CISA's list that day
9 December 2025
On CISA added 2 vulnerabilities to its list of exploited vulnerabilities, in RARLAB WinRAR and Microsoft Windows. US federal agencies must fix them by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2025-6218Path Traversal | RARLAB WinRAR | Patch this weekEPSS 0.90 | 0.90 | ||
| CVE-2025-62221Use After Free | Microsoft Windows | Patch soon | 0.03 |
Other changes that day
- CVE-2025-55182 Meta React Server ComponentsDeadline moved from 26 December 2025 to 12 December 2025. Edited: notes.