CISA's list that day
15 December 2025
On CISA added 2 vulnerabilities to its list of exploited vulnerabilities, in Gladinet CentreStack and Triofox and Apple Multiple Products. US federal agencies must fix them by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2025-14611Hard Coded Cryptographic | Gladinet CentreStack and Triofox | Patch this weekMetasploit module; EPSS 0.53 | 0.53 | ||
| CVE-2025-43529Use-After-Free WebKit | Apple Multiple Products | Patch soon | 0.09 |