Content:
[CVE-2025-10585] Google Chromium V8 Type Confusion Vulnerability (CVSS v3.1: 9.8)
[Exploited by ransomware: Unknown] Google Chromium has a type confusion vulnerability in its V8 JavaScript and WebAssembly engine, which a remote attacker can exploit to achieve arbitrary code execution or cause a crash.
[Affected Platforms] Please refer to the official list of affected versions
-
[CVE-2025-20362] Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Missing Authorization Vulnerability (CVSS v3.1: 6.5)
[Exploited by ransomware: Unknown] Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) have a Missing Authorization vulnerability in the VPN Web services. This vulnerability may be exploited in conjunction with CVE-2025-20333.
[Affected Platforms] Please refer to the official list of affected versions
-
[CVE-2025-20333] Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Buffer Overflow Vulnerability (CVSS v3.1: 9.9)
[Exploited by ransomware: Unknown] Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) have a buffer overflow vulnerability in the VPN Web services, which may lead to remote code execution. This vulnerability may be exploited in conjunction with CVE-2025-20362.
[Affected Platforms] Please refer to the official list of affected versions
-
Affected Platforms:
Recommended Action:
[CVE-2025-10585] The vendor has released a fix for the vulnerability. Please update to the relevant version.
[CVE-2025-20362] The vendor has released a fix for the vulnerability. Please update to the relevant version.
[CVE-2025-20333] The vendor has released a fix for the vulnerability. Please update to the relevant version.
Computer and Communications Center
Network Systems Group