logo

Last Week In AppSec for 14. October 2025

ID: 6ed00b70-56da-57b2-a194-e46eca562b15

STIX ID: report--6ed00b70-56da-57b2-a194-e46eca562b15

Feed Name: Checkmarx Zero

Threat Score
70/100

Date Published: 2025-10-14

Date Updated: 2026-04-27

Author: Darren Meyer

...
...

This Checkmarx AppSec bulletin highlights two vulnerabilities: a Poppler use-after-free (CVE-2025-52885, CVSS 7.8) that could expose information or enable arbitrary code execution, and a Liferay Account Admin Web IDOR (CVE-2025-62242, CVSS 9.1) that allows attackers to access privileged user data; the report urges affected parties to apply patches, hunt for the libraries in applications and containers, and review access controls and third-party plugins.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.