Wednesday, December 31, 2025 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Yesterday's disclosures include 20 critical-severity vulnerabilities, marking a 122% increase from the prior day's 9 critical CVEs. High-priority vulnerabilities also increased substantially with 100 CVEs representing a 52% rise. Eight actively exploited vulnerabilities remain on the KEV list, including CVE-2025-58360 affecting OSGeo GeoServer, CVE-2025-14174 in Google Chromium, and CVE-2025-43529 impacting Apple products. Notable critical disclosures include multiple Improper Control of Filename vulnerabilities (CVE-2025-68974, CVE-2025-68987, CVE-2025-68983) with CVSS 9.8 scores affecting multiple products, plus CVE-2025-15255 targeting Tenda devices. Patch availability stands at 0%, requiring organizations to prioritize compensating controls and monitoring.

  • 20 critical CVEs disclosed (122% increase from prior day's 9)
  • 100 high-priority CVEs identified (52% increase from 66)
  • 8 actively exploited vulnerabilities including GeoServer, Chromium, Apple, and MongoDB
  • 0% patch availability for disclosed vulnerabilities
  • Multiple products affected by filename control vulnerabilities (CVSS 9.8)
  • Tenda, Sierra Wireless, ASUS, and Gladinet products among affected vendors

Immediate action: Organizations using GeoServer, Chromium, Apple products, MongoDB, Tenda devices, Sierra Wireless AirLink, ASUS Live Update, or Gladinet CentreStack should implement additional monitoring and access controls. With 0% patch availability for today's disclosures, focus on network segmentation and detection capabilities for affected systems.

How to read this brief

CVSS score (e.g. 9.1) โ€” severity from 0โ€“10. Red marks critical (9+), orange high (7โ€“8.9).

Exploitability โ€” how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical โ€” how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges โ€” the access they need first. No privileges means no login required.
  • No interaction / User interaction โ€” whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale โ€” โ€œNetwork ยท No privileges ยท No interactionโ€ is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited โ€” confirmed under attack in the wild (CISAโ€™s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS ยท Nth percentile โ€” FIRST.orgโ€™s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% โ€” a statistical signal itโ€™s unusually likely to be targeted, separate from whether attacks are confirmed.

๐Ÿ’ก Tip: Swipe CVE cards left to โญ star, right to โŒ remove

Section Navigation