Critical vulnerabilities, curated daily for security professionals
📊
Archived Security Brief
Sunday's security landscape reveals notable activity with two maximum-severity CVSS 10.0 vulnerabilities affecting General Industrial Controls products and Desktop Alert PingAlert systems. The weekend disclosure includes 4 critical CVEs (CVSS 9.0+) and 26 high-priority vulnerabilities, representing a 25% increase in critical disclosures compared to Friday while high-priority issues decreased by 49%. Patch availability remains limited at 16%, requiring organizations to implement compensating controls for unpatched systems. Eleven actively exploited CISA KEV vulnerabilities continue to demand attention, including recent additions affecting VMware Aria Operations (CVE-2025-41244), Microsoft Windows (CVE-2025-62215), and Fortinet FortiWeb (CVE-2025-64446). Industrial control systems face heightened risk this weekend with authentication bypass flaws enabling remote device resets.
Critical CVEs: 4 critical vulnerabilities disclosed, up 25% from yesterday's 4
High-priority vulnerabilities: 26 issues requiring attention, down 49% from yesterday's 51
Patch availability: 16% of new vulnerabilities have vendor patches available
Weekend security posture: Organizations should monitor industrial control systems for authentication bypass attempts
Immediate action: Immediate action: Deploy patches for the two CVSS 10.0 industrial control vulnerabilities (CVE-2025-58083 affecting General Industrial Controls Lynx+ Gateway, CVE-2025-54339 affecting Desktop Alert PingAlert). Implement network segmentation and access controls for unpatched ICS components. Priority patching recommended for 11 actively exploited CISA KEV vulnerabilities, particularly CVE-2025-64446 (Fortinet FortiWeb path traversal), CVE-2025-62215 (Microsoft Windows), and CVE-2025-41244 (VMware Aria Operations). Monitor industrial control system web interfaces for unauthorized reset attempts and unexpected device reboots.
How to read this brief
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
No / Low / High privileges — the access they need first. No privileges means no login required.
No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove
Section Navigation
⚠️
CISA Known Exploited Vulnerabilities
⚠️ CISA KEVURGENT
CVE-2025-6204
9.5
Dassault SystèmesDELMIA Apriso
🔴 Actively exploited in the wild
Dassault Systèmes DELMIA Apriso Code Injection Vulnerability - Active in CISA KEV catalog.
XWiki Platform Eval Injection Vulnerability - Active in CISA KEV catalog.
⚠️ CISA KEVURGENT
CVE-2025-64446
9.8
A relative path traversal vulnerability in Fortinet FortiWebMultiple Products
🔴 Actively exploited in the wild
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.
General Industrial Controls Lynx+ Gateway
is missing critical authentication in the embedded web server which could allow an attacker to remotely reset the device.
Information Disclosure in web-accessible backup file in SourceCodester Simple Online Book Store System allows a remote unauthenticated attacker to disclose full database contents (including schema and credential hashes) via an unauthenticated HTTP GET request to /obs/database/obs_db
The SNORDIAN's H5PxAPIkatchu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'insert_data' AJAX endpoint in all versions up to, and including, 0
Nero BackItUp in the Nero Productline is vulnerable to a path parsing/UI rendering flaw (CWE-22) that, in combination with Windows ShellExecuteW fallback extension resolution, leads to arbitrary code execution when a user clicks a crafted entry
General Industrial Controls Lynx+ Gateway is vulnerable to a weak password requirement vulnerability, which may
allow an attacker to execute a brute-force attack resulting in
unauthorized access and login
IQ-Support developed by IQ Service International has an Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Relative Path Traversal to download arbitrary system files
General Industrial Controls Lynx+ Gateway is missing critical authentication in the embedded web server which
could allow an attacker to send GET requests to obtain sensitive device
information
General Industrial Controls Lynx+ Gateway is vulnerable to a cleartext transmission vulnerability that could allow
an attacker to observe network traffic to obtain sensitive information,
including plaintext credentials
Authorization Bypass Through User-Controlled Key, Weak Password Recovery Mechanism for Forgotten Password, Authentication Bypass by Assumed-Immutable Data vulnerability in Optimus Software Brokerage Automation allows Exploiting Trust in Client, Authentication Bypass, Manipulate Registry Information
Brightpick Mission Control
discloses device telemetry, configuration, and credential information
via WebSocket traffic to unauthenticated users when they connect to a
specific URL
CVE-2025-9317
8.4
reverseMultiple Products
The vulnerability, if exploited, could allow a miscreant with read
access to Edge Project files or Edge Offline Cache files to reverse
engineer Edge users' app-native or Active Directory passwords through
computational brute-forcing of weak hashes
CVE-2025-54346
7.6
ApplicationMultiple Products
A Reflected Cross Site Scripting (XSS) vulnerability was found in the Application Server of Desktop Alert PingAlert version 6
CVE-2025-54345
7.5
ApplicationMultiple Products
An issue was found in the Application Server of Desktop Alert PingAlert version 6
CVE-2025-13033
7.5
wasMultiple Products
A vulnerability was identified in the email parsing library due to improper handling of specially formatted recipient email addresses
CVE-2025-13169
7.3
ReservationMultiple Products
A security vulnerability has been detected in code-projects Simple Online Hotel Reservation System 1
CVE-2025-13170
7.3
ReservationMultiple Products
A vulnerability was detected in code-projects Simple Online Hotel Reservation System 1
CVE-2025-13204
7.3
npmMultiple Products
npm package `expr-eval` is vulnerable to Prototype Pollution