CRIL tracked over 1,045 vulnerabilities disclosed Sept 10–16, 2025, with more than 135 PoCs accelerating exploit risk and active weaponization discussed on underground forums. High-impact flaws affect Apple OS, Zimbra, Samsung Android, Adobe Commerce, and DELMIA Apriso, with exploits and a claimed Google-domain zero-day circulating. #CVE-2025-43362 #CVE-2025-54236
Keypoints
- CRIL tracked 1,045 IT vulnerabilities from Sept 10–16, 2025, with 135+ having public PoCs, shrinking time-to-exploit.
- Apple operating systems have logic and LaunchServices flaws (CVE-2025-43359, CVE-2025-43362) enabling stealthy keystroke monitoring and data exfiltration.
- Zimbra Collaboration Suite (CVE-2025-54391) allows 2FA bypass via the EnableTwoFactorAuthRequest SOAP endpoint, enabling account takeover.
- Samsung devices affected by CVE-2025-21043 (libimagecodec.quram.so) permit remote code execution and elevated privileges.
- Adobe Commerce / Magento Open Source vulnerable to CVE-2025-54236 (“SessionReaper”), enabling account hijack and potential RCE via the REST API.
- CISA added DELMIA Apriso CVE-2025-5086 (CVSS 9.8) to KEV after observed exploitation enabling RCE in manufacturing environments.
- Underground forums show weaponized exploits (e.g., Hydroph0bia UEFI CVE-2025-4275), kernel and Tomcat flaws, plus an unverified BIGBROTHER Google-domain zero-day claim.
MITRE Techniques
- [T1555] Credentials from Password Stores – Zimbra 2FA bypass (CVE-2025-54391) allowed attackers with valid credentials to configure an additional 2FA method without a valid token: “‘Attackers with valid credentials can bypass existing Two-Factor Authentication (2FA) by configuring an additional 2FA method without requiring a valid token.’”
- [T1059] Command and Scripting Interpreter – Adobe Commerce REST API flaw (CVE-2025-54236) enabled unauthenticated attackers to hijack accounts and under certain conditions achieve remote code execution: “‘Unauthenticated attackers can hijack customer accounts and, under certain conditions, achieve remote code execution.’”
- [T1210] Exploitation of Remote Services – DELMIA Apriso (CVE-2025-5086) actively exploited via crafted HTTP requests to enable remote code execution: “‘Actively exploited via crafted HTTP requests, enabling remote code execution.’”
- [T1543] Create or Modify System Process – UEFI firmware flaw (CVE-2025-4275, “Hydroph0bia”) enabling injection of rogue certificates to bypass Secure Boot and facilitate persistent bootkit/rootkit deployment: “‘enabling attackers to bypass Secure Boot protections by injecting rogue certificates. Facilitates persistent bootkit malware and rootkit deployment.’”
- [T1203] Exploitation for Privilege Escalation – Linux kernel ETS module bug (CVE-2025-21692) allowing local privilege escalation: “‘Linux kernel bug in the Enhanced Transmission Selection (ETS) module allowing local privilege escalation.’”
- [T1190] Exploit Public-Facing Application – Apache Tomcat path-equivalence flaw (CVE-2025-24813) enabling RCE via crafted JSESSIONID values under specific configurations: “‘Apache Tomcat path-equivalence flaw enabling remote code execution through crafted JSESSIONID values under specific configurations.’”
- [T1588] Obtain Capabilities: External Remote Services – Samsung libimagecodec.quram.so OOB write (CVE-2025-21043) enabling remote code execution with elevated privileges on Android devices: “‘allows remote attackers to execute arbitrary code with elevated privileges.’”
Indicators of Compromise
- [Vulnerability IDs] tracked exploited CVEs – CVE-2025-43362, CVE-2025-54236, and CVE-2025-5086.
- [File/Component Names] vulnerable libraries and endpoints – libimagecodec.quram.so (Samsung) and EnableTwoFactorAuthRequest SOAP endpoint (Zimbra).
- [Product/Platform] affected products – Apple operating systems (macOS/iOS), Zimbra Collaboration Suite, Adobe Commerce / Magento Open Source, DELMIA Apriso.
- [Exploit Names/Claims] underground exploit references – “Hydroph0bia” (CVE-2025-4275) UEFI exploit and a BIGBROTHER Google-domain redirection claim (unverified).
- [Attack Vectors] observed exploit mechanisms – crafted HTTP requests for DELMIA Apriso RCE and crafted JSESSIONID values for Apache Tomcat RCE.
Read more: https://cyble.com/blog/weekly-it-it-vulnerabilities-report/