Wednesday, November 19, 2025 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Wednesday's vulnerability landscape demonstrates continued disclosure activity with 6 critical vulnerabilities (50% increase from yesterday's 4) and 86 high-priority vulnerabilities (69% increase from 51). The primary concerns include three CVSS 9.8 vulnerabilities enabling unauthenticated remote code execution across multiple affected devices, alongside three CVSS 9.1 vulnerabilities in SolarWinds Serv-U requiring administrative privileges for exploitation. Patch availability improved modestly to 10% from yesterday's 7%, requiring organizations to maintain compensating controls for the majority of newly disclosed vulnerabilities. Ten actively exploited CISA KEV vulnerabilities continue to require priority remediation across VMware, Fortinet, Microsoft, and Samsung products.

  • Critical vulnerability count increased 50% from 4 to 6 CVEs, with three unauthenticated remote code execution vulnerabilities rated CVSS 9.8
  • CVE-2025-41734 (CVSS 9.8) enables unauthenticated remote attackers to execute arbitrary PHP files and gain full device access
  • CVE-2025-9312 (CVSS 9.8) exposes missing authentication enforcement in mutual TLS implementations across affected devices
  • High-priority vulnerabilities increased 69% from 51 to 86 CVEs, indicating sustained midweek disclosure activity
  • Patch availability improved to 10% (up from 7%), requiring continued deployment of WAF rules, network segmentation, and access restrictions for unpatched vulnerabilities
  • Ten actively exploited CISA KEV vulnerabilities require continued priority remediation, including VMware Aria Operations, Fortinet FortiWeb, and Microsoft Windows flaws

Immediate action: Security teams must immediately address the three unauthenticated remote code execution vulnerabilities (CVE-2025-41734, CVE-2025-9312, CVE-2025-41733) by applying vendor patches where available or implementing network segmentation and access controls. Organizations running SolarWinds Serv-U should evaluate the three CVSS 9.1 vulnerabilities (CVE-2025-40547, CVE-2025-40548, CVE-2025-40549) and restrict administrative access as a compensating control. With 90% of new vulnerabilities lacking vendor patches, implement Web Application Firewalls with command injection and authentication bypass detection rules. Continue priority remediation of the ten actively exploited vulnerabilities while monitoring for the six new critical disclosures.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation