CISA's list that day

9 December 2025

On CISA added 2 vulnerabilities to its list of exploited vulnerabilities, in RARLAB WinRAR and Microsoft Windows. US federal agencies must fix them by .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2025-6218Path TraversalRARLAB WinRARPatch this weekEPSS 0.900.90
CVE-2025-62221Use After FreeMicrosoft WindowsPatch soon0.03

Other changes that day

  1. CVE-2025-55182 Meta React Server ComponentsDeadline moved from 26 December 2025 to 12 December 2025. Edited: notes.
  2. CVE-2025-55182 Meta React Server ComponentsEdited: notes and description.