Mar 13, 2025 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Juniper Junos OS added to CISA KEV — confirmed in-the-wild exploitation.
  • 3 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2025-21590 Juniper Junos OS Improper Isolation or Compartmentalization

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV
  • Potential privilege escalation to admin/root

Juniper Junos OS privilege escalation is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Critical exposure

CVE-2025-2263 Santesoft Sante Pacs Server Buffer Overflow

  • CVSS 9.8

New critical Santesoft Sante Pacs Server Buffer Overflow (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2025-26163 Cmsol Auto Atendimento SQL Injection

  • CVSS 9.8

New critical Cmsol Auto Atendimento SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Juniper Junos OS Improper Isolation or Compartmentalization

Apple Multiple Products WebKit Out-of-Bounds Write

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2025-2080 CVSS 9.3

Optigo Networks Visual BACnet Capture Tool and Optigo Visual Networks Capture Tool version 3.1.2rc11 contain an exposed web management se...

CVE-2025-2263 CVSS 9.8

During login to the web server in "Sante PACS Server.exe", OpenSSL function EVP_DecryptUpdate is called to decrypt the username and passw...

CVE-2025-26163 CVSS 9.8

CM Soluces Informatica Ltda Auto Atendimento 1.x.x was discovered to contain a SQL injection via the CPF parameter.

View critical disclosures

cvelogic Threat Intelligence