CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2025-64446

Fortinet FortiWeb Path Traversal Vulnerability

Vendor: Fortinet

Product: FortiWeb

Added: 2025-11-14

Due Date: 2025-11-21

Description:

Fortinet FortiWeb contains a relative path traversal vulnerability that may allow an unauthenticated attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-23

CVE-2025-12480

Gladinet Triofox Improper Access Control Vulnerability

Vendor: Gladinet

Product: Triofox

Added: 2025-11-12

Due Date: 2025-12-03

Description:

Gladinet Triofox contains an improper access control vulnerability that allows access to initial setup pages even after setup is complete.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-284

CVE-2025-62215

Microsoft Windows Race Condition Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2025-11-12

Due Date: 2025-12-03

Description:

Microsoft Windows Kernel contains a race condition vulnerability that allows a local attacker with low-level privileges to escalate privileges. Successful exploitation of this vulnerability could enable the attacker to gain SYSTEM-level access.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-362

CVE-2025-9242

WatchGuard Firebox Out-of-Bounds Write Vulnerability

Vendor: WatchGuard

Product: Firebox

Added: 2025-11-12

Due Date: 2025-12-03

Description:

WatchGuard Firebox contains an out-of-bounds write vulnerability in the OS iked process that may allow a remote unauthenticated attacker to execute arbitrary code.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-787

CVE-2025-21042

Samsung Mobile Devices Out-of-Bounds Write Vulnerability

Vendor: Samsung

Product: Mobile Devices

Added: 2025-11-10

Due Date: 2025-12-01

Description:

Samsung mobile devices contain an out-of-bounds write vulnerability in libimagecodec.quram.so. This vulnerability could allow remote attackers to execute arbitrary code.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-787

CVE-2025-48703

CWP Control Web Panel OS Command Injection Vulnerability

Vendor: CWP

Product: Control Web Panel

Added: 2025-11-04

Due Date: 2025-11-25

Description:

CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command Injection vulnerability that allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager changePerm request. A valid non-root username must be known.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-78

CVE-2025-11371

Gladinet CentreStack and Triofox Files or Directories Accessible to External Parties Vulnerability

Vendor: Gladinet

Product: CentreStack and Triofox

Added: 2025-11-04

Due Date: 2025-11-25

Description:

Gladinet CentreStack and Triofox contains a files or directories accessible to external parties vulnerability that allows unintended disclosure of system files.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-552

CVE-2025-41244

Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability

Vendor: Broadcom

Product: VMware Aria Operations and VMware Tools

Added: 2025-10-30

Due Date: 2025-11-20

Description:

Broadcom VMware Aria Operations and VMware Tools contain a privilege defined with unsafe actions vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-267

CVE-2025-24893

XWiki Platform Eval Injection Vulnerability

Vendor: XWiki

Product: Platform

Added: 2025-10-30

Due Date: 2025-11-20

Description:

XWiki Platform contains an eval injection vulnerability that could allow any guest to perform arbitrary remote code execution through a request to SolrSearch.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-95

CVE-2025-6204

Dassault Systèmes DELMIA Apriso Code Injection Vulnerability

Vendor: Dassault Systèmes

Product: DELMIA Apriso

Added: 2025-10-28

Due Date: 2025-11-18

Description:

Dassault Systèmes DELMIA Apriso contains a code injection vulnerability that could allow an attacker to execute arbitrary code.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-94

CVE-2025-6205

Dassault Systèmes DELMIA Apriso Missing Authorization Vulnerability

Vendor: Dassault Systèmes

Product: DELMIA Apriso

Added: 2025-10-28

Due Date: 2025-11-18

Description:

Dassault Systèmes DELMIA Apriso contains a missing authorization vulnerability that could allow an attacker to gain privileged access to the application.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-862

CVE-2025-54236

Adobe Commerce and Magento Improper Input Validation Vulnerability

Vendor: Adobe

Product: Commerce and Magento

Added: 2025-10-24

Due Date: 2025-11-14

Description:

Adobe Commerce and Magento Open Source contain an improper input validation vulnerability that could allow an attacker to take over customer accounts through the Commerce REST API.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-20

CVE-2025-59287

Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2025-10-24

Due Date: 2025-11-14

Description:

Microsoft Windows Server Update Service (WSUS) contains a deserialization of untrusted data vulnerability that allows for remote code execution.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-502

CVE-2025-61932

Motex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel Vulnerability

Vendor: Motex

Product: LANSCOPE Endpoint Manager

Added: 2025-10-22

Due Date: 2025-11-12

Description:

Motex LANSCOPE Endpoint Manager contains an improper verification of source of a communication channel vulnerability allowing an attacker to execute arbitrary code by sending specially crafted packets.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-940

CVE-2022-48503

Apple Multiple Products Unspecified Vulnerability

Vendor: Apple

Product: Multiple Products

Added: 2025-10-20

Due Date: 2025-11-10

Description:

Apple macOS, iOS, tvOS, Safari, and watchOS contain an unspecified vulnerability in JavaScriptCore that when processing web content may lead to arbitrary code execution. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.