Friday, November 21, 2025 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Friday's vulnerability landscape demonstrates significant escalation with 12 critical vulnerabilities (100% increase from yesterday's 6), including two maximum severity CVSS 10.0 issues affecting Azure Bastion and The Itel DAB Encoder. High-priority CVEs decreased 20% from 71 to 57, while nine actively exploited CISA KEV vulnerabilities (13% increase from 8) require priority weekend remediation. The disclosure environment includes eight CVSS 9.8 vulnerabilities enabling unauthenticated remote code execution and authentication bypass attacks. Patch availability declined to 17% from yesterday's 24%, requiring organizations to maintain compensating controls heading into the weekend.

  • Critical CVE count doubled from 6 to 12 vulnerabilities, representing a 100% increase in maximum severity disclosures
  • Two CVSS 10.0 vulnerabilities require immediate assessment: CVE-2025-49752 (Azure Bastion) and CVE-2025-63224 (Itel DAB Encoder)
  • CVE-2025-12057, CVE-2025-59245, CVE-2025-63218, CVE-2025-63223, CVE-2025-10437, CVE-2025-63206, CVE-2025-63210 (CVSS 9.8) enable unauthenticated attacks across enterprise and broadcast infrastructure
  • High-priority vulnerabilities decreased 20% from 71 to 57 CVEs, suggesting focused critical disclosure activity
  • Patch availability declined to 17% (down from 24%), requiring weekend deployment of network segmentation and access controls
  • Nine actively exploited CISA KEV vulnerabilities (13% increase) demand priority remediation before weekend staffing reductions

Immediate action: URGENT WEEKEND ACTION: Security teams must immediately assess CVE-2025-49752 (CVSS 10.0) affecting Azure Bastion cloud infrastructure and CVE-2025-63224 (CVSS 10.0) affecting Itel DAB Encoder systems. Priority patching should address the eight CVSS 9.8 unauthenticated remote code execution and authentication bypass vulnerabilities, particularly CVE-2025-59245 (SharePoint Online), CVE-2025-12057 (WordPress WavePlayer), and CVE-2025-63206 (Dasan Switch) where vendor patches may be available. With only 17% patch availability and weekend approaching, organizations must deploy network segmentation, restrict administrative access, and implement Web Application Firewalls with command injection and authentication bypass detection rules. The nine actively exploited CISA KEV vulnerabilities require immediate remediation before weekend staffing reductions limit response capabilities.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation