CISA adds two known exploited vulnerabilities to catalog
CISA adds two vulnerabilities affecting XWiki Platform and Broadcom VMware to its KEV Catalog, with federal agencies required to remediate them.
Decision Insights Threat Desk • November 25, 2025
CISA adds two vulnerabilities affecting XWiki Platform and Broadcom VMware to its KEV Catalog, with federal agencies required to remediate them.
Decision Insights Threat Desk • November 25, 2025
CISA added CVE-2025-58034, a Fortinet FortiWeb OS command code injection vulnerability, to the Known Exploited Vulnerabilities Catalog with a one-week remediation guideline.
Decision Insights Threat Desk • November 25, 2025
A vulnerability in Forge's TLS cryptographic library allows crafted ASN.1 data to bypass signature verification.
Decision Insights Threat Desk • November 25, 2025
CISA added CVE-2025-58034, a Fortinet FortiWeb OS command code injection vulnerability, to its Known Exploited Vulnerabilities Catalog. This vulnerability is actively exploited, with a recommended remediation timeframe of one week. Federal agencies are required to address such vulnerabilities under BOD 22-01.
Decision Insights Threat Desk • November 25, 2025
A vulnerability in Shelly Pro 4PM smart DIN rail switches prior to version 1.6 allows attackers to cause denial of service by exploiting a resource allocation flaw in the JSON parser. The issue has a CVSS v4 score of 8.3. Mitigations include software updates and network security measures.
Decision Insights Threat Desk • November 25, 2025
A vulnerability in Shelly Pro 3EM switch allows crafted Modbus requests to trigger device reboots causing denial of service.