CISA's list that day

12 December 2025

On CISA added 2 vulnerabilities to its list of exploited vulnerabilities, in Sierra Wireless AirLink ALEOS and Google Chromium. US federal agencies must fix them by .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2018-4063Unrestricted Upload of File with Dangerous TypeSierra Wireless AirLink ALEOSPatch soon0.27
CVE-2025-14174Out of Bounds Memory AccessGoogle ChromiumPatch soon0.22

Other changes that day

  1. CVE-2025-55182 Meta React Server ComponentsRansomware use: Unknown to Known.