Feb 26, 2025 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2025-25789 Foxcms RCE

  • CVSS 9.8
  • Remote code execution exposure

New critical Foxcms RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2024-50688 SunGrow iSolarCloud Android application V2.1.6.20241017 and prior contains hardcoded credentials.

  • CVSS 9.8

New critical disclosure (CVSS 9.8) — high severity with a short public awareness window before exploit material typically surfaces.

Critical exposure

CVE-2024-53573 Unifiedtransform v2.X is vulnerable to Incorrect Access Control.

  • CVSS 9.8

New critical disclosure (CVSS 9.8) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2024-50685 CVSS 9.1

SunGrow iSolarCloud before the October 31, 2024 remediation, is vulnerable to insecure direct object references (IDOR) via the powerStati...

CVE-2024-50686 CVSS 9.1

SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) via the commonServi...

CVE-2024-50687 CVSS 9.1

SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) via the devService...

CVE-2024-50688 CVSS 9.8

SunGrow iSolarCloud Android application V2.1.6.20241017 and prior contains hardcoded credentials.

CVE-2024-50689 CVSS 9.1

SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) via the orgService...

CVE-2024-50693 CVSS 9.1

SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) via the userService...

CVE-2024-53573 CVSS 9.8

Unifiedtransform v2.X is vulnerable to Incorrect Access Control.

CVE-2024-57040 CVSS 9.8

TP-Link TL-WR845N devices with firmware TL-WR845N(UN)_V4_200909 and TL-WR845N(UN)_V4_190219 was discovered to contain a hardcoded passwor...

CVE-2025-25789 CVSS 9.8

FoxCMS v1.2.5 was discovered to contain a remote code execution (RCE) vulnerability via the index() method at \controller\Sitemap.php.

CVE-2025-25790 CVSS 9.8

An arbitrary file upload vulnerability in the component \controller\LocalTemplate.php of FoxCMS v1.2.5 allows attackers to execute arbitr...

View critical disclosures

cvelogic Threat Intelligence