Saturday, November 8, 2025 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Saturday's security landscape presents a critical patch availability crisis as organizations head into the weekend with only 18% of newly disclosed vulnerabilities having vendor patches available. While critical CVE disclosures dropped 75% to just 6 vulnerabilities, 14 actively exploited CISA KEV vulnerabilities demand urgent attention with 5 federal deadlines expiring within the next 5 days including critical flaws in Apple iOS (CVE-2022-48503), Microsoft Windows (CVE-2025-33073), and Kentico CMS (CVE-2025-2746, CVE-2025-2747). The 93 high-priority CVEs represent a 9.4% increase from Friday, with significant impacts to WordPress ecosystems, enterprise infrastructure, and industrial control systems requiring immediate weekend security operations.

  • CISA KEV Crisis: 5 federal compliance deadlines expire within 5 days (November 9-13)
  • Patch Availability Emergency: Only 18% of vulnerabilities have vendor patches available
  • Critical CVEs: 6 vulnerabilities with CVSS 9.0+ scores (down 75% from yesterday)
  • High Priority Surge: 93 vulnerabilities requiring attention (up 9.4% from Friday)
  • Weekend Security Posture: Organizations must prioritize emergency patching for Apple iOS, Microsoft Windows, and Kentico CMS KEV vulnerabilities before Monday

Immediate action: Immediate action: Deploy emergency patches for CISA KEV vulnerabilities CVE-2022-48503 (Apple iOS), CVE-2025-33073 (Microsoft Windows), CVE-2025-2746 and CVE-2025-2747 (Kentico CMS) before November 9 federal deadline. Implement network segmentation and enhanced monitoring for the 82% of vulnerabilities lacking vendor patches. Security teams must maintain weekend staffing for compliance deadlines expiring Sunday and Monday.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation