CyberMax
Home › Exploited CVEs

NETGEAR known exploited vulnerabilities

CISA KEV catalog 2026.09.25 (1,726 CVEs) with FIRST EPSS scores from 2026-09-27.

CISA lists 8 NETGEAR CVEs as exploited in the wild. 0 were added in the last 12 months (latest 2022-09-08), and 0 are known to be used in ransomware campaigns.

NETGEAR CVEs added to CISA KEV per year
2021: 1202112022: 720227

Year = when CISA added the CVE to the catalog (KEV started in November 2021).

Patch first: highest EPSS right now

EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.

Most affected NETGEAR products

Multiple Devices (2), DGN2200 Devices (1), Wireless Access Point (WAP) Devices (1), WNR2000v5 Router (1), Wireless Router DGN2200 (1), Multiple Routers (1), JGS516PE Devices (1).

All NETGEAR CVEs in KEV

CVEProductFlawAddedFederal dueEPSSRansomware
CVE-2017-5521Multiple DevicesMultiple Devices Exposure of Sensitive Information2022-09-082022-09-2989.2%–
CVE-2017-6862Multiple DevicesMultiple Devices Buffer Overflow2022-06-082022-06-2245.7%–
CVE-2017-6334DGN2200 DevicesDGN2200 Devices OS Command Injection2022-03-252022-04-1572.6%–
CVE-2016-1555Wireless Access Point (WAP) DevicesMultiple WAP Devices Command Injection2022-03-252022-04-1598.3%–
CVE-2016-10174WNR2000v5 RouterWNR2000v5 Router Buffer Overflow2022-03-252022-04-1583.3%–
CVE-2017-6077Wireless Router DGN2200DGN2200 Remote Code Execution2022-03-072022-09-0768.7%–
CVE-2016-6277Multiple RoutersMultiple Routers Remote Code Execution2022-03-072022-09-0799.8%–
CVE-2020-26919JGS516PE DevicesNetgear JGS516PE Devices Missing Function Level Access Control2021-11-032022-05-0357.5%–
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.

Read next: Which CVEs to patch first this week · All vendors