9 new critical disclosures — review patch status on exposed services.
Top threats today
Three highest-priority changes — analyst brief, not a CVE dump.
Critical active threat
CVE-2025-21042Samsung Mobile Devices Out-of-Bounds Write
Actively exploited (CISA KEV)
Listed on CISA KEV
Samsung Mobile Devices Out-of-Bounds Write is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.
Critical exposure
CVE-2025-42890SQL Anywhere Monitor (Non-GUI) baked credentials into the code,exposing the resources or function...
CVSS 10
Remote code execution exposure
New critical disclosure (CVSS 10) — high severity with a short public awareness window before exploit material typically surfaces.
Critical exposure
CVE-2025-42887Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert...
CVSS 9.9
New critical disclosure (CVSS 9.9) — high severity with a short public awareness window before exploit material typically surfaces.