Wednesday, December 10, 2025 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Wednesday's vulnerability landscape shows increased disclosure activity with eighteen critical vulnerabilities (CVSS 9.0+) and 189 high-priority CVEs requiring assessment. The critical CVE count increased by five issues from Tuesday, while high-priority disclosures increased by 89 vulnerabilities. Ten actively exploited vulnerabilities require priority remediation. The overall critical CVE frequency shows a 54% increase compared to historical averages, marking elevated mid-week disclosure activity with limited patch availability at 9%.

  • Eighteen critical vulnerabilities (CVSS 9.0+), representing a 38% increase from Tuesday's thirteen critical issues
  • 189 high-priority vulnerabilities (CVSS 7.0-8.9), an 89% increase from Tuesday's 100 issues
  • Ten actively exploited vulnerabilities requiring priority remediation across enterprise and critical infrastructure environments
  • Critical CVE frequency increased 54% compared to historical average, indicating elevated mid-week disclosure activity
  • Limited patch availability at 9%, requiring organizations to focus on compensating controls and risk mitigation strategies

Immediate action: Security teams should prioritize assessment of the five newly disclosed critical vulnerabilities and review the 189 high-priority CVEs for applicability to their environments. Organizations should expedite remediation of the ten actively exploited vulnerabilities. Given the limited 9% patch availability, teams should implement compensating controls and network segmentation where patches are not yet available.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation