Vulnerabilities are weaknesses or flaws in systems, software, hardware, configurations, or processes that adversaries can exploit to compromise confidentiality, integrity, or availability. The concept underpins vulnerability management, regulatory compliance, risk assessment, and security investment decisions across enterprise IT, cloud, and operational technology environments.
CISA updated its alert to include two vulnerabilities, CVE-2025-64446 and CVE-2025-58034, affecting Fortinet FortiWeb web application firewalls. Exploitation of these could lead to unauthenticated remote code execution. Fortinet recommends upgrading to specified versions or disabling HTTP/HTTPS access for internet-facing interfaces.
CISA added a new vulnerability, CVE-2025-61757, involving missing authentication in Oracle Fusion Middleware, to its Known Exploited Vulnerabilities Catalog due to active exploitation. Federal agencies must remediate it per Binding Operational Directive 22-01. CISA urges all organizations to prioritize addressing such vulnerabilities.
CISA includes CVE-2021-26829 OpenPLC ScadaBR XSS vulnerability in its Known Exploited Vulnerabilities Catalog following reports of active exploitation.