logo

November 2025 CVE Landscape: 10 Critical Vulnerabilities Show 69% Drop from October

ID: e4ba9917-dd4d-52f9-a518-32dc4239c924

STIX ID: report--e4ba9917-dd4d-52f9-a518-32dc4239c924

Feed Name: Recorded Future Blog

Threat Score
90/100

Date Published: 2025-12-09

Date Updated: 2026-04-28

...
...

Recorded Future’s Insikt Group reports that November 2025 saw active exploitation of 10 high-impact vulnerabilities — notably two FortiWeb authentication-bypass flaws and a zero-click Samsung image-processing exploit used by the LANDFALL spyware — with seven public PoCs and widespread risk (e.g., ~4,768 exposed FortiWeb instances); the report includes technical analysis, targeted regions/devices, IOCs, mitigation steps, and Nuclei detection templates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.