Weekend Edition: September 27-28, 2025 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

This week's security landscape witnessed unprecedented chaos with a critical Nx supply chain attack targeting thousands of development pipelines, multiple EXPIRED federal KEV deadlines for Cisco firewall vulnerabilities under active exploitation, and a surge in WordPress plugin compromises. The week began with 38 critical CVEs on Monday, peaked with supply chain attacks mid-week, and ended with emergency Cisco patches. With over 150 critical vulnerabilities and 500+ high-priority issues disclosed this week, including 20+ CISA KEV entries, organizations face an overwhelming remediation burden heading into the weekend.

  • WEEK IN CRISIS: 150+ critical CVEs including supply chain attacks and expired federal deadlines
  • Nx build system compromised via malicious npm packages affecting enterprise CI/CD pipelines
  • Multiple Cisco ASA/FTD firewall vulnerabilities with EXPIRED federal compliance deadlines
  • WordPress ecosystem under siege with 15+ plugin vulnerabilities enabling site takeover
  • Google Chrome V8 engine zero-day (CVE-2025-10585) actively exploited in the wild
  • SolarWinds Web Help Desk RCE and multiple database exposure incidents
  • CISA KEV catalog expanded with 20+ entries requiring immediate federal response

Immediate action: WEEKEND EMERGENCY RESPONSE REQUIRED: Organizations must dedicate weekend resources to address the backlog of critical vulnerabilities from this week. Priority #1: Patch all Cisco firewall vulnerabilities with expired KEV deadlines. Priority #2: Audit npm dependencies for Nx supply chain compromise. Priority #3: Update all WordPress plugins with known vulnerabilities. Security teams should maintain 24/7 monitoring throughout the weekend given the high volume of unpatched critical issues.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation