Full Report
Last week’s reports from Cyble Research & Intelligence Labs (CRIL) to clients highlighted new flaws from December 03 through December 09, 2025, including newly disclosed IT vulnerabilities, ICS vulnerabilities, active exploitation attempts, and dark-web discussions around weaponized CVEs. Drawing from CISA alerts, CRIL’s global sensor network, and Cyble’s vulnerability intelligence platform, the findings outline rapid PoC release cycles, persistent automated exploitation, and targeted attacks against critical infrastructure. CRIL’s threat-hunting infrastructure deployed across multiple regions continues to record real-time malicious activity, including exploit attempts, brute-force intrusions, malware injections, and financially motivated attacks. There has been a sustained rise in botnet-driven campaigns and opportunistic exploitation of internet-exposed and misconfigured industrial devices throughout the reporting period. More broadly, CRIL’s weekly insight reveals a sharp increase in newly disclosed vulnerabilities. The Vulnerability Intelligence (VI) module identified 1,378 vulnerabilities this week, including over 131 with publicly available PoCs and three new zero-days. The Week’s Top IT Vulnerabilities CRIL’s weekly vulnerability intelligence analysis found multiple high-impact issues affecting enterprise technologies, software ecosystems, and internet-facing applications. Major vendors reporting significant vulnerability counts included Linux distributions, Google, Microsoft, Siemens, and Nextcloud. A subset of critical vulnerabilities drew community and industry attention: CVE-2025-67494: A critical server-side request forgery (SSRF) flaw in ZITADEL, enabling unauthorized network pivoting and data exposure. CVE-2025-59719: An authentication bypass impacting Fortinet products. CVE-2025-42880: A code injection flaw in SAP Solution Manager. CVE-2025-66516: A severe XML External Entity (XXE) vulnerability in Apache Tika affects modules such as tika-core, tika-pdf-module, and tika-parsers. These IT vulnerabilities present a direct risk to organizations due to their potential to enable unauthorized access, data theft, and remote code execution. Across all disclosures, CRIL identified 68 critical vulnerabilities under CVSS v3.1 and 23 rated critical under CVSS v4.0, making it another high-activity week in vulnerability disclosure trends. CISA – Known Exploited Vulnerabilities (KEV) Catalogue Between December 3 and December 9, 2025, CISA added six new exploited vulnerabilities to its CVE catalog. Notable additions include: CVE-2025-6218: A directory traversal flaw in RARLAB WinRAR enables remote code execution (RCE). CVE-2025-55182: A critical pre-authentication RCE in React Server Components (RSC) leveraging unsafe deserialization in the “Flight” protocol. The exploitation of CVE-2025-55182 began around December 08, employing payloads that diverged from the December 04 PoC publicly released by researchers. The variant techniques suggest rapid adaptation by attackers following disclosure. Notable Vulnerabilities Discussed in Open-Source Communities CRIL identified multiple trending vulnerabilities drawing attention across open-source security and research forums. Key discussions included: CVE-2025-62221: A use-after-free elevation of privilege vulnerability in the Windows Cloud Files Mini Filter Driver. A local attacker could gain SYSTEM-level privileges, and the flaw can be chained with phishing or browser exploits for full host compromise. CVE-2025-10573: A critical stored XSS vulnerability in Ivanti Endpoint Manager, allowing remote unauthenticated attackers to embed malicious JavaScript that executes when an administrator views the dashboard. Vulnerabilities Under Discussion on the Dark Web CRIL’s dark-web monitoring identified several vulnerabilities actively discussed, traded, or weaponized by threat actors: CVE-2025-6440: A critical arbitrary file upload vulnerability in the WooCommerce Designer Pro plugin for WordPress (also distributed with the Pricom Printing Company & Design Services theme). Allows unauthenticated file upload and remote code execution via malicious PHP web shells. CVE-2025-55182: Also referred to as “React2Shell” or “React4Shell,” actively weaponized on underground forums. The flaw affects React 19's Server Components Flight protocol and frameworks such as Next.js. CVE-2025-66516: A severe XXE vulnerability in Apache Tika. The administrator of the “Proxy Bar” Telegram channel circulated exploit material demonstrating how malicious PDF files with embedded XFA forms could achieve arbitrary file read, SSRF, denial-of-service, and, in some cases, remote code execution. CRIL’s vulnerability intelligence timeline notes: CVE Product CVE Release DW Capture PoC CVE-2025-6440 WooCommerce Designer Pro Oct 24, 2025 Dec 03, 2025 Yes CVE-2025-55182 React Server Components Dec 03, 2025 Dec 05, 2025 Yes CVE-2025-66516 Apache Tika Modules Dec 04, 2025 Dec 08, 2025 Yes Top ICS Vulnerabilities Tracked This Week CRIL highlighted multiple ICS vulnerabilities affecting industrial vendors across energy, manufacturing, and commercial facilities. Key issues included: Sunbird – DCIM dcTrack & Power IQ (≤ 9.2.0): Authentication bypass and hard-coded credentials vulnerabilities (CVSS 6.5 and 6.7), risking unauthorized access and credential compromise. Johnson Controls OpenBlue Workplace (2025.1.2 and prior): A CVSS 9.3 Forced Browsing vulnerability enabling unauthorized access to sensitive operations in critical infrastructure environments. Across the ICS landscape, most vulnerabilities were medium severity, while commercial facilities, critical manufacturing, and energy sectors accounted for 43% of total incidents. Multi-sector issues, including IT, government, healthcare, and transportation, accounted for an additional 29%. Recommendations and Mitigations CRIL’s report reiterates essential mitigation steps: Apply all vendor patches promptly, particularly for vulnerabilities listed in the KEV catalog. Implement a structured patch management program covering testing, deployment, and verification. Segment networks to isolate critical systems and reduce lateral movement. Maintain an incident response plan and test it regularly. Deploy comprehensive monitoring and logging with SIEM correlation. Track alerts from vendors, CERTs, and government authorities. Conduct routine VAPT exercises and security audits. Maintain visibility into internal and external assets. Enforce strong password policies, replace all default credentials, and adopt MFA across all environments. Conclusion The wide range of vulnerabilities identified this week highlights the expanding threat landscape facing industrial and operational environments. Security teams must act quickly and focus on risk-based vulnerability management to protect critical systems. Key practices, such as network segmentation, restricting exposed assets, applying Zero-Trust principles, maintaining resilient backups, hardening configurations, and continuous monitoring, remain essential for reducing attack surface and improving incident response readiness. Cyble’s attack surface management solutions can support these efforts by detecting exposures across network and cloud environments, prioritizing remediation, and providing early indicators of potential cyberattacks. To see how Cyble can strengthen your industrial security posture, request a demo today. The post The Week in Vulnerabilities: Cyble Tracks New ICS Threats, Zero-Days, and Active Exploitation appeared first on Cyble.
Analysis Summary
This summary consolidates the high-priority vulnerabilities identified by Cyble Research & Intelligence Labs (CRIL) between December 3 and December 9, 2025, focusing on critical flaws with active exploitation or public Proof-of-Concept (PoC) availability.
---
# Vulnerability: ZITADEL Critical SSRF
## CVE Details
- CVE ID: CVE-2025-67494
- CVSS Score: Not explicitly provided, but rated **Critical**.
## Affected Systems
- Products: ZITADEL
- Versions: Not specified.
- Configurations: Affects the server component.
## Vulnerability Description
A critical Server-Side Request Forgery (SSRF) flaw exists within ZITADEL, potentially enabling an attacker to pivot unauthorized requests across the network and lead to data exposure.
## Exploitation
- Status: Newly disclosed, high-impact. PoC status not explicitly detailed in context, assumed to be or quickly forthcoming given the trend.
- Complexity: Not rated.
- Attack Vector: Network.
## Impact
- Confidentiality: High potential for data exposure.
- Integrity: Potential for unauthorized requests.
- Availability: Potential for Denial of Service (DoS).
## Remediation
### Patches
- Vendor patches should be applied promptly. (Specific patch details unavailable in the summary).
### Workarounds
- Implementing strict network egress filtering for server components may limit pivoting.
## Detection
- Monitor outbound network traffic for unusual server requests to internal or external hosts.
## References
- N/A (Specific vendor advisory link not provided in summary text).
---
# Vulnerability: Fortinet Authentication Bypass
## CVE Details
- CVE ID: CVE-2025-59719
- CVSS Score: Not explicitly provided, but characterized as a major issue.
## Affected Systems
- Products: Fortinet products
- Versions: Not specified.
- Configurations: Not specified.
## Vulnerability Description
An authentication bypass vulnerability impacting multiple Fortinet products.
## Exploitation
- Status: Newly disclosed, high-impact.
- Complexity: Not rated.
- Attack Vector: Network.
## Impact
- Confidentiality: High potential for unauthorized access.
- Integrity: High potential for unauthorized actions.
- Availability: Not immediately specified.
## Remediation
### Patches
- Apply all vendor patches for related Fortinet security advisories.
### Workarounds
- Review authentication logs for unusual access patterns.
## Detection
- Monitor authentication systems for bypass attempts or access from unknown sources.
## References
- N/A
---
# Vulnerability: SAP Solution Manager Code Injection
## CVE Details
- CVE ID: CVE-2025-42880
- CVSS Score: Not explicitly provided, but characterized as a major issue.
## Affected Systems
- Products: SAP Solution Manager
- Versions: Not specified.
- Configurations: Not specified.
## Vulnerability Description
A code injection flaw discovered in SAP Solution Manager.
## Exploitation
- Status: Newly disclosed, high-impact.
- Complexity: Not rated.
- Attack Vector: Network (likely).
## Impact
- Confidentiality: Potential for information disclosure.
- Integrity: High potential for code execution.
- Availability: Potential for service disruption.
## Remediation
### Patches
- Apply relevant patches released by SAP for Solution Manager.
### Workarounds
- Restrict access to the vulnerable components of Solution Manager if possible.
## Detection
- Monitor application logs for evidence of injected code execution attempts.
## References
- N/A
---
# Vulnerability: Apache Tika XXE
## CVE Details
- CVE ID: CVE-2025-66516
- CVSS Score: Not explicitly provided, but rated **severe**.
- CWE: XML External Entity (XXE)
## Affected Systems
- Products: Apache Tika
- Versions: Affects modules including `tika-core`, `tika-pdf-module`, and `tika-parsers`.
- Configurations: Specific vulnerable versions not listed, applies to modules handling XML/document parsing.
## Vulnerability Description
A severe XML External Entity (XXE) vulnerability. Exploit material circulated showed that malicious PDF files embedding XFA forms could lead to arbitrary file read, SSRF, DoS, and potentially RCE.
## Exploitation
- Status: **Actively weaponized on Dark Web**. Exploit material circulated (Telegram). PoC available (Capture Date: Dec 08, 2025).
- Complexity: Not rated, but demonstrated weaponization suggests practical exploitation is feasible.
- Attack Vector: Network (via file upload/processing).
## Impact
- Confidentiality: File read, SSRF.
- Integrity: Potential for DoS/RCE.
- Availability: Denial-of-Service.
## Remediation
### Patches
- Apply vendor patches for Apache Tika modules.
### Workarounds
- Disable XML external entity processing entirely if possible, or strictly validate user-supplied input/files being processed by Tika modules.
## Detection
- Monitor network egress traffic for unexpected connections stemming from the Tika server process (indicative of SSRF).
- Scan incoming files for suspicious embedded structures.
## References
- Discussed on "Proxy Bar" Telegram channel.
---
# Vulnerability: WinRAR RCE (CISA KEV)
## CVE Details
- CVE ID: CVE-2025-6218
- CVSS Score: Not explicitly provided, but included in CISA KEV catalogue (indicating active exploitation).
## Affected Systems
- Products: RARLAB WinRAR
- Versions: Not specified.
- Configurations: Not specified.
## Vulnerability Description
A directory traversal flaw in WinRAR that can lead to Remote Code Execution (RCE).
## Exploitation
- Status: **Added to CISA Known Exploited Vulnerabilities (KEV) catalogue**.
- Complexity: Not rated.
- Attack Vector: Likely file processing or archival manipulation.
## Impact
- Confidentiality: High (RCE).
- Integrity: High (RCE).
- Availability: High (RCE/System compromise).
## Remediation
### Patches
- **Apply vendor patches immediately (Critical Priority due to KEV status).**
### Workarounds
- Restrict the ability for untrusted users to supply `.rar` or related archive files for processing on critical systems.
## Detection
- Systems should have detection rules implemented for CISA KEVs.
## References
- CISA KEV Catalogue addition (Dec 3 - Dec 9, 2025 timeframe).
---
# Vulnerability: React Server Components RCE (CISA KEV, Active Weaponization)
## CVE Details
- CVE ID: CVE-2025-55182
- CVSS Score: Not explicitly provided, but rated **Critical** and added to CISA KEV catalogue.
- Nicknames: "React2Shell" or "React4Shell"
## Affected Systems
- Products: React Server Components (RSC), frameworks relying on the "Flight" protocol (e.g., Next.js).
- Versions: Affecting React 19 components using the Flight protocol.
- Configurations: Relies on unsafe deserialization within the Flight protocol.
## Vulnerability Description
A critical, pre-authentication Remote Code Execution (RCE) vulnerability stemming from unsafe deserialization in the React Server Components (RSC) "Flight" protocol.
## Exploitation
- Status: **Actively weaponized in the wild**. Exploitation attempts recorded using payloads diverging from the initial PoC, indicating rapid attacker adaptation. PoC available (Capture Date: Dec 05, 2025).
- Complexity: Low; pre-authentication.
- Attack Vector: Network.
## Impact
- Confidentiality: High (RCE).
- Integrity: High (RCE).
- Availability: High (System compromise).
## Remediation
### Patches
- **Apply vendor patches immediately (Critical Priority due to KEV status and active weaponization).**
### Workarounds
- Disable or audit the usage of the RSC "Flight" protocol if immediate patching is impossible.
## Detection
- Look for anomalous deserialization patterns or unexpected process execution related to web application services handling React/Next.js traffic.
## References
- CISA KEV Catalogue addition (Dec 3 - Dec 9, 2025 timeframe).
---
# Vulnerability: Windows Cloud Files Mini Filter Driver UAF
## CVE Details
- CVE ID: CVE-2025-62221
- CVSS Score: Not explicitly provided, but enables SYSTEM-level privilege escalation.
## Affected Systems
- Products: Windows Cloud Files Mini Filter Driver
- Versions: Not specified.
- Configurations: Local attacker required.
## Vulnerability Description
A Use-After-Free (UAF) vulnerability in the Windows Cloud Files Mini Filter Driver allowing a local attacker to elevate privileges to SYSTEM level. Often chained with initial access methods (phishing/browser exploits).
## Exploitation
- Status: Trending vulnerability discussed in open-source communities. PoC status not specified.
- Complexity: Local access required, but chaining suggests high overall exploitability.
- Attack Vector: Local.
## Impact
- Confidentiality: High (Full system compromise).
- Integrity: High (Full system compromise).
- Availability: High (System control).
## Remediation
### Patches
- Apply all relevant Microsoft Windows security updates.
### Workarounds
- Enforce strict access controls on endpoints to prevent unauthorized local execution leading to driver interaction.
## Detection
- Monitor for unusual driver load behavior or file system filter activity.
## References
- Discussed in open-source security forums.
---
# Vulnerability: Ivanti Endpoint Manager Stored XSS
## CVE Details
- CVE ID: CVE-2025-10573
- CVSS Score: Not explicitly provided, but rated **Critical**.
## Affected Systems
- Products: Ivanti Endpoint Manager
- Versions: Not specified.
- Configurations: Impacts the administrator dashboard view.
## Vulnerability Description
A critical Stored Cross-Site Scripting (XSS) vulnerability. A remote, unauthenticated attacker can inject malicious JavaScript that executes when an administrator views the dashboard.
## Exploitation
- Status: Trending vulnerability discussed in open-source communities.
- Complexity: Low (Remote, unauthenticated injection possible).
- Attack Vector: Network.
## Impact
- Confidentiality: High (Credential theft, session hijacking).
- Integrity: High (Actions performed by compromised administrator session).
- Availability: Low to Medium.
## Remediation
### Patches
- Apply all relevant Ivanti security patches for Endpoint Manager.
### Workarounds
- Restrict administrative access to the Ivanti dashboard via network controls (VPN/internal network only) until patched.
## Detection
- Monitor network traffic for unexpected JavaScript payloads being served by the Ivanti Endpoint Manager server.
## References
- Discussed in open-source security forums.
---
# Vulnerability: WooCommerce Designer Pro File Upload (Dark Web)
## CVE Details
- CVE ID: CVE-2025-6440
- CVSS Score: Not explicitly provided, but allows RCE.
## Affected Systems
- Products: WooCommerce Designer Pro plugin for WordPress, and the Pricom Printing Company & Design Services theme.
- Versions: Not specified.
- Configurations: WordPress environment utilizing the plugin/theme.
## Vulnerability Description
A critical arbitrary file upload vulnerability. Allows unauthenticated access to upload malicious PHP web shells, leading to Remote Code Execution.
## Exploitation
- Status: **Actively discussed/traded on the Dark Web**. PoC available (Capture Date: Dec 03, 2025).
- Complexity: Low (Unauthenticated).
- Attack Vector: Network (Web application).
## Impact
- Confidentiality: High (RCE).
- Integrity: High (RCE).
- Availability: High (Website takeover/DoS).
## Remediation
### Patches
- Remove the vulnerable plugin/theme or apply vendor patches immediately.
### Workarounds
- Disable file upload functionality via web application firewall (WAF) rules targeting PHP file extensions, verify user roles for upload permissions.
## Detection
- Monitor for new or unusual `.php` files appearing in web-accessible directories, especially those containing web shell signatures.
## References
- Dark Web discussions tracked by CRIL.
---
# ICS Vulnerabilities Summary
CRIL tracked serious issues impacting Industrial Control Systems (ICS):
1. **Sunbird dcTrack & Power IQ (≤ 9.2.0):** Authentication bypass and hard-coded credentials (CVSS 6.5/6.7). Risks unauthorized access and credential compromise.
* **Mitigation:** Change all default/hard-coded credentials immediately; apply patches.
2. **Johnson Controls OpenBlue Workplace (2025.1.2 and prior):** CVSS 9.3 Forced Browsing vulnerability. Risks unauthorized access to sensitive operations in critical infrastructure.
* **Mitigation:** Apply patches; restrict network access immediately.
---
# General Mitigation Strategies (CRIL Recommendations)
Across all findings, CRIL emphasizes the need for proactive security posture:
1. **Patch Management:** Apply all vendor patches promptly, prioritizing CISA KEV entries.
2. **Network Security:** Implement network segmentation to isolate critical systems and limit lateral movement.
3. **Access Control:** Enforce strong password policies, replace all default credentials, and adopt Multi-Factor Authentication (MFA).
4. **Monitoring & Response:** Maintain comprehensive monitoring (SIEM) and regularly test Incident Response plans.
5. **Asset Management:** Maintain full visibility into internal and external assets (Attack Surface Management).