{
  "query": {
    "exploited": "1",
    "page": "12"
  },
  "count": 20,
  "total": 1734,
  "page": 12,
  "limit": 20,
  "updated": {
    "cves": "2026-10-06T08:45:32.201Z",
    "kev": "2026-10-06T08:44:32.120Z",
    "epss": "2026-10-06T06:57:27.860Z",
    "breaches": "2026-10-06T06:45:27.314Z",
    "posts": "2026-10-06T08:45:32.201Z"
  },
  "links": {
    "web": "https://spydr.io/threats?exploited=1&page=12",
    "next": "https://spydr.io/threats.json?exploited=1&page=13"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2025-11371",
      "url": "https://spydr.io/cve/CVE-2025-11371",
      "published": "2025-10-09T17:15:58.507Z",
      "modified": "2026-06-17T08:30:19.667Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "CISA ADP",
      "epss": 0.92137,
      "epss_percentile": 0.9982,
      "exploited": true,
      "kev": {
        "added": "2025-11-04",
        "due": "2025-11-25",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Gladinet"
      ],
      "products": [
        "Gladinet CentreStack and TrioFox"
      ],
      "cwes": [
        "CWE-552"
      ],
      "description": "In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusion Flaw that allows unintended disclosure of system files. Exploitation of this vulnerability has been observed in the wild. This issue impacts Gladinet CentreStack and Triofox: All versions prior to and including 16.7.10368.56560"
    },
    {
      "id": "CVE-2025-61882",
      "url": "https://spydr.io/cve/CVE-2025-61882",
      "published": "2025-10-05T04:15:40.340Z",
      "modified": "2026-08-04T05:16:36.247Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "oracle.com",
      "epss": 0.99732,
      "epss_percentile": 0.99952,
      "exploited": true,
      "kev": {
        "added": "2025-10-06",
        "due": "2025-10-27",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Oracle Corporation"
      ],
      "products": [
        "Oracle Corporation Oracle Concurrent Processing"
      ],
      "cwes": [
        "CWE-287"
      ],
      "description": "Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Concurrent Processing. Successful attacks of this vulnerability can result in takeover of Oracle Concurrent Processing. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)."
    },
    {
      "id": "CVE-2025-41244",
      "url": "https://spydr.io/cve/CVE-2025-41244",
      "published": "2025-09-29T17:15:30.843Z",
      "modified": "2026-06-17T09:22:39.880Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "vmware.com",
      "epss": 0.08438,
      "epss_percentile": 0.9485,
      "exploited": true,
      "kev": {
        "added": "2025-10-30",
        "due": "2025-11-20",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "VMware"
      ],
      "products": [
        "VMware VCF operations",
        "VMware tools",
        "VMware Aria Operations",
        "VMware Cloud Foundation",
        "VMware Telco Cloud Platform",
        "VMware Telco Cloud Infrastructure"
      ],
      "cwes": [
        "CWE-267"
      ],
      "description": "VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM."
    },
    {
      "id": "CVE-2025-20362",
      "url": "https://spydr.io/cve/CVE-2025-20362",
      "published": "2025-09-25T16:15:32.280Z",
      "modified": "2026-08-11T19:33:44.513Z",
      "score": 8.6,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H",
      "score_source": "NVD",
      "epss": 0.87085,
      "epss_percentile": 0.99746,
      "exploited": true,
      "kev": {
        "added": "2025-09-25",
        "due": "2025-09-26",
        "action": "The KEV due date refers to the deadline by which FCEB agencies are expected to review and begin implementing the guidance outlined in Emergency Directive (ED) 25-03 (URL listed below in Notes). Agencies must follow the mitigation steps provided by CISA (URL listed below in Notes) and vendor’s instructions (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco Secure Firewall Adaptive Security Appliance (ASA) Software",
        "Cisco Secure Firewall Threat Defense (FTD) Software"
      ],
      "cwes": [
        "CWE-862"
      ],
      "description": "Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTD Software releases that are affected by CVE-2025-20333 and CVE-2025-20362. This attack can cause unpatched devices to unexpectedly reload, leading to denial of service (DoS) conditions. Cisco strongly recommends that all customers upgrade to the fixed software releases that are listed in the Fixed Software [\"#fs\"] section of this advisory. A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to access restricted URL endpoints that are related to remote access VPN that should otherwise be inaccessible without authentication. This vulnerability is due to improper validation of user-supplied input in HTTP(S) requests. An attacker could exploit this vulnerability by sending crafted HTTP requests to a targeted web server on a device. A successful exploit could allow the attacker to access a restricted URL without authentication."
    },
    {
      "id": "CVE-2025-20333",
      "url": "https://spydr.io/cve/CVE-2025-20333",
      "published": "2025-09-25T16:15:32.073Z",
      "modified": "2026-08-11T19:33:44.513Z",
      "score": 9.9,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "cisco.com",
      "epss": 0.70651,
      "epss_percentile": 0.99378,
      "exploited": true,
      "kev": {
        "added": "2025-09-25",
        "due": "2025-09-26",
        "action": "The KEV due date refers to the deadline by which FCEB agencies are expected to review and begin implementing the guidance outlined in Emergency Directive (ED) 25-03 (URL listed below in Notes). Agencies must follow the mitigation steps provided by CISA (URL listed below in Notes) and vendor’s instructions (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco Secure Firewall Adaptive Security Appliance (ASA) Software",
        "Cisco Secure Firewall Threat Defense (FTD) Software"
      ],
      "cwes": [
        "CWE-120"
      ],
      "description": "A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to improper validation of user-supplied input in HTTP(S) requests. An attacker with valid VPN user credentials could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as root, possibly resulting in the complete compromise of the affected device."
    },
    {
      "id": "CVE-2025-20352",
      "url": "https://spydr.io/cve/CVE-2025-20352",
      "published": "2025-09-24T18:15:36.930Z",
      "modified": "2026-09-26T00:10:00.127Z",
      "score": 7.7,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H",
      "score_source": "cisco.com",
      "epss": 0.39447,
      "epss_percentile": 0.98571,
      "exploited": true,
      "kev": {
        "added": "2025-09-29",
        "due": "2025-10-20",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco IOS",
        "Cisco IOS XE Software",
        "Cisco IOS XE Catalyst SD-WAN"
      ],
      "cwes": [
        "CWE-121"
      ],
      "description": "A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following: An authenticated, remote attacker with low privileges could cause a denial of service (DoS) condition on an affected device that is running Cisco IOS Software or Cisco IOS XE Software. To cause the DoS, the attacker must have the SNMPv2c or earlier read-only community string or valid SNMPv3 user credentials. An authenticated, remote attacker with high privileges could execute code as the root user on an affected device that is running Cisco IOS XE Software. To execute code as the root user, the attacker must have the SNMPv1 or v2c read-only community string or valid SNMPv3 user credentials and administrative or privilege 15 credentials on the affected device. An attacker could exploit this vulnerability by sending a crafted SNMP packet to an affected device over IPv4 or IPv6 networks. This vulnerability is due to a stack overflow condition in the SNMP subsystem of the affected software. A successful exploit could allow a low-privileged attacker to cause the affected system to reload, resulting in a DoS condition, or allow a high-privileged attacker to execute arbitrary code as the root user and obtain full control of the affected system. Note: This vulnerability affects all versions of SNMP."
    },
    {
      "id": "CVE-2025-10585",
      "url": "https://spydr.io/cve/CVE-2025-10585",
      "published": "2025-09-24T17:15:39.473Z",
      "modified": "2026-07-14T15:21:36.793Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.05391,
      "epss_percentile": 0.9244,
      "exploited": true,
      "kev": {
        "added": "2025-09-23",
        "due": "2025-10-14",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google",
        "Siemens"
      ],
      "products": [
        "Google Chrome",
        "Siemens CADRA"
      ],
      "cwes": [
        "CWE-843"
      ],
      "description": "Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)"
    },
    {
      "id": "CVE-2025-26399",
      "url": "https://spydr.io/cve/CVE-2025-26399",
      "published": "2025-09-23T05:15:35.777Z",
      "modified": "2026-06-17T09:01:42.407Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.895,
      "epss_percentile": 0.99783,
      "exploited": true,
      "kev": {
        "added": "2026-03-09",
        "due": "2026-03-12",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "SolarWinds"
      ],
      "products": [
        "SolarWinds Web Help Desk"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. This vulnerability is a patch bypass of CVE-2024-28988, which in turn is a patch bypass of CVE-2024-28986."
    },
    {
      "id": "CVE-2025-59689",
      "url": "https://spydr.io/cve/CVE-2025-59689",
      "published": "2025-09-19T20:15:40.340Z",
      "modified": "2026-06-17T09:46:31.727Z",
      "score": 6.1,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
      "score_source": "mitre.org",
      "epss": 0.01864,
      "epss_percentile": 0.78555,
      "exploited": true,
      "kev": {
        "added": "2025-09-29",
        "due": "2025-10-20",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Libraesva"
      ],
      "products": [
        "Libraesva Email Security Gateway"
      ],
      "cwes": [
        "CWE-77"
      ],
      "description": "Libraesva ESG 4.5 through 5.5.x before 5.5.7 allows command injection via a compressed e-mail attachment. For ESG 5.0 a fix has been released in 5.0.31. For ESG 5.1 a fix has been released in 5.1.20. For ESG 5.2 a fix has been released in 5.2.31. For ESG 5.4 a fix has been released in 5.4.8. For ESG 5.5. a fix has been released in 5.5.7."
    },
    {
      "id": "CVE-2025-48703",
      "url": "https://spydr.io/cve/CVE-2025-48703",
      "published": "2025-09-19T18:15:36.620Z",
      "modified": "2026-06-17T09:30:12.133Z",
      "score": 9,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "mitre.org",
      "epss": 0.99655,
      "epss_percentile": 0.99949,
      "exploited": true,
      "kev": {
        "added": "2025-11-04",
        "due": "2025-11-25",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "centos-webpanel"
      ],
      "products": [
        "centos-webpanel CentOS Web Panel"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager changePerm request. A valid non-root username must be known."
    },
    {
      "id": "CVE-2025-10035",
      "url": "https://spydr.io/cve/CVE-2025-10035",
      "published": "2025-09-18T22:15:41.857Z",
      "modified": "2026-08-04T05:16:33.317Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99799,
      "epss_percentile": 0.99957,
      "exploited": true,
      "kev": {
        "added": "2025-09-29",
        "due": "2025-10-20",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Fortra"
      ],
      "products": [
        "Fortra GoAnywhere MFT"
      ],
      "cwes": [
        "CWE-77",
        "CWE-502"
      ],
      "description": "A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection."
    },
    {
      "id": "CVE-2025-9242",
      "url": "https://spydr.io/cve/CVE-2025-9242",
      "published": "2025-09-17T08:15:33.960Z",
      "modified": "2026-08-10T19:59:12.133Z",
      "score": 9.3,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "CNA",
      "epss": 0.913,
      "epss_percentile": 0.9981,
      "exploited": true,
      "kev": {
        "added": "2025-11-12",
        "due": "2025-12-03",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "WatchGuard"
      ],
      "products": [
        "WatchGuard Fireware OS"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer. If the Firebox was previously configured with the mobile user VPN with IKEv2 or a branch office VPN using IKEv2 to a dynamic gateway peer, and both of those configurations have since been deleted, that Firebox may still be vulnerable if a branch office VPN to a static gateway peer is still configured."
    },
    {
      "id": "CVE-2025-21043",
      "url": "https://spydr.io/cve/CVE-2025-21043",
      "published": "2025-09-12T08:15:44.920Z",
      "modified": "2026-06-17T08:42:30.067Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.0214,
      "epss_percentile": 0.814,
      "exploited": true,
      "kev": {
        "added": "2025-10-02",
        "due": "2025-10-23",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Samsung Mobile"
      ],
      "products": [
        "Samsung Mobile Devices"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code."
    },
    {
      "id": "CVE-2025-21042",
      "url": "https://spydr.io/cve/CVE-2025-21042",
      "published": "2025-09-12T08:15:44.743Z",
      "modified": "2026-09-30T23:10:00.237Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.3317,
      "epss_percentile": 0.98324,
      "exploited": true,
      "kev": {
        "added": "2025-11-10",
        "due": "2025-12-01",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Samsung Mobile"
      ],
      "products": [
        "Samsung Mobile Devices"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitrary code."
    },
    {
      "id": "CVE-2025-54236",
      "url": "https://spydr.io/cve/CVE-2025-54236",
      "published": "2025-09-09T14:15:46.563Z",
      "modified": "2026-06-17T09:39:41.293Z",
      "score": 9.1,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
      "score_source": "adobe.com",
      "epss": 0.94532,
      "epss_percentile": 0.99853,
      "exploited": true,
      "kev": {
        "added": "2025-10-24",
        "due": "2025-11-14",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Adobe"
      ],
      "products": [
        "Adobe Commerce"
      ],
      "cwes": [
        "CWE-20"
      ],
      "description": "Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality, and integrity impact to high. Exploitation of this issue does not require user interaction."
    },
    {
      "id": "CVE-2025-39682",
      "url": "https://spydr.io/cve/CVE-2025-39682",
      "published": "2025-09-05T18:15:44.670Z",
      "modified": "2026-09-21T12:00:36.613Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.0288,
      "epss_percentile": 0.86386,
      "exploited": true,
      "kev": {
        "added": "2026-09-18",
        "due": "2026-09-21",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Linux",
        "Siemens"
      ],
      "products": [
        "Linux",
        "Siemens SIMATIC CN 4100"
      ],
      "cwes": [
        "CWE-754"
      ],
      "description": "In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call must process either - only contiguous DATA records (any number of them) - one non-DATA record If the next record has different type than what has already been processed we break out of the main processing loop. If the record has already been decrypted (which may be the case for TLS 1.3 where we don't know type until decryption) we queue the pending record to the rx_list. Next recvmsg() will pick it up from there. Queuing the skb to rx_list after zero-copy decrypt is not possible, since in that case we decrypted directly to the user space buffer, and we don't have an skb to queue (darg.skb points to the ciphertext skb for access to metadata like length). Only data records are allowed zero-copy, and we break the processing loop after each non-data record. So we should never zero-copy and then find out that the record type has changed. The corner case we missed is when the initial record comes from rx_list, and it's zero length."
    },
    {
      "id": "CVE-2025-48543",
      "url": "https://spydr.io/cve/CVE-2025-48543",
      "published": "2025-09-04T19:15:40.780Z",
      "modified": "2026-06-17T09:29:49.153Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.00543,
      "epss_percentile": 0.4368,
      "exploited": true,
      "kev": {
        "added": "2025-09-04",
        "due": "2025-09-25",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Android"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "In multiple locations, there is a possible way to escape chrome sandbox to attack android system_server due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation."
    },
    {
      "id": "CVE-2025-53690",
      "url": "https://spydr.io/cve/CVE-2025-53690",
      "published": "2025-09-03T20:15:33.473Z",
      "modified": "2026-06-17T09:38:43.133Z",
      "score": 9,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "CNA",
      "epss": 0.51094,
      "epss_percentile": 0.98903,
      "exploited": true,
      "kev": {
        "added": "2025-09-04",
        "due": "2025-09-25",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Sitecore"
      ],
      "products": [
        "Sitecore Experience Manager (XM)",
        "Sitecore Experience Platform (XP)"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Code Injection.This issue affects Experience Manager (XM): through 9.0; Experience Platform (XP): through 9.0."
    },
    {
      "id": "CVE-2025-9377",
      "url": "https://spydr.io/cve/CVE-2025-9377",
      "published": "2025-08-29T18:15:43.220Z",
      "modified": "2026-06-17T10:08:50.390Z",
      "score": 8.6,
      "severity": "high",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "CNA",
      "epss": 0.33524,
      "epss_percentile": 0.9834,
      "exploited": true,
      "kev": {
        "added": "2025-09-03",
        "due": "2025-09-24",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "TP-Link Systems Inc."
      ],
      "products": [
        "TP-Link Systems Inc. Archer C7(EU) V2",
        "TP-Link Systems Inc. TL-WR841N/ND(MS) V9"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "The authenticated remote command execution (RCE) vulnerability exists in the Parental Control page on TP-Link Archer C7(EU) V2 and TL-WR841N/ND(MS) V9. This issue affects Archer C7(EU) V2: before 241108 and TL-WR841N/ND(MS) V9: before 241108. Both products have reached the status of EOL (end-of-life). It's recommending to purchase the new product to ensure better performance and security. If replacement is not an option in the short term, please use the second reference link to download and install the patch(es)."
    },
    {
      "id": "CVE-2025-55177",
      "url": "https://spydr.io/cve/CVE-2025-55177",
      "published": "2025-08-29T16:15:36.723Z",
      "modified": "2026-06-17T09:41:24.433Z",
      "score": 5.4,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
      "score_source": "fb.com",
      "epss": 0.04304,
      "epss_percentile": 0.90853,
      "exploited": true,
      "kev": {
        "added": "2025-09-02",
        "due": "2025-09-23",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Facebook"
      ],
      "products": [
        "Facebook WhatsApp Desktop for Mac",
        "Facebook WhatsApp Business for iOS",
        "Facebook WhatsApp for iOS"
      ],
      "cwes": [
        "CWE-863"
      ],
      "description": "Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsApp for Mac v2.25.21.78 could have allowed an unrelated user to trigger processing of content from an arbitrary URL on a target’s device. We assess that this vulnerability, in combination with an OS-level vulnerability on Apple platforms (CVE-2025-43300), may have been exploited in a sophisticated attack against specific targeted users."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
