Friday , July 31 2026

Vulnerabilities

Alert: HPE (CVE-2025-37164) warns RCE flaw and ASUS (CVE-2025-59374) Flaw added in KEV

Hewlett Packard Enterprise (HPE) has fixed a critical vulnerability in its OneView software that allowed remote code execution. OneView is HPE’s software for managing infrastructure, helping IT admins streamline server, storage, and network management. Vietnamese researcher Nguyen Quoc Khanh (brocked200) reported the critical security flaw (CVE-2025-37164) to the company’s security …

Read More »

CISA added Actively Exploited Apple WebKit 0-Day Flow

zero-day

CISA has listed a critical zero-day vulnerability affecting various Apple products in its Known Exploited Vulnerabilities catalog, indicating it is being actively exploited. CVE-2025-43529 is a severe use-after-free vulnerability in WebKit, Apple’s rendering engine, affecting millions of users on iOS, iPadOS, macOS, and other Apple platforms. A use-after-free vulnerability (CWE-416) …

Read More »

Critical FortiGate Vulnarability Under Active Attack

Critical

Threat actors started to exploit two critical flaws (CVE: 2025-59718 and CVE: 2025-59719 in Fortinet FortiGate devices. Unauthenticated attackers can exploit these vulnerabilities to bypass SSO login protections using crafted SAML messages when FortiCloud SSO is enabled on affected devices. December 12, 2025, Arctic Wolf identified coordinated attacks using malicious …

Read More »

Apple Patches Two Critical WebKit Zero-Days Under Active Exploitation

WebKit

Apple has urgently patched two critical zero-day vulnerabilities in the WebKit browser engine affecting iPhone and iPad users. The company revealed these flaws are actively exploited, enabling advanced attacks on high-risk targets. Vulnerabilities CVE-2025-43529 and CVE-2025-14174 let attackers run malicious code if a victim visits a specific web page. WebKit …

Read More »

20 Top Most Exploited Vulns of 2025

exploited

In 2025, many CVEs were exploited, averaging a CVSS severity rating of 8.5, with two hitting the maximum of 10.0, highlighting their critical importance. Most Exploited Vulnerabilities of 2025: CVE-2025-55182: React2Shell CVE-2025-32433: Erlang/OTP SSH Zero-Day Crisis CVE-2025-59287: Microsoft WSUS Deserialization Vulnerability CVE-2025-62221: Windows Cloud Files Driver Zero-Day CVE-2025-62215: Windows Kernel …

Read More »

Alert: CISA orders feds to patch actively exploited Geoserver flaw urgently

Geoserver

CISA has ordered U.S. federal agencies to fix a serious GeoServer vulnerability that is currently being exploited in XML External Entity (XXE) injection attacks. CISA reported a security flaw (CVE-2025-58360) on Thursday, an unauthenticated XML External Entity (XXE) vulnerability in GeoServer 2.26.1 and earlier versions. This open-source server for geospatial …

Read More »

India-based CCTV cameras flaw allow attacker stealing video feeds, credentials

CCTV

A severe security flaw has been revealed in various CCTV camera brands in India. This vulnerability enables attackers to access video feeds and steal login information without needing to authenticate. CISA issued an alert on December 9, 2025, with code ICSA-25-343-03. Identifying threats from D-Link India Limited, Sparsh Securitech, and …

Read More »

SAP fixes 3 critical vulns across multiple products

3

SAP’s December security updates have fixed 14 vulnerabilities in various products, including 3 critical ones. CVE-2025-42880, a code injection flaw with a CVSS score of 9.9, is the most critical issue affecting SAP Solution Manager ST 720. “Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to …

Read More »

FortiOS, FortiWeb, and FortiProxy Vuln Allow Bad Actors Bypass FortiCloud SSO Flaw

FortiProxy

Fortinet released security updates for critical vulnerabilities in FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager that could let attackers bypass FortiCloud SSO authentication. Threat actors can exploit the security flaws CVE-2025-59718 and CVE-2025-59719 by taking advantage of weaknesses in cryptographic signature verification in affected products using a malicious SAML message. Fortinet stated …

Read More »

Microsoft patched 3 zero days with 56 vulns in December 2025 Patch Tuesday

56

Microsoft’s last Patch Tuesday updates of 2025 on December fixed 56 vulnerabilities in Windows, Office, Exchange Server, and more. This update addresses 3 serious security issues: two remote code execution problems that have been made public and one vulnerability that allows attackers to gain elevated permissions. Several critical issues are …

Read More »