CyberMax
Home › Exploited CVEs › Samsung

Samsung Mobile Devices known exploited vulnerabilities, ranked

CISA KEV catalog 2026.10.02 · FIRST EPSS scores from 2026-10-02

CISA lists 13 Samsung Mobile Devices CVEs as exploited in the wild. 2 were added in the last 12 months and 0 are known to be used in ransomware. The table ranks all of them by EPSS, FIRST's estimate of the chance a CVE is exploited in the next 30 days, so the first rows are the ones to patch first.

Patch these first

All 13 Samsung Mobile Devices CVEs in CISA KEV, by EPSS

#CVEFlawEPSSRansomwareAddedFederal due
1CVE-2025-21042Mobile Devices Out-of-Bounds Write33.2%–2025-11-102025-12-01
2CVE-2021-25337Mobile Devices Improper Access Control2.8%–2022-11-082022-11-29
3CVE-2023-21492Mobile Devices Insertion of Sensitive Information Into Log File2.6%–2023-05-192023-06-09
4CVE-2025-21043Mobile Devices Out-of-Bounds Write2.1%–2025-10-022025-10-23
5CVE-2021-25369Mobile Devices Improper Access Control1.1%–2022-11-082022-11-29
6CVE-2021-25370Mobile Devices Memory Corruption0.9%–2022-11-082022-11-29
7CVE-2021-25372Mobile Devices Improper Boundary Check0.8%–2023-06-292023-07-20
8CVE-2021-25371Mobile Devices Unspecified0.8%–2023-06-292023-07-20
9CVE-2021-25487Mobile Devices Out-of-Bounds Read0.6%–2023-06-292023-07-20
10CVE-2021-25489Mobile Devices Improper Input Validation0.5%–2023-06-292023-07-20
11CVE-2021-25394Mobile Devices Race Condition0.4%–2023-06-292023-07-20
12CVE-2022-22265Mobile Devices Use-After-Free0.4%–2023-09-182023-10-09
13CVE-2021-25395Mobile Devices Race Condition0.4%–2023-06-292023-07-20
EPSS changes daily; a CVE with a low EPSS that is in KEV is still exploited somewhere. Federal due dates bind US federal civilian agencies; everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.

More: all Samsung KEV CVEs · free KEV badge for Samsung · all vendors