National Cyber Warfare Foundation (NCWF)

October 2025 CVE Landscape


0 user ratings
2025-11-11 19:42:49
milo
Blue Team (CND)
Discover the top 32 high-risk CVEs identified in October 2025 by Recorded Future’s Insikt Group, including active zero-day exploits, legacy system threats, and CL0P ransomware campaigns targeting Oracle EBS.

In October 2025, Recorded Future’s Insikt Group® identified thirty-two high-impact vulnerabilities that should be prioritized for remediation. This represents an increase from the sixteen identified in September, with the number of Very Critical vulnerabilities also increasing (26) month over month.


These vulnerabilities have affected the following vendors: Broadcom, XWiki, Dassault Systèmes, Adobe, Microsoft, Motex, Apple, Kentico, Oracle, IGEL, SKYSEA, Grafana Labs, Synacor, Linux, Mozilla, GNU, Jenkins, Juniper, Samsung, Smartbedded, and Gladinet.


October was dominated by flaws in Microsoft, which represented eight of the thirty-two vulnerabilities, and the CL0P ransomware group’s exploitation of Oracle E-Business Suite (EBS; CVE-2025-61882). CVE-2025-61882 enabled unauthenticated remote code execution (RCE), with potential for web shell deployment, persistence, lateral movement, and data exfiltration. In observed activity, CL0P (or an affiliate) chained multiple flaws to gain RCE, establish persistence, run interactive shells, and pressure victims via extortion emails.


Of the fourteen vulnerabilities we identified that enable RCE, five are more than a decade old. This highlights how attackers can target unretired legacy systems and internet-facing applications where patching has lagged.



Source: RecordedFuture
Source Link: https://www.recordedfuture.com/blog/october-2025-cve-landscape


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Blue Team (CND)



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.