CISA's list that day

29 September 2025

On CISA added 5 vulnerabilities to its list of exploited vulnerabilities, in Adminer, Fortra GoAnywhere MFT, Cisco IOS and IOS XE and 2 other products. US federal agencies must fix them by .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2025-32463Inclusion of Functionality from Untrusted Control SphereSudo SudoPatch this weekMetasploit module; EPSS 0.550.55
CVE-2021-21311Server-Side Request ForgeryAdminer AdminerPatch this weekEPSS 0.980.98
CVE-2025-10035Deserialization of Untrusted DataFortra GoAnywhere MFTPatch this weekRansomware use; EPSS 0.990.99
CVE-2025-20352Software SNMP Denial of Service and Remote Code ExecutionCisco IOS and IOS XEPatch soon0.39
CVE-2025-59689Command InjectionLibraesva Email Security GatewayPatch soon0.02

Other changes that day

  1. CVE-2025-20352 Cisco IOS and IOS XEEdited: name.