Tuesday, November 18, 2025 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Tuesday's security landscape reveals a significant escalation in vulnerability disclosures following Monday's quiet period, with 4 new critical vulnerabilities requiring immediate attention. The WordPress W3 Total Cache plugin command injection vulnerability (CVE-2025-9501, CVSS 9.0) poses the most immediate threat to organizations, allowing unauthenticated attackers to execute arbitrary commands through malicious comment submissions. High-priority vulnerabilities surged 240% from 15 to 51 issues, while patch availability remains critically low at 7%, requiring organizations to implement compensating controls. Nine actively exploited CISA KEV vulnerabilities continue to demand priority remediation across VMware, Fortinet, and Microsoft products.

  • WordPress W3 Total Cache command injection (CVE-2025-9501, CVSS 9.0) enables unauthenticated remote code execution via comment submission with public exploit code available
  • Three additional critical vulnerabilities disclosed: PHPGurukul SQL injection (CVE-2024-44659), ThinPLUS command injection (CVE-2025-13284), and QaTraq default credentials (CVE-2025-63747), all rated CVSS 9.8
  • High-priority CVE count surged 240% from 15 to 51 vulnerabilities, indicating accelerated disclosure activity following Monday's quieter period
  • Patch availability at 7% requires immediate deployment of compensating controls including WAF rules, network segmentation, and access restrictions
  • Nine CISA KEV vulnerabilities require continued priority remediation, including VMware Aria Operations, Fortinet FortiWeb, and Microsoft Windows flaws
  • Multiple unauthenticated remote code execution flaws across web applications demand immediate attention from security teams

Immediate action: Security teams must immediately update WordPress W3 Total Cache to version 2.8.13 or later and review web server logs for comment submission exploitation attempts. Organizations with limited patch availability should deploy Web Application Firewalls with command injection and SQL injection detection rules. Priority remediation of the nine active CISA KEV vulnerabilities should continue while monitoring for the four new critical disclosures. All affected systems should be treated as potentially compromised until verified secure through log analysis and system integrity checks.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation