The Week in Vulnerabilities: 1000+ Bugs with 135 Publicly Known PoCs  

The Week in Vulnerabilities: 1000+ Bugs with 135 Publicly Known PoCs  

CRIL tracked over 1,045 vulnerabilities disclosed Sept 10–16, 2025, with more than 135 PoCs accelerating exploit risk and active weaponization discussed on underground forums. High-impact flaws affect Apple OS, Zimbra, Samsung Android, Adobe Commerce, and DELMIA Apriso, with exploits and a claimed Google-domain zero-day circulating. #CVE-2025-43362 #CVE-2025-54236

Keypoints

  • CRIL tracked 1,045 IT vulnerabilities from Sept 10–16, 2025, with 135+ having public PoCs, shrinking time-to-exploit.
  • Apple operating systems have logic and LaunchServices flaws (CVE-2025-43359, CVE-2025-43362) enabling stealthy keystroke monitoring and data exfiltration.
  • Zimbra Collaboration Suite (CVE-2025-54391) allows 2FA bypass via the EnableTwoFactorAuthRequest SOAP endpoint, enabling account takeover.
  • Samsung devices affected by CVE-2025-21043 (libimagecodec.quram.so) permit remote code execution and elevated privileges.
  • Adobe Commerce / Magento Open Source vulnerable to CVE-2025-54236 (“SessionReaper”), enabling account hijack and potential RCE via the REST API.
  • CISA added DELMIA Apriso CVE-2025-5086 (CVSS 9.8) to KEV after observed exploitation enabling RCE in manufacturing environments.
  • Underground forums show weaponized exploits (e.g., Hydroph0bia UEFI CVE-2025-4275), kernel and Tomcat flaws, plus an unverified BIGBROTHER Google-domain zero-day claim.

MITRE Techniques

  • [T1555] Credentials from Password Stores – Zimbra 2FA bypass (CVE-2025-54391) allowed attackers with valid credentials to configure an additional 2FA method without a valid token: “‘Attackers with valid credentials can bypass existing Two-Factor Authentication (2FA) by configuring an additional 2FA method without requiring a valid token.’”
  • [T1059] Command and Scripting Interpreter – Adobe Commerce REST API flaw (CVE-2025-54236) enabled unauthenticated attackers to hijack accounts and under certain conditions achieve remote code execution: “‘Unauthenticated attackers can hijack customer accounts and, under certain conditions, achieve remote code execution.’”
  • [T1210] Exploitation of Remote Services – DELMIA Apriso (CVE-2025-5086) actively exploited via crafted HTTP requests to enable remote code execution: “‘Actively exploited via crafted HTTP requests, enabling remote code execution.’”
  • [T1543] Create or Modify System Process – UEFI firmware flaw (CVE-2025-4275, “Hydroph0bia”) enabling injection of rogue certificates to bypass Secure Boot and facilitate persistent bootkit/rootkit deployment: “‘enabling attackers to bypass Secure Boot protections by injecting rogue certificates. Facilitates persistent bootkit malware and rootkit deployment.’”
  • [T1203] Exploitation for Privilege Escalation – Linux kernel ETS module bug (CVE-2025-21692) allowing local privilege escalation: “‘Linux kernel bug in the Enhanced Transmission Selection (ETS) module allowing local privilege escalation.’”
  • [T1190] Exploit Public-Facing Application – Apache Tomcat path-equivalence flaw (CVE-2025-24813) enabling RCE via crafted JSESSIONID values under specific configurations: “‘Apache Tomcat path-equivalence flaw enabling remote code execution through crafted JSESSIONID values under specific configurations.’”
  • [T1588] Obtain Capabilities: External Remote Services – Samsung libimagecodec.quram.so OOB write (CVE-2025-21043) enabling remote code execution with elevated privileges on Android devices: “‘allows remote attackers to execute arbitrary code with elevated privileges.’”

Indicators of Compromise

  • [Vulnerability IDs] tracked exploited CVEs – CVE-2025-43362, CVE-2025-54236, and CVE-2025-5086.
  • [File/Component Names] vulnerable libraries and endpoints – libimagecodec.quram.so (Samsung) and EnableTwoFactorAuthRequest SOAP endpoint (Zimbra).
  • [Product/Platform] affected products – Apple operating systems (macOS/iOS), Zimbra Collaboration Suite, Adobe Commerce / Magento Open Source, DELMIA Apriso.
  • [Exploit Names/Claims] underground exploit references – “Hydroph0bia” (CVE-2025-4275) UEFI exploit and a BIGBROTHER Google-domain redirection claim (unverified).
  • [Attack Vectors] observed exploit mechanisms – crafted HTTP requests for DELMIA Apriso RCE and crafted JSESSIONID values for Apache Tomcat RCE.


Read more: https://cyble.com/blog/weekly-it-it-vulnerabilities-report/