logo

September 2025 CVE Landscape

ID: 0251f5da-2611-50d7-b06d-880133e16a57

STIX ID: report--0251f5da-2611-50d7-b06d-880133e16a57

Feed Name: Recorded Future Blog

Threat Score
85/100

Date Published: 2025-10-17

Date Updated: 2026-04-28

...
...

**Executive summary:** Recorded Future's Insikt Group identified sixteen prioritized, high-impact vulnerabilities for September 2025 and documented multiple active exploitations — including a persistent bootkit and modular shellcode (RayInitiator and LINE VIPER) targeting legacy Cisco ASA devices, Sitecore ViewState deserialization exploited to deploy WEEPSTEEL/EARTHWORM/SharpHound, Adminer SSRF abuse, and linked vulnerability chains affecting WhatsApp and Apple devices — while providing Nuclei detection templates, IoCs, and remediation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.