The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added several vulnerabilities to its Known Exploited Vulnerabilities catalog, including flaws in Microsoft Power Pages, Adobe ColdFusion (CVE-2017-3066), and Oracle Agile Product Lifecycle Management (CVE-2024-20953). These vulnerabilities are actively exploited, prompting CISA and the FBI to urge security teams to implement patches and segment their networks. Additionally, a zero-day vulnerability in Parallels Desktop has been reported, allowing for root privilege escalation. Other critical vulnerabilities, such as CVE-2024-56171 and CVE-2025-24928 in Libxml2, and CVE-2025-20051, CVE-2025-24490, and CVE-2025-25279 in Mattermost, have also been flagged for their potential to expose systems to serious security threats, including remote code execution. The FBI has expressed concern over the 'Ghost' cyberattacks affecting organizations in over 70 countries, highlighting the urgency of addressing these security issues.
CVE-2025-27364 (CVSS 10): Remote Code Execution Flaw Found in MITRE Caldera, PoC Releases https://t.co/4rjwre53lQ
Two Actively Exploited Security Flaws in Adobe and Oracle Products Flagged by CISA: https://t.co/6WMLYRBGSZ by The Hacker News #infosec #cybersecurity #technology #news
Critical Mattermost Flaws (CVE-2025-20051, CVE-2025-24490, CVE-2025-25279) Expose Systems to File Read and SQL Injection Attacks https://t.co/UPqEin5F1b