Skip to content

Products › Server applications and development

Server applications and development

Web and application servers

Web servers, application servers and hosting control panels.

For example: IIS, Apache Tomcat, Oracle WebLogic, ColdFusion.

Category RSS feed

Pace of additions

Number of “Web servers” vulnerabilities added to CISA’s KEV catalog, per 30-day period (the last one, still in progress, ends on September 28, 2026). Source: CISA KEV catalog.
Catalog additions per 30-day period
PeriodVulnerabilities added
Sep 4, 2025 to Oct 3, 20250
Oct 4, 2025 to Nov 2, 20250
Nov 3, 2025 to Dec 2, 20251
Dec 3, 2025 to Jan 1, 20260
Jan 2, 2026 to Jan 31, 20260
Feb 1, 2026 to Mar 2, 20260
Mar 3, 2026 to Apr 1, 20260
Apr 2, 2026 to May 1, 20262
May 2, 2026 to May 31, 20261
Jun 1, 2026 to Jun 30, 20262
Jul 1, 2026 to Jul 30, 20261
Jul 31, 2026 to Aug 29, 20262
Aug 30, 2026 to Sep 28, 2026 (in progress)1

Affected brands

In alphabetical order, with their number of vulnerabilities in this category.

A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.

See also

Patch first

In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this category.

  1. Rank 1WSO2 API Manager, Identity Server, Integrator

    CVE-2026-5430

    Recently addedHunt for compromise (CISA)

    WSO2 Multiple Products Path Traversal Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 24, 2026
    CISA deadline
    3 days
    CVSS severity
    10.0 (critical)
  2. Rank 2Oracle WebLogic Server

    CVE-2026-21962

    Hunt for compromise (CISA)

    Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Aug 24, 2026
    CISA deadline
    3 days
    CVSS severity
    10.0 (critical)
  3. Rank 3Adobe ColdFusion

    CVE-2026-48282

    Hunt for compromise (CISA)

    Adobe ColdFusion Path Traversal Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 7, 2026
    CISA deadline
    3 days
    CVSS severity
    10.0 (critical)
  4. Rank 4LiteSpeed cPanel Plugin

    CVE-2026-48172

    LiteSpeed cPanel Plugin Privilege Escalation Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    May 26, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  5. Rank 5cPanel (WebPros) cPanel & WHM (WP Squared)

    CVE-2026-41940

    Ransomware

    WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 30, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  6. Rank 6CWP (Control Web Panel / CentOS Web Panel) Control Web Panel

    CVE-2025-48703

    CWP Control Web Panel OS Command Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Nov 4, 2025
    CISA deadline
    21 days
    CVSS severity
    9.0 (critical)
  7. Rank 7Apache ActiveMQ

    CVE-2026-34197

    Apache ActiveMQ Improper Input Validation Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 16, 2026
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  8. Rank 8LiteSpeed cPanel Plugin

    CVE-2026-54420

    LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jun 15, 2026
    CISA deadline
    3 days
    CVSS severity
    8.5 (high)
  9. Rank 9Apache Tomcat

    CVE-2026-34486

    Apache Tomcat Missing Encryption of Sensitive Data Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Aug 4, 2026
    CISA deadline
    3 days
    CVSS severity
    7.5 (high)
  10. Rank 10Oracle WebLogic Server

    CVE-2024-21182

    CVE from 2024, added in 2026

    Oracle WebLogic Server Unspecified Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jun 1, 2026
    CISA deadline
    3 days
    CVSS severity
    7.5 (high)
Show 57 more vulnerabilities
  1. Rank 11Apache Tomcat

    CVE-2025-24813

    Apache Tomcat Path Equivalence Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 1, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  2. Rank 12Adobe ColdFusion

    CVE-2017-3066

    CVE from 2017, added in 2025

    Adobe ColdFusion Deserialization Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 24, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  3. Rank 13Oracle WebLogic Server

    CVE-2020-2883

    CVE from 2020, added in 2025

    Oracle WebLogic Server Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 7, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  4. Rank 14CyberPanel (CyberPersons) CyberPanel

    CVE-2024-51378

    Ransomware

    CyberPanel Incorrect Default Permissions Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 4, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  5. Rank 15Nostromo nhttpd

    CVE-2019-16278

    CVE from 2019, added in 2024

    Nostromo nhttpd Directory Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 7, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  6. Rank 16CyberPanel (CyberPersons) CyberPanel

    CVE-2024-51567

    Ransomware

    CyberPanel Incorrect Default Permissions Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 7, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  7. Rank 17Oracle WebLogic Server

    CVE-2020-14644

    CVE from 2020, added in 2024

    Oracle WebLogic Server Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 18, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  8. Rank 18Adobe ColdFusion

    CVE-2023-29300

    Ransomware

    Adobe ColdFusion Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 8, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  9. Rank 19Adobe ColdFusion

    CVE-2023-38203

    Ransomware

    Adobe ColdFusion Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 8, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  10. Rank 20Oracle WebLogic Server

    CVE-2020-2551

    CVE from 2020, added in 2023

    Oracle Fusion Middleware Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 16, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  11. Rank 21Apache ActiveMQ

    CVE-2023-46604

    Ransomware

    Apache ActiveMQ Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 2, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  12. Rank 22Apache RocketMQ

    CVE-2023-33246

    Apache RocketMQ Command Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 6, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  13. Rank 23Adobe ColdFusion

    CVE-2023-26359

    Adobe ColdFusion Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 21, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  14. Rank 24Apache Tomcat

    CVE-2016-8735

    CVE from 2016, added in 2023

    Apache Tomcat Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 12, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  15. Rank 25Adobe ColdFusion

    CVE-2023-26360

    Adobe ColdFusion Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 15, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  16. Rank 26CWP (Control Web Panel / CentOS Web Panel) Control Web Panel

    CVE-2022-44877

    CWP Control Web Panel OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 17, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  17. Rank 27Oracle WebLogic Server

    CVE-2018-2628

    CVE from 2018, added in 2022

    Oracle WebLogic Server Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 8, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  18. Rank 28Apache APISIX

    CVE-2022-24112

    Apache APISIX Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  19. Rank 29Oracle Fusion Middleware

    CVE-2012-1710

    RansomwareCVE from 2012, added in 2022

    Oracle Fusion Middleware Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  20. Rank 30WSO2 API Manager, Identity Server, Integrator

    CVE-2022-29464

    Ransomware

    WSO2 Multiple Products Unrestrictive Upload of File Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  21. Rank 31Adobe ColdFusion

    CVE-2010-2861

    RansomwareCVE from 2010, added in 2022

    Adobe ColdFusion Directory Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  22. Rank 32Webmin

    CVE-2019-15107

    RansomwareCVE from 2019, added in 2022

    Webmin Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  23. Rank 33Adobe ColdFusion

    CVE-2013-0625

    CVE from 2013, added in 2022

    Adobe ColdFusion Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 7, 2022
    CISA deadline
    184 days
    CVSS severity
    9.8 (critical)
  24. Rank 34Adobe ColdFusion

    CVE-2013-0632

    CVE from 2013, added in 2022

    Adobe ColdFusion Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  25. Rank 35Apache Tomcat

    CVE-2020-1938

    CVE from 2020, added in 2022

    Apache Tomcat Improper Privilege Management Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  26. Rank 36Apache ActiveMQ

    CVE-2016-3088

    CVE from 2016, added in 2022

    Apache ActiveMQ Improper Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 10, 2022
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  27. Rank 37IBM WebSphere Application Server

    CVE-2015-7450

    CVE from 2015, added in 2022

    IBM WebSphere Application Server and Server Hypervisor Edition Code Injection.

    Added more than a year ago: ranked by severity.

    Added
    Jan 10, 2022
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  28. Rank 38Oracle WebLogic Server

    CVE-2019-2725

    RansomwareCVE from 2019, added in 2022

    Oracle WebLogic Server, Injection

    Added more than a year ago: ranked by severity.

    Added
    Jan 10, 2022
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  29. Rank 39Red Hat JBoss Application Server / EAP

    CVE-2017-12149

    RansomwareCVE from 2017, added in 2021

    Red Hat JBoss Application Server Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 10, 2021
    CISA deadline
    182 days
    CVSS severity
    9.8 (critical)
  30. Rank 40Oracle WebLogic Server

    CVE-2015-4852

    CVE from 2015, added in 2021

    Oracle WebLogic Server Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  31. Rank 41Microsoft IIS

    CVE-2017-7269

    CVE from 2017, added in 2021

    Microsoft Windows Server Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  32. Rank 42Adobe ColdFusion

    CVE-2018-15961

    CVE from 2018, added in 2021

    Adobe ColdFusion Unrestricted File Upload Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  33. Rank 43Adobe ColdFusion

    CVE-2018-4939

    CVE from 2018, added in 2021

    Adobe ColdFusion Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  34. Rank 44Oracle WebLogic Server

    CVE-2020-14750

    Oracle WebLogic Server Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  35. Rank 45Oracle WebLogic Server

    CVE-2020-14882

    Oracle WebLogic Server Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  36. Rank 46Oracle Coherence

    CVE-2020-2555

    Oracle Multiple Products Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  37. Rank 47Apache HTTP Server

    CVE-2021-41773

    Ransomware

    Apache HTTP Server Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  38. Rank 48Apache HTTP Server

    CVE-2021-42013

    Ransomware

    Apache HTTP Server Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  39. Rank 49Apache HTTP Server

    CVE-2024-38475

    Apache HTTP Server Improper Escaping of Output Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 1, 2025
    CISA deadline
    21 days
    CVSS severity
    9.1 (critical)
  40. Rank 50Oracle Fusion Middleware

    CVE-2012-3152

    CVE from 2012, added in 2021

    Oracle Fusion Middleware Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.1 (critical)
  41. Rank 51Apache HTTP Server

    CVE-2021-40438

    Ransomware

    Apache HTTP Server-Side Request Forgery (SSRF)

    Added more than a year ago: ranked by severity.

    Added
    Dec 1, 2021
    CISA deadline
    14 days
    CVSS severity
    9.0 (critical)
  42. Rank 52Apache Tomcat

    CVE-2017-12615

    RansomwareCVE from 2017, added in 2022

    Apache Tomcat on Windows Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.1 (high)
  43. Rank 53Apache Tomcat

    CVE-2017-12617

    CVE from 2017, added in 2022

    Apache Tomcat Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.1 (high)
  44. Rank 54Embedthis GoAhead

    CVE-2017-17562

    CVE from 2017, added in 2021

    Embedthis GoAhead Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 10, 2021
    CISA deadline
    182 days
    CVSS severity
    8.1 (high)
  45. Rank 55Apache HTTP Server

    CVE-2019-0211

    CVE from 2019, added in 2021

    Apache HTTP Server Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  46. Rank 56Protocoles (IETF) HTTP/2

    CVE-2023-44487

    HTTP/2 Rapid Reset Attack Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 10, 2023
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  47. Rank 57Adobe ColdFusion

    CVE-2023-29298

    Adobe ColdFusion Improper Access Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 20, 2023
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  48. Rank 58Adobe ColdFusion

    CVE-2023-38205

    Adobe ColdFusion Improper Access Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 20, 2023
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  49. Rank 59Oracle WebLogic Server

    CVE-2023-21839

    Oracle WebLogic Server Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 1, 2023
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  50. Rank 60Red Hat JBoss Application Server / EAP

    CVE-2010-1428

    RansomwareCVE from 2010, added in 2022

    Red Hat JBoss Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  51. Rank 61Adobe ColdFusion

    CVE-2013-0629

    CVE from 2013, added in 2022

    Adobe ColdFusion Directory Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 7, 2022
    CISA deadline
    184 days
    CVSS severity
    7.5 (high)
  52. Rank 62Adobe ColdFusion

    CVE-2013-0631

    CVE from 2013, added in 2022

    Adobe ColdFusion Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 7, 2022
    CISA deadline
    184 days
    CVSS severity
    7.5 (high)
  53. Rank 63Oracle WebLogic Server

    CVE-2017-10271

    RansomwareCVE from 2017, added in 2022

    Oracle Corporation WebLogic Server Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 10, 2022
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  54. Rank 64Adobe ColdFusion

    CVE-2024-20767

    Adobe ColdFusion Improper Access Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 16, 2024
    CISA deadline
    21 days
    CVSS severity
    7.4 (high)
  55. Rank 65Oracle WebLogic Server

    CVE-2017-3506

    CVE from 2017, added in 2024

    Oracle WebLogic Server OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 3, 2024
    CISA deadline
    21 days
    CVSS severity
    7.4 (high)
  56. Rank 66Oracle WebLogic Server

    CVE-2020-14883

    Oracle WebLogic Server Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.2 (high)
  57. Rank 67Red Hat JBoss Application Server / EAP

    CVE-2010-0738

    RansomwareCVE from 2010, added in 2022

    Red Hat JBoss Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    5.3 (medium)

Filed under another category

These 2 vulnerabilities also concern this type of product, but are counted in their main category. My radar finds them when you follow this category.

  1. Oracle ADF Faces

    CVE-2022-21445

    CVE from 2022, added in 2024

    Oracle ADF Faces Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 18, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  2. Adobe BlazeDS

    CVE-2009-3960

    RansomwareCVE from 2009, added in 2022

    Adobe BlazeDS Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 7, 2022
    CISA deadline
    184 days
    CVSS severity
    6.5 (medium)

Follow and verify

Get new vulnerabilities in this category: RSS feed (add it to Outlook, Teams, Slack or your feed reader).

Indicative classification, based on the vendor and product names given by CISA. How products are classified.