CISA's list that day
7 July 2025
On CISA added 4 vulnerabilities to its list of exploited vulnerabilities, in Looking Glass Multi-Router Looking Glass (MRLG), PHPMailer, Rails Ruby on Rails and 1 other product. US federal agencies must fix them by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2016-10033Command Injection | PHP PHPMailer | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| CVE-2019-9621Server-Side Request Forgery (SSRF) | Synacor Zimbra Collaboration Suite (ZCS) | Patch this weekMetasploit module; EPSS 0.81; verified Exploit-DB entry | 0.81 | ||
| CVE-2019-5418Path Traversal | Rails Ruby on Rails | Patch this weekMetasploit module; EPSS 0.99 | 0.99 | ||
| CVE-2014-3931Buffer Overflow | Looking Glass Multi-Router Looking Glass (MRLG) | Patch soon | 0.29 |