CISA's list that day

30 October 2025

On CISA added 2 vulnerabilities to its list of exploited vulnerabilities, in XWiki Platform and Broadcom VMware Aria Operations and VMware Tools. US federal agencies must fix them by .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2025-24893Eval InjectionXWiki PlatformPatch this weekMetasploit module; EPSS 0.990.99
CVE-2025-41244Privilege Defined with Unsafe ActionsBroadcom VMware Aria Operations and VMware ToolsPatch soon0.08

Other changes that day

  1. CVE-2024-1086 Linux KernelRansomware use: Unknown to Known.