Friday, November 28, 2025 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Friday's disclosure activity includes 6 critical vulnerabilities (CVSS 9.8) affecting WordPress plugins and 25 high-priority CVEs. Six actively exploited CISA KEV vulnerabilities require continued remediation across Samsung Mobile, Gladinet Triofox, Microsoft Windows, WatchGuard Firebox, Google Chromium, and Oracle Fusion Middleware systems. Fifteen CVEs have been enhanced with Gemini AI analysis, providing detailed technical context for affected organizations.

  • Six critical CVEs disclosed (CVSS 9.8), primarily affecting WordPress themes and plugins with privilege escalation vulnerabilities
  • Twenty-five high-priority vulnerabilities (CVSS 7.0-8.9) spanning enterprise infrastructure and web applications
  • Six CISA KEV vulnerabilities unchanged from previous day, requiring federal compliance remediation
  • Fifteen CVEs enhanced with Gemini AI analyst comments (6 critical + 9 high-priority), indicated by analysis badge

Immediate action: Security teams should assess organizational exposure to the 6 critical vulnerabilities disclosed today, particularly those running affected WordPress themes and plugins. Priority should be given to CVEs with Gemini AI analysis (indicated by analysis badge) which provide detailed technical context and remediation guidance. Organizations should address the 6 CISA KEV vulnerabilities to meet federal compliance requirements. For systems lacking vendor patches, consider implementing compensating controls such as network segmentation, Web Application Firewall rules, enhanced logging, and access restrictions. Detailed analyst comments are available for 15 CVEs to support remediation planning.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation