CISA's list that day
24 October 2025
On CISA added 2 vulnerabilities to its list of exploited vulnerabilities, in Adobe Commerce and Magento and Microsoft Windows. US federal agencies must fix them by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2025-54236Improper Input Validation | Adobe Commerce and Magento | Patch this weekMetasploit module; EPSS 0.95 | 0.95 | ||
| CVE-2025-59287Server Update Service (WSUS) Deserialization of Untrusted Data | Microsoft Windows | Patch this weekMetasploit module; EPSS 0.99 | 0.99 |