Thursday, November 13, 2025 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Thursday's security environment reveals a significant shift in threat patterns with 3 critical vulnerabilities (down 40% from Wednesday) and 100 high-priority issues (up 186% from yesterday's 35 disclosures), marking a dramatic mid-week surge in disclosure activity. The threat landscape is dominated by authentication bypass flaws in Dell Data Lakehouse (CVE-2025-46608, CVSS 9.1) and dual critical vulnerabilities in aEnrich a+HRD (CVE-2025-12870, CVE-2025-12871, both CVSS 9.8). With 12 actively exploited vulnerabilities and only 8% patch availability, organizations face heightened risk. Two urgent CISA KEV deadlines pass today (November 13) for Adobe Commerce and Microsoft Windows WSUS, both rated CVSS 9.5, while two additional Dassault DELMIA Apriso vulnerabilities approach deadlines on November 17.

  • Critical vulnerabilities: 3 CVSS 9.0+ issues (down 40% from Wednesday's 5)
  • High-priority surge: 100 CVEs disclosed (186% increase from yesterday's 35)
  • Active exploitation: 12 vulnerabilities in CISA KEV catalog (up 20% from 10)
  • URGENT DEADLINES TODAY: Adobe Commerce CVE-2025-54236 and Microsoft WSUS CVE-2025-59287 (both CVSS 9.5)
  • Patch availability: Only 8% of disclosed vulnerabilities have vendor patches
  • Authentication threats: Dual CVSS 9.8 bypasses in aEnrich a+HRD HR management platform
  • Enterprise impact: Dell Data Lakehouse privilege escalation (CVSS 9.1) threatens data integrity
  • Approaching deadlines: Dassault DELMIA Apriso CVE-2025-6204 and CVE-2025-6205 due November 17

Immediate action: IMMEDIATE ACTION REQUIRED: Patch Adobe Commerce and Microsoft WSUS systems before end of day to meet federal deadline. Organizations using Dell Data Lakehouse or aEnrich a+HRD must prioritize emergency patching for CVSS 9.0+ authentication bypass vulnerabilities.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation