CISA's list that day

20 October 2025

On CISA added 5 vulnerabilities to its list of exploited vulnerabilities, in Apple Multiple Products, Kentico Xperience CMS, Microsoft Windows and 1 other product. US federal agencies must fix them by .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2025-61884Server-Side Request Forgery (SSRF)Oracle E-Business SuitePatch nowRansomware use, listed within a year0.96
CVE-2025-2746Authentication Bypass Using an Alternate Path or ChannelKentico Xperience CMSPatch this weekEPSS 0.730.73
CVE-2025-2747Authentication Bypass Using an Alternate Path or ChannelKentico Xperience CMSPatch this weekEPSS 0.970.97
CVE-2025-33073SMB Client Improper Access ControlMicrosoft WindowsPatch this weekEPSS 0.830.83
CVE-2022-48503UnspecifiedApple Multiple ProductsPatch soon0.03