CISA's list that day

22 July 2025

On CISA added 6 vulnerabilities to its list of exploited vulnerabilities, in SysAid On-Prem, Google Chromium, Microsoft SharePoint and 1 other product. The US federal deadlines run from to .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2025-49704Code InjectionMicrosoft SharePointPatch this weekRansomware use; Metasploit module; EPSS 0.990.99
CVE-2025-49706Improper AuthenticationMicrosoft SharePointPatch this weekRansomware use; Metasploit module; EPSS 0.990.99
CVE-2025-2776Improper Restriction of XML External Entity ReferenceSysAid SysAid On-PremPatch this weekEPSS 0.650.65
CVE-2025-54309Unprotected Alternate ChannelCrushFTP CrushFTPPatch this weekEPSS 0.950.95
CVE-2025-2775Improper Restriction of XML External Entity ReferenceSysAid SysAid On-PremPatch soon0.43
CVE-2025-6558ANGLE and GPU Improper Input ValidationGoogle ChromiumPatch soon0.09

Other changes that day

  1. CVE-2025-53770 Microsoft SharePointEdited: notes.