For people who run a VPN appliance: Fortinet, Ivanti, Cisco ASA, SonicWall, Citrix, Palo Alto and the rest. On a commercial VPN app you own none of this hardware and have nothing here to patch. Go to the leak test.
A curated match on VPN and remote-access products in the CISA Known Exploited Vulnerabilities catalogue. It is selective, so a device absent here is not certified clean: check the vendor advisory for your model and firmware. The due date is CISA's remediation deadline for US federal civilian agencies. It binds nobody else, and it stays the best public marker of how urgent CISA considered each bug.
EPSS is the chance of exploitation in the next 30 days. On a KEV entry it already happened, so a low score means targeted activity, never a reason to defer the patch.
Which appliance line has the most known-exploited bugs. Long bar, long break-in record. Red bar, ransomware crews used it.