CISA's list that day
29 September 2025
On CISA added 5 vulnerabilities to its list of exploited vulnerabilities, in Adminer, Fortra GoAnywhere MFT, Cisco IOS and IOS XE and 2 other products. US federal agencies must fix them by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2025-32463Inclusion of Functionality from Untrusted Control Sphere | Sudo Sudo | Patch this weekMetasploit module; EPSS 0.55 | 0.55 | ||
| CVE-2021-21311Server-Side Request Forgery | Adminer Adminer | Patch this weekEPSS 0.98 | 0.98 | ||
| CVE-2025-10035Deserialization of Untrusted Data | Fortra GoAnywhere MFT | Patch this weekRansomware use; EPSS 0.99 | 0.99 | ||
| CVE-2025-20352Software SNMP Denial of Service and Remote Code Execution | Cisco IOS and IOS XE | Patch soon | 0.39 | ||
| CVE-2025-59689Command Injection | Libraesva Email Security Gateway | Patch soon | 0.02 |