Saturday, September 20, 2025 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

This week's security landscape witnessed an unprecedented cascade of critical vulnerabilities with 2 CVSS 10.0 maximum-severity flaws (Logo Software Diva and GoAnywhere MFT), expired federal KEV deadline for Sangoma FreePBX, and WordPress ecosystem under sustained attack with 15+ plugin vulnerabilities. With 8 active CISA KEVs approaching Monday deadlines and only 15% patches available across 400+ weekly vulnerabilities, security teams face significant weekend remediation challenges.

  • WEEK IN REVIEW: 2 CVSS 10.0 flaws, 100+ critical CVEs, 40+ CISA KEVs tracked
  • MONDAY DEADLINE: TP-Link and WhatsApp KEVs expire September 22-23
  • WordPress ecosystem crisis: 15+ critical plugin vulnerabilities this week
  • NeuVector default admin password exposed, Accela platform RCE active
  • 60 new vulnerabilities today with Control Web Panel unauthenticated RCE

Immediate action: WEEKEND PRIORITY: Patch TP-Link routers and WhatsApp before Monday KEV deadline. Address WordPress plugin vulnerabilities immediately. Change all NeuVector admin passwords if running ≤5.4.5.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation