CVE-2021-30858
published 2021-08-24CVE-2021-30858: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6. Processing…
PriorityP187high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2021-11-17
Exploited in the wild
EPSS
13.49%
96.0th percentile
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | ios | >= unspecified < 14.8 | 14.8 |
| apple | ios_14.8_and_ipados | — | — |
| apple | ipados | >= 13.1 < 14.8 | 14.8 |
| apple | iphone_os | < 12.5.5 | 12.5.5 |
| apple | iphone_os | >= 13.0 < 14.8 | 14.8 |
| apple | macos | < 11.6 | 11.6 |
| apple | macos | >= unspecified < 11.6 | 11.6 |
| apple | macos_big_sur | — | — |
| apple | safari | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | webkit2gtk | < webkit2gtk 2.32.4-1 (bookworm) | webkit2gtk 2.32.4-1 (bookworm) |
| debian | wpewebkit | < webkit2gtk 2.32.4-1 (bookworm) | webkit2gtk 2.32.4-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2021-30858 is a WebKit use-after-free triggered by processing a specially crafted web page; detection should focus on WebKit/WebKitGTK versions below the fixed releases (webkit2gtk 2.32.4-1 on Debian/Ubuntu) ↗
- →The vulnerability is exploitable via a maliciously crafted web page (zero-click or one-click browser vector); monitor for suspicious WebKit/browser process crashes or unexpected code execution originating from web content rendering processes ↗
- →This vulnerability was actively exploited in the wild as part of the NSO Pegasus spyware campaign; treat any unpatched iOS/iPadOS/macOS device as potentially compromised ↗
- →On Ubuntu/Debian Linux systems, check for WebKitGTK versions older than 2.32.4-1; applications using WebKitGTK (e.g., Epiphany) are attack surface ↗
- →Qualys QID 610367 (signature version SEM VULNSIGS-1.0.0.45) detects CVE-2021-30858 on iOS/iPadOS 14.x devices; use this QID for asset-level confirmation of exposure ↗
- ·The vulnerability affects a broad range of Apple devices; patched versions are iOS/iPadOS 14.8, macOS Big Sur 11.6, iOS/iPadOS 12.5.5 (for older devices), and WebKitGTK 2.32.4-1 on Linux — ensure detection logic accounts for all affected platforms ↗
- ·On older Apple hardware (iPhone 5s, iPhone 6/6 Plus, iPad Air, iPad mini 2/3, iPod touch 6th gen), the fix was delivered separately in iOS/iPadOS 12.5.5 — detection tools must check for this separate patch train ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vulncheck8.8HIGH
cisa8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Apple iOS, iPadOS, macOS Use-After-Free Vulnerability
cisa·2021-11-03·CVSS 8.8
CVE-2021-30858 [HIGH] CWE-416 Apple iOS, iPadOS, macOS Use-After-Free Vulnerability
Vulnerability: Apple iOS, iPadOS, macOS Use-After-Free Vulnerability
Affected: Apple iOS, iPadOS, and macOS
Apple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-30858
Remediation Due Date: 2021-11-17
Apple
CVE-2021-30858: iOS 12.5.5
vendor_apple·2021-09-23·CVSS 8.8
CVE-2021-30858 [HIGH] CVE-2021-30858: iOS 12.5.5
Apple Security Update: About the security content of iOS 12.5.5
Product: iOS
Version: 12.5.5
CVE: CVE-2021-30858
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
Description: A use after free issue was addressed with improved memory management.
Ubuntu
WebKitGTK vulnerabilities
vendor_ubuntu·2021-09-22
CVE-2021-30858 WebKitGTK vulnerabilities
Title: WebKitGTK vulnerabilities
Summary: Several security issues were fixed in WebKitGTK.
A large number of security issues were discovered in the WebKitGTK Web and
JavaScript engines. If a user were tricked into viewing a malicious
website, a remote attacker could exploit a variety of issues related to web
browser security, including cross-site scripting attacks, denial of service
attacks, and arbitrary code execution.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart any applications
that use WebKitGTK, such as Epiphany, to make all the necessary changes.
Red Hat
webkitgtk: Use-after-free leading to arbitrary code execution
vendor_redhat·2021-09-20·CVSS 8.8
CVE-2021-30858 [HIGH] CWE-416 webkitgtk: Use-after-free leading to arbitrary code execution
webkitgtk: Use-after-free leading to arbitrary code execution
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
A flaw was found in webkitgtk. This flaw could allow an attacker to use maliciously crafted web content leading to arbitrary code execution.
Statement: This flaw is rated as having Moderate impact considering the ability of an attacker to perform arbitrary code execution is limited to cases where a web browser is involved. Red Hat expects customers to not feed untrusted input into WebKit.
Mitigation: This flaw can be mitigated by eit
Apple
CVE-2021-30858: iOS 14.8 and iPadOS 14.8
vendor_apple·2021-09-13·CVSS 8.8
CVE-2021-30858 [HIGH] CVE-2021-30858: iOS 14.8 and iPadOS 14.8
Apple Security Update: About the security content of iOS 14.8 and iPadOS 14.8
Product: iOS 14.8 and iPadOS
Version: 14.8
CVE: CVE-2021-30858
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
Description: A use after free issue was addressed with improved memory management.
Apple
CVE-2021-30858: Safari 14.1.2
vendor_apple·2021-09-13·CVSS 8.8
CVE-2021-30858 [HIGH] CVE-2021-30858: Safari 14.1.2
Apple Security Update: About the security content of Safari 14.1.2
Product: Safari
Version: 14.1.2
CVE: CVE-2021-30858
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
Description: A use after free issue was addressed with improved memory management.
Apple
CVE-2021-30858: macOS Big Sur 11.6
vendor_apple·2021-09-13·CVSS 8.8
CVE-2021-30858 [HIGH] CVE-2021-30858: macOS Big Sur 11.6
Apple Security Update: About the security content of macOS Big Sur 11.6
Product: macOS Big Sur
Version: 11.6
CVE: CVE-2021-30858
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
Description: A use after free issue was addressed with improved memory management.
Debian
CVE-2021-30858: webkit2gtk - A use after free issue was addressed with improved memory management. This issue...
vendor_debian·2021·CVSS 8.8
CVE-2021-30858 [HIGH] CVE-2021-30858: webkit2gtk - A use after free issue was addressed with improved memory management. This issue...
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
Scope: local
bookworm: resolved (fixed in 2.32.4-1)
bullseye: resolved (fixed in 2.32.4-1~deb11u1)
forky: resolved (fixed in 2.32.4-1)
sid: resolved (fixed in 2.32.4-1)
trixie: resolved (fixed in 2.32.4-1)
Project0
The More You Know, The More You Know You Don’t Know - Project Zero
project_zero·2022-04-01
CVE-2016-4654 The More You Know, The More You Know You Don’t Know - Project Zero
A Year in Review of 0-days Used In-the-Wild in 2021
Posted by Maddie Stone, Google Project Zero
This is our third annual year in review of 0-days exploited in-the-wild [2020, 2019]. Each year we’ve looked back at all of the detected and disclosed in-the-wild 0-days as a group and synthesized what we think the trends and takeaways are. The goal of this report is not to detail each individual exploit, but instead to analyze the exploits from the year as a group, looking for trends, gaps, lessons learned, successes, etc. If you’re interested in the analysis of individual exploits, please check out our root cause analysis repository.
We perform and share this analysis in order to make 0-day hard. We want it to be more costly, more resource intensive, and overall more difficult for
OSV
CVE-2021-30858: A use after free issue was addressed with improved memory management
osv·2021-08-24·CVSS 8.8
CVE-2021-30858 [HIGH] CVE-2021-30858: A use after free issue was addressed with improved memory management
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
VulnCheck
Apple iOS, iPadOS, macOS Use-After-Free Vulnerability
vulncheck·2021·CVSS 8.8
CVE-2021-30858 [HIGH] CWE-416 Apple iOS, iPadOS, macOS Use-After-Free Vulnerability
Apple iOS, iPadOS, macOS Use-After-Free Vulnerability
Apple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Affected: Apple iOS, iPadOS, and macOS
Required Action: Apply updates per vendor instructions.
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://support.apple.com/en-us/103147; https://support.apple.com/en-us/103151; https://support.apple.com/kb/HT212807; https://support.apple.com/en-us/103157; https://www.cisa.gov/sites/default/files/feeds/know
Project0
Project Zero RCA: CVE-2021-30858
project_zero·CVSS 8.8
CVE-2021-30858 [HIGH] Project Zero RCA: CVE-2021-30858
## CVE-2021-30858: WebKit use-after-free in IndexedDB
*Maddie Stone, Google Project Zero*
## The Basics
**Disclosure or Patch Date:** 13 September 2021
**Product:** Apple WebKit
**Advisory:** https://support.apple.com/en-us/HT212808
**Affected Versions:** pre-Safari 14.1.2, pre-iOS 14.8
**First Patched Version:** Safari 14.1.2, iOS 14.8
**Issue/Bug Report:** https://bugs.webkit.org/show_bug.cgi?id=229375
**Patch CL:** https://trac.webkit.org/changeset/281384/webkit
**Bug-Introducing CL:** ??
**Reporter(s):** Anonymous
## The Code
**Proof-of-concept:**
index.html
```html
w = new Worker('idbworker.js');
```
idbworker.js
```javascript
function freememory() {
for (var i = 0; i ` so the cross-thread task will use a `RefPtr` for the callee ([source](https://github.com/WebKit/We
No detection rules found.
No public exploits indexed.
Qualys
Qualys Response to CISA Alert: Binding Operational Directive 22-01
blogs_qualys·2021-11-09
Qualys Response to CISA Alert: Binding Operational Directive 22-01
## Table of Contents
Overview
Directive Scope
CISA Catalog of Known Exploited Vulnerabilities
Detect CISAs Vulnerabilities Using Qualys VMDR
Remediation
Federal Enterprises and Agencies Can Act Now
Summary
Getting Started
Start your VMDR 30-day, no-cost trial today
## Overview
On November 3, 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a Binding Operational Directive 22-01 , “Reducing the Significant Risk of Known Exploited Vulnerabilities.” This directive recommends urgent and prioritized remediation of the vulnerabilities that adversaries are actively exploiting. It establishes a CISA-managed catalog of known exploited vulnerabilities that carry significant risk to the federal government and establishes requirements for agencies to remediate
Qualys
Qualys Response to CISA Alert: Binding Operational Directive 22-01 | Qualys
blogs_qualys·2021-11-09
Qualys Response to CISA Alert: Binding Operational Directive 22-01 | Qualys
#### Table of Contents
- Overview
- Directive Scope
- CISA Catalog of Known Exploited Vulnerabilities
- Detect CISAs Vulnerabilities Using Qualys VMDR
- Remediation
- Federal Enterprises and Agencies Can Act Now
- Summary
- Getting Started
Start your VMDR 30-day, no-cost trial today
## Overview
On November 3, 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a Binding Operational Directive 22-01, “Reducing the Significant Risk of Known Exploited Vulnerabilities.” This directive recommends urgent and prioritized remediation of the vulnerabilities that adversaries are actively exploiting. It establishes a CISA-managed catalog of known exploited vulnerabilities that carry significant risk to the federal government and establishes requirements for agencies to
Qualys
Apple fixes zero-day in iOS and iPadOS 15.0.2 emergency release: Detect and Prioritize Vulnerabilities using VMDR for Mobile Devices
blogs_qualys·2021-10-18·CVSS 7.0
[HIGH] Apple fixes zero-day in iOS and iPadOS 15.0.2 emergency release: Detect and Prioritize Vulnerabilities using VMDR for Mobile Devices
Apple recently released iOS and iPadOS 15.0.2 as an emergency security update that addresses 1 critical zero-day vulnerabilities, which is exploited in wild. Qualys recommends that security teams should immediately update all devices running iOS and iPadOS to the latest version. “ Apple is aware of a report that this issue may have been actively exploited ,” the company said in security advisories .
This year, Apple has released multiple emergency releases to fix the actively exploited vulnerabilities which Apple is aware of a report that this issue may have been actively exploited . Successful exploitation of the vulnerability allows an application to execute arbitrary code with kernel privileges, and spyware like Pegasus can be easily deployed on affect devices, and exploiting other vul
Qualys
Apple fixes zero-day in iOS and iPadOS 15.0.2 emergency release: Detect and Prioritize Vulnerabilities using VMDR for Mobile Devices | Qualys
blogs_qualys·2021-10-18·CVSS 7.0
[HIGH] Apple fixes zero-day in iOS and iPadOS 15.0.2 emergency release: Detect and Prioritize Vulnerabilities using VMDR for Mobile Devices | Qualys
Apple recently released iOS and iPadOS 15.0.2 as an emergency security update that addresses 1 critical zero-day vulnerabilities, which is exploited in wild. Qualys recommends that security teams should immediately update all devices running iOS and iPadOS to the latest version. “Apple is aware of a report that this issue may have been actively exploited,” the company said in security advisories.
This year, Apple has released multiple emergency releases to fix the actively exploited vulnerabilities which Apple is aware of a report that this issue may have been actively exploited. Successful exploitation of the vulnerability allows an application to execute arbitrary code with kernel privileges, and spyware like Pegasus can be easily deployed on affect devices, and exploiting other vulnera
Qualys
NSO Pegasus iPhone Spyware Vulnerabilities Fixed by Apple - Detect & Prioritize Using VMDR for Mobile Devices | Qualys
blogs_qualys·2021-09-29·CVSS 8.8
[HIGH] NSO Pegasus iPhone Spyware Vulnerabilities Fixed by Apple - Detect & Prioritize Using VMDR for Mobile Devices | Qualys
#### Table of Contents
- CoreGraphics Arbitrary Code Execution Vulnerability
- WebKit Arbitrary Code Execution Vulnerability
- XNU Arbitrary Code Execution with Kernel Privileges Vulnerability
- Multiple ImageIO Arbitrary Code Execution Vulnerabilities
- Discover Vulnerabilities and Take Remote Response Action Using VMDR for Mobile Devices
Apple recently released iOS and iPadOS 12.5.5, 15.0, which includes a security update that addresses almost 25 vulnerabilities, including several critical RCE and privilege escalation vulnerabilities. In 12.5.5, Apple fixed 3 critical zero-day vulnerabilities, which are used to deploy NSO Pegasus iPhone spyware to secure old iPhones. Earlier in 14.8 these 2 critical zero-day vulnerabilities exploited by NSO Pegasus were fixed and on 20th September Appl
Qualys
NSO Pegasus iPhone Spyware Vulnerabilities Fixed by Apple – Detect & Prioritize Using VMDR for Mobile Devices
blogs_qualys·2021-09-29·CVSS 8.8
[HIGH] NSO Pegasus iPhone Spyware Vulnerabilities Fixed by Apple – Detect & Prioritize Using VMDR for Mobile Devices
## Table of Contents
CoreGraphics Arbitrary Code Execution Vulnerability
WebKit Arbitrary Code Execution Vulnerability
XNU Arbitrary Code Execution with Kernel Privileges Vulnerability
Multiple ImageIO Arbitrary Code Execution Vulnerabilities
Discover Vulnerabilities and Take Remote Response Action Using VMDR for Mobile Devices
Apple recently released iOS and iPadOS 12.5.5 , 15.0 , which includes a security update that addresses almost 25 vulnerabilities, including several critical RCE and privilege escalation vulnerabilities. In 12.5.5, Apple fixed 3 critical zero-day vulnerabilities, which are used to deploy NSO Pegasus iPhone spyware to secure old iPhones. Earlier in 14.8 these 2 critical zero-day vulnerabilities exploited by NSO Pegasus were fixed and on 20 th September Apple upd
Qualys
Detect & Prioritize NSO Pegasus iPhone Spyware Vulnerabilities Using VMDR for Mobile Devices
blogs_qualys·2021-09-20·CVSS 8.8
[HIGH] Detect & Prioritize NSO Pegasus iPhone Spyware Vulnerabilities Using VMDR for Mobile Devices
Apple recently released iOS and iPadOS 14.8 as a security update that addresses 2 critical zero-day vulnerabilities, which are used to deploy NSO Pegasus iPhone spyware . Qualys recommends that security teams should immediately update all devices running iOS and iPadOS to the latest version. “ Apple is aware of a report that this issue may have been actively exploited ,” the company said in security advisories .
The vulnerabilities affect iOS, iPadOS, watchOS, and macOS components including Core Graphics, and WebKit. Apple has released a fourth time an immediate security update release (14.8) after the major minor security update release (14.7.1) to fix the critical vulnerability (CVE-2021-30860) that has been actively exploited. Successful exploitation of vulnerability allows an applicat
Qualys
Detect & Prioritize NSO Pegasus iPhone Spyware Vulnerabilities Using VMDR for Mobile Devices | Qualys
blogs_qualys·2021-09-20·CVSS 8.8
[HIGH] Detect & Prioritize NSO Pegasus iPhone Spyware Vulnerabilities Using VMDR for Mobile Devices | Qualys
Apple recently released iOS and iPadOS 14.8 as a security update that addresses 2 critical zero-day vulnerabilities, which are used to deploy NSO Pegasus iPhone spyware. Qualys recommends that security teams should immediately update all devices running iOS and iPadOS to the latest version. “Apple is aware of a report that this issue may have been actively exploited,” the company said in security advisories.
The vulnerabilities affect iOS, iPadOS, watchOS, and macOS components including Core Graphics, and WebKit. Apple has released a fourth time an immediate security update release (14.8) after the major minor security update release (14.7.1) to fix the critical vulnerability (CVE-2021-30860) that has been actively exploited. Successful exploitation of vulnerability allows an application
Checkpoint
20th September – Threat Intelligence Report
blogs_checkpoint·2021-09-19·CVSS 7.8
CVE-2021-40444 [HIGH] 20th September – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 20th September – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 20th September, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Check Point Research has seen a global surge in the black market for fake COVID-19 vaccine certificates on Telegram, following US President Biden’s vaccine mandate announcements. The black market has expanded to serve 28 countries, including Austria, UAE, Brazil, UK, Singapore and more. The price for fake vaccine cert
http://seclists.org/fulldisclosure/2021/Sep/25http://seclists.org/fulldisclosure/2021/Sep/27http://seclists.org/fulldisclosure/2021/Sep/29http://seclists.org/fulldisclosure/2021/Sep/38http://seclists.org/fulldisclosure/2021/Sep/39http://seclists.org/fulldisclosure/2021/Sep/50http://www.openwall.com/lists/oss-security/2021/09/20/1http://www.openwall.com/lists/oss-security/2021/10/26/9http://www.openwall.com/lists/oss-security/2021/10/27/1http://www.openwall.com/lists/oss-security/2021/10/27/2http://www.openwall.com/lists/oss-security/2021/10/27/4https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BO6DMTHZR57JDBOXPSNR2MKDMCRWV265/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XYNV7ASK4LQVAUMJXNXBS3Z7RVDQ2N3W/https://support.apple.com/en-us/HT212804https://support.apple.com/en-us/HT212807https://support.apple.com/kb/HT212824https://www.debian.org/security/2021/dsa-4975https://www.debian.org/security/2021/dsa-4976http://seclists.org/fulldisclosure/2021/Sep/25http://seclists.org/fulldisclosure/2021/Sep/27http://seclists.org/fulldisclosure/2021/Sep/29http://seclists.org/fulldisclosure/2021/Sep/38http://seclists.org/fulldisclosure/2021/Sep/39http://seclists.org/fulldisclosure/2021/Sep/50http://www.openwall.com/lists/oss-security/2021/09/20/1http://www.openwall.com/lists/oss-security/2021/10/26/9http://www.openwall.com/lists/oss-security/2021/10/27/1http://www.openwall.com/lists/oss-security/2021/10/27/2http://www.openwall.com/lists/oss-security/2021/10/27/4https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BO6DMTHZR57JDBOXPSNR2MKDMCRWV265/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XYNV7ASK4LQVAUMJXNXBS3Z7RVDQ2N3W/https://support.apple.com/en-us/HT212804https://support.apple.com/en-us/HT212807https://support.apple.com/kb/HT212824https://www.debian.org/security/2021/dsa-4975https://www.debian.org/security/2021/dsa-4976https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-30858
2021-08-24
Published
2021-11-03
Added to CISA KEV
Exploited in the wild