CISA's list that day
9 June 2025
On CISA added 2 vulnerabilities to its list of exploited vulnerabilities, in Roundcube Webmail and Erlang/OTP. US federal agencies must fix them by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2025-32433SSH Server Missing Authentication for Critical Function | Erlang Erlang/OTP | Patch this weekMetasploit module; EPSS 0.99 | 0.99 | ||
| CVE-2024-42009Cross-Site Scripting | Roundcube Webmail | Patch this weekEPSS 0.83 | 0.83 |
Other changes that day
- CVE-2021-44529 Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA)Ransomware use: Unknown to Known.