Cyber Threat Digest – 2025-09-09
🔥 Known Exploited Vulnerabilities (CISA KEV)
8 exploited vulns of note.
- CVE-2025-38352 — Linux Kernel Time-of-Check Time-of-Use (TOCTOU) Race Condition Vulnerability — Linux Kernel (Added: 2025-09-04) — Details
- CVE-2025-48543 — Android Runtime Use-After-Free Vulnerability — Android Runtime (Added: 2025-09-04) — Details
- CVE-2025-53690 — Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability — Sitecore Multiple Products (Added: 2025-09-04) — Details
- CVE-2023-50224 — TP-Link TL-WR841N Authentication Bypass by Spoofing Vulnerability — TP-Link TL-WR841N (Added: 2025-09-03) — Details
- CVE-2025-9377 — TP-Link Archer C7(EU) and TL-WR841N/ND(MS) OS Command Injection Vulnerability — TP-Link Multiple Routers (Added: 2025-09-03) — Details
- CVE-2020-24363 — TP-link TL-WA855RE Missing Authentication for Critical Function Vulnerability — TP-Link TL-WA855RE (Added: 2025-09-02) — Details
- CVE-2025-55177 — Meta Platforms WhatsApp Incorrect Authorization Vulnerability — Meta Platforms WhatsApp (Added: 2025-09-02) — Details
- CVE-2025-57819 — Sangoma FreePBX Authentication Bypass Vulnerability — Sangoma FreePBX (Added: 2025-08-29) — Details
⚠️ Recent CVEs (NVD)
Latest CVEs with CVSS badges.
- CVE-2025-22956 — OPSI before 4.3 allows any client to retrieve any ProductPropertyState, including those of other clients. This can lead to privilege escalation if any ProductPropertyState contains… — Details
- CVE-2025-36853 — A vulnerability (CVE-2025-21172) exists in msdia140.dll due to integer overflow and heap-based overflow. Per CWE-122: Heap-based Buffer Overflow, a heap overflow condition is a b… HIGH 7.5 — Details
- CVE-2025-36854 — A vulnerability ( CVE-2024-38229 https://www.cve.org/CVERecord ) exists in EOL ASP.NET when closing an HTTP/3 stream while application code is writing to the response body, a race … HIGH 8.1 — Details
- CVE-2025-36855 — A vulnerability ( CVE-2025-21176 https://www.cve.org/CVERecord ) exists in DiaSymReader.dll due to buffer over-read. Per CWE-126: Buffer Over-read https://cwe.mitre.org/data/def… HIGH 8.8 — Details
- CVE-2022-50238 — The on-endpoint Microsoft vulnerable driver blocklist is not fully synchronized with the online Microsoft recommended driver block rules. Some entries present on the online list ha… — Details
- CVE-2025-40928 — JSON::XS before version 4.04 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified impact HIGH 7.5 — Details
📰 Security News
Top headlines from trusted sources.
- Microsoft: Anti-spam bug blocks links in Exchange Online, Teams
— Tue, 09 Sep 2025 13:40:58 GMT - SAP fixes maximum severity NetWeaver command execution flaw
— Tue, 09 Sep 2025 13:18:11 GMT - Microsoft testing new AI features in Windows 11 File Explorer
— Tue, 09 Sep 2025 11:41:12 GMT - Plex tells users to reset passwords after new data breach
— Tue, 09 Sep 2025 01:03:02 GMT - Surge in networks scans targeting Cisco ASA devices raise concerns
— Mon, 08 Sep 2025 21:44:50 GMT - Hackers steal 3,325 secrets in GhostAction GitHub supply chain attack
— Mon, 08 Sep 2025 19:53:59 GMT
Comments
Post a Comment