CVE-2025-47827
IGEL OS Use of a Key Past its Expiration Date Vulnerability - Active in CISA KEV catalog.
Critical vulnerabilities, curated daily for security professionals
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
Monday morning reveals dramatic weekend threat decline with only 2 critical vulnerabilities (-78% from Sunday) and 14 high-priority CVEs (-69% decrease). However, TODAY is the federal compliance deadline for 4 CISA KEV vulnerabilities (CVE-2025-47827, CVE-2025-24990, CVE-2025-59230, CVE-2016-7836) affecting IGEL OS, Microsoft Windows, and SKYSEA Client View. Organizations must complete immediate remediation or deploy compensating controls before end of business to maintain federal compliance.
Immediate action: IMMEDIATE FEDERAL DEADLINE ACTION: 4 CISA KEV vulnerabilities (CVE-2025-47827, CVE-2025-24990, CVE-2025-59230, CVE-2016-7836) MUST be remediated by end of business TODAY. Deploy emergency patches for IGEL OS, Microsoft Windows, and SKYSEA Client View. Organizations unable to patch must implement compensating controls and prepare exception documentation for federal compliance reporting.
IGEL OS Use of a Key Past its Expiration Date Vulnerability - Active in CISA KEV catalog.
Microsoft Windows Untrusted Pointer Dereference Vulnerability - Active in CISA KEV catalog.
Microsoft Windows Improper Access Control Vulnerability - Active in CISA KEV catalog.
SKYSEA Client View Improper Authentication Vulnerability - Active in CISA KEV catalog.
Adobe Experience Manager Forms Code Execution Vulnerability - Active in CISA KEV catalog.
Apple Multiple Products Unspecified Vulnerability - Active in CISA KEV catalog.
Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability - Active in CISA KEV catalog.
Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability - Active in CISA KEV catalog.
Microsoft Windows SMB Client Improper Access Control Vulnerability - Active in CISA KEV catalog.
Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability - Active in CISA KEV catalog.
Motex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel Vulnerability - Active in CISA KEV catalog.
Adobe Commerce andâ¯Magento Improper Input Validation Vulnerability - Active in CISA KEV catalog.
Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability - Active in CISA KEV catalog.
Dassault Systèmes DELMIA Apriso Code Injection Vulnerability - Active in CISA KEV catalog.
Dassault Systèmes DELMIA Apriso Missing Authorization Vulnerability - Active in CISA KEV catalog.
Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability - Active in CISA KEV catalog.
XWiki Platform Eval Injection Vulnerability - Active in CISA KEV catalog.
The kallyas theme for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4
The Advanced Ads â Ad Manager & AdSense plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2
The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6
The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and excluding, 6
The WPCOM Member plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1
The WP Delicious â Recipe Plugin for Food Bloggers (formerly Delicious Recipes) plugin for WordPress is vulnerable to arbitrary file uploads when importing recipes via CSV in all versions up to, and including, 1
The RESTful Content Syndication plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ingest_image() function in versions 1
The Community Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via event details parameter in all versions up to, and including, 1
IBM i 7
A weakness has been identified in Tenda AC23 16
A security vulnerability has been detected in Tenda AC23 16
A vulnerability has been found in itsourcecode Online Loan Management System 1
A vulnerability was found in itsourcecode Online Loan Management System 1
A vulnerability was determined in itsourcecode Online Loan Management System 1