Vulnerabilities CISA Warns of Exploited Flaw in Asus Update Tool Tracked as CVE-2025-59374, the issue is a software backdoor implanted in Asus Live Update in a supply chain attack. Ionut ArghireDecember 18, 2025
Vulnerabilities Recent GeoServer Vulnerability Exploited in Attacks Because user input is not sufficiently sanitized, attackers could exploit the flaw to define external entities within an XML request. Ionut ArghireDecember 12, 2025
ICS/OT CISA Warns of ScadaBR Vulnerability After Hacktivist ICS Attack CISA has added CVE-2021-26829 to its Known Exploited Vulnerabilities (KEV) catalog. Eduard KovacsDecember 1, 2025
Vulnerabilities Critical WatchGuard Firebox Vulnerability Exploited in Attacks Tracked as CVE-2025-9242 (CVSS score of 9.3), the flaw leads to unauthenticated, remote code execution on vulnerable firewalls. Ionut ArghireNovember 13, 2025
Vulnerabilities CISA Warns of CWP Vulnerability Exploited in the Wild A critical vulnerability in Control Web Panel (CWP), tracked as CVE-2025-48703, allows remote, unauthenticated command execution. Eduard KovacsNovember 5, 2025
Vulnerabilities CISA Adds Exploited XWiki, VMware Flaws to KEV Catalog Broadcom has updated its advisory on CVE-2025-41244 to mention the vulnerability’s in-the-wild exploitation. Ionut ArghireOctober 31, 2025
ICS/OT CISA Warns of Exploited DELMIA Factory Software Vulnerabilities Two DELMIA Apriso flaws can be chained together to gain privileged access to the application and execute arbitrary code remotely. Ionut ArghireOctober 29, 2025
Vulnerabilities CISA Warns of Exploited Apple, Kentico, Microsoft Vulnerabilities Leading to code execution, authentication bypass, and privilege escalation, the flaws were added to CISA’s KEV list. Ionut ArghireOctober 21, 2025
Vulnerabilities CISA Confirms Exploitation of Latest Oracle EBS Vulnerability The cybersecurity agency has added CVE-2025-61884 to its Known Exploited Vulnerabilities (KEV) catalog. Eduard KovacsOctober 21, 2025
Vulnerabilities Organizations Warned of Exploited Adobe AEM Forms Vulnerability A public PoC existed when Adobe patched the Experience Manager Forms (AEM Forms) bug in early August. Ionut ArghireOctober 16, 2025
Vulnerabilities Organizations Warned of Exploited Meteobridge Vulnerability Patched in mid-May, the security defect allows remote unauthenticated attackers to execute arbitrary commands with root privileges. Ionut ArghireOctober 3, 2025
Vulnerabilities Organizations Warned of Exploited Sudo Vulnerability The vulnerability could allow local, low-privileged attackers to execute commands with root privileges, leading to full system compromise. Ionut ArghireSeptember 30, 2025
Vulnerabilities Organizations Warned of Exploited Git Vulnerability CISA urges federal agencies to immediately patch an exploited arbitrary file write vulnerability in Git that leads to remote code execution. Ionut ArghireAugust 26, 2025
Vulnerabilities CISA Warns of Attacks Exploiting N-able Vulnerabilities CISA reported becoming aware of attacks exploiting CVE-2025-8875 and CVE-2025-8876 in N-able N-central on the day they were patched. Eduard KovacsAugust 14, 2025
Vulnerabilities Organizations Warned of Exploited PaperCut Flaw Threat actors are exploiting a two-year-old vulnerability in PaperCut that allows them to execute arbitrary code remotely. Ionut ArghireJuly 29, 2025
Vulnerabilities CISA Warns of SysAid Vulnerability Exploitation CISA has added two recent SysAid vulnerabilities, CVE-2025-2776 and CVE-2025-2775, to its KEV catalog. Eduard KovacsJuly 23, 2025
Vulnerabilities CitrixBleed 2 Flaw Poses Unacceptable Risk: CISA CISA considers the recently disclosed CitrixBleed 2 vulnerability an unacceptable risk and has added it to the KEV catalog. Ionut ArghireJuly 14, 2025
Vulnerabilities CISA Warns of Two Exploited TeleMessage Vulnerabilities CISA says two more vulnerabilities in the messaging application TeleMessage TM SGNL have been exploited in the wild. Ionut ArghireJuly 2, 2025
Vulnerabilities CISA Warns AMI BMC Vulnerability Exploited in the Wild CISA is urging federal agencies to patch a recent AMI BMC vulnerability and a half-a-decade-old bug in FortiOS by July 17. Ionut ArghireJune 26, 2025
Vulnerabilities Linux Security: New Flaws Allow Root Access, CISA Warns of Old Bug Exploitation Qualys has disclosed two Linux vulnerabilities that can be chained for full root access, and CISA added a flaw to its KEV catalog. Eduard KovacsJune 18, 2025