Vulnerabilities are weaknesses or flaws in systems, software, hardware, configurations, or processes that adversaries can exploit to compromise confidentiality, integrity, or availability. The concept underpins vulnerability management, regulatory compliance, risk assessment, and security investment decisions across enterprise IT, cloud, and operational technology environments.
Opto 22's groov View software and firmware versions prior to R4.5e and 4.0.3 respectively have a vulnerability exposing sensitive metadata such as API keys. The company has released patches and CISA advises network isolation and VPN use to mitigate potential exploitation risks.
CISA added CVE-2025-21042, an out-of-bounds write flaw in Samsung mobile devices, to its Known Exploited Vulnerabilities catalog due to active exploitation.
CISA reported exploitation of CVE-2025-64446, a relative path traversal vulnerability in Fortinet FortiWeb versions between 7.0.0 and 8.0.1. The flaw allows unauthenticated actors to execute administrative commands via crafted HTTP(S) requests. Fortinet advises upgrading to specified fixed versions or disabling HTTP/HTTPS for external interfaces.