CISA Known Exploited Vulnerabilities
KEV additions — September 2025
16 CVEs entered the KEV catalog in September 2025.
Added September 29, 20255
| CVE | Vulnerability | CVSS | EPSS | Due date |
|---|---|---|---|---|
| CVE-2021-21311 | Adminer Server-Side Request Forgery Vulnerability | 7.2 | 94.2 % | October 20, 2025 |
| CVE-2025-10035ransomware | Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability | 9.8 | 59.3 % | October 20, 2025 |
| CVE-2025-20352 | Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability | 7.7 | 1.9 % | October 20, 2025 |
| CVE-2025-32463 | Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability | 9.3 | 47.0 % | October 20, 2025 |
| CVE-2025-59689 | Libraesva Email Security Gateway Command Injection Vulnerability | 6.1 | 5.2 % | October 20, 2025 |
Added September 25, 20252
| CVE | Vulnerability | CVSS | EPSS | Due date |
|---|---|---|---|---|
| CVE-2025-20333 | Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Buffer Overflow Vulnerability | 9.9 | 16.6 % | September 26, 2025 |
| CVE-2025-20362 | Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Missing Authorization Vulnerability | 8.6 | 42.3 % | September 26, 2025 |
Added September 23, 20251
| CVE | Vulnerability | CVSS | EPSS | Due date |
|---|---|---|---|---|
| CVE-2025-10585 | Google Chromium V8 Type Confusion Vulnerability | 9.8 | 0.6 % | October 14, 2025 |
Added September 11, 20251
| CVE | Vulnerability | CVSS | EPSS | Due date |
|---|---|---|---|---|
| CVE-2025-5086 | Dassault Systèmes DELMIA Apriso Deserialization of Untrusted Data Vulnerability | 9 | 42.1 % | October 2, 2025 |
Added September 4, 20253
| CVE | Vulnerability | CVSS | EPSS | Due date |
|---|---|---|---|---|
| CVE-2025-38352 | Linux Kernel Time-of-Check Time-of-Use (TOCTOU) Race Condition Vulnerability | 7.4 | 0.1 % | September 25, 2025 |
| CVE-2025-48543 | Android Runtime Use-After-Free Vulnerability | 8.8 | 0.3 % | September 25, 2025 |
| CVE-2025-53690 | Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability | 9 | 9.5 % | September 25, 2025 |
Added September 3, 20252
| CVE | Vulnerability | CVSS | EPSS | Due date |
|---|---|---|---|---|
| CVE-2023-50224 | TP-Link TL-WR841N Authentication Bypass by Spoofing Vulnerability | 6.5 | 1.5 % | September 24, 2025 |
| CVE-2025-9377 | TP-Link Archer C7(EU) and TL-WR841N/ND(MS) OS Command Injection Vulnerability | 7.2 | 15.6 % | September 24, 2025 |
Added September 2, 20252
| CVE | Vulnerability | CVSS | EPSS | Due date |
|---|---|---|---|---|
| CVE-2020-24363 | TP-link TL-WA855RE Missing Authentication for Critical Function Vulnerability | 8.8 | 11.1 % | September 23, 2025 |
| CVE-2025-55177 | Meta Platforms WhatsApp Incorrect Authorization Vulnerability | 5.4 | 0.9 % | September 23, 2025 |