CyberMax
Home › Exploited CVEs

Mitel known exploited vulnerabilities

CISA KEV catalog 2026.09.25 (1,726 CVEs) with FIRST EPSS scores from 2026-09-27.

CISA lists 7 Mitel CVEs as exploited in the wild. 0 were added in the last 12 months (latest 2025-02-12), and 5 are known to be used in ransomware campaigns.

Mitel CVEs added to CISA KEV per year
2022: 2202222023: 2202322025: 320253

Year = when CISA added the CVE to the catalog (KEV started in November 2021).

Patch first: highest EPSS right now

EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.

Most affected Mitel products

MiVoice Connect (3), MiCollab (2), SIP Phones (1), MiCollab, MiVoice Business Express (1).

All Mitel CVEs in KEV

CVEProductFlawAddedFederal dueEPSSRansomware
CVE-2024-41710SIP PhonesSIP Phones Argument Injection2025-02-122025-03-0541.6%–
CVE-2024-55550MiCollabMiCollab Path Traversal2025-01-072025-01-2837.9%Yes
CVE-2024-41713MiCollabMiCollab Path Traversal2025-01-072025-01-2898.1%Yes
CVE-2022-41223MiVoice ConnectMiVoice Connect Code Injection2023-02-212023-03-1410.7%Yes
CVE-2022-40765MiVoice ConnectMiVoice Connect Command Injection2023-02-212023-03-1410.6%Yes
CVE-2022-29499MiVoice ConnectMiVoice Connect Data Validation2022-06-272022-07-1855.0%Yes
CVE-2022-26143MiCollab, MiVoice Business ExpressMiCollab, MiVoice Business Express Access Control2022-03-252022-04-1587.3%–
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.

Read next: Which CVEs to patch first this week · All vendors