Monday, December 22, 2025 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Monday's vulnerability landscape includes 4 critical CVEs (CVSS 9.0+), a 100% increase from yesterday's 2 critical disclosures. High-priority vulnerabilities decreased to 19 from yesterday's 39, representing a 51% reduction. The 17 actively exploited (KEV) vulnerabilities include threats affecting Fortinet products, Android Framework, SonicWall SMA1000, Cisco products, and Microsoft Windows. Notable critical disclosures include CVE-2025-15006 and CVE-2025-15007 affecting Tenda products, and CVE-2025-15016 impacting Ragic Enterprise Cloud Database, all with CVSS 9.8 scores. Patch availability currently stands at 0%, requiring organizations to implement compensating controls while monitoring for vendor updates.

  • 4 critical vulnerabilities disclosed, up 100% from yesterday's 2 critical CVEs
  • 19 high-priority CVEs, down 51% from yesterday's 39 high-severity disclosures
  • 17 actively exploited vulnerabilities affecting Fortinet, Android, SonicWall, Cisco, Microsoft, and Apple products
  • 0% patch availability requires immediate implementation of compensating controls
  • Multiple Tenda products and Ragic Enterprise Cloud Database among critical disclosures with CVSS 9.8

Immediate action: Prioritize network segmentation and access controls for systems affected by KEV vulnerabilities, particularly Fortinet, SonicWall SMA1000, and Cisco products. Monitor vendor security advisories for patch releases and implement network-based detection for exploitation attempts. Beginning-of-week staffing should account for elevated KEV count requiring coordinated response across security teams.

How to read this brief

CVSS score (e.g. 9.1) β€” severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability β€” how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical β€” how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges β€” the access they need first. No privileges means no login required.
  • No interaction / User interaction β€” whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale β€” β€œNetwork Β· No privileges Β· No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited β€” confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS Β· Nth percentile β€” FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% β€” a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

πŸ’‘ Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation