CISA's list that day

14 October 2025

On CISA added 5 vulnerabilities to its list of exploited vulnerabilities, in SKYSEA Client View, Rapid7 Velociraptor, Microsoft Windows and 1 other product. US federal agencies must fix them by .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2016-7836Improper AuthenticationSKYSEA Client ViewPatch soon0.19
CVE-2025-24990Untrusted Pointer DereferenceMicrosoft WindowsPatch soon0.06
CVE-2025-47827Use of a Key Past its Expiration DateIGEL IGEL OSPatch soon0.05
CVE-2025-59230Improper Access ControlMicrosoft WindowsPatch soon0.03
CVE-2025-6264Incorrect Default PermissionsRapid7 VelociraptorRemoved from CISA's list0.01

Other changes that day

  1. CVE-2025-6264 Rapid7 VelociraptorRansomware use: Unknown to Known.