Several critical cybersecurity vulnerabilities have been recently addressed by major technology companies amid active exploitation attempts. Citrix patched three flaws in its NetScaler product, including CVE-2025-7775, which is currently being exploited in the wild and allows attackers to execute remote code or crash systems. Docker released an update (v4.44.3) to fix a critical container escape vulnerability (CVE-2025-9074) with a CVSS score of 9.3, which permits malicious containers to hijack host systems, notably allowing full access to the C:\ drive on Windows and elevated privileges. Apple issued an emergency software update to fix a zero-day vulnerability (CVE-2025-43300) involving an out-of-bounds write defect affecting its popular devices. Additionally, a critical flaw in Microsoft’s on-premises SharePoint, initially patched but soon bypassed by hackers linked to China, has exposed hundreds of organizations, including the U.S. Nuclear Weapons Safety Agency. Another vulnerability in Git (CVE-2025-48384) leading to remote code execution is also under active exploitation. These developments underscore ongoing cybersecurity challenges, with no available workarounds for some flaws, emphasizing the urgency for organizations to apply patches promptly.
CPPA Adopts ADMT, Cybersecurity and Risk Assessment Regulations https://t.co/0Wu2RJuZAd | by @SheppardMullin
Git vulnerability leading to RCE is being exploited by attackers (CVE-2025-48384) https://t.co/uviZx3ZS42
Commentary: A critical flaw in Microsoft’s on-premises SharePoint, initially patched but soon bypassed by hackers linked to China, has exposed hundreds of organizations — including the U.S. Nuclear Weapons Safety Agency. https://t.co/DV36hrZXna