CISA's list that day

6 October 2025

On CISA added 7 vulnerabilities to its list of exploited vulnerabilities, in Mozilla Multiple Products, Microsoft Internet Explorer, Microsoft Windows and 2 other products. US federal agencies must fix them by .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2010-3765Remote Code ExecutionMozilla Multiple ProductsPatch this weekMetasploit module; EPSS 0.83; verified Exploit-DB entry0.83
CVE-2010-3962Uninitialized Memory CorruptionMicrosoft Internet ExplorerPatch this weekMetasploit module; EPSS 0.97; verified Exploit-DB entry0.97
CVE-2013-3918Out-of-Bounds WriteMicrosoft WindowsPatch this weekMetasploit module; EPSS 0.74; verified Exploit-DB entry0.74
CVE-2021-22555Heap Out-of-Bounds WriteLinux KernelPatch this weekMetasploit module; EPSS 0.79; verified Exploit-DB entry0.79
CVE-2011-3402Remote Code ExecutionMicrosoft WindowsPatch this weekMetasploit module; EPSS 0.780.78
CVE-2025-61882UnspecifiedOracle E-Business SuitePatch this weekRansomware use; Metasploit module; EPSS 0.990.99
CVE-2021-43226Privilege EscalationMicrosoft WindowsPatch this weekRansomware use0.03

Other changes that day

  1. CVE-2025-10035 Fortra GoAnywhere MFTRansomware use: Unknown to Known.
  2. CVE-2025-61882 Oracle E-Business SuiteDeadline moved from 28 October 2025 to 27 October 2025. Listing date changed from 7 October 2025 to 6 October 2025.
  3. CVE-2025-61882 Oracle E-Business SuiteRansomware use: Unknown to Known.