Oct 16, 2025 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2025-10611 Wso2 Api Control Plane privilege escalation

  • CVSS 9.8
  • Potential privilege escalation to admin/root

New critical Wso2 Api Control Plane privilege escalation (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2025-9152 Wso2 Api Control Plane privilege escalation

  • CVSS 9.8
  • Potential privilege escalation to admin/root

New critical Wso2 Api Control Plane privilege escalation (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2025-9804 Wso2 Api Control Plane privilege escalation

  • CVSS 9.6
  • Potential privilege escalation to admin/root

New critical Wso2 Api Control Plane privilege escalation (CVSS 9.6) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2025-10611 CVSS 9.8

Due to an insufficient access control implementation in multiple WSO2 Products, authentication and authorization checks for certain REST...

CVE-2025-11492 CVSS 9.6

In the ConnectWise Automate Agent, communications could be configured to use HTTP instead of HTTPS.

CVE-2025-34513 CVSS 9.3

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an OS command injection vulnerability in mbus_build_from_csv.php that allo...

CVE-2025-34515 CVSS 9.3

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an execution with unnecessary privileges vulnerability in sync_project.sh...

CVE-2025-34516 CVSS 9.3

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a use of default credentials vulnerability that allows an unauthenticated...

CVE-2025-61922 CVSS 9.1

PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal.

CVE-2025-6338 CVSS 9.2

There is an incomplete cleanup vulnerability in Qt Network's Schannel support on Windows which can lead to a Denial of Service over a lon...

CVE-2025-6893 CVSS 9.3

An Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and routers.

CVE-2025-9152 CVSS 9.8

An improper privilege management vulnerability exists in WSO2 API Manager due to missing authentication and authorization checks in the k...

CVE-2025-9804 CVSS 9.6

An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in certain internal...

View critical disclosures

cvelogic Threat Intelligence