CISA's list that day

15 December 2025

On CISA added 2 vulnerabilities to its list of exploited vulnerabilities, in Gladinet CentreStack and Triofox and Apple Multiple Products. US federal agencies must fix them by .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2025-14611Hard Coded CryptographicGladinet CentreStack and TriofoxPatch this weekMetasploit module; EPSS 0.530.53
CVE-2025-43529Use-After-Free WebKitApple Multiple ProductsPatch soon0.09