Recent cybersecurity reports have highlighted multiple critical vulnerabilities affecting various systems. Notably, researchers identified two severe flaws in mySCADA myPRO, designated CVE-2025-20014 and CVE-2025-20061, which have a CVSS score of 9.3. These vulnerabilities could allow attackers to execute system commands and potentially hijack operations, posing a risk of full industrial network compromise. Additionally, an Apache Tomcat remote code execution flaw (CVE-2025-24813) is being actively exploited, allowing unauthorized control via a simple unauthenticated PUT request. Affected versions include Tomcat 9.0.0.M1 through 11.0.2, with a fix available in versions 9.0.99, 10.1.35, and 11.0.3. Furthermore, the Cybersecurity and Infrastructure Security Agency (CISA) has flagged a backup flaw (CVE-2024-48248) in NAKIVO Backup & Replication, which exposes sensitive data and credentials. Veeam Backup has also released a patch for a critical 9.9 vulnerability that allows remote code execution, affecting version 12.3.0.310 and earlier. Users are urged to update their systems promptly to mitigate these risks.
Backup and recovery company @Veeam released a patch for a critical 9.9 deserialization vulnerability in its backup and replication product that could let attackers run a remote code execution (RCE). #cybersecurity #infosec #ITsecurity https://t.co/0wtOOx3uXi
Hackers are ramping up attacks using year-old ServiceNow security bugs to target unpatched systems: https://t.co/AAzCSNaL2T by TechCrunch #infosec #cybersecurity #technology #news
Veeam and IBM Release Patches for High-Risk Flaws in Backup and AIX Systems: https://t.co/tNvhMQUr5F by The Hacker News #infosec #cybersecurity #technology #news