Samsung known exploited vulnerabilities
CISA lists 15 Samsung CVEs as exploited in the wild. 3 were added in the last 12 months (latest 2026-04-24), and 0 are known to be used in ransomware campaigns.
Year = when CISA added the CVE to the catalog (KEV started in November 2021).
Patch first: highest EPSS right now
EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.
- CVE-2024-7399 (MagicINFO 9 Server): EPSS 91.9%, added 2026-04-24
- CVE-2025-21042 (Mobile Devices): EPSS 33.2%, added 2025-11-10
- CVE-2025-4632 (MagicINFO 9 Server): EPSS 24.3%, added 2025-05-22
- CVE-2021-25337 (Mobile Devices): EPSS 2.8%, added 2022-11-08
- CVE-2023-21492 (Mobile Devices): EPSS 2.6%, added 2023-05-19
Most affected Samsung products
Mobile Devices (13), MagicINFO 9 Server (2).
All Samsung CVEs in KEV
| CVE | Product | Flaw | Added | Federal due | EPSS | Ransomware |
|---|---|---|---|---|---|---|
| CVE-2024-7399 | MagicINFO 9 Server | MagicINFO 9 Server Path Traversal | 2026-04-24 | 2026-05-08 | 91.9% | – |
| CVE-2025-21042 | Mobile Devices | Mobile Devices Out-of-Bounds Write | 2025-11-10 | 2025-12-01 | 33.2% | – |
| CVE-2025-21043 | Mobile Devices | Mobile Devices Out-of-Bounds Write | 2025-10-02 | 2025-10-23 | 2.1% | – |
| CVE-2025-4632 | MagicINFO 9 Server | MagicINFO 9 Server Path Traversal | 2025-05-22 | 2025-06-12 | 24.3% | – |
| CVE-2022-22265 | Mobile Devices | Mobile Devices Use-After-Free | 2023-09-18 | 2023-10-09 | 0.4% | – |
| CVE-2021-25489 | Mobile Devices | Mobile Devices Improper Input Validation | 2023-06-29 | 2023-07-20 | 0.5% | – |
| CVE-2021-25487 | Mobile Devices | Mobile Devices Out-of-Bounds Read | 2023-06-29 | 2023-07-20 | 0.6% | – |
| CVE-2021-25395 | Mobile Devices | Mobile Devices Race Condition | 2023-06-29 | 2023-07-20 | 0.4% | – |
| CVE-2021-25394 | Mobile Devices | Mobile Devices Race Condition | 2023-06-29 | 2023-07-20 | 0.4% | – |
| CVE-2021-25372 | Mobile Devices | Mobile Devices Improper Boundary Check | 2023-06-29 | 2023-07-20 | 0.8% | – |
| CVE-2021-25371 | Mobile Devices | Mobile Devices Unspecified | 2023-06-29 | 2023-07-20 | 0.8% | – |
| CVE-2023-21492 | Mobile Devices | Mobile Devices Insertion of Sensitive Information Into Log File | 2023-05-19 | 2023-06-09 | 2.6% | – |
| CVE-2021-25370 | Mobile Devices | Mobile Devices Memory Corruption | 2022-11-08 | 2022-11-29 | 0.9% | – |
| CVE-2021-25369 | Mobile Devices | Mobile Devices Improper Access Control | 2022-11-08 | 2022-11-29 | 1.1% | – |
| CVE-2021-25337 | Mobile Devices | Mobile Devices Improper Access Control | 2022-11-08 | 2022-11-29 | 2.8% | – |
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.
Read next: Which CVEs to patch first this week · All vendors