CISA's list that day
20 October 2025
On CISA added 5 vulnerabilities to its list of exploited vulnerabilities, in Apple Multiple Products, Kentico Xperience CMS, Microsoft Windows and 1 other product. US federal agencies must fix them by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2025-61884Server-Side Request Forgery (SSRF) | Oracle E-Business Suite | Patch nowRansomware use, listed within a year | 0.96 | ||
| CVE-2025-2746Authentication Bypass Using an Alternate Path or Channel | Kentico Xperience CMS | Patch this weekEPSS 0.73 | 0.73 | ||
| CVE-2025-2747Authentication Bypass Using an Alternate Path or Channel | Kentico Xperience CMS | Patch this weekEPSS 0.97 | 0.97 | ||
| CVE-2025-33073SMB Client Improper Access Control | Microsoft Windows | Patch this weekEPSS 0.83 | 0.83 | ||
| CVE-2022-48503Unspecified | Apple Multiple Products | Patch soon | 0.03 |