CyberMax
Home › Exploited CVEs

Samsung known exploited vulnerabilities

CISA KEV catalog 2026.09.25 (1,726 CVEs) with FIRST EPSS scores from 2026-09-27.

CISA lists 15 Samsung CVEs as exploited in the wild. 3 were added in the last 12 months (latest 2026-04-24), and 0 are known to be used in ransomware campaigns.

Samsung CVEs added to CISA KEV per year
2022: 3202232023: 8202382025: 3202532026: 120261

Year = when CISA added the CVE to the catalog (KEV started in November 2021).

Patch first: highest EPSS right now

EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.

Most affected Samsung products

Mobile Devices (13), MagicINFO 9 Server (2).

All Samsung CVEs in KEV

CVEProductFlawAddedFederal dueEPSSRansomware
CVE-2024-7399MagicINFO 9 ServerMagicINFO 9 Server Path Traversal2026-04-242026-05-0891.9%–
CVE-2025-21042Mobile DevicesMobile Devices Out-of-Bounds Write2025-11-102025-12-0133.2%–
CVE-2025-21043Mobile DevicesMobile Devices Out-of-Bounds Write2025-10-022025-10-232.1%–
CVE-2025-4632MagicINFO 9 ServerMagicINFO 9 Server Path Traversal2025-05-222025-06-1224.3%–
CVE-2022-22265Mobile DevicesMobile Devices Use-After-Free2023-09-182023-10-090.4%–
CVE-2021-25489Mobile DevicesMobile Devices Improper Input Validation2023-06-292023-07-200.5%–
CVE-2021-25487Mobile DevicesMobile Devices Out-of-Bounds Read2023-06-292023-07-200.6%–
CVE-2021-25395Mobile DevicesMobile Devices Race Condition2023-06-292023-07-200.4%–
CVE-2021-25394Mobile DevicesMobile Devices Race Condition2023-06-292023-07-200.4%–
CVE-2021-25372Mobile DevicesMobile Devices Improper Boundary Check2023-06-292023-07-200.8%–
CVE-2021-25371Mobile DevicesMobile Devices Unspecified2023-06-292023-07-200.8%–
CVE-2023-21492Mobile DevicesMobile Devices Insertion of Sensitive Information Into Log File2023-05-192023-06-092.6%–
CVE-2021-25370Mobile DevicesMobile Devices Memory Corruption2022-11-082022-11-290.9%–
CVE-2021-25369Mobile DevicesMobile Devices Improper Access Control2022-11-082022-11-291.1%–
CVE-2021-25337Mobile DevicesMobile Devices Improper Access Control2022-11-082022-11-292.8%–
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.

Read next: Which CVEs to patch first this week · All vendors