The Week in Security
Other had 29 vulnerabilities this week including Goanywhere Managed File Transfer Deserialization of Untrusted Data (CVSS 10.0 CRITICAL) (CVSS 10.0). Microsoft got hit with a CVSS 10.0 for Netweaver Security (CVSS 10.0 CRITICAL). Mozilla Firefox had 3 vulnerabilities this week including Firefox Security (CVSS 9.8 CRITICAL) (CVSS 9.8).
We tracked 38 vulnerabilities this week. 29 scored 9.0 or above. If you only have time for one thing today, scroll to "What To Do This Week" at the bottom.
Other Had a Rough Week
29 vulnerabilities across Other products this week. The worst: CVE-2025-10035 (CVSS 10.0) lets attackers run code on your systems. Patch now if you run Other.
- CVE-2025-10035: Goanywhere Managed File Transfer Deserialization of Untrusted Data (CVSS 10.0 CRITICAL) (CVSS 10.0)
- CVE-2024-51378: Cyberpanel OS Command Injection (CVSS 10.0 CRITICAL) (CVSS 10.0)
- CVE-2024-51378: Cyberpanel OS Command Injection (CVSS 10.0 CRITICAL) (CVSS 10.0)
- CVE-2024-51378: Cyberpanel OS Command Injection (CVSS 10.0 CRITICAL) (CVSS 10.0)
- CVE-2024-42467: Openhab Web Interface Security (CVSS 10.0 CRITICAL) (CVSS 10.0)
- CVE-2024-42467: Openhab Web Interface Security (CVSS 10.0 CRITICAL) (CVSS 10.0)
- CVE-2025-62718: Axios Security (CVSS 9.9 CRITICAL) (CVSS 9.9)
- CVE-2025-62718: Axios Security (CVSS 9.9 CRITICAL) (CVSS 9.9)
- CVE-2025-62718: Axios Security (CVSS 9.9 CRITICAL) (CVSS 9.9)
- CVE-2026-49875: Cxf Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
- CVE-2026-14537: Mcp Toolbox For Databases Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
- CVE-2026-14537: Mcp Toolbox For Databases Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
- CVE-2026-12569: Flexplm Deserialization of Untrusted Data (CVSS 9.8 CRITICAL) (CVSS 9.8)
- CVE-2024-55956: Harmony Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
- CVE-2024-50623: Harmony Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
- CVE-2024-21762: Fortiproxy Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
- CVE-2024-21762: Fortiproxy Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
- CVE-2024-21762: Fortiproxy Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
- CVE-2026-8037: Connection Manager For Objectscale Security (CVSS 9.6 CRITICAL) (CVSS 9.6)
- CVE-2026-8037: Connection Manager For Objectscale Security (CVSS 9.6 CRITICAL) (CVSS 9.6)
- CVE-2024-24919: Quantum Spark Firmware Security (CVSS 8.6 HIGH) (CVSS 8.6)
- CVE-2024-24919: Quantum Spark Firmware Security (CVSS 8.6 HIGH) (CVSS 8.6)
- CVE-2024-24919: Quantum Spark Firmware Security (CVSS 8.6 HIGH) (CVSS 8.6)
- CVE-2025-22225: Esxi Security (CVSS 8.2 HIGH) (CVSS 8.2)
- CVE-2025-22225: Esxi Security (CVSS 8.2 HIGH) (CVSS 8.2)
- CVE-2025-22225: Esxi Security (CVSS 8.2 HIGH) (CVSS 8.2)
- CVE-2024-1086: H300S Firmware Security (CVSS 7.8 HIGH) (CVSS 7.8)
- CVE-2024-1086: H300S Firmware Security (CVSS 7.8 HIGH) (CVSS 7.8)
- CVE-2024-11667: Zld Path Traversal (CVSS 7.5 HIGH) (CVSS 7.5)
Microsoft Hit With CVSS 10.0
CVE-2025-31324 scores a 10.0. Microsoft lets attackers run code on your systems.
- CVE-2025-31324: Netweaver Security (CVSS 10.0 CRITICAL) (CVSS 10.0)
Mozilla Firefox: 3 Critical Flaws at Once
3 vulnerabilities across Mozilla Firefox products this week. The worst: CVE-2024-9680 (CVSS 9.8) lets attackers run code on your systems. Patch now if you run Mozilla Firefox.
- CVE-2024-9680: Firefox Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
- CVE-2024-9680: Firefox Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
- CVE-2024-9680: Firefox Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
Linux Kernel: 5 Critical Flaws at Once
5 vulnerabilities across Linux Kernel products this week. The worst: CVE-2025-38209 (CVSS 9.8) lets attackers run code on your systems. Patch now if you run Linux Kernel.
- CVE-2025-38209: Linux Kernel Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
- CVE-2025-38139: Linux Kernel Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
- CVE-2025-37879: Linux Kernel Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
- CVE-2025-37750: Linux Kernel Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
- CVE-2025-21927: Linux Kernel Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
By the Numbers
| Total CVEs analyzed | 38 |
| Critical (9.0+) | 29 |
| High (7.0-8.9) | 9 |
| Remote code execution | 38 |
| Authentication bypass | 0 |
| Cross-site scripting | 0 |
| SQL injection | 0 |
What To Do This Week
One action item per vendor. Start at the top and work down.
- Other: Update immediately. 20 critical-severity issues patched this week.
- Microsoft: Update immediately. 1 critical-severity issues patched this week.
- Mozilla Firefox: Update immediately. 3 critical-severity issues patched this week.
- Linux Kernel: Update immediately. 5 critical-severity issues patched this week.