Monday, November 17, 2025 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Monday's security landscape shows lower disclosure activity following the weekend, with no newly disclosed critical CVEs (CVSS 9.0+) and 15 high-priority vulnerabilities identified. The week begins with three D-Link router command injection vulnerabilities (CVE-2025-13189, CVE-2025-13190, CVE-2025-13191) allowing unauthenticated remote code execution, each rated CVSS 8.8. Patch availability remains at 0% for new disclosures, requiring organizations to implement compensating controls while awaiting vendor updates. Eleven actively exploited CISA KEV vulnerabilities continue to require priority remediation, with two Dassault Systèmes DELMIA Apriso vulnerabilities reaching their remediation timeline. The decrease in critical CVEs represents a 100% reduction from Sunday's four disclosures, while high-priority issues dropped 42% from 26 to 15 vulnerabilities.

  • Critical CVEs: Zero new critical vulnerabilities disclosed, down 100% from yesterday's 4
  • High-priority vulnerabilities: 15 issues requiring attention, down 42% from yesterday's 26
  • Patch availability: 0% of new vulnerabilities have vendor patches currently available
  • D-Link routers: Three unauthenticated remote code execution vulnerabilities (CVSS 8.8) in DIR-816L firmware
  • Actively exploited vulnerabilities: 11 CISA KEV entries require priority patching
  • Week start: Lower vulnerability disclosure activity following weekend period

Immediate action: Immediate action: Apply vendor patches for three D-Link DIR-816L router vulnerabilities (CVE-2025-13189, CVE-2025-13190, CVE-2025-13191) allowing unauthenticated remote code execution. Restrict administrative interface access to trusted networks and implement firewall rules blocking external management port access for unpatched devices. Priority patching recommended for 11 actively exploited CISA KEV vulnerabilities, particularly two Dassault Systèmes DELMIA Apriso vulnerabilities (CVE-2025-6204, CVE-2025-6205) approaching remediation timelines. Organizations should monitor for WordPress plugin vulnerabilities (CVE-2025-12482) and legacy system disclosures while awaiting patch releases.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation