Sunday, December 14, 2025 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Sunday's vulnerability landscape reveals 3 critical CVEs, a 67% decrease from Saturday's count of 9. High-priority vulnerabilities dropped 47% to 53 issues, reflecting typical weekend reduction patterns. The 11 actively exploited KEV vulnerabilities remain unchanged from yesterday, with notable entries including Android Framework flaws (CVE-2025-48633, CVE-2025-48572), Array Networks ArrayOS AG (CVE-2025-66644), and Microsoft Windows (CVE-2025-62221). Critical WordPress plugin vulnerabilities include CVE-2025-10738 affecting URL Shortener Plugin and CVE-2025-14440 impacting JAY Login. Patch availability stands at 0%, requiring organizations to prioritize network segmentation and access controls as interim mitigations.

  • 3 critical CVEs identified, down 67% from Saturday's 9 critical issues
  • 53 high-priority vulnerabilities, representing 47% decrease from 100 yesterday
  • 11 actively exploited KEV entries targeting Android Framework, Microsoft Windows, Array Networks, and WinRAR
  • 0% patch availability necessitates compensating controls across all affected systems
  • WordPress plugins (URL Shortener, JAY Login, Export WP Page to Static HTML) contain SQL injection flaws at CVSS 9.8

Immediate action: Prioritize mitigation of the 11 actively exploited vulnerabilities, particularly Android Framework and Microsoft Windows flaws affecting enterprise environments. Implement network segmentation and restrict access to vulnerable WordPress installations, D-Link routers, and GeoServer deployments until patches become available. Weekend security teams should monitor for exploitation attempts against KEV-listed products and escalate confirmed activity.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation