Cyber Threat Digest – 2025-09-10
🔥 Known Exploited Vulnerabilities (CISA KEV)
8 exploited vulns of note.
- CVE-2025-38352 — Linux Kernel Time-of-Check Time-of-Use (TOCTOU) Race Condition Vulnerability — Linux Kernel (Added: 2025-09-04) — Details
- CVE-2025-48543 — Android Runtime Use-After-Free Vulnerability — Android Runtime (Added: 2025-09-04) — Details
- CVE-2025-53690 — Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability — Sitecore Multiple Products (Added: 2025-09-04) — Details
- CVE-2023-50224 — TP-Link TL-WR841N Authentication Bypass by Spoofing Vulnerability — TP-Link TL-WR841N (Added: 2025-09-03) — Details
- CVE-2025-9377 — TP-Link Archer C7(EU) and TL-WR841N/ND(MS) OS Command Injection Vulnerability — TP-Link Multiple Routers (Added: 2025-09-03) — Details
- CVE-2020-24363 — TP-link TL-WA855RE Missing Authentication for Critical Function Vulnerability — TP-Link TL-WA855RE (Added: 2025-09-02) — Details
- CVE-2025-55177 — Meta Platforms WhatsApp Incorrect Authorization Vulnerability — Meta Platforms WhatsApp (Added: 2025-09-02) — Details
- CVE-2025-57819 — Sangoma FreePBX Authentication Bypass Vulnerability — Sangoma FreePBX (Added: 2025-08-29) — Details
⚠️ Recent CVEs (NVD)
Latest CVEs with CVSS badges.
- CVE-2024-45325 — An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiDDoS-F version 7.0.0 through 7.02 and before… MEDIUM 6.7 — Details
- CVE-2025-33045 — APTIOV contains vulnerabilities in the BIOS where a privileged user may cause "Write-what-where Condition" and "Exposure of Sensitive Information to an Unauthorized Actor" through … HIGH 8.2 — Details
- CVE-2025-47416 — A vulnerability exists in the ConsoleFindCommandMatchList function in libsymproc. so imported by ctpd that may lead to unauthorized execution of an attacker-defined file that gets … MEDIUM 5.9 — Details
- CVE-2025-53609 — A Relative Path Traversal vulnerability [CWE-23] in FortiWeb 7.6.0 through 7.6.4, 7.4.0 through 7.4.8, 7.2.0 through 7.2.11, 7.0.2 through 7.0.11 may allow an authenticated attacke… MEDIUM 4.9 — Details
- CVE-2025-54236 — Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability. A successful attac… CRITICAL 9.1 — Details
- CVE-2025-9951 — A heap-buffer-overflow write exists in jpeg2000dec FFmpeg which allows an attacker to potentially gain remote code execution or cause denial of service via the channel definition c… HIGH 7.2 — Details
📰 Security News
Top headlines from trusted sources.
- Microsoft fixes streaming issues triggered by Windows updates
— Wed, 10 Sep 2025 13:02:44 GMT - Microsoft fixes app install issues caused by August Windows updates
— Wed, 10 Sep 2025 12:02:35 GMT - U.S. sanctions cyber scammers who stole billions from Americans
— Tue, 09 Sep 2025 20:25:49 GMT - Hackers hide behind Tor in exposed Docker API breaches
— Tue, 09 Sep 2025 19:16:30 GMT - Windows 10 KB5065429 update includes 14 changes and fixes
— Tue, 09 Sep 2025 17:57:12 GMT - Microsoft September 2025 Patch Tuesday fixes 81 flaws, two zero-days
— Tue, 09 Sep 2025 17:43:33 GMT
Comments
Post a Comment