CISA's list that day
14 October 2025
On CISA added 5 vulnerabilities to its list of exploited vulnerabilities, in SKYSEA Client View, Rapid7 Velociraptor, Microsoft Windows and 1 other product. US federal agencies must fix them by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2016-7836Improper Authentication | SKYSEA Client View | Patch soon | 0.19 | ||
| CVE-2025-24990Untrusted Pointer Dereference | Microsoft Windows | Patch soon | 0.06 | ||
| CVE-2025-47827Use of a Key Past its Expiration Date | IGEL IGEL OS | Patch soon | 0.05 | ||
| CVE-2025-59230Improper Access Control | Microsoft Windows | Patch soon | 0.03 | ||
| CVE-2025-6264Incorrect Default Permissions | Rapid7 Velociraptor | Removed from CISA's list | 0.01 |