CISA's list that day

2 October 2025

On CISA added 5 vulnerabilities to its list of exploited vulnerabilities, in GNU Bash, Juniper ScreenOS, Jenkins and 2 other products. US federal agencies must fix them by .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2014-6278OS Command InjectionGNU GNU BashPatch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry0.99
CVE-2015-7755Improper AuthenticationJuniper ScreenOSPatch this weekMetasploit module; EPSS 0.610.61
CVE-2017-1000353Remote Code ExecutionJenkins JenkinsPatch this weekMetasploit module; EPSS 0.990.99
CVE-2025-4008Command InjectionSmartbedded MeteobridgePatch this weekEPSS 0.940.94
CVE-2025-21043Out-of-Bounds WriteSamsung Mobile DevicesPatch soon0.02