CISA's list that day
22 July 2025
On CISA added 6 vulnerabilities to its list of exploited vulnerabilities, in SysAid On-Prem, Google Chromium, Microsoft SharePoint and 1 other product. The US federal deadlines run from to .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2025-49704Code Injection | Microsoft SharePoint | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| CVE-2025-49706Improper Authentication | Microsoft SharePoint | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| CVE-2025-2776Improper Restriction of XML External Entity Reference | SysAid SysAid On-Prem | Patch this weekEPSS 0.65 | 0.65 | ||
| CVE-2025-54309Unprotected Alternate Channel | CrushFTP CrushFTP | Patch this weekEPSS 0.95 | 0.95 | ||
| CVE-2025-2775Improper Restriction of XML External Entity Reference | SysAid SysAid On-Prem | Patch soon | 0.43 | ||
| CVE-2025-6558ANGLE and GPU Improper Input Validation | Google Chromium | Patch soon | 0.09 |