Cyber Threat Digest – 2025-09-11
🔥 Known Exploited Vulnerabilities (CISA KEV)
8 exploited vulns of note.
- CVE-2025-38352 — Linux Kernel Time-of-Check Time-of-Use (TOCTOU) Race Condition Vulnerability — Linux Kernel (Added: 2025-09-04) — Details
- CVE-2025-48543 — Android Runtime Use-After-Free Vulnerability — Android Runtime (Added: 2025-09-04) — Details
- CVE-2025-53690 — Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability — Sitecore Multiple Products (Added: 2025-09-04) — Details
- CVE-2023-50224 — TP-Link TL-WR841N Authentication Bypass by Spoofing Vulnerability — TP-Link TL-WR841N (Added: 2025-09-03) — Details
- CVE-2025-9377 — TP-Link Archer C7(EU) and TL-WR841N/ND(MS) OS Command Injection Vulnerability — TP-Link Multiple Routers (Added: 2025-09-03) — Details
- CVE-2020-24363 — TP-link TL-WA855RE Missing Authentication for Critical Function Vulnerability — TP-Link TL-WA855RE (Added: 2025-09-02) — Details
- CVE-2025-55177 — Meta Platforms WhatsApp Incorrect Authorization Vulnerability — Meta Platforms WhatsApp (Added: 2025-09-02) — Details
- CVE-2025-57819 — Sangoma FreePBX Authentication Bypass Vulnerability — Sangoma FreePBX (Added: 2025-08-29) — Details
⚠️ Recent CVEs (NVD)
Latest CVEs with CVSS badges.
- CVE-2025-10231 — An Incorrect File Handling Permission bug exists on the N-central Windows Agent and Probe that, in the right circumstances, can allow a local low-level user to run commands with el… HIGH 7.0 — Details
- CVE-2025-56404 — An issue was discovered in MariaDB MCP 0.1.0 allowing attackers to gain sensitive information via the SSE service as the SSE service lacks user validation. HIGH 7.5 — Details
- CVE-2025-56405 — An issue was discovered in litmusautomation litmus-mcp-server thru 0.0.1 allowing unauthorized attackers to control the target's MCP service through the SSE protocol. HIGH 7.5 — Details
- CVE-2025-56406 — An issue was discovered in mcp-neo4j 0.3.0 allowing attackers to gain sensitive information or execute arbitrary commands via the SSE service. HIGH 7.5 — Details
- CVE-2025-56407 — A vulnerability has been found in HuangDou UTCMS V9 and classified as critical. This vulnerability affects the function RunSql of the file app/modules/ut-data/admin/mysql.php. The … HIGH 8.8 — Details
- CVE-2025-56413 — OS Command injection vulnerability in function OperateSSH in 1panel 2.0.8 allowing attackers to execute arbitrary commands via the operation parameter to the /api/v2/hosts/ssh/oper… HIGH 8.8 — Details
📰 Security News
Top headlines from trusted sources.
- DDoS defender targeted in 1.5 Bpps denial-of-service attack
— Wed, 10 Sep 2025 22:09:41 GMT - Microsoft waives fees for Windows devs publishing to Microsoft Store
— Wed, 10 Sep 2025 18:21:30 GMT - Hackers left empty-handed after massive NPM supply-chain attack
— Wed, 10 Sep 2025 17:56:15 GMT - Pixel 10 fights AI fakes with new Android photo verification tech
— Wed, 10 Sep 2025 16:00:00 GMT - Cursor AI editor lets repos "autorun" malicious code on devices
— Wed, 10 Sep 2025 15:46:24 GMT - Jaguar Land Rover confirms data theft after recent cyberattack
— Wed, 10 Sep 2025 15:29:16 GMT
Comments
Post a Comment