CISA Warns Actively Exploited GeoServer Unauthenticated XML XXE Vulnerability (CVE-2025-58360) The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an OSGeo GeoServer vulnerability to its Known Exploited Vulnerabilities Catalog, acknowledging the active exploitation of the vulnerability. Tracked as... 16/12/2025 Qualys-Threat-Protect
Google Patches Zero-day Vulnerability Exploited in Attack Google has issued urgent updates to address another Chrome zero-day vulnerability that is actively being exploited in the wild, making... 12/12/2025 Qualys-Threat-Protect
Ivanti Endpoint Manager (EPM) Multiple Vulnerabilities (CVE-2025-10573, CVE-2025-13659, CVE-2025-13661, & CVE-2025-13662) Ivanti released a security advisory to address three high-severity vulnerabilities and one critical-severity vulnerability impacting EPM core and remote consoles. Ivanti mentioned in their advisory that they are unaware... 12/12/2025 Qualys-Threat-Protect
Fortinet Addresses Critical Vulnerabilities Impacting Multiple Fortinet Products (CVE-2025-59718 & CVE-2025-59719) Fortinet releases fixes to address two critical vulnerabilities affecting FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager. Tracked as CVE-2025-59718 and CVE-2025-59719, both... 11/12/2025 Qualys-Threat-Protect
Microsoft Patch Tuesday, December 2025 Security Update Review As the year winds down, Microsoft Patch Tuesday in December arrives with essential fixes and enhancements to close vulnerabilities and boost performance. Here’s a quick breakdown of what you need to know.... 10/12/2025 Qualys-Threat-Protect
React Server Components (RSC) Remote Code Execution Vulnerabilities On December 3rd, 2025, React disclosed a critical remote code execution (RCE) vulnerability in React Server Components (RSC), tracked as... 04/12/2025 Qualys-Threat-Protect
Shai-Hulud 2.0 Supply Chain Attack Compromised Major Packages A renewed and intensified npm supply chain attack campaign linked to the original Shai-Hulud malware is making headlines. This campaign,... 27/11/2025 Qualys-Threat-Protect
Fortinet FortiWeb Zero-day Vulnerability Exploited in the Wild (CVE-2025-64446) Threat actors are exploiting a zero-day vulnerability, CVE-2025-64446, that has been discovered in Fortinet’s FortiWeb web application firewall product. Successful... 15/11/2025 Qualys-Threat-Protect
Microsoft Patch Tuesday, November 2025 Security Update Review Microsoft released its November Patch Tuesday Security Updates. Here’s a quick breakdown of what you need to know. This month’s... 12/11/2025 Qualys-Threat-Protect
Cisco Addresses Remote Code Execution Vulnerabilities in Unified Contact Center Express (CVE-2025-20354 & CVE-2025-20358) Cisco Unified CCX is vulnerable to two security vulnerabilities that could allow an unauthenticated, remote attacker to upload arbitrary files, bypass authentication,... 07/11/2025 Qualys-Threat-Protect