Samsung Vulnerabilities
Most Samsung entries in KEV concern Galaxy mobile devices, which get monthly security updates, plus the MagicINFO server for digital signage content management. The database tracks 15 Samsung CVE records. CISA lists 15 of them as exploited in the wild, most recently on 2026-04-24. The most affected products are Mobile Devices, MagicINFO 9 Server.
Recently Exploited Samsung CVEs
Samsung MagicINFO 9 Server Path Traversal Vulnerability
Samsung Mobile Devices Out-of-Bounds Write Vulnerability
Samsung Mobile Devices Out-of-Bounds Write Vulnerability
Samsung MagicINFO 9 Server Path Traversal Vulnerability
Samsung Mobile Devices Use-After-Free Vulnerability
Samsung Mobile Devices Improper Boundary Check Vulnerability
Affected Products
2 products| Product | CVEs | KEV | Latest |
|---|---|---|---|
| Mobile Devices | 13 | 13 | 2025-11-10 |
| MagicINFO 9 Server | 2 | 2 | 2026-04-24 |
All Samsung CVEs
15 records| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2024-7399 | Samsung MagicINFO 9 Server Path Traversal Vulnerability | Samsung Electronics | 8.8 | 91.9% | KEV | 2024-08-09 |
| CVE-2025-21042 | Samsung Mobile Devices Out-of-Bounds Write Vulnerability | Samsung Mobile | 8.8 | 33.2% | KEV | 2025-09-12 |
| CVE-2025-21043 | Samsung Mobile Devices Out-of-Bounds Write Vulnerability | Samsung Mobile | 8.8 | 2.1% | KEV | 2025-09-12 |
| CVE-2025-4632 | Samsung MagicINFO 9 Server Path Traversal Vulnerability | Samsung Electronics | 9.8 | 24.3% | KEV | 2025-05-13 |
| CVE-2022-22265 | Samsung Mobile Devices Use-After-Free Vulnerability | Samsung Mobile | 5.0 | 0.4% | KEV | 2022-01-07 |
| CVE-2021-25372 | Samsung Mobile Devices Improper Boundary Check Vulnerability | Samsung Mobile | 6.1 | 0.8% | KEV | 2021-03-26 |
| CVE-2021-25371 | Samsung Mobile Devices Unspecified Vulnerability | Samsung Mobile | 6.1 | 0.8% | KEV | 2021-03-26 |
| CVE-2021-25487 | Samsung Mobile Devices Out-of-Bounds Read Vulnerability | Samsung Mobile | 7.3 | 0.6% | KEV | 2021-10-06 |
| CVE-2021-25489 | Samsung Mobile Devices Improper Input Validation Vulnerability | Samsung Mobile | 3.3 | 0.5% | KEV | 2021-10-06 |
| CVE-2021-25394 | Samsung Mobile Devices Race Condition Vulnerability | Samsung Mobile | 6.4 | 0.4% | KEV | 2021-06-11 |
| CVE-2021-25395 | Samsung Mobile Devices Race Condition Vulnerability | Samsung Mobile | 6.4 | 0.4% | KEV | 2021-06-11 |
| CVE-2023-21492 | Samsung Mobile Devices Insertion of Sensitive Information Into Log File Vulnerability | Samsung Mobile | 4.4 | 2.6% | KEV | 2023-05-04 |
| CVE-2021-25337 | Samsung Mobile Devices Improper Access Control Vulnerability | Samsung Mobile | 4.4 | 2.8% | KEV | 2021-03-04 |
| CVE-2021-25369 | Samsung Mobile Devices Improper Access Control Vulnerability | Samsung Mobile | 6.2 | 1.1% | KEV | 2021-03-26 |
| CVE-2021-25370 | Samsung Mobile Devices Memory Corruption Vulnerability | Samsung Mobile | 6.1 | 0.9% | KEV | 2021-03-26 |
Frequently Asked Questions
How many Samsung vulnerabilities are actively exploited?→
15 Samsung CVEs are in the CISA Known Exploited Vulnerabilities catalog as of 2026-10-09. The latest was added on 2026-04-24.
Which Samsung products have the most exploited vulnerabilities?→
- +Mobile Devices: 13 CVEs (13 in KEV)
- +MagicINFO 9 Server: 2 CVEs (2 in KEV)
Where does Samsung publish security advisories?→
Samsung publishes security advisories at https://security.samsungmobile.com/securityUpdate.smsb. Check the vendor advisory for fixed versions and workarounds before applying updates.
Sources
CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Vendor and product names for exploited CVEs follow the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not affiliated with or endorsed by Samsung, MITRE, CISA, or FIRST.