Oct 7, 2025 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Synacor Zimbra Collaboration Suite (ZCS) added to CISA KEV — confirmed in-the-wild exploitation.
  • Zte Zxhn H108n R1a Firmware — exploitation likelihood rose sharply (EPSS 17% → 35% · rising (+18%)).
  • 5 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2025-27915 Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV

Synacor Zimbra Collaboration Suite (ZCS) XSS is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Emerging exploitation risk

CVE-2015-7248 Zte Zxhn H108n R1a Firmware

  • Exploitation likelihood sharply increased
  • EPSS 17% → 35% · rising (+18%)

Zte Zxhn H108n R1a Firmware: EPSS 17% → 35% · rising (+18%) — EPSS is climbing faster than peer CVEs in this window, a leading indicator even before KEV or public exploit linkage.

Critical exposure

CVE-2025-44823 Nagios Log Server

  • CVSS 9.9

New critical disclosure (CVSS 9.9) — high severity with a short public awareness window before exploit material typically surfaces.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

CVE-2015-7248 EPSS 17% → 35% · rising (+18%) CVSS 7.5

Zte Zxhn H108n R1a Firmware

See EPSS increases

New critical disclosures

CVE-2025-0603 CVSS 9.8

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Callvision Healthcare Callvision Em...

CVE-2025-11462 CVSS 9.3

Improper Link Resolution Before File Access in the AWS VPN Client for macOS versions 1.3.2- 5.2.0 allows a local user to execute code wit...

CVE-2025-3450 CVSS 9.3

An Improper Resource Locking vulnerability in the SDM component of B&R Automation Runtime versions before 6.3 and before Q4.93 may allow...

CVE-2025-44823 CVSS 9.9

Nagios Log Server before 2024R1.3.2 allows authenticated users to retrieve cleartext administrative API keys via a /nagioslogserver/index...

CVE-2025-52021 CVSS 9.8

A SQL Injection vulnerability exists in the edit_product.php file of PuneethReddyHC Online Shopping System Advanced 1.0.

View critical disclosures

cvelogic Threat Intelligence