CISA's list that day

24 October 2025

On CISA added 2 vulnerabilities to its list of exploited vulnerabilities, in Adobe Commerce and Magento and Microsoft Windows. US federal agencies must fix them by .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2025-54236Improper Input ValidationAdobe Commerce and MagentoPatch this weekMetasploit module; EPSS 0.950.95
CVE-2025-59287Server Update Service (WSUS) Deserialization of Untrusted DataMicrosoft WindowsPatch this weekMetasploit module; EPSS 0.990.99