Mitel known exploited vulnerabilities
CISA lists 7 Mitel CVEs as exploited in the wild. 0 were added in the last 12 months (latest 2025-02-12), and 5 are known to be used in ransomware campaigns.
Year = when CISA added the CVE to the catalog (KEV started in November 2021).
Patch first: highest EPSS right now
EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.
- CVE-2024-41713 (MiCollab): EPSS 98.1%, added 2025-01-07
- CVE-2022-26143 (MiCollab, MiVoice Business Express): EPSS 87.3%, added 2022-03-25
- CVE-2022-29499 (MiVoice Connect): EPSS 55.0%, added 2022-06-27
- CVE-2024-41710 (SIP Phones): EPSS 41.6%, added 2025-02-12
- CVE-2024-55550 (MiCollab): EPSS 37.9%, added 2025-01-07
Most affected Mitel products
MiVoice Connect (3), MiCollab (2), SIP Phones (1), MiCollab, MiVoice Business Express (1).
All Mitel CVEs in KEV
| CVE | Product | Flaw | Added | Federal due | EPSS | Ransomware |
|---|---|---|---|---|---|---|
| CVE-2024-41710 | SIP Phones | SIP Phones Argument Injection | 2025-02-12 | 2025-03-05 | 41.6% | – |
| CVE-2024-55550 | MiCollab | MiCollab Path Traversal | 2025-01-07 | 2025-01-28 | 37.9% | Yes |
| CVE-2024-41713 | MiCollab | MiCollab Path Traversal | 2025-01-07 | 2025-01-28 | 98.1% | Yes |
| CVE-2022-41223 | MiVoice Connect | MiVoice Connect Code Injection | 2023-02-21 | 2023-03-14 | 10.7% | Yes |
| CVE-2022-40765 | MiVoice Connect | MiVoice Connect Command Injection | 2023-02-21 | 2023-03-14 | 10.6% | Yes |
| CVE-2022-29499 | MiVoice Connect | MiVoice Connect Data Validation | 2022-06-27 | 2022-07-18 | 55.0% | Yes |
| CVE-2022-26143 | MiCollab, MiVoice Business Express | MiCollab, MiVoice Business Express Access Control | 2022-03-25 | 2022-04-15 | 87.3% | – |
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.
Read next: Which CVEs to patch first this week · All vendors