Cyber Threat Digest – 2025-09-26
🔥 Known Exploited Vulnerabilities (CISA KEV)
2 exploited vulns of note in the last 48 hours.
- CVE-2025-20362 — Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Missing Authorization Vulnerability — Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense (Added: 2025-09-25) — Details
- CVE-2025-20333 — Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Buffer Overflow Vulnerability — Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense (Added: 2025-09-25) — Details
⚠️ Recent CVEs (NVD)
Latest CVEs with CVSS badges.
- CVE-2025-10467 — Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PROLIZ Computer Software Hardware Service Trade Ltd. Co. OBS (Student A… HIGH 8.9 — Details
- CVE-2025-10540 — iMonitor EAM 9.6394 transmits communication between the EAM client agent and the EAM server, as well as between the EAM monitor management software and the server, in plaintext wit… MEDIUM 6.5 — Details
- CVE-2025-10948 — A vulnerability has been found in MikroTik RouterOS 7. This affects the function parse_json_element of the file /rest/ip/address/print of the component libjson.so. The manipulation… HIGH 7.4 — Details
- CVE-2025-26278 — A prototype pollution in the lib.set function of dref v0.1.2 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload. HIGH 7.5 — Details
- CVE-2025-27261 — Ericsson Indoor Connect 8855 contains a SQL injection vulnerability which if exploited can lead to unauthorized disclosure and modification of user and configuration data. HIGH 8.7 — Details
- CVE-2025-57317 — apidoc-core is the core parser library to generate apidoc result following the apidoc-spec. A Prototype Pollution vulnerability in the preProcess function of apidoc-core versions t… HIGH 7.5 — Details
📰 Security News
Top headlines from trusted sources.
- Maximum severity GoAnywhere MFT flaw exploited as zero day
— Fri, 26 Sep 2025 13:50:42 GMT - Microsoft releases the final Windows 10 22H2 preview update
— Fri, 26 Sep 2025 13:32:07 GMT - Microsoft warns of new XCSSET macOS malware variant targeting Xcode devs
— Thu, 25 Sep 2025 22:49:22 GMT - Unofficial Postmark MCP npm silently stole users' emails
— Thu, 25 Sep 2025 20:23:34 GMT - Co-op says it lost $107 million after Scattered Spider attack
— Thu, 25 Sep 2025 18:05:14 GMT - CISA orders agencies to patch Cisco flaws exploited in zero-day attacks
— Thu, 25 Sep 2025 17:52:55 GMT
Comments
Post a Comment