logo

August 2025 CVE Landscape

ID: 277d0824-3883-530d-af61-63a04bda72d1

STIX ID: report--277d0824-3883-530d-af61-63a04bda72d1

Feed Name: Recorded Future Blog

Threat Score
88/100

Date Published: 2025-09-15

Date Updated: 2026-04-28

...
...

Recorded Future’s Insikt Group identified eighteen high-impact vulnerabilities actively exploited in August 2025, driven largely by Citrix and D-Link flaws; notable incidents include active exploitation of Citrix NetScaler (CVE-2025-7775) leading to widespread web shell deployment and a RomCom campaign exploiting WinRAR (CVE-2025-8088) to deliver SnipBot, RustyClaw, and a Mythic C2 agent. The report lists affected vendors, published PoCs and detection templates (Nuclei), public IOCs (sample hashes and C2 URLs), CISA KEV additions, and vendor patches or mitigations, and recommends urgent patching and monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.