CVE-2025-62554: Microsoft Office Type Confusion Flaw Enables Remote Code Execution
Vulnerability Summary Overview CVE-2025-62554 is a serious remote code execution vulnerability affecting Microsoft Office. The flaw allows…
continue reading..
CVE-2025-48572: Android Framework Zero-Day Enables Privilege Escalation Attacks
Vulnerability Summary Overview CVE-2025-48572 is a serious security flaw in the core Android operating system that attackers…
continue reading..
CVE-2025-14265: ScreenConnect Extension Integrity Flaw Enables Server Compromise
Vulnerability Summary Overview ConnectWise has disclosed and fixed a critical security flaw in the ScreenConnect server that…
continue reading..
CVE-2025-59719: FortiWeb SAML Authentication Flaw Enables Full Login Bypass
Vulnerability Summary Overview Fortinet has addressed a critical authentication bypass vulnerability in its FortiWeb Web Application Firewall…
continue reading..
CVE-2025-67494: ZITADEL Login UI Flaw Enables Unauthenticated Full-Read SSRF
Vulnerability Summary Overview ZITADEL has fixed a critical security issue that allowed unauthenticated attackers to abuse the…
continue reading..
CVE-2025-66516: Apache Tika PDF Parsing Vulnerability Enables XXE Attacks
Vulnerability Summary Overview Apache Tika has addressed a high-severity security issue involving the processing of XFA (XML…
continue reading..
CVE-2025-62472: Windows RasMan Privilege Escalation Vulnerability
Vulnerability Summary Overview Microsoft has addressed a serious local privilege escalation vulnerability in the Windows Remote Access…
continue reading..
CVE-2025-62562: Microsoft Patches Outlook RCE Risk
Microsoft addressed CVE-2025-62562 as part of its December 2025 Patch Tuesday release. The vulnerability affects Microsoft Outlook…
continue reading..
Atlassian’s December Security Update: What Teams Need to Know Now
Atlassian has released a coordinated set of security updates as part of its December security cycle, addressing…
continue reading..
