September 2025 CVE Landscape
ID: 0251f5da-2611-50d7-b06d-880133e16a57
STIX ID: report--0251f5da-2611-50d7-b06d-880133e16a57
Feed Name: Recorded Future Blog
**Executive summary:** Recorded Future's Insikt Group identified sixteen prioritized, high-impact vulnerabilities for September 2025 and documented multiple active exploitations — including a persistent bootkit and modular shellcode (RayInitiator and LINE VIPER) targeting legacy Cisco ASA devices, Sitecore ViewState deserialization exploited to deploy WEEPSTEEL/EARTHWORM/SharpHound, Adminer SSRF abuse, and linked vulnerability chains affecting WhatsApp and Apple devices — while providing Nuclei detection templates, IoCs, and remediation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
