CISA's list that day
2 October 2025
On CISA added 5 vulnerabilities to its list of exploited vulnerabilities, in GNU Bash, Juniper ScreenOS, Jenkins and 2 other products. US federal agencies must fix them by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2014-6278OS Command Injection | GNU GNU Bash | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| CVE-2015-7755Improper Authentication | Juniper ScreenOS | Patch this weekMetasploit module; EPSS 0.61 | 0.61 | ||
| CVE-2017-1000353Remote Code Execution | Jenkins Jenkins | Patch this weekMetasploit module; EPSS 0.99 | 0.99 | ||
| CVE-2025-4008Command Injection | Smartbedded Meteobridge | Patch this weekEPSS 0.94 | 0.94 | ||
| CVE-2025-21043Out-of-Bounds Write | Samsung Mobile Devices | Patch soon | 0.02 |