (in progress)6

Affected brands

In alphabetical order, with their number of vulnerabilities in this category.

  • Array Networks 2 vulnerabilities · 1 in the last 12 months
  • Check Point 5 vulnerabilities · 4 in the last 12 months
  • Cisco 19 vulnerabilities · 4 in the last 12 months
  • FatPipe 1 vulnerability
  • Fortinet 21 vulnerabilities · 4 in the last 12 months
  • Ivanti 14 vulnerabilities
  • Juniper 1 vulnerability · 1 in the last 12 months
  • Microsoft 1 vulnerability
  • Palo Alto Networks 15 vulnerabilities · 2 in the last 12 months
  • SonicWall 16 vulnerabilities · 5 in the last 12 months
  • Sophos 6 vulnerabilities
  • WatchGuard 4 vulnerabilities · 2 in the last 12 months
  • Zyxel 6 vulnerabilities

A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.

See also

Patch first

In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this category.

  1. Rank 1Check Point Quantum Security Gateway

    CVE-2026-85102

    Recently addedHunt for compromise (CISA)

    Check Point Multiple Products Improper Certificate Validation Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 22, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  2. Rank 2Check Point Security Management / SmartConsole

    CVE-2026-93616

    Recently addedHunt for compromise (CISA)

    Check Point Multiple Products Path Traversal Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 22, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  3. Rank 3Cisco Secure Firewall Management Center (FMC)

    CVE-2026-20079

    Recently addedHunt for compromise (CISA)

    Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 9, 2026
    CISA deadline
    3 days
    CVSS severity
    10.0 (critical)
  4. Rank 4Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2025-25249

    Recently addedHunt for compromise (CISA)

    Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 9, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  5. Rank 5SonicWall SMA 1000

    CVE-2026-83548

    Recently addedActive CERT-FR alertHunt for compromise (CISA)

    SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 2, 2026
    CISA deadline
    3 days
    CVSS severity
    10.0 (critical)
  6. Rank 6SonicWall SMA 1000

    CVE-2026-83549

    Recently addedActive CERT-FR alertHunt for compromise (CISA)

    SonicWall SMA1000 Appliances OS Command Injection Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 2, 2026
    CISA deadline
    3 days
    CVSS severity
    7.8 (high)
  7. Rank 7SonicWall SMA 1000

    CVE-2026-15409

    Hunt for compromise (CISA)Ransomware

    SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 14, 2026
    CISA deadline
    3 days
    CVSS severity
    10.0 (critical)
  8. Rank 8Cisco Secure Firewall Management Center (FMC)

    CVE-2026-20131

    Ransomware

    Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Mar 19, 2026
    CISA deadline
    3 days
    CVSS severity
    10.0 (critical)
  9. Rank 9Check Point Security Management / SmartConsole

    CVE-2026-16232

    Hunt for compromise (CISA)

    Check Point SmartConsole Improper Authentication Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 22, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  10. Rank 10Palo Alto Networks PAN-OS / GlobalProtect

    CVE-2026-0300

    Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    May 6, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
Show 99 more vulnerabilities
  1. Rank 11Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2026-24858

    Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jan 27, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  2. Rank 12WatchGuard Firebox / XTM (Fireware)

    CVE-2025-14733

    Ransomware

    WatchGuard Firebox Out of Bounds Write Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Dec 19, 2025
    CISA deadline
    7 days
    CVSS severity
    9.8 (critical)
  3. Rank 13Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2025-59718

    Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Dec 16, 2025
    CISA deadline
    7 days
    CVSS severity
    9.8 (critical)
  4. Rank 14Array Networks ArrayOS AG / vxAG

    CVE-2025-66644

    Array Networks ArrayOS AG OS Command Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Dec 8, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  5. Rank 15WatchGuard Firebox / XTM (Fireware)

    CVE-2025-9242

    WatchGuard Firebox Out-of-Bounds Write Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Nov 12, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  6. Rank 16Juniper ScreenOS (NetScreen)

    CVE-2015-7755

    CVE from 2015, added in 2025

    Juniper ScreenOS Improper Authentication Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 2, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  7. Rank 17Check Point Quantum Security Gateway

    CVE-2026-50751

    Ransomware

    Check Point Security Gateway Improper Authentication Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jun 8, 2026
    CISA deadline
    3 days
    CVSS severity
    9.3 (critical)
  8. Rank 18Palo Alto Networks PAN-OS / GlobalProtect

    CVE-2026-0257

    Ransomware

    Palo Alto Networks PAN-OS Authentication Bypass Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    May 29, 2026
    CISA deadline
    3 days
    CVSS severity
    9.1 (critical)
  9. Rank 19Cisco ASA / Firepower (FTD)

    CVE-2026-20349

    Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Aug 11, 2026
    CISA deadline
    3 days
    CVSS severity
    8.6 (high)
  10. Rank 20SonicWall SMA 1000

    CVE-2026-15410

    Hunt for compromise (CISA)Ransomware

    SonicWall SMA1000 Appliances Code Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 14, 2026
    CISA deadline
    3 days
    CVSS severity
    7.2 (high)
  11. Rank 21SonicWall SMA 1000

    CVE-2025-40602

    SonicWall SMA1000 Missing Authorization Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Dec 17, 2025
    CISA deadline
    7 days
    CVSS severity
    6.6 (medium)
  12. Rank 22Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2025-68686

    Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 27, 2026
    CISA deadline
    14 days
    CVSS severity
    5.9 (medium)
  13. Rank 23Cisco Secure Firewall Management Center (FMC)

    CVE-2026-20316

    Ransomware

    Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 29, 2026
    CISA deadline
    3 days
    CVSS severity
    5.3 (medium)
  14. Rank 24Palo Alto Networks PAN-OS / GlobalProtect

    CVE-2024-3400

    Ransomware

    Palo Alto Networks PAN-OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 12, 2024
    CISA deadline
    7 days
    CVSS severity
    10.0 (critical)
  15. Rank 25Palo Alto Networks PAN-OS / GlobalProtect

    CVE-2020-2021

    RansomwareCVE from 2020, added in 2022

    Palo Alto Networks PAN-OS Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    10.0 (critical)
  16. Rank 26Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)

    CVE-2019-11510

    RansomwareCVE from 2019, added in 2021

    Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    10.0 (critical)
  17. Rank 27Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)

    CVE-2021-22893

    Ransomware

    Ivanti Pulse Connect Secure Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    10.0 (critical)
  18. Rank 28Cisco ASA / Firepower (FTD)

    CVE-2025-20333

    Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 25, 2025
    CISA deadline
    1 day
    CVSS severity
    9.9 (critical)
  19. Rank 29Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)

    CVE-2025-22457

    Ransomware

    Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 4, 2025
    CISA deadline
    7 days
    CVSS severity
    9.8 (critical)
  20. Rank 30SonicWall SonicOS

    CVE-2024-53704

    Ransomware

    SonicWall SonicOS SSLVPN Improper Authentication Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 18, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  21. Rank 31Sophos Firewall (SFOS, ex-XG)

    CVE-2020-15069

    CVE from 2020, added in 2025

    Sophos XG Firewall Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 6, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  22. Rank 32SonicWall SMA 1000

    CVE-2025-23006

    Ransomware

    SonicWall SMA1000 Appliances Deserialization Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 24, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  23. Rank 33Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2024-55591

    Ransomware

    Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 14, 2025
    CISA deadline
    7 days
    CVSS severity
    9.8 (critical)
  24. Rank 34Zyxel Firewalls (ATP, USG FLEX, ZyWALL/USG)

    CVE-2024-11667

    Ransomware

    Zyxel Multiple Firewalls Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 3, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  25. Rank 35Array Networks ArrayOS AG / vxAG

    CVE-2023-28461

    Ransomware

    Array Networks AG and vxAG ArrayOS Missing Authentication for Critical Function Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 25, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  26. Rank 36Palo Alto Networks PAN-OS / GlobalProtect

    CVE-2024-0012

    Ransomware

    Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 18, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  27. Rank 37Palo Alto Networks Expedition

    CVE-2024-5910

    Palo Alto Networks Expedition Missing Authentication Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 7, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  28. Rank 38Fortinet FortiManager / FortiAnalyzer

    CVE-2024-47575

    Fortinet FortiManager Missing Authentication Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 23, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  29. Rank 39Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2024-23113

    Fortinet Multiple Products Format String Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 9, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  30. Rank 40SonicWall SonicOS

    CVE-2024-40766

    Ransomware

    SonicWall SonicOS Improper Access Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 9, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  31. Rank 41Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2024-21762

    Ransomware

    Fortinet FortiOS Out-of-Bound Write Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 9, 2024
    CISA deadline
    7 days
    CVSS severity
    9.8 (critical)
  32. Rank 42Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2023-27997

    Ransomware

    Fortinet FortiOS and FortiProxy SSL-VPN Heap-Based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 13, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  33. Rank 43Zyxel Firewalls (ATP, USG FLEX, ZyWALL/USG)

    CVE-2023-33009

    Zyxel Multiple Firewalls Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 5, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  34. Rank 44Zyxel Firewalls (ATP, USG FLEX, ZyWALL/USG)

    CVE-2023-33010

    Zyxel Multiple Firewalls Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 5, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  35. Rank 45Zyxel Firewalls (ATP, USG FLEX, ZyWALL/USG)

    CVE-2023-28771

    Zyxel Multiple Firewalls OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 31, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  36. Rank 46Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2022-42475

    Ransomware

    Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 13, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  37. Rank 47Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2022-40684

    Ransomware

    Fortinet Multiple Products Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 11, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  38. Rank 48Sophos Firewall (SFOS, ex-XG)

    CVE-2022-3236

    Sophos Firewall Code Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 23, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  39. Rank 49Palo Alto Networks PAN-OS / GlobalProtect

    CVE-2017-15944

    CVE from 2017, added in 2022

    Palo Alto Networks PAN-OS Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 18, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  40. Rank 50Zyxel Firewalls (ATP, USG FLEX, ZyWALL/USG)

    CVE-2022-30525

    Zyxel Multiple Firewalls OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 16, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  41. Rank 51Sophos Firewall (SFOS, ex-XG)

    CVE-2022-1040

    Sophos Firewall Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 31, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  42. Rank 52Sophos SG UTM

    CVE-2020-25223

    CVE from 2020, added in 2022

    Sophos SG UTM Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  43. Rank 53WatchGuard Firebox / XTM (Fireware)

    CVE-2022-26318

    WatchGuard Firebox and XTM Appliances Arbitrary Code Execution

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  44. Rank 54SonicWall SonicOS

    CVE-2020-5135

    RansomwareCVE from 2020, added in 2022

    SonicWall SonicOS Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 15, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  45. Rank 55Microsoft Forefront TMG

    CVE-2011-1889

    CVE from 2011, added in 2022

    Microsoft Forefront TMG Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  46. Rank 56SonicWall SMA 100 (ex-SRA)

    CVE-2021-20038

    Ransomware

    SonicWall SMA 100 Appliances Stack-Based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 28, 2022
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  47. Rank 57Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2018-13379

    RansomwareCVE from 2018, added in 2021

    Fortinet FortiOS SSL VPN Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  48. Rank 58Sophos Firewall (SFOS, ex-XG)

    CVE-2020-12271

    Ransomware

    Sophos SFOS SQL Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  49. Rank 59Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2020-12812

    Ransomware

    Fortinet FortiOS SSL VPN Improper Authentication Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  50. Rank 60Zyxel Firewalls (ATP, USG FLEX, ZyWALL/USG)

    CVE-2020-29583

    Zyxel Multiple Products Use of Hard-Coded Credentials Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  51. Rank 61SonicWall SMA 100 (ex-SRA)

    CVE-2021-20016

    Ransomware

    SonicWall SSLVPN SMA100 SQL Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  52. Rank 62Palo Alto Networks PAN-OS / GlobalProtect

    CVE-2025-0108

    Palo Alto Networks PAN-OS Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 18, 2025
    CISA deadline
    21 days
    CVSS severity
    9.1 (critical)
  53. Rank 63Palo Alto Networks Expedition

    CVE-2024-9465

    Palo Alto Networks Expedition SQL Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 14, 2024
    CISA deadline
    21 days
    CVSS severity
    9.1 (critical)
  54. Rank 64Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)

    CVE-2024-21887

    Ransomware

    Ivanti Connect Secure and Policy Secure Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 10, 2024
    CISA deadline
    12 days
    CVSS severity
    9.1 (critical)
  55. Rank 65Cisco ASA / Firepower (FTD)

    CVE-2023-20269

    Ransomware

    Cisco Adaptive Security Appliance and Firepower Threat Defense Unauthorized Access Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 13, 2023
    CISA deadline
    21 days
    CVSS severity
    9.1 (critical)
  56. Rank 66Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)

    CVE-2025-0282

    Ransomware

    Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 8, 2025
    CISA deadline
    7 days
    CVSS severity
    9.0 (critical)
  57. Rank 67Cisco ASA / Firepower (FTD)

    CVE-2016-6366

    CVE from 2016, added in 2022

    Cisco Adaptive Security Appliance (ASA) SNMP Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 24, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  58. Rank 68WatchGuard Firebox / XTM (Fireware)

    CVE-2022-23176

    WatchGuard Firebox and XTM Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 11, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  59. Rank 69FatPipe WARP, IPVPN, and MPVPN software

    CVE-2021-27860

    FatPipe WARP, IPVPN, and MPVPN Configuration Upload exploit

    Added more than a year ago: ranked by severity.

    Added
    Jan 10, 2022
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  60. Rank 70Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)

    CVE-2021-22894

    Ivanti Pulse Connect Secure Collaboration Suite Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  61. Rank 71Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)

    CVE-2021-22899

    Ivanti Pulse Connect Secure Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  62. Rank 72Cisco ASA / Firepower (FTD)

    CVE-2025-20362

    Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Missing Authorization Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 25, 2025
    CISA deadline
    1 day
    CVSS severity
    8.6 (high)
  63. Rank 73Check Point Quantum Security Gateway

    CVE-2024-24919

    Ransomware

    Check Point Quantum Security Gateways Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 30, 2024
    CISA deadline
    21 days
    CVSS severity
    8.6 (high)
  64. Rank 74Cisco ASA / Firepower (FTD)

    CVE-2024-20353

    Cisco ASA and FTD Denial of Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 24, 2024
    CISA deadline
    7 days
    CVSS severity
    8.6 (high)
  65. Rank 75Palo Alto Networks PAN-OS / GlobalProtect

    CVE-2022-0028

    Palo Alto Networks PAN-OS Reflected Amplification Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 22, 2022
    CISA deadline
    21 days
    CVSS severity
    8.6 (high)
  66. Rank 76Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)

    CVE-2024-21893

    Ransomware

    Ivanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 31, 2024
    CISA deadline
    2 days
    CVSS severity
    8.2 (high)
  67. Rank 77Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)

    CVE-2023-46805

    Ransomware

    Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 10, 2024
    CISA deadline
    12 days
    CVSS severity
    8.2 (high)
  68. Rank 78Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2025-24472

    Ransomware

    Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 18, 2025
    CISA deadline
    21 days
    CVSS severity
    8.1 (high)
  69. Rank 79Palo Alto Networks PAN-OS / GlobalProtect

    CVE-2019-1579

    RansomwareCVE from 2019, added in 2022

    Palo Alto Networks PAN-OS Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 10, 2022
    CISA deadline
    181 days
    CVSS severity
    8.1 (high)
  70. Rank 80Cisco AnyConnect Secure Mobility Client

    CVE-2020-3433

    RansomwareCVE from 2020, added in 2022

    Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 24, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  71. Rank 81Cisco ASA / Firepower (FTD)

    CVE-2016-6367

    CVE from 2016, added in 2022

    Cisco Adaptive Security Appliance (ASA) CLI Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 24, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  72. Rank 82Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2021-44168

    Fortinet FortiOS Arbitrary File Download

    Added more than a year ago: ranked by severity.

    Added
    Dec 10, 2021
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  73. Rank 83Palo Alto Networks PAN-OS / GlobalProtect

    CVE-2024-3393

    Palo Alto Networks PAN-OS Malicious DNS Packet Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 30, 2024
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  74. Rank 84Palo Alto Networks Expedition

    CVE-2024-9463

    Palo Alto Networks Expedition OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 14, 2024
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  75. Rank 85Cisco ASA / Firepower (FTD)

    CVE-2020-3259

    RansomwareCVE from 2020, added in 2024

    Cisco ASA and FTD Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 15, 2024
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  76. Rank 86SonicWall SMA 100 (ex-SRA)

    CVE-2019-7483

    CVE from 2019, added in 2022

    SonicWall SMA100 Directory Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  77. Rank 87Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2018-13382

    RansomwareCVE from 2018, added in 2022

    Fortinet FortiOS and FortiProxy Improper Authorization

    Added more than a year ago: ranked by severity.

    Added
    Jan 10, 2022
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  78. Rank 88Cisco ASA / Firepower (FTD)

    CVE-2018-0296

    CVE from 2018, added in 2021

    Cisco Adaptive Security Appliance (ASA) Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  79. Rank 89SonicWall SMA 100 (ex-SRA)

    CVE-2019-7481

    RansomwareCVE from 2019, added in 2021

    SonicWall SMA100 SQL Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  80. Rank 90Cisco ASA / Firepower (FTD)

    CVE-2020-3452

    Cisco ASA and FTD Read-Only Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  81. Rank 91SonicWall SMA 100 (ex-SRA)

    CVE-2023-44221

    CVE from 2023, added in 2025

    SonicWall SMA100 Appliances OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 1, 2025
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  82. Rank 92Palo Alto Networks PAN-OS / GlobalProtect

    CVE-2024-9474

    Ransomware

    Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 18, 2024
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  83. Rank 93Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)

    CVE-2020-8218

    CVE from 2020, added in 2022

    Pulse Connect Secure Code Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 7, 2022
    CISA deadline
    184 days
    CVSS severity
    7.2 (high)
  84. Rank 94Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)

    CVE-2019-11539

    RansomwareCVE from 2019, added in 2021

    Ivanti Pulse Connect Secure and Policy Secure Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.2 (high)
  85. Rank 95Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)

    CVE-2020-8243

    Ivanti Pulse Connect Secure Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.2 (high)
  86. Rank 96Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)

    CVE-2020-8260

    Ivanti Pulse Connect Secure Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.2 (high)
  87. Rank 97Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)

    CVE-2021-22900

    Ivanti Pulse Connect Secure Unrestricted File Upload Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.2 (high)
  88. Rank 98Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2022-41328

    Fortinet FortiOS Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 14, 2023
    CISA deadline
    21 days
    CVSS severity
    7.1 (high)
  89. Rank 99Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2019-6693

    RansomwareCVE from 2019, added in 2025

    Fortinet FortiOS Use of Hard-Coded Credentials Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 25, 2025
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  90. Rank 100SonicWall SMA 100 (ex-SRA)

    CVE-2021-20035

    CVE from 2021, added in 2025

    SonicWall SMA100 Appliances OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 16, 2025
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  91. Rank 101Palo Alto Networks PAN-OS / GlobalProtect

    CVE-2025-0111

    Palo Alto Networks PAN-OS File Read Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 20, 2025
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  92. Rank 102Cisco AnyConnect Secure Mobility Client

    CVE-2020-3153

    RansomwareCVE from 2020, added in 2022

    Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 24, 2022
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  93. Rank 103Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2018-13383

    RansomwareCVE from 2018, added in 2022

    Fortinet FortiOS and FortiProxy Out-of-bounds Write

    Added more than a year ago: ranked by severity.

    Added
    Jan 10, 2022
    CISA deadline
    181 days
    CVSS severity
    6.5 (medium)
  94. Rank 104Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2019-5591

    RansomwareCVE from 2019, added in 2021

    Fortinet FortiOS Default Configuration Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    6.5 (medium)
  95. Rank 105Cisco ASA / Firepower (FTD)

    CVE-2014-2120

    CVE from 2014, added in 2024

    Cisco Adaptive Security Appliance (ASA) Cross-Site Scripting (XSS) Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 12, 2024
    CISA deadline
    21 days
    CVSS severity
    6.1 (medium)
  96. Rank 106Cisco ASA / Firepower (FTD)

    CVE-2020-3580

    Ransomware

    Cisco ASA and FTD Cross-Site Scripting (XSS) Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    6.1 (medium)
  97. Rank 107Cisco ASA / Firepower (FTD)

    CVE-2024-20359

    Cisco ASA and FTD Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 24, 2024
    CISA deadline
    7 days
    CVSS severity
    6.0 (medium)
  98. Rank 108Cisco ASA / Firepower (FTD)

    CVE-2024-20481

    Cisco ASA and FTD Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 24, 2024
    CISA deadline
    21 days
    CVSS severity
    5.8 (medium)
  99. Rank 109Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2018-13374

    RansomwareCVE from 2018, added in 2022

    Fortinet FortiOS and FortiADC Improper Access Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 8, 2022
    CISA deadline
    21 days
    CVSS severity
    4.3 (medium)

Filed under another category

These 23 vulnerabilities also concern this type of product, but are counted in their main category. My radar finds them when you follow this category.

  1. Citrix NetScaler ADC / Gateway

    CVE-2026-88771

    Recently addedActive CERT-FR alertHunt for compromise (CISA)

    Citrix NetScaler Improper Input Validation Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 27, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  2. Citrix NetScaler ADC / Gateway

    CVE-2026-88772

    Recently addedActive CERT-FR alertHunt for compromise (CISA)

    Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 27, 2026
    CISA deadline
    3 days
    CVSS severity
    8.1 (high)
  3. F5 BIG-IP

    CVE-2026-94127

    Recently addedHunt for compromise (CISA)

    F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 22, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  4. Citrix NetScaler ADC / Gateway

    CVE-2026-19490

    Recently addedHunt for compromise (CISA)

    Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 9, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  5. Citrix NetScaler ADC / Gateway

    CVE-2026-8452

    Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Aug 26, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
Show 18 more vulnerabilities
  1. Citrix NetScaler ADC / Gateway

    CVE-2026-3055

    Citrix NetScaler Out-of-Bounds Read Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Mar 30, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  2. F5 BIG-IP

    CVE-2025-53521

    F5 BIG-IP Stack-Based Buffer Overflow Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Mar 27, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  3. Citrix NetScaler ADC / Gateway

    CVE-2025-7775

    Citrix NetScaler Memory Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 26, 2025
    CISA deadline
    2 days
    CVSS severity
    9.8 (critical)
  4. Citrix NetScaler ADC / Gateway

    CVE-2025-6543

    Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 30, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  5. Juniper Junos OS

    CVE-2023-36845

    Juniper Junos OS EX Series and SRX Series PHP External Variable Modification Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 13, 2023
    CISA deadline
    4 days
    CVSS severity
    9.8 (critical)
  6. Citrix NetScaler ADC / Gateway

    CVE-2023-3519

    Ransomware

    Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 19, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  7. Citrix NetScaler ADC / Gateway

    CVE-2022-27518

    Citrix Application Delivery Controller (ADC) and Gateway Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 13, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  8. Juniper Junos OS

    CVE-2020-1631

    CVE from 2020, added in 2022

    Juniper Junos OS Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  9. Citrix NetScaler ADC / Gateway

    CVE-2019-19781

    RansomwareCVE from 2019, added in 2021

    Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  10. Citrix NetScaler ADC / Gateway

    CVE-2023-6548

    Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 17, 2024
    CISA deadline
    7 days
    CVSS severity
    8.8 (high)
  11. Citrix NetScaler ADC / Gateway

    CVE-2025-5777

    Ransomware

    Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 10, 2025
    CISA deadline
    1 day
    CVSS severity
    7.5 (high)
  12. Citrix NetScaler ADC / Gateway

    CVE-2023-6549

    Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 17, 2024
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  13. Citrix NetScaler ADC / Gateway

    CVE-2023-4966

    Ransomware

    Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 18, 2023
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  14. Citrix NetScaler ADC / Gateway

    CVE-2020-8193

    Citrix ADC, Gateway, and SD-WAN WANOP Appliance Authorization Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    6.5 (medium)
  15. Citrix NetScaler ADC / Gateway

    CVE-2020-8195

    Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    6.5 (medium)
  16. Juniper Junos OS

    CVE-2023-36846

    Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 13, 2023
    CISA deadline
    4 days
    CVSS severity
    5.3 (medium)
  17. Juniper Junos OS

    CVE-2023-36851

    Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 13, 2023
    CISA deadline
    4 days
    CVSS severity
    5.3 (medium)
  18. Citrix NetScaler ADC / Gateway

    CVE-2020-8196

    Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    4.3 (medium)

End of life: remove

These products are no longer supported: no patch is coming. Remove them or isolate them from the network.

  1. Sophos CyberoamOS (Cyberoam)

    CVE-2020-29574

    RansomwareEnd of lifeCVE from 2020, added in 2025

    CyberoamOS (CROS) SQL Injection Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Feb 6, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  2. SonicWall SMA 100 (ex-SRA)

    CVE-2021-20028

    RansomwareEnd of life

    SonicWall Secure Remote Access (SRA) SQL Injection Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)

Follow and verify

Get new vulnerabilities in this category: RSS feed (add it to Outlook, Teams, Slack or your feed reader).

Indicative classification, based on the vendor and product names given by CISA. How products are classified.