Weekend Edition: September 13-14, 2025 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

This week witnessed extraordinary volatility in the security landscape, with critical vulnerabilities surging to 40 on Wednesday before dropping to 18 by Friday. The WordPress ecosystem faced relentless attacks with over 50 plugin vulnerabilities disclosed, while enterprise platforms including SAP NetWeaver (CVSS 9.9), Microsoft HPC Pack, and Delta Electronics industrial systems suffered severe authentication and code execution flaws. Organizations struggled with historically low patch availability, forcing widespread deployment of compensating controls.

  • 📊 Week's roller coaster: Critical CVEs peaked at 40 Wednesday, ended at 18 Friday - extreme volatility
  • 🔌 WordPress crisis: 50+ plugin vulnerabilities this week mark worst plugin security event of 2025
  • 🏭 Industrial systems at risk: Delta Electronics CVSS 10.0 and multiple SQL injection clusters threaten operations
  • 💼 Enterprise platforms compromised: SAP NetWeaver, Microsoft HPC, Citrix, and Git face authentication bypasses
  • 📈 Patch availability improved to 35% by Friday but remains insufficient for the volume of threats

Immediate action: Weekend priorities: Audit all WordPress plugins, patch SAP NetWeaver and Microsoft HPC systems, implement network segmentation for industrial control systems, and prepare incident response teams for potential exploitation of unpatched vulnerabilities.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation